adv-mixer-2: row Q7 measured (redraw rule: after-fraction 0 over 2^24 days), log
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
24ddf3576d
commit
0c930efad3
3 changed files with 190 additions and 5 deletions
159
docs/analysis/cryptanalysis/logs/adv-mixer-2/redraw-2p24-206.log
Normal file
159
docs/analysis/cryptanalysis/logs/adv-mixer-2/redraw-2p24-206.log
Normal file
|
|
@ -0,0 +1,159 @@
|
|||
2026-10-07T20:53:06Z start redraw-2p24-206 (lease pool 32 min 16): /srv/builds/_adv-adv-mixer-2/bin/adv-mixer-2 redraw-census --from 20729 --count 2^24 --threads {cores} --max-cost 206
|
||||
lease: 0 of 16 pool cores free (32 leased), a higher class waits ahead; waiting
|
||||
lease: holding 16 pool cores (24,25,26,27,28,29,30,31,76,77,78,79,80,81,82,83, waited 6059 s, class adv): adv-mixer-2 redraw-2p24-206
|
||||
adv-mixer-2 redraw-census --from 20729 --count 2^24 --threads 16 --max-cost 206 | internal adversarial pass, not an independent review | class v4 x8, 72 applications per item | median cost A for gains 226
|
||||
|
||||
redraw-census: rule = redraw while cost A < 206 or model C k >= 1 or ROT all equal; 16777216 days from 20729, 8.3 s
|
||||
|
||||
| Redraws needed | Days | Fraction |
|
||||
|---|---|---|
|
||||
| 0 | 16767195 | 9.994e-1 |
|
||||
| 1 | 10014 | 5.969e-4 |
|
||||
| 2 | 7 | 4.172e-7 |
|
||||
|
||||
## After the redraw rule: 16777216 days from 20729
|
||||
|
||||
| Class | Count | Fraction | log2 | Worst day: cost A, gain A, date |
|
||||
|---|---|---|---|---|
|
||||
| ROT all equal | 0 | 0.000e0 | -inf | none |
|
||||
| ROT distinct <= 2 | 4 | 2.384e-7 | -22.0 | day 57146: 220, 1.0273x, 2126-06-18 |
|
||||
| ROT distinct <= 3 | 533 | 3.177e-5 | -14.9 | day 14722898: 207, 1.0918x, 42279-12-05 |
|
||||
| ROT distinct <= 4 | 26005 | 1.550e-3 | -9.3 | day 804699: 206, 1.0971x, 4173-03-11 |
|
||||
| ROT max multiplicity >= 4 | 35631 | 2.124e-3 | -8.9 | day 74772: 206, 1.0971x, 2174-09-20 |
|
||||
| ROT same-word pair sums to 32 | 2062531 | 1.229e-1 | -3.0 | day 94648: 206, 1.0971x, 2229-02-20 |
|
||||
| ROT two same-word pairs sum to 32 | 100726 | 6.004e-3 | -7.4 | day 170878: 206, 1.0971x, 2437-11-06 |
|
||||
| ROT any pair sums to 32 | 10021966 | 5.974e-1 | -0.7 | day 27016: 206, 1.0971x, 2043-12-20 |
|
||||
| ROT >= 4 in {1,31} | 16548 | 9.863e-4 | -10.0 | day 311263: 206, 1.0971x, 2822-03-18 |
|
||||
| ROT all 8 in {1,2,30,31} | 2 | 1.192e-7 | -23.0 | day 14330190: 213, 1.0610x, 41204-09-23 |
|
||||
| ROT >= 4 in {8,16,24} | 74547 | 4.443e-3 | -7.8 | day 274689: 206, 1.0971x, 2722-01-28 |
|
||||
| ROT column set == diagonal set | 384 | 2.289e-5 | -15.4 | day 11582441: 209, 1.0813x, 33681-08-24 |
|
||||
| MUL any = 1 | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any = 2^32-1 | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any involution (x^2 = 1) | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any w32 <= 2 | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any w32 <= 3 | 63 | 3.755e-6 | -18.0 | day 9046825: 207, 1.0918x, 26739-05-15 |
|
||||
| MUL any w32 <= 4 | 5986 | 3.568e-4 | -11.5 | day 498141: 206, 1.0971x, 3333-11-12 |
|
||||
| MUL >= 2 with w32 <= 4 | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any popcount <= 4 or >= 28 | 4998 | 2.979e-4 | -11.7 | day 321675: 206, 1.0971x, 2850-09-19 |
|
||||
| MUL two equal | 0 | 0.000e0 | -inf | none |
|
||||
| MUL two inverse (a*b = 1) | 1 | 5.960e-8 | -24.0 | day 12321130: 232, 0.9741x, 35704-02-10 |
|
||||
| MUL any in exact 2-adder set (model C k >= 1) | 0 | 0.000e0 | -inf | none |
|
||||
| MUL model C k >= 2 | 0 | 0.000e0 | -inf | none |
|
||||
| RC any = 0 | 0 | 0.000e0 | -inf | none |
|
||||
| RC any popcount <= 4 or >= 28 | 5183 | 3.089e-4 | -11.7 | day 9198601: 207, 1.0918x, 27154-12-01 |
|
||||
| RC + rk = 0 for any of the 72 keys | 10 | 5.960e-7 | -20.7 | day 3194363: 212, 1.0660x, 10715-11-15 |
|
||||
| RC two equal | 1 | 5.960e-8 | -24.0 | day 2875598: 220, 1.0273x, 9843-02-14 |
|
||||
| RC[i] + rk = RC[j] + rk' for some i != j, two of the 72 keys | 76 | 4.530e-6 | -17.8 | day 3826820: 211, 1.0711x, 12447-06-24 |
|
||||
| cost A gain >= 1.1x | 0 | 0.000e0 | -inf | none |
|
||||
| cost A gain >= 1.2x | 0 | 0.000e0 | -inf | none |
|
||||
| cost A gain >= 1.5x | 0 | 0.000e0 | -inf | none |
|
||||
|
||||
| Cost A statistic | Value |
|
||||
|---|---|
|
||||
| mean | 225.792 |
|
||||
| median (this census) | 226 |
|
||||
| median used for gains | 226 |
|
||||
| min | 206 (gain 1.0971x) |
|
||||
| max | 257 |
|
||||
| days with gain A >= 1.05x (cost <= 215) | 782984 (4.667e-2, log2 -4.4) |
|
||||
| days with gain A >= 1.1x (cost <= 205) | 0 (0.000e0, log2 -inf) |
|
||||
| days with gain A >= 1.2x (cost <= 188) | 0 (0.000e0, log2 -inf) |
|
||||
| days with gain A >= 1.5x (cost <= 150) | 0 (0.000e0, log2 -inf) |
|
||||
| days with gain A >= 2x (cost <= 113) | 0 (0.000e0, log2 -inf) |
|
||||
|
||||
| Model C k | Days |
|
||||
|---|---|
|
||||
| 0 (gain 1.0000x) | 16777216 |
|
||||
|
||||
| w32 per word | Count | Fraction |
|
||||
|---|---|---|
|
||||
| 3 | 63 | 2.347e-7 |
|
||||
| 4 | 5923 | 2.206e-5 |
|
||||
| 5 | 64356 | 2.397e-4 |
|
||||
| 6 | 474522 | 1.768e-3 |
|
||||
| 7 | 2485126 | 9.258e-3 |
|
||||
| 8 | 9444678 | 3.518e-2 |
|
||||
| 9 | 25903310 | 9.650e-2 |
|
||||
| 10 | 50634472 | 1.886e-1 |
|
||||
| 11 | 68787631 | 2.563e-1 |
|
||||
| 12 | 62385076 | 2.324e-1 |
|
||||
| 13 | 35325627 | 1.316e-1 |
|
||||
| 14 | 11217095 | 4.179e-2 |
|
||||
| 15 | 1637985 | 6.102e-3 |
|
||||
| 16 | 69592 | 2.593e-4 |
|
||||
|
||||
| Cost A | Days |
|
||||
|---|---|
|
||||
| 206 | 6723 |
|
||||
| 207 | 11133 |
|
||||
| 208 | 17599 |
|
||||
| 209 | 27170 |
|
||||
| 210 | 41294 |
|
||||
| 211 | 61912 |
|
||||
| 212 | 88589 |
|
||||
| 213 | 125512 |
|
||||
| 214 | 172244 |
|
||||
| 215 | 230808 |
|
||||
| 216 | 301058 |
|
||||
| 217 | 384074 |
|
||||
| 218 | 479343 |
|
||||
| 219 | 581994 |
|
||||
| 220 | 688482 |
|
||||
| 221 | 795374 |
|
||||
| 222 | 894929 |
|
||||
| 223 | 980480 |
|
||||
| 224 | 1044184 |
|
||||
| 225 | 1086025 |
|
||||
| 226 | 1097816 |
|
||||
| 227 | 1083051 |
|
||||
| 228 | 1035556 |
|
||||
| 229 | 966507 |
|
||||
| 230 | 879269 |
|
||||
| 231 | 773993 |
|
||||
| 232 | 665591 |
|
||||
| 233 | 554660 |
|
||||
| 234 | 448812 |
|
||||
| 235 | 354267 |
|
||||
| 236 | 269627 |
|
||||
| 237 | 200632 |
|
||||
| 238 | 143983 |
|
||||
| 239 | 100948 |
|
||||
| 240 | 68459 |
|
||||
| 241 | 45041 |
|
||||
| 242 | 28659 |
|
||||
| 243 | 17530 |
|
||||
| 244 | 10563 |
|
||||
| 245 | 6130 |
|
||||
| 246 | 3454 |
|
||||
| 247 | 1792 |
|
||||
| 248 | 976 |
|
||||
| 249 | 511 |
|
||||
| 250 | 245 |
|
||||
| 251 | 108 |
|
||||
| 252 | 65 |
|
||||
| 253 | 23 |
|
||||
| 254 | 13 |
|
||||
| 255 | 2 |
|
||||
| 256 | 5 |
|
||||
| 257 | 1 |
|
||||
|
||||
Lowest-cost days (cost A, day, date, gain A):
|
||||
206 27016 2043-12-20 1.0971x
|
||||
206 43428 2088-11-25 1.0971x
|
||||
206 51241 2110-04-18 1.0971x
|
||||
206 53114 2115-06-04 1.0971x
|
||||
206 62837 2142-01-16 1.0971x
|
||||
206 63489 2143-10-30 1.0971x
|
||||
206 68173 2156-08-26 1.0971x
|
||||
206 68393 2157-04-03 1.0971x
|
||||
206 69945 2161-07-03 1.0971x
|
||||
206 73231 2170-07-02 1.0971x
|
||||
206 74772 2174-09-20 1.0971x
|
||||
206 75398 2176-06-07 1.0971x
|
||||
206 84603 2201-08-21 1.0971x
|
||||
206 85594 2204-05-08 1.0971x
|
||||
206 86393 2206-07-16 1.0971x
|
||||
206 92181 2222-05-21 1.0971x
|
||||
|
||||
lease: released 16 pool cores after 6068 s, exit 0
|
||||
2026-10-07T22:34:14Z end redraw-2p24-206 rc=0
|
||||
|
|
@ -0,0 +1,4 @@
|
|||
2026-10-07T22:34:14Z start redraw-2p28-206 (lease pool 32 min 16): /srv/builds/_adv-adv-mixer-2/bin/adv-mixer-2 redraw-census --from 20729 --count 2^28 --threads {cores} --max-cost 206
|
||||
lease: holding 16 pool cores (24,25,26,27,28,29,30,31,76,77,78,79,80,81,82,83, waited 0 s, class adv): adv-mixer-2 redraw-2p28-206
|
||||
adv-mixer-2 redraw-census --from 20729 --count 2^28 --threads 16 --max-cost 206 | internal adversarial pass, not an independent review | class v4 x8, 72 applications per item | median cost A for gains 226
|
||||
|
||||
|
|
@ -56,7 +56,7 @@ take even if it buys no hash rate against the chip model's attacker. The worst r
|
|||
| Q5 cross-day structure | seed collisions, stream shifts by k in 1..72, shared MUL and RC values over the calendar | planted shift pair (found) | counts against expectation | 64-bit seed collisions 0 (expected 3.6e-11); stream shifts 0 (expected 5.2e-9); MUL values shared between two days 77 (expected 79.5), RC 39 (39.8): chance, and a shared constant hands a datapath nothing (the other 39 draws differ) | PASS (BOUND: nothing beyond chance) |
|
||||
| Q2 model B | `scm-refine` on the calendar (36,525 days), on the lowest 2^14 days of the 2^24 census, on a 2^16-day random sample | the self-test constants (3, 5, 7, 9, 2^32 - 1, 2^31 + 1 at 1 adder; 45 at 2): all as expected | the certified-cost distribution | exact sets: 90 constants at 1 adder, 4,101 at 2, 185,223 at 3, 7,983,205 at 4 (0.38 percent of odd constants at 4 or fewer under the restricted form); random words certified at 5 or fewer: 12.3 percent; the rest uncertified. Cost B is a PARTIAL metric (a certified word costs 5, an uncertified one w32 - 1), so its between-day spread (sample: mean 219, min 176; calendar worst day 43959 = 2090-05-10 at B 181) is the certificate's selectivity, not a measured gain, and is not read as one | PARTIAL (bound on the per-word chain length only) |
|
||||
| Q6 ROT diffusion | `avalanche` (1, 2, 3, 4, 8 applications; the 22 address bits; 1,024 states x 512 input bits) on the genesis day, the plants, the 7 worst ROT days of the census | plant rot1 and weakday must read weaker than the genesis day at 1 application: they do (mean flip 0.345 and 0.324 against 0.461; 16,197 and 11,454 input-output pairs never flipped against 5,534) | a per-day gain only if a bit-exact shortcut follows | at 2 applications every day, planted days included, reads mean 0.500, every output bit between 0.42 and 0.58 (sampling spread of 1,024 states), address bits 0.500, no pair unflipped; 8 applications sit between reads. No day gives a shortcut; gain 0 | PASS (BOUND) |
|
||||
| Q7 redraw rule | `redraw-census` 2^24 and 2^28 days with the rule below | `--max-cost 0` must reproduce the real draw on 1,000 days (asserted in the binary) | fraction redrawn; residual over 1.1x must be 0 | queue 07 | RUNNING |
|
||||
| Q7 redraw rule | `redraw-census` 2^24 and 2^28 days with the rule below | `--max-cost 0` must reproduce the real draw on 1,000 days (asserted in the binary; passed) | fraction redrawn; residual over 1.1x must be 0 | 2^24 days: 10,014 redrawn once (5.97e-4), 7 twice (4.2e-7), none three times; after the rule gain A >= 1.1x on 0 days (min cost 206, 1.097x), model C k = 0 on every day, ROT all equal 0; mean cost 225.79 (225.78 before), the 1.05x fraction 4.67e-2 (4.72e-2 before): the rule touches only the tail. 2^28 run PENDING | FINDING closed by the rule (after-fraction 0 on 2^24) |
|
||||
| Q8 anything else | watched while the rows ran; three observations, no box time | n/a | stated or measured | (1) Lead time: the only per-day attacker is an FPGA bitstream synthesised for the day, and synthesis of a full-device design takes hours (approximate, from memory; no figure measured here). Under the interim day rule (`bind::day_bytes`, a pure function of the calendar) the attacker has unlimited lead; under the spec's own proposal O-1.10 (day bytes carry the first epoch seed of the day, known about 20 minutes ahead, section 1.12) a per-day bitstream cannot be ready in time, which removes the whole class without a redraw. (2) The mixer stream is seeded by 64 bits of the day key (K[0], K[1]); K[2..7] enter only the item init; no collision or shift was found in 100 years or 2^24 days, and the planted shift was. (3) The 72 round keys are fixed multiples of 0x9E3779B9; RC + rk = 0 happened on 10 of 2^24 days (expected 4.5, within Poisson) and costs a datapath nothing on either side | PASS (stated) |
|
||||
| GPU rows | none needed | | | no row of this class depends on a GPU | BLOCKED (not applicable) |
|
||||
|
||||
|
|
@ -70,8 +70,8 @@ once a day; nothing else changes; every accepted day is a day the current rule c
|
|||
|
||||
| Quantity | Value |
|
||||
|---|---|
|
||||
| Fraction of days redrawn at least once (exact, models A and C) | 5.694e-4 + 3.123e-5 = 6.0e-4 (2^-10.7), about 22 days per 100 years |
|
||||
| Fraction over 1.1x under model A after the rule | 0 by construction; measured by queue 07 over 2^24 and 2^28 days (PENDING). Before the rule, measured: 5.677e-4 (2^24 census), 4.107e-4 (the 100-year calendar, 15 of 36,525 days) |
|
||||
| Fraction of days redrawn at least once | exact 5.694e-4 + 3.123e-5 = 6.0e-4 (2^-10.7), about 22 days per 100 years; measured over 2^24 days 5.97e-4 once, 4.2e-7 twice, never three times |
|
||||
| Fraction over 1.1x under model A after the rule | 0 measured over 2^24 days (min cost 206, gain 1.097x); 2^28 PENDING. Before the rule, measured: 5.677e-4 (2^24 census), 5.693e-4 (2^32), 4.107e-4 (the 100-year calendar, 15 of 36,525 days) |
|
||||
| Fraction over 1.1x under model C after the rule | 0 (k = 0 on every accepted day) |
|
||||
| Chip-model reading after the rule | unchanged: 1.0 on every day before and after |
|
||||
| What the rule does not fix | the seed is 64 bits of the day key (K[0], K[1]); the day is a pure function of the calendar; both stand; neither is a weakness of this class on the numbers above |
|
||||
|
|
@ -320,6 +320,26 @@ lane's reading of the same numbers is FINDING on the area reading, BOUND for eve
|
|||
also timed the verifier on the worst day (pending in its record when read), which this lane did not repeat: the
|
||||
verifier's instruction count is day-independent by construction.
|
||||
|
||||
### Q7 the redraw rule, measured (FINDING closed)
|
||||
|
||||
Command on box 1 (queue 07, lease held 16 pool cores from 23:32 UK after a 6,059 s wait behind the v5 gate, 8.3 s of
|
||||
compute): `adv-mixer-2 redraw-census --from 20729 --count 2^24 --threads 16 --max-cost 206` (redraw while cost A <
|
||||
206, that is <= 205, or model C k >= 1, or all ROT equal). Log: logs/adv-mixer-2/redraw-2p24-206.log. The
|
||||
self-check inside the binary (`--max-cost 0` on 1,000 days reproduces `MixParams::with_shape` draw for draw) passed.
|
||||
|
||||
| Quantity | Before the rule (2^24 census) | After the rule (2^24 days) |
|
||||
|---|---|---|
|
||||
| days redrawn once / twice / three times | | 10,014 (5.97e-4) / 7 (4.2e-7) / 0 |
|
||||
| gain A >= 1.1x | 9,525 (5.68e-4) | 0 |
|
||||
| gain A >= 1.05x | 792,234 (4.72e-2) | 782,984 (4.67e-2) |
|
||||
| min cost A | 191 (1.183x) | 206 (1.097x) |
|
||||
| mean cost A | 225.780 | 225.792 |
|
||||
| model C k >= 1 | 511 | 0 |
|
||||
| ROT all equal | 0 | 0 |
|
||||
|
||||
Cost to the honest side: forty more SplitMix64 draws on 6e-4 of days, once a day; the verifier and every miner
|
||||
compute the same rule from the same key. The 2^28 run (queue 07, second line) lands below when the lease serves it.
|
||||
|
||||
### Ledger of rule changes during the run (box-hours stay honest)
|
||||
|
||||
| Time (UK) | Change | Effect on this lane |
|
||||
|
|
@ -337,9 +357,11 @@ verifier's instruction count is day-independent by construction.
|
|||
| 21:39 | certificate restructured (shifted-set bitmaps, about 25k lookups per constant), rebuilt on both boxes (sha256 b5d823aa...), chain 03 to 05 restarted on box 2 | |
|
||||
| 21:40 to 21:4x | queue 03, 04, 05 done on box 2 (scm 2 to 4 s each on 24 to 30 cores; eleven avalanche runs on 1 core each) | 0.03 box-hours |
|
||||
| 21:42 to 21:53 | queue 06 census 2^32 on box 1, 32 cores, held 616 s (615 s compute; the lease line's "1480 s" counts from the 21:28 submission, 864 s of it waiting) | 0.17 box-hours (32 cores x 616 s / 96) |
|
||||
| 21:53 | queue 07 redraw-census submitted on box 1; a waiter at class adv behind the v5 gate's leases (correct: it holds nothing); at 22:18 still waiting | |
|
||||
| 21:53 | queue 07 redraw-census submitted on box 1; a waiter at class adv behind the v5 gate's leases (correct: it holds nothing) | |
|
||||
| 22:21 | pre-emption at any size for adv holders once a release or v5 waiter has waited 120 s (lease ce30e357) | nothing of mine held cores; noted |
|
||||
| 23:32 | queue 07 served: 16 cores, redraw 2^24 in 8.3 s; the 2^28 line follows on the same lease | 0.02 box-hours so far |
|
||||
|
||||
Box-hours spent so far: 0.29 (the smoke runs, queue 01 to 06 and the stopped 03), counted as cores held x seconds / 96. The redraw census (queue 07, about a minute of 32 cores) waits on box 1 behind the v5 gate. Pod-hours: 0. GPU: none.
|
||||
Box-hours spent so far: 0.31 (the smoke runs, queue 01 to 07's first line and the stopped 03), counted as cores held x seconds / 96. The redraw census over 2^28 days runs on box 1 on 16 cores. Pod-hours: 0. GPU: none.
|
||||
|
||||
## Bound reached, honestly
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue