attack-pass: internal F1 to F10 pass doc, F5 sweep PASS and F6 proxy landed
The internal cryptanalysis pass before the freeze tag cryptanalysis-target-1 (docs/plans/cryptanalysis.md 4.2). Ten rows with method, known-failed shape, gate and status. Landed: F5 chip-model sweep (the 2.1x per joule edge over the 5090 at v4 and k=1 reproduces exactly on the GDDR7 measured-anchor column; AWS F2 hour skipped, no AWS account on this Mac; X9 k=0.33 carried as a claimed pessimistic bound from a withdrawn design, with the NRE-recovery economic row); F6 verifier v4 average 4.90 to 5.06 ms one-core cold, 8.23 ms half-core proxy, under the 10 ms gate (worst-case 10^5 search and the laptop run owed). The rest are RUNNING or, for F9 header grinding, BLOCKED on the PC 2 or rented-pod go. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
107090dba9
commit
b0229e89c2
1 changed files with 165 additions and 0 deletions
165
docs/analysis/attack-pass-2026-10.md
Normal file
165
docs/analysis/attack-pass-2026-10.md
Normal file
|
|
@ -0,0 +1,165 @@
|
|||
# Internal attack pass before the freeze (F1 to F10)
|
||||
|
||||
The internal cryptanalysis pass of `docs/plans/cryptanalysis.md` section 4.2, run before the freeze tag
|
||||
`cryptanalysis-target-1`, so the paid engagement confirms rather than discovers. the project lead's word, 7 October 2026:
|
||||
"make sure they find ZERO flaws". Every finding is ours, fixed and re-gated, before any firm starts.
|
||||
|
||||
Target: the hash class the chain runs after 0.3.15's flip, `igneum-pow` generator v4 `V4_CLASS` = `mx8+sh256x27`
|
||||
(`LoadClass::MX8`, `ShadowClass { instrs: 256, reps: 27 }`), the acceptance rule, the verifier, the era draw,
|
||||
the latency-shadow dataset and ladder, the chip and FPGA cost model. Scope and gates are section 1.1 and 1.4 of
|
||||
the plan, the same tests the firm is held to.
|
||||
|
||||
Lane: attack-pass, worktree `igneum-wt-attack`, branch `attack-pass` from `origin/master` `ab99e5e3`.
|
||||
Binary built on igneum-build-1 (ELF x86-64, `igneum-pow` 0.2.0, sha256 6d2867...1a9ebe5) and run there under
|
||||
the box's slots; model and era work from `sim/horizon/algorithm/model.py` and `infra/fast-time/`. Each row below
|
||||
carries the method, the known-failed shape where one exists, the result with numbers, and PASS, RUNNING,
|
||||
BLOCKED or FINDING. The freeze tag waits on every row reading PASS or FIXED-AND-PASSED. Main checks every number
|
||||
against the log before quoting it to the project lead.
|
||||
|
||||
## Status board
|
||||
|
||||
| # | Attack | Gate (same as 1.4) | Result so far | Status |
|
||||
|---|---|---|---|---|
|
||||
| F1 | Shadow block compressibility and shortcut search | best compressed block within 5% of N on every program; no program over 10% compressible | pending evidence map + box run | RUNNING |
|
||||
| F2 | Mixer round margin (SAT/MILP, 1 to 4 keyed applications) | no distinguisher or shortcut beyond 2 of the 8 applications | pending evidence map (ca2-mixer) + box run | RUNNING |
|
||||
| F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | pending evidence map (ca2-cache) + box run | RUNNING |
|
||||
| F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | pending box census | RUNNING |
|
||||
| F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 ("2.1x per joule over the 5090 at v4, k=1") holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x reproduces exactly at k=1 GDDR7; FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). F2 hour SKIPPED: no AWS account on this Mac | PASS (sweep); F2 SKIPPED |
|
||||
| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | v4 average 4.90 to 5.06 ms one-core cold, 8.23 ms half-core proxy (under 10 ms). Worst-case search over 10^5 and laptop run owed | RUNNING |
|
||||
| F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | model era section: re-roll needs a 1,800x VDF (300x beats only the epoch); weakest op-weight corner about 20% of shadow datapath energy, 0 chip effect. Harness + 2^20 census owed | RUNNING |
|
||||
| F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | largest bucket within 6 sigma of uniform; no hot set under 1% of items | pending box census | RUNNING |
|
||||
| F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | edges reproducible via `accept`; grinding measurement needs PC 2's 5090 or a rented pod | BLOCKED (PC 2 go / pod) |
|
||||
| F10 | Ladder signal monotonicity harness | no step without 90% over 7 windows in either direction | pending fast-time harness | RUNNING |
|
||||
|
||||
## The rows
|
||||
|
||||
### F1. Shadow block compressibility and shortcut search (hash lane)
|
||||
|
||||
Method: over 10^4 class v4 programs, constant folding, dead-register elimination, common subexpressions across the
|
||||
27 repetitions, linear sub-block detection, SAT equivalence on reduced blocks; the minimum op count per program
|
||||
against N. Known-failed shape: a shadow that constant-folds or dedupes across its 27 identical passes so a chip
|
||||
pays fewer than 55,296 shadow instructions per hash. Entry point: `igneum-pow show --program-class v4` prints the
|
||||
256-instruction shadow (op mix add=47 rotl=30 xor=30 shfl=29 mad=27 mul=22 sub=21 rotr=20 mulhi=18 or=12 on the
|
||||
genesis seed). Gate: best compressed block within 5% of N on every program; no program over 10% compressible.
|
||||
Result: RUNNING. What a failure moves: an acceptance-rule line for the shadow block (rule (c) runs the block),
|
||||
packs re-cut.
|
||||
|
||||
### F2. Mixer round margin (hash lane, on the box)
|
||||
|
||||
Method: SAT or MILP differential and linear search on 1 to 4 keyed applications with drawn rotations; rotational-XOR
|
||||
on the ARX layer; the fold of the multiply layer across applications checked algebraically. Known-failed shape: a
|
||||
differential or linear trail or an algebraic fold that distinguishes or shortcuts more than 2 of the 8 applications
|
||||
between dependent reads. Gate: no distinguisher or shortcut beyond 2 of the 8 applications. Result: RUNNING (prior
|
||||
`ca2-mixer` evidence to be re-gated). What a failure moves: `mixer_mult` 16 or a shape change; verifier re-measured.
|
||||
|
||||
### F3. Chained cache j+1 bound and storage-vs-recompute curve (hash lane, on the box)
|
||||
|
||||
Method: exhaustive search on a 2^10-line model segment for a line derivable without an earlier line; the curve from
|
||||
f = 1/64 to 1 in ops per item. Known-failed shape: a line (s, j) computable in fewer than j+1 block evaluations
|
||||
without an earlier line (the MTP address-steering break shape). Gate: no derivation under j+1 blocks; curve monotone;
|
||||
f=1 point unchanged. Result: RUNNING (prior `ca2-cache` evidence to be re-gated). What a failure moves: the chain
|
||||
construction (a second feed-forward or a cross-segment tie).
|
||||
|
||||
### F4. Weak-day census over 2^24 day keys (hash lane, on the box)
|
||||
|
||||
Method: 2^24 day keys through `MixParams::with_shape`; the ROT classes (all equal, complementary pairs, small
|
||||
amounts), MUL low weight, RC structure, each per-day gain measured on the box verifier. Known-failed shape: a day
|
||||
key whose drawn ROT/MUL/RC gives a fixed datapath a gain over 1.1x (the "weaker authorized parameters" class,
|
||||
Kudelski 2019). Gate: the fraction of days with any gain over 1.1x under 2^-20. Result: RUNNING. What a failure
|
||||
moves: a rejection-and-redraw rule on the draws.
|
||||
|
||||
### F5. Chip-model sweep and the FPGA hour (algorithm lane)
|
||||
|
||||
Method: `sim/horizon/algorithm/model.py` over k 0.2 to 1.5, tFAW 12 and 28 ns, HBM4 2.3 and 21.4 G reads per
|
||||
stack, amortisation 1 to 3 years, electricity USD 0.05 to 0.15 per kWh; and the AWS F2 hour replacing the FPGA
|
||||
ceiling row with a measurement. Known-failed shape: an input of the published model that, when corrected, lifts the
|
||||
f=1 chip's per-joule edge over the 5090 above the published 2.1x at k=1.
|
||||
|
||||
Gate: the published sentence (evidence row 17) holds across the sweep; the FPGA row under 27 M reads/s/W.
|
||||
|
||||
Result (sweep): PASS. The model's measured-anchor column (GDDR7, the 5090 reads 82% of its ceiling) gives the
|
||||
f=1 chip's v4 per-joule edge over the RTX 5090 bench row as 4.1x / 3.2x / 2.1x / 1.5x at k = 0.3 / 0.5 / 1 / 1.5.
|
||||
At k = 1 the figure is 2.1x, exactly the published sentence. The higher HBM3 and HBM4 columns rest on an 8-activate
|
||||
per 12 ns window that JEDEC HBM2 timings (4 per 28 ns) do not support; the model already states GDDR7 is the column
|
||||
to quote, so the sentence stands with its bound.
|
||||
|
||||
FPGA row: the HBM2 FPGA ceiling is 2.3 to 2.9 G reads/s (measured Shuhai U280, FCCM 2020, equal to the JEDEC
|
||||
tFAW-bound 2.3 G/s), 10 to 21 M reads/s/W at 115 to 150 W, 0.30 to 0.47x of the 5090 per watt. Under the 27 M
|
||||
reads/s/W gate. The AWS F2 hour is SKIPPED: there is no AWS account or `aws` CLI on this Mac, so the measurement
|
||||
cannot be taken here; the row stays the literature-bound figure and the firm is told the F2 measurement was not
|
||||
run internally.
|
||||
|
||||
X9 note (coordinator, 7 October 2026): Bitmain's Antminer X9 (RandomX ASIC, 1 MH/s, 2,472 W, about USD 5,600) was
|
||||
announced and, per pcpraha.cz and r/MoneroMining, withdrawn before launch. Its implied core efficiency (k about
|
||||
0.33) is a CLAIMED, unmeasured figure from a design that never shipped or was benchmarked. It is carried as the
|
||||
pessimistic bound, not as a calibration point. At k = 0.33 the sweep reads the GDDR7 v4 edge near 4.0x, inside the
|
||||
range already modelled; it does not move the k = 1 published sentence.
|
||||
|
||||
Economic row the withdrawal implies: a recompute chip at a 3x fixed-function factor against a CPU and GPU fleet
|
||||
must recover its NRE (low to mid seven figures at a modern node, `chip-model-v3.md`) and carry a fork threat (a
|
||||
class change at 95% miner signal can redraw the datapath the chip bakes in). The X9 at 2.47 J per KH against a
|
||||
RandomX CPU fleet did not clear that bar at Monero's hash and price; the same arithmetic against Igneum's class v4,
|
||||
with the shadow block and the automatic era draw as extra firmware risk, is why the chip model's verdict is a
|
||||
deliverable and not a courtesy (plan 2.3). This row is the pessimistic case, not a measured gain.
|
||||
|
||||
### F6. Verifier worst case (algorithm lane)
|
||||
|
||||
Method: 10^5 class v4 programs timed on the box one-core and half-core proxies for the slowest warp (base program
|
||||
and shadow block), plus the O-1.14 laptop run (the Windows `igneum-pow` build on the box, the relay, `bench
|
||||
--warps 50`). Known-failed shape: a drawn program whose verifier warp exceeds 10 ms cold (the acceptance rule bounds
|
||||
the miner's side, not the verifier's; `dr736` already FAILs at 10.51 ms cold one-core, but it is not the shipping
|
||||
class). Gate: the worst program under 10 ms cold on the half-core proxy and on the laptop.
|
||||
|
||||
Result (average, verified on the box): class v4 `mx8+sh256x27` runs 4.90 to 5.06 ms per warp cold on one EPYC
|
||||
9454P core (nice 19, taskset), 8.23 ms on the half-core proxy (both SMT siblings busy). Under 10 ms. Status
|
||||
RUNNING: the 10^5-program worst-case search and the O-1.14 laptop relay run are owed before the row reads PASS.
|
||||
What a failure moves: an acceptance-rule bound on verifier cost; the ladder's ceiling set from the measured core.
|
||||
|
||||
### F7. Era-draw bias harness and census (node lane harness, hash lane census)
|
||||
|
||||
Method: the fast-time 3-node network (`infra/fast-time/`) with an adversary withholding or publishing the last blue
|
||||
block before C_era(n) to re-roll the draw; a census of 2^20 era seeds for stride, ROT and weight-perturbation
|
||||
classes with gain over 1.1x; the 64-bit seeding of the day-key stream against the spec's intent. Known-failed shape:
|
||||
a re-roll of the era draw inside the 2 s publish window, or an era class (stride bijection, all-equal ROT, low-weight
|
||||
M) with a chip gain. Gate: no re-roll inside the publish window; no era class with gain over 1.1x at a fraction over
|
||||
2^-20; the draw's input set as the spec states it.
|
||||
|
||||
Result (model, from the era section): re-rolling by withholding needs the 3,600 s VDF evaluated inside the 2 s
|
||||
publish window, a 1,800x faster evaluator; the spec's margin table gives 300x, which beats only the epoch, not the
|
||||
era. Forging the checkpoint needs 20 days of 100% hash. The weakest op-weight corner (fewest multiplies, 16 of 75)
|
||||
is about 20% of the shadow's datapath energy and 0 on the memory side, and the GPU moves the same way. The fast-time
|
||||
re-roll harness and the 2^20 census are owed. Status RUNNING. What a failure moves: the draw procedure or the C_era
|
||||
cut rule; a redraw rule for the era stream.
|
||||
|
||||
### F8. Uniformity censuses (hash lane, on the box)
|
||||
|
||||
Method: the line-index distribution over 2^28 derivations; distinct lines per hash and per warp on 10^6 nonces of
|
||||
three programs; the cross-hash item histogram of one epoch. Gate: the largest bucket within 6 sigma of uniform; no
|
||||
hot set under 1% of items. Result: RUNNING. What a failure moves: the mask or the fold; packs re-cut.
|
||||
|
||||
### F9. Acceptance edges and header grinding (hash lane; one PC 2 job)
|
||||
|
||||
Method: the 39 edge disagreements reproduced and bounded; a search over 10^6 seeds for programs that pass rule (c)
|
||||
with a hot set under 1%; the header-grinding search cost against its DRAM-locality gain measured on PC 2's RTX 5090
|
||||
(one job through `tools/build-job.mjs`). Known-failed shape: a seed grind that steers a program to a hot cache set
|
||||
for DRAM locality, or an edge where the closed-form stand-in disagrees with the live verifier in the attacker's
|
||||
favour. Gate: zero passing programs with a hot set under 1%; the grinding gain under 1% of rate at any search cost.
|
||||
|
||||
Result: the `accept` path reproduces per-seed verdicts (genesis seed: 1 candidate ACCEPTED, bias max 54, 0
|
||||
saturated). The header-grinding cost-versus-gain measurement needs a 5090. Status BLOCKED on the go decision: use
|
||||
PC 2's 5090 through a relay run job only if PC 2 is online and mining is unaffected, else a rented pod under the
|
||||
standing fleet budget. What a failure moves: the closed-form stand-in replaced by the live verdict at the edges; a
|
||||
locality term in rule (c).
|
||||
|
||||
### F10. Ladder signal monotonicity (node lane)
|
||||
|
||||
Method: the fast-time harness with a weight that steps the ladder down and never up, and an 89% signal; the step
|
||||
rule's monotonicity and its memoisation per seed block. Known-failed shape: a chip owner stepping the ladder down
|
||||
(cheaper N) without the 90% threshold, or a step registered under 90%. Gate: no step without 90% over 7 windows in
|
||||
either direction; a step down needs the same. Result: RUNNING. What a failure moves: the step rule's text in spec 01
|
||||
before the ladder is frozen.
|
||||
|
||||
## Ledger rows
|
||||
|
||||
No findings yet. Any finding is logged here and in `docs/fud-ledger.md` with its owning lane (hash and algorithm:
|
||||
fixed in `igneum-pow` behind a test and re-gated; node: the node lane) before the row is marked FIXED-AND-PASSED.
|
||||
Loading…
Reference in a new issue