Skip to content

[OC-058] Implement cryptographic panic erase #59

Description

@tcballard

Gate: G5 — Packaging, hardening, and release

Planning source: validated implementation plan PR #1


  • Depends on: OC-010, OC-052.
  • Deliverable: daemon transaction that stops transports, rejects new clients, zeroizes memory, deletes Secret Service/file master keys, unlinks state, syncs metadata, and regenerates only on next start; ctl/TUI confirmations.
  • Acceptance: previously captured ciphertext cannot decrypt after panic; all upstream-listed state is absent on restart; tests document CoW/snapshot/SSD/network-copy limits; no claim of guaranteed physical overwrite.
  • Excludes: remote deletion from relays/peers.

Maintainer reconciliation — 2026-09-04

Next closure evidence/work: Run actual Secret Service panic deletion; audit coverage of newer account/registry/room state and integrate #225 confirmation changes.

Baseline reviewed: main 87c3bcb7d65e3e2ab8ae317694b751f8efe9a8ed. Implementation presence is not a live conformance claim.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions