Switch to an unsigned and larger integer type for loaded password hash and salt counts
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 13.6k
- Forks
- 2.6k
- PR merge metrics
- No merged PRs in 30d
Description
It may soon be not unreasonable to load more than 2 billion password hashes at once (albeit not in a 32-bit build).
For starters, we should change these in struct db_main:
/* Number of salts, passwords and guesses */
int salt_count, password_count, guess_count;
and the corresponding uses of %d.
Then there's more, such as this in struct db_salt:
/* Number of passwords with this salt */
int count;
...changing which to a larger type may unfortunately increase memory usage in case of many single-hash salts.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating struct db_main and struct db_salt, then trace every use of salt_count, password_count, guess_count, and count, including the corresponding %d format strings. The work is done when these count paths consistently support the intended larger unsigned range and the memory impact of per-salt counts has been assessed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c
- Domain
- security
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100