diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index 328c93e76..a373e4791 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -25,7 +25,7 @@ against the log before quoting it to the project lead. | F3 | Chained cache j+1 bound and storage-vs-recompute curve | no derivation under j+1 blocks; curve monotone; f=1 point unchanged | 0 of 64 and 0 of 1,024 lines under j+1 (exhaustive closure search, cross-checked by exhaustive pebbling at 10 lines, 10,240 pairs, 0 mismatches); both planted broken chains fire; curve monotone at both op counts; f=1 point 9,360 ops per item unchanged. Record `docs/analysis/attack-pass/f3-cache.md` | PASS | | F4 | Weak-day census over 2^24 day keys | fraction of days with gain over 1.1x under 2^-20 | pending box census | RUNNING | | F5 | Chip-model sweep + AWS F2 FPGA hour | evidence row 17 holds across the sweep; FPGA row under 27 M reads/s/W | sweep: 2.1x at k=1 GDDR7 reproduces, 3.2x at k=0.5, 4.1x at k=0.3 (matches ledger M32); FPGA row 2.3 to 2.9 G/s, 10 to 20 M reads/s/W (literature). FINDING: the k=0.33 figure is framed as the X9's measured core (M32) and a "measured class" (ladder branch ยง5a); the X9 was withdrawn before launch and never benchmarked. F2 hour SKIPPED: no AWS account | FIXED-AND-PASSED (sweep PASS; AP-F5-1 fixed and re-gated 7 Oct 2026: chip section re-run 2.1x at k=1 unchanged, identity grep 0 hits, site lane concurred); F2 hour SKIPPED-BY-DECISION (the project lead, 7 Oct 2026, 09:5x UK; plan 4.2 row F5 is the sweep only at 3714c2a0; the FPGA row stays the JEDEC-ceiling model row labelled unmeasured) | -| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | v4 average 4.90 to 5.06 ms one-core cold, 8.23 ms half-core proxy (under 10 ms). Worst-case search over 10^5 and laptop run owed | RUNNING | +| F6 | Verifier worst case over 10^5 programs + O-1.14 laptop run | worst program under 10 ms cold on the half-core proxy and the laptop | O-1.14 CLOSED on an i7-9700K (2019 desktop core): v4 6.006 ms avg, 6.334 cold max per warp; dr736 10.04 (the known-fail fires); box proxies 5.06 / 8.23. Worst-case search over 10^5 owed | RUNNING (O-1.14 closed) | | F7 | Era-draw bias harness + 2^20 era-seed census | no re-roll inside the publish window; no era class with gain over 1.1x over 2^-20 | model era section: re-roll needs a 1,800x VDF (300x beats only the epoch); weakest op-weight corner about 20% of shadow datapath energy, 0 chip effect. Harness + 2^20 census owed | RUNNING | | F8 | Uniformity censuses (line-index 2^28, distinct lines, cross-hash histogram) | largest bucket within 6 sigma of uniform; no hot set under 1% of items | interim, phase D at 2^26 nonces: top 0.1% of items take 0.520% of reads vs 0.115% uniform (4.05x), top 1% 2.49% (1.37x), one item 153x the mean, read site 15 feeds 6.37% of its reads into the hot 0.1% in all 8 iterations; shortcut under 1% of rate today. AP-F8-1: the 4.05x is largely the designed per-site windows of layer 8 (spec 1.13.1); the gate is now the window model from the program's own draws, the finding stays open only for the excess beyond it (the 153x item, or a low-entropy source at site 15 if the 64-seed census shows one); no generator change to v4 (on the live vote) | FINDING (open on the excess only) | | F9 | Acceptance edges (39) + header grinding on an RTX 5090 | zero passing programs with a hot set under 1%; grinding gain under 1% of rate | edges reproducible via `accept`; grinding measurement needs PC 2's 5090 or a rented pod | BLOCKED (PC 2 go / pod) | @@ -160,6 +160,32 @@ rent stood up and ran, hidden by Vast's instance listing cap of 25 rows on an ac idle and were destroyed. The fallback is re-rented under the same word (i7-9700K class, two-hour cap from its start, read by id); the result replaces this line when it lands. +O-1.14 RESULT, 7 October 2026, 09:49 UK, Vast instance 54613164, Intel Core i7-9700K (2019 desktop core, Coffee Lake, +read at 4,170 MHz during the run, 31 GB DDR4, Ubuntu 24.04), the box-built Linux `igneum-pow` (sha256 6d286783...), +`bench --seed igneum-genesis --day 2026-10-03 --warps 50` on one core (`taskset -c 1`), the host otherwise idle; log +`docs/analysis/attack-pass/o114-i7-9700K-2026-10-07.log`: + +| Class | Cold max (ms per warp) | Average of 50 (ms) | Gate 10 ms | Box one-core cold | Box half-core | +|---|---|---|---|---|---| +| v2 | 1.582 | 1.280 | pass | 1.30 | n/a | +| mx8 (class v3) | 5.394 | 5.267 | pass | 4.67 | 7.56 | +| mx8+sh256x27 (class v4, the target) | 6.334 | 6.006 | pass, 3.7 ms of headroom | 5.06 | 8.23 | +| dr368 | 5.540 | 5.426 | pass | 5.32 | 8.16 | +| dr736 (the known-fail) | 10.290 | 10.042 | FAIL, as it must | 10.51 | 15.49 | + +Cache fill 276 ms on the 9700K core (box 361 ms, M5 Max 175 to 181 ms). The 2019 desktop core sits between the box's +two proxies as the arithmetic predicted (1.2x the box one-core cold on v4, 0.77x the half-core); the known-fail +fires on it. A 2019 laptop core at 3.5 GHz reads about 15 to 20 percent slower than this desktop part (approximate, +clock ratio), so about 7.0 to 7.6 ms on v4, still under 10 ms. Consequences: a 2019-class node verifying class v4 +spends 0.6 percent of one core at 1 bps and 6 percent at 10 bps; a header flood needs about 160 invalid headers a +second to saturate one such core; a pool verifies about 160 shares a second per core; IBD of 108,000 headers is +about 11 minutes of one core. The implied ladder ceiling on this core: the shadow costs 0.74 ms per 55,296 +instructions (v4 minus mx8), so the 4.0 ms of headroom buys about 300,000 more shadow instructions, N about 650,000 +counted ops at the 1.83 convention (approximate), against 370,000 on the half-core proxy and 1,060,000 on the +2.5x rule; the half-core proxy stays the standing pessimistic rule and the ladder's ceiling should be taken from +it, not from this desktop part. O-1.14 is CLOSED on a real 2019-class core for the genesis program; the F6 row +still owes the 10^5-program worst case before it reads PASS. + Result (average, verified on the box): class v4 `mx8+sh256x27` runs 4.90 to 5.06 ms per warp cold on one EPYC 9454P core (nice 19, taskset), 8.23 ms on the half-core proxy (both SMT siblings busy). Under 10 ms. Status RUNNING: the 10^5-program worst-case search and the O-1.14 laptop relay run are owed before the row reads PASS. diff --git a/docs/analysis/attack-pass/o114-i7-9700K-2026-10-07.log b/docs/analysis/attack-pass/o114-i7-9700K-2026-10-07.log new file mode 100644 index 000000000..cd997b466 --- /dev/null +++ b/docs/analysis/attack-pass/o114-i7-9700K-2026-10-07.log @@ -0,0 +1,53 @@ +# O-1.14 bench start 2026-10-07T08:49:03Z host root@ssh9.vast.ai +Warning: Permanently added '[ssh9.vast.ai]:35608' (ED25519) to the list of known hosts. +Welcome to vast.ai. If authentication fails, try again after a few seconds, and double check your ssh key. +Have fun! +# binary copied, sha256 6d28678359d3d6bd158b245f7e522d6f2a5b0704d9997c0fb50ebc3471a9ebe5 +Welcome to vast.ai. If authentication fails, try again after a few seconds, and double check your ssh key. +Have fun! +# cpu: Intel(R) Core(TM) i7-9700K CPU @ 3.60GHz +# cores: 8 mem: 31 GB +# glibc: ldd (Ubuntu GLIBC 2.39-0ubuntu8.9) 2.39 +# clock MHz: 4169.856 + 08:49:07 up 20 days, 10:27, 0 user, load average: 0.13, 0.07, 0.05 +## --class v2 08:49:07Z +Welcome to vast.ai. If authentication fails, try again after a few seconds, and double check your ssh key. +Have fun! +cache: fill 283.0 ms on one core (2^26 words, 256 MiB, 65536 chains of 64 ChaCha12 blocks), FNV-1a 64 48c4f5bf24166b2e +warp base 0: single cold run 1.582 ms, 4096 items derived, lane0 42246ba99fc58e4f lane31 b08446b1f2de7793 +warp base 4096: single cold run 1.392 ms, 4096 items derived, lane0 3d3903e310ca038f lane31 61c242509efdccdd +warp base 1000000: single cold run 1.374 ms, 4096 items derived, lane0 f218c1bd58e6dfe0 lane31 6c3b2c11adfbfcac +CPU verify: 1.280 ms per 32-lane warp, avg of 50 (checksum 19297e99c7b9a55e) +## --class mx8 08:49:09Z +Welcome to vast.ai. If authentication fails, try again after a few seconds, and double check your ssh key. +Have fun! +cache: fill 276.6 ms on one core (2^26 words, 256 MiB, 65536 chains of 64 ChaCha12 blocks), FNV-1a 64 48c4f5bf24166b2e +warp base 0: single cold run 5.394 ms, 4096 items derived, lane0 19b56348bc85304d lane31 359192708e4f754a +warp base 4096: single cold run 5.285 ms, 4096 items derived, lane0 62fb132a9943127a lane31 7d7866cb9cfca8ff +warp base 1000000: single cold run 5.293 ms, 4096 items derived, lane0 86b6cb0e13d89b03 lane31 9c004678515e44ec +CPU verify: 5.267 ms per 32-lane warp, avg of 50 (checksum 653a23f7ee1c8c63) +## --program-class v4 08:49:11Z +Welcome to vast.ai. If authentication fails, try again after a few seconds, and double check your ssh key. +Have fun! +cache: fill 276.6 ms on one core (2^26 words, 256 MiB, 65536 chains of 64 ChaCha12 blocks), FNV-1a 64 48c4f5bf24166b2e +warp base 0: single cold run 6.334 ms, 4096 items derived, lane0 2576769ee4a14c8d lane31 c58ddcb717dd3370 +warp base 4096: single cold run 6.198 ms, 4096 items derived, lane0 1ce77a600ec573b4 lane31 03600a05ffba0055 +warp base 1000000: single cold run 6.174 ms, 4096 items derived, lane0 6b390e64bbdd91ce lane31 91c944d603539c62 +CPU verify: 6.006 ms per 32-lane warp, avg of 50 (checksum 17e36e7905b81375) +## --class dr368 08:49:14Z +Welcome to vast.ai. If authentication fails, try again after a few seconds, and double check your ssh key. +Have fun! +cache: fill 276.3 ms on one core (2^26 words, 256 MiB, 65536 chains of 64 ChaCha12 blocks), FNV-1a 64 48c4f5bf24166b2e +warp base 0: single cold run 5.540 ms, 4096 items derived, lane0 c77c7625bbe0f452 lane31 c8e84ff2655d9934 +warp base 4096: single cold run 5.433 ms, 4096 items derived, lane0 7229bd981a5786ca lane31 1c5495083ae60453 +warp base 1000000: single cold run 5.430 ms, 4096 items derived, lane0 5533769c9cdbf0a7 lane31 2426905704457b11 +CPU verify: 5.426 ms per 32-lane warp, avg of 50 (checksum 94fcbf0a77e03bdc) +## --class dr736 08:49:16Z +Welcome to vast.ai. If authentication fails, try again after a few seconds, and double check your ssh key. +Have fun! +cache: fill 275.7 ms on one core (2^26 words, 256 MiB, 65536 chains of 64 ChaCha12 blocks), FNV-1a 64 48c4f5bf24166b2e +warp base 0: single cold run 10.290 ms, 4096 items derived, lane0 e23d389f3eea0c83 lane31 6605db059b381bd9 +warp base 4096: single cold run 10.072 ms, 4096 items derived, lane0 fdb4b214da8ce292 lane31 db698d03437d74f7 +warp base 1000000: single cold run 10.056 ms, 4096 items derived, lane0 534671b1bf5cea36 lane31 733b123353f13d21 +CPU verify: 10.042 ms per 32-lane warp, avg of 50 (checksum bf79909c25836153) +# O-1.14 bench end 2026-10-07T08:49:19Z diff --git a/docs/bench-log.md b/docs/bench-log.md index af812f224..3961f9359 100644 --- a/docs/bench-log.md +++ b/docs/bench-log.md @@ -2633,3 +2633,12 @@ in the same shape and reports a box behind its wanted binary. | Rig | the same, and a rig that leaves is itself a weight removal: at 459 MH/s on tonight's devnet it is about 20 percent of the weight, over the hour's budget by itself | | Pool | a pool node is one voter carrying its members' whole weight; a pool restart is the largest single removal on the network and must be sliced like the fleet's | | The network | finality by miner weight is only as steady as the miners' uptime; until public hash dwarfs the fleet, the fleet's supervisor is a consensus component | + +## O-1.14: the CPU verifier on a 2019-class core (attack pass F6, 7 October 2026, 09:49 UK) + +Rented Vast instance 54613164, Intel Core i7-9700K at 4,170 MHz as read, one core, the box-built Linux `igneum-pow` +(sha256 6d286783...), `bench --seed igneum-genesis --day 2026-10-03 --warps 50`. Ms per warp, cold max / average of 50: +v2 1.582 / 1.280; mx8 5.394 / 5.267; mx8+sh256x27 (class v4) 6.334 / 6.006; dr368 5.540 / 5.426; dr736 10.290 / 10.042 +(fails the 10 ms gate, the known-fail). Cache fill 276 ms. Log `docs/analysis/attack-pass/o114-i7-9700K-2026-10-07.log`; +record `docs/analysis/attack-pass-2026-10.md` row F6. Class v4 passes a real 2019-class core with 3.7 ms to spare; the +half-core proxy (8.23 ms) stays the standing pessimistic rule for the ladder's ceiling.