I eyeballed the patch. Looks mechanical and fine. One thing stood out, but it's from the existing code:
diff --git a/contrib/pgcrypto/crypt-sha.c b/contrib/pgcrypto/crypt-sha.c index 8191ba02b23..eab86f8206c 100644 --- a/contrib/pgcrypto/crypt-sha.c +++ b/contrib/pgcrypto/crypt-sha.c @@ -477,7 +477,7 @@ px_crypt_shacrypt(const char *pw, const char *salt, char *passwd, unsigned dstle memcpy(cp, sha_buf_tmp, block); /* Make sure we don't leave something important behind */ - px_memset(&sha_buf_tmp, 0, sizeof sha_buf); + explicit_bzero(&sha_buf_tmp, sizeof sha_buf); /*- * 21. Repeat a loop according to the number specified in the rounds=<N> That's sha_buf in the sizeof but we're zeroing out sha_buf_tmp. They're both of length PX_SHACRYPT_DIGEST_MAX_LEN so the result is the same. It just reads weird. Might as well fix that now too if going to touch that line. Regards, -- Sehrope Sarkuni Founder & CEO | JackDB, Inc. | https://www.jackdb.com/
