check / check (push) Failing after 3s
secret.IdentityToLockedBuffer replaces the eight places that converted an age identity's String() to bytes for a locked buffer and left the string, which holds the private key, in ordinary memory. It moves the string's own bytes into the buffer, which overwrites them. The copies age makes while encoding the key remain; the function's comment says so. TODO.md drops these places from the 1.0 memory-security entry, along with its stale version.go reference. Model: opus-5-5
30 lines
831 B
Go
30 lines
831 B
Go
package secret_test
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"filippo.io/age"
|
|
"git.eeqj.de/sneak/secret/internal/secret"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// TestIdentityToLockedBuffer checks that the buffer holds the identity's
|
|
// private key, and that the identity still gives that key afterwards: the
|
|
// helper overwrites the string age returned, so age must not keep it.
|
|
func TestIdentityToLockedBuffer(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
identity, err := age.GenerateX25519Identity()
|
|
require.NoError(t, err)
|
|
|
|
buffer := secret.IdentityToLockedBuffer(identity)
|
|
defer buffer.Destroy()
|
|
|
|
parsed, err := age.ParseX25519Identity(buffer.String())
|
|
require.NoError(t, err)
|
|
assert.Equal(t, identity.Recipient().String(), parsed.Recipient().String())
|
|
|
|
assert.Equal(t, identity.String(), buffer.String())
|
|
}
|