pub fn keccak256_varlen(
builder: &CircuitBuilder,
message: &ByteVec,
) -> [Wire; 4]Expand description
Computes the Keccak-256 hash of a variable-length message.
This gadget consumes a ByteVec whose actual length is runtime-determined and returns the
256-bit digest as 4 wires (little-endian 64-bit words), matching
fixed_length::keccak256’s output layout.
Keccak is a sponge: the message is pad10*1-padded (the 0x01 domain byte immediately after
the message, then zeros, with 0x80 set in the final byte of the last rate block), split into
136-byte (17-word) blocks that are XORed into the 1600-bit state and permuted by
keccak_f1600. Each padded word is computed as a derived wire, classified by
its position relative to the runtime boundary word w_bd = len_bytes >> 3:
word_index < w_bd- pure message word,word_index == w_bd- boundary word (trailing message bytes mixed with the0x01delimiter, plus0x80when it is also the last word of the final block),word_index > w_bd- padding (zero, except the final block’s last word, which carries the0x80delimiter).
The digest is the first four state words after the block that contains the padding, selected via a multiplexer indexed by the runtime length. Because the padded words are derived (not witnessed), no padding-correctness constraints are needed.
Both ByteVec and Keccak pack bytes little-endian, so — unlike
crate::sha512::sha512_varlen — no byte swap is needed.
§Arguments
builder- Circuit buildermessage- Input message as aByteVec; itslen_byteswire holds the actual length.
§Returns
[Wire; 4]- The Keccak-256 digest as 4 little-endian 64-bit words.