fix: copy the master at each layer so zeroization stays local
This commit is contained in:
parent
d7179694a6
commit
f7452832ea
3 changed files with 19 additions and 5 deletions
|
|
@ -145,14 +145,17 @@ class SmolStore {
|
|||
void setMaster(Uint8List fresh) {
|
||||
// Hive's in-memory state updates synchronously and persists in the
|
||||
// background, so the store is consistent without awaiting the write.
|
||||
unawaited(_meta.put("master", fresh));
|
||||
// The put takes its own copy: the caller's buffer is the caller's to
|
||||
// zeroize (the onboarding screen does, on dispose), and a shared object
|
||||
// would scrub the store's view with it.
|
||||
unawaited(_meta.put("master", Uint8List.fromList(fresh)));
|
||||
_native.setMaster(fresh, rotations: 0);
|
||||
}
|
||||
|
||||
/// The master restored from a backup, already at the rotation index the
|
||||
/// server bound.
|
||||
void restoreMaster(Uint8List master, int index) {
|
||||
unawaited(_meta.put("master", master));
|
||||
unawaited(_meta.put("master", Uint8List.fromList(master)));
|
||||
_native.setMaster(master, rotations: index);
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue