{"record":{"id":"c3c9bef94e3dd441","repo":"siyuan-note/siyuan","slug":"argon2id-memory-too-low-minimum-64-mb","errorCode":null,"errorMessage":"Argon2id Memory too low (minimum 64 MB)","messagePattern":"Argon2id Memory too low \\(minimum 64 MB\\)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/util/kdf.go","lineNumber":68,"sourceCode":"\n// DefaultArgon2Params 返回 OWASP 2023 推荐的 Argon2id 参数。\nfunc DefaultArgon2Params() Argon2Params {\n\treturn Argon2Params{\n\t\tMemory:      64 * 1024,\n\t\tIterations:  3,\n\t\tParallelism: 4,\n\t\tKeyLength:   32,\n\t}\n}\n\n// ValidateArgon2Params 校验 Argon2id 参数是否在合理范围内，防止恶意备份设置极大内存导致 OOM，\n// 或过弱参数降低安全性。\nfunc ValidateArgon2Params(p Argon2Params) (Argon2Params, error) {\n\tif p.KeyLength != 32 {\n\t\treturn p, errors.New(\"Argon2id KeyLength must be 32\")\n\t}\n\tif p.Memory < 64*1024 {\n\t\treturn p, errors.New(\"Argon2id Memory too low (minimum 64 MB)\")\n\t}\n\tif p.Memory > 256*1024 {\n\t\treturn p, errors.New(\"Argon2id Memory too high (maximum 256 MB)\")\n\t}\n\tif p.Iterations < 3 {\n\t\treturn p, errors.New(\"Argon2id Iterations too low (minimum 3)\")\n\t}\n\tif p.Iterations > 10 {\n\t\treturn p, errors.New(\"Argon2id Iterations too high (maximum 10)\")\n\t}\n\tif p.Parallelism == 0 || p.Parallelism > 16 {\n\t\treturn p, errors.New(\"Argon2id Parallelism must be between 1 and 16\")\n\t}\n\treturn p, nil\n}\n\n// DeriveKey 用 Argon2id 从密码派生密钥。同一 password+salt+params 多次调用结果一致。\nfunc DeriveKey(password string, salt []byte, p Argon2Params) []byte {","sourceCodeStart":50,"sourceCodeEnd":86,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/util/kdf.go#L50-L86","documentation":"ValidateArgon2Params enforces a lower bound of 64 MB (64*1024 KiB) on the Argon2id memory parameter. Too little memory makes the key derivation weak against GPU/ASIC brute-force attacks, so the library rejects such configurations to keep encrypted-notebook key derivation within its security budget.","triggerScenarios":"Calling ValidateArgon2Params (directly or via deriveKEK / EnableEncryptedNotebook / backup import-restore paths) with Argon2Params.Memory below 64*1024 — e.g. a hand-edited crypto config, a backup exported with weaker parameters, or a struct defaulting Memory to 0.","commonSituations":"Users manually lowering memory in the encrypted-notebook settings to speed up unlock; importing a crypto backup generated by modified tooling with weak parameters; code constructing Argon2Params without initializing Memory; config corruption resetting the field.","solutions":["Set Memory to at least 64*1024 (64 MB) in Argon2Params","If the value came from an imported backup, re-export the backup with default/valid parameters, or use a backup whose parameters authenticate successfully","For faster unlock times, tune Iterations/parallelism within allowed ranges instead of dropping memory below the floor","If restoring is impossible, recover from a valid notebook crypto backup; never bypass validation or discard keys"],"exampleFix":"// before\np := util.Argon2Params{Memory: 16 * 1024, Iterations: 3, KeyLength: 32} // 16 MB — too low\n_, err := util.ValidateArgon2Params(p)\n// after\np := util.Argon2Params{Memory: 64 * 1024, Iterations: 3, KeyLength: 32}\n_, err := util.ValidateArgon2Params(p) // ok","handlingStrategy":"validation","validationCode":"if p.Memory < 64*1024 || p.Memory > 256*1024 { return fmt.Errorf(\"Memory must be 64-256 MB, got %d\", p.Memory) }\n// then call util.ValidateArgon2Params(p)","typeGuard":"func hasValidMemory(p util.Argon2Params) bool { return p.Memory >= 64*1024 && p.Memory <= 256*1024 }","tryCatchPattern":"if _, err := util.ValidateArgon2Params(p); err != nil && strings.Contains(err.Error(), \"Memory too low\") {\n    p.Memory = 64 * 1024 // clamp to the minimum, then retry\n}","preventionTips":["Clamp Memory to 64-256 MB before validation","Never hand-edit the encrypted-notebook crypto config values","Re-export backups with official tooling if parameters were weakened"],"tags":["kdf","argon2","encryption","validation"],"backgroundTag":"value-out-of-range","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}