Making sure SecretKey is zeroized on drop
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 42/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 冷清
- 技术栈
- rust
- 领域
- cryptography
调研方向
首先,在启用 zeroize 功能的情况下复现所提供的示例,然后检查 secret_key.rs 中的 Drop 实现以及 Cargo.toml 中的功能配置。确定观察到的内存内容是否符合预期的清零行为,并记录或修正该行为;如果仓库现有的测试提供了合适的位置,则添加一个针对性的回归测试。
由索引模型根据 Issue 内容生成。
描述
I was trying to make my newtype of SecretKey zeroize properly, and realized I can't even trigger zeroization for SecretKey itself. Consider the code:
use k256::SecretKey;
use rand_core::OsRng;
fn main() {
let sk = SecretKey::random(&mut OsRng);
let ptr = &sk as *const SecretKey;
let ptr_u8 = ptr as *const u8;
println!("Pointer: {:p}", ptr);
drop(sk);
println!("Memory: {:?}", unsafe {
core::slice::from_raw_parts(ptr_u8, 4)
});
}
k256 has zeroize feature enabled in Cargo.toml. This still gives a non-zero output after SecretKey was dropped, despite there being a Drop implementation in secret_key.rs that calls zeroize(). Am I misunderstanding something?
- 主要语言
- Rust
- 星标
- 756
- 派生
- 256
- 平均合并
- 1 小时 27 分钟
- 30 天内合并 PR
- 2
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
RustCrypto/traits 的其他 Issue
-
难度 3/5 1-2 天 新手友好度 52/100
RustCrypto/traits#2487 · 2 条评论 ·
-
难度 4/5 3-5 天 新手友好度 45/100
RustCrypto/traits#2482 · 5 条评论 ·
-
难度 5/5 一周以上 新手友好度 32/100
RustCrypto/traits#2478 · 5 条评论 ·
-
cipher
难度 4/5 3-5 天 新手友好度 38/100
RustCrypto/traits#2424 ·
-
难度 5/5 一周以上 新手友好度 25/100
RustCrypto/traits#2401 ·
查看 RustCrypto/traits 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 75/100
TheLarkInn/aipm#2413 ·
-
documentation
难度 1/5 1 小时以内 新手友好度 90/100
alexgorbatchev/simple-ptt#15 ·
-
tooling
难度 2/5 1-3 小时 新手友好度 75/100
-
todo:ticket
难度 2/5 1-3 小时 新手友好度 70/100
-
难度 2/5 1-3 小时 新手友好度 75/100
taikoxyz/taiko-mono#22168 · 1 条评论 ·