4 ms·
I don't know if it's still true in 2021 but it used to be kind of difficult to valgrind C and C++ code that linked with OpenSSL since it did some tricks that co
by aninteger 6y ago
I don't know if it's still true in 2021 but it used to be kind of difficult to valgrind C and C++ code that linked with OpenSSL since it did some tricks that confused valgrind. You would usually have to recompile OpenSSL with a special preprocessor flag (-DPURIFY).
This was one of the advantages of just linking with LibreSSL on Linux.
While I don't test my software directly on OpenBSD, I do test it on both Debian stable and VoidLinux and using valgrind on Debian used to cause some pain.
- belgesel 6y agoI believe it is still true. OpenSSL uses dirty stack bytes for randomness and it causes valgrind to warn for invalid access.