Skip to content

PBS-49 feature: move SHA-256 digest into opensslpp::digest_context - #192

Merged
kamil-holubicki merged 1 commit into
Percona-Lab:mainfrom
kamil-holubicki:PBS-49
Sep 24, 2026
Merged

kamil-holubicki merged 1 commit into
Percona-Lab:mainfrom
kamil-holubicki:PBS-49

Conversation

@kamil-holubicki

Copy link
Copy Markdown
Contributor

https://perconadev.atlassian.net/browse/PBS-49

Problem:
The caching_sha2_password authenticator was the only translation unit in the PBS tree that still included OpenSSL headers directly and drove EVP_MD_CTX by hand. Every other cryptographic primitive already lives in the shared opensslpp module (cipher_context, crypto_rng, core_error). PBS-49 tracks pulling the remaining raw calls behind that same wrapper.

Solution:
Introduce opensslpp::digest_context, a minimal RAII wrapper around EVP_MD_CTX that exposes exactly the operations the plugin needs: select a digest by digest_code_type (only sha256 today), update() with a std::string_view of input, and finalize() to a std::string of raw digest bytes. A static one-shot calculate() mirrors PS opensslpp's free-standing calculate_digest.

Comment thread src/opensslpp/digest_context.hpp Outdated
class digest_context {
public:
digest_context() noexcept = default;
explicit digest_context(digest_code_type code);

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

May be similarly to cipher_context make the constructor accept
const std::string &digest_name and get rid of digest_code_type completely?

https://perconadev.atlassian.net/browse/PBS-49

Problem:
The caching_sha2_password authenticator was the only translation unit
in the PBS tree that still included OpenSSL headers directly and drove
EVP_MD_CTX by hand. Every other cryptographic primitive already lives
in the shared opensslpp module (cipher_context, crypto_rng,
core_error). PBS-49 tracks pulling the remaining raw calls behind that
same wrapper.

Solution:
Introduce opensslpp::digest_context, a minimal RAII wrapper around
EVP_MD_CTX that exposes exactly the operations the plugin needs:
select a digest by digest_code_type (only sha256 today), update() with
a std::string_view of input, and finalize() to a std::string of raw
digest bytes. A static one-shot calculate() mirrors PS opensslpp's
free-standing calculate_digest.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

@percona-ysorokin percona-ysorokin left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kamil-holubicki
kamil-holubicki merged commit 5b5f280 into Percona-Lab:main Sep 24, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants