Skip to main content

derive_key_from_untrusted_params

Function derive_key_from_untrusted_params 

Source
pub fn derive_key_from_untrusted_params(
    memory_cost: u32,
    time_cost: u32,
    parallelism: u32,
    key_size: u8,
    derive: impl FnOnce() -> Result<(SecureKey, KeyDerivationReport), KeyDerivationError>,
) -> WorkflowResult<SecureKey>
Expand description

Derives a key from KDF parameters read out of an untrusted file header.

Validates the parameters against the bounds above and, only if they pass, runs derive while holding a reservation against the global memory budget. This is the single intended entry point for header-supplied parameters: fusing the two steps makes it impossible to run an unvalidated derivation from a crafted file.

Takes raw values rather than a version-specific params struct so that every format version can use the same guard.