pub fn blake3_compress_2x(
builder: &CircuitBuilder,
cv: [Wire; 8],
block: [Wire; 16],
counter_lo: Wire,
counter_hi: Wire,
block_len: Wire,
flags: Wire,
) -> [Wire; 8]Expand description
BLAKE3 compression function running two independent compressions in parallel.
Each 64-bit input wire packs two 32-bit lanes: bits [0:32] hold the lane-0 word,
bits [32:64] hold the lane-1 word. This matches the lane layout expected by the
parallel-halves iadd_32 and
rotr32 gates, so the 7-round core runs both
compressions at the gate cost of a single one.
The 64-bit block counter is split by the caller into low and high 32-bit halves:
counter_lo packs each lane’s t_low, counter_hi packs each lane’s t_high.
§Arguments
All wires follow the packing convention above.
cv: 8 chaining-value words (per lane).block: 16 message words (per lane).counter_lo: low 32 bits of each lane’s block counter.counter_hi: high 32 bits of each lane’s block counter.block_len: byte count (0..=64) per lane.flags: domain-separation flags per lane.
§Returns
The updated 8-word chaining value, with each word packing both lanes.
§Chips
This is a ChipGadget. A circuit that calls
register_chip with Blake3Compress2x before building
turns every compression under it into a chip call, including the ones
blake3_compress_2x_seq and the chunk and tree gadgets reach.