pub fn sha256_compress_2x_seq(
builder: &CircuitBuilder,
state_in: State,
blocks: [[Wire; 16]; 2],
) -> StateExpand description
Two sequential SHA-256 block compressions evaluated in one parallel core.
The second block’s compression takes the first block’s output state as its input state. Both run as the two 32-bit lanes of a single parallel compression:
high lane [32:64]: S1 = compress(input state, first block)
low lane [0:32] : S2 = compress(S1, second block)So two chained blocks cost one compression instead of two.
The two lanes run concurrently, yet the low lane needs the high lane’s output as its input.
A hint breaks this dependency by precomputing S1 off-circuit.
The hinted S1 seeds the low lane’s input and is constrained two ways, so it cannot lie:
- its high half must equal the real input state (the first compression’s input).
- its low half must equal the first compression’s in-circuit output.
§Arguments
state_in: 8-word input state for the first compression, value in the low 32 bits of each.blocks: two 16-word message blocks;blocks[0]feeds the first,blocks[1]the second.
§Preconditions
- Every input wire holds a valid 32-bit value in its low 32 bits.
- High halves need not be empty.
- A block word’s high half is masked off.
- A state word’s is discarded by the shift that lifts it into the high lane.
§Returns
8 wires, each packing both output states:
- low 32 bits: the second compression’s output.
- high 32 bits: the first compression’s output.