Skip to content

fix(md5crypt): apply the default iterations for the sun variant - #353

Merged
james-d-elliott merged 1 commit into
masterfrom
fix/md5crypt-default-iterations
Sep 24, 2026
Merged

james-d-elliott merged 1 commit into
masterfrom
fix/md5crypt-default-iterations

Conversation

@james-d-elliott

@james-d-elliott james-d-elliott commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

The documented default of 34000 iterations was never applied. The only place it was set compared the uint32 iterations against an IterationsMin of 0, which can never be true, so the Sun variant always defaulted to 0 additional rounds.

The hasher now tracks whether iterations were explicitly configured and applies IterationsDefault when they were not, following the same approach as sha1crypt. An explicit WithIterations(0) is still honoured. The unreachable check in Digest.defaults is removed, and the WithIterations documentation now reflects the rounds parameter and the actual maximum.

Digests produced by the Sun variant with default options will now include rounds=34000. Existing digests are unaffected.

Summary by CodeRabbit

  • Bug Fixes
    • Explicitly configured iteration counts are now preserved, including a setting of zero. Digests created with zero iterations use the rounds-free format and can be verified.
    • The Sun variant now defaults to 34,000 rounds, while the standard variant retains its existing format. Digests for both variants correctly verify matching passwords and reject incorrect ones.
  • Documentation
    • Clarified how iteration counts are encoded and corrected the documented maximum value.

The documented default of 34000 iterations was never applied. The only
place it was set compared the uint32 iterations against an
IterationsMin of 0, which can never be true, so the Sun variant always
defaulted to 0 additional rounds.

The hasher now tracks whether iterations were explicitly configured and
applies IterationsDefault when they were not, following the same
approach as sha1crypt. An explicit WithIterations(0) is still honoured.
The unreachable check in Digest.defaults is removed, and the
WithIterations documentation now reflects the rounds parameter and the
actual maximum.

Digests produced by the Sun variant with default options will now
include rounds=34000. Existing digests are unaffected.
@james-d-elliott
james-d-elliott requested a review from a team as a code owner September 24, 2026 11:19
@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9824ea22-4418-462d-adc3-5be5ff41c60e

📥 Commits

Reviewing files that changed from the base of the PR and between 5266c5b and 8fabdbd.

📒 Files selected for processing (4)
  • algorithm/md5crypt/digest.go
  • algorithm/md5crypt/hasher.go
  • algorithm/md5crypt/opts.go
  • algorithm/md5crypt/regression_test.go
💤 Files with no reviewable changes (1)
  • algorithm/md5crypt/digest.go

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

MD5crypt now preserves explicitly configured iteration counts, including zero, and applies the default count only when iterations were not set. Regression tests cover Sun and standard variant encoding and password verification.

Changes

MD5crypt iteration handling

Layer / File(s) Summary
Preserve configured iterations
algorithm/md5crypt/hasher.go, algorithm/md5crypt/opts.go, algorithm/md5crypt/digest.go, algorithm/md5crypt/regression_test.go
Hasher tracks whether iterations were explicitly set. Defaults apply only when they were not set, and digest initialization no longer resets values below the minimum. Regression tests cover the Sun default of 34,000 rounds, explicitly setting zero rounds, and the standard variant’s $1$ format. The option documentation names the encoded parameter rounds and lists the maximum as 4294963199.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 8fabd

Omitted Sun iterations now use the 34,000 rounds setting, while explicit zero and standard-variant behavior are preserved. The available repository evidence shows no concrete merge-blocking regression.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: applying the default iteration count for the Sun variant in md5crypt.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.13.2)

Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions
The command is terminated due to an error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.77%. Comparing base (6b59085) to head (8fabdbd).
⚠️ Report is 6 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #353      +/-   ##
==========================================
+ Coverage   82.28%   82.77%   +0.48%     
==========================================
  Files          49       49              
  Lines        1716     1724       +8     
==========================================
+ Hits         1412     1427      +15     
+ Misses        304      297       -7     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@james-d-elliott

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 14 minutes.

@james-d-elliott

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

@james-d-elliott

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@james-d-elliott
james-d-elliott merged commit 55f8a3c into master Sep 24, 2026
13 checks passed
@james-d-elliott
james-d-elliott deleted the fix/md5crypt-default-iterations branch September 24, 2026 22:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant