{"record":{"id":"84b181983ebcdbdf","repo":"siyuan-note/siyuan","slug":"argon2id-parallelism-must-be-between-1-and-16","errorCode":null,"errorMessage":"Argon2id Parallelism must be between 1 and 16","messagePattern":"Argon2id Parallelism must be between 1 and 16","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/util/kdf.go","lineNumber":80,"sourceCode":"// 或过弱参数降低安全性。\nfunc ValidateArgon2Params(p Argon2Params) (Argon2Params, error) {\n\tif p.KeyLength != 32 {\n\t\treturn p, errors.New(\"Argon2id KeyLength must be 32\")\n\t}\n\tif p.Memory < 64*1024 {\n\t\treturn p, errors.New(\"Argon2id Memory too low (minimum 64 MB)\")\n\t}\n\tif p.Memory > 256*1024 {\n\t\treturn p, errors.New(\"Argon2id Memory too high (maximum 256 MB)\")\n\t}\n\tif p.Iterations < 3 {\n\t\treturn p, errors.New(\"Argon2id Iterations too low (minimum 3)\")\n\t}\n\tif p.Iterations > 10 {\n\t\treturn p, errors.New(\"Argon2id Iterations too high (maximum 10)\")\n\t}\n\tif p.Parallelism == 0 || p.Parallelism > 16 {\n\t\treturn p, errors.New(\"Argon2id Parallelism must be between 1 and 16\")\n\t}\n\treturn p, nil\n}\n\n// DeriveKey 用 Argon2id 从密码派生密钥。同一 password+salt+params 多次调用结果一致。\nfunc DeriveKey(password string, salt []byte, p Argon2Params) []byte {\n\treturn argon2.IDKey([]byte(password), salt, p.Iterations, p.Memory, p.Parallelism, p.KeyLength)\n}\n\n// Encrypt 用 AES-256-GCM 加密。每次调用生成随机 nonce，因此同一明文多次加密结果不同。\n// 返回格式：magic(4B) || spec(1B) || algorithm(1B) || nonceLength(1B) || nonce || ciphertext || GCM tag(16B)。\nfunc Encrypt(key, plaintext []byte) ([]byte, error) {\n\treturn encryptGCM(key, plaintext, nil, \"Encrypt\")\n}\n\n// Decrypt 对应 Encrypt 的解密。密钥错误、格式无效或密文被篡改时返回错误。\nfunc Decrypt(key, ciphertext []byte) ([]byte, error) {\n\treturn decryptGCM(key, ciphertext, nil, \"Decrypt\")","sourceCodeStart":62,"sourceCodeEnd":98,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/util/kdf.go#L62-L98","documentation":"ValidateArgon2Params requires Parallelism (number of Argon2id lanes/threads) to be between 1 and 16 inclusive. Zero would be invalid input to the Argon2 function and oversized values could oversubscribe CPUs, so both are rejected.","triggerScenarios":"Calling ValidateArgon2Params (directly or via EnableEncryptedNotebook, ImportNotebookCryptoBackup, deriveKEK, or backup-restore paths) with Argon2Params.Parallelism == 0 or > 16 — commonly a zero-value struct where Parallelism was never set.","commonSituations":"Constructing Argon2Params without setting Parallelism (uint8 zero value), deserializing a config JSON that lacks the 'parallelism' key, or copying parallelism from a machine with many cores (e.g. 32 threads).","solutions":["Set Parallelism to a value in 1-16; util.DefaultArgon2Params() uses 4","Unmarshal the config into a struct pre-populated with util.DefaultArgon2Params() so a missing 'parallelism' key doesn't yield 0","Cap parallelism from runtime.NumCPU() at 16 before validating"],"exampleFix":"// before\np := util.Argon2Params{Memory: 64 * 1024, Iterations: 3, KeyLength: 32} // Parallelism zero\n\n// after\np := util.Argon2Params{Memory: 64 * 1024, Iterations: 3, Parallelism: 4, KeyLength: 32}","handlingStrategy":"validation","validationCode":"if p.Parallelism == 0 || p.Parallelism > 16 {\n    return fmt.Errorf(\"parallelism must be 1-16, got %d\", p.Parallelism)\n}","typeGuard":null,"tryCatchPattern":"if _, err := util.ValidateArgon2Params(p); err != nil {\n    return fmt.Errorf(\"invalid KDF params: %w\", err)\n}","preventionTips":["Always set Parallelism explicitly (default 4) when constructing Argon2Params","Derive it from min(runtime.NumCPU(), 16) rather than raw core count","Use DefaultArgon2Params() as the unmarshal target so missing keys keep sane values"],"tags":["kdf","argon2id","validation","zero-value","config"],"backgroundTag":"value-out-of-range","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}