Some examples...
Compare these two blocks of assignments and memcpy calls:
https://github.com/trustcrypto/libraries/blob/5bd1f8eb15eb04...
https://github.com/trustcrypto/libraries/blob/5bd1f8eb15eb04...
Yes, they are as identical as they appear. The only differences (other than a couple of lines commented out in one) are the use of 'data' in the first and 'large_resp_buffer+offset' in the second, along with some arbitrary whitespace differences. (The first uses spaces around the + operators, the second does not.) And all the hard coded numbers! What do they mean?
Or this block of code that appears to be a limited version of a decimal number formatter:
https://github.com/trustcrypto/libraries/blob/5bd1f8eb15eb04...
Or this code that keeps checking the same flags over and over again instead of combining the tests:
https://github.com/trustcrypto/libraries/blob/5bd1f8eb15eb04...
(Scroll horizontally to see all the repeated tests!)
Or this code with the same logic repeated 24 times:
https://github.com/trustcrypto/libraries/blob/5bd1f8eb15eb04...
The next function after that one also has 24 copies of duplicate logic.
Well, the logic isn't entirely duplicated. The individual cases call functions like onlykey_eeget_urllen1, onlykey_eeget_urllen2, ... onlykey_eeget_urllen24, and onlykey_eeset_urllen1, onlykey_eeset_urllen2, ... onlykey_eeset_urllen24. Here are those functions:
https://github.com/trustcrypto/libraries/blob/527113dfeeb20e...
Yes, they are all identical except for the different constants each one uses:
https://github.com/trustcrypto/libraries/blob/527113dfeeb20e...
This pattern of "24 copies of the same logic with different constants" occurs all through the code. Look through okeeprom.h/cpp for several other examples.
None of this inspires confidence that the code can be trusted.