Skip to content

Fix/hkeyring branch key material 1691 - #1698

Closed
kessplas wants to merge 2 commits into
masterfrom
fix/hkeyring-branch-key-material-1691
Closed

Fix/hkeyring branch key material 1691#1698
kessplas wants to merge 2 commits into
masterfrom
fix/hkeyring-branch-key-material-1691

Conversation

@kessplas

Copy link
Copy Markdown
Contributor

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

Check any applicable:

  • Were any files moved? Moving files changes their URL, which breaks all hyperlinks to the files.

getBranchKeyMaterials returned the cached NodeBranchKeyMaterial by
reference. The cryptographic materials cache zeroes a material's buffer
in place when the entry is evicted, so under concurrency an eviction
(overwrite, TTL expiry, or tail eviction) could zero the branch key
another in-flight operation was about to derive its wrapping key from.

Triggering this requires two branch key acquisitions to resolve within
the same event-loop tick. This does not arise during normal operation
with the DynamoDB/KMS-backed keystore; fetches complete on separate
I/O callbacks. We are nevertheless patching it.

Return an independent deep copy from getBranchKeyMaterials so callers
never share a buffer the cache can zero. Add concurrency regression
tests covering both the encrypt and decrypt paths.

Fixes #1691
@kessplas kessplas closed this Aug 18, 2026
@kessplas
kessplas deleted the fix/hkeyring-branch-key-material-1691 branch August 18, 2026 22:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant