code wiki / (root) / nx_sha256.nx

nx_sha256.nx

buildroot/runtime/nx_sha256.nx

24579 B549 linesdepth 4pulls 4 transitivereach 2582 importersview sourcekind librarytopic sha256
docsdependenciesstructsconstsfunctions

about

sha256.nx -- SHA-256 in pure NishiLang (Phase G9, FIPS 180-4). Canonical: this is the substrate-wide canonical SHA-256 implementation per [[feedback-no-tool-proliferation-bit-level]]. HMAC-SHA256 / HKDF-SHA256 / DRBG-SHA256 etc. compose THIS file's sha256 primitive; they're distinct primitives (different specs: FIPS 198-1 HMAC, RFC 5869 HKDF, NIST SP 800-90A DRBG) but all share THIS sha256 as their SHA-256 backbone. Re-implementing the SHA-256 K-table or round function inline is refused. license_tier: INDEPENDENT_REDERIVE genealogy_id: international-research-sources/nist/fips_180_4 Used for: content-addressed build artifacts (F6), session tokens (rand.nx + sha256 = HMAC), TLS 1.3 handshake (G15), Git-style object addressing, reproducible-build attestation. Implementation follows FIPS 180-4 section 6.2 exactly -- no precomputed tables beyond the standard K[0..63] round constants. Pure i64 arithmetic; all 32-bit ops masked with 0xFFFFFFFF. API: sha256_init(*ctx) — reset a fresh Sha256 context sha256_update(*ctx, *u8 bytes, len) — feed input chunks sha256_final(*ctx, *u8 out32) — write 32-byte digest sha256_digest(*u8 bytes, len, *u8 out32) — one-shot convenience The context is ~128 bytes: 8 words of hash state + 64-byte partial block buffer + 8-byte length counter + an index. Caller allocates (stack or heap) and passes pointer. nx_safety_envelope: (schema: nishi-library/seeds/safety-critical-standards.toml) intended_use: "SHA-256 cryptographic hash -- HMAC + HKDF + content-addressed storage + digital signatures + Wheeler-DDC integrity chain" sil_target: SIL3 (integrity primitive; collision or preimage attack = signature forgery) asil_target: QM dal_target: DAL B iec_62304_class: B

dependencies 2 imports · 284 importers

nx_syscalls.nx nx_bits.nx nx_sha256.nx _doc_cas_authored.nx _locator_authored.nx _tlskdf_minrepro.nx nx_abi_lock.nx nx_abi_lock_test.nx nx_accept_binding_candidate_t230.n nx_accept_ref_lib.nx nx_accept_release_binding.nx nx_access_audit.nx nx_acct_admin_handoff.nx

diagram shows first 10 each side; +0 more imports, +274 more importers in the complete lists below.

imports: nx_syscalls.nxnx_bits.nx

imported by: _doc_cas_authored.nx_locator_authored.nx_tlskdf_minrepro.nxnx_abi_lock.nxnx_abi_lock_test.nxnx_accept_binding_candidate_t230.nxnx_accept_ref_lib.nxnx_accept_release_binding.nxnx_access_audit.nxnx_acct_admin_handoff.nxnx_aimode_read.nxnx_analyst_html.nxnx_apertus_shard_verify.nxnx_asset_prov_clock_candidate_t346.nxnx_asset_prov_lib.nxnx_atomic_publish.nxnx_atomic_publish_gate.nxnx_audit_log.nxnx_authenticode_sign.nxnx_bld_cache_cas_gate.nxnx_blob_store.nxnx_blob_store_mcu.nxnx_bt_v2_merkle.nxnx_bt_v2_merkle_gate.nxnx_build_key_identity_lib.nxnx_campaign_verify.nxnx_canon_cid.nxnx_capture_append_lib.nxnx_cast_aperture_artifact_gate_t207.nxnx_cast_aperture_artifact_group_gate_t207.nxnx_cdc_gate.nxnx_cdc_lib.nxnx_claude_harvest.nxnx_claude_harvest_requests_t144.nxnx_claude_harvest_usage_t76.nxnx_closurehash.nxnx_cms_admin.nxnx_cms_admin_gate.nxnx_cms_analytics_gate.nxnx_cms_argon_gate.nxnx_cms_blocks_gate.nxnx_cms_draft_gate.nxnx_cms_forms_gate.nxnx_cms_gate.nxnx_cms_migrate.nxnx_cms_multisite_gate.nxnx_cms_seo_gate.nxnx_cms_setpw.nxnx_cms_snapshot_gate.nxnx_cms_tls_gate.nxnx_cms_webdev_gate.nxnx_coe_consistency.nxnx_coe_frame.nxnx_coe_witness.nxnx_commons_witness.nxnx_communitypulse.nxnx_compare_cite.nxnx_compare_cite_gate.nxnx_compare_ladder_isolated_lib.nxnx_compare_shared_fit_lib_20260910.nxnx_comparestale_dependency_t138.nxnx_comparestale_edge_lib_t139.nxnx_comparestale_lib.nxnx_compute_graph_test.nxnx_compute_node.nxnx_container_registry.nxnx_content_get.nxnx_content_get_client.nxnx_content_get_gate.nxnx_content_put.nxnx_content_put_client.nxnx_content_put_gate.nxnx_deployjrnl_lib.nxnx_dist_publish.nxnx_dr_archive.nxnx_dr_dedup.nxnx_dr_dedup_gate.nxnx_dr_encrypt.nxnx_dr_encrypt_gate.nxnx_dr_incremental.nxnx_dr_restore_verify.nxnx_dr_restore_verify_gate.nxnx_dr_retention.nxnx_drbg_hmac.nxnx_drbg_hmac_test.nxnx_ecdsa_p384_real_bisect_test.nxnx_efivars_enrol.nxnx_email_auth.nxnx_emitted_substrate.nxnx_entity_media.nxnx_etag.nxnx_evidence_gather.nxnx_extllm_call.nxnx_f6_gate.nxnx_fetch_decode_capture_t253.nxnx_fetchprobed.nxnx_filehash.nxnx_fio.nxnx_flash_test.nxnx_forge_evidence_t274.nx +184 more (shown cap 100 declared)

structs

62struct Sha256 {

consts

60const K_MAGIC_536870912: i64 = 536870912
99const M32: i64 = 0xFFFFFFFF
477const SHA256_WORD_ALIGN: i64 = 8
478const SHA256_BLOCK_BYTES: i64 = 64
479const SHA256_ROUND_WORDS: i64 = 64
480const SHA256_WIDE_WORD: i64 = 8
481const SHA256_PACKED_WORD: i64 = 4
482const SHA256_STATE_WORDS: i64 = 8
483const SHA256_DIGEST_BYTES: i64 = 32
484const SHA256_SIGNED_MAX: i64 = 9223372036854775807
485const SHA256_BITS_PER_BYTE: i64 = 8
486const SHA256_E_INPUT: i64 = 0-1
487const SHA256_E_WORKSPACE: i64 = 0-2
488const SHA256_E_MAPPING: i64 = 0-3
489const SHA256_E_RELEASE: i64 = 0-4

functions

103func rotr32(x: i64, n: i64) -> i64 {
calls 1: nx_bits_rotr32
107func shr32(x: i64, n: i64) -> i64 {
114func sha256_k(i: i64) -> i64 {
184func blk_byte(c: *Sha256, n: i64) -> i64 {
called by 1: blk_word
190func blk_set_byte(c: *Sha256, n: i64, v: i64) -> i64 {
198func blk_word(c: *Sha256, i: i64) -> i64 {
called by 1: sha256_compress calls 1: blk_byte
212func sha256_compress_ni(c: *Sha256) -> i64 {
called by 1: sha256_compress
231func sha256_compress_ni_blocks(c: *Sha256, blocks: i64, nblk: i64) -> i64 {
called by 1: sha256_update
253func sha256_compress(c: *Sha256) -> i64 {
316func sha256_seed_allocated(c: *Sha256) -> i64 {
343func sha256_init(c: *Sha256) -> i64 {
354func sha256_update(c: *Sha256, bytes: *u8, n: i64) -> i64 {
384func sha256_final(c: *Sha256, out: *u8) -> i64 {
454func sha256_destroy(c: *Sha256) -> i64 {
463func sha256_digest(bytes: *u8, n: i64, out: *u8) -> i64 {
491func sha256_context_aligned_bytes() -> i64 {
494func sha256_workspace_bytes() -> i64 {
497func sha256_checked_input(bytes: *u8, n: i64, out: *u8) -> i64 {
504func sha256_ranges_overlap(a: i64, an: i64, b: i64, bn: i64) -> i64 {
510func sha256_init_workspace(workspace: *u8, capacity: i64) -> i64 {
521func sha256_digest_workspace(bytes: *u8, n: i64, out: *u8, workspace: *u8, capacity: i64) -> i64 {
535func sha256_digest_mapping_native(bytes: *u8, n: i64, out: *u8, mapping: i64) -> i64 {
544func sha256_digest_checked_native(bytes: *u8, n: i64, out: *u8) -> i64 {