adv-mixer: Q1 deepening rows (linrel 16 days x 3 K, lineindex K1-3, CNF model); sweeps running

Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-07 18:52:16 +00:00
parent 1662a76082
commit d10eee9f34

View file

@ -132,6 +132,69 @@ above does not depend on the choice. Reconciling the median is handed to adv-mix
1.17x FPGA-datapath gain the chip model does not credit as hash rate (the chip is bound by the 8 cache reads and
the fixed op count, not by one day's multiply-adder count), and a weak day is a public calendar.
## Q1 deepening (from 20:4x BST): more days, all key pairs, exact relations, the address bits, a SAT model
Main's re-scope asked for the probes at full 32-bit width over more days and more rk pairs, a SAT model of two
keyed applications for an algebraic relation, and a relation search in the s[0] line-index bits. Binary sha256
bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 (frozen-identical tree, same bytes on both
boxes). Queue files tools/attack/adv-mixer/queue/11..14, claimed in /srv/builds/_adv/mixer/claims. Logs under
/srv/builds/_adv-adv-mixer/logs on each box, copied into docs/analysis/cryptanalysis/logs/adv-mixer when done.
### Exact affine-relation search at full width (linrel), queue 14, box 2
Command: `attack-adv-mixer linrel --day 20729 --apps K --samples 8192 --days 16` for K in 1, 2, 8. Each sample
is a GF(2) row over 1025 columns (512 input bits, 512 output bits, the constant). Rank 1025 means no exact
affine relation a.x XOR b.y = c exists between the input and output bits of K applications; a chance survivor
has odds 2^-(8192-1025) = 2^-7167.
| Applications K | Days (20729 to 20744) | Rank | Kernel dimension | Reading |
|---|---|---|---|---|
| 1 | 16 of 16 | 1025 | 0 | no affine relation after one application |
| 2 | 16 of 16 | 1025 | 0 | no affine relation after two |
| 8 | 16 of 16 | 1025 | 0 | no affine relation across the full between-reads block |
This is the decidable algebraic probe the brief's "algebraic form" question needs: at full width with the real
day constants there is no linear or affine structure a chip could use to batch or predict the 8 applications.
### The line-index bits of s[0] (lineindex), queue 13, box 1
Command: `attack-adv-mixer lineindex --day 20729 --apps K --states 1000000 --threads 44`. The 22 address bits
(s[0] AND 2^22-1) against each of the 512 input bits; band 8 sigma = 0.004 at 1e6 states.
| K | Mean address-bit flip | Holes / 11264 | Strong cells / 11264 | Worst cell | Verdict |
|---|---|---|---|---|---|
| 1 | 0.4275 | 70 | 6904 | 1000 sigma | FINDING: address bits predictable after one application |
| 2 | 0.500007 | 0 | 0 | 3.9 sigma | clean |
| 3 | clean | 0 | 0 | inside band | clean |
| 4 | running | | | | RUNNING |
Reading for the chip: the line index a read depends on is not predictable before the second of the 8
applications completes, so a prefetch cannot hide more than 1 of the 8 applications behind the memory latency.
The address-restricted exact relation search (linrel --addr, 8 days, K = 1 and 2) is in the same queue file and
lands here.
### Fold probes over 1024 days and all 71 adjacent key pairs (fold-sweep), queue 11, box 1
Command: `attack-adv-mixer fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44`: probes (a) and
(c) on every adjacent application pair (i, i+1) for i in 0..70 and probe (b) on the full block, per day.
RUNNING; the row lands here.
### Integral degree test over 32 days (integral), queue 12, box 2
Command: `attack-adv-mixer integral --day 20729 --apps K --dmax 16 --placements 2000 --days 32` for K = 1, 2.
RUNNING; the row lands here.
### SAT model of two keyed applications (cnf), queue 14 then a solve on box 2
Command: `attack-adv-mixer cnf --day 20729 --out .../adv-mixer-commute-20729.cnf`. Bit-exact Tseitin encoding
of M(M(x,rk1),rk2) and M(M(x,rk2),rk1) on a shared 512-variable input with the two outputs constrained equal:
105,652 variables, 361,188 clauses, 6.8 MB. SAT = a state on which the two key orders commute; UNSAT = a proof
over all 2^512 states that fold probe (c) holds exactly. No solver reaches the box from crates.io (HTTP 403), so
the harness marks the solve BLOCKED; the sibling lane adv-mixer-3 has cadical 3.0.1 built from source on box 2,
and that binary is running on this instance under a one-hour cap at nice 10 (log sat-commute-20729.log).
RUNNING; the row lands here. A timeout is the honest expected outcome: the instance is a preimage-shaped search
on a 2^512 space, and a plain timeout is a bound on solver reach, not evidence either way.
## Confirmation across the stale and frozen trees
The branch was first cut from stale master 3f0afcd5. Its igneum-pow differed from the frozen object in six