pub fn sha256_compress_2x(
builder: &CircuitBuilder,
state_in: State,
m: [Wire; 16],
) -> StateExpand description
SHA-256 compression function running two independent compressions in parallel.
Each 64-bit input wire packs two 32-bit lanes: bits [0:32] hold the lane-0 word, bits
[32:64] hold the lane-1 word. SHA-256’s mixing is built entirely from the parallel-halves
gates (iadd_32, rotr32,
srl32) plus lane-agnostic bxor/band, so the schedule and all 64
rounds run both compressions at the gate cost of a single one. The only lane-specific detail is
the round constants, which are replicated into both halves here.
§Arguments
state_in: the 8-word input state, each wire packing both lanes’ words.m: 16 message words for this block, each wire packing both lanes’ words.
It is a PRECONDITION that each 32-bit lane be a valid 32-bit value (no spillover across the lane boundary), i.e. the input words fit in their respective halves. It is the caller’s responsibility to ensure this; otherwise the gadget’s behavior is undefined / insecure.
§Returns
The updated 8-word state, with each wire packing both lanes’ results.
§Chips
This is a ChipGadget. A circuit that calls
register_chip with Sha256Compress2x before building
turns every paired compression under it into a chip call, including the ones
sha256_compress_2x_seq and the fixed and variable length hashers reach.