pub fn blake3_keyed_fixed_2x(
builder: &CircuitBuilder,
messages: [&[Wire]; 2],
len_bytes: usize,
keys: [&ByteVec; 2],
) -> [[Wire; 8]; 2]Expand description
Computes two keyed BLAKE3 hashes of equal-length messages side by side.
Each digest matches blake3_keyed_fixed on its own message and key.
bits [0:32] = lane 0: keys[0], messages[0] --\
>-- one paired core per block
bits [32:64] = lane 1: keys[1], messages[1] --/Equal lengths are what put the two hashes in lockstep.
- The block count, the block lengths, the flags and the tree shape all agree.
- So every compression of one hash has exactly one partner in the other.
The saving lands where a single hash has an odd block with no partner to pair with.
- That block goes through
blake3_compress, which fills the lanes by splitting its own rounds across them and so evaluates 3 of its 7 rounds twice. - Pairing two hashes puts a real second hash in that lane instead, and the duplicated rounds are what it recovers: 336 AND constraints against 384, for a one-block message.
§Arguments
builder: Circuit builder.messages: the two messages, each as inblake3_fixed, their high halves masked here so one cannot spill into the other lane.len_bytes: the compile-time-known length both messages share.keys: the two keys, each as inblake3_keyed_fixed, and free to differ in length.
§Returns
The two digests, each as in blake3_fixed.
§Panics
- If either message is not
len_bytes.div_ceil(4)wires long. - If either key’s length is not fixed at circuit construction time.
- If either key is longer than
KEY_BYTES.