Skip to main content

blake3_compress_2x_seq

Function blake3_compress_2x_seq 

Source
pub fn blake3_compress_2x_seq(
    builder: &CircuitBuilder,
    cv: [Wire; 8],
    blocks: [[Wire; 16]; 2],
    counter: Wire,
    block_lens: [Wire; 2],
    flags: [Wire; 2],
) -> [Wire; 8]
Expand description

Two sequential BLAKE3 compressions evaluated as the two lanes of blake3_compress_2x.

Computes C2 = compress(C1, block2, …) where C1 = compress(cv, block1, …) — the output chaining value of the first compression is the input chaining value of the second. Both compressions share the single 7-round core of blake3_compress_2x: the first runs in the high lane (bits [32:64]), the second in the low lane (bits [0:32]).

The data dependency — the second compression needs the first’s output as its input — is resolved with a Blake3CompressHint that precomputes C1’s output chaining value. That value is fed into the low lane of the merged input chaining value (the second compression’s input) and constrained word-for-word against the first compression’s in-circuit output (the high lane of the result), so the hint cannot lie.

§Arguments

All wires carry 32-bit values in their low 32 bits, matching blake3_compress.

  • A wire feeding a lane’s low half is masked here, not assumed clean.

  • So a caller leaving the high 32 bits dirty cannot steer either compression.

  • cv: input chaining value for the first compression (8 words).

  • blocks: the two message blocks (blocks[0] for C1, blocks[1] for C2), 16 words each.

  • counter: the 64-bit block counter, shared by both compressions. Sequential chaining only happens within a single BLAKE3 chunk, where every block carries the chunk counter unchanged.

  • block_lens: per-compression block lengths.

  • flags: per-compression flags.

§Returns

The two output chaining values packed into 8 wires: the second compression’s output in the low 32 bits of each wire, the first compression’s output in the high 32 bits.