siyuan-note/siyuan · error
Argon2id Memory too high (maximum 256 MB)
Error message
Argon2id Memory too high (maximum 256 MB)
What it means
ValidateArgon2Params enforces sane Argon2id KDF bounds so a malicious or careless encrypted-notebook backup cannot request gigabytes of memory (OOM) or degrade security. Memory is expressed in KiB and must be at most 256*1024 (256 MB). Values above that are rejected before any key derivation runs.
Solutions
- Lower Argon2Params.Memory to <= 262144 (KiB); 65536 (64 MB) is the OWASP default via DefaultArgon2Params()
- If the value came from an imported backup, edit the backup's crypto config JSON to bring memory within bounds before importing
- If a stronger KDF is genuinely needed, benchmark within the 64-256 MB range and increase Iterations (max 10) instead of Memory
- Confirm units: the field is KiB; a value meant as bytes or a raw MB number will overshoot the cap
Example fix
// before
p := util.Argon2Params{Memory: 512 * 1024, Iterations: 3, Parallelism: 4, KeyLength: 32}
if _, err := util.ValidateArgon2Params(p); err != nil { return err }
// after
p := util.Argon2Params{Memory: 256 * 1024, Iterations: 3, Parallelism: 4, KeyLength: 32}
if _, err := util.ValidateArgon2Params(p); err != nil { return err } Defensive patterns
Strategy: validation
Validate before calling
if p.Memory < 64*1024 || p.Memory > 256*1024 {
return fmt.Errorf("memory must be 64-256 MB KiB, got %d", p.Memory)
}
if _, err := util.ValidateArgon2Params(p); err != nil { return err } Try / catch
if _, err := util.ValidateArgon2Params(p); err != nil {
// err message names the exact violated bound
return fmt.Errorf("invalid KDF params: %w", err)
} Prevention
- Start from util.DefaultArgon2Params() and only adjust within documented bounds
- Remember Memory is in KiB, not bytes or MB
- Validate any imported backup crypto config before persisting it
When it happens
Trigger: Calling ValidateArgon2Params (directly or via EnableEncryptedNotebook, ImportNotebookCryptoBackup, deriveKEK, or notebook crypto restore paths) with Argon2Params.Memory > 262144 KiB, typically after importing a third-party or hand-edited crypto backup config.
Common situations: Importing an encrypted-notebook backup whose config was tuned on a machine with abundant RAM (e.g. memory=1048576 for 1 GB), hand-editing the notebook crypto JSON to 'harden' KDF settings, or migrating params from another Argon2 implementation that uses bytes instead of KiB.
Understand the failure class
Background: "value must be between 0 and 1" / "out of range" / "must not be negative" errors: fixing range-validation failures across open-source libraries — this error's family across 42 libraries.
Related errors
- Argon2id Iterations too high (maximum 10)
- Argon2id Parallelism must be between 1 and 16
- Argon2id Iterations too low (minimum 3)
- Argon2id KeyLength must be 32
- Argon2id Memory too low (minimum 64 MB)
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/ef11b80c39a3477e.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/util/kdf.go:71
return Argon2Params{
Memory: 64 * 1024,
Iterations: 3,
Parallelism: 4,
KeyLength: 32,
}
}
// ValidateArgon2Params 校验 Argon2id 参数是否在合理范围内,防止恶意备份设置极大内存导致 OOM,
// 或过弱参数降低安全性。
func ValidateArgon2Params(p Argon2Params) (Argon2Params, error) {
if p.KeyLength != 32 {
return p, errors.New("Argon2id KeyLength must be 32")
}
if p.Memory < 64*1024 {
return p, errors.New("Argon2id Memory too low (minimum 64 MB)")
}
if p.Memory > 256*1024 {
return p, errors.New("Argon2id Memory too high (maximum 256 MB)")
}
if p.Iterations < 3 {
return p, errors.New("Argon2id Iterations too low (minimum 3)")
}
if p.Iterations > 10 {
return p, errors.New("Argon2id Iterations too high (maximum 10)")
}
if p.Parallelism == 0 || p.Parallelism > 16 {
return p, errors.New("Argon2id Parallelism must be between 1 and 16")
}
return p, nil
}
// DeriveKey 用 Argon2id 从密码派生密钥。同一 password+salt+params 多次调用结果一致。
func DeriveKey(password string, salt []byte, p Argon2Params) []byte {
return argon2.IDKey([]byte(password), salt, p.Iterations, p.Memory, p.Parallelism, p.KeyLength)
}
View on GitHub (pinned to 9f775e8a12)