diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index 26f96e6f..d153d9b8 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -24,7 +24,7 @@ against the log before quoting it to the project lead. | F2 | Mixer round margin (SAT/MILP, 1 to 4 keyed applications) | no distinguisher or shortcut beyond 2 of the 8 applications | pending evidence map (ca2-mixer) + box run | RUNNING | | F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | pending evidence map (ca2-cache) + box run | RUNNING | | F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | pending box census | RUNNING | -| F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 ("2.1x per joule over the 5090 at v4, k=1") holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x reproduces exactly at k=1 GDDR7; FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). F2 hour SKIPPED: no AWS account on this Mac | PASS (sweep); F2 SKIPPED | +| F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x at k=1 GDDR7 reproduces, 3.2x at k=0.5, 4.1x at k=0.3 (matches ledger M32); FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). FINDING: the k=0.33 figure is framed as the X9's measured core (M32) and a "measured class" (ladder branch ยง5a); the X9 was withdrawn before launch and never benchmarked. F2 hour SKIPPED: no AWS account | PASS (sweep); FINDING (X9 framing); F2 SKIPPED | | F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | v4 average 4.90 to 5.06 ms one-core cold, 8.23 ms half-core proxy (under 10 ms). Worst-case search over 10^5 and laptop run owed | RUNNING | | F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | model era section: re-roll needs a 1,800x VDF (300x beats only the epoch); weakest op-weight corner about 20% of shadow datapath energy, 0 chip effect. Harness + 2^20 census owed | RUNNING | | F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | largest bucket within 6 sigma of uniform; no hot set under 1% of items | pending box census | RUNNING | @@ -77,11 +77,14 @@ f=1 chip's per-joule edge over the 5090 above the published 2.1x at k=1. Gate: the published sentence (evidence row 17) holds across the sweep; the FPGA row under 27 M reads/s/W. -Result (sweep): PASS. The model's measured-anchor column (GDDR7, the 5090 reads 82% of its ceiling) gives the -f=1 chip's v4 per-joule edge over the RTX 5090 bench row as 4.1x / 3.2x / 2.1x / 1.5x at k = 0.3 / 0.5 / 1 / 1.5. -At k = 1 the figure is 2.1x, exactly the published sentence. The higher HBM3 and HBM4 columns rest on an 8-activate -per 12 ns window that JEDEC HBM2 timings (4 per 28 ns) do not support; the model already states GDDR7 is the column -to quote, so the sentence stands with its bound. +Result (sweep): PASS on the numbers. The model's measured-anchor column (GDDR7, the 5090 reads 82% of its ceiling) +gives the f=1 chip's v4 per-joule edge over the RTX 5090 bench row as 4.1x / 3.2x / 2.1x / 1.5x at k = 0.3 / 0.5 / +1 / 1.5. At k = 1 the figure is 2.1x, and 3.9x at k about 0.33, which matches `fud-ledger.md` M32. The higher HBM3 +and HBM4 columns rest on an 8-activate per 12 ns window that JEDEC HBM2 timings (4 per 28 ns) do not support; the +model already states GDDR7 is the column to quote. One wording gap: `evidence.md` row 17 says "brings it to about +2x", which is a floor that holds at k about 0.9 and above but understates the edge at lower k (3.2x at k = 0.5). The +accurate statement is M32's, 2.1x at k = 1 with the k range beside it. The sweep's numbers stand; the finding is the +X9 framing below. FPGA row: the HBM2 FPGA ceiling is 2.3 to 2.9 G reads/s (measured Shuhai U280, FCCM 2020, equal to the JEDEC tFAW-bound 2.3 G/s), 10 to 21 M reads/s/W at 115 to 150 W, 0.30 to 0.47x of the 5090 per watt. Under the 27 M @@ -89,11 +92,22 @@ reads/s/W gate. The AWS F2 hour is SKIPPED: there is no AWS account or `aws` CLI cannot be taken here; the row stays the literature-bound figure and the firm is told the F2 measurement was not run internally. -X9 note (coordinator, 7 October 2026): Bitmain's Antminer X9 (RandomX ASIC, 1 MH/s, 2,472 W, about USD 5,600) was -announced and, per pcpraha.cz and r/MoneroMining, withdrawn before launch. Its implied core efficiency (k about -0.33) is a CLAIMED, unmeasured figure from a design that never shipped or was benchmarked. It is carried as the -pessimistic bound, not as a calibration point. At k = 0.33 the sweep reads the GDDR7 v4 edge near 4.0x, inside the -range already modelled; it does not move the k = 1 published sentence. +FINDING (X9 framing), owning lane algorithm and hash (the ladder lane is closed, so ours): the published numbers +already carry 2.1x at k = 1 beside 3.9x at k about 0.33 (`fud-ledger.md` M32, recalibrated under X35). The error is +the framing. M32 calls the k = 0.33 figure "the X9's core" and the `ladder` branch's `latency-ladder.md` section 5a +calls k about 0.33 a "measured class". Bitmain's Antminer X9 (RandomX ASIC, 1 MH/s, 2,472 W, about USD 5,600) was +announced and, per pcpraha.cz ("Antminer X9 canceled: Bitmain withdraws model from market before launch") and +r/MoneroMining, withdrawn before launch. Its implied core efficiency (k about 0.33) is a CLAIMED datasheet figure +from a design that never shipped and was never benchmarked, not a measured calibration point. It is carried as the +pessimistic bound, not a calibration. This collides with the merged ledger X34 ("RandomX has a shipping chip; +correct every sentence that said otherwise"): if the X9 was withdrawn, X34's correction is itself wrong and must be +reversed. A research agent (coordinator, 7 October 2026) is confirming the withdrawal date and whether any unit was +benchmarked; the public X9 sentences in `evidence.md`, `fud-ledger.md` M32 and the `ladder` branch are NOT rewritten +until that confirmation lands, to avoid thrashing a public claim on an unconfirmed fact. What a finding moves +(plan 4.2 F5): the sentence re-cut before the freeze so the firms attack the corrected model. The re-cut, once the +fact is confirmed: k about 0.33 labelled a claimed pessimistic bound from a withdrawn design everywhere it appears; +2.1x at k = 1 on the GDDR7 measured anchor kept as the headline with the k range beside it; k itself unmeasured +until Lot C produces it. This row reads FIXED-AND-PASSED only after the re-cut and its re-gate. Economic row the withdrawal implies: a recompute chip at a 3x fixed-function factor against a CPU and GPU fleet must recover its NRE (low to mid seven figures at a modern node, `chip-model-v3.md`) and carry a fork threat (a @@ -161,5 +175,14 @@ before the ladder is frozen. ## Ledger rows -No findings yet. Any finding is logged here and in `docs/fud-ledger.md` with its owning lane (hash and algorithm: -fixed in `igneum-pow` behind a test and re-gated; node: the node lane) before the row is marked FIXED-AND-PASSED. +AP-F5-1 (algorithm and hash lane, ours; the ladder lane is closed). The k about 0.33 chip-efficiency figure is +framed as a measured calibration ("the X9's core", `fud-ledger.md` M32 L172; "measured class", `ladder` branch +`docs/design/latency-ladder.md` section 5a). The Antminer X9 was withdrawn before launch and never benchmarked, so +k about 0.33 is a claimed datasheet bound, not a measurement. This also puts the merged ledger X34 ("RandomX has a +shipping chip") in question. Fix owed, held until the coordinator's research agent confirms the withdrawal and the +no-benchmark fact: relabel k about 0.33 as a claimed pessimistic bound from a withdrawn design in `evidence.md` row +17, `fud-ledger.md` M32 and the `ladder` branch; reverse X34 if the withdrawal is confirmed; keep 2.1x at k = 1 on +the GDDR7 measured anchor as the headline with the k range beside it. Re-gate after the re-cut. Status: FINDING-OPEN. + +Any further finding is logged here and in `docs/fud-ledger.md` with its owning lane (hash and algorithm: fixed in +`igneum-pow` behind a test and re-gated; node: the node lane, relay agent) before the row is marked FIXED-AND-PASSED.