Skip to main content

sha256_varlen

Function sha256_varlen 

Source
pub fn sha256_varlen(builder: &CircuitBuilder, message: &ByteVec) -> [Wire; 4]
Expand description

Computes the SHA-256 hash of a variable-length message.

This gadget consumes a ByteVec whose actual length is runtime-determined and returns the 256-bit digest as 4 wires of 64 bits each in big-endian order, matching sha256_fixed’s output layout (produced by State::pack_4x64b).

Internally the gadget computes each 32-bit word of the SHA-256 padded message as a derived wire, classifying every word position with the flags is_message_word, is_boundary_word, and is_length_block. The word at the message/padding boundary mixes the trailing message bytes with the 0x80 delimiter; padding words are zero except word 15 of the length block, which holds the bit length. The compression chain is run over every possible block and the final state is selected via a multiplexer indexed by the runtime length block.

Unlike a checker gadget that asserts a caller-supplied digest, this function takes no such digest and performs no digest assertion: the returned digest is a single-valued function of (data, len_bytes), so a free len_bytes can only select which message prefix is hashed, never an arbitrary digest. The caller remains responsible for constraining len_bytes to its intended value.

The input ByteVec packs bytes little-endian, whereas the compression function consumes big-endian words, so the data wires are byte-swapped up front. SHA-256’s 32-bit schedule words are half the width of a ByteVec word, so each data word yields two consecutive schedule words.

§Arguments

  • builder - Circuit builder
  • message - Input message as a ByteVec. Its len_bytes wire holds the actual message length.

§Returns

  • [Wire; 4] - The SHA-256 digest as 4 wires of 64 bits each in big-endian order.

§Panics

  • If the maximum message bit length cannot be represented in the 32-bit length field.