diff --git a/hashes/zkevm/src/sha256/vanilla/constraints.rs b/hashes/zkevm/src/sha256/vanilla/constraints.rs index f0ff78a1..27dc7ec9 100644 --- a/hashes/zkevm/src/sha256/vanilla/constraints.rs +++ b/hashes/zkevm/src/sha256/vanilla/constraints.rs @@ -293,7 +293,7 @@ impl Sha256CircuitConfig { |cb| { // Input bytes need to be zero, or 128 if this is the first padding byte cb.require_equal( - "padding start/intermediate byte", + "padding start/intermediate byte, all padding rows except the last one", input_bytes[idx].clone(), is_first_padding.expr() * 128.expr(), ); @@ -309,7 +309,7 @@ impl Sha256CircuitConfig { |cb| { // Input bytes need to be zero, or 128 if this is the first padding byte cb.require_equal( - "padding start/intermediate byte", + "padding start/intermediate byte, last padding row but not in the final block", input_bytes[idx].clone(), is_first_padding.expr() * 128.expr(), );