A practical incremental and one-pass, pure API to the SHA-1 hash algorithm (including HMAC support) with performance close to the fastest implementations available in other languages.

The implementation is made in C with a haskell FFI wrapper that hides the C implementation.

NOTE: This package has been forked off cryptohash-0.11.7 because the cryptohash package has been deprecated and so this package continues to satisfy the need for a lightweight package providing the SHA1 hash algorithm without any dependencies on packages other than base and bytestring.

Consequently, this package can be used as a drop-in replacement for cryptohash's Crypto.Hash.SHA1 module, though with a clearly smaller footprint.


  • Add Eq instance for Ctx

  • add start and startlazy producing Ctx

  • Remove ineffective RULES

  • Declare Crypto.Hash.MD5 module -XTrustworthy

  • Convert to CApiFFI

  • Added ...AndLength variants of hashing functions:

    • finalizeAndLength
    • hashlazyAndLength
    • hmaclazyAndLength
  • Minor optimizations in hmac and hash

  • Use __builtin_bswap{32,64} only with GCC >= 4.3

  • new hmac and hmaclazy functions providing HMAC-SHA1 computation conforming to RFC2104 and RFC2202

  • switch to ‘safe’ FFI for calls where overhead becomes negligible
  • removed inline assembly in favour of portable C constructs
  • fix 32bit length overflow bug in hash function
  • fix inaccurate context-size
  • add context-size verification to incremental API operations
  • fix unaligned memory-accesses

  • first version forked off cryptohash-0.11.7 release