Class v6 family gate, the 17:00 cut: the last-resort rows corrected for class v5's verified scan (the finding at the corner is the correlation of one era's attempts, 1,000x the independent estimate, not an unchecked program); the harness patch series at 236ef3a5 (the lossy-share curve and the scan's verdict column)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-08 11:27:11 +00:00
parent d4cd6a3ce2
commit debcb01092
2 changed files with 89 additions and 10 deletions

View file

@ -119,7 +119,7 @@ The three rings. A test's ring says who runs it and what a failure costs.
| (c''') the hot-item floor at 0.995 | the same `E_s`; the floor's clean spread re-read per stratum (section 6): a fixed 0.995 under a spread that moves with the shape or the width is either a liveness cost or a miss | seed 100767 (0.9919) and the nine live hot sets | 2.435 percent of accepted class v4 programs, +0.045 on the mean attempt | in the (c'') pass |
| The per-site largest-256-item-bucket bound (NEW, the F8 tail's catch) | the largest count over a site's 4,096-word buckets in its window against `N / (W_s / 4096)`, in SIGMA of the bucket's expectation (`(max - E) / sqrt(E)`), refused above a band set from the clean spread. The ratio alone cannot carry the bound: a clean full-window site's largest of 65,536 Poisson(16) buckets reads 2.1x at +4.4 sigma, a quarter-window site's largest of 16,384 Poisson(64) buckets 1.5x at +4 sigma (the 16-era smoke run read ratios 2.2 to 2.4 on clean sites); the four tail seeds' 3.1x to 5.6x at narrow windows are +17 to +37 sigma | p4, p8, p10, p34 | measured in section 6 (the columns `bucket_z_max`, `bucket_win`) | one linear pass over the (c'') indices |
| The index-bit bias read (NEW, adv-cache-2's value-level test) | per site, the one-count of each free index bit (bits above the width's alignment and below the window's cut) over the 2^20 evaluations, in sigma (`sigma = sqrt(N) / 2 = 512`); a 6-sigma band is a bias of 0.3 percent at 2^20 (the product law's bit 0 at 25 percent reads z about 512, bit 1 at 3/8 z 256, bit 3 at 3.1 percent z 64, bit 6 at 0.4 percent z 8, bit 7 at 0.2 percent z 4: passes). MEASURED on the first 16 drawn eras (11:21 BST, section 6): 7 of 16 accepted programs carry one site with a bias of 130 to 511 sigma at address bit R or R + 1 (the era's rotation), the era-stride class exactly, on programs (c''') passes at 0.9954 to 1.0000; the 9 others read under 3.8 sigma. So as a REFUSAL the read would redraw about 40 percent of epochs; its right use is as a record per era plus the structural lever (fold the product's low bits in `load_index` before the rotation, a next-class item), and the chip price is stated in section 5 | Devnet 3 site 0, era-drawn-28 site 15, the per-load candidate 0; and now the 7 of 16 | 7 of 16 at 6 sigma (a refusal is not the form); 0 of 16 at a 600-sigma band | one pass over the indices, 28 bit tests each |
| The cap and the last resort | unchanged at 256; the last resort's own verdict is adv-accept-3's finding 1 (9 percent of last-resort programs fail (a)); the family keeps the open fix (continue past 256 until one passes) | the reject-everything mirror | 0 reached in 1.02 x 10^6 seeds | n/a |
| The cap and the last resort | unchanged at 256; class v5 carries the verified construction (`last_resort_v5`: a scan of 256 more candidates past the cap, each rewritten and its stale loads re-sourced, the first that passes the whole rule; the unchecked fallback behind it), so adv-accept-3's finding 1 (sub-version 3's unchecked last resort failing (a) in 9 percent of seeds) is closed on the family's crate. What the family changes: the scan's stated odds (under 1e-300) assume independent attempts, and section 6 measures a per-era exhaustion rate 1,000x the independent estimate at the lossy corner, so the fallback's odds are the corner's, not the arithmetic's; ring A keeps the corner out of the band | the reject-everything mirror; the 61 exhausted eras of section 6 (the scan's verdict on each is the full report's item 5) | 0 reached in 1.02 x 10^6 seeds of the shipped draw; 0 of 19,000 family eras outside the lossy corner | n/a |
### 3.3 Ring C: the offline tests per drawn era
@ -184,14 +184,14 @@ What the family gate cannot see, and how a chip would use it.
| The verifier at `m = 16` and rung 2 on a 2019-class core | unmeasured (an estimate of 9 ms against the 10 ms gate) | nothing for a chip; a node tier retired if the corner is drawn | the row is owed before 16 enters the band |
| The acceptance's stand-in at D = 28 against a live D = 29 | the windows cap `min(k_off, D - 26)` and the rotation's cut set move with D; the gap is measured at D = 28 only | a per-site concentration the closed form does not reproduce | 0.0004 at D = 28; unmeasured at 29 (ring C row) |
| The union bound's own looseness | the per-test miss rates rest on 3 to 11 known-failed cases each (section 2.2), so the family's false-pass rate is not yet a number under 1 | nothing new; the bound is on what the gate claims, not on the hash | fixed by cases, not eras: 60 fired cases per test for `delta` under 0.05 |
| The last-resort program | 9 percent of last-resort programs fail (a) and are handed out unchecked; a lossy-corner era that raised `r` toward 0.95 would reach it at 2e-6 per epoch | a program that re-reads one address in two loads of the same hash | ring A's lossy-share bound keeps `r` under 0.85 (`r^256` under 1e-18); the fix (continue past 256) is owed to the rule's owner |
| The last-resort path at a corner | class v5's scan hands out a rule-checked program, and its unchecked fallback is priced at under 1e-300 on INDEPENDENT attempts; the lossy corner measured 1.2 percent of eras exhausting against a 1.3e-5 independent estimate, so at a corner the attempts of one era are correlated through the era's own weights and the fallback's odds are unknown there | a program that re-reads one address in two loads of the same hash, if the fallback were ever reached | ring A keeps the corner out of the band (0 of 19,000 eras exhaust elsewhere); the scan's verdict on the 61 exhausted eras is owed (section 7 item 5) |
| The era redraw's own grindability | a ring-A redraw consumes the stream's next block, so an adversary who could steer `E_n` could steer which block is used; the era VDF of F7 (517 s on the fastest prover, 259x the window) closes the steering of `E_n` itself | nothing beyond F7's bound | F7 (a) PASS with the VDF in the node |
A GPU-like chip (the `f = 1` stored-dataset chip with a programmable core, chip-model-v3 section 5) loses nothing on any era of the family: every drawn parameter is firmware to it, and what the family costs it is the core sized for the band's top (the research lane's USD 30 to 60 per chip, modelled). The family gate's job is therefore not to defeat that chip (the identity of the research file's section 2 says the per-joule edge is the card's own idle, 2.1x at `k = 1`) but to make sure no drawn era hands ANY chip more than the one hash did: a per-era hot set, a per-era mixer shortcut, a per-era verifier miss. Everything in this document is a bound on that increment, and the increments found so far are 1.002x and 1.0024x.
## 6. The coverage measured (24,000 drawn eras, 11:16 to 12:13 BST, 8 October 2026)
The harness: branch `family-gate-v5` at e94f4db0 (the class v5 crate 8f481459 plus `accept::tests::family_gate_era_census`; the patch series is `logs/harness-family-gate-v5-e94f4db0.patch` in this directory, since the branch's push to the mirror was refused by the class v5 tree's own pre-push hook and is held). What it does per era `k` of a label space: the era bytes from `igneum-family-gate[/stratum]/era/k` and the epoch bytes from `.../program/k` (the F8 label space's form); from the era's own stream, in a fixed order and consumed whether pinned or not, the shadow block shape in {64 x 108, 128 x 54, 256 x 27}, the mixer multiplier in {4, 8, 16} (recorded: the acceptance never runs the mixer), the ten non-load weights perturbed by `below(2B + 1) - B` with shfl and mulhi never raised and renormalised to 75 by largest remainder (B = 4), the read width through the era draw over {1, 4} words (the mix one-hot on the drawn width); then the chain draw of that era's epoch through the real rule keyed on the family's shape (`is_family_shape`, the acceptance's `is_class_v4_shape` generalised behind `IGNEUM_FAMILY_GATE`; the draw's source rule reads the same predicate), every candidate's first failing part recorded, the cap 256 and the last resort as shipped; on the accepted program, on the rule's own 2^20 sample (4,096 units), per site: the (c'') and (c''') ratio with the window divided by the width, the largest 4,096-word (256-item) bucket in sigma of its expectation, and the largest index-bit one-count excess in sigma over the free bits. One TSV row per era (`logs/<stratum>-family_gate_era_census-<from>-<n>.tsv`, the run's log beside it with the binary's sha256 and the lease line); every binary a pinned copy under `/srv/builds/_adv-family-gate/bin/<tag>/` (fg2 9b7f764a for the first corners, fg5 e7a50f8d for the width-4 and lossy-base strata). Cost: about 10 core-seconds per era; 54.4 core-hours in all (1.7 box-hours of 32-core slots) on build-1 (random, lossy cap, width 4) and build-3 (shape 64, lossy base, width 4 plus lossy cap), every run under `lease pool` at class measure. The control: `v5_attempts_census` on the shipped class v5 draw over 10,000 seeds of the F8 label space (build-1, 24 cores, 1,534 s, binary 4bec799c, `logs/base-v5_attempts_census-1000-10000.log`): r = 0.6854, mean attempt 2.179, 0 exhaustions, (a') 82.5 percent of rejections, (c''') 0.9 percent, the row-90 reading reproduced.
The harness: branch `family-gate-v5` at 236ef3a5 (the class v5 crate 8f481459 plus `accept::tests::family_gate_era_census`; the patch series is `logs/harness-family-gate-v5-236ef3a5.patch` in this directory, since the branch's push to the mirror was refused by the class v5 tree's own pre-push hook and is held). What it does per era `k` of a label space: the era bytes from `igneum-family-gate[/stratum]/era/k` and the epoch bytes from `.../program/k` (the F8 label space's form); from the era's own stream, in a fixed order and consumed whether pinned or not, the shadow block shape in {64 x 108, 128 x 54, 256 x 27}, the mixer multiplier in {4, 8, 16} (recorded: the acceptance never runs the mixer), the ten non-load weights perturbed by `below(2B + 1) - B` with shfl and mulhi never raised and renormalised to 75 by largest remainder (B = 4), the read width through the era draw over {1, 4} words (the mix one-hot on the drawn width); then the chain draw of that era's epoch through the real rule keyed on the family's shape (`is_family_shape`, the acceptance's `is_class_v4_shape` generalised behind `IGNEUM_FAMILY_GATE`; the draw's source rule reads the same predicate), every candidate's first failing part recorded, the cap 256 and the last resort as shipped; on the accepted program, on the rule's own 2^20 sample (4,096 units), per site: the (c'') and (c''') ratio with the window divided by the width, the largest 4,096-word (256-item) bucket in sigma of its expectation, and the largest index-bit one-count excess in sigma over the free bits. One TSV row per era (`logs/<stratum>-family_gate_era_census-<from>-<n>.tsv`, the run's log beside it with the binary's sha256 and the lease line); every binary a pinned copy under `/srv/builds/_adv-family-gate/bin/<tag>/` (fg2 9b7f764a for the first corners, fg5 e7a50f8d for the width-4 and lossy-base strata). Cost: about 10 core-seconds per era; 54.4 core-hours in all (1.7 box-hours of 32-core slots) on build-1 (random, lossy cap, width 4) and build-3 (shape 64, lossy base, width 4 plus lossy cap), every run under `lease pool` at class measure. The control: `v5_attempts_census` on the shipped class v5 draw over 10,000 seeds of the F8 label space (build-1, 24 cores, 1,534 s, binary 4bec799c, `logs/base-v5_attempts_census-1000-10000.log`): r = 0.6854, mean attempt 2.179, 0 exhaustions, (a') 82.5 percent of rejections, (c''') 0.9 percent, the row-90 reading reproduced.
Voided and stated: the first width-4 stratum (3,000 eras, 11:2x to 11:4x BST) ran at width 1, because `LoadClass::era` with a one-entry allowed set is the pinned path and redraws to the base's widest width; the fix builds the pinned class by hand (the era drawn over the one-entry set, the mix one-hot); the void rows are not in this directory and the stratum was re-run under its own label space. The first corner strata (lossy cap, shape 64) share the random stratum's label space, so where the random draw happened to land on the pinned value the era is the same program in both; the later strata use per-stratum labels.
@ -240,7 +240,7 @@ Readings, each a measured row above:
| An era of the proposed band whose chain draw exhausts the 256 cap | 3,000 of 3,000 passed (lossy base) | under 1.0e-3 of eras (one in 1,000: one per 490 years at 180-day eras) | under 1.5e-3 |
| The same on the random stratum at B = 4 on every family | 10,000 of 10,000 | under 3.0e-4 | under 4.6e-4 |
| An era of the band whose accepted draw sits under the (c''') floor | 3,000 of 3,000 (and 19,000 of 19,000 outside the lossy corner) | under 1.0e-3 | under 1.5e-3 |
| An era of the lossy corner that exhausts | 61 of 5,000 FAILED | the rate is 1.2 percent, a measurement, not a bound: the corner is out of the band | |
| An era of the lossy corner that exhausts | 61 of 5,000 FAILED | the rate is 1.2 percent, a measurement, not a bound: the corner is out of the band; class v5's last-resort scan then hands each such era a rule-checked program (the scan's own verdicts on the 61 are owed) | |
| The (c''') floor's miss rate on the few-item hot-set class | 9 of 9 fired (unchanged: this census reads the acceptance's sample, not the live dataset) | under 0.33 | under 0.40 |
| The bit-bias read's firing on the product class | 5,172 of the random stratum's eras read over 6 sigma; the three named cases (Devnet 3 site 0, era-drawn-28 site 15, the per-load candidate 0) are of that class | a record, not a refusal: no miss rate is claimed | |
@ -252,7 +252,7 @@ The union bound stays loose where section 2.2 said it would: the two floors' mis
2. The bucket bound stated in sigma from the bit-clean spread (p99 +6.8, max +28 over 4,828 eras): a band at +8 sigma refuses under 1 percent of bit-clean programs and every F8 tail seed (+17 to +37); its cost on the biased eras is the bit read's cost, so the two tests are one rule.
3. The lossy-corner reading taken one step further: the exhaustion rate per era against the lossy share in points (18 to 30 of 75), so the band's edge is a measured curve, not one corner; 10^4 seeds at each of three shares.
4. The mixer rows at `m = 4` and 16 (adv-mixer-3's index and sac at k = 2 on two days; the SAT at k = 2) as the per-family corner rows, on build-4 when its pool frees; else the plan with its hours.
5. The last-resort programs of the 61 exhausted eras run through the real rule (adv-accept-3's finding 1 at the corner: how many fail (a)).
5. The class v5 last-resort scan on the 61 exhausted eras (the first passing k past the cap, or the fallback), and the lossy-share curve at +1, +2, +3 and +4 points (3,000 eras each, running on build-1 from 12:5x BST with the fg6 harness).
6. The F8-form census at 2^24 on 64 seeds of two eras of the band (one at width 4, one with a 1,000-sigma site under R in 1..27), the first ring-C rows on the family (about 2 box-hours each): the live-dataset hot-set price of the bit-level bias.
7. The gate-record JSON per era (the format of 4.3) generated from the TSV rows by `fg-records.py` (in `logs/`), and the family summary.
8. The two build-4 strata (shape 64 plus lossy cap, shape 256) when its pool frees; nothing in the cut depends on them.

View file

@ -1,7 +1,7 @@
From 4c408ef180a2f9a321756e10de224b7610c37cbc Mon Sep 17 00:00:00 2001
From: igneum-labs <337424239+[removed]>
Date: Thu, 8 Oct 2026 11:15:23 +0100
Subject: [PATCH 1/5] class v6 family-gate harness: the acceptance keyed on the
Subject: [PATCH 1/6] class v6 family-gate harness: the acceptance keyed on the
family's shapes behind IGNEUM_FAMILY_GATE (never a chain path), per-thread
weight tables, family_site_stats (largest 256-item bucket, index-bit bias)
and the family_gate_era_census test (one drawn era per seed, every parameter
@ -396,7 +396,7 @@ index 3f2d6723..00730eac 100644
From 1d5f551e0bec6840377c5e5bc3b98fe00e2cb5fa Mon Sep 17 00:00:00 2001
From: igneum-labs <337424239+[removed]>
Date: Thu, 8 Oct 2026 11:22:50 +0100
Subject: [PATCH 2/5] family-gate harness: the bucket excess in sigma and each
Subject: [PATCH 2/6] family-gate harness: the bucket excess in sigma and each
site's window draw beside the ratio (a clean full-window site reads a ratio
of 2.1 at +4.4 sigma, so the ratio alone cannot carry a bound); the
retired-weights doc comment back on its item
@ -507,7 +507,7 @@ index 00730eac..6e611d45 100644
From adce49deea93678b0165fbaa76349a0b347794c5 Mon Sep 17 00:00:00 2001
From: igneum-labs <337424239+[removed]>
Date: Thu, 8 Oct 2026 11:33:16 +0100
Subject: [PATCH 3/5] family-gate harness: a pinned width is a two-entry
Subject: [PATCH 3/6] family-gate harness: a pinned width is a two-entry
allowed set (the one-entry set is LoadClass::era's pinned path and redraws to
the base's 1 word: the first width-4 stratum ran at width 1, void)
@ -542,7 +542,7 @@ index f9febaab..c92a54ce 100644
From a1a7e1318961869b0ef074ec753e1bb45544127b Mon Sep 17 00:00:00 2001
From: igneum-labs <337424239+[removed]>
Date: Thu, 8 Oct 2026 11:41:57 +0100
Subject: [PATCH 4/5] family-gate harness: IGNEUM_FG_LOSSY_BASE, the proposed
Subject: [PATCH 4/6] family-gate harness: IGNEUM_FG_LOSSY_BASE, the proposed
band (B on the injecting families only, or/mul/mulhi never raised)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@ -581,7 +581,7 @@ index c92a54ce..d6551ec5 100644
From e94f4db05dd3fd76e356de8bdb4de70455144e5c Mon Sep 17 00:00:00 2001
From: igneum-labs <337424239+[removed]>
Date: Thu, 8 Oct 2026 11:43:12 +0100
Subject: [PATCH 5/5] family-gate harness: a pinned width builds the class by
Subject: [PATCH 5/6] family-gate harness: a pinned width builds the class by
hand (era_draw over the one-entry set, the mix one-hot); the two-entry set
tripped era_draw's ascending assert (w4b exit 101)
@ -625,3 +625,82 @@ index d6551ec5..f38e4399 100644
--
2.41.0
From 236ef3a5c2ce4bb3f82310d5eabb1b9cadc423c0 Mon Sep 17 00:00:00 2001
From: igneum-labs <337424239+[removed]>
Date: Thu, 8 Oct 2026 12:26:37 +0100
Subject: [PATCH 6/6] family-gate harness: IGNEUM_FG_LOSSY_PLUS=n (the
lossy-share curve) and the class v5 last-resort scan on an exhausted era (the
first passing k past the cap, or fallback)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---
igneum-pow/src/accept.rs | 28 ++++++++++++++++++++++++++--
1 file changed, 26 insertions(+), 2 deletions(-)
diff --git a/igneum-pow/src/accept.rs b/igneum-pow/src/accept.rs
index f38e4399..533ec672 100644
--- a/igneum-pow/src/accept.rs
+++ b/igneum-pow/src/accept.rs
@@ -1419,10 +1419,12 @@ mod tests {
// the proposed band after the 12:00 BST reading of 8 October: B on the injecting families only, the three lossy
// families (or, mul, mulhi) never raised above their base
let lossy_base = std::env::var_os("IGNEUM_FG_LOSSY_BASE").is_some();
+ // the lossy-share curve (the full report's item 3): or, mul and mulhi each at exactly +n points
+ let lossy_plus: Option<i64> = std::env::var("IGNEUM_FG_LOSSY_PLUS").ok().and_then(|v| v.parse().ok());
let out_path = std::env::var("IGNEUM_FG_OUT").unwrap_or_else(|_| "family-gate.tsv".to_string());
let out = Mutex::new(std::fs::File::create(&out_path).expect("IGNEUM_FG_OUT"));
let wnames: Vec<String> = NONLOAD_WEIGHTS.iter().map(|(o, _)| format!("w_{o:?}").to_lowercase()).collect();
- writeln!(out.lock().unwrap(), "k\tshape\treps\tmixer\twidth\tR\tM\tpos\t{}\tattempt\tcandidates\ta_prime\ta\tb\tc_const\tc_lane\tc_sat\tc_bias\tc_distinct\tc1_sat_source\tc2_low_entropy\tc3_hot_item\tmin_ratio\tmin_site\ttop_count_max\tbucket_ratio_max\tbucket_z_max\tbucket_site\tbucket_win\tbit_z_max\tbit_site\tbit_win\tbit\tsecs", wnames.join("\t")).unwrap();
+ writeln!(out.lock().unwrap(), "k\tshape\treps\tmixer\twidth\tR\tM\tpos\t{}\tattempt\tcandidates\ta_prime\ta\tb\tc_const\tc_lane\tc_sat\tc_bias\tc_distinct\tc1_sat_source\tc2_low_entropy\tc3_hot_item\tmin_ratio\tmin_site\ttop_count_max\tbucket_ratio_max\tbucket_z_max\tbucket_site\tbucket_win\tbit_z_max\tbit_site\tbit_win\tbit\tlast_resort_k\tsecs", wnames.join("\t")).unwrap();
let part_ix = |r: &Reject| -> usize {
match r {
Reject::UnfreshLoadSource { .. } => 0,
@@ -1472,6 +1474,11 @@ mod tests {
if lossy_base && matches!(op, Op::Or | Op::Mul | Op::MulHi) && d > 0 {
d = 0;
}
+ if let Some(n) = lossy_plus {
+ if matches!(op, Op::Or | Op::Mul | Op::MulHi) {
+ d = n;
+ }
+ }
raw[i] = (*wgt as i64 + d).max(1);
}
// renormalise to 75 by largest remainder
@@ -1528,6 +1535,23 @@ mod tests {
Err(r) => parts[part_ix(&r)] += 1,
}
}
+ // an exhausted era takes class v5's last resort: the scan of 256 more candidates past the cap, each
+ // rewritten (or, mul, mulhi to xor) and its stale loads re-sourced, the first that passes the whole
+ // rule; the column records that k (cap + i), or "fallback" when none of the 256 passed
+ let last_resort_k: String = if accepted.is_none() {
+ use crate::generator::{last_resort_v4, repair_stale_loads, LAST_RESORT_SCAN};
+ let mut found = String::from("fallback");
+ for kk in MAX_ATTEMPTS_V4..MAX_ATTEMPTS_V4 + LAST_RESORT_SCAN {
+ let q = repair_stale_loads(last_resort_v4(candidate_class(&lbl, &epoch, kk, class)));
+ if check(&q).is_ok() {
+ found = kk.to_string();
+ break;
+ }
+ }
+ found
+ } else {
+ String::new()
+ };
set_family_weights(None);
let candidates: u32 = parts.iter().sum::<u32>() + accepted.is_some() as u32;
let (attempt, stats_row) = match &accepted {
@@ -1565,7 +1589,7 @@ mod tests {
};
let wcols: Vec<String> = weights.iter().map(|(_, x)| x.to_string()).collect();
let pcols: Vec<String> = parts.iter().map(|x| x.to_string()).collect();
- let row = format!("{k}\t{shape}\t{reps}\t{mixer}\t{}\t{}\t{:08x}\t{:?}\t{}\t{attempt}\t{candidates}\t{}\t{stats_row}\t{:.1}", e.width_words, e.stride_rot, e.stride_mul, e.pos, wcols.join("\t"), pcols.join("\t"), ts.elapsed().as_secs_f64());
+ let row = format!("{k}\t{shape}\t{reps}\t{mixer}\t{}\t{}\t{:08x}\t{:?}\t{}\t{attempt}\t{candidates}\t{}\t{stats_row}\t{last_resort_k}\t{:.1}", e.width_words, e.stride_rot, e.stride_mul, e.pos, wcols.join("\t"), pcols.join("\t"), ts.elapsed().as_secs_f64());
writeln!(out.lock().unwrap(), "{row}").unwrap();
let d = done.fetch_add(1, Ordering::Relaxed) + 1;
if d % 100 == 0 {
--
2.41.0