pub fn blake3_compress_2x_seq(
builder: &CircuitBuilder,
cv: [Wire; 8],
blocks: [[Wire; 16]; 2],
counter: Wire,
block_lens: [Wire; 2],
flags: [Wire; 2],
) -> [Wire; 8]Expand description
Two sequential BLAKE3 compressions evaluated as the two lanes of blake3_compress_2x.
Computes C2 = compress(C1, block2, …) where C1 = compress(cv, block1, …) — the output
chaining value of the first compression is the input chaining value of the second. Both
compressions share the single 7-round core of blake3_compress_2x: the first runs in the
high lane (bits [32:64]), the second in the low lane (bits [0:32]).
The data dependency — the second compression needs the first’s output as its input — is
resolved with a Blake3CompressHint that precomputes C1’s output chaining value. That
value is fed into the low lane of the merged input chaining value (the second compression’s
input) and constrained word-for-word against the first compression’s in-circuit output (the
high lane of the result), so the hint cannot lie.
§Arguments
All wires carry 32-bit values in their low 32 bits, matching blake3_compress.
-
A wire feeding a lane’s low half is masked here, not assumed clean.
-
So a caller leaving the high 32 bits dirty cannot steer either compression.
-
cv: input chaining value for the first compression (8 words). -
blocks: the two message blocks (blocks[0]for C1,blocks[1]for C2), 16 words each. -
counter: the 64-bit block counter, shared by both compressions. Sequential chaining only happens within a single BLAKE3 chunk, where every block carries the chunk counter unchanged. -
block_lens: per-compression block lengths. -
flags: per-compression flags.
§Returns
The two output chaining values packed into 8 wires: the second compression’s output in the low 32 bits of each wire, the first compression’s output in the high 32 bits.