cmd/age-plugin-batchpass: correct documented scrypt limit

Reported by Joe Doyle of Trail of Bits.
This commit is contained in:
Filippo Valsorda
2026-08-29 19:30:10 +02:00
parent 6ff2f308e6
commit 3604609d98
2 changed files with 9 additions and 6 deletions
+5 -4
View File
@@ -68,11 +68,12 @@ a file descriptor. Trailing newlines are stripped from the file contents.
When encrypting, you can set AGE_PASSPHRASE_WORK_FACTOR to adjust the scrypt When encrypting, you can set AGE_PASSPHRASE_WORK_FACTOR to adjust the scrypt
work factor (between 1 and 30, default 18). Higher values are more secure work factor (between 1 and 30, default 18). Higher values are more secure
but slower. but slower. The age CLI refuses to decrypt files above 22, and so does this
plugin unless AGE_PASSPHRASE_MAX_WORK_FACTOR is set to at least the same value.
When decrypting, you can set AGE_PASSPHRASE_MAX_WORK_FACTOR to limit the When decrypting, you can set AGE_PASSPHRASE_MAX_WORK_FACTOR to change the
maximum scrypt work factor accepted (between 1 and 30, default 30). This can maximum scrypt work factor accepted (between 1 and 30, default 22). This can
be used to avoid very slow decryptions.` be used to avoid very slow decryptions, or to allow slower ones.`
// Version can be set at link time to override debug.BuildInfo.Main.Version when // Version can be set at link time to override debug.BuildInfo.Main.Version when
// building manually without git history. It should look like "v1.2.3". // building manually without git history. It should look like "v1.2.3".
+4 -2
View File
@@ -65,11 +65,13 @@ persisted in the shell history or leaked to other users on multi-user systems.
The scrypt work factor to use when encrypting. The scrypt work factor to use when encrypting.
Must be between 1 and 30. Default is 18. Must be between 1 and 30. Default is 18.
Higher values are more secure but slower. Higher values are more secure but slower.
The age CLI refuses to decrypt files above 22, and so does this plugin
unless `AGE_PASSPHRASE_MAX_WORK_FACTOR` is set to at least the same value.
* `AGE_PASSPHRASE_MAX_WORK_FACTOR`: * `AGE_PASSPHRASE_MAX_WORK_FACTOR`:
The maximum scrypt work factor to accept when decrypting. The maximum scrypt work factor to accept when decrypting.
Must be between 1 and 30. Default is 30. Must be between 1 and 30. Default is 22.
Can be used to avoid very slow decryptions. Can be used to avoid very slow decryptions, or to allow slower ones.
## EXAMPLES ## EXAMPLES