diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index ae3957778..31485a359 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -28,7 +28,7 @@ against the log before quoting it to the project lead. | F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x at k=1 GDDR7 reproduces, 3.2x at k=0.5, 4.1x at k=0.3 (matches ledger M32); FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). FINDING: the k=0.33 figure is framed as the X9's measured core (M32) and a "measured class" (ladder branch ยง5a); the X9 was withdrawn before launch and never benchmarked. F2 hour SKIPPED: no AWS account | FIXED-AND-PASSED (sweep PASS; AP-F5-1 fixed and re-gated 7 Oct 2026: chip section re-run 2.1x at k=1 unchanged, identity grep 0 hits, site lane concurred); F2 hour SKIPPED-BY-DECISION (the project lead, 7 Oct 2026, 09:5x UK; plan 4.2 row F5 is the sweep only at 3714c2a0; the FPGA row stays the JEDEC-ceiling model row labelled unmeasured) | | F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | O-1.14 CLOSED on an i7-9700K (2019 desktop core): v4 6.006 ms avg, 6.334 cold max per warp; dr736 10.04 (the known-fail fires); box proxies 5.06 / 8.23. Worst-case search over 10^5 owed | RUNNING (O-1.14 closed) | | F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | (b) census PASS at 2^24 seeds: no class over 1.1x, stride bijective on all draws, R, pos and M uniform (chi-square 38.5 on 30 dof), op-weight corners 1.0x, planted cases fire; (c) 64-bit day-key seeding PASS as the spec intends, 0 collisions in 2^17; (a) re-roll harness INCOMPLETE by the plan's allowance: the node's era seed is a plain chain block hash (`seed_below`), the cut is grindable with one block of hash at no delay (1 of 6 epochs) and immune past one block interval (0 of 6), and the 1-hour VDF of spec 4.4 is not in the node; the era-VDF lane builds it with `reroll.mjs` as its gate. Record `docs/analysis/attack-pass/f7-era.md` | PASS (b, c); INCOMPLETE (a) pending the era VDF, a freeze precondition | -| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model (coordinator, 7 Oct 2026, 11:2x UK; the plan's 1.4 gate (4) and row F8 carry the same sentence) | interim, phase D at 2^26 nonces: top 0.1% of items take 0.520% of reads vs 0.115% uniform (4.05x), top 1% 2.49% (1.37x), one item 153x the mean, read site 15 feeds 6.37% of its reads into the hot 0.1% in all 8 iterations; shortcut under 1% of rate today. AP-F8-1: the 4.05x is largely the designed per-site windows of layer 8 (spec 1.13.1); the gate is now the window model from the program's own draws, the finding stays open only for the excess beyond it (the 153x item, or a low-entropy source at site 15 if the 64-seed census shows one); no generator change to v4 (on the live vote) | FINDING (open on the excess only) | +| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds; no hot set under 1% of items beyond the model | AP-F8-1 resolved to a mechanism: the window null gives 1.39x at the top 0.1% (not 4.05x); the rest is a lossy LOAD SOURCE (an `or` writer feeding site 15's load; the all-ones source is item 0xca5b92, 7 of 7 next-hottest predicted), a fault class in the acceptance rule's blind spot carried by 96.6% of v4 programs; hot-set bound at most 1.067x under rule (c); no v4 change, v5 generator item with phase E as its gate; phase E (64 seeds) pending | FINDING (mechanism ours; v5 fix pending) | | F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | edges reproducible via `accept`; grinding measurement needs PC 2's 5090 or a rented pod | BLOCKED (PC 2 go / pod) | | F10 | Ladder signal monotonicity harness | no step without 90% over 7 windows in either direction | pending fast-time harness | RUNNING | @@ -305,7 +305,28 @@ the hot-set bound (a 0.1 percent cache, about 1.7 MB of SRAM, under one percent Gate wording settled (coordinator, 11:2x UK): plan 1.4 gate (4) and row F8 now read "uniform within the window model of spec 1.13.1, layer 8; the excess beyond it within 6 sigma over 64 seeds", carried into the plan's scope text by the cryptanalysis lane so the firms are briefed on the windows before they start. -Status: FINDING-OPEN on the excess only; the Counter ASIC lane's window model with numbers and F8's phase E close it. +Mechanism (hash lane, branch `ca3-v4-uniform` 095f84a7, `docs/analysis/ca3-v4-uniform.md`, harness +`tools/ca3-v4-uniform`, 7 October 2026, 12:3x UK): the windows-union null (a Poisson mixture at 416 / 288 / 736 / 608 +reads per item by quarter from the program's 16 draws) moves the top 0.1 percent from 0.115 to 0.160 percent, 1.39x, +not 4.05x; every per-site row of F8's attribution except site 15 is the window model. The rest is the LOAD SOURCE: +site 15 is the load at 63 reading r6, whose last writer is `or` at 61 (r6 = r6 | r4), so the source is all-ones with +probability about (3/4)^32 per read; under the era map x = 0xffffffff is item 0xca5b92, the hottest item exactly, and +the next seven hottest are the seven one-zero-bit sources whose zero survives the window mask (7 of 7); the measured +count fixes the bias at p = 0.7585 per bit. The class: a load whose source's last writer is lossy (or: 0.30 percent +of a site's reads on 0.1 percent of values; mul, trailing zeros: 1.07; mulhi: 0.79; an or of an or: about 4.5). +Static census of 1,024 chain-shaped v4 programs: 96.6 percent carry a lossy-sourced load (48.5 percent or, 4.9 +percent an or chain, 73 percent mul, 64 percent mulhi); predicted S_0.1 median 0.45, 90th 0.88, 99th 5.3, max 9.8 +percent; p1 / p2 / p3 predicted 0.58 / 0.32 / 4.72 against measured 0.52 / 0.27 / 4.60. The fault sits in the +acceptance rule's blind spot: part (a) takes any write as fresh, part (c) counts saturation on final values only. +Consequence: the 1.2x-against-window gate fails 96.6 percent of today's programs, so it is withdrawn as a v4 gate and +becomes the v5 generator item's gate (draw a load's source from registers whose last writer injects; a dynamic check +counting saturated load sources), with F8's phase E as its test. Chip side: the top 0.1 percent of items is 1.07 MB +of SRAM (0.53 mm^2, about USD 0.25) serving 0.52 percent of p1's reads and 4.6 percent of p3's, at most 1.005x and +1.048x in rate; the ceiling under rule (c)'s 120-of-128 floor is one site repeating its item in all 8 iterations, +6.25 percent of reads, 1.067x. That 1.067x is the v4 hot-set bound the record carries. No generator change to v4; +the hash lane takes the two flip options priced to main. +Status: FINDING-OPEN: mechanism found and ours; FIXED-AND-PASSED when the v5 rule is in accept.rs and phase E passes +against it; v4 carries the documented null, the fault class and the 1.067x bound into the firms' brief. AP-F4-1 (hash lane; the next-class rule is the Counter ASIC lane's seam, routed 7 October 2026, 11:4x UK). A bound on the day-key draw, not a weak class: on the M1 metric (every multiply in LUT adders, adders per mixer application