Allow compile-time alternate to mbedtls_zeroize()

Add a new macro MBEDTLS_UTILS_ZEROIZE that allows users to configure
mbedtls_zeroize() to an alternative definition when defined. If the
macro is not defined, then mbed TLS will use the default definition of
the function.
This commit is contained in:
Andres Amaya Garcia 2017-10-25 09:51:14 +01:00 committed by Andres Amaya Garcia
parent e32df087fb
commit b1262a3bdb
2 changed files with 16 additions and 0 deletions

View file

@ -19,10 +19,17 @@
* This file is part of mbed TLS (https://tls.mbed.org)
*/
#if !defined(MBEDTLS_CONFIG_FILE)
#include "mbedtls/config.h"
#else
#include MBEDTLS_CONFIG_FILE
#endif
#include "mbedtls/utils.h"
#include <stddef.h>
#if !defined(MBEDTLS_UTILS_ZEROIZE_ALT)
/* This implementation should never be optimized out by the compiler */
void mbedtls_zeroize( void *buf, size_t len )
{
@ -31,3 +38,4 @@ void mbedtls_zeroize( void *buf, size_t len )
while( len-- )
*p++ = 0;
}
#endif /* MBEDTLS_UTILS_ZEROIZE_ALT */