mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
[tls] Always use zfree() rather than free()
TLS currently uses free() instead of zfree() where the memory being freed contains no secrets. The cost of using zfree() everywhere is negligible (no code size increase, and used only in non-fast-path operations), and avoids the need to reason about whether or not the memory contains secrets. Switch to using zfree() unconditionally throughout the TLS code. Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
+4
-4
@@ -363,7 +363,7 @@ static void free_tls ( struct refcnt *refcnt ) {
|
||||
/* Free dynamically-allocated resources */
|
||||
zfree ( tls->new_ticket.data );
|
||||
tls_clear_digest ( tls );
|
||||
free ( tls->verify.dynamic );
|
||||
zfree ( tls->verify.dynamic );
|
||||
tls_clear_cipher ( tls, &tls->tx.cipherspec );
|
||||
tls_clear_cipher ( tls, &tls->rx.cipherspec );
|
||||
list_for_each_entry_safe ( iobuf, tmp, &tls->rx.data, list ) {
|
||||
@@ -638,7 +638,7 @@ static int tls_set_verify_len ( struct tls_connection *tls,
|
||||
void *dynamic;
|
||||
|
||||
/* Free any existing dynamically allocated storage */
|
||||
free ( verify->dynamic );
|
||||
zfree ( verify->dynamic );
|
||||
memset ( verify, 0, sizeof ( *verify ) );
|
||||
|
||||
/* Allocate dynamic storage */
|
||||
@@ -2227,7 +2227,7 @@ static int tls_send_client_key_exchange ( struct tls_connection *tls ) {
|
||||
err_alloc:
|
||||
err_size:
|
||||
err_encrypt:
|
||||
free ( builder.data );
|
||||
zfree ( builder.data );
|
||||
return rc;
|
||||
}
|
||||
|
||||
@@ -2324,7 +2324,7 @@ static int tls_send_certificate_verify ( struct tls_connection *tls ) {
|
||||
err_sig_hash:
|
||||
err_cert:
|
||||
err_chain:
|
||||
free ( builder.data );
|
||||
zfree ( builder.data );
|
||||
return rc;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user