fix(argon2): validate memory against effective parallelism - #349
Conversation
The hasher validated the memory parameter against the configured parallelism, which is 0 when unset, while the digest later applied the default parallelism of 4. This allowed options such as WithM(30) to pass validation, after which the memory was rounded down to 16 and the resulting digest was rejected by the decoder, making it impossible to verify. Validation now uses the parallelism and memory values that will actually be applied, and Hash and HashWithSalt validate the hasher so that unvalidated hashers can no longer produce undecodable digests.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
ChangesArgon2 parameter validation
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The Argon2 validation change is mergeable after normal checks; no concrete remaining risk is established. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 golangci-lint (2.13.2)Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## master #349 +/- ##
==========================================
+ Coverage 82.28% 82.70% +0.42%
==========================================
Files 49 49
Lines 1716 1723 +7
==========================================
+ Hits 1412 1425 +13
+ Misses 304 298 -6 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
The hasher validated the memory parameter against the configured parallelism, which is 0 when unset, while the digest later applied the default parallelism of 4. This allowed options such as WithM(30) to pass validation, after which the memory was rounded down to 16 and the resulting digest was rejected by the decoder, making it impossible to verify.
Validation now uses the parallelism and memory values that will actually be applied, and Hash and HashWithSalt validate the hasher so that unvalidated hashers can no longer produce undecodable digests.
Summary by CodeRabbit