SHA-512 (FIPS 180-4 §6.4) — 512-bit hash; parametric builder shared with sha384/512_224/512_256.
Module sha512 | Source packages/front/fw/src/crypto/hash/sha512.js | Deps bitArray, utf8 | Worker-safe yes
Streaming fn API + one-shot hash. The parametric factory _internal.makeSha(init, outWords) is used by sha384, sha512_224, sha512_256.
Resolve
const sha512 = runtime.resolve('sha512');
// Returns: { fn, hash, _internal }
API
| Method | Signature | Returns |
|---|---|---|
hash |
(data: string | bitArray) => bitArray |
Digest (16 words × 32 bits = 512 bits) |
fn |
constructor() or constructor(other) |
Streaming instance + copy constructor |
fn.prototype.update |
(data) => this |
Absorbs; chainable |
fn.prototype.finalize |
() => bitArray |
Emits the digest and resets |
_internal.makeSha |
(init: number[], outWords: number) => {fn, hash} |
Builder for truncated variants |
Examples
const { sha512, hex, bitArray } = fw.runtime.resolveAll(['sha512', 'hex', 'bitArray']);
const digestBa = sha512.hash('abc');
hex.fromBytes(bitArray.ba_to_ui8(digestBa));
// "ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a..."
Parametric builder (internal)
// Used by sha384.js / sha512_224.js / sha512_256.js
const sha384Like = sha512._internal.makeSha(_INIT_384, 12);
const digest = sha384Like.hash('abc'); // 12 words × 32 = 384 bits
Worker Usage
const worker = fw.createWorker(
function ({ libs, args }) { self.postMessage(libs.sha512.hash(args[0])); },
{ dependencies: ['sha512'], args: ['abc'] }
);
Notes
- Input domain is a
bitArray, not raw bytes.hash(data)accepts a UTF-8 string or abitArray. Passing aUint8Arraydoes not throw — it is consumed as a word array and yields a wrong-but-deterministic digest that still round-trips self-consistently and only fails against official vectors. Convert first:sha512.hash(bitArray.ui8_to_ba(bytes)). The same domain applies to thepkchash helper; the WASMsha2/sha3wrappers, by contrast, consume raw bytes directly. A green round-trip is not evidence of a correct digest. - Block size: 1024 bits (vs 512 for SHA-256). 64-bit
_lengthcounter FIPS 180-4 §5.1.2 limited to 2⁵³−1 by IEEE-754. - 64-bit operations emulated as 32-bit pairs (high/low) — no BigInt.
- LDT 1 GiB validation gated behind
CRYPTO_FULL=1(Iteration H1).
See also
- sha384, sha512_224, sha512_256 — truncated variants
- hmac — HMAC-SHA-512 via
hmac.fn(key, sha512) - Conformance sha512.acvp.md