Repository navigation
Bound native group-key generation and wrapping allocations - #254
Merged
iFixRobots merged 1 commit intoOct 5, 2026
Merged
iFixRobots merged 1 commit into
iFixRobots merged 1 commit into
Conversation
indent
Bot
force-pushed
the
iFixRobots/own-line-crypto-runtimes
branch
from
October 5, 2026 18:00
db96479 to
9a9abc6
Compare
indent
Bot
force-pushed
the
iFixRobots/isolate-group-key-wrapping
branch
from
October 5, 2026 18:00
476b8c2 to
5dd854f
Compare
|
No issues found.
All CI checks passed on
Select any unchecked box below to run or rerun that agent. Passed (1)Full resultsIndent Review Agent
|
indent
Bot
force-pushed
the
iFixRobots/isolate-group-key-wrapping
branch
2 times, most recently
from
October 5, 2026 18:23
3ae462c to
51a9bc0
Compare
indent
Bot
force-pushed
the
iFixRobots/isolate-group-key-wrapping
branch
from
October 5, 2026 18:31
51a9bc0 to
9fb4867
Compare
highesttt
approved these changes
Oct 5, 2026
iFixRobots
merged commit Oct 5, 2026
8a13ff0
into
iFixRobots/own-line-crypto-runtimes
9 checks passed
iFixRobots
added a commit
that referenced
this pull request
Oct 6, 2026
* Own LINE crypto by session and login attempt * Require upstream cancellation-aware login admission * Do not treat retired crypto owners as missing login keys * Preserve reusable login keys after ordinary reconnect export failures Keep the established manual reconnect fallback for a verified same account with stored keys. Cancellation, deadlines, terminal crypto errors, forced full verification and account mismatches still reject completion. * Keep recovered tokens when reusable E2EE keys survive ordinary refresh errors Preserve staged token publication for the verified same account when existing key metadata is reusable and the active owner remains usable. Failed fresh-key validation does not publish partial key metadata. Cancellation, retirement, forced verification and terminal crypto failures still stop recovery. * Keep registration generation and wrapping on a disposable crypto heap (#254) * Preserve LINE recovery across request timeouts and cache failures Distinguish individual HTTP timeouts from expired caller or login-attempt contexts. Allow stored-key fallback during startup before an E2EE manager exists. Reset missing-key notification state only after fresh keys, database metadata and live tokens are published successfully. Keep post-publication secure-file failures warning-only.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Releasing the generated registration key is not enough to stop native allocation growth. A local 1,000-iteration generate/wrap/destroy run grew the authoritative heap from 6,352 to 1,198,696 live bytes. Generation/destruction alone grew it to 198,392 bytes.
Run the complete registration batch on the existing disposable crypto snapshot instead: generate one group key, wrap that same key for all recipients, and return only copied ciphertext bytes. Mark the snapshot dirty after every batch, including errors and panics. No temporary native key pointer is published in the session heap, and no destructor runs on a damaged snapshot.
The real Manager takes this batch path. Existing fake/legacy Generate/Wrap/Release callers remain compatible; their native generation path is not made leak-free by this change. Existing single-key wrapping also uses the disposable snapshot. Shadow aborts return an error without quarantining the healthy authoritative heap; authoritative channel-creation aborts still quarantine it.