pub fn sha512_varlen(builder: &CircuitBuilder, message: &ByteVec) -> [Wire; 8]Expand description
Computes SHA-512 hash of a variable-length message.
This gadget consumes a ByteVec whose actual length is runtime-determined and returns the
512-bit digest as 8 wires in big-endian order, matching sha512_fixed’s output layout.
Internally the gadget computes each word of the SHA-512 padded message as a derived wire,
classifying every word position with the flags is_message_word, is_boundary_word, and
is_length_block. The word at the message/padding boundary mixes the trailing message bytes
with the 0x80 delimiter; padding words are zero except word 15 of the length block, which
holds the 64-bit bit length. The compression chain is then run over every possible block and
the final state is selected via a multiplexer indexed by the runtime length block.
The input ByteVec packs bytes little-endian, whereas the compression function consumes
big-endian words, so the data wires are byte-swapped up front.
§Arguments
builder- Circuit buildermessage- Input message as aByteVec. Itslen_byteswire holds the actual message length.
§Returns
[Wire; 8]- The SHA-512 digest as 8 wires of 64 bits each in big-endian order.
§Panics
- If the maximum message bit length cannot be represented in a 64-bit wire.