From 4aef687fcff7d0b4a6f2942a5b21c97f8da33097 Mon Sep 17 00:00:00 2001 From: Adam Langley Date: Mon, 29 Mar 2021 12:13:17 -0700 Subject: [PATCH] Zero out FIPS counters. MSAN doesn't like the counters starting at whatever value malloc found to be free. Change-Id: I0968e61e0025db35b82291fde5d1e193aef77c1e Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/46444 Commit-Queue: Adam Langley Commit-Queue: David Benjamin Reviewed-by: David Benjamin --- crypto/fipsmodule/self_check/fips.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/crypto/fipsmodule/self_check/fips.c b/crypto/fipsmodule/self_check/fips.c index 09fffddc0..d55c493cb 100644 --- a/crypto/fipsmodule/self_check/fips.c +++ b/crypto/fipsmodule/self_check/fips.c @@ -52,10 +52,13 @@ void boringssl_fips_inc_counter(enum fips_counter_t counter) { size_t *array = CRYPTO_get_thread_local(OPENSSL_THREAD_LOCAL_FIPS_COUNTERS); if (!array) { - array = OPENSSL_malloc(sizeof(size_t) * (fips_counter_max + 1)); + const size_t num_bytes = sizeof(size_t) * (fips_counter_max + 1); + array = OPENSSL_malloc(num_bytes); if (!array) { return; } + + OPENSSL_memset(array, 0, num_bytes); if (!CRYPTO_set_thread_local(OPENSSL_THREAD_LOCAL_FIPS_COUNTERS, array, OPENSSL_free)) { // |OPENSSL_free| has already been called by |CRYPTO_set_thread_local|.