diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index 26d94756c..db0b30d5e 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -21,7 +21,7 @@ against the log before quoting it to the project lead. | # | Attack | Gate (same as 1.4) | Result so far | Status | |---|---|---|---|---| -| F1 | Shadow block compressibility and shortcut search | best compressed block within 5% of N on every program; no program over 10% compressible | 10^4 and 10^5 class v4 programs: saved instructions mean 0.62%, max 4.69% at 10^4 and 5.078% at 10^5 (1 of 100,000 over 5%, 0 over 10%); nothing folds or dedupes across the 27 passes; every saving is local peephole algebra that clang -O3 removes from the honest kernel too (IR counts match on the worst programs); 0 mismatches in 2 x 10^5 differential and verifier checks, z3 window proofs 0 counterexamples. AP-F1-1: the 0.078-point letter miss on one program, ruling asked. Record `docs/analysis/attack-pass/f1-shadow.md` | PASS on substance; AP-F1-1 letter miss, ruling asked | +| F1 | Shadow block compressibility and shortcut search | no compression of the shadow block beyond the honest compiler's simplification, measured against that compiler on the same program; the 27 repetitions never fewer than 27x (coordinator's ruling 7 Oct 2026, 12:3x UK; the plan's gate (1) and row F1 carry the same) | 10^4 and 10^5 class v4 programs: saved instructions mean 0.62%, max 5.078% at 10^5 (1 of 100,000 over 5%, 0 over 10%); nothing folds or dedupes across the 27 passes; every saving is local peephole algebra that clang -O3 removes from the honest kernel too (IR counts match on the worst programs), so against the compiler the compression is 0; 0 mismatches in 2 x 10^5 differential and verifier checks, z3 window proofs 0 counterexamples. AP-F1-1 routed to the v5 list as a shadow redundancy bound. Record `docs/analysis/attack-pass/f1-shadow.md` | PASS; AP-F1-1 on the v5 list | | F2 | Mixer round margin (SAT/MILP, 1 to 4 keyed applications) | no distinguisher or shortcut beyond 2 of the 8 applications | one application characterised (differential weight 10 to 12, linear 1, verified on the real code on three days); two applications: no trail at or below weight 20 to 24 within 7,200 s per job, the MSB and LSB families die at two; rotational-XOR no bias at one application; the multiply layer folds on 0 of 2^20 inputs, k applications cost k; k = 3, 4 general jobs closing on the box. Record `docs/analysis/attack-pass/f2-mixer.md` | PASS (effort-bounded; k = 3, 4 lines pending) | | F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | 0 of 64 and 0 of 1,024 lines under j+1 (exhaustive closure search, cross-checked by exhaustive pebbling at 10 lines, 10,240 pairs, 0 mismatches); both planted broken chains fire; curve monotone at both op counts; f=1 point 9,360 ops per item unchanged. Record `docs/analysis/attack-pass/f3-cache.md` | PASS | | F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | PASS against M2 (DSP-bound datapath): 0 of 2^28 days over 1.1x; planted weak days fire; every ROT and RC class 0. Bound finding AP-F4-1 on M1 (LUT adders): 5,476 of 2^24 days (3.26e-4) over 1.1x as the tail of a sum, no weak class; worst public-calendar day 29,337 at 1.121x, at most 12.1% more rate that day for a per-day LUT FPGA, 0 for any chip; redraw rule (NAF sum under 163 rejected) routed to the next class. Record `docs/analysis/attack-pass/f4-weakday.md` | PASS (v4); AP-F4-1 routed to the next class | @@ -267,7 +267,13 @@ relative to a card: no shortcut. The gate as written counts honest-compiler simp ways to close: re-word gate (1) and row F1 to "compressible beyond the honest compiler's own simplification" (the firms then attack chip-relative compression, which is the question), or a shadow-draw redundancy bound in the next class (reject a shadow with over 12 peephole-removable instructions per pass, rejection about 1e-5; class v4 is on -the live vote). Status: FINDING-OPEN by the letter, PASS on substance; the coordinator rules. +the live vote). Ruling (coordinator, 7 October 2026, 12:3x UK): both. Gate (1) and row F1 re-worded to "no +compression of the shadow block beyond the honest compiler's simplification, measured against that compiler on the +same program" (sent to the cryptanalysis lane for the plan and the firms' brief), under which the 5.078 percent +letter miss at honest-compiler parity is a PASS; and a shadow redundancy bound on the v5 generator's list beside +AP-F4-1 and AP-F8-1 (the generator refuses a shadow block whose honest-compiler simplification exceeds a stated +fraction; the v5 lane sets the fraction from F1's census), gated by F1's harness on 64 seeds of the v5 stream. +Status: F1 PASS; AP-F1-1 FIXED-AND-PASSED against v5 once the bound is in the v5 generator and F1's census passes. AP-F5-1 (algorithm and hash lane, ours; the ladder lane is closed). The k about 0.33 chip-efficiency figure is