Fix the findings of the pre-release review - #1
Merged
Merged
Conversation
Code (each fix has a test that failed before it): - Decoding is bounded per Envelope cap, in a buffer that cannot grow: a small row could make Open allocate 16-90 MiB, and a flood of small zstd frames 2 GB, before refusing it. Blobs longer than the cap allows are refused before decryption. - Reseal, for a safe AuthKey cutover and AuthKey rotation. - Envelope.DisableCompression: stored zstd frames, so a field's length no longer depends on its content (CRIME within one field). - All-zero keys refused; NewLocalKeyring rejects an empty seed (NewEphemeralKeyring for tests); ErrInvalidConfig from every constructor; public keys that cannot be sealed to are refused at load. - Hostile rows: leaf ids <= 256 bytes, sealed leaves exactly 1168 bytes, row values truncated in errors, partial cache eviction, RequireGenerationStamp. - HKDF from the standard library (x/crypto dropped; vectors unchanged); klauspost/compress 1.20.0; concurrent encoders/decoders. - Vectors for negative/non-ASCII bindings, unstamped and uncompressed rows. CI: fuzz jobs now target one package (they never ran); tests on the go.mod minimum and latest 1.26 patch; Dependabot; issue forms route security reports to SECURITY.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VwpTwdibuwvYAqEb4hETUu
- The cutover no longer picks the envelope from schema_version (a column the forger writes): re-seal once with Reseal, then read authenticated only; the forgery window lasts until the migration finishes. - Compression's in-field length oracle, unauthenticated metadata, the per-request binding and compromised writers are documented. - README usage snippets handle errors and are compiled by a test; install line; aligned diagrams; 'hybrid post-quantum' instead of 'quantum-safe'. - SPEC, ATTACK and CHANGELOG updated; 'audit' becomes 'internal review'. - SECURITY.md: supported versions and response timeline; NOTICE and CODE_OF_CONDUCT added. - All six translations updated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VwpTwdibuwvYAqEb4hETUu
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes everything found by an internal, AI-assisted pre-release review. Three separate AI reviewers each worked from a frozen snapshot, covering the cryptographic construction, the implementation and the public claims. A fourth re-tested the fixes. This is not an independent audit by human cryptographers, and CHANGELOG.md says so.
Every code fix comes with a test that failed before it.
Findings fixed
schema_version, a column the forger writes, so following the docs re-opened forgeryReseal; cutover is now: re-seal once, then read authenticated only. The forgery window (until the migration finishes) is documented. A test pins the old advice as unsafe.Openallocated 16–90 MiB before refusing a row under any cap. Many small zstd frames cost 2 GB for a 22 KB row.-fuzzover./..., two packages).; a test checks the command formEnvelope.DisableCompression(a stored zstd frame, readable by any reader)NewLocalKeyring(nil)silently ephemeral; inconsistentErrInvalidConfig; unusable public keys accepted; unbounded hostile-row inputs; process-wide serialisation; test gapsOther changes
golang.org/x/cryptois dropped; the known-answer vectors are unchanged.klauspost/compressis bumped to 1.20.0.Verification
go vet,gofmt,go test -race ./...and staticcheck are all clean.govulncheckcould not run locally (vuln.go.dev is blocked in the sandbox); CI runs it.Please check before merging
Note: CI may not run until the organization's Actions billing issue is resolved.
🤖 Generated with Claude Code
https://claude.ai/code/session_01VwpTwdibuwvYAqEb4hETUu
Generated by Claude Code