ossl_err_load_ASN1_strings:
  210|      2|{
  211|      2|#ifndef OPENSSL_NO_ERR
  212|      2|    if (ERR_reason_error_string(ASN1_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (212:9): [True: 2, False: 0]
  ------------------
  213|      2|        ERR_load_strings_const(ASN1_str_reasons);
  214|      2|#endif
  215|      2|    return 1;
  216|      2|}

ossl_err_load_ASYNC_strings:
   31|      2|{
   32|      2|#ifndef OPENSSL_NO_ERR
   33|      2|    if (ERR_reason_error_string(ASYNC_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (33:9): [True: 2, False: 0]
  ------------------
   34|      2|        ERR_load_strings_const(ASYNC_str_reasons);
   35|      2|#endif
   36|      2|    return 1;
   37|      2|}

ossl_err_load_BIO_strings:
   93|      2|{
   94|      2|#ifndef OPENSSL_NO_ERR
   95|      2|    if (ERR_reason_error_string(BIO_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (95:9): [True: 2, False: 0]
  ------------------
   96|      2|        ERR_load_strings_const(BIO_str_reasons);
   97|      2|#endif
   98|      2|    return 1;
   99|      2|}

bio_cleanup:
  947|      2|{
  948|      2|#ifndef OPENSSL_NO_SOCK
  949|      2|    bio_sock_cleanup_int();
  950|      2|    CRYPTO_THREAD_lock_free(bio_lookup_lock);
  951|      2|    bio_lookup_lock = NULL;
  952|      2|#endif
  953|      2|    CRYPTO_FREE_REF(&bio_type_count);
  954|      2|}

bio_sock_cleanup_int:
  201|      2|{
  202|       |# ifdef OPENSSL_SYS_WINDOWS
  203|       |    if (wsa_init_done) {
  204|       |        wsa_init_done = 0;
  205|       |        WSACleanup();
  206|       |    }
  207|       |# endif
  208|      2|}

ossl_bio_core_globals_free:
   26|      2|{
   27|      2|    OPENSSL_free(vbcg);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   28|      2|}
ossl_bio_core_globals_new:
   31|      2|{
   32|      2|    return OPENSSL_zalloc(sizeof(BIO_CORE_GLOBALS));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   33|      2|}

bn_mul_add_words:
  112|  1.22M|{
  113|  1.22M|    BN_ULONG c1 = 0;
  ------------------
  |  |   37|  1.22M|#  define BN_ULONG        unsigned long
  ------------------
  114|       |
  115|  1.22M|    if (num <= 0)
  ------------------
  |  Branch (115:9): [True: 0, False: 1.22M]
  ------------------
  116|      0|        return c1;
  117|       |
  118|  15.3M|    while (num & ~3) {
  ------------------
  |  Branch (118:12): [True: 14.1M, False: 1.22M]
  ------------------
  119|  14.1M|        mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   74|  14.1M|# define mul_add(r,a,word,carry) do {   \
  |  |   75|  14.1M|        register BN_ULONG high,low;     \
  |  |   76|  14.1M|        asm ("mulq %3"                  \
  |  |   77|  14.1M|                : "=a"(low),"=d"(high)  \
  |  |   78|  14.1M|                : "a"(word),"m"(a)      \
  |  |   79|  14.1M|                : "cc");                \
  |  |   80|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   81|  14.1M|                : "+r"(carry),"+d"(high)\
  |  |   82|  14.1M|                : "a"(low),"g"(0)       \
  |  |   83|  14.1M|                : "cc");                \
  |  |   84|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   85|  14.1M|                : "+m"(r),"+d"(high)    \
  |  |   86|  14.1M|                : "r"(carry),"g"(0)     \
  |  |   87|  14.1M|                : "cc");                \
  |  |   88|  14.1M|        carry=high;                     \
  |  |   89|  14.1M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (89:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  120|  14.1M|        mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   74|  14.1M|# define mul_add(r,a,word,carry) do {   \
  |  |   75|  14.1M|        register BN_ULONG high,low;     \
  |  |   76|  14.1M|        asm ("mulq %3"                  \
  |  |   77|  14.1M|                : "=a"(low),"=d"(high)  \
  |  |   78|  14.1M|                : "a"(word),"m"(a)      \
  |  |   79|  14.1M|                : "cc");                \
  |  |   80|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   81|  14.1M|                : "+r"(carry),"+d"(high)\
  |  |   82|  14.1M|                : "a"(low),"g"(0)       \
  |  |   83|  14.1M|                : "cc");                \
  |  |   84|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   85|  14.1M|                : "+m"(r),"+d"(high)    \
  |  |   86|  14.1M|                : "r"(carry),"g"(0)     \
  |  |   87|  14.1M|                : "cc");                \
  |  |   88|  14.1M|        carry=high;                     \
  |  |   89|  14.1M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (89:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  121|  14.1M|        mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   74|  14.1M|# define mul_add(r,a,word,carry) do {   \
  |  |   75|  14.1M|        register BN_ULONG high,low;     \
  |  |   76|  14.1M|        asm ("mulq %3"                  \
  |  |   77|  14.1M|                : "=a"(low),"=d"(high)  \
  |  |   78|  14.1M|                : "a"(word),"m"(a)      \
  |  |   79|  14.1M|                : "cc");                \
  |  |   80|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   81|  14.1M|                : "+r"(carry),"+d"(high)\
  |  |   82|  14.1M|                : "a"(low),"g"(0)       \
  |  |   83|  14.1M|                : "cc");                \
  |  |   84|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   85|  14.1M|                : "+m"(r),"+d"(high)    \
  |  |   86|  14.1M|                : "r"(carry),"g"(0)     \
  |  |   87|  14.1M|                : "cc");                \
  |  |   88|  14.1M|        carry=high;                     \
  |  |   89|  14.1M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (89:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  122|  14.1M|        mul_add(rp[3], ap[3], w, c1);
  ------------------
  |  |   74|  14.1M|# define mul_add(r,a,word,carry) do {   \
  |  |   75|  14.1M|        register BN_ULONG high,low;     \
  |  |   76|  14.1M|        asm ("mulq %3"                  \
  |  |   77|  14.1M|                : "=a"(low),"=d"(high)  \
  |  |   78|  14.1M|                : "a"(word),"m"(a)      \
  |  |   79|  14.1M|                : "cc");                \
  |  |   80|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   81|  14.1M|                : "+r"(carry),"+d"(high)\
  |  |   82|  14.1M|                : "a"(low),"g"(0)       \
  |  |   83|  14.1M|                : "cc");                \
  |  |   84|  14.1M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   85|  14.1M|                : "+m"(r),"+d"(high)    \
  |  |   86|  14.1M|                : "r"(carry),"g"(0)     \
  |  |   87|  14.1M|                : "cc");                \
  |  |   88|  14.1M|        carry=high;                     \
  |  |   89|  14.1M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (89:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  123|  14.1M|        ap += 4;
  124|  14.1M|        rp += 4;
  125|  14.1M|        num -= 4;
  126|  14.1M|    }
  127|  1.22M|    if (num) {
  ------------------
  |  Branch (127:9): [True: 937k, False: 288k]
  ------------------
  128|   937k|        mul_add(rp[0], ap[0], w, c1);
  ------------------
  |  |   74|   937k|# define mul_add(r,a,word,carry) do {   \
  |  |   75|   937k|        register BN_ULONG high,low;     \
  |  |   76|   937k|        asm ("mulq %3"                  \
  |  |   77|   937k|                : "=a"(low),"=d"(high)  \
  |  |   78|   937k|                : "a"(word),"m"(a)      \
  |  |   79|   937k|                : "cc");                \
  |  |   80|   937k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   81|   937k|                : "+r"(carry),"+d"(high)\
  |  |   82|   937k|                : "a"(low),"g"(0)       \
  |  |   83|   937k|                : "cc");                \
  |  |   84|   937k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   85|   937k|                : "+m"(r),"+d"(high)    \
  |  |   86|   937k|                : "r"(carry),"g"(0)     \
  |  |   87|   937k|                : "cc");                \
  |  |   88|   937k|        carry=high;                     \
  |  |   89|   937k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (89:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  129|   937k|        if (--num == 0)
  ------------------
  |  Branch (129:13): [True: 403k, False: 533k]
  ------------------
  130|   403k|            return c1;
  131|   533k|        mul_add(rp[1], ap[1], w, c1);
  ------------------
  |  |   74|   533k|# define mul_add(r,a,word,carry) do {   \
  |  |   75|   533k|        register BN_ULONG high,low;     \
  |  |   76|   533k|        asm ("mulq %3"                  \
  |  |   77|   533k|                : "=a"(low),"=d"(high)  \
  |  |   78|   533k|                : "a"(word),"m"(a)      \
  |  |   79|   533k|                : "cc");                \
  |  |   80|   533k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   81|   533k|                : "+r"(carry),"+d"(high)\
  |  |   82|   533k|                : "a"(low),"g"(0)       \
  |  |   83|   533k|                : "cc");                \
  |  |   84|   533k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   85|   533k|                : "+m"(r),"+d"(high)    \
  |  |   86|   533k|                : "r"(carry),"g"(0)     \
  |  |   87|   533k|                : "cc");                \
  |  |   88|   533k|        carry=high;                     \
  |  |   89|   533k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (89:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  132|   533k|        if (--num == 0)
  ------------------
  |  Branch (132:13): [True: 268k, False: 264k]
  ------------------
  133|   268k|            return c1;
  134|   264k|        mul_add(rp[2], ap[2], w, c1);
  ------------------
  |  |   74|   264k|# define mul_add(r,a,word,carry) do {   \
  |  |   75|   264k|        register BN_ULONG high,low;     \
  |  |   76|   264k|        asm ("mulq %3"                  \
  |  |   77|   264k|                : "=a"(low),"=d"(high)  \
  |  |   78|   264k|                : "a"(word),"m"(a)      \
  |  |   79|   264k|                : "cc");                \
  |  |   80|   264k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   81|   264k|                : "+r"(carry),"+d"(high)\
  |  |   82|   264k|                : "a"(low),"g"(0)       \
  |  |   83|   264k|                : "cc");                \
  |  |   84|   264k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   85|   264k|                : "+m"(r),"+d"(high)    \
  |  |   86|   264k|                : "r"(carry),"g"(0)     \
  |  |   87|   264k|                : "cc");                \
  |  |   88|   264k|        carry=high;                     \
  |  |   89|   264k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (89:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  135|   264k|        return c1;
  136|   533k|    }
  137|       |
  138|   288k|    return c1;
  139|  1.22M|}
bn_mul_words:
  142|  1.30M|{
  143|  1.30M|    BN_ULONG c1 = 0;
  ------------------
  |  |   37|  1.30M|#  define BN_ULONG        unsigned long
  ------------------
  144|       |
  145|  1.30M|    if (num <= 0)
  ------------------
  |  Branch (145:9): [True: 0, False: 1.30M]
  ------------------
  146|      0|        return c1;
  147|       |
  148|  20.5M|    while (num & ~3) {
  ------------------
  |  Branch (148:12): [True: 19.2M, False: 1.30M]
  ------------------
  149|  19.2M|        mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   91|  19.2M|# define mul(r,a,word,carry) do {       \
  |  |   92|  19.2M|        register BN_ULONG high,low;     \
  |  |   93|  19.2M|        asm ("mulq %3"                  \
  |  |   94|  19.2M|                : "=a"(low),"=d"(high)  \
  |  |   95|  19.2M|                : "a"(word),"g"(a)      \
  |  |   96|  19.2M|                : "cc");                \
  |  |   97|  19.2M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   98|  19.2M|                : "+r"(carry),"+d"(high)\
  |  |   99|  19.2M|                : "a"(low),"g"(0)       \
  |  |  100|  19.2M|                : "cc");                \
  |  |  101|  19.2M|        (r)=carry, carry=high;          \
  |  |  102|  19.2M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (102:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  150|  19.2M|        mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   91|  19.2M|# define mul(r,a,word,carry) do {       \
  |  |   92|  19.2M|        register BN_ULONG high,low;     \
  |  |   93|  19.2M|        asm ("mulq %3"                  \
  |  |   94|  19.2M|                : "=a"(low),"=d"(high)  \
  |  |   95|  19.2M|                : "a"(word),"g"(a)      \
  |  |   96|  19.2M|                : "cc");                \
  |  |   97|  19.2M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   98|  19.2M|                : "+r"(carry),"+d"(high)\
  |  |   99|  19.2M|                : "a"(low),"g"(0)       \
  |  |  100|  19.2M|                : "cc");                \
  |  |  101|  19.2M|        (r)=carry, carry=high;          \
  |  |  102|  19.2M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (102:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  151|  19.2M|        mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   91|  19.2M|# define mul(r,a,word,carry) do {       \
  |  |   92|  19.2M|        register BN_ULONG high,low;     \
  |  |   93|  19.2M|        asm ("mulq %3"                  \
  |  |   94|  19.2M|                : "=a"(low),"=d"(high)  \
  |  |   95|  19.2M|                : "a"(word),"g"(a)      \
  |  |   96|  19.2M|                : "cc");                \
  |  |   97|  19.2M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   98|  19.2M|                : "+r"(carry),"+d"(high)\
  |  |   99|  19.2M|                : "a"(low),"g"(0)       \
  |  |  100|  19.2M|                : "cc");                \
  |  |  101|  19.2M|        (r)=carry, carry=high;          \
  |  |  102|  19.2M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (102:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  152|  19.2M|        mul(rp[3], ap[3], w, c1);
  ------------------
  |  |   91|  19.2M|# define mul(r,a,word,carry) do {       \
  |  |   92|  19.2M|        register BN_ULONG high,low;     \
  |  |   93|  19.2M|        asm ("mulq %3"                  \
  |  |   94|  19.2M|                : "=a"(low),"=d"(high)  \
  |  |   95|  19.2M|                : "a"(word),"g"(a)      \
  |  |   96|  19.2M|                : "cc");                \
  |  |   97|  19.2M|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   98|  19.2M|                : "+r"(carry),"+d"(high)\
  |  |   99|  19.2M|                : "a"(low),"g"(0)       \
  |  |  100|  19.2M|                : "cc");                \
  |  |  101|  19.2M|        (r)=carry, carry=high;          \
  |  |  102|  19.2M|        } while (0)
  |  |  ------------------
  |  |  |  Branch (102:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  153|  19.2M|        ap += 4;
  154|  19.2M|        rp += 4;
  155|  19.2M|        num -= 4;
  156|  19.2M|    }
  157|  1.30M|    if (num) {
  ------------------
  |  Branch (157:9): [True: 983k, False: 321k]
  ------------------
  158|   983k|        mul(rp[0], ap[0], w, c1);
  ------------------
  |  |   91|   983k|# define mul(r,a,word,carry) do {       \
  |  |   92|   983k|        register BN_ULONG high,low;     \
  |  |   93|   983k|        asm ("mulq %3"                  \
  |  |   94|   983k|                : "=a"(low),"=d"(high)  \
  |  |   95|   983k|                : "a"(word),"g"(a)      \
  |  |   96|   983k|                : "cc");                \
  |  |   97|   983k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   98|   983k|                : "+r"(carry),"+d"(high)\
  |  |   99|   983k|                : "a"(low),"g"(0)       \
  |  |  100|   983k|                : "cc");                \
  |  |  101|   983k|        (r)=carry, carry=high;          \
  |  |  102|   983k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (102:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  159|   983k|        if (--num == 0)
  ------------------
  |  Branch (159:13): [True: 628k, False: 355k]
  ------------------
  160|   628k|            return c1;
  161|   355k|        mul(rp[1], ap[1], w, c1);
  ------------------
  |  |   91|   355k|# define mul(r,a,word,carry) do {       \
  |  |   92|   355k|        register BN_ULONG high,low;     \
  |  |   93|   355k|        asm ("mulq %3"                  \
  |  |   94|   355k|                : "=a"(low),"=d"(high)  \
  |  |   95|   355k|                : "a"(word),"g"(a)      \
  |  |   96|   355k|                : "cc");                \
  |  |   97|   355k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   98|   355k|                : "+r"(carry),"+d"(high)\
  |  |   99|   355k|                : "a"(low),"g"(0)       \
  |  |  100|   355k|                : "cc");                \
  |  |  101|   355k|        (r)=carry, carry=high;          \
  |  |  102|   355k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (102:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  162|   355k|        if (--num == 0)
  ------------------
  |  Branch (162:13): [True: 164k, False: 190k]
  ------------------
  163|   164k|            return c1;
  164|   190k|        mul(rp[2], ap[2], w, c1);
  ------------------
  |  |   91|   190k|# define mul(r,a,word,carry) do {       \
  |  |   92|   190k|        register BN_ULONG high,low;     \
  |  |   93|   190k|        asm ("mulq %3"                  \
  |  |   94|   190k|                : "=a"(low),"=d"(high)  \
  |  |   95|   190k|                : "a"(word),"g"(a)      \
  |  |   96|   190k|                : "cc");                \
  |  |   97|   190k|        asm ("addq %2,%0; adcq %3,%1"   \
  |  |   98|   190k|                : "+r"(carry),"+d"(high)\
  |  |   99|   190k|                : "a"(low),"g"(0)       \
  |  |  100|   190k|                : "cc");                \
  |  |  101|   190k|        (r)=carry, carry=high;          \
  |  |  102|   190k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (102:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  165|   190k|    }
  166|   512k|    return c1;
  167|  1.30M|}
bn_sqr_words:
  170|   318k|{
  171|   318k|    if (n <= 0)
  ------------------
  |  Branch (171:9): [True: 0, False: 318k]
  ------------------
  172|      0|        return;
  173|       |
  174|   538k|    while (n & ~3) {
  ------------------
  |  Branch (174:12): [True: 219k, False: 318k]
  ------------------
  175|   219k|        sqr(r[0], r[1], a[0]);
  ------------------
  |  |  105|   219k|        asm ("mulq %2"                  \
  |  |  106|   219k|                : "=a"(r0),"=d"(r1)     \
  |  |  107|   219k|                : "a"(a)                \
  |  |  108|   219k|                : "cc");
  ------------------
  176|   219k|        sqr(r[2], r[3], a[1]);
  ------------------
  |  |  105|   219k|        asm ("mulq %2"                  \
  |  |  106|   219k|                : "=a"(r0),"=d"(r1)     \
  |  |  107|   219k|                : "a"(a)                \
  |  |  108|   219k|                : "cc");
  ------------------
  177|   219k|        sqr(r[4], r[5], a[2]);
  ------------------
  |  |  105|   219k|        asm ("mulq %2"                  \
  |  |  106|   219k|                : "=a"(r0),"=d"(r1)     \
  |  |  107|   219k|                : "a"(a)                \
  |  |  108|   219k|                : "cc");
  ------------------
  178|   219k|        sqr(r[6], r[7], a[3]);
  ------------------
  |  |  105|   219k|        asm ("mulq %2"                  \
  |  |  106|   219k|                : "=a"(r0),"=d"(r1)     \
  |  |  107|   219k|                : "a"(a)                \
  |  |  108|   219k|                : "cc");
  ------------------
  179|   219k|        a += 4;
  180|   219k|        r += 8;
  181|   219k|        n -= 4;
  182|   219k|    }
  183|   318k|    if (n) {
  ------------------
  |  Branch (183:9): [True: 315k, False: 2.43k]
  ------------------
  184|   315k|        sqr(r[0], r[1], a[0]);
  ------------------
  |  |  105|   315k|        asm ("mulq %2"                  \
  |  |  106|   315k|                : "=a"(r0),"=d"(r1)     \
  |  |  107|   315k|                : "a"(a)                \
  |  |  108|   315k|                : "cc");
  ------------------
  185|   315k|        if (--n == 0)
  ------------------
  |  Branch (185:13): [True: 299k, False: 16.7k]
  ------------------
  186|   299k|            return;
  187|  16.7k|        sqr(r[2], r[3], a[1]);
  ------------------
  |  |  105|  16.7k|        asm ("mulq %2"                  \
  |  |  106|  16.7k|                : "=a"(r0),"=d"(r1)     \
  |  |  107|  16.7k|                : "a"(a)                \
  |  |  108|  16.7k|                : "cc");
  ------------------
  188|  16.7k|        if (--n == 0)
  ------------------
  |  Branch (188:13): [True: 7.73k, False: 9.02k]
  ------------------
  189|  7.73k|            return;
  190|  9.02k|        sqr(r[4], r[5], a[2]);
  ------------------
  |  |  105|  9.02k|        asm ("mulq %2"                  \
  |  |  106|  9.02k|                : "=a"(r0),"=d"(r1)     \
  |  |  107|  9.02k|                : "a"(a)                \
  |  |  108|  9.02k|                : "cc");
  ------------------
  191|  9.02k|    }
  192|   318k|}
bn_div_words:
  195|  1.00M|{
  196|  1.00M|    BN_ULONG ret, waste;
  ------------------
  |  |   37|  1.00M|#  define BN_ULONG        unsigned long
  ------------------
  197|       |
  198|  1.00M| asm("divq      %4":"=a"(ret), "=d"(waste)
  199|  1.00M| :     "a"(l), "d"(h), "r"(d)
  200|  1.00M| :     "cc");
  201|       |
  202|  1.00M|    return ret;
  203|  1.00M|}
bn_add_words:
  207|  3.04M|{
  208|  3.04M|    BN_ULONG ret;
  ------------------
  |  |   37|  3.04M|#  define BN_ULONG        unsigned long
  ------------------
  209|  3.04M|    size_t i = 0;
  210|       |
  211|  3.04M|    if (n <= 0)
  ------------------
  |  Branch (211:9): [True: 1.28k, False: 3.04M]
  ------------------
  212|  1.28k|        return 0;
  213|       |
  214|  3.04M|    asm volatile ("       subq    %0,%0           \n" /* clear carry */
  215|  3.04M|                  "       jmp     1f              \n"
  216|  3.04M|                  ".p2align 4                     \n"
  217|  3.04M|                  "1:     movq    (%4,%2,8),%0    \n"
  218|  3.04M|                  "       adcq    (%5,%2,8),%0    \n"
  219|  3.04M|                  "       movq    %0,(%3,%2,8)    \n"
  220|  3.04M|                  "       lea     1(%2),%2        \n"
  221|  3.04M|                  "       dec     %1              \n"
  222|  3.04M|                  "       jnz     1b              \n"
  223|  3.04M|                  "       sbbq    %0,%0           \n"
  224|  3.04M|                  :"=&r" (ret), "+c"(n), "+r"(i)
  225|  3.04M|                  :"r"(rp), "r"(ap), "r"(bp)
  226|  3.04M|                  :"cc", "memory");
  227|       |
  228|  3.04M|    return ret & 1;
  229|  3.04M|}
bn_sub_words:
  234|  2.67M|{
  235|  2.67M|    BN_ULONG ret;
  ------------------
  |  |   37|  2.67M|#  define BN_ULONG        unsigned long
  ------------------
  236|  2.67M|    size_t i = 0;
  237|       |
  238|  2.67M|    if (n <= 0)
  ------------------
  |  Branch (238:9): [True: 5.57k, False: 2.66M]
  ------------------
  239|  5.57k|        return 0;
  240|       |
  241|  2.66M|    asm volatile ("       subq    %0,%0           \n" /* clear borrow */
  242|  2.66M|                  "       jmp     1f              \n"
  243|  2.66M|                  ".p2align 4                     \n"
  244|  2.66M|                  "1:     movq    (%4,%2,8),%0    \n"
  245|  2.66M|                  "       sbbq    (%5,%2,8),%0    \n"
  246|  2.66M|                  "       movq    %0,(%3,%2,8)    \n"
  247|  2.66M|                  "       lea     1(%2),%2        \n"
  248|  2.66M|                  "       dec     %1              \n"
  249|  2.66M|                  "       jnz     1b              \n"
  250|  2.66M|                  "       sbbq    %0,%0           \n"
  251|  2.66M|                  :"=&r" (ret), "+c"(n), "+r"(i)
  252|  2.66M|                  :"r"(rp), "r"(ap), "r"(bp)
  253|  2.66M|                  :"cc", "memory");
  254|       |
  255|  2.66M|    return ret & 1;
  256|  2.67M|}
bn_mul_comba8:
  394|   999k|{
  395|   999k|    BN_ULONG c1, c2, c3;
  ------------------
  |  |   37|   999k|#  define BN_ULONG        unsigned long
  ------------------
  396|       |
  397|   999k|    c1 = 0;
  398|   999k|    c2 = 0;
  399|   999k|    c3 = 0;
  400|   999k|    mul_add_c(a[0], b[0], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  401|   999k|    r[0] = c1;
  402|   999k|    c1 = 0;
  403|   999k|    mul_add_c(a[0], b[1], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  404|   999k|    mul_add_c(a[1], b[0], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  405|   999k|    r[1] = c2;
  406|   999k|    c2 = 0;
  407|   999k|    mul_add_c(a[2], b[0], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  408|   999k|    mul_add_c(a[1], b[1], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  409|   999k|    mul_add_c(a[0], b[2], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  410|   999k|    r[2] = c3;
  411|   999k|    c3 = 0;
  412|   999k|    mul_add_c(a[0], b[3], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  413|   999k|    mul_add_c(a[1], b[2], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  414|   999k|    mul_add_c(a[2], b[1], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  415|   999k|    mul_add_c(a[3], b[0], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  416|   999k|    r[3] = c1;
  417|   999k|    c1 = 0;
  418|   999k|    mul_add_c(a[4], b[0], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  419|   999k|    mul_add_c(a[3], b[1], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  420|   999k|    mul_add_c(a[2], b[2], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  421|   999k|    mul_add_c(a[1], b[3], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  422|   999k|    mul_add_c(a[0], b[4], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  423|   999k|    r[4] = c2;
  424|   999k|    c2 = 0;
  425|   999k|    mul_add_c(a[0], b[5], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  426|   999k|    mul_add_c(a[1], b[4], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  427|   999k|    mul_add_c(a[2], b[3], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  428|   999k|    mul_add_c(a[3], b[2], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  429|   999k|    mul_add_c(a[4], b[1], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  430|   999k|    mul_add_c(a[5], b[0], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  431|   999k|    r[5] = c3;
  432|   999k|    c3 = 0;
  433|   999k|    mul_add_c(a[6], b[0], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  434|   999k|    mul_add_c(a[5], b[1], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  435|   999k|    mul_add_c(a[4], b[2], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  436|   999k|    mul_add_c(a[3], b[3], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  437|   999k|    mul_add_c(a[2], b[4], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  438|   999k|    mul_add_c(a[1], b[5], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  439|   999k|    mul_add_c(a[0], b[6], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  440|   999k|    r[6] = c1;
  441|   999k|    c1 = 0;
  442|   999k|    mul_add_c(a[0], b[7], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  443|   999k|    mul_add_c(a[1], b[6], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  444|   999k|    mul_add_c(a[2], b[5], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  445|   999k|    mul_add_c(a[3], b[4], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  446|   999k|    mul_add_c(a[4], b[3], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  447|   999k|    mul_add_c(a[5], b[2], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  448|   999k|    mul_add_c(a[6], b[1], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  449|   999k|    mul_add_c(a[7], b[0], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  450|   999k|    r[7] = c2;
  451|   999k|    c2 = 0;
  452|   999k|    mul_add_c(a[7], b[1], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  453|   999k|    mul_add_c(a[6], b[2], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  454|   999k|    mul_add_c(a[5], b[3], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  455|   999k|    mul_add_c(a[4], b[4], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  456|   999k|    mul_add_c(a[3], b[5], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  457|   999k|    mul_add_c(a[2], b[6], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  458|   999k|    mul_add_c(a[1], b[7], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  459|   999k|    r[8] = c3;
  460|   999k|    c3 = 0;
  461|   999k|    mul_add_c(a[2], b[7], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  462|   999k|    mul_add_c(a[3], b[6], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  463|   999k|    mul_add_c(a[4], b[5], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  464|   999k|    mul_add_c(a[5], b[4], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  465|   999k|    mul_add_c(a[6], b[3], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  466|   999k|    mul_add_c(a[7], b[2], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  467|   999k|    r[9] = c1;
  468|   999k|    c1 = 0;
  469|   999k|    mul_add_c(a[7], b[3], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  470|   999k|    mul_add_c(a[6], b[4], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  471|   999k|    mul_add_c(a[5], b[5], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  472|   999k|    mul_add_c(a[4], b[6], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  473|   999k|    mul_add_c(a[3], b[7], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  474|   999k|    r[10] = c2;
  475|   999k|    c2 = 0;
  476|   999k|    mul_add_c(a[4], b[7], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  477|   999k|    mul_add_c(a[5], b[6], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  478|   999k|    mul_add_c(a[6], b[5], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  479|   999k|    mul_add_c(a[7], b[4], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  480|   999k|    r[11] = c3;
  481|   999k|    c3 = 0;
  482|   999k|    mul_add_c(a[7], b[5], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  483|   999k|    mul_add_c(a[6], b[6], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  484|   999k|    mul_add_c(a[5], b[7], c1, c2, c3);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  485|   999k|    r[12] = c1;
  486|   999k|    c1 = 0;
  487|   999k|    mul_add_c(a[6], b[7], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  488|   999k|    mul_add_c(a[7], b[6], c2, c3, c1);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  489|   999k|    r[13] = c2;
  490|   999k|    c2 = 0;
  491|   999k|    mul_add_c(a[7], b[7], c3, c1, c2);
  ------------------
  |  |  349|   999k|#  define mul_add_c(a,b,c0,c1,c2) do {  \
  |  |  350|   999k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|   999k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  351|   999k|        asm ("mulq %3"                  \
  |  |  352|   999k|                : "=a"(t1),"=d"(t2)     \
  |  |  353|   999k|                : "a"(a),"m"(b)         \
  |  |  354|   999k|                : "cc");                \
  |  |  355|   999k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  356|   999k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  357|   999k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  358|   999k|                : "cc");                                \
  |  |  359|   999k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (359:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  492|   999k|    r[14] = c3;
  493|   999k|    r[15] = c1;
  494|   999k|}
bn_sqr_comba8:
  536|  72.7k|{
  537|  72.7k|    BN_ULONG c1, c2, c3;
  ------------------
  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  ------------------
  538|       |
  539|  72.7k|    c1 = 0;
  540|  72.7k|    c2 = 0;
  541|  72.7k|    c3 = 0;
  542|  72.7k|    sqr_add_c(a, 0, c1, c2, c3);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  543|  72.7k|    r[0] = c1;
  544|  72.7k|    c1 = 0;
  545|  72.7k|    sqr_add_c2(a, 1, 0, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  546|  72.7k|    r[1] = c2;
  547|  72.7k|    c2 = 0;
  548|  72.7k|    sqr_add_c(a, 1, c3, c1, c2);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  549|  72.7k|    sqr_add_c2(a, 2, 0, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  550|  72.7k|    r[2] = c3;
  551|  72.7k|    c3 = 0;
  552|  72.7k|    sqr_add_c2(a, 3, 0, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  553|  72.7k|    sqr_add_c2(a, 2, 1, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  554|  72.7k|    r[3] = c1;
  555|  72.7k|    c1 = 0;
  556|  72.7k|    sqr_add_c(a, 2, c2, c3, c1);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  557|  72.7k|    sqr_add_c2(a, 3, 1, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  558|  72.7k|    sqr_add_c2(a, 4, 0, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  559|  72.7k|    r[4] = c2;
  560|  72.7k|    c2 = 0;
  561|  72.7k|    sqr_add_c2(a, 5, 0, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  562|  72.7k|    sqr_add_c2(a, 4, 1, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  563|  72.7k|    sqr_add_c2(a, 3, 2, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  564|  72.7k|    r[5] = c3;
  565|  72.7k|    c3 = 0;
  566|  72.7k|    sqr_add_c(a, 3, c1, c2, c3);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  567|  72.7k|    sqr_add_c2(a, 4, 2, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  568|  72.7k|    sqr_add_c2(a, 5, 1, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  569|  72.7k|    sqr_add_c2(a, 6, 0, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  570|  72.7k|    r[6] = c1;
  571|  72.7k|    c1 = 0;
  572|  72.7k|    sqr_add_c2(a, 7, 0, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  573|  72.7k|    sqr_add_c2(a, 6, 1, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  574|  72.7k|    sqr_add_c2(a, 5, 2, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  575|  72.7k|    sqr_add_c2(a, 4, 3, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  576|  72.7k|    r[7] = c2;
  577|  72.7k|    c2 = 0;
  578|  72.7k|    sqr_add_c(a, 4, c3, c1, c2);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  579|  72.7k|    sqr_add_c2(a, 5, 3, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  580|  72.7k|    sqr_add_c2(a, 6, 2, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  581|  72.7k|    sqr_add_c2(a, 7, 1, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  582|  72.7k|    r[8] = c3;
  583|  72.7k|    c3 = 0;
  584|  72.7k|    sqr_add_c2(a, 7, 2, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  585|  72.7k|    sqr_add_c2(a, 6, 3, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  586|  72.7k|    sqr_add_c2(a, 5, 4, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  587|  72.7k|    r[9] = c1;
  588|  72.7k|    c1 = 0;
  589|  72.7k|    sqr_add_c(a, 5, c2, c3, c1);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  590|  72.7k|    sqr_add_c2(a, 6, 4, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  591|  72.7k|    sqr_add_c2(a, 7, 3, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  592|  72.7k|    r[10] = c2;
  593|  72.7k|    c2 = 0;
  594|  72.7k|    sqr_add_c2(a, 7, 4, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  595|  72.7k|    sqr_add_c2(a, 6, 5, c3, c1, c2);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  596|  72.7k|    r[11] = c3;
  597|  72.7k|    c3 = 0;
  598|  72.7k|    sqr_add_c(a, 6, c1, c2, c3);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  599|  72.7k|    sqr_add_c2(a, 7, 5, c1, c2, c3);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  600|  72.7k|    r[12] = c1;
  601|  72.7k|    c1 = 0;
  602|  72.7k|    sqr_add_c2(a, 7, 6, c2, c3, c1);
  ------------------
  |  |  391|  72.7k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  72.7k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  72.7k|        asm ("mulq %3"                  \
  |  |  |  |  376|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  72.7k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  72.7k|                : "cc");                \
  |  |  |  |  379|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  72.7k|                : "cc");                                \
  |  |  |  |  383|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  72.7k|                : "cc");                                \
  |  |  |  |  387|  72.7k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  603|  72.7k|    r[13] = c2;
  604|  72.7k|    c2 = 0;
  605|  72.7k|    sqr_add_c(a, 7, c3, c1, c2);
  ------------------
  |  |  361|  72.7k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  72.7k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  72.7k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  72.7k|        asm ("mulq %2"                  \
  |  |  364|  72.7k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  72.7k|                : "a"(a[i])             \
  |  |  366|  72.7k|                : "cc");                \
  |  |  367|  72.7k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  72.7k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  72.7k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  72.7k|                : "cc");                                \
  |  |  371|  72.7k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  606|  72.7k|    r[14] = c3;
  607|  72.7k|    r[15] = c1;
  608|  72.7k|}
bn_sqr_comba4:
  611|  2.40k|{
  612|  2.40k|    BN_ULONG c1, c2, c3;
  ------------------
  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  ------------------
  613|       |
  614|  2.40k|    c1 = 0;
  615|  2.40k|    c2 = 0;
  616|  2.40k|    c3 = 0;
  617|  2.40k|    sqr_add_c(a, 0, c1, c2, c3);
  ------------------
  |  |  361|  2.40k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  2.40k|        asm ("mulq %2"                  \
  |  |  364|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  2.40k|                : "a"(a[i])             \
  |  |  366|  2.40k|                : "cc");                \
  |  |  367|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  2.40k|                : "cc");                                \
  |  |  371|  2.40k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  618|  2.40k|    r[0] = c1;
  619|  2.40k|    c1 = 0;
  620|  2.40k|    sqr_add_c2(a, 1, 0, c2, c3, c1);
  ------------------
  |  |  391|  2.40k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  2.40k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  2.40k|        asm ("mulq %3"                  \
  |  |  |  |  376|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  2.40k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  2.40k|                : "cc");                \
  |  |  |  |  379|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  2.40k|                : "cc");                                \
  |  |  |  |  383|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  2.40k|                : "cc");                                \
  |  |  |  |  387|  2.40k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  621|  2.40k|    r[1] = c2;
  622|  2.40k|    c2 = 0;
  623|  2.40k|    sqr_add_c(a, 1, c3, c1, c2);
  ------------------
  |  |  361|  2.40k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  2.40k|        asm ("mulq %2"                  \
  |  |  364|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  2.40k|                : "a"(a[i])             \
  |  |  366|  2.40k|                : "cc");                \
  |  |  367|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  2.40k|                : "cc");                                \
  |  |  371|  2.40k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  624|  2.40k|    sqr_add_c2(a, 2, 0, c3, c1, c2);
  ------------------
  |  |  391|  2.40k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  2.40k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  2.40k|        asm ("mulq %3"                  \
  |  |  |  |  376|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  2.40k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  2.40k|                : "cc");                \
  |  |  |  |  379|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  2.40k|                : "cc");                                \
  |  |  |  |  383|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  2.40k|                : "cc");                                \
  |  |  |  |  387|  2.40k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  625|  2.40k|    r[2] = c3;
  626|  2.40k|    c3 = 0;
  627|  2.40k|    sqr_add_c2(a, 3, 0, c1, c2, c3);
  ------------------
  |  |  391|  2.40k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  2.40k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  2.40k|        asm ("mulq %3"                  \
  |  |  |  |  376|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  2.40k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  2.40k|                : "cc");                \
  |  |  |  |  379|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  2.40k|                : "cc");                                \
  |  |  |  |  383|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  2.40k|                : "cc");                                \
  |  |  |  |  387|  2.40k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  628|  2.40k|    sqr_add_c2(a, 2, 1, c1, c2, c3);
  ------------------
  |  |  391|  2.40k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  2.40k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  2.40k|        asm ("mulq %3"                  \
  |  |  |  |  376|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  2.40k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  2.40k|                : "cc");                \
  |  |  |  |  379|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  2.40k|                : "cc");                                \
  |  |  |  |  383|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  2.40k|                : "cc");                                \
  |  |  |  |  387|  2.40k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  629|  2.40k|    r[3] = c1;
  630|  2.40k|    c1 = 0;
  631|  2.40k|    sqr_add_c(a, 2, c2, c3, c1);
  ------------------
  |  |  361|  2.40k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  2.40k|        asm ("mulq %2"                  \
  |  |  364|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  2.40k|                : "a"(a[i])             \
  |  |  366|  2.40k|                : "cc");                \
  |  |  367|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  2.40k|                : "cc");                                \
  |  |  371|  2.40k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  632|  2.40k|    sqr_add_c2(a, 3, 1, c2, c3, c1);
  ------------------
  |  |  391|  2.40k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  2.40k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  2.40k|        asm ("mulq %3"                  \
  |  |  |  |  376|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  2.40k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  2.40k|                : "cc");                \
  |  |  |  |  379|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  2.40k|                : "cc");                                \
  |  |  |  |  383|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  2.40k|                : "cc");                                \
  |  |  |  |  387|  2.40k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  633|  2.40k|    r[4] = c2;
  634|  2.40k|    c2 = 0;
  635|  2.40k|    sqr_add_c2(a, 3, 2, c3, c1, c2);
  ------------------
  |  |  391|  2.40k|        mul_add_c2((a)[i],(a)[j],c0,c1,c2)
  |  |  ------------------
  |  |  |  |  373|  2.40k|#  define mul_add_c2(a,b,c0,c1,c2) do { \
  |  |  |  |  374|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  |  |  ------------------
  |  |  |  |  375|  2.40k|        asm ("mulq %3"                  \
  |  |  |  |  376|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  |  |  377|  2.40k|                : "a"(a),"m"(b)         \
  |  |  |  |  378|  2.40k|                : "cc");                \
  |  |  |  |  379|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  380|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  381|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  382|  2.40k|                : "cc");                                \
  |  |  |  |  383|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  |  |  384|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  |  |  385|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  |  |  386|  2.40k|                : "cc");                                \
  |  |  |  |  387|  2.40k|        } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (387:18): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  636|  2.40k|    r[5] = c3;
  637|  2.40k|    c3 = 0;
  638|  2.40k|    sqr_add_c(a, 3, c1, c2, c3);
  ------------------
  |  |  361|  2.40k|#  define sqr_add_c(a,i,c0,c1,c2) do {  \
  |  |  362|  2.40k|        BN_ULONG t1,t2;                 \
  |  |  ------------------
  |  |  |  |   37|  2.40k|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  363|  2.40k|        asm ("mulq %2"                  \
  |  |  364|  2.40k|                : "=a"(t1),"=d"(t2)     \
  |  |  365|  2.40k|                : "a"(a[i])             \
  |  |  366|  2.40k|                : "cc");                \
  |  |  367|  2.40k|        asm ("addq %3,%0; adcq %4,%1; adcq %5,%2"       \
  |  |  368|  2.40k|                : "+r"(c0),"+r"(c1),"+r"(c2)            \
  |  |  369|  2.40k|                : "r"(t1),"r"(t2),"g"(0)                \
  |  |  370|  2.40k|                : "cc");                                \
  |  |  371|  2.40k|        } while (0)
  |  |  ------------------
  |  |  |  Branch (371:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
  639|  2.40k|    r[6] = c1;
  640|  2.40k|    r[7] = c2;
  641|  2.40k|}

BN_add:
   15|  2.27k|{
   16|  2.27k|    int ret, r_neg, cmp_res;
   17|       |
   18|  2.27k|    bn_check_top(a);
   19|  2.27k|    bn_check_top(b);
   20|       |
   21|  2.27k|    if (a->neg == b->neg) {
  ------------------
  |  Branch (21:9): [True: 0, False: 2.27k]
  ------------------
   22|      0|        r_neg = a->neg;
   23|      0|        ret = BN_uadd(r, a, b);
   24|  2.27k|    } else {
   25|  2.27k|        cmp_res = BN_ucmp(a, b);
   26|  2.27k|        if (cmp_res > 0) {
  ------------------
  |  Branch (26:13): [True: 0, False: 2.27k]
  ------------------
   27|      0|            r_neg = a->neg;
   28|      0|            ret = BN_usub(r, a, b);
   29|  2.27k|        } else if (cmp_res < 0) {
  ------------------
  |  Branch (29:20): [True: 2.27k, False: 0]
  ------------------
   30|  2.27k|            r_neg = b->neg;
   31|  2.27k|            ret = BN_usub(r, b, a);
   32|  2.27k|        } else {
   33|      0|            r_neg = 0;
   34|      0|            BN_zero(r);
  ------------------
  |  |  202|      0|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
   35|      0|            ret = 1;
   36|      0|        }
   37|  2.27k|    }
   38|       |
   39|  2.27k|    r->neg = r_neg;
   40|  2.27k|    bn_check_top(r);
   41|  2.27k|    return ret;
   42|  2.27k|}
BN_sub:
   46|  2.52k|{
   47|  2.52k|    int ret, r_neg, cmp_res;
   48|       |
   49|  2.52k|    bn_check_top(a);
   50|  2.52k|    bn_check_top(b);
   51|       |
   52|  2.52k|    if (a->neg != b->neg) {
  ------------------
  |  Branch (52:9): [True: 0, False: 2.52k]
  ------------------
   53|      0|        r_neg = a->neg;
   54|      0|        ret = BN_uadd(r, a, b);
   55|  2.52k|    } else {
   56|  2.52k|        cmp_res = BN_ucmp(a, b);
   57|  2.52k|        if (cmp_res > 0) {
  ------------------
  |  Branch (57:13): [True: 730, False: 1.79k]
  ------------------
   58|    730|            r_neg = a->neg;
   59|    730|            ret = BN_usub(r, a, b);
   60|  1.79k|        } else if (cmp_res < 0) {
  ------------------
  |  Branch (60:20): [True: 1.79k, False: 0]
  ------------------
   61|  1.79k|            r_neg = !b->neg;
   62|  1.79k|            ret = BN_usub(r, b, a);
   63|  1.79k|        } else {
   64|      0|            r_neg = 0;
   65|      0|            BN_zero(r);
  ------------------
  |  |  202|      0|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
   66|      0|            ret = 1;
   67|      0|        }
   68|  2.52k|    }
   69|       |
   70|  2.52k|    r->neg = r_neg;
   71|  2.52k|    bn_check_top(r);
   72|  2.52k|    return ret;
   73|  2.52k|}
BN_uadd:
   77|  77.8k|{
   78|  77.8k|    int max, min, dif;
   79|  77.8k|    const BN_ULONG *ap, *bp;
   80|  77.8k|    BN_ULONG *rp, carry, t1, t2;
  ------------------
  |  |   37|  77.8k|#  define BN_ULONG        unsigned long
  ------------------
   81|       |
   82|  77.8k|    bn_check_top(a);
   83|  77.8k|    bn_check_top(b);
   84|       |
   85|  77.8k|    if (a->top < b->top) {
  ------------------
  |  Branch (85:9): [True: 1.67k, False: 76.2k]
  ------------------
   86|  1.67k|        const BIGNUM *tmp;
   87|       |
   88|  1.67k|        tmp = a;
   89|  1.67k|        a = b;
   90|  1.67k|        b = tmp;
   91|  1.67k|    }
   92|  77.8k|    max = a->top;
   93|  77.8k|    min = b->top;
   94|  77.8k|    dif = max - min;
   95|       |
   96|  77.8k|    if (bn_wexpand(r, max + 1) == NULL)
  ------------------
  |  Branch (96:9): [True: 0, False: 77.8k]
  ------------------
   97|      0|        return 0;
   98|       |
   99|  77.8k|    r->top = max;
  100|       |
  101|  77.8k|    ap = a->d;
  102|  77.8k|    bp = b->d;
  103|  77.8k|    rp = r->d;
  104|       |
  105|  77.8k|    carry = bn_add_words(rp, ap, bp, min);
  106|  77.8k|    rp += min;
  107|  77.8k|    ap += min;
  108|       |
  109|  86.6k|    while (dif) {
  ------------------
  |  Branch (109:12): [True: 8.74k, False: 77.8k]
  ------------------
  110|  8.74k|        dif--;
  111|  8.74k|        t1 = *(ap++);
  112|  8.74k|        t2 = (t1 + carry) & BN_MASK2;
  ------------------
  |  |   94|  8.74k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  113|  8.74k|        *(rp++) = t2;
  114|  8.74k|        carry &= (t2 == 0);
  115|  8.74k|    }
  116|  77.8k|    *rp = carry;
  117|  77.8k|    r->top += carry;
  118|       |
  119|  77.8k|    r->neg = 0;
  120|  77.8k|    bn_check_top(r);
  121|  77.8k|    return 1;
  122|  77.8k|}
BN_usub:
  126|   206k|{
  127|   206k|    int max, min, dif;
  128|   206k|    BN_ULONG t1, t2, borrow, *rp;
  ------------------
  |  |   37|   206k|#  define BN_ULONG        unsigned long
  ------------------
  129|   206k|    const BN_ULONG *ap, *bp;
  130|       |
  131|   206k|    bn_check_top(a);
  132|   206k|    bn_check_top(b);
  133|       |
  134|   206k|    max = a->top;
  135|   206k|    min = b->top;
  136|   206k|    dif = max - min;
  137|       |
  138|   206k|    if (dif < 0) {              /* hmm... should not be happening */
  ------------------
  |  Branch (138:9): [True: 0, False: 206k]
  ------------------
  139|      0|        ERR_raise(ERR_LIB_BN, BN_R_ARG2_LT_ARG3);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  140|      0|        return 0;
  141|      0|    }
  142|       |
  143|   206k|    if (bn_wexpand(r, max) == NULL)
  ------------------
  |  Branch (143:9): [True: 0, False: 206k]
  ------------------
  144|      0|        return 0;
  145|       |
  146|   206k|    ap = a->d;
  147|   206k|    bp = b->d;
  148|   206k|    rp = r->d;
  149|       |
  150|   206k|    borrow = bn_sub_words(rp, ap, bp, min);
  151|   206k|    ap += min;
  152|   206k|    rp += min;
  153|       |
  154|   285k|    while (dif) {
  ------------------
  |  Branch (154:12): [True: 78.6k, False: 206k]
  ------------------
  155|  78.6k|        dif--;
  156|  78.6k|        t1 = *(ap++);
  157|  78.6k|        t2 = (t1 - borrow) & BN_MASK2;
  ------------------
  |  |   94|  78.6k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  158|  78.6k|        *(rp++) = t2;
  159|  78.6k|        borrow &= (t1 == 0);
  160|  78.6k|    }
  161|       |
  162|  1.03M|    while (max && *--rp == 0)
  ------------------
  |  Branch (162:12): [True: 1.03M, False: 1.33k]
  |  Branch (162:19): [True: 831k, False: 205k]
  ------------------
  163|   831k|        max--;
  164|       |
  165|   206k|    r->top = max;
  166|   206k|    r->neg = 0;
  167|   206k|    bn_pollute(r);
  168|       |
  169|   206k|    return 1;
  170|   206k|}

BN_CTX_new_ex:
  119|  3.05k|{
  120|  3.05k|    BN_CTX *ret;
  121|       |
  122|  3.05k|    if ((ret = OPENSSL_zalloc(sizeof(*ret))) == NULL)
  ------------------
  |  |  104|  3.05k|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  3.05k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  3.05k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (122:9): [True: 0, False: 3.05k]
  ------------------
  123|      0|        return NULL;
  124|       |    /* Initialise the structure */
  125|  3.05k|    BN_POOL_init(&ret->pool);
  126|  3.05k|    BN_STACK_init(&ret->stack);
  127|  3.05k|    ret->libctx = ctx;
  128|  3.05k|    return ret;
  129|  3.05k|}
BN_CTX_new:
  133|  3.05k|{
  134|  3.05k|    return BN_CTX_new_ex(NULL);
  135|  3.05k|}
BN_CTX_free:
  155|  4.34k|{
  156|  4.34k|    if (ctx == NULL)
  ------------------
  |  Branch (156:9): [True: 1.28k, False: 3.05k]
  ------------------
  157|  1.28k|        return;
  158|  3.05k|#ifndef FIPS_MODULE
  159|  3.05k|    OSSL_TRACE_BEGIN(BN_CTX) {
  ------------------
  |  |  219|  3.05k|    do {                                        \
  |  |  220|  3.05k|        BIO *trc_out = NULL;                    \
  |  |  221|  3.05k|        if (0)
  |  |  ------------------
  |  |  |  Branch (221:13): [Folded - Ignored]
  |  |  ------------------
  ------------------
  160|      0|        BN_POOL_ITEM *pool = ctx->pool.head;
  161|      0|        BIO_printf(trc_out,
  162|      0|                   "BN_CTX_free(): stack-size=%d, pool-bignums=%d\n",
  163|      0|                   ctx->stack.size, ctx->pool.size);
  164|      0|        BIO_printf(trc_out, "  dmaxs: ");
  165|      0|        while (pool) {
  ------------------
  |  Branch (165:16): [True: 0, False: 0]
  ------------------
  166|      0|            unsigned loop = 0;
  167|      0|            while (loop < BN_CTX_POOL_SIZE)
  ------------------
  |  |   15|      0|#define BN_CTX_POOL_SIZE        16
  ------------------
  |  Branch (167:20): [True: 0, False: 0]
  ------------------
  168|      0|                BIO_printf(trc_out, "%02x ", pool->vals[loop++].dmax);
  169|      0|            pool = pool->next;
  170|      0|        }
  171|      0|        BIO_printf(trc_out, "\n");
  172|  3.05k|    } OSSL_TRACE_END(BN_CTX);
  ------------------
  |  |  224|  3.05k|    } while(0)
  |  |  ------------------
  |  |  |  Branch (224:13): [Folded - Ignored]
  |  |  ------------------
  ------------------
  173|  3.05k|#endif
  174|  3.05k|    BN_STACK_finish(&ctx->stack);
  175|  3.05k|    BN_POOL_finish(&ctx->pool);
  176|  3.05k|    OPENSSL_free(ctx);
  ------------------
  |  |  115|  3.05k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  3.05k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  3.05k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  177|  3.05k|}
BN_CTX_start:
  180|  1.29M|{
  181|  1.29M|    CTXDBG("ENTER BN_CTX_start()", ctx);
  ------------------
  |  |  110|  1.29M|    OSSL_TRACE_BEGIN(BN_CTX) {      \
  |  |  ------------------
  |  |  |  |  219|  1.29M|    do {                                        \
  |  |  |  |  220|  1.29M|        BIO *trc_out = NULL;                    \
  |  |  |  |  221|  1.29M|        if (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (221:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  111|      0|        ctxdbg(trc_out, str, ctx);  \
  |  |  112|  1.29M|    } OSSL_TRACE_END(BN_CTX)
  |  |  ------------------
  |  |  |  |  224|  1.29M|    } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (224:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  182|       |    /* If we're already overflowing ... */
  183|  1.29M|    if (ctx->err_stack || ctx->too_many)
  ------------------
  |  Branch (183:9): [True: 0, False: 1.29M]
  |  Branch (183:27): [True: 0, False: 1.29M]
  ------------------
  184|      0|        ctx->err_stack++;
  185|       |    /* (Try to) get a new frame pointer */
  186|  1.29M|    else if (!BN_STACK_push(&ctx->stack, ctx->used)) {
  ------------------
  |  Branch (186:14): [True: 0, False: 1.29M]
  ------------------
  187|      0|        ERR_raise(ERR_LIB_BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  188|      0|        ctx->err_stack++;
  189|      0|    }
  190|  1.29M|    CTXDBG("LEAVE BN_CTX_start()", ctx);
  ------------------
  |  |  110|  1.29M|    OSSL_TRACE_BEGIN(BN_CTX) {      \
  |  |  ------------------
  |  |  |  |  219|  1.29M|    do {                                        \
  |  |  |  |  220|  1.29M|        BIO *trc_out = NULL;                    \
  |  |  |  |  221|  1.29M|        if (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (221:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  111|      0|        ctxdbg(trc_out, str, ctx);  \
  |  |  112|  1.29M|    } OSSL_TRACE_END(BN_CTX)
  |  |  ------------------
  |  |  |  |  224|  1.29M|    } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (224:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  191|  1.29M|}
BN_CTX_end:
  194|  1.29M|{
  195|  1.29M|    if (ctx == NULL)
  ------------------
  |  Branch (195:9): [True: 0, False: 1.29M]
  ------------------
  196|      0|        return;
  197|  1.29M|    CTXDBG("ENTER BN_CTX_end()", ctx);
  ------------------
  |  |  110|  1.29M|    OSSL_TRACE_BEGIN(BN_CTX) {      \
  |  |  ------------------
  |  |  |  |  219|  1.29M|    do {                                        \
  |  |  |  |  220|  1.29M|        BIO *trc_out = NULL;                    \
  |  |  |  |  221|  1.29M|        if (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (221:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  111|      0|        ctxdbg(trc_out, str, ctx);  \
  |  |  112|  1.29M|    } OSSL_TRACE_END(BN_CTX)
  |  |  ------------------
  |  |  |  |  224|  1.29M|    } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (224:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  198|  1.29M|    if (ctx->err_stack)
  ------------------
  |  Branch (198:9): [True: 0, False: 1.29M]
  ------------------
  199|      0|        ctx->err_stack--;
  200|  1.29M|    else {
  201|  1.29M|        unsigned int fp = BN_STACK_pop(&ctx->stack);
  202|       |        /* Does this stack frame have anything to release? */
  203|  1.29M|        if (fp < ctx->used)
  ------------------
  |  Branch (203:13): [True: 1.10M, False: 196k]
  ------------------
  204|  1.10M|            BN_POOL_release(&ctx->pool, ctx->used - fp);
  205|  1.29M|        ctx->used = fp;
  206|       |        /* Unjam "too_many" in case "get" had failed */
  207|  1.29M|        ctx->too_many = 0;
  208|  1.29M|    }
  209|  1.29M|    CTXDBG("LEAVE BN_CTX_end()", ctx);
  ------------------
  |  |  110|  1.29M|    OSSL_TRACE_BEGIN(BN_CTX) {      \
  |  |  ------------------
  |  |  |  |  219|  1.29M|    do {                                        \
  |  |  |  |  220|  1.29M|        BIO *trc_out = NULL;                    \
  |  |  |  |  221|  1.29M|        if (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (221:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  111|      0|        ctxdbg(trc_out, str, ctx);  \
  |  |  112|  1.29M|    } OSSL_TRACE_END(BN_CTX)
  |  |  ------------------
  |  |  |  |  224|  1.29M|    } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (224:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  210|  1.29M|}
BN_CTX_get:
  213|  1.93M|{
  214|  1.93M|    BIGNUM *ret;
  215|       |
  216|  1.93M|    CTXDBG("ENTER BN_CTX_get()", ctx);
  ------------------
  |  |  110|  1.93M|    OSSL_TRACE_BEGIN(BN_CTX) {      \
  |  |  ------------------
  |  |  |  |  219|  1.93M|    do {                                        \
  |  |  |  |  220|  1.93M|        BIO *trc_out = NULL;                    \
  |  |  |  |  221|  1.93M|        if (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (221:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  111|      0|        ctxdbg(trc_out, str, ctx);  \
  |  |  112|  1.93M|    } OSSL_TRACE_END(BN_CTX)
  |  |  ------------------
  |  |  |  |  224|  1.93M|    } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (224:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  217|  1.93M|    if (ctx->err_stack || ctx->too_many)
  ------------------
  |  Branch (217:9): [True: 0, False: 1.93M]
  |  Branch (217:27): [True: 0, False: 1.93M]
  ------------------
  218|      0|        return NULL;
  219|  1.93M|    if ((ret = BN_POOL_get(&ctx->pool, ctx->flags)) == NULL) {
  ------------------
  |  Branch (219:9): [True: 0, False: 1.93M]
  ------------------
  220|       |        /*
  221|       |         * Setting too_many prevents repeated "get" attempts from cluttering
  222|       |         * the error stack.
  223|       |         */
  224|      0|        ctx->too_many = 1;
  225|      0|        ERR_raise(ERR_LIB_BN, BN_R_TOO_MANY_TEMPORARY_VARIABLES);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  226|      0|        return NULL;
  227|      0|    }
  228|       |    /* OK, make sure the returned bignum is "zero" */
  229|  1.93M|    BN_zero(ret);
  ------------------
  |  |  202|  1.93M|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  230|       |    /* clear BN_FLG_CONSTTIME if leaked from previous frames */
  231|  1.93M|    ret->flags &= (~BN_FLG_CONSTTIME);
  ------------------
  |  |   67|  1.93M|# define BN_FLG_CONSTTIME        0x04
  ------------------
  232|  1.93M|    ctx->used++;
  233|  1.93M|    CTXDBG("LEAVE BN_CTX_get()", ctx);
  ------------------
  |  |  110|  1.93M|    OSSL_TRACE_BEGIN(BN_CTX) {      \
  |  |  ------------------
  |  |  |  |  219|  1.93M|    do {                                        \
  |  |  |  |  220|  1.93M|        BIO *trc_out = NULL;                    \
  |  |  |  |  221|  1.93M|        if (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (221:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  111|      0|        ctxdbg(trc_out, str, ctx);  \
  |  |  112|  1.93M|    } OSSL_TRACE_END(BN_CTX)
  |  |  ------------------
  |  |  |  |  224|  1.93M|    } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (224:13): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  234|  1.93M|    return ret;
  235|  1.93M|}
bn_ctx.c:BN_STACK_init:
  249|  3.05k|{
  250|  3.05k|    st->indexes = NULL;
  251|  3.05k|    st->depth = st->size = 0;
  252|  3.05k|}
bn_ctx.c:BN_STACK_finish:
  255|  3.05k|{
  256|  3.05k|    OPENSSL_free(st->indexes);
  ------------------
  |  |  115|  3.05k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  3.05k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  3.05k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  257|  3.05k|    st->indexes = NULL;
  258|  3.05k|}
bn_ctx.c:BN_STACK_push:
  262|  1.29M|{
  263|  1.29M|    if (st->depth == st->size) {
  ------------------
  |  Branch (263:9): [True: 2.83k, False: 1.29M]
  ------------------
  264|       |        /* Need to expand */
  265|  2.83k|        unsigned int newsize =
  266|  2.83k|            st->size ? (st->size * 3 / 2) : BN_CTX_START_FRAMES;
  ------------------
  |  |   17|  2.83k|#define BN_CTX_START_FRAMES     32
  ------------------
  |  Branch (266:13): [True: 0, False: 2.83k]
  ------------------
  267|  2.83k|        unsigned int *newitems;
  268|       |
  269|  2.83k|        if ((newitems = OPENSSL_malloc(sizeof(*newitems) * newsize)) == NULL)
  ------------------
  |  |  102|  2.83k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  2.83k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  2.83k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (269:13): [True: 0, False: 2.83k]
  ------------------
  270|      0|            return 0;
  271|  2.83k|        if (st->depth)
  ------------------
  |  Branch (271:13): [True: 0, False: 2.83k]
  ------------------
  272|      0|            memcpy(newitems, st->indexes, sizeof(*newitems) * st->depth);
  273|  2.83k|        OPENSSL_free(st->indexes);
  ------------------
  |  |  115|  2.83k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  2.83k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  2.83k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  274|  2.83k|        st->indexes = newitems;
  275|  2.83k|        st->size = newsize;
  276|  2.83k|    }
  277|  1.29M|    st->indexes[(st->depth)++] = idx;
  278|  1.29M|    return 1;
  279|  1.29M|}
bn_ctx.c:BN_STACK_pop:
  282|  1.29M|{
  283|  1.29M|    return st->indexes[--(st->depth)];
  284|  1.29M|}
bn_ctx.c:BN_POOL_init:
  291|  3.05k|{
  292|  3.05k|    p->head = p->current = p->tail = NULL;
  293|  3.05k|    p->used = p->size = 0;
  294|  3.05k|}
bn_ctx.c:BN_POOL_finish:
  297|  3.05k|{
  298|  3.05k|    unsigned int loop;
  299|  3.05k|    BIGNUM *bn;
  300|       |
  301|  6.03k|    while (p->head) {
  ------------------
  |  Branch (301:12): [True: 2.98k, False: 3.05k]
  ------------------
  302|  50.6k|        for (loop = 0, bn = p->head->vals; loop++ < BN_CTX_POOL_SIZE; bn++)
  ------------------
  |  |   15|  50.6k|#define BN_CTX_POOL_SIZE        16
  ------------------
  |  Branch (302:44): [True: 47.6k, False: 2.98k]
  ------------------
  303|  47.6k|            if (bn->d)
  ------------------
  |  Branch (303:17): [True: 32.1k, False: 15.5k]
  ------------------
  304|  32.1k|                BN_clear_free(bn);
  305|  2.98k|        p->current = p->head->next;
  306|  2.98k|        OPENSSL_free(p->head);
  ------------------
  |  |  115|  2.98k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  2.98k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  2.98k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  307|  2.98k|        p->head = p->current;
  308|  2.98k|    }
  309|  3.05k|}
bn_ctx.c:BN_POOL_get:
  313|  1.93M|{
  314|  1.93M|    BIGNUM *bn;
  315|  1.93M|    unsigned int loop;
  316|       |
  317|       |    /* Full; allocate a new pool item and link it in. */
  318|  1.93M|    if (p->used == p->size) {
  ------------------
  |  Branch (318:9): [True: 2.98k, False: 1.93M]
  ------------------
  319|  2.98k|        BN_POOL_ITEM *item;
  320|       |
  321|  2.98k|        if ((item = OPENSSL_malloc(sizeof(*item))) == NULL)
  ------------------
  |  |  102|  2.98k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  2.98k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  2.98k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (321:13): [True: 0, False: 2.98k]
  ------------------
  322|      0|            return NULL;
  323|  50.6k|        for (loop = 0, bn = item->vals; loop++ < BN_CTX_POOL_SIZE; bn++) {
  ------------------
  |  |   15|  50.6k|#define BN_CTX_POOL_SIZE        16
  ------------------
  |  Branch (323:41): [True: 47.6k, False: 2.98k]
  ------------------
  324|  47.6k|            bn_init(bn);
  325|  47.6k|            if ((flag & BN_FLG_SECURE) != 0)
  ------------------
  |  |   68|  47.6k|# define BN_FLG_SECURE           0x08
  ------------------
  |  Branch (325:17): [True: 0, False: 47.6k]
  ------------------
  326|      0|                BN_set_flags(bn, BN_FLG_SECURE);
  ------------------
  |  |   68|      0|# define BN_FLG_SECURE           0x08
  ------------------
  327|  47.6k|        }
  328|  2.98k|        item->prev = p->tail;
  329|  2.98k|        item->next = NULL;
  330|       |
  331|  2.98k|        if (p->head == NULL)
  ------------------
  |  Branch (331:13): [True: 2.83k, False: 147]
  ------------------
  332|  2.83k|            p->head = p->current = p->tail = item;
  333|    147|        else {
  334|    147|            p->tail->next = item;
  335|    147|            p->tail = item;
  336|    147|            p->current = item;
  337|    147|        }
  338|  2.98k|        p->size += BN_CTX_POOL_SIZE;
  ------------------
  |  |   15|  2.98k|#define BN_CTX_POOL_SIZE        16
  ------------------
  339|  2.98k|        p->used++;
  340|       |        /* Return the first bignum from the new pool */
  341|  2.98k|        return item->vals;
  342|  2.98k|    }
  343|       |
  344|  1.93M|    if (!p->used)
  ------------------
  |  Branch (344:9): [True: 2.83k, False: 1.93M]
  ------------------
  345|  2.83k|        p->current = p->head;
  346|  1.93M|    else if ((p->used % BN_CTX_POOL_SIZE) == 0)
  ------------------
  |  |   15|  1.93M|#define BN_CTX_POOL_SIZE        16
  ------------------
  |  Branch (346:14): [True: 815, False: 1.92M]
  ------------------
  347|    815|        p->current = p->current->next;
  348|  1.93M|    return p->current->vals + ((p->used++) % BN_CTX_POOL_SIZE);
  ------------------
  |  |   15|  1.93M|#define BN_CTX_POOL_SIZE        16
  ------------------
  349|  1.93M|}
bn_ctx.c:BN_POOL_release:
  352|  1.10M|{
  353|  1.10M|    unsigned int offset = (p->used - 1) % BN_CTX_POOL_SIZE;
  ------------------
  |  |   15|  1.10M|#define BN_CTX_POOL_SIZE        16
  ------------------
  354|       |
  355|  1.10M|    p->used -= num;
  356|  3.03M|    while (num--) {
  ------------------
  |  Branch (356:12): [True: 1.93M, False: 1.10M]
  ------------------
  357|  1.93M|        bn_check_top(p->current->vals + offset);
  358|  1.93M|        if (offset == 0) {
  ------------------
  |  Branch (358:13): [True: 6.62k, False: 1.92M]
  ------------------
  359|  6.62k|            offset = BN_CTX_POOL_SIZE - 1;
  ------------------
  |  |   15|  6.62k|#define BN_CTX_POOL_SIZE        16
  ------------------
  360|  6.62k|            p->current = p->current->prev;
  361|  6.62k|        } else
  362|  1.92M|            offset--;
  363|  1.93M|    }
  364|  1.10M|}

BN_div:
  211|   199k|{
  212|   199k|    int ret;
  213|       |
  214|   199k|    if (BN_is_zero(divisor)) {
  ------------------
  |  Branch (214:9): [True: 0, False: 199k]
  ------------------
  215|      0|        ERR_raise(ERR_LIB_BN, BN_R_DIV_BY_ZERO);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  216|      0|        return 0;
  217|      0|    }
  218|       |
  219|       |    /*
  220|       |     * Invalid zero-padding would have particularly bad consequences so don't
  221|       |     * just rely on bn_check_top() here (bn_check_top() works only for
  222|       |     * BN_DEBUG builds)
  223|       |     */
  224|   199k|    if (divisor->d[divisor->top - 1] == 0) {
  ------------------
  |  Branch (224:9): [True: 0, False: 199k]
  ------------------
  225|      0|        ERR_raise(ERR_LIB_BN, BN_R_NOT_INITIALIZED);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  226|      0|        return 0;
  227|      0|    }
  228|       |
  229|   199k|    ret = bn_div_fixed_top(dv, rm, num, divisor, ctx);
  230|       |
  231|   199k|    if (ret) {
  ------------------
  |  Branch (231:9): [True: 199k, False: 0]
  ------------------
  232|   199k|        if (dv != NULL)
  ------------------
  |  Branch (232:13): [True: 2.79k, False: 196k]
  ------------------
  233|  2.79k|            bn_correct_top(dv);
  234|   199k|        if (rm != NULL)
  ------------------
  |  Branch (234:13): [True: 196k, False: 2.79k]
  ------------------
  235|   196k|            bn_correct_top(rm);
  236|   199k|    }
  237|       |
  238|   199k|    return ret;
  239|   199k|}
bn_div_fixed_top:
  266|   199k|{
  267|   199k|    int norm_shift, i, j, loop;
  268|   199k|    BIGNUM *tmp, *snum, *sdiv, *res;
  269|   199k|    BN_ULONG *resp, *wnum, *wnumtop;
  ------------------
  |  |   37|   199k|#  define BN_ULONG        unsigned long
  ------------------
  270|   199k|    BN_ULONG d0, d1;
  ------------------
  |  |   37|   199k|#  define BN_ULONG        unsigned long
  ------------------
  271|   199k|    int num_n, div_n, num_neg;
  272|       |
  273|   199k|    assert(divisor->top > 0 && divisor->d[divisor->top - 1] != 0);
  274|       |
  275|   199k|    bn_check_top(num);
  276|   199k|    bn_check_top(divisor);
  277|   199k|    bn_check_top(dv);
  278|   199k|    bn_check_top(rm);
  279|       |
  280|   199k|    BN_CTX_start(ctx);
  281|   199k|    res = (dv == NULL) ? BN_CTX_get(ctx) : dv;
  ------------------
  |  Branch (281:11): [True: 196k, False: 2.79k]
  ------------------
  282|   199k|    tmp = BN_CTX_get(ctx);
  283|   199k|    snum = BN_CTX_get(ctx);
  284|   199k|    sdiv = BN_CTX_get(ctx);
  285|   199k|    if (sdiv == NULL)
  ------------------
  |  Branch (285:9): [True: 0, False: 199k]
  ------------------
  286|      0|        goto err;
  287|       |
  288|       |    /* First we normalise the numbers */
  289|   199k|    if (!BN_copy(sdiv, divisor))
  ------------------
  |  Branch (289:9): [True: 0, False: 199k]
  ------------------
  290|      0|        goto err;
  291|   199k|    norm_shift = bn_left_align(sdiv);
  292|   199k|    sdiv->neg = 0;
  293|       |    /*
  294|       |     * Note that bn_lshift_fixed_top's output is always one limb longer
  295|       |     * than input, even when norm_shift is zero. This means that amount of
  296|       |     * inner loop iterations is invariant of dividend value, and that one
  297|       |     * doesn't need to compare dividend and divisor if they were originally
  298|       |     * of the same bit length.
  299|       |     */
  300|   199k|    if (!(bn_lshift_fixed_top(snum, num, norm_shift)))
  ------------------
  |  Branch (300:9): [True: 0, False: 199k]
  ------------------
  301|      0|        goto err;
  302|       |
  303|   199k|    div_n = sdiv->top;
  304|   199k|    num_n = snum->top;
  305|       |
  306|   199k|    if (num_n <= div_n) {
  ------------------
  |  Branch (306:9): [True: 18.6k, False: 181k]
  ------------------
  307|       |        /* caller didn't pad dividend -> no constant-time guarantee... */
  308|  18.6k|        if (bn_wexpand(snum, div_n + 1) == NULL)
  ------------------
  |  Branch (308:13): [True: 0, False: 18.6k]
  ------------------
  309|      0|            goto err;
  310|  18.6k|        memset(&(snum->d[num_n]), 0, (div_n - num_n + 1) * sizeof(BN_ULONG));
  311|  18.6k|        snum->top = num_n = div_n + 1;
  312|  18.6k|    }
  313|       |
  314|   199k|    loop = num_n - div_n;
  315|       |    /*
  316|       |     * Lets setup a 'window' into snum This is the part that corresponds to
  317|       |     * the current 'area' being divided
  318|       |     */
  319|   199k|    wnum = &(snum->d[loop]);
  320|   199k|    wnumtop = &(snum->d[num_n - 1]);
  321|       |
  322|       |    /* Get the top 2 words of sdiv */
  323|   199k|    d0 = sdiv->d[div_n - 1];
  324|   199k|    d1 = (div_n == 1) ? 0 : sdiv->d[div_n - 2];
  ------------------
  |  Branch (324:10): [True: 144k, False: 54.8k]
  ------------------
  325|       |
  326|       |    /* Setup quotient */
  327|   199k|    if (!bn_wexpand(res, loop))
  ------------------
  |  Branch (327:9): [True: 0, False: 199k]
  ------------------
  328|      0|        goto err;
  329|   199k|    num_neg = num->neg;
  330|   199k|    res->neg = (num_neg ^ divisor->neg);
  331|   199k|    res->top = loop;
  332|   199k|    res->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   199k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  333|   199k|    resp = &(res->d[loop]);
  334|       |
  335|       |    /* space for temp */
  336|   199k|    if (!bn_wexpand(tmp, (div_n + 1)))
  ------------------
  |  Branch (336:9): [True: 0, False: 199k]
  ------------------
  337|      0|        goto err;
  338|       |
  339|  1.23M|    for (i = 0; i < loop; i++, wnumtop--) {
  ------------------
  |  Branch (339:17): [True: 1.03M, False: 199k]
  ------------------
  340|  1.03M|        BN_ULONG q, l0;
  ------------------
  |  |   37|  1.03M|#  define BN_ULONG        unsigned long
  ------------------
  341|       |        /*
  342|       |         * the first part of the loop uses the top two words of snum and sdiv
  343|       |         * to calculate a BN_ULONG q such that | wnum - sdiv * q | < sdiv
  344|       |         */
  345|       |# if defined(BN_DIV3W)
  346|       |        q = bn_div_3_words(wnumtop, d1, d0);
  347|       |# else
  348|  1.03M|        BN_ULONG n0, n1, rem = 0;
  ------------------
  |  |   37|  1.03M|#  define BN_ULONG        unsigned long
  ------------------
  349|       |
  350|  1.03M|        n0 = wnumtop[0];
  351|  1.03M|        n1 = wnumtop[-1];
  352|  1.03M|        if (n0 == d0)
  ------------------
  |  Branch (352:13): [True: 28.7k, False: 1.00M]
  ------------------
  353|  28.7k|            q = BN_MASK2;
  ------------------
  |  |   94|  28.7k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  354|  1.00M|        else {                  /* n0 < d0 */
  355|  1.00M|            BN_ULONG n2 = (wnumtop == wnum) ? 0 : wnumtop[-2];
  ------------------
  |  |   37|  1.00M|#  define BN_ULONG        unsigned long
  ------------------
  |  Branch (355:27): [True: 207k, False: 799k]
  ------------------
  356|       |#  ifdef BN_LLONG
  357|       |            BN_ULLONG t2;
  358|       |
  359|       |#   if defined(BN_LLONG) && defined(BN_DIV2W) && !defined(bn_div_words)
  360|       |            q = (BN_ULONG)(((((BN_ULLONG) n0) << BN_BITS2) | n1) / d0);
  361|       |#   else
  362|       |            q = bn_div_words(n0, n1, d0);
  363|       |#   endif
  364|       |
  365|       |#   ifndef REMAINDER_IS_ALREADY_CALCULATED
  366|       |            /*
  367|       |             * rem doesn't have to be BN_ULLONG. The least we
  368|       |             * know it's less that d0, isn't it?
  369|       |             */
  370|       |            rem = (n1 - q * d0) & BN_MASK2;
  371|       |#   endif
  372|       |            t2 = (BN_ULLONG) d1 *q;
  373|       |
  374|       |            for (;;) {
  375|       |                if (t2 <= ((((BN_ULLONG) rem) << BN_BITS2) | n2))
  376|       |                    break;
  377|       |                q--;
  378|       |                rem += d0;
  379|       |                if (rem < d0)
  380|       |                    break;      /* don't let rem overflow */
  381|       |                t2 -= d1;
  382|       |            }
  383|       |#  else                         /* !BN_LLONG */
  384|  1.00M|            BN_ULONG t2l, t2h;
  ------------------
  |  |   37|  1.00M|#  define BN_ULONG        unsigned long
  ------------------
  385|       |
  386|  1.00M|            q = bn_div_words(n0, n1, d0);
  387|  1.00M|#   ifndef REMAINDER_IS_ALREADY_CALCULATED
  388|  1.00M|            rem = (n1 - q * d0) & BN_MASK2;
  ------------------
  |  |   94|  1.00M|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  389|  1.00M|#   endif
  390|       |
  391|       |#   if defined(BN_UMULT_LOHI)
  392|       |            BN_UMULT_LOHI(t2l, t2h, d1, q);
  393|       |#   elif defined(BN_UMULT_HIGH)
  394|       |            t2l = d1 * q;
  395|       |            t2h = BN_UMULT_HIGH(d1, q);
  396|       |#   else
  397|  1.00M|            {
  398|  1.00M|                BN_ULONG ql, qh;
  ------------------
  |  |   37|  1.00M|#  define BN_ULONG        unsigned long
  ------------------
  399|  1.00M|                t2l = LBITS(d1);
  ------------------
  |  |  566|  1.00M|#  define LBITS(a)        ((a)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   95|  1.00M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  400|  1.00M|                t2h = HBITS(d1);
  ------------------
  |  |  567|  1.00M|#  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   93|  1.00M|#  define BN_BITS4        32
  |  |  ------------------
  |  |               #  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   95|  1.00M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  401|  1.00M|                ql = LBITS(q);
  ------------------
  |  |  566|  1.00M|#  define LBITS(a)        ((a)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   95|  1.00M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  402|  1.00M|                qh = HBITS(q);
  ------------------
  |  |  567|  1.00M|#  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   93|  1.00M|#  define BN_BITS4        32
  |  |  ------------------
  |  |               #  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  ------------------
  |  |  |  |   95|  1.00M|#  define BN_MASK2l       (0xffffffffL)
  |  |  ------------------
  ------------------
  403|  1.00M|                mul64(t2l, t2h, ql, qh); /* t2=(BN_ULLONG)d1*q; */
  ------------------
  |  |  575|  1.00M|        { \
  |  |  576|  1.00M|        BN_ULONG m,m1,lt,ht; \
  |  |  ------------------
  |  |  |  |   37|  1.00M|#  define BN_ULONG        unsigned long
  |  |  ------------------
  |  |  577|  1.00M| \
  |  |  578|  1.00M|        lt=l; \
  |  |  579|  1.00M|        ht=h; \
  |  |  580|  1.00M|        m =(bh)*(lt); \
  |  |  581|  1.00M|        lt=(bl)*(lt); \
  |  |  582|  1.00M|        m1=(bl)*(ht); \
  |  |  583|  1.00M|        ht =(bh)*(ht); \
  |  |  584|  1.00M|        m=(m+m1)&BN_MASK2; ht += L2HBITS((BN_ULONG)(m < m1)); \
  |  |  ------------------
  |  |  |  |   94|  1.00M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  ------------------
  |  |                       m=(m+m1)&BN_MASK2; ht += L2HBITS((BN_ULONG)(m < m1)); \
  |  |  ------------------
  |  |  |  |  568|  1.00M|#  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   93|  1.00M|#  define BN_BITS4        32
  |  |  |  |  ------------------
  |  |  |  |               #  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   94|  1.00M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  585|  1.00M|        ht+=HBITS(m); \
  |  |  ------------------
  |  |  |  |  567|  1.00M|#  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  |  |  ------------------
  |  |  |  |  |  |   93|  1.00M|#  define BN_BITS4        32
  |  |  |  |  ------------------
  |  |  |  |               #  define HBITS(a)        (((a)>>BN_BITS4)&BN_MASK2l)
  |  |  |  |  ------------------
  |  |  |  |  |  |   95|  1.00M|#  define BN_MASK2l       (0xffffffffL)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  586|  1.00M|        m1=L2HBITS(m); \
  |  |  ------------------
  |  |  |  |  568|  1.00M|#  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   93|  1.00M|#  define BN_BITS4        32
  |  |  |  |  ------------------
  |  |  |  |               #  define L2HBITS(a)      (((a)<<BN_BITS4)&BN_MASK2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   94|  1.00M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  587|  1.00M|        lt=(lt+m1)&BN_MASK2; ht += (lt < m1); \
  |  |  ------------------
  |  |  |  |   94|  1.00M|#  define BN_MASK2        (0xffffffffffffffffL)
  |  |  ------------------
  |  |  588|  1.00M|        (l)=lt; \
  |  |  589|  1.00M|        (h)=ht; \
  |  |  590|  1.00M|        }
  ------------------
  404|  1.00M|            }
  405|  1.00M|#   endif
  406|       |
  407|  1.05M|            for (;;) {
  408|  1.05M|                if ((t2h < rem) || ((t2h == rem) && (t2l <= n2)))
  ------------------
  |  Branch (408:21): [True: 726k, False: 330k]
  |  Branch (408:37): [True: 109k, False: 221k]
  |  Branch (408:53): [True: 107k, False: 1.49k]
  ------------------
  409|   833k|                    break;
  410|   222k|                q--;
  411|   222k|                rem += d0;
  412|   222k|                if (rem < d0)
  ------------------
  |  Branch (412:21): [True: 172k, False: 49.7k]
  ------------------
  413|   172k|                    break;      /* don't let rem overflow */
  414|  49.7k|                if (t2l < d1)
  ------------------
  |  Branch (414:21): [True: 36.4k, False: 13.3k]
  ------------------
  415|  36.4k|                    t2h--;
  416|  49.7k|                t2l -= d1;
  417|  49.7k|            }
  418|  1.00M|#  endif                        /* !BN_LLONG */
  419|  1.00M|        }
  420|  1.03M|# endif                         /* !BN_DIV3W */
  421|       |
  422|  1.03M|        l0 = bn_mul_words(tmp->d, sdiv->d, div_n, q);
  423|  1.03M|        tmp->d[div_n] = l0;
  424|  1.03M|        wnum--;
  425|       |        /*
  426|       |         * ignore top values of the bignums just sub the two BN_ULONG arrays
  427|       |         * with bn_sub_words
  428|       |         */
  429|  1.03M|        l0 = bn_sub_words(wnum, wnum, tmp->d, div_n + 1);
  430|  1.03M|        q -= l0;
  431|       |        /*
  432|       |         * Note: As we have considered only the leading two BN_ULONGs in
  433|       |         * the calculation of q, sdiv * q might be greater than wnum (but
  434|       |         * then (q-1) * sdiv is less or equal than wnum)
  435|       |         */
  436|  77.4M|        for (l0 = 0 - l0, j = 0; j < div_n; j++)
  ------------------
  |  Branch (436:34): [True: 76.4M, False: 1.03M]
  ------------------
  437|  76.4M|            tmp->d[j] = sdiv->d[j] & l0;
  438|  1.03M|        l0 = bn_add_words(wnum, wnum, tmp->d, div_n);
  439|  1.03M|        (*wnumtop) += l0;
  440|  1.03M|        assert((*wnumtop) == 0);
  441|       |
  442|       |        /* store part of the result */
  443|  1.03M|        *--resp = q;
  444|  1.03M|    }
  445|       |    /* snum holds remainder, it's as wide as divisor */
  446|   199k|    snum->neg = num_neg;
  447|   199k|    snum->top = div_n;
  448|   199k|    snum->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   199k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  449|       |
  450|   199k|    if (rm != NULL && bn_rshift_fixed_top(rm, snum, norm_shift) == 0)
  ------------------
  |  Branch (450:9): [True: 196k, False: 2.79k]
  |  Branch (450:23): [True: 0, False: 196k]
  ------------------
  451|      0|        goto err;
  452|       |
  453|   199k|    BN_CTX_end(ctx);
  454|   199k|    return 1;
  455|      0| err:
  456|      0|    bn_check_top(rm);
  457|      0|    BN_CTX_end(ctx);
  458|      0|    return 0;
  459|   199k|}
bn_div.c:bn_left_align:
  142|   199k|{
  143|   199k|    BN_ULONG *d = num->d, n, m, rmask;
  ------------------
  |  |   37|   199k|#  define BN_ULONG        unsigned long
  ------------------
  144|   199k|    int top = num->top;
  145|   199k|    int rshift = BN_num_bits_word(d[top - 1]), lshift, i;
  146|       |
  147|   199k|    lshift = BN_BITS2 - rshift;
  ------------------
  |  |   54|   199k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   199k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  148|   199k|    rshift %= BN_BITS2;            /* say no to undefined behaviour */
  ------------------
  |  |   54|   199k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   199k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  149|   199k|    rmask = (BN_ULONG)0 - rshift;  /* rmask = 0 - (rshift != 0) */
  150|   199k|    rmask |= rmask >> 8;
  151|       |
  152|  2.17M|    for (i = 0, m = 0; i < top; i++) {
  ------------------
  |  Branch (152:24): [True: 1.97M, False: 199k]
  ------------------
  153|  1.97M|        n = d[i];
  154|  1.97M|        d[i] = ((n << lshift) | m) & BN_MASK2;
  ------------------
  |  |   94|  1.97M|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  155|  1.97M|        m = (n >> rshift) & rmask;
  156|  1.97M|    }
  157|       |
  158|   199k|    return lshift;
  159|   199k|}

ossl_err_load_BN_strings:
   50|      2|{
   51|      2|#ifndef OPENSSL_NO_ERR
   52|      2|    if (ERR_reason_error_string(BN_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (52:9): [True: 2, False: 0]
  ------------------
   53|      2|        ERR_load_strings_const(BN_str_reasons);
   54|      2|#endif
   55|      2|    return 1;
   56|      2|}

BN_mod_exp:
   99|  3.02k|{
  100|  3.02k|    int ret;
  101|       |
  102|  3.02k|    bn_check_top(a);
  103|  3.02k|    bn_check_top(p);
  104|  3.02k|    bn_check_top(m);
  105|       |
  106|       |    /*-
  107|       |     * For even modulus  m = 2^k*m_odd, it might make sense to compute
  108|       |     * a^p mod m_odd  and  a^p mod 2^k  separately (with Montgomery
  109|       |     * exponentiation for the odd part), using appropriate exponent
  110|       |     * reductions, and combine the results using the CRT.
  111|       |     *
  112|       |     * For now, we use Montgomery only if the modulus is odd; otherwise,
  113|       |     * exponentiation using the reciprocal-based quick remaindering
  114|       |     * algorithm is used.
  115|       |     *
  116|       |     * (Timing obtained with expspeed.c [computations  a^p mod m
  117|       |     * where  a, p, m  are of the same length: 256, 512, 1024, 2048,
  118|       |     * 4096, 8192 bits], compared to the running time of the
  119|       |     * standard algorithm:
  120|       |     *
  121|       |     *   BN_mod_exp_mont   33 .. 40 %  [AMD K6-2, Linux, debug configuration]
  122|       |     *                     55 .. 77 %  [UltraSparc processor, but
  123|       |     *                                  debug-solaris-sparcv8-gcc conf.]
  124|       |     *
  125|       |     *   BN_mod_exp_recp   50 .. 70 %  [AMD K6-2, Linux, debug configuration]
  126|       |     *                     62 .. 118 % [UltraSparc, debug-solaris-sparcv8-gcc]
  127|       |     *
  128|       |     * On the Sparc, BN_mod_exp_recp was faster than BN_mod_exp_mont
  129|       |     * at 2048 and more bits, but at 512 and 1024 bits, it was
  130|       |     * slower even than the standard algorithm!
  131|       |     *
  132|       |     * "Real" timings [linux-elf, solaris-sparcv9-gcc configurations]
  133|       |     * should be obtained when the new Montgomery reduction code
  134|       |     * has been integrated into OpenSSL.)
  135|       |     */
  136|       |
  137|  3.02k|#define MONT_MUL_MOD
  138|  3.02k|#define MONT_EXP_WORD
  139|  3.02k|#define RECP_MUL_MOD
  140|       |
  141|  3.02k|#ifdef MONT_MUL_MOD
  142|  3.02k|    if (BN_is_odd(m)) {
  ------------------
  |  Branch (142:9): [True: 1.43k, False: 1.58k]
  ------------------
  143|  1.43k|# ifdef MONT_EXP_WORD
  144|  1.43k|        if (a->top == 1 && !a->neg
  ------------------
  |  Branch (144:13): [True: 623, False: 816]
  |  Branch (144:28): [True: 421, False: 202]
  ------------------
  145|  1.43k|            && (BN_get_flags(p, BN_FLG_CONSTTIME) == 0)
  ------------------
  |  |   67|    421|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (145:16): [True: 421, False: 0]
  ------------------
  146|  1.43k|            && (BN_get_flags(a, BN_FLG_CONSTTIME) == 0)
  ------------------
  |  |   67|    421|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (146:16): [True: 421, False: 0]
  ------------------
  147|  1.43k|            && (BN_get_flags(m, BN_FLG_CONSTTIME) == 0)) {
  ------------------
  |  |   67|    421|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (147:16): [True: 421, False: 0]
  ------------------
  148|    421|            BN_ULONG A = a->d[0];
  ------------------
  |  |   37|    421|#  define BN_ULONG        unsigned long
  ------------------
  149|    421|            ret = BN_mod_exp_mont_word(r, A, p, m, ctx, NULL);
  150|    421|        } else
  151|  1.01k|# endif
  152|  1.01k|            ret = BN_mod_exp_mont(r, a, p, m, ctx, NULL);
  153|  1.43k|    } else
  154|  1.58k|#endif
  155|  1.58k|#ifdef RECP_MUL_MOD
  156|  1.58k|    {
  157|  1.58k|        ret = BN_mod_exp_recp(r, a, p, m, ctx);
  158|  1.58k|    }
  159|       |#else
  160|       |    {
  161|       |        ret = BN_mod_exp_simple(r, a, p, m, ctx);
  162|       |    }
  163|       |#endif
  164|       |
  165|  3.02k|    bn_check_top(r);
  166|  3.02k|    return ret;
  167|  3.02k|}
BN_mod_exp_recp:
  171|  1.58k|{
  172|  1.58k|    int i, j, bits, ret = 0, wstart, wend, window;
  173|  1.58k|    int start = 1;
  174|  1.58k|    BIGNUM *aa;
  175|       |    /* Table of variables obtained from 'ctx' */
  176|  1.58k|    BIGNUM *val[TABLE_SIZE];
  177|  1.58k|    BN_RECP_CTX recp;
  178|       |
  179|  1.58k|    if (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   67|  1.58k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (179:9): [True: 0, False: 1.58k]
  ------------------
  180|  1.58k|            || BN_get_flags(a, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   67|  1.58k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (180:16): [True: 0, False: 1.58k]
  ------------------
  181|  1.58k|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0) {
  ------------------
  |  |   67|  1.58k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (181:16): [True: 0, False: 1.58k]
  ------------------
  182|       |        /* BN_FLG_CONSTTIME only supported by BN_mod_exp_mont() */
  183|      0|        ERR_raise(ERR_LIB_BN, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  184|      0|        return 0;
  185|      0|    }
  186|       |
  187|  1.58k|    bits = BN_num_bits(p);
  188|  1.58k|    if (bits == 0) {
  ------------------
  |  Branch (188:9): [True: 57, False: 1.52k]
  ------------------
  189|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
  190|     57|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (190:13): [True: 0, False: 57]
  ------------------
  191|      0|            ret = 1;
  192|      0|            BN_zero(r);
  ------------------
  |  |  202|      0|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  193|     57|        } else {
  194|     57|            ret = BN_one(r);
  ------------------
  |  |  197|     57|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  195|     57|        }
  196|     57|        return ret;
  197|     57|    }
  198|       |
  199|  1.52k|    BN_RECP_CTX_init(&recp);
  200|       |
  201|  1.52k|    BN_CTX_start(ctx);
  202|  1.52k|    aa = BN_CTX_get(ctx);
  203|  1.52k|    val[0] = BN_CTX_get(ctx);
  204|  1.52k|    if (val[0] == NULL)
  ------------------
  |  Branch (204:9): [True: 0, False: 1.52k]
  ------------------
  205|      0|        goto err;
  206|       |
  207|  1.52k|    if (m->neg) {
  ------------------
  |  Branch (207:9): [True: 591, False: 935]
  ------------------
  208|       |        /* ignore sign of 'm' */
  209|    591|        if (!BN_copy(aa, m))
  ------------------
  |  Branch (209:13): [True: 0, False: 591]
  ------------------
  210|      0|            goto err;
  211|    591|        aa->neg = 0;
  212|    591|        if (BN_RECP_CTX_set(&recp, aa, ctx) <= 0)
  ------------------
  |  Branch (212:13): [True: 0, False: 591]
  ------------------
  213|      0|            goto err;
  214|    935|    } else {
  215|    935|        if (BN_RECP_CTX_set(&recp, m, ctx) <= 0)
  ------------------
  |  Branch (215:13): [True: 0, False: 935]
  ------------------
  216|      0|            goto err;
  217|    935|    }
  218|       |
  219|  1.52k|    if (!BN_nnmod(val[0], a, m, ctx))
  ------------------
  |  Branch (219:9): [True: 0, False: 1.52k]
  ------------------
  220|      0|        goto err;               /* 1 */
  221|  1.52k|    if (BN_is_zero(val[0])) {
  ------------------
  |  Branch (221:9): [True: 31, False: 1.49k]
  ------------------
  222|     31|        BN_zero(r);
  ------------------
  |  |  202|     31|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  223|     31|        ret = 1;
  224|     31|        goto err;
  225|     31|    }
  226|       |
  227|  1.49k|    window = BN_window_bits_for_exponent_size(bits);
  ------------------
  |  |  322|  1.49k|                ((b) > 671 ? 6 : \
  |  |  ------------------
  |  |  |  Branch (322:18): [True: 20, False: 1.47k]
  |  |  ------------------
  |  |  323|  1.49k|                 (b) > 239 ? 5 : \
  |  |  ------------------
  |  |  |  Branch (323:18): [True: 19, False: 1.45k]
  |  |  ------------------
  |  |  324|  1.47k|                 (b) >  79 ? 4 : \
  |  |  ------------------
  |  |  |  Branch (324:18): [True: 60, False: 1.39k]
  |  |  ------------------
  |  |  325|  1.45k|                 (b) >  23 ? 3 : 1)
  |  |  ------------------
  |  |  |  Branch (325:18): [True: 173, False: 1.22k]
  |  |  ------------------
  ------------------
  228|  1.49k|    if (window > 1) {
  ------------------
  |  Branch (228:9): [True: 272, False: 1.22k]
  ------------------
  229|    272|        if (!BN_mod_mul_reciprocal(aa, val[0], val[0], &recp, ctx))
  ------------------
  |  Branch (229:13): [True: 0, False: 272]
  ------------------
  230|      0|            goto err;           /* 2 */
  231|    272|        j = 1 << (window - 1);
  232|  2.11k|        for (i = 1; i < j; i++) {
  ------------------
  |  Branch (232:21): [True: 1.84k, False: 272]
  ------------------
  233|  1.84k|            if (((val[i] = BN_CTX_get(ctx)) == NULL) ||
  ------------------
  |  Branch (233:17): [True: 0, False: 1.84k]
  ------------------
  234|  1.84k|                !BN_mod_mul_reciprocal(val[i], val[i - 1], aa, &recp, ctx))
  ------------------
  |  Branch (234:17): [True: 0, False: 1.84k]
  ------------------
  235|      0|                goto err;
  236|  1.84k|        }
  237|    272|    }
  238|       |
  239|  1.49k|    start = 1;                  /* This is used to avoid multiplication etc
  240|       |                                 * when there is only the value '1' in the
  241|       |                                 * buffer. */
  242|  1.49k|    wstart = bits - 1;          /* The top bit of the window */
  243|  1.49k|    wend = 0;                   /* The bottom bit of the window */
  244|       |
  245|  1.49k|    if (r == p) {
  ------------------
  |  Branch (245:9): [True: 0, False: 1.49k]
  ------------------
  246|      0|        BIGNUM *p_dup = BN_CTX_get(ctx);
  247|       |
  248|      0|        if (p_dup == NULL || BN_copy(p_dup, p) == NULL)
  ------------------
  |  Branch (248:13): [True: 0, False: 0]
  |  Branch (248:30): [True: 0, False: 0]
  ------------------
  249|      0|            goto err;
  250|      0|        p = p_dup;
  251|      0|    }
  252|       |
  253|  1.49k|    if (!BN_one(r))
  ------------------
  |  |  197|  1.49k|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (253:9): [True: 0, False: 1.49k]
  ------------------
  254|      0|        goto err;
  255|       |
  256|  59.5k|    for (;;) {
  257|  59.5k|        int wvalue;             /* The 'value' of the window */
  258|       |
  259|  59.5k|        if (BN_is_bit_set(p, wstart) == 0) {
  ------------------
  |  Branch (259:13): [True: 41.4k, False: 18.0k]
  ------------------
  260|  41.4k|            if (!start)
  ------------------
  |  Branch (260:17): [True: 41.4k, False: 0]
  ------------------
  261|  41.4k|                if (!BN_mod_mul_reciprocal(r, r, r, &recp, ctx))
  ------------------
  |  Branch (261:21): [True: 0, False: 41.4k]
  ------------------
  262|      0|                    goto err;
  263|  41.4k|            if (wstart == 0)
  ------------------
  |  Branch (263:17): [True: 446, False: 41.0k]
  ------------------
  264|    446|                break;
  265|  41.0k|            wstart--;
  266|  41.0k|            continue;
  267|  41.4k|        }
  268|       |        /*
  269|       |         * We now have wstart on a 'set' bit, we now need to work out how bit
  270|       |         * a window to do.  To do this we need to scan forward until the last
  271|       |         * set bit before the end of the window
  272|       |         */
  273|  18.0k|        wvalue = 1;
  274|  18.0k|        wend = 0;
  275|  56.5k|        for (i = 1; i < window; i++) {
  ------------------
  |  Branch (275:21): [True: 38.5k, False: 17.9k]
  ------------------
  276|  38.5k|            if (wstart - i < 0)
  ------------------
  |  Branch (276:17): [True: 139, False: 38.4k]
  ------------------
  277|    139|                break;
  278|  38.4k|            if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (278:17): [True: 26.6k, False: 11.8k]
  ------------------
  279|  26.6k|                wvalue <<= (i - wend);
  280|  26.6k|                wvalue |= 1;
  281|  26.6k|                wend = i;
  282|  26.6k|            }
  283|  38.4k|        }
  284|       |
  285|       |        /* wend is the size of the current window */
  286|  18.0k|        j = wend + 1;
  287|       |        /* add the 'bytes above' */
  288|  18.0k|        if (!start)
  ------------------
  |  Branch (288:13): [True: 16.6k, False: 1.49k]
  ------------------
  289|  64.3k|            for (i = 0; i < j; i++) {
  ------------------
  |  Branch (289:25): [True: 47.7k, False: 16.6k]
  ------------------
  290|  47.7k|                if (!BN_mod_mul_reciprocal(r, r, r, &recp, ctx))
  ------------------
  |  Branch (290:21): [True: 0, False: 47.7k]
  ------------------
  291|      0|                    goto err;
  292|  47.7k|            }
  293|       |
  294|       |        /* wvalue will be an odd number < 2^window */
  295|  18.0k|        if (!BN_mod_mul_reciprocal(r, r, val[wvalue >> 1], &recp, ctx))
  ------------------
  |  Branch (295:13): [True: 0, False: 18.0k]
  ------------------
  296|      0|            goto err;
  297|       |
  298|       |        /* move the 'window' down further */
  299|  18.0k|        wstart -= wend + 1;
  300|  18.0k|        start = 0;
  301|  18.0k|        if (wstart < 0)
  ------------------
  |  Branch (301:13): [True: 1.04k, False: 17.0k]
  ------------------
  302|  1.04k|            break;
  303|  18.0k|    }
  304|  1.49k|    ret = 1;
  305|  1.52k| err:
  306|  1.52k|    BN_CTX_end(ctx);
  307|  1.52k|    BN_RECP_CTX_free(&recp);
  308|  1.52k|    bn_check_top(r);
  309|  1.52k|    return ret;
  310|  1.49k|}
BN_mod_exp_mont:
  314|  1.01k|{
  315|  1.01k|    int i, j, bits, ret = 0, wstart, wend, window;
  316|  1.01k|    int start = 1;
  317|  1.01k|    BIGNUM *d, *r;
  318|  1.01k|    const BIGNUM *aa;
  319|       |    /* Table of variables obtained from 'ctx' */
  320|  1.01k|    BIGNUM *val[TABLE_SIZE];
  321|  1.01k|    BN_MONT_CTX *mont = NULL;
  322|       |
  323|  1.01k|    bn_check_top(a);
  324|  1.01k|    bn_check_top(p);
  325|  1.01k|    bn_check_top(m);
  326|       |
  327|  1.01k|    if (!BN_is_odd(m)) {
  ------------------
  |  Branch (327:9): [True: 0, False: 1.01k]
  ------------------
  328|      0|        ERR_raise(ERR_LIB_BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  329|      0|        return 0;
  330|      0|    }
  331|       |
  332|  1.01k|    if (m->top <= BN_CONSTTIME_SIZE_LIMIT
  ------------------
  |  |   46|  2.03k|#define BN_CONSTTIME_SIZE_LIMIT (INT_MAX / BN_BYTES / 256)
  |  |  ------------------
  |  |  |  |   38|  1.01k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (332:9): [True: 1.01k, False: 0]
  ------------------
  333|  1.01k|        && (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   67|  1.01k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (333:13): [True: 0, False: 1.01k]
  ------------------
  334|  1.01k|            || BN_get_flags(a, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   67|  1.01k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (334:16): [True: 0, False: 1.01k]
  ------------------
  335|  1.01k|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0)) {
  ------------------
  |  |   67|  1.01k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (335:16): [True: 0, False: 1.01k]
  ------------------
  336|      0|        return BN_mod_exp_mont_consttime(rr, a, p, m, ctx, in_mont);
  337|      0|    }
  338|       |
  339|  1.01k|    bits = BN_num_bits(p);
  340|  1.01k|    if (bits == 0) {
  ------------------
  |  Branch (340:9): [True: 123, False: 895]
  ------------------
  341|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
  342|    123|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (342:13): [True: 1, False: 122]
  ------------------
  343|      1|            ret = 1;
  344|      1|            BN_zero(rr);
  ------------------
  |  |  202|      1|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  345|    122|        } else {
  346|    122|            ret = BN_one(rr);
  ------------------
  |  |  197|    122|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  347|    122|        }
  348|    123|        return ret;
  349|    123|    }
  350|       |
  351|    895|    BN_CTX_start(ctx);
  352|    895|    d = BN_CTX_get(ctx);
  353|    895|    r = BN_CTX_get(ctx);
  354|    895|    val[0] = BN_CTX_get(ctx);
  355|    895|    if (val[0] == NULL)
  ------------------
  |  Branch (355:9): [True: 0, False: 895]
  ------------------
  356|      0|        goto err;
  357|       |
  358|       |    /*
  359|       |     * If this is not done, things will break in the montgomery part
  360|       |     */
  361|       |
  362|    895|    if (in_mont != NULL)
  ------------------
  |  Branch (362:9): [True: 0, False: 895]
  ------------------
  363|      0|        mont = in_mont;
  364|    895|    else {
  365|    895|        if ((mont = BN_MONT_CTX_new()) == NULL)
  ------------------
  |  Branch (365:13): [True: 0, False: 895]
  ------------------
  366|      0|            goto err;
  367|    895|        if (!BN_MONT_CTX_set(mont, m, ctx))
  ------------------
  |  Branch (367:13): [True: 0, False: 895]
  ------------------
  368|      0|            goto err;
  369|    895|    }
  370|       |
  371|    895|    if (a->neg || BN_ucmp(a, m) >= 0) {
  ------------------
  |  Branch (371:9): [True: 203, False: 692]
  |  Branch (371:19): [True: 9, False: 683]
  ------------------
  372|    212|        if (!BN_nnmod(val[0], a, m, ctx))
  ------------------
  |  Branch (372:13): [True: 0, False: 212]
  ------------------
  373|      0|            goto err;
  374|    212|        aa = val[0];
  375|    212|    } else
  376|    683|        aa = a;
  377|    895|    if (!bn_to_mont_fixed_top(val[0], aa, mont, ctx))
  ------------------
  |  Branch (377:9): [True: 0, False: 895]
  ------------------
  378|      0|        goto err;               /* 1 */
  379|       |
  380|    895|    window = BN_window_bits_for_exponent_size(bits);
  ------------------
  |  |  322|    895|                ((b) > 671 ? 6 : \
  |  |  ------------------
  |  |  |  Branch (322:18): [True: 19, False: 876]
  |  |  ------------------
  |  |  323|    895|                 (b) > 239 ? 5 : \
  |  |  ------------------
  |  |  |  Branch (323:18): [True: 14, False: 862]
  |  |  ------------------
  |  |  324|    876|                 (b) >  79 ? 4 : \
  |  |  ------------------
  |  |  |  Branch (324:18): [True: 18, False: 844]
  |  |  ------------------
  |  |  325|    862|                 (b) >  23 ? 3 : 1)
  |  |  ------------------
  |  |  |  Branch (325:18): [True: 56, False: 788]
  |  |  ------------------
  ------------------
  381|    895|    if (window > 1) {
  ------------------
  |  Branch (381:9): [True: 107, False: 788]
  ------------------
  382|    107|        if (!bn_mul_mont_fixed_top(d, val[0], val[0], mont, ctx))
  ------------------
  |  Branch (382:13): [True: 0, False: 107]
  ------------------
  383|      0|            goto err;           /* 2 */
  384|    107|        j = 1 << (window - 1);
  385|  1.20k|        for (i = 1; i < j; i++) {
  ------------------
  |  Branch (385:21): [True: 1.09k, False: 107]
  ------------------
  386|  1.09k|            if (((val[i] = BN_CTX_get(ctx)) == NULL) ||
  ------------------
  |  Branch (386:17): [True: 0, False: 1.09k]
  ------------------
  387|  1.09k|                !bn_mul_mont_fixed_top(val[i], val[i - 1], d, mont, ctx))
  ------------------
  |  Branch (387:17): [True: 0, False: 1.09k]
  ------------------
  388|      0|                goto err;
  389|  1.09k|        }
  390|    107|    }
  391|       |
  392|    895|    start = 1;                  /* This is used to avoid multiplication etc
  393|       |                                 * when there is only the value '1' in the
  394|       |                                 * buffer. */
  395|    895|    wstart = bits - 1;          /* The top bit of the window */
  396|    895|    wend = 0;                   /* The bottom bit of the window */
  397|       |
  398|    895|#if 1                           /* by Shay Gueron's suggestion */
  399|    895|    j = m->top;                 /* borrow j */
  400|    895|    if (m->d[j - 1] & (((BN_ULONG)1) << (BN_BITS2 - 1))) {
  ------------------
  |  |   54|    895|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|    895|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (400:9): [True: 138, False: 757]
  ------------------
  401|    138|        if (bn_wexpand(r, j) == NULL)
  ------------------
  |  Branch (401:13): [True: 0, False: 138]
  ------------------
  402|      0|            goto err;
  403|       |        /* 2^(top*BN_BITS2) - m */
  404|    138|        r->d[0] = (0 - m->d[0]) & BN_MASK2;
  ------------------
  |  |   94|    138|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  405|    853|        for (i = 1; i < j; i++)
  ------------------
  |  Branch (405:21): [True: 715, False: 138]
  ------------------
  406|    715|            r->d[i] = (~m->d[i]) & BN_MASK2;
  ------------------
  |  |   94|    853|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  407|    138|        r->top = j;
  408|    138|        r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|    138|#  define BN_FLG_FIXED_TOP 0
  ------------------
  409|    138|    } else
  410|    757|#endif
  411|    757|    if (!bn_to_mont_fixed_top(r, BN_value_one(), mont, ctx))
  ------------------
  |  Branch (411:9): [True: 0, False: 757]
  ------------------
  412|      0|        goto err;
  413|  49.3k|    for (;;) {
  414|  49.3k|        int wvalue;             /* The 'value' of the window */
  415|       |
  416|  49.3k|        if (BN_is_bit_set(p, wstart) == 0) {
  ------------------
  |  Branch (416:13): [True: 37.0k, False: 12.2k]
  ------------------
  417|  37.0k|            if (!start) {
  ------------------
  |  Branch (417:17): [True: 37.0k, False: 0]
  ------------------
  418|  37.0k|                if (!bn_mul_mont_fixed_top(r, r, r, mont, ctx))
  ------------------
  |  Branch (418:21): [True: 0, False: 37.0k]
  ------------------
  419|      0|                    goto err;
  420|  37.0k|            }
  421|  37.0k|            if (wstart == 0)
  ------------------
  |  Branch (421:17): [True: 346, False: 36.7k]
  ------------------
  422|    346|                break;
  423|  36.7k|            wstart--;
  424|  36.7k|            continue;
  425|  37.0k|        }
  426|       |        /*
  427|       |         * We now have wstart on a 'set' bit, we now need to work out how bit
  428|       |         * a window to do.  To do this we need to scan forward until the last
  429|       |         * set bit before the end of the window
  430|       |         */
  431|  12.2k|        wvalue = 1;
  432|  12.2k|        wend = 0;
  433|  49.4k|        for (i = 1; i < window; i++) {
  ------------------
  |  Branch (433:21): [True: 37.2k, False: 12.2k]
  ------------------
  434|  37.2k|            if (wstart - i < 0)
  ------------------
  |  Branch (434:17): [True: 46, False: 37.1k]
  ------------------
  435|     46|                break;
  436|  37.1k|            if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (436:17): [True: 25.9k, False: 11.2k]
  ------------------
  437|  25.9k|                wvalue <<= (i - wend);
  438|  25.9k|                wvalue |= 1;
  439|  25.9k|                wend = i;
  440|  25.9k|            }
  441|  37.1k|        }
  442|       |
  443|       |        /* wend is the size of the current window */
  444|  12.2k|        j = wend + 1;
  445|       |        /* add the 'bytes above' */
  446|  12.2k|        if (!start)
  ------------------
  |  Branch (446:13): [True: 11.3k, False: 895]
  ------------------
  447|  52.8k|            for (i = 0; i < j; i++) {
  ------------------
  |  Branch (447:25): [True: 41.4k, False: 11.3k]
  ------------------
  448|  41.4k|                if (!bn_mul_mont_fixed_top(r, r, r, mont, ctx))
  ------------------
  |  Branch (448:21): [True: 0, False: 41.4k]
  ------------------
  449|      0|                    goto err;
  450|  41.4k|            }
  451|       |
  452|       |        /* wvalue will be an odd number < 2^window */
  453|  12.2k|        if (!bn_mul_mont_fixed_top(r, r, val[wvalue >> 1], mont, ctx))
  ------------------
  |  Branch (453:13): [True: 0, False: 12.2k]
  ------------------
  454|      0|            goto err;
  455|       |
  456|       |        /* move the 'window' down further */
  457|  12.2k|        wstart -= wend + 1;
  458|  12.2k|        start = 0;
  459|  12.2k|        if (wstart < 0)
  ------------------
  |  Branch (459:13): [True: 549, False: 11.6k]
  ------------------
  460|    549|            break;
  461|  12.2k|    }
  462|       |    /*
  463|       |     * Done with zero-padded intermediate BIGNUMs. Final BN_from_montgomery
  464|       |     * removes padding [if any] and makes return value suitable for public
  465|       |     * API consumer.
  466|       |     */
  467|       |#if defined(SPARC_T4_MONT)
  468|       |    if (OPENSSL_sparcv9cap_P[0] & (SPARCV9_VIS3 | SPARCV9_PREFER_FPU)) {
  469|       |        j = mont->N.top;        /* borrow j */
  470|       |        val[0]->d[0] = 1;       /* borrow val[0] */
  471|       |        for (i = 1; i < j; i++)
  472|       |            val[0]->d[i] = 0;
  473|       |        val[0]->top = j;
  474|       |        if (!BN_mod_mul_montgomery(rr, r, val[0], mont, ctx))
  475|       |            goto err;
  476|       |    } else
  477|       |#endif
  478|    895|    if (!BN_from_montgomery(rr, r, mont, ctx))
  ------------------
  |  Branch (478:9): [True: 0, False: 895]
  ------------------
  479|      0|        goto err;
  480|    895|    ret = 1;
  481|    895| err:
  482|    895|    if (in_mont == NULL)
  ------------------
  |  Branch (482:9): [True: 895, False: 0]
  ------------------
  483|    895|        BN_MONT_CTX_free(mont);
  484|    895|    BN_CTX_end(ctx);
  485|    895|    bn_check_top(rr);
  486|    895|    return ret;
  487|    895|}
BN_mod_exp_mont_word:
 1165|    421|{
 1166|    421|    BN_MONT_CTX *mont = NULL;
 1167|    421|    int b, bits, ret = 0;
 1168|    421|    int r_is_one;
 1169|    421|    BN_ULONG w, next_w;
  ------------------
  |  |   37|    421|#  define BN_ULONG        unsigned long
  ------------------
 1170|    421|    BIGNUM *r, *t;
 1171|    421|    BIGNUM *swap_tmp;
 1172|    421|#define BN_MOD_MUL_WORD(r, w, m) \
 1173|    421|                (BN_mul_word(r, (w)) && \
 1174|    421|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
 1175|    421|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
 1176|       |    /*
 1177|       |     * BN_MOD_MUL_WORD is only used with 'w' large, so the BN_ucmp test is
 1178|       |     * probably more overhead than always using BN_mod (which uses BN_copy if
 1179|       |     * a similar test returns true).
 1180|       |     */
 1181|       |    /*
 1182|       |     * We can use BN_mod and do not need BN_nnmod because our accumulator is
 1183|       |     * never negative (the result of BN_mod does not depend on the sign of
 1184|       |     * the modulus).
 1185|       |     */
 1186|    421|#define BN_TO_MONTGOMERY_WORD(r, w, mont) \
 1187|    421|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
 1188|       |
 1189|    421|    if (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   67|    421|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1189:9): [True: 0, False: 421]
  ------------------
 1190|    421|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0) {
  ------------------
  |  |   67|    421|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1190:16): [True: 0, False: 421]
  ------------------
 1191|       |        /* BN_FLG_CONSTTIME only supported by BN_mod_exp_mont() */
 1192|      0|        ERR_raise(ERR_LIB_BN, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
 1193|      0|        return 0;
 1194|      0|    }
 1195|       |
 1196|    421|    bn_check_top(p);
 1197|    421|    bn_check_top(m);
 1198|       |
 1199|    421|    if (!BN_is_odd(m)) {
  ------------------
  |  Branch (1199:9): [True: 0, False: 421]
  ------------------
 1200|      0|        ERR_raise(ERR_LIB_BN, BN_R_CALLED_WITH_EVEN_MODULUS);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
 1201|      0|        return 0;
 1202|      0|    }
 1203|    421|    if (m->top == 1)
  ------------------
  |  Branch (1203:9): [True: 346, False: 75]
  ------------------
 1204|    346|        a %= m->d[0];           /* make sure that 'a' is reduced */
 1205|       |
 1206|    421|    bits = BN_num_bits(p);
 1207|    421|    if (bits == 0) {
  ------------------
  |  Branch (1207:9): [True: 9, False: 412]
  ------------------
 1208|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
 1209|      9|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (1209:13): [True: 1, False: 8]
  ------------------
 1210|      1|            ret = 1;
 1211|      1|            BN_zero(rr);
  ------------------
  |  |  202|      1|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
 1212|      8|        } else {
 1213|      8|            ret = BN_one(rr);
  ------------------
  |  |  197|      8|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
 1214|      8|        }
 1215|      9|        return ret;
 1216|      9|    }
 1217|    412|    if (a == 0) {
  ------------------
  |  Branch (1217:9): [True: 1, False: 411]
  ------------------
 1218|      1|        BN_zero(rr);
  ------------------
  |  |  202|      1|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
 1219|      1|        ret = 1;
 1220|      1|        return ret;
 1221|      1|    }
 1222|       |
 1223|    411|    BN_CTX_start(ctx);
 1224|    411|    r = BN_CTX_get(ctx);
 1225|    411|    t = BN_CTX_get(ctx);
 1226|    411|    if (t == NULL)
  ------------------
  |  Branch (1226:9): [True: 0, False: 411]
  ------------------
 1227|      0|        goto err;
 1228|       |
 1229|    411|    if (in_mont != NULL)
  ------------------
  |  Branch (1229:9): [True: 0, False: 411]
  ------------------
 1230|      0|        mont = in_mont;
 1231|    411|    else {
 1232|    411|        if ((mont = BN_MONT_CTX_new()) == NULL)
  ------------------
  |  Branch (1232:13): [True: 0, False: 411]
  ------------------
 1233|      0|            goto err;
 1234|    411|        if (!BN_MONT_CTX_set(mont, m, ctx))
  ------------------
  |  Branch (1234:13): [True: 0, False: 411]
  ------------------
 1235|      0|            goto err;
 1236|    411|    }
 1237|       |
 1238|    411|    r_is_one = 1;               /* except for Montgomery factor */
 1239|       |
 1240|       |    /* bits-1 >= 0 */
 1241|       |
 1242|       |    /* The result is accumulated in the product r*w. */
 1243|    411|    w = a;                      /* bit 'bits-1' of 'p' is always set */
 1244|  47.5k|    for (b = bits - 2; b >= 0; b--) {
  ------------------
  |  Branch (1244:24): [True: 47.1k, False: 411]
  ------------------
 1245|       |        /* First, square r*w. */
 1246|  47.1k|        next_w = w * w;
 1247|  47.1k|        if ((next_w / w) != w) { /* overflow */
  ------------------
  |  Branch (1247:13): [True: 7.19k, False: 39.9k]
  ------------------
 1248|  7.19k|            if (r_is_one) {
  ------------------
  |  Branch (1248:17): [True: 310, False: 6.88k]
  ------------------
 1249|    310|                if (!BN_TO_MONTGOMERY_WORD(r, w, mont))
  ------------------
  |  | 1187|    310|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
  |  |  ------------------
  |  |  |  Branch (1187:18): [True: 310, False: 0]
  |  |  |  Branch (1187:41): [True: 310, False: 0]
  |  |  ------------------
  ------------------
 1250|      0|                    goto err;
 1251|    310|                r_is_one = 0;
 1252|  6.88k|            } else {
 1253|  6.88k|                if (!BN_MOD_MUL_WORD(r, w, m))
  ------------------
  |  | 1173|  6.88k|                (BN_mul_word(r, (w)) && \
  |  |  ------------------
  |  |  |  Branch (1173:18): [True: 6.88k, False: 0]
  |  |  ------------------
  |  | 1174|  6.88k|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
  |  | 1175|  6.88k|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
  |  |  ------------------
  |  |  |  |  277|  13.7k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (277:30): [True: 6.88k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (1175:50): [True: 6.88k, False: 0]
  |  |  ------------------
  ------------------
 1254|      0|                    goto err;
 1255|  6.88k|            }
 1256|  7.19k|            next_w = 1;
 1257|  7.19k|        }
 1258|  47.1k|        w = next_w;
 1259|  47.1k|        if (!r_is_one) {
  ------------------
  |  Branch (1259:13): [True: 45.6k, False: 1.48k]
  ------------------
 1260|  45.6k|            if (!BN_mod_mul_montgomery(r, r, r, mont, ctx))
  ------------------
  |  Branch (1260:17): [True: 0, False: 45.6k]
  ------------------
 1261|      0|                goto err;
 1262|  45.6k|        }
 1263|       |
 1264|       |        /* Second, multiply r*w by 'a' if exponent bit is set. */
 1265|  47.1k|        if (BN_is_bit_set(p, b)) {
  ------------------
  |  Branch (1265:13): [True: 24.7k, False: 22.3k]
  ------------------
 1266|  24.7k|            next_w = w * a;
 1267|  24.7k|            if ((next_w / a) != w) { /* overflow */
  ------------------
  |  Branch (1267:17): [True: 11.2k, False: 13.4k]
  ------------------
 1268|  11.2k|                if (r_is_one) {
  ------------------
  |  Branch (1268:21): [True: 81, False: 11.1k]
  ------------------
 1269|     81|                    if (!BN_TO_MONTGOMERY_WORD(r, w, mont))
  ------------------
  |  | 1187|     81|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
  |  |  ------------------
  |  |  |  Branch (1187:18): [True: 81, False: 0]
  |  |  |  Branch (1187:41): [True: 81, False: 0]
  |  |  ------------------
  ------------------
 1270|      0|                        goto err;
 1271|     81|                    r_is_one = 0;
 1272|  11.1k|                } else {
 1273|  11.1k|                    if (!BN_MOD_MUL_WORD(r, w, m))
  ------------------
  |  | 1173|  11.1k|                (BN_mul_word(r, (w)) && \
  |  |  ------------------
  |  |  |  Branch (1173:18): [True: 11.1k, False: 0]
  |  |  ------------------
  |  | 1174|  11.1k|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
  |  | 1175|  11.1k|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
  |  |  ------------------
  |  |  |  |  277|  22.3k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (277:30): [True: 11.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (1175:50): [True: 11.1k, False: 0]
  |  |  ------------------
  ------------------
 1274|      0|                        goto err;
 1275|  11.1k|                }
 1276|  11.2k|                next_w = a;
 1277|  11.2k|            }
 1278|  24.7k|            w = next_w;
 1279|  24.7k|        }
 1280|  47.1k|    }
 1281|       |
 1282|       |    /* Finally, set r:=r*w. */
 1283|    411|    if (w != 1) {
  ------------------
  |  Branch (1283:9): [True: 375, False: 36]
  ------------------
 1284|    375|        if (r_is_one) {
  ------------------
  |  Branch (1284:13): [True: 13, False: 362]
  ------------------
 1285|     13|            if (!BN_TO_MONTGOMERY_WORD(r, w, mont))
  ------------------
  |  | 1187|     13|                (BN_set_word(r, (w)) && BN_to_montgomery(r, r, (mont), ctx))
  |  |  ------------------
  |  |  |  Branch (1187:18): [True: 13, False: 0]
  |  |  |  Branch (1187:41): [True: 13, False: 0]
  |  |  ------------------
  ------------------
 1286|      0|                goto err;
 1287|     13|            r_is_one = 0;
 1288|    362|        } else {
 1289|    362|            if (!BN_MOD_MUL_WORD(r, w, m))
  ------------------
  |  | 1173|    362|                (BN_mul_word(r, (w)) && \
  |  |  ------------------
  |  |  |  Branch (1173:18): [True: 362, False: 0]
  |  |  ------------------
  |  | 1174|    362|                (/* BN_ucmp(r, (m)) < 0 ? 1 :*/  \
  |  | 1175|    362|                        (BN_mod(t, r, m, ctx) && (swap_tmp = r, r = t, t = swap_tmp, 1))))
  |  |  ------------------
  |  |  |  |  277|    724|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (277:30): [True: 362, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (1175:50): [True: 362, False: 0]
  |  |  ------------------
  ------------------
 1290|      0|                goto err;
 1291|    362|        }
 1292|    375|    }
 1293|       |
 1294|    411|    if (r_is_one) {             /* can happen only if a == 1 */
  ------------------
  |  Branch (1294:9): [True: 7, False: 404]
  ------------------
 1295|      7|        if (!BN_one(rr))
  ------------------
  |  |  197|      7|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (1295:13): [True: 0, False: 7]
  ------------------
 1296|      0|            goto err;
 1297|    404|    } else {
 1298|    404|        if (!BN_from_montgomery(rr, r, mont, ctx))
  ------------------
  |  Branch (1298:13): [True: 0, False: 404]
  ------------------
 1299|      0|            goto err;
 1300|    404|    }
 1301|    411|    ret = 1;
 1302|    411| err:
 1303|    411|    if (in_mont == NULL)
  ------------------
  |  Branch (1303:9): [True: 411, False: 0]
  ------------------
 1304|    411|        BN_MONT_CTX_free(mont);
 1305|    411|    BN_CTX_end(ctx);
 1306|    411|    bn_check_top(rr);
 1307|    411|    return ret;
 1308|    411|}
BN_mod_exp_simple:
 1313|  3.02k|{
 1314|  3.02k|    int i, j, bits, ret = 0, wstart, wend, window;
 1315|  3.02k|    int start = 1;
 1316|  3.02k|    BIGNUM *d;
 1317|       |    /* Table of variables obtained from 'ctx' */
 1318|  3.02k|    BIGNUM *val[TABLE_SIZE];
 1319|       |
 1320|  3.02k|    if (BN_get_flags(p, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   67|  3.02k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1320:9): [True: 0, False: 3.02k]
  ------------------
 1321|  3.02k|            || BN_get_flags(a, BN_FLG_CONSTTIME) != 0
  ------------------
  |  |   67|  3.02k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1321:16): [True: 0, False: 3.02k]
  ------------------
 1322|  3.02k|            || BN_get_flags(m, BN_FLG_CONSTTIME) != 0) {
  ------------------
  |  |   67|  3.02k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (1322:16): [True: 0, False: 3.02k]
  ------------------
 1323|       |        /* BN_FLG_CONSTTIME only supported by BN_mod_exp_mont() */
 1324|      0|        ERR_raise(ERR_LIB_BN, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
 1325|      0|        return 0;
 1326|      0|    }
 1327|       |
 1328|  3.02k|    if (r == m) {
  ------------------
  |  Branch (1328:9): [True: 0, False: 3.02k]
  ------------------
 1329|      0|        ERR_raise(ERR_LIB_BN, ERR_R_PASSED_INVALID_ARGUMENT);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
 1330|      0|        return 0;
 1331|      0|    }
 1332|       |
 1333|  3.02k|    bits = BN_num_bits(p);
 1334|  3.02k|    if (bits == 0) {
  ------------------
  |  Branch (1334:9): [True: 189, False: 2.83k]
  ------------------
 1335|       |        /* x**0 mod 1, or x**0 mod -1 is still zero. */
 1336|    189|        if (BN_abs_is_word(m, 1)) {
  ------------------
  |  Branch (1336:13): [True: 2, False: 187]
  ------------------
 1337|      2|            ret = 1;
 1338|      2|            BN_zero(r);
  ------------------
  |  |  202|      2|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
 1339|    187|        } else {
 1340|    187|            ret = BN_one(r);
  ------------------
  |  |  197|    187|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
 1341|    187|        }
 1342|    189|        return ret;
 1343|    189|    }
 1344|       |
 1345|  2.83k|    BN_CTX_start(ctx);
 1346|  2.83k|    d = BN_CTX_get(ctx);
 1347|  2.83k|    val[0] = BN_CTX_get(ctx);
 1348|  2.83k|    if (val[0] == NULL)
  ------------------
  |  Branch (1348:9): [True: 0, False: 2.83k]
  ------------------
 1349|      0|        goto err;
 1350|       |
 1351|  2.83k|    if (!BN_nnmod(val[0], a, m, ctx))
  ------------------
  |  Branch (1351:9): [True: 0, False: 2.83k]
  ------------------
 1352|      0|        goto err;               /* 1 */
 1353|  2.83k|    if (BN_is_zero(val[0])) {
  ------------------
  |  Branch (1353:9): [True: 717, False: 2.11k]
  ------------------
 1354|    717|        BN_zero(r);
  ------------------
  |  |  202|    717|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
 1355|    717|        ret = 1;
 1356|    717|        goto err;
 1357|    717|    }
 1358|       |
 1359|  2.11k|    window = BN_window_bits_for_exponent_size(bits);
  ------------------
  |  |  322|  2.11k|                ((b) > 671 ? 6 : \
  |  |  ------------------
  |  |  |  Branch (322:18): [True: 33, False: 2.08k]
  |  |  ------------------
  |  |  323|  2.11k|                 (b) > 239 ? 5 : \
  |  |  ------------------
  |  |  |  Branch (323:18): [True: 25, False: 2.05k]
  |  |  ------------------
  |  |  324|  2.08k|                 (b) >  79 ? 4 : \
  |  |  ------------------
  |  |  |  Branch (324:18): [True: 80, False: 1.97k]
  |  |  ------------------
  |  |  325|  2.05k|                 (b) >  23 ? 3 : 1)
  |  |  ------------------
  |  |  |  Branch (325:18): [True: 226, False: 1.75k]
  |  |  ------------------
  ------------------
 1360|  2.11k|    if (window > 1) {
  ------------------
  |  Branch (1360:9): [True: 364, False: 1.75k]
  ------------------
 1361|    364|        if (!BN_mod_mul(d, val[0], val[0], m, ctx))
  ------------------
  |  Branch (1361:13): [True: 0, False: 364]
  ------------------
 1362|      0|            goto err;           /* 2 */
 1363|    364|        j = 1 << (window - 1);
 1364|  3.00k|        for (i = 1; i < j; i++) {
  ------------------
  |  Branch (1364:21): [True: 2.63k, False: 364]
  ------------------
 1365|  2.63k|            if (((val[i] = BN_CTX_get(ctx)) == NULL) ||
  ------------------
  |  Branch (1365:17): [True: 0, False: 2.63k]
  ------------------
 1366|  2.63k|                !BN_mod_mul(val[i], val[i - 1], d, m, ctx))
  ------------------
  |  Branch (1366:17): [True: 0, False: 2.63k]
  ------------------
 1367|      0|                goto err;
 1368|  2.63k|        }
 1369|    364|    }
 1370|       |
 1371|  2.11k|    start = 1;                  /* This is used to avoid multiplication etc
 1372|       |                                 * when there is only the value '1' in the
 1373|       |                                 * buffer. */
 1374|  2.11k|    wstart = bits - 1;          /* The top bit of the window */
 1375|  2.11k|    wend = 0;                   /* The bottom bit of the window */
 1376|       |
 1377|  2.11k|    if (r == p) {
  ------------------
  |  Branch (1377:9): [True: 0, False: 2.11k]
  ------------------
 1378|      0|        BIGNUM *p_dup = BN_CTX_get(ctx);
 1379|       |
 1380|      0|        if (p_dup == NULL || BN_copy(p_dup, p) == NULL)
  ------------------
  |  Branch (1380:13): [True: 0, False: 0]
  |  Branch (1380:30): [True: 0, False: 0]
  ------------------
 1381|      0|            goto err;
 1382|      0|        p = p_dup;
 1383|      0|    }
 1384|       |
 1385|  2.11k|    if (!BN_one(r))
  ------------------
  |  |  197|  2.11k|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (1385:9): [True: 0, False: 2.11k]
  ------------------
 1386|      0|        goto err;
 1387|       |
 1388|  89.4k|    for (;;) {
 1389|  89.4k|        int wvalue;             /* The 'value' of the window */
 1390|       |
 1391|  89.4k|        if (BN_is_bit_set(p, wstart) == 0) {
  ------------------
  |  Branch (1391:13): [True: 62.2k, False: 27.1k]
  ------------------
 1392|  62.2k|            if (!start)
  ------------------
  |  Branch (1392:17): [True: 62.2k, False: 0]
  ------------------
 1393|  62.2k|                if (!BN_mod_mul(r, r, r, m, ctx))
  ------------------
  |  Branch (1393:21): [True: 0, False: 62.2k]
  ------------------
 1394|      0|                    goto err;
 1395|  62.2k|            if (wstart == 0)
  ------------------
  |  Branch (1395:17): [True: 634, False: 61.5k]
  ------------------
 1396|    634|                break;
 1397|  61.5k|            wstart--;
 1398|  61.5k|            continue;
 1399|  62.2k|        }
 1400|       |        /*
 1401|       |         * We now have wstart on a 'set' bit, we now need to work out how bit
 1402|       |         * a window to do.  To do this we need to scan forward until the last
 1403|       |         * set bit before the end of the window
 1404|       |         */
 1405|  27.1k|        wvalue = 1;
 1406|  27.1k|        wend = 0;
 1407|  91.3k|        for (i = 1; i < window; i++) {
  ------------------
  |  Branch (1407:21): [True: 64.3k, False: 26.9k]
  ------------------
 1408|  64.3k|            if (wstart - i < 0)
  ------------------
  |  Branch (1408:17): [True: 189, False: 64.1k]
  ------------------
 1409|    189|                break;
 1410|  64.1k|            if (BN_is_bit_set(p, wstart - i)) {
  ------------------
  |  Branch (1410:17): [True: 45.6k, False: 18.5k]
  ------------------
 1411|  45.6k|                wvalue <<= (i - wend);
 1412|  45.6k|                wvalue |= 1;
 1413|  45.6k|                wend = i;
 1414|  45.6k|            }
 1415|  64.1k|        }
 1416|       |
 1417|       |        /* wend is the size of the current window */
 1418|  27.1k|        j = wend + 1;
 1419|       |        /* add the 'bytes above' */
 1420|  27.1k|        if (!start)
  ------------------
  |  Branch (1420:13): [True: 25.0k, False: 2.11k]
  ------------------
 1421|   103k|            for (i = 0; i < j; i++) {
  ------------------
  |  Branch (1421:25): [True: 78.2k, False: 25.0k]
  ------------------
 1422|  78.2k|                if (!BN_mod_mul(r, r, r, m, ctx))
  ------------------
  |  Branch (1422:21): [True: 0, False: 78.2k]
  ------------------
 1423|      0|                    goto err;
 1424|  78.2k|            }
 1425|       |
 1426|       |        /* wvalue will be an odd number < 2^window */
 1427|  27.1k|        if (!BN_mod_mul(r, r, val[wvalue >> 1], m, ctx))
  ------------------
  |  Branch (1427:13): [True: 0, False: 27.1k]
  ------------------
 1428|      0|            goto err;
 1429|       |
 1430|       |        /* move the 'window' down further */
 1431|  27.1k|        wstart -= wend + 1;
 1432|  27.1k|        start = 0;
 1433|  27.1k|        if (wstart < 0)
  ------------------
  |  Branch (1433:13): [True: 1.48k, False: 25.6k]
  ------------------
 1434|  1.48k|            break;
 1435|  27.1k|    }
 1436|  2.11k|    ret = 1;
 1437|  2.83k| err:
 1438|  2.83k|    BN_CTX_end(ctx);
 1439|  2.83k|    bn_check_top(r);
 1440|  2.83k|    return ret;
 1441|  2.11k|}

int_bn_mod_inverse:
  201|  1.28k|{
  202|  1.28k|    BIGNUM *A, *B, *X, *Y, *M, *D, *T, *R = NULL;
  203|  1.28k|    BIGNUM *ret = NULL;
  204|  1.28k|    int sign;
  205|       |
  206|       |    /* This is invalid input so we don't worry about constant time here */
  207|  1.28k|    if (BN_abs_is_word(n, 1) || BN_is_zero(n)) {
  ------------------
  |  Branch (207:9): [True: 0, False: 1.28k]
  |  Branch (207:33): [True: 0, False: 1.28k]
  ------------------
  208|      0|        *pnoinv = 1;
  209|      0|        return NULL;
  210|      0|    }
  211|       |
  212|  1.28k|    *pnoinv = 0;
  213|       |
  214|  1.28k|    if ((BN_get_flags(a, BN_FLG_CONSTTIME) != 0)
  ------------------
  |  |   67|  1.28k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (214:9): [True: 0, False: 1.28k]
  ------------------
  215|  1.28k|        || (BN_get_flags(n, BN_FLG_CONSTTIME) != 0)) {
  ------------------
  |  |   67|  1.28k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (215:12): [True: 0, False: 1.28k]
  ------------------
  216|      0|        return bn_mod_inverse_no_branch(in, a, n, ctx, pnoinv);
  217|      0|    }
  218|       |
  219|  1.28k|    bn_check_top(a);
  220|  1.28k|    bn_check_top(n);
  221|       |
  222|  1.28k|    BN_CTX_start(ctx);
  223|  1.28k|    A = BN_CTX_get(ctx);
  224|  1.28k|    B = BN_CTX_get(ctx);
  225|  1.28k|    X = BN_CTX_get(ctx);
  226|  1.28k|    D = BN_CTX_get(ctx);
  227|  1.28k|    M = BN_CTX_get(ctx);
  228|  1.28k|    Y = BN_CTX_get(ctx);
  229|  1.28k|    T = BN_CTX_get(ctx);
  230|  1.28k|    if (T == NULL)
  ------------------
  |  Branch (230:9): [True: 0, False: 1.28k]
  ------------------
  231|      0|        goto err;
  232|       |
  233|  1.28k|    if (in == NULL)
  ------------------
  |  Branch (233:9): [True: 0, False: 1.28k]
  ------------------
  234|      0|        R = BN_new();
  235|  1.28k|    else
  236|  1.28k|        R = in;
  237|  1.28k|    if (R == NULL)
  ------------------
  |  Branch (237:9): [True: 0, False: 1.28k]
  ------------------
  238|      0|        goto err;
  239|       |
  240|  1.28k|    if (!BN_one(X))
  ------------------
  |  |  197|  1.28k|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (240:9): [True: 0, False: 1.28k]
  ------------------
  241|      0|        goto err;
  242|  1.28k|    BN_zero(Y);
  ------------------
  |  |  202|  1.28k|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  243|  1.28k|    if (BN_copy(B, a) == NULL)
  ------------------
  |  Branch (243:9): [True: 0, False: 1.28k]
  ------------------
  244|      0|        goto err;
  245|  1.28k|    if (BN_copy(A, n) == NULL)
  ------------------
  |  Branch (245:9): [True: 0, False: 1.28k]
  ------------------
  246|      0|        goto err;
  247|  1.28k|    A->neg = 0;
  248|  1.28k|    if (B->neg || (BN_ucmp(B, A) >= 0)) {
  ------------------
  |  Branch (248:9): [True: 0, False: 1.28k]
  |  Branch (248:19): [True: 1.28k, False: 0]
  ------------------
  249|  1.28k|        if (!BN_nnmod(B, B, A, ctx))
  ------------------
  |  Branch (249:13): [True: 0, False: 1.28k]
  ------------------
  250|      0|            goto err;
  251|  1.28k|    }
  252|  1.28k|    sign = -1;
  253|       |    /*-
  254|       |     * From  B = a mod |n|,  A = |n|  it follows that
  255|       |     *
  256|       |     *      0 <= B < A,
  257|       |     *     -sign*X*a  ==  B   (mod |n|),
  258|       |     *      sign*Y*a  ==  A   (mod |n|).
  259|       |     */
  260|       |
  261|  1.28k|    if (BN_is_odd(n) && (BN_num_bits(n) <= 2048)) {
  ------------------
  |  Branch (261:9): [True: 1.28k, False: 0]
  |  Branch (261:25): [True: 1.28k, False: 0]
  ------------------
  262|       |        /*
  263|       |         * Binary inversion algorithm; requires odd modulus. This is faster
  264|       |         * than the general algorithm if the modulus is sufficiently small
  265|       |         * (about 400 .. 500 bits on 32-bit systems, but much more on 64-bit
  266|       |         * systems)
  267|       |         */
  268|  1.28k|        int shift;
  269|       |
  270|  49.9k|        while (!BN_is_zero(B)) {
  ------------------
  |  Branch (270:16): [True: 48.6k, False: 1.28k]
  ------------------
  271|       |            /*-
  272|       |             *      0 < B < |n|,
  273|       |             *      0 < A <= |n|,
  274|       |             * (1) -sign*X*a  ==  B   (mod |n|),
  275|       |             * (2)  sign*Y*a  ==  A   (mod |n|)
  276|       |             */
  277|       |
  278|       |            /*
  279|       |             * Now divide B by the maximum possible power of two in the
  280|       |             * integers, and divide X by the same value mod |n|. When we're
  281|       |             * done, (1) still holds.
  282|       |             */
  283|  48.6k|            shift = 0;
  284|  66.0k|            while (!BN_is_bit_set(B, shift)) { /* note that 0 < B */
  ------------------
  |  Branch (284:20): [True: 17.4k, False: 48.6k]
  ------------------
  285|  17.4k|                shift++;
  286|       |
  287|  17.4k|                if (BN_is_odd(X)) {
  ------------------
  |  Branch (287:21): [True: 7.67k, False: 9.72k]
  ------------------
  288|  7.67k|                    if (!BN_uadd(X, X, n))
  ------------------
  |  Branch (288:25): [True: 0, False: 7.67k]
  ------------------
  289|      0|                        goto err;
  290|  7.67k|                }
  291|       |                /*
  292|       |                 * now X is even, so we can easily divide it by two
  293|       |                 */
  294|  17.4k|                if (!BN_rshift1(X, X))
  ------------------
  |  Branch (294:21): [True: 0, False: 17.4k]
  ------------------
  295|      0|                    goto err;
  296|  17.4k|            }
  297|  48.6k|            if (shift > 0) {
  ------------------
  |  Branch (297:17): [True: 12.6k, False: 36.0k]
  ------------------
  298|  12.6k|                if (!BN_rshift(B, B, shift))
  ------------------
  |  Branch (298:21): [True: 0, False: 12.6k]
  ------------------
  299|      0|                    goto err;
  300|  12.6k|            }
  301|       |
  302|       |            /*
  303|       |             * Same for A and Y.  Afterwards, (2) still holds.
  304|       |             */
  305|  48.6k|            shift = 0;
  306|  88.1k|            while (!BN_is_bit_set(A, shift)) { /* note that 0 < A */
  ------------------
  |  Branch (306:20): [True: 39.5k, False: 48.6k]
  ------------------
  307|  39.5k|                shift++;
  308|       |
  309|  39.5k|                if (BN_is_odd(Y)) {
  ------------------
  |  Branch (309:21): [True: 21.5k, False: 17.9k]
  ------------------
  310|  21.5k|                    if (!BN_uadd(Y, Y, n))
  ------------------
  |  Branch (310:25): [True: 0, False: 21.5k]
  ------------------
  311|      0|                        goto err;
  312|  21.5k|                }
  313|       |                /* now Y is even */
  314|  39.5k|                if (!BN_rshift1(Y, Y))
  ------------------
  |  Branch (314:21): [True: 0, False: 39.5k]
  ------------------
  315|      0|                    goto err;
  316|  39.5k|            }
  317|  48.6k|            if (shift > 0) {
  ------------------
  |  Branch (317:17): [True: 35.1k, False: 13.4k]
  ------------------
  318|  35.1k|                if (!BN_rshift(A, A, shift))
  ------------------
  |  Branch (318:21): [True: 0, False: 35.1k]
  ------------------
  319|      0|                    goto err;
  320|  35.1k|            }
  321|       |
  322|       |            /*-
  323|       |             * We still have (1) and (2).
  324|       |             * Both  A  and  B  are odd.
  325|       |             * The following computations ensure that
  326|       |             *
  327|       |             *     0 <= B < |n|,
  328|       |             *      0 < A < |n|,
  329|       |             * (1) -sign*X*a  ==  B   (mod |n|),
  330|       |             * (2)  sign*Y*a  ==  A   (mod |n|),
  331|       |             *
  332|       |             * and that either  A  or  B  is even in the next iteration.
  333|       |             */
  334|  48.6k|            if (BN_ucmp(B, A) >= 0) {
  ------------------
  |  Branch (334:17): [True: 13.4k, False: 35.1k]
  ------------------
  335|       |                /* -sign*(X + Y)*a == B - A  (mod |n|) */
  336|  13.4k|                if (!BN_uadd(X, X, Y))
  ------------------
  |  Branch (336:21): [True: 0, False: 13.4k]
  ------------------
  337|      0|                    goto err;
  338|       |                /*
  339|       |                 * NB: we could use BN_mod_add_quick(X, X, Y, n), but that
  340|       |                 * actually makes the algorithm slower
  341|       |                 */
  342|  13.4k|                if (!BN_usub(B, B, A))
  ------------------
  |  Branch (342:21): [True: 0, False: 13.4k]
  ------------------
  343|      0|                    goto err;
  344|  35.1k|            } else {
  345|       |                /*  sign*(X + Y)*a == A - B  (mod |n|) */
  346|  35.1k|                if (!BN_uadd(Y, Y, X))
  ------------------
  |  Branch (346:21): [True: 0, False: 35.1k]
  ------------------
  347|      0|                    goto err;
  348|       |                /*
  349|       |                 * as above, BN_mod_add_quick(Y, Y, X, n) would slow things down
  350|       |                 */
  351|  35.1k|                if (!BN_usub(A, A, B))
  ------------------
  |  Branch (351:21): [True: 0, False: 35.1k]
  ------------------
  352|      0|                    goto err;
  353|  35.1k|            }
  354|  48.6k|        }
  355|  1.28k|    } else {
  356|       |        /* general inversion algorithm */
  357|       |
  358|      0|        while (!BN_is_zero(B)) {
  ------------------
  |  Branch (358:16): [True: 0, False: 0]
  ------------------
  359|      0|            BIGNUM *tmp;
  360|       |
  361|       |            /*-
  362|       |             *      0 < B < A,
  363|       |             * (*) -sign*X*a  ==  B   (mod |n|),
  364|       |             *      sign*Y*a  ==  A   (mod |n|)
  365|       |             */
  366|       |
  367|       |            /* (D, M) := (A/B, A%B) ... */
  368|      0|            if (BN_num_bits(A) == BN_num_bits(B)) {
  ------------------
  |  Branch (368:17): [True: 0, False: 0]
  ------------------
  369|      0|                if (!BN_one(D))
  ------------------
  |  |  197|      0|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (369:21): [True: 0, False: 0]
  ------------------
  370|      0|                    goto err;
  371|      0|                if (!BN_sub(M, A, B))
  ------------------
  |  Branch (371:21): [True: 0, False: 0]
  ------------------
  372|      0|                    goto err;
  373|      0|            } else if (BN_num_bits(A) == BN_num_bits(B) + 1) {
  ------------------
  |  Branch (373:24): [True: 0, False: 0]
  ------------------
  374|       |                /* A/B is 1, 2, or 3 */
  375|      0|                if (!BN_lshift1(T, B))
  ------------------
  |  Branch (375:21): [True: 0, False: 0]
  ------------------
  376|      0|                    goto err;
  377|      0|                if (BN_ucmp(A, T) < 0) {
  ------------------
  |  Branch (377:21): [True: 0, False: 0]
  ------------------
  378|       |                    /* A < 2*B, so D=1 */
  379|      0|                    if (!BN_one(D))
  ------------------
  |  |  197|      0|# define BN_one(a)       (BN_set_word((a),1))
  ------------------
  |  Branch (379:25): [True: 0, False: 0]
  ------------------
  380|      0|                        goto err;
  381|      0|                    if (!BN_sub(M, A, B))
  ------------------
  |  Branch (381:25): [True: 0, False: 0]
  ------------------
  382|      0|                        goto err;
  383|      0|                } else {
  384|       |                    /* A >= 2*B, so D=2 or D=3 */
  385|      0|                    if (!BN_sub(M, A, T))
  ------------------
  |  Branch (385:25): [True: 0, False: 0]
  ------------------
  386|      0|                        goto err;
  387|      0|                    if (!BN_add(D, T, B))
  ------------------
  |  Branch (387:25): [True: 0, False: 0]
  ------------------
  388|      0|                        goto err; /* use D (:= 3*B) as temp */
  389|      0|                    if (BN_ucmp(A, D) < 0) {
  ------------------
  |  Branch (389:25): [True: 0, False: 0]
  ------------------
  390|       |                        /* A < 3*B, so D=2 */
  391|      0|                        if (!BN_set_word(D, 2))
  ------------------
  |  Branch (391:29): [True: 0, False: 0]
  ------------------
  392|      0|                            goto err;
  393|       |                        /*
  394|       |                         * M (= A - 2*B) already has the correct value
  395|       |                         */
  396|      0|                    } else {
  397|       |                        /* only D=3 remains */
  398|      0|                        if (!BN_set_word(D, 3))
  ------------------
  |  Branch (398:29): [True: 0, False: 0]
  ------------------
  399|      0|                            goto err;
  400|       |                        /*
  401|       |                         * currently M = A - 2*B, but we need M = A - 3*B
  402|       |                         */
  403|      0|                        if (!BN_sub(M, M, B))
  ------------------
  |  Branch (403:29): [True: 0, False: 0]
  ------------------
  404|      0|                            goto err;
  405|      0|                    }
  406|      0|                }
  407|      0|            } else {
  408|      0|                if (!BN_div(D, M, A, B, ctx))
  ------------------
  |  Branch (408:21): [True: 0, False: 0]
  ------------------
  409|      0|                    goto err;
  410|      0|            }
  411|       |
  412|       |            /*-
  413|       |             * Now
  414|       |             *      A = D*B + M;
  415|       |             * thus we have
  416|       |             * (**)  sign*Y*a  ==  D*B + M   (mod |n|).
  417|       |             */
  418|       |
  419|      0|            tmp = A;    /* keep the BIGNUM object, the value does not matter */
  420|       |
  421|       |            /* (A, B) := (B, A mod B) ... */
  422|      0|            A = B;
  423|      0|            B = M;
  424|       |            /* ... so we have  0 <= B < A  again */
  425|       |
  426|       |            /*-
  427|       |             * Since the former  M  is now  B  and the former  B  is now  A,
  428|       |             * (**) translates into
  429|       |             *       sign*Y*a  ==  D*A + B    (mod |n|),
  430|       |             * i.e.
  431|       |             *       sign*Y*a - D*A  ==  B    (mod |n|).
  432|       |             * Similarly, (*) translates into
  433|       |             *      -sign*X*a  ==  A          (mod |n|).
  434|       |             *
  435|       |             * Thus,
  436|       |             *   sign*Y*a + D*sign*X*a  ==  B  (mod |n|),
  437|       |             * i.e.
  438|       |             *        sign*(Y + D*X)*a  ==  B  (mod |n|).
  439|       |             *
  440|       |             * So if we set  (X, Y, sign) := (Y + D*X, X, -sign), we arrive back at
  441|       |             *      -sign*X*a  ==  B   (mod |n|),
  442|       |             *       sign*Y*a  ==  A   (mod |n|).
  443|       |             * Note that  X  and  Y  stay non-negative all the time.
  444|       |             */
  445|       |
  446|       |            /*
  447|       |             * most of the time D is very small, so we can optimize tmp := D*X+Y
  448|       |             */
  449|      0|            if (BN_is_one(D)) {
  ------------------
  |  Branch (449:17): [True: 0, False: 0]
  ------------------
  450|      0|                if (!BN_add(tmp, X, Y))
  ------------------
  |  Branch (450:21): [True: 0, False: 0]
  ------------------
  451|      0|                    goto err;
  452|      0|            } else {
  453|      0|                if (BN_is_word(D, 2)) {
  ------------------
  |  Branch (453:21): [True: 0, False: 0]
  ------------------
  454|      0|                    if (!BN_lshift1(tmp, X))
  ------------------
  |  Branch (454:25): [True: 0, False: 0]
  ------------------
  455|      0|                        goto err;
  456|      0|                } else if (BN_is_word(D, 4)) {
  ------------------
  |  Branch (456:28): [True: 0, False: 0]
  ------------------
  457|      0|                    if (!BN_lshift(tmp, X, 2))
  ------------------
  |  Branch (457:25): [True: 0, False: 0]
  ------------------
  458|      0|                        goto err;
  459|      0|                } else if (D->top == 1) {
  ------------------
  |  Branch (459:28): [True: 0, False: 0]
  ------------------
  460|      0|                    if (!BN_copy(tmp, X))
  ------------------
  |  Branch (460:25): [True: 0, False: 0]
  ------------------
  461|      0|                        goto err;
  462|      0|                    if (!BN_mul_word(tmp, D->d[0]))
  ------------------
  |  Branch (462:25): [True: 0, False: 0]
  ------------------
  463|      0|                        goto err;
  464|      0|                } else {
  465|      0|                    if (!BN_mul(tmp, D, X, ctx))
  ------------------
  |  Branch (465:25): [True: 0, False: 0]
  ------------------
  466|      0|                        goto err;
  467|      0|                }
  468|      0|                if (!BN_add(tmp, tmp, Y))
  ------------------
  |  Branch (468:21): [True: 0, False: 0]
  ------------------
  469|      0|                    goto err;
  470|      0|            }
  471|       |
  472|      0|            M = Y;      /* keep the BIGNUM object, the value does not matter */
  473|      0|            Y = X;
  474|      0|            X = tmp;
  475|      0|            sign = -sign;
  476|      0|        }
  477|      0|    }
  478|       |
  479|       |    /*-
  480|       |     * The while loop (Euclid's algorithm) ends when
  481|       |     *      A == gcd(a,n);
  482|       |     * we have
  483|       |     *       sign*Y*a  ==  A  (mod |n|),
  484|       |     * where  Y  is non-negative.
  485|       |     */
  486|       |
  487|  1.28k|    if (sign < 0) {
  ------------------
  |  Branch (487:9): [True: 1.28k, False: 0]
  ------------------
  488|  1.28k|        if (!BN_sub(Y, n, Y))
  ------------------
  |  Branch (488:13): [True: 0, False: 1.28k]
  ------------------
  489|      0|            goto err;
  490|  1.28k|    }
  491|       |    /* Now  Y*a  ==  A  (mod |n|).  */
  492|       |
  493|  1.28k|    if (BN_is_one(A)) {
  ------------------
  |  Branch (493:9): [True: 1.28k, False: 0]
  ------------------
  494|       |        /* Y*a == 1  (mod |n|) */
  495|  1.28k|        if (!Y->neg && BN_ucmp(Y, n) < 0) {
  ------------------
  |  Branch (495:13): [True: 730, False: 554]
  |  Branch (495:24): [True: 730, False: 0]
  ------------------
  496|    730|            if (!BN_copy(R, Y))
  ------------------
  |  Branch (496:17): [True: 0, False: 730]
  ------------------
  497|      0|                goto err;
  498|    730|        } else {
  499|    554|            if (!BN_nnmod(R, Y, n, ctx))
  ------------------
  |  Branch (499:17): [True: 0, False: 554]
  ------------------
  500|      0|                goto err;
  501|    554|        }
  502|  1.28k|    } else {
  503|      0|        *pnoinv = 1;
  504|      0|        goto err;
  505|      0|    }
  506|  1.28k|    ret = R;
  507|  1.28k| err:
  508|  1.28k|    if ((ret == NULL) && (in == NULL))
  ------------------
  |  Branch (508:9): [True: 0, False: 1.28k]
  |  Branch (508:26): [True: 0, False: 0]
  ------------------
  509|      0|        BN_free(R);
  510|  1.28k|    BN_CTX_end(ctx);
  511|  1.28k|    bn_check_top(ret);
  512|  1.28k|    return ret;
  513|  1.28k|}
BN_mod_inverse:
  518|  1.28k|{
  519|  1.28k|    BN_CTX *new_ctx = NULL;
  520|  1.28k|    BIGNUM *rv;
  521|  1.28k|    int noinv = 0;
  522|       |
  523|  1.28k|    if (ctx == NULL) {
  ------------------
  |  Branch (523:9): [True: 0, False: 1.28k]
  ------------------
  524|      0|        ctx = new_ctx = BN_CTX_new_ex(NULL);
  525|      0|        if (ctx == NULL) {
  ------------------
  |  Branch (525:13): [True: 0, False: 0]
  ------------------
  526|      0|            ERR_raise(ERR_LIB_BN, ERR_R_BN_LIB);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  527|      0|            return NULL;
  528|      0|        }
  529|      0|    }
  530|       |
  531|  1.28k|    rv = int_bn_mod_inverse(in, a, n, ctx, &noinv);
  532|  1.28k|    if (noinv)
  ------------------
  |  Branch (532:9): [True: 0, False: 1.28k]
  ------------------
  533|  1.28k|        ERR_raise(ERR_LIB_BN, BN_R_NO_INVERSE);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  534|  1.28k|    BN_CTX_free(new_ctx);
  535|  1.28k|    return rv;
  536|  1.28k|}

BN_value_one:
   83|    757|{
   84|    757|    static const BN_ULONG data_one = 1L;
   85|    757|    static const BIGNUM const_one = {
   86|    757|        (BN_ULONG *)&data_one, 1, 1, 0, BN_FLG_STATIC_DATA
  ------------------
  |  |   59|    757|# define BN_FLG_STATIC_DATA      0x02
  ------------------
   87|    757|    };
   88|       |
   89|    757|    return &const_one;
   90|    757|}
BN_num_bits_word:
  102|   365k|{
  103|   365k|    BN_ULONG x, mask;
  ------------------
  |  |   37|   365k|#  define BN_ULONG        unsigned long
  ------------------
  104|   365k|    int bits = (l != 0);
  105|       |
  106|   365k|#if BN_BITS2 > 32
  107|   365k|    x = l >> 32;
  108|   365k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   94|   365k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  109|   365k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   54|   365k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   365k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  110|   365k|    bits += 32 & mask;
  111|   365k|    l ^= (x ^ l) & mask;
  112|   365k|#endif
  113|       |
  114|   365k|    x = l >> 16;
  115|   365k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   94|   365k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  116|   365k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   54|   365k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   365k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  117|   365k|    bits += 16 & mask;
  118|   365k|    l ^= (x ^ l) & mask;
  119|       |
  120|   365k|    x = l >> 8;
  121|   365k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   94|   365k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  122|   365k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   54|   365k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   365k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  123|   365k|    bits += 8 & mask;
  124|   365k|    l ^= (x ^ l) & mask;
  125|       |
  126|   365k|    x = l >> 4;
  127|   365k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   94|   365k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  128|   365k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   54|   365k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   365k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  129|   365k|    bits += 4 & mask;
  130|   365k|    l ^= (x ^ l) & mask;
  131|       |
  132|   365k|    x = l >> 2;
  133|   365k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   94|   365k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  134|   365k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   54|   365k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   365k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  135|   365k|    bits += 2 & mask;
  136|   365k|    l ^= (x ^ l) & mask;
  137|       |
  138|   365k|    x = l >> 1;
  139|   365k|    mask = (0 - x) & BN_MASK2;
  ------------------
  |  |   94|   365k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  140|   365k|    mask = (0 - (mask >> (BN_BITS2 - 1)));
  ------------------
  |  |   54|   365k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   365k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  141|   365k|    bits += 1 & mask;
  142|       |
  143|   365k|    return bits;
  144|   365k|}
BN_num_bits:
  180|  98.2k|{
  181|  98.2k|    int i = a->top - 1;
  182|  98.2k|    bn_check_top(a);
  183|       |
  184|  98.2k|    if (a->flags & BN_FLG_CONSTTIME) {
  ------------------
  |  |   67|  98.2k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (184:9): [True: 0, False: 98.2k]
  ------------------
  185|       |        /*
  186|       |         * We assume that BIGNUMs flagged as CONSTTIME have also been expanded
  187|       |         * so that a->dmax is not leaking secret information.
  188|       |         *
  189|       |         * In other words, it's the caller's responsibility to ensure `a` has
  190|       |         * been preallocated in advance to a public length if we hit this
  191|       |         * branch.
  192|       |         *
  193|       |         */
  194|      0|        return bn_num_bits_consttime(a);
  195|      0|    }
  196|       |
  197|  98.2k|    if (BN_is_zero(a))
  ------------------
  |  Branch (197:9): [True: 378, False: 97.8k]
  ------------------
  198|    378|        return 0;
  199|       |
  200|  97.8k|    return ((i * BN_BITS2) + BN_num_bits_word(a->d[i]));
  ------------------
  |  |   54|  97.8k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  97.8k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  201|  98.2k|}
BN_clear_free:
  215|  36.0k|{
  216|  36.0k|    if (a == NULL)
  ------------------
  |  Branch (216:9): [True: 0, False: 36.0k]
  ------------------
  217|      0|        return;
  218|  36.0k|    if (a->d != NULL && !BN_get_flags(a, BN_FLG_STATIC_DATA))
  ------------------
  |  |   59|  34.7k|# define BN_FLG_STATIC_DATA      0x02
  ------------------
  |  Branch (218:9): [True: 34.7k, False: 1.30k]
  |  Branch (218:25): [True: 34.7k, False: 0]
  ------------------
  219|  34.7k|        bn_free_d(a, 1);
  220|  36.0k|    if (BN_get_flags(a, BN_FLG_MALLOCED)) {
  ------------------
  |  |   58|  36.0k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (220:9): [True: 0, False: 36.0k]
  ------------------
  221|      0|        OPENSSL_cleanse(a, sizeof(*a));
  222|      0|        OPENSSL_free(a);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  223|      0|    }
  224|  36.0k|}
BN_free:
  227|  18.3k|{
  228|  18.3k|    if (a == NULL)
  ------------------
  |  Branch (228:9): [True: 0, False: 18.3k]
  ------------------
  229|      0|        return;
  230|  18.3k|    if (!BN_get_flags(a, BN_FLG_STATIC_DATA))
  ------------------
  |  |   59|  18.3k|# define BN_FLG_STATIC_DATA      0x02
  ------------------
  |  Branch (230:9): [True: 18.3k, False: 0]
  ------------------
  231|  18.3k|        bn_free_d(a, 0);
  232|  18.3k|    if (a->flags & BN_FLG_MALLOCED)
  ------------------
  |  |   58|  18.3k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (232:9): [True: 15.2k, False: 3.05k]
  ------------------
  233|  15.2k|        OPENSSL_free(a);
  ------------------
  |  |  115|  15.2k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  15.2k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  15.2k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  234|  18.3k|}
bn_init:
  237|  55.9k|{
  238|  55.9k|    static BIGNUM nilbn;
  239|       |
  240|  55.9k|    *a = nilbn;
  241|  55.9k|    bn_check_top(a);
  242|  55.9k|}
BN_new:
  245|  15.2k|{
  246|  15.2k|    BIGNUM *ret;
  247|       |
  248|  15.2k|    if ((ret = OPENSSL_zalloc(sizeof(*ret))) == NULL)
  ------------------
  |  |  104|  15.2k|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  15.2k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  15.2k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (248:9): [True: 0, False: 15.2k]
  ------------------
  249|      0|        return NULL;
  250|  15.2k|    ret->flags = BN_FLG_MALLOCED;
  ------------------
  |  |   58|  15.2k|# define BN_FLG_MALLOCED         0x01
  ------------------
  251|  15.2k|    bn_check_top(ret);
  252|  15.2k|    return ret;
  253|  15.2k|}
bn_expand2:
  300|  77.6k|{
  301|  77.6k|    if (words > b->dmax) {
  ------------------
  |  Branch (301:9): [True: 77.6k, False: 0]
  ------------------
  302|  77.6k|        BN_ULONG *a = bn_expand_internal(b, words);
  ------------------
  |  |   37|  77.6k|#  define BN_ULONG        unsigned long
  ------------------
  303|  77.6k|        if (!a)
  ------------------
  |  Branch (303:13): [True: 0, False: 77.6k]
  ------------------
  304|      0|            return NULL;
  305|  77.6k|        if (b->d != NULL)
  ------------------
  |  Branch (305:13): [True: 26.6k, False: 51.0k]
  ------------------
  306|  26.6k|            bn_free_d(b, 1);
  307|  77.6k|        b->d = a;
  308|  77.6k|        b->dmax = words;
  309|  77.6k|    }
  310|       |
  311|  77.6k|    return b;
  312|  77.6k|}
BN_copy:
  334|   228k|{
  335|   228k|    int bn_words;
  336|       |
  337|   228k|    bn_check_top(b);
  338|       |
  339|   228k|    bn_words = BN_get_flags(b, BN_FLG_CONSTTIME) ? b->dmax : b->top;
  ------------------
  |  |   67|   228k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (339:16): [True: 0, False: 228k]
  ------------------
  340|       |
  341|   228k|    if (a == b)
  ------------------
  |  Branch (341:9): [True: 0, False: 228k]
  ------------------
  342|      0|        return a;
  343|   228k|    if (bn_wexpand(a, bn_words) == NULL)
  ------------------
  |  Branch (343:9): [True: 0, False: 228k]
  ------------------
  344|      0|        return NULL;
  345|       |
  346|   228k|    if (b->top > 0)
  ------------------
  |  Branch (346:9): [True: 221k, False: 7.00k]
  ------------------
  347|   221k|        memcpy(a->d, b->d, sizeof(b->d[0]) * bn_words);
  348|       |
  349|   228k|    a->neg = b->neg;
  350|   228k|    a->top = b->top;
  351|   228k|    a->flags |= b->flags & BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   228k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  352|   228k|    bn_check_top(a);
  353|   228k|    return a;
  354|   228k|}
BN_clear:
  396|  1.14k|{
  397|  1.14k|    if (a == NULL)
  ------------------
  |  Branch (397:9): [True: 0, False: 1.14k]
  ------------------
  398|      0|        return;
  399|  1.14k|    bn_check_top(a);
  400|  1.14k|    if (a->d != NULL)
  ------------------
  |  Branch (400:9): [True: 0, False: 1.14k]
  ------------------
  401|      0|        OPENSSL_cleanse(a->d, sizeof(*a->d) * a->dmax);
  402|  1.14k|    a->neg = 0;
  403|  1.14k|    a->top = 0;
  404|  1.14k|    a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|  1.14k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  405|  1.14k|}
BN_set_word:
  418|  6.97k|{
  419|  6.97k|    bn_check_top(a);
  420|  6.97k|    if (bn_expand(a, (int)sizeof(BN_ULONG) * 8) == NULL)
  ------------------
  |  Branch (420:9): [True: 0, False: 6.97k]
  ------------------
  421|      0|        return 0;
  422|  6.97k|    a->neg = 0;
  423|  6.97k|    a->d[0] = w;
  424|  6.97k|    a->top = (w ? 1 : 0);
  ------------------
  |  Branch (424:15): [True: 6.97k, False: 0]
  ------------------
  425|  6.97k|    a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|  6.97k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  426|  6.97k|    bn_check_top(a);
  427|  6.97k|    return 1;
  428|  6.97k|}
BN_bin2bn:
  536|  9.17k|{
  537|  9.17k|    return bin2bn(s, len, ret, BIG, UNSIGNED);
  538|  9.17k|}
BN_ucmp:
  708|   318k|{
  709|   318k|    int i;
  710|   318k|    BN_ULONG t1, t2, *ap, *bp;
  ------------------
  |  |   37|   318k|#  define BN_ULONG        unsigned long
  ------------------
  711|       |
  712|   318k|    ap = a->d;
  713|   318k|    bp = b->d;
  714|       |
  715|   318k|    if (BN_get_flags(a, BN_FLG_CONSTTIME)
  ------------------
  |  |   67|   318k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (715:9): [True: 0, False: 318k]
  ------------------
  716|   318k|            && a->top == b->top) {
  ------------------
  |  Branch (716:16): [True: 0, False: 0]
  ------------------
  717|      0|        int res = 0;
  718|       |
  719|      0|        for (i = 0; i < b->top; i++) {
  ------------------
  |  Branch (719:21): [True: 0, False: 0]
  ------------------
  720|      0|            res = constant_time_select_int(constant_time_lt_bn(ap[i], bp[i]),
  721|      0|                                           -1, res);
  722|      0|            res = constant_time_select_int(constant_time_lt_bn(bp[i], ap[i]),
  723|      0|                                           1, res);
  724|      0|        }
  725|      0|        return res;
  726|      0|    }
  727|       |
  728|   318k|    bn_check_top(a);
  729|   318k|    bn_check_top(b);
  730|       |
  731|   318k|    i = a->top - b->top;
  732|   318k|    if (i != 0)
  ------------------
  |  Branch (732:9): [True: 93.1k, False: 225k]
  ------------------
  733|  93.1k|        return i;
  734|       |
  735|   464k|    for (i = a->top - 1; i >= 0; i--) {
  ------------------
  |  Branch (735:26): [True: 462k, False: 1.33k]
  ------------------
  736|   462k|        t1 = ap[i];
  737|   462k|        t2 = bp[i];
  738|   462k|        if (t1 != t2)
  ------------------
  |  Branch (738:13): [True: 224k, False: 238k]
  ------------------
  739|   224k|            return ((t1 > t2) ? 1 : -1);
  ------------------
  |  Branch (739:21): [True: 99.4k, False: 124k]
  ------------------
  740|   462k|    }
  741|  1.33k|    return 0;
  742|   225k|}
BN_cmp:
  745|  3.02k|{
  746|  3.02k|    int i;
  747|  3.02k|    int gt, lt;
  748|  3.02k|    BN_ULONG t1, t2;
  ------------------
  |  |   37|  3.02k|#  define BN_ULONG        unsigned long
  ------------------
  749|       |
  750|  3.02k|    if ((a == NULL) || (b == NULL)) {
  ------------------
  |  Branch (750:9): [True: 0, False: 3.02k]
  |  Branch (750:24): [True: 0, False: 3.02k]
  ------------------
  751|      0|        if (a != NULL)
  ------------------
  |  Branch (751:13): [True: 0, False: 0]
  ------------------
  752|      0|            return -1;
  753|      0|        else if (b != NULL)
  ------------------
  |  Branch (753:18): [True: 0, False: 0]
  ------------------
  754|      0|            return 1;
  755|      0|        else
  756|      0|            return 0;
  757|      0|    }
  758|       |
  759|  3.02k|    bn_check_top(a);
  760|  3.02k|    bn_check_top(b);
  761|       |
  762|  3.02k|    if (a->neg != b->neg) {
  ------------------
  |  Branch (762:9): [True: 0, False: 3.02k]
  ------------------
  763|      0|        if (a->neg)
  ------------------
  |  Branch (763:13): [True: 0, False: 0]
  ------------------
  764|      0|            return -1;
  765|      0|        else
  766|      0|            return 1;
  767|      0|    }
  768|  3.02k|    if (a->neg == 0) {
  ------------------
  |  Branch (768:9): [True: 3.02k, False: 0]
  ------------------
  769|  3.02k|        gt = 1;
  770|  3.02k|        lt = -1;
  771|  3.02k|    } else {
  772|      0|        gt = -1;
  773|      0|        lt = 1;
  774|      0|    }
  775|       |
  776|  3.02k|    if (a->top > b->top)
  ------------------
  |  Branch (776:9): [True: 0, False: 3.02k]
  ------------------
  777|      0|        return gt;
  778|  3.02k|    if (a->top < b->top)
  ------------------
  |  Branch (778:9): [True: 0, False: 3.02k]
  ------------------
  779|      0|        return lt;
  780|  35.1k|    for (i = a->top - 1; i >= 0; i--) {
  ------------------
  |  Branch (780:26): [True: 32.1k, False: 3.02k]
  ------------------
  781|  32.1k|        t1 = a->d[i];
  782|  32.1k|        t2 = b->d[i];
  783|  32.1k|        if (t1 > t2)
  ------------------
  |  Branch (783:13): [True: 0, False: 32.1k]
  ------------------
  784|      0|            return gt;
  785|  32.1k|        if (t1 < t2)
  ------------------
  |  Branch (785:13): [True: 0, False: 32.1k]
  ------------------
  786|      0|            return lt;
  787|  32.1k|    }
  788|  3.02k|    return 0;
  789|  3.02k|}
BN_set_bit:
  792|  4.09k|{
  793|  4.09k|    int i, j, k;
  794|       |
  795|  4.09k|    if (n < 0)
  ------------------
  |  Branch (795:9): [True: 0, False: 4.09k]
  ------------------
  796|      0|        return 0;
  797|       |
  798|  4.09k|    i = n / BN_BITS2;
  ------------------
  |  |   54|  4.09k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  4.09k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  799|  4.09k|    j = n % BN_BITS2;
  ------------------
  |  |   54|  4.09k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  4.09k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  800|  4.09k|    if (a->top <= i) {
  ------------------
  |  Branch (800:9): [True: 4.09k, False: 0]
  ------------------
  801|  4.09k|        if (bn_wexpand(a, i + 1) == NULL)
  ------------------
  |  Branch (801:13): [True: 0, False: 4.09k]
  ------------------
  802|      0|            return 0;
  803|  85.4k|        for (k = a->top; k < i + 1; k++)
  ------------------
  |  Branch (803:26): [True: 81.3k, False: 4.09k]
  ------------------
  804|  81.3k|            a->d[k] = 0;
  805|  4.09k|        a->top = i + 1;
  806|  4.09k|        a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|  4.09k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  807|  4.09k|    }
  808|       |
  809|  4.09k|    a->d[i] |= (((BN_ULONG)1) << j);
  810|  4.09k|    bn_check_top(a);
  811|  4.09k|    return 1;
  812|  4.09k|}
BN_is_bit_set:
  833|   539k|{
  834|   539k|    int i, j;
  835|       |
  836|   539k|    bn_check_top(a);
  837|   539k|    if (n < 0)
  ------------------
  |  Branch (837:9): [True: 0, False: 539k]
  ------------------
  838|      0|        return 0;
  839|   539k|    i = n / BN_BITS2;
  ------------------
  |  |   54|   539k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   539k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  840|   539k|    j = n % BN_BITS2;
  ------------------
  |  |   54|   539k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   539k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  841|   539k|    if (a->top <= i)
  ------------------
  |  Branch (841:9): [True: 0, False: 539k]
  ------------------
  842|      0|        return 0;
  843|   539k|    return (int)(((a->d[i]) >> j) & ((BN_ULONG)1));
  844|   539k|}
BN_set_negative:
  879|  6.11k|{
  880|  6.11k|    if (b && !BN_is_zero(a))
  ------------------
  |  Branch (880:9): [True: 3.33k, False: 2.77k]
  |  Branch (880:14): [True: 2.78k, False: 555]
  ------------------
  881|  2.78k|        a->neg = 1;
  882|  3.33k|    else
  883|  3.33k|        a->neg = 0;
  884|  6.11k|}
bn_cmp_words:
  887|   970k|{
  888|   970k|    int i;
  889|   970k|    BN_ULONG aa, bb;
  ------------------
  |  |   37|   970k|#  define BN_ULONG        unsigned long
  ------------------
  890|       |
  891|   970k|    if (n == 0)
  ------------------
  |  Branch (891:9): [True: 0, False: 970k]
  ------------------
  892|      0|        return 0;
  893|       |
  894|   970k|    aa = a[n - 1];
  895|   970k|    bb = b[n - 1];
  896|   970k|    if (aa != bb)
  ------------------
  |  Branch (896:9): [True: 881k, False: 89.0k]
  ------------------
  897|   881k|        return ((aa > bb) ? 1 : -1);
  ------------------
  |  Branch (897:17): [True: 434k, False: 446k]
  ------------------
  898|   527k|    for (i = n - 2; i >= 0; i--) {
  ------------------
  |  Branch (898:21): [True: 504k, False: 23.0k]
  ------------------
  899|   504k|        aa = a[i];
  900|   504k|        bb = b[i];
  901|   504k|        if (aa != bb)
  ------------------
  |  Branch (901:13): [True: 66.0k, False: 438k]
  ------------------
  902|  66.0k|            return ((aa > bb) ? 1 : -1);
  ------------------
  |  Branch (902:21): [True: 34.5k, False: 31.5k]
  ------------------
  903|   504k|    }
  904|  23.0k|    return 0;
  905|  89.0k|}
bn_cmp_part_words:
  917|  1.00M|{
  918|  1.00M|    int n, i;
  919|  1.00M|    n = cl - 1;
  920|       |
  921|  1.00M|    if (dl < 0) {
  ------------------
  |  Branch (921:9): [True: 37.5k, False: 965k]
  ------------------
  922|  97.0k|        for (i = dl; i < 0; i++) {
  ------------------
  |  Branch (922:22): [True: 92.7k, False: 4.31k]
  ------------------
  923|  92.7k|            if (b[n - i] != 0)
  ------------------
  |  Branch (923:17): [True: 33.1k, False: 59.5k]
  ------------------
  924|  33.1k|                return -1;      /* a < b */
  925|  92.7k|        }
  926|  37.5k|    }
  927|   970k|    if (dl > 0) {
  ------------------
  |  Branch (927:9): [True: 39.0k, False: 931k]
  ------------------
  928|   138k|        for (i = dl; i > 0; i--) {
  ------------------
  |  Branch (928:22): [True: 129k, False: 8.54k]
  ------------------
  929|   129k|            if (a[n + i] != 0)
  ------------------
  |  Branch (929:17): [True: 30.5k, False: 99.3k]
  ------------------
  930|  30.5k|                return 1;       /* a > b */
  931|   129k|        }
  932|  39.0k|    }
  933|   939k|    return bn_cmp_words(a, b, cl);
  934|   970k|}
BN_zero_ex:
 1025|  1.96M|{
 1026|  1.96M|    a->neg = 0;
 1027|  1.96M|    a->top = 0;
 1028|  1.96M|    a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|  1.96M|#  define BN_FLG_FIXED_TOP 0
  ------------------
 1029|  1.96M|}
BN_abs_is_word:
 1032|  4.25k|{
 1033|  4.25k|    return ((a->top == 1) && (a->d[0] == w)) || ((w == 0) && (a->top == 0));
  ------------------
  |  Branch (1033:13): [True: 4.17k, False: 76]
  |  Branch (1033:30): [True: 1.31k, False: 2.86k]
  |  Branch (1033:50): [True: 0, False: 2.94k]
  |  Branch (1033:62): [True: 0, False: 0]
  ------------------
 1034|  4.25k|}
BN_is_zero:
 1037|   575k|{
 1038|   575k|    return a->top == 0;
 1039|   575k|}
BN_is_one:
 1042|  2.59k|{
 1043|  2.59k|    return BN_abs_is_word(a, 1) && !a->neg;
  ------------------
  |  Branch (1043:12): [True: 1.30k, False: 1.28k]
  |  Branch (1043:36): [True: 1.30k, False: 0]
  ------------------
 1044|  2.59k|}
BN_is_odd:
 1068|  62.6k|{
 1069|  62.6k|    return (a->top > 0) && (a->d[0] & 1);
  ------------------
  |  Branch (1069:12): [True: 62.6k, False: 0]
  |  Branch (1069:28): [True: 33.4k, False: 29.2k]
  ------------------
 1070|  62.6k|}
BN_to_montgomery:
 1079|    404|{
 1080|    404|    return BN_mod_mul_montgomery(r, a, &(mont->RR), mont, ctx);
 1081|    404|}
BN_get_flags:
 1117|   896k|{
 1118|   896k|    return b->flags & n;
 1119|   896k|}
bn_wexpand:
 1147|  2.43M|{
 1148|  2.43M|    return (words <= a->dmax) ? a : bn_expand2(a, words);
  ------------------
  |  Branch (1148:12): [True: 2.36M, False: 71.9k]
  ------------------
 1149|  2.43M|}
bn_correct_top:
 1174|   936k|{
 1175|   936k|    BN_ULONG *ftl;
  ------------------
  |  |   37|   936k|#  define BN_ULONG        unsigned long
  ------------------
 1176|   936k|    int tmp_top = a->top;
 1177|       |
 1178|   936k|    if (tmp_top > 0) {
  ------------------
  |  Branch (1178:9): [True: 917k, False: 18.8k]
  ------------------
 1179|  2.17M|        for (ftl = &(a->d[tmp_top]); tmp_top > 0; tmp_top--) {
  ------------------
  |  Branch (1179:38): [True: 2.15M, False: 11.8k]
  ------------------
 1180|  2.15M|            ftl--;
 1181|  2.15M|            if (*ftl != 0)
  ------------------
  |  Branch (1181:17): [True: 905k, False: 1.25M]
  ------------------
 1182|   905k|                break;
 1183|  2.15M|        }
 1184|   917k|        a->top = tmp_top;
 1185|   917k|    }
 1186|   936k|    if (a->top == 0)
  ------------------
  |  Branch (1186:9): [True: 30.7k, False: 905k]
  ------------------
 1187|  30.7k|        a->neg = 0;
 1188|   936k|    a->flags &= ~BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   936k|#  define BN_FLG_FIXED_TOP 0
  ------------------
 1189|   936k|    bn_pollute(a);
 1190|   936k|}
bn_lib.c:bn_free_d:
  204|  79.7k|{
  205|  79.7k|    if (BN_get_flags(a, BN_FLG_SECURE))
  ------------------
  |  |   68|  79.7k|# define BN_FLG_SECURE           0x08
  ------------------
  |  Branch (205:9): [True: 0, False: 79.7k]
  ------------------
  206|      0|        OPENSSL_secure_clear_free(a->d, a->dmax * sizeof(a->d[0]));
  ------------------
  |  |  129|      0|        CRYPTO_secure_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_secure_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  207|  79.7k|    else if (clear != 0)
  ------------------
  |  Branch (207:14): [True: 61.3k, False: 18.3k]
  ------------------
  208|  61.3k|        OPENSSL_clear_free(a->d, a->dmax * sizeof(a->d[0]));
  ------------------
  |  |  113|  61.3k|        CRYPTO_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  61.3k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_clear_free(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  61.3k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  209|  18.3k|    else
  210|  18.3k|        OPENSSL_free(a->d);
  ------------------
  |  |  115|  18.3k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  18.3k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  18.3k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  211|  79.7k|}
bn_lib.c:bn_expand_internal:
  266|  77.6k|{
  267|  77.6k|    BN_ULONG *a = NULL;
  ------------------
  |  |   37|  77.6k|#  define BN_ULONG        unsigned long
  ------------------
  268|       |
  269|  77.6k|    if (words > (INT_MAX / (4 * BN_BITS2))) {
  ------------------
  |  |   54|  77.6k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  77.6k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (269:9): [True: 0, False: 77.6k]
  ------------------
  270|      0|        ERR_raise(ERR_LIB_BN, BN_R_BIGNUM_TOO_LONG);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  271|      0|        return NULL;
  272|      0|    }
  273|  77.6k|    if (BN_get_flags(b, BN_FLG_STATIC_DATA)) {
  ------------------
  |  |   59|  77.6k|# define BN_FLG_STATIC_DATA      0x02
  ------------------
  |  Branch (273:9): [True: 0, False: 77.6k]
  ------------------
  274|      0|        ERR_raise(ERR_LIB_BN, BN_R_EXPAND_ON_STATIC_BIGNUM_DATA);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  275|      0|        return NULL;
  276|      0|    }
  277|  77.6k|    if (BN_get_flags(b, BN_FLG_SECURE))
  ------------------
  |  |   68|  77.6k|# define BN_FLG_SECURE           0x08
  ------------------
  |  Branch (277:9): [True: 0, False: 77.6k]
  ------------------
  278|      0|        a = OPENSSL_secure_zalloc(words * sizeof(*a));
  ------------------
  |  |  125|      0|        CRYPTO_secure_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_secure_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  279|  77.6k|    else
  280|  77.6k|        a = OPENSSL_zalloc(words * sizeof(*a));
  ------------------
  |  |  104|  77.6k|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  77.6k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  77.6k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  281|  77.6k|    if (a == NULL)
  ------------------
  |  Branch (281:9): [True: 0, False: 77.6k]
  ------------------
  282|      0|        return NULL;
  283|       |
  284|  77.6k|    assert(b->top <= words);
  285|  77.6k|    if (b->top > 0)
  ------------------
  |  Branch (285:9): [True: 9.94k, False: 67.7k]
  ------------------
  286|  9.94k|        memcpy(a, b->d, sizeof(*a) * b->top);
  287|       |
  288|  77.6k|    return a;
  289|  77.6k|}
bn_lib.c:bin2bn:
  435|  9.17k|{
  436|  9.17k|    int inc;
  437|  9.17k|    const unsigned char *s2;
  438|  9.17k|    int inc2;
  439|  9.17k|    int neg = 0, xor = 0, carry = 0;
  440|  9.17k|    unsigned int i;
  441|  9.17k|    unsigned int n;
  442|  9.17k|    BIGNUM *bn = NULL;
  443|       |
  444|       |    /* Negative length is not acceptable */
  445|  9.17k|    if (len < 0)
  ------------------
  |  Branch (445:9): [True: 0, False: 9.17k]
  ------------------
  446|      0|        return NULL;
  447|       |
  448|  9.17k|    if (ret == NULL)
  ------------------
  |  Branch (448:9): [True: 0, False: 9.17k]
  ------------------
  449|      0|        ret = bn = BN_new();
  450|  9.17k|    if (ret == NULL)
  ------------------
  |  Branch (450:9): [True: 0, False: 9.17k]
  ------------------
  451|      0|        return NULL;
  452|  9.17k|    bn_check_top(ret);
  453|       |
  454|       |    /*
  455|       |     * If the input has no bits, the number is considered zero.
  456|       |     * This makes calls with s==NULL and len==0 safe.
  457|       |     */
  458|  9.17k|    if (len == 0) {
  ------------------
  |  Branch (458:9): [True: 1.14k, False: 8.02k]
  ------------------
  459|  1.14k|        BN_clear(ret);
  460|  1.14k|        return ret;
  461|  1.14k|    }
  462|       |
  463|       |    /*
  464|       |     * The loop that does the work iterates from least to most
  465|       |     * significant BIGNUM chunk, so we adapt parameters to transfer
  466|       |     * input bytes accordingly.
  467|       |     */
  468|  8.02k|    if (endianness == LITTLE) {
  ------------------
  |  Branch (468:9): [True: 0, False: 8.02k]
  ------------------
  469|      0|        s2 = s + len - 1;
  470|      0|        inc2 = -1;
  471|      0|        inc = 1;
  472|  8.02k|    } else {
  473|  8.02k|        s2 = s;
  474|  8.02k|        inc2 = 1;
  475|  8.02k|        inc = -1;
  476|  8.02k|        s += len - 1;
  477|  8.02k|    }
  478|       |
  479|       |    /* Take note of the signedness of the input bytes*/
  480|  8.02k|    if (signedness == SIGNED) {
  ------------------
  |  Branch (480:9): [True: 0, False: 8.02k]
  ------------------
  481|      0|        neg = !!(*s2 & 0x80);
  482|      0|        xor = neg ? 0xff : 0x00;
  ------------------
  |  Branch (482:15): [True: 0, False: 0]
  ------------------
  483|      0|        carry = neg;
  484|      0|    }
  485|       |
  486|       |    /*
  487|       |     * Skip leading sign extensions (the value of |xor|).
  488|       |     * This is the only spot where |s2| and |inc2| are used.
  489|       |     */
  490|  8.34k|    for ( ; len > 0 && *s2 == xor; s2 += inc2, len--)
  ------------------
  |  Branch (490:13): [True: 8.32k, False: 18]
  |  Branch (490:24): [True: 317, False: 8.01k]
  ------------------
  491|    317|        continue;
  492|       |
  493|       |    /*
  494|       |     * If there was a set of 0xff, we backtrack one byte unless the next
  495|       |     * one has a sign bit, as the last 0xff is then part of the actual
  496|       |     * number, rather then a mere sign extension.
  497|       |     */
  498|  8.02k|    if (xor == 0xff) {
  ------------------
  |  Branch (498:9): [True: 0, False: 8.02k]
  ------------------
  499|      0|        if (len == 0 || !(*s2 & 0x80))
  ------------------
  |  Branch (499:13): [True: 0, False: 0]
  |  Branch (499:25): [True: 0, False: 0]
  ------------------
  500|      0|            len++;
  501|      0|    }
  502|       |    /* If it was all zeros, we're done */
  503|  8.02k|    if (len == 0) {
  ------------------
  |  Branch (503:9): [True: 18, False: 8.01k]
  ------------------
  504|     18|        ret->top = 0;
  505|     18|        return ret;
  506|     18|    }
  507|  8.01k|    n = ((len - 1) / BN_BYTES) + 1; /* Number of resulting bignum chunks */
  ------------------
  |  |   38|  8.01k|#  define BN_BYTES        8
  ------------------
  508|  8.01k|    if (bn_wexpand(ret, (int)n) == NULL) {
  ------------------
  |  Branch (508:9): [True: 0, False: 8.01k]
  ------------------
  509|      0|        BN_free(bn);
  510|      0|        return NULL;
  511|      0|    }
  512|  8.01k|    ret->top = n;
  513|  8.01k|    ret->neg = neg;
  514|  58.2k|    for (i = 0; n-- > 0; i++) {
  ------------------
  |  Branch (514:17): [True: 50.2k, False: 8.01k]
  ------------------
  515|  50.2k|        BN_ULONG l = 0;        /* Accumulator */
  ------------------
  |  |   37|  50.2k|#  define BN_ULONG        unsigned long
  ------------------
  516|  50.2k|        unsigned int m = 0;    /* Offset in a bignum chunk, in bits */
  517|       |
  518|   408k|        for (; len > 0 && m < BN_BYTES * 8; len--, s += inc, m += 8) {
  ------------------
  |  |   38|   400k|#  define BN_BYTES        8
  ------------------
  |  Branch (518:16): [True: 400k, False: 8.01k]
  |  Branch (518:27): [True: 357k, False: 42.2k]
  ------------------
  519|   357k|            BN_ULONG byte_xored = *s ^ xor;
  ------------------
  |  |   37|   357k|#  define BN_ULONG        unsigned long
  ------------------
  520|   357k|            BN_ULONG byte = (byte_xored + carry) & 0xff;
  ------------------
  |  |   37|   357k|#  define BN_ULONG        unsigned long
  ------------------
  521|       |
  522|   357k|            carry = byte_xored > byte; /* Implicit 1 or 0 */
  523|   357k|            l |= (byte << m);
  524|   357k|        }
  525|  50.2k|        ret->d[i] = l;
  526|  50.2k|    }
  527|       |    /*
  528|       |     * need to call this due to clear byte at top if avoiding having the top
  529|       |     * bit set (-ve number)
  530|       |     */
  531|  8.01k|    bn_correct_top(ret);
  532|  8.01k|    return ret;
  533|  8.01k|}

bn_lib.c:bn_expand:
  670|  6.97k|{
  671|  6.97k|    if (bits > (INT_MAX - BN_BITS2 + 1))
  ------------------
  |  |   54|  6.97k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  6.97k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (671:9): [True: 0, False: 6.97k]
  ------------------
  672|      0|        return NULL;
  673|       |
  674|  6.97k|    if (((bits+BN_BITS2-1)/BN_BITS2) <= (a)->dmax)
  ------------------
  |  |   54|  6.97k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  6.97k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                  if (((bits+BN_BITS2-1)/BN_BITS2) <= (a)->dmax)
  ------------------
  |  |   54|  6.97k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  6.97k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (674:9): [True: 1.23k, False: 5.73k]
  ------------------
  675|  1.23k|        return a;
  676|       |
  677|  5.73k|    return bn_expand2((a),(bits+BN_BITS2-1)/BN_BITS2);
  ------------------
  |  |   54|  5.73k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  5.73k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                  return bn_expand2((a),(bits+BN_BITS2-1)/BN_BITS2);
  ------------------
  |  |   54|  5.73k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  5.73k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  678|  6.97k|}

BN_nnmod:
   15|   177k|{
   16|       |    /*
   17|       |     * like BN_mod, but returns non-negative remainder (i.e., 0 <= r < |d|
   18|       |     * always holds)
   19|       |     */
   20|       |
   21|   177k|    if (r == d) {
  ------------------
  |  Branch (21:9): [True: 0, False: 177k]
  ------------------
   22|      0|        ERR_raise(ERR_LIB_BN, ERR_R_PASSED_INVALID_ARGUMENT);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
   23|      0|        return 0;
   24|      0|    }
   25|       |
   26|   177k|    if (!(BN_mod(r, m, d, ctx)))
  ------------------
  |  |  277|   177k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  ------------------
  |  Branch (26:9): [True: 0, False: 177k]
  ------------------
   27|      0|        return 0;
   28|   177k|    if (!r->neg)
  ------------------
  |  Branch (28:9): [True: 173k, False: 3.51k]
  ------------------
   29|   173k|        return 1;
   30|       |    /* now   -|d| < r < 0,  so we have to set  r := r + |d| */
   31|  3.51k|    return (d->neg ? BN_sub : BN_add) (r, r, d);
  ------------------
  |  Branch (31:13): [True: 1.24k, False: 2.27k]
  ------------------
   32|   177k|}
BN_mod_mul:
  208|   170k|{
  209|   170k|    BIGNUM *t;
  210|   170k|    int ret = 0;
  211|       |
  212|   170k|    bn_check_top(a);
  213|   170k|    bn_check_top(b);
  214|   170k|    bn_check_top(m);
  215|       |
  216|   170k|    BN_CTX_start(ctx);
  217|   170k|    if ((t = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (217:9): [True: 0, False: 170k]
  ------------------
  218|      0|        goto err;
  219|   170k|    if (a == b) {
  ------------------
  |  Branch (219:9): [True: 140k, False: 29.8k]
  ------------------
  220|   140k|        if (!BN_sqr(t, a, ctx))
  ------------------
  |  Branch (220:13): [True: 0, False: 140k]
  ------------------
  221|      0|            goto err;
  222|   140k|    } else {
  223|  29.8k|        if (!BN_mul(t, a, b, ctx))
  ------------------
  |  Branch (223:13): [True: 0, False: 29.8k]
  ------------------
  224|      0|            goto err;
  225|  29.8k|    }
  226|   170k|    if (!BN_nnmod(r, t, m, ctx))
  ------------------
  |  Branch (226:9): [True: 0, False: 170k]
  ------------------
  227|      0|        goto err;
  228|   170k|    bn_check_top(r);
  229|   170k|    ret = 1;
  230|   170k| err:
  231|   170k|    BN_CTX_end(ctx);
  232|   170k|    return ret;
  233|   170k|}

BN_mod_mul_montgomery:
   28|  46.0k|{
   29|  46.0k|    int ret = bn_mul_mont_fixed_top(r, a, b, mont, ctx);
   30|       |
   31|  46.0k|    bn_correct_top(r);
   32|  46.0k|    bn_check_top(r);
   33|       |
   34|  46.0k|    return ret;
   35|  46.0k|}
bn_mul_mont_fixed_top:
   39|   139k|{
   40|   139k|    BIGNUM *tmp;
   41|   139k|    int ret = 0;
   42|   139k|    int num = mont->N.top;
   43|       |
   44|   139k|#if defined(OPENSSL_BN_ASM_MONT) && defined(MONT_WORD)
   45|   139k|    if (num > 1 && num <= BN_SOFT_LIMIT && a->top == num && b->top == num) {
  ------------------
  |  |   62|   150k|#  define BN_SOFT_LIMIT         (4096 / BN_BYTES)
  |  |  ------------------
  |  |  |  |   38|  10.4k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (45:9): [True: 10.4k, False: 129k]
  |  Branch (45:20): [True: 10.4k, False: 0]
  |  Branch (45:44): [True: 9.32k, False: 1.09k]
  |  Branch (45:61): [True: 9.32k, False: 0]
  ------------------
   46|  9.32k|        if (bn_wexpand(r, num) == NULL)
  ------------------
  |  Branch (46:13): [True: 0, False: 9.32k]
  ------------------
   47|      0|            return 0;
   48|  9.32k|        if (bn_mul_mont(r->d, a->d, b->d, mont->N.d, mont->n0, num)) {
  ------------------
  |  Branch (48:13): [True: 9.32k, False: 0]
  ------------------
   49|  9.32k|            r->neg = a->neg ^ b->neg;
   50|  9.32k|            r->top = num;
   51|  9.32k|            r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|  9.32k|#  define BN_FLG_FIXED_TOP 0
  ------------------
   52|  9.32k|            return 1;
   53|  9.32k|        }
   54|  9.32k|    }
   55|   130k|#endif
   56|       |
   57|   130k|    if ((a->top + b->top) > 2 * num)
  ------------------
  |  Branch (57:9): [True: 0, False: 130k]
  ------------------
   58|      0|        return 0;
   59|       |
   60|   130k|    BN_CTX_start(ctx);
   61|   130k|    tmp = BN_CTX_get(ctx);
   62|   130k|    if (tmp == NULL)
  ------------------
  |  Branch (62:9): [True: 0, False: 130k]
  ------------------
   63|      0|        goto err;
   64|       |
   65|   130k|    bn_check_top(tmp);
   66|   130k|    if (a == b) {
  ------------------
  |  Branch (66:9): [True: 117k, False: 12.5k]
  ------------------
   67|   117k|        if (!bn_sqr_fixed_top(tmp, a, ctx))
  ------------------
  |  Branch (67:13): [True: 0, False: 117k]
  ------------------
   68|      0|            goto err;
   69|   117k|    } else {
   70|  12.5k|        if (!bn_mul_fixed_top(tmp, a, b, ctx))
  ------------------
  |  Branch (70:13): [True: 0, False: 12.5k]
  ------------------
   71|      0|            goto err;
   72|  12.5k|    }
   73|       |    /* reduce from aRR to aR */
   74|   130k|#ifdef MONT_WORD
   75|   130k|    if (!bn_from_montgomery_word(r, tmp, mont))
  ------------------
  |  Branch (75:9): [True: 0, False: 130k]
  ------------------
   76|      0|        goto err;
   77|       |#else
   78|       |    if (!BN_from_montgomery(r, tmp, mont, ctx))
   79|       |        goto err;
   80|       |#endif
   81|   130k|    ret = 1;
   82|   130k| err:
   83|   130k|    BN_CTX_end(ctx);
   84|   130k|    return ret;
   85|   130k|}
BN_from_montgomery:
  164|  1.29k|{
  165|  1.29k|    int retn;
  166|       |
  167|  1.29k|    retn = bn_from_mont_fixed_top(ret, a, mont, ctx);
  168|  1.29k|    bn_correct_top(ret);
  169|  1.29k|    bn_check_top(ret);
  170|       |
  171|  1.29k|    return retn;
  172|  1.29k|}
bn_from_mont_fixed_top:
  176|  1.29k|{
  177|  1.29k|    int retn = 0;
  178|  1.29k|#ifdef MONT_WORD
  179|  1.29k|    BIGNUM *t;
  180|       |
  181|  1.29k|    BN_CTX_start(ctx);
  182|  1.29k|    if ((t = BN_CTX_get(ctx)) && BN_copy(t, a)) {
  ------------------
  |  Branch (182:9): [True: 1.29k, False: 0]
  |  Branch (182:34): [True: 1.29k, False: 0]
  ------------------
  183|  1.29k|        retn = bn_from_montgomery_word(ret, t, mont);
  184|  1.29k|    }
  185|  1.29k|    BN_CTX_end(ctx);
  186|       |#else                           /* !MONT_WORD */
  187|       |    BIGNUM *t1, *t2;
  188|       |
  189|       |    BN_CTX_start(ctx);
  190|       |    t1 = BN_CTX_get(ctx);
  191|       |    t2 = BN_CTX_get(ctx);
  192|       |    if (t2 == NULL)
  193|       |        goto err;
  194|       |
  195|       |    if (!BN_copy(t1, a))
  196|       |        goto err;
  197|       |    BN_mask_bits(t1, mont->ri);
  198|       |
  199|       |    if (!BN_mul(t2, t1, &mont->Ni, ctx))
  200|       |        goto err;
  201|       |    BN_mask_bits(t2, mont->ri);
  202|       |
  203|       |    if (!BN_mul(t1, t2, &mont->N, ctx))
  204|       |        goto err;
  205|       |    if (!BN_add(t2, a, t1))
  206|       |        goto err;
  207|       |    if (!BN_rshift(ret, t2, mont->ri))
  208|       |        goto err;
  209|       |
  210|       |    if (BN_ucmp(ret, &(mont->N)) >= 0) {
  211|       |        if (!BN_usub(ret, ret, &(mont->N)))
  212|       |            goto err;
  213|       |    }
  214|       |    retn = 1;
  215|       |    bn_check_top(ret);
  216|       | err:
  217|       |    BN_CTX_end(ctx);
  218|       |#endif                          /* MONT_WORD */
  219|  1.29k|    return retn;
  220|  1.29k|}
bn_to_mont_fixed_top:
  224|  1.65k|{
  225|  1.65k|    return bn_mul_mont_fixed_top(r, a, &(mont->RR), mont, ctx);
  226|  1.65k|}
BN_MONT_CTX_new:
  229|  1.30k|{
  230|  1.30k|    BN_MONT_CTX *ret;
  231|       |
  232|  1.30k|    if ((ret = OPENSSL_malloc(sizeof(*ret))) == NULL)
  ------------------
  |  |  102|  1.30k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  1.30k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  1.30k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (232:9): [True: 0, False: 1.30k]
  ------------------
  233|      0|        return NULL;
  234|       |
  235|  1.30k|    BN_MONT_CTX_init(ret);
  236|  1.30k|    ret->flags = BN_FLG_MALLOCED;
  ------------------
  |  |   58|  1.30k|# define BN_FLG_MALLOCED         0x01
  ------------------
  237|  1.30k|    return ret;
  238|  1.30k|}
BN_MONT_CTX_init:
  241|  1.30k|{
  242|  1.30k|    ctx->ri = 0;
  243|  1.30k|    bn_init(&ctx->RR);
  244|  1.30k|    bn_init(&ctx->N);
  245|  1.30k|    bn_init(&ctx->Ni);
  246|  1.30k|    ctx->n0[0] = ctx->n0[1] = 0;
  247|  1.30k|    ctx->flags = 0;
  248|  1.30k|}
BN_MONT_CTX_free:
  251|  1.30k|{
  252|  1.30k|    if (mont == NULL)
  ------------------
  |  Branch (252:9): [True: 0, False: 1.30k]
  ------------------
  253|      0|        return;
  254|  1.30k|    BN_clear_free(&mont->RR);
  255|  1.30k|    BN_clear_free(&mont->N);
  256|  1.30k|    BN_clear_free(&mont->Ni);
  257|  1.30k|    if (mont->flags & BN_FLG_MALLOCED)
  ------------------
  |  |   58|  1.30k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (257:9): [True: 1.30k, False: 0]
  ------------------
  258|  1.30k|        OPENSSL_free(mont);
  ------------------
  |  |  115|  1.30k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  1.30k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  1.30k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  259|  1.30k|}
BN_MONT_CTX_set:
  262|  1.30k|{
  263|  1.30k|    int i, ret = 0;
  264|  1.30k|    BIGNUM *Ri, *R;
  265|       |
  266|  1.30k|    if (BN_is_zero(mod))
  ------------------
  |  Branch (266:9): [True: 0, False: 1.30k]
  ------------------
  267|      0|        return 0;
  268|       |
  269|  1.30k|    BN_CTX_start(ctx);
  270|  1.30k|    if ((Ri = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (270:9): [True: 0, False: 1.30k]
  ------------------
  271|      0|        goto err;
  272|  1.30k|    R = &(mont->RR);            /* grab RR as a temp */
  273|  1.30k|    if (!BN_copy(&(mont->N), mod))
  ------------------
  |  Branch (273:9): [True: 0, False: 1.30k]
  ------------------
  274|      0|        goto err;               /* Set N */
  275|  1.30k|    if (BN_get_flags(mod, BN_FLG_CONSTTIME) != 0)
  ------------------
  |  |   67|  1.30k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (275:9): [True: 0, False: 1.30k]
  ------------------
  276|      0|        BN_set_flags(&(mont->N), BN_FLG_CONSTTIME);
  ------------------
  |  |   67|      0|# define BN_FLG_CONSTTIME        0x04
  ------------------
  277|  1.30k|    mont->N.neg = 0;
  278|       |
  279|  1.30k|#ifdef MONT_WORD
  280|  1.30k|    {
  281|  1.30k|        BIGNUM tmod;
  282|  1.30k|        BN_ULONG buf[2];
  ------------------
  |  |   37|  1.30k|#  define BN_ULONG        unsigned long
  ------------------
  283|       |
  284|  1.30k|        bn_init(&tmod);
  285|  1.30k|        tmod.d = buf;
  286|  1.30k|        tmod.dmax = 2;
  287|  1.30k|        tmod.neg = 0;
  288|       |
  289|  1.30k|        if (BN_get_flags(mod, BN_FLG_CONSTTIME) != 0)
  ------------------
  |  |   67|  1.30k|# define BN_FLG_CONSTTIME        0x04
  ------------------
  |  Branch (289:13): [True: 0, False: 1.30k]
  ------------------
  290|      0|            BN_set_flags(&tmod, BN_FLG_CONSTTIME);
  ------------------
  |  |   67|      0|# define BN_FLG_CONSTTIME        0x04
  ------------------
  291|       |
  292|  1.30k|        mont->ri = (BN_num_bits(mod) + (BN_BITS2 - 1)) / BN_BITS2 * BN_BITS2;
  ------------------
  |  |   54|  1.30k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  1.30k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                      mont->ri = (BN_num_bits(mod) + (BN_BITS2 - 1)) / BN_BITS2 * BN_BITS2;
  ------------------
  |  |   54|  1.30k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  1.30k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
                      mont->ri = (BN_num_bits(mod) + (BN_BITS2 - 1)) / BN_BITS2 * BN_BITS2;
  ------------------
  |  |   54|  1.30k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  1.30k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  293|       |
  294|       |# if defined(OPENSSL_BN_ASM_MONT) && (BN_BITS2<=32)
  295|       |        /*
  296|       |         * Only certain BN_BITS2<=32 platforms actually make use of n0[1],
  297|       |         * and we could use the #else case (with a shorter R value) for the
  298|       |         * others.  However, currently only the assembler files do know which
  299|       |         * is which.
  300|       |         */
  301|       |
  302|       |        BN_zero(R);
  303|       |        if (!(BN_set_bit(R, 2 * BN_BITS2)))
  304|       |            goto err;
  305|       |
  306|       |        tmod.top = 0;
  307|       |        if ((buf[0] = mod->d[0]))
  308|       |            tmod.top = 1;
  309|       |        if ((buf[1] = mod->top > 1 ? mod->d[1] : 0))
  310|       |            tmod.top = 2;
  311|       |
  312|       |        if (BN_is_one(&tmod))
  313|       |            BN_zero(Ri);
  314|       |        else if ((BN_mod_inverse(Ri, R, &tmod, ctx)) == NULL)
  315|       |            goto err;
  316|       |        if (!BN_lshift(Ri, Ri, 2 * BN_BITS2))
  317|       |            goto err;           /* R*Ri */
  318|       |        if (!BN_is_zero(Ri)) {
  319|       |            if (!BN_sub_word(Ri, 1))
  320|       |                goto err;
  321|       |        } else {                /* if N mod word size == 1 */
  322|       |
  323|       |            if (bn_expand(Ri, (int)sizeof(BN_ULONG) * 2) == NULL)
  324|       |                goto err;
  325|       |            /* Ri-- (mod double word size) */
  326|       |            Ri->neg = 0;
  327|       |            Ri->d[0] = BN_MASK2;
  328|       |            Ri->d[1] = BN_MASK2;
  329|       |            Ri->top = 2;
  330|       |        }
  331|       |        if (!BN_div(Ri, NULL, Ri, &tmod, ctx))
  332|       |            goto err;
  333|       |        /*
  334|       |         * Ni = (R*Ri-1)/N, keep only couple of least significant words:
  335|       |         */
  336|       |        mont->n0[0] = (Ri->top > 0) ? Ri->d[0] : 0;
  337|       |        mont->n0[1] = (Ri->top > 1) ? Ri->d[1] : 0;
  338|       |# else
  339|  1.30k|        BN_zero(R);
  ------------------
  |  |  202|  1.30k|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  340|  1.30k|        if (!(BN_set_bit(R, BN_BITS2)))
  ------------------
  |  |   54|  1.30k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  1.30k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (340:13): [True: 0, False: 1.30k]
  ------------------
  341|      0|            goto err;           /* R */
  342|       |
  343|  1.30k|        buf[0] = mod->d[0];     /* tmod = N mod word size */
  344|  1.30k|        buf[1] = 0;
  345|  1.30k|        tmod.top = buf[0] != 0 ? 1 : 0;
  ------------------
  |  Branch (345:20): [True: 1.30k, False: 0]
  ------------------
  346|       |        /* Ri = R^-1 mod N */
  347|  1.30k|        if (BN_is_one(&tmod))
  ------------------
  |  Branch (347:13): [True: 22, False: 1.28k]
  ------------------
  348|     22|            BN_zero(Ri);
  ------------------
  |  |  202|     22|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  349|  1.28k|        else if ((BN_mod_inverse(Ri, R, &tmod, ctx)) == NULL)
  ------------------
  |  Branch (349:18): [True: 0, False: 1.28k]
  ------------------
  350|      0|            goto err;
  351|  1.30k|        if (!BN_lshift(Ri, Ri, BN_BITS2))
  ------------------
  |  |   54|  1.30k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  1.30k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  |  Branch (351:13): [True: 0, False: 1.30k]
  ------------------
  352|      0|            goto err;           /* R*Ri */
  353|  1.30k|        if (!BN_is_zero(Ri)) {
  ------------------
  |  Branch (353:13): [True: 1.28k, False: 22]
  ------------------
  354|  1.28k|            if (!BN_sub_word(Ri, 1))
  ------------------
  |  Branch (354:17): [True: 0, False: 1.28k]
  ------------------
  355|      0|                goto err;
  356|  1.28k|        } else {                /* if N mod word size == 1 */
  357|       |
  358|     22|            if (!BN_set_word(Ri, BN_MASK2))
  ------------------
  |  |   94|     22|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  |  Branch (358:17): [True: 0, False: 22]
  ------------------
  359|      0|                goto err;       /* Ri-- (mod word size) */
  360|     22|        }
  361|  1.30k|        if (!BN_div(Ri, NULL, Ri, &tmod, ctx))
  ------------------
  |  Branch (361:13): [True: 0, False: 1.30k]
  ------------------
  362|      0|            goto err;
  363|       |        /*
  364|       |         * Ni = (R*Ri-1)/N, keep only least significant word:
  365|       |         */
  366|  1.30k|        mont->n0[0] = (Ri->top > 0) ? Ri->d[0] : 0;
  ------------------
  |  Branch (366:23): [True: 1.30k, False: 0]
  ------------------
  367|  1.30k|        mont->n0[1] = 0;
  368|  1.30k|# endif
  369|  1.30k|    }
  370|       |#else                           /* !MONT_WORD */
  371|       |    {                           /* bignum version */
  372|       |        mont->ri = BN_num_bits(&mont->N);
  373|       |        BN_zero(R);
  374|       |        if (!BN_set_bit(R, mont->ri))
  375|       |            goto err;           /* R = 2^ri */
  376|       |        /* Ri = R^-1 mod N */
  377|       |        if ((BN_mod_inverse(Ri, R, &mont->N, ctx)) == NULL)
  378|       |            goto err;
  379|       |        if (!BN_lshift(Ri, Ri, mont->ri))
  380|       |            goto err;           /* R*Ri */
  381|       |        if (!BN_sub_word(Ri, 1))
  382|       |            goto err;
  383|       |        /*
  384|       |         * Ni = (R*Ri-1) / N
  385|       |         */
  386|       |        if (!BN_div(&(mont->Ni), NULL, Ri, &mont->N, ctx))
  387|       |            goto err;
  388|       |    }
  389|       |#endif
  390|       |
  391|       |    /* setup RR for conversions */
  392|  1.30k|    BN_zero(&(mont->RR));
  ------------------
  |  |  202|  1.30k|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  393|  1.30k|    if (!BN_set_bit(&(mont->RR), mont->ri * 2))
  ------------------
  |  Branch (393:9): [True: 0, False: 1.30k]
  ------------------
  394|      0|        goto err;
  395|  1.30k|    if (!BN_mod(&(mont->RR), &(mont->RR), &(mont->N), ctx))
  ------------------
  |  |  277|  1.30k|# define BN_mod(rem,m,d,ctx) BN_div(NULL,(rem),(m),(d),(ctx))
  ------------------
  |  Branch (395:9): [True: 0, False: 1.30k]
  ------------------
  396|      0|        goto err;
  397|       |
  398|  1.41k|    for (i = mont->RR.top, ret = mont->N.top; i < ret; i++)
  ------------------
  |  Branch (398:47): [True: 108, False: 1.30k]
  ------------------
  399|    108|        mont->RR.d[i] = 0;
  400|  1.30k|    mont->RR.top = ret;
  401|  1.30k|    mont->RR.flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|  1.30k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  402|       |
  403|  1.30k|    ret = 1;
  404|  1.30k| err:
  405|  1.30k|    BN_CTX_end(ctx);
  406|  1.30k|    return ret;
  407|  1.30k|}
bn_mont.c:bn_from_montgomery_word:
   89|   131k|{
   90|   131k|    BIGNUM *n;
   91|   131k|    BN_ULONG *ap, *np, *rp, n0, v, carry;
  ------------------
  |  |   37|   131k|#  define BN_ULONG        unsigned long
  ------------------
   92|   131k|    int nl, max, i;
   93|   131k|    unsigned int rtop;
   94|       |
   95|   131k|    n = &(mont->N);
   96|   131k|    nl = n->top;
   97|   131k|    if (nl == 0) {
  ------------------
  |  Branch (97:9): [True: 0, False: 131k]
  ------------------
   98|      0|        ret->top = 0;
   99|      0|        return 1;
  100|      0|    }
  101|       |
  102|   131k|    max = (2 * nl);             /* carry is stored separately */
  103|   131k|    if (bn_wexpand(r, max) == NULL)
  ------------------
  |  Branch (103:9): [True: 0, False: 131k]
  ------------------
  104|      0|        return 0;
  105|       |
  106|   131k|    r->neg ^= n->neg;
  107|   131k|    np = n->d;
  108|   131k|    rp = r->d;
  109|       |
  110|       |    /* clear the top words of T */
  111|   431k|    for (rtop = r->top, i = 0; i < max; i++) {
  ------------------
  |  Branch (111:32): [True: 300k, False: 131k]
  ------------------
  112|   300k|        v = (BN_ULONG)0 - ((i - rtop) >> (8 * sizeof(rtop) - 1));
  113|   300k|        rp[i] &= v;
  114|   300k|    }
  115|       |
  116|   131k|    r->top = max;
  117|   131k|    r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   131k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  118|   131k|    n0 = mont->n0[0];
  119|       |
  120|       |    /*
  121|       |     * Add multiples of |n| to |r| until R = 2^(nl * BN_BITS2) divides it. On
  122|       |     * input, we had |r| < |n| * R, so now |r| < 2 * |n| * R. Note that |r|
  123|       |     * includes |carry| which is stored separately.
  124|       |     */
  125|   281k|    for (carry = 0, i = 0; i < nl; i++, rp++) {
  ------------------
  |  Branch (125:28): [True: 150k, False: 131k]
  ------------------
  126|   150k|        v = bn_mul_add_words(rp, np, nl, (rp[0] * n0) & BN_MASK2);
  ------------------
  |  |   94|   150k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  127|   150k|        v = (v + carry + rp[nl]) & BN_MASK2;
  ------------------
  |  |   94|   150k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  128|   150k|        carry |= (v != rp[nl]);
  129|   150k|        carry &= (v <= rp[nl]);
  130|   150k|        rp[nl] = v;
  131|   150k|    }
  132|       |
  133|   131k|    if (bn_wexpand(ret, nl) == NULL)
  ------------------
  |  Branch (133:9): [True: 0, False: 131k]
  ------------------
  134|      0|        return 0;
  135|   131k|    ret->top = nl;
  136|   131k|    ret->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   131k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  137|   131k|    ret->neg = r->neg;
  138|       |
  139|   131k|    rp = ret->d;
  140|       |
  141|       |    /*
  142|       |     * Shift |nl| words to divide by R. We have |ap| < 2 * |n|. Note that |ap|
  143|       |     * includes |carry| which is stored separately.
  144|       |     */
  145|   131k|    ap = &(r->d[nl]);
  146|       |
  147|   131k|    carry -= bn_sub_words(rp, ap, np, nl);
  148|       |    /*
  149|       |     * |carry| is -1 if |ap| - |np| underflowed or zero if it did not. Note
  150|       |     * |carry| cannot be 1. That would imply the subtraction did not fit in
  151|       |     * |nl| words, and we know at most one subtraction is needed.
  152|       |     */
  153|   281k|    for (i = 0; i < nl; i++) {
  ------------------
  |  Branch (153:17): [True: 150k, False: 131k]
  ------------------
  154|   150k|        rp[i] = (carry & ap[i]) | (~carry & rp[i]);
  155|   150k|        ap[i] = 0;
  156|   150k|    }
  157|       |
  158|   131k|    return 1;
  159|   131k|}

bn_sub_part_words:
   30|   968k|{
   31|   968k|    BN_ULONG c, t;
  ------------------
  |  |   37|   968k|#  define BN_ULONG        unsigned long
  ------------------
   32|       |
   33|   968k|    assert(cl >= 0);
   34|   968k|    c = bn_sub_words(r, a, b, cl);
   35|       |
   36|   968k|    if (dl == 0)
  ------------------
  |  Branch (36:9): [True: 891k, False: 76.3k]
  ------------------
   37|   891k|        return c;
   38|       |
   39|  76.3k|    r += cl;
   40|  76.3k|    a += cl;
   41|  76.3k|    b += cl;
   42|       |
   43|  76.3k|    if (dl < 0) {
  ------------------
  |  Branch (43:9): [True: 10.6k, False: 65.6k]
  ------------------
   44|  29.4k|        for (;;) {
   45|  29.4k|            t = b[0];
   46|  29.4k|            r[0] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   94|  29.4k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   47|  29.4k|            if (t != 0)
  ------------------
  |  Branch (47:17): [True: 0, False: 29.4k]
  ------------------
   48|      0|                c = 1;
   49|  29.4k|            if (++dl >= 0)
  ------------------
  |  Branch (49:17): [True: 2.06k, False: 27.3k]
  ------------------
   50|  2.06k|                break;
   51|       |
   52|  27.3k|            t = b[1];
   53|  27.3k|            r[1] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   94|  27.3k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   54|  27.3k|            if (t != 0)
  ------------------
  |  Branch (54:17): [True: 0, False: 27.3k]
  ------------------
   55|      0|                c = 1;
   56|  27.3k|            if (++dl >= 0)
  ------------------
  |  Branch (56:17): [True: 1.58k, False: 25.8k]
  ------------------
   57|  1.58k|                break;
   58|       |
   59|  25.8k|            t = b[2];
   60|  25.8k|            r[2] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   94|  25.8k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   61|  25.8k|            if (t != 0)
  ------------------
  |  Branch (61:17): [True: 0, False: 25.8k]
  ------------------
   62|      0|                c = 1;
   63|  25.8k|            if (++dl >= 0)
  ------------------
  |  Branch (63:17): [True: 6.26k, False: 19.5k]
  ------------------
   64|  6.26k|                break;
   65|       |
   66|  19.5k|            t = b[3];
   67|  19.5k|            r[3] = (0 - t - c) & BN_MASK2;
  ------------------
  |  |   94|  19.5k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   68|  19.5k|            if (t != 0)
  ------------------
  |  Branch (68:17): [True: 0, False: 19.5k]
  ------------------
   69|      0|                c = 1;
   70|  19.5k|            if (++dl >= 0)
  ------------------
  |  Branch (70:17): [True: 728, False: 18.8k]
  ------------------
   71|    728|                break;
   72|       |
   73|  18.8k|            b += 4;
   74|  18.8k|            r += 4;
   75|  18.8k|        }
   76|  65.6k|    } else {
   77|  65.6k|        int save_dl = dl;
   78|  83.2k|        while (c) {
  ------------------
  |  Branch (78:16): [True: 23.3k, False: 59.8k]
  ------------------
   79|  23.3k|            t = a[0];
   80|  23.3k|            r[0] = (t - c) & BN_MASK2;
  ------------------
  |  |   94|  23.3k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   81|  23.3k|            if (t != 0)
  ------------------
  |  Branch (81:17): [True: 9.44k, False: 13.9k]
  ------------------
   82|  9.44k|                c = 0;
   83|  23.3k|            if (--dl <= 0)
  ------------------
  |  Branch (83:17): [True: 1.96k, False: 21.3k]
  ------------------
   84|  1.96k|                break;
   85|       |
   86|  21.3k|            t = a[1];
   87|  21.3k|            r[1] = (t - c) & BN_MASK2;
  ------------------
  |  |   94|  21.3k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   88|  21.3k|            if (t != 0)
  ------------------
  |  Branch (88:17): [True: 7.85k, False: 13.5k]
  ------------------
   89|  7.85k|                c = 0;
   90|  21.3k|            if (--dl <= 0)
  ------------------
  |  Branch (90:17): [True: 955, False: 20.4k]
  ------------------
   91|    955|                break;
   92|       |
   93|  20.4k|            t = a[2];
   94|  20.4k|            r[2] = (t - c) & BN_MASK2;
  ------------------
  |  |   94|  20.4k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   95|  20.4k|            if (t != 0)
  ------------------
  |  Branch (95:17): [True: 9.22k, False: 11.2k]
  ------------------
   96|  9.22k|                c = 0;
   97|  20.4k|            if (--dl <= 0)
  ------------------
  |  Branch (97:17): [True: 2.36k, False: 18.0k]
  ------------------
   98|  2.36k|                break;
   99|       |
  100|  18.0k|            t = a[3];
  101|  18.0k|            r[3] = (t - c) & BN_MASK2;
  ------------------
  |  |   94|  18.0k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  102|  18.0k|            if (t != 0)
  ------------------
  |  Branch (102:17): [True: 7.65k, False: 10.4k]
  ------------------
  103|  7.65k|                c = 0;
  104|  18.0k|            if (--dl <= 0)
  ------------------
  |  Branch (104:17): [True: 509, False: 17.5k]
  ------------------
  105|    509|                break;
  106|       |
  107|  17.5k|            save_dl = dl;
  108|  17.5k|            a += 4;
  109|  17.5k|            r += 4;
  110|  17.5k|        }
  111|  65.6k|        if (dl > 0) {
  ------------------
  |  Branch (111:13): [True: 59.8k, False: 5.79k]
  ------------------
  112|  59.8k|            if (save_dl > dl) {
  ------------------
  |  Branch (112:17): [True: 0, False: 59.8k]
  ------------------
  113|      0|                switch (save_dl - dl) {
  ------------------
  |  Branch (113:25): [True: 0, False: 0]
  ------------------
  114|      0|                case 1:
  ------------------
  |  Branch (114:17): [True: 0, False: 0]
  ------------------
  115|      0|                    r[1] = a[1];
  116|      0|                    if (--dl <= 0)
  ------------------
  |  Branch (116:25): [True: 0, False: 0]
  ------------------
  117|      0|                        break;
  118|       |                    /* fall through */
  119|      0|                case 2:
  ------------------
  |  Branch (119:17): [True: 0, False: 0]
  ------------------
  120|      0|                    r[2] = a[2];
  121|      0|                    if (--dl <= 0)
  ------------------
  |  Branch (121:25): [True: 0, False: 0]
  ------------------
  122|      0|                        break;
  123|       |                    /* fall through */
  124|      0|                case 3:
  ------------------
  |  Branch (124:17): [True: 0, False: 0]
  ------------------
  125|      0|                    r[3] = a[3];
  126|      0|                    if (--dl <= 0)
  ------------------
  |  Branch (126:25): [True: 0, False: 0]
  ------------------
  127|      0|                        break;
  128|      0|                }
  129|      0|                a += 4;
  130|      0|                r += 4;
  131|      0|            }
  132|  59.8k|        }
  133|  65.6k|        if (dl > 0) {
  ------------------
  |  Branch (133:13): [True: 59.8k, False: 5.79k]
  ------------------
  134|   303k|            for (;;) {
  135|   303k|                r[0] = a[0];
  136|   303k|                if (--dl <= 0)
  ------------------
  |  Branch (136:21): [True: 15.4k, False: 288k]
  ------------------
  137|  15.4k|                    break;
  138|   288k|                r[1] = a[1];
  139|   288k|                if (--dl <= 0)
  ------------------
  |  Branch (139:21): [True: 7.76k, False: 280k]
  ------------------
  140|  7.76k|                    break;
  141|   280k|                r[2] = a[2];
  142|   280k|                if (--dl <= 0)
  ------------------
  |  Branch (142:21): [True: 25.3k, False: 254k]
  ------------------
  143|  25.3k|                    break;
  144|   254k|                r[3] = a[3];
  145|   254k|                if (--dl <= 0)
  ------------------
  |  Branch (145:21): [True: 11.3k, False: 243k]
  ------------------
  146|  11.3k|                    break;
  147|       |
  148|   243k|                a += 4;
  149|   243k|                r += 4;
  150|   243k|            }
  151|  59.8k|        }
  152|  65.6k|    }
  153|  76.3k|    return c;
  154|  76.3k|}
bn_mul_recursive:
  177|   471k|{
  178|   471k|    int n = n2 / 2, c1, c2;
  179|   471k|    int tna = n + dna, tnb = n + dnb;
  180|   471k|    unsigned int neg, zero;
  181|   471k|    BN_ULONG ln, lo, *p;
  ------------------
  |  |   37|   471k|#  define BN_ULONG        unsigned long
  ------------------
  182|       |
  183|   471k|# ifdef BN_MUL_COMBA
  184|       |#  if 0
  185|       |    if (n2 == 4) {
  186|       |        bn_mul_comba4(r, a, b);
  187|       |        return;
  188|       |    }
  189|       |#  endif
  190|       |    /*
  191|       |     * Only call bn_mul_comba 8 if n2 == 8 and the two arrays are complete
  192|       |     * [steve]
  193|       |     */
  194|   471k|    if (n2 == 8 && dna == 0 && dnb == 0) {
  ------------------
  |  Branch (194:9): [True: 6.42k, False: 465k]
  |  Branch (194:20): [True: 4.48k, False: 1.94k]
  |  Branch (194:32): [True: 3.68k, False: 800]
  ------------------
  195|  3.68k|        bn_mul_comba8(r, a, b);
  196|  3.68k|        return;
  197|  3.68k|    }
  198|   467k|# endif                         /* BN_MUL_COMBA */
  199|       |    /* Else do normal multiply */
  200|   467k|    if (n2 < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  365|   467k|# define BN_MUL_RECURSIVE_SIZE_NORMAL            (16)/* 32 less than */
  ------------------
  |  Branch (200:9): [True: 2.74k, False: 465k]
  ------------------
  201|  2.74k|        bn_mul_normal(r, a, n2 + dna, b, n2 + dnb);
  202|  2.74k|        if ((dna + dnb) < 0)
  ------------------
  |  Branch (202:13): [True: 2.74k, False: 0]
  ------------------
  203|  2.74k|            memset(&r[2 * n2 + dna + dnb], 0,
  204|  2.74k|                   sizeof(BN_ULONG) * -(dna + dnb));
  205|  2.74k|        return;
  206|  2.74k|    }
  207|       |    /* r=(a[0]-a[1])*(b[1]-b[0]) */
  208|   465k|    c1 = bn_cmp_part_words(a, &(a[n]), tna, n - tna);
  209|   465k|    c2 = bn_cmp_part_words(&(b[n]), b, tnb, tnb - n);
  210|   465k|    zero = neg = 0;
  211|   465k|    switch (c1 * 3 + c2) {
  ------------------
  |  Branch (211:13): [True: 0, False: 465k]
  ------------------
  212|   106k|    case -4:
  ------------------
  |  Branch (212:5): [True: 106k, False: 358k]
  ------------------
  213|   106k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  214|   106k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  215|   106k|        break;
  216|  2.70k|    case -3:
  ------------------
  |  Branch (216:5): [True: 2.70k, False: 462k]
  ------------------
  217|  2.70k|        zero = 1;
  218|  2.70k|        break;
  219|  92.3k|    case -2:
  ------------------
  |  Branch (219:5): [True: 92.3k, False: 372k]
  ------------------
  220|  92.3k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  221|  92.3k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n); /* + */
  222|  92.3k|        neg = 1;
  223|  92.3k|        break;
  224|  4.28k|    case -1:
  ------------------
  |  Branch (224:5): [True: 4.28k, False: 460k]
  ------------------
  225|  6.90k|    case 0:
  ------------------
  |  Branch (225:5): [True: 2.61k, False: 462k]
  ------------------
  226|  11.7k|    case 1:
  ------------------
  |  Branch (226:5): [True: 4.87k, False: 460k]
  ------------------
  227|  11.7k|        zero = 1;
  228|  11.7k|        break;
  229|   147k|    case 2:
  ------------------
  |  Branch (229:5): [True: 147k, False: 318k]
  ------------------
  230|   147k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna); /* + */
  231|   147k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  232|   147k|        neg = 1;
  233|   147k|        break;
  234|  3.15k|    case 3:
  ------------------
  |  Branch (234:5): [True: 3.15k, False: 461k]
  ------------------
  235|  3.15k|        zero = 1;
  236|  3.15k|        break;
  237|   101k|    case 4:
  ------------------
  |  Branch (237:5): [True: 101k, False: 363k]
  ------------------
  238|   101k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna);
  239|   101k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n);
  240|   101k|        break;
  241|   465k|    }
  242|       |
  243|   465k|# ifdef BN_MUL_COMBA
  244|   465k|    if (n == 4 && dna == 0 && dnb == 0) { /* XXX: bn_mul_comba4 could take
  ------------------
  |  Branch (244:9): [True: 0, False: 465k]
  |  Branch (244:19): [True: 0, False: 0]
  |  Branch (244:31): [True: 0, False: 0]
  ------------------
  245|       |                                           * extra args to do this well */
  246|      0|        if (!zero)
  ------------------
  |  Branch (246:13): [True: 0, False: 0]
  ------------------
  247|      0|            bn_mul_comba4(&(t[n2]), t, &(t[n]));
  248|      0|        else
  249|      0|            memset(&t[n2], 0, sizeof(*t) * 8);
  250|       |
  251|      0|        bn_mul_comba4(r, a, b);
  252|      0|        bn_mul_comba4(&(r[n2]), &(a[n]), &(b[n]));
  253|   465k|    } else if (n == 8 && dna == 0 && dnb == 0) { /* XXX: bn_mul_comba8 could
  ------------------
  |  Branch (253:16): [True: 334k, False: 130k]
  |  Branch (253:26): [True: 332k, False: 1.34k]
  |  Branch (253:38): [True: 332k, False: 463]
  ------------------
  254|       |                                                  * take extra args to do
  255|       |                                                  * this well */
  256|   332k|        if (!zero)
  ------------------
  |  Branch (256:13): [True: 317k, False: 14.4k]
  ------------------
  257|   317k|            bn_mul_comba8(&(t[n2]), t, &(t[n]));
  258|  14.4k|        else
  259|  14.4k|            memset(&t[n2], 0, sizeof(*t) * 16);
  260|       |
  261|   332k|        bn_mul_comba8(r, a, b);
  262|   332k|        bn_mul_comba8(&(r[n2]), &(a[n]), &(b[n]));
  263|   332k|    } else
  264|   132k|# endif                         /* BN_MUL_COMBA */
  265|   132k|    {
  266|   132k|        p = &(t[n2 * 2]);
  267|   132k|        if (!zero)
  ------------------
  |  Branch (267:13): [True: 129k, False: 3.19k]
  ------------------
  268|   129k|            bn_mul_recursive(&(t[n2]), t, &(t[n]), n, 0, 0, p);
  269|  3.19k|        else
  270|  3.19k|            memset(&t[n2], 0, sizeof(*t) * n2);
  271|   132k|        bn_mul_recursive(r, a, b, n, 0, 0, p);
  272|   132k|        bn_mul_recursive(&(r[n2]), &(a[n]), &(b[n]), n, dna, dnb, p);
  273|   132k|    }
  274|       |
  275|       |    /*-
  276|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0]), c1 is the sign
  277|       |     * r[10] holds (a[0]*b[0])
  278|       |     * r[32] holds (b[1]*b[1])
  279|       |     */
  280|       |
  281|   465k|    c1 = (int)(bn_add_words(t, r, &(r[n2]), n2));
  282|       |
  283|   465k|    if (neg) {                  /* if t[32] is negative */
  ------------------
  |  Branch (283:9): [True: 239k, False: 225k]
  ------------------
  284|   239k|        c1 -= (int)(bn_sub_words(&(t[n2]), t, &(t[n2]), n2));
  285|   239k|    } else {
  286|       |        /* Might have a carry */
  287|   225k|        c1 += (int)(bn_add_words(&(t[n2]), &(t[n2]), t, n2));
  288|   225k|    }
  289|       |
  290|       |    /*-
  291|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0])+(a[0]*b[0])+(a[1]*b[1])
  292|       |     * r[10] holds (a[0]*b[0])
  293|       |     * r[32] holds (b[1]*b[1])
  294|       |     * c1 holds the carry bits
  295|       |     */
  296|   465k|    c1 += (int)(bn_add_words(&(r[n]), &(r[n]), &(t[n2]), n2));
  297|   465k|    if (c1) {
  ------------------
  |  Branch (297:9): [True: 167k, False: 297k]
  ------------------
  298|   167k|        p = &(r[n + n2]);
  299|   167k|        lo = *p;
  300|   167k|        ln = (lo + c1) & BN_MASK2;
  ------------------
  |  |   94|   167k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  301|   167k|        *p = ln;
  302|       |
  303|       |        /*
  304|       |         * The overflow will stop before we over write words we should not
  305|       |         * overwrite
  306|       |         */
  307|   167k|        if (ln < (BN_ULONG)c1) {
  ------------------
  |  Branch (307:13): [True: 1.33k, False: 165k]
  ------------------
  308|  3.58k|            do {
  309|  3.58k|                p++;
  310|  3.58k|                lo = *p;
  311|  3.58k|                ln = (lo + 1) & BN_MASK2;
  ------------------
  |  |   94|  3.58k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  312|  3.58k|                *p = ln;
  313|  3.58k|            } while (ln == 0);
  ------------------
  |  Branch (313:22): [True: 2.25k, False: 1.33k]
  ------------------
  314|  1.33k|        }
  315|   167k|    }
  316|   465k|}
bn_mul_part_recursive:
  324|  36.6k|{
  325|  36.6k|    int i, j, n2 = n * 2;
  326|  36.6k|    int c1, c2, neg;
  327|  36.6k|    BN_ULONG ln, lo, *p;
  ------------------
  |  |   37|  36.6k|#  define BN_ULONG        unsigned long
  ------------------
  328|       |
  329|  36.6k|    if (n < 8) {
  ------------------
  |  Branch (329:9): [True: 0, False: 36.6k]
  ------------------
  330|      0|        bn_mul_normal(r, a, n + tna, b, n + tnb);
  331|      0|        return;
  332|      0|    }
  333|       |
  334|       |    /* r=(a[0]-a[1])*(b[1]-b[0]) */
  335|  36.6k|    c1 = bn_cmp_part_words(a, &(a[n]), tna, n - tna);
  336|  36.6k|    c2 = bn_cmp_part_words(&(b[n]), b, tnb, tnb - n);
  337|  36.6k|    neg = 0;
  338|  36.6k|    switch (c1 * 3 + c2) {
  ------------------
  |  Branch (338:13): [True: 0, False: 36.6k]
  ------------------
  339|  5.37k|    case -4:
  ------------------
  |  Branch (339:5): [True: 5.37k, False: 31.2k]
  ------------------
  340|  5.37k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  341|  5.37k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  342|  5.37k|        break;
  343|    216|    case -3:
  ------------------
  |  Branch (343:5): [True: 216, False: 36.4k]
  ------------------
  344|  1.59k|    case -2:
  ------------------
  |  Branch (344:5): [True: 1.37k, False: 35.2k]
  ------------------
  345|  1.59k|        bn_sub_part_words(t, &(a[n]), a, tna, tna - n); /* - */
  346|  1.59k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n); /* + */
  347|  1.59k|        neg = 1;
  348|  1.59k|        break;
  349|    474|    case -1:
  ------------------
  |  Branch (349:5): [True: 474, False: 36.1k]
  ------------------
  350|    682|    case 0:
  ------------------
  |  Branch (350:5): [True: 208, False: 36.4k]
  ------------------
  351|    919|    case 1:
  ------------------
  |  Branch (351:5): [True: 237, False: 36.4k]
  ------------------
  352|  27.6k|    case 2:
  ------------------
  |  Branch (352:5): [True: 26.7k, False: 9.89k]
  ------------------
  353|  27.6k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna); /* + */
  354|  27.6k|        bn_sub_part_words(&(t[n]), b, &(b[n]), tnb, n - tnb); /* - */
  355|  27.6k|        neg = 1;
  356|  27.6k|        break;
  357|    626|    case 3:
  ------------------
  |  Branch (357:5): [True: 626, False: 36.0k]
  ------------------
  358|  2.01k|    case 4:
  ------------------
  |  Branch (358:5): [True: 1.38k, False: 35.2k]
  ------------------
  359|  2.01k|        bn_sub_part_words(t, a, &(a[n]), tna, n - tna);
  360|  2.01k|        bn_sub_part_words(&(t[n]), &(b[n]), b, tnb, tnb - n);
  361|  2.01k|        break;
  362|  36.6k|    }
  363|       |    /*
  364|       |     * The zero case isn't yet implemented here. The speedup would probably
  365|       |     * be negligible.
  366|       |     */
  367|       |# if 0
  368|       |    if (n == 4) {
  369|       |        bn_mul_comba4(&(t[n2]), t, &(t[n]));
  370|       |        bn_mul_comba4(r, a, b);
  371|       |        bn_mul_normal(&(r[n2]), &(a[n]), tn, &(b[n]), tn);
  372|       |        memset(&r[n2 + tn * 2], 0, sizeof(*r) * (n2 - tn * 2));
  373|       |    } else
  374|       |# endif
  375|  36.6k|    if (n == 8) {
  ------------------
  |  Branch (375:9): [True: 6.04k, False: 30.6k]
  ------------------
  376|  6.04k|        bn_mul_comba8(&(t[n2]), t, &(t[n]));
  377|  6.04k|        bn_mul_comba8(r, a, b);
  378|  6.04k|        bn_mul_normal(&(r[n2]), &(a[n]), tna, &(b[n]), tnb);
  379|  6.04k|        memset(&r[n2 + tna + tnb], 0, sizeof(*r) * (n2 - tna - tnb));
  380|  30.6k|    } else {
  381|  30.6k|        p = &(t[n2 * 2]);
  382|  30.6k|        bn_mul_recursive(&(t[n2]), t, &(t[n]), n, 0, 0, p);
  383|  30.6k|        bn_mul_recursive(r, a, b, n, 0, 0, p);
  384|  30.6k|        i = n / 2;
  385|       |        /*
  386|       |         * If there is only a bottom half to the number, just do it
  387|       |         */
  388|  30.6k|        if (tna > tnb)
  ------------------
  |  Branch (388:13): [True: 1.83k, False: 28.7k]
  ------------------
  389|  1.83k|            j = tna - i;
  390|  28.7k|        else
  391|  28.7k|            j = tnb - i;
  392|  30.6k|        if (j == 0) {
  ------------------
  |  Branch (392:13): [True: 1.82k, False: 28.7k]
  ------------------
  393|  1.82k|            bn_mul_recursive(&(r[n2]), &(a[n]), &(b[n]),
  394|  1.82k|                             i, tna - i, tnb - i, p);
  395|  1.82k|            memset(&r[n2 + i * 2], 0, sizeof(*r) * (n2 - i * 2));
  396|  28.7k|        } else if (j > 0) {     /* eg, n == 16, i == 8 and tn == 11 */
  ------------------
  |  Branch (396:20): [True: 10.2k, False: 18.5k]
  ------------------
  397|  10.2k|            bn_mul_part_recursive(&(r[n2]), &(a[n]), &(b[n]),
  398|  10.2k|                                  i, tna - i, tnb - i, p);
  399|  10.2k|            memset(&(r[n2 + tna + tnb]), 0,
  400|  10.2k|                   sizeof(BN_ULONG) * (n2 - tna - tnb));
  401|  18.5k|        } else {                /* (j < 0) eg, n == 16, i == 8 and tn == 5 */
  402|       |
  403|  18.5k|            memset(&r[n2], 0, sizeof(*r) * n2);
  404|  18.5k|            if (tna < BN_MUL_RECURSIVE_SIZE_NORMAL
  ------------------
  |  |  365|  37.0k|# define BN_MUL_RECURSIVE_SIZE_NORMAL            (16)/* 32 less than */
  ------------------
  |  Branch (404:17): [True: 15.9k, False: 2.59k]
  ------------------
  405|  18.5k|                && tnb < BN_MUL_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  365|  15.9k|# define BN_MUL_RECURSIVE_SIZE_NORMAL            (16)/* 32 less than */
  ------------------
  |  Branch (405:20): [True: 15.5k, False: 319]
  ------------------
  406|  15.5k|                bn_mul_normal(&(r[n2]), &(a[n]), tna, &(b[n]), tnb);
  407|  15.5k|            } else {
  408|  3.65k|                for (;;) {
  409|  3.65k|                    i /= 2;
  410|       |                    /*
  411|       |                     * these simplified conditions work exclusively because
  412|       |                     * difference between tna and tnb is 1 or 0
  413|       |                     */
  414|  3.65k|                    if (i < tna || i < tnb) {
  ------------------
  |  Branch (414:25): [True: 1.66k, False: 1.99k]
  |  Branch (414:36): [True: 271, False: 1.72k]
  ------------------
  415|  1.93k|                        bn_mul_part_recursive(&(r[n2]),
  416|  1.93k|                                              &(a[n]), &(b[n]),
  417|  1.93k|                                              i, tna - i, tnb - i, p);
  418|  1.93k|                        break;
  419|  1.93k|                    } else if (i == tna || i == tnb) {
  ------------------
  |  Branch (419:32): [True: 665, False: 1.05k]
  |  Branch (419:44): [True: 319, False: 738]
  ------------------
  420|    984|                        bn_mul_recursive(&(r[n2]),
  421|    984|                                         &(a[n]), &(b[n]),
  422|    984|                                         i, tna - i, tnb - i, p);
  423|    984|                        break;
  424|    984|                    }
  425|  3.65k|                }
  426|  2.91k|            }
  427|  18.5k|        }
  428|  30.6k|    }
  429|       |
  430|       |    /*-
  431|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0]), c1 is the sign
  432|       |     * r[10] holds (a[0]*b[0])
  433|       |     * r[32] holds (b[1]*b[1])
  434|       |     */
  435|       |
  436|  36.6k|    c1 = (int)(bn_add_words(t, r, &(r[n2]), n2));
  437|       |
  438|  36.6k|    if (neg) {                  /* if t[32] is negative */
  ------------------
  |  Branch (438:9): [True: 29.2k, False: 7.38k]
  ------------------
  439|  29.2k|        c1 -= (int)(bn_sub_words(&(t[n2]), t, &(t[n2]), n2));
  440|  29.2k|    } else {
  441|       |        /* Might have a carry */
  442|  7.38k|        c1 += (int)(bn_add_words(&(t[n2]), &(t[n2]), t, n2));
  443|  7.38k|    }
  444|       |
  445|       |    /*-
  446|       |     * t[32] holds (a[0]-a[1])*(b[1]-b[0])+(a[0]*b[0])+(a[1]*b[1])
  447|       |     * r[10] holds (a[0]*b[0])
  448|       |     * r[32] holds (b[1]*b[1])
  449|       |     * c1 holds the carry bits
  450|       |     */
  451|  36.6k|    c1 += (int)(bn_add_words(&(r[n]), &(r[n]), &(t[n2]), n2));
  452|  36.6k|    if (c1) {
  ------------------
  |  Branch (452:9): [True: 1.16k, False: 35.5k]
  ------------------
  453|  1.16k|        p = &(r[n + n2]);
  454|  1.16k|        lo = *p;
  455|  1.16k|        ln = (lo + c1) & BN_MASK2;
  ------------------
  |  |   94|  1.16k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  456|  1.16k|        *p = ln;
  457|       |
  458|       |        /*
  459|       |         * The overflow will stop before we over write words we should not
  460|       |         * overwrite
  461|       |         */
  462|  1.16k|        if (ln < (BN_ULONG)c1) {
  ------------------
  |  Branch (462:13): [True: 390, False: 772]
  ------------------
  463|    981|            do {
  464|    981|                p++;
  465|    981|                lo = *p;
  466|    981|                ln = (lo + 1) & BN_MASK2;
  ------------------
  |  |   94|    981|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  467|    981|                *p = ln;
  468|    981|            } while (ln == 0);
  ------------------
  |  Branch (468:22): [True: 591, False: 390]
  ------------------
  469|    390|        }
  470|  1.16k|    }
  471|  36.6k|}
BN_mul:
  498|   225k|{
  499|   225k|    int ret = bn_mul_fixed_top(r, a, b, ctx);
  500|       |
  501|   225k|    bn_correct_top(r);
  502|   225k|    bn_check_top(r);
  503|       |
  504|   225k|    return ret;
  505|   225k|}
bn_mul_fixed_top:
  508|   238k|{
  509|   238k|    int ret = 0;
  510|   238k|    int top, al, bl;
  511|   238k|    BIGNUM *rr;
  512|   238k|#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
  513|   238k|    int i;
  514|   238k|#endif
  515|   238k|#ifdef BN_RECURSION
  516|   238k|    BIGNUM *t = NULL;
  517|   238k|    int j = 0, k;
  518|   238k|#endif
  519|       |
  520|   238k|    bn_check_top(a);
  521|   238k|    bn_check_top(b);
  522|   238k|    bn_check_top(r);
  523|       |
  524|   238k|    al = a->top;
  525|   238k|    bl = b->top;
  526|       |
  527|   238k|    if ((al == 0) || (bl == 0)) {
  ------------------
  |  Branch (527:9): [True: 3.01k, False: 235k]
  |  Branch (527:22): [True: 1.31k, False: 234k]
  ------------------
  528|  4.33k|        BN_zero(r);
  ------------------
  |  |  202|  4.33k|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  529|  4.33k|        return 1;
  530|  4.33k|    }
  531|   234k|    top = al + bl;
  532|       |
  533|   234k|    BN_CTX_start(ctx);
  534|   234k|    if ((r == a) || (r == b)) {
  ------------------
  |  Branch (534:9): [True: 0, False: 234k]
  |  Branch (534:21): [True: 0, False: 234k]
  ------------------
  535|      0|        if ((rr = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (535:13): [True: 0, False: 0]
  ------------------
  536|      0|            goto err;
  537|      0|    } else
  538|   234k|        rr = r;
  539|       |
  540|   234k|#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
  541|   234k|    i = al - bl;
  542|   234k|#endif
  543|   234k|#ifdef BN_MUL_COMBA
  544|   234k|    if (i == 0) {
  ------------------
  |  Branch (544:9): [True: 175k, False: 59.0k]
  ------------------
  545|       |# if 0
  546|       |        if (al == 4) {
  547|       |            if (bn_wexpand(rr, 8) == NULL)
  548|       |                goto err;
  549|       |            rr->top = 8;
  550|       |            bn_mul_comba4(rr->d, a->d, b->d);
  551|       |            goto end;
  552|       |        }
  553|       |# endif
  554|   175k|        if (al == 8) {
  ------------------
  |  Branch (554:13): [True: 504, False: 174k]
  ------------------
  555|    504|            if (bn_wexpand(rr, 16) == NULL)
  ------------------
  |  Branch (555:17): [True: 0, False: 504]
  ------------------
  556|      0|                goto err;
  557|    504|            rr->top = 16;
  558|    504|            bn_mul_comba8(rr->d, a->d, b->d);
  559|    504|            goto end;
  560|    504|        }
  561|   175k|    }
  562|   233k|#endif                          /* BN_MUL_COMBA */
  563|   233k|#ifdef BN_RECURSION
  564|   233k|    if ((al >= BN_MULL_SIZE_NORMAL) && (bl >= BN_MULL_SIZE_NORMAL)) {
  ------------------
  |  |  364|   233k|# define BN_MULL_SIZE_NORMAL                     (16)/* 32 */
  ------------------
                  if ((al >= BN_MULL_SIZE_NORMAL) && (bl >= BN_MULL_SIZE_NORMAL)) {
  ------------------
  |  |  364|  46.0k|# define BN_MULL_SIZE_NORMAL                     (16)/* 32 */
  ------------------
  |  Branch (564:9): [True: 46.0k, False: 187k]
  |  Branch (564:40): [True: 39.4k, False: 6.62k]
  ------------------
  565|  39.4k|        if (i >= -1 && i <= 1) {
  ------------------
  |  Branch (565:13): [True: 37.9k, False: 1.47k]
  |  Branch (565:24): [True: 37.1k, False: 807]
  ------------------
  566|       |            /*
  567|       |             * Find out the power of two lower or equal to the longest of the
  568|       |             * two numbers
  569|       |             */
  570|  37.1k|            if (i >= 0) {
  ------------------
  |  Branch (570:17): [True: 30.8k, False: 6.35k]
  ------------------
  571|  30.8k|                j = BN_num_bits_word((BN_ULONG)al);
  572|  30.8k|            }
  573|  37.1k|            if (i == -1) {
  ------------------
  |  Branch (573:17): [True: 6.35k, False: 30.8k]
  ------------------
  574|  6.35k|                j = BN_num_bits_word((BN_ULONG)bl);
  575|  6.35k|            }
  576|  37.1k|            j = 1 << (j - 1);
  577|  37.1k|            assert(j <= al || j <= bl);
  578|  37.1k|            k = j + j;
  579|  37.1k|            t = BN_CTX_get(ctx);
  580|  37.1k|            if (t == NULL)
  ------------------
  |  Branch (580:17): [True: 0, False: 37.1k]
  ------------------
  581|      0|                goto err;
  582|  37.1k|            if (al > j || bl > j) {
  ------------------
  |  Branch (582:17): [True: 21.5k, False: 15.5k]
  |  Branch (582:27): [True: 2.85k, False: 12.7k]
  ------------------
  583|  24.4k|                if (bn_wexpand(t, k * 4) == NULL)
  ------------------
  |  Branch (583:21): [True: 0, False: 24.4k]
  ------------------
  584|      0|                    goto err;
  585|  24.4k|                if (bn_wexpand(rr, k * 4) == NULL)
  ------------------
  |  Branch (585:21): [True: 0, False: 24.4k]
  ------------------
  586|      0|                    goto err;
  587|  24.4k|                bn_mul_part_recursive(rr->d, a->d, b->d,
  588|  24.4k|                                      j, al - j, bl - j, t->d);
  589|  24.4k|            } else {            /* al <= j || bl <= j */
  590|       |
  591|  12.7k|                if (bn_wexpand(t, k * 2) == NULL)
  ------------------
  |  Branch (591:21): [True: 0, False: 12.7k]
  ------------------
  592|      0|                    goto err;
  593|  12.7k|                if (bn_wexpand(rr, k * 2) == NULL)
  ------------------
  |  Branch (593:21): [True: 0, False: 12.7k]
  ------------------
  594|      0|                    goto err;
  595|  12.7k|                bn_mul_recursive(rr->d, a->d, b->d, j, al - j, bl - j, t->d);
  596|  12.7k|            }
  597|  37.1k|            rr->top = top;
  598|  37.1k|            goto end;
  599|  37.1k|        }
  600|  39.4k|    }
  601|   196k|#endif                          /* BN_RECURSION */
  602|   196k|    if (bn_wexpand(rr, top) == NULL)
  ------------------
  |  Branch (602:9): [True: 0, False: 196k]
  ------------------
  603|      0|        goto err;
  604|   196k|    rr->top = top;
  605|   196k|    bn_mul_normal(rr->d, a->d, al, b->d, bl);
  606|       |
  607|   196k|#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
  608|   234k| end:
  609|   234k|#endif
  610|   234k|    rr->neg = a->neg ^ b->neg;
  611|   234k|    rr->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   234k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  612|   234k|    if (r != rr && BN_copy(r, rr) == NULL)
  ------------------
  |  Branch (612:9): [True: 0, False: 234k]
  |  Branch (612:20): [True: 0, False: 0]
  ------------------
  613|      0|        goto err;
  614|       |
  615|   234k|    ret = 1;
  616|   234k| err:
  617|   234k|    bn_check_top(r);
  618|   234k|    BN_CTX_end(ctx);
  619|   234k|    return ret;
  620|   234k|}
bn_mul_normal:
  623|   220k|{
  624|   220k|    BN_ULONG *rr;
  ------------------
  |  |   37|   220k|#  define BN_ULONG        unsigned long
  ------------------
  625|       |
  626|   220k|    if (na < nb) {
  ------------------
  |  Branch (626:9): [True: 45.9k, False: 174k]
  ------------------
  627|  45.9k|        int itmp;
  628|  45.9k|        BN_ULONG *ltmp;
  ------------------
  |  |   37|  45.9k|#  define BN_ULONG        unsigned long
  ------------------
  629|       |
  630|  45.9k|        itmp = na;
  631|  45.9k|        na = nb;
  632|  45.9k|        nb = itmp;
  633|  45.9k|        ltmp = a;
  634|  45.9k|        a = b;
  635|  45.9k|        b = ltmp;
  636|       |
  637|  45.9k|    }
  638|   220k|    rr = &(r[na]);
  639|   220k|    if (nb <= 0) {
  ------------------
  |  Branch (639:9): [True: 4.29k, False: 216k]
  ------------------
  640|  4.29k|        (void)bn_mul_words(r, a, na, 0);
  641|  4.29k|        return;
  642|  4.29k|    } else
  643|   216k|        rr[0] = bn_mul_words(r, a, na, b[0]);
  644|       |
  645|   251k|    for (;;) {
  646|   251k|        if (--nb <= 0)
  ------------------
  |  Branch (646:13): [True: 184k, False: 67.7k]
  ------------------
  647|   184k|            return;
  648|  67.7k|        rr[1] = bn_mul_add_words(&(r[1]), a, na, b[1]);
  649|  67.7k|        if (--nb <= 0)
  ------------------
  |  Branch (649:13): [True: 11.8k, False: 55.9k]
  ------------------
  650|  11.8k|            return;
  651|  55.9k|        rr[2] = bn_mul_add_words(&(r[2]), a, na, b[2]);
  652|  55.9k|        if (--nb <= 0)
  ------------------
  |  Branch (652:13): [True: 12.1k, False: 43.8k]
  ------------------
  653|  12.1k|            return;
  654|  43.8k|        rr[3] = bn_mul_add_words(&(r[3]), a, na, b[3]);
  655|  43.8k|        if (--nb <= 0)
  ------------------
  |  Branch (655:13): [True: 8.34k, False: 35.4k]
  ------------------
  656|  8.34k|            return;
  657|  35.4k|        rr[4] = bn_mul_add_words(&(r[4]), a, na, b[4]);
  658|  35.4k|        rr += 4;
  659|  35.4k|        r += 4;
  660|  35.4k|        b += 4;
  661|  35.4k|    }
  662|   216k|}

BN_RECP_CTX_init:
   14|  1.52k|{
   15|  1.52k|    memset(recp, 0, sizeof(*recp));
   16|  1.52k|    bn_init(&(recp->N));
   17|  1.52k|    bn_init(&(recp->Nr));
   18|  1.52k|}
BN_RECP_CTX_free:
   34|  1.52k|{
   35|  1.52k|    if (recp == NULL)
  ------------------
  |  Branch (35:9): [True: 0, False: 1.52k]
  ------------------
   36|      0|        return;
   37|  1.52k|    BN_free(&recp->N);
   38|  1.52k|    BN_free(&recp->Nr);
   39|  1.52k|    if (recp->flags & BN_FLG_MALLOCED)
  ------------------
  |  |   58|  1.52k|# define BN_FLG_MALLOCED         0x01
  ------------------
  |  Branch (39:9): [True: 0, False: 1.52k]
  ------------------
   40|      0|        OPENSSL_free(recp);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   41|  1.52k|}
BN_RECP_CTX_set:
   44|  1.52k|{
   45|  1.52k|    if (BN_is_zero(d) || !BN_copy(&(recp->N), d))
  ------------------
  |  Branch (45:9): [True: 0, False: 1.52k]
  |  Branch (45:26): [True: 0, False: 1.52k]
  ------------------
   46|      0|        return 0;
   47|  1.52k|    BN_zero(&(recp->Nr));
  ------------------
  |  |  202|  1.52k|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
   48|  1.52k|    recp->num_bits = BN_num_bits(d);
   49|  1.52k|    recp->shift = 0;
   50|  1.52k|    return 1;
   51|  1.52k|}
BN_mod_mul_reciprocal:
   55|   109k|{
   56|   109k|    int ret = 0;
   57|   109k|    BIGNUM *a;
   58|   109k|    const BIGNUM *ca;
   59|       |
   60|   109k|    BN_CTX_start(ctx);
   61|   109k|    if ((a = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (61:9): [True: 0, False: 109k]
  ------------------
   62|      0|        goto err;
   63|   109k|    if (y != NULL) {
  ------------------
  |  Branch (63:9): [True: 109k, False: 0]
  ------------------
   64|   109k|        if (x == y) {
  ------------------
  |  Branch (64:13): [True: 89.4k, False: 19.9k]
  ------------------
   65|  89.4k|            if (!BN_sqr(a, x, ctx))
  ------------------
  |  Branch (65:17): [True: 0, False: 89.4k]
  ------------------
   66|      0|                goto err;
   67|  89.4k|        } else {
   68|  19.9k|            if (!BN_mul(a, x, y, ctx))
  ------------------
  |  Branch (68:17): [True: 0, False: 19.9k]
  ------------------
   69|      0|                goto err;
   70|  19.9k|        }
   71|   109k|        ca = a;
   72|   109k|    } else
   73|      0|        ca = x;                 /* Just do the mod */
   74|       |
   75|   109k|    ret = BN_div_recp(NULL, r, ca, recp, ctx);
   76|   109k| err:
   77|   109k|    BN_CTX_end(ctx);
   78|   109k|    bn_check_top(r);
   79|   109k|    return ret;
   80|   109k|}
BN_div_recp:
   84|   109k|{
   85|   109k|    int i, j, ret = 0;
   86|   109k|    BIGNUM *a, *b, *d, *r;
   87|       |
   88|   109k|    BN_CTX_start(ctx);
   89|   109k|    d = (dv != NULL) ? dv : BN_CTX_get(ctx);
  ------------------
  |  Branch (89:9): [True: 0, False: 109k]
  ------------------
   90|   109k|    r = (rem != NULL) ? rem : BN_CTX_get(ctx);
  ------------------
  |  Branch (90:9): [True: 109k, False: 0]
  ------------------
   91|   109k|    a = BN_CTX_get(ctx);
   92|   109k|    b = BN_CTX_get(ctx);
   93|   109k|    if (b == NULL)
  ------------------
  |  Branch (93:9): [True: 0, False: 109k]
  ------------------
   94|      0|        goto err;
   95|       |
   96|   109k|    if (BN_ucmp(m, &(recp->N)) < 0) {
  ------------------
  |  Branch (96:9): [True: 21.3k, False: 88.0k]
  ------------------
   97|  21.3k|        BN_zero(d);
  ------------------
  |  |  202|  21.3k|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
   98|  21.3k|        if (!BN_copy(r, m)) {
  ------------------
  |  Branch (98:13): [True: 0, False: 21.3k]
  ------------------
   99|      0|            BN_CTX_end(ctx);
  100|      0|            return 0;
  101|      0|        }
  102|  21.3k|        BN_CTX_end(ctx);
  103|  21.3k|        return 1;
  104|  21.3k|    }
  105|       |
  106|       |    /*
  107|       |     * We want the remainder Given input of ABCDEF / ab we need multiply
  108|       |     * ABCDEF by 3 digests of the reciprocal of ab
  109|       |     */
  110|       |
  111|       |    /* i := max(BN_num_bits(m), 2*BN_num_bits(N)) */
  112|  88.0k|    i = BN_num_bits(m);
  113|  88.0k|    j = recp->num_bits << 1;
  114|  88.0k|    if (j > i)
  ------------------
  |  Branch (114:9): [True: 73.4k, False: 14.6k]
  ------------------
  115|  73.4k|        i = j;
  116|       |
  117|       |    /* Nr := round(2^i / N) */
  118|  88.0k|    if (i != recp->shift)
  ------------------
  |  Branch (118:9): [True: 1.48k, False: 86.6k]
  ------------------
  119|  1.48k|        recp->shift = BN_reciprocal(&(recp->Nr), &(recp->N), i, ctx);
  120|       |    /* BN_reciprocal could have returned -1 for an error */
  121|  88.0k|    if (recp->shift == -1)
  ------------------
  |  Branch (121:9): [True: 0, False: 88.0k]
  ------------------
  122|      0|        goto err;
  123|       |
  124|       |    /*-
  125|       |     * d := |round(round(m / 2^BN_num_bits(N)) * recp->Nr / 2^(i - BN_num_bits(N)))|
  126|       |     *    = |round(round(m / 2^BN_num_bits(N)) * round(2^i / N) / 2^(i - BN_num_bits(N)))|
  127|       |     *   <= |(m / 2^BN_num_bits(N)) * (2^i / N) * (2^BN_num_bits(N) / 2^i)|
  128|       |     *    = |m/N|
  129|       |     */
  130|  88.0k|    if (!BN_rshift(a, m, recp->num_bits))
  ------------------
  |  Branch (130:9): [True: 0, False: 88.0k]
  ------------------
  131|      0|        goto err;
  132|  88.0k|    if (!BN_mul(b, a, &(recp->Nr), ctx))
  ------------------
  |  Branch (132:9): [True: 0, False: 88.0k]
  ------------------
  133|      0|        goto err;
  134|  88.0k|    if (!BN_rshift(d, b, i - recp->num_bits))
  ------------------
  |  Branch (134:9): [True: 0, False: 88.0k]
  ------------------
  135|      0|        goto err;
  136|  88.0k|    d->neg = 0;
  137|       |
  138|  88.0k|    if (!BN_mul(b, &(recp->N), d, ctx))
  ------------------
  |  Branch (138:9): [True: 0, False: 88.0k]
  ------------------
  139|      0|        goto err;
  140|  88.0k|    if (!BN_usub(r, m, b))
  ------------------
  |  Branch (140:9): [True: 0, False: 88.0k]
  ------------------
  141|      0|        goto err;
  142|  88.0k|    r->neg = 0;
  143|       |
  144|  88.0k|    j = 0;
  145|   153k|    while (BN_ucmp(r, &(recp->N)) >= 0) {
  ------------------
  |  Branch (145:12): [True: 65.1k, False: 88.0k]
  ------------------
  146|  65.1k|        if (j++ > 2) {
  ------------------
  |  Branch (146:13): [True: 0, False: 65.1k]
  ------------------
  147|      0|            ERR_raise(ERR_LIB_BN, BN_R_BAD_RECIPROCAL);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  148|      0|            goto err;
  149|      0|        }
  150|  65.1k|        if (!BN_usub(r, r, &(recp->N)))
  ------------------
  |  Branch (150:13): [True: 0, False: 65.1k]
  ------------------
  151|      0|            goto err;
  152|  65.1k|        if (!BN_add_word(d, 1))
  ------------------
  |  Branch (152:13): [True: 0, False: 65.1k]
  ------------------
  153|      0|            goto err;
  154|  65.1k|    }
  155|       |
  156|  88.0k|    r->neg = BN_is_zero(r) ? 0 : m->neg;
  ------------------
  |  Branch (156:14): [True: 54, False: 88.0k]
  ------------------
  157|  88.0k|    d->neg = m->neg ^ recp->N.neg;
  158|  88.0k|    ret = 1;
  159|  88.0k| err:
  160|  88.0k|    BN_CTX_end(ctx);
  161|  88.0k|    bn_check_top(dv);
  162|  88.0k|    bn_check_top(rem);
  163|  88.0k|    return ret;
  164|  88.0k|}
BN_reciprocal:
  173|  1.48k|{
  174|  1.48k|    int ret = -1;
  175|  1.48k|    BIGNUM *t;
  176|       |
  177|  1.48k|    BN_CTX_start(ctx);
  178|  1.48k|    if ((t = BN_CTX_get(ctx)) == NULL)
  ------------------
  |  Branch (178:9): [True: 0, False: 1.48k]
  ------------------
  179|      0|        goto err;
  180|       |
  181|  1.48k|    if (!BN_set_bit(t, len))
  ------------------
  |  Branch (181:9): [True: 0, False: 1.48k]
  ------------------
  182|      0|        goto err;
  183|       |
  184|  1.48k|    if (!BN_div(r, NULL, t, m, ctx))
  ------------------
  |  Branch (184:9): [True: 0, False: 1.48k]
  ------------------
  185|      0|        goto err;
  186|       |
  187|  1.48k|    ret = len;
  188|  1.48k| err:
  189|  1.48k|    bn_check_top(r);
  190|  1.48k|    BN_CTX_end(ctx);
  191|  1.48k|    return ret;
  192|  1.48k|}

BN_rshift1:
   46|  56.9k|{
   47|  56.9k|    BN_ULONG *ap, *rp, t, c;
  ------------------
  |  |   37|  56.9k|#  define BN_ULONG        unsigned long
  ------------------
   48|  56.9k|    int i;
   49|       |
   50|  56.9k|    bn_check_top(r);
   51|  56.9k|    bn_check_top(a);
   52|       |
   53|  56.9k|    if (BN_is_zero(a)) {
  ------------------
  |  Branch (53:9): [True: 0, False: 56.9k]
  ------------------
   54|      0|        BN_zero(r);
  ------------------
  |  |  202|      0|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
   55|      0|        return 1;
   56|      0|    }
   57|  56.9k|    i = a->top;
   58|  56.9k|    ap = a->d;
   59|  56.9k|    if (a != r) {
  ------------------
  |  Branch (59:9): [True: 0, False: 56.9k]
  ------------------
   60|      0|        if (bn_wexpand(r, i) == NULL)
  ------------------
  |  Branch (60:13): [True: 0, False: 0]
  ------------------
   61|      0|            return 0;
   62|      0|        r->neg = a->neg;
   63|      0|    }
   64|  56.9k|    rp = r->d;
   65|  56.9k|    r->top = i;
   66|  56.9k|    t = ap[--i];
   67|  56.9k|    rp[i] = t >> 1;
   68|  56.9k|    c = t << (BN_BITS2 - 1);
  ------------------
  |  |   54|  56.9k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  56.9k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
   69|  56.9k|    r->top -= (t == 1);
   70|  79.8k|    while (i > 0) {
  ------------------
  |  Branch (70:12): [True: 22.9k, False: 56.9k]
  ------------------
   71|  22.9k|        t = ap[--i];
   72|  22.9k|        rp[i] = ((t >> 1) & BN_MASK2) | c;
  ------------------
  |  |   94|  22.9k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
   73|  22.9k|        c = t << (BN_BITS2 - 1);
  ------------------
  |  |   54|  22.9k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|  22.9k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
   74|  22.9k|    }
   75|  56.9k|    if (!r->top)
  ------------------
  |  Branch (75:9): [True: 0, False: 56.9k]
  ------------------
   76|      0|        r->neg = 0; /* don't allow negative zero */
   77|  56.9k|    bn_check_top(r);
   78|  56.9k|    return 1;
   79|  56.9k|}
BN_lshift:
   82|  1.30k|{
   83|  1.30k|    int ret;
   84|       |
   85|  1.30k|    if (n < 0) {
  ------------------
  |  Branch (85:9): [True: 0, False: 1.30k]
  ------------------
   86|      0|        ERR_raise(ERR_LIB_BN, BN_R_INVALID_SHIFT);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
   87|      0|        return 0;
   88|      0|    }
   89|       |
   90|  1.30k|    ret = bn_lshift_fixed_top(r, a, n);
   91|       |
   92|  1.30k|    bn_correct_top(r);
   93|  1.30k|    bn_check_top(r);
   94|       |
   95|  1.30k|    return ret;
   96|  1.30k|}
bn_lshift_fixed_top:
  105|   200k|{
  106|   200k|    int i, nw;
  107|   200k|    unsigned int lb, rb;
  108|   200k|    BN_ULONG *t, *f;
  ------------------
  |  |   37|   200k|#  define BN_ULONG        unsigned long
  ------------------
  109|   200k|    BN_ULONG l, m, rmask = 0;
  ------------------
  |  |   37|   200k|#  define BN_ULONG        unsigned long
  ------------------
  110|       |
  111|   200k|    assert(n >= 0);
  112|       |
  113|   200k|    bn_check_top(r);
  114|   200k|    bn_check_top(a);
  115|       |
  116|   200k|    nw = n / BN_BITS2;
  ------------------
  |  |   54|   200k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   200k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  117|   200k|    if (bn_wexpand(r, a->top + nw + 1) == NULL)
  ------------------
  |  Branch (117:9): [True: 0, False: 200k]
  ------------------
  118|      0|        return 0;
  119|       |
  120|   200k|    if (a->top != 0) {
  ------------------
  |  Branch (120:9): [True: 191k, False: 9.09k]
  ------------------
  121|   191k|        lb = (unsigned int)n % BN_BITS2;
  ------------------
  |  |   54|   191k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   191k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  122|   191k|        rb = BN_BITS2 - lb;
  ------------------
  |  |   54|   191k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   191k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  123|   191k|        rb %= BN_BITS2;            /* say no to undefined behaviour */
  ------------------
  |  |   54|   191k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   191k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  124|   191k|        rmask = (BN_ULONG)0 - rb;  /* rmask = 0 - (rb != 0) */
  125|   191k|        rmask |= rmask >> 8;
  126|   191k|        f = &(a->d[0]);
  127|   191k|        t = &(r->d[nw]);
  128|   191k|        l = f[a->top - 1];
  129|   191k|        t[a->top] = (l >> rb) & rmask;
  130|  2.01M|        for (i = a->top - 1; i > 0; i--) {
  ------------------
  |  Branch (130:30): [True: 1.82M, False: 191k]
  ------------------
  131|  1.82M|            m = l << lb;
  132|  1.82M|            l = f[i - 1];
  133|  1.82M|            t[i] = (m | ((l >> rb) & rmask)) & BN_MASK2;
  ------------------
  |  |   94|  1.82M|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  134|  1.82M|        }
  135|   191k|        t[0] = (l << lb) & BN_MASK2;
  ------------------
  |  |   94|   191k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  136|   191k|    } else {
  137|       |        /* shouldn't happen, but formally required */
  138|  9.09k|        r->d[nw] = 0;
  139|  9.09k|    }
  140|   200k|    if (nw != 0)
  ------------------
  |  Branch (140:9): [True: 1.30k, False: 199k]
  ------------------
  141|  1.30k|        memset(r->d, 0, sizeof(*t) * nw);
  142|       |
  143|   200k|    r->neg = a->neg;
  144|   200k|    r->top = a->top + nw + 1;
  145|   200k|    r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   200k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  146|       |
  147|   200k|    return 1;
  148|   200k|}
BN_rshift:
  151|   223k|{
  152|   223k|    int ret = 0;
  153|       |
  154|   223k|    if (n < 0) {
  ------------------
  |  Branch (154:9): [True: 0, False: 223k]
  ------------------
  155|      0|        ERR_raise(ERR_LIB_BN, BN_R_INVALID_SHIFT);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  156|      0|        return 0;
  157|      0|    }
  158|       |
  159|   223k|    bn_check_top(r);
  160|   223k|    bn_check_top(a);
  161|       |
  162|   223k|    ret = bn_rshift_fixed_top(r, a, n);
  163|       |
  164|   223k|    bn_correct_top(r);
  165|   223k|    bn_check_top(r);
  166|       |
  167|   223k|    return ret;
  168|   223k|}
bn_rshift_fixed_top:
  177|   420k|{
  178|   420k|    int i, top, nw;
  179|   420k|    unsigned int lb, rb;
  180|   420k|    BN_ULONG *t, *f;
  ------------------
  |  |   37|   420k|#  define BN_ULONG        unsigned long
  ------------------
  181|   420k|    BN_ULONG l, m, mask;
  ------------------
  |  |   37|   420k|#  define BN_ULONG        unsigned long
  ------------------
  182|       |
  183|   420k|    assert(n >= 0);
  184|       |
  185|   420k|    nw = n / BN_BITS2;
  ------------------
  |  |   54|   420k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   420k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  186|   420k|    if (nw >= a->top) {
  ------------------
  |  Branch (186:9): [True: 1.32k, False: 419k]
  ------------------
  187|       |        /* shouldn't happen, but formally required */
  188|  1.32k|        BN_zero(r);
  ------------------
  |  |  202|  1.32k|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  189|  1.32k|        return 1;
  190|  1.32k|    }
  191|       |
  192|   419k|    rb = (unsigned int)n % BN_BITS2;
  ------------------
  |  |   54|   419k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   419k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  193|   419k|    lb = BN_BITS2 - rb;
  ------------------
  |  |   54|   419k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   419k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  194|   419k|    lb %= BN_BITS2;            /* say no to undefined behaviour */
  ------------------
  |  |   54|   419k|# define BN_BITS2       (BN_BYTES * 8)
  |  |  ------------------
  |  |  |  |   38|   419k|#  define BN_BYTES        8
  |  |  ------------------
  ------------------
  195|   419k|    mask = (BN_ULONG)0 - lb;   /* mask = 0 - (lb != 0) */
  196|   419k|    mask |= mask >> 8;
  197|   419k|    top = a->top - nw;
  198|   419k|    if (r != a && bn_wexpand(r, top) == NULL)
  ------------------
  |  Branch (198:9): [True: 371k, False: 47.7k]
  |  Branch (198:19): [True: 0, False: 371k]
  ------------------
  199|      0|        return 0;
  200|       |
  201|   419k|    t = &(r->d[0]);
  202|   419k|    f = &(a->d[nw]);
  203|   419k|    l = f[0];
  204|  3.53M|    for (i = 0; i < top - 1; i++) {
  ------------------
  |  Branch (204:17): [True: 3.11M, False: 419k]
  ------------------
  205|  3.11M|        m = f[i + 1];
  206|  3.11M|        t[i] = (l >> rb) | ((m << lb) & mask);
  207|  3.11M|        l = m;
  208|  3.11M|    }
  209|   419k|    t[i] = l >> rb;
  210|       |
  211|   419k|    r->neg = a->neg;
  212|   419k|    r->top = top;
  213|   419k|    r->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   419k|#  define BN_FLG_FIXED_TOP 0
  ------------------
  214|       |
  215|   419k|    return 1;
  216|   419k|}

BN_sqr:
   18|   230k|{
   19|   230k|    int ret = bn_sqr_fixed_top(r, a, ctx);
   20|       |
   21|   230k|    bn_correct_top(r);
   22|   230k|    bn_check_top(r);
   23|       |
   24|   230k|    return ret;
   25|   230k|}
bn_sqr_fixed_top:
   28|   348k|{
   29|   348k|    int max, al;
   30|   348k|    int ret = 0;
   31|   348k|    BIGNUM *tmp, *rr;
   32|       |
   33|   348k|    bn_check_top(a);
   34|       |
   35|   348k|    al = a->top;
   36|   348k|    if (al <= 0) {
  ------------------
  |  Branch (36:9): [True: 14.6k, False: 333k]
  ------------------
   37|  14.6k|        r->top = 0;
   38|  14.6k|        r->neg = 0;
   39|  14.6k|        return 1;
   40|  14.6k|    }
   41|       |
   42|   333k|    BN_CTX_start(ctx);
   43|   333k|    rr = (a != r) ? r : BN_CTX_get(ctx);
  ------------------
  |  Branch (43:10): [True: 333k, False: 0]
  ------------------
   44|   333k|    tmp = BN_CTX_get(ctx);
   45|   333k|    if (rr == NULL || tmp == NULL)
  ------------------
  |  Branch (45:9): [True: 0, False: 333k]
  |  Branch (45:23): [True: 0, False: 333k]
  ------------------
   46|      0|        goto err;
   47|       |
   48|   333k|    max = 2 * al;               /* Non-zero (from above) */
   49|   333k|    if (bn_wexpand(rr, max) == NULL)
  ------------------
  |  Branch (49:9): [True: 0, False: 333k]
  ------------------
   50|      0|        goto err;
   51|       |
   52|   333k|    if (al == 4) {
  ------------------
  |  Branch (52:9): [True: 2.40k, False: 331k]
  ------------------
   53|       |#ifndef BN_SQR_COMBA
   54|       |        BN_ULONG t[8];
   55|       |        bn_sqr_normal(rr->d, a->d, 4, t);
   56|       |#else
   57|  2.40k|        bn_sqr_comba4(rr->d, a->d);
   58|  2.40k|#endif
   59|   331k|    } else if (al == 8) {
  ------------------
  |  Branch (59:16): [True: 635, False: 330k]
  ------------------
   60|       |#ifndef BN_SQR_COMBA
   61|       |        BN_ULONG t[16];
   62|       |        bn_sqr_normal(rr->d, a->d, 8, t);
   63|       |#else
   64|    635|        bn_sqr_comba8(rr->d, a->d);
   65|    635|#endif
   66|   330k|    } else {
   67|   330k|#if defined(BN_RECURSION)
   68|   330k|        if (al < BN_SQR_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  366|   330k|# define BN_SQR_RECURSIVE_SIZE_NORMAL            (16)/* 32 */
  ------------------
  |  Branch (68:13): [True: 300k, False: 30.3k]
  ------------------
   69|   300k|            BN_ULONG t[BN_SQR_RECURSIVE_SIZE_NORMAL * 2];
  ------------------
  |  |   37|   300k|#  define BN_ULONG        unsigned long
  ------------------
   70|   300k|            bn_sqr_normal(rr->d, a->d, al, t);
   71|   300k|        } else {
   72|  30.3k|            int j, k;
   73|       |
   74|  30.3k|            j = BN_num_bits_word((BN_ULONG)al);
   75|  30.3k|            j = 1 << (j - 1);
   76|  30.3k|            k = j + j;
   77|  30.3k|            if (al == j) {
  ------------------
  |  Branch (77:17): [True: 12.1k, False: 18.1k]
  ------------------
   78|  12.1k|                if (bn_wexpand(tmp, k * 2) == NULL)
  ------------------
  |  Branch (78:21): [True: 0, False: 12.1k]
  ------------------
   79|      0|                    goto err;
   80|  12.1k|                bn_sqr_recursive(rr->d, a->d, al, tmp->d);
   81|  18.1k|            } else {
   82|  18.1k|                if (bn_wexpand(tmp, max) == NULL)
  ------------------
  |  Branch (82:21): [True: 0, False: 18.1k]
  ------------------
   83|      0|                    goto err;
   84|  18.1k|                bn_sqr_normal(rr->d, a->d, al, tmp->d);
   85|  18.1k|            }
   86|  30.3k|        }
   87|       |#else
   88|       |        if (bn_wexpand(tmp, max) == NULL)
   89|       |            goto err;
   90|       |        bn_sqr_normal(rr->d, a->d, al, tmp->d);
   91|       |#endif
   92|   330k|    }
   93|       |
   94|   333k|    rr->neg = 0;
   95|   333k|    rr->top = max;
   96|   333k|    rr->flags |= BN_FLG_FIXED_TOP;
  ------------------
  |  |  226|   333k|#  define BN_FLG_FIXED_TOP 0
  ------------------
   97|   333k|    if (r != rr && BN_copy(r, rr) == NULL)
  ------------------
  |  Branch (97:9): [True: 0, False: 333k]
  |  Branch (97:20): [True: 0, False: 0]
  ------------------
   98|      0|        goto err;
   99|       |
  100|   333k|    ret = 1;
  101|   333k| err:
  102|   333k|    bn_check_top(rr);
  103|   333k|    bn_check_top(tmp);
  104|   333k|    BN_CTX_end(ctx);
  105|   333k|    return ret;
  106|   333k|}
bn_sqr_normal:
  110|   318k|{
  111|   318k|    int i, j, max;
  112|   318k|    const BN_ULONG *ap;
  113|   318k|    BN_ULONG *rp;
  ------------------
  |  |   37|   318k|#  define BN_ULONG        unsigned long
  ------------------
  114|       |
  115|   318k|    max = n * 2;
  116|   318k|    ap = a;
  117|   318k|    rp = r;
  118|   318k|    rp[0] = rp[max - 1] = 0;
  119|   318k|    rp++;
  120|   318k|    j = n;
  121|       |
  122|   318k|    if (--j > 0) {
  ------------------
  |  Branch (122:9): [True: 30.7k, False: 287k]
  ------------------
  123|  30.7k|        ap++;
  124|  30.7k|        rp[j] = bn_mul_words(rp, ap, j, ap[-1]);
  125|  30.7k|        rp += 2;
  126|  30.7k|    }
  127|       |
  128|  1.19M|    for (i = n - 2; i > 0; i--) {
  ------------------
  |  Branch (128:21): [True: 872k, False: 318k]
  ------------------
  129|   872k|        j--;
  130|   872k|        ap++;
  131|   872k|        rp[j] = bn_mul_add_words(rp, ap, j, ap[-1]);
  132|   872k|        rp += 2;
  133|   872k|    }
  134|       |
  135|   318k|    bn_add_words(r, r, r, max);
  136|       |
  137|       |    /* There will not be a carry */
  138|       |
  139|   318k|    bn_sqr_words(tmp, a, n);
  140|       |
  141|   318k|    bn_add_words(r, r, tmp, max);
  142|   318k|}
bn_sqr_recursive:
  157|   102k|{
  158|   102k|    int n = n2 / 2;
  159|   102k|    int zero, c1;
  160|   102k|    BN_ULONG ln, lo, *p;
  ------------------
  |  |   37|   102k|#  define BN_ULONG        unsigned long
  ------------------
  161|       |
  162|   102k|    if (n2 == 4) {
  ------------------
  |  Branch (162:9): [True: 0, False: 102k]
  ------------------
  163|       |# ifndef BN_SQR_COMBA
  164|       |        bn_sqr_normal(r, a, 4, t);
  165|       |# else
  166|      0|        bn_sqr_comba4(r, a);
  167|      0|# endif
  168|      0|        return;
  169|   102k|    } else if (n2 == 8) {
  ------------------
  |  Branch (169:16): [True: 72.1k, False: 30.3k]
  ------------------
  170|       |# ifndef BN_SQR_COMBA
  171|       |        bn_sqr_normal(r, a, 8, t);
  172|       |# else
  173|  72.1k|        bn_sqr_comba8(r, a);
  174|  72.1k|# endif
  175|  72.1k|        return;
  176|  72.1k|    }
  177|  30.3k|    if (n2 < BN_SQR_RECURSIVE_SIZE_NORMAL) {
  ------------------
  |  |  366|  30.3k|# define BN_SQR_RECURSIVE_SIZE_NORMAL            (16)/* 32 */
  ------------------
  |  Branch (177:9): [True: 0, False: 30.3k]
  ------------------
  178|      0|        bn_sqr_normal(r, a, n2, t);
  179|      0|        return;
  180|      0|    }
  181|       |    /* r=(a[0]-a[1])*(a[1]-a[0]) */
  182|  30.3k|    c1 = bn_cmp_words(a, &(a[n]), n);
  183|  30.3k|    zero = 0;
  184|  30.3k|    if (c1 > 0)
  ------------------
  |  Branch (184:9): [True: 17.1k, False: 13.2k]
  ------------------
  185|  17.1k|        bn_sub_words(t, a, &(a[n]), n);
  186|  13.2k|    else if (c1 < 0)
  ------------------
  |  Branch (186:14): [True: 12.4k, False: 792]
  ------------------
  187|  12.4k|        bn_sub_words(t, &(a[n]), a, n);
  188|    792|    else
  189|    792|        zero = 1;
  190|       |
  191|       |    /* The result will always be negative unless it is zero */
  192|  30.3k|    p = &(t[n2 * 2]);
  193|       |
  194|  30.3k|    if (!zero)
  ------------------
  |  Branch (194:9): [True: 29.5k, False: 792]
  ------------------
  195|  29.5k|        bn_sqr_recursive(&(t[n2]), t, n, p);
  196|    792|    else
  197|    792|        memset(&t[n2], 0, sizeof(*t) * n2);
  198|  30.3k|    bn_sqr_recursive(r, a, n, p);
  199|  30.3k|    bn_sqr_recursive(&(r[n2]), &(a[n]), n, p);
  200|       |
  201|       |    /*-
  202|       |     * t[32] holds (a[0]-a[1])*(a[1]-a[0]), it is negative or zero
  203|       |     * r[10] holds (a[0]*b[0])
  204|       |     * r[32] holds (b[1]*b[1])
  205|       |     */
  206|       |
  207|  30.3k|    c1 = (int)(bn_add_words(t, r, &(r[n2]), n2));
  208|       |
  209|       |    /* t[32] is negative */
  210|  30.3k|    c1 -= (int)(bn_sub_words(&(t[n2]), t, &(t[n2]), n2));
  211|       |
  212|       |    /*-
  213|       |     * t[32] holds (a[0]-a[1])*(a[1]-a[0])+(a[0]*a[0])+(a[1]*a[1])
  214|       |     * r[10] holds (a[0]*a[0])
  215|       |     * r[32] holds (a[1]*a[1])
  216|       |     * c1 holds the carry bits
  217|       |     */
  218|  30.3k|    c1 += (int)(bn_add_words(&(r[n]), &(r[n]), &(t[n2]), n2));
  219|  30.3k|    if (c1) {
  ------------------
  |  Branch (219:9): [True: 9.82k, False: 20.5k]
  ------------------
  220|  9.82k|        p = &(r[n + n2]);
  221|  9.82k|        lo = *p;
  222|  9.82k|        ln = (lo + c1) & BN_MASK2;
  ------------------
  |  |   94|  9.82k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  223|  9.82k|        *p = ln;
  224|       |
  225|       |        /*
  226|       |         * The overflow will stop before we over write words we should not
  227|       |         * overwrite
  228|       |         */
  229|  9.82k|        if (ln < (BN_ULONG)c1) {
  ------------------
  |  Branch (229:13): [True: 392, False: 9.43k]
  ------------------
  230|    828|            do {
  231|    828|                p++;
  232|    828|                lo = *p;
  233|    828|                ln = (lo + 1) & BN_MASK2;
  ------------------
  |  |   94|    828|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  234|    828|                *p = ln;
  235|    828|            } while (ln == 0);
  ------------------
  |  Branch (235:22): [True: 436, False: 392]
  ------------------
  236|    392|        }
  237|  9.82k|    }
  238|  30.3k|}

BN_add_word:
   99|  65.1k|{
  100|  65.1k|    BN_ULONG l;
  ------------------
  |  |   37|  65.1k|#  define BN_ULONG        unsigned long
  ------------------
  101|  65.1k|    int i;
  102|       |
  103|  65.1k|    bn_check_top(a);
  104|  65.1k|    w &= BN_MASK2;
  ------------------
  |  |   94|  65.1k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  105|       |
  106|       |    /* degenerate case: w is zero */
  107|  65.1k|    if (!w)
  ------------------
  |  Branch (107:9): [True: 0, False: 65.1k]
  ------------------
  108|      0|        return 1;
  109|       |    /* degenerate case: a is zero */
  110|  65.1k|    if (BN_is_zero(a))
  ------------------
  |  Branch (110:9): [True: 1.27k, False: 63.8k]
  ------------------
  111|  1.27k|        return BN_set_word(a, w);
  112|       |    /* handle 'a' when negative */
  113|  63.8k|    if (a->neg) {
  ------------------
  |  Branch (113:9): [True: 0, False: 63.8k]
  ------------------
  114|      0|        a->neg = 0;
  115|      0|        i = BN_sub_word(a, w);
  116|      0|        if (!BN_is_zero(a))
  ------------------
  |  Branch (116:13): [True: 0, False: 0]
  ------------------
  117|      0|            a->neg = !(a->neg);
  118|      0|        return i;
  119|      0|    }
  120|   129k|    for (i = 0; w != 0 && i < a->top; i++) {
  ------------------
  |  Branch (120:17): [True: 65.3k, False: 63.6k]
  |  Branch (120:27): [True: 65.1k, False: 195]
  ------------------
  121|  65.1k|        a->d[i] = l = (a->d[i] + w) & BN_MASK2;
  ------------------
  |  |   94|  65.1k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  122|  65.1k|        w = (w > l) ? 1 : 0;
  ------------------
  |  Branch (122:13): [True: 1.47k, False: 63.6k]
  ------------------
  123|  65.1k|    }
  124|  63.8k|    if (w && i == a->top) {
  ------------------
  |  Branch (124:9): [True: 195, False: 63.6k]
  |  Branch (124:14): [True: 195, False: 0]
  ------------------
  125|    195|        if (bn_wexpand(a, a->top + 1) == NULL)
  ------------------
  |  Branch (125:13): [True: 0, False: 195]
  ------------------
  126|      0|            return 0;
  127|    195|        a->top++;
  128|    195|        a->d[i] = w;
  129|    195|    }
  130|  63.8k|    bn_check_top(a);
  131|  63.8k|    return 1;
  132|  63.8k|}
BN_sub_word:
  135|  1.28k|{
  136|  1.28k|    int i;
  137|       |
  138|  1.28k|    bn_check_top(a);
  139|  1.28k|    w &= BN_MASK2;
  ------------------
  |  |   94|  1.28k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  140|       |
  141|       |    /* degenerate case: w is zero */
  142|  1.28k|    if (!w)
  ------------------
  |  Branch (142:9): [True: 0, False: 1.28k]
  ------------------
  143|      0|        return 1;
  144|       |    /* degenerate case: a is zero */
  145|  1.28k|    if (BN_is_zero(a)) {
  ------------------
  |  Branch (145:9): [True: 0, False: 1.28k]
  ------------------
  146|      0|        i = BN_set_word(a, w);
  147|      0|        if (i != 0)
  ------------------
  |  Branch (147:13): [True: 0, False: 0]
  ------------------
  148|      0|            BN_set_negative(a, 1);
  149|      0|        return i;
  150|      0|    }
  151|       |    /* handle 'a' when negative */
  152|  1.28k|    if (a->neg) {
  ------------------
  |  Branch (152:9): [True: 0, False: 1.28k]
  ------------------
  153|      0|        a->neg = 0;
  154|      0|        i = BN_add_word(a, w);
  155|      0|        a->neg = 1;
  156|      0|        return i;
  157|      0|    }
  158|       |
  159|  1.28k|    if ((a->top == 1) && (a->d[0] < w)) {
  ------------------
  |  Branch (159:9): [True: 0, False: 1.28k]
  |  Branch (159:26): [True: 0, False: 0]
  ------------------
  160|      0|        a->d[0] = w - a->d[0];
  161|      0|        a->neg = 1;
  162|      0|        return 1;
  163|      0|    }
  164|  1.28k|    i = 0;
  165|  2.56k|    for (;;) {
  166|  2.56k|        if (a->d[i] >= w) {
  ------------------
  |  Branch (166:13): [True: 1.28k, False: 1.28k]
  ------------------
  167|  1.28k|            a->d[i] -= w;
  168|  1.28k|            break;
  169|  1.28k|        } else {
  170|  1.28k|            a->d[i] = (a->d[i] - w) & BN_MASK2;
  ------------------
  |  |   94|  1.28k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  171|  1.28k|            i++;
  172|  1.28k|            w = 1;
  173|  1.28k|        }
  174|  2.56k|    }
  175|  1.28k|    if ((a->d[i] == 0) && (i == (a->top - 1)))
  ------------------
  |  Branch (175:9): [True: 181, False: 1.10k]
  |  Branch (175:27): [True: 181, False: 0]
  ------------------
  176|    181|        a->top--;
  177|  1.28k|    bn_check_top(a);
  178|  1.28k|    return 1;
  179|  1.28k|}
BN_mul_word:
  182|  18.4k|{
  183|  18.4k|    BN_ULONG ll;
  ------------------
  |  |   37|  18.4k|#  define BN_ULONG        unsigned long
  ------------------
  184|       |
  185|  18.4k|    bn_check_top(a);
  186|  18.4k|    w &= BN_MASK2;
  ------------------
  |  |   94|  18.4k|#  define BN_MASK2        (0xffffffffffffffffL)
  ------------------
  187|  18.4k|    if (a->top) {
  ------------------
  |  Branch (187:9): [True: 18.1k, False: 305]
  ------------------
  188|  18.1k|        if (w == 0)
  ------------------
  |  Branch (188:13): [True: 0, False: 18.1k]
  ------------------
  189|      0|            BN_zero(a);
  ------------------
  |  |  202|      0|#  define BN_zero(a)      BN_zero_ex(a)
  ------------------
  190|  18.1k|        else {
  191|  18.1k|            ll = bn_mul_words(a->d, a->d, a->top, w);
  192|  18.1k|            if (ll) {
  ------------------
  |  Branch (192:17): [True: 14.1k, False: 3.99k]
  ------------------
  193|  14.1k|                if (bn_wexpand(a, a->top + 1) == NULL)
  ------------------
  |  Branch (193:21): [True: 0, False: 14.1k]
  ------------------
  194|      0|                    return 0;
  195|  14.1k|                a->d[a->top++] = ll;
  196|  14.1k|            }
  197|  18.1k|        }
  198|  18.1k|    }
  199|  18.4k|    bn_check_top(a);
  200|  18.4k|    return 1;
  201|  18.4k|}

ossl_err_load_BUF_strings:
   24|      2|{
   25|      2|#ifndef OPENSSL_NO_ERR
   26|      2|    if (ERR_reason_error_string(BUF_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (26:9): [True: 2, False: 0]
  ------------------
   27|      2|        ERR_load_strings_const(BUF_str_reasons);
   28|      2|#endif
   29|      2|    return 1;
   30|      2|}

ossl_err_load_CMP_strings:
  193|      2|{
  194|      2|# ifndef OPENSSL_NO_ERR
  195|      2|    if (ERR_reason_error_string(CMP_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (195:9): [True: 2, False: 0]
  ------------------
  196|      2|        ERR_load_strings_const(CMP_str_reasons);
  197|      2|# endif
  198|      2|    return 1;
  199|      2|}

OSSL_CMP_log_close:
   41|      2|{
   42|      2|    (void)OSSL_trace_set_channel(OSSL_TRACE_CATEGORY_CMP, NULL);
  ------------------
  |  |   53|      2|# define OSSL_TRACE_CATEGORY_CMP                13
  ------------------
   43|      2|}

ossl_err_load_CMS_strings:
  173|      2|{
  174|      2|# ifndef OPENSSL_NO_ERR
  175|      2|    if (ERR_reason_error_string(CMS_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (175:9): [True: 2, False: 0]
  ------------------
  176|      2|        ERR_load_strings_const(CMS_str_reasons);
  177|      2|# endif
  178|      2|    return 1;
  179|      2|}

ossl_comp_brotli_cleanup:
  353|      2|{
  354|       |#ifdef BROTLI_SHARED
  355|       |    DSO_free(brotli_encode_dso);
  356|       |    brotli_encode_dso = NULL;
  357|       |    DSO_free(brotli_decode_dso);
  358|       |    brotli_decode_dso = NULL;
  359|       |    p_encode_init = NULL;
  360|       |    p_encode_stream = NULL;
  361|       |    p_encode_has_more = NULL;
  362|       |    p_encode_end = NULL;
  363|       |    p_encode_oneshot = NULL;
  364|       |    p_decode_init = NULL;
  365|       |    p_decode_stream = NULL;
  366|       |    p_decode_has_more = NULL;
  367|       |    p_decode_end = NULL;
  368|       |    p_decode_error = NULL;
  369|       |    p_decode_error_string = NULL;
  370|       |    p_decode_is_finished = NULL;
  371|       |    p_decode_oneshot = NULL;
  372|       |#endif
  373|      2|}

COMP_zlib:
  311|      2|{
  312|      2|    COMP_METHOD *meth = NULL;
  313|       |
  314|       |#ifndef OPENSSL_NO_ZLIB
  315|       |    if (RUN_ONCE(&zlib_once, ossl_comp_zlib_init))
  316|       |        meth = &zlib_stateful_method;
  317|       |#endif
  318|       |
  319|      2|    return meth;
  320|      2|}
ossl_comp_zlib_cleanup:
  336|      2|{
  337|       |#ifdef ZLIB_SHARED
  338|       |    DSO_free(zlib_dso);
  339|       |    zlib_dso = NULL;
  340|       |#endif
  341|      2|}

ossl_comp_zstd_cleanup:
  428|      2|{
  429|       |#ifdef ZSTD_SHARED
  430|       |    DSO_free(zstd_dso);
  431|       |    zstd_dso = NULL;
  432|       |    p_createCStream = NULL;
  433|       |    p_initCStream = NULL;
  434|       |    p_freeCStream = NULL;
  435|       |    p_compressStream2 = NULL;
  436|       |    p_flushStream = NULL;
  437|       |    p_endStream = NULL;
  438|       |    p_compress = NULL;
  439|       |    p_createDStream = NULL;
  440|       |    p_initDStream = NULL;
  441|       |    p_freeDStream = NULL;
  442|       |    p_decompressStream = NULL;
  443|       |    p_decompress = NULL;
  444|       |    p_isError = NULL;
  445|       |    p_getErrorName = NULL;
  446|       |    p_DStreamInSize = NULL;
  447|       |    p_CStreamInSize = NULL;
  448|       |#endif
  449|      2|}

ossl_err_load_COMP_strings:
   45|      2|{
   46|      2|# ifndef OPENSSL_NO_ERR
   47|      2|    if (ERR_reason_error_string(COMP_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (47:9): [True: 2, False: 0]
  ------------------
   48|      2|        ERR_load_strings_const(COMP_str_reasons);
   49|      2|# endif
   50|      2|    return 1;
   51|      2|}

COMP_get_type:
   41|      2|{
   42|      2|    if (meth == NULL)
  ------------------
  |  Branch (42:9): [True: 2, False: 0]
  ------------------
   43|      2|        return NID_undef;
  ------------------
  |  |   18|      2|#define NID_undef                       0
  ------------------
   44|      0|    return meth->type;
   45|      2|}

ossl_load_builtin_compressions:
   29|      2|{
   30|      2|    STACK_OF(SSL_COMP) *comp_methods = NULL;
  ------------------
  |  |   31|      2|# define STACK_OF(type) struct stack_st_##type
  ------------------
   31|      2|#ifndef OPENSSL_NO_COMP
   32|      2|    SSL_COMP *comp = NULL;
   33|      2|    COMP_METHOD *method = COMP_zlib();
   34|       |
   35|      2|    comp_methods = sk_SSL_COMP_new(sk_comp_cmp);
  ------------------
  |  |   69|      2|#define sk_SSL_COMP_new(cmp) ((STACK_OF(SSL_COMP) *)OPENSSL_sk_new(ossl_check_SSL_COMP_compfunc_type(cmp)))
  ------------------
   36|       |
   37|      2|    if (COMP_get_type(method) != NID_undef && comp_methods != NULL) {
  ------------------
  |  |   18|      4|#define NID_undef                       0
  ------------------
  |  Branch (37:9): [True: 0, False: 2]
  |  Branch (37:47): [True: 0, False: 0]
  ------------------
   38|      0|        comp = OPENSSL_malloc(sizeof(*comp));
  ------------------
  |  |  102|      0|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   39|      0|        if (comp != NULL) {
  ------------------
  |  Branch (39:13): [True: 0, False: 0]
  ------------------
   40|      0|            comp->method = method;
   41|      0|            comp->id = SSL_COMP_ZLIB_IDX;
  ------------------
  |  |   18|      0|#define SSL_COMP_ZLIB_IDX       1
  ------------------
   42|      0|            comp->name = COMP_get_name(method);
   43|      0|            if (!sk_SSL_COMP_push(comp_methods, comp))
  ------------------
  |  |   77|      0|#define sk_SSL_COMP_push(sk, ptr) OPENSSL_sk_push(ossl_check_SSL_COMP_sk_type(sk), ossl_check_SSL_COMP_type(ptr))
  ------------------
  |  Branch (43:17): [True: 0, False: 0]
  ------------------
   44|      0|                OPENSSL_free(comp);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   45|      0|        }
   46|      0|    }
   47|      2|#endif
   48|      2|    return comp_methods;
   49|      2|}
ossl_free_compression_methods_int:
   57|      2|{
   58|      2|    sk_SSL_COMP_pop_free(methods, cmeth_free);
  ------------------
  |  |   81|      2|#define sk_SSL_COMP_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_SSL_COMP_sk_type(sk),ossl_check_SSL_COMP_freefunc_type(freefunc))
  ------------------
   59|      2|}

ossl_err_load_CONF_strings:
   68|      2|{
   69|      2|#ifndef OPENSSL_NO_ERR
   70|      2|    if (ERR_reason_error_string(CONF_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (70:9): [True: 2, False: 0]
  ------------------
   71|      2|        ERR_load_strings_const(CONF_str_reasons);
   72|      2|#endif
   73|      2|    return 1;
   74|      2|}

CONF_modules_unload:
  517|      2|{
  518|      2|    int i;
  519|      2|    CONF_MODULE *md;
  520|      2|    STACK_OF(CONF_MODULE) *old_modules;
  ------------------
  |  |   31|      2|# define STACK_OF(type) struct stack_st_##type
  ------------------
  521|      2|    STACK_OF(CONF_MODULE) *new_modules;
  ------------------
  |  |   31|      2|# define STACK_OF(type) struct stack_st_##type
  ------------------
  522|      2|    STACK_OF(CONF_MODULE) *to_delete;
  ------------------
  |  |   31|      2|# define STACK_OF(type) struct stack_st_##type
  ------------------
  523|       |
  524|      2|    if (!conf_modules_finish_int()) /* also inits module list lock */
  ------------------
  |  Branch (524:9): [True: 0, False: 2]
  ------------------
  525|      0|        return;
  526|       |
  527|      2|    ossl_rcu_write_lock(module_list_lock);
  528|       |
  529|      2|    old_modules = ossl_rcu_deref(&supported_modules);
  ------------------
  |  |   30|      2|#define ossl_rcu_deref(p) ossl_rcu_uptr_deref((void **)p)
  ------------------
  530|      2|    new_modules = sk_CONF_MODULE_dup(old_modules);
  531|       |
  532|      2|    if (new_modules == NULL) {
  ------------------
  |  Branch (532:9): [True: 0, False: 2]
  ------------------
  533|      0|        ossl_rcu_write_unlock(module_list_lock);
  534|      0|        return;
  535|      0|    }
  536|       |
  537|      2|    to_delete = sk_CONF_MODULE_new_null();
  538|       |
  539|       |    /* unload modules in reverse order */
  540|      2|    for (i = sk_CONF_MODULE_num(new_modules) - 1; i >= 0; i--) {
  ------------------
  |  Branch (540:51): [True: 0, False: 2]
  ------------------
  541|      0|        md = sk_CONF_MODULE_value(new_modules, i);
  542|       |        /* If static or in use and 'all' not set ignore it */
  543|      0|        if (((md->links > 0) || !md->dso) && !all)
  ------------------
  |  Branch (543:14): [True: 0, False: 0]
  |  Branch (543:33): [True: 0, False: 0]
  |  Branch (543:46): [True: 0, False: 0]
  ------------------
  544|      0|            continue;
  545|       |        /* Since we're working in reverse this is OK */
  546|      0|        (void)sk_CONF_MODULE_delete(new_modules, i);
  547|      0|        sk_CONF_MODULE_push(to_delete, md);
  548|      0|    }
  549|       |
  550|      2|    if (sk_CONF_MODULE_num(new_modules) == 0) {
  ------------------
  |  Branch (550:9): [True: 2, False: 0]
  ------------------
  551|      2|        sk_CONF_MODULE_free(new_modules);
  552|      2|        new_modules = NULL;
  553|      2|    }
  554|       |
  555|      2|    ossl_rcu_assign_ptr(&supported_modules, &new_modules);
  ------------------
  |  |   31|      2|#define ossl_rcu_assign_ptr(p,v) ossl_rcu_assign_uptr((void **)p, (void **)v)
  ------------------
  556|      2|    ossl_rcu_write_unlock(module_list_lock);
  557|      2|    ossl_synchronize_rcu(module_list_lock);
  558|      2|    sk_CONF_MODULE_free(old_modules);
  559|      2|    sk_CONF_MODULE_pop_free(to_delete, module_free);
  560|       |
  561|      2|}
ossl_config_modules_free:
  632|      2|{
  633|      2|    CONF_modules_unload(1); /* calls CONF_modules_finish */
  634|      2|    module_lists_free();
  635|      2|}
conf_mod.c:do_init_module_list_lock:
  101|      2|{
  102|      2|    module_list_lock = ossl_rcu_lock_new(1, NULL);
  103|      2|    if (module_list_lock == NULL) {
  ------------------
  |  Branch (103:9): [True: 0, False: 2]
  ------------------
  104|      0|        ERR_raise(ERR_LIB_CONF, ERR_R_CRYPTO_LIB);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  105|      0|        return 0;
  106|      0|    }
  107|       |
  108|      2|    return 1;
  109|      2|}
conf_mod.c:conf_modules_finish_int:
  574|      2|{
  575|      2|    CONF_IMODULE *imod;
  576|      2|    STACK_OF(CONF_IMODULE) *old_modules;
  ------------------
  |  |   31|      2|# define STACK_OF(type) struct stack_st_##type
  ------------------
  577|      2|    STACK_OF(CONF_IMODULE) *new_modules = NULL;
  ------------------
  |  |   31|      2|# define STACK_OF(type) struct stack_st_##type
  ------------------
  578|       |
  579|      2|    if (!RUN_ONCE(&init_module_list_lock, do_init_module_list_lock))
  ------------------
  |  |  130|      2|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (579:9): [True: 0, False: 2]
  ------------------
  580|      0|        return 0;
  581|       |
  582|       |    /* If module_list_lock is NULL here it means we were already unloaded */
  583|      2|    if (module_list_lock == NULL)
  ------------------
  |  Branch (583:9): [True: 0, False: 2]
  ------------------
  584|      0|        return 0;
  585|       |
  586|      2|    ossl_rcu_write_lock(module_list_lock);
  587|      2|    old_modules = ossl_rcu_deref(&initialized_modules);
  ------------------
  |  |   30|      2|#define ossl_rcu_deref(p) ossl_rcu_uptr_deref((void **)p)
  ------------------
  588|      2|    ossl_rcu_assign_ptr(&initialized_modules, &new_modules);
  ------------------
  |  |   31|      2|#define ossl_rcu_assign_ptr(p,v) ossl_rcu_assign_uptr((void **)p, (void **)v)
  ------------------
  589|      2|    ossl_rcu_write_unlock(module_list_lock);
  590|      2|    ossl_synchronize_rcu(module_list_lock);
  591|       |
  592|      2|    while (sk_CONF_IMODULE_num(old_modules) > 0) {
  ------------------
  |  Branch (592:12): [True: 0, False: 2]
  ------------------
  593|      0|        imod = sk_CONF_IMODULE_pop(old_modules);
  594|      0|        module_finish(imod);
  595|      0|    }
  596|      2|    sk_CONF_IMODULE_free(old_modules);
  597|       |
  598|      2|    return 1;
  599|      2|}
conf_mod.c:module_lists_free:
   89|      2|{
   90|      2|    ossl_rcu_lock_free(module_list_lock);
   91|      2|    module_list_lock = NULL;
   92|       |
   93|      2|    sk_CONF_MODULE_free(supported_modules);
   94|      2|    supported_modules = NULL;
   95|       |
   96|      2|    sk_CONF_IMODULE_free(initialized_modules);
   97|      2|    initialized_modules = NULL;
   98|      2|}

ossl_lib_ctx_default_deinit:
  417|      2|{
  418|      2|    if (!default_context_inited)
  ------------------
  |  Branch (418:9): [True: 0, False: 2]
  ------------------
  419|      0|        return;
  420|      2|    context_deinit(&default_context_int);
  421|      2|    CRYPTO_THREAD_cleanup_local(&default_context_thread_local);
  422|      2|    default_context_inited = 0;
  423|      2|}
ossl_lib_ctx_get_concrete:
  548|     22|{
  549|     22|#ifndef FIPS_MODULE
  550|     22|    if (ctx == NULL)
  ------------------
  |  Branch (550:9): [True: 2, False: 20]
  ------------------
  551|      2|        return get_default_context();
  552|     20|#endif
  553|     20|    return ctx;
  554|     22|}
ossl_lib_ctx_get_data:
  575|     16|{
  576|     16|    void *p;
  577|       |
  578|     16|    ctx = ossl_lib_ctx_get_concrete(ctx);
  579|     16|    if (ctx == NULL)
  ------------------
  |  Branch (579:9): [True: 0, False: 16]
  ------------------
  580|      0|        return NULL;
  581|       |
  582|     16|    switch (index) {
  583|     16|    case OSSL_LIB_CTX_PROPERTY_STRING_INDEX:
  ------------------
  |  |   99|     16|# define OSSL_LIB_CTX_PROPERTY_STRING_INDEX          3
  ------------------
  |  Branch (583:5): [True: 16, False: 0]
  ------------------
  584|     16|        return ctx->property_string_data;
  585|      0|    case OSSL_LIB_CTX_EVP_METHOD_STORE_INDEX:
  ------------------
  |  |   96|      0|# define OSSL_LIB_CTX_EVP_METHOD_STORE_INDEX         0
  ------------------
  |  Branch (585:5): [True: 0, False: 16]
  ------------------
  586|      0|        return ctx->evp_method_store;
  587|      0|    case OSSL_LIB_CTX_PROVIDER_STORE_INDEX:
  ------------------
  |  |   97|      0|# define OSSL_LIB_CTX_PROVIDER_STORE_INDEX           1
  ------------------
  |  Branch (587:5): [True: 0, False: 16]
  ------------------
  588|      0|        return ctx->provider_store;
  589|      0|    case OSSL_LIB_CTX_NAMEMAP_INDEX:
  ------------------
  |  |  100|      0|# define OSSL_LIB_CTX_NAMEMAP_INDEX                  4
  ------------------
  |  Branch (589:5): [True: 0, False: 16]
  ------------------
  590|      0|        return ctx->namemap;
  591|      0|    case OSSL_LIB_CTX_PROPERTY_DEFN_INDEX:
  ------------------
  |  |   98|      0|# define OSSL_LIB_CTX_PROPERTY_DEFN_INDEX            2
  ------------------
  |  Branch (591:5): [True: 0, False: 16]
  ------------------
  592|      0|        return ctx->property_defns;
  593|      0|    case OSSL_LIB_CTX_GLOBAL_PROPERTIES:
  ------------------
  |  |  112|      0|# define OSSL_LIB_CTX_GLOBAL_PROPERTIES             14
  ------------------
  |  Branch (593:5): [True: 0, False: 16]
  ------------------
  594|      0|        return ctx->global_properties;
  595|      0|    case OSSL_LIB_CTX_DRBG_INDEX:
  ------------------
  |  |  101|      0|# define OSSL_LIB_CTX_DRBG_INDEX                     5
  ------------------
  |  Branch (595:5): [True: 0, False: 16]
  ------------------
  596|      0|        return ctx->drbg;
  597|      0|    case OSSL_LIB_CTX_DRBG_NONCE_INDEX:
  ------------------
  |  |  102|      0|# define OSSL_LIB_CTX_DRBG_NONCE_INDEX               6
  ------------------
  |  Branch (597:5): [True: 0, False: 16]
  ------------------
  598|      0|        return ctx->drbg_nonce;
  599|      0|#ifndef FIPS_MODULE
  600|      0|    case OSSL_LIB_CTX_PROVIDER_CONF_INDEX:
  ------------------
  |  |  114|      0|# define OSSL_LIB_CTX_PROVIDER_CONF_INDEX           16
  ------------------
  |  Branch (600:5): [True: 0, False: 16]
  ------------------
  601|      0|        return ctx->provider_conf;
  602|      0|    case OSSL_LIB_CTX_BIO_CORE_INDEX:
  ------------------
  |  |  115|      0|# define OSSL_LIB_CTX_BIO_CORE_INDEX                17
  ------------------
  |  Branch (602:5): [True: 0, False: 16]
  ------------------
  603|      0|        return ctx->bio_core;
  604|      0|    case OSSL_LIB_CTX_CHILD_PROVIDER_INDEX:
  ------------------
  |  |  116|      0|# define OSSL_LIB_CTX_CHILD_PROVIDER_INDEX          18
  ------------------
  |  Branch (604:5): [True: 0, False: 16]
  ------------------
  605|      0|        return ctx->child_provider;
  606|      0|    case OSSL_LIB_CTX_DECODER_STORE_INDEX:
  ------------------
  |  |  109|      0|# define OSSL_LIB_CTX_DECODER_STORE_INDEX           11
  ------------------
  |  Branch (606:5): [True: 0, False: 16]
  ------------------
  607|      0|        return ctx->decoder_store;
  608|      0|    case OSSL_LIB_CTX_DECODER_CACHE_INDEX:
  ------------------
  |  |  118|      0|# define OSSL_LIB_CTX_DECODER_CACHE_INDEX           20
  ------------------
  |  Branch (608:5): [True: 0, False: 16]
  ------------------
  609|      0|        return ctx->decoder_cache;
  610|      0|    case OSSL_LIB_CTX_ENCODER_STORE_INDEX:
  ------------------
  |  |  108|      0|# define OSSL_LIB_CTX_ENCODER_STORE_INDEX           10
  ------------------
  |  Branch (610:5): [True: 0, False: 16]
  ------------------
  611|      0|        return ctx->encoder_store;
  612|      0|    case OSSL_LIB_CTX_STORE_LOADER_STORE_INDEX:
  ------------------
  |  |  113|      0|# define OSSL_LIB_CTX_STORE_LOADER_STORE_INDEX      15
  ------------------
  |  Branch (612:5): [True: 0, False: 16]
  ------------------
  613|      0|        return ctx->store_loader_store;
  614|      0|    case OSSL_LIB_CTX_SELF_TEST_CB_INDEX:
  ------------------
  |  |  110|      0|# define OSSL_LIB_CTX_SELF_TEST_CB_INDEX            12
  ------------------
  |  Branch (614:5): [True: 0, False: 16]
  ------------------
  615|      0|        return ctx->self_test_cb;
  616|      0|    case OSSL_LIB_CTX_INDICATOR_CB_INDEX:
  ------------------
  |  |  120|      0|# define OSSL_LIB_CTX_INDICATOR_CB_INDEX            22
  ------------------
  |  Branch (616:5): [True: 0, False: 16]
  ------------------
  617|      0|        return ctx->indicator_cb;
  618|      0|#endif
  619|      0|#ifndef OPENSSL_NO_THREAD_POOL
  620|      0|    case OSSL_LIB_CTX_THREAD_INDEX:
  ------------------
  |  |  117|      0|# define OSSL_LIB_CTX_THREAD_INDEX                  19
  ------------------
  |  Branch (620:5): [True: 0, False: 16]
  ------------------
  621|      0|        return ctx->threads;
  622|      0|#endif
  623|       |
  624|      0|    case OSSL_LIB_CTX_RAND_CRNGT_INDEX: {
  ------------------
  |  |  103|      0|# define OSSL_LIB_CTX_RAND_CRNGT_INDEX               7
  ------------------
  |  Branch (624:5): [True: 0, False: 16]
  ------------------
  625|       |
  626|       |        /*
  627|       |         * rand_crngt must be lazily initialized because it calls into
  628|       |         * libctx, so must not be called from context_init, else a deadlock
  629|       |         * will occur.
  630|       |         *
  631|       |         * We use a separate lock because code called by the instantiation
  632|       |         * of rand_crngt is liable to try and take the libctx lock.
  633|       |         */
  634|      0|        if (CRYPTO_THREAD_read_lock(ctx->rand_crngt_lock) != 1)
  ------------------
  |  Branch (634:13): [True: 0, False: 0]
  ------------------
  635|      0|            return NULL;
  636|       |
  637|      0|        if (ctx->rand_crngt == NULL) {
  ------------------
  |  Branch (637:13): [True: 0, False: 0]
  ------------------
  638|      0|            CRYPTO_THREAD_unlock(ctx->rand_crngt_lock);
  639|       |
  640|      0|            if (CRYPTO_THREAD_write_lock(ctx->rand_crngt_lock) != 1)
  ------------------
  |  Branch (640:17): [True: 0, False: 0]
  ------------------
  641|      0|                return NULL;
  642|       |
  643|      0|            if (ctx->rand_crngt == NULL)
  ------------------
  |  Branch (643:17): [True: 0, False: 0]
  ------------------
  644|      0|                ctx->rand_crngt = ossl_rand_crng_ctx_new(ctx);
  645|      0|        }
  646|       |
  647|      0|        p = ctx->rand_crngt;
  648|       |
  649|      0|        CRYPTO_THREAD_unlock(ctx->rand_crngt_lock);
  650|       |
  651|      0|        return p;
  652|      0|    }
  653|       |
  654|       |#ifdef FIPS_MODULE
  655|       |    case OSSL_LIB_CTX_THREAD_EVENT_HANDLER_INDEX:
  656|       |        return ctx->thread_event_handler;
  657|       |
  658|       |    case OSSL_LIB_CTX_FIPS_PROV_INDEX:
  659|       |        return ctx->fips_prov;
  660|       |#endif
  661|       |
  662|      0|    case OSSL_LIB_CTX_COMP_METHODS:
  ------------------
  |  |  119|      0|# define OSSL_LIB_CTX_COMP_METHODS                  21
  ------------------
  |  Branch (662:5): [True: 0, False: 16]
  ------------------
  663|      0|        return (void *)&ctx->comp_methods;
  664|       |
  665|      0|    default:
  ------------------
  |  Branch (665:5): [True: 0, False: 16]
  ------------------
  666|      0|        return NULL;
  667|     16|    }
  668|     16|}
ossl_lib_ctx_get_ex_data_global:
  676|      4|{
  677|      4|    ctx = ossl_lib_ctx_get_concrete(ctx);
  678|      4|    if (ctx == NULL)
  ------------------
  |  Branch (678:9): [True: 0, False: 4]
  ------------------
  679|      0|        return NULL;
  680|      4|    return &ctx->global;
  681|      4|}
context.c:context_deinit:
  373|      2|{
  374|      2|    if (ctx == NULL)
  ------------------
  |  Branch (374:9): [True: 0, False: 2]
  ------------------
  375|      0|        return 1;
  376|       |
  377|      2|    ossl_ctx_thread_stop(ctx);
  378|       |
  379|      2|    context_deinit_objs(ctx);
  380|       |
  381|      2|    ossl_crypto_cleanup_all_ex_data_int(ctx);
  382|       |
  383|      2|    CRYPTO_THREAD_lock_free(ctx->rand_crngt_lock);
  384|      2|    CRYPTO_THREAD_lock_free(ctx->lock);
  385|      2|    ctx->rand_crngt_lock = NULL;
  386|      2|    ctx->lock = NULL;
  387|      2|    CRYPTO_THREAD_cleanup_local(&ctx->rcu_local_key);
  388|      2|    return 1;
  389|      2|}
context.c:context_deinit_objs:
  233|      2|{
  234|       |    /* P2. We want evp_method_store to be cleaned up before the provider store */
  235|      2|    if (ctx->evp_method_store != NULL) {
  ------------------
  |  Branch (235:9): [True: 2, False: 0]
  ------------------
  236|      2|        ossl_method_store_free(ctx->evp_method_store);
  237|      2|        ctx->evp_method_store = NULL;
  238|      2|    }
  239|       |
  240|       |    /* P2. */
  241|      2|    if (ctx->drbg != NULL) {
  ------------------
  |  Branch (241:9): [True: 2, False: 0]
  ------------------
  242|      2|        ossl_rand_ctx_free(ctx->drbg);
  243|      2|        ctx->drbg = NULL;
  244|      2|    }
  245|       |
  246|      2|#ifndef FIPS_MODULE
  247|       |    /* P2. */
  248|      2|    if (ctx->provider_conf != NULL) {
  ------------------
  |  Branch (248:9): [True: 2, False: 0]
  ------------------
  249|      2|        ossl_prov_conf_ctx_free(ctx->provider_conf);
  250|      2|        ctx->provider_conf = NULL;
  251|      2|    }
  252|       |
  253|       |    /*
  254|       |     * P2. We want decoder_store/decoder_cache to be cleaned up before the
  255|       |     * provider store
  256|       |     */
  257|      2|    if (ctx->decoder_store != NULL) {
  ------------------
  |  Branch (257:9): [True: 2, False: 0]
  ------------------
  258|      2|        ossl_method_store_free(ctx->decoder_store);
  259|      2|        ctx->decoder_store = NULL;
  260|      2|    }
  261|      2|    if (ctx->decoder_cache != NULL) {
  ------------------
  |  Branch (261:9): [True: 2, False: 0]
  ------------------
  262|      2|        ossl_decoder_cache_free(ctx->decoder_cache);
  263|      2|        ctx->decoder_cache = NULL;
  264|      2|    }
  265|       |
  266|       |
  267|       |    /* P2. We want encoder_store to be cleaned up before the provider store */
  268|      2|    if (ctx->encoder_store != NULL) {
  ------------------
  |  Branch (268:9): [True: 2, False: 0]
  ------------------
  269|      2|        ossl_method_store_free(ctx->encoder_store);
  270|      2|        ctx->encoder_store = NULL;
  271|      2|    }
  272|       |
  273|       |    /* P2. We want loader_store to be cleaned up before the provider store */
  274|      2|    if (ctx->store_loader_store != NULL) {
  ------------------
  |  Branch (274:9): [True: 2, False: 0]
  ------------------
  275|      2|        ossl_method_store_free(ctx->store_loader_store);
  276|      2|        ctx->store_loader_store = NULL;
  277|      2|    }
  278|      2|#endif
  279|       |
  280|       |    /* P1. Needs to be freed before the child provider data is freed */
  281|      2|    if (ctx->provider_store != NULL) {
  ------------------
  |  Branch (281:9): [True: 2, False: 0]
  ------------------
  282|      2|        ossl_provider_store_free(ctx->provider_store);
  283|      2|        ctx->provider_store = NULL;
  284|      2|    }
  285|       |
  286|       |    /* Default priority. */
  287|      2|    if (ctx->property_string_data != NULL) {
  ------------------
  |  Branch (287:9): [True: 2, False: 0]
  ------------------
  288|      2|        ossl_property_string_data_free(ctx->property_string_data);
  289|      2|        ctx->property_string_data = NULL;
  290|      2|    }
  291|       |
  292|      2|    if (ctx->namemap != NULL) {
  ------------------
  |  Branch (292:9): [True: 2, False: 0]
  ------------------
  293|      2|        ossl_stored_namemap_free(ctx->namemap);
  294|      2|        ctx->namemap = NULL;
  295|      2|    }
  296|       |
  297|      2|    if (ctx->property_defns != NULL) {
  ------------------
  |  Branch (297:9): [True: 2, False: 0]
  ------------------
  298|      2|        ossl_property_defns_free(ctx->property_defns);
  299|      2|        ctx->property_defns = NULL;
  300|      2|    }
  301|       |
  302|      2|    if (ctx->global_properties != NULL) {
  ------------------
  |  Branch (302:9): [True: 2, False: 0]
  ------------------
  303|      2|        ossl_ctx_global_properties_free(ctx->global_properties);
  304|      2|        ctx->global_properties = NULL;
  305|      2|    }
  306|       |
  307|      2|#ifndef FIPS_MODULE
  308|      2|    if (ctx->bio_core != NULL) {
  ------------------
  |  Branch (308:9): [True: 2, False: 0]
  ------------------
  309|      2|        ossl_bio_core_globals_free(ctx->bio_core);
  310|      2|        ctx->bio_core = NULL;
  311|      2|    }
  312|      2|#endif
  313|       |
  314|      2|    if (ctx->drbg_nonce != NULL) {
  ------------------
  |  Branch (314:9): [True: 2, False: 0]
  ------------------
  315|      2|        ossl_prov_drbg_nonce_ctx_free(ctx->drbg_nonce);
  316|      2|        ctx->drbg_nonce = NULL;
  317|      2|    }
  318|       |
  319|      2|#ifndef FIPS_MODULE
  320|      2|    if (ctx->indicator_cb != NULL) {
  ------------------
  |  Branch (320:9): [True: 2, False: 0]
  ------------------
  321|      2|        ossl_indicator_set_callback_free(ctx->indicator_cb);
  322|      2|        ctx->indicator_cb = NULL;
  323|      2|    }
  324|       |
  325|      2|    if (ctx->self_test_cb != NULL) {
  ------------------
  |  Branch (325:9): [True: 2, False: 0]
  ------------------
  326|      2|        ossl_self_test_set_callback_free(ctx->self_test_cb);
  327|      2|        ctx->self_test_cb = NULL;
  328|      2|    }
  329|      2|#endif
  330|       |
  331|      2|    if (ctx->rand_crngt != NULL) {
  ------------------
  |  Branch (331:9): [True: 0, False: 2]
  ------------------
  332|      0|        ossl_rand_crng_ctx_free(ctx->rand_crngt);
  333|      0|        ctx->rand_crngt = NULL;
  334|      0|    }
  335|       |
  336|       |#ifdef FIPS_MODULE
  337|       |    if (ctx->thread_event_handler != NULL) {
  338|       |        ossl_thread_event_ctx_free(ctx->thread_event_handler);
  339|       |        ctx->thread_event_handler = NULL;
  340|       |    }
  341|       |
  342|       |    if (ctx->fips_prov != NULL) {
  343|       |        ossl_fips_prov_ossl_ctx_free(ctx->fips_prov);
  344|       |        ctx->fips_prov = NULL;
  345|       |    }
  346|       |#endif
  347|       |
  348|      2|#ifndef OPENSSL_NO_THREAD_POOL
  349|      2|    if (ctx->threads != NULL) {
  ------------------
  |  Branch (349:9): [True: 2, False: 0]
  ------------------
  350|      2|        ossl_threads_ctx_free(ctx->threads);
  351|      2|        ctx->threads = NULL;
  352|      2|    }
  353|      2|#endif
  354|       |
  355|       |    /* Low priority. */
  356|      2|#ifndef FIPS_MODULE
  357|      2|    if (ctx->child_provider != NULL) {
  ------------------
  |  Branch (357:9): [True: 2, False: 0]
  ------------------
  358|      2|        ossl_child_prov_ctx_free(ctx->child_provider);
  359|      2|        ctx->child_provider = NULL;
  360|      2|    }
  361|      2|#endif
  362|       |
  363|      2|#ifndef FIPS_MODULE
  364|      2|    if (ctx->comp_methods != NULL) {
  ------------------
  |  Branch (364:9): [True: 2, False: 0]
  ------------------
  365|      2|        ossl_free_compression_methods_int(ctx->comp_methods);
  366|      2|        ctx->comp_methods = NULL;
  367|      2|    }
  368|      2|#endif
  369|       |
  370|      2|}
context.c:context_init:
   86|      2|{
   87|      2|    int exdata_done = 0;
   88|       |
   89|      2|    if (!CRYPTO_THREAD_init_local(&ctx->rcu_local_key, NULL))
  ------------------
  |  Branch (89:9): [True: 0, False: 2]
  ------------------
   90|      0|        return 0;
   91|       |
   92|      2|    ctx->lock = CRYPTO_THREAD_lock_new();
   93|      2|    if (ctx->lock == NULL)
  ------------------
  |  Branch (93:9): [True: 0, False: 2]
  ------------------
   94|      0|        goto err;
   95|       |
   96|      2|    ctx->rand_crngt_lock = CRYPTO_THREAD_lock_new();
   97|      2|    if (ctx->rand_crngt_lock == NULL)
  ------------------
  |  Branch (97:9): [True: 0, False: 2]
  ------------------
   98|      0|        goto err;
   99|       |
  100|       |    /* Initialize ex_data. */
  101|      2|    if (!ossl_do_ex_data_init(ctx))
  ------------------
  |  Branch (101:9): [True: 0, False: 2]
  ------------------
  102|      0|        goto err;
  103|      2|    exdata_done = 1;
  104|       |
  105|       |    /* P2. We want evp_method_store to be cleaned up before the provider store */
  106|      2|    ctx->evp_method_store = ossl_method_store_new(ctx);
  107|      2|    if (ctx->evp_method_store == NULL)
  ------------------
  |  Branch (107:9): [True: 0, False: 2]
  ------------------
  108|      0|        goto err;
  109|       |
  110|      2|#ifndef FIPS_MODULE
  111|       |    /* P2. Must be freed before the provider store is freed */
  112|      2|    ctx->provider_conf = ossl_prov_conf_ctx_new(ctx);
  113|      2|    if (ctx->provider_conf == NULL)
  ------------------
  |  Branch (113:9): [True: 0, False: 2]
  ------------------
  114|      0|        goto err;
  115|      2|#endif
  116|       |
  117|       |    /* P2. */
  118|      2|    ctx->drbg = ossl_rand_ctx_new(ctx);
  119|      2|    if (ctx->drbg == NULL)
  ------------------
  |  Branch (119:9): [True: 0, False: 2]
  ------------------
  120|      0|        goto err;
  121|       |
  122|      2|#ifndef FIPS_MODULE
  123|       |    /*
  124|       |     * P2. We want decoder_store/decoder_cache to be cleaned up before the
  125|       |     * provider store
  126|       |     */
  127|      2|    ctx->decoder_store = ossl_method_store_new(ctx);
  128|      2|    if (ctx->decoder_store == NULL)
  ------------------
  |  Branch (128:9): [True: 0, False: 2]
  ------------------
  129|      0|        goto err;
  130|      2|    ctx->decoder_cache = ossl_decoder_cache_new(ctx);
  131|      2|    if (ctx->decoder_cache == NULL)
  ------------------
  |  Branch (131:9): [True: 0, False: 2]
  ------------------
  132|      0|        goto err;
  133|       |
  134|       |    /* P2. We want encoder_store to be cleaned up before the provider store */
  135|      2|    ctx->encoder_store = ossl_method_store_new(ctx);
  136|      2|    if (ctx->encoder_store == NULL)
  ------------------
  |  Branch (136:9): [True: 0, False: 2]
  ------------------
  137|      0|        goto err;
  138|       |
  139|       |    /* P2. We want loader_store to be cleaned up before the provider store */
  140|      2|    ctx->store_loader_store = ossl_method_store_new(ctx);
  141|      2|    if (ctx->store_loader_store == NULL)
  ------------------
  |  Branch (141:9): [True: 0, False: 2]
  ------------------
  142|      0|        goto err;
  143|      2|#endif
  144|       |
  145|       |    /* P1. Needs to be freed before the child provider data is freed */
  146|      2|    ctx->provider_store = ossl_provider_store_new(ctx);
  147|      2|    if (ctx->provider_store == NULL)
  ------------------
  |  Branch (147:9): [True: 0, False: 2]
  ------------------
  148|      0|        goto err;
  149|       |
  150|       |    /* Default priority. */
  151|      2|    ctx->property_string_data = ossl_property_string_data_new(ctx);
  152|      2|    if (ctx->property_string_data == NULL)
  ------------------
  |  Branch (152:9): [True: 0, False: 2]
  ------------------
  153|      0|        goto err;
  154|       |
  155|      2|    ctx->namemap = ossl_stored_namemap_new(ctx);
  156|      2|    if (ctx->namemap == NULL)
  ------------------
  |  Branch (156:9): [True: 0, False: 2]
  ------------------
  157|      0|        goto err;
  158|       |
  159|      2|    ctx->property_defns = ossl_property_defns_new(ctx);
  160|      2|    if (ctx->property_defns == NULL)
  ------------------
  |  Branch (160:9): [True: 0, False: 2]
  ------------------
  161|      0|        goto err;
  162|       |
  163|      2|    ctx->global_properties = ossl_ctx_global_properties_new(ctx);
  164|      2|    if (ctx->global_properties == NULL)
  ------------------
  |  Branch (164:9): [True: 0, False: 2]
  ------------------
  165|      0|        goto err;
  166|       |
  167|      2|#ifndef FIPS_MODULE
  168|      2|    ctx->bio_core = ossl_bio_core_globals_new(ctx);
  169|      2|    if (ctx->bio_core == NULL)
  ------------------
  |  Branch (169:9): [True: 0, False: 2]
  ------------------
  170|      0|        goto err;
  171|      2|#endif
  172|       |
  173|      2|    ctx->drbg_nonce = ossl_prov_drbg_nonce_ctx_new(ctx);
  174|      2|    if (ctx->drbg_nonce == NULL)
  ------------------
  |  Branch (174:9): [True: 0, False: 2]
  ------------------
  175|      0|        goto err;
  176|       |
  177|      2|#ifndef FIPS_MODULE
  178|      2|    ctx->self_test_cb = ossl_self_test_set_callback_new(ctx);
  179|      2|    if (ctx->self_test_cb == NULL)
  ------------------
  |  Branch (179:9): [True: 0, False: 2]
  ------------------
  180|      0|        goto err;
  181|      2|    ctx->indicator_cb = ossl_indicator_set_callback_new(ctx);
  182|      2|    if (ctx->indicator_cb == NULL)
  ------------------
  |  Branch (182:9): [True: 0, False: 2]
  ------------------
  183|      0|        goto err;
  184|      2|#endif
  185|       |
  186|       |#ifdef FIPS_MODULE
  187|       |    ctx->thread_event_handler = ossl_thread_event_ctx_new(ctx);
  188|       |    if (ctx->thread_event_handler == NULL)
  189|       |        goto err;
  190|       |
  191|       |    ctx->fips_prov = ossl_fips_prov_ossl_ctx_new(ctx);
  192|       |    if (ctx->fips_prov == NULL)
  193|       |        goto err;
  194|       |#endif
  195|       |
  196|      2|#ifndef OPENSSL_NO_THREAD_POOL
  197|      2|    ctx->threads = ossl_threads_ctx_new(ctx);
  198|      2|    if (ctx->threads == NULL)
  ------------------
  |  Branch (198:9): [True: 0, False: 2]
  ------------------
  199|      0|        goto err;
  200|      2|#endif
  201|       |
  202|       |    /* Low priority. */
  203|      2|#ifndef FIPS_MODULE
  204|      2|    ctx->child_provider = ossl_child_prov_ctx_new(ctx);
  205|      2|    if (ctx->child_provider == NULL)
  ------------------
  |  Branch (205:9): [True: 0, False: 2]
  ------------------
  206|      0|        goto err;
  207|      2|#endif
  208|       |
  209|       |    /* Everything depends on properties, so we also pre-initialise that */
  210|      2|    if (!ossl_property_parse_init(ctx))
  ------------------
  |  Branch (210:9): [True: 0, False: 2]
  ------------------
  211|      0|        goto err;
  212|       |
  213|      2|#ifndef FIPS_MODULE
  214|      2|    ctx->comp_methods = ossl_load_builtin_compressions();
  215|      2|#endif
  216|       |
  217|      2|    return 1;
  218|       |
  219|      0| err:
  220|      0|    context_deinit_objs(ctx);
  221|       |
  222|      0|    if (exdata_done)
  ------------------
  |  Branch (222:9): [True: 0, False: 0]
  ------------------
  223|      0|        ossl_crypto_cleanup_all_ex_data_int(ctx);
  224|       |
  225|      0|    CRYPTO_THREAD_lock_free(ctx->rand_crngt_lock);
  226|      0|    CRYPTO_THREAD_lock_free(ctx->lock);
  227|      0|    CRYPTO_THREAD_cleanup_local(&ctx->rcu_local_key);
  228|      0|    memset(ctx, '\0', sizeof(*ctx));
  229|      0|    return 0;
  230|      2|}
context.c:default_context_do_init:
  400|      2|{
  401|      2|    if (!CRYPTO_THREAD_init_local(&default_context_thread_local, NULL))
  ------------------
  |  Branch (401:9): [True: 0, False: 2]
  ------------------
  402|      0|        goto err;
  403|       |
  404|      2|    if (!context_init(&default_context_int))
  ------------------
  |  Branch (404:9): [True: 0, False: 2]
  ------------------
  405|      0|        goto deinit_thread;
  406|       |
  407|      2|    default_context_inited = 1;
  408|      2|    return 1;
  409|       |
  410|      0|deinit_thread:
  411|      0|    CRYPTO_THREAD_cleanup_local(&default_context_thread_local);
  412|      0|err:
  413|      0|    return 0;
  414|      0|}
context.c:get_default_context:
  434|      2|{
  435|      2|    OSSL_LIB_CTX *current_defctx = get_thread_default_context();
  436|       |
  437|      2|    if (current_defctx == NULL)
  ------------------
  |  Branch (437:9): [True: 2, False: 0]
  ------------------
  438|      2|        current_defctx = &default_context_int;
  439|      2|    return current_defctx;
  440|      2|}
context.c:get_thread_default_context:
  426|      2|{
  427|      2|    if (!RUN_ONCE(&default_context_init, default_context_do_init))
  ------------------
  |  |  130|      2|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (427:9): [True: 0, False: 2]
  ------------------
  428|      0|        return NULL;
  429|       |
  430|      2|    return CRYPTO_THREAD_get_local(&default_context_thread_local);
  431|      2|}

ossl_stored_namemap_new:
   65|      2|{
   66|      2|    OSSL_NAMEMAP *namemap = ossl_namemap_new();
   67|       |
   68|      2|    if (namemap != NULL)
  ------------------
  |  Branch (68:9): [True: 2, False: 0]
  ------------------
   69|      2|        namemap->stored = 1;
   70|       |
   71|      2|    return namemap;
   72|      2|}
ossl_stored_namemap_free:
   75|      2|{
   76|      2|    OSSL_NAMEMAP *namemap = vnamemap;
   77|       |
   78|      2|    if (namemap != NULL) {
  ------------------
  |  Branch (78:9): [True: 2, False: 0]
  ------------------
   79|       |        /* Pretend it isn't stored, or ossl_namemap_free() will do nothing */
   80|      2|        namemap->stored = 0;
   81|      2|        ossl_namemap_free(namemap);
   82|      2|    }
   83|      2|}
ossl_namemap_new:
  512|      2|{
  513|      2|    OSSL_NAMEMAP *namemap;
  514|       |
  515|      2|    if ((namemap = OPENSSL_zalloc(sizeof(*namemap))) != NULL
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (515:9): [True: 2, False: 0]
  ------------------
  516|      2|        && (namemap->lock = CRYPTO_THREAD_lock_new()) != NULL
  ------------------
  |  Branch (516:12): [True: 2, False: 0]
  ------------------
  517|      2|        && (namemap->namenum =
  ------------------
  |  Branch (517:12): [True: 2, False: 0]
  ------------------
  518|      2|            lh_NAMENUM_ENTRY_new(namenum_hash, namenum_cmp)) != NULL)
  519|      2|        return namemap;
  520|       |
  521|      0|    ossl_namemap_free(namemap);
  522|      0|    return NULL;
  523|      2|}
ossl_namemap_free:
  526|      2|{
  527|      2|    if (namemap == NULL || namemap->stored)
  ------------------
  |  Branch (527:9): [True: 0, False: 2]
  |  Branch (527:28): [True: 0, False: 2]
  ------------------
  528|      0|        return;
  529|       |
  530|      2|    lh_NAMENUM_ENTRY_doall(namemap->namenum, namenum_free);
  531|      2|    lh_NAMENUM_ENTRY_free(namemap->namenum);
  532|       |
  533|      2|    CRYPTO_THREAD_lock_free(namemap->lock);
  534|      2|    OPENSSL_free(namemap);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  535|      2|}

ossl_err_load_CRYPTO_strings:
   82|      2|{
   83|      2|#ifndef OPENSSL_NO_ERR
   84|      2|    if (ERR_reason_error_string(CRYPTO_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (84:9): [True: 2, False: 0]
  ------------------
   85|      2|        ERR_load_strings_const(CRYPTO_str_reasons);
   86|      2|#endif
   87|      2|    return 1;
   88|      2|}

OPENSSL_cpuid_setup:
   96|      4|{
   97|      4|    static int trigger = 0;
   98|      4|    IA32CAP OPENSSL_ia32_cpuid(unsigned int *);
   99|      4|    IA32CAP vec;
  100|      4|    const variant_char *env;
  101|       |
  102|      4|    if (trigger)
  ------------------
  |  Branch (102:9): [True: 2, False: 2]
  ------------------
  103|      2|        return;
  104|       |
  105|      2|    trigger = 1;
  106|      2|    if ((env = ossl_getenv("OPENSSL_ia32cap")) != NULL) {
  ------------------
  |  |   47|      2|#   define ossl_getenv getenv
  ------------------
  |  Branch (106:9): [True: 0, False: 2]
  ------------------
  107|      0|        int off = (env[0] == '~') ? 1 : 0;
  ------------------
  |  Branch (107:19): [True: 0, False: 0]
  ------------------
  108|       |
  109|      0|        vec = ossl_strtouint64(env + off);
  110|       |
  111|      0|        if (off) {
  ------------------
  |  Branch (111:13): [True: 0, False: 0]
  ------------------
  112|      0|            IA32CAP mask = vec;
  113|      0|            vec = OPENSSL_ia32_cpuid(OPENSSL_ia32cap_P) & ~mask;
  114|      0|            if (mask & (1<<24)) {
  ------------------
  |  Branch (114:17): [True: 0, False: 0]
  ------------------
  115|       |                /*
  116|       |                 * User disables FXSR bit, mask even other capabilities
  117|       |                 * that operate exclusively on XMM, so we don't have to
  118|       |                 * double-check all the time. We mask PCLMULQDQ, AMD XOP,
  119|       |                 * AES-NI and AVX. Formally speaking we don't have to
  120|       |                 * do it in x86_64 case, but we can safely assume that
  121|       |                 * x86_64 users won't actually flip this flag.
  122|       |                 */
  123|      0|                vec &= ~((IA32CAP)(1<<1|1<<11|1<<25|1<<28) << 32);
  124|      0|            }
  125|      0|        } else if (env[0] == ':') {
  ------------------
  |  Branch (125:20): [True: 0, False: 0]
  ------------------
  126|      0|            vec = OPENSSL_ia32_cpuid(OPENSSL_ia32cap_P);
  127|      0|        }
  128|       |
  129|      0|        if ((env = ossl_strchr(env, ':')) != NULL) {
  ------------------
  |  Branch (129:13): [True: 0, False: 0]
  ------------------
  130|      0|            IA32CAP vecx;
  131|       |
  132|      0|            env++;
  133|      0|            off = (env[0] == '~') ? 1 : 0;
  ------------------
  |  Branch (133:19): [True: 0, False: 0]
  ------------------
  134|      0|            vecx = ossl_strtouint64(env + off);
  135|      0|            if (off) {
  ------------------
  |  Branch (135:17): [True: 0, False: 0]
  ------------------
  136|      0|                OPENSSL_ia32cap_P[2] &= ~(unsigned int)vecx;
  137|      0|                OPENSSL_ia32cap_P[3] &= ~(unsigned int)(vecx >> 32);
  138|      0|            } else {
  139|      0|                OPENSSL_ia32cap_P[2] = (unsigned int)vecx;
  140|      0|                OPENSSL_ia32cap_P[3] = (unsigned int)(vecx >> 32);
  141|      0|            }
  142|      0|        } else {
  143|      0|            OPENSSL_ia32cap_P[2] = 0;
  144|      0|            OPENSSL_ia32cap_P[3] = 0;
  145|      0|        }
  146|      2|    } else {
  147|      2|        vec = OPENSSL_ia32_cpuid(OPENSSL_ia32cap_P);
  148|      2|    }
  149|       |
  150|       |    /*
  151|       |     * |(1<<10) sets a reserved bit to signal that variable
  152|       |     * was initialized already... This is to avoid interference
  153|       |     * with cpuid snippets in ELF .init segment.
  154|       |     */
  155|      2|    OPENSSL_ia32cap_P[0] = (unsigned int)vec | (1 << 10);
  156|      2|    OPENSSL_ia32cap_P[1] = (unsigned int)(vec >> 32);
  157|      2|}

ossl_err_load_CRMF_strings:
   65|      2|{
   66|      2|# ifndef OPENSSL_NO_ERR
   67|      2|    if (ERR_reason_error_string(CRMF_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (67:9): [True: 2, False: 0]
  ------------------
   68|      2|        ERR_load_strings_const(CRMF_str_reasons);
   69|      2|# endif
   70|      2|    return 1;
   71|      2|}

ossl_err_load_CT_strings:
   52|      2|{
   53|      2|# ifndef OPENSSL_NO_ERR
   54|      2|    if (ERR_reason_error_string(CT_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (54:9): [True: 2, False: 0]
  ------------------
   55|      2|        ERR_load_strings_const(CT_str_reasons);
   56|      2|# endif
   57|      2|    return 1;
   58|      2|}

ossl_err_load_DH_strings:
   68|      2|{
   69|      2|# ifndef OPENSSL_NO_ERR
   70|      2|    if (ERR_reason_error_string(DH_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (70:9): [True: 2, False: 0]
  ------------------
   71|      2|        ERR_load_strings_const(DH_str_reasons);
   72|      2|# endif
   73|      2|    return 1;
   74|      2|}

ossl_err_load_DSA_strings:
   46|      2|{
   47|      2|# ifndef OPENSSL_NO_ERR
   48|      2|    if (ERR_reason_error_string(DSA_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (48:9): [True: 2, False: 0]
  ------------------
   49|      2|        ERR_load_strings_const(DSA_str_reasons);
   50|      2|# endif
   51|      2|    return 1;
   52|      2|}

ossl_err_load_DSO_strings:
   50|      2|{
   51|      2|#ifndef OPENSSL_NO_ERR
   52|      2|    if (ERR_reason_error_string(DSO_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (52:9): [True: 2, False: 0]
  ------------------
   53|      2|        ERR_load_strings_const(DSO_str_reasons);
   54|      2|#endif
   55|      2|    return 1;
   56|      2|}

ossl_err_load_EC_strings:
  127|      2|{
  128|      2|# ifndef OPENSSL_NO_ERR
  129|      2|    if (ERR_reason_error_string(EC_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (129:9): [True: 2, False: 0]
  ------------------
  130|      2|        ERR_load_strings_const(EC_str_reasons);
  131|      2|# endif
  132|      2|    return 1;
  133|      2|}

ossl_decoder_cache_new:
  683|      2|{
  684|      2|    DECODER_CACHE *cache = OPENSSL_malloc(sizeof(*cache));
  ------------------
  |  |  102|      2|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  685|       |
  686|      2|    if (cache == NULL)
  ------------------
  |  Branch (686:9): [True: 0, False: 2]
  ------------------
  687|      0|        return NULL;
  688|       |
  689|      2|    cache->lock = CRYPTO_THREAD_lock_new();
  690|      2|    if (cache->lock == NULL) {
  ------------------
  |  Branch (690:9): [True: 0, False: 2]
  ------------------
  691|      0|        OPENSSL_free(cache);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  692|      0|        return NULL;
  693|      0|    }
  694|      2|    cache->hashtable = lh_DECODER_CACHE_ENTRY_new(decoder_cache_entry_hash,
  695|      2|                                                  decoder_cache_entry_cmp);
  696|      2|    if (cache->hashtable == NULL) {
  ------------------
  |  Branch (696:9): [True: 0, False: 2]
  ------------------
  697|      0|        CRYPTO_THREAD_lock_free(cache->lock);
  698|      0|        OPENSSL_free(cache);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  699|      0|        return NULL;
  700|      0|    }
  701|       |
  702|      2|    return cache;
  703|      2|}
ossl_decoder_cache_free:
  706|      2|{
  707|      2|    DECODER_CACHE *cache = (DECODER_CACHE *)vcache;
  708|       |
  709|      2|    lh_DECODER_CACHE_ENTRY_doall(cache->hashtable, decoder_cache_entry_free);
  710|      2|    lh_DECODER_CACHE_ENTRY_free(cache->hashtable);
  711|      2|    CRYPTO_THREAD_lock_free(cache->lock);
  712|      2|    OPENSSL_free(cache);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  713|      2|}

ossl_err_load_ENGINE_strings:
   85|      2|{
   86|      2|# ifndef OPENSSL_NO_ERR
   87|      2|    if (ERR_reason_error_string(ENGINE_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (87:9): [True: 2, False: 0]
  ------------------
   88|      2|        ERR_load_strings_const(ENGINE_str_reasons);
   89|      2|# endif
   90|      2|    return 1;
   91|      2|}

engine_cleanup_int:
  176|      2|{
  177|      2|    if (int_cleanup_check(0)) {
  ------------------
  |  Branch (177:9): [True: 0, False: 2]
  ------------------
  178|      0|        sk_ENGINE_CLEANUP_ITEM_pop_free(cleanup_stack,
  179|      0|                                        engine_cleanup_cb_free);
  180|      0|        cleanup_stack = NULL;
  181|      0|    }
  182|      2|    CRYPTO_THREAD_lock_free(global_engine_lock);
  183|      2|    global_engine_lock = NULL;
  184|      2|}
eng_lib.c:int_cleanup_check:
  119|      2|{
  120|      2|    if (cleanup_stack)
  ------------------
  |  Branch (120:9): [True: 0, False: 2]
  ------------------
  121|      0|        return 1;
  122|      2|    if (!create)
  ------------------
  |  Branch (122:9): [True: 2, False: 0]
  ------------------
  123|      2|        return 0;
  124|      0|    cleanup_stack = sk_ENGINE_CLEANUP_ITEM_new_null();
  125|      0|    return (cleanup_stack ? 1 : 0);
  ------------------
  |  Branch (125:13): [True: 0, False: 0]
  ------------------
  126|      2|}

OSSL_ERR_STATE_free:
  202|      2|{
  203|      2|    int i;
  204|       |
  205|      2|    if (state == NULL)
  ------------------
  |  Branch (205:9): [True: 0, False: 2]
  ------------------
  206|      0|        return;
  207|     34|    for (i = 0; i < ERR_NUM_ERRORS; i++) {
  ------------------
  |  |   55|     34|#  define ERR_NUM_ERRORS  16
  ------------------
  |  Branch (207:17): [True: 32, False: 2]
  ------------------
  208|     32|        err_clear(state, i, 1);
  209|     32|    }
  210|      2|    CRYPTO_free(state, OPENSSL_FILE, OPENSSL_LINE);
  ------------------
  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  ------------------
                  CRYPTO_free(state, OPENSSL_FILE, OPENSSL_LINE);
  ------------------
  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  ------------------
  211|      2|}
err_cleanup:
  233|      2|{
  234|      2|    if (set_err_thread_local != 0)
  ------------------
  |  Branch (234:9): [True: 2, False: 0]
  ------------------
  235|      2|        CRYPTO_THREAD_cleanup_local(&err_thread_local);
  236|      2|    CRYPTO_THREAD_lock_free(err_string_lock);
  237|      2|    err_string_lock = NULL;
  238|      2|#ifndef OPENSSL_NO_ERR
  239|      2|    lh_ERR_STRING_DATA_free(int_error_hash);
  ------------------
  |  |  376|      2|#define lh_ERR_STRING_DATA_free(lh) OPENSSL_LH_free(ossl_check_ERR_STRING_DATA_lh_type(lh))
  ------------------
  240|      2|    int_error_hash = NULL;
  241|      2|#endif
  242|      2|}
ossl_err_load_ERR_strings:
  272|     70|{
  273|     70|#ifndef OPENSSL_NO_ERR
  274|     70|    if (!RUN_ONCE(&err_string_init, do_err_strings_init))
  ------------------
  |  |  130|     70|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 70, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (274:9): [True: 0, False: 70]
  ------------------
  275|      0|        return 0;
  276|       |
  277|     70|    err_load_strings(ERR_str_libraries);
  278|     70|    err_load_strings(ERR_str_reasons);
  279|     70|#endif
  280|     70|    return 1;
  281|     70|}
ERR_load_strings_const:
  297|     68|{
  298|     68|#ifndef OPENSSL_NO_ERR
  299|     68|    if (ossl_err_load_ERR_strings() == 0)
  ------------------
  |  Branch (299:9): [True: 0, False: 68]
  ------------------
  300|      0|        return 0;
  301|     68|    err_load_strings(str);
  302|     68|#endif
  303|       |
  304|     68|    return 1;
  305|     68|}
ERR_clear_error:
  335|  3.06k|{
  336|  3.06k|    int i;
  337|  3.06k|    ERR_STATE *es;
  338|       |
  339|  3.06k|    es = ossl_err_get_state_int();
  340|  3.06k|    if (es == NULL)
  ------------------
  |  Branch (340:9): [True: 0, False: 3.06k]
  ------------------
  341|      0|        return;
  342|       |
  343|  52.0k|    for (i = 0; i < ERR_NUM_ERRORS; i++) {
  ------------------
  |  |   55|  52.0k|#  define ERR_NUM_ERRORS  16
  ------------------
  |  Branch (343:17): [True: 48.9k, False: 3.06k]
  ------------------
  344|  48.9k|        err_clear(es, i, 0);
  345|  48.9k|    }
  346|  3.06k|    es->top = es->bottom = 0;
  347|  3.06k|}
ERR_reason_error_string:
  613|     68|{
  614|     68|#ifndef OPENSSL_NO_ERR
  615|     68|    ERR_STRING_DATA d, *p = NULL;
  616|     68|    unsigned long l, r;
  617|       |
  618|     68|    if (!RUN_ONCE(&err_string_init, do_err_strings_init)) {
  ------------------
  |  |  130|     68|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 68, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (618:9): [True: 0, False: 68]
  ------------------
  619|      0|        return NULL;
  620|      0|    }
  621|       |
  622|       |    /*
  623|       |     * ERR_reason_error_string() can't safely return system error strings,
  624|       |     * since openssl_strerror_r() needs a buffer for thread safety, and we
  625|       |     * haven't got one that would serve any sensible purpose.
  626|       |     */
  627|     68|    if (ERR_SYSTEM_ERROR(e))
  ------------------
  |  |  239|     68|# define ERR_SYSTEM_ERROR(errcode)      (((errcode) & ERR_SYSTEM_FLAG) != 0)
  |  |  ------------------
  |  |  |  |  218|     68|# define ERR_SYSTEM_FLAG                ((unsigned int)INT_MAX + 1)
  |  |  ------------------
  |  |  |  Branch (239:41): [True: 0, False: 68]
  |  |  ------------------
  ------------------
  628|      0|        return NULL;
  629|       |
  630|     68|    l = ERR_GET_LIB(e);
  631|     68|    r = ERR_GET_REASON(e);
  632|     68|    d.error = ERR_PACK(l, 0, r);
  ------------------
  |  |  279|     68|    ( (((unsigned long)(lib)    & ERR_LIB_MASK   ) << ERR_LIB_OFFSET) | \
  |  |  ------------------
  |  |  |  |  227|     68|# define ERR_LIB_MASK                   0xFF
  |  |  ------------------
  |  |                   ( (((unsigned long)(lib)    & ERR_LIB_MASK   ) << ERR_LIB_OFFSET) | \
  |  |  ------------------
  |  |  |  |  226|     68|# define ERR_LIB_OFFSET                 23L
  |  |  ------------------
  |  |  280|     68|      (((unsigned long)(reason) & ERR_REASON_MASK)) )
  |  |  ------------------
  |  |  |  |  230|     68|# define ERR_REASON_MASK                0X7FFFFF
  |  |  ------------------
  ------------------
  633|     68|    p = int_err_get_item(&d);
  634|     68|    if (p == NULL) {
  ------------------
  |  Branch (634:9): [True: 68, False: 0]
  ------------------
  635|     68|        d.error = ERR_PACK(0, 0, r);
  ------------------
  |  |  279|     68|    ( (((unsigned long)(lib)    & ERR_LIB_MASK   ) << ERR_LIB_OFFSET) | \
  |  |  ------------------
  |  |  |  |  227|     68|# define ERR_LIB_MASK                   0xFF
  |  |  ------------------
  |  |                   ( (((unsigned long)(lib)    & ERR_LIB_MASK   ) << ERR_LIB_OFFSET) | \
  |  |  ------------------
  |  |  |  |  226|     68|# define ERR_LIB_OFFSET                 23L
  |  |  ------------------
  |  |  280|     68|      (((unsigned long)(reason) & ERR_REASON_MASK)) )
  |  |  ------------------
  |  |  |  |  230|     68|# define ERR_REASON_MASK                0X7FFFFF
  |  |  ------------------
  ------------------
  636|     68|        p = int_err_get_item(&d);
  637|     68|    }
  638|     68|    return ((p == NULL) ? NULL : p->string);
  ------------------
  |  Branch (638:13): [True: 68, False: 0]
  ------------------
  639|       |#else
  640|       |    return NULL;
  641|       |#endif
  642|     68|}
ossl_err_get_state_int:
  673|  3.06k|{
  674|  3.06k|    ERR_STATE *state;
  675|  3.06k|    int saveerrno = get_last_sys_error();
  ------------------
  |  |   30|  3.06k|# define get_last_sys_error()    errno
  ------------------
  676|       |
  677|  3.06k|    if (!OPENSSL_init_crypto(OPENSSL_INIT_BASE_ONLY, NULL))
  ------------------
  |  |   31|  3.06k|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (677:9): [True: 0, False: 3.06k]
  ------------------
  678|      0|        return NULL;
  679|       |
  680|  3.06k|    if (!RUN_ONCE(&err_init, err_do_init))
  ------------------
  |  |  130|  3.06k|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 3.06k, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (680:9): [True: 0, False: 3.06k]
  ------------------
  681|      0|        return NULL;
  682|       |
  683|  3.06k|    state = CRYPTO_THREAD_get_local(&err_thread_local);
  684|  3.06k|    if (state == (ERR_STATE*)-1)
  ------------------
  |  Branch (684:9): [True: 0, False: 3.06k]
  ------------------
  685|      0|        return NULL;
  686|       |
  687|  3.06k|    if (state == NULL) {
  ------------------
  |  Branch (687:9): [True: 2, False: 3.05k]
  ------------------
  688|      2|        if (!CRYPTO_THREAD_set_local(&err_thread_local, (ERR_STATE*)-1))
  ------------------
  |  Branch (688:13): [True: 0, False: 2]
  ------------------
  689|      0|            return NULL;
  690|       |
  691|      2|        state = OSSL_ERR_STATE_new();
  692|      2|        if (state == NULL) {
  ------------------
  |  Branch (692:13): [True: 0, False: 2]
  ------------------
  693|      0|            CRYPTO_THREAD_set_local(&err_thread_local, NULL);
  694|      0|            return NULL;
  695|      0|        }
  696|       |
  697|      2|        if (!ossl_init_thread_start(NULL, NULL, err_delete_thread_state)
  ------------------
  |  Branch (697:13): [True: 0, False: 2]
  ------------------
  698|      2|                || !CRYPTO_THREAD_set_local(&err_thread_local, state)) {
  ------------------
  |  Branch (698:20): [True: 0, False: 2]
  ------------------
  699|      0|            OSSL_ERR_STATE_free(state);
  700|      0|            CRYPTO_THREAD_set_local(&err_thread_local, NULL);
  701|      0|            return NULL;
  702|      0|        }
  703|       |
  704|       |        /* Ignore failures from these */
  705|      2|        OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL);
  ------------------
  |  |  463|      2|# define OPENSSL_INIT_LOAD_CRYPTO_STRINGS    0x00000002L
  ------------------
  706|      2|    }
  707|       |
  708|  3.06k|    set_sys_error(saveerrno);
  ------------------
  |  |   32|  3.06k|# define set_sys_error(e)        errno=(e)
  ------------------
  709|  3.06k|    return state;
  710|  3.06k|}
err_shelve_state:
  725|      2|{
  726|      2|    int saveerrno = get_last_sys_error();
  ------------------
  |  |   30|      2|# define get_last_sys_error()    errno
  ------------------
  727|       |
  728|       |    /*
  729|       |     * Note, at present our only caller is OPENSSL_init_crypto(), indirectly
  730|       |     * via ossl_init_load_crypto_nodelete(), by which point the requested
  731|       |     * "base" initialization has already been performed, so the below call is a
  732|       |     * NOOP, that re-enters OPENSSL_init_crypto() only to quickly return.
  733|       |     *
  734|       |     * If are no other valid callers of this function, the call below can be
  735|       |     * removed, avoiding the re-entry into OPENSSL_init_crypto().  If there are
  736|       |     * potential uses that are not from inside OPENSSL_init_crypto(), then this
  737|       |     * call is needed, but some care is required to make sure that the re-entry
  738|       |     * remains a NOOP.
  739|       |     */
  740|      2|    if (!OPENSSL_init_crypto(OPENSSL_INIT_BASE_ONLY, NULL))
  ------------------
  |  |   31|      2|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (740:9): [True: 0, False: 2]
  ------------------
  741|      0|        return 0;
  742|       |
  743|      2|    if (!RUN_ONCE(&err_init, err_do_init))
  ------------------
  |  |  130|      2|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (743:9): [True: 0, False: 2]
  ------------------
  744|      0|        return 0;
  745|       |
  746|      2|    *state = CRYPTO_THREAD_get_local(&err_thread_local);
  747|      2|    if (!CRYPTO_THREAD_set_local(&err_thread_local, (ERR_STATE*)-1))
  ------------------
  |  Branch (747:9): [True: 0, False: 2]
  ------------------
  748|      0|        return 0;
  749|       |
  750|      2|    set_sys_error(saveerrno);
  ------------------
  |  |   32|      2|# define set_sys_error(e)        errno=(e)
  ------------------
  751|      2|    return 1;
  752|      2|}
err_unshelve_state:
  759|      2|{
  760|      2|    if (state != (void*)-1)
  ------------------
  |  Branch (760:9): [True: 2, False: 0]
  ------------------
  761|      2|        CRYPTO_THREAD_set_local(&err_thread_local, (ERR_STATE*)state);
  762|      2|}
err.c:do_err_strings_init:
  214|      2|{
  215|      2|    if (!OPENSSL_init_crypto(OPENSSL_INIT_BASE_ONLY, NULL))
  ------------------
  |  |   31|      2|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (215:9): [True: 0, False: 2]
  ------------------
  216|      0|        return 0;
  217|      2|    err_string_lock = CRYPTO_THREAD_lock_new();
  218|      2|    if (err_string_lock == NULL)
  ------------------
  |  Branch (218:9): [True: 0, False: 2]
  ------------------
  219|      0|        return 0;
  220|      2|#ifndef OPENSSL_NO_ERR
  221|      2|    int_error_hash = lh_ERR_STRING_DATA_new(err_string_data_hash,
  ------------------
  |  |  375|      2|#define lh_ERR_STRING_DATA_new(hfn, cmp) ((LHASH_OF(ERR_STRING_DATA) *)OPENSSL_LH_set_thunks(OPENSSL_LH_new(ossl_check_ERR_STRING_DATA_lh_hashfunc_type(hfn), ossl_check_ERR_STRING_DATA_lh_compfunc_type(cmp)), lh_ERR_STRING_DATA_hash_thunk, lh_ERR_STRING_DATA_comp_thunk, lh_ERR_STRING_DATA_doall_thunk, lh_ERR_STRING_DATA_doall_arg_thunk))
  ------------------
  222|      2|                                            err_string_data_cmp);
  223|      2|    if (int_error_hash == NULL) {
  ------------------
  |  Branch (223:9): [True: 0, False: 2]
  ------------------
  224|      0|        CRYPTO_THREAD_lock_free(err_string_lock);
  225|      0|        err_string_lock = NULL;
  226|      0|        return 0;
  227|      0|    }
  228|      2|#endif
  229|      2|    return 1;
  230|      2|}
err.c:err_string_data_hash:
  172|  8.67k|{
  173|  8.67k|    unsigned long ret, l;
  174|       |
  175|  8.67k|    l = a->error;
  176|  8.67k|    ret = l ^ ERR_GET_LIB(l);
  177|  8.67k|    return (ret ^ ret % 19 * 13);
  178|  8.67k|}
err.c:err_string_data_cmp:
  182|  5.88k|{
  183|  5.88k|    if (a->error == b->error)
  ------------------
  |  Branch (183:9): [True: 5.57k, False: 304]
  ------------------
  184|  5.57k|        return 0;
  185|    304|    return a->error > b->error ? 1 : -1;
  ------------------
  |  Branch (185:12): [True: 164, False: 140]
  ------------------
  186|  5.88k|}
err.c:err_load_strings:
  260|    208|{
  261|    208|    if (!CRYPTO_THREAD_write_lock(err_string_lock))
  ------------------
  |  Branch (261:9): [True: 0, False: 208]
  ------------------
  262|      0|        return 0;
  263|  8.74k|    for (; str->error; str++)
  ------------------
  |  Branch (263:12): [True: 8.53k, False: 208]
  ------------------
  264|  8.53k|        (void)lh_ERR_STRING_DATA_insert(int_error_hash,
  ------------------
  |  |  378|  8.74k|#define lh_ERR_STRING_DATA_insert(lh, ptr) ((ERR_STRING_DATA *)OPENSSL_LH_insert(ossl_check_ERR_STRING_DATA_lh_type(lh), ossl_check_ERR_STRING_DATA_lh_plain_type(ptr)))
  ------------------
  265|    208|                                       (ERR_STRING_DATA *)str);
  266|    208|    CRYPTO_THREAD_unlock(err_string_lock);
  267|    208|    return 1;
  268|    208|}
err.c:int_err_get_item:
  189|    136|{
  190|    136|    ERR_STRING_DATA *p = NULL;
  191|       |
  192|    136|    if (!CRYPTO_THREAD_read_lock(err_string_lock))
  ------------------
  |  Branch (192:9): [True: 0, False: 136]
  ------------------
  193|      0|        return NULL;
  194|    136|    p = lh_ERR_STRING_DATA_retrieve(int_error_hash, d);
  ------------------
  |  |  380|    136|#define lh_ERR_STRING_DATA_retrieve(lh, ptr) ((ERR_STRING_DATA *)OPENSSL_LH_retrieve(ossl_check_ERR_STRING_DATA_lh_type(lh), ossl_check_const_ERR_STRING_DATA_lh_plain_type(ptr)))
  ------------------
  195|    136|    CRYPTO_THREAD_unlock(err_string_lock);
  196|       |
  197|    136|    return p;
  198|    136|}
err.c:err_do_init:
  667|      2|{
  668|      2|    set_err_thread_local = 1;
  669|      2|    return CRYPTO_THREAD_init_local(&err_thread_local, NULL);
  670|      2|}
err.c:err_delete_thread_state:
  645|      2|{
  646|      2|    ERR_STATE *state = CRYPTO_THREAD_get_local(&err_thread_local);
  647|      2|    if (state == NULL)
  ------------------
  |  Branch (647:9): [True: 0, False: 2]
  ------------------
  648|      0|        return;
  649|       |
  650|      2|    CRYPTO_THREAD_set_local(&err_thread_local, NULL);
  651|      2|    OSSL_ERR_STATE_free(state);
  652|      2|}

ossl_err_load_crypto_strings:
   49|      2|{
   50|      2|    if (0
  ------------------
  |  Branch (50:9): [Folded - Ignored]
  ------------------
   51|      2|#ifndef OPENSSL_NO_ERR
   52|      2|        || ossl_err_load_ERR_strings() == 0 /* include error strings for SYSerr */
  ------------------
  |  Branch (52:12): [True: 0, False: 2]
  ------------------
   53|      2|        || ossl_err_load_BN_strings() == 0
  ------------------
  |  Branch (53:12): [True: 0, False: 2]
  ------------------
   54|      2|        || ossl_err_load_RSA_strings() == 0
  ------------------
  |  Branch (54:12): [True: 0, False: 2]
  ------------------
   55|      2|# ifndef OPENSSL_NO_DH
   56|      2|        || ossl_err_load_DH_strings() == 0
  ------------------
  |  Branch (56:12): [True: 0, False: 2]
  ------------------
   57|      2|# endif
   58|      2|        || ossl_err_load_EVP_strings() == 0
  ------------------
  |  Branch (58:12): [True: 0, False: 2]
  ------------------
   59|      2|        || ossl_err_load_BUF_strings() == 0
  ------------------
  |  Branch (59:12): [True: 0, False: 2]
  ------------------
   60|      2|        || ossl_err_load_OBJ_strings() == 0
  ------------------
  |  Branch (60:12): [True: 0, False: 2]
  ------------------
   61|      2|        || ossl_err_load_PEM_strings() == 0
  ------------------
  |  Branch (61:12): [True: 0, False: 2]
  ------------------
   62|      2|# ifndef OPENSSL_NO_DSA
   63|      2|        || ossl_err_load_DSA_strings() == 0
  ------------------
  |  Branch (63:12): [True: 0, False: 2]
  ------------------
   64|      2|# endif
   65|      2|        || ossl_err_load_X509_strings() == 0
  ------------------
  |  Branch (65:12): [True: 0, False: 2]
  ------------------
   66|      2|        || ossl_err_load_ASN1_strings() == 0
  ------------------
  |  Branch (66:12): [True: 0, False: 2]
  ------------------
   67|      2|        || ossl_err_load_CONF_strings() == 0
  ------------------
  |  Branch (67:12): [True: 0, False: 2]
  ------------------
   68|      2|        || ossl_err_load_CRYPTO_strings() == 0
  ------------------
  |  Branch (68:12): [True: 0, False: 2]
  ------------------
   69|      2|# ifndef OPENSSL_NO_COMP
   70|      2|        || ossl_err_load_COMP_strings() == 0
  ------------------
  |  Branch (70:12): [True: 0, False: 2]
  ------------------
   71|      2|# endif
   72|      2|# ifndef OPENSSL_NO_EC
   73|      2|        || ossl_err_load_EC_strings() == 0
  ------------------
  |  Branch (73:12): [True: 0, False: 2]
  ------------------
   74|      2|# endif
   75|       |        /* skip ossl_err_load_SSL_strings() because it is not in this library */
   76|      2|        || ossl_err_load_BIO_strings() == 0
  ------------------
  |  Branch (76:12): [True: 0, False: 2]
  ------------------
   77|      2|        || ossl_err_load_PKCS7_strings() == 0
  ------------------
  |  Branch (77:12): [True: 0, False: 2]
  ------------------
   78|      2|        || ossl_err_load_X509V3_strings() == 0
  ------------------
  |  Branch (78:12): [True: 0, False: 2]
  ------------------
   79|      2|        || ossl_err_load_PKCS12_strings() == 0
  ------------------
  |  Branch (79:12): [True: 0, False: 2]
  ------------------
   80|      2|        || ossl_err_load_RAND_strings() == 0
  ------------------
  |  Branch (80:12): [True: 0, False: 2]
  ------------------
   81|      2|        || ossl_err_load_DSO_strings() == 0
  ------------------
  |  Branch (81:12): [True: 0, False: 2]
  ------------------
   82|      2|# ifndef OPENSSL_NO_TS
   83|      2|        || ossl_err_load_TS_strings() == 0
  ------------------
  |  Branch (83:12): [True: 0, False: 2]
  ------------------
   84|      2|# endif
   85|      2|# ifndef OPENSSL_NO_ENGINE
   86|      2|        || ossl_err_load_ENGINE_strings() == 0
  ------------------
  |  Branch (86:12): [True: 0, False: 2]
  ------------------
   87|      2|# endif
   88|      2|# ifndef OPENSSL_NO_HTTP
   89|      2|        || ossl_err_load_HTTP_strings() == 0
  ------------------
  |  Branch (89:12): [True: 0, False: 2]
  ------------------
   90|      2|# endif
   91|      2|# ifndef OPENSSL_NO_OCSP
   92|      2|        || ossl_err_load_OCSP_strings() == 0
  ------------------
  |  Branch (92:12): [True: 0, False: 2]
  ------------------
   93|      2|# endif
   94|      2|        || ossl_err_load_UI_strings() == 0
  ------------------
  |  Branch (94:12): [True: 0, False: 2]
  ------------------
   95|      2|# ifndef OPENSSL_NO_CMS
   96|      2|        || ossl_err_load_CMS_strings() == 0
  ------------------
  |  Branch (96:12): [True: 0, False: 2]
  ------------------
   97|      2|# endif
   98|      2|# ifndef OPENSSL_NO_CRMF
   99|      2|        || ossl_err_load_CRMF_strings() == 0
  ------------------
  |  Branch (99:12): [True: 0, False: 2]
  ------------------
  100|      2|        || ossl_err_load_CMP_strings() == 0
  ------------------
  |  Branch (100:12): [True: 0, False: 2]
  ------------------
  101|      2|# endif
  102|      2|# ifndef OPENSSL_NO_CT
  103|      2|        || ossl_err_load_CT_strings() == 0
  ------------------
  |  Branch (103:12): [True: 0, False: 2]
  ------------------
  104|      2|# endif
  105|      2|        || ossl_err_load_ESS_strings() == 0
  ------------------
  |  Branch (105:12): [True: 0, False: 2]
  ------------------
  106|      2|        || ossl_err_load_ASYNC_strings() == 0
  ------------------
  |  Branch (106:12): [True: 0, False: 2]
  ------------------
  107|      2|        || ossl_err_load_OSSL_STORE_strings() == 0
  ------------------
  |  Branch (107:12): [True: 0, False: 2]
  ------------------
  108|      2|        || ossl_err_load_PROP_strings() == 0
  ------------------
  |  Branch (108:12): [True: 0, False: 2]
  ------------------
  109|      2|        || ossl_err_load_PROV_strings() == 0
  ------------------
  |  Branch (109:12): [True: 0, False: 2]
  ------------------
  110|      2|#endif
  111|      2|        )
  112|      0|        return 0;
  113|       |
  114|      2|    return 1;
  115|      2|}

err.c:err_clear:
   85|  48.9k|{
   86|  48.9k|    err_clear_data(es, i, (deall));
   87|  48.9k|    es->err_marks[i] = 0;
   88|  48.9k|    es->err_flags[i] = 0;
   89|  48.9k|    es->err_buffer[i] = 0;
   90|  48.9k|    es->err_line[i] = -1;
   91|  48.9k|    OPENSSL_free(es->err_file[i]);
  ------------------
  |  |  115|  48.9k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  48.9k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  48.9k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   92|  48.9k|    es->err_file[i] = NULL;
   93|  48.9k|    OPENSSL_free(es->err_func[i]);
  ------------------
  |  |  115|  48.9k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  48.9k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  48.9k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   94|  48.9k|    es->err_func[i] = NULL;
   95|  48.9k|}
err.c:err_clear_data:
   22|  48.9k|{
   23|  48.9k|    if (es->err_data_flags[i] & ERR_TXT_MALLOCED) {
  ------------------
  |  |   48|  48.9k|# define ERR_TXT_MALLOCED        0x01
  ------------------
  |  Branch (23:9): [True: 0, False: 48.9k]
  ------------------
   24|      0|        if (deall) {
  ------------------
  |  Branch (24:13): [True: 0, False: 0]
  ------------------
   25|      0|            OPENSSL_free(es->err_data[i]);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   26|      0|            es->err_data[i] = NULL;
   27|      0|            es->err_data_size[i] = 0;
   28|      0|            es->err_data_flags[i] = 0;
   29|      0|        } else if (es->err_data[i] != NULL) {
  ------------------
  |  Branch (29:20): [True: 0, False: 0]
  ------------------
   30|      0|            es->err_data[i][0] = '\0';
   31|      0|            es->err_data_flags[i] = ERR_TXT_MALLOCED;
  ------------------
  |  |   48|      0|# define ERR_TXT_MALLOCED        0x01
  ------------------
   32|      0|        }
   33|  48.9k|    } else {
   34|  48.9k|        es->err_data[i] = NULL;
   35|  48.9k|        es->err_data_size[i] = 0;
   36|  48.9k|        es->err_data_flags[i] = 0;
   37|  48.9k|    }
   38|  48.9k|}

OSSL_ERR_STATE_new:
   22|      2|{
   23|      2|    return CRYPTO_zalloc(sizeof(ERR_STATE), NULL, 0);
   24|      2|}

ossl_err_load_ESS_strings:
   42|      2|{
   43|      2|#ifndef OPENSSL_NO_ERR
   44|      2|    if (ERR_reason_error_string(ESS_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (44:9): [True: 2, False: 0]
  ------------------
   45|      2|        ERR_load_strings_const(ESS_str_reasons);
   46|      2|#endif
   47|      2|    return 1;
   48|      2|}

ossl_err_load_EVP_strings:
  206|      2|{
  207|      2|#ifndef OPENSSL_NO_ERR
  208|      2|    if (ERR_reason_error_string(EVP_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (208:9): [True: 2, False: 0]
  ------------------
  209|      2|        ERR_load_strings_const(EVP_str_reasons);
  210|      2|#endif
  211|      2|    return 1;
  212|      2|}

EVP_PBE_cleanup:
  295|      2|{
  296|      2|    sk_EVP_PBE_CTL_pop_free(pbe_algs, free_evp_pbe_ctl);
  297|      2|    pbe_algs = NULL;
  298|      2|}

EVP_RAND_CTX_free:
  386|      4|{
  387|      4|    int ref = 0;
  388|      4|    EVP_RAND_CTX *parent;
  389|       |
  390|      4|    if (ctx == NULL)
  ------------------
  |  Branch (390:9): [True: 4, False: 0]
  ------------------
  391|      4|        return;
  392|       |
  393|      0|    CRYPTO_DOWN_REF(&ctx->refcnt, &ref);
  394|      0|    if (ref > 0)
  ------------------
  |  Branch (394:9): [True: 0, False: 0]
  ------------------
  395|      0|        return;
  396|      0|    parent = ctx->parent;
  397|      0|    ctx->meth->freectx(ctx->algctx);
  398|      0|    ctx->algctx = NULL;
  399|      0|    EVP_RAND_free(ctx->meth);
  400|      0|    CRYPTO_FREE_REF(&ctx->refcnt);
  401|      0|    OPENSSL_free(ctx);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  402|      0|    EVP_RAND_CTX_free(parent);
  403|      0|}

evp_cleanup_int:
  154|      2|{
  155|      2|    OBJ_NAME_cleanup(OBJ_NAME_TYPE_KDF_METH);
  ------------------
  |  |   30|      2|# define OBJ_NAME_TYPE_KDF_METH          0x06
  ------------------
  156|      2|    OBJ_NAME_cleanup(OBJ_NAME_TYPE_CIPHER_METH);
  ------------------
  |  |   26|      2|# define OBJ_NAME_TYPE_CIPHER_METH       0x02
  ------------------
  157|      2|    OBJ_NAME_cleanup(OBJ_NAME_TYPE_MD_METH);
  ------------------
  |  |   25|      2|# define OBJ_NAME_TYPE_MD_METH           0x01
  ------------------
  158|       |    /*
  159|       |     * The above calls will only clean out the contents of the name hash
  160|       |     * table, but not the hash table itself.  The following line does that
  161|       |     * part.  -- Richard Levitte
  162|       |     */
  163|      2|    OBJ_NAME_cleanup(-1);
  164|       |
  165|      2|    EVP_PBE_cleanup();
  166|      2|    OBJ_sigid_free();
  167|       |
  168|      2|    evp_app_cleanup_int();
  169|      2|}

evp_app_cleanup_int:
  618|      2|{
  619|      2|    if (app_pkey_methods != NULL)
  ------------------
  |  Branch (619:9): [True: 0, False: 2]
  ------------------
  620|      0|        sk_EVP_PKEY_METHOD_pop_free(app_pkey_methods, EVP_PKEY_meth_free);
  621|      2|}

ossl_do_ex_data_init:
   15|      2|{
   16|      2|    OSSL_EX_DATA_GLOBAL *global = ossl_lib_ctx_get_ex_data_global(ctx);
   17|       |
   18|      2|    if (global == NULL)
  ------------------
  |  Branch (18:9): [True: 0, False: 2]
  ------------------
   19|      0|        return 0;
   20|       |
   21|      2|    global->ex_data_lock = CRYPTO_THREAD_lock_new();
   22|      2|    return global->ex_data_lock != NULL;
   23|      2|}
ossl_crypto_cleanup_all_ex_data_int:
   73|      2|{
   74|      2|    int i;
   75|      2|    OSSL_EX_DATA_GLOBAL *global = ossl_lib_ctx_get_ex_data_global(ctx);
   76|       |
   77|      2|    if (global == NULL)
  ------------------
  |  Branch (77:9): [True: 0, False: 2]
  ------------------
   78|      0|        return;
   79|       |
   80|     38|    for (i = 0; i < CRYPTO_EX_INDEX__COUNT; ++i) {
  ------------------
  |  |  247|     38|# define CRYPTO_EX_INDEX__COUNT          18
  ------------------
  |  Branch (80:17): [True: 36, False: 2]
  ------------------
   81|     36|        EX_CALLBACKS *ip = &global->ex_data[i];
   82|       |
   83|     36|        sk_EX_CALLBACK_pop_free(ip->meth, cleanup_cb);
   84|     36|        ip->meth = NULL;
   85|     36|    }
   86|       |
   87|      2|    CRYPTO_THREAD_lock_free(global->ex_data_lock);
   88|      2|    global->ex_data_lock = NULL;
   89|      2|}

ossl_err_load_HTTP_strings:
   80|      2|{
   81|      2|# ifndef OPENSSL_NO_ERR
   82|      2|    if (ERR_reason_error_string(HTTP_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (82:9): [True: 2, False: 0]
  ------------------
   83|      2|        ERR_load_strings_const(HTTP_str_reasons);
   84|      2|# endif
   85|      2|    return 1;
   86|      2|}

ossl_indicator_set_callback_new:
   22|      2|{
   23|      2|    INDICATOR_CB *cb;
   24|       |
   25|      2|    cb = OPENSSL_zalloc(sizeof(*cb));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   26|      2|    return cb;
   27|      2|}
ossl_indicator_set_callback_free:
   30|      2|{
   31|      2|    OPENSSL_free(cb);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   32|      2|}

OPENSSL_cleanup:
  354|      2|{
  355|      2|    OPENSSL_INIT_STOP *currhandler, *lasthandler;
  356|       |
  357|       |    /*
  358|       |     * At some point we should consider looking at this function with a view to
  359|       |     * moving most/all of this into onfree handlers in OSSL_LIB_CTX.
  360|       |     */
  361|       |
  362|       |    /* If we've not been inited then no need to deinit */
  363|      2|    if (!base_inited)
  ------------------
  |  Branch (363:9): [True: 0, False: 2]
  ------------------
  364|      0|        return;
  365|       |
  366|       |    /* Might be explicitly called and also by atexit */
  367|      2|    if (stopped)
  ------------------
  |  Branch (367:9): [True: 0, False: 2]
  ------------------
  368|      0|        return;
  369|      2|    stopped = 1;
  370|       |
  371|       |    /*
  372|       |     * Thread stop may not get automatically called by the thread library for
  373|       |     * the very last thread in some situations, so call it directly.
  374|       |     */
  375|      2|    OPENSSL_thread_stop();
  376|       |
  377|      2|    currhandler = stop_handlers;
  378|      2|    while (currhandler != NULL) {
  ------------------
  |  Branch (378:12): [True: 0, False: 2]
  ------------------
  379|      0|        currhandler->handler();
  380|      0|        lasthandler = currhandler;
  381|      0|        currhandler = currhandler->next;
  382|      0|        OPENSSL_free(lasthandler);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  383|      0|    }
  384|      2|    stop_handlers = NULL;
  385|       |
  386|      2|    CRYPTO_THREAD_lock_free(optsdone_lock);
  387|      2|    optsdone_lock = NULL;
  388|      2|    CRYPTO_THREAD_lock_free(init_lock);
  389|      2|    init_lock = NULL;
  390|       |
  391|      2|    CRYPTO_THREAD_cleanup_local(&in_init_config_local);
  392|       |
  393|       |    /*
  394|       |     * We assume we are single-threaded for this function, i.e. no race
  395|       |     * conditions for the various "*_inited" vars below.
  396|       |     */
  397|       |
  398|      2|#ifndef OPENSSL_NO_COMP
  399|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_comp_zlib_cleanup()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  400|      2|    ossl_comp_zlib_cleanup();
  401|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_comp_brotli_cleanup()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  402|      2|    ossl_comp_brotli_cleanup();
  403|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_comp_zstd_cleanup()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  404|      2|    ossl_comp_zstd_cleanup();
  405|      2|#endif
  406|       |
  407|      2|    if (async_inited) {
  ------------------
  |  Branch (407:9): [True: 0, False: 2]
  ------------------
  408|      0|        OSSL_TRACE(INIT, "OPENSSL_cleanup: async_deinit()\n");
  ------------------
  |  |  287|      0|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      0|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  409|      0|        async_deinit();
  410|      0|    }
  411|       |
  412|       |    /*
  413|       |     * Note that cleanup order is important:
  414|       |     * - ossl_rand_cleanup_int could call an ENGINE's RAND cleanup function so
  415|       |     * must be called before engine_cleanup_int()
  416|       |     * - ENGINEs use CRYPTO_EX_DATA and therefore, must be cleaned up
  417|       |     * before the ex data handlers are wiped during default ossl_lib_ctx deinit.
  418|       |     * - ossl_config_modules_free() can end up in ENGINE code so must be called
  419|       |     * before engine_cleanup_int()
  420|       |     * - ENGINEs and additional EVP algorithms might use added OIDs names so
  421|       |     * ossl_obj_cleanup_int() must be called last
  422|       |     */
  423|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_rand_cleanup_int()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  424|      2|    ossl_rand_cleanup_int();
  425|       |
  426|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_config_modules_free()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  427|      2|    ossl_config_modules_free();
  428|       |
  429|      2|#ifndef OPENSSL_NO_ENGINE
  430|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: engine_cleanup_int()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  431|      2|    engine_cleanup_int();
  432|      2|#endif
  433|       |
  434|      2|#ifndef OPENSSL_NO_DEPRECATED_3_0
  435|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_store_cleanup_int()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  436|      2|    ossl_store_cleanup_int();
  437|      2|#endif
  438|       |
  439|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_lib_ctx_default_deinit()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  440|      2|    ossl_lib_ctx_default_deinit();
  441|       |
  442|      2|    ossl_cleanup_thread();
  443|       |
  444|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: bio_cleanup()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  445|      2|    bio_cleanup();
  446|       |
  447|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: evp_cleanup_int()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  448|      2|    evp_cleanup_int();
  449|       |
  450|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_obj_cleanup_int()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  451|      2|    ossl_obj_cleanup_int();
  452|       |
  453|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: err_int()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  454|      2|    err_cleanup();
  455|       |
  456|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: CRYPTO_secure_malloc_done()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  457|      2|    CRYPTO_secure_malloc_done();
  458|       |
  459|      2|#ifndef OPENSSL_NO_CMP
  460|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: OSSL_CMP_log_close()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  461|      2|    OSSL_CMP_log_close();
  462|      2|#endif
  463|       |
  464|      2|    OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_trace_cleanup()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  465|      2|    ossl_trace_cleanup();
  466|       |
  467|      2|    base_inited = 0;
  468|      2|}
OPENSSL_init_crypto:
  476|  3.07k|{
  477|  3.07k|    uint64_t tmp;
  478|  3.07k|    int aloaddone = 0;
  479|       |
  480|       |   /* Applications depend on 0 being returned when cleanup was already done */
  481|  3.07k|    if (stopped) {
  ------------------
  |  Branch (481:9): [True: 2, False: 3.06k]
  ------------------
  482|      2|        if (!(opts & OPENSSL_INIT_BASE_ONLY))
  ------------------
  |  |   31|      2|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (482:13): [True: 0, False: 2]
  ------------------
  483|      2|            ERR_raise(ERR_LIB_CRYPTO, ERR_R_INIT_FAIL);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  484|      2|        return 0;
  485|      2|    }
  486|       |
  487|       |    /*
  488|       |     * We ignore failures from this function. It is probably because we are
  489|       |     * on a platform that doesn't support lockless atomic loads (we may not
  490|       |     * have created optsdone_lock yet so we can't use it). This is just an
  491|       |     * optimisation to skip the full checks in this function if we don't need
  492|       |     * to, so we carry on regardless in the event of failure.
  493|       |     *
  494|       |     * There could be a race here with other threads, so that optsdone has not
  495|       |     * been updated yet, even though the options have in fact been initialised.
  496|       |     * This doesn't matter - it just means we will run the full function
  497|       |     * unnecessarily - but all the critical code is contained in RUN_ONCE
  498|       |     * functions anyway so we are safe.
  499|       |     */
  500|  3.06k|    if (CRYPTO_atomic_load(&optsdone, &tmp, NULL)) {
  ------------------
  |  Branch (500:9): [True: 3.06k, False: 0]
  ------------------
  501|  3.06k|        if ((tmp & opts) == opts)
  ------------------
  |  Branch (501:13): [True: 2, False: 3.06k]
  ------------------
  502|      2|            return 1;
  503|  3.06k|        aloaddone = 1;
  504|  3.06k|    }
  505|       |
  506|       |    /*
  507|       |     * At some point we should look at this function with a view to moving
  508|       |     * most/all of this into OSSL_LIB_CTX.
  509|       |     *
  510|       |     * When the caller specifies OPENSSL_INIT_BASE_ONLY, that should be the
  511|       |     * *only* option specified.  With that option we return immediately after
  512|       |     * doing the requested limited initialization.  Note that
  513|       |     * err_shelve_state() called by us via ossl_init_load_crypto_nodelete()
  514|       |     * re-enters OPENSSL_init_crypto() with OPENSSL_INIT_BASE_ONLY, but with
  515|       |     * base already initialized this is a harmless NOOP.
  516|       |     *
  517|       |     * If we remain the only caller of err_shelve_state() the recursion should
  518|       |     * perhaps be removed, but if in doubt, it can be left in place.
  519|       |     */
  520|  3.06k|    if (!RUN_ONCE(&base, ossl_init_base))
  ------------------
  |  |  130|  3.06k|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 3.06k, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (520:9): [True: 0, False: 3.06k]
  ------------------
  521|      0|        return 0;
  522|       |
  523|  3.06k|    if (opts & OPENSSL_INIT_BASE_ONLY)
  ------------------
  |  |   31|  3.06k|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  |  Branch (523:9): [True: 3.06k, False: 2]
  ------------------
  524|  3.06k|        return 1;
  525|       |
  526|       |    /*
  527|       |     * optsdone_lock should definitely be set up now, so we can now repeat the
  528|       |     * same check from above but be sure that it will work even on platforms
  529|       |     * without lockless CRYPTO_atomic_load
  530|       |     */
  531|      2|    if (!aloaddone) {
  ------------------
  |  Branch (531:9): [True: 0, False: 2]
  ------------------
  532|      0|        if (!CRYPTO_atomic_load(&optsdone, &tmp, optsdone_lock))
  ------------------
  |  Branch (532:13): [True: 0, False: 0]
  ------------------
  533|      0|            return 0;
  534|      0|        if ((tmp & opts) == opts)
  ------------------
  |  Branch (534:13): [True: 0, False: 0]
  ------------------
  535|      0|            return 1;
  536|      0|    }
  537|       |
  538|       |    /*
  539|       |     * Now we don't always set up exit handlers, the INIT_BASE_ONLY calls
  540|       |     * should not have the side-effect of setting up exit handlers, and
  541|       |     * therefore, this code block is below the INIT_BASE_ONLY-conditioned early
  542|       |     * return above.
  543|       |     */
  544|      2|    if ((opts & OPENSSL_INIT_NO_ATEXIT) != 0) {
  ------------------
  |  |  481|      2|# define OPENSSL_INIT_NO_ATEXIT              0x00080000L
  ------------------
  |  Branch (544:9): [True: 0, False: 2]
  ------------------
  545|      0|        if (!RUN_ONCE_ALT(&register_atexit, ossl_init_no_register_atexit,
  ------------------
  |  |  148|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (148:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (545:13): [True: 0, False: 0]
  ------------------
  546|      0|                          ossl_init_register_atexit))
  547|      0|            return 0;
  548|      2|    } else if (!RUN_ONCE(&register_atexit, ossl_init_register_atexit)) {
  ------------------
  |  |  130|      2|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (548:16): [True: 0, False: 2]
  ------------------
  549|      0|        return 0;
  550|      0|    }
  551|       |
  552|      2|    if (!RUN_ONCE(&load_crypto_nodelete, ossl_init_load_crypto_nodelete))
  ------------------
  |  |  130|      2|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (552:9): [True: 0, False: 2]
  ------------------
  553|      0|        return 0;
  554|       |
  555|      2|    if ((opts & OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS)
  ------------------
  |  |  462|      2|# define OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS 0x00000001L
  ------------------
  |  Branch (555:9): [True: 0, False: 2]
  ------------------
  556|      2|            && !RUN_ONCE_ALT(&load_crypto_strings,
  ------------------
  |  |  148|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (148:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (556:16): [True: 0, False: 0]
  ------------------
  557|      2|                             ossl_init_no_load_crypto_strings,
  558|      2|                             ossl_init_load_crypto_strings))
  559|      0|        return 0;
  560|       |
  561|      2|    if ((opts & OPENSSL_INIT_LOAD_CRYPTO_STRINGS)
  ------------------
  |  |  463|      2|# define OPENSSL_INIT_LOAD_CRYPTO_STRINGS    0x00000002L
  ------------------
  |  Branch (561:9): [True: 2, False: 0]
  ------------------
  562|      2|            && !RUN_ONCE(&load_crypto_strings, ossl_init_load_crypto_strings))
  ------------------
  |  |  130|      2|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (562:16): [True: 0, False: 2]
  ------------------
  563|      0|        return 0;
  564|       |
  565|      2|    if ((opts & OPENSSL_INIT_NO_ADD_ALL_CIPHERS)
  ------------------
  |  |  466|      2|# define OPENSSL_INIT_NO_ADD_ALL_CIPHERS     0x00000010L
  ------------------
  |  Branch (565:9): [True: 0, False: 2]
  ------------------
  566|      2|            && !RUN_ONCE_ALT(&add_all_ciphers, ossl_init_no_add_all_ciphers,
  ------------------
  |  |  148|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (148:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (566:16): [True: 0, False: 0]
  ------------------
  567|      2|                             ossl_init_add_all_ciphers))
  568|      0|        return 0;
  569|       |
  570|      2|    if ((opts & OPENSSL_INIT_ADD_ALL_CIPHERS)
  ------------------
  |  |  464|      2|# define OPENSSL_INIT_ADD_ALL_CIPHERS        0x00000004L
  ------------------
  |  Branch (570:9): [True: 0, False: 2]
  ------------------
  571|      2|            && !RUN_ONCE(&add_all_ciphers, ossl_init_add_all_ciphers))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (571:16): [True: 0, False: 0]
  ------------------
  572|      0|        return 0;
  573|       |
  574|      2|    if ((opts & OPENSSL_INIT_NO_ADD_ALL_DIGESTS)
  ------------------
  |  |  467|      2|# define OPENSSL_INIT_NO_ADD_ALL_DIGESTS     0x00000020L
  ------------------
  |  Branch (574:9): [True: 0, False: 2]
  ------------------
  575|      2|            && !RUN_ONCE_ALT(&add_all_digests, ossl_init_no_add_all_digests,
  ------------------
  |  |  148|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (148:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (575:16): [True: 0, False: 0]
  ------------------
  576|      2|                             ossl_init_add_all_digests))
  577|      0|        return 0;
  578|       |
  579|      2|    if ((opts & OPENSSL_INIT_ADD_ALL_DIGESTS)
  ------------------
  |  |  465|      2|# define OPENSSL_INIT_ADD_ALL_DIGESTS        0x00000008L
  ------------------
  |  Branch (579:9): [True: 0, False: 2]
  ------------------
  580|      2|            && !RUN_ONCE(&add_all_digests, ossl_init_add_all_digests))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (580:16): [True: 0, False: 0]
  ------------------
  581|      0|        return 0;
  582|       |
  583|      2|    if ((opts & OPENSSL_INIT_ATFORK)
  ------------------
  |  |  479|      2|# define OPENSSL_INIT_ATFORK                 0x00020000L
  ------------------
  |  Branch (583:9): [True: 0, False: 2]
  ------------------
  584|      2|            && !openssl_init_fork_handlers())
  ------------------
  |  Branch (584:16): [True: 0, False: 0]
  ------------------
  585|      0|        return 0;
  586|       |
  587|      2|    if ((opts & OPENSSL_INIT_NO_LOAD_CONFIG)
  ------------------
  |  |  469|      2|# define OPENSSL_INIT_NO_LOAD_CONFIG         0x00000080L
  ------------------
  |  Branch (587:9): [True: 0, False: 2]
  ------------------
  588|      2|            && !RUN_ONCE_ALT(&config, ossl_init_no_config, ossl_init_config))
  ------------------
  |  |  148|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (148:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (588:16): [True: 0, False: 0]
  ------------------
  589|      0|        return 0;
  590|       |
  591|      2|    if (opts & OPENSSL_INIT_LOAD_CONFIG) {
  ------------------
  |  |  468|      2|# define OPENSSL_INIT_LOAD_CONFIG            0x00000040L
  ------------------
  |  Branch (591:9): [True: 0, False: 2]
  ------------------
  592|      0|        int loading = CRYPTO_THREAD_get_local(&in_init_config_local) != NULL;
  593|       |
  594|       |        /* If called recursively from OBJ_ calls, just skip it. */
  595|      0|        if (!loading) {
  ------------------
  |  Branch (595:13): [True: 0, False: 0]
  ------------------
  596|      0|            int ret;
  597|       |
  598|      0|            if (!CRYPTO_THREAD_set_local(&in_init_config_local, (void *)-1))
  ------------------
  |  Branch (598:17): [True: 0, False: 0]
  ------------------
  599|      0|                return 0;
  600|      0|            if (settings == NULL) {
  ------------------
  |  Branch (600:17): [True: 0, False: 0]
  ------------------
  601|      0|                ret = RUN_ONCE(&config, ossl_init_config);
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  602|      0|            } else {
  603|      0|                if (!CRYPTO_THREAD_write_lock(init_lock))
  ------------------
  |  Branch (603:21): [True: 0, False: 0]
  ------------------
  604|      0|                    return 0;
  605|      0|                conf_settings = settings;
  606|      0|                ret = RUN_ONCE_ALT(&config, ossl_init_config_settings,
  ------------------
  |  |  148|      0|    (CRYPTO_THREAD_run_once(once, initalt##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (148:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  607|      0|                                   ossl_init_config);
  608|      0|                conf_settings = NULL;
  609|      0|                CRYPTO_THREAD_unlock(init_lock);
  610|      0|            }
  611|       |
  612|      0|            if (ret <= 0)
  ------------------
  |  Branch (612:17): [True: 0, False: 0]
  ------------------
  613|      0|                return 0;
  614|      0|        }
  615|      0|    }
  616|       |
  617|      2|    if ((opts & OPENSSL_INIT_ASYNC)
  ------------------
  |  |  470|      2|# define OPENSSL_INIT_ASYNC                  0x00000100L
  ------------------
  |  Branch (617:9): [True: 0, False: 2]
  ------------------
  618|      2|            && !RUN_ONCE(&async, ossl_init_async))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (618:16): [True: 0, False: 0]
  ------------------
  619|      0|        return 0;
  620|       |
  621|      2|#ifndef OPENSSL_NO_ENGINE
  622|      2|    if ((opts & OPENSSL_INIT_ENGINE_OPENSSL)
  ------------------
  |  |  473|      2|# define OPENSSL_INIT_ENGINE_OPENSSL         0x00000800L
  ------------------
  |  Branch (622:9): [True: 0, False: 2]
  ------------------
  623|      2|            && !RUN_ONCE(&engine_openssl, ossl_init_engine_openssl))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (623:16): [True: 0, False: 0]
  ------------------
  624|      0|        return 0;
  625|      2|# ifndef OPENSSL_NO_RDRAND
  626|      2|    if ((opts & OPENSSL_INIT_ENGINE_RDRAND)
  ------------------
  |  |  471|      2|# define OPENSSL_INIT_ENGINE_RDRAND          0x00000200L
  ------------------
  |  Branch (626:9): [True: 0, False: 2]
  ------------------
  627|      2|            && !RUN_ONCE(&engine_rdrand, ossl_init_engine_rdrand))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (627:16): [True: 0, False: 0]
  ------------------
  628|      0|        return 0;
  629|      2|# endif
  630|      2|    if ((opts & OPENSSL_INIT_ENGINE_DYNAMIC)
  ------------------
  |  |  472|      2|# define OPENSSL_INIT_ENGINE_DYNAMIC         0x00000400L
  ------------------
  |  Branch (630:9): [True: 0, False: 2]
  ------------------
  631|      2|            && !RUN_ONCE(&engine_dynamic, ossl_init_engine_dynamic))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (631:16): [True: 0, False: 0]
  ------------------
  632|      0|        return 0;
  633|      2|# ifndef OPENSSL_NO_STATIC_ENGINE
  634|       |#  ifndef OPENSSL_NO_DEVCRYPTOENG
  635|       |    if ((opts & OPENSSL_INIT_ENGINE_CRYPTODEV)
  636|       |            && !RUN_ONCE(&engine_devcrypto, ossl_init_engine_devcrypto))
  637|       |        return 0;
  638|       |#  endif
  639|      2|#  if !defined(OPENSSL_NO_PADLOCKENG)
  640|      2|    if ((opts & OPENSSL_INIT_ENGINE_PADLOCK)
  ------------------
  |  |  476|      2|# define OPENSSL_INIT_ENGINE_PADLOCK         0x00004000L
  ------------------
  |  Branch (640:9): [True: 0, False: 2]
  ------------------
  641|      2|            && !RUN_ONCE(&engine_padlock, ossl_init_engine_padlock))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (641:16): [True: 0, False: 0]
  ------------------
  642|      0|        return 0;
  643|      2|#  endif
  644|       |#  if defined(OPENSSL_SYS_WIN32) && !defined(OPENSSL_NO_CAPIENG)
  645|       |    if ((opts & OPENSSL_INIT_ENGINE_CAPI)
  646|       |            && !RUN_ONCE(&engine_capi, ossl_init_engine_capi))
  647|       |        return 0;
  648|       |#  endif
  649|      2|#  if !defined(OPENSSL_NO_AFALGENG)
  650|      2|    if ((opts & OPENSSL_INIT_ENGINE_AFALG)
  ------------------
  |  |  477|      2|# define OPENSSL_INIT_ENGINE_AFALG           0x00008000L
  ------------------
  |  Branch (650:9): [True: 0, False: 2]
  ------------------
  651|      2|            && !RUN_ONCE(&engine_afalg, ossl_init_engine_afalg))
  ------------------
  |  |  130|      0|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (651:16): [True: 0, False: 0]
  ------------------
  652|      0|        return 0;
  653|      2|#  endif
  654|      2|# endif
  655|      2|    if (opts & (OPENSSL_INIT_ENGINE_ALL_BUILTIN
  ------------------
  |  |  493|      2|    (OPENSSL_INIT_ENGINE_RDRAND | OPENSSL_INIT_ENGINE_DYNAMIC \
  |  |  ------------------
  |  |  |  |  471|      2|# define OPENSSL_INIT_ENGINE_RDRAND          0x00000200L
  |  |  ------------------
  |  |                   (OPENSSL_INIT_ENGINE_RDRAND | OPENSSL_INIT_ENGINE_DYNAMIC \
  |  |  ------------------
  |  |  |  |  472|      2|# define OPENSSL_INIT_ENGINE_DYNAMIC         0x00000400L
  |  |  ------------------
  |  |  494|      2|    | OPENSSL_INIT_ENGINE_CRYPTODEV | OPENSSL_INIT_ENGINE_CAPI | \
  |  |  ------------------
  |  |  |  |  474|      2|# define OPENSSL_INIT_ENGINE_CRYPTODEV       0x00001000L
  |  |  ------------------
  |  |                   | OPENSSL_INIT_ENGINE_CRYPTODEV | OPENSSL_INIT_ENGINE_CAPI | \
  |  |  ------------------
  |  |  |  |  475|      2|# define OPENSSL_INIT_ENGINE_CAPI            0x00002000L
  |  |  ------------------
  |  |  495|      2|    OPENSSL_INIT_ENGINE_PADLOCK)
  |  |  ------------------
  |  |  |  |  476|      2|# define OPENSSL_INIT_ENGINE_PADLOCK         0x00004000L
  |  |  ------------------
  ------------------
  |  Branch (655:9): [True: 0, False: 2]
  ------------------
  656|      2|                | OPENSSL_INIT_ENGINE_OPENSSL
  ------------------
  |  |  473|      2|# define OPENSSL_INIT_ENGINE_OPENSSL         0x00000800L
  ------------------
  657|      2|                | OPENSSL_INIT_ENGINE_AFALG)) {
  ------------------
  |  |  477|      2|# define OPENSSL_INIT_ENGINE_AFALG           0x00008000L
  ------------------
  658|      0|        ENGINE_register_all_complete();
  659|      0|    }
  660|      2|#endif
  661|       |
  662|      2|    if (!CRYPTO_atomic_or(&optsdone, opts, &tmp, optsdone_lock))
  ------------------
  |  Branch (662:9): [True: 0, False: 2]
  ------------------
  663|      0|        return 0;
  664|       |
  665|      2|    return 1;
  666|      2|}
init.c:ossl_init_base:
   56|      2|{
   57|       |    /* no need to init trace */
   58|       |
   59|      2|    OSSL_TRACE(INIT, "ossl_init_base: setting up stop handlers\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
   60|       |#ifndef OPENSSL_NO_CRYPTO_MDEBUG
   61|       |    ossl_malloc_setup_failures();
   62|       |#endif
   63|       |
   64|      2|    if ((optsdone_lock = CRYPTO_THREAD_lock_new()) == NULL
  ------------------
  |  Branch (64:9): [True: 0, False: 2]
  ------------------
   65|      2|        || (init_lock = CRYPTO_THREAD_lock_new()) == NULL)
  ------------------
  |  Branch (65:12): [True: 0, False: 2]
  ------------------
   66|      0|        goto err;
   67|       |
   68|      2|    OPENSSL_cpuid_setup();
   69|       |
   70|      2|    if (!ossl_init_thread())
  ------------------
  |  Branch (70:9): [True: 0, False: 2]
  ------------------
   71|      0|        goto err;
   72|       |
   73|      2|    if (!CRYPTO_THREAD_init_local(&in_init_config_local, NULL))
  ------------------
  |  Branch (73:9): [True: 0, False: 2]
  ------------------
   74|      0|        goto err;
   75|       |
   76|      2|    base_inited = 1;
   77|      2|    return 1;
   78|       |
   79|      0|err:
   80|      0|    OSSL_TRACE(INIT, "ossl_init_base failed!\n");
  ------------------
  |  |  287|      0|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      0|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
   81|      0|    CRYPTO_THREAD_lock_free(optsdone_lock);
   82|      0|    optsdone_lock = NULL;
   83|      0|    CRYPTO_THREAD_lock_free(init_lock);
   84|      0|    init_lock = NULL;
   85|       |
   86|      0|    return 0;
   87|      2|}
init.c:ossl_init_register_atexit:
   99|      2|{
  100|      2|#ifndef OPENSSL_NO_ATEXIT
  101|       |# ifdef OPENSSL_INIT_DEBUG
  102|       |    fprintf(stderr, "OPENSSL_INIT: ossl_init_register_atexit()\n");
  103|       |# endif
  104|      2|# ifndef OPENSSL_SYS_UEFI
  105|       |#  if defined(_WIN32) && !defined(__BORLANDC__)
  106|       |    /* We use _onexit() in preference because it gets called on DLL unload */
  107|       |    if (_onexit(win32atexit) == NULL)
  108|       |        return 0;
  109|       |#  else
  110|      2|    if (atexit(OPENSSL_cleanup) != 0)
  ------------------
  |  Branch (110:9): [True: 0, False: 2]
  ------------------
  111|      0|        return 0;
  112|      2|#  endif
  113|      2|# endif
  114|      2|#endif
  115|       |
  116|      2|    return 1;
  117|      2|}
init.c:ossl_init_load_crypto_nodelete:
  131|      2|{
  132|      2|    OSSL_TRACE(INIT, "ossl_init_load_crypto_nodelete()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  133|       |
  134|       |#if !defined(OPENSSL_USE_NODELETE) \
  135|       |    && !defined(OPENSSL_NO_PINSHARED)
  136|       |# if defined(DSO_WIN32) && !defined(_WIN32_WCE)
  137|       |    {
  138|       |        HMODULE handle = NULL;
  139|       |        BOOL ret;
  140|       |
  141|       |        /* We don't use the DSO route for WIN32 because there is a better way */
  142|       |        ret = GetModuleHandleEx(GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS
  143|       |                                | GET_MODULE_HANDLE_EX_FLAG_PIN,
  144|       |                                (void *)&base_inited, &handle);
  145|       |
  146|       |        OSSL_TRACE1(INIT,
  147|       |                    "ossl_init_load_crypto_nodelete: "
  148|       |                    "obtained DSO reference? %s\n",
  149|       |                    (ret == TRUE ? "No!" : "Yes."));
  150|       |        return (ret == TRUE) ? 1 : 0;
  151|       |    }
  152|       |# elif !defined(DSO_NONE)
  153|       |    /*
  154|       |     * Deliberately leak a reference to ourselves. This will force the library
  155|       |     * to remain loaded until the atexit() handler is run at process exit.
  156|       |     */
  157|       |    {
  158|       |        DSO *dso;
  159|       |        void *err;
  160|       |
  161|       |        if (!err_shelve_state(&err))
  162|       |            return 0;
  163|       |
  164|       |        dso = DSO_dsobyaddr(&base_inited, DSO_FLAG_NO_UNLOAD_ON_FREE);
  165|       |        /*
  166|       |         * In case of No!, it is uncertain our exit()-handlers can still be
  167|       |         * called. After dlclose() the whole library might have been unloaded
  168|       |         * already.
  169|       |         */
  170|       |        OSSL_TRACE1(INIT, "obtained DSO reference? %s\n",
  171|       |                    (dso == NULL ? "No!" : "Yes."));
  172|       |        DSO_free(dso);
  173|       |        err_unshelve_state(err);
  174|       |    }
  175|       |# endif
  176|       |#endif
  177|       |
  178|      2|    return 1;
  179|      2|}
init.c:ossl_init_load_crypto_strings:
  184|      2|{
  185|      2|    int ret = 1;
  186|       |    /*
  187|       |     * OPENSSL_NO_AUTOERRINIT is provided here to prevent at compile time
  188|       |     * pulling in all the error strings during static linking
  189|       |     */
  190|      2|#if !defined(OPENSSL_NO_ERR) && !defined(OPENSSL_NO_AUTOERRINIT)
  191|      2|    void *err;
  192|       |
  193|      2|    if (!err_shelve_state(&err))
  ------------------
  |  Branch (193:9): [True: 0, False: 2]
  ------------------
  194|      0|        return 0;
  195|       |
  196|      2|    OSSL_TRACE(INIT, "ossl_err_load_crypto_strings()\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
  197|      2|    ret = ossl_err_load_crypto_strings();
  198|       |
  199|      2|    err_unshelve_state(err);
  200|      2|#endif
  201|      2|    return ret;
  202|      2|}

ossl_init_thread:
  203|      2|{
  204|      2|    if (!CRYPTO_THREAD_init_local(&destructor_key.value,
  ------------------
  |  Branch (204:9): [True: 0, False: 2]
  ------------------
  205|      2|                                  init_thread_destructor))
  206|      0|        return 0;
  207|       |
  208|      2|    return 1;
  209|      2|}
ossl_cleanup_thread:
  212|      2|{
  213|      2|    init_thread_deregister(NULL, 1);
  214|      2|    CRYPTO_THREAD_cleanup_local(&destructor_key.value);
  215|      2|    destructor_key.sane = -1;
  216|      2|}
OPENSSL_thread_stop:
  230|      2|{
  231|      2|    if (destructor_key.sane != -1) {
  ------------------
  |  Branch (231:9): [True: 2, False: 0]
  ------------------
  232|      2|        THREAD_EVENT_HANDLER **hands
  233|      2|            = init_get_thread_local(&destructor_key.value, 0, 0);
  234|      2|        init_thread_stop(NULL, hands);
  235|       |
  236|      2|        init_thread_remove_handlers(hands);
  237|      2|        OPENSSL_free(hands);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  238|      2|    }
  239|      2|}
ossl_ctx_thread_stop:
  242|      2|{
  243|      2|    if (destructor_key.sane != -1) {
  ------------------
  |  Branch (243:9): [True: 2, False: 0]
  ------------------
  244|      2|        THREAD_EVENT_HANDLER **hands
  245|      2|            = init_get_thread_local(&destructor_key.value, 0, 1);
  246|      2|        init_thread_stop(ctx, hands);
  247|      2|    }
  248|      2|}
ossl_init_thread_start:
  367|      2|{
  368|      2|    THREAD_EVENT_HANDLER **hands;
  369|      2|    THREAD_EVENT_HANDLER *hand;
  370|       |#ifdef FIPS_MODULE
  371|       |    OSSL_LIB_CTX *ctx = arg;
  372|       |
  373|       |    /*
  374|       |     * In FIPS mode the list of THREAD_EVENT_HANDLERs is unique per combination
  375|       |     * of OSSL_LIB_CTX and thread. This is because in FIPS mode each
  376|       |     * OSSL_LIB_CTX gets informed about thread stop events individually.
  377|       |     */
  378|       |    CRYPTO_THREAD_LOCAL *local
  379|       |        = ossl_lib_ctx_get_data(ctx, OSSL_LIB_CTX_THREAD_EVENT_HANDLER_INDEX);
  380|       |#else
  381|       |    /*
  382|       |     * Outside of FIPS mode the list of THREAD_EVENT_HANDLERs is unique per
  383|       |     * thread, but may hold multiple OSSL_LIB_CTXs. We only get told about
  384|       |     * thread stop events globally, so we have to ensure all affected
  385|       |     * OSSL_LIB_CTXs are informed.
  386|       |     */
  387|      2|    CRYPTO_THREAD_LOCAL *local = &destructor_key.value;
  388|      2|#endif
  389|       |
  390|      2|    hands = init_get_thread_local(local, 1, 0);
  391|      2|    if (hands == NULL)
  ------------------
  |  Branch (391:9): [True: 0, False: 2]
  ------------------
  392|      0|        return 0;
  393|       |
  394|       |#ifdef FIPS_MODULE
  395|       |    if (*hands == NULL) {
  396|       |        /*
  397|       |         * We've not yet registered any handlers for this thread. We need to get
  398|       |         * libcrypto to tell us about later thread stop events. c_thread_start
  399|       |         * is a callback to libcrypto defined in fipsprov.c
  400|       |         */
  401|       |        if (!ossl_thread_register_fips(ctx))
  402|       |            return 0;
  403|       |    }
  404|       |#endif
  405|       |
  406|      2|    hand = OPENSSL_malloc(sizeof(*hand));
  ------------------
  |  |  102|      2|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  407|      2|    if (hand == NULL)
  ------------------
  |  Branch (407:9): [True: 0, False: 2]
  ------------------
  408|      0|        return 0;
  409|       |
  410|      2|    hand->handfn = handfn;
  411|      2|    hand->arg = arg;
  412|      2|#ifndef FIPS_MODULE
  413|      2|    hand->index = index;
  414|      2|#endif
  415|      2|    hand->next = *hands;
  416|      2|    *hands = hand;
  417|       |
  418|      2|    return 1;
  419|      2|}
initthread.c:init_get_thread_local:
   95|      6|{
   96|      6|    THREAD_EVENT_HANDLER **hands = CRYPTO_THREAD_get_local(local);
   97|       |
   98|      6|    if (alloc) {
  ------------------
  |  Branch (98:9): [True: 2, False: 4]
  ------------------
   99|      2|        if (hands == NULL) {
  ------------------
  |  Branch (99:13): [True: 2, False: 0]
  ------------------
  100|       |
  101|      2|            if ((hands = OPENSSL_zalloc(sizeof(*hands))) == NULL)
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (101:17): [True: 0, False: 2]
  ------------------
  102|      0|                return NULL;
  103|       |
  104|      2|            if (!CRYPTO_THREAD_set_local(local, hands)) {
  ------------------
  |  Branch (104:17): [True: 0, False: 2]
  ------------------
  105|      0|                OPENSSL_free(hands);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  106|      0|                return NULL;
  107|      0|            }
  108|       |
  109|      2|#ifndef FIPS_MODULE
  110|      2|            if (!init_thread_push_handlers(hands)) {
  ------------------
  |  Branch (110:17): [True: 0, False: 2]
  ------------------
  111|      0|                CRYPTO_THREAD_set_local(local, NULL);
  112|      0|                OPENSSL_free(hands);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  113|      0|                return NULL;
  114|      0|            }
  115|      2|#endif
  116|      2|        }
  117|      4|    } else if (!keep) {
  ------------------
  |  Branch (117:16): [True: 2, False: 2]
  ------------------
  118|      2|        CRYPTO_THREAD_set_local(local, NULL);
  119|      2|    }
  120|       |
  121|      6|    return hands;
  122|      6|}
initthread.c:init_thread_push_handlers:
  155|      2|{
  156|      2|    int ret;
  157|      2|    GLOBAL_TEVENT_REGISTER *gtr;
  158|       |
  159|      2|    gtr = get_global_tevent_register();
  160|      2|    if (gtr == NULL)
  ------------------
  |  Branch (160:9): [True: 0, False: 2]
  ------------------
  161|      0|        return 0;
  162|       |
  163|      2|    if (!CRYPTO_THREAD_write_lock(gtr->lock))
  ------------------
  |  Branch (163:9): [True: 0, False: 2]
  ------------------
  164|      0|        return 0;
  165|      2|    ret = (sk_THREAD_EVENT_HANDLER_PTR_push(gtr->skhands, hands) != 0);
  166|      2|    CRYPTO_THREAD_unlock(gtr->lock);
  167|       |
  168|      2|    return ret;
  169|      2|}
initthread.c:get_global_tevent_register:
   78|      8|{
   79|      8|    if (!RUN_ONCE(&tevent_register_runonce, create_global_tevent_register))
  ------------------
  |  |  130|      8|    (CRYPTO_THREAD_run_once(once, init##_ossl_) ? init##_ossl_ret_ : 0)
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 8, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (79:9): [True: 0, False: 8]
  ------------------
   80|      0|        return NULL;
   81|      8|    return glob_tevent_reg;
   82|      8|}
initthread.c:create_global_tevent_register:
   59|      2|{
   60|      2|    glob_tevent_reg = OPENSSL_zalloc(sizeof(*glob_tevent_reg));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   61|      2|    if (glob_tevent_reg == NULL)
  ------------------
  |  Branch (61:9): [True: 0, False: 2]
  ------------------
   62|      0|        return 0;
   63|       |
   64|      2|    glob_tevent_reg->skhands = sk_THREAD_EVENT_HANDLER_PTR_new_null();
   65|      2|    glob_tevent_reg->lock = CRYPTO_THREAD_lock_new();
   66|      2|    if (glob_tevent_reg->skhands == NULL || glob_tevent_reg->lock == NULL) {
  ------------------
  |  Branch (66:9): [True: 0, False: 2]
  |  Branch (66:45): [True: 0, False: 2]
  ------------------
   67|      0|        sk_THREAD_EVENT_HANDLER_PTR_free(glob_tevent_reg->skhands);
   68|      0|        CRYPTO_THREAD_lock_free(glob_tevent_reg->lock);
   69|      0|        OPENSSL_free(glob_tevent_reg);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   70|      0|        glob_tevent_reg = NULL;
   71|      0|        return 0;
   72|      0|    }
   73|       |
   74|      2|    return 1;
   75|      2|}
initthread.c:init_thread_remove_handlers:
  172|      2|{
  173|      2|    GLOBAL_TEVENT_REGISTER *gtr;
  174|      2|    int i;
  175|       |
  176|      2|    gtr = get_global_tevent_register();
  177|      2|    if (gtr == NULL)
  ------------------
  |  Branch (177:9): [True: 0, False: 2]
  ------------------
  178|      0|        return;
  179|      2|    if (!CRYPTO_THREAD_write_lock(gtr->lock))
  ------------------
  |  Branch (179:9): [True: 0, False: 2]
  ------------------
  180|      0|        return;
  181|      2|    for (i = 0; i < sk_THREAD_EVENT_HANDLER_PTR_num(gtr->skhands); i++) {
  ------------------
  |  Branch (181:17): [True: 2, False: 0]
  ------------------
  182|      2|        THREAD_EVENT_HANDLER **hands
  183|      2|            = sk_THREAD_EVENT_HANDLER_PTR_value(gtr->skhands, i);
  184|       |
  185|      2|        if (hands == handsin) {
  ------------------
  |  Branch (185:13): [True: 2, False: 0]
  ------------------
  186|      2|            sk_THREAD_EVENT_HANDLER_PTR_delete(gtr->skhands, i);
  187|      2|            CRYPTO_THREAD_unlock(gtr->lock);
  188|      2|            return;
  189|      2|        }
  190|      2|    }
  191|      0|    CRYPTO_THREAD_unlock(gtr->lock);
  192|      0|    return;
  193|      2|}
initthread.c:init_thread_stop:
  323|      4|{
  324|      4|    THREAD_EVENT_HANDLER *curr, *prev = NULL, *tmp;
  325|      4|#ifndef FIPS_MODULE
  326|      4|    GLOBAL_TEVENT_REGISTER *gtr;
  327|      4|#endif
  328|       |
  329|       |    /* Can't do much about this */
  330|      4|    if (hands == NULL)
  ------------------
  |  Branch (330:9): [True: 2, False: 2]
  ------------------
  331|      2|        return;
  332|       |
  333|      2|#ifndef FIPS_MODULE
  334|      2|    gtr = get_global_tevent_register();
  335|      2|    if (gtr == NULL)
  ------------------
  |  Branch (335:9): [True: 0, False: 2]
  ------------------
  336|      0|        return;
  337|       |
  338|      2|    if (!CRYPTO_THREAD_write_lock(gtr->lock))
  ------------------
  |  Branch (338:9): [True: 0, False: 2]
  ------------------
  339|      0|        return;
  340|      2|#endif
  341|       |
  342|      2|    curr = *hands;
  343|      4|    while (curr != NULL) {
  ------------------
  |  Branch (343:12): [True: 2, False: 2]
  ------------------
  344|      2|        if (arg != NULL && curr->arg != arg) {
  ------------------
  |  Branch (344:13): [True: 0, False: 2]
  |  Branch (344:28): [True: 0, False: 0]
  ------------------
  345|      0|            prev = curr;
  346|      0|            curr = curr->next;
  347|      0|            continue;
  348|      0|        }
  349|      2|        curr->handfn(curr->arg);
  350|      2|        if (prev == NULL)
  ------------------
  |  Branch (350:13): [True: 2, False: 0]
  ------------------
  351|      2|            *hands = curr->next;
  352|      0|        else
  353|      0|            prev->next = curr->next;
  354|       |
  355|      2|        tmp = curr;
  356|      2|        curr = curr->next;
  357|       |
  358|      2|        OPENSSL_free(tmp);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  359|      2|    }
  360|      2|#ifndef FIPS_MODULE
  361|      2|    CRYPTO_THREAD_unlock(gtr->lock);
  362|      2|#endif
  363|      2|}
initthread.c:init_thread_deregister:
  423|      2|{
  424|      2|    GLOBAL_TEVENT_REGISTER *gtr;
  425|      2|    int i;
  426|       |
  427|      2|    gtr = get_global_tevent_register();
  428|      2|    if (gtr == NULL)
  ------------------
  |  Branch (428:9): [True: 0, False: 2]
  ------------------
  429|      0|        return 0;
  430|      2|    if (!all) {
  ------------------
  |  Branch (430:9): [True: 0, False: 2]
  ------------------
  431|      0|        if (!CRYPTO_THREAD_write_lock(gtr->lock))
  ------------------
  |  Branch (431:13): [True: 0, False: 0]
  ------------------
  432|      0|            return 0;
  433|      2|    } else {
  434|      2|        glob_tevent_reg = NULL;
  435|      2|    }
  436|      2|    for (i = 0; i < sk_THREAD_EVENT_HANDLER_PTR_num(gtr->skhands); i++) {
  ------------------
  |  Branch (436:17): [True: 0, False: 2]
  ------------------
  437|      0|        THREAD_EVENT_HANDLER **hands
  438|      0|            = sk_THREAD_EVENT_HANDLER_PTR_value(gtr->skhands, i);
  439|      0|        THREAD_EVENT_HANDLER *curr = NULL, *prev = NULL, *tmp;
  440|       |
  441|      0|        if (hands == NULL) {
  ------------------
  |  Branch (441:13): [True: 0, False: 0]
  ------------------
  442|      0|            if (!all)
  ------------------
  |  Branch (442:17): [True: 0, False: 0]
  ------------------
  443|      0|                CRYPTO_THREAD_unlock(gtr->lock);
  444|      0|            return 0;
  445|      0|        }
  446|      0|        curr = *hands;
  447|      0|        while (curr != NULL) {
  ------------------
  |  Branch (447:16): [True: 0, False: 0]
  ------------------
  448|      0|            if (all || curr->index == index) {
  ------------------
  |  Branch (448:17): [True: 0, False: 0]
  |  Branch (448:24): [True: 0, False: 0]
  ------------------
  449|      0|                if (prev != NULL)
  ------------------
  |  Branch (449:21): [True: 0, False: 0]
  ------------------
  450|      0|                    prev->next = curr->next;
  451|      0|                else
  452|      0|                    *hands = curr->next;
  453|      0|                tmp = curr;
  454|      0|                curr = curr->next;
  455|      0|                OPENSSL_free(tmp);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  456|      0|                continue;
  457|      0|            }
  458|      0|            prev = curr;
  459|      0|            curr = curr->next;
  460|      0|        }
  461|      0|        if (all)
  ------------------
  |  Branch (461:13): [True: 0, False: 0]
  ------------------
  462|      0|            OPENSSL_free(hands);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  463|      0|    }
  464|      2|    if (all) {
  ------------------
  |  Branch (464:9): [True: 2, False: 0]
  ------------------
  465|      2|        CRYPTO_THREAD_lock_free(gtr->lock);
  466|      2|        sk_THREAD_EVENT_HANDLER_PTR_free(gtr->skhands);
  467|      2|        OPENSSL_free(gtr);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  468|      2|    } else {
  469|      0|        CRYPTO_THREAD_unlock(gtr->lock);
  470|      0|    }
  471|      2|    return 1;
  472|      2|}

OPENSSL_LH_set_thunks:
   52|     12|{
   53|       |
   54|     12|    if (lh == NULL)
  ------------------
  |  Branch (54:9): [True: 0, False: 12]
  ------------------
   55|      0|        return NULL;
   56|     12|    lh->compw = cw;
   57|     12|    lh->hashw = hw;
   58|     12|    lh->daw = daw;
   59|     12|    lh->daaw = daaw;
   60|     12|    return lh;
   61|     12|}
OPENSSL_LH_new:
   64|     12|{
   65|     12|    OPENSSL_LHASH *ret;
   66|       |
   67|     12|    if ((ret = OPENSSL_zalloc(sizeof(*ret))) == NULL)
  ------------------
  |  |  104|     12|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     12|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     12|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (67:9): [True: 0, False: 12]
  ------------------
   68|      0|        return NULL;
   69|     12|    if ((ret->b = OPENSSL_zalloc(sizeof(*ret->b) * MIN_NODES)) == NULL)
  ------------------
  |  |  104|     12|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     12|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     12|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (69:9): [True: 0, False: 12]
  ------------------
   70|      0|        goto err;
   71|     12|    ret->comp = ((c == NULL) ? (OPENSSL_LH_COMPFUNC)strcmp : c);
  ------------------
  |  Branch (71:18): [True: 0, False: 12]
  ------------------
   72|     12|    ret->hash = ((h == NULL) ? (OPENSSL_LH_HASHFUNC)OPENSSL_LH_strhash : h);
  ------------------
  |  Branch (72:18): [True: 0, False: 12]
  ------------------
   73|     12|    ret->num_nodes = MIN_NODES / 2;
  ------------------
  |  |   39|     12|#define MIN_NODES       16
  ------------------
   74|     12|    ret->num_alloc_nodes = MIN_NODES;
  ------------------
  |  |   39|     12|#define MIN_NODES       16
  ------------------
   75|     12|    ret->pmax = MIN_NODES / 2;
  ------------------
  |  |   39|     12|#define MIN_NODES       16
  ------------------
   76|     12|    ret->up_load = UP_LOAD;
  ------------------
  |  |   40|     12|#define UP_LOAD         (2*LH_LOAD_MULT) /* load times 256 (default 2) */
  |  |  ------------------
  |  |  |  |   85|     12|# define LH_LOAD_MULT    256
  |  |  ------------------
  ------------------
   77|     12|    ret->down_load = DOWN_LOAD;
  ------------------
  |  |   41|     12|#define DOWN_LOAD       (LH_LOAD_MULT) /* load times 256 (default 1) */
  |  |  ------------------
  |  |  |  |   85|     12|# define LH_LOAD_MULT    256
  |  |  ------------------
  ------------------
   78|     12|    return ret;
   79|       |
   80|      0|err:
   81|      0|    OPENSSL_free(ret->b);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   82|      0|    OPENSSL_free(ret);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   83|      0|    return NULL;
   84|     12|}
OPENSSL_LH_free:
   87|     14|{
   88|     14|    if (lh == NULL)
  ------------------
  |  Branch (88:9): [True: 2, False: 12]
  ------------------
   89|      2|        return;
   90|       |
   91|     12|    OPENSSL_LH_flush(lh);
   92|     12|    OPENSSL_free(lh->b);
  ------------------
  |  |  115|     12|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     12|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     12|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   93|     12|    OPENSSL_free(lh);
  ------------------
  |  |  115|     12|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     12|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     12|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   94|     12|}
OPENSSL_LH_flush:
   97|     12|{
   98|     12|    unsigned int i;
   99|     12|    OPENSSL_LH_NODE *n, *nn;
  100|       |
  101|     12|    if (lh == NULL)
  ------------------
  |  Branch (101:9): [True: 0, False: 12]
  ------------------
  102|      0|        return;
  103|       |
  104|  1.57k|    for (i = 0; i < lh->num_nodes; i++) {
  ------------------
  |  Branch (104:17): [True: 1.56k, False: 12]
  ------------------
  105|  1.56k|        n = lh->b[i];
  106|  4.53k|        while (n != NULL) {
  ------------------
  |  Branch (106:16): [True: 2.97k, False: 1.56k]
  ------------------
  107|  2.97k|            nn = n->next;
  108|  2.97k|            OPENSSL_free(n);
  ------------------
  |  |  115|  2.97k|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  2.97k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  2.97k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  109|  2.97k|            n = nn;
  110|  2.97k|        }
  111|  1.56k|        lh->b[i] = NULL;
  112|  1.56k|    }
  113|       |
  114|     12|    lh->num_items = 0;
  115|     12|}
OPENSSL_LH_insert:
  118|  8.55k|{
  119|  8.55k|    unsigned long hash;
  120|  8.55k|    OPENSSL_LH_NODE *nn, **rn;
  121|  8.55k|    void *ret;
  122|       |
  123|  8.55k|    lh->error = 0;
  124|  8.55k|    if ((lh->up_load <= (lh->num_items * LH_LOAD_MULT / lh->num_nodes)) && !expand(lh))
  ------------------
  |  |   85|  8.55k|# define LH_LOAD_MULT    256
  ------------------
  |  Branch (124:9): [True: 1.46k, False: 7.09k]
  |  Branch (124:76): [True: 0, False: 1.46k]
  ------------------
  125|      0|        return NULL;        /* 'lh->error++' already done in 'expand' */
  126|       |
  127|  8.55k|    rn = getrn(lh, data, &hash);
  128|       |
  129|  8.55k|    if (*rn == NULL) {
  ------------------
  |  Branch (129:9): [True: 2.97k, False: 5.57k]
  ------------------
  130|  2.97k|        if ((nn = OPENSSL_malloc(sizeof(*nn))) == NULL) {
  ------------------
  |  |  102|  2.97k|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|  2.97k|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|  2.97k|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (130:13): [True: 0, False: 2.97k]
  ------------------
  131|      0|            lh->error++;
  132|      0|            return NULL;
  133|      0|        }
  134|  2.97k|        nn->data = data;
  135|  2.97k|        nn->next = NULL;
  136|  2.97k|        nn->hash = hash;
  137|  2.97k|        *rn = nn;
  138|  2.97k|        ret = NULL;
  139|  2.97k|        lh->num_items++;
  140|  5.57k|    } else {                    /* replace same key */
  141|  5.57k|        ret = (*rn)->data;
  142|  5.57k|        (*rn)->data = data;
  143|  5.57k|    }
  144|  8.55k|    return ret;
  145|  8.55k|}
OPENSSL_LH_retrieve:
  174|    168|{
  175|    168|    unsigned long hash;
  176|    168|    OPENSSL_LH_NODE **rn;
  177|       |
  178|    168|    if (lh->error != 0)
  ------------------
  |  Branch (178:9): [True: 0, False: 168]
  ------------------
  179|      0|        lh->error = 0;
  180|       |
  181|    168|    rn = getrn(lh, data, &hash);
  182|       |
  183|    168|    return *rn == NULL ? NULL : (*rn)->data;
  ------------------
  |  Branch (183:12): [True: 168, False: 0]
  ------------------
  184|    168|}
OPENSSL_LH_doall:
  217|     10|{
  218|     10|    if (lh == NULL)
  ------------------
  |  Branch (218:9): [True: 0, False: 10]
  ------------------
  219|      0|        return;
  220|       |
  221|     10|    doall_util_fn(lh, 0, lh->daw, func, (OPENSSL_LH_DOALL_FUNCARG)NULL,
  222|     10|                  (OPENSSL_LH_DOALL_FUNCARG_THUNK)NULL, NULL);
  223|     10|}
OPENSSL_LH_strhash:
  362|     48|{
  363|     48|    unsigned long ret = 0;
  364|     48|    long n;
  365|     48|    unsigned long v;
  366|     48|    int r;
  367|       |
  368|     48|    if ((c == NULL) || (*c == '\0'))
  ------------------
  |  Branch (368:9): [True: 0, False: 48]
  |  Branch (368:24): [True: 0, False: 48]
  ------------------
  369|      0|        return ret;
  370|       |
  371|     48|    n = 0x100;
  372|    312|    while (*c) {
  ------------------
  |  Branch (372:12): [True: 264, False: 48]
  ------------------
  373|    264|        v = n | (*c);
  374|    264|        n += 0x100;
  375|    264|        r = (int)((v >> 2) ^ v) & 0x0f;
  376|       |        /* cast to uint64_t to avoid 32 bit shift of 32 bit value */
  377|    264|        ret = (ret << r) | (unsigned long)((uint64_t)ret >> (32 - r));
  378|    264|        ret &= 0xFFFFFFFFL;
  379|    264|        ret ^= v * v;
  380|    264|        c++;
  381|    264|    }
  382|     48|    return (ret >> 16) ^ ret;
  383|     48|}
OPENSSL_LH_error:
  442|     16|{
  443|     16|    return lh->error;
  444|     16|}
lhash.c:doall_util_fn:
  192|     10|{
  193|     10|    int i;
  194|     10|    OPENSSL_LH_NODE *a, *n;
  195|       |
  196|     10|    if (lh == NULL)
  ------------------
  |  Branch (196:9): [True: 0, False: 10]
  ------------------
  197|      0|        return;
  198|       |
  199|       |    /*
  200|       |     * reverse the order so we search from 'top to bottom' We were having
  201|       |     * memory leaks otherwise
  202|       |     */
  203|     90|    for (i = lh->num_nodes - 1; i >= 0; i--) {
  ------------------
  |  Branch (203:33): [True: 80, False: 10]
  ------------------
  204|     80|        a = lh->b[i];
  205|     96|        while (a != NULL) {
  ------------------
  |  Branch (205:16): [True: 16, False: 80]
  ------------------
  206|     16|            n = a->next;
  207|     16|            if (use_arg)
  ------------------
  |  Branch (207:17): [True: 0, False: 16]
  ------------------
  208|      0|                wfunc_arg(a->data, arg, func_arg);
  209|     16|            else
  210|     16|                wfunc(a->data, func);
  211|     16|            a = n;
  212|     16|        }
  213|     80|    }
  214|     10|}
lhash.c:expand:
  244|  1.46k|{
  245|  1.46k|    OPENSSL_LH_NODE **n, **n1, **n2, *np;
  246|  1.46k|    unsigned int p, pmax, nni, j;
  247|  1.46k|    unsigned long hash;
  248|       |
  249|  1.46k|    nni = lh->num_alloc_nodes;
  250|  1.46k|    p = lh->p;
  251|  1.46k|    pmax = lh->pmax;
  252|  1.46k|    if (p + 1 >= pmax) {
  ------------------
  |  Branch (252:9): [True: 12, False: 1.45k]
  ------------------
  253|     12|        j = nni * 2;
  254|     12|        n = OPENSSL_realloc(lh->b, sizeof(OPENSSL_LH_NODE *) * j);
  ------------------
  |  |  109|     12|        CRYPTO_realloc(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     12|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_realloc(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     12|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  255|     12|        if (n == NULL) {
  ------------------
  |  Branch (255:13): [True: 0, False: 12]
  ------------------
  256|      0|            lh->error++;
  257|      0|            return 0;
  258|      0|        }
  259|     12|        lh->b = n;
  260|     12|        memset(n + nni, 0, sizeof(*n) * (j - nni));
  261|     12|        lh->pmax = nni;
  262|     12|        lh->num_alloc_nodes = j;
  263|     12|        lh->p = 0;
  264|  1.45k|    } else {
  265|  1.45k|        lh->p++;
  266|  1.45k|    }
  267|       |
  268|  1.46k|    lh->num_nodes++;
  269|  1.46k|    n1 = &(lh->b[p]);
  270|  1.46k|    n2 = &(lh->b[p + pmax]);
  271|  1.46k|    *n2 = NULL;
  272|       |
  273|  6.70k|    for (np = *n1; np != NULL;) {
  ------------------
  |  Branch (273:20): [True: 5.24k, False: 1.46k]
  ------------------
  274|  5.24k|        hash = np->hash;
  275|  5.24k|        if ((hash % nni) != p) { /* move it */
  ------------------
  |  Branch (275:13): [True: 788, False: 4.45k]
  ------------------
  276|    788|            *n1 = (*n1)->next;
  277|    788|            np->next = *n2;
  278|    788|            *n2 = np;
  279|    788|        } else
  280|  4.45k|            n1 = &((*n1)->next);
  281|  5.24k|        np = *n1;
  282|  5.24k|    }
  283|       |
  284|  1.46k|    return 1;
  285|  1.46k|}
lhash.c:getrn:
  322|  8.72k|{
  323|  8.72k|    OPENSSL_LH_NODE **ret, *n1;
  324|  8.72k|    unsigned long hash, nn;
  325|       |
  326|  8.72k|    if (lh->hashw != NULL)
  ------------------
  |  Branch (326:9): [True: 8.72k, False: 0]
  ------------------
  327|  8.72k|        hash = lh->hashw(data, lh->hash);
  328|      0|    else
  329|      0|        hash = lh->hash(data);
  330|       |
  331|  8.72k|    *rhash = hash;
  332|       |
  333|  8.72k|    nn = hash % lh->pmax;
  334|  8.72k|    if (nn < lh->p)
  ------------------
  |  Branch (334:9): [True: 3.82k, False: 4.89k]
  ------------------
  335|  3.82k|        nn = hash % lh->num_alloc_nodes;
  336|       |
  337|  8.72k|    ret = &(lh->b[(int)nn]);
  338|  21.9k|    for (n1 = *ret; n1 != NULL; n1 = n1->next) {
  ------------------
  |  Branch (338:21): [True: 18.7k, False: 3.14k]
  ------------------
  339|  18.7k|        if (n1->hash != hash) {
  ------------------
  |  Branch (339:13): [True: 12.8k, False: 5.88k]
  ------------------
  340|  12.8k|            ret = &(n1->next);
  341|  12.8k|            continue;
  342|  12.8k|        }
  343|       |
  344|  5.88k|        if (lh->compw != NULL) {
  ------------------
  |  Branch (344:13): [True: 5.88k, False: 0]
  ------------------
  345|  5.88k|            if (lh->compw(n1->data, data, lh->comp) == 0)
  ------------------
  |  Branch (345:17): [True: 5.57k, False: 304]
  ------------------
  346|  5.57k|                break;
  347|  5.88k|        } else {
  348|      0|            if (lh->comp(n1->data, data) == 0)
  ------------------
  |  Branch (348:17): [True: 0, False: 0]
  ------------------
  349|      0|                break;
  350|      0|        }
  351|    304|        ret = &(n1->next);
  352|    304|    }
  353|  8.72k|    return ret;
  354|  8.72k|}

CRYPTO_malloc:
  178|   106k|{
  179|   106k|    void *ptr;
  180|       |
  181|   106k|    INCREMENT(malloc_count);
  182|   106k|    if (malloc_impl != CRYPTO_malloc) {
  ------------------
  |  Branch (182:9): [True: 0, False: 106k]
  ------------------
  183|      0|        ptr = malloc_impl(num, file, line);
  184|      0|        if (ptr != NULL || num == 0)
  ------------------
  |  Branch (184:13): [True: 0, False: 0]
  |  Branch (184:28): [True: 0, False: 0]
  ------------------
  185|      0|            return ptr;
  186|      0|        goto err;
  187|      0|    }
  188|       |
  189|   106k|    if (num == 0)
  ------------------
  |  Branch (189:9): [True: 0, False: 106k]
  ------------------
  190|      0|        return NULL;
  191|       |
  192|   106k|    FAILTEST();
  193|   106k|    if (allow_customize) {
  ------------------
  |  Branch (193:9): [True: 2, False: 106k]
  ------------------
  194|       |        /*
  195|       |         * Disallow customization after the first allocation. We only set this
  196|       |         * if necessary to avoid a store to the same cache line on every
  197|       |         * allocation.
  198|       |         */
  199|      2|        allow_customize = 0;
  200|      2|    }
  201|       |
  202|   106k|    ptr = malloc(num);
  203|   106k|    if (ptr != NULL)
  ------------------
  |  Branch (203:9): [True: 106k, False: 0]
  ------------------
  204|   106k|        return ptr;
  205|      0| err:
  206|       |    /*
  207|       |     * ossl_err_get_state_int() in err.c uses CRYPTO_zalloc(num, NULL, 0) for
  208|       |     * ERR_STATE allocation. Prevent mem alloc error loop while reporting error.
  209|       |     */
  210|      0|    if (file != NULL || line != 0) {
  ------------------
  |  Branch (210:9): [True: 0, False: 0]
  |  Branch (210:25): [True: 0, False: 0]
  ------------------
  211|      0|        ERR_new();
  212|      0|        ERR_set_debug(file, line, NULL);
  213|      0|        ERR_set_error(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE, NULL);
  ------------------
  |  |   85|      0|# define ERR_LIB_CRYPTO          15
  ------------------
                      ERR_set_error(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE, NULL);
  ------------------
  |  |  351|      0|# define ERR_R_MALLOC_FAILURE                    (256|ERR_R_FATAL)
  |  |  ------------------
  |  |  |  |  350|      0|# define ERR_R_FATAL                             (ERR_RFLAG_FATAL|ERR_RFLAG_COMMON)
  |  |  |  |  ------------------
  |  |  |  |  |  |  236|      0|# define ERR_RFLAG_FATAL                (0x1 << ERR_RFLAGS_OFFSET)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  228|      0|# define ERR_RFLAGS_OFFSET              18L
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |               # define ERR_R_FATAL                             (ERR_RFLAG_FATAL|ERR_RFLAG_COMMON)
  |  |  |  |  ------------------
  |  |  |  |  |  |  237|      0|# define ERR_RFLAG_COMMON               (0x2 << ERR_RFLAGS_OFFSET)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  228|      0|# define ERR_RFLAGS_OFFSET              18L
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  214|      0|    }
  215|      0|    return NULL;
  216|   106k|}
CRYPTO_zalloc:
  219|  96.1k|{
  220|  96.1k|    void *ret;
  221|       |
  222|  96.1k|    ret = CRYPTO_malloc(num, file, line);
  223|  96.1k|    if (ret != NULL)
  ------------------
  |  Branch (223:9): [True: 96.1k, False: 0]
  ------------------
  224|  96.1k|        memset(ret, 0, num);
  225|       |
  226|  96.1k|    return ret;
  227|  96.1k|}
CRYPTO_realloc:
  289|     14|{
  290|     14|    INCREMENT(realloc_count);
  291|     14|    if (realloc_impl != CRYPTO_realloc)
  ------------------
  |  Branch (291:9): [True: 0, False: 14]
  ------------------
  292|      0|        return realloc_impl(str, num, file, line);
  293|       |
  294|     14|    if (str == NULL)
  ------------------
  |  Branch (294:9): [True: 0, False: 14]
  ------------------
  295|      0|        return CRYPTO_malloc(num, file, line);
  296|       |
  297|     14|    if (num == 0) {
  ------------------
  |  Branch (297:9): [True: 0, False: 14]
  ------------------
  298|      0|        CRYPTO_free(str, file, line);
  299|      0|        return NULL;
  300|      0|    }
  301|       |
  302|     14|    FAILTEST();
  303|     14|    return realloc(str, num);
  304|     14|}
CRYPTO_free:
  334|   209k|{
  335|   209k|    INCREMENT(free_count);
  336|   209k|    if (free_impl != CRYPTO_free) {
  ------------------
  |  Branch (336:9): [True: 0, False: 209k]
  ------------------
  337|      0|        free_impl(str, file, line);
  338|      0|        return;
  339|      0|    }
  340|       |
  341|   209k|    free(str);
  342|   209k|}
CRYPTO_clear_free:
  345|  61.3k|{
  346|  61.3k|    if (str == NULL)
  ------------------
  |  Branch (346:9): [True: 0, False: 61.3k]
  ------------------
  347|      0|        return;
  348|  61.3k|    if (num)
  ------------------
  |  Branch (348:9): [True: 61.3k, False: 0]
  ------------------
  349|  61.3k|        OPENSSL_cleanse(str, num);
  350|  61.3k|    CRYPTO_free(str, file, line);
  351|  61.3k|}

CRYPTO_secure_malloc_done:
  132|      2|{
  133|      2|#ifndef OPENSSL_NO_SECURE_MEMORY
  134|      2|    if (secure_mem_used == 0) {
  ------------------
  |  Branch (134:9): [True: 2, False: 0]
  ------------------
  135|      2|        sh_done();
  136|      2|        secure_mem_initialized = 0;
  137|      2|        CRYPTO_THREAD_lock_free(sec_malloc_lock);
  138|      2|        sec_malloc_lock = NULL;
  139|      2|        return 1;
  140|      2|    }
  141|      0|#endif /* OPENSSL_NO_SECURE_MEMORY */
  142|      0|    return 0;
  143|      2|}
mem_sec.c:sh_done:
  599|      2|{
  600|      2|    OPENSSL_free(sh.freelist);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  601|      2|    OPENSSL_free(sh.bittable);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  602|      2|    OPENSSL_free(sh.bitmalloc);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  603|      2|#if !defined(_WIN32)
  604|      2|    if (sh.map_result != MAP_FAILED && sh.map_size)
  ------------------
  |  Branch (604:9): [True: 2, False: 0]
  |  Branch (604:40): [True: 0, False: 2]
  ------------------
  605|      0|        munmap(sh.map_result, sh.map_size);
  606|       |#else
  607|       |    if (sh.map_result != NULL && sh.map_size)
  608|       |        VirtualFree(sh.map_result, 0, MEM_RELEASE);
  609|       |#endif
  610|      2|    memset(&sh, 0, sizeof(sh));
  611|      2|}

OBJ_NAME_cleanup:
  368|      8|{
  369|      8|    unsigned long down_load;
  370|       |
  371|      8|    if (names_lh == NULL)
  ------------------
  |  Branch (371:9): [True: 8, False: 0]
  ------------------
  372|      8|        return;
  373|       |
  374|      0|    free_type = type;
  375|      0|    down_load = lh_OBJ_NAME_get_down_load(names_lh);
  376|      0|    lh_OBJ_NAME_set_down_load(names_lh, 0);
  377|       |
  378|      0|    lh_OBJ_NAME_doall(names_lh, names_lh_free_doall);
  379|      0|    if (type < 0) {
  ------------------
  |  Branch (379:9): [True: 0, False: 0]
  ------------------
  380|      0|        lh_OBJ_NAME_free(names_lh);
  381|      0|        sk_NAME_FUNCS_pop_free(name_funcs_stack, name_funcs_free);
  382|      0|        CRYPTO_THREAD_lock_free(obj_lock);
  383|      0|        names_lh = NULL;
  384|      0|        name_funcs_stack = NULL;
  385|      0|        obj_lock = NULL;
  386|      0|    } else
  387|      0|        lh_OBJ_NAME_set_down_load(names_lh, down_load);
  388|      0|}

ossl_obj_cleanup_int:
  212|      2|{
  213|      2|    if (added != NULL) {
  ------------------
  |  Branch (213:9): [True: 0, False: 2]
  ------------------
  214|      0|        lh_ADDED_OBJ_set_down_load(added, 0);
  215|      0|        lh_ADDED_OBJ_doall(added, cleanup1_doall); /* zero counters */
  216|      0|        lh_ADDED_OBJ_doall(added, cleanup2_doall); /* set counters */
  217|      0|        lh_ADDED_OBJ_doall(added, cleanup3_doall); /* free objects */
  218|      0|        lh_ADDED_OBJ_free(added);
  219|      0|        added = NULL;
  220|      0|    }
  221|      2|    objs_free_locks();
  222|      2|}
obj_dat.c:objs_free_locks:
   49|      2|{
   50|      2|    CRYPTO_THREAD_lock_free(ossl_obj_lock);
   51|      2|    ossl_obj_lock = NULL;
   52|       |#ifdef TSAN_REQUIRES_LOCKING
   53|       |    CRYPTO_THREAD_lock_free(ossl_obj_nid_lock);
   54|       |    ossl_obj_nid_lock = NULL;
   55|       |#endif
   56|      2|}

ossl_err_load_OBJ_strings:
   28|      2|{
   29|      2|#ifndef OPENSSL_NO_ERR
   30|      2|    if (ERR_reason_error_string(OBJ_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (30:9): [True: 2, False: 0]
  ------------------
   31|      2|        ERR_load_strings_const(OBJ_str_reasons);
   32|      2|#endif
   33|      2|    return 1;
   34|      2|}

OBJ_sigid_free:
  215|      2|{
  216|      2|    sk_nid_triple_pop_free(sig_app, sid_free);
  217|      2|    sk_nid_triple_free(sigx_app);
  218|      2|    CRYPTO_THREAD_lock_free(sig_lock);
  219|      2|    sig_app = NULL;
  220|      2|    sigx_app = NULL;
  221|      2|    sig_lock = NULL;
  222|      2|}

ossl_err_load_OCSP_strings:
   66|      2|{
   67|      2|# ifndef OPENSSL_NO_ERR
   68|      2|    if (ERR_reason_error_string(OCSP_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (68:9): [True: 2, False: 0]
  ------------------
   69|      2|        ERR_load_strings_const(OCSP_str_reasons);
   70|      2|# endif
   71|      2|    return 1;
   72|      2|}

ossl_err_load_PEM_strings:
   68|      2|{
   69|      2|#ifndef OPENSSL_NO_ERR
   70|      2|    if (ERR_reason_error_string(PEM_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (70:9): [True: 2, False: 0]
  ------------------
   71|      2|        ERR_load_strings_const(PEM_str_reasons);
   72|      2|#endif
   73|      2|    return 1;
   74|      2|}

ossl_err_load_PKCS12_strings:
   56|      2|{
   57|      2|#ifndef OPENSSL_NO_ERR
   58|      2|    if (ERR_reason_error_string(PKCS12_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (58:9): [True: 2, False: 0]
  ------------------
   59|      2|        ERR_load_strings_const(PKCS12_str_reasons);
   60|      2|#endif
   61|      2|    return 1;
   62|      2|}

ossl_err_load_PKCS7_strings:
   92|      2|{
   93|      2|#ifndef OPENSSL_NO_ERR
   94|      2|    if (ERR_reason_error_string(PKCS7_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (94:9): [True: 2, False: 0]
  ------------------
   95|      2|        ERR_load_strings_const(PKCS7_str_reasons);
   96|      2|#endif
   97|      2|    return 1;
   98|      2|}

ossl_property_defns_free:
   52|      2|{
   53|      2|    LHASH_OF(PROPERTY_DEFN_ELEM) *property_defns = vproperty_defns;
  ------------------
  |  |  149|      2|# define LHASH_OF(type) struct lhash_st_##type
  ------------------
   54|       |
   55|      2|    if (property_defns != NULL) {
  ------------------
  |  Branch (55:9): [True: 2, False: 0]
  ------------------
   56|      2|        lh_PROPERTY_DEFN_ELEM_doall(property_defns,
   57|      2|                                    &property_defn_free);
   58|      2|        lh_PROPERTY_DEFN_ELEM_free(property_defns);
   59|      2|    }
   60|      2|}
ossl_property_defns_new:
   62|      2|void *ossl_property_defns_new(OSSL_LIB_CTX *ctx) {
   63|      2|    return lh_PROPERTY_DEFN_ELEM_new(&property_defn_hash, &property_defn_cmp);
   64|      2|}

ossl_ctx_global_properties_free:
  114|      2|{
  115|      2|    OSSL_GLOBAL_PROPERTIES *globp = vglobp;
  116|       |
  117|      2|    if (globp != NULL) {
  ------------------
  |  Branch (117:9): [True: 2, False: 0]
  ------------------
  118|      2|        ossl_property_free(globp->list);
  119|      2|        OPENSSL_free(globp);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  120|      2|    }
  121|      2|}
ossl_ctx_global_properties_new:
  124|      2|{
  125|      2|    return OPENSSL_zalloc(sizeof(OSSL_GLOBAL_PROPERTIES));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  126|      2|}
ossl_method_store_new:
  243|      8|{
  244|      8|    OSSL_METHOD_STORE *res;
  245|       |
  246|      8|    res = OPENSSL_zalloc(sizeof(*res));
  ------------------
  |  |  104|      8|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      8|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      8|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  247|      8|    if (res != NULL) {
  ------------------
  |  Branch (247:9): [True: 8, False: 0]
  ------------------
  248|      8|        res->ctx = ctx;
  249|      8|        if ((res->algs = ossl_sa_ALGORITHM_new()) == NULL
  ------------------
  |  Branch (249:13): [True: 0, False: 8]
  ------------------
  250|      8|            || (res->lock = CRYPTO_THREAD_lock_new()) == NULL
  ------------------
  |  Branch (250:16): [True: 0, False: 8]
  ------------------
  251|      8|            || (res->biglock = CRYPTO_THREAD_lock_new()) == NULL) {
  ------------------
  |  Branch (251:16): [True: 0, False: 8]
  ------------------
  252|      0|            ossl_method_store_free(res);
  253|      0|            return NULL;
  254|      0|        }
  255|      8|    }
  256|      8|    return res;
  257|      8|}
ossl_method_store_free:
  260|      8|{
  261|      8|    if (store != NULL) {
  ------------------
  |  Branch (261:9): [True: 8, False: 0]
  ------------------
  262|      8|        if (store->algs != NULL)
  ------------------
  |  Branch (262:13): [True: 8, False: 0]
  ------------------
  263|      8|            ossl_sa_ALGORITHM_doall_arg(store->algs, &alg_cleanup, store);
  264|      8|        ossl_sa_ALGORITHM_free(store->algs);
  265|      8|        CRYPTO_THREAD_lock_free(store->lock);
  266|      8|        CRYPTO_THREAD_lock_free(store->biglock);
  267|      8|        OPENSSL_free(store);
  ------------------
  |  |  115|      8|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      8|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      8|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  268|      8|    }
  269|      8|}

ossl_err_load_PROP_strings:
   40|      2|{
   41|      2|#ifndef OPENSSL_NO_ERR
   42|      2|    if (ERR_reason_error_string(PROP_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (42:9): [True: 2, False: 0]
  ------------------
   43|      2|        ERR_load_strings_const(PROP_str_reasons);
   44|      2|#endif
   45|      2|    return 1;
   46|      2|}

ossl_property_free:
  530|      2|{
  531|      2|    OPENSSL_free(p);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  532|      2|}
ossl_property_parse_init:
  576|      2|{
  577|      2|    static const char *const predefined_names[] = {
  578|      2|        "provider",     /* Name of provider (default, legacy, fips) */
  579|      2|        "version",      /* Version number of this provider */
  580|      2|        "fips",         /* FIPS validated or FIPS supporting algorithm */
  581|      2|        "output",       /* Output type for encoders */
  582|      2|        "input",        /* Input type for decoders */
  583|      2|        "structure",    /* Structure name for encoders and decoders */
  584|      2|    };
  585|      2|    size_t i;
  586|       |
  587|     14|    for (i = 0; i < OSSL_NELEM(predefined_names); i++)
  ------------------
  |  |   14|     14|# define OSSL_NELEM(x)    (sizeof(x)/sizeof((x)[0]))
  ------------------
  |  Branch (587:17): [True: 12, False: 2]
  ------------------
  588|     12|        if (ossl_property_name(ctx, predefined_names[i], 1) == 0)
  ------------------
  |  Branch (588:13): [True: 0, False: 12]
  ------------------
  589|      0|            goto err;
  590|       |
  591|       |    /*
  592|       |     * Pre-populate the two Boolean values. We must do them before any other
  593|       |     * values and in this order so that we get the same index as the global
  594|       |     * OSSL_PROPERTY_TRUE and OSSL_PROPERTY_FALSE values
  595|       |     */
  596|      2|    if ((ossl_property_value(ctx, "yes", 1) != OSSL_PROPERTY_TRUE)
  ------------------
  |  |   37|      2|#define OSSL_PROPERTY_TRUE      1
  ------------------
  |  Branch (596:9): [True: 0, False: 2]
  ------------------
  597|      2|        || (ossl_property_value(ctx, "no", 1) != OSSL_PROPERTY_FALSE))
  ------------------
  |  |   38|      2|#define OSSL_PROPERTY_FALSE     2
  ------------------
  |  Branch (597:12): [True: 0, False: 2]
  ------------------
  598|      0|        goto err;
  599|       |
  600|      2|    return 1;
  601|      0|err:
  602|      0|    return 0;
  603|      2|}

ossl_property_string_data_free:
   77|      2|{
   78|      2|    PROPERTY_STRING_DATA *propdata = vpropdata;
   79|       |
   80|      2|    if (propdata == NULL)
  ------------------
  |  Branch (80:9): [True: 0, False: 2]
  ------------------
   81|      0|        return;
   82|       |
   83|      2|    CRYPTO_THREAD_lock_free(propdata->lock);
   84|      2|    property_table_free(&propdata->prop_names);
   85|      2|    property_table_free(&propdata->prop_values);
   86|      2|#ifndef OPENSSL_SMALL_FOOTPRINT
   87|      2|    sk_OPENSSL_CSTRING_free(propdata->prop_namelist);
  ------------------
  |  |  238|      2|#define sk_OPENSSL_CSTRING_free(sk) OPENSSL_sk_free(ossl_check_OPENSSL_CSTRING_sk_type(sk))
  ------------------
   88|      2|    sk_OPENSSL_CSTRING_free(propdata->prop_valuelist);
  ------------------
  |  |  238|      2|#define sk_OPENSSL_CSTRING_free(sk) OPENSSL_sk_free(ossl_check_OPENSSL_CSTRING_sk_type(sk))
  ------------------
   89|      2|    propdata->prop_namelist = propdata->prop_valuelist = NULL;
   90|      2|#endif
   91|      2|    propdata->prop_name_idx = propdata->prop_value_idx = 0;
   92|       |
   93|      2|    OPENSSL_free(propdata);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   94|      2|}
ossl_property_string_data_new:
   96|      2|void *ossl_property_string_data_new(OSSL_LIB_CTX *ctx) {
   97|      2|    PROPERTY_STRING_DATA *propdata = OPENSSL_zalloc(sizeof(*propdata));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   98|       |
   99|      2|    if (propdata == NULL)
  ------------------
  |  Branch (99:9): [True: 0, False: 2]
  ------------------
  100|      0|        return NULL;
  101|       |
  102|      2|    propdata->lock = CRYPTO_THREAD_lock_new();
  103|      2|    propdata->prop_names = lh_PROPERTY_STRING_new(&property_hash,
  104|      2|                                                  &property_cmp);
  105|      2|    propdata->prop_values = lh_PROPERTY_STRING_new(&property_hash,
  106|      2|                                                   &property_cmp);
  107|      2|#ifndef OPENSSL_SMALL_FOOTPRINT
  108|      2|    propdata->prop_namelist = sk_OPENSSL_CSTRING_new_null();
  ------------------
  |  |  235|      2|#define sk_OPENSSL_CSTRING_new_null() ((STACK_OF(OPENSSL_CSTRING) *)OPENSSL_sk_new_null())
  ------------------
  109|      2|    propdata->prop_valuelist = sk_OPENSSL_CSTRING_new_null();
  ------------------
  |  |  235|      2|#define sk_OPENSSL_CSTRING_new_null() ((STACK_OF(OPENSSL_CSTRING) *)OPENSSL_sk_new_null())
  ------------------
  110|      2|#endif
  111|      2|    if (propdata->lock == NULL
  ------------------
  |  Branch (111:9): [True: 0, False: 2]
  ------------------
  112|      2|#ifndef OPENSSL_SMALL_FOOTPRINT
  113|      2|            || propdata->prop_namelist == NULL
  ------------------
  |  Branch (113:16): [True: 0, False: 2]
  ------------------
  114|      2|            || propdata->prop_valuelist == NULL
  ------------------
  |  Branch (114:16): [True: 0, False: 2]
  ------------------
  115|      2|#endif
  116|      2|            || propdata->prop_names == NULL
  ------------------
  |  Branch (116:16): [True: 0, False: 2]
  ------------------
  117|      2|            || propdata->prop_values == NULL) {
  ------------------
  |  Branch (117:16): [True: 0, False: 2]
  ------------------
  118|      0|        ossl_property_string_data_free(propdata);
  119|      0|        return NULL;
  120|      0|    }
  121|      2|    return propdata;
  122|      2|}
ossl_property_name:
  253|     12|{
  254|     12|    return ossl_property_string(ctx, 1, create, s);
  255|     12|}
ossl_property_value:
  264|      4|{
  265|      4|    return ossl_property_string(ctx, 0, create, s);
  266|      4|}
property_string.c:property_table_free:
   66|      4|{
   67|      4|    PROP_TABLE *t = *pt;
   68|       |
   69|      4|    if (t != NULL) {
  ------------------
  |  Branch (69:9): [True: 4, False: 0]
  ------------------
   70|      4|        lh_PROPERTY_STRING_doall(t, &property_free);
   71|      4|        lh_PROPERTY_STRING_free(t);
   72|      4|        *pt = NULL;
   73|      4|    }
   74|      4|}
property_string.c:property_free:
   61|     16|{
   62|     16|    OPENSSL_free(ps);
  ------------------
  |  |  115|     16|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     16|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     16|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   63|     16|}
property_string.c:property_hash:
   51|     48|{
   52|     48|    return OPENSSL_LH_strhash(a->s);
   53|     48|}
property_string.c:ossl_property_string:
  144|     16|{
  145|     16|    PROPERTY_STRING p, *ps, *ps_new;
  146|     16|    PROP_TABLE *t;
  147|     16|    OSSL_PROPERTY_IDX *pidx;
  148|     16|    PROPERTY_STRING_DATA *propdata
  149|     16|        = ossl_lib_ctx_get_data(ctx, OSSL_LIB_CTX_PROPERTY_STRING_INDEX);
  ------------------
  |  |   99|     16|# define OSSL_LIB_CTX_PROPERTY_STRING_INDEX          3
  ------------------
  150|       |
  151|     16|    if (propdata == NULL)
  ------------------
  |  Branch (151:9): [True: 0, False: 16]
  ------------------
  152|      0|        return 0;
  153|       |
  154|     16|    t = name ? propdata->prop_names : propdata->prop_values;
  ------------------
  |  Branch (154:9): [True: 12, False: 4]
  ------------------
  155|     16|    p.s = s;
  156|     16|    if (!CRYPTO_THREAD_read_lock(propdata->lock)) {
  ------------------
  |  Branch (156:9): [True: 0, False: 16]
  ------------------
  157|      0|        ERR_raise(ERR_LIB_CRYPTO, ERR_R_UNABLE_TO_GET_READ_LOCK);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  158|      0|        return 0;
  159|      0|    }
  160|     16|    ps = lh_PROPERTY_STRING_retrieve(t, &p);
  161|     16|    if (ps == NULL && create) {
  ------------------
  |  Branch (161:9): [True: 16, False: 0]
  |  Branch (161:23): [True: 16, False: 0]
  ------------------
  162|     16|        CRYPTO_THREAD_unlock(propdata->lock);
  163|     16|        if (!CRYPTO_THREAD_write_lock(propdata->lock)) {
  ------------------
  |  Branch (163:13): [True: 0, False: 16]
  ------------------
  164|      0|            ERR_raise(ERR_LIB_CRYPTO, ERR_R_UNABLE_TO_GET_WRITE_LOCK);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  165|      0|            return 0;
  166|      0|        }
  167|     16|        pidx = name ? &propdata->prop_name_idx : &propdata->prop_value_idx;
  ------------------
  |  Branch (167:16): [True: 12, False: 4]
  ------------------
  168|     16|        ps = lh_PROPERTY_STRING_retrieve(t, &p);
  169|     16|        if (ps == NULL && (ps_new = new_property_string(s, pidx)) != NULL) {
  ------------------
  |  Branch (169:13): [True: 16, False: 0]
  |  Branch (169:27): [True: 16, False: 0]
  ------------------
  170|     16|#ifndef OPENSSL_SMALL_FOOTPRINT
  171|     16|            STACK_OF(OPENSSL_CSTRING) *slist;
  ------------------
  |  |   31|     16|# define STACK_OF(type) struct stack_st_##type
  ------------------
  172|       |
  173|     16|            slist = name ? propdata->prop_namelist : propdata->prop_valuelist;
  ------------------
  |  Branch (173:21): [True: 12, False: 4]
  ------------------
  174|     16|            if (sk_OPENSSL_CSTRING_push(slist, ps_new->s) <= 0) {
  ------------------
  |  |  242|     16|#define sk_OPENSSL_CSTRING_push(sk, ptr) OPENSSL_sk_push(ossl_check_OPENSSL_CSTRING_sk_type(sk), ossl_check_OPENSSL_CSTRING_type(ptr))
  ------------------
  |  Branch (174:17): [True: 0, False: 16]
  ------------------
  175|      0|                property_free(ps_new);
  176|      0|                CRYPTO_THREAD_unlock(propdata->lock);
  177|      0|                return 0;
  178|      0|            }
  179|     16|#endif
  180|     16|            lh_PROPERTY_STRING_insert(t, ps_new);
  181|     16|            if (lh_PROPERTY_STRING_error(t)) {
  ------------------
  |  Branch (181:17): [True: 0, False: 16]
  ------------------
  182|       |                /*-
  183|       |                 * Undo the previous push which means also decrementing the
  184|       |                 * index and freeing the allocated storage.
  185|       |                 */
  186|      0|#ifndef OPENSSL_SMALL_FOOTPRINT
  187|      0|                sk_OPENSSL_CSTRING_pop(slist);
  ------------------
  |  |  244|      0|#define sk_OPENSSL_CSTRING_pop(sk) ((const char *)OPENSSL_sk_pop(ossl_check_OPENSSL_CSTRING_sk_type(sk)))
  ------------------
  188|      0|#endif
  189|      0|                property_free(ps_new);
  190|      0|                --*pidx;
  191|      0|                CRYPTO_THREAD_unlock(propdata->lock);
  192|      0|                return 0;
  193|      0|            }
  194|     16|            ps = ps_new;
  195|     16|        }
  196|     16|    }
  197|     16|    CRYPTO_THREAD_unlock(propdata->lock);
  198|     16|    return ps != NULL ? ps->idx : 0;
  ------------------
  |  Branch (198:12): [True: 16, False: 0]
  ------------------
  199|     16|}
property_string.c:new_property_string:
  126|     16|{
  127|     16|    const size_t l = strlen(s);
  128|     16|    PROPERTY_STRING *ps = OPENSSL_malloc(sizeof(*ps) + l);
  ------------------
  |  |  102|     16|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     16|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     16|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  129|       |
  130|     16|    if (ps != NULL) {
  ------------------
  |  Branch (130:9): [True: 16, False: 0]
  ------------------
  131|     16|        memcpy(ps->body, s, l + 1);
  132|     16|        ps->s = ps->body;
  133|     16|        ps->idx = ++*pidx;
  134|     16|        if (ps->idx == 0) {
  ------------------
  |  Branch (134:13): [True: 0, False: 16]
  ------------------
  135|      0|            OPENSSL_free(ps);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  136|      0|            return NULL;
  137|      0|        }
  138|     16|    }
  139|     16|    return ps;
  140|     16|}

ossl_child_prov_ctx_new:
   38|      2|{
   39|      2|    return OPENSSL_zalloc(sizeof(struct child_prov_globals));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   40|      2|}
ossl_child_prov_ctx_free:
   43|      2|{
   44|      2|    struct child_prov_globals *gbl = vgbl;
   45|       |
   46|      2|    CRYPTO_THREAD_lock_free(gbl->lock);
   47|      2|    OPENSSL_free(gbl);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   48|      2|}

ossl_prov_conf_ctx_new:
   31|      2|{
   32|      2|    PROVIDER_CONF_GLOBAL *pcgbl = OPENSSL_zalloc(sizeof(*pcgbl));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   33|       |
   34|      2|    if (pcgbl == NULL)
  ------------------
  |  Branch (34:9): [True: 0, False: 2]
  ------------------
   35|      0|        return NULL;
   36|       |
   37|      2|    pcgbl->lock = CRYPTO_THREAD_lock_new();
   38|      2|    if (pcgbl->lock == NULL) {
  ------------------
  |  Branch (38:9): [True: 0, False: 2]
  ------------------
   39|      0|        OPENSSL_free(pcgbl);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   40|      0|        return NULL;
   41|      0|    }
   42|       |
   43|      2|    return pcgbl;
   44|      2|}
ossl_prov_conf_ctx_free:
   47|      2|{
   48|      2|    PROVIDER_CONF_GLOBAL *pcgbl = vpcgbl;
   49|       |
   50|      2|    sk_OSSL_PROVIDER_pop_free(pcgbl->activated_providers,
   51|      2|                              ossl_provider_free);
   52|       |
   53|      2|    OSSL_TRACE(CONF, "Cleaned up providers\n");
  ------------------
  |  |  287|      2|    OSSL_TRACEV(category, (trc_out, "%s", text))
  |  |  ------------------
  |  |  |  |  282|      2|#  define OSSL_TRACEV(category, args) ((void)0)
  |  |  ------------------
  ------------------
   54|      2|    CRYPTO_THREAD_lock_free(pcgbl->lock);
   55|      2|    OPENSSL_free(pcgbl);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   56|      2|}

ossl_provider_store_free:
  287|      2|{
  288|      2|    struct provider_store_st *store = vstore;
  289|      2|    size_t i;
  290|       |
  291|      2|    if (store == NULL)
  ------------------
  |  Branch (291:9): [True: 0, False: 2]
  ------------------
  292|      0|        return;
  293|      2|    store->freeing = 1;
  294|      2|    OPENSSL_free(store->default_path);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  295|      2|    sk_OSSL_PROVIDER_pop_free(store->providers, provider_deactivate_free);
  296|      2|#ifndef FIPS_MODULE
  297|      2|    sk_OSSL_PROVIDER_CHILD_CB_pop_free(store->child_cbs,
  298|      2|                                       ossl_provider_child_cb_free);
  299|      2|#endif
  300|      2|    CRYPTO_THREAD_lock_free(store->default_path_lock);
  301|      2|    CRYPTO_THREAD_lock_free(store->lock);
  302|      2|    for (i = 0; i < store->numprovinfo; i++)
  ------------------
  |  Branch (302:17): [True: 0, False: 2]
  ------------------
  303|      0|        ossl_provider_info_clear(&store->provinfo[i]);
  304|      2|    OPENSSL_free(store->provinfo);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  305|      2|    OPENSSL_free(store);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  306|      2|}
ossl_provider_store_new:
  309|      2|{
  310|      2|    struct provider_store_st *store = OPENSSL_zalloc(sizeof(*store));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  311|       |
  312|      2|    if (store == NULL
  ------------------
  |  Branch (312:9): [True: 0, False: 2]
  ------------------
  313|      2|        || (store->providers = sk_OSSL_PROVIDER_new(ossl_provider_cmp)) == NULL
  ------------------
  |  Branch (313:12): [True: 0, False: 2]
  ------------------
  314|      2|        || (store->default_path_lock = CRYPTO_THREAD_lock_new()) == NULL
  ------------------
  |  Branch (314:12): [True: 0, False: 2]
  ------------------
  315|      2|#ifndef FIPS_MODULE
  316|      2|        || (store->child_cbs = sk_OSSL_PROVIDER_CHILD_CB_new_null()) == NULL
  ------------------
  |  Branch (316:12): [True: 0, False: 2]
  ------------------
  317|      2|#endif
  318|      2|        || (store->lock = CRYPTO_THREAD_lock_new()) == NULL) {
  ------------------
  |  Branch (318:12): [True: 0, False: 2]
  ------------------
  319|      0|        ossl_provider_store_free(store);
  320|      0|        return NULL;
  321|      0|    }
  322|      2|    store->libctx = ctx;
  323|      2|    store->use_fallbacks = 1;
  324|       |
  325|      2|    return store;
  326|      2|}

ossl_err_load_RAND_strings:
  103|      2|{
  104|      2|#ifndef OPENSSL_NO_ERR
  105|      2|    if (ERR_reason_error_string(RAND_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (105:9): [True: 2, False: 0]
  ------------------
  106|      2|        ERR_load_strings_const(RAND_str_reasons);
  107|      2|#endif
  108|      2|    return 1;
  109|      2|}

ossl_rand_cleanup_int:
   81|      2|{
   82|      2|# ifndef OPENSSL_NO_DEPRECATED_3_0
   83|      2|    const RAND_METHOD *meth = default_RAND_meth;
   84|       |
   85|      2|    if (!rand_inited)
  ------------------
  |  Branch (85:9): [True: 2, False: 0]
  ------------------
   86|      2|        return;
   87|       |
   88|      0|    if (meth != NULL && meth->cleanup != NULL)
  ------------------
  |  Branch (88:9): [True: 0, False: 0]
  |  Branch (88:25): [True: 0, False: 0]
  ------------------
   89|      0|        meth->cleanup();
   90|      0|    RAND_set_rand_method(NULL);
   91|      0|# endif
   92|      0|    ossl_rand_pool_cleanup();
   93|      0|# ifndef OPENSSL_NO_ENGINE
   94|      0|    CRYPTO_THREAD_lock_free(rand_engine_lock);
   95|      0|    rand_engine_lock = NULL;
   96|      0|# endif
   97|      0|# ifndef OPENSSL_NO_DEPRECATED_3_0
   98|      0|    CRYPTO_THREAD_lock_free(rand_meth_lock);
   99|      0|    rand_meth_lock = NULL;
  100|      0|# endif
  101|      0|    ossl_release_default_drbg_ctx();
  102|      0|    rand_inited = 0;
  103|      0|}
ossl_rand_ctx_new:
  454|      2|{
  455|      2|    RAND_GLOBAL *dgbl = OPENSSL_zalloc(sizeof(*dgbl));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  456|       |
  457|      2|    if (dgbl == NULL)
  ------------------
  |  Branch (457:9): [True: 0, False: 2]
  ------------------
  458|      0|        return NULL;
  459|       |
  460|      2|#ifndef FIPS_MODULE
  461|       |    /*
  462|       |     * We need to ensure that base libcrypto thread handling has been
  463|       |     * initialised.
  464|       |     */
  465|      2|     OPENSSL_init_crypto(OPENSSL_INIT_BASE_ONLY, NULL);
  ------------------
  |  |   31|      2|# define OPENSSL_INIT_BASE_ONLY              0x00040000L
  ------------------
  466|      2|#endif
  467|       |
  468|      2|    dgbl->lock = CRYPTO_THREAD_lock_new();
  469|      2|    if (dgbl->lock == NULL)
  ------------------
  |  Branch (469:9): [True: 0, False: 2]
  ------------------
  470|      0|        goto err1;
  471|       |
  472|      2|    if (!CRYPTO_THREAD_init_local(&dgbl->private, NULL))
  ------------------
  |  Branch (472:9): [True: 0, False: 2]
  ------------------
  473|      0|        goto err1;
  474|       |
  475|      2|    if (!CRYPTO_THREAD_init_local(&dgbl->public, NULL))
  ------------------
  |  Branch (475:9): [True: 0, False: 2]
  ------------------
  476|      0|        goto err2;
  477|       |
  478|      2|    return dgbl;
  479|       |
  480|      0| err2:
  481|      0|    CRYPTO_THREAD_cleanup_local(&dgbl->private);
  482|      0| err1:
  483|      0|    CRYPTO_THREAD_lock_free(dgbl->lock);
  484|      0|    OPENSSL_free(dgbl);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  485|      0|    return NULL;
  486|      0|}
ossl_rand_ctx_free:
  489|      2|{
  490|      2|    RAND_GLOBAL *dgbl = vdgbl;
  491|       |
  492|      2|    if (dgbl == NULL)
  ------------------
  |  Branch (492:9): [True: 0, False: 2]
  ------------------
  493|      0|        return;
  494|       |
  495|      2|    CRYPTO_THREAD_lock_free(dgbl->lock);
  496|      2|    CRYPTO_THREAD_cleanup_local(&dgbl->private);
  497|      2|    CRYPTO_THREAD_cleanup_local(&dgbl->public);
  498|      2|    EVP_RAND_CTX_free(dgbl->primary);
  499|      2|    EVP_RAND_CTX_free(dgbl->seed);
  500|      2|    OPENSSL_free(dgbl->rng_name);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  501|      2|    OPENSSL_free(dgbl->rng_cipher);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  502|      2|    OPENSSL_free(dgbl->rng_digest);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  503|      2|    OPENSSL_free(dgbl->rng_propq);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  504|      2|    OPENSSL_free(dgbl->seed_name);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  505|      2|    OPENSSL_free(dgbl->seed_propq);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  506|       |
  507|      2|    OPENSSL_free(dgbl);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  508|      2|}

ossl_err_load_RSA_strings:
  160|      2|{
  161|      2|#ifndef OPENSSL_NO_ERR
  162|      2|    if (ERR_reason_error_string(RSA_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (162:9): [True: 2, False: 0]
  ------------------
  163|      2|        ERR_load_strings_const(RSA_str_reasons);
  164|      2|#endif
  165|      2|    return 1;
  166|      2|}

ossl_self_test_set_callback_new:
   35|      2|{
   36|      2|    SELF_TEST_CB *stcb;
   37|       |
   38|      2|    stcb = OPENSSL_zalloc(sizeof(*stcb));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   39|      2|    return stcb;
   40|      2|}
ossl_self_test_set_callback_free:
   43|      2|{
   44|      2|    OPENSSL_free(stcb);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   45|      2|}

ossl_sa_new:
   59|      8|{
   60|      8|    OPENSSL_SA *res = OPENSSL_zalloc(sizeof(*res));
  ------------------
  |  |  104|      8|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      8|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      8|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   61|       |
   62|      8|    return res;
   63|      8|}
ossl_sa_free:
  111|      8|{
  112|      8|    if (sa != NULL) {
  ------------------
  |  Branch (112:9): [True: 8, False: 0]
  ------------------
  113|      8|        sa_doall(sa, &sa_free_node, NULL, NULL);
  114|      8|        OPENSSL_free(sa);
  ------------------
  |  |  115|      8|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      8|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      8|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  115|      8|    }
  116|      8|}
ossl_sa_doall_arg:
  146|      8|{
  147|      8|    if (sa != NULL)
  ------------------
  |  Branch (147:9): [True: 8, False: 0]
  ------------------
  148|      8|        sa_doall(sa, NULL, leaf, arg);
  149|      8|}
sparse_array.c:sa_doall:
   67|     16|{
   68|     16|    int i[SA_BLOCK_MAX_LEVELS];
   69|     16|    void *nodes[SA_BLOCK_MAX_LEVELS];
   70|     16|    ossl_uintmax_t idx = 0;
   71|     16|    int l = 0;
   72|       |
   73|     16|    i[0] = 0;
   74|     16|    nodes[0] = sa->nodes;
   75|    288|    while (l >= 0) {
  ------------------
  |  Branch (75:12): [True: 272, False: 16]
  ------------------
   76|    272|        const int n = i[l];
   77|    272|        void ** const p = nodes[l];
   78|       |
   79|    272|        if (n >= SA_BLOCK_MAX) {
  ------------------
  |  |   45|    272|#define SA_BLOCK_MAX            (1 << OPENSSL_SA_BLOCK_BITS)
  |  |  ------------------
  |  |  |  |   34|    272|# define OPENSSL_SA_BLOCK_BITS           4
  |  |  ------------------
  ------------------
  |  Branch (79:13): [True: 16, False: 256]
  ------------------
   80|     16|            if (p != NULL && node != NULL)
  ------------------
  |  Branch (80:17): [True: 0, False: 16]
  |  Branch (80:30): [True: 0, False: 0]
  ------------------
   81|      0|                (*node)(p);
   82|     16|            l--;
   83|     16|            idx >>= OPENSSL_SA_BLOCK_BITS;
  ------------------
  |  |   34|     16|# define OPENSSL_SA_BLOCK_BITS           4
  ------------------
   84|    256|        } else {
   85|    256|            i[l] = n + 1;
   86|    256|            if (p != NULL && p[n] != NULL) {
  ------------------
  |  Branch (86:17): [True: 0, False: 256]
  |  Branch (86:30): [True: 0, False: 0]
  ------------------
   87|      0|                idx = (idx & ~SA_BLOCK_MASK) | n;
  ------------------
  |  |   46|      0|#define SA_BLOCK_MASK           (SA_BLOCK_MAX - 1)
  |  |  ------------------
  |  |  |  |   45|      0|#define SA_BLOCK_MAX            (1 << OPENSSL_SA_BLOCK_BITS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   34|      0|# define OPENSSL_SA_BLOCK_BITS           4
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   88|      0|                if (l < sa->levels - 1) {
  ------------------
  |  Branch (88:21): [True: 0, False: 0]
  ------------------
   89|      0|                    i[++l] = 0;
   90|      0|                    nodes[l] = p[n];
   91|      0|                    idx <<= OPENSSL_SA_BLOCK_BITS;
  ------------------
  |  |   34|      0|# define OPENSSL_SA_BLOCK_BITS           4
  ------------------
   92|      0|                } else if (leaf != NULL) {
  ------------------
  |  Branch (92:28): [True: 0, False: 0]
  ------------------
   93|      0|                    (*leaf)(idx, p[n], arg);
   94|      0|                }
   95|      0|            }
   96|    256|        }
   97|    272|    }
   98|     16|}

OPENSSL_sk_dup:
   48|      2|{
   49|      2|    OPENSSL_STACK *ret;
   50|       |
   51|      2|    if ((ret = OPENSSL_malloc(sizeof(*ret))) == NULL)
  ------------------
  |  |  102|      2|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (51:9): [True: 0, False: 2]
  ------------------
   52|      0|        goto err;
   53|       |
   54|      2|    if (sk == NULL) {
  ------------------
  |  Branch (54:9): [True: 2, False: 0]
  ------------------
   55|      2|        ret->num = 0;
   56|      2|        ret->sorted = 0;
   57|      2|        ret->comp = NULL;
   58|      2|    } else {
   59|       |        /* direct structure assignment */
   60|      0|        *ret = *sk;
   61|      0|    }
   62|       |
   63|      2|    if (sk == NULL || sk->num == 0) {
  ------------------
  |  Branch (63:9): [True: 2, False: 0]
  |  Branch (63:23): [True: 0, False: 0]
  ------------------
   64|       |        /* postpone |ret->data| allocation */
   65|      2|        ret->data = NULL;
   66|      2|        ret->num_alloc = 0;
   67|      2|        return ret;
   68|      2|    }
   69|       |
   70|       |    /* duplicate |sk->data| content */
   71|      0|    ret->data = OPENSSL_malloc(sizeof(*ret->data) * sk->num_alloc);
  ------------------
  |  |  102|      0|        CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_malloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
   72|      0|    if (ret->data == NULL)
  ------------------
  |  Branch (72:9): [True: 0, False: 0]
  ------------------
   73|      0|        goto err;
   74|      0|    memcpy(ret->data, sk->data, sizeof(void *) * sk->num);
   75|      0|    return ret;
   76|       |
   77|      0| err:
   78|      0|    OPENSSL_sk_free(ret);
   79|      0|    return NULL;
   80|      0|}
OPENSSL_sk_new_null:
  131|     10|{
  132|     10|    return OPENSSL_sk_new_reserve(NULL, 0);
  133|     10|}
OPENSSL_sk_new:
  136|      4|{
  137|      4|    return OPENSSL_sk_new_reserve(c, 0);
  138|      4|}
OPENSSL_sk_new_reserve:
  227|     14|{
  228|     14|    OPENSSL_STACK *st = OPENSSL_zalloc(sizeof(OPENSSL_STACK));
  ------------------
  |  |  104|     14|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     14|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     14|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  229|       |
  230|     14|    if (st == NULL)
  ------------------
  |  Branch (230:9): [True: 0, False: 14]
  ------------------
  231|      0|        return NULL;
  232|       |
  233|     14|    st->comp = c;
  234|       |
  235|     14|    if (n <= 0)
  ------------------
  |  Branch (235:9): [True: 14, False: 0]
  ------------------
  236|     14|        return st;
  237|       |
  238|      0|    if (!sk_reserve(st, n, 1)) {
  ------------------
  |  Branch (238:9): [True: 0, False: 0]
  ------------------
  239|      0|        OPENSSL_sk_free(st);
  240|      0|        return NULL;
  241|      0|    }
  242|       |
  243|      0|    return st;
  244|      0|}
OPENSSL_sk_insert:
  259|     18|{
  260|     18|    if (st == NULL) {
  ------------------
  |  Branch (260:9): [True: 0, False: 18]
  ------------------
  261|      0|        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  262|      0|        return 0;
  263|      0|    }
  264|     18|    if (st->num == max_nodes) {
  ------------------
  |  Branch (264:9): [True: 0, False: 18]
  ------------------
  265|      0|        ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_MANY_RECORDS);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  266|      0|        return 0;
  267|      0|    }
  268|       |
  269|     18|    if (!sk_reserve(st, 1, 0))
  ------------------
  |  Branch (269:9): [True: 0, False: 18]
  ------------------
  270|      0|        return 0;
  271|       |
  272|     18|    if ((loc >= st->num) || (loc < 0)) {
  ------------------
  |  Branch (272:9): [True: 18, False: 0]
  |  Branch (272:29): [True: 0, False: 0]
  ------------------
  273|     18|        st->data[st->num] = data;
  274|     18|    } else {
  275|      0|        memmove(&st->data[loc + 1], &st->data[loc],
  276|      0|                sizeof(st->data[0]) * (st->num - loc));
  277|      0|        st->data[loc] = data;
  278|      0|    }
  279|     18|    st->num++;
  280|     18|    st->sorted = 0;
  281|     18|    return st->num;
  282|     18|}
OPENSSL_sk_delete:
  310|      2|{
  311|      2|    if (st == NULL || loc < 0 || loc >= st->num)
  ------------------
  |  Branch (311:9): [True: 0, False: 2]
  |  Branch (311:23): [True: 0, False: 2]
  |  Branch (311:34): [True: 0, False: 2]
  ------------------
  312|      0|        return NULL;
  313|       |
  314|      2|    return internal_delete(st, loc);
  315|      2|}
OPENSSL_sk_push:
  398|     18|{
  399|     18|    if (st == NULL)
  ------------------
  |  Branch (399:9): [True: 0, False: 18]
  ------------------
  400|      0|        return 0;
  401|     18|    return OPENSSL_sk_insert(st, data, st->num);
  402|     18|}
OPENSSL_sk_pop_free:
  432|     50|{
  433|     50|    int i;
  434|       |
  435|     50|    if (st == NULL)
  ------------------
  |  Branch (435:9): [True: 42, False: 8]
  ------------------
  436|     42|        return;
  437|      8|    for (i = 0; i < st->num; i++)
  ------------------
  |  Branch (437:17): [True: 0, False: 8]
  ------------------
  438|      0|        if (st->data[i] != NULL)
  ------------------
  |  Branch (438:13): [True: 0, False: 0]
  ------------------
  439|      0|            func((char *)st->data[i]);
  440|      8|    OPENSSL_sk_free(st);
  441|      8|}
OPENSSL_sk_free:
  444|     26|{
  445|     26|    if (st == NULL)
  ------------------
  |  Branch (445:9): [True: 10, False: 16]
  ------------------
  446|     10|        return;
  447|     16|    OPENSSL_free(st->data);
  ------------------
  |  |  115|     16|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     16|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     16|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  448|     16|    OPENSSL_free(st);
  ------------------
  |  |  115|     16|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     16|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     16|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  449|     16|}
OPENSSL_sk_num:
  452|     10|{
  453|     10|    return st == NULL ? -1 : st->num;
  ------------------
  |  Branch (453:12): [True: 2, False: 8]
  ------------------
  454|     10|}
OPENSSL_sk_value:
  457|      2|{
  458|      2|    if (st == NULL || i < 0 || i >= st->num)
  ------------------
  |  Branch (458:9): [True: 0, False: 2]
  |  Branch (458:23): [True: 0, False: 2]
  |  Branch (458:32): [True: 0, False: 2]
  ------------------
  459|      0|        return NULL;
  460|      2|    return (void *)st->data[i];
  461|      2|}
stack.c:sk_reserve:
  178|     18|{
  179|     18|    const void **tmpdata;
  180|     18|    int num_alloc;
  181|       |
  182|       |    /* Check to see the reservation isn't exceeding the hard limit */
  183|     18|    if (n > max_nodes - st->num) {
  ------------------
  |  Branch (183:9): [True: 0, False: 18]
  ------------------
  184|      0|        ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_MANY_RECORDS);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  185|      0|        return 0;
  186|      0|    }
  187|       |
  188|       |    /* Figure out the new size */
  189|     18|    num_alloc = st->num + n;
  190|     18|    if (num_alloc < min_nodes)
  ------------------
  |  Branch (190:9): [True: 12, False: 6]
  ------------------
  191|     12|        num_alloc = min_nodes;
  192|       |
  193|       |    /* If |st->data| allocation was postponed */
  194|     18|    if (st->data == NULL) {
  ------------------
  |  Branch (194:9): [True: 6, False: 12]
  ------------------
  195|       |        /*
  196|       |         * At this point, |st->num_alloc| and |st->num| are 0;
  197|       |         * so |num_alloc| value is |n| or |min_nodes| if greater than |n|.
  198|       |         */
  199|      6|        if ((st->data = OPENSSL_zalloc(sizeof(void *) * num_alloc)) == NULL)
  ------------------
  |  |  104|      6|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      6|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      6|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (199:13): [True: 0, False: 6]
  ------------------
  200|      0|            return 0;
  201|      6|        st->num_alloc = num_alloc;
  202|      6|        return 1;
  203|      6|    }
  204|       |
  205|     12|    if (!exact) {
  ------------------
  |  Branch (205:9): [True: 12, False: 0]
  ------------------
  206|     12|        if (num_alloc <= st->num_alloc)
  ------------------
  |  Branch (206:13): [True: 10, False: 2]
  ------------------
  207|     10|            return 1;
  208|      2|        num_alloc = compute_growth(num_alloc, st->num_alloc);
  209|      2|        if (num_alloc == 0) {
  ------------------
  |  Branch (209:13): [True: 0, False: 2]
  ------------------
  210|      0|            ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_MANY_RECORDS);
  ------------------
  |  |  401|      0|# define ERR_raise(lib, reason) ERR_raise_data((lib),(reason),NULL)
  |  |  ------------------
  |  |  |  |  403|      0|    (ERR_new(),                                                 \
  |  |  |  |  404|      0|     ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  |  |  ------------------
  |  |  |  |                    ERR_set_debug(OPENSSL_FILE,OPENSSL_LINE,OPENSSL_FUNC),     \
  |  |  |  |  ------------------
  |  |  |  |  |  |  312|      0|#    define OPENSSL_FUNC __func__
  |  |  |  |  ------------------
  |  |  |  |  405|      0|     ERR_set_error)
  |  |  ------------------
  ------------------
  211|      0|            return 0;
  212|      0|        }
  213|      2|    } else if (num_alloc == st->num_alloc) {
  ------------------
  |  Branch (213:16): [True: 0, False: 0]
  ------------------
  214|      0|        return 1;
  215|      0|    }
  216|       |
  217|      2|    tmpdata = OPENSSL_realloc((void *)st->data, sizeof(void *) * num_alloc);
  ------------------
  |  |  109|      2|        CRYPTO_realloc(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_realloc(addr, num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  218|      2|    if (tmpdata == NULL)
  ------------------
  |  Branch (218:9): [True: 0, False: 2]
  ------------------
  219|      0|        return 0;
  220|       |
  221|      2|    st->data = tmpdata;
  222|      2|    st->num_alloc = num_alloc;
  223|      2|    return 1;
  224|      2|}
stack.c:compute_growth:
  160|      2|{
  161|      2|    int err = 0;
  162|       |
  163|      4|    while (current < target) {
  ------------------
  |  Branch (163:12): [True: 2, False: 2]
  ------------------
  164|      2|        if (current >= max_nodes)
  ------------------
  |  Branch (164:13): [True: 0, False: 2]
  ------------------
  165|      0|            return 0;
  166|       |
  167|      2|        current = safe_muldiv_int(current, 8, 5, &err);
  168|      2|        if (err != 0)
  ------------------
  |  Branch (168:13): [True: 0, False: 2]
  ------------------
  169|      0|            return 0;
  170|      2|        if (current >= max_nodes)
  ------------------
  |  Branch (170:13): [True: 0, False: 2]
  ------------------
  171|      0|            current = max_nodes;
  172|      2|    }
  173|      2|    return current;
  174|      2|}
stack.c:internal_delete:
  285|      2|{
  286|      2|    const void *ret = st->data[loc];
  287|       |
  288|      2|    if (loc != st->num - 1)
  ------------------
  |  Branch (288:9): [True: 0, False: 2]
  ------------------
  289|      0|        memmove(&st->data[loc], &st->data[loc + 1],
  290|      0|                sizeof(st->data[0]) * (st->num - loc - 1));
  291|      2|    st->num--;
  292|       |
  293|      2|    return (void *)ret;
  294|      2|}

ossl_err_load_OSSL_STORE_strings:
   69|      2|{
   70|      2|#ifndef OPENSSL_NO_ERR
   71|      2|    if (ERR_reason_error_string(OSSL_STORE_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (71:9): [True: 2, False: 0]
  ------------------
   72|      2|        ERR_load_strings_const(OSSL_STORE_str_reasons);
   73|      2|#endif
   74|      2|    return 1;
   75|      2|}

ossl_store_cleanup_int:
   14|      2|{
   15|      2|    ossl_store_destroy_loaders_int();
   16|      2|}

ossl_store_destroy_loaders_int:
  281|      2|{
  282|      2|    lh_OSSL_STORE_LOADER_free(loader_register);
  283|      2|    loader_register = NULL;
  284|      2|    CRYPTO_THREAD_lock_free(registry_lock);
  285|      2|    registry_lock = NULL;
  286|      2|}

ossl_crypto_mutex_new:
   97|      2|{
   98|      2|    pthread_mutex_t *mutex;
   99|       |
  100|      2|    if ((mutex = OPENSSL_zalloc(sizeof(*mutex))) == NULL)
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (100:9): [True: 0, False: 2]
  ------------------
  101|      0|        return NULL;
  102|      2|    if (pthread_mutex_init(mutex, NULL) != 0) {
  ------------------
  |  Branch (102:9): [True: 0, False: 2]
  ------------------
  103|      0|        OPENSSL_free(mutex);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  104|      0|        return NULL;
  105|      0|    }
  106|      2|    return (CRYPTO_MUTEX *)mutex;
  107|      2|}
ossl_crypto_mutex_free:
  142|      2|{
  143|      2|    pthread_mutex_t **mutex_p;
  144|       |
  145|      2|    if (mutex == NULL)
  ------------------
  |  Branch (145:9): [True: 0, False: 2]
  ------------------
  146|      0|        return;
  147|       |
  148|      2|    mutex_p = (pthread_mutex_t **)mutex;
  149|      2|    if (*mutex_p != NULL)
  ------------------
  |  Branch (149:9): [True: 2, False: 0]
  ------------------
  150|      2|        pthread_mutex_destroy(*mutex_p);
  151|      2|    OPENSSL_free(*mutex_p);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  152|      2|    *mutex = NULL;
  153|      2|}
ossl_crypto_condvar_new:
  156|      2|{
  157|      2|    pthread_cond_t *cv_p;
  158|       |
  159|      2|    if ((cv_p = OPENSSL_zalloc(sizeof(*cv_p))) == NULL)
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (159:9): [True: 0, False: 2]
  ------------------
  160|      0|        return NULL;
  161|      2|    if (pthread_cond_init(cv_p, NULL) != 0) {
  ------------------
  |  Branch (161:9): [True: 0, False: 2]
  ------------------
  162|      0|        OPENSSL_free(cv_p);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  163|      0|        return NULL;
  164|      0|    }
  165|      2|    return (CRYPTO_CONDVAR *) cv_p;
  166|      2|}
ossl_crypto_condvar_free:
  220|      2|{
  221|      2|    pthread_cond_t **cv_p;
  222|       |
  223|      2|    if (cv == NULL)
  ------------------
  |  Branch (223:9): [True: 0, False: 2]
  ------------------
  224|      0|        return;
  225|       |
  226|      2|    cv_p = (pthread_cond_t **)cv;
  227|      2|    if (*cv_p != NULL)
  ------------------
  |  Branch (227:9): [True: 2, False: 0]
  ------------------
  228|      2|        pthread_cond_destroy(*cv_p);
  229|      2|    OPENSSL_free(*cv_p);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  230|      2|    *cv_p = NULL;
  231|      2|}

ossl_threads_ctx_new:
  128|      2|{
  129|      2|    struct openssl_threads_st *t = OPENSSL_zalloc(sizeof(*t));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  130|       |
  131|      2|    if (t == NULL)
  ------------------
  |  Branch (131:9): [True: 0, False: 2]
  ------------------
  132|      0|        return NULL;
  133|       |
  134|      2|    t->lock = ossl_crypto_mutex_new();
  135|      2|    t->cond_finished = ossl_crypto_condvar_new();
  136|       |
  137|      2|    if (t->lock == NULL || t->cond_finished == NULL)
  ------------------
  |  Branch (137:9): [True: 0, False: 2]
  |  Branch (137:28): [True: 0, False: 2]
  ------------------
  138|      0|        goto fail;
  139|       |
  140|      2|    return t;
  141|       |
  142|      0|fail:
  143|      0|    ossl_threads_ctx_free((void *)t);
  144|      0|    return NULL;
  145|      2|}
ossl_threads_ctx_free:
  148|      2|{
  149|      2|    OSSL_LIB_CTX_THREADS *t = (OSSL_LIB_CTX_THREADS *) vdata;
  150|       |
  151|      2|    if (t == NULL)
  ------------------
  |  Branch (151:9): [True: 0, False: 2]
  ------------------
  152|      0|        return;
  153|       |
  154|      2|    ossl_crypto_mutex_free(&t->lock);
  155|      2|    ossl_crypto_condvar_free(&t->cond_finished);
  156|      2|    OPENSSL_free(t);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  157|      2|}

ossl_rcu_write_lock:
  576|      4|{
  577|      4|    pthread_mutex_lock(&lock->write_lock);
  578|      4|    TSAN_FAKE_UNLOCK(&lock->write_lock);
  579|      4|}
ossl_rcu_write_unlock:
  582|      4|{
  583|      4|    TSAN_FAKE_LOCK(&lock->write_lock);
  584|      4|    pthread_mutex_unlock(&lock->write_lock);
  585|      4|}
ossl_synchronize_rcu:
  588|      6|{
  589|      6|    struct rcu_qp *qp;
  590|      6|    uint64_t count;
  591|      6|    struct rcu_cb_item *cb_items, *tmpcb;
  592|       |
  593|      6|    pthread_mutex_lock(&lock->write_lock);
  594|      6|    cb_items = lock->cb_items;
  595|      6|    lock->cb_items = NULL;
  596|      6|    pthread_mutex_unlock(&lock->write_lock);
  597|       |
  598|      6|    qp = update_qp(lock);
  599|       |
  600|       |    /*
  601|       |     * wait for the reader count to reach zero
  602|       |     * Note the use of __ATOMIC_ACQUIRE here to ensure that any
  603|       |     * prior __ATOMIC_RELEASE write operation in get_hold_current_qp
  604|       |     * is visible prior to our read
  605|       |     */
  606|      6|    do {
  607|      6|        count = ATOMIC_LOAD_N(uint64_t, &qp->users, __ATOMIC_ACQUIRE);
  ------------------
  |  |  122|      6|#   define ATOMIC_LOAD_N(t, p, o) __atomic_load_n(p, o)
  ------------------
  608|      6|    } while (READER_COUNT(count) != 0);
  ------------------
  |  |  281|      6|# define READER_COUNT(x) ((uint32_t)(((uint64_t)(x) >> READER_SHIFT) & \
  |  |  ------------------
  |  |  |  |  273|      6|# define READER_SHIFT 0
  |  |  ------------------
  |  |  282|      6|                                     READER_MASK))
  |  |  ------------------
  |  |  |  |  279|      6|# define READER_MASK     (((uint64_t)1 << READER_SIZE) - 1)
  |  |  |  |  ------------------
  |  |  |  |  |  |  276|      6|# define READER_SIZE 16
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (608:14): [True: 0, False: 6]
  ------------------
  609|       |
  610|       |    /* retire in order */
  611|      6|    pthread_mutex_lock(&lock->prior_lock);
  612|      6|    while (lock->next_to_retire != ID_VAL(count))
  ------------------
  |  |  283|      6|# define ID_VAL(x)       ((uint32_t)(((uint64_t)(x) >> ID_SHIFT) & ID_MASK))
  |  |  ------------------
  |  |  |  |  274|      6|# define ID_SHIFT 32
  |  |  ------------------
  |  |               # define ID_VAL(x)       ((uint32_t)(((uint64_t)(x) >> ID_SHIFT) & ID_MASK))
  |  |  ------------------
  |  |  |  |  280|      6|# define ID_MASK         (((uint64_t)1 << ID_SIZE) - 1)
  |  |  |  |  ------------------
  |  |  |  |  |  |  277|      6|# define ID_SIZE 32
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (612:12): [True: 0, False: 6]
  ------------------
  613|      0|        pthread_cond_wait(&lock->prior_signal, &lock->prior_lock);
  614|      6|    lock->next_to_retire++;
  615|      6|    pthread_cond_broadcast(&lock->prior_signal);
  616|      6|    pthread_mutex_unlock(&lock->prior_lock);
  617|       |
  618|      6|    retire_qp(lock, qp);
  619|       |
  620|       |    /* handle any callbacks that we have */
  621|      6|    while (cb_items != NULL) {
  ------------------
  |  Branch (621:12): [True: 0, False: 6]
  ------------------
  622|      0|        tmpcb = cb_items;
  623|      0|        cb_items = cb_items->next;
  624|      0|        tmpcb->fn(tmpcb->data);
  625|      0|        OPENSSL_free(tmpcb);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  626|      0|    }
  627|      6|}
ossl_rcu_uptr_deref:
  651|      4|{
  652|      4|    return ATOMIC_LOAD_N(pvoid, p, __ATOMIC_ACQUIRE);
  ------------------
  |  |  122|      4|#   define ATOMIC_LOAD_N(t, p, o) __atomic_load_n(p, o)
  ------------------
  653|      4|}
ossl_rcu_assign_uptr:
  656|      4|{
  657|      4|    ATOMIC_STORE(pvoid, p, v, __ATOMIC_RELEASE);
  ------------------
  |  |  125|      4|#  define ATOMIC_STORE(t, p, v, o) __atomic_store(p, v, o)
  ------------------
  658|      4|}
ossl_rcu_lock_new:
  661|      2|{
  662|      2|    struct rcu_lock_st *new;
  663|       |
  664|      2|    if (num_writers < 1)
  ------------------
  |  Branch (664:9): [True: 0, False: 2]
  ------------------
  665|      0|        num_writers = 1;
  666|       |
  667|      2|    ctx = ossl_lib_ctx_get_concrete(ctx);
  668|      2|    if (ctx == NULL)
  ------------------
  |  Branch (668:9): [True: 0, False: 2]
  ------------------
  669|      0|        return 0;
  670|       |
  671|      2|    new = OPENSSL_zalloc(sizeof(*new));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  672|      2|    if (new == NULL)
  ------------------
  |  Branch (672:9): [True: 0, False: 2]
  ------------------
  673|      0|        return NULL;
  674|       |
  675|      2|    new->ctx = ctx;
  676|      2|    pthread_mutex_init(&new->write_lock, NULL);
  677|      2|    pthread_mutex_init(&new->prior_lock, NULL);
  678|      2|    pthread_mutex_init(&new->alloc_lock, NULL);
  679|      2|    pthread_cond_init(&new->prior_signal, NULL);
  680|      2|    pthread_cond_init(&new->alloc_signal, NULL);
  681|      2|    new->qp_group = allocate_new_qp_group(new, num_writers + 1);
  682|      2|    if (new->qp_group == NULL) {
  ------------------
  |  Branch (682:9): [True: 0, False: 2]
  ------------------
  683|      0|        OPENSSL_free(new);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  684|      0|        new = NULL;
  685|      0|    }
  686|      2|    return new;
  687|      2|}
ossl_rcu_lock_free:
  690|      2|{
  691|      2|    struct rcu_lock_st *rlock = (struct rcu_lock_st *)lock;
  692|       |
  693|      2|    if (lock == NULL)
  ------------------
  |  Branch (693:9): [True: 0, False: 2]
  ------------------
  694|      0|        return;
  695|       |
  696|       |    /* make sure we're synchronized */
  697|      2|    ossl_synchronize_rcu(rlock);
  698|       |
  699|      2|    OPENSSL_free(rlock->qp_group);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  700|       |    /* There should only be a single qp left now */
  701|      2|    OPENSSL_free(rlock);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  702|      2|}
CRYPTO_THREAD_lock_new:
  705|     46|{
  706|     46|# ifdef USE_RWLOCK
  707|     46|    CRYPTO_RWLOCK *lock;
  708|       |
  709|     46|    if ((lock = OPENSSL_zalloc(sizeof(pthread_rwlock_t))) == NULL)
  ------------------
  |  |  104|     46|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     46|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     46|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  |  Branch (709:9): [True: 0, False: 46]
  ------------------
  710|       |        /* Don't set error, to avoid recursion blowup. */
  711|      0|        return NULL;
  712|       |
  713|     46|    if (pthread_rwlock_init(lock, NULL) != 0) {
  ------------------
  |  Branch (713:9): [True: 0, False: 46]
  ------------------
  714|      0|        OPENSSL_free(lock);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  715|      0|        return NULL;
  716|      0|    }
  717|       |# else
  718|       |    pthread_mutexattr_t attr;
  719|       |    CRYPTO_RWLOCK *lock;
  720|       |
  721|       |    if ((lock = OPENSSL_zalloc(sizeof(pthread_mutex_t))) == NULL)
  722|       |        /* Don't set error, to avoid recursion blowup. */
  723|       |        return NULL;
  724|       |
  725|       |    /*
  726|       |     * We don't use recursive mutexes, but try to catch errors if we do.
  727|       |     */
  728|       |    pthread_mutexattr_init(&attr);
  729|       |#  if !defined (__TANDEM) && !defined (_SPT_MODEL_)
  730|       |#   if !defined(NDEBUG) && !defined(OPENSSL_NO_MUTEX_ERRORCHECK)
  731|       |    pthread_mutexattr_settype(&attr, PTHREAD_MUTEX_ERRORCHECK);
  732|       |#   endif
  733|       |#  else
  734|       |    /* The SPT Thread Library does not define MUTEX attributes. */
  735|       |#  endif
  736|       |
  737|       |    if (pthread_mutex_init(lock, &attr) != 0) {
  738|       |        pthread_mutexattr_destroy(&attr);
  739|       |        OPENSSL_free(lock);
  740|       |        return NULL;
  741|       |    }
  742|       |
  743|       |    pthread_mutexattr_destroy(&attr);
  744|       |# endif
  745|       |
  746|     46|    return lock;
  747|     46|}
CRYPTO_THREAD_read_lock:
  750|    152|{
  751|    152|# ifdef USE_RWLOCK
  752|    152|    if (pthread_rwlock_rdlock(lock) != 0)
  ------------------
  |  Branch (752:9): [True: 0, False: 152]
  ------------------
  753|      0|        return 0;
  754|       |# else
  755|       |    if (pthread_mutex_lock(lock) != 0) {
  756|       |        assert(errno != EDEADLK && errno != EBUSY);
  757|       |        return 0;
  758|       |    }
  759|       |# endif
  760|       |
  761|    152|    return 1;
  762|    152|}
CRYPTO_THREAD_write_lock:
  765|    230|{
  766|    230|# ifdef USE_RWLOCK
  767|    230|    if (pthread_rwlock_wrlock(lock) != 0)
  ------------------
  |  Branch (767:9): [True: 0, False: 230]
  ------------------
  768|      0|        return 0;
  769|       |# else
  770|       |    if (pthread_mutex_lock(lock) != 0) {
  771|       |        assert(errno != EDEADLK && errno != EBUSY);
  772|       |        return 0;
  773|       |    }
  774|       |# endif
  775|       |
  776|    230|    return 1;
  777|    230|}
CRYPTO_THREAD_unlock:
  780|    382|{
  781|    382|# ifdef USE_RWLOCK
  782|    382|    if (pthread_rwlock_unlock(lock) != 0)
  ------------------
  |  Branch (782:9): [True: 0, False: 382]
  ------------------
  783|      0|        return 0;
  784|       |# else
  785|       |    if (pthread_mutex_unlock(lock) != 0) {
  786|       |        assert(errno != EPERM);
  787|       |        return 0;
  788|       |    }
  789|       |# endif
  790|       |
  791|    382|    return 1;
  792|    382|}
CRYPTO_THREAD_lock_free:
  795|     60|{
  796|     60|    if (lock == NULL)
  ------------------
  |  Branch (796:9): [True: 14, False: 46]
  ------------------
  797|     14|        return;
  798|       |
  799|     46|# ifdef USE_RWLOCK
  800|     46|    pthread_rwlock_destroy(lock);
  801|       |# else
  802|       |    pthread_mutex_destroy(lock);
  803|       |# endif
  804|     46|    OPENSSL_free(lock);
  ------------------
  |  |  115|     46|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|     46|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|     46|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  805|       |
  806|     46|    return;
  807|     60|}
CRYPTO_THREAD_run_once:
  810|  6.28k|{
  811|  6.28k|    if (pthread_once(once, init) != 0)
  ------------------
  |  Branch (811:9): [True: 0, False: 6.28k]
  ------------------
  812|      0|        return 0;
  813|       |
  814|  6.28k|    return 1;
  815|  6.28k|}
CRYPTO_THREAD_init_local:
  818|     14|{
  819|     14|    if (pthread_key_create(key, cleanup) != 0)
  ------------------
  |  Branch (819:9): [True: 0, False: 14]
  ------------------
  820|      0|        return 0;
  821|       |
  822|     14|    return 1;
  823|     14|}
CRYPTO_THREAD_get_local:
  826|  3.07k|{
  827|  3.07k|    return pthread_getspecific(*key);
  828|  3.07k|}
CRYPTO_THREAD_set_local:
  831|     14|{
  832|     14|    if (pthread_setspecific(*key, val) != 0)
  ------------------
  |  Branch (832:9): [True: 0, False: 14]
  ------------------
  833|      0|        return 0;
  834|       |
  835|     14|    return 1;
  836|     14|}
CRYPTO_THREAD_cleanup_local:
  839|     14|{
  840|     14|    if (pthread_key_delete(*key) != 0)
  ------------------
  |  Branch (840:9): [True: 0, False: 14]
  ------------------
  841|      0|        return 0;
  842|       |
  843|     14|    return 1;
  844|     14|}
CRYPTO_atomic_or:
  936|      2|{
  937|      2|# if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
  938|      2|    if (__atomic_is_lock_free(sizeof(*val), val)) {
  ------------------
  |  Branch (938:9): [Folded - Ignored]
  ------------------
  939|      2|        *ret = __atomic_or_fetch(val, op, __ATOMIC_ACQ_REL);
  940|      2|        return 1;
  941|      2|    }
  942|       |# elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
  943|       |    /* This will work for all future Solaris versions. */
  944|       |    if (ret != NULL) {
  945|       |        *ret = atomic_or_64_nv(val, op);
  946|       |        return 1;
  947|       |    }
  948|       |# endif
  949|      0|    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock))
  ------------------
  |  Branch (949:9): [True: 0, False: 0]
  |  Branch (949:25): [True: 0, False: 0]
  ------------------
  950|      0|        return 0;
  951|      0|    *val |= op;
  952|      0|    *ret  = *val;
  953|       |
  954|      0|    if (!CRYPTO_THREAD_unlock(lock))
  ------------------
  |  Branch (954:9): [True: 0, False: 0]
  ------------------
  955|      0|        return 0;
  956|       |
  957|      0|    return 1;
  958|      0|}
CRYPTO_atomic_load:
  961|  3.06k|{
  962|  3.06k|# if defined(__GNUC__) && defined(__ATOMIC_ACQUIRE) && !defined(BROKEN_CLANG_ATOMICS)
  963|  3.06k|    if (__atomic_is_lock_free(sizeof(*val), val)) {
  ------------------
  |  Branch (963:9): [Folded - Ignored]
  ------------------
  964|  3.06k|        __atomic_load(val, ret, __ATOMIC_ACQUIRE);
  965|  3.06k|        return 1;
  966|  3.06k|    }
  967|       |# elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
  968|       |    /* This will work for all future Solaris versions. */
  969|       |    if (ret != NULL) {
  970|       |        *ret = atomic_or_64_nv(val, 0);
  971|       |        return 1;
  972|       |    }
  973|       |# endif
  974|      0|    if (lock == NULL || !CRYPTO_THREAD_read_lock(lock))
  ------------------
  |  Branch (974:9): [True: 0, False: 0]
  |  Branch (974:25): [True: 0, False: 0]
  ------------------
  975|      0|        return 0;
  976|      0|    *ret  = *val;
  977|      0|    if (!CRYPTO_THREAD_unlock(lock))
  ------------------
  |  Branch (977:9): [True: 0, False: 0]
  ------------------
  978|      0|        return 0;
  979|       |
  980|      0|    return 1;
  981|      0|}
threads_pthread.c:update_qp:
  501|      6|{
  502|      6|    uint64_t new_id;
  503|      6|    uint32_t current_idx;
  504|       |
  505|      6|    pthread_mutex_lock(&lock->alloc_lock);
  506|       |
  507|       |    /*
  508|       |     * we need at least one qp to be available with one
  509|       |     * left over, so that readers can start working on
  510|       |     * one that isn't yet being waited on
  511|       |     */
  512|      6|    while (lock->group_count - lock->writers_alloced < 2)
  ------------------
  |  Branch (512:12): [True: 0, False: 6]
  ------------------
  513|       |        /* we have to wait for one to be free */
  514|      0|        pthread_cond_wait(&lock->alloc_signal, &lock->alloc_lock);
  515|       |
  516|      6|    current_idx = lock->current_alloc_idx;
  517|       |
  518|       |    /* Allocate the qp */
  519|      6|    lock->writers_alloced++;
  520|       |
  521|       |    /* increment the allocation index */
  522|      6|    lock->current_alloc_idx =
  523|      6|        (lock->current_alloc_idx + 1) % lock->group_count;
  524|       |
  525|       |    /* get and insert a new id */
  526|      6|    new_id = VAL_ID(lock->id_ctr);
  ------------------
  |  |  285|      6|# define VAL_ID(x)       ((uint64_t)x << ID_SHIFT)
  |  |  ------------------
  |  |  |  |  274|      6|# define ID_SHIFT 32
  |  |  ------------------
  ------------------
  527|      6|    lock->id_ctr++;
  528|       |
  529|       |    /*
  530|       |     * Even though we are under a write side lock here
  531|       |     * We need to use atomic instructions to ensure that the results
  532|       |     * of this update are published to the read side prior to updating the
  533|       |     * reader idx below
  534|       |     */
  535|      6|    ATOMIC_AND_FETCH(&lock->qp_group[current_idx].users, ID_MASK,
  ------------------
  |  |  130|      6|#  define ATOMIC_AND_FETCH(p, m, o) __atomic_and_fetch(p, m, o)
  ------------------
  536|      6|                     __ATOMIC_RELEASE);
  537|      6|    ATOMIC_OR_FETCH(&lock->qp_group[current_idx].users, new_id,
  ------------------
  |  |  131|      6|#  define ATOMIC_OR_FETCH(p, m, o) __atomic_or_fetch(p, m, o)
  ------------------
  538|      6|                    __ATOMIC_RELEASE);
  539|       |
  540|       |    /*
  541|       |     * Update the reader index to be the prior qp.
  542|       |     * Note the use of __ATOMIC_RELEASE here is based on the corresponding use
  543|       |     * of __ATOMIC_ACQUIRE in get_hold_current_qp, as we want any publication
  544|       |     * of this value to be seen on the read side immediately after it happens
  545|       |     */
  546|      6|    ATOMIC_STORE_N(uint32_t, &lock->reader_idx, lock->current_alloc_idx,
  ------------------
  |  |  124|      6|#  define ATOMIC_STORE_N(t, p, v, o) __atomic_store_n(p, v, o)
  ------------------
  547|      6|                   __ATOMIC_RELEASE);
  548|       |
  549|       |    /* wake up any waiters */
  550|      6|    pthread_cond_signal(&lock->alloc_signal);
  551|      6|    pthread_mutex_unlock(&lock->alloc_lock);
  552|      6|    return &lock->qp_group[current_idx];
  553|      6|}
threads_pthread.c:retire_qp:
  556|      6|{
  557|      6|    pthread_mutex_lock(&lock->alloc_lock);
  558|      6|    lock->writers_alloced--;
  559|      6|    pthread_cond_signal(&lock->alloc_signal);
  560|      6|    pthread_mutex_unlock(&lock->alloc_lock);
  561|      6|}
threads_pthread.c:allocate_new_qp_group:
  567|      2|{
  568|      2|    struct rcu_qp *new =
  569|      2|        OPENSSL_zalloc(sizeof(*new) * count);
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  570|       |
  571|      2|    lock->group_count = count;
  572|      2|    return new;
  573|      2|}

ossl_trace_cleanup:
  338|      2|{
  339|       |#ifndef OPENSSL_NO_TRACE
  340|       |    int category;
  341|       |    BIO *channel = NULL;
  342|       |    const char *prefix = NULL;
  343|       |    const char *suffix = NULL;
  344|       |
  345|       |    for (category = 0; category < OSSL_TRACE_CATEGORY_NUM; category++) {
  346|       |        /* We force the TRACE category to be treated last */
  347|       |        if (category == OSSL_TRACE_CATEGORY_TRACE)
  348|       |            continue;
  349|       |        set_trace_data(category, 0, &channel, &prefix, &suffix,
  350|       |                       trace_attach_cb, trace_detach_cb);
  351|       |    }
  352|       |    set_trace_data(OSSL_TRACE_CATEGORY_TRACE, 0, &channel,
  353|       |                   &prefix, &suffix,
  354|       |                   trace_attach_cb, trace_detach_cb);
  355|       |    CRYPTO_THREAD_lock_free(trace_lock);
  356|       |#endif
  357|      2|}
OSSL_trace_set_channel:
  360|      2|{
  361|       |#ifndef OPENSSL_NO_TRACE
  362|       |    if (category >= 0 && category < OSSL_TRACE_CATEGORY_NUM)
  363|       |        return set_trace_data(category, SIMPLE_CHANNEL, &channel, NULL, NULL,
  364|       |                              trace_attach_cb, trace_detach_cb);
  365|       |#endif
  366|      2|    return 0;
  367|      2|}

ossl_err_load_TS_strings:
   82|      2|{
   83|      2|# ifndef OPENSSL_NO_ERR
   84|      2|    if (ERR_reason_error_string(TS_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (84:9): [True: 2, False: 0]
  ------------------
   85|      2|        ERR_load_strings_const(TS_str_reasons);
   86|      2|# endif
   87|      2|    return 1;
   88|      2|}

ossl_err_load_UI_strings:
   41|      2|{
   42|      2|#ifndef OPENSSL_NO_ERR
   43|      2|    if (ERR_reason_error_string(UI_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (43:9): [True: 2, False: 0]
  ------------------
   44|      2|        ERR_load_strings_const(UI_str_reasons);
   45|      2|#endif
   46|      2|    return 1;
   47|      2|}

ossl_err_load_X509V3_strings:
  144|      2|{
  145|      2|#ifndef OPENSSL_NO_ERR
  146|      2|    if (ERR_reason_error_string(X509V3_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (146:9): [True: 2, False: 0]
  ------------------
  147|      2|        ERR_load_strings_const(X509V3_str_reasons);
  148|      2|#endif
  149|      2|    return 1;
  150|      2|}

ossl_err_load_X509_strings:
   92|      2|{
   93|      2|#ifndef OPENSSL_NO_ERR
   94|      2|    if (ERR_reason_error_string(X509_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (94:9): [True: 2, False: 0]
  ------------------
   95|      2|        ERR_load_strings_const(X509_str_reasons);
   96|      2|#endif
   97|      2|    return 1;
   98|      2|}

FuzzerInitialize:
   23|      2|{
   24|      2|    OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL);
  ------------------
  |  |  463|      2|# define OPENSSL_INIT_LOAD_CRYPTO_STRINGS    0x00000002L
  ------------------
   25|      2|    ERR_clear_error();
   26|       |
   27|      2|    return 1;
   28|      2|}
FuzzerTestOneInput:
   31|  3.05k|{
   32|  3.05k|    int success = 0;
   33|  3.05k|    size_t l1 = 0, l2 = 0, l3 = 0;
   34|  3.05k|    int s1 = 0, s3 = 0;
   35|  3.05k|    BN_CTX *ctx;
   36|  3.05k|    BIGNUM *b1;
   37|  3.05k|    BIGNUM *b2;
   38|  3.05k|    BIGNUM *b3;
   39|  3.05k|    BIGNUM *b4;
   40|  3.05k|    BIGNUM *b5;
   41|       |
   42|  3.05k|    b1 = BN_new();
   43|  3.05k|    b2 = BN_new();
   44|  3.05k|    b3 = BN_new();
   45|  3.05k|    b4 = BN_new();
   46|  3.05k|    b5 = BN_new();
   47|  3.05k|    ctx = BN_CTX_new();
   48|       |
   49|       |    /* Divide the input into three parts, using the values of the first two
   50|       |     * bytes to choose lengths, which generate b1, b2 and b3. Use three bits
   51|       |     * of the third byte to choose signs for the three numbers.
   52|       |     */
   53|  3.05k|    if (len > 2) {
  ------------------
  |  Branch (53:9): [True: 3.05k, False: 2]
  ------------------
   54|  3.05k|        len -= 3;
   55|  3.05k|        l1 = (buf[0] * len) / 255;
   56|  3.05k|        ++buf;
   57|  3.05k|        l2 = (buf[0] * (len - l1)) / 255;
   58|  3.05k|        ++buf;
   59|  3.05k|        l3 = len - l1 - l2;
   60|       |
   61|  3.05k|        s1 = buf[0] & 1;
   62|  3.05k|        s3 = buf[0] & 4;
   63|  3.05k|        ++buf;
   64|  3.05k|    }
   65|  3.05k|    OPENSSL_assert(BN_bin2bn(buf, l1, b1) == b1);
  ------------------
  |  |  434|  3.05k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (434:12): [True: 3.05k, False: 0]
  |  |  ------------------
  ------------------
   66|  3.05k|    BN_set_negative(b1, s1);
   67|  3.05k|    OPENSSL_assert(BN_bin2bn(buf + l1, l2, b2) == b2);
  ------------------
  |  |  434|  3.05k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (434:12): [True: 3.05k, False: 0]
  |  |  ------------------
  ------------------
   68|  3.05k|    OPENSSL_assert(BN_bin2bn(buf + l1 + l2, l3, b3) == b3);
  ------------------
  |  |  434|  3.05k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (434:12): [True: 3.05k, False: 0]
  |  |  ------------------
  ------------------
   69|  3.05k|    BN_set_negative(b3, s3);
   70|       |
   71|       |    /* mod 0 is undefined */
   72|  3.05k|    if (BN_is_zero(b3)) {
  ------------------
  |  Branch (72:9): [True: 36, False: 3.02k]
  ------------------
   73|     36|        success = 1;
   74|     36|        goto done;
   75|     36|    }
   76|       |
   77|  3.02k|    OPENSSL_assert(BN_mod_exp(b4, b1, b2, b3, ctx));
  ------------------
  |  |  434|  3.02k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (434:12): [True: 3.02k, False: 0]
  |  |  ------------------
  ------------------
   78|  3.02k|    OPENSSL_assert(BN_mod_exp_simple(b5, b1, b2, b3, ctx));
  ------------------
  |  |  434|  3.02k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (434:12): [True: 3.02k, False: 0]
  |  |  ------------------
  ------------------
   79|       |
   80|  3.02k|    success = BN_cmp(b4, b5) == 0;
   81|  3.02k|    if (!success) {
  ------------------
  |  Branch (81:9): [True: 0, False: 3.02k]
  ------------------
   82|      0|        BN_print_fp(stdout, b1);
   83|      0|        putchar('\n');
   84|      0|        BN_print_fp(stdout, b2);
   85|      0|        putchar('\n');
   86|      0|        BN_print_fp(stdout, b3);
   87|      0|        putchar('\n');
   88|      0|        BN_print_fp(stdout, b4);
   89|      0|        putchar('\n');
   90|      0|        BN_print_fp(stdout, b5);
   91|      0|        putchar('\n');
   92|      0|    }
   93|       |
   94|  3.05k| done:
   95|  3.05k|    OPENSSL_assert(success);
  ------------------
  |  |  434|  3.05k|    (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                   (void)((e) ? 0 : (OPENSSL_die("assertion failed: " #e, OPENSSL_FILE, OPENSSL_LINE), 1))
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  |  |  |  Branch (434:12): [True: 3.05k, False: 0]
  |  |  ------------------
  ------------------
   96|  3.05k|    BN_free(b1);
   97|  3.05k|    BN_free(b2);
   98|  3.05k|    BN_free(b3);
   99|  3.05k|    BN_free(b4);
  100|  3.05k|    BN_free(b5);
  101|  3.05k|    BN_CTX_free(ctx);
  102|  3.05k|    ERR_clear_error();
  103|       |
  104|  3.05k|    return 0;
  105|  3.02k|}

LLVMFuzzerInitialize:
   22|      2|{
   23|      2|    return FuzzerInitialize(argc, argv);
   24|      2|}
LLVMFuzzerTestOneInput:
   27|  3.05k|{
   28|  3.05k|    return FuzzerTestOneInput(buf, len);
   29|  3.05k|}

property.c:ossl_sa_ALGORITHM_new:
   27|      8|    { \
   28|      8|        return (SPARSE_ARRAY_OF(type) *)ossl_sa_new(); \
   29|      8|    } \
property.c:ossl_sa_ALGORITHM_doall_arg:
   56|      8|    { \
   57|      8|        ossl_sa_doall_arg((OPENSSL_SA *)sa, \
   58|      8|                          (void (*)(ossl_uintmax_t, void *, void *))leaf, arg); \
   59|      8|    } \
property.c:ossl_sa_ALGORITHM_free:
   32|      8|    { \
   33|      8|        ossl_sa_free((OPENSSL_SA *)sa); \
   34|      8|    } \

bio_lib.c:CRYPTO_FREE_REF:
  273|      2|static ossl_unused ossl_inline void CRYPTO_FREE_REF(CRYPTO_REF_COUNT *refcnt)                                  \
  274|      2|{
  275|      2|}

stack.c:safe_muldiv_int:
  322|      2|    {                                                                        \
  323|      2|        int e2 = 0;                                                          \
  324|      2|        type q, r, x, y;                                                     \
  325|      2|                                                                             \
  326|      2|        if (c == 0) {                                                        \
  ------------------
  |  Branch (326:13): [True: 0, False: 2]
  ------------------
  327|      0|            *err |= 1;                                                       \
  328|      0|            return a == 0 || b == 0 ? 0 : max;                               \
  ------------------
  |  Branch (328:20): [True: 0, False: 0]
  |  Branch (328:30): [True: 0, False: 0]
  ------------------
  329|      0|        }                                                                    \
  330|      2|        x = safe_mul_ ## type_name(a, b, &e2);                               \
  331|      2|        if (!e2)                                                             \
  ------------------
  |  Branch (331:13): [True: 2, False: 0]
  ------------------
  332|      2|            return safe_div_ ## type_name(x, c, err);                        \
  333|      2|        if (b > a) {                                                         \
  ------------------
  |  Branch (333:13): [True: 0, False: 0]
  ------------------
  334|      0|            x = b;                                                           \
  335|      0|            b = a;                                                           \
  336|      0|            a = x;                                                           \
  337|      0|        }                                                                    \
  338|      0|        q = safe_div_ ## type_name(a, c, err);                               \
  339|      0|        r = safe_mod_ ## type_name(a, c, err);                               \
  340|      0|        x = safe_mul_ ## type_name(r, b, err);                               \
  341|      0|        y = safe_mul_ ## type_name(q, b, err);                               \
  342|      0|        q = safe_div_ ## type_name(x, c, err);                               \
  343|      0|        return safe_add_ ## type_name(y, q, err);                            \
  344|      2|    }
stack.c:safe_mul_int:
  136|      2|    {                                                                        \
  137|      2|        type r;                                                              \
  138|      2|                                                                             \
  139|      2|        if (!__builtin_mul_overflow(a, b, &r))                               \
  ------------------
  |  Branch (139:13): [True: 2, False: 0]
  ------------------
  140|      2|            return r;                                                        \
  141|      2|        *err |= 1;                                                           \
  142|      0|        return (a < 0) ^ (b < 0) ? min : max;                                \
  ------------------
  |  Branch (142:16): [True: 0, False: 0]
  ------------------
  143|      2|    }
stack.c:safe_div_int:
  199|      2|    {                                                                        \
  200|      2|        if (b == 0) {                                                        \
  ------------------
  |  Branch (200:13): [True: 0, False: 2]
  ------------------
  201|      0|            *err |= 1;                                                       \
  202|      0|            return a < 0 ? min : max;                                        \
  ------------------
  |  Branch (202:20): [True: 0, False: 0]
  ------------------
  203|      0|        }                                                                    \
  204|      2|        if (b == -1 && a == min) {                                           \
  ------------------
  |  Branch (204:13): [True: 0, False: 2]
  |  Branch (204:24): [True: 0, False: 0]
  ------------------
  205|      0|            *err |= 1;                                                       \
  206|      0|            return max;                                                      \
  207|      0|        }                                                                    \
  208|      2|        return a / b;                                                        \
  209|      2|    }

err.c:do_err_strings_init_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
err.c:err_do_init_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
init.c:ossl_init_base_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
init.c:ossl_init_register_atexit_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
init.c:ossl_init_load_crypto_nodelete_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
init.c:ossl_init_load_crypto_strings_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
initthread.c:create_global_tevent_register_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
conf_mod.c:do_init_module_list_lock_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \
context.c:default_context_do_init_ossl_:
   73|      2|    {                                           \
   74|      2|        init##_ossl_ret_ = init();              \
   75|      2|    }                                           \

err.c:ERR_GET_LIB:
  242|  8.74k|{
  243|  8.74k|    if (ERR_SYSTEM_ERROR(errcode))
  ------------------
  |  |  239|  8.74k|# define ERR_SYSTEM_ERROR(errcode)      (((errcode) & ERR_SYSTEM_FLAG) != 0)
  |  |  ------------------
  |  |  |  |  218|  8.74k|# define ERR_SYSTEM_FLAG                ((unsigned int)INT_MAX + 1)
  |  |  ------------------
  |  |  |  Branch (239:41): [True: 0, False: 8.74k]
  |  |  ------------------
  ------------------
  244|      0|        return ERR_LIB_SYS;
  ------------------
  |  |   72|      0|# define ERR_LIB_SYS             2
  ------------------
  245|  8.74k|    return (errcode >> ERR_LIB_OFFSET) & ERR_LIB_MASK;
  ------------------
  |  |  226|  8.74k|# define ERR_LIB_OFFSET                 23L
  ------------------
                  return (errcode >> ERR_LIB_OFFSET) & ERR_LIB_MASK;
  ------------------
  |  |  227|  8.74k|# define ERR_LIB_MASK                   0xFF
  ------------------
  246|  8.74k|}
err.c:ERR_GET_REASON:
  256|     68|{
  257|     68|    if (ERR_SYSTEM_ERROR(errcode))
  ------------------
  |  |  239|     68|# define ERR_SYSTEM_ERROR(errcode)      (((errcode) & ERR_SYSTEM_FLAG) != 0)
  |  |  ------------------
  |  |  |  |  218|     68|# define ERR_SYSTEM_FLAG                ((unsigned int)INT_MAX + 1)
  |  |  ------------------
  |  |  |  Branch (239:41): [True: 0, False: 68]
  |  |  ------------------
  ------------------
  258|      0|        return errcode & ERR_SYSTEM_MASK;
  ------------------
  |  |  219|      0|# define ERR_SYSTEM_MASK                ((unsigned int)INT_MAX)
  ------------------
  259|     68|    return errcode & ERR_REASON_MASK;
  ------------------
  |  |  230|     68|# define ERR_REASON_MASK                0X7FFFFF
  ------------------
  260|     68|}

err.c:ossl_check_ERR_STRING_DATA_lh_type:
  196|  8.67k|    { \
  197|  8.67k|        return (OPENSSL_LHASH *)lh; \
  198|  8.67k|    } \
err.c:ossl_check_ERR_STRING_DATA_lh_hashfunc_type:
  206|      2|    { \
  207|      2|        return (OPENSSL_LH_HASHFUNC)hfn; \
  208|      2|    } \
err.c:ossl_check_ERR_STRING_DATA_lh_compfunc_type:
  201|      2|    { \
  202|      2|        return (OPENSSL_LH_COMPFUNC)cmp; \
  203|      2|    } \
err.c:lh_ERR_STRING_DATA_hash_thunk:
  160|  8.67k|    { \
  161|  8.67k|        unsigned long (*hfn_conv)(const type *) = (unsigned long (*)(const type *))hfn; \
  162|  8.67k|        return hfn_conv((const type *)data); \
  163|  8.67k|    } \
err.c:lh_ERR_STRING_DATA_comp_thunk:
  165|  5.88k|    { \
  166|  5.88k|        int (*cfn_conv)(const type *, const type *) = (int (*)(const type *, const type *))cfn; \
  167|  5.88k|        return cfn_conv((const type *)da, (const type *)db); \
  168|  5.88k|    } \
err.c:ossl_check_ERR_STRING_DATA_lh_plain_type:
  181|  8.53k|    { \
  182|  8.53k|        return ptr; \
  183|  8.53k|    } \
err.c:ossl_check_const_ERR_STRING_DATA_lh_plain_type:
  186|    136|    { \
  187|    136|        return ptr; \
  188|    136|    } \
store_register.c:lh_OSSL_STORE_LOADER_free:
  254|      2|    { \
  255|      2|        OPENSSL_LH_free((OPENSSL_LHASH *)lh); \
  256|      2|    } \
core_namemap.c:lh_NAMENUM_ENTRY_new:
  317|      2|    { \
  318|      2|        return (LHASH_OF(type) *)OPENSSL_LH_set_thunks(OPENSSL_LH_new((OPENSSL_LH_HASHFUNC)hfn, (OPENSSL_LH_COMPFUNC)cfn), \
  319|      2|                                lh_##type##_hfn_thunk, lh_##type##_cfn_thunk, \
  320|      2|                                lh_##type##_doall_thunk, \
  321|      2|                                lh_##type##_doall_arg_thunk); \
  322|      2|    } \
core_namemap.c:lh_NAMENUM_ENTRY_doall:
  311|      2|    { \
  312|      2|        OPENSSL_LH_doall((OPENSSL_LHASH *)lh, (OPENSSL_LH_DOALL_FUNC)doall); \
  313|      2|    } \
core_namemap.c:lh_NAMENUM_ENTRY_free:
  254|      2|    { \
  255|      2|        OPENSSL_LH_free((OPENSSL_LHASH *)lh); \
  256|      2|    } \
defn_cache.c:lh_PROPERTY_DEFN_ELEM_doall:
  311|      2|    { \
  312|      2|        OPENSSL_LH_doall((OPENSSL_LHASH *)lh, (OPENSSL_LH_DOALL_FUNC)doall); \
  313|      2|    } \
defn_cache.c:lh_PROPERTY_DEFN_ELEM_free:
  254|      2|    { \
  255|      2|        OPENSSL_LH_free((OPENSSL_LHASH *)lh); \
  256|      2|    } \
defn_cache.c:lh_PROPERTY_DEFN_ELEM_new:
  317|      2|    { \
  318|      2|        return (LHASH_OF(type) *)OPENSSL_LH_set_thunks(OPENSSL_LH_new((OPENSSL_LH_HASHFUNC)hfn, (OPENSSL_LH_COMPFUNC)cfn), \
  319|      2|                                lh_##type##_hfn_thunk, lh_##type##_cfn_thunk, \
  320|      2|                                lh_##type##_doall_thunk, \
  321|      2|                                lh_##type##_doall_arg_thunk); \
  322|      2|    } \
property_string.c:lh_PROPERTY_STRING_doall:
  311|      4|    { \
  312|      4|        OPENSSL_LH_doall((OPENSSL_LHASH *)lh, (OPENSSL_LH_DOALL_FUNC)doall); \
  313|      4|    } \
property_string.c:lh_PROPERTY_STRING_free:
  254|      4|    { \
  255|      4|        OPENSSL_LH_free((OPENSSL_LHASH *)lh); \
  256|      4|    } \
property_string.c:lh_PROPERTY_STRING_new:
  317|      4|    { \
  318|      4|        return (LHASH_OF(type) *)OPENSSL_LH_set_thunks(OPENSSL_LH_new((OPENSSL_LH_HASHFUNC)hfn, (OPENSSL_LH_COMPFUNC)cfn), \
  319|      4|                                lh_##type##_hfn_thunk, lh_##type##_cfn_thunk, \
  320|      4|                                lh_##type##_doall_thunk, \
  321|      4|                                lh_##type##_doall_arg_thunk); \
  322|      4|    } \
property_string.c:lh_PROPERTY_STRING_hfn_thunk:
  243|     48|    { \
  244|     48|        unsigned long (*hfn_conv)(const type *) = (unsigned long (*)(const type *))hfn; \
  245|     48|        return hfn_conv((const type *)data); \
  246|     48|    } \
property_string.c:lh_PROPERTY_STRING_doall_thunk:
  299|     16|    { \
  300|     16|        void (*doall_conv)(type *) = (void (*)(type *))doall; \
  301|     16|        doall_conv((type *)node); \
  302|     16|    } \
property_string.c:lh_PROPERTY_STRING_retrieve:
  274|     32|    { \
  275|     32|        return (type *)OPENSSL_LH_retrieve((OPENSSL_LHASH *)lh, d); \
  276|     32|    } \
property_string.c:lh_PROPERTY_STRING_insert:
  264|     16|    { \
  265|     16|        return (type *)OPENSSL_LH_insert((OPENSSL_LHASH *)lh, d); \
  266|     16|    } \
property_string.c:lh_PROPERTY_STRING_error:
  279|     16|    { \
  280|     16|        return OPENSSL_LH_error((OPENSSL_LHASH *)lh); \
  281|     16|    } \
decoder_pkey.c:lh_DECODER_CACHE_ENTRY_new:
  317|      2|    { \
  318|      2|        return (LHASH_OF(type) *)OPENSSL_LH_set_thunks(OPENSSL_LH_new((OPENSSL_LH_HASHFUNC)hfn, (OPENSSL_LH_COMPFUNC)cfn), \
  319|      2|                                lh_##type##_hfn_thunk, lh_##type##_cfn_thunk, \
  320|      2|                                lh_##type##_doall_thunk, \
  321|      2|                                lh_##type##_doall_arg_thunk); \
  322|      2|    } \
decoder_pkey.c:lh_DECODER_CACHE_ENTRY_doall:
  311|      2|    { \
  312|      2|        OPENSSL_LH_doall((OPENSSL_LHASH *)lh, (OPENSSL_LH_DOALL_FUNC)doall); \
  313|      2|    } \
decoder_pkey.c:lh_DECODER_CACHE_ENTRY_free:
  254|      2|    { \
  255|      2|        OPENSSL_LH_free((OPENSSL_LHASH *)lh); \
  256|      2|    } \

initthread.c:sk_THREAD_EVENT_HANDLER_PTR_new_null:
   82|      2|    { \
   83|      2|        return (STACK_OF(t1) *)OPENSSL_sk_new_null(); \
   84|      2|    } \
initthread.c:sk_THREAD_EVENT_HANDLER_PTR_free:
   94|      2|    { \
   95|      2|        OPENSSL_sk_free((OPENSSL_STACK *)sk); \
   96|      2|    } \
initthread.c:sk_THREAD_EVENT_HANDLER_PTR_push:
  111|      2|    { \
  112|      2|        return OPENSSL_sk_push((OPENSSL_STACK *)sk, (const void *)ptr); \
  113|      2|    } \
initthread.c:sk_THREAD_EVENT_HANDLER_PTR_num:
   70|      4|    { \
   71|      4|        return OPENSSL_sk_num((const OPENSSL_STACK *)sk); \
   72|      4|    } \
initthread.c:sk_THREAD_EVENT_HANDLER_PTR_value:
   74|      2|    { \
   75|      2|        return (t2 *)OPENSSL_sk_value((const OPENSSL_STACK *)sk, idx); \
   76|      2|    } \
initthread.c:sk_THREAD_EVENT_HANDLER_PTR_delete:
  102|      2|    { \
  103|      2|        return (t2 *)OPENSSL_sk_delete((OPENSSL_STACK *)sk, i); \
  104|      2|    } \
conf_mod.c:sk_CONF_IMODULE_free:
   94|      4|    { \
   95|      4|        OPENSSL_sk_free((OPENSSL_STACK *)sk); \
   96|      4|    } \
conf_mod.c:sk_CONF_MODULE_dup:
  159|      2|    { \
  160|      2|        return (STACK_OF(t1) *)OPENSSL_sk_dup((const OPENSSL_STACK *)sk); \
  161|      2|    } \
conf_mod.c:sk_CONF_MODULE_new_null:
   82|      2|    { \
   83|      2|        return (STACK_OF(t1) *)OPENSSL_sk_new_null(); \
   84|      2|    } \
conf_mod.c:sk_CONF_MODULE_num:
   70|      4|    { \
   71|      4|        return OPENSSL_sk_num((const OPENSSL_STACK *)sk); \
   72|      4|    } \
conf_mod.c:sk_CONF_MODULE_free:
   94|      6|    { \
   95|      6|        OPENSSL_sk_free((OPENSSL_STACK *)sk); \
   96|      6|    } \
conf_mod.c:sk_CONF_MODULE_pop_free:
  127|      2|    { \
  128|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
  129|      2|    } \
conf_mod.c:sk_CONF_IMODULE_num:
   70|      2|    { \
   71|      2|        return OPENSSL_sk_num((const OPENSSL_STACK *)sk); \
   72|      2|    } \
ex_data.c:sk_EX_CALLBACK_pop_free:
  127|     36|    { \
  128|     36|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
  129|     36|    } \
provider_conf.c:sk_OSSL_PROVIDER_pop_free:
  127|      2|    { \
  128|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
  129|      2|    } \
provider_core.c:sk_OSSL_PROVIDER_pop_free:
  127|      2|    { \
  128|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
  129|      2|    } \
provider_core.c:sk_OSSL_PROVIDER_CHILD_CB_pop_free:
  127|      2|    { \
  128|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
  129|      2|    } \
provider_core.c:sk_OSSL_PROVIDER_new:
   78|      2|    { \
   79|      2|        return (STACK_OF(t1) *)OPENSSL_sk_new((OPENSSL_sk_compfunc)compare); \
   80|      2|    } \
provider_core.c:sk_OSSL_PROVIDER_CHILD_CB_new_null:
   82|      2|    { \
   83|      2|        return (STACK_OF(t1) *)OPENSSL_sk_new_null(); \
   84|      2|    } \
obj_xref.c:sk_nid_triple_pop_free:
  127|      2|    { \
  128|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
  129|      2|    } \
obj_xref.c:sk_nid_triple_free:
   94|      2|    { \
   95|      2|        OPENSSL_sk_free((OPENSSL_STACK *)sk); \
   96|      2|    } \
property_string.c:ossl_check_OPENSSL_CSTRING_sk_type:
   48|     20|    { \
   49|     20|        return (OPENSSL_STACK *)sk; \
   50|     20|    } \
property_string.c:ossl_check_OPENSSL_CSTRING_type:
   40|     16|    { \
   41|     16|        return ptr; \
   42|     16|    } \
evp_pbe.c:sk_EVP_PBE_CTL_pop_free:
  127|      2|    { \
  128|      2|        OPENSSL_sk_pop_free((OPENSSL_STACK *)sk, (OPENSSL_sk_freefunc)freefunc); \
  129|      2|    } \
comp_methods.c:ossl_check_SSL_COMP_compfunc_type:
   52|      2|    { \
   53|      2|        return (OPENSSL_sk_compfunc)cmp; \
   54|      2|    } \
comp_methods.c:ossl_check_SSL_COMP_sk_type:
   48|      2|    { \
   49|      2|        return (OPENSSL_STACK *)sk; \
   50|      2|    } \
comp_methods.c:ossl_check_SSL_COMP_freefunc_type:
   60|      2|    { \
   61|      2|        return (OPENSSL_sk_freefunc)fr; \
   62|      2|    }

ossl_err_load_PROV_strings:
  230|      2|{
  231|      2|#ifndef OPENSSL_NO_ERR
  232|      2|    if (ERR_reason_error_string(PROV_str_reasons[0].error) == NULL)
  ------------------
  |  Branch (232:9): [True: 2, False: 0]
  ------------------
  233|      2|        ERR_load_strings_const(PROV_str_reasons);
  234|      2|#endif
  235|      2|    return 1;
  236|      2|}

ossl_prov_drbg_nonce_ctx_new:
  282|      2|{
  283|      2|    PROV_DRBG_NONCE_GLOBAL *dngbl = OPENSSL_zalloc(sizeof(*dngbl));
  ------------------
  |  |  104|      2|        CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_zalloc(num, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  284|       |
  285|      2|    if (dngbl == NULL)
  ------------------
  |  Branch (285:9): [True: 0, False: 2]
  ------------------
  286|      0|        return NULL;
  287|       |
  288|      2|    dngbl->rand_nonce_lock = CRYPTO_THREAD_lock_new();
  289|      2|    if (dngbl->rand_nonce_lock == NULL) {
  ------------------
  |  Branch (289:9): [True: 0, False: 2]
  ------------------
  290|      0|        OPENSSL_free(dngbl);
  ------------------
  |  |  115|      0|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      0|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      0|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  291|      0|        return NULL;
  292|      0|    }
  293|       |
  294|      2|    return dngbl;
  295|      2|}
ossl_prov_drbg_nonce_ctx_free:
  298|      2|{
  299|      2|    PROV_DRBG_NONCE_GLOBAL *dngbl = vdngbl;
  300|       |
  301|      2|    if (dngbl == NULL)
  ------------------
  |  Branch (301:9): [True: 0, False: 2]
  ------------------
  302|      0|        return;
  303|       |
  304|      2|    CRYPTO_THREAD_lock_free(dngbl->rand_nonce_lock);
  305|       |
  306|      2|    OPENSSL_free(dngbl);
  ------------------
  |  |  115|      2|        CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  291|      2|#   define OPENSSL_FILE __FILE__
  |  |  ------------------
  |  |                       CRYPTO_free(addr, OPENSSL_FILE, OPENSSL_LINE)
  |  |  ------------------
  |  |  |  |  292|      2|#   define OPENSSL_LINE __LINE__
  |  |  ------------------
  ------------------
  307|      2|}

