#compiler-optimization #memory #volatile #secure #memset #zero

no-std zeroize

Securely clear secrets from memory with a simple trait built on stable Rust primitives which guarantee memory is zeroed using an operation will not be 'optimized away' by the compiler. Uses a portable pure Rust implementation that works everywhere, even WASM!

17 stable releases

1.8.1 May 25, 2024
1.7.0 Nov 16, 2023
1.6.0 Mar 26, 2023
1.5.7 Jul 20, 2022
0.4.2 Nov 28, 2018

#769 in Cryptography

Download history 1632118/week @ 2024-07-30 1640836/week @ 2024-08-06 1654421/week @ 2024-08-13 1690604/week @ 2024-08-20 1639557/week @ 2024-08-27 1759294/week @ 2024-09-03 1667434/week @ 2024-09-10 1743837/week @ 2024-09-17 1854216/week @ 2024-09-24 2196921/week @ 2024-10-01 2410967/week @ 2024-10-08 2345763/week @ 2024-10-15 1913330/week @ 2024-10-22 1779944/week @ 2024-10-29 1775731/week @ 2024-11-05 1549754/week @ 2024-11-12

7,411,781 downloads per month
Used in 14,253 crates (959 directly)

Apache-2.0 OR MIT

36KB
456 lines

RustCrypto: zeroize

Crate Docs Apache 2.0/MIT Licensed MSRV Build Status

Securely zero memory (a.k.a. zeroize) while avoiding compiler optimizations.

This crate implements a portable approach to securely zeroing memory using techniques which guarantee they won't be "optimized away" by the compiler.

The Zeroize trait is the crate's primary API.

Documentation

About

Zeroing memory securely is hard - compilers optimize for performance, and in doing so they love to "optimize away" unnecessary zeroing calls. There are many documented "tricks" to attempt to avoid these optimizations and ensure that a zeroing routine is performed reliably.

This crate isn't about tricks: it uses core::ptr::write_volatile and core::sync::atomic memory fences to provide easy-to-use, portable zeroing behavior which works on all of Rust's core number types and slices thereof, implemented in pure Rust with no usage of FFI or assembly.

  • No insecure fallbacks!
  • No dependencies!
  • No FFI or inline assembly! WASM friendly (and tested)!
  • #![no_std] i.e. embedded-friendly!
  • No functionality besides securely zeroing memory!
  • (Optional) Custom derive support for zeroing complex structures

Minimum Supported Rust Version

Rust 1.60 or newer.

In the future, we reserve the right to change MSRV (i.e. MSRV is out-of-scope for this crate's SemVer guarantees), however when we do it will be accompanied by a minor version bump.

License

Licensed under either of:

at your option.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

Dependencies

~165KB