Skip to main content

sha512_varlen

Function sha512_varlen 

Source
pub fn sha512_varlen(builder: &CircuitBuilder, message: &ByteVec) -> [Wire; 8]
Expand description

Computes SHA-512 hash of a variable-length message.

This gadget consumes a ByteVec whose actual length is runtime-determined and returns the 512-bit digest as 8 wires in big-endian order, matching sha512_fixed’s output layout.

Internally the gadget computes each word of the SHA-512 padded message as a derived wire, classifying every word position with the flags is_message_word, is_boundary_word, and is_length_block. The word at the message/padding boundary mixes the trailing message bytes with the 0x80 delimiter; padding words are zero except word 15 of the length block, which holds the 64-bit bit length. The compression chain is then run over every possible block and the final state is selected via a multiplexer indexed by the runtime length block.

The input ByteVec packs bytes little-endian, whereas the compression function consumes big-endian words, so the data wires are byte-swapped up front.

§Arguments

  • builder - Circuit builder
  • message - Input message as a ByteVec. Its len_bytes wire holds the actual message length.

§Returns

  • [Wire; 8] - The SHA-512 digest as 8 wires of 64 bits each in big-endian order.

§Panics

  • If the maximum message bit length cannot be represented in a 64-bit wire.