siyuan-note/siyuan · error
Argon2id Memory too low (minimum 64 MB)
Error message
Argon2id Memory too low (minimum 64 MB)
What it means
ValidateArgon2Params enforces a lower bound of 64 MB (64*1024 KiB) on the Argon2id memory parameter. Too little memory makes the key derivation weak against GPU/ASIC brute-force attacks, so the library rejects such configurations to keep encrypted-notebook key derivation within its security budget.
Solutions
- Set Memory to at least 64*1024 (64 MB) in Argon2Params
- If the value came from an imported backup, re-export the backup with default/valid parameters, or use a backup whose parameters authenticate successfully
- For faster unlock times, tune Iterations/parallelism within allowed ranges instead of dropping memory below the floor
- If restoring is impossible, recover from a valid notebook crypto backup; never bypass validation or discard keys
Example fix
// before
p := util.Argon2Params{Memory: 16 * 1024, Iterations: 3, KeyLength: 32} // 16 MB — too low
_, err := util.ValidateArgon2Params(p)
// after
p := util.Argon2Params{Memory: 64 * 1024, Iterations: 3, KeyLength: 32}
_, err := util.ValidateArgon2Params(p) // ok Defensive patterns
Strategy: validation
Validate before calling
if p.Memory < 64*1024 || p.Memory > 256*1024 { return fmt.Errorf("Memory must be 64-256 MB, got %d", p.Memory) }
// then call util.ValidateArgon2Params(p) Type guard
func hasValidMemory(p util.Argon2Params) bool { return p.Memory >= 64*1024 && p.Memory <= 256*1024 } Try / catch
if _, err := util.ValidateArgon2Params(p); err != nil && strings.Contains(err.Error(), "Memory too low") {
p.Memory = 64 * 1024 // clamp to the minimum, then retry
} Prevention
- Clamp Memory to 64-256 MB before validation
- Never hand-edit the encrypted-notebook crypto config values
- Re-export backups with official tooling if parameters were weakened
When it happens
Trigger: Calling ValidateArgon2Params (directly or via deriveKEK / EnableEncryptedNotebook / backup import-restore paths) with Argon2Params.Memory below 64*1024 — e.g. a hand-edited crypto config, a backup exported with weaker parameters, or a struct defaulting Memory to 0.
Common situations: Users manually lowering memory in the encrypted-notebook settings to speed up unlock; importing a crypto backup generated by modified tooling with weak parameters; code constructing Argon2Params without initializing Memory; config corruption resetting the field.
Understand the failure class
Background: "value must be between 0 and 1" / "out of range" / "must not be negative" errors: fixing range-validation failures across open-source libraries — this error's family across 42 libraries.
Related errors
- Argon2id KeyLength must be 32
- Argon2id Iterations too high (maximum 10)
- Argon2id Iterations too low (minimum 3)
- Argon2id Memory too high (maximum 256 MB)
- Argon2id Parallelism must be between 1 and 16
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/c3c9bef94e3dd441.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/util/kdf.go:68
// DefaultArgon2Params 返回 OWASP 2023 推荐的 Argon2id 参数。
func DefaultArgon2Params() Argon2Params {
return Argon2Params{
Memory: 64 * 1024,
Iterations: 3,
Parallelism: 4,
KeyLength: 32,
}
}
// ValidateArgon2Params 校验 Argon2id 参数是否在合理范围内,防止恶意备份设置极大内存导致 OOM,
// 或过弱参数降低安全性。
func ValidateArgon2Params(p Argon2Params) (Argon2Params, error) {
if p.KeyLength != 32 {
return p, errors.New("Argon2id KeyLength must be 32")
}
if p.Memory < 64*1024 {
return p, errors.New("Argon2id Memory too low (minimum 64 MB)")
}
if p.Memory > 256*1024 {
return p, errors.New("Argon2id Memory too high (maximum 256 MB)")
}
if p.Iterations < 3 {
return p, errors.New("Argon2id Iterations too low (minimum 3)")
}
if p.Iterations > 10 {
return p, errors.New("Argon2id Iterations too high (maximum 10)")
}
if p.Parallelism == 0 || p.Parallelism > 16 {
return p, errors.New("Argon2id Parallelism must be between 1 and 16")
}
return p, nil
}
// DeriveKey 用 Argon2id 从密码派生密钥。同一 password+salt+params 多次调用结果一致。
func DeriveKey(password string, salt []byte, p Argon2Params) []byte {View on GitHub (pinned to 9f775e8a12)