diff --git a/docs/analysis/cryptanalysis/report-acceptance-rule.md b/docs/analysis/cryptanalysis/report-acceptance-rule.md index 329c0eed6..23e497ff6 100644 --- a/docs/analysis/cryptanalysis/report-acceptance-rule.md +++ b/docs/analysis/cryptanalysis/report-acceptance-rule.md @@ -34,7 +34,7 @@ check is owed once I copy its program.json read-only from build-1. | Q | Method | Known-failed shape (must fire) | Gate | Result | Status | |---|---|---|---|---|---| -| Q1 | Steering/hot set: the chain's class v4 draw over the F8 label space (shards of 100k seeds; 19:27 BST to 19:4x BST under the SIGSTOP yield, since 19:4x BST nice 10 on cores 8-95, no yield), the stand-in per-site ratio at 256 units as the proxy, the live hot set by the unmodified f8 harness (adv-live) on the lowest-ratio seeds and on a consecutive-seed census | adv-live const-item plant FLAGGED (21.8x, X_1% +6.49); clean control 0.9996x PASS | X_f >= f flags a hot set; gain = implied on-die SRAM copy size | 23,319 accepted programs drawn; seed 100767 flags the hot-set test at 2^24 nonces (X_0.1% +0.155%, 2.05x) under class v4 AND under class v5 with the state leaves (+0.155%, 2.05x, the same eight hot items); 12 lowest stand-in-ratio seeds live: 5 beyond the f8 1.2x gate, 7 within; 11 random: 1 beyond; hot set 1 of 22 at 2^24; gain 1.002x (1 MB copy serves 0.31% of loads) | FINDING, bounded: a program-dataflow distinguisher (site 6, a near-zero source under the 1% (c') limit) that survives the class v5 dataset; not an exploitable bypass; the 256-unit selector is weak (7 of 12 false positives); shards and 23 live rows re-queued in the lease pool | +| Q1 | Steering/hot set: the chain's class v4 draw over the F8 label space (shards of 100k seeds; 19:27 BST to 19:4x BST under the SIGSTOP yield, since 19:4x BST nice 10 on cores 8-95, no yield), the stand-in per-site ratio at 256 units as the proxy, the live hot set by the unmodified f8 harness (adv-live) on the lowest-ratio seeds and on a consecutive-seed census | adv-live const-item plant FLAGGED (21.8x, X_1% +6.49); clean control 0.9996x PASS | X_f >= f flags a hot set; gain = implied on-die SRAM copy size | 29,032 accepted programs drawn; three pass the rule and flag the f8 hot-set test at 2^24 nonces (100767 X_0.1% +0.155% 2.05x, 4346 +0.178% 2.24x, 5245 +0.129% 1.86x), 100767 also under the class v5 dataset (+0.155%, the same hot items); 16 lowest stand-in-ratio seeds live: 9 beyond the f8 1.2x gate, 3 hot sets; 17 random: 1 beyond, 0 hot sets; each hot set is 1 MB of items holding 0.28 to 0.33% of reads: gain 1.002x | FINDING, bounded: a program-dataflow distinguisher (site 6, a near-zero source under the 1% (c') limit) that survives the class v5 dataset; not an exploitable bypass; the 256-unit selector is weak (7 of 12 false positives); shards and 23 live rows re-queued in the lease pool | | Q2 | Stand-in gap: a validated mirror runs the rule's own units on the closed form and on the live dataset; per-site ratio at 2^20 and the (c) metrics compared | zero-dataset plant: live 0.9733 REJECT against closed accept (fired) | any false accept that reads a hot set on the live set | 54 programs: max per-site gap 0.0004 (the 2^20 sampling noise), mean min-ratio gap 0.00002, 0 verdict disagreements, (c) metrics agree to 0.019 of 128 | BOUND | | Q3 | Handed to lane adv-accept-3 (unspawned); row 90 (exhaustion census: per-part rejections, cap, last resort) claimed by this lane, owner adv-accept-3 | forced-exhaust plant must hit the cap and print the last-resort program | P(exhaust) bounded; last resort characterised | attempts census over 20k seeds RUNNING (box 2); plant RUNNING | RUNNING (owner adv-accept-3, unspawned) | | Q4 | Handed to lane adv-accept-2 | | | | HANDED OVER | @@ -330,6 +330,28 @@ sweep's ratio column already locates (rows under 0.9810 at 256 units, then a 2^2 | 106474 | 0.9960 | 0.9996x within | -0.000% (0.00) | clear | | 4765 | 0.9960 | 1.020x within | +0.003% (0.03) | clear | | 106700 | 0.9960 | 1.0006x within | +0.000% (0.00) | clear | +| 4346 | 0.9968 | 2.241x BEYOND | +0.178% (1.78) | HOT SET | +| 5245 | 0.9970 | 1.857x BEYOND | +0.129% (1.29) | HOT SET | +| 101905 | 0.9973 | 1.336x BEYOND | +0.050% (0.50) | clear | +| 1605 | 0.9976 | 1.367x BEYOND | +0.054% (0.54) | clear | + +Reading at 21:1x BST (the re-submitted chain's first four, build-1, 2^24 nonces, --diag 1): two more hot sets. +The lowest-16 live set now reads 9 beyond the f8 gate of 16 (56 percent) and 3 hot sets by X_f >= f (100767, +4346, 5245) against 1 beyond of 17 random and 0 hot sets; the hot-set rate among the stand-in tail is 3 of 16 +against 0 of 17. Seed 4346's excess (+0.178 percent at f = 0.1 percent) is the largest seen: still a 1 MB +item set holding about 0.33 percent of reads, gain about 1.002x. The distinguisher is real and repeatable; +its price does not move. + +Attribution of the two new hot sets (log live-low14-16m.log, copied to logs/adv-accept/ at the chain's end): + +| Seed, id, attempt | hot items (top 0.1%) and their reads | hottest item and traced source | sites carrying it | +|---|---|---|---| +| 4346, bbb38e847011c354, attempt 2 | 17,103 items, 0.326% of reads | 0x000000 with 97,943 reads (0.0046% of all); site instr 4 reads r4 = zero, last writer mad@1 | site 2 (instr 19, src r1, full window) puts 2.17% of its reads into the hot set; sites 8 and 9 (instrs 44 and 49) 0.67% each; largest saturated-source share 0.044% at site 2 | +| 5245, beaad44840bb9e4e, attempt 5 | 16,899 items, 0.281% of reads | 0x000000 with 47,936 reads (0.0022% of all); site instr 7 reads r2 = zero, last writer load@6 | site 8 (instr 37, src r2, quarter window) puts 3.36% of its reads into the hot set; the top 8 items are again multiples of 2^19 | + +The same mechanism each time: one load site whose source register reaches zero (or a value near zero or +all-ones) in a few hundredths of a percent of evaluations, under the (c') 1 percent limit, with the era +stride mapping those values to a fixed item set; item 0x000000 is the hottest in all three programs. | 1352 (random) | 0.9999 | 1.057x within | +0.009% | clear | | 100521 (random) | 0.9999 | 1.153x within | +0.025% (0.25) | clear | | 106359 (random) | 0.9999 | 1.0001x within | +0.000% | clear |