dstu-core (Python bindings)
Not independently audited. See the root project's docs/SECURITY.md and docs/DECISIONS.md
for the full threat model and per-construction status. This binding wraps the full
dstu_core::crypto_* surface (docs/bindings-strategy.md T-49).
Installing
pip install dstu-core
python -c "import dstu_core; dstu_core.selftest()"
Building from source (contributors)
python -m venv .venv
source .venv/bin/activate # or .venv\Scripts\activate on Windows
pip install maturin
maturin develop --release
python -c "import dstu_core; dstu_core.selftest()"
pyo3 needs a real Python interpreter to link against at build time. Plain python/python3 may
not be enough to find one — on Windows in particular, those names can resolve to non-functional
Microsoft Store alias stubs instead of a real install. If cargo build/maturin develop fails to
find (or finds the wrong) Python, point it at one explicitly:
export PYO3_PYTHON=/path/to/a/real/python3 # POSIX
$env:PYO3_PYTHON = "C:\path\to\python.exe" # PowerShell
maturin develop builds the Rust extension and installs it into the active virtualenv as an
editable package. dstu_core.selftest() re-runs dstu_core::selftest::run() (docs/TASKS.md
T-161) against the exact compiled build and raises RuntimeError if anything official-vector-level
is wrong — the first thing to run after any build to confirm it actually works, not just compiled.
This crate is its own Cargo workspace, separate from the repo root (docs/DECISIONS.md D-119) —
build/test it from inside this directory, not from the repo root.
Usage
Every function/class below lives directly on the dstu_core module (no submodules). See
examples/ for complete, runnable scripts, and tests/ for the full correctness/rejection/misuse
suite each one is verified against (D-64/D-65).
import dstu_core as d
key = d.secretbox_keygen()
sealed = d.secretbox_seal(key, b"a message worth protecting")
assert d.secretbox_open(key, sealed) == b"a message worth protecting"
| Module | Functions/classes | Notes |
|---|---|---|
crypto_secretbox |
secretbox_keygen, secretbox_seal, secretbox_open |
Single-message authenticated encryption. examples/secretbox.py. |
crypto_box |
box_keygen, box_public_key, box_seal, box_open |
Public-key encryption (hybrid via KDF over hazmat::dstu9041, l(p)=256, D-169). box_seal/box_open are not memory-bounded — the whole message is held in memory. examples/box.py. |
crypto_box512 |
box512_keygen, box512_public_key, box512_seal, box512_open |
l(p)=512/E512/1 sibling of crypto_box (T-193/T-204). examples/box512.py. |
crypto_secretstream |
secretstream_keygen, SecretStreamPushState, SecretStreamPullState, SecretStreamEncryptor, SecretStreamDecryptor |
Chunked streaming AEAD. The file-like SecretStreamEncryptor/SecretStreamDecryptor wire format matches uacrypt encrypt/decrypt exactly (D-118). examples/secretstream_file.py. |
crypto_sign |
sign_keygen, sign_verifying_key, sign_message, sign_verify |
DSTU 4145 m=163 digital signatures, deterministic nonce (no RNG dependency). examples/sign.py. |
crypto_sign257 |
sign257_keygen, sign257_verifying_key, sign257_message, sign257_verify |
m=257 sibling of crypto_sign (T-199/T-204) — the curve real Diia-issued qualified signatures use. examples/sign257.py. |
crypto_pwhash |
pwhash_hash_password, pwhash_verify_password, PWHASH_INTERACTIVE/PWHASH_MODERATE/PWHASH_SENSITIVE |
Argon2id (the one deliberately non-DSTU component, D-49/D-50). examples/password_hashing.py. |
crypto_auth |
auth_keygen, auth, auth_verify |
Keyed message authentication (Kupyna-KMAC). examples/misc.py. |
crypto_kdf |
kdf_keygen, kdf_derive_subkey |
Deterministic subkey derivation. examples/misc.py. |
crypto_generichash |
kupyna256, kupyna512, Kupyna256Hasher, Kupyna512Hasher |
One-shot and streaming Kupyna hashing. examples/misc.py. |
crypto_stream |
stream_keygen, stream_encrypt, stream_decrypt |
Strumok-256 keystream — unauthenticated, stream_decrypt never fails on tampered input. examples/misc.py. |
randombytes |
randombytes_buf |
CSPRNG-backed random bytes. examples/misc.py. |
| — | selftest, DstuError |
Runtime KAT self-check (T-161); the one exception type every crypto-operation failure raises. |
Testing
pip install pytest ruff
pytest
ruff check .
ruff format --check .
cargo build -p uacrypt --release (from the repo root) first if you want
tests/test_secretstream.py's live uacrypt CLI interop test to actually run instead of skipping.
cargo xtask python (from the repo root) runs this whole sequence, including that build step, in
one command.
Metadata
Release files for dstu-core 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dstu_core-0.1.1-cp39-abi3-win_amd64.whl | CPython 3.9 | abi3 | Windows x86-64 | Details |
| dstu_core-0.1.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.9 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| dstu_core-0.1.1-cp39-abi3-macosx_11_0_arm64.whl | CPython 3.9 | abi3 | macOS 11.0+ ARM64 | Details |
Total release size: 1.3 MB
Release files / dstu_core-0.1.1-cp39-abi3-win_amd64.whl
| Download URL | dstu_core-0.1.1-cp39-abi3-win_amd64.whl |
|---|---|
| Size | 321.5 kB |
| Tags | CPython 3.9 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
f728d4df8cfa26d7aa866933c30b391f28b0aee93d1f4ee3e82dbd6f8a6dafc4
|
|
BLAKE2b-256 checksum How to use checksums |
c3ba5609479bd0b0e5a2548a8f1c4de8c6b4455f5dbc5a8e69c92b19a77ed9bd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 13, 2026.
Transparency logRelease files / dstu_core-0.1.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | dstu_core-0.1.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 484.8 kB |
| Tags | CPython 3.9 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
e579c5e6eae4c8ed9ee4dc78a1a9e9c73ab7f364d0202726b23481a9247cb841
|
|
BLAKE2b-256 checksum How to use checksums |
e0b99053e4818862acbadf3506d4eec41a79759a127189795e353e4e4c030743
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 13, 2026.
Transparency logRelease files / dstu_core-0.1.1-cp39-abi3-macosx_11_0_arm64.whl
| Download URL | dstu_core-0.1.1-cp39-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 457.6 kB |
| Tags | CPython 3.9 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
5cba6bfebf49bd40082d627c6e95042cf15e24623dc9c4b98e3a8d57f25207d4
|
|
BLAKE2b-256 checksum How to use checksums |
9ba994f2b69b0d5319d6152d5b0ef38e18563675c727b28aeac08c622fe7fe89
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 13, 2026.
Transparency log