Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Python streaming SHA-256: hash bytes without a second full copy

Last updated: 1 Oct 20265 min read
tutorial
IntermediateBy AITrove Editorial

A digest can be updated in chunks while reading a byte stream, but it does not authenticate who supplied the bytes.

Download Python source kit

Operation contract

The receipt payload is fed to SHA-256 seven bytes at a time. Its result matches a one-shot digest of the same bytes. The chunk loop is useful when the input is a file or stream and retaining another complete copy would be wasteful. The exact bytes and their order are part of the contract; text normalization changes the digest.

Failure and ownership boundary

A matching digest detects accidental changes only when the expected digest comes from a trusted channel. An attacker who can replace both content and its plain digest can make them agree. Use a keyed MAC or signature for sender authentication. For an untrusted stream, enforce byte and time limits while hashing.

Working program

python
import hashlib
import io

payload = b"R" * 47 + b"|north-47"
digest = hashlib.sha256()
source = io.BytesIO(payload)
while chunk := source.read(7):
    digest.update(chunk)
expected = hashlib.sha256(payload).digest()
print("same", digest.digest() == expected)
print("bytes", len(payload))

Output

Output
same True
bytes 56

Costs and limits

Hashing visits each byte once and retains a fixed digest state plus one seven-byte chunk here. Its CPU cost grows linearly with input size.

Common Mistakes

  • A plain digest is not an authentication tag.
  • Hash the exact bytes that the protocol defines.
  • A streaming hash does not impose its own input-size limit.

Connected lessons

Test this boundary.

python
hashlib-streaming-integrity
Storage details