SDK

MemoryLockWarning

Emitted once when the OS refused to lock at least one secret in RAM. The secret still has guard pages, no-dump and zero-on-drop; what it lost is the guarantee of never reaching swap. The fix is operational, not in code: raise `ulimit -l`, grant `CAP_IPC_LOCK`, or set `DIAGNOS_MEMORY_LOCK=require` to refuse to run this way.

On this page

exception

Signature #

class MemoryLockWarning

Bases: RuntimeWarning

Emitted once when the OS refused to lock at least one secret in RAM.

The secret still has guard pages, no-dump and zero-on-drop; what it lost is the guarantee of never reaching swap. The fix is operational, not in code: raise ulimit -l, grant CAP_IPC_LOCK, or set DIAGNOS_MEMORY_LOCK=require to refuse to run this way.