bauta-rs
The optional native masker for Bauta.
Bauta masks data on its way from production to a copy. Masking key and
fpe columns costs tens of microseconds a value in Python, most of it spent in
the interpreter rather than in cryptography. This computes the same masks in
Rust, seven to nine times faster on a whole job on one core, and can use
several.
It is optional. Bauta works without it, and produces identical output either way.
Installing
pip install "bauta[native]"
The extra installs the bauta-rs released with your version of bauta, which
is the only one Bauta uses; any other is ignored with a warning. Wheels cover
Linux (x86-64 and ARM) and macOS (Apple silicon and Intel) on every supported
Python. Elsewhere pip compiles it, which needs Rust 1.83 or newer.
Layout
| Path | What it is |
|---|---|
core/ |
The constructions. No Python dependency, so they are testable without an interpreter. |
py/ |
The PyO3 layer: conversions in, results out, and every unsafe boundary. |
vectors/reference.json |
What the Python implementation produces, recorded. The contract between the two. |
generate_vectors.py |
Regenerates that file from the Python implementation. |
Building
From a clone, with Rust 1.83 or newer.
cargo test --release
cd py && maturin build --release
pip install ../target/wheels/bauta_rs-*.whl
--release matters for the tests: two of them measure SHA-256 and AES
throughput to catch a backend that has silently fallen back to software, and a
debug build is indistinguishable from one. cargo test covers core/; py/
needs a Python interpreter to link, so it is tested from Python, by
tests/masking/test_nativeMasking.py.
Threads, and remembering masks
A chunk's distinct values are masked across a thread pool, whose size the
Python layer sets per process (setThreads) from jobs.yaml's
maskingThreads; each mask depends on its value alone, so the count changes no
result. availableCores() reads a container's CPU quota, which Python's
os.cpu_count() doesn't. key, fpe and the fake* strategies also remember
masks across chunks. The extension allocates through mimalloc: the system
allocators serialise masking's many small allocations across threads.
The rule
Python is the reference. This crate exists to be faster, not to be different. Where the two disagree, Python is right.
That is not a style preference. Bauta's masks are deterministic and keyed, so a difference between the two implementations would not surface as a wrong answer — it would surface as a changed key, months later, as joins between an old copy and a new one quietly stopping matching. The key fingerprint would not change, because the key did not.
So:
- Every covered strategy is checked against
vectors/reference.json, over a corpus chosen for boundaries rather than volume: the lengths where a Feistel half stops fitting a machine word, domains of exactly 2**128, the maximum identifier length, single-character alphabets, mixed-case hex, and every refusal with its exact message. - Anything whose behaviour depends on Python's own Unicode rules is not
reimplemented. Non-ASCII text,
str.isspace()when an address is stripped, digits normalised across scripts — those values are handed back, and Python masks them. - FF1 is checked against NIST SP 800-38G's sample vectors, and the keyed hash against RFC 4231.
What it covers
key, fpe, hash, email, digits, and the fake* strategies, which
pick from the lists Python passes in when a masker is built -- so the lists
are defined once, in Python, and the vectors record them. Everything else
stays in Python: redact needs lookbehind that Rust's regex engine doesn't
offer, shuffle, dateShift, number, keep, null and constant are
already cheap, and custom strategies are Python by definition.
Release files for bauta-rs 0.1.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| bauta_rs-0.1.7.tar.gz | 33.3 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| bauta_rs-0.1.7-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| bauta_rs-0.1.7-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ ARM64 | Details |
| bauta_rs-0.1.7-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
| bauta_rs-0.1.7-cp310-abi3-macosx_10_12_x86_64.whl | CPython 3.10 | abi3 | macOS 10.12+ x86-64 | Details |
Total release size: 1.7 MB
Release files / bauta_rs-0.1.7.tar.gz
| Download URL | bauta_rs-0.1.7.tar.gz |
|---|---|
| Size | 33.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a82d9cbf380779ec0b69605482f5de6b498857ba35405cad892c75dd646b85f6
|
|
BLAKE2b-256 checksum How to use checksums |
bb34bdd3774551c1fdb1c88b57209101205a718a4cc6721f47f037e6f410dabe
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency logRelease files / bauta_rs-0.1.7-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | bauta_rs-0.1.7-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 432.4 kB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
6253f99c7dfa17043478d5498f97ee68afc51089ff53d66732c2010773778b81
|
|
BLAKE2b-256 checksum How to use checksums |
c799499c580b2140ca96bc128b5ef9b040ba20269cd8cf3a219b34af71b6a273
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency logRelease files / bauta_rs-0.1.7-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | bauta_rs-0.1.7-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 424.0 kB |
| Tags | CPython 3.10 Linux glibc 2.17+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
656aa8ff002b1f136c2910123e07354c399f5c325e26e0939adee4f36a826f62
|
|
BLAKE2b-256 checksum How to use checksums |
4a7ae03c934b8c87f8181543c53105a3902a03621e03e6b6c2471928c93406e4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency logRelease files / bauta_rs-0.1.7-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | bauta_rs-0.1.7-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 369.1 kB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
807a63bde9d018b5109f399af8a7f2bab6efe73d3f2797987384456eddb6f7b8
|
|
BLAKE2b-256 checksum How to use checksums |
51e44bb123aba5a9b3725e789bc98b1082e963ff39479b5bea74c78b710975b7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency logRelease files / bauta_rs-0.1.7-cp310-abi3-macosx_10_12_x86_64.whl
| Download URL | bauta_rs-0.1.7-cp310-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 397.2 kB |
| Tags | CPython 3.10 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
cf6fba40ad58dfc98641478a94767feb4b2c466f003e6cf335e5ba8404c3bac8
|
|
BLAKE2b-256 checksum How to use checksums |
f9deef4f5488c8ba9b37f941c5c58479bac540328f3ac8f41c63c87df4d0ae41
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency log