diff --git a/docs/plans/counter-asic-3-status.md b/docs/plans/counter-asic-3-status.md index ae676f39..61181128 100644 --- a/docs/plans/counter-asic-3-status.md +++ b/docs/plans/counter-asic-3-status.md @@ -345,6 +345,10 @@ the project lead gave the go in advance for tonight: the shipper runs publish 1 The cryptanalysis brief's rank-3 question (a weak-key class in the day's rotation and multiplier draws, MEMHARD's untested all-equal ROT draw) is now measured: `docs/analysis/attack-pass/f4-weakday.md` (branch attack-pass). No weak class: the cheap days are the tail of a sum (the exact convolution predicts the census to 0.6 percent). Against the DSP-bound datapath (M2) PASS, 0 of 2^28 days over 1.1x. On the LUT-adder metric (M1, every multiply in adders, census median 231 adders per mixer application) 5,476 of 2^24 days over 1.1x (3.26e-4, 342x the 2^-20 gate); the worst in 2^24 1.173x; the worst in the public calendar's first 100 years chain day 29,337 at 1.121x (M2 1.000x). Priced: a per-day LUT-recompute FPGA gets at most 12.1 percent more hash rate on that day (reads and shadow untouched), 12 days a century, 0.004 percent of a century's hashes; 0 for a stored-dataset FPGA or any chip; one bitstream a day under USD 3 compiled ahead on the public calendar. Consequence per tier: nothing for any GPU miner or pool; the chip model is unmoved. The rule for the NEXT class (sent to the v5 lane with F4's harness as the gate; v4 untouched): reject a MUL block with NAF sum under 163, NAF weight at least 4 per word, at least 4 distinct ROT amounts, redraw from the next stream values, 6.1e-4 rejection per day, the first calendar redraw day 22,633; no devnet or testnet pack changes. +### AP-F1-1, the shadow redundancy bound (the attack-pass lane, 7 October, 12:3x UK): PASS against v4, a class v5 rule + +Over 100,000 class v4 programs the shadow block's peephole-removable instructions (a register written twice from one source with no write between) average 0.62 percent of the 256 per pass, maximum 5.078 percent, 1 in 100,000 over 5 percent; nothing crosses a pass; clang -O3 removes the same instructions from the honest kernel, so it is a bound on the shadow's useful work, not a chip shortcut (`docs/analysis/attack-pass/f1-shadow.md`). Consequence per tier: nothing for any miner or chip; the chip model is unmoved. The rule for the next class (sent to the v5 lane with F1's harness on 64 seeds as the gate; v4 untouched): the generator refuses a shadow block whose honest-compiler simplification exceeds a fraction set from the census (a 5 percent bound rejects about 1e-5 of draws, 3 percent about 4e-3) and redraws. + ## 8. Close Closed 6 October 2026, 18:1x UTC. The lanes: item 1 (ca3-analysis), item 2 (ca3-derive), items 4 and 5 (ca3-detector), item 3 (ca3-crypto-brief), items 6 and 7 (ca3-reserve), item 8 (ca3-shadow), the PC 1 AMD jobs (ca3-pc1-amd), the hash gates (ca3-v4-hash) and the node gates with both preconditions (ca3-v4-node and the fork): thank you, every one of you, for the numbers and for the faults you found in your own work and in mine before they reached a cut.