From 635efc0d37af825862638b5153eedb98cc2db315 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 14:22:42 +0000 Subject: [PATCH] attack-pass F8: sub-version 2 re-gate verdict FAIL (9 of 64, worst 4.82x), the per-seed table and the clean per-site spread; sub-version 3 is the target Co-Authored-By: Claude Fable 5.1 --- docs/analysis/attack-pass-2026-10.md | 28 +++++++++++++++++++++++++--- 1 file changed, 25 insertions(+), 3 deletions(-) diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index 02b5b284a..0e7192931 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -28,7 +28,7 @@ against the log before quoting it to the project lead. | F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x at k=1 GDDR7 reproduces, 3.2x at k=0.5, 4.1x at k=0.3 (matches ledger M32); FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). FINDING: the k=0.33 figure is framed as the X9's measured core (M32) and a "measured class" (ladder branch ยง5a); the X9 was withdrawn before launch and never benchmarked. F2 hour SKIPPED: no AWS account | FIXED-AND-PASSED (sweep PASS; AP-F5-1 fixed and re-gated 7 Oct 2026: chip section re-run 2.1x at k=1 unchanged, identity grep 0 hits, site lane concurred); F2 hour SKIPPED-BY-DECISION (the project lead, 7 Oct 2026, 09:5x UK; plan 4.2 row F5 is the sweep only at 3714c2a0; the FPGA row stays the JEDEC-ceiling model row labelled unmeasured) | | F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | 100,000 programs ranked, 50,000 timed cold one-core (worst 6.194 ms), the worst 200 re-timed and the worst 1,000 timed on the half-core proxy under the per-core lease (core 40 at 3,799.9 MHz): worst 8.708 ms (`attack-f6/87142`), 1.29 ms under the gate, every half-core reading under 9 ms; dr736 fails as it must (15.49). O-1.14 CLOSED on an i7-9700K (v4 6.334 ms cold max, dr736 10.04 fails). Ladder ceiling from the worst program on the half-core proxy: N about 300,000, so rung 2 admissible, rung 3 not. Record `docs/analysis/attack-pass/f6-verifier.md` | PASS | | F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | (b) census PASS at 2^24 seeds: no class over 1.1x, stride bijective on all draws, R, pos and M uniform (chi-square 38.5 on 30 dof), op-weight corners 1.0x, planted cases fire; (c) 64-bit day-key seeding PASS as the spec intends, 0 collisions in 2^17; (a) re-roll harness INCOMPLETE by the plan's allowance: the node's era seed is a plain chain block hash (`seed_below`), the cut is grindable with one block of hash at no delay (1 of 6 epochs) and immune past one block interval (0 of 6), and the 1-hour VDF of spec 4.4 is not in the node; the era-VDF lane builds it with `reroll.mjs` as its gate. Record `docs/analysis/attack-pass/f7-era.md`; the harness's three devnet-980 nodes stopped by pid at 12:1x UK | PASS (b, c); INCOMPLETE (a) pending the era VDF, a freeze precondition | -| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model | line index PASS at 2^28. Phase E (6 Oct stream): 31 of 64 seeds over 1.2x, the lossy load-source class, AP-F8-1. Re-gate on sub-version 1 (8c728ca3, 0.3.20): 11 of 64 over 1.2x, worst 29.27x (p31), a constant delivered through an admitted writer or across the iteration boundary; three residual classes named; sub-version 2 (freshness fixpoint + dynamic source count) is the fix. F9's harness retired from the re-gate (counts the windows) | FINDING; sub-version 1 FAILS 11 of 64; re-gate on sub-version 2 pending | +| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model | line index PASS at 2^28. Phase E (6 Oct stream): 31 of 64 seeds over 1.2x, the lossy load-source class, AP-F8-1. Re-gate on sub-version 1 (8c728ca3, 0.3.20): 11 of 64 over 1.2x, worst 29.27x (p31), a constant delivered through an admitted writer or across the iteration boundary; three residual classes named; sub-version 2 (freshness fixpoint + dynamic source count) is the fix. F9's harness retired from the re-gate (counts the windows) | FINDING; sub-version 1 FAILS 11 of 64, sub-version 2 FAILS 9 of 64 (worst 4.82x; one low-entropy site per program, lineage-blind, the acceptance never ran the shadow: AP-F8-3); AP-F8-2 exhaustion FIXED-AND-PASSED at 8bdcbdd8; sub-version 3 is the target | | F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | (a) edges on generator 4 over 10^5 seeds: 34 disagreements in 105,064 candidates (29 const_bit, 4 bias, 1 lane_const), every one a one-bit or sampling-noise property moving the choice to an attempt both stand-ins accept, nothing in the attacker's favour: PASS; (b) hot-set search over 10^6 seeds: 11,696 passing programs (1.17%) concentrate 1% or more of reads on a hot set, worst 17.3%: FINDING, the same or-saturation load-source class as AP-F8-1 found by a second harness (F9-1 merged into AP-F8-1), re-gated on the amended stream; (c) grinding on the 5090: +0.004% at K = 2^14, ceiling +43%: PASS. Record `docs/analysis/attack-pass/f9-grind.md` | (a) PASS; (b) FINDING = AP-F8-1 class (10^6 seeds on the 6 Oct stream); the harness is retired from the re-gate (its metric counts the era's windows), F8's census re-gates; (c) PASS | | F10 | Ladder signal monotonicity harness | no step without 90% over 7 windows in either direction | known-fail fails, known pass passes; new cases on the exact-share driver: 89% up holds (no step), 89 then 90% down with restarts steps only at 90% after the 7-window cool-down, the floor holds under 100% down (never below rung 0); decision per seed block memoised, identical after a restart, never differs between nodes; 19 of 19 checks per case. Two items to main, not findings: a stale commit string in the ladder lane's igneumd, and proof-synced nodes deciding rung 0 until the witness lands (a precondition line for spec 01). Record `docs/analysis/attack-pass/f10-ladder.md` | PASS | @@ -433,8 +433,30 @@ rejected below a threshold set from the clean seeds' spread (expected near 0.95 spread from the 53 clean sub-version 1 seeds' by-site entropy); the structural alternative (an abstract value class tracking "r6 holds r4's bits") catches this idiom and nothing it does not know. Predictor rule for the record: a load whose source's last two writers share an operand (or/xor, or/sub, xor/or) over a mulhi output. -Status: FINDING-OPEN; sub-version 1 FAILS the re-gate (11 of 64); sub-version 2 FAILS it at 8 of 39 and counting; -FIXED-AND-PASSED on the 64-seed verdict against the stream that carries the two further changes. +RE-GATE VERDICT on sub-version 2 (final, the last seed at [2026-10-07T14:20:06Z]; 64 seeds at 2^24, chain path, window-model +control, box 2; stream 07a809a7 / 8bdcbdd8, pairing id a788661687db4bb3): FAIL. 55 of 64 under 1.2x (0.9915x to +1.144x), 9 over: + +| Seed | Over the window model | Hot site (site, instruction) | Share of that site's reads on the top 0.1 percent | Bucket entropy of uniform | Predicted source | +|---|---|---|---|---|---| +| p23 | 4.82x | 7, 38 | 9.43 percent | 0.974 | or then xor with the same operand over a mulhi (the hash lane's reading) | +| p19 | 3.32x | 15, 62 | 6.64 percent | 0.964 | zero through a load (unchanged from sub-version 1) | +| p15 | 2.57x | 2, 12 | 4.49 percent | 0.982 | zero through rotl at 0 | +| p18 | 2.50x | 6, 30 | 5.55 percent | 0.937 | all-ones through a load | +| p56 | 2.01x | 2, 10 | 3.34 percent | 0.994 | unattributed (new over sub-version 1) | +| p10 | 1.50x | 8, 28 | 2.04 percent | 0.979 | unattributed (identical to sub-version 1) | +| p8 | 1.38x | 14, 51 | 1.42 percent | 0.980 | unattributed | +| p34 | 1.25x | 1, 13 | 1.35 percent | 0.997 | one-bit value through sub | +| p4 | 1.22x | 1, 8 | 1.45 percent | 0.981 | unattributed (1.57x on sub-version 1) | + +Every failing seed is one low-entropy load site. Clean-seed spread of the per-site bucket entropy (848 site rows of +sub-version 1's 53 clean seeds): min 0.9865, p1 0.9961, p5 0.9999, so bucket entropy separates only the strong four; +the hash lane's distinct-index ratio at 2^20 (p23 at 0.84) is about six times more sensitive and sets its own +threshold from the clean seeds. Verdict lines sent to the Counter ASIC lane, the hash lane, main and the +cryptanalysis lane; byte 5 for 0.3.21 stands on this evidence. +Status: FINDING-OPEN; sub-version 1 FAILS the re-gate (11 of 64); sub-version 2 FAILS it (9 of 64, worst 4.82x); +FIXED-AND-PASSED on the 64-seed verdict against sub-version 3 (the acceptance executing the shadow block, the +per-site distinct-index ratio rule, the cap and the last resort). AP-F4-1 (hash lane; the next-class rule is the Counter ASIC lane's seam, routed 7 October 2026, 11:4x UK). A bound on the day-key draw, not a weak class: on the M1 metric (every multiply in LUT adders, adders per mixer application