adv-accept report: reproducibility block, selector base rate over 16,337 programs, row 90 plant; status board updated

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-07 18:53:52 +00:00
parent d01fa093ec
commit a1b2c3e30e
2 changed files with 71 additions and 9 deletions

View file

@ -0,0 +1,10 @@
adv-accept attempts: seeds 2..5 (3), 3 threads, cap 256, force-exhaust true
seed 2: EXHAUSTED at cap 8; last resort id e3f47f1ab9d3c562 attempt 8 op mix xor=19 load=16 add=7 rotl=7 mad=5 rotr=5 shfl=4 sub=1 shadow mix xor=90 add=46 mad=29 shfl=28 rotl=24 sub=20 rotr=19; rule verdict on it Ok("accept distinct_mean 128.000 sat 0 bias 63"); structure lossy_last 0 or 0 mul 0 mulhi 0 regs 8
seed 4: EXHAUSTED at cap 8; last resort id 592875c46032e6ad attempt 8 op mix xor=17 load=16 sub=9 shfl=6 add=5 rotl=4 rotr=4 mad=3 shadow mix xor=93 add=37 shfl=35 mad=28 rotr=22 rotl=21 sub=20; rule verdict on it Ok("accept distinct_mean 127.864 sat 0 bias 58"); structure lossy_last 0 or 0 mul 0 mulhi 0 regs 8
seed 3: EXHAUSTED at cap 8; last resort id 579a85a94f80826b attempt 8 op mix xor=17 load=16 rotl=10 shfl=7 add=6 mad=6 rotr=2 shadow mix xor=93 add=40 mad=31 shfl=26 rotl=23 sub=23 rotr=20; rule verdict on it Ok("accept distinct_mean 128.000 sat 0 bias 66"); structure lossy_last 0 or 0 mul 0 mulhi 0 regs 8
attempts: 3 seeds in 116 s; 17 rejected candidates, 0 accepted, 3 exhausted (cap 256)
rejection by part over all candidates: (a) stale=3 (17.6%) (b) no-inject=1 (5.9%) (a') unfresh=13 (76.5%) (c) const-bit=0 (0.0%) (c) lane-const=0 (0.0%) (c) saturated=0 (0.0%) (c') sat-source=0 (0.0%) (c'') repeated=0 (0.0%) (c'') low-entropy=0 (0.0%) (c) bias=0 (0.0%) (c) distinct=0 (0.0%)
accepted-attempt histogram 0..0: [0]
attempt 0: 2 candidates, rejected 2 (100.0%): (a) stale=1 (b) no-inject=1
mean accepted attempt 0.000; per-candidate rejection probability 1.0000; P(256 consecutive rejections) if independent = 1.000e0
attempts DONE

View file

@ -34,12 +34,12 @@ check is owed once I copy its program.json read-only from build-1.
| Q | Method | Known-failed shape (must fire) | Gate | Result | Status |
|---|---|---|---|---|---|
| Q1 | Steering/hot set: draw accepted class v4 programs over >=10^6 seeds, measure the hot set of the 128 live loads per hash (share of reads on top 0.1% / 1% of items vs uniform) | f8 const-item / quarter-lines / half-lines plant must FLAG; clean control within noise | X_f >= f flags a hot set; gain = implied on-die SRAM copy size | closed-form proxy sweep (10k seeds) running; live-dataset histogram owed | RUNNING |
| Q2 | Stand-in gap: compare the (c) metrics (distinct-address sum, saturation, bias, per-site ratio) on the closed form vs the live memory-hard dataset for accepted programs; count and bound false accepts | a hand-built closed-form-accept / live-reject program must be reported as such | any false accept that reads a hot set on the live set | not started (rides on Q1 cache) | PENDING |
| Q3 | Attempt grinding + last resort: variance of the hot set across attempts of one seed vs across seeds; what last_resort_v4 (256-cap, or/mul/mulhi->xor, no (c) check) hands an attacker | the forced last-resort program's live hot set must be measurable; derive check fce15bf61030be57 | a predictable or weak accepted program the hot-set rule never sees | not started | PENDING |
| Q4 | Header grinding for locality: vary H and nonce_hi (init words only), measure distinct DRAM rows / cache lines a 32-lane group touches, search cost vs clustering gain | a harness-mirror patch making the address depend on I must let the search find a clustering header; the real path must not | best clustering over a header budget, cost in hashes | not started | PENDING |
| Q5 | Generator distinguishers: over accepted programs count lossy last writes, contractions, register-set collapse, low-entropy sites in the 0.98 tail; headroom of the floor | reproduce the crate's ratio verdict: p15/p18/p19/p56 rejected, p23 attempt 1 accepted | a structural shape that lowers the live distinct-item count | per-site ratio distribution in the 10k sweep; F8 reproduction owed | RUNNING |
| Q6 | Fixed (c) sample grindability; live-size invariance of the (c) verdict | a program tuned to the 2,048 fixed nonces but failing off-sample must be found or bounded | BOUND unless something fires | not started | PENDING |
| Q1 | Steering/hot set: the chain's class v4 draw over the F8 label space (shards of 100k seeds; 18:27Z to 18:4xZ under the SIGSTOP yield, since 18:4xZ nice 10 on cores 8-95, no yield), the stand-in per-site ratio at 256 units as the proxy, the live hot set by the unmodified f8 harness (adv-live) on the lowest-ratio seeds and on a consecutive-seed census | adv-live const-item plant FLAGGED (21.8x, X_1% +6.49); clean control 0.9996x PASS | X_f >= f flags a hot set; gain = implied on-die SRAM copy size | seed 100767 (of 4,600 accepted) flags the hot-set test at 2^24 nonces: X_0.1% +0.155%, 2.05x; four lowest-ratio seeds all BEYOND the f8 1.2x gate live; 27 random accepted programs: 0 beyond, 0 hot sets; gain 1.002x (1 MB copy serves 0.31% of loads) | FINDING, bounded: a distinguisher and a seed selector, not an exploitable bypass; sweep RUNNING |
| Q2 | Stand-in gap: a validated mirror runs the rule's own units on the closed form and on the live dataset; per-site ratio at 2^20 and the (c) metrics compared | zero-dataset plant: live 0.9733 REJECT against closed accept (fired) | any false accept that reads a hot set on the live set | 4 + 6 programs so far: max site gap 0.0003, 0 verdict disagreements | BOUND (widening to 50 RUNNING) |
| Q3 | Handed to lane adv-accept-3 (unspawned); row 90 (exhaustion census: per-part rejections, cap, last resort) claimed by this lane, owner adv-accept-3 | forced-exhaust plant must hit the cap and print the last-resort program | P(exhaust) bounded; last resort characterised | attempts census over 20k seeds RUNNING (box 2); plant RUNNING | RUNNING (owner adv-accept-3, unspawned) |
| Q4 | Handed to lane adv-accept-2 | | | | HANDED OVER |
| Q5 | Generator distinguishers over accepted programs: lossy last write, register-set collapse, the per-site ratio tail against the 0.98 floor | the five lowest-ratio seeds reproduce as live tail programs (done); F8 p15/p18/p19/p56 reproduction owed | a structural shape that lowers the live distinct-item count | first 864: lossy last write in 83%, 0 register collapse, min ratio 0.9986 at 256 units; at 2^20 the tail reaches 0.9832 (floor 0.98) | RUNNING |
| Q6 | Fixed (c) sample grindability; live-size invariance of the (c) verdict | | BOUND unless something fires | not started | PENDING |
The plant (known-failed shape for the harness itself) fired: planting an `or` write of a load's
source register immediately before the load makes the rule reject with "(a') load at 1 reads r4, not
@ -139,9 +139,22 @@ loose enough (these sit at 0.9986) that (c'') never fires either.
### FINDING (bounded): seed 100767 at 2^24 nonces passes the rule and flags the f8 hot-set test (box 1, 18:4xZ)
`adv-live warps --program 100767 --nonces 16777216 --threads 32 --diag 1` (log adv/live-confirm-16m.log,
copied to logs/adv-accept/ when the four runs end). Program id 9d68e6286fc817d4, attempt 2, accepted by
every part of the rule.
Reproduce in one command, from the frozen crate (017e7037) with the unmodified f8-uniform harness built as
adv-live (tools/attack/adv-accept, `cargo build --release`):
adv-live warps --program 100767 --nonces 16777216 --threads 32 --diag 1 --validate sample --out <dir>
The program is the chain's class v4 draw for epoch seed bytes = the little-endian words of
seed_words_from_bytes("igneum-attack-f8/program/100767") =
74484b391756fc49568cdd716bcfd839a55d31a45633c223c65c7f2ab4617fd4 and era seed bytes = the same of
"igneum-attack-f8/era/100767" = 7a65a05391dcd87b8fdaf7f74813aa17c6e13f7c56a03da2aaa6176987ef038b
(f8's program_spec(k) for k >= 2; `adv-accept gap --seeds 100767` prints the same id), through
generate_era(V4_CLASS, V3_ALLOWED): attempt 2, program id 9d68e6286fc817d4, class
mx8-era763e5847+sh256x27, day bytes "igneum-day/" || 20730_le64 (f8's default day). The run's log is
logs/adv-accept/live-confirm-16m.log in this branch (copied from box 1,
/srv/builds/_adv-adv-accept/live-confirm-16m.log); the harness checks its mirror against Epoch::hash_warp
on 64 warps plus every 997th (0 mismatches in the log). Accepted by every part of the rule: it is the
program try_generate_class returns for the seed (attempt 0 and 1 rejected).
| Measure | Value | Uniform / control |
|---|---|---|
@ -180,6 +193,45 @@ programs gave X_0.1% = 0.155%. If the tail scales as the extreme of the populati
times that, still under 1% of reads. The census over consecutive seeds (random accepted programs) says how
often the hot-set test fires in the population; that number lands below.
### The selector's base rate (sweep rows read at 18:5xZ: 16,337 accepted programs, shards 00 and 01)
The stand-in per-site ratio at 256 units, over every accepted program so far (one row per seed; every seed
of the F8 label space yields an accepted program through the chain draw):
| Quantile | min | 0.1% | 1% | 5% | 25% | median | 75% | max |
|---|---|---|---|---|---|---|---|---|
| ratio | 0.9945 | 0.9980 | 0.9993 | 0.9997 | 0.9998 | 0.9999 | 0.9999 | 1.0000 |
| Threshold | Programs under it | Tries per hit |
|---|---|---|
| ratio < 0.9990 | 85 of 16,337 | 1 in 192 |
| ratio < 0.9988 | 54 | 1 in 303 |
| ratio < 0.9986 (the five confirmed seeds sat here) | 34 | 1 in 480 |
Cost of the selector: one chain draw per try (about 3 s of one core: the accepted attempt's 2^20 ratio pass
dominates) plus a 256-unit ratio read (milliseconds), so a seed under 0.9986 costs about 25 core-minutes of
grinding, and a seed-steering attacker who can choose among epoch seeds needs about 500 candidate seeds per
hit. The five confirmed hits at that threshold all failed the f8 1.2x gate live; the random sample's live
failure rate is 0 of 27 so far (census), so the gate-failure rate conditional on the selector is 5 of 5
against 0 of 27 unconditional. The widened rows (20 lowest, 20 random, at 2^24 nonces) turn this into a
correlation with its error when they land (live-low20-16m.log on box 1, live-random20-16m.log on box 2).
Attempt histogram over the 16,337 (accepted attempt 0..11): 5,271, 3,602, 2,434, 1,585, 1,110, 740, 521,
368, 211, 166, 100, 72; max 26; mean 2.097; last-resort programs 0. Q5 structure: a lossy last write to an
output register in 13,662 (83.6%), register-set collapse 0.
### Row 90 (owner adv-accept-3, unspawned; claimed): the attempt loop, the cap and the last resort
Known-failed shape fired (box 2, 18:50Z, `adv-accept attempts --seed-start 2 --seeds 3 --force-exhaust`,
log adv/attempts-plant.log): with every verdict read as a rejection the loop hits its cap and hands the
last-resort program, which the tool prints and re-checks. The three last-resort programs (cap 8 under the
plant): every or, mul and mulhi rewritten to xor (op mix xor 17 to 19, load 16, 0 lossy ops, 8 registers
written), and the real rule accepts each one as drawn (distinct mean 127.86 to 128.00, 0 saturated, bias
max 58 to 66). Reading: the last resort is predictable (a deterministic function of attempt 256's draw) and
is NOT weak by the rule's own measures; it is a program with no lossy op at all, which the live hot-set
measure has not yet been run on (owed). The 20k-seed census of real attempts (per-part rejections, cap
reached, P(exhaust)) is running (attempts-20k.log); its numbers land here.
### Q2, the stand-in gap: first bound (box 2, 18:46Z, `adv-accept gap`)
Tool: a mirror interpreter with per-site index capture, run on the rule's own base nonces (seed-keyed