Whirlpool哈希函数返回结果不符预期,求排查建议
Hey there, let's walk through the most common culprits that could be causing your Whirlpool hash mismatch with the online tool, especially since the empty string case works fine:
Character Encoding Discrepancy
This is the #1 reason for hash mismatches with string inputs. The online tool almost certainly uses UTF-8 encoding for converting "test" to bytes, but your Java code might be using the default platform encoding (like Windows-1252 on some systems) if you're callinggetBytes()without specifying a charset. Empty strings will always convert to an empty byte array regardless of encoding, which is why that case works. Fix this by explicitly using UTF-8:byte[] inputBytes = "test".getBytes(StandardCharsets.UTF_8);Output Format Differences
Double-check the case and formatting of your hash output. The online tool might return uppercase hex characters, while your code outputs lowercase (or vice versa). Some tools also add a0xprefix, which your implementation might omit. Make sure you're comparing apples to apples—try normalizing both outputs to the same case and stripping any extra characters before comparing.Outdated GNU Crypto Implementation
GNU Crypto 2.0.1 is a very old release (dating back to 2006). It's possible this version has a subtle deviation from the official Whirlpool specification, or might implement a deprecated variant of the algorithm. Try testing with a modern, well-maintained library like BouncyCastle to see if you get the matching hash. Here's a quick example using BouncyCastle's Whirlpool implementation:import org.bouncycastle.crypto.digests.WhirlpoolDigest; import org.bouncycastle.util.encoders.Hex; import java.nio.charset.StandardCharsets; public class WhirlpoolCheck { public static void main(String[] args) { String input = "test"; WhirlpoolDigest digest = new WhirlpoolDigest(); byte[] inputBytes = input.getBytes(StandardCharsets.UTF_8); digest.update(inputBytes, 0, inputBytes.length); byte[] hashBytes = new byte[digest.getDigestSize()]; digest.doFinal(hashBytes, 0); System.out.println(Hex.toHexString(hashBytes).toUpperCase()); } }Hidden Input Characters
It's easy to accidentally include invisible characters (like trailing newlines or spaces) in your input string that you don't notice. Empty strings don't have this issue, but "test" might have extra bytes you aren't accounting for. Print out the length of your input byte array and each byte's value to confirm it matches exactly what you're entering into the online tool.
Start with checking the encoding first—it's the most likely fix. If that doesn't work, testing with BouncyCastle will help you rule out a problem with the GNU Crypto library itself.
内容的提问来源于stack exchange,提问作者Mirco Widmer

