SHA-512/256 (FIPS 180-4 §5.3.6.2) — wrapper over sha512 with a distinct IV + 8-word truncation = 256 bits.
Module sha512_256 | Source packages/front/fw/src/crypto/hash/sha512_256.js | Deps sha512 | Worker-safe yes
256-bit security like SHA-256, with no length-extension risk thanks to internal truncation. Recommended by NIST SP 800-185 §4.
Resolve
const sha512_256 = runtime.resolve('sha512_256');
// Returns: { name, fn, hash }
API
| Method | Signature | Returns |
|---|---|---|
hash |
(data) => bitArray |
Digest 8 words × 32 bits = 256 bits |
fn |
constructor() |
Streaming HMAC-compatible (blockSize 1024) |
Examples
const { sha512_256, hex, bitArray } = fw.runtime.resolveAll(['sha512_256', 'hex', 'bitArray']);
hex.fromBytes(bitArray.ba_to_ui8(sha512_256.hash('abc')));
// "53048e2681941ef99b2e29b76b4c7dabe4c2d0c634fc6d46e0e2f13107e7af23"
Worker Usage
const worker = fw.createWorker(
function ({ libs, args }) { self.postMessage(libs.sha512_256.hash(args[0])); },
{ dependencies: ['sha512_256'], args: ['abc'] }
);
Notes
- Incorrect IV corrected: the widely-circulated value
c84d6b74for H_1 is wrong; this module uses the correct valuec84c64c2(derived by independent computation + cross-checked against OpenSSL). - Block size: 1024 bits.
- LDT 1 GiB gated behind
CRYPTO_FULL=1(gap-fix audit).