java-topology/defects/wireguard-go/patch/CLEAN.md
russell@unturf.com efe58242e0 wine: all 5 MOADs CLEAN (wine-0001 pre-existing); wireguard-go: all 5 MOADs CLEAN
Wine scan: hot paths use hash tables (module lookup), red-black trees (font
families, shader cache), binary search (registry), bounded lists (FBO<=64,
sampler<=16, MUI<=8). wine-0001 covers loader dependency dedup. No additional
CWE-407 defects. MOADs 0002-0005 CLEAN: loader_section is by design, no
request-scoped TLS leakage, kerberos logs only auth_data pointer (not value),
all caches protected by critical sections.

WireGuard-go scan: peers.keyMap is hash map O(1), AllowedIPs is radix trie O(32).
Private key and PSK are never logged (only "Updating X" labels). Device struct
has per-sub-struct sync.RWMutex with no thundering herd patterns. MOADs 0002-0005
CLEAN: well-decomposed Device struct, no goroutine-local leakage, proper sync.
2026-03-31 20:10:00 -04:00

3.8 KiB

CLEAN — WireGuard/wireguard-go — all 5 MOADs scanned 2026-03-31

Repository: https://github.com/WireGuard/wireguard-go Version: HEAD (depth=1 clone) Language: Go Size: ~40 Go source files

Note: wireguard-tools (C userspace tools) was scanned previously and is CLEAN. This entry covers wireguard-go (pure Go userspace WireGuard implementation).

MOAD-0001 (CWE-407): CLEAN

Hot paths scanned:

device/device.go: peer lookup uses peers.keyMap (map[NoisePublicKey]*Peer) — O(1) hash map per peer lookup. No linear scan of peer list in the packet path.

device/allowedips.go: AllowedIPs uses a radix trie (256-ary, one level per bit). IP-to-peer lookup is O(32) for IPv4 or O(128) for IPv6 — bounded and constant. Not a linear scan. CLEAN.

device/receive.go: ReceiveIPv4/ReceiveIPv6 batch processing loops are O(batch_size) with no inner membership scans. Handshake queue processing dispatches by index table (IndexTable, which is map[uint32]*indexTableEntry). CLEAN.

device/uapi.go: UAPI config parsing scans device.peers.keyMap for peer lookup — O(P) configuration-time only, not per-packet. P = number of peers (bounded by WireGuard protocol limits, typically < 10,000). CLEAN.

MOAD-0002 (Intertangle): CLEAN

Device struct (device/device.go) is well-decomposed into named sub-structs: state (atomic + Mutex), net (RWMutex + bind/port/fwmark), staticIdentity (RWMutex + privateKey/publicKey), peers (RWMutex + keyMap), rate, pool, queue, tun. Each sub-struct owns its own mutex.

No god-object pattern: cryptographic handshake (noise-protocol.go) is isolated from packet routing (allowedips.go), session key management (keypair.go), and rate limiting (ratelimiter/). Subsystems communicate through channel queues (device.queue.handshake, device.queue.encryption, device.queue.decryption), not shared mutable global state.

MOAD-0003 (Leaked Context): CLEAN

No goroutine-local state beyond sync.Pool buffers (byteBufferPool). Go does not have goroutine-local storage; the design relies on explicit context propagation.

context.Context is used only in ipc/namedpipe (Windows IPC) and tun/netstack (virtual network stack) — both pass context explicitly, not via goroutine-local storage. No request-scoped identity leaked across goroutine boundaries.

MOAD-0004 (Logged Secret): CLEAN

device/uapi.go:

  • private_key handling: device.log.Verbosef("UAPI: Updating private key") — logs label only, never logs the key value. The key bytes come from sk.FromMaybeZeroHex(value) and are passed to device.SetPrivateKey(sk). Value is never interpolated into any log call. CLEAN.
  • preshared_key handling: device.log.Verbosef("%v - UAPI: Updating preshared key", peer.Peer) — logs peer identifier and label only. Key bytes from peer.handshake.presharedKey.FromHex(value) are never logged. CLEAN.

device/noise-protocol.go: no log calls that reference key material. Handshake state transitions logged as enum values (ConsumeMessageInitiation: handshake replay, flood). No Curve25519 private key, ChaCha20-Poly1305 session key, or PSK ever interpolated into log output.

CRITICAL CHECK PASSED: no private key or pre-shared key logging found anywhere.

MOAD-0005 (Thundering Herd): CLEAN

device/device.go: all peer map access guarded by peers.RWMutex (readers use RLock, writers use Lock). No check-null-compute-put pattern.

device/noise-protocol.go: handshake state uses handshake.mutex (sync.RWMutex). Keypair rotation uses atomic operations (keypairs struct with Next/Current/Previous protected by sync.RWMutex).

device/allowedips.go: AllowedIPs mutations protected by mutex (sync.RWMutex at AllowedIPs struct level). Trie updates hold the write lock throughout.

device/keypair.go: keypair store uses sync.RWMutex for all access.

ratelimiter/: uses sync.Mutex for table access, time.Ticker for GC — properly synchronized.

No unsynchronized cache get+null+compute+put pattern found in any hot path.