Repository navigation
v2.1.4
v2.1.4 Security & Correctness Fixes
Resolved high-severity vulnerabilities by removing TOCTOU filesystem races via fd-first open()/fstat() patterns and enforcing non-optimizable secure memory zeroization for cryptographic material.
FIX 1 & 2
TOCTOU in get_device_size() (lines 87, 115): Replaced stat(path) → open(path) with open(path) first → fstat(fd). The fd is bound to the inode at open time and can't be swapped by an attacker.
FIX 3
Dead-store memset in zupt_x25519() (line 318): Replaced memset(e, 0, 32) with a volatile pointer loop (volatile uint8_t *ve = e; for(...) ve[i] = 0;). The compiler must emit these stores because volatile reads/writes have observable side effects.
FIX 4
TOCTOU in zupt_disk_restore() (line 601): Replaced stat(target_path) → open(target_path) with open() first → fstat(fd) → fcntl(fd, F_SETFL, O_SYNC) for block devices. Same open-then-classify pattern as the get_device_size fix.
Verified: 78/78 tests (70 core + 8 disk), ASAN clean, from-scratch tarball build + 100MB ext4 LZHP+PQ roundtrip byte-exact, e2fsck clean