Skip to content

fix(argon2): validate memory against effective parallelism - #349

Merged
james-d-elliott merged 1 commit into
masterfrom
fix/argon2-memory-validation
Sep 24, 2026
Merged

james-d-elliott merged 1 commit into
masterfrom
fix/argon2-memory-validation

Conversation

@james-d-elliott

@james-d-elliott james-d-elliott commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

The hasher validated the memory parameter against the configured parallelism, which is 0 when unset, while the digest later applied the default parallelism of 4. This allowed options such as WithM(30) to pass validation, after which the memory was rounded down to 16 and the resulting digest was rejected by the decoder, making it impossible to verify.

Validation now uses the parallelism and memory values that will actually be applied, and Hash and HashWithSalt validate the hasher so that unvalidated hashers can no longer produce undecodable digests.

Summary by CodeRabbit

  • Bug Fixes
    • Argon2 hashing now validates configuration before generating a hash, including when a hasher is configured directly. Invalid memory settings are rejected with an error that reflects the effective parallelism and memory limits.
    • Hashes created with default parallelism and supported memory settings now round-trip successfully through encoding, decoding, and matching.

The hasher validated the memory parameter against the configured
parallelism, which is 0 when unset, while the digest later applied the
default parallelism of 4. This allowed options such as WithM(30) to pass
validation, after which the memory was rounded down to 16 and the
resulting digest was rejected by the decoder, making it impossible to
verify.

Validation now uses the parallelism and memory values that will actually
be applied, and Hash and HashWithSalt validate the hasher so that
unvalidated hashers can no longer produce undecodable digests.
@james-d-elliott
james-d-elliott requested a review from a team as a code owner September 24, 2026 11:04
@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 2073ee4a-994c-4c65-b94a-d0ea18bac830

📥 Commits

Reviewing files that changed from the base of the PR and between 4aa856f and 3d86b19.

📒 Files selected for processing (2)
  • algorithm/argon2/hasher.go
  • algorithm/argon2/regression_test.go

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Hash and HashWithSalt now validate parameters before hashing. Validation applies effective parallelism and memory defaults when checking memory bounds. Regression tests cover invalid memory values and digest round trips at default parallelism.

Changes

Argon2 parameter validation

Layer / File(s) Summary
Effective parameter validation
algorithm/argon2/hasher.go, algorithm/argon2/regression_test.go
Hash and HashWithSalt call validate() before hashing. Validation applies effective defaults when enforcing memory bounds and reporting errors. Tests cover invalid memory values and digest round trips at default parallelism.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 3d86b

The Argon2 validation change is mergeable after normal checks; no concrete remaining risk is established.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: validating Argon2 memory against effective parallelism.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.13.2)

Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions
The command is terminated due to an error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 91.66667% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 82.70%. Comparing base (6b59085) to head (3d86b19).
⚠️ Report is 2 commits behind head on master.

Files with missing lines Patch % Lines
algorithm/argon2/hasher.go 91.66% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master     #349      +/-   ##
==========================================
+ Coverage   82.28%   82.70%   +0.42%     
==========================================
  Files          49       49              
  Lines        1716     1723       +7     
==========================================
+ Hits         1412     1425      +13     
+ Misses        304      298       -6     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@james-d-elliott
james-d-elliott merged commit 5266c5b into master Sep 24, 2026
13 checks passed
@james-d-elliott
james-d-elliott deleted the fix/argon2-memory-validation branch September 24, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant