BigPizzaV3/CodexPlusPlus · error

分享会话解密失败

Error message

分享会话解密失败

What it means

decrypt_shared_payload decodes the base64 iv/ciphertext, checks key/iv lengths and ciphertext bounds, then decrypts the share payload with AES-256-GCM. This error fires when the decryption (or its authentication tag verification) fails — the share link key is wrong, the URL was tampered with, or the ciphertext is corrupted.

Source

Thrown at crates/codex-plus-core/src/session_share.rs:142

            .get(field)
            .and_then(Value::as_str)
            .with_context(|| format!("分享数据缺少 {field}"))?;
        base64::engine::general_purpose::URL_SAFE_NO_PAD
            .decode(value)
            .with_context(|| format!("分享数据 {field} 无效"))
    };
    let key = base64::engine::general_purpose::URL_SAFE_NO_PAD
        .decode(key_value)
        .context("分享链接解密密钥无效")?;
    let iv = decode("iv")?;
    let ciphertext = decode("ciphertext")?;
    if key.len() != 32 || iv.len() != 12 || ciphertext.len() > MAX_ROLLOUT_BYTES + 16 {
        bail!("分享数据大小或格式无效");
    }
    let cipher = Aes256Gcm::new_from_slice(&key).context("创建会话解密器失败")?;
    cipher
        .decrypt(Nonce::from_slice(&iv), ciphertext.as_ref())
        .map_err(|_| anyhow::anyhow!("分享会话解密失败"))
}

pub fn import_rollout_file(home: &Path, source_path: &Path) -> anyhow::Result<Value> {
    let bytes = fs::read(source_path)
        .with_context(|| format!("读取会话文件失败:{}", source_path.display()))?;
    if bytes.len() > MAX_ROLLOUT_BYTES {
        bail!("会话文件超过导入大小限制");
    }
    let content = String::from_utf8(bytes).context("会话文件不是有效的 UTF-8")?;
    if let Ok(payload) = serde_json::from_str::<Value>(&content)
        && payload.get("kind").and_then(Value::as_str) == Some("codex-rollout")
    {
        return import_rollout(home, &payload);
    }
    let session_id = find_session_id(&content)
        .or_else(|| {
            source_path
                .file_stem()

View on GitHub (pinned to f2074595a2)

Solutions

  1. Regenerate the share link; the key/URL may be stale or mistyped
  2. Confirm the full share URL was copied without truncation
  3. Verify the ciphertext was not modified in transit
Defensive patterns

Strategy: try-catch

When it happens

Trigger: Thrown at crates/codex-plus-core/src/session_share.rs:142 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of BigPizzaV3/CodexPlusPlus@f2074595a2 (2026-08-23). Data as JSON: /api/errors/92debf5d534020c3. Report an issue: GitHub.