Bug#865374: libdigest-sha3-perl: sha3sum perl v5.24.1 and v5.20.0 create a different checksum for the same input

Niko Tyni ntyni at debian.org
Tue Jun 20 20:10:10 UTC 2017


Control: forwarded -1 https://rt.cpan.org/Public/Bug/Display.html?id=110364

On Tue, Jun 20, 2017 at 09:50:20PM +0200, Honovere wrote:
> Package: libdigest-sha3-perl
> Version: 0.25-1+b1
> Severity: important
> 
> Dear Maintainer,
> 
> checksums created with sha3sum for the exact same input with Debian 8 and 9 are different. They should be identical.

Hi, this seems to expected behaviour. Quoting the upstream author in

 https://rt.cpan.org/Public/Bug/Display.html?id=110364

  Yes, the outputs are different. As of version 0.23 the Digest::SHA3
  module reflects the then-recent updates made to FIPS 202 which called
  for the use of domain separation bits (ref. the Changes file). These
  updates caused changes to all digest outputs, as expected.

  To my knowledge the current Digest::SHA3 module passes all official,
  published test vectors, including those with partial-byte inputs. If
  you know of any exceptions, let me know

So it looks like the standard is/was still evolving.
-- 
Niko Tyni   ntyni at debian.org



More information about the pkg-perl-maintainers mailing list