Wipe memguard buffers on every exit, restore echo on Ctrl-C (closes #35)
check / check (push) Successful in 1m4s

Entry() now returns the exit code and only main calls os.Exit, so the
deferred memguard.Purge() in Entry() runs on success and on error;
before, os.Exit(1) skipped every deferred Destroy().

SIGINT and SIGTERM go through memguard's handler, which wipes every
buffer and exits with status 1. The passphrase prompt turns terminal
echo off until its read returns, and the handler exits before that, so
on Ctrl-C the handler first restores the terminal settings saved at
startup. It leaves the terminal alone on SIGTERM, which can reach a
background process, and changing the terminal from the background would
stop the process.

Model: opus-5-5
This commit is contained in:
2026-10-03 12:15:47 +00:00
parent d52b4f1240
commit 6f2538cfd2
4 changed files with 145 additions and 7 deletions
+6
View File
@@ -25,6 +25,12 @@ Bring the repo into policy compliance in one commit:
# Completed Steps
- 2026-10-03: Key material is wiped on every exit: `Entry()` returns
the exit code after its deferred `memguard.Purge()` has run, and only
`main` calls `os.Exit`. SIGINT and SIGTERM go through memguard's
handler, which wipes every buffer before exiting; on Ctrl-C it first
restores the terminal settings from startup, so an interrupted
passphrase prompt no longer leaves echo off.
- 2026-10-02: A plain `docker build .` builds again: the size tests
skip a case that needs more locked memory than the process can
lock, and run every case under `script/cibuild`. The image stamps the