leak-detective: Add whitelist entries for AWS-LC
AWS-LC (and likely BoringSSL) uses thread specific data to store internal library state which gets freed via a registered destructor when the thread terminates. If this thread happens to be the main thread, which runs the leak-detective evaluation, the detective won't observe the corresponding free of the related memory and erroneously reports it as a leak. The two places this happens are: - `RAND_bytes` for storing internal RNG state. - `ERR_put_error` for storing the per-thread OpenSSL error queue. References strongswan/strongswan#1907 Closes strongswan/strongswan#2147
This commit is contained in:
committed by
Tobias Brunner
parent
44e241fccc
commit
8237968c2c
@@ -632,6 +632,9 @@ static char *whitelist[] = {
|
|||||||
"CRYPTO_get_ex_new_index",
|
"CRYPTO_get_ex_new_index",
|
||||||
/* OpenSSL libssl */
|
/* OpenSSL libssl */
|
||||||
"SSL_COMP_get_compression_methods",
|
"SSL_COMP_get_compression_methods",
|
||||||
|
/* AWS-LC */
|
||||||
|
"RAND_bytes",
|
||||||
|
"ERR_put_error",
|
||||||
/* NSPR */
|
/* NSPR */
|
||||||
"PR_CallOnce",
|
"PR_CallOnce",
|
||||||
/* libapr */
|
/* libapr */
|
||||||
|
|||||||
Reference in New Issue
Block a user