ssh_digest_bytes:
  101|    300|{
  102|    300|	const struct ssh_digest *digest = ssh_digest_by_alg(alg);
  103|       |
  104|    300|	return digest == NULL ? 0 : digest->digest_len;
  ------------------
  |  Branch (104:9): [True: 0, False: 300]
  ------------------
  105|    300|}
ssh_digest_memory:
  186|     41|{
  187|     41|	const struct ssh_digest *digest = ssh_digest_by_alg(alg);
  188|     41|	u_int mdlen;
  189|       |
  190|     41|	if (digest == NULL)
  ------------------
  |  Branch (190:6): [True: 0, False: 41]
  ------------------
  191|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  192|     41|	if (dlen > UINT_MAX)
  ------------------
  |  Branch (192:6): [True: 0, False: 41]
  ------------------
  193|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  194|     41|	if (dlen < digest->digest_len)
  ------------------
  |  Branch (194:6): [True: 0, False: 41]
  ------------------
  195|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  196|     41|	mdlen = dlen;
  197|     41|	if (!EVP_Digest(m, mlen, d, &mdlen, digest->mdfunc(), NULL))
  ------------------
  |  Branch (197:6): [True: 0, False: 41]
  ------------------
  198|      0|		return SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  199|     41|	return 0;
  200|     41|}
ssh_digest_buffer:
  204|      1|{
  205|      1|	return ssh_digest_memory(alg, sshbuf_ptr(b), sshbuf_len(b), d, dlen);
  206|      1|}
digest-openssl.c:ssh_digest_by_alg:
   69|    341|{
   70|    341|	if (alg < 0 || alg >= SSH_DIGEST_MAX)
  ------------------
  |  |   30|    341|#define SSH_DIGEST_MAX		5
  ------------------
  |  Branch (70:6): [True: 0, False: 341]
  |  Branch (70:17): [True: 0, False: 341]
  ------------------
   71|      0|		return NULL;
   72|    341|	if (digests[alg].id != alg) /* sanity */
  ------------------
  |  Branch (72:6): [True: 0, False: 341]
  ------------------
   73|      0|		return NULL;
   74|    341|	if (digests[alg].mdfunc == NULL)
  ------------------
  |  Branch (74:6): [True: 0, False: 341]
  ------------------
   75|      0|		return NULL;
   76|    341|	return &(digests[alg]);
   77|    341|}

crypto_sign_ed25519_ref_fe25519_getparity:
  268|    124|{
  269|    124|  fe25519 t = *x;
  ------------------
  |  |   72|    124|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  270|    124|  fe25519_freeze(&t);
  ------------------
  |  |   73|    124|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  271|    124|  return t.v[0] & 1;
  272|    124|}
crypto_sign_ed25519_ref_unpackneg_vartime:
 1786|     80|{
 1787|     80|  unsigned char par;
 1788|     80|  fe25519 t, chk, num, den, den2, den4, den6;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1789|     80|  fe25519_setone(&r->z);
  ------------------
  |  |   79|     80|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1790|     80|  par = p[31] >> 7;
 1791|     80|  fe25519_unpack(&r->y, p);
  ------------------
  |  |   74|     80|#define fe25519_unpack       crypto_sign_ed25519_ref_fe25519_unpack
  ------------------
 1792|     80|  fe25519_square(&num, &r->y); /* x = y^2 */
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1793|     80|  fe25519_mul(&den, &num, &ge25519_ecd); /* den = dy^2 */
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1794|     80|  fe25519_sub(&num, &num, &r->z); /* x = y^2-1 */
  ------------------
  |  |   84|     80|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1795|     80|  fe25519_add(&den, &r->z, &den); /* den = dy^2+1 */
  ------------------
  |  |   83|     80|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1796|       |
 1797|       |  /* Computation of sqrt(num/den) */
 1798|       |  /* 1.: computation of num^((p-5)/8)*den^((7p-35)/8) = (num*den^7)^((p-5)/8) */
 1799|     80|  fe25519_square(&den2, &den);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1800|     80|  fe25519_square(&den4, &den2);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1801|     80|  fe25519_mul(&den6, &den4, &den2);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1802|     80|  fe25519_mul(&t, &den6, &num);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1803|     80|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1804|       |
 1805|     80|  fe25519_pow2523(&t, &t);
  ------------------
  |  |   88|     80|#define fe25519_pow2523      crypto_sign_ed25519_ref_fe25519_pow2523
  ------------------
 1806|       |  /* 2. computation of r->x = t * num * den^3 */
 1807|     80|  fe25519_mul(&t, &t, &num);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1808|     80|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1809|     80|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1810|     80|  fe25519_mul(&r->x, &t, &den);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1811|       |
 1812|       |  /* 3. Check whether sqrt computation gave correct result, multiply by sqrt(-1) if not: */
 1813|     80|  fe25519_square(&chk, &r->x);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1814|     80|  fe25519_mul(&chk, &chk, &den);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1815|     80|  if (!fe25519_iseq_vartime(&chk, &num))
  ------------------
  |  |   77|     80|#define fe25519_iseq_vartime crypto_sign_ed25519_ref_fe25519_iseq_vartime
  ------------------
  |  Branch (1815:7): [True: 58, False: 22]
  ------------------
 1816|     58|    fe25519_mul(&r->x, &r->x, &ge25519_sqrtm1);
  ------------------
  |  |   85|     58|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1817|       |
 1818|       |  /* 4. Now we have one of the two square roots, except if input was not a square */
 1819|     80|  fe25519_square(&chk, &r->x);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1820|     80|  fe25519_mul(&chk, &chk, &den);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1821|     80|  if (!fe25519_iseq_vartime(&chk, &num))
  ------------------
  |  |   77|     80|#define fe25519_iseq_vartime crypto_sign_ed25519_ref_fe25519_iseq_vartime
  ------------------
  |  Branch (1821:7): [True: 18, False: 62]
  ------------------
 1822|     18|    return -1;
 1823|       |
 1824|       |  /* 5. Choose the desired square root according to parity: */
 1825|     62|  if(fe25519_getparity(&r->x) != (1-par))
  ------------------
  |  |   82|     62|#define fe25519_getparity    crypto_sign_ed25519_ref_fe25519_getparity
  ------------------
  |  Branch (1825:6): [True: 42, False: 20]
  ------------------
 1826|     42|    fe25519_neg(&r->x, &r->x);
  ------------------
  |  |   81|     42|#define fe25519_neg          crypto_sign_ed25519_ref_fe25519_neg
  ------------------
 1827|       |
 1828|     62|  fe25519_mul(&r->t, &r->x, &r->y);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1829|     62|  return 0;
 1830|     80|}
crypto_sign_ed25519_open:
 1993|     92|{
 1994|     92|  unsigned char pkcopy[32];
 1995|     92|  unsigned char rcopy[32];
 1996|     92|  unsigned char hram[64];
 1997|     92|  unsigned char rcheck[32];
 1998|     92|  ge25519 get1, get2;
  ------------------
  |  |  724|     92|#define ge25519                           crypto_sign_ed25519_ref_ge25519
  ------------------
 1999|     92|  sc25519 schram, scs;
  ------------------
  |  |  461|     92|#define sc25519                  crypto_sign_ed25519_ref_sc25519
  ------------------
 2000|       |
 2001|     92|  if (smlen < 64) goto badsig;
  ------------------
  |  Branch (2001:7): [True: 0, False: 92]
  ------------------
 2002|     92|  if (sm[63] & 224) goto badsig;
  ------------------
  |  Branch (2002:7): [True: 12, False: 80]
  ------------------
 2003|     80|  if (ge25519_unpackneg_vartime(&get1,pk)) goto badsig;
  ------------------
  |  |  726|     80|#define ge25519_unpackneg_vartime         crypto_sign_ed25519_ref_unpackneg_vartime
  ------------------
  |  Branch (2003:7): [True: 18, False: 62]
  ------------------
 2004|       |
 2005|     62|  memmove(pkcopy,pk,32);
 2006|     62|  memmove(rcopy,sm,32);
 2007|       |
 2008|     62|  sc25519_from32bytes(&scs, sm+32);
  ------------------
  |  |  463|     62|#define sc25519_from32bytes      crypto_sign_ed25519_ref_sc25519_from32bytes
  ------------------
 2009|       |
 2010|     62|  memmove(m,sm,smlen);
 2011|     62|  memmove(m + 32,pkcopy,32);
 2012|     62|  crypto_hash_sha512(hram,m,smlen);
 2013|       |
 2014|     62|  sc25519_from64bytes(&schram, hram);
  ------------------
  |  |  464|     62|#define sc25519_from64bytes      crypto_sign_ed25519_ref_sc25519_from64bytes
  ------------------
 2015|       |
 2016|     62|  ge25519_double_scalarmult_vartime(&get2, &get1, &schram, &ge25519_base, &scs);
  ------------------
  |  |  729|     62|#define ge25519_double_scalarmult_vartime crypto_sign_ed25519_ref_double_scalarmult_vartime
  ------------------
                ge25519_double_scalarmult_vartime(&get2, &get1, &schram, &ge25519_base, &scs);
  ------------------
  |  |  725|     62|#define ge25519_base                      crypto_sign_ed25519_ref_ge25519_base
  ------------------
 2017|     62|  ge25519_pack(rcheck, &get2);
  ------------------
  |  |  727|     62|#define ge25519_pack                      crypto_sign_ed25519_ref_pack
  ------------------
 2018|       |
 2019|     62|  if (crypto_verify_32(rcopy,rcheck) == 0) {
  ------------------
  |  Branch (2019:7): [True: 12, False: 50]
  ------------------
 2020|     12|    memmove(m,m + 64,smlen - 64);
 2021|     12|    memset(m + smlen - 64,0,64);
 2022|     12|    *mlen = smlen - 64;
 2023|     12|    return 0;
 2024|     12|  }
 2025|       |
 2026|     80|badsig:
 2027|     80|  *mlen = (unsigned long long) -1;
 2028|     80|  memset(m,0,smlen);
 2029|     80|  return -1;
 2030|     62|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_freeze:
  203|    506|{
  204|    506|  int i;
  205|    506|  crypto_uint32 m = fe25519_equal(r->v[31],127);
  206|  15.6k|  for(i=30;i>0;i--)
  ------------------
  |  Branch (206:12): [True: 15.1k, False: 506]
  ------------------
  207|  15.1k|    m &= fe25519_equal(r->v[i],255);
  208|    506|  m &= ge(r->v[0],237);
  209|       |
  210|    506|  m = -m;
  211|       |
  212|    506|  r->v[31] -= m&127;
  213|  15.6k|  for(i=30;i>0;i--)
  ------------------
  |  Branch (213:12): [True: 15.1k, False: 506]
  ------------------
  214|  15.1k|    r->v[i] -= m&255;
  215|    506|  r->v[0] -= m&237;
  216|    506|}
ed25519.c:fe25519_equal:
  135|  15.6k|{
  136|  15.6k|  crypto_uint32 x = a ^ b; /* 0: yes; 1..65535: no */
  137|  15.6k|  x -= 1; /* 4294967295: yes; 0..65534: no */
  138|  15.6k|  x >>= 31; /* 1: yes; 0: no */
  139|  15.6k|  return x;
  140|  15.6k|}
ed25519.c:ge:
  143|    506|{
  144|    506|  unsigned int x = a;
  145|    506|  x -= (unsigned int) b; /* 0..65535: yes; 4294901761..4294967295: no */
  146|    506|  x >>= 31; /* 0: yes; 1: no */
  147|    506|  x ^= 1; /* 1: yes; 0: no */
  148|    506|  return x;
  149|    506|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_setone:
  275|    204|{
  276|    204|  int i;
  277|    204|  r->v[0] = 1;
  278|  6.52k|  for(i=1;i<32;i++) r->v[i]=0;
  ------------------
  |  Branch (278:11): [True: 6.32k, False: 204]
  ------------------
  279|    204|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_unpack:
  219|     80|{
  220|     80|  int i;
  221|  2.64k|  for(i=0;i<32;i++) r->v[i] = x[i];
  ------------------
  |  Branch (221:11): [True: 2.56k, False: 80]
  ------------------
  222|     80|  r->v[31] &= 127;
  223|     80|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_square:
  332|  99.4k|{
  333|  99.4k|  fe25519_mul(r, x, x);
  ------------------
  |  |   85|  99.4k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  334|  99.4k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_mul:
  315|   210k|{
  316|   210k|  int i,j;
  317|   210k|  crypto_uint32 t[63];
  318|  13.4M|  for(i=0;i<63;i++)t[i] = 0;
  ------------------
  |  Branch (318:11): [True: 13.2M, False: 210k]
  ------------------
  319|       |
  320|  6.95M|  for(i=0;i<32;i++)
  ------------------
  |  Branch (320:11): [True: 6.74M, False: 210k]
  ------------------
  321|   222M|    for(j=0;j<32;j++)
  ------------------
  |  Branch (321:13): [True: 215M, False: 6.74M]
  ------------------
  322|   215M|      t[i+j] += x->v[i] * y->v[j];
  323|       |
  324|  6.74M|  for(i=32;i<63;i++)
  ------------------
  |  Branch (324:12): [True: 6.53M, False: 210k]
  ------------------
  325|  6.53M|    r->v[i-32] = t[i-32] + times38(t[i]);
  326|   210k|  r->v[31] = t[31]; /* result now in r[0]...r[31] */
  327|       |
  328|   210k|  reduce_mul(r);
  329|   210k|}
ed25519.c:times38:
  157|  6.53M|{
  158|  6.53M|  return (a << 5) + (a << 2) + (a << 1);
  159|  6.53M|}
ed25519.c:reduce_mul:
  182|   210k|{
  183|   210k|  crypto_uint32 t;
  184|   210k|  int i,rep;
  185|       |
  186|   632k|  for(rep=0;rep<2;rep++)
  ------------------
  |  Branch (186:13): [True: 421k, False: 210k]
  ------------------
  187|   421k|  {
  188|   421k|    t = r->v[31] >> 7;
  189|   421k|    r->v[31] &= 127;
  190|   421k|    t = times19(t);
  191|   421k|    r->v[0] += t;
  192|  13.4M|    for(i=0;i<31;i++)
  ------------------
  |  Branch (192:13): [True: 13.0M, False: 421k]
  ------------------
  193|  13.0M|    {
  194|  13.0M|      t = r->v[i] >> 8;
  195|  13.0M|      r->v[i+1] += t;
  196|  13.0M|      r->v[i] &= 255;
  197|  13.0M|    }
  198|   421k|  }
  199|   210k|}
ed25519.c:times19:
  152|  1.17M|{
  153|  1.17M|  return (a << 4) + (a << 1) + a;
  154|  1.17M|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_sub:
  304|   106k|{
  305|   106k|  int i;
  306|   106k|  crypto_uint32 t[32];
  307|   106k|  t[0] = x->v[0] + 0x1da;
  308|   106k|  t[31] = x->v[31] + 0xfe;
  309|  3.29M|  for(i=1;i<31;i++) t[i] = x->v[i] + 0x1fe;
  ------------------
  |  Branch (309:11): [True: 3.18M, False: 106k]
  ------------------
  310|  3.50M|  for(i=0;i<32;i++) r->v[i] = t[i] - y->v[i];
  ------------------
  |  Branch (310:11): [True: 3.40M, False: 106k]
  ------------------
  311|   106k|  fe25519_reduce_add_sub(r);
  312|   106k|}
ed25519.c:fe25519_reduce_add_sub:
  162|   187k|{
  163|   187k|  crypto_uint32 t;
  164|   187k|  int i,rep;
  165|       |
  166|   938k|  for(rep=0;rep<4;rep++)
  ------------------
  |  Branch (166:13): [True: 750k, False: 187k]
  ------------------
  167|   750k|  {
  168|   750k|    t = r->v[31] >> 7;
  169|   750k|    r->v[31] &= 127;
  170|   750k|    t = times19(t);
  171|   750k|    r->v[0] += t;
  172|  24.0M|    for(i=0;i<31;i++)
  ------------------
  |  Branch (172:13): [True: 23.2M, False: 750k]
  ------------------
  173|  23.2M|    {
  174|  23.2M|      t = r->v[i] >> 8;
  175|  23.2M|      r->v[i+1] += t;
  176|  23.2M|      r->v[i] &= 255;
  177|  23.2M|    }
  178|   750k|  }
  179|   187k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_add:
  297|  81.4k|{
  298|  81.4k|  int i;
  299|  2.68M|  for(i=0;i<32;i++) r->v[i] = x->v[i] + y->v[i];
  ------------------
  |  Branch (299:11): [True: 2.60M, False: 81.4k]
  ------------------
  300|  81.4k|  fe25519_reduce_add_sub(r);
  301|  81.4k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_pow2523:
  404|     80|{
  405|     80|	fe25519 z2;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  406|     80|	fe25519 z9;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  407|     80|	fe25519 z11;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  408|     80|	fe25519 z2_5_0;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  409|     80|	fe25519 z2_10_0;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  410|     80|	fe25519 z2_20_0;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  411|     80|	fe25519 z2_50_0;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  412|     80|	fe25519 z2_100_0;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  413|     80|	fe25519 t;
  ------------------
  |  |   72|     80|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  414|     80|	int i;
  415|       |
  416|     80|	/* 2 */ fe25519_square(&z2,x);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  417|       |	/* 4 */ fe25519_square(&t,&z2);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  418|       |	/* 8 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  419|       |	/* 9 */ fe25519_mul(&z9,&t,x);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  420|       |	/* 11 */ fe25519_mul(&z11,&z9,&z2);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  421|       |	/* 22 */ fe25519_square(&t,&z11);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  422|       |	/* 2^5 - 2^0 = 31 */ fe25519_mul(&z2_5_0,&t,&z9);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  423|       |
  424|     80|	/* 2^6 - 2^1 */ fe25519_square(&t,&z2_5_0);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  425|    400|	/* 2^10 - 2^5 */ for (i = 1;i < 5;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    320|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (425:30): [True: 320, False: 80]
  ------------------
  426|       |	/* 2^10 - 2^0 */ fe25519_mul(&z2_10_0,&t,&z2_5_0);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  427|       |
  428|     80|	/* 2^11 - 2^1 */ fe25519_square(&t,&z2_10_0);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  429|    800|	/* 2^20 - 2^10 */ for (i = 1;i < 10;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    720|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (429:31): [True: 720, False: 80]
  ------------------
  430|       |	/* 2^20 - 2^0 */ fe25519_mul(&z2_20_0,&t,&z2_10_0);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  431|       |
  432|     80|	/* 2^21 - 2^1 */ fe25519_square(&t,&z2_20_0);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  433|  1.60k|	/* 2^40 - 2^20 */ for (i = 1;i < 20;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  1.52k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (433:31): [True: 1.52k, False: 80]
  ------------------
  434|       |	/* 2^40 - 2^0 */ fe25519_mul(&t,&t,&z2_20_0);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  435|       |
  436|     80|	/* 2^41 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  437|    800|	/* 2^50 - 2^10 */ for (i = 1;i < 10;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    720|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (437:31): [True: 720, False: 80]
  ------------------
  438|       |	/* 2^50 - 2^0 */ fe25519_mul(&z2_50_0,&t,&z2_10_0);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  439|       |
  440|     80|	/* 2^51 - 2^1 */ fe25519_square(&t,&z2_50_0);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  441|  4.00k|	/* 2^100 - 2^50 */ for (i = 1;i < 50;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  3.92k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (441:32): [True: 3.92k, False: 80]
  ------------------
  442|       |	/* 2^100 - 2^0 */ fe25519_mul(&z2_100_0,&t,&z2_50_0);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  443|       |
  444|     80|	/* 2^101 - 2^1 */ fe25519_square(&t,&z2_100_0);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  445|  8.00k|	/* 2^200 - 2^100 */ for (i = 1;i < 100;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  7.92k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (445:33): [True: 7.92k, False: 80]
  ------------------
  446|       |	/* 2^200 - 2^0 */ fe25519_mul(&t,&t,&z2_100_0);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  447|       |
  448|     80|	/* 2^201 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  449|  4.00k|	/* 2^250 - 2^50 */ for (i = 1;i < 50;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  3.92k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (449:32): [True: 3.92k, False: 80]
  ------------------
  450|       |	/* 2^250 - 2^0 */ fe25519_mul(&t,&t,&z2_50_0);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  451|       |
  452|     80|	/* 2^251 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  453|       |	/* 2^252 - 2^2 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     80|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  454|       |	/* 2^252 - 3 */ fe25519_mul(r,&t,x);
  ------------------
  |  |   85|     80|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  455|     80|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_iseq_vartime:
  248|    160|{
  249|    160|  int i;
  250|    160|  fe25519 t1 = *x;
  ------------------
  |  |   72|    160|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  251|    160|  fe25519 t2 = *y;
  ------------------
  |  |   72|    160|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  252|    160|  fe25519_freeze(&t1);
  ------------------
  |  |   73|    160|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  253|    160|  fe25519_freeze(&t2);
  ------------------
  |  |   73|    160|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  254|  2.85k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (254:11): [True: 2.77k, False: 84]
  ------------------
  255|  2.77k|    if(t1.v[i] != t2.v[i]) return 0;
  ------------------
  |  Branch (255:8): [True: 76, False: 2.69k]
  ------------------
  256|     84|  return 1;
  257|    160|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_neg:
  288|  15.8k|{
  289|  15.8k|  fe25519 t;
  ------------------
  |  |   72|  15.8k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  290|  15.8k|  int i;
  291|   523k|  for(i=0;i<32;i++) t.v[i]=x->v[i];
  ------------------
  |  Branch (291:11): [True: 507k, False: 15.8k]
  ------------------
  292|  15.8k|  fe25519_setzero(r);
  ------------------
  |  |   80|  15.8k|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
  293|  15.8k|  fe25519_sub(r, r, &t);
  ------------------
  |  |   84|  15.8k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
  294|  15.8k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_setzero:
  282|  15.9k|{
  283|  15.9k|  int i;
  284|   527k|  for(i=0;i<32;i++) r->v[i]=0;
  ------------------
  |  Branch (284:11): [True: 511k, False: 15.9k]
  ------------------
  285|  15.9k|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_from32bytes:
  604|     62|{
  605|     62|  int i;
  606|     62|  crypto_uint32 t[64];
  607|  2.04k|  for(i=0;i<32;i++) t[i] = x[i];
  ------------------
  |  Branch (607:11): [True: 1.98k, False: 62]
  ------------------
  608|  2.04k|  for(i=32;i<64;++i) t[i] = 0;
  ------------------
  |  Branch (608:12): [True: 1.98k, False: 62]
  ------------------
  609|     62|  barrett_reduce(r, t);
  610|     62|}
ed25519.c:barrett_reduce:
  553|    124|{
  554|       |  /* See HAC, Alg. 14.42 */
  555|    124|  int i,j;
  556|    124|  crypto_uint32 q2[66];
  557|    124|  crypto_uint32 *q3 = q2 + 33;
  558|    124|  crypto_uint32 r1[33];
  559|    124|  crypto_uint32 r2[33];
  560|    124|  crypto_uint32 carry;
  561|    124|  crypto_uint32 pb = 0;
  562|    124|  crypto_uint32 b;
  563|       |
  564|  8.30k|  for (i = 0;i < 66;++i) q2[i] = 0;
  ------------------
  |  Branch (564:14): [True: 8.18k, False: 124]
  ------------------
  565|  4.21k|  for (i = 0;i < 33;++i) r2[i] = 0;
  ------------------
  |  Branch (565:14): [True: 4.09k, False: 124]
  ------------------
  566|       |
  567|  4.21k|  for(i=0;i<33;i++)
  ------------------
  |  Branch (567:11): [True: 4.09k, False: 124]
  ------------------
  568|   139k|    for(j=0;j<33;j++)
  ------------------
  |  Branch (568:13): [True: 135k, False: 4.09k]
  ------------------
  569|   135k|      if(i+j >= 31) q2[i+j] += sc25519_mu[i]*x[j+31];
  ------------------
  |  Branch (569:10): [True: 73.5k, False: 61.5k]
  ------------------
  570|    124|  carry = q2[31] >> 8;
  571|    124|  q2[32] += carry;
  572|    124|  carry = q2[32] >> 8;
  573|    124|  q2[33] += carry;
  574|       |
  575|  4.21k|  for(i=0;i<33;i++)r1[i] = x[i];
  ------------------
  |  Branch (575:11): [True: 4.09k, False: 124]
  ------------------
  576|  4.09k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (576:11): [True: 3.96k, False: 124]
  ------------------
  577|   134k|    for(j=0;j<33;j++)
  ------------------
  |  Branch (577:13): [True: 130k, False: 3.96k]
  ------------------
  578|   130k|      if(i+j < 33) r2[i+j] += sc25519_m[i]*q3[j];
  ------------------
  |  Branch (578:10): [True: 69.4k, False: 61.5k]
  ------------------
  579|       |
  580|  4.09k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (580:11): [True: 3.96k, False: 124]
  ------------------
  581|  3.96k|  {
  582|  3.96k|    carry = r2[i] >> 8;
  583|  3.96k|    r2[i+1] += carry;
  584|  3.96k|    r2[i] &= 0xff;
  585|  3.96k|  }
  586|       |
  587|  4.09k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (587:11): [True: 3.96k, False: 124]
  ------------------
  588|  3.96k|  {
  589|  3.96k|    pb += r2[i];
  590|  3.96k|    b = lt(r1[i],pb);
  591|  3.96k|    r->v[i] = r1[i]-pb+(b<<8);
  592|  3.96k|    pb = b;
  593|  3.96k|  }
  594|       |
  595|       |  /* XXX: Can it really happen that r<0?, See HAC, Alg 14.42, Step 3
  596|       |   * If so: Handle  it here!
  597|       |   */
  598|       |
  599|    124|  sc25519_reduce_add_sub(r);
  600|    124|  sc25519_reduce_add_sub(r);
  601|    124|}
ed25519.c:lt:
  523|  11.9k|{
  524|  11.9k|  unsigned int x = a;
  525|  11.9k|  x -= (unsigned int) b; /* 0..65535: no; 4294901761..4294967295: yes */
  526|  11.9k|  x >>= 31; /* 0: no; 1: yes */
  527|  11.9k|  return x;
  528|  11.9k|}
ed25519.c:sc25519_reduce_add_sub:
  532|    248|{
  533|    248|  crypto_uint32 pb = 0;
  534|    248|  crypto_uint32 b;
  535|    248|  crypto_uint32 mask;
  536|    248|  int i;
  537|    248|  unsigned char t[32];
  538|       |
  539|  8.18k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (539:11): [True: 7.93k, False: 248]
  ------------------
  540|  7.93k|  {
  541|  7.93k|    pb += sc25519_m[i];
  542|  7.93k|    b = lt(r->v[i],pb);
  543|  7.93k|    t[i] = r->v[i]-pb+(b<<8);
  544|  7.93k|    pb = b;
  545|  7.93k|  }
  546|    248|  mask = b - 1;
  547|  8.18k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (547:11): [True: 7.93k, False: 248]
  ------------------
  548|  7.93k|    r->v[i] ^= mask & (r->v[i] ^ t[i]);
  549|    248|}
ed25519.c:crypto_sign_ed25519_ref_pack:
 1833|     62|{
 1834|     62|  fe25519 tx, ty, zi;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1835|     62|  fe25519_invert(&zi, &p->z);
  ------------------
  |  |   87|     62|#define fe25519_invert       crypto_sign_ed25519_ref_fe25519_invert
  ------------------
 1836|     62|  fe25519_mul(&tx, &p->x, &zi);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1837|     62|  fe25519_mul(&ty, &p->y, &zi);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1838|     62|  fe25519_pack(r, &ty);
  ------------------
  |  |   75|     62|#define fe25519_pack         crypto_sign_ed25519_ref_fe25519_pack
  ------------------
 1839|     62|  r[31] ^= fe25519_getparity(&tx) << 7;
  ------------------
  |  |   82|     62|#define fe25519_getparity    crypto_sign_ed25519_ref_fe25519_getparity
  ------------------
 1840|     62|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_invert:
  337|     62|{
  338|     62|	fe25519 z2;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  339|     62|	fe25519 z9;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  340|     62|	fe25519 z11;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  341|     62|	fe25519 z2_5_0;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  342|     62|	fe25519 z2_10_0;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  343|     62|	fe25519 z2_20_0;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  344|     62|	fe25519 z2_50_0;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  345|     62|	fe25519 z2_100_0;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  346|     62|	fe25519 t0;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  347|     62|	fe25519 t1;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  348|     62|	int i;
  349|       |
  350|     62|	/* 2 */ fe25519_square(&z2,x);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  351|       |	/* 4 */ fe25519_square(&t1,&z2);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  352|       |	/* 8 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  353|       |	/* 9 */ fe25519_mul(&z9,&t0,x);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  354|       |	/* 11 */ fe25519_mul(&z11,&z9,&z2);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  355|       |	/* 22 */ fe25519_square(&t0,&z11);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  356|       |	/* 2^5 - 2^0 = 31 */ fe25519_mul(&z2_5_0,&t0,&z9);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  357|       |
  358|     62|	/* 2^6 - 2^1 */ fe25519_square(&t0,&z2_5_0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  359|       |	/* 2^7 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  360|       |	/* 2^8 - 2^3 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  361|       |	/* 2^9 - 2^4 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  362|       |	/* 2^10 - 2^5 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  363|       |	/* 2^10 - 2^0 */ fe25519_mul(&z2_10_0,&t0,&z2_5_0);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  364|       |
  365|     62|	/* 2^11 - 2^1 */ fe25519_square(&t0,&z2_10_0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  366|       |	/* 2^12 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  367|    310|	/* 2^20 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    248|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^20 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    248|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (367:31): [True: 248, False: 62]
  ------------------
  368|       |	/* 2^20 - 2^0 */ fe25519_mul(&z2_20_0,&t1,&z2_10_0);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  369|       |
  370|     62|	/* 2^21 - 2^1 */ fe25519_square(&t0,&z2_20_0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  371|       |	/* 2^22 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  372|    620|	/* 2^40 - 2^20 */ for (i = 2;i < 20;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    558|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^40 - 2^20 */ for (i = 2;i < 20;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    558|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (372:31): [True: 558, False: 62]
  ------------------
  373|       |	/* 2^40 - 2^0 */ fe25519_mul(&t0,&t1,&z2_20_0);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  374|       |
  375|     62|	/* 2^41 - 2^1 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  376|       |	/* 2^42 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  377|    310|	/* 2^50 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|    248|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^50 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|    248|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (377:31): [True: 248, False: 62]
  ------------------
  378|       |	/* 2^50 - 2^0 */ fe25519_mul(&z2_50_0,&t0,&z2_10_0);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  379|       |
  380|     62|	/* 2^51 - 2^1 */ fe25519_square(&t0,&z2_50_0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  381|       |	/* 2^52 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  382|  1.55k|	/* 2^100 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.48k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^100 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.48k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (382:32): [True: 1.48k, False: 62]
  ------------------
  383|       |	/* 2^100 - 2^0 */ fe25519_mul(&z2_100_0,&t1,&z2_50_0);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  384|       |
  385|     62|	/* 2^101 - 2^1 */ fe25519_square(&t1,&z2_100_0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  386|       |	/* 2^102 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  387|  3.10k|	/* 2^200 - 2^100 */ for (i = 2;i < 100;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|  3.03k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^200 - 2^100 */ for (i = 2;i < 100;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|  3.03k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (387:33): [True: 3.03k, False: 62]
  ------------------
  388|       |	/* 2^200 - 2^0 */ fe25519_mul(&t1,&t0,&z2_100_0);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  389|       |
  390|     62|	/* 2^201 - 2^1 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  391|       |	/* 2^202 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  392|  1.55k|	/* 2^250 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.48k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^250 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.48k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (392:32): [True: 1.48k, False: 62]
  ------------------
  393|       |	/* 2^250 - 2^0 */ fe25519_mul(&t0,&t1,&z2_50_0);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  394|       |
  395|     62|	/* 2^251 - 2^1 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  396|       |	/* 2^252 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  397|       |	/* 2^253 - 2^3 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  398|       |	/* 2^254 - 2^4 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  399|       |	/* 2^255 - 2^5 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     62|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  400|       |	/* 2^255 - 21 */ fe25519_mul(r,&t1,&z11);
  ------------------
  |  |   85|     62|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  401|     62|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_pack:
  227|     62|{
  228|     62|  int i;
  229|     62|  fe25519 y = *x;
  ------------------
  |  |   72|     62|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  230|     62|  fe25519_freeze(&y);
  ------------------
  |  |   73|     62|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  231|  2.04k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (231:11): [True: 1.98k, False: 62]
  ------------------
  232|  1.98k|    r[i] = y.v[i];
  233|     62|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_from64bytes:
  614|     62|{
  615|     62|  int i;
  616|     62|  crypto_uint32 t[64];
  617|  4.03k|  for(i=0;i<64;i++) t[i] = x[i];
  ------------------
  |  Branch (617:11): [True: 3.96k, False: 62]
  ------------------
  618|     62|  barrett_reduce(r, t);
  619|     62|}
ed25519.c:crypto_sign_ed25519_ref_double_scalarmult_vartime:
 1852|     62|{
 1853|     62|  ge25519_p1p1 tp1p1;
 1854|     62|  ge25519_p3 pre[16];
  ------------------
  |  |  771|     62|#define ge25519_p3 ge25519
  |  |  ------------------
  |  |  |  |  724|     62|#define ge25519                           crypto_sign_ed25519_ref_ge25519
  |  |  ------------------
  ------------------
 1855|     62|  unsigned char b[127];
 1856|     62|  int i;
 1857|       |
 1858|       |  /* precomputation                                                        s2 s1 */
 1859|     62|  setneutral(pre);                                                      /* 00 00 */
 1860|     62|  pre[1] = *p1;                                                         /* 00 01 */
 1861|     62|  dbl_p1p1(&tp1p1,(ge25519_p2 *)p1);      p1p1_to_p3( &pre[2], &tp1p1); /* 00 10 */
 1862|     62|  add_p1p1(&tp1p1,&pre[1], &pre[2]);      p1p1_to_p3( &pre[3], &tp1p1); /* 00 11 */
 1863|     62|  pre[4] = *p2;                                                         /* 01 00 */
 1864|     62|  add_p1p1(&tp1p1,&pre[1], &pre[4]);      p1p1_to_p3( &pre[5], &tp1p1); /* 01 01 */
 1865|     62|  add_p1p1(&tp1p1,&pre[2], &pre[4]);      p1p1_to_p3( &pre[6], &tp1p1); /* 01 10 */
 1866|     62|  add_p1p1(&tp1p1,&pre[3], &pre[4]);      p1p1_to_p3( &pre[7], &tp1p1); /* 01 11 */
 1867|     62|  dbl_p1p1(&tp1p1,(ge25519_p2 *)p2);      p1p1_to_p3( &pre[8], &tp1p1); /* 10 00 */
 1868|     62|  add_p1p1(&tp1p1,&pre[1], &pre[8]);      p1p1_to_p3( &pre[9], &tp1p1); /* 10 01 */
 1869|     62|  dbl_p1p1(&tp1p1,(ge25519_p2 *)&pre[5]); p1p1_to_p3(&pre[10], &tp1p1); /* 10 10 */
 1870|     62|  add_p1p1(&tp1p1,&pre[3], &pre[8]);      p1p1_to_p3(&pre[11], &tp1p1); /* 10 11 */
 1871|     62|  add_p1p1(&tp1p1,&pre[4], &pre[8]);      p1p1_to_p3(&pre[12], &tp1p1); /* 11 00 */
 1872|     62|  add_p1p1(&tp1p1,&pre[1],&pre[12]);      p1p1_to_p3(&pre[13], &tp1p1); /* 11 01 */
 1873|     62|  add_p1p1(&tp1p1,&pre[2],&pre[12]);      p1p1_to_p3(&pre[14], &tp1p1); /* 11 10 */
 1874|     62|  add_p1p1(&tp1p1,&pre[3],&pre[12]);      p1p1_to_p3(&pre[15], &tp1p1); /* 11 11 */
 1875|       |
 1876|     62|  sc25519_2interleave2(b,s1,s2);
  ------------------
  |  |  469|     62|#define sc25519_2interleave2     crypto_sign_ed25519_ref_sc25519_2interleave2
  ------------------
 1877|       |
 1878|       |  /* scalar multiplication */
 1879|     62|  *r = pre[b[126]];
 1880|  7.87k|  for(i=125;i>=0;i--)
  ------------------
  |  Branch (1880:13): [True: 7.81k, False: 62]
  ------------------
 1881|  7.81k|  {
 1882|  7.81k|    dbl_p1p1(&tp1p1, (ge25519_p2 *)r);
 1883|  7.81k|    p1p1_to_p2((ge25519_p2 *) r, &tp1p1);
 1884|  7.81k|    dbl_p1p1(&tp1p1, (ge25519_p2 *)r);
 1885|  7.81k|    if(b[i]!=0)
  ------------------
  |  Branch (1885:8): [True: 6.16k, False: 1.65k]
  ------------------
 1886|  6.16k|    {
 1887|  6.16k|      p1p1_to_p3(r, &tp1p1);
 1888|  6.16k|      add_p1p1(&tp1p1, r, &pre[b[i]]);
 1889|  6.16k|    }
 1890|  7.81k|    if(i != 0) p1p1_to_p2((ge25519_p2 *)r, &tp1p1);
  ------------------
  |  Branch (1890:8): [True: 7.75k, False: 62]
  ------------------
 1891|     62|    else p1p1_to_p3(r, &tp1p1);
 1892|  7.81k|  }
 1893|     62|}
ed25519.c:setneutral:
 1773|     62|{
 1774|     62|  fe25519_setzero(&r->x);
  ------------------
  |  |   80|     62|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
 1775|     62|  fe25519_setone(&r->y);
  ------------------
  |  |   79|     62|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1776|     62|  fe25519_setone(&r->z);
  ------------------
  |  |   79|     62|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1777|     62|  fe25519_setzero(&r->t);
  ------------------
  |  |   80|     62|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
 1778|     62|}
ed25519.c:dbl_p1p1:
 1717|  15.8k|{
 1718|  15.8k|  fe25519 a,b,c,d;
  ------------------
  |  |   72|  15.8k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1719|  15.8k|  fe25519_square(&a, &p->x);
  ------------------
  |  |   86|  15.8k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1720|  15.8k|  fe25519_square(&b, &p->y);
  ------------------
  |  |   86|  15.8k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1721|  15.8k|  fe25519_square(&c, &p->z);
  ------------------
  |  |   86|  15.8k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1722|  15.8k|  fe25519_add(&c, &c, &c);
  ------------------
  |  |   83|  15.8k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1723|  15.8k|  fe25519_neg(&d, &a);
  ------------------
  |  |   81|  15.8k|#define fe25519_neg          crypto_sign_ed25519_ref_fe25519_neg
  ------------------
 1724|       |
 1725|  15.8k|  fe25519_add(&r->x, &p->x, &p->y);
  ------------------
  |  |   83|  15.8k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1726|  15.8k|  fe25519_square(&r->x, &r->x);
  ------------------
  |  |   86|  15.8k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1727|  15.8k|  fe25519_sub(&r->x, &r->x, &a);
  ------------------
  |  |   84|  15.8k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1728|  15.8k|  fe25519_sub(&r->x, &r->x, &b);
  ------------------
  |  |   84|  15.8k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1729|  15.8k|  fe25519_add(&r->z, &d, &b);
  ------------------
  |  |   83|  15.8k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1730|  15.8k|  fe25519_sub(&r->t, &r->z, &c);
  ------------------
  |  |   84|  15.8k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1731|  15.8k|  fe25519_sub(&r->y, &d, &b);
  ------------------
  |  |   84|  15.8k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1732|  15.8k|}
ed25519.c:p1p1_to_p3:
 1667|  7.02k|{
 1668|  7.02k|  p1p1_to_p2((ge25519_p2 *)r, p);
 1669|  7.02k|  fe25519_mul(&r->t, &p->x, &p->y);
  ------------------
  |  |   85|  7.02k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1670|  7.02k|}
ed25519.c:add_p1p1:
 1696|  6.78k|{
 1697|  6.78k|  fe25519 a, b, c, d, t;
  ------------------
  |  |   72|  6.78k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1698|       |
 1699|  6.78k|  fe25519_sub(&a, &p->y, &p->x); /* A = (Y1-X1)*(Y2-X2) */
  ------------------
  |  |   84|  6.78k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1700|  6.78k|  fe25519_sub(&t, &q->y, &q->x);
  ------------------
  |  |   84|  6.78k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1701|  6.78k|  fe25519_mul(&a, &a, &t);
  ------------------
  |  |   85|  6.78k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1702|  6.78k|  fe25519_add(&b, &p->x, &p->y); /* B = (Y1+X1)*(Y2+X2) */
  ------------------
  |  |   83|  6.78k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1703|  6.78k|  fe25519_add(&t, &q->x, &q->y);
  ------------------
  |  |   83|  6.78k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1704|  6.78k|  fe25519_mul(&b, &b, &t);
  ------------------
  |  |   85|  6.78k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1705|  6.78k|  fe25519_mul(&c, &p->t, &q->t); /* C = T1*k*T2 */
  ------------------
  |  |   85|  6.78k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1706|  6.78k|  fe25519_mul(&c, &c, &ge25519_ec2d);
  ------------------
  |  |   85|  6.78k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1707|  6.78k|  fe25519_mul(&d, &p->z, &q->z); /* D = Z1*2*Z2 */
  ------------------
  |  |   85|  6.78k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1708|  6.78k|  fe25519_add(&d, &d, &d);
  ------------------
  |  |   83|  6.78k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1709|  6.78k|  fe25519_sub(&r->x, &b, &a); /* E = B-A */
  ------------------
  |  |   84|  6.78k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1710|  6.78k|  fe25519_sub(&r->t, &d, &c); /* F = D-C */
  ------------------
  |  |   84|  6.78k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1711|  6.78k|  fe25519_add(&r->z, &d, &c); /* G = D+C */
  ------------------
  |  |   83|  6.78k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1712|  6.78k|  fe25519_add(&r->y, &b, &a); /* H = B+A */
  ------------------
  |  |   83|  6.78k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1713|  6.78k|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_2interleave2:
  706|     62|{
  707|     62|  int i;
  708|  1.98k|  for(i=0;i<31;i++)
  ------------------
  |  Branch (708:11): [True: 1.92k, False: 62]
  ------------------
  709|  1.92k|  {
  710|  1.92k|    r[4*i]   = ( s1->v[i]       & 3) ^ (( s2->v[i]       & 3) << 2);
  711|  1.92k|    r[4*i+1] = ((s1->v[i] >> 2) & 3) ^ (((s2->v[i] >> 2) & 3) << 2);
  712|  1.92k|    r[4*i+2] = ((s1->v[i] >> 4) & 3) ^ (((s2->v[i] >> 4) & 3) << 2);
  713|  1.92k|    r[4*i+3] = ((s1->v[i] >> 6) & 3) ^ (((s2->v[i] >> 6) & 3) << 2);
  714|  1.92k|  }
  715|     62|  r[124] = ( s1->v[31]       & 3) ^ (( s2->v[31]       & 3) << 2);
  716|     62|  r[125] = ((s1->v[31] >> 2) & 3) ^ (((s2->v[31] >> 2) & 3) << 2);
  717|     62|  r[126] = ((s1->v[31] >> 4) & 3) ^ (((s2->v[31] >> 4) & 3) << 2);
  718|     62|}
ed25519.c:p1p1_to_p2:
 1660|  22.5k|{
 1661|  22.5k|  fe25519_mul(&r->x, &p->x, &p->t);
  ------------------
  |  |   85|  22.5k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1662|  22.5k|  fe25519_mul(&r->y, &p->y, &p->z);
  ------------------
  |  |   85|  22.5k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1663|  22.5k|  fe25519_mul(&r->z, &p->z, &p->t);
  ------------------
  |  |   85|  22.5k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1664|  22.5k|}
ed25519.c:crypto_verify_32:
   30|     62|{
   31|     62|  unsigned int differentbits = 0;
   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
   33|     62|  F(0)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   34|     62|  F(1)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   35|     62|  F(2)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   36|     62|  F(3)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   37|     62|  F(4)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   38|     62|  F(5)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   39|     62|  F(6)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   40|     62|  F(7)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   41|     62|  F(8)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   42|     62|  F(9)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   43|     62|  F(10)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   44|     62|  F(11)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   45|     62|  F(12)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   46|     62|  F(13)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   47|     62|  F(14)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   48|     62|  F(15)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   49|     62|  F(16)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   50|     62|  F(17)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   51|     62|  F(18)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   52|     62|  F(19)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   53|     62|  F(20)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   54|     62|  F(21)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   55|     62|  F(22)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   56|     62|  F(23)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   57|     62|  F(24)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   58|     62|  F(25)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   59|     62|  F(26)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   60|     62|  F(27)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   61|     62|  F(28)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   62|     62|  F(29)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   63|     62|  F(30)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   64|     62|  F(31)
  ------------------
  |  |   32|     62|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   65|     62|  return (1 & ((differentbits - 1) >> 8)) - 1;
   66|     62|}

crypto_hash_sha512:
   19|     62|{
   20|       |
   21|     62|	if (!EVP_Digest(in, inlen, out, NULL, EVP_sha512(), NULL))
  ------------------
  |  Branch (21:6): [True: 0, False: 62]
  ------------------
   22|      0|		return -1;
   23|     62|	return 0;
   24|     62|}

sshlog:
  429|     80|{
  430|     80|	va_list args;
  431|       |
  432|     80|	va_start(args, fmt);
  433|     80|	sshlogv(file, func, line, showfunc, level, suffix, fmt, args);
  434|     80|	va_end(args);
  435|     80|}
sshlogv:
  466|     80|{
  467|     80|	char tag[128], fmt2[MSGBUFSIZ + 128];
  468|     80|	int forced = 0;
  469|     80|	const char *cp;
  470|     80|	size_t i;
  471|       |
  472|     80|	snprintf(tag, sizeof(tag), "%.48s:%.48s():%d (pid=%ld)",
  473|     80|	    (cp = strrchr(file, '/')) == NULL ? file : cp + 1, func, line,
  ------------------
  |  Branch (473:6): [True: 80, False: 0]
  ------------------
  474|     80|	    (long)getpid());
  475|     80|	for (i = 0; i < nlog_verbose; i++) {
  ------------------
  |  Branch (475:14): [True: 0, False: 80]
  ------------------
  476|      0|		if (match_pattern_list(tag, log_verbose[i], 0) == 1) {
  ------------------
  |  Branch (476:7): [True: 0, False: 0]
  ------------------
  477|      0|			forced = 1;
  478|      0|			break;
  479|      0|		}
  480|      0|	}
  481|       |
  482|     80|	if (forced)
  ------------------
  |  Branch (482:6): [True: 0, False: 80]
  ------------------
  483|      0|		snprintf(fmt2, sizeof(fmt2), "%s: %s", tag, fmt);
  484|     80|	else if (showfunc)
  ------------------
  |  Branch (484:11): [True: 80, False: 0]
  ------------------
  485|     80|		snprintf(fmt2, sizeof(fmt2), "%s: %s", func, fmt);
  486|      0|	else
  487|      0|		strlcpy(fmt2, fmt, sizeof(fmt2));
  488|       |
  489|     80|	do_log(level, forced, suffix, fmt2, args);
  490|     80|}
log.c:do_log:
  339|     80|{
  340|       |#if defined(HAVE_OPENLOG_R) && defined(SYSLOG_DATA_INIT)
  341|       |	struct syslog_data sdata = SYSLOG_DATA_INIT;
  342|       |#endif
  343|     80|	char msgbuf[MSGBUFSIZ];
  344|     80|	char fmtbuf[MSGBUFSIZ];
  345|     80|	char *txt = NULL;
  346|     80|	int pri = LOG_INFO;
  347|     80|	int saved_errno = errno;
  348|     80|	log_handler_fn *tmp_handler;
  349|     80|	const char *progname = argv0 != NULL ? argv0 : __progname;
  ------------------
  |  Branch (349:25): [True: 0, False: 80]
  ------------------
  350|       |
  351|     80|	if (!force && level > log_level)
  ------------------
  |  Branch (351:6): [True: 80, False: 0]
  |  Branch (351:16): [True: 80, False: 0]
  ------------------
  352|     80|		return;
  353|       |
  354|      0|	switch (level) {
  355|      0|	case SYSLOG_LEVEL_FATAL:
  ------------------
  |  Branch (355:2): [True: 0, False: 0]
  ------------------
  356|      0|		if (!log_on_stderr)
  ------------------
  |  Branch (356:7): [True: 0, False: 0]
  ------------------
  357|      0|			txt = "fatal";
  358|      0|		pri = LOG_CRIT;
  359|      0|		break;
  360|      0|	case SYSLOG_LEVEL_ERROR:
  ------------------
  |  Branch (360:2): [True: 0, False: 0]
  ------------------
  361|      0|		if (!log_on_stderr)
  ------------------
  |  Branch (361:7): [True: 0, False: 0]
  ------------------
  362|      0|			txt = "error";
  363|      0|		pri = LOG_ERR;
  364|      0|		break;
  365|      0|	case SYSLOG_LEVEL_INFO:
  ------------------
  |  Branch (365:2): [True: 0, False: 0]
  ------------------
  366|      0|		pri = LOG_INFO;
  367|      0|		break;
  368|      0|	case SYSLOG_LEVEL_VERBOSE:
  ------------------
  |  Branch (368:2): [True: 0, False: 0]
  ------------------
  369|      0|		pri = LOG_INFO;
  370|      0|		break;
  371|      0|	case SYSLOG_LEVEL_DEBUG1:
  ------------------
  |  Branch (371:2): [True: 0, False: 0]
  ------------------
  372|      0|		txt = "debug1";
  373|      0|		pri = LOG_DEBUG;
  374|      0|		break;
  375|      0|	case SYSLOG_LEVEL_DEBUG2:
  ------------------
  |  Branch (375:2): [True: 0, False: 0]
  ------------------
  376|      0|		txt = "debug2";
  377|      0|		pri = LOG_DEBUG;
  378|      0|		break;
  379|      0|	case SYSLOG_LEVEL_DEBUG3:
  ------------------
  |  Branch (379:2): [True: 0, False: 0]
  ------------------
  380|      0|		txt = "debug3";
  381|      0|		pri = LOG_DEBUG;
  382|      0|		break;
  383|      0|	default:
  ------------------
  |  Branch (383:2): [True: 0, False: 0]
  ------------------
  384|      0|		txt = "internal error";
  385|      0|		pri = LOG_ERR;
  386|      0|		break;
  387|      0|	}
  388|      0|	if (txt != NULL && log_handler == NULL) {
  ------------------
  |  Branch (388:6): [True: 0, False: 0]
  |  Branch (388:21): [True: 0, False: 0]
  ------------------
  389|      0|		snprintf(fmtbuf, sizeof(fmtbuf), "%s: %s", txt, fmt);
  390|      0|		vsnprintf(msgbuf, sizeof(msgbuf), fmtbuf, args);
  391|      0|	} else {
  392|      0|		vsnprintf(msgbuf, sizeof(msgbuf), fmt, args);
  393|      0|	}
  394|      0|	if (suffix != NULL) {
  ------------------
  |  Branch (394:6): [True: 0, False: 0]
  ------------------
  395|      0|		snprintf(fmtbuf, sizeof(fmtbuf), "%s: %s", msgbuf, suffix);
  396|      0|		strlcpy(msgbuf, fmtbuf, sizeof(msgbuf));
  397|      0|	}
  398|      0|	strnvis(fmtbuf, msgbuf, sizeof(fmtbuf),
  399|      0|	    log_on_stderr ? LOG_STDERR_VIS : LOG_SYSLOG_VIS);
  ------------------
  |  |   69|      0|#define LOG_STDERR_VIS	(VIS_SAFE|VIS_OCTAL)
  |  |  ------------------
  |  |  |  |   60|      0|#define	VIS_SAFE	0x20	/* only encode "unsafe" characters */
  |  |  ------------------
  |  |               #define LOG_STDERR_VIS	(VIS_SAFE|VIS_OCTAL)
  |  |  ------------------
  |  |  |  |   49|      0|#define	VIS_OCTAL	0x01	/* use octal \ddd format */
  |  |  ------------------
  ------------------
              	    log_on_stderr ? LOG_STDERR_VIS : LOG_SYSLOG_VIS);
  ------------------
  |  |   68|      0|#define LOG_SYSLOG_VIS	(VIS_CSTYLE|VIS_NL|VIS_TAB|VIS_OCTAL)
  |  |  ------------------
  |  |  |  |   50|      0|#define	VIS_CSTYLE	0x02	/* use \[nrft0..] where appropriate */
  |  |  ------------------
  |  |               #define LOG_SYSLOG_VIS	(VIS_CSTYLE|VIS_NL|VIS_TAB|VIS_OCTAL)
  |  |  ------------------
  |  |  |  |   58|      0|#define	VIS_NL		0x10	/* also encode newline */
  |  |  ------------------
  |  |               #define LOG_SYSLOG_VIS	(VIS_CSTYLE|VIS_NL|VIS_TAB|VIS_OCTAL)
  |  |  ------------------
  |  |  |  |   57|      0|#define	VIS_TAB		0x08	/* also encode tab */
  |  |  ------------------
  |  |               #define LOG_SYSLOG_VIS	(VIS_CSTYLE|VIS_NL|VIS_TAB|VIS_OCTAL)
  |  |  ------------------
  |  |  |  |   49|      0|#define	VIS_OCTAL	0x01	/* use octal \ddd format */
  |  |  ------------------
  ------------------
  |  Branch (399:6): [True: 0, False: 0]
  ------------------
  400|      0|	if (log_handler != NULL) {
  ------------------
  |  Branch (400:6): [True: 0, False: 0]
  ------------------
  401|       |		/* Avoid recursion */
  402|      0|		tmp_handler = log_handler;
  403|      0|		log_handler = NULL;
  404|      0|		tmp_handler(level, force, fmtbuf, log_handler_ctx);
  405|      0|		log_handler = tmp_handler;
  406|      0|	} else if (log_on_stderr) {
  ------------------
  |  Branch (406:13): [True: 0, False: 0]
  ------------------
  407|      0|		snprintf(msgbuf, sizeof msgbuf, "%s%s%.*s\r\n",
  408|      0|		    (log_on_stderr > 1) ? progname : "",
  ------------------
  |  Branch (408:7): [True: 0, False: 0]
  ------------------
  409|      0|		    (log_on_stderr > 1) ? ": " : "",
  ------------------
  |  Branch (409:7): [True: 0, False: 0]
  ------------------
  410|      0|		    (int)sizeof msgbuf - 3, fmtbuf);
  411|      0|		(void)write(log_stderr_fd, msgbuf, strlen(msgbuf));
  412|      0|	} else {
  413|       |#if defined(HAVE_OPENLOG_R) && defined(SYSLOG_DATA_INIT)
  414|       |		openlog_r(progname, LOG_PID, log_facility, &sdata);
  415|       |		syslog_r(pri, &sdata, "%.500s", fmtbuf);
  416|       |		closelog_r(&sdata);
  417|       |#else
  418|      0|		openlog(progname, LOG_PID, log_facility);
  419|      0|		syslog(pri, "%.500s", fmtbuf);
  420|      0|		closelog();
  421|      0|#endif
  422|      0|	}
  423|      0|	errno = saved_errno;
  424|      0|}

__b64_ntop:
  134|    121|{
  135|    121|	size_t datalength = 0;
  136|    121|	u_char input[3];
  137|    121|	u_char output[4];
  138|    121|	u_int i;
  139|       |
  140|   497k|	while (2 < srclength) {
  ------------------
  |  Branch (140:9): [True: 497k, False: 121]
  ------------------
  141|   497k|		input[0] = *src++;
  142|   497k|		input[1] = *src++;
  143|   497k|		input[2] = *src++;
  144|   497k|		srclength -= 3;
  145|       |
  146|   497k|		output[0] = input[0] >> 2;
  147|   497k|		output[1] = ((input[0] & 0x03) << 4) + (input[1] >> 4);
  148|   497k|		output[2] = ((input[1] & 0x0f) << 2) + (input[2] >> 6);
  149|   497k|		output[3] = input[2] & 0x3f;
  150|       |
  151|   497k|		if (datalength + 4 > targsize)
  ------------------
  |  Branch (151:7): [True: 0, False: 497k]
  ------------------
  152|      0|			return (-1);
  153|   497k|		target[datalength++] = Base64[output[0]];
  154|   497k|		target[datalength++] = Base64[output[1]];
  155|   497k|		target[datalength++] = Base64[output[2]];
  156|   497k|		target[datalength++] = Base64[output[3]];
  157|   497k|	}
  158|       |    
  159|       |	/* Now we worry about padding. */
  160|    121|	if (0 != srclength) {
  ------------------
  |  Branch (160:6): [True: 92, False: 29]
  ------------------
  161|       |		/* Get what's left. */
  162|     92|		input[0] = input[1] = input[2] = '\0';
  163|    225|		for (i = 0; i < srclength; i++)
  ------------------
  |  Branch (163:15): [True: 133, False: 92]
  ------------------
  164|    133|			input[i] = *src++;
  165|       |	
  166|     92|		output[0] = input[0] >> 2;
  167|     92|		output[1] = ((input[0] & 0x03) << 4) + (input[1] >> 4);
  168|     92|		output[2] = ((input[1] & 0x0f) << 2) + (input[2] >> 6);
  169|       |
  170|     92|		if (datalength + 4 > targsize)
  ------------------
  |  Branch (170:7): [True: 0, False: 92]
  ------------------
  171|      0|			return (-1);
  172|     92|		target[datalength++] = Base64[output[0]];
  173|     92|		target[datalength++] = Base64[output[1]];
  174|     92|		if (srclength == 1)
  ------------------
  |  Branch (174:7): [True: 51, False: 41]
  ------------------
  175|     51|			target[datalength++] = Pad64;
  176|     41|		else
  177|     41|			target[datalength++] = Base64[output[2]];
  178|     92|		target[datalength++] = Pad64;
  179|     92|	}
  180|    121|	if (datalength >= targsize)
  ------------------
  |  Branch (180:6): [True: 0, False: 121]
  ------------------
  181|      0|		return (-1);
  182|    121|	target[datalength] = '\0';	/* Returned value doesn't count \0. */
  183|    121|	return (datalength);
  184|    121|}

freezero:
   26|  54.3k|{
   27|  54.3k|	if (ptr == NULL)
  ------------------
  |  Branch (27:6): [True: 18.3k, False: 36.0k]
  ------------------
   28|  18.3k|		return;
   29|  36.0k|	explicit_bzero(ptr, sz);
   30|  36.0k|	free(ptr);
   31|  36.0k|}

recallocarray:
   39|  5.21k|{
   40|  5.21k|	size_t oldsize, newsize;
   41|  5.21k|	void *newptr;
   42|       |
   43|  5.21k|	if (ptr == NULL)
  ------------------
  |  Branch (43:6): [True: 198, False: 5.01k]
  ------------------
   44|    198|		return calloc(newnmemb, size);
   45|       |
   46|  5.01k|	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  10.0k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
              	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  5.01k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
  |  Branch (46:7): [True: 0, False: 5.01k]
  |  Branch (46:38): [True: 0, False: 5.01k]
  ------------------
   47|  5.01k|	    newnmemb > 0 && SIZE_MAX / newnmemb < size) {
  ------------------
  |  Branch (47:6): [True: 0, False: 0]
  |  Branch (47:22): [True: 0, False: 0]
  ------------------
   48|      0|		errno = ENOMEM;
   49|      0|		return NULL;
   50|      0|	}
   51|  5.01k|	newsize = newnmemb * size;
   52|       |
   53|  5.01k|	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  10.0k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
              	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  5.01k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
  |  Branch (53:7): [True: 0, False: 5.01k]
  |  Branch (53:38): [True: 0, False: 5.01k]
  ------------------
   54|  5.01k|	    oldnmemb > 0 && SIZE_MAX / oldnmemb < size) {
  ------------------
  |  Branch (54:6): [True: 0, False: 0]
  |  Branch (54:22): [True: 0, False: 0]
  ------------------
   55|      0|		errno = EINVAL;
   56|      0|		return NULL;
   57|      0|	}
   58|  5.01k|	oldsize = oldnmemb * size;
   59|       |	
   60|       |	/*
   61|       |	 * Don't bother too much if we're shrinking just a bit,
   62|       |	 * we do not shrink for series of small steps, oh well.
   63|       |	 */
   64|  5.01k|	if (newsize <= oldsize) {
  ------------------
  |  Branch (64:6): [True: 58, False: 4.95k]
  ------------------
   65|     58|		size_t d = oldsize - newsize;
   66|       |
   67|     58|		if (d < oldsize / 2 && d < (size_t)getpagesize()) {
  ------------------
  |  Branch (67:7): [True: 0, False: 58]
  |  Branch (67:26): [True: 0, False: 0]
  ------------------
   68|      0|			memset((char *)ptr + newsize, 0, d);
   69|      0|			return ptr;
   70|      0|		}
   71|     58|	}
   72|       |
   73|  5.01k|	newptr = malloc(newsize);
   74|  5.01k|	if (newptr == NULL)
  ------------------
  |  Branch (74:6): [True: 0, False: 5.01k]
  ------------------
   75|      0|		return NULL;
   76|       |
   77|  5.01k|	if (newsize > oldsize) {
  ------------------
  |  Branch (77:6): [True: 4.95k, False: 58]
  ------------------
   78|  4.95k|		memcpy(newptr, ptr, oldsize);
   79|  4.95k|		memset((char *)newptr + oldsize, 0, newsize - oldsize);
   80|  4.95k|	} else
   81|     58|		memcpy(newptr, ptr, newsize);
   82|       |
   83|  5.01k|	explicit_bzero(ptr, oldsize);
   84|  5.01k|	free(ptr);
   85|       |
   86|  5.01k|	return newptr;
   87|  5.01k|}

timingsafe_bcmp:
   25|     14|{
   26|     14|	const unsigned char *p1 = b1, *p2 = b2;
   27|     14|	int ret = 0;
   28|       |
   29|  6.39k|	for (; n > 0; n--)
  ------------------
  |  Branch (29:9): [True: 6.38k, False: 14]
  ------------------
   30|  6.38k|		ret |= *p1++ ^ *p2++;
   31|     14|	return (ret != 0);
   32|     14|}

LLVMFuzzerTestOneInput:
   11|  4.13k|{
   12|  4.13k|	struct sshkey *k = NULL;
   13|  4.13k|	struct sshbuf *b = sshbuf_from(data, size);
   14|  4.13k|	int r = sshkey_private_deserialize(b, &k);
   15|  4.13k|	if (r == 0) sshkey_free(k);
  ------------------
  |  Branch (15:6): [True: 48, False: 4.08k]
  ------------------
   16|  4.13k|	sshbuf_free(b);
   17|  4.13k|	return 0;
   18|  4.13k|}

ssh-dss.c:ssh_dss_alloc:
   63|  2.02k|{
   64|  2.02k|	if ((k->dsa = DSA_new()) == NULL)
  ------------------
  |  Branch (64:6): [True: 0, False: 2.02k]
  ------------------
   65|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   66|  2.02k|	return 0;
   67|  2.02k|}
ssh-dss.c:ssh_dss_cleanup:
   71|  2.02k|{
   72|  2.02k|	DSA_free(k->dsa);
   73|  2.02k|	k->dsa = NULL;
   74|  2.02k|}
ssh-dss.c:ssh_dss_deserialize_public:
  203|  1.98k|{
  204|  1.98k|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  1.98k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  205|  1.98k|	BIGNUM *dsa_p = NULL, *dsa_q = NULL, *dsa_g = NULL, *dsa_pub_key = NULL;
  206|       |
  207|  1.98k|	if (sshbuf_get_bignum2(b, &dsa_p) != 0 ||
  ------------------
  |  Branch (207:6): [True: 40, False: 1.94k]
  ------------------
  208|  1.98k|	    sshbuf_get_bignum2(b, &dsa_q) != 0 ||
  ------------------
  |  Branch (208:6): [True: 20, False: 1.92k]
  ------------------
  209|  1.98k|	    sshbuf_get_bignum2(b, &dsa_g) != 0 ||
  ------------------
  |  Branch (209:6): [True: 5, False: 1.92k]
  ------------------
  210|  1.98k|	    sshbuf_get_bignum2(b, &dsa_pub_key) != 0) {
  ------------------
  |  Branch (210:6): [True: 9, False: 1.91k]
  ------------------
  211|     74|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     74|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  212|     74|		goto out;
  213|     74|	}
  214|  1.91k|	if (!DSA_set0_pqg(key->dsa, dsa_p, dsa_q, dsa_g)) {
  ------------------
  |  Branch (214:6): [True: 0, False: 1.91k]
  ------------------
  215|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  216|      0|		goto out;
  217|      0|	}
  218|  1.91k|	dsa_p = dsa_q = dsa_g = NULL; /* transferred */
  219|  1.91k|	if (!DSA_set0_key(key->dsa, dsa_pub_key, NULL)) {
  ------------------
  |  Branch (219:6): [True: 0, False: 1.91k]
  ------------------
  220|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  221|      0|		goto out;
  222|      0|	}
  223|  1.91k|	dsa_pub_key = NULL; /* transferred */
  224|       |#ifdef DEBUG_PK
  225|       |	DSA_print_fp(stderr, key->dsa, 8);
  226|       |#endif
  227|       |	/* success */
  228|  1.91k|	ret = 0;
  229|  1.98k| out:
  230|  1.98k|	BN_clear_free(dsa_p);
  231|  1.98k|	BN_clear_free(dsa_q);
  232|  1.98k|	BN_clear_free(dsa_g);
  233|  1.98k|	BN_clear_free(dsa_pub_key);
  234|  1.98k|	return ret;
  235|  1.91k|}
ssh-dss.c:ssh_dss_deserialize_private:
  240|     74|{
  241|     74|	int r;
  242|     74|	BIGNUM *dsa_priv_key = NULL;
  243|       |
  244|     74|	if (!sshkey_is_cert(key)) {
  ------------------
  |  Branch (244:6): [True: 73, False: 1]
  ------------------
  245|     73|		if ((r = ssh_dss_deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (245:7): [True: 60, False: 13]
  ------------------
  246|     60|			return r;
  247|     73|	}
  248|       |
  249|     14|	if ((r = sshbuf_get_bignum2(b, &dsa_priv_key)) != 0)
  ------------------
  |  Branch (249:6): [True: 11, False: 3]
  ------------------
  250|     11|		return r;
  251|      3|	if (!DSA_set0_key(key->dsa, NULL, dsa_priv_key)) {
  ------------------
  |  Branch (251:6): [True: 0, False: 3]
  ------------------
  252|      0|		BN_clear_free(dsa_priv_key);
  253|      0|		return SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  254|      0|	}
  255|      3|	return 0;
  256|      3|}
ssh-dss.c:ssh_dss_verify:
  333|    102|{
  334|    102|	DSA_SIG *dsig = NULL;
  335|    102|	BIGNUM *sig_r = NULL, *sig_s = NULL;
  336|    102|	u_char digest[SSH_DIGEST_MAX_LENGTH], *sigblob = NULL;
  337|    102|	size_t len, hlen = ssh_digest_bytes(SSH_DIGEST_SHA1);
  ------------------
  |  |   26|    102|#define SSH_DIGEST_SHA1		1
  ------------------
  338|    102|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    102|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  339|    102|	struct sshbuf *b = NULL;
  340|    102|	char *ktype = NULL;
  341|       |
  342|    102|	if (key == NULL || key->dsa == NULL ||
  ------------------
  |  Branch (342:6): [True: 0, False: 102]
  |  Branch (342:21): [True: 0, False: 102]
  ------------------
  343|    102|	    sshkey_type_plain(key->type) != KEY_DSA ||
  ------------------
  |  Branch (343:6): [True: 0, False: 102]
  ------------------
  344|    102|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (344:6): [True: 0, False: 102]
  |  Branch (344:21): [True: 0, False: 102]
  ------------------
  345|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  346|    102|	if (hlen == 0)
  ------------------
  |  Branch (346:6): [True: 0, False: 102]
  ------------------
  347|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  348|       |
  349|       |	/* fetch signature */
  350|    102|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (350:6): [True: 0, False: 102]
  ------------------
  351|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  352|    102|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0 ||
  ------------------
  |  Branch (352:6): [True: 13, False: 89]
  ------------------
  353|    102|	    sshbuf_get_string(b, &sigblob, &len) != 0) {
  ------------------
  |  Branch (353:6): [True: 2, False: 87]
  ------------------
  354|     15|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     15|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  355|     15|		goto out;
  356|     15|	}
  357|     87|	if (strcmp("ssh-dss", ktype) != 0) {
  ------------------
  |  Branch (357:6): [True: 63, False: 24]
  ------------------
  358|     63|		ret = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|     63|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  359|     63|		goto out;
  360|     63|	}
  361|     24|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (361:6): [True: 13, False: 11]
  ------------------
  362|     13|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|     13|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  363|     13|		goto out;
  364|     13|	}
  365|       |
  366|     11|	if (len != SIGBLOB_LEN) {
  ------------------
  |  |   48|     11|#define SIGBLOB_LEN	(2*INTBLOB_LEN)
  |  |  ------------------
  |  |  |  |   47|     11|#define INTBLOB_LEN	20
  |  |  ------------------
  ------------------
  |  Branch (366:6): [True: 10, False: 1]
  ------------------
  367|     10|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     10|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  368|     10|		goto out;
  369|     10|	}
  370|       |
  371|       |	/* parse signature */
  372|      1|	if ((dsig = DSA_SIG_new()) == NULL ||
  ------------------
  |  Branch (372:6): [True: 0, False: 1]
  ------------------
  373|      1|	    (sig_r = BN_new()) == NULL ||
  ------------------
  |  Branch (373:6): [True: 0, False: 1]
  ------------------
  374|      1|	    (sig_s = BN_new()) == NULL) {
  ------------------
  |  Branch (374:6): [True: 0, False: 1]
  ------------------
  375|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  376|      0|		goto out;
  377|      0|	}
  378|      1|	if ((BN_bin2bn(sigblob, INTBLOB_LEN, sig_r) == NULL) ||
  ------------------
  |  |   47|      1|#define INTBLOB_LEN	20
  ------------------
  |  Branch (378:6): [True: 0, False: 1]
  ------------------
  379|      1|	    (BN_bin2bn(sigblob + INTBLOB_LEN, INTBLOB_LEN, sig_s) == NULL)) {
  ------------------
  |  |   47|      1|#define INTBLOB_LEN	20
  ------------------
              	    (BN_bin2bn(sigblob + INTBLOB_LEN, INTBLOB_LEN, sig_s) == NULL)) {
  ------------------
  |  |   47|      1|#define INTBLOB_LEN	20
  ------------------
  |  Branch (379:6): [True: 0, False: 1]
  ------------------
  380|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  381|      0|		goto out;
  382|      0|	}
  383|      1|	if (!DSA_SIG_set0(dsig, sig_r, sig_s)) {
  ------------------
  |  Branch (383:6): [True: 0, False: 1]
  ------------------
  384|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  385|      0|		goto out;
  386|      0|	}
  387|      1|	sig_r = sig_s = NULL; /* transferred */
  388|       |
  389|       |	/* sha1 the data */
  390|      1|	if ((ret = ssh_digest_memory(SSH_DIGEST_SHA1, data, dlen,
  ------------------
  |  |   26|      1|#define SSH_DIGEST_SHA1		1
  ------------------
  |  Branch (390:6): [True: 0, False: 1]
  ------------------
  391|      1|	    digest, sizeof(digest))) != 0)
  392|      0|		goto out;
  393|       |
  394|      1|	switch (DSA_do_verify(digest, hlen, dsig, key->dsa)) {
  395|      0|	case 1:
  ------------------
  |  Branch (395:2): [True: 0, False: 1]
  ------------------
  396|      0|		ret = 0;
  397|      0|		break;
  398|      0|	case 0:
  ------------------
  |  Branch (398:2): [True: 0, False: 1]
  ------------------
  399|      0|		ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  400|      0|		goto out;
  401|      1|	default:
  ------------------
  |  Branch (401:2): [True: 1, False: 0]
  ------------------
  402|      1|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      1|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  403|      1|		goto out;
  404|      1|	}
  405|       |
  406|    102| out:
  407|    102|	explicit_bzero(digest, sizeof(digest));
  408|    102|	DSA_SIG_free(dsig);
  409|    102|	BN_clear_free(sig_r);
  410|    102|	BN_clear_free(sig_s);
  411|    102|	sshbuf_free(b);
  412|    102|	free(ktype);
  413|    102|	if (sigblob != NULL)
  ------------------
  |  Branch (413:6): [True: 87, False: 15]
  ------------------
  414|     87|		freezero(sigblob, len);
  415|    102|	return ret;
  416|      1|}

ssh-ecdsa-sk.c:ssh_ecdsa_sk_cleanup:
   69|    467|{
   70|    467|	sshkey_sk_cleanup(k);
   71|    467|	sshkey_ecdsa_funcs.cleanup(k);
   72|    467|}
ssh-ecdsa-sk.c:ssh_ecdsa_sk_deserialize_public:
  130|    456|{
  131|    456|	int r;
  132|       |
  133|    456|	if ((r = sshkey_ecdsa_funcs.deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (133:6): [True: 7, False: 449]
  ------------------
  134|      7|		return r;
  135|    449|	if ((r = sshkey_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (135:6): [True: 1, False: 448]
  ------------------
  136|      1|		return r;
  137|    448|	return 0;
  138|    449|}
ssh-ecdsa-sk.c:ssh_ecdsa_sk_deserialize_private:
  143|     11|{
  144|     11|	int r;
  145|       |
  146|     11|	if (!sshkey_is_cert(key)) {
  ------------------
  |  Branch (146:6): [True: 11, False: 0]
  ------------------
  147|     11|		if ((r = sshkey_ecdsa_funcs.deserialize_public(ktype,
  ------------------
  |  Branch (147:7): [True: 6, False: 5]
  ------------------
  148|     11|		    b, key)) != 0)
  149|      6|			return r;
  150|     11|	}
  151|      5|	if ((r = sshkey_private_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (151:6): [True: 4, False: 1]
  ------------------
  152|      4|		return r;
  153|       |
  154|      1|	return 0;
  155|      5|}
ssh-ecdsa-sk.c:ssh_ecdsa_sk_verify:
  238|    443|{
  239|    443|	ECDSA_SIG *esig = NULL;
  240|    443|	BIGNUM *sig_r = NULL, *sig_s = NULL;
  241|    443|	u_char sig_flags;
  242|    443|	u_char msghash[32], apphash[32], sighash[32];
  243|    443|	u_int sig_counter;
  244|    443|	int is_webauthn = 0, ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    443|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  245|    443|	struct sshbuf *b = NULL, *sigbuf = NULL, *original_signed = NULL;
  246|    443|	struct sshbuf *webauthn_wrapper = NULL, *webauthn_exts = NULL;
  247|    443|	char *ktype = NULL, *webauthn_origin = NULL;
  248|    443|	struct sshkey_sig_details *details = NULL;
  249|       |#ifdef DEBUG_SK
  250|       |	char *tmp = NULL;
  251|       |#endif
  252|       |
  253|    443|	if (detailsp != NULL)
  ------------------
  |  Branch (253:6): [True: 0, False: 443]
  ------------------
  254|      0|		*detailsp = NULL;
  255|    443|	if (key == NULL || key->ecdsa == NULL ||
  ------------------
  |  Branch (255:6): [True: 0, False: 443]
  |  Branch (255:21): [True: 0, False: 443]
  ------------------
  256|    443|	    sshkey_type_plain(key->type) != KEY_ECDSA_SK ||
  ------------------
  |  Branch (256:6): [True: 0, False: 443]
  ------------------
  257|    443|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (257:6): [True: 0, False: 443]
  |  Branch (257:21): [True: 0, False: 443]
  ------------------
  258|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  259|       |
  260|    443|	if (key->ecdsa_nid != NID_X9_62_prime256v1)
  ------------------
  |  Branch (260:6): [True: 0, False: 443]
  ------------------
  261|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  262|       |
  263|       |	/* fetch signature */
  264|    443|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (264:6): [True: 0, False: 443]
  ------------------
  265|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  266|    443|	if ((details = calloc(1, sizeof(*details))) == NULL) {
  ------------------
  |  Branch (266:6): [True: 0, False: 443]
  ------------------
  267|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  268|      0|		goto out;
  269|      0|	}
  270|    443|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0) {
  ------------------
  |  Branch (270:6): [True: 18, False: 425]
  ------------------
  271|     18|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     18|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  272|     18|		goto out;
  273|     18|	}
  274|    425|	if (strcmp(ktype, "webauthn-sk-ecdsa-sha2-nistp256@openssh.com") == 0)
  ------------------
  |  Branch (274:6): [True: 142, False: 283]
  ------------------
  275|    142|		is_webauthn = 1;
  276|    283|	else if (strcmp(ktype, "sk-ecdsa-sha2-nistp256@openssh.com") != 0) {
  ------------------
  |  Branch (276:11): [True: 267, False: 16]
  ------------------
  277|    267|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|    267|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  278|    267|		goto out;
  279|    267|	}
  280|    158|	if (sshbuf_froms(b, &sigbuf) != 0 ||
  ------------------
  |  Branch (280:6): [True: 3, False: 155]
  ------------------
  281|    158|	    sshbuf_get_u8(b, &sig_flags) != 0 ||
  ------------------
  |  Branch (281:6): [True: 1, False: 154]
  ------------------
  282|    158|	    sshbuf_get_u32(b, &sig_counter) != 0) {
  ------------------
  |  Branch (282:6): [True: 1, False: 153]
  ------------------
  283|      5|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      5|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  284|      5|		goto out;
  285|      5|	}
  286|    153|	if (is_webauthn) {
  ------------------
  |  Branch (286:6): [True: 141, False: 12]
  ------------------
  287|    141|		if (sshbuf_get_cstring(b, &webauthn_origin, NULL) != 0 ||
  ------------------
  |  Branch (287:7): [True: 2, False: 139]
  ------------------
  288|    141|		    sshbuf_froms(b, &webauthn_wrapper) != 0 ||
  ------------------
  |  Branch (288:7): [True: 2, False: 137]
  ------------------
  289|    141|		    sshbuf_froms(b, &webauthn_exts) != 0) {
  ------------------
  |  Branch (289:7): [True: 3, False: 134]
  ------------------
  290|      7|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      7|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  291|      7|			goto out;
  292|      7|		}
  293|    141|	}
  294|    146|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (294:6): [True: 14, False: 132]
  ------------------
  295|     14|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|     14|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  296|     14|		goto out;
  297|     14|	}
  298|       |
  299|       |	/* parse signature */
  300|    132|	if (sshbuf_get_bignum2(sigbuf, &sig_r) != 0 ||
  ------------------
  |  Branch (300:6): [True: 2, False: 130]
  ------------------
  301|    132|	    sshbuf_get_bignum2(sigbuf, &sig_s) != 0) {
  ------------------
  |  Branch (301:6): [True: 1, False: 129]
  ------------------
  302|      3|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      3|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  303|      3|		goto out;
  304|      3|	}
  305|    129|	if (sshbuf_len(sigbuf) != 0) {
  ------------------
  |  Branch (305:6): [True: 1, False: 128]
  ------------------
  306|      1|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      1|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  307|      1|		goto out;
  308|      1|	}
  309|       |
  310|       |#ifdef DEBUG_SK
  311|       |	fprintf(stderr, "%s: data: (len %zu)\n", __func__, datalen);
  312|       |	/* sshbuf_dump_data(data, datalen, stderr); */
  313|       |	fprintf(stderr, "%s: sig_r: %s\n", __func__, (tmp = BN_bn2hex(sig_r)));
  314|       |	free(tmp);
  315|       |	fprintf(stderr, "%s: sig_s: %s\n", __func__, (tmp = BN_bn2hex(sig_s)));
  316|       |	free(tmp);
  317|       |	fprintf(stderr, "%s: sig_flags = 0x%02x, sig_counter = %u\n",
  318|       |	    __func__, sig_flags, sig_counter);
  319|       |	if (is_webauthn) {
  320|       |		fprintf(stderr, "%s: webauthn origin: %s\n", __func__,
  321|       |		    webauthn_origin);
  322|       |		fprintf(stderr, "%s: webauthn_wrapper:\n", __func__);
  323|       |		sshbuf_dump(webauthn_wrapper, stderr);
  324|       |	}
  325|       |#endif
  326|    128|	if ((esig = ECDSA_SIG_new()) == NULL) {
  ------------------
  |  Branch (326:6): [True: 0, False: 128]
  ------------------
  327|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  328|      0|		goto out;
  329|      0|	}
  330|    128|	if (!ECDSA_SIG_set0(esig, sig_r, sig_s)) {
  ------------------
  |  Branch (330:6): [True: 0, False: 128]
  ------------------
  331|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  332|      0|		goto out;
  333|      0|	}
  334|    128|	sig_r = sig_s = NULL; /* transferred */
  335|       |
  336|       |	/* Reconstruct data that was supposedly signed */
  337|    128|	if ((original_signed = sshbuf_new()) == NULL) {
  ------------------
  |  Branch (337:6): [True: 0, False: 128]
  ------------------
  338|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  339|      0|		goto out;
  340|      0|	}
  341|    128|	if (is_webauthn) {
  ------------------
  |  Branch (341:6): [True: 127, False: 1]
  ------------------
  342|    127|		if ((ret = webauthn_check_prepare_hash(data, dlen,
  ------------------
  |  Branch (342:7): [True: 127, False: 0]
  ------------------
  343|    127|		    webauthn_origin, webauthn_wrapper, sig_flags, webauthn_exts,
  344|    127|		    msghash, sizeof(msghash))) != 0)
  345|    127|			goto out;
  346|    127|	} else if ((ret = ssh_digest_memory(SSH_DIGEST_SHA256, data, dlen,
  ------------------
  |  |   27|      1|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (346:13): [True: 0, False: 1]
  ------------------
  347|      1|	    msghash, sizeof(msghash))) != 0)
  348|      0|		goto out;
  349|       |	/* Application value is hashed before signature */
  350|      1|	if ((ret = ssh_digest_memory(SSH_DIGEST_SHA256, key->sk_application,
  ------------------
  |  |   27|      1|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (350:6): [True: 0, False: 1]
  ------------------
  351|      1|	    strlen(key->sk_application), apphash, sizeof(apphash))) != 0)
  352|      0|		goto out;
  353|       |#ifdef DEBUG_SK
  354|       |	fprintf(stderr, "%s: hashed application:\n", __func__);
  355|       |	sshbuf_dump_data(apphash, sizeof(apphash), stderr);
  356|       |	fprintf(stderr, "%s: hashed message:\n", __func__);
  357|       |	sshbuf_dump_data(msghash, sizeof(msghash), stderr);
  358|       |#endif
  359|      1|	if ((ret = sshbuf_put(original_signed,
  ------------------
  |  Branch (359:6): [True: 0, False: 1]
  ------------------
  360|      1|	    apphash, sizeof(apphash))) != 0 ||
  361|      1|	    (ret = sshbuf_put_u8(original_signed, sig_flags)) != 0 ||
  ------------------
  |  Branch (361:6): [True: 0, False: 1]
  ------------------
  362|      1|	    (ret = sshbuf_put_u32(original_signed, sig_counter)) != 0 ||
  ------------------
  |  Branch (362:6): [True: 0, False: 1]
  ------------------
  363|      1|	    (ret = sshbuf_putb(original_signed, webauthn_exts)) != 0 ||
  ------------------
  |  Branch (363:6): [True: 0, False: 1]
  ------------------
  364|      1|	    (ret = sshbuf_put(original_signed, msghash, sizeof(msghash))) != 0)
  ------------------
  |  Branch (364:6): [True: 0, False: 1]
  ------------------
  365|      0|		goto out;
  366|       |	/* Signature is over H(original_signed) */
  367|      1|	if ((ret = ssh_digest_buffer(SSH_DIGEST_SHA256, original_signed,
  ------------------
  |  |   27|      1|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (367:6): [True: 0, False: 1]
  ------------------
  368|      1|	    sighash, sizeof(sighash))) != 0)
  369|      0|		goto out;
  370|      1|	details->sk_counter = sig_counter;
  371|      1|	details->sk_flags = sig_flags;
  372|       |#ifdef DEBUG_SK
  373|       |	fprintf(stderr, "%s: signed buf:\n", __func__);
  374|       |	sshbuf_dump(original_signed, stderr);
  375|       |	fprintf(stderr, "%s: signed hash:\n", __func__);
  376|       |	sshbuf_dump_data(sighash, sizeof(sighash), stderr);
  377|       |#endif
  378|       |
  379|       |	/* Verify it */
  380|      1|	switch (ECDSA_do_verify(sighash, sizeof(sighash), esig, key->ecdsa)) {
  381|      0|	case 1:
  ------------------
  |  Branch (381:2): [True: 0, False: 1]
  ------------------
  382|      0|		ret = 0;
  383|      0|		break;
  384|      1|	case 0:
  ------------------
  |  Branch (384:2): [True: 1, False: 0]
  ------------------
  385|      1|		ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      1|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  386|      1|		goto out;
  387|      0|	default:
  ------------------
  |  Branch (387:2): [True: 0, False: 1]
  ------------------
  388|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  389|      0|		goto out;
  390|      1|	}
  391|       |	/* success */
  392|      0|	if (detailsp != NULL) {
  ------------------
  |  Branch (392:6): [True: 0, False: 0]
  ------------------
  393|      0|		*detailsp = details;
  394|      0|		details = NULL;
  395|      0|	}
  396|    443| out:
  397|    443|	explicit_bzero(&sig_flags, sizeof(sig_flags));
  398|    443|	explicit_bzero(&sig_counter, sizeof(sig_counter));
  399|    443|	explicit_bzero(msghash, sizeof(msghash));
  400|    443|	explicit_bzero(sighash, sizeof(msghash));
  401|    443|	explicit_bzero(apphash, sizeof(apphash));
  402|    443|	sshkey_sig_details_free(details);
  403|    443|	sshbuf_free(webauthn_wrapper);
  404|    443|	sshbuf_free(webauthn_exts);
  405|    443|	free(webauthn_origin);
  406|    443|	sshbuf_free(original_signed);
  407|    443|	sshbuf_free(sigbuf);
  408|    443|	sshbuf_free(b);
  409|    443|	ECDSA_SIG_free(esig);
  410|    443|	BN_clear_free(sig_r);
  411|    443|	BN_clear_free(sig_s);
  412|    443|	free(ktype);
  413|    443|	return ret;
  414|      0|}
ssh-ecdsa-sk.c:webauthn_check_prepare_hash:
  174|    127|{
  175|    127|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    127|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  176|    127|	struct sshbuf *chall = NULL, *m = NULL;
  177|       |
  178|    127|	if ((m = sshbuf_new()) == NULL ||
  ------------------
  |  Branch (178:6): [True: 0, False: 127]
  ------------------
  179|    127|	    (chall = sshbuf_from(data, datalen)) == NULL) {
  ------------------
  |  Branch (179:6): [True: 0, False: 127]
  ------------------
  180|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  181|      0|		goto out;
  182|      0|	}
  183|       |	/*
  184|       |	 * Ensure origin contains no quote character and that the flags are
  185|       |	 * consistent with what we received
  186|       |	 */
  187|    127|	if (strchr(origin, '\"') != NULL ||
  ------------------
  |  Branch (187:6): [True: 1, False: 126]
  ------------------
  188|    127|	    (flags & 0x40) != 0 /* AD */ ||
  ------------------
  |  Branch (188:6): [True: 2, False: 124]
  ------------------
  189|    127|	    ((flags & 0x80) == 0 /* ED */) != (sshbuf_len(extensions) == 0)) {
  ------------------
  |  Branch (189:6): [True: 3, False: 121]
  ------------------
  190|      6|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      6|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  191|      6|		goto out;
  192|      6|	}
  193|       |
  194|       |	/*
  195|       |	 * Prepare the preamble to clientData that we expect, poking the
  196|       |	 * challenge and origin into their canonical positions in the
  197|       |	 * structure. The crossOrigin flag and any additional extension
  198|       |	 * fields present are ignored.
  199|       |	 */
  200|    121|#define WEBAUTHN_0	"{\"type\":\"webauthn.get\",\"challenge\":\""
  201|    121|#define WEBAUTHN_1	"\",\"origin\":\""
  202|    121|#define WEBAUTHN_2	"\""
  203|    121|	if ((r = sshbuf_put(m, WEBAUTHN_0, sizeof(WEBAUTHN_0) - 1)) != 0 ||
  ------------------
  |  |  200|    121|#define WEBAUTHN_0	"{\"type\":\"webauthn.get\",\"challenge\":\""
  ------------------
              	if ((r = sshbuf_put(m, WEBAUTHN_0, sizeof(WEBAUTHN_0) - 1)) != 0 ||
  ------------------
  |  |  200|    121|#define WEBAUTHN_0	"{\"type\":\"webauthn.get\",\"challenge\":\""
  ------------------
  |  Branch (203:6): [True: 0, False: 121]
  ------------------
  204|    121|	    (r = sshbuf_dtourlb64(chall, m, 0)) != 0 ||
  ------------------
  |  Branch (204:6): [True: 0, False: 121]
  ------------------
  205|    121|	    (r = sshbuf_put(m, WEBAUTHN_1, sizeof(WEBAUTHN_1) - 1)) != 0 ||
  ------------------
  |  |  201|    121|#define WEBAUTHN_1	"\",\"origin\":\""
  ------------------
              	    (r = sshbuf_put(m, WEBAUTHN_1, sizeof(WEBAUTHN_1) - 1)) != 0 ||
  ------------------
  |  |  201|    121|#define WEBAUTHN_1	"\",\"origin\":\""
  ------------------
  |  Branch (205:6): [True: 0, False: 121]
  ------------------
  206|    121|	    (r = sshbuf_put(m, origin, strlen(origin))) != 0 ||
  ------------------
  |  Branch (206:6): [True: 0, False: 121]
  ------------------
  207|    121|	    (r = sshbuf_put(m, WEBAUTHN_2, sizeof(WEBAUTHN_2) - 1)) != 0)
  ------------------
  |  |  202|    121|#define WEBAUTHN_2	"\""
  ------------------
              	    (r = sshbuf_put(m, WEBAUTHN_2, sizeof(WEBAUTHN_2) - 1)) != 0)
  ------------------
  |  |  202|    121|#define WEBAUTHN_2	"\""
  ------------------
  |  Branch (207:6): [True: 0, False: 121]
  ------------------
  208|      0|		goto out;
  209|       |#ifdef DEBUG_SK
  210|       |	fprintf(stderr, "%s: received origin: %s\n", __func__, origin);
  211|       |	fprintf(stderr, "%s: received clientData:\n", __func__);
  212|       |	sshbuf_dump(wrapper, stderr);
  213|       |	fprintf(stderr, "%s: expected clientData premable:\n", __func__);
  214|       |	sshbuf_dump(m, stderr);
  215|       |#endif
  216|       |	/* Check that the supplied clientData has the preamble we expect */
  217|    121|	if ((r = sshbuf_cmp(wrapper, 0, sshbuf_ptr(m), sshbuf_len(m))) != 0)
  ------------------
  |  Branch (217:6): [True: 121, False: 0]
  ------------------
  218|    121|		goto out;
  219|       |
  220|       |	/* Prepare hash of clientData */
  221|      0|	if ((r = ssh_digest_buffer(SSH_DIGEST_SHA256, wrapper,
  ------------------
  |  |   27|      0|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (221:6): [True: 0, False: 0]
  ------------------
  222|      0|	    msghash, msghashlen)) != 0)
  223|      0|		goto out;
  224|       |
  225|       |	/* success */
  226|      0|	r = 0;
  227|    127| out:
  228|    127|	sshbuf_free(chall);
  229|    127|	sshbuf_free(m);
  230|    127|	return r;
  231|      0|}

ssh-ecdsa.c:ssh_ecdsa_cleanup:
   67|    945|{
   68|    945|	EC_KEY_free(k->ecdsa);
   69|    945|	k->ecdsa = NULL;
   70|    945|}
ssh-ecdsa.c:ssh_ecdsa_deserialize_public:
  159|    945|{
  160|    945|	int r;
  161|    945|	char *curve = NULL;
  162|       |
  163|    945|	if ((key->ecdsa_nid = sshkey_ecdsa_nid_from_name(ktype)) == -1)
  ------------------
  |  Branch (163:6): [True: 14, False: 931]
  ------------------
  164|     14|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|     14|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  165|    931|	if ((r = sshbuf_get_cstring(b, &curve, NULL)) != 0)
  ------------------
  |  Branch (165:6): [True: 13, False: 918]
  ------------------
  166|     13|		goto out;
  167|    918|	if (key->ecdsa_nid != sshkey_curve_name_to_nid(curve)) {
  ------------------
  |  Branch (167:6): [True: 118, False: 800]
  ------------------
  168|    118|		r = SSH_ERR_EC_CURVE_MISMATCH;
  ------------------
  |  |   39|    118|#define SSH_ERR_EC_CURVE_MISMATCH		-15
  ------------------
  169|    118|		goto out;
  170|    118|	}
  171|    800|	EC_KEY_free(key->ecdsa);
  172|    800|	key->ecdsa = NULL;
  173|    800|	if ((key->ecdsa = EC_KEY_new_by_curve_name(key->ecdsa_nid)) == NULL) {
  ------------------
  |  Branch (173:6): [True: 0, False: 800]
  ------------------
  174|      0|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  175|      0|		goto out;
  176|      0|	}
  177|    800|	if ((r = sshbuf_get_eckey(b, key->ecdsa)) != 0)
  ------------------
  |  Branch (177:6): [True: 128, False: 672]
  ------------------
  178|    128|		goto out;
  179|    672|	if (sshkey_ec_validate_public(EC_KEY_get0_group(key->ecdsa),
  ------------------
  |  Branch (179:6): [True: 0, False: 672]
  ------------------
  180|    672|	    EC_KEY_get0_public_key(key->ecdsa)) != 0) {
  181|      0|		r = SSH_ERR_KEY_INVALID_EC_VALUE;
  ------------------
  |  |   44|      0|#define SSH_ERR_KEY_INVALID_EC_VALUE		-20
  ------------------
  182|      0|		goto out;
  183|      0|	}
  184|       |	/* success */
  185|    672|	r = 0;
  186|       |#ifdef DEBUG_PK
  187|       |	sshkey_dump_ec_point(EC_KEY_get0_group(key->ecdsa),
  188|       |	    EC_KEY_get0_public_key(key->ecdsa));
  189|       |#endif
  190|    931| out:
  191|    931|	free(curve);
  192|    931|	if (r != 0) {
  ------------------
  |  Branch (192:6): [True: 259, False: 672]
  ------------------
  193|    259|		EC_KEY_free(key->ecdsa);
  194|    259|		key->ecdsa = NULL;
  195|    259|	}
  196|    931|	return r;
  197|    672|}
ssh-ecdsa.c:ssh_ecdsa_deserialize_private:
  202|    304|{
  203|    304|	int r;
  204|    304|	BIGNUM *exponent = NULL;
  205|       |
  206|    304|	if (!sshkey_is_cert(key)) {
  ------------------
  |  Branch (206:6): [True: 304, False: 0]
  ------------------
  207|    304|		if ((r = ssh_ecdsa_deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (207:7): [True: 253, False: 51]
  ------------------
  208|    253|			return r;
  209|    304|	}
  210|     51|	if ((r = sshbuf_get_bignum2(b, &exponent)) != 0)
  ------------------
  |  Branch (210:6): [True: 6, False: 45]
  ------------------
  211|      6|		goto out;
  212|     45|	if (EC_KEY_set_private_key(key->ecdsa, exponent) != 1) {
  ------------------
  |  Branch (212:6): [True: 0, False: 45]
  ------------------
  213|      0|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  214|      0|		goto out;
  215|      0|	}
  216|     45|	if ((r = sshkey_ec_validate_private(key->ecdsa)) != 0)
  ------------------
  |  Branch (216:6): [True: 32, False: 13]
  ------------------
  217|     32|		goto out;
  218|       |	/* success */
  219|     13|	r = 0;
  220|     51| out:
  221|     51|	BN_clear_free(exponent);
  222|     51|	return r;
  223|     13|}
ssh-ecdsa.c:ssh_ecdsa_verify:
  295|    166|{
  296|    166|	ECDSA_SIG *esig = NULL;
  297|    166|	BIGNUM *sig_r = NULL, *sig_s = NULL;
  298|    166|	int hash_alg;
  299|    166|	u_char digest[SSH_DIGEST_MAX_LENGTH];
  300|    166|	size_t hlen;
  301|    166|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    166|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  302|    166|	struct sshbuf *b = NULL, *sigbuf = NULL;
  303|    166|	char *ktype = NULL;
  304|       |
  305|    166|	if (key == NULL || key->ecdsa == NULL ||
  ------------------
  |  Branch (305:6): [True: 0, False: 166]
  |  Branch (305:21): [True: 0, False: 166]
  ------------------
  306|    166|	    sshkey_type_plain(key->type) != KEY_ECDSA ||
  ------------------
  |  Branch (306:6): [True: 0, False: 166]
  ------------------
  307|    166|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (307:6): [True: 0, False: 166]
  |  Branch (307:21): [True: 0, False: 166]
  ------------------
  308|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  309|       |
  310|    166|	if ((hash_alg = sshkey_ec_nid_to_hash_alg(key->ecdsa_nid)) == -1 ||
  ------------------
  |  Branch (310:6): [True: 0, False: 166]
  ------------------
  311|    166|	    (hlen = ssh_digest_bytes(hash_alg)) == 0)
  ------------------
  |  Branch (311:6): [True: 0, False: 166]
  ------------------
  312|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  313|       |
  314|       |	/* fetch signature */
  315|    166|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (315:6): [True: 0, False: 166]
  ------------------
  316|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  317|    166|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0 ||
  ------------------
  |  Branch (317:6): [True: 11, False: 155]
  ------------------
  318|    166|	    sshbuf_froms(b, &sigbuf) != 0) {
  ------------------
  |  Branch (318:6): [True: 1, False: 154]
  ------------------
  319|     12|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     12|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  320|     12|		goto out;
  321|     12|	}
  322|    154|	if (strcmp(sshkey_ssh_name_plain(key), ktype) != 0) {
  ------------------
  |  Branch (322:6): [True: 140, False: 14]
  ------------------
  323|    140|		ret = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    140|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  324|    140|		goto out;
  325|    140|	}
  326|     14|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (326:6): [True: 8, False: 6]
  ------------------
  327|      8|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      8|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  328|      8|		goto out;
  329|      8|	}
  330|       |
  331|       |	/* parse signature */
  332|      6|	if (sshbuf_get_bignum2(sigbuf, &sig_r) != 0 ||
  ------------------
  |  Branch (332:6): [True: 2, False: 4]
  ------------------
  333|      6|	    sshbuf_get_bignum2(sigbuf, &sig_s) != 0) {
  ------------------
  |  Branch (333:6): [True: 2, False: 2]
  ------------------
  334|      4|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      4|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  335|      4|		goto out;
  336|      4|	}
  337|      2|	if ((esig = ECDSA_SIG_new()) == NULL) {
  ------------------
  |  Branch (337:6): [True: 0, False: 2]
  ------------------
  338|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  339|      0|		goto out;
  340|      0|	}
  341|      2|	if (!ECDSA_SIG_set0(esig, sig_r, sig_s)) {
  ------------------
  |  Branch (341:6): [True: 0, False: 2]
  ------------------
  342|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  343|      0|		goto out;
  344|      0|	}
  345|      2|	sig_r = sig_s = NULL; /* transferred */
  346|       |
  347|      2|	if (sshbuf_len(sigbuf) != 0) {
  ------------------
  |  Branch (347:6): [True: 1, False: 1]
  ------------------
  348|      1|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      1|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  349|      1|		goto out;
  350|      1|	}
  351|      1|	if ((ret = ssh_digest_memory(hash_alg, data, dlen,
  ------------------
  |  Branch (351:6): [True: 0, False: 1]
  ------------------
  352|      1|	    digest, sizeof(digest))) != 0)
  353|      0|		goto out;
  354|       |
  355|      1|	switch (ECDSA_do_verify(digest, hlen, esig, key->ecdsa)) {
  356|      0|	case 1:
  ------------------
  |  Branch (356:2): [True: 0, False: 1]
  ------------------
  357|      0|		ret = 0;
  358|      0|		break;
  359|      1|	case 0:
  ------------------
  |  Branch (359:2): [True: 1, False: 0]
  ------------------
  360|      1|		ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      1|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  361|      1|		goto out;
  362|      0|	default:
  ------------------
  |  Branch (362:2): [True: 0, False: 1]
  ------------------
  363|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  364|      0|		goto out;
  365|      1|	}
  366|       |
  367|    166| out:
  368|    166|	explicit_bzero(digest, sizeof(digest));
  369|    166|	sshbuf_free(sigbuf);
  370|    166|	sshbuf_free(b);
  371|    166|	ECDSA_SIG_free(esig);
  372|    166|	BN_clear_free(sig_r);
  373|    166|	BN_clear_free(sig_s);
  374|    166|	free(ktype);
  375|    166|	return ret;
  376|      1|}

ssh-ed25519-sk.c:ssh_ed25519_sk_cleanup:
   43|    342|{
   44|    342|	sshkey_sk_cleanup(k);
   45|    342|	sshkey_ed25519_funcs.cleanup(k);
   46|    342|}
ssh-ed25519-sk.c:ssh_ed25519_sk_deserialize_public:
  101|    180|{
  102|    180|	int r;
  103|       |
  104|    180|	if ((r = sshkey_ed25519_funcs.deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (104:6): [True: 4, False: 176]
  ------------------
  105|      4|		return r;
  106|    176|	if ((r = sshkey_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (106:6): [True: 1, False: 175]
  ------------------
  107|      1|		return r;
  108|    175|	return 0;
  109|    176|}
ssh-ed25519-sk.c:ssh_ed25519_sk_deserialize_private:
  114|    161|{
  115|    161|	int r;
  116|       |
  117|    161|	if ((r = sshkey_ed25519_funcs.deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (117:6): [True: 26, False: 135]
  ------------------
  118|     26|		return r;
  119|    135|	if ((r = sshkey_private_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (119:6): [True: 112, False: 23]
  ------------------
  120|    112|		return r;
  121|     23|	return 0;
  122|    135|}
ssh-ed25519-sk.c:ssh_ed25519_sk_verify:
  129|    167|{
  130|    167|	struct sshbuf *b = NULL;
  131|    167|	struct sshbuf *encoded = NULL;
  132|    167|	char *ktype = NULL;
  133|    167|	const u_char *sigblob;
  134|    167|	const u_char *sm;
  135|    167|	u_char *m = NULL;
  136|    167|	u_char apphash[32];
  137|    167|	u_char msghash[32];
  138|    167|	u_char sig_flags;
  139|    167|	u_int sig_counter;
  140|    167|	size_t len;
  141|    167|	unsigned long long smlen = 0, mlen = 0;
  142|    167|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    167|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  143|    167|	int ret;
  144|    167|	struct sshkey_sig_details *details = NULL;
  145|       |
  146|    167|	if (detailsp != NULL)
  ------------------
  |  Branch (146:6): [True: 0, False: 167]
  ------------------
  147|      0|		*detailsp = NULL;
  148|       |
  149|    167|	if (key == NULL ||
  ------------------
  |  Branch (149:6): [True: 0, False: 167]
  ------------------
  150|    167|	    sshkey_type_plain(key->type) != KEY_ED25519_SK ||
  ------------------
  |  Branch (150:6): [True: 0, False: 167]
  ------------------
  151|    167|	    key->ed25519_pk == NULL ||
  ------------------
  |  Branch (151:6): [True: 0, False: 167]
  ------------------
  152|    167|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (152:6): [True: 0, False: 167]
  |  Branch (152:21): [True: 0, False: 167]
  ------------------
  153|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  154|       |
  155|    167|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (155:6): [True: 0, False: 167]
  ------------------
  156|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  157|    167|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0 ||
  ------------------
  |  Branch (157:6): [True: 14, False: 153]
  ------------------
  158|    167|	    sshbuf_get_string_direct(b, &sigblob, &len) != 0 ||
  ------------------
  |  Branch (158:6): [True: 2, False: 151]
  ------------------
  159|    167|	    sshbuf_get_u8(b, &sig_flags) != 0 ||
  ------------------
  |  Branch (159:6): [True: 1, False: 150]
  ------------------
  160|    167|	    sshbuf_get_u32(b, &sig_counter) != 0) {
  ------------------
  |  Branch (160:6): [True: 1, False: 149]
  ------------------
  161|     18|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     18|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  162|     18|		goto out;
  163|     18|	}
  164|       |#ifdef DEBUG_SK
  165|       |	fprintf(stderr, "%s: data:\n", __func__);
  166|       |	/* sshbuf_dump_data(data, datalen, stderr); */
  167|       |	fprintf(stderr, "%s: sigblob:\n", __func__);
  168|       |	sshbuf_dump_data(sigblob, len, stderr);
  169|       |	fprintf(stderr, "%s: sig_flags = 0x%02x, sig_counter = %u\n",
  170|       |	    __func__, sig_flags, sig_counter);
  171|       |#endif
  172|    149|	if (strcmp(sshkey_ssh_name_plain(key), ktype) != 0) {
  ------------------
  |  Branch (172:6): [True: 132, False: 17]
  ------------------
  173|    132|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    132|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  174|    132|		goto out;
  175|    132|	}
  176|     17|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (176:6): [True: 2, False: 15]
  ------------------
  177|      2|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      2|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  178|      2|		goto out;
  179|      2|	}
  180|     15|	if (len > crypto_sign_ed25519_BYTES) {
  ------------------
  |  |   37|     15|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (180:6): [True: 5, False: 10]
  ------------------
  181|      5|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      5|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  182|      5|		goto out;
  183|      5|	}
  184|     10|	if (ssh_digest_memory(SSH_DIGEST_SHA256, key->sk_application,
  ------------------
  |  |   27|     10|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (184:6): [True: 0, False: 10]
  ------------------
  185|     10|	    strlen(key->sk_application), apphash, sizeof(apphash)) != 0 ||
  186|     10|	    ssh_digest_memory(SSH_DIGEST_SHA256, data, dlen,
  ------------------
  |  |   27|     10|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (186:6): [True: 0, False: 10]
  ------------------
  187|     10|	    msghash, sizeof(msghash)) != 0) {
  188|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  189|      0|		goto out;
  190|      0|	}
  191|       |#ifdef DEBUG_SK
  192|       |	fprintf(stderr, "%s: hashed application:\n", __func__);
  193|       |	sshbuf_dump_data(apphash, sizeof(apphash), stderr);
  194|       |	fprintf(stderr, "%s: hashed message:\n", __func__);
  195|       |	sshbuf_dump_data(msghash, sizeof(msghash), stderr);
  196|       |#endif
  197|     10|	if ((details = calloc(1, sizeof(*details))) == NULL) {
  ------------------
  |  Branch (197:6): [True: 0, False: 10]
  ------------------
  198|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  199|      0|		goto out;
  200|      0|	}
  201|     10|	details->sk_counter = sig_counter;
  202|     10|	details->sk_flags = sig_flags;
  203|     10|	if ((encoded = sshbuf_new()) == NULL) {
  ------------------
  |  Branch (203:6): [True: 0, False: 10]
  ------------------
  204|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  205|      0|		goto out;
  206|      0|	}
  207|     10|	if (sshbuf_put(encoded, sigblob, len) != 0 ||
  ------------------
  |  Branch (207:6): [True: 0, False: 10]
  ------------------
  208|     10|	    sshbuf_put(encoded, apphash, sizeof(apphash)) != 0 ||
  ------------------
  |  Branch (208:6): [True: 0, False: 10]
  ------------------
  209|     10|	    sshbuf_put_u8(encoded, sig_flags) != 0 ||
  ------------------
  |  Branch (209:6): [True: 0, False: 10]
  ------------------
  210|     10|	    sshbuf_put_u32(encoded, sig_counter) != 0 ||
  ------------------
  |  Branch (210:6): [True: 0, False: 10]
  ------------------
  211|     10|	    sshbuf_put(encoded, msghash, sizeof(msghash)) != 0) {
  ------------------
  |  Branch (211:6): [True: 0, False: 10]
  ------------------
  212|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  213|      0|		goto out;
  214|      0|	}
  215|       |#ifdef DEBUG_SK
  216|       |	fprintf(stderr, "%s: signed buf:\n", __func__);
  217|       |	sshbuf_dump(encoded, stderr);
  218|       |#endif
  219|     10|	sm = sshbuf_ptr(encoded);
  220|     10|	smlen = sshbuf_len(encoded);
  221|     10|	mlen = smlen;
  222|     10|	if ((m = malloc(smlen)) == NULL) {
  ------------------
  |  Branch (222:6): [True: 0, False: 10]
  ------------------
  223|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  224|      0|		goto out;
  225|      0|	}
  226|     10|	if ((ret = crypto_sign_ed25519_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (226:6): [True: 10, False: 0]
  ------------------
  227|     10|	    key->ed25519_pk)) != 0) {
  228|     10|		debug2_f("crypto_sign_ed25519_open failed: %d", ret);
  ------------------
  |  |  101|     10|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  229|     10|	}
  230|     10|	if (ret != 0 || mlen != smlen - len) {
  ------------------
  |  Branch (230:6): [True: 10, False: 0]
  |  Branch (230:18): [True: 0, False: 0]
  ------------------
  231|     10|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|     10|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  232|     10|		goto out;
  233|     10|	}
  234|       |	/* XXX compare 'm' and 'sm + len' ? */
  235|       |	/* success */
  236|      0|	r = 0;
  237|      0|	if (detailsp != NULL) {
  ------------------
  |  Branch (237:6): [True: 0, False: 0]
  ------------------
  238|      0|		*detailsp = details;
  239|      0|		details = NULL;
  240|      0|	}
  241|    167| out:
  242|    167|	if (m != NULL)
  ------------------
  |  Branch (242:6): [True: 10, False: 157]
  ------------------
  243|     10|		freezero(m, smlen); /* NB mlen may be invalid if r != 0 */
  244|    167|	sshkey_sig_details_free(details);
  245|    167|	sshbuf_free(b);
  246|    167|	sshbuf_free(encoded);
  247|    167|	free(ktype);
  248|    167|	return r;
  249|      0|}

ssh-ed25519.c:ssh_ed25519_cleanup:
   37|    705|{
   38|    705|	freezero(k->ed25519_pk, ED25519_PK_SZ);
  ------------------
  |  |  159|    705|#define	ED25519_PK_SZ	crypto_sign_ed25519_PUBLICKEYBYTES
  |  |  ------------------
  |  |  |  |   36|    705|#define crypto_sign_ed25519_PUBLICKEYBYTES 32U
  |  |  ------------------
  ------------------
   39|    705|	freezero(k->ed25519_sk, ED25519_SK_SZ);
  ------------------
  |  |  158|    705|#define	ED25519_SK_SZ	crypto_sign_ed25519_SECRETKEYBYTES
  |  |  ------------------
  |  |  |  |   35|    705|#define crypto_sign_ed25519_SECRETKEYBYTES 64U
  |  |  ------------------
  ------------------
   40|    705|	k->ed25519_pk = NULL;
   41|    705|	k->ed25519_sk = NULL;
   42|    705|}
ssh-ed25519.c:ssh_ed25519_deserialize_public:
  105|    703|{
  106|    703|	u_char *pk = NULL;
  107|    703|	size_t len = 0;
  108|    703|	int r;
  109|       |
  110|    703|	if ((r = sshbuf_get_string(b, &pk, &len)) != 0)
  ------------------
  |  Branch (110:6): [True: 66, False: 637]
  ------------------
  111|     66|		return r;
  112|    637|	if (len != ED25519_PK_SZ) {
  ------------------
  |  |  159|    637|#define	ED25519_PK_SZ	crypto_sign_ed25519_PUBLICKEYBYTES
  |  |  ------------------
  |  |  |  |   36|    637|#define crypto_sign_ed25519_PUBLICKEYBYTES 32U
  |  |  ------------------
  ------------------
  |  Branch (112:6): [True: 80, False: 557]
  ------------------
  113|     80|		freezero(pk, len);
  114|     80|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     80|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  115|     80|	}
  116|    557|	key->ed25519_pk = pk;
  117|    557|	return 0;
  118|    637|}
ssh-ed25519.c:ssh_ed25519_deserialize_private:
  123|    141|{
  124|    141|	int r;
  125|    141|	size_t sklen = 0;
  126|    141|	u_char *ed25519_sk = NULL;
  127|       |
  128|    141|	if ((r = ssh_ed25519_deserialize_public(NULL, b, key)) != 0)
  ------------------
  |  Branch (128:6): [True: 114, False: 27]
  ------------------
  129|    114|		goto out;
  130|     27|	if ((r = sshbuf_get_string(b, &ed25519_sk, &sklen)) != 0)
  ------------------
  |  Branch (130:6): [True: 2, False: 25]
  ------------------
  131|      2|		goto out;
  132|     25|	if (sklen != ED25519_SK_SZ) {
  ------------------
  |  |  158|     25|#define	ED25519_SK_SZ	crypto_sign_ed25519_SECRETKEYBYTES
  |  |  ------------------
  |  |  |  |   35|     25|#define crypto_sign_ed25519_SECRETKEYBYTES 64U
  |  |  ------------------
  ------------------
  |  Branch (132:6): [True: 24, False: 1]
  ------------------
  133|     24|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     24|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  134|     24|		goto out;
  135|     24|	}
  136|      1|	key->ed25519_sk = ed25519_sk;
  137|      1|	ed25519_sk = NULL; /* transferred */
  138|       |	/* success */
  139|      1|	r = 0;
  140|    141| out:
  141|    141|	freezero(ed25519_sk, sklen);
  142|    141|	return r;
  143|      1|}
ssh-ed25519.c:ssh_ed25519_verify:
  209|    211|{
  210|    211|	struct sshbuf *b = NULL;
  211|    211|	char *ktype = NULL;
  212|    211|	const u_char *sigblob;
  213|    211|	u_char *sm = NULL, *m = NULL;
  214|    211|	size_t len;
  215|    211|	unsigned long long smlen = 0, mlen = 0;
  216|    211|	int r, ret;
  217|       |
  218|    211|	if (key == NULL ||
  ------------------
  |  Branch (218:6): [True: 0, False: 211]
  ------------------
  219|    211|	    sshkey_type_plain(key->type) != KEY_ED25519 ||
  ------------------
  |  Branch (219:6): [True: 0, False: 211]
  ------------------
  220|    211|	    key->ed25519_pk == NULL ||
  ------------------
  |  Branch (220:6): [True: 0, False: 211]
  ------------------
  221|    211|	    dlen >= INT_MAX - crypto_sign_ed25519_BYTES ||
  ------------------
  |  |   37|    422|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (221:6): [True: 0, False: 211]
  ------------------
  222|    211|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (222:6): [True: 0, False: 211]
  |  Branch (222:21): [True: 0, False: 211]
  ------------------
  223|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  224|       |
  225|    211|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (225:6): [True: 0, False: 211]
  ------------------
  226|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  227|    211|	if ((r = sshbuf_get_cstring(b, &ktype, NULL)) != 0 ||
  ------------------
  |  Branch (227:6): [True: 15, False: 196]
  ------------------
  228|    211|	    (r = sshbuf_get_string_direct(b, &sigblob, &len)) != 0)
  ------------------
  |  Branch (228:6): [True: 5, False: 191]
  ------------------
  229|     20|		goto out;
  230|    191|	if (strcmp("ssh-ed25519", ktype) != 0) {
  ------------------
  |  Branch (230:6): [True: 99, False: 92]
  ------------------
  231|     99|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|     99|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  232|     99|		goto out;
  233|     99|	}
  234|     92|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (234:6): [True: 7, False: 85]
  ------------------
  235|      7|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      7|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  236|      7|		goto out;
  237|      7|	}
  238|     85|	if (len > crypto_sign_ed25519_BYTES) {
  ------------------
  |  |   37|     85|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (238:6): [True: 3, False: 82]
  ------------------
  239|      3|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      3|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  240|      3|		goto out;
  241|      3|	}
  242|     82|	if (dlen >= SIZE_MAX - len) {
  ------------------
  |  Branch (242:6): [True: 0, False: 82]
  ------------------
  243|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  244|      0|		goto out;
  245|      0|	}
  246|     82|	smlen = len + dlen;
  247|     82|	mlen = smlen;
  248|     82|	if ((sm = malloc(smlen)) == NULL || (m = malloc(mlen)) == NULL) {
  ------------------
  |  Branch (248:6): [True: 0, False: 82]
  |  Branch (248:38): [True: 0, False: 82]
  ------------------
  249|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  250|      0|		goto out;
  251|      0|	}
  252|     82|	memcpy(sm, sigblob, len);
  253|     82|	memcpy(sm+len, data, dlen);
  254|     82|	if ((ret = crypto_sign_ed25519_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (254:6): [True: 70, False: 12]
  ------------------
  255|     82|	    key->ed25519_pk)) != 0) {
  256|     70|		debug2_f("crypto_sign_ed25519_open failed: %d", ret);
  ------------------
  |  |  101|     70|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  257|     70|	}
  258|     82|	if (ret != 0 || mlen != dlen) {
  ------------------
  |  Branch (258:6): [True: 70, False: 12]
  |  Branch (258:18): [True: 11, False: 1]
  ------------------
  259|     81|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|     81|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  260|     81|		goto out;
  261|     81|	}
  262|       |	/* XXX compare 'm' and 'data' ? */
  263|       |	/* success */
  264|      1|	r = 0;
  265|    211| out:
  266|    211|	if (sm != NULL)
  ------------------
  |  Branch (266:6): [True: 82, False: 129]
  ------------------
  267|     82|		freezero(sm, smlen);
  268|    211|	if (m != NULL)
  ------------------
  |  Branch (268:6): [True: 82, False: 129]
  ------------------
  269|     82|		freezero(m, smlen); /* NB mlen may be invalid if r != 0 */
  270|    211|	sshbuf_free(b);
  271|    211|	free(ktype);
  272|    211|	return r;
  273|      1|}

ssh_rsa_complete_crt_parameters:
  337|      8|{
  338|      8|	const BIGNUM *rsa_p, *rsa_q, *rsa_d;
  339|      8|	BIGNUM *aux = NULL, *d_consttime = NULL;
  340|      8|	BIGNUM *rsa_dmq1 = NULL, *rsa_dmp1 = NULL, *rsa_iqmp = NULL;
  341|      8|	BN_CTX *ctx = NULL;
  342|      8|	int r;
  343|       |
  344|      8|	if (key == NULL || key->rsa == NULL ||
  ------------------
  |  Branch (344:6): [True: 0, False: 8]
  |  Branch (344:21): [True: 0, False: 8]
  ------------------
  345|      8|	    sshkey_type_plain(key->type) != KEY_RSA)
  ------------------
  |  Branch (345:6): [True: 0, False: 8]
  ------------------
  346|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  347|       |
  348|      8|	RSA_get0_key(key->rsa, NULL, NULL, &rsa_d);
  349|      8|	RSA_get0_factors(key->rsa, &rsa_p, &rsa_q);
  350|       |
  351|      8|	if ((ctx = BN_CTX_new()) == NULL)
  ------------------
  |  Branch (351:6): [True: 0, False: 8]
  ------------------
  352|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  353|      8|	if ((aux = BN_new()) == NULL ||
  ------------------
  |  Branch (353:6): [True: 0, False: 8]
  ------------------
  354|      8|	    (rsa_dmq1 = BN_new()) == NULL ||
  ------------------
  |  Branch (354:6): [True: 0, False: 8]
  ------------------
  355|      8|	    (rsa_dmp1 = BN_new()) == NULL)
  ------------------
  |  Branch (355:6): [True: 0, False: 8]
  ------------------
  356|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  357|      8|	if ((d_consttime = BN_dup(rsa_d)) == NULL ||
  ------------------
  |  Branch (357:6): [True: 0, False: 8]
  ------------------
  358|      8|	    (rsa_iqmp = BN_dup(iqmp)) == NULL) {
  ------------------
  |  Branch (358:6): [True: 0, False: 8]
  ------------------
  359|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  360|      0|		goto out;
  361|      0|	}
  362|      8|	BN_set_flags(aux, BN_FLG_CONSTTIME);
  363|      8|	BN_set_flags(d_consttime, BN_FLG_CONSTTIME);
  364|       |
  365|      8|	if ((BN_sub(aux, rsa_q, BN_value_one()) == 0) ||
  ------------------
  |  Branch (365:6): [True: 0, False: 8]
  ------------------
  366|      8|	    (BN_mod(rsa_dmq1, d_consttime, aux, ctx) == 0) ||
  ------------------
  |  Branch (366:6): [True: 1, False: 7]
  ------------------
  367|      8|	    (BN_sub(aux, rsa_p, BN_value_one()) == 0) ||
  ------------------
  |  Branch (367:6): [True: 0, False: 7]
  ------------------
  368|      8|	    (BN_mod(rsa_dmp1, d_consttime, aux, ctx) == 0)) {
  ------------------
  |  Branch (368:6): [True: 1, False: 6]
  ------------------
  369|      2|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      2|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  370|      2|		goto out;
  371|      2|	}
  372|      6|	if (!RSA_set0_crt_params(key->rsa, rsa_dmp1, rsa_dmq1, rsa_iqmp)) {
  ------------------
  |  Branch (372:6): [True: 0, False: 6]
  ------------------
  373|      0|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  374|      0|		goto out;
  375|      0|	}
  376|      6|	rsa_dmp1 = rsa_dmq1 = rsa_iqmp = NULL; /* transferred */
  377|       |	/* success */
  378|      6|	r = 0;
  379|      8| out:
  380|      8|	BN_clear_free(aux);
  381|      8|	BN_clear_free(d_consttime);
  382|      8|	BN_clear_free(rsa_dmp1);
  383|      8|	BN_clear_free(rsa_dmq1);
  384|      8|	BN_clear_free(rsa_iqmp);
  385|      8|	BN_CTX_free(ctx);
  386|      8|	return r;
  387|      6|}
ssh-rsa.c:ssh_rsa_alloc:
   54|    394|{
   55|    394|	if ((k->rsa = RSA_new()) == NULL)
  ------------------
  |  Branch (55:6): [True: 0, False: 394]
  ------------------
   56|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   57|    394|	return 0;
   58|    394|}
ssh-rsa.c:ssh_rsa_cleanup:
   62|    394|{
   63|    394|	RSA_free(k->rsa);
   64|    394|	k->rsa = NULL;
   65|    394|}
ssh-rsa.c:ssh_rsa_deserialize_public:
  188|    258|{
  189|    258|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    258|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  190|    258|	BIGNUM *rsa_n = NULL, *rsa_e = NULL;
  191|       |
  192|    258|	if (sshbuf_get_bignum2(b, &rsa_e) != 0 ||
  ------------------
  |  Branch (192:6): [True: 5, False: 253]
  ------------------
  193|    258|	    sshbuf_get_bignum2(b, &rsa_n) != 0) {
  ------------------
  |  Branch (193:6): [True: 2, False: 251]
  ------------------
  194|      7|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      7|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  195|      7|		goto out;
  196|      7|	}
  197|    251|	if (!RSA_set0_key(key->rsa, rsa_n, rsa_e, NULL)) {
  ------------------
  |  Branch (197:6): [True: 0, False: 251]
  ------------------
  198|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  199|      0|		goto out;
  200|      0|	}
  201|    251|	rsa_n = rsa_e = NULL; /* transferred */
  202|    251|	if ((ret = sshkey_check_rsa_length(key, 0)) != 0)
  ------------------
  |  Branch (202:6): [True: 4, False: 247]
  ------------------
  203|      4|		goto out;
  204|       |#ifdef DEBUG_PK
  205|       |	RSA_print_fp(stderr, key->rsa, 8);
  206|       |#endif
  207|       |	/* success */
  208|    247|	ret = 0;
  209|    258| out:
  210|    258|	BN_clear_free(rsa_n);
  211|    258|	BN_clear_free(rsa_e);
  212|    258|	return ret;
  213|    247|}
ssh-rsa.c:ssh_rsa_deserialize_private:
  218|    128|{
  219|    128|	int r;
  220|    128|	BIGNUM *rsa_n = NULL, *rsa_e = NULL, *rsa_d = NULL;
  221|    128|	BIGNUM *rsa_iqmp = NULL, *rsa_p = NULL, *rsa_q = NULL;
  222|       |
  223|       |	/* Note: can't reuse ssh_rsa_deserialize_public: e, n vs. n, e */
  224|    128|	if (!sshkey_is_cert(key)) {
  ------------------
  |  Branch (224:6): [True: 128, False: 0]
  ------------------
  225|    128|		if ((r = sshbuf_get_bignum2(b, &rsa_n)) != 0 ||
  ------------------
  |  Branch (225:7): [True: 43, False: 85]
  ------------------
  226|    128|		    (r = sshbuf_get_bignum2(b, &rsa_e)) != 0)
  ------------------
  |  Branch (226:7): [True: 38, False: 47]
  ------------------
  227|     81|			goto out;
  228|     47|		if (!RSA_set0_key(key->rsa, rsa_n, rsa_e, NULL)) {
  ------------------
  |  Branch (228:7): [True: 0, False: 47]
  ------------------
  229|      0|			r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  230|      0|			goto out;
  231|      0|		}
  232|     47|		rsa_n = rsa_e = NULL; /* transferred */
  233|     47|	}
  234|     47|	if ((r = sshbuf_get_bignum2(b, &rsa_d)) != 0 ||
  ------------------
  |  Branch (234:6): [True: 9, False: 38]
  ------------------
  235|     47|	    (r = sshbuf_get_bignum2(b, &rsa_iqmp)) != 0 ||
  ------------------
  |  Branch (235:6): [True: 2, False: 36]
  ------------------
  236|     47|	    (r = sshbuf_get_bignum2(b, &rsa_p)) != 0 ||
  ------------------
  |  Branch (236:6): [True: 2, False: 34]
  ------------------
  237|     47|	    (r = sshbuf_get_bignum2(b, &rsa_q)) != 0)
  ------------------
  |  Branch (237:6): [True: 3, False: 31]
  ------------------
  238|     16|		goto out;
  239|     31|	if (!RSA_set0_key(key->rsa, NULL, NULL, rsa_d)) {
  ------------------
  |  Branch (239:6): [True: 0, False: 31]
  ------------------
  240|      0|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  241|      0|		goto out;
  242|      0|	}
  243|     31|	rsa_d = NULL; /* transferred */
  244|     31|	if (!RSA_set0_factors(key->rsa, rsa_p, rsa_q)) {
  ------------------
  |  Branch (244:6): [True: 0, False: 31]
  ------------------
  245|      0|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  246|      0|		goto out;
  247|      0|	}
  248|     31|	rsa_p = rsa_q = NULL; /* transferred */
  249|     31|	if ((r = sshkey_check_rsa_length(key, 0)) != 0)
  ------------------
  |  Branch (249:6): [True: 23, False: 8]
  ------------------
  250|     23|		goto out;
  251|      8|	if ((r = ssh_rsa_complete_crt_parameters(key, rsa_iqmp)) != 0)
  ------------------
  |  Branch (251:6): [True: 2, False: 6]
  ------------------
  252|      2|		goto out;
  253|      6|	if (RSA_blinding_on(key->rsa, NULL) != 1) {
  ------------------
  |  Branch (253:6): [True: 5, False: 1]
  ------------------
  254|      5|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      5|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  255|      5|		goto out;
  256|      5|	}
  257|       |	/* success */
  258|      1|	r = 0;
  259|    128| out:
  260|    128|	BN_clear_free(rsa_n);
  261|    128|	BN_clear_free(rsa_e);
  262|    128|	BN_clear_free(rsa_d);
  263|    128|	BN_clear_free(rsa_p);
  264|    128|	BN_clear_free(rsa_q);
  265|    128|	BN_clear_free(rsa_iqmp);
  266|    128|	return r;
  267|      1|}
ssh-rsa.c:rsa_hash_id_from_ident:
  289|    220|{
  290|    220|	if (strcmp(ident, "ssh-rsa") == 0)
  ------------------
  |  Branch (290:6): [True: 34, False: 186]
  ------------------
  291|     34|		return SSH_DIGEST_SHA1;
  ------------------
  |  |   26|     34|#define SSH_DIGEST_SHA1		1
  ------------------
  292|    186|	if (strcmp(ident, "rsa-sha2-256") == 0)
  ------------------
  |  Branch (292:6): [True: 3, False: 183]
  ------------------
  293|      3|		return SSH_DIGEST_SHA256;
  ------------------
  |  |   27|      3|#define SSH_DIGEST_SHA256	2
  ------------------
  294|    183|	if (strcmp(ident, "rsa-sha2-512") == 0)
  ------------------
  |  Branch (294:6): [True: 3, False: 180]
  ------------------
  295|      3|		return SSH_DIGEST_SHA512;
  ------------------
  |  |   29|      3|#define SSH_DIGEST_SHA512	4
  ------------------
  296|    180|	return -1;
  297|    183|}
ssh-rsa.c:ssh_rsa_verify:
  478|    239|{
  479|    239|	const BIGNUM *rsa_n;
  480|    239|	char *sigtype = NULL;
  481|    239|	int hash_alg, want_alg, ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    239|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  482|    239|	size_t len = 0, diff, modlen, hlen;
  483|    239|	struct sshbuf *b = NULL;
  484|    239|	u_char digest[SSH_DIGEST_MAX_LENGTH], *osigblob, *sigblob = NULL;
  485|       |
  486|    239|	if (key == NULL || key->rsa == NULL ||
  ------------------
  |  Branch (486:6): [True: 0, False: 239]
  |  Branch (486:21): [True: 0, False: 239]
  ------------------
  487|    239|	    sshkey_type_plain(key->type) != KEY_RSA ||
  ------------------
  |  Branch (487:6): [True: 0, False: 239]
  ------------------
  488|    239|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (488:6): [True: 0, False: 239]
  |  Branch (488:21): [True: 0, False: 239]
  ------------------
  489|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  490|    239|	RSA_get0_key(key->rsa, &rsa_n, NULL, NULL);
  491|    239|	if (BN_num_bits(rsa_n) < SSH_RSA_MINIMUM_MODULUS_SIZE)
  ------------------
  |  |   53|    239|#define SSH_RSA_MINIMUM_MODULUS_SIZE	1024
  ------------------
  |  Branch (491:6): [True: 0, False: 239]
  ------------------
  492|      0|		return SSH_ERR_KEY_LENGTH;
  ------------------
  |  |   80|      0|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
  493|       |
  494|    239|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (494:6): [True: 0, False: 239]
  ------------------
  495|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  496|    239|	if (sshbuf_get_cstring(b, &sigtype, NULL) != 0) {
  ------------------
  |  Branch (496:6): [True: 19, False: 220]
  ------------------
  497|     19|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     19|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  498|     19|		goto out;
  499|     19|	}
  500|    220|	if ((hash_alg = rsa_hash_id_from_ident(sigtype)) == -1) {
  ------------------
  |  Branch (500:6): [True: 180, False: 40]
  ------------------
  501|    180|		ret = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    180|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  502|    180|		goto out;
  503|    180|	}
  504|       |	/*
  505|       |	 * Allow ssh-rsa-cert-v01 certs to generate SHA2 signatures for
  506|       |	 * legacy reasons, but otherwise the signature type should match.
  507|       |	 */
  508|     40|	if (alg != NULL && strcmp(alg, "ssh-rsa-cert-v01@openssh.com") != 0) {
  ------------------
  |  Branch (508:6): [True: 0, False: 40]
  |  Branch (508:21): [True: 0, False: 0]
  ------------------
  509|      0|		if ((want_alg = rsa_hash_id_from_keyname(alg)) == -1) {
  ------------------
  |  Branch (509:7): [True: 0, False: 0]
  ------------------
  510|      0|			ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  511|      0|			goto out;
  512|      0|		}
  513|      0|		if (hash_alg != want_alg) {
  ------------------
  |  Branch (513:7): [True: 0, False: 0]
  ------------------
  514|      0|			ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  515|      0|			goto out;
  516|      0|		}
  517|      0|	}
  518|     40|	if (sshbuf_get_string(b, &sigblob, &len) != 0) {
  ------------------
  |  Branch (518:6): [True: 4, False: 36]
  ------------------
  519|      4|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      4|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  520|      4|		goto out;
  521|      4|	}
  522|     36|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (522:6): [True: 12, False: 24]
  ------------------
  523|     12|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|     12|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  524|     12|		goto out;
  525|     12|	}
  526|       |	/* RSA_verify expects a signature of RSA_size */
  527|     24|	modlen = RSA_size(key->rsa);
  528|     24|	if (len > modlen) {
  ------------------
  |  Branch (528:6): [True: 8, False: 16]
  ------------------
  529|      8|		ret = SSH_ERR_KEY_BITS_MISMATCH;
  ------------------
  |  |   35|      8|#define SSH_ERR_KEY_BITS_MISMATCH		-11
  ------------------
  530|      8|		goto out;
  531|     16|	} else if (len < modlen) {
  ------------------
  |  Branch (531:13): [True: 15, False: 1]
  ------------------
  532|     15|		diff = modlen - len;
  533|     15|		osigblob = sigblob;
  534|     15|		if ((sigblob = realloc(sigblob, modlen)) == NULL) {
  ------------------
  |  Branch (534:7): [True: 0, False: 15]
  ------------------
  535|      0|			sigblob = osigblob; /* put it back for clear/free */
  536|      0|			ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  537|      0|			goto out;
  538|      0|		}
  539|     15|		memmove(sigblob + diff, sigblob, len);
  540|     15|		explicit_bzero(sigblob, diff);
  541|     15|		len = modlen;
  542|     15|	}
  543|     16|	if ((hlen = ssh_digest_bytes(hash_alg)) == 0) {
  ------------------
  |  Branch (543:6): [True: 0, False: 16]
  ------------------
  544|      0|		ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  545|      0|		goto out;
  546|      0|	}
  547|     16|	if ((ret = ssh_digest_memory(hash_alg, data, dlen,
  ------------------
  |  Branch (547:6): [True: 0, False: 16]
  ------------------
  548|     16|	    digest, sizeof(digest))) != 0)
  549|      0|		goto out;
  550|       |
  551|     16|	ret = openssh_RSA_verify(hash_alg, digest, hlen, sigblob, len,
  552|     16|	    key->rsa);
  553|    239| out:
  554|    239|	freezero(sigblob, len);
  555|    239|	free(sigtype);
  556|    239|	sshbuf_free(b);
  557|    239|	explicit_bzero(digest, sizeof(digest));
  558|    239|	return ret;
  559|     16|}
ssh-rsa.c:openssh_RSA_verify:
  635|     16|{
  636|     16|	size_t rsasize = 0, oidlen = 0, hlen = 0;
  637|     16|	int ret, len, oidmatch, hashmatch;
  638|     16|	const u_char *oid = NULL;
  639|     16|	u_char *decrypted = NULL;
  640|       |
  641|     16|	if ((ret = rsa_hash_alg_oid(hash_alg, &oid, &oidlen)) != 0)
  ------------------
  |  Branch (641:6): [True: 0, False: 16]
  ------------------
  642|      0|		return ret;
  643|     16|	ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|     16|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  644|     16|	hlen = ssh_digest_bytes(hash_alg);
  645|     16|	if (hashlen != hlen) {
  ------------------
  |  Branch (645:6): [True: 0, False: 16]
  ------------------
  646|      0|		ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  647|      0|		goto done;
  648|      0|	}
  649|     16|	rsasize = RSA_size(rsa);
  650|     16|	if (rsasize <= 0 || rsasize > SSHBUF_MAX_BIGNUM ||
  ------------------
  |  |   33|     32|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (650:6): [True: 0, False: 16]
  |  Branch (650:22): [True: 0, False: 16]
  ------------------
  651|     16|	    siglen == 0 || siglen > rsasize) {
  ------------------
  |  Branch (651:6): [True: 0, False: 16]
  |  Branch (651:21): [True: 0, False: 16]
  ------------------
  652|      0|		ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  653|      0|		goto done;
  654|      0|	}
  655|     16|	if ((decrypted = malloc(rsasize)) == NULL) {
  ------------------
  |  Branch (655:6): [True: 0, False: 16]
  ------------------
  656|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  657|      0|		goto done;
  658|      0|	}
  659|     16|	if ((len = RSA_public_decrypt(siglen, sigbuf, decrypted, rsa,
  ------------------
  |  Branch (659:6): [True: 16, False: 0]
  ------------------
  660|     16|	    RSA_PKCS1_PADDING)) < 0) {
  661|     16|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|     16|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  662|     16|		goto done;
  663|     16|	}
  664|      0|	if (len < 0 || (size_t)len != hlen + oidlen) {
  ------------------
  |  Branch (664:6): [True: 0, False: 0]
  |  Branch (664:17): [True: 0, False: 0]
  ------------------
  665|      0|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  666|      0|		goto done;
  667|      0|	}
  668|      0|	oidmatch = timingsafe_bcmp(decrypted, oid, oidlen) == 0;
  669|      0|	hashmatch = timingsafe_bcmp(decrypted + oidlen, hash, hlen) == 0;
  670|      0|	if (!oidmatch || !hashmatch) {
  ------------------
  |  Branch (670:6): [True: 0, False: 0]
  |  Branch (670:19): [True: 0, False: 0]
  ------------------
  671|      0|		ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  672|      0|		goto done;
  673|      0|	}
  674|      0|	ret = 0;
  675|     16|done:
  676|     16|	freezero(decrypted, rsasize);
  677|     16|	return ret;
  678|      0|}
ssh-rsa.c:rsa_hash_alg_oid:
  612|     16|{
  613|     16|	switch (hash_alg) {
  614|     12|	case SSH_DIGEST_SHA1:
  ------------------
  |  |   26|     12|#define SSH_DIGEST_SHA1		1
  ------------------
  |  Branch (614:2): [True: 12, False: 4]
  ------------------
  615|     12|		*oidp = id_sha1;
  616|     12|		*oidlenp = sizeof(id_sha1);
  617|     12|		break;
  618|      2|	case SSH_DIGEST_SHA256:
  ------------------
  |  |   27|      2|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (618:2): [True: 2, False: 14]
  ------------------
  619|      2|		*oidp = id_sha256;
  620|      2|		*oidlenp = sizeof(id_sha256);
  621|      2|		break;
  622|      2|	case SSH_DIGEST_SHA512:
  ------------------
  |  |   29|      2|#define SSH_DIGEST_SHA512	4
  ------------------
  |  Branch (622:2): [True: 2, False: 14]
  ------------------
  623|      2|		*oidp = id_sha512;
  624|      2|		*oidlenp = sizeof(id_sha512);
  625|      2|		break;
  626|      0|	default:
  ------------------
  |  Branch (626:2): [True: 0, False: 16]
  ------------------
  627|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  628|     16|	}
  629|     16|	return 0;
  630|     16|}

ssh-xmss.c:ssh_xmss_cleanup:
   42|    912|{
   43|    912|	freezero(k->xmss_pk, sshkey_xmss_pklen(k));
   44|    912|	freezero(k->xmss_sk, sshkey_xmss_sklen(k));
   45|    912|	sshkey_xmss_free_state(k);
   46|    912|	free(k->xmss_name);
   47|    912|	free(k->xmss_filename);
   48|    912|	k->xmss_pk = NULL;
   49|    912|	k->xmss_sk = NULL;
   50|    912|	k->xmss_name = NULL;
   51|    912|	k->xmss_filename = NULL;
   52|    912|}
ssh-xmss.c:ssh_xmss_deserialize_public:
  132|    271|{
  133|    271|	size_t len = 0;
  134|    271|	char *xmss_name = NULL;
  135|    271|	u_char *pk = NULL;
  136|    271|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    271|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  137|       |
  138|    271|	if ((ret = sshbuf_get_cstring(b, &xmss_name, NULL)) != 0)
  ------------------
  |  Branch (138:6): [True: 4, False: 267]
  ------------------
  139|      4|		goto out;
  140|    267|	if ((ret = sshkey_xmss_init(key, xmss_name)) != 0)
  ------------------
  |  Branch (140:6): [True: 5, False: 262]
  ------------------
  141|      5|		goto out;
  142|    262|	if ((ret = sshbuf_get_string(b, &pk, &len)) != 0)
  ------------------
  |  Branch (142:6): [True: 4, False: 258]
  ------------------
  143|      4|		goto out;
  144|    258|	if (len == 0 || len != sshkey_xmss_pklen(key)) {
  ------------------
  |  Branch (144:6): [True: 1, False: 257]
  |  Branch (144:18): [True: 39, False: 218]
  ------------------
  145|     40|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     40|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  146|     40|		goto out;
  147|     40|	}
  148|    218|	key->xmss_pk = pk;
  149|    218|	pk = NULL;
  150|    218|	if (!sshkey_is_cert(key) &&
  ------------------
  |  Branch (150:6): [True: 214, False: 4]
  ------------------
  151|    218|	    (ret = sshkey_xmss_deserialize_pk_info(key, b)) != 0)
  ------------------
  |  Branch (151:6): [True: 28, False: 186]
  ------------------
  152|     28|		goto out;
  153|       |	/* success */
  154|    190|	ret = 0;
  155|    271| out:
  156|    271|	free(xmss_name);
  157|    271|	freezero(pk, len);
  158|    271|	return ret;
  159|    190|}
ssh-xmss.c:ssh_xmss_deserialize_private:
  164|    641|{
  165|    641|	int r;
  166|    641|	char *xmss_name = NULL;
  167|    641|	size_t pklen = 0, sklen = 0;
  168|    641|	u_char *xmss_pk = NULL, *xmss_sk = NULL;
  169|       |
  170|       |	/* Note: can't reuse ssh_xmss_deserialize_public because of sk order */
  171|    641|	if ((r = sshbuf_get_cstring(b, &xmss_name, NULL)) != 0 ||
  ------------------
  |  Branch (171:6): [True: 3, False: 638]
  ------------------
  172|    641|	    (r = sshbuf_get_string(b, &xmss_pk, &pklen)) != 0 ||
  ------------------
  |  Branch (172:6): [True: 3, False: 635]
  ------------------
  173|    641|	    (r = sshbuf_get_string(b, &xmss_sk, &sklen)) != 0)
  ------------------
  |  Branch (173:6): [True: 5, False: 630]
  ------------------
  174|     11|		goto out;
  175|    630|	if (!sshkey_is_cert(key) &&
  ------------------
  |  Branch (175:6): [True: 630, False: 0]
  ------------------
  176|    630|	    (r = sshkey_xmss_init(key, xmss_name)) != 0)
  ------------------
  |  Branch (176:6): [True: 153, False: 477]
  ------------------
  177|    153|		goto out;
  178|    477|	if (pklen != sshkey_xmss_pklen(key) ||
  ------------------
  |  Branch (178:6): [True: 40, False: 437]
  ------------------
  179|    477|	    sklen != sshkey_xmss_sklen(key)) {
  ------------------
  |  Branch (179:6): [True: 38, False: 399]
  ------------------
  180|     78|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     78|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  181|     78|		goto out;
  182|     78|	}
  183|    399|	key->xmss_pk = xmss_pk;
  184|    399|	key->xmss_sk = xmss_sk;
  185|    399|	xmss_pk = xmss_sk = NULL;
  186|       |	/* optional internal state */
  187|    399|	if ((r = sshkey_xmss_deserialize_state_opt(key, b)) != 0)
  ------------------
  |  Branch (187:6): [True: 393, False: 6]
  ------------------
  188|    393|		goto out;
  189|       |	/* success */
  190|      6|	r = 0;
  191|    641| out:
  192|    641|	free(xmss_name);
  193|    641|	freezero(xmss_pk, pklen);
  194|    641|	freezero(xmss_sk, sklen);
  195|    641|	return r;
  196|      6|}
ssh-xmss.c:ssh_xmss_verify:
  279|    180|{
  280|    180|	struct sshbuf *b = NULL;
  281|    180|	char *ktype = NULL;
  282|    180|	const u_char *sigblob;
  283|    180|	u_char *sm = NULL, *m = NULL;
  284|    180|	size_t len, required_siglen;
  285|    180|	unsigned long long smlen = 0, mlen = 0;
  286|    180|	int r, ret;
  287|       |
  288|    180|	if (key == NULL ||
  ------------------
  |  Branch (288:6): [True: 0, False: 180]
  ------------------
  289|    180|	    sshkey_type_plain(key->type) != KEY_XMSS ||
  ------------------
  |  Branch (289:6): [True: 0, False: 180]
  ------------------
  290|    180|	    key->xmss_pk == NULL ||
  ------------------
  |  Branch (290:6): [True: 0, False: 180]
  ------------------
  291|    180|	    sshkey_xmss_params(key) == NULL ||
  ------------------
  |  Branch (291:6): [True: 0, False: 180]
  ------------------
  292|    180|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (292:6): [True: 0, False: 180]
  |  Branch (292:21): [True: 0, False: 180]
  ------------------
  293|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  294|    180|	if ((r = sshkey_xmss_siglen(key, &required_siglen)) != 0)
  ------------------
  |  Branch (294:6): [True: 0, False: 180]
  ------------------
  295|      0|		return r;
  296|    180|	if (dlen >= INT_MAX - required_siglen)
  ------------------
  |  Branch (296:6): [True: 0, False: 180]
  ------------------
  297|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  298|       |
  299|    180|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (299:6): [True: 0, False: 180]
  ------------------
  300|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  301|    180|	if ((r = sshbuf_get_cstring(b, &ktype, NULL)) != 0 ||
  ------------------
  |  Branch (301:6): [True: 19, False: 161]
  ------------------
  302|    180|	    (r = sshbuf_get_string_direct(b, &sigblob, &len)) != 0)
  ------------------
  |  Branch (302:6): [True: 3, False: 158]
  ------------------
  303|     22|		goto out;
  304|    158|	if (strcmp("ssh-xmss@openssh.com", ktype) != 0) {
  ------------------
  |  Branch (304:6): [True: 148, False: 10]
  ------------------
  305|    148|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    148|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  306|    148|		goto out;
  307|    148|	}
  308|     10|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (308:6): [True: 3, False: 7]
  ------------------
  309|      3|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      3|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  310|      3|		goto out;
  311|      3|	}
  312|      7|	if (len != required_siglen) {
  ------------------
  |  Branch (312:6): [True: 7, False: 0]
  ------------------
  313|      7|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      7|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  314|      7|		goto out;
  315|      7|	}
  316|      0|	if (dlen >= SIZE_MAX - len) {
  ------------------
  |  Branch (316:6): [True: 0, False: 0]
  ------------------
  317|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  318|      0|		goto out;
  319|      0|	}
  320|      0|	smlen = len + dlen;
  321|      0|	mlen = smlen;
  322|      0|	if ((sm = malloc(smlen)) == NULL || (m = malloc(mlen)) == NULL) {
  ------------------
  |  Branch (322:6): [True: 0, False: 0]
  |  Branch (322:38): [True: 0, False: 0]
  ------------------
  323|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  324|      0|		goto out;
  325|      0|	}
  326|      0|	memcpy(sm, sigblob, len);
  327|      0|	memcpy(sm+len, data, dlen);
  328|      0|	if ((ret = xmss_sign_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (328:6): [True: 0, False: 0]
  ------------------
  329|      0|	    key->xmss_pk, sshkey_xmss_params(key))) != 0) {
  330|      0|		debug2_f("xmss_sign_open failed: %d", ret);
  ------------------
  |  |  101|      0|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  331|      0|	}
  332|      0|	if (ret != 0 || mlen != dlen) {
  ------------------
  |  Branch (332:6): [True: 0, False: 0]
  |  Branch (332:18): [True: 0, False: 0]
  ------------------
  333|      0|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  334|      0|		goto out;
  335|      0|	}
  336|       |	/* XXX compare 'm' and 'data' ? */
  337|       |	/* success */
  338|      0|	r = 0;
  339|    180| out:
  340|    180|	if (sm != NULL)
  ------------------
  |  Branch (340:6): [True: 0, False: 180]
  ------------------
  341|      0|		freezero(sm, smlen);
  342|    180|	if (m != NULL)
  ------------------
  |  Branch (342:6): [True: 0, False: 180]
  ------------------
  343|      0|		freezero(m, smlen);
  344|    180|	sshbuf_free(b);
  345|    180|	free(ktype);
  346|    180|	return r;
  347|      0|}

sshbuf_get:
   36|     96|{
   37|     96|	const u_char *p = sshbuf_ptr(buf);
   38|     96|	int r;
   39|       |
   40|     96|	if ((r = sshbuf_consume(buf, len)) < 0)
  ------------------
  |  Branch (40:6): [True: 0, False: 96]
  ------------------
   41|      0|		return r;
   42|     96|	if (v != NULL && len != 0)
  ------------------
  |  Branch (42:6): [True: 96, False: 0]
  |  Branch (42:19): [True: 42, False: 54]
  ------------------
   43|     42|		memcpy(v, p, len);
   44|     96|	return 0;
   45|     96|}
sshbuf_get_u64:
   49|  5.36k|{
   50|  5.36k|	const u_char *p = sshbuf_ptr(buf);
   51|  5.36k|	int r;
   52|       |
   53|  5.36k|	if ((r = sshbuf_consume(buf, 8)) < 0)
  ------------------
  |  Branch (53:6): [True: 11, False: 5.34k]
  ------------------
   54|     11|		return r;
   55|  5.34k|	if (valp != NULL)
  ------------------
  |  Branch (55:6): [True: 5.34k, False: 0]
  ------------------
   56|  5.34k|		*valp = PEEK_U64(p);
  ------------------
  |  |  303|  5.34k|	(((u_int64_t)(((const u_char *)(p))[0]) << 56) | \
  |  |  304|  5.34k|	 ((u_int64_t)(((const u_char *)(p))[1]) << 48) | \
  |  |  305|  5.34k|	 ((u_int64_t)(((const u_char *)(p))[2]) << 40) | \
  |  |  306|  5.34k|	 ((u_int64_t)(((const u_char *)(p))[3]) << 32) | \
  |  |  307|  5.34k|	 ((u_int64_t)(((const u_char *)(p))[4]) << 24) | \
  |  |  308|  5.34k|	 ((u_int64_t)(((const u_char *)(p))[5]) << 16) | \
  |  |  309|  5.34k|	 ((u_int64_t)(((const u_char *)(p))[6]) << 8) | \
  |  |  310|  5.34k|	  (u_int64_t)(((const u_char *)(p))[7]))
  ------------------
   57|  5.34k|	return 0;
   58|  5.36k|}
sshbuf_get_u32:
   62|  3.87k|{
   63|  3.87k|	const u_char *p = sshbuf_ptr(buf);
   64|  3.87k|	int r;
   65|       |
   66|  3.87k|	if ((r = sshbuf_consume(buf, 4)) < 0)
  ------------------
  |  Branch (66:6): [True: 93, False: 3.77k]
  ------------------
   67|     93|		return r;
   68|  3.77k|	if (valp != NULL)
  ------------------
  |  Branch (68:6): [True: 3.77k, False: 0]
  ------------------
   69|  3.77k|		*valp = PEEK_U32(p);
  ------------------
  |  |  312|  3.77k|	(((u_int32_t)(((const u_char *)(p))[0]) << 24) | \
  |  |  313|  3.77k|	 ((u_int32_t)(((const u_char *)(p))[1]) << 16) | \
  |  |  314|  3.77k|	 ((u_int32_t)(((const u_char *)(p))[2]) << 8) | \
  |  |  315|  3.77k|	  (u_int32_t)(((const u_char *)(p))[3]))
  ------------------
   70|  3.77k|	return 0;
   71|  3.87k|}
sshbuf_get_u8:
   88|  1.15k|{
   89|  1.15k|	const u_char *p = sshbuf_ptr(buf);
   90|  1.15k|	int r;
   91|       |
   92|  1.15k|	if ((r = sshbuf_consume(buf, 1)) < 0)
  ------------------
  |  Branch (92:6): [True: 19, False: 1.13k]
  ------------------
   93|     19|		return r;
   94|  1.13k|	if (valp != NULL)
  ------------------
  |  Branch (94:6): [True: 1.13k, False: 0]
  ------------------
   95|  1.13k|		*valp = (u_int8_t)*p;
   96|  1.13k|	return 0;
   97|  1.15k|}
sshbuf_get_string:
  188|  6.16k|{
  189|  6.16k|	const u_char *val;
  190|  6.16k|	size_t len;
  191|  6.16k|	int r;
  192|       |
  193|  6.16k|	if (valp != NULL)
  ------------------
  |  Branch (193:6): [True: 6.16k, False: 0]
  ------------------
  194|  6.16k|		*valp = NULL;
  195|  6.16k|	if (lenp != NULL)
  ------------------
  |  Branch (195:6): [True: 6.16k, False: 0]
  ------------------
  196|  6.16k|		*lenp = 0;
  197|  6.16k|	if ((r = sshbuf_get_string_direct(buf, &val, &len)) < 0)
  ------------------
  |  Branch (197:6): [True: 111, False: 6.05k]
  ------------------
  198|    111|		return r;
  199|  6.05k|	if (valp != NULL) {
  ------------------
  |  Branch (199:6): [True: 6.05k, False: 0]
  ------------------
  200|  6.05k|		if ((*valp = malloc(len + 1)) == NULL) {
  ------------------
  |  Branch (200:7): [True: 0, False: 6.05k]
  ------------------
  201|      0|			SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  202|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  203|      0|		}
  204|  6.05k|		if (len != 0)
  ------------------
  |  Branch (204:7): [True: 4.58k, False: 1.47k]
  ------------------
  205|  4.58k|			memcpy(*valp, val, len);
  206|  6.05k|		(*valp)[len] = '\0';
  207|  6.05k|	}
  208|  6.05k|	if (lenp != NULL)
  ------------------
  |  Branch (208:6): [True: 6.05k, False: 0]
  ------------------
  209|  6.05k|		*lenp = len;
  210|  6.05k|	return 0;
  211|  6.05k|}
sshbuf_get_string_direct:
  215|  33.5k|{
  216|  33.5k|	size_t len;
  217|  33.5k|	const u_char *p;
  218|  33.5k|	int r;
  219|       |
  220|  33.5k|	if (valp != NULL)
  ------------------
  |  Branch (220:6): [True: 6.67k, False: 26.8k]
  ------------------
  221|  6.67k|		*valp = NULL;
  222|  33.5k|	if (lenp != NULL)
  ------------------
  |  Branch (222:6): [True: 6.67k, False: 26.8k]
  ------------------
  223|  6.67k|		*lenp = 0;
  224|  33.5k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) < 0)
  ------------------
  |  Branch (224:6): [True: 258, False: 33.2k]
  ------------------
  225|    258|		return r;
  226|  33.2k|	if (valp != NULL)
  ------------------
  |  Branch (226:6): [True: 6.55k, False: 26.7k]
  ------------------
  227|  6.55k|		*valp = p;
  228|  33.2k|	if (lenp != NULL)
  ------------------
  |  Branch (228:6): [True: 6.55k, False: 26.7k]
  ------------------
  229|  6.55k|		*lenp = len;
  230|  33.2k|	if (sshbuf_consume(buf, len + 4) != 0) {
  ------------------
  |  Branch (230:6): [True: 0, False: 33.2k]
  ------------------
  231|       |		/* Shouldn't happen */
  232|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  233|      0|		SSHBUF_ABORT();
  234|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  235|      0|	}
  236|  33.2k|	return 0;
  237|  33.2k|}
sshbuf_peek_string_direct:
  242|  72.0k|{
  243|  72.0k|	u_int32_t len;
  244|  72.0k|	const u_char *p = sshbuf_ptr(buf);
  245|       |
  246|  72.0k|	if (valp != NULL)
  ------------------
  |  Branch (246:6): [True: 71.8k, False: 201]
  ------------------
  247|  71.8k|		*valp = NULL;
  248|  72.0k|	if (lenp != NULL)
  ------------------
  |  Branch (248:6): [True: 71.8k, False: 201]
  ------------------
  249|  71.8k|		*lenp = 0;
  250|  72.0k|	if (sshbuf_len(buf) < 4) {
  ------------------
  |  Branch (250:6): [True: 363, False: 71.7k]
  ------------------
  251|    363|		SSHBUF_DBG(("SSH_ERR_MESSAGE_INCOMPLETE"));
  252|    363|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    363|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  253|    363|	}
  254|  71.7k|	len = PEEK_U32(p);
  ------------------
  |  |  312|  71.7k|	(((u_int32_t)(((const u_char *)(p))[0]) << 24) | \
  |  |  313|  71.7k|	 ((u_int32_t)(((const u_char *)(p))[1]) << 16) | \
  |  |  314|  71.7k|	 ((u_int32_t)(((const u_char *)(p))[2]) << 8) | \
  |  |  315|  71.7k|	  (u_int32_t)(((const u_char *)(p))[3]))
  ------------------
  255|  71.7k|	if (len > SSHBUF_SIZE_MAX - 4) {
  ------------------
  |  |   31|  71.7k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  |  Branch (255:6): [True: 292, False: 71.4k]
  ------------------
  256|    292|		SSHBUF_DBG(("SSH_ERR_STRING_TOO_LARGE"));
  257|    292|		return SSH_ERR_STRING_TOO_LARGE;
  ------------------
  |  |   30|    292|#define SSH_ERR_STRING_TOO_LARGE		-6
  ------------------
  258|    292|	}
  259|  71.4k|	if (sshbuf_len(buf) - 4 < len) {
  ------------------
  |  Branch (259:6): [True: 400, False: 71.0k]
  ------------------
  260|    400|		SSHBUF_DBG(("SSH_ERR_MESSAGE_INCOMPLETE"));
  261|    400|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    400|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  262|    400|	}
  263|  71.0k|	if (valp != NULL)
  ------------------
  |  Branch (263:6): [True: 70.9k, False: 96]
  ------------------
  264|  70.9k|		*valp = p + 4;
  265|  71.0k|	if (lenp != NULL)
  ------------------
  |  Branch (265:6): [True: 70.9k, False: 96]
  ------------------
  266|  70.9k|		*lenp = len;
  267|  71.0k|	return 0;
  268|  71.4k|}
sshbuf_get_cstring:
  272|  18.5k|{
  273|  18.5k|	size_t len;
  274|  18.5k|	const u_char *p, *z;
  275|  18.5k|	int r;
  276|       |
  277|  18.5k|	if (valp != NULL)
  ------------------
  |  Branch (277:6): [True: 18.5k, False: 0]
  ------------------
  278|  18.5k|		*valp = NULL;
  279|  18.5k|	if (lenp != NULL)
  ------------------
  |  Branch (279:6): [True: 1.79k, False: 16.7k]
  ------------------
  280|  1.79k|		*lenp = 0;
  281|  18.5k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) != 0)
  ------------------
  |  Branch (281:6): [True: 363, False: 18.1k]
  ------------------
  282|    363|		return r;
  283|       |	/* Allow a \0 only at the end of the string */
  284|  18.1k|	if (len > 0 &&
  ------------------
  |  Branch (284:6): [True: 11.6k, False: 6.44k]
  ------------------
  285|  18.1k|	    (z = memchr(p , '\0', len)) != NULL && z < p + len - 1) {
  ------------------
  |  Branch (285:6): [True: 575, False: 11.1k]
  |  Branch (285:45): [True: 22, False: 553]
  ------------------
  286|     22|		SSHBUF_DBG(("SSH_ERR_INVALID_FORMAT"));
  287|     22|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     22|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  288|     22|	}
  289|  18.1k|	if ((r = sshbuf_skip_string(buf)) != 0)
  ------------------
  |  |  205|  18.1k|#define sshbuf_skip_string(buf) sshbuf_get_string_direct(buf, NULL, NULL)
  ------------------
  |  Branch (289:6): [True: 0, False: 18.1k]
  ------------------
  290|      0|		return -1;
  291|  18.1k|	if (valp != NULL) {
  ------------------
  |  Branch (291:6): [True: 18.1k, False: 0]
  ------------------
  292|  18.1k|		if ((*valp = malloc(len + 1)) == NULL) {
  ------------------
  |  Branch (292:7): [True: 0, False: 18.1k]
  ------------------
  293|      0|			SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  294|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  295|      0|		}
  296|  18.1k|		if (len != 0)
  ------------------
  |  Branch (296:7): [True: 11.6k, False: 6.44k]
  ------------------
  297|  11.6k|			memcpy(*valp, p, len);
  298|  18.1k|		(*valp)[len] = '\0';
  299|  18.1k|	}
  300|  18.1k|	if (lenp != NULL)
  ------------------
  |  Branch (300:6): [True: 1.78k, False: 16.3k]
  ------------------
  301|  1.78k|		*lenp = (size_t)len;
  302|  18.1k|	return 0;
  303|  18.1k|}
sshbuf_get_stringb:
  307|    201|{
  308|    201|	u_int32_t len;
  309|    201|	u_char *p;
  310|    201|	int r;
  311|       |
  312|       |	/*
  313|       |	 * Use sshbuf_peek_string_direct() to figure out if there is
  314|       |	 * a complete string in 'buf' and copy the string directly
  315|       |	 * into 'v'.
  316|       |	 */
  317|    201|	if ((r = sshbuf_peek_string_direct(buf, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (317:6): [True: 105, False: 96]
  ------------------
  318|    201|	    (r = sshbuf_get_u32(buf, &len)) != 0 ||
  ------------------
  |  Branch (318:6): [True: 0, False: 96]
  ------------------
  319|    201|	    (r = sshbuf_reserve(v, len, &p)) != 0 ||
  ------------------
  |  Branch (319:6): [True: 0, False: 96]
  ------------------
  320|    201|	    (r = sshbuf_get(buf, p, len)) != 0)
  ------------------
  |  Branch (320:6): [True: 0, False: 96]
  ------------------
  321|    105|		return r;
  322|     96|	return 0;
  323|    201|}
sshbuf_put:
  327|  5.89k|{
  328|  5.89k|	u_char *p;
  329|  5.89k|	int r;
  330|       |
  331|  5.89k|	if ((r = sshbuf_reserve(buf, len, &p)) < 0)
  ------------------
  |  Branch (331:6): [True: 0, False: 5.89k]
  ------------------
  332|      0|		return r;
  333|  5.89k|	if (len != 0)
  ------------------
  |  Branch (333:6): [True: 2.56k, False: 3.32k]
  ------------------
  334|  2.56k|		memcpy(p, v, len);
  335|  5.89k|	return 0;
  336|  5.89k|}
sshbuf_putb:
  340|  5.25k|{
  341|  5.25k|	if (v == NULL)
  ------------------
  |  Branch (341:6): [True: 1, False: 5.25k]
  ------------------
  342|      1|		return 0;
  343|  5.25k|	return sshbuf_put(buf, sshbuf_ptr(v), sshbuf_len(v));
  344|  5.25k|}
sshbuf_put_u32:
  405|     11|{
  406|     11|	u_char *p;
  407|     11|	int r;
  408|       |
  409|     11|	if ((r = sshbuf_reserve(buf, 4, &p)) < 0)
  ------------------
  |  Branch (409:6): [True: 0, False: 11]
  ------------------
  410|      0|		return r;
  411|     11|	POKE_U32(p, val);
  ------------------
  |  |  333|     11|	do { \
  |  |  334|     11|		const u_int32_t __v = (v); \
  |  |  335|     11|		((u_char *)(p))[0] = (__v >> 24) & 0xff; \
  |  |  336|     11|		((u_char *)(p))[1] = (__v >> 16) & 0xff; \
  |  |  337|     11|		((u_char *)(p))[2] = (__v >> 8) & 0xff; \
  |  |  338|     11|		((u_char *)(p))[3] = __v & 0xff; \
  |  |  339|     11|	} while (0)
  |  |  ------------------
  |  |  |  Branch (339:11): [Folded - Ignored]
  |  |  ------------------
  ------------------
  412|     11|	return 0;
  413|     11|}
sshbuf_put_u8:
  429|     11|{
  430|     11|	u_char *p;
  431|     11|	int r;
  432|       |
  433|     11|	if ((r = sshbuf_reserve(buf, 1, &p)) < 0)
  ------------------
  |  Branch (433:6): [True: 0, False: 11]
  ------------------
  434|      0|		return r;
  435|     11|	p[0] = val;
  436|     11|	return 0;
  437|     11|}
sshbuf_froms:
  548|  10.0k|{
  549|  10.0k|	const u_char *p;
  550|  10.0k|	size_t len;
  551|  10.0k|	struct sshbuf *ret;
  552|  10.0k|	int r;
  553|       |
  554|  10.0k|	if (buf == NULL || bufp == NULL)
  ------------------
  |  Branch (554:6): [True: 0, False: 10.0k]
  |  Branch (554:21): [True: 0, False: 10.0k]
  ------------------
  555|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  556|  10.0k|	*bufp = NULL;
  557|  10.0k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) != 0)
  ------------------
  |  Branch (557:6): [True: 84, False: 9.92k]
  ------------------
  558|     84|		return r;
  559|  9.92k|	if ((ret = sshbuf_from(p, len)) == NULL)
  ------------------
  |  Branch (559:6): [True: 0, False: 9.92k]
  ------------------
  560|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  561|  9.92k|	if ((r = sshbuf_consume(buf, len + 4)) != 0 ||  /* Shouldn't happen */
  ------------------
  |  Branch (561:6): [True: 0, False: 9.92k]
  ------------------
  562|  9.92k|	    (r = sshbuf_set_parent(ret, buf)) != 0) {
  ------------------
  |  Branch (562:6): [True: 0, False: 9.92k]
  ------------------
  563|      0|		sshbuf_free(ret);
  564|      0|		return r;
  565|      0|	}
  566|  9.92k|	*bufp = ret;
  567|  9.92k|	return 0;
  568|  9.92k|}
sshbuf_get_bignum2_bytes_direct:
  602|  9.00k|{
  603|  9.00k|	const u_char *d;
  604|  9.00k|	size_t len, olen;
  605|  9.00k|	int r;
  606|       |
  607|  9.00k|	if ((r = sshbuf_peek_string_direct(buf, &d, &olen)) < 0)
  ------------------
  |  Branch (607:6): [True: 188, False: 8.81k]
  ------------------
  608|    188|		return r;
  609|  8.81k|	len = olen;
  610|       |	/* Refuse negative (MSB set) bignums */
  611|  8.81k|	if ((len != 0 && (*d & 0x80) != 0))
  ------------------
  |  Branch (611:7): [True: 1.33k, False: 7.47k]
  |  Branch (611:19): [True: 9, False: 1.32k]
  ------------------
  612|      9|		return SSH_ERR_BIGNUM_IS_NEGATIVE;
  ------------------
  |  |   29|      9|#define SSH_ERR_BIGNUM_IS_NEGATIVE		-5
  ------------------
  613|       |	/* Refuse overlong bignums, allow prepended \0 to avoid MSB set */
  614|  8.80k|	if (len > SSHBUF_MAX_BIGNUM + 1 ||
  ------------------
  |  |   33|  8.80k|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (614:6): [True: 4, False: 8.80k]
  ------------------
  615|  8.80k|	    (len == SSHBUF_MAX_BIGNUM + 1 && *d != 0))
  ------------------
  |  |   33|  8.80k|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (615:7): [True: 11, False: 8.79k]
  |  Branch (615:39): [True: 1, False: 10]
  ------------------
  616|      5|		return SSH_ERR_BIGNUM_TOO_LARGE;
  ------------------
  |  |   31|      5|#define SSH_ERR_BIGNUM_TOO_LARGE		-7
  ------------------
  617|       |	/* Trim leading zeros */
  618|  11.0k|	while (len > 0 && *d == 0x00) {
  ------------------
  |  Branch (618:9): [True: 3.42k, False: 7.63k]
  |  Branch (618:20): [True: 2.26k, False: 1.16k]
  ------------------
  619|  2.26k|		d++;
  620|  2.26k|		len--;
  621|  2.26k|	}
  622|  8.80k|	if (valp != NULL)
  ------------------
  |  Branch (622:6): [True: 8.80k, False: 0]
  ------------------
  623|  8.80k|		*valp = d;
  624|  8.80k|	if (lenp != NULL)
  ------------------
  |  Branch (624:6): [True: 8.80k, False: 0]
  ------------------
  625|  8.80k|		*lenp = len;
  626|  8.80k|	if (sshbuf_consume(buf, olen + 4) != 0) {
  ------------------
  |  Branch (626:6): [True: 0, False: 8.80k]
  ------------------
  627|       |		/* Shouldn't happen */
  628|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  629|      0|		SSHBUF_ABORT();
  630|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  631|      0|	}
  632|  8.80k|	return 0;
  633|  8.80k|}

sshbuf_get_bignum2:
   37|  9.00k|{
   38|  9.00k|	BIGNUM *v;
   39|  9.00k|	const u_char *d;
   40|  9.00k|	size_t len;
   41|  9.00k|	int r;
   42|       |
   43|  9.00k|	if (valp != NULL)
  ------------------
  |  Branch (43:6): [True: 9.00k, False: 0]
  ------------------
   44|  9.00k|		*valp = NULL;
   45|  9.00k|	if ((r = sshbuf_get_bignum2_bytes_direct(buf, &d, &len)) != 0)
  ------------------
  |  Branch (45:6): [True: 202, False: 8.80k]
  ------------------
   46|    202|		return r;
   47|  8.80k|	if (valp != NULL) {
  ------------------
  |  Branch (47:6): [True: 8.80k, False: 0]
  ------------------
   48|  8.80k|		if ((v = BN_new()) == NULL ||
  ------------------
  |  Branch (48:7): [True: 0, False: 8.80k]
  ------------------
   49|  8.80k|		    BN_bin2bn(d, len, v) == NULL) {
  ------------------
  |  Branch (49:7): [True: 0, False: 8.80k]
  ------------------
   50|      0|			BN_clear_free(v);
   51|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   52|      0|		}
   53|  8.80k|		*valp = v;
   54|  8.80k|	}
   55|  8.80k|	return 0;
   56|  8.80k|}
sshbuf_get_eckey:
   96|    800|{
   97|    800|	EC_POINT *pt = EC_POINT_new(EC_KEY_get0_group(v));
   98|    800|	int r;
   99|    800|	const u_char *d;
  100|    800|	size_t len;
  101|       |
  102|    800|	if (pt == NULL) {
  ------------------
  |  Branch (102:6): [True: 0, False: 800]
  ------------------
  103|      0|		SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  104|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  105|      0|	}
  106|    800|	if ((r = sshbuf_peek_string_direct(buf, &d, &len)) < 0) {
  ------------------
  |  Branch (106:6): [True: 57, False: 743]
  ------------------
  107|     57|		EC_POINT_free(pt);
  108|     57|		return r;
  109|     57|	}
  110|    743|	if ((r = get_ec(d, len, pt, EC_KEY_get0_group(v))) != 0) {
  ------------------
  |  Branch (110:6): [True: 71, False: 672]
  ------------------
  111|     71|		EC_POINT_free(pt);
  112|     71|		return r;
  113|     71|	}
  114|    672|	if (EC_KEY_set_public_key(v, pt) != 1) {
  ------------------
  |  Branch (114:6): [True: 0, False: 672]
  ------------------
  115|      0|		EC_POINT_free(pt);
  116|      0|		return SSH_ERR_ALLOC_FAIL; /* XXX assumption */
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  117|      0|	}
  118|    672|	EC_POINT_free(pt);
  119|       |	/* Skip string */
  120|    672|	if (sshbuf_get_string_direct(buf, NULL, NULL) != 0) {
  ------------------
  |  Branch (120:6): [True: 0, False: 672]
  ------------------
  121|       |		/* Shouldn't happen */
  122|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  123|      0|		SSHBUF_ABORT();
  124|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  125|      0|	}
  126|    672|	return 0;	
  127|    672|}
sshbuf-getput-crypto.c:get_ec:
   61|    743|{
   62|       |	/* Refuse overlong bignums */
   63|    743|	if (len == 0 || len > SSHBUF_MAX_ECPOINT)
  ------------------
  |  |   34|    724|#define SSHBUF_MAX_ECPOINT	((528 * 2 / 8) + 1) /* Max EC point *bytes* */
  ------------------
  |  Branch (63:6): [True: 19, False: 724]
  |  Branch (63:18): [True: 23, False: 701]
  ------------------
   64|     42|		return SSH_ERR_ECPOINT_TOO_LARGE;
  ------------------
  |  |   32|     42|#define SSH_ERR_ECPOINT_TOO_LARGE		-8
  ------------------
   65|       |	/* Only handle uncompressed points */
   66|    701|	if (*d != POINT_CONVERSION_UNCOMPRESSED)
  ------------------
  |  Branch (66:6): [True: 27, False: 674]
  ------------------
   67|     27|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     27|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
   68|    674|	if (v != NULL && EC_POINT_oct2point(g, v, d, len, NULL) != 1)
  ------------------
  |  Branch (68:6): [True: 674, False: 0]
  |  Branch (68:19): [True: 2, False: 672]
  ------------------
   69|      2|		return SSH_ERR_INVALID_FORMAT; /* XXX assumption */
  ------------------
  |  |   28|      2|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
   70|    672|	return 0;
   71|    674|}

sshbuf_dtob64:
   95|    121|{
   96|    121|	size_t i, slen = 0;
   97|    121|	char *s = NULL;
   98|    121|	int r;
   99|       |
  100|    121|	if (d == NULL || b64 == NULL || sshbuf_len(d) >= SIZE_MAX / 2)
  ------------------
  |  Branch (100:6): [True: 0, False: 121]
  |  Branch (100:19): [True: 0, False: 121]
  |  Branch (100:34): [True: 0, False: 121]
  ------------------
  101|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  102|    121|	if (sshbuf_len(d) == 0)
  ------------------
  |  Branch (102:6): [True: 0, False: 121]
  ------------------
  103|      0|		return 0;
  104|    121|	slen = ((sshbuf_len(d) + 2) / 3) * 4 + 1;
  105|    121|	if ((s = malloc(slen)) == NULL)
  ------------------
  |  Branch (105:6): [True: 0, False: 121]
  ------------------
  106|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  107|    121|	if (b64_ntop(sshbuf_ptr(d), sshbuf_len(d), s, slen) == -1) {
  ------------------
  |  Branch (107:6): [True: 0, False: 121]
  ------------------
  108|      0|		r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  109|      0|		goto fail;
  110|      0|	}
  111|    121|	if (wrap) {
  ------------------
  |  Branch (111:6): [True: 0, False: 121]
  ------------------
  112|      0|		for (i = 0; s[i] != '\0'; i++) {
  ------------------
  |  Branch (112:15): [True: 0, False: 0]
  ------------------
  113|      0|			if ((r = sshbuf_put_u8(b64, s[i])) != 0)
  ------------------
  |  Branch (113:8): [True: 0, False: 0]
  ------------------
  114|      0|				goto fail;
  115|      0|			if (i % 70 == 69 && (r = sshbuf_put_u8(b64, '\n')) != 0)
  ------------------
  |  Branch (115:8): [True: 0, False: 0]
  |  Branch (115:24): [True: 0, False: 0]
  ------------------
  116|      0|				goto fail;
  117|      0|		}
  118|      0|		if ((i - 1) % 70 != 69 && (r = sshbuf_put_u8(b64, '\n')) != 0)
  ------------------
  |  Branch (118:7): [True: 0, False: 0]
  |  Branch (118:29): [True: 0, False: 0]
  ------------------
  119|      0|			goto fail;
  120|    121|	} else {
  121|    121|		if ((r = sshbuf_put(b64, s, strlen(s))) != 0)
  ------------------
  |  Branch (121:7): [True: 0, False: 121]
  ------------------
  122|      0|			goto fail;
  123|    121|	}
  124|       |	/* Success */
  125|    121|	r = 0;
  126|    121| fail:
  127|    121|	freezero(s, slen);
  128|    121|	return r;
  129|    121|}
sshbuf_dtourlb64:
  173|    121|{
  174|    121|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    121|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  175|    121|	u_char *p;
  176|    121|	struct sshbuf *b = NULL;
  177|    121|	size_t i, l;
  178|       |
  179|    121|	if ((b = sshbuf_new()) == NULL)
  ------------------
  |  Branch (179:6): [True: 0, False: 121]
  ------------------
  180|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  181|       |	/* Encode using regular base64; we'll transform it once done */
  182|    121|	if ((r = sshbuf_dtob64(d, b, wrap)) != 0)
  ------------------
  |  Branch (182:6): [True: 0, False: 121]
  ------------------
  183|      0|		goto out;
  184|       |	/* remove padding from end of encoded string*/
  185|    264|	for (;;) {
  186|    264|		l = sshbuf_len(b);
  187|    264|		if (l <= 1 || sshbuf_ptr(b) == NULL) {
  ------------------
  |  Branch (187:7): [True: 0, False: 264]
  |  Branch (187:17): [True: 0, False: 264]
  ------------------
  188|      0|			r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  189|      0|			goto out;
  190|      0|		}
  191|    264|		if (sshbuf_ptr(b)[l - 1] != '=')
  ------------------
  |  Branch (191:7): [True: 121, False: 143]
  ------------------
  192|    121|			break;
  193|    143|		if ((r = sshbuf_consume_end(b, 1)) != 0)
  ------------------
  |  Branch (193:7): [True: 0, False: 143]
  ------------------
  194|      0|			goto out;
  195|    143|	}
  196|       |	/* Replace characters with rfc4648 equivalents */
  197|    121|	l = sshbuf_len(b);
  198|    121|	if ((p = sshbuf_mutable_ptr(b)) == NULL) {
  ------------------
  |  Branch (198:6): [True: 0, False: 121]
  ------------------
  199|      0|		r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  200|      0|		goto out;
  201|      0|	}
  202|  1.99M|	for (i = 0; i < l; i++) {
  ------------------
  |  Branch (202:14): [True: 1.99M, False: 121]
  ------------------
  203|  1.99M|		if (p[i] == '+')
  ------------------
  |  Branch (203:7): [True: 13.1k, False: 1.97M]
  ------------------
  204|  13.1k|			p[i] = '-';
  205|  1.97M|		else if (p[i] == '/')
  ------------------
  |  Branch (205:12): [True: 85.4k, False: 1.89M]
  ------------------
  206|  85.4k|			p[i] = '_';
  207|  1.99M|	}
  208|    121|	r = sshbuf_putb(b64, b);
  209|    121| out:
  210|    121|	sshbuf_free(b);
  211|    121|	return r;
  212|    121|}
sshbuf_cmp:
  240|    121|{
  241|    121|	if (sshbuf_ptr(b) == NULL)
  ------------------
  |  Branch (241:6): [True: 0, False: 121]
  ------------------
  242|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  243|    121|	if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
  ------------------
  |  |   31|    242|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
              	if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
  ------------------
  |  |   31|    242|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  |  Branch (243:6): [True: 0, False: 121]
  |  Branch (243:34): [True: 0, False: 121]
  |  Branch (243:59): [True: 0, False: 121]
  ------------------
  244|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  245|    121|	if (offset + len > sshbuf_len(b))
  ------------------
  |  Branch (245:6): [True: 107, False: 14]
  ------------------
  246|    107|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    107|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  247|     14|	if (timingsafe_bcmp(sshbuf_ptr(b) + offset, s, len) != 0)
  ------------------
  |  Branch (247:6): [True: 14, False: 0]
  ------------------
  248|     14|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     14|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  249|      0|	return 0;
  250|     14|}

sshbuf_new:
   93|  6.26k|{
   94|  6.26k|	struct sshbuf *ret;
   95|       |
   96|  6.26k|	if ((ret = calloc(sizeof(*ret), 1)) == NULL)
  ------------------
  |  Branch (96:6): [True: 0, False: 6.26k]
  ------------------
   97|      0|		return NULL;
   98|  6.26k|	ret->alloc = SSHBUF_SIZE_INIT;
  ------------------
  |  |  370|  6.26k|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
   99|  6.26k|	ret->max_size = SSHBUF_SIZE_MAX;
  ------------------
  |  |   31|  6.26k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  100|  6.26k|	ret->readonly = 0;
  101|  6.26k|	ret->refcount = 1;
  102|  6.26k|	ret->parent = NULL;
  103|  6.26k|	if ((ret->cd = ret->d = calloc(1, ret->alloc)) == NULL) {
  ------------------
  |  Branch (103:6): [True: 0, False: 6.26k]
  ------------------
  104|      0|		free(ret);
  105|      0|		return NULL;
  106|      0|	}
  107|  6.26k|	return ret;
  108|  6.26k|}
sshbuf_from:
  112|  19.5k|{
  113|  19.5k|	struct sshbuf *ret;
  114|       |
  115|  19.5k|	if (blob == NULL || len > SSHBUF_SIZE_MAX ||
  ------------------
  |  |   31|  39.0k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  |  Branch (115:6): [True: 0, False: 19.5k]
  |  Branch (115:22): [True: 0, False: 19.5k]
  ------------------
  116|  19.5k|	    (ret = calloc(sizeof(*ret), 1)) == NULL)
  ------------------
  |  Branch (116:6): [True: 0, False: 19.5k]
  ------------------
  117|      0|		return NULL;
  118|  19.5k|	ret->alloc = ret->size = ret->max_size = len;
  119|  19.5k|	ret->readonly = 1;
  120|  19.5k|	ret->refcount = 1;
  121|  19.5k|	ret->parent = NULL;
  122|  19.5k|	ret->cd = blob;
  123|  19.5k|	ret->d = NULL;
  124|  19.5k|	return ret;
  125|  19.5k|}
sshbuf_set_parent:
  129|  13.7k|{
  130|  13.7k|	int r;
  131|       |
  132|  13.7k|	if ((r = sshbuf_check_sanity(child)) != 0 ||
  ------------------
  |  Branch (132:6): [True: 0, False: 13.7k]
  ------------------
  133|  13.7k|	    (r = sshbuf_check_sanity(parent)) != 0)
  ------------------
  |  Branch (133:6): [True: 0, False: 13.7k]
  ------------------
  134|      0|		return r;
  135|  13.7k|	if (child->parent != NULL && child->parent != parent)
  ------------------
  |  Branch (135:6): [True: 0, False: 13.7k]
  |  Branch (135:31): [True: 0, False: 0]
  ------------------
  136|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  137|  13.7k|	child->parent = parent;
  138|  13.7k|	child->parent->refcount++;
  139|  13.7k|	return 0;
  140|  13.7k|}
sshbuf_fromb:
  144|  3.83k|{
  145|  3.83k|	struct sshbuf *ret;
  146|       |
  147|  3.83k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (147:6): [True: 0, False: 3.83k]
  ------------------
  148|      0|		return NULL;
  149|  3.83k|	if ((ret = sshbuf_from(sshbuf_ptr(buf), sshbuf_len(buf))) == NULL)
  ------------------
  |  Branch (149:6): [True: 0, False: 3.83k]
  ------------------
  150|      0|		return NULL;
  151|  3.83k|	if (sshbuf_set_parent(ret, buf) != 0) {
  ------------------
  |  Branch (151:6): [True: 0, False: 3.83k]
  ------------------
  152|      0|		sshbuf_free(ret);
  153|      0|		return NULL;
  154|      0|	}
  155|  3.83k|	return ret;
  156|  3.83k|}
sshbuf_free:
  160|  54.4k|{
  161|  54.4k|	if (buf == NULL)
  ------------------
  |  Branch (161:6): [True: 14.8k, False: 39.5k]
  ------------------
  162|  14.8k|		return;
  163|       |	/*
  164|       |	 * The following will leak on insane buffers, but this is the safest
  165|       |	 * course of action - an invalid pointer or already-freed pointer may
  166|       |	 * have been passed to us and continuing to scribble over memory would
  167|       |	 * be bad.
  168|       |	 */
  169|  39.5k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (169:6): [True: 0, False: 39.5k]
  ------------------
  170|      0|		return;
  171|       |
  172|       |	/*
  173|       |	 * If we are a parent with still-extant children, then don't free just
  174|       |	 * yet. The last child's call to sshbuf_free should decrement our
  175|       |	 * refcount to 0 and trigger the actual free.
  176|       |	 */
  177|  39.5k|	buf->refcount--;
  178|  39.5k|	if (buf->refcount > 0)
  ------------------
  |  Branch (178:6): [True: 13.7k, False: 25.7k]
  ------------------
  179|  13.7k|		return;
  180|       |
  181|       |	/*
  182|       |	 * If we are a child, the free our parent to decrement its reference
  183|       |	 * count and possibly free it.
  184|       |	 */
  185|  25.7k|	sshbuf_free(buf->parent);
  186|  25.7k|	buf->parent = NULL;
  187|       |
  188|  25.7k|	if (!buf->readonly) {
  ------------------
  |  Branch (188:6): [True: 6.26k, False: 19.5k]
  ------------------
  189|  6.26k|		explicit_bzero(buf->d, buf->alloc);
  190|  6.26k|		free(buf->d);
  191|  6.26k|	}
  192|  25.7k|	freezero(buf, sizeof(*buf));
  193|  25.7k|}
sshbuf_reset:
  197|     84|{
  198|     84|	u_char *d;
  199|       |
  200|     84|	if (buf->readonly || buf->refcount > 1) {
  ------------------
  |  Branch (200:6): [True: 0, False: 84]
  |  Branch (200:23): [True: 0, False: 84]
  ------------------
  201|       |		/* Nonsensical. Just make buffer appear empty */
  202|      0|		buf->off = buf->size;
  203|      0|		return;
  204|      0|	}
  205|     84|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (205:6): [True: 0, False: 84]
  ------------------
  206|      0|		return;
  207|     84|	buf->off = buf->size = 0;
  208|     84|	if (buf->alloc != SSHBUF_SIZE_INIT) {
  ------------------
  |  |  370|     84|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  |  Branch (208:6): [True: 58, False: 26]
  ------------------
  209|     58|		if ((d = recallocarray(buf->d, buf->alloc, SSHBUF_SIZE_INIT,
  ------------------
  |  |  370|     58|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  |  Branch (209:7): [True: 58, False: 0]
  ------------------
  210|     58|		    1)) != NULL) {
  211|     58|			buf->cd = buf->d = d;
  212|     58|			buf->alloc = SSHBUF_SIZE_INIT;
  ------------------
  |  |  370|     58|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  213|     58|		}
  214|     58|	}
  215|     84|	explicit_bzero(buf->d, buf->alloc);
  216|     84|}
sshbuf_len:
  282|   233k|{
  283|   233k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (283:6): [True: 0, False: 233k]
  ------------------
  284|      0|		return 0;
  285|   233k|	return buf->size - buf->off;
  286|   233k|}
sshbuf_ptr:
  298|  94.0k|{
  299|  94.0k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (299:6): [True: 0, False: 94.0k]
  ------------------
  300|      0|		return NULL;
  301|  94.0k|	return buf->cd + buf->off;
  302|  94.0k|}
sshbuf_mutable_ptr:
  306|    121|{
  307|    121|	if (sshbuf_check_sanity(buf) != 0 || buf->readonly || buf->refcount > 1)
  ------------------
  |  Branch (307:6): [True: 0, False: 121]
  |  Branch (307:39): [True: 0, False: 121]
  |  Branch (307:56): [True: 0, False: 121]
  ------------------
  308|      0|		return NULL;
  309|    121|	return buf->d + buf->off;
  310|    121|}
sshbuf_check_reserve:
  314|  7.12k|{
  315|  7.12k|	int r;
  316|       |
  317|  7.12k|	if ((r = sshbuf_check_sanity(buf)) != 0)
  ------------------
  |  Branch (317:6): [True: 0, False: 7.12k]
  ------------------
  318|      0|		return r;
  319|  7.12k|	if (buf->readonly || buf->refcount > 1)
  ------------------
  |  Branch (319:6): [True: 0, False: 7.12k]
  |  Branch (319:23): [True: 0, False: 7.12k]
  ------------------
  320|      0|		return SSH_ERR_BUFFER_READ_ONLY;
  ------------------
  |  |   73|      0|#define SSH_ERR_BUFFER_READ_ONLY		-49
  ------------------
  321|  7.12k|	SSHBUF_TELL("check");
  322|       |	/* Check that len is reasonable and that max_size + available < len */
  323|  7.12k|	if (len > buf->max_size || buf->max_size - len < buf->size - buf->off)
  ------------------
  |  Branch (323:6): [True: 0, False: 7.12k]
  |  Branch (323:29): [True: 0, False: 7.12k]
  ------------------
  324|      0|		return SSH_ERR_NO_BUFFER_SPACE;
  ------------------
  |  |   33|      0|#define SSH_ERR_NO_BUFFER_SPACE			-9
  ------------------
  325|  7.12k|	return 0;
  326|  7.12k|}
sshbuf_allocate:
  330|  6.01k|{
  331|  6.01k|	size_t rlen, need;
  332|  6.01k|	u_char *dp;
  333|  6.01k|	int r;
  334|       |
  335|  6.01k|	SSHBUF_DBG(("allocate buf = %p len = %zu", buf, len));
  336|  6.01k|	if ((r = sshbuf_check_reserve(buf, len)) != 0)
  ------------------
  |  Branch (336:6): [True: 0, False: 6.01k]
  ------------------
  337|      0|		return r;
  338|       |	/*
  339|       |	 * If the requested allocation appended would push us past max_size
  340|       |	 * then pack the buffer, zeroing buf->off.
  341|       |	 */
  342|  6.01k|	sshbuf_maybe_pack(buf, buf->size + len > buf->max_size);
  343|  6.01k|	SSHBUF_TELL("allocate");
  344|  6.01k|	if (len + buf->size <= buf->alloc)
  ------------------
  |  Branch (344:6): [True: 4.89k, False: 1.11k]
  ------------------
  345|  4.89k|		return 0; /* already have it. */
  346|       |
  347|       |	/*
  348|       |	 * Prefer to alloc in SSHBUF_SIZE_INC units, but
  349|       |	 * allocate less if doing so would overflow max_size.
  350|       |	 */
  351|  1.11k|	need = len + buf->size - buf->alloc;
  352|  1.11k|	rlen = ROUNDUP(buf->alloc + need, SSHBUF_SIZE_INC);
  ------------------
  |  |  238|  1.11k|#define ROUNDUP(x, y)   ((((x)+((y)-1))/(y))*(y))
  ------------------
  353|  1.11k|	SSHBUF_DBG(("need %zu initial rlen %zu", need, rlen));
  354|  1.11k|	if (rlen > buf->max_size)
  ------------------
  |  Branch (354:6): [True: 0, False: 1.11k]
  ------------------
  355|      0|		rlen = buf->alloc + need;
  356|  1.11k|	SSHBUF_DBG(("adjusted rlen %zu", rlen));
  357|  1.11k|	if ((dp = recallocarray(buf->d, buf->alloc, rlen, 1)) == NULL) {
  ------------------
  |  Branch (357:6): [True: 0, False: 1.11k]
  ------------------
  358|      0|		SSHBUF_DBG(("realloc fail"));
  359|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  360|      0|	}
  361|  1.11k|	buf->alloc = rlen;
  362|  1.11k|	buf->cd = buf->d = dp;
  363|  1.11k|	if ((r = sshbuf_check_reserve(buf, len)) < 0) {
  ------------------
  |  Branch (363:6): [True: 0, False: 1.11k]
  ------------------
  364|       |		/* shouldn't fail */
  365|      0|		return r;
  366|      0|	}
  367|  1.11k|	SSHBUF_TELL("done");
  368|  1.11k|	return 0;
  369|  1.11k|}
sshbuf_reserve:
  373|  6.01k|{
  374|  6.01k|	u_char *dp;
  375|  6.01k|	int r;
  376|       |
  377|  6.01k|	if (dpp != NULL)
  ------------------
  |  Branch (377:6): [True: 6.01k, False: 0]
  ------------------
  378|  6.01k|		*dpp = NULL;
  379|       |
  380|  6.01k|	SSHBUF_DBG(("reserve buf = %p len = %zu", buf, len));
  381|  6.01k|	if ((r = sshbuf_allocate(buf, len)) != 0)
  ------------------
  |  Branch (381:6): [True: 0, False: 6.01k]
  ------------------
  382|      0|		return r;
  383|       |
  384|  6.01k|	dp = buf->d + buf->size;
  385|  6.01k|	buf->size += len;
  386|  6.01k|	if (dpp != NULL)
  ------------------
  |  Branch (386:6): [True: 6.01k, False: 0]
  ------------------
  387|  6.01k|		*dpp = dp;
  388|  6.01k|	return 0;
  389|  6.01k|}
sshbuf_consume:
  393|  62.5k|{
  394|  62.5k|	int r;
  395|       |
  396|  62.5k|	SSHBUF_DBG(("len = %zu", len));
  397|  62.5k|	if ((r = sshbuf_check_sanity(buf)) != 0)
  ------------------
  |  Branch (397:6): [True: 0, False: 62.5k]
  ------------------
  398|      0|		return r;
  399|  62.5k|	if (len == 0)
  ------------------
  |  Branch (399:6): [True: 54, False: 62.4k]
  ------------------
  400|     54|		return 0;
  401|  62.4k|	if (len > sshbuf_len(buf))
  ------------------
  |  Branch (401:6): [True: 123, False: 62.3k]
  ------------------
  402|    123|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    123|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  403|  62.3k|	buf->off += len;
  404|       |	/* deal with empty buffer */
  405|  62.3k|	if (buf->off == buf->size)
  ------------------
  |  Branch (405:6): [True: 7.32k, False: 55.0k]
  ------------------
  406|  7.32k|		buf->off = buf->size = 0;
  407|  62.3k|	SSHBUF_TELL("done");
  408|  62.3k|	return 0;
  409|  62.4k|}
sshbuf_consume_end:
  413|    143|{
  414|    143|	int r;
  415|       |
  416|    143|	SSHBUF_DBG(("len = %zu", len));
  417|    143|	if ((r = sshbuf_check_sanity(buf)) != 0)
  ------------------
  |  Branch (417:6): [True: 0, False: 143]
  ------------------
  418|      0|		return r;
  419|    143|	if (len == 0)
  ------------------
  |  Branch (419:6): [True: 0, False: 143]
  ------------------
  420|      0|		return 0;
  421|    143|	if (len > sshbuf_len(buf))
  ------------------
  |  Branch (421:6): [True: 0, False: 143]
  ------------------
  422|      0|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|      0|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  423|    143|	buf->size -= len;
  424|    143|	SSHBUF_TELL("done");
  425|    143|	return 0;
  426|    143|}
sshbuf.c:sshbuf_check_sanity:
   56|   468k|{
   57|   468k|	SSHBUF_TELL("sanity");
   58|   468k|	if (__predict_false(buf == NULL ||
  ------------------
  |  |  924|  7.98M|#  define __predict_false(exp)    __builtin_expect(((exp) != 0), 0)
  |  |  ------------------
  |  |  |  Branch (924:35): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 18.5k, False: 449k]
  |  |  |  Branch (924:54): [True: 0, False: 18.5k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  |  Branch (924:54): [True: 0, False: 468k]
  |  |  ------------------
  ------------------
   59|   468k|	    (!buf->readonly && buf->d != buf->cd) ||
   60|   468k|	    buf->refcount < 1 || buf->refcount > SSHBUF_REFS_MAX ||
   61|   468k|	    buf->cd == NULL ||
   62|   468k|	    buf->max_size > SSHBUF_SIZE_MAX ||
   63|   468k|	    buf->alloc > buf->max_size ||
   64|   468k|	    buf->size > buf->alloc ||
   65|   468k|	    buf->off > buf->size)) {
   66|       |		/* Do not try to recover from corrupted buffer internals */
   67|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
   68|      0|		ssh_signal(SIGSEGV, SIG_DFL);
   69|      0|		raise(SIGSEGV);
   70|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
   71|      0|	}
   72|   468k|	return 0;
   73|   468k|}
sshbuf.c:sshbuf_maybe_pack:
   77|  6.01k|{
   78|  6.01k|	SSHBUF_DBG(("force %d", force));
   79|  6.01k|	SSHBUF_TELL("pre-pack");
   80|  6.01k|	if (buf->off == 0 || buf->readonly || buf->refcount > 1)
  ------------------
  |  Branch (80:6): [True: 6.01k, False: 0]
  |  Branch (80:23): [True: 0, False: 0]
  |  Branch (80:40): [True: 0, False: 0]
  ------------------
   81|  6.01k|		return;
   82|      0|	if (force ||
  ------------------
  |  Branch (82:6): [True: 0, False: 0]
  ------------------
   83|      0|	    (buf->off >= SSHBUF_PACK_MIN && buf->off >= buf->size / 2)) {
  ------------------
  |  |  372|      0|# define SSHBUF_PACK_MIN	8192		/* Minimum packable offset */
  ------------------
  |  Branch (83:7): [True: 0, False: 0]
  |  Branch (83:38): [True: 0, False: 0]
  ------------------
   84|      0|		memmove(buf->d, buf->d + buf->off, buf->size - buf->off);
   85|      0|		buf->size -= buf->off;
   86|      0|		buf->off = 0;
   87|      0|		SSHBUF_TELL("packed");
   88|      0|	}
   89|      0|}

sshkey_xmss_init:
   96|    897|{
   97|    897|	struct ssh_xmss_state *state;
   98|       |
   99|    897|	if (key->xmss_state != NULL)
  ------------------
  |  Branch (99:6): [True: 0, False: 897]
  ------------------
  100|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  101|    897|	if (name == NULL)
  ------------------
  |  Branch (101:6): [True: 0, False: 897]
  ------------------
  102|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  103|    897|	state = calloc(sizeof(struct ssh_xmss_state), 1);
  104|    897|	if (state == NULL)
  ------------------
  |  Branch (104:6): [True: 0, False: 897]
  ------------------
  105|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  106|    897|	if (strcmp(name, XMSS_SHA2_256_W16_H10_NAME) == 0) {
  ------------------
  |  |   28|    897|#define XMSS_SHA2_256_W16_H10_NAME	"XMSS_SHA2-256_W16_H10"
  ------------------
  |  Branch (106:6): [True: 571, False: 326]
  ------------------
  107|    571|		state->n = 32;
  108|    571|		state->w = 16;
  109|    571|		state->h = 10;
  110|    571|	} else if (strcmp(name, XMSS_SHA2_256_W16_H16_NAME) == 0) {
  ------------------
  |  |   29|    326|#define XMSS_SHA2_256_W16_H16_NAME	"XMSS_SHA2-256_W16_H16"
  ------------------
  |  Branch (110:13): [True: 107, False: 219]
  ------------------
  111|    107|		state->n = 32;
  112|    107|		state->w = 16;
  113|    107|		state->h = 16;
  114|    219|	} else if (strcmp(name, XMSS_SHA2_256_W16_H20_NAME) == 0) {
  ------------------
  |  |   30|    219|#define XMSS_SHA2_256_W16_H20_NAME	"XMSS_SHA2-256_W16_H20"
  ------------------
  |  Branch (114:13): [True: 61, False: 158]
  ------------------
  115|     61|		state->n = 32;
  116|     61|		state->w = 16;
  117|     61|		state->h = 20;
  118|    158|	} else {
  119|    158|		free(state);
  120|    158|		return SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|    158|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
  121|    158|	}
  122|    739|	if ((key->xmss_name = strdup(name)) == NULL) {
  ------------------
  |  Branch (122:6): [True: 0, False: 739]
  ------------------
  123|      0|		free(state);
  124|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  125|      0|	}
  126|    739|	state->k = 2;	/* XXX hardcoded */
  127|    739|	state->lockfd = -1;
  128|    739|	if (xmss_set_params(&state->params, state->n, state->h, state->w,
  ------------------
  |  Branch (128:6): [True: 0, False: 739]
  ------------------
  129|    739|	    state->k) != 0) {
  130|      0|		free(state);
  131|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  132|      0|	}
  133|    739|	key->xmss_state = state;
  134|    739|	return 0;
  135|    739|}
sshkey_xmss_free_state:
  139|    912|{
  140|    912|	struct ssh_xmss_state *state = key->xmss_state;
  141|       |
  142|    912|	sshkey_xmss_free_bds(key);
  143|    912|	if (state) {
  ------------------
  |  Branch (143:6): [True: 739, False: 173]
  ------------------
  144|    739|		if (state->enc_keyiv) {
  ------------------
  |  Branch (144:7): [True: 6, False: 733]
  ------------------
  145|      6|			explicit_bzero(state->enc_keyiv, state->enc_keyiv_len);
  146|      6|			free(state->enc_keyiv);
  147|      6|		}
  148|    739|		free(state->enc_ciphername);
  149|    739|		free(state);
  150|    739|	}
  151|    912|	key->xmss_state = NULL;
  152|    912|}
sshkey_xmss_free_bds:
  191|    912|{
  192|    912|	struct ssh_xmss_state *state = key->xmss_state;
  193|       |
  194|    912|	if (state == NULL)
  ------------------
  |  Branch (194:6): [True: 173, False: 739]
  ------------------
  195|    173|		return;
  196|    739|	free(state->stack);
  197|    739|	free(state->stacklevels);
  198|    739|	free(state->auth);
  199|    739|	free(state->keep);
  200|    739|	free(state->th_nodes);
  201|    739|	free(state->retain);
  202|    739|	free(state->treehash);
  203|    739|	state->stack = NULL;
  204|    739|	state->stacklevels = NULL;
  205|    739|	state->auth = NULL;
  206|    739|	state->keep = NULL;
  207|    739|	state->th_nodes = NULL;
  208|    739|	state->retain = NULL;
  209|    739|	state->treehash = NULL;
  210|    739|}
sshkey_xmss_params:
  214|    180|{
  215|    180|	struct ssh_xmss_state *state = key->xmss_state;
  216|       |
  217|    180|	if (state == NULL)
  ------------------
  |  Branch (217:6): [True: 0, False: 180]
  ------------------
  218|      0|		return NULL;
  219|    180|	return &state->params;
  220|    180|}
sshkey_xmss_siglen:
  234|    180|{
  235|    180|	struct ssh_xmss_state *state = key->xmss_state;
  236|       |
  237|    180|	if (lenp == NULL)
  ------------------
  |  Branch (237:6): [True: 0, False: 180]
  ------------------
  238|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  239|    180|	if (state == NULL)
  ------------------
  |  Branch (239:6): [True: 0, False: 180]
  ------------------
  240|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  241|    180|	*lenp = 4 + state->n +
  242|    180|	    state->params.wots_par.keysize +
  243|    180|	    state->h * state->n;
  244|    180|	return 0;
  245|    180|}
sshkey_xmss_pklen:
  249|  1.64k|{
  250|  1.64k|	struct ssh_xmss_state *state = key->xmss_state;
  251|       |
  252|  1.64k|	if (state == NULL)
  ------------------
  |  Branch (252:6): [True: 173, False: 1.47k]
  ------------------
  253|    173|		return 0;
  254|  1.47k|	return state->n * 2;
  255|  1.64k|}
sshkey_xmss_sklen:
  259|  1.34k|{
  260|  1.34k|	struct ssh_xmss_state *state = key->xmss_state;
  261|       |
  262|  1.34k|	if (state == NULL)
  ------------------
  |  Branch (262:6): [True: 173, False: 1.17k]
  ------------------
  263|    173|		return 0;
  264|  1.17k|	return state->n * 4 + 4;
  265|  1.34k|}
sshkey_xmss_deserialize_enc_key:
  310|     21|{
  311|     21|	struct ssh_xmss_state *state = k->xmss_state;
  312|     21|	size_t len;
  313|     21|	int r;
  314|       |
  315|     21|	if (state == NULL)
  ------------------
  |  Branch (315:6): [True: 0, False: 21]
  ------------------
  316|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  317|     21|	if ((r = sshbuf_get_cstring(b, &state->enc_ciphername, NULL)) != 0 ||
  ------------------
  |  Branch (317:6): [True: 11, False: 10]
  ------------------
  318|     21|	    (r = sshbuf_get_string(b, &state->enc_keyiv, &len)) != 0)
  ------------------
  |  Branch (318:6): [True: 4, False: 6]
  ------------------
  319|     15|		return r;
  320|      6|	state->enc_keyiv_len = len;
  321|      6|	return 0;
  322|     21|}
sshkey_xmss_deserialize_pk_info:
  347|    214|{
  348|    214|	struct ssh_xmss_state *state = k->xmss_state;
  349|    214|	u_char have_info;
  350|    214|	int r;
  351|       |
  352|    214|	if (state == NULL)
  ------------------
  |  Branch (352:6): [True: 0, False: 214]
  ------------------
  353|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  354|       |	/* optional */
  355|    214|	if (sshbuf_len(b) == 0)
  ------------------
  |  Branch (355:6): [True: 161, False: 53]
  ------------------
  356|    161|		return 0;
  357|     53|	if ((r = sshbuf_get_u8(b, &have_info)) != 0)
  ------------------
  |  Branch (357:6): [True: 0, False: 53]
  ------------------
  358|      0|		return r;
  359|     53|	if (have_info != 1)
  ------------------
  |  Branch (359:6): [True: 23, False: 30]
  ------------------
  360|     23|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|     23|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  361|     30|	if ((r = sshbuf_get_u32(b, &state->idx)) != 0 ||
  ------------------
  |  Branch (361:6): [True: 2, False: 28]
  ------------------
  362|     30|	    (r = sshbuf_get_u32(b, &state->maxidx)) != 0)
  ------------------
  |  Branch (362:6): [True: 3, False: 25]
  ------------------
  363|      5|		return r;
  364|     25|	return 0;
  365|     30|}
sshkey_xmss_deserialize_state:
  773|    363|{
  774|    363|	struct ssh_xmss_state *state = k->xmss_state;
  775|    363|	treehash_inst *th;
  776|    363|	u_int32_t i, lh, node;
  777|    363|	size_t ls, lsl, la, lk, ln, lr;
  778|    363|	char *magic;
  779|    363|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    363|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  780|       |
  781|    363|	if (state == NULL)
  ------------------
  |  Branch (781:6): [True: 0, False: 363]
  ------------------
  782|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  783|    363|	if (k->xmss_sk == NULL)
  ------------------
  |  Branch (783:6): [True: 0, False: 363]
  ------------------
  784|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  785|    363|	if ((state->treehash = calloc(num_treehash(state),
  ------------------
  |  |  161|    363|#define num_treehash(x)		((x->h) - (x->k))
  ------------------
  |  Branch (785:6): [True: 0, False: 363]
  ------------------
  786|    363|	    sizeof(treehash_inst))) == NULL)
  787|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  788|    363|	if ((r = sshbuf_get_cstring(b, &magic, NULL)) != 0 ||
  ------------------
  |  Branch (788:6): [True: 12, False: 351]
  ------------------
  789|    363|	    (r = sshbuf_get_u32(b, &state->idx)) != 0 ||
  ------------------
  |  Branch (789:6): [True: 1, False: 350]
  ------------------
  790|    363|	    (r = sshbuf_get_string(b, &state->stack, &ls)) != 0 ||
  ------------------
  |  Branch (790:6): [True: 2, False: 348]
  ------------------
  791|    363|	    (r = sshbuf_get_u32(b, &state->stackoffset)) != 0 ||
  ------------------
  |  Branch (791:6): [True: 12, False: 336]
  ------------------
  792|    363|	    (r = sshbuf_get_string(b, &state->stacklevels, &lsl)) != 0 ||
  ------------------
  |  Branch (792:6): [True: 3, False: 333]
  ------------------
  793|    363|	    (r = sshbuf_get_string(b, &state->auth, &la)) != 0 ||
  ------------------
  |  Branch (793:6): [True: 4, False: 329]
  ------------------
  794|    363|	    (r = sshbuf_get_string(b, &state->keep, &lk)) != 0 ||
  ------------------
  |  Branch (794:6): [True: 4, False: 325]
  ------------------
  795|    363|	    (r = sshbuf_get_string(b, &state->th_nodes, &ln)) != 0 ||
  ------------------
  |  Branch (795:6): [True: 2, False: 323]
  ------------------
  796|    363|	    (r = sshbuf_get_string(b, &state->retain, &lr)) != 0 ||
  ------------------
  |  Branch (796:6): [True: 3, False: 320]
  ------------------
  797|    363|	    (r = sshbuf_get_u32(b, &lh)) != 0)
  ------------------
  |  Branch (797:6): [True: 10, False: 310]
  ------------------
  798|     53|		goto out;
  799|    310|	if (strcmp(magic, SSH_XMSS_K2_MAGIC) != 0) {
  ------------------
  |  |  154|    310|#define SSH_XMSS_K2_MAGIC	"k=2"
  ------------------
  |  Branch (799:6): [True: 29, False: 281]
  ------------------
  800|     29|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|     29|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  801|     29|		goto out;
  802|     29|	}
  803|       |	/* XXX check stackoffset */
  804|    281|	if (ls != num_stack(state) ||
  ------------------
  |  |  155|    562|#define num_stack(x)		((x->h+1)*(x->n))
  ------------------
  |  Branch (804:6): [True: 38, False: 243]
  ------------------
  805|    281|	    lsl != num_stacklevels(state) ||
  ------------------
  |  |  156|    524|#define num_stacklevels(x)	(x->h+1)
  ------------------
  |  Branch (805:6): [True: 37, False: 206]
  ------------------
  806|    281|	    la != num_auth(state) ||
  ------------------
  |  |  157|    487|#define num_auth(x)		((x->h)*(x->n))
  ------------------
  |  Branch (806:6): [True: 26, False: 180]
  ------------------
  807|    281|	    lk != num_keep(state) ||
  ------------------
  |  |  158|    461|#define num_keep(x)		((x->h >> 1)*(x->n))
  ------------------
  |  Branch (807:6): [True: 37, False: 143]
  ------------------
  808|    281|	    ln != num_th_nodes(state) ||
  ------------------
  |  |  159|    424|#define num_th_nodes(x)		((x->h - x->k)*(x->n))
  ------------------
  |  Branch (808:6): [True: 38, False: 105]
  ------------------
  809|    281|	    lr != num_retain(state) ||
  ------------------
  |  |  160|    386|#define num_retain(x)		(((1ULL << x->k) - x->k - 1) * (x->n))
  ------------------
  |  Branch (809:6): [True: 37, False: 68]
  ------------------
  810|    281|	    lh != num_treehash(state)) {
  ------------------
  |  |  161|     68|#define num_treehash(x)		((x->h) - (x->k))
  ------------------
  |  Branch (810:6): [True: 2, False: 66]
  ------------------
  811|    215|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|    215|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  812|    215|		goto out;
  813|    215|	}
  814|    196|	for (i = 0; i < num_treehash(state); i++) {
  ------------------
  |  |  161|    196|#define num_treehash(x)		((x->h) - (x->k))
  ------------------
  |  Branch (814:14): [True: 191, False: 5]
  ------------------
  815|    191|		th = &state->treehash[i];
  816|    191|		if ((r = sshbuf_get_u32(b, &th->h)) != 0 ||
  ------------------
  |  Branch (816:7): [True: 52, False: 139]
  ------------------
  817|    191|		    (r = sshbuf_get_u32(b, &th->next_idx)) != 0 ||
  ------------------
  |  Branch (817:7): [True: 4, False: 135]
  ------------------
  818|    191|		    (r = sshbuf_get_u32(b, &th->stackusage)) != 0 ||
  ------------------
  |  Branch (818:7): [True: 1, False: 134]
  ------------------
  819|    191|		    (r = sshbuf_get_u8(b, &th->completed)) != 0 ||
  ------------------
  |  Branch (819:7): [True: 2, False: 132]
  ------------------
  820|    191|		    (r = sshbuf_get_u32(b, &node)) != 0)
  ------------------
  |  Branch (820:7): [True: 2, False: 130]
  ------------------
  821|     61|			goto out;
  822|    130|		if (node < num_th_nodes(state))
  ------------------
  |  |  159|    130|#define num_th_nodes(x)		((x->h - x->k)*(x->n))
  ------------------
  |  Branch (822:7): [True: 38, False: 92]
  ------------------
  823|     38|			th->node = &state->th_nodes[node];
  824|    130|	}
  825|      5|	POKE_U32(k->xmss_sk, state->idx);
  ------------------
  |  |  333|      5|	do { \
  |  |  334|      5|		const u_int32_t __v = (v); \
  |  |  335|      5|		((u_char *)(p))[0] = (__v >> 24) & 0xff; \
  |  |  336|      5|		((u_char *)(p))[1] = (__v >> 16) & 0xff; \
  |  |  337|      5|		((u_char *)(p))[2] = (__v >> 8) & 0xff; \
  |  |  338|      5|		((u_char *)(p))[3] = __v & 0xff; \
  |  |  339|      5|	} while (0)
  |  |  ------------------
  |  |  |  Branch (339:11): [Folded - Ignored]
  |  |  ------------------
  ------------------
  826|      5|	xmss_set_bds_state(&state->bds, state->stack, state->stackoffset,
  827|      5|	    state->stacklevels, state->auth, state->keep, state->treehash,
  828|      5|	    state->retain, 0);
  829|       |	/* success */
  830|      5|	r = 0;
  831|    363| out:
  832|    363|	free(magic);
  833|    363|	return r;
  834|      5|}
sshkey_xmss_deserialize_state_opt:
  838|    399|{
  839|    399|	struct ssh_xmss_state *state = k->xmss_state;
  840|    399|	enum sshkey_serialize_rep opts;
  841|    399|	u_char have_state, have_stack, have_filename, have_enc;
  842|    399|	int r;
  843|       |
  844|    399|	if ((r = sshbuf_get_u8(b, &have_state)) != 0)
  ------------------
  |  Branch (844:6): [True: 1, False: 398]
  ------------------
  845|      1|		return r;
  846|       |
  847|    398|	opts = have_state;
  848|    398|	switch (opts) {
  849|      1|	case SSHKEY_SERIALIZE_DEFAULT:
  ------------------
  |  Branch (849:2): [True: 1, False: 397]
  ------------------
  850|      1|		r = 0;
  851|      1|		break;
  852|     81|	case SSHKEY_SERIALIZE_SHIELD:
  ------------------
  |  Branch (852:2): [True: 81, False: 317]
  ------------------
  853|     81|		if ((r = sshbuf_get_u8(b, &have_stack)) != 0)
  ------------------
  |  Branch (853:7): [True: 1, False: 80]
  ------------------
  854|      1|			return r;
  855|     80|		if (have_stack &&
  ------------------
  |  Branch (855:7): [True: 52, False: 28]
  ------------------
  856|     80|		    (r = sshkey_xmss_deserialize_state(k, b)) != 0)
  ------------------
  |  Branch (856:7): [True: 51, False: 1]
  ------------------
  857|     51|			return r;
  858|     29|		if ((r = sshbuf_get_u8(b, &have_filename)) != 0)
  ------------------
  |  Branch (858:7): [True: 2, False: 27]
  ------------------
  859|      2|			return r;
  860|     27|		if (have_filename &&
  ------------------
  |  Branch (860:7): [True: 12, False: 15]
  ------------------
  861|     27|		    (r = sshbuf_get_cstring(b, &k->xmss_filename, NULL)) != 0)
  ------------------
  |  Branch (861:7): [True: 9, False: 3]
  ------------------
  862|      9|			return r;
  863|     18|		if ((r = sshbuf_get_u8(b, &have_enc)) != 0)
  ------------------
  |  Branch (863:7): [True: 3, False: 15]
  ------------------
  864|      3|			return r;
  865|     15|		if (have_enc &&
  ------------------
  |  Branch (865:7): [True: 12, False: 3]
  ------------------
  866|     15|		    (r = sshkey_xmss_deserialize_enc_key(k, b)) != 0)
  ------------------
  |  Branch (866:7): [True: 11, False: 1]
  ------------------
  867|     11|			return r;
  868|      4|		if ((r = sshbuf_get_u32(b, &state->maxidx)) != 0 ||
  ------------------
  |  Branch (868:7): [True: 2, False: 2]
  ------------------
  869|      4|		    (r = sshbuf_get_u8(b, &state->allow_update)) != 0)
  ------------------
  |  Branch (869:7): [True: 1, False: 1]
  ------------------
  870|      3|			return r;
  871|      1|		break;
  872|    306|	case SSHKEY_SERIALIZE_STATE:
  ------------------
  |  Branch (872:2): [True: 306, False: 92]
  ------------------
  873|    306|		if ((r = sshkey_xmss_deserialize_state(k, b)) != 0)
  ------------------
  |  Branch (873:7): [True: 303, False: 3]
  ------------------
  874|    303|			return r;
  875|      3|		break;
  876|      9|	case SSHKEY_SERIALIZE_FULL:
  ------------------
  |  Branch (876:2): [True: 9, False: 389]
  ------------------
  877|      9|		if ((r = sshkey_xmss_deserialize_enc_key(k, b)) != 0 ||
  ------------------
  |  Branch (877:7): [True: 4, False: 5]
  ------------------
  878|      9|		    (r = sshkey_xmss_deserialize_state(k, b)) != 0)
  ------------------
  |  Branch (878:7): [True: 4, False: 1]
  ------------------
  879|      8|			return r;
  880|      1|		break;
  881|      1|	default:
  ------------------
  |  Branch (881:2): [True: 1, False: 397]
  ------------------
  882|      1|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      1|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  883|      1|		break;
  884|    398|	}
  885|      7|	return r;
  886|    398|}

sshkey_type_is_cert:
  225|  24.3k|{
  226|  24.3k|	const struct sshkey_impl *impl;
  227|       |
  228|  24.3k|	if ((impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (228:6): [True: 868, False: 23.5k]
  ------------------
  229|    868|		return 0;
  230|  23.5k|	return impl->cert;
  231|  24.3k|}
sshkey_ssh_name_plain:
  241|    303|{
  242|    303|	return sshkey_ssh_name_from_type_nid(sshkey_type_plain(k->type),
  243|    303|	    k->ecdsa_nid);
  244|    303|}
sshkey_type_from_name:
  248|  7.80k|{
  249|  7.80k|	int i;
  250|  7.80k|	const struct sshkey_impl *impl;
  251|       |
  252|   113k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (252:14): [True: 112k, False: 505]
  ------------------
  253|   112k|		impl = keyimpls[i];
  254|       |		/* Only allow shortname matches for plain key types */
  255|   112k|		if ((impl->name != NULL && strcmp(name, impl->name) == 0) ||
  ------------------
  |  Branch (255:8): [True: 112k, False: 0]
  |  Branch (255:30): [True: 5.34k, False: 107k]
  ------------------
  256|   112k|		    (!impl->cert && strcasecmp(impl->shortname, name) == 0))
  ------------------
  |  Branch (256:8): [True: 59.7k, False: 47.5k]
  |  Branch (256:23): [True: 1.95k, False: 57.7k]
  ------------------
  257|  7.30k|			return impl->type;
  258|   112k|	}
  259|    505|	return KEY_UNSPEC;
  260|  7.80k|}
sshkey_ecdsa_nid_from_name:
  277|    945|{
  278|    945|	int i;
  279|       |
  280|  7.92k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (280:14): [True: 7.90k, False: 14]
  ------------------
  281|  7.90k|		if (!key_type_is_ecdsa_variant(keyimpls[i]->type))
  ------------------
  |  Branch (281:7): [True: 3.92k, False: 3.98k]
  ------------------
  282|  3.92k|			continue;
  283|  3.98k|		if (keyimpls[i]->name != NULL &&
  ------------------
  |  Branch (283:7): [True: 3.98k, False: 0]
  ------------------
  284|  3.98k|		    strcmp(name, keyimpls[i]->name) == 0)
  ------------------
  |  Branch (284:7): [True: 931, False: 3.05k]
  ------------------
  285|    931|			return keyimpls[i]->nid;
  286|  3.98k|	}
  287|     14|	return -1;
  288|    945|}
sshkey_is_cert:
  407|  15.2k|{
  408|  15.2k|	if (k == NULL)
  ------------------
  |  Branch (408:6): [True: 0, False: 15.2k]
  ------------------
  409|      0|		return 0;
  410|  15.2k|	return sshkey_type_is_cert(k->type);
  411|  15.2k|}
sshkey_type_plain:
  430|  1.81k|{
  431|  1.81k|	switch (type) {
  432|      0|	case KEY_RSA_CERT:
  ------------------
  |  Branch (432:2): [True: 0, False: 1.81k]
  ------------------
  433|      0|		return KEY_RSA;
  434|      0|	case KEY_DSA_CERT:
  ------------------
  |  Branch (434:2): [True: 0, False: 1.81k]
  ------------------
  435|      0|		return KEY_DSA;
  436|      0|	case KEY_ECDSA_CERT:
  ------------------
  |  Branch (436:2): [True: 0, False: 1.81k]
  ------------------
  437|      0|		return KEY_ECDSA;
  438|      0|	case KEY_ECDSA_SK_CERT:
  ------------------
  |  Branch (438:2): [True: 0, False: 1.81k]
  ------------------
  439|      0|		return KEY_ECDSA_SK;
  440|      0|	case KEY_ED25519_CERT:
  ------------------
  |  Branch (440:2): [True: 0, False: 1.81k]
  ------------------
  441|      0|		return KEY_ED25519;
  442|      0|	case KEY_ED25519_SK_CERT:
  ------------------
  |  Branch (442:2): [True: 0, False: 1.81k]
  ------------------
  443|      0|		return KEY_ED25519_SK;
  444|      0|	case KEY_XMSS_CERT:
  ------------------
  |  Branch (444:2): [True: 0, False: 1.81k]
  ------------------
  445|      0|		return KEY_XMSS;
  446|  1.81k|	default:
  ------------------
  |  Branch (446:2): [True: 1.81k, False: 0]
  ------------------
  447|  1.81k|		return type;
  448|  1.81k|	}
  449|  1.81k|}
sshkey_curve_name_to_nid:
  479|    918|{
  480|    918|	if (strcmp(name, "nistp256") == 0)
  ------------------
  |  Branch (480:6): [True: 794, False: 124]
  ------------------
  481|    794|		return NID_X9_62_prime256v1;
  482|    124|	else if (strcmp(name, "nistp384") == 0)
  ------------------
  |  Branch (482:11): [True: 8, False: 116]
  ------------------
  483|      8|		return NID_secp384r1;
  484|    116|# ifdef OPENSSL_HAS_NISTP521
  485|    116|	else if (strcmp(name, "nistp521") == 0)
  ------------------
  |  Branch (485:11): [True: 1, False: 115]
  ------------------
  486|      1|		return NID_secp521r1;
  487|    115|# endif /* OPENSSL_HAS_NISTP521 */
  488|    115|	else
  489|    115|		return -1;
  490|    918|}
sshkey_curve_nid_to_bits:
  494|    166|{
  495|    166|	switch (nid) {
  496|    166|	case NID_X9_62_prime256v1:
  ------------------
  |  Branch (496:2): [True: 166, False: 0]
  ------------------
  497|    166|		return 256;
  498|      0|	case NID_secp384r1:
  ------------------
  |  Branch (498:2): [True: 0, False: 166]
  ------------------
  499|      0|		return 384;
  500|      0|# ifdef OPENSSL_HAS_NISTP521
  501|      0|	case NID_secp521r1:
  ------------------
  |  Branch (501:2): [True: 0, False: 166]
  ------------------
  502|      0|		return 521;
  503|      0|# endif /* OPENSSL_HAS_NISTP521 */
  504|      0|	default:
  ------------------
  |  Branch (504:2): [True: 0, False: 166]
  ------------------
  505|      0|		return 0;
  506|    166|	}
  507|    166|}
sshkey_ec_nid_to_hash_alg:
  545|    166|{
  546|    166|	int kbits = sshkey_curve_nid_to_bits(nid);
  547|       |
  548|    166|	if (kbits <= 0)
  ------------------
  |  Branch (548:6): [True: 0, False: 166]
  ------------------
  549|      0|		return -1;
  550|       |
  551|       |	/* RFC5656 section 6.2.1 */
  552|    166|	if (kbits <= 256)
  ------------------
  |  Branch (552:6): [True: 166, False: 0]
  ------------------
  553|    166|		return SSH_DIGEST_SHA256;
  ------------------
  |  |   27|    166|#define SSH_DIGEST_SHA256	2
  ------------------
  554|      0|	else if (kbits <= 384)
  ------------------
  |  Branch (554:11): [True: 0, False: 0]
  ------------------
  555|      0|		return SSH_DIGEST_SHA384;
  ------------------
  |  |   28|      0|#define SSH_DIGEST_SHA384	3
  ------------------
  556|      0|	else
  557|      0|		return SSH_DIGEST_SHA512;
  ------------------
  |  |   29|      0|#define SSH_DIGEST_SHA512	4
  ------------------
  558|    166|}
sshkey_new:
  602|  5.27k|{
  603|  5.27k|	struct sshkey *k;
  604|  5.27k|	const struct sshkey_impl *impl = NULL;
  605|       |
  606|  5.27k|	if (type != KEY_UNSPEC &&
  ------------------
  |  Branch (606:6): [True: 4.98k, False: 289]
  ------------------
  607|  5.27k|	    (impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (607:6): [True: 0, False: 4.98k]
  ------------------
  608|      0|		return NULL;
  609|       |
  610|       |	/* All non-certificate types may act as CAs */
  611|  5.27k|	if ((k = calloc(1, sizeof(*k))) == NULL)
  ------------------
  |  Branch (611:6): [True: 0, False: 5.27k]
  ------------------
  612|      0|		return NULL;
  613|  5.27k|	k->type = type;
  614|  5.27k|	k->ecdsa_nid = -1;
  615|  5.27k|	if (impl != NULL && impl->funcs->alloc != NULL) {
  ------------------
  |  Branch (615:6): [True: 4.98k, False: 289]
  |  Branch (615:22): [True: 2.42k, False: 2.56k]
  ------------------
  616|  2.42k|		if (impl->funcs->alloc(k) != 0) {
  ------------------
  |  Branch (616:7): [True: 0, False: 2.42k]
  ------------------
  617|      0|			free(k);
  618|      0|			return NULL;
  619|      0|		}
  620|  2.42k|	}
  621|  5.27k|	if (sshkey_is_cert(k)) {
  ------------------
  |  Branch (621:6): [True: 1.86k, False: 3.40k]
  ------------------
  622|  1.86k|		if ((k->cert = cert_new()) == NULL) {
  ------------------
  |  Branch (622:7): [True: 0, False: 1.86k]
  ------------------
  623|      0|			sshkey_free(k);
  624|      0|			return NULL;
  625|      0|		}
  626|  1.86k|	}
  627|       |
  628|  5.27k|	return k;
  629|  5.27k|}
sshkey_sk_cleanup:
  634|    809|{
  635|    809|	free(k->sk_application);
  636|    809|	sshbuf_free(k->sk_key_handle);
  637|    809|	sshbuf_free(k->sk_reserved);
  638|    809|	k->sk_application = NULL;
  639|    809|	k->sk_key_handle = k->sk_reserved = NULL;
  640|    809|}
sshkey_free:
  660|  9.88k|{
  661|  9.88k|	sshkey_free_contents(k);
  662|  9.88k|	freezero(k, sizeof(*k));
  663|  9.88k|}
sshkey_check_rsa_length:
 1324|    282|{
 1325|    282|#ifdef WITH_OPENSSL
 1326|    282|	const BIGNUM *rsa_n;
 1327|    282|	int nbits;
 1328|       |
 1329|    282|	if (k == NULL || k->rsa == NULL ||
  ------------------
  |  Branch (1329:6): [True: 0, False: 282]
  |  Branch (1329:19): [True: 0, False: 282]
  ------------------
 1330|    282|	    (k->type != KEY_RSA && k->type != KEY_RSA_CERT))
  ------------------
  |  Branch (1330:7): [True: 5, False: 277]
  |  Branch (1330:29): [True: 0, False: 5]
  ------------------
 1331|      0|		return 0;
 1332|    282|	RSA_get0_key(k->rsa, &rsa_n, NULL, NULL);
 1333|    282|	nbits = BN_num_bits(rsa_n);
 1334|    282|	if (nbits < SSH_RSA_MINIMUM_MODULUS_SIZE ||
  ------------------
  |  |   53|    564|#define SSH_RSA_MINIMUM_MODULUS_SIZE	1024
  ------------------
  |  Branch (1334:6): [True: 27, False: 255]
  ------------------
 1335|    282|	    (min_size > 0 && nbits < min_size))
  ------------------
  |  Branch (1335:7): [True: 0, False: 255]
  |  Branch (1335:23): [True: 0, False: 0]
  ------------------
 1336|     27|		return SSH_ERR_KEY_LENGTH;
  ------------------
  |  |   80|     27|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
 1337|    255|#endif /* WITH_OPENSSL */
 1338|    255|	return 0;
 1339|    282|}
sshkey_deserialize_sk:
 1881|    625|{
 1882|       |	/* Parse additional security-key application string */
 1883|    625|	if (sshbuf_get_cstring(b, &key->sk_application, NULL) != 0)
  ------------------
  |  Branch (1883:6): [True: 2, False: 623]
  ------------------
 1884|      2|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      2|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1885|    623|	return 0;
 1886|    625|}
sshkey_froms:
 1976|  2.31k|{
 1977|  2.31k|	struct sshbuf *b;
 1978|  2.31k|	int r;
 1979|       |
 1980|  2.31k|	if ((r = sshbuf_froms(buf, &b)) != 0)
  ------------------
  |  Branch (1980:6): [True: 62, False: 2.25k]
  ------------------
 1981|     62|		return r;
 1982|  2.25k|	r = sshkey_from_blob_internal(b, keyp, 1);
 1983|  2.25k|	sshbuf_free(b);
 1984|  2.25k|	return r;
 1985|  2.31k|}
sshkey_get_sigtype:
 1989|      1|{
 1990|      1|	int r;
 1991|      1|	struct sshbuf *b = NULL;
 1992|      1|	char *sigtype = NULL;
 1993|       |
 1994|      1|	if (sigtypep != NULL)
  ------------------
  |  Branch (1994:6): [True: 1, False: 0]
  ------------------
 1995|      1|		*sigtypep = NULL;
 1996|      1|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (1996:6): [True: 0, False: 1]
  ------------------
 1997|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1998|      1|	if ((r = sshbuf_get_cstring(b, &sigtype, NULL)) != 0)
  ------------------
  |  Branch (1998:6): [True: 0, False: 1]
  ------------------
 1999|      0|		goto out;
 2000|       |	/* success */
 2001|      1|	if (sigtypep != NULL) {
  ------------------
  |  Branch (2001:6): [True: 1, False: 0]
  ------------------
 2002|      1|		*sigtypep = sigtype;
 2003|      1|		sigtype = NULL;
 2004|      1|	}
 2005|      1|	r = 0;
 2006|      1| out:
 2007|      1|	free(sigtype);
 2008|      1|	sshbuf_free(b);
 2009|      1|	return r;
 2010|      1|}
sshkey_verify:
 2124|  1.51k|{
 2125|  1.51k|	const struct sshkey_impl *impl;
 2126|       |
 2127|  1.51k|	if (detailsp != NULL)
  ------------------
  |  Branch (2127:6): [True: 0, False: 1.51k]
  ------------------
 2128|      0|		*detailsp = NULL;
 2129|  1.51k|	if (siglen == 0 || dlen > SSH_KEY_MAX_SIGN_DATA_SIZE)
  ------------------
  |  |   54|  1.50k|#define SSH_KEY_MAX_SIGN_DATA_SIZE	(1 << 20)
  ------------------
  |  Branch (2129:6): [True: 3, False: 1.50k]
  |  Branch (2129:21): [True: 0, False: 1.50k]
  ------------------
 2130|      3|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      3|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
 2131|  1.50k|	if ((impl = sshkey_impl_from_key(key)) == NULL)
  ------------------
  |  Branch (2131:6): [True: 0, False: 1.50k]
  ------------------
 2132|      0|		return SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|      0|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
 2133|  1.50k|	return impl->funcs->verify(key, sig, siglen, data, dlen,
 2134|  1.50k|	    alg, compat, detailsp);
 2135|  1.50k|}
sshkey_private_deserialize_sk:
 2487|    140|{
 2488|    140|	int r;
 2489|       |
 2490|    140|	if ((k->sk_key_handle = sshbuf_new()) == NULL ||
  ------------------
  |  Branch (2490:6): [True: 0, False: 140]
  ------------------
 2491|    140|	    (k->sk_reserved = sshbuf_new()) == NULL)
  ------------------
  |  Branch (2491:6): [True: 0, False: 140]
  ------------------
 2492|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 2493|    140|	if ((r = sshbuf_get_cstring(buf, &k->sk_application, NULL)) != 0 ||
  ------------------
  |  Branch (2493:6): [True: 4, False: 136]
  ------------------
 2494|    140|	    (r = sshbuf_get_u8(buf, &k->sk_flags)) != 0 ||
  ------------------
  |  Branch (2494:6): [True: 7, False: 129]
  ------------------
 2495|    140|	    (r = sshbuf_get_stringb(buf, k->sk_key_handle)) != 0 ||
  ------------------
  |  Branch (2495:6): [True: 57, False: 72]
  ------------------
 2496|    140|	    (r = sshbuf_get_stringb(buf, k->sk_reserved)) != 0)
  ------------------
  |  Branch (2496:6): [True: 48, False: 24]
  ------------------
 2497|    116|		return r;
 2498|       |
 2499|     24|	return 0;
 2500|    140|}
sshkey_private_deserialize:
 2504|  4.13k|{
 2505|  4.13k|	const struct sshkey_impl *impl;
 2506|  4.13k|	char *tname = NULL;
 2507|  4.13k|	char *expect_sk_application = NULL;
 2508|  4.13k|	u_char *expect_ed25519_pk = NULL;
 2509|  4.13k|	struct sshkey *k = NULL;
 2510|  4.13k|	int type, r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  4.13k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 2511|       |
 2512|  4.13k|	if (kp != NULL)
  ------------------
  |  Branch (2512:6): [True: 4.13k, False: 0]
  ------------------
 2513|  4.13k|		*kp = NULL;
 2514|  4.13k|	if ((r = sshbuf_get_cstring(buf, &tname, NULL)) != 0)
  ------------------
  |  Branch (2514:6): [True: 71, False: 4.06k]
  ------------------
 2515|     71|		goto out;
 2516|  4.06k|	type = sshkey_type_from_name(tname);
 2517|  4.06k|	if (sshkey_type_is_cert(type)) {
  ------------------
  |  Branch (2517:6): [True: 2.31k, False: 1.74k]
  ------------------
 2518|       |		/*
 2519|       |		 * Certificate key private keys begin with the certificate
 2520|       |		 * itself. Make sure this matches the type of the enclosing
 2521|       |		 * private key.
 2522|       |		 */
 2523|  2.31k|		if ((r = sshkey_froms(buf, &k)) != 0)
  ------------------
  |  Branch (2523:7): [True: 2.30k, False: 12]
  ------------------
 2524|  2.30k|			goto out;
 2525|     12|		if (k->type != type) {
  ------------------
  |  Branch (2525:7): [True: 11, False: 1]
  ------------------
 2526|     11|			r = SSH_ERR_KEY_CERT_MISMATCH;
  ------------------
  |  |   69|     11|#define SSH_ERR_KEY_CERT_MISMATCH		-45
  ------------------
 2527|     11|			goto out;
 2528|     11|		}
 2529|       |		/* For ECDSA keys, the group must match too */
 2530|      1|		if (k->type == KEY_ECDSA &&
  ------------------
  |  Branch (2530:7): [True: 0, False: 1]
  ------------------
 2531|      1|		    k->ecdsa_nid != sshkey_ecdsa_nid_from_name(tname)) {
  ------------------
  |  Branch (2531:7): [True: 0, False: 0]
  ------------------
 2532|      0|			r = SSH_ERR_KEY_CERT_MISMATCH;
  ------------------
  |  |   69|      0|#define SSH_ERR_KEY_CERT_MISMATCH		-45
  ------------------
 2533|      0|			goto out;
 2534|      0|		}
 2535|       |		/*
 2536|       |		 * Several fields are redundant between certificate and
 2537|       |		 * private key body, we require these to match.
 2538|       |		 */
 2539|      1|		expect_sk_application = k->sk_application;
 2540|      1|		expect_ed25519_pk = k->ed25519_pk;
 2541|      1|		k->sk_application = NULL;
 2542|      1|		k->ed25519_pk = NULL;
 2543|       |		/* XXX xmss too or refactor */
 2544|  1.74k|	} else {
 2545|  1.74k|		if ((k = sshkey_new(type)) == NULL) {
  ------------------
  |  Branch (2545:7): [True: 0, False: 1.74k]
  ------------------
 2546|      0|			r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 2547|      0|			goto out;
 2548|      0|		}
 2549|  1.74k|	}
 2550|  1.74k|	if ((impl = sshkey_impl_from_type(type)) == NULL) {
  ------------------
  |  Branch (2550:6): [True: 289, False: 1.46k]
  ------------------
 2551|    289|		r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    289|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 2552|    289|		goto out;
 2553|    289|	}
 2554|  1.46k|	if ((r = impl->funcs->deserialize_private(tname, buf, k)) != 0)
  ------------------
  |  Branch (2554:6): [True: 1.41k, False: 48]
  ------------------
 2555|  1.41k|		goto out;
 2556|       |
 2557|       |	/* XXX xmss too or refactor */
 2558|     48|	if ((expect_sk_application != NULL && (k->sk_application == NULL ||
  ------------------
  |  Branch (2558:7): [True: 0, False: 48]
  |  Branch (2558:41): [True: 0, False: 0]
  ------------------
 2559|      0|	    strcmp(expect_sk_application, k->sk_application) != 0)) ||
  ------------------
  |  Branch (2559:6): [True: 0, False: 0]
  ------------------
 2560|     48|	    (expect_ed25519_pk != NULL && (k->ed25519_pk == NULL ||
  ------------------
  |  Branch (2560:7): [True: 0, False: 48]
  |  Branch (2560:37): [True: 0, False: 0]
  ------------------
 2561|      0|	    memcmp(expect_ed25519_pk, k->ed25519_pk, ED25519_PK_SZ) != 0))) {
  ------------------
  |  |  159|      0|#define	ED25519_PK_SZ	crypto_sign_ed25519_PUBLICKEYBYTES
  |  |  ------------------
  |  |  |  |   36|      0|#define crypto_sign_ed25519_PUBLICKEYBYTES 32U
  |  |  ------------------
  ------------------
  |  Branch (2561:6): [True: 0, False: 0]
  ------------------
 2562|      0|		r = SSH_ERR_KEY_CERT_MISMATCH;
  ------------------
  |  |   69|      0|#define SSH_ERR_KEY_CERT_MISMATCH		-45
  ------------------
 2563|      0|		goto out;
 2564|      0|	}
 2565|       |	/* success */
 2566|     48|	r = 0;
 2567|     48|	if (kp != NULL) {
  ------------------
  |  Branch (2567:6): [True: 48, False: 0]
  ------------------
 2568|     48|		*kp = k;
 2569|     48|		k = NULL;
 2570|     48|	}
 2571|  4.13k| out:
 2572|  4.13k|	free(tname);
 2573|  4.13k|	sshkey_free(k);
 2574|  4.13k|	free(expect_sk_application);
 2575|  4.13k|	free(expect_ed25519_pk);
 2576|  4.13k|	return r;
 2577|     48|}
sshkey_ec_validate_public:
 2582|    672|{
 2583|    672|	EC_POINT *nq = NULL;
 2584|    672|	BIGNUM *order = NULL, *x = NULL, *y = NULL, *tmp = NULL;
 2585|    672|	int ret = SSH_ERR_KEY_INVALID_EC_VALUE;
  ------------------
  |  |   44|    672|#define SSH_ERR_KEY_INVALID_EC_VALUE		-20
  ------------------
 2586|       |
 2587|       |	/*
 2588|       |	 * NB. This assumes OpenSSL has already verified that the public
 2589|       |	 * point lies on the curve. This is done by EC_POINT_oct2point()
 2590|       |	 * implicitly calling EC_POINT_is_on_curve(). If this code is ever
 2591|       |	 * reachable with public points not unmarshalled using
 2592|       |	 * EC_POINT_oct2point then the caller will need to explicitly check.
 2593|       |	 */
 2594|       |
 2595|       |	/*
 2596|       |	 * We shouldn't ever hit this case because bignum_get_ecpoint()
 2597|       |	 * refuses to load GF2m points.
 2598|       |	 */
 2599|    672|	if (EC_METHOD_get_field_type(EC_GROUP_method_of(group)) !=
  ------------------
  |  Branch (2599:6): [True: 0, False: 672]
  ------------------
 2600|    672|	    NID_X9_62_prime_field)
 2601|      0|		goto out;
 2602|       |
 2603|       |	/* Q != infinity */
 2604|    672|	if (EC_POINT_is_at_infinity(group, public))
  ------------------
  |  Branch (2604:6): [True: 0, False: 672]
  ------------------
 2605|      0|		goto out;
 2606|       |
 2607|    672|	if ((x = BN_new()) == NULL ||
  ------------------
  |  Branch (2607:6): [True: 0, False: 672]
  ------------------
 2608|    672|	    (y = BN_new()) == NULL ||
  ------------------
  |  Branch (2608:6): [True: 0, False: 672]
  ------------------
 2609|    672|	    (order = BN_new()) == NULL ||
  ------------------
  |  Branch (2609:6): [True: 0, False: 672]
  ------------------
 2610|    672|	    (tmp = BN_new()) == NULL) {
  ------------------
  |  Branch (2610:6): [True: 0, False: 672]
  ------------------
 2611|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 2612|      0|		goto out;
 2613|      0|	}
 2614|       |
 2615|       |	/* log2(x) > log2(order)/2, log2(y) > log2(order)/2 */
 2616|    672|	if (EC_GROUP_get_order(group, order, NULL) != 1 ||
  ------------------
  |  Branch (2616:6): [True: 0, False: 672]
  ------------------
 2617|    672|	    EC_POINT_get_affine_coordinates_GFp(group, public,
  ------------------
  |  Branch (2617:6): [True: 0, False: 672]
  ------------------
 2618|    672|	    x, y, NULL) != 1) {
 2619|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
 2620|      0|		goto out;
 2621|      0|	}
 2622|    672|	if (BN_num_bits(x) <= BN_num_bits(order) / 2 ||
  ------------------
  |  Branch (2622:6): [True: 0, False: 672]
  ------------------
 2623|    672|	    BN_num_bits(y) <= BN_num_bits(order) / 2)
  ------------------
  |  Branch (2623:6): [True: 0, False: 672]
  ------------------
 2624|      0|		goto out;
 2625|       |
 2626|       |	/* nQ == infinity (n == order of subgroup) */
 2627|    672|	if ((nq = EC_POINT_new(group)) == NULL) {
  ------------------
  |  Branch (2627:6): [True: 0, False: 672]
  ------------------
 2628|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 2629|      0|		goto out;
 2630|      0|	}
 2631|    672|	if (EC_POINT_mul(group, nq, NULL, public, order, NULL) != 1) {
  ------------------
  |  Branch (2631:6): [True: 0, False: 672]
  ------------------
 2632|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
 2633|      0|		goto out;
 2634|      0|	}
 2635|    672|	if (EC_POINT_is_at_infinity(group, nq) != 1)
  ------------------
  |  Branch (2635:6): [True: 0, False: 672]
  ------------------
 2636|      0|		goto out;
 2637|       |
 2638|       |	/* x < order - 1, y < order - 1 */
 2639|    672|	if (!BN_sub(tmp, order, BN_value_one())) {
  ------------------
  |  Branch (2639:6): [True: 0, False: 672]
  ------------------
 2640|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
 2641|      0|		goto out;
 2642|      0|	}
 2643|    672|	if (BN_cmp(x, tmp) >= 0 || BN_cmp(y, tmp) >= 0)
  ------------------
  |  Branch (2643:6): [True: 0, False: 672]
  |  Branch (2643:29): [True: 0, False: 672]
  ------------------
 2644|      0|		goto out;
 2645|    672|	ret = 0;
 2646|    672| out:
 2647|    672|	BN_clear_free(x);
 2648|    672|	BN_clear_free(y);
 2649|    672|	BN_clear_free(order);
 2650|    672|	BN_clear_free(tmp);
 2651|    672|	EC_POINT_free(nq);
 2652|    672|	return ret;
 2653|    672|}
sshkey_ec_validate_private:
 2657|     45|{
 2658|     45|	BIGNUM *order = NULL, *tmp = NULL;
 2659|     45|	int ret = SSH_ERR_KEY_INVALID_EC_VALUE;
  ------------------
  |  |   44|     45|#define SSH_ERR_KEY_INVALID_EC_VALUE		-20
  ------------------
 2660|       |
 2661|     45|	if ((order = BN_new()) == NULL || (tmp = BN_new()) == NULL) {
  ------------------
  |  Branch (2661:6): [True: 0, False: 45]
  |  Branch (2661:36): [True: 0, False: 45]
  ------------------
 2662|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 2663|      0|		goto out;
 2664|      0|	}
 2665|       |
 2666|       |	/* log2(private) > log2(order)/2 */
 2667|     45|	if (EC_GROUP_get_order(EC_KEY_get0_group(key), order, NULL) != 1) {
  ------------------
  |  Branch (2667:6): [True: 0, False: 45]
  ------------------
 2668|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
 2669|      0|		goto out;
 2670|      0|	}
 2671|     45|	if (BN_num_bits(EC_KEY_get0_private_key(key)) <=
  ------------------
  |  Branch (2671:6): [True: 11, False: 34]
  ------------------
 2672|     45|	    BN_num_bits(order) / 2)
 2673|     11|		goto out;
 2674|       |
 2675|       |	/* private < order - 1 */
 2676|     34|	if (!BN_sub(tmp, order, BN_value_one())) {
  ------------------
  |  Branch (2676:6): [True: 0, False: 34]
  ------------------
 2677|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
 2678|      0|		goto out;
 2679|      0|	}
 2680|     34|	if (BN_cmp(EC_KEY_get0_private_key(key), tmp) >= 0)
  ------------------
  |  Branch (2680:6): [True: 21, False: 13]
  ------------------
 2681|     21|		goto out;
 2682|     13|	ret = 0;
 2683|     45| out:
 2684|     45|	BN_clear_free(order);
 2685|     45|	BN_clear_free(tmp);
 2686|     45|	return ret;
 2687|     13|}
sshkey_sig_details_free:
 3566|    610|{
 3567|    610|	freezero(details, sizeof(*details));
 3568|    610|}
sshkey.c:sshkey_impl_from_key:
  197|  1.50k|{
  198|  1.50k|	if (k == NULL)
  ------------------
  |  Branch (198:6): [True: 0, False: 1.50k]
  ------------------
  199|      0|		return NULL;
  200|  1.50k|	return sshkey_impl_from_type_nid(k->type, k->ecdsa_nid);
  201|  1.50k|}
sshkey.c:sshkey_impl_from_type_nid:
  184|  1.81k|{
  185|  1.81k|	int i;
  186|       |
  187|  16.8k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (187:14): [True: 16.8k, False: 0]
  ------------------
  188|  16.8k|		if (keyimpls[i]->type == type &&
  ------------------
  |  Branch (188:7): [True: 1.81k, False: 15.0k]
  ------------------
  189|  16.8k|		    (keyimpls[i]->nid == 0 || keyimpls[i]->nid == nid))
  ------------------
  |  Branch (189:8): [True: 1.04k, False: 763]
  |  Branch (189:33): [True: 763, False: 0]
  ------------------
  190|  1.81k|			return keyimpls[i];
  191|  16.8k|	}
  192|      0|	return NULL;
  193|  1.81k|}
sshkey.c:sshkey_impl_from_type:
  172|  41.6k|{
  173|  41.6k|	int i;
  174|       |
  175|   566k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (175:14): [True: 564k, False: 1.66k]
  ------------------
  176|   564k|		if (keyimpls[i]->type == type)
  ------------------
  |  Branch (176:7): [True: 39.9k, False: 524k]
  ------------------
  177|  39.9k|			return keyimpls[i];
  178|   564k|	}
  179|  1.66k|	return NULL;
  180|  41.6k|}
sshkey.c:sshkey_ssh_name_from_type_nid:
  215|    303|{
  216|    303|	const struct sshkey_impl *impl;
  217|       |
  218|    303|	if ((impl = sshkey_impl_from_type_nid(type, nid)) == NULL)
  ------------------
  |  Branch (218:6): [True: 0, False: 303]
  ------------------
  219|      0|		return "ssh-unknown";
  220|    303|	return impl->name;
  221|    303|}
sshkey.c:key_type_is_ecdsa_variant:
  264|  7.90k|{
  265|  7.90k|	switch (type) {
  ------------------
  |  Branch (265:10): [True: 3.92k, False: 3.98k]
  ------------------
  266|  1.97k|	case KEY_ECDSA:
  ------------------
  |  Branch (266:2): [True: 1.97k, False: 5.93k]
  ------------------
  267|  3.48k|	case KEY_ECDSA_CERT:
  ------------------
  |  Branch (267:2): [True: 1.50k, False: 6.40k]
  ------------------
  268|  3.97k|	case KEY_ECDSA_SK:
  ------------------
  |  Branch (268:2): [True: 489, False: 7.42k]
  ------------------
  269|  3.98k|	case KEY_ECDSA_SK_CERT:
  ------------------
  |  Branch (269:2): [True: 18, False: 7.89k]
  ------------------
  270|  3.98k|		return 1;
  271|  7.90k|	}
  272|  3.92k|	return 0;
  273|  7.90k|}
sshkey.c:cert_new:
  582|  1.86k|{
  583|  1.86k|	struct sshkey_cert *cert;
  584|       |
  585|  1.86k|	if ((cert = calloc(1, sizeof(*cert))) == NULL)
  ------------------
  |  Branch (585:6): [True: 0, False: 1.86k]
  ------------------
  586|      0|		return NULL;
  587|  1.86k|	if ((cert->certblob = sshbuf_new()) == NULL ||
  ------------------
  |  Branch (587:6): [True: 0, False: 1.86k]
  ------------------
  588|  1.86k|	    (cert->critical = sshbuf_new()) == NULL ||
  ------------------
  |  Branch (588:6): [True: 0, False: 1.86k]
  ------------------
  589|  1.86k|	    (cert->extensions = sshbuf_new()) == NULL) {
  ------------------
  |  Branch (589:6): [True: 0, False: 1.86k]
  ------------------
  590|      0|		cert_free(cert);
  591|      0|		return NULL;
  592|      0|	}
  593|  1.86k|	cert->key_id = NULL;
  594|  1.86k|	cert->principals = NULL;
  595|  1.86k|	cert->signature_key = NULL;
  596|  1.86k|	cert->signature_type = NULL;
  597|  1.86k|	return cert;
  598|  1.86k|}
sshkey.c:sshkey_free_contents:
  644|  9.88k|{
  645|  9.88k|	const struct sshkey_impl *impl;
  646|       |
  647|  9.88k|	if (k == NULL)
  ------------------
  |  Branch (647:6): [True: 4.61k, False: 5.27k]
  ------------------
  648|  4.61k|		return;
  649|  5.27k|	if ((impl = sshkey_impl_from_type(k->type)) != NULL &&
  ------------------
  |  Branch (649:6): [True: 4.98k, False: 289]
  ------------------
  650|  5.27k|	    impl->funcs->cleanup != NULL)
  ------------------
  |  Branch (650:6): [True: 4.98k, False: 0]
  ------------------
  651|  4.98k|		impl->funcs->cleanup(k);
  652|  5.27k|	if (sshkey_is_cert(k))
  ------------------
  |  Branch (652:6): [True: 1.86k, False: 3.40k]
  ------------------
  653|  1.86k|		cert_free(k->cert);
  654|  5.27k|	freezero(k->shielded_private, k->shielded_len);
  655|  5.27k|	freezero(k->shield_prekey, k->shield_prekey_len);
  656|  5.27k|}
sshkey.c:cert_free:
  563|  1.86k|{
  564|  1.86k|	u_int i;
  565|       |
  566|  1.86k|	if (cert == NULL)
  ------------------
  |  Branch (566:6): [True: 0, False: 1.86k]
  ------------------
  567|      0|		return;
  568|  1.86k|	sshbuf_free(cert->certblob);
  569|  1.86k|	sshbuf_free(cert->critical);
  570|  1.86k|	sshbuf_free(cert->extensions);
  571|  1.86k|	free(cert->key_id);
  572|  5.90k|	for (i = 0; i < cert->nprincipals; i++)
  ------------------
  |  Branch (572:14): [True: 4.04k, False: 1.86k]
  ------------------
  573|  4.04k|		free(cert->principals[i]);
  574|  1.86k|	free(cert->principals);
  575|  1.86k|	sshkey_free(cert->signature_key);
  576|  1.86k|	free(cert->signature_type);
  577|  1.86k|	freezero(cert, sizeof(*cert));
  578|  1.86k|}
sshkey.c:sshkey_from_blob_internal:
 1891|  3.83k|{
 1892|  3.83k|	int type, ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  3.83k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 1893|  3.83k|	char *ktype = NULL;
 1894|  3.83k|	struct sshkey *key = NULL;
 1895|  3.83k|	struct sshbuf *copy;
 1896|  3.83k|	const struct sshkey_impl *impl;
 1897|       |
 1898|       |#ifdef DEBUG_PK /* XXX */
 1899|       |	sshbuf_dump(b, stderr);
 1900|       |#endif
 1901|  3.83k|	if (keyp != NULL)
  ------------------
  |  Branch (1901:6): [True: 3.83k, False: 0]
  ------------------
 1902|  3.83k|		*keyp = NULL;
 1903|  3.83k|	if ((copy = sshbuf_fromb(b)) == NULL) {
  ------------------
  |  Branch (1903:6): [True: 0, False: 3.83k]
  ------------------
 1904|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1905|      0|		goto out;
 1906|      0|	}
 1907|  3.83k|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0) {
  ------------------
  |  Branch (1907:6): [True: 94, False: 3.74k]
  ------------------
 1908|     94|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     94|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1909|     94|		goto out;
 1910|     94|	}
 1911|       |
 1912|  3.74k|	type = sshkey_type_from_name(ktype);
 1913|  3.74k|	if (!allow_cert && sshkey_type_is_cert(type)) {
  ------------------
  |  Branch (1913:6): [True: 1.53k, False: 2.20k]
  |  Branch (1913:21): [True: 3, False: 1.53k]
  ------------------
 1914|      3|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|      3|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1915|      3|		goto out;
 1916|      3|	}
 1917|  3.74k|	if ((impl = sshkey_impl_from_type(type)) == NULL) {
  ------------------
  |  Branch (1917:6): [True: 216, False: 3.52k]
  ------------------
 1918|    216|		ret = SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|    216|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
 1919|    216|		goto out;
 1920|    216|	}
 1921|  3.52k|	if ((key = sshkey_new(type)) == NULL) {
  ------------------
  |  Branch (1921:6): [True: 0, False: 3.52k]
  ------------------
 1922|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1923|      0|		goto out;
 1924|      0|	}
 1925|  3.52k|	if (sshkey_type_is_cert(type)) {
  ------------------
  |  Branch (1925:6): [True: 1.86k, False: 1.66k]
  ------------------
 1926|       |		/* Skip nonce that preceeds all certificates */
 1927|  1.86k|		if (sshbuf_get_string_direct(b, NULL, NULL) != 0) {
  ------------------
  |  Branch (1927:7): [True: 50, False: 1.81k]
  ------------------
 1928|     50|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     50|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1929|     50|			goto out;
 1930|     50|		}
 1931|  1.86k|	}
 1932|  3.47k|	if ((ret = impl->funcs->deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (1932:6): [True: 128, False: 3.34k]
  ------------------
 1933|    128|		goto out;
 1934|       |
 1935|       |	/* Parse certificate potion */
 1936|  3.34k|	if (sshkey_is_cert(key) && (ret = cert_parse(b, key, copy)) != 0)
  ------------------
  |  Branch (1936:6): [True: 1.80k, False: 1.54k]
  |  Branch (1936:29): [True: 1.79k, False: 1]
  ------------------
 1937|  1.79k|		goto out;
 1938|       |
 1939|  1.54k|	if (key != NULL && sshbuf_len(b) != 0) {
  ------------------
  |  Branch (1939:6): [True: 1.54k, False: 0]
  |  Branch (1939:21): [True: 25, False: 1.52k]
  ------------------
 1940|     25|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     25|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1941|     25|		goto out;
 1942|     25|	}
 1943|  1.52k|	ret = 0;
 1944|  1.52k|	if (keyp != NULL) {
  ------------------
  |  Branch (1944:6): [True: 1.52k, False: 0]
  ------------------
 1945|  1.52k|		*keyp = key;
 1946|  1.52k|		key = NULL;
 1947|  1.52k|	}
 1948|  3.83k| out:
 1949|  3.83k|	sshbuf_free(copy);
 1950|  3.83k|	sshkey_free(key);
 1951|  3.83k|	free(ktype);
 1952|  3.83k|	return ret;
 1953|  1.52k|}
sshkey.c:cert_parse:
 1755|  1.80k|{
 1756|  1.80k|	struct sshbuf *principals = NULL, *crit = NULL;
 1757|  1.80k|	struct sshbuf *exts = NULL, *ca = NULL;
 1758|  1.80k|	u_char *sig = NULL;
 1759|  1.80k|	size_t signed_len = 0, slen = 0, kidlen = 0;
 1760|  1.80k|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  1.80k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 1761|       |
 1762|       |	/* Copy the entire key blob for verification and later serialisation */
 1763|  1.80k|	if ((ret = sshbuf_putb(key->cert->certblob, certbuf)) != 0)
  ------------------
  |  Branch (1763:6): [True: 0, False: 1.80k]
  ------------------
 1764|      0|		return ret;
 1765|       |
 1766|       |	/* Parse body of certificate up to signature */
 1767|  1.80k|	if ((ret = sshbuf_get_u64(b, &key->cert->serial)) != 0 ||
  ------------------
  |  Branch (1767:6): [True: 6, False: 1.79k]
  ------------------
 1768|  1.80k|	    (ret = sshbuf_get_u32(b, &key->cert->type)) != 0 ||
  ------------------
  |  Branch (1768:6): [True: 2, False: 1.79k]
  ------------------
 1769|  1.80k|	    (ret = sshbuf_get_cstring(b, &key->cert->key_id, &kidlen)) != 0 ||
  ------------------
  |  Branch (1769:6): [True: 6, False: 1.78k]
  ------------------
 1770|  1.80k|	    (ret = sshbuf_froms(b, &principals)) != 0 ||
  ------------------
  |  Branch (1770:6): [True: 4, False: 1.78k]
  ------------------
 1771|  1.80k|	    (ret = sshbuf_get_u64(b, &key->cert->valid_after)) != 0 ||
  ------------------
  |  Branch (1771:6): [True: 4, False: 1.77k]
  ------------------
 1772|  1.80k|	    (ret = sshbuf_get_u64(b, &key->cert->valid_before)) != 0 ||
  ------------------
  |  Branch (1772:6): [True: 1, False: 1.77k]
  ------------------
 1773|  1.80k|	    (ret = sshbuf_froms(b, &crit)) != 0 ||
  ------------------
  |  Branch (1773:6): [True: 5, False: 1.77k]
  ------------------
 1774|  1.80k|	    (ret = sshbuf_froms(b, &exts)) != 0 ||
  ------------------
  |  Branch (1774:6): [True: 2, False: 1.77k]
  ------------------
 1775|  1.80k|	    (ret = sshbuf_get_string_direct(b, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1775:6): [True: 3, False: 1.76k]
  ------------------
 1776|  1.80k|	    (ret = sshbuf_froms(b, &ca)) != 0) {
  ------------------
  |  Branch (1776:6): [True: 2, False: 1.76k]
  ------------------
 1777|       |		/* XXX debug print error for ret */
 1778|     35|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     35|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1779|     35|		goto out;
 1780|     35|	}
 1781|       |
 1782|       |	/* Signature is left in the buffer so we can calculate this length */
 1783|  1.76k|	signed_len = sshbuf_len(key->cert->certblob) - sshbuf_len(b);
 1784|       |
 1785|  1.76k|	if ((ret = sshbuf_get_string(b, &sig, &slen)) != 0) {
  ------------------
  |  Branch (1785:6): [True: 3, False: 1.76k]
  ------------------
 1786|      3|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      3|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1787|      3|		goto out;
 1788|      3|	}
 1789|       |
 1790|  1.76k|	if (key->cert->type != SSH2_CERT_TYPE_USER &&
  ------------------
  |  |  173|  3.52k|#define SSH2_CERT_TYPE_USER				1
  ------------------
  |  Branch (1790:6): [True: 688, False: 1.07k]
  ------------------
 1791|  1.76k|	    key->cert->type != SSH2_CERT_TYPE_HOST) {
  ------------------
  |  |  174|    688|#define SSH2_CERT_TYPE_HOST				2
  ------------------
  |  Branch (1791:6): [True: 48, False: 640]
  ------------------
 1792|     48|		ret = SSH_ERR_KEY_CERT_UNKNOWN_TYPE;
  ------------------
  |  |   42|     48|#define SSH_ERR_KEY_CERT_UNKNOWN_TYPE		-18
  ------------------
 1793|     48|		goto out;
 1794|     48|	}
 1795|       |
 1796|       |	/* Parse principals section */
 1797|  5.75k|	while (sshbuf_len(principals) > 0) {
  ------------------
  |  Branch (1797:9): [True: 4.08k, False: 1.66k]
  ------------------
 1798|  4.08k|		char *principal = NULL;
 1799|  4.08k|		char **oprincipals = NULL;
 1800|       |
 1801|  4.08k|		if (key->cert->nprincipals >= SSHKEY_CERT_MAX_PRINCIPALS) {
  ------------------
  |  |  108|  4.08k|#define SSHKEY_CERT_MAX_PRINCIPALS	256
  ------------------
  |  Branch (1801:7): [True: 2, False: 4.08k]
  ------------------
 1802|      2|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      2|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1803|      2|			goto out;
 1804|      2|		}
 1805|  4.08k|		if ((ret = sshbuf_get_cstring(principals, &principal,
  ------------------
  |  Branch (1805:7): [True: 45, False: 4.04k]
  ------------------
 1806|  4.08k|		    NULL)) != 0) {
 1807|     45|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     45|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1808|     45|			goto out;
 1809|     45|		}
 1810|  4.04k|		oprincipals = key->cert->principals;
 1811|  4.04k|		key->cert->principals = recallocarray(key->cert->principals,
 1812|  4.04k|		    key->cert->nprincipals, key->cert->nprincipals + 1,
 1813|  4.04k|		    sizeof(*key->cert->principals));
 1814|  4.04k|		if (key->cert->principals == NULL) {
  ------------------
  |  Branch (1814:7): [True: 0, False: 4.04k]
  ------------------
 1815|      0|			free(principal);
 1816|      0|			key->cert->principals = oprincipals;
 1817|      0|			ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1818|      0|			goto out;
 1819|      0|		}
 1820|  4.04k|		key->cert->principals[key->cert->nprincipals++] = principal;
 1821|  4.04k|	}
 1822|       |
 1823|       |	/*
 1824|       |	 * Stash a copies of the critical options and extensions sections
 1825|       |	 * for later use.
 1826|       |	 */
 1827|  1.66k|	if ((ret = sshbuf_putb(key->cert->critical, crit)) != 0 ||
  ------------------
  |  Branch (1827:6): [True: 0, False: 1.66k]
  ------------------
 1828|  1.66k|	    (exts != NULL &&
  ------------------
  |  Branch (1828:7): [True: 1.66k, False: 0]
  ------------------
 1829|  1.66k|	    (ret = sshbuf_putb(key->cert->extensions, exts)) != 0))
  ------------------
  |  Branch (1829:6): [True: 0, False: 1.66k]
  ------------------
 1830|      0|		goto out;
 1831|       |
 1832|       |	/*
 1833|       |	 * Validate critical options and extensions sections format.
 1834|       |	 */
 1835|  3.02k|	while (sshbuf_len(crit) != 0) {
  ------------------
  |  Branch (1835:9): [True: 1.40k, False: 1.62k]
  ------------------
 1836|  1.40k|		if ((ret = sshbuf_get_string_direct(crit, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1836:7): [True: 30, False: 1.37k]
  ------------------
 1837|  1.40k|		    (ret = sshbuf_get_string_direct(crit, NULL, NULL)) != 0) {
  ------------------
  |  Branch (1837:7): [True: 13, False: 1.35k]
  ------------------
 1838|     43|			sshbuf_reset(key->cert->critical);
 1839|     43|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     43|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1840|     43|			goto out;
 1841|     43|		}
 1842|  1.40k|	}
 1843|  2.43k|	while (exts != NULL && sshbuf_len(exts) != 0) {
  ------------------
  |  Branch (1843:9): [True: 2.43k, False: 0]
  |  Branch (1843:25): [True: 852, False: 1.58k]
  ------------------
 1844|    852|		if ((ret = sshbuf_get_string_direct(exts, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1844:7): [True: 27, False: 825]
  ------------------
 1845|    852|		    (ret = sshbuf_get_string_direct(exts, NULL, NULL)) != 0) {
  ------------------
  |  Branch (1845:7): [True: 14, False: 811]
  ------------------
 1846|     41|			sshbuf_reset(key->cert->extensions);
 1847|     41|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     41|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1848|     41|			goto out;
 1849|     41|		}
 1850|    852|	}
 1851|       |
 1852|       |	/* Parse CA key and check signature */
 1853|  1.58k|	if (sshkey_from_blob_internal(ca, &key->cert->signature_key, 0) != 0) {
  ------------------
  |  Branch (1853:6): [True: 72, False: 1.51k]
  ------------------
 1854|     72|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|     72|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1855|     72|		goto out;
 1856|     72|	}
 1857|  1.51k|	if (!sshkey_type_is_valid_ca(key->cert->signature_key->type)) {
  ------------------
  |  Branch (1857:6): [True: 0, False: 1.51k]
  ------------------
 1858|      0|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|      0|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1859|      0|		goto out;
 1860|      0|	}
 1861|  1.51k|	if ((ret = sshkey_verify(key->cert->signature_key, sig, slen,
  ------------------
  |  Branch (1861:6): [True: 1.51k, False: 1]
  ------------------
 1862|  1.51k|	    sshbuf_ptr(key->cert->certblob), signed_len, NULL, 0, NULL)) != 0)
 1863|  1.51k|		goto out;
 1864|      1|	if ((ret = sshkey_get_sigtype(sig, slen,
  ------------------
  |  Branch (1864:6): [True: 0, False: 1]
  ------------------
 1865|      1|	    &key->cert->signature_type)) != 0)
 1866|      0|		goto out;
 1867|       |
 1868|       |	/* Success */
 1869|      1|	ret = 0;
 1870|  1.80k| out:
 1871|  1.80k|	sshbuf_free(ca);
 1872|  1.80k|	sshbuf_free(crit);
 1873|  1.80k|	sshbuf_free(exts);
 1874|  1.80k|	sshbuf_free(principals);
 1875|  1.80k|	free(sig);
 1876|  1.80k|	return ret;
 1877|      1|}
sshkey.c:sshkey_type_is_valid_ca:
  396|  1.51k|{
  397|  1.51k|	const struct sshkey_impl *impl;
  398|       |
  399|  1.51k|	if ((impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (399:6): [True: 0, False: 1.51k]
  ------------------
  400|      0|		return 0;
  401|       |	/* All non-certificate types may act as CAs */
  402|  1.51k|	return !impl->cert;
  403|  1.51k|}

xmss_set_params:
   54|    739|{
   55|    739|  if (k >= h || k < 2 || (h - k) % 2) {
  ------------------
  |  Branch (55:7): [True: 0, False: 739]
  |  Branch (55:17): [True: 0, False: 739]
  |  Branch (55:26): [True: 0, False: 739]
  ------------------
   56|      0|    fprintf(stderr, "For BDS traversal, H - K must be even, with H > K >= 2!\n");
   57|      0|    return 1;
   58|      0|  }
   59|    739|  params->h = h;
   60|    739|  params->n = n;
   61|    739|  params->k = k;
   62|    739|  wots_params wots_par;
   63|    739|  wots_set_params(&wots_par, n, w);
   64|    739|  params->wots_par = wots_par;
   65|    739|  return 0;
   66|    739|}
xmss_set_bds_state:
   73|      5|{
   74|      5|  state->stack = stack;
   75|      5|  state->stackoffset = stackoffset;
   76|      5|  state->stacklevels = stacklevels;
   77|      5|  state->auth = auth;
   78|      5|  state->keep = keep;
   79|      5|  state->treehash = treehash;
   80|      5|  state->retain = retain;
   81|      5|  state->next_leaf = next_leaf;
   82|      5|}

wots_set_params:
   39|    739|{
   40|    739|  params->n = n;
   41|    739|  params->w = w;
   42|    739|  params->log_w = wots_log2(params->w);
   43|    739|  params->len_1 = (CHAR_BIT * n) / params->log_w;
   44|    739|  params->len_2 = (wots_log2(params->len_1 * (w - 1)) / params->log_w) + 1;
   45|    739|  params->len = params->len_1 + params->len_2;
   46|    739|  params->keysize = params->len * params->n;
   47|    739|}
xmss_wots.c:wots_log2:
   26|  1.47k|{
   27|  1.47k|  int      b;
   28|       |
   29|  37.6k|  for (b = sizeof (v) * CHAR_BIT - 1; b >= 0; b--) {
  ------------------
  |  Branch (29:39): [True: 37.6k, False: 0]
  ------------------
   30|  37.6k|    if ((1U << b) & v) {
  ------------------
  |  Branch (30:9): [True: 1.47k, False: 36.2k]
  ------------------
   31|  1.47k|      return b;
   32|  1.47k|    }
   33|  37.6k|  }
   34|      0|  return 0;
   35|  1.47k|}

