Skip to content

Bound native group-key generation and wrapping allocations - #254

Merged
iFixRobots merged 1 commit into
iFixRobots/own-line-crypto-runtimesfrom
iFixRobots/isolate-group-key-wrapping
Oct 5, 2026
Merged

iFixRobots merged 1 commit into
iFixRobots/own-line-crypto-runtimesfrom
iFixRobots/isolate-group-key-wrapping

Conversation

@iFixRobots

@iFixRobots iFixRobots commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Releasing the generated registration key is not enough to stop native allocation growth. A local 1,000-iteration generate/wrap/destroy run grew the authoritative heap from 6,352 to 1,198,696 live bytes. Generation/destruction alone grew it to 198,392 bytes.

Run the complete registration batch on the existing disposable crypto snapshot instead: generate one group key, wrap that same key for all recipients, and return only copied ciphertext bytes. Mark the snapshot dirty after every batch, including errors and panics. No temporary native key pointer is published in the session heap, and no destructor runs on a damaged snapshot.

The real Manager takes this batch path. Existing fake/legacy Generate/Wrap/Release callers remain compatible; their native generation path is not made leak-free by this change. Existing single-key wrapping also uses the disposable snapshot. Shadow aborts return an error without quarantining the healthy authoritative heap; authoritative channel-creation aborts still quarantine it.

@indent
indent Bot force-pushed the iFixRobots/own-line-crypto-runtimes branch from db96479 to 9a9abc6 Compare October 5, 2026 18:00
@indent
indent Bot force-pushed the iFixRobots/isolate-group-key-wrapping branch from 476b8c2 to 5dd854f Compare October 5, 2026 18:00
@indent
indent Bot marked this pull request as ready for review October 5, 2026 18:03
@indent

indent Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Issues

No issues found.

CI Checks

All CI checks passed on 9fb4867.

Review agents

Select any unchecked box below to run or rerun that agent.

Passed (1)
  • Indent Review Agent · Rebase only; PR changes are identical and still work with the base connector changes. No bugs found.
Full results

Indent Review Agent

  • Summary: Rebase only; PR changes are identical and still work with the base connector changes. No bugs found.
  • Last ran on commit: 9fb48676
  • Latest result
    {
      "summary": "Rebase only; PR changes are identical and still work with the base connector changes. No bugs found.",
      "findings": []
    }

@indent
indent Bot force-pushed the iFixRobots/isolate-group-key-wrapping branch 2 times, most recently from 3ae462c to 51a9bc0 Compare October 5, 2026 18:23
@indent
indent Bot force-pushed the iFixRobots/isolate-group-key-wrapping branch from 51a9bc0 to 9fb4867 Compare October 5, 2026 18:31
@iFixRobots
iFixRobots requested a review from highesttt October 5, 2026 18:34
@iFixRobots
iFixRobots merged commit 8a13ff0 into iFixRobots/own-line-crypto-runtimes Oct 5, 2026
9 checks passed
@iFixRobots
iFixRobots deleted the iFixRobots/isolate-group-key-wrapping branch October 5, 2026 20:40
iFixRobots added a commit that referenced this pull request Oct 6, 2026
* Own LINE crypto by session and login attempt

* Require upstream cancellation-aware login admission

* Do not treat retired crypto owners as missing login keys

* Preserve reusable login keys after ordinary reconnect export failures

Keep the established manual reconnect fallback for a verified same account with stored keys. Cancellation, deadlines, terminal crypto errors, forced full verification and account mismatches still reject completion.

* Keep recovered tokens when reusable E2EE keys survive ordinary refresh errors

Preserve staged token publication for the verified same account when existing key metadata is reusable and the active owner remains usable. Failed fresh-key validation does not publish partial key metadata. Cancellation, retirement, forced verification and terminal crypto failures still stop recovery.

* Keep registration generation and wrapping on a disposable crypto heap (#254)

* Preserve LINE recovery across request timeouts and cache failures

Distinguish individual HTTP timeouts from expired caller or login-attempt contexts. Allow stored-key fallback during startup before an E2EE manager exists. Reset missing-key notification state only after fresh keys, database metadata and live tokens are published successfully. Keep post-publication secure-file failures warning-only.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants