Skip to content

Hash spec markers with a const SHA-256 - #2080

Merged
leighmcculloch merged 41 commits into
mainfrom
const-sha256-for-spec-markers
Sep 28, 2026
Merged

leighmcculloch merged 41 commits into
mainfrom
const-sha256-for-spec-markers

Conversation

@leighmcculloch

@leighmcculloch leighmcculloch commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

What

Make the function soroban_spec::shaking::generate_marker_for_xdr callable in const contexts and in nostd crates.

Caution

Replaces the use of the sha2 crate for hashing the spec entries with an in-repo const-compatible sha256 implementation.

Why

So that the function can be called from within Soroban contracts, in the definition of a static variable. In the stack of PRs above the PR after this shifts to building XDR into a const, and the XDR will no longer be known at proc-macro execution time. The function generate_marker_for_xdr is currently called from within the proc-macros, but because the XDR will not be known until const evaluation, the marker generation will also need to move to const evaluation.

SemVer Change

  • Major (vX._._) - Breaking change to the public API.
  • Minor (v_.Y._) - Additive change to the public API.
  • Patch (v_._.Z) - No change to the public API.

Fuzz Coverage

Screenshot 2026-09-23 at 3 29 04 pm

Generated by Claude Code

@socket-security

socket-security Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedlibfuzzer-sys@​0.4.134710093100100

View full report

This comment was marked as outdated.

Copilot AI review requested due to automatic review settings September 22, 2026 23:41

This comment was marked as outdated.

Copilot AI review requested due to automatic review settings September 22, 2026 23:46

This comment was marked as outdated.

@leighmcculloch

This comment was marked as outdated.

@leighmcculloch
leighmcculloch force-pushed the const-sha256-for-spec-markers branch from 87c3a1f to 8aacaf3 Compare September 23, 2026 06:57
Copilot AI review requested due to automatic review settings September 23, 2026 06:57

This comment was marked as outdated.

Copilot AI review requested due to automatic review settings September 25, 2026 00:22

This comment was marked as outdated.

@leighmcculloch
leighmcculloch force-pushed the const-sha256-for-spec-markers branch from 82cbe23 to 23f0dc1 Compare September 25, 2026 00:32
@leighmcculloch
leighmcculloch marked this pull request as draft September 25, 2026 11:24
@leighmcculloch
leighmcculloch marked this pull request as ready for review September 25, 2026 13:55
Copilot AI review requested due to automatic review settings September 25, 2026 13:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The package omits test vectors required at compile time, and the fuzz job lacks generic CPU flags.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 High severity

Open (2)
Resolved since last review (1)

Comment thread soroban-spec/Cargo.toml

@mootz12 mootz12 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LG2M!

@leighmcculloch
leighmcculloch added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 453c19a Sep 28, 2026
129 of 137 checks passed
@leighmcculloch
leighmcculloch deleted the const-sha256-for-spec-markers branch September 28, 2026 02:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants