SHA-256 (FIPS 180-4 §6.2) — 256-bit hash, parametric factory shared with sha224.

Module sha256 | Source packages/front/fw/src/crypto/hash/sha256.js | Deps bitArray, utf8 | Worker-safe yes

Streaming fn API + one-shot hash. The parametric factory _internal.makeSha(init, outWords) is used by sha224 (mirrors the sha512 ↔ sha512_224 / sha512_256 pattern).

Resolve

const sha256 = runtime.resolve('sha256');
// Returns: { fn, hash, _internal }

API

Method Signature Returns
hash (data: string | bitArray) => bitArray Digest (8 words × 32 bits = 256 bits)
fn constructor() or constructor(other) Streaming instance, copy constructor for cloning
fn.prototype.update (data: string | bitArray) => this Absorbs; chainable
fn.prototype.finalize () => bitArray Emits the digest and resets
fn.prototype.reset () => this Reinitializes state
_internal.makeSha (init: number[], outWords: number) => {fn, hash} Parametric builder (used by sha224)

Examples

One-shot

const { sha256, hex, bitArray } = fw.runtime.resolveAll(['sha256', 'hex', 'bitArray']);

const digestBa = sha256.hash('abc');
hex.fromBytes(bitArray.ba_to_ui8(digestBa));
// "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"

Streaming

const h = new sha256.fn();
h.update('hello ').update('world');
const digestBa = h.finalize();

LDT 1 GiB (CRYPTO_FULL)

// CRYPTO_FULL=1 bun test src/crypto/hash/sha256.test.js
// Validates the 64-bit _length counter FIPS 180-4 §5.1.1 over 8 589 934 592 bits.

Worker Usage

const worker = fw.createWorker(
    function ({ libs, args }) {
        self.postMessage(libs.sha256.hash(args[0]));
    },
    { dependencies: ['sha256'], args: ['hello'] }
);

Notes

  • Max limit: update rejects via false + console.warn('INVALID') beyond 2⁵³−1 bits (IEEE-754 limit of the _length counter).
  • update after finalize: finalize() resets state → the instance is reusable. To clone without reset: new sha256.fn(other).
  • LDT (Large Data Test) 1 GiB validation gated behind CRYPTO_FULL=1 (Iteration H1).

See also