From 13a5a906e941b147d9b214a91d03d9ee356d723e Mon Sep 17 00:00:00 2001 From: Martin Willi Date: Mon, 13 Apr 2015 17:12:49 +0200 Subject: [PATCH] gcrypt: Explicitly initialize RNG backend to allocate static data The libgcrypt RNG implementation uses static buffer allocation which it does not free. There is no symbol we can catch in leak-detective, hence we explicitly initialize the RNG during the whitelisted gcrypt_plugin_create() function. --- src/libstrongswan/plugins/gcrypt/gcrypt_plugin.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/libstrongswan/plugins/gcrypt/gcrypt_plugin.c b/src/libstrongswan/plugins/gcrypt/gcrypt_plugin.c index 480c083c0..04f1f43ef 100644 --- a/src/libstrongswan/plugins/gcrypt/gcrypt_plugin.c +++ b/src/libstrongswan/plugins/gcrypt/gcrypt_plugin.c @@ -158,6 +158,9 @@ plugin_t *gcrypt_plugin_create() } gcry_control(GCRYCTL_INITIALIZATION_FINISHED, 0); + /* initialize static allocations we want to exclude from leak-detective */ + gcry_create_nonce(NULL, 0); + INIT(this, .public = { .plugin = {