Merge attack-pass fcf92fb8 into master (gate: green on fcf92fb8, recorded by tools/ci/pre-push.sh; the full gate runs in CI on this merge)
This commit is contained in:
commit
41fb1b3bf4
9 changed files with 95 additions and 24 deletions
|
|
@ -1,13 +1,13 @@
|
|||
# Internal attack pass before the freeze (F1 to F10)
|
||||
|
||||
The internal cryptanalysis pass of `docs/plans/cryptanalysis.md` section 4.2, run before the freeze tag
|
||||
`cryptanalysis-target-1`, so the paid engagement confirms rather than discovers. The founder's word, 7 October 2026:
|
||||
"make sure they find ZERO flaws". Every finding is ours, fixed and re-gated, before any firm starts.
|
||||
`cryptanalysis-target-1`, so the adversarial lanes confirm rather than discover. The founder's word, 7 October 2026:
|
||||
"make sure they find ZERO flaws". Every finding is ours, fixed and re-gated, before the public report.
|
||||
|
||||
Target: the hash class the chain runs after 0.3.15's flip, `igneum-pow` generator v4 `V4_CLASS` = `mx8+sh256x27`
|
||||
(`LoadClass::MX8`, `ShadowClass { instrs: 256, reps: 27 }`), the acceptance rule, the verifier, the era draw,
|
||||
the latency-shadow dataset and ladder, the chip and FPGA cost model. Scope and gates are section 1.1 and 1.4 of
|
||||
the plan, the same tests the firm is held to.
|
||||
the plan, the same tests the public report is held to.
|
||||
|
||||
Lane: attack-pass, worktree `igneum-wt-attack`, branch `attack-pass` from `origin/master` `ab99e5e3`.
|
||||
Binary built on igneum-build-1 (ELF x86-64, `igneum-pow` 0.2.0, sha256 6d2867...1a9ebe5) and run there under
|
||||
|
|
@ -77,7 +77,7 @@ there was nothing to re-gate. Observation (coordinator and the F3 record, not a
|
|||
prices the trade-off at the naive placement; the optimal placement of every 8th line costs 3.17 blocks per read,
|
||||
not 3.5, and 16.0 at f = 1/64, not 31.5 (brute force over 4,426,165,368 sets at n = 8); the chip stays worse than
|
||||
the full mirror at every f under 1, so the verdict stands, and a `chacha_block` shortcut in chaining mode stays
|
||||
the paid question (Lot A and B). What a failure would have moved: the chain construction (a second feed-forward or
|
||||
the open question of the adversarial lanes. What a failure would have moved: the chain construction (a second feed-forward or
|
||||
a cross-segment tie).
|
||||
|
||||
### F4. Weak-day census over 2^24 day keys (hash lane, on the box)
|
||||
|
|
@ -111,7 +111,7 @@ tFAW-bound 2.3 G/s), 10 to 21 M reads/s/W at 115 to 150 W, 0.30 to 0.47x of the
|
|||
reads/s/W gate. The AWS F2 hour is SKIPPED-BY-DECISION (the founder, 7 October 2026, 09:5x UK: not needed for now, not blocked;
|
||||
plan 4.2 row F5 at commit 3714c2a0 on branch cryptanalysis is the chip-model sweep only, 4 h, the algorithm lane).
|
||||
There is also no AWS account or `aws` CLI on this Mac. The FPGA row stays the JEDEC-ceiling model row labelled
|
||||
unmeasured; Lot C prices it from the reads-in-flight model; the firm is told the F2 measurement was not run.
|
||||
unmeasured; the chip-model lane prices it from the reads-in-flight model; the public report states that the F2 measurement was not run.
|
||||
|
||||
FINDING (X9 framing), owning lane algorithm and hash (the ladder lane is closed, so ours): the published numbers
|
||||
already carry 2.1x at k = 1 beside 3.9x at k about 0.33 (`fud-ledger.md` M32, recalibrated under X35). The error is
|
||||
|
|
@ -131,10 +131,10 @@ and measured cells) and `fud-ledger.md` M32's answer paragraph on attack-pass, a
|
|||
on branch `attack-ladder-5a` from the ladder tip 7003f9f5 (the `ladder` branch is checked out by another lane, so
|
||||
the fix rides its own branch for the ladder owner to take). The served-text rows (X34 reversal, X36) belong to the
|
||||
site lane, which confirmed the wording agrees. What a finding moves
|
||||
(plan 4.2 F5): the sentence re-cut before the freeze so the firms attack the corrected model. The re-cut, once the
|
||||
(plan 4.2 F5): the sentence re-cut before the freeze so the public report carries the corrected model. The re-cut, once the
|
||||
fact is confirmed: k about 0.33 labelled a claimed pessimistic bound from a withdrawn design everywhere it appears;
|
||||
2.1x at k = 1 on the GDDR7 measured anchor kept as the headline with the k range beside it; k itself unmeasured
|
||||
until Lot C produces it. This row reads FIXED-AND-PASSED only after the re-cut and its re-gate.
|
||||
until the chip-model lane produces it. This row reads FIXED-AND-PASSED only after the re-cut and its re-gate.
|
||||
|
||||
Economic row the withdrawal implies: a recompute chip at a 3x fixed-function factor against a CPU and GPU fleet
|
||||
must recover its NRE (low to mid seven figures at a modern node, `chip-model-v3.md`) and carry a fork threat (a
|
||||
|
|
@ -288,9 +288,13 @@ attack-pass) by the coordinator's exception rule; nothing touches GitHub.
|
|||
| Family | Class v5 run | Result | Verdict |
|
||||
|---|---|---|---|
|
||||
| F4 weak-day census | 2^24 chain days from 20,729 under `Shape::for_class(&V5_CLASS)`, box 1, 18:5x to 19:1x UTC | byte-identical to the class v4 census: M2 (DSP-bound) 0 of 2^24 days over 1.1x; M1 (LUT adders) 5,476 days, 3.264e-4, the same bounded tail, worst day 4,819,563 at cost 197 against the median 231; planted weak days fire (mul1all M2 unbounded, mulnaf 1.333x). The day-key draw depends on the mixer shape alone and v5 adds only the state flag, so identity is the expected and the measured result | PASS (v4's reading; AP-F4-1 stays the next-class item) |
|
||||
| F8 hot-set gate | 64 seeds at 2^24, chain path, v5 with the dn3 state, box 2 (64 threads), from 18:47 UTC | pending | pending |
|
||||
| F9 exhaustion count | 10^5 chain-shaped seeds on the v5 chain path with the dn3 state, box 1, ten parallel chunks (the chain draw costs about 2.2 s per candidate through (c''), so 10^6 is about fifty hours) | pending | pending |
|
||||
| F1 shadow redundancy | 10^5 class v5 programs through the string-seed path, box 1 | pending | pending |
|
||||
| F8 hot-set gate (pre-freeze reading) | 64 seeds at 2^24, chain path, v5 with the dn3 state, box 2: hand-started at 18:47 UTC (11 seeds, killed on the coordinator's rule: every hand-started run off the boxes, loads 601 and 401), re-queued through `lease pool 64` at 19:23 UTC (17 more seeds), released at 19:4x UTC on the Counter ASIC lane's yield so the class v5 (c''') census, the 0.3.24 board's critical path, could take the pool | every seed read equals sub-version 3's seed for seed (0.9915x to 1.144x, p10 1.50x), as the v5 lane predicted: the leaves change the words, not the read addresses | READING, not the gate line |
|
||||
| F8 hot-set gate, the frozen tip (THE GATE LINE) | igneum-pow class-v5 1c420786 (the 0.995 per-site floor (c''') on sub-version 3's rules; binary sha256 0f5c98dc41a1b3aa..., run from a copy); pairing: the library draws the dn3 epoch-0 program as e5a4ac5978462156, the harness validates bit for bit against the library on the dn3 state (0 mismatches on 66 validation lines); 64 seeds p2 to p65 at 2^24 nonces, chain path, the v5 dataset from v5-dn3-epoch0's state.igsd1, window-model control, build-2 under `lease pool` class v5 as two halves of 32 (ended 21:58:43Z and 22:03:21Z) | 61 of 64 under 1.2x of the window model (0.9919x to 1.144x, p75 1.0024x); 3 over, all inside the named four-seed residue and none new: p10 1.5047x (0x4018f5, 346 reads of 2^31, no predicted source), p8 1.3787x (0x839d33, 419), p4 1.2166x (0x400197, 363); p34 0.9997x under the (c''') floor; p23 1.0000x, p19 0.9997x, p15 0.9998x, p18 1.0001x, p56 1.0000x. Seed for seed the ratios equal sub-version 3's within 0.001 except where the floor moved a draw: the state leaves change the words, not the read addresses. Nothing to a chip | PASS (the known residue p4, p8, p10 unattributed and chased) |
|
||||
| F9 exhaustion count, the frozen tip (A GATE LINE for the 0.3.24 move) | 10^5 chain-shaped seeds on the v5 chain path (era-composed class, `--chain`) with the dn3 state at igneum-pow class-v5 1c420786, pairing e5a4ac5978462156, build-1, ten chunks of 10,000 under `lease pool 4` (chunks 1, 3, 5 to 9 under class v5; chunks 0, 2, 4 re-leased under class release on the coordinator's order; 14,477 to 14,480 s per chunk, about 1.45 s per seed); binary copied into the run dir; interim line sent at 00:55 UTC (seeds drawn, 0 exhausted, 0 panics, max 30, F1 0 failures), which cleared the move; last chunk written 02:34:54 UTC | 100,000 of 100,000 seeds drawn, 0 exhausted, 0 panics, 0 past attempt index 31, max attempt index 30; histogram by attempt index (0 = accepted on the first draw) 0: 31,454; 1: 21,460; 2: 14,660; 3: 10,263; 4: 7,047; 5: 4,701; 6: 3,297; 7: 2,256; 8: 1,532; 9: 1,027; 10: 702; 11: 509; 12: 365; 13: 216; 14: 153; 15: 103; 16: 80; 17: 56; 18: 39; 19: 20; 20: 24; 21: 9; 22: 6; 23: 9; 24: 3; 25: 4; 26: 2; 27: 1; 29: 1; 30: 1; first-draw acceptance 0.3145, mean attempt index 2.185 (3.185 draws per seed), 4,862 seeds (4.86 percent) at index 8 or above, 255 (0.255 percent) at 16 or above; the 256-attempt cap and the deterministic last resort never reached. Meaning per tier: no epoch seed in 10^5 fails to draw a program, so the liveness halt of AP-F8-2 has no observed case on the frozen tip at this count (the bound it supports is under 3e-5 per seed at 95 percent, about one epoch in 33,000 at worst; a halt a node operator would see as a stuck epoch, a miner as a dead epoch, a holder as a paused chain), and the draw cost stays at about 3.2 candidates per epoch for every node | PASS (0 of 10^5; the record `f9-grind.md`, section (d)) |
|
||||
| F1 shadow redundancy, the frozen tip (A GATE LINE for the 0.3.24 move) | 10^5 class v5 programs through the string-seed path (`generate_from_seed_bytes_program_class`, class V5, every candidate draw through the (c''') floor over 2^20) at igneum-pow class-v5 1c420786, build-1, `lease pool 16` re-leased under class release at 22:34:05 UTC (cores 8 to 23), binary copied into `frozen-1c420786-f1/bin` | Running at the 03:06 UTC reading (8 October 2026): the census process (pid 3151604) at 15 busy cores over a 45 s sample, 2 d 19 h of CPU banked over 4 h 30 min of wall, 0 on its live panic path (`census.log`), no end marker; projected end about 09:00 UTC from F9's measured draw cost (about 1.8 core-s per candidate under the night's load, 3.2 draws per program). The interim zeros stand as the partial. Harness gap, named: the census collects every Report in memory and writes `out/census.csv` only at its end, with no progress line, so a count before the end is not an observable on this harness (the v4 10^5 reference of 07 Oct 09:33 UTC, 0.13 core-s per program, ran before sub-version 3's acceptance rule, which is the fifteenfold). Owed on this branch before the harness's next 10^5 run on any class (coordinator's ruling, 04:1x UK): a progress line every 1,000 programs (count, elapsed, running failure count), a partial `census.csv` flushed at the same cadence, and a known-failed test of the flush (a kill after 2,000 programs leaves 2,000 rows) | running; the record line in a second merge when `census.csv` writes |
|
||||
| F4 weak-day census, the post-freeze commit | 2^24 chain days at class-v5 8ca66afa (AP-F4-1 in the agreed form: cost A at most 205, k >= 1 or all-ROT-equal rejected, the forty redrawn), the harness on the agreed w32 convention (digits 0 to 31) and median 226; known-failed day 29,337 redrawn under the rule (cost 203 to 228), day 20,729 at 219 unchanged; build-1 `lease pool 12` class adv, 379 s, ended 22:3x UTC | 0 of 2^24 days over 1.1x on M1 (median 226; minimum cost 206 at day 27,016, 1.097x, one adder above the reject line) and 0 on M2; mean 225.79, sd 6.07 (pre-rule: 5.69e-4 over, min 203). The redraw rule removes the LUT tail by construction and the measurement agrees | PASS; AP-F4-1 FIXED-AND-PASSED against class v5 at 8ca66afa |
|
||||
| F9 exhaustion count | 10^5 chain-shaped seeds on the v5 chain path with the dn3 state, box 1, ten parallel chunks (the chain draw costs about 2.2 s per candidate through (c''), so 10^6 is about fifty hours); killed before its first chunk closed, re-queued through `lease pool` | pending | pending the re-queue |
|
||||
| F1 shadow redundancy | 10^5 class v5 programs through the string-seed path, box 1; the known firings fire under v5 (planted 50 of 256: 19.53 percent; the real block 0.000; the must-not-fire 1.157); the census killed before its end, re-queued through `lease pool` | pending | pending the re-queue |
|
||||
|
||||
## Operating hazards found by the pass
|
||||
|
||||
|
|
@ -323,11 +327,11 @@ register written twice from one source with no write between), nothing crosses a
|
|||
same instructions from the honest kernel (IR counts match the harness on the worst programs), so a chip gains nothing
|
||||
relative to a card: no shortcut. The gate as written counts honest-compiler simplification as compressibility. Two
|
||||
ways to close: re-word gate (1) and row F1 to "compressible beyond the honest compiler's own simplification" (the
|
||||
firms then attack chip-relative compression, which is the question), or a shadow-draw redundancy bound in the next
|
||||
question is chip-relative compression), or a shadow-draw redundancy bound in the next
|
||||
class (reject a shadow with over 12 peephole-removable instructions per pass, rejection about 1e-5; class v4 is on
|
||||
the live vote). Ruling (coordinator, 7 October 2026, 12:3x UK): both. Gate (1) and row F1 re-worded to "no
|
||||
compression of the shadow block beyond the honest compiler's simplification, measured against that compiler on the
|
||||
same program" (sent to the cryptanalysis lane for the plan and the firms' brief), under which the 5.078 percent
|
||||
same program" (sent to the cryptanalysis lane for the plan and the public report), under which the 5.078 percent
|
||||
letter miss at honest-compiler parity is a PASS; and a shadow redundancy bound on the v5 generator's list beside
|
||||
AP-F4-1 and AP-F8-1 (the generator refuses a shadow block whose honest-compiler simplification exceeds a stated
|
||||
fraction; the v5 lane sets the fraction from F1's census), gated by F1's harness on 64 seeds of the v5 stream.
|
||||
|
|
@ -382,7 +386,7 @@ census shows a real fault it goes to the coordinator priced; otherwise the recor
|
|||
the hot-set bound (a 0.1 percent cache, about 1.7 MB of SRAM, under one percent of rate) goes into the next class.
|
||||
Gate wording settled (coordinator, 11:2x UK): plan 1.4 gate (4) and row F8 now read "uniform within the window
|
||||
model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds", carried into the plan's scope
|
||||
text by the cryptanalysis lane so the firms are briefed on the windows before they start.
|
||||
text by the cryptanalysis lane so the public report states the windows.
|
||||
Mechanism (hash lane, branch `ca3-v4-uniform` 095f84a7, `docs/analysis/ca3-v4-uniform.md`, harness
|
||||
`tools/ca3-v4-uniform`, 7 October 2026, 12:3x UK): the windows-union null (a Poisson mixture at 416 / 288 / 736 / 608
|
||||
reads per item by quarter from the program's 16 draws) moves the top 0.1 percent from 0.115 to 0.160 percent, 1.39x,
|
||||
|
|
@ -557,8 +561,13 @@ redraw day 22,633; no pack changes. Landed (Counter ASIC lane, 7 October 2026, 1
|
|||
(`docs/design/class-v5-stored-state.md` section 11) with F4's harness as its gate, re-gated by this lane against the
|
||||
v5 branch once its `accept.rs` carries it. The brief's rank 3 (funding.md B2, the untested all-equal ROT draw of
|
||||
MEMHARD.md) now reads "a bounded tail, measured", with the F4 record as the source.
|
||||
Status: F4 PASS against v4; AP-F4-1 FIXED-AND-PASSED against v5 once the lane's accept.rs carries the rule and the
|
||||
census passes against it.
|
||||
Reconciled with adv-mixer-2's independent census (7 October 2026, 21:5x UK; F4 record section 9): the same class
|
||||
and cost form; this record's NAF counted the carry digit at position 32, which a 32-bit multiplier never pays, so the
|
||||
agreed figures are adv-mixer-2's: median 226, a 1.1x gain at cost A at most 205, 5.69e-4 of days (2^-10.8), 15 days
|
||||
a century, worst 2050-04-28 (day 29,337) at 1.113x; the DSP-bound readings agree at 0; the redraw rule for the next
|
||||
class takes adv-mixer-2's form (cost A at most 205, or k >= 1, or the eight ROT equal).
|
||||
Status: F4 PASS against v4; AP-F4-1 FIXED-AND-PASSED against class v5 at 8ca66afa (7 October 2026, 22:3x UTC: 0 of
|
||||
2^24 days over 1.1x on both metrics with the agreed rule in the draw).
|
||||
|
||||
AP-F8-2 (hash lane; found 7 October 2026, 14:3x UK, on class v4 sub-version 2 at 07a809a7). A chain-shaped epoch
|
||||
seed can exhaust all 32 draw attempts under the new rule (a') and the generator treats exhaustion as a consensus fault
|
||||
|
|
@ -567,7 +576,7 @@ candidates rejected, last: (a') load at 16 reads r6, not fresh by dataflow in th
|
|||
first 331,672 chain-shaped seeds (300,000 drew clean), so a rate of order 10^-6 to 10^-5 per epoch seed; the 10^6-seed
|
||||
measurement with the attempts distribution runs on box 2 (F9's chain path, the panic caught and counted). Meaning:
|
||||
an exhausted epoch seed is an epoch no node can draw a program for, a liveness halt, and the seeds are VDF outputs
|
||||
nobody can steer around it; at one epoch an hour the bracketed rate is one halt per 11 to 40 years, which the firms
|
||||
nobody can steer around it; at one epoch an hour the bracketed rate is one halt per 11 to 40 years, which the public report's readers
|
||||
would compute from the rule as written. Sub-version 1: 0 exhausted in 10^6 chain-shaped seeds. Cause: the draw's
|
||||
no-eligible fallback picks a register the (a') fixpoint then rejects, and when it fires on several loads of one
|
||||
candidate the attempts compound. Fix (the hash lane's call): the draw enforces the freshness fixpoint itself so (a')
|
||||
|
|
|
|||
|
|
@ -275,4 +275,4 @@ exclude), which is the workaround until the build-server lane's check lands.
|
|||
| A chip | gains nothing relative to the cards: the shortcuts are local algebra every compiler takes, and nothing crosses the 27 passes, so `N x 11 pJ x k` keeps its shape with N the executed count (0.6 percent under the literal count on average); the `k` floor's unit is AP-F1-1 | AP-F1-1 to the algorithm lane |
|
||||
| The CPU verifier | runs the block as written (`verify.rs` interprets every instruction), so on a 4.7 percent program it does 4.7 percent of the shadow work a compiled miner skips: 0.03 ms of the 0.67 ms shadow share on the half-core proxy, inside the 10 ms gate with the margin F6 measures | none |
|
||||
| The ladder and the packs | no re-cut: the gate holds; the optional draw-time rule of section 9 is the only change on the table and it is not taken | none |
|
||||
| The paid review | this file and the harness go to the firms with the target; the window-proof script and the census line are the reproduction | hand over with the pass record |
|
||||
| The public report | this file and the harness are published with the target; the window-proof script and the census line are the reproduction | hand over with the pass record |
|
||||
|
|
|
|||
|
|
@ -205,7 +205,7 @@ To main, not findings against the gate:
|
|||
| Stale commit string in the ladder lane's `igneumd` | the binary built 6 October 22:15Z from the fork at 1591ee1d carries 8dbb7a23 (its parent) and no 1591ee1d; the ladder code is in it | the commit-string-check class (CLAUDE.md, 6 October 2026); the ladder lane rebuilds with the two-step before any Devnet 2 crossing; nothing in this row depends on it |
|
||||
| Proof-synced nodes decide rung 0 until the witness lands | `processes::latency_ladder::step_of_epoch` returns rung 0 with a warning when the seed block's windows cannot be walked; after a step, such a node runs the wrong program and splits from full-history peers | a precondition line for the step rule's text in spec 01 when the ladder is adopted: "the ladder activates only once every node can walk the seven windows below every seed block, or carries the ladder witness in its pruning proof"; the design doc already lists the witness as owed (section 9); node lane |
|
||||
| Spec text for the ladder, when adopted (none in spec 01 today; the only ladder there is `epoch_len`'s) | the rule as run: 90 percent of blue blocks in each of 7 consecutive windows ending at the seed block, floor rounding, one rung per decision, the oldest window at or after the last step in either direction, never below rung 0, never into an inadmissible rung; the template's weakest is the live sink tally and the decision's is at the seed | the algorithm lane's spec line; this record is the test it cites |
|
||||
| Three harness faults in the F10 driver | section 4.3; all three were the driver's reading of the node, fixed in `ladder-exact.mjs` v3 | none owed; recorded so the firm does not repeat them |
|
||||
| Three harness faults in the F10 driver | section 4.3; all three were the driver's reading of the node, fixed in `ladder-exact.mjs` v3 | none owed; recorded so the public report does not repeat them |
|
||||
|
||||
Blocked: nothing. Not run: a real-mining 89 percent case (three equal miners cannot cast it; the exact-share driver
|
||||
asks the rule the same question through the same submit path and the same consensus code).
|
||||
|
|
|
|||
|
|
@ -205,8 +205,8 @@ item assumes. `mixer_mult` stays 8; the verifier measurement of F6 stands unchan
|
|||
## 7. What this does not do
|
||||
|
||||
- It does not bound the mixer from below: the general models are trail models (Markov for the multiply's
|
||||
differential, piling-up for the linear), and the family models are exact only inside their families. The firm's
|
||||
job (funding.md B5 rank 1) is the effort-bounded version of the same search with their tools.
|
||||
differential, piling-up for the linear), and the family models are exact only inside their families. The adversarial
|
||||
lanes' job (funding.md B5 rank 1) is the effort-bounded version of the same search with their own tools.
|
||||
- Three days, not a census: the ROT, MUL, RC classes over 2^24 days are F4's row. One cheap addition for F4 from
|
||||
this harness: the MSB-family death at k = 2 (`model.py search --kind diff --family msb --apps 2`) runs in seconds
|
||||
per day, and a day where it does not die is a weak day of the kind the gate is about.
|
||||
|
|
|
|||
|
|
@ -136,7 +136,7 @@ Verdict: PASS.
|
|||
|---|---|---|---|
|
||||
| `funding.md` B2 rank 2 prices the honest trade-off at the naive placement | 3.5 blocks per read at f = 1/8 against 3.17 optimal (9.4 percent less); 31.5 against 16.0 at f = 1/64 (2.0x less, because storing line 0 is worthless: it costs 1 block anyway) | the chip at f = 1/8 reads 15.8 MH/s (608 ops per block, optimal placement) or 14.4 (700, optimal) against `funding.md`'s 13.5 (700, naive); still 0.38x of the full SRAM mirror's 41.7 and 0.12x of the 5090's 136.1 (chip-model-v3.md section 2); the curve stays monotone, so the published verdict (the partial chip is not the threat, the full mirror beats it) stands | one sentence in `funding.md` B2 rank 2: "holding every 8th line at the best placement costs 3.2 blocks per read (3.5 for every 8th line from line 0)". Not edited here: outside this row's two files; for main to serialise |
|
||||
| The chain's hardness per line is sequential time, not memory | one pebble (64 bytes) over j + 1 steps: the cumulative memory of deriving a line is about 64 x (j + 1) byte-steps | the chain protects the cache by op count, which is exactly what the curve prices in ops; parallel attackers pipeline items and pay E(f) x 608 ops per read in throughput, E(f) block latencies in latency; a chip that holds nothing (f = 0) pays 32.5 x 608 = 19,760 ops per read, 158,080 per item, 167,440 with the mixer (17.9x the mixer alone), 2.3 MH/s at 50 T op/s | nothing to move; the public model should keep quoting ops, never bytes, for this piece |
|
||||
| What this row does not cover | a cryptanalytic shortcut inside `chacha_block` in this chaining mode (the differential and avalanche tests are sanity checks, not a bound) | the paid engagement's rank 2 question (`funding.md` B2) stays worth the money; plan 4.2 says the internal pass cannot prove the chain's trade-off curve | none |
|
||||
| What this row does not cover | a cryptanalytic shortcut inside `chacha_block` in this chaining mode (the differential and avalanche tests are sanity checks, not a bound) | the adversarial lanes's rank 2 question (`funding.md` B2) stays worth the money; plan 4.2 says the internal pass cannot prove the chain's trade-off curve | none |
|
||||
|
||||
## Consequences per user tier
|
||||
|
||||
|
|
@ -145,4 +145,4 @@ Verdict: PASS.
|
|||
| Home miner, one 8 / 12 / 16 / 24 or 32 GB card, any vendor, any OS | nothing: the honest miner holds the dataset, the verifier holds the 256 MiB cache; no memory, hash rate, or power figure moves |
|
||||
| Rig, pool user | nothing |
|
||||
| Chip builder | the partial-cache chip is priced 9 percent better at f = 1/8 and 2x better at f = 1/64 than `funding.md` says, and is still worse than the full SRAM mirror at every f below 1; the public per-joule sentence (evidence row 17, 2.1x at k = 1) rests on the item curve's f = 1 point, which this row leaves untouched |
|
||||
| The paid review | the firm receives this record and the harness; rank 2's open question is the block function in chaining mode, not the graph |
|
||||
| The public report | the record and the harness are published; rank 2's open question is the block function in chaining mode, not the graph |
|
||||
|
|
|
|||
|
|
@ -307,3 +307,33 @@ under 4 in `census-100y.md`); the `ROT` rule redraws one, day 57,146 (2 distinct
|
|||
* It did not search optimal single-constant multiplication costs (not computable at 2^28 scale); NAF is the standard
|
||||
canonical bound and the ratio between days is what the gate asks.
|
||||
* It did not census the era draw (F7) or the spec's intent for the 64-bit seeding (F7); the fact is stated in section 1.
|
||||
|
||||
## 9. Reconciliation with adv-mixer-2's independent census (7 October 2026, 21:5x UK; main's order through the
|
||||
crypto-engage coordinator: the two tables side by side, the median each used, one agreed figure)
|
||||
|
||||
Both censuses read the same class, the FPGA LUT multiplier-adder area (no chip or GPU gain), with the same cost form,
|
||||
64 + the sum over the sixteen MUL of (signed-digit weight - 1). They differ in one convention. This harness's
|
||||
`naf_weight` (src/main.rs line 72) computes the canonical NAF of the constant as a `u64` and counts every digit,
|
||||
including the carry digit at position 32 that a 32-bit odd constant carries with probability 1/3; adv-mixer-2's
|
||||
`w32` counts the digits at positions 0 to 31 only, because a multiplier modulo 2^32 is never built with a digit at
|
||||
position 32. Checked on 2^18 random odd constants: mean weight 11.442 with the carry digit against 11.109 without
|
||||
(P(digit at 32) = 0.3334), cost 231.1 against 225.7. So this record charged every day about 5 adders a 32-bit
|
||||
multiplier never pays, unevenly per day, which is the whole of 231 against 226 and of 12 against 15 days a century.
|
||||
|
||||
| Quantity | This record (M1, carry digit counted) | adv-mixer-2 (model A, w32 modulo 2^32) | Agreed |
|
||||
|---|---|---|---|
|
||||
| Cost form | 64 + sum(NAF(MUL_i) - 1), NAF over u64 | 64 + sum(w32(MUL_i) - 1), digits 0 to 31 | adv-mixer-2's: the digit at position 32 costs nothing in a 32-bit multiply |
|
||||
| Median per application | 231 (census over 2^24 chain days; mean 231.113) | 226 (exact, 16-fold convolution over all 2^31 odd constants; the log's provisional 231 superseded) | 226 |
|
||||
| Threshold for a 1.1x gain | cost under 210 (NAF sum under 163) | cost A at most 205 | cost A at most 205 |
|
||||
| Fraction of days over 1.1x | 3.264e-4 (5,476 of 2^24); exact expectation 3.243e-4 | 5.677e-4 (2^24 census); exact 5.694e-4 | 5.69e-4, about 2^-10.8, against the 2^-20 gate |
|
||||
| Days over 1.1x per century (36,525 public days) | 12 | 15, listed in its Q4 | 15 |
|
||||
| Worst public day | 29,337 (2050-04-28), cost 206, 1.121x | 29,337 (2050-04-28), cost A 203, 1.113x | 29,337, 1.113x |
|
||||
| Genesis day 20,729 | cost 226, 0.978x | cost A 219, 1.032x | 219 |
|
||||
| DSP-bound metric | M2: 0 days with k >= 2 in 2^28; k >= 1 at 1.067x | model C: P(k >= 1) 3.12e-5 (1.067x), P(k >= 2) 4.57e-10 (1.143x) | agree: under the gate at every k |
|
||||
| Redraw rule for the next class | reject NAF sum under 163 (cost under 211), redraw from the next stream values | cost A at most 205, or k >= 1, or the eight ROT equal: continue the same SplitMix64 stream and draw the forty again | adv-mixer-2's form and numbers |
|
||||
|
||||
Verdict unchanged: PASS against class v4 on the DSP-bound reading (M2 and model C agree at 0), the LUT tail bounded
|
||||
and measured; the agreed numbers above replace this record's M1 figures wherever quoted, and AP-F4-1's rule on the
|
||||
v5 list takes adv-mixer-2's form. Harness note: `attack-f4 plant` and `day` default `--median` to 221 when the flag is
|
||||
absent (the plant lines of the class v5 run this evening read "median 221" for that reason); every census line in
|
||||
this record was run with `--median 231` and is restated against 226 above.
|
||||
|
|
|
|||
|
|
@ -133,7 +133,7 @@ block input), so the dataset depends on the full key; the mixer-constant stream
|
|||
| Distinct (ROT, MUL, RC) tuples over 2^17 days | 131,072 |
|
||||
| Birthday bound on a 64-bit collision among 2^16 days | 2^(32 - 65) = 2^-33 |
|
||||
|
||||
The spec intends 64 bits for the mixer-constant draw, and the truncation is not a reduction of the draw space the firm
|
||||
The spec intends 64 bits for the mixer-constant draw, and the truncation is not a reduction of the draw space the public report
|
||||
would flag: at most 2^16 days are ever drawn, each a distinct calendar day with a distinct 64-bit seed (0 collisions in
|
||||
2^17), so no two days share a mixer. One observation, within spec intent and recorded for the written argument of
|
||||
`funding.md` B5 rank 6: the mixer-constant stream has 64 bits of seed entropy, so at most 2^64 distinct daily mixers are
|
||||
|
|
|
|||
|
|
@ -137,7 +137,7 @@ every item from the program's 16 windows, and a control that draws each read fro
|
|||
A chip gains nothing from the window steps: the union of the windows is the whole dataset every hour (era-layout.md
|
||||
section 7), the floor window is 2^26 words (256 MiB), and which quarter is dense changes with the program.
|
||||
|
||||
#### The window model (reproducible by the firms)
|
||||
#### The window model (reproducible by any reader)
|
||||
|
||||
For load site s with window draw `(k_s, o_s)` at the 2^28-word dataset: `k = min(k_s, 28 - 26)`, the word window is
|
||||
`[o_s << (28 - k), (o_s + 1) << (28 - k))`; the item window is `[o_s << (24 - k), (o_s + 1) << (24 - k))` of
|
||||
|
|
|
|||
|
|
@ -267,3 +267,35 @@ the or-saturated load source, which is the same fault class the F8 row found fro
|
|||
program's address trace per site, one from the item histogram across hashes. F9-1 therefore merges into AP-F8-1,
|
||||
and the fix is the amendment shipping in 0.3.20 (a load's source drawn only from registers whose last writer injects
|
||||
or is a rotate). Sub-row (b): FINDING (AP-F8-1 class); re-gated on the amended stream with this harness below.
|
||||
|
||||
### (d) Exhaustion count on the frozen class v5 tip, 10^5 chain-shaped seeds (1c420786; the 0.3.24 gate line)
|
||||
|
||||
Run: igneum-pow class-v5 1c420786 (pairing e5a4ac5978462156, the harness draws through `Epoch::chain_program` with the
|
||||
era-composed class, `--chain`, the dn3 state leaves), build-1, ten chunks of 10,000 seeds under `lease pool 4` (chunks 1,
|
||||
3 and 5 to 9 under class v5, chunks 0, 2 and 4 re-leased under class release on the coordinator's order), the binary
|
||||
copied into `frozen-1c420786-f9/bin`, 14,477 to 14,480 s per chunk (about 1.45 s per seed), last chunk written
|
||||
02:34:54 UTC on 8 October 2026 (`par0.tsv` to `par9.tsv`, `par0.log`, `par2.log`, `par4.log`). The interim line at
|
||||
00:55 UTC (seeds drawn to that minute, 0 exhausted, 0 panics, max 30) cleared the 0.3.24 move; this is the record line.
|
||||
|
||||
| Quantity | 100,000 seeds |
|
||||
|---|---|
|
||||
| Seeds drawn | 100,000 of 100,000 |
|
||||
| Exhausted (the 256-attempt cap reached, or the deterministic last resort used) | 0 |
|
||||
| Panics on the draw path (caught and counted) | 0 |
|
||||
| Past attempt index 31 | 0 |
|
||||
| Max attempt index | 30 (one seed) |
|
||||
| First-draw acceptance (index 0) | 31,454 (0.3145) |
|
||||
| Mean attempt index (draws per seed) | 2.185 (3.185) |
|
||||
| Index 8 or above | 4,862 (4.86 percent) |
|
||||
| Index 16 or above | 255 (0.255 percent) |
|
||||
|
||||
Histogram by attempt index: 0: 31,454; 1: 21,460; 2: 14,660; 3: 10,263; 4: 7,047; 5: 4,701; 6: 3,297; 7: 2,256;
|
||||
8: 1,532; 9: 1,027; 10: 702; 11: 509; 12: 365; 13: 216; 14: 153; 15: 103; 16: 80; 17: 56; 18: 39; 19: 20; 20: 24;
|
||||
21: 9; 22: 6; 23: 9; 24: 3; 25: 4; 26: 2; 27: 1; 29: 1; 30: 1. The tail is geometric at a ratio of about 0.69 per
|
||||
index (the per-draw rejection rate under (a'), (c'), (c'') and (c''') together), so the chance of reaching the cap at
|
||||
256 is far below the count; the observed bound is under 3e-5 per seed at 95 percent (0 of 10^5).
|
||||
|
||||
Verdict: PASS. Consequences per tier: no epoch seed in 10^5 fails to draw, so the AP-F8-2 liveness halt (a stuck
|
||||
epoch for a node operator, a dead epoch for a miner, a paused chain for a holder) has no observed case on the frozen
|
||||
tip; the draw costs every node about 3.2 candidates per epoch, which at about 1.45 s per seed on one box core is under
|
||||
five seconds of CPU per epoch and does not change any tier's cost.
|
||||
|
|
|
|||
Loading…
Reference in a new issue