Skip to main content

bauta-rs

The optional native masker for Bauta.

Bauta masks data on its way from production to a copy. Masking key and fpe columns costs tens of microseconds a value in Python, most of it spent in the interpreter rather than in cryptography. This computes the same masks in Rust, about ten times faster on a whole job on one core, and can use several.

It is optional. Bauta works without it, and produces identical output either way.

Installing

pip install "bauta[native]"

The extra installs the bauta-rs released with your version of bauta, which is the only one Bauta uses; any other is ignored with a warning. Wheels cover Linux (x86-64 and ARM) and macOS (Apple silicon and Intel) on every supported Python. Elsewhere pip compiles it, which needs Rust 1.83 or newer.

Layout

Path What it is
core/ The constructions. No Python dependency, so they are testable without an interpreter.
py/ The PyO3 layer: conversions in, results out, and every unsafe boundary.
vectors/reference.json What the Python implementation produces, recorded. The contract between the two. Its pythonOnly section records the strategies with no port, so Python can't change those masks unnoticed either; nothing here reads it.
generate_vectors.py Regenerates that file from the Python implementation.

Building

From a clone, with Rust 1.83 or newer.

cargo test --release
cd py && maturin build --release
pip install ../target/wheels/bauta_rs-*.whl

--release matters for the tests: two of them measure SHA-256 and AES throughput to catch a backend that has silently fallen back to software, and a debug build is indistinguishable from one. cargo test covers core/; py/ needs a Python interpreter to link, so it is tested from Python, by tests/masking/test_nativeMasking.py.

Threads, and remembering masks

A chunk's distinct values are masked across a thread pool, whose size the Python layer sets per process (setThreads) from jobs.yaml's maskingThreads; each mask depends on its value alone, so the count changes no result. availableCores() reads a container's CPU quota, which Python's os.cpu_count() doesn't. key, fpe and the fake* strategies also remember masks across chunks. The extension allocates through mimalloc: the system allocators serialise masking's many small allocations across threads.

Machine integers where they fit

key's Feistel network and fpe's FF1 rounds each have two paths: one in u64 halves, taken wherever the values fit -- any key domain up to 2**128, and FF1 halves of up to 19 decimal digits, which is every identifier in practice -- and the original in BigUint for anything wider. Both hash and encrypt exactly the same bytes; the first only skips allocating a big integer every round, which was 40% of a key mask and three quarters of an fpe one. Unit tests run both paths over every width the fast one takes and require the same result, and the vectors cover each side of both boundaries.

Integers cross the Python boundary the same way: as an i64 through the C API where they fit, and as a BigInt otherwise. The extension is built against the stable ABI (abi3), where PyO3 converts a BigInt by calling int.to_bytes and int.from_bytes -- a Python call per value, made while every masking thread waits for the results.

The rule

Python is the reference. This crate exists to be faster, not to be different. Where the two disagree, Python is right.

That is not a style preference. Bauta's masks are deterministic and keyed, so a difference between the two implementations would not surface as a wrong answer — it would surface as a changed key, months later, as joins between an old copy and a new one quietly stopping matching. The key fingerprint would not change, because the key did not.

So:

  • Every covered strategy is checked against vectors/reference.json, over a corpus chosen for boundaries rather than volume: the lengths where a Feistel half stops fitting a machine word, domains of exactly 2**128, the maximum identifier length, single-character alphabets, mixed-case hex, and every refusal with its exact message.
  • Anything whose behaviour depends on Python's own Unicode rules is not reimplemented. Non-ASCII text, str.isspace() when an address is stripped, digits normalised across scripts — those values are handed back, and Python masks them.
  • FF1 is checked against NIST SP 800-38G's sample vectors, and the keyed hash against RFC 4231.

What it covers

key, fpe, hash, email, digits, number, and the fake* strategies, which pick from the lists Python passes in when a masker is built -- so the lists are defined once, in Python, and the vectors record them. number (core/src/number.rs) reproduces Python's decimal arithmetic at 60 digits for the operations it uses, and hands back zeros, non-finite values and anything that would take Python's rounding past what it reproduces. Everything else stays in Python: redact needs lookbehind that Rust's regex engine doesn't offer, shuffle, dateShift, keep, null and constant are already cheap, and custom strategies are Python by definition.

Release files for bauta-rs 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for bauta-rs 0.2.1
File Size Uploaded
bauta_rs-0.2.1.tar.gz 43.9 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for bauta-rs 0.2.1
File
bauta_rs-0.2.1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 abi3 Linux glibc 2.17+ x86-64 Details
bauta_rs-0.2.1-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl CPython 3.10 abi3 Linux glibc 2.17+ ARM64 Details
bauta_rs-0.2.1-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details
bauta_rs-0.2.1-cp310-abi3-macosx_10_12_x86_64.whl CPython 3.10 abi3 macOS 10.12+ x86-64 Details

Total release size: 1.8 MB

Release files / bauta_rs-0.2.1.tar.gz

Download URL bauta_rs-0.2.1.tar.gz
Size 43.9 kB
Tags Source
SHA-256 checksum
How to use checksums
f6f9cfac41f44fab7f2478283694761aa8332a76daf7ee652b0ccc23bae52015
BLAKE2b-256 checksum
How to use checksums
2eba4a4c93f94a8adbdf566be7a3f4217bd0f28c6efe4fb406564bb2e0a38b30
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / bauta_rs-0.2.1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL bauta_rs-0.2.1-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 471.2 kB
Tags CPython 3.10 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
2ec6c81e0f73020a4581638b916fa7a2844fc197e25a35eb23d995899e42443d
BLAKE2b-256 checksum
How to use checksums
49d6801b9632f131325d80554cf606531008ba7c53c7c7aa9d2db66f7db79b43
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / bauta_rs-0.2.1-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL bauta_rs-0.2.1-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 459.2 kB
Tags CPython 3.10 Linux glibc 2.17+ ARM64 abi3
SHA-256 checksum
How to use checksums
865217b0ba2062458a8424600e7cf2a882ae78c0fafba639723266dad0b4f9c0
BLAKE2b-256 checksum
How to use checksums
5d3ae8a9de2e222886ef5333dc7a6154355557b6a97874f9e6eae356437a0dea
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / bauta_rs-0.2.1-cp310-abi3-macosx_11_0_arm64.whl

Download URL bauta_rs-0.2.1-cp310-abi3-macosx_11_0_arm64.whl
Size 403.4 kB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
1d1faf74103aea89cd92eeb8eec9a4cfa2522cc14eeb665ec1fd01e04c9b5af8
BLAKE2b-256 checksum
How to use checksums
825c8bf9ba757ad8db35b19229998af3b23ee7ce03f3df55dbd53643f3a37d71
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / bauta_rs-0.2.1-cp310-abi3-macosx_10_12_x86_64.whl

Download URL bauta_rs-0.2.1-cp310-abi3-macosx_10_12_x86_64.whl
Size 434.0 kB
Tags CPython 3.10 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
78cee0ca964d71e7f10351748d3bb531ec7c812e7a71133ea620a32488acb3ef
BLAKE2b-256 checksum
How to use checksums
542a55eec48eadb6688eb1e3d4377c2e8b3680e4f413995222612ab4c48cc508
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.2

5 release files

This release

0.2.1 This release

5 release files

0.2.0

5 release files

0.1.9

5 release files

0.1.8

5 release files

0.1.7

5 release files

0.1.6

5 release files

0.1.5

5 release files

0.1.4

5 release files

0.1.3

5 release files

0.1.2

5 release files

0.1.1

5 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page