Compare commits
16 commits
master
...
adv-cache-
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ff4c3ebcd8 | ||
|
|
5d015b22d8 | ||
|
|
ff8afa731f | ||
|
|
c0b4fc3445 | ||
|
|
73a53783f0 | ||
|
|
f71ff308e7 | ||
|
|
0f8890777c | ||
|
|
655a28b1a4 | ||
|
|
e3f3e07700 | ||
|
|
ba2619c4cc | ||
|
|
52ea3f8bcd | ||
|
|
f737b38c24 | ||
|
|
0156c2345c | ||
|
|
667296f14f | ||
|
|
42827d16eb | ||
|
|
fa61c67060 |
46 changed files with 2469 additions and 0 deletions
4
docs/analysis/cryptanalysis/logs/adv-cache-3/check.log
Normal file
4
docs/analysis/cryptanalysis/logs/adv-cache-3/check.log
Normal file
|
|
@ -0,0 +1,4 @@
|
|||
[2026-10-07T19:06:03Z] adv-cache-3 check (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:06:03Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:06:04Z] day 20730: cache FNV-1a 64 0x448274a57f508cbc (vectors.json 0x448274a57f508cbc: MATCH), head word 0 0xebd9055c, fill 0.95 s
|
||||
[2026-10-07T19:06:05Z] day 20733: cache FNV-1a 64 0x7334fa46e5d972eb (vectors.json 0x7334fa46e5d972eb: MATCH), head word 0 0x47e15959, fill 0.97 s
|
||||
|
|
@ -0,0 +1,11 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 cross-d20730
|
||||
[2026-10-07T19:22:59Z] adv-cache-3 cross (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:59Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:59Z] cross: day 20730 (and 20731) segments 4096 w 32 double rounds 6 plant none threads 88
|
||||
[2026-10-07T19:22:59Z] cross-segment j=0: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 4.50 at (in bit 308, out bit 235) = (word 9 bit 20, word 7 bit 11); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:22:59Z] cross-segment j=1: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 4.75 at (in bit 418, out bit 64) = (word 13 bit 2, word 2 bit 0); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:22:59Z] cross-segment j=63: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 5.00 at (in bit 230, out bit 306) = (word 7 bit 6, word 9 bit 18); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:22:59Z] cross-day: line_j(s) of day d against day d + 1, same (s, j): n 4096 cells 262144 worst |z| 4.56 at (in bit 456, out bit 15) = (word 14 bit 8, word 0 bit 15); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:22:59Z] known constants of x_j from the code: j = 0: 16 of 16 words (x_0 = c_0 is public); j >= 1: 0 of 16 (every word is XORed with the previous line)
|
||||
[2026-10-07T19:22:59Z] CROSS RESULT: worst |z| 5.00, gate 6 at 4096 samples PASS; 0.1 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
|
|
@ -0,0 +1,11 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 1 s): adv-cache-3 cross-plant-noxor-r1
|
||||
[2026-10-07T19:23:00Z] adv-cache-3 cross (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:23:00Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:23:00Z] cross: day 20730 (and 20731) segments 4096 w 32 double rounds 1 plant no-xor threads 88
|
||||
[2026-10-07T19:23:00Z] cross-segment j=0: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 64.00 at (in bit 14, out bit 14) = (word 0 bit 14, word 0 bit 14); cells over 5 sigma 4045 (expected 0.149); over 6 sigma 3385 (expected 0.00052)
|
||||
[2026-10-07T19:23:00Z] cross-segment j=1: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 64.00 at (in bit 13, out bit 13) = (word 0 bit 13, word 0 bit 13); cells over 5 sigma 4236 (expected 0.149); over 6 sigma 3585 (expected 0.00052)
|
||||
[2026-10-07T19:23:00Z] cross-segment j=63: line_j(s) against line_j(s XOR 2^b): n 4096 cells 262144 worst |z| 64.00 at (in bit 14, out bit 14) = (word 0 bit 14, word 0 bit 14); cells over 5 sigma 4306 (expected 0.149); over 6 sigma 3564 (expected 0.00052)
|
||||
[2026-10-07T19:23:00Z] cross-day: line_j(s) of day d against day d + 1, same (s, j): n 4096 cells 262144 worst |z| 56.28 at (in bit 55, out bit 55) = (word 1 bit 23, word 1 bit 23); cells over 5 sigma 1591 (expected 0.149); over 6 sigma 1113 (expected 0.00052)
|
||||
[2026-10-07T19:23:00Z] known constants of x_j from the code: j = 0: 16 of 16 words (x_0 = c_0 is public); j >= 1: 0 of 16 (every word is XORed with the previous line)
|
||||
[2026-10-07T19:23:00Z] CROSS RESULT: worst |z| 64.00, gate 6 at 4096 samples FIRE; 0.1 s
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
|
|
@ -0,0 +1,24 @@
|
|||
lease: 0 of 16 pool cores free (88 leased); waiting
|
||||
lease: holding 30 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60, waited 1874 s, class adv): adv-cache-3 flip-r2-2e18
|
||||
[2026-10-07T20:14:10Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T20:14:10Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T20:14:10Z] skip: day 20730 w 32 double rounds 2 lines 64 segments 4160 plant none threads 30; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T20:14:10Z] templates: 34340800 compares of 512-bit lines, chance matches expected 2.561e-147, 0.1 s
|
||||
[2026-10-07T20:14:10Z] template 0 [B(c_j)] at 1 block(s): matches 4160 (j0:4160)
|
||||
[2026-10-07T20:14:10Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:10Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:10Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:10Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:10Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:10Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:10Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 266240 (gate 0) PASS
|
||||
[2026-10-07T20:14:10Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:10Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:10Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:10Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:10Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T20:14:15Z] dependence: 262080 lines, 512 x 512 flip table: worst cells z +4.71 / -4.73 (gate 6), zero cells 0 of 262144; word table min 262080 of 262080 (every output word changes when any input word changes: YES); 4.9 s
|
||||
[2026-10-07T20:14:15Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T20:14:15Z] inversion: 65536 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
|
||||
[2026-10-07T20:14:15Z] skip done in 5.5 s
|
||||
lease: released 30 pool cores after 1879 s, exit 0
|
||||
|
|
@ -0,0 +1,24 @@
|
|||
lease: holding 30 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60, waited 1 s, class adv): adv-cache-3 flip-r3-2e18
|
||||
[2026-10-07T20:14:16Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T20:14:16Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T20:14:16Z] skip: day 20730 w 32 double rounds 3 lines 64 segments 4160 plant none threads 30; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T20:14:16Z] templates: 34340800 compares of 512-bit lines, chance matches expected 2.561e-147, 0.1 s
|
||||
[2026-10-07T20:14:16Z] template 0 [B(c_j)] at 1 block(s): matches 4160 (j0:4160)
|
||||
[2026-10-07T20:14:16Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:16Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:16Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:16Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:16Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:16Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:16Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 266240 (gate 0) PASS
|
||||
[2026-10-07T20:14:16Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:16Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:16Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:16Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:16Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T20:14:21Z] dependence: 262080 lines, 512 x 512 flip table: worst cells z +4.81 / -4.70 (gate 6), zero cells 0 of 262144; word table min 262080 of 262080 (every output word changes when any input word changes: YES); 5.3 s
|
||||
[2026-10-07T20:14:21Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T20:14:21Z] inversion: 65536 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
|
||||
[2026-10-07T20:14:21Z] skip done in 5.8 s
|
||||
Terminated
|
||||
lease: released 30 pool cores after 6 s, exit 0
|
||||
|
|
@ -0,0 +1,24 @@
|
|||
lease: holding 30 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60, waited 0 s, class adv): adv-cache-3 flip-r4-2e18
|
||||
[2026-10-07T20:14:22Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T20:14:22Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T20:14:22Z] skip: day 20730 w 32 double rounds 4 lines 64 segments 4160 plant none threads 30; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T20:14:22Z] templates: 34340800 compares of 512-bit lines, chance matches expected 2.561e-147, 0.1 s
|
||||
[2026-10-07T20:14:22Z] template 0 [B(c_j)] at 1 block(s): matches 4160 (j0:4160)
|
||||
[2026-10-07T20:14:22Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:22Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:22Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:22Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:22Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:22Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:22Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 266240 (gate 0) PASS
|
||||
[2026-10-07T20:14:22Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:22Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:22Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:22Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:22Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T20:14:28Z] dependence: 262080 lines, 512 x 512 flip table: worst cells z +4.76 / -4.77 (gate 6), zero cells 0 of 262144; word table min 262080 of 262080 (every output word changes when any input word changes: YES); 5.3 s
|
||||
[2026-10-07T20:14:28Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T20:14:28Z] inversion: 65536 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
|
||||
[2026-10-07T20:14:28Z] skip done in 6.0 s
|
||||
Terminated
|
||||
lease: released 30 pool cores after 6 s, exit 0
|
||||
|
|
@ -0,0 +1,24 @@
|
|||
lease: holding 30 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60, waited 0 s, class adv): adv-cache-3 flip-r6-2e18
|
||||
[2026-10-07T20:14:28Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T20:14:28Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T20:14:28Z] skip: day 20730 w 32 double rounds 6 lines 64 segments 4160 plant none threads 30; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T20:14:28Z] templates: 34340800 compares of 512-bit lines, chance matches expected 2.561e-147, 0.1 s
|
||||
[2026-10-07T20:14:28Z] template 0 [B(c_j)] at 1 block(s): matches 4160 (j0:4160)
|
||||
[2026-10-07T20:14:28Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:28Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:28Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:28Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T20:14:28Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:28Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T20:14:28Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 266240 (gate 0) PASS
|
||||
[2026-10-07T20:14:28Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:28Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:28Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:28Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T20:14:29Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T20:14:34Z] dependence: 262080 lines, 512 x 512 flip table: worst cells z +4.38 / -4.66 (gate 6), zero cells 0 of 262144; word table min 262080 of 262080 (every output word changes when any input word changes: YES); 5.4 s
|
||||
[2026-10-07T20:14:34Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T20:14:34Z] inversion: 65536 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
|
||||
[2026-10-07T20:14:34Z] skip done in 6.0 s
|
||||
Terminated
|
||||
lease: released 30 pool cores after 6 s, exit 0
|
||||
|
|
@ -0,0 +1,12 @@
|
|||
lease: holding 32 pool cores (10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41, waited 1 s, class adv): adv-cache-3 image-w2-plant-noff
|
||||
[2026-10-07T20:27:02Z] adv-cache-3 image (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T20:27:02Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T20:27:02Z] image: w 2 double rounds 6 depth 6 plant no-feedforward threads 32; rotations [1, 1, 1, 1]; all 2^32 states enumerated per step
|
||||
[2026-10-07T20:28:20Z] depth 1: image size 4294967296 = 1.000000 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.632121; 2/k: 2.000000; a permutation: 1.000000); 78 s
|
||||
[2026-10-07T20:29:37Z] depth 2: image size 4294967296 = 1.000000 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.468536; 2/k: 1.000000; a permutation: 1.000000); 155 s
|
||||
[2026-10-07T20:30:53Z] depth 3: image size 4294967296 = 1.000000 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.374082; 2/k: 0.666667; a permutation: 1.000000); 231 s
|
||||
[2026-10-07T20:32:05Z] depth 4: image size 4294967296 = 1.000000 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.312080; 2/k: 0.500000; a permutation: 1.000000); 303 s
|
||||
[2026-10-07T20:33:10Z] depth 5: image size 4294967296 = 1.000000 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.268077; 2/k: 0.400000; a permutation: 1.000000); 368 s
|
||||
[2026-10-07T20:34:32Z] depth 6: image size 4294967296 = 1.000000 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.235151; 2/k: 0.333333; a permutation: 1.000000); 450 s
|
||||
Terminated
|
||||
lease: released 32 pool cores after 451 s, exit 0
|
||||
|
|
@ -0,0 +1,71 @@
|
|||
lease: 0 of 16 pool cores free (88 leased); waiting
|
||||
lease: holding 32 pool cores (10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41, waited 173 s, class adv): adv-cache-3 image-w2-r6-d64-full
|
||||
[2026-10-07T20:16:28Z] adv-cache-3 image (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T20:16:28Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T20:16:28Z] image: w 2 double rounds 6 depth 64 plant none threads 32; rotations [1, 1, 1, 1]; all 2^32 states enumerated per step
|
||||
[2026-10-07T20:17:55Z] depth 1: image size 2715029335 = 0.632142 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.632121; 2/k: 2.000000; a permutation: 1.000000); 87 s
|
||||
[2026-10-07T20:18:41Z] depth 2: image size 2012444452 = 0.468559 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.468536; 2/k: 1.000000; a permutation: 1.000000); 133 s
|
||||
[2026-10-07T20:19:15Z] depth 3: image size 1606748932 = 0.374100 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.374082; 2/k: 0.666667; a permutation: 1.000000); 167 s
|
||||
[2026-10-07T20:19:49Z] depth 4: image size 1340451469 = 0.312098 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.312080; 2/k: 0.500000; a permutation: 1.000000); 201 s
|
||||
[2026-10-07T20:20:17Z] depth 5: image size 1151447703 = 0.268092 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.268077; 2/k: 0.400000; a permutation: 1.000000); 229 s
|
||||
[2026-10-07T20:20:39Z] depth 6: image size 1010025987 = 0.235165 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.235151; 2/k: 0.333333; a permutation: 1.000000); 251 s
|
||||
[2026-10-07T20:20:59Z] depth 7: image size 900056868 = 0.209561 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.209548; 2/k: 0.285714; a permutation: 1.000000); 271 s
|
||||
[2026-10-07T20:21:16Z] depth 8: image size 812009253 = 0.189061 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.189050; 2/k: 0.250000; a permutation: 1.000000); 288 s
|
||||
[2026-10-07T20:21:33Z] depth 9: image size 739877239 = 0.172266 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.172255; 2/k: 0.222222; a permutation: 1.000000); 304 s
|
||||
[2026-10-07T20:21:49Z] depth 10: image size 679651606 = 0.158244 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.158235; 2/k: 0.200000; a permutation: 1.000000); 320 s
|
||||
[2026-10-07T20:22:04Z] depth 11: image size 628605897 = 0.146359 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.146351; 2/k: 0.181818; a permutation: 1.000000); 336 s
|
||||
[2026-10-07T20:22:17Z] depth 12: image size 584777272 = 0.136154 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.136146; 2/k: 0.166667; a permutation: 1.000000); 349 s
|
||||
[2026-10-07T20:22:28Z] depth 13: image size 546724260 = 0.127294 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.127284; 2/k: 0.153846; a permutation: 1.000000); 360 s
|
||||
[2026-10-07T20:22:41Z] depth 14: image size 513354089 = 0.119525 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.119517; 2/k: 0.142857; a permutation: 1.000000); 372 s
|
||||
[2026-10-07T20:22:52Z] depth 15: image size 483867161 = 0.112659 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.112651; 2/k: 0.133333; a permutation: 1.000000); 383 s
|
||||
[2026-10-07T20:23:03Z] depth 16: image size 457612723 = 0.106546 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.106537; 2/k: 0.125000; a permutation: 1.000000); 395 s
|
||||
[2026-10-07T20:23:13Z] depth 17: image size 434084362 = 0.101068 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.101059; 2/k: 0.117647; a permutation: 1.000000); 405 s
|
||||
[2026-10-07T20:23:22Z] depth 18: image size 412860819 = 0.096127 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.096120; 2/k: 0.111111; a permutation: 1.000000); 414 s
|
||||
[2026-10-07T20:23:33Z] depth 19: image size 393640994 = 0.091652 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.091645; 2/k: 0.105263; a permutation: 1.000000); 425 s
|
||||
[2026-10-07T20:23:42Z] depth 20: image size 376139020 = 0.087577 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.087571; 2/k: 0.100000; a permutation: 1.000000); 434 s
|
||||
[2026-10-07T20:23:51Z] depth 21: image size 360145138 = 0.083853 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.083846; 2/k: 0.095238; a permutation: 1.000000); 443 s
|
||||
[2026-10-07T20:23:59Z] depth 22: image size 345452853 = 0.080432 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.080427; 2/k: 0.090909; a permutation: 1.000000); 451 s
|
||||
[2026-10-07T20:24:07Z] depth 23: image size 331928058 = 0.077283 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.077278; 2/k: 0.086957; a permutation: 1.000000); 459 s
|
||||
[2026-10-07T20:24:14Z] depth 24: image size 319423465 = 0.074372 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.074368; 2/k: 0.083333; a permutation: 1.000000); 466 s
|
||||
[2026-10-07T20:24:21Z] depth 25: image size 307837370 = 0.071674 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.071670; 2/k: 0.080000; a permutation: 1.000000); 473 s
|
||||
[2026-10-07T20:24:28Z] depth 26: image size 297059541 = 0.069165 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.069162; 2/k: 0.076923; a permutation: 1.000000); 479 s
|
||||
[2026-10-07T20:24:34Z] depth 27: image size 287021221 = 0.066827 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.066824; 2/k: 0.074074; a permutation: 1.000000); 486 s
|
||||
[2026-10-07T20:24:40Z] depth 28: image size 277639719 = 0.064643 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.064640; 2/k: 0.071429; a permutation: 1.000000); 492 s
|
||||
[2026-10-07T20:24:46Z] depth 29: image size 268856948 = 0.062598 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.062595; 2/k: 0.068966; a permutation: 1.000000); 498 s
|
||||
[2026-10-07T20:24:52Z] depth 30: image size 260608732 = 0.060678 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.060677; 2/k: 0.066667; a permutation: 1.000000); 503 s
|
||||
[2026-10-07T20:24:57Z] depth 31: image size 252860685 = 0.058874 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.058872; 2/k: 0.064516; a permutation: 1.000000); 509 s
|
||||
[2026-10-07T20:25:01Z] depth 32: image size 245561711 = 0.057174 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.057173; 2/k: 0.062500; a permutation: 1.000000); 513 s
|
||||
[2026-10-07T20:25:05Z] depth 33: image size 238674533 = 0.055571 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.055569; 2/k: 0.060606; a permutation: 1.000000); 517 s
|
||||
[2026-10-07T20:25:09Z] depth 34: image size 232159656 = 0.054054 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.054053; 2/k: 0.058824; a permutation: 1.000000); 521 s
|
||||
[2026-10-07T20:25:13Z] depth 35: image size 225998978 = 0.052619 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.052619; 2/k: 0.057143; a permutation: 1.000000); 525 s
|
||||
[2026-10-07T20:25:17Z] depth 36: image size 220155903 = 0.051259 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.051258; 2/k: 0.055556; a permutation: 1.000000); 529 s
|
||||
[2026-10-07T20:25:22Z] depth 37: image size 214608267 = 0.049967 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.049967; 2/k: 0.054054; a permutation: 1.000000); 534 s
|
||||
[2026-10-07T20:25:27Z] depth 38: image size 209333660 = 0.048739 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.048739; 2/k: 0.052632; a permutation: 1.000000); 538 s
|
||||
[2026-10-07T20:25:31Z] depth 39: image size 204315520 = 0.047571 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.047570; 2/k: 0.051282; a permutation: 1.000000); 543 s
|
||||
[2026-10-07T20:25:36Z] depth 40: image size 199532563 = 0.046457 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.046456; 2/k: 0.050000; a permutation: 1.000000); 548 s
|
||||
[2026-10-07T20:25:40Z] depth 41: image size 194967404 = 0.045394 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.045394; 2/k: 0.048780; a permutation: 1.000000); 552 s
|
||||
[2026-10-07T20:25:44Z] depth 42: image size 190606921 = 0.044379 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.044379; 2/k: 0.047619; a permutation: 1.000000); 556 s
|
||||
[2026-10-07T20:25:49Z] depth 43: image size 186440468 = 0.043409 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.043409; 2/k: 0.046512; a permutation: 1.000000); 560 s
|
||||
[2026-10-07T20:25:52Z] depth 44: image size 182452390 = 0.042481 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.042480; 2/k: 0.045455; a permutation: 1.000000); 564 s
|
||||
[2026-10-07T20:25:56Z] depth 45: image size 178630354 = 0.041591 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.041590; 2/k: 0.044444; a permutation: 1.000000); 568 s
|
||||
[2026-10-07T20:25:59Z] depth 46: image size 174963974 = 0.040737 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.040737; 2/k: 0.043478; a permutation: 1.000000); 571 s
|
||||
[2026-10-07T20:26:03Z] depth 47: image size 171449833 = 0.039919 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.039919; 2/k: 0.042553; a permutation: 1.000000); 575 s
|
||||
[2026-10-07T20:26:07Z] depth 48: image size 168074588 = 0.039133 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.039132; 2/k: 0.041667; a permutation: 1.000000); 579 s
|
||||
[2026-10-07T20:26:11Z] depth 49: image size 164826920 = 0.038377 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.038377; 2/k: 0.040816; a permutation: 1.000000); 582 s
|
||||
[2026-10-07T20:26:14Z] depth 50: image size 161701909 = 0.037649 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.037650; 2/k: 0.040000; a permutation: 1.000000); 586 s
|
||||
[2026-10-07T20:26:18Z] depth 51: image size 158696483 = 0.036949 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.036950; 2/k: 0.039216; a permutation: 1.000000); 589 s
|
||||
[2026-10-07T20:26:21Z] depth 52: image size 155801922 = 0.036275 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.036275; 2/k: 0.038462; a permutation: 1.000000); 593 s
|
||||
[2026-10-07T20:26:24Z] depth 53: image size 153009220 = 0.035625 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.035625; 2/k: 0.037736; a permutation: 1.000000); 596 s
|
||||
[2026-10-07T20:26:28Z] depth 54: image size 150314071 = 0.034998 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.034998; 2/k: 0.037037; a permutation: 1.000000); 599 s
|
||||
[2026-10-07T20:26:31Z] depth 55: image size 147714567 = 0.034392 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.034393; 2/k: 0.036364; a permutation: 1.000000); 603 s
|
||||
[2026-10-07T20:26:35Z] depth 56: image size 145205271 = 0.033808 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.033808; 2/k: 0.035714; a permutation: 1.000000); 606 s
|
||||
[2026-10-07T20:26:38Z] depth 57: image size 142777802 = 0.033243 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.033243; 2/k: 0.035088; a permutation: 1.000000); 610 s
|
||||
[2026-10-07T20:26:42Z] depth 58: image size 140429121 = 0.032696 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.032697; 2/k: 0.034483; a permutation: 1.000000); 614 s
|
||||
[2026-10-07T20:26:45Z] depth 59: image size 138158047 = 0.032167 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.032168; 2/k: 0.033898; a permutation: 1.000000); 616 s
|
||||
[2026-10-07T20:26:48Z] depth 60: image size 135961613 = 0.031656 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.031656; 2/k: 0.033333; a permutation: 1.000000); 620 s
|
||||
[2026-10-07T20:26:51Z] depth 61: image size 133832450 = 0.031160 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.031160; 2/k: 0.032787; a permutation: 1.000000); 623 s
|
||||
[2026-10-07T20:26:55Z] depth 62: image size 131767169 = 0.030679 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.030680; 2/k: 0.032258; a permutation: 1.000000); 626 s
|
||||
[2026-10-07T20:26:58Z] depth 63: image size 129765689 = 0.030213 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.030214; 2/k: 0.031746; a permutation: 1.000000); 630 s
|
||||
[2026-10-07T20:27:01Z] depth 64: image size 127826507 = 0.029762 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.029762; 2/k: 0.031250; a permutation: 1.000000); 633 s
|
||||
Terminated
|
||||
lease: released 32 pool cores after 806 s, exit 0
|
||||
|
|
@ -0,0 +1,20 @@
|
|||
lease: holding 87 pool cores (9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 image-w2-r6-d64
|
||||
[2026-10-07T19:22:50Z] adv-cache-3 image (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:50Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:50Z] image: w 2 double rounds 6 depth 64 plant none threads 87; rotations [1, 1, 1, 1]; all 2^32 states enumerated per step
|
||||
[2026-10-07T19:23:14Z] depth 1: image size 2715029335 = 0.632142 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.632121; 2/k: 2.000000; a permutation: 1.000000); 24 s
|
||||
[2026-10-07T19:23:29Z] depth 2: image size 2012444452 = 0.468559 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.468536; 2/k: 1.000000; a permutation: 1.000000); 39 s
|
||||
[2026-10-07T19:23:40Z] depth 3: image size 1606748932 = 0.374100 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.374082; 2/k: 0.666667; a permutation: 1.000000); 50 s
|
||||
[2026-10-07T19:23:48Z] depth 4: image size 1340451469 = 0.312098 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.312080; 2/k: 0.500000; a permutation: 1.000000); 58 s
|
||||
[2026-10-07T19:23:55Z] depth 5: image size 1151447703 = 0.268092 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.268077; 2/k: 0.400000; a permutation: 1.000000); 65 s
|
||||
[2026-10-07T19:24:01Z] depth 6: image size 1010025987 = 0.235165 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.235151; 2/k: 0.333333; a permutation: 1.000000); 71 s
|
||||
[2026-10-07T19:24:07Z] depth 7: image size 900056868 = 0.209561 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.209548; 2/k: 0.285714; a permutation: 1.000000); 77 s
|
||||
[2026-10-07T19:24:13Z] depth 8: image size 812009253 = 0.189061 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.189050; 2/k: 0.250000; a permutation: 1.000000); 83 s
|
||||
[2026-10-07T19:24:18Z] depth 9: image size 739877239 = 0.172266 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.172255; 2/k: 0.222222; a permutation: 1.000000); 88 s
|
||||
[2026-10-07T19:24:23Z] depth 10: image size 679651606 = 0.158244 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.158235; 2/k: 0.200000; a permutation: 1.000000); 93 s
|
||||
[2026-10-07T19:24:28Z] depth 11: image size 628605897 = 0.146359 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.146351; 2/k: 0.181818; a permutation: 1.000000); 98 s
|
||||
[2026-10-07T19:24:32Z] depth 12: image size 584777272 = 0.136154 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.136146; 2/k: 0.166667; a permutation: 1.000000); 102 s
|
||||
[2026-10-07T19:24:36Z] depth 13: image size 546724260 = 0.127294 of 2^32 (random-function recursion tau_k = 1 - exp(-tau_k-1): 0.127284; 2/k: 0.153846; a permutation: 1.000000); 106 s
|
||||
Terminated
|
||||
Terminated
|
||||
lease: released 87 pool cores after 106 s, exit 143
|
||||
11
docs/analysis/cryptanalysis/logs/adv-cache-3/ledger-box2.txt
Normal file
11
docs/analysis/cryptanalysis/logs/adv-cache-3/ledger-box2.txt
Normal file
|
|
@ -0,0 +1,11 @@
|
|||
2026-10-07T19:22:50Z start image-w2-r6-d64
|
||||
2026-10-07T19:24:38Z RELEASED image-w2-r6-d64 lease by order (partial kept to depth 8), re-queue at 48 cores later
|
||||
2026-10-07T19:35:51Z start image-w2-r6-d64-full
|
||||
2026-10-07T19:41:22Z HOLD file 97: no adv-cache-3 lease on box 2 until main clears it (class v5 census first)
|
||||
2026-10-07T19:41:55Z KILLED image-w2-r6-d64-full (file 97 had passed its yield at 19:35:51Z when the v5 waiter line was briefly absent; held 48 cores 19:41:15Z to 19:41:xxZ while class-v5 waited; partial kept)
|
||||
2026-10-07T20:13:35Z RESTART file 97 at 32 threads: box 2 opened to adv-* by main at 20:12Z
|
||||
2026-10-07T20:13:35Z start image-w2-r6-d64-full
|
||||
2026-10-07T20:27:01Z end image-w2-r6-d64-full rc=0
|
||||
2026-10-07T20:27:01Z start image-w2-plant-noff
|
||||
2026-10-07T20:34:32Z end image-w2-plant-noff rc=0
|
||||
2026-10-07T20:35:27Z start sibling-43 warps-devnet-2e26-v2 (owner adv-cache-2) at 32 threads
|
||||
54
docs/analysis/cryptanalysis/logs/adv-cache-3/ledger.txt
Normal file
54
docs/analysis/cryptanalysis/logs/adv-cache-3/ledger.txt
Normal file
|
|
@ -0,0 +1,54 @@
|
|||
2026-10-07T19:22:52Z start skip-d20730
|
||||
2026-10-07T19:22:53Z end skip-d20730 rc=0
|
||||
2026-10-07T19:22:53Z start skip-d20733
|
||||
2026-10-07T19:22:54Z end skip-d20733 rc=0
|
||||
2026-10-07T19:22:54Z start skip-plant-noxor
|
||||
2026-10-07T19:22:54Z end skip-plant-noxor rc=0
|
||||
2026-10-07T19:22:54Z start skip-plant-noff
|
||||
2026-10-07T19:22:55Z end skip-plant-noff rc=0
|
||||
2026-10-07T19:22:55Z start skip-rounds0
|
||||
2026-10-07T19:22:55Z end skip-rounds0 rc=0
|
||||
2026-10-07T19:22:55Z start skip-rounds1
|
||||
2026-10-07T19:22:56Z end skip-rounds1 rc=0
|
||||
2026-10-07T19:22:56Z start skip-rounds2
|
||||
2026-10-07T19:22:57Z end skip-rounds2 rc=0
|
||||
2026-10-07T19:22:57Z start skip-w4-r2
|
||||
2026-10-07T19:22:57Z end skip-w4-r2 rc=0
|
||||
2026-10-07T19:22:57Z start skip-w4-r2-plant-noxor
|
||||
2026-10-07T19:22:57Z end skip-w4-r2-plant-noxor rc=0
|
||||
2026-10-07T19:22:57Z start skip-w4-r2-plant-noff
|
||||
2026-10-07T19:22:57Z end skip-w4-r2-plant-noff rc=0
|
||||
2026-10-07T19:22:57Z start pebble
|
||||
2026-10-07T19:22:59Z end pebble rc=0
|
||||
2026-10-07T19:22:59Z start pebble-plant-skip8
|
||||
2026-10-07T19:22:59Z end pebble-plant-skip8 rc=0
|
||||
2026-10-07T19:22:59Z start cross-d20730
|
||||
2026-10-07T19:22:59Z end cross-d20730 rc=0
|
||||
2026-10-07T19:22:59Z start cross-plant-noxor-r1
|
||||
2026-10-07T19:23:00Z end cross-plant-noxor-r1 rc=0
|
||||
2026-10-07T19:23:00Z start relations-4d-l20
|
||||
2026-10-07T19:23:02Z end relations-4d-l20 rc=0
|
||||
2026-10-07T19:23:02Z start relations-plant-r1
|
||||
2026-10-07T19:23:02Z end relations-plant-r1 rc=0
|
||||
2026-10-07T19:23:02Z start relations-plant-r2
|
||||
2026-10-07T19:23:02Z end relations-plant-r2 rc=0
|
||||
2026-10-07T19:23:02Z start relations-r3
|
||||
2026-10-07T19:23:03Z end relations-r3 rc=0
|
||||
2026-10-07T19:23:03Z start skip-1024-d20730
|
||||
2026-10-07T19:23:04Z end skip-1024-d20730 rc=0
|
||||
2026-10-07T19:23:04Z start skip-1024-d20733
|
||||
2026-10-07T19:23:05Z end skip-1024-d20733 rc=0
|
||||
2026-10-07T19:23:05Z start skip-1024-plant-noxor
|
||||
2026-10-07T19:23:05Z end skip-1024-plant-noxor rc=0
|
||||
2026-10-07T19:23:05Z start skip-1024-plant-noff
|
||||
2026-10-07T19:23:06Z end skip-1024-plant-noff rc=0
|
||||
2026-10-07T19:32:52Z start flip-r2-2e18
|
||||
2026-10-07T19:42:56Z RESUBMIT file 98 at 32 threads under the ranked lease (release > v5 > measure > adv)
|
||||
2026-10-07T19:42:56Z start flip-r2-2e18
|
||||
2026-10-07T20:14:15Z end flip-r2-2e18 rc=0
|
||||
2026-10-07T20:14:15Z start flip-r3-2e18
|
||||
2026-10-07T20:14:21Z end flip-r3-2e18 rc=0
|
||||
2026-10-07T20:14:22Z start flip-r4-2e18
|
||||
2026-10-07T20:14:28Z end flip-r4-2e18 rc=0
|
||||
2026-10-07T20:14:28Z start flip-r6-2e18
|
||||
2026-10-07T20:14:34Z end flip-r6-2e18 rc=0
|
||||
|
|
@ -0,0 +1,31 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 pebble-plant-skip8
|
||||
[2026-10-07T19:22:59Z] adv-cache-3 pebble (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:59Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:59Z] pebble: lines 64 exhaustive check up to 12 lines, Monte Carlo 200000 trials per point, skip edge 8 (PLANT: line j also from line j - 8 in one block)
|
||||
[2026-10-07T19:22:59Z] exhaustive n=10 k=1: optimum 2.5000 blocks per read, DP 2.5000 AGREE
|
||||
[2026-10-07T19:22:59Z] exhaustive n=10 k=2: optimum 1.5000 blocks per read, DP 1.5000 AGREE
|
||||
[2026-10-07T19:22:59Z] exhaustive n=10 k=4: optimum 0.7000 blocks per read, DP 0.7000 AGREE
|
||||
[2026-10-07T19:22:59Z] exhaustive n=12 k=1: optimum 3.0000 blocks per read, DP 3.0000 AGREE
|
||||
[2026-10-07T19:22:59Z] exhaustive n=12 k=2: optimum 1.8333 blocks per read, DP 1.8333 AGREE
|
||||
[2026-10-07T19:22:59Z] exhaustive n=12 k=4: optimum 0.9167 blocks per read, DP 0.9167 AGREE
|
||||
[2026-10-07T19:22:59Z] static curve (blocks per uniform read; ops per item = 9,360 + 8 x blocks x 608; SRAM = f x 128 mm^2 at the N5 headline of chip-model-v3 section 2):
|
||||
[2026-10-07T19:22:59Z] f=k/64 | k held | DP optimum (plain path) | stride offset 0 | stride offset step-1 | best over the planted graph (k=1 exhaustive, else local search) | ops per item at the optimum | SRAM mm^2
|
||||
[2026-10-07T19:22:59Z] 1/64 | 1 | 16.0000 | 31.5000 | 31.5000 | 5.1875 | 87184 | 2.0
|
||||
[2026-10-07T19:22:59Z] 2/64 | 2 | 10.5000 | 15.5000 | 15.5000 | 0.0000 | 60432 | 4.0
|
||||
[2026-10-07T19:22:59Z] 4/64 | 4 | 6.0938 | 7.5000 | 7.5000 | 0.0000 | 39000 | 8.0
|
||||
[2026-10-07T19:22:59Z] 8/64 | 8 | 3.1719 | 3.5000 | 3.5000 | 0.0156 | 24788 | 16.0
|
||||
[2026-10-07T19:22:59Z] 16/64 | 16 | 1.4531 | 1.5000 | 1.5000 | 0.0000 | 16428 | 32.0
|
||||
[2026-10-07T19:22:59Z] 32/64 | 32 | 0.5000 | 0.5000 | 0.5000 | 0.5000 | 11792 | 64.0
|
||||
[2026-10-07T19:22:59Z] 64/64 | 64 | -0.0000 | 0.0000 | 0.0000 | 0.0000 | 9360 | 128.0
|
||||
[2026-10-07T19:22:59Z] static curve: monotone in f YES; f = 1 reads 9360 ops per item (gate 9,360); planted graph under the path optimum at some f: YES PLANT FIRES
|
||||
[2026-10-07T19:22:59Z] amortising adversary (Monte Carlo 200000 trials): blocks per read with m requests in one segment, one walk per gap from the nearest held line to the deepest request; the stride store at offset step-1 (the DP optimum's shape for k >= 2)
|
||||
[2026-10-07T19:22:59Z] f=k/64 | m=1 | m=2 | m=4 | m=8 | m=16 | m=64 | Poisson m=1 | Poisson m=8 | Poisson m=64
|
||||
[2026-10-07T19:22:59Z] 1/64 | 31.550 | 21.099 | 12.691 | 7.037 | 3.731 | 0.975 | 23.211 | 6.953 | 0.976
|
||||
[2026-10-07T19:22:59Z] 2/64 | 15.500 | 12.933 | 9.556 | 6.102 | 3.470 | 0.951 | 13.277 | 5.902 | 0.951
|
||||
[2026-10-07T19:22:59Z] 4/64 | 7.486 | 6.894 | 5.904 | 4.480 | 2.929 | 0.902 | 6.920 | 4.323 | 0.902
|
||||
[2026-10-07T19:22:59Z] 8/64 | 3.504 | 3.370 | 3.114 | 2.691 | 2.088 | 0.805 | 3.367 | 2.624 | 0.803
|
||||
[2026-10-07T19:22:59Z] 16/64 | 1.498 | 1.472 | 1.420 | 1.323 | 1.158 | 0.614 | 1.473 | 1.303 | 0.612
|
||||
[2026-10-07T19:22:59Z] 32/64 | 0.500 | 0.495 | 0.489 | 0.475 | 0.446 | 0.317 | 0.497 | 0.468 | 0.314
|
||||
[2026-10-07T19:22:59Z] 64/64 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000
|
||||
[2026-10-07T19:22:59Z] cross-check points: the plain path with nothing held at m = 1 must read 32.5 (E[j] + 1); sibling adv-cache measured 23.84, 7.06 and 0.99 blocks per read on real addresses at Poisson m = 1, 8, 64 with nothing held (its batch rows)
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
37
docs/analysis/cryptanalysis/logs/adv-cache-3/pebble.log
Normal file
37
docs/analysis/cryptanalysis/logs/adv-cache-3/pebble.log
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 pebble
|
||||
[2026-10-07T19:22:57Z] adv-cache-3 pebble (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:57Z] pebble: lines 64 exhaustive check up to 16 lines, Monte Carlo 1000000 trials per point, skip edge none (the plain path)
|
||||
[2026-10-07T19:22:57Z] exhaustive n=10 k=1: optimum 2.5000 blocks per read, DP 2.5000 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=10 k=2: optimum 1.5000 blocks per read, DP 1.5000 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=10 k=4: optimum 0.7000 blocks per read, DP 0.7000 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=12 k=1: optimum 3.0000 blocks per read, DP 3.0000 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=12 k=2: optimum 1.8333 blocks per read, DP 1.8333 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=12 k=4: optimum 0.9167 blocks per read, DP 0.9167 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=14 k=1: optimum 3.5000 blocks per read, DP 3.5000 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=14 k=2: optimum 2.1429 blocks per read, DP 2.1429 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=14 k=4: optimum 1.0714 blocks per read, DP 1.0714 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=16 k=1: optimum 4.0000 blocks per read, DP 4.0000 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=16 k=2: optimum 2.5000 blocks per read, DP 2.5000 AGREE
|
||||
[2026-10-07T19:22:57Z] exhaustive n=16 k=4: optimum 1.3125 blocks per read, DP 1.3125 AGREE
|
||||
[2026-10-07T19:22:57Z] static curve (blocks per uniform read; ops per item = 9,360 + 8 x blocks x 608; SRAM = f x 128 mm^2 at the N5 headline of chip-model-v3 section 2):
|
||||
[2026-10-07T19:22:57Z] f=k/64 | k held | DP optimum (plain path) | stride offset 0 | stride offset step-1 | best over the planted graph (k=1 exhaustive, else local search) | ops per item at the optimum | SRAM mm^2
|
||||
[2026-10-07T19:22:57Z] 1/64 | 1 | 16.0000 | 31.5000 | 31.5000 | 16.0000 | 87184 | 2.0
|
||||
[2026-10-07T19:22:57Z] 2/64 | 2 | 10.5000 | 15.5000 | 15.5000 | 10.5000 | 60432 | 4.0
|
||||
[2026-10-07T19:22:57Z] 4/64 | 4 | 6.0938 | 7.5000 | 7.5000 | 6.0938 | 39000 | 8.0
|
||||
[2026-10-07T19:22:57Z] 8/64 | 8 | 3.1719 | 3.5000 | 3.5000 | 3.1719 | 24788 | 16.0
|
||||
[2026-10-07T19:22:57Z] 16/64 | 16 | 1.4531 | 1.5000 | 1.5000 | 1.4531 | 16428 | 32.0
|
||||
[2026-10-07T19:22:57Z] 32/64 | 32 | 0.5000 | 0.5000 | 0.5000 | 0.5000 | 11792 | 64.0
|
||||
[2026-10-07T19:22:57Z] 64/64 | 64 | -0.0000 | 0.0000 | 0.0000 | -0.0000 | 9360 | 128.0
|
||||
[2026-10-07T19:22:57Z] static curve: monotone in f YES; f = 1 reads 9360 ops per item (gate 9,360); planted graph under the path optimum at some f: NO PASS
|
||||
[2026-10-07T19:22:57Z] amortising adversary (Monte Carlo 1000000 trials): blocks per read with m requests in one segment, one walk per gap from the nearest held line to the deepest request; the stride store at offset step-1 (the DP optimum's shape for k >= 2)
|
||||
[2026-10-07T19:22:57Z] f=k/64 | m=1 | m=2 | m=4 | m=8 | m=16 | m=64 | Poisson m=1 | Poisson m=8 | Poisson m=64
|
||||
[2026-10-07T19:22:58Z] 1/64 | 31.523 | 21.072 | 12.670 | 7.046 | 3.733 | 0.976 | 23.242 | 6.948 | 0.975
|
||||
[2026-10-07T19:22:58Z] 2/64 | 15.487 | 12.938 | 9.550 | 6.095 | 3.466 | 0.951 | 13.236 | 5.899 | 0.950
|
||||
[2026-10-07T19:22:58Z] 4/64 | 7.498 | 6.896 | 5.889 | 4.484 | 2.939 | 0.902 | 6.931 | 4.325 | 0.899
|
||||
[2026-10-07T19:22:58Z] 8/64 | 3.498 | 3.363 | 3.113 | 2.694 | 2.085 | 0.804 | 3.369 | 2.619 | 0.801
|
||||
[2026-10-07T19:22:58Z] 16/64 | 1.500 | 1.472 | 1.420 | 1.324 | 1.157 | 0.614 | 1.474 | 1.303 | 0.612
|
||||
[2026-10-07T19:22:58Z] 32/64 | 0.500 | 0.496 | 0.489 | 0.474 | 0.445 | 0.317 | 0.496 | 0.471 | 0.316
|
||||
[2026-10-07T19:22:59Z] 64/64 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000
|
||||
[2026-10-07T19:22:59Z] cross-check points: the plain path with nothing held at m = 1 must read 32.5 (E[j] + 1); sibling adv-cache measured 23.84, 7.06 and 0.99 blocks per read on real addresses at Poisson m = 1, 8, 64 with nothing held (its batch rows)
|
||||
lease: released 88 pool cores after 2 s, exit 0
|
||||
|
|
@ -0,0 +1,15 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-4d-l20
|
||||
[2026-10-07T19:23:00Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:23:00Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:23:00Z] relations: days 20730..20733 lines per day 2^20 (16384 segments x 64) w 32 double rounds 6 plant none threads 88
|
||||
[2026-10-07T19:23:00Z] day 20730 done, 1032192 lines so far, 0.5 s
|
||||
[2026-10-07T19:23:01Z] day 20731 done, 2064384 lines so far, 1.1 s
|
||||
[2026-10-07T19:23:01Z] day 20732 done, 3096576 lines so far, 1.6 s
|
||||
[2026-10-07T19:23:02Z] day 20733 done, 4128768 lines so far, 2.1 s
|
||||
[2026-10-07T19:23:02Z] bias [line_j XOR x_j]: 512 bits over 4128768 lines: worst |z| 3.00 at bit 48 (word 1 bit 16), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 4128768 lines: worst |z| 3.58 at bit 75 (word 2 bit 11), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j XOR line_j-1]: 512 bits over 4128768 lines: worst |z| 3.29 at bit 267 (word 8 bit 11), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j - line_j-1]: 512 bits over 4128768 lines: worst |z| 3.29 at bit 333 (word 10 bit 13), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 4128768 cells 262144 worst |z| 4.83 at (in bit 296, out bit 467) = (word 9 bit 8, word 14 bit 19); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:23:02Z] RELATIONS RESULT: worst bias |z| 3.58, worst correlation |z| 4.83, gate 6 at 4128768 samples PASS; 2.1 s
|
||||
lease: released 88 pool cores after 2 s, exit 0
|
||||
|
|
@ -0,0 +1,12 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-plant-r1
|
||||
[2026-10-07T19:23:02Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:23:02Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:23:02Z] relations: days 20730..20730 lines per day 2^16 (1024 segments x 64) w 32 double rounds 1 plant none threads 88
|
||||
[2026-10-07T19:23:02Z] day 20730 done, 64512 lines so far, 0.1 s
|
||||
[2026-10-07T19:23:02Z] bias [line_j XOR x_j]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j XOR line_j-1]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j - line_j-1]: 512 bits over 64512 lines: worst |z| 3.22 at bit 352 (word 11 bit 0), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 64512 cells 262144 worst |z| 4.47 at (in bit 296, out bit 269) = (word 9 bit 8, word 8 bit 13); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:23:02Z] RELATIONS RESULT: worst bias |z| 3.22, worst correlation |z| 4.47, gate 6 at 64512 samples PASS; 0.1 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
|
|
@ -0,0 +1,12 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-plant-r2
|
||||
[2026-10-07T19:23:02Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:23:02Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:23:02Z] relations: days 20730..20730 lines per day 2^16 (1024 segments x 64) w 32 double rounds 2 plant none threads 88
|
||||
[2026-10-07T19:23:02Z] day 20730 done, 64512 lines so far, 0.1 s
|
||||
[2026-10-07T19:23:02Z] bias [line_j XOR x_j]: 512 bits over 64512 lines: worst |z| 4.58 at bit 297 (word 9 bit 9), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 64512 lines: worst |z| 3.27 at bit 296 (word 9 bit 8), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j XOR line_j-1]: 512 bits over 64512 lines: worst |z| 4.58 at bit 297 (word 9 bit 9), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] bias [line_j - line_j-1]: 512 bits over 64512 lines: worst |z| 3.50 at bit 1 (word 0 bit 1), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:02Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 64512 cells 262144 worst |z| 4.65 at (in bit 412, out bit 35) = (word 12 bit 28, word 1 bit 3); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:23:02Z] RELATIONS RESULT: worst bias |z| 4.58, worst correlation |z| 4.65, gate 6 at 64512 samples PASS; 0.1 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
|
|
@ -0,0 +1,13 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 relations-r3
|
||||
[2026-10-07T19:23:03Z] adv-cache-3 relations (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:23:03Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:23:03Z] relations: days 20730..20730 lines per day 2^18 (4096 segments x 64) w 32 double rounds 3 plant none threads 88
|
||||
[2026-10-07T19:23:03Z] day 20730 done, 258048 lines so far, 0.2 s
|
||||
[2026-10-07T19:23:03Z] bias [line_j XOR x_j]: 512 bits over 258048 lines: worst |z| 3.55 at bit 334 (word 10 bit 14), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:03Z] bias [line_j - x_j (= C(x_j))]: 512 bits over 258048 lines: worst |z| 4.33 at bit 54 (word 1 bit 22), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:03Z] bias [line_j XOR line_j-1]: 512 bits over 258048 lines: worst |z| 3.55 at bit 334 (word 10 bit 14), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:03Z] bias [line_j - line_j-1]: 512 bits over 258048 lines: worst |z| 3.80 at bit 212 (word 6 bit 20), bits over 6 sigma 0
|
||||
[2026-10-07T19:23:03Z] correlation x_j bits against line_j bits (the line_j-1 table is the same up to a sign per column, x_j = line_j-1 XOR c_j): n 258048 cells 262144 worst |z| 4.45 at (in bit 296, out bit 372) = (word 9 bit 8, word 11 bit 20); cells over 5 sigma 0 (expected 0.149); over 6 sigma 0 (expected 0.00052)
|
||||
[2026-10-07T19:23:03Z] RELATIONS RESULT: worst bias |z| 4.33, worst correlation |z| 4.45, gate 6 at 258048 samples PASS; 0.2 s
|
||||
Terminated
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
|
|
@ -0,0 +1,53 @@
|
|||
lease: 0 of 16 pool cores free (88 leased); waiting
|
||||
lease: holding 24 pool cores (50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73, waited 92 s, class adv): adv-cache-2 warps-devnet-2e26-v2 (run by adv-cache-3)
|
||||
[2026-10-07T20:36:59Z] adv-cache-2 0.1.0 (igneum-pow generator v4); args ["warps", "--programs", "devnet", "--day", "20730", "--nonces", "67108864", "--validate", "sample", "--threads", "24", "--out", "/srv/builds/_adv-adv-cache-2"]
|
||||
[2026-10-07T20:36:59Z] warps: programs ["devnet"] day 20730 nonces 67108864 threads 24 plant none validate sample check_every 997 fingerprint false
|
||||
[2026-10-07T20:36:59Z] day 20730: cache filled in 0.41 s, fnv 448274a57f508cbc
|
||||
[2026-10-07T20:37:02Z] table: 16777216 items derived with their 8 lines in 2.6 s; library comparison sample (0 mismatches)
|
||||
[2026-10-07T20:37:04Z] static devnet-epoch0: s0:instr1:r7:base-writer rotl@0:shadow-writes add=5,mad=5,mul=4,mulhi=1,rotr=4,shfl=2,sub=3,xor=3:last-shadow-writer add | s1:instr4:r4:base-writer load@1:shadow-writes add=7,mad=1,mul=7,mulhi=2,or=5,rotr=1,shfl=5,sub=2,xor=5:last-shadow-writer or | s2:instr6:r0:base-writer load@4:shadow-writes add=8,mad=9,mul=4,mulhi=2,rotl=6,rotr=2,shfl=2,sub=3,xor=8:last-shadow-writer add | s3:instr10:r7:base-writer mad@2:shadow-writes add=5,mad=5,mul=4,mulhi=1,rotr=4,shfl=2,sub=3,xor=3:last-shadow-writer add | s4:instr12:r2:base-writer rotl@11:shadow-writes add=4,mad=3,mul=3,mulhi=3,or=1,rotl=4,rotr=3,shfl=2,sub=4,xor=5:last-shadow-writer add | s5:instr20:r1:base-writer shfl@18:shadow-writes add=5,mad=3,mulhi=1,or=3,rotl=1,rotr=3,shfl=5,sub=7,xor=3:last-shadow-writer rotr | s6:instr27:r7:base-writer mad@14:shadow-writes add=5,mad=5,mul=4,mulhi=1,rotr=4,shfl=2,sub=3,xor=3:last-shadow-writer add | s7:instr30:r2:base-writer sub@19:shadow-writes add=4,mad=3,mul=3,mulhi=3,or=1,rotl=4,rotr=3,shfl=2,sub=4,xor=5:last-shadow-writer add | s8:instr35:r4:base-writer xor@33:shadow-writes add=7,mad=1,mul=7,mulhi=2,or=5,rotr=1,shfl=5,sub=2,xor=5:last-shadow-writer or | s9:instr40:r7:base-writer mad@38:shadow-writes add=5,mad=5,mul=4,mulhi=1,rotr=4,shfl=2,sub=3,xor=3:last-shadow-writer add | s10:instr41:r0:base-writer mad@21:shadow-writes add=8,mad=9,mul=4,mulhi=2,rotl=6,rotr=2,shfl=2,sub=3,xor=8:last-shadow-writer add | s11:instr43:r3:base-writer sub@22:shadow-writes add=6,mad=2,mul=2,mulhi=2,or=3,rotl=1,rotr=2,shfl=2,sub=2,xor=3:last-shadow-writer shfl | s12:instr45:r1:base-writer load@43:shadow-writes add=5,mad=3,mulhi=1,or=3,rotl=1,rotr=3,shfl=5,sub=7,xor=3:last-shadow-writer rotr | s13:instr52:r1:base-writer rotr@46:shadow-writes add=5,mad=3,mulhi=1,or=3,rotl=1,rotr=3,shfl=5,sub=7,xor=3:last-shadow-writer rotr | s14:instr53:r3:base-writer load@52:shadow-writes add=6,mad=2,mul=2,mulhi=2,or=3,rotl=1,rotr=2,shfl=2,sub=2,xor=3:last-shadow-writer shfl | s15:instr54:r5:base-writer load@53:shadow-writes add=5,mad=6,mul=3,mulhi=2,or=3,rotl=6,rotr=3,shfl=3,xor=7:last-shadow-writer xor
|
||||
[2026-10-07T20:37:04Z] program devnet-epoch0: epoch seed edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 era seed edc4fa844da9dc98d37e965176f6558a31560e40502ab3ae5491b21aaaabfb07 id a785001687d8688a attempt 1 class mx8-erad810f22d+sh256x27 op mix load=16 mad=8 mul=6 xor=6 rotr=5 shfl=5 sub=5 add=4 mulhi=4 rotl=4 or=1; era stride mul 0x9ad30d99 rot 29 interleave [0, 2, 12, 13]; sites instr:win:off 1:2:3 4:2:1 6:2:1 10:1:1 12:0:0 20:0:0 27:0:0 30:0:0 35:2:3 40:0:0 41:2:1 43:0:0 45:2:1 52:1:1 53:0:0 54:2:1
|
||||
[2026-10-07T20:37:04Z] window layer devnet-epoch0: site windows (first, items) (0xc00000,2^22) (0x400000,2^22) (0x400000,2^22) (0x800000,2^23) (0x0,2^24) (0x0,2^24) (0x0,2^24) (0x0,2^24) (0xc00000,2^22) (0x0,2^24) (0x400000,2^22) (0x0,2^24) (0x400000,2^22) (0x800000,2^23) (0x0,2^24) (0x400000,2^22); expected share per quarter 0.1094 0.4219 0.1719 0.2969; top quarter 0.4219 (uniform 0.25), top aligned half 0.5312 (uniform 0.5)
|
||||
[2026-10-07T20:38:41Z] devnet-epoch0: 2097152 warps (67108864 nonces) interpreted in 96.7 s (1.106 ms per warp per thread); Epoch::hash_warp agreement on 2167 warps: 0 mismatches
|
||||
[2026-10-07T20:38:41Z] devnet-epoch0: warp 0 lanes agree with the pack's vectors.json
|
||||
[2026-10-07T20:38:41Z] devnet-epoch0 item histogram (flat): bins 16777216 reads 8589934592 mean 512.000 sigma 22.627 max 1038 (bin 6539211) z_max +23.25 min 149 z_min -16.04 chi2/dof 119.00549 chi2_z +341780.41 top0.1% 0.18602% top0.5% 0.91409% top1% 1.81245%
|
||||
[2026-10-07T20:38:41Z] devnet-epoch0: measured share per quarter 0.10937 0.42187 0.17187 0.29688; top quarter 0.42187 (window model 0.42188, uniform 0.25); top aligned half 0.53125 (model 0.53125, uniform 0.5)
|
||||
[2026-10-07T20:38:51Z] devnet-epoch0 WINDOWED CONTROL item histogram: bins 16777216 reads 8589934592 mean 512.000 sigma 22.627 max 1013 (bin 5944996) z_max +22.14 min 153 z_min -15.87 chi2/dof 119.00156 chi2_z +341769.02 top0.1% 0.18600% top0.5% 0.91401% top1% 1.81232%
|
||||
[2026-10-07T20:39:00Z] devnet-epoch0 FLAT CONTROL item histogram: bins 16777216 reads 8589934592 mean 512.000 sigma 22.627 max 637 (bin 15131992) z_max +5.52 min 396 z_min -5.13 chi2/dof 1.00036 chi2_z +1.04 top0.1% 0.11522% top0.5% 0.56513% top1% 1.11982%
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (windowed control): f 0.1% S_f 0.18602% E_f(control) 0.18600% X_f +0.00002% X_f/f +0.0002 ratio S/E 1.0001x -> no hot set
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (windowed control): f 0.5% S_f 0.91409% E_f(control) 0.91401% X_f +0.00009% X_f/f +0.0002 ratio S/E 1.0001x -> no hot set
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (windowed control): f 1.0% S_f 1.81245% E_f(control) 1.81232% X_f +0.00013% X_f/f +0.0001 ratio S/E 1.0001x -> no hot set
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (windowed control): verdict clear
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (flat control): f 0.1% S_f 0.18602% E_f(control) 0.11522% X_f +0.07080% X_f/f +0.7080 ratio S/E 1.6144x -> no hot set
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (flat control): f 0.5% S_f 0.91409% E_f(control) 0.56513% X_f +0.34896% X_f/f +0.6979 ratio S/E 1.6175x -> no hot set
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (flat control): f 1.0% S_f 1.81245% E_f(control) 1.11982% X_f +0.69263% X_f/f +0.6926 ratio S/E 1.6185x -> no hot set
|
||||
[2026-10-07T20:39:00Z] hot-set devnet-epoch0 items (flat control): verdict clear
|
||||
[2026-10-07T20:39:00Z] 6-sigma devnet-epoch0 items buckets64 against the window density: largest +4.68 sigma smallest -4.30; WINDOWED CONTROL largest +4.74 smallest -4.28 -> within 6 sigma
|
||||
[2026-10-07T20:39:00Z] site 0 (instr 1, win 2, off 3, window 2^22 items, reads outside the window 0): hist: bins 4194304 reads 536870912 mean 128.000 sigma 11.314 max 188 (bin 518621) z_max +5.30 min 77 z_min -4.51 chi2/dof 1.03228 chi2_z +46.75 top0.1% 0.13172% top0.5% 0.63514% top1% 1.24819%; control top0.1% 0.13099% top1% 1.24299%; ratio top0.1% 1.0056x top1% 1.0042x; z_max +5.30
|
||||
[2026-10-07T20:39:01Z] site 1 (instr 4, win 2, off 1, window 2^22 items, reads outside the window 0): hist: bins 4194304 reads 536870912 mean 128.000 sigma 11.314 max 191 (bin 3835793) z_max +5.57 min 72 z_min -4.95 chi2/dof 1.00389 chi2_z +5.64 top0.1% 0.13114% top0.5% 0.63273% top1% 1.24377%; control top0.1% 0.13113% top1% 1.24348%; ratio top0.1% 1.0000x top1% 1.0002x; z_max +5.57
|
||||
[2026-10-07T20:39:02Z] site 2 (instr 6, win 2, off 1, window 2^22 items, reads outside the window 0): hist: bins 4194304 reads 536870912 mean 128.000 sigma 11.314 max 192 (bin 324711) z_max +5.66 min 71 z_min -5.04 chi2/dof 0.99897 chi2_z -1.50 top0.1% 0.13102% top0.5% 0.63230% top1% 1.24306%; control top0.1% 0.13105% top1% 1.24315%; ratio top0.1% 0.9997x top1% 0.9999x; z_max +5.66
|
||||
[2026-10-07T20:39:03Z] site 3 (instr 10, win 1, off 1, window 2^23 items, reads outside the window 0): hist: bins 8388608 reads 536870912 mean 64.000 sigma 8.000 max 111 (bin 2230563) z_max +5.88 min 28 z_min -4.50 chi2/dof 1.00044 chi2_z +0.90 top0.1% 0.14480% top0.5% 0.69060% top1% 1.34938%; control top0.1% 0.14469% top1% 1.34845%; ratio top0.1% 1.0008x top1% 1.0007x; z_max +5.88
|
||||
[2026-10-07T20:39:04Z] site 4 (instr 12, win 0, off 0, window 2^24 items, reads outside the window 0): hist: bins 16777216 reads 536870912 mean 32.000 sigma 5.657 max 66 (bin 10898139) z_max +6.01 min 7 z_min -4.42 chi2/dof 0.99859 chi2_z -4.08 top0.1% 0.16440% top0.5% 0.77394% top1% 1.50074%; control top0.1% 0.16466% top1% 1.50140%; ratio top0.1% 0.9984x top1% 0.9996x; z_max +6.01
|
||||
[2026-10-07T20:39:05Z] site 5 (instr 20, win 0, off 0, window 2^24 items, reads outside the window 0): hist: bins 16777216 reads 536870912 mean 32.000 sigma 5.657 max 67 (bin 12762242) z_max +6.19 min 5 z_min -4.77 chi2/dof 1.00005 chi2_z +0.16 top0.1% 0.16457% top0.5% 0.77433% top1% 1.50129%; control top0.1% 0.16468% top1% 1.50183%; ratio top0.1% 0.9994x top1% 0.9996x; z_max +6.19
|
||||
[2026-10-07T20:39:06Z] site 6 (instr 27, win 0, off 0, window 2^24 items, reads outside the window 0): hist: bins 16777216 reads 536870912 mean 32.000 sigma 5.657 max 68 (bin 5199608) z_max +6.36 min 7 z_min -4.42 chi2/dof 1.03897 chi2_z +112.87 top0.1% 0.16644% top0.5% 0.78088% top1% 1.51414%; control top0.1% 0.16444% top1% 1.50099%; ratio top0.1% 1.0122x top1% 1.0088x; z_max +6.36
|
||||
[2026-10-07T20:39:08Z] site 7 (instr 30, win 0, off 0, window 2^24 items, reads outside the window 0): hist: bins 16777216 reads 536870912 mean 32.000 sigma 5.657 max 65 (bin 1845013) z_max +5.83 min 7 z_min -4.42 chi2/dof 1.00051 chi2_z +1.49 top0.1% 0.16470% top0.5% 0.77463% top1% 1.50171%; control top0.1% 0.16454% top1% 1.50106%; ratio top0.1% 1.0010x top1% 1.0004x; z_max +5.83
|
||||
[2026-10-07T20:39:09Z] site 8 (instr 35, win 2, off 3, window 2^22 items, reads outside the window 0): hist: bins 4194304 reads 536870912 mean 128.000 sigma 11.314 max 189 (bin 538673) z_max +5.39 min 76 z_min -4.60 chi2/dof 0.99978 chi2_z -0.32 top0.1% 0.13100% top0.5% 0.63244% top1% 1.24329%; control top0.1% 0.13110% top1% 1.24364%; ratio top0.1% 0.9992x top1% 0.9997x; z_max +5.39
|
||||
[2026-10-07T20:39:10Z] site 9 (instr 40, win 0, off 0, window 2^24 items, reads outside the window 0): hist: bins 16777216 reads 536870912 mean 32.000 sigma 5.657 max 68 (bin 8589291) z_max +6.36 min 7 z_min -4.42 chi2/dof 1.00002 chi2_z +0.05 top0.1% 0.16464% top0.5% 0.77437% top1% 1.50129%; control top0.1% 0.16461% top1% 1.50116%; ratio top0.1% 1.0002x top1% 1.0001x; z_max +6.36
|
||||
[2026-10-07T20:39:11Z] site 10 (instr 41, win 2, off 1, window 2^22 items, reads outside the window 0): hist: bins 4194304 reads 536870912 mean 128.000 sigma 11.314 max 189 (bin 168200) z_max +5.39 min 73 z_min -4.86 chi2/dof 1.00065 chi2_z +0.94 top0.1% 0.13111% top0.5% 0.63268% top1% 1.24367%; control top0.1% 0.13103% top1% 1.24327%; ratio top0.1% 1.0006x top1% 1.0003x; z_max +5.39
|
||||
[2026-10-07T20:39:13Z] site 11 (instr 43, win 0, off 0, window 2^24 items, reads outside the window 0): hist: bins 16777216 reads 536870912 mean 32.000 sigma 5.657 max 65 (bin 3298723) z_max +5.83 min 7 z_min -4.42 chi2/dof 1.00024 chi2_z +0.71 top0.1% 0.16463% top0.5% 0.77463% top1% 1.50162%; control top0.1% 0.16469% top1% 1.50149%; ratio top0.1% 0.9996x top1% 1.0001x; z_max +5.83
|
||||
[2026-10-07T20:39:13Z] site 12 (instr 45, win 2, off 1, window 2^22 items, reads outside the window 0): hist: bins 4194304 reads 536870912 mean 128.000 sigma 11.314 max 190 (bin 2894156) z_max +5.48 min 75 z_min -4.68 chi2/dof 1.00050 chi2_z +0.73 top0.1% 0.13111% top0.5% 0.63256% top1% 1.24333%; control top0.1% 0.13107% top1% 1.24355%; ratio top0.1% 1.0003x top1% 0.9998x; z_max +5.48
|
||||
[2026-10-07T20:39:14Z] site 13 (instr 52, win 1, off 1, window 2^23 items, reads outside the window 0): hist: bins 8388608 reads 536870912 mean 64.000 sigma 8.000 max 108 (bin 1575406) z_max +5.50 min 24 z_min -5.00 chi2/dof 0.99966 chi2_z -0.70 top0.1% 0.14473% top0.5% 0.69035% top1% 1.34863%; control top0.1% 0.14472% top1% 1.34906%; ratio top0.1% 1.0000x top1% 0.9997x; z_max +5.50
|
||||
[2026-10-07T20:39:16Z] site 14 (instr 53, win 0, off 0, window 2^24 items, reads outside the window 0): hist: bins 16777216 reads 536870912 mean 32.000 sigma 5.657 max 67 (bin 8045963) z_max +6.19 min 7 z_min -4.42 chi2/dof 1.00038 chi2_z +1.10 top0.1% 0.16453% top0.5% 0.77442% top1% 1.50137%; control top0.1% 0.16467% top1% 1.50166%; ratio top0.1% 0.9991x top1% 0.9998x; z_max +6.19
|
||||
[2026-10-07T20:39:17Z] site 15 (instr 54, win 2, off 1, window 2^22 items, reads outside the window 0): hist: bins 4194304 reads 536870912 mean 128.000 sigma 11.314 max 187 (bin 386380) z_max +5.21 min 74 z_min -4.77 chi2/dof 1.00084 chi2_z +1.22 top0.1% 0.13109% top0.5% 0.63269% top1% 1.24367%; control top0.1% 0.13111% top1% 1.24343%; ratio top0.1% 0.9999x top1% 1.0002x; z_max +5.21
|
||||
[2026-10-07T20:39:18Z] devnet-epoch0 LINE histogram (8 lines per item read): bins 4194304 reads 68719476736 mean 16384.000 sigma 128.000 max 35247 (bin 1956659) z_max +147.37 min 3672 z_min -99.31 chi2/dof 630.31205 chi2_z +911341.08 top0.1% 0.17332% top0.5% 0.80992% top1% 1.56635%
|
||||
[2026-10-07T20:39:19Z] devnet-epoch0 LINE histogram under the WINDOWED CONTROL items: bins 4194304 reads 68719476736 mean 16384.000 sigma 128.000 max 35200 (bin 3638725) z_max +147.00 min 3705 z_min -99.05 chi2/dof 630.29307 chi2_z +911313.60 top0.1% 0.17332% top0.5% 0.80985% top1% 1.56622%
|
||||
[2026-10-07T20:39:19Z] hot-set devnet-epoch0 lines (windowed control): f 0.1% S_f 0.17332% E_f(control) 0.17332% X_f +0.00000% X_f/f +0.0000 ratio S/E 1.0000x -> no hot set
|
||||
[2026-10-07T20:39:19Z] hot-set devnet-epoch0 lines (windowed control): f 0.5% S_f 0.80992% E_f(control) 0.80985% X_f +0.00007% X_f/f +0.0001 ratio S/E 1.0001x -> no hot set
|
||||
[2026-10-07T20:39:19Z] hot-set devnet-epoch0 lines (windowed control): f 1.0% S_f 1.56635% E_f(control) 1.56622% X_f +0.00013% X_f/f +0.0001 ratio S/E 1.0001x -> no hot set
|
||||
[2026-10-07T20:39:19Z] hot-set devnet-epoch0 lines (windowed control): verdict clear
|
||||
[2026-10-07T20:39:19Z] devnet-epoch0 SEGMENT histogram (lines / 64): bins 65536 reads 68719476736 mean 1048576.000 sigma 1024.000 max 1179216 (bin 21859) z_max +127.58 min 941348 z_min -104.71 chi2/dof 631.63507 chi2_z +114156.27 top0.1% 0.10911% top0.5% 0.53624% top1% 1.06502%
|
||||
[2026-10-07T20:39:19Z] devnet-epoch0 SEGMENT histogram under the WINDOWED CONTROL items: bins 65536 reads 68719476736 mean 1048576.000 sigma 1024.000 max 1178923 (bin 21859) z_max +127.29 min 942254 z_min -103.83 chi2/dof 631.67558 chi2_z +114163.60 top0.1% 0.10910% top0.5% 0.53622% top1% 1.06499%
|
||||
[2026-10-07T20:39:19Z] lines-vs-control devnet-epoch0: chi2/dof lines 630.3120 vs control 630.2931; z_max +147.37 vs +147.00; segments chi2/dof 631.6351 vs 631.6756; z_max +127.58 vs +127.29 -> matches the control
|
||||
[2026-10-07T20:39:22Z] devnet-epoch0 REAL LINE STORE: f=1/2 stride: hit 0.50006 evals/item 3.9995 ops/item 2432 (+0.260x of 9360); f=1/2 hottest: hit 0.57818 evals/item 6.6382 ops/item 4036 (+0.431x of 9360); f=1/4 stride: hit 0.25005 evals/item 11.9994 ops/item 7296 (+0.779x of 9360); f=1/4 hottest: hit 0.31384 evals/item 20.8975 ops/item 12706 (+1.357x of 9360); f=1/8 stride: hit 0.12501 evals/item 27.9989 ops/item 17023 (+1.819x of 9360); f=1/8 hottest: hit 0.16705 evals/item 47.4988 ops/item 28879 (+3.085x of 9360); f=1/16 stride: hit 0.06251 evals/item 60.0002 ops/item 36480 (+3.897x of 9360); f=1/16 hottest: hit 0.08796 evals/item 89.7625 ops/item 54576 (+5.831x of 9360); f=1/32 stride: hit 0.03123 evals/item 124.0092 ops/item 75398 (+8.055x of 9360); f=1/32 hottest: hit 0.04598 evals/item 141.1802 ops/item 85838 (+9.171x of 9360); f=1/64 stride: hit 0.01561 evals/item 252.0162 ops/item 153226 (+16.370x of 9360); f=1/64 hottest: hit 0.02391 evals/item 187.3220 ops/item 113892 (+12.168x of 9360)
|
||||
[2026-10-07T20:39:27Z] devnet-epoch0 WINDOWED CONTROL LINE STORE: f=1/2 stride: hit 0.50005 evals/item 3.9996 ops/item 2432 (+0.260x of 9360); f=1/2 hottest: hit 0.57818 evals/item 6.6374 ops/item 4036 (+0.431x of 9360); f=1/4 stride: hit 0.25005 evals/item 11.9995 ops/item 7296 (+0.779x of 9360); f=1/4 hottest: hit 0.31384 evals/item 20.9008 ops/item 12708 (+1.358x of 9360); f=1/8 stride: hit 0.12501 evals/item 27.9990 ops/item 17023 (+1.819x of 9360); f=1/8 hottest: hit 0.16705 evals/item 47.4978 ops/item 28879 (+3.085x of 9360); f=1/16 stride: hit 0.06251 evals/item 60.0004 ops/item 36480 (+3.897x of 9360); f=1/16 hottest: hit 0.08795 evals/item 89.7300 ops/item 54556 (+5.829x of 9360); f=1/32 stride: hit 0.03123 evals/item 124.0093 ops/item 75398 (+8.055x of 9360); f=1/32 hottest: hit 0.04598 evals/item 141.2671 ops/item 85890 (+9.176x of 9360); f=1/64 stride: hit 0.01561 evals/item 252.0169 ops/item 153226 (+16.370x of 9360); f=1/64 hottest: hit 0.02391 evals/item 187.3729 ops/item 113923 (+12.171x of 9360)
|
||||
[2026-10-07T20:39:27Z] devnet-epoch0 ITEM STORE (hottest items, read-weighted): f=0.001: S_f 0.00186 (control 0.00186, uniform 0.00100); ops/hash 1196363 vs model 1197394 (0.9991x); f=0.01: S_f 0.01812 (control 0.01812, uniform 0.01000); ops/hash 1176877 vs model 1186611 (0.9918x); f=0.1: S_f 0.17431 (control 0.17430, uniform 0.10000); ops/hash 989757 vs model 1078784 (0.9175x); f=0.25: S_f 0.42187 (control 0.42188, uniform 0.25000); ops/hash 693155 vs model 899072 (0.7710x); f=0.5: S_f 0.71875 (control 0.71875, uniform 0.50000); ops/hash 337469 vs model 599552 (0.5629x); f=0.75: S_f 0.89063 (control 0.89063, uniform 0.75000); ops/hash 131550 vs model 300032 (0.4385x)
|
||||
lease: released 24 pool cores after 247 s, exit 143
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-1024-d20730
|
||||
[2026-10-07T19:23:03Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:23:03Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:23:03Z] skip: day 20730 w 32 double rounds 6 lines 1024 segments 64 plant none threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:23:03Z] templates: 134283200 compares of 512-bit lines, chance matches expected 1.002e-146, 0.1 s
|
||||
[2026-10-07T19:23:03Z] template 0 [B(c_j)] at 1 block(s): matches 64 (j0:64)
|
||||
[2026-10-07T19:23:03Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:03Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:23:03Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:03Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:23:03Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:03Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:03Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
|
||||
[2026-10-07T19:23:03Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:03Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:03Z] rank j=512: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:03Z] rank j=1023: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:03Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T19:23:04Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.34 / -4.88 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
|
||||
[2026-10-07T19:23:04Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T19:23:04Z] inversion: 65472 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
|
||||
[2026-10-07T19:23:04Z] skip done in 0.7 s
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-1024-d20733
|
||||
[2026-10-07T19:23:04Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:23:04Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:23:04Z] skip: day 20733 w 32 double rounds 6 lines 1024 segments 64 plant none threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:23:04Z] templates: 134283200 compares of 512-bit lines, chance matches expected 1.002e-146, 0.1 s
|
||||
[2026-10-07T19:23:04Z] template 0 [B(c_j)] at 1 block(s): matches 64 (j0:64)
|
||||
[2026-10-07T19:23:04Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:04Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:23:04Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:04Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:23:04Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:04Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:23:04Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
|
||||
[2026-10-07T19:23:04Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:04Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:04Z] rank j=512: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:04Z] rank j=1023: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:23:04Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T19:23:04Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.41 / -4.47 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
|
||||
[2026-10-07T19:23:04Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T19:23:04Z] inversion: 65472 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.1 s
|
||||
[2026-10-07T19:23:04Z] skip done in 0.7 s
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
24
docs/analysis/cryptanalysis/logs/adv-cache-3/skip-d20730.log
Normal file
24
docs/analysis/cryptanalysis/logs/adv-cache-3/skip-d20730.log
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 1 s): adv-cache-3 skip-d20730
|
||||
[2026-10-07T19:22:53Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:53Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:53Z] skip: day 20730 w 32 double rounds 6 lines 64 segments 1024 plant none threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:22:53Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
|
||||
[2026-10-07T19:22:53Z] template 0 [B(c_j)] at 1 block(s): matches 1024 (j0:1024)
|
||||
[2026-10-07T19:22:53Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
|
||||
[2026-10-07T19:22:53Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:53Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:53Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:53Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:53Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T19:22:53Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.44 / -4.53 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
|
||||
[2026-10-07T19:22:53Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T19:22:53Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:53Z] skip done in 0.5 s
|
||||
Terminated
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
24
docs/analysis/cryptanalysis/logs/adv-cache-3/skip-d20733.log
Normal file
24
docs/analysis/cryptanalysis/logs/adv-cache-3/skip-d20733.log
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-d20733
|
||||
[2026-10-07T19:22:53Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:53Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:53Z] skip: day 20733 w 32 double rounds 6 lines 64 segments 1024 plant none threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:22:53Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
|
||||
[2026-10-07T19:22:53Z] template 0 [B(c_j)] at 1 block(s): matches 1024 (j0:1024)
|
||||
[2026-10-07T19:22:53Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:53Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 65536 (gate 0) PASS
|
||||
[2026-10-07T19:22:53Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:53Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:54Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:54Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:54Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T19:22:54Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.47 / -4.47 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
|
||||
[2026-10-07T19:22:54Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T19:22:54Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:54Z] skip done in 0.5 s
|
||||
Terminated
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 1 s): adv-cache-3 skip-plant-noff
|
||||
[2026-10-07T19:22:55Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:55Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:55Z] skip: day 20730 w 32 double rounds 6 lines 64 segments 1024 plant no-feedforward threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:22:55Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
|
||||
[2026-10-07T19:22:55Z] template 0 [B(c_j)] at 1 block(s): matches 1024 (j0:1024)
|
||||
[2026-10-07T19:22:55Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 64512 (j1:1024 j2:1024 j3:1024 j4:1024 j5:1024 j6:1024 j7:1024 j8:1024 j9:1024 j10:1024 j11:1024 j12:1024 j13:1024 j14:1024 j15:1024 j16:1024 j17:1024 j18:1024 j19:1024 j20:1024 j21:1024 j22:1024 j23:1024 j24:1024 j25:1024 j26:1024 j27:1024 j28:1024 j29:1024 j30:1024 j31:1024 j32:1024 j33:1024 j34:1024 j35:1024 j36:1024 j37:1024 j38:1024 j39:1024 j40:1024 j41:1024 j42:1024 j43:1024 j44:1024 j45:1024 j46:1024 j47:1024 j48:1024 j49:1024 j50:1024 j51:1024 j52:1024 j53:1024 j54:1024 j55:1024 j56:1024 j57:1024 j58:1024 j59:1024 j60:1024 j61:1024 j62:1024 j63:1024)
|
||||
[2026-10-07T19:22:55Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 64512 of 65536 (gate 0; a plant must read above 0) PASS
|
||||
[2026-10-07T19:22:55Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:55Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:55Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:55Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:55Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T19:22:55Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.91 / -4.69 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
|
||||
[2026-10-07T19:22:55Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T19:22:55Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 64512; fixed-point iteration x <- Cinv(y - x) converged 64512 (gate 0; the plant must read all); 0.0 s
|
||||
[2026-10-07T19:22:55Z] skip done in 0.5 s
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-plant-noxor
|
||||
[2026-10-07T19:22:54Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:54Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:54Z] skip: day 20730 w 32 double rounds 6 lines 64 segments 1024 plant no-xor threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:22:54Z] templates: 8453120 compares of 512-bit lines, chance matches expected 6.305e-148, 0.0 s
|
||||
[2026-10-07T19:22:54Z] template 0 [B(c_j)] at 1 block(s): matches 65536 (j0:1024 j1:1024 j2:1024 j3:1024 j4:1024 j5:1024 j6:1024 j7:1024 j8:1024 j9:1024 j10:1024 j11:1024 j12:1024 j13:1024 j14:1024 j15:1024 j16:1024 j17:1024 j18:1024 j19:1024 j20:1024 j21:1024 j22:1024 j23:1024 j24:1024 j25:1024 j26:1024 j27:1024 j28:1024 j29:1024 j30:1024 j31:1024 j32:1024 j33:1024 j34:1024 j35:1024 j36:1024 j37:1024 j38:1024 j39:1024 j40:1024 j41:1024 j42:1024 j43:1024 j44:1024 j45:1024 j46:1024 j47:1024 j48:1024 j49:1024 j50:1024 j51:1024 j52:1024 j53:1024 j54:1024 j55:1024 j56:1024 j57:1024 j58:1024 j59:1024 j60:1024 j61:1024 j62:1024 j63:1024)
|
||||
[2026-10-07T19:22:54Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:54Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:54Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:54Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:54Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:54Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:54Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 64512 of 65536 (gate 0; a plant must read above 0) PASS
|
||||
[2026-10-07T19:22:54Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:54Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:54Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:54Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 529 rank(line_j-1, line_j) 1025 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:54Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 535 of 1025 DEFICIENT
|
||||
[2026-10-07T19:22:54Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +0.00 / -64.00 (gate 6), zero cells 262144 of 262144; word table min 0 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.1 s
|
||||
[2026-10-07T19:22:54Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
|
||||
[2026-10-07T19:22:54Z] inversion: 64512 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:54Z] skip done in 0.4 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-rounds0
|
||||
[2026-10-07T19:22:55Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:55Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:55Z] skip: day 20730 w 32 double rounds 0 lines 64 segments 256 plant none threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:22:55Z] templates: 2113280 compares of 512-bit lines, chance matches expected 1.576e-148, 0.0 s
|
||||
[2026-10-07T19:22:55Z] template 0 [B(c_j)] at 1 block(s): matches 256 (j0:256)
|
||||
[2026-10-07T19:22:55Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 16384 (gate 0) PASS
|
||||
[2026-10-07T19:22:55Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:55Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:55Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:55Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 17 rank(line_j-1, line_j) 17 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:55Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 94 of 1025 DEFICIENT
|
||||
[2026-10-07T19:22:55Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +64.00 / -64.00 (gate 6), zero cells 261648 of 262144; word table min 0 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.1 s
|
||||
[2026-10-07T19:22:55Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
|
||||
[2026-10-07T19:22:55Z] inversion: 16128 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:55Z] skip done in 0.1 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-rounds1
|
||||
[2026-10-07T19:22:55Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:55Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:55Z] skip: day 20730 w 32 double rounds 1 lines 64 segments 256 plant none threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:22:55Z] templates: 2113280 compares of 512-bit lines, chance matches expected 1.576e-148, 0.0 s
|
||||
[2026-10-07T19:22:55Z] template 0 [B(c_j)] at 1 block(s): matches 256 (j0:256)
|
||||
[2026-10-07T19:22:55Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:55Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 16384 (gate 0) PASS
|
||||
[2026-10-07T19:22:56Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1004 rank(line_j-1, line_j) 1004 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:56Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:56Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:56Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:56Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T19:22:56Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +64.00 / -64.00 (gate 6), zero cells 6985 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
|
||||
[2026-10-07T19:22:56Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T19:22:56Z] inversion: 16128 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:56Z] skip done in 0.5 s
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-rounds2
|
||||
[2026-10-07T19:22:56Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:56Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:56Z] skip: day 20730 w 32 double rounds 2 lines 64 segments 256 plant none threads 88; rotations [16, 12, 8, 7]
|
||||
[2026-10-07T19:22:56Z] templates: 2113280 compares of 512-bit lines, chance matches expected 1.576e-148, 0.0 s
|
||||
[2026-10-07T19:22:56Z] template 0 [B(c_j)] at 1 block(s): matches 256 (j0:256)
|
||||
[2026-10-07T19:22:56Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:56Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:56Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:56Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:56Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:56Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:56Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 16384 (gate 0) PASS
|
||||
[2026-10-07T19:22:56Z] rank j=1: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:56Z] rank j=2: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:56Z] rank j=32: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:56Z] rank j=63: samples 4096, columns 1025 (x bits, line bits, 1): rank(x_j, line_j) 1025 rank(line_j-1, line_j) 1025 FULL
|
||||
[2026-10-07T19:22:56Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 1025 of 1025 FULL
|
||||
[2026-10-07T19:22:57Z] dependence: 4096 lines, 512 x 512 flip table: worst cells z +4.72 / -4.59 (gate 6), zero cells 0 of 262144; word table min 4096 of 4096 (every output word changes when any input word changes: YES); 0.1 s
|
||||
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 0 of 16 (gate 0)
|
||||
[2026-10-07T19:22:57Z] inversion: 16128 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:57Z] skip done in 0.5 s
|
||||
lease: released 88 pool cores after 1 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-w4-r2-plant-noff
|
||||
[2026-10-07T19:22:57Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:57Z] skip: day 20730 w 4 double rounds 2 lines 16 segments 4096 plant no-feedforward threads 88; rotations [1, 1, 1, 3]
|
||||
[2026-10-07T19:22:57Z] templates: 2158592 compares of 64-bit lines, chance matches expected 1.170e-13, 0.0 s
|
||||
[2026-10-07T19:22:57Z] template 0 [B(c_j)] at 1 block(s): matches 4096 (j0:4096)
|
||||
[2026-10-07T19:22:57Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 61440 (j1:4096 j2:4096 j3:4096 j4:4096 j5:4096 j6:4096 j7:4096 j8:4096 j9:4096 j10:4096 j11:4096 j12:4096 j13:4096 j14:4096 j15:4096)
|
||||
[2026-10-07T19:22:57Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 61440 of 65536 (gate 0; a plant must read above 0) PASS
|
||||
[2026-10-07T19:22:57Z] rank j=1: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=2: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=8: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=15: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 129 of 129 FULL
|
||||
[2026-10-07T19:22:57Z] dependence: 4096 lines, 64 x 64 flip table: worst cells z +13.41 / -14.91 (gate 6), zero cells 0 of 4096; word table min 3773 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.0 s
|
||||
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
|
||||
[2026-10-07T19:22:57Z] inversion: 61440 lines: Cinv(line_j) = x_j directly 61440; fixed-point iteration x <- Cinv(y - x) converged 61440 (gate 0; the plant must read all); 0.0 s
|
||||
[2026-10-07T19:22:57Z] skip done in 0.0 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-w4-r2-plant-noxor
|
||||
[2026-10-07T19:22:57Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:57Z] skip: day 20730 w 4 double rounds 2 lines 16 segments 4096 plant no-xor threads 88; rotations [1, 1, 1, 3]
|
||||
[2026-10-07T19:22:57Z] templates: 2158592 compares of 64-bit lines, chance matches expected 1.170e-13, 0.0 s
|
||||
[2026-10-07T19:22:57Z] template 0 [B(c_j)] at 1 block(s): matches 65536 (j0:4096 j1:4096 j2:4096 j3:4096 j4:4096 j5:4096 j6:4096 j7:4096 j8:4096 j9:4096 j10:4096 j11:4096 j12:4096 j13:4096 j14:4096 j15:4096)
|
||||
[2026-10-07T19:22:57Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 61440 of 65536 (gate 0; a plant must read above 0) PASS
|
||||
[2026-10-07T19:22:57Z] rank j=1: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=2: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=8: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=15: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 73 of 129 DEFICIENT
|
||||
[2026-10-07T19:22:57Z] dependence: 4096 lines, 64 x 64 flip table: worst cells z +0.00 / -64.00 (gate 6), zero cells 4096 of 4096; word table min 0 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.0 s
|
||||
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
|
||||
[2026-10-07T19:22:57Z] inversion: 61440 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:57Z] skip done in 0.1 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
23
docs/analysis/cryptanalysis/logs/adv-cache-3/skip-w4-r2.log
Normal file
23
docs/analysis/cryptanalysis/logs/adv-cache-3/skip-w4-r2.log
Normal file
|
|
@ -0,0 +1,23 @@
|
|||
lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 skip-w4-r2
|
||||
[2026-10-07T19:22:57Z] adv-cache-3 skip (internal adversarial pass, not an independent review)
|
||||
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
|
||||
[2026-10-07T19:22:57Z] skip: day 20730 w 4 double rounds 2 lines 16 segments 65536 plant none threads 88; rotations [1, 1, 1, 3]
|
||||
[2026-10-07T19:22:57Z] templates: 34537472 compares of 64-bit lines, chance matches expected 1.872e-12, 0.0 s
|
||||
[2026-10-07T19:22:57Z] template 0 [B(c_j)] at 1 block(s): matches 65536 (j0:65536)
|
||||
[2026-10-07T19:22:57Z] template 1 [B(c_j XOR c_i), i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 2 [B(c_j) XOR B(c_i), i < j] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 3 [B(c_j) XOR c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 4 [B(B(c_j))] at 2 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 5 [B(c_j) + c_i, i < j] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] template 6 [Cinv(line_j) XOR c_j = line_{j-1} (up the chain)] at 1 block(s): matches 0
|
||||
[2026-10-07T19:22:57Z] SKIP RESULT: lines derived under j + 1 blocks by any template: 0 of 1048576 (gate 0) PASS
|
||||
[2026-10-07T19:22:57Z] rank j=1: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=2: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=8: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank j=15: samples 4096, columns 129 (x bits, line bits, 1): rank(x_j, line_j) 16 rank(line_j-1, line_j) 16 DEFICIENT: an affine relation exists
|
||||
[2026-10-07T19:22:57Z] rank pooled j>=1: samples 4096, rank(x_j, line_j) 129 of 129 FULL
|
||||
[2026-10-07T19:22:57Z] dependence: 4096 lines, 64 x 64 flip table: worst cells z +14.94 / -15.34 (gate 6), zero cells 0 of 4096; word table min 3771 of 4096 (every output word changes when any input word changes: NO, a word is computable from fewer than 16 input words); 0.0 s
|
||||
[2026-10-07T19:22:57Z] partial knowledge: output words computable from a proper subset of the 16 input words: 16 of 16 (gate 0)
|
||||
[2026-10-07T19:22:57Z] inversion: 65536 lines: Cinv(line_j) = x_j directly 0; fixed-point iteration x <- Cinv(y - x) converged 0 (gate 0); 0.0 s
|
||||
[2026-10-07T19:22:57Z] skip done in 0.1 s
|
||||
lease: released 88 pool cores after 0 s, exit 0
|
||||
186
docs/analysis/cryptanalysis/report-chained-cache-3.md
Normal file
186
docs/analysis/cryptanalysis/report-chained-cache-3.md
Normal file
|
|
@ -0,0 +1,186 @@
|
|||
# Report: the chained cache, chain break or skip (lane adv-cache-3)
|
||||
|
||||
Internal adversarial pass, not an independent review. Lane `adv-cache-3`, the chain-break-or-skip class of the chained cache: line `(s, j)` in fewer than `j + 1` blocks without an earlier line; relations through the XOR chaining and the feed-forward; partial knowledge; the pebbling curve of the 64-line chain. Plan: `docs/plans/cryptanalysis/plan-chained-cache-3.md`. Every sentence here that could be quoted publicly carries the label: internal adversarial pass, not an independent review. Times are UK time (BST); the logs carry UTC.
|
||||
|
||||
## Header
|
||||
|
||||
| Item | Value |
|
||||
|---|---|
|
||||
| Target commit | `017e70376489251e18564c0abce7e466e606c8b3` (class v4 sub-version 3, object byte 7); `igneum-pow` at `build/master` 04c4d9bc is byte-identical (`git diff --quiet 017e7037 HEAD -- igneum-pow` printed IDENTICAL at 19:42), and the harness depends on it by path |
|
||||
| Harness | `tools/attack/adv-cache-3/` (crate `attack-adv-cache-3`, binary `adv-cache-3`, commands `check`, `skip`, `relations`, `image`, `pebble`, `cross`), branch `adv-cache-3` on the build mirror |
|
||||
| Binary sha256 | `37a7a661c548a67827e29c4134bb91751ef2083920b386d3ebc9b599add3ca8a` on both boxes (built from commit 4e363b91's tree, `cargo build --release`, rustc 1.99.0). The first build `067ad69c...` had 66 rank samples per `j` instead of 4,096 and was replaced; its one run (`skip-d20730`, 20:09) agrees with the rerun on every other number |
|
||||
| Self-test on every start | the restated `B` equals the library's `chacha_block` on 4,096 random inputs; `core_inv` inverts `core` at w = 2, 4, 8, 16, 32; the restated chain equals `Cache::fill_segment` on segments 0, 21,859 and 65,535 of day 20730 |
|
||||
| Vectors passed | day 20730 cache FNV-1a 64 `0x448274a57f508cbc` (the kit's `vectors.json`) and day 20733 `0x7334fa46e5d972eb` (the Devnet 3 pack): MATCH (`check.log`) |
|
||||
| Boxes and scheduling | build box 1 for the skip, relations, pebble and cross runs, build box 2 for the exhaustive image census; every run through `/srv/builds/_bin/lease pool` (main's rule of 20:1x, no sweep by hand), nice 10 on cores 8 to 95; the boxes read load 400 to 600 on 96 threads all evening, so wall times are not timings |
|
||||
| Logs | `/srv/builds/_adv-cache-3/logs/<tag>.log` on each box (outside the worktree mirror); copies under `docs/analysis/cryptanalysis/logs/adv-cache-3/` on this branch, `ledger.txt` the start and end of every run |
|
||||
| THE QUEUE | files 90, 91, 92 (the coordinator's definitions) claimed at 19:49 with owner files; implemented and run as files 93 (skip batch, 14 runs), 94 (relations, 4 runs), 96 (the 1,024-line chain, 4 runs) on build box 1 and 95 (the image census) on build box 2; 97 (the image census again at 48 cores) queued behind the class v5 waiters |
|
||||
| Box-hours | 0.26 slot-hours in all (section 9); no pod-hours (no GPU row in this lane) |
|
||||
|
||||
## Status board
|
||||
|
||||
| # | Question | Method | Known-failed shape (fired?) | Gate | Result | Status |
|
||||
|---|---|---|---|---|---|---|
|
||||
| Q1 (brief a, file 90) | Line `(s, j)` in fewer than `j + 1` blocks without an earlier line of its segment | `skip`: 7 earlier-line-free templates at 1 or 2 blocks against every line; the GF(2) rank of the `(x_j, line_j, 1)` sample matrix; the 512 x 512 bit-dependence table and the 16 x 16 word table; the inversion attempt; the reduced-round ladder | `no-xor` fired (64,512 of 65,536 lines at 1 block; dependence table all zero); `no-feedforward` fired (64,512 lines recovered up the chain; 64,512 of 64,512 inversions); `--rounds 0` fired (rank 17 of 1,025) | 0 lines under `j + 1`; rank 1,025; no zero cell; 0 inversions | 64-line chain, 1,024 segments, days 20730 and 20733: 0 of 131,072 lines by any template (16.9 M compares); 1,024-line chain, 64 segments, both days: 0 of 131,072 (268.6 M compares); rank 1,025 of 1,025 at `j` = 1, 2, 32, 63 and 1,023; flip table worst z +4.47 / -4.88 of 262,144 cells, 0 zero cells; every output word changes with every input word; 0 of 130,000 inversions | BOUND, PASS |
|
||||
| Q1 (4) | Exhaustive image census at w = 2: every one of 2^32 states per step, depth 64 | `image` | `no-feedforward` fired (a permutation: the image stays 2^32 at every one of 6 depths) | the chain loses entropy no faster than a random function | all 64 depths: image 0.632142, 0.468559, 0.312098, 0.189061, 0.106546, 0.057174, 0.029762 of 2^32 at depths 1, 2, 4, 8, 16, 32, 64 against the random-function recursion 0.632121, 0.468536, 0.312080, 0.189050, 0.106537, 0.057173, 0.029762: within 2.3 x 10^-5 at every depth, exactly equal at depth 64 to six places | BOUND, PASS |
|
||||
| Q2 (brief b, c, file 91) | Relations through `line_j = C(x_j) + x_j`; partial knowledge | `relations`: per-bit bias of 4 relations and the 512 x 512 linear-correlation table over 4 day keys x 2^20 lines; `skip`'s word table and inversion for the partial-knowledge half | `--rounds 1` and `--rounds 2` did NOT fire on the bias and correlation statistics (worst 4.47 and 4.65 sigma at 2^16 lines); the relation class's plants that do fire are in `skip`: `--rounds 1` leaves 21 exact affine relations (rank 1,004) and 6,985 zero cells in the flip table, `no-feedforward` inverts every line | every bias and cell within 6 sigma at 2^22 samples; 0 words from a proper subset; 0 inversions | 4,128,768 lines: worst bias 3.58 sigma of 2,048 bits; worst correlation cell 4.83 sigma of 262,144 (0 cells over 5, 0.15 expected); 0 of 16 output words from a proper subset of input words; 0 inversions | BOUND, PASS; the plant caveat in section 2 |
|
||||
| Q3 (brief d, file 92) | The pebbling curve of the 64-line chain under storage `f`; the amortising adversary | `pebble`: exact DP optimum over placements (checked against exhaustive search at 10, 12, 14, 16 lines, 12 of 12 agree), the two stride placements, ops per item and SRAM; Monte Carlo of `m` requests per segment, fixed and Poisson | `--skip-edge 8` fired (optimum 5.19 blocks at `f = 1/64` against 16.0) | monotone; never under the honest hold-every-k-th curve; 9,360 at `f = 1` | Monotone, 9,360 at `f = 1`. The DP optimum sits UNDER the hold-every-k-th curve at small `f`: 16.0 against 31.5 blocks per read at `f = 1/64`, 10.5 against 15.5 at 2/64, 6.09 against 7.5 at 4/64, 3.17 against 3.5 at 8/64, 1.45 against 1.5 at 16/64, equal from 32/64. Not an attack: a correction of the honest baseline (section 3) | FINDING (bookkeeping, not a break): the honest curve of the gate is mis-specified at small `f`; the chip's partial-cache price at `f = 1/64` is 9.3x the item's ops, not 17.4x |
|
||||
| Q4 (brief e) | Cross-segment and cross-day relations; the known-constant words | `cross`: 512 x 512 correlation tables at `j` = 0, 1, 63 across one-bit segment pairs and across days 20730 and 20731 | `--plant no-xor --rounds 1` fired (3,385 to 3,585 cells over 6 sigma per table, worst 64) | every cell within 6 sigma | 4,096 pairs per table: worst 4.50, 4.75, 5.00 (segments at `j` = 0, 1, 63), 4.56 (days); 0 cells over 6 sigma of 1,048,576 | BOUND, PASS |
|
||||
|
||||
## 1. Q1: the skip search
|
||||
|
||||
Commands (box 1, file 93 and file 96, binary `37a7a661...`): `adv-cache-3 skip --day 20730 --segments 1024 --threads 88` and `--day 20733`; `--segments 64 --lines 1024` on both days; plants `--plant no-xor`, `--plant no-feedforward` at 64 and 1,024 lines; the ladder `--rounds 0, 1, 2` at 256 segments; the model `--w 4 --rounds 2 --segments 65536 --lines 16` with both plants. Seeds: the chain day keys `seed_words_from_bytes("igneum-day/" || le64(d))`; segments `s = (p * 0x9E37) AND 0xffff` for `p` in 0..segments, or every segment when `segments >= 65,536`. Logs `skip-*.log`.
|
||||
|
||||
What was searched, from the code (`memhard.rs` `chacha_block`, `fill_segment_tagged`):
|
||||
|
||||
| Test | What it would catch | Day 20730 | Day 20733 |
|
||||
|---|---|---|---|
|
||||
| Templates: `B(c_j)`, `B(c_j XOR c_i)`, `B(c_j) XOR B(c_i)`, `B(c_j) XOR c_i`, `B(B(c_j))`, `B(c_j) + c_i` for `i < j`, and `Cinv(line_j) XOR c_j = line_{j-1}` (up the chain from a stored later line) | a line computable from the public constants alone, or a line computable from its successor | 0 matches on 65,536 lines at 64 lines and 65,536 at 1,024 lines (`B(c_0) = line_0` is the chain's own definition at 1 = j + 1 blocks and is counted as not under); chance expectation under 10^-146 | the same, 0 |
|
||||
| GF(2) rank of the 4,096 x 1,025 matrix `(x_j bits, line_j bits, 1)` and of `(line_{j-1}, line_j, 1)` | any affine relation between a line and its input, which is a skip (a linear `B` chains to a linear closed form) | 1,025 of 1,025 at `j` = 1, 2, 32, 63 and pooled; at 1,024 lines 1,025 at `j` = 1 and 1,023 | the same |
|
||||
| Flip table: each of the 512 bits of `line_{j-1}` flipped, the flip rate of each of the 512 bits of `line_j`, over 4,096 lines | a bit of a line that does not reach a bit of the next (a skip through a sub-block) | worst z +4.44 / -4.53 (64-line), +4.34 / -4.88 (1,024-line); 0 zero cells | +4.47 / -4.47; +4.41 / -4.47; 0 zero cells |
|
||||
| Word table: each input word randomised, which output words change | an output word computable from fewer than 16 input words (the partial-knowledge gain) | 4,096 of 4,096 for every pair; 0 of 16 words from a proper subset | the same |
|
||||
| Inversion: `Cinv(line_j) = x_j`; the fixed-point iteration `x <- Cinv(y - x)` from 0, 64 steps | a cheap inverse of `B = C + x`, which walks up the chain from any stored line | 0 of 64,512 (64-line) and 0 of 65,472 (1,024-line) | 0 and 0 |
|
||||
|
||||
The reduced-round ladder (256 segments, day 20730), the margin of the rank and flip tests:
|
||||
|
||||
| Double rounds of `C` | Rank at `j = 1` of 1,025 | Zero cells of 262,144 | Flip table worst z | Reading |
|
||||
|---|---|---|---|---|
|
||||
| 0 (`B(x) = 2x`) | 17 | 261,648 | 64 | fully affine; the plant for the rank test |
|
||||
| 1 (2 ChaCha rounds) | 1,004 | 6,985 | 64 | 21 exact affine relations survive one double round; 6,985 input-output bit pairs never interact |
|
||||
| 2 (4 rounds) | 1,025 | 0 | +4.72 / -4.59 at 4,096 lines; +4.71 / -4.73 at 262,080 lines (file 98) | nothing: at 2^18 lines a flip bias of 2^-8.5 would read 6 sigma, so the single-bit flip test stops between one and two double rounds |
|
||||
| 3 (6 rounds) | 1,025 | 0 | +4.81 / -4.70 at 262,080 lines | nothing |
|
||||
| 4 (8 rounds) | 1,025 | 0 | +4.76 / -4.77 at 262,080 lines | nothing |
|
||||
| 6 (12 rounds, the real `B`) | 1,025 | 0 | +4.47 / -4.53 at 4,096 lines; +4.38 / -4.66 at 262,080 lines | nothing; the expected maximum of 262,144 normal draws is 4.9 sigma and every ladder row sits on it |
|
||||
|
||||
The small-scale model `B(4, 2)` (16 words of 4 bits, 2 double rounds, rotations 1, 1, 1, 3): the template search over the 16-line chain reads 0 matches on 1,048,576 lines (34.5 M compares, chance 1.9 x 10^-12); the flip table has 0 zero cells. Two caveats on the model, stated so nobody over-reads it: `s` is truncated to 4 bits, so the 65,536 "segments" are 16 distinct chains repeated (the per-`j` rank of 16 is that repetition, not a relation); and the word-level test is not valid at 4-bit words (a 4-bit output word equals its old value by chance 1 in 16, so "16 of 16 words from a subset" at w = 4 is chance, not structure). The model's job here was to run the same code at a width where the plants are cheap; both plants fired on it (61,440 of 65,536 lines each).
|
||||
|
||||
Known-failed shapes, all fired: `no-xor` (prev not XORed in) reads 64,512 of 65,536 lines at 1 block by `B(c_j)`, a flip table of 262,144 zero cells and 16 of 16 words from a subset (rank of `(x_j, line_j)` 529, since `x_j = c_j` varies in two words only); `no-feedforward` (`B = C`) reads 64,512 lines recovered by `Cinv(line_j) XOR c_j` and 64,512 of 64,512 inversions, with the rank and flip tables unchanged (a permutation is still a good mixer; the loss is the one-way property); `--rounds 0` collapses the rank to 17. At 1,024 lines the plants read 16,368 of 16,384.
|
||||
|
||||
Reading: no earlier-line-free derivation of any line, no affine relation between consecutive lines, no bit or word of a line computable from part of its input, no inverse. The one-way property of `B = C(x) + x` is what the chain's cost rests on, and the plant without it falls to the inverse template at once.
|
||||
|
||||
## 2. Q2: the feed-forward relations and partial knowledge
|
||||
|
||||
Command (box 1, file 94): `adv-cache-3 relations --day0 20730 --days 4 --lines-log2 20 --threads 88` (log `relations-4d-l20.log`); the ladder `--rounds 1`, `--rounds 2` at 2^16 lines, `--rounds 3` at 2^18. Lines `j >= 1` of segments 0 to 16,383 on days 20730 to 20733: 4,128,768 lines.
|
||||
|
||||
| Statistic | Samples | Worst |z| | Where | Gate 6 |
|
||||
|---|---|---|---|---|
|
||||
| `line_j XOR x_j`, per bit | 4,128,768 | 3.00 | word 1 bit 16 | PASS |
|
||||
| `line_j - x_j` (that is `C(x_j)`), per bit | 4,128,768 | 3.58 | word 2 bit 11 | PASS |
|
||||
| `line_j XOR line_{j-1}`, per bit | 4,128,768 | 3.29 | word 8 bit 11 | PASS |
|
||||
| `line_j - line_{j-1}`, per bit | 4,128,768 | 3.29 | word 10 bit 13 | PASS |
|
||||
| `x_j[a] XOR line_j[b]` over all 262,144 cells (the `line_{j-1}` table is the same up to a sign per column, since `x_j = line_{j-1} XOR c_j`) | 4,128,768 | 4.83 | in word 9 bit 8, out word 14 bit 19; 0 cells over 5 sigma against 0.15 expected | PASS |
|
||||
|
||||
The expected maximum of 2,048 or 262,144 normal draws is 3.5 or 4.9 sigma; the worst cells sit on those.
|
||||
|
||||
Partial knowledge (section 1's word table and inversion): given `k < 16` words of `line_{j-1}`, 0 words of `line_j` are determined (every output word changes when any single input word changes, 4,096 of 4,096 times); given `line_j`, nothing of `x_j` leaks beyond the correlation table's chance level, the direct inverse recovers 0 lines and the fixed-point iteration converges on 0. What IS known of `x_j` from the code: at `j = 0` all 16 words (`x_0 = c_0`, public, the spec says so); at `j >= 1` no word, since every word of `c_j` is XORed with the previous line.
|
||||
|
||||
The plant caveat, stated plainly: the queue file's known-failed shape ("a reduced C at 2 rounds must show a measurable bias") did not fire on the bias and correlation statistics. At one double round (2 ChaCha rounds) the worst bias reads 3.22 sigma and the worst correlation cell 4.47 at 2^16 lines; at two double rounds 4.58 and 4.65; at three 4.33 and 4.45 at 2^18 lines. Single-bit biases of `C(x) + x` over a near-uniform `x` and single-bit-in, single-bit-out linear correlations are not where a reduced ChaCha leaks: the 21 affine relations one double round leaves involve many bits at once, and the public distinguishers on 3 to 7 rounds use a chosen input difference with a multi-bit output mask and 2^30 or more samples. The relation class's plants that do fire are the rank test (rank 1,004 at one double round, 17 at zero) and the flip table (6,985 zero cells at one double round), both in section 1, and `no-feedforward` on the inversion. So the Q2 sweep is a bound on exactly what it measures (per-bit biases and pairwise correlations at 2^22 samples, under 6 sigma), and the known-failed shape for the relation class is carried by section 1's tests, not by this one. A statistic that would fire at two double rounds is a differential-linear one with 2^20 or more samples per input difference; section 8b.
|
||||
|
||||
## 3. Q3: the pebbling curve
|
||||
|
||||
Command (box 1, file 93): `adv-cache-3 pebble --lines 64 --exhaustive-upto 16 --mc 1000000` (log `pebble.log`); plant `--skip-edge 8` (`pebble-plant-skip8.log`). Pure arithmetic and Monte Carlo on the chain as a graph; no day key.
|
||||
|
||||
The model: `k` held lines of 64 (`f = k / 64`); a uniform read of line `j` costs the walk from the nearest held line at or below `j` (or from nothing: `j + 1`). The exact optimum over placements by dynamic programming agrees with exhaustive search over every subset at 10, 12, 14 and 16 lines for `k` = 1, 2, 4 (12 of 12). Ops per item `9,360 + 8 x blocks x 608`; SRAM `f x 128 mm^2` at the N5 headline of `chip-model-v3.md` section 2.
|
||||
|
||||
| `f` | `k` held | DP optimum, blocks per read | hold every (64/k)-th line (offset 0 and offset step-1) | ops per item at the optimum | multiple of the item's 9,360 | SRAM mm^2 |
|
||||
|---|---|---|---|---|---|---|
|
||||
| 1/64 | 1 | 16.00 (line 32 held) | 31.50 | 87,184 | 9.3x | 2 |
|
||||
| 2/64 | 2 | 10.50 | 15.50 | 60,432 | 6.5x | 4 |
|
||||
| 4/64 | 4 | 6.09 | 7.50 | 39,000 | 4.2x | 8 |
|
||||
| 8/64 | 8 | 3.17 | 3.50 | 24,788 | 2.6x | 16 |
|
||||
| 16/64 | 16 | 1.45 | 1.50 | 16,428 | 1.8x | 32 |
|
||||
| 32/64 | 32 | 0.50 | 0.50 | 11,792 | 1.26x | 64 |
|
||||
| 1 | 64 | 0 | 0 | 9,360 | 1.00x | 128 |
|
||||
|
||||
The finding, and what it is not: the gate asked for a curve "never below the honest hold-every-k-th curve". The optimum IS below it at small `f`, by 2.0x at `f = 1/64` and 1.5x at 2/64, because holding every `(64/k)`-th line puts the first held line at the segment's start, where the chain is cheap anyway (line 0 costs 1 block from nothing), and leaves the far half unprotected. The optimal single held line is line 32; the optimal `k` lines are spaced closer toward the end of the segment. This is a correction of the honest baseline that sibling `adv-cache`'s Q1b table and the gate wording carry (31.5, 15.5, 7.5, 3.5, 1.5, 0.5 blocks), not an attack: the honest miner holds the whole cache and pays nothing per read; what moves is the price a partial-cache chip pays, which at `f = 1/64` is 9.3x the item's operations instead of 17.4x. At the chip-relevant point `f = 1/2` nothing changes (0.50 blocks per read, 1.26x the item's ops, 64 mm^2 saved), so the SRAM column of `chip-model-v3.md` and sibling `adv-cache`'s verdict (monotone toward the full store) stand. The curve is monotone in `f` and reads 9,360 at `f = 1` as the gate requires.
|
||||
|
||||
The amortising adversary (`m` requests in one segment, one walk per gap from the nearest held line to the deepest request; the 2^16 segments are independent so nothing amortises across them; Monte Carlo 10^6 trials, the stride placement at offset step-1):
|
||||
|
||||
| `f` | m = 1 | m = 2 | m = 4 | m = 8 | m = 16 | m = 64 | Poisson 1 | Poisson 8 | Poisson 64 |
|
||||
|---|---|---|---|---|---|---|---|---|---|
|
||||
| 1/64 (line 63 held: in effect nothing) | 31.52 | 21.07 | 12.67 | 7.05 | 3.73 | 0.98 | 23.24 | 6.95 | 0.98 |
|
||||
| 2/64 | 15.49 | 12.94 | 9.55 | 6.10 | 3.47 | 0.95 | 13.24 | 5.90 | 0.95 |
|
||||
| 4/64 | 7.50 | 6.90 | 5.89 | 4.48 | 2.94 | 0.90 | 6.93 | 4.33 | 0.90 |
|
||||
| 8/64 | 3.50 | 3.36 | 3.11 | 2.69 | 2.09 | 0.80 | 3.37 | 2.62 | 0.80 |
|
||||
| 16/64 | 1.50 | 1.47 | 1.42 | 1.32 | 1.16 | 0.61 | 1.47 | 1.30 | 0.61 |
|
||||
| 32/64 | 0.50 | 0.50 | 0.49 | 0.47 | 0.45 | 0.32 | 0.50 | 0.47 | 0.32 |
|
||||
|
||||
Cross-check: with nothing held the Poisson rows read 23.24, 6.95 and 0.98 blocks per read at `m` = 1, 8, 64; sibling `adv-cache` measured 23.84, 7.06 and 0.99 on real addresses (its batch rows), so the uniform model and the real derivation agree to 3 percent. Batching helps only when `m` requests per segment are many, which costs `m x 2^16 x 64 B` of item state (the sibling's point); with half the lines held the gain at `m = 64` is 0.50 to 0.32 blocks per read, 0.2 x 608 = 110 operations per read against the item's 9,360.
|
||||
|
||||
Known-failed shape: `--skip-edge 8` (line `j` also derivable from line `j - 8` in one block) lowers the `f = 1/64` optimum from 16.00 to 5.19 blocks per read; fired.
|
||||
|
||||
## 4. Q4: cross-segment and cross-day relations
|
||||
|
||||
Command (box 1, file 93): `adv-cache-3 cross --day 20730 --segments 4096 --threads 88` (`cross-d20730.log`); plant `--plant no-xor --rounds 1` (`cross-plant-noxor-r1.log`). Pairs `s, s XOR 2^(p mod 16)` with `s = (p * 0x9E37) AND 0xffff`; the cross-day table pairs line `(s, j)` of day 20730 with the same of day 20731, `j = p mod 64`.
|
||||
|
||||
| Table | Samples | Worst |z| of 262,144 cells | Cells over 6 sigma |
|
||||
|---|---|---|---|
|
||||
| `line_0(s)` against `line_0(s XOR 2^b)` (the 2^16 first inputs differ in word 12 only: the multi-target) | 4,096 | 4.50 | 0 |
|
||||
| `line_1(s)` against `line_1(s XOR 2^b)` | 4,096 | 4.75 | 0 |
|
||||
| `line_63(s)` against `line_63(s XOR 2^b)` | 4,096 | 5.00 | 0 |
|
||||
| `line_j(s)` of day 20730 against day 20731 | 4,096 | 4.56 | 0 |
|
||||
|
||||
The plant (prev not XORed in, one double round) reads 3,385 to 3,585 cells over 6 sigma per segment table (worst 64) and 1,113 in the day table; fired.
|
||||
|
||||
## 5. Q1 (4): the exhaustive image census at w = 2
|
||||
|
||||
Command (box 2, file 95 to depth 8 at 87 cores, then file 97 in full at 32 cores): `adv-cache-3 image --w 2 --rounds 6 --depth 64 --threads {cores}` (logs `image-w2-r6-d64-partial-to-depth8.log`, `image-w2-r6-d64-full.log`); the plant `--plant no-feedforward --depth 6` (`image-w2-plant-noff.log`). The 16-word block at 2-bit words is a 32-bit state; every one of the 2^32 states is enumerated at each step, so the census is exact. `S_0` is every state; `S_k = { B(p XOR c_k) : p in S_{k-1} }` with the real constant layout truncated to 2 bits (`j` wraps mod 4). What it measures: how much of the state space the chain can still reach at depth `k`, against a random function (`tau_k = 1 - exp(-tau_{k-1})`) and a permutation (1 at every depth, the plant).
|
||||
|
||||
| Depth | Image of 2^32 | Random-function recursion | Difference | Wall at 32 cores |
|
||||
|---|---|---|---|---|
|
||||
| 1 | 0.632142 | 0.632121 | +2.1 x 10^-5 | 87 s |
|
||||
| 2 | 0.468559 | 0.468536 | +2.3 x 10^-5 | 133 s |
|
||||
| 4 | 0.312098 | 0.312080 | +1.8 x 10^-5 | 201 s |
|
||||
| 8 | 0.189061 | 0.189050 | +1.1 x 10^-5 | 288 s |
|
||||
| 16 | 0.106546 | 0.106537 | +0.9 x 10^-5 | 395 s |
|
||||
| 24 | 0.074372 | 0.074368 | +0.4 x 10^-5 | 466 s |
|
||||
| 32 | 0.057174 | 0.057173 | +0.1 x 10^-5 | 513 s |
|
||||
| 48 | 0.039133 | 0.039132 | +0.1 x 10^-5 | 579 s |
|
||||
| 64 | 0.029762 | 0.029762 | 0 to six places | 633 s |
|
||||
| plant `no-feedforward`, depths 1 to 6 | 1.000000 at every depth (4,294,967,296 states) | | | 451 s |
|
||||
|
||||
The full run was 2.3 x 10^11 reduced block evaluations (the images summed over 64 depths), 10.5 minutes on 32 cores. Reading: `B = C + x` behaves as a random function to five decimal places at every depth of the chain, so the chain loses `log2(k / 2)` bits of its state per `k` steps (about 5 bits of 512 at depth 64, 0.03 of the space at 2-bit words) and no faster. A skip would show as an image smaller than the recursion (a collapse of the state space, which a chip could enumerate) or larger (a permutation-like structure, which inverts); neither. The plant without the feed-forward is a permutation and reads 2^32 at every depth, so the test fires on the shape it is meant to catch. A caveat on the model, the same as section 1's: at 2-bit words the rotations are all 1 and `s`, `j` are truncated, so this measures the chain's shape under a ChaCha-like random-looking block, not 12-round ChaCha's own diffusion.
|
||||
|
||||
## 6. Consequences per tier
|
||||
|
||||
Every row is a bound or a bookkeeping correction, so nothing changes for any tier today: a home miner with one 8, 12, 16 or 24 GB card on any vendor and OS, a rig and a pool user fill the 256 MiB cache once a day (0.2 s on one core per the spec's table, under a second at the growth steps) and the hash never reads it. For the chip model: the partial-cache price at small `f` is about half of what the hold-every-k-th curve says (section 3), which makes a chip holding 1/64 of the cache pay 9.3x the item's operations instead of 17.4x; still far above the full store, and at `f = 1/2` nothing moves, so the SRAM column (128 mm^2, $46 at N5 for 256 MiB) stays the chip's cost. What is being done: the curve row is handed to the coordinator for `chip-model-v3.md` and sibling `adv-cache`'s table; section 8b names the one statistic that would sharpen the reduced-round margin.
|
||||
|
||||
## 7. What is not covered
|
||||
|
||||
- No differential-linear cryptanalysis of reduced ChaCha with chosen input differences and multi-bit masks; the ladder here stops where single-bit statistics stop (two double rounds at 4,096 to 2^16 samples). Public work on 7 of 20 rounds is general knowledge here, not a citation, and the real `B` has 12 rounds.
|
||||
- The 2-bit and 4-bit models change the rotations (1, 1, 1, 3 and 1, 1, 1, 1) and truncate `s` and `j`; they test the code path and the chain shape, not ChaCha's diffusion.
|
||||
- The derivation program class (`derive_len != 0`) is not exercised; class v4 has the fixed mixer and the chain does not depend on it.
|
||||
- GPU: no row; nothing in this class needs one.
|
||||
|
||||
## 8b. What a longer pass would add
|
||||
|
||||
One line: a differential-linear sweep on the reduced ladder (one chosen input difference, every output bit and every two-bit output mask, 2^24 samples per round count, 2 to 6 double rounds) would put a number on the round margin where section 1's single-bit tests stop (between one and two double rounds at 2^18 lines, file 98); it changes no row at 12 rounds, and nothing here is a reason to wait for it.
|
||||
|
||||
## 9. Run ledger and box-hours
|
||||
|
||||
| Run | Box | Started (BST) | Wall | Slot-hours |
|
||||
|---|---|---|---|---|
|
||||
| `check`, first `skip` (binary `067ad69c...`, under the sweep flock) | 1 | 20:06, 20:09 | 2 s, 1 s (3 min waiting for the lock) | 0.001 |
|
||||
| Files 93, 94, 95 queued under the sweep flock | 1, 2 | 20:12 to 20:15 | never started; killed by pid file 20:20 to 20:21 under main's rule (every sweep through `lease pool`); nothing measured was lost | 0 |
|
||||
| File 93 (14 runs: skip x 10, pebble x 2, cross x 2), file 94 (relations x 4), file 96 (skip at 1,024 lines x 4), through `lease pool 88` | 1 | 20:22:52 to 20:23:06 | 14 s in all, 0.1 to 2 s per run on 88 cores | 0.004 |
|
||||
| File 95, the image census, `lease pool 88` (87 cores taken) | 2 | 20:22:46 | 106 s to depth 8; released at 20:24:38 by main's order for the class v5 gate (partial kept) | 0.026 |
|
||||
| File 97, the image census again plus the plant, `lease pool 48 --min 16` | 2 | queued 20:26; its yield loop passed at 20:35 when the class-v5 waiter line was absent for a moment, the lease took 48 cores at 20:41:15 and the binary ran about 30 s while class-v5 waited; killed by pid 20:41:5x (my error against main's order of 20:3x: no adv-* lease on box 2 until the class v5 census runs); not restarted until main clears box 2 | 0.4 min | 0.007 |
|
||||
| File 98, the flip-table ladder at 2^18 lines (rounds 2, 3, 4, 6), resubmitted 20:43 at `lease pool 32 --min 16` under the ranked lease (class adv), binary `45911ba7...` (the harness with `--dep-samples`, commit d5d53701) | 1 | queued 20:33, cores taken 21:13 after 30 min waiting | 4 runs of 5 s each on 32 cores, done 21:14 | 0.005 |
|
||||
| File 97, the image census again at `lease pool 32 --min 16`, class adv | 2 | restarted 21:13 when main opened box 2; cores taken 21:13 | depth 64 in 10.5 min, the plant 7.5 min; done 21:34 | 0.17 (32 of 88 cores for 18 min, counted as 0.36 of a slot) |
|
||||
| Sibling file 43 (`adv-cache-2 warps-devnet-2e26-v2`, owner adv-cache-2: the 2^26-nonce warps census of the devnet program), claimed by this lane at 21:16 as the next unclaimed queue file, run with the same command at 32 threads (24 taken) | 2 | 21:35 | killed at 21:39 by adv-cache-2's drain (by mistake, as an orphan of its own; 247 s and 24 cores lost); the owner says file 43 is superseded by its item 430 at 2^25 nonces, so it is not run again; the partial log is kept as `sibling-43-warps-devnet-2e26-v2.log` (section 10) | 0.03 |
|
||||
|
||||
Running total: 0.26 slot-hours of the 8 budgeted (the ask line is 16); no pod-hours. Every sweep the plan called for ran in seconds because the chain is 2^22 blocks a day and the statistics here are 2^22 to 2^27 block evaluations; the width went into day keys, chain lengths and the reduced-round ladder rather than into time.
|
||||
|
||||
## 10. Sibling queue file 43, run for adv-cache-2
|
||||
|
||||
Claimed at 21:16 as the only unclaimed file in THE QUEUE (`43-adv-cache-2-warps-devnet-2e26-v2.sh`, owner `adv-cache-2`, its binary and its log directory), run with the file's own command at 32 threads (`lease pool 32 --min 16`, 24 cores taken) from 21:35. The process was ended by SIGTERM at 21:39 after 247 s (rc 143): adv-cache-2's drain killed it by mistake as an orphan of its own, about 3 minutes of 24 cores lost. The owner has since said the file is superseded by its item 430 at 2^25 nonces, so the row is not needed and the file is not run again. What the log had written before the kill, for the owner to read against its own gates (its statistics, not this lane's):
|
||||
|
||||
| Row in the owner's log | Reading |
|
||||
|---|---|
|
||||
| per-site histograms (16 sites, 2^22 items each, 2^29 reads) | worst z_max +5.21, chi2/dof 1.00084 at site 15 |
|
||||
| LINE histogram, 2^36 line reads | matches the windowed control to 4 figures (chi2/dof 630.31 against 630.29; z_max 147.4 against 147.0: the window layer's designed non-uniformity, present in the control too) |
|
||||
| hot set, lines, f = 0.1 / 0.5 / 1 percent | S_f equals the control's E_f to 1.0000x, 1.0001x, 1.0001x: "verdict clear" |
|
||||
| SEGMENT histogram | matches the control (631.64 against 631.68; the largest bucket 21,859 in both) |
|
||||
| REAL LINE STORE | f = 1/2 stride 0.260x of the item's ops, f = 1/2 hottest 0.431x, f = 1/4 stride 0.779x; equal under the control |
|
||||
| ITEM STORE (hottest items) | f = 0.001: 0.9991x of the model's ops per hash; f = 0.01: 0.9918x; the f = 0.1 row cut by the kill |
|
||||
|
||||
The file stays claimed as it is; nothing else was queued behind it in this lane.
|
||||
88
docs/plans/cryptanalysis/plan-chained-cache-3.md
Normal file
88
docs/plans/cryptanalysis/plan-chained-cache-3.md
Normal file
|
|
@ -0,0 +1,88 @@
|
|||
# Attack plan: the chained cache, chain break or skip (lane adv-cache-3)
|
||||
|
||||
Internal adversarial pass, not an independent review. Every sentence in this file and in the report that could be quoted publicly carries that label.
|
||||
|
||||
Lane `adv-cache-3`, branch `adv-cache-3` cut from `build/master` 04c4d9bc at 19:42 BST on 7 October 2026. The attacker here is an outsider with the public kit who has never worked on the hash code. The question class is the chain break or skip: can line `(s, j)` of the cache be had for fewer than `j + 1` block evaluations without holding an earlier line of its segment, and what structure do the XOR chaining and the feed-forward leave between lines.
|
||||
|
||||
## 0. The outsider rule, applied
|
||||
|
||||
| Check | Result |
|
||||
|---|---|
|
||||
| Frozen commit | `017e70376489251e18564c0abce7e466e606c8b3` (class v4 sub-version 3, object byte 7) |
|
||||
| HEAD of this worktree | `04c4d9bc3942b3d312559212aa990fdf94e0c755` (`build/master` at 19:42 BST) |
|
||||
| `git diff --quiet 017e7037 HEAD -- igneum-pow` | IDENTICAL (printed at 19:42 BST). The harness depends on the worktree's `igneum-pow/` by path `../../../igneum-pow`; the check is repeated before every build |
|
||||
| Public kit zip | sha256 `4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154` as the brief states; the eight packs are read from `proto-cuda/packs-ca3-v4/` in the worktree |
|
||||
| Devnet 3 epoch-0 pack | `/srv/artefacts/packs/v4-devnet3-epoch0.zip` on build box 1, sha256 `e025750f71175ed14d6e2a24e387ebbf1979b1cd0faee9139c41a7671165b334` (verified on the box, 19:43 BST); `program.json` id `0xfce15bf61030be57` at attempt 0, day bytes le64(20733); read in place, nothing copied into the repository |
|
||||
| Worktree | `/Users/joshm/Projects/igneum-wt-adv-cache-3`, harness crate `tools/attack/adv-cache-3/` |
|
||||
| Logs and results | `/srv/builds/_adv-cache-3/` on each box (outside the worktree mirror); copies under `docs/analysis/cryptanalysis/logs/adv-cache-3/` on this branch |
|
||||
|
||||
Files opened, the complete list:
|
||||
|
||||
| File | How much |
|
||||
|---|---|
|
||||
| `igneum-pow/src/memhard.rs` | in full (`chacha_block`, `qr`, `fill_segment_tagged`, `mixer`, `derive_items_mask`, `Shape`, the tests) |
|
||||
| `igneum-pow/src/seed.rs`, `igneum-pow/src/lib.rs` | in full |
|
||||
| `igneum-pow/src/bind.rs` | the public function list, `day_bytes`, `day_index`, the `day_bytes_layout` test |
|
||||
| `igneum-pow/Cargo.toml`, `igneum-pow/Cargo.lock`, `igneum-pow/README.md` (first 60 lines), the `src/` and `tests/` file list | in full |
|
||||
| `docs/spec/01-lottery-hash.md` at 017e7037 | the heading list; sections 1.8 (1.8.1 to 1.8.5) and 1.13.3 |
|
||||
| `docs/analysis/chip-model-v3.md` at HEAD | the heading list; sections 1, 2, 5 (5.1 to 5.9), 6 |
|
||||
| `proto-cuda/packs-ca3-v4/` | the directory and file listing (eight packs); `vectors.json` fields read when the fingerprint check runs |
|
||||
| Devnet 3 pack `program.json` on build box 1 | the first 40 lines (id, attempt, seed, class, mixer text) |
|
||||
| `tools/attack/f4-weakday/{Cargo.toml,src/main.rs}` from `build/attack-pass` | Cargo.toml in full; main.rs the header and first 80 lines (the crate layout, the day rule) |
|
||||
| `tools/attack/f8-uniform/{Cargo.toml,src/main.rs}` from the attack-regate worktree | Cargo.toml in full; main.rs lines 1 to 260 (the crate layout, the log macro, the traced derivation, the histogram statistics) |
|
||||
| `tools/build-remote.sh`, `infra/build-server/lib.sh`, `infra/build-server/remote-run.sh`, `tools/ci/export-exclude.txt` | in full (the box routing, the bounded class, the source overlay with `--delete` and its target-dir excludes, the slot files) |
|
||||
| `/srv/builds/_adv/cache/queue/90-adv-cache-3-chain-skip-search.sh`, `91-adv-cache-3-feedforward-relations.sh`, `92-adv-cache-3-pebbling-curve.sh` on build box 2 | in full (the definitions); the queue and claims directory listings |
|
||||
| Sibling lanes on the build mirror | `build/adv-cache:docs/plans/cryptanalysis/plan-chained-cache.md` and `docs/analysis/cryptanalysis/report-chained-cache.md` in full; `build/adv-cache-2:docs/plans/cryptanalysis/plan-chained-cache-2.md` in full; the file lists of the mixer and accept lanes' `cryptanalysis/` directories (not read) |
|
||||
|
||||
Not opened: anything else under `docs/`, `site/`, `proto-metal/`, `git log`, commit messages, other branches or worktrees. The `memhard.rs` doc comments point at `docs/plans/mixer-x4.md`, `hot-table.md`, `era-layout.md` and `MEMHARD.md`: not followed. The spec points at `MEMHARD.md` and several analyses: not followed. The repository's `CLAUDE.md` pointers were not followed. Sibling log directories on the boxes were listed by name while locating the queue; no sibling log was opened.
|
||||
|
||||
## 1. The target, restated from the spec and the code
|
||||
|
||||
Spec 1.8.3 and `memhard.rs` `fill_segment_tagged`: the cache is 2^26 words = 2^22 lines of 16 words in 2^16 segments of 64 lines. Segment `s`, line `j`:
|
||||
|
||||
```
|
||||
c_j = (sigma[0..3] || K[0..7] || s || j || tag[0..1]) 16 words, all public once the day is known
|
||||
x_0 = c_0 prev_0 = 0
|
||||
x_j = line_{j-1} XOR c_j j >= 1
|
||||
line_j = B(x_j) = C(x_j) + x_j C = the 12-round ChaCha permutation (6 double rounds), + word-wise mod 2^32
|
||||
```
|
||||
|
||||
The block layout of `x_j` by word index: 0 to 3 sigma (constants), 4 to 11 `K[0..7]` (the day key, public), 12 `s` (16 significant bits), 13 `j` (6 significant bits), 14 and 15 the tag (constants); every word is XORed with `line_{j-1}`. For `j = 0` all 16 words are known. For `j >= 1` no word of `x_j` is known without `line_{j-1}`, since the XOR spreads the previous line over every word. The day key is `K = seed_words_from_bytes("igneum-day/" || d_le64)` (`bind::day_bytes`). Line `j` costs `j + 1` block evaluations from nothing; one block is 6 x 8 x 12 + 16 + 16 = 608 integer operations as written. The 2^16 segments share nothing but `K`.
|
||||
|
||||
Spec 1.8.5 under class v4 (`mixer_mult = 8`): an item is 72 mixer applications and 8 dependent line reads at `a = s[0] AND 0x3fffff`, about 9,360 operations (`chip-model-v3.md` 5.2). A recompute chip that does not hold line `(s, j)` pays `j + 1` blocks of 608 operations, 32.5 blocks on average: 19,760 operations, 2.1x the item. The chip model's SRAM column (128 mm^2, $46 for 256 MiB at N5) and the partial-store curve of 5.4 rest on that price. A chain break or skip is anything that lowers it.
|
||||
|
||||
## 2. The questions, in attack order
|
||||
|
||||
Harness crate `attack-adv-cache-3`, binary `adv-cache-3`, one subcommand per row, `igneum-pow` by path. The real `B` is the library's `chacha_block`; the chain is restated in the harness and checked against `Cache::fill_segment` word for word on every run. The vectors are the kit's day-20730 cache fingerprint and the Devnet 3 day-20733 fingerprint, read from the packs' `vectors.json`. A reduced block `B(w, r)` (16 words of `w` bits, `r` double rounds, the ChaCha rotations reduced mod `w` and floored at 1, the same chaining and the same word layout truncated to `w` bits) is the small-scale model. Every claim on the model is cross-checked on the real `B` on a few segments.
|
||||
|
||||
| # | Question (brief letter; queue file) | Method | Command | Known-failed shape (must fire before the real run counts) | Gate | Box-hours |
|
||||
|---|---|---|---|---|---|---|
|
||||
| Q1 | (a; 90) Line `(s, j)` in fewer than `j + 1` blocks without an earlier line | (1) Template skip search: for every `j` in 0..63 and 1,024 segments on 2 day keys, every earlier-line-free formula of a template set is evaluated and compared with the real line: `B(c_j)`, `B(c_j XOR c_i)` for `i < j`, `B(c_j) XOR B(c_i)`, `B(c_j) XOR c_i`, `B(B(c_j))`, `B(c_j) + c_i`, and the inverse direction `Cinv(line_j) XOR c_j = line_{j-1}` (a shortcut up the chain). A match is a derivation in 1 or 2 blocks. (2) The GF(2) affine-relation search: over 4,096 samples of `(x_j, line_j)` the 1,025-column bit matrix (512 input bits, 512 output bits, the constant) must have rank 1,025; a deficiency is an affine relation and a skip. The same on `(line_{j-1}, line_j)` across the real chain. (3) Dependence: for each of the 512 bits of `x_j` the flip probability of each bit of `line_j` (a 512 x 512 table over 2^12 lines) and the 16 x 16 word table; a zero cell means a line independent of part of its input. (4) Exhaustive at small scale: `B(4, 2)` with all 2^16 segments and a 16-line chain for (1) to (3); `B(2, r)` with a 32-bit state and every one of the 2^32 inputs enumerated: the image size of one block (how far `B` is from a permutation) and of the `k`-fold chain for `k` up to 64 (entropy lost down the chain), against the random-function expectation `2N / k` | `adv-cache-3 skip --day 20730 --segments 1024`, `--day 20733`; `adv-cache-3 skip --w 4 --rounds 2 --segments 65536 --lines 16`; `adv-cache-3 image --w 2 --rounds 6` | `--plant no-xor` (prev not XORed in): the template `B(c_j)` must match every line at 1 block and the dependence table must read 0. `--plant no-feedforward` (`B = C`): the inverse template must recover `line_{j-1}` from `line_j` on every line, and at w = 2 the image must be all 2^32 states (a permutation). `--rounds 1` on the rank test: a one-double-round `C` has affine output bits (bit 0 of an add is an XOR) and the rank must fall under 1,025 | 0 lines under `j + 1` blocks on the real chain at 64 lines and 1,024 segments, and on the model at 16 lines and 65,536 segments; rank 1,025 at every `j` tested; every flip cell within 6 sigma of 0.5; every plant fires | 0.3 (the w = 2 image census is 64 x 2^32 block evaluations on a 32-bit state, about 10 minutes on 88 cores; the rest seconds) |
|
||||
| Q2 | (b, c; 91) Relations through `line_j = C(x_j) + x_j` and partial knowledge | Over 2^20 lines per day key (2^14 segments x 64 lines) on 4 day keys (20730 to 20733), `j >= 1`: (1) per-bit bias of `line_j XOR x_j`, `line_j - x_j` (that is `C(x_j)`), `line_j XOR line_{j-1}` and `line_j - line_{j-1}`, 512 bits each, in sigma against 1/2; (2) the 512 x 512 linear-correlation table between bits of `x_j` and bits of `line_j` (the bias of `x[a] XOR line[b]`), the largest cell in sigma; the same between `line_{j-1}` and `line_j`; (3) partial knowledge: the word-level dependence table of Q1 (3) read as "given `k` words of `line_{j-1}`, how many words of `line_j` are determined" (a word is computable from a subset of input words only if it is insensitive to the rest), and the reverse, what of `x_j` is determined by `line_j`: the correlation table read column-wise, plus a fixed-point inversion attempt `x <- Cinv(y - x)` from `x = 0`, 64 steps, on 2^16 lines, counting convergences | `adv-cache-3 relations --day0 20730 --days 4 --lines-log2 20 --threads 88`; `adv-cache-3 partial --day 20730 --lines-log2 16` | `--rounds 1` (one double round; the queue file's "2 rounds"): the correlation table must show cells far beyond 6 sigma where the 12-round table shows none; `--plant no-feedforward`: the inversion must converge on every line | every bias and every correlation cell within 6 sigma of uniform at 2^22 samples; no word of `line_j` computable from fewer than 16 words of `x_j`; 0 inversions converge; the plants fire | 0.5 (2^22 lines x 512 x 512 bit correlations by popcount, about 2 x 10^12 bit operations, minutes on 88 cores) |
|
||||
| Q3 | (d; 92) The 64-line chain and the 2^16 independent segments under a parallel amortising adversary: the pebbling curve | Exact arithmetic and simulation on the chain as a graph. (1) The static pebbling optimum: for `k` held lines of 64 (`f = k / 64`), the expected blocks per uniform read for the best placement, by dynamic programming on the path (exact), against the honest hold-every-`(64 / k)`-th-line placement, for `f = 1/64, 2/64, 4/64, 8/64, 16/64, 32/64, 1`; exhaustive over every subset of held lines at 10 to 16 lines to check the DP. (2) The amortising adversary: `m` requests per segment in flight (the 2^16 segments are independent, so amortisation is only within a segment), one walk per segment from the nearest held line to the deepest request; blocks per read by exact combinatorics over uniform requests and by Monte Carlo, for `m = 1, 2, 4, ..., 64` at each `f`; the cross-check is sibling adv-cache's real-address batch rows (23.84 at m = 1, 7.06 at m = 8, 0.99 at m = 64 with nothing held). (3) Ops per item at each point: `72 x 128 + 144 + 8 x blocks x 608`, against 9,360 at `f = 1`, with the SRAM held (`f` x 128 mm^2) beside it | `adv-cache-3 pebble --lines 64 --exhaustive-upto 16 --mc 1000000` | `--plant skip-edge 8` (every line `j` also derivable from line `j - 8` in one block): the optimal cost at `f = 1/64` must fall under the path's | the curve is monotone in `f` and never below the honest hold-every-`k`-th curve at the same `f`; `f = 1` reads 9,360 ops per item; the plant fires | 0.1 |
|
||||
| Q4 | (e) Anything else | (1) Cross-segment relation: the 512 x 512 correlation table between `line_j(s)` and `line_j(s XOR 2^b)` at `j` in {0, 1, 63}, the one-word-difference multi-target at `j = 0` included. (2) Cross-day relation: the same table between `line_j` of day `d` and of day `d + 1` for the same `(s, j)`. (3) The known-constant words: the count of input words of `x_j` with a known value for `j = 0` (16) and `j >= 1` (0), stated from the code | `adv-cache-3 cross --day 20730 --segments 4096` | `--plant no-xor`: at `j >= 1` lines of adjacent segments differ in word 12 only before the block, so a reduced-round `C` must show cross-segment correlation | every cell within 6 sigma; the plant fires | 0.1 |
|
||||
|
||||
Total estimate: about 1.0 box-hours of the 8 budgeted (the ask line is 16). Memory per run: under 1 GiB (the w = 2 image census holds a 2^32-bit bitmap, 512 MiB; the correlation tables are 512 x 512 u64, 2 MiB each).
|
||||
|
||||
## 3. Running rules followed
|
||||
|
||||
- No cargo on the Mac. Builds through `tools/build-remote.sh --box 1|2 -- build --release` from `tools/attack/adv-cache-3/`; the binary is copied to `/srv/builds/_adv-cache-3/bin/` on the box that runs it and its sha256 recorded in the report.
|
||||
- Runs over 10 minutes start on the box from `tools/attack/adv-cache-3/run-box.sh`: `nohup nice -n 10 taskset -c 8-95 <bin> <args> > <log> 2>&1 &` with a pid file beside the log under `/srv/builds/_adv-cache-3/`. No SIGSTOP yield. Kill by pid file only. Cores 0 to 7 never used. No GPU row exists in this lane.
|
||||
- The queue: files 90, 91, 92 on build box 2 are claimed with `mkdir /srv/builds/_adv/cache/claims/<file>` before they run; every further sweep is written as `/srv/builds/_adv/cache/queue/NN-adv-cache-3-<name>.sh` (self-contained) and claimed the same way. When this lane's queue is empty, the next unclaimed sibling file in name order is claimed and run, the owner named in the report.
|
||||
- Box-hours: 8 is a reading, 16 the ask line.
|
||||
- Pushes only to `build adv-cache-3`; `origin` never touched; every other branch read-only. Commits as igneum-labs.
|
||||
- No secrets, keys or host lines in any document. Every time quoted is current UK time (BST), checked with `TZ=Europe/London date`.
|
||||
|
||||
## 4. Order of work and clock (BST, 7 to 8 October 2026)
|
||||
|
||||
| Step | What | When |
|
||||
|---|---|---|
|
||||
| 1 | This plan committed and pushed | by 20:10 |
|
||||
| 2 | Harness crate written, built on a box; the fingerprint checks; every plant fired and logged | 20:10 to 21:30 |
|
||||
| 3 | Q1 skip, rank, dependence; Q3 pebble (seconds each); the w = 2 image census and Q2 relations queued back to back | 21:30 to 23:00 |
|
||||
| 4 | Q4 cross; the report with first rows pushed | by 00:00 |
|
||||
| 5 | Sibling queue files, if any are unclaimed; the report updated as rows land | from 00:00 |
|
||||
|
||||
## 5. What a result is
|
||||
|
||||
A BREAK is a method with a counted gain (a line at fewer than `j + 1` blocks, or a pebbling point under the honest curve at the same `f`), reproducible from the command and the seed in the report. A BOUND is what was searched, with which tool, how far (segments, lines, day keys, samples) and the margin (sigma, or the rank margin). "Nothing found" counts only with its effort stated.
|
||||
14
tools/attack/adv-cache-3/Cargo.lock
generated
Normal file
14
tools/attack/adv-cache-3/Cargo.lock
generated
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
# This file is automatically @generated by Cargo.
|
||||
# It is not intended for manual editing.
|
||||
version = 4
|
||||
|
||||
[[package]]
|
||||
name = "attack-adv-cache-3"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"igneum-pow",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "igneum-pow"
|
||||
version = "0.2.0"
|
||||
21
tools/attack/adv-cache-3/Cargo.toml
Normal file
21
tools/attack/adv-cache-3/Cargo.toml
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
[package]
|
||||
name = "attack-adv-cache-3"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
description = "Adversarial lane adv-cache-3: the chain break or skip of the memory-hard cache (template skip search, GF(2) rank, dependence, feed-forward relations, exhaustive image census at small word size, the pebbling curve); igneum-pow by path, nothing re-implemented but the restated chain, which is checked against the library"
|
||||
license = "MIT"
|
||||
publish = false
|
||||
|
||||
[[bin]]
|
||||
name = "adv-cache-3"
|
||||
path = "src/main.rs"
|
||||
|
||||
[dependencies]
|
||||
igneum-pow = { path = "../../../igneum-pow" }
|
||||
|
||||
[workspace]
|
||||
|
||||
[profile.release]
|
||||
opt-level = 3
|
||||
lto = true
|
||||
codegen-units = 1
|
||||
24
tools/attack/adv-cache-3/queue/93-adv-cache-3-skip-batch.sh
Executable file
24
tools/attack/adv-cache-3/queue/93-adv-cache-3-skip-batch.sh
Executable file
|
|
@ -0,0 +1,24 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-cache-3 (owner), queue 90's implementation plus the pebble (92) and cross rows: the quick batch, seconds each.
|
||||
# Runs ON build box 1 through the lease pool. Binary /srv/builds/_adv-cache-3/bin/adv-cache-3 (sha in the report).
|
||||
set -u
|
||||
BIN=/srv/builds/_adv-cache-3/bin/adv-cache-3; D=/srv/builds/_adv-cache-3/logs; mkdir -p $D
|
||||
T=${THREADS:-48}
|
||||
# main's rule of 20:1x BST, 7 October 2026: every sweep starts through the build-server lane's lease pool, never by hand
|
||||
run() { tag=$1; shift; echo "$(date -u +%FT%TZ) start $tag" >> $D/ledger.txt; /srv/builds/_bin/lease pool $T --min 16 --label "adv-cache-3 $tag" --owner adv-cache-3 -- $BIN "$@" > $D/$tag.log 2>&1; rc=$?; echo "$(date -u +%FT%TZ) end $tag rc=$rc" >> $D/ledger.txt; echo "$tag rc=$rc"; }
|
||||
echo $$ > $D/skip-batch.pid
|
||||
run skip-d20730 skip --day 20730 --segments 1024 --threads {cores}
|
||||
run skip-d20733 skip --day 20733 --segments 1024 --threads {cores}
|
||||
run skip-plant-noxor skip --day 20730 --segments 1024 --plant no-xor --threads {cores}
|
||||
run skip-plant-noff skip --day 20730 --segments 1024 --plant no-feedforward --threads {cores}
|
||||
run skip-rounds0 skip --day 20730 --segments 256 --rounds 0 --threads {cores}
|
||||
run skip-rounds1 skip --day 20730 --segments 256 --rounds 1 --threads {cores}
|
||||
run skip-rounds2 skip --day 20730 --segments 256 --rounds 2 --threads {cores}
|
||||
run skip-w4-r2 skip --day 20730 --segments 65536 --lines 16 --w 4 --rounds 2 --threads {cores}
|
||||
run skip-w4-r2-plant-noxor skip --day 20730 --segments 4096 --lines 16 --w 4 --rounds 2 --plant no-xor --threads {cores}
|
||||
run skip-w4-r2-plant-noff skip --day 20730 --segments 4096 --lines 16 --w 4 --rounds 2 --plant no-feedforward --threads {cores}
|
||||
run pebble pebble --lines 64 --exhaustive-upto 16 --mc 1000000
|
||||
run pebble-plant-skip8 pebble --lines 64 --exhaustive-upto 12 --mc 200000 --skip-edge 8
|
||||
run cross-d20730 cross --day 20730 --segments 4096 --threads {cores}
|
||||
run cross-plant-noxor-r1 cross --day 20730 --segments 4096 --plant no-xor --rounds 1 --threads {cores}
|
||||
echo "skip-batch done $(date -u +%FT%TZ)"
|
||||
14
tools/attack/adv-cache-3/queue/94-adv-cache-3-relations.sh
Executable file
14
tools/attack/adv-cache-3/queue/94-adv-cache-3-relations.sh
Executable file
|
|
@ -0,0 +1,14 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-cache-3 (owner), queue 91's implementation: feed-forward relations, 4 day keys x 2^20 lines, the 512 x 512 correlation
|
||||
# table, plus the reduced-C plant (one double round) and the no-feedforward inversion plant. Runs ON build box 1.
|
||||
set -u
|
||||
BIN=/srv/builds/_adv-cache-3/bin/adv-cache-3; D=/srv/builds/_adv-cache-3/logs; mkdir -p $D
|
||||
T=${THREADS:-48}
|
||||
# main's rule of 20:1x BST, 7 October 2026: every sweep starts through the build-server lane's lease pool, never by hand
|
||||
run() { tag=$1; shift; echo "$(date -u +%FT%TZ) start $tag" >> $D/ledger.txt; /srv/builds/_bin/lease pool $T --min 16 --label "adv-cache-3 $tag" --owner adv-cache-3 -- $BIN "$@" > $D/$tag.log 2>&1; rc=$?; echo "$(date -u +%FT%TZ) end $tag rc=$rc" >> $D/ledger.txt; echo "$tag rc=$rc"; }
|
||||
echo $$ > $D/relations-batch.pid
|
||||
run relations-4d-l20 relations --day0 20730 --days 4 --lines-log2 20 --threads {cores}
|
||||
run relations-plant-r1 relations --day0 20730 --days 1 --lines-log2 16 --rounds 1 --threads {cores}
|
||||
run relations-plant-r2 relations --day0 20730 --days 1 --lines-log2 16 --rounds 2 --threads {cores}
|
||||
run relations-r3 relations --day0 20730 --days 1 --lines-log2 18 --rounds 3 --threads {cores}
|
||||
echo "relations-batch done $(date -u +%FT%TZ)"
|
||||
12
tools/attack/adv-cache-3/queue/95-adv-cache-3-image-w2.sh
Executable file
12
tools/attack/adv-cache-3/queue/95-adv-cache-3-image-w2.sh
Executable file
|
|
@ -0,0 +1,12 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-cache-3 (owner), queue 90 (4): the exhaustive image census at w = 2 (every one of 2^32 states per step), depth 64,
|
||||
# and the no-feedforward plant (a permutation: the image must stay 2^32) at depth 6. Runs ON build box 2.
|
||||
set -u
|
||||
BIN=/srv/builds/_adv-cache-3/bin/adv-cache-3; D=/srv/builds/_adv-cache-3/logs; mkdir -p $D
|
||||
T=${THREADS:-48}
|
||||
# main's rule of 20:1x BST, 7 October 2026: every sweep starts through the build-server lane's lease pool, never by hand
|
||||
run() { tag=$1; shift; echo "$(date -u +%FT%TZ) start $tag" >> $D/ledger.txt; /srv/builds/_bin/lease pool $T --min 16 --label "adv-cache-3 $tag" --owner adv-cache-3 -- $BIN "$@" > $D/$tag.log 2>&1; rc=$?; echo "$(date -u +%FT%TZ) end $tag rc=$rc" >> $D/ledger.txt; echo "$tag rc=$rc"; }
|
||||
echo $$ > $D/image-batch.pid
|
||||
run image-w2-r6-d64 image --w 2 --rounds 6 --depth 64 --threads {cores}
|
||||
run image-w2-plant-noff image --w 2 --rounds 6 --depth 6 --plant no-feedforward --threads {cores}
|
||||
echo "image-batch done $(date -u +%FT%TZ)"
|
||||
14
tools/attack/adv-cache-3/queue/96-adv-cache-3-skip-1024.sh
Executable file
14
tools/attack/adv-cache-3/queue/96-adv-cache-3-skip-1024.sh
Executable file
|
|
@ -0,0 +1,14 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-cache-3 (owner), queue 90's gate wording "at 64 and 1,024 lines": the chain extended to 1,024 lines (j up to 1,023, the
|
||||
# same layout, the same B) on 64 segments of 2 day keys, plus the two plants at 1,024 lines. Runs ON build box 1.
|
||||
set -u
|
||||
BIN=/srv/builds/_adv-cache-3/bin/adv-cache-3; D=/srv/builds/_adv-cache-3/logs; mkdir -p $D
|
||||
T=${THREADS:-48}
|
||||
# main's rule of 20:1x BST, 7 October 2026: every sweep starts through the build-server lane's lease pool, never by hand
|
||||
run() { tag=$1; shift; echo "$(date -u +%FT%TZ) start $tag" >> $D/ledger.txt; /srv/builds/_bin/lease pool $T --min 16 --label "adv-cache-3 $tag" --owner adv-cache-3 -- $BIN "$@" > $D/$tag.log 2>&1; rc=$?; echo "$(date -u +%FT%TZ) end $tag rc=$rc" >> $D/ledger.txt; echo "$tag rc=$rc"; }
|
||||
echo $$ > $D/skip1024-batch.pid
|
||||
run skip-1024-d20730 skip --day 20730 --segments 64 --lines 1024 --threads {cores}
|
||||
run skip-1024-d20733 skip --day 20733 --segments 64 --lines 1024 --threads {cores}
|
||||
run skip-1024-plant-noxor skip --day 20730 --segments 16 --lines 1024 --plant no-xor --threads {cores}
|
||||
run skip-1024-plant-noff skip --day 20730 --segments 16 --lines 1024 --plant no-feedforward --threads {cores}
|
||||
echo "skip1024-batch done $(date -u +%FT%TZ)"
|
||||
13
tools/attack/adv-cache-3/queue/97-adv-cache-3-image-w2-resume.sh
Executable file
13
tools/attack/adv-cache-3/queue/97-adv-cache-3-image-w2-resume.sh
Executable file
|
|
@ -0,0 +1,13 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-cache-3 (owner): the w = 2 exhaustive image census again in full (the 20:22 BST run was released at depth 8 by main's
|
||||
# order for the class v5 gate). 48 cores at most, --min 16; started only when `lease status` shows no "v5 gate" or "v5 kit"
|
||||
# waiter (main, 20:2x BST). Runs ON build box 2.
|
||||
set -u
|
||||
BIN=/srv/builds/_adv-cache-3/bin/adv-cache-3; D=/srv/builds/_adv-cache-3/logs; mkdir -p $D
|
||||
T=${THREADS:-32}
|
||||
echo $$ > $D/image2-batch.pid
|
||||
yield_v5() { while /srv/builds/_bin/lease status 2>/dev/null | sed -n "/^waiting:/,\$p" | grep -E "owner=class-v5|v5.*owner=attack-pass" | grep -vq "owner=adv-"; do sleep 30; done; }
|
||||
run() { tag=$1; shift; yield_v5; echo "$(date -u +%FT%TZ) start $tag" >> $D/ledger.txt; /srv/builds/_bin/lease pool $T --min 16 --label "adv-cache-3 $tag" --owner adv-cache-3 -- $BIN "$@" > $D/$tag.log 2>&1; rc=$?; echo "$(date -u +%FT%TZ) end $tag rc=$rc" >> $D/ledger.txt; echo "$tag rc=$rc"; }
|
||||
run image-w2-r6-d64-full image --w 2 --rounds 6 --depth 64 --threads {cores}
|
||||
run image-w2-plant-noff image --w 2 --rounds 6 --depth 6 --plant no-feedforward --threads {cores}
|
||||
echo "image2-batch done $(date -u +%FT%TZ)"
|
||||
15
tools/attack/adv-cache-3/queue/98-adv-cache-3-flip-ladder.sh
Executable file
15
tools/attack/adv-cache-3/queue/98-adv-cache-3-flip-ladder.sh
Executable file
|
|
@ -0,0 +1,15 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-cache-3 (owner): the reduced-round flip-table ladder at 2^18 lines (a flip bias of 2^-8.5 at 6 sigma), rounds 2, 3, 4 and
|
||||
# the real 6, to put a number on where the single-bit statistics stop (report section 2's caveat). Binary with --dep-samples.
|
||||
# 48 cores at most, --min 16, yields to any waiter with owner class-v5 or a "v5" label (main, 20:3x BST). Runs ON build box 1.
|
||||
set -u
|
||||
BIN=/srv/builds/_adv-cache-3/bin/adv-cache-3-dep; D=/srv/builds/_adv-cache-3/logs; mkdir -p $D
|
||||
T=${THREADS:-32}
|
||||
yield_v5() { while /srv/builds/_bin/lease status 2>/dev/null | sed -n "/^waiting:/,\$p" | grep -E "owner=class-v5|v5.*owner=attack-pass" | grep -vq "owner=adv-"; do sleep 30; done; }
|
||||
run() { tag=$1; shift; yield_v5; echo "$(date -u +%FT%TZ) start $tag" >> $D/ledger.txt; /srv/builds/_bin/lease pool $T --min 16 --label "adv-cache-3 $tag" --owner adv-cache-3 -- $BIN "$@" > $D/$tag.log 2>&1; rc=$?; echo "$(date -u +%FT%TZ) end $tag rc=$rc" >> $D/ledger.txt; echo "$tag rc=$rc"; }
|
||||
echo $$ > $D/flip-batch.pid
|
||||
run flip-r2-2e18 skip --day 20730 --segments 4160 --rounds 2 --dep-samples 262144 --threads {cores}
|
||||
run flip-r3-2e18 skip --day 20730 --segments 4160 --rounds 3 --dep-samples 262144 --threads {cores}
|
||||
run flip-r4-2e18 skip --day 20730 --segments 4160 --rounds 4 --dep-samples 262144 --threads {cores}
|
||||
run flip-r6-2e18 skip --day 20730 --segments 4160 --rounds 6 --dep-samples 262144 --threads {cores}
|
||||
echo "flip-batch done $(date -u +%FT%TZ)"
|
||||
19
tools/attack/adv-cache-3/run-box.sh
Executable file
19
tools/attack/adv-cache-3/run-box.sh
Executable file
|
|
@ -0,0 +1,19 @@
|
|||
#!/usr/bin/env bash
|
||||
# Start one adv-cache-3 sweep on a build box (run ON the box). Internal adversarial pass, not an independent review.
|
||||
# run-box.sh <tag> <args...> (THREADS=N caps the pool ask; default 32, the ceiling an adv holder keeps)
|
||||
# The binary is /srv/builds/_adv-cache-3/bin/adv-cache-3 (copied there after tools/build-remote.sh). The log and pid file
|
||||
# live under /srv/builds/_adv-cache-3/logs/<tag>.log{,.pid}, outside the worktree mirror, which build-remote.sh's source
|
||||
# sync would wipe. Every sweep starts through the build-server lane's ranked lease (main, 7 October 2026, 20:1x and 20:40
|
||||
# BST: `lease pool`, class adv, holders above 32 threads are pre-empted), pinned by the lease to the cores it took, at
|
||||
# nice 10, never on cores 0 to 7; "{cores}" in the arguments becomes the count taken. No `-c` string, no inline rm
|
||||
# (main, 21:33 BST). Kill by pid file only: kill $(cat <pid>).
|
||||
set -euo pipefail
|
||||
tag="$1"; shift
|
||||
BIN=/srv/builds/_adv-cache-3/bin/adv-cache-3
|
||||
DIR=/srv/builds/_adv-cache-3/logs
|
||||
T="${THREADS:-32}"
|
||||
mkdir -p "$DIR"
|
||||
log="$DIR/$tag.log"
|
||||
nohup /srv/builds/_bin/lease pool "$T" --min 16 --label "adv-cache-3 $tag" --owner adv-cache-3 -- "$BIN" "$@" >> "$log" 2>&1 &
|
||||
echo $! > "$log.pid"
|
||||
echo "started $tag pid $(cat "$log.pid") log $log (waits in the lease queue while fewer than 16 pool cores are free)"
|
||||
1258
tools/attack/adv-cache-3/src/main.rs
Normal file
1258
tools/attack/adv-cache-3/src/main.rs
Normal file
File diff suppressed because it is too large
Load diff
|
|
@ -15,3 +15,7 @@ docs/analysis/ci-failures-2026-10-06.md
|
|||
# 7 October 2026: the last research round (the mission lanes and the closed list): internal research written for the
|
||||
# owner, quoting his words and the operations record; the public spec mirror carries none of it
|
||||
docs/analysis/mission
|
||||
# 7 October 2026: the adversarial lanes (internal adversarial pass, not an independent review): plans and reports written for the
|
||||
# team, naming box paths and operations; the public spec mirror carries none of it
|
||||
docs/plans/cryptanalysis
|
||||
docs/analysis/cryptanalysis
|
||||
|
|
|
|||
Loading…
Reference in a new issue