fix: copy the master at each layer so zeroization stays local

This commit is contained in:
randogoth 2026-09-29 20:35:16 +03:00
parent d7179694a6
commit f7452832ea
3 changed files with 19 additions and 5 deletions

View file

@ -77,14 +77,20 @@ void main() {
final store = await freshStore("wipe");
final master = randomBytes(32);
store.setMaster(master);
// The store's own copy, read back before the wipe.
final stored = store.master()!;
store.pinServer("example.org",
"lm2gqd7e5q67xq3isc5hx6jfj2q7a7xvq4l7trctxipudujovmgq");
store.markRead("cd" * 32);
await store.wipe();
// The bytes the store owned are overwritten, not just dereferenced —
// the caller's reference sees the zeros too.
expect(master.every((b) => b == 0), isTrue);
// the reference read back through the store sees the zeros. The
// caller's own buffer is the caller's to zeroize: the store holds a
// copy precisely so nobody else's zeroization can reach it, and vice
// versa a wipe never reaches a buffer the store handed out.
expect(stored.every((b) => b == 0), isTrue);
expect(master.every((b) => b == 0), isFalse);
expect(store.master(), isNull);
expect(store.identity(), isNull);
expect(store.serverPin("example.org"), isNull);