SHA-256 (FIPS 180-4 §6.2) — 256-bit hash, parametric factory shared with sha224.
Module sha256 | Source packages/front/fw/src/crypto/hash/sha256.js | Deps bitArray, utf8 | Worker-safe yes
Streaming fn API + one-shot hash. The parametric factory _internal.makeSha(init, outWords) is used by sha224 (mirrors the sha512 ↔ sha512_224 / sha512_256 pattern).
Resolve
const sha256 = runtime.resolve('sha256');
// Returns: { fn, hash, _internal }
API
| Method | Signature | Returns |
|---|---|---|
hash |
(data: string | bitArray) => bitArray |
Digest (8 words × 32 bits = 256 bits) |
fn |
constructor() or constructor(other) |
Streaming instance, copy constructor for cloning |
fn.prototype.update |
(data: string | bitArray) => this |
Absorbs; chainable |
fn.prototype.finalize |
() => bitArray |
Emits the digest and resets |
fn.prototype.reset |
() => this |
Reinitializes state |
_internal.makeSha |
(init: number[], outWords: number) => {fn, hash} |
Parametric builder (used by sha224) |
Examples
One-shot
const { sha256, hex, bitArray } = fw.runtime.resolveAll(['sha256', 'hex', 'bitArray']);
const digestBa = sha256.hash('abc');
hex.fromBytes(bitArray.ba_to_ui8(digestBa));
// "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad"
Streaming
const h = new sha256.fn();
h.update('hello ').update('world');
const digestBa = h.finalize();
LDT 1 GiB (CRYPTO_FULL)
// CRYPTO_FULL=1 bun test src/crypto/hash/sha256.test.js
// Validates the 64-bit _length counter FIPS 180-4 §5.1.1 over 8 589 934 592 bits.
Worker Usage
const worker = fw.createWorker(
function ({ libs, args }) {
self.postMessage(libs.sha256.hash(args[0]));
},
{ dependencies: ['sha256'], args: ['hello'] }
);
Notes
- Max limit:
updaterejects viafalse+console.warn('INVALID')beyond 2⁵³−1 bits (IEEE-754 limit of the_lengthcounter). updateafterfinalize:finalize()resets state → the instance is reusable. To clone without reset:new sha256.fn(other).- LDT (Large Data Test) 1 GiB validation gated behind
CRYPTO_FULL=1(Iteration H1).
See also
- sha224 — truncated wrapper on the same builder
- hmac — MAC consumer (default = sha256)
- Conformance sha256.acvp.md