diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index a373e4791..fda2ee33e 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -23,11 +23,11 @@ against the log before quoting it to the project lead. | F1 | Shadow block compressibility and shortcut search | best compressed block within 5% of N on every program; no program over 10% compressible | pending evidence map + box run | RUNNING | | F2 | Mixer round margin (SAT/MILP, 1 to 4 keyed applications) | no distinguisher or shortcut beyond 2 of the 8 applications | pending evidence map (ca2-mixer) + box run | RUNNING | | F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | 0 of 64 and 0 of 1,024 lines under j+1 (exhaustive closure search, cross-checked by exhaustive pebbling at 10 lines, 10,240 pairs, 0 mismatches); both planted broken chains fire; curve monotone at both op counts; f=1 point 9,360 ops per item unchanged. Record `docs/analysis/attack-pass/f3-cache.md` | PASS | -| F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | pending box census | RUNNING | +| F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | interim: 2^24 and 2^28 censuses done, planted weak days fire; every ROT and RC class 0 over 1.1x on the exact metrics; M1 (per-day LUT datapath, adders per mixer application vs the census median) counts 5,476 of 2^24 days over 1.1x (3.26e-4, 342x the gate). Final verdict waits on the timing row; if M1 holds it is a finding on the draw, routed with the rejection-and-redraw remedy priced as F8 (v4 untouched, the rule into the next class unless a fault), naming the worst day in adders per application | INTERIM | | F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x at k=1 GDDR7 reproduces, 3.2x at k=0.5, 4.1x at k=0.3 (matches ledger M32); FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). FINDING: the k=0.33 figure is framed as the X9's measured core (M32) and a "measured class" (ladder branch ยง5a); the X9 was withdrawn before launch and never benchmarked. F2 hour SKIPPED: no AWS account | FIXED-AND-PASSED (sweep PASS; AP-F5-1 fixed and re-gated 7 Oct 2026: chip section re-run 2.1x at k=1 unchanged, identity grep 0 hits, site lane concurred); F2 hour SKIPPED-BY-DECISION (the project lead, 7 Oct 2026, 09:5x UK; plan 4.2 row F5 is the sweep only at 3714c2a0; the FPGA row stays the JEDEC-ceiling model row labelled unmeasured) | | F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | O-1.14 CLOSED on an i7-9700K (2019 desktop core): v4 6.006 ms avg, 6.334 cold max per warp; dr736 10.04 (the known-fail fires); box proxies 5.06 / 8.23. Worst-case search over 10^5 owed | RUNNING (O-1.14 closed) | | F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | model era section: re-roll needs a 1,800x VDF (300x beats only the epoch); weakest op-weight corner about 20% of shadow datapath energy, 0 chip effect. Harness + 2^20 census owed | RUNNING | -| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | largest bucket within 6 sigma of uniform; no hot set under 1% of items | interim, phase D at 2^26 nonces: top 0.1% of items take 0.520% of reads vs 0.115% uniform (4.05x), top 1% 2.49% (1.37x), one item 153x the mean, read site 15 feeds 6.37% of its reads into the hot 0.1% in all 8 iterations; shortcut under 1% of rate today. AP-F8-1: the 4.05x is largely the designed per-site windows of layer 8 (spec 1.13.1); the gate is now the window model from the program's own draws, the finding stays open only for the excess beyond it (the 153x item, or a low-entropy source at site 15 if the 64-seed census shows one); no generator change to v4 (on the live vote) | FINDING (open on the excess only) | +| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model (coordinator, 7 Oct 2026, 11:2x UK; the plan's 1.4 gate (4) and row F8 carry the same sentence) | interim, phase D at 2^26 nonces: top 0.1% of items take 0.520% of reads vs 0.115% uniform (4.05x), top 1% 2.49% (1.37x), one item 153x the mean, read site 15 feeds 6.37% of its reads into the hot 0.1% in all 8 iterations; shortcut under 1% of rate today. AP-F8-1: the 4.05x is largely the designed per-site windows of layer 8 (spec 1.13.1); the gate is now the window model from the program's own draws, the finding stays open only for the excess beyond it (the 153x item, or a low-entropy source at site 15 if the 64-seed census shows one); no generator change to v4 (on the live vote) | FINDING (open on the excess only) | | F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | edges reproducible via `accept`; grinding measurement needs PC 2's 5090 or a rented pod | BLOCKED (PC 2 go / pod) | | F10 | Ladder signal monotonicity harness | no step without 90% over 7 windows in either direction | pending fast-time harness | RUNNING | @@ -293,6 +293,9 @@ model (the 153x item, or a low-entropy source at site 15 if the 64-seed census s class v4 is allowed: it is on the live devnet's vote, and a class change before the flip splits the chain. If the census shows a real fault it goes to the coordinator priced; otherwise the record carries the documented null and the hot-set bound (a 0.1 percent cache, about 1.7 MB of SRAM, under one percent of rate) goes into the next class. +Gate wording settled (coordinator, 11:2x UK): plan 1.4 gate (4) and row F8 now read "uniform within the window +model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds", carried into the plan's scope +text by the cryptanalysis lane so the firms are briefed on the windows before they start. Status: FINDING-OPEN on the excess only; the Counter ASIC lane's window model with numbers and F8's phase E close it. Any further finding is logged here and in `docs/fud-ledger.md` with its owning lane (hash and algorithm: fixed in