Skip to content

Fix 8 findings from independent code audit - #99

Merged
sidick merged 1 commit into
mainfrom
audit-2026-07-fixes
Jul 27, 2026
Merged

sidick merged 1 commit into
mainfrom
audit-2026-07-fixes

Conversation

@sidick

@sidick sidick commented Jul 27, 2026

Copy link
Copy Markdown
Owner

Summary

  • Fixes all 8 findings from the independent code audit recorded in docs/AUDIT_2026-07.md
  • High: SNTP spoofing (connect() the UDP socket to the resolved server) and GUI passphrase entry not feeding the entropy pool
  • Medium: ReAction gadget-tree leak on window-creation failure (4 requesters); HMAC init leaving key material unzeroed
  • Low: PBKDF2 scratch buffers unzeroed; vault digits field unvalidated; CLI secret not zeroed on vault-open failure; QR decode NULL-check ordering

Test plan

  • make test — 292/292 passing
  • make m68k-docker gui-docker — clean cross-build, no warnings
  • Reviewed for user-visible behaviour changes — none found; no userdocs/ updates needed (see docs/AUDIT_2026-07.md for per-finding detail)

🤖 Generated with Claude Code

Reject spoofed SNTP replies (connect() the UDP socket to the resolved
server), feed keystroke timing into the entropy pool from the GUI's own
passphrase requester, fix a ReAction gadget-tree leak on window-creation
failure across four requesters, zero key-derived scratch buffers in
HMAC/PBKDF2, validate the vault's per-account digits field, zero a
decoded secret on a CLI vault-open failure, and fix a NULL-check
ordering bug in the QR decode wrapper.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sidick
sidick merged commit d89831a into main Jul 27, 2026
13 of 14 checks passed
@sidick
sidick deleted the audit-2026-07-fixes branch July 27, 2026 21:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant