module

Pyrite::Integrity

Module responsible for real-time cryptographic calculation and streaming self-integrity verification of executable binaries.

Memory Efficiency

All file hashing is performed in fixed 16KB streaming buffers (Bytes.new(16384)), guaranteeing $O(1)$ memory consumption even when hashing large binaries (100MB+).

Class methods

current_binary_sha256

Computes the hexadecimal SHA-256 digest of the running binary at /proc/self/exe.

Example

live_hash = Pyrite::Integrity.current_binary_sha256
puts "Live binary SHA-256: #{live_hash}"
Source
executable_path

Resolves the absolute filesystem path to the currently executing binary.

On Linux systems, /proc/self/exe is prioritized as the kernel VFS file descriptor to the running image, preventing TOCTOU file replacement attacks. Falls back to Process.executable_path for portable non-Linux systems.

Raises Pyrite::SecurityError if the running binary cannot be resolved.

Source
file_sha256(path : String) : String

Computes the hexadecimal SHA-256 digest of any file on disk using memory-efficient 16KB chunk streaming.

Parameters

  • path (String): Absolute or relative filesystem path to hash.

Errors

  • Pyrite::MissingEnvelopeError: Raised if path does not exist.

Example

binary_digest = Pyrite::Integrity.file_sha256("bin/app")
puts "Calculated digest: #{binary_digest}"
Source