Skip to main content

Crate cloud_sdk_sanitization

Crate cloud_sdk_sanitization 

Source
Expand description

provider-neutral mandatory cleanup and optional secret storage for cloud-sdk.
Provider crates, explicit API domains, security-first release gates, and transport-free core types.


cloud-sdk Rust crate overview

§cloud-sdk-sanitization

Provider-neutral cleanup and secret-handling boundary for the main cloud-sdk workspace and cloud-sdk crate.

This crate provides the mandatory volatile cleanup primitive used by the default no_std SDK plus reusable caller-owned guards. It delegates clearing to the independently reviewed sanitization crate with default features disabled.

§Install

[dependencies]
cloud-sdk = "0.50.0"
cloud-sdk-sanitization = "0.19.0"

§Example

use cloud_sdk_sanitization::SecretBuffer;

let mut output = [0_u8; 128];
{
    let mut guarded = SecretBuffer::new(&mut output);
    guarded.as_mut_slice()[..6].copy_from_slice(b"secret");
    assert_eq!(&guarded.as_slice()[..6], b"secret");
}
assert_eq!(output, [0_u8; 128]);

With the optional alloc feature, the reviewed sanitization::SecretString and sanitization::SecretBoxBytes types are re-exported. SecretString consumes an owned String without copying its plaintext bytes, restricts access to checked closures, and volatile-clears the full allocation capacity on drop:

extern crate alloc;

use alloc::string::String;
use cloud_sdk_sanitization::SecretString;

let secret = SecretString::from_string(String::from("temporary secret"));
assert_eq!(
    secret.try_with_secret(|value| value == "temporary secret"),
    Ok(true)
);
assert!(!alloc::format!("{secret:?}").contains("temporary secret"));

SecretBoxBytes provides fixed-length, fallibly allocated protected bytes. Moving the owner transfers only allocation metadata, so the classified bytes remain at one stable address until the allocation is cleared on drop:

use cloud_sdk_sanitization::SecretBoxBytes;

let protected = SecretBoxBytes::try_from_slice(b"topology", 8)
    .unwrap_or_else(|_| unreachable!("fixed protected allocation failed"));
let before = protected.with_secret(<[u8]>::as_ptr);
let moved = protected;
assert_eq!(before, moved.with_secret(<[u8]>::as_ptr));

try_append_secret_string grows protected text with fallible allocation and a caller-supplied public byte ceiling. Growth prepares replacement storage, then clears the old allocation before replacing it:

use cloud_sdk_sanitization::{SecretString, try_append_secret_string};

let mut secret = SecretString::empty();
try_append_secret_string(&mut secret, "bounded", 32)?;
assert_eq!(secret.try_with_secret(|text| text == "bounded"), Ok(true));

§Features

FeatureDefaultEffect
defaultyesEmpty; keeps the boundary no_std.
allocnoAdds stable owned volatile-clearing UTF-8 and fixed-byte secret storage.
stdnoEnables alloc and standard-library integration in cloud-sdk; clearing behavior is unchanged.

Docs.rs builds with all features. The underlying sanitization dependency keeps its default features disabled in every configuration.

§Security Notes

SecretBuffer volatile-clears its entire borrowed slice on drop, including after early returns and unwind where unwind exists. SecretString and SecretBoxBytes clear their full owned allocation capacities on drop. Moving a SecretBoxBytes owner does not move its classified allocation. try_append_secret_string reports bounded growth failure and clears old storage before replacement. sanitize_bytes provides the reviewed byte primitive used by core; sanitize_value applies the same boundary to scalar lifecycle state.

These helpers do not clear immutable source strings or copies made by transports, operating systems, crash handlers, swap, remote services, or other processes. They also do not replace review of token ownership, logging, environment variables, paging, compiler behavior, or process boundaries.

Structs§

SecretBoxBytes
Fixed-allocation secret bytes with a runtime length.
SecretBuffer
Caller-owned byte buffer that is volatile-cleared when dropped.
SecretString
Heap-allocated secret UTF-8 text with clear-on-drop behavior.

Enums§

SecretStringAppendError
Failure while fallibly appending to protected UTF-8 storage.

Functions§

sanitize_bytes
Volatile-clears an ordinary caller-owned byte buffer.
sanitize_string
Volatile-clears an owned UTF-8 allocation’s complete capacity.
sanitize_value
Volatile-clears one value through its reviewed field-wise sanitizer.
try_append_secret_string
Fallibly appends text to protected storage within a public byte bound.