From fda79422624afe6cb6b2fd2251fb68431111adf6 Mon Sep 17 00:00:00 2001 From: Chris Duncan Date: Wed, 30 Sep 2026 17:23:01 -0700 Subject: [PATCH] Move mutex release into Mutex object for clarity of intent. --- src/lib/derive.ts | 4 ++-- src/lib/sign.ts | 4 ++-- src/lib/verify.ts | 6 +++--- src/lib/wasm.ts | 21 ++++++++++++--------- 4 files changed, 19 insertions(+), 16 deletions(-) diff --git a/src/lib/derive.ts b/src/lib/derive.ts index 160fa9b..3a40eae 100644 --- a/src/lib/derive.ts +++ b/src/lib/derive.ts @@ -2,7 +2,7 @@ //! SPDX-License-Identifier: GPL-3.0-or-later import { allocate, byteLength, bytesToHex, copy, fill, isBytes, normalize } from './primordials' -import { clearMemory, constants, getOutput, Mutex, setInput, derive as wasm_derive, } from './wasm' +import { Mutex, constants, getOutput, setInput, derive as wasm_derive, } from './wasm' const { KEY_BYTELENGTH, } = constants @@ -28,6 +28,6 @@ export function derive (prv: unknown, out?: unknown): string | void { } finally { fill(privateKey, 0) fill(publicKey, 0) - clearMemory() + Mutex.unlock() } } diff --git a/src/lib/sign.ts b/src/lib/sign.ts index 3f10308..ce11676 100644 --- a/src/lib/sign.ts +++ b/src/lib/sign.ts @@ -2,7 +2,7 @@ //! SPDX-License-Identifier: GPL-3.0-or-later import { allocate, byteLength, bytesToHex, copy, fill, isBytes, normalize } from './primordials' -import { Mutex, clearMemory, constants, getOutput, setInput, sign as wasm_sign } from './wasm' +import { Mutex, constants, getOutput, setInput, sign as wasm_sign, } from './wasm' const { KEY_BYTELENGTH, MAX_MESSAGE_BYTELENGTH, SIGNATURE_BYTELENGTH, } = constants @@ -33,6 +33,6 @@ export function sign (msg: unknown, prv: unknown, pub: unknown, out?: unknown): fill(privateKey, 0) fill(publicKey, 0) fill(signature, 0) - clearMemory() + Mutex.unlock() } } diff --git a/src/lib/verify.ts b/src/lib/verify.ts index a0b9aed..20eccd4 100644 --- a/src/lib/verify.ts +++ b/src/lib/verify.ts @@ -2,7 +2,7 @@ //! SPDX-License-Identifier: GPL-3.0-or-later import { allocate, byteLength, copy, isArray, normalize } from './primordials' -import { Mutex, clearMemory, constants, getOutput, setInput, verify as wasm_verify, verify_blocks as wasm_verify_blocks, } from './wasm' +import { Mutex, constants, getOutput, setInput, verify as wasm_verify, verify_blocks as wasm_verify_blocks, } from './wasm' const { BLOCKHASH_BYTELENGTH, KEY_BYTELENGTH, MAX_MESSAGE_BYTELENGTH, MAX_VERIFY_BLOCKS, SIGNATURE_BYTELENGTH, } = constants @@ -19,7 +19,7 @@ export function verify (sig: unknown, msg: unknown, pub: unknown): boolean { const verified = getOutput('verify', 0) return verified === 1 } finally { - clearMemory() + Mutex.unlock() } } @@ -62,6 +62,6 @@ export function verify_blocks (pub: unknown, data: unknown): boolean[] { } return verified } finally { - clearMemory() + Mutex.unlock() } } diff --git a/src/lib/wasm.ts b/src/lib/wasm.ts index d986d30..9d5578e 100644 --- a/src/lib/wasm.ts +++ b/src/lib/wasm.ts @@ -45,9 +45,21 @@ type Exports = WebAssembly.Instance['exports'] & { let locked = false export const Mutex = { + /** + * Sets a module-scoped variable to prevent reentry into the WASM module. This + * method *must* be called at the start of every `nano25519` API function. + */ lock (): void { if (locked) throw new Nano25519TypeError('Failed to acquire mutex') locked = true + }, + /** + * Tells the WASM module to clear its own I/O buffers internally, and then + * releases the mutex lock. + */ + unlock (): void { + exports.clearMemory() + locked = false } } @@ -286,15 +298,6 @@ function setInputSig (sig: Bytes): void { setInputSigEndian(s) } -/** - * Tells the WASM module to clear its own I/O buffers internally, and then - * releases the mutex lock. - */ -export function clearMemory (): void { - exports.clearMemory() - locked = false -} - export const constants = { BLOCKHASH_BYTELENGTH, KEY_BYTELENGTH, -- 2.52.0