diff --git a/docs/analysis/cryptanalysis/logs/adv-accept/attempts-plant.log b/docs/analysis/cryptanalysis/logs/adv-accept/attempts-plant.log new file mode 100644 index 000000000..40c88b0d0 --- /dev/null +++ b/docs/analysis/cryptanalysis/logs/adv-accept/attempts-plant.log @@ -0,0 +1,10 @@ +adv-accept attempts: seeds 2..5 (3), 3 threads, cap 256, force-exhaust true +seed 2: EXHAUSTED at cap 8; last resort id e3f47f1ab9d3c562 attempt 8 op mix xor=19 load=16 add=7 rotl=7 mad=5 rotr=5 shfl=4 sub=1 shadow mix xor=90 add=46 mad=29 shfl=28 rotl=24 sub=20 rotr=19; rule verdict on it Ok("accept distinct_mean 128.000 sat 0 bias 63"); structure lossy_last 0 or 0 mul 0 mulhi 0 regs 8 +seed 4: EXHAUSTED at cap 8; last resort id 592875c46032e6ad attempt 8 op mix xor=17 load=16 sub=9 shfl=6 add=5 rotl=4 rotr=4 mad=3 shadow mix xor=93 add=37 shfl=35 mad=28 rotr=22 rotl=21 sub=20; rule verdict on it Ok("accept distinct_mean 127.864 sat 0 bias 58"); structure lossy_last 0 or 0 mul 0 mulhi 0 regs 8 +seed 3: EXHAUSTED at cap 8; last resort id 579a85a94f80826b attempt 8 op mix xor=17 load=16 rotl=10 shfl=7 add=6 mad=6 rotr=2 shadow mix xor=93 add=40 mad=31 shfl=26 rotl=23 sub=23 rotr=20; rule verdict on it Ok("accept distinct_mean 128.000 sat 0 bias 66"); structure lossy_last 0 or 0 mul 0 mulhi 0 regs 8 +attempts: 3 seeds in 116 s; 17 rejected candidates, 0 accepted, 3 exhausted (cap 256) +rejection by part over all candidates: (a) stale=3 (17.6%) (b) no-inject=1 (5.9%) (a') unfresh=13 (76.5%) (c) const-bit=0 (0.0%) (c) lane-const=0 (0.0%) (c) saturated=0 (0.0%) (c') sat-source=0 (0.0%) (c'') repeated=0 (0.0%) (c'') low-entropy=0 (0.0%) (c) bias=0 (0.0%) (c) distinct=0 (0.0%) +accepted-attempt histogram 0..0: [0] +attempt 0: 2 candidates, rejected 2 (100.0%): (a) stale=1 (b) no-inject=1 +mean accepted attempt 0.000; per-candidate rejection probability 1.0000; P(256 consecutive rejections) if independent = 1.000e0 +attempts DONE diff --git a/docs/analysis/cryptanalysis/report-acceptance-rule.md b/docs/analysis/cryptanalysis/report-acceptance-rule.md index 38bd33283..47e6684f8 100644 --- a/docs/analysis/cryptanalysis/report-acceptance-rule.md +++ b/docs/analysis/cryptanalysis/report-acceptance-rule.md @@ -34,12 +34,12 @@ check is owed once I copy its program.json read-only from build-1. | Q | Method | Known-failed shape (must fire) | Gate | Result | Status | |---|---|---|---|---|---| -| Q1 | Steering/hot set: draw accepted class v4 programs over >=10^6 seeds, measure the hot set of the 128 live loads per hash (share of reads on top 0.1% / 1% of items vs uniform) | f8 const-item / quarter-lines / half-lines plant must FLAG; clean control within noise | X_f >= f flags a hot set; gain = implied on-die SRAM copy size | closed-form proxy sweep (10k seeds) running; live-dataset histogram owed | RUNNING | -| Q2 | Stand-in gap: compare the (c) metrics (distinct-address sum, saturation, bias, per-site ratio) on the closed form vs the live memory-hard dataset for accepted programs; count and bound false accepts | a hand-built closed-form-accept / live-reject program must be reported as such | any false accept that reads a hot set on the live set | not started (rides on Q1 cache) | PENDING | -| Q3 | Attempt grinding + last resort: variance of the hot set across attempts of one seed vs across seeds; what last_resort_v4 (256-cap, or/mul/mulhi->xor, no (c) check) hands an attacker | the forced last-resort program's live hot set must be measurable; derive check fce15bf61030be57 | a predictable or weak accepted program the hot-set rule never sees | not started | PENDING | -| Q4 | Header grinding for locality: vary H and nonce_hi (init words only), measure distinct DRAM rows / cache lines a 32-lane group touches, search cost vs clustering gain | a harness-mirror patch making the address depend on I must let the search find a clustering header; the real path must not | best clustering over a header budget, cost in hashes | not started | PENDING | -| Q5 | Generator distinguishers: over accepted programs count lossy last writes, contractions, register-set collapse, low-entropy sites in the 0.98 tail; headroom of the floor | reproduce the crate's ratio verdict: p15/p18/p19/p56 rejected, p23 attempt 1 accepted | a structural shape that lowers the live distinct-item count | per-site ratio distribution in the 10k sweep; F8 reproduction owed | RUNNING | -| Q6 | Fixed (c) sample grindability; live-size invariance of the (c) verdict | a program tuned to the 2,048 fixed nonces but failing off-sample must be found or bounded | BOUND unless something fires | not started | PENDING | +| Q1 | Steering/hot set: the chain's class v4 draw over the F8 label space (shards of 100k seeds; 18:27Z to 18:4xZ under the SIGSTOP yield, since 18:4xZ nice 10 on cores 8-95, no yield), the stand-in per-site ratio at 256 units as the proxy, the live hot set by the unmodified f8 harness (adv-live) on the lowest-ratio seeds and on a consecutive-seed census | adv-live const-item plant FLAGGED (21.8x, X_1% +6.49); clean control 0.9996x PASS | X_f >= f flags a hot set; gain = implied on-die SRAM copy size | seed 100767 (of 4,600 accepted) flags the hot-set test at 2^24 nonces: X_0.1% +0.155%, 2.05x; four lowest-ratio seeds all BEYOND the f8 1.2x gate live; 27 random accepted programs: 0 beyond, 0 hot sets; gain 1.002x (1 MB copy serves 0.31% of loads) | FINDING, bounded: a distinguisher and a seed selector, not an exploitable bypass; sweep RUNNING | +| Q2 | Stand-in gap: a validated mirror runs the rule's own units on the closed form and on the live dataset; per-site ratio at 2^20 and the (c) metrics compared | zero-dataset plant: live 0.9733 REJECT against closed accept (fired) | any false accept that reads a hot set on the live set | 4 + 6 programs so far: max site gap 0.0003, 0 verdict disagreements | BOUND (widening to 50 RUNNING) | +| Q3 | Handed to lane adv-accept-3 (unspawned); row 90 (exhaustion census: per-part rejections, cap, last resort) claimed by this lane, owner adv-accept-3 | forced-exhaust plant must hit the cap and print the last-resort program | P(exhaust) bounded; last resort characterised | attempts census over 20k seeds RUNNING (box 2); plant RUNNING | RUNNING (owner adv-accept-3, unspawned) | +| Q4 | Handed to lane adv-accept-2 | | | | HANDED OVER | +| Q5 | Generator distinguishers over accepted programs: lossy last write, register-set collapse, the per-site ratio tail against the 0.98 floor | the five lowest-ratio seeds reproduce as live tail programs (done); F8 p15/p18/p19/p56 reproduction owed | a structural shape that lowers the live distinct-item count | first 864: lossy last write in 83%, 0 register collapse, min ratio 0.9986 at 256 units; at 2^20 the tail reaches 0.9832 (floor 0.98) | RUNNING | +| Q6 | Fixed (c) sample grindability; live-size invariance of the (c) verdict | | BOUND unless something fires | not started | PENDING | The plant (known-failed shape for the harness itself) fired: planting an `or` write of a load's source register immediately before the load makes the rule reject with "(a') load at 1 reads r4, not @@ -139,9 +139,22 @@ loose enough (these sit at 0.9986) that (c'') never fires either. ### FINDING (bounded): seed 100767 at 2^24 nonces passes the rule and flags the f8 hot-set test (box 1, 18:4xZ) -`adv-live warps --program 100767 --nonces 16777216 --threads 32 --diag 1` (log adv/live-confirm-16m.log, -copied to logs/adv-accept/ when the four runs end). Program id 9d68e6286fc817d4, attempt 2, accepted by -every part of the rule. +Reproduce in one command, from the frozen crate (017e7037) with the unmodified f8-uniform harness built as +adv-live (tools/attack/adv-accept, `cargo build --release`): + + adv-live warps --program 100767 --nonces 16777216 --threads 32 --diag 1 --validate sample --out