Skip to main content

blake3_compress

Function blake3_compress 

Source
pub fn blake3_compress(
    builder: &CircuitBuilder,
    cv: [Wire; 8],
    block: [Wire; 16],
    counter: Wire,
    block_len: Wire,
    flags: Wire,
) -> [Wire; 8]
Expand description

BLAKE3 compression function.

A single compression, evaluated as two lanes of one packed core: the round sequence is cut in two and the halves run side by side rather than one after the other.

    high lane (bits [32:64]):  round 0 -> round 1 -> round 2 -> (idle)
    low  lane (bits  [0:32]):  round 3 -> round 4 -> round 5 -> round 6

Both halves of the split want the same thing: the state after round 2, which is the low lane’s input and the high lane’s output. That circular dependency is broken with a Blake3RoundSplitHint that computes the state off-circuit and feeds it in, then constrains it word-for-word against what the high lane really computed, so the hint cannot lie.

Four packed rounds replace seven single-lane ones. The high lane sits idle through the last of them — 7 rounds do not divide evenly in two — and its result is discarded.

§Arguments

  • cv: 8 chaining-value words (32-bit each, stored in the low 32 bits of each wire).
  • block: 16 message words (32-bit each, low 32 bits of each wire, little-endian).
  • counter: the 64-bit block counter. Low 32 bits are t_low, high 32 are t_high. The wire may carry either a genuinely-64-bit counter (multi-chunk) or a 32-bit value with zero high half (single-chunk).
  • block_len: byte count for this block, 0..=64. 32-bit value in low 32 bits.
  • flags: domain-separation flags. 32-bit value in low 32 bits.

§Preconditions

  • Every 32-bit input holds its value in the low 32 bits; counter is a full 64-bit value.
  • High halves need not be empty.
    • A message word’s high half is masked off.
    • Every other input’s is discarded by the shift that lifts it into the high lane.

§Returns

The updated 8-word chaining value in the low 32 bits of each word. The high 32 bits carry the high lane’s discarded round and are not cleared, so a caller that reads them must mask them off — the same treatment a pair’s first compression gets from blake3_compress_2x_seq.