diff --git a/Cargo.lock b/Cargo.lock index 25b2707e..1ff965e3 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -333,6 +333,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "d2f6c7dbe95a6ed67ad9f18e57daf93a2f034c524b99fd2b76d18fdfeb6660aa" dependencies = [ "hybrid-array", + "zeroize", ] [[package]] @@ -1028,6 +1029,7 @@ dependencies = [ "const-oid", "crypto-common 0.2.2", "ctutils", + "zeroize", ] [[package]] @@ -1175,6 +1177,7 @@ dependencies = [ "futures", "hex", "hkdf", + "hmac 0.13.0", "libc", "libm", "mdns-sd", diff --git a/Cargo.toml b/Cargo.toml index 58188ce8..ae71c12e 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -22,8 +22,12 @@ profiling = [] [dependencies] ratatui = "0.30" secp256k1 = { version = "0.30", features = ["rand", "global-context"] } -sha2 = "0.11" +# The `zeroize` features clear the SHA-256 and HMAC states on drop. `hmac`'s +# feature only forwards to `digest`'s, which `sha2`'s also turns on; it is +# listed so the HMAC inside `hkdf` keeps it if `sha2`'s ever stops doing so. +sha2 = { version = "0.11", features = ["zeroize"] } hkdf = "0.13" +hmac = { version = "0.13", features = ["zeroize"] } ring = "0.17" libm = "0.2" zeroize = { version = "1.9", features = ["zeroize_derive"] } diff --git a/src/noise/tests.rs b/src/noise/tests.rs index 4c5e86b3..d8adec46 100644 --- a/src/noise/tests.rs +++ b/src/noise/tests.rs @@ -915,3 +915,15 @@ fn test_xk_invalid_msg3_size() { .is_err() ); } + +/// The `zeroize` features of `sha2` and `hmac` are on, so the SHA-256 state +/// that hashes each Diffie-Hellman result, and the two SHA-256 cores inside +/// the HMAC that HKDF runs on, are cleared when dropped. Without `sha2`'s +/// feature this does not compile; `hmac`'s forwards to the same `digest` +/// feature, so dropping it alone changes nothing while `sha2`'s is on. +#[test] +fn test_sha256_states_used_by_hashing_and_hkdf_are_cleared_on_drop() { + fn clears_on_drop() {} + clears_on_drop::(); + clears_on_drop::<::Core>(); +}