What changed, and why it matters
This commit only updates the project's internal coding guidelines document (AGENTS.md). It adds advice about keeping sensitive data in heap-backed storage and avoiding reallocations after writing sensitive data, because discarded memory allocations are not automatically wiped. There is no actual code change, no bug fix, and no reported vulnerability being addressed.
No action required. Treat as a routine documentation/clarification update to secure-coding guidelines.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff modifies a single documentation file, AGENTS.md, changing one bullet point in the secure-coding guidelines. The old text recommended Zeroizing
Changed components
AGENTS.md documentation fileInspect captured patch +3 / −2
### AGENTS.md
@@ -141,8 +141,9 @@ reviews conclude.
util::Bytes::BytesMut ot pass in buffers and write to out buffers.
Always initialize C buffers passed to `rust_util_bytes_mut` to zeroes, e.g.
`uint8_t buf[32] = {0}`.
-- when using Zeroizing<...> for buffers, use Zeroizing<Vec<u8>>. For other sensitive data, use
- Zeroizing<Box<...>>.
+- Keep sensitive data in heap-backed storage, such as Zeroizing<Vec<u8>>, Zeroizing<String>,
+ or Zeroizing<Box<T>>. Avoid reallocations after writing sensitive data, since discarded
+ allocations are not wiped automatically.
- when wrapping C functions, always use a '-sys' crate for the bindings, make it safe idiomatic
Rust, with no C types in the input/output, especially no pointers. Results should be returned,
not passed to an out param. Check all invariants in the C code and panic in case they are not met.Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.