Skip to main content

circuit_tweak_hash_2x

Function circuit_tweak_hash_2x 

Source
pub fn circuit_tweak_hash_2x(
    builder: &CircuitBuilder,
    public_param: &[Wire; 2],
    tweak_type: u8,
    sub_positions: [Wire; 2],
    index: Wire,
    payloads: [&[Wire]; 2],
) -> [[Wire; 2]; 2]
Expand description

Two independent tweak hashes evaluated as the two lanes of one core.

Two hashes of equal length run in lockstep — same block count, same block lengths, same flags, same tree shape — so every compression of one has a partner in the other and the two share a paired core. Here the lanes differ only in their key’s sub-position and in their payload, which is exactly how two chains at one step differ.

This is cheaper than two lone hashes, though not for the reason the lane count suggests. A lone compression already uses both lanes, splitting its own seven rounds across them, so on rounds alone the pair only trades eight for seven. The rest of the saving is the split itself: a lone compression hints its mid-round state and then constrains that hint word for word, and a pair has no split to pin.

§Panics

  • If the two payloads differ in length.