pub fn blake3_compress(
builder: &CircuitBuilder,
cv: [Wire; 8],
block: [Wire; 16],
counter: Wire,
block_len: Wire,
flags: Wire,
) -> [Wire; 8]Expand description
BLAKE3 compression function.
A single compression, evaluated as two lanes of one packed core: the round sequence is cut in two and the halves run side by side rather than one after the other.
high lane (bits [32:64]): round 0 -> round 1 -> round 2 -> (idle)
low lane (bits [0:32]): round 3 -> round 4 -> round 5 -> round 6Both halves of the split want the same thing: the state after round 2, which is the low lane’s
input and the high lane’s output. That circular dependency is broken with a
Blake3RoundSplitHint that computes the state off-circuit and feeds it in, then constrains it
word-for-word against what the high lane really computed, so the hint cannot lie.
Four packed rounds replace seven single-lane ones. The high lane sits idle through the last of them — 7 rounds do not divide evenly in two — and its result is discarded.
§Arguments
cv: 8 chaining-value words (32-bit each, stored in the low 32 bits of each wire).block: 16 message words (32-bit each, low 32 bits of each wire, little-endian).counter: the 64-bit block counter. Low 32 bits aret_low, high 32 aret_high. The wire may carry either a genuinely-64-bit counter (multi-chunk) or a 32-bit value with zero high half (single-chunk).block_len: byte count for this block, 0..=64. 32-bit value in low 32 bits.flags: domain-separation flags. 32-bit value in low 32 bits.
§Preconditions
- Every 32-bit input holds its value in the low 32 bits;
counteris a full 64-bit value. - High halves need not be empty.
- A message word’s high half is masked off.
- Every other input’s is discarded by the shift that lifts it into the high lane.
§Returns
The updated 8-word chaining value in the low 32 bits of each word. The high 32 bits carry the
high lane’s discarded round and are not cleared, so a caller that reads them must mask them off
— the same treatment a pair’s first compression gets from blake3_compress_2x_seq.