code wiki / (root) / nx_sha256.nx

nx_sha256.nx

buildroot/runtime/nx_sha256.nx

19362 B454 linesdepth 4pulls 4 transitivereach 1636 importersview sourcekind librarytopic sha256
docsdependenciesstructsconstsfunctions

about

sha256.nx -- SHA-256 in pure NishiLang (Phase G9, FIPS 180-4). Canonical: this is the substrate-wide canonical SHA-256 implementation per [[feedback-no-tool-proliferation-bit-level]]. HMAC-SHA256 / HKDF-SHA256 / DRBG-SHA256 etc. compose THIS file's sha256 primitive; they're distinct primitives (different specs: FIPS 198-1 HMAC, RFC 5869 HKDF, NIST SP 800-90A DRBG) but all share THIS sha256 as their SHA-256 backbone. Re-implementing the SHA-256 K-table or round function inline is refused. license_tier: INDEPENDENT_REDERIVE genealogy_id: international-research-sources/nist/fips_180_4 Used for: content-addressed build artifacts (F6), session tokens (rand.nx + sha256 = HMAC), TLS 1.3 handshake (G15), Git-style object addressing, reproducible-build attestation. Implementation follows FIPS 180-4 section 6.2 exactly -- no precomputed tables beyond the standard K[0..63] round constants. Pure i64 arithmetic; all 32-bit ops masked with 0xFFFFFFFF. API: sha256_init(*ctx) — reset a fresh Sha256 context sha256_update(*ctx, *u8 bytes, len) — feed input chunks sha256_final(*ctx, *u8 out32) — write 32-byte digest sha256_digest(*u8 bytes, len, *u8 out32) — one-shot convenience The context is ~128 bytes: 8 words of hash state + 64-byte partial block buffer + 8-byte length counter + an index. Caller allocates (stack or heap) and passes pointer. nx_safety_envelope: (schema: nishi-library/seeds/safety-critical-standards.toml) intended_use: "SHA-256 cryptographic hash -- HMAC + HKDF + content-addressed storage + digital signatures + Wheeler-DDC integrity chain" sil_target: SIL3 (integrity primitive; collision or preimage attack = signature forgery) asil_target: QM dal_target: DAL B iec_62304_class: B

dependencies 2 imports · 141 importers

nx_syscalls.nx nx_bits.nx nx_sha256.nx _doc_cas_authored.nx _locator_authored.nx _tlskdf_minrepro.nx nx_abi_lock.nx nx_abi_lock_test.nx nx_access_audit.nx nx_acct_admin_handoff.nx nx_analyst_html.nx nx_apertus_shard_verify.nx nx_audit_log.nx

diagram shows first 10 each side; +0 more imports, +131 more importers in the complete lists below.

imports: nx_syscalls.nxnx_bits.nx

imported by: _doc_cas_authored.nx_locator_authored.nx_tlskdf_minrepro.nxnx_abi_lock.nxnx_abi_lock_test.nxnx_access_audit.nxnx_acct_admin_handoff.nxnx_analyst_html.nxnx_apertus_shard_verify.nxnx_audit_log.nxnx_blob_store.nxnx_blob_store_mcu.nxnx_bt_v2_merkle.nxnx_bt_v2_merkle_gate.nxnx_canon_cid.nxnx_cms_admin.nxnx_cms_admin_gate.nxnx_cms_analytics_gate.nxnx_cms_argon_gate.nxnx_cms_blocks_gate.nxnx_cms_draft_gate.nxnx_cms_forms_gate.nxnx_cms_gate.nxnx_cms_migrate.nxnx_cms_multisite_gate.nxnx_cms_seo_gate.nxnx_cms_setpw.nxnx_cms_snapshot_gate.nxnx_cms_tls_gate.nxnx_cms_webdev_gate.nxnx_coe_consistency.nxnx_coe_frame.nxnx_coe_witness.nxnx_compute_graph_test.nxnx_compute_node.nxnx_container_registry.nxnx_dist_publish.nxnx_dr_archive.nxnx_dr_dedup.nxnx_dr_dedup_gate.nxnx_dr_encrypt.nxnx_dr_encrypt_gate.nxnx_dr_incremental.nxnx_dr_restore_verify.nxnx_dr_restore_verify_gate.nxnx_dr_retention.nxnx_drbg_hmac.nxnx_drbg_hmac_test.nxnx_ecdsa_p384_real_bisect_test.nxnx_email_auth.nxnx_emitted_substrate.nxnx_entity_media.nxnx_etag.nxnx_evidence_gather.nxnx_f6_gate.nxnx_fetchprobed.nxnx_filehash.nxnx_flash_test.nxnx_fw_safeflash.nxnx_gate_bite.nxnx_hash_bench.nxnx_hmac.nxnx_hr_entitle.nxnx_hr_pow.nxnx_hr_sov.nxnx_https_get_happy_test.nxnx_install_hash.nxnx_invite_token.nxnx_jose_es256.nxnx_journal_log.nxnx_jwk_ec.nxnx_libdata.nxnx_log_chunked.nxnx_log_chunked_test.nxnx_machine_key.nxnx_media_gather.nxnx_media_grab.nxnx_mgmt_api.nxnx_mgmt_client.nxnx_mgmt_upload_gate.nxnx_mirror_orchestrator.nxnx_module_cas.nxnx_module_cas_test.nxnx_mvault_walk.nxnx_nishi_install_os.nxnx_nishi_usb_install.nxnx_nishifs_boot.nxnx_nishifs_bootasm.nxnx_nishifs_cid.nxnx_nishifs_cow.nxnx_nishifs_crypt.nxnx_nishifs_mount.nxnx_nishios_germ_gate.nxnx_nxe_lib.nxnx_nxgguf.nxnx_oauth2_pkce.nxnx_p256_ecdh.nxnx_pattern_emit15.nxnx_pow_challenge.nxnx_pub_reader_receipt.nx +41 more (shown cap 100 declared)

structs

62struct Sha256 {

consts

60const K_MAGIC_536870912: i64 = 536870912
99const M32: i64 = 0xFFFFFFFF

functions

103func rotr32(x: i64, n: i64) -> i64 {
calls 1: nx_bits_rotr32
107func shr32(x: i64, n: i64) -> i64 {
114func sha256_k(i: i64) -> i64 {
184func blk_byte(c: *Sha256, n: i64) -> i64 {
called by 1: blk_word
190func blk_set_byte(c: *Sha256, n: i64, v: i64) -> i64 {
198func blk_word(c: *Sha256, i: i64) -> i64 {
called by 1: sha256_compress calls 1: blk_byte
212func sha256_compress_ni(c: *Sha256) -> i64 {
called by 1: sha256_compress
231func sha256_compress_ni_blocks(c: *Sha256, blocks: i64, nblk: i64) -> i64 {
called by 1: sha256_update
253func sha256_compress(c: *Sha256) -> i64 {
315func sha256_init(c: *Sha256) -> i64 {
349func sha256_update(c: *Sha256, bytes: *u8, n: i64) -> i64 {
379func sha256_final(c: *Sha256, out: *u8) -> i64 {
447func sha256_digest(bytes: *u8, n: i64, out: *u8) -> i64 {