Skip to content

security(crypto): enforce context-managed key isolation with explicit overwrite sweep - #734

Open
abdullahilateefat03-boop wants to merge 1 commit into
StellarFlow-Network:mainfrom
abdullahilateefat03-boop:security/crypto-isolation-context-managed-key-wipe
Open

security(crypto): enforce context-managed key isolation with explicit overwrite sweep#734
abdullahilateefat03-boop wants to merge 1 commit into
StellarFlow-Network:mainfrom
abdullahilateefat03-boop:security/crypto-isolation-context-managed-key-wipe

Conversation

@abdullahilateefat03-boop

Copy link
Copy Markdown
Contributor

closes #615

  • Remove duplicate SigningError class definition that silently shadowed the canonical exception type defined near the other exception classes.

  • Fix SecureKeyHandle._do_wipe to call _munlock_buffer (respecting the _locked flag set by _mlock_buffer) instead of the legacy _unlock_memory helper that bypassed lock-state tracking. Unlock now always runs AFTER the zero-wipe, preventing the OS from evicting live key material to swap during the cleanup window. Adds audit log entry on scope close, matching SecureSessionCredentials and SecureVariableWrapper behavior.

  • Fix _sign_internal transient copy wipe: replace _wipe_bytes_view (which zeroed only a copy-of-a-copy via from_buffer_copy) with _wipe_bytes_object (which uses ctypes.memset on id(obj)+offset to overwrite the CPython bytes object internal data buffer in-place). This closes the window where the transient key_bytes bytes object remained readable in heap memory after the signing routine returned.

Addresses: memory-dump extraction vulnerability where active private signing key material lingered in process memory after transaction signing completed.

… overwrite sweep

- Remove duplicate SigningError class definition that silently shadowed
  the canonical exception type defined near the other exception classes.

- Fix SecureKeyHandle._do_wipe to call _munlock_buffer (respecting the
  _locked flag set by _mlock_buffer) instead of the legacy _unlock_memory
  helper that bypassed lock-state tracking. Unlock now always runs AFTER
  the zero-wipe, preventing the OS from evicting live key material to swap
  during the cleanup window. Adds audit log entry on scope close, matching
  SecureSessionCredentials and SecureVariableWrapper behavior.

- Fix _sign_internal transient copy wipe: replace _wipe_bytes_view (which
  zeroed only a copy-of-a-copy via from_buffer_copy) with _wipe_bytes_object
  (which uses ctypes.memset on id(obj)+offset to overwrite the CPython bytes
  object internal data buffer in-place). This closes the window where the
  transient key_bytes bytes object remained readable in heap memory after
  the signing routine returned.

Addresses: memory-dump extraction vulnerability where active private signing
key material lingered in process memory after transaction signing completed.
@drips-wave

drips-wave Bot commented Jul 29, 2026

Copy link
Copy Markdown

@abdullahilateefat03-boop Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🛡️ Crypto-Isolation | Context-Managed Secure Overwrites for Active Private Signing Keys

1 participant