const K: [u32; 64] = [
0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5,
0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5,
0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3,
0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174,
0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc,
0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da,
0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7,
0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967,
0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13,
0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,
0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3,
0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070,
0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5,
0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3,
0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208,
0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2,
];
const H_INIT: [u32; 8] = [
0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a,
0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19,
];
#[inline(always)]
fn rotr(x: u32, n: u32) -> u32 {
(x >> n) | (x << (32 - n))
}
#[inline(always)]
fn ch(x: u32, y: u32, z: u32) -> u32 {
(x & y) ^ ((!x) & z)
}
#[inline(always)]
fn maj(x: u32, y: u32, z: u32) -> u32 {
(x & y) ^ (x & z) ^ (y & z)
}
#[inline(always)]
fn big_sigma0(x: u32) -> u32 {
rotr(x, 2) ^ rotr(x, 13) ^ rotr(x, 22)
}
#[inline(always)]
fn big_sigma1(x: u32) -> u32 {
rotr(x, 6) ^ rotr(x, 11) ^ rotr(x, 25)
}
#[inline(always)]
fn small_sigma0(x: u32) -> u32 {
rotr(x, 7) ^ rotr(x, 18) ^ (x >> 3)
}
#[inline(always)]
fn small_sigma1(x: u32) -> u32 {
rotr(x, 17) ^ rotr(x, 19) ^ (x >> 10)
}
fn pad_message(data: &[u8]) -> Vec<u8> {
let bit_len = (data.len() as u64).wrapping_mul(8);
let mut padded = Vec::with_capacity(data.len() + 72);
padded.extend_from_slice(data);
padded.push(0x80);
while padded.len() % 64 != 56 {
padded.push(0x00);
}
padded.extend_from_slice(&bit_len.to_be_bytes());
padded
}
fn process_block(state: &mut [u32; 8], block: &[u8]) {
debug_assert_eq!(block.len(), 64);
let mut w = [0u32; 64];
for i in 0..16 {
w[i] = u32::from_be_bytes([
block[i * 4],
block[i * 4 + 1],
block[i * 4 + 2],
block[i * 4 + 3],
]);
}
for i in 16..64 {
w[i] = small_sigma1(w[i - 2])
.wrapping_add(w[i - 7])
.wrapping_add(small_sigma0(w[i - 15]))
.wrapping_add(w[i - 16]);
}
let mut a = state[0];
let mut b = state[1];
let mut c = state[2];
let mut d = state[3];
let mut e = state[4];
let mut f = state[5];
let mut g = state[6];
let mut h = state[7];
for i in 0..64 {
let t1 = h
.wrapping_add(big_sigma1(e))
.wrapping_add(ch(e, f, g))
.wrapping_add(K[i])
.wrapping_add(w[i]);
let t2 = big_sigma0(a).wrapping_add(maj(a, b, c));
h = g;
g = f;
f = e;
e = d.wrapping_add(t1);
d = c;
c = b;
b = a;
a = t1.wrapping_add(t2);
}
state[0] = state[0].wrapping_add(a);
state[1] = state[1].wrapping_add(b);
state[2] = state[2].wrapping_add(c);
state[3] = state[3].wrapping_add(d);
state[4] = state[4].wrapping_add(e);
state[5] = state[5].wrapping_add(f);
state[6] = state[6].wrapping_add(g);
state[7] = state[7].wrapping_add(h);
}
pub fn sha256(data: &[u8]) -> [u8; 32] {
let padded = pad_message(data);
let mut state = H_INIT;
for block in padded.chunks_exact(64) {
process_block(&mut state, block);
}
let mut digest = [0u8; 32];
for (i, &word) in state.iter().enumerate() {
let bytes = word.to_be_bytes();
digest[i * 4] = bytes[0];
digest[i * 4 + 1] = bytes[1];
digest[i * 4 + 2] = bytes[2];
digest[i * 4 + 3] = bytes[3];
}
digest
}
#[derive(Debug, Clone)]
pub struct Sha256 {
state: [u32; 8],
buffer: [u8; 64],
buffer_len: usize,
total_len: u64,
}
impl Default for Sha256 {
fn default() -> Self {
Self::new()
}
}
impl Sha256 {
pub fn new() -> Self {
Self {
state: H_INIT,
buffer: [0u8; 64],
buffer_len: 0,
total_len: 0,
}
}
pub fn update(&mut self, data: &[u8]) {
self.total_len = self.total_len.wrapping_add(data.len() as u64);
let mut input = data;
if self.buffer_len > 0 {
let needed = 64 - self.buffer_len;
if input.len() < needed {
self.buffer[self.buffer_len..self.buffer_len + input.len()]
.copy_from_slice(input);
self.buffer_len += input.len();
return;
}
self.buffer[self.buffer_len..64].copy_from_slice(&input[..needed]);
process_block(&mut self.state, &self.buffer);
self.buffer_len = 0;
input = &input[needed..];
}
while input.len() >= 64 {
process_block(&mut self.state, &input[..64]);
input = &input[64..];
}
if !input.is_empty() {
self.buffer[..input.len()].copy_from_slice(input);
self.buffer_len = input.len();
}
}
pub fn finalize(mut self) -> [u8; 32] {
let bit_len = self.total_len.wrapping_mul(8);
self.buffer[self.buffer_len] = 0x80;
self.buffer_len += 1;
if self.buffer_len > 56 {
for i in self.buffer_len..64 {
self.buffer[i] = 0;
}
process_block(&mut self.state, &self.buffer);
self.buffer = [0u8; 64];
self.buffer_len = 0;
}
for i in self.buffer_len..56 {
self.buffer[i] = 0;
}
self.buffer[56..64].copy_from_slice(&bit_len.to_be_bytes());
process_block(&mut self.state, &self.buffer);
let mut digest = [0u8; 32];
for (i, &word) in self.state.iter().enumerate() {
let bytes = word.to_be_bytes();
digest[i * 4..i * 4 + 4].copy_from_slice(&bytes);
}
digest
}
}
pub fn hex_to_hash(hex: &str) -> Result<[u8; 32], String> {
if hex.len() != 64 {
return Err(format!("expected 64 hex chars, got {}", hex.len()));
}
let mut hash = [0u8; 32];
for i in 0..32 {
hash[i] = u8::from_str_radix(&hex[i * 2..i * 2 + 2], 16)
.map_err(|_| format!("invalid hex at position {}", i * 2))?;
}
Ok(hash)
}
pub fn hex_string(hash: &[u8; 32]) -> String {
let mut s = String::with_capacity(64);
for &byte in hash {
s.push_str(&format!("{:02x}", byte));
}
s
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn test_sha256_empty_string() {
let digest = sha256(b"");
assert_eq!(
hex_string(&digest),
"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
);
}
#[test]
fn test_sha256_abc() {
let digest = sha256(b"abc");
assert_eq!(
hex_string(&digest),
"ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
);
}
#[test]
fn test_sha256_448_bit_message() {
let digest = sha256(b"abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq");
assert_eq!(
hex_string(&digest),
"248d6a61d20638b8e5c026930c3e6039a33ce45964ff2167f6ecedd419db06c1"
);
}
#[test]
fn test_sha256_deterministic() {
let d1 = sha256(b"hello world");
let d2 = sha256(b"hello world");
assert_eq!(d1, d2, "SHA-256 must be deterministic");
}
#[test]
fn test_sha256_different_inputs() {
let d1 = sha256(b"hello");
let d2 = sha256(b"Hello");
assert_ne!(d1, d2, "Different inputs must produce different hashes");
}
#[test]
fn test_sha256_single_char() {
let digest = sha256(b"a");
assert_eq!(
hex_string(&digest),
"ca978112ca1bbdcafac231b39a23dc4da786eff8147c4e72b9807785afee48bb"
);
}
#[test]
fn test_hex_string_format() {
let hash = [0u8; 32];
let s = hex_string(&hash);
assert_eq!(s.len(), 64);
assert_eq!(s, "0000000000000000000000000000000000000000000000000000000000000000");
}
fn streamed(chunks: &[&[u8]]) -> [u8; 32] {
let mut h = Sha256::new();
for c in chunks {
h.update(c);
}
h.finalize()
}
#[test]
fn streaming_matches_one_shot_empty() {
assert_eq!(streamed(&[]), sha256(b""));
assert_eq!(streamed(&[b""]), sha256(b""));
}
#[test]
fn streaming_matches_one_shot_short() {
assert_eq!(streamed(&[b"abc"]), sha256(b"abc"));
assert_eq!(streamed(&[b"a"]), sha256(b"a"));
assert_eq!(streamed(&[b"hello world"]), sha256(b"hello world"));
}
#[test]
fn streaming_matches_one_shot_chunked() {
let full = b"abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq";
let one_shot = sha256(full);
assert_eq!(streamed(&[full]), one_shot);
assert_eq!(streamed(&[&full[..3], &full[3..]]), one_shot);
assert_eq!(streamed(&[&full[..1], &full[1..2], &full[2..]]), one_shot);
assert_eq!(
streamed(&[&full[..16], &full[16..32], &full[32..48], &full[48..]]),
one_shot
);
}
#[test]
fn streaming_matches_one_shot_block_boundary() {
for &n in &[55usize, 56, 57, 63, 64, 65, 119, 128, 191, 192, 256, 1000] {
let input: Vec<u8> = (0..n).map(|i| (i & 0xff) as u8).collect();
let one_shot = sha256(&input);
assert_eq!(streamed(&[&input]), one_shot, "len={n} single-update");
let chunks: Vec<&[u8]> = (0..n).map(|i| &input[i..i + 1]).collect();
assert_eq!(streamed(&chunks), one_shot, "len={n} byte-by-byte");
assert_eq!(
streamed(&[&input[..n / 2], &input[n / 2..]]),
one_shot,
"len={n} half-and-half"
);
}
}
#[test]
fn streaming_matches_concat_one_shot_for_audit_pattern() {
let prev_hash = [0xa5u8; 32];
for payload_len in [0usize, 1, 16, 32, 56, 63, 64, 65, 96, 128, 257] {
let payload: Vec<u8> = (0..payload_len).map(|i| (i & 0xff) as u8).collect();
let mut concat = Vec::with_capacity(32 + payload.len());
concat.extend_from_slice(&prev_hash);
concat.extend_from_slice(&payload);
let one_shot = sha256(&concat);
let streamed = {
let mut h = Sha256::new();
h.update(&prev_hash);
h.update(&payload);
h.finalize()
};
assert_eq!(streamed, one_shot, "audit pattern, payload_len={payload_len}");
}
}
#[test]
fn streaming_default_equals_new() {
let mut a = Sha256::new();
let mut b = Sha256::default();
a.update(b"abc");
b.update(b"abc");
assert_eq!(a.finalize(), b.finalize());
}
#[test]
fn streaming_clone_independent() {
let mut a = Sha256::new();
a.update(b"prefix");
let b = a.clone();
a.update(b"-suffix-A");
let mut c = b;
c.update(b"-suffix-B");
assert_eq!(a.finalize(), sha256(b"prefix-suffix-A"));
assert_eq!(c.finalize(), sha256(b"prefix-suffix-B"));
}
}