attack-pass F6: PASS, the worst of 10^5 class v4 programs reads 8.708 ms on the half-core proxy (1.29 ms under the gate), batches B and C under the per-core lease
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
d1a9544376
commit
8d633c2ad1
3 changed files with 41 additions and 1 deletions
|
|
@ -26,7 +26,7 @@ against the log before quoting it to the project lead.
|
|||
| F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | 0 of 64 and 0 of 1,024 lines under j+1 (exhaustive closure search, cross-checked by exhaustive pebbling at 10 lines, 10,240 pairs, 0 mismatches); both planted broken chains fire; curve monotone at both op counts; f=1 point 9,360 ops per item unchanged. Record `docs/analysis/attack-pass/f3-cache.md` | PASS |
|
||||
| F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | PASS against M2 (DSP-bound datapath): 0 of 2^28 days over 1.1x; planted weak days fire; every ROT and RC class 0. Bound finding AP-F4-1 on M1 (LUT adders): 5,476 of 2^24 days (3.26e-4) over 1.1x as the tail of a sum, no weak class; worst public-calendar day 29,337 at 1.121x, at most 12.1% more rate that day for a per-day LUT FPGA, 0 for any chip; redraw rule (NAF sum under 163 rejected) routed to the next class. Record `docs/analysis/attack-pass/f4-weakday.md` | PASS (v4); AP-F4-1 routed to the next class |
|
||||
| F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x at k=1 GDDR7 reproduces, 3.2x at k=0.5, 4.1x at k=0.3 (matches ledger M32); FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). FINDING: the k=0.33 figure is framed as the X9's measured core (M32) and a "measured class" (ladder branch §5a); the X9 was withdrawn before launch and never benchmarked. F2 hour SKIPPED: no AWS account | FIXED-AND-PASSED (sweep PASS; AP-F5-1 fixed and re-gated 7 Oct 2026: chip section re-run 2.1x at k=1 unchanged, identity grep 0 hits, site lane concurred); F2 hour SKIPPED-BY-DECISION (the project lead, 7 Oct 2026, 09:5x UK; plan 4.2 row F5 is the sweep only at 3714c2a0; the FPGA row stays the JEDEC-ceiling model row labelled unmeasured) |
|
||||
| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | O-1.14 CLOSED on an i7-9700K (v4 6.006 ms avg, 6.334 cold max; dr736 10.04 fails as it must). Box search: 100,000 programs drawn and ranked, 50,000 timed cold on the one-core proxy (min / median / p99 / max 4.610 / 4.948 / 5.606 / 6.194 ms, `attack-f6/48484`); half-core re-times of the worst (batches B and C) queued, starved of the exclusive hold by back-to-back shared holders (F2's runner now stopped to free it); carried at the genesis ratio the worst would read 10.3 ms, at the additive cost 9.66 ms, so batch C decides | INCOMPLETE (batch C decides; re-armed) |
|
||||
| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | 100,000 programs ranked, 50,000 timed cold one-core (worst 6.194 ms), the worst 200 re-timed and the worst 1,000 timed on the half-core proxy under the per-core lease (core 40 at 3,799.9 MHz): worst 8.708 ms (`attack-f6/87142`), 1.29 ms under the gate, every half-core reading under 9 ms; dr736 fails as it must (15.49). O-1.14 CLOSED on an i7-9700K (v4 6.334 ms cold max, dr736 10.04 fails). Ladder ceiling from the worst program on the half-core proxy: N about 300,000, so rung 2 admissible, rung 3 not. Record `docs/analysis/attack-pass/f6-verifier.md` | PASS |
|
||||
| F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | (b) census PASS at 2^24 seeds: no class over 1.1x, stride bijective on all draws, R, pos and M uniform (chi-square 38.5 on 30 dof), op-weight corners 1.0x, planted cases fire; (c) 64-bit day-key seeding PASS as the spec intends, 0 collisions in 2^17; (a) re-roll harness INCOMPLETE by the plan's allowance: the node's era seed is a plain chain block hash (`seed_below`), the cut is grindable with one block of hash at no delay (1 of 6 epochs) and immune past one block interval (0 of 6), and the 1-hour VDF of spec 4.4 is not in the node; the era-VDF lane builds it with `reroll.mjs` as its gate. Record `docs/analysis/attack-pass/f7-era.md`; the harness's three devnet-980 nodes stopped by pid at 12:1x UK | PASS (b, c); INCOMPLETE (a) pending the era VDF, a freeze precondition |
|
||||
| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model | line index PASS at 2^28. Phase E (6 Oct stream): 31 of 64 seeds over 1.2x, the lossy load-source class, AP-F8-1. Re-gate on sub-version 1 (8c728ca3, 0.3.20): 11 of 64 over 1.2x, worst 29.27x (p31), a constant delivered through an admitted writer or across the iteration boundary; three residual classes named; sub-version 2 (freshness fixpoint + dynamic source count) is the fix. F9's harness retired from the re-gate (counts the windows) | FINDING; sub-version 1 FAILS 11 of 64; re-gate on sub-version 2 pending |
|
||||
| F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | (a) edges on generator 4 over 10^5 seeds: 34 disagreements in 105,064 candidates (29 const_bit, 4 bias, 1 lane_const), every one a one-bit or sampling-noise property moving the choice to an attempt both stand-ins accept, nothing in the attacker's favour: PASS; (b) hot-set search over 10^6 seeds: 11,696 passing programs (1.17%) concentrate 1% or more of reads on a hot set, worst 17.3%: FINDING, the same or-saturation load-source class as AP-F8-1 found by a second harness (F9-1 merged into AP-F8-1), re-gated on the amended stream; (c) grinding on the 5090: +0.004% at K = 2^14, ceiling +43%: PASS. Record `docs/analysis/attack-pass/f9-grind.md` | (a) PASS; (b) FINDING = AP-F8-1 class (10^6 seeds on the 6 Oct stream); the harness is retired from the re-gate (its metric counts the era's windows), F8's census re-gates; (c) PASS |
|
||||
|
|
|
|||
|
|
@ -196,3 +196,34 @@ program reads 10 ms or more on the half-core proxy, the finding goes to main wit
|
|||
proposed fix: an acceptance-rule bound on verifier cost (a per-program cost model over the family counts checked at
|
||||
draw time, a redraw when it exceeds the bound, exactly as rule (c) redraws on bias) and the ladder's ceiling set from
|
||||
the measured worst, not the average; `igneum-pow` is not edited by this lane.
|
||||
|
||||
## Batches B and C landed (7 October 2026, 13:5x UTC, cores 40 and 88 under the per-core lease)
|
||||
|
||||
The measure file was retired at 13:3x UTC and replaced by per-core leases; cores 40 and 88 were leased to this row
|
||||
(`/srv/builds/_bin/lease cores 40,88 --owner attack-pass`), so the batches ran with nothing else on those cores while
|
||||
builds continued on the rest of the box. Core 40's clock (`clock-2b.log`, `clock-2c.log`): median 3,799.9 MHz in both
|
||||
batches, 954 of 958 and 57 of 63 samples at 3.7 GHz or more, the 1.5 GHz readings between runs.
|
||||
|
||||
| Batch | What | Programs | Reps | Worst program | Half-core cold max | Log |
|
||||
|---|---|---|---|---|---|---|
|
||||
| B | the second 50,000 of the one-core pass, then the worst 50 by proxy and the worst 50 by coarse time re-timed cold on both proxies | 200 re-timed | 10 | `attack-f6/87142` | 8.708 ms | `phase2b.log`, done 13:52:11Z |
|
||||
| C | the worst 1,000 by the full one-core pass on the half-core, then the worst 10 at 20 cold reps on both proxies | 1,000 + 10 | 2, then 20 | `attack-f6/88521` (8.629), `attack-f6/15781` (8.414) | 8.629 ms | `phase2c.log`, done 13:57:45Z |
|
||||
|
||||
The one-core worst of the full pass (`attack-f6/48484`, 6.194 ms single warp) does not reach the half-core top ten:
|
||||
its one-core reading was a short disturbance, as the batch C re-scan shows. Every program timed on the half-core
|
||||
proxy reads under 9 ms.
|
||||
|
||||
## Gate line and verdict
|
||||
|
||||
Gate: the worst program under 10 ms cold on the half-core proxy (and on a 2019-class core: O-1.14, the i7-9700K row,
|
||||
class v4 6.334 ms cold max). Result: the worst of 100,000 class v4 programs on the half-core proxy is 8.708 ms,
|
||||
1.29 ms under the gate; the genesis program reads 8.624 on the same proxy, so the worst drawn program costs 1 percent
|
||||
more than the genesis one and the distribution is tight (one-core clean rows 4.610 to 6.194 ms, p99 5.606).
|
||||
Verdict: PASS. The two firings fired (dr736 FAIL at 15.49 ms half-core; class v4 genesis PASS at 8.62). Consequences
|
||||
per tier: a 2019-class node verifying the worst class v4 program spends 0.9 percent of one core at 1 bps and 9 percent
|
||||
at 10 bps on the pessimistic proxy; a header flood needs about 115 invalid headers a second to saturate one such
|
||||
core; a pool verifies about 115 shares a second per core; IBD of 108,000 headers is about 16 minutes of one core.
|
||||
Implied ladder ceiling on the half-core proxy from the worst program: 10 - 8.708 = 1.29 ms of headroom buys about
|
||||
106,000 shadow instructions, N about 300,000 counted ops at the 1.83 convention (approximate), against 370,000
|
||||
from the genesis program's headroom; the ladder's ceiling should be read from the worst program, not the genesis
|
||||
one, so rung 2 (199,600) stays admissible and rung 3 (330,700) does not on this proxy.
|
||||
|
|
|
|||
|
|
@ -2661,3 +2661,12 @@ v2 1.582 / 1.280; mx8 5.394 / 5.267; mx8+sh256x27 (class v4) 6.334 / 6.006; dr36
|
|||
(fails the 10 ms gate, the known-fail). Cache fill 276 ms. Log `docs/analysis/attack-pass/o114-i7-9700K-2026-10-07.log`;
|
||||
record `docs/analysis/attack-pass-2026-10.md` row F6. Class v4 passes a real 2019-class core with 3.7 ms to spare; the
|
||||
half-core proxy (8.23 ms) stays the standing pessimistic rule for the ladder's ceiling.
|
||||
|
||||
## F6: the verifier's worst case over 10^5 class v4 programs (attack pass, 7 October 2026, 13:5x UTC)
|
||||
|
||||
igneum-build-1, cores 40 (one-core proxy) and 88 (the half-core proxy, both SMT siblings busy) under the per-core lease,
|
||||
core 40 at a median 3,799.9 MHz. 100,000 programs ranked by exact op counts; 50,000 timed cold on core 40 (min / median /
|
||||
p99 / max 4.610 / 4.948 / 5.606 / 6.194 ms per warp); the worst 200 re-timed at 10 cold reps on both proxies and the worst
|
||||
1,000 on the half-core at 2 reps, the worst 10 at 20: worst half-core cold max 8.708 ms (`attack-f6/87142`), then 8.629
|
||||
(`attack-f6/88521`), 8.414 (`attack-f6/15781`); the genesis program 8.624. Gate 10 ms: PASS by 1.29 ms. Record
|
||||
`docs/analysis/attack-pass/f6-verifier.md`; logs `/srv/builds/igneum-wt-attack/target-attack-f6/phase2b.log`, `phase2c.log`.
|
||||
|
|
|
|||
Loading…
Reference in a new issue