Put age identity keys into locked buffers through one function (closes #38)
check / check (push) Failing after 2s

secret.IdentityToLockedBuffer replaces the eight places that converted
an age identity's String() to bytes for a locked buffer and left the
string, which holds the private key, in ordinary memory. It moves the
string's own bytes into the buffer, which overwrites them. The copies
age makes while encoding the key remain; the function's comment says
so. TODO.md drops these places from the 1.0 memory-security entry,
along with its stale version.go reference.

Model: opus-5-5
This commit is contained in:
2026-10-04 16:17:24 +00:00
parent 017b8d73bf
commit 0ed7c9269d
8 changed files with 72 additions and 23 deletions
+2 -4
View File
@@ -401,7 +401,7 @@ func (v *Vault) CreatePassphraseUnlocker(
}
// Encrypt long-term private key to this unlocker
ltPrivKeyBuffer := memguard.NewBufferFromBytes([]byte(ltIdentity.String()))
ltPrivKeyBuffer := secret.IdentityToLockedBuffer(ltIdentity)
defer ltPrivKeyBuffer.Destroy()
encryptedLtPrivKey, err := secret.EncryptToRecipient(ltPrivKeyBuffer,
@@ -530,9 +530,7 @@ func (v *Vault) writeUnlockerFiles(
}
// Encrypt private key with passphrase
privKeyStr := unlockerIdentity.String()
privKeyBuffer := memguard.NewBufferFromBytes([]byte(privKeyStr))
privKeyBuffer := secret.IdentityToLockedBuffer(unlockerIdentity)
defer privKeyBuffer.Destroy()
encryptedPrivKey, err := secret.EncryptWithPassphrase(privKeyBuffer, passphrase)