Skip to content

feat(discovery): secret zeroization, request limits, error sanitization - #510

Merged
m-kus merged 1 commit into
mainfrom
02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization
Mar 2, 2026
Merged

m-kus merged 1 commit into
mainfrom
02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization

Conversation

@m-kus

@m-kus m-kus commented Feb 18, 2026 •

Copy link
Copy Markdown

Implement SecretFelt for Sensitive Key Management

This PR enhances security by implementing proper handling of sensitive cryptographic material throughout the discovery service:

  • Adds SecretFelt wrapper for sensitive keys with:

    • Automatic zeroization on drop (via zeroize crate)
    • Debug redaction ([REDACTED] instead of key values)
    • No Copy trait to prevent accidental duplication
    • Controlled serialization/deserialization
  • Applies SecretFelt to all sensitive keys:

    • viewing_key in API requests
    • channel_key in cursors and channel objects
    • All key parameters in crypto primitives
  • Improves error sanitization:

    • Decryption errors no longer leak channel indices or internal details
    • RPC/storage errors are logged server-side but not forwarded to clients
  • Adds HTTP-level protections:

    • Request body size limit (default 100KB)
    • Request timeout (default 30s)
    • Server budget minimum enforcement (MIN_SERVER_BUDGET = 3)
  • Updates security documentation to reflect implemented mitigations

This change is Reviewable

m-kus commented Feb 18, 2026 •

Copy link
Copy Markdown
Author

@m-kus
m-kus marked this pull request as ready for review February 18, 2026 19:15
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch 6 times, most recently from 2817181 to 6d1c30b Compare February 18, 2026 20:31
@m-kus
m-kus changed the base branch from 02-13-feat_discovery-service_add_docker_image_and_ci_workflow to graphite-base/510 February 19, 2026 15:06
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from 6d1c30b to b07e567 Compare February 19, 2026 15:41
@m-kus
m-kus changed the base branch from graphite-base/510 to 02-13-feat_discovery-service_add_docker_image_and_ci_workflow February 19, 2026 15:42
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from b07e567 to de329a4 Compare February 19, 2026 16:29
@m-kus
m-kus requested a review from Yoni-Starkware February 19, 2026 16:33
@m-kus
m-kus force-pushed the 02-13-feat_discovery-service_add_docker_image_and_ci_workflow branch from 4894f41 to 1a716aa Compare February 19, 2026 16:52
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch 2 times, most recently from 8fa742f to 852caed Compare February 22, 2026 17:26
@m-kus
m-kus force-pushed the 02-13-feat_discovery-service_add_docker_image_and_ci_workflow branch from 1a716aa to 3a51071 Compare February 22, 2026 17:26
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from 852caed to d1127ea Compare February 22, 2026 18:19
@m-kus
m-kus force-pushed the 02-13-feat_discovery-service_add_docker_image_and_ci_workflow branch from 3a51071 to a6531a6 Compare February 22, 2026 18:19
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from d1127ea to b6b94bf Compare February 22, 2026 18:25
@m-kus
m-kus force-pushed the 02-13-feat_discovery-service_add_docker_image_and_ci_workflow branch from a6531a6 to 6a3c48e Compare February 22, 2026 18:25
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from b6b94bf to e22a8e5 Compare February 23, 2026 15:46
@m-kus
m-kus force-pushed the 02-13-feat_discovery-service_add_docker_image_and_ci_workflow branch from 6a3c48e to c8443b9 Compare February 23, 2026 15:46
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from e22a8e5 to 6c5d66c Compare February 23, 2026 15:50
@m-kus
m-kus force-pushed the 02-13-feat_discovery-service_add_docker_image_and_ci_workflow branch from c8443b9 to 0087239 Compare February 23, 2026 15:50
@m-kus
m-kus changed the base branch from 02-13-feat_discovery-service_add_docker_image_and_ci_workflow to graphite-base/510 February 23, 2026 16:00
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from 6c5d66c to bf77877 Compare February 23, 2026 16:10

@Yoni-Starkware Yoni-Starkware left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Yoni-Starkware reviewed 3 files and all commit messages, and made 2 comments.
Reviewable status: 3 of 43 files reviewed, 2 unresolved discussions (waiting on m-kus).


crates/discovery-core/src/test_fixtures.rs line 73 at r2 (raw file):

    pub auditor_public_key: Felt,
    pub user_addr: Felt,
    pub user_private_key: Felt,

Anything else that should be marked as secret?

Code quote:

    pub auditor_private_key: Felt,
    pub auditor_public_key: Felt,
    pub user_addr: Felt,
    pub user_private_key: Felt,

crates/discovery-core/src/privacy_pool/types.rs line 79 at r2 (raw file):

        Felt::deserialize(d).map(SecretFelt::new)
    }
}

Why in a separate mod?

Code quote:

pub mod secret_felt_serde {
    use super::*;
    use serde::{Deserializer, Serializer};

    pub fn serialize<S>(secret: &SecretFelt, s: S) -> Result<S::Ok, S::Error>
    where
        S: Serializer,
    {
        Felt::serialize(&secret.0, s)
    }

    pub fn deserialize<'de, D>(d: D) -> Result<SecretFelt, D::Error>
    where
        D: Deserializer<'de>,
    {
        Felt::deserialize(d).map(SecretFelt::new)
    }
}

@Yoni-Starkware Yoni-Starkware left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Yoni-Starkware made 1 comment.
Reviewable status: 3 of 43 files reviewed, 2 unresolved discussions (waiting on m-kus).


crates/discovery-core/src/privacy_pool/types.rs line 79 at r2 (raw file):

Previously, Yoni-Starkware (Yoni) wrote…

Why in a separate mod?

I.e., why not make these the default serde for SecretFelt?

@m-kus m-kus left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@m-kus made 2 comments.
Reviewable status: 3 of 43 files reviewed, 2 unresolved discussions (waiting on Yoni-Starkware).


crates/discovery-core/src/test_fixtures.rs line 73 at r2 (raw file):

Previously, Yoni-Starkware (Yoni) wrote…

Anything else that should be marked as secret?

These are for tests anyways, I just made secret the ones we need - to reduce the casting boilerplate


crates/discovery-core/src/privacy_pool/types.rs line 79 at r2 (raw file):

Previously, Yoni-Starkware (Yoni) wrote…

I.e., why not make these the default serde for SecretFelt?

To avoid unintentional serialization

@Yoni-Starkware Yoni-Starkware left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Yoni-Starkware reviewed 2 files, made 1 comment, and resolved 1 discussion.
Reviewable status: 5 of 43 files reviewed, 2 unresolved discussions (waiting on m-kus).


crates/discovery-core/src/discovery/cursor.rs line 82 at r2 (raw file):

pub struct ChannelCursor {
    // TODO: Consider encrypting/masking channel_key in the serialized cursor
    // to avoid exposing it in plaintext (sensitive value).

The channel key is still exposed in the serialized cursor, right? Was this your intention? It doesn't seem so

Code quote:

    // TODO: Consider encrypting/masking channel_key in the serialized cursor
    // to avoid exposing it in plaintext (sensitive value).

@m-kus
m-kus force-pushed the 02-24-fix_discovery-core_handle_note_probing_gap branch from e27a5ed to 7115da6 Compare February 25, 2026 13:10
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from e60326a to 1a65d84 Compare February 25, 2026 13:10

@m-kus m-kus left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@m-kus made 1 comment.
Reviewable status: 4 of 46 files reviewed, 2 unresolved discussions (waiting on Yoni-Starkware).


crates/discovery-core/src/discovery/cursor.rs line 82 at r2 (raw file):

Previously, Yoni-Starkware (Yoni) wrote…

The channel key is still exposed in the serialized cursor, right? Was this your intention? It doesn't seem so

Resolved (likely rebasing artifact)

@m-kus
m-kus requested a review from Yoni-Starkware February 25, 2026 13:24
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from 1a65d84 to 40f2ed6 Compare February 25, 2026 13:27
@m-kus m-kus self-assigned this Feb 25, 2026

@Yoni-Starkware Yoni-Starkware left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Yoni-Starkware made 1 comment and resolved 1 discussion.
Reviewable status: 4 of 46 files reviewed, 1 unresolved discussion (waiting on m-kus).


crates/discovery-core/src/discovery/cursor.rs line 82 at r2 (raw file):

Previously, m-kus (Michael Zaikin) wrote…

Resolved (likely rebasing artifact)

No, I mean that the serde of channel_key looks like a normal Felt serde, while your TODO says that you want to mask it in the serialized cursor.

@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from 40f2ed6 to a63997f Compare February 26, 2026 11:04
@m-kus
m-kus force-pushed the 02-24-fix_discovery-core_handle_note_probing_gap branch from 7115da6 to 522935b Compare February 26, 2026 11:04

@m-kus m-kus left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@m-kus made 1 comment.
Reviewable status: 4 of 46 files reviewed, 1 unresolved discussion (waiting on m-kus and Yoni-Starkware).


crates/discovery-core/src/discovery/cursor.rs line 82 at r2 (raw file):

Previously, Yoni-Starkware (Yoni) wrote…

No, I mean that the serde of channel_key looks like a normal Felt serde, while your TODO says that you want to mask it in the serialized cursor.

Ah got it, yeah that's the intention - use secretfelt for sensitive keys, not adding additional app-level encryption (rely on tls)

@m-kus
m-kus force-pushed the 02-24-fix_discovery-core_handle_note_probing_gap branch from 522935b to a18d822 Compare February 26, 2026 18:05
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from a63997f to 5a1f287 Compare February 26, 2026 18:05
@m-kus
m-kus force-pushed the 02-24-fix_discovery-core_handle_note_probing_gap branch from a18d822 to e41eea7 Compare March 2, 2026 09:47
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from 5a1f287 to 2a855f3 Compare March 2, 2026 09:47

@Yoni-Starkware Yoni-Starkware left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:lgtm:

@Yoni-Starkware partially reviewed 42 files and all commit messages, made 1 comment, and resolved 1 discussion.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved (waiting on m-kus).

@m-kus
m-kus changed the base branch from 02-24-fix_discovery-core_handle_note_probing_gap to graphite-base/510 March 2, 2026 15:24
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from 2a855f3 to a79525b Compare March 2, 2026 15:28
@m-kus
m-kus changed the base branch from graphite-base/510 to main March 2, 2026 15:28
@m-kus
m-kus force-pushed the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch from a79525b to ca4b658 Compare March 2, 2026 15:30
@m-kus
m-kus merged commit af6cd46 into main Mar 2, 2026
9 checks passed
@m-kus
m-kus deleted the 02-18-feat_discovery_secret_zeroization_request_limits_error_sanitization branch March 2, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants