FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

InvalidHash on Ubuntu 20.04 · Issue #225 · bcrypt-ruby/bcrypt-ruby · GitHub

Repository navigation

InvalidHash on Ubuntu 20.04 #225

Description

On Ubuntu 20.04 using ruby 2.6.5, the following error is thrown at 512 characters (fewer characters works fine):

irb(main):004:0> BCrypt::Password.create("a"*512)
Traceback (most recent call last):
        7: from /home/jwcooper/.asdf/installs/ruby/2.6.5/bin/irb:23:in `<main>'
        6: from /home/jwcooper/.asdf/installs/ruby/2.6.5/bin/irb:23:in `load'
        5: from /home/jwcooper/.asdf/installs/ruby/2.6.5/lib/ruby/gems/2.6.0/gems/irb-1.0.0/exe/irb:11:in `<top (required)>'
        4: from (irb):4
        3: from /home/jwcooper/.asdf/installs/ruby/2.6.5/lib/ruby/gems/2.6.0/gems/bcrypt-3.1.13/lib/bcrypt/password.rb:46:in `create'
        2: from /home/jwcooper/.asdf/installs/ruby/2.6.5/lib/ruby/gems/2.6.0/gems/bcrypt-3.1.13/lib/bcrypt/password.rb:46:in `new'
        1: from /home/jwcooper/.asdf/installs/ruby/2.6.5/lib/ruby/gems/2.6.0/gems/bcrypt-3.1.13/lib/bcrypt/password.rb:60:in `initialize'
BCrypt::Errors::InvalidHash (invalid hash)

Let me know if I can provide any further information. This isn't happening on Ubuntu 18.04 or any other distributions I've tested it on.

Activity

  1. tjschuck commented on May 12, 2020

    Collaborator

    Your password is longer than bcrypt supports. (Note: bcrypt itself, not bcrypt-ruby.) Any input after 72 bytes is truncated anyway.

    See #208 (comment) and the followup comments for more info. You should probably be restricting incoming passwords to under 72 bytes if this is a UX concern for you.

  2. jwcooper commented on May 12, 2020

    Author

    Sorry, I figured this was worth posting as it's a regression from my other systems.

    irb(main):010:0> BCrypt::Password.create("a"*10000)
    => "..."
    

    That works just fine on Ubuntu 18.04, for example, even if it only uses the first 72 bytes.

  3. tjschuck commented on May 12, 2020

    Collaborator

    That's fair. I'll reopen the issue to document it, but the easiest/best solution is still probably going to be validating the input first.

  4. jwcooper commented on May 13, 2020

    Author

    Here's a simple test case for rails has_secure_password that also throws the InvalidHash, as bcrypt appears to be called before the length validations run.

    # frozen_string_literal: true
    
    require "bundler/inline"
    
    gemfile(true) do
      source "https://rubygems.org"
    
      git_source(:github) { |repo| "https://github.com/#{repo}.git" }
    
      gem "rails", github: "rails/rails"
      gem "sqlite3"
      gem "bcrypt"
    end
    
    require "active_record"
    require "minitest/autorun"
    require "logger"
    
    # This connection will do for database-independent bug reports.
    ActiveRecord::Base.establish_connection(adapter: "sqlite3", database: ":memory:")
    ActiveRecord::Base.logger = Logger.new(STDOUT)
    
    ActiveRecord::Schema.define do
      create_table :users, force: true do |t|
        t.string :password_digest
      end
    end
    
    class User < ActiveRecord::Base
      has_secure_password
    end
    
    class BcryptTest < Minitest::Test
      def test_invalid_length
        user = User.new
        user.password = "password"
        user.password_confirmation = "password"
    
        assert user.valid?(:create), "user should be valid"
    
        user.password = "a" * 150
        user.password_confirmation = "a" * 150
    
        assert user.invalid?(:create), "user should be invalid"
      end
    
      def test_bcrypt_invalid_hash
        user = User.new
        user.password = "password"
        user.password_confirmation = "password"
    
        assert user.valid?(:create), "user should be valid"
    
        user.password = "a" * 1000
        user.password_confirmation = "a" * 1000
    
        assert user.invalid?(:create), "user should be invalid"
      end
    end
    
    
  5. thewalkingtoast commented on May 20, 2020

    I am also seeing this now after upgrading to Pop!_OS 20.04 LTS x86_64. New OpenSSL lib difference?

  6. thewalkingtoast commented on May 20, 2020

    My issue was with @rajeevkannav's comment in #226 (comment)

    TL;DR - Upgrade to bcrypt 3.1.13

  7. adsteel commented on Oct 8, 2020

    Upgrading also solved my issue.

  8. foreverLoveWisdom commented on Oct 15, 2020

    My issue was with @rajeevkannav's comment in #226 (comment)

    TL;DR - Upgrade to bcrypt 3.1.13

    Upgrade to bcrypt 3.1.16 does solve my problem.
    My OS: Ubuntu 20.04
    Rails: 4.1.0
    Ruby: 2.1.1

  9. jwcooper commented on Dec 14, 2020

    Author

    As a follow-up, as some users are reporting this is fixed, I can confirm I'm still seeing this issue on 20.04 with bcrypt-ruby 3.1.16 on rails 6.0 and ruby 2.7.2.

  10. gmbollati commented on Apr 19, 2021

    I have the wame issue whith rails 3.2.22 and ruby 2.2.1
    my ruby gems is 2.6.14
    Help :D

  11. erikbrannstrom commented on Mar 14, 2022

    I just caught this in our logs. From what I can gather, #255 fixes this, but is waiting for a release to be cut?

    I don't think this issue is a big deal, but I just want to know if we should do some quick workaround for this (rare!) event, or just ignore it until we can grab an updated bcrypt-ruby version!

  12. tjschuck commented on Mar 14, 2022

    Collaborator

    @erikbrannstrom I just cut and pushed 3.1.17 which includes #255.

  13. erikbrannstrom commented on Mar 21, 2022

    @tjschuck Thanks a bunch! 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL