Skip to main content

MemoryEnclave

Struct MemoryEnclave 

Source
pub struct MemoryEnclave { /* private fields */ }
Expand description

An in-memory AES-256-GCM sealed secret.

Plaintext is encrypted under the process-global Coffer master key. open() returns the plaintext in a PoolSlot (slab-backed if the plaintext fits in the smallest tier’s slot size, otherwise standalone). A hot cache in the slab avoids decryption when the same MemoryEnclave is opened multiple times in quick succession.

When dropped, the hot cache entry for this enclave is evicted.

§Security note: hot cache

After the first successful open(), the plaintext is cached in the locked slab until this MemoryEnclave is dropped (or until LRU pressure evicts it). The cached copy lives in a guard-paged, mlock’d slab slot — but it is present for the lifetime of this value. For secrets that should not persist in memory, drop the MemoryEnclave promptly after use.

Implementations§

Source§

impl MemoryEnclave

Source

pub fn seal(plaintext: &[u8]) -> Result<Self>

Seal plaintext under the Coffer key.

Source

pub fn seal_buffer(buf: &mut SecureBuffer) -> Result<Self>

Seal a SecureBuffer’s contents (melt → read → re-freeze).

Source

pub fn seal_slot(slot: &PoolSlot) -> Result<Self>

Seal a PoolSlot’s contents. The caller is responsible for dropping the slot (which zeroizes it).

Source

pub fn open(&self) -> Result<PoolSlot>

Decrypt and return the plaintext in a PoolSlot.

Hot cache fast path: if this enclave was recently opened, the plaintext is copied from the slab cache into a new transient PoolSlot without AES-GCM decryption.

Source

pub fn plaintext_len(&self) -> usize

Source

pub fn id(&self) -> u64

Trait Implementations§

Source§

impl Debug for MemoryEnclave

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Drop for MemoryEnclave

Source§

fn drop(&mut self)

Executes the destructor for this type. Read more
Source§

fn pin_drop(self: Pin<&mut Self>)

🔬This is a nightly-only experimental API. (pin_ergonomics)
Execute the destructor for this type, but different to Drop::drop, it requires self to be pinned. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more