Skip to main content

dstu-core (Python bindings)

Not independently audited. See the root project's docs/SECURITY.md and docs/DECISIONS.md for the full threat model and per-construction status. This binding wraps the full dstu_core::crypto_* surface (docs/bindings-strategy.md T-49).

Installing

pip install dstu-core
python -c "import dstu_core; dstu_core.selftest()"

Building from source (contributors)

python -m venv .venv
source .venv/bin/activate        # or .venv\Scripts\activate on Windows
pip install maturin
maturin develop --release
python -c "import dstu_core; dstu_core.selftest()"

pyo3 needs a real Python interpreter to link against at build time. Plain python/python3 may not be enough to find one — on Windows in particular, those names can resolve to non-functional Microsoft Store alias stubs instead of a real install. If cargo build/maturin develop fails to find (or finds the wrong) Python, point it at one explicitly:

export PYO3_PYTHON=/path/to/a/real/python3   # POSIX
$env:PYO3_PYTHON = "C:\path\to\python.exe"   # PowerShell

maturin develop builds the Rust extension and installs it into the active virtualenv as an editable package. dstu_core.selftest() re-runs dstu_core::selftest::run() (docs/TASKS.md T-161) against the exact compiled build and raises RuntimeError if anything official-vector-level is wrong — the first thing to run after any build to confirm it actually works, not just compiled.

This crate is its own Cargo workspace, separate from the repo root (docs/DECISIONS.md D-119) — build/test it from inside this directory, not from the repo root.

Usage

Every function/class below lives directly on the dstu_core module (no submodules). See examples/ for complete, runnable scripts, and tests/ for the full correctness/rejection/misuse suite each one is verified against (D-64/D-65).

import dstu_core as d

key = d.secretbox_keygen()
sealed = d.secretbox_seal(key, b"a message worth protecting")
assert d.secretbox_open(key, sealed) == b"a message worth protecting"
Module Functions/classes Notes
crypto_secretbox secretbox_keygen, secretbox_seal, secretbox_open Single-message authenticated encryption. examples/secretbox.py.
crypto_box box_keygen, box_public_key, box_seal, box_open Public-key encryption (hybrid via KDF over hazmat::dstu9041, l(p)=256, D-169). box_seal/box_open are not memory-bounded — the whole message is held in memory. examples/box.py.
crypto_box512 box512_keygen, box512_public_key, box512_seal, box512_open l(p)=512/E512/1 sibling of crypto_box (T-193/T-204). examples/box512.py.
crypto_secretstream secretstream_keygen, SecretStreamPushState, SecretStreamPullState, SecretStreamEncryptor, SecretStreamDecryptor Chunked streaming AEAD. The file-like SecretStreamEncryptor/SecretStreamDecryptor wire format matches uacrypt encrypt/decrypt exactly (D-118). examples/secretstream_file.py.
crypto_sign sign_keygen, sign_verifying_key, sign_message, sign_verify DSTU 4145 m=163 digital signatures, deterministic nonce (no RNG dependency). examples/sign.py.
crypto_sign257 sign257_keygen, sign257_verifying_key, sign257_message, sign257_verify m=257 sibling of crypto_sign (T-199/T-204) — the curve real Diia-issued qualified signatures use. examples/sign257.py.
crypto_pwhash pwhash_hash_password, pwhash_verify_password, PWHASH_INTERACTIVE/PWHASH_MODERATE/PWHASH_SENSITIVE Argon2id (the one deliberately non-DSTU component, D-49/D-50). examples/password_hashing.py.
crypto_auth auth_keygen, auth, auth_verify Keyed message authentication (Kupyna-KMAC). examples/misc.py.
crypto_kdf kdf_keygen, kdf_derive_subkey Deterministic subkey derivation. examples/misc.py.
crypto_generichash kupyna256, kupyna512, Kupyna256Hasher, Kupyna512Hasher One-shot and streaming Kupyna hashing. examples/misc.py.
crypto_stream stream_keygen, stream_encrypt, stream_decrypt Strumok-256 keystream — unauthenticated, stream_decrypt never fails on tampered input. examples/misc.py.
randombytes randombytes_buf CSPRNG-backed random bytes. examples/misc.py.
— selftest, DstuError Runtime KAT self-check (T-161); the one exception type every crypto-operation failure raises.

Testing

pip install pytest ruff
pytest
ruff check .
ruff format --check .

cargo build -p uacrypt --release (from the repo root) first if you want tests/test_secretstream.py's live uacrypt CLI interop test to actually run instead of skipping. cargo xtask python (from the repo root) runs this whole sequence, including that build step, in one command.

Metadata

Release files for dstu-core 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for dstu-core 0.1.1
File Interpreter ABI Platform
dstu_core-0.1.1-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
dstu_core-0.1.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.9 abi3 Linux glibc 2.17+ x86-64 Details
dstu_core-0.1.1-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details

Total release size: 1.3 MB

Release files / dstu_core-0.1.1-cp39-abi3-win_amd64.whl

Download URL dstu_core-0.1.1-cp39-abi3-win_amd64.whl
Size 321.5 kB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
f728d4df8cfa26d7aa866933c30b391f28b0aee93d1f4ee3e82dbd6f8a6dafc4
BLAKE2b-256 checksum
How to use checksums
c3ba5609479bd0b0e5a2548a8f1c4de8c6b4455f5dbc5a8e69c92b19a77ed9bd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 13, 2026.

Transparency log

Release files / dstu_core-0.1.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL dstu_core-0.1.1-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 484.8 kB
Tags CPython 3.9 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
e579c5e6eae4c8ed9ee4dc78a1a9e9c73ab7f364d0202726b23481a9247cb841
BLAKE2b-256 checksum
How to use checksums
e0b99053e4818862acbadf3506d4eec41a79759a127189795e353e4e4c030743
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 13, 2026.

Transparency log

Release files / dstu_core-0.1.1-cp39-abi3-macosx_11_0_arm64.whl

Download URL dstu_core-0.1.1-cp39-abi3-macosx_11_0_arm64.whl
Size 457.6 kB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
5cba6bfebf49bd40082d627c6e95042cf15e24623dc9c4b98e3a8d57f25207d4
BLAKE2b-256 checksum
How to use checksums
9ba994f2b69b0d5319d6152d5b0ef38e18563675c727b28aeac08c622fe7fe89
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 13, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

3 release files

0.1.0

3 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page