RAMWAL is a durability and recovery primitive. Report vulnerabilities to the maintainer privately; do not open a public issue for a confirmed exploit.
- Recovery accepting a record that should be rejected (false record)
- Recovery silently truncating a complete-but-invalid record (data loss)
- Memory exhaustion from a crafted segment (payload_len is bounded by MAX_RECORD_SIZE before allocation, but report any bypass)
- Format ambiguity between versions
RAMWAL is not encrypted, authenticated, or tamper-evident by design. It detects corruption, not malice. Assume the WAL directory is trusted.
Contact: maintainer (this repository's owner). Include:
- version
- the segment bytes (or a minimal reproducer)
- expected vs actual behavior