fix(scrypt): reject parallelism other than 1 for yescrypt - #356
Conversation
The yescrypt key derivation only supports a parallelism of 1 and the yescrypt encoding has no field for it, but the hasher accepted any value from WithP during validation. A hasher configured with the yescrypt variant and a parallelism greater than 1 was therefore created without error and then failed on every call to Hash. Validation now rejects a parallelism other than 1 for the yescrypt variant so the misconfiguration is reported when the hasher is created. The scrypt variant is unaffected.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughYescrypt validation now rejects parallelism values greater than 1 with ChangesYescrypt parallelism validation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Unsupported yescrypt parallelism is rejected during hasher creation, with no actionable merge risk identified in the supplied evidence. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change rejects an unsupported yescrypt setting earlier, without an identified new security exposure. Callers using that setting will receive an error at construction, so the behavior change is worth reviewing even though its scope appears limited. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 golangci-lint (2.13.2)Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #356 +/- ##
==========================================
+ Coverage 82.28% 83.33% +1.04%
==========================================
Files 49 49
Lines 1716 1746 +30
==========================================
+ Hits 1412 1455 +43
+ Misses 304 291 -13 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
The yescrypt key derivation only supports a parallelism of 1 and the yescrypt encoding has no field for it, but the hasher accepted any value from WithP during validation. A hasher configured with the yescrypt variant and a parallelism greater than 1 was therefore created without error and then failed on every call to Hash.
Validation now rejects a parallelism other than 1 for the yescrypt variant so the misconfiguration is reported when the hasher is created. The scrypt variant is unaffected.
Summary by CodeRabbit