Skip to content

Host SHA-256 primitive sha256_hex_of_text beside the HMAC seam (d0_store_operation_wall, before PR 4a) - #12718

Closed
gunbai-bot[bot] wants to merge 4 commits into
mainfrom
lively-dove-256-sha256host
Closed

gunbai-bot[bot] wants to merge 4 commits into
mainfrom
lively-dove-256-sha256host

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Host SHA-256 primitive for the d0_store_operation_wall chain (proud-deer-538, option A). It lands before #12537 (PR 4a), which consumes it.

Why. The fabric store door digests the approved intent on every protected write, checking that the SHA-256 of the presented intent is the approved revision. The only substrate SHA-256, the pure extdeps.crypto.sha2 fold, costs about 200k interpreted eval steps per 64-octet block, measured below. That put #12537's admission witnesses at 533k–910k steps against the 72.3k new-witness budget, and it is the door's per-write cost too.

What. sha256_hex_of_text(text) returns the lowercase-hex SHA-256 of the text's UTF-8 bytes. It is wired exactly like hmac_sha256_hex, and is the same RustCrypto sha2 crate the HMAC seam already uses:

  • src/v1/04_method.dag builtin signature, plus the regenerated v1_compiler_infer_method.rs (the stage0 --required-regen candidate; only this file drifted);
  • the interpreter arm and sha256_hex_of_text_digest, plus the regenerated v1_interpreter_dispatch_generated.rs;
  • the gunbc.v1_interpreter_primitive_surface authored arm;
  • std.primitives sha256_hex_of_text_contract and both rosters;
  • the gunbc.primitive_egress evidence row.

Seed growth. gunbc.host_crypto_digest_seed_growth enumerates both host digest seams: sha256_hex_of_text_digest, and hmac_sha256_hex_tag, which had no receipt. It is registered in gunbc.seed_growth_admission. Retirement trigger: an emitted rt_function_registry bridge body admitted by the #12389 gate, so that the digests run in emitted code.

v1 admission. This serves v2's fabric store door, which is the purpose test of gunbc.v1_maintenance_standing v1_seed_standing. That standing records refusals, not per-change admissions, so the admission is stated here and in the seed-growth receipt.

Evidence.

  • On the floor: test.claim.sha256_host_known_answer_witness. Nine host-vs-known-answer claims, at most 7 eval steps each, all PASS locally:
    • empty, abc and the NIST 448-bit text, whose values test.claim.sha256_fips_witness_test (grandfathered) asserts of the pure fold, so host == pure holds transitively through the shared value;
    • the padding boundaries 55, 56, 63, 64, 65 and a 130-octet three-block text, with known answers from an independent implementation (Python hashlib). On these the pure fold is not asserted on the floor.
  • Local receipt (not gated): the direct comparison, host == pure fold == known answer, on all nine vectors. It was run with claim_batch built from this branch, and all nine PASS. Its eval steps were: empty 236,231; abc 205,849; 55 → 206,192; 56 → 391,980; 63 → 392,807; 64 → 392,661; 65 → 393,392; 448-bit 396,340; 130-octet 582,121. That is the per-block cost that motivated this change.

🤖 Generated with Claude Code

Brian Searls and others added 2 commits September 30, 2026 00:16
…the pure fold as its differential oracle

The fabric store door digests an approved intent on every protected write;
the pure extdeps.crypto.sha2 fold costs ~200k interpreted eval steps per
64-octet block (measured). sha256_hex_of_text is the RustCrypto sha2 digest of
the text's UTF-8 bytes, wired exactly like hmac_sha256_hex: 04_method builtin
signature (+ regenerated v1_compiler_infer_method.rs), interpreter arm
(+ regenerated dispatch), authored dispatch row, std.primitives contract and
rosters, primitive_egress evidence row. test.claim.sha256_host_differential_
witness: host == pure fold == known answer on empty, abc, 55/56/63/64/65,
130-octet and the NIST 448-bit text (all PASS locally).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…vely through sha256_fips_witness's KATs), and the host crypto seams' seed-growth receipt

Per proud-deer-538: the floor carries only host-vs-known-answer claims (7
eval steps at most) over the FIPS vectors sha256_fips_witness asserts of the
pure fold plus the padding boundaries; the direct pure-vs-host comparison is a
local receipt. gunbc.host_crypto_digest_seed_growth enumerates both host
digest seams (sha256_hex_of_text_digest, and hmac_sha256_hex_tag, which had
none), retired by an emitted #12389 bridge body.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 30, 2026
…; witnesses over pinned receipts at one interface

intent_digest calls sha256_hex_of_text instead of the pure fold. The
admission witnesses take receipts as supplied values (the mint's own claim
constructor, tag and revision computed outside the substrate and pinned),
not re-running issuance per claim; the positive control admits only when the
store's own digest equals the pinned revision and the pinned tag verifies.
Measured locally: 6 PASS, max 49,380 eval steps (was 533k-910k).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ns, which had captured them (review 72974)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 72974 in b583a71. Both placements are fixed. sha256_hex_of_text_contract and its comment now sit above the HMAC "Issuance:" block, which is back on hmac_sha256_hex_contract. sha256_hex_of_text_digest sits above the /// doc, which is back on hmac_sha256_hex_tag.

— sent from lively-dove-256

… placed under its own comment (review 73004)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 73004 in 402742c. All three findings are fixed.

  1. Citations. The unresolvable extdeps.crypto.hash sha256_hex_of_text is gone. The interpreter comment and the egress row now cite std.primitives sha256_hex_of_text_contract as the home, and extdeps.crypto.sha2 sha256_hex as the pure fold sharing its known answers.
  2. Consumer. The frontier and its trigger are now on sha256_hex_of_text_contract. The consumer is gunbc.fabric_store_operation_admission intent_digest in Fabric store per-operation admission fold (d0_store_operation_wall PR 4a) #12537, which already calls it on its branch. The trigger is that change landing. If the door digests some other way, the primitive is deleted with it.
  3. Arm placement. The SHA-256 arm now sits above the HMAC issuance comment, under its own one-line comment (total, no refusal).

— sent from lively-dove-256

@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Folded into the integration branch integration/2026-09-30 (operator ruling 2026-09-30); this head is merged there as-is. — sent from proud-deer-538

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants