adv-mixer-2: report closed: redraw 2^28, final ledger and bound
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
3b0928d42b
commit
4aca40071a
3 changed files with 173 additions and 11 deletions
|
|
@ -2,3 +2,159 @@
|
|||
lease: holding 16 pool cores (24,25,26,27,28,29,30,31,76,77,78,79,80,81,82,83, waited 0 s, class adv): adv-mixer-2 redraw-2p28-206
|
||||
adv-mixer-2 redraw-census --from 20729 --count 2^28 --threads 16 --max-cost 206 | internal adversarial pass, not an independent review | class v4 x8, 72 applications per item | median cost A for gains 226
|
||||
|
||||
redraw-census: rule = redraw while cost A < 206 or model C k >= 1 or ROT all equal; 268435456 days from 20729, 117.7 s
|
||||
|
||||
| Redraws needed | Days | Fraction |
|
||||
|---|---|---|
|
||||
| 0 | 268274111 | 9.994e-1 |
|
||||
| 1 | 161258 | 6.007e-4 |
|
||||
| 2 | 87 | 3.241e-7 |
|
||||
|
||||
## After the redraw rule: 268435456 days from 20729
|
||||
|
||||
| Class | Count | Fraction | log2 | Worst day: cost A, gain A, date |
|
||||
|---|---|---|---|---|
|
||||
| ROT all equal | 0 | 0.000e0 | -inf | none |
|
||||
| ROT distinct <= 2 | 32 | 1.192e-7 | -23.0 | day 190301293: 217, 1.0415x, 522997-03-30 |
|
||||
| ROT distinct <= 3 | 8228 | 3.065e-5 | -15.0 | day 39816193: 206, 1.0971x, 110983-01-13 |
|
||||
| ROT distinct <= 4 | 412704 | 1.537e-3 | -9.3 | day 804699: 206, 1.0971x, 4173-03-11 |
|
||||
| ROT max multiplicity >= 4 | 568390 | 2.117e-3 | -8.9 | day 74772: 206, 1.0971x, 2174-09-20 |
|
||||
| ROT same-word pair sums to 32 | 32997376 | 1.229e-1 | -3.0 | day 94648: 206, 1.0971x, 2229-02-20 |
|
||||
| ROT two same-word pairs sum to 32 | 1605553 | 5.981e-3 | -7.4 | day 170878: 206, 1.0971x, 2437-11-06 |
|
||||
| ROT any pair sums to 32 | 160353991 | 5.974e-1 | -0.7 | day 27016: 206, 1.0971x, 2043-12-20 |
|
||||
| ROT >= 4 in {1,31} | 263318 | 9.809e-4 | -10.0 | day 311263: 206, 1.0971x, 2822-03-18 |
|
||||
| ROT all 8 in {1,2,30,31} | 19 | 7.078e-8 | -23.8 | day 14330190: 213, 1.0610x, 41204-09-23 |
|
||||
| ROT >= 4 in {8,16,24} | 1196366 | 4.457e-3 | -7.8 | day 274689: 206, 1.0971x, 2722-01-28 |
|
||||
| ROT column set == diagonal set | 6268 | 2.335e-5 | -15.4 | day 201591174: 206, 1.0971x, 553907-11-22 |
|
||||
| MUL any = 1 | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any = 2^32-1 | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any involution (x^2 = 1) | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any w32 <= 2 | 0 | 0.000e0 | -inf | none |
|
||||
| MUL any w32 <= 3 | 703 | 2.619e-6 | -18.5 | day 69746502: 206, 1.0971x, 192929-06-09 |
|
||||
| MUL any w32 <= 4 | 95903 | 3.573e-4 | -11.5 | day 498141: 206, 1.0971x, 3333-11-12 |
|
||||
| MUL >= 2 with w32 <= 4 | 17 | 6.333e-8 | -23.9 | day 256974098: 207, 1.0918x, 705541-03-09 |
|
||||
| MUL any popcount <= 4 or >= 28 | 80023 | 2.981e-4 | -11.7 | day 321675: 206, 1.0971x, 2850-09-19 |
|
||||
| MUL two equal | 18 | 6.706e-8 | -23.8 | day 256306190: 219, 1.0320x, 703712-07-07 |
|
||||
| MUL two inverse (a*b = 1) | 11 | 4.098e-8 | -24.5 | day 197091944: 216, 1.0463x, 541589-06-01 |
|
||||
| MUL any in exact 2-adder set (model C k >= 1) | 0 | 0.000e0 | -inf | none |
|
||||
| MUL model C k >= 2 | 0 | 0.000e0 | -inf | none |
|
||||
| RC any = 0 | 1 | 3.725e-9 | -28.0 | day 109542046: 234, 0.9658x, 301885-12-08 |
|
||||
| RC any popcount <= 4 or >= 28 | 82815 | 3.085e-4 | -11.7 | day 21562119: 206, 1.0971x, 61005-01-29 |
|
||||
| RC + rk = 0 for any of the 72 keys | 87 | 3.241e-7 | -21.6 | day 3194363: 212, 1.0660x, 10715-11-15 |
|
||||
| RC two equal | 8 | 2.980e-8 | -25.0 | day 249730909: 218, 1.0367x, 685710-01-03 |
|
||||
| RC[i] + rk = RC[j] + rk' for some i != j, two of the 72 keys | 1068 | 3.979e-6 | -17.9 | day 60488491: 206, 1.0971x, 167581-11-12 |
|
||||
| cost A gain >= 1.1x | 0 | 0.000e0 | -inf | none |
|
||||
| cost A gain >= 1.2x | 0 | 0.000e0 | -inf | none |
|
||||
| cost A gain >= 1.5x | 0 | 0.000e0 | -inf | none |
|
||||
|
||||
| Cost A statistic | Value |
|
||||
|---|---|
|
||||
| mean | 225.791 |
|
||||
| median (this census) | 226 |
|
||||
| median used for gains | 226 |
|
||||
| min | 206 (gain 1.0971x) |
|
||||
| max | 258 |
|
||||
| days with gain A >= 1.05x (cost <= 215) | 12517683 (4.663e-2, log2 -4.4) |
|
||||
| days with gain A >= 1.1x (cost <= 205) | 0 (0.000e0, log2 -inf) |
|
||||
| days with gain A >= 1.2x (cost <= 188) | 0 (0.000e0, log2 -inf) |
|
||||
| days with gain A >= 1.5x (cost <= 150) | 0 (0.000e0, log2 -inf) |
|
||||
| days with gain A >= 2x (cost <= 113) | 0 (0.000e0, log2 -inf) |
|
||||
|
||||
| Model C k | Days |
|
||||
|---|---|
|
||||
| 0 (gain 1.0000x) | 268435456 |
|
||||
|
||||
| w32 per word | Count | Fraction |
|
||||
|---|---|---|
|
||||
| 3 | 703 | 1.637e-7 |
|
||||
| 4 | 95217 | 2.217e-5 |
|
||||
| 5 | 1032192 | 2.403e-4 |
|
||||
| 6 | 7568223 | 1.762e-3 |
|
||||
| 7 | 39772502 | 9.260e-3 |
|
||||
| 8 | 151123534 | 3.519e-2 |
|
||||
| 9 | 414500552 | 9.651e-2 |
|
||||
| 10 | 810154189 | 1.886e-1 |
|
||||
| 11 | 1100851475 | 2.563e-1 |
|
||||
| 12 | 997943944 | 2.324e-1 |
|
||||
| 13 | 565113139 | 1.316e-1 |
|
||||
| 14 | 179459264 | 4.178e-2 |
|
||||
| 15 | 26236719 | 6.109e-3 |
|
||||
| 16 | 1115643 | 2.598e-4 |
|
||||
|
||||
| Cost A | Days |
|
||||
|---|---|
|
||||
| 206 | 109302 |
|
||||
| 207 | 178706 |
|
||||
| 208 | 282379 |
|
||||
| 209 | 437883 |
|
||||
| 210 | 664947 |
|
||||
| 211 | 983455 |
|
||||
| 212 | 1419889 |
|
||||
| 213 | 2002232 |
|
||||
| 214 | 2751340 |
|
||||
| 215 | 3687550 |
|
||||
| 216 | 4827857 |
|
||||
| 217 | 6164783 |
|
||||
| 218 | 7673378 |
|
||||
| 219 | 9323930 |
|
||||
| 220 | 11027714 |
|
||||
| 221 | 12728598 |
|
||||
| 222 | 14301838 |
|
||||
| 223 | 15661992 |
|
||||
| 224 | 16714435 |
|
||||
| 225 | 17375179 |
|
||||
| 226 | 17567938 |
|
||||
| 227 | 17314369 |
|
||||
| 228 | 16593465 |
|
||||
| 229 | 15474154 |
|
||||
| 230 | 14047779 |
|
||||
| 231 | 12396831 |
|
||||
| 232 | 10632307 |
|
||||
| 233 | 8866419 |
|
||||
| 234 | 7183682 |
|
||||
| 235 | 5652425 |
|
||||
| 236 | 4319616 |
|
||||
| 237 | 3203594 |
|
||||
| 238 | 2308900 |
|
||||
| 239 | 1615334 |
|
||||
| 240 | 1094861 |
|
||||
| 241 | 720625 |
|
||||
| 242 | 459556 |
|
||||
| 243 | 283034 |
|
||||
| 244 | 169462 |
|
||||
| 245 | 98197 |
|
||||
| 246 | 55263 |
|
||||
| 247 | 29708 |
|
||||
| 248 | 15363 |
|
||||
| 249 | 7928 |
|
||||
| 250 | 3949 |
|
||||
| 251 | 1785 |
|
||||
| 252 | 853 |
|
||||
| 253 | 386 |
|
||||
| 254 | 172 |
|
||||
| 255 | 61 |
|
||||
| 256 | 38 |
|
||||
| 257 | 12 |
|
||||
| 258 | 3 |
|
||||
|
||||
Lowest-cost days (cost A, day, date, gain A):
|
||||
206 27016 2043-12-20 1.0971x
|
||||
206 43428 2088-11-25 1.0971x
|
||||
206 51241 2110-04-18 1.0971x
|
||||
206 53114 2115-06-04 1.0971x
|
||||
206 62837 2142-01-16 1.0971x
|
||||
206 63489 2143-10-30 1.0971x
|
||||
206 68173 2156-08-26 1.0971x
|
||||
206 68393 2157-04-03 1.0971x
|
||||
206 69945 2161-07-03 1.0971x
|
||||
206 73231 2170-07-02 1.0971x
|
||||
206 74772 2174-09-20 1.0971x
|
||||
206 75398 2176-06-07 1.0971x
|
||||
206 84603 2201-08-21 1.0971x
|
||||
206 85594 2204-05-08 1.0971x
|
||||
206 86393 2206-07-16 1.0971x
|
||||
206 92181 2222-05-21 1.0971x
|
||||
|
||||
Terminated
|
||||
lease: released 16 pool cores after 118 s, exit 0
|
||||
2026-10-07T22:36:12Z end redraw-2p28-206 rc=0
|
||||
|
|
|
|||
|
|
@ -56,7 +56,7 @@ take even if it buys no hash rate against the chip model's attacker. The worst r
|
|||
| Q5 cross-day structure | seed collisions, stream shifts by k in 1..72, shared MUL and RC values over the calendar | planted shift pair (found) | counts against expectation | 64-bit seed collisions 0 (expected 3.6e-11); stream shifts 0 (expected 5.2e-9); MUL values shared between two days 77 (expected 79.5), RC 39 (39.8): chance, and a shared constant hands a datapath nothing (the other 39 draws differ) | PASS (BOUND: nothing beyond chance) |
|
||||
| Q2 model B | `scm-refine` on the calendar (36,525 days), on the lowest 2^14 days of the 2^24 census, on a 2^16-day random sample | the self-test constants (3, 5, 7, 9, 2^32 - 1, 2^31 + 1 at 1 adder; 45 at 2): all as expected | the certified-cost distribution | exact sets: 90 constants at 1 adder, 4,101 at 2, 185,223 at 3, 7,983,205 at 4 (0.38 percent of odd constants at 4 or fewer under the restricted form); random words certified at 5 or fewer: 12.3 percent; the rest uncertified. Cost B is a PARTIAL metric (a certified word costs 5, an uncertified one w32 - 1), so its between-day spread (sample: mean 219, min 176; calendar worst day 43959 = 2090-05-10 at B 181) is the certificate's selectivity, not a measured gain, and is not read as one | PARTIAL (bound on the per-word chain length only) |
|
||||
| Q6 ROT diffusion | `avalanche` (1, 2, 3, 4, 8 applications; the 22 address bits; 1,024 states x 512 input bits) on the genesis day, the plants, the 7 worst ROT days of the census | plant rot1 and weakday must read weaker than the genesis day at 1 application: they do (mean flip 0.345 and 0.324 against 0.461; 16,197 and 11,454 input-output pairs never flipped against 5,534) | a per-day gain only if a bit-exact shortcut follows | at 2 applications every day, planted days included, reads mean 0.500, every output bit between 0.42 and 0.58 (sampling spread of 1,024 states), address bits 0.500, no pair unflipped; 8 applications sit between reads. No day gives a shortcut; gain 0 | PASS (BOUND) |
|
||||
| Q7 redraw rule | `redraw-census` 2^24 and 2^28 days with the rule below | `--max-cost 0` must reproduce the real draw on 1,000 days (asserted in the binary; passed) | fraction redrawn; residual over 1.1x must be 0 | 2^24 days: 10,014 redrawn once (5.97e-4), 7 twice (4.2e-7), none three times; after the rule gain A >= 1.1x on 0 days (min cost 206, 1.097x), model C k = 0 on every day, ROT all equal 0; mean cost 225.79 (225.78 before), the 1.05x fraction 4.67e-2 (4.72e-2 before): the rule touches only the tail. 2^28 run PENDING | FINDING closed by the rule (after-fraction 0 on 2^24) |
|
||||
| Q7 redraw rule | `redraw-census` 2^24 and 2^28 days with the rule below | `--max-cost 0` must reproduce the real draw on 1,000 days (asserted in the binary; passed) | fraction redrawn; residual over 1.1x must be 0 | 2^24 days: 10,014 redrawn once (5.97e-4), 7 twice (4.2e-7), none three times; after the rule gain A >= 1.1x on 0 days (min cost 206, 1.097x), model C k = 0 on every day, ROT all equal 0; mean cost 225.79 (225.78 before), the 1.05x fraction 4.67e-2 (4.72e-2 before): the rule touches only the tail. 2^28 days: 161,258 redrawn once (6.01e-4), 87 twice (3.2e-7), 0 three times; after the rule 0 days over 1.1x, min cost 206 | FINDING closed by the rule (after-fraction 0 on 2^24 and 2^28) |
|
||||
| Q8 anything else | watched while the rows ran; three observations, no box time | n/a | stated or measured | (1) Lead time: the only per-day attacker is an FPGA bitstream synthesised for the day, and synthesis of a full-device design takes hours (approximate, from memory; no figure measured here). Under the interim day rule (`bind::day_bytes`, a pure function of the calendar) the attacker has unlimited lead; under the spec's own proposal O-1.10 (day bytes carry the first epoch seed of the day, known about 20 minutes ahead, section 1.12) a per-day bitstream cannot be ready in time, which removes the whole class without a redraw. (2) The mixer stream is seeded by 64 bits of the day key (K[0], K[1]); K[2..7] enter only the item init; no collision or shift was found in 100 years or 2^24 days, and the planted shift was. (3) The 72 round keys are fixed multiples of 0x9E3779B9; RC + rk = 0 happened on 10 of 2^24 days (expected 4.5, within Poisson) and costs a datapath nothing on either side | PASS (stated) |
|
||||
| GPU rows | none needed | | | no row of this class depends on a GPU | BLOCKED (not applicable) |
|
||||
|
||||
|
|
@ -71,7 +71,7 @@ once a day; nothing else changes; every accepted day is a day the current rule c
|
|||
| Quantity | Value |
|
||||
|---|---|
|
||||
| Fraction of days redrawn at least once | exact 5.694e-4 + 3.123e-5 = 6.0e-4 (2^-10.7), about 22 days per 100 years; measured over 2^24 days 5.97e-4 once, 4.2e-7 twice, never three times |
|
||||
| Fraction over 1.1x under model A after the rule | 0 measured over 2^24 days (min cost 206, gain 1.097x); 2^28 PENDING. Before the rule, measured: 5.677e-4 (2^24 census), 5.693e-4 (2^32), 4.107e-4 (the 100-year calendar, 15 of 36,525 days) |
|
||||
| Fraction over 1.1x under model A after the rule | 0 measured over 2^24 and over 2^28 days (min cost 206, gain 1.097x). Before the rule, measured: 5.677e-4 (2^24 census), 5.693e-4 (2^32), 4.107e-4 (the 100-year calendar, 15 of 36,525 days) |
|
||||
| Fraction over 1.1x under model C after the rule | 0 (k = 0 on every accepted day) |
|
||||
| Chip-model reading after the rule | unchanged: 1.0 on every day before and after |
|
||||
| What the rule does not fix | the seed is 64 bits of the day key (K[0], K[1]); the day is a pure function of the calendar; both stand; neither is a weakness of this class on the numbers above |
|
||||
|
|
@ -329,8 +329,8 @@ self-check inside the binary (`--max-cost 0` on 1,000 days reproduces `MixParams
|
|||
|
||||
| Quantity | Before the rule (2^24 census) | After the rule (2^24 days) |
|
||||
|---|---|---|
|
||||
| days redrawn once / twice / three times | | 10,014 (5.97e-4) / 7 (4.2e-7) / 0 |
|
||||
| gain A >= 1.1x | 9,525 (5.68e-4) | 0 |
|
||||
| days redrawn once / twice / three times | | 10,014 (5.97e-4) / 7 (4.2e-7) / 0; over 2^28 days: 161,258 (6.01e-4) / 87 (3.2e-7) / 0 |
|
||||
| gain A >= 1.1x | 9,525 (5.68e-4) | 0 (and 0 over 2^28) |
|
||||
| gain A >= 1.05x | 792,234 (4.72e-2) | 782,984 (4.67e-2) |
|
||||
| min cost A | 191 (1.183x) | 206 (1.097x) |
|
||||
| mean cost A | 225.780 | 225.792 |
|
||||
|
|
@ -338,7 +338,7 @@ self-check inside the binary (`--max-cost 0` on 1,000 days reproduces `MixParams
|
|||
| ROT all equal | 0 | 0 |
|
||||
|
||||
Cost to the honest side: forty more SplitMix64 draws on 6e-4 of days, once a day; the verifier and every miner
|
||||
compute the same rule from the same key. The 2^28 run (queue 07, second line) lands below when the lease serves it.
|
||||
compute the same rule from the same key. The 2^28 run (same lease, 117.7 s on 16 cores, log redraw-2p28-206.log) reads the same: 0 days over 1.1x after the rule, mean cost 225.791, the 1.05x fraction 4.66e-2.
|
||||
|
||||
### Ledger of rule changes during the run (box-hours stay honest)
|
||||
|
||||
|
|
@ -359,13 +359,19 @@ compute the same rule from the same key. The 2^28 run (queue 07, second line) la
|
|||
| 21:42 to 21:53 | queue 06 census 2^32 on box 1, 32 cores, held 616 s (615 s compute; the lease line's "1480 s" counts from the 21:28 submission, 864 s of it waiting) | 0.17 box-hours (32 cores x 616 s / 96) |
|
||||
| 21:53 | queue 07 redraw-census submitted on box 1; a waiter at class adv behind the v5 gate's leases (correct: it holds nothing) | |
|
||||
| 22:21 | pre-emption at any size for adv holders once a release or v5 waiter has waited 120 s (lease ce30e357) | nothing of mine held cores; noted |
|
||||
| 23:32 | queue 07 served: 16 cores, redraw 2^24 in 8.3 s; the 2^28 line follows on the same lease | 0.02 box-hours so far |
|
||||
| 23:32 to 23:36 | queue 07 served: 16 cores, redraw 2^24 in 8.3 s and 2^28 in 117.7 s; chain ended, nothing of this lane left on either box | 0.02 box-hours |
|
||||
|
||||
Box-hours spent so far: 0.31 (the smoke runs, queue 01 to 07's first line and the stopped 03), counted as cores held x seconds / 96. The redraw census over 2^28 days runs on box 1 on 16 cores. Pod-hours: 0. GPU: none.
|
||||
Box-hours spent: 0.31 in all (the smoke runs, queue 01 to 07 and the stopped 03), counted as cores held x seconds / 96. Pod-hours 0. GPU none. Nothing is running at the close (23:36 UK, 7 October 2026). Pod-hours: 0. GPU: none.
|
||||
|
||||
## Bound reached, honestly
|
||||
|
||||
Exact for model A and model C over the whole draw space (every odd constant counted, not sampled); the census rows,
|
||||
the real-calendar worst day, model B and the diffusion numbers are pending the lease pool. A longer pass would add
|
||||
model B certificates past 5 adders (an exact optimal-SCM table for all 2^31 constants) and a census over 2^36 days
|
||||
for the model A tail below 2^-28; neither changes the crossing above, which is exact.
|
||||
Exact for model A and model C over the whole draw space (every odd constant counted, not sampled), confirmed by
|
||||
censuses over 2^24 and 2^32 consecutive chain days and the 100-year calendar; model B bounds the per-word chain
|
||||
length from above for 12 percent of words and is not read as a gain; diffusion is uniform by 2 of the 8
|
||||
applications between reads on every day tried, the planted ones included; the redraw rule's after-fraction is 0 on
|
||||
2^24 and 2^28 days. The verdict of this lane: BOUND for every chip, GPU and the verifier (gain 1.0 on every day,
|
||||
the chip-model reading); FINDING on the per-day FPGA LUT-area reading only, 2^-10.8 of days over 1.1x, closed by
|
||||
the redraw rule, or by the spec's O-1.10 day derivation. One line on what a longer pass would add: an exact
|
||||
optimal-SCM table for all 2^31 odd constants (an exhaustive adder-graph search, hours on a box) to replace models A
|
||||
and B with the synthesiser's true per-day cost, and a 2^36-day census for the 1.2x tail; neither moves the crossing,
|
||||
which is exact.
|
||||
|
|
|
|||
Loading…
Reference in a new issue