Skip to content

fix(scrypt): reject parallelism other than 1 for yescrypt - #356

Merged
james-d-elliott merged 1 commit into
masterfrom
fix/yescrypt-parallelism-validation
Sep 25, 2026
Merged

james-d-elliott merged 1 commit into
masterfrom
fix/yescrypt-parallelism-validation

Conversation

@james-d-elliott

@james-d-elliott james-d-elliott commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

The yescrypt key derivation only supports a parallelism of 1 and the yescrypt encoding has no field for it, but the hasher accepted any value from WithP during validation. A hasher configured with the yescrypt variant and a parallelism greater than 1 was therefore created without error and then failed on every call to Hash.

Validation now rejects a parallelism other than 1 for the yescrypt variant so the misconfiguration is reported when the hasher is created. The scrypt variant is unaffected.

Summary by CodeRabbit

  • Bug Fixes
    • Yescrypt configurations now reject parallelism values other than 1 with a parameter validation error. Other Scrypt configurations continue to support higher values.
  • Documentation
    • Clarified that yescrypt supports a parallelism value of 1 only.

The yescrypt key derivation only supports a parallelism of 1 and the
yescrypt encoding has no field for it, but the hasher accepted any value
from WithP during validation. A hasher configured with the yescrypt
variant and a parallelism greater than 1 was therefore created without
error and then failed on every call to Hash.

Validation now rejects a parallelism other than 1 for the yescrypt
variant so the misconfiguration is reported when the hasher is created.
The scrypt variant is unaffected.
@james-d-elliott
james-d-elliott requested a review from a team as a code owner September 25, 2026 01:39
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 00987d0f-1700-4f13-b8c6-24eb9bb9161b

📥 Commits

Reviewing files that changed from the base of the PR and between c8faeb5 and 8b66066.

📒 Files selected for processing (3)
  • algorithm/scrypt/hasher.go
  • algorithm/scrypt/opts.go
  • algorithm/scrypt/regression_test.go

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Yescrypt validation now rejects parallelism values greater than 1 with algorithm.ErrParameterInvalid. The WithP documentation states this limit. Regression tests cover rejected yescrypt configurations and successful hashing for supported yescrypt and scrypt values.

Changes

Yescrypt parallelism validation

Layer / File(s) Summary
Validate yescrypt parallelism
algorithm/scrypt/hasher.go, algorithm/scrypt/opts.go, algorithm/scrypt/regression_test.go
Validation rejects yescrypt configurations with p greater than 1. The WithP documentation states the limit. Tests check rejection and successful hash encoding, decoding, and matching for yescrypt with p=1 and scrypt with p=2.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 8b660

Unsupported yescrypt parallelism is rejected during hasher creation, with no actionable merge risk identified in the supplied evidence.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8b660

The change rejects an unsupported yescrypt setting earlier, without an identified new security exposure. Callers using that setting will receive an error at construction, so the behavior change is worth reviewing even though its scope appears limited.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The identified behavior change is at hasher configuration, before hashing. The changed test ranges do not add production entrypoints; downstream application exposure is not established by the available evidence.

Trust Boundaries and Controls

  • observed — Constructor validation rejects unsupported yescrypt parallelism before returning a hasher; the identified tests exercise that control through NewYescrypt rather than bypassing it.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 28.57% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: rejecting yescrypt parallelism values other than 1.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.13.2)

Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions
The command is terminated due to an error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 83.33%. Comparing base (6b59085) to head (8b66066).
⚠️ Report is 10 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #356      +/-   ##
==========================================
+ Coverage   82.28%   83.33%   +1.04%     
==========================================
  Files          49       49              
  Lines        1716     1746      +30     
==========================================
+ Hits         1412     1455      +43     
+ Misses        304      291      -13     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@james-d-elliott

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@james-d-elliott
james-d-elliott merged commit b2eae9f into master Sep 25, 2026
13 checks passed
@james-d-elliott
james-d-elliott deleted the fix/yescrypt-parallelism-validation branch September 25, 2026 01:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant