leak-detective: Add whitelist entries for AWS-LC

AWS-LC (and likely BoringSSL) uses thread specific data to store internal
library state which gets freed via a registered destructor when the thread
terminates. If this thread happens to be the main thread, which runs the
leak-detective evaluation, the detective won't observe the corresponding free
of the related memory and erroneously reports it as a leak.

The two places this happens are:
- `RAND_bytes` for storing internal RNG state.
- `ERR_put_error` for storing the per-thread OpenSSL error queue.

References strongswan/strongswan#1907
Closes strongswan/strongswan#2147
This commit is contained in:
Gerardo Ravago
2024-03-07 15:06:40 +01:00
committed by Tobias Brunner
parent 44e241fccc
commit 8237968c2c
+3
View File
@@ -632,6 +632,9 @@ static char *whitelist[] = {
"CRYPTO_get_ex_new_index",
/* OpenSSL libssl */
"SSL_COMP_get_compression_methods",
/* AWS-LC */
"RAND_bytes",
"ERR_put_error",
/* NSPR */
"PR_CallOnce",
/* libapr */