Fixed in https://github.com/badbundle/vault-app/pull/630 (merged as af33bfdf).
This adds Argon2id key derivation from the vendored PHC reference implementation (CArgon2, single-threaded, built with -O3), exposed as Argon2idKeyDeriver in CryptoEngine and parameterized by the file header. AppLockKeyDerivationCalibrator in VaultKeygen calibrates on the device: 64 MiB, the fastest of three t = 3 runs, t clamped to 3–32 for about 0.5 s, plus the unlock deadline, all behind an injectable timer. Working memory is zeroed. It's tested against the RFC 9106 vectors and the reference known-answer tests, make calibrate-app-lock measures a device, and Argon2 is credited in the third-party libraries list.