diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index 6c3a40c0..26d94756 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -21,16 +21,16 @@ against the log before quoting it to the project lead. | # | Attack | Gate (same as 1.4) | Result so far | Status | |---|---|---|---|---| -| F1 | Shadow block compressibility and shortcut search | best compressed block within 5% of N on every program; no program over 10% compressible | pending evidence map + box run | RUNNING | -| F2 | Mixer round margin (SAT/MILP, 1 to 4 keyed applications) | no distinguisher or shortcut beyond 2 of the 8 applications | pending evidence map (ca2-mixer) + box run | RUNNING | +| F1 | Shadow block compressibility and shortcut search | best compressed block within 5% of N on every program; no program over 10% compressible | 10^4 and 10^5 class v4 programs: saved instructions mean 0.62%, max 4.69% at 10^4 and 5.078% at 10^5 (1 of 100,000 over 5%, 0 over 10%); nothing folds or dedupes across the 27 passes; every saving is local peephole algebra that clang -O3 removes from the honest kernel too (IR counts match on the worst programs); 0 mismatches in 2 x 10^5 differential and verifier checks, z3 window proofs 0 counterexamples. AP-F1-1: the 0.078-point letter miss on one program, ruling asked. Record `docs/analysis/attack-pass/f1-shadow.md` | PASS on substance; AP-F1-1 letter miss, ruling asked | +| F2 | Mixer round margin (SAT/MILP, 1 to 4 keyed applications) | no distinguisher or shortcut beyond 2 of the 8 applications | one application characterised (differential weight 10 to 12, linear 1, verified on the real code on three days); two applications: no trail at or below weight 20 to 24 within 7,200 s per job, the MSB and LSB families die at two; rotational-XOR no bias at one application; the multiply layer folds on 0 of 2^20 inputs, k applications cost k; k = 3, 4 general jobs closing on the box. Record `docs/analysis/attack-pass/f2-mixer.md` | PASS (effort-bounded; k = 3, 4 lines pending) | | F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | 0 of 64 and 0 of 1,024 lines under j+1 (exhaustive closure search, cross-checked by exhaustive pebbling at 10 lines, 10,240 pairs, 0 mismatches); both planted broken chains fire; curve monotone at both op counts; f=1 point 9,360 ops per item unchanged. Record `docs/analysis/attack-pass/f3-cache.md` | PASS | | F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | PASS against M2 (DSP-bound datapath): 0 of 2^28 days over 1.1x; planted weak days fire; every ROT and RC class 0. Bound finding AP-F4-1 on M1 (LUT adders): 5,476 of 2^24 days (3.26e-4) over 1.1x as the tail of a sum, no weak class; worst public-calendar day 29,337 at 1.121x, at most 12.1% more rate that day for a per-day LUT FPGA, 0 for any chip; redraw rule (NAF sum under 163 rejected) routed to the next class. Record `docs/analysis/attack-pass/f4-weakday.md` | PASS (v4); AP-F4-1 routed to the next class | | F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x at k=1 GDDR7 reproduces, 3.2x at k=0.5, 4.1x at k=0.3 (matches ledger M32); FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). FINDING: the k=0.33 figure is framed as the X9's measured core (M32) and a "measured class" (ladder branch ยง5a); the X9 was withdrawn before launch and never benchmarked. F2 hour SKIPPED: no AWS account | FIXED-AND-PASSED (sweep PASS; AP-F5-1 fixed and re-gated 7 Oct 2026: chip section re-run 2.1x at k=1 unchanged, identity grep 0 hits, site lane concurred); F2 hour SKIPPED-BY-DECISION (the project lead, 7 Oct 2026, 09:5x UK; plan 4.2 row F5 is the sweep only at 3714c2a0; the FPGA row stays the JEDEC-ceiling model row labelled unmeasured) | -| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | O-1.14 CLOSED on an i7-9700K (2019 desktop core): v4 6.006 ms avg, 6.334 cold max per warp; dr736 10.04 (the known-fail fires); box proxies 5.06 / 8.23. Worst-case search over 10^5 owed | RUNNING (O-1.14 closed) | -| F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | (b) census PASS at 2^24 seeds: no class over 1.1x, stride bijective on all draws, R, pos and M uniform (chi-square 38.5 on 30 dof), op-weight corners 1.0x, planted cases fire; (c) 64-bit day-key seeding PASS as the spec intends, 0 collisions in 2^17; (a) re-roll harness INCOMPLETE by the plan's allowance: the node's era seed is a plain chain block hash (`seed_below`), the cut is grindable with one block of hash at no delay (1 of 6 epochs) and immune past one block interval (0 of 6), and the 1-hour VDF of spec 4.4 is not in the node; the era-VDF lane builds it with `reroll.mjs` as its gate. Record `docs/analysis/attack-pass/f7-era.md` | PASS (b, c); INCOMPLETE (a) pending the era VDF, a freeze precondition | -| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model | AP-F8-1 resolved to a mechanism: the window null gives 1.39x at the top 0.1% (not 4.05x); the rest is a lossy LOAD SOURCE (an `or` writer feeding site 15's load; the all-ones source is item 0xca5b92, 7 of 7 next-hottest predicted), a fault class in the acceptance rule's blind spot carried by 96.6% of v4 programs; hot-set bound at most 1.067x under rule (c); no v4 change, v5 generator item with phase E as its gate; phase E (64 seeds) pending | FINDING (mechanism ours; fix ships in 0.3.20 (the feature node) on `ca3-v4-amend`, re-gate by this lane's 64-seed census) | -| F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | edges reproducible via `accept`; grinding measurement needs PC 2's 5090 or a rented pod | BLOCKED (PC 2 go / pod) | -| F10 | Ladder signal monotonicity harness | no step without 90% over 7 windows in either direction | pending fast-time harness | RUNNING | +| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | O-1.14 CLOSED on an i7-9700K (v4 6.006 ms avg, 6.334 cold max; dr736 10.04 fails as it must). Box search: 100,000 programs drawn and ranked, 50,000 timed cold on the one-core proxy (min / median / p99 / max 4.610 / 4.948 / 5.606 / 6.194 ms, `attack-f6/48484`); half-core re-times of the worst (batches B and C) queued, starved of the exclusive hold by back-to-back shared holders (F2's runner now stopped to free it); carried at the genesis ratio the worst would read 10.3 ms, at the additive cost 9.66 ms, so batch C decides | INCOMPLETE (batch C decides; re-armed) | +| F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | (b) census PASS at 2^24 seeds: no class over 1.1x, stride bijective on all draws, R, pos and M uniform (chi-square 38.5 on 30 dof), op-weight corners 1.0x, planted cases fire; (c) 64-bit day-key seeding PASS as the spec intends, 0 collisions in 2^17; (a) re-roll harness INCOMPLETE by the plan's allowance: the node's era seed is a plain chain block hash (`seed_below`), the cut is grindable with one block of hash at no delay (1 of 6 epochs) and immune past one block interval (0 of 6), and the 1-hour VDF of spec 4.4 is not in the node; the era-VDF lane builds it with `reroll.mjs` as its gate. Record `docs/analysis/attack-pass/f7-era.md`; the harness's three devnet-980 nodes stopped by pid at 12:1x UK | PASS (b, c); INCOMPLETE (a) pending the era VDF, a freeze precondition | +| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model | line index PASS at 2^28 (max +5.61 sigma, control +5.61). Phase E, 64 seeds at 2^18 nonces: 31 of 64 over 1.2x of the window model (median 1.17x, p90 2.70x, max 13.09x), 23 with a hot item, the lossy-source class across the stream. AP-F8-1 resolved to a mechanism: the window null gives 1.39x at the top 0.1% (not 4.05x); the rest is a lossy LOAD SOURCE (an `or` writer feeding site 15's load; the all-ones source is item 0xca5b92, 7 of 7 next-hottest predicted), a fault class in the acceptance rule's blind spot carried by 96.6% of v4 programs; hot-set bound at most 1.067x under rule (c); no v4 change, v5 generator item with phase E as its gate; phase E (64 seeds) pending | FINDING (mechanism ours; fix ships in 0.3.20 (the feature node) on `ca3-v4-amend`, re-gate by this lane's 64-seed census) | +| F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | (c) grinding on the 5090 pod: +0.004% of rate at K = 2^14 (141.62 vs 141.61 MH/s, sd 0.003, 5 rounds) at 11.7 hashes of search per hash, ceiling +43%: PASS; (a) edges on generator 4 running in parts (21,007 agreeing so far); (b) hot-set search over 10^6 seeds running in parts (about half done) | (c) PASS; (a), (b) RUNNING on the box | +| F10 | Ladder signal monotonicity harness | no step without 90% over 7 windows in either direction | known-fail fails, known pass passes; new cases on the exact-share driver: 89% up holds (no step), 89 then 90% down with restarts steps only at 90% after the 7-window cool-down, the floor holds under 100% down (never below rung 0); decision per seed block memoised, identical after a restart, never differs between nodes; 19 of 19 checks per case. Two items to main, not findings: a stale commit string in the ladder lane's igneumd, and proof-synced nodes deciding rung 0 until the witness lands (a precondition line for spec 01). Record `docs/analysis/attack-pass/f10-ladder.md` | PASS | ## The rows @@ -258,6 +258,18 @@ OPEN until that check lands (CLAUDE.md: a rule row closes only with its check). ## Ledger rows +AP-F1-1 (hash lane; ruling asked). At 10^5 class v4 programs one program (`attack-f1/37341`) compresses by 5.078 +percent (13 of 256 shadow instructions per pass), 0.078 points over the gate's first clause, on 1 of 100,000; every +other program is within 5 percent and none over 10. The saving is the same local shape as on every program (a +register written twice from one source with no write between), nothing crosses a pass, and clang -O3 removes the +same instructions from the honest kernel (IR counts match the harness on the worst programs), so a chip gains nothing +relative to a card: no shortcut. The gate as written counts honest-compiler simplification as compressibility. Two +ways to close: re-word gate (1) and row F1 to "compressible beyond the honest compiler's own simplification" (the +firms then attack chip-relative compression, which is the question), or a shadow-draw redundancy bound in the next +class (reject a shadow with over 12 peephole-removable instructions per pass, rejection about 1e-5; class v4 is on +the live vote). Status: FINDING-OPEN by the letter, PASS on substance; the coordinator rules. + + AP-F5-1 (algorithm and hash lane, ours; the ladder lane is closed). The k about 0.33 chip-efficiency figure is framed as a measured calibration ("the X9's core", `fud-ledger.md` M32 L172; "measured class", `ladder` branch `docs/design/latency-ladder.md` section 5a). The Antminer X9 was withdrawn before launch and never benchmarked, so diff --git a/docs/analysis/attack-pass/f1-shadow.md b/docs/analysis/attack-pass/f1-shadow.md index 7207928c..45a713e2 100644 --- a/docs/analysis/attack-pass/f1-shadow.md +++ b/docs/analysis/attack-pass/f1-shadow.md @@ -7,9 +7,10 @@ box (copies of the summaries, firings and explains in `tools/attack/f1-shadow/re ## 0. One line -PASS at 10^4 and at 10^5 programs: the best compressed shadow block is 6,912 to 6,588 instructions per iteration on -the worst program (4.69 percent, seed `attack-f1/8556`), mean 0.63 percent, no program over 5 percent, none over -10 percent; nothing folds or dedupes across the 27 passes (the saving per pass is the same in every pass, 12 x 27 +PASS on substance at 10^4 and 10^5 programs, with one letter-of-gate miss at 10^5 (AP-F1-1): the best compressed +shadow block is 6,912 to 6,588 instructions per iteration on the worst of 10^4 (4.69 percent, seed +`attack-f1/8556`) and 6,912 to 6,561 on the worst of 10^5 (5.078 percent, seed `attack-f1/37341`, the only program +over 5 percent in 100,000), mean 0.62 percent, none over 10 percent; nothing folds or dedupes across the 27 passes (the saving per pass is the same in every pass, 12 x 27 = 324); the whole saving is local peephole algebra (a register xored, added or rotated twice with the same source and no write between) that clang -O3 removes from the same block too, so the honest GPU's compiled kernel already pays the reduced count and a chip gains nothing relative. Verified: 0 mismatches in 10^4 + 10^5 differential tests @@ -154,7 +155,23 @@ Top of the tail (`results/f1-top50-corrected.csv`): 8556 and 4259 at 4.69 percen ### 7.2 10^5 programs (`logs/census100k-1.log`, `out/census100k/census.csv`) -[[100K]] +| Quantity | Value | +|---|---| +| Programs | 100,000 (`attack-f1/0` to `attack-f1/99999`), 12 threads, 1,073.7 s, finished 10:51 UK | +| Instructions saved, min / mean / max | 0.000 / 0.617 / 5.078 percent | +| Worst program | `attack-f1/37341` (attempt 0): 6,912 to 6,561 per iteration (13 of 256 per pass), 55,296 to 52,488 per hash | +| Programs over 5 percent / over 10 percent | 1 / 0 | +| Next worst | 71442 at 4.70, then 95060, 8556, 77816 at 4.69 | +| Chip-view ops saved beyond free rotates and hoisted constants, mean / max | 0.513 / 5.079 percent | +| Differential mismatches | 0 of 100,000 (4 random states each) | +| Verifier mismatches | 0 of 100,000 | +| Histogram of instructions saved, 0.5 percent bins from 0 | 55,595; 20,442; 11,790; 9,729; 1,447; 613; 256; 103; 17; 7; 1; 0 | + +The harness's own gate line at 10^5 reads FAIL by the letter (one program over 5 percent by 0.078 points); the +substance of section 7.3 and 7.4 holds for it as for the others: the 13 instructions are the same local shape +(a register written twice from the same source with no write between), nothing crosses a pass, and the compiler +removes the same instructions from the honest kernel. Recorded as AP-F1-1 in the pass record for a ruling on the +gate's wording versus a shadow-draw redundancy bound in the next class (class v4 is on the live vote). ### 7.3 What the saving is (`out/explain2-8556.txt`, `results/explain2-8556.txt`) diff --git a/docs/analysis/attack-pass/f2-mixer.md b/docs/analysis/attack-pass/f2-mixer.md index 7a5ef82a..d0865dbf 100644 --- a/docs/analysis/attack-pass/f2-mixer.md +++ b/docs/analysis/attack-pass/f2-mixer.md @@ -84,11 +84,45 @@ are reported. ### 4.2 Differential trails -[FILL: table from logs/summary.md] +| Model | Day | Variant | k | Best trail weight found | No trail at or below (model) | Closed | Per-application floor | Verified on the real code (chain; per application) | Solver s | +|---|---|---|---|---|---|---|---|---|---| +| diff/general | 2026-10-03 | real | 1 | 12 | 11 | yes | 0 | 12.011; [11.939] | 186 | +| diff/general | 2026-10-03 | real | 2 | none | 24 | no (timebox) | 12 | | 1,739 | +| diff/general | 2026-10-04 | real | 1 | 10 | 9 | yes | 0 | 10.001; [9.999] | 321 | +| diff/general | 2026-10-04 | real | 2 | none | 20 | no (timebox) | 10 | | 663 | +| diff/general | 2027-03-01 | real | 1 | 12 | 11 | yes | 0 | 12.057; [11.907] | 175 | +| diff/msb | 2026-10-03 | real | 1 | 12 | 11 | yes | 0 | 12.206; [11.972] | 4 | +| diff/msb | 2026-10-03 | real | 2, 3, 4 | none | 512 (the family dies) | yes | 12 | | 26, 33, 22 | +| diff/msb | 2026-10-04 | real | 1 | 10 | 9 | yes | 0 | 10.001; [10.001] | 309 | +| diff/msb | 2026-10-04 | real | 2, 3, 4 | none | 512 | yes | 10 | | 20, 33, 44 | +| diff/msb | 2027-03-01 | real | 1 | 12 | 11 | yes | 0 | 12.057; [11.907] | 3 | +| diff/msb | 2027-03-01 | real | 2, 3, 4 | none | 512 | yes | 12 | | 10, 15, 21 | +| diff/general | 2026-10-03 | nomul (known fail) | 1 | 7 | 6 | yes | 0 | 5.002; [5.003] | 38 | +| diff/general | 2026-10-03 | nomul | 2 | none | 20 | no | 7 | | 1,309 | +| diff/general, diff/msb | 2026-10-03 | rot0 (known fail) | 1, 2, 4 | 0 | | yes | 0 | probability 1 | under 1 | + +The general model's k = 3 and k = 4 jobs on the three days (7,200 s each) were still running at the Mac's reboot and +their lines are appended from `logs/summary.md` when they close; a trail of weight under 32 at k = 3 would be a +finding and is not expected (the per-application floor is 10 to 12). ### 4.3 Linear trails -[FILL] +| Model | Day | Variant | k | Best trail weight found (correlation 2^-w) | No trail at or below | Closed | Verified (chain; per application) | Solver s | +|---|---|---|---|---|---|---|---|---| +| lin/general | 2026-10-03 | real | 1 | 1 | 0 | yes | 0.996; [0.997] | 5 | +| lin/general | 2026-10-03 | real | 2 | none | 20 | no (timebox) | | 1,019 | +| lin/general | 2026-10-04 | real | 1 | 1 | 0 | yes | 0.995; [0.999] | 5 | +| lin/general | 2026-10-04 | real | 2 | none | 24 | no (timebox) | | 1,669 | +| lin/general | 2027-03-01 | real | 1 | 1 | 0 | yes | 1.003; [0.996] | 5 | +| lin/general | 2027-03-01 | real | 2 | none | 20 | no (timebox) | | 1,224 | +| lin/low2 | 2026-10-03, 2026-10-04, 2027-03-01 | real | 1 | 1 | 0 | yes | 0.995 to 1.003 | 4 to 5 | +| lin/low2 | 2027-03-01 | real | 2, 3, 4 | none | 512 (the family dies) | yes | | 12, 18, 27 | +| lin/general | 2026-10-03 | nomul (known fail) | 1 | 1 | 0 | yes | 0.999; [1.003] | 4 | +| lin/general, lin/low2 | 2026-10-03 | rot0 (known fail) | 1, 2, 4 | 0 | | yes | correlation 1 | 5 to 10 | + +One application carries a weight-1 linear trail (the LSB mask through the prologue and one add, correlation 1/2), +the structural residue of 4.5; at two applications no trail at or below weight 20 to 24 exists in the general +model within the timebox, and the LSB family dies (no trail at or below 512) from k = 2. ### 4.4 Rotational-XOR @@ -130,11 +164,27 @@ shape would keep one application's trail weights. ## 5. Gate and verdict -[FILL] +Gate (plan 4.2 F2, 1.4 (1)): no distinguisher or shortcut beyond 2 of the 8 applications between dependent reads, +after the stated search. + +| Line of attack | Reach | Verdict | +|---|---|---| +| Differential, general model (Markov on the multiply, exact add rule, SAT) | one application: best trail weight 10 to 12 on three days, verified on the real code; two applications: no trail at or below weight 20 to 24 within 7,200 s per job (not closed); the MSB family dies at two applications on every day | nothing reaches 2 applications below 2^-20 | +| Linear, general model (piling-up, SAT) | one application: weight 1 (the LSB residue); two applications: no trail at or below 20 to 24 within the timebox; the LSB family dies at two | nothing reaches 2 applications below 2^-20 | +| Rotational-XOR | no per-bit bias at one application (max abs z 4.0 to 4.6 at 2^20 states, noise ceiling 4.3); 0 exact pairs; the multiply prologue is rotational on at most 3 of 2^20 inputs; the bare double round fires at 134 | does not reach 1 application | +| Algebraic fold of the multiply layer | every identity a fold needs holds on 0 of 2^20 inputs on every day; k applications cost k | no shortcut | + +Verdict: PASS with the effort bound stated: about 60 solver jobs, 2 to 29 minutes each, on three day keys; the +reduced-round margin reached is one application fully characterised (weights 10 to 12 differential, 1 linear) and +two applications with no trail under weight 20 to 24, against 8 applications between reads, so the margin between +what the search reaches and what the construction uses is 6 applications. The k = 3 and k = 4 general jobs +strengthen this when they close. What this does not do is in section 7; the lower bound is the paid question. ## 6. Consequences per tier -[FILL] +No shortcut, so no tier moves: a home card, a rig and a pool pay the 72 applications per item the verifier pays; +a chip with a fixed datapath pays them too (the fold test), which is what `chip-model-v3.md` 5.2's 9,360 ops per +item assumes. `mixer_mult` stays 8; the verifier measurement of F6 stands unchanged. ## 7. What this does not do diff --git a/docs/analysis/attack-pass/f8-uniform.md b/docs/analysis/attack-pass/f8-uniform.md index e98c6848..f49845c8 100644 --- a/docs/analysis/attack-pass/f8-uniform.md +++ b/docs/analysis/attack-pass/f8-uniform.md @@ -242,11 +242,11 @@ ratio-to-window-model above 1.2x at f = 0.1%. |---|---|---| | The largest bucket within 6 sigma of uniform on the stated sample sizes (line index, 2^28 derivations) | +4.84 sigma on 64-line segments, +5.61 on 2^22 lines (control +4.18 / +5.61), chi2/dof 0.99937 | PASS | | The item distribution within 6 sigma of uniform (against the window model, the design's own null) | p2 +4.59 sigma (control +4.64); p1 +45.77; p3 +12,245.66 | FAIL on p1 and p3 | -| No hot set under 1% of items among passing seeds (10^6 nonces on three programs; the 64-seed census at 2^18) | p2 none; p1 top 0.1% at 1.888x the window model (2.247x flat), X/f 2.57; p3 16.46x (18.92x flat), X/f 43.2; census: CENSUS-GATE | FAIL | -| The Counter ASIC lane's record gate: top 0.1% within 1.2x of the window-model control on every seed | p2 1.029x; p1 1.888x; p3 16.46x; census: CENSUS-GATE2 | FAIL | +| No hot set under 1% of items among passing seeds (10^6 nonces on three programs; the 64-seed census at 2^18) | p2 none; p1 top 0.1% at 1.888x the window model (2.247x flat), X/f 2.57; p3 16.46x (18.92x flat), X/f 43.2; census: 31 of 64 seeds over 1.2x of the window model, 23 with a hot item | FAIL | +| The Counter ASIC lane's record gate: top 0.1% within 1.2x of the window-model control on every seed | p2 1.029x; p1 1.888x; p3 16.46x; census: 31 of 64 seeds over 1.2x (median 1.17x, p90 2.70x, max 13.09x on p31) | FAIL | **Verdict: FINDING (AP-F8-1).** The line index passes at 2^28 derivations. The cross-hash item histogram fails -the hot-set gate on 2 of the 3 named programs (one of them the live devnet epoch-0 program) and on CENSUS-FRACTION of +the hot-set gate on 2 of the 3 named programs (one of them the live devnet epoch-0 program) and on 31 of 64 seeds (48 percent) of of the 64-seed census, from `or` (and mildly `mul`) writes on a load's source register after its last injecting write, outside every test of rule (c). What it moves: not the mask or the fold (the derivation is uniform) but the acceptance rule, (a') and (c') above, and the packs re-cut. Ownership: the Counter ASIC lane (generator and rule), diff --git a/docs/analysis/attack-pass/f9-grind.md b/docs/analysis/attack-pass/f9-grind.md index 9f9baff9..f103215b 100644 --- a/docs/analysis/attack-pass/f9-grind.md +++ b/docs/analysis/attack-pass/f9-grind.md @@ -216,3 +216,12 @@ hash and costs 3,400 x 1,280 lane-instructions = 2.4 hashes of search. The measu |---|---| | selftest, inspect, grind, census parts and drivers | `/srv/builds/igneum-wt-attack/attack-f9/` on igneum-build-1 (`selftest.log`, `inspect-*.log`, `grind-*.log`, `edges.part*.tsv`, `edges.driver.log`, `hotset.part*.tsv`, `hotset.driver.log`, `hotset-timing.tsv`, `ref.txt`, `table-*.bin`) | | card smoke run and full run | the pod's `/workspace/f9/podjob/smoke/log/` and `log/` (`run.log`, `nvcc.log`, `host.log`, `power.csv`, `power-by-variant.txt`, `sha256.txt`), copied to `/srv/builds/igneum-wt-attack/attack-f9/pod/` at the end | + +### The card, the measurement (RTX 5090 pod ap-f9, `pod/host.log`, sha256 83b1372c..., copied to +`/srv/builds/igneum-wt-attack/attack-f9/pod/`) + +Per-warp header grinding at K = 2^14 draws per warp against the honest kernel, 5 interleaved rounds of 8 s each: +141.62 against 141.61 MH/s, +0.004 percent of rate, sd 0.003, at 11.7 hashes of search per hash. The unreachable +ceiling (the five init-determined loads fully coalesced, `forced1` extended) is +43 percent. Gate: the grinding gain +under 1 percent of rate at any search cost. Sub-row (c): PASS. Pod time about 1 h 50 min from 09:02 UK; destroyed on +the lane's done line.