A digest can be updated in chunks while reading a byte stream, but it does not authenticate who supplied the bytes.
Python streaming SHA-256: hash bytes without a second full copy
Operation contract
The receipt payload is fed to SHA-256 seven bytes at a time. Its result matches a one-shot digest of the same bytes. The chunk loop is useful when the input is a file or stream and retaining another complete copy would be wasteful. The exact bytes and their order are part of the contract; text normalization changes the digest.
Failure and ownership boundary
A matching digest detects accidental changes only when the expected digest comes from a trusted channel. An attacker who can replace both content and its plain digest can make them agree. Use a keyed MAC or signature for sender authentication. For an untrusted stream, enforce byte and time limits while hashing.
Working program
import hashlib
import io
payload = b"R" * 47 + b"|north-47"
digest = hashlib.sha256()
source = io.BytesIO(payload)
while chunk := source.read(7):
digest.update(chunk)
expected = hashlib.sha256(payload).digest()
print("same", digest.digest() == expected)
print("bytes", len(payload))Output
same True
bytes 56Costs and limits
Hashing visits each byte once and retains a fixed digest state plus one seven-byte chunk here. Its CPU cost grows linearly with input size.
Common Mistakes
- A plain digest is not an authentication tag.
- Hash the exact bytes that the protocol defines.
- A streaming hash does not impose its own input-size limit.
