diff --git a/include/picotls.h b/include/picotls.h
index 94eb844..ea5c15e 100644
--- a/include/picotls.h
+++ b/include/picotls.h
@@ -341,7 +341,7 @@
     const struct st_ptls_aead_algorithm_t *algo;
     /* field above this line must not be altered by the crypto binding */
     void (*dispose_crypto)(struct st_ptls_aead_context_t *ctx);
-    void (*do_xor_iv)(struct st_ptls_aead_context_t *ctx, const void * bytes, size_t len);
+    void (*do_xor_iv)(struct st_ptls_aead_context_t *ctx, const void *bytes, size_t len);
     void (*do_encrypt_init)(struct st_ptls_aead_context_t *ctx, uint64_t seq, const void *aad, size_t aadlen);
     size_t (*do_encrypt_update)(struct st_ptls_aead_context_t *ctx, void *output, const void *input, size_t inlen);
     size_t (*do_encrypt_final)(struct st_ptls_aead_context_t *ctx, void *output);
diff --git a/include/picotls/asn1.h b/include/picotls/asn1.h
index 5314c58..e03ce0f 100644
--- a/include/picotls/asn1.h
+++ b/include/picotls/asn1.h
@@ -1,18 +1,18 @@
 /*
-* Copyright (c) 2017 Christian Huitema <huitema@huitema.net>
-*
-* Permission to use, copy, modify, and distribute this software for any
-* purpose with or without fee is hereby granted, provided that the above
-* copyright notice and this permission notice appear in all copies.
-*
-* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
-* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
-* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
-* ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
-* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
-* ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
-* OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
-*/
+ * Copyright (c) 2017 Christian Huitema <huitema@huitema.net>
+ *
+ * Permission to use, copy, modify, and distribute this software for any
+ * purpose with or without fee is hereby granted, provided that the above
+ * copyright notice and this permission notice appear in all copies.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
+ * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
+ * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
+ * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
+ * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
+ * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
+ * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
+ */
 
 #ifndef PTLS_ASN1_H
 #define PTLS_ASN1_H
@@ -20,19 +20,19 @@
 // #include "picotls/minicrypto.h"
 
 /*
-* The ASN.1 functions take a "log context" parameter of type ptls_minicrypto_log_ctx_t.
-*
-* The log function in that code can be instantiated for example as:
-*
-* void log_printf(void * ctx, const char * format, ...)
-* {
-*     va_list argptr;
-*     va_start(argptr, format);
-*     vfprintf(stderr, format, argptr);
-* }
-*
-* Using definitions from <stdio.h> and <stdarg.h>
-*/
+ * The ASN.1 functions take a "log context" parameter of type ptls_minicrypto_log_ctx_t.
+ *
+ * The log function in that code can be instantiated for example as:
+ *
+ * void log_printf(void * ctx, const char * format, ...)
+ * {
+ *     va_list argptr;
+ *     va_start(argptr, format);
+ *     vfprintf(stderr, format, argptr);
+ * }
+ *
+ * Using definitions from <stdio.h> and <stdarg.h>
+ */
 
 typedef struct st_ptls_minicrypto_log_ctx_t {
     void *ctx;
diff --git a/include/picotls/pembase64.h b/include/picotls/pembase64.h
index 1b59910..9ffdd6b 100644
--- a/include/picotls/pembase64.h
+++ b/include/picotls/pembase64.h
@@ -1,25 +1,25 @@
 /*
-* Copyright (c) 2017 Christian Huitema <huitema@huitema.net>
-*
-* Permission to use, copy, modify, and distribute this software for any
-* purpose with or without fee is hereby granted, provided that the above
-* copyright notice and this permission notice appear in all copies.
-*
-* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
-* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
-* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
-* ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
-* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
-* ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
-* OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
-*/
+ * Copyright (c) 2017 Christian Huitema <huitema@huitema.net>
+ *
+ * Permission to use, copy, modify, and distribute this software for any
+ * purpose with or without fee is hereby granted, provided that the above
+ * copyright notice and this permission notice appear in all copies.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
+ * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
+ * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
+ * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
+ * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
+ * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
+ * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
+ */
 
 #ifndef PTLS_PEMBASE64_H
 #define PTLS_PEMBASE64_H
 
 /*
-* Base64 functions used in encoding and decoding of PEM files
-*/
+ * Base64 functions used in encoding and decoding of PEM files
+ */
 
 #define PTLS_BASE64_DECODE_DONE 0
 #define PTLS_BASE64_DECODE_IN_PROGRESS 1
diff --git a/lib/cifra/random.c b/lib/cifra/random.c
index 9d26634..17991be 100644
--- a/lib/cifra/random.c
+++ b/lib/cifra/random.c
@@ -37,8 +37,8 @@
 #include <stdio.h>
 #ifdef _WINDOWS
 #ifdef _WINDOWS_XP
- /* The modern BCrypt API is only available on Windows Vista and later versions.
-  * If compiling on Windows XP, we need to use the olded "wincrypt" API */
+/* The modern BCrypt API is only available on Windows Vista and later versions.
+ * If compiling on Windows XP, we need to use the olded "wincrypt" API */
 #include <wincrypt.h>
 
 static void read_entropy(uint8_t *entropy, size_t size)
@@ -57,13 +57,13 @@
     }
 }
 #else
- /* The old "Wincrypt" API requires access to default security containers.
-  * This can cause access control errors on some systems. We prefer
-  * to use the modern BCrypt API when available */
+/* The old "Wincrypt" API requires access to default security containers.
+ * This can cause access control errors on some systems. We prefer
+ * to use the modern BCrypt API when available */
 #include <bcrypt.h>
 
- static void read_entropy(uint8_t *entropy, size_t size)
- {
+static void read_entropy(uint8_t *entropy, size_t size)
+{
     NTSTATUS nts = 0;
     BCRYPT_ALG_HANDLE hAlgorithm = 0;
 
diff --git a/lib/minicrypto-pem.c b/lib/minicrypto-pem.c
index 9d6c499..d9e8dc5 100644
--- a/lib/minicrypto-pem.c
+++ b/lib/minicrypto-pem.c
@@ -105,13 +105,13 @@
             byte_index += oid_length;
         }
     }
-  
+
     if (*decode_error == 0) {
         /* get parameters, ANY */
         if (log_ctx != NULL) {
             log_ctx->fn(log_ctx->ctx, "      Parameters:\n");
         }
-      
+
         if (last_byte1 <= byte_index) {
             pkey->parameters_index = 0;
             pkey->parameters_length = 0;
diff --git a/lib/openssl.c b/lib/openssl.c
index 2663df7..c63ba86 100644
--- a/lib/openssl.c
+++ b/lib/openssl.c
@@ -1242,8 +1242,7 @@
         if (server_name != NULL) {
             if (ptls_server_name_is_ipaddr(server_name)) {
                 X509_VERIFY_PARAM_set1_ip_asc(params, server_name);
-            }
-            else {
+            } else {
                 X509_VERIFY_PARAM_set1_host(params, server_name, 0);
                 X509_VERIFY_PARAM_set_hostflags(params, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS);
             }
@@ -1382,7 +1381,7 @@
 {
     ptls_openssl_raw_pubkey_verify_certificate_t *self = (ptls_openssl_raw_pubkey_verify_certificate_t *)_self;
     int ret = PTLS_ALERT_BAD_CERTIFICATE;
-    ptls_iovec_t expected_pubkey = { 0 };
+    ptls_iovec_t expected_pubkey = {0};
 
     assert(num_certs != 0);
 
diff --git a/lib/pembase64.c b/lib/pembase64.c
index 70197ef..94246b2 100644
--- a/lib/pembase64.c
+++ b/lib/pembase64.c
@@ -1,18 +1,18 @@
 /*
-* Copyright (c) 2016 Christian Huitema <huitema@huitema.net>
-*
-* Permission to use, copy, modify, and distribute this software for any
-* purpose with or without fee is hereby granted, provided that the above
-* copyright notice and this permission notice appear in all copies.
-*
-* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
-* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
-* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
-* ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
-* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
-* ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
-* OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
-*/
+ * Copyright (c) 2016 Christian Huitema <huitema@huitema.net>
+ *
+ * Permission to use, copy, modify, and distribute this software for any
+ * purpose with or without fee is hereby granted, provided that the above
+ * copyright notice and this permission notice appear in all copies.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
+ * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
+ * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
+ * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
+ * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
+ * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
+ * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
+ */
 
 /*
  * Manage Base64 encoding.
diff --git a/lib/picotls.c b/lib/picotls.c
index aef5530..8ea30b6 100644
--- a/lib/picotls.c
+++ b/lib/picotls.c
@@ -4013,21 +4013,21 @@
     }
 
     /* send ServerHello */
-    EMIT_SERVER_HELLO(tls->key_schedule,
-                      { tls->ctx->random_bytes(emitter->buf->base + emitter->buf->off, PTLS_HELLO_RANDOM_SIZE); },
-                      {
-                          ptls_buffer_t *sendbuf = emitter->buf;
-                          if (mode != HANDSHAKE_MODE_PSK) {
-                              buffer_push_extension(sendbuf, PTLS_EXTENSION_TYPE_KEY_SHARE, {
-                                  ptls_buffer_push16(sendbuf, key_share.algorithm->id);
-                                  ptls_buffer_push_block(sendbuf, 2, { ptls_buffer_pushv(sendbuf, pubkey.base, pubkey.len); });
-                              });
-                          }
-                          if (mode != HANDSHAKE_MODE_FULL) {
-                              buffer_push_extension(sendbuf, PTLS_EXTENSION_TYPE_PRE_SHARED_KEY,
-                                                    { ptls_buffer_push16(sendbuf, (uint16_t)psk_index); });
-                          }
-                      });
+    EMIT_SERVER_HELLO(
+        tls->key_schedule, { tls->ctx->random_bytes(emitter->buf->base + emitter->buf->off, PTLS_HELLO_RANDOM_SIZE); },
+        {
+            ptls_buffer_t *sendbuf = emitter->buf;
+            if (mode != HANDSHAKE_MODE_PSK) {
+                buffer_push_extension(sendbuf, PTLS_EXTENSION_TYPE_KEY_SHARE, {
+                    ptls_buffer_push16(sendbuf, key_share.algorithm->id);
+                    ptls_buffer_push_block(sendbuf, 2, { ptls_buffer_pushv(sendbuf, pubkey.base, pubkey.len); });
+                });
+            }
+            if (mode != HANDSHAKE_MODE_FULL) {
+                buffer_push_extension(sendbuf, PTLS_EXTENSION_TYPE_PRE_SHARED_KEY,
+                                      { ptls_buffer_push16(sendbuf, (uint16_t)psk_index); });
+            }
+        });
     if ((ret = push_change_cipher_spec(tls, emitter)) != 0)
         goto Exit;
 
diff --git a/lib/ptlsbcrypt.c b/lib/ptlsbcrypt.c
index 45f8803..92e26fd 100644
--- a/lib/ptlsbcrypt.c
+++ b/lib/ptlsbcrypt.c
@@ -427,8 +427,8 @@
     return cbResult;
 }
 
-void ptls_bcrypt_do_encrypt(ptls_aead_context_t *ctx, void *output, const void *input, size_t inlen, uint64_t seq,
-                                  const void *aad, size_t aadlen, ptls_aead_supplementary_encryption_t *supp)
+void ptls_bcrypt_do_encrypt(ptls_aead_context_t *ctx, void *output, const void *input, size_t inlen, uint64_t seq, const void *aad,
+                            size_t aadlen, ptls_aead_supplementary_encryption_t *supp)
 {
     size_t after_update;
 
