]> git.ipfire.org Git - thirdparty/Python/cpython.git/commit
gh-99108: Replace SHA2-224 & 256 with verified code from HACL* (#99109)
authorJonathan Protzenko <protz@microsoft.com>
Tue, 7 Feb 2023 02:11:01 +0000 (18:11 -0800)
committerGitHub <noreply@github.com>
Tue, 7 Feb 2023 02:11:01 +0000 (18:11 -0800)
commit1fcc0efdaa84b3602c236391633b70ff36df149b
treec3be6de92320d8e82e9d94849ec22f9268b6dfc3
parent914f8fd9f7fc5e48b54d938a68c932cc618ef3a6
gh-99108: Replace SHA2-224 & 256 with verified code from HACL* (#99109)

replacing hashlib primitives (for the non-OpenSSL case) with verified implementations from HACL*. This is the first PR in the series, and focuses specifically on SHA2-256 and SHA2-224.

This PR imports Hacl_Streaming_SHA2 into the Python tree. This is the HACL* implementation of SHA2, which combines a core implementation of SHA2 along with a layer of buffer management that allows updating the digest with any number of bytes. This supersedes the previous implementation in the tree.

@franziskuskiefer was kind enough to benchmark the changes: in addition to being verified (thus providing significant safety and security improvements), this implementation also provides a sizeable performance boost!

```
---------------------------------------------------------------
Benchmark                     Time             CPU   Iterations
---------------------------------------------------------------
Sha2_256_Streaming            3163 ns      3160 ns       219353     // this PR
LibTomCrypt_Sha2_256          5057 ns      5056 ns       136234     // library used by Python currently
```

The changes in this PR are as follows:
- import the subset of HACL* that covers SHA2-256/224 into `Modules/_hacl`
- rewire sha256module.c to use the HACL* implementation

Co-authored-by: Gregory P. Smith [Google LLC] <greg@krypto.org>
Co-authored-by: Erlend E. Aasland <erlend.aasland@protonmail.com>
18 files changed:
Lib/test/test_hashlib.py
Makefile.pre.in
Misc/NEWS.d/next/Security/2022-11-08-12-06-52.gh-issue-99108.4Wrsuh.rst [new file with mode: 0644]
Modules/Setup.stdlib.in
Modules/_hacl/Hacl_Streaming_SHA2.c [new file with mode: 0644]
Modules/_hacl/Hacl_Streaming_SHA2.h [new file with mode: 0644]
Modules/_hacl/README.md [new file with mode: 0644]
Modules/_hacl/include/krml/FStar_UInt_8_16_32_64.h [new file with mode: 0644]
Modules/_hacl/include/krml/internal/target.h [new file with mode: 0644]
Modules/_hacl/include/krml/lowstar_endianness.h [new file with mode: 0644]
Modules/_hacl/include/python_hacl_namespaces.h [new file with mode: 0644]
Modules/_hacl/internal/Hacl_SHA2_Generic.h [new file with mode: 0644]
Modules/_hacl/refresh.sh [new file with mode: 0755]
Modules/sha256module.c
PCbuild/pythoncore.vcxproj
PCbuild/pythoncore.vcxproj.filters
configure
configure.ac