Skip to content

Security: grep999/ramwal

Security

SECURITY.md

Security

RAMWAL is a durability and recovery primitive. Report vulnerabilities to the maintainer privately; do not open a public issue for a confirmed exploit.

What is security-relevant

  • Recovery accepting a record that should be rejected (false record)
  • Recovery silently truncating a complete-but-invalid record (data loss)
  • Memory exhaustion from a crafted segment (payload_len is bounded by MAX_RECORD_SIZE before allocation, but report any bypass)
  • Format ambiguity between versions

Non-goals

RAMWAL is not encrypted, authenticated, or tamper-evident by design. It detects corruption, not malice. Assume the WAL directory is trusted.

Reporting

Contact: maintainer (this repository's owner). Include:

  • version
  • the segment bytes (or a minimal reproducer)
  • expected vs actual behavior

There aren't any published security advisories