{"record":{"id":"ef11b80c39a3477e","repo":"siyuan-note/siyuan","slug":"argon2id-memory-too-high-maximum-256-mb","errorCode":null,"errorMessage":"Argon2id Memory too high (maximum 256 MB)","messagePattern":"Argon2id Memory too high \\(maximum 256 MB\\)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/util/kdf.go","lineNumber":71,"sourceCode":"\treturn Argon2Params{\n\t\tMemory:      64 * 1024,\n\t\tIterations:  3,\n\t\tParallelism: 4,\n\t\tKeyLength:   32,\n\t}\n}\n\n// ValidateArgon2Params 校验 Argon2id 参数是否在合理范围内，防止恶意备份设置极大内存导致 OOM，\n// 或过弱参数降低安全性。\nfunc ValidateArgon2Params(p Argon2Params) (Argon2Params, error) {\n\tif p.KeyLength != 32 {\n\t\treturn p, errors.New(\"Argon2id KeyLength must be 32\")\n\t}\n\tif p.Memory < 64*1024 {\n\t\treturn p, errors.New(\"Argon2id Memory too low (minimum 64 MB)\")\n\t}\n\tif p.Memory > 256*1024 {\n\t\treturn p, errors.New(\"Argon2id Memory too high (maximum 256 MB)\")\n\t}\n\tif p.Iterations < 3 {\n\t\treturn p, errors.New(\"Argon2id Iterations too low (minimum 3)\")\n\t}\n\tif p.Iterations > 10 {\n\t\treturn p, errors.New(\"Argon2id Iterations too high (maximum 10)\")\n\t}\n\tif p.Parallelism == 0 || p.Parallelism > 16 {\n\t\treturn p, errors.New(\"Argon2id Parallelism must be between 1 and 16\")\n\t}\n\treturn p, nil\n}\n\n// DeriveKey 用 Argon2id 从密码派生密钥。同一 password+salt+params 多次调用结果一致。\nfunc DeriveKey(password string, salt []byte, p Argon2Params) []byte {\n\treturn argon2.IDKey([]byte(password), salt, p.Iterations, p.Memory, p.Parallelism, p.KeyLength)\n}\n","sourceCodeStart":53,"sourceCodeEnd":89,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/util/kdf.go#L53-L89","documentation":"ValidateArgon2Params enforces sane Argon2id KDF bounds so a malicious or careless encrypted-notebook backup cannot request gigabytes of memory (OOM) or degrade security. Memory is expressed in KiB and must be at most 256*1024 (256 MB). Values above that are rejected before any key derivation runs.","triggerScenarios":"Calling ValidateArgon2Params (directly or via EnableEncryptedNotebook, ImportNotebookCryptoBackup, deriveKEK, or notebook crypto restore paths) with Argon2Params.Memory > 262144 KiB, typically after importing a third-party or hand-edited crypto backup config.","commonSituations":"Importing an encrypted-notebook backup whose config was tuned on a machine with abundant RAM (e.g. memory=1048576 for 1 GB), hand-editing the notebook crypto JSON to 'harden' KDF settings, or migrating params from another Argon2 implementation that uses bytes instead of KiB.","solutions":["Lower Argon2Params.Memory to <= 262144 (KiB); 65536 (64 MB) is the OWASP default via DefaultArgon2Params()","If the value came from an imported backup, edit the backup's crypto config JSON to bring memory within bounds before importing","If a stronger KDF is genuinely needed, benchmark within the 64-256 MB range and increase Iterations (max 10) instead of Memory","Confirm units: the field is KiB; a value meant as bytes or a raw MB number will overshoot the cap"],"exampleFix":"// before\np := util.Argon2Params{Memory: 512 * 1024, Iterations: 3, Parallelism: 4, KeyLength: 32}\nif _, err := util.ValidateArgon2Params(p); err != nil { return err }\n\n// after\np := util.Argon2Params{Memory: 256 * 1024, Iterations: 3, Parallelism: 4, KeyLength: 32}\nif _, err := util.ValidateArgon2Params(p); err != nil { return err }","handlingStrategy":"validation","validationCode":"if p.Memory < 64*1024 || p.Memory > 256*1024 {\n    return fmt.Errorf(\"memory must be 64-256 MB KiB, got %d\", p.Memory)\n}\nif _, err := util.ValidateArgon2Params(p); err != nil { return err }","typeGuard":null,"tryCatchPattern":"if _, err := util.ValidateArgon2Params(p); err != nil {\n    // err message names the exact violated bound\n    return fmt.Errorf(\"invalid KDF params: %w\", err)\n}","preventionTips":["Start from util.DefaultArgon2Params() and only adjust within documented bounds","Remember Memory is in KiB, not bytes or MB","Validate any imported backup crypto config before persisting it"],"tags":["kdf","argon2id","validation","memory-limit","config"],"backgroundTag":"value-out-of-range","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}