From 9cde808df7bce90d26cb4b6986adc6a86bcc4960 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Thu, 8 Oct 2026 02:01:33 +0000 Subject: [PATCH] adv-mixer-3 report: Q7 days 27406 and 33333 complete (uniform, clean) Co-Authored-By: Claude Fable 5.1 --- docs/analysis/cryptanalysis/report-mixer-3.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/analysis/cryptanalysis/report-mixer-3.md b/docs/analysis/cryptanalysis/report-mixer-3.md index 13836a320..4f3c7ebc2 100644 --- a/docs/analysis/cryptanalysis/report-mixer-3.md +++ b/docs/analysis/cryptanalysis/report-mixer-3.md @@ -32,7 +32,7 @@ Plant rule: a tool is trusted once it has fired on a known-failed shape. Which s | Q4b | t-bit linear correlations on the round-0 input, 2^26 samples | k = 0 (fired: c = 1.0, t bit 0 to s[8] bit 0) | no cell beyond 6 sigma | both days, k = 1..8: worst c 0.00046 to 0.00059 (z 3.7 to 4.9 over 16,384 cells), 0 cells beyond 6 sigma | PASS from k = 1 (BOUND) | | Q5 | rotational-XOR, rotations 1, 8, 16, 2^22 samples | `weak0` at k = 1 (fired: 740 zero-difference words of 2^20 at r = 1, 245 at r = 16) | no zero-difference word above 2 of N, no repeated difference above 3 | both days, k = 1, 2, 3, 4 at 2^22 samples: 0 zero-difference words at every rotation (random expects about 0.001), most frequent per-word difference multiplicity 3 (the birthday expectation at 2^22 draws of 32 bits) | PASS from k = 1 (BOUND: the XOR constants and the odd multiply kill the rotational property inside one application) | | Q6 | SAT (CaDiCaL) on the round-0 input: find t with a given 22-bit index after k applications | k = 1 solved and verified | solve inside one hour per k, time against the honest 2^10 x k x 130 ops | k = 1: SATISFIABLE in 137 s wall on build-1 (load about 160) and 1,593 s on build-2 (load about 500), the same model t = 0x49880000 both times, verified to the target 0x20eb79 through the real code; k = 2: TIMEOUT at the one-hour cap (68,624 vars, 227,767 clauses); k = 3: TIMEOUT (103,375 vars, 343,206 clauses); k = 4: TIMEOUT (138,126 vars, 458,645 clauses). Honest: 2^10 trials is under a millisecond at every k | PASS at k = 1..4 on day 20729 (BOUND: no SAT shortcut, the solver loses to brute force at k = 1 and does not return at k = 2, 3 or 4 inside an hour); day 20733 k = 2 TIMEOUT too; k = 3, 4 RUNNING under the cap | -| Q7 | days: 20733 on every row, 8 fixed day indices on Q1 and Q2 (queue 07, run by the sibling adv-mixer from the shared queue) | as above | as above | day 20733: every row above; days 20730, 20745, 21057, 23311 complete (index uniform at k = 2, 3, 4, 8; sac clean at k = 2, 3, 4); four more days running in queue 07 on build-1 | RUNNING | +| Q7 | days: 20733 on every row, 8 fixed day indices on Q1 and Q2 (queue 07, run by the sibling adv-mixer from the shared queue) | as above | as above | day 20733: every row above; days 20730, 20745, 21057, 23311, 27406, 33333 complete (index uniform at k = 2, 3, 4, 8; sac clean at k = 2, 3, 4); days 50000 and 99999 running in queue 07 on build-1 | RUNNING | | GPU | any GPU row | n/a | n/a | no GPU on either box | BLOCKED | The round margin so far (internal adversarial pass, not an independent review): every single-bit statistic that @@ -173,6 +173,8 @@ rows were run by the sibling adv-mixer from the shared queue; the rest by this l | 20745 | -1.01 / -1.82 / -0.87 / 0.72 (0) | -4.68 / -4.63 / -4.94 (0) | uniform, clean | | 21057 | -0.76 / -2.52 / -0.39 / -1.16 (0) | 4.89 / -4.90 / -4.57 (0) | uniform, clean | | 23311 | 0.85 / 0.06 / -0.21 / 0.41 (0) | 4.35 / -5.24 / 5.06 (0) | uniform, clean | +| 27406 | 0.53 / 0.29 / 0.85 / 0.17 (0) | 4.58 / -4.64 / -4.80 (0) | uniform, clean | +| 33333 | -0.55 / 0.19 / 0.80 / 0.50 (0) | 4.51 / -4.86 / 4.41 (0) | uniform, clean | ## Q3: differential multiplicity