zeroize 0.1.0
zeroize: ^0.1.0 copied to clipboard
Best-effort secret memory zeroing, constant-time operations, and secure containers for pure Dart. No FFI or dart:io required.
Changelog #
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog and this project adheres to Semantic Versioning.
Unreleased #
0.1.0 — 2026-09-23 #
Added #
Core Zeroing Engine
secureZero(Uint8List)— multi-pass secure zeroing withZeroizePatternselectionsecureZeroIntList(List<int>)— zeroing for NTT polynomial coefficient arrayssecureZeroRange(Uint8List, offset, count)— sub-region zeroing viaUint8List.sublistViewZeroizePatternenum —zero,ones,twoPass(default),dod,pseudoRandom,gutmann7
DSE Guard
_dseOpaqueSink— mutable package-level variable that defeats Dead Store EliminationdseOpaqueRead(List<int>, idx)—@pragma('vm:never-inline')read after overwrite passdseOpaqueReadFold(List<int>, idx)— read + 32-bit rotate-left mixing between passesdseObserve(int)— forces an intermediate value to be observable- All DSE-guard values kept within 32-bit Smi range to avoid Mint/BigInt promotion
Containers
-
SecretBytes— primary secret container- Factories:
fromList,fromUint8List,ofLength,generate - Access:
use(fn),mutate(fn)(never exposes backing buffer directly) - Operations:
xorWith,fill,subrange,concat - CT comparison:
timingSafeEquals,timingSafeEqualsBytes Finalizer<_FinalizerToken>for GC-triggered backstop zeroingZeroizeConfig.trackAllocate/trackDisposefor debug leak detection
- Factories:
-
SecretIntList—List<int>container for NTT polynomial arrays- Factories:
ofLength,fromList - Access:
[],[]=,use(fn),mutate(fn) Finalizerfor GC-triggered backstop zeroing
- Factories:
-
SecretBuffer— incremental secret accumulatoraddByte,addBytes,addList,addFill- Internal growth zeroes the old
Uint8Listallocation before release seal()atomically transfers toSecretBytesand disposes buffer
-
SecretBox<T>— generic opaque wrapper with caller-supplied zero callback -
PasswordInput— DartString-aware password handlertoUtf8SecretBytes()— UTF-8 byte representation (zeroable)toCodePointsBytes()— big-endian 32-bit code-point encoding (zeroable)- Documents the byte-collection alternative via
SecretBuffer
Lifecycle Management
Zeroizablemixin —zeroize(),useAndZeroize(fn),useAndZeroizeAsync(fn)ZeroizeScope— RAII scope with LIFO disposal ordertrack<T extends Zeroizable>(item)— registers for zeroingrun(fn)/runAsync(fn)— factory runners with guaranteed disposal
withZeroizedBytes(Uint8List, fn)/withZeroizedBytesAsync— scoped raw buffer zeroingwithZeroized(List<Zeroizable>, fn)/withZeroizedAsync— LIFO multi-secret guard
Constant-Time Primitives
- Byte comparison:
ctCompareBytes,ctEquals,ctCompareIntLists,ctEqualsIntLists - Tag verification:
ctVerifyTag— with length-mismatch dummy scan - Integer selection:
ctSelect,ctSelectByte - Buffer ops:
ctConditionalCopy,ctConditionalSwap - Predicates:
ctLessThan,ctGreaterThan,ctLessOrEqual,ctGreaterOrEqual,ctIntEquals,ctIsZero,ctIsNonZero - Arithmetic:
ctAbs,ctClamp - Modular:
ctReduceOnce,ctLiftToPositive,ctConditionalAdd,ctConditionalSub
Extensions
Uint8ListZeroize—.secureZeroize(),.xorWith(),.isAllZero,.toHexString()ListIntZeroize—.secureZeroize()
Configuration & Annotations
ZeroizeConfig—defaultPattern,setDefaultPattern,liveSecretCount,totalAllocated,debugAssertNoLeaks()@sensitive/@constantTimeannotationsZeroizeDisposedError/ZeroizeContractError— typed error hierarchy
Utilities
PseudoRng— Xorshift32 PRNG for overwrite pattern diversity (non-cryptographic)- 60+ unit tests across all components
Documentation
doc/ARCHITECTURE.md— layer-by-layer design rationaledoc/SECURITY_MODEL.md— threat model, mitigations, and known limitationsdoc/FEATURES.md— complete feature cataloguedoc/ROADMAP.md— planned versions and future directionsdoc/API_GUIDE.md— usage guide with realistic examplesdoc/INTEGRATION.md— integration patterns forpqcrypto,pqforge,pqtransportdoc/CONTRIBUTING.md— contribution process and safety rules