Skip to main content

sha256_compress_2x

Function sha256_compress_2x 

Source
pub fn sha256_compress_2x(
    builder: &CircuitBuilder,
    state_in: State,
    m: [Wire; 16],
) -> State
Expand description

SHA-256 compression function running two independent compressions in parallel.

Each 64-bit input wire packs two 32-bit lanes: bits [0:32] hold the lane-0 word, bits [32:64] hold the lane-1 word. SHA-256’s mixing is built entirely from the parallel-halves gates (iadd_32, rotr32, srl32) plus lane-agnostic bxor/band, so the schedule and all 64 rounds run both compressions at the gate cost of a single one. The only lane-specific detail is the round constants, which are replicated into both halves here.

§Arguments

  • state_in: the 8-word input state, each wire packing both lanes’ words.
  • m: 16 message words for this block, each wire packing both lanes’ words.

It is a PRECONDITION that each 32-bit lane be a valid 32-bit value (no spillover across the lane boundary), i.e. the input words fit in their respective halves. It is the caller’s responsibility to ensure this; otherwise the gadget’s behavior is undefined / insecure.

§Returns

The updated 8-word state, with each wire packing both lanes’ results.

§Chips

This is a ChipGadget. A circuit that calls register_chip with Sha256Compress2x before building turns every paired compression under it into a chip call, including the ones sha256_compress_2x_seq and the fixed and variable length hashers reach.