ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
sha256.h File Reference

SHA-256 (FIPS 180-4) - streaming and one-shot digest. More...

#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  Sha256Ns
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Macros

#define PROTOCORE_SHA256_DIGEST_LEN   32
 SHA-256 digest length in bytes.
 
#define PROTOCORE_SHA256_BLOCK_LEN   64
 SHA-256 block size in bytes.
 

Functions

 PROTOCORE_NS_LAYOUT (Sha256Ns, init, update, final, hash)
 
proto_bool protocore_sha256_init (uint8_t *work)
 Start a digest.
 
proto_bool protocore_sha256_update (uint8_t *work, const uint8_t *data, size_t len)
 Feed the running digest a chunk.
 
proto_bool protocore_sha256_final (uint8_t *work, uint8_t *out)
 Pad, compress the last block, write the 32 bytes out.
 
proto_bool protocore_sha256_hash (uint8_t *work, const uint8_t *data, size_t len, uint8_t *out)
 Init, update and final in one call, for a message already whole.
 

Variables

PROTOCORE_NS Sha256Ns Sha256 PROTOCORE_UNUSED
 Module namespace.
 

Detailed Description

SHA-256 (FIPS 180-4) - streaming and one-shot digest.

The shared SHA-256 primitive for the whole library (SSH per-packet HMAC and KEX exchange-hash, TLS 1.3 / QUIC / DTLS key schedules, SNMPv3, JWT, CSRF, SMB 2.x message signing). The entries below are one surface over both arms: a part with a hashing peripheral compresses on it, a part without runs the FIPS 180-4 rounds. Mirrors the sha512 structure.

Sha256Ns::final leaves the running digest where it was: the padded blocks compress into a copy of the state, so the hash keeps taking data afterwards. That is what lets TLS 1.3 read Transcript-Hash at every stage the key schedule asks for without snapshotting anything.

work is PROTOCORE_SHA256_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. The borrow IS the digest, so two running hashes are two borrows and never collide.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file sha256.h.

Macro Definition Documentation

◆ PROTOCORE_SHA256_DIGEST_LEN

#define PROTOCORE_SHA256_DIGEST_LEN   32

SHA-256 digest length in bytes.

Definition at line 34 of file sha256.h.

◆ PROTOCORE_SHA256_BLOCK_LEN

#define PROTOCORE_SHA256_BLOCK_LEN   64

SHA-256 block size in bytes.

Definition at line 37 of file sha256.h.

Function Documentation

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( Sha256Ns  ,
init  ,
update  ,
final  ,
hash   
)

◆ protocore_sha256_init()

proto_bool protocore_sha256_init ( uint8_t *  work)

Start a digest.

Parameters
workPROTOCORE_SHA256_BORROW bytes the caller took. Not held past the call.
Returns
PROTO_TRUE on success.

◆ protocore_sha256_update()

proto_bool protocore_sha256_update ( uint8_t *  work,
const uint8_t *  data,
size_t  len 
)

Feed the running digest a chunk.

Parameters
workPROTOCORE_SHA256_BORROW bytes the caller took. Not held past the call.
datathe bytes
lenhow many
Returns
PROTO_TRUE on success.

◆ protocore_sha256_final()

proto_bool protocore_sha256_final ( uint8_t *  work,
uint8_t *  out 
)

Pad, compress the last block, write the 32 bytes out.

Parameters
workPROTOCORE_SHA256_BORROW bytes the caller took. Not held past the call.
outPROTOCORE_SHA256_DIGEST_LEN bytes
Returns
PROTO_TRUE on success.

◆ protocore_sha256_hash()

proto_bool protocore_sha256_hash ( uint8_t *  work,
const uint8_t *  data,
size_t  len,
uint8_t *  out 
)

Init, update and final in one call, for a message already whole.

Parameters
workPROTOCORE_SHA256_BORROW bytes the caller took. Not held past the call.
datathe message
lenits length
outPROTOCORE_SHA256_DIGEST_LEN bytes
Returns
PROTO_TRUE on success.

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS Sha256Ns Sha256 PROTOCORE_UNUSED
Initial value:
proto_bool protocore_sha256_update(uint8_t *work, const uint8_t *data, size_t len)
Feed the running digest a chunk.
proto_bool protocore_sha256_init(uint8_t *work)
Start a digest.
proto_bool protocore_sha256_final(uint8_t *work, uint8_t *out)
Pad, compress the last block, write the 32 bytes out.
proto_bool protocore_sha256_hash(uint8_t *work, const uint8_t *data, size_t len, uint8_t *out)
Init, update and final in one call, for a message already whole.

Module namespace.

Definition at line 81 of file sha256.h.