Skip to main content

keccak256_varlen

Function keccak256_varlen 

Source
pub fn keccak256_varlen(
    builder: &CircuitBuilder,
    message: &ByteVec,
) -> [Wire; 4]
Expand description

Computes the Keccak-256 hash of a variable-length message.

This gadget consumes a ByteVec whose actual length is runtime-determined and returns the 256-bit digest as 4 wires (little-endian 64-bit words), matching fixed_length::keccak256’s output layout.

Keccak is a sponge: the message is pad10*1-padded (the 0x01 domain byte immediately after the message, then zeros, with 0x80 set in the final byte of the last rate block), split into 136-byte (17-word) blocks that are XORed into the 1600-bit state and permuted by keccak_f1600. Each padded word is computed as a derived wire, classified by its position relative to the runtime boundary word w_bd = len_bytes >> 3:

  1. word_index < w_bd - pure message word,
  2. word_index == w_bd - boundary word (trailing message bytes mixed with the 0x01 delimiter, plus 0x80 when it is also the last word of the final block),
  3. word_index > w_bd - padding (zero, except the final block’s last word, which carries the 0x80 delimiter).

The digest is the first four state words after the block that contains the padding, selected via a multiplexer indexed by the runtime length. Because the padded words are derived (not witnessed), no padding-correctness constraints are needed.

Both ByteVec and Keccak pack bytes little-endian, so — unlike crate::sha512::sha512_varlen — no byte swap is needed.

§Arguments

  • builder - Circuit builder
  • message - Input message as a ByteVec; its len_bytes wire holds the actual length.

§Returns

  • [Wire; 4] - The Keccak-256 digest as 4 little-endian 64-bit words.