From f0860e618ccbb2da979c79c3652489ede08b0af4 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 08:48:52 +0000 Subject: [PATCH] attack-pass F8: AP-F8-1 reframed against the window model of spec 1.13.1; the 153x item is the question; gate wording raised Co-Authored-By: Claude Fable 5.1 --- docs/analysis/attack-pass-2026-10.md | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/docs/analysis/attack-pass-2026-10.md b/docs/analysis/attack-pass-2026-10.md index bd537f1c..5dc1686a 100644 --- a/docs/analysis/attack-pass-2026-10.md +++ b/docs/analysis/attack-pass-2026-10.md @@ -247,7 +247,21 @@ an auditor flags a non-uniform read map in a design that claims uniform random r is the cause to name. Fix asked: per-site index whitening or a rejected class above a bound. Re-gate: the top 0.1 percent within 1.2x of the control over 2^26 nonces on every one of 64 seeds, with F8's harness against the Counter ASIC lane's branch. Phase E (the 64-program census) decides whether it is one program or the class. -Status: FINDING-OPEN. +Framing from the Counter ASIC lane (the generator's owner, 7 October 2026, 10:5x UK): class v4's item map is not +designed to be uniform per program. Layer 8 (spec 01 section 1.13.1) gives each load site k_off = below(3), so a +site reads the whole dataset, a half or a quarter under the era's stride and interleave; a quarter-window site +concentrates 4x on its quarter by design, which is the 4.05x at the top 0.1 percent, and the windows exist so a +chip's SRAM mirror must hold the whole dataset every hour (the Counter ASIC 2.0 windows-union census). The right +control is therefore the window model from the program's own 16 draws, reported beside the uniform control (what an +auditor sees first); the number that must be explained is the single item 0xca5b92 at 153x the mean (window +coincidence under the era mapping with a stated tail, or a low-entropy index source at site 15, which would be a +fault). The lane reproduces with F8's harness on branch `ca3-v4-uniform`, waits for phase E, re-prices the chip +consequence (a 0.1 percent hot-set cache, about 1.7 MB of SRAM, serving 0.5 percent of reads: under one percent of +rate) and changes the generator only on a fault beyond the model, since v4 is on the live devnet's vote. F8 was +re-briefed to carry both controls and the per-site table. Raised to the coordinator: plan 1.4 gate (4) and row F8 +say "within 6 sigma of uniform"; if the design is windowed, the gate text must say "uniform within the window model +of spec 1.13.1" before the freeze tag, or every reviewer files the windows as a finding on day one. +Status: FINDING-OPEN (fault or model tail to be decided by phase E). Any further finding is logged here and in `docs/fud-ledger.md` with its owning lane (hash and algorithm: fixed in `igneum-pow` behind a test and re-gated; node: the node lane, relay agent) before the row is marked FIXED-AND-PASSED.