Keep the keychain unlocker passphrase in locked memory (closes #36) #63

Merged
clawbot merged 1 commits from issue-36-keychain-passphrase-locked into next 2026-10-03 17:07:57 +02:00
1 Commits
Author SHA1 Message Date
sneak c2b3ac03b4 Keep the keychain unlocker passphrase in locked memory (closes #36)
check / check (push) Successful in 1m18s
The passphrase protecting the keychain unlocker's age key was a plain
string passed through encoding/json, leaving copies in ordinary memory
when an unlocker was created and each time one was used.

It is now generated into a locked buffer, and KeychainData, moved to
keychaindata.go, which is not darwin-only so its tests run on Linux,
writes and reads the keychain JSON itself: encode copies the parts
straight into a locked buffer, and decodeKeychainData takes the
passphrase from a json.RawMessage that it wipes. The JSON field names
are unchanged. keychainunlocker.go only calls this code and stores the
item from the locked buffer without a string copy.

Model: opus-5-5
2026-10-03 12:17:24 +00:00