From a25c8ea1f806c00ef552e4b118333bbc69c0b0ba Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 22:37:47 +0000 Subject: [PATCH] in-house-pass.md: adv-mixer-2 closed (86bec7ec): the redraw rule leaves 0 days over 1.1x Co-Authored-By: Claude Fable 5.1 --- docs/plans/cryptanalysis/in-house-pass.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/plans/cryptanalysis/in-house-pass.md b/docs/plans/cryptanalysis/in-house-pass.md index 85dc4e517..6d5f29937 100644 --- a/docs/plans/cryptanalysis/in-house-pass.md +++ b/docs/plans/cryptanalysis/in-house-pass.md @@ -157,7 +157,7 @@ It is not an independent review and is never called one. Nothing is sent outside | Lane | Plan on the mirror | First results | Defender's line | Box-hours | |---|---|---|---|---| | adv-mixer | 1d720654, 19:09 BST | COMPLETE at 22:1x BST (tip on build/adv-mixer at its final push): Q1 algebraic structure BOUND, no composition of the 8 applications cheaper than 8x, 9,360 ops per item unchanged; the operative evidence is the commutation probe at 0 in 1,454,080,000 over 1,024 days; the SAT row is a bound on solver reach only (three CaDiCaL runs, 6,455 s on one core, neither SAT nor UNSAT, the expected shape for a preimage-sized instance); deepening rows 11 to 15 (fold sweep replicated, linear-relation kernel 0 at 3 to 7 applications, integral saturated at 8, line-index bits at 5 to 8) all BOUND; about 0.6 box-hours. Earlier: e35556af, 19:40 BST: Q1 algebraic structure BOUND (fold probe 1e6 of 1e6 affinity violations, 0 of 256 dead word pairs, 0 of 1e6 key-order agreements; integral degree at least 16 after one application, saturated after two; 9,360 ops per item stand); courtesy readings on Q2 (full diffusion at 2 applications, margin 6 of 8) and Q3 (2^24 days, best day 1.17x FPGA multiply datapath, 1 in 2^24, no DSP or wall-time gain) | pending | 0.4 | -| adv-mixer-2 | 5704a7b3, 19:32 BST (IDENTICAL at 7a7caa34 and 04c4d9bc; about 4 box-hours estimated) | tip ae3088a9, 21:3x BST (first word from the lane since spawn): harness built on both boxes (binary 88f6a3ed, outside the mirror), two chains waiting at class adv, 32 threads (box 2: the 2^24 census, the calendar, the small-constant-multiplier calendar and tail, avalanche; box 1: the 2^32 census and the redraw census); nothing hand-started beyond three sub-11 s smoke runs. Rows at 49656c2e, 21:3x BST: model A is an FPGA LUT-area gain for a per-day build (multiplier adders), NOT a wall-time or op-count gain: under the chip model's 9,360 ops per item the per-day gain is 1.0 on every day for every GPU, the verifier and any chip with a general multiplier; against the exact median 226, P(model A at or above 1.1x) = 5.69e-4 = 2^-10.8 per day (the earlier 2^-7.9 used a provisional median of 231); model C (DSP) stays under 2^-20 at 1.1x (1.067x on 2^-15 of days); the 1.1x-on-2^-20 threshold is crossed by model A only, the same bounded class as AP-F4-1; worst real day 29337 = 2050-04-28 at 1.113x, 15 days over 1.1x in 100 years; RECONCILED with the attack-pass lane's F4 at 21:4x BST (F4 record section 9, both medians side by side): F4's NAF weight counted a carry digit at position 32 that a 32-bit multiplier never pays (0.333 digits per word, 5.3 adders per day), the whole of 231 against 226 and 12 against 15 days a century; the agreed figure is median 226, a 1.1x gain at cost A at most 205, 5.69e-4 of days (2^-10.8), 15 days a century, worst 2050-04-28 at 1.113x; the DSP-bound readings agree at 0 for k at least 2; F4's PASS against class v4 stands; the redraw rule for the next class takes adv-mixer-2's form; a redraw rule row (continue the stream and redraw all 40 draws if cost A is 205 or less, or a 2-adder MUL, or all ROT equal; about 22 days per 100 years redrawn) with the before fraction, the after fraction owed with the redraw census; no seed collisions or stream shifts; the 2^24 census matches the exact table on every class; all six plants fire. Running: the small-constant-multiplier calendar on box 2 (24 cores); the 2^32 census waiting on box 1. Tip 52a31815, 21:4x BST: all rows but two landed: model B (partial: 12.3 percent of words certified at 5 or fewer adders, 0.38 percent at 4 or fewer; the between-day spread is the certificate's reach, not a gain), ROT diffusion (every day and every plant at the uniform 0.500 by 2 applications, address bits with them, 8 sit between reads: gain 0, BOUND), the F4 reconciliation mirrored; the 2^32 census running on 32 leased build-1 cores since 21:42 BST (about 25 minutes), then the redraw census at 2^24 and 2^28; box 2 chain done; 0.12 box-hours so far. Ledger: one inline rm over its own claim directories at 21:36 BST, three minutes after the rule reached it; later deletions through script files. The coordinator wrongly chased this plan as overdue between 20:25 and 20:32 BST | pending | | +| adv-mixer-2 | 5704a7b3, 19:32 BST (IDENTICAL at 7a7caa34 and 04c4d9bc; about 4 box-hours estimated) | CLOSED at 2a632579, 23:37 BST, 0.31 box-hours, 0 pod-hours, nothing on either box: the redraw rule measured over 2^24 and 2^28 days (0 days over 1.1x after it; 6.0e-4 of days redrawn once, 3e-7 twice, never three times; mean cost unchanged); verdict BOUND for every chip, GPU and the verifier (gain 1.0 every day at 9,360 ops per item), FINDING on the per-day FPGA LUT-area reading only (2^-10.8 of days over 1.1x, exact to 2^32, worst 28 April 2050 at 1.113x), closed by the redraw rule or by the spec's O-1.10 day derivation. Earlier: tip ae3088a9, 21:3x BST (first word from the lane since spawn): harness built on both boxes (binary 88f6a3ed, outside the mirror), two chains waiting at class adv, 32 threads (box 2: the 2^24 census, the calendar, the small-constant-multiplier calendar and tail, avalanche; box 1: the 2^32 census and the redraw census); nothing hand-started beyond three sub-11 s smoke runs. Rows at 49656c2e, 21:3x BST: model A is an FPGA LUT-area gain for a per-day build (multiplier adders), NOT a wall-time or op-count gain: under the chip model's 9,360 ops per item the per-day gain is 1.0 on every day for every GPU, the verifier and any chip with a general multiplier; against the exact median 226, P(model A at or above 1.1x) = 5.69e-4 = 2^-10.8 per day (the earlier 2^-7.9 used a provisional median of 231); model C (DSP) stays under 2^-20 at 1.1x (1.067x on 2^-15 of days); the 1.1x-on-2^-20 threshold is crossed by model A only, the same bounded class as AP-F4-1; worst real day 29337 = 2050-04-28 at 1.113x, 15 days over 1.1x in 100 years; RECONCILED with the attack-pass lane's F4 at 21:4x BST (F4 record section 9, both medians side by side): F4's NAF weight counted a carry digit at position 32 that a 32-bit multiplier never pays (0.333 digits per word, 5.3 adders per day), the whole of 231 against 226 and 12 against 15 days a century; the agreed figure is median 226, a 1.1x gain at cost A at most 205, 5.69e-4 of days (2^-10.8), 15 days a century, worst 2050-04-28 at 1.113x; the DSP-bound readings agree at 0 for k at least 2; F4's PASS against class v4 stands; the redraw rule for the next class takes adv-mixer-2's form; a redraw rule row (continue the stream and redraw all 40 draws if cost A is 205 or less, or a 2-adder MUL, or all ROT equal; about 22 days per 100 years redrawn) with the before fraction, the after fraction owed with the redraw census; no seed collisions or stream shifts; the 2^24 census matches the exact table on every class; all six plants fire. Running: the small-constant-multiplier calendar on box 2 (24 cores); the 2^32 census waiting on box 1. Tip 52a31815, 21:4x BST: all rows but two landed: model B (partial: 12.3 percent of words certified at 5 or fewer adders, 0.38 percent at 4 or fewer; the between-day spread is the certificate's reach, not a gain), ROT diffusion (every day and every plant at the uniform 0.500 by 2 applications, address bits with them, 8 sit between reads: gain 0, BOUND), the F4 reconciliation mirrored; the 2^32 census running on 32 leased build-1 cores since 21:42 BST (about 25 minutes), then the redraw census at 2^24 and 2^28; box 2 chain done; 0.12 box-hours so far. Ledger: one inline rm over its own claim directories at 21:36 BST, three minutes after the rule reached it; later deletions through script files. The coordinator wrongly chased this plan as overdue between 20:25 and 20:32 BST | pending | | | adv-mixer-3 | 37a08b6c, 19:4x BST | rows committed before the 20:21 BST kill (3cb6c1df and later): line-index bits uniform at 0 to 8 applications on day 20729; the SAC and linear bands clean at 2 to 8 applications on both days (a k = 1 statistic exists, the known single-application diffusion); rotational-XOR clean at 1 to 4 on both days; SAT at 1 application; THE ROUND MARGIN AS IT STANDS: no statistic survives 2 of the 8 applications between reads. Lost to the kill: SAC at 5 to 8 and its 2^27 rows, the 2^28 SAC-zero rows on 20733, the index census on 20733 at 2 to 8, CaDiCaL at 2 to 4; re-queued as queue 17 through the lease. Earlier: sweeps on both boxes from 19:42 and 19:47 BST (index census, SAC, differential, linear, rotational-XOR on days 20729 and 20733; the SAT model under CaDiCaL 3.0.1) | pending | | | adv-cache | 476e4516, 19:04 BST | 2c7bb6b4, 19:33 BST; FINAL 49ef7747, 19:50 BST: every row BOUND, every plant fired (the recompute curve monotone toward the full store, f = 1/2 at 1.26x the ops and 0.875x of the full-store chip's rate under equal silicon; no cheaper fill; chain avalanche full at every j; line index uniform over 160 day keys and about 1.6 x 10^10 reads; batching loses to the stride store from 32 MiB) | 19:5x BST, NO DISPUTE: Q1b, Q1c and Q4 stand as BOUND from the defender (the curve equals logs/queue-a/curve.log row for row; target 017e7037; ledger honest; energy columns from chip-model-v3 5.2); Q2 and Q3 were measured before the re-scope and stand as readings for adv-cache-2 to confirm or contradict, not as its verdict | 0.55 | | adv-cache-2 | 3d9bcece, 19:31 BST | tip 46551013, 21:2x BST: the 2^35-read line census PASS over 272 days; the 16,384-day weak-day scan PASS; the site finding is now a CLASS: 3 of 432 load sites (Devnet 3 site 0; era-fixed-20 site 11; era-drawn-2 site 13) concentrate item reads 1.26x to 1.45x at their top 0.1 percent, each attributed to the shadow block's last write to the load's source register (mul: the product low-bit law 0.25, 0.375, 0.4375 on bits 0 to 2, measured exactly; mulhi: a 52x hi16 bucket and one item read by 16 whole warps; sub), worth 0.03 to 0.1 percent of a hash's reads each; handed to adv-accept's freshness question in the report. MECHANISM, 23:1x BST: the same base program (shared epoch seed) is clean under the devnet era (stride rotation R = 29) and biased under drawn eras with R from 3 to 22: a product's biased low bits (P(bit 0) = 1/4, measured) survive the odd stride multiplier and the rotation places them at address bits R and up, inside the 28-bit item index unless R is 28 or more; the devnet era's R = 29 cuts them off, which is why 31 of 32 devnet-era programs are clean while 6 of 16 drawn-era programs show a site over 1.04x (2 over 1.2x, worst 1.51x); widened at 23:3x BST to 13 of 27 drawn-era programs with a site over 1.04x (8 over 1.2x; worst era-drawn-28 site 15 at 1.7451x, era-drawn-25 site 11 at 1.3571x) against 2 of 32 under the devnet era (R = 29), the 61-program table with full epoch and era hex, attempt, id, R and site handed to the v5 lane and going into the report's section 2.3; under the 2 GiB genesis dataset (D = 29) R = 29 would show it too; the price to a partial-store chip stays under 0.1 percent of a hash's reads per site. The v5 lane (23:1x BST) reads its (c''') floor on the 16 drawn-era programs and the devnet control at the 2^20 sample (adv-cache-2 handing it the recipes); for the record its 4,600-seed census ran across drawn eras (each f8 seed with its own era bytes, so R varied), so the 2.435 percent clean rejection rate already spans the R range. THE READ, 23:3x BST: the 0.995 floor refuses 0 of 29 adv-cache-2 programs read so far (24 drawn-era, era-fixed-20, four devnet-era controls); the six over 1.2x read 0.9965 (era-drawn-15 at 1.51x) to 0.9997 at their minimum site, the 1.04x to 1.2x band 0.9986 to 0.9998, the clean ones 0.9999 to 1.0000; every class v5 draw lands on the class v4 attempt. The v5 lane's reading: the distinct-index statistic sees concentration on FEW items (adv-accept's hot sets: 3 percent of a site's reads on 512 word indices), not a DIFFUSE excess over the top 0.1 percent of items (16,384 items), which is what the era-stride low-bit law produces; two instruments, two classes; the floor closes the first and does not reach the second. The remaining rows (era-drawn-25 to -28, the 32 devnet-era controls) land within the hour (log class-v5-harness/v5-listed-adv-cache-2-full.log). Line census at 2^35 + 3 x 2^33 reads all PASS; the 16,384-day weak-day scan PASS. Earlier: first rows 19:5x BST (report being pushed): tip 4f470d40 at 20:23 BST, about 0.95 box-hours, killed its one running census at 20:20 BST (11 of 32 drawn programs kept as partial), re-queue pending on the lease; two FINDING rows for the defender: Devnet 3 load site 0 (instruction 3) non-uniform at the item level (chi2/dof 3.70 at 2^26, top 0.1 percent at 1.449x its control, a fixed per-item weight from iteration 1, a low-bit bias of its source register; worth 0.1 percent of a hash's reads to a store); and the chip model's f = 0.25 and f = 0.5 partial-store rows overstate the recompute share at the measured window hit rates (0.883x and 0.838x of its ops per hash at the mean; 0.56x for Devnet 3's half; the full-store verdict unchanged). Earlier: Q1 line census at 2^31 reads PASS (segments +4.84 sigma against a control at +4.24; top 1 percent of lines 1.1198 against 1.1196 percent); Q3 steering PASS (worst cell 3.95 sigma); Q2 Devnet 3 at 2^24 nonces: fingerprint e510ad92b4d24846 reproduced through its mirror, items and lines clear against the window-model control (1.003x), one load site (site 0, instruction 3) non-uniform at chi2/dof 1.67 and 1.29x at its top 0.1 percent, worth 0.03 percent of a hash's reads; the window layer puts 36 to 45 percent of reads in one aligned quarter (model exact to 4 digits), being priced against the chip model's partial rows | pending | |