diff --git a/docs/plans/cryptanalysis/in-house-pass.md b/docs/plans/cryptanalysis/in-house-pass.md index 9aebe985..9fc96e04 100644 --- a/docs/plans/cryptanalysis/in-house-pass.md +++ b/docs/plans/cryptanalysis/in-house-pass.md @@ -161,7 +161,7 @@ It is not an independent review and is never called one. Nothing is sent outside | adv-cache | 476e4516, 19:04 BST | 2c7bb6b4, 19:33 BST; FINAL 49ef7747, 19:50 BST: every row BOUND, every plant fired (the recompute curve monotone toward the full store, f = 1/2 at 1.26x the ops and 0.875x of the full-store chip's rate under equal silicon; no cheaper fill; chain avalanche full at every j; line index uniform over 160 day keys and about 1.6 x 10^10 reads; batching loses to the stride store from 32 MiB) | 19:5x BST, NO DISPUTE: Q1b, Q1c and Q4 stand as BOUND from the defender (the curve equals logs/queue-a/curve.log row for row; target 017e7037; ledger honest; energy columns from chip-model-v3 5.2); Q2 and Q3 were measured before the re-scope and stand as readings for adv-cache-2 to confirm or contradict, not as its verdict | 0.55 | | adv-cache-2 | 3d9bcece, 19:31 BST | first rows 19:5x BST (report being pushed): tip 4f470d40 at 20:23 BST, about 0.95 box-hours, killed its one running census at 20:20 BST (11 of 32 drawn programs kept as partial), re-queue pending on the lease; two FINDING rows for the defender: Devnet 3 load site 0 (instruction 3) non-uniform at the item level (chi2/dof 3.70 at 2^26, top 0.1 percent at 1.449x its control, a fixed per-item weight from iteration 1, a low-bit bias of its source register; worth 0.1 percent of a hash's reads to a store); and the chip model's f = 0.25 and f = 0.5 partial-store rows overstate the recompute share at the measured window hit rates (0.883x and 0.838x of its ops per hash at the mean; 0.56x for Devnet 3's half; the full-store verdict unchanged). Earlier: Q1 line census at 2^31 reads PASS (segments +4.84 sigma against a control at +4.24; top 1 percent of lines 1.1198 against 1.1196 percent); Q3 steering PASS (worst cell 3.95 sigma); Q2 Devnet 3 at 2^24 nonces: fingerprint e510ad92b4d24846 reproduced through its mirror, items and lines clear against the window-model control (1.003x), one load site (site 0, instruction 3) non-uniform at chi2/dof 1.67 and 1.29x at its top 0.1 percent, worth 0.03 percent of a hash's reads; the window layer puts 36 to 45 percent of reads in one aligned quarter (model exact to 4 digits), being priced against the chip model's partial rows | pending | | | adv-cache-3 | 9fdd4031, 19:49 BST | report 091edc34, 20:29 BST, 0.04 slot-hours; FINDING, bookkeeping not a break: the exact pebbling optimum (DP, checked against exhaustive search at 10 to 16 lines) sits under the "hold every k-th line" curve the chip model and adv-cache's Q1b table use: 16.0 against 31.5 blocks per read at f = 1/64 (the one held line belongs at line 32, not line 0), 10.5 against 15.5 at 2/64, 6.09 against 7.5 at 4/64, 3.17 against 3.5 at 8/64, 1.45 against 1.5 at 16/64, equal from f = 1/2; so a chip holding 1/64 of the cache pays 9.3x the item's ops, not 17.4x; at f = 1/2 nothing moves and the SRAM column stands (a line owed in chip-model-v3 and in adv-cache's table). Plant caveat stated: the per-bit bias and 512 x 512 correlation statistics do not fire at one or two double rounds (worst 4.5 sigma at 2^16 lines); the firing known-failed shapes for the relation class are the GF(2) rank (1,004 of 1,025 at one double round, 17 at zero), the flip table (6,985 zero cells at one double round) and no-feedforward on the inversion; a larger flip table is being added. First rows 20:2x BST: every gate PASS, every plant fired (0 of 65,536 lines under j + 1 at 64 and at 1,024 lines on two day keys; GF(2) rank 1,025 of 1,025 at j = 1, 2, 32, 63, 1,023; no zero cell in the 512 x 512 dependence table; 0 inversions; feed-forward relations over 4 days x 2^20 lines worst bias 3.58 sigma, worst correlation cell 4.83 sigma of 262,144; the pebbling optimum curve monotone with 9,360 ops at f = 1, the skip-edge plant fires; cross-segment and cross-day worst 5.00 sigma); its 87-core build-2 lease released at 20:24:38 BST for the v5 census, the w = 2 image census partial at depth 8 of 64, the rest queued behind any v5 waiter. Earlier: its three definitions (90 to 92) claimed 19:49:54 BST, by itself on the timing (owner files were not yet the rule); adv-cache offers its chain-skip, pebble and ffrel implementations on branch adv-cache as a harness, and does not run them | pending | | -| adv-accept | d2bc4dc8, 19:1x BST | a22d5ba0, 19:51 BST, FINDING-class row: one accepted class v4 program (F8 label-space seed 100767, id 9d68e6286fc817d4, attempt 2) passes every part of the frozen rule and flags the f8 hot-set gate on the live dataset at 2^24 nonces (X at 0.1 percent +0.155, X/f 1.55, top 0.1 percent at 2.05x the window model, 6-sigma +295); the four lowest stand-in-ratio seeds of 4,600 accepted programs all beyond 1.2x live (1.29x to 2.05x), 23 random accepted programs at most 1.043x; attribution one load site (instruction 23, source r6, quarter window) sending 3.35 percent of its reads to items at multiples of 2^19, (c') saturation 0.013 percent there; the lane's price: a 1 MB hot copy serves 0.31 percent of loads instead of 0.15, a 1.002x gain, no chip-model row moves; "a real distinguisher and a cheap seed selector, not an exploitable bypass". Q2 stand-in gap BOUND so far (agreement to 2e-4 at 2^20 on 4 programs plus a firing plant; 50-program widening running). 20:06 BST, tip 12e0e9fa: Q2 BOUND landed on 54 accepted programs (closed-form and live per-site ratios agree to 0.0004 at 2^20, mean min-ratio gap 0.00002, 0 verdict disagreements, (c) metrics agree to 0.019 of 128; no steering through the stand-in gap); the selector read widened and honest: of the 8 lowest-ratio seeds measured live, 6 beyond the 1.2x gate and 2 not (103378 at 1.157x, 105756 at 0.9996x), so the 256-unit stand-in ratio is a noisy selector at the 0.996 level; random control 0 of 4 beyond (max 1.0034x); 17 lowest and 16 random rows running at about 7 minutes each; the class v5 exemplar check and the repeated-index read queued behind the lock. Row 90 (adv-accept-3's attempts census) claimed and running. Killed every run at 20:21 BST (both shards, both adv-live chains, the census, the attempts census), 0 binaries alive, partial kept: 23,321 accepted-program rows, 17 live rows at 2^24 (11 lowest-ratio seeds: 6 beyond 1.2x, 5 within; 11 random: 1 beyond), Q2 BOUND on 54; re-queue order through the lease: the shards from their frontiers, the 14 and 9 remaining live rows, the class v5 exemplar check, the repeated-index read, row 90 | 19:5x BST, FINDING CONFIRMED, bounded, no dispute on the numbers (read against live-confirm-16m.log): (c'') passes at ratio 0.9988, inside the clean spread, the shape of the four-seed tail AP-F8-1 left unattributed; the source is zero in 0.0126 percent of evaluations (under (c')'s 1 percent) and the hot items are the images of small source values under the era stride; the class is a value-level constant from a lineage-fresh writer (a mad at instruction 4), which neither the lineage rule nor the per-site ratio at 2^20 reaches. NEW and the finding's substance: the stand-in ratio is a cheap seed selector without the live dataset, and one member of the unattributed tail is now attributed by value. Routing: FINDING (bounded) on class v4 sub-version 3, no change to the frozen object, chip gain nil; the fix question (a value-level source test at the live-dataset scale, or a per-site hot-item test in acceptance) goes to class v5 / 0.3.23 beside AP-F4-1 and AP-F1-1; taken to main as an exception. Asked of the lane's final: the selector's false-positive rate over at least 20 low-ratio seeds; whether the seed reads hot under class v5's state-derived dataset. ANSWERED 20:37 BST: under class v5 (vendored class-v5 igneum-pow, generator 5, id 2fd83dbae09c366d, dataset keyed by the Devnet 3 v5 pack's state stream) at 2^24 nonces the seed reads the SAME hot set as under v4 (X at 0.1 percent +0.15514 against +0.15503, 2.046x against 2.045x, the same eight hottest items at multiples of 2^19, site 6 at 3.36 percent of its reads; plant fired at 25.7x; 589 warps agree with the library): the concentration is the program's dataflow at site 6 plus the era stride, not the dataset's values, so class v5's dataset change does not touch the finding and the price stays 1.002x; the acceptance-side fix is the only lever. DEFENDER'S READ, 20:4x BST: taken, and it is the CONFIRMING ROW for the class v5 fix (c'''), NOT a v5 finding: id 2fd83dbae09c366d is the pre-(c''') class v5 draw at attempt 2 (the vendored class-v5 igneum-pow before ab6f980b); under the frozen v5 rule the same seed is refused at attempt 2 by (c''') naming site 6 at 0.991 and the draw lands on attempt 4 (734fbb8e3e4cd20f), as the v5 lane's known-failed test read green at 20:33 BST; the lever is the acceptance floor, now 0.995 keyed on the state flag; the number still owed on the fix is the census's clean rejection rate, from the v5 lane | about 1.6 | +| adv-accept | d2bc4dc8, 19:1x BST | a22d5ba0, 19:51 BST, FINDING-class row: one accepted class v4 program (F8 label-space seed 100767, id 9d68e6286fc817d4, attempt 2) passes every part of the frozen rule and flags the f8 hot-set gate on the live dataset at 2^24 nonces (X at 0.1 percent +0.155, X/f 1.55, top 0.1 percent at 2.05x the window model, 6-sigma +295); the four lowest stand-in-ratio seeds of 4,600 accepted programs all beyond 1.2x live (1.29x to 2.05x), 23 random accepted programs at most 1.043x; attribution one load site (instruction 23, source r6, quarter window) sending 3.35 percent of its reads to items at multiples of 2^19, (c') saturation 0.013 percent there; the lane's price: a 1 MB hot copy serves 0.31 percent of loads instead of 0.15, a 1.002x gain, no chip-model row moves; "a real distinguisher and a cheap seed selector, not an exploitable bypass". Q2 stand-in gap BOUND so far (agreement to 2e-4 at 2^20 on 4 programs plus a firing plant; 50-program widening running). 20:06 BST, tip 12e0e9fa: Q2 BOUND landed on 54 accepted programs (closed-form and live per-site ratios agree to 0.0004 at 2^20, mean min-ratio gap 0.00002, 0 verdict disagreements, (c) metrics agree to 0.019 of 128; no steering through the stand-in gap); the selector read widened and honest: of the 8 lowest-ratio seeds measured live, 6 beyond the 1.2x gate and 2 not (103378 at 1.157x, 105756 at 0.9996x), so the 256-unit stand-in ratio is a noisy selector at the 0.996 level; random control 0 of 4 beyond (max 1.0034x); 17 lowest and 16 random rows running at about 7 minutes each; the class v5 exemplar check and the repeated-index read queued behind the lock. Row 90 (adv-accept-3's attempts census) claimed and running. Killed every run at 20:21 BST (both shards, both adv-live chains, the census, the attempts census), 0 binaries alive, partial kept: 23,321 accepted-program rows, 17 live rows at 2^24 (11 lowest-ratio seeds: 6 beyond 1.2x, 5 within; 11 random: 1 beyond), Q2 BOUND on 54; re-queue order through the lease: the shards from their frontiers, the 14 and 9 remaining live rows, the class v5 exemplar check, the repeated-index read, row 90 | 19:5x BST, FINDING CONFIRMED, bounded, no dispute on the numbers (read against live-confirm-16m.log): (c'') passes at ratio 0.9988, inside the clean spread, the shape of the four-seed tail AP-F8-1 left unattributed; the source is zero in 0.0126 percent of evaluations (under (c')'s 1 percent) and the hot items are the images of small source values under the era stride; the class is a value-level constant from a lineage-fresh writer (a mad at instruction 4), which neither the lineage rule nor the per-site ratio at 2^20 reaches. NEW and the finding's substance: the stand-in ratio is a cheap seed selector without the live dataset, and one member of the unattributed tail is now attributed by value. Routing: FINDING (bounded) on class v4 sub-version 3, no change to the frozen object, chip gain nil; the fix question (a value-level source test at the live-dataset scale, or a per-site hot-item test in acceptance) goes to class v5 / 0.3.23 beside AP-F4-1 and AP-F1-1; taken to main as an exception. Asked of the lane's final: the selector's false-positive rate over at least 20 low-ratio seeds; whether the seed reads hot under class v5's state-derived dataset. ANSWERED 20:37 BST: under class v5 (vendored class-v5 igneum-pow, generator 5, id 2fd83dbae09c366d, dataset keyed by the Devnet 3 v5 pack's state stream) at 2^24 nonces the seed reads the SAME hot set as under v4 (X at 0.1 percent +0.15514 against +0.15503, 2.046x against 2.045x, the same eight hottest items at multiples of 2^19, site 6 at 3.36 percent of its reads; plant fired at 25.7x; 589 warps agree with the library): the concentration is the program's dataflow at site 6 plus the era stride, not the dataset's values, so class v5's dataset change does not touch the finding and the price stays 1.002x; the acceptance-side fix is the only lever. DEFENDER'S READ, 20:4x BST: taken, and it is the CONFIRMING ROW for the class v5 fix (c'''), NOT a v5 finding: id 2fd83dbae09c366d is the pre-(c''') class v5 draw at attempt 2 (the vendored class-v5 igneum-pow before ab6f980b); under the frozen v5 rule the same seed is refused at attempt 2 by (c''') naming site 6 at 0.991 and the draw lands on attempt 4 (734fbb8e3e4cd20f), as the v5 lane's known-failed test read green at 20:33 BST; the lever is the acceptance floor, now 0.995 keyed on the state flag; the number still owed on the fix is the census's clean rejection rate, from the v5 lane. SELECTOR TALLY at 2^24, 21:1x BST (the re-submitted chain got build-1 cores at about 20:55): of the 16 lowest stand-in-ratio seeds, 9 beyond the 1.2x gate and 3 HOT SETS by the f8 test (100767; 4346 at X 0.1 percent +0.178, X/f 1.78, 2.24x the window model; 5245 at +0.129, 1.29, 1.86x); of 17 random accepted programs, 1 beyond and 0 hot sets; each hot set about 1 MB of items holding 0.3 percent of reads, gain about 1.002x: the distinguisher is real and repeatable, the bypass not exploitable | about 1.6 | | adv-accept-2 | 9b86d4e2, 19:4x BST | FINAL 3df22a4c, 20:42 BST: BOUND with one 0.1 percent per-program FINDING (drawn program 0x5d7cc2b09fc6922a repeats a word across load sites 1 and 5 in 1.55 percent of hashes per iteration: the only write between them is a rotate by a register amount, the identity 1 in 32, and site 1's quarter window lies inside site 5's half window; header-independent; admitted by the 120-of-128 floor); about 0.7 core-hours and 0.3 pod-hours; a 1e-6 tail and a 300-program prevalence census of the repeat class append when the pool serves them. Earlier: tip 74b8f3a1, 20:2x BST: Q1 to Q4 all landed, BOUND, with one per-program FINDING at 0.1 percent; the A6000 card row: the best header-ground groups read +0.09 percent dependent-read throughput at 15 hashes each against random, the const-site plant +6.3 percent (log logs/adv-accept-2/gpu-rowbench-a6000-2048x200.log); one more leased run follows for the 1e-6 tail and a prevalence census of the finding. Earlier rows (tip 9e8b1326): the two real programs and 8 drawn ones match the windowed random baseline at mean, min and the 1e-3, 1e-4 and 1e-5 tails for 2 KiB rows, 8 KiB rows, 64 B lines and items, per hash and per unit (closed form and live agree); one-bit header flips move 100.00 percent of the 4,096 unit addresses (the header-blind plant reads 0.0000); 2 to 4 of 16 load sites in iteration 0 are header-predictable, none later; both plants fire; the pod measures one point (dependent-read throughput of the best header-ground units from 1e7 hashes against random units and the two planted-clustering programs), "done" expected about 22:45 BST. "done" given at 20:2x BST; destroyed 20:27 BST and verified absent from the provider: 0.58 hours, USD 0.31 (plus a duplicate the fleet's retry loop rented the same minute and destroyed within two minutes, about USD 0.02). The pass's pod ledger: one pod, USD 0.33 in all, none originated by this lane; nothing of the pass remains on the fleet. Reading from the code: the header reaches the hash only through the init words (bind.rs) and never the program or the dataset, so a found header fixes one 32-lane group and a grind cannot amortise; GPU per-card confirmation BLOCKED, bound analytic; a GPU pod for the one BLOCKED confirmation was rented by the fleet lane under the word it holds (not by this lane): RunPod secure RTX A6000 48 GB, READY 20:06 BST, 3 hours, USD 1.59, registry label adv-accept-2-pls4, destroyed on the lane's "done"; the SSH line routed to the lane at 20:0x BST | pending | | | adv-accept-3 | 57fd32ea, 19:58 BST (spawned 19:5x BST after three attempts at the subagent cap) | report v1 cde2562f, 20:24 BST: 0 verdict disagreements between the code and a second interpretation over 2,546 attempt verdicts of 792 seeds; the (c'') f64 compare cannot flip a verdict at the shipped constants (margins 0.32 to 0.44 counts, 0 of 2^20 disagree); FINDING, documentation class: program.json's program_id_derivation string and spec 1.4.6 omit the "sub/" || 3_le16 suffix the code appends under generator 4 (text-derived id 30956569d8f3d8d7 for Devnet 3 against the pack's fce15bf61030be57), so a second client written from the text would disagree on every program id; the code is the consensus, the text and the exporter string are wrong; queue 93 to 99 re-queued through `lease pool 40` at 20:24 BST | pending | |