adv-cache-3: report with every row landed (Q1, Q2, Q3, Q4 bounds, the pebbling baseline finding, the image census to depth 8) and the logs

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-07 19:28:55 +00:00
parent 52ea3f8bcd
commit ba2619c4cc
27 changed files with 676 additions and 20 deletions

View file

@ -0,0 +1,4 @@
[2026-10-07T19:06:03Z] adv-cache-3 check (internal adversarial pass, not an independent review)
[2026-10-07T19:06:03Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:06:04Z] day 20730: cache FNV-1a 64 0x448274a57f508cbc (vectors.json 0x448274a57f508cbc: MATCH), head word 0 0xebd9055c, fill 0.95 s
[2026-10-07T19:06:05Z] day 20733: cache FNV-1a 64 0x7334fa46e5d972eb (vectors.json 0x7334fa46e5d972eb: MATCH), head word 0 0x47e15959, fill 0.97 s

View file

@ -0,0 +1,11 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 cross-d20730
[2026-10-07T19:22:59Z] adv-cache-3 cross (internal adversarial pass, not an independent review)
[2026-10-07T19:22:59Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:59Z] cross: day 20730 (and 20731) segments 4096 w 32 double rounds 6 plant none threads 88
[2026-10-07T19:22:59Z] cross-segment j=0: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 4.50 at (in bit 308, out bit 235) = (word 9 bit 20, word 7 bit 11); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:22:59Z] cross-segment j=1: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 4.75 at (in bit 418, out bit 64) = (word 13 bit 2, word 2 bit 0); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:22:59Z] cross-segment j=63: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 5.00 at (in bit 230, out bit 306) = (word 7 bit 6, word 9 bit 18); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:22:59Z] cross-day: line_j(s) of day d against day d + 1, same (s, j): n 4096 cells 262144 worst |z| 4.56 at (in bit 456, out bit 15) = (word 14 bit 8, word 0 bit 15); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:22:59Z] known constants of x_j from the code: j = 0: 16 of 16 words (x_0 = c_0 is public); j >= 1: 0 of 16 (every word is XORed with the previous line)
[2026-10-07T19:22:59Z] CROSS RESULT: worst |z| 5.00, gate 6 at 4096 samples PASS; 0.1 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,11 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 1 s): adv-cache-3 cross-plant-noxor-r1
[2026-10-07T19:23:00Z] adv-cache-3 cross (internal adversarial pass, not an independent review)
[2026-10-07T19:23:00Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:23:00Z] cross: day 20730 (and 20731) segments 4096 w 32 double rounds 1 plant no-xor threads 88
[2026-10-07T19:23:00Z] cross-segment j=0: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 64.00 at (in bit 14, out bit 14) = (word 0 bit 14, word 0 bit 14); cells over 5 sigma 4045 (expected 0.149); over 6 sigma 3385 (expected 0.00052)
[2026-10-07T19:23:00Z] cross-segment j=1: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 64.00 at (in bit 13, out bit 13) = (word 0 bit 13, word 0 bit 13); cells over 5 sigma 4236 (expected 0.149); over 6 sigma 3585 (expected 0.00052)
[2026-10-07T19:23:00Z] cross-segment j=63: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 64.00 at (in bit 14, out bit 14) = (word 0 bit 14, word 0 bit 14); cells over 5 sigma 4306 (expected 0.149); over 6 sigma 3564 (expected 0.00052)
[2026-10-07T19:23:00Z] cross-day: line_j(s) of day d against day d + 1, same (s, j): n 4096 cells 262144 worst |z| 56.28 at (in bit 55, out bit 55) = (word 1 bit 23, word 1 bit 23); cells over 5 sigma 1591 (expected 0.149); over 6 sigma 1113 (expected 0.00052)
[2026-10-07T19:23:00Z] known constants of x_j from the code: j = 0: 16 of 16 words (x_0 = c_0 is public); j >= 1: 0 of 16 (every word is XORed with the previous line)
[2026-10-07T19:23:00Z] CROSS RESULT: worst |z| 64.00, gate 6 at 4096 samples FIRE; 0.1 s
lease: released 88 pool cores after 1 s, exit 0

View file

@ -0,0 +1,20 @@
lease: holding 87 pool cores (9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 image-w2-r6-d64
[2026-10-07T19:22:50Z] adv-cache-3 image (internal adversarial pass, not an independent review)
[2026-10-07T19:22:50Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:50Z] image: w 2 double rounds 6 depth 64 plant none threads 87; rotations [1, 1, 1, 1]; all 2^32 states enumerated per step
[2026-10-07T19:23:14Z] depth 1: image size 2715029335 = 0.632142 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.632121; 2/k: 2.000000; a permutation: 1.000000); 24 s
[2026-10-07T19:23:29Z] depth 2: image size 2012444452 = 0.468559 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.468536; 2/k: 1.000000; a permutation: 1.000000); 39 s
[2026-10-07T19:23:40Z] depth 3: image size 1606748932 = 0.374100 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.374082; 2/k: 0.666667; a permutation: 1.000000); 50 s
[2026-10-07T19:23:48Z] depth 4: image size 1340451469 = 0.312098 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.312080; 2/k: 0.500000; a permutation: 1.000000); 58 s
[2026-10-07T19:23:55Z] depth 5: image size 1151447703 = 0.268092 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.268077; 2/k: 0.400000; a permutation: 1.000000); 65 s
[2026-10-07T19:24:01Z] depth 6: image size 1010025987 = 0.235165 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.235151; 2/k: 0.333333; a permutation: 1.000000); 71 s
[2026-10-07T19:24:07Z] depth 7: image size 900056868 = 0.209561 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.209548; 2/k: 0.285714; a permutation: 1.000000); 77 s
[2026-10-07T19:24:13Z] depth 8: image size 812009253 = 0.189061 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.189050; 2/k: 0.250000; a permutation: 1.000000); 83 s
[2026-10-07T19:24:18Z] depth 9: image size 739877239 = 0.172266 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.172255; 2/k: 0.222222; a permutation: 1.000000); 88 s
[2026-10-07T19:24:23Z] depth 10: image size 679651606 = 0.158244 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.158235; 2/k: 0.200000; a permutation: 1.000000); 93 s
[2026-10-07T19:24:28Z] depth 11: image size 628605897 = 0.146359 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.146351; 2/k: 0.181818; a permutation: 1.000000); 98 s
[2026-10-07T19:24:32Z] depth 12: image size 584777272 = 0.136154 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.136146; 2/k: 0.166667; a permutation: 1.000000); 102 s
[2026-10-07T19:24:36Z] depth 13: image size 546724260 = 0.127294 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.127284; 2/k: 0.153846; a permutation: 1.000000); 106 s
Terminated
Terminated
lease: released 87 pool cores after 106 s, exit 143

View file

@ -0,0 +1,2 @@
2026-10-07T19:22:50Z start image-w2-r6-d64
2026-10-07T19:24:38Z RELEASED image-w2-r6-d64 lease by order (partial kept to depth 8), re-queue at 48 cores later

View file

@ -0,0 +1,44 @@
2026-10-07T19:22:52Z start skip-d20730
2026-10-07T19:22:53Z end skip-d20730 rc=0
2026-10-07T19:22:53Z start skip-d20733
2026-10-07T19:22:54Z end skip-d20733 rc=0
2026-10-07T19:22:54Z start skip-plant-noxor
2026-10-07T19:22:54Z end skip-plant-noxor rc=0
2026-10-07T19:22:54Z start skip-plant-noff
2026-10-07T19:22:55Z end skip-plant-noff rc=0
2026-10-07T19:22:55Z start skip-rounds0
2026-10-07T19:22:55Z end skip-rounds0 rc=0
2026-10-07T19:22:55Z start skip-rounds1
2026-10-07T19:22:56Z end skip-rounds1 rc=0
2026-10-07T19:22:56Z start skip-rounds2
2026-10-07T19:22:57Z end skip-rounds2 rc=0
2026-10-07T19:22:57Z start skip-w4-r2
2026-10-07T19:22:57Z end skip-w4-r2 rc=0
2026-10-07T19:22:57Z start skip-w4-r2-plant-noxor
2026-10-07T19:22:57Z end skip-w4-r2-plant-noxor rc=0
2026-10-07T19:22:57Z start skip-w4-r2-plant-noff
2026-10-07T19:22:57Z end skip-w4-r2-plant-noff rc=0
2026-10-07T19:22:57Z start pebble
2026-10-07T19:22:59Z end pebble rc=0
2026-10-07T19:22:59Z start pebble-plant-skip8
2026-10-07T19:22:59Z end pebble-plant-skip8 rc=0
2026-10-07T19:22:59Z start cross-d20730
2026-10-07T19:22:59Z end cross-d20730 rc=0
2026-10-07T19:22:59Z start cross-plant-noxor-r1
2026-10-07T19:23:00Z end cross-plant-noxor-r1 rc=0
2026-10-07T19:23:00Z start relations-4d-l20
2026-10-07T19:23:02Z end relations-4d-l20 rc=0
2026-10-07T19:23:02Z start relations-plant-r1
2026-10-07T19:23:02Z end relations-plant-r1 rc=0
2026-10-07T19:23:02Z start relations-plant-r2
2026-10-07T19:23:02Z end relations-plant-r2 rc=0
2026-10-07T19:23:02Z start relations-r3
2026-10-07T19:23:03Z end relations-r3 rc=0
2026-10-07T19:23:03Z start skip-1024-d20730
2026-10-07T19:23:04Z end skip-1024-d20730 rc=0
2026-10-07T19:23:04Z start skip-1024-d20733
2026-10-07T19:23:05Z end skip-1024-d20733 rc=0
2026-10-07T19:23:05Z start skip-1024-plant-noxor
2026-10-07T19:23:05Z end skip-1024-plant-noxor rc=0
2026-10-07T19:23:05Z start skip-1024-plant-noff
2026-10-07T19:23:06Z end skip-1024-plant-noff rc=0

View file

@ -0,0 +1,31 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 pebble-plant-skip8
[2026-10-07T19:22:59Z] adv-cache-3 pebble (internal adversarial pass, not an independent review)
[2026-10-07T19:22:59Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:59Z] pebble: lines 64 exhaustive check up to 12 lines, Monte Carlo 200000 trials per point, skip edge 8 (PLANT: line j also from line j - 8 in one block)
[2026-10-07T19:22:59Z] exhaustive n=10 k=1: optimum 2.5000 blocks per read, DP 2.5000 AGREE
[2026-10-07T19:22:59Z] exhaustive n=10 k=2: optimum 1.5000 blocks per read, DP 1.5000 AGREE
[2026-10-07T19:22:59Z] exhaustive n=10 k=4: optimum 0.7000 blocks per read, DP 0.7000 AGREE
[2026-10-07T19:22:59Z] exhaustive n=12 k=1: optimum 3.0000 blocks per read, DP 3.0000 AGREE
[2026-10-07T19:22:59Z] exhaustive n=12 k=2: optimum 1.8333 blocks per read, DP 1.8333 AGREE
[2026-10-07T19:22:59Z] exhaustive n=12 k=4: optimum 0.9167 blocks per read, DP 0.9167 AGREE
[2026-10-07T19:22:59Z] static curve (blocks per uniform read; ops per item = 9,360 + 8 x blocks x 608; SRAM = f x 128 mm^2 at the N5 headline of chip-model-v3 section 2):
[2026-10-07T19:22:59Z] f=k/64 | k held | DP optimum (plain path) | stride offset 0 | stride offset step-1 | best over the planted graph (k=1 exhaustive, else local search) | ops per item at the optimum | SRAM mm^2
[2026-10-07T19:22:59Z] 1/64 | 1 | 16.0000 | 31.5000 | 31.5000 | 5.1875 | 87184 | 2.0
[2026-10-07T19:22:59Z] 2/64 | 2 | 10.5000 | 15.5000 | 15.5000 | 0.0000 | 60432 | 4.0
[2026-10-07T19:22:59Z] 4/64 | 4 | 6.0938 | 7.5000 | 7.5000 | 0.0000 | 39000 | 8.0
[2026-10-07T19:22:59Z] 8/64 | 8 | 3.1719 | 3.5000 | 3.5000 | 0.0156 | 24788 | 16.0
[2026-10-07T19:22:59Z] 16/64 | 16 | 1.4531 | 1.5000 | 1.5000 | 0.0000 | 16428 | 32.0
[2026-10-07T19:22:59Z] 32/64 | 32 | 0.5000 | 0.5000 | 0.5000 | 0.5000 | 11792 | 64.0
[2026-10-07T19:22:59Z] 64/64 | 64 | -0.0000 | 0.0000 | 0.0000 | 0.0000 | 9360 | 128.0
[2026-10-07T19:22:59Z] static curve: monotone in f YES; f = 1 reads 9360 ops per item (gate 9,360); planted graph under the path optimum at some f: YES PLANT FIRES
[2026-10-07T19:22:59Z] amortising adversary (Monte Carlo 200000 trials): blocks per read with m requests in one segment, one walk per gap from the nearest held line to the deepest request; the stride store at offset step-1 (the DP optimum's shape for k >= 2)
[2026-10-07T19:22:59Z] f=k/64 | m=1 | m=2 | m=4 | m=8 | m=16 | m=64 | Poisson m=1 | Poisson m=8 | Poisson m=64
[2026-10-07T19:22:59Z] 1/64 | 31.550 | 21.099 | 12.691 | 7.037 | 3.731 | 0.975 | 23.211 | 6.953 | 0.976
[2026-10-07T19:22:59Z] 2/64 | 15.500 | 12.933 | 9.556 | 6.102 | 3.470 | 0.951 | 13.277 | 5.902 | 0.951
[2026-10-07T19:22:59Z] 4/64 | 7.486 | 6.894 | 5.904 | 4.480 | 2.929 | 0.902 | 6.920 | 4.323 | 0.902
[2026-10-07T19:22:59Z] 8/64 | 3.504 | 3.370 | 3.114 | 2.691 | 2.088 | 0.805 | 3.367 | 2.624 | 0.803
[2026-10-07T19:22:59Z] 16/64 | 1.498 | 1.472 | 1.420 | 1.323 | 1.158 | 0.614 | 1.473 | 1.303 | 0.612
[2026-10-07T19:22:59Z] 32/64 | 0.500 | 0.495 | 0.489 | 0.475 | 0.446 | 0.317 | 0.497 | 0.468 | 0.314
[2026-10-07T19:22:59Z] 64/64 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000
[2026-10-07T19:22:59Z] cross-check points: the plain path with nothing held at m = 1 must read 32.5 (E[j] + 1); sibling adv-cache measured 23.84, 7.06 and 0.99 blocks per read on real addresses at Poisson m = 1, 8, 64 with nothing held (its batch rows)
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,37 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 pebble
[2026-10-07T19:22:57Z] adv-cache-3 pebble (internal adversarial pass, not an independent review)
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:57Z] pebble: lines 64 exhaustive check up to 16 lines, Monte Carlo 1000000 trials per point, skip edge none (the plain path)
[2026-10-07T19:22:57Z] exhaustive n=10 k=1: optimum 2.5000 blocks per read, DP 2.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=10 k=2: optimum 1.5000 blocks per read, DP 1.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=10 k=4: optimum 0.7000 blocks per read, DP 0.7000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=12 k=1: optimum 3.0000 blocks per read, DP 3.0000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=12 k=2: optimum 1.8333 blocks per read, DP 1.8333 AGREE
[2026-10-07T19:22:57Z] exhaustive n=12 k=4: optimum 0.9167 blocks per read, DP 0.9167 AGREE
[2026-10-07T19:22:57Z] exhaustive n=14 k=1: optimum 3.5000 blocks per read, DP 3.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=14 k=2: optimum 2.1429 blocks per read, DP 2.1429 AGREE
[2026-10-07T19:22:57Z] exhaustive n=14 k=4: optimum 1.0714 blocks per read, DP 1.0714 AGREE
[2026-10-07T19:22:57Z] exhaustive n=16 k=1: optimum 4.0000 blocks per read, DP 4.0000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=16 k=2: optimum 2.5000 blocks per read, DP 2.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=16 k=4: optimum 1.3125 blocks per read, DP 1.3125 AGREE
[2026-10-07T19:22:57Z] static curve (blocks per uniform read; ops per item = 9,360 + 8 x blocks x 608; SRAM = f x 128 mm^2 at the N5 headline of chip-model-v3 section 2):
[2026-10-07T19:22:57Z] f=k/64 | k held | DP optimum (plain path) | stride offset 0 | stride offset step-1 | best over the planted graph (k=1 exhaustive, else local search) | ops per item at the optimum | SRAM mm^2
[2026-10-07T19:22:57Z] 1/64 | 1 | 16.0000 | 31.5000 | 31.5000 | 16.0000 | 87184 | 2.0
[2026-10-07T19:22:57Z] 2/64 | 2 | 10.5000 | 15.5000 | 15.5000 | 10.5000 | 60432 | 4.0
[2026-10-07T19:22:57Z] 4/64 | 4 | 6.0938 | 7.5000 | 7.5000 | 6.0938 | 39000 | 8.0
[2026-10-07T19:22:57Z] 8/64 | 8 | 3.1719 | 3.5000 | 3.5000 | 3.1719 | 24788 | 16.0
[2026-10-07T19:22:57Z] 16/64 | 16 | 1.4531 | 1.5000 | 1.5000 | 1.4531 | 16428 | 32.0
[2026-10-07T19:22:57Z] 32/64 | 32 | 0.5000 | 0.5000 | 0.5000 | 0.5000 | 11792 | 64.0
[2026-10-07T19:22:57Z] 64/64 | 64 | -0.0000 | 0.0000 | 0.0000 | -0.0000 | 9360 | 128.0
[2026-10-07T19:22:57Z] static curve: monotone in f YES; f = 1 reads 9360 ops per item (gate 9,360); planted graph under the path optimum at some f: NO PASS
[2026-10-07T19:22:57Z] amortising adversary (Monte Carlo 1000000 trials): blocks per read with m requests in one segment, one walk per gap from the nearest held line to the deepest request; the stride store at offset step-1 (the DP optimum's shape for k >= 2)
[2026-10-07T19:22:57Z] f=k/64 | m=1 | m=2 | m=4 | m=8 | m=16 | m=64 | Poisson m=1 | Poisson m=8 | Poisson m=64
[2026-10-07T19:22:58Z] 1/64 | 31.523 | 21.072 | 12.670 | 7.046 | 3.733 | 0.976 | 23.242 | 6.948 | 0.975
[2026-10-07T19:22:58Z] 2/64 | 15.487 | 12.938 | 9.550 | 6.095 | 3.466 | 0.951 | 13.236 | 5.899 | 0.950
[2026-10-07T19:22:58Z] 4/64 | 7.498 | 6.896 | 5.889 | 4.484 | 2.939 | 0.902 | 6.931 | 4.325 | 0.899
[2026-10-07T19:22:58Z] 8/64 | 3.498 | 3.363 | 3.113 | 2.694 | 2.085 | 0.804 | 3.369 | 2.619 | 0.801
[2026-10-07T19:22:58Z] 16/64 | 1.500 | 1.472 | 1.420 | 1.324 | 1.157 | 0.614 | 1.474 | 1.303 | 0.612
[2026-10-07T19:22:58Z] 32/64 | 0.500 | 0.496 | 0.489 | 0.474 | 0.445 | 0.317 | 0.496 | 0.471 | 0.316
[2026-10-07T19:22:59Z] 64/64 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000
[2026-10-07T19:22:59Z] cross-check points: the plain path with nothing held at m = 1 must read 32.5 (E[j] + 1); sibling adv-cache measured 23.84, 7.06 and 0.99 blocks per read on real addresses at Poisson m = 1, 8, 64 with nothing held (its batch rows)
lease: released 88 pool cores after 2 s, exit 0

View file

@ -0,0 +1,15 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-4d-l20
[2026-10-07T19:23:00Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
[2026-10-07T19:23:00Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:23:00Z] relations: days 20730..20733 lines per day 2^20 (16384 segments x 64) w 32 double rounds 6 plant none threads 88
[2026-10-07T19:23:00Z] day 20730 done, 1032192 lines so far, 0.5 s
[2026-10-07T19:23:01Z] day 20731 done, 2064384 lines so far, 1.1 s
[2026-10-07T19:23:01Z] day 20732 done, 3096576 lines so far, 1.6 s
[2026-10-07T19:23:02Z] day 20733 done, 4128768 lines so far, 2.1 s
[2026-10-07T19:23:02Z] bias [line_j XOR x_j]: 512 bits over 4128768 lines: worst |z| 3.00 at bit 48 (word 1 bit 16), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 4128768 lines: worst |z| 3.58 at bit 75 (word 2 bit 11), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j XOR line_j-1]: 512 bits over 4128768 lines: worst |z| 3.29 at bit 267 (word 8 bit 11), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j - line_j-1]: 512 bits over 4128768 lines: worst |z| 3.29 at bit 333 (word 10 bit 13), bits over 6 sigma 0
[2026-10-07T19:23:02Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 4128768 cells 262144 worst |z| 4.83 at (in bit 296, out bit 467) = (word 9 bit 8, word 14 bit 19); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:23:02Z] RELATIONS RESULT: worst bias |z| 3.58, worst correlation |z| 4.83, gate 6 at 4128768 samples PASS; 2.1 s
lease: released 88 pool cores after 2 s, exit 0

View file

@ -0,0 +1,12 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-plant-r1
[2026-10-07T19:23:02Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
[2026-10-07T19:23:02Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:23:02Z] relations: days 20730..20730 lines per day 2^16 (1024 segments x 64) w 32 double rounds 1 plant none threads 88
[2026-10-07T19:23:02Z] day 20730 done, 64512 lines so far, 0.1 s
[2026-10-07T19:23:02Z] bias [line_j XOR x_j]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j XOR line_j-1]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j - line_j-1]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
[2026-10-07T19:23:02Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 64512 cells 262144 worst |z| 4.47 at (in bit 296, out bit 269) = (word 9 bit 8, word 8 bit 13); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:23:02Z] RELATIONS RESULT: worst bias |z| 3.22, worst correlation |z| 4.47, gate 6 at 64512 samples PASS; 0.1 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,12 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-plant-r2
[2026-10-07T19:23:02Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
[2026-10-07T19:23:02Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:23:02Z] relations: days 20730..20730 lines per day 2^16 (1024 segments x 64) w 32 double rounds 2 plant none threads 88
[2026-10-07T19:23:02Z] day 20730 done, 64512 lines so far, 0.1 s
[2026-10-07T19:23:02Z] bias [line_j XOR x_j]: 512 bits over 64512 lines: worst |z| 4.58 at bit 297 (word 9 bit 9), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 64512 lines: worst |z| 3.27 at bit 296 (word 9 bit 8), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j XOR line_j-1]: 512 bits over 64512 lines: worst |z| 4.58 at bit 297 (word 9 bit 9), bits over 6 sigma 0
[2026-10-07T19:23:02Z] bias [line_j - line_j-1]: 512 bits over 64512 lines: worst |z| 3.50 at bit 1 (word 0 bit 1), bits over 6 sigma 0
[2026-10-07T19:23:02Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 64512 cells 262144 worst |z| 4.65 at (in bit 412, out bit 35) = (word 12 bit 28, word 1 bit 3); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:23:02Z] RELATIONS RESULT: worst bias |z| 4.58, worst correlation |z| 4.65, gate 6 at 64512 samples PASS; 0.1 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,13 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-r3
[2026-10-07T19:23:03Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
[2026-10-07T19:23:03Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:23:03Z] relations: days 20730..20730 lines per day 2^18 (4096 segments x 64) w 32 double rounds 3 plant none threads 88
[2026-10-07T19:23:03Z] day 20730 done, 258048 lines so far, 0.2 s
[2026-10-07T19:23:03Z] bias [line_j XOR x_j]: 512 bits over 258048 lines: worst |z| 3.55 at bit 334 (word 10 bit 14), bits over 6 sigma 0
[2026-10-07T19:23:03Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 258048 lines: worst |z| 4.33 at bit 54 (word 1 bit 22), bits over 6 sigma 0
[2026-10-07T19:23:03Z] bias [line_j XOR line_j-1]: 512 bits over 258048 lines: worst |z| 3.55 at bit 334 (word 10 bit 14), bits over 6 sigma 0
[2026-10-07T19:23:03Z] bias [line_j - line_j-1]: 512 bits over 258048 lines: worst |z| 3.80 at bit 212 (word 6 bit 20), bits over 6 sigma 0
[2026-10-07T19:23:03Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 258048 cells 262144 worst |z| 4.45 at (in bit 296, out bit 372) = (word 9 bit 8, word 11 bit 20); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
[2026-10-07T19:23:03Z] RELATIONS RESULT: worst bias |z| 4.33, worst correlation |z| 4.45, gate 6 at 258048 samples PASS; 0.2 s
Terminated
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-1024-d20730
[2026-10-07T19:23:03Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:23:03Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:23:03Z] skip: day 20730 w 32 double rounds 6 lines 1024 segments 64 plant none threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:23:03Z] templates: 134283200 compares of 512-bit lines, chance matches expected 1.002e-146, 0.1 s
[2026-10-07T19:23:03Z] template 0 [B(c_j)] at 1 block(s): matches 64 (j0:64)
[2026-10-07T19:23:03Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:23:03Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:23:03Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:23:03Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:23:03Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:23:03Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:23:03Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
[2026-10-07T19:23:03Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:03Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:03Z] rank j=512: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:03Z] rank j=1023: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:03Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
[2026-10-07T19:23:04Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.34 / -4.88 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
[2026-10-07T19:23:04Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
[2026-10-07T19:23:04Z] inversion: 65472 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
[2026-10-07T19:23:04Z] skip done in 0.7 s
lease: released 88 pool cores after 1 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-1024-d20733
[2026-10-07T19:23:04Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:23:04Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:23:04Z] skip: day 20733 w 32 double rounds 6 lines 1024 segments 64 plant none threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:23:04Z] templates: 134283200 compares of 512-bit lines, chance matches expected 1.002e-146, 0.1 s
[2026-10-07T19:23:04Z] template 0 [B(c_j)] at 1 block(s): matches 64 (j0:64)
[2026-10-07T19:23:04Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:23:04Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:23:04Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:23:04Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:23:04Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:23:04Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:23:04Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
[2026-10-07T19:23:04Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:04Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:04Z] rank j=512: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:04Z] rank j=1023: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:23:04Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
[2026-10-07T19:23:04Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.41 / -4.47 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
[2026-10-07T19:23:04Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
[2026-10-07T19:23:04Z] inversion: 65472 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
[2026-10-07T19:23:04Z] skip done in 0.7 s
lease: released 88 pool cores after 1 s, exit 0

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

View file

@ -0,0 +1,24 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 1 s): adv-cache-3 skip-d20730
[2026-10-07T19:22:53Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:53Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:53Z] skip: day 20730 w 32 double rounds 6 lines 64 segments 1024 plant none threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:22:53Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
[2026-10-07T19:22:53Z] template 0 [B(c_j)] at 1 block(s): matches 1024 (j0:1024)
[2026-10-07T19:22:53Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:53Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:53Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
[2026-10-07T19:22:53Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:53Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:53Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:53Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:53Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
[2026-10-07T19:22:53Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.44 / -4.53 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
[2026-10-07T19:22:53Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
[2026-10-07T19:22:53Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:53Z] skip done in 0.5 s
Terminated
lease: released 88 pool cores after 1 s, exit 0

View file

@ -0,0 +1,24 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-d20733
[2026-10-07T19:22:53Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:53Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:53Z] skip: day 20733 w 32 double rounds 6 lines 64 segments 1024 plant none threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:22:53Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
[2026-10-07T19:22:53Z] template 0 [B(c_j)] at 1 block(s): matches 1024 (j0:1024)
[2026-10-07T19:22:53Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:53Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:53Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:53Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
[2026-10-07T19:22:53Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:53Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:54Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:54Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:54Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
[2026-10-07T19:22:54Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.47 / -4.47 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
[2026-10-07T19:22:54Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
[2026-10-07T19:22:54Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:54Z] skip done in 0.5 s
Terminated
lease: released 88 pool cores after 1 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 1 s): adv-cache-3 skip-plant-noff
[2026-10-07T19:22:55Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:55Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:55Z] skip: day 20730 w 32 double rounds 6 lines 64 segments 1024 plant no-feedforward threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:22:55Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
[2026-10-07T19:22:55Z] template 0 [B(c_j)] at 1 block(s): matches 1024 (j0:1024)
[2026-10-07T19:22:55Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:55Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:55Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 64512 (j1:1024 j2:1024 j3:1024 j4:1024 j5:1024 j6:1024 j7:1024 j8:1024 j9:1024 j10:1024 j11:1024 j12:1024 j13:1024 j14:1024 j15:1024 j16:1024 j17:1024 j18:1024 j19:1024 j20:1024 j21:1024 j22:1024 j23:1024 j24:1024 j25:1024 j26:1024 j27:1024 j28:1024 j29:1024 j30:1024 j31:1024 j32:1024 j33:1024 j34:1024 j35:1024 j36:1024 j37:1024 j38:1024 j39:1024 j40:1024 j41:1024 j42:1024 j43:1024 j44:1024 j45:1024 j46:1024 j47:1024 j48:1024 j49:1024 j50:1024 j51:1024 j52:1024 j53:1024 j54:1024 j55:1024 j56:1024 j57:1024 j58:1024 j59:1024 j60:1024 j61:1024 j62:1024 j63:1024)
[2026-10-07T19:22:55Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 64512 of 65536 (gate 0; a plant must read above 0) PASS
[2026-10-07T19:22:55Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:55Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:55Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:55Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:55Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
[2026-10-07T19:22:55Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.91 / -4.69 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
[2026-10-07T19:22:55Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
[2026-10-07T19:22:55Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 64512; fixed-point iteration x <- Cinv(y - x) converged 64512 (gate 0; the plant must read all); 0.0 s
[2026-10-07T19:22:55Z] skip done in 0.5 s
lease: released 88 pool cores after 1 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-plant-noxor
[2026-10-07T19:22:54Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:54Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:54Z] skip: day 20730 w 32 double rounds 6 lines 64 segments 1024 plant no-xor threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:22:54Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
[2026-10-07T19:22:54Z] template 0 [B(c_j)] at 1 block(s): matches 65536 (j0:1024 j1:1024 j2:1024 j3:1024 j4:1024 j5:1024 j6:1024 j7:1024 j8:1024 j9:1024 j10:1024 j11:1024 j12:1024 j13:1024 j14:1024 j15:1024 j16:1024 j17:1024 j18:1024 j19:1024 j20:1024 j21:1024 j22:1024 j23:1024 j24:1024 j25:1024 j26:1024 j27:1024 j28:1024 j29:1024 j30:1024 j31:1024 j32:1024 j33:1024 j34:1024 j35:1024 j36:1024 j37:1024 j38:1024 j39:1024 j40:1024 j41:1024 j42:1024 j43:1024 j44:1024 j45:1024 j46:1024 j47:1024 j48:1024 j49:1024 j50:1024 j51:1024 j52:1024 j53:1024 j54:1024 j55:1024 j56:1024 j57:1024 j58:1024 j59:1024 j60:1024 j61:1024 j62:1024 j63:1024)
[2026-10-07T19:22:54Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:54Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:54Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:54Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:54Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:54Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:54Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 64512 of 65536 (gate 0; a plant must read above 0) PASS
[2026-10-07T19:22:54Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
[2026-10-07T19:22:54Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
[2026-10-07T19:22:54Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
[2026-10-07T19:22:54Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
[2026-10-07T19:22:54Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 535 of 1025 DEFICIENT
[2026-10-07T19:22:54Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +0.00 / -64.00 (gate 6), zero cells 262144 of 262144; word table min 0 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.1 s
[2026-10-07T19:22:54Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
[2026-10-07T19:22:54Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:54Z] skip done in 0.4 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-rounds0
[2026-10-07T19:22:55Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:55Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:55Z] skip: day 20730 w 32 double rounds 0 lines 64 segments 256 plant none threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:22:55Z] templates: 2113280 compares of 512-bit lines, chance matches expected 1.576e-148, 0.0 s
[2026-10-07T19:22:55Z] template 0 [B(c_j)] at 1 block(s): matches 256 (j0:256)
[2026-10-07T19:22:55Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:55Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:55Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 16384 (gate 0) PASS
[2026-10-07T19:22:55Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
[2026-10-07T19:22:55Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
[2026-10-07T19:22:55Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
[2026-10-07T19:22:55Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
[2026-10-07T19:22:55Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 94 of 1025 DEFICIENT
[2026-10-07T19:22:55Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +64.00 / -64.00 (gate 6), zero cells 261648 of 262144; word table min 0 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.1 s
[2026-10-07T19:22:55Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
[2026-10-07T19:22:55Z] inversion: 16128 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:55Z] skip done in 0.1 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-rounds1
[2026-10-07T19:22:55Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:55Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:55Z] skip: day 20730 w 32 double rounds 1 lines 64 segments 256 plant none threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:22:55Z] templates: 2113280 compares of 512-bit lines, chance matches expected 1.576e-148, 0.0 s
[2026-10-07T19:22:55Z] template 0 [B(c_j)] at 1 block(s): matches 256 (j0:256)
[2026-10-07T19:22:55Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:55Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:55Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:55Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 16384 (gate 0) PASS
[2026-10-07T19:22:56Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1004 rank(line_j-1, line_j) 1004 DEFICIENT: an affine relation exists
[2026-10-07T19:22:56Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:56Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:56Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:56Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
[2026-10-07T19:22:56Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +64.00 / -64.00 (gate 6), zero cells 6985 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
[2026-10-07T19:22:56Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
[2026-10-07T19:22:56Z] inversion: 16128 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:56Z] skip done in 0.5 s
lease: released 88 pool cores after 1 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-rounds2
[2026-10-07T19:22:56Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:56Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:56Z] skip: day 20730 w 32 double rounds 2 lines 64 segments 256 plant none threads 88; rotations [16, 12, 8, 7]
[2026-10-07T19:22:56Z] templates: 2113280 compares of 512-bit lines, chance matches expected 1.576e-148, 0.0 s
[2026-10-07T19:22:56Z] template 0 [B(c_j)] at 1 block(s): matches 256 (j0:256)
[2026-10-07T19:22:56Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:56Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:56Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:56Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:56Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:56Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:56Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 16384 (gate 0) PASS
[2026-10-07T19:22:56Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:56Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:56Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:56Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
[2026-10-07T19:22:56Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
[2026-10-07T19:22:57Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.72 / -4.59 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
[2026-10-07T19:22:57Z] inversion: 16128 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:57Z] skip done in 0.5 s
lease: released 88 pool cores after 1 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-w4-r2-plant-noff
[2026-10-07T19:22:57Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:57Z] skip: day 20730 w 4 double rounds 2 lines 16 segments 4096 plant no-feedforward threads 88; rotations [1, 1, 1, 3]
[2026-10-07T19:22:57Z] templates: 2158592 compares of 64-bit lines, chance matches expected 1.170e-13, 0.0 s
[2026-10-07T19:22:57Z] template 0 [B(c_j)] at 1 block(s): matches 4096 (j0:4096)
[2026-10-07T19:22:57Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:57Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:57Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 61440 (j1:4096 j2:4096 j3:4096 j4:4096 j5:4096 j6:4096 j7:4096 j8:4096 j9:4096 j10:4096 j11:4096 j12:4096 j13:4096 j14:4096 j15:4096)
[2026-10-07T19:22:57Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 61440 of 65536 (gate 0; a plant must read above 0) PASS
[2026-10-07T19:22:57Z] rank j=1: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=2: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=8: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=15: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 129 of 129 FULL
[2026-10-07T19:22:57Z] dependence: 4096 lines, 64 x 64 flip table: worst cells z +13.41 / -14.91 (gate 6), zero cells 0 of 4096; word table min 3773 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.0 s
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
[2026-10-07T19:22:57Z] inversion: 61440 lines: Cinv(line_j) = x_j directly 61440; fixed-point iteration x <- Cinv(y - x) converged 61440 (gate 0; the plant must read all); 0.0 s
[2026-10-07T19:22:57Z] skip done in 0.0 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-w4-r2-plant-noxor
[2026-10-07T19:22:57Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:57Z] skip: day 20730 w 4 double rounds 2 lines 16 segments 4096 plant no-xor threads 88; rotations [1, 1, 1, 3]
[2026-10-07T19:22:57Z] templates: 2158592 compares of 64-bit lines, chance matches expected 1.170e-13, 0.0 s
[2026-10-07T19:22:57Z] template 0 [B(c_j)] at 1 block(s): matches 65536 (j0:4096 j1:4096 j2:4096 j3:4096 j4:4096 j5:4096 j6:4096 j7:4096 j8:4096 j9:4096 j10:4096 j11:4096 j12:4096 j13:4096 j14:4096 j15:4096)
[2026-10-07T19:22:57Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:57Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:57Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 61440 of 65536 (gate 0; a plant must read above 0) PASS
[2026-10-07T19:22:57Z] rank j=1: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=2: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=8: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=15: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 73 of 129 DEFICIENT
[2026-10-07T19:22:57Z] dependence: 4096 lines, 64 x 64 flip table: worst cells z +0.00 / -64.00 (gate 6), zero cells 4096 of 4096; word table min 0 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.0 s
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
[2026-10-07T19:22:57Z] inversion: 61440 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:57Z] skip done in 0.1 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -0,0 +1,23 @@
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-w4-r2
[2026-10-07T19:22:57Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:57Z] skip: day 20730 w 4 double rounds 2 lines 16 segments 65536 plant none threads 88; rotations [1, 1, 1, 3]
[2026-10-07T19:22:57Z] templates: 34537472 compares of 64-bit lines, chance matches expected 1.872e-12, 0.0 s
[2026-10-07T19:22:57Z] template 0 [B(c_j)] at 1 block(s): matches 65536 (j0:65536)
[2026-10-07T19:22:57Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
[2026-10-07T19:22:57Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
[2026-10-07T19:22:57Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
[2026-10-07T19:22:57Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 1048576 (gate 0) PASS
[2026-10-07T19:22:57Z] rank j=1: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=2: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=8: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank j=15: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
[2026-10-07T19:22:57Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 129 of 129 FULL
[2026-10-07T19:22:57Z] dependence: 4096 lines, 64 x 64 flip table: worst cells z +14.94 / -15.34 (gate 6), zero cells 0 of 4096; word table min 3771 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.0 s
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
[2026-10-07T19:22:57Z] inversion: 65536 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
[2026-10-07T19:22:57Z] skip done in 0.1 s
lease: released 88 pool cores after 0 s, exit 0

View file

@ -1,40 +1,160 @@
# Report: the chained cache, chain break or skip (lane adv-cache-3)
Internal adversarial pass, not an independent review. Lane `adv-cache-3`, the chain-break-or-skip class of the chained cache (line `(s, j)` in fewer than `j + 1` blocks without an earlier line; relations through the XOR chaining and the feed-forward; partial knowledge; the pebbling curve). Plan: `docs/plans/cryptanalysis/plan-chained-cache-3.md`. Every sentence here that could be quoted publicly carries the label: internal adversarial pass, not an independent review.
Internal adversarial pass, not an independent review. Lane `adv-cache-3`, the chain-break-or-skip class of the chained cache: line `(s, j)` in fewer than `j + 1` blocks without an earlier line; relations through the XOR chaining and the feed-forward; partial knowledge; the pebbling curve of the 64-line chain. Plan: `docs/plans/cryptanalysis/plan-chained-cache-3.md`. Every sentence here that could be quoted publicly carries the label: internal adversarial pass, not an independent review. Times are UK time (BST); the logs carry UTC.
## Header
| Item | Value |
|---|---|
| Target commit | `017e70376489251e18564c0abce7e466e606c8b3` (class v4 sub-version 3, object byte 7); `igneum-pow` at `build/master` 04c4d9bc is byte-identical (`git diff --quiet 017e7037 HEAD -- igneum-pow` printed IDENTICAL at 19:42 BST), and the harness depends on it by path |
| Harness | `tools/attack/adv-cache-3/` (crate `attack-adv-cache-3`, binary `adv-cache-3`), branch `adv-cache-3` on the build mirror |
| Binary sha256 | `37a7a661c548a67827e29c4134bb91751ef2083920b386d3ebc9b599add3ca8a` (built on both boxes from commit 4e363b91's tree, `cargo build --release`, rustc 1.99.0; the first build `067ad69c...` had 66 rank samples per `j` instead of 4,096 and was replaced before any number below) |
| Target commit | `017e70376489251e18564c0abce7e466e606c8b3` (class v4 sub-version 3, object byte 7); `igneum-pow` at `build/master` 04c4d9bc is byte-identical (`git diff --quiet 017e7037 HEAD -- igneum-pow` printed IDENTICAL at 19:42), and the harness depends on it by path |
| Harness | `tools/attack/adv-cache-3/` (crate `attack-adv-cache-3`, binary `adv-cache-3`, commands `check`, `skip`, `relations`, `image`, `pebble`, `cross`), branch `adv-cache-3` on the build mirror |
| Binary sha256 | `37a7a661c548a67827e29c4134bb91751ef2083920b386d3ebc9b599add3ca8a` on both boxes (built from commit 4e363b91's tree, `cargo build --release`, rustc 1.99.0). The first build `067ad69c...` had 66 rank samples per `j` instead of 4,096 and was replaced; its one run (`skip-d20730`, 20:09) agrees with the rerun on every other number |
| Self-test on every start | the restated `B` equals the library's `chacha_block` on 4,096 random inputs; `core_inv` inverts `core` at w = 2, 4, 8, 16, 32; the restated chain equals `Cache::fill_segment` on segments 0, 21,859 and 65,535 of day 20730 |
| Vectors passed | day 20730 cache FNV-1a 64 `0x448274a57f508cbc` (the kit's `vectors.json`) and day 20733 `0x7334fa46e5d972eb` (the Devnet 3 pack): MATCH, `check.log` |
| Boxes and scheduling | build box 1 (the skip, relations and cross batches) and build box 2 (the exhaustive image census), each under the per-box sweep lock (`/srv/builds/_adv/locks/sweep.lock`, one sweep per box at a time, the coordinator's rule of 19:55 BST), nice 10 on cores 8 to 95, no SIGSTOP yield; the boxes read load 500 to 560 on 96 threads all evening, so wall times below are not timings |
| Logs | `/srv/builds/_adv-cache-3/logs/<tag>.log` on each box (outside the worktree mirror); copies under `docs/analysis/cryptanalysis/logs/adv-cache-3/` on this branch |
| THE QUEUE | files 90, 91, 92 (the coordinator's definitions) claimed at 19:49 BST with owner files; their implementations run as files 93 (skip batch), 94 (relations batch) and 95 (image census), claimed the same way |
| Box-hours | section 9 |
| Vectors passed | day 20730 cache FNV-1a 64 `0x448274a57f508cbc` (the kit's `vectors.json`) and day 20733 `0x7334fa46e5d972eb` (the Devnet 3 pack): MATCH (`check.log`) |
| Boxes and scheduling | build box 1 for the skip, relations, pebble and cross runs, build box 2 for the exhaustive image census; every run through `/srv/builds/_bin/lease pool` (main's rule of 20:1x, no sweep by hand), nice 10 on cores 8 to 95; the boxes read load 400 to 600 on 96 threads all evening, so wall times are not timings |
| Logs | `/srv/builds/_adv-cache-3/logs/<tag>.log` on each box (outside the worktree mirror); copies under `docs/analysis/cryptanalysis/logs/adv-cache-3/` on this branch, `ledger.txt` the start and end of every run |
| THE QUEUE | files 90, 91, 92 (the coordinator's definitions) claimed at 19:49 with owner files; implemented and run as files 93 (skip batch, 14 runs), 94 (relations, 4 runs), 96 (the 1,024-line chain, 4 runs) on build box 1 and 95 (the image census) on build box 2; 97 (the image census again at 48 cores) queued behind the class v5 waiters |
| Box-hours | 0.04 slot-hours in all (section 9); no pod-hours (no GPU row in this lane) |
## Status board
| # | Question | Method | Known-failed shape (fired?) | Gate | Result | Status |
|---|---|---|---|---|---|---|
| Q1 (brief a, file 90) | Line `(s, j)` in fewer than `j + 1` blocks without an earlier line | `skip`: 7 earlier-line-free templates (1 or 2 blocks) against every line of 1,024 segments x 64 lines on 2 day keys; the GF(2) rank of the 1,025-column `(x_j, line_j, 1)` sample matrix; the 512 x 512 bit-dependence table and the 16 x 16 word table; the inversion attempt; the w = 4 model at 65,536 segments x 16 lines | `no-xor`, `no-feedforward`, `--rounds 0` | 0 lines under `j + 1`; rank 1,025; no zero cell; plants fire | first run on day 20730: 0 of 65,536 lines under `j + 1` by any template; pooled rank 1,025 of 1,025; flip table worst z +4.44 / -4.53 with 0 zero cells of 262,144; every output word changes with every input word; 0 inversions of 64,512 | RUNNING |
| Q1 (4) | Exhaustive image census at w = 2 (every 2^32 state per step, depth 64) | `image` | `no-feedforward` (a permutation: the image must stay 2^32) | the image follows the random-function recursion, not slower | queued on build box 2 | RUNNING |
| Q2 (brief b, c, file 91) | Relations through `line_j = C(x_j) + x_j`; partial knowledge | `relations`: per-bit bias of 4 relations over 4 day keys x 2^20 lines; the 512 x 512 correlation table; `skip`'s word table and inversion | `--rounds 1`, `--rounds 2`, `no-feedforward` | every bias and cell within 6 sigma at 2^22 samples; 0 words from a proper subset; 0 inversions | queued behind the skip batch | RUNNING |
| Q3 (brief d, file 92) | The pebbling curve of the 64-line chain under storage `f`; the amortising adversary | `pebble`: DP optimum (checked against exhaustive search at 10 to 16 lines), two stride placements, ops per item and SRAM; Monte Carlo of `m` requests per segment, fixed and Poisson | `--skip-edge 8` | monotone, never under the honest curve, 9,360 at `f = 1`; the plant lowers `f = 1/64` | queued in the skip batch | RUNNING |
| Q4 (brief e) | Cross-segment and cross-day relations; the known-constant words | `cross`: 512 x 512 correlation tables at `j` = 0, 1, 63 across one-bit segment pairs and across days | `--plant no-xor --rounds 1` | every cell within 6 sigma | queued in the skip batch | RUNNING |
| Q1 (brief a, file 90) | Line `(s, j)` in fewer than `j + 1` blocks without an earlier line of its segment | `skip`: 7 earlier-line-free templates at 1 or 2 blocks against every line; the GF(2) rank of the `(x_j, line_j, 1)` sample matrix; the 512 x 512 bit-dependence table and the 16 x 16 word table; the inversion attempt; the reduced-round ladder | `no-xor` fired (64,512 of 65,536 lines at 1 block; dependence table all zero); `no-feedforward` fired (64,512 lines recovered up the chain; 64,512 of 64,512 inversions); `--rounds 0` fired (rank 17 of 1,025) | 0 lines under `j + 1`; rank 1,025; no zero cell; 0 inversions | 64-line chain, 1,024 segments, days 20730 and 20733: 0 of 131,072 lines by any template (16.9 M compares); 1,024-line chain, 64 segments, both days: 0 of 131,072 (268.6 M compares); rank 1,025 of 1,025 at `j` = 1, 2, 32, 63 and 1,023; flip table worst z +4.47 / -4.88 of 262,144 cells, 0 zero cells; every output word changes with every input word; 0 of 130,000 inversions | BOUND, PASS |
| Q1 (4) | Exhaustive image census at w = 2: every one of 2^32 states per step | `image` | `no-feedforward` (the image must stay 2^32): queued | the chain loses entropy no faster than a random function | depths 1 to 8 (the run was released at depth 8 by main's order for the class v5 gate): image 0.632142, 0.468559, 0.374100, 0.312098, 0.268092, 0.235165, 0.209561, 0.189061 of 2^32 against the random-function recursion 0.632121, 0.468536, 0.374082, 0.312080, 0.268077, 0.235151, 0.209548, 0.189050 (within 2 x 10^-5 at every depth) | RUNNING (depths 9 to 64 and the plant queued as file 97) |
| Q2 (brief b, c, file 91) | Relations through `line_j = C(x_j) + x_j`; partial knowledge | `relations`: per-bit bias of 4 relations and the 512 x 512 linear-correlation table over 4 day keys x 2^20 lines; `skip`'s word table and inversion for the partial-knowledge half | `--rounds 1` and `--rounds 2` did NOT fire on the bias and correlation statistics (worst 4.47 and 4.65 sigma at 2^16 lines); the relation class's plants that do fire are in `skip`: `--rounds 1` leaves 21 exact affine relations (rank 1,004) and 6,985 zero cells in the flip table, `no-feedforward` inverts every line | every bias and cell within 6 sigma at 2^22 samples; 0 words from a proper subset; 0 inversions | 4,128,768 lines: worst bias 3.58 sigma of 2,048 bits; worst correlation cell 4.83 sigma of 262,144 (0 cells over 5, 0.15 expected); 0 of 16 output words from a proper subset of input words; 0 inversions | BOUND, PASS; the plant caveat in section 2 |
| Q3 (brief d, file 92) | The pebbling curve of the 64-line chain under storage `f`; the amortising adversary | `pebble`: exact DP optimum over placements (checked against exhaustive search at 10, 12, 14, 16 lines, 12 of 12 agree), the two stride placements, ops per item and SRAM; Monte Carlo of `m` requests per segment, fixed and Poisson | `--skip-edge 8` fired (optimum 5.19 blocks at `f = 1/64` against 16.0) | monotone; never under the honest hold-every-k-th curve; 9,360 at `f = 1` | Monotone, 9,360 at `f = 1`. The DP optimum sits UNDER the hold-every-k-th curve at small `f`: 16.0 against 31.5 blocks per read at `f = 1/64`, 10.5 against 15.5 at 2/64, 6.09 against 7.5 at 4/64, 3.17 against 3.5 at 8/64, 1.45 against 1.5 at 16/64, equal from 32/64. Not an attack: a correction of the honest baseline (section 3) | FINDING (bookkeeping, not a break): the honest curve of the gate is mis-specified at small `f`; the chip's partial-cache price at `f = 1/64` is 9.3x the item's ops, not 17.4x |
| Q4 (brief e) | Cross-segment and cross-day relations; the known-constant words | `cross`: 512 x 512 correlation tables at `j` = 0, 1, 63 across one-bit segment pairs and across days 20730 and 20731 | `--plant no-xor --rounds 1` fired (3,385 to 3,585 cells over 6 sigma per table, worst 64) | every cell within 6 sigma | 4,096 pairs per table: worst 4.50, 4.75, 5.00 (segments at `j` = 0, 1, 63), 4.56 (days); 0 cells over 6 sigma of 1,048,576 | BOUND, PASS |
The sections below are filled in as the rows land. Times in this file are UK time (BST).
## 1. Q1: the skip search
Commands (box 1, file 93 and file 96, binary `37a7a661...`): `adv-cache-3 skip --day 20730 --segments 1024 --threads 88` and `--day 20733`; `--segments 64 --lines 1024` on both days; plants `--plant no-xor`, `--plant no-feedforward` at 64 and 1,024 lines; the ladder `--rounds 0, 1, 2` at 256 segments; the model `--w 4 --rounds 2 --segments 65536 --lines 16` with both plants. Seeds: the chain day keys `seed_words_from_bytes("igneum-day/" || le64(d))`; segments `s = (p * 0x9E37) AND 0xffff` for `p` in 0..segments, or every segment when `segments >= 65,536`. Logs `skip-*.log`.
What was searched, from the code (`memhard.rs` `chacha_block`, `fill_segment_tagged`):
| Test | What it would catch | Day 20730 | Day 20733 |
|---|---|---|---|
| Templates: `B(c_j)`, `B(c_j XOR c_i)`, `B(c_j) XOR B(c_i)`, `B(c_j) XOR c_i`, `B(B(c_j))`, `B(c_j) + c_i` for `i < j`, and `Cinv(line_j) XOR c_j = line_{j-1}` (up the chain from a stored later line) | a line computable from the public constants alone, or a line computable from its successor | 0 matches on 65,536 lines at 64 lines and 65,536 at 1,024 lines (`B(c_0) = line_0` is the chain's own definition at 1 = j + 1 blocks and is counted as not under); chance expectation under 10^-146 | the same, 0 |
| GF(2) rank of the 4,096 x 1,025 matrix `(x_j bits, line_j bits, 1)` and of `(line_{j-1}, line_j, 1)` | any affine relation between a line and its input, which is a skip (a linear `B` chains to a linear closed form) | 1,025 of 1,025 at `j` = 1, 2, 32, 63 and pooled; at 1,024 lines 1,025 at `j` = 1 and 1,023 | the same |
| Flip table: each of the 512 bits of `line_{j-1}` flipped, the flip rate of each of the 512 bits of `line_j`, over 4,096 lines | a bit of a line that does not reach a bit of the next (a skip through a sub-block) | worst z +4.44 / -4.53 (64-line), +4.34 / -4.88 (1,024-line); 0 zero cells | +4.47 / -4.47; +4.41 / -4.47; 0 zero cells |
| Word table: each input word randomised, which output words change | an output word computable from fewer than 16 input words (the partial-knowledge gain) | 4,096 of 4,096 for every pair; 0 of 16 words from a proper subset | the same |
| Inversion: `Cinv(line_j) = x_j`; the fixed-point iteration `x <- Cinv(y - x)` from 0, 64 steps | a cheap inverse of `B = C + x`, which walks up the chain from any stored line | 0 of 64,512 (64-line) and 0 of 65,472 (1,024-line) | 0 and 0 |
The reduced-round ladder (256 segments, day 20730), the margin of the rank and flip tests:
| Double rounds of `C` | Rank at `j = 1` of 1,025 | Zero cells of 262,144 | Flip table worst z | Reading |
|---|---|---|---|---|
| 0 (`B(x) = 2x`) | 17 | 261,648 | 64 | fully affine; the plant for the rank test |
| 1 (2 ChaCha rounds) | 1,004 | 6,985 | 64 | 21 exact affine relations survive one double round; 6,985 input-output bit pairs never interact |
| 2 (4 rounds) | 1,025 | 0 | +4.72 / -4.59 | nothing at 4,096 samples (a 4-round bias under about 2^-4.4 would escape this sample size) |
| 6 (12 rounds, the real `B`) | 1,025 | 0 | +4.47 / -4.53 | nothing |
The small-scale model `B(4, 2)` (16 words of 4 bits, 2 double rounds, rotations 1, 1, 1, 3): the template search over the 16-line chain reads 0 matches on 1,048,576 lines (34.5 M compares, chance 1.9 x 10^-12); the flip table has 0 zero cells. Two caveats on the model, stated so nobody over-reads it: `s` is truncated to 4 bits, so the 65,536 "segments" are 16 distinct chains repeated (the per-`j` rank of 16 is that repetition, not a relation); and the word-level test is not valid at 4-bit words (a 4-bit output word equals its old value by chance 1 in 16, so "16 of 16 words from a subset" at w = 4 is chance, not structure). The model's job here was to run the same code at a width where the plants are cheap; both plants fired on it (61,440 of 65,536 lines each).
Known-failed shapes, all fired: `no-xor` (prev not XORed in) reads 64,512 of 65,536 lines at 1 block by `B(c_j)`, a flip table of 262,144 zero cells and 16 of 16 words from a subset (rank of `(x_j, line_j)` 529, since `x_j = c_j` varies in two words only); `no-feedforward` (`B = C`) reads 64,512 lines recovered by `Cinv(line_j) XOR c_j` and 64,512 of 64,512 inversions, with the rank and flip tables unchanged (a permutation is still a good mixer; the loss is the one-way property); `--rounds 0` collapses the rank to 17. At 1,024 lines the plants read 16,368 of 16,384.
Reading: no earlier-line-free derivation of any line, no affine relation between consecutive lines, no bit or word of a line computable from part of its input, no inverse. The one-way property of `B = C(x) + x` is what the chain's cost rests on, and the plant without it falls to the inverse template at once.
## 2. Q2: the feed-forward relations and partial knowledge
Command (box 1, file 94): `adv-cache-3 relations --day0 20730 --days 4 --lines-log2 20 --threads 88` (log `relations-4d-l20.log`); the ladder `--rounds 1`, `--rounds 2` at 2^16 lines, `--rounds 3` at 2^18. Lines `j >= 1` of segments 0 to 16,383 on days 20730 to 20733: 4,128,768 lines.
| Statistic | Samples | Worst |z| | Where | Gate 6 |
|---|---|---|---|---|
| `line_j XOR x_j`, per bit | 4,128,768 | 3.00 | word 1 bit 16 | PASS |
| `line_j - x_j` (that is `C(x_j)`), per bit | 4,128,768 | 3.58 | word 2 bit 11 | PASS |
| `line_j XOR line_{j-1}`, per bit | 4,128,768 | 3.29 | word 8 bit 11 | PASS |
| `line_j - line_{j-1}`, per bit | 4,128,768 | 3.29 | word 10 bit 13 | PASS |
| `x_j[a] XOR line_j[b]` over all 262,144 cells (the `line_{j-1}` table is the same up to a sign per column, since `x_j = line_{j-1} XOR c_j`) | 4,128,768 | 4.83 | in word 9 bit 8, out word 14 bit 19; 0 cells over 5 sigma against 0.15 expected | PASS |
The expected maximum of 2,048 or 262,144 normal draws is 3.5 or 4.9 sigma; the worst cells sit on those.
Partial knowledge (section 1's word table and inversion): given `k < 16` words of `line_{j-1}`, 0 words of `line_j` are determined (every output word changes when any single input word changes, 4,096 of 4,096 times); given `line_j`, nothing of `x_j` leaks beyond the correlation table's chance level, the direct inverse recovers 0 lines and the fixed-point iteration converges on 0. What IS known of `x_j` from the code: at `j = 0` all 16 words (`x_0 = c_0`, public, the spec says so); at `j >= 1` no word, since every word of `c_j` is XORed with the previous line.
The plant caveat, stated plainly: the queue file's known-failed shape ("a reduced C at 2 rounds must show a measurable bias") did not fire on the bias and correlation statistics. At one double round (2 ChaCha rounds) the worst bias reads 3.22 sigma and the worst correlation cell 4.47 at 2^16 lines; at two double rounds 4.58 and 4.65; at three 4.33 and 4.45 at 2^18 lines. Single-bit biases of `C(x) + x` over a near-uniform `x` and single-bit-in, single-bit-out linear correlations are not where a reduced ChaCha leaks: the 21 affine relations one double round leaves involve many bits at once, and the public distinguishers on 3 to 7 rounds use a chosen input difference with a multi-bit output mask and 2^30 or more samples. The relation class's plants that do fire are the rank test (rank 1,004 at one double round, 17 at zero) and the flip table (6,985 zero cells at one double round), both in section 1, and `no-feedforward` on the inversion. So the Q2 sweep is a bound on exactly what it measures (per-bit biases and pairwise correlations at 2^22 samples, under 6 sigma), and the known-failed shape for the relation class is carried by section 1's tests, not by this one. A statistic that would fire at two double rounds is a differential-linear one with 2^20 or more samples per input difference; section 8b.
## 3. Q3: the pebbling curve
Command (box 1, file 93): `adv-cache-3 pebble --lines 64 --exhaustive-upto 16 --mc 1000000` (log `pebble.log`); plant `--skip-edge 8` (`pebble-plant-skip8.log`). Pure arithmetic and Monte Carlo on the chain as a graph; no day key.
The model: `k` held lines of 64 (`f = k / 64`); a uniform read of line `j` costs the walk from the nearest held line at or below `j` (or from nothing: `j + 1`). The exact optimum over placements by dynamic programming agrees with exhaustive search over every subset at 10, 12, 14 and 16 lines for `k` = 1, 2, 4 (12 of 12). Ops per item `9,360 + 8 x blocks x 608`; SRAM `f x 128 mm^2` at the N5 headline of `chip-model-v3.md` section 2.
| `f` | `k` held | DP optimum, blocks per read | hold every (64/k)-th line (offset 0 and offset step-1) | ops per item at the optimum | multiple of the item's 9,360 | SRAM mm^2 |
|---|---|---|---|---|---|---|
| 1/64 | 1 | 16.00 (line 32 held) | 31.50 | 87,184 | 9.3x | 2 |
| 2/64 | 2 | 10.50 | 15.50 | 60,432 | 6.5x | 4 |
| 4/64 | 4 | 6.09 | 7.50 | 39,000 | 4.2x | 8 |
| 8/64 | 8 | 3.17 | 3.50 | 24,788 | 2.6x | 16 |
| 16/64 | 16 | 1.45 | 1.50 | 16,428 | 1.8x | 32 |
| 32/64 | 32 | 0.50 | 0.50 | 11,792 | 1.26x | 64 |
| 1 | 64 | 0 | 0 | 9,360 | 1.00x | 128 |
The finding, and what it is not: the gate asked for a curve "never below the honest hold-every-k-th curve". The optimum IS below it at small `f`, by 2.0x at `f = 1/64` and 1.5x at 2/64, because holding every `(64/k)`-th line puts the first held line at the segment's start, where the chain is cheap anyway (line 0 costs 1 block from nothing), and leaves the far half unprotected. The optimal single held line is line 32; the optimal `k` lines are spaced closer toward the end of the segment. This is a correction of the honest baseline that sibling `adv-cache`'s Q1b table and the gate wording carry (31.5, 15.5, 7.5, 3.5, 1.5, 0.5 blocks), not an attack: the honest miner holds the whole cache and pays nothing per read; what moves is the price a partial-cache chip pays, which at `f = 1/64` is 9.3x the item's operations instead of 17.4x. At the chip-relevant point `f = 1/2` nothing changes (0.50 blocks per read, 1.26x the item's ops, 64 mm^2 saved), so the SRAM column of `chip-model-v3.md` and sibling `adv-cache`'s verdict (monotone toward the full store) stand. The curve is monotone in `f` and reads 9,360 at `f = 1` as the gate requires.
The amortising adversary (`m` requests in one segment, one walk per gap from the nearest held line to the deepest request; the 2^16 segments are independent so nothing amortises across them; Monte Carlo 10^6 trials, the stride placement at offset step-1):
| `f` | m = 1 | m = 2 | m = 4 | m = 8 | m = 16 | m = 64 | Poisson 1 | Poisson 8 | Poisson 64 |
|---|---|---|---|---|---|---|---|---|---|
| 1/64 (line 63 held: in effect nothing) | 31.52 | 21.07 | 12.67 | 7.05 | 3.73 | 0.98 | 23.24 | 6.95 | 0.98 |
| 2/64 | 15.49 | 12.94 | 9.55 | 6.10 | 3.47 | 0.95 | 13.24 | 5.90 | 0.95 |
| 4/64 | 7.50 | 6.90 | 5.89 | 4.48 | 2.94 | 0.90 | 6.93 | 4.33 | 0.90 |
| 8/64 | 3.50 | 3.36 | 3.11 | 2.69 | 2.09 | 0.80 | 3.37 | 2.62 | 0.80 |
| 16/64 | 1.50 | 1.47 | 1.42 | 1.32 | 1.16 | 0.61 | 1.47 | 1.30 | 0.61 |
| 32/64 | 0.50 | 0.50 | 0.49 | 0.47 | 0.45 | 0.32 | 0.50 | 0.47 | 0.32 |
Cross-check: with nothing held the Poisson rows read 23.24, 6.95 and 0.98 blocks per read at `m` = 1, 8, 64; sibling `adv-cache` measured 23.84, 7.06 and 0.99 on real addresses (its batch rows), so the uniform model and the real derivation agree to 3 percent. Batching helps only when `m` requests per segment are many, which costs `m x 2^16 x 64 B` of item state (the sibling's point); with half the lines held the gain at `m = 64` is 0.50 to 0.32 blocks per read, 0.2 x 608 = 110 operations per read against the item's 9,360.
Known-failed shape: `--skip-edge 8` (line `j` also derivable from line `j - 8` in one block) lowers the `f = 1/64` optimum from 16.00 to 5.19 blocks per read; fired.
## 4. Q4: cross-segment and cross-day relations
Command (box 1, file 93): `adv-cache-3 cross --day 20730 --segments 4096 --threads 88` (`cross-d20730.log`); plant `--plant no-xor --rounds 1` (`cross-plant-noxor-r1.log`). Pairs `s, s XOR 2^(p mod 16)` with `s = (p * 0x9E37) AND 0xffff`; the cross-day table pairs line `(s, j)` of day 20730 with the same of day 20731, `j = p mod 64`.
| Table | Samples | Worst |z| of 262,144 cells | Cells over 6 sigma |
|---|---|---|---|
| `line_0(s)` against `line_0(s XOR 2^b)` (the 2^16 first inputs differ in word 12 only: the multi-target) | 4,096 | 4.50 | 0 |
| `line_1(s)` against `line_1(s XOR 2^b)` | 4,096 | 4.75 | 0 |
| `line_63(s)` against `line_63(s XOR 2^b)` | 4,096 | 5.00 | 0 |
| `line_j(s)` of day 20730 against day 20731 | 4,096 | 4.56 | 0 |
The plant (prev not XORed in, one double round) reads 3,385 to 3,585 cells over 6 sigma per segment table (worst 64) and 1,113 in the day table; fired.
## 5. Q1 (4): the exhaustive image census at w = 2
Command (box 2, file 95): `adv-cache-3 image --w 2 --rounds 6 --depth 64 --threads 87` (log `image-w2-r6-d64-partial-to-depth8.log`). The 16-word block at 2-bit words is a 32-bit state; every one of the 2^32 states is enumerated at each step, so the census is exact. `S_0` is every state; `S_k = { B(p XOR c_k) : p in S_{k-1} }` with the real constant layout truncated to 2 bits (`j` wraps mod 4). What it measures: how much of the state space the chain can still reach at depth `k`, against a random function (`tau_k = 1 - exp(-tau_{k-1})`) and a permutation (1 at every depth, the `no-feedforward` plant).
| Depth | Image of 2^32 | Random-function recursion | Difference |
|---|---|---|---|
| 1 | 0.632142 | 0.632121 | +2.1 x 10^-5 |
| 2 | 0.468559 | 0.468536 | +2.3 x 10^-5 |
| 4 | 0.312098 | 0.312080 | +1.8 x 10^-5 |
| 8 | 0.189061 | 0.189050 | +1.1 x 10^-5 |
Reading so far: `B = C + x` behaves as a random function to five decimal places at every measured depth, so the chain loses `log2(k / 2)` bits of its 512 per `k` steps (about 5 bits at depth 64) and no faster. A skip would show as an image smaller than the recursion (a collapse) or larger (a permutation-like structure); neither. The run was released at depth 8 (20:24) for the class v5 gate and is queued again in full with the plant (file 97, 48 cores, behind every "v5 gate" or "v5 kit" waiter).
## 6. Consequences per tier
Every row is a bound or a bookkeeping correction, so nothing changes for any tier today: a home miner with one 8, 12, 16 or 24 GB card on any vendor and OS, a rig and a pool user fill the 256 MiB cache once a day (0.2 s on one core per the spec's table, under a second at the growth steps) and the hash never reads it. For the chip model: the partial-cache price at small `f` is about half of what the hold-every-k-th curve says (section 3), which makes a chip holding 1/64 of the cache pay 9.3x the item's operations instead of 17.4x; still far above the full store, and at `f = 1/2` nothing moves, so the SRAM column (128 mm^2, $46 at N5 for 256 MiB) stays the chip's cost. What is being done: the curve row is handed to the coordinator for `chip-model-v3.md` and sibling `adv-cache`'s table; the image census completes; section 8b names the one statistic that would sharpen the reduced-round margin.
## 7. What is not covered
- No differential-linear cryptanalysis of reduced ChaCha with chosen input differences and multi-bit masks; the ladder here stops where single-bit statistics stop (two double rounds at 4,096 to 2^16 samples). Public work on 7 of 20 rounds is general knowledge here, not a citation, and the real `B` has 12 rounds.
- The 2-bit and 4-bit models change the rotations (1, 1, 1, 3 and 1, 1, 1, 1) and truncate `s` and `j`; they test the code path and the chain shape, not ChaCha's diffusion.
- The derivation program class (`derive_len != 0`) is not exercised; class v4 has the fixed mixer and the chain does not depend on it.
- GPU: no row; nothing in this class needs one.
## 8b. What a longer pass would add
One line: a differential-linear sweep on the reduced ladder (one chosen input difference, every output bit and every two-bit output mask, 2^24 samples per round count, 2 to 6 double rounds) would put a number on the round margin where section 1's single-bit tests stop at two double rounds; it changes no row at 12 rounds, and nothing here is a reason to wait for it.
## 9. Run ledger and box-hours
| Run | Box | Started (BST) | Wall | Slot-hours |
|---|---|---|---|---|
| `check`, first `skip` (binary `067ad69c...`) | 1 | 20:06, 20:09 | 2 s, 1 s (3 min waiting on the sweep lock) | 0.01 |
| 93 skip batch, 94 relations batch | 1 | queued 20:15 behind the sweep lock; never started | killed by pid file 20:20 BST under main's rule (every sweep through the build-server lane's `lease pool`; nothing measured was lost) | 0 |
| 95 image census | 2 | queued 20:12 behind the sweep lock; never started | killed by pid file 20:21 BST, the same rule | 0 |
| 93, 94, 96 (box 1) and 95 (box 2), re-queued | 1, 2 | when `lease pool` lands | through `lease pool <threads> --owner adv-cache-3 -- <cmd>` | |
| `check`, first `skip` (binary `067ad69c...`, under the sweep flock) | 1 | 20:06, 20:09 | 2 s, 1 s (3 min waiting for the lock) | 0.001 |
| Files 93, 94, 95 queued under the sweep flock | 1, 2 | 20:12 to 20:15 | never started; killed by pid file 20:20 to 20:21 under main's rule (every sweep through `lease pool`); nothing measured was lost | 0 |
| File 93 (14 runs: skip x 10, pebble x 2, cross x 2), file 94 (relations x 4), file 96 (skip at 1,024 lines x 4), through `lease pool 88` | 1 | 20:22:52 to 20:23:06 | 14 s in all, 0.1 to 2 s per run on 88 cores | 0.004 |
| File 95, the image census, `lease pool 88` (87 cores taken) | 2 | 20:22:46 | 106 s to depth 8; released at 20:24:38 by main's order for the class v5 gate (partial kept) | 0.026 |
| File 97, the image census again plus the plant, `lease pool 48 --min 16`, yielding to every "v5 gate" or "v5 kit" waiter | 2 | queued 20:26 | | |
Running total: under 0.1 box-hours of the 8 budgeted (the ask line is 16); no pod-hours (no GPU row).
Running total: 0.04 slot-hours of the 8 budgeted (the ask line is 16); no pod-hours. Every sweep the plan called for ran in seconds because the chain is 2^22 blocks a day and the statistics here are 2^22 to 2^27 block evaluations; the width went into day keys, chain lengths and the reduced-round ladder rather than into time.