pub fn sha256_varlen(builder: &CircuitBuilder, message: &ByteVec) -> [Wire; 4]Expand description
Computes the SHA-256 hash of a variable-length message.
This gadget consumes a ByteVec whose actual length is runtime-determined and returns the
256-bit digest as 4 wires of 64 bits each in big-endian order, matching sha256_fixed’s
output layout (produced by State::pack_4x64b).
Internally the gadget computes each 32-bit word of the SHA-256 padded message as a derived
wire, classifying every word position with the flags is_message_word, is_boundary_word, and
is_length_block. The word at the message/padding boundary mixes the trailing message bytes
with the 0x80 delimiter; padding words are zero except word 15 of the length block, which
holds the bit length. The compression chain is run over every possible block and the final state
is selected via a multiplexer indexed by the runtime length block.
Unlike a checker gadget that asserts a caller-supplied digest, this function takes no such
digest and performs no digest assertion: the returned digest is a single-valued function of
(data, len_bytes), so a free len_bytes can only select which message prefix is hashed, never
an arbitrary digest. The caller remains responsible for constraining len_bytes to its intended
value.
The input ByteVec packs bytes little-endian, whereas the compression function consumes
big-endian words, so the data wires are byte-swapped up front. SHA-256’s 32-bit schedule words
are half the width of a ByteVec word, so each data word yields two consecutive schedule words.
§Arguments
builder- Circuit buildermessage- Input message as aByteVec. Itslen_byteswire holds the actual message length.
§Returns
[Wire; 4]- The SHA-256 digest as 4 wires of 64 bits each in big-endian order.
§Panics
- If the maximum message bit length cannot be represented in the 32-bit length field.