ERR_load_ASN1_strings:
  344|      2|{
  345|      2|#ifndef OPENSSL_NO_ERR
  346|      2|    if (ERR_func_error_string(ASN1_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (346:9): [True: 2, False: 0]
  ------------------
  347|      2|        ERR_load_strings_const(ASN1_str_functs);
  348|      2|        ERR_load_strings_const(ASN1_str_reasons);
  349|      2|    }
  350|      2|#endif
  351|      2|    return 1;
  352|      2|}

ERR_load_ASYNC_strings:
   43|      2|{
   44|      2|#ifndef OPENSSL_NO_ERR
   45|      2|    if (ERR_func_error_string(ASYNC_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (45:9): [True: 2, False: 0]
  ------------------
   46|      2|        ERR_load_strings_const(ASYNC_str_functs);
   47|      2|        ERR_load_strings_const(ASYNC_str_reasons);
   48|      2|    }
   49|      2|#endif
   50|      2|    return 1;
   51|      2|}

bio_sock_cleanup_int:
  152|      2|{
  153|       |# ifdef OPENSSL_SYS_WINDOWS
  154|       |    if (wsa_init_done) {
  155|       |        wsa_init_done = 0;
  156|       |        WSACleanup();
  157|       |    }
  158|       |# endif
  159|      2|}

ERR_load_BIO_strings:
  137|      2|{
  138|      2|#ifndef OPENSSL_NO_ERR
  139|      2|    if (ERR_func_error_string(BIO_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (139:9): [True: 2, False: 0]
  ------------------
  140|      2|        ERR_load_strings_const(BIO_str_functs);
  141|      2|        ERR_load_strings_const(BIO_str_reasons);
  142|      2|    }
  143|      2|#endif
  144|      2|    return 1;
  145|      2|}

bio_cleanup:
  778|      2|{
  779|      2|#ifndef OPENSSL_NO_SOCK
  780|      2|    bio_sock_cleanup_int();
  781|      2|    CRYPTO_THREAD_lock_free(bio_lookup_lock);
  782|      2|    bio_lookup_lock = NULL;
  783|      2|#endif
  784|      2|    CRYPTO_THREAD_lock_free(bio_type_lock);
  785|      2|    bio_type_lock = NULL;
  786|      2|}

bn_mul_add_words:
  113|  1.54M|{
  114|  1.54M|    BN_ULONG c1 = 0;
  ------------------
  |  |   31|  1.54M|#  define BN_ULONG        unsigned long
  ------------------
  115|       |
  116|  1.54M|    if (num <= 0)
  ------------------
  |  Branch (116:9): [True: 0, False: 1.54M]
  ------------------
  117|      0|        return c1;
  118|       |
  119|  19.1M|    while (num & ~3) {
  ------------------
  |  Branch (119:12): [True: 17.6M, False: 1.54M]
  ------------------
  120|  17.6M|        mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   75|  17.6M|# define mul_add(r,a,word,carry) do {   \
  |  |   76|  17.6M|        register BN_ULONG high,low;     \
  |  |   77|  17.6M|        asm ("mulq %3"                  \
  |  |   78|  17.6M|                : "=a"(low),"=d"(high)  \
  |  |   79|  17.6M|                : "a"(word),"m"(a)      \
  |  |   80|  17.6M|                : "cc");                \
  |  |   81|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   82|  17.6M|                : "+r"(carry),"+d"(high)\
  |  |   83|  17.6M|                : "a"(low),"g"(0)       \
  |  |   84|  17.6M|                : "cc");                \
  |  |   85|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   86|  17.6M|                : "+m"(r),"+d"(high)    \
  |  |   87|  17.6M|                : "r"(carry),"g"(0)     \
  |  |   88|  17.6M|                : "cc");                \
  |  |   89|  17.6M|        carry=high;                     \
  |  |   90|  17.6M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (90:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  121|  17.6M|        mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   75|  17.6M|# define mul_add(r,a,word,carry) do {   \
  |  |   76|  17.6M|        register BN_ULONG high,low;     \
  |  |   77|  17.6M|        asm ("mulq %3"                  \
  |  |   78|  17.6M|                : "=a"(low),"=d"(high)  \
  |  |   79|  17.6M|                : "a"(word),"m"(a)      \
  |  |   80|  17.6M|                : "cc");                \
  |  |   81|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   82|  17.6M|                : "+r"(carry),"+d"(high)\
  |  |   83|  17.6M|                : "a"(low),"g"(0)       \
  |  |   84|  17.6M|                : "cc");                \
  |  |   85|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   86|  17.6M|                : "+m"(r),"+d"(high)    \
  |  |   87|  17.6M|                : "r"(carry),"g"(0)     \
  |  |   88|  17.6M|                : "cc");                \
  |  |   89|  17.6M|        carry=high;                     \
  |  |   90|  17.6M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (90:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  122|  17.6M|        mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   75|  17.6M|# define mul_add(r,a,word,carry) do {   \
  |  |   76|  17.6M|        register BN_ULONG high,low;     \
  |  |   77|  17.6M|        asm ("mulq %3"                  \
  |  |   78|  17.6M|                : "=a"(low),"=d"(high)  \
  |  |   79|  17.6M|                : "a"(word),"m"(a)      \
  |  |   80|  17.6M|                : "cc");                \
  |  |   81|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   82|  17.6M|                : "+r"(carry),"+d"(high)\
  |  |   83|  17.6M|                : "a"(low),"g"(0)       \
  |  |   84|  17.6M|                : "cc");                \
  |  |   85|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   86|  17.6M|                : "+m"(r),"+d"(high)    \
  |  |   87|  17.6M|                : "r"(carry),"g"(0)     \
  |  |   88|  17.6M|                : "cc");                \
  |  |   89|  17.6M|        carry=high;                     \
  |  |   90|  17.6M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (90:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  123|  17.6M|        mul_add(rp[3], ap[3], w, c1);
  ------------------
  |  |   75|  17.6M|# define mul_add(r,a,word,carry) do {   \
  |  |   76|  17.6M|        register BN_ULONG high,low;     \
  |  |   77|  17.6M|        asm ("mulq %3"                  \
  |  |   78|  17.6M|                : "=a"(low),"=d"(high)  \
  |  |   79|  17.6M|                : "a"(word),"m"(a)      \
  |  |   80|  17.6M|                : "cc");                \
  |  |   81|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   82|  17.6M|                : "+r"(carry),"+d"(high)\
  |  |   83|  17.6M|                : "a"(low),"g"(0)       \
  |  |   84|  17.6M|                : "cc");                \
  |  |   85|  17.6M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   86|  17.6M|                : "+m"(r),"+d"(high)    \
  |  |   87|  17.6M|                : "r"(carry),"g"(0)     \
  |  |   88|  17.6M|                : "cc");                \
  |  |   89|  17.6M|        carry=high;                     \
  |  |   90|  17.6M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (90:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  124|  17.6M|        ap += 4;
  125|  17.6M|        rp += 4;
  126|  17.6M|        num -= 4;
  127|  17.6M|    }
  128|  1.54M|    if (num) {
  ------------------
  |  Branch (128:9): [True: 1.18M, False: 360k]
  ------------------
  129|  1.18M|        mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   75|  1.18M|# define mul_add(r,a,word,carry) do {   \
  |  |   76|  1.18M|        register BN_ULONG high,low;     \
  |  |   77|  1.18M|        asm ("mulq %3"                  \
  |  |   78|  1.18M|                : "=a"(low),"=d"(high)  \
  |  |   79|  1.18M|                : "a"(word),"m"(a)      \
  |  |   80|  1.18M|                : "cc");                \
  |  |   81|  1.18M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   82|  1.18M|                : "+r"(carry),"+d"(high)\
  |  |   83|  1.18M|                : "a"(low),"g"(0)       \
  |  |   84|  1.18M|                : "cc");                \
  |  |   85|  1.18M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   86|  1.18M|                : "+m"(r),"+d"(high)    \
  |  |   87|  1.18M|                : "r"(carry),"g"(0)     \
  |  |   88|  1.18M|                : "cc");                \
  |  |   89|  1.18M|        carry=high;                     \
  |  |   90|  1.18M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (90:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  130|  1.18M|        if (--num == 0)
  ------------------
  |  Branch (130:13): [True: 516k, False: 672k]
  ------------------
  131|   516k|            return c1;
  132|   672k|        mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   75|   672k|# define mul_add(r,a,word,carry) do {   \
  |  |   76|   672k|        register BN_ULONG high,low;     \
  |  |   77|   672k|        asm ("mulq %3"                  \
  |  |   78|   672k|                : "=a"(low),"=d"(high)  \
  |  |   79|   672k|                : "a"(word),"m"(a)      \
  |  |   80|   672k|                : "cc");                \
  |  |   81|   672k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   82|   672k|                : "+r"(carry),"+d"(high)\
  |  |   83|   672k|                : "a"(low),"g"(0)       \
  |  |   84|   672k|                : "cc");                \
  |  |   85|   672k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   86|   672k|                : "+m"(r),"+d"(high)    \
  |  |   87|   672k|                : "r"(carry),"g"(0)     \
  |  |   88|   672k|                : "cc");                \
  |  |   89|   672k|        carry=high;                     \
  |  |   90|   672k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (90:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  133|   672k|        if (--num == 0)
  ------------------
  |  Branch (133:13): [True: 337k, False: 334k]
  ------------------
  134|   337k|            return c1;
  135|   334k|        mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   75|   334k|# define mul_add(r,a,word,carry) do {   \
  |  |   76|   334k|        register BN_ULONG high,low;     \
  |  |   77|   334k|        asm ("mulq %3"                  \
  |  |   78|   334k|                : "=a"(low),"=d"(high)  \
  |  |   79|   334k|                : "a"(word),"m"(a)      \
  |  |   80|   334k|                : "cc");                \
  |  |   81|   334k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   82|   334k|                : "+r"(carry),"+d"(high)\
  |  |   83|   334k|                : "a"(low),"g"(0)       \
  |  |   84|   334k|                : "cc");                \
  |  |   85|   334k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   86|   334k|                : "+m"(r),"+d"(high)    \
  |  |   87|   334k|                : "r"(carry),"g"(0)     \
  |  |   88|   334k|                : "cc");                \
  |  |   89|   334k|        carry=high;                     \
  |  |   90|   334k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (90:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  136|   334k|        return c1;
  137|   672k|    }
  138|       |
  139|   360k|    return c1;
  140|  1.54M|}
bn_mul_words:
  143|  1.50M|{
  144|  1.50M|    BN_ULONG c1 = 0;
  ------------------
  |  |   31|  1.50M|#  define BN_ULONG        unsigned long
  ------------------
  145|       |
  146|  1.50M|    if (num <= 0)
  ------------------
  |  Branch (146:9): [True: 0, False: 1.50M]
  ------------------
  147|      0|        return c1;
  148|       |
  149|  25.0M|    while (num & ~3) {
  ------------------
  |  Branch (149:12): [True: 23.5M, False: 1.50M]
  ------------------
  150|  23.5M|        mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   92|  23.5M|# define mul(r,a,word,carry) do {       \
  |  |   93|  23.5M|        register BN_ULONG high,low;     \
  |  |   94|  23.5M|        asm ("mulq %3"                  \
  |  |   95|  23.5M|                : "=a"(low),"=d"(high)  \
  |  |   96|  23.5M|                : "a"(word),"g"(a)      \
  |  |   97|  23.5M|                : "cc");                \
  |  |   98|  23.5M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   99|  23.5M|                : "+r"(carry),"+d"(high)\
  |  |  100|  23.5M|                : "a"(low),"g"(0)       \
  |  |  101|  23.5M|                : "cc");                \
  |  |  102|  23.5M|        (r)=carry, carry=high;          \
  |  |  103|  23.5M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (103:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  151|  23.5M|        mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   92|  23.5M|# define mul(r,a,word,carry) do {       \
  |  |   93|  23.5M|        register BN_ULONG high,low;     \
  |  |   94|  23.5M|        asm ("mulq %3"                  \
  |  |   95|  23.5M|                : "=a"(low),"=d"(high)  \
  |  |   96|  23.5M|                : "a"(word),"g"(a)      \
  |  |   97|  23.5M|                : "cc");                \
  |  |   98|  23.5M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   99|  23.5M|                : "+r"(carry),"+d"(high)\
  |  |  100|  23.5M|                : "a"(low),"g"(0)       \
  |  |  101|  23.5M|                : "cc");                \
  |  |  102|  23.5M|        (r)=carry, carry=high;          \
  |  |  103|  23.5M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (103:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  152|  23.5M|        mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   92|  23.5M|# define mul(r,a,word,carry) do {       \
  |  |   93|  23.5M|        register BN_ULONG high,low;     \
  |  |   94|  23.5M|        asm ("mulq %3"                  \
  |  |   95|  23.5M|                : "=a"(low),"=d"(high)  \
  |  |   96|  23.5M|                : "a"(word),"g"(a)      \
  |  |   97|  23.5M|                : "cc");                \
  |  |   98|  23.5M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   99|  23.5M|                : "+r"(carry),"+d"(high)\
  |  |  100|  23.5M|                : "a"(low),"g"(0)       \
  |  |  101|  23.5M|                : "cc");                \
  |  |  102|  23.5M|        (r)=carry, carry=high;          \
  |  |  103|  23.5M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (103:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|  23.5M|        mul(rp[3], ap[3], w, c1);
  ------------------
  |  |   92|  23.5M|# define mul(r,a,word,carry) do {       \
  |  |   93|  23.5M|        register BN_ULONG high,low;     \
  |  |   94|  23.5M|        asm ("mulq %3"                  \
  |  |   95|  23.5M|                : "=a"(low),"=d"(high)  \
  |  |   96|  23.5M|                : "a"(word),"g"(a)      \
  |  |   97|  23.5M|                : "cc");                \
  |  |   98|  23.5M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   99|  23.5M|                : "+r"(carry),"+d"(high)\
  |  |  100|  23.5M|                : "a"(low),"g"(0)       \
  |  |  101|  23.5M|                : "cc");                \
  |  |  102|  23.5M|        (r)=carry, carry=high;          \
  |  |  103|  23.5M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (103:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  154|  23.5M|        ap += 4;
  155|  23.5M|        rp += 4;
  156|  23.5M|        num -= 4;
  157|  23.5M|    }
  158|  1.50M|    if (num) {
  ------------------
  |  Branch (158:9): [True: 1.13M, False: 368k]
  ------------------
  159|  1.13M|        mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   92|  1.13M|# define mul(r,a,word,carry) do {       \
  |  |   93|  1.13M|        register BN_ULONG high,low;     \
  |  |   94|  1.13M|        asm ("mulq %3"                  \
  |  |   95|  1.13M|                : "=a"(low),"=d"(high)  \
  |  |   96|  1.13M|                : "a"(word),"g"(a)      \
  |  |   97|  1.13M|                : "cc");                \
  |  |   98|  1.13M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   99|  1.13M|                : "+r"(carry),"+d"(high)\
  |  |  100|  1.13M|                : "a"(low),"g"(0)       \
  |  |  101|  1.13M|                : "cc");                \
  |  |  102|  1.13M|        (r)=carry, carry=high;          \
  |  |  103|  1.13M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (103:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  160|  1.13M|        if (--num == 0)
  ------------------
  |  Branch (160:13): [True: 796k, False: 343k]
  ------------------
  161|   796k|            return c1;
  162|   343k|        mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   92|   343k|# define mul(r,a,word,carry) do {       \
  |  |   93|   343k|        register BN_ULONG high,low;     \
  |  |   94|   343k|        asm ("mulq %3"                  \
  |  |   95|   343k|                : "=a"(low),"=d"(high)  \
  |  |   96|   343k|                : "a"(word),"g"(a)      \
  |  |   97|   343k|                : "cc");                \
  |  |   98|   343k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   99|   343k|                : "+r"(carry),"+d"(high)\
  |  |  100|   343k|                : "a"(low),"g"(0)       \
  |  |  101|   343k|                : "cc");                \
  |  |  102|   343k|        (r)=carry, carry=high;          \
  |  |  103|   343k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (103:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  163|   343k|        if (--num == 0)
  ------------------
  |  Branch (163:13): [True: 181k, False: 161k]
  ------------------
  164|   181k|            return c1;
  165|   161k|        mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   92|   161k|# define mul(r,a,word,carry) do {       \
  |  |   93|   161k|        register BN_ULONG high,low;     \
  |  |   94|   161k|        asm ("mulq %3"                  \
  |  |   95|   161k|                : "=a"(low),"=d"(high)  \
  |  |   96|   161k|                : "a"(word),"g"(a)      \
  |  |   97|   161k|                : "cc");                \
  |  |   98|   161k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   99|   161k|                : "+r"(carry),"+d"(high)\
  |  |  100|   161k|                : "a"(low),"g"(0)       \
  |  |  101|   161k|                : "cc");                \
  |  |  102|   161k|        (r)=carry, carry=high;          \
  |  |  103|   161k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (103:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  166|   161k|    }
  167|   530k|    return c1;
  168|  1.50M|}
bn_sqr_words:
  171|   344k|{
  172|   344k|    if (n <= 0)
  ------------------
  |  Branch (172:9): [True: 0, False: 344k]
  ------------------
  173|      0|        return;
  174|       |
  175|   640k|    while (n & ~3) {
  ------------------
  |  Branch (175:12): [True: 295k, False: 344k]
  ------------------
  176|   295k|        sqr(r[0], r[1], a[0]);
  ------------------
  |  |  106|   295k|        asm ("mulq %2"                  \
  |  |  107|   295k|                : "=a"(r0),"=d"(r1)     \
  |  |  108|   295k|                : "a"(a)                \
  |  |  109|   295k|                : "cc");
  ------------------
  177|   295k|        sqr(r[2], r[3], a[1]);
  ------------------
  |  |  106|   295k|        asm ("mulq %2"                  \
  |  |  107|   295k|                : "=a"(r0),"=d"(r1)     \
  |  |  108|   295k|                : "a"(a)                \
  |  |  109|   295k|                : "cc");
  ------------------
  178|   295k|        sqr(r[4], r[5], a[2]);
  ------------------
  |  |  106|   295k|        asm ("mulq %2"                  \
  |  |  107|   295k|                : "=a"(r0),"=d"(r1)     \
  |  |  108|   295k|                : "a"(a)                \
  |  |  109|   295k|                : "cc");
  ------------------
  179|   295k|        sqr(r[6], r[7], a[3]);
  ------------------
  |  |  106|   295k|        asm ("mulq %2"                  \
  |  |  107|   295k|                : "=a"(r0),"=d"(r1)     \
  |  |  108|   295k|                : "a"(a)                \
  |  |  109|   295k|                : "cc");
  ------------------
  180|   295k|        a += 4;
  181|   295k|        r += 8;
  182|   295k|        n -= 4;
  183|   295k|    }
  184|   344k|    if (n) {
  ------------------
  |  Branch (184:9): [True: 341k, False: 2.69k]
  ------------------
  185|   341k|        sqr(r[0], r[1], a[0]);
  ------------------
  |  |  106|   341k|        asm ("mulq %2"                  \
  |  |  107|   341k|                : "=a"(r0),"=d"(r1)     \
  |  |  108|   341k|                : "a"(a)                \
  |  |  109|   341k|                : "cc");
  ------------------
  186|   341k|        if (--n == 0)
  ------------------
  |  Branch (186:13): [True: 323k, False: 18.1k]
  ------------------
  187|   323k|            return;
  188|  18.1k|        sqr(r[2], r[3], a[1]);
  ------------------
  |  |  106|  18.1k|        asm ("mulq %2"                  \
  |  |  107|  18.1k|                : "=a"(r0),"=d"(r1)     \
  |  |  108|  18.1k|                : "a"(a)                \
  |  |  109|  18.1k|                : "cc");
  ------------------
  189|  18.1k|        if (--n == 0)
  ------------------
  |  Branch (189:13): [True: 10.4k, False: 7.72k]
  ------------------
  190|  10.4k|            return;
  191|  7.72k|        sqr(r[4], r[5], a[2]);
  ------------------
  |  |  106|  7.72k|        asm ("mulq %2"                  \
  |  |  107|  7.72k|                : "=a"(r0),"=d"(r1)     \
  |  |  108|  7.72k|                : "a"(a)                \
  |  |  109|  7.72k|                : "cc");
  ------------------
  192|  7.72k|    }
  193|   344k|}
bn_div_words:
  196|  1.17M|{
  197|  1.17M|    BN_ULONG ret, waste;
  ------------------
  |  |   31|  1.17M|#  define BN_ULONG        unsigned long
  ------------------
  198|       |
  199|  1.17M| asm("divq      %4":"=a"(ret), "=d"(waste)
  200|  1.17M| :     "a"(l), "d"(h), "r"(d)
  201|  1.17M| :     "cc");
  202|       |
  203|  1.17M|    return ret;
  204|  1.17M|}
bn_add_words:
  208|  3.69M|{
  209|  3.69M|    BN_ULONG ret;
  ------------------
  |  |   31|  3.69M|#  define BN_ULONG        unsigned long
  ------------------
  210|  3.69M|    size_t i = 0;
  211|       |
  212|  3.69M|    if (n <= 0)
  ------------------
  |  Branch (212:9): [True: 1.35k, False: 3.69M]
  ------------------
  213|  1.35k|        return 0;
  214|       |
  215|  3.69M|    asm volatile ("       subq    %0,%0           \n" /* clear carry */
  216|  3.69M|                  "       jmp     1f              \n"
  217|  3.69M|                  ".p2align 4                     \n"
  218|  3.69M|                  "1:     movq    (%4,%2,8),%0    \n"
  219|  3.69M|                  "       adcq    (%5,%2,8),%0    \n"
  220|  3.69M|                  "       movq    %0,(%3,%2,8)    \n"
  221|  3.69M|                  "       lea     1(%2),%2        \n"
  222|  3.69M|                  "       dec     %1              \n"
  223|  3.69M|                  "       jnz     1b              \n"
  224|  3.69M|                  "       sbbq    %0,%0           \n"
  225|  3.69M|                  :"=&r" (ret), "+c"(n), "+r"(i)
  226|  3.69M|                  :"r"(rp), "r"(ap), "r"(bp)
  227|  3.69M|                  :"cc", "memory");
  228|       |
  229|  3.69M|    return ret & 1;
  230|  3.69M|}
bn_sub_words:
  235|  3.30M|{
  236|  3.30M|    BN_ULONG ret;
  ------------------
  |  |   31|  3.30M|#  define BN_ULONG        unsigned long
  ------------------
  237|  3.30M|    size_t i = 0;
  238|       |
  239|  3.30M|    if (n <= 0)
  ------------------
  |  Branch (239:9): [True: 5.28k, False: 3.29M]
  ------------------
  240|  5.28k|        return 0;
  241|       |
  242|  3.29M|    asm volatile ("       subq    %0,%0           \n" /* clear borrow */
  243|  3.29M|                  "       jmp     1f              \n"
  244|  3.29M|                  ".p2align 4                     \n"
  245|  3.29M|                  "1:     movq    (%4,%2,8),%0    \n"
  246|  3.29M|                  "       sbbq    (%5,%2,8),%0    \n"
  247|  3.29M|                  "       movq    %0,(%3,%2,8)    \n"
  248|  3.29M|                  "       lea     1(%2),%2        \n"
  249|  3.29M|                  "       dec     %1              \n"
  250|  3.29M|                  "       jnz     1b              \n"
  251|  3.29M|                  "       sbbq    %0,%0           \n"
  252|  3.29M|                  :"=&r" (ret), "+c"(n), "+r"(i)
  253|  3.29M|                  :"r"(rp), "r"(ap), "r"(bp)
  254|  3.29M|                  :"cc", "memory");
  255|       |
  256|  3.29M|    return ret & 1;
  257|  3.30M|}
bn_mul_comba8:
  395|  1.33M|{
  396|  1.33M|    BN_ULONG c1, c2, c3;
  ------------------
  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  ------------------
  397|       |
  398|  1.33M|    c1 = 0;
  399|  1.33M|    c2 = 0;
  400|  1.33M|    c3 = 0;
  401|  1.33M|    mul_add_c(a[0], b[0], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  402|  1.33M|    r[0] = c1;
  403|  1.33M|    c1 = 0;
  404|  1.33M|    mul_add_c(a[0], b[1], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  405|  1.33M|    mul_add_c(a[1], b[0], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  406|  1.33M|    r[1] = c2;
  407|  1.33M|    c2 = 0;
  408|  1.33M|    mul_add_c(a[2], b[0], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  409|  1.33M|    mul_add_c(a[1], b[1], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  410|  1.33M|    mul_add_c(a[0], b[2], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  411|  1.33M|    r[2] = c3;
  412|  1.33M|    c3 = 0;
  413|  1.33M|    mul_add_c(a[0], b[3], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  414|  1.33M|    mul_add_c(a[1], b[2], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  415|  1.33M|    mul_add_c(a[2], b[1], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  416|  1.33M|    mul_add_c(a[3], b[0], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  417|  1.33M|    r[3] = c1;
  418|  1.33M|    c1 = 0;
  419|  1.33M|    mul_add_c(a[4], b[0], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  420|  1.33M|    mul_add_c(a[3], b[1], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  421|  1.33M|    mul_add_c(a[2], b[2], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  422|  1.33M|    mul_add_c(a[1], b[3], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  423|  1.33M|    mul_add_c(a[0], b[4], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  424|  1.33M|    r[4] = c2;
  425|  1.33M|    c2 = 0;
  426|  1.33M|    mul_add_c(a[0], b[5], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  427|  1.33M|    mul_add_c(a[1], b[4], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  428|  1.33M|    mul_add_c(a[2], b[3], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  429|  1.33M|    mul_add_c(a[3], b[2], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  430|  1.33M|    mul_add_c(a[4], b[1], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  431|  1.33M|    mul_add_c(a[5], b[0], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  432|  1.33M|    r[5] = c3;
  433|  1.33M|    c3 = 0;
  434|  1.33M|    mul_add_c(a[6], b[0], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  435|  1.33M|    mul_add_c(a[5], b[1], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  436|  1.33M|    mul_add_c(a[4], b[2], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  437|  1.33M|    mul_add_c(a[3], b[3], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  438|  1.33M|    mul_add_c(a[2], b[4], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  439|  1.33M|    mul_add_c(a[1], b[5], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  440|  1.33M|    mul_add_c(a[0], b[6], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  441|  1.33M|    r[6] = c1;
  442|  1.33M|    c1 = 0;
  443|  1.33M|    mul_add_c(a[0], b[7], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  444|  1.33M|    mul_add_c(a[1], b[6], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  445|  1.33M|    mul_add_c(a[2], b[5], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  446|  1.33M|    mul_add_c(a[3], b[4], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  447|  1.33M|    mul_add_c(a[4], b[3], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  448|  1.33M|    mul_add_c(a[5], b[2], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  449|  1.33M|    mul_add_c(a[6], b[1], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  450|  1.33M|    mul_add_c(a[7], b[0], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  451|  1.33M|    r[7] = c2;
  452|  1.33M|    c2 = 0;
  453|  1.33M|    mul_add_c(a[7], b[1], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  454|  1.33M|    mul_add_c(a[6], b[2], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  455|  1.33M|    mul_add_c(a[5], b[3], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  456|  1.33M|    mul_add_c(a[4], b[4], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  457|  1.33M|    mul_add_c(a[3], b[5], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  458|  1.33M|    mul_add_c(a[2], b[6], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  459|  1.33M|    mul_add_c(a[1], b[7], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  460|  1.33M|    r[8] = c3;
  461|  1.33M|    c3 = 0;
  462|  1.33M|    mul_add_c(a[2], b[7], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  463|  1.33M|    mul_add_c(a[3], b[6], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  464|  1.33M|    mul_add_c(a[4], b[5], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  465|  1.33M|    mul_add_c(a[5], b[4], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  466|  1.33M|    mul_add_c(a[6], b[3], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  467|  1.33M|    mul_add_c(a[7], b[2], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  468|  1.33M|    r[9] = c1;
  469|  1.33M|    c1 = 0;
  470|  1.33M|    mul_add_c(a[7], b[3], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  471|  1.33M|    mul_add_c(a[6], b[4], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  472|  1.33M|    mul_add_c(a[5], b[5], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  473|  1.33M|    mul_add_c(a[4], b[6], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  474|  1.33M|    mul_add_c(a[3], b[7], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  475|  1.33M|    r[10] = c2;
  476|  1.33M|    c2 = 0;
  477|  1.33M|    mul_add_c(a[4], b[7], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  478|  1.33M|    mul_add_c(a[5], b[6], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  479|  1.33M|    mul_add_c(a[6], b[5], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  480|  1.33M|    mul_add_c(a[7], b[4], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  481|  1.33M|    r[11] = c3;
  482|  1.33M|    c3 = 0;
  483|  1.33M|    mul_add_c(a[7], b[5], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  484|  1.33M|    mul_add_c(a[6], b[6], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  485|  1.33M|    mul_add_c(a[5], b[7], c1, c2, c3);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  486|  1.33M|    r[12] = c1;
  487|  1.33M|    c1 = 0;
  488|  1.33M|    mul_add_c(a[6], b[7], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  489|  1.33M|    mul_add_c(a[7], b[6], c2, c3, c1);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  490|  1.33M|    r[13] = c2;
  491|  1.33M|    c2 = 0;
  492|  1.33M|    mul_add_c(a[7], b[7], c3, c1, c2);
  ------------------
  |  |  350|  1.33M|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  351|  1.33M|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.33M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  352|  1.33M|        asm ("mulq %3"                  \
  |  |  353|  1.33M|                : "=a"(t1),"=d"(t2)     \
  |  |  354|  1.33M|                : "a"(a),"m"(b)         \
  |  |  355|  1.33M|                : "cc");                \
  |  |  356|  1.33M|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  357|  1.33M|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  358|  1.33M|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  359|  1.33M|                : "cc");                                \
  |  |  360|  1.33M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (360:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  493|  1.33M|    r[14] = c3;
  494|  1.33M|    r[15] = c1;
  495|  1.33M|}
bn_sqr_comba8:
  537|  70.5k|{
  538|  70.5k|    BN_ULONG c1, c2, c3;
  ------------------
  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  ------------------
  539|       |
  540|  70.5k|    c1 = 0;
  541|  70.5k|    c2 = 0;
  542|  70.5k|    c3 = 0;
  543|  70.5k|    sqr_add_c(a, 0, c1, c2, c3);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  544|  70.5k|    r[0] = c1;
  545|  70.5k|    c1 = 0;
  546|  70.5k|    sqr_add_c2(a, 1, 0, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  547|  70.5k|    r[1] = c2;
  548|  70.5k|    c2 = 0;
  549|  70.5k|    sqr_add_c(a, 1, c3, c1, c2);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  550|  70.5k|    sqr_add_c2(a, 2, 0, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  551|  70.5k|    r[2] = c3;
  552|  70.5k|    c3 = 0;
  553|  70.5k|    sqr_add_c2(a, 3, 0, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  554|  70.5k|    sqr_add_c2(a, 2, 1, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  555|  70.5k|    r[3] = c1;
  556|  70.5k|    c1 = 0;
  557|  70.5k|    sqr_add_c(a, 2, c2, c3, c1);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  558|  70.5k|    sqr_add_c2(a, 3, 1, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  559|  70.5k|    sqr_add_c2(a, 4, 0, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  560|  70.5k|    r[4] = c2;
  561|  70.5k|    c2 = 0;
  562|  70.5k|    sqr_add_c2(a, 5, 0, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  563|  70.5k|    sqr_add_c2(a, 4, 1, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  564|  70.5k|    sqr_add_c2(a, 3, 2, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  565|  70.5k|    r[5] = c3;
  566|  70.5k|    c3 = 0;
  567|  70.5k|    sqr_add_c(a, 3, c1, c2, c3);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  568|  70.5k|    sqr_add_c2(a, 4, 2, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  569|  70.5k|    sqr_add_c2(a, 5, 1, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  570|  70.5k|    sqr_add_c2(a, 6, 0, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  571|  70.5k|    r[6] = c1;
  572|  70.5k|    c1 = 0;
  573|  70.5k|    sqr_add_c2(a, 7, 0, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  574|  70.5k|    sqr_add_c2(a, 6, 1, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  575|  70.5k|    sqr_add_c2(a, 5, 2, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  576|  70.5k|    sqr_add_c2(a, 4, 3, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  577|  70.5k|    r[7] = c2;
  578|  70.5k|    c2 = 0;
  579|  70.5k|    sqr_add_c(a, 4, c3, c1, c2);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  580|  70.5k|    sqr_add_c2(a, 5, 3, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  581|  70.5k|    sqr_add_c2(a, 6, 2, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  582|  70.5k|    sqr_add_c2(a, 7, 1, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  583|  70.5k|    r[8] = c3;
  584|  70.5k|    c3 = 0;
  585|  70.5k|    sqr_add_c2(a, 7, 2, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  586|  70.5k|    sqr_add_c2(a, 6, 3, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  587|  70.5k|    sqr_add_c2(a, 5, 4, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  588|  70.5k|    r[9] = c1;
  589|  70.5k|    c1 = 0;
  590|  70.5k|    sqr_add_c(a, 5, c2, c3, c1);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  591|  70.5k|    sqr_add_c2(a, 6, 4, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  592|  70.5k|    sqr_add_c2(a, 7, 3, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  593|  70.5k|    r[10] = c2;
  594|  70.5k|    c2 = 0;
  595|  70.5k|    sqr_add_c2(a, 7, 4, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  596|  70.5k|    sqr_add_c2(a, 6, 5, c3, c1, c2);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  597|  70.5k|    r[11] = c3;
  598|  70.5k|    c3 = 0;
  599|  70.5k|    sqr_add_c(a, 6, c1, c2, c3);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  600|  70.5k|    sqr_add_c2(a, 7, 5, c1, c2, c3);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  601|  70.5k|    r[12] = c1;
  602|  70.5k|    c1 = 0;
  603|  70.5k|    sqr_add_c2(a, 7, 6, c2, c3, c1);
  ------------------
  |  |  392|  70.5k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  70.5k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  70.5k|        asm ("mulq %3"                  \
  |  |  |  |  377|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  70.5k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  70.5k|                : "cc");                \
  |  |  |  |  380|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  70.5k|                : "cc");                                \
  |  |  |  |  384|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  70.5k|                : "cc");                                \
  |  |  |  |  388|  70.5k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  604|  70.5k|    r[13] = c2;
  605|  70.5k|    c2 = 0;
  606|  70.5k|    sqr_add_c(a, 7, c3, c1, c2);
  ------------------
  |  |  362|  70.5k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  70.5k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  70.5k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  70.5k|        asm ("mulq %2"                  \
  |  |  365|  70.5k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  70.5k|                : "a"(a[i])             \
  |  |  367|  70.5k|                : "cc");                \
  |  |  368|  70.5k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  70.5k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  70.5k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  70.5k|                : "cc");                                \
  |  |  372|  70.5k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  607|  70.5k|    r[14] = c3;
  608|  70.5k|    r[15] = c1;
  609|  70.5k|}
bn_sqr_comba4:
  612|  1.76k|{
  613|  1.76k|    BN_ULONG c1, c2, c3;
  ------------------
  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  ------------------
  614|       |
  615|  1.76k|    c1 = 0;
  616|  1.76k|    c2 = 0;
  617|  1.76k|    c3 = 0;
  618|  1.76k|    sqr_add_c(a, 0, c1, c2, c3);
  ------------------
  |  |  362|  1.76k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  1.76k|        asm ("mulq %2"                  \
  |  |  365|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  1.76k|                : "a"(a[i])             \
  |  |  367|  1.76k|                : "cc");                \
  |  |  368|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  1.76k|                : "cc");                                \
  |  |  372|  1.76k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  619|  1.76k|    r[0] = c1;
  620|  1.76k|    c1 = 0;
  621|  1.76k|    sqr_add_c2(a, 1, 0, c2, c3, c1);
  ------------------
  |  |  392|  1.76k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  1.76k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  1.76k|        asm ("mulq %3"                  \
  |  |  |  |  377|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  1.76k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  1.76k|                : "cc");                \
  |  |  |  |  380|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  1.76k|                : "cc");                                \
  |  |  |  |  384|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  1.76k|                : "cc");                                \
  |  |  |  |  388|  1.76k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  622|  1.76k|    r[1] = c2;
  623|  1.76k|    c2 = 0;
  624|  1.76k|    sqr_add_c(a, 1, c3, c1, c2);
  ------------------
  |  |  362|  1.76k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  1.76k|        asm ("mulq %2"                  \
  |  |  365|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  1.76k|                : "a"(a[i])             \
  |  |  367|  1.76k|                : "cc");                \
  |  |  368|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  1.76k|                : "cc");                                \
  |  |  372|  1.76k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  625|  1.76k|    sqr_add_c2(a, 2, 0, c3, c1, c2);
  ------------------
  |  |  392|  1.76k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  1.76k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  1.76k|        asm ("mulq %3"                  \
  |  |  |  |  377|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  1.76k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  1.76k|                : "cc");                \
  |  |  |  |  380|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  1.76k|                : "cc");                                \
  |  |  |  |  384|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  1.76k|                : "cc");                                \
  |  |  |  |  388|  1.76k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  626|  1.76k|    r[2] = c3;
  627|  1.76k|    c3 = 0;
  628|  1.76k|    sqr_add_c2(a, 3, 0, c1, c2, c3);
  ------------------
  |  |  392|  1.76k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  1.76k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  1.76k|        asm ("mulq %3"                  \
  |  |  |  |  377|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  1.76k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  1.76k|                : "cc");                \
  |  |  |  |  380|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  1.76k|                : "cc");                                \
  |  |  |  |  384|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  1.76k|                : "cc");                                \
  |  |  |  |  388|  1.76k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  629|  1.76k|    sqr_add_c2(a, 2, 1, c1, c2, c3);
  ------------------
  |  |  392|  1.76k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  1.76k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  1.76k|        asm ("mulq %3"                  \
  |  |  |  |  377|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  1.76k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  1.76k|                : "cc");                \
  |  |  |  |  380|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  1.76k|                : "cc");                                \
  |  |  |  |  384|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  1.76k|                : "cc");                                \
  |  |  |  |  388|  1.76k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  630|  1.76k|    r[3] = c1;
  631|  1.76k|    c1 = 0;
  632|  1.76k|    sqr_add_c(a, 2, c2, c3, c1);
  ------------------
  |  |  362|  1.76k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  1.76k|        asm ("mulq %2"                  \
  |  |  365|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  1.76k|                : "a"(a[i])             \
  |  |  367|  1.76k|                : "cc");                \
  |  |  368|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  1.76k|                : "cc");                                \
  |  |  372|  1.76k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  633|  1.76k|    sqr_add_c2(a, 3, 1, c2, c3, c1);
  ------------------
  |  |  392|  1.76k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  1.76k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  1.76k|        asm ("mulq %3"                  \
  |  |  |  |  377|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  1.76k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  1.76k|                : "cc");                \
  |  |  |  |  380|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  1.76k|                : "cc");                                \
  |  |  |  |  384|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  1.76k|                : "cc");                                \
  |  |  |  |  388|  1.76k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  634|  1.76k|    r[4] = c2;
  635|  1.76k|    c2 = 0;
  636|  1.76k|    sqr_add_c2(a, 3, 2, c3, c1, c2);
  ------------------
  |  |  392|  1.76k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  374|  1.76k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  375|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  376|  1.76k|        asm ("mulq %3"                  \
  |  |  |  |  377|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  378|  1.76k|                : "a"(a),"m"(b)         \
  |  |  |  |  379|  1.76k|                : "cc");                \
  |  |  |  |  380|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  381|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  382|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  383|  1.76k|                : "cc");                                \
  |  |  |  |  384|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  385|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  386|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  387|  1.76k|                : "cc");                                \
  |  |  |  |  388|  1.76k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (388:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  637|  1.76k|    r[5] = c3;
  638|  1.76k|    c3 = 0;
  639|  1.76k|    sqr_add_c(a, 3, c1, c2, c3);
  ------------------
  |  |  362|  1.76k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  363|  1.76k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   31|  1.76k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  364|  1.76k|        asm ("mulq %2"                  \
  |  |  365|  1.76k|                : "=a"(t1),"=d"(t2)     \
  |  |  366|  1.76k|                : "a"(a[i])             \
  |  |  367|  1.76k|                : "cc");                \
  |  |  368|  1.76k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  369|  1.76k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  370|  1.76k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  371|  1.76k|                : "cc");                                \
  |  |  372|  1.76k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (372:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  640|  1.76k|    r[6] = c1;
  641|  1.76k|    r[7] = c2;
  642|  1.76k|}

BN_add:
   15|  2.44k|{
   16|  2.44k|    int ret, r_neg, cmp_res;
   17|       |
   18|  2.44k|    bn_check_top(a);
   19|  2.44k|    bn_check_top(b);
   20|       |
   21|  2.44k|    if (a->neg == b->neg) {
  ------------------
  |  Branch (21:9): [True: 0, False: 2.44k]
  ------------------
   22|      0|        r_neg = a->neg;
   23|      0|        ret = BN_uadd(r, a, b);
   24|  2.44k|    } else {
   25|  2.44k|        cmp_res = BN_ucmp(a, b);
   26|  2.44k|        if (cmp_res > 0) {
  ------------------
  |  Branch (26:13): [True: 0, False: 2.44k]
  ------------------
   27|      0|            r_neg = a->neg;
   28|      0|            ret = BN_usub(r, a, b);
   29|  2.44k|        } else if (cmp_res < 0) {
  ------------------
  |  Branch (29:20): [True: 2.44k, False: 0]
  ------------------
   30|  2.44k|            r_neg = b->neg;
   31|  2.44k|            ret = BN_usub(r, b, a);
   32|  2.44k|        } else {
   33|      0|            r_neg = 0;
   34|      0|            BN_zero(r);
  ------------------
  |  |  196|      0|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
   35|      0|            ret = 1;
   36|      0|        }
   37|  2.44k|    }
   38|       |
   39|  2.44k|    r->neg = r_neg;
   40|  2.44k|    bn_check_top(r);
   41|  2.44k|    return ret;
   42|  2.44k|}
BN_sub:
   46|  2.77k|{
   47|  2.77k|    int ret, r_neg, cmp_res;
   48|       |
   49|  2.77k|    bn_check_top(a);
   50|  2.77k|    bn_check_top(b);
   51|       |
   52|  2.77k|    if (a->neg != b->neg) {
  ------------------
  |  Branch (52:9): [True: 0, False: 2.77k]
  ------------------
   53|      0|        r_neg = a->neg;
   54|      0|        ret = BN_uadd(r, a, b);
   55|  2.77k|    } else {
   56|  2.77k|        cmp_res = BN_ucmp(a, b);
   57|  2.77k|        if (cmp_res > 0) {
  ------------------
  |  Branch (57:13): [True: 720, False: 2.05k]
  ------------------
   58|    720|            r_neg = a->neg;
   59|    720|            ret = BN_usub(r, a, b);
   60|  2.05k|        } else if (cmp_res < 0) {
  ------------------
  |  Branch (60:20): [True: 2.05k, False: 0]
  ------------------
   61|  2.05k|            r_neg = !b->neg;
   62|  2.05k|            ret = BN_usub(r, b, a);
   63|  2.05k|        } else {
   64|      0|            r_neg = 0;
   65|      0|            BN_zero(r);
  ------------------
  |  |  196|      0|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
   66|      0|            ret = 1;
   67|      0|        }
   68|  2.77k|    }
   69|       |
   70|  2.77k|    r->neg = r_neg;
   71|  2.77k|    bn_check_top(r);
   72|  2.77k|    return ret;
   73|  2.77k|}
BN_uadd:
   77|  82.6k|{
   78|  82.6k|    int max, min, dif;
   79|  82.6k|    const BN_ULONG *ap, *bp;
   80|  82.6k|    BN_ULONG *rp, carry, t1, t2;
  ------------------
  |  |   31|  82.6k|#  define BN_ULONG        unsigned long
  ------------------
   81|       |
   82|  82.6k|    bn_check_top(a);
   83|  82.6k|    bn_check_top(b);
   84|       |
   85|  82.6k|    if (a->top < b->top) {
  ------------------
  |  Branch (85:9): [True: 1.73k, False: 80.9k]
  ------------------
   86|  1.73k|        const BIGNUM *tmp;
   87|       |
   88|  1.73k|        tmp = a;
   89|  1.73k|        a = b;
   90|  1.73k|        b = tmp;
   91|  1.73k|    }
   92|  82.6k|    max = a->top;
   93|  82.6k|    min = b->top;
   94|  82.6k|    dif = max - min;
   95|       |
   96|  82.6k|    if (bn_wexpand(r, max + 1) == NULL)
  ------------------
  |  Branch (96:9): [True: 0, False: 82.6k]
  ------------------
   97|      0|        return 0;
   98|       |
   99|  82.6k|    r->top = max;
  100|       |
  101|  82.6k|    ap = a->d;
  102|  82.6k|    bp = b->d;
  103|  82.6k|    rp = r->d;
  104|       |
  105|  82.6k|    carry = bn_add_words(rp, ap, bp, min);
  106|  82.6k|    rp += min;
  107|  82.6k|    ap += min;
  108|       |
  109|  92.4k|    while (dif) {
  ------------------
  |  Branch (109:12): [True: 9.79k, False: 82.6k]
  ------------------
  110|  9.79k|        dif--;
  111|  9.79k|        t1 = *(ap++);
  112|  9.79k|        t2 = (t1 + carry) & BN_MASK2;
  ------------------
  |  |   87|  9.79k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  113|  9.79k|        *(rp++) = t2;
  114|  9.79k|        carry &= (t2 == 0);
  115|  9.79k|    }
  116|  82.6k|    *rp = carry;
  117|  82.6k|    r->top += carry;
  118|       |
  119|  82.6k|    r->neg = 0;
  120|  82.6k|    bn_check_top(r);
  121|  82.6k|    return 1;
  122|  82.6k|}
BN_usub:
  126|   211k|{
  127|   211k|    int max, min, dif;
  128|   211k|    BN_ULONG t1, t2, borrow, *rp;
  ------------------
  |  |   31|   211k|#  define BN_ULONG        unsigned long
  ------------------
  129|   211k|    const BN_ULONG *ap, *bp;
  130|       |
  131|   211k|    bn_check_top(a);
  132|   211k|    bn_check_top(b);
  133|       |
  134|   211k|    max = a->top;
  135|   211k|    min = b->top;
  136|   211k|    dif = max - min;
  137|       |
  138|   211k|    if (dif < 0) {              /* hmm... should not be happening */
  ------------------
  |  Branch (138:9): [True: 0, False: 211k]
  ------------------
  139|      0|        BNerr(BN_F_BN_USUB, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  140|      0|        return 0;
  141|      0|    }
  142|       |
  143|   211k|    if (bn_wexpand(r, max) == NULL)
  ------------------
  |  Branch (143:9): [True: 0, False: 211k]
  ------------------
  144|      0|        return 0;
  145|       |
  146|   211k|    ap = a->d;
  147|   211k|    bp = b->d;
  148|   211k|    rp = r->d;
  149|       |
  150|   211k|    borrow = bn_sub_words(rp, ap, bp, min);
  151|   211k|    ap += min;
  152|   211k|    rp += min;
  153|       |
  154|   289k|    while (dif) {
  ------------------
  |  Branch (154:12): [True: 77.4k, False: 211k]
  ------------------
  155|  77.4k|        dif--;
  156|  77.4k|        t1 = *(ap++);
  157|  77.4k|        t2 = (t1 - borrow) & BN_MASK2;
  ------------------
  |  |   87|  77.4k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  158|  77.4k|        *(rp++) = t2;
  159|  77.4k|        borrow &= (t1 == 0);
  160|  77.4k|    }
  161|       |
  162|  1.24M|    while (max && *--rp == 0)
  ------------------
  |  Branch (162:12): [True: 1.23M, False: 1.41k]
  |  Branch (162:19): [True: 1.02M, False: 210k]
  ------------------
  163|  1.02M|        max--;
  164|       |
  165|   211k|    r->top = max;
  166|   211k|    r->neg = 0;
  167|   211k|    bn_pollute(r);
  168|       |
  169|   211k|    return 1;
  170|   211k|}

BN_CTX_new:
  135|  3.24k|{
  136|  3.24k|    BN_CTX *ret;
  137|       |
  138|  3.24k|    if ((ret = OPENSSL_zalloc(sizeof(*ret))) == NULL) {
  ------------------
  |  |  120|  3.24k|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  3.24k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  3.24k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (138:9): [True: 0, False: 3.24k]
  ------------------
  139|      0|        BNerr(BN_F_BN_CTX_NEW, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  140|      0|        return NULL;
  141|      0|    }
  142|       |    /* Initialise the structure */
  143|  3.24k|    BN_POOL_init(&ret->pool);
  144|  3.24k|    BN_STACK_init(&ret->stack);
  145|  3.24k|    return ret;
  146|  3.24k|}
BN_CTX_free:
  158|  4.60k|{
  159|  4.60k|    if (ctx == NULL)
  ------------------
  |  Branch (159:9): [True: 1.35k, False: 3.24k]
  ------------------
  160|  1.35k|        return;
  161|       |#ifdef BN_CTX_DEBUG
  162|       |    {
  163|       |        BN_POOL_ITEM *pool = ctx->pool.head;
  164|       |        fprintf(stderr, "BN_CTX_free, stack-size=%d, pool-bignums=%d\n",
  165|       |                ctx->stack.size, ctx->pool.size);
  166|       |        fprintf(stderr, "dmaxs: ");
  167|       |        while (pool) {
  168|       |            unsigned loop = 0;
  169|       |            while (loop < BN_CTX_POOL_SIZE)
  170|       |                fprintf(stderr, "%02x ", pool->vals[loop++].dmax);
  171|       |            pool = pool->next;
  172|       |        }
  173|       |        fprintf(stderr, "\n");
  174|       |    }
  175|       |#endif
  176|  3.24k|    BN_STACK_finish(&ctx->stack);
  177|  3.24k|    BN_POOL_finish(&ctx->pool);
  178|  3.24k|    OPENSSL_free(ctx);
  ------------------
  |  |  128|  3.24k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  3.24k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  3.24k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  179|  3.24k|}
BN_CTX_start:
  182|  1.37M|{
  183|  1.37M|    CTXDBG_ENTRY("BN_CTX_start", ctx);
  184|       |    /* If we're already overflowing ... */
  185|  1.37M|    if (ctx->err_stack || ctx->too_many)
  ------------------
  |  Branch (185:9): [True: 0, False: 1.37M]
  |  Branch (185:27): [True: 0, False: 1.37M]
  ------------------
  186|      0|        ctx->err_stack++;
  187|       |    /* (Try to) get a new frame pointer */
  188|  1.37M|    else if (!BN_STACK_push(&ctx->stack, ctx->used)) {
  ------------------
  |  Branch (188:14): [True: 0, False: 1.37M]
  ------------------
  189|      0|        BNerr(BN_F_BN_CTX_START, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  190|      0|        ctx->err_stack++;
  191|      0|    }
  192|  1.37M|    CTXDBG_EXIT(ctx);
  193|  1.37M|}
BN_CTX_end:
  196|  1.37M|{
  197|  1.37M|    if (ctx == NULL)
  ------------------
  |  Branch (197:9): [True: 0, False: 1.37M]
  ------------------
  198|      0|        return;
  199|  1.37M|    CTXDBG_ENTRY("BN_CTX_end", ctx);
  200|  1.37M|    if (ctx->err_stack)
  ------------------
  |  Branch (200:9): [True: 0, False: 1.37M]
  ------------------
  201|      0|        ctx->err_stack--;
  202|  1.37M|    else {
  203|  1.37M|        unsigned int fp = BN_STACK_pop(&ctx->stack);
  204|       |        /* Does this stack frame have anything to release? */
  205|  1.37M|        if (fp < ctx->used)
  ------------------
  |  Branch (205:13): [True: 1.16M, False: 211k]
  ------------------
  206|  1.16M|            BN_POOL_release(&ctx->pool, ctx->used - fp);
  207|  1.37M|        ctx->used = fp;
  208|       |        /* Unjam "too_many" in case "get" had failed */
  209|  1.37M|        ctx->too_many = 0;
  210|  1.37M|    }
  211|  1.37M|    CTXDBG_EXIT(ctx);
  212|  1.37M|}
BN_CTX_get:
  215|  1.98M|{
  216|  1.98M|    BIGNUM *ret;
  217|       |
  218|  1.98M|    CTXDBG_ENTRY("BN_CTX_get", ctx);
  219|  1.98M|    if (ctx->err_stack || ctx->too_many)
  ------------------
  |  Branch (219:9): [True: 0, False: 1.98M]
  |  Branch (219:27): [True: 0, False: 1.98M]
  ------------------
  220|      0|        return NULL;
  221|  1.98M|    if ((ret = BN_POOL_get(&ctx->pool, ctx->flags)) == NULL) {
  ------------------
  |  Branch (221:9): [True: 0, False: 1.98M]
  ------------------
  222|       |        /*
  223|       |         * Setting too_many prevents repeated "get" attempts from cluttering
  224|       |         * the error stack.
  225|       |         */
  226|      0|        ctx->too_many = 1;
  227|      0|        BNerr(BN_F_BN_CTX_GET, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  228|      0|        return NULL;
  229|      0|    }
  230|       |    /* OK, make sure the returned bignum is "zero" */
  231|  1.98M|    BN_zero(ret);
  ------------------
  |  |  196|  1.98M|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  232|       |    /* clear BN_FLG_CONSTTIME if leaked from previous frames */
  233|  1.98M|    ret->flags &= (~BN_FLG_CONSTTIME);
  ------------------
  |  |   61|  1.98M|# define BN_FLG_CONSTTIME        0x04
  ------------------
  234|  1.98M|    ctx->used++;
  235|  1.98M|    CTXDBG_RET(ctx, ret);
  236|  1.98M|    return ret;
  237|  1.98M|}
bn_ctx.c:BN_STACK_init:
  244|  3.24k|{
  245|  3.24k|    st->indexes = NULL;
  246|  3.24k|    st->depth = st->size = 0;
  247|  3.24k|}
bn_ctx.c:BN_STACK_finish:
  250|  3.24k|{
  251|  3.24k|    OPENSSL_free(st->indexes);
  ------------------
  |  |  128|  3.24k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  3.24k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  3.24k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  252|  3.24k|    st->indexes = NULL;
  253|  3.24k|}
bn_ctx.c:BN_STACK_push:
  257|  1.37M|{
  258|  1.37M|    if (st->depth == st->size) {
  ------------------
  |  Branch (258:9): [True: 3.01k, False: 1.37M]
  ------------------
  259|       |        /* Need to expand */
  260|  3.01k|        unsigned int newsize =
  261|  3.01k|            st->size ? (st->size * 3 / 2) : BN_CTX_START_FRAMES;
  ------------------
  |  |   29|  3.01k|#define BN_CTX_START_FRAMES     32
  ------------------
  |  Branch (261:13): [True: 0, False: 3.01k]
  ------------------
  262|  3.01k|        unsigned int *newitems;
  263|       |
  264|  3.01k|        if ((newitems = OPENSSL_malloc(sizeof(*newitems) * newsize)) == NULL) {
  ------------------
  |  |  118|  3.01k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  3.01k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  3.01k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (264:13): [True: 0, False: 3.01k]
  ------------------
  265|      0|            BNerr(BN_F_BN_STACK_PUSH, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  266|      0|            return 0;
  267|      0|        }
  268|  3.01k|        if (st->depth)
  ------------------
  |  Branch (268:13): [True: 0, False: 3.01k]
  ------------------
  269|      0|            memcpy(newitems, st->indexes, sizeof(*newitems) * st->depth);
  270|  3.01k|        OPENSSL_free(st->indexes);
  ------------------
  |  |  128|  3.01k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  3.01k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  3.01k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  271|  3.01k|        st->indexes = newitems;
  272|  3.01k|        st->size = newsize;
  273|  3.01k|    }
  274|  1.37M|    st->indexes[(st->depth)++] = idx;
  275|  1.37M|    return 1;
  276|  1.37M|}
bn_ctx.c:BN_STACK_pop:
  279|  1.37M|{
  280|  1.37M|    return st->indexes[--(st->depth)];
  281|  1.37M|}
bn_ctx.c:BN_POOL_init:
  288|  3.24k|{
  289|  3.24k|    p->head = p->current = p->tail = NULL;
  290|  3.24k|    p->used = p->size = 0;
  291|  3.24k|}
bn_ctx.c:BN_POOL_finish:
  294|  3.24k|{
  295|  3.24k|    unsigned int loop;
  296|  3.24k|    BIGNUM *bn;
  297|       |
  298|  6.42k|    while (p->head) {
  ------------------
  |  Branch (298:12): [True: 3.17k, False: 3.24k]
  ------------------
  299|  53.9k|        for (loop = 0, bn = p->head->vals; loop++ < BN_CTX_POOL_SIZE; bn++)
  ------------------
  |  |   27|  53.9k|#define BN_CTX_POOL_SIZE        16
  ------------------
  |  Branch (299:44): [True: 50.8k, False: 3.17k]
  ------------------
  300|  50.8k|            if (bn->d)
  ------------------
  |  Branch (300:17): [True: 38.4k, False: 12.4k]
  ------------------
  301|  38.4k|                BN_clear_free(bn);
  302|  3.17k|        p->current = p->head->next;
  303|  3.17k|        OPENSSL_free(p->head);
  ------------------
  |  |  128|  3.17k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  3.17k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  3.17k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  304|  3.17k|        p->head = p->current;
  305|  3.17k|    }
  306|  3.24k|}
bn_ctx.c:BN_POOL_get:
  310|  1.98M|{
  311|  1.98M|    BIGNUM *bn;
  312|  1.98M|    unsigned int loop;
  313|       |
  314|       |    /* Full; allocate a new pool item and link it in. */
  315|  1.98M|    if (p->used == p->size) {
  ------------------
  |  Branch (315:9): [True: 3.17k, False: 1.98M]
  ------------------
  316|  3.17k|        BN_POOL_ITEM *item;
  317|       |
  318|  3.17k|        if ((item = OPENSSL_malloc(sizeof(*item))) == NULL) {
  ------------------
  |  |  118|  3.17k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  3.17k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  3.17k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (318:13): [True: 0, False: 3.17k]
  ------------------
  319|      0|            BNerr(BN_F_BN_POOL_GET, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  320|      0|            return NULL;
  321|      0|        }
  322|  53.9k|        for (loop = 0, bn = item->vals; loop++ < BN_CTX_POOL_SIZE; bn++) {
  ------------------
  |  |   27|  53.9k|#define BN_CTX_POOL_SIZE        16
  ------------------
  |  Branch (322:41): [True: 50.8k, False: 3.17k]
  ------------------
  323|  50.8k|            bn_init(bn);
  324|  50.8k|            if ((flag & BN_FLG_SECURE) != 0)
  ------------------
  |  |   62|  50.8k|# define BN_FLG_SECURE           0x08
  ------------------
  |  Branch (324:17): [True: 0, False: 50.8k]
  ------------------
  325|      0|                BN_set_flags(bn, BN_FLG_SECURE);
  ------------------
  |  |   62|      0|# define BN_FLG_SECURE           0x08
  ------------------
  326|  50.8k|        }
  327|  3.17k|        item->prev = p->tail;
  328|  3.17k|        item->next = NULL;
  329|       |
  330|  3.17k|        if (p->head == NULL)
  ------------------
  |  Branch (330:13): [True: 3.01k, False: 164]
  ------------------
  331|  3.01k|            p->head = p->current = p->tail = item;
  332|    164|        else {
  333|    164|            p->tail->next = item;
  334|    164|            p->tail = item;
  335|    164|            p->current = item;
  336|    164|        }
  337|  3.17k|        p->size += BN_CTX_POOL_SIZE;
  ------------------
  |  |   27|  3.17k|#define BN_CTX_POOL_SIZE        16
  ------------------
  338|  3.17k|        p->used++;
  339|       |        /* Return the first bignum from the new pool */
  340|  3.17k|        return item->vals;
  341|  3.17k|    }
  342|       |
  343|  1.98M|    if (!p->used)
  ------------------
  |  Branch (343:9): [True: 3.01k, False: 1.97M]
  ------------------
  344|  3.01k|        p->current = p->head;
  345|  1.97M|    else if ((p->used % BN_CTX_POOL_SIZE) == 0)
  ------------------
  |  |   27|  1.97M|#define BN_CTX_POOL_SIZE        16
  ------------------
  |  Branch (345:14): [True: 838, False: 1.97M]
  ------------------
  346|    838|        p->current = p->current->next;
  347|  1.98M|    return p->current->vals + ((p->used++) % BN_CTX_POOL_SIZE);
  ------------------
  |  |   27|  1.98M|#define BN_CTX_POOL_SIZE        16
  ------------------
  348|  1.98M|}
bn_ctx.c:BN_POOL_release:
  351|  1.16M|{
  352|  1.16M|    unsigned int offset = (p->used - 1) % BN_CTX_POOL_SIZE;
  ------------------
  |  |   27|  1.16M|#define BN_CTX_POOL_SIZE        16
  ------------------
  353|       |
  354|  1.16M|    p->used -= num;
  355|  3.14M|    while (num--) {
  ------------------
  |  Branch (355:12): [True: 1.98M, False: 1.16M]
  ------------------
  356|  1.98M|        bn_check_top(p->current->vals + offset);
  357|  1.98M|        if (offset == 0) {
  ------------------
  |  Branch (357:13): [True: 7.02k, False: 1.97M]
  ------------------
  358|  7.02k|            offset = BN_CTX_POOL_SIZE - 1;
  ------------------
  |  |   27|  7.02k|#define BN_CTX_POOL_SIZE        16
  ------------------
  359|  7.02k|            p->current = p->current->prev;
  360|  7.02k|        } else
  361|  1.97M|            offset--;
  362|  1.98M|    }
  363|  1.16M|}

BN_div:
  211|   192k|{
  212|   192k|    int ret;
  213|       |
  214|   192k|    if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (214:9): [True: 0, False: 192k]
  ------------------
  215|      0|        BNerr(BN_F_BN_DIV, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  216|      0|        return 0;
  217|      0|    }
  218|       |
  219|       |    /*
  220|       |     * Invalid zero-padding would have particularly bad consequences so don't
  221|       |     * just rely on bn_check_top() here (bn_check_top() works only for
  222|       |     * BN_DEBUG builds)
  223|       |     */
  224|   192k|    if (divisor->d[divisor->top - 1] == 0) {
  ------------------
  |  Branch (224:9): [True: 0, False: 192k]
  ------------------
  225|      0|        BNerr(BN_F_BN_DIV, BN_R_NOT_INITIALIZED);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  226|      0|        return 0;
  227|      0|    }
  228|       |
  229|   192k|    ret = bn_div_fixed_top(dv, rm, num, divisor, ctx);
  230|       |
  231|   192k|    if (ret) {
  ------------------
  |  Branch (231:9): [True: 192k, False: 0]
  ------------------
  232|   192k|        if (dv != NULL)
  ------------------
  |  Branch (232:13): [True: 2.97k, False: 189k]
  ------------------
  233|  2.97k|            bn_correct_top(dv);
  234|   192k|        if (rm != NULL)
  ------------------
  |  Branch (234:13): [True: 189k, False: 2.97k]
  ------------------
  235|   189k|            bn_correct_top(rm);
  236|   192k|    }
  237|       |
  238|   192k|    return ret;
  239|   192k|}
bn_div_fixed_top:
  266|   192k|{
  267|   192k|    int norm_shift, i, j, loop;
  268|   192k|    BIGNUM *tmp, *snum, *sdiv, *res;
  269|   192k|    BN_ULONG *resp, *wnum, *wnumtop;
  ------------------
  |  |   31|   192k|#  define BN_ULONG        unsigned long
  ------------------
  270|   192k|    BN_ULONG d0, d1;
  ------------------
  |  |   31|   192k|#  define BN_ULONG        unsigned long
  ------------------
  271|   192k|    int num_n, div_n, num_neg;
  272|       |
  273|   192k|    assert(divisor->top > 0 && divisor->d[divisor->top - 1] != 0);
  274|       |
  275|   192k|    bn_check_top(num);
  276|   192k|    bn_check_top(divisor);
  277|   192k|    bn_check_top(dv);
  278|   192k|    bn_check_top(rm);
  279|       |
  280|   192k|    BN_CTX_start(ctx);
  281|   192k|    res = (dv == NULL) ? BN_CTX_get(ctx) : dv;
  ------------------
  |  Branch (281:11): [True: 189k, False: 2.97k]
  ------------------
  282|   192k|    tmp = BN_CTX_get(ctx);
  283|   192k|    snum = BN_CTX_get(ctx);
  284|   192k|    sdiv = BN_CTX_get(ctx);
  285|   192k|    if (sdiv == NULL)
  ------------------
  |  Branch (285:9): [True: 0, False: 192k]
  ------------------
  286|      0|        goto err;
  287|       |
  288|       |    /* First we normalise the numbers */
  289|   192k|    if (!BN_copy(sdiv, divisor))
  ------------------
  |  Branch (289:9): [True: 0, False: 192k]
  ------------------
  290|      0|        goto err;
  291|   192k|    norm_shift = bn_left_align(sdiv);
  292|   192k|    sdiv->neg = 0;
  293|       |    /*
  294|       |     * Note that bn_lshift_fixed_top's output is always one limb longer
  295|       |     * than input, even when norm_shift is zero. This means that amount of
  296|       |     * inner loop iterations is invariant of dividend value, and that one
  297|       |     * doesn't need to compare dividend and divisor if they were originally
  298|       |     * of the same bit length.
  299|       |     */
  300|   192k|    if (!(bn_lshift_fixed_top(snum, num, norm_shift)))
  ------------------
  |  Branch (300:9): [True: 0, False: 192k]
  ------------------
  301|      0|        goto err;
  302|       |
  303|   192k|    div_n = sdiv->top;
  304|   192k|    num_n = snum->top;
  305|       |
  306|   192k|    if (num_n <= div_n) {
  ------------------
  |  Branch (306:9): [True: 18.7k, False: 174k]
  ------------------
  307|       |        /* caller didn't pad dividend -> no constant-time guarantee... */
  308|  18.7k|        if (bn_wexpand(snum, div_n + 1) == NULL)
  ------------------
  |  Branch (308:13): [True: 0, False: 18.7k]
  ------------------
  309|      0|            goto err;
  310|  18.7k|        memset(&(snum->d[num_n]), 0, (div_n - num_n + 1) * sizeof(BN_ULONG));
  311|  18.7k|        snum->top = num_n = div_n + 1;
  312|  18.7k|    }
  313|       |
  314|   192k|    loop = num_n - div_n;
  315|       |    /*
  316|       |     * Lets setup a 'window' into snum This is the part that corresponds to
  317|       |     * the current 'area' being divided
  318|       |     */
  319|   192k|    wnum = &(snum->d[loop]);
  320|   192k|    wnumtop = &(snum->d[num_n - 1]);
  321|       |
  322|       |    /* Get the top 2 words of sdiv */
  323|   192k|    d0 = sdiv->d[div_n - 1];
  324|   192k|    d1 = (div_n == 1) ? 0 : sdiv->d[div_n - 2];
  ------------------
  |  Branch (324:10): [True: 134k, False: 58.2k]
  ------------------
  325|       |
  326|       |    /* Setup quotient */
  327|   192k|    if (!bn_wexpand(res, loop))
  ------------------
  |  Branch (327:9): [True: 0, False: 192k]
  ------------------
  328|      0|        goto err;
  329|   192k|    num_neg = num->neg;
  330|   192k|    res->neg = (num_neg ^ divisor->neg);
  331|   192k|    res->top = loop;
  332|   192k|    res->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   192k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  333|   192k|    resp = &(res->d[loop]);
  334|       |
  335|       |    /* space for temp */
  336|   192k|    if (!bn_wexpand(tmp, (div_n + 1)))
  ------------------
  |  Branch (336:9): [True: 0, False: 192k]
  ------------------
  337|      0|        goto err;
  338|       |
  339|  1.40M|    for (i = 0; i < loop; i++, wnumtop--) {
  ------------------
  |  Branch (339:17): [True: 1.21M, False: 192k]
  ------------------
  340|  1.21M|        BN_ULONG q, l0;
  ------------------
  |  |   31|  1.21M|#  define BN_ULONG        unsigned long
  ------------------
  341|       |        /*
  342|       |         * the first part of the loop uses the top two words of snum and sdiv
  343|       |         * to calculate a BN_ULONG q such that | wnum - sdiv * q | < sdiv
  344|       |         */
  345|       |# if defined(BN_DIV3W)
  346|       |        q = bn_div_3_words(wnumtop, d1, d0);
  347|       |# else
  348|  1.21M|        BN_ULONG n0, n1, rem = 0;
  ------------------
  |  |   31|  1.21M|#  define BN_ULONG        unsigned long
  ------------------
  349|       |
  350|  1.21M|        n0 = wnumtop[0];
  351|  1.21M|        n1 = wnumtop[-1];
  352|  1.21M|        if (n0 == d0)
  ------------------
  |  Branch (352:13): [True: 37.7k, False: 1.17M]
  ------------------
  353|  37.7k|            q = BN_MASK2;
  ------------------
  |  |   87|  37.7k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  354|  1.17M|        else {                  /* n0 < d0 */
  355|  1.17M|            BN_ULONG n2 = (wnumtop == wnum) ? 0 : wnumtop[-2];
  ------------------
  |  |   31|  1.17M|#  define BN_ULONG        unsigned long
  ------------------
  |  Branch (355:27): [True: 199k, False: 977k]
  ------------------
  356|       |#  ifdef BN_LLONG
  357|       |            BN_ULLONG t2;
  358|       |
  359|       |#   if defined(BN_LLONG) && defined(BN_DIV2W) && !defined(bn_div_words)
  360|       |            q = (BN_ULONG)(((((BN_ULLONG) n0) << BN_BITS2) | n1) / d0);
  361|       |#   else
  362|       |            q = bn_div_words(n0, n1, d0);
  363|       |#   endif
  364|       |
  365|       |#   ifndef REMAINDER_IS_ALREADY_CALCULATED
  366|       |            /*
  367|       |             * rem doesn't have to be BN_ULLONG. The least we
  368|       |             * know it's less that d0, isn't it?
  369|       |             */
  370|       |            rem = (n1 - q * d0) & BN_MASK2;
  371|       |#   endif
  372|       |            t2 = (BN_ULLONG) d1 *q;
  373|       |
  374|       |            for (;;) {
  375|       |                if (t2 <= ((((BN_ULLONG) rem) << BN_BITS2) | n2))
  376|       |                    break;
  377|       |                q--;
  378|       |                rem += d0;
  379|       |                if (rem < d0)
  380|       |                    break;      /* don't let rem overflow */
  381|       |                t2 -= d1;
  382|       |            }
  383|       |#  else                         /* !BN_LLONG */
  384|  1.17M|            BN_ULONG t2l, t2h;
  ------------------
  |  |   31|  1.17M|#  define BN_ULONG        unsigned long
  ------------------
  385|       |
  386|  1.17M|            q = bn_div_words(n0, n1, d0);
  387|  1.17M|#   ifndef REMAINDER_IS_ALREADY_CALCULATED
  388|  1.17M|            rem = (n1 - q * d0) & BN_MASK2;
  ------------------
  |  |   87|  1.17M|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  389|  1.17M|#   endif
  390|       |
  391|       |#   if defined(BN_UMULT_LOHI)
  392|       |            BN_UMULT_LOHI(t2l, t2h, d1, q);
  393|       |#   elif defined(BN_UMULT_HIGH)
  394|       |            t2l = d1 * q;
  395|       |            t2h = BN_UMULT_HIGH(d1, q);
  396|       |#   else
  397|  1.17M|            {
  398|  1.17M|                BN_ULONG ql, qh;
  ------------------
  |  |   31|  1.17M|#  define BN_ULONG        unsigned long
  ------------------
  399|  1.17M|                t2l = LBITS(d1);
  ------------------
  |  |  574|  1.17M|#  define LBITS(a)        ((a)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   88|  1.17M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  400|  1.17M|                t2h = HBITS(d1);
  ------------------
  |  |  575|  1.17M|#  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   86|  1.17M|#  define BN_BITS4        32
  |  |  ------------------
  |  |               #  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   88|  1.17M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  401|  1.17M|                ql = LBITS(q);
  ------------------
  |  |  574|  1.17M|#  define LBITS(a)        ((a)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   88|  1.17M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  402|  1.17M|                qh = HBITS(q);
  ------------------
  |  |  575|  1.17M|#  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   86|  1.17M|#  define BN_BITS4        32
  |  |  ------------------
  |  |               #  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   88|  1.17M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  403|  1.17M|                mul64(t2l, t2h, ql, qh); /* t2=(BN_ULLONG)d1*q; */
  ------------------
  |  |  583|  1.17M|        { \
  |  |  584|  1.17M|        BN_ULONG m,m1,lt,ht; \
  |  |  ------------------
  |  |  |  |   31|  1.17M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  585|  1.17M| \
  |  |  586|  1.17M|        lt=l; \
  |  |  587|  1.17M|        ht=h; \
  |  |  588|  1.17M|        m =(bh)*(lt); \
  |  |  589|  1.17M|        lt=(bl)*(lt); \
  |  |  590|  1.17M|        m1=(bl)*(ht); \
  |  |  591|  1.17M|        ht =(bh)*(ht); \
  |  |  592|  1.17M|        m=(m+m1)&BN_MASK2; ht += L2HBITS((BN_ULONG)(m < m1)); \
  |  |  ------------------
  |  |  |  |   87|  1.17M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  ------------------
  |  |                       m=(m+m1)&BN_MASK2; ht += L2HBITS((BN_ULONG)(m < m1)); \
  |  |  ------------------
  |  |  |  |  576|  1.17M|#  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   86|  1.17M|#  define BN_BITS4        32
  |  |  |  |  ------------------
  |  |  |  |               #  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   87|  1.17M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  593|  1.17M|        ht+=HBITS(m); \
  |  |  ------------------
  |  |  |  |  575|  1.17M|#  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  |  |  ------------------
  |  |  |  |  |  |   86|  1.17M|#  define BN_BITS4        32
  |  |  |  |  ------------------
  |  |  |  |               #  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  |  |  ------------------
  |  |  |  |  |  |   88|  1.17M|#  define BN_MASK2l       (0xffffffffL)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  594|  1.17M|        m1=L2HBITS(m); \
  |  |  ------------------
  |  |  |  |  576|  1.17M|#  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   86|  1.17M|#  define BN_BITS4        32
  |  |  |  |  ------------------
  |  |  |  |               #  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   87|  1.17M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  595|  1.17M|        lt=(lt+m1)&BN_MASK2; ht += (lt < m1); \
  |  |  ------------------
  |  |  |  |   87|  1.17M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  ------------------
  |  |  596|  1.17M|        (l)=lt; \
  |  |  597|  1.17M|        (h)=ht; \
  |  |  598|  1.17M|        }
  ------------------
  404|  1.17M|            }
  405|  1.17M|#   endif
  406|       |
  407|  1.32M|            for (;;) {
  408|  1.32M|                if ((t2h < rem) || ((t2h == rem) && (t2l <= n2)))
  ------------------
  |  Branch (408:21): [True: 857k, False: 469k]
  |  Branch (408:37): [True: 104k, False: 365k]
  |  Branch (408:53): [True: 103k, False: 1.43k]
  ------------------
  409|   960k|                    break;
  410|   366k|                q--;
  411|   366k|                rem += d0;
  412|   366k|                if (rem < d0)
  ------------------
  |  Branch (412:21): [True: 216k, False: 150k]
  ------------------
  413|   216k|                    break;      /* don't let rem overflow */
  414|   150k|                if (t2l < d1)
  ------------------
  |  Branch (414:21): [True: 136k, False: 13.5k]
  ------------------
  415|   136k|                    t2h--;
  416|   150k|                t2l -= d1;
  417|   150k|            }
  418|  1.17M|#  endif                        /* !BN_LLONG */
  419|  1.17M|        }
  420|  1.21M|# endif                         /* !BN_DIV3W */
  421|       |
  422|  1.21M|        l0 = bn_mul_words(tmp->d, sdiv->d, div_n, q);
  423|  1.21M|        tmp->d[div_n] = l0;
  424|  1.21M|        wnum--;
  425|       |        /*
  426|       |         * ignore top values of the bignums just sub the two BN_ULONG arrays
  427|       |         * with bn_sub_words
  428|       |         */
  429|  1.21M|        l0 = bn_sub_words(wnum, wnum, tmp->d, div_n + 1);
  430|  1.21M|        q -= l0;
  431|       |        /*
  432|       |         * Note: As we have considered only the leading two BN_ULONGs in
  433|       |         * the calculation of q, sdiv * q might be greater than wnum (but
  434|       |         * then (q-1) * sdiv is less or equal than wnum)
  435|       |         */
  436|  94.8M|        for (l0 = 0 - l0, j = 0; j < div_n; j++)
  ------------------
  |  Branch (436:34): [True: 93.6M, False: 1.21M]
  ------------------
  437|  93.6M|            tmp->d[j] = sdiv->d[j] & l0;
  438|  1.21M|        l0 = bn_add_words(wnum, wnum, tmp->d, div_n);
  439|  1.21M|        (*wnumtop) += l0;
  440|  1.21M|        assert((*wnumtop) == 0);
  441|       |
  442|       |        /* store part of the result */
  443|  1.21M|        *--resp = q;
  444|  1.21M|    }
  445|       |    /* snum holds remainder, it's as wide as divisor */
  446|   192k|    snum->neg = num_neg;
  447|   192k|    snum->top = div_n;
  448|   192k|    snum->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   192k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  449|       |
  450|   192k|    if (rm != NULL && bn_rshift_fixed_top(rm, snum, norm_shift) == 0)
  ------------------
  |  Branch (450:9): [True: 189k, False: 2.97k]
  |  Branch (450:23): [True: 0, False: 189k]
  ------------------
  451|      0|        goto err;
  452|       |
  453|   192k|    BN_CTX_end(ctx);
  454|   192k|    return 1;
  455|      0| err:
  456|      0|    bn_check_top(rm);
  457|      0|    BN_CTX_end(ctx);
  458|      0|    return 0;
  459|   192k|}
bn_div.c:bn_left_align:
  142|   192k|{
  143|   192k|    BN_ULONG *d = num->d, n, m, rmask;
  ------------------
  |  |   31|   192k|#  define BN_ULONG        unsigned long
  ------------------
  144|   192k|    int top = num->top;
  145|   192k|    int rshift = BN_num_bits_word(d[top - 1]), lshift, i;
  146|       |
  147|   192k|    lshift = BN_BITS2 - rshift;
  ------------------
  |  |   48|   192k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   192k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  148|   192k|    rshift %= BN_BITS2;            /* say no to undefined behaviour */
  ------------------
  |  |   48|   192k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   192k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  149|   192k|    rmask = (BN_ULONG)0 - rshift;  /* rmask = 0 - (rshift != 0) */
  150|   192k|    rmask |= rmask >> 8;
  151|       |
  152|  2.05M|    for (i = 0, m = 0; i < top; i++) {
  ------------------
  |  Branch (152:24): [True: 1.86M, False: 192k]
  ------------------
  153|  1.86M|        n = d[i];
  154|  1.86M|        d[i] = ((n << lshift) | m) & BN_MASK2;
  ------------------
  |  |   87|  1.86M|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  155|  1.86M|        m = (n >> rshift) & rmask;
  156|  1.86M|    }
  157|       |
  158|   192k|    return lshift;
  159|   192k|}

ERR_load_BN_strings:
  110|      2|{
  111|      2|#ifndef OPENSSL_NO_ERR
  112|      2|    if (ERR_func_error_string(BN_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (112:9): [True: 2, False: 0]
  ------------------
  113|      2|        ERR_load_strings_const(BN_str_functs);
  114|      2|        ERR_load_strings_const(BN_str_reasons);
  115|      2|    }
  116|      2|#endif
  117|      2|    return 1;
  118|      2|}

BN_mod_exp:
  100|  3.19k|{
  101|  3.19k|    int ret;
  102|       |
  103|  3.19k|    bn_check_top(a);
  104|  3.19k|    bn_check_top(p);
  105|  3.19k|    bn_check_top(m);
  106|       |
  107|       |    /*-
  108|       |     * For even modulus  m = 2^k*m_odd, it might make sense to compute
  109|       |     * a^p mod m_odd  and  a^p mod 2^k  separately (with Montgomery
  110|       |     * exponentiation for the odd part), using appropriate exponent
  111|       |     * reductions, and combine the results using the CRT.
  112|       |     *
  113|       |     * For now, we use Montgomery only if the modulus is odd; otherwise,
  114|       |     * exponentiation using the reciprocal-based quick remaindering
  115|       |     * algorithm is used.
  116|       |     *
  117|       |     * (Timing obtained with expspeed.c [computations  a^p mod m
  118|       |     * where  a, p, m  are of the same length: 256, 512, 1024, 2048,
  119|       |     * 4096, 8192 bits], compared to the running time of the
  120|       |     * standard algorithm:
  121|       |     *
  122|       |     *   BN_mod_exp_mont   33 .. 40 %  [AMD K6-2, Linux, debug configuration]
  123|       |     *                     55 .. 77 %  [UltraSparc processor, but
  124|       |     *                                  debug-solaris-sparcv8-gcc conf.]
  125|       |     *
  126|       |     *   BN_mod_exp_recp   50 .. 70 %  [AMD K6-2, Linux, debug configuration]
  127|       |     *                     62 .. 118 % [UltraSparc, debug-solaris-sparcv8-gcc]
  128|       |     *
  129|       |     * On the Sparc, BN_mod_exp_recp was faster than BN_mod_exp_mont
  130|       |     * at 2048 and more bits, but at 512 and 1024 bits, it was
  131|       |     * slower even than the standard algorithm!
  132|       |     *
  133|       |     * "Real" timings [linux-elf, solaris-sparcv9-gcc configurations]
  134|       |     * should be obtained when the new Montgomery reduction code
  135|       |     * has been integrated into OpenSSL.)
  136|       |     */
  137|       |
  138|  3.19k|#define MONT_MUL_MOD
  139|  3.19k|#define MONT_EXP_WORD
  140|  3.19k|#define RECP_MUL_MOD
  141|       |
  142|  3.19k|#ifdef MONT_MUL_MOD
  143|  3.19k|    if (BN_is_odd(m)) {
  ------------------
  |  Branch (143:9): [True: 1.51k, False: 1.68k]
  ------------------
  144|  1.51k|# ifdef MONT_EXP_WORD
  145|  1.51k|        if (a->top == 1 && !a->neg
  ------------------
  |  Branch (145:13): [True: 674, False: 840]
  |  Branch (145:28): [True: 430, False: 244]
  ------------------
  146|  1.51k|            && (BN_get_flags(p, BN_FLG_CONSTTIME) == 0)
  ------------------
  |  |   61|    430|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (146:16): [True: 430, False: 0]
  ------------------
  147|  1.51k|            && (BN_get_flags(a, BN_FLG_CONSTTIME) == 0)
  ------------------
  |  |   61|    430|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (147:16): [True: 430, False: 0]
  ------------------
  148|  1.51k|            && (BN_get_flags(m, BN_FLG_CONSTTIME) == 0)) {
  ------------------
  |  |   61|    430|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (148:16): [True: 430, False: 0]
  ------------------
  149|    430|            BN_ULONG A = a->d[0];
  ------------------
  |  |   31|    430|#  define BN_ULONG        unsigned long
  ------------------
  150|    430|            ret = BN_mod_exp_mont_word(r, A, p, m, ctx, NULL);
  151|    430|        } else
  152|  1.08k|# endif
  153|  1.08k|            ret = BN_mod_exp_mont(r, a, p, m, ctx, NULL);
  154|  1.51k|    } else
  155|  1.68k|#endif
  156|  1.68k|#ifdef RECP_MUL_MOD
  157|  1.68k|    {
  158|  1.68k|        ret = BN_mod_exp_recp(r, a, p, m, ctx);
  159|  1.68k|    }
  160|       |#else
  161|       |    {
  162|       |        ret = BN_mod_exp_simple(r, a, p, m, ctx);
  163|       |    }
  164|       |#endif
  165|       |
  166|  3.19k|    bn_check_top(r);
  167|  3.19k|    return ret;
  168|  3.19k|}
BN_mod_exp_recp:
  172|  1.68k|{
  173|  1.68k|    int i, j, bits, ret = 0, wstart, wend, window, wvalue;
  174|  1.68k|    int start = 1;
  175|  1.68k|    BIGNUM *aa;
  176|       |    /* Table of variables obtained from 'ctx' */
  177|  1.68k|    BIGNUM *val[TABLE_SIZE];
  178|  1.68k|    BN_RECP_CTX recp;
  179|       |
  180|  1.68k|    if (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   61|  1.68k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (180:9): [True: 0, False: 1.68k]
  ------------------
  181|  1.68k|            || BN_get_flags(a, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   61|  1.68k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (181:16): [True: 0, False: 1.68k]
  ------------------
  182|  1.68k|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0) {
  ------------------
  |  |   61|  1.68k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (182:16): [True: 0, False: 1.68k]
  ------------------
  183|       |        /* BN_FLG_CONSTTIME only supported by BN_mod_exp_mont() */
  184|      0|        BNerr(BN_F_BN_MOD_EXP_RECP, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  185|      0|        return 0;
  186|      0|    }
  187|       |
  188|  1.68k|    bits = BN_num_bits(p);
  189|  1.68k|    if (bits == 0) {
  ------------------
  |  Branch (189:9): [True: 63, False: 1.61k]
  ------------------
  190|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
  191|     63|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (191:13): [True: 0, False: 63]
  ------------------
  192|      0|            ret = 1;
  193|      0|            BN_zero(r);
  ------------------
  |  |  196|      0|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  194|     63|        } else {
  195|     63|            ret = BN_one(r);
  ------------------
  |  |  189|     63|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  196|     63|        }
  197|     63|        return ret;
  198|     63|    }
  199|       |
  200|  1.61k|    BN_RECP_CTX_init(&recp);
  201|       |
  202|  1.61k|    BN_CTX_start(ctx);
  203|  1.61k|    aa = BN_CTX_get(ctx);
  204|  1.61k|    val[0] = BN_CTX_get(ctx);
  205|  1.61k|    if (val[0] == NULL)
  ------------------
  |  Branch (205:9): [True: 0, False: 1.61k]
  ------------------
  206|      0|        goto err;
  207|       |
  208|  1.61k|    if (m->neg) {
  ------------------
  |  Branch (208:9): [True: 631, False: 986]
  ------------------
  209|       |        /* ignore sign of 'm' */
  210|    631|        if (!BN_copy(aa, m))
  ------------------
  |  Branch (210:13): [True: 0, False: 631]
  ------------------
  211|      0|            goto err;
  212|    631|        aa->neg = 0;
  213|    631|        if (BN_RECP_CTX_set(&recp, aa, ctx) <= 0)
  ------------------
  |  Branch (213:13): [True: 0, False: 631]
  ------------------
  214|      0|            goto err;
  215|    986|    } else {
  216|    986|        if (BN_RECP_CTX_set(&recp, m, ctx) <= 0)
  ------------------
  |  Branch (216:13): [True: 0, False: 986]
  ------------------
  217|      0|            goto err;
  218|    986|    }
  219|       |
  220|  1.61k|    if (!BN_nnmod(val[0], a, m, ctx))
  ------------------
  |  Branch (220:9): [True: 0, False: 1.61k]
  ------------------
  221|      0|        goto err;               /* 1 */
  222|  1.61k|    if (BN_is_zero(val[0])) {
  ------------------
  |  Branch (222:9): [True: 26, False: 1.59k]
  ------------------
  223|     26|        BN_zero(r);
  ------------------
  |  |  196|     26|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  224|     26|        ret = 1;
  225|     26|        goto err;
  226|     26|    }
  227|       |
  228|  1.59k|    window = BN_window_bits_for_exponent_size(bits);
  ------------------
  |  |  312|  1.59k|                ((b) > 671 ? 6 : \
  |  |  ------------------
  |  |  |  Branch (312:18): [True: 19, False: 1.57k]
  |  |  ------------------
  |  |  313|  1.59k|                 (b) > 239 ? 5 : \
  |  |  ------------------
  |  |  |  Branch (313:18): [True: 22, False: 1.55k]
  |  |  ------------------
  |  |  314|  1.57k|                 (b) >  79 ? 4 : \
  |  |  ------------------
  |  |  |  Branch (314:18): [True: 70, False: 1.48k]
  |  |  ------------------
  |  |  315|  1.55k|                 (b) >  23 ? 3 : 1)
  |  |  ------------------
  |  |  |  Branch (315:18): [True: 173, False: 1.30k]
  |  |  ------------------
  ------------------
  229|  1.59k|    if (window > 1) {
  ------------------
  |  Branch (229:9): [True: 284, False: 1.30k]
  ------------------
  230|    284|        if (!BN_mod_mul_reciprocal(aa, val[0], val[0], &recp, ctx))
  ------------------
  |  Branch (230:13): [True: 0, False: 284]
  ------------------
  231|      0|            goto err;           /* 2 */
  232|    284|        j = 1 << (window - 1);
  233|  2.21k|        for (i = 1; i < j; i++) {
  ------------------
  |  Branch (233:21): [True: 1.92k, False: 284]
  ------------------
  234|  1.92k|            if (((val[i] = BN_CTX_get(ctx)) == NULL) ||
  ------------------
  |  Branch (234:17): [True: 0, False: 1.92k]
  ------------------
  235|  1.92k|                !BN_mod_mul_reciprocal(val[i], val[i - 1], aa, &recp, ctx))
  ------------------
  |  Branch (235:17): [True: 0, False: 1.92k]
  ------------------
  236|      0|                goto err;
  237|  1.92k|        }
  238|    284|    }
  239|       |
  240|  1.59k|    start = 1;                  /* This is used to avoid multiplication etc
  241|       |                                 * when there is only the value '1' in the
  242|       |                                 * buffer. */
  243|  1.59k|    wvalue = 0;                 /* The 'value' of the window */
  244|  1.59k|    wstart = bits - 1;          /* The top bit of the window */
  245|  1.59k|    wend = 0;                   /* The bottom bit of the window */
  246|       |
  247|  1.59k|    if (!BN_one(r))
  ------------------
  |  |  189|  1.59k|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (247:9): [True: 0, False: 1.59k]
  ------------------
  248|      0|        goto err;
  249|       |
  250|  50.8k|    for (;;) {
  251|  50.8k|        if (BN_is_bit_set(p, wstart) == 0) {
  ------------------
  |  Branch (251:13): [True: 30.2k, False: 20.5k]
  ------------------
  252|  30.2k|            if (!start)
  ------------------
  |  Branch (252:17): [True: 30.2k, False: 0]
  ------------------
  253|  30.2k|                if (!BN_mod_mul_reciprocal(r, r, r, &recp, ctx))
  ------------------
  |  Branch (253:21): [True: 0, False: 30.2k]
  ------------------
  254|      0|                    goto err;
  255|  30.2k|            if (wstart == 0)
  ------------------
  |  Branch (255:17): [True: 454, False: 29.8k]
  ------------------
  256|    454|                break;
  257|  29.8k|            wstart--;
  258|  29.8k|            continue;
  259|  30.2k|        }
  260|       |        /*
  261|       |         * We now have wstart on a 'set' bit, we now need to work out how bit
  262|       |         * a window to do.  To do this we need to scan forward until the last
  263|       |         * set bit before the end of the window
  264|       |         */
  265|  20.5k|        j = wstart;
  266|  20.5k|        wvalue = 1;
  267|  20.5k|        wend = 0;
  268|  67.8k|        for (i = 1; i < window; i++) {
  ------------------
  |  Branch (268:21): [True: 47.4k, False: 20.3k]
  ------------------
  269|  47.4k|            if (wstart - i < 0)
  ------------------
  |  Branch (269:17): [True: 139, False: 47.3k]
  ------------------
  270|    139|                break;
  271|  47.3k|            if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (271:17): [True: 35.4k, False: 11.8k]
  ------------------
  272|  35.4k|                wvalue <<= (i - wend);
  273|  35.4k|                wvalue |= 1;
  274|  35.4k|                wend = i;
  275|  35.4k|            }
  276|  47.3k|        }
  277|       |
  278|       |        /* wend is the size of the current window */
  279|  20.5k|        j = wend + 1;
  280|       |        /* add the 'bytes above' */
  281|  20.5k|        if (!start)
  ------------------
  |  Branch (281:13): [True: 18.9k, False: 1.59k]
  ------------------
  282|  78.6k|            for (i = 0; i < j; i++) {
  ------------------
  |  Branch (282:25): [True: 59.6k, False: 18.9k]
  ------------------
  283|  59.6k|                if (!BN_mod_mul_reciprocal(r, r, r, &recp, ctx))
  ------------------
  |  Branch (283:21): [True: 0, False: 59.6k]
  ------------------
  284|      0|                    goto err;
  285|  59.6k|            }
  286|       |
  287|       |        /* wvalue will be an odd number < 2^window */
  288|  20.5k|        if (!BN_mod_mul_reciprocal(r, r, val[wvalue >> 1], &recp, ctx))
  ------------------
  |  Branch (288:13): [True: 0, False: 20.5k]
  ------------------
  289|      0|            goto err;
  290|       |
  291|       |        /* move the 'window' down further */
  292|  20.5k|        wstart -= wend + 1;
  293|  20.5k|        wvalue = 0;
  294|  20.5k|        start = 0;
  295|  20.5k|        if (wstart < 0)
  ------------------
  |  Branch (295:13): [True: 1.13k, False: 19.3k]
  ------------------
  296|  1.13k|            break;
  297|  20.5k|    }
  298|  1.59k|    ret = 1;
  299|  1.61k| err:
  300|  1.61k|    BN_CTX_end(ctx);
  301|  1.61k|    BN_RECP_CTX_free(&recp);
  302|  1.61k|    bn_check_top(r);
  303|  1.61k|    return ret;
  304|  1.59k|}
BN_mod_exp_mont:
  308|  1.08k|{
  309|  1.08k|    int i, j, bits, ret = 0, wstart, wend, window, wvalue;
  310|  1.08k|    int start = 1;
  311|  1.08k|    BIGNUM *d, *r;
  312|  1.08k|    const BIGNUM *aa;
  313|       |    /* Table of variables obtained from 'ctx' */
  314|  1.08k|    BIGNUM *val[TABLE_SIZE];
  315|  1.08k|    BN_MONT_CTX *mont = NULL;
  316|       |
  317|  1.08k|    bn_check_top(a);
  318|  1.08k|    bn_check_top(p);
  319|  1.08k|    bn_check_top(m);
  320|       |
  321|  1.08k|    if (!BN_is_odd(m)) {
  ------------------
  |  Branch (321:9): [True: 0, False: 1.08k]
  ------------------
  322|      0|        BNerr(BN_F_BN_MOD_EXP_MONT, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  323|      0|        return 0;
  324|      0|    }
  325|       |
  326|  1.08k|    if (m->top <= BN_CONSTTIME_SIZE_LIMIT
  ------------------
  |  |   47|  2.16k|#define BN_CONSTTIME_SIZE_LIMIT (INT_MAX / BN_BYTES / 256)
  |  |  ------------------
  |  |  |  |   32|  1.08k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (326:9): [True: 1.08k, False: 0]
  ------------------
  327|  1.08k|        && (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   61|  1.08k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (327:13): [True: 0, False: 1.08k]
  ------------------
  328|  1.08k|            || BN_get_flags(a, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   61|  1.08k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (328:16): [True: 0, False: 1.08k]
  ------------------
  329|  1.08k|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0)) {
  ------------------
  |  |   61|  1.08k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (329:16): [True: 0, False: 1.08k]
  ------------------
  330|      0|        return BN_mod_exp_mont_consttime(rr, a, p, m, ctx, in_mont);
  331|      0|    }
  332|       |
  333|  1.08k|    bits = BN_num_bits(p);
  334|  1.08k|    if (bits == 0) {
  ------------------
  |  Branch (334:9): [True: 110, False: 974]
  ------------------
  335|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
  336|    110|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (336:13): [True: 3, False: 107]
  ------------------
  337|      3|            ret = 1;
  338|      3|            BN_zero(rr);
  ------------------
  |  |  196|      3|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  339|    107|        } else {
  340|    107|            ret = BN_one(rr);
  ------------------
  |  |  189|    107|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  341|    107|        }
  342|    110|        return ret;
  343|    110|    }
  344|       |
  345|    974|    BN_CTX_start(ctx);
  346|    974|    d = BN_CTX_get(ctx);
  347|    974|    r = BN_CTX_get(ctx);
  348|    974|    val[0] = BN_CTX_get(ctx);
  349|    974|    if (val[0] == NULL)
  ------------------
  |  Branch (349:9): [True: 0, False: 974]
  ------------------
  350|      0|        goto err;
  351|       |
  352|       |    /*
  353|       |     * If this is not done, things will break in the montgomery part
  354|       |     */
  355|       |
  356|    974|    if (in_mont != NULL)
  ------------------
  |  Branch (356:9): [True: 0, False: 974]
  ------------------
  357|      0|        mont = in_mont;
  358|    974|    else {
  359|    974|        if ((mont = BN_MONT_CTX_new()) == NULL)
  ------------------
  |  Branch (359:13): [True: 0, False: 974]
  ------------------
  360|      0|            goto err;
  361|    974|        if (!BN_MONT_CTX_set(mont, m, ctx))
  ------------------
  |  Branch (361:13): [True: 0, False: 974]
  ------------------
  362|      0|            goto err;
  363|    974|    }
  364|       |
  365|    974|    if (a->neg || BN_ucmp(a, m) >= 0) {
  ------------------
  |  Branch (365:9): [True: 243, False: 731]
  |  Branch (365:19): [True: 12, False: 719]
  ------------------
  366|    255|        if (!BN_nnmod(val[0], a, m, ctx))
  ------------------
  |  Branch (366:13): [True: 0, False: 255]
  ------------------
  367|      0|            goto err;
  368|    255|        aa = val[0];
  369|    255|    } else
  370|    719|        aa = a;
  371|    974|    if (!bn_to_mont_fixed_top(val[0], aa, mont, ctx))
  ------------------
  |  Branch (371:9): [True: 0, False: 974]
  ------------------
  372|      0|        goto err;               /* 1 */
  373|       |
  374|    974|    window = BN_window_bits_for_exponent_size(bits);
  ------------------
  |  |  312|    974|                ((b) > 671 ? 6 : \
  |  |  ------------------
  |  |  |  Branch (312:18): [True: 25, False: 949]
  |  |  ------------------
  |  |  313|    974|                 (b) > 239 ? 5 : \
  |  |  ------------------
  |  |  |  Branch (313:18): [True: 23, False: 926]
  |  |  ------------------
  |  |  314|    949|                 (b) >  79 ? 4 : \
  |  |  ------------------
  |  |  |  Branch (314:18): [True: 25, False: 901]
  |  |  ------------------
  |  |  315|    926|                 (b) >  23 ? 3 : 1)
  |  |  ------------------
  |  |  |  Branch (315:18): [True: 54, False: 847]
  |  |  ------------------
  ------------------
  375|    974|    if (window > 1) {
  ------------------
  |  Branch (375:9): [True: 127, False: 847]
  ------------------
  376|    127|        if (!bn_mul_mont_fixed_top(d, val[0], val[0], mont, ctx))
  ------------------
  |  Branch (376:13): [True: 0, False: 127]
  ------------------
  377|      0|            goto err;           /* 2 */
  378|    127|        j = 1 << (window - 1);
  379|  1.58k|        for (i = 1; i < j; i++) {
  ------------------
  |  Branch (379:21): [True: 1.45k, False: 127]
  ------------------
  380|  1.45k|            if (((val[i] = BN_CTX_get(ctx)) == NULL) ||
  ------------------
  |  Branch (380:17): [True: 0, False: 1.45k]
  ------------------
  381|  1.45k|                !bn_mul_mont_fixed_top(val[i], val[i - 1], d, mont, ctx))
  ------------------
  |  Branch (381:17): [True: 0, False: 1.45k]
  ------------------
  382|      0|                goto err;
  383|  1.45k|        }
  384|    127|    }
  385|       |
  386|    974|    start = 1;                  /* This is used to avoid multiplication etc
  387|       |                                 * when there is only the value '1' in the
  388|       |                                 * buffer. */
  389|    974|    wvalue = 0;                 /* The 'value' of the window */
  390|    974|    wstart = bits - 1;          /* The top bit of the window */
  391|    974|    wend = 0;                   /* The bottom bit of the window */
  392|       |
  393|    974|#if 1                           /* by Shay Gueron's suggestion */
  394|    974|    j = m->top;                 /* borrow j */
  395|    974|    if (m->d[j - 1] & (((BN_ULONG)1) << (BN_BITS2 - 1))) {
  ------------------
  |  |   48|    974|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|    974|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (395:9): [True: 158, False: 816]
  ------------------
  396|    158|        if (bn_wexpand(r, j) == NULL)
  ------------------
  |  Branch (396:13): [True: 0, False: 158]
  ------------------
  397|      0|            goto err;
  398|       |        /* 2^(top*BN_BITS2) - m */
  399|    158|        r->d[0] = (0 - m->d[0]) & BN_MASK2;
  ------------------
  |  |   87|    158|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  400|    413|        for (i = 1; i < j; i++)
  ------------------
  |  Branch (400:21): [True: 255, False: 158]
  ------------------
  401|    255|            r->d[i] = (~m->d[i]) & BN_MASK2;
  ------------------
  |  |   87|    413|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  402|    158|        r->top = j;
  403|    158|        r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|    158|#  define BN_FLG_FIXED_TOP 0
  ------------------
  404|    158|    } else
  405|    816|#endif
  406|    816|    if (!bn_to_mont_fixed_top(r, BN_value_one(), mont, ctx))
  ------------------
  |  Branch (406:9): [True: 0, False: 816]
  ------------------
  407|      0|        goto err;
  408|  67.1k|    for (;;) {
  409|  67.1k|        if (BN_is_bit_set(p, wstart) == 0) {
  ------------------
  |  Branch (409:13): [True: 49.8k, False: 17.2k]
  ------------------
  410|  49.8k|            if (!start) {
  ------------------
  |  Branch (410:17): [True: 49.8k, False: 0]
  ------------------
  411|  49.8k|                if (!bn_mul_mont_fixed_top(r, r, r, mont, ctx))
  ------------------
  |  Branch (411:21): [True: 0, False: 49.8k]
  ------------------
  412|      0|                    goto err;
  413|  49.8k|            }
  414|  49.8k|            if (wstart == 0)
  ------------------
  |  Branch (414:17): [True: 270, False: 49.6k]
  ------------------
  415|    270|                break;
  416|  49.6k|            wstart--;
  417|  49.6k|            continue;
  418|  49.8k|        }
  419|       |        /*
  420|       |         * We now have wstart on a 'set' bit, we now need to work out how bit
  421|       |         * a window to do.  To do this we need to scan forward until the last
  422|       |         * set bit before the end of the window
  423|       |         */
  424|  17.2k|        j = wstart;
  425|  17.2k|        wvalue = 1;
  426|  17.2k|        wend = 0;
  427|  74.1k|        for (i = 1; i < window; i++) {
  ------------------
  |  Branch (427:21): [True: 56.9k, False: 17.1k]
  ------------------
  428|  56.9k|            if (wstart - i < 0)
  ------------------
  |  Branch (428:17): [True: 70, False: 56.8k]
  ------------------
  429|     70|                break;
  430|  56.8k|            if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (430:17): [True: 42.6k, False: 14.2k]
  ------------------
  431|  42.6k|                wvalue <<= (i - wend);
  432|  42.6k|                wvalue |= 1;
  433|  42.6k|                wend = i;
  434|  42.6k|            }
  435|  56.8k|        }
  436|       |
  437|       |        /* wend is the size of the current window */
  438|  17.2k|        j = wend + 1;
  439|       |        /* add the 'bytes above' */
  440|  17.2k|        if (!start)
  ------------------
  |  Branch (440:13): [True: 16.2k, False: 974]
  ------------------
  441|  81.8k|            for (i = 0; i < j; i++) {
  ------------------
  |  Branch (441:25): [True: 65.5k, False: 16.2k]
  ------------------
  442|  65.5k|                if (!bn_mul_mont_fixed_top(r, r, r, mont, ctx))
  ------------------
  |  Branch (442:21): [True: 0, False: 65.5k]
  ------------------
  443|      0|                    goto err;
  444|  65.5k|            }
  445|       |
  446|       |        /* wvalue will be an odd number < 2^window */
  447|  17.2k|        if (!bn_mul_mont_fixed_top(r, r, val[wvalue >> 1], mont, ctx))
  ------------------
  |  Branch (447:13): [True: 0, False: 17.2k]
  ------------------
  448|      0|            goto err;
  449|       |
  450|       |        /* move the 'window' down further */
  451|  17.2k|        wstart -= wend + 1;
  452|  17.2k|        wvalue = 0;
  453|  17.2k|        start = 0;
  454|  17.2k|        if (wstart < 0)
  ------------------
  |  Branch (454:13): [True: 704, False: 16.5k]
  ------------------
  455|    704|            break;
  456|  17.2k|    }
  457|       |    /*
  458|       |     * Done with zero-padded intermediate BIGNUMs. Final BN_from_montgomery
  459|       |     * removes padding [if any] and makes return value suitable for public
  460|       |     * API consumer.
  461|       |     */
  462|       |#if defined(SPARC_T4_MONT)
  463|       |    if (OPENSSL_sparcv9cap_P[0] & (SPARCV9_VIS3 | SPARCV9_PREFER_FPU)) {
  464|       |        j = mont->N.top;        /* borrow j */
  465|       |        val[0]->d[0] = 1;       /* borrow val[0] */
  466|       |        for (i = 1; i < j; i++)
  467|       |            val[0]->d[i] = 0;
  468|       |        val[0]->top = j;
  469|       |        if (!BN_mod_mul_montgomery(rr, r, val[0], mont, ctx))
  470|       |            goto err;
  471|       |    } else
  472|       |#endif
  473|    974|    if (!BN_from_montgomery(rr, r, mont, ctx))
  ------------------
  |  Branch (473:9): [True: 0, False: 974]
  ------------------
  474|      0|        goto err;
  475|    974|    ret = 1;
  476|    974| err:
  477|    974|    if (in_mont == NULL)
  ------------------
  |  Branch (477:9): [True: 974, False: 0]
  ------------------
  478|    974|        BN_MONT_CTX_free(mont);
  479|    974|    BN_CTX_end(ctx);
  480|    974|    bn_check_top(rr);
  481|    974|    return ret;
  482|    974|}
BN_mod_exp_mont_word:
 1160|    430|{
 1161|    430|    BN_MONT_CTX *mont = NULL;
 1162|    430|    int b, bits, ret = 0;
 1163|    430|    int r_is_one;
 1164|    430|    BN_ULONG w, next_w;
  ------------------
  |  |   31|    430|#  define BN_ULONG        unsigned long
  ------------------
 1165|    430|    BIGNUM *r, *t;
 1166|    430|    BIGNUM *swap_tmp;
 1167|    430|#define BN_MOD_MUL_WORD(r, w, m) \
 1168|    430|                (BN_mul_word(r, (w)) && \
 1169|    430|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
 1170|    430|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
 1171|       |    /*
 1172|       |     * BN_MOD_MUL_WORD is only used with 'w' large, so the BN_ucmp test is
 1173|       |     * probably more overhead than always using BN_mod (which uses BN_copy if
 1174|       |     * a similar test returns true).
 1175|       |     */
 1176|       |    /*
 1177|       |     * We can use BN_mod and do not need BN_nnmod because our accumulator is
 1178|       |     * never negative (the result of BN_mod does not depend on the sign of
 1179|       |     * the modulus).
 1180|       |     */
 1181|    430|#define BN_TO_MONTGOMERY_WORD(r, w, mont) \
 1182|    430|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
 1183|       |
 1184|    430|    if (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   61|    430|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1184:9): [True: 0, False: 430]
  ------------------
 1185|    430|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0) {
  ------------------
  |  |   61|    430|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1185:16): [True: 0, False: 430]
  ------------------
 1186|       |        /* BN_FLG_CONSTTIME only supported by BN_mod_exp_mont() */
 1187|      0|        BNerr(BN_F_BN_MOD_EXP_MONT_WORD, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
 1188|      0|        return 0;
 1189|      0|    }
 1190|       |
 1191|    430|    bn_check_top(p);
 1192|    430|    bn_check_top(m);
 1193|       |
 1194|    430|    if (!BN_is_odd(m)) {
  ------------------
  |  Branch (1194:9): [True: 0, False: 430]
  ------------------
 1195|      0|        BNerr(BN_F_BN_MOD_EXP_MONT_WORD, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
 1196|      0|        return 0;
 1197|      0|    }
 1198|    430|    if (m->top == 1)
  ------------------
  |  Branch (1198:9): [True: 359, False: 71]
  ------------------
 1199|    359|        a %= m->d[0];           /* make sure that 'a' is reduced */
 1200|       |
 1201|    430|    bits = BN_num_bits(p);
 1202|    430|    if (bits == 0) {
  ------------------
  |  Branch (1202:9): [True: 9, False: 421]
  ------------------
 1203|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
 1204|      9|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (1204:13): [True: 1, False: 8]
  ------------------
 1205|      1|            ret = 1;
 1206|      1|            BN_zero(rr);
  ------------------
  |  |  196|      1|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
 1207|      8|        } else {
 1208|      8|            ret = BN_one(rr);
  ------------------
  |  |  189|      8|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
 1209|      8|        }
 1210|      9|        return ret;
 1211|      9|    }
 1212|    421|    if (a == 0) {
  ------------------
  |  Branch (1212:9): [True: 2, False: 419]
  ------------------
 1213|      2|        BN_zero(rr);
  ------------------
  |  |  196|      2|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
 1214|      2|        ret = 1;
 1215|      2|        return ret;
 1216|      2|    }
 1217|       |
 1218|    419|    BN_CTX_start(ctx);
 1219|    419|    r = BN_CTX_get(ctx);
 1220|    419|    t = BN_CTX_get(ctx);
 1221|    419|    if (t == NULL)
  ------------------
  |  Branch (1221:9): [True: 0, False: 419]
  ------------------
 1222|      0|        goto err;
 1223|       |
 1224|    419|    if (in_mont != NULL)
  ------------------
  |  Branch (1224:9): [True: 0, False: 419]
  ------------------
 1225|      0|        mont = in_mont;
 1226|    419|    else {
 1227|    419|        if ((mont = BN_MONT_CTX_new()) == NULL)
  ------------------
  |  Branch (1227:13): [True: 0, False: 419]
  ------------------
 1228|      0|            goto err;
 1229|    419|        if (!BN_MONT_CTX_set(mont, m, ctx))
  ------------------
  |  Branch (1229:13): [True: 0, False: 419]
  ------------------
 1230|      0|            goto err;
 1231|    419|    }
 1232|       |
 1233|    419|    r_is_one = 1;               /* except for Montgomery factor */
 1234|       |
 1235|       |    /* bits-1 >= 0 */
 1236|       |
 1237|       |    /* The result is accumulated in the product r*w. */
 1238|    419|    w = a;                      /* bit 'bits-1' of 'p' is always set */
 1239|  40.3k|    for (b = bits - 2; b >= 0; b--) {
  ------------------
  |  Branch (1239:24): [True: 39.8k, False: 419]
  ------------------
 1240|       |        /* First, square r*w. */
 1241|  39.8k|        next_w = w * w;
 1242|  39.8k|        if ((next_w / w) != w) { /* overflow */
  ------------------
  |  Branch (1242:13): [True: 6.03k, False: 33.8k]
  ------------------
 1243|  6.03k|            if (r_is_one) {
  ------------------
  |  Branch (1243:17): [True: 304, False: 5.72k]
  ------------------
 1244|    304|                if (!BN_TO_MONTGOMERY_WORD(r, w, mont))
  ------------------
  |  | 1182|    304|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
  |  |  ------------------
  |  |  |  Branch (1182:18): [True: 304, False: 0]
  |  |  |  Branch (1182:41): [True: 304, False: 0]
  |  |  ------------------
  ------------------
 1245|      0|                    goto err;
 1246|    304|                r_is_one = 0;
 1247|  5.72k|            } else {
 1248|  5.72k|                if (!BN_MOD_MUL_WORD(r, w, m))
  ------------------
  |  | 1168|  5.72k|                (BN_mul_word(r, (w)) && \
  |  |  ------------------
  |  |  |  Branch (1168:18): [True: 5.72k, False: 0]
  |  |  ------------------
  |  | 1169|  5.72k|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
  |  | 1170|  5.72k|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
  |  |  ------------------
  |  |  |  |  247|  11.4k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (247:30): [True: 5.72k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (1170:50): [True: 5.72k, False: 0]
  |  |  ------------------
  ------------------
 1249|      0|                    goto err;
 1250|  5.72k|            }
 1251|  6.03k|            next_w = 1;
 1252|  6.03k|        }
 1253|  39.8k|        w = next_w;
 1254|  39.8k|        if (!r_is_one) {
  ------------------
  |  Branch (1254:13): [True: 39.0k, False: 844]
  ------------------
 1255|  39.0k|            if (!BN_mod_mul_montgomery(r, r, r, mont, ctx))
  ------------------
  |  Branch (1255:17): [True: 0, False: 39.0k]
  ------------------
 1256|      0|                goto err;
 1257|  39.0k|        }
 1258|       |
 1259|       |        /* Second, multiply r*w by 'a' if exponent bit is set. */
 1260|  39.8k|        if (BN_is_bit_set(p, b)) {
  ------------------
  |  Branch (1260:13): [True: 20.5k, False: 19.3k]
  ------------------
 1261|  20.5k|            next_w = w * a;
 1262|  20.5k|            if ((next_w / a) != w) { /* overflow */
  ------------------
  |  Branch (1262:17): [True: 9.40k, False: 11.1k]
  ------------------
 1263|  9.40k|                if (r_is_one) {
  ------------------
  |  Branch (1263:21): [True: 94, False: 9.30k]
  ------------------
 1264|     94|                    if (!BN_TO_MONTGOMERY_WORD(r, w, mont))
  ------------------
  |  | 1182|     94|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
  |  |  ------------------
  |  |  |  Branch (1182:18): [True: 94, False: 0]
  |  |  |  Branch (1182:41): [True: 94, False: 0]
  |  |  ------------------
  ------------------
 1265|      0|                        goto err;
 1266|     94|                    r_is_one = 0;
 1267|  9.30k|                } else {
 1268|  9.30k|                    if (!BN_MOD_MUL_WORD(r, w, m))
  ------------------
  |  | 1168|  9.30k|                (BN_mul_word(r, (w)) && \
  |  |  ------------------
  |  |  |  Branch (1168:18): [True: 9.30k, False: 0]
  |  |  ------------------
  |  | 1169|  9.30k|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
  |  | 1170|  9.30k|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
  |  |  ------------------
  |  |  |  |  247|  18.6k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (247:30): [True: 9.30k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (1170:50): [True: 9.30k, False: 0]
  |  |  ------------------
  ------------------
 1269|      0|                        goto err;
 1270|  9.30k|                }
 1271|  9.40k|                next_w = a;
 1272|  9.40k|            }
 1273|  20.5k|            w = next_w;
 1274|  20.5k|        }
 1275|  39.8k|    }
 1276|       |
 1277|       |    /* Finally, set r:=r*w. */
 1278|    419|    if (w != 1) {
  ------------------
  |  Branch (1278:9): [True: 381, False: 38]
  ------------------
 1279|    381|        if (r_is_one) {
  ------------------
  |  Branch (1279:13): [True: 15, False: 366]
  ------------------
 1280|     15|            if (!BN_TO_MONTGOMERY_WORD(r, w, mont))
  ------------------
  |  | 1182|     15|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
  |  |  ------------------
  |  |  |  Branch (1182:18): [True: 15, False: 0]
  |  |  |  Branch (1182:41): [True: 15, False: 0]
  |  |  ------------------
  ------------------
 1281|      0|                goto err;
 1282|     15|            r_is_one = 0;
 1283|    366|        } else {
 1284|    366|            if (!BN_MOD_MUL_WORD(r, w, m))
  ------------------
  |  | 1168|    366|                (BN_mul_word(r, (w)) && \
  |  |  ------------------
  |  |  |  Branch (1168:18): [True: 366, False: 0]
  |  |  ------------------
  |  | 1169|    366|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
  |  | 1170|    366|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
  |  |  ------------------
  |  |  |  |  247|    732|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (247:30): [True: 366, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (1170:50): [True: 366, False: 0]
  |  |  ------------------
  ------------------
 1285|      0|                goto err;
 1286|    366|        }
 1287|    381|    }
 1288|       |
 1289|    419|    if (r_is_one) {             /* can happen only if a == 1 */
  ------------------
  |  Branch (1289:9): [True: 6, False: 413]
  ------------------
 1290|      6|        if (!BN_one(rr))
  ------------------
  |  |  189|      6|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (1290:13): [True: 0, False: 6]
  ------------------
 1291|      0|            goto err;
 1292|    413|    } else {
 1293|    413|        if (!BN_from_montgomery(rr, r, mont, ctx))
  ------------------
  |  Branch (1293:13): [True: 0, False: 413]
  ------------------
 1294|      0|            goto err;
 1295|    413|    }
 1296|    419|    ret = 1;
 1297|    419| err:
 1298|    419|    if (in_mont == NULL)
  ------------------
  |  Branch (1298:9): [True: 419, False: 0]
  ------------------
 1299|    419|        BN_MONT_CTX_free(mont);
 1300|    419|    BN_CTX_end(ctx);
 1301|    419|    bn_check_top(rr);
 1302|    419|    return ret;
 1303|    419|}
BN_mod_exp_simple:
 1308|  3.19k|{
 1309|  3.19k|    int i, j, bits, ret = 0, wstart, wend, window, wvalue;
 1310|  3.19k|    int start = 1;
 1311|  3.19k|    BIGNUM *d;
 1312|       |    /* Table of variables obtained from 'ctx' */
 1313|  3.19k|    BIGNUM *val[TABLE_SIZE];
 1314|       |
 1315|  3.19k|    if (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   61|  3.19k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1315:9): [True: 0, False: 3.19k]
  ------------------
 1316|  3.19k|            || BN_get_flags(a, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   61|  3.19k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1316:16): [True: 0, False: 3.19k]
  ------------------
 1317|  3.19k|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0) {
  ------------------
  |  |   61|  3.19k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1317:16): [True: 0, False: 3.19k]
  ------------------
 1318|       |        /* BN_FLG_CONSTTIME only supported by BN_mod_exp_mont() */
 1319|      0|        BNerr(BN_F_BN_MOD_EXP_SIMPLE, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
 1320|      0|        return 0;
 1321|      0|    }
 1322|       |
 1323|  3.19k|    bits = BN_num_bits(p);
 1324|  3.19k|    if (bits == 0) {
  ------------------
  |  Branch (1324:9): [True: 182, False: 3.01k]
  ------------------
 1325|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
 1326|    182|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (1326:13): [True: 4, False: 178]
  ------------------
 1327|      4|            ret = 1;
 1328|      4|            BN_zero(r);
  ------------------
  |  |  196|      4|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
 1329|    178|        } else {
 1330|    178|            ret = BN_one(r);
  ------------------
  |  |  189|    178|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
 1331|    178|        }
 1332|    182|        return ret;
 1333|    182|    }
 1334|       |
 1335|  3.01k|    BN_CTX_start(ctx);
 1336|  3.01k|    d = BN_CTX_get(ctx);
 1337|  3.01k|    val[0] = BN_CTX_get(ctx);
 1338|  3.01k|    if (val[0] == NULL)
  ------------------
  |  Branch (1338:9): [True: 0, False: 3.01k]
  ------------------
 1339|      0|        goto err;
 1340|       |
 1341|  3.01k|    if (!BN_nnmod(val[0], a, m, ctx))
  ------------------
  |  Branch (1341:9): [True: 0, False: 3.01k]
  ------------------
 1342|      0|        goto err;               /* 1 */
 1343|  3.01k|    if (BN_is_zero(val[0])) {
  ------------------
  |  Branch (1343:9): [True: 750, False: 2.26k]
  ------------------
 1344|    750|        BN_zero(r);
  ------------------
  |  |  196|    750|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
 1345|    750|        ret = 1;
 1346|    750|        goto err;
 1347|    750|    }
 1348|       |
 1349|  2.26k|    window = BN_window_bits_for_exponent_size(bits);
  ------------------
  |  |  312|  2.26k|                ((b) > 671 ? 6 : \
  |  |  ------------------
  |  |  |  Branch (312:18): [True: 31, False: 2.23k]
  |  |  ------------------
  |  |  313|  2.26k|                 (b) > 239 ? 5 : \
  |  |  ------------------
  |  |  |  Branch (313:18): [True: 27, False: 2.20k]
  |  |  ------------------
  |  |  314|  2.23k|                 (b) >  79 ? 4 : \
  |  |  ------------------
  |  |  |  Branch (314:18): [True: 94, False: 2.11k]
  |  |  ------------------
  |  |  315|  2.20k|                 (b) >  23 ? 3 : 1)
  |  |  ------------------
  |  |  |  Branch (315:18): [True: 225, False: 1.88k]
  |  |  ------------------
  ------------------
 1350|  2.26k|    if (window > 1) {
  ------------------
  |  Branch (1350:9): [True: 377, False: 1.88k]
  ------------------
 1351|    377|        if (!BN_mod_mul(d, val[0], val[0], m, ctx))
  ------------------
  |  Branch (1351:13): [True: 0, False: 377]
  ------------------
 1352|      0|            goto err;           /* 2 */
 1353|    377|        j = 1 << (window - 1);
 1354|  3.07k|        for (i = 1; i < j; i++) {
  ------------------
  |  Branch (1354:21): [True: 2.69k, False: 377]
  ------------------
 1355|  2.69k|            if (((val[i] = BN_CTX_get(ctx)) == NULL) ||
  ------------------
  |  Branch (1355:17): [True: 0, False: 2.69k]
  ------------------
 1356|  2.69k|                !BN_mod_mul(val[i], val[i - 1], d, m, ctx))
  ------------------
  |  Branch (1356:17): [True: 0, False: 2.69k]
  ------------------
 1357|      0|                goto err;
 1358|  2.69k|        }
 1359|    377|    }
 1360|       |
 1361|  2.26k|    start = 1;                  /* This is used to avoid multiplication etc
 1362|       |                                 * when there is only the value '1' in the
 1363|       |                                 * buffer. */
 1364|  2.26k|    wvalue = 0;                 /* The 'value' of the window */
 1365|  2.26k|    wstart = bits - 1;          /* The top bit of the window */
 1366|  2.26k|    wend = 0;                   /* The bottom bit of the window */
 1367|       |
 1368|  2.26k|    if (!BN_one(r))
  ------------------
  |  |  189|  2.26k|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (1368:9): [True: 0, False: 2.26k]
  ------------------
 1369|      0|        goto err;
 1370|       |
 1371|  77.1k|    for (;;) {
 1372|  77.1k|        if (BN_is_bit_set(p, wstart) == 0) {
  ------------------
  |  Branch (1372:13): [True: 47.9k, False: 29.2k]
  ------------------
 1373|  47.9k|            if (!start)
  ------------------
  |  Branch (1373:17): [True: 47.9k, False: 0]
  ------------------
 1374|  47.9k|                if (!BN_mod_mul(r, r, r, m, ctx))
  ------------------
  |  Branch (1374:21): [True: 0, False: 47.9k]
  ------------------
 1375|      0|                    goto err;
 1376|  47.9k|            if (wstart == 0)
  ------------------
  |  Branch (1376:17): [True: 650, False: 47.2k]
  ------------------
 1377|    650|                break;
 1378|  47.2k|            wstart--;
 1379|  47.2k|            continue;
 1380|  47.9k|        }
 1381|       |        /*
 1382|       |         * We now have wstart on a 'set' bit, we now need to work out how bit
 1383|       |         * a window to do.  To do this we need to scan forward until the last
 1384|       |         * set bit before the end of the window
 1385|       |         */
 1386|  29.2k|        j = wstart;
 1387|  29.2k|        wvalue = 1;
 1388|  29.2k|        wend = 0;
 1389|  98.5k|        for (i = 1; i < window; i++) {
  ------------------
  |  Branch (1389:21): [True: 69.4k, False: 29.0k]
  ------------------
 1390|  69.4k|            if (wstart - i < 0)
  ------------------
  |  Branch (1390:17): [True: 193, False: 69.2k]
  ------------------
 1391|    193|                break;
 1392|  69.2k|            if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (1392:17): [True: 50.6k, False: 18.5k]
  ------------------
 1393|  50.6k|                wvalue <<= (i - wend);
 1394|  50.6k|                wvalue |= 1;
 1395|  50.6k|                wend = i;
 1396|  50.6k|            }
 1397|  69.2k|        }
 1398|       |
 1399|       |        /* wend is the size of the current window */
 1400|  29.2k|        j = wend + 1;
 1401|       |        /* add the 'bytes above' */
 1402|  29.2k|        if (!start)
  ------------------
  |  Branch (1402:13): [True: 27.0k, False: 2.26k]
  ------------------
 1403|   112k|            for (i = 0; i < j; i++) {
  ------------------
  |  Branch (1403:25): [True: 85.8k, False: 27.0k]
  ------------------
 1404|  85.8k|                if (!BN_mod_mul(r, r, r, m, ctx))
  ------------------
  |  Branch (1404:21): [True: 0, False: 85.8k]
  ------------------
 1405|      0|                    goto err;
 1406|  85.8k|            }
 1407|       |
 1408|       |        /* wvalue will be an odd number < 2^window */
 1409|  29.2k|        if (!BN_mod_mul(r, r, val[wvalue >> 1], m, ctx))
  ------------------
  |  Branch (1409:13): [True: 0, False: 29.2k]
  ------------------
 1410|      0|            goto err;
 1411|       |
 1412|       |        /* move the 'window' down further */
 1413|  29.2k|        wstart -= wend + 1;
 1414|  29.2k|        wvalue = 0;
 1415|  29.2k|        start = 0;
 1416|  29.2k|        if (wstart < 0)
  ------------------
  |  Branch (1416:13): [True: 1.61k, False: 27.6k]
  ------------------
 1417|  1.61k|            break;
 1418|  29.2k|    }
 1419|  2.26k|    ret = 1;
 1420|  3.01k| err:
 1421|  3.01k|    BN_CTX_end(ctx);
 1422|  3.01k|    bn_check_top(r);
 1423|  3.01k|    return ret;
 1424|  2.26k|}

int_bn_mod_inverse:
  200|  1.35k|{
  201|  1.35k|    BIGNUM *A, *B, *X, *Y, *M, *D, *T, *R = NULL;
  202|  1.35k|    BIGNUM *ret = NULL;
  203|  1.35k|    int sign;
  204|       |
  205|       |    /* This is invalid input so we don't worry about constant time here */
  206|  1.35k|    if (BN_abs_is_word(n, 1) || BN_is_zero(n)) {
  ------------------
  |  Branch (206:9): [True: 0, False: 1.35k]
  |  Branch (206:33): [True: 0, False: 1.35k]
  ------------------
  207|      0|        *pnoinv = 1;
  208|      0|        return NULL;
  209|      0|    }
  210|       |
  211|  1.35k|    *pnoinv = 0;
  212|       |
  213|  1.35k|    if ((BN_get_flags(a, BN_FLG_CONSTTIME) != 0)
  ------------------
  |  |   61|  1.35k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (213:9): [True: 0, False: 1.35k]
  ------------------
  214|  1.35k|        || (BN_get_flags(n, BN_FLG_CONSTTIME) != 0)) {
  ------------------
  |  |   61|  1.35k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (214:12): [True: 0, False: 1.35k]
  ------------------
  215|      0|        return bn_mod_inverse_no_branch(in, a, n, ctx, pnoinv);
  216|      0|    }
  217|       |
  218|  1.35k|    bn_check_top(a);
  219|  1.35k|    bn_check_top(n);
  220|       |
  221|  1.35k|    BN_CTX_start(ctx);
  222|  1.35k|    A = BN_CTX_get(ctx);
  223|  1.35k|    B = BN_CTX_get(ctx);
  224|  1.35k|    X = BN_CTX_get(ctx);
  225|  1.35k|    D = BN_CTX_get(ctx);
  226|  1.35k|    M = BN_CTX_get(ctx);
  227|  1.35k|    Y = BN_CTX_get(ctx);
  228|  1.35k|    T = BN_CTX_get(ctx);
  229|  1.35k|    if (T == NULL)
  ------------------
  |  Branch (229:9): [True: 0, False: 1.35k]
  ------------------
  230|      0|        goto err;
  231|       |
  232|  1.35k|    if (in == NULL)
  ------------------
  |  Branch (232:9): [True: 0, False: 1.35k]
  ------------------
  233|      0|        R = BN_new();
  234|  1.35k|    else
  235|  1.35k|        R = in;
  236|  1.35k|    if (R == NULL)
  ------------------
  |  Branch (236:9): [True: 0, False: 1.35k]
  ------------------
  237|      0|        goto err;
  238|       |
  239|  1.35k|    if (!BN_one(X))
  ------------------
  |  |  189|  1.35k|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (239:9): [True: 0, False: 1.35k]
  ------------------
  240|      0|        goto err;
  241|  1.35k|    BN_zero(Y);
  ------------------
  |  |  196|  1.35k|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  242|  1.35k|    if (BN_copy(B, a) == NULL)
  ------------------
  |  Branch (242:9): [True: 0, False: 1.35k]
  ------------------
  243|      0|        goto err;
  244|  1.35k|    if (BN_copy(A, n) == NULL)
  ------------------
  |  Branch (244:9): [True: 0, False: 1.35k]
  ------------------
  245|      0|        goto err;
  246|  1.35k|    A->neg = 0;
  247|  1.35k|    if (B->neg || (BN_ucmp(B, A) >= 0)) {
  ------------------
  |  Branch (247:9): [True: 0, False: 1.35k]
  |  Branch (247:19): [True: 1.35k, False: 0]
  ------------------
  248|  1.35k|        if (!BN_nnmod(B, B, A, ctx))
  ------------------
  |  Branch (248:13): [True: 0, False: 1.35k]
  ------------------
  249|      0|            goto err;
  250|  1.35k|    }
  251|  1.35k|    sign = -1;
  252|       |    /*-
  253|       |     * From  B = a mod |n|,  A = |n|  it follows that
  254|       |     *
  255|       |     *      0 <= B < A,
  256|       |     *     -sign*X*a  ==  B   (mod |n|),
  257|       |     *      sign*Y*a  ==  A   (mod |n|).
  258|       |     */
  259|       |
  260|  1.35k|    if (BN_is_odd(n) && (BN_num_bits(n) <= 2048)) {
  ------------------
  |  Branch (260:9): [True: 1.35k, False: 0]
  |  Branch (260:25): [True: 1.35k, False: 0]
  ------------------
  261|       |        /*
  262|       |         * Binary inversion algorithm; requires odd modulus. This is faster
  263|       |         * than the general algorithm if the modulus is sufficiently small
  264|       |         * (about 400 .. 500 bits on 32-bit systems, but much more on 64-bit
  265|       |         * systems)
  266|       |         */
  267|  1.35k|        int shift;
  268|       |
  269|  53.7k|        while (!BN_is_zero(B)) {
  ------------------
  |  Branch (269:16): [True: 52.3k, False: 1.35k]
  ------------------
  270|       |            /*-
  271|       |             *      0 < B < |n|,
  272|       |             *      0 < A <= |n|,
  273|       |             * (1) -sign*X*a  ==  B   (mod |n|),
  274|       |             * (2)  sign*Y*a  ==  A   (mod |n|)
  275|       |             */
  276|       |
  277|       |            /*
  278|       |             * Now divide B by the maximum possible power of two in the
  279|       |             * integers, and divide X by the same value mod |n|. When we're
  280|       |             * done, (1) still holds.
  281|       |             */
  282|  52.3k|            shift = 0;
  283|  71.2k|            while (!BN_is_bit_set(B, shift)) { /* note that 0 < B */
  ------------------
  |  Branch (283:20): [True: 18.8k, False: 52.3k]
  ------------------
  284|  18.8k|                shift++;
  285|       |
  286|  18.8k|                if (BN_is_odd(X)) {
  ------------------
  |  Branch (286:21): [True: 8.40k, False: 10.4k]
  ------------------
  287|  8.40k|                    if (!BN_uadd(X, X, n))
  ------------------
  |  Branch (287:25): [True: 0, False: 8.40k]
  ------------------
  288|      0|                        goto err;
  289|  8.40k|                }
  290|       |                /*
  291|       |                 * now X is even, so we can easily divide it by two
  292|       |                 */
  293|  18.8k|                if (!BN_rshift1(X, X))
  ------------------
  |  Branch (293:21): [True: 0, False: 18.8k]
  ------------------
  294|      0|                    goto err;
  295|  18.8k|            }
  296|  52.3k|            if (shift > 0) {
  ------------------
  |  Branch (296:17): [True: 13.9k, False: 38.4k]
  ------------------
  297|  13.9k|                if (!BN_rshift(B, B, shift))
  ------------------
  |  Branch (297:21): [True: 0, False: 13.9k]
  ------------------
  298|      0|                    goto err;
  299|  13.9k|            }
  300|       |
  301|       |            /*
  302|       |             * Same for A and Y.  Afterwards, (2) still holds.
  303|       |             */
  304|  52.3k|            shift = 0;
  305|  94.2k|            while (!BN_is_bit_set(A, shift)) { /* note that 0 < A */
  ------------------
  |  Branch (305:20): [True: 41.8k, False: 52.3k]
  ------------------
  306|  41.8k|                shift++;
  307|       |
  308|  41.8k|                if (BN_is_odd(Y)) {
  ------------------
  |  Branch (308:21): [True: 21.8k, False: 19.9k]
  ------------------
  309|  21.8k|                    if (!BN_uadd(Y, Y, n))
  ------------------
  |  Branch (309:25): [True: 0, False: 21.8k]
  ------------------
  310|      0|                        goto err;
  311|  21.8k|                }
  312|       |                /* now Y is even */
  313|  41.8k|                if (!BN_rshift1(Y, Y))
  ------------------
  |  Branch (313:21): [True: 0, False: 41.8k]
  ------------------
  314|      0|                    goto err;
  315|  41.8k|            }
  316|  52.3k|            if (shift > 0) {
  ------------------
  |  Branch (316:17): [True: 37.5k, False: 14.8k]
  ------------------
  317|  37.5k|                if (!BN_rshift(A, A, shift))
  ------------------
  |  Branch (317:21): [True: 0, False: 37.5k]
  ------------------
  318|      0|                    goto err;
  319|  37.5k|            }
  320|       |
  321|       |            /*-
  322|       |             * We still have (1) and (2).
  323|       |             * Both  A  and  B  are odd.
  324|       |             * The following computations ensure that
  325|       |             *
  326|       |             *     0 <= B < |n|,
  327|       |             *      0 < A < |n|,
  328|       |             * (1) -sign*X*a  ==  B   (mod |n|),
  329|       |             * (2)  sign*Y*a  ==  A   (mod |n|),
  330|       |             *
  331|       |             * and that either  A  or  B  is even in the next iteration.
  332|       |             */
  333|  52.3k|            if (BN_ucmp(B, A) >= 0) {
  ------------------
  |  Branch (333:17): [True: 14.8k, False: 37.5k]
  ------------------
  334|       |                /* -sign*(X + Y)*a == B - A  (mod |n|) */
  335|  14.8k|                if (!BN_uadd(X, X, Y))
  ------------------
  |  Branch (335:21): [True: 0, False: 14.8k]
  ------------------
  336|      0|                    goto err;
  337|       |                /*
  338|       |                 * NB: we could use BN_mod_add_quick(X, X, Y, n), but that
  339|       |                 * actually makes the algorithm slower
  340|       |                 */
  341|  14.8k|                if (!BN_usub(B, B, A))
  ------------------
  |  Branch (341:21): [True: 0, False: 14.8k]
  ------------------
  342|      0|                    goto err;
  343|  37.5k|            } else {
  344|       |                /*  sign*(X + Y)*a == A - B  (mod |n|) */
  345|  37.5k|                if (!BN_uadd(Y, Y, X))
  ------------------
  |  Branch (345:21): [True: 0, False: 37.5k]
  ------------------
  346|      0|                    goto err;
  347|       |                /*
  348|       |                 * as above, BN_mod_add_quick(Y, Y, X, n) would slow things down
  349|       |                 */
  350|  37.5k|                if (!BN_usub(A, A, B))
  ------------------
  |  Branch (350:21): [True: 0, False: 37.5k]
  ------------------
  351|      0|                    goto err;
  352|  37.5k|            }
  353|  52.3k|        }
  354|  1.35k|    } else {
  355|       |        /* general inversion algorithm */
  356|       |
  357|      0|        while (!BN_is_zero(B)) {
  ------------------
  |  Branch (357:16): [True: 0, False: 0]
  ------------------
  358|      0|            BIGNUM *tmp;
  359|       |
  360|       |            /*-
  361|       |             *      0 < B < A,
  362|       |             * (*) -sign*X*a  ==  B   (mod |n|),
  363|       |             *      sign*Y*a  ==  A   (mod |n|)
  364|       |             */
  365|       |
  366|       |            /* (D, M) := (A/B, A%B) ... */
  367|      0|            if (BN_num_bits(A) == BN_num_bits(B)) {
  ------------------
  |  Branch (367:17): [True: 0, False: 0]
  ------------------
  368|      0|                if (!BN_one(D))
  ------------------
  |  |  189|      0|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (368:21): [True: 0, False: 0]
  ------------------
  369|      0|                    goto err;
  370|      0|                if (!BN_sub(M, A, B))
  ------------------
  |  Branch (370:21): [True: 0, False: 0]
  ------------------
  371|      0|                    goto err;
  372|      0|            } else if (BN_num_bits(A) == BN_num_bits(B) + 1) {
  ------------------
  |  Branch (372:24): [True: 0, False: 0]
  ------------------
  373|       |                /* A/B is 1, 2, or 3 */
  374|      0|                if (!BN_lshift1(T, B))
  ------------------
  |  Branch (374:21): [True: 0, False: 0]
  ------------------
  375|      0|                    goto err;
  376|      0|                if (BN_ucmp(A, T) < 0) {
  ------------------
  |  Branch (376:21): [True: 0, False: 0]
  ------------------
  377|       |                    /* A < 2*B, so D=1 */
  378|      0|                    if (!BN_one(D))
  ------------------
  |  |  189|      0|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (378:25): [True: 0, False: 0]
  ------------------
  379|      0|                        goto err;
  380|      0|                    if (!BN_sub(M, A, B))
  ------------------
  |  Branch (380:25): [True: 0, False: 0]
  ------------------
  381|      0|                        goto err;
  382|      0|                } else {
  383|       |                    /* A >= 2*B, so D=2 or D=3 */
  384|      0|                    if (!BN_sub(M, A, T))
  ------------------
  |  Branch (384:25): [True: 0, False: 0]
  ------------------
  385|      0|                        goto err;
  386|      0|                    if (!BN_add(D, T, B))
  ------------------
  |  Branch (386:25): [True: 0, False: 0]
  ------------------
  387|      0|                        goto err; /* use D (:= 3*B) as temp */
  388|      0|                    if (BN_ucmp(A, D) < 0) {
  ------------------
  |  Branch (388:25): [True: 0, False: 0]
  ------------------
  389|       |                        /* A < 3*B, so D=2 */
  390|      0|                        if (!BN_set_word(D, 2))
  ------------------
  |  Branch (390:29): [True: 0, False: 0]
  ------------------
  391|      0|                            goto err;
  392|       |                        /*
  393|       |                         * M (= A - 2*B) already has the correct value
  394|       |                         */
  395|      0|                    } else {
  396|       |                        /* only D=3 remains */
  397|      0|                        if (!BN_set_word(D, 3))
  ------------------
  |  Branch (397:29): [True: 0, False: 0]
  ------------------
  398|      0|                            goto err;
  399|       |                        /*
  400|       |                         * currently M = A - 2*B, but we need M = A - 3*B
  401|       |                         */
  402|      0|                        if (!BN_sub(M, M, B))
  ------------------
  |  Branch (402:29): [True: 0, False: 0]
  ------------------
  403|      0|                            goto err;
  404|      0|                    }
  405|      0|                }
  406|      0|            } else {
  407|      0|                if (!BN_div(D, M, A, B, ctx))
  ------------------
  |  Branch (407:21): [True: 0, False: 0]
  ------------------
  408|      0|                    goto err;
  409|      0|            }
  410|       |
  411|       |            /*-
  412|       |             * Now
  413|       |             *      A = D*B + M;
  414|       |             * thus we have
  415|       |             * (**)  sign*Y*a  ==  D*B + M   (mod |n|).
  416|       |             */
  417|       |
  418|      0|            tmp = A;    /* keep the BIGNUM object, the value does not matter */
  419|       |
  420|       |            /* (A, B) := (B, A mod B) ... */
  421|      0|            A = B;
  422|      0|            B = M;
  423|       |            /* ... so we have  0 <= B < A  again */
  424|       |
  425|       |            /*-
  426|       |             * Since the former  M  is now  B  and the former  B  is now  A,
  427|       |             * (**) translates into
  428|       |             *       sign*Y*a  ==  D*A + B    (mod |n|),
  429|       |             * i.e.
  430|       |             *       sign*Y*a - D*A  ==  B    (mod |n|).
  431|       |             * Similarly, (*) translates into
  432|       |             *      -sign*X*a  ==  A          (mod |n|).
  433|       |             *
  434|       |             * Thus,
  435|       |             *   sign*Y*a + D*sign*X*a  ==  B  (mod |n|),
  436|       |             * i.e.
  437|       |             *        sign*(Y + D*X)*a  ==  B  (mod |n|).
  438|       |             *
  439|       |             * So if we set  (X, Y, sign) := (Y + D*X, X, -sign), we arrive back at
  440|       |             *      -sign*X*a  ==  B   (mod |n|),
  441|       |             *       sign*Y*a  ==  A   (mod |n|).
  442|       |             * Note that  X  and  Y  stay non-negative all the time.
  443|       |             */
  444|       |
  445|       |            /*
  446|       |             * most of the time D is very small, so we can optimize tmp := D*X+Y
  447|       |             */
  448|      0|            if (BN_is_one(D)) {
  ------------------
  |  Branch (448:17): [True: 0, False: 0]
  ------------------
  449|      0|                if (!BN_add(tmp, X, Y))
  ------------------
  |  Branch (449:21): [True: 0, False: 0]
  ------------------
  450|      0|                    goto err;
  451|      0|            } else {
  452|      0|                if (BN_is_word(D, 2)) {
  ------------------
  |  Branch (452:21): [True: 0, False: 0]
  ------------------
  453|      0|                    if (!BN_lshift1(tmp, X))
  ------------------
  |  Branch (453:25): [True: 0, False: 0]
  ------------------
  454|      0|                        goto err;
  455|      0|                } else if (BN_is_word(D, 4)) {
  ------------------
  |  Branch (455:28): [True: 0, False: 0]
  ------------------
  456|      0|                    if (!BN_lshift(tmp, X, 2))
  ------------------
  |  Branch (456:25): [True: 0, False: 0]
  ------------------
  457|      0|                        goto err;
  458|      0|                } else if (D->top == 1) {
  ------------------
  |  Branch (458:28): [True: 0, False: 0]
  ------------------
  459|      0|                    if (!BN_copy(tmp, X))
  ------------------
  |  Branch (459:25): [True: 0, False: 0]
  ------------------
  460|      0|                        goto err;
  461|      0|                    if (!BN_mul_word(tmp, D->d[0]))
  ------------------
  |  Branch (461:25): [True: 0, False: 0]
  ------------------
  462|      0|                        goto err;
  463|      0|                } else {
  464|      0|                    if (!BN_mul(tmp, D, X, ctx))
  ------------------
  |  Branch (464:25): [True: 0, False: 0]
  ------------------
  465|      0|                        goto err;
  466|      0|                }
  467|      0|                if (!BN_add(tmp, tmp, Y))
  ------------------
  |  Branch (467:21): [True: 0, False: 0]
  ------------------
  468|      0|                    goto err;
  469|      0|            }
  470|       |
  471|      0|            M = Y;      /* keep the BIGNUM object, the value does not matter */
  472|      0|            Y = X;
  473|      0|            X = tmp;
  474|      0|            sign = -sign;
  475|      0|        }
  476|      0|    }
  477|       |
  478|       |    /*-
  479|       |     * The while loop (Euclid's algorithm) ends when
  480|       |     *      A == gcd(a,n);
  481|       |     * we have
  482|       |     *       sign*Y*a  ==  A  (mod |n|),
  483|       |     * where  Y  is non-negative.
  484|       |     */
  485|       |
  486|  1.35k|    if (sign < 0) {
  ------------------
  |  Branch (486:9): [True: 1.35k, False: 0]
  ------------------
  487|  1.35k|        if (!BN_sub(Y, n, Y))
  ------------------
  |  Branch (487:13): [True: 0, False: 1.35k]
  ------------------
  488|      0|            goto err;
  489|  1.35k|    }
  490|       |    /* Now  Y*a  ==  A  (mod |n|).  */
  491|       |
  492|  1.35k|    if (BN_is_one(A)) {
  ------------------
  |  Branch (492:9): [True: 1.35k, False: 0]
  ------------------
  493|       |        /* Y*a == 1  (mod |n|) */
  494|  1.35k|        if (!Y->neg && BN_ucmp(Y, n) < 0) {
  ------------------
  |  Branch (494:13): [True: 720, False: 638]
  |  Branch (494:24): [True: 720, False: 0]
  ------------------
  495|    720|            if (!BN_copy(R, Y))
  ------------------
  |  Branch (495:17): [True: 0, False: 720]
  ------------------
  496|      0|                goto err;
  497|    720|        } else {
  498|    638|            if (!BN_nnmod(R, Y, n, ctx))
  ------------------
  |  Branch (498:17): [True: 0, False: 638]
  ------------------
  499|      0|                goto err;
  500|    638|        }
  501|  1.35k|    } else {
  502|      0|        *pnoinv = 1;
  503|      0|        goto err;
  504|      0|    }
  505|  1.35k|    ret = R;
  506|  1.35k| err:
  507|  1.35k|    if ((ret == NULL) && (in == NULL))
  ------------------
  |  Branch (507:9): [True: 0, False: 1.35k]
  |  Branch (507:26): [True: 0, False: 0]
  ------------------
  508|      0|        BN_free(R);
  509|  1.35k|    BN_CTX_end(ctx);
  510|  1.35k|    bn_check_top(ret);
  511|  1.35k|    return ret;
  512|  1.35k|}
BN_mod_inverse:
  517|  1.35k|{
  518|  1.35k|    BN_CTX *new_ctx = NULL;
  519|  1.35k|    BIGNUM *rv;
  520|  1.35k|    int noinv = 0;
  521|       |
  522|  1.35k|    if (ctx == NULL) {
  ------------------
  |  Branch (522:9): [True: 0, False: 1.35k]
  ------------------
  523|      0|        ctx = new_ctx = BN_CTX_new();
  524|      0|        if (ctx == NULL) {
  ------------------
  |  Branch (524:13): [True: 0, False: 0]
  ------------------
  525|      0|            BNerr(BN_F_BN_MOD_INVERSE, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  526|      0|            return NULL;
  527|      0|        }
  528|      0|    }
  529|       |
  530|  1.35k|    rv = int_bn_mod_inverse(in, a, n, ctx, &noinv);
  531|  1.35k|    if (noinv)
  ------------------
  |  Branch (531:9): [True: 0, False: 1.35k]
  ------------------
  532|  1.35k|        BNerr(BN_F_BN_MOD_INVERSE, BN_R_NO_INVERSE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  533|  1.35k|    BN_CTX_free(new_ctx);
  534|  1.35k|    return rv;
  535|  1.35k|}

BN_value_one:
   82|    816|{
   83|    816|    static const BN_ULONG data_one = 1L;
   84|    816|    static const BIGNUM const_one =
   85|    816|        { (BN_ULONG *)&data_one, 1, 1, 0, BN_FLG_STATIC_DATA };
  ------------------
  |  |   53|    816|# define BN_FLG_STATIC_DATA      0x02
  ------------------
   86|       |
   87|    816|    return &const_one;
   88|    816|}
BN_num_bits_word:
  100|   374k|{
  101|   374k|    BN_ULONG x, mask;
  ------------------
  |  |   31|   374k|#  define BN_ULONG        unsigned long
  ------------------
  102|   374k|    int bits = (l != 0);
  103|       |
  104|   374k|#if BN_BITS2 > 32
  105|   374k|    x = l >> 32;
  106|   374k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   87|   374k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  107|   374k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   48|   374k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   374k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  108|   374k|    bits += 32 & mask;
  109|   374k|    l ^= (x ^ l) & mask;
  110|   374k|#endif
  111|       |
  112|   374k|    x = l >> 16;
  113|   374k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   87|   374k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  114|   374k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   48|   374k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   374k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  115|   374k|    bits += 16 & mask;
  116|   374k|    l ^= (x ^ l) & mask;
  117|       |
  118|   374k|    x = l >> 8;
  119|   374k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   87|   374k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  120|   374k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   48|   374k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   374k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  121|   374k|    bits += 8 & mask;
  122|   374k|    l ^= (x ^ l) & mask;
  123|       |
  124|   374k|    x = l >> 4;
  125|   374k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   87|   374k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  126|   374k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   48|   374k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   374k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  127|   374k|    bits += 4 & mask;
  128|   374k|    l ^= (x ^ l) & mask;
  129|       |
  130|   374k|    x = l >> 2;
  131|   374k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   87|   374k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  132|   374k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   48|   374k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   374k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  133|   374k|    bits += 2 & mask;
  134|   374k|    l ^= (x ^ l) & mask;
  135|       |
  136|   374k|    x = l >> 1;
  137|   374k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   87|   374k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  138|   374k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   48|   374k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   374k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  139|   374k|    bits += 1 & mask;
  140|       |
  141|   374k|    return bits;
  142|   374k|}
BN_num_bits:
  178|   104k|{
  179|   104k|    int i = a->top - 1;
  180|   104k|    bn_check_top(a);
  181|       |
  182|   104k|    if (a->flags & BN_FLG_CONSTTIME) {
  ------------------
  |  |   61|   104k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (182:9): [True: 0, False: 104k]
  ------------------
  183|       |        /*
  184|       |         * We assume that BIGNUMs flagged as CONSTTIME have also been expanded
  185|       |         * so that a->dmax is not leaking secret information.
  186|       |         *
  187|       |         * In other words, it's the caller's responsibility to ensure `a` has
  188|       |         * been preallocated in advance to a public length if we hit this
  189|       |         * branch.
  190|       |         *
  191|       |         */
  192|      0|        return bn_num_bits_consttime(a);
  193|      0|    }
  194|       |
  195|   104k|    if (BN_is_zero(a))
  ------------------
  |  Branch (195:9): [True: 364, False: 103k]
  ------------------
  196|    364|        return 0;
  197|       |
  198|   103k|    return ((i * BN_BITS2) + BN_num_bits_word(a->d[i]));
  ------------------
  |  |   48|   103k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   103k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  199|   104k|}
BN_clear_free:
  213|  42.5k|{
  214|  42.5k|    if (a == NULL)
  ------------------
  |  Branch (214:9): [True: 0, False: 42.5k]
  ------------------
  215|      0|        return;
  216|  42.5k|    if (a->d != NULL && !BN_get_flags(a, BN_FLG_STATIC_DATA))
  ------------------
  |  |   53|  41.1k|# define BN_FLG_STATIC_DATA      0x02
  ------------------
  |  Branch (216:9): [True: 41.1k, False: 1.39k]
  |  Branch (216:25): [True: 41.1k, False: 0]
  ------------------
  217|  41.1k|        bn_free_d(a, 1);
  218|  42.5k|    if (BN_get_flags(a, BN_FLG_MALLOCED)) {
  ------------------
  |  |   52|  42.5k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (218:9): [True: 0, False: 42.5k]
  ------------------
  219|      0|        OPENSSL_cleanse(a, sizeof(*a));
  220|      0|        OPENSSL_free(a);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  221|      0|    }
  222|  42.5k|}
BN_free:
  225|  19.4k|{
  226|  19.4k|    if (a == NULL)
  ------------------
  |  Branch (226:9): [True: 0, False: 19.4k]
  ------------------
  227|      0|        return;
  228|  19.4k|    if (!BN_get_flags(a, BN_FLG_STATIC_DATA))
  ------------------
  |  |   53|  19.4k|# define BN_FLG_STATIC_DATA      0x02
  ------------------
  |  Branch (228:9): [True: 19.4k, False: 0]
  ------------------
  229|  19.4k|        bn_free_d(a, 0);
  230|  19.4k|    if (a->flags & BN_FLG_MALLOCED)
  ------------------
  |  |   52|  19.4k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (230:9): [True: 16.2k, False: 3.23k]
  ------------------
  231|  16.2k|        OPENSSL_free(a);
  ------------------
  |  |  128|  16.2k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  16.2k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  16.2k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  232|  19.4k|}
bn_init:
  235|  59.6k|{
  236|  59.6k|    static BIGNUM nilbn;
  237|       |
  238|  59.6k|    *a = nilbn;
  239|  59.6k|    bn_check_top(a);
  240|  59.6k|}
BN_new:
  243|  16.2k|{
  244|  16.2k|    BIGNUM *ret;
  245|       |
  246|  16.2k|    if ((ret = OPENSSL_zalloc(sizeof(*ret))) == NULL) {
  ------------------
  |  |  120|  16.2k|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  16.2k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  16.2k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (246:9): [True: 0, False: 16.2k]
  ------------------
  247|      0|        BNerr(BN_F_BN_NEW, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  248|      0|        return NULL;
  249|      0|    }
  250|  16.2k|    ret->flags = BN_FLG_MALLOCED;
  ------------------
  |  |   52|  16.2k|# define BN_FLG_MALLOCED         0x01
  ------------------
  251|  16.2k|    bn_check_top(ret);
  252|  16.2k|    return ret;
  253|  16.2k|}
bn_expand2:
  302|   112k|{
  303|   112k|    if (words > b->dmax) {
  ------------------
  |  Branch (303:9): [True: 112k, False: 0]
  ------------------
  304|   112k|        BN_ULONG *a = bn_expand_internal(b, words);
  ------------------
  |  |   31|   112k|#  define BN_ULONG        unsigned long
  ------------------
  305|   112k|        if (!a)
  ------------------
  |  Branch (305:13): [True: 0, False: 112k]
  ------------------
  306|      0|            return NULL;
  307|   112k|        if (b->d != NULL)
  ------------------
  |  Branch (307:13): [True: 53.0k, False: 59.3k]
  ------------------
  308|  53.0k|            bn_free_d(b, 1);
  309|   112k|        b->d = a;
  310|   112k|        b->dmax = words;
  311|   112k|    }
  312|       |
  313|   112k|    return b;
  314|   112k|}
BN_copy:
  336|   220k|{
  337|   220k|    int bn_words;
  338|       |
  339|   220k|    bn_check_top(b);
  340|       |
  341|   220k|    bn_words = BN_get_flags(b, BN_FLG_CONSTTIME) ? b->dmax : b->top;
  ------------------
  |  |   61|   220k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (341:16): [True: 0, False: 220k]
  ------------------
  342|       |
  343|   220k|    if (a == b)
  ------------------
  |  Branch (343:9): [True: 0, False: 220k]
  ------------------
  344|      0|        return a;
  345|   220k|    if (bn_wexpand(a, bn_words) == NULL)
  ------------------
  |  Branch (345:9): [True: 0, False: 220k]
  ------------------
  346|      0|        return NULL;
  347|       |
  348|   220k|    if (b->top > 0)
  ------------------
  |  Branch (348:9): [True: 214k, False: 6.21k]
  ------------------
  349|   214k|        memcpy(a->d, b->d, sizeof(b->d[0]) * bn_words);
  350|       |
  351|   220k|    a->neg = b->neg;
  352|   220k|    a->top = b->top;
  353|   220k|    a->flags |= b->flags & BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   220k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  354|   220k|    bn_check_top(a);
  355|   220k|    return a;
  356|   220k|}
BN_set_word:
  420|  2.02M|{
  421|  2.02M|    bn_check_top(a);
  422|  2.02M|    if (bn_expand(a, (int)sizeof(BN_ULONG) * 8) == NULL)
  ------------------
  |  Branch (422:9): [True: 0, False: 2.02M]
  ------------------
  423|      0|        return 0;
  424|  2.02M|    a->neg = 0;
  425|  2.02M|    a->d[0] = w;
  426|  2.02M|    a->top = (w ? 1 : 0);
  ------------------
  |  Branch (426:15): [True: 6.94k, False: 2.01M]
  ------------------
  427|  2.02M|    a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|  2.02M|#  define BN_FLG_FIXED_TOP 0
  ------------------
  428|  2.02M|    bn_check_top(a);
  429|  2.02M|    return 1;
  430|  2.02M|}
BN_bin2bn:
  433|  9.73k|{
  434|  9.73k|    unsigned int i, m;
  435|  9.73k|    unsigned int n;
  436|  9.73k|    BN_ULONG l;
  ------------------
  |  |   31|  9.73k|#  define BN_ULONG        unsigned long
  ------------------
  437|  9.73k|    BIGNUM *bn = NULL;
  438|       |
  439|  9.73k|    if (ret == NULL)
  ------------------
  |  Branch (439:9): [True: 0, False: 9.73k]
  ------------------
  440|      0|        ret = bn = BN_new();
  441|  9.73k|    if (ret == NULL)
  ------------------
  |  Branch (441:9): [True: 0, False: 9.73k]
  ------------------
  442|      0|        return NULL;
  443|  9.73k|    bn_check_top(ret);
  444|       |    /* Skip leading zero's. */
  445|  10.0k|    for ( ; len > 0 && *s == 0; s++, len--)
  ------------------
  |  Branch (445:13): [True: 8.87k, False: 1.20k]
  |  Branch (445:24): [True: 340, False: 8.53k]
  ------------------
  446|    340|        continue;
  447|  9.73k|    n = len;
  448|  9.73k|    if (n == 0) {
  ------------------
  |  Branch (448:9): [True: 1.20k, False: 8.53k]
  ------------------
  449|  1.20k|        ret->top = 0;
  450|  1.20k|        return ret;
  451|  1.20k|    }
  452|  8.53k|    i = ((n - 1) / BN_BYTES) + 1;
  ------------------
  |  |   32|  8.53k|#  define BN_BYTES        8
  ------------------
  453|  8.53k|    m = ((n - 1) % (BN_BYTES));
  ------------------
  |  |   32|  8.53k|#  define BN_BYTES        8
  ------------------
  454|  8.53k|    if (bn_wexpand(ret, (int)i) == NULL) {
  ------------------
  |  Branch (454:9): [True: 0, False: 8.53k]
  ------------------
  455|      0|        BN_free(bn);
  456|      0|        return NULL;
  457|      0|    }
  458|  8.53k|    ret->top = i;
  459|  8.53k|    ret->neg = 0;
  460|  8.53k|    l = 0;
  461|   376k|    while (n--) {
  ------------------
  |  Branch (461:12): [True: 367k, False: 8.53k]
  ------------------
  462|   367k|        l = (l << 8L) | *(s++);
  463|   367k|        if (m-- == 0) {
  ------------------
  |  Branch (463:13): [True: 51.8k, False: 315k]
  ------------------
  464|  51.8k|            ret->d[--i] = l;
  465|  51.8k|            l = 0;
  466|  51.8k|            m = BN_BYTES - 1;
  ------------------
  |  |   32|  51.8k|#  define BN_BYTES        8
  ------------------
  467|  51.8k|        }
  468|   367k|    }
  469|       |    /*
  470|       |     * need to call this due to clear byte at top if avoiding having the top
  471|       |     * bit set (-ve number)
  472|       |     */
  473|  8.53k|    bn_correct_top(ret);
  474|  8.53k|    return ret;
  475|  8.53k|}
BN_ucmp:
  597|   327k|{
  598|   327k|    int i;
  599|   327k|    BN_ULONG t1, t2, *ap, *bp;
  ------------------
  |  |   31|   327k|#  define BN_ULONG        unsigned long
  ------------------
  600|       |
  601|   327k|    bn_check_top(a);
  602|   327k|    bn_check_top(b);
  603|       |
  604|   327k|    i = a->top - b->top;
  605|   327k|    if (i != 0)
  ------------------
  |  Branch (605:9): [True: 93.5k, False: 233k]
  ------------------
  606|  93.5k|        return i;
  607|   233k|    ap = a->d;
  608|   233k|    bp = b->d;
  609|   490k|    for (i = a->top - 1; i >= 0; i--) {
  ------------------
  |  Branch (609:26): [True: 489k, False: 1.41k]
  ------------------
  610|   489k|        t1 = ap[i];
  611|   489k|        t2 = bp[i];
  612|   489k|        if (t1 != t2)
  ------------------
  |  Branch (612:13): [True: 232k, False: 256k]
  ------------------
  613|   232k|            return ((t1 > t2) ? 1 : -1);
  ------------------
  |  Branch (613:21): [True: 102k, False: 130k]
  ------------------
  614|   489k|    }
  615|  1.41k|    return 0;
  616|   233k|}
BN_cmp:
  619|  3.19k|{
  620|  3.19k|    int i;
  621|  3.19k|    int gt, lt;
  622|  3.19k|    BN_ULONG t1, t2;
  ------------------
  |  |   31|  3.19k|#  define BN_ULONG        unsigned long
  ------------------
  623|       |
  624|  3.19k|    if ((a == NULL) || (b == NULL)) {
  ------------------
  |  Branch (624:9): [True: 0, False: 3.19k]
  |  Branch (624:24): [True: 0, False: 3.19k]
  ------------------
  625|      0|        if (a != NULL)
  ------------------
  |  Branch (625:13): [True: 0, False: 0]
  ------------------
  626|      0|            return -1;
  627|      0|        else if (b != NULL)
  ------------------
  |  Branch (627:18): [True: 0, False: 0]
  ------------------
  628|      0|            return 1;
  629|      0|        else
  630|      0|            return 0;
  631|      0|    }
  632|       |
  633|  3.19k|    bn_check_top(a);
  634|  3.19k|    bn_check_top(b);
  635|       |
  636|  3.19k|    if (a->neg != b->neg) {
  ------------------
  |  Branch (636:9): [True: 0, False: 3.19k]
  ------------------
  637|      0|        if (a->neg)
  ------------------
  |  Branch (637:13): [True: 0, False: 0]
  ------------------
  638|      0|            return -1;
  639|      0|        else
  640|      0|            return 1;
  641|      0|    }
  642|  3.19k|    if (a->neg == 0) {
  ------------------
  |  Branch (642:9): [True: 3.19k, False: 0]
  ------------------
  643|  3.19k|        gt = 1;
  644|  3.19k|        lt = -1;
  645|  3.19k|    } else {
  646|      0|        gt = -1;
  647|      0|        lt = 1;
  648|      0|    }
  649|       |
  650|  3.19k|    if (a->top > b->top)
  ------------------
  |  Branch (650:9): [True: 0, False: 3.19k]
  ------------------
  651|      0|        return gt;
  652|  3.19k|    if (a->top < b->top)
  ------------------
  |  Branch (652:9): [True: 0, False: 3.19k]
  ------------------
  653|      0|        return lt;
  654|  36.7k|    for (i = a->top - 1; i >= 0; i--) {
  ------------------
  |  Branch (654:26): [True: 33.5k, False: 3.19k]
  ------------------
  655|  33.5k|        t1 = a->d[i];
  656|  33.5k|        t2 = b->d[i];
  657|  33.5k|        if (t1 > t2)
  ------------------
  |  Branch (657:13): [True: 0, False: 33.5k]
  ------------------
  658|      0|            return gt;
  659|  33.5k|        if (t1 < t2)
  ------------------
  |  Branch (659:13): [True: 0, False: 33.5k]
  ------------------
  660|      0|            return lt;
  661|  33.5k|    }
  662|  3.19k|    return 0;
  663|  3.19k|}
BN_set_bit:
  666|  4.36k|{
  667|  4.36k|    int i, j, k;
  668|       |
  669|  4.36k|    if (n < 0)
  ------------------
  |  Branch (669:9): [True: 0, False: 4.36k]
  ------------------
  670|      0|        return 0;
  671|       |
  672|  4.36k|    i = n / BN_BITS2;
  ------------------
  |  |   48|  4.36k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  4.36k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  673|  4.36k|    j = n % BN_BITS2;
  ------------------
  |  |   48|  4.36k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  4.36k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  674|  4.36k|    if (a->top <= i) {
  ------------------
  |  Branch (674:9): [True: 4.36k, False: 0]
  ------------------
  675|  4.36k|        if (bn_wexpand(a, i + 1) == NULL)
  ------------------
  |  Branch (675:13): [True: 0, False: 4.36k]
  ------------------
  676|      0|            return 0;
  677|  88.6k|        for (k = a->top; k < i + 1; k++)
  ------------------
  |  Branch (677:26): [True: 84.3k, False: 4.36k]
  ------------------
  678|  84.3k|            a->d[k] = 0;
  679|  4.36k|        a->top = i + 1;
  680|  4.36k|        a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|  4.36k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  681|  4.36k|    }
  682|       |
  683|  4.36k|    a->d[i] |= (((BN_ULONG)1) << j);
  684|  4.36k|    bn_check_top(a);
  685|  4.36k|    return 1;
  686|  4.36k|}
BN_is_bit_set:
  707|   573k|{
  708|   573k|    int i, j;
  709|       |
  710|   573k|    bn_check_top(a);
  711|   573k|    if (n < 0)
  ------------------
  |  Branch (711:9): [True: 0, False: 573k]
  ------------------
  712|      0|        return 0;
  713|   573k|    i = n / BN_BITS2;
  ------------------
  |  |   48|   573k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   573k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  714|   573k|    j = n % BN_BITS2;
  ------------------
  |  |   48|   573k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   573k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  715|   573k|    if (a->top <= i)
  ------------------
  |  Branch (715:9): [True: 0, False: 573k]
  ------------------
  716|      0|        return 0;
  717|   573k|    return (int)(((a->d[i]) >> j) & ((BN_ULONG)1));
  718|   573k|}
BN_set_negative:
  743|  6.49k|{
  744|  6.49k|    if (b && !BN_is_zero(a))
  ------------------
  |  Branch (744:9): [True: 3.70k, False: 2.78k]
  |  Branch (744:14): [True: 3.07k, False: 628]
  ------------------
  745|  3.07k|        a->neg = 1;
  746|  3.41k|    else
  747|  3.41k|        a->neg = 0;
  748|  6.49k|}
bn_cmp_words:
  751|  1.28M|{
  752|  1.28M|    int i;
  753|  1.28M|    BN_ULONG aa, bb;
  ------------------
  |  |   31|  1.28M|#  define BN_ULONG        unsigned long
  ------------------
  754|       |
  755|  1.28M|    if (n == 0)
  ------------------
  |  Branch (755:9): [True: 0, False: 1.28M]
  ------------------
  756|      0|        return 0;
  757|       |
  758|  1.28M|    aa = a[n - 1];
  759|  1.28M|    bb = b[n - 1];
  760|  1.28M|    if (aa != bb)
  ------------------
  |  Branch (760:9): [True: 1.16M, False: 123k]
  ------------------
  761|  1.16M|        return ((aa > bb) ? 1 : -1);
  ------------------
  |  Branch (761:17): [True: 565k, False: 598k]
  ------------------
  762|   795k|    for (i = n - 2; i >= 0; i--) {
  ------------------
  |  Branch (762:21): [True: 763k, False: 32.6k]
  ------------------
  763|   763k|        aa = a[i];
  764|   763k|        bb = b[i];
  765|   763k|        if (aa != bb)
  ------------------
  |  Branch (765:13): [True: 90.4k, False: 672k]
  ------------------
  766|  90.4k|            return ((aa > bb) ? 1 : -1);
  ------------------
  |  Branch (766:21): [True: 45.9k, False: 44.5k]
  ------------------
  767|   763k|    }
  768|  32.6k|    return 0;
  769|   123k|}
bn_cmp_part_words:
  781|  1.34M|{
  782|  1.34M|    int n, i;
  783|  1.34M|    n = cl - 1;
  784|       |
  785|  1.34M|    if (dl < 0) {
  ------------------
  |  Branch (785:9): [True: 48.8k, False: 1.29M]
  ------------------
  786|   125k|        for (i = dl; i < 0; i++) {
  ------------------
  |  Branch (786:22): [True: 120k, False: 4.89k]
  ------------------
  787|   120k|            if (b[n - i] != 0)
  ------------------
  |  Branch (787:17): [True: 43.9k, False: 76.7k]
  ------------------
  788|  43.9k|                return -1;      /* a < b */
  789|   120k|        }
  790|  48.8k|    }
  791|  1.30M|    if (dl > 0) {
  ------------------
  |  Branch (791:9): [True: 50.3k, False: 1.24M]
  ------------------
  792|   138k|        for (i = dl; i > 0; i--) {
  ------------------
  |  Branch (792:22): [True: 130k, False: 8.17k]
  ------------------
  793|   130k|            if (a[n + i] != 0)
  ------------------
  |  Branch (793:17): [True: 42.2k, False: 88.4k]
  ------------------
  794|  42.2k|                return 1;       /* a > b */
  795|   130k|        }
  796|  50.3k|    }
  797|  1.25M|    return bn_cmp_words(a, b, cl);
  798|  1.30M|}
BN_abs_is_word:
  899|  4.47k|{
  900|  4.47k|    return ((a->top == 1) && (a->d[0] == w)) || ((w == 0) && (a->top == 0));
  ------------------
  |  Branch (900:13): [True: 4.40k, False: 66]
  |  Branch (900:30): [True: 1.40k, False: 3.00k]
  |  Branch (900:50): [True: 0, False: 3.07k]
  |  Branch (900:62): [True: 0, False: 0]
  ------------------
  901|  4.47k|}
BN_is_zero:
  904|   582k|{
  905|   582k|    return a->top == 0;
  906|   582k|}
BN_is_one:
  909|  2.75k|{
  910|  2.75k|    return BN_abs_is_word(a, 1) && !a->neg;
  ------------------
  |  Branch (910:12): [True: 1.39k, False: 1.35k]
  |  Branch (910:36): [True: 1.39k, False: 0]
  ------------------
  911|  2.75k|}
BN_is_odd:
  919|  66.7k|{
  920|  66.7k|    return (a->top > 0) && (a->d[0] & 1);
  ------------------
  |  Branch (920:12): [True: 66.7k, False: 0]
  |  Branch (920:28): [True: 34.6k, False: 32.1k]
  ------------------
  921|  66.7k|}
BN_to_montgomery:
  930|    413|{
  931|    413|    return BN_mod_mul_montgomery(r, a, &(mont->RR), mont, ctx);
  932|    413|}
BN_get_flags:
  970|   687k|{
  971|   687k|    return b->flags & n;
  972|   687k|}
bn_wexpand:
 1000|  2.54M|{
 1001|  2.54M|    return (words <= a->dmax) ? a : bn_expand2(a, words);
  ------------------
  |  Branch (1001:12): [True: 2.48M, False: 66.0k]
  ------------------
 1002|  2.54M|}
bn_correct_top:
 1027|   947k|{
 1028|   947k|    BN_ULONG *ftl;
  ------------------
  |  |   31|   947k|#  define BN_ULONG        unsigned long
  ------------------
 1029|   947k|    int tmp_top = a->top;
 1030|       |
 1031|   947k|    if (tmp_top > 0) {
  ------------------
  |  Branch (1031:9): [True: 931k, False: 15.9k]
  ------------------
 1032|  1.91M|        for (ftl = &(a->d[tmp_top]); tmp_top > 0; tmp_top--) {
  ------------------
  |  Branch (1032:38): [True: 1.90M, False: 10.3k]
  ------------------
 1033|  1.90M|            ftl--;
 1034|  1.90M|            if (*ftl != 0)
  ------------------
  |  Branch (1034:17): [True: 921k, False: 979k]
  ------------------
 1035|   921k|                break;
 1036|  1.90M|        }
 1037|   931k|        a->top = tmp_top;
 1038|   931k|    }
 1039|   947k|    if (a->top == 0)
  ------------------
  |  Branch (1039:9): [True: 26.3k, False: 921k]
  ------------------
 1040|  26.3k|        a->neg = 0;
 1041|   947k|    a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   947k|#  define BN_FLG_FIXED_TOP 0
  ------------------
 1042|   947k|    bn_pollute(a);
 1043|   947k|}
bn_lib.c:bn_free_d:
  202|   113k|{
  203|   113k|    if (BN_get_flags(a, BN_FLG_SECURE))
  ------------------
  |  |   62|   113k|# define BN_FLG_SECURE           0x08
  ------------------
  |  Branch (203:9): [True: 0, False: 113k]
  ------------------
  204|      0|        OPENSSL_secure_clear_free(a->d, a->dmax * sizeof(a->d[0]));
  ------------------
  |  |  142|      0|        CRYPTO_secure_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_secure_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  205|   113k|    else if (clear != 0)
  ------------------
  |  Branch (205:14): [True: 94.2k, False: 19.4k]
  ------------------
  206|  94.2k|        OPENSSL_clear_free(a->d, a->dmax * sizeof(a->d[0]));
  ------------------
  |  |  126|  94.2k|        CRYPTO_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  94.2k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  94.2k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  207|  19.4k|    else
  208|  19.4k|        OPENSSL_free(a->d);
  ------------------
  |  |  128|  19.4k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  19.4k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  19.4k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  209|   113k|}
bn_lib.c:bn_expand_internal:
  266|   112k|{
  267|   112k|    BN_ULONG *a = NULL;
  ------------------
  |  |   31|   112k|#  define BN_ULONG        unsigned long
  ------------------
  268|       |
  269|   112k|    if (words > (INT_MAX / (4 * BN_BITS2))) {
  ------------------
  |  |   48|   112k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   112k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (269:9): [True: 0, False: 112k]
  ------------------
  270|      0|        BNerr(BN_F_BN_EXPAND_INTERNAL, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  271|      0|        return NULL;
  272|      0|    }
  273|   112k|    if (BN_get_flags(b, BN_FLG_STATIC_DATA)) {
  ------------------
  |  |   53|   112k|# define BN_FLG_STATIC_DATA      0x02
  ------------------
  |  Branch (273:9): [True: 0, False: 112k]
  ------------------
  274|      0|        BNerr(BN_F_BN_EXPAND_INTERNAL, BN_R_EXPAND_ON_STATIC_BIGNUM_DATA);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  275|      0|        return NULL;
  276|      0|    }
  277|   112k|    if (BN_get_flags(b, BN_FLG_SECURE))
  ------------------
  |  |   62|   112k|# define BN_FLG_SECURE           0x08
  ------------------
  |  Branch (277:9): [True: 0, False: 112k]
  ------------------
  278|      0|        a = OPENSSL_secure_zalloc(words * sizeof(*a));
  ------------------
  |  |  138|      0|        CRYPTO_secure_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_secure_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  279|   112k|    else
  280|   112k|        a = OPENSSL_zalloc(words * sizeof(*a));
  ------------------
  |  |  120|   112k|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|   112k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|   112k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  281|   112k|    if (a == NULL) {
  ------------------
  |  Branch (281:9): [True: 0, False: 112k]
  ------------------
  282|      0|        BNerr(BN_F_BN_EXPAND_INTERNAL, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  283|      0|        return NULL;
  284|      0|    }
  285|       |
  286|   112k|    assert(b->top <= words);
  287|   112k|    if (b->top > 0)
  ------------------
  |  Branch (287:9): [True: 10.4k, False: 101k]
  ------------------
  288|  10.4k|        memcpy(a, b->d, sizeof(*a) * b->top);
  289|       |
  290|   112k|    return a;
  291|   112k|}

bn_lib.c:bn_expand:
  678|  2.02M|{
  679|  2.02M|    if (bits > (INT_MAX - BN_BITS2 + 1))
  ------------------
  |  |   48|  2.02M|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  2.02M|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (679:9): [True: 0, False: 2.02M]
  ------------------
  680|      0|        return NULL;
  681|       |
  682|  2.02M|    if (((bits+BN_BITS2-1)/BN_BITS2) <= (a)->dmax)
  ------------------
  |  |   48|  2.02M|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  2.02M|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                  if (((bits+BN_BITS2-1)/BN_BITS2) <= (a)->dmax)
  ------------------
  |  |   48|  2.02M|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  2.02M|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (682:9): [True: 1.97M, False: 46.4k]
  ------------------
  683|  1.97M|        return a;
  684|       |
  685|  46.4k|    return bn_expand2((a),(bits+BN_BITS2-1)/BN_BITS2);
  ------------------
  |  |   48|  46.4k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  46.4k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                  return bn_expand2((a),(bits+BN_BITS2-1)/BN_BITS2);
  ------------------
  |  |   48|  46.4k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  46.4k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  686|  2.02M|}

BN_nnmod:
   14|   173k|{
   15|       |    /*
   16|       |     * like BN_mod, but returns non-negative remainder (i.e., 0 <= r < |d|
   17|       |     * always holds)
   18|       |     */
   19|       |
   20|   173k|    if (!(BN_mod(r, m, d, ctx)))
  ------------------
  |  |  247|   173k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  ------------------
  |  Branch (20:9): [True: 0, False: 173k]
  ------------------
   21|      0|        return 0;
   22|   173k|    if (!r->neg)
  ------------------
  |  Branch (22:9): [True: 169k, False: 3.85k]
  ------------------
   23|   169k|        return 1;
   24|       |    /* now   -|d| < r < 0,  so we have to set  r := r + |d| */
   25|  3.85k|    return (d->neg ? BN_sub : BN_add) (r, r, d);
  ------------------
  |  Branch (25:13): [True: 1.41k, False: 2.44k]
  ------------------
   26|   173k|}
BN_mod_mul:
  195|   166k|{
  196|   166k|    BIGNUM *t;
  197|   166k|    int ret = 0;
  198|       |
  199|   166k|    bn_check_top(a);
  200|   166k|    bn_check_top(b);
  201|   166k|    bn_check_top(m);
  202|       |
  203|   166k|    BN_CTX_start(ctx);
  204|   166k|    if ((t = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (204:9): [True: 0, False: 166k]
  ------------------
  205|      0|        goto err;
  206|   166k|    if (a == b) {
  ------------------
  |  Branch (206:9): [True: 134k, False: 31.9k]
  ------------------
  207|   134k|        if (!BN_sqr(t, a, ctx))
  ------------------
  |  Branch (207:13): [True: 0, False: 134k]
  ------------------
  208|      0|            goto err;
  209|   134k|    } else {
  210|  31.9k|        if (!BN_mul(t, a, b, ctx))
  ------------------
  |  Branch (210:13): [True: 0, False: 31.9k]
  ------------------
  211|      0|            goto err;
  212|  31.9k|    }
  213|   166k|    if (!BN_nnmod(r, t, m, ctx))
  ------------------
  |  Branch (213:9): [True: 0, False: 166k]
  ------------------
  214|      0|        goto err;
  215|   166k|    bn_check_top(r);
  216|   166k|    ret = 1;
  217|   166k| err:
  218|   166k|    BN_CTX_end(ctx);
  219|   166k|    return ret;
  220|   166k|}

BN_mod_mul_montgomery:
   28|  39.4k|{
   29|  39.4k|    int ret = bn_mul_mont_fixed_top(r, a, b, mont, ctx);
   30|       |
   31|  39.4k|    bn_correct_top(r);
   32|  39.4k|    bn_check_top(r);
   33|       |
   34|  39.4k|    return ret;
   35|  39.4k|}
bn_mul_mont_fixed_top:
   39|   175k|{
   40|   175k|    BIGNUM *tmp;
   41|   175k|    int ret = 0;
   42|   175k|    int num = mont->N.top;
   43|       |
   44|   175k|#if defined(OPENSSL_BN_ASM_MONT) && defined(MONT_WORD)
   45|   175k|    if (num > 1 && num <= BN_SOFT_LIMIT && a->top == num && b->top == num) {
  ------------------
  |  |   55|   187k|#  define BN_SOFT_LIMIT         (4096 / BN_BYTES)
  |  |  ------------------
  |  |  |  |   32|  12.4k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (45:9): [True: 12.4k, False: 163k]
  |  Branch (45:20): [True: 12.4k, False: 0]
  |  Branch (45:44): [True: 11.4k, False: 1.03k]
  |  Branch (45:61): [True: 11.4k, False: 0]
  ------------------
   46|  11.4k|        if (bn_wexpand(r, num) == NULL)
  ------------------
  |  Branch (46:13): [True: 0, False: 11.4k]
  ------------------
   47|      0|            return 0;
   48|  11.4k|        if (bn_mul_mont(r->d, a->d, b->d, mont->N.d, mont->n0, num)) {
  ------------------
  |  Branch (48:13): [True: 11.4k, False: 0]
  ------------------
   49|  11.4k|            r->neg = a->neg ^ b->neg;
   50|  11.4k|            r->top = num;
   51|  11.4k|            r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|  11.4k|#  define BN_FLG_FIXED_TOP 0
  ------------------
   52|  11.4k|            return 1;
   53|  11.4k|        }
   54|  11.4k|    }
   55|   164k|#endif
   56|       |
   57|   164k|    if ((a->top + b->top) > 2 * num)
  ------------------
  |  Branch (57:9): [True: 0, False: 164k]
  ------------------
   58|      0|        return 0;
   59|       |
   60|   164k|    BN_CTX_start(ctx);
   61|   164k|    tmp = BN_CTX_get(ctx);
   62|   164k|    if (tmp == NULL)
  ------------------
  |  Branch (62:9): [True: 0, False: 164k]
  ------------------
   63|      0|        goto err;
   64|       |
   65|   164k|    bn_check_top(tmp);
   66|   164k|    if (a == b) {
  ------------------
  |  Branch (66:9): [True: 146k, False: 17.6k]
  ------------------
   67|   146k|        if (!bn_sqr_fixed_top(tmp, a, ctx))
  ------------------
  |  Branch (67:13): [True: 0, False: 146k]
  ------------------
   68|      0|            goto err;
   69|   146k|    } else {
   70|  17.6k|        if (!bn_mul_fixed_top(tmp, a, b, ctx))
  ------------------
  |  Branch (70:13): [True: 0, False: 17.6k]
  ------------------
   71|      0|            goto err;
   72|  17.6k|    }
   73|       |    /* reduce from aRR to aR */
   74|   164k|#ifdef MONT_WORD
   75|   164k|    if (!bn_from_montgomery_word(r, tmp, mont))
  ------------------
  |  Branch (75:9): [True: 0, False: 164k]
  ------------------
   76|      0|        goto err;
   77|       |#else
   78|       |    if (!BN_from_montgomery(r, tmp, mont, ctx))
   79|       |        goto err;
   80|       |#endif
   81|   164k|    ret = 1;
   82|   164k| err:
   83|   164k|    BN_CTX_end(ctx);
   84|   164k|    return ret;
   85|   164k|}
BN_from_montgomery:
  164|  1.38k|{
  165|  1.38k|    int retn;
  166|       |
  167|  1.38k|    retn = bn_from_mont_fixed_top(ret, a, mont, ctx);
  168|  1.38k|    bn_correct_top(ret);
  169|  1.38k|    bn_check_top(ret);
  170|       |
  171|  1.38k|    return retn;
  172|  1.38k|}
bn_from_mont_fixed_top:
  176|  1.38k|{
  177|  1.38k|    int retn = 0;
  178|  1.38k|#ifdef MONT_WORD
  179|  1.38k|    BIGNUM *t;
  180|       |
  181|  1.38k|    BN_CTX_start(ctx);
  182|  1.38k|    if ((t = BN_CTX_get(ctx)) && BN_copy(t, a)) {
  ------------------
  |  Branch (182:9): [True: 1.38k, False: 0]
  |  Branch (182:34): [True: 1.38k, False: 0]
  ------------------
  183|  1.38k|        retn = bn_from_montgomery_word(ret, t, mont);
  184|  1.38k|    }
  185|  1.38k|    BN_CTX_end(ctx);
  186|       |#else                           /* !MONT_WORD */
  187|       |    BIGNUM *t1, *t2;
  188|       |
  189|       |    BN_CTX_start(ctx);
  190|       |    t1 = BN_CTX_get(ctx);
  191|       |    t2 = BN_CTX_get(ctx);
  192|       |    if (t2 == NULL)
  193|       |        goto err;
  194|       |
  195|       |    if (!BN_copy(t1, a))
  196|       |        goto err;
  197|       |    BN_mask_bits(t1, mont->ri);
  198|       |
  199|       |    if (!BN_mul(t2, t1, &mont->Ni, ctx))
  200|       |        goto err;
  201|       |    BN_mask_bits(t2, mont->ri);
  202|       |
  203|       |    if (!BN_mul(t1, t2, &mont->N, ctx))
  204|       |        goto err;
  205|       |    if (!BN_add(t2, a, t1))
  206|       |        goto err;
  207|       |    if (!BN_rshift(ret, t2, mont->ri))
  208|       |        goto err;
  209|       |
  210|       |    if (BN_ucmp(ret, &(mont->N)) >= 0) {
  211|       |        if (!BN_usub(ret, ret, &(mont->N)))
  212|       |            goto err;
  213|       |    }
  214|       |    retn = 1;
  215|       |    bn_check_top(ret);
  216|       | err:
  217|       |    BN_CTX_end(ctx);
  218|       |#endif                          /* MONT_WORD */
  219|  1.38k|    return retn;
  220|  1.38k|}
bn_to_mont_fixed_top:
  224|  1.79k|{
  225|  1.79k|    return bn_mul_mont_fixed_top(r, a, &(mont->RR), mont, ctx);
  226|  1.79k|}
BN_MONT_CTX_new:
  229|  1.39k|{
  230|  1.39k|    BN_MONT_CTX *ret;
  231|       |
  232|  1.39k|    if ((ret = OPENSSL_malloc(sizeof(*ret))) == NULL) {
  ------------------
  |  |  118|  1.39k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  1.39k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  1.39k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (232:9): [True: 0, False: 1.39k]
  ------------------
  233|      0|        BNerr(BN_F_BN_MONT_CTX_NEW, ERR_R_MALLOC_FAILURE);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  234|      0|        return NULL;
  235|      0|    }
  236|       |
  237|  1.39k|    BN_MONT_CTX_init(ret);
  238|  1.39k|    ret->flags = BN_FLG_MALLOCED;
  ------------------
  |  |   52|  1.39k|# define BN_FLG_MALLOCED         0x01
  ------------------
  239|  1.39k|    return ret;
  240|  1.39k|}
BN_MONT_CTX_init:
  243|  1.39k|{
  244|  1.39k|    ctx->ri = 0;
  245|  1.39k|    bn_init(&ctx->RR);
  246|  1.39k|    bn_init(&ctx->N);
  247|  1.39k|    bn_init(&ctx->Ni);
  248|  1.39k|    ctx->n0[0] = ctx->n0[1] = 0;
  249|  1.39k|    ctx->flags = 0;
  250|  1.39k|}
BN_MONT_CTX_free:
  253|  1.39k|{
  254|  1.39k|    if (mont == NULL)
  ------------------
  |  Branch (254:9): [True: 0, False: 1.39k]
  ------------------
  255|      0|        return;
  256|  1.39k|    BN_clear_free(&mont->RR);
  257|  1.39k|    BN_clear_free(&mont->N);
  258|  1.39k|    BN_clear_free(&mont->Ni);
  259|  1.39k|    if (mont->flags & BN_FLG_MALLOCED)
  ------------------
  |  |   52|  1.39k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (259:9): [True: 1.39k, False: 0]
  ------------------
  260|  1.39k|        OPENSSL_free(mont);
  ------------------
  |  |  128|  1.39k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  1.39k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  1.39k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  261|  1.39k|}
BN_MONT_CTX_set:
  264|  1.39k|{
  265|  1.39k|    int i, ret = 0;
  266|  1.39k|    BIGNUM *Ri, *R;
  267|       |
  268|  1.39k|    if (BN_is_zero(mod))
  ------------------
  |  Branch (268:9): [True: 0, False: 1.39k]
  ------------------
  269|      0|        return 0;
  270|       |
  271|  1.39k|    BN_CTX_start(ctx);
  272|  1.39k|    if ((Ri = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (272:9): [True: 0, False: 1.39k]
  ------------------
  273|      0|        goto err;
  274|  1.39k|    R = &(mont->RR);            /* grab RR as a temp */
  275|  1.39k|    if (!BN_copy(&(mont->N), mod))
  ------------------
  |  Branch (275:9): [True: 0, False: 1.39k]
  ------------------
  276|      0|        goto err;               /* Set N */
  277|  1.39k|    if (BN_get_flags(mod, BN_FLG_CONSTTIME) != 0)
  ------------------
  |  |   61|  1.39k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (277:9): [True: 0, False: 1.39k]
  ------------------
  278|      0|        BN_set_flags(&(mont->N), BN_FLG_CONSTTIME);
  ------------------
  |  |   61|      0|# define BN_FLG_CONSTTIME        0x04
  ------------------
  279|  1.39k|    mont->N.neg = 0;
  280|       |
  281|  1.39k|#ifdef MONT_WORD
  282|  1.39k|    {
  283|  1.39k|        BIGNUM tmod;
  284|  1.39k|        BN_ULONG buf[2];
  ------------------
  |  |   31|  1.39k|#  define BN_ULONG        unsigned long
  ------------------
  285|       |
  286|  1.39k|        bn_init(&tmod);
  287|  1.39k|        tmod.d = buf;
  288|  1.39k|        tmod.dmax = 2;
  289|  1.39k|        tmod.neg = 0;
  290|       |
  291|  1.39k|        if (BN_get_flags(mod, BN_FLG_CONSTTIME) != 0)
  ------------------
  |  |   61|  1.39k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (291:13): [True: 0, False: 1.39k]
  ------------------
  292|      0|            BN_set_flags(&tmod, BN_FLG_CONSTTIME);
  ------------------
  |  |   61|      0|# define BN_FLG_CONSTTIME        0x04
  ------------------
  293|       |
  294|  1.39k|        mont->ri = (BN_num_bits(mod) + (BN_BITS2 - 1)) / BN_BITS2 * BN_BITS2;
  ------------------
  |  |   48|  1.39k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  1.39k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                      mont->ri = (BN_num_bits(mod) + (BN_BITS2 - 1)) / BN_BITS2 * BN_BITS2;
  ------------------
  |  |   48|  1.39k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  1.39k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                      mont->ri = (BN_num_bits(mod) + (BN_BITS2 - 1)) / BN_BITS2 * BN_BITS2;
  ------------------
  |  |   48|  1.39k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  1.39k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  295|       |
  296|       |# if defined(OPENSSL_BN_ASM_MONT) && (BN_BITS2<=32)
  297|       |        /*
  298|       |         * Only certain BN_BITS2<=32 platforms actually make use of n0[1],
  299|       |         * and we could use the #else case (with a shorter R value) for the
  300|       |         * others.  However, currently only the assembler files do know which
  301|       |         * is which.
  302|       |         */
  303|       |
  304|       |        BN_zero(R);
  305|       |        if (!(BN_set_bit(R, 2 * BN_BITS2)))
  306|       |            goto err;
  307|       |
  308|       |        tmod.top = 0;
  309|       |        if ((buf[0] = mod->d[0]))
  310|       |            tmod.top = 1;
  311|       |        if ((buf[1] = mod->top > 1 ? mod->d[1] : 0))
  312|       |            tmod.top = 2;
  313|       |
  314|       |        if (BN_is_one(&tmod))
  315|       |            BN_zero(Ri);
  316|       |        else if ((BN_mod_inverse(Ri, R, &tmod, ctx)) == NULL)
  317|       |            goto err;
  318|       |        if (!BN_lshift(Ri, Ri, 2 * BN_BITS2))
  319|       |            goto err;           /* R*Ri */
  320|       |        if (!BN_is_zero(Ri)) {
  321|       |            if (!BN_sub_word(Ri, 1))
  322|       |                goto err;
  323|       |        } else {                /* if N mod word size == 1 */
  324|       |
  325|       |            if (bn_expand(Ri, (int)sizeof(BN_ULONG) * 2) == NULL)
  326|       |                goto err;
  327|       |            /* Ri-- (mod double word size) */
  328|       |            Ri->neg = 0;
  329|       |            Ri->d[0] = BN_MASK2;
  330|       |            Ri->d[1] = BN_MASK2;
  331|       |            Ri->top = 2;
  332|       |        }
  333|       |        if (!BN_div(Ri, NULL, Ri, &tmod, ctx))
  334|       |            goto err;
  335|       |        /*
  336|       |         * Ni = (R*Ri-1)/N, keep only couple of least significant words:
  337|       |         */
  338|       |        mont->n0[0] = (Ri->top > 0) ? Ri->d[0] : 0;
  339|       |        mont->n0[1] = (Ri->top > 1) ? Ri->d[1] : 0;
  340|       |# else
  341|  1.39k|        BN_zero(R);
  ------------------
  |  |  196|  1.39k|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  342|  1.39k|        if (!(BN_set_bit(R, BN_BITS2)))
  ------------------
  |  |   48|  1.39k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  1.39k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (342:13): [True: 0, False: 1.39k]
  ------------------
  343|      0|            goto err;           /* R */
  344|       |
  345|  1.39k|        buf[0] = mod->d[0];     /* tmod = N mod word size */
  346|  1.39k|        buf[1] = 0;
  347|  1.39k|        tmod.top = buf[0] != 0 ? 1 : 0;
  ------------------
  |  Branch (347:20): [True: 1.39k, False: 0]
  ------------------
  348|       |        /* Ri = R^-1 mod N */
  349|  1.39k|        if (BN_is_one(&tmod))
  ------------------
  |  Branch (349:13): [True: 35, False: 1.35k]
  ------------------
  350|     35|            BN_zero(Ri);
  ------------------
  |  |  196|     35|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  351|  1.35k|        else if ((BN_mod_inverse(Ri, R, &tmod, ctx)) == NULL)
  ------------------
  |  Branch (351:18): [True: 0, False: 1.35k]
  ------------------
  352|      0|            goto err;
  353|  1.39k|        if (!BN_lshift(Ri, Ri, BN_BITS2))
  ------------------
  |  |   48|  1.39k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  1.39k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (353:13): [True: 0, False: 1.39k]
  ------------------
  354|      0|            goto err;           /* R*Ri */
  355|  1.39k|        if (!BN_is_zero(Ri)) {
  ------------------
  |  Branch (355:13): [True: 1.35k, False: 35]
  ------------------
  356|  1.35k|            if (!BN_sub_word(Ri, 1))
  ------------------
  |  Branch (356:17): [True: 0, False: 1.35k]
  ------------------
  357|      0|                goto err;
  358|  1.35k|        } else {                /* if N mod word size == 1 */
  359|       |
  360|     35|            if (!BN_set_word(Ri, BN_MASK2))
  ------------------
  |  |   87|     35|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  |  Branch (360:17): [True: 0, False: 35]
  ------------------
  361|      0|                goto err;       /* Ri-- (mod word size) */
  362|     35|        }
  363|  1.39k|        if (!BN_div(Ri, NULL, Ri, &tmod, ctx))
  ------------------
  |  Branch (363:13): [True: 0, False: 1.39k]
  ------------------
  364|      0|            goto err;
  365|       |        /*
  366|       |         * Ni = (R*Ri-1)/N, keep only least significant word:
  367|       |         */
  368|  1.39k|        mont->n0[0] = (Ri->top > 0) ? Ri->d[0] : 0;
  ------------------
  |  Branch (368:23): [True: 1.39k, False: 0]
  ------------------
  369|  1.39k|        mont->n0[1] = 0;
  370|  1.39k|# endif
  371|  1.39k|    }
  372|       |#else                           /* !MONT_WORD */
  373|       |    {                           /* bignum version */
  374|       |        mont->ri = BN_num_bits(&mont->N);
  375|       |        BN_zero(R);
  376|       |        if (!BN_set_bit(R, mont->ri))
  377|       |            goto err;           /* R = 2^ri */
  378|       |        /* Ri = R^-1 mod N */
  379|       |        if ((BN_mod_inverse(Ri, R, &mont->N, ctx)) == NULL)
  380|       |            goto err;
  381|       |        if (!BN_lshift(Ri, Ri, mont->ri))
  382|       |            goto err;           /* R*Ri */
  383|       |        if (!BN_sub_word(Ri, 1))
  384|       |            goto err;
  385|       |        /*
  386|       |         * Ni = (R*Ri-1) / N
  387|       |         */
  388|       |        if (!BN_div(&(mont->Ni), NULL, Ri, &mont->N, ctx))
  389|       |            goto err;
  390|       |    }
  391|       |#endif
  392|       |
  393|       |    /* setup RR for conversions */
  394|  1.39k|    BN_zero(&(mont->RR));
  ------------------
  |  |  196|  1.39k|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  395|  1.39k|    if (!BN_set_bit(&(mont->RR), mont->ri * 2))
  ------------------
  |  Branch (395:9): [True: 0, False: 1.39k]
  ------------------
  396|      0|        goto err;
  397|  1.39k|    if (!BN_mod(&(mont->RR), &(mont->RR), &(mont->N), ctx))
  ------------------
  |  |  247|  1.39k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  ------------------
  |  Branch (397:9): [True: 0, False: 1.39k]
  ------------------
  398|      0|        goto err;
  399|       |
  400|  1.52k|    for (i = mont->RR.top, ret = mont->N.top; i < ret; i++)
  ------------------
  |  Branch (400:47): [True: 129, False: 1.39k]
  ------------------
  401|    129|        mont->RR.d[i] = 0;
  402|  1.39k|    mont->RR.top = ret;
  403|  1.39k|    mont->RR.flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|  1.39k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  404|       |
  405|  1.39k|    ret = 1;
  406|  1.39k| err:
  407|  1.39k|    BN_CTX_end(ctx);
  408|  1.39k|    return ret;
  409|  1.39k|}
bn_mont.c:bn_from_montgomery_word:
   89|   165k|{
   90|   165k|    BIGNUM *n;
   91|   165k|    BN_ULONG *ap, *np, *rp, n0, v, carry;
  ------------------
  |  |   31|   165k|#  define BN_ULONG        unsigned long
  ------------------
   92|   165k|    int nl, max, i;
   93|   165k|    unsigned int rtop;
   94|       |
   95|   165k|    n = &(mont->N);
   96|   165k|    nl = n->top;
   97|   165k|    if (nl == 0) {
  ------------------
  |  Branch (97:9): [True: 0, False: 165k]
  ------------------
   98|      0|        ret->top = 0;
   99|      0|        return 1;
  100|      0|    }
  101|       |
  102|   165k|    max = (2 * nl);             /* carry is stored separately */
  103|   165k|    if (bn_wexpand(r, max) == NULL)
  ------------------
  |  Branch (103:9): [True: 0, False: 165k]
  ------------------
  104|      0|        return 0;
  105|       |
  106|   165k|    r->neg ^= n->neg;
  107|   165k|    np = n->d;
  108|   165k|    rp = r->d;
  109|       |
  110|       |    /* clear the top words of T */
  111|   523k|    for (rtop = r->top, i = 0; i < max; i++) {
  ------------------
  |  Branch (111:32): [True: 357k, False: 165k]
  ------------------
  112|   357k|        v = (BN_ULONG)0 - ((i - rtop) >> (8 * sizeof(rtop) - 1));
  113|   357k|        rp[i] &= v;
  114|   357k|    }
  115|       |
  116|   165k|    r->top = max;
  117|   165k|    r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   165k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  118|   165k|    n0 = mont->n0[0];
  119|       |
  120|       |    /*
  121|       |     * Add multiples of |n| to |r| until R = 2^(nl * BN_BITS2) divides it. On
  122|       |     * input, we had |r| < |n| * R, so now |r| < 2 * |n| * R. Note that |r|
  123|       |     * includes |carry| which is stored separately.
  124|       |     */
  125|   344k|    for (carry = 0, i = 0; i < nl; i++, rp++) {
  ------------------
  |  Branch (125:28): [True: 178k, False: 165k]
  ------------------
  126|   178k|        v = bn_mul_add_words(rp, np, nl, (rp[0] * n0) & BN_MASK2);
  ------------------
  |  |   87|   178k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  127|   178k|        v = (v + carry + rp[nl]) & BN_MASK2;
  ------------------
  |  |   87|   178k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  128|   178k|        carry |= (v != rp[nl]);
  129|   178k|        carry &= (v <= rp[nl]);
  130|   178k|        rp[nl] = v;
  131|   178k|    }
  132|       |
  133|   165k|    if (bn_wexpand(ret, nl) == NULL)
  ------------------
  |  Branch (133:9): [True: 0, False: 165k]
  ------------------
  134|      0|        return 0;
  135|   165k|    ret->top = nl;
  136|   165k|    ret->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   165k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  137|   165k|    ret->neg = r->neg;
  138|       |
  139|   165k|    rp = ret->d;
  140|       |
  141|       |    /*
  142|       |     * Shift |nl| words to divide by R. We have |ap| < 2 * |n|. Note that |ap|
  143|       |     * includes |carry| which is stored separately.
  144|       |     */
  145|   165k|    ap = &(r->d[nl]);
  146|       |
  147|   165k|    carry -= bn_sub_words(rp, ap, np, nl);
  148|       |    /*
  149|       |     * |carry| is -1 if |ap| - |np| underflowed or zero if it did not. Note
  150|       |     * |carry| cannot be 1. That would imply the subtraction did not fit in
  151|       |     * |nl| words, and we know at most one subtraction is needed.
  152|       |     */
  153|   344k|    for (i = 0; i < nl; i++) {
  ------------------
  |  Branch (153:17): [True: 178k, False: 165k]
  ------------------
  154|   178k|        rp[i] = (carry & ap[i]) | (~carry & rp[i]);
  155|   178k|        ap[i] = 0;
  156|   178k|    }
  157|       |
  158|   165k|    return 1;
  159|   165k|}

bn_sub_part_words:
   30|  1.28M|{
   31|  1.28M|    BN_ULONG c, t;
  ------------------
  |  |   31|  1.28M|#  define BN_ULONG        unsigned long
  ------------------
   32|       |
   33|  1.28M|    assert(cl >= 0);
   34|  1.28M|    c = bn_sub_words(r, a, b, cl);
   35|       |
   36|  1.28M|    if (dl == 0)
  ------------------
  |  Branch (36:9): [True: 1.19M, False: 99.0k]
  ------------------
   37|  1.19M|        return c;
   38|       |
   39|  99.0k|    r += cl;
   40|  99.0k|    a += cl;
   41|  99.0k|    b += cl;
   42|       |
   43|  99.0k|    if (dl < 0) {
  ------------------
  |  Branch (43:9): [True: 9.83k, False: 89.2k]
  ------------------
   44|  29.3k|        for (;;) {
   45|  29.3k|            t = b[0];
   46|  29.3k|            r[0] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   87|  29.3k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   47|  29.3k|            if (t != 0)
  ------------------
  |  Branch (47:17): [True: 0, False: 29.3k]
  ------------------
   48|      0|                c = 1;
   49|  29.3k|            if (++dl >= 0)
  ------------------
  |  Branch (49:17): [True: 1.69k, False: 27.6k]
  ------------------
   50|  1.69k|                break;
   51|       |
   52|  27.6k|            t = b[1];
   53|  27.6k|            r[1] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   87|  27.6k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   54|  27.6k|            if (t != 0)
  ------------------
  |  Branch (54:17): [True: 0, False: 27.6k]
  ------------------
   55|      0|                c = 1;
   56|  27.6k|            if (++dl >= 0)
  ------------------
  |  Branch (56:17): [True: 1.40k, False: 26.2k]
  ------------------
   57|  1.40k|                break;
   58|       |
   59|  26.2k|            t = b[2];
   60|  26.2k|            r[2] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   87|  26.2k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   61|  26.2k|            if (t != 0)
  ------------------
  |  Branch (61:17): [True: 0, False: 26.2k]
  ------------------
   62|      0|                c = 1;
   63|  26.2k|            if (++dl >= 0)
  ------------------
  |  Branch (63:17): [True: 5.63k, False: 20.6k]
  ------------------
   64|  5.63k|                break;
   65|       |
   66|  20.6k|            t = b[3];
   67|  20.6k|            r[3] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   87|  20.6k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   68|  20.6k|            if (t != 0)
  ------------------
  |  Branch (68:17): [True: 0, False: 20.6k]
  ------------------
   69|      0|                c = 1;
   70|  20.6k|            if (++dl >= 0)
  ------------------
  |  Branch (70:17): [True: 1.09k, False: 19.5k]
  ------------------
   71|  1.09k|                break;
   72|       |
   73|  19.5k|            b += 4;
   74|  19.5k|            r += 4;
   75|  19.5k|        }
   76|  89.2k|    } else {
   77|  89.2k|        int save_dl = dl;
   78|   105k|        while (c) {
  ------------------
  |  Branch (78:16): [True: 24.1k, False: 81.5k]
  ------------------
   79|  24.1k|            t = a[0];
   80|  24.1k|            r[0] = (t - c) & BN_MASK2;
  ------------------
  |  |   87|  24.1k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   81|  24.1k|            if (t != 0)
  ------------------
  |  Branch (81:17): [True: 11.1k, False: 13.0k]
  ------------------
   82|  11.1k|                c = 0;
   83|  24.1k|            if (--dl <= 0)
  ------------------
  |  Branch (83:17): [True: 2.19k, False: 21.9k]
  ------------------
   84|  2.19k|                break;
   85|       |
   86|  21.9k|            t = a[1];
   87|  21.9k|            r[1] = (t - c) & BN_MASK2;
  ------------------
  |  |   87|  21.9k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   88|  21.9k|            if (t != 0)
  ------------------
  |  Branch (88:17): [True: 10.0k, False: 11.9k]
  ------------------
   89|  10.0k|                c = 0;
   90|  21.9k|            if (--dl <= 0)
  ------------------
  |  Branch (90:17): [True: 882, False: 21.0k]
  ------------------
   91|    882|                break;
   92|       |
   93|  21.0k|            t = a[2];
   94|  21.0k|            r[2] = (t - c) & BN_MASK2;
  ------------------
  |  |   87|  21.0k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   95|  21.0k|            if (t != 0)
  ------------------
  |  Branch (95:17): [True: 11.0k, False: 10.0k]
  ------------------
   96|  11.0k|                c = 0;
   97|  21.0k|            if (--dl <= 0)
  ------------------
  |  Branch (97:17): [True: 2.99k, False: 18.1k]
  ------------------
   98|  2.99k|                break;
   99|       |
  100|  18.1k|            t = a[3];
  101|  18.1k|            r[3] = (t - c) & BN_MASK2;
  ------------------
  |  |   87|  18.1k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  102|  18.1k|            if (t != 0)
  ------------------
  |  Branch (102:17): [True: 8.84k, False: 9.25k]
  ------------------
  103|  8.84k|                c = 0;
  104|  18.1k|            if (--dl <= 0)
  ------------------
  |  Branch (104:17): [True: 1.57k, False: 16.5k]
  ------------------
  105|  1.57k|                break;
  106|       |
  107|  16.5k|            save_dl = dl;
  108|  16.5k|            a += 4;
  109|  16.5k|            r += 4;
  110|  16.5k|        }
  111|  89.2k|        if (dl > 0) {
  ------------------
  |  Branch (111:13): [True: 81.5k, False: 7.63k]
  ------------------
  112|  81.5k|            if (save_dl > dl) {
  ------------------
  |  Branch (112:17): [True: 0, False: 81.5k]
  ------------------
  113|      0|                switch (save_dl - dl) {
  ------------------
  |  Branch (113:25): [True: 0, False: 0]
  ------------------
  114|      0|                case 1:
  ------------------
  |  Branch (114:17): [True: 0, False: 0]
  ------------------
  115|      0|                    r[1] = a[1];
  116|      0|                    if (--dl <= 0)
  ------------------
  |  Branch (116:25): [True: 0, False: 0]
  ------------------
  117|      0|                        break;
  118|       |                    /* fall thru */
  119|      0|                case 2:
  ------------------
  |  Branch (119:17): [True: 0, False: 0]
  ------------------
  120|      0|                    r[2] = a[2];
  121|      0|                    if (--dl <= 0)
  ------------------
  |  Branch (121:25): [True: 0, False: 0]
  ------------------
  122|      0|                        break;
  123|       |                    /* fall thru */
  124|      0|                case 3:
  ------------------
  |  Branch (124:17): [True: 0, False: 0]
  ------------------
  125|      0|                    r[3] = a[3];
  126|      0|                    if (--dl <= 0)
  ------------------
  |  Branch (126:25): [True: 0, False: 0]
  ------------------
  127|      0|                        break;
  128|      0|                }
  129|      0|                a += 4;
  130|      0|                r += 4;
  131|      0|            }
  132|  81.5k|        }
  133|  89.2k|        if (dl > 0) {
  ------------------
  |  Branch (133:13): [True: 81.5k, False: 7.63k]
  ------------------
  134|   463k|            for (;;) {
  135|   463k|                r[0] = a[0];
  136|   463k|                if (--dl <= 0)
  ------------------
  |  Branch (136:21): [True: 14.1k, False: 449k]
  ------------------
  137|  14.1k|                    break;
  138|   449k|                r[1] = a[1];
  139|   449k|                if (--dl <= 0)
  ------------------
  |  Branch (139:21): [True: 9.47k, False: 440k]
  ------------------
  140|  9.47k|                    break;
  141|   440k|                r[2] = a[2];
  142|   440k|                if (--dl <= 0)
  ------------------
  |  Branch (142:21): [True: 44.8k, False: 395k]
  ------------------
  143|  44.8k|                    break;
  144|   395k|                r[3] = a[3];
  145|   395k|                if (--dl <= 0)
  ------------------
  |  Branch (145:21): [True: 13.1k, False: 382k]
  ------------------
  146|  13.1k|                    break;
  147|       |
  148|   382k|                a += 4;
  149|   382k|                r += 4;
  150|   382k|            }
  151|  81.5k|        }
  152|  89.2k|    }
  153|  99.0k|    return c;
  154|  99.0k|}
bn_mul_recursive:
  177|   630k|{
  178|   630k|    int n = n2 / 2, c1, c2;
  179|   630k|    int tna = n + dna, tnb = n + dnb;
  180|   630k|    unsigned int neg, zero;
  181|   630k|    BN_ULONG ln, lo, *p;
  ------------------
  |  |   31|   630k|#  define BN_ULONG        unsigned long
  ------------------
  182|       |
  183|   630k|# ifdef BN_MUL_COMBA
  184|       |#  if 0
  185|       |    if (n2 == 4) {
  186|       |        bn_mul_comba4(r, a, b);
  187|       |        return;
  188|       |    }
  189|       |#  endif
  190|       |    /*
  191|       |     * Only call bn_mul_comba 8 if n2 == 8 and the two arrays are complete
  192|       |     * [steve]
  193|       |     */
  194|   630k|    if (n2 == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (194:9): [True: 6.52k, False: 624k]
  |  Branch (194:20): [True: 4.58k, False: 1.94k]
  |  Branch (194:32): [True: 3.74k, False: 841]
  ------------------
  195|  3.74k|        bn_mul_comba8(r, a, b);
  196|  3.74k|        return;
  197|  3.74k|    }
  198|   626k|# endif                         /* BN_MUL_COMBA */
  199|       |    /* Else do normal multiply */
  200|   626k|    if (n2 < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  355|   626k|# define BN_MUL_RECURSIVE_SIZE_NORMAL            (16)/* 32 less than */
  ------------------
  |  Branch (200:9): [True: 2.78k, False: 624k]
  ------------------
  201|  2.78k|        bn_mul_normal(r, a, n2 + dna, b, n2 + dnb);
  202|  2.78k|        if ((dna + dnb) < 0)
  ------------------
  |  Branch (202:13): [True: 2.78k, False: 0]
  ------------------
  203|  2.78k|            memset(&r[2 * n2 + dna + dnb], 0,
  204|  2.78k|                   sizeof(BN_ULONG) * -(dna + dnb));
  205|  2.78k|        return;
  206|  2.78k|    }
  207|       |    /* r=(a[0]-a[1])*(b[1]-b[0]) */
  208|   624k|    c1 = bn_cmp_part_words(a, &(a[n]), tna, n - tna);
  209|   624k|    c2 = bn_cmp_part_words(&(b[n]), b, tnb, tnb - n);
  210|   624k|    zero = neg = 0;
  211|   624k|    switch (c1 * 3 + c2) {
  ------------------
  |  Branch (211:13): [True: 0, False: 624k]
  ------------------
  212|   146k|    case -4:
  ------------------
  |  Branch (212:5): [True: 146k, False: 477k]
  ------------------
  213|   146k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  214|   146k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  215|   146k|        break;
  216|  6.17k|    case -3:
  ------------------
  |  Branch (216:5): [True: 6.17k, False: 617k]
  ------------------
  217|  6.17k|        zero = 1;
  218|  6.17k|        break;
  219|   130k|    case -2:
  ------------------
  |  Branch (219:5): [True: 130k, False: 493k]
  ------------------
  220|   130k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  221|   130k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n); /* + */
  222|   130k|        neg = 1;
  223|   130k|        break;
  224|  5.59k|    case -1:
  ------------------
  |  Branch (224:5): [True: 5.59k, False: 618k]
  ------------------
  225|  8.15k|    case 0:
  ------------------
  |  Branch (225:5): [True: 2.55k, False: 621k]
  ------------------
  226|  14.4k|    case 1:
  ------------------
  |  Branch (226:5): [True: 6.29k, False: 617k]
  ------------------
  227|  14.4k|        zero = 1;
  228|  14.4k|        break;
  229|   189k|    case 2:
  ------------------
  |  Branch (229:5): [True: 189k, False: 434k]
  ------------------
  230|   189k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna); /* + */
  231|   189k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  232|   189k|        neg = 1;
  233|   189k|        break;
  234|  6.69k|    case 3:
  ------------------
  |  Branch (234:5): [True: 6.69k, False: 617k]
  ------------------
  235|  6.69k|        zero = 1;
  236|  6.69k|        break;
  237|   130k|    case 4:
  ------------------
  |  Branch (237:5): [True: 130k, False: 494k]
  ------------------
  238|   130k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna);
  239|   130k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n);
  240|   130k|        break;
  241|   624k|    }
  242|       |
  243|   624k|# ifdef BN_MUL_COMBA
  244|   624k|    if (n == 4 && dna == 0 && dnb == 0) { /* XXX: bn_mul_comba4 could take
  ------------------
  |  Branch (244:9): [True: 0, False: 624k]
  |  Branch (244:19): [True: 0, False: 0]
  |  Branch (244:31): [True: 0, False: 0]
  ------------------
  245|       |                                           * extra args to do this well */
  246|      0|        if (!zero)
  ------------------
  |  Branch (246:13): [True: 0, False: 0]
  ------------------
  247|      0|            bn_mul_comba4(&(t[n2]), t, &(t[n]));
  248|      0|        else
  249|      0|            memset(&t[n2], 0, sizeof(*t) * 8);
  250|       |
  251|      0|        bn_mul_comba4(r, a, b);
  252|      0|        bn_mul_comba4(&(r[n2]), &(a[n]), &(b[n]));
  253|   624k|    } else if (n == 8 && dna == 0 && dnb == 0) { /* XXX: bn_mul_comba8 could
  ------------------
  |  Branch (253:16): [True: 446k, False: 177k]
  |  Branch (253:26): [True: 445k, False: 1.33k]
  |  Branch (253:38): [True: 444k, False: 485]
  ------------------
  254|       |                                                  * take extra args to do
  255|       |                                                  * this well */
  256|   444k|        if (!zero)
  ------------------
  |  Branch (256:13): [True: 423k, False: 21.5k]
  ------------------
  257|   423k|            bn_mul_comba8(&(t[n2]), t, &(t[n]));
  258|  21.5k|        else
  259|  21.5k|            memset(&t[n2], 0, sizeof(*t) * 16);
  260|       |
  261|   444k|        bn_mul_comba8(r, a, b);
  262|   444k|        bn_mul_comba8(&(r[n2]), &(a[n]), &(b[n]));
  263|   444k|    } else
  264|   179k|# endif                         /* BN_MUL_COMBA */
  265|   179k|    {
  266|   179k|        p = &(t[n2 * 2]);
  267|   179k|        if (!zero)
  ------------------
  |  Branch (267:13): [True: 173k, False: 5.79k]
  ------------------
  268|   173k|            bn_mul_recursive(&(t[n2]), t, &(t[n]), n, 0, 0, p);
  269|  5.79k|        else
  270|  5.79k|            memset(&t[n2], 0, sizeof(*t) * n2);
  271|   179k|        bn_mul_recursive(r, a, b, n, 0, 0, p);
  272|   179k|        bn_mul_recursive(&(r[n2]), &(a[n]), &(b[n]), n, dna, dnb, p);
  273|   179k|    }
  274|       |
  275|       |    /*-
  276|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0]), c1 is the sign
  277|       |     * r[10] holds (a[0]*b[0])
  278|       |     * r[32] holds (b[1]*b[1])
  279|       |     */
  280|       |
  281|   624k|    c1 = (int)(bn_add_words(t, r, &(r[n2]), n2));
  282|       |
  283|   624k|    if (neg) {                  /* if t[32] is negative */
  ------------------
  |  Branch (283:9): [True: 319k, False: 304k]
  ------------------
  284|   319k|        c1 -= (int)(bn_sub_words(&(t[n2]), t, &(t[n2]), n2));
  285|   319k|    } else {
  286|       |        /* Might have a carry */
  287|   304k|        c1 += (int)(bn_add_words(&(t[n2]), &(t[n2]), t, n2));
  288|   304k|    }
  289|       |
  290|       |    /*-
  291|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0])+(a[0]*b[0])+(a[1]*b[1])
  292|       |     * r[10] holds (a[0]*b[0])
  293|       |     * r[32] holds (b[1]*b[1])
  294|       |     * c1 holds the carry bits
  295|       |     */
  296|   624k|    c1 += (int)(bn_add_words(&(r[n]), &(r[n]), &(t[n2]), n2));
  297|   624k|    if (c1) {
  ------------------
  |  Branch (297:9): [True: 250k, False: 373k]
  ------------------
  298|   250k|        p = &(r[n + n2]);
  299|   250k|        lo = *p;
  300|   250k|        ln = (lo + c1) & BN_MASK2;
  ------------------
  |  |   87|   250k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  301|   250k|        *p = ln;
  302|       |
  303|       |        /*
  304|       |         * The overflow will stop before we over write words we should not
  305|       |         * overwrite
  306|       |         */
  307|   250k|        if (ln < (BN_ULONG)c1) {
  ------------------
  |  Branch (307:13): [True: 1.77k, False: 248k]
  ------------------
  308|  5.47k|            do {
  309|  5.47k|                p++;
  310|  5.47k|                lo = *p;
  311|  5.47k|                ln = (lo + 1) & BN_MASK2;
  ------------------
  |  |   87|  5.47k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  312|  5.47k|                *p = ln;
  313|  5.47k|            } while (ln == 0);
  ------------------
  |  Branch (313:22): [True: 3.70k, False: 1.77k]
  ------------------
  314|  1.77k|        }
  315|   250k|    }
  316|   624k|}
bn_mul_part_recursive:
  324|  48.0k|{
  325|  48.0k|    int i, j, n2 = n * 2;
  326|  48.0k|    int c1, c2, neg;
  327|  48.0k|    BN_ULONG ln, lo, *p;
  ------------------
  |  |   31|  48.0k|#  define BN_ULONG        unsigned long
  ------------------
  328|       |
  329|  48.0k|    if (n < 8) {
  ------------------
  |  Branch (329:9): [True: 0, False: 48.0k]
  ------------------
  330|      0|        bn_mul_normal(r, a, n + tna, b, n + tnb);
  331|      0|        return;
  332|      0|    }
  333|       |
  334|       |    /* r=(a[0]-a[1])*(b[1]-b[0]) */
  335|  48.0k|    c1 = bn_cmp_part_words(a, &(a[n]), tna, n - tna);
  336|  48.0k|    c2 = bn_cmp_part_words(&(b[n]), b, tnb, tnb - n);
  337|  48.0k|    neg = 0;
  338|  48.0k|    switch (c1 * 3 + c2) {
  ------------------
  |  Branch (338:13): [True: 0, False: 48.0k]
  ------------------
  339|  4.52k|    case -4:
  ------------------
  |  Branch (339:5): [True: 4.52k, False: 43.5k]
  ------------------
  340|  4.52k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  341|  4.52k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  342|  4.52k|        break;
  343|    216|    case -3:
  ------------------
  |  Branch (343:5): [True: 216, False: 47.8k]
  ------------------
  344|  1.59k|    case -2:
  ------------------
  |  Branch (344:5): [True: 1.38k, False: 46.6k]
  ------------------
  345|  1.59k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  346|  1.59k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n); /* + */
  347|  1.59k|        neg = 1;
  348|  1.59k|        break;
  349|    904|    case -1:
  ------------------
  |  Branch (349:5): [True: 904, False: 47.1k]
  ------------------
  350|  1.10k|    case 0:
  ------------------
  |  Branch (350:5): [True: 201, False: 47.8k]
  ------------------
  351|  1.33k|    case 1:
  ------------------
  |  Branch (351:5): [True: 226, False: 47.8k]
  ------------------
  352|  39.8k|    case 2:
  ------------------
  |  Branch (352:5): [True: 38.5k, False: 9.47k]
  ------------------
  353|  39.8k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna); /* + */
  354|  39.8k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  355|  39.8k|        neg = 1;
  356|  39.8k|        break;
  357|    609|    case 3:
  ------------------
  |  Branch (357:5): [True: 609, False: 47.4k]
  ------------------
  358|  2.02k|    case 4:
  ------------------
  |  Branch (358:5): [True: 1.41k, False: 46.6k]
  ------------------
  359|  2.02k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna);
  360|  2.02k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n);
  361|  2.02k|        break;
  362|  48.0k|    }
  363|       |    /*
  364|       |     * The zero case isn't yet implemented here. The speedup would probably
  365|       |     * be negligible.
  366|       |     */
  367|       |# if 0
  368|       |    if (n == 4) {
  369|       |        bn_mul_comba4(&(t[n2]), t, &(t[n]));
  370|       |        bn_mul_comba4(r, a, b);
  371|       |        bn_mul_normal(&(r[n2]), &(a[n]), tn, &(b[n]), tn);
  372|       |        memset(&r[n2 + tn * 2], 0, sizeof(*r) * (n2 - tn * 2));
  373|       |    } else
  374|       |# endif
  375|  48.0k|    if (n == 8) {
  ------------------
  |  Branch (375:9): [True: 6.42k, False: 41.6k]
  ------------------
  376|  6.42k|        bn_mul_comba8(&(t[n2]), t, &(t[n]));
  377|  6.42k|        bn_mul_comba8(r, a, b);
  378|  6.42k|        bn_mul_normal(&(r[n2]), &(a[n]), tna, &(b[n]), tnb);
  379|  6.42k|        memset(&r[n2 + tna + tnb], 0, sizeof(*r) * (n2 - tna - tnb));
  380|  41.6k|    } else {
  381|  41.6k|        p = &(t[n2 * 2]);
  382|  41.6k|        bn_mul_recursive(&(t[n2]), t, &(t[n]), n, 0, 0, p);
  383|  41.6k|        bn_mul_recursive(r, a, b, n, 0, 0, p);
  384|  41.6k|        i = n / 2;
  385|       |        /*
  386|       |         * If there is only a bottom half to the number, just do it
  387|       |         */
  388|  41.6k|        if (tna > tnb)
  ------------------
  |  Branch (388:13): [True: 2.22k, False: 39.3k]
  ------------------
  389|  2.22k|            j = tna - i;
  390|  39.3k|        else
  391|  39.3k|            j = tnb - i;
  392|  41.6k|        if (j == 0) {
  ------------------
  |  Branch (392:13): [True: 1.88k, False: 39.7k]
  ------------------
  393|  1.88k|            bn_mul_recursive(&(r[n2]), &(a[n]), &(b[n]),
  394|  1.88k|                             i, tna - i, tnb - i, p);
  395|  1.88k|            memset(&r[n2 + i * 2], 0, sizeof(*r) * (n2 - i * 2));
  396|  39.7k|        } else if (j > 0) {     /* eg, n == 16, i == 8 and tn == 11 */
  ------------------
  |  Branch (396:20): [True: 11.5k, False: 28.2k]
  ------------------
  397|  11.5k|            bn_mul_part_recursive(&(r[n2]), &(a[n]), &(b[n]),
  398|  11.5k|                                  i, tna - i, tnb - i, p);
  399|  11.5k|            memset(&(r[n2 + tna + tnb]), 0,
  400|  11.5k|                   sizeof(BN_ULONG) * (n2 - tna - tnb));
  401|  28.2k|        } else {                /* (j < 0) eg, n == 16, i == 8 and tn == 5 */
  402|       |
  403|  28.2k|            memset(&r[n2], 0, sizeof(*r) * n2);
  404|  28.2k|            if (tna < BN_MUL_RECURSIVE_SIZE_NORMAL
  ------------------
  |  |  355|  56.4k|# define BN_MUL_RECURSIVE_SIZE_NORMAL            (16)/* 32 less than */
  ------------------
  |  Branch (404:17): [True: 21.9k, False: 6.25k]
  ------------------
  405|  28.2k|                && tnb < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  355|  21.9k|# define BN_MUL_RECURSIVE_SIZE_NORMAL            (16)/* 32 less than */
  ------------------
  |  Branch (405:20): [True: 21.6k, False: 360]
  ------------------
  406|  21.6k|                bn_mul_normal(&(r[n2]), &(a[n]), tna, &(b[n]), tnb);
  407|  21.6k|            } else {
  408|  7.30k|                for (;;) {
  409|  7.30k|                    i /= 2;
  410|       |                    /*
  411|       |                     * these simplified conditions work exclusively because
  412|       |                     * difference between tna and tnb is 1 or 0
  413|       |                     */
  414|  7.30k|                    if (i < tna || i < tnb) {
  ------------------
  |  Branch (414:25): [True: 5.14k, False: 2.15k]
  |  Branch (414:36): [True: 434, False: 1.72k]
  ------------------
  415|  5.58k|                        bn_mul_part_recursive(&(r[n2]),
  416|  5.58k|                                              &(a[n]), &(b[n]),
  417|  5.58k|                                              i, tna - i, tnb - i, p);
  418|  5.58k|                        break;
  419|  5.58k|                    } else if (i == tna || i == tnb) {
  ------------------
  |  Branch (419:32): [True: 675, False: 1.04k]
  |  Branch (419:44): [True: 360, False: 689]
  ------------------
  420|  1.03k|                        bn_mul_recursive(&(r[n2]),
  421|  1.03k|                                         &(a[n]), &(b[n]),
  422|  1.03k|                                         i, tna - i, tnb - i, p);
  423|  1.03k|                        break;
  424|  1.03k|                    }
  425|  7.30k|                }
  426|  6.61k|            }
  427|  28.2k|        }
  428|  41.6k|    }
  429|       |
  430|       |    /*-
  431|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0]), c1 is the sign
  432|       |     * r[10] holds (a[0]*b[0])
  433|       |     * r[32] holds (b[1]*b[1])
  434|       |     */
  435|       |
  436|  48.0k|    c1 = (int)(bn_add_words(t, r, &(r[n2]), n2));
  437|       |
  438|  48.0k|    if (neg) {                  /* if t[32] is negative */
  ------------------
  |  Branch (438:9): [True: 41.4k, False: 6.54k]
  ------------------
  439|  41.4k|        c1 -= (int)(bn_sub_words(&(t[n2]), t, &(t[n2]), n2));
  440|  41.4k|    } else {
  441|       |        /* Might have a carry */
  442|  6.54k|        c1 += (int)(bn_add_words(&(t[n2]), &(t[n2]), t, n2));
  443|  6.54k|    }
  444|       |
  445|       |    /*-
  446|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0])+(a[0]*b[0])+(a[1]*b[1])
  447|       |     * r[10] holds (a[0]*b[0])
  448|       |     * r[32] holds (b[1]*b[1])
  449|       |     * c1 holds the carry bits
  450|       |     */
  451|  48.0k|    c1 += (int)(bn_add_words(&(r[n]), &(r[n]), &(t[n2]), n2));
  452|  48.0k|    if (c1) {
  ------------------
  |  Branch (452:9): [True: 1.15k, False: 46.8k]
  ------------------
  453|  1.15k|        p = &(r[n + n2]);
  454|  1.15k|        lo = *p;
  455|  1.15k|        ln = (lo + c1) & BN_MASK2;
  ------------------
  |  |   87|  1.15k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  456|  1.15k|        *p = ln;
  457|       |
  458|       |        /*
  459|       |         * The overflow will stop before we over write words we should not
  460|       |         * overwrite
  461|       |         */
  462|  1.15k|        if (ln < (BN_ULONG)c1) {
  ------------------
  |  Branch (462:13): [True: 396, False: 755]
  ------------------
  463|    922|            do {
  464|    922|                p++;
  465|    922|                lo = *p;
  466|    922|                ln = (lo + 1) & BN_MASK2;
  ------------------
  |  |   87|    922|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  467|    922|                *p = ln;
  468|    922|            } while (ln == 0);
  ------------------
  |  Branch (468:22): [True: 526, False: 396]
  ------------------
  469|    396|        }
  470|  1.15k|    }
  471|  48.0k|}
BN_mul:
  498|   241k|{
  499|   241k|    int ret = bn_mul_fixed_top(r, a, b, ctx);
  500|       |
  501|   241k|    bn_correct_top(r);
  502|   241k|    bn_check_top(r);
  503|       |
  504|   241k|    return ret;
  505|   241k|}
bn_mul_fixed_top:
  508|   258k|{
  509|   258k|    int ret = 0;
  510|   258k|    int top, al, bl;
  511|   258k|    BIGNUM *rr;
  512|   258k|#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
  513|   258k|    int i;
  514|   258k|#endif
  515|   258k|#ifdef BN_RECURSION
  516|   258k|    BIGNUM *t = NULL;
  517|   258k|    int j = 0, k;
  518|   258k|#endif
  519|       |
  520|   258k|    bn_check_top(a);
  521|   258k|    bn_check_top(b);
  522|   258k|    bn_check_top(r);
  523|       |
  524|   258k|    al = a->top;
  525|   258k|    bl = b->top;
  526|       |
  527|   258k|    if ((al == 0) || (bl == 0)) {
  ------------------
  |  Branch (527:9): [True: 3.11k, False: 255k]
  |  Branch (527:22): [True: 975, False: 254k]
  ------------------
  528|  4.09k|        BN_zero(r);
  ------------------
  |  |  196|  4.09k|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  529|  4.09k|        return 1;
  530|  4.09k|    }
  531|   254k|    top = al + bl;
  532|       |
  533|   254k|    BN_CTX_start(ctx);
  534|   254k|    if ((r == a) || (r == b)) {
  ------------------
  |  Branch (534:9): [True: 0, False: 254k]
  |  Branch (534:21): [True: 0, False: 254k]
  ------------------
  535|      0|        if ((rr = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (535:13): [True: 0, False: 0]
  ------------------
  536|      0|            goto err;
  537|      0|    } else
  538|   254k|        rr = r;
  539|       |
  540|   254k|#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
  541|   254k|    i = al - bl;
  542|   254k|#endif
  543|   254k|#ifdef BN_MUL_COMBA
  544|   254k|    if (i == 0) {
  ------------------
  |  Branch (544:9): [True: 194k, False: 60.1k]
  ------------------
  545|       |# if 0
  546|       |        if (al == 4) {
  547|       |            if (bn_wexpand(rr, 8) == NULL)
  548|       |                goto err;
  549|       |            rr->top = 8;
  550|       |            bn_mul_comba4(rr->d, a->d, b->d);
  551|       |            goto end;
  552|       |        }
  553|       |# endif
  554|   194k|        if (al == 8) {
  ------------------
  |  Branch (554:13): [True: 534, False: 194k]
  ------------------
  555|    534|            if (bn_wexpand(rr, 16) == NULL)
  ------------------
  |  Branch (555:17): [True: 0, False: 534]
  ------------------
  556|      0|                goto err;
  557|    534|            rr->top = 16;
  558|    534|            bn_mul_comba8(rr->d, a->d, b->d);
  559|    534|            goto end;
  560|    534|        }
  561|   194k|    }
  562|   254k|#endif                          /* BN_MUL_COMBA */
  563|   254k|#ifdef BN_RECURSION
  564|   254k|    if ((al >= BN_MULL_SIZE_NORMAL) && (bl >= BN_MULL_SIZE_NORMAL)) {
  ------------------
  |  |  354|   254k|# define BN_MULL_SIZE_NORMAL                     (16)/* 32 */
  ------------------
                  if ((al >= BN_MULL_SIZE_NORMAL) && (bl >= BN_MULL_SIZE_NORMAL)) {
  ------------------
  |  |  354|  52.2k|# define BN_MULL_SIZE_NORMAL                     (16)/* 32 */
  ------------------
  |  Branch (564:9): [True: 52.2k, False: 202k]
  |  Branch (564:40): [True: 45.7k, False: 6.52k]
  ------------------
  565|  45.7k|        if (i >= -1 && i <= 1) {
  ------------------
  |  Branch (565:13): [True: 44.2k, False: 1.45k]
  |  Branch (565:24): [True: 43.6k, False: 634]
  ------------------
  566|       |            /*
  567|       |             * Find out the power of two lower or equal to the longest of the
  568|       |             * two numbers
  569|       |             */
  570|  43.6k|            if (i >= 0) {
  ------------------
  |  Branch (570:17): [True: 36.2k, False: 7.40k]
  ------------------
  571|  36.2k|                j = BN_num_bits_word((BN_ULONG)al);
  572|  36.2k|            }
  573|  43.6k|            if (i == -1) {
  ------------------
  |  Branch (573:17): [True: 7.40k, False: 36.2k]
  ------------------
  574|  7.40k|                j = BN_num_bits_word((BN_ULONG)bl);
  575|  7.40k|            }
  576|  43.6k|            j = 1 << (j - 1);
  577|  43.6k|            assert(j <= al || j <= bl);
  578|  43.6k|            k = j + j;
  579|  43.6k|            t = BN_CTX_get(ctx);
  580|  43.6k|            if (t == NULL)
  ------------------
  |  Branch (580:17): [True: 0, False: 43.6k]
  ------------------
  581|      0|                goto err;
  582|  43.6k|            if (al > j || bl > j) {
  ------------------
  |  Branch (582:17): [True: 28.1k, False: 15.4k]
  |  Branch (582:27): [True: 2.77k, False: 12.7k]
  ------------------
  583|  30.9k|                if (bn_wexpand(t, k * 4) == NULL)
  ------------------
  |  Branch (583:21): [True: 0, False: 30.9k]
  ------------------
  584|      0|                    goto err;
  585|  30.9k|                if (bn_wexpand(rr, k * 4) == NULL)
  ------------------
  |  Branch (585:21): [True: 0, False: 30.9k]
  ------------------
  586|      0|                    goto err;
  587|  30.9k|                bn_mul_part_recursive(rr->d, a->d, b->d,
  588|  30.9k|                                      j, al - j, bl - j, t->d);
  589|  30.9k|            } else {            /* al <= j || bl <= j */
  590|       |
  591|  12.7k|                if (bn_wexpand(t, k * 2) == NULL)
  ------------------
  |  Branch (591:21): [True: 0, False: 12.7k]
  ------------------
  592|      0|                    goto err;
  593|  12.7k|                if (bn_wexpand(rr, k * 2) == NULL)
  ------------------
  |  Branch (593:21): [True: 0, False: 12.7k]
  ------------------
  594|      0|                    goto err;
  595|  12.7k|                bn_mul_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  596|  12.7k|            }
  597|  43.6k|            rr->top = top;
  598|  43.6k|            goto end;
  599|  43.6k|        }
  600|  45.7k|    }
  601|   210k|#endif                          /* BN_RECURSION */
  602|   210k|    if (bn_wexpand(rr, top) == NULL)
  ------------------
  |  Branch (602:9): [True: 0, False: 210k]
  ------------------
  603|      0|        goto err;
  604|   210k|    rr->top = top;
  605|   210k|    bn_mul_normal(rr->d, a->d, al, b->d, bl);
  606|       |
  607|   210k|#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
  608|   254k| end:
  609|   254k|#endif
  610|   254k|    rr->neg = a->neg ^ b->neg;
  611|   254k|    rr->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   254k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  612|   254k|    if (r != rr && BN_copy(r, rr) == NULL)
  ------------------
  |  Branch (612:9): [True: 0, False: 254k]
  |  Branch (612:20): [True: 0, False: 0]
  ------------------
  613|      0|        goto err;
  614|       |
  615|   254k|    ret = 1;
  616|   254k| err:
  617|   254k|    bn_check_top(r);
  618|   254k|    BN_CTX_end(ctx);
  619|   254k|    return ret;
  620|   254k|}
bn_mul_normal:
  623|   241k|{
  624|   241k|    BN_ULONG *rr;
  ------------------
  |  |   31|   241k|#  define BN_ULONG        unsigned long
  ------------------
  625|       |
  626|   241k|    if (na < nb) {
  ------------------
  |  Branch (626:9): [True: 47.5k, False: 194k]
  ------------------
  627|  47.5k|        int itmp;
  628|  47.5k|        BN_ULONG *ltmp;
  ------------------
  |  |   31|  47.5k|#  define BN_ULONG        unsigned long
  ------------------
  629|       |
  630|  47.5k|        itmp = na;
  631|  47.5k|        na = nb;
  632|  47.5k|        nb = itmp;
  633|  47.5k|        ltmp = a;
  634|  47.5k|        a = b;
  635|  47.5k|        b = ltmp;
  636|       |
  637|  47.5k|    }
  638|   241k|    rr = &(r[na]);
  639|   241k|    if (nb <= 0) {
  ------------------
  |  Branch (639:9): [True: 4.36k, False: 237k]
  ------------------
  640|  4.36k|        (void)bn_mul_words(r, a, na, 0);
  641|  4.36k|        return;
  642|  4.36k|    } else
  643|   237k|        rr[0] = bn_mul_words(r, a, na, b[0]);
  644|       |
  645|   272k|    for (;;) {
  646|   272k|        if (--nb <= 0)
  ------------------
  |  Branch (646:13): [True: 206k, False: 66.2k]
  ------------------
  647|   206k|            return;
  648|  66.2k|        rr[1] = bn_mul_add_words(&(r[1]), a, na, b[1]);
  649|  66.2k|        if (--nb <= 0)
  ------------------
  |  Branch (649:13): [True: 12.0k, False: 54.2k]
  ------------------
  650|  12.0k|            return;
  651|  54.2k|        rr[2] = bn_mul_add_words(&(r[2]), a, na, b[2]);
  652|  54.2k|        if (--nb <= 0)
  ------------------
  |  Branch (652:13): [True: 11.1k, False: 43.0k]
  ------------------
  653|  11.1k|            return;
  654|  43.0k|        rr[3] = bn_mul_add_words(&(r[3]), a, na, b[3]);
  655|  43.0k|        if (--nb <= 0)
  ------------------
  |  Branch (655:13): [True: 7.35k, False: 35.7k]
  ------------------
  656|  7.35k|            return;
  657|  35.7k|        rr[4] = bn_mul_add_words(&(r[4]), a, na, b[4]);
  658|  35.7k|        rr += 4;
  659|  35.7k|        r += 4;
  660|  35.7k|        b += 4;
  661|  35.7k|    }
  662|   237k|}

BN_RECP_CTX_init:
   14|  1.61k|{
   15|  1.61k|    memset(recp, 0, sizeof(*recp));
   16|  1.61k|    bn_init(&(recp->N));
   17|  1.61k|    bn_init(&(recp->Nr));
   18|  1.61k|}
BN_RECP_CTX_free:
   36|  1.61k|{
   37|  1.61k|    if (recp == NULL)
  ------------------
  |  Branch (37:9): [True: 0, False: 1.61k]
  ------------------
   38|      0|        return;
   39|  1.61k|    BN_free(&recp->N);
   40|  1.61k|    BN_free(&recp->Nr);
   41|  1.61k|    if (recp->flags & BN_FLG_MALLOCED)
  ------------------
  |  |   52|  1.61k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (41:9): [True: 0, False: 1.61k]
  ------------------
   42|      0|        OPENSSL_free(recp);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   43|  1.61k|}
BN_RECP_CTX_set:
   46|  1.61k|{
   47|  1.61k|    if (!BN_copy(&(recp->N), d))
  ------------------
  |  Branch (47:9): [True: 0, False: 1.61k]
  ------------------
   48|      0|        return 0;
   49|  1.61k|    BN_zero(&(recp->Nr));
  ------------------
  |  |  196|  1.61k|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
   50|  1.61k|    recp->num_bits = BN_num_bits(d);
   51|  1.61k|    recp->shift = 0;
   52|  1.61k|    return 1;
   53|  1.61k|}
BN_mod_mul_reciprocal:
   57|   112k|{
   58|   112k|    int ret = 0;
   59|   112k|    BIGNUM *a;
   60|   112k|    const BIGNUM *ca;
   61|       |
   62|   112k|    BN_CTX_start(ctx);
   63|   112k|    if ((a = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (63:9): [True: 0, False: 112k]
  ------------------
   64|      0|        goto err;
   65|   112k|    if (y != NULL) {
  ------------------
  |  Branch (65:9): [True: 112k, False: 0]
  ------------------
   66|   112k|        if (x == y) {
  ------------------
  |  Branch (66:13): [True: 90.2k, False: 22.4k]
  ------------------
   67|  90.2k|            if (!BN_sqr(a, x, ctx))
  ------------------
  |  Branch (67:17): [True: 0, False: 90.2k]
  ------------------
   68|      0|                goto err;
   69|  90.2k|        } else {
   70|  22.4k|            if (!BN_mul(a, x, y, ctx))
  ------------------
  |  Branch (70:17): [True: 0, False: 22.4k]
  ------------------
   71|      0|                goto err;
   72|  22.4k|        }
   73|   112k|        ca = a;
   74|   112k|    } else
   75|      0|        ca = x;                 /* Just do the mod */
   76|       |
   77|   112k|    ret = BN_div_recp(NULL, r, ca, recp, ctx);
   78|   112k| err:
   79|   112k|    BN_CTX_end(ctx);
   80|   112k|    bn_check_top(r);
   81|   112k|    return ret;
   82|   112k|}
BN_div_recp:
   86|   112k|{
   87|   112k|    int i, j, ret = 0;
   88|   112k|    BIGNUM *a, *b, *d, *r;
   89|       |
   90|   112k|    BN_CTX_start(ctx);
   91|   112k|    d = (dv != NULL) ? dv : BN_CTX_get(ctx);
  ------------------
  |  Branch (91:9): [True: 0, False: 112k]
  ------------------
   92|   112k|    r = (rem != NULL) ? rem : BN_CTX_get(ctx);
  ------------------
  |  Branch (92:9): [True: 112k, False: 0]
  ------------------
   93|   112k|    a = BN_CTX_get(ctx);
   94|   112k|    b = BN_CTX_get(ctx);
   95|   112k|    if (b == NULL)
  ------------------
  |  Branch (95:9): [True: 0, False: 112k]
  ------------------
   96|      0|        goto err;
   97|       |
   98|   112k|    if (BN_ucmp(m, &(recp->N)) < 0) {
  ------------------
  |  Branch (98:9): [True: 19.2k, False: 93.4k]
  ------------------
   99|  19.2k|        BN_zero(d);
  ------------------
  |  |  196|  19.2k|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  100|  19.2k|        if (!BN_copy(r, m)) {
  ------------------
  |  Branch (100:13): [True: 0, False: 19.2k]
  ------------------
  101|      0|            BN_CTX_end(ctx);
  102|      0|            return 0;
  103|      0|        }
  104|  19.2k|        BN_CTX_end(ctx);
  105|  19.2k|        return 1;
  106|  19.2k|    }
  107|       |
  108|       |    /*
  109|       |     * We want the remainder Given input of ABCDEF / ab we need multiply
  110|       |     * ABCDEF by 3 digests of the reciprocal of ab
  111|       |     */
  112|       |
  113|       |    /* i := max(BN_num_bits(m), 2*BN_num_bits(N)) */
  114|  93.4k|    i = BN_num_bits(m);
  115|  93.4k|    j = recp->num_bits << 1;
  116|  93.4k|    if (j > i)
  ------------------
  |  Branch (116:9): [True: 77.4k, False: 15.9k]
  ------------------
  117|  77.4k|        i = j;
  118|       |
  119|       |    /* Nr := round(2^i / N) */
  120|  93.4k|    if (i != recp->shift)
  ------------------
  |  Branch (120:9): [True: 1.58k, False: 91.8k]
  ------------------
  121|  1.58k|        recp->shift = BN_reciprocal(&(recp->Nr), &(recp->N), i, ctx);
  122|       |    /* BN_reciprocal could have returned -1 for an error */
  123|  93.4k|    if (recp->shift == -1)
  ------------------
  |  Branch (123:9): [True: 0, False: 93.4k]
  ------------------
  124|      0|        goto err;
  125|       |
  126|       |    /*-
  127|       |     * d := |round(round(m / 2^BN_num_bits(N)) * recp->Nr / 2^(i - BN_num_bits(N)))|
  128|       |     *    = |round(round(m / 2^BN_num_bits(N)) * round(2^i / N) / 2^(i - BN_num_bits(N)))|
  129|       |     *   <= |(m / 2^BN_num_bits(N)) * (2^i / N) * (2^BN_num_bits(N) / 2^i)|
  130|       |     *    = |m/N|
  131|       |     */
  132|  93.4k|    if (!BN_rshift(a, m, recp->num_bits))
  ------------------
  |  Branch (132:9): [True: 0, False: 93.4k]
  ------------------
  133|      0|        goto err;
  134|  93.4k|    if (!BN_mul(b, a, &(recp->Nr), ctx))
  ------------------
  |  Branch (134:9): [True: 0, False: 93.4k]
  ------------------
  135|      0|        goto err;
  136|  93.4k|    if (!BN_rshift(d, b, i - recp->num_bits))
  ------------------
  |  Branch (136:9): [True: 0, False: 93.4k]
  ------------------
  137|      0|        goto err;
  138|  93.4k|    d->neg = 0;
  139|       |
  140|  93.4k|    if (!BN_mul(b, &(recp->N), d, ctx))
  ------------------
  |  Branch (140:9): [True: 0, False: 93.4k]
  ------------------
  141|      0|        goto err;
  142|  93.4k|    if (!BN_usub(r, m, b))
  ------------------
  |  Branch (142:9): [True: 0, False: 93.4k]
  ------------------
  143|      0|        goto err;
  144|  93.4k|    r->neg = 0;
  145|       |
  146|  93.4k|    j = 0;
  147|   154k|    while (BN_ucmp(r, &(recp->N)) >= 0) {
  ------------------
  |  Branch (147:12): [True: 60.8k, False: 93.4k]
  ------------------
  148|  60.8k|        if (j++ > 2) {
  ------------------
  |  Branch (148:13): [True: 0, False: 60.8k]
  ------------------
  149|      0|            BNerr(BN_F_BN_DIV_RECP, BN_R_BAD_RECIPROCAL);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  150|      0|            goto err;
  151|      0|        }
  152|  60.8k|        if (!BN_usub(r, r, &(recp->N)))
  ------------------
  |  Branch (152:13): [True: 0, False: 60.8k]
  ------------------
  153|      0|            goto err;
  154|  60.8k|        if (!BN_add_word(d, 1))
  ------------------
  |  Branch (154:13): [True: 0, False: 60.8k]
  ------------------
  155|      0|            goto err;
  156|  60.8k|    }
  157|       |
  158|  93.4k|    r->neg = BN_is_zero(r) ? 0 : m->neg;
  ------------------
  |  Branch (158:14): [True: 58, False: 93.3k]
  ------------------
  159|  93.4k|    d->neg = m->neg ^ recp->N.neg;
  160|  93.4k|    ret = 1;
  161|  93.4k| err:
  162|  93.4k|    BN_CTX_end(ctx);
  163|  93.4k|    bn_check_top(dv);
  164|  93.4k|    bn_check_top(rem);
  165|  93.4k|    return ret;
  166|  93.4k|}
BN_reciprocal:
  175|  1.58k|{
  176|  1.58k|    int ret = -1;
  177|  1.58k|    BIGNUM *t;
  178|       |
  179|  1.58k|    BN_CTX_start(ctx);
  180|  1.58k|    if ((t = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (180:9): [True: 0, False: 1.58k]
  ------------------
  181|      0|        goto err;
  182|       |
  183|  1.58k|    if (!BN_set_bit(t, len))
  ------------------
  |  Branch (183:9): [True: 0, False: 1.58k]
  ------------------
  184|      0|        goto err;
  185|       |
  186|  1.58k|    if (!BN_div(r, NULL, t, m, ctx))
  ------------------
  |  Branch (186:9): [True: 0, False: 1.58k]
  ------------------
  187|      0|        goto err;
  188|       |
  189|  1.58k|    ret = len;
  190|  1.58k| err:
  191|  1.58k|    bn_check_top(r);
  192|  1.58k|    BN_CTX_end(ctx);
  193|  1.58k|    return ret;
  194|  1.58k|}

BN_rshift1:
   46|  60.7k|{
   47|  60.7k|    BN_ULONG *ap, *rp, t, c;
  ------------------
  |  |   31|  60.7k|#  define BN_ULONG        unsigned long
  ------------------
   48|  60.7k|    int i;
   49|       |
   50|  60.7k|    bn_check_top(r);
   51|  60.7k|    bn_check_top(a);
   52|       |
   53|  60.7k|    if (BN_is_zero(a)) {
  ------------------
  |  Branch (53:9): [True: 0, False: 60.7k]
  ------------------
   54|      0|        BN_zero(r);
  ------------------
  |  |  196|      0|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
   55|      0|        return 1;
   56|      0|    }
   57|  60.7k|    i = a->top;
   58|  60.7k|    ap = a->d;
   59|  60.7k|    if (a != r) {
  ------------------
  |  Branch (59:9): [True: 0, False: 60.7k]
  ------------------
   60|      0|        if (bn_wexpand(r, i) == NULL)
  ------------------
  |  Branch (60:13): [True: 0, False: 0]
  ------------------
   61|      0|            return 0;
   62|      0|        r->neg = a->neg;
   63|      0|    }
   64|  60.7k|    rp = r->d;
   65|  60.7k|    r->top = i;
   66|  60.7k|    t = ap[--i];
   67|  60.7k|    rp[i] = t >> 1;
   68|  60.7k|    c = t << (BN_BITS2 - 1);
  ------------------
  |  |   48|  60.7k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  60.7k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
   69|  60.7k|    r->top -= (t == 1);
   70|  85.3k|    while (i > 0) {
  ------------------
  |  Branch (70:12): [True: 24.6k, False: 60.7k]
  ------------------
   71|  24.6k|        t = ap[--i];
   72|  24.6k|        rp[i] = ((t >> 1) & BN_MASK2) | c;
  ------------------
  |  |   87|  24.6k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   73|  24.6k|        c = t << (BN_BITS2 - 1);
  ------------------
  |  |   48|  24.6k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|  24.6k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
   74|  24.6k|    }
   75|  60.7k|    if (!r->top)
  ------------------
  |  Branch (75:9): [True: 0, False: 60.7k]
  ------------------
   76|      0|        r->neg = 0; /* don't allow negative zero */
   77|  60.7k|    bn_check_top(r);
   78|  60.7k|    return 1;
   79|  60.7k|}
BN_lshift:
   82|  1.39k|{
   83|  1.39k|    int ret;
   84|       |
   85|  1.39k|    if (n < 0) {
  ------------------
  |  Branch (85:9): [True: 0, False: 1.39k]
  ------------------
   86|      0|        BNerr(BN_F_BN_LSHIFT, BN_R_INVALID_SHIFT);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
   87|      0|        return 0;
   88|      0|    }
   89|       |
   90|  1.39k|    ret = bn_lshift_fixed_top(r, a, n);
   91|       |
   92|  1.39k|    bn_correct_top(r);
   93|  1.39k|    bn_check_top(r);
   94|       |
   95|  1.39k|    return ret;
   96|  1.39k|}
bn_lshift_fixed_top:
  105|   194k|{
  106|   194k|    int i, nw;
  107|   194k|    unsigned int lb, rb;
  108|   194k|    BN_ULONG *t, *f;
  ------------------
  |  |   31|   194k|#  define BN_ULONG        unsigned long
  ------------------
  109|   194k|    BN_ULONG l, m, rmask = 0;
  ------------------
  |  |   31|   194k|#  define BN_ULONG        unsigned long
  ------------------
  110|       |
  111|   194k|    assert(n >= 0);
  112|       |
  113|   194k|    bn_check_top(r);
  114|   194k|    bn_check_top(a);
  115|       |
  116|   194k|    nw = n / BN_BITS2;
  ------------------
  |  |   48|   194k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   194k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  117|   194k|    if (bn_wexpand(r, a->top + nw + 1) == NULL)
  ------------------
  |  Branch (117:9): [True: 0, False: 194k]
  ------------------
  118|      0|        return 0;
  119|       |
  120|   194k|    if (a->top != 0) {
  ------------------
  |  Branch (120:9): [True: 186k, False: 8.05k]
  ------------------
  121|   186k|        lb = (unsigned int)n % BN_BITS2;
  ------------------
  |  |   48|   186k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   186k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  122|   186k|        rb = BN_BITS2 - lb;
  ------------------
  |  |   48|   186k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   186k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  123|   186k|        rb %= BN_BITS2;            /* say no to undefined behaviour */
  ------------------
  |  |   48|   186k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   186k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  124|   186k|        rmask = (BN_ULONG)0 - rb;  /* rmask = 0 - (rb != 0) */
  125|   186k|        rmask |= rmask >> 8;
  126|   186k|        f = &(a->d[0]);
  127|   186k|        t = &(r->d[nw]);
  128|   186k|        l = f[a->top - 1];
  129|   186k|        t[a->top] = (l >> rb) & rmask;
  130|  2.37M|        for (i = a->top - 1; i > 0; i--) {
  ------------------
  |  Branch (130:30): [True: 2.18M, False: 186k]
  ------------------
  131|  2.18M|            m = l << lb;
  132|  2.18M|            l = f[i - 1];
  133|  2.18M|            t[i] = (m | ((l >> rb) & rmask)) & BN_MASK2;
  ------------------
  |  |   87|  2.18M|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  134|  2.18M|        }
  135|   186k|        t[0] = (l << lb) & BN_MASK2;
  ------------------
  |  |   87|   186k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  136|   186k|    } else {
  137|       |        /* shouldn't happen, but formally required */
  138|  8.05k|        r->d[nw] = 0;
  139|  8.05k|    }
  140|   194k|    if (nw != 0)
  ------------------
  |  Branch (140:9): [True: 1.39k, False: 192k]
  ------------------
  141|  1.39k|        memset(r->d, 0, sizeof(*t) * nw);
  142|       |
  143|   194k|    r->neg = a->neg;
  144|   194k|    r->top = a->top + nw + 1;
  145|   194k|    r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   194k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  146|       |
  147|   194k|    return 1;
  148|   194k|}
BN_rshift:
  151|   238k|{
  152|   238k|    int ret = 0;
  153|       |
  154|   238k|    if (n < 0) {
  ------------------
  |  Branch (154:9): [True: 0, False: 238k]
  ------------------
  155|      0|        BNerr(BN_F_BN_RSHIFT, BN_R_INVALID_SHIFT);
  ------------------
  |  |  102|      0|# define BNerr(f,r)   ERR_PUT_error(ERR_LIB_BN,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  156|      0|        return 0;
  157|      0|    }
  158|       |
  159|   238k|    ret = bn_rshift_fixed_top(r, a, n);
  160|       |
  161|   238k|    bn_correct_top(r);
  162|   238k|    bn_check_top(r);
  163|       |
  164|   238k|    return ret;
  165|   238k|}
bn_rshift_fixed_top:
  174|   428k|{
  175|   428k|    int i, top, nw;
  176|   428k|    unsigned int lb, rb;
  177|   428k|    BN_ULONG *t, *f;
  ------------------
  |  |   31|   428k|#  define BN_ULONG        unsigned long
  ------------------
  178|   428k|    BN_ULONG l, m, mask;
  ------------------
  |  |   31|   428k|#  define BN_ULONG        unsigned long
  ------------------
  179|       |
  180|   428k|    bn_check_top(r);
  181|   428k|    bn_check_top(a);
  182|       |
  183|   428k|    assert(n >= 0);
  184|       |
  185|   428k|    nw = n / BN_BITS2;
  ------------------
  |  |   48|   428k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   428k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  186|   428k|    if (nw >= a->top) {
  ------------------
  |  Branch (186:9): [True: 946, False: 427k]
  ------------------
  187|       |        /* shouldn't happen, but formally required */
  188|    946|        BN_zero(r);
  ------------------
  |  |  196|    946|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  189|    946|        return 1;
  190|    946|    }
  191|       |
  192|   427k|    rb = (unsigned int)n % BN_BITS2;
  ------------------
  |  |   48|   427k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   427k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  193|   427k|    lb = BN_BITS2 - rb;
  ------------------
  |  |   48|   427k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   427k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  194|   427k|    lb %= BN_BITS2;            /* say no to undefined behaviour */
  ------------------
  |  |   48|   427k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   32|   427k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  195|   427k|    mask = (BN_ULONG)0 - lb;   /* mask = 0 - (lb != 0) */
  196|   427k|    mask |= mask >> 8;
  197|   427k|    top = a->top - nw;
  198|   427k|    if (r != a && bn_wexpand(r, top) == NULL)
  ------------------
  |  Branch (198:9): [True: 375k, False: 51.4k]
  |  Branch (198:19): [True: 0, False: 375k]
  ------------------
  199|      0|        return 0;
  200|       |
  201|   427k|    t = &(r->d[0]);
  202|   427k|    f = &(a->d[nw]);
  203|   427k|    l = f[0];
  204|  3.82M|    for (i = 0; i < top - 1; i++) {
  ------------------
  |  Branch (204:17): [True: 3.39M, False: 427k]
  ------------------
  205|  3.39M|        m = f[i + 1];
  206|  3.39M|        t[i] = (l >> rb) | ((m << lb) & mask);
  207|  3.39M|        l = m;
  208|  3.39M|    }
  209|   427k|    t[i] = l >> rb;
  210|       |
  211|   427k|    r->neg = a->neg;
  212|   427k|    r->top = top;
  213|   427k|    r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   427k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  214|       |
  215|   427k|    return 1;
  216|   427k|}

BN_sqr:
   18|   224k|{
   19|   224k|    int ret = bn_sqr_fixed_top(r, a, ctx);
   20|       |
   21|   224k|    bn_correct_top(r);
   22|   224k|    bn_check_top(r);
   23|       |
   24|   224k|    return ret;
   25|   224k|}
bn_sqr_fixed_top:
   28|   370k|{
   29|   370k|    int max, al;
   30|   370k|    int ret = 0;
   31|   370k|    BIGNUM *tmp, *rr;
   32|       |
   33|   370k|    bn_check_top(a);
   34|       |
   35|   370k|    al = a->top;
   36|   370k|    if (al <= 0) {
  ------------------
  |  Branch (36:9): [True: 12.1k, False: 358k]
  ------------------
   37|  12.1k|        r->top = 0;
   38|  12.1k|        r->neg = 0;
   39|  12.1k|        return 1;
   40|  12.1k|    }
   41|       |
   42|   358k|    BN_CTX_start(ctx);
   43|   358k|    rr = (a != r) ? r : BN_CTX_get(ctx);
  ------------------
  |  Branch (43:10): [True: 358k, False: 0]
  ------------------
   44|   358k|    tmp = BN_CTX_get(ctx);
   45|   358k|    if (rr == NULL || tmp == NULL)
  ------------------
  |  Branch (45:9): [True: 0, False: 358k]
  |  Branch (45:23): [True: 0, False: 358k]
  ------------------
   46|      0|        goto err;
   47|       |
   48|   358k|    max = 2 * al;               /* Non-zero (from above) */
   49|   358k|    if (bn_wexpand(rr, max) == NULL)
  ------------------
  |  Branch (49:9): [True: 0, False: 358k]
  ------------------
   50|      0|        goto err;
   51|       |
   52|   358k|    if (al == 4) {
  ------------------
  |  Branch (52:9): [True: 1.76k, False: 356k]
  ------------------
   53|       |#ifndef BN_SQR_COMBA
   54|       |        BN_ULONG t[8];
   55|       |        bn_sqr_normal(rr->d, a->d, 4, t);
   56|       |#else
   57|  1.76k|        bn_sqr_comba4(rr->d, a->d);
   58|  1.76k|#endif
   59|   356k|    } else if (al == 8) {
  ------------------
  |  Branch (59:16): [True: 526, False: 356k]
  ------------------
   60|       |#ifndef BN_SQR_COMBA
   61|       |        BN_ULONG t[16];
   62|       |        bn_sqr_normal(rr->d, a->d, 8, t);
   63|       |#else
   64|    526|        bn_sqr_comba8(rr->d, a->d);
   65|    526|#endif
   66|   356k|    } else {
   67|   356k|#if defined(BN_RECURSION)
   68|   356k|        if (al < BN_SQR_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  356|   356k|# define BN_SQR_RECURSIVE_SIZE_NORMAL            (16)/* 32 */
  ------------------
  |  Branch (68:13): [True: 321k, False: 34.4k]
  ------------------
   69|   321k|            BN_ULONG t[BN_SQR_RECURSIVE_SIZE_NORMAL * 2];
  ------------------
  |  |   31|   321k|#  define BN_ULONG        unsigned long
  ------------------
   70|   321k|            bn_sqr_normal(rr->d, a->d, al, t);
   71|   321k|        } else {
   72|  34.4k|            int j, k;
   73|       |
   74|  34.4k|            j = BN_num_bits_word((BN_ULONG)al);
   75|  34.4k|            j = 1 << (j - 1);
   76|  34.4k|            k = j + j;
   77|  34.4k|            if (al == j) {
  ------------------
  |  Branch (77:17): [True: 12.2k, False: 22.2k]
  ------------------
   78|  12.2k|                if (bn_wexpand(tmp, k * 2) == NULL)
  ------------------
  |  Branch (78:21): [True: 0, False: 12.2k]
  ------------------
   79|      0|                    goto err;
   80|  12.2k|                bn_sqr_recursive(rr->d, a->d, al, tmp->d);
   81|  22.2k|            } else {
   82|  22.2k|                if (bn_wexpand(tmp, max) == NULL)
  ------------------
  |  Branch (82:21): [True: 0, False: 22.2k]
  ------------------
   83|      0|                    goto err;
   84|  22.2k|                bn_sqr_normal(rr->d, a->d, al, tmp->d);
   85|  22.2k|            }
   86|  34.4k|        }
   87|       |#else
   88|       |        if (bn_wexpand(tmp, max) == NULL)
   89|       |            goto err;
   90|       |        bn_sqr_normal(rr->d, a->d, al, tmp->d);
   91|       |#endif
   92|   356k|    }
   93|       |
   94|   358k|    rr->neg = 0;
   95|   358k|    rr->top = max;
   96|   358k|    rr->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  219|   358k|#  define BN_FLG_FIXED_TOP 0
  ------------------
   97|   358k|    if (r != rr && BN_copy(r, rr) == NULL)
  ------------------
  |  Branch (97:9): [True: 0, False: 358k]
  |  Branch (97:20): [True: 0, False: 0]
  ------------------
   98|      0|        goto err;
   99|       |
  100|   358k|    ret = 1;
  101|   358k| err:
  102|   358k|    bn_check_top(rr);
  103|   358k|    bn_check_top(tmp);
  104|   358k|    BN_CTX_end(ctx);
  105|   358k|    return ret;
  106|   358k|}
bn_sqr_normal:
  110|   344k|{
  111|   344k|    int i, j, max;
  112|   344k|    const BN_ULONG *ap;
  113|   344k|    BN_ULONG *rp;
  ------------------
  |  |   31|   344k|#  define BN_ULONG        unsigned long
  ------------------
  114|       |
  115|   344k|    max = n * 2;
  116|   344k|    ap = a;
  117|   344k|    rp = r;
  118|   344k|    rp[0] = rp[max - 1] = 0;
  119|   344k|    rp++;
  120|   344k|    j = n;
  121|       |
  122|   344k|    if (--j > 0) {
  ------------------
  |  Branch (122:9): [True: 35.9k, False: 308k]
  ------------------
  123|  35.9k|        ap++;
  124|  35.9k|        rp[j] = bn_mul_words(rp, ap, j, ap[-1]);
  125|  35.9k|        rp += 2;
  126|  35.9k|    }
  127|       |
  128|  1.51M|    for (i = n - 2; i > 0; i--) {
  ------------------
  |  Branch (128:21): [True: 1.17M, False: 344k]
  ------------------
  129|  1.17M|        j--;
  130|  1.17M|        ap++;
  131|  1.17M|        rp[j] = bn_mul_add_words(rp, ap, j, ap[-1]);
  132|  1.17M|        rp += 2;
  133|  1.17M|    }
  134|       |
  135|   344k|    bn_add_words(r, r, r, max);
  136|       |
  137|       |    /* There will not be a carry */
  138|       |
  139|   344k|    bn_sqr_words(tmp, a, n);
  140|       |
  141|   344k|    bn_add_words(r, r, tmp, max);
  142|   344k|}
bn_sqr_recursive:
  157|  99.0k|{
  158|  99.0k|    int n = n2 / 2;
  159|  99.0k|    int zero, c1;
  160|  99.0k|    BN_ULONG ln, lo, *p;
  ------------------
  |  |   31|  99.0k|#  define BN_ULONG        unsigned long
  ------------------
  161|       |
  162|  99.0k|    if (n2 == 4) {
  ------------------
  |  Branch (162:9): [True: 0, False: 99.0k]
  ------------------
  163|       |# ifndef BN_SQR_COMBA
  164|       |        bn_sqr_normal(r, a, 4, t);
  165|       |# else
  166|      0|        bn_sqr_comba4(r, a);
  167|      0|# endif
  168|      0|        return;
  169|  99.0k|    } else if (n2 == 8) {
  ------------------
  |  Branch (169:16): [True: 69.9k, False: 29.0k]
  ------------------
  170|       |# ifndef BN_SQR_COMBA
  171|       |        bn_sqr_normal(r, a, 8, t);
  172|       |# else
  173|  69.9k|        bn_sqr_comba8(r, a);
  174|  69.9k|# endif
  175|  69.9k|        return;
  176|  69.9k|    }
  177|  29.0k|    if (n2 < BN_SQR_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  356|  29.0k|# define BN_SQR_RECURSIVE_SIZE_NORMAL            (16)/* 32 */
  ------------------
  |  Branch (177:9): [True: 0, False: 29.0k]
  ------------------
  178|      0|        bn_sqr_normal(r, a, n2, t);
  179|      0|        return;
  180|      0|    }
  181|       |    /* r=(a[0]-a[1])*(a[1]-a[0]) */
  182|  29.0k|    c1 = bn_cmp_words(a, &(a[n]), n);
  183|  29.0k|    zero = 0;
  184|  29.0k|    if (c1 > 0)
  ------------------
  |  Branch (184:9): [True: 16.8k, False: 12.2k]
  ------------------
  185|  16.8k|        bn_sub_words(t, a, &(a[n]), n);
  186|  12.2k|    else if (c1 < 0)
  ------------------
  |  Branch (186:14): [True: 11.7k, False: 413]
  ------------------
  187|  11.7k|        bn_sub_words(t, &(a[n]), a, n);
  188|    413|    else
  189|    413|        zero = 1;
  190|       |
  191|       |    /* The result will always be negative unless it is zero */
  192|  29.0k|    p = &(t[n2 * 2]);
  193|       |
  194|  29.0k|    if (!zero)
  ------------------
  |  Branch (194:9): [True: 28.6k, False: 413]
  ------------------
  195|  28.6k|        bn_sqr_recursive(&(t[n2]), t, n, p);
  196|    413|    else
  197|    413|        memset(&t[n2], 0, sizeof(*t) * n2);
  198|  29.0k|    bn_sqr_recursive(r, a, n, p);
  199|  29.0k|    bn_sqr_recursive(&(r[n2]), &(a[n]), n, p);
  200|       |
  201|       |    /*-
  202|       |     * t[32] holds (a[0]-a[1])*(a[1]-a[0]), it is negative or zero
  203|       |     * r[10] holds (a[0]*b[0])
  204|       |     * r[32] holds (b[1]*b[1])
  205|       |     */
  206|       |
  207|  29.0k|    c1 = (int)(bn_add_words(t, r, &(r[n2]), n2));
  208|       |
  209|       |    /* t[32] is negative */
  210|  29.0k|    c1 -= (int)(bn_sub_words(&(t[n2]), t, &(t[n2]), n2));
  211|       |
  212|       |    /*-
  213|       |     * t[32] holds (a[0]-a[1])*(a[1]-a[0])+(a[0]*a[0])+(a[1]*a[1])
  214|       |     * r[10] holds (a[0]*a[0])
  215|       |     * r[32] holds (a[1]*a[1])
  216|       |     * c1 holds the carry bits
  217|       |     */
  218|  29.0k|    c1 += (int)(bn_add_words(&(r[n]), &(r[n]), &(t[n2]), n2));
  219|  29.0k|    if (c1) {
  ------------------
  |  Branch (219:9): [True: 9.14k, False: 19.9k]
  ------------------
  220|  9.14k|        p = &(r[n + n2]);
  221|  9.14k|        lo = *p;
  222|  9.14k|        ln = (lo + c1) & BN_MASK2;
  ------------------
  |  |   87|  9.14k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  223|  9.14k|        *p = ln;
  224|       |
  225|       |        /*
  226|       |         * The overflow will stop before we over write words we should not
  227|       |         * overwrite
  228|       |         */
  229|  9.14k|        if (ln < (BN_ULONG)c1) {
  ------------------
  |  Branch (229:13): [True: 427, False: 8.71k]
  ------------------
  230|    831|            do {
  231|    831|                p++;
  232|    831|                lo = *p;
  233|    831|                ln = (lo + 1) & BN_MASK2;
  ------------------
  |  |   87|    831|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  234|    831|                *p = ln;
  235|    831|            } while (ln == 0);
  ------------------
  |  Branch (235:22): [True: 404, False: 427]
  ------------------
  236|    427|        }
  237|  9.14k|    }
  238|  29.0k|}

BN_add_word:
   99|  60.8k|{
  100|  60.8k|    BN_ULONG l;
  ------------------
  |  |   31|  60.8k|#  define BN_ULONG        unsigned long
  ------------------
  101|  60.8k|    int i;
  102|       |
  103|  60.8k|    bn_check_top(a);
  104|  60.8k|    w &= BN_MASK2;
  ------------------
  |  |   87|  60.8k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  105|       |
  106|       |    /* degenerate case: w is zero */
  107|  60.8k|    if (!w)
  ------------------
  |  Branch (107:9): [True: 0, False: 60.8k]
  ------------------
  108|      0|        return 1;
  109|       |    /* degenerate case: a is zero */
  110|  60.8k|    if (BN_is_zero(a))
  ------------------
  |  Branch (110:9): [True: 919, False: 59.9k]
  ------------------
  111|    919|        return BN_set_word(a, w);
  112|       |    /* handle 'a' when negative */
  113|  59.9k|    if (a->neg) {
  ------------------
  |  Branch (113:9): [True: 0, False: 59.9k]
  ------------------
  114|      0|        a->neg = 0;
  115|      0|        i = BN_sub_word(a, w);
  116|      0|        if (!BN_is_zero(a))
  ------------------
  |  Branch (116:13): [True: 0, False: 0]
  ------------------
  117|      0|            a->neg = !(a->neg);
  118|      0|        return i;
  119|      0|    }
  120|   120k|    for (i = 0; w != 0 && i < a->top; i++) {
  ------------------
  |  Branch (120:17): [True: 60.9k, False: 59.7k]
  |  Branch (120:27): [True: 60.7k, False: 197]
  ------------------
  121|  60.7k|        a->d[i] = l = (a->d[i] + w) & BN_MASK2;
  ------------------
  |  |   87|  60.7k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  122|  60.7k|        w = (w > l) ? 1 : 0;
  ------------------
  |  Branch (122:13): [True: 985, False: 59.7k]
  ------------------
  123|  60.7k|    }
  124|  59.9k|    if (w && i == a->top) {
  ------------------
  |  Branch (124:9): [True: 197, False: 59.7k]
  |  Branch (124:14): [True: 197, False: 0]
  ------------------
  125|    197|        if (bn_wexpand(a, a->top + 1) == NULL)
  ------------------
  |  Branch (125:13): [True: 0, False: 197]
  ------------------
  126|      0|            return 0;
  127|    197|        a->top++;
  128|    197|        a->d[i] = w;
  129|    197|    }
  130|  59.9k|    bn_check_top(a);
  131|  59.9k|    return 1;
  132|  59.9k|}
BN_sub_word:
  135|  1.35k|{
  136|  1.35k|    int i;
  137|       |
  138|  1.35k|    bn_check_top(a);
  139|  1.35k|    w &= BN_MASK2;
  ------------------
  |  |   87|  1.35k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  140|       |
  141|       |    /* degenerate case: w is zero */
  142|  1.35k|    if (!w)
  ------------------
  |  Branch (142:9): [True: 0, False: 1.35k]
  ------------------
  143|      0|        return 1;
  144|       |    /* degenerate case: a is zero */
  145|  1.35k|    if (BN_is_zero(a)) {
  ------------------
  |  Branch (145:9): [True: 0, False: 1.35k]
  ------------------
  146|      0|        i = BN_set_word(a, w);
  147|      0|        if (i != 0)
  ------------------
  |  Branch (147:13): [True: 0, False: 0]
  ------------------
  148|      0|            BN_set_negative(a, 1);
  149|      0|        return i;
  150|      0|    }
  151|       |    /* handle 'a' when negative */
  152|  1.35k|    if (a->neg) {
  ------------------
  |  Branch (152:9): [True: 0, False: 1.35k]
  ------------------
  153|      0|        a->neg = 0;
  154|      0|        i = BN_add_word(a, w);
  155|      0|        a->neg = 1;
  156|      0|        return i;
  157|      0|    }
  158|       |
  159|  1.35k|    if ((a->top == 1) && (a->d[0] < w)) {
  ------------------
  |  Branch (159:9): [True: 0, False: 1.35k]
  |  Branch (159:26): [True: 0, False: 0]
  ------------------
  160|      0|        a->d[0] = w - a->d[0];
  161|      0|        a->neg = 1;
  162|      0|        return 1;
  163|      0|    }
  164|  1.35k|    i = 0;
  165|  2.71k|    for (;;) {
  166|  2.71k|        if (a->d[i] >= w) {
  ------------------
  |  Branch (166:13): [True: 1.35k, False: 1.35k]
  ------------------
  167|  1.35k|            a->d[i] -= w;
  168|  1.35k|            break;
  169|  1.35k|        } else {
  170|  1.35k|            a->d[i] = (a->d[i] - w) & BN_MASK2;
  ------------------
  |  |   87|  1.35k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  171|  1.35k|            i++;
  172|  1.35k|            w = 1;
  173|  1.35k|        }
  174|  2.71k|    }
  175|  1.35k|    if ((a->d[i] == 0) && (i == (a->top - 1)))
  ------------------
  |  Branch (175:9): [True: 186, False: 1.17k]
  |  Branch (175:27): [True: 186, False: 0]
  ------------------
  176|    186|        a->top--;
  177|  1.35k|    bn_check_top(a);
  178|  1.35k|    return 1;
  179|  1.35k|}
BN_mul_word:
  182|  15.3k|{
  183|  15.3k|    BN_ULONG ll;
  ------------------
  |  |   31|  15.3k|#  define BN_ULONG        unsigned long
  ------------------
  184|       |
  185|  15.3k|    bn_check_top(a);
  186|  15.3k|    w &= BN_MASK2;
  ------------------
  |  |   87|  15.3k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  187|  15.3k|    if (a->top) {
  ------------------
  |  Branch (187:9): [True: 15.1k, False: 259]
  ------------------
  188|  15.1k|        if (w == 0)
  ------------------
  |  Branch (188:13): [True: 0, False: 15.1k]
  ------------------
  189|      0|            BN_zero(a);
  ------------------
  |  |  196|      0|#  define BN_zero(a)      (BN_set_word((a),0))
  ------------------
  190|  15.1k|        else {
  191|  15.1k|            ll = bn_mul_words(a->d, a->d, a->top, w);
  192|  15.1k|            if (ll) {
  ------------------
  |  Branch (192:17): [True: 11.9k, False: 3.21k]
  ------------------
  193|  11.9k|                if (bn_wexpand(a, a->top + 1) == NULL)
  ------------------
  |  Branch (193:21): [True: 0, False: 11.9k]
  ------------------
  194|      0|                    return 0;
  195|  11.9k|                a->d[a->top++] = ll;
  196|  11.9k|            }
  197|  15.1k|        }
  198|  15.1k|    }
  199|  15.3k|    bn_check_top(a);
  200|  15.3k|    return 1;
  201|  15.3k|}

ERR_load_BUF_strings:
   30|      2|{
   31|      2|#ifndef OPENSSL_NO_ERR
   32|      2|    if (ERR_func_error_string(BUF_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (32:9): [True: 2, False: 0]
  ------------------
   33|      2|        ERR_load_strings_const(BUF_str_functs);
   34|      2|        ERR_load_strings_const(BUF_str_reasons);
   35|      2|    }
   36|      2|#endif
   37|      2|    return 1;
   38|      2|}

ERR_load_CMS_strings:
  291|      2|{
  292|      2|#ifndef OPENSSL_NO_ERR
  293|      2|    if (ERR_func_error_string(CMS_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (293:9): [True: 2, False: 0]
  ------------------
  294|      2|        ERR_load_strings_const(CMS_str_functs);
  295|      2|        ERR_load_strings_const(CMS_str_reasons);
  296|      2|    }
  297|      2|#endif
  298|      2|    return 1;
  299|      2|}

ERR_load_COMP_strings:
   38|      2|{
   39|      2|#ifndef OPENSSL_NO_ERR
   40|      2|    if (ERR_func_error_string(COMP_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (40:9): [True: 2, False: 0]
  ------------------
   41|      2|        ERR_load_strings_const(COMP_str_functs);
   42|      2|        ERR_load_strings_const(COMP_str_reasons);
   43|      2|    }
   44|      2|#endif
   45|      2|    return 1;
   46|      2|}

ERR_load_CONF_strings:
   87|      2|{
   88|      2|#ifndef OPENSSL_NO_ERR
   89|      2|    if (ERR_func_error_string(CONF_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (89:9): [True: 2, False: 0]
  ------------------
   90|      2|        ERR_load_strings_const(CONF_str_functs);
   91|      2|        ERR_load_strings_const(CONF_str_reasons);
   92|      2|    }
   93|      2|#endif
   94|      2|    return 1;
   95|      2|}

CONF_modules_unload:
  360|      2|{
  361|      2|    int i;
  362|      2|    CONF_MODULE *md;
  363|      2|    CONF_modules_finish();
  364|       |    /* unload modules in reverse order */
  365|      2|    for (i = sk_CONF_MODULE_num(supported_modules) - 1; i >= 0; i--) {
  ------------------
  |  Branch (365:57): [True: 0, False: 2]
  ------------------
  366|      0|        md = sk_CONF_MODULE_value(supported_modules, i);
  367|       |        /* If static or in use and 'all' not set ignore it */
  368|      0|        if (((md->links > 0) || !md->dso) && !all)
  ------------------
  |  Branch (368:14): [True: 0, False: 0]
  |  Branch (368:33): [True: 0, False: 0]
  |  Branch (368:46): [True: 0, False: 0]
  ------------------
  369|      0|            continue;
  370|       |        /* Since we're working in reverse this is OK */
  371|      0|        (void)sk_CONF_MODULE_delete(supported_modules, i);
  372|      0|        module_free(md);
  373|      0|    }
  374|      2|    if (sk_CONF_MODULE_num(supported_modules) == 0) {
  ------------------
  |  Branch (374:9): [True: 0, False: 2]
  ------------------
  375|      0|        sk_CONF_MODULE_free(supported_modules);
  376|      0|        supported_modules = NULL;
  377|      0|    }
  378|      2|}
CONF_modules_finish:
  391|      4|{
  392|      4|    CONF_IMODULE *imod;
  393|      4|    while (sk_CONF_IMODULE_num(initialized_modules) > 0) {
  ------------------
  |  Branch (393:12): [True: 0, False: 4]
  ------------------
  394|      0|        imod = sk_CONF_IMODULE_pop(initialized_modules);
  395|      0|        module_finish(imod);
  396|      0|    }
  397|      4|    sk_CONF_IMODULE_free(initialized_modules);
  398|      4|    initialized_modules = NULL;
  399|      4|}
conf_modules_free_int:
  427|      2|{
  428|      2|    CONF_modules_finish();
  429|      2|    CONF_modules_unload(1);
  430|      2|}

ERR_load_CRYPTO_strings:
   69|      2|{
   70|      2|#ifndef OPENSSL_NO_ERR
   71|      2|    if (ERR_func_error_string(CRYPTO_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (71:9): [True: 2, False: 0]
  ------------------
   72|      2|        ERR_load_strings_const(CRYPTO_str_functs);
   73|      2|        ERR_load_strings_const(CRYPTO_str_reasons);
   74|      2|    }
   75|      2|#endif
   76|      2|    return 1;
   77|      2|}

OPENSSL_cpuid_setup:
   98|      4|{
   99|      4|    static int trigger = 0;
  100|      4|    IA32CAP OPENSSL_ia32_cpuid(unsigned int *);
  101|      4|    IA32CAP vec;
  102|      4|    const variant_char *env;
  103|       |
  104|      4|    if (trigger)
  ------------------
  |  Branch (104:9): [True: 2, False: 2]
  ------------------
  105|      2|        return;
  106|       |
  107|      2|    trigger = 1;
  108|      2|    if ((env = ossl_getenv("OPENSSL_ia32cap")) != NULL) {
  ------------------
  |  |   49|      2|#   define ossl_getenv getenv
  ------------------
  |  Branch (108:9): [True: 0, False: 2]
  ------------------
  109|      0|        int off = (env[0] == '~') ? 1 : 0;
  ------------------
  |  Branch (109:19): [True: 0, False: 0]
  ------------------
  110|       |
  111|      0|        vec = ossl_strtouint64(env + off);
  112|       |
  113|      0|        if (off) {
  ------------------
  |  Branch (113:13): [True: 0, False: 0]
  ------------------
  114|      0|            IA32CAP mask = vec;
  115|      0|            vec = OPENSSL_ia32_cpuid(OPENSSL_ia32cap_P) & ~mask;
  116|      0|            if (mask & (1<<24)) {
  ------------------
  |  Branch (116:17): [True: 0, False: 0]
  ------------------
  117|       |                /*
  118|       |                 * User disables FXSR bit, mask even other capabilities
  119|       |                 * that operate exclusively on XMM, so we don't have to
  120|       |                 * double-check all the time. We mask PCLMULQDQ, AMD XOP,
  121|       |                 * AES-NI and AVX. Formally speaking we don't have to
  122|       |                 * do it in x86_64 case, but we can safely assume that
  123|       |                 * x86_64 users won't actually flip this flag.
  124|       |                 */
  125|      0|                vec &= ~((IA32CAP)(1<<1|1<<11|1<<25|1<<28) << 32);
  126|      0|            }
  127|      0|        } else if (env[0] == ':') {
  ------------------
  |  Branch (127:20): [True: 0, False: 0]
  ------------------
  128|      0|            vec = OPENSSL_ia32_cpuid(OPENSSL_ia32cap_P);
  129|      0|        }
  130|       |
  131|      0|        if ((env = ossl_strchr(env, ':')) != NULL) {
  ------------------
  |  Branch (131:13): [True: 0, False: 0]
  ------------------
  132|      0|            IA32CAP vecx;
  133|       |
  134|      0|            env++;
  135|      0|            off = (env[0] == '~') ? 1 : 0;
  ------------------
  |  Branch (135:19): [True: 0, False: 0]
  ------------------
  136|      0|            vecx = ossl_strtouint64(env + off);
  137|      0|            if (off) {
  ------------------
  |  Branch (137:17): [True: 0, False: 0]
  ------------------
  138|      0|                OPENSSL_ia32cap_P[2] &= ~(unsigned int)vecx;
  139|      0|                OPENSSL_ia32cap_P[3] &= ~(unsigned int)(vecx >> 32);
  140|      0|            } else {
  141|      0|                OPENSSL_ia32cap_P[2] = (unsigned int)vecx;
  142|      0|                OPENSSL_ia32cap_P[3] = (unsigned int)(vecx >> 32);
  143|      0|            }
  144|      0|        } else {
  145|      0|            OPENSSL_ia32cap_P[2] = 0;
  146|      0|            OPENSSL_ia32cap_P[3] = 0;
  147|      0|        }
  148|      2|    } else {
  149|      2|        vec = OPENSSL_ia32_cpuid(OPENSSL_ia32cap_P);
  150|      2|    }
  151|       |
  152|       |    /*
  153|       |     * |(1<<10) sets a reserved bit to signal that variable
  154|       |     * was initialized already... This is to avoid interference
  155|       |     * with cpuid snippets in ELF .init segment.
  156|       |     */
  157|      2|    OPENSSL_ia32cap_P[0] = (unsigned int)vec | (1 << 10);
  158|      2|    OPENSSL_ia32cap_P[1] = (unsigned int)(vec >> 32);
  159|      2|}

ERR_load_CT_strings:
   88|      2|{
   89|      2|#ifndef OPENSSL_NO_ERR
   90|      2|    if (ERR_func_error_string(CT_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (90:9): [True: 2, False: 0]
  ------------------
   91|      2|        ERR_load_strings_const(CT_str_functs);
   92|      2|        ERR_load_strings_const(CT_str_reasons);
   93|      2|    }
   94|      2|#endif
   95|      2|    return 1;
   96|      2|}

ossl_ctype_check:
  253|    250|{
  254|    250|    const int max = sizeof(ctype_char_map) / sizeof(*ctype_char_map);
  255|    250|    const int a = ossl_toascii(c);
  ------------------
  |  |   53|    250|#  define ossl_toascii(c)       (c)
  ------------------
  256|       |
  257|    250|    return a >= 0 && a < max && (ctype_char_map[a] & mask) != 0;
  ------------------
  |  Branch (257:12): [True: 250, False: 0]
  |  Branch (257:22): [True: 250, False: 0]
  |  Branch (257:33): [True: 0, False: 250]
  ------------------
  258|    250|}

ERR_load_DH_strings:
   94|      2|{
   95|      2|#ifndef OPENSSL_NO_ERR
   96|      2|    if (ERR_func_error_string(DH_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (96:9): [True: 2, False: 0]
  ------------------
   97|      2|        ERR_load_strings_const(DH_str_functs);
   98|      2|        ERR_load_strings_const(DH_str_reasons);
   99|      2|    }
  100|      2|#endif
  101|      2|    return 1;
  102|      2|}

ERR_load_DSA_strings:
   70|      2|{
   71|      2|#ifndef OPENSSL_NO_ERR
   72|      2|    if (ERR_func_error_string(DSA_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (72:9): [True: 2, False: 0]
  ------------------
   73|      2|        ERR_load_strings_const(DSA_str_functs);
   74|      2|        ERR_load_strings_const(DSA_str_reasons);
   75|      2|    }
   76|      2|#endif
   77|      2|    return 1;
   78|      2|}

ERR_load_DSO_strings:
   92|      2|{
   93|      2|#ifndef OPENSSL_NO_ERR
   94|      2|    if (ERR_func_error_string(DSO_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (94:9): [True: 2, False: 0]
  ------------------
   95|      2|        ERR_load_strings_const(DSO_str_functs);
   96|      2|        ERR_load_strings_const(DSO_str_reasons);
   97|      2|    }
   98|      2|#endif
   99|      2|    return 1;
  100|      2|}

ERR_load_EC_strings:
  387|      2|{
  388|      2|#ifndef OPENSSL_NO_ERR
  389|      2|    if (ERR_func_error_string(EC_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (389:9): [True: 2, False: 0]
  ------------------
  390|      2|        ERR_load_strings_const(EC_str_functs);
  391|      2|        ERR_load_strings_const(EC_str_reasons);
  392|      2|    }
  393|      2|#endif
  394|      2|    return 1;
  395|      2|}

ERR_load_ENGINE_strings:
  146|      2|{
  147|      2|#ifndef OPENSSL_NO_ERR
  148|      2|    if (ERR_func_error_string(ENGINE_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (148:9): [True: 2, False: 0]
  ------------------
  149|      2|        ERR_load_strings_const(ENGINE_str_functs);
  150|      2|        ERR_load_strings_const(ENGINE_str_reasons);
  151|      2|    }
  152|      2|#endif
  153|      2|    return 1;
  154|      2|}

engine_cleanup_int:
  169|      2|{
  170|      2|    if (int_cleanup_check(0)) {
  ------------------
  |  Branch (170:9): [True: 0, False: 2]
  ------------------
  171|      0|        sk_ENGINE_CLEANUP_ITEM_pop_free(cleanup_stack,
  172|      0|                                        engine_cleanup_cb_free);
  173|      0|        cleanup_stack = NULL;
  174|      0|    }
  175|      2|    CRYPTO_THREAD_lock_free(global_engine_lock);
  176|      2|    global_engine_lock = NULL;
  177|      2|}
eng_lib.c:int_cleanup_check:
  117|      2|{
  118|      2|    if (cleanup_stack)
  ------------------
  |  Branch (118:9): [True: 0, False: 2]
  ------------------
  119|      0|        return 1;
  120|      2|    if (!create)
  ------------------
  |  Branch (120:9): [True: 2, False: 0]
  ------------------
  121|      2|        return 0;
  122|      0|    cleanup_stack = sk_ENGINE_CLEANUP_ITEM_new_null();
  123|      0|    return (cleanup_stack ? 1 : 0);
  ------------------
  |  Branch (123:13): [True: 0, False: 0]
  ------------------
  124|      2|}

err_cleanup:
  321|      2|{
  322|      2|    if (set_err_thread_local != 0)
  ------------------
  |  Branch (322:9): [True: 2, False: 0]
  ------------------
  323|      2|        CRYPTO_THREAD_cleanup_local(&err_thread_local);
  324|      2|    CRYPTO_THREAD_lock_free(err_string_lock);
  325|      2|    err_string_lock = NULL;
  326|      2|#ifndef OPENSSL_NO_ERR
  327|      2|    lh_ERR_STRING_DATA_free(int_error_hash);
  328|      2|    int_error_hash = NULL;
  329|      2|#endif
  330|      2|}
ERR_load_ERR_strings:
  359|    118|{
  360|    118|#ifndef OPENSSL_NO_ERR
  361|    118|    if (!RUN_ONCE(&err_string_init, do_err_strings_init))
  ------------------
  |  |  119|    118|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 118, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (361:9): [True: 0, False: 118]
  ------------------
  362|      0|        return 0;
  363|       |
  364|    118|    err_load_strings(ERR_str_libraries);
  365|    118|    err_load_strings(ERR_str_reasons);
  366|    118|    err_patch(ERR_LIB_SYS, ERR_str_functs);
  ------------------
  |  |   55|    118|# define ERR_LIB_SYS             2
  ------------------
  367|    118|    err_load_strings(ERR_str_functs);
  368|    118|    build_SYS_str_reasons();
  369|    118|#endif
  370|    118|    return 1;
  371|    118|}
ERR_load_strings_const:
  387|    116|{
  388|    116|#ifndef OPENSSL_NO_ERR
  389|    116|    if (ERR_load_ERR_strings() == 0)
  ------------------
  |  Branch (389:9): [True: 0, False: 116]
  ------------------
  390|      0|        return 0;
  391|    116|    err_load_strings(str);
  392|    116|#endif
  393|       |
  394|    116|    return 1;
  395|    116|}
ERR_clear_error:
  461|  3.24k|{
  462|  3.24k|    int i;
  463|  3.24k|    ERR_STATE *es;
  464|       |
  465|  3.24k|    es = ERR_get_state();
  466|  3.24k|    if (es == NULL)
  ------------------
  |  Branch (466:9): [True: 0, False: 3.24k]
  ------------------
  467|      0|        return;
  468|       |
  469|  55.1k|    for (i = 0; i < ERR_NUM_ERRORS; i++) {
  ------------------
  |  |   42|  55.1k|# define ERR_NUM_ERRORS  16
  ------------------
  |  Branch (469:17): [True: 51.9k, False: 3.24k]
  ------------------
  470|  51.9k|        err_clear(es, i);
  ------------------
  |  |  281|  51.9k|        do { \
  |  |  282|  51.9k|            err_clear_data(p, i); \
  |  |  ------------------
  |  |  |  |  272|  51.9k|        do { \
  |  |  |  |  273|  51.9k|            if ((p)->err_data_flags[i] & ERR_TXT_MALLOCED) {\
  |  |  |  |  ------------------
  |  |  |  |  |  |   36|  51.9k|# define ERR_TXT_MALLOCED        0x01
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (273:17): [True: 0, False: 51.9k]
  |  |  |  |  ------------------
  |  |  |  |  274|      0|                OPENSSL_free((p)->err_data[i]); \
  |  |  |  |  ------------------
  |  |  |  |  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |  275|      0|                (p)->err_data[i] = NULL; \
  |  |  |  |  276|      0|            } \
  |  |  |  |  277|  51.9k|            (p)->err_data_flags[i] = 0; \
  |  |  |  |  278|  51.9k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (278:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  283|  51.9k|            (p)->err_flags[i] = 0; \
  |  |  284|  51.9k|            (p)->err_buffer[i] = 0; \
  |  |  285|  51.9k|            (p)->err_file[i] = NULL; \
  |  |  286|  51.9k|            (p)->err_line[i] = -1; \
  |  |  287|  51.9k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (287:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  471|  51.9k|    }
  472|  3.24k|    es->top = es->bottom = 0;
  473|  3.24k|}
ERR_func_error_string:
  676|     58|{
  677|     58|#ifndef OPENSSL_NO_ERR
  678|     58|    ERR_STRING_DATA d, *p;
  679|     58|    unsigned long l, f;
  680|       |
  681|     58|    if (!RUN_ONCE(&err_string_init, do_err_strings_init)) {
  ------------------
  |  |  119|     58|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 58, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (681:9): [True: 0, False: 58]
  ------------------
  682|      0|        return NULL;
  683|      0|    }
  684|       |
  685|     58|    l = ERR_GET_LIB(e);
  ------------------
  |  |  142|     58|# define ERR_GET_LIB(l)          (int)(((l) >> 24L) & 0x0FFL)
  ------------------
  686|     58|    f = ERR_GET_FUNC(e);
  ------------------
  |  |  143|     58|# define ERR_GET_FUNC(l)         (int)(((l) >> 12L) & 0xFFFL)
  ------------------
  687|     58|    d.error = ERR_PACK(l, f, 0);
  ------------------
  |  |  138|     58|# define ERR_PACK(l,f,r) ( \
  |  |  139|     58|        (((unsigned int)(l) & 0x0FF) << 24L) | \
  |  |  140|     58|        (((unsigned int)(f) & 0xFFF) << 12L) | \
  |  |  141|     58|        (((unsigned int)(r) & 0xFFF)       ) )
  ------------------
  688|     58|    p = int_err_get_item(&d);
  689|     58|    return ((p == NULL) ? NULL : p->string);
  ------------------
  |  Branch (689:13): [True: 58, False: 0]
  ------------------
  690|       |#else
  691|       |    return NULL;
  692|       |#endif
  693|     58|}
err_delete_thread_state:
  720|      2|{
  721|      2|    ERR_STATE *state = CRYPTO_THREAD_get_local(&err_thread_local);
  722|      2|    if (state == NULL)
  ------------------
  |  Branch (722:9): [True: 0, False: 2]
  ------------------
  723|      0|        return;
  724|       |
  725|      2|    CRYPTO_THREAD_set_local(&err_thread_local, NULL);
  726|      2|    ERR_STATE_free(state);
  727|      2|}
ERR_get_state:
  748|  3.24k|{
  749|  3.24k|    ERR_STATE *state;
  750|  3.24k|    int saveerrno = get_last_sys_error();
  ------------------
  |  |   75|  3.24k|# define get_last_sys_error()    errno
  ------------------
  751|       |
  752|  3.24k|    if (!OPENSSL_init_crypto(OPENSSL_INIT_BASE_ONLY, NULL))
  ------------------
  |  |   28|  3.24k|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (752:9): [True: 0, False: 3.24k]
  ------------------
  753|      0|        return NULL;
  754|       |
  755|  3.24k|    if (!RUN_ONCE(&err_init, err_do_init))
  ------------------
  |  |  119|  3.24k|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 3.24k, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (755:9): [True: 0, False: 3.24k]
  ------------------
  756|      0|        return NULL;
  757|       |
  758|  3.24k|    state = CRYPTO_THREAD_get_local(&err_thread_local);
  759|  3.24k|    if (state == (ERR_STATE*)-1)
  ------------------
  |  Branch (759:9): [True: 0, False: 3.24k]
  ------------------
  760|      0|        return NULL;
  761|       |
  762|  3.24k|    if (state == NULL) {
  ------------------
  |  Branch (762:9): [True: 2, False: 3.24k]
  ------------------
  763|      2|        if (!CRYPTO_THREAD_set_local(&err_thread_local, (ERR_STATE*)-1))
  ------------------
  |  Branch (763:13): [True: 0, False: 2]
  ------------------
  764|      0|            return NULL;
  765|       |
  766|      2|        if ((state = OPENSSL_zalloc(sizeof(*state))) == NULL) {
  ------------------
  |  |  120|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (766:13): [True: 0, False: 2]
  ------------------
  767|      0|            CRYPTO_THREAD_set_local(&err_thread_local, NULL);
  768|      0|            return NULL;
  769|      0|        }
  770|       |
  771|      2|        if (!ossl_init_thread_start(OPENSSL_INIT_THREAD_ERR_STATE)
  ------------------
  |  |   32|      2|# define OPENSSL_INIT_THREAD_ERR_STATE       0x02
  ------------------
  |  Branch (771:13): [True: 0, False: 2]
  ------------------
  772|      2|                || !CRYPTO_THREAD_set_local(&err_thread_local, state)) {
  ------------------
  |  Branch (772:20): [True: 0, False: 2]
  ------------------
  773|      0|            ERR_STATE_free(state);
  774|      0|            CRYPTO_THREAD_set_local(&err_thread_local, NULL);
  775|      0|            return NULL;
  776|      0|        }
  777|       |
  778|       |        /* Ignore failures from these */
  779|      2|        OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL);
  ------------------
  |  |  357|      2|# define OPENSSL_INIT_LOAD_CRYPTO_STRINGS    0x00000002L
  ------------------
  780|      2|    }
  781|       |
  782|  3.24k|    set_sys_error(saveerrno);
  ------------------
  |  |   77|  3.24k|# define set_sys_error(e)        errno=(e)
  ------------------
  783|  3.24k|    return state;
  784|  3.24k|}
err.c:do_err_strings_init:
  302|      2|{
  303|      2|    if (!OPENSSL_init_crypto(0, NULL))
  ------------------
  |  Branch (303:9): [True: 0, False: 2]
  ------------------
  304|      0|        return 0;
  305|      2|    err_string_lock = CRYPTO_THREAD_lock_new();
  306|      2|    if (err_string_lock == NULL)
  ------------------
  |  Branch (306:9): [True: 0, False: 2]
  ------------------
  307|      0|        return 0;
  308|      2|#ifndef OPENSSL_NO_ERR
  309|      2|    int_error_hash = lh_ERR_STRING_DATA_new(err_string_data_hash,
  310|      2|                                            err_string_data_cmp);
  311|      2|    if (int_error_hash == NULL) {
  ------------------
  |  Branch (311:9): [True: 0, False: 2]
  ------------------
  312|      0|        CRYPTO_THREAD_lock_free(err_string_lock);
  313|      0|        err_string_lock = NULL;
  314|      0|        return 0;
  315|      0|    }
  316|      2|#endif
  317|      2|    return 1;
  318|      2|}
err.c:err_string_data_hash:
  167|  15.2k|{
  168|  15.2k|    unsigned long ret, l;
  169|       |
  170|  15.2k|    l = a->error;
  171|  15.2k|    ret = l ^ ERR_GET_LIB(l) ^ ERR_GET_FUNC(l);
  ------------------
  |  |  142|  15.2k|# define ERR_GET_LIB(l)          (int)(((l) >> 24L) & 0x0FFL)
  ------------------
                  ret = l ^ ERR_GET_LIB(l) ^ ERR_GET_FUNC(l);
  ------------------
  |  |  143|  15.2k|# define ERR_GET_FUNC(l)         (int)(((l) >> 12L) & 0xFFFL)
  ------------------
  172|  15.2k|    return (ret ^ ret % 19 * 13);
  173|  15.2k|}
err.c:err_string_data_cmp:
  177|  10.5k|{
  178|  10.5k|    if (a->error == b->error)
  ------------------
  |  Branch (178:9): [True: 10.3k, False: 246]
  ------------------
  179|  10.3k|        return 0;
  180|    246|    return a->error > b->error ? 1 : -1;
  ------------------
  |  Branch (180:12): [True: 150, False: 96]
  ------------------
  181|  10.5k|}
err.c:err_load_strings:
  348|    472|{
  349|    472|    CRYPTO_THREAD_write_lock(err_string_lock);
  350|  15.6k|    for (; str->error; str++)
  ------------------
  |  Branch (350:12): [True: 15.1k, False: 472]
  ------------------
  351|  15.1k|        (void)lh_ERR_STRING_DATA_insert(int_error_hash,
  352|  15.1k|                                       (ERR_STRING_DATA *)str);
  353|    472|    CRYPTO_THREAD_unlock(err_string_lock);
  354|    472|    return 1;
  355|    472|}
err.c:err_patch:
  337|    118|{
  338|    118|    unsigned long plib = ERR_PACK(lib, 0, 0);
  ------------------
  |  |  138|    118|# define ERR_PACK(l,f,r) ( \
  |  |  139|    118|        (((unsigned int)(l) & 0x0FF) << 24L) | \
  |  |  140|    118|        (((unsigned int)(f) & 0xFFF) << 12L) | \
  |  |  141|    118|        (((unsigned int)(r) & 0xFFF)       ) )
  ------------------
  339|       |
  340|  2.83k|    for (; str->error != 0; str++)
  ------------------
  |  Branch (340:12): [True: 2.71k, False: 118]
  ------------------
  341|  2.71k|        str->error |= plib;
  342|    118|}
err.c:build_SYS_str_reasons:
  210|    118|{
  211|       |    /* OPENSSL_malloc cannot be used here, use static storage instead */
  212|    118|    static char strerror_pool[SPACE_SYS_STR_REASONS];
  213|    118|    char *cur = strerror_pool;
  214|    118|    size_t cnt = 0;
  215|    118|    static int init = 1;
  216|    118|    int i;
  217|    118|    int saveerrno = get_last_sys_error();
  ------------------
  |  |   75|    118|# define get_last_sys_error()    errno
  ------------------
  218|       |
  219|    118|    CRYPTO_THREAD_write_lock(err_string_lock);
  220|    118|    if (!init) {
  ------------------
  |  Branch (220:9): [True: 116, False: 2]
  ------------------
  221|    116|        CRYPTO_THREAD_unlock(err_string_lock);
  222|    116|        return;
  223|    116|    }
  224|       |
  225|    256|    for (i = 1; i <= NUM_SYS_STR_REASONS; i++) {
  ------------------
  |  |  196|    256|# define NUM_SYS_STR_REASONS 127
  ------------------
  |  Branch (225:17): [True: 254, False: 2]
  ------------------
  226|    254|        ERR_STRING_DATA *str = &SYS_str_reasons[i - 1];
  227|       |
  228|    254|        str->error = ERR_PACK(ERR_LIB_SYS, 0, i);
  ------------------
  |  |  138|    254|# define ERR_PACK(l,f,r) ( \
  |  |  139|    254|        (((unsigned int)(l) & 0x0FF) << 24L) | \
  |  |  140|    254|        (((unsigned int)(f) & 0xFFF) << 12L) | \
  |  |  141|    254|        (((unsigned int)(r) & 0xFFF)       ) )
  ------------------
  229|       |        /*
  230|       |         * If we have used up all the space in strerror_pool,
  231|       |         * there's no point in calling openssl_strerror_r()
  232|       |         */
  233|    254|        if (str->string == NULL && cnt < sizeof(strerror_pool)) {
  ------------------
  |  Branch (233:13): [True: 254, False: 0]
  |  Branch (233:36): [True: 254, False: 0]
  ------------------
  234|    254|            if (openssl_strerror_r(i, cur, sizeof(strerror_pool) - cnt)) {
  ------------------
  |  Branch (234:17): [True: 250, False: 4]
  ------------------
  235|    250|                size_t l = strlen(cur);
  236|       |
  237|    250|                str->string = cur;
  238|    250|                cnt += l;
  239|    250|                cur += l;
  240|       |
  241|       |                /*
  242|       |                 * VMS has an unusual quirk of adding spaces at the end of
  243|       |                 * some (most? all?) messages. Lets trim them off.
  244|       |                 */
  245|    250|                while (cur > strerror_pool && ossl_isspace(cur[-1])) {
  ------------------
  |  |   76|    250|# define ossl_isspace(c)        (ossl_ctype_check((c), CTYPE_MASK_space))
  |  |  ------------------
  |  |  |  |   27|    250|# define CTYPE_MASK_space       0x8
  |  |  ------------------
  |  |  |  Branch (76:33): [True: 0, False: 250]
  |  |  ------------------
  ------------------
  |  Branch (245:24): [True: 250, False: 0]
  ------------------
  246|      0|                    cur--;
  247|      0|                    cnt--;
  248|      0|                }
  249|    250|                *cur++ = '\0';
  250|    250|                cnt++;
  251|    250|            }
  252|    254|        }
  253|    254|        if (str->string == NULL)
  ------------------
  |  Branch (253:13): [True: 4, False: 250]
  ------------------
  254|      4|            str->string = "unknown";
  255|    254|    }
  256|       |
  257|       |    /*
  258|       |     * Now we still have SYS_str_reasons[NUM_SYS_STR_REASONS] = {0, NULL}, as
  259|       |     * required by ERR_load_strings.
  260|       |     */
  261|       |
  262|      2|    init = 0;
  263|       |
  264|      2|    CRYPTO_THREAD_unlock(err_string_lock);
  265|       |    /* openssl_strerror_r could change errno, but we want to preserve it */
  266|      2|    set_sys_error(saveerrno);
  ------------------
  |  |   77|      2|# define set_sys_error(e)        errno=(e)
  ------------------
  267|      2|    err_load_strings(SYS_str_reasons);
  268|      2|}
err.c:int_err_get_item:
  184|     58|{
  185|     58|    ERR_STRING_DATA *p = NULL;
  186|       |
  187|     58|    CRYPTO_THREAD_read_lock(err_string_lock);
  188|     58|    p = lh_ERR_STRING_DATA_retrieve(int_error_hash, d);
  189|     58|    CRYPTO_THREAD_unlock(err_string_lock);
  190|       |
  191|     58|    return p;
  192|     58|}
err.c:ERR_STATE_free:
  290|      2|{
  291|      2|    int i;
  292|       |
  293|      2|    if (s == NULL)
  ------------------
  |  Branch (293:9): [True: 0, False: 2]
  ------------------
  294|      0|        return;
  295|     34|    for (i = 0; i < ERR_NUM_ERRORS; i++) {
  ------------------
  |  |   42|     34|# define ERR_NUM_ERRORS  16
  ------------------
  |  Branch (295:17): [True: 32, False: 2]
  ------------------
  296|     32|        err_clear_data(s, i);
  ------------------
  |  |  272|     32|        do { \
  |  |  273|     32|            if ((p)->err_data_flags[i] & ERR_TXT_MALLOCED) {\
  |  |  ------------------
  |  |  |  |   36|     32|# define ERR_TXT_MALLOCED        0x01
  |  |  ------------------
  |  |  |  Branch (273:17): [True: 0, False: 32]
  |  |  ------------------
  |  |  274|      0|                OPENSSL_free((p)->err_data[i]); \
  |  |  ------------------
  |  |  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  275|      0|                (p)->err_data[i] = NULL; \
  |  |  276|      0|            } \
  |  |  277|     32|            (p)->err_data_flags[i] = 0; \
  |  |  278|     32|        } while (0)
  |  |  ------------------
  |  |  |  Branch (278:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  297|     32|    }
  298|      2|    OPENSSL_free(s);
  ------------------
  |  |  128|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  299|      2|}
err.c:err_do_init:
  742|      2|{
  743|      2|    set_err_thread_local = 1;
  744|      2|    return CRYPTO_THREAD_init_local(&err_thread_local, NULL);
  745|      2|}

err_load_crypto_strings_int:
   43|      2|{
   44|      2|    if (
   45|      2|#ifndef OPENSSL_NO_ERR
   46|      2|        ERR_load_ERR_strings() == 0 ||    /* include error strings for SYSerr */
  ------------------
  |  Branch (46:9): [True: 0, False: 2]
  ------------------
   47|      2|        ERR_load_BN_strings() == 0 ||
  ------------------
  |  Branch (47:9): [True: 0, False: 2]
  ------------------
   48|      2|# ifndef OPENSSL_NO_RSA
   49|      2|        ERR_load_RSA_strings() == 0 ||
  ------------------
  |  Branch (49:9): [True: 0, False: 2]
  ------------------
   50|      2|# endif
   51|      2|# ifndef OPENSSL_NO_DH
   52|      2|        ERR_load_DH_strings() == 0 ||
  ------------------
  |  Branch (52:9): [True: 0, False: 2]
  ------------------
   53|      2|# endif
   54|      2|        ERR_load_EVP_strings() == 0 ||
  ------------------
  |  Branch (54:9): [True: 0, False: 2]
  ------------------
   55|      2|        ERR_load_BUF_strings() == 0 ||
  ------------------
  |  Branch (55:9): [True: 0, False: 2]
  ------------------
   56|      2|        ERR_load_OBJ_strings() == 0 ||
  ------------------
  |  Branch (56:9): [True: 0, False: 2]
  ------------------
   57|      2|        ERR_load_PEM_strings() == 0 ||
  ------------------
  |  Branch (57:9): [True: 0, False: 2]
  ------------------
   58|      2|# ifndef OPENSSL_NO_DSA
   59|      2|        ERR_load_DSA_strings() == 0 ||
  ------------------
  |  Branch (59:9): [True: 0, False: 2]
  ------------------
   60|      2|# endif
   61|      2|        ERR_load_X509_strings() == 0 ||
  ------------------
  |  Branch (61:9): [True: 0, False: 2]
  ------------------
   62|      2|        ERR_load_ASN1_strings() == 0 ||
  ------------------
  |  Branch (62:9): [True: 0, False: 2]
  ------------------
   63|      2|        ERR_load_CONF_strings() == 0 ||
  ------------------
  |  Branch (63:9): [True: 0, False: 2]
  ------------------
   64|      2|        ERR_load_CRYPTO_strings() == 0 ||
  ------------------
  |  Branch (64:9): [True: 0, False: 2]
  ------------------
   65|      2|# ifndef OPENSSL_NO_COMP
   66|      2|        ERR_load_COMP_strings() == 0 ||
  ------------------
  |  Branch (66:9): [True: 0, False: 2]
  ------------------
   67|      2|# endif
   68|      2|# ifndef OPENSSL_NO_EC
   69|      2|        ERR_load_EC_strings() == 0 ||
  ------------------
  |  Branch (69:9): [True: 0, False: 2]
  ------------------
   70|      2|# endif
   71|       |        /* skip ERR_load_SSL_strings() because it is not in this library */
   72|      2|        ERR_load_BIO_strings() == 0 ||
  ------------------
  |  Branch (72:9): [True: 0, False: 2]
  ------------------
   73|      2|        ERR_load_PKCS7_strings() == 0 ||
  ------------------
  |  Branch (73:9): [True: 0, False: 2]
  ------------------
   74|      2|        ERR_load_X509V3_strings() == 0 ||
  ------------------
  |  Branch (74:9): [True: 0, False: 2]
  ------------------
   75|      2|        ERR_load_PKCS12_strings() == 0 ||
  ------------------
  |  Branch (75:9): [True: 0, False: 2]
  ------------------
   76|      2|        ERR_load_RAND_strings() == 0 ||
  ------------------
  |  Branch (76:9): [True: 0, False: 2]
  ------------------
   77|      2|        ERR_load_DSO_strings() == 0 ||
  ------------------
  |  Branch (77:9): [True: 0, False: 2]
  ------------------
   78|      2|# ifndef OPENSSL_NO_TS
   79|      2|        ERR_load_TS_strings() == 0 ||
  ------------------
  |  Branch (79:9): [True: 0, False: 2]
  ------------------
   80|      2|# endif
   81|      2|# ifndef OPENSSL_NO_ENGINE
   82|      2|        ERR_load_ENGINE_strings() == 0 ||
  ------------------
  |  Branch (82:9): [True: 0, False: 2]
  ------------------
   83|      2|# endif
   84|      2|# ifndef OPENSSL_NO_OCSP
   85|      2|        ERR_load_OCSP_strings() == 0 ||
  ------------------
  |  Branch (85:9): [True: 0, False: 2]
  ------------------
   86|      2|# endif
   87|      2|        ERR_load_UI_strings() == 0 ||
  ------------------
  |  Branch (87:9): [True: 0, False: 2]
  ------------------
   88|      2|# ifndef OPENSSL_NO_CMS
   89|      2|        ERR_load_CMS_strings() == 0 ||
  ------------------
  |  Branch (89:9): [True: 0, False: 2]
  ------------------
   90|      2|# endif
   91|      2|# ifndef OPENSSL_NO_CT
   92|      2|        ERR_load_CT_strings() == 0 ||
  ------------------
  |  Branch (92:9): [True: 0, False: 2]
  ------------------
   93|      2|# endif
   94|      2|        ERR_load_ASYNC_strings() == 0 ||
  ------------------
  |  Branch (94:9): [True: 0, False: 2]
  ------------------
   95|      2|#endif
   96|      2|        ERR_load_KDF_strings() == 0 ||
  ------------------
  |  Branch (96:9): [True: 0, False: 2]
  ------------------
   97|      2|        ERR_load_OSSL_STORE_strings() == 0)
  ------------------
  |  Branch (97:9): [True: 0, False: 2]
  ------------------
   98|      0|        return 0;
   99|       |
  100|      2|    return 1;
  101|      2|}

ERR_load_EVP_strings:
  287|      2|{
  288|      2|#ifndef OPENSSL_NO_ERR
  289|      2|    if (ERR_func_error_string(EVP_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (289:9): [True: 2, False: 0]
  ------------------
  290|      2|        ERR_load_strings_const(EVP_str_functs);
  291|      2|        ERR_load_strings_const(EVP_str_reasons);
  292|      2|    }
  293|      2|#endif
  294|      2|    return 1;
  295|      2|}

EVP_PBE_cleanup:
  244|      2|{
  245|      2|    sk_EVP_PBE_CTL_pop_free(pbe_algs, free_evp_pbe_ctl);
  246|      2|    pbe_algs = NULL;
  247|      2|}

evp_cleanup_int:
   81|      2|{
   82|      2|    OBJ_NAME_cleanup(OBJ_NAME_TYPE_CIPHER_METH);
  ------------------
  |  |   20|      2|# define OBJ_NAME_TYPE_CIPHER_METH       0x02
  ------------------
   83|      2|    OBJ_NAME_cleanup(OBJ_NAME_TYPE_MD_METH);
  ------------------
  |  |   19|      2|# define OBJ_NAME_TYPE_MD_METH           0x01
  ------------------
   84|       |    /*
   85|       |     * The above calls will only clean out the contents of the name hash
   86|       |     * table, but not the hash table itself.  The following line does that
   87|       |     * part.  -- Richard Levitte
   88|       |     */
   89|      2|    OBJ_NAME_cleanup(-1);
   90|       |
   91|      2|    EVP_PBE_cleanup();
   92|      2|    OBJ_sigid_free();
   93|       |
   94|      2|    evp_app_cleanup_int();
   95|      2|}

evp_app_cleanup_int:
  317|      2|{
  318|      2|    if (app_pkey_methods != NULL)
  ------------------
  |  Branch (318:9): [True: 0, False: 2]
  ------------------
  319|      0|        sk_EVP_PKEY_METHOD_pop_free(app_pkey_methods, EVP_PKEY_meth_free);
  320|      2|}

crypto_cleanup_all_ex_data_int:
   94|      2|{
   95|      2|    int i;
   96|       |
   97|     34|    for (i = 0; i < CRYPTO_EX_INDEX__COUNT; ++i) {
  ------------------
  |  |  110|     34|# define CRYPTO_EX_INDEX__COUNT          16
  ------------------
  |  Branch (97:17): [True: 32, False: 2]
  ------------------
   98|     32|        EX_CALLBACKS *ip = &ex_data[i];
   99|       |
  100|     32|        sk_EX_CALLBACK_pop_free(ip->meth, cleanup_cb);
  101|     32|        ip->meth = NULL;
  102|     32|    }
  103|       |
  104|      2|    CRYPTO_THREAD_lock_free(ex_data_lock);
  105|      2|    ex_data_lock = NULL;
  106|      2|}

ossl_init_thread_start:
  458|      2|{
  459|      2|    struct thread_local_inits_st *locals;
  460|       |
  461|      2|    if (!OPENSSL_init_crypto(0, NULL))
  ------------------
  |  Branch (461:9): [True: 0, False: 2]
  ------------------
  462|      0|        return 0;
  463|       |
  464|      2|    locals = ossl_init_get_thread_local(1);
  465|       |
  466|      2|    if (locals == NULL)
  ------------------
  |  Branch (466:9): [True: 0, False: 2]
  ------------------
  467|      0|        return 0;
  468|       |
  469|      2|    if (opts & OPENSSL_INIT_THREAD_ASYNC) {
  ------------------
  |  |   31|      2|# define OPENSSL_INIT_THREAD_ASYNC           0x01
  ------------------
  |  Branch (469:9): [True: 0, False: 2]
  ------------------
  470|       |#ifdef OPENSSL_INIT_DEBUG
  471|       |        fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_start: "
  472|       |                        "marking thread for async\n");
  473|       |#endif
  474|      0|        locals->async = 1;
  475|      0|    }
  476|       |
  477|      2|    if (opts & OPENSSL_INIT_THREAD_ERR_STATE) {
  ------------------
  |  |   32|      2|# define OPENSSL_INIT_THREAD_ERR_STATE       0x02
  ------------------
  |  Branch (477:9): [True: 2, False: 0]
  ------------------
  478|       |#ifdef OPENSSL_INIT_DEBUG
  479|       |        fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_start: "
  480|       |                        "marking thread for err_state\n");
  481|       |#endif
  482|      2|        locals->err_state = 1;
  483|      2|    }
  484|       |
  485|      2|    if (opts & OPENSSL_INIT_THREAD_RAND) {
  ------------------
  |  |   33|      2|# define OPENSSL_INIT_THREAD_RAND            0x04
  ------------------
  |  Branch (485:9): [True: 0, False: 2]
  ------------------
  486|       |#ifdef OPENSSL_INIT_DEBUG
  487|       |        fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_start: "
  488|       |                        "marking thread for rand\n");
  489|       |#endif
  490|      0|        locals->rand = 1;
  491|      0|    }
  492|       |
  493|      2|    return 1;
  494|      2|}
OPENSSL_cleanup:
  497|      2|{
  498|      2|    OPENSSL_INIT_STOP *currhandler, *lasthandler;
  499|      2|    CRYPTO_THREAD_LOCAL key;
  500|       |
  501|       |    /* If we've not been inited then no need to deinit */
  502|      2|    if (!base_inited)
  ------------------
  |  Branch (502:9): [True: 0, False: 2]
  ------------------
  503|      0|        return;
  504|       |
  505|       |    /* Might be explicitly called and also by atexit */
  506|      2|    if (stopped)
  ------------------
  |  Branch (506:9): [True: 0, False: 2]
  ------------------
  507|      0|        return;
  508|      2|    stopped = 1;
  509|       |
  510|       |    /*
  511|       |     * Thread stop may not get automatically called by the thread library for
  512|       |     * the very last thread in some situations, so call it directly.
  513|       |     */
  514|      2|    ossl_init_thread_stop(ossl_init_get_thread_local(0));
  515|       |
  516|      2|    currhandler = stop_handlers;
  517|      2|    while (currhandler != NULL) {
  ------------------
  |  Branch (517:12): [True: 0, False: 2]
  ------------------
  518|      0|        currhandler->handler();
  519|      0|        lasthandler = currhandler;
  520|      0|        currhandler = currhandler->next;
  521|      0|        OPENSSL_free(lasthandler);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  522|      0|    }
  523|      2|    stop_handlers = NULL;
  524|       |
  525|      2|    CRYPTO_THREAD_lock_free(init_lock);
  526|      2|    init_lock = NULL;
  527|       |
  528|       |    /*
  529|       |     * We assume we are single-threaded for this function, i.e. no race
  530|       |     * conditions for the various "*_inited" vars below.
  531|       |     */
  532|       |
  533|      2|#ifndef OPENSSL_NO_COMP
  534|      2|    if (zlib_inited) {
  ------------------
  |  Branch (534:9): [True: 0, False: 2]
  ------------------
  535|       |#ifdef OPENSSL_INIT_DEBUG
  536|       |        fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  537|       |                        "comp_zlib_cleanup_int()\n");
  538|       |#endif
  539|      0|        comp_zlib_cleanup_int();
  540|      0|    }
  541|      2|#endif
  542|       |
  543|      2|    if (async_inited) {
  ------------------
  |  Branch (543:9): [True: 0, False: 2]
  ------------------
  544|       |# ifdef OPENSSL_INIT_DEBUG
  545|       |        fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  546|       |                        "async_deinit()\n");
  547|       |# endif
  548|      0|        async_deinit();
  549|      0|    }
  550|       |
  551|      2|    key = destructor_key.value;
  552|      2|    destructor_key.sane = -1;
  553|      2|    CRYPTO_THREAD_cleanup_local(&key);
  554|       |
  555|       |#ifdef OPENSSL_INIT_DEBUG
  556|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  557|       |                    "rand_cleanup_int()\n");
  558|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  559|       |                    "conf_modules_free_int()\n");
  560|       |#ifndef OPENSSL_NO_ENGINE
  561|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  562|       |                    "engine_cleanup_int()\n");
  563|       |#endif
  564|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  565|       |                    "crypto_cleanup_all_ex_data_int()\n");
  566|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  567|       |                    "bio_sock_cleanup_int()\n");
  568|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  569|       |                    "bio_cleanup()\n");
  570|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  571|       |                    "evp_cleanup_int()\n");
  572|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  573|       |                    "obj_cleanup_int()\n");
  574|       |    fprintf(stderr, "OPENSSL_INIT: OPENSSL_cleanup: "
  575|       |                    "err_cleanup()\n");
  576|       |#endif
  577|       |    /*
  578|       |     * Note that cleanup order is important:
  579|       |     * - rand_cleanup_int could call an ENGINE's RAND cleanup function so
  580|       |     * must be called before engine_cleanup_int()
  581|       |     * - ENGINEs use CRYPTO_EX_DATA and therefore, must be cleaned up
  582|       |     * before the ex data handlers are wiped in CRYPTO_cleanup_all_ex_data().
  583|       |     * - conf_modules_free_int() can end up in ENGINE code so must be called
  584|       |     * before engine_cleanup_int()
  585|       |     * - ENGINEs and additional EVP algorithms might use added OIDs names so
  586|       |     * obj_cleanup_int() must be called last
  587|       |     */
  588|      2|    rand_cleanup_int();
  589|      2|    rand_drbg_cleanup_int();
  590|      2|    conf_modules_free_int();
  591|      2|#ifndef OPENSSL_NO_ENGINE
  592|      2|    engine_cleanup_int();
  593|      2|#endif
  594|      2|    ossl_store_cleanup_int();
  595|      2|    crypto_cleanup_all_ex_data_int();
  596|      2|    bio_cleanup();
  597|      2|    evp_cleanup_int();
  598|      2|    obj_cleanup_int();
  599|      2|    err_cleanup();
  600|       |
  601|      2|    CRYPTO_secure_malloc_done();
  602|       |
  603|      2|    base_inited = 0;
  604|      2|}
OPENSSL_init_crypto:
  612|  3.25k|{
  613|  3.25k|    if (stopped) {
  ------------------
  |  Branch (613:9): [True: 0, False: 3.25k]
  ------------------
  614|      0|        if (!(opts & OPENSSL_INIT_BASE_ONLY))
  ------------------
  |  |   28|      0|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (614:13): [True: 0, False: 0]
  ------------------
  615|      0|            CRYPTOerr(CRYPTO_F_OPENSSL_INIT_CRYPTO, ERR_R_INIT_FAIL);
  ------------------
  |  |  113|      0|# define CRYPTOerr(f,r) ERR_PUT_error(ERR_LIB_CRYPTO,(f),(r),OPENSSL_FILE,OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |   29|      0|#  define ERR_PUT_error(a,b,c,d,e)        ERR_put_error(a,b,c,d,e)
  |  |  ------------------
  ------------------
  616|      0|        return 0;
  617|      0|    }
  618|       |
  619|       |    /*
  620|       |     * When the caller specifies OPENSSL_INIT_BASE_ONLY, that should be the
  621|       |     * *only* option specified.  With that option we return immediately after
  622|       |     * doing the requested limited initialization.  Note that
  623|       |     * err_shelve_state() called by us via ossl_init_load_crypto_nodelete()
  624|       |     * re-enters OPENSSL_init_crypto() with OPENSSL_INIT_BASE_ONLY, but with
  625|       |     * base already initialized this is a harmless NOOP.
  626|       |     *
  627|       |     * If we remain the only caller of err_shelve_state() the recursion should
  628|       |     * perhaps be removed, but if in doubt, it can be left in place.
  629|       |     */
  630|  3.25k|    if (!RUN_ONCE(&base, ossl_init_base))
  ------------------
  |  |  119|  3.25k|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 3.25k, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (630:9): [True: 0, False: 3.25k]
  ------------------
  631|      0|        return 0;
  632|  3.25k|    if (opts & OPENSSL_INIT_BASE_ONLY)
  ------------------
  |  |   28|  3.25k|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (632:9): [True: 3.24k, False: 8]
  ------------------
  633|  3.24k|        return 1;
  634|       |
  635|       |    /*
  636|       |     * Now we don't always set up exit handlers, the INIT_BASE_ONLY calls
  637|       |     * should not have the side-effect of setting up exit handlers, and
  638|       |     * therefore, this code block is below the INIT_BASE_ONLY-conditioned early
  639|       |     * return above.
  640|       |     */
  641|      8|    if ((opts & OPENSSL_INIT_NO_ATEXIT) != 0) {
  ------------------
  |  |  375|      8|# define OPENSSL_INIT_NO_ATEXIT              0x00080000L
  ------------------
  |  Branch (641:9): [True: 0, False: 8]
  ------------------
  642|      0|        if (!RUN_ONCE_ALT(&register_atexit, ossl_init_no_register_atexit,
  ------------------
  |  |  137|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (137:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (642:13): [True: 0, False: 0]
  ------------------
  643|      0|                          ossl_init_register_atexit))
  644|      0|            return 0;
  645|      8|    } else if (!RUN_ONCE(&register_atexit, ossl_init_register_atexit)) {
  ------------------
  |  |  119|      8|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 8, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (645:16): [True: 0, False: 8]
  ------------------
  646|      0|        return 0;
  647|      0|    }
  648|       |
  649|      8|    if (!RUN_ONCE(&load_crypto_nodelete, ossl_init_load_crypto_nodelete))
  ------------------
  |  |  119|      8|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 8, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (649:9): [True: 0, False: 8]
  ------------------
  650|      0|        return 0;
  651|       |
  652|      8|    if ((opts & OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS)
  ------------------
  |  |  356|      8|# define OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS 0x00000001L
  ------------------
  |  Branch (652:9): [True: 0, False: 8]
  ------------------
  653|      8|            && !RUN_ONCE_ALT(&load_crypto_strings,
  ------------------
  |  |  137|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (137:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (653:16): [True: 0, False: 0]
  ------------------
  654|      8|                             ossl_init_no_load_crypto_strings,
  655|      8|                             ossl_init_load_crypto_strings))
  656|      0|        return 0;
  657|       |
  658|      8|    if ((opts & OPENSSL_INIT_LOAD_CRYPTO_STRINGS)
  ------------------
  |  |  357|      8|# define OPENSSL_INIT_LOAD_CRYPTO_STRINGS    0x00000002L
  ------------------
  |  Branch (658:9): [True: 4, False: 4]
  ------------------
  659|      8|            && !RUN_ONCE(&load_crypto_strings, ossl_init_load_crypto_strings))
  ------------------
  |  |  119|      4|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 4, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (659:16): [True: 0, False: 4]
  ------------------
  660|      0|        return 0;
  661|       |
  662|      8|    if ((opts & OPENSSL_INIT_NO_ADD_ALL_CIPHERS)
  ------------------
  |  |  360|      8|# define OPENSSL_INIT_NO_ADD_ALL_CIPHERS     0x00000010L
  ------------------
  |  Branch (662:9): [True: 0, False: 8]
  ------------------
  663|      8|            && !RUN_ONCE_ALT(&add_all_ciphers, ossl_init_no_add_all_ciphers,
  ------------------
  |  |  137|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (137:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (663:16): [True: 0, False: 0]
  ------------------
  664|      8|                             ossl_init_add_all_ciphers))
  665|      0|        return 0;
  666|       |
  667|      8|    if ((opts & OPENSSL_INIT_ADD_ALL_CIPHERS)
  ------------------
  |  |  358|      8|# define OPENSSL_INIT_ADD_ALL_CIPHERS        0x00000004L
  ------------------
  |  Branch (667:9): [True: 0, False: 8]
  ------------------
  668|      8|            && !RUN_ONCE(&add_all_ciphers, ossl_init_add_all_ciphers))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (668:16): [True: 0, False: 0]
  ------------------
  669|      0|        return 0;
  670|       |
  671|      8|    if ((opts & OPENSSL_INIT_NO_ADD_ALL_DIGESTS)
  ------------------
  |  |  361|      8|# define OPENSSL_INIT_NO_ADD_ALL_DIGESTS     0x00000020L
  ------------------
  |  Branch (671:9): [True: 0, False: 8]
  ------------------
  672|      8|            && !RUN_ONCE_ALT(&add_all_digests, ossl_init_no_add_all_digests,
  ------------------
  |  |  137|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (137:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (672:16): [True: 0, False: 0]
  ------------------
  673|      8|                             ossl_init_add_all_digests))
  674|      0|        return 0;
  675|       |
  676|      8|    if ((opts & OPENSSL_INIT_ADD_ALL_DIGESTS)
  ------------------
  |  |  359|      8|# define OPENSSL_INIT_ADD_ALL_DIGESTS        0x00000008L
  ------------------
  |  Branch (676:9): [True: 0, False: 8]
  ------------------
  677|      8|            && !RUN_ONCE(&add_all_digests, ossl_init_add_all_digests))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (677:16): [True: 0, False: 0]
  ------------------
  678|      0|        return 0;
  679|       |
  680|      8|    if ((opts & OPENSSL_INIT_ATFORK)
  ------------------
  |  |  373|      8|# define OPENSSL_INIT_ATFORK                 0x00020000L
  ------------------
  |  Branch (680:9): [True: 0, False: 8]
  ------------------
  681|      8|            && !openssl_init_fork_handlers())
  ------------------
  |  Branch (681:16): [True: 0, False: 0]
  ------------------
  682|      0|        return 0;
  683|       |
  684|      8|    if ((opts & OPENSSL_INIT_NO_LOAD_CONFIG)
  ------------------
  |  |  363|      8|# define OPENSSL_INIT_NO_LOAD_CONFIG         0x00000080L
  ------------------
  |  Branch (684:9): [True: 0, False: 8]
  ------------------
  685|      8|            && !RUN_ONCE_ALT(&config, ossl_init_no_config, ossl_init_config))
  ------------------
  |  |  137|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (137:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (685:16): [True: 0, False: 0]
  ------------------
  686|      0|        return 0;
  687|       |
  688|      8|    if (opts & OPENSSL_INIT_LOAD_CONFIG) {
  ------------------
  |  |  362|      8|# define OPENSSL_INIT_LOAD_CONFIG            0x00000040L
  ------------------
  |  Branch (688:9): [True: 0, False: 8]
  ------------------
  689|      0|        int ret;
  690|      0|        CRYPTO_THREAD_write_lock(init_lock);
  691|      0|        conf_settings = settings;
  692|      0|        ret = RUN_ONCE(&config, ossl_init_config);
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  693|      0|        conf_settings = NULL;
  694|      0|        CRYPTO_THREAD_unlock(init_lock);
  695|      0|        if (ret <= 0)
  ------------------
  |  Branch (695:13): [True: 0, False: 0]
  ------------------
  696|      0|            return 0;
  697|      0|    }
  698|       |
  699|      8|    if ((opts & OPENSSL_INIT_ASYNC)
  ------------------
  |  |  364|      8|# define OPENSSL_INIT_ASYNC                  0x00000100L
  ------------------
  |  Branch (699:9): [True: 0, False: 8]
  ------------------
  700|      8|            && !RUN_ONCE(&async, ossl_init_async))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (700:16): [True: 0, False: 0]
  ------------------
  701|      0|        return 0;
  702|       |
  703|      8|#ifndef OPENSSL_NO_ENGINE
  704|      8|    if ((opts & OPENSSL_INIT_ENGINE_OPENSSL)
  ------------------
  |  |  367|      8|# define OPENSSL_INIT_ENGINE_OPENSSL         0x00000800L
  ------------------
  |  Branch (704:9): [True: 0, False: 8]
  ------------------
  705|      8|            && !RUN_ONCE(&engine_openssl, ossl_init_engine_openssl))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (705:16): [True: 0, False: 0]
  ------------------
  706|      0|        return 0;
  707|       |# if !defined(OPENSSL_NO_HW) && !defined(OPENSSL_NO_DEVCRYPTOENG)
  708|       |    if ((opts & OPENSSL_INIT_ENGINE_CRYPTODEV)
  709|       |            && !RUN_ONCE(&engine_devcrypto, ossl_init_engine_devcrypto))
  710|       |        return 0;
  711|       |# endif
  712|      8|# ifndef OPENSSL_NO_RDRAND
  713|      8|    if ((opts & OPENSSL_INIT_ENGINE_RDRAND)
  ------------------
  |  |  365|      8|# define OPENSSL_INIT_ENGINE_RDRAND          0x00000200L
  ------------------
  |  Branch (713:9): [True: 0, False: 8]
  ------------------
  714|      8|            && !RUN_ONCE(&engine_rdrand, ossl_init_engine_rdrand))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (714:16): [True: 0, False: 0]
  ------------------
  715|      0|        return 0;
  716|      8|# endif
  717|      8|    if ((opts & OPENSSL_INIT_ENGINE_DYNAMIC)
  ------------------
  |  |  366|      8|# define OPENSSL_INIT_ENGINE_DYNAMIC         0x00000400L
  ------------------
  |  Branch (717:9): [True: 0, False: 8]
  ------------------
  718|      8|            && !RUN_ONCE(&engine_dynamic, ossl_init_engine_dynamic))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (718:16): [True: 0, False: 0]
  ------------------
  719|      0|        return 0;
  720|      8|# ifndef OPENSSL_NO_STATIC_ENGINE
  721|      8|#  if !defined(OPENSSL_NO_HW) && !defined(OPENSSL_NO_HW_PADLOCK)
  722|      8|    if ((opts & OPENSSL_INIT_ENGINE_PADLOCK)
  ------------------
  |  |  370|      8|# define OPENSSL_INIT_ENGINE_PADLOCK         0x00004000L
  ------------------
  |  Branch (722:9): [True: 0, False: 8]
  ------------------
  723|      8|            && !RUN_ONCE(&engine_padlock, ossl_init_engine_padlock))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (723:16): [True: 0, False: 0]
  ------------------
  724|      0|        return 0;
  725|      8|#  endif
  726|       |#  if defined(OPENSSL_SYS_WIN32) && !defined(OPENSSL_NO_CAPIENG)
  727|       |    if ((opts & OPENSSL_INIT_ENGINE_CAPI)
  728|       |            && !RUN_ONCE(&engine_capi, ossl_init_engine_capi))
  729|       |        return 0;
  730|       |#  endif
  731|      8|#  if !defined(OPENSSL_NO_AFALGENG)
  732|      8|    if ((opts & OPENSSL_INIT_ENGINE_AFALG)
  ------------------
  |  |  371|      8|# define OPENSSL_INIT_ENGINE_AFALG           0x00008000L
  ------------------
  |  Branch (732:9): [True: 0, False: 8]
  ------------------
  733|      8|            && !RUN_ONCE(&engine_afalg, ossl_init_engine_afalg))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (733:16): [True: 0, False: 0]
  ------------------
  734|      0|        return 0;
  735|      8|#  endif
  736|      8|# endif
  737|      8|    if (opts & (OPENSSL_INIT_ENGINE_ALL_BUILTIN
  ------------------
  |  |  381|      8|    (OPENSSL_INIT_ENGINE_RDRAND | OPENSSL_INIT_ENGINE_DYNAMIC \
  |  |  ------------------
  |  |  |  |  365|      8|# define OPENSSL_INIT_ENGINE_RDRAND          0x00000200L
  |  |  ------------------
  |  |                   (OPENSSL_INIT_ENGINE_RDRAND | OPENSSL_INIT_ENGINE_DYNAMIC \
  |  |  ------------------
  |  |  |  |  366|      8|# define OPENSSL_INIT_ENGINE_DYNAMIC         0x00000400L
  |  |  ------------------
  |  |  382|      8|    | OPENSSL_INIT_ENGINE_CRYPTODEV | OPENSSL_INIT_ENGINE_CAPI | \
  |  |  ------------------
  |  |  |  |  368|      8|# define OPENSSL_INIT_ENGINE_CRYPTODEV       0x00001000L
  |  |  ------------------
  |  |                   | OPENSSL_INIT_ENGINE_CRYPTODEV | OPENSSL_INIT_ENGINE_CAPI | \
  |  |  ------------------
  |  |  |  |  369|      8|# define OPENSSL_INIT_ENGINE_CAPI            0x00002000L
  |  |  ------------------
  |  |  383|      8|    OPENSSL_INIT_ENGINE_PADLOCK)
  |  |  ------------------
  |  |  |  |  370|      8|# define OPENSSL_INIT_ENGINE_PADLOCK         0x00004000L
  |  |  ------------------
  ------------------
  |  Branch (737:9): [True: 0, False: 8]
  ------------------
  738|      8|                | OPENSSL_INIT_ENGINE_OPENSSL
  ------------------
  |  |  367|      8|# define OPENSSL_INIT_ENGINE_OPENSSL         0x00000800L
  ------------------
  739|      8|                | OPENSSL_INIT_ENGINE_AFALG)) {
  ------------------
  |  |  371|      8|# define OPENSSL_INIT_ENGINE_AFALG           0x00008000L
  ------------------
  740|      0|        ENGINE_register_all_complete();
  741|      0|    }
  742|      8|#endif
  743|       |
  744|      8|#ifndef OPENSSL_NO_COMP
  745|      8|    if ((opts & OPENSSL_INIT_ZLIB)
  ------------------
  |  |   27|      8|# define OPENSSL_INIT_ZLIB                   0x00010000L
  ------------------
  |  Branch (745:9): [True: 0, False: 8]
  ------------------
  746|      8|            && !RUN_ONCE(&zlib, ossl_init_zlib))
  ------------------
  |  |  119|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (746:16): [True: 0, False: 0]
  ------------------
  747|      0|        return 0;
  748|      8|#endif
  749|       |
  750|      8|    return 1;
  751|      8|}
init.c:ossl_init_thread_stop:
  419|      2|{
  420|       |    /* Can't do much about this */
  421|      2|    if (locals == NULL)
  ------------------
  |  Branch (421:9): [True: 0, False: 2]
  ------------------
  422|      0|        return;
  423|       |
  424|      2|    if (locals->async) {
  ------------------
  |  Branch (424:9): [True: 0, False: 2]
  ------------------
  425|       |#ifdef OPENSSL_INIT_DEBUG
  426|       |        fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_stop: "
  427|       |                        "async_delete_thread_state()\n");
  428|       |#endif
  429|      0|        async_delete_thread_state();
  430|      0|    }
  431|       |
  432|      2|    if (locals->err_state) {
  ------------------
  |  Branch (432:9): [True: 2, False: 0]
  ------------------
  433|       |#ifdef OPENSSL_INIT_DEBUG
  434|       |        fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_stop: "
  435|       |                        "err_delete_thread_state()\n");
  436|       |#endif
  437|      2|        err_delete_thread_state();
  438|      2|    }
  439|       |
  440|      2|    if (locals->rand) {
  ------------------
  |  Branch (440:9): [True: 0, False: 2]
  ------------------
  441|       |#ifdef OPENSSL_INIT_DEBUG
  442|       |        fprintf(stderr, "OPENSSL_INIT: ossl_init_thread_stop: "
  443|       |                        "drbg_delete_thread_state()\n");
  444|       |#endif
  445|      0|        drbg_delete_thread_state();
  446|      0|    }
  447|       |
  448|      2|    OPENSSL_free(locals);
  ------------------
  |  |  128|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  449|      2|}
init.c:ossl_init_get_thread_local:
   60|      4|{
   61|      4|    struct thread_local_inits_st *local =
   62|      4|        CRYPTO_THREAD_get_local(&destructor_key.value);
   63|       |
   64|      4|    if (alloc) {
  ------------------
  |  Branch (64:9): [True: 2, False: 2]
  ------------------
   65|      2|        if (local == NULL
  ------------------
  |  Branch (65:13): [True: 2, False: 0]
  ------------------
   66|      2|            && (local = OPENSSL_zalloc(sizeof(*local))) != NULL
  ------------------
  |  |  120|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (66:16): [True: 2, False: 0]
  ------------------
   67|      2|            && !CRYPTO_THREAD_set_local(&destructor_key.value, local)) {
  ------------------
  |  Branch (67:16): [True: 0, False: 2]
  ------------------
   68|      0|            OPENSSL_free(local);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   69|      0|            return NULL;
   70|      0|        }
   71|      2|    } else {
   72|      2|        CRYPTO_THREAD_set_local(&destructor_key.value, NULL);
   73|      2|    }
   74|       |
   75|      4|    return local;
   76|      4|}
init.c:ossl_init_base:
   90|      2|{
   91|      2|    CRYPTO_THREAD_LOCAL key;
   92|       |
   93|       |#ifdef OPENSSL_INIT_DEBUG
   94|       |    fprintf(stderr, "OPENSSL_INIT: ossl_init_base: Setting up stop handlers\n");
   95|       |#endif
   96|       |#ifndef OPENSSL_NO_CRYPTO_MDEBUG
   97|       |    ossl_malloc_setup_failures();
   98|       |#endif
   99|      2|    if (!CRYPTO_THREAD_init_local(&key, ossl_init_thread_destructor))
  ------------------
  |  Branch (99:9): [True: 0, False: 2]
  ------------------
  100|      0|        return 0;
  101|      2|    if ((init_lock = CRYPTO_THREAD_lock_new()) == NULL)
  ------------------
  |  Branch (101:9): [True: 0, False: 2]
  ------------------
  102|      0|        goto err;
  103|      2|    OPENSSL_cpuid_setup();
  104|       |
  105|      2|    destructor_key.value = key;
  106|      2|    base_inited = 1;
  107|      2|    return 1;
  108|       |
  109|      0|err:
  110|       |#ifdef OPENSSL_INIT_DEBUG
  111|       |    fprintf(stderr, "OPENSSL_INIT: ossl_init_base not ok!\n");
  112|       |#endif
  113|      0|    CRYPTO_THREAD_lock_free(init_lock);
  114|      0|    init_lock = NULL;
  115|       |
  116|      0|    CRYPTO_THREAD_cleanup_local(&key);
  117|      0|    return 0;
  118|      2|}
init.c:ossl_init_register_atexit:
  130|      2|{
  131|       |#ifdef OPENSSL_INIT_DEBUG
  132|       |    fprintf(stderr, "OPENSSL_INIT: ossl_init_register_atexit()\n");
  133|       |#endif
  134|      2|#ifndef OPENSSL_SYS_UEFI
  135|       |# ifdef _WIN32
  136|       |    /* We use _onexit() in preference because it gets called on DLL unload */
  137|       |    if (_onexit(win32atexit) == NULL)
  138|       |        return 0;
  139|       |# else
  140|      2|    if (atexit(OPENSSL_cleanup) != 0)
  ------------------
  |  Branch (140:9): [True: 0, False: 2]
  ------------------
  141|      0|        return 0;
  142|      2|# endif
  143|      2|#endif
  144|       |
  145|      2|    return 1;
  146|      2|}
init.c:ossl_init_load_crypto_nodelete:
  160|      2|{
  161|       |#ifdef OPENSSL_INIT_DEBUG
  162|       |    fprintf(stderr, "OPENSSL_INIT: ossl_init_load_crypto_nodelete()\n");
  163|       |#endif
  164|       |#if !defined(OPENSSL_USE_NODELETE) \
  165|       |    && !defined(OPENSSL_NO_PINSHARED)
  166|       |# if defined(DSO_WIN32) && !defined(_WIN32_WCE)
  167|       |    {
  168|       |        HMODULE handle = NULL;
  169|       |        BOOL ret;
  170|       |
  171|       |        /* We don't use the DSO route for WIN32 because there is a better way */
  172|       |        ret = GetModuleHandleEx(GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS
  173|       |                                | GET_MODULE_HANDLE_EX_FLAG_PIN,
  174|       |                                (void *)&base_inited, &handle);
  175|       |
  176|       |#  ifdef OPENSSL_INIT_DEBUG
  177|       |        fprintf(stderr, "OPENSSL_INIT: obtained DSO reference? %s\n",
  178|       |                (ret == TRUE ? "No!" : "Yes."));
  179|       |#  endif
  180|       |        return (ret == TRUE) ? 1 : 0;
  181|       |    }
  182|       |# elif !defined(DSO_NONE)
  183|       |    /*
  184|       |     * Deliberately leak a reference to ourselves. This will force the library
  185|       |     * to remain loaded until the atexit() handler is run at process exit.
  186|       |     */
  187|       |    {
  188|       |        DSO *dso;
  189|       |        void *err;
  190|       |
  191|       |        if (!err_shelve_state(&err))
  192|       |            return 0;
  193|       |
  194|       |        dso = DSO_dsobyaddr(&base_inited, DSO_FLAG_NO_UNLOAD_ON_FREE);
  195|       |#  ifdef OPENSSL_INIT_DEBUG
  196|       |        fprintf(stderr, "OPENSSL_INIT: obtained DSO reference? %s\n",
  197|       |                (dso == NULL ? "No!" : "Yes."));
  198|       |        /*
  199|       |         * In case of No!, it is uncertain our exit()-handlers can still be
  200|       |         * called. After dlclose() the whole library might have been unloaded
  201|       |         * already.
  202|       |         */
  203|       |#  endif
  204|       |        DSO_free(dso);
  205|       |        err_unshelve_state(err);
  206|       |    }
  207|       |# endif
  208|       |#endif
  209|       |
  210|      2|    return 1;
  211|      2|}
init.c:ossl_init_load_crypto_strings:
  216|      2|{
  217|      2|    int ret = 1;
  218|       |    /*
  219|       |     * OPENSSL_NO_AUTOERRINIT is provided here to prevent at compile time
  220|       |     * pulling in all the error strings during static linking
  221|       |     */
  222|      2|#if !defined(OPENSSL_NO_ERR) && !defined(OPENSSL_NO_AUTOERRINIT)
  223|       |# ifdef OPENSSL_INIT_DEBUG
  224|       |    fprintf(stderr, "OPENSSL_INIT: ossl_init_load_crypto_strings: "
  225|       |                    "err_load_crypto_strings_int()\n");
  226|       |# endif
  227|      2|    ret = err_load_crypto_strings_int();
  228|      2|#endif
  229|      2|    return ret;
  230|      2|}

ERR_load_KDF_strings:
   59|      2|{
   60|      2|#ifndef OPENSSL_NO_ERR
   61|      2|    if (ERR_func_error_string(KDF_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (61:9): [True: 2, False: 0]
  ------------------
   62|      2|        ERR_load_strings_const(KDF_str_functs);
   63|      2|        ERR_load_strings_const(KDF_str_reasons);
   64|      2|    }
   65|      2|#endif
   66|      2|    return 1;
   67|      2|}

OPENSSL_LH_new:
   48|      2|{
   49|      2|    OPENSSL_LHASH *ret;
   50|       |
   51|      2|    if ((ret = OPENSSL_zalloc(sizeof(*ret))) == NULL) {
  ------------------
  |  |  120|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (51:9): [True: 0, False: 2]
  ------------------
   52|       |        /*
   53|       |         * Do not set the error code, because the ERR code uses LHASH
   54|       |         * and we want to avoid possible endless error loop.
   55|       |         * CRYPTOerr(CRYPTO_F_OPENSSL_LH_NEW, ERR_R_MALLOC_FAILURE);
   56|       |         */
   57|      0|        return NULL;
   58|      0|    }
   59|      2|    if ((ret->b = OPENSSL_zalloc(sizeof(*ret->b) * MIN_NODES)) == NULL)
  ------------------
  |  |  120|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (59:9): [True: 0, False: 2]
  ------------------
   60|      0|        goto err;
   61|      2|    ret->comp = ((c == NULL) ? (OPENSSL_LH_COMPFUNC)strcmp : c);
  ------------------
  |  Branch (61:18): [True: 0, False: 2]
  ------------------
   62|      2|    ret->hash = ((h == NULL) ? (OPENSSL_LH_HASHFUNC)OPENSSL_LH_strhash : h);
  ------------------
  |  Branch (62:18): [True: 0, False: 2]
  ------------------
   63|      2|    ret->num_nodes = MIN_NODES / 2;
  ------------------
  |  |   39|      2|#define MIN_NODES       16
  ------------------
   64|      2|    ret->num_alloc_nodes = MIN_NODES;
  ------------------
  |  |   39|      2|#define MIN_NODES       16
  ------------------
   65|      2|    ret->pmax = MIN_NODES / 2;
  ------------------
  |  |   39|      2|#define MIN_NODES       16
  ------------------
   66|      2|    ret->up_load = UP_LOAD;
  ------------------
  |  |   40|      2|#define UP_LOAD         (2*LH_LOAD_MULT) /* load times 256 (default 2) */
  |  |  ------------------
  |  |  |  |   70|      2|# define LH_LOAD_MULT    256
  |  |  ------------------
  ------------------
   67|      2|    ret->down_load = DOWN_LOAD;
  ------------------
  |  |   41|      2|#define DOWN_LOAD       (LH_LOAD_MULT) /* load times 256 (default 1) */
  |  |  ------------------
  |  |  |  |   70|      2|# define LH_LOAD_MULT    256
  |  |  ------------------
  ------------------
   68|      2|    return ret;
   69|       |
   70|      0|err:
   71|      0|    OPENSSL_free(ret->b);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   72|      0|    OPENSSL_free(ret);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   73|      0|    return NULL;
   74|      2|}
OPENSSL_LH_free:
   77|      4|{
   78|      4|    unsigned int i;
   79|      4|    OPENSSL_LH_NODE *n, *nn;
   80|       |
   81|      4|    if (lh == NULL)
  ------------------
  |  Branch (81:9): [True: 2, False: 2]
  ------------------
   82|      2|        return;
   83|       |
   84|  2.43k|    for (i = 0; i < lh->num_nodes; i++) {
  ------------------
  |  Branch (84:17): [True: 2.43k, False: 2]
  ------------------
   85|  2.43k|        n = lh->b[i];
   86|  7.30k|        while (n != NULL) {
  ------------------
  |  Branch (86:16): [True: 4.87k, False: 2.43k]
  ------------------
   87|  4.87k|            nn = n->next;
   88|  4.87k|            OPENSSL_free(n);
  ------------------
  |  |  128|  4.87k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  4.87k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  4.87k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   89|  4.87k|            n = nn;
   90|  4.87k|        }
   91|  2.43k|    }
   92|      2|    OPENSSL_free(lh->b);
  ------------------
  |  |  128|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   93|      2|    OPENSSL_free(lh);
  ------------------
  |  |  128|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   94|      2|}
OPENSSL_LH_insert:
   97|  15.1k|{
   98|  15.1k|    unsigned long hash;
   99|  15.1k|    OPENSSL_LH_NODE *nn, **rn;
  100|  15.1k|    void *ret;
  101|       |
  102|  15.1k|    lh->error = 0;
  103|  15.1k|    if ((lh->up_load <= (lh->num_items * LH_LOAD_MULT / lh->num_nodes)) && !expand(lh))
  ------------------
  |  |   70|  15.1k|# define LH_LOAD_MULT    256
  ------------------
  |  Branch (103:9): [True: 2.42k, False: 12.7k]
  |  Branch (103:76): [True: 0, False: 2.42k]
  ------------------
  104|      0|        return NULL;        /* 'lh->error++' already done in 'expand' */
  105|       |
  106|  15.1k|    rn = getrn(lh, data, &hash);
  107|       |
  108|  15.1k|    if (*rn == NULL) {
  ------------------
  |  Branch (108:9): [True: 4.87k, False: 10.3k]
  ------------------
  109|  4.87k|        if ((nn = OPENSSL_malloc(sizeof(*nn))) == NULL) {
  ------------------
  |  |  118|  4.87k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|  4.87k|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|  4.87k|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (109:13): [True: 0, False: 4.87k]
  ------------------
  110|      0|            lh->error++;
  111|      0|            return NULL;
  112|      0|        }
  113|  4.87k|        nn->data = data;
  114|  4.87k|        nn->next = NULL;
  115|  4.87k|        nn->hash = hash;
  116|  4.87k|        *rn = nn;
  117|  4.87k|        ret = NULL;
  118|  4.87k|        lh->num_insert++;
  119|  4.87k|        lh->num_items++;
  120|  10.3k|    } else {                    /* replace same key */
  121|  10.3k|        ret = (*rn)->data;
  122|  10.3k|        (*rn)->data = data;
  123|  10.3k|        lh->num_replace++;
  124|  10.3k|    }
  125|  15.1k|    return ret;
  126|  15.1k|}
OPENSSL_LH_retrieve:
  157|     58|{
  158|     58|    unsigned long hash;
  159|     58|    OPENSSL_LH_NODE **rn;
  160|     58|    void *ret;
  161|       |
  162|     58|    tsan_store((TSAN_QUALIFIER int *)&lh->error, 0);
  ------------------
  |  |   58|     58|#  define tsan_store(ptr, val) atomic_store_explicit((ptr), (val), memory_order_relaxed)
  ------------------
  163|       |
  164|     58|    rn = getrn(lh, data, &hash);
  165|       |
  166|     58|    if (*rn == NULL) {
  ------------------
  |  Branch (166:9): [True: 58, False: 0]
  ------------------
  167|     58|        tsan_counter(&lh->num_retrieve_miss);
  ------------------
  |  |   59|     58|#  define tsan_counter(ptr) atomic_fetch_add_explicit((ptr), 1, memory_order_relaxed)
  ------------------
  168|     58|        return NULL;
  169|     58|    } else {
  170|      0|        ret = (*rn)->data;
  171|      0|        tsan_counter(&lh->num_retrieve);
  ------------------
  |  |   59|      0|#  define tsan_counter(ptr) atomic_fetch_add_explicit((ptr), 1, memory_order_relaxed)
  ------------------
  172|      0|    }
  173|       |
  174|      0|    return ret;
  175|     58|}
OPENSSL_LH_num_items:
  378|      2|{
  379|      2|    return lh ? lh->num_items : 0;
  ------------------
  |  Branch (379:12): [True: 0, False: 2]
  ------------------
  380|      2|}
lhash.c:expand:
  215|  2.42k|{
  216|  2.42k|    OPENSSL_LH_NODE **n, **n1, **n2, *np;
  217|  2.42k|    unsigned int p, pmax, nni, j;
  218|  2.42k|    unsigned long hash;
  219|       |
  220|  2.42k|    nni = lh->num_alloc_nodes;
  221|  2.42k|    p = lh->p;
  222|  2.42k|    pmax = lh->pmax;
  223|  2.42k|    if (p + 1 >= pmax) {
  ------------------
  |  Branch (223:9): [True: 14, False: 2.40k]
  ------------------
  224|     14|        j = nni * 2;
  225|     14|        n = OPENSSL_realloc(lh->b, sizeof(OPENSSL_LH_NODE *) * j);
  ------------------
  |  |  122|     14|        CRYPTO_realloc(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|     14|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_realloc(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|     14|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  226|     14|        if (n == NULL) {
  ------------------
  |  Branch (226:13): [True: 0, False: 14]
  ------------------
  227|      0|            lh->error++;
  228|      0|            return 0;
  229|      0|        }
  230|     14|        lh->b = n;
  231|     14|        memset(n + nni, 0, sizeof(*n) * (j - nni));
  232|     14|        lh->pmax = nni;
  233|     14|        lh->num_alloc_nodes = j;
  234|     14|        lh->num_expand_reallocs++;
  235|     14|        lh->p = 0;
  236|  2.40k|    } else {
  237|  2.40k|        lh->p++;
  238|  2.40k|    }
  239|       |
  240|  2.42k|    lh->num_nodes++;
  241|  2.42k|    lh->num_expands++;
  242|  2.42k|    n1 = &(lh->b[p]);
  243|  2.42k|    n2 = &(lh->b[p + pmax]);
  244|  2.42k|    *n2 = NULL;
  245|       |
  246|  11.3k|    for (np = *n1; np != NULL;) {
  ------------------
  |  Branch (246:20): [True: 8.93k, False: 2.42k]
  ------------------
  247|  8.93k|        hash = np->hash;
  248|  8.93k|        if ((hash % nni) != p) { /* move it */
  ------------------
  |  Branch (248:13): [True: 704, False: 8.22k]
  ------------------
  249|    704|            *n1 = (*n1)->next;
  250|    704|            np->next = *n2;
  251|    704|            *n2 = np;
  252|    704|        } else
  253|  8.22k|            n1 = &((*n1)->next);
  254|  8.93k|        np = *n1;
  255|  8.93k|    }
  256|       |
  257|  2.42k|    return 1;
  258|  2.42k|}
lhash.c:getrn:
  297|  15.2k|{
  298|  15.2k|    OPENSSL_LH_NODE **ret, *n1;
  299|  15.2k|    unsigned long hash, nn;
  300|  15.2k|    OPENSSL_LH_COMPFUNC cf;
  301|       |
  302|  15.2k|    hash = (*(lh->hash)) (data);
  303|  15.2k|    tsan_counter(&lh->num_hash_calls);
  ------------------
  |  |   59|  15.2k|#  define tsan_counter(ptr) atomic_fetch_add_explicit((ptr), 1, memory_order_relaxed)
  ------------------
  304|  15.2k|    *rhash = hash;
  305|       |
  306|  15.2k|    nn = hash % lh->pmax;
  307|  15.2k|    if (nn < lh->p)
  ------------------
  |  Branch (307:9): [True: 8.94k, False: 6.30k]
  ------------------
  308|  8.94k|        nn = hash % lh->num_alloc_nodes;
  309|       |
  310|  15.2k|    cf = lh->comp;
  311|  15.2k|    ret = &(lh->b[(int)nn]);
  312|  44.6k|    for (n1 = *ret; n1 != NULL; n1 = n1->next) {
  ------------------
  |  Branch (312:21): [True: 39.6k, False: 4.92k]
  ------------------
  313|  39.6k|        tsan_counter(&lh->num_hash_comps);
  ------------------
  |  |   59|  39.6k|#  define tsan_counter(ptr) atomic_fetch_add_explicit((ptr), 1, memory_order_relaxed)
  ------------------
  314|  39.6k|        if (n1->hash != hash) {
  ------------------
  |  Branch (314:13): [True: 29.1k, False: 10.5k]
  ------------------
  315|  29.1k|            ret = &(n1->next);
  316|  29.1k|            continue;
  317|  29.1k|        }
  318|  39.6k|        tsan_counter(&lh->num_comp_calls);
  ------------------
  |  |   59|  39.6k|#  define tsan_counter(ptr) atomic_fetch_add_explicit((ptr), 1, memory_order_relaxed)
  ------------------
  319|  10.5k|        if (cf(n1->data, data) == 0)
  ------------------
  |  Branch (319:13): [True: 10.3k, False: 246]
  ------------------
  320|  10.3k|            break;
  321|    246|        ret = &(n1->next);
  322|    246|    }
  323|  15.2k|    return ret;
  324|  15.2k|}

CRYPTO_malloc:
  193|   144k|{
  194|   144k|    void *ret = NULL;
  195|       |
  196|   144k|    INCREMENT(malloc_count);
  197|   144k|    if (malloc_impl != NULL && malloc_impl != CRYPTO_malloc)
  ------------------
  |  Branch (197:9): [True: 144k, False: 0]
  |  Branch (197:32): [True: 0, False: 144k]
  ------------------
  198|      0|        return malloc_impl(num, file, line);
  199|       |
  200|   144k|    if (num == 0)
  ------------------
  |  Branch (200:9): [True: 0, False: 144k]
  ------------------
  201|      0|        return NULL;
  202|       |
  203|   144k|    FAILTEST();
  204|   144k|    if (allow_customize) {
  ------------------
  |  Branch (204:9): [True: 2, False: 144k]
  ------------------
  205|       |        /*
  206|       |         * Disallow customization after the first allocation. We only set this
  207|       |         * if necessary to avoid a store to the same cache line on every
  208|       |         * allocation.
  209|       |         */
  210|      2|        allow_customize = 0;
  211|      2|    }
  212|       |#ifndef OPENSSL_NO_CRYPTO_MDEBUG
  213|       |    if (call_malloc_debug) {
  214|       |        CRYPTO_mem_debug_malloc(NULL, num, 0, file, line);
  215|       |        ret = malloc(num);
  216|       |        CRYPTO_mem_debug_malloc(ret, num, 1, file, line);
  217|       |    } else {
  218|       |        ret = malloc(num);
  219|       |    }
  220|       |#else
  221|   144k|    (void)(file); (void)(line);
  222|   144k|    ret = malloc(num);
  223|   144k|#endif
  224|       |
  225|   144k|    return ret;
  226|   144k|}
CRYPTO_zalloc:
  229|   131k|{
  230|   131k|    void *ret = CRYPTO_malloc(num, file, line);
  231|       |
  232|   131k|    FAILTEST();
  233|   131k|    if (ret != NULL)
  ------------------
  |  Branch (233:9): [True: 131k, False: 0]
  ------------------
  234|   131k|        memset(ret, 0, num);
  235|   131k|    return ret;
  236|   131k|}
CRYPTO_realloc:
  239|     14|{
  240|     14|    INCREMENT(realloc_count);
  241|     14|    if (realloc_impl != NULL && realloc_impl != &CRYPTO_realloc)
  ------------------
  |  Branch (241:9): [True: 14, False: 0]
  |  Branch (241:33): [True: 0, False: 14]
  ------------------
  242|      0|        return realloc_impl(str, num, file, line);
  243|       |
  244|     14|    FAILTEST();
  245|     14|    if (str == NULL)
  ------------------
  |  Branch (245:9): [True: 0, False: 14]
  ------------------
  246|      0|        return CRYPTO_malloc(num, file, line);
  247|       |
  248|     14|    if (num == 0) {
  ------------------
  |  Branch (248:9): [True: 0, False: 14]
  ------------------
  249|      0|        CRYPTO_free(str, file, line);
  250|      0|        return NULL;
  251|      0|    }
  252|       |
  253|       |#ifndef OPENSSL_NO_CRYPTO_MDEBUG
  254|       |    if (call_malloc_debug) {
  255|       |        void *ret;
  256|       |        CRYPTO_mem_debug_realloc(str, NULL, num, 0, file, line);
  257|       |        ret = realloc(str, num);
  258|       |        CRYPTO_mem_debug_realloc(str, ret, num, 1, file, line);
  259|       |        return ret;
  260|       |    }
  261|       |#else
  262|     14|    (void)(file); (void)(line);
  263|     14|#endif
  264|     14|    return realloc(str, num);
  265|       |
  266|     14|}
CRYPTO_free:
  296|   148k|{
  297|   148k|    INCREMENT(free_count);
  298|   148k|    if (free_impl != NULL && free_impl != &CRYPTO_free) {
  ------------------
  |  Branch (298:9): [True: 148k, False: 0]
  |  Branch (298:30): [True: 0, False: 148k]
  ------------------
  299|      0|        free_impl(str, file, line);
  300|      0|        return;
  301|      0|    }
  302|       |
  303|       |#ifndef OPENSSL_NO_CRYPTO_MDEBUG
  304|       |    if (call_malloc_debug) {
  305|       |        CRYPTO_mem_debug_free(str, 0, file, line);
  306|       |        free(str);
  307|       |        CRYPTO_mem_debug_free(str, 1, file, line);
  308|       |    } else {
  309|       |        free(str);
  310|       |    }
  311|       |#else
  312|   148k|    free(str);
  313|   148k|#endif
  314|   148k|}
CRYPTO_clear_free:
  317|  94.2k|{
  318|  94.2k|    if (str == NULL)
  ------------------
  |  Branch (318:9): [True: 0, False: 94.2k]
  ------------------
  319|      0|        return;
  320|  94.2k|    if (num)
  ------------------
  |  Branch (320:9): [True: 94.2k, False: 0]
  ------------------
  321|  94.2k|        OPENSSL_cleanse(str, num);
  322|  94.2k|    CRYPTO_free(str, file, line);
  323|  94.2k|}

CRYPTO_secure_malloc_done:
   98|      2|{
   99|      2|#ifdef OPENSSL_SECURE_MEMORY
  100|      2|    if (secure_mem_used == 0) {
  ------------------
  |  Branch (100:9): [True: 2, False: 0]
  ------------------
  101|      2|        sh_done();
  102|      2|        secure_mem_initialized = 0;
  103|      2|        CRYPTO_THREAD_lock_free(sec_malloc_lock);
  104|      2|        sec_malloc_lock = NULL;
  105|      2|        return 1;
  106|      2|    }
  107|      0|#endif /* OPENSSL_SECURE_MEMORY */
  108|      0|    return 0;
  109|      2|}
mem_sec.c:sh_done:
  507|      2|{
  508|      2|    OPENSSL_free(sh.freelist);
  ------------------
  |  |  128|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  509|      2|    OPENSSL_free(sh.bittable);
  ------------------
  |  |  128|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  510|      2|    OPENSSL_free(sh.bitmalloc);
  ------------------
  |  |  128|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      2|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      2|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  511|      2|    if (sh.map_result != MAP_FAILED && sh.map_size)
  ------------------
  |  Branch (511:9): [True: 2, False: 0]
  |  Branch (511:40): [True: 0, False: 2]
  ------------------
  512|      0|        munmap(sh.map_result, sh.map_size);
  513|      2|    memset(&sh, 0, sizeof(sh));
  514|      2|}

openssl_strerror_r:
  222|    254|{
  223|       |#if defined(_MSC_VER) && _MSC_VER>=1400 && !defined(_WIN32_WCE)
  224|       |    return !strerror_s(buf, buflen, errnum);
  225|       |#elif defined(_GNU_SOURCE)
  226|       |    char *err;
  227|       |
  228|       |    /*
  229|       |     * GNU strerror_r may not actually set buf.
  230|       |     * It can return a pointer to some (immutable) static string in which case
  231|       |     * buf is left unused.
  232|       |     */
  233|       |    err = strerror_r(errnum, buf, buflen);
  234|       |    if (err == NULL || buflen == 0)
  235|       |        return 0;
  236|       |    /*
  237|       |     * If err is statically allocated, err != buf and we need to copy the data.
  238|       |     * If err points somewhere inside buf, OPENSSL_strlcpy can handle this,
  239|       |     * since src and dest are not annotated with __restrict and the function
  240|       |     * reads src byte for byte and writes to dest.
  241|       |     * If err == buf we do not have to copy anything.
  242|       |     */
  243|       |    if (err != buf)
  244|       |        OPENSSL_strlcpy(buf, err, buflen);
  245|       |    return 1;
  246|       |#elif (defined(_POSIX_C_SOURCE) && _POSIX_C_SOURCE >= 200112L) || \
  247|       |      (defined(_XOPEN_SOURCE) && _XOPEN_SOURCE >= 600)
  248|       |    /*
  249|       |     * We can use "real" strerror_r. The OpenSSL version differs in that it
  250|       |     * gives 1 on success and 0 on failure for consistency with other OpenSSL
  251|       |     * functions. Real strerror_r does it the other way around
  252|       |     */
  253|    254|    return !strerror_r(errnum, buf, buflen);
  254|       |#else
  255|       |    char *err;
  256|       |
  257|       |    /* Fall back to non-thread safe strerror()...its all we can do */
  258|       |    if (buflen < 2)
  259|       |        return 0;
  260|       |    err = strerror(errnum);
  261|       |    /* Can this ever happen? */
  262|       |    if (err == NULL)
  263|       |        return 0;
  264|       |    OPENSSL_strlcpy(buf, err, buflen);
  265|       |    return 1;
  266|       |#endif
  267|    254|}

OBJ_NAME_cleanup:
  390|      6|{
  391|      6|    unsigned long down_load;
  392|       |
  393|      6|    if (names_lh == NULL)
  ------------------
  |  Branch (393:9): [True: 6, False: 0]
  ------------------
  394|      6|        return;
  395|       |
  396|      0|    free_type = type;
  397|      0|    down_load = lh_OBJ_NAME_get_down_load(names_lh);
  398|      0|    lh_OBJ_NAME_set_down_load(names_lh, 0);
  399|       |
  400|      0|    lh_OBJ_NAME_doall(names_lh, names_lh_free_doall);
  401|      0|    if (type < 0) {
  ------------------
  |  Branch (401:9): [True: 0, False: 0]
  ------------------
  402|      0|        lh_OBJ_NAME_free(names_lh);
  403|      0|        sk_NAME_FUNCS_pop_free(name_funcs_stack, name_funcs_free);
  404|      0|        CRYPTO_THREAD_lock_free(obj_lock);
  405|      0|        names_lh = NULL;
  406|      0|        name_funcs_stack = NULL;
  407|      0|        obj_lock = NULL;
  408|      0|    } else
  409|      0|        lh_OBJ_NAME_set_down_load(names_lh, down_load);
  410|      0|}

obj_cleanup_int:
  154|      2|{
  155|      2|    if (added == NULL)
  ------------------
  |  Branch (155:9): [True: 2, False: 0]
  ------------------
  156|      2|        return;
  157|      0|    lh_ADDED_OBJ_set_down_load(added, 0);
  158|      0|    lh_ADDED_OBJ_doall(added, cleanup1_doall); /* zero counters */
  159|      0|    lh_ADDED_OBJ_doall(added, cleanup2_doall); /* set counters */
  160|      0|    lh_ADDED_OBJ_doall(added, cleanup3_doall); /* free objects */
  161|      0|    lh_ADDED_OBJ_free(added);
  162|      0|    added = NULL;
  163|      0|}

ERR_load_OBJ_strings:
   38|      2|{
   39|      2|#ifndef OPENSSL_NO_ERR
   40|      2|    if (ERR_func_error_string(OBJ_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (40:9): [True: 2, False: 0]
  ------------------
   41|      2|        ERR_load_strings_const(OBJ_str_functs);
   42|      2|        ERR_load_strings_const(OBJ_str_reasons);
   43|      2|    }
   44|      2|#endif
   45|      2|    return 1;
   46|      2|}

OBJ_sigid_free:
  134|      2|{
  135|      2|    sk_nid_triple_pop_free(sig_app, sid_free);
  136|      2|    sig_app = NULL;
  137|      2|    sk_nid_triple_free(sigx_app);
  138|      2|    sigx_app = NULL;
  139|      2|}

ERR_load_OCSP_strings:
   93|      2|{
   94|      2|#ifndef OPENSSL_NO_ERR
   95|      2|    if (ERR_func_error_string(OCSP_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (95:9): [True: 2, False: 0]
  ------------------
   96|      2|        ERR_load_strings_const(OCSP_str_functs);
   97|      2|        ERR_load_strings_const(OCSP_str_reasons);
   98|      2|    }
   99|      2|#endif
  100|      2|    return 1;
  101|      2|}

ERR_load_PEM_strings:
  122|      2|{
  123|      2|#ifndef OPENSSL_NO_ERR
  124|      2|    if (ERR_func_error_string(PEM_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (124:9): [True: 2, False: 0]
  ------------------
  125|      2|        ERR_load_strings_const(PEM_str_functs);
  126|      2|        ERR_load_strings_const(PEM_str_reasons);
  127|      2|    }
  128|      2|#endif
  129|      2|    return 1;
  130|      2|}

ERR_load_PKCS12_strings:
  109|      2|{
  110|      2|#ifndef OPENSSL_NO_ERR
  111|      2|    if (ERR_func_error_string(PKCS12_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (111:9): [True: 2, False: 0]
  ------------------
  112|      2|        ERR_load_strings_const(PKCS12_str_functs);
  113|      2|        ERR_load_strings_const(PKCS12_str_reasons);
  114|      2|    }
  115|      2|#endif
  116|      2|    return 1;
  117|      2|}

ERR_load_PKCS7_strings:
  148|      2|{
  149|      2|#ifndef OPENSSL_NO_ERR
  150|      2|    if (ERR_func_error_string(PKCS7_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (150:9): [True: 2, False: 0]
  ------------------
  151|      2|        ERR_load_strings_const(PKCS7_str_functs);
  152|      2|        ERR_load_strings_const(PKCS7_str_reasons);
  153|      2|    }
  154|      2|#endif
  155|      2|    return 1;
  156|      2|}

rand_drbg_cleanup_int:
  925|      2|{
  926|      2|    if (master_drbg != NULL) {
  ------------------
  |  Branch (926:9): [True: 0, False: 2]
  ------------------
  927|      0|        RAND_DRBG_free(master_drbg);
  928|      0|        master_drbg = NULL;
  929|       |
  930|      0|        CRYPTO_THREAD_cleanup_local(&private_drbg);
  931|      0|        CRYPTO_THREAD_cleanup_local(&public_drbg);
  932|      0|    }
  933|      2|}

ERR_load_RAND_strings:
  131|      2|{
  132|      2|#ifndef OPENSSL_NO_ERR
  133|      2|    if (ERR_func_error_string(RAND_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (133:9): [True: 2, False: 0]
  ------------------
  134|      2|        ERR_load_strings_const(RAND_str_functs);
  135|      2|        ERR_load_strings_const(RAND_str_reasons);
  136|      2|    }
  137|      2|#endif
  138|      2|    return 1;
  139|      2|}

rand_cleanup_int:
  345|      2|{
  346|      2|    const RAND_METHOD *meth = default_RAND_meth;
  347|       |
  348|      2|    if (!rand_inited)
  ------------------
  |  Branch (348:9): [True: 2, False: 0]
  ------------------
  349|      2|        return;
  350|       |
  351|      0|    if (meth != NULL && meth->cleanup != NULL)
  ------------------
  |  Branch (351:9): [True: 0, False: 0]
  |  Branch (351:25): [True: 0, False: 0]
  ------------------
  352|      0|        meth->cleanup();
  353|      0|    RAND_set_rand_method(NULL);
  354|      0|    rand_pool_cleanup();
  355|      0|#ifndef OPENSSL_NO_ENGINE
  356|      0|    CRYPTO_THREAD_lock_free(rand_engine_lock);
  357|      0|    rand_engine_lock = NULL;
  358|      0|#endif
  359|      0|    CRYPTO_THREAD_lock_free(rand_meth_lock);
  360|      0|    rand_meth_lock = NULL;
  361|      0|    CRYPTO_THREAD_lock_free(rand_nonce_lock);
  362|      0|    rand_nonce_lock = NULL;
  363|      0|    rand_inited = 0;
  364|      0|}

ERR_load_RSA_strings:
  240|      2|{
  241|      2|#ifndef OPENSSL_NO_ERR
  242|      2|    if (ERR_func_error_string(RSA_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (242:9): [True: 2, False: 0]
  ------------------
  243|      2|        ERR_load_strings_const(RSA_str_functs);
  244|      2|        ERR_load_strings_const(RSA_str_reasons);
  245|      2|    }
  246|      2|#endif
  247|      2|    return 1;
  248|      2|}

OPENSSL_sk_pop_free:
  361|     36|{
  362|     36|    int i;
  363|       |
  364|     36|    if (st == NULL)
  ------------------
  |  Branch (364:9): [True: 36, False: 0]
  ------------------
  365|     36|        return;
  366|      0|    for (i = 0; i < st->num; i++)
  ------------------
  |  Branch (366:17): [True: 0, False: 0]
  ------------------
  367|      0|        if (st->data[i] != NULL)
  ------------------
  |  Branch (367:13): [True: 0, False: 0]
  ------------------
  368|      0|            func((char *)st->data[i]);
  369|      0|    OPENSSL_sk_free(st);
  370|      0|}
OPENSSL_sk_free:
  373|      6|{
  374|      6|    if (st == NULL)
  ------------------
  |  Branch (374:9): [True: 6, False: 0]
  ------------------
  375|      6|        return;
  376|      0|    OPENSSL_free(st->data);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  377|      0|    OPENSSL_free(st);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  378|      0|}
OPENSSL_sk_num:
  381|      8|{
  382|      8|    return st == NULL ? -1 : st->num;
  ------------------
  |  Branch (382:12): [True: 8, False: 0]
  ------------------
  383|      8|}

ERR_load_OSSL_STORE_strings:
  138|      2|{
  139|      2|#ifndef OPENSSL_NO_ERR
  140|      2|    if (ERR_func_error_string(OSSL_STORE_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (140:9): [True: 2, False: 0]
  ------------------
  141|      2|        ERR_load_strings_const(OSSL_STORE_str_functs);
  142|      2|        ERR_load_strings_const(OSSL_STORE_str_reasons);
  143|      2|    }
  144|      2|#endif
  145|      2|    return 1;
  146|      2|}

ossl_store_cleanup_int:
   31|      2|{
   32|      2|    ossl_store_destroy_loaders_int();
   33|      2|}

ossl_store_destroy_loaders_int:
  278|      2|{
  279|      2|    assert(lh_OSSL_STORE_LOADER_num_items(loader_register) == 0);
  280|      2|    lh_OSSL_STORE_LOADER_free(loader_register);
  281|      2|    loader_register = NULL;
  282|      2|    CRYPTO_THREAD_lock_free(registry_lock);
  283|      2|    registry_lock = NULL;
  284|      2|}

CRYPTO_THREAD_lock_new:
   25|      4|{
   26|      4|# ifdef USE_RWLOCK
   27|      4|    CRYPTO_RWLOCK *lock;
   28|       |
   29|      4|    if ((lock = OPENSSL_zalloc(sizeof(pthread_rwlock_t))) == NULL) {
  ------------------
  |  |  120|      4|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      4|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      4|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (29:9): [True: 0, False: 4]
  ------------------
   30|       |        /* Don't set error, to avoid recursion blowup. */
   31|      0|        return NULL;
   32|      0|    }
   33|       |
   34|      4|    if (pthread_rwlock_init(lock, NULL) != 0) {
  ------------------
  |  Branch (34:9): [True: 0, False: 4]
  ------------------
   35|      0|        OPENSSL_free(lock);
  ------------------
  |  |  128|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   36|      0|        return NULL;
   37|      0|    }
   38|       |# else
   39|       |    pthread_mutexattr_t attr;
   40|       |    CRYPTO_RWLOCK *lock;
   41|       |
   42|       |    if ((lock = OPENSSL_zalloc(sizeof(pthread_mutex_t))) == NULL) {
   43|       |        /* Don't set error, to avoid recursion blowup. */
   44|       |        return NULL;
   45|       |    }
   46|       |
   47|       |    pthread_mutexattr_init(&attr);
   48|       |    pthread_mutexattr_settype(&attr, PTHREAD_MUTEX_RECURSIVE);
   49|       |
   50|       |    if (pthread_mutex_init(lock, &attr) != 0) {
   51|       |        pthread_mutexattr_destroy(&attr);
   52|       |        OPENSSL_free(lock);
   53|       |        return NULL;
   54|       |    }
   55|       |
   56|       |    pthread_mutexattr_destroy(&attr);
   57|       |# endif
   58|       |
   59|      4|    return lock;
   60|      4|}
CRYPTO_THREAD_read_lock:
   63|     58|{
   64|     58|# ifdef USE_RWLOCK
   65|     58|    if (pthread_rwlock_rdlock(lock) != 0)
  ------------------
  |  Branch (65:9): [True: 0, False: 58]
  ------------------
   66|      0|        return 0;
   67|       |# else
   68|       |    if (pthread_mutex_lock(lock) != 0)
   69|       |        return 0;
   70|       |# endif
   71|       |
   72|     58|    return 1;
   73|     58|}
CRYPTO_THREAD_write_lock:
   76|    590|{
   77|    590|# ifdef USE_RWLOCK
   78|    590|    if (pthread_rwlock_wrlock(lock) != 0)
  ------------------
  |  Branch (78:9): [True: 0, False: 590]
  ------------------
   79|      0|        return 0;
   80|       |# else
   81|       |    if (pthread_mutex_lock(lock) != 0)
   82|       |        return 0;
   83|       |# endif
   84|       |
   85|    590|    return 1;
   86|    590|}
CRYPTO_THREAD_unlock:
   89|    648|{
   90|    648|# ifdef USE_RWLOCK
   91|    648|    if (pthread_rwlock_unlock(lock) != 0)
  ------------------
  |  Branch (91:9): [True: 0, False: 648]
  ------------------
   92|      0|        return 0;
   93|       |# else
   94|       |    if (pthread_mutex_unlock(lock) != 0)
   95|       |        return 0;
   96|       |# endif
   97|       |
   98|    648|    return 1;
   99|    648|}
CRYPTO_THREAD_lock_free:
  102|     16|{
  103|     16|    if (lock == NULL)
  ------------------
  |  Branch (103:9): [True: 12, False: 4]
  ------------------
  104|     12|        return;
  105|       |
  106|      4|# ifdef USE_RWLOCK
  107|      4|    pthread_rwlock_destroy(lock);
  108|       |# else
  109|       |    pthread_mutex_destroy(lock);
  110|       |# endif
  111|      4|    OPENSSL_free(lock);
  ------------------
  |  |  128|      4|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  109|      4|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  110|      4|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  112|       |
  113|      4|    return;
  114|     16|}
CRYPTO_THREAD_run_once:
  117|  6.70k|{
  118|  6.70k|    if (pthread_once(once, init) != 0)
  ------------------
  |  Branch (118:9): [True: 0, False: 6.70k]
  ------------------
  119|      0|        return 0;
  120|       |
  121|  6.70k|    return 1;
  122|  6.70k|}
CRYPTO_THREAD_init_local:
  125|      4|{
  126|      4|    if (pthread_key_create(key, cleanup) != 0)
  ------------------
  |  Branch (126:9): [True: 0, False: 4]
  ------------------
  127|      0|        return 0;
  128|       |
  129|      4|    return 1;
  130|      4|}
CRYPTO_THREAD_get_local:
  133|  3.25k|{
  134|  3.25k|    return pthread_getspecific(*key);
  135|  3.25k|}
CRYPTO_THREAD_set_local:
  138|     10|{
  139|     10|    if (pthread_setspecific(*key, val) != 0)
  ------------------
  |  Branch (139:9): [True: 0, False: 10]
  ------------------
  140|      0|        return 0;
  141|       |
  142|     10|    return 1;
  143|     10|}
CRYPTO_THREAD_cleanup_local:
  146|      4|{
  147|      4|    if (pthread_key_delete(*key) != 0)
  ------------------
  |  Branch (147:9): [True: 0, False: 4]
  ------------------
  148|      0|        return 0;
  149|       |
  150|      4|    return 1;
  151|      4|}

ERR_load_TS_strings:
  176|      2|{
  177|      2|#ifndef OPENSSL_NO_ERR
  178|      2|    if (ERR_func_error_string(TS_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (178:9): [True: 2, False: 0]
  ------------------
  179|      2|        ERR_load_strings_const(TS_str_functs);
  180|      2|        ERR_load_strings_const(TS_str_reasons);
  181|      2|    }
  182|      2|#endif
  183|      2|    return 1;
  184|      2|}

ERR_load_UI_strings:
   70|      2|{
   71|      2|#ifndef OPENSSL_NO_ERR
   72|      2|    if (ERR_func_error_string(UI_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (72:9): [True: 2, False: 0]
  ------------------
   73|      2|        ERR_load_strings_const(UI_str_functs);
   74|      2|        ERR_load_strings_const(UI_str_reasons);
   75|      2|    }
   76|      2|#endif
   77|      2|    return 1;
   78|      2|}

ERR_load_X509_strings:
  176|      2|{
  177|      2|#ifndef OPENSSL_NO_ERR
  178|      2|    if (ERR_func_error_string(X509_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (178:9): [True: 2, False: 0]
  ------------------
  179|      2|        ERR_load_strings_const(X509_str_functs);
  180|      2|        ERR_load_strings_const(X509_str_reasons);
  181|      2|    }
  182|      2|#endif
  183|      2|    return 1;
  184|      2|}

ERR_load_X509V3_strings:
  253|      2|{
  254|      2|#ifndef OPENSSL_NO_ERR
  255|      2|    if (ERR_func_error_string(X509V3_str_functs[0].error) == NULL) {
  ------------------
  |  Branch (255:9): [True: 2, False: 0]
  ------------------
  256|      2|        ERR_load_strings_const(X509V3_str_functs);
  257|      2|        ERR_load_strings_const(X509V3_str_reasons);
  258|      2|    }
  259|      2|#endif
  260|      2|    return 1;
  261|      2|}

FuzzerInitialize:
   23|      2|{
   24|      2|    OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL);
  ------------------
  |  |  357|      2|# define OPENSSL_INIT_LOAD_CRYPTO_STRINGS    0x00000002L
  ------------------
   25|      2|    ERR_get_state();
   26|       |
   27|      2|    return 1;
   28|      2|}
FuzzerTestOneInput:
   31|  3.24k|{
   32|  3.24k|    int success = 0;
   33|  3.24k|    size_t l1 = 0, l2 = 0, l3 = 0;
   34|  3.24k|    int s1 = 0, s3 = 0;
   35|  3.24k|    BN_CTX *ctx;
   36|  3.24k|    BIGNUM *b1;
   37|  3.24k|    BIGNUM *b2;
   38|  3.24k|    BIGNUM *b3;
   39|  3.24k|    BIGNUM *b4;
   40|  3.24k|    BIGNUM *b5;
   41|       |
   42|  3.24k|    b1 = BN_new();
   43|  3.24k|    b2 = BN_new();
   44|  3.24k|    b3 = BN_new();
   45|  3.24k|    b4 = BN_new();
   46|  3.24k|    b5 = BN_new();
   47|  3.24k|    ctx = BN_CTX_new();
   48|       |
   49|       |    /* Divide the input into three parts, using the values of the first two
   50|       |     * bytes to choose lengths, which generate b1, b2 and b3. Use three bits
   51|       |     * of the third byte to choose signs for the three numbers.
   52|       |     */
   53|  3.24k|    if (len > 2) {
  ------------------
  |  Branch (53:9): [True: 3.24k, False: 2]
  ------------------
   54|  3.24k|        len -= 3;
   55|  3.24k|        l1 = (buf[0] * len) / 255;
   56|  3.24k|        ++buf;
   57|  3.24k|        l2 = (buf[0] * (len - l1)) / 255;
   58|  3.24k|        ++buf;
   59|  3.24k|        l3 = len - l1 - l2;
   60|       |
   61|  3.24k|        s1 = buf[0] & 1;
   62|  3.24k|        s3 = buf[0] & 4;
   63|  3.24k|        ++buf;
   64|  3.24k|    }
   65|  3.24k|    OPENSSL_assert(BN_bin2bn(buf, l1, b1) == b1);
  ------------------
  |  |  327|  3.24k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (327:12): [True: 3.24k, False: 0]
  |  |  ------------------
  ------------------
   66|  3.24k|    BN_set_negative(b1, s1);
   67|  3.24k|    OPENSSL_assert(BN_bin2bn(buf + l1, l2, b2) == b2);
  ------------------
  |  |  327|  3.24k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (327:12): [True: 3.24k, False: 0]
  |  |  ------------------
  ------------------
   68|  3.24k|    OPENSSL_assert(BN_bin2bn(buf + l1 + l2, l3, b3) == b3);
  ------------------
  |  |  327|  3.24k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (327:12): [True: 3.24k, False: 0]
  |  |  ------------------
  ------------------
   69|  3.24k|    BN_set_negative(b3, s3);
   70|       |
   71|       |    /* mod 0 is undefined */
   72|  3.24k|    if (BN_is_zero(b3)) {
  ------------------
  |  Branch (72:9): [True: 52, False: 3.19k]
  ------------------
   73|     52|        success = 1;
   74|     52|        goto done;
   75|     52|    }
   76|       |
   77|  3.19k|    OPENSSL_assert(BN_mod_exp(b4, b1, b2, b3, ctx));
  ------------------
  |  |  327|  3.19k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (327:12): [True: 3.19k, False: 0]
  |  |  ------------------
  ------------------
   78|  3.19k|    OPENSSL_assert(BN_mod_exp_simple(b5, b1, b2, b3, ctx));
  ------------------
  |  |  327|  3.19k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (327:12): [True: 3.19k, False: 0]
  |  |  ------------------
  ------------------
   79|       |
   80|  3.19k|    success = BN_cmp(b4, b5) == 0;
   81|  3.19k|    if (!success) {
  ------------------
  |  Branch (81:9): [True: 0, False: 3.19k]
  ------------------
   82|      0|        BN_print_fp(stdout, b1);
   83|      0|        putchar('\n');
   84|      0|        BN_print_fp(stdout, b2);
   85|      0|        putchar('\n');
   86|      0|        BN_print_fp(stdout, b3);
   87|      0|        putchar('\n');
   88|      0|        BN_print_fp(stdout, b4);
   89|      0|        putchar('\n');
   90|      0|        BN_print_fp(stdout, b5);
   91|      0|        putchar('\n');
   92|      0|    }
   93|       |
   94|  3.24k| done:
   95|  3.24k|    OPENSSL_assert(success);
  ------------------
  |  |  327|  3.24k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  109|      0|#  define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  110|      0|#  define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (327:12): [True: 3.24k, False: 0]
  |  |  ------------------
  ------------------
   96|  3.24k|    BN_free(b1);
   97|  3.24k|    BN_free(b2);
   98|  3.24k|    BN_free(b3);
   99|  3.24k|    BN_free(b4);
  100|  3.24k|    BN_free(b5);
  101|  3.24k|    BN_CTX_free(ctx);
  102|  3.24k|    ERR_clear_error();
  103|       |
  104|  3.24k|    return 0;
  105|  3.19k|}

LLVMFuzzerInitialize:
   22|      2|{
   23|      2|    return FuzzerInitialize(argc, argv);
   24|      2|}
LLVMFuzzerTestOneInput:
   27|  3.24k|{
   28|  3.24k|    return FuzzerTestOneInput(buf, len);
   29|  3.24k|}

err.c:do_err_strings_init_ossl_:
   62|      2|    {                                           \
   63|      2|        init##_ossl_ret_ = init();              \
   64|      2|    }                                           \
err.c:err_do_init_ossl_:
   62|      2|    {                                           \
   63|      2|        init##_ossl_ret_ = init();              \
   64|      2|    }                                           \
init.c:ossl_init_base_ossl_:
   62|      2|    {                                           \
   63|      2|        init##_ossl_ret_ = init();              \
   64|      2|    }                                           \
init.c:ossl_init_register_atexit_ossl_:
   62|      2|    {                                           \
   63|      2|        init##_ossl_ret_ = init();              \
   64|      2|    }                                           \
init.c:ossl_init_load_crypto_nodelete_ossl_:
   62|      2|    {                                           \
   63|      2|        init##_ossl_ret_ = init();              \
   64|      2|    }                                           \
init.c:ossl_init_load_crypto_strings_ossl_:
   62|      2|    {                                           \
   63|      2|        init##_ossl_ret_ = init();              \
   64|      2|    }                                           \

err.c:lh_ERR_STRING_DATA_free:
  130|      2|    { \
  131|      2|        OPENSSL_LH_free((OPENSSL_LHASH *)lh); \
  132|      2|    } \
err.c:lh_ERR_STRING_DATA_new:
  125|      2|    { \
  126|      2|        return (LHASH_OF(type) *) \
  127|      2|            OPENSSL_LH_new((OPENSSL_LH_HASHFUNC)hfn, (OPENSSL_LH_COMPFUNC)cfn); \
  128|      2|    } \
err.c:lh_ERR_STRING_DATA_insert:
  134|  15.1k|    { \
  135|  15.1k|        return (type *)OPENSSL_LH_insert((OPENSSL_LHASH *)lh, d); \
  136|  15.1k|    } \
err.c:lh_ERR_STRING_DATA_retrieve:
  142|     58|    { \
  143|     58|        return (type *)OPENSSL_LH_retrieve((OPENSSL_LHASH *)lh, d); \
  144|     58|    } \
store_register.c:lh_OSSL_STORE_LOADER_num_items:
  150|      2|    { \
  151|      2|        return OPENSSL_LH_num_items((OPENSSL_LHASH *)lh); \
  152|      2|    } \
store_register.c:lh_OSSL_STORE_LOADER_free:
  130|      2|    { \
  131|      2|        OPENSSL_LH_free((OPENSSL_LHASH *)lh); \
  132|      2|    } \

conf_mod.c:sk_CONF_MODULE_num:
   28|      4|    { \
   29|      4|        return OPENSSL_sk_num((const OPENSSL_STACK *)sk); \
   30|      4|    } \
conf_mod.c:sk_CONF_IMODULE_num:
   28|      4|    { \
   29|      4|        return OPENSSL_sk_num((const OPENSSL_STACK *)sk); \
   30|      4|    } \
conf_mod.c:sk_CONF_IMODULE_free:
   52|      4|    { \
   53|      4|        OPENSSL_sk_free((OPENSSL_STACK *)sk); \
   54|      4|    } \
ex_data.c:sk_EX_CALLBACK_pop_free:
   85|     32|    { \
   86|     32|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
   87|     32|    } \
obj_xref.c:sk_nid_triple_pop_free:
   85|      2|    { \
   86|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
   87|      2|    } \
obj_xref.c:sk_nid_triple_free:
   52|      2|    { \
   53|      2|        OPENSSL_sk_free((OPENSSL_STACK *)sk); \
   54|      2|    } \
evp_pbe.c:sk_EVP_PBE_CTL_pop_free:
   85|      2|    { \
   86|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
   87|      2|    } \

