Functional Weave
Code in Python

crypto.sha256

The SHA-256 digest of a byte string (FIPS 180-4), in pure code that also runs in the browser.

1.0.0 · published 2026-10-03 by charlie · Anterra

Pinned by 13 tests, run in TypeScript, Python and Rust.

What it does

`sha256(utf8Encode("abc"))` is the 32 bytes `ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad` (print them with `hexEncode`). This is SHA-256 exactly as FIPS 180-4 defines it.

Bytes in and out are lists of integers 0 to 255, as everywhere in the registry (see `encoding.hex`); hash text by encoding it with `encoding.utf8` first, so all three languages hash the same bytes.

For example

  • sha256() → 227, 176, 196, 66, 152, 252, 28, 20, 154, 251, 244, 200, 153, 111, 185, 36, 39, 174, 65, 228, 100, 155, 147, 76, 164, 149, 153, 27, 120, 82, 184, 85 FIPS 180-4 example: the empty message
  • sha256(97, 98, 99) → 186, 120, 22, 191, 143, 1, 207, 234, 65, 65, 64, 222, 93, 174, 34, 35, 176, 3, 97, 163, 150, 23, 122, 156, 180, 16, 255, 97, 242, 0, 21, 173 FIPS 180-4 example: "abc", one block
  • sha256(97, 98, 99, 100, 98, 99, 100, 101, 99, 100, 101, 102, 100, 101, 102, 103, 101, 102, 103, 104, 102, 103, 104, 105, 103, 104, 105, 106, 104, 105, 106, 107, 105, 106, 107, 108, 106, …) → 36, 141, 106, 97, 210, 6, 56, 184, 229, 192, 38, 147, 12, 62, 96, 57, 163, 60, 228, 89, 100, 255, 33, 103, 246, 236, 237, 212, 25, 219, 6, 193 FIPS 180-4 example: the 448-bit message, whose padding needs a second block

The function

The same function in TypeScript, Python and Rust, pinned by the same tests. Pick your language; the choice follows you around the registry.

def sha256(bytes: Sequence[int]) -> List[int]
bytesint[]the message, each an integer from 0 to 255; hash text with encoding.utf8 first
returnsint[]the 32-byte digest; encoding.hex prints it the way sha256sum does

Your code names it in one line, in the file that uses it

from fune.crypto.sha256 import sha256  # crypto.sha256@^1
impl/python.py · 18 lines · open · raw
import builtins
import hashlib
from typing import List, Sequence


def sha256(bytes: Sequence[int]) -> List[int]:
    """The SHA-256 digest of a byte string (FIPS 180-4), from hashlib.

    A Python ``bytes`` value is accepted as is; a list must hold integers
    0-255, checked here so a bad value fails with the same words as in
    TypeScript and Rust rather than hashlib's own.
    """
    if isinstance(bytes, (str, dict)) or not hasattr(bytes, "__len__"):
        raise TypeError("bytes must be a list of integers from 0 to 255")
    for b in bytes:
        if type(b) is not int or b < 0 or b > 255:
            raise ValueError("bytes must be a list of integers from 0 to 255")
    return list(hashlib.sha256(builtins.bytes(bytes)).digest())

Install

fune build

With that line in your source, in a Python project (language python in fune.project), fune build resolves it and nothing else, pins them in fune.lock, downloads only the Python package of each, and builds the code above into your project’s .fune/build, one readable file per capability with a header linking back here. Or pin a range in fune.project and build in one step:

fune add crypto.sha256
Download for Python crypto.sha256-1.0.0-python.fune · 9,009 bytes sha256 0dc9805f42b79d2e66c7aa4e9b658d7069bac35156fac942c71689026653dc9b

The manifest, vectors and README with only the Python implementation. Install it without the registry with fune add ./crypto.sha256-1.0.0-python.fune, or fetch it from a terminal with fune pull crypto.sha256@1.0.0:python.

The whole function, every language, is one file too: crypto.sha256-1.0.0.fune, 17,379 bytes, sha256 beb0733f73c235f9276b554934618e517a26461d4bf4350f5465f14bfd89c645. It installs into a project of any language.

Customise it in your app

The seams this capability offers. Put a marker directly above a function of your own and fune build wires it into the built code; the package on the registry is not changed, the built file’s header lists it under CUSTOMISED, and fune hooks lists every hook in the project. How hooks work.

before — your function gets the arguments and returns them, changed or not, or throws to refuse the call.

# fune: before crypto.sha256

after — your function gets the result and the arguments, and returns the final result.

# fune: after crypto.sha256

replace — it requires no other capability, so there is no dependency to replace.

step — your function runs at a numbered point inside the function’s body, receives the in-scope values it names as parameters, and may return replacements. List the points with fune show crypto.sha256 --steps.

# fune: step crypto.sha256 after <n|label>

Tests

A version published now needs at least 8 tests for every function, and one that expects the error for each function that throws; the registry refuses it otherwise. fune verify --all runs each case in TypeScript, Python and Rust, and a project runs them again with fune verify. This page lists the cases; it does not run them. The exact JSON is vectors.json.

CaseArgumentsExpected
FIPS 180-4 example: the empty message → 227, 176, 196, 66, 152, 252, 28, 20, 154, 251, 244, 200, 153, 111, 185, 36, 39, 174, 65, 228, 100, 155, 147, 76, 164, 149, 153, 27, 120, 82, 184, 85
FIPS 180-4 example: "abc", one block 97, 98, 99 → 186, 120, 22, 191, 143, 1, 207, 234, 65, 65, 64, 222, 93, 174, 34, 35, 176, 3, 97, 163, 150, 23, 122, 156, 180, 16, 255, 97, 242, 0, 21, 173
FIPS 180-4 example: the 448-bit message, whose padding needs a second block 97, 98, 99, 100, 98, 99, 100, 101, 99, 100, 101, 102, 100, 101, 102, 103, 101, 102, 103, 104, 102, 103, 104, 105, 103, 104, 105, 106, 104, 105, 106, 107, 105, 106, 107, 108, 106, … → 36, 141, 106, 97, 210, 6, 56, 184, 229, 192, 38, 147, 12, 62, 96, 57, 163, 60, 228, 89, 100, 255, 33, 103, 246, 236, 237, 212, 25, 219, 6, 193
FIPS 180-4 example: the 896-bit message 97, 98, 99, 100, 101, 102, 103, 104, 98, 99, 100, 101, 102, 103, 104, 105, 99, 100, 101, 102, 103, 104, 105, 106, 100, 101, 102, 103, 104, 105, 106, 107, 101, 102, 103, 104, 105, … → 207, 91, 22, 167, 120, 175, 131, 128, 3, 108, 229, 158, 123, 4, 146, 55, 11, 36, 155, 17, 232, 240, 122, 81, 175, 172, 69, 3, 122, 254, 233, 209
the pangram 84, 104, 101, 32, 113, 117, 105, 99, 107, 32, 98, 114, 111, 119, 110, 32, 102, 111, 120, 32, 106, 117, 109, 112, 115, 32, 111, 118, 101, 114, 32, 116, 104, 101, 32, 108, 97, 122, … → 215, 168, 251, 179, 7, 215, 128, 148, 105, 202, 154, 188, 176, 8, 46, 79, 141, 86, 81, 228, 109, 60, 219, 118, 45, 2, 208, 191, 55, 201, 229, 146
55 bytes, the most that fits one block with its padding (hashlib as the reference) 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97,… → 159, 67, 144, 248, 211, 12, 45, 217, 46, 201, 240, 149, 182, 94, 43, 154, 233, 176, 169, 37, 165, 37, 142, 36, 28, 159, 30, 145, 15, 115, 67, 24
56 bytes, one too many for one block (hashlib as the reference) 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97,… → 179, 84, 57, 164, 172, 111, 9, 72, 182, 214, 249, 227, 198, 175, 15, 95, 89, 12, 226, 15, 27, 222, 112, 144, 239, 121, 112, 104, 110, 198, 115, 138
64 bytes, exactly one block of message (hashlib as the reference) 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97,… → 255, 224, 84, 254, 122, 224, 203, 109, 198, 92, 58, 249, 182, 29, 82, 9, 244, 57, 133, 29, 180, 61, 11, 165, 153, 115, 55, 223, 21, 70, 104, 235
119 bytes, the most that fits two blocks (hashlib as the reference) 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97, 97,… → 49, 235, 165, 28, 49, 58, 92, 8, 34, 106, 223, 24, 212, 163, 89, 207, 223, 216, 210, 232, 22, 177, 63, 74, 249, 82, 247, 234, 101, 132, 220, 251
a single zero byte is not the empty message 0 → 110, 52, 11, 156, 255, 179, 122, 152, 156, 165, 68, 230, 187, 120, 10, 44, 120, 144, 29, 63, 179, 55, 56, 118, 133, 17, 163, 6, 23, 175, 160, 29
Show the other 3 tests
CaseArgumentsExpected
256 is not a byte 97, 256 → error: bytes must be a list of integers from 0 to 255
a fraction is not a byte 97.5 → error: bytes must be a list of integers from 0 to 255
a character is not a byte: encode text with encoding.utf8 first a → error: bytes must be a list of integers from 0 to 255

More from the author

The TypeScript implementation is plain code with no `node:crypto` and no `crypto.subtle`, so it runs unchanged in a browser, in Node and in a worker, synchronously (`crypto.subtle.digest` is asynchronous and only exists in secure contexts). The Python implementation uses the standard library's `hashlib`, and the Rust one is written out with the standard library only. All three are checked against the same vectors.

A hash is not a password hash: a single SHA-256 of a password can be guessed billions of times a second. Store passwords with `auth.password-hash`, which uses PBKDF2 with a salt and many iterations. A hash is not a MAC either: to prove a message came from someone holding a key, use `crypto.hmac-sha256` (prefixing the key and hashing is open to length extension).

The digests in the vectors are the published ones: "abc" and the 448-bit message from the NIST example values for FIPS 180-4 (SHA256.pdf), the empty string, the pangram, and messages of 55, 56, 64 and 119 bytes, which sit on either side of the points where the padding needs a second block.

Source: FIPS 180-4, Secure Hash Standard, section 6.2 (https://csrc.nist.gov/pubs/fips/180-4/upd1/final) and the NIST cryptographic standards example values (https://csrc.nist.gov/projects/cryptographic-standards-and-guidelines/example-values).

Files

PathBytes
README.md1,731
impl/python.py750
impl/rust.rs3,849
impl/typescript.ts4,284
vectors.json5,012