Skip to content

Bound correction alignment cache growth #21

Description

@BenWestgate

Medium security finding. src/codex32/correction.py uses an unbounded process-global @cache for _syndrome_alignment, keyed by caller-controlled HRP and length. Long-lived GUI/service callers can accumulate alignment tables monotonically.

Remediation: remove attacker-specific global caching or use a small bounded LRU with lifecycle clearing; add churn/regression tests.

Parent: #20

Activity

  1. BenWestgate commented on Sep 24, 2026

    @BenWestgate
    OwnerAuthor

    @claude did PR #24 close this issue?

  2. BenWestgate commented on Sep 25, 2026

    @BenWestgate
    OwnerAuthor

    Resolved on reviewability-v1 by merged PR #24 (correction: Bound alignment cache growth). _syndrome_alignment now uses a bounded LRU and the regression suite covers cache churn/bounds. Closing this finding as completed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    gate: adversarial reviewResolve, merge, or explicitly defer before the next full adversarial review.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions