security(crypto): enforce context-managed key isolation with explicit overwrite sweep - #734
Open
abdullahilateefat03-boop wants to merge 1 commit into
Conversation
… overwrite sweep - Remove duplicate SigningError class definition that silently shadowed the canonical exception type defined near the other exception classes. - Fix SecureKeyHandle._do_wipe to call _munlock_buffer (respecting the _locked flag set by _mlock_buffer) instead of the legacy _unlock_memory helper that bypassed lock-state tracking. Unlock now always runs AFTER the zero-wipe, preventing the OS from evicting live key material to swap during the cleanup window. Adds audit log entry on scope close, matching SecureSessionCredentials and SecureVariableWrapper behavior. - Fix _sign_internal transient copy wipe: replace _wipe_bytes_view (which zeroed only a copy-of-a-copy via from_buffer_copy) with _wipe_bytes_object (which uses ctypes.memset on id(obj)+offset to overwrite the CPython bytes object internal data buffer in-place). This closes the window where the transient key_bytes bytes object remained readable in heap memory after the signing routine returned. Addresses: memory-dump extraction vulnerability where active private signing key material lingered in process memory after transaction signing completed.
|
@abdullahilateefat03-boop Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes #615
Remove duplicate SigningError class definition that silently shadowed the canonical exception type defined near the other exception classes.
Fix SecureKeyHandle._do_wipe to call _munlock_buffer (respecting the _locked flag set by _mlock_buffer) instead of the legacy _unlock_memory helper that bypassed lock-state tracking. Unlock now always runs AFTER the zero-wipe, preventing the OS from evicting live key material to swap during the cleanup window. Adds audit log entry on scope close, matching SecureSessionCredentials and SecureVariableWrapper behavior.
Fix _sign_internal transient copy wipe: replace _wipe_bytes_view (which zeroed only a copy-of-a-copy via from_buffer_copy) with _wipe_bytes_object (which uses ctypes.memset on id(obj)+offset to overwrite the CPython bytes object internal data buffer in-place). This closes the window where the transient key_bytes bytes object remained readable in heap memory after the signing routine returned.
Addresses: memory-dump extraction vulnerability where active private signing key material lingered in process memory after transaction signing completed.