openwall / openwall/john

Switch to an unsigned and larger integer type for loaded password hash and salt counts

Open
#5,334 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement maintenance/cleanup
Dominant language
C
Stars
13.6k
Forks
2.6k
PR merge metrics
No merged PRs in 30d

Description

It may soon be not unreasonable to load more than 2 billion password hashes at once (albeit not in a 32-bit build).

For starters, we should change these in struct db_main:

/* Number of salts, passwords and guesses */
        int salt_count, password_count, guess_count;

and the corresponding uses of %d.

Then there's more, such as this in struct db_salt:

/* Number of passwords with this salt */
        int count;

...changing which to a larger type may unfortunately increase memory usage in case of many single-hash salts.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating struct db_main and struct db_salt, then trace every use of salt_count, password_count, guess_count, and count, including the corresponding %d format strings. The work is done when these count paths consistently support the intended larger unsigned range and the memory impact of per-salt counts has been assessed.

Written by the indexing model from the issue text.

Assessment

Tech stack
c
Domain
security
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.