memfd-secret
v1.0.0
Published
Allocate Node Buffers backed by Linux memfd_secret(2) secret memory
Downloads
216
Maintainers
Readme
memfd-secret
Allocate Node.js Buffers backed by Linux memfd_secret(2): anonymous RAM whose pages are dropped from the kernel direct map so other processes (and most kernel paths) cannot read them via get_user_pages.
This is not an enclave or SGX. Userspace in this process can still read the Buffer. JavaScript can still copy bytes (toString(), spreading into other Buffers, some crypto APIs). Hibernation is inhibited while mappings exist.
Requirements
- Linux 5.14+
- Before Linux 6.5, boot with
secretmem.enable=y(orsecretmem.enable=1) - Some kernels (including current WSL) reject
FD_CLOEXECin the syscall flags; this library uses flags0and thenfcntl(FD_CLOEXEC) - Mappings count against
RLIMIT_MEMLOCKlikemlock(2) - A C++ toolchain;
npm installruns"install": "node-gyp rebuild"
Install
npm install memfd-secretLinux-only ("os": ["linux"]).
API
const { isSupported, alloc, wipe, close } = require('memfd-secret')
if (!isSupported()) {
throw new Error('memfd_secret unavailable')
}
const buf = alloc(32)
buf.write('hello')
wipe(buf) // explicit_bzero over the full page-rounded mapping
close(buf) // wipe + munmap + close fd (idempotent)| Function | Description |
| --- | --- |
| isSupported() | Probe the syscall once and cache the result |
| alloc(size) | Buffer of size bytes. size must be a positive integer. Throws ENOSYS when unavailable |
| wipe(buf) | Zero the mapping. Throws if buf did not come from alloc or was already closed |
| close(buf) | Wipe, unmap, close the memfd. Safe to call twice. Do not read/write buf afterwards |
buf.length is the requested size. The kernel mapping is rounded up to the page size; wipe/close always cover the full mapping.
If you never call close, a native finalizer still disposes the mapping when the Buffer is garbage-collected.
Do not pass the Buffer into syscalls
The kernel cannot access these pages. fs.write(fd, buf), read, and similar will fail or fault. Use userspace copies if you must leave secret memory.
License
MIT
