ssh_digest_alg_by_name:
   81|  2.10k|{
   82|  2.10k|	int alg;
   83|       |
   84|  8.30k|	for (alg = 0; digests[alg].id != -1; alg++) {
  ------------------
  |  Branch (84:16): [True: 8.30k, False: 0]
  ------------------
   85|  8.30k|		if (strcasecmp(name, digests[alg].name) == 0)
  ------------------
  |  Branch (85:7): [True: 2.10k, False: 6.20k]
  ------------------
   86|  2.10k|			return digests[alg].id;
   87|  8.30k|	}
   88|      0|	return -1;
   89|  2.10k|}
ssh_digest_bytes:
  101|  4.24k|{
  102|  4.24k|	const struct ssh_digest *digest = ssh_digest_by_alg(alg);
  103|       |
  104|  4.24k|	return digest == NULL ? 0 : digest->digest_len;
  ------------------
  |  Branch (104:9): [True: 0, False: 4.24k]
  ------------------
  105|  4.24k|}
ssh_digest_memory:
  186|  2.13k|{
  187|  2.13k|	const struct ssh_digest *digest = ssh_digest_by_alg(alg);
  188|  2.13k|	u_int mdlen;
  189|       |
  190|  2.13k|	if (digest == NULL)
  ------------------
  |  Branch (190:6): [True: 0, False: 2.13k]
  ------------------
  191|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  192|  2.13k|	if (dlen > UINT_MAX)
  ------------------
  |  Branch (192:6): [True: 0, False: 2.13k]
  ------------------
  193|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  194|  2.13k|	if (dlen < digest->digest_len)
  ------------------
  |  Branch (194:6): [True: 0, False: 2.13k]
  ------------------
  195|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  196|  2.13k|	mdlen = dlen;
  197|  2.13k|	if (!EVP_Digest(m, mlen, d, &mdlen, digest->mdfunc(), NULL))
  ------------------
  |  Branch (197:6): [True: 0, False: 2.13k]
  ------------------
  198|      0|		return SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  199|  2.13k|	return 0;
  200|  2.13k|}
ssh_digest_buffer:
  204|  2.10k|{
  205|  2.10k|	return ssh_digest_memory(alg, sshbuf_ptr(b), sshbuf_len(b), d, dlen);
  206|  2.10k|}
digest-openssl.c:ssh_digest_by_alg:
   69|  6.37k|{
   70|  6.37k|	if (alg < 0 || alg >= SSH_DIGEST_MAX)
  ------------------
  |  |   30|  6.37k|#define SSH_DIGEST_MAX		5
  ------------------
  |  Branch (70:6): [True: 0, False: 6.37k]
  |  Branch (70:17): [True: 0, False: 6.37k]
  ------------------
   71|      0|		return NULL;
   72|  6.37k|	if (digests[alg].id != alg) /* sanity */
  ------------------
  |  Branch (72:6): [True: 0, False: 6.37k]
  ------------------
   73|      0|		return NULL;
   74|  6.37k|	if (digests[alg].mdfunc == NULL)
  ------------------
  |  Branch (74:6): [True: 0, False: 6.37k]
  ------------------
   75|      0|		return NULL;
   76|  6.37k|	return &(digests[alg]);
   77|  6.37k|}

crypto_sign_ed25519_ref_fe25519_getparity:
  268|     78|{
  269|     78|  fe25519 t = *x;
  ------------------
  |  |   72|     78|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  270|     78|  fe25519_freeze(&t);
  ------------------
  |  |   73|     78|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  271|     78|  return t.v[0] & 1;
  272|     78|}
crypto_sign_ed25519_ref_unpackneg_vartime:
 1786|     51|{
 1787|     51|  unsigned char par;
 1788|     51|  fe25519 t, chk, num, den, den2, den4, den6;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1789|     51|  fe25519_setone(&r->z);
  ------------------
  |  |   79|     51|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1790|     51|  par = p[31] >> 7;
 1791|     51|  fe25519_unpack(&r->y, p);
  ------------------
  |  |   74|     51|#define fe25519_unpack       crypto_sign_ed25519_ref_fe25519_unpack
  ------------------
 1792|     51|  fe25519_square(&num, &r->y); /* x = y^2 */
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1793|     51|  fe25519_mul(&den, &num, &ge25519_ecd); /* den = dy^2 */
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1794|     51|  fe25519_sub(&num, &num, &r->z); /* x = y^2-1 */
  ------------------
  |  |   84|     51|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1795|     51|  fe25519_add(&den, &r->z, &den); /* den = dy^2+1 */
  ------------------
  |  |   83|     51|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1796|       |
 1797|       |  /* Computation of sqrt(num/den) */
 1798|       |  /* 1.: computation of num^((p-5)/8)*den^((7p-35)/8) = (num*den^7)^((p-5)/8) */
 1799|     51|  fe25519_square(&den2, &den);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1800|     51|  fe25519_square(&den4, &den2);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1801|     51|  fe25519_mul(&den6, &den4, &den2);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1802|     51|  fe25519_mul(&t, &den6, &num);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1803|     51|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1804|       |
 1805|     51|  fe25519_pow2523(&t, &t);
  ------------------
  |  |   88|     51|#define fe25519_pow2523      crypto_sign_ed25519_ref_fe25519_pow2523
  ------------------
 1806|       |  /* 2. computation of r->x = t * num * den^3 */
 1807|     51|  fe25519_mul(&t, &t, &num);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1808|     51|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1809|     51|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1810|     51|  fe25519_mul(&r->x, &t, &den);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1811|       |
 1812|       |  /* 3. Check whether sqrt computation gave correct result, multiply by sqrt(-1) if not: */
 1813|     51|  fe25519_square(&chk, &r->x);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1814|     51|  fe25519_mul(&chk, &chk, &den);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1815|     51|  if (!fe25519_iseq_vartime(&chk, &num))
  ------------------
  |  |   77|     51|#define fe25519_iseq_vartime crypto_sign_ed25519_ref_fe25519_iseq_vartime
  ------------------
  |  Branch (1815:7): [True: 31, False: 20]
  ------------------
 1816|     31|    fe25519_mul(&r->x, &r->x, &ge25519_sqrtm1);
  ------------------
  |  |   85|     31|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1817|       |
 1818|       |  /* 4. Now we have one of the two square roots, except if input was not a square */
 1819|     51|  fe25519_square(&chk, &r->x);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1820|     51|  fe25519_mul(&chk, &chk, &den);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1821|     51|  if (!fe25519_iseq_vartime(&chk, &num))
  ------------------
  |  |   77|     51|#define fe25519_iseq_vartime crypto_sign_ed25519_ref_fe25519_iseq_vartime
  ------------------
  |  Branch (1821:7): [True: 12, False: 39]
  ------------------
 1822|     12|    return -1;
 1823|       |
 1824|       |  /* 5. Choose the desired square root according to parity: */
 1825|     39|  if(fe25519_getparity(&r->x) != (1-par))
  ------------------
  |  |   82|     39|#define fe25519_getparity    crypto_sign_ed25519_ref_fe25519_getparity
  ------------------
  |  Branch (1825:6): [True: 25, False: 14]
  ------------------
 1826|     25|    fe25519_neg(&r->x, &r->x);
  ------------------
  |  |   81|     25|#define fe25519_neg          crypto_sign_ed25519_ref_fe25519_neg
  ------------------
 1827|       |
 1828|     39|  fe25519_mul(&r->t, &r->x, &r->y);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1829|     39|  return 0;
 1830|     51|}
crypto_sign_ed25519_open:
 1993|     61|{
 1994|     61|  unsigned char pkcopy[32];
 1995|     61|  unsigned char rcopy[32];
 1996|     61|  unsigned char hram[64];
 1997|     61|  unsigned char rcheck[32];
 1998|     61|  ge25519 get1, get2;
  ------------------
  |  |  724|     61|#define ge25519                           crypto_sign_ed25519_ref_ge25519
  ------------------
 1999|     61|  sc25519 schram, scs;
  ------------------
  |  |  461|     61|#define sc25519                  crypto_sign_ed25519_ref_sc25519
  ------------------
 2000|       |
 2001|     61|  if (smlen < 64) goto badsig;
  ------------------
  |  Branch (2001:7): [True: 0, False: 61]
  ------------------
 2002|     61|  if (sm[63] & 224) goto badsig;
  ------------------
  |  Branch (2002:7): [True: 10, False: 51]
  ------------------
 2003|     51|  if (ge25519_unpackneg_vartime(&get1,pk)) goto badsig;
  ------------------
  |  |  726|     51|#define ge25519_unpackneg_vartime         crypto_sign_ed25519_ref_unpackneg_vartime
  ------------------
  |  Branch (2003:7): [True: 12, False: 39]
  ------------------
 2004|       |
 2005|     39|  memmove(pkcopy,pk,32);
 2006|     39|  memmove(rcopy,sm,32);
 2007|       |
 2008|     39|  sc25519_from32bytes(&scs, sm+32);
  ------------------
  |  |  463|     39|#define sc25519_from32bytes      crypto_sign_ed25519_ref_sc25519_from32bytes
  ------------------
 2009|       |
 2010|     39|  memmove(m,sm,smlen);
 2011|     39|  memmove(m + 32,pkcopy,32);
 2012|     39|  crypto_hash_sha512(hram,m,smlen);
 2013|       |
 2014|     39|  sc25519_from64bytes(&schram, hram);
  ------------------
  |  |  464|     39|#define sc25519_from64bytes      crypto_sign_ed25519_ref_sc25519_from64bytes
  ------------------
 2015|       |
 2016|     39|  ge25519_double_scalarmult_vartime(&get2, &get1, &schram, &ge25519_base, &scs);
  ------------------
  |  |  729|     39|#define ge25519_double_scalarmult_vartime crypto_sign_ed25519_ref_double_scalarmult_vartime
  ------------------
                ge25519_double_scalarmult_vartime(&get2, &get1, &schram, &ge25519_base, &scs);
  ------------------
  |  |  725|     39|#define ge25519_base                      crypto_sign_ed25519_ref_ge25519_base
  ------------------
 2017|     39|  ge25519_pack(rcheck, &get2);
  ------------------
  |  |  727|     39|#define ge25519_pack                      crypto_sign_ed25519_ref_pack
  ------------------
 2018|       |
 2019|     39|  if (crypto_verify_32(rcopy,rcheck) == 0) {
  ------------------
  |  Branch (2019:7): [True: 3, False: 36]
  ------------------
 2020|      3|    memmove(m,m + 64,smlen - 64);
 2021|      3|    memset(m + smlen - 64,0,64);
 2022|      3|    *mlen = smlen - 64;
 2023|      3|    return 0;
 2024|      3|  }
 2025|       |
 2026|     58|badsig:
 2027|     58|  *mlen = (unsigned long long) -1;
 2028|     58|  memset(m,0,smlen);
 2029|     58|  return -1;
 2030|     39|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_freeze:
  203|    321|{
  204|    321|  int i;
  205|    321|  crypto_uint32 m = fe25519_equal(r->v[31],127);
  206|  9.95k|  for(i=30;i>0;i--)
  ------------------
  |  Branch (206:12): [True: 9.63k, False: 321]
  ------------------
  207|  9.63k|    m &= fe25519_equal(r->v[i],255);
  208|    321|  m &= ge(r->v[0],237);
  209|       |
  210|    321|  m = -m;
  211|       |
  212|    321|  r->v[31] -= m&127;
  213|  9.95k|  for(i=30;i>0;i--)
  ------------------
  |  Branch (213:12): [True: 9.63k, False: 321]
  ------------------
  214|  9.63k|    r->v[i] -= m&255;
  215|    321|  r->v[0] -= m&237;
  216|    321|}
ed25519.c:fe25519_equal:
  135|  9.95k|{
  136|  9.95k|  crypto_uint32 x = a ^ b; /* 0: yes; 1..65535: no */
  137|  9.95k|  x -= 1; /* 4294967295: yes; 0..65534: no */
  138|  9.95k|  x >>= 31; /* 1: yes; 0: no */
  139|  9.95k|  return x;
  140|  9.95k|}
ed25519.c:ge:
  143|    321|{
  144|    321|  unsigned int x = a;
  145|    321|  x -= (unsigned int) b; /* 0..65535: yes; 4294901761..4294967295: no */
  146|    321|  x >>= 31; /* 0: yes; 1: no */
  147|    321|  x ^= 1; /* 1: yes; 0: no */
  148|    321|  return x;
  149|    321|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_setone:
  275|    129|{
  276|    129|  int i;
  277|    129|  r->v[0] = 1;
  278|  4.12k|  for(i=1;i<32;i++) r->v[i]=0;
  ------------------
  |  Branch (278:11): [True: 3.99k, False: 129]
  ------------------
  279|    129|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_unpack:
  219|     51|{
  220|     51|  int i;
  221|  1.68k|  for(i=0;i<32;i++) r->v[i] = x[i];
  ------------------
  |  Branch (221:11): [True: 1.63k, False: 51]
  ------------------
  222|     51|  r->v[31] &= 127;
  223|     51|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_square:
  332|  62.7k|{
  333|  62.7k|  fe25519_mul(r, x, x);
  ------------------
  |  |   85|  62.7k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  334|  62.7k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_mul:
  315|   134k|{
  316|   134k|  int i,j;
  317|   134k|  crypto_uint32 t[63];
  318|  8.62M|  for(i=0;i<63;i++)t[i] = 0;
  ------------------
  |  Branch (318:11): [True: 8.49M, False: 134k]
  ------------------
  319|       |
  320|  4.44M|  for(i=0;i<32;i++)
  ------------------
  |  Branch (320:11): [True: 4.31M, False: 134k]
  ------------------
  321|   142M|    for(j=0;j<32;j++)
  ------------------
  |  Branch (321:13): [True: 138M, False: 4.31M]
  ------------------
  322|   138M|      t[i+j] += x->v[i] * y->v[j];
  323|       |
  324|  4.31M|  for(i=32;i<63;i++)
  ------------------
  |  Branch (324:12): [True: 4.17M, False: 134k]
  ------------------
  325|  4.17M|    r->v[i-32] = t[i-32] + times38(t[i]);
  326|   134k|  r->v[31] = t[31]; /* result now in r[0]...r[31] */
  327|       |
  328|   134k|  reduce_mul(r);
  329|   134k|}
ed25519.c:times38:
  157|  4.17M|{
  158|  4.17M|  return (a << 5) + (a << 2) + (a << 1);
  159|  4.17M|}
ed25519.c:reduce_mul:
  182|   134k|{
  183|   134k|  crypto_uint32 t;
  184|   134k|  int i,rep;
  185|       |
  186|   404k|  for(rep=0;rep<2;rep++)
  ------------------
  |  Branch (186:13): [True: 269k, False: 134k]
  ------------------
  187|   269k|  {
  188|   269k|    t = r->v[31] >> 7;
  189|   269k|    r->v[31] &= 127;
  190|   269k|    t = times19(t);
  191|   269k|    r->v[0] += t;
  192|  8.62M|    for(i=0;i<31;i++)
  ------------------
  |  Branch (192:13): [True: 8.35M, False: 269k]
  ------------------
  193|  8.35M|    {
  194|  8.35M|      t = r->v[i] >> 8;
  195|  8.35M|      r->v[i+1] += t;
  196|  8.35M|      r->v[i] &= 255;
  197|  8.35M|    }
  198|   269k|  }
  199|   134k|}
ed25519.c:times19:
  152|   750k|{
  153|   750k|  return (a << 4) + (a << 1) + a;
  154|   750k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_sub:
  304|  67.7k|{
  305|  67.7k|  int i;
  306|  67.7k|  crypto_uint32 t[32];
  307|  67.7k|  t[0] = x->v[0] + 0x1da;
  308|  67.7k|  t[31] = x->v[31] + 0xfe;
  309|  2.10M|  for(i=1;i<31;i++) t[i] = x->v[i] + 0x1fe;
  ------------------
  |  Branch (309:11): [True: 2.03M, False: 67.7k]
  ------------------
  310|  2.23M|  for(i=0;i<32;i++) r->v[i] = t[i] - y->v[i];
  ------------------
  |  Branch (310:11): [True: 2.16M, False: 67.7k]
  ------------------
  311|  67.7k|  fe25519_reduce_add_sub(r);
  312|  67.7k|}
ed25519.c:fe25519_reduce_add_sub:
  162|   120k|{
  163|   120k|  crypto_uint32 t;
  164|   120k|  int i,rep;
  165|       |
  166|   600k|  for(rep=0;rep<4;rep++)
  ------------------
  |  Branch (166:13): [True: 480k, False: 120k]
  ------------------
  167|   480k|  {
  168|   480k|    t = r->v[31] >> 7;
  169|   480k|    r->v[31] &= 127;
  170|   480k|    t = times19(t);
  171|   480k|    r->v[0] += t;
  172|  15.3M|    for(i=0;i<31;i++)
  ------------------
  |  Branch (172:13): [True: 14.8M, False: 480k]
  ------------------
  173|  14.8M|    {
  174|  14.8M|      t = r->v[i] >> 8;
  175|  14.8M|      r->v[i+1] += t;
  176|  14.8M|      r->v[i] &= 255;
  177|  14.8M|    }
  178|   480k|  }
  179|   120k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_add:
  297|  52.3k|{
  298|  52.3k|  int i;
  299|  1.72M|  for(i=0;i<32;i++) r->v[i] = x->v[i] + y->v[i];
  ------------------
  |  Branch (299:11): [True: 1.67M, False: 52.3k]
  ------------------
  300|  52.3k|  fe25519_reduce_add_sub(r);
  301|  52.3k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_pow2523:
  404|     51|{
  405|     51|	fe25519 z2;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  406|     51|	fe25519 z9;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  407|     51|	fe25519 z11;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  408|     51|	fe25519 z2_5_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  409|     51|	fe25519 z2_10_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  410|     51|	fe25519 z2_20_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  411|     51|	fe25519 z2_50_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  412|     51|	fe25519 z2_100_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  413|     51|	fe25519 t;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  414|     51|	int i;
  415|       |
  416|     51|	/* 2 */ fe25519_square(&z2,x);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  417|       |	/* 4 */ fe25519_square(&t,&z2);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  418|       |	/* 8 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  419|       |	/* 9 */ fe25519_mul(&z9,&t,x);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  420|       |	/* 11 */ fe25519_mul(&z11,&z9,&z2);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  421|       |	/* 22 */ fe25519_square(&t,&z11);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  422|       |	/* 2^5 - 2^0 = 31 */ fe25519_mul(&z2_5_0,&t,&z9);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  423|       |
  424|     51|	/* 2^6 - 2^1 */ fe25519_square(&t,&z2_5_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  425|    255|	/* 2^10 - 2^5 */ for (i = 1;i < 5;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    204|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (425:30): [True: 204, False: 51]
  ------------------
  426|       |	/* 2^10 - 2^0 */ fe25519_mul(&z2_10_0,&t,&z2_5_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  427|       |
  428|     51|	/* 2^11 - 2^1 */ fe25519_square(&t,&z2_10_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  429|    510|	/* 2^20 - 2^10 */ for (i = 1;i < 10;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    459|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (429:31): [True: 459, False: 51]
  ------------------
  430|       |	/* 2^20 - 2^0 */ fe25519_mul(&z2_20_0,&t,&z2_10_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  431|       |
  432|     51|	/* 2^21 - 2^1 */ fe25519_square(&t,&z2_20_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  433|  1.02k|	/* 2^40 - 2^20 */ for (i = 1;i < 20;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    969|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (433:31): [True: 969, False: 51]
  ------------------
  434|       |	/* 2^40 - 2^0 */ fe25519_mul(&t,&t,&z2_20_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  435|       |
  436|     51|	/* 2^41 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  437|    510|	/* 2^50 - 2^10 */ for (i = 1;i < 10;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    459|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (437:31): [True: 459, False: 51]
  ------------------
  438|       |	/* 2^50 - 2^0 */ fe25519_mul(&z2_50_0,&t,&z2_10_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  439|       |
  440|     51|	/* 2^51 - 2^1 */ fe25519_square(&t,&z2_50_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  441|  2.55k|	/* 2^100 - 2^50 */ for (i = 1;i < 50;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  2.49k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (441:32): [True: 2.49k, False: 51]
  ------------------
  442|       |	/* 2^100 - 2^0 */ fe25519_mul(&z2_100_0,&t,&z2_50_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  443|       |
  444|     51|	/* 2^101 - 2^1 */ fe25519_square(&t,&z2_100_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  445|  5.10k|	/* 2^200 - 2^100 */ for (i = 1;i < 100;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  5.04k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (445:33): [True: 5.04k, False: 51]
  ------------------
  446|       |	/* 2^200 - 2^0 */ fe25519_mul(&t,&t,&z2_100_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  447|       |
  448|     51|	/* 2^201 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  449|  2.55k|	/* 2^250 - 2^50 */ for (i = 1;i < 50;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  2.49k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (449:32): [True: 2.49k, False: 51]
  ------------------
  450|       |	/* 2^250 - 2^0 */ fe25519_mul(&t,&t,&z2_50_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  451|       |
  452|     51|	/* 2^251 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  453|       |	/* 2^252 - 2^2 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  454|       |	/* 2^252 - 3 */ fe25519_mul(r,&t,x);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  455|     51|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_iseq_vartime:
  248|    102|{
  249|    102|  int i;
  250|    102|  fe25519 t1 = *x;
  ------------------
  |  |   72|    102|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  251|    102|  fe25519 t2 = *y;
  ------------------
  |  |   72|    102|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  252|    102|  fe25519_freeze(&t1);
  ------------------
  |  |   73|    102|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  253|    102|  fe25519_freeze(&t2);
  ------------------
  |  |   73|    102|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  254|  2.00k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (254:11): [True: 1.94k, False: 59]
  ------------------
  255|  1.94k|    if(t1.v[i] != t2.v[i]) return 0;
  ------------------
  |  Branch (255:8): [True: 43, False: 1.89k]
  ------------------
  256|     59|  return 1;
  257|    102|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_neg:
  288|  9.97k|{
  289|  9.97k|  fe25519 t;
  ------------------
  |  |   72|  9.97k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  290|  9.97k|  int i;
  291|   329k|  for(i=0;i<32;i++) t.v[i]=x->v[i];
  ------------------
  |  Branch (291:11): [True: 319k, False: 9.97k]
  ------------------
  292|  9.97k|  fe25519_setzero(r);
  ------------------
  |  |   80|  9.97k|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
  293|  9.97k|  fe25519_sub(r, r, &t);
  ------------------
  |  |   84|  9.97k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
  294|  9.97k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_setzero:
  282|  10.0k|{
  283|  10.0k|  int i;
  284|   331k|  for(i=0;i<32;i++) r->v[i]=0;
  ------------------
  |  Branch (284:11): [True: 321k, False: 10.0k]
  ------------------
  285|  10.0k|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_from32bytes:
  604|     39|{
  605|     39|  int i;
  606|     39|  crypto_uint32 t[64];
  607|  1.28k|  for(i=0;i<32;i++) t[i] = x[i];
  ------------------
  |  Branch (607:11): [True: 1.24k, False: 39]
  ------------------
  608|  1.28k|  for(i=32;i<64;++i) t[i] = 0;
  ------------------
  |  Branch (608:12): [True: 1.24k, False: 39]
  ------------------
  609|     39|  barrett_reduce(r, t);
  610|     39|}
ed25519.c:barrett_reduce:
  553|     78|{
  554|       |  /* See HAC, Alg. 14.42 */
  555|     78|  int i,j;
  556|     78|  crypto_uint32 q2[66];
  557|     78|  crypto_uint32 *q3 = q2 + 33;
  558|     78|  crypto_uint32 r1[33];
  559|     78|  crypto_uint32 r2[33];
  560|     78|  crypto_uint32 carry;
  561|     78|  crypto_uint32 pb = 0;
  562|     78|  crypto_uint32 b;
  563|       |
  564|  5.22k|  for (i = 0;i < 66;++i) q2[i] = 0;
  ------------------
  |  Branch (564:14): [True: 5.14k, False: 78]
  ------------------
  565|  2.65k|  for (i = 0;i < 33;++i) r2[i] = 0;
  ------------------
  |  Branch (565:14): [True: 2.57k, False: 78]
  ------------------
  566|       |
  567|  2.65k|  for(i=0;i<33;i++)
  ------------------
  |  Branch (567:11): [True: 2.57k, False: 78]
  ------------------
  568|  87.5k|    for(j=0;j<33;j++)
  ------------------
  |  Branch (568:13): [True: 84.9k, False: 2.57k]
  ------------------
  569|  84.9k|      if(i+j >= 31) q2[i+j] += sc25519_mu[i]*x[j+31];
  ------------------
  |  Branch (569:10): [True: 46.2k, False: 38.6k]
  ------------------
  570|     78|  carry = q2[31] >> 8;
  571|     78|  q2[32] += carry;
  572|     78|  carry = q2[32] >> 8;
  573|     78|  q2[33] += carry;
  574|       |
  575|  2.65k|  for(i=0;i<33;i++)r1[i] = x[i];
  ------------------
  |  Branch (575:11): [True: 2.57k, False: 78]
  ------------------
  576|  2.57k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (576:11): [True: 2.49k, False: 78]
  ------------------
  577|  84.8k|    for(j=0;j<33;j++)
  ------------------
  |  Branch (577:13): [True: 82.3k, False: 2.49k]
  ------------------
  578|  82.3k|      if(i+j < 33) r2[i+j] += sc25519_m[i]*q3[j];
  ------------------
  |  Branch (578:10): [True: 43.6k, False: 38.6k]
  ------------------
  579|       |
  580|  2.57k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (580:11): [True: 2.49k, False: 78]
  ------------------
  581|  2.49k|  {
  582|  2.49k|    carry = r2[i] >> 8;
  583|  2.49k|    r2[i+1] += carry;
  584|  2.49k|    r2[i] &= 0xff;
  585|  2.49k|  }
  586|       |
  587|  2.57k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (587:11): [True: 2.49k, False: 78]
  ------------------
  588|  2.49k|  {
  589|  2.49k|    pb += r2[i];
  590|  2.49k|    b = lt(r1[i],pb);
  591|  2.49k|    r->v[i] = r1[i]-pb+(b<<8);
  592|  2.49k|    pb = b;
  593|  2.49k|  }
  594|       |
  595|       |  /* XXX: Can it really happen that r<0?, See HAC, Alg 14.42, Step 3
  596|       |   * If so: Handle  it here!
  597|       |   */
  598|       |
  599|     78|  sc25519_reduce_add_sub(r);
  600|     78|  sc25519_reduce_add_sub(r);
  601|     78|}
ed25519.c:lt:
  523|  7.48k|{
  524|  7.48k|  unsigned int x = a;
  525|  7.48k|  x -= (unsigned int) b; /* 0..65535: no; 4294901761..4294967295: yes */
  526|  7.48k|  x >>= 31; /* 0: no; 1: yes */
  527|  7.48k|  return x;
  528|  7.48k|}
ed25519.c:sc25519_reduce_add_sub:
  532|    156|{
  533|    156|  crypto_uint32 pb = 0;
  534|    156|  crypto_uint32 b;
  535|    156|  crypto_uint32 mask;
  536|    156|  int i;
  537|    156|  unsigned char t[32];
  538|       |
  539|  5.14k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (539:11): [True: 4.99k, False: 156]
  ------------------
  540|  4.99k|  {
  541|  4.99k|    pb += sc25519_m[i];
  542|  4.99k|    b = lt(r->v[i],pb);
  543|  4.99k|    t[i] = r->v[i]-pb+(b<<8);
  544|  4.99k|    pb = b;
  545|  4.99k|  }
  546|    156|  mask = b - 1;
  547|  5.14k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (547:11): [True: 4.99k, False: 156]
  ------------------
  548|  4.99k|    r->v[i] ^= mask & (r->v[i] ^ t[i]);
  549|    156|}
ed25519.c:crypto_sign_ed25519_ref_pack:
 1833|     39|{
 1834|     39|  fe25519 tx, ty, zi;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1835|     39|  fe25519_invert(&zi, &p->z);
  ------------------
  |  |   87|     39|#define fe25519_invert       crypto_sign_ed25519_ref_fe25519_invert
  ------------------
 1836|     39|  fe25519_mul(&tx, &p->x, &zi);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1837|     39|  fe25519_mul(&ty, &p->y, &zi);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1838|     39|  fe25519_pack(r, &ty);
  ------------------
  |  |   75|     39|#define fe25519_pack         crypto_sign_ed25519_ref_fe25519_pack
  ------------------
 1839|     39|  r[31] ^= fe25519_getparity(&tx) << 7;
  ------------------
  |  |   82|     39|#define fe25519_getparity    crypto_sign_ed25519_ref_fe25519_getparity
  ------------------
 1840|     39|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_invert:
  337|     39|{
  338|     39|	fe25519 z2;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  339|     39|	fe25519 z9;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  340|     39|	fe25519 z11;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  341|     39|	fe25519 z2_5_0;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  342|     39|	fe25519 z2_10_0;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  343|     39|	fe25519 z2_20_0;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  344|     39|	fe25519 z2_50_0;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  345|     39|	fe25519 z2_100_0;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  346|     39|	fe25519 t0;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  347|     39|	fe25519 t1;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  348|     39|	int i;
  349|       |
  350|     39|	/* 2 */ fe25519_square(&z2,x);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  351|       |	/* 4 */ fe25519_square(&t1,&z2);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  352|       |	/* 8 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  353|       |	/* 9 */ fe25519_mul(&z9,&t0,x);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  354|       |	/* 11 */ fe25519_mul(&z11,&z9,&z2);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  355|       |	/* 22 */ fe25519_square(&t0,&z11);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  356|       |	/* 2^5 - 2^0 = 31 */ fe25519_mul(&z2_5_0,&t0,&z9);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  357|       |
  358|     39|	/* 2^6 - 2^1 */ fe25519_square(&t0,&z2_5_0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  359|       |	/* 2^7 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  360|       |	/* 2^8 - 2^3 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  361|       |	/* 2^9 - 2^4 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  362|       |	/* 2^10 - 2^5 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  363|       |	/* 2^10 - 2^0 */ fe25519_mul(&z2_10_0,&t0,&z2_5_0);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  364|       |
  365|     39|	/* 2^11 - 2^1 */ fe25519_square(&t0,&z2_10_0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  366|       |	/* 2^12 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  367|    195|	/* 2^20 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    156|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^20 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    156|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (367:31): [True: 156, False: 39]
  ------------------
  368|       |	/* 2^20 - 2^0 */ fe25519_mul(&z2_20_0,&t1,&z2_10_0);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  369|       |
  370|     39|	/* 2^21 - 2^1 */ fe25519_square(&t0,&z2_20_0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  371|       |	/* 2^22 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  372|    390|	/* 2^40 - 2^20 */ for (i = 2;i < 20;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    351|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^40 - 2^20 */ for (i = 2;i < 20;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    351|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (372:31): [True: 351, False: 39]
  ------------------
  373|       |	/* 2^40 - 2^0 */ fe25519_mul(&t0,&t1,&z2_20_0);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  374|       |
  375|     39|	/* 2^41 - 2^1 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  376|       |	/* 2^42 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  377|    195|	/* 2^50 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|    156|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^50 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|    156|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (377:31): [True: 156, False: 39]
  ------------------
  378|       |	/* 2^50 - 2^0 */ fe25519_mul(&z2_50_0,&t0,&z2_10_0);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  379|       |
  380|     39|	/* 2^51 - 2^1 */ fe25519_square(&t0,&z2_50_0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  381|       |	/* 2^52 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  382|    975|	/* 2^100 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    936|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^100 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    936|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (382:32): [True: 936, False: 39]
  ------------------
  383|       |	/* 2^100 - 2^0 */ fe25519_mul(&z2_100_0,&t1,&z2_50_0);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  384|       |
  385|     39|	/* 2^101 - 2^1 */ fe25519_square(&t1,&z2_100_0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  386|       |	/* 2^102 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  387|  1.95k|	/* 2^200 - 2^100 */ for (i = 2;i < 100;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|  1.91k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^200 - 2^100 */ for (i = 2;i < 100;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|  1.91k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (387:33): [True: 1.91k, False: 39]
  ------------------
  388|       |	/* 2^200 - 2^0 */ fe25519_mul(&t1,&t0,&z2_100_0);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  389|       |
  390|     39|	/* 2^201 - 2^1 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  391|       |	/* 2^202 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  392|    975|	/* 2^250 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    936|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^250 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    936|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (392:32): [True: 936, False: 39]
  ------------------
  393|       |	/* 2^250 - 2^0 */ fe25519_mul(&t0,&t1,&z2_50_0);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  394|       |
  395|     39|	/* 2^251 - 2^1 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  396|       |	/* 2^252 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  397|       |	/* 2^253 - 2^3 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  398|       |	/* 2^254 - 2^4 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  399|       |	/* 2^255 - 2^5 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     39|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  400|       |	/* 2^255 - 21 */ fe25519_mul(r,&t1,&z11);
  ------------------
  |  |   85|     39|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  401|     39|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_pack:
  227|     39|{
  228|     39|  int i;
  229|     39|  fe25519 y = *x;
  ------------------
  |  |   72|     39|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  230|     39|  fe25519_freeze(&y);
  ------------------
  |  |   73|     39|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  231|  1.28k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (231:11): [True: 1.24k, False: 39]
  ------------------
  232|  1.24k|    r[i] = y.v[i];
  233|     39|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_from64bytes:
  614|     39|{
  615|     39|  int i;
  616|     39|  crypto_uint32 t[64];
  617|  2.53k|  for(i=0;i<64;i++) t[i] = x[i];
  ------------------
  |  Branch (617:11): [True: 2.49k, False: 39]
  ------------------
  618|     39|  barrett_reduce(r, t);
  619|     39|}
ed25519.c:crypto_sign_ed25519_ref_double_scalarmult_vartime:
 1852|     39|{
 1853|     39|  ge25519_p1p1 tp1p1;
 1854|     39|  ge25519_p3 pre[16];
  ------------------
  |  |  771|     39|#define ge25519_p3 ge25519
  |  |  ------------------
  |  |  |  |  724|     39|#define ge25519                           crypto_sign_ed25519_ref_ge25519
  |  |  ------------------
  ------------------
 1855|     39|  unsigned char b[127];
 1856|     39|  int i;
 1857|       |
 1858|       |  /* precomputation                                                        s2 s1 */
 1859|     39|  setneutral(pre);                                                      /* 00 00 */
 1860|     39|  pre[1] = *p1;                                                         /* 00 01 */
 1861|     39|  dbl_p1p1(&tp1p1,(ge25519_p2 *)p1);      p1p1_to_p3( &pre[2], &tp1p1); /* 00 10 */
 1862|     39|  add_p1p1(&tp1p1,&pre[1], &pre[2]);      p1p1_to_p3( &pre[3], &tp1p1); /* 00 11 */
 1863|     39|  pre[4] = *p2;                                                         /* 01 00 */
 1864|     39|  add_p1p1(&tp1p1,&pre[1], &pre[4]);      p1p1_to_p3( &pre[5], &tp1p1); /* 01 01 */
 1865|     39|  add_p1p1(&tp1p1,&pre[2], &pre[4]);      p1p1_to_p3( &pre[6], &tp1p1); /* 01 10 */
 1866|     39|  add_p1p1(&tp1p1,&pre[3], &pre[4]);      p1p1_to_p3( &pre[7], &tp1p1); /* 01 11 */
 1867|     39|  dbl_p1p1(&tp1p1,(ge25519_p2 *)p2);      p1p1_to_p3( &pre[8], &tp1p1); /* 10 00 */
 1868|     39|  add_p1p1(&tp1p1,&pre[1], &pre[8]);      p1p1_to_p3( &pre[9], &tp1p1); /* 10 01 */
 1869|     39|  dbl_p1p1(&tp1p1,(ge25519_p2 *)&pre[5]); p1p1_to_p3(&pre[10], &tp1p1); /* 10 10 */
 1870|     39|  add_p1p1(&tp1p1,&pre[3], &pre[8]);      p1p1_to_p3(&pre[11], &tp1p1); /* 10 11 */
 1871|     39|  add_p1p1(&tp1p1,&pre[4], &pre[8]);      p1p1_to_p3(&pre[12], &tp1p1); /* 11 00 */
 1872|     39|  add_p1p1(&tp1p1,&pre[1],&pre[12]);      p1p1_to_p3(&pre[13], &tp1p1); /* 11 01 */
 1873|     39|  add_p1p1(&tp1p1,&pre[2],&pre[12]);      p1p1_to_p3(&pre[14], &tp1p1); /* 11 10 */
 1874|     39|  add_p1p1(&tp1p1,&pre[3],&pre[12]);      p1p1_to_p3(&pre[15], &tp1p1); /* 11 11 */
 1875|       |
 1876|     39|  sc25519_2interleave2(b,s1,s2);
  ------------------
  |  |  469|     39|#define sc25519_2interleave2     crypto_sign_ed25519_ref_sc25519_2interleave2
  ------------------
 1877|       |
 1878|       |  /* scalar multiplication */
 1879|     39|  *r = pre[b[126]];
 1880|  4.95k|  for(i=125;i>=0;i--)
  ------------------
  |  Branch (1880:13): [True: 4.91k, False: 39]
  ------------------
 1881|  4.91k|  {
 1882|  4.91k|    dbl_p1p1(&tp1p1, (ge25519_p2 *)r);
 1883|  4.91k|    p1p1_to_p2((ge25519_p2 *) r, &tp1p1);
 1884|  4.91k|    dbl_p1p1(&tp1p1, (ge25519_p2 *)r);
 1885|  4.91k|    if(b[i]!=0)
  ------------------
  |  Branch (1885:8): [True: 4.10k, False: 811]
  ------------------
 1886|  4.10k|    {
 1887|  4.10k|      p1p1_to_p3(r, &tp1p1);
 1888|  4.10k|      add_p1p1(&tp1p1, r, &pre[b[i]]);
 1889|  4.10k|    }
 1890|  4.91k|    if(i != 0) p1p1_to_p2((ge25519_p2 *)r, &tp1p1);
  ------------------
  |  Branch (1890:8): [True: 4.87k, False: 39]
  ------------------
 1891|     39|    else p1p1_to_p3(r, &tp1p1);
 1892|  4.91k|  }
 1893|     39|}
ed25519.c:setneutral:
 1773|     39|{
 1774|     39|  fe25519_setzero(&r->x);
  ------------------
  |  |   80|     39|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
 1775|     39|  fe25519_setone(&r->y);
  ------------------
  |  |   79|     39|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1776|     39|  fe25519_setone(&r->z);
  ------------------
  |  |   79|     39|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1777|     39|  fe25519_setzero(&r->t);
  ------------------
  |  |   80|     39|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
 1778|     39|}
ed25519.c:dbl_p1p1:
 1717|  9.94k|{
 1718|  9.94k|  fe25519 a,b,c,d;
  ------------------
  |  |   72|  9.94k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1719|  9.94k|  fe25519_square(&a, &p->x);
  ------------------
  |  |   86|  9.94k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1720|  9.94k|  fe25519_square(&b, &p->y);
  ------------------
  |  |   86|  9.94k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1721|  9.94k|  fe25519_square(&c, &p->z);
  ------------------
  |  |   86|  9.94k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1722|  9.94k|  fe25519_add(&c, &c, &c);
  ------------------
  |  |   83|  9.94k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1723|  9.94k|  fe25519_neg(&d, &a);
  ------------------
  |  |   81|  9.94k|#define fe25519_neg          crypto_sign_ed25519_ref_fe25519_neg
  ------------------
 1724|       |
 1725|  9.94k|  fe25519_add(&r->x, &p->x, &p->y);
  ------------------
  |  |   83|  9.94k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1726|  9.94k|  fe25519_square(&r->x, &r->x);
  ------------------
  |  |   86|  9.94k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1727|  9.94k|  fe25519_sub(&r->x, &r->x, &a);
  ------------------
  |  |   84|  9.94k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1728|  9.94k|  fe25519_sub(&r->x, &r->x, &b);
  ------------------
  |  |   84|  9.94k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1729|  9.94k|  fe25519_add(&r->z, &d, &b);
  ------------------
  |  |   83|  9.94k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1730|  9.94k|  fe25519_sub(&r->t, &r->z, &c);
  ------------------
  |  |   84|  9.94k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1731|  9.94k|  fe25519_sub(&r->y, &d, &b);
  ------------------
  |  |   84|  9.94k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1732|  9.94k|}
ed25519.c:p1p1_to_p3:
 1667|  4.64k|{
 1668|  4.64k|  p1p1_to_p2((ge25519_p2 *)r, p);
 1669|  4.64k|  fe25519_mul(&r->t, &p->x, &p->y);
  ------------------
  |  |   85|  4.64k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1670|  4.64k|}
ed25519.c:add_p1p1:
 1696|  4.49k|{
 1697|  4.49k|  fe25519 a, b, c, d, t;
  ------------------
  |  |   72|  4.49k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1698|       |
 1699|  4.49k|  fe25519_sub(&a, &p->y, &p->x); /* A = (Y1-X1)*(Y2-X2) */
  ------------------
  |  |   84|  4.49k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1700|  4.49k|  fe25519_sub(&t, &q->y, &q->x);
  ------------------
  |  |   84|  4.49k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1701|  4.49k|  fe25519_mul(&a, &a, &t);
  ------------------
  |  |   85|  4.49k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1702|  4.49k|  fe25519_add(&b, &p->x, &p->y); /* B = (Y1+X1)*(Y2+X2) */
  ------------------
  |  |   83|  4.49k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1703|  4.49k|  fe25519_add(&t, &q->x, &q->y);
  ------------------
  |  |   83|  4.49k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1704|  4.49k|  fe25519_mul(&b, &b, &t);
  ------------------
  |  |   85|  4.49k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1705|  4.49k|  fe25519_mul(&c, &p->t, &q->t); /* C = T1*k*T2 */
  ------------------
  |  |   85|  4.49k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1706|  4.49k|  fe25519_mul(&c, &c, &ge25519_ec2d);
  ------------------
  |  |   85|  4.49k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1707|  4.49k|  fe25519_mul(&d, &p->z, &q->z); /* D = Z1*2*Z2 */
  ------------------
  |  |   85|  4.49k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1708|  4.49k|  fe25519_add(&d, &d, &d);
  ------------------
  |  |   83|  4.49k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1709|  4.49k|  fe25519_sub(&r->x, &b, &a); /* E = B-A */
  ------------------
  |  |   84|  4.49k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1710|  4.49k|  fe25519_sub(&r->t, &d, &c); /* F = D-C */
  ------------------
  |  |   84|  4.49k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1711|  4.49k|  fe25519_add(&r->z, &d, &c); /* G = D+C */
  ------------------
  |  |   83|  4.49k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1712|  4.49k|  fe25519_add(&r->y, &b, &a); /* H = B+A */
  ------------------
  |  |   83|  4.49k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1713|  4.49k|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_2interleave2:
  706|     39|{
  707|     39|  int i;
  708|  1.24k|  for(i=0;i<31;i++)
  ------------------
  |  Branch (708:11): [True: 1.20k, False: 39]
  ------------------
  709|  1.20k|  {
  710|  1.20k|    r[4*i]   = ( s1->v[i]       & 3) ^ (( s2->v[i]       & 3) << 2);
  711|  1.20k|    r[4*i+1] = ((s1->v[i] >> 2) & 3) ^ (((s2->v[i] >> 2) & 3) << 2);
  712|  1.20k|    r[4*i+2] = ((s1->v[i] >> 4) & 3) ^ (((s2->v[i] >> 4) & 3) << 2);
  713|  1.20k|    r[4*i+3] = ((s1->v[i] >> 6) & 3) ^ (((s2->v[i] >> 6) & 3) << 2);
  714|  1.20k|  }
  715|     39|  r[124] = ( s1->v[31]       & 3) ^ (( s2->v[31]       & 3) << 2);
  716|     39|  r[125] = ((s1->v[31] >> 2) & 3) ^ (((s2->v[31] >> 2) & 3) << 2);
  717|     39|  r[126] = ((s1->v[31] >> 4) & 3) ^ (((s2->v[31] >> 4) & 3) << 2);
  718|     39|}
ed25519.c:p1p1_to_p2:
 1660|  14.4k|{
 1661|  14.4k|  fe25519_mul(&r->x, &p->x, &p->t);
  ------------------
  |  |   85|  14.4k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1662|  14.4k|  fe25519_mul(&r->y, &p->y, &p->z);
  ------------------
  |  |   85|  14.4k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1663|  14.4k|  fe25519_mul(&r->z, &p->z, &p->t);
  ------------------
  |  |   85|  14.4k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1664|  14.4k|}
ed25519.c:crypto_verify_32:
   30|     39|{
   31|     39|  unsigned int differentbits = 0;
   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
   33|     39|  F(0)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   34|     39|  F(1)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   35|     39|  F(2)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   36|     39|  F(3)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   37|     39|  F(4)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   38|     39|  F(5)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   39|     39|  F(6)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   40|     39|  F(7)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   41|     39|  F(8)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   42|     39|  F(9)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   43|     39|  F(10)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   44|     39|  F(11)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   45|     39|  F(12)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   46|     39|  F(13)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   47|     39|  F(14)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   48|     39|  F(15)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   49|     39|  F(16)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   50|     39|  F(17)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   51|     39|  F(18)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   52|     39|  F(19)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   53|     39|  F(20)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   54|     39|  F(21)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   55|     39|  F(22)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   56|     39|  F(23)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   57|     39|  F(24)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   58|     39|  F(25)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   59|     39|  F(26)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   60|     39|  F(27)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   61|     39|  F(28)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   62|     39|  F(29)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   63|     39|  F(30)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   64|     39|  F(31)
  ------------------
  |  |   32|     39|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   65|     39|  return (1 & ((differentbits - 1) >> 8)) - 1;
   66|     39|}

crypto_hash_sha512:
   19|     39|{
   20|       |
   21|     39|	if (!EVP_Digest(in, inlen, out, NULL, EVP_sha512(), NULL))
  ------------------
  |  Branch (21:6): [True: 0, False: 39]
  ------------------
   22|      0|		return -1;
   23|     39|	return 0;
   24|     39|}

log_init:
  196|  2.53k|{
  197|       |#if defined(HAVE_OPENLOG_R) && defined(SYSLOG_DATA_INIT)
  198|       |	struct syslog_data sdata = SYSLOG_DATA_INIT;
  199|       |#endif
  200|       |
  201|  2.53k|	argv0 = av0;
  202|       |
  203|  2.53k|	if (log_change_level(level) != 0) {
  ------------------
  |  Branch (203:6): [True: 0, False: 2.53k]
  ------------------
  204|      0|		fprintf(stderr, "Unrecognized internal syslog level code %d\n",
  205|      0|		    (int) level);
  206|      0|		exit(1);
  207|      0|	}
  208|       |
  209|  2.53k|	log_handler = NULL;
  210|  2.53k|	log_handler_ctx = NULL;
  211|       |
  212|  2.53k|	log_on_stderr = on_stderr;
  213|  2.53k|	if (on_stderr)
  ------------------
  |  Branch (213:6): [True: 2.53k, False: 0]
  ------------------
  214|  2.53k|		return;
  215|       |
  216|      0|	switch (facility) {
  217|      0|	case SYSLOG_FACILITY_DAEMON:
  ------------------
  |  Branch (217:2): [True: 0, False: 0]
  ------------------
  218|      0|		log_facility = LOG_DAEMON;
  219|      0|		break;
  220|      0|	case SYSLOG_FACILITY_USER:
  ------------------
  |  Branch (220:2): [True: 0, False: 0]
  ------------------
  221|      0|		log_facility = LOG_USER;
  222|      0|		break;
  223|      0|	case SYSLOG_FACILITY_AUTH:
  ------------------
  |  Branch (223:2): [True: 0, False: 0]
  ------------------
  224|      0|		log_facility = LOG_AUTH;
  225|      0|		break;
  226|      0|#ifdef LOG_AUTHPRIV
  227|      0|	case SYSLOG_FACILITY_AUTHPRIV:
  ------------------
  |  Branch (227:2): [True: 0, False: 0]
  ------------------
  228|      0|		log_facility = LOG_AUTHPRIV;
  229|      0|		break;
  230|      0|#endif
  231|      0|	case SYSLOG_FACILITY_LOCAL0:
  ------------------
  |  Branch (231:2): [True: 0, False: 0]
  ------------------
  232|      0|		log_facility = LOG_LOCAL0;
  233|      0|		break;
  234|      0|	case SYSLOG_FACILITY_LOCAL1:
  ------------------
  |  Branch (234:2): [True: 0, False: 0]
  ------------------
  235|      0|		log_facility = LOG_LOCAL1;
  236|      0|		break;
  237|      0|	case SYSLOG_FACILITY_LOCAL2:
  ------------------
  |  Branch (237:2): [True: 0, False: 0]
  ------------------
  238|      0|		log_facility = LOG_LOCAL2;
  239|      0|		break;
  240|      0|	case SYSLOG_FACILITY_LOCAL3:
  ------------------
  |  Branch (240:2): [True: 0, False: 0]
  ------------------
  241|      0|		log_facility = LOG_LOCAL3;
  242|      0|		break;
  243|      0|	case SYSLOG_FACILITY_LOCAL4:
  ------------------
  |  Branch (243:2): [True: 0, False: 0]
  ------------------
  244|      0|		log_facility = LOG_LOCAL4;
  245|      0|		break;
  246|      0|	case SYSLOG_FACILITY_LOCAL5:
  ------------------
  |  Branch (246:2): [True: 0, False: 0]
  ------------------
  247|      0|		log_facility = LOG_LOCAL5;
  248|      0|		break;
  249|      0|	case SYSLOG_FACILITY_LOCAL6:
  ------------------
  |  Branch (249:2): [True: 0, False: 0]
  ------------------
  250|      0|		log_facility = LOG_LOCAL6;
  251|      0|		break;
  252|      0|	case SYSLOG_FACILITY_LOCAL7:
  ------------------
  |  Branch (252:2): [True: 0, False: 0]
  ------------------
  253|      0|		log_facility = LOG_LOCAL7;
  254|      0|		break;
  255|      0|	default:
  ------------------
  |  Branch (255:2): [True: 0, False: 0]
  ------------------
  256|      0|		fprintf(stderr,
  257|      0|		    "Unrecognized internal syslog facility code %d\n",
  258|      0|		    (int) facility);
  259|      0|		exit(1);
  260|      0|	}
  261|       |
  262|       |	/*
  263|       |	 * If an external library (eg libwrap) attempts to use syslog
  264|       |	 * immediately after reexec, syslog may be pointing to the wrong
  265|       |	 * facility, so we force an open/close of syslog here.
  266|       |	 */
  267|       |#if defined(HAVE_OPENLOG_R) && defined(SYSLOG_DATA_INIT)
  268|       |	openlog_r(argv0 ? argv0 : __progname, LOG_PID, log_facility, &sdata);
  269|       |	closelog_r(&sdata);
  270|       |#else
  271|      0|	openlog(argv0 ? argv0 : __progname, LOG_PID, log_facility);
  ------------------
  |  Branch (271:10): [True: 0, False: 0]
  ------------------
  272|      0|	closelog();
  273|      0|#endif
  274|      0|}
log_change_level:
  278|  2.53k|{
  279|       |	/* no-op if log_init has not been called */
  280|  2.53k|	if (argv0 == NULL)
  ------------------
  |  Branch (280:6): [True: 0, False: 2.53k]
  ------------------
  281|      0|		return 0;
  282|       |
  283|  2.53k|	switch (new_log_level) {
  284|  2.53k|	case SYSLOG_LEVEL_QUIET:
  ------------------
  |  Branch (284:2): [True: 2.53k, False: 0]
  ------------------
  285|  2.53k|	case SYSLOG_LEVEL_FATAL:
  ------------------
  |  Branch (285:2): [True: 0, False: 2.53k]
  ------------------
  286|  2.53k|	case SYSLOG_LEVEL_ERROR:
  ------------------
  |  Branch (286:2): [True: 0, False: 2.53k]
  ------------------
  287|  2.53k|	case SYSLOG_LEVEL_INFO:
  ------------------
  |  Branch (287:2): [True: 0, False: 2.53k]
  ------------------
  288|  2.53k|	case SYSLOG_LEVEL_VERBOSE:
  ------------------
  |  Branch (288:2): [True: 0, False: 2.53k]
  ------------------
  289|  2.53k|	case SYSLOG_LEVEL_DEBUG1:
  ------------------
  |  Branch (289:2): [True: 0, False: 2.53k]
  ------------------
  290|  2.53k|	case SYSLOG_LEVEL_DEBUG2:
  ------------------
  |  Branch (290:2): [True: 0, False: 2.53k]
  ------------------
  291|  2.53k|	case SYSLOG_LEVEL_DEBUG3:
  ------------------
  |  Branch (291:2): [True: 0, False: 2.53k]
  ------------------
  292|  2.53k|		log_level = new_log_level;
  293|  2.53k|		return 0;
  294|      0|	default:
  ------------------
  |  Branch (294:2): [True: 0, False: 2.53k]
  ------------------
  295|      0|		return -1;
  296|  2.53k|	}
  297|  2.53k|}
sshlog:
  429|  9.06k|{
  430|  9.06k|	va_list args;
  431|       |
  432|  9.06k|	va_start(args, fmt);
  433|  9.06k|	sshlogv(file, func, line, showfunc, level, suffix, fmt, args);
  434|  9.06k|	va_end(args);
  435|  9.06k|}
sshlogv:
  453|  9.06k|{
  454|  9.06k|	char tag[128], fmt2[MSGBUFSIZ + 128];
  455|  9.06k|	int forced = 0;
  456|  9.06k|	const char *cp;
  457|  9.06k|	size_t i;
  458|       |
  459|       |	/* short circuit processing early if we're not going to log anything */
  460|  9.06k|	if (nlog_verbose == 0 && level > log_level)
  ------------------
  |  Branch (460:6): [True: 9.06k, False: 0]
  |  Branch (460:27): [True: 9.06k, False: 0]
  ------------------
  461|  9.06k|		return;
  462|       |
  463|      0|	snprintf(tag, sizeof(tag), "%.48s:%.48s():%d (pid=%ld)",
  464|      0|	    (cp = strrchr(file, '/')) == NULL ? file : cp + 1, func, line,
  ------------------
  |  Branch (464:6): [True: 0, False: 0]
  ------------------
  465|      0|	    (long)getpid());
  466|      0|	for (i = 0; i < nlog_verbose; i++) {
  ------------------
  |  Branch (466:14): [True: 0, False: 0]
  ------------------
  467|      0|		if (match_pattern_list(tag, log_verbose[i], 0) == 1) {
  ------------------
  |  Branch (467:7): [True: 0, False: 0]
  ------------------
  468|      0|			forced = 1;
  469|      0|			break;
  470|      0|		}
  471|      0|	}
  472|       |
  473|      0|	if (forced)
  ------------------
  |  Branch (473:6): [True: 0, False: 0]
  ------------------
  474|      0|		snprintf(fmt2, sizeof(fmt2), "%s: %s", tag, fmt);
  475|      0|	else if (showfunc)
  ------------------
  |  Branch (475:11): [True: 0, False: 0]
  ------------------
  476|      0|		snprintf(fmt2, sizeof(fmt2), "%s: %s", func, fmt);
  477|      0|	else
  478|      0|		strlcpy(fmt2, fmt, sizeof(fmt2));
  479|       |
  480|      0|	do_log(level, forced, suffix, fmt2, args);
  481|      0|}

match_pattern:
   58|  4.38k|{
   59|  24.1k|	for (;;) {
   60|       |		/* If at end of pattern, accept if also at end of string. */
   61|  24.1k|		if (!*pattern)
  ------------------
  |  Branch (61:7): [True: 2.14k, False: 22.0k]
  ------------------
   62|  2.14k|			return !*s;
   63|       |
   64|  22.0k|		if (*pattern == '*') {
  ------------------
  |  Branch (64:7): [True: 0, False: 22.0k]
  ------------------
   65|       |			/* Skip this and any consecutive asterisks. */
   66|      0|			while (*pattern == '*')
  ------------------
  |  Branch (66:11): [True: 0, False: 0]
  ------------------
   67|      0|				pattern++;
   68|       |
   69|       |			/* If at end of pattern, accept immediately. */
   70|      0|			if (!*pattern)
  ------------------
  |  Branch (70:8): [True: 0, False: 0]
  ------------------
   71|      0|				return 1;
   72|       |
   73|       |			/* If next character in pattern is known, optimize. */
   74|      0|			if (*pattern != '?' && *pattern != '*') {
  ------------------
  |  Branch (74:8): [True: 0, False: 0]
  |  Branch (74:27): [True: 0, False: 0]
  ------------------
   75|       |				/*
   76|       |				 * Look instances of the next character in
   77|       |				 * pattern, and try to match starting from
   78|       |				 * those.
   79|       |				 */
   80|      0|				for (; *s; s++)
  ------------------
  |  Branch (80:12): [True: 0, False: 0]
  ------------------
   81|      0|					if (*s == *pattern &&
  ------------------
  |  Branch (81:10): [True: 0, False: 0]
  ------------------
   82|      0|					    match_pattern(s + 1, pattern + 1))
  ------------------
  |  Branch (82:10): [True: 0, False: 0]
  ------------------
   83|      0|						return 1;
   84|       |				/* Failed. */
   85|      0|				return 0;
   86|      0|			}
   87|       |			/*
   88|       |			 * Move ahead one character at a time and try to
   89|       |			 * match at each position.
   90|       |			 */
   91|      0|			for (; *s; s++)
  ------------------
  |  Branch (91:11): [True: 0, False: 0]
  ------------------
   92|      0|				if (match_pattern(s, pattern))
  ------------------
  |  Branch (92:9): [True: 0, False: 0]
  ------------------
   93|      0|					return 1;
   94|       |			/* Failed. */
   95|      0|			return 0;
   96|      0|		}
   97|       |		/*
   98|       |		 * There must be at least one more character in the string.
   99|       |		 * If we are at the end, fail.
  100|       |		 */
  101|  22.0k|		if (!*s)
  ------------------
  |  Branch (101:7): [True: 70, False: 21.9k]
  ------------------
  102|     70|			return 0;
  103|       |
  104|       |		/* Check if the next character of the string is acceptable. */
  105|  21.9k|		if (*pattern != '?' && *pattern != *s)
  ------------------
  |  Branch (105:7): [True: 21.9k, False: 0]
  |  Branch (105:26): [True: 2.17k, False: 19.7k]
  ------------------
  106|  2.17k|			return 0;
  107|       |
  108|       |		/* Move to the next character, both in string and in pattern. */
  109|  19.7k|		s++;
  110|  19.7k|		pattern++;
  111|  19.7k|	}
  112|       |	/* NOTREACHED */
  113|  4.38k|}
match_pattern_list:
  123|  2.19k|{
  124|  2.19k|	char sub[1024];
  125|  2.19k|	int negated;
  126|  2.19k|	int got_positive;
  127|  2.19k|	u_int i, subi, len = strlen(pattern);
  128|       |
  129|  2.19k|	got_positive = 0;
  130|  6.58k|	for (i = 0; i < len;) {
  ------------------
  |  Branch (130:14): [True: 4.38k, False: 2.19k]
  ------------------
  131|       |		/* Check if the subpattern is negated. */
  132|  4.38k|		if (pattern[i] == '!') {
  ------------------
  |  Branch (132:7): [True: 0, False: 4.38k]
  ------------------
  133|      0|			negated = 1;
  134|      0|			i++;
  135|      0|		} else
  136|  4.38k|			negated = 0;
  137|       |
  138|       |		/*
  139|       |		 * Extract the subpattern up to a comma or end.  Convert the
  140|       |		 * subpattern to lowercase.
  141|       |		 */
  142|  4.38k|		for (subi = 0;
  143|  31.1k|		    i < len && subi < sizeof(sub) - 1 && pattern[i] != ',';
  ------------------
  |  Branch (143:7): [True: 28.9k, False: 2.19k]
  |  Branch (143:18): [True: 28.9k, False: 0]
  |  Branch (143:44): [True: 26.7k, False: 2.19k]
  ------------------
  144|  26.7k|		    subi++, i++)
  145|  26.7k|			sub[subi] = dolower && isupper((u_char)pattern[i]) ?
  ------------------
  |  Branch (145:16): [True: 0, False: 26.7k]
  ------------------
  146|  26.7k|			    tolower((u_char)pattern[i]) : pattern[i];
  147|       |		/* If subpattern too long, return failure (no match). */
  148|  4.38k|		if (subi >= sizeof(sub) - 1)
  ------------------
  |  Branch (148:7): [True: 0, False: 4.38k]
  ------------------
  149|      0|			return 0;
  150|       |
  151|       |		/* If the subpattern was terminated by a comma, then skip it. */
  152|  4.38k|		if (i < len && pattern[i] == ',')
  ------------------
  |  Branch (152:7): [True: 2.19k, False: 2.19k]
  |  Branch (152:18): [True: 2.19k, False: 0]
  ------------------
  153|  2.19k|			i++;
  154|       |
  155|       |		/* Null-terminate the subpattern. */
  156|  4.38k|		sub[subi] = '\0';
  157|       |
  158|       |		/* Try to match the subpattern against the string. */
  159|  4.38k|		if (match_pattern(string, sub)) {
  ------------------
  |  Branch (159:7): [True: 2.13k, False: 2.25k]
  ------------------
  160|  2.13k|			if (negated)
  ------------------
  |  Branch (160:8): [True: 0, False: 2.13k]
  ------------------
  161|      0|				return -1;		/* Negative */
  162|  2.13k|			else
  163|  2.13k|				got_positive = 1;	/* Positive */
  164|  2.13k|		}
  165|  4.38k|	}
  166|       |
  167|       |	/*
  168|       |	 * Return success if got a positive match.  If there was a negative
  169|       |	 * match, we have already returned -1 and never get here.
  170|       |	 */
  171|  2.19k|	return got_positive;
  172|  2.19k|}

tohex:
 1534|  2.10k|{
 1535|  2.10k|	const u_char *p = (const u_char *)vp;
 1536|  2.10k|	char b[3], *r;
 1537|  2.10k|	size_t i, hl;
 1538|       |
 1539|  2.10k|	if (l > 65536)
  ------------------
  |  Branch (1539:6): [True: 0, False: 2.10k]
  ------------------
 1540|      0|		return xstrdup("tohex: length > 65536");
 1541|       |
 1542|  2.10k|	hl = l * 2 + 1;
 1543|  2.10k|	r = xcalloc(1, hl);
 1544|   101k|	for (i = 0; i < l; i++) {
  ------------------
  |  Branch (1544:14): [True: 99.2k, False: 2.10k]
  ------------------
 1545|  99.2k|		snprintf(b, sizeof(b), "%02x", p[i]);
 1546|  99.2k|		strlcat(r, b, hl);
 1547|  99.2k|	}
 1548|  2.10k|	return (r);
 1549|  2.10k|}

freezero:
   26|  41.5k|{
   27|  41.5k|	if (ptr == NULL)
  ------------------
  |  Branch (27:6): [True: 14.5k, False: 26.9k]
  ------------------
   28|  14.5k|		return;
   29|  26.9k|	explicit_bzero(ptr, sz);
   30|  26.9k|	free(ptr);
   31|  26.9k|}

recallocarray:
   39|  2.69k|{
   40|  2.69k|	size_t oldsize, newsize;
   41|  2.69k|	void *newptr;
   42|       |
   43|  2.69k|	if (ptr == NULL)
  ------------------
  |  Branch (43:6): [True: 37, False: 2.65k]
  ------------------
   44|     37|		return calloc(newnmemb, size);
   45|       |
   46|  2.65k|	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  5.31k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
              	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  2.65k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
  |  Branch (46:7): [True: 0, False: 2.65k]
  |  Branch (46:38): [True: 0, False: 2.65k]
  ------------------
   47|  2.65k|	    newnmemb > 0 && SIZE_MAX / newnmemb < size) {
  ------------------
  |  Branch (47:6): [True: 0, False: 0]
  |  Branch (47:22): [True: 0, False: 0]
  ------------------
   48|      0|		errno = ENOMEM;
   49|      0|		return NULL;
   50|      0|	}
   51|  2.65k|	newsize = newnmemb * size;
   52|       |
   53|  2.65k|	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  5.31k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
              	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  2.65k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
  |  Branch (53:7): [True: 0, False: 2.65k]
  |  Branch (53:38): [True: 0, False: 2.65k]
  ------------------
   54|  2.65k|	    oldnmemb > 0 && SIZE_MAX / oldnmemb < size) {
  ------------------
  |  Branch (54:6): [True: 0, False: 0]
  |  Branch (54:22): [True: 0, False: 0]
  ------------------
   55|      0|		errno = EINVAL;
   56|      0|		return NULL;
   57|      0|	}
   58|  2.65k|	oldsize = oldnmemb * size;
   59|       |	
   60|       |	/*
   61|       |	 * Don't bother too much if we're shrinking just a bit,
   62|       |	 * we do not shrink for series of small steps, oh well.
   63|       |	 */
   64|  2.65k|	if (newsize <= oldsize) {
  ------------------
  |  Branch (64:6): [True: 42, False: 2.61k]
  ------------------
   65|     42|		size_t d = oldsize - newsize;
   66|       |
   67|     42|		if (d < oldsize / 2 && d < (size_t)getpagesize()) {
  ------------------
  |  Branch (67:7): [True: 0, False: 42]
  |  Branch (67:26): [True: 0, False: 0]
  ------------------
   68|      0|			memset((char *)ptr + newsize, 0, d);
   69|      0|			return ptr;
   70|      0|		}
   71|     42|	}
   72|       |
   73|  2.65k|	newptr = malloc(newsize);
   74|  2.65k|	if (newptr == NULL)
  ------------------
  |  Branch (74:6): [True: 0, False: 2.65k]
  ------------------
   75|      0|		return NULL;
   76|       |
   77|  2.65k|	if (newsize > oldsize) {
  ------------------
  |  Branch (77:6): [True: 2.61k, False: 42]
  ------------------
   78|  2.61k|		memcpy(newptr, ptr, oldsize);
   79|  2.61k|		memset((char *)newptr + oldsize, 0, newsize - oldsize);
   80|  2.61k|	} else
   81|     42|		memcpy(newptr, ptr, newsize);
   82|       |
   83|  2.65k|	explicit_bzero(ptr, oldsize);
   84|  2.65k|	free(ptr);
   85|       |
   86|  2.65k|	return newptr;
   87|  2.65k|}

strlcat:
   36|  99.2k|{
   37|  99.2k|	char *d = dst;
   38|  99.2k|	const char *s = src;
   39|  99.2k|	size_t n = siz;
   40|  99.2k|	size_t dlen;
   41|       |
   42|       |	/* Find the end of dst and adjust bytes left but don't go past end */
   43|  5.23M|	while (n-- != 0 && *d != '\0')
  ------------------
  |  Branch (43:9): [True: 5.23M, False: 0]
  |  Branch (43:21): [True: 5.13M, False: 99.2k]
  ------------------
   44|  5.13M|		d++;
   45|  99.2k|	dlen = d - dst;
   46|  99.2k|	n = siz - dlen;
   47|       |
   48|  99.2k|	if (n == 0)
  ------------------
  |  Branch (48:6): [True: 0, False: 99.2k]
  ------------------
   49|      0|		return(dlen + strlen(s));
   50|   297k|	while (*s != '\0') {
  ------------------
  |  Branch (50:9): [True: 198k, False: 99.2k]
  ------------------
   51|   198k|		if (n != 1) {
  ------------------
  |  Branch (51:7): [True: 198k, False: 0]
  ------------------
   52|   198k|			*d++ = *s;
   53|   198k|			n--;
   54|   198k|		}
   55|   198k|		s++;
   56|   198k|	}
   57|  99.2k|	*d = '\0';
   58|       |
   59|  99.2k|	return(dlen + (s - src));	/* count does not include NUL */
   60|  99.2k|}

timingsafe_bcmp:
   25|  4.63k|{
   26|  4.63k|	const unsigned char *p1 = b1, *p2 = b2;
   27|  4.63k|	int ret = 0;
   28|       |
   29|  32.4k|	for (; n > 0; n--)
  ------------------
  |  Branch (29:9): [True: 27.8k, False: 4.63k]
  ------------------
   30|  27.8k|		ret |= *p1++ ^ *p2++;
   31|  4.63k|	return (ret != 0);
   32|  4.63k|}

LLVMFuzzerTestOneInput:
   19|  2.53k|{
   20|  2.53k|  static const char *data = "If everyone started announcing his nose had "
   21|  2.53k|      "run away, I don’t know how it would all end";
   22|  2.53k|  struct sshbuf *signature = sshbuf_from(sig, slen);
   23|  2.53k|  struct sshbuf *message = sshbuf_from(data, strlen(data));
   24|  2.53k|  struct sshkey *k = NULL;
   25|  2.53k|  struct sshkey_sig_details *details = NULL;
   26|  2.53k|  extern char *__progname;
   27|       |
   28|  2.53k|  log_init(__progname, SYSLOG_LEVEL_QUIET, SYSLOG_FACILITY_USER, 1);
   29|  2.53k|  sshsig_verifyb(signature, message, "castle", &k, &details);
   30|  2.53k|  sshkey_sig_details_free(details);
   31|  2.53k|  sshkey_free(k);
   32|  2.53k|  sshbuf_free(signature);
   33|  2.53k|  sshbuf_free(message);
   34|  2.53k|  return 0;
   35|  2.53k|}

ssh-ecdsa-sk.c:ssh_ecdsa_sk_cleanup:
   69|      9|{
   70|      9|	sshkey_sk_cleanup(k);
   71|      9|	sshkey_ecdsa_funcs.cleanup(k);
   72|      9|}
ssh-ecdsa-sk.c:ssh_ecdsa_sk_deserialize_public:
  130|      9|{
  131|      9|	int r;
  132|       |
  133|      9|	if ((r = sshkey_ecdsa_funcs.deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (133:6): [True: 9, False: 0]
  ------------------
  134|      9|		return r;
  135|      0|	if ((r = sshkey_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (135:6): [True: 0, False: 0]
  ------------------
  136|      0|		return r;
  137|      0|	return 0;
  138|      0|}

ssh-ecdsa.c:ssh_ecdsa_cleanup:
   67|    263|{
   68|    263|	EC_KEY_free(k->ecdsa);
   69|    263|	k->ecdsa = NULL;
   70|    263|}
ssh-ecdsa.c:ssh_ecdsa_deserialize_public:
  159|    263|{
  160|    263|	int r;
  161|    263|	char *curve = NULL;
  162|       |
  163|    263|	if ((key->ecdsa_nid = sshkey_ecdsa_nid_from_name(ktype)) == -1)
  ------------------
  |  Branch (163:6): [True: 10, False: 253]
  ------------------
  164|     10|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|     10|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  165|    253|	if ((r = sshbuf_get_cstring(b, &curve, NULL)) != 0)
  ------------------
  |  Branch (165:6): [True: 9, False: 244]
  ------------------
  166|      9|		goto out;
  167|    244|	if (key->ecdsa_nid != sshkey_curve_name_to_nid(curve)) {
  ------------------
  |  Branch (167:6): [True: 115, False: 129]
  ------------------
  168|    115|		r = SSH_ERR_EC_CURVE_MISMATCH;
  ------------------
  |  |   39|    115|#define SSH_ERR_EC_CURVE_MISMATCH		-15
  ------------------
  169|    115|		goto out;
  170|    115|	}
  171|    129|	EC_KEY_free(key->ecdsa);
  172|    129|	key->ecdsa = NULL;
  173|    129|	if ((key->ecdsa = EC_KEY_new_by_curve_name(key->ecdsa_nid)) == NULL) {
  ------------------
  |  Branch (173:6): [True: 0, False: 129]
  ------------------
  174|      0|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  175|      0|		goto out;
  176|      0|	}
  177|    129|	if ((r = sshbuf_get_eckey(b, key->ecdsa)) != 0)
  ------------------
  |  Branch (177:6): [True: 129, False: 0]
  ------------------
  178|    129|		goto out;
  179|      0|	if (sshkey_ec_validate_public(EC_KEY_get0_group(key->ecdsa),
  ------------------
  |  Branch (179:6): [True: 0, False: 0]
  ------------------
  180|      0|	    EC_KEY_get0_public_key(key->ecdsa)) != 0) {
  181|      0|		r = SSH_ERR_KEY_INVALID_EC_VALUE;
  ------------------
  |  |   44|      0|#define SSH_ERR_KEY_INVALID_EC_VALUE		-20
  ------------------
  182|      0|		goto out;
  183|      0|	}
  184|       |	/* success */
  185|      0|	r = 0;
  186|       |#ifdef DEBUG_PK
  187|       |	sshkey_dump_ec_point(EC_KEY_get0_group(key->ecdsa),
  188|       |	    EC_KEY_get0_public_key(key->ecdsa));
  189|       |#endif
  190|    253| out:
  191|    253|	free(curve);
  192|    253|	if (r != 0) {
  ------------------
  |  Branch (192:6): [True: 253, False: 0]
  ------------------
  193|    253|		EC_KEY_free(key->ecdsa);
  194|    253|		key->ecdsa = NULL;
  195|    253|	}
  196|    253|	return r;
  197|      0|}

ssh-ed25519-sk.c:ssh_ed25519_sk_cleanup:
   43|    611|{
   44|    611|	sshkey_sk_cleanup(k);
   45|    611|	sshkey_ed25519_funcs.cleanup(k);
   46|    611|}
ssh-ed25519-sk.c:ssh_ed25519_sk_deserialize_public:
  101|    610|{
  102|    610|	int r;
  103|       |
  104|    610|	if ((r = sshkey_ed25519_funcs.deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (104:6): [True: 5, False: 605]
  ------------------
  105|      5|		return r;
  106|    605|	if ((r = sshkey_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (106:6): [True: 2, False: 603]
  ------------------
  107|      2|		return r;
  108|    603|	return 0;
  109|    605|}
ssh-ed25519-sk.c:ssh_ed25519_sk_verify:
  129|    175|{
  130|    175|	struct sshbuf *b = NULL;
  131|    175|	struct sshbuf *encoded = NULL;
  132|    175|	char *ktype = NULL;
  133|    175|	const u_char *sigblob;
  134|    175|	const u_char *sm;
  135|    175|	u_char *m = NULL;
  136|    175|	u_char apphash[32];
  137|    175|	u_char msghash[32];
  138|    175|	u_char sig_flags;
  139|    175|	u_int sig_counter;
  140|    175|	size_t len;
  141|    175|	unsigned long long smlen = 0, mlen = 0;
  142|    175|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    175|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  143|    175|	int ret;
  144|    175|	struct sshkey_sig_details *details = NULL;
  145|       |
  146|    175|	if (detailsp != NULL)
  ------------------
  |  Branch (146:6): [True: 154, False: 21]
  ------------------
  147|    154|		*detailsp = NULL;
  148|       |
  149|    175|	if (key == NULL ||
  ------------------
  |  Branch (149:6): [True: 0, False: 175]
  ------------------
  150|    175|	    sshkey_type_plain(key->type) != KEY_ED25519_SK ||
  ------------------
  |  Branch (150:6): [True: 0, False: 175]
  ------------------
  151|    175|	    key->ed25519_pk == NULL ||
  ------------------
  |  Branch (151:6): [True: 0, False: 175]
  ------------------
  152|    175|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (152:6): [True: 0, False: 175]
  |  Branch (152:21): [True: 0, False: 175]
  ------------------
  153|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  154|       |
  155|    175|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (155:6): [True: 0, False: 175]
  ------------------
  156|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  157|    175|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0 ||
  ------------------
  |  Branch (157:6): [True: 7, False: 168]
  ------------------
  158|    175|	    sshbuf_get_string_direct(b, &sigblob, &len) != 0 ||
  ------------------
  |  Branch (158:6): [True: 4, False: 164]
  ------------------
  159|    175|	    sshbuf_get_u8(b, &sig_flags) != 0 ||
  ------------------
  |  Branch (159:6): [True: 3, False: 161]
  ------------------
  160|    175|	    sshbuf_get_u32(b, &sig_counter) != 0) {
  ------------------
  |  Branch (160:6): [True: 2, False: 159]
  ------------------
  161|     16|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     16|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  162|     16|		goto out;
  163|     16|	}
  164|       |#ifdef DEBUG_SK
  165|       |	fprintf(stderr, "%s: data:\n", __func__);
  166|       |	/* sshbuf_dump_data(data, datalen, stderr); */
  167|       |	fprintf(stderr, "%s: sigblob:\n", __func__);
  168|       |	sshbuf_dump_data(sigblob, len, stderr);
  169|       |	fprintf(stderr, "%s: sig_flags = 0x%02x, sig_counter = %u\n",
  170|       |	    __func__, sig_flags, sig_counter);
  171|       |#endif
  172|    159|	if (strcmp(sshkey_ssh_name_plain(key), ktype) != 0) {
  ------------------
  |  Branch (172:6): [True: 141, False: 18]
  ------------------
  173|    141|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    141|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  174|    141|		goto out;
  175|    141|	}
  176|     18|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (176:6): [True: 8, False: 10]
  ------------------
  177|      8|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      8|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  178|      8|		goto out;
  179|      8|	}
  180|     10|	if (len > crypto_sign_ed25519_BYTES) {
  ------------------
  |  |   37|     10|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (180:6): [True: 2, False: 8]
  ------------------
  181|      2|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      2|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  182|      2|		goto out;
  183|      2|	}
  184|      8|	if (ssh_digest_memory(SSH_DIGEST_SHA256, key->sk_application,
  ------------------
  |  |   27|      8|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (184:6): [True: 0, False: 8]
  ------------------
  185|      8|	    strlen(key->sk_application), apphash, sizeof(apphash)) != 0 ||
  186|      8|	    ssh_digest_memory(SSH_DIGEST_SHA256, data, dlen,
  ------------------
  |  |   27|      8|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (186:6): [True: 0, False: 8]
  ------------------
  187|      8|	    msghash, sizeof(msghash)) != 0) {
  188|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  189|      0|		goto out;
  190|      0|	}
  191|       |#ifdef DEBUG_SK
  192|       |	fprintf(stderr, "%s: hashed application:\n", __func__);
  193|       |	sshbuf_dump_data(apphash, sizeof(apphash), stderr);
  194|       |	fprintf(stderr, "%s: hashed message:\n", __func__);
  195|       |	sshbuf_dump_data(msghash, sizeof(msghash), stderr);
  196|       |#endif
  197|      8|	if ((details = calloc(1, sizeof(*details))) == NULL) {
  ------------------
  |  Branch (197:6): [True: 0, False: 8]
  ------------------
  198|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  199|      0|		goto out;
  200|      0|	}
  201|      8|	details->sk_counter = sig_counter;
  202|      8|	details->sk_flags = sig_flags;
  203|      8|	if ((encoded = sshbuf_new()) == NULL) {
  ------------------
  |  Branch (203:6): [True: 0, False: 8]
  ------------------
  204|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  205|      0|		goto out;
  206|      0|	}
  207|      8|	if (sshbuf_put(encoded, sigblob, len) != 0 ||
  ------------------
  |  Branch (207:6): [True: 0, False: 8]
  ------------------
  208|      8|	    sshbuf_put(encoded, apphash, sizeof(apphash)) != 0 ||
  ------------------
  |  Branch (208:6): [True: 0, False: 8]
  ------------------
  209|      8|	    sshbuf_put_u8(encoded, sig_flags) != 0 ||
  ------------------
  |  Branch (209:6): [True: 0, False: 8]
  ------------------
  210|      8|	    sshbuf_put_u32(encoded, sig_counter) != 0 ||
  ------------------
  |  Branch (210:6): [True: 0, False: 8]
  ------------------
  211|      8|	    sshbuf_put(encoded, msghash, sizeof(msghash)) != 0) {
  ------------------
  |  Branch (211:6): [True: 0, False: 8]
  ------------------
  212|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  213|      0|		goto out;
  214|      0|	}
  215|       |#ifdef DEBUG_SK
  216|       |	fprintf(stderr, "%s: signed buf:\n", __func__);
  217|       |	sshbuf_dump(encoded, stderr);
  218|       |#endif
  219|      8|	sm = sshbuf_ptr(encoded);
  220|      8|	smlen = sshbuf_len(encoded);
  221|      8|	mlen = smlen;
  222|      8|	if ((m = malloc(smlen)) == NULL) {
  ------------------
  |  Branch (222:6): [True: 0, False: 8]
  ------------------
  223|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  224|      0|		goto out;
  225|      0|	}
  226|      8|	if ((ret = crypto_sign_ed25519_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (226:6): [True: 8, False: 0]
  ------------------
  227|      8|	    key->ed25519_pk)) != 0) {
  228|      8|		debug2_f("crypto_sign_ed25519_open failed: %d", ret);
  ------------------
  |  |   97|      8|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  229|      8|	}
  230|      8|	if (ret != 0 || mlen != smlen - len) {
  ------------------
  |  Branch (230:6): [True: 8, False: 0]
  |  Branch (230:18): [True: 0, False: 0]
  ------------------
  231|      8|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      8|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  232|      8|		goto out;
  233|      8|	}
  234|       |	/* XXX compare 'm' and 'sm + len' ? */
  235|       |	/* success */
  236|      0|	r = 0;
  237|      0|	if (detailsp != NULL) {
  ------------------
  |  Branch (237:6): [True: 0, False: 0]
  ------------------
  238|      0|		*detailsp = details;
  239|      0|		details = NULL;
  240|      0|	}
  241|    175| out:
  242|    175|	if (m != NULL)
  ------------------
  |  Branch (242:6): [True: 8, False: 167]
  ------------------
  243|      8|		freezero(m, smlen); /* NB mlen may be invalid if r != 0 */
  244|    175|	sshkey_sig_details_free(details);
  245|    175|	sshbuf_free(b);
  246|    175|	sshbuf_free(encoded);
  247|    175|	free(ktype);
  248|    175|	return r;
  249|      0|}

ssh-ed25519.c:ssh_ed25519_cleanup:
   37|    948|{
   38|    948|	freezero(k->ed25519_pk, ED25519_PK_SZ);
  ------------------
  |  |  159|    948|#define	ED25519_PK_SZ	crypto_sign_ed25519_PUBLICKEYBYTES
  |  |  ------------------
  |  |  |  |   36|    948|#define crypto_sign_ed25519_PUBLICKEYBYTES 32U
  |  |  ------------------
  ------------------
   39|    948|	freezero(k->ed25519_sk, ED25519_SK_SZ);
  ------------------
  |  |  158|    948|#define	ED25519_SK_SZ	crypto_sign_ed25519_SECRETKEYBYTES
  |  |  ------------------
  |  |  |  |   35|    948|#define crypto_sign_ed25519_SECRETKEYBYTES 64U
  |  |  ------------------
  ------------------
   40|    948|	k->ed25519_pk = NULL;
   41|    948|	k->ed25519_sk = NULL;
   42|    948|}
ssh-ed25519.c:ssh_ed25519_deserialize_public:
  105|    945|{
  106|    945|	u_char *pk = NULL;
  107|    945|	size_t len = 0;
  108|    945|	int r;
  109|       |
  110|    945|	if ((r = sshbuf_get_string(b, &pk, &len)) != 0)
  ------------------
  |  Branch (110:6): [True: 6, False: 939]
  ------------------
  111|      6|		return r;
  112|    939|	if (len != ED25519_PK_SZ) {
  ------------------
  |  |  159|    939|#define	ED25519_PK_SZ	crypto_sign_ed25519_PUBLICKEYBYTES
  |  |  ------------------
  |  |  |  |   36|    939|#define crypto_sign_ed25519_PUBLICKEYBYTES 32U
  |  |  ------------------
  ------------------
  |  Branch (112:6): [True: 27, False: 912]
  ------------------
  113|     27|		freezero(pk, len);
  114|     27|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     27|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  115|     27|	}
  116|    912|	key->ed25519_pk = pk;
  117|    912|	return 0;
  118|    939|}
ssh-ed25519.c:ssh_ed25519_verify:
  209|    183|{
  210|    183|	struct sshbuf *b = NULL;
  211|    183|	char *ktype = NULL;
  212|    183|	const u_char *sigblob;
  213|    183|	u_char *sm = NULL, *m = NULL;
  214|    183|	size_t len;
  215|    183|	unsigned long long smlen = 0, mlen = 0;
  216|    183|	int r, ret;
  217|       |
  218|    183|	if (key == NULL ||
  ------------------
  |  Branch (218:6): [True: 0, False: 183]
  ------------------
  219|    183|	    sshkey_type_plain(key->type) != KEY_ED25519 ||
  ------------------
  |  Branch (219:6): [True: 0, False: 183]
  ------------------
  220|    183|	    key->ed25519_pk == NULL ||
  ------------------
  |  Branch (220:6): [True: 0, False: 183]
  ------------------
  221|    183|	    dlen >= INT_MAX - crypto_sign_ed25519_BYTES ||
  ------------------
  |  |   37|    366|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (221:6): [True: 0, False: 183]
  ------------------
  222|    183|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (222:6): [True: 0, False: 183]
  |  Branch (222:21): [True: 0, False: 183]
  ------------------
  223|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  224|       |
  225|    183|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (225:6): [True: 0, False: 183]
  ------------------
  226|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  227|    183|	if ((r = sshbuf_get_cstring(b, &ktype, NULL)) != 0 ||
  ------------------
  |  Branch (227:6): [True: 19, False: 164]
  ------------------
  228|    183|	    (r = sshbuf_get_string_direct(b, &sigblob, &len)) != 0)
  ------------------
  |  Branch (228:6): [True: 4, False: 160]
  ------------------
  229|     23|		goto out;
  230|    160|	if (strcmp("ssh-ed25519", ktype) != 0) {
  ------------------
  |  Branch (230:6): [True: 90, False: 70]
  ------------------
  231|     90|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|     90|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  232|     90|		goto out;
  233|     90|	}
  234|     70|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (234:6): [True: 14, False: 56]
  ------------------
  235|     14|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|     14|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  236|     14|		goto out;
  237|     14|	}
  238|     56|	if (len > crypto_sign_ed25519_BYTES) {
  ------------------
  |  |   37|     56|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (238:6): [True: 3, False: 53]
  ------------------
  239|      3|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      3|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  240|      3|		goto out;
  241|      3|	}
  242|     53|	if (dlen >= SIZE_MAX - len) {
  ------------------
  |  Branch (242:6): [True: 0, False: 53]
  ------------------
  243|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  244|      0|		goto out;
  245|      0|	}
  246|     53|	smlen = len + dlen;
  247|     53|	mlen = smlen;
  248|     53|	if ((sm = malloc(smlen)) == NULL || (m = malloc(mlen)) == NULL) {
  ------------------
  |  Branch (248:6): [True: 0, False: 53]
  |  Branch (248:38): [True: 0, False: 53]
  ------------------
  249|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  250|      0|		goto out;
  251|      0|	}
  252|     53|	memcpy(sm, sigblob, len);
  253|     53|	memcpy(sm+len, data, dlen);
  254|     53|	if ((ret = crypto_sign_ed25519_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (254:6): [True: 50, False: 3]
  ------------------
  255|     53|	    key->ed25519_pk)) != 0) {
  256|     50|		debug2_f("crypto_sign_ed25519_open failed: %d", ret);
  ------------------
  |  |   97|     50|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  257|     50|	}
  258|     53|	if (ret != 0 || mlen != dlen) {
  ------------------
  |  Branch (258:6): [True: 50, False: 3]
  |  Branch (258:18): [True: 2, False: 1]
  ------------------
  259|     52|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|     52|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  260|     52|		goto out;
  261|     52|	}
  262|       |	/* XXX compare 'm' and 'data' ? */
  263|       |	/* success */
  264|      1|	r = 0;
  265|    183| out:
  266|    183|	if (sm != NULL)
  ------------------
  |  Branch (266:6): [True: 53, False: 130]
  ------------------
  267|     53|		freezero(sm, smlen);
  268|    183|	if (m != NULL)
  ------------------
  |  Branch (268:6): [True: 53, False: 130]
  ------------------
  269|     53|		freezero(m, smlen); /* NB mlen may be invalid if r != 0 */
  270|    183|	sshbuf_free(b);
  271|    183|	free(ktype);
  272|    183|	return r;
  273|      1|}

ssh-rsa.c:ssh_rsa_alloc:
   54|    493|{
   55|    493|	if ((k->rsa = RSA_new()) == NULL)
  ------------------
  |  Branch (55:6): [True: 0, False: 493]
  ------------------
   56|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   57|    493|	return 0;
   58|    493|}
ssh-rsa.c:ssh_rsa_cleanup:
   62|    493|{
   63|    493|	RSA_free(k->rsa);
   64|    493|	k->rsa = NULL;
   65|    493|}
ssh-rsa.c:ssh_rsa_deserialize_public:
  188|    492|{
  189|    492|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    492|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  190|    492|	BIGNUM *rsa_n = NULL, *rsa_e = NULL;
  191|       |
  192|    492|	if (sshbuf_get_bignum2(b, &rsa_e) != 0 ||
  ------------------
  |  Branch (192:6): [True: 70, False: 422]
  ------------------
  193|    492|	    sshbuf_get_bignum2(b, &rsa_n) != 0) {
  ------------------
  |  Branch (193:6): [True: 51, False: 371]
  ------------------
  194|    121|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|    121|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  195|    121|		goto out;
  196|    121|	}
  197|    371|	if (!RSA_set0_key(key->rsa, rsa_n, rsa_e, NULL)) {
  ------------------
  |  Branch (197:6): [True: 0, False: 371]
  ------------------
  198|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  199|      0|		goto out;
  200|      0|	}
  201|    371|	rsa_n = rsa_e = NULL; /* transferred */
  202|    371|	if ((ret = sshkey_check_rsa_length(key, 0)) != 0)
  ------------------
  |  Branch (202:6): [True: 27, False: 344]
  ------------------
  203|     27|		goto out;
  204|       |#ifdef DEBUG_PK
  205|       |	RSA_print_fp(stderr, key->rsa, 8);
  206|       |#endif
  207|       |	/* success */
  208|    344|	ret = 0;
  209|    492| out:
  210|    492|	BN_clear_free(rsa_n);
  211|    492|	BN_clear_free(rsa_e);
  212|    492|	return ret;
  213|    344|}
ssh-rsa.c:rsa_hash_id_from_ident:
  289|    230|{
  290|    230|	if (strcmp(ident, "ssh-rsa") == 0)
  ------------------
  |  Branch (290:6): [True: 14, False: 216]
  ------------------
  291|     14|		return SSH_DIGEST_SHA1;
  ------------------
  |  |   26|     14|#define SSH_DIGEST_SHA1		1
  ------------------
  292|    216|	if (strcmp(ident, "rsa-sha2-256") == 0)
  ------------------
  |  Branch (292:6): [True: 24, False: 192]
  ------------------
  293|     24|		return SSH_DIGEST_SHA256;
  ------------------
  |  |   27|     24|#define SSH_DIGEST_SHA256	2
  ------------------
  294|    192|	if (strcmp(ident, "rsa-sha2-512") == 0)
  ------------------
  |  Branch (294:6): [True: 12, False: 180]
  ------------------
  295|     12|		return SSH_DIGEST_SHA512;
  ------------------
  |  |   29|     12|#define SSH_DIGEST_SHA512	4
  ------------------
  296|    180|	return -1;
  297|    192|}
ssh-rsa.c:ssh_rsa_verify:
  478|    236|{
  479|    236|	const BIGNUM *rsa_n;
  480|    236|	char *sigtype = NULL;
  481|    236|	int hash_alg, want_alg, ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    236|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  482|    236|	size_t len = 0, diff, modlen, hlen;
  483|    236|	struct sshbuf *b = NULL;
  484|    236|	u_char digest[SSH_DIGEST_MAX_LENGTH], *osigblob, *sigblob = NULL;
  485|       |
  486|    236|	if (key == NULL || key->rsa == NULL ||
  ------------------
  |  Branch (486:6): [True: 0, False: 236]
  |  Branch (486:21): [True: 0, False: 236]
  ------------------
  487|    236|	    sshkey_type_plain(key->type) != KEY_RSA ||
  ------------------
  |  Branch (487:6): [True: 0, False: 236]
  ------------------
  488|    236|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (488:6): [True: 0, False: 236]
  |  Branch (488:21): [True: 0, False: 236]
  ------------------
  489|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  490|    236|	RSA_get0_key(key->rsa, &rsa_n, NULL, NULL);
  491|    236|	if (BN_num_bits(rsa_n) < SSH_RSA_MINIMUM_MODULUS_SIZE)
  ------------------
  |  |   53|    236|#define SSH_RSA_MINIMUM_MODULUS_SIZE	1024
  ------------------
  |  Branch (491:6): [True: 0, False: 236]
  ------------------
  492|      0|		return SSH_ERR_KEY_LENGTH;
  ------------------
  |  |   80|      0|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
  493|       |
  494|    236|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (494:6): [True: 0, False: 236]
  ------------------
  495|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  496|    236|	if (sshbuf_get_cstring(b, &sigtype, NULL) != 0) {
  ------------------
  |  Branch (496:6): [True: 6, False: 230]
  ------------------
  497|      6|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      6|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  498|      6|		goto out;
  499|      6|	}
  500|    230|	if ((hash_alg = rsa_hash_id_from_ident(sigtype)) == -1) {
  ------------------
  |  Branch (500:6): [True: 180, False: 50]
  ------------------
  501|    180|		ret = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    180|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  502|    180|		goto out;
  503|    180|	}
  504|       |	/*
  505|       |	 * Allow ssh-rsa-cert-v01 certs to generate SHA2 signatures for
  506|       |	 * legacy reasons, but otherwise the signature type should match.
  507|       |	 */
  508|     50|	if (alg != NULL && strcmp(alg, "ssh-rsa-cert-v01@openssh.com") != 0) {
  ------------------
  |  Branch (508:6): [True: 0, False: 50]
  |  Branch (508:21): [True: 0, False: 0]
  ------------------
  509|      0|		if ((want_alg = rsa_hash_id_from_keyname(alg)) == -1) {
  ------------------
  |  Branch (509:7): [True: 0, False: 0]
  ------------------
  510|      0|			ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  511|      0|			goto out;
  512|      0|		}
  513|      0|		if (hash_alg != want_alg) {
  ------------------
  |  Branch (513:7): [True: 0, False: 0]
  ------------------
  514|      0|			ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  515|      0|			goto out;
  516|      0|		}
  517|      0|	}
  518|     50|	if (sshbuf_get_string(b, &sigblob, &len) != 0) {
  ------------------
  |  Branch (518:6): [True: 4, False: 46]
  ------------------
  519|      4|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      4|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  520|      4|		goto out;
  521|      4|	}
  522|     46|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (522:6): [True: 17, False: 29]
  ------------------
  523|     17|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|     17|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  524|     17|		goto out;
  525|     17|	}
  526|       |	/* RSA_verify expects a signature of RSA_size */
  527|     29|	modlen = RSA_size(key->rsa);
  528|     29|	if (len > modlen) {
  ------------------
  |  Branch (528:6): [True: 8, False: 21]
  ------------------
  529|      8|		ret = SSH_ERR_KEY_BITS_MISMATCH;
  ------------------
  |  |   35|      8|#define SSH_ERR_KEY_BITS_MISMATCH		-11
  ------------------
  530|      8|		goto out;
  531|     21|	} else if (len < modlen) {
  ------------------
  |  Branch (531:13): [True: 20, False: 1]
  ------------------
  532|     20|		diff = modlen - len;
  533|     20|		osigblob = sigblob;
  534|     20|		if ((sigblob = realloc(sigblob, modlen)) == NULL) {
  ------------------
  |  Branch (534:7): [True: 0, False: 20]
  ------------------
  535|      0|			sigblob = osigblob; /* put it back for clear/free */
  536|      0|			ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  537|      0|			goto out;
  538|      0|		}
  539|     20|		memmove(sigblob + diff, sigblob, len);
  540|     20|		explicit_bzero(sigblob, diff);
  541|     20|		len = modlen;
  542|     20|	}
  543|     21|	if ((hlen = ssh_digest_bytes(hash_alg)) == 0) {
  ------------------
  |  Branch (543:6): [True: 0, False: 21]
  ------------------
  544|      0|		ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  545|      0|		goto out;
  546|      0|	}
  547|     21|	if ((ret = ssh_digest_memory(hash_alg, data, dlen,
  ------------------
  |  Branch (547:6): [True: 0, False: 21]
  ------------------
  548|     21|	    digest, sizeof(digest))) != 0)
  549|      0|		goto out;
  550|       |
  551|     21|	ret = openssh_RSA_verify(hash_alg, digest, hlen, sigblob, len,
  552|     21|	    key->rsa);
  553|    236| out:
  554|    236|	freezero(sigblob, len);
  555|    236|	free(sigtype);
  556|    236|	sshbuf_free(b);
  557|    236|	explicit_bzero(digest, sizeof(digest));
  558|    236|	return ret;
  559|     21|}
ssh-rsa.c:openssh_RSA_verify:
  635|     21|{
  636|     21|	size_t rsasize = 0, oidlen = 0, hlen = 0;
  637|     21|	int ret, len, oidmatch, hashmatch;
  638|     21|	const u_char *oid = NULL;
  639|     21|	u_char *decrypted = NULL;
  640|       |
  641|     21|	if ((ret = rsa_hash_alg_oid(hash_alg, &oid, &oidlen)) != 0)
  ------------------
  |  Branch (641:6): [True: 0, False: 21]
  ------------------
  642|      0|		return ret;
  643|     21|	ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|     21|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  644|     21|	hlen = ssh_digest_bytes(hash_alg);
  645|     21|	if (hashlen != hlen) {
  ------------------
  |  Branch (645:6): [True: 0, False: 21]
  ------------------
  646|      0|		ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  647|      0|		goto done;
  648|      0|	}
  649|     21|	rsasize = RSA_size(rsa);
  650|     21|	if (rsasize <= 0 || rsasize > SSHBUF_MAX_BIGNUM ||
  ------------------
  |  |   33|     42|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (650:6): [True: 0, False: 21]
  |  Branch (650:22): [True: 0, False: 21]
  ------------------
  651|     21|	    siglen == 0 || siglen > rsasize) {
  ------------------
  |  Branch (651:6): [True: 0, False: 21]
  |  Branch (651:21): [True: 0, False: 21]
  ------------------
  652|      0|		ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  653|      0|		goto done;
  654|      0|	}
  655|     21|	if ((decrypted = malloc(rsasize)) == NULL) {
  ------------------
  |  Branch (655:6): [True: 0, False: 21]
  ------------------
  656|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  657|      0|		goto done;
  658|      0|	}
  659|     21|	if ((len = RSA_public_decrypt(siglen, sigbuf, decrypted, rsa,
  ------------------
  |  Branch (659:6): [True: 21, False: 0]
  ------------------
  660|     21|	    RSA_PKCS1_PADDING)) < 0) {
  661|     21|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|     21|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  662|     21|		goto done;
  663|     21|	}
  664|      0|	if (len < 0 || (size_t)len != hlen + oidlen) {
  ------------------
  |  Branch (664:6): [True: 0, False: 0]
  |  Branch (664:17): [True: 0, False: 0]
  ------------------
  665|      0|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  666|      0|		goto done;
  667|      0|	}
  668|      0|	oidmatch = timingsafe_bcmp(decrypted, oid, oidlen) == 0;
  669|      0|	hashmatch = timingsafe_bcmp(decrypted + oidlen, hash, hlen) == 0;
  670|      0|	if (!oidmatch || !hashmatch) {
  ------------------
  |  Branch (670:6): [True: 0, False: 0]
  |  Branch (670:19): [True: 0, False: 0]
  ------------------
  671|      0|		ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  672|      0|		goto done;
  673|      0|	}
  674|      0|	ret = 0;
  675|     21|done:
  676|     21|	freezero(decrypted, rsasize);
  677|     21|	return ret;
  678|      0|}
ssh-rsa.c:rsa_hash_alg_oid:
  612|     21|{
  613|     21|	switch (hash_alg) {
  614|      1|	case SSH_DIGEST_SHA1:
  ------------------
  |  |   26|      1|#define SSH_DIGEST_SHA1		1
  ------------------
  |  Branch (614:2): [True: 1, False: 20]
  ------------------
  615|      1|		*oidp = id_sha1;
  616|      1|		*oidlenp = sizeof(id_sha1);
  617|      1|		break;
  618|     13|	case SSH_DIGEST_SHA256:
  ------------------
  |  |   27|     13|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (618:2): [True: 13, False: 8]
  ------------------
  619|     13|		*oidp = id_sha256;
  620|     13|		*oidlenp = sizeof(id_sha256);
  621|     13|		break;
  622|      7|	case SSH_DIGEST_SHA512:
  ------------------
  |  |   29|      7|#define SSH_DIGEST_SHA512	4
  ------------------
  |  Branch (622:2): [True: 7, False: 14]
  ------------------
  623|      7|		*oidp = id_sha512;
  624|      7|		*oidlenp = sizeof(id_sha512);
  625|      7|		break;
  626|      0|	default:
  ------------------
  |  Branch (626:2): [True: 0, False: 21]
  ------------------
  627|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  628|     21|	}
  629|     21|	return 0;
  630|     21|}

ssh-xmss.c:ssh_xmss_cleanup:
   44|    416|{
   45|    416|	freezero(k->xmss_pk, sshkey_xmss_pklen(k));
   46|    416|	freezero(k->xmss_sk, sshkey_xmss_sklen(k));
   47|    416|	sshkey_xmss_free_state(k);
   48|    416|	free(k->xmss_name);
   49|    416|	free(k->xmss_filename);
   50|    416|	k->xmss_pk = NULL;
   51|    416|	k->xmss_sk = NULL;
   52|    416|	k->xmss_name = NULL;
   53|    416|	k->xmss_filename = NULL;
   54|    416|}
ssh-xmss.c:ssh_xmss_deserialize_public:
  134|    416|{
  135|    416|	size_t len = 0;
  136|    416|	char *xmss_name = NULL;
  137|    416|	u_char *pk = NULL;
  138|    416|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    416|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  139|       |
  140|    416|	if ((ret = sshbuf_get_cstring(b, &xmss_name, NULL)) != 0)
  ------------------
  |  Branch (140:6): [True: 3, False: 413]
  ------------------
  141|      3|		goto out;
  142|    413|	if ((ret = sshkey_xmss_init(key, xmss_name)) != 0)
  ------------------
  |  Branch (142:6): [True: 154, False: 259]
  ------------------
  143|    154|		goto out;
  144|    259|	if ((ret = sshbuf_get_string(b, &pk, &len)) != 0)
  ------------------
  |  Branch (144:6): [True: 6, False: 253]
  ------------------
  145|      6|		goto out;
  146|    253|	if (len == 0 || len != sshkey_xmss_pklen(key)) {
  ------------------
  |  Branch (146:6): [True: 1, False: 252]
  |  Branch (146:18): [True: 41, False: 211]
  ------------------
  147|     42|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     42|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  148|     42|		goto out;
  149|     42|	}
  150|    211|	key->xmss_pk = pk;
  151|    211|	pk = NULL;
  152|    211|	if (!sshkey_is_cert(key) &&
  ------------------
  |  Branch (152:6): [True: 204, False: 7]
  ------------------
  153|    211|	    (ret = sshkey_xmss_deserialize_pk_info(key, b)) != 0)
  ------------------
  |  Branch (153:6): [True: 25, False: 179]
  ------------------
  154|     25|		goto out;
  155|       |	/* success */
  156|    186|	ret = 0;
  157|    416| out:
  158|    416|	free(xmss_name);
  159|    416|	freezero(pk, len);
  160|    416|	return ret;
  161|    186|}
ssh-xmss.c:ssh_xmss_verify:
  281|    173|{
  282|    173|	struct sshbuf *b = NULL;
  283|    173|	char *ktype = NULL;
  284|    173|	const u_char *sigblob;
  285|    173|	u_char *sm = NULL, *m = NULL;
  286|    173|	size_t len, required_siglen;
  287|    173|	unsigned long long smlen = 0, mlen = 0;
  288|    173|	int r, ret;
  289|       |
  290|    173|	if (key == NULL ||
  ------------------
  |  Branch (290:6): [True: 0, False: 173]
  ------------------
  291|    173|	    sshkey_type_plain(key->type) != KEY_XMSS ||
  ------------------
  |  Branch (291:6): [True: 0, False: 173]
  ------------------
  292|    173|	    key->xmss_pk == NULL ||
  ------------------
  |  Branch (292:6): [True: 0, False: 173]
  ------------------
  293|    173|	    sshkey_xmss_params(key) == NULL ||
  ------------------
  |  Branch (293:6): [True: 0, False: 173]
  ------------------
  294|    173|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (294:6): [True: 0, False: 173]
  |  Branch (294:21): [True: 0, False: 173]
  ------------------
  295|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  296|    173|	if ((r = sshkey_xmss_siglen(key, &required_siglen)) != 0)
  ------------------
  |  Branch (296:6): [True: 0, False: 173]
  ------------------
  297|      0|		return r;
  298|    173|	if (dlen >= INT_MAX - required_siglen)
  ------------------
  |  Branch (298:6): [True: 0, False: 173]
  ------------------
  299|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  300|       |
  301|    173|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (301:6): [True: 0, False: 173]
  ------------------
  302|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  303|    173|	if ((r = sshbuf_get_cstring(b, &ktype, NULL)) != 0 ||
  ------------------
  |  Branch (303:6): [True: 21, False: 152]
  ------------------
  304|    173|	    (r = sshbuf_get_string_direct(b, &sigblob, &len)) != 0)
  ------------------
  |  Branch (304:6): [True: 3, False: 149]
  ------------------
  305|     24|		goto out;
  306|    149|	if (strcmp("ssh-xmss@openssh.com", ktype) != 0) {
  ------------------
  |  Branch (306:6): [True: 132, False: 17]
  ------------------
  307|    132|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    132|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  308|    132|		goto out;
  309|    132|	}
  310|     17|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (310:6): [True: 9, False: 8]
  ------------------
  311|      9|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      9|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  312|      9|		goto out;
  313|      9|	}
  314|      8|	if (len != required_siglen) {
  ------------------
  |  Branch (314:6): [True: 8, False: 0]
  ------------------
  315|      8|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      8|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  316|      8|		goto out;
  317|      8|	}
  318|      0|	if (dlen >= SIZE_MAX - len) {
  ------------------
  |  Branch (318:6): [True: 0, False: 0]
  ------------------
  319|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  320|      0|		goto out;
  321|      0|	}
  322|      0|	smlen = len + dlen;
  323|      0|	mlen = smlen;
  324|      0|	if ((sm = malloc(smlen)) == NULL || (m = malloc(mlen)) == NULL) {
  ------------------
  |  Branch (324:6): [True: 0, False: 0]
  |  Branch (324:38): [True: 0, False: 0]
  ------------------
  325|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  326|      0|		goto out;
  327|      0|	}
  328|      0|	memcpy(sm, sigblob, len);
  329|      0|	memcpy(sm+len, data, dlen);
  330|      0|	if ((ret = xmss_sign_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (330:6): [True: 0, False: 0]
  ------------------
  331|      0|	    key->xmss_pk, sshkey_xmss_params(key))) != 0) {
  332|      0|		debug2_f("xmss_sign_open failed: %d", ret);
  ------------------
  |  |   97|      0|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  333|      0|	}
  334|      0|	if (ret != 0 || mlen != dlen) {
  ------------------
  |  Branch (334:6): [True: 0, False: 0]
  |  Branch (334:18): [True: 0, False: 0]
  ------------------
  335|      0|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  336|      0|		goto out;
  337|      0|	}
  338|       |	/* XXX compare 'm' and 'data' ? */
  339|       |	/* success */
  340|      0|	r = 0;
  341|    173| out:
  342|    173|	if (sm != NULL)
  ------------------
  |  Branch (342:6): [True: 0, False: 173]
  ------------------
  343|      0|		freezero(sm, smlen);
  344|    173|	if (m != NULL)
  ------------------
  |  Branch (344:6): [True: 0, False: 173]
  ------------------
  345|      0|		freezero(m, smlen);
  346|    173|	sshbuf_free(b);
  347|    173|	free(ktype);
  348|    173|	return r;
  349|      0|}

sshbuf_get_u64:
   49|  1.56k|{
   50|  1.56k|	const u_char *p = sshbuf_ptr(buf);
   51|  1.56k|	int r;
   52|       |
   53|  1.56k|	if ((r = sshbuf_consume(buf, 8)) < 0)
  ------------------
  |  Branch (53:6): [True: 18, False: 1.54k]
  ------------------
   54|     18|		return r;
   55|  1.54k|	if (valp != NULL)
  ------------------
  |  Branch (55:6): [True: 1.54k, False: 0]
  ------------------
   56|  1.54k|		*valp = PEEK_U64(p);
  ------------------
  |  |  303|  1.54k|	(((u_int64_t)(((const u_char *)(p))[0]) << 56) | \
  |  |  304|  1.54k|	 ((u_int64_t)(((const u_char *)(p))[1]) << 48) | \
  |  |  305|  1.54k|	 ((u_int64_t)(((const u_char *)(p))[2]) << 40) | \
  |  |  306|  1.54k|	 ((u_int64_t)(((const u_char *)(p))[3]) << 32) | \
  |  |  307|  1.54k|	 ((u_int64_t)(((const u_char *)(p))[4]) << 24) | \
  |  |  308|  1.54k|	 ((u_int64_t)(((const u_char *)(p))[5]) << 16) | \
  |  |  309|  1.54k|	 ((u_int64_t)(((const u_char *)(p))[6]) << 8) | \
  |  |  310|  1.54k|	  (u_int64_t)(((const u_char *)(p))[7]))
  ------------------
   57|  1.54k|	return 0;
   58|  1.56k|}
sshbuf_get_u32:
   62|  5.33k|{
   63|  5.33k|	const u_char *p = sshbuf_ptr(buf);
   64|  5.33k|	int r;
   65|       |
   66|  5.33k|	if ((r = sshbuf_consume(buf, 4)) < 0)
  ------------------
  |  Branch (66:6): [True: 11, False: 5.32k]
  ------------------
   67|     11|		return r;
   68|  5.32k|	if (valp != NULL)
  ------------------
  |  Branch (68:6): [True: 5.32k, False: 0]
  ------------------
   69|  5.32k|		*valp = PEEK_U32(p);
  ------------------
  |  |  312|  5.32k|	(((u_int32_t)(((const u_char *)(p))[0]) << 24) | \
  |  |  313|  5.32k|	 ((u_int32_t)(((const u_char *)(p))[1]) << 16) | \
  |  |  314|  5.32k|	 ((u_int32_t)(((const u_char *)(p))[2]) << 8) | \
  |  |  315|  5.32k|	  (u_int32_t)(((const u_char *)(p))[3]))
  ------------------
   70|  5.32k|	return 0;
   71|  5.33k|}
sshbuf_get_u8:
   88|    192|{
   89|    192|	const u_char *p = sshbuf_ptr(buf);
   90|    192|	int r;
   91|       |
   92|    192|	if ((r = sshbuf_consume(buf, 1)) < 0)
  ------------------
  |  Branch (92:6): [True: 3, False: 189]
  ------------------
   93|      3|		return r;
   94|    189|	if (valp != NULL)
  ------------------
  |  Branch (94:6): [True: 189, False: 0]
  ------------------
   95|    189|		*valp = (u_int8_t)*p;
   96|    189|	return 0;
   97|    192|}
sshbuf_get_string:
  188|  4.69k|{
  189|  4.69k|	const u_char *val;
  190|  4.69k|	size_t len;
  191|  4.69k|	int r;
  192|       |
  193|  4.69k|	if (valp != NULL)
  ------------------
  |  Branch (193:6): [True: 1.70k, False: 2.98k]
  ------------------
  194|  1.70k|		*valp = NULL;
  195|  4.69k|	if (lenp != NULL)
  ------------------
  |  Branch (195:6): [True: 1.70k, False: 2.98k]
  ------------------
  196|  1.70k|		*lenp = 0;
  197|  4.69k|	if ((r = sshbuf_get_string_direct(buf, &val, &len)) < 0)
  ------------------
  |  Branch (197:6): [True: 93, False: 4.59k]
  ------------------
  198|     93|		return r;
  199|  4.59k|	if (valp != NULL) {
  ------------------
  |  Branch (199:6): [True: 1.68k, False: 2.91k]
  ------------------
  200|  1.68k|		if ((*valp = malloc(len + 1)) == NULL) {
  ------------------
  |  Branch (200:7): [True: 0, False: 1.68k]
  ------------------
  201|      0|			SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  202|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  203|      0|		}
  204|  1.68k|		if (len != 0)
  ------------------
  |  Branch (204:7): [True: 1.49k, False: 194]
  ------------------
  205|  1.49k|			memcpy(*valp, val, len);
  206|  1.68k|		(*valp)[len] = '\0';
  207|  1.68k|	}
  208|  4.59k|	if (lenp != NULL)
  ------------------
  |  Branch (208:6): [True: 1.68k, False: 2.91k]
  ------------------
  209|  1.68k|		*lenp = len;
  210|  4.59k|	return 0;
  211|  4.59k|}
sshbuf_get_string_direct:
  215|  30.5k|{
  216|  30.5k|	size_t len;
  217|  30.5k|	const u_char *p;
  218|  30.5k|	int r;
  219|       |
  220|  30.5k|	if (valp != NULL)
  ------------------
  |  Branch (220:6): [True: 5.79k, False: 24.7k]
  ------------------
  221|  5.79k|		*valp = NULL;
  222|  30.5k|	if (lenp != NULL)
  ------------------
  |  Branch (222:6): [True: 5.79k, False: 24.7k]
  ------------------
  223|  5.79k|		*lenp = 0;
  224|  30.5k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) < 0)
  ------------------
  |  Branch (224:6): [True: 360, False: 30.2k]
  ------------------
  225|    360|		return r;
  226|  30.2k|	if (valp != NULL)
  ------------------
  |  Branch (226:6): [True: 5.69k, False: 24.5k]
  ------------------
  227|  5.69k|		*valp = p;
  228|  30.2k|	if (lenp != NULL)
  ------------------
  |  Branch (228:6): [True: 5.69k, False: 24.5k]
  ------------------
  229|  5.69k|		*lenp = len;
  230|  30.2k|	if (sshbuf_consume(buf, len + 4) != 0) {
  ------------------
  |  Branch (230:6): [True: 0, False: 30.2k]
  ------------------
  231|       |		/* Shouldn't happen */
  232|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  233|      0|		SSHBUF_ABORT();
  234|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  235|      0|	}
  236|  30.2k|	return 0;
  237|  30.2k|}
sshbuf_peek_string_direct:
  242|  46.5k|{
  243|  46.5k|	u_int32_t len;
  244|  46.5k|	const u_char *p = sshbuf_ptr(buf);
  245|       |
  246|  46.5k|	if (valp != NULL)
  ------------------
  |  Branch (246:6): [True: 46.5k, False: 0]
  ------------------
  247|  46.5k|		*valp = NULL;
  248|  46.5k|	if (lenp != NULL)
  ------------------
  |  Branch (248:6): [True: 46.5k, False: 0]
  ------------------
  249|  46.5k|		*lenp = 0;
  250|  46.5k|	if (sshbuf_len(buf) < 4) {
  ------------------
  |  Branch (250:6): [True: 326, False: 46.1k]
  ------------------
  251|    326|		SSHBUF_DBG(("SSH_ERR_MESSAGE_INCOMPLETE"));
  252|    326|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    326|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  253|    326|	}
  254|  46.1k|	len = PEEK_U32(p);
  ------------------
  |  |  312|  46.1k|	(((u_int32_t)(((const u_char *)(p))[0]) << 24) | \
  |  |  313|  46.1k|	 ((u_int32_t)(((const u_char *)(p))[1]) << 16) | \
  |  |  314|  46.1k|	 ((u_int32_t)(((const u_char *)(p))[2]) << 8) | \
  |  |  315|  46.1k|	  (u_int32_t)(((const u_char *)(p))[3]))
  ------------------
  255|  46.1k|	if (len > SSHBUF_SIZE_MAX - 4) {
  ------------------
  |  |   31|  46.1k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  |  Branch (255:6): [True: 182, False: 45.9k]
  ------------------
  256|    182|		SSHBUF_DBG(("SSH_ERR_STRING_TOO_LARGE"));
  257|    182|		return SSH_ERR_STRING_TOO_LARGE;
  ------------------
  |  |   30|    182|#define SSH_ERR_STRING_TOO_LARGE		-6
  ------------------
  258|    182|	}
  259|  45.9k|	if (sshbuf_len(buf) - 4 < len) {
  ------------------
  |  Branch (259:6): [True: 309, False: 45.6k]
  ------------------
  260|    309|		SSHBUF_DBG(("SSH_ERR_MESSAGE_INCOMPLETE"));
  261|    309|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    309|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  262|    309|	}
  263|  45.6k|	if (valp != NULL)
  ------------------
  |  Branch (263:6): [True: 45.6k, False: 0]
  ------------------
  264|  45.6k|		*valp = p + 4;
  265|  45.6k|	if (lenp != NULL)
  ------------------
  |  Branch (265:6): [True: 45.6k, False: 0]
  ------------------
  266|  45.6k|		*lenp = len;
  267|  45.6k|	return 0;
  268|  45.9k|}
sshbuf_get_cstring:
  272|  10.8k|{
  273|  10.8k|	size_t len;
  274|  10.8k|	const u_char *p, *z;
  275|  10.8k|	int r;
  276|       |
  277|  10.8k|	if (valp != NULL)
  ------------------
  |  Branch (277:6): [True: 10.8k, False: 0]
  ------------------
  278|  10.8k|		*valp = NULL;
  279|  10.8k|	if (lenp != NULL)
  ------------------
  |  Branch (279:6): [True: 543, False: 10.2k]
  ------------------
  280|    543|		*lenp = 0;
  281|  10.8k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) != 0)
  ------------------
  |  Branch (281:6): [True: 237, False: 10.5k]
  ------------------
  282|    237|		return r;
  283|       |	/* Allow a \0 only at the end of the string */
  284|  10.5k|	if (len > 0 &&
  ------------------
  |  Branch (284:6): [True: 7.42k, False: 3.15k]
  ------------------
  285|  10.5k|	    (z = memchr(p , '\0', len)) != NULL && z < p + len - 1) {
  ------------------
  |  Branch (285:6): [True: 502, False: 6.92k]
  |  Branch (285:45): [True: 5, False: 497]
  ------------------
  286|      5|		SSHBUF_DBG(("SSH_ERR_INVALID_FORMAT"));
  287|      5|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      5|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  288|      5|	}
  289|  10.5k|	if ((r = sshbuf_skip_string(buf)) != 0)
  ------------------
  |  |  205|  10.5k|#define sshbuf_skip_string(buf) sshbuf_get_string_direct(buf, NULL, NULL)
  ------------------
  |  Branch (289:6): [True: 0, False: 10.5k]
  ------------------
  290|      0|		return -1;
  291|  10.5k|	if (valp != NULL) {
  ------------------
  |  Branch (291:6): [True: 10.5k, False: 0]
  ------------------
  292|  10.5k|		if ((*valp = malloc(len + 1)) == NULL) {
  ------------------
  |  Branch (292:7): [True: 0, False: 10.5k]
  ------------------
  293|      0|			SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  294|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  295|      0|		}
  296|  10.5k|		if (len != 0)
  ------------------
  |  Branch (296:7): [True: 7.41k, False: 3.15k]
  ------------------
  297|  7.41k|			memcpy(*valp, p, len);
  298|  10.5k|		(*valp)[len] = '\0';
  299|  10.5k|	}
  300|  10.5k|	if (lenp != NULL)
  ------------------
  |  Branch (300:6): [True: 535, False: 10.0k]
  ------------------
  301|    535|		*lenp = (size_t)len;
  302|  10.5k|	return 0;
  303|  10.5k|}
sshbuf_put:
  327|  5.50k|{
  328|  5.50k|	u_char *p;
  329|  5.50k|	int r;
  330|       |
  331|  5.50k|	if ((r = sshbuf_reserve(buf, len, &p)) < 0)
  ------------------
  |  Branch (331:6): [True: 0, False: 5.50k]
  ------------------
  332|      0|		return r;
  333|  5.50k|	if (len != 0)
  ------------------
  |  Branch (333:6): [True: 4.86k, False: 639]
  ------------------
  334|  4.86k|		memcpy(p, v, len);
  335|  5.50k|	return 0;
  336|  5.50k|}
sshbuf_putb:
  340|  1.28k|{
  341|  1.28k|	if (v == NULL)
  ------------------
  |  Branch (341:6): [True: 0, False: 1.28k]
  ------------------
  342|      0|		return 0;
  343|  1.28k|	return sshbuf_put(buf, sshbuf_ptr(v), sshbuf_len(v));
  344|  1.28k|}
sshbuf_put_u32:
  405|      8|{
  406|      8|	u_char *p;
  407|      8|	int r;
  408|       |
  409|      8|	if ((r = sshbuf_reserve(buf, 4, &p)) < 0)
  ------------------
  |  Branch (409:6): [True: 0, False: 8]
  ------------------
  410|      0|		return r;
  411|      8|	POKE_U32(p, val);
  ------------------
  |  |  333|      8|	do { \
  |  |  334|      8|		const u_int32_t __v = (v); \
  |  |  335|      8|		((u_char *)(p))[0] = (__v >> 24) & 0xff; \
  |  |  336|      8|		((u_char *)(p))[1] = (__v >> 16) & 0xff; \
  |  |  337|      8|		((u_char *)(p))[2] = (__v >> 8) & 0xff; \
  |  |  338|      8|		((u_char *)(p))[3] = __v & 0xff; \
  |  |  339|      8|	} while (0)
  |  |  ------------------
  |  |  |  Branch (339:11): [Folded - Ignored]
  |  |  ------------------
  ------------------
  412|      8|	return 0;
  413|      8|}
sshbuf_put_u8:
  429|      8|{
  430|      8|	u_char *p;
  431|      8|	int r;
  432|       |
  433|      8|	if ((r = sshbuf_reserve(buf, 1, &p)) < 0)
  ------------------
  |  Branch (433:6): [True: 0, False: 8]
  ------------------
  434|      0|		return r;
  435|      8|	p[0] = val;
  436|      8|	return 0;
  437|      8|}
sshbuf_put_string:
  515|  8.40k|{
  516|  8.40k|	u_char *d;
  517|  8.40k|	int r;
  518|       |
  519|  8.40k|	if (len > SSHBUF_SIZE_MAX - 4) {
  ------------------
  |  |   31|  8.40k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  |  Branch (519:6): [True: 0, False: 8.40k]
  ------------------
  520|      0|		SSHBUF_DBG(("SSH_ERR_NO_BUFFER_SPACE"));
  521|      0|		return SSH_ERR_NO_BUFFER_SPACE;
  ------------------
  |  |   33|      0|#define SSH_ERR_NO_BUFFER_SPACE			-9
  ------------------
  522|      0|	}
  523|  8.40k|	if ((r = sshbuf_reserve(buf, len + 4, &d)) < 0)
  ------------------
  |  Branch (523:6): [True: 0, False: 8.40k]
  ------------------
  524|      0|		return r;
  525|  8.40k|	POKE_U32(d, len);
  ------------------
  |  |  333|  8.40k|	do { \
  |  |  334|  8.40k|		const u_int32_t __v = (v); \
  |  |  335|  8.40k|		((u_char *)(p))[0] = (__v >> 24) & 0xff; \
  |  |  336|  8.40k|		((u_char *)(p))[1] = (__v >> 16) & 0xff; \
  |  |  337|  8.40k|		((u_char *)(p))[2] = (__v >> 8) & 0xff; \
  |  |  338|  8.40k|		((u_char *)(p))[3] = __v & 0xff; \
  |  |  339|  8.40k|	} while (0)
  |  |  ------------------
  |  |  |  Branch (339:11): [Folded - Ignored]
  |  |  ------------------
  ------------------
  526|  8.40k|	if (len != 0)
  ------------------
  |  Branch (526:6): [True: 6.30k, False: 2.10k]
  ------------------
  527|  6.30k|		memcpy(d + 4, v, len);
  528|  8.40k|	return 0;
  529|  8.40k|}
sshbuf_put_cstring:
  533|  4.20k|{
  534|  4.20k|	return sshbuf_put_string(buf, v, v == NULL ? 0 : strlen(v));
  ------------------
  |  Branch (534:35): [True: 0, False: 4.20k]
  ------------------
  535|  4.20k|}
sshbuf_put_stringb:
  539|  2.10k|{
  540|  2.10k|	if (v == NULL)
  ------------------
  |  Branch (540:6): [True: 0, False: 2.10k]
  ------------------
  541|      0|		return sshbuf_put_string(buf, NULL, 0);
  542|       |
  543|  2.10k|	return sshbuf_put_string(buf, sshbuf_ptr(v), sshbuf_len(v));
  544|  2.10k|}
sshbuf_froms:
  548|  4.07k|{
  549|  4.07k|	const u_char *p;
  550|  4.07k|	size_t len;
  551|  4.07k|	struct sshbuf *ret;
  552|  4.07k|	int r;
  553|       |
  554|  4.07k|	if (buf == NULL || bufp == NULL)
  ------------------
  |  Branch (554:6): [True: 0, False: 4.07k]
  |  Branch (554:21): [True: 0, False: 4.07k]
  ------------------
  555|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  556|  4.07k|	*bufp = NULL;
  557|  4.07k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) != 0)
  ------------------
  |  Branch (557:6): [True: 65, False: 4.00k]
  ------------------
  558|     65|		return r;
  559|  4.00k|	if ((ret = sshbuf_from(p, len)) == NULL)
  ------------------
  |  Branch (559:6): [True: 0, False: 4.00k]
  ------------------
  560|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  561|  4.00k|	if ((r = sshbuf_consume(buf, len + 4)) != 0 ||  /* Shouldn't happen */
  ------------------
  |  Branch (561:6): [True: 0, False: 4.00k]
  ------------------
  562|  4.00k|	    (r = sshbuf_set_parent(ret, buf)) != 0) {
  ------------------
  |  Branch (562:6): [True: 0, False: 4.00k]
  ------------------
  563|      0|		sshbuf_free(ret);
  564|      0|		return r;
  565|      0|	}
  566|  4.00k|	*bufp = ret;
  567|  4.00k|	return 0;
  568|  4.00k|}
sshbuf_get_bignum2_bytes_direct:
  602|    914|{
  603|    914|	const u_char *d;
  604|    914|	size_t len, olen;
  605|    914|	int r;
  606|       |
  607|    914|	if ((r = sshbuf_peek_string_direct(buf, &d, &olen)) < 0)
  ------------------
  |  Branch (607:6): [True: 97, False: 817]
  ------------------
  608|     97|		return r;
  609|    817|	len = olen;
  610|       |	/* Refuse negative (MSB set) bignums */
  611|    817|	if ((len != 0 && (*d & 0x80) != 0))
  ------------------
  |  Branch (611:7): [True: 505, False: 312]
  |  Branch (611:19): [True: 13, False: 492]
  ------------------
  612|     13|		return SSH_ERR_BIGNUM_IS_NEGATIVE;
  ------------------
  |  |   29|     13|#define SSH_ERR_BIGNUM_IS_NEGATIVE		-5
  ------------------
  613|       |	/* Refuse overlong bignums, allow prepended \0 to avoid MSB set */
  614|    804|	if (len > SSHBUF_MAX_BIGNUM + 1 ||
  ------------------
  |  |   33|    804|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (614:6): [True: 6, False: 798]
  ------------------
  615|    804|	    (len == SSHBUF_MAX_BIGNUM + 1 && *d != 0))
  ------------------
  |  |   33|    798|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (615:7): [True: 11, False: 787]
  |  Branch (615:39): [True: 5, False: 6]
  ------------------
  616|     11|		return SSH_ERR_BIGNUM_TOO_LARGE;
  ------------------
  |  |   31|     11|#define SSH_ERR_BIGNUM_TOO_LARGE		-7
  ------------------
  617|       |	/* Trim leading zeros */
  618|  2.66k|	while (len > 0 && *d == 0x00) {
  ------------------
  |  Branch (618:9): [True: 2.34k, False: 325]
  |  Branch (618:20): [True: 1.87k, False: 468]
  ------------------
  619|  1.87k|		d++;
  620|  1.87k|		len--;
  621|  1.87k|	}
  622|    793|	if (valp != NULL)
  ------------------
  |  Branch (622:6): [True: 793, False: 0]
  ------------------
  623|    793|		*valp = d;
  624|    793|	if (lenp != NULL)
  ------------------
  |  Branch (624:6): [True: 793, False: 0]
  ------------------
  625|    793|		*lenp = len;
  626|    793|	if (sshbuf_consume(buf, olen + 4) != 0) {
  ------------------
  |  Branch (626:6): [True: 0, False: 793]
  ------------------
  627|       |		/* Shouldn't happen */
  628|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  629|      0|		SSHBUF_ABORT();
  630|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  631|      0|	}
  632|    793|	return 0;
  633|    793|}

sshbuf_get_bignum2:
   37|    914|{
   38|    914|	BIGNUM *v;
   39|    914|	const u_char *d;
   40|    914|	size_t len;
   41|    914|	int r;
   42|       |
   43|    914|	if (valp != NULL)
  ------------------
  |  Branch (43:6): [True: 914, False: 0]
  ------------------
   44|    914|		*valp = NULL;
   45|    914|	if ((r = sshbuf_get_bignum2_bytes_direct(buf, &d, &len)) != 0)
  ------------------
  |  Branch (45:6): [True: 121, False: 793]
  ------------------
   46|    121|		return r;
   47|    793|	if (valp != NULL) {
  ------------------
  |  Branch (47:6): [True: 793, False: 0]
  ------------------
   48|    793|		if ((v = BN_new()) == NULL ||
  ------------------
  |  Branch (48:7): [True: 0, False: 793]
  ------------------
   49|    793|		    BN_bin2bn(d, len, v) == NULL) {
  ------------------
  |  Branch (49:7): [True: 0, False: 793]
  ------------------
   50|      0|			BN_clear_free(v);
   51|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   52|      0|		}
   53|    793|		*valp = v;
   54|    793|	}
   55|    793|	return 0;
   56|    793|}
sshbuf_get_eckey:
   96|    129|{
   97|    129|	EC_POINT *pt = EC_POINT_new(EC_KEY_get0_group(v));
   98|    129|	int r;
   99|    129|	const u_char *d;
  100|    129|	size_t len;
  101|       |
  102|    129|	if (pt == NULL) {
  ------------------
  |  Branch (102:6): [True: 0, False: 129]
  ------------------
  103|      0|		SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  104|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  105|      0|	}
  106|    129|	if ((r = sshbuf_peek_string_direct(buf, &d, &len)) < 0) {
  ------------------
  |  Branch (106:6): [True: 58, False: 71]
  ------------------
  107|     58|		EC_POINT_free(pt);
  108|     58|		return r;
  109|     58|	}
  110|     71|	if ((r = get_ec(d, len, pt, EC_KEY_get0_group(v))) != 0) {
  ------------------
  |  Branch (110:6): [True: 71, False: 0]
  ------------------
  111|     71|		EC_POINT_free(pt);
  112|     71|		return r;
  113|     71|	}
  114|      0|	if (EC_KEY_set_public_key(v, pt) != 1) {
  ------------------
  |  Branch (114:6): [True: 0, False: 0]
  ------------------
  115|      0|		EC_POINT_free(pt);
  116|      0|		return SSH_ERR_ALLOC_FAIL; /* XXX assumption */
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  117|      0|	}
  118|      0|	EC_POINT_free(pt);
  119|       |	/* Skip string */
  120|      0|	if (sshbuf_get_string_direct(buf, NULL, NULL) != 0) {
  ------------------
  |  Branch (120:6): [True: 0, False: 0]
  ------------------
  121|       |		/* Shouldn't happen */
  122|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  123|      0|		SSHBUF_ABORT();
  124|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  125|      0|	}
  126|      0|	return 0;
  127|      0|}
sshbuf-getput-crypto.c:get_ec:
   61|     71|{
   62|       |	/* Refuse overlong bignums */
   63|     71|	if (len == 0 || len > SSHBUF_MAX_ECPOINT)
  ------------------
  |  |   34|     56|#define SSHBUF_MAX_ECPOINT	((528 * 2 / 8) + 1) /* Max EC point *bytes* */
  ------------------
  |  Branch (63:6): [True: 15, False: 56]
  |  Branch (63:18): [True: 25, False: 31]
  ------------------
   64|     40|		return SSH_ERR_ECPOINT_TOO_LARGE;
  ------------------
  |  |   32|     40|#define SSH_ERR_ECPOINT_TOO_LARGE		-8
  ------------------
   65|       |	/* Only handle uncompressed points */
   66|     31|	if (*d != POINT_CONVERSION_UNCOMPRESSED)
  ------------------
  |  Branch (66:6): [True: 28, False: 3]
  ------------------
   67|     28|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     28|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
   68|      3|	if (v != NULL && EC_POINT_oct2point(g, v, d, len, NULL) != 1)
  ------------------
  |  Branch (68:6): [True: 3, False: 0]
  |  Branch (68:19): [True: 3, False: 0]
  ------------------
   69|      3|		return SSH_ERR_INVALID_FORMAT; /* XXX assumption */
  ------------------
  |  |   28|      3|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
   70|      0|	return 0;
   71|      3|}

sshbuf_cmp:
  240|  4.63k|{
  241|  4.63k|	if (sshbuf_ptr(b) == NULL)
  ------------------
  |  Branch (241:6): [True: 0, False: 4.63k]
  ------------------
  242|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  243|  4.63k|	if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
  ------------------
  |  |   31|  9.27k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
              	if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
  ------------------
  |  |   31|  9.27k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  |  Branch (243:6): [True: 0, False: 4.63k]
  |  Branch (243:34): [True: 0, False: 4.63k]
  |  Branch (243:59): [True: 0, False: 4.63k]
  ------------------
  244|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  245|  4.63k|	if (offset + len > sshbuf_len(b))
  ------------------
  |  Branch (245:6): [True: 4, False: 4.63k]
  ------------------
  246|      4|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|      4|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  247|  4.63k|	if (timingsafe_bcmp(sshbuf_ptr(b) + offset, s, len) != 0)
  ------------------
  |  Branch (247:6): [True: 12, False: 4.62k]
  ------------------
  248|     12|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     12|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  249|  4.62k|	return 0;
  250|  4.63k|}

sshbuf_new:
   93|  5.91k|{
   94|  5.91k|	struct sshbuf *ret;
   95|       |
   96|  5.91k|	if ((ret = calloc(sizeof(*ret), 1)) == NULL)
  ------------------
  |  Branch (96:6): [True: 0, False: 5.91k]
  ------------------
   97|      0|		return NULL;
   98|  5.91k|	ret->alloc = SSHBUF_SIZE_INIT;
  ------------------
  |  |  370|  5.91k|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
   99|  5.91k|	ret->max_size = SSHBUF_SIZE_MAX;
  ------------------
  |  |   31|  5.91k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  100|  5.91k|	ret->readonly = 0;
  101|  5.91k|	ret->refcount = 1;
  102|  5.91k|	ret->parent = NULL;
  103|  5.91k|	if ((ret->cd = ret->d = calloc(1, ret->alloc)) == NULL) {
  ------------------
  |  Branch (103:6): [True: 0, False: 5.91k]
  ------------------
  104|      0|		free(ret);
  105|      0|		return NULL;
  106|      0|	}
  107|  5.91k|	return ret;
  108|  5.91k|}
sshbuf_from:
  112|  14.8k|{
  113|  14.8k|	struct sshbuf *ret;
  114|       |
  115|  14.8k|	if (blob == NULL || len > SSHBUF_SIZE_MAX ||
  ------------------
  |  |   31|  29.6k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size */
  ------------------
  |  Branch (115:6): [True: 0, False: 14.8k]
  |  Branch (115:22): [True: 0, False: 14.8k]
  ------------------
  116|  14.8k|	    (ret = calloc(sizeof(*ret), 1)) == NULL)
  ------------------
  |  Branch (116:6): [True: 0, False: 14.8k]
  ------------------
  117|      0|		return NULL;
  118|  14.8k|	ret->alloc = ret->size = ret->max_size = len;
  119|  14.8k|	ret->readonly = 1;
  120|  14.8k|	ret->refcount = 1;
  121|  14.8k|	ret->parent = NULL;
  122|  14.8k|	ret->cd = blob;
  123|  14.8k|	ret->d = NULL;
  124|  14.8k|	return ret;
  125|  14.8k|}
sshbuf_set_parent:
  129|  8.94k|{
  130|  8.94k|	int r;
  131|       |
  132|  8.94k|	if ((r = sshbuf_check_sanity(child)) != 0 ||
  ------------------
  |  Branch (132:6): [True: 0, False: 8.94k]
  ------------------
  133|  8.94k|	    (r = sshbuf_check_sanity(parent)) != 0)
  ------------------
  |  Branch (133:6): [True: 0, False: 8.94k]
  ------------------
  134|      0|		return r;
  135|  8.94k|	if (child->parent != NULL && child->parent != parent)
  ------------------
  |  Branch (135:6): [True: 0, False: 8.94k]
  |  Branch (135:31): [True: 0, False: 0]
  ------------------
  136|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  137|  8.94k|	child->parent = parent;
  138|  8.94k|	child->parent->refcount++;
  139|  8.94k|	return 0;
  140|  8.94k|}
sshbuf_fromb:
  144|  4.93k|{
  145|  4.93k|	struct sshbuf *ret;
  146|       |
  147|  4.93k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (147:6): [True: 0, False: 4.93k]
  ------------------
  148|      0|		return NULL;
  149|  4.93k|	if ((ret = sshbuf_from(sshbuf_ptr(buf), sshbuf_len(buf))) == NULL)
  ------------------
  |  Branch (149:6): [True: 0, False: 4.93k]
  ------------------
  150|      0|		return NULL;
  151|  4.93k|	if (sshbuf_set_parent(ret, buf) != 0) {
  ------------------
  |  Branch (151:6): [True: 0, False: 4.93k]
  ------------------
  152|      0|		sshbuf_free(ret);
  153|      0|		return NULL;
  154|      0|	}
  155|  4.93k|	return ret;
  156|  4.93k|}
sshbuf_free:
  160|  47.4k|{
  161|  47.4k|	if (buf == NULL)
  ------------------
  |  Branch (161:6): [True: 17.7k, False: 29.6k]
  ------------------
  162|  17.7k|		return;
  163|       |	/*
  164|       |	 * The following will leak on insane buffers, but this is the safest
  165|       |	 * course of action - an invalid pointer or already-freed pointer may
  166|       |	 * have been passed to us and continuing to scribble over memory would
  167|       |	 * be bad.
  168|       |	 */
  169|  29.6k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (169:6): [True: 0, False: 29.6k]
  ------------------
  170|      0|		return;
  171|       |
  172|       |	/*
  173|       |	 * If we are a parent with still-extant children, then don't free just
  174|       |	 * yet. The last child's call to sshbuf_free should decrement our
  175|       |	 * refcount to 0 and trigger the actual free.
  176|       |	 */
  177|  29.6k|	buf->refcount--;
  178|  29.6k|	if (buf->refcount > 0)
  ------------------
  |  Branch (178:6): [True: 8.94k, False: 20.7k]
  ------------------
  179|  8.94k|		return;
  180|       |
  181|       |	/*
  182|       |	 * If we are a child, the free our parent to decrement its reference
  183|       |	 * count and possibly free it.
  184|       |	 */
  185|  20.7k|	sshbuf_free(buf->parent);
  186|  20.7k|	buf->parent = NULL;
  187|       |
  188|  20.7k|	if (!buf->readonly) {
  ------------------
  |  Branch (188:6): [True: 5.91k, False: 14.8k]
  ------------------
  189|  5.91k|		explicit_bzero(buf->d, buf->alloc);
  190|  5.91k|		free(buf->d);
  191|  5.91k|	}
  192|  20.7k|	freezero(buf, sizeof(*buf));
  193|  20.7k|}
sshbuf_reset:
  197|     71|{
  198|     71|	u_char *d;
  199|       |
  200|     71|	if (buf->readonly || buf->refcount > 1) {
  ------------------
  |  Branch (200:6): [True: 0, False: 71]
  |  Branch (200:23): [True: 0, False: 71]
  ------------------
  201|       |		/* Nonsensical. Just make buffer appear empty */
  202|      0|		buf->off = buf->size;
  203|      0|		return;
  204|      0|	}
  205|     71|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (205:6): [True: 0, False: 71]
  ------------------
  206|      0|		return;
  207|     71|	buf->off = buf->size = 0;
  208|     71|	if (buf->alloc != SSHBUF_SIZE_INIT) {
  ------------------
  |  |  370|     71|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  |  Branch (208:6): [True: 42, False: 29]
  ------------------
  209|     42|		if ((d = recallocarray(buf->d, buf->alloc, SSHBUF_SIZE_INIT,
  ------------------
  |  |  370|     42|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  |  Branch (209:7): [True: 42, False: 0]
  ------------------
  210|     42|		    1)) != NULL) {
  211|     42|			buf->cd = buf->d = d;
  212|     42|			buf->alloc = SSHBUF_SIZE_INIT;
  ------------------
  |  |  370|     42|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  213|     42|		}
  214|     42|	}
  215|     71|	explicit_bzero(buf->d, buf->alloc);
  216|     71|}
sshbuf_len:
  282|   165k|{
  283|   165k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (283:6): [True: 0, False: 165k]
  ------------------
  284|      0|		return 0;
  285|   165k|	return buf->size - buf->off;
  286|   165k|}
sshbuf_ptr:
  298|  74.0k|{
  299|  74.0k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (299:6): [True: 0, False: 74.0k]
  ------------------
  300|      0|		return NULL;
  301|  74.0k|	return buf->cd + buf->off;
  302|  74.0k|}
sshbuf_check_reserve:
  314|  14.3k|{
  315|  14.3k|	int r;
  316|       |
  317|  14.3k|	if ((r = sshbuf_check_sanity(buf)) != 0)
  ------------------
  |  Branch (317:6): [True: 0, False: 14.3k]
  ------------------
  318|      0|		return r;
  319|  14.3k|	if (buf->readonly || buf->refcount > 1)
  ------------------
  |  Branch (319:6): [True: 0, False: 14.3k]
  |  Branch (319:23): [True: 0, False: 14.3k]
  ------------------
  320|      0|		return SSH_ERR_BUFFER_READ_ONLY;
  ------------------
  |  |   73|      0|#define SSH_ERR_BUFFER_READ_ONLY		-49
  ------------------
  321|  14.3k|	SSHBUF_TELL("check");
  322|       |	/* Check that len is reasonable and that max_size + available < len */
  323|  14.3k|	if (len > buf->max_size || buf->max_size - len < buf->size - buf->off)
  ------------------
  |  Branch (323:6): [True: 0, False: 14.3k]
  |  Branch (323:29): [True: 0, False: 14.3k]
  ------------------
  324|      0|		return SSH_ERR_NO_BUFFER_SPACE;
  ------------------
  |  |   33|      0|#define SSH_ERR_NO_BUFFER_SPACE			-9
  ------------------
  325|  14.3k|	return 0;
  326|  14.3k|}
sshbuf_allocate:
  330|  13.9k|{
  331|  13.9k|	size_t rlen, need;
  332|  13.9k|	u_char *dp;
  333|  13.9k|	int r;
  334|       |
  335|  13.9k|	SSHBUF_DBG(("allocate buf = %p len = %zu", buf, len));
  336|  13.9k|	if ((r = sshbuf_check_reserve(buf, len)) != 0)
  ------------------
  |  Branch (336:6): [True: 0, False: 13.9k]
  ------------------
  337|      0|		return r;
  338|       |	/*
  339|       |	 * If the requested allocation appended would push us past max_size
  340|       |	 * then pack the buffer, zeroing buf->off.
  341|       |	 */
  342|  13.9k|	sshbuf_maybe_pack(buf, buf->size + len > buf->max_size);
  343|  13.9k|	SSHBUF_TELL("allocate");
  344|  13.9k|	if (len + buf->size <= buf->alloc)
  ------------------
  |  Branch (344:6): [True: 13.5k, False: 414]
  ------------------
  345|  13.5k|		return 0; /* already have it. */
  346|       |
  347|       |	/*
  348|       |	 * Prefer to alloc in SSHBUF_SIZE_INC units, but
  349|       |	 * allocate less if doing so would overflow max_size.
  350|       |	 */
  351|    414|	need = len + buf->size - buf->alloc;
  352|    414|	rlen = ROUNDUP(buf->alloc + need, SSHBUF_SIZE_INC);
  ------------------
  |  |  251|    414|#define ROUNDUP(x, y)   ((((x)+((y)-1))/(y))*(y))
  ------------------
  353|    414|	SSHBUF_DBG(("need %zu initial rlen %zu", need, rlen));
  354|    414|	if (rlen > buf->max_size)
  ------------------
  |  Branch (354:6): [True: 0, False: 414]
  ------------------
  355|      0|		rlen = buf->alloc + need;
  356|    414|	SSHBUF_DBG(("adjusted rlen %zu", rlen));
  357|    414|	if ((dp = recallocarray(buf->d, buf->alloc, rlen, 1)) == NULL) {
  ------------------
  |  Branch (357:6): [True: 0, False: 414]
  ------------------
  358|      0|		SSHBUF_DBG(("realloc fail"));
  359|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  360|      0|	}
  361|    414|	buf->alloc = rlen;
  362|    414|	buf->cd = buf->d = dp;
  363|    414|	if ((r = sshbuf_check_reserve(buf, len)) < 0) {
  ------------------
  |  Branch (363:6): [True: 0, False: 414]
  ------------------
  364|       |		/* shouldn't fail */
  365|      0|		return r;
  366|      0|	}
  367|    414|	SSHBUF_TELL("done");
  368|    414|	return 0;
  369|    414|}
sshbuf_reserve:
  373|  13.9k|{
  374|  13.9k|	u_char *dp;
  375|  13.9k|	int r;
  376|       |
  377|  13.9k|	if (dpp != NULL)
  ------------------
  |  Branch (377:6): [True: 13.9k, False: 0]
  ------------------
  378|  13.9k|		*dpp = NULL;
  379|       |
  380|  13.9k|	SSHBUF_DBG(("reserve buf = %p len = %zu", buf, len));
  381|  13.9k|	if ((r = sshbuf_allocate(buf, len)) != 0)
  ------------------
  |  Branch (381:6): [True: 0, False: 13.9k]
  ------------------
  382|      0|		return r;
  383|       |
  384|  13.9k|	dp = buf->d + buf->size;
  385|  13.9k|	buf->size += len;
  386|  13.9k|	if (dpp != NULL)
  ------------------
  |  Branch (386:6): [True: 13.9k, False: 0]
  ------------------
  387|  13.9k|		*dpp = dp;
  388|  13.9k|	return 0;
  389|  13.9k|}
sshbuf_consume:
  393|  46.7k|{
  394|  46.7k|	int r;
  395|       |
  396|  46.7k|	SSHBUF_DBG(("len = %zu", len));
  397|  46.7k|	if ((r = sshbuf_check_sanity(buf)) != 0)
  ------------------
  |  Branch (397:6): [True: 0, False: 46.7k]
  ------------------
  398|      0|		return r;
  399|  46.7k|	if (len == 0)
  ------------------
  |  Branch (399:6): [True: 0, False: 46.7k]
  ------------------
  400|      0|		return 0;
  401|  46.7k|	if (len > sshbuf_len(buf))
  ------------------
  |  Branch (401:6): [True: 32, False: 46.6k]
  ------------------
  402|     32|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|     32|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  403|  46.6k|	buf->off += len;
  404|       |	/* deal with empty buffer */
  405|  46.6k|	if (buf->off == buf->size)
  ------------------
  |  Branch (405:6): [True: 4.63k, False: 42.0k]
  ------------------
  406|  4.63k|		buf->off = buf->size = 0;
  407|  46.6k|	SSHBUF_TELL("done");
  408|  46.6k|	return 0;
  409|  46.7k|}
sshbuf.c:sshbuf_check_sanity:
   56|   353k|{
   57|   353k|	SSHBUF_TELL("sanity");
   58|   353k|	if (__predict_false(buf == NULL ||
  ------------------
  |  |  924|  6.04M|#  define __predict_false(exp)    __builtin_expect(((exp) != 0), 0)
  |  |  ------------------
  |  |  |  Branch (924:35): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 28.3k, False: 325k]
  |  |  |  Branch (924:54): [True: 0, False: 28.3k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  |  Branch (924:54): [True: 0, False: 353k]
  |  |  ------------------
  ------------------
   59|   353k|	    (!buf->readonly && buf->d != buf->cd) ||
   60|   353k|	    buf->refcount < 1 || buf->refcount > SSHBUF_REFS_MAX ||
   61|   353k|	    buf->cd == NULL ||
   62|   353k|	    buf->max_size > SSHBUF_SIZE_MAX ||
   63|   353k|	    buf->alloc > buf->max_size ||
   64|   353k|	    buf->size > buf->alloc ||
   65|   353k|	    buf->off > buf->size)) {
   66|       |		/* Do not try to recover from corrupted buffer internals */
   67|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
   68|      0|		ssh_signal(SIGSEGV, SIG_DFL);
   69|      0|		raise(SIGSEGV);
   70|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
   71|      0|	}
   72|   353k|	return 0;
   73|   353k|}
sshbuf.c:sshbuf_maybe_pack:
   77|  13.9k|{
   78|  13.9k|	SSHBUF_DBG(("force %d", force));
   79|  13.9k|	SSHBUF_TELL("pre-pack");
   80|  13.9k|	if (buf->off == 0 || buf->readonly || buf->refcount > 1)
  ------------------
  |  Branch (80:6): [True: 13.9k, False: 0]
  |  Branch (80:23): [True: 0, False: 0]
  |  Branch (80:40): [True: 0, False: 0]
  ------------------
   81|  13.9k|		return;
   82|      0|	if (force ||
  ------------------
  |  Branch (82:6): [True: 0, False: 0]
  ------------------
   83|      0|	    (buf->off >= SSHBUF_PACK_MIN && buf->off >= buf->size / 2)) {
  ------------------
  |  |  372|      0|# define SSHBUF_PACK_MIN	8192		/* Minimum packable offset */
  ------------------
  |  Branch (83:7): [True: 0, False: 0]
  |  Branch (83:38): [True: 0, False: 0]
  ------------------
   84|      0|		memmove(buf->d, buf->d + buf->off, buf->size - buf->off);
   85|      0|		buf->size -= buf->off;
   86|      0|		buf->off = 0;
   87|      0|		SSHBUF_TELL("packed");
   88|      0|	}
   89|      0|}

ssh_err:
   24|  2.37k|{
   25|  2.37k|	switch (n) {
   26|      0|	case SSH_ERR_SUCCESS:
  ------------------
  |  |   24|      0|#define SSH_ERR_SUCCESS				0
  ------------------
  |  Branch (26:2): [True: 0, False: 2.37k]
  ------------------
   27|      0|		return "success";
   28|      0|	case SSH_ERR_INTERNAL_ERROR:
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  |  Branch (28:2): [True: 0, False: 2.37k]
  ------------------
   29|      0|		return "unexpected internal error";
   30|      0|	case SSH_ERR_ALLOC_FAIL:
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  |  Branch (30:2): [True: 0, False: 2.37k]
  ------------------
   31|      0|		return "memory allocation failed";
   32|    358|	case SSH_ERR_MESSAGE_INCOMPLETE:
  ------------------
  |  |   27|    358|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  |  Branch (32:2): [True: 358, False: 2.02k]
  ------------------
   33|    358|		return "incomplete message";
   34|    526|	case SSH_ERR_INVALID_FORMAT:
  ------------------
  |  |   28|    526|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  |  Branch (34:2): [True: 526, False: 1.85k]
  ------------------
   35|    526|		return "invalid format";
   36|      0|	case SSH_ERR_BIGNUM_IS_NEGATIVE:
  ------------------
  |  |   29|      0|#define SSH_ERR_BIGNUM_IS_NEGATIVE		-5
  ------------------
  |  Branch (36:2): [True: 0, False: 2.37k]
  ------------------
   37|      0|		return "bignum is negative";
   38|     90|	case SSH_ERR_STRING_TOO_LARGE:
  ------------------
  |  |   30|     90|#define SSH_ERR_STRING_TOO_LARGE		-6
  ------------------
  |  Branch (38:2): [True: 90, False: 2.28k]
  ------------------
   39|     90|		return "string is too large";
   40|      0|	case SSH_ERR_BIGNUM_TOO_LARGE:
  ------------------
  |  |   31|      0|#define SSH_ERR_BIGNUM_TOO_LARGE		-7
  ------------------
  |  Branch (40:2): [True: 0, False: 2.37k]
  ------------------
   41|      0|		return "bignum is too large";
   42|     40|	case SSH_ERR_ECPOINT_TOO_LARGE:
  ------------------
  |  |   32|     40|#define SSH_ERR_ECPOINT_TOO_LARGE		-8
  ------------------
  |  Branch (42:2): [True: 40, False: 2.33k]
  ------------------
   43|     40|		return "elliptic curve point is too large";
   44|      0|	case SSH_ERR_NO_BUFFER_SPACE:
  ------------------
  |  |   33|      0|#define SSH_ERR_NO_BUFFER_SPACE			-9
  ------------------
  |  Branch (44:2): [True: 0, False: 2.37k]
  ------------------
   45|      0|		return "insufficient buffer space";
   46|     35|	case SSH_ERR_INVALID_ARGUMENT:
  ------------------
  |  |   34|     35|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  |  Branch (46:2): [True: 35, False: 2.34k]
  ------------------
   47|     35|		return "invalid argument";
   48|      8|	case SSH_ERR_KEY_BITS_MISMATCH:
  ------------------
  |  |   35|      8|#define SSH_ERR_KEY_BITS_MISMATCH		-11
  ------------------
  |  Branch (48:2): [True: 8, False: 2.37k]
  ------------------
   49|      8|		return "key bits do not match";
   50|      0|	case SSH_ERR_EC_CURVE_INVALID:
  ------------------
  |  |   36|      0|#define SSH_ERR_EC_CURVE_INVALID		-12
  ------------------
  |  Branch (50:2): [True: 0, False: 2.37k]
  ------------------
   51|      0|		return "invalid elliptic curve";
   52|    543|	case SSH_ERR_KEY_TYPE_MISMATCH:
  ------------------
  |  |   37|    543|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  |  Branch (52:2): [True: 543, False: 1.83k]
  ------------------
   53|    543|		return "key type does not match";
   54|    359|	case SSH_ERR_KEY_TYPE_UNKNOWN:
  ------------------
  |  |   38|    359|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
  |  Branch (54:2): [True: 359, False: 2.02k]
  ------------------
   55|    359|		return "unknown or unsupported key type";
   56|    115|	case SSH_ERR_EC_CURVE_MISMATCH:
  ------------------
  |  |   39|    115|#define SSH_ERR_EC_CURVE_MISMATCH		-15
  ------------------
  |  Branch (56:2): [True: 115, False: 2.26k]
  ------------------
   57|    115|		return "elliptic curve does not match";
   58|      0|	case SSH_ERR_EXPECTED_CERT:
  ------------------
  |  |   40|      0|#define SSH_ERR_EXPECTED_CERT			-16
  ------------------
  |  Branch (58:2): [True: 0, False: 2.37k]
  ------------------
   59|      0|		return "plain key provided where certificate required";
   60|      0|	case SSH_ERR_KEY_LACKS_CERTBLOB:
  ------------------
  |  |   41|      0|#define SSH_ERR_KEY_LACKS_CERTBLOB		-17
  ------------------
  |  Branch (60:2): [True: 0, False: 2.37k]
  ------------------
   61|      0|		return "key lacks certificate data";
   62|     55|	case SSH_ERR_KEY_CERT_UNKNOWN_TYPE:
  ------------------
  |  |   42|     55|#define SSH_ERR_KEY_CERT_UNKNOWN_TYPE		-18
  ------------------
  |  Branch (62:2): [True: 55, False: 2.32k]
  ------------------
   63|     55|		return "unknown/unsupported certificate type";
   64|     43|	case SSH_ERR_KEY_CERT_INVALID_SIGN_KEY:
  ------------------
  |  |   43|     43|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
  |  Branch (64:2): [True: 43, False: 2.33k]
  ------------------
   65|     43|		return "invalid certificate signing key";
   66|      0|	case SSH_ERR_KEY_INVALID_EC_VALUE:
  ------------------
  |  |   44|      0|#define SSH_ERR_KEY_INVALID_EC_VALUE		-20
  ------------------
  |  Branch (66:2): [True: 0, False: 2.37k]
  ------------------
   67|      0|		return "invalid elliptic curve value";
   68|     60|	case SSH_ERR_SIGNATURE_INVALID:
  ------------------
  |  |   45|     60|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  |  Branch (68:2): [True: 60, False: 2.31k]
  ------------------
   69|     60|		return "incorrect signature";
   70|     21|	case SSH_ERR_LIBCRYPTO_ERROR:
  ------------------
  |  |   46|     21|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  |  Branch (70:2): [True: 21, False: 2.35k]
  ------------------
   71|     21|		return "error in libcrypto";  /* XXX fetch and return */
   72|     48|	case SSH_ERR_UNEXPECTED_TRAILING_DATA:
  ------------------
  |  |   47|     48|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  |  Branch (72:2): [True: 48, False: 2.33k]
  ------------------
   73|     48|		return "unexpected bytes remain after decoding";
   74|      0|	case SSH_ERR_SYSTEM_ERROR:
  ------------------
  |  |   48|      0|#define SSH_ERR_SYSTEM_ERROR			-24
  ------------------
  |  Branch (74:2): [True: 0, False: 2.37k]
  ------------------
   75|      0|		return strerror(errno);
   76|      0|	case SSH_ERR_KEY_CERT_INVALID:
  ------------------
  |  |   49|      0|#define SSH_ERR_KEY_CERT_INVALID		-25
  ------------------
  |  Branch (76:2): [True: 0, False: 2.37k]
  ------------------
   77|      0|		return "invalid certificate";
   78|      0|	case SSH_ERR_AGENT_COMMUNICATION:
  ------------------
  |  |   50|      0|#define SSH_ERR_AGENT_COMMUNICATION		-26
  ------------------
  |  Branch (78:2): [True: 0, False: 2.37k]
  ------------------
   79|      0|		return "communication with agent failed";
   80|      0|	case SSH_ERR_AGENT_FAILURE:
  ------------------
  |  |   51|      0|#define SSH_ERR_AGENT_FAILURE			-27
  ------------------
  |  Branch (80:2): [True: 0, False: 2.37k]
  ------------------
   81|      0|		return "agent refused operation";
   82|      0|	case SSH_ERR_DH_GEX_OUT_OF_RANGE:
  ------------------
  |  |   52|      0|#define SSH_ERR_DH_GEX_OUT_OF_RANGE		-28
  ------------------
  |  Branch (82:2): [True: 0, False: 2.37k]
  ------------------
   83|      0|		return "DH GEX group out of range";
   84|      0|	case SSH_ERR_DISCONNECTED:
  ------------------
  |  |   53|      0|#define SSH_ERR_DISCONNECTED			-29
  ------------------
  |  Branch (84:2): [True: 0, False: 2.37k]
  ------------------
   85|      0|		return "disconnected";
   86|      0|	case SSH_ERR_MAC_INVALID:
  ------------------
  |  |   54|      0|#define SSH_ERR_MAC_INVALID			-30
  ------------------
  |  Branch (86:2): [True: 0, False: 2.37k]
  ------------------
   87|      0|		return "message authentication code incorrect";
   88|      0|	case SSH_ERR_NO_CIPHER_ALG_MATCH:
  ------------------
  |  |   55|      0|#define SSH_ERR_NO_CIPHER_ALG_MATCH		-31
  ------------------
  |  Branch (88:2): [True: 0, False: 2.37k]
  ------------------
   89|      0|		return "no matching cipher found";
   90|      0|	case SSH_ERR_NO_MAC_ALG_MATCH:
  ------------------
  |  |   56|      0|#define SSH_ERR_NO_MAC_ALG_MATCH		-32
  ------------------
  |  Branch (90:2): [True: 0, False: 2.37k]
  ------------------
   91|      0|		return "no matching MAC found";
   92|      0|	case SSH_ERR_NO_COMPRESS_ALG_MATCH:
  ------------------
  |  |   57|      0|#define SSH_ERR_NO_COMPRESS_ALG_MATCH		-33
  ------------------
  |  Branch (92:2): [True: 0, False: 2.37k]
  ------------------
   93|      0|		return "no matching compression method found";
   94|      0|	case SSH_ERR_NO_KEX_ALG_MATCH:
  ------------------
  |  |   58|      0|#define SSH_ERR_NO_KEX_ALG_MATCH		-34
  ------------------
  |  Branch (94:2): [True: 0, False: 2.37k]
  ------------------
   95|      0|		return "no matching key exchange method found";
   96|      0|	case SSH_ERR_NO_HOSTKEY_ALG_MATCH:
  ------------------
  |  |   59|      0|#define SSH_ERR_NO_HOSTKEY_ALG_MATCH		-35
  ------------------
  |  Branch (96:2): [True: 0, False: 2.37k]
  ------------------
   97|      0|		return "no matching host key type found";
   98|      0|	case SSH_ERR_PROTOCOL_MISMATCH:
  ------------------
  |  |   61|      0|#define SSH_ERR_PROTOCOL_MISMATCH		-37
  ------------------
  |  Branch (98:2): [True: 0, False: 2.37k]
  ------------------
   99|      0|		return "protocol version mismatch";
  100|      0|	case SSH_ERR_NO_PROTOCOL_VERSION:
  ------------------
  |  |   62|      0|#define SSH_ERR_NO_PROTOCOL_VERSION		-38
  ------------------
  |  Branch (100:2): [True: 0, False: 2.37k]
  ------------------
  101|      0|		return "could not read protocol version";
  102|      0|	case SSH_ERR_NO_HOSTKEY_LOADED:
  ------------------
  |  |   60|      0|#define SSH_ERR_NO_HOSTKEY_LOADED		-36
  ------------------
  |  Branch (102:2): [True: 0, False: 2.37k]
  ------------------
  103|      0|		return "could not load host key";
  104|      0|	case SSH_ERR_NEED_REKEY:
  ------------------
  |  |   63|      0|#define SSH_ERR_NEED_REKEY			-39
  ------------------
  |  Branch (104:2): [True: 0, False: 2.37k]
  ------------------
  105|      0|		return "rekeying not supported by peer";
  106|      0|	case SSH_ERR_PASSPHRASE_TOO_SHORT:
  ------------------
  |  |   64|      0|#define SSH_ERR_PASSPHRASE_TOO_SHORT		-40
  ------------------
  |  Branch (106:2): [True: 0, False: 2.37k]
  ------------------
  107|      0|		return "passphrase is too short (minimum five characters)";
  108|      0|	case SSH_ERR_FILE_CHANGED:
  ------------------
  |  |   65|      0|#define SSH_ERR_FILE_CHANGED			-41
  ------------------
  |  Branch (108:2): [True: 0, False: 2.37k]
  ------------------
  109|      0|		return "file changed while reading";
  110|      0|	case SSH_ERR_KEY_UNKNOWN_CIPHER:
  ------------------
  |  |   66|      0|#define SSH_ERR_KEY_UNKNOWN_CIPHER		-42
  ------------------
  |  Branch (110:2): [True: 0, False: 2.37k]
  ------------------
  111|      0|		return "key encrypted using unsupported cipher";
  112|      0|	case SSH_ERR_KEY_WRONG_PASSPHRASE:
  ------------------
  |  |   67|      0|#define SSH_ERR_KEY_WRONG_PASSPHRASE		-43
  ------------------
  |  Branch (112:2): [True: 0, False: 2.37k]
  ------------------
  113|      0|		return "incorrect passphrase supplied to decrypt private key";
  114|      0|	case SSH_ERR_KEY_BAD_PERMISSIONS:
  ------------------
  |  |   68|      0|#define SSH_ERR_KEY_BAD_PERMISSIONS		-44
  ------------------
  |  Branch (114:2): [True: 0, False: 2.37k]
  ------------------
  115|      0|		return "bad permissions";
  116|      0|	case SSH_ERR_KEY_CERT_MISMATCH:
  ------------------
  |  |   69|      0|#define SSH_ERR_KEY_CERT_MISMATCH		-45
  ------------------
  |  Branch (116:2): [True: 0, False: 2.37k]
  ------------------
  117|      0|		return "certificate does not match key";
  118|      0|	case SSH_ERR_KEY_NOT_FOUND:
  ------------------
  |  |   70|      0|#define SSH_ERR_KEY_NOT_FOUND			-46
  ------------------
  |  Branch (118:2): [True: 0, False: 2.37k]
  ------------------
  119|      0|		return "key not found";
  120|      0|	case SSH_ERR_AGENT_NOT_PRESENT:
  ------------------
  |  |   71|      0|#define SSH_ERR_AGENT_NOT_PRESENT		-47
  ------------------
  |  Branch (120:2): [True: 0, False: 2.37k]
  ------------------
  121|      0|		return "agent not present";
  122|      0|	case SSH_ERR_AGENT_NO_IDENTITIES:
  ------------------
  |  |   72|      0|#define SSH_ERR_AGENT_NO_IDENTITIES		-48
  ------------------
  |  Branch (122:2): [True: 0, False: 2.37k]
  ------------------
  123|      0|		return "agent contains no identities";
  124|      0|	case SSH_ERR_BUFFER_READ_ONLY:
  ------------------
  |  |   73|      0|#define SSH_ERR_BUFFER_READ_ONLY		-49
  ------------------
  |  Branch (124:2): [True: 0, False: 2.37k]
  ------------------
  125|      0|		return "internal error: buffer is read-only";
  126|      0|	case SSH_ERR_KRL_BAD_MAGIC:
  ------------------
  |  |   74|      0|#define SSH_ERR_KRL_BAD_MAGIC			-50
  ------------------
  |  Branch (126:2): [True: 0, False: 2.37k]
  ------------------
  127|      0|		return "KRL file has invalid magic number";
  128|      0|	case SSH_ERR_KEY_REVOKED:
  ------------------
  |  |   75|      0|#define SSH_ERR_KEY_REVOKED			-51
  ------------------
  |  Branch (128:2): [True: 0, False: 2.37k]
  ------------------
  129|      0|		return "Key is revoked";
  130|      0|	case SSH_ERR_CONN_CLOSED:
  ------------------
  |  |   76|      0|#define SSH_ERR_CONN_CLOSED			-52
  ------------------
  |  Branch (130:2): [True: 0, False: 2.37k]
  ------------------
  131|      0|		return "Connection closed";
  132|      0|	case SSH_ERR_CONN_TIMEOUT:
  ------------------
  |  |   77|      0|#define SSH_ERR_CONN_TIMEOUT			-53
  ------------------
  |  Branch (132:2): [True: 0, False: 2.37k]
  ------------------
  133|      0|		return "Connection timed out";
  134|      0|	case SSH_ERR_CONN_CORRUPT:
  ------------------
  |  |   78|      0|#define SSH_ERR_CONN_CORRUPT			-54
  ------------------
  |  Branch (134:2): [True: 0, False: 2.37k]
  ------------------
  135|      0|		return "Connection corrupted";
  136|      0|	case SSH_ERR_PROTOCOL_ERROR:
  ------------------
  |  |   79|      0|#define SSH_ERR_PROTOCOL_ERROR			-55
  ------------------
  |  Branch (136:2): [True: 0, False: 2.37k]
  ------------------
  137|      0|		return "Protocol error";
  138|     23|	case SSH_ERR_KEY_LENGTH:
  ------------------
  |  |   80|     23|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
  |  Branch (138:2): [True: 23, False: 2.35k]
  ------------------
  139|     23|		return "Invalid key length";
  140|      0|	case SSH_ERR_NUMBER_TOO_LARGE:
  ------------------
  |  |   81|      0|#define SSH_ERR_NUMBER_TOO_LARGE		-57
  ------------------
  |  Branch (140:2): [True: 0, False: 2.37k]
  ------------------
  141|      0|		return "number is too large";
  142|     55|	case SSH_ERR_SIGN_ALG_UNSUPPORTED:
  ------------------
  |  |   82|     55|#define SSH_ERR_SIGN_ALG_UNSUPPORTED		-58
  ------------------
  |  Branch (142:2): [True: 55, False: 2.32k]
  ------------------
  143|     55|		return "signature algorithm not supported";
  144|      0|	case SSH_ERR_FEATURE_UNSUPPORTED:
  ------------------
  |  |   83|      0|#define SSH_ERR_FEATURE_UNSUPPORTED		-59
  ------------------
  |  Branch (144:2): [True: 0, False: 2.37k]
  ------------------
  145|      0|		return "requested feature not supported";
  146|      0|	case SSH_ERR_DEVICE_NOT_FOUND:
  ------------------
  |  |   84|      0|#define SSH_ERR_DEVICE_NOT_FOUND		-60
  ------------------
  |  Branch (146:2): [True: 0, False: 2.37k]
  ------------------
  147|      0|		return "device not found";
  148|      0|	default:
  ------------------
  |  Branch (148:2): [True: 0, False: 2.37k]
  ------------------
  149|      0|		return "unknown error";
  150|  2.37k|	}
  151|  2.37k|}

sshkey_xmss_init:
   96|    413|{
   97|    413|	struct ssh_xmss_state *state;
   98|       |
   99|    413|	if (key->xmss_state != NULL)
  ------------------
  |  Branch (99:6): [True: 0, False: 413]
  ------------------
  100|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  101|    413|	if (name == NULL)
  ------------------
  |  Branch (101:6): [True: 0, False: 413]
  ------------------
  102|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  103|    413|	state = calloc(sizeof(struct ssh_xmss_state), 1);
  104|    413|	if (state == NULL)
  ------------------
  |  Branch (104:6): [True: 0, False: 413]
  ------------------
  105|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  106|    413|	if (strcmp(name, XMSS_SHA2_256_W16_H10_NAME) == 0) {
  ------------------
  |  |   28|    413|#define XMSS_SHA2_256_W16_H10_NAME	"XMSS_SHA2-256_W16_H10"
  ------------------
  |  Branch (106:6): [True: 90, False: 323]
  ------------------
  107|     90|		state->n = 32;
  108|     90|		state->w = 16;
  109|     90|		state->h = 10;
  110|    323|	} else if (strcmp(name, XMSS_SHA2_256_W16_H16_NAME) == 0) {
  ------------------
  |  |   29|    323|#define XMSS_SHA2_256_W16_H16_NAME	"XMSS_SHA2-256_W16_H16"
  ------------------
  |  Branch (110:13): [True: 80, False: 243]
  ------------------
  111|     80|		state->n = 32;
  112|     80|		state->w = 16;
  113|     80|		state->h = 16;
  114|    243|	} else if (strcmp(name, XMSS_SHA2_256_W16_H20_NAME) == 0) {
  ------------------
  |  |   30|    243|#define XMSS_SHA2_256_W16_H20_NAME	"XMSS_SHA2-256_W16_H20"
  ------------------
  |  Branch (114:13): [True: 89, False: 154]
  ------------------
  115|     89|		state->n = 32;
  116|     89|		state->w = 16;
  117|     89|		state->h = 20;
  118|    154|	} else {
  119|    154|		free(state);
  120|    154|		return SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|    154|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
  121|    154|	}
  122|    259|	if ((key->xmss_name = strdup(name)) == NULL) {
  ------------------
  |  Branch (122:6): [True: 0, False: 259]
  ------------------
  123|      0|		free(state);
  124|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  125|      0|	}
  126|    259|	state->k = 2;	/* XXX hardcoded */
  127|    259|	state->lockfd = -1;
  128|    259|	if (xmss_set_params(&state->params, state->n, state->h, state->w,
  ------------------
  |  Branch (128:6): [True: 0, False: 259]
  ------------------
  129|    259|	    state->k) != 0) {
  130|      0|		free(state);
  131|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  132|      0|	}
  133|    259|	key->xmss_state = state;
  134|    259|	return 0;
  135|    259|}
sshkey_xmss_free_state:
  139|    416|{
  140|    416|	struct ssh_xmss_state *state = key->xmss_state;
  141|       |
  142|    416|	sshkey_xmss_free_bds(key);
  143|    416|	if (state) {
  ------------------
  |  Branch (143:6): [True: 259, False: 157]
  ------------------
  144|    259|		if (state->enc_keyiv) {
  ------------------
  |  Branch (144:7): [True: 0, False: 259]
  ------------------
  145|      0|			explicit_bzero(state->enc_keyiv, state->enc_keyiv_len);
  146|      0|			free(state->enc_keyiv);
  147|      0|		}
  148|    259|		free(state->enc_ciphername);
  149|    259|		free(state);
  150|    259|	}
  151|    416|	key->xmss_state = NULL;
  152|    416|}
sshkey_xmss_free_bds:
  191|    416|{
  192|    416|	struct ssh_xmss_state *state = key->xmss_state;
  193|       |
  194|    416|	if (state == NULL)
  ------------------
  |  Branch (194:6): [True: 157, False: 259]
  ------------------
  195|    157|		return;
  196|    259|	free(state->stack);
  197|    259|	free(state->stacklevels);
  198|    259|	free(state->auth);
  199|    259|	free(state->keep);
  200|    259|	free(state->th_nodes);
  201|    259|	free(state->retain);
  202|    259|	free(state->treehash);
  203|    259|	state->stack = NULL;
  204|    259|	state->stacklevels = NULL;
  205|    259|	state->auth = NULL;
  206|    259|	state->keep = NULL;
  207|    259|	state->th_nodes = NULL;
  208|    259|	state->retain = NULL;
  209|    259|	state->treehash = NULL;
  210|    259|}
sshkey_xmss_params:
  214|    173|{
  215|    173|	struct ssh_xmss_state *state = key->xmss_state;
  216|       |
  217|    173|	if (state == NULL)
  ------------------
  |  Branch (217:6): [True: 0, False: 173]
  ------------------
  218|      0|		return NULL;
  219|    173|	return &state->params;
  220|    173|}
sshkey_xmss_siglen:
  234|    173|{
  235|    173|	struct ssh_xmss_state *state = key->xmss_state;
  236|       |
  237|    173|	if (lenp == NULL)
  ------------------
  |  Branch (237:6): [True: 0, False: 173]
  ------------------
  238|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  239|    173|	if (state == NULL)
  ------------------
  |  Branch (239:6): [True: 0, False: 173]
  ------------------
  240|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  241|    173|	*lenp = 4 + state->n +
  242|    173|	    state->params.wots_par.keysize +
  243|    173|	    state->h * state->n;
  244|    173|	return 0;
  245|    173|}
sshkey_xmss_pklen:
  249|    668|{
  250|    668|	struct ssh_xmss_state *state = key->xmss_state;
  251|       |
  252|    668|	if (state == NULL)
  ------------------
  |  Branch (252:6): [True: 157, False: 511]
  ------------------
  253|    157|		return 0;
  254|    511|	return state->n * 2;
  255|    668|}
sshkey_xmss_sklen:
  259|    416|{
  260|    416|	struct ssh_xmss_state *state = key->xmss_state;
  261|       |
  262|    416|	if (state == NULL)
  ------------------
  |  Branch (262:6): [True: 157, False: 259]
  ------------------
  263|    157|		return 0;
  264|    259|	return state->n * 4 + 4;
  265|    416|}
sshkey_xmss_deserialize_pk_info:
  347|    204|{
  348|    204|	struct ssh_xmss_state *state = k->xmss_state;
  349|    204|	u_char have_info;
  350|    204|	int r;
  351|       |
  352|    204|	if (state == NULL)
  ------------------
  |  Branch (352:6): [True: 0, False: 204]
  ------------------
  353|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  354|       |	/* optional */
  355|    204|	if (sshbuf_len(b) == 0)
  ------------------
  |  Branch (355:6): [True: 176, False: 28]
  ------------------
  356|    176|		return 0;
  357|     28|	if ((r = sshbuf_get_u8(b, &have_info)) != 0)
  ------------------
  |  Branch (357:6): [True: 0, False: 28]
  ------------------
  358|      0|		return r;
  359|     28|	if (have_info != 1)
  ------------------
  |  Branch (359:6): [True: 21, False: 7]
  ------------------
  360|     21|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|     21|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  361|      7|	if ((r = sshbuf_get_u32(b, &state->idx)) != 0 ||
  ------------------
  |  Branch (361:6): [True: 3, False: 4]
  ------------------
  362|      7|	    (r = sshbuf_get_u32(b, &state->maxidx)) != 0)
  ------------------
  |  Branch (362:6): [True: 1, False: 3]
  ------------------
  363|      4|		return r;
  364|      3|	return 0;
  365|      7|}

sshkey_type_is_cert:
  230|  8.28k|{
  231|  8.28k|	const struct sshkey_impl *impl;
  232|       |
  233|  8.28k|	if ((impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (233:6): [True: 1, False: 8.28k]
  ------------------
  234|      1|		return 0;
  235|  8.28k|	return impl->cert;
  236|  8.28k|}
sshkey_ssh_name_plain:
  246|    159|{
  247|    159|	return sshkey_ssh_name_from_type_nid(sshkey_type_plain(k->type),
  248|    159|	    k->ecdsa_nid);
  249|    159|}
sshkey_type_from_name:
  253|  2.32k|{
  254|  2.32k|	int i;
  255|  2.32k|	const struct sshkey_impl *impl;
  256|       |
  257|  24.3k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (257:14): [True: 24.1k, False: 207]
  ------------------
  258|  24.1k|		impl = keyimpls[i];
  259|       |		/* Only allow shortname matches for plain key types */
  260|  24.1k|		if ((impl->name != NULL && strcmp(name, impl->name) == 0) ||
  ------------------
  |  Branch (260:8): [True: 24.1k, False: 0]
  |  Branch (260:30): [True: 1.15k, False: 23.0k]
  ------------------
  261|  24.1k|		    (!impl->cert && strcasecmp(impl->shortname, name) == 0))
  ------------------
  |  Branch (261:8): [True: 12.8k, False: 10.1k]
  |  Branch (261:23): [True: 970, False: 11.8k]
  ------------------
  262|  2.12k|			return impl->type;
  263|  24.1k|	}
  264|    207|	return KEY_UNSPEC;
  265|  2.32k|}
sshkey_ecdsa_nid_from_name:
  282|    263|{
  283|    263|	int i;
  284|       |
  285|  1.98k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (285:14): [True: 1.97k, False: 10]
  ------------------
  286|  1.97k|		if (!key_type_is_ecdsa_variant(keyimpls[i]->type))
  ------------------
  |  Branch (286:7): [True: 1.13k, False: 844]
  ------------------
  287|  1.13k|			continue;
  288|    844|		if (keyimpls[i]->name != NULL &&
  ------------------
  |  Branch (288:7): [True: 844, False: 0]
  ------------------
  289|    844|		    strcmp(name, keyimpls[i]->name) == 0)
  ------------------
  |  Branch (289:7): [True: 253, False: 591]
  ------------------
  290|    253|			return keyimpls[i]->nid;
  291|    844|	}
  292|     10|	return -1;
  293|    263|}
sshkey_is_cert:
  415|  5.89k|{
  416|  5.89k|	if (k == NULL)
  ------------------
  |  Branch (416:6): [True: 0, False: 5.89k]
  ------------------
  417|      0|		return 0;
  418|  5.89k|	return sshkey_type_is_cert(k->type);
  419|  5.89k|}
sshkey_type_plain:
  438|  1.45k|{
  439|  1.45k|	switch (type) {
  440|      0|	case KEY_RSA_CERT:
  ------------------
  |  Branch (440:2): [True: 0, False: 1.45k]
  ------------------
  441|      0|		return KEY_RSA;
  442|      0|	case KEY_DSA_CERT:
  ------------------
  |  Branch (442:2): [True: 0, False: 1.45k]
  ------------------
  443|      0|		return KEY_DSA;
  444|      0|	case KEY_ECDSA_CERT:
  ------------------
  |  Branch (444:2): [True: 0, False: 1.45k]
  ------------------
  445|      0|		return KEY_ECDSA;
  446|      0|	case KEY_ECDSA_SK_CERT:
  ------------------
  |  Branch (446:2): [True: 0, False: 1.45k]
  ------------------
  447|      0|		return KEY_ECDSA_SK;
  448|      0|	case KEY_ED25519_CERT:
  ------------------
  |  Branch (448:2): [True: 0, False: 1.45k]
  ------------------
  449|      0|		return KEY_ED25519;
  450|      0|	case KEY_ED25519_SK_CERT:
  ------------------
  |  Branch (450:2): [True: 0, False: 1.45k]
  ------------------
  451|      0|		return KEY_ED25519_SK;
  452|      0|	case KEY_XMSS_CERT:
  ------------------
  |  Branch (452:2): [True: 0, False: 1.45k]
  ------------------
  453|      0|		return KEY_XMSS;
  454|  1.45k|	default:
  ------------------
  |  Branch (454:2): [True: 1.45k, False: 0]
  ------------------
  455|  1.45k|		return type;
  456|  1.45k|	}
  457|  1.45k|}
sshkey_curve_name_to_nid:
  487|    244|{
  488|    244|	if (strcmp(name, "nistp256") == 0)
  ------------------
  |  Branch (488:6): [True: 35, False: 209]
  ------------------
  489|     35|		return NID_X9_62_prime256v1;
  490|    209|	else if (strcmp(name, "nistp384") == 0)
  ------------------
  |  Branch (490:11): [True: 63, False: 146]
  ------------------
  491|     63|		return NID_secp384r1;
  492|    146|# ifdef OPENSSL_HAS_NISTP521
  493|    146|	else if (strcmp(name, "nistp521") == 0)
  ------------------
  |  Branch (493:11): [True: 34, False: 112]
  ------------------
  494|     34|		return NID_secp521r1;
  495|    112|# endif /* OPENSSL_HAS_NISTP521 */
  496|    112|	else
  497|    112|		return -1;
  498|    244|}
sshkey_new:
  610|  2.12k|{
  611|  2.12k|	struct sshkey *k;
  612|  2.12k|	const struct sshkey_impl *impl = NULL;
  613|       |
  614|  2.12k|	if (type != KEY_UNSPEC &&
  ------------------
  |  Branch (614:6): [True: 2.12k, False: 0]
  ------------------
  615|  2.12k|	    (impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (615:6): [True: 0, False: 2.12k]
  ------------------
  616|      0|		return NULL;
  617|       |
  618|       |	/* All non-certificate types may act as CAs */
  619|  2.12k|	if ((k = calloc(1, sizeof(*k))) == NULL)
  ------------------
  |  Branch (619:6): [True: 0, False: 2.12k]
  ------------------
  620|      0|		return NULL;
  621|  2.12k|	k->type = type;
  622|  2.12k|	k->ecdsa_nid = -1;
  623|  2.12k|	if (impl != NULL && impl->funcs->alloc != NULL) {
  ------------------
  |  Branch (623:6): [True: 2.12k, False: 0]
  |  Branch (623:22): [True: 493, False: 1.62k]
  ------------------
  624|    493|		if (impl->funcs->alloc(k) != 0) {
  ------------------
  |  Branch (624:7): [True: 0, False: 493]
  ------------------
  625|      0|			free(k);
  626|      0|			return NULL;
  627|      0|		}
  628|    493|	}
  629|  2.12k|	if (sshkey_is_cert(k)) {
  ------------------
  |  Branch (629:6): [True: 570, False: 1.55k]
  ------------------
  630|    570|		if ((k->cert = cert_new()) == NULL) {
  ------------------
  |  Branch (630:7): [True: 0, False: 570]
  ------------------
  631|      0|			sshkey_free(k);
  632|      0|			return NULL;
  633|      0|		}
  634|    570|	}
  635|       |
  636|  2.12k|	return k;
  637|  2.12k|}
sshkey_sk_cleanup:
  642|    620|{
  643|    620|	free(k->sk_application);
  644|    620|	sshbuf_free(k->sk_key_handle);
  645|    620|	sshbuf_free(k->sk_reserved);
  646|    620|	k->sk_application = NULL;
  647|    620|	k->sk_key_handle = k->sk_reserved = NULL;
  648|    620|}
sshkey_free:
  668|  7.60k|{
  669|  7.60k|	sshkey_free_contents(k);
  670|  7.60k|	freezero(k, sizeof(*k));
  671|  7.60k|}
sshkey_check_rsa_length:
 1332|    371|{
 1333|    371|#ifdef WITH_OPENSSL
 1334|    371|	const BIGNUM *rsa_n;
 1335|    371|	int nbits;
 1336|       |
 1337|    371|	if (k == NULL || k->rsa == NULL ||
  ------------------
  |  Branch (1337:6): [True: 0, False: 371]
  |  Branch (1337:19): [True: 0, False: 371]
  ------------------
 1338|    371|	    (k->type != KEY_RSA && k->type != KEY_RSA_CERT))
  ------------------
  |  Branch (1338:7): [True: 93, False: 278]
  |  Branch (1338:29): [True: 0, False: 93]
  ------------------
 1339|      0|		return 0;
 1340|    371|	RSA_get0_key(k->rsa, &rsa_n, NULL, NULL);
 1341|    371|	nbits = BN_num_bits(rsa_n);
 1342|    371|	if (nbits < SSH_RSA_MINIMUM_MODULUS_SIZE ||
  ------------------
  |  |   53|    742|#define SSH_RSA_MINIMUM_MODULUS_SIZE	1024
  ------------------
  |  Branch (1342:6): [True: 27, False: 344]
  ------------------
 1343|    371|	    (min_size > 0 && nbits < min_size))
  ------------------
  |  Branch (1343:7): [True: 0, False: 344]
  |  Branch (1343:23): [True: 0, False: 0]
  ------------------
 1344|     27|		return SSH_ERR_KEY_LENGTH;
  ------------------
  |  |   80|     27|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
 1345|    344|#endif /* WITH_OPENSSL */
 1346|    344|	return 0;
 1347|    371|}
sshkey_deserialize_sk:
 1889|    605|{
 1890|       |	/* Parse additional security-key application string */
 1891|    605|	if (sshbuf_get_cstring(b, &key->sk_application, NULL) != 0)
  ------------------
  |  Branch (1891:6): [True: 2, False: 603]
  ------------------
 1892|      2|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      2|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1893|    603|	return 0;
 1894|    605|}
sshkey_froms:
 1984|  2.10k|{
 1985|  2.10k|	struct sshbuf *b;
 1986|  2.10k|	int r;
 1987|       |
 1988|  2.10k|	if ((r = sshbuf_froms(buf, &b)) != 0)
  ------------------
  |  Branch (1988:6): [True: 0, False: 2.10k]
  ------------------
 1989|      0|		return r;
 1990|  2.10k|	r = sshkey_from_blob_internal(b, keyp, 1);
 1991|  2.10k|	sshbuf_free(b);
 1992|  2.10k|	return r;
 1993|  2.10k|}
sshkey_get_sigtype:
 1997|     41|{
 1998|     41|	int r;
 1999|     41|	struct sshbuf *b = NULL;
 2000|     41|	char *sigtype = NULL;
 2001|       |
 2002|     41|	if (sigtypep != NULL)
  ------------------
  |  Branch (2002:6): [True: 41, False: 0]
  ------------------
 2003|     41|		*sigtypep = NULL;
 2004|     41|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (2004:6): [True: 0, False: 41]
  ------------------
 2005|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 2006|     41|	if ((r = sshbuf_get_cstring(b, &sigtype, NULL)) != 0)
  ------------------
  |  Branch (2006:6): [True: 2, False: 39]
  ------------------
 2007|      2|		goto out;
 2008|       |	/* success */
 2009|     39|	if (sigtypep != NULL) {
  ------------------
  |  Branch (2009:6): [True: 39, False: 0]
  ------------------
 2010|     39|		*sigtypep = sigtype;
 2011|     39|		sigtype = NULL;
 2012|     39|	}
 2013|     39|	r = 0;
 2014|     41| out:
 2015|     41|	free(sigtype);
 2016|     41|	sshbuf_free(b);
 2017|     41|	return r;
 2018|     39|}
sshkey_verify:
 2132|    772|{
 2133|    772|	const struct sshkey_impl *impl;
 2134|       |
 2135|    772|	if (detailsp != NULL)
  ------------------
  |  Branch (2135:6): [True: 521, False: 251]
  ------------------
 2136|    521|		*detailsp = NULL;
 2137|    772|	if (siglen == 0 || dlen > SSH_KEY_MAX_SIGN_DATA_SIZE)
  ------------------
  |  |   54|    767|#define SSH_KEY_MAX_SIGN_DATA_SIZE	(1 << 20)
  ------------------
  |  Branch (2137:6): [True: 5, False: 767]
  |  Branch (2137:21): [True: 0, False: 767]
  ------------------
 2138|      5|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      5|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
 2139|    767|	if ((impl = sshkey_impl_from_key(key)) == NULL)
  ------------------
  |  Branch (2139:6): [True: 0, False: 767]
  ------------------
 2140|      0|		return SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|      0|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
 2141|    767|	return impl->funcs->verify(key, sig, siglen, data, dlen,
 2142|    767|	    alg, compat, detailsp);
 2143|    767|}
sshkey_sig_details_free:
 3611|  2.71k|{
 3612|  2.71k|	freezero(details, sizeof(*details));
 3613|  2.71k|}
sshkey.c:sshkey_impl_from_key:
  202|    767|{
  203|    767|	if (k == NULL)
  ------------------
  |  Branch (203:6): [True: 0, False: 767]
  ------------------
  204|      0|		return NULL;
  205|    767|	return sshkey_impl_from_type_nid(k->type, k->ecdsa_nid);
  206|    767|}
sshkey.c:sshkey_impl_from_type_nid:
  189|    926|{
  190|    926|	int i;
  191|       |
  192|  7.94k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (192:14): [True: 7.94k, False: 0]
  ------------------
  193|  7.94k|		if (keyimpls[i]->type == type &&
  ------------------
  |  Branch (193:7): [True: 926, False: 7.02k]
  ------------------
  194|  7.94k|		    (keyimpls[i]->nid == 0 || keyimpls[i]->nid == nid))
  ------------------
  |  Branch (194:8): [True: 926, False: 0]
  |  Branch (194:33): [True: 0, False: 0]
  ------------------
  195|    926|			return keyimpls[i];
  196|  7.94k|	}
  197|      0|	return NULL;
  198|    926|}
sshkey.c:sshkey_impl_from_type:
  177|  15.1k|{
  178|  15.1k|	int i;
  179|       |
  180|   142k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (180:14): [True: 142k, False: 208]
  ------------------
  181|   142k|		if (keyimpls[i]->type == type)
  ------------------
  |  Branch (181:7): [True: 14.8k, False: 127k]
  ------------------
  182|  14.8k|			return keyimpls[i];
  183|   142k|	}
  184|    208|	return NULL;
  185|  15.1k|}
sshkey.c:sshkey_ssh_name_from_type_nid:
  220|    159|{
  221|    159|	const struct sshkey_impl *impl;
  222|       |
  223|    159|	if ((impl = sshkey_impl_from_type_nid(type, nid)) == NULL)
  ------------------
  |  Branch (223:6): [True: 0, False: 159]
  ------------------
  224|      0|		return "ssh-unknown";
  225|    159|	return impl->name;
  226|    159|}
sshkey.c:key_type_is_ecdsa_variant:
  269|  1.97k|{
  270|  1.97k|	switch (type) {
  ------------------
  |  Branch (270:10): [True: 1.13k, False: 844]
  ------------------
  271|    526|	case KEY_ECDSA:
  ------------------
  |  Branch (271:2): [True: 526, False: 1.45k]
  ------------------
  272|    807|	case KEY_ECDSA_CERT:
  ------------------
  |  Branch (272:2): [True: 281, False: 1.69k]
  ------------------
  273|    833|	case KEY_ECDSA_SK:
  ------------------
  |  Branch (273:2): [True: 26, False: 1.95k]
  ------------------
  274|    844|	case KEY_ECDSA_SK_CERT:
  ------------------
  |  Branch (274:2): [True: 11, False: 1.96k]
  ------------------
  275|    844|		return 1;
  276|  1.97k|	}
  277|  1.13k|	return 0;
  278|  1.97k|}
sshkey.c:cert_new:
  590|    570|{
  591|    570|	struct sshkey_cert *cert;
  592|       |
  593|    570|	if ((cert = calloc(1, sizeof(*cert))) == NULL)
  ------------------
  |  Branch (593:6): [True: 0, False: 570]
  ------------------
  594|      0|		return NULL;
  595|    570|	if ((cert->certblob = sshbuf_new()) == NULL ||
  ------------------
  |  Branch (595:6): [True: 0, False: 570]
  ------------------
  596|    570|	    (cert->critical = sshbuf_new()) == NULL ||
  ------------------
  |  Branch (596:6): [True: 0, False: 570]
  ------------------
  597|    570|	    (cert->extensions = sshbuf_new()) == NULL) {
  ------------------
  |  Branch (597:6): [True: 0, False: 570]
  ------------------
  598|      0|		cert_free(cert);
  599|      0|		return NULL;
  600|      0|	}
  601|    570|	cert->key_id = NULL;
  602|    570|	cert->principals = NULL;
  603|    570|	cert->signature_key = NULL;
  604|    570|	cert->signature_type = NULL;
  605|    570|	return cert;
  606|    570|}
sshkey.c:sshkey_free_contents:
  652|  7.60k|{
  653|  7.60k|	const struct sshkey_impl *impl;
  654|       |
  655|  7.60k|	if (k == NULL)
  ------------------
  |  Branch (655:6): [True: 5.48k, False: 2.12k]
  ------------------
  656|  5.48k|		return;
  657|  2.12k|	if ((impl = sshkey_impl_from_type(k->type)) != NULL &&
  ------------------
  |  Branch (657:6): [True: 2.12k, False: 0]
  ------------------
  658|  2.12k|	    impl->funcs->cleanup != NULL)
  ------------------
  |  Branch (658:6): [True: 2.12k, False: 0]
  ------------------
  659|  2.12k|		impl->funcs->cleanup(k);
  660|  2.12k|	if (sshkey_is_cert(k))
  ------------------
  |  Branch (660:6): [True: 570, False: 1.55k]
  ------------------
  661|    570|		cert_free(k->cert);
  662|  2.12k|	freezero(k->shielded_private, k->shielded_len);
  663|  2.12k|	freezero(k->shield_prekey, k->shield_prekey_len);
  664|  2.12k|}
sshkey.c:cert_free:
  571|    570|{
  572|    570|	u_int i;
  573|       |
  574|    570|	if (cert == NULL)
  ------------------
  |  Branch (574:6): [True: 0, False: 570]
  ------------------
  575|      0|		return;
  576|    570|	sshbuf_free(cert->certblob);
  577|    570|	sshbuf_free(cert->critical);
  578|    570|	sshbuf_free(cert->extensions);
  579|    570|	free(cert->key_id);
  580|  2.80k|	for (i = 0; i < cert->nprincipals; i++)
  ------------------
  |  Branch (580:14): [True: 2.23k, False: 570]
  ------------------
  581|  2.23k|		free(cert->principals[i]);
  582|    570|	free(cert->principals);
  583|    570|	sshkey_free(cert->signature_key);
  584|    570|	free(cert->signature_type);
  585|    570|	freezero(cert, sizeof(*cert));
  586|    570|}
sshkey.c:sshkey_from_blob_internal:
 1899|  2.39k|{
 1900|  2.39k|	int type, ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.39k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 1901|  2.39k|	char *ktype = NULL;
 1902|  2.39k|	struct sshkey *key = NULL;
 1903|  2.39k|	struct sshbuf *copy;
 1904|  2.39k|	const struct sshkey_impl *impl;
 1905|       |
 1906|       |#ifdef DEBUG_PK /* XXX */
 1907|       |	sshbuf_dump(b, stderr);
 1908|       |#endif
 1909|  2.39k|	if (keyp != NULL)
  ------------------
  |  Branch (1909:6): [True: 2.39k, False: 0]
  ------------------
 1910|  2.39k|		*keyp = NULL;
 1911|  2.39k|	if ((copy = sshbuf_fromb(b)) == NULL) {
  ------------------
  |  Branch (1911:6): [True: 0, False: 2.39k]
  ------------------
 1912|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1913|      0|		goto out;
 1914|      0|	}
 1915|  2.39k|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0) {
  ------------------
  |  Branch (1915:6): [True: 65, False: 2.32k]
  ------------------
 1916|     65|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     65|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1917|     65|		goto out;
 1918|     65|	}
 1919|       |
 1920|  2.32k|	type = sshkey_type_from_name(ktype);
 1921|  2.32k|	if (!allow_cert && sshkey_type_is_cert(type)) {
  ------------------
  |  Branch (1921:6): [True: 272, False: 2.05k]
  |  Branch (1921:21): [True: 2, False: 270]
  ------------------
 1922|      2|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|      2|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1923|      2|		goto out;
 1924|      2|	}
 1925|  2.32k|	if ((impl = sshkey_impl_from_type(type)) == NULL) {
  ------------------
  |  Branch (1925:6): [True: 207, False: 2.12k]
  ------------------
 1926|    207|		ret = SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|    207|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
 1927|    207|		goto out;
 1928|    207|	}
 1929|  2.12k|	if ((key = sshkey_new(type)) == NULL) {
  ------------------
  |  Branch (1929:6): [True: 0, False: 2.12k]
  ------------------
 1930|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1931|      0|		goto out;
 1932|      0|	}
 1933|  2.12k|	if (sshkey_type_is_cert(type)) {
  ------------------
  |  Branch (1933:6): [True: 570, False: 1.55k]
  ------------------
 1934|       |		/* Skip nonce that precedes all certificates */
 1935|    570|		if (sshbuf_get_string_direct(b, NULL, NULL) != 0) {
  ------------------
  |  Branch (1935:7): [True: 4, False: 566]
  ------------------
 1936|      4|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      4|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1937|      4|			goto out;
 1938|      4|		}
 1939|    570|	}
 1940|  2.11k|	if ((ret = impl->funcs->deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (1940:6): [True: 676, False: 1.44k]
  ------------------
 1941|    676|		goto out;
 1942|       |
 1943|       |	/* Parse certificate potion */
 1944|  1.44k|	if (sshkey_is_cert(key) && (ret = cert_parse(b, key, copy)) != 0)
  ------------------
  |  Branch (1944:6): [True: 550, False: 890]
  |  Branch (1944:29): [True: 550, False: 0]
  ------------------
 1945|    550|		goto out;
 1946|       |
 1947|    890|	if (key != NULL && sshbuf_len(b) != 0) {
  ------------------
  |  Branch (1947:6): [True: 890, False: 0]
  |  Branch (1947:21): [True: 20, False: 870]
  ------------------
 1948|     20|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     20|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1949|     20|		goto out;
 1950|     20|	}
 1951|    870|	ret = 0;
 1952|    870|	if (keyp != NULL) {
  ------------------
  |  Branch (1952:6): [True: 870, False: 0]
  ------------------
 1953|    870|		*keyp = key;
 1954|    870|		key = NULL;
 1955|    870|	}
 1956|  2.39k| out:
 1957|  2.39k|	sshbuf_free(copy);
 1958|  2.39k|	sshkey_free(key);
 1959|  2.39k|	free(ktype);
 1960|  2.39k|	return ret;
 1961|    870|}
sshkey.c:cert_parse:
 1763|    550|{
 1764|    550|	struct sshbuf *principals = NULL, *crit = NULL;
 1765|    550|	struct sshbuf *exts = NULL, *ca = NULL;
 1766|    550|	u_char *sig = NULL;
 1767|    550|	size_t signed_len = 0, slen = 0, kidlen = 0;
 1768|    550|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    550|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 1769|       |
 1770|       |	/* Copy the entire key blob for verification and later serialisation */
 1771|    550|	if ((ret = sshbuf_putb(key->cert->certblob, certbuf)) != 0)
  ------------------
  |  Branch (1771:6): [True: 0, False: 550]
  ------------------
 1772|      0|		return ret;
 1773|       |
 1774|       |	/* Parse body of certificate up to signature */
 1775|    550|	if ((ret = sshbuf_get_u64(b, &key->cert->serial)) != 0 ||
  ------------------
  |  Branch (1775:6): [True: 6, False: 544]
  ------------------
 1776|    550|	    (ret = sshbuf_get_u32(b, &key->cert->type)) != 0 ||
  ------------------
  |  Branch (1776:6): [True: 1, False: 543]
  ------------------
 1777|    550|	    (ret = sshbuf_get_cstring(b, &key->cert->key_id, &kidlen)) != 0 ||
  ------------------
  |  Branch (1777:6): [True: 8, False: 535]
  ------------------
 1778|    550|	    (ret = sshbuf_froms(b, &principals)) != 0 ||
  ------------------
  |  Branch (1778:6): [True: 25, False: 510]
  ------------------
 1779|    550|	    (ret = sshbuf_get_u64(b, &key->cert->valid_after)) != 0 ||
  ------------------
  |  Branch (1779:6): [True: 9, False: 501]
  ------------------
 1780|    550|	    (ret = sshbuf_get_u64(b, &key->cert->valid_before)) != 0 ||
  ------------------
  |  Branch (1780:6): [True: 3, False: 498]
  ------------------
 1781|    550|	    (ret = sshbuf_froms(b, &crit)) != 0 ||
  ------------------
  |  Branch (1781:6): [True: 18, False: 480]
  ------------------
 1782|    550|	    (ret = sshbuf_froms(b, &exts)) != 0 ||
  ------------------
  |  Branch (1782:6): [True: 14, False: 466]
  ------------------
 1783|    550|	    (ret = sshbuf_get_string_direct(b, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1783:6): [True: 6, False: 460]
  ------------------
 1784|    550|	    (ret = sshbuf_froms(b, &ca)) != 0) {
  ------------------
  |  Branch (1784:6): [True: 8, False: 452]
  ------------------
 1785|       |		/* XXX debug print error for ret */
 1786|     98|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     98|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1787|     98|		goto out;
 1788|     98|	}
 1789|       |
 1790|       |	/* Signature is left in the buffer so we can calculate this length */
 1791|    452|	signed_len = sshbuf_len(key->cert->certblob) - sshbuf_len(b);
 1792|       |
 1793|    452|	if ((ret = sshbuf_get_string(b, &sig, &slen)) != 0) {
  ------------------
  |  Branch (1793:6): [True: 6, False: 446]
  ------------------
 1794|      6|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      6|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1795|      6|		goto out;
 1796|      6|	}
 1797|       |
 1798|    446|	if (key->cert->type != SSH2_CERT_TYPE_USER &&
  ------------------
  |  |  179|    892|#define SSH2_CERT_TYPE_USER				1
  ------------------
  |  Branch (1798:6): [True: 170, False: 276]
  ------------------
 1799|    446|	    key->cert->type != SSH2_CERT_TYPE_HOST) {
  ------------------
  |  |  180|    170|#define SSH2_CERT_TYPE_HOST				2
  ------------------
  |  Branch (1799:6): [True: 55, False: 115]
  ------------------
 1800|     55|		ret = SSH_ERR_KEY_CERT_UNKNOWN_TYPE;
  ------------------
  |  |   42|     55|#define SSH_ERR_KEY_CERT_UNKNOWN_TYPE		-18
  ------------------
 1801|     55|		goto out;
 1802|     55|	}
 1803|       |
 1804|       |	/* Parse principals section */
 1805|  2.62k|	while (sshbuf_len(principals) > 0) {
  ------------------
  |  Branch (1805:9): [True: 2.26k, False: 365]
  ------------------
 1806|  2.26k|		char *principal = NULL;
 1807|  2.26k|		char **oprincipals = NULL;
 1808|       |
 1809|  2.26k|		if (key->cert->nprincipals >= SSHKEY_CERT_MAX_PRINCIPALS) {
  ------------------
  |  |  108|  2.26k|#define SSHKEY_CERT_MAX_PRINCIPALS	256
  ------------------
  |  Branch (1809:7): [True: 1, False: 2.26k]
  ------------------
 1810|      1|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      1|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1811|      1|			goto out;
 1812|      1|		}
 1813|  2.26k|		if ((ret = sshbuf_get_cstring(principals, &principal,
  ------------------
  |  Branch (1813:7): [True: 25, False: 2.23k]
  ------------------
 1814|  2.26k|		    NULL)) != 0) {
 1815|     25|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     25|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1816|     25|			goto out;
 1817|     25|		}
 1818|  2.23k|		oprincipals = key->cert->principals;
 1819|  2.23k|		key->cert->principals = recallocarray(key->cert->principals,
 1820|  2.23k|		    key->cert->nprincipals, key->cert->nprincipals + 1,
 1821|  2.23k|		    sizeof(*key->cert->principals));
 1822|  2.23k|		if (key->cert->principals == NULL) {
  ------------------
  |  Branch (1822:7): [True: 0, False: 2.23k]
  ------------------
 1823|      0|			free(principal);
 1824|      0|			key->cert->principals = oprincipals;
 1825|      0|			ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1826|      0|			goto out;
 1827|      0|		}
 1828|  2.23k|		key->cert->principals[key->cert->nprincipals++] = principal;
 1829|  2.23k|	}
 1830|       |
 1831|       |	/*
 1832|       |	 * Stash a copies of the critical options and extensions sections
 1833|       |	 * for later use.
 1834|       |	 */
 1835|    365|	if ((ret = sshbuf_putb(key->cert->critical, crit)) != 0 ||
  ------------------
  |  Branch (1835:6): [True: 0, False: 365]
  ------------------
 1836|    365|	    (exts != NULL &&
  ------------------
  |  Branch (1836:7): [True: 365, False: 0]
  ------------------
 1837|    365|	    (ret = sshbuf_putb(key->cert->extensions, exts)) != 0))
  ------------------
  |  Branch (1837:6): [True: 0, False: 365]
  ------------------
 1838|      0|		goto out;
 1839|       |
 1840|       |	/*
 1841|       |	 * Validate critical options and extensions sections format.
 1842|       |	 */
 1843|  2.17k|	while (sshbuf_len(crit) != 0) {
  ------------------
  |  Branch (1843:9): [True: 1.85k, False: 325]
  ------------------
 1844|  1.85k|		if ((ret = sshbuf_get_string_direct(crit, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1844:7): [True: 22, False: 1.82k]
  ------------------
 1845|  1.85k|		    (ret = sshbuf_get_string_direct(crit, NULL, NULL)) != 0) {
  ------------------
  |  Branch (1845:7): [True: 18, False: 1.81k]
  ------------------
 1846|     40|			sshbuf_reset(key->cert->critical);
 1847|     40|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     40|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1848|     40|			goto out;
 1849|     40|		}
 1850|  1.85k|	}
 1851|  1.49k|	while (exts != NULL && sshbuf_len(exts) != 0) {
  ------------------
  |  Branch (1851:9): [True: 1.49k, False: 0]
  |  Branch (1851:25): [True: 1.19k, False: 294]
  ------------------
 1852|  1.19k|		if ((ret = sshbuf_get_string_direct(exts, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1852:7): [True: 28, False: 1.17k]
  ------------------
 1853|  1.19k|		    (ret = sshbuf_get_string_direct(exts, NULL, NULL)) != 0) {
  ------------------
  |  Branch (1853:7): [True: 3, False: 1.16k]
  ------------------
 1854|     31|			sshbuf_reset(key->cert->extensions);
 1855|     31|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     31|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1856|     31|			goto out;
 1857|     31|		}
 1858|  1.19k|	}
 1859|       |
 1860|       |	/* Parse CA key and check signature */
 1861|    294|	if (sshkey_from_blob_internal(ca, &key->cert->signature_key, 0) != 0) {
  ------------------
  |  Branch (1861:6): [True: 43, False: 251]
  ------------------
 1862|     43|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|     43|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1863|     43|		goto out;
 1864|     43|	}
 1865|    251|	if (!sshkey_type_is_valid_ca(key->cert->signature_key->type)) {
  ------------------
  |  Branch (1865:6): [True: 0, False: 251]
  ------------------
 1866|      0|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|      0|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1867|      0|		goto out;
 1868|      0|	}
 1869|    251|	if ((ret = sshkey_verify(key->cert->signature_key, sig, slen,
  ------------------
  |  Branch (1869:6): [True: 251, False: 0]
  ------------------
 1870|    251|	    sshbuf_ptr(key->cert->certblob), signed_len, NULL, 0, NULL)) != 0)
 1871|    251|		goto out;
 1872|      0|	if ((ret = sshkey_get_sigtype(sig, slen,
  ------------------
  |  Branch (1872:6): [True: 0, False: 0]
  ------------------
 1873|      0|	    &key->cert->signature_type)) != 0)
 1874|      0|		goto out;
 1875|       |
 1876|       |	/* Success */
 1877|      0|	ret = 0;
 1878|    550| out:
 1879|    550|	sshbuf_free(ca);
 1880|    550|	sshbuf_free(crit);
 1881|    550|	sshbuf_free(exts);
 1882|    550|	sshbuf_free(principals);
 1883|    550|	free(sig);
 1884|    550|	return ret;
 1885|      0|}
sshkey.c:sshkey_type_is_valid_ca:
  404|    251|{
  405|    251|	const struct sshkey_impl *impl;
  406|       |
  407|    251|	if ((impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (407:6): [True: 0, False: 251]
  ------------------
  408|      0|		return 0;
  409|       |	/* All non-certificate types may act as CAs */
  410|    251|	return !impl->cert;
  411|    251|}

sshsig_verifyb:
  473|  2.53k|{
  474|  2.53k|	struct sshbuf *b = NULL;
  475|  2.53k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.53k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  476|  2.53k|	char *hashalg = NULL;
  477|       |
  478|  2.53k|	if (sig_details != NULL)
  ------------------
  |  Branch (478:6): [True: 2.53k, False: 0]
  ------------------
  479|  2.53k|		*sig_details = NULL;
  480|  2.53k|	if (sign_keyp != NULL)
  ------------------
  |  Branch (480:6): [True: 2.53k, False: 0]
  ------------------
  481|  2.53k|		*sign_keyp = NULL;
  482|  2.53k|	if ((r = sshsig_peek_hashalg(signature, &hashalg)) != 0)
  ------------------
  |  Branch (482:6): [True: 383, False: 2.15k]
  ------------------
  483|    383|		return r;
  484|  2.15k|	debug_f("signature made with hash \"%s\"", hashalg);
  ------------------
  |  |   98|  2.15k|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  485|  2.15k|	if ((r = hash_buffer(message, hashalg, &b)) != 0) {
  ------------------
  |  Branch (485:6): [True: 55, False: 2.10k]
  ------------------
  486|     55|		error_fr(r, "hash buffer");
  ------------------
  |  |  121|     55|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  487|     55|		goto out;
  488|     55|	}
  489|  2.10k|	if ((r = sshsig_wrap_verify(signature, hashalg, b, expect_namespace,
  ------------------
  |  Branch (489:6): [True: 2.09k, False: 1]
  ------------------
  490|  2.10k|	    sign_keyp, sig_details)) != 0)
  491|  2.09k|		goto out;
  492|       |	/* success */
  493|      1|	r = 0;
  494|  2.15k| out:
  495|  2.15k|	sshbuf_free(b);
  496|  2.15k|	free(hashalg);
  497|  2.15k|	return r;
  498|      1|}
sshsig.c:hash_buffer:
  402|  2.15k|{
  403|  2.15k|	char *hex, hash[SSH_DIGEST_MAX_LENGTH];
  404|  2.15k|	int alg, r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.15k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  405|  2.15k|	struct sshbuf *b = NULL;
  406|       |
  407|  2.15k|	*bp = NULL;
  408|  2.15k|	memset(hash, 0, sizeof(hash));
  409|       |
  410|  2.15k|	if ((r = sshsig_check_hashalg(hashalg)) != 0)
  ------------------
  |  Branch (410:6): [True: 55, False: 2.10k]
  ------------------
  411|     55|		return r;
  412|  2.10k|	if ((alg = ssh_digest_alg_by_name(hashalg)) == -1) {
  ------------------
  |  Branch (412:6): [True: 0, False: 2.10k]
  ------------------
  413|      0|		error_f("can't look up hash algorithm %s", hashalg);
  ------------------
  |  |  101|      0|#define error_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  414|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  415|      0|	}
  416|  2.10k|	if ((r = ssh_digest_buffer(alg, m, hash, sizeof(hash))) != 0) {
  ------------------
  |  Branch (416:6): [True: 0, False: 2.10k]
  ------------------
  417|      0|		error_fr(r, "ssh_digest_buffer");
  ------------------
  |  |  121|      0|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  418|      0|		return r;
  419|      0|	}
  420|  2.10k|	if ((hex = tohex(hash, ssh_digest_bytes(alg))) != NULL) {
  ------------------
  |  Branch (420:6): [True: 2.10k, False: 0]
  ------------------
  421|  2.10k|		debug3_f("final hash: %s", hex);
  ------------------
  |  |   96|  2.10k|#define debug3_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG3, NULL, __VA_ARGS__)
  ------------------
  422|  2.10k|		freezero(hex, strlen(hex));
  423|  2.10k|	}
  424|  2.10k|	if ((b = sshbuf_new()) == NULL) {
  ------------------
  |  Branch (424:6): [True: 0, False: 2.10k]
  ------------------
  425|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  426|      0|		goto out;
  427|      0|	}
  428|  2.10k|	if ((r = sshbuf_put(b, hash, ssh_digest_bytes(alg))) != 0) {
  ------------------
  |  Branch (428:6): [True: 0, False: 2.10k]
  ------------------
  429|      0|		error_fr(r, "sshbuf_put");
  ------------------
  |  |  121|      0|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  430|      0|		goto out;
  431|      0|	}
  432|  2.10k|	*bp = b;
  433|  2.10k|	b = NULL; /* transferred */
  434|       |	/* success */
  435|  2.10k|	r = 0;
  436|  2.10k| out:
  437|  2.10k|	sshbuf_free(b);
  438|  2.10k|	explicit_bzero(hash, sizeof(hash));
  439|  2.10k|	return r;
  440|  2.10k|}
sshsig.c:sshsig_check_hashalg:
  259|  2.15k|{
  260|  2.15k|	if (hashalg == NULL ||
  ------------------
  |  Branch (260:6): [True: 0, False: 2.15k]
  ------------------
  261|  2.15k|	    match_pattern_list(hashalg, HASHALG_ALLOWED, 0) == 1)
  ------------------
  |  |   46|  2.15k|#define HASHALG_ALLOWED		"sha256,sha512"
  ------------------
  |  Branch (261:6): [True: 2.10k, False: 55]
  ------------------
  262|  2.10k|		return 0;
  263|     55|	error_f("unsupported hash algorithm \"%.100s\"", hashalg);
  ------------------
  |  |  101|     55|#define error_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  264|     55|	return SSH_ERR_SIGN_ALG_UNSUPPORTED;
  ------------------
  |  |   82|     55|#define SSH_ERR_SIGN_ALG_UNSUPPORTED		-58
  ------------------
  265|  2.15k|}
sshsig.c:sshsig_peek_hashalg:
  269|  2.53k|{
  270|  2.53k|	struct sshbuf *buf = NULL;
  271|  2.53k|	char *hashalg = NULL;
  272|  2.53k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.53k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  273|       |
  274|  2.53k|	if (hashalgp != NULL)
  ------------------
  |  Branch (274:6): [True: 2.53k, False: 0]
  ------------------
  275|  2.53k|		*hashalgp = NULL;
  276|  2.53k|	if ((buf = sshbuf_fromb(signature)) == NULL)
  ------------------
  |  Branch (276:6): [True: 0, False: 2.53k]
  ------------------
  277|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  278|  2.53k|	if ((r = sshsig_parse_preamble(buf)) != 0)
  ------------------
  |  Branch (278:6): [True: 63, False: 2.47k]
  ------------------
  279|     63|		goto done;
  280|  2.47k|	if ((r = sshbuf_get_string_direct(buf, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (280:6): [True: 52, False: 2.42k]
  ------------------
  281|  2.47k|	    (r = sshbuf_get_string_direct(buf, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (281:6): [True: 55, False: 2.36k]
  ------------------
  282|  2.47k|	    (r = sshbuf_get_string(buf, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (282:6): [True: 71, False: 2.29k]
  ------------------
  283|  2.47k|	    (r = sshbuf_get_cstring(buf, &hashalg, NULL)) != 0 ||
  ------------------
  |  Branch (283:6): [True: 74, False: 2.22k]
  ------------------
  284|  2.47k|	    (r = sshbuf_get_string_direct(buf, NULL, NULL)) != 0) {
  ------------------
  |  Branch (284:6): [True: 68, False: 2.15k]
  ------------------
  285|    320|		error_fr(r, "parse signature object");
  ------------------
  |  |  121|    320|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  286|    320|		goto done;
  287|    320|	}
  288|       |
  289|       |	/* success */
  290|  2.15k|	r = 0;
  291|  2.15k|	*hashalgp = hashalg;
  292|  2.15k|	hashalg = NULL;
  293|  2.53k| done:
  294|  2.53k|	free(hashalg);
  295|  2.53k|	sshbuf_free(buf);
  296|  2.53k|	return r;
  297|  2.15k|}
sshsig.c:sshsig_wrap_verify:
  303|  2.10k|{
  304|  2.10k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.10k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  305|  2.10k|	struct sshbuf *buf = NULL, *toverify = NULL;
  306|  2.10k|	struct sshkey *key = NULL;
  307|  2.10k|	const u_char *sig;
  308|  2.10k|	char *got_namespace = NULL, *sigtype = NULL, *sig_hashalg = NULL;
  309|  2.10k|	size_t siglen;
  310|       |
  311|  2.10k|	debug_f("verify message length %zu", sshbuf_len(h_message));
  ------------------
  |  |   98|  2.10k|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  312|  2.10k|	if (sig_details != NULL)
  ------------------
  |  Branch (312:6): [True: 2.10k, False: 0]
  ------------------
  313|  2.10k|		*sig_details = NULL;
  314|  2.10k|	if (sign_keyp != NULL)
  ------------------
  |  Branch (314:6): [True: 2.10k, False: 0]
  ------------------
  315|  2.10k|		*sign_keyp = NULL;
  316|       |
  317|  2.10k|	if ((toverify = sshbuf_new()) == NULL) {
  ------------------
  |  Branch (317:6): [True: 0, False: 2.10k]
  ------------------
  318|      0|		error_f("sshbuf_new failed");
  ------------------
  |  |  101|      0|#define error_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  319|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  320|      0|		goto done;
  321|      0|	}
  322|  2.10k|	if ((r = sshbuf_put(toverify, MAGIC_PREAMBLE,
  ------------------
  |  |   39|  2.10k|#define MAGIC_PREAMBLE		"SSHSIG"
  ------------------
  |  Branch (322:6): [True: 0, False: 2.10k]
  ------------------
  323|  2.10k|	    MAGIC_PREAMBLE_LEN)) != 0 ||
  ------------------
  |  |   40|  2.10k|#define MAGIC_PREAMBLE_LEN	(sizeof(MAGIC_PREAMBLE) - 1)
  |  |  ------------------
  |  |  |  |   39|  2.10k|#define MAGIC_PREAMBLE		"SSHSIG"
  |  |  ------------------
  ------------------
  324|  2.10k|	    (r = sshbuf_put_cstring(toverify, expect_namespace)) != 0 ||
  ------------------
  |  Branch (324:6): [True: 0, False: 2.10k]
  ------------------
  325|  2.10k|	    (r = sshbuf_put_string(toverify, NULL, 0)) != 0 || /* reserved */
  ------------------
  |  Branch (325:6): [True: 0, False: 2.10k]
  ------------------
  326|  2.10k|	    (r = sshbuf_put_cstring(toverify, hashalg)) != 0 ||
  ------------------
  |  Branch (326:6): [True: 0, False: 2.10k]
  ------------------
  327|  2.10k|	    (r = sshbuf_put_stringb(toverify, h_message)) != 0) {
  ------------------
  |  Branch (327:6): [True: 0, False: 2.10k]
  ------------------
  328|      0|		error_fr(r, "assemble message to verify");
  ------------------
  |  |  121|      0|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  329|      0|		goto done;
  330|      0|	}
  331|       |
  332|  2.10k|	if ((r = sshsig_parse_preamble(signature)) != 0)
  ------------------
  |  Branch (332:6): [True: 0, False: 2.10k]
  ------------------
  333|      0|		goto done;
  334|       |
  335|  2.10k|	if ((r = sshkey_froms(signature, &key)) != 0 ||
  ------------------
  |  Branch (335:6): [True: 1.48k, False: 619]
  ------------------
  336|  2.10k|	    (r = sshbuf_get_cstring(signature, &got_namespace, NULL)) != 0 ||
  ------------------
  |  Branch (336:6): [True: 1, False: 618]
  ------------------
  337|  2.10k|	    (r = sshbuf_get_string(signature, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (337:6): [True: 0, False: 618]
  ------------------
  338|  2.10k|	    (r = sshbuf_get_cstring(signature, &sig_hashalg, NULL)) != 0 ||
  ------------------
  |  Branch (338:6): [True: 0, False: 618]
  ------------------
  339|  2.10k|	    (r = sshbuf_get_string_direct(signature, &sig, &siglen)) != 0) {
  ------------------
  |  Branch (339:6): [True: 0, False: 618]
  ------------------
  340|  1.48k|		error_fr(r, "parse signature object");
  ------------------
  |  |  121|  1.48k|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  341|  1.48k|		goto done;
  342|  1.48k|	}
  343|       |
  344|    618|	if (sshbuf_len(signature) != 0) {
  ------------------
  |  Branch (344:6): [True: 30, False: 588]
  ------------------
  345|     30|		error("Signature contains trailing data");
  ------------------
  |  |   90|     30|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  346|     30|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     30|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  347|     30|		goto done;
  348|     30|	}
  349|       |
  350|    588|	if (strcmp(expect_namespace, got_namespace) != 0) {
  ------------------
  |  Branch (350:6): [True: 62, False: 526]
  ------------------
  351|     62|		error("Couldn't verify signature: namespace does not match");
  ------------------
  |  |   90|     62|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  352|     62|		debug_f("expected namespace \"%s\" received \"%s\"",
  ------------------
  |  |   98|     62|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  353|     62|		    expect_namespace, got_namespace);
  354|     62|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|     62|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  355|     62|		goto done;
  356|     62|	}
  357|    526|	if (strcmp(hashalg, sig_hashalg) != 0) {
  ------------------
  |  Branch (357:6): [True: 0, False: 526]
  ------------------
  358|      0|		error("Couldn't verify signature: hash algorithm mismatch");
  ------------------
  |  |   90|      0|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  359|      0|		debug_f("expected algorithm \"%s\" received \"%s\"",
  ------------------
  |  |   98|      0|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  360|      0|		    hashalg, sig_hashalg);
  361|      0|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  362|      0|		goto done;
  363|      0|	}
  364|       |	/* Ensure that RSA keys use an acceptable signature algorithm */
  365|    526|	if (sshkey_type_plain(key->type) == KEY_RSA) {
  ------------------
  |  Branch (365:6): [True: 41, False: 485]
  ------------------
  366|     41|		if ((r = sshkey_get_sigtype(sig, siglen, &sigtype)) != 0) {
  ------------------
  |  Branch (366:7): [True: 2, False: 39]
  ------------------
  367|      2|			error_r(r, "Couldn't verify signature: unable to get "
  ------------------
  |  |  112|      2|#define error_r(r, ...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  368|      2|			    "signature type");
  369|      2|			goto done;
  370|      2|		}
  371|     39|		if (match_pattern_list(sigtype, RSA_SIGN_ALLOWED, 0) != 1) {
  ------------------
  |  |   44|     39|#define RSA_SIGN_ALLOWED	"rsa-sha2-512,rsa-sha2-256"
  ------------------
  |  Branch (371:7): [True: 3, False: 36]
  ------------------
  372|      3|			error("Couldn't verify signature: unsupported RSA "
  ------------------
  |  |   90|      3|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  373|      3|			    "signature algorithm %s", sigtype);
  374|      3|			r = SSH_ERR_SIGN_ALG_UNSUPPORTED;
  ------------------
  |  |   82|      3|#define SSH_ERR_SIGN_ALG_UNSUPPORTED		-58
  ------------------
  375|      3|			goto done;
  376|      3|		}
  377|     39|	}
  378|    521|	if ((r = sshkey_verify(key, sig, siglen, sshbuf_ptr(toverify),
  ------------------
  |  Branch (378:6): [True: 520, False: 1]
  ------------------
  379|    521|	    sshbuf_len(toverify), NULL, 0, sig_details)) != 0) {
  380|    520|		error_r(r, "Signature verification failed");
  ------------------
  |  |  112|    520|#define error_r(r, ...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  381|    520|		goto done;
  382|    520|	}
  383|       |
  384|       |	/* success */
  385|      1|	r = 0;
  386|      1|	if (sign_keyp != NULL) {
  ------------------
  |  Branch (386:6): [True: 1, False: 0]
  ------------------
  387|      1|		*sign_keyp = key;
  388|      1|		key = NULL; /* transferred */
  389|      1|	}
  390|  2.10k|done:
  391|  2.10k|	free(got_namespace);
  392|  2.10k|	free(sigtype);
  393|  2.10k|	free(sig_hashalg);
  394|  2.10k|	sshbuf_free(buf);
  395|  2.10k|	sshbuf_free(toverify);
  396|  2.10k|	sshkey_free(key);
  397|  2.10k|	return r;
  398|      1|}
sshsig.c:sshsig_parse_preamble:
  238|  4.63k|{
  239|  4.63k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  4.63k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  240|  4.63k|	uint32_t sversion;
  241|       |
  242|  4.63k|	if ((r = sshbuf_cmp(buf, 0, MAGIC_PREAMBLE, MAGIC_PREAMBLE_LEN)) != 0 ||
  ------------------
  |  |   39|  4.63k|#define MAGIC_PREAMBLE		"SSHSIG"
  ------------------
              	if ((r = sshbuf_cmp(buf, 0, MAGIC_PREAMBLE, MAGIC_PREAMBLE_LEN)) != 0 ||
  ------------------
  |  |   40|  4.63k|#define MAGIC_PREAMBLE_LEN	(sizeof(MAGIC_PREAMBLE) - 1)
  |  |  ------------------
  |  |  |  |   39|  4.63k|#define MAGIC_PREAMBLE		"SSHSIG"
  |  |  ------------------
  ------------------
  |  Branch (242:6): [True: 16, False: 4.62k]
  ------------------
  243|  4.63k|	    (r = sshbuf_consume(buf, (sizeof(MAGIC_PREAMBLE)-1))) != 0 ||
  ------------------
  |  |   39|  4.62k|#define MAGIC_PREAMBLE		"SSHSIG"
  ------------------
  |  Branch (243:6): [True: 0, False: 4.62k]
  ------------------
  244|  4.63k|	    (r = sshbuf_get_u32(buf, &sversion)) != 0) {
  ------------------
  |  Branch (244:6): [True: 4, False: 4.61k]
  ------------------
  245|     20|		error("Couldn't verify signature: invalid format");
  ------------------
  |  |   90|     20|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  246|     20|		return r;
  247|     20|	}
  248|       |
  249|  4.61k|	if (sversion > SIG_VERSION) {
  ------------------
  |  |   38|  4.61k|#define SIG_VERSION		0x01
  ------------------
  |  Branch (249:6): [True: 43, False: 4.57k]
  ------------------
  250|     43|		error("Signature version %lu is larger than supported "
  ------------------
  |  |   90|     43|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  251|     43|		    "version %u", (unsigned long)sversion, SIG_VERSION);
  252|     43|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     43|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  253|     43|	}
  254|  4.57k|	return 0;
  255|  4.61k|}

xcalloc:
   48|  2.10k|{
   49|  2.10k|	void *ptr;
   50|       |
   51|  2.10k|	if (size == 0 || nmemb == 0)
  ------------------
  |  Branch (51:6): [True: 0, False: 2.10k]
  |  Branch (51:19): [True: 0, False: 2.10k]
  ------------------
   52|      0|		fatal("xcalloc: zero size");
  ------------------
  |  |   91|      0|#define fatal(...)		sshfatal(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_FATAL, NULL, __VA_ARGS__)
  ------------------
   53|  2.10k|	if (SIZE_MAX / nmemb < size)
  ------------------
  |  Branch (53:6): [True: 0, False: 2.10k]
  ------------------
   54|      0|		fatal("xcalloc: nmemb * size > SIZE_MAX");
  ------------------
  |  |   91|      0|#define fatal(...)		sshfatal(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_FATAL, NULL, __VA_ARGS__)
  ------------------
   55|  2.10k|	ptr = calloc(nmemb, size);
   56|  2.10k|	if (ptr == NULL)
  ------------------
  |  Branch (56:6): [True: 0, False: 2.10k]
  ------------------
   57|      0|		fatal("xcalloc: out of memory (allocating %zu bytes)",
  ------------------
  |  |   91|      0|#define fatal(...)		sshfatal(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_FATAL, NULL, __VA_ARGS__)
  ------------------
   58|  2.10k|		    size * nmemb);
   59|  2.10k|	return ptr;
   60|  2.10k|}

xmss_set_params:
   54|    259|{
   55|    259|  if (k >= h || k < 2 || (h - k) % 2) {
  ------------------
  |  Branch (55:7): [True: 0, False: 259]
  |  Branch (55:17): [True: 0, False: 259]
  |  Branch (55:26): [True: 0, False: 259]
  ------------------
   56|      0|    fprintf(stderr, "For BDS traversal, H - K must be even, with H > K >= 2!\n");
   57|      0|    return 1;
   58|      0|  }
   59|    259|  params->h = h;
   60|    259|  params->n = n;
   61|    259|  params->k = k;
   62|    259|  wots_params wots_par;
   63|    259|  wots_set_params(&wots_par, n, w);
   64|    259|  params->wots_par = wots_par;
   65|    259|  return 0;
   66|    259|}

wots_set_params:
   39|    259|{
   40|    259|  params->n = n;
   41|    259|  params->w = w;
   42|    259|  params->log_w = wots_log2(params->w);
   43|    259|  params->len_1 = (CHAR_BIT * n) / params->log_w;
   44|    259|  params->len_2 = (wots_log2(params->len_1 * (w - 1)) / params->log_w) + 1;
   45|    259|  params->len = params->len_1 + params->len_2;
   46|    259|  params->keysize = params->len * params->n;
   47|    259|}
xmss_wots.c:wots_log2:
   26|    518|{
   27|    518|  int      b;
   28|       |
   29|  13.2k|  for (b = sizeof (v) * CHAR_BIT - 1; b >= 0; b--) {
  ------------------
  |  Branch (29:39): [True: 13.2k, False: 0]
  ------------------
   30|  13.2k|    if ((1U << b) & v) {
  ------------------
  |  Branch (30:9): [True: 518, False: 12.6k]
  ------------------
   31|    518|      return b;
   32|    518|    }
   33|  13.2k|  }
   34|      0|  return 0;
   35|    518|}

