mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 03:28:24 +00:00
The security reference had no account of key clearing; the only one was in the v0.4.2 release notes and changelog, and it rested on reading the source. Add a "Key Material in Memory" section measured against an x86_64 release build instead. Every erase in the Noise handshake and identity code that the daemon links is present as stores in the generated code. What the erases do not reach is stated concretely: the copies a move leaves behind (a handshake state is built on the stack and moved several times, taking a completed handshake out of its connection slot leaves its full contents, the long-term private key included, in heap memory, and a completed session is moved into the session slot and taking it out leaves both traffic keys there), registers and spilled temporaries, and library state the daemon cannot clear. The SHA-256 and HKDF states are cleared on drop by an opt-in zeroize feature of sha2 0.11 and hmac 0.13 that the daemon does not yet enable; ring's LessSafeKey offers no way to clear its cached key; libsecp256k1 clears its own signing nonce and secret scalar on a best-effort basis, but the daemon cannot clear the library's internals. A completed session keeps an uncleared copy of the handshake hash on purpose, since nothing derives a key from it and the session hands it out. The doc comments on Identity, ErasingKeypair, Drop for HandshakeState and NoiseSession said the compiler "may duplicate or move the bytes to places no code here can name". They now say what a release build shows: the erases are kept, and the copies they miss are the ones moves leave behind, such as the intermediate Identity that from_secret_str builds and copies into its Result, left in that constructor's frame, and the contents a take leaves in a connection's handshake or session slot.
Reference
Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.
Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.
Available Reference
| Document | Scope |
|---|---|
| wire-formats.md | All FMP and FSP message byte layouts, encapsulation walkthrough |
| configuration.md | Full YAML configuration reference for the daemon and gateway |
| security.md | nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix |
| nostr-events.md | Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays |
| transports.md | Per-transport statistics counter inventory |
| control-socket.md | Line-delimited JSON control protocol for the daemon and gateway |
| native-api.md | Native datagram API: the Rust surface, addressing and ports, errno table, ceilings, line protocol, command reference |
| cli-fips.md | fips daemon CLI: options, exit codes, environment, files |
| cli-fipsctl.md | fipsctl control-client: subcommands, options, exit codes |
| cli-fipstop.md | fipstop live-status TUI: tabs, keybindings |
| cli-fips-gateway.md | fips-gateway service CLI: options, exit codes, files |