Compare commits
24 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7d76d9a08b | ||
|
|
16728d3171 | ||
|
|
03569a2144 | ||
|
|
e38edec586 | ||
|
|
0c7fe45e44 | ||
|
|
9a7b70f5db | ||
|
|
c043ca3adf | ||
|
|
56a0bb50e4 | ||
|
|
77a97e3252 | ||
|
|
cb04d9eaba | ||
|
|
fbb24413c3 | ||
|
|
cd7ab85456 | ||
|
|
76682349d0 | ||
|
|
30b24efbe5 | ||
|
|
d10eee9f34 | ||
|
|
1662a76082 | ||
|
|
a26e52c3dd | ||
|
|
06f1382f3e | ||
|
|
996d0ad353 | ||
|
|
e3fbe5176d | ||
|
|
29a03a0d74 | ||
|
|
5bddb289c3 | ||
|
|
029e5219d6 | ||
|
|
6033df803c |
50 changed files with 6632 additions and 0 deletions
389
docs/analysis/cryptanalysis/logs/adv-mixer/census-2pow24.log
Normal file
389
docs/analysis/cryptanalysis/logs/adv-mixer/census-2pow24.log
Normal file
|
|
@ -0,0 +1,389 @@
|
|||
# attack-f4 census: 16777216 chain days from day index 20729 (genesis 20729), class v4 shape (mixer x8, cache 2^26), 32 threads, 4.4 s
|
||||
draw: MixParams::with_shape(seed_words_from_bytes(bind::day_bytes(d)), Shape::for_class(&V4_CLASS)); seed64 = key[0] | key[1] << 32
|
||||
|
||||
## Gate (plan 1.4 (3), B5 rank 3): fraction of days with any gain over 1.1x under 2^-20 = 9.537e-7
|
||||
|
||||
| Metric | Reference | Days over 1.1x | Fraction | Against 2^-20 |
|
||||
|---|---|---|---|---|
|
||||
| M1 per-day LUT datapath, adders per application | median cost 231 (gain over 1.1x = cost under 210) | 5476 | 3.264e-4 | OVER |
|
||||
| M1 against the mean cost 231.11 (sd 6.19) | cost under 210.10 | 9363 | 5.581e-4 | OVER |
|
||||
| M2 DSP-bound datapath, 16/(16-k) with k = words of NAF weight <= 3 | k >= 2 | 0 | 0.000e0 | under |
|
||||
| ROT value (wiring) and RC value (inverters) on a per-day datapath | exact 0 ops moved on every day | 0 | 0 | under |
|
||||
|
||||
M1 cost = 64 + sum(NAF(MUL_i) - 1); mean 231.113, sd 6.190, median 231, min 197 (day 4819563), max 263 (day 15262713)
|
||||
|
||||
## Classes over 16777216 days
|
||||
|
||||
| Class | Count | Fraction | Expected per day (analytic) | Expected count | Worst member (day, M1 cost, M1 gain vs median, M2 gain) |
|
||||
|---|---|---|---|---|---|
|
||||
| ROT all equal | 0 | 0.000e0 | 3.635e-11 (1 in 2.751e10) | 0.001 | none |
|
||||
| ROT distinct <= 3 | 534 | 3.183e-5 | 3.069e-5 (1 in 3.259e4) | 514.813 | day 11482247 , cost 208 , 1.1106x , 1.000x |
|
||||
| ROT distinct <= 4 | 26010 | 1.550e-3 | 1.537e-3 (1 in 6.507e2) | 25782.741 | day 1092491 , cost 207 , 1.1159x , 1.000x |
|
||||
| ROT max multiplicity >= 4 | 35631 | 2.124e-3 | 2.350e-3 (1 in 4.256e2) | 39421.474 | day 9506389 , cost 206 , 1.1214x , 1.000x |
|
||||
| ROT same-word pair sums to 32 | 2062481 | 1.229e-1 | 1.229e-1 (1 in 8.135e0) | 2062288.067 | day 3675001 , cost 201 , 1.1493x , 1.000x |
|
||||
| ROT any pair sums to 32 | 10022037 | 5.974e-1 | 6.007e-1 (1 in 1.665e0) | 10078561.158 | day 4819563 , cost 197 , 1.1726x , 1.000x |
|
||||
| ROT all 8 in {1,2,30,31} | 2 | 1.192e-7 | 7.684e-8 (1 in 1.301e7) | 1.289 | day 14330190 , cost 217 , 1.0645x , 1.000x |
|
||||
| ROT >= 6 in {1,2,30,31} | 1761 | 1.050e-4 | 1.023e-4 (1 in 9.780e3) | 1715.548 | day 155537 , cost 212 , 1.0896x , 1.000x |
|
||||
| ROT >= 4 in {1,2,30,31} | 211152 | 1.259e-2 | 1.259e-2 (1 in 7.942e1) | 211253.447 | day 12915578 , cost 198 , 1.1667x , 1.000x |
|
||||
| ROT >= 4 in {8,16,24} | 74541 | 4.443e-3 | 4.456e-3 (1 in 2.244e2) | 74756.114 | day 5517722 , cost 198 , 1.1667x , 1.000x |
|
||||
| MUL any = 1 | 0 | 0.000e0 | 7.451e-9 (1 in 1.342e8) | 0.125 | none |
|
||||
| MUL any = 2^32-1 | 0 | 0.000e0 | 7.451e-9 (1 in 1.342e8) | 0.125 | none |
|
||||
| MUL any popcount <= 2 | 0 | 0.000e0 | 2.384e-7 (1 in 4.194e6) | 4.000 | none |
|
||||
| MUL any popcount <= 4 | 612 | 3.648e-5 | 3.719e-5 (1 in 2.689e4) | 623.989 | day 7275755 , cost 200 , 1.1550x , 1.000x |
|
||||
| MUL any popcount <= 8 | 441646 | 2.632e-2 | 2.629e-2 (1 in 3.804e1) | 441000.196 | day 12915578 , cost 198 , 1.1667x , 1.000x |
|
||||
| MUL any NAF weight <= 2 | 4 | 2.384e-7 | see `expect` | see `expect` | day 7786546 , cost 221 , 1.0452x , 1.067x |
|
||||
| MUL any NAF weight <= 3 | 216 | 1.287e-5 | see `expect` | see `expect` | day 332924 , cost 207 , 1.1159x , 1.067x |
|
||||
| MUL any NAF weight <= 4 | 3637 | 2.168e-4 | see `expect` | see `expect` | day 7275755 , cost 200 , 1.1550x , 1.000x |
|
||||
| MUL any < 256 | 22 | 1.311e-6 | 9.537e-7 (1 in 1.049e6) | 16.000 | day 14317428 , cost 216 , 1.0694x , 1.000x |
|
||||
| MUL two equal | 0 | 0.000e0 | 5.588e-8 (1 in 1.790e7) | 0.937 | none |
|
||||
| MUL M2 k >= 2 (gain >= 1.14x) | 0 | 0.000e0 | see `expect` | see `expect` | none |
|
||||
| RC any = 0 | 0 | 0.000e0 | 3.725e-9 (1 in 2.684e8) | 0.062 | none |
|
||||
| RC any popcount <= 4 or >= 28 | 5186 | 3.091e-4 | 3.088e-4 (1 in 3.239e3) | 5180.375 | day 7999545 , cost 208 , 1.1106x , 1.000x |
|
||||
| RC + rk = 0 for any of the 72 keys | 10 | 5.960e-7 | 2.682e-7 (1 in 3.728e6) | 4.500 | day 3194363 , cost 218 , 1.0596x , 1.000x |
|
||||
| RC two equal | 1 | 5.960e-8 | 2.794e-8 (1 in 3.579e7) | 0.469 | day 2875598 , cost 226 , 1.0221x , 1.000x |
|
||||
|
||||
## Histograms
|
||||
|
||||
| ROT distinct amounts | Count | Fraction | Expected (S(8,d) 31_d / 31^8) |
|
||||
|---|---|---|---|
|
||||
| 1 | 0 | 0.0000e0 | 3.6347e-11 |
|
||||
| 2 | 4 | 2.3842e-7 | 1.3848e-7 |
|
||||
| 3 | 530 | 3.1590e-5 | 3.0547e-5 |
|
||||
| 4 | 25476 | 1.5185e-3 | 1.5061e-3 |
|
||||
| 5 | 421405 | 2.5118e-2 | 2.5101e-2 |
|
||||
| 6 | 2773843 | 1.6533e-1 | 1.6533e-1 |
|
||||
| 7 | 7302781 | 4.3528e-1 | 4.3509e-1 |
|
||||
| 8 | 6253177 | 3.7272e-1 | 3.7294e-1 |
|
||||
|
||||
| ROT amounts in {1,2,30,31} | Count | Expected Binomial(8, 4/31) | ROT amounts in {8,16,24} | Count | Expected Binomial(8, 3/31) | ROT max multiplicity | Count |
|
||||
|---|---|---|---|---|---|---|---|
|
||||
| 0 | 5558032 | 5555670.2 | 0 | 7436763 | 7431741.5 | 0 | 0 |
|
||||
| 1 | 6581255 | 6584498.0 | 1 | 6367439 | 6370064.2 | 1 | 6253177 |
|
||||
| 2 | 3416505 | 3414184.2 | 2 | 2387947 | 2388774.1 | 2 | 9662112 |
|
||||
| 3 | 1010272 | 1011610.1 | 3 | 510526 | 511880.2 | 3 | 826296 |
|
||||
| 4 | 187244 | 187335.2 | 4 | 68359 | 68555.4 | 4 | 34667 |
|
||||
| 5 | 22147 | 22202.7 | 5 | 5828 | 5876.2 | 5 | 947 |
|
||||
| 6 | 1696 | 1644.6 | 6 | 345 | 314.8 | 6 | 17 |
|
||||
| 7 | 63 | 69.6 | 7 | 9 | 9.6 | 7 | 0 |
|
||||
| 8 | 2 | 1.3 | 8 | 0 | 0.1 | 8 | 0 |
|
||||
|
||||
| M2 k (words of NAF weight <= 3) | Count | Gain 16/(16-k) |
|
||||
|---|---|---|
|
||||
| 0 | 16777000 | 1.000x |
|
||||
| 1 | 216 | 1.067x |
|
||||
| 2 | 0 | 1.143x |
|
||||
| 3 | 0 | 1.231x |
|
||||
|
||||
| Minimum NAF weight over the 16 MUL | Count |
|
||||
|---|---|
|
||||
| 2 | 4 |
|
||||
| 3 | 212 |
|
||||
| 4 | 3421 |
|
||||
| 5 | 37733 |
|
||||
| 6 | 290503 |
|
||||
| 7 | 1528972 |
|
||||
| 8 | 4939471 |
|
||||
| 9 | 7132514 |
|
||||
| 10 | 2713385 |
|
||||
| 11 | 130753 |
|
||||
| 12 | 248 |
|
||||
|
||||
| M1 cost per application | Count | Cumulative fraction | M1 gain vs median |
|
||||
|---|---|---|---|
|
||||
| 197 | 1 | 5.9605e-8 | 1.1726x |
|
||||
| 198 | 2 | 1.7881e-7 | 1.1667x |
|
||||
| 199 | 1 | 2.3842e-7 | 1.1608x |
|
||||
| 200 | 10 | 8.3447e-7 | 1.1550x |
|
||||
| 201 | 15 | 1.7285e-6 | 1.1493x |
|
||||
| 202 | 25 | 3.2187e-6 | 1.1436x |
|
||||
| 203 | 66 | 7.1526e-6 | 1.1379x |
|
||||
| 204 | 124 | 1.4544e-5 | 1.1324x |
|
||||
| 205 | 250 | 2.9445e-5 | 1.1268x |
|
||||
| 206 | 432 | 5.5194e-5 | 1.1214x |
|
||||
| 207 | 781 | 1.0175e-4 | 1.1159x |
|
||||
| 208 | 1382 | 1.8412e-4 | 1.1106x |
|
||||
| 209 | 2387 | 3.2640e-4 | 1.1053x |
|
||||
| 210 | 3887 | 5.5808e-4 | 1.1000x |
|
||||
| 211 | 6602 | 9.5159e-4 | 1.0948x |
|
||||
| 212 | 10657 | 1.5868e-3 | 1.0896x |
|
||||
| 213 | 17018 | 2.6011e-3 | 1.0845x |
|
||||
| 214 | 26180 | 4.1616e-3 | 1.0794x |
|
||||
| 215 | 39884 | 6.5389e-3 | 1.0744x |
|
||||
| 216 | 58060 | 9.9995e-3 | 1.0694x |
|
||||
| 217 | 83645 | 1.4985e-2 | 1.0645x |
|
||||
| 218 | 117632 | 2.1997e-2 | 1.0596x |
|
||||
| 219 | 162182 | 3.1663e-2 | 1.0548x |
|
||||
| 220 | 216961 | 4.4595e-2 | 1.0500x |
|
||||
| 221 | 283558 | 6.1497e-2 | 1.0452x |
|
||||
| 222 | 362047 | 8.3076e-2 | 1.0405x |
|
||||
| 223 | 450814 | 1.0995e-1 | 1.0359x |
|
||||
| 224 | 550735 | 1.4277e-1 | 1.0312x |
|
||||
| 225 | 652577 | 1.8167e-1 | 1.0267x |
|
||||
| 226 | 756846 | 2.2678e-1 | 1.0221x |
|
||||
| 227 | 855148 | 2.7775e-1 | 1.0176x |
|
||||
| 228 | 941391 | 3.3386e-1 | 1.0132x |
|
||||
| 229 | 1011617 | 3.9416e-1 | 1.0087x |
|
||||
| 230 | 1059221 | 4.5730e-1 | 1.0043x |
|
||||
| 231 | 1079174 | 5.2162e-1 | 1.0000x |
|
||||
| 232 | 1070912 | 5.8545e-1 | 0.9957x |
|
||||
| 233 | 1039183 | 6.4739e-1 | 0.9914x |
|
||||
| 234 | 980014 | 7.0580e-1 | 0.9872x |
|
||||
| 235 | 899809 | 7.5944e-1 | 0.9830x |
|
||||
| 236 | 805446 | 8.0744e-1 | 0.9788x |
|
||||
| 237 | 700659 | 8.4921e-1 | 0.9747x |
|
||||
| 238 | 592824 | 8.8454e-1 | 0.9706x |
|
||||
| 239 | 489326 | 9.1371e-1 | 0.9665x |
|
||||
| 240 | 391079 | 9.3702e-1 | 0.9625x |
|
||||
| 241 | 304227 | 9.5515e-1 | 0.9585x |
|
||||
| 242 | 229565 | 9.6884e-1 | 0.9545x |
|
||||
| 243 | 168335 | 9.7887e-1 | 0.9506x |
|
||||
| 244 | 120776 | 9.8607e-1 | 0.9467x |
|
||||
| 245 | 83871 | 9.9107e-1 | 0.9429x |
|
||||
| 246 | 56312 | 9.9442e-1 | 0.9390x |
|
||||
| 247 | 36832 | 9.9662e-1 | 0.9352x |
|
||||
| 248 | 23268 | 9.9801e-1 | 0.9315x |
|
||||
| 249 | 14347 | 9.9886e-1 | 0.9277x |
|
||||
| 250 | 8495 | 9.9937e-1 | 0.9240x |
|
||||
| 251 | 4856 | 9.9966e-1 | 0.9203x |
|
||||
| 252 | 2783 | 9.9982e-1 | 0.9167x |
|
||||
| 253 | 1472 | 9.9991e-1 | 0.9130x |
|
||||
| 254 | 757 | 9.9995e-1 | 0.9094x |
|
||||
| 255 | 415 | 9.9998e-1 | 0.9059x |
|
||||
| 256 | 179 | 9.9999e-1 | 0.9023x |
|
||||
| 257 | 79 | 1.0000e0 | 0.8988x |
|
||||
| 258 | 43 | 1.0000e0 | 0.8953x |
|
||||
| 259 | 23 | 1.0000e0 | 0.8919x |
|
||||
| 260 | 9 | 1.0000e0 | 0.8885x |
|
||||
| 261 | 3 | 1.0000e0 | 0.8851x |
|
||||
| 262 | 4 | 1.0000e0 | 0.8817x |
|
||||
| 263 | 1 | 1.0000e0 | 0.8783x |
|
||||
|
||||
## The 16 lowest-cost days (M1)
|
||||
|
||||
- day 4819563: cost 197, gain 1.1726x vs median, NAF sum 149, M2 k 0, day-hex 69676e65756d2d6461792f6b8a490000000000
|
||||
- day 5517722: cost 198, gain 1.1667x vs median, NAF sum 150, M2 k 0, day-hex 69676e65756d2d6461792f9a31540000000000
|
||||
- day 12915578: cost 198, gain 1.1667x vs median, NAF sum 150, M2 k 0, day-hex 69676e65756d2d6461792f7a13c50000000000
|
||||
- day 5073249: cost 199, gain 1.1608x vs median, NAF sum 151, M2 k 0, day-hex 69676e65756d2d6461792f61694d0000000000
|
||||
- day 295616: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792fc082040000000000
|
||||
- day 2339457: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f81b2230000000000
|
||||
- day 7275755: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792feb046f0000000000
|
||||
- day 7921343: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792fbfde780000000000
|
||||
- day 10331167: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f1fa49d0000000000
|
||||
- day 10514223: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f2f6fa00000000000
|
||||
- day 12709144: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f18edc10000000000
|
||||
- day 14463384: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f98b1dc0000000000
|
||||
- day 14777650: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f327de10000000000
|
||||
- day 15551477: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792ff54bed0000000000
|
||||
- day 515226: cost 201, gain 1.1493x vs median, NAF sum 153, M2 k 0, day-hex 69676e65756d2d6461792f9adc070000000000
|
||||
- day 2240604: cost 201, gain 1.1493x vs median, NAF sum 153, M2 k 0, day-hex 69676e65756d2d6461792f5c30220000000000
|
||||
|
||||
## Worst member of every class, in full
|
||||
|
||||
### ROT distinct <= 3: day 11482247
|
||||
```
|
||||
day index 11482247 (genesis + 11461518), day bytes 69676e65756d2d6461792f8734af0000000000 , seed64 99b37b14bce80e05
|
||||
key bce80e05 99b37b14 a88409a4 a5469d0e 35c4b54e c027571b 152552c8 9d942222
|
||||
ROT [12, 19, 19, 4, 19, 12, 19, 19] distinct 3 max multiplicity 5 small 0 byte-aligned 0 same-word pair 32 false any pair 32 false
|
||||
MUL 23684433 345dfd6d 13878a5b dff7431f 60e1ffa5 fb7bcf75 ef826109 6fd6c065 1d5b0701 75f4b29f 24197fc1 1367fa6d 87f0f4ed 03b41769 92cbf013 03bbeca7
|
||||
NAF [11, 11, 11, 9, 9, 10, 9, 10, 9, 12, 8, 11, 10, 10, 11, 9] sum 160 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 93abe65f 6886b6d0 3a68d00d 3889c0c6 b194b674 4094caf5 161c68f0 6b3cdc05 f1fbf7c0 2ee32537 5779f1ba 56b1eabc 914f7e4d 35c47fa0 ab029a5b ae0b61a1
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 208 adder-equivalents per application (14976 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1106x
|
||||
classes: ROT distinct <= 3; ROT distinct <= 4; ROT max multiplicity >= 4
|
||||
```
|
||||
### ROT distinct <= 4: day 1092491
|
||||
```
|
||||
day index 1092491 (genesis + 1071762), day bytes 69676e65756d2d6461792f8bab100000000000 , seed64 da149ee55aaab937
|
||||
key 5aaab937 da149ee5 11819d67 3f60c5a0 6045fabb ac9ede0d 919ff013 7143f2b9
|
||||
ROT [21, 16, 12, 16, 31, 12, 12, 31] distinct 4 max multiplicity 3 small 2 byte-aligned 2 same-word pair 32 true any pair 32 true
|
||||
MUL a05bba01 bec09787 7afe483b 28844197 b7eafc73 aa1d3f0f 83508105 f39cc103 d21f51a1 ffa61343 40cfaea1 03bebcd3 7f059f6f b00ededf ca070e07 3bd803db
|
||||
NAF [9, 10, 9, 10, 11, 11, 9, 11, 12, 11, 10, 10, 9, 9, 10, 8] sum 159 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 9ea401b9 c5b29850 00371b55 5592306c 77d7ec18 f100a72b ca4db32b 82fc9dc4 83168f22 e3359513 ad711b53 b7f5dc09 add1d8ab 982a05b1 06b37a9b 829bb32d
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 207 adder-equivalents per application (14904 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1159x
|
||||
classes: ROT distinct <= 4; ROT same-word pair sums to 32; ROT any pair sums to 32
|
||||
```
|
||||
### ROT max multiplicity >= 4: day 9506389
|
||||
```
|
||||
day index 9506389 (genesis + 9485660), day bytes 69676e65756d2d6461792f550e910000000000 , seed64 6982e9080d6a4cdf
|
||||
key 0d6a4cdf 6982e908 4a0a0b42 a399c15d 99e27fe1 fdfb9b00 4e90d671 78401cd0
|
||||
ROT [15, 5, 31, 5, 5, 24, 6, 5] distinct 5 max multiplicity 4 small 1 byte-aligned 1 same-word pair 32 false any pair 32 false
|
||||
MUL 37800e03 d714c2fb a4be52db 87737201 5ac001d7 95f7c07f c1fb39d9 8bdfc411 70097121 e009077d f0ef802b 36f0ebbf 087b2dd7 8270b24d c3b48dad fc354847
|
||||
NAF [7, 12, 13, 9, 9, 8, 11, 8, 9, 8, 9, 9, 10, 12, 13, 11] sum 158 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC c4769637 de22eaea 7aa5b4ed 46b93f02 41831974 bbd9933b c6a06ba1 c102f45e 6483273a c33cfd56 5669b2b7 f5ee5a3d f4c63fc9 50ccdb45 522844d2 c405d738
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 206 adder-equivalents per application (14832 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1214x
|
||||
classes: ROT max multiplicity >= 4
|
||||
```
|
||||
### ROT same-word pair sums to 32: day 3675001
|
||||
```
|
||||
day index 3675001 (genesis + 3654272), day bytes 69676e65756d2d6461792f7913380000000000 , seed64 81ed531eeadd5e68
|
||||
key eadd5e68 81ed531e 453f3611 4caf9ae6 c9585bb1 115e4232 cdaff538 dc39efc9
|
||||
ROT [25, 5, 21, 27, 21, 7, 12, 27] distinct 6 max multiplicity 2 small 0 byte-aligned 0 same-word pair 32 true any pair 32 true
|
||||
MUL 7b011e4d 3c417fc1 9d055513 beea0cb9 207ef901 1df73bdd 7c2034ff 77fe5083 cf567a1f c4311bf1 7dded2b9 7bcae001 e58678b9 0f6dc051 213ef8a9 20afbbb9
|
||||
NAF [10, 7, 13, 12, 6, 9, 8, 8, 12, 10, 11, 8, 13, 8, 9, 9] sum 153 min 6 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 113c7ffd 754403c6 9d01091b 58b7ed13 a5685eec e1a691a0 e98f235e 3f622792 3fc0a2a9 a8b91f03 3aa824aa 7ff52b9d a7f69c00 3cc25c5e c3a37dd3 90c308ad
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 201 adder-equivalents per application (14472 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1493x
|
||||
classes: ROT same-word pair sums to 32; ROT any pair sums to 32
|
||||
```
|
||||
### ROT any pair sums to 32: day 4819563
|
||||
```
|
||||
day index 4819563 (genesis + 4798834), day bytes 69676e65756d2d6461792f6b8a490000000000 , seed64 d4924b5d4dc26798
|
||||
key 4dc26798 d4924b5d c75c47df 64b4f00f 0836e7ff cd383a15 4c85767a 6a08a753
|
||||
ROT [26, 18, 8, 30, 24, 24, 6, 9] distinct 7 max multiplicity 2 small 1 byte-aligned 3 same-word pair 32 false any pair 32 true
|
||||
MUL a0653c83 a09de525 810085fb 6a00eba1 bf8205ff bba82079 f27da4c3 2cb80223 6001efcf 1c2814f7 ae9d09d7 ffedd7b7 943dde01 39ff47e1 0513a83f c028eef9
|
||||
NAF [11, 11, 7, 10, 7, 10, 12, 10, 7, 9, 13, 8, 8, 8, 9, 9] sum 149 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 3ba362fd 47c4ea3e c8d59f08 c76a1b32 a33837f3 2295b6a8 6578c14a 348c033f 35f3d38e 60755b0f 75437163 235c6abb eae387e0 09ad148b dfd1092c aebb5f8e
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 197 adder-equivalents per application (14184 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1726x
|
||||
classes: ROT any pair sums to 32
|
||||
```
|
||||
### ROT all 8 in {1,2,30,31}: day 14330190
|
||||
```
|
||||
day index 14330190 (genesis + 14309461), day bytes 69676e65756d2d6461792f4ea9da0000000000 , seed64 722cea0895f65bbe
|
||||
key 95f65bbe 722cea08 b6716401 2aa400d8 7e0054e3 7edf5115 73008e0c ea61f647
|
||||
ROT [1, 1, 2, 31, 1, 31, 1, 31] distinct 3 max multiplicity 4 small 8 byte-aligned 0 same-word pair 32 true any pair 32 true
|
||||
MUL 5111ff0d 0915ca85 e63f87e3 3a3eec25 74fc4b01 04849df9 740b798f 96300b51 c7c8033d 90111e63 268db4a9 cf40e4a5 ac91052f 18814e21 92657099 3b7fa903
|
||||
NAF [9, 11, 10, 10, 10, 8, 11, 12, 10, 10, 13, 12, 12, 9, 13, 9] sum 169 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 57ed2402 ab186f3e 8c7e4d2c b7a0915d 6c47d3d1 3ab1c1a5 91ba307f 177182e3 b19522c4 93deec89 cdc3dcc7 c8637063 0abd4442 d4df5f23 4606f7ab 3595b758
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 217 adder-equivalents per application (15624 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.0645x
|
||||
classes: ROT distinct <= 3; ROT distinct <= 4; ROT max multiplicity >= 4; ROT same-word pair sums to 32; ROT any pair sums to 32; ROT all 8 in {1,2,30,31}; ROT >= 6 in {1,2,30,31}; ROT >= 4 in {1,2,30,31}
|
||||
```
|
||||
### ROT >= 6 in {1,2,30,31}: day 155537
|
||||
```
|
||||
day index 155537 (genesis + 134808), day bytes 69676e65756d2d6461792f915f020000000000 , seed64 62a533010044516b
|
||||
key 0044516b 62a53301 877d9dac ad817c3f 788dace2 7cda9997 77fab135 e51ef305
|
||||
ROT [22, 21, 30, 30, 2, 31, 31, 2] distinct 5 max multiplicity 2 small 6 byte-aligned 0 same-word pair 32 false any pair 32 true
|
||||
MUL 205bfc49 00e29caf 3e1cdf05 88267f01 efad6031 2edbba8f 5802025d 7b6aef0f db740619 253f4b7b 3310231d ca01a579 5b5b8e69 0b051b43 3fef1507 e10e7aad
|
||||
NAF [8, 10, 9, 8, 10, 11, 9, 10, 11, 11, 11, 12, 13, 11, 8, 12] sum 164 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 9f220844 5c8a4552 e6f7dc41 bca5026c bac2bcec 8d331e54 eeb4b6f1 7ef67511 602e8964 54ee8e4b b57c03b6 1dd85466 efa50b4d 6d72abe6 2cccea1f d9f6ed77
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 212 adder-equivalents per application (15264 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.0896x
|
||||
classes: ROT any pair sums to 32; ROT >= 6 in {1,2,30,31}; ROT >= 4 in {1,2,30,31}
|
||||
```
|
||||
### ROT >= 4 in {1,2,30,31}: day 12915578
|
||||
```
|
||||
day index 12915578 (genesis + 12894849), day bytes 69676e65756d2d6461792f7a13c50000000000 , seed64 57f6497ce6d7a118
|
||||
key e6d7a118 57f6497c fefb5f19 c79046cc b1a6df7d aa592471 1cd1d432 48e25d80
|
||||
ROT [30, 30, 31, 17, 16, 31, 13, 9] distinct 6 max multiplicity 2 small 4 byte-aligned 1 same-word pair 32 false any pair 32 false
|
||||
MUL 41406225 06c21421 80fe91b1 145d8359 10c01035 2025c17f 7f801477 1b53081b 547e7dc7 381c841f 02baf16b 6ce88fef 08e447f9 077440cd 9dddb2d7 7ae58045
|
||||
NAF [9, 8, 9, 11, 8, 8, 7, 11, 10, 8, 11, 10, 8, 10, 12, 10] sum 150 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC a7246db5 dff83962 82647cfd 3eb91ca4 b17e51e1 f10dc65b b24a5f72 3e849586 2a1248a1 f44e7f64 ad012d93 0074a57e b10c2709 2986079c 9f0b9f4c 0f1c9565
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 198 adder-equivalents per application (14256 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1667x
|
||||
classes: ROT >= 4 in {1,2,30,31}; MUL any popcount <= 8
|
||||
```
|
||||
### ROT >= 4 in {8,16,24}: day 5517722
|
||||
```
|
||||
day index 5517722 (genesis + 5496993), day bytes 69676e65756d2d6461792f9a31540000000000 , seed64 6cb96c5fb4321712
|
||||
key b4321712 6cb96c5f a77367f6 b2719260 5edf1eba 183ecb78 4522b1e7 560ae215
|
||||
ROT [19, 8, 24, 20, 19, 8, 2, 8] distinct 5 max multiplicity 3 small 1 byte-aligned 4 same-word pair 32 false any pair 32 true
|
||||
MUL 1bce207f 382ff2bd f60fdaaf 424a1321 f6590551 231258b3 546dc127 08ac8085 070a003d 41bbfd91 c5dfc81b 007b2f19 983f01e7 0847837f 060f90a7 040e9015
|
||||
NAF [8, 10, 10, 10, 12, 13, 11, 9, 7, 8, 10, 9, 9, 7, 9, 8] sum 150 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC ff224509 ec7e2a5b 5968f4aa b9a7e963 df762e0d 1e62e44e 2fa7540b 0aa0e15d ab38c25f a88b3cb8 006e698c 2bfc51dc 5e0d671a 7b9af6ce a0a8e6e0 89595bcb
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 198 adder-equivalents per application (14256 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1667x
|
||||
classes: ROT any pair sums to 32; ROT >= 4 in {8,16,24}
|
||||
```
|
||||
### MUL any popcount <= 4: day 7275755
|
||||
```
|
||||
day index 7275755 (genesis + 7255026), day bytes 69676e65756d2d6461792feb046f0000000000 , seed64 8c466b2af98a2e86
|
||||
key f98a2e86 8c466b2a 7aeceb13 73b046e4 6bf5ee94 1f2ffb0c 68e00b58 8939ea67
|
||||
ROT [7, 20, 3, 30, 26, 14, 14, 9] distinct 7 max multiplicity 2 small 1 byte-aligned 0 same-word pair 32 false any pair 32 false
|
||||
MUL 22b167d9 1217c0ff 83f9d6ff 53f47821 9e6f203f 8ddf1105 503197e7 5203053f 18100001 b1afa8e1 fc0d2e77 47d30207 a62e473f 9a30a787 f7fb9443 4453f77d
|
||||
NAF [12, 7, 8, 9, 9, 9, 11, 9, 4, 12, 11, 9, 12, 12, 9, 9] sum 152 min 4 =1 0 =-1 0 pop<=4 1 naf<=3 0 <256 0 dup false
|
||||
RC ffb825e4 f8be0580 73dbb4cf 358c1f2f 27cf0dda bb3480ee 7b357f42 e12fe90f fb7486d5 429d3607 2d5bd341 7d426c5c 3ca53a8d 6bba1a7b 834a9b7b 4b7ebe4f
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 200 adder-equivalents per application (14400 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1550x
|
||||
classes: MUL any popcount <= 4; MUL any popcount <= 8; MUL any NAF weight <= 4
|
||||
```
|
||||
### MUL any NAF weight <= 2: day 7786546
|
||||
```
|
||||
day index 7786546 (genesis + 7765817), day bytes 69676e65756d2d6461792f32d0760000000000 , seed64 7ac5b9e18cde6f44
|
||||
key 8cde6f44 7ac5b9e1 39a3e509 a2faa026 6a1437c0 a21b7c6b 2a625719 405689b1
|
||||
ROT [25, 7, 21, 19, 12, 28, 9, 25] distinct 7 max multiplicity 2 small 0 byte-aligned 0 same-word pair 32 false any pair 32 true
|
||||
MUL a9f9aaa5 393fdfb5 fb11d523 8c2df7b7 e9c31551 cb349fcd c9dd7baf 3e676067 6359fad5 53e1ffeb 000007ff 6057c76d 3c86f067 b791a083 3738eec7 b42ba445
|
||||
NAF [14, 9, 12, 10, 13, 14, 11, 11, 13, 8, 2, 11, 10, 11, 11, 13] sum 173 min 2 =1 0 =-1 0 pop<=4 0 naf<=3 1 <256 0 dup false
|
||||
RC 8af42dee f0e6dcd6 1e594042 eee6defb bc86dccf 6cfa11fe 4f8ba636 455f5e8a d21de702 382b305f 56a1c147 b386e182 3d2d8d04 756a3cd8 71ed29eb 7b08de97
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 221 adder-equivalents per application (15912 per item, 72 applications); M2 k 1 (gain 1.067x)
|
||||
M1 gain against the census median 231: 1.0452x
|
||||
classes: ROT any pair sums to 32; MUL any NAF weight <= 2; MUL any NAF weight <= 3; MUL any NAF weight <= 4
|
||||
```
|
||||
### MUL any NAF weight <= 3: day 332924
|
||||
```
|
||||
day index 332924 (genesis + 312195), day bytes 69676e65756d2d6461792f7c14050000000000 , seed64 f808897c2547d426
|
||||
key 2547d426 f808897c 513cca7d 52f7f508 3c4e673e 02a296f7 7d51ea58 cc6a6d4c
|
||||
ROT [1, 23, 1, 1, 12, 11, 16, 18] distinct 6 max multiplicity 3 small 3 byte-aligned 1 same-word pair 32 false any pair 32 false
|
||||
MUL 02fe3349 ebfbb02d 03ffc001 bd03f177 c59affa1 080e4a8f 02ce4063 466595f5 3e80970f 00f39991 0937c1c5 49a3a27f 1705f1db e14c5f59 feb802ed b3c7e543
|
||||
NAF [10, 10, 3, 10, 11, 9, 10, 14, 9, 10, 9, 11, 10, 12, 9, 12] sum 159 min 3 =1 0 =-1 0 pop<=4 0 naf<=3 1 <256 0 dup false
|
||||
RC 1b116748 5923a322 2b3a87a3 a6766c2f ce61047f ed58e672 59023641 a5898f72 65026fe7 7fcc8696 ee849527 ae5ac84c 48c6da86 870d31f1 aa7bafdc 163aa9fa
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 207 adder-equivalents per application (14904 per item, 72 applications); M2 k 1 (gain 1.067x)
|
||||
M1 gain against the census median 231: 1.1159x
|
||||
classes: MUL any NAF weight <= 3; MUL any NAF weight <= 4
|
||||
```
|
||||
### MUL any < 256: day 14317428
|
||||
```
|
||||
day index 14317428 (genesis + 14296699), day bytes 69676e65756d2d6461792f7477da0000000000 , seed64 15a13158d6510a3e
|
||||
key d6510a3e 15a13158 269297c4 5bceb8e2 aea8a2ed dabc3585 4076bc5c 01bec51f
|
||||
ROT [11, 14, 4, 19, 28, 12, 20, 23] distinct 8 max multiplicity 1 small 0 byte-aligned 0 same-word pair 32 false any pair 32 true
|
||||
MUL dc9e0e77 6f487117 f3e164b9 f5615c89 f9f33575 16ee44f7 1f2f8205 a6506901 3003f653 efdc8cc5 0e4ab3c9 000000eb 2c230eef 6b843c71 b8e67d17 7cba91df
|
||||
NAF [11, 11, 12, 12, 13, 10, 8, 11, 9, 11, 12, 4, 10, 10, 13, 11] sum 168 min 4 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 1 dup false
|
||||
RC ebf15842 e0a148eb a2e4ee1d 1fc2bea3 2d63622e c45c96bf b3a36493 486b4d26 00366580 61c9b1c0 b884e3ea e3e9b598 d42d5626 a9115df7 87259e61 f5ce1730
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
|
||||
M1 cost 216 adder-equivalents per application (15552 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.0694x
|
||||
classes: ROT any pair sums to 32; MUL any popcount <= 8; MUL any NAF weight <= 4; MUL any < 256
|
||||
```
|
||||
### RC any popcount <= 4 or >= 28: day 7999545
|
||||
```
|
||||
day index 7999545 (genesis + 7978816), day bytes 69676e65756d2d6461792f39107a0000000000 , seed64 c93bd7b37f21862d
|
||||
key 7f21862d c93bd7b3 5b8af838 808161f4 824aa21f 2e361c27 3a9893f5 a174f291
|
||||
ROT [2, 9, 21, 30, 26, 31, 20, 6] distinct 8 max multiplicity 1 small 3 byte-aligned 0 same-word pair 32 false any pair 32 true
|
||||
MUL 5eeafff1 20d43481 f82a157b b074ba81 6fd05fab 0436f05d bf4b2e11 200619df fd87f81b af944de5 ed74aadf 8fca07c3 1446e11f 43fc06c5 01c1b977 484a8ac3
|
||||
NAF [8, 10, 11, 12, 10, 9, 12, 8, 8, 12, 13, 9, 9, 8, 9, 12] sum 160 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 864fb298 1ac6b021 33767a7e 9368cb81 e8846716 1aa3ce3d 9812d074 67e4fc2c e4778444 c36dd02b fee3ffff 04723a67 4138fef0 ddf770c6 83dac053 28e4d10c
|
||||
RC zero 0 pop<=4|>=28 1 rc+rk=0 0 dup false
|
||||
M1 cost 208 adder-equivalents per application (14976 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.1106x
|
||||
classes: ROT any pair sums to 32; RC any popcount <= 4 or >= 28
|
||||
```
|
||||
### RC + rk = 0 for any of the 72 keys: day 3194363
|
||||
```
|
||||
day index 3194363 (genesis + 3173634), day bytes 69676e65756d2d6461792ffbbd300000000000 , seed64 bc1e82a5c9f5ddde
|
||||
key c9f5ddde bc1e82a5 96ab4399 0671592a bb1c6360 3913fe9a 9804267d 299ae13d
|
||||
ROT [1, 7, 16, 9, 15, 4, 30, 22] distinct 8 max multiplicity 1 small 2 byte-aligned 1 same-word pair 32 false any pair 32 false
|
||||
MUL e7190f35 650c36eb afa6090b a8fb90ef 034e3297 862b6f0d dbf807f5 284be071 dbf8a029 100809e5 23747809 71ab3457 40f884c9 bf8f55e7 f1549811 996781e5
|
||||
NAF [13, 12, 12, 10, 12, 12, 8, 9, 9, 7, 9, 14, 9, 11, 11, 12] sum 170 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC d8cfa0e8 b7d3cbda 43cfc80c d25da2da 2e0e8163 c53232b1 b12fccd0 554503c1 926caee2 0e443238 f57e07fb 2b6fa3e6 3cbf689c 85b2a4b4 7ba7972d d9c14302
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 1 dup false
|
||||
M1 cost 218 adder-equivalents per application (15696 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.0596x
|
||||
classes: RC + rk = 0 for any of the 72 keys
|
||||
```
|
||||
### RC two equal: day 2875598
|
||||
```
|
||||
day index 2875598 (genesis + 2854869), day bytes 69676e65756d2d6461792fcee02b0000000000 , seed64 cbb947500a68806e
|
||||
key 0a68806e cbb94750 a7becf69 57289c05 faec9414 c10772ba d2903fe5 74af4324
|
||||
ROT [29, 30, 4, 8, 19, 13, 25, 29] distinct 7 max multiplicity 2 small 1 byte-aligned 1 same-word pair 32 false any pair 32 true
|
||||
MUL f2f52c69 155a7899 e6ff1b2f 8ca5703d 4643df15 8100291f c31dad25 bc9cfef1 73c502d7 72f4b489 ae01e6dd 67dfd461 0b1d0b75 fa948d61 1dd832eb 0e09fb03
|
||||
NAF [14, 13, 11, 12, 10, 7, 13, 10, 11, 13, 11, 10, 12, 12, 11, 8] sum 178 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
|
||||
RC 16dd5198 a438a5ee d0ef08a1 29be50c8 9758bd94 4983af82 ad80a68b 1c6080f9 9dbb6eb7 491a03b8 b5c6622a cf646720 9a211c17 f952fecb 56c26eec b5c6622a
|
||||
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup true
|
||||
M1 cost 226 adder-equivalents per application (16272 per item, 72 applications); M2 k 0 (gain 1.000x)
|
||||
M1 gain against the census median 231: 1.0221x
|
||||
classes: ROT any pair sums to 32; RC two equal
|
||||
```
|
||||
|
|
@ -0,0 +1,3 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
cnf day=20729 vars=105652 clauses=361188 written /srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf
|
||||
BLOCKED on the solve: no SAT solver reaches the box (crates.io refused, none installed); the model is the artefact
|
||||
|
|
@ -0,0 +1,76 @@
|
|||
adv-mixer diffusion sweep; internal adversarial pass, not an independent review
|
||||
a01bf61016a8bda530468f081442131f1bff4a7b6401dd84cbcde83c78bb48f3
|
||||
UTC_START 2026-10-07T18:19:48Z
|
||||
===== K=1 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=1 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.461177 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 578 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 111997 of 262144
|
||||
worst cell: in_bit 60 -> out_bit 107 p = 1.000000 dev = 0.500000 (1414.2 sigma)
|
||||
VERDICT: FINDING (holes or strong bias at this K)
|
||||
===== K=2 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=2 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.500001 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 107 -> out_bit 490 p = 0.501702 dev = 0.001702 (4.8 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
===== K=3 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=3 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 112 -> out_bit 295 p = 0.498383 dev = 0.001617 (4.6 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
===== K=4 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=4 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 220 -> out_bit 106 p = 0.498354 dev = 0.001646 (4.7 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
===== K=5 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=5 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 453 -> out_bit 93 p = 0.498283 dev = 0.001717 (4.9 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
===== K=6 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=6 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 494 -> out_bit 479 p = 0.498377 dev = 0.001623 (4.6 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
===== K=7 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=7 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 161 -> out_bit 378 p = 0.501592 dev = 0.001592 (4.5 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
===== K=8 =====
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=8 start=0 states=2000000 threads=32
|
||||
mean output-flip probability over all 262144 cells: 0.500001 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 202 -> out_bit 367 p = 0.498295 dev = 0.001705 (4.8 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
UTC_END 2026-10-07T18:30:40Z
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
fold-sweep from_day=20729 days=1024 pairs_per_day=71 trials_per_pair=20000
|
||||
(a) affinity violations: 1454080000 of 1454080000 pair-trials; lowest per-pair violation fraction 1.000000 (1.0 = never affine)
|
||||
(b) dead word pairs summed over 1024 days: 0 (0 = complete dependency every day)
|
||||
(c) key-order agreements: 0 of 1454080000 pair-trials
|
||||
VERDICT: BOUND: no fold on any day or pair probed
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
fold-sweep from_day=20729 days=1024 pairs_per_day=71 trials_per_pair=20000
|
||||
(a) affinity violations: 1454080000 of 1454080000 pair-trials; lowest per-pair violation fraction 1.000000 (1.0 = never affine)
|
||||
(b) dead word pairs summed over 1024 days: 0 (0 = complete dependency every day)
|
||||
(c) key-order agreements: 0 of 1454080000 pair-trials
|
||||
VERDICT: BOUND: no fold on any day or pair probed
|
||||
609
docs/analysis/cryptanalysis/logs/adv-mixer/integral-a1-32d.log
Normal file
609
docs/analysis/cryptanalysis/logs/adv-mixer/integral-a1-32d.log
Normal file
|
|
@ -0,0 +1,609 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
integral day=20729 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 236.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 184.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 175.0/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 172.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 172.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 173.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 175.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 174.6/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 175.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 177.6/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 182.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 184.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 187.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 191.5/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 196.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 203.3/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20730 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 229.8/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 177.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 165.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 1999/2000 = 0.9995 mean out-bits set 158.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 157.5/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 161.0/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 162.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 164.2/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 169.2/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 174.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 183.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 188.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 192.3/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 198.6/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 205.7/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 213.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20731 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 242.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 194.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 184.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 185.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 186.4/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 188.1/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 190.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 191.4/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 195.0/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 199.2/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 202.4/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 206.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 216.2/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 219.5/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 223.8/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20732 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 233.5/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 182.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 170.5/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 164.6/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 160.9/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 159.5/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 159.3/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 161.5/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 165.1/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 168.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 173.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 176.8/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 185.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 187.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 190.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20733 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 188.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 175.5/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 173.1/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 171.5/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 171.5/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 175.0/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 173.4/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 176.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 178.9/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 187.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 192.4/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 194.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20734 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 232.8/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 186.6/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 177.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 173.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 170.4/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 171.0/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 174.0/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 177.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 181.6/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 188.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 193.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.6/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 208.8/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 213.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 220.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20735 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 230.6/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 182.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 168.7/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 163.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 161.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 161.6/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 164.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 163.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 167.6/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 168.8/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 176.4/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 182.4/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 188.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 191.6/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 199.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 205.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20736 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 238.6/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.3/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 178.7/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 178.3/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 185.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 194.8/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 198.4/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 204.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 209.6/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 214.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 220.5/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 225.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20737 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 237.4/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 180.5/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 178.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 177.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 177.5/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 180.7/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 183.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 186.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 193.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 195.9/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 202.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 204.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 206.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20738 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 198.5/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 189.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 191.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 194.3/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 195.5/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 202.7/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 204.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 208.8/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 216.6/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 219.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 223.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 228.7/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 232.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20739 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 194.6/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 189.0/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 189.4/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 191.3/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 193.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 196.4/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 202.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 204.1/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 206.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 209.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 212.6/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 216.0/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 218.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 218.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 221.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20740 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 241.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.6/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 186.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 186.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 189.6/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 192.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 196.5/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 199.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 202.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 208.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 214.9/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 218.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 223.5/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 227.4/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 231.6/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20741 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 231.6/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 177.5/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 163.4/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 157.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 153.5/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 152.6/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 152.0/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 155.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 159.1/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 164.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 169.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 173.6/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 183.2/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 187.3/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 191.8/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20742 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 244.5/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 204.5/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 197.1/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 201.4/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 204.6/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 206.6/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 211.5/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 214.7/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 216.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 219.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 222.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 224.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 225.1/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 226.0/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 226.7/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 228.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20743 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 238.8/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 191.6/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 183.7/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 183.3/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 184.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 183.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 186.7/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 188.7/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 190.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 193.2/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 196.6/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 201.4/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 206.7/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 211.4/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 214.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 219.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20744 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 233.3/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 188.4/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 175.6/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 172.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 173.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 173.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 180.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 184.2/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 189.6/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 191.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 196.3/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 203.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 206.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 207.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20745 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.6/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 197.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 189.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 188.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 188.9/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 193.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 194.7/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 199.3/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 201.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 206.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 209.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 213.5/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 218.6/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 221.3/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 224.3/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 228.3/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20746 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 236.4/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 180.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 179.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 174.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 178.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 182.5/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 183.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 189.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 194.4/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 196.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 199.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 201.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 204.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20747 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 181.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 178.9/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 180.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 177.7/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 180.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 183.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 186.3/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 189.3/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 190.5/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 195.0/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 198.4/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 203.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 206.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20748 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 242.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 199.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 188.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 189.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 189.6/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 192.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 193.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 196.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 198.6/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 202.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 205.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 210.5/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 215.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 218.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20749 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.5/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.6/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 187.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 187.1/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 188.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 188.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 191.5/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 193.3/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 197.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 200.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 204.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 207.3/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 212.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 215.8/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 219.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 223.5/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20750 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 236.7/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 186.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 179.7/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 178.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 182.6/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 191.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 194.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 198.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 202.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 208.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 212.6/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 216.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 221.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 225.3/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20751 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 242.5/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.4/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 187.0/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 186.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 187.6/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 189.0/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 194.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 196.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 200.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 203.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 207.5/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 215.6/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 219.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 223.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20752 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.1/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 182.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 172.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 168.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 166.3/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 166.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 167.7/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 167.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 169.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 170.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 172.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 175.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 177.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 179.3/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 183.7/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 188.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20753 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.7/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 198.2/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 190.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 192.4/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 193.5/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 195.7/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 196.2/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 198.5/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 199.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 201.3/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 204.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 203.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 205.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20754 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 238.7/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 181.6/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 178.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 180.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 178.5/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 179.4/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 183.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 186.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 192.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 196.3/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 202.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 208.0/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 211.0/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 217.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20755 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 239.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 187.4/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 186.5/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 184.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 185.6/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 186.3/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 189.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 191.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 195.9/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 198.3/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 202.0/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 205.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 208.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20756 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 230.8/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 166.6/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 163.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 162.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 164.6/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 169.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 172.5/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 177.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 182.2/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 187.7/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 193.8/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 205.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 210.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 215.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20757 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 241.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 197.6/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 192.8/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 193.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 193.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 203.0/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 207.5/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 210.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 215.2/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 219.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 223.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 226.3/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 229.0/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 231.9/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 232.5/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20758 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 235.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 189.4/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 174.4/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 172.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 169.6/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 170.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 169.6/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 174.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 177.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 181.6/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 184.5/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 188.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 193.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 197.2/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 204.0/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 208.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20759 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.8/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 200.3/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 189.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 192.9/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 193.2/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 197.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 197.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 200.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 202.6/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 207.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 208.8/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 215.1/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 219.3/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 223.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 227.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20760 apps=1 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.7/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 184.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 176.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 177.8/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 182.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 184.4/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 188.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 191.2/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 195.6/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 201.2/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 205.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 211.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
609
docs/analysis/cryptanalysis/logs/adv-mixer/integral-a2-32d.log
Normal file
609
docs/analysis/cryptanalysis/logs/adv-mixer/integral-a2-32d.log
Normal file
|
|
@ -0,0 +1,609 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
integral day=20729 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20730 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20731 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20732 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20733 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.7/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20734 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20735 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20736 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.7/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20737 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20738 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20739 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20740 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20741 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20742 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20743 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20744 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20745 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20746 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20747 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20748 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20749 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20750 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20751 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20752 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20753 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20754 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20755 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20756 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20757 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20758 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.4/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20759 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20760 apps=2 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
|
|
@ -0,0 +1,69 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
integral day=20729 apps=8 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20730 apps=8 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20731 apps=8 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
integral day=20732 apps=8 placements_per_d=2000 threads=44
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
|
||||
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=1 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.427506 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 70 of 11264; strong-bias cells: 6904 of 11264
|
||||
worst cell: in_bit 127 -> addr_bit 10 p = 0.000001 (1000.0 sigma)
|
||||
VERDICT: FINDING (address bits predictable at this K)
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=2 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.500007 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 0 of 11264; strong-bias cells: 0 of 11264
|
||||
worst cell: in_bit 491 -> addr_bit 10 p = 0.498051 (3.9 sigma)
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=3 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.500005 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 0 of 11264; strong-bias cells: 0 of 11264
|
||||
worst cell: in_bit 497 -> addr_bit 20 p = 0.501943 (3.9 sigma)
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=4 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.499998 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 0 of 11264; strong-bias cells: 0 of 11264
|
||||
worst cell: in_bit 13 -> addr_bit 16 p = 0.498123 (3.8 sigma)
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=5 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.499995 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 0 of 11264; strong-bias cells: 0 of 11264
|
||||
worst cell: in_bit 30 -> addr_bit 6 p = 0.502168 (4.3 sigma)
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=6 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.500003 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 0 of 11264; strong-bias cells: 0 of 11264
|
||||
worst cell: in_bit 203 -> addr_bit 10 p = 0.502329 (4.7 sigma)
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=7 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.499995 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 0 of 11264; strong-bias cells: 0 of 11264
|
||||
worst cell: in_bit 374 -> addr_bit 21 p = 0.501813 (3.6 sigma)
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
lineindex day=20729 apps=8 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
|
||||
mean address-bit flip probability: 0.499987 (ideal 0.5); band 8 sigma = 0.004000
|
||||
holes: 0 of 11264; strong-bias cells: 0 of 11264
|
||||
worst cell: in_bit 412 -> addr_bit 4 p = 0.498147 (3.7 sigma)
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
|
|
@ -0,0 +1,17 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20730 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20731 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20732 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20733 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20734 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20735 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20736 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
|
|
@ -0,0 +1,17 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20730 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20731 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20732 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20733 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20734 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20735 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20736 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
|
|
@ -0,0 +1,33 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20733 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20734 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20735 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20736 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20737 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20738 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20739 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20740 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20741 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20742 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20743 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20744 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,33 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20733 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20734 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20735 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20736 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20737 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20738 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20739 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20740 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20741 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20742 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20743 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20744 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,9 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,9 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,9 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,9 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,9 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,33 @@
|
|||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
linrel day=20729 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20733 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20734 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20735 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20736 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20737 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20738 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20739 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20740 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20741 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20742 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20743 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20744 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
|
|
@ -0,0 +1,70 @@
|
|||
FROZEN_HEAD d8eea5f7 igneum-pow IDENTICAL to 017e7037
|
||||
bin 179b77a5bb1e2158004d4044de6d6622cf649ce6e8cc5e69623053e849651274
|
||||
UTC_START 2026-10-07T18:32:17Z
|
||||
### fold confirm
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
fold day=20729 trials=1000000
|
||||
(a) GF(2) affinity violations of the 2-application map: 1000000 of 1000000 (0 would be a BREAK: the map is affine)
|
||||
(b) dead (in_word -> out_word) pairs over the full 8-application block: 0 of 256 (any would be a broken dependency)
|
||||
(c) key-order agreements M(M(.,rk1),rk2) == M(M(.,rk2),rk1): 0 of 1000000 (any would let keys fold)
|
||||
VERDICT: BOUND: no fold on these probes
|
||||
### integral apps=1
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
integral day=20729 apps=1 placements_per_d=4000 threads=48
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 4000/4000 = 1.0000 mean out-bits set 236.1/512 [degree >= d reached]
|
||||
d= 2 nonzero 4000/4000 = 1.0000 mean out-bits set 185.4/512 [degree >= d reached]
|
||||
d= 3 nonzero 4000/4000 = 1.0000 mean out-bits set 174.6/512 [degree >= d reached]
|
||||
d= 4 nonzero 4000/4000 = 1.0000 mean out-bits set 172.3/512 [degree >= d reached]
|
||||
d= 5 nonzero 4000/4000 = 1.0000 mean out-bits set 172.5/512 [degree >= d reached]
|
||||
d= 6 nonzero 4000/4000 = 1.0000 mean out-bits set 172.3/512 [degree >= d reached]
|
||||
d= 7 nonzero 4000/4000 = 1.0000 mean out-bits set 174.6/512 [degree >= d reached]
|
||||
d= 8 nonzero 4000/4000 = 1.0000 mean out-bits set 174.7/512 [degree >= d reached]
|
||||
d= 9 nonzero 4000/4000 = 1.0000 mean out-bits set 176.1/512 [degree >= d reached]
|
||||
d=10 nonzero 4000/4000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
|
||||
d=11 nonzero 4000/4000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
|
||||
d=12 nonzero 4000/4000 = 1.0000 mean out-bits set 183.6/512 [degree >= d reached]
|
||||
d=13 nonzero 4000/4000 = 1.0000 mean out-bits set 187.3/512 [degree >= d reached]
|
||||
d=14 nonzero 4000/4000 = 1.0000 mean out-bits set 191.5/512 [degree >= d reached]
|
||||
d=15 nonzero 4000/4000 = 1.0000 mean out-bits set 196.4/512 [degree >= d reached]
|
||||
d=16 nonzero 4000/4000 = 1.0000 mean out-bits set 203.1/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
### integral apps=2
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
integral day=20729 apps=2 placements_per_d=4000 threads=48
|
||||
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
|
||||
d= 1 nonzero 4000/4000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d= 2 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 3 nonzero 4000/4000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 4 nonzero 4000/4000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
d= 5 nonzero 4000/4000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
|
||||
d= 6 nonzero 4000/4000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 7 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d= 8 nonzero 4000/4000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
|
||||
d= 9 nonzero 4000/4000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
|
||||
d=10 nonzero 4000/4000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=11 nonzero 4000/4000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
|
||||
d=12 nonzero 4000/4000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=13 nonzero 4000/4000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
|
||||
d=14 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=15 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
|
||||
d=16 nonzero 4000/4000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
|
||||
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
|
||||
### diffusion spot K=1,2
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=1 start=0 states=2000000 threads=48
|
||||
mean output-flip probability over all 262144 cells: 0.461179 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 551 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 112032 of 262144
|
||||
worst cell: in_bit 29 -> out_bit 76 p = 1.000000 dev = 0.500000 (1414.2 sigma)
|
||||
VERDICT: FINDING (holes or strong bias at this K)
|
||||
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
|
||||
diffusion day=20729 plant=none apps=2 start=0 states=2000000 threads=48
|
||||
mean output-flip probability over all 262144 cells: 0.500001 (ideal 0.5)
|
||||
census band: 8 sigma = 0.002828 (2000000 states)
|
||||
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
|
||||
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
|
||||
worst cell: in_bit 203 -> out_bit 42 p = 0.501711 dev = 0.001711 (4.8 sigma)
|
||||
VERDICT: no distinguisher at this K
|
||||
UTC_END 2026-10-07T18:34:01Z
|
||||
|
|
@ -0,0 +1,5 @@
|
|||
start igneum-build-1 2026-10-07T18:50:38Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
|
||||
== fold-sweep-1024d 2026-10-07T18:50:38Z
|
||||
rc=0
|
||||
VERDICT: BOUND: no fold on any day or pair probed
|
||||
end 2026-10-07T18:52:02Z
|
||||
|
|
@ -0,0 +1,6 @@
|
|||
start igneum-build-2 2026-10-07T18:50:34Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
|
||||
== integral-a1-32d 2026-10-07T18:50:34Z
|
||||
rc=0
|
||||
== integral-a2-32d 2026-10-07T18:52:24Z
|
||||
rc=0
|
||||
end 2026-10-07T18:54:55Z
|
||||
|
|
@ -0,0 +1,50 @@
|
|||
start igneum-build-1 2026-10-07T18:50:38Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
|
||||
== lineindex-k1 2026-10-07T18:50:38Z
|
||||
rc=0
|
||||
VERDICT: FINDING (address bits predictable at this K)
|
||||
== lineindex-k2 2026-10-07T18:50:53Z
|
||||
rc=0
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
== lineindex-k3 2026-10-07T18:51:14Z
|
||||
rc=0
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
== lineindex-k4 2026-10-07T18:51:33Z
|
||||
rc=0
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
== linrel-addr-a1-8d 2026-10-07T18:51:53Z
|
||||
rc=0
|
||||
linrel day=20729 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20730 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20731 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20732 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20733 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20734 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20735 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20736 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
== linrel-addr-a2-8d 2026-10-07T18:51:54Z
|
||||
rc=0
|
||||
linrel day=20729 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20730 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20731 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20732 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20733 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20734 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20735 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
linrel day=20736 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
|
||||
end 2026-10-07T18:51:55Z
|
||||
|
|
@ -0,0 +1,108 @@
|
|||
start igneum-build-2 2026-10-07T18:50:34Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
|
||||
== linrel-full-a1-16d 2026-10-07T18:50:34Z
|
||||
rc=0
|
||||
linrel day=20729 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20733 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20734 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20735 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20736 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20737 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20738 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20739 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20740 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20741 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20742 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20743 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20744 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== linrel-full-a2-16d 2026-10-07T18:50:37Z
|
||||
rc=0
|
||||
linrel day=20729 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20733 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20734 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20735 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20736 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20737 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20738 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20739 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20740 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20741 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20742 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20743 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20744 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== linrel-full-a8-16d 2026-10-07T18:50:39Z
|
||||
rc=0
|
||||
linrel day=20729 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20733 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20734 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20735 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20736 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20737 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20738 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20739 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20740 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20741 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20742 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20743 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20744 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== cnf-commute-20729 2026-10-07T18:50:44Z
|
||||
rc=0
|
||||
cnf day=20729 vars=105652 clauses=361188 written /srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf
|
||||
BLOCKED on the solve: no SAT solver reaches the box (crates.io refused, none installed); the model is the artefact
|
||||
end 2026-10-07T18:50:44Z
|
||||
|
|
@ -0,0 +1,69 @@
|
|||
start igneum-build-2 2026-10-07T18:57:10Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
|
||||
== fold-sweep-1024d 2026-10-07T18:57:10Z
|
||||
rc=0
|
||||
VERDICT: BOUND: no fold on any day or pair probed
|
||||
== linrel-full-a3-4d 2026-10-07T18:58:29Z
|
||||
rc=0
|
||||
linrel day=20729 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== linrel-full-a4-4d 2026-10-07T18:58:30Z
|
||||
rc=0
|
||||
linrel day=20729 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== linrel-full-a5-4d 2026-10-07T18:58:31Z
|
||||
rc=0
|
||||
linrel day=20729 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== linrel-full-a6-4d 2026-10-07T18:58:31Z
|
||||
rc=0
|
||||
linrel day=20729 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== linrel-full-a7-4d 2026-10-07T18:58:32Z
|
||||
rc=0
|
||||
linrel day=20729 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20730 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20731 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
linrel day=20732 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
|
||||
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
|
||||
== integral-a8-4d 2026-10-07T18:58:33Z
|
||||
rc=0
|
||||
== lineindex-k5 2026-10-07T18:58:42Z
|
||||
rc=0
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
== lineindex-k6 2026-10-07T18:58:56Z
|
||||
rc=0
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
== lineindex-k7 2026-10-07T18:59:14Z
|
||||
rc=0
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
== lineindex-k8 2026-10-07T18:59:42Z
|
||||
rc=0
|
||||
VERDICT: no address-bit distinguisher at this K
|
||||
end 2026-10-07T19:00:02Z
|
||||
337
docs/analysis/cryptanalysis/report-mixer.md
Normal file
337
docs/analysis/cryptanalysis/report-mixer.md
Normal file
|
|
@ -0,0 +1,337 @@
|
|||
# Report: adversarial cryptanalysis of the mixer M_r
|
||||
|
||||
Internal adversarial pass, not an independent review.
|
||||
|
||||
The label "internal adversarial pass, not an independent review" applies to every sentence here that could be
|
||||
quoted in public. This is such a pass. It is not an outside review.
|
||||
|
||||
## Header
|
||||
|
||||
| Field | Value |
|
||||
|---|---|
|
||||
| Target commit | 017e70376489251e18564c0abce7e466e606c8b3 (class v4 sub-version 3, object byte 7) |
|
||||
| Target | the mixer M_r (spec 01 section 1.8.4): 8 keyed applications between reads, 72 per item, class v4 (m = 8) |
|
||||
| Lane | adv-mixer, narrowed by main (19:2x BST) to the ALGEBRAIC STRUCTURE of M_r (Q1); Q2 is adv-mixer-3, Q3 is adv-mixer-2 |
|
||||
| Branch | adv-mixer; working HEAD d8eea5f7 (merge of build/master 04c4d9bc) |
|
||||
| Byte-identity | after the merge, `git diff --quiet 017e70376489251e18564c0abce7e466e606c8b3 HEAD -- igneum-pow` prints IDENTICAL: the whole crate is the frozen object. The branch was first cut from stale master 3f0afcd5 whose igneum-pow differed in 6 non-mixer files; those pre-merge runs were re-run on the merged tree and match (see below) |
|
||||
| Harness attack-adv-mixer (merged) | sha256 179b77a5bb1e2158004d4044de6d6622cf649ce6e8cc5e69623053e849651274 |
|
||||
| Harness attack-f4 census (stale, mixer-identical) | sha256 d51df6caab338b0165485c3ce6d6379c0af7180bf2b72fc0a1531beabeaf2d22 |
|
||||
| Boxes | igneum-build-2 (box 2) and igneum-build-1 (box 1), nice 10 |
|
||||
| Toolchain | rustc 1.99.0 both sides |
|
||||
| Day under test | chain day index 20729 (genesis, 3 October 2026), bind::day_bytes(20729) |
|
||||
| Clock | plan pushed 19:09 BST; first results in this report 19:40 BST (ask line 00:00 BST); times are TZ=Europe/London |
|
||||
|
||||
## Status board
|
||||
|
||||
| Q | Lane | Method | Known-failed shape | Gate | Result (numbers) | Status |
|
||||
|---|---|---|---|---|---|---|
|
||||
| Q1 algebraic structure | adv-mixer (this) | fold probes (1024 days x 71 key pairs), exact GF(2) affine-relation kernel at full width, integral cube-sum degree (32 days), the 22 line-index bits, a SAT model of two applications | the probes are their own control; the diffusion plant fired | affinity violations > 0, dead pairs = 0, key agreements = 0, kernel = 0, degree saturates | 1,454,080,000/1,454,080,000 affinity violations, 0 dead word pairs, 0 key-order agreements over 1024 days; kernel 0 at K = 1, 2, 8 on 16 days (full width) and on the address bits; degree >= 16 after 1 application and saturated after 2 on 32 days; address bits clean from K = 2 | PASS (BOUND: no composition cheaper than 8x; 9,360 ops per item stand) |
|
||||
| Q2 round margin | adv-mixer-3 (courtesy run here) | diffusion avalanche census K=1..8, 2e6 states | diffusion --plant weak (fired) | full diffusion at K | distinguisher reaches K=1 only; K=2..8 clean (0 holes, 0 strong, worst 4.5 to 4.9 sigma) | BOUND (handed to adv-mixer-3) |
|
||||
| Q3 weak draws | adv-mixer-2 (courtesy run here) | f4 census over 2^24 days | plant alleq/mul1/mul1all/rc0/rcrk0 (all fired) | any class >= 1.1x on a non-negligible fraction | M1 cost 197 to 263, mean 231.1; best day a 1.17x smaller FPGA multiply datapath, 1 day in 2^24; 0 days DSP or wall-time gain; ROT-all-equal never seen | BOUND+tail (handed to adv-mixer-2) |
|
||||
|
||||
## Q1: the algebraic structure of M_r (BOUND: no composition cheaper than 8x)
|
||||
|
||||
The question. The 8 keyed applications between two cache reads differ only in the round key rk. Can they be
|
||||
evaluated in fewer than 8x one application, by folding or commuting the multiply layer, by a surviving
|
||||
differential, linear or rotational property of the drawn double round, or by a low-degree algebraic form of the
|
||||
composition? Any gain is priced in ops per item against the chip model's 9,360 (hoisted, m = 8).
|
||||
|
||||
Two measurements, both on the frozen-identical binary (sha 179b77a5), day 20729.
|
||||
|
||||
### Fold probe
|
||||
|
||||
Command (box 1):
|
||||
```
|
||||
nice -n 10 attack-adv-mixer fold --day 20729 --trials 1000000
|
||||
```
|
||||
|
||||
| Probe | Result | Reading |
|
||||
|---|---|---|
|
||||
| (a) GF(2) affinity of the 2-application map g | 1,000,000 of 1,000,000 quadruples violate g(a)+g(b)+g(c)+g(a+b+c)=g(0) | g is maximally far from affine; the two multiply layers do not fold through the double round |
|
||||
| (b) dead (in_word, out_word) pairs over the full 8-application block | 0 of 256 | every output word depends on every input word; no separability to split on |
|
||||
| (c) key-order agreements M(M(.,rk1),rk2) == M(M(.,rk2),rk1) | 0 of 1,000,000 | key order matters; the 8 round keys cannot be folded or commuted |
|
||||
|
||||
### Integral (algebraic-degree) cube-sum test
|
||||
|
||||
Command (box 1):
|
||||
```
|
||||
nice -n 10 attack-adv-mixer integral --day 20729 --apps 1 --dmax 16 --placements 4000 --threads 48
|
||||
nice -n 10 attack-adv-mixer integral --day 20729 --apps 2 --dmax 16 --placements 4000 --threads 48
|
||||
```
|
||||
For each cube dimension d the harness XOR-sums the output over all 2^d flips of d random input bits, over 4000
|
||||
random placements. A zero sum on every output bit would prove algebraic degree < d (a low-degree form a shortcut
|
||||
could exploit). The result:
|
||||
|
||||
| Applications | d = 1..16 | Cube-sum nonzero fraction | Mean output bits set per cube-sum | Reading |
|
||||
|---|---|---|---|---|
|
||||
| 1 | every d | 1.0000 at every d | 172 to 236 of 512 | degree >= 16 already after one application |
|
||||
| 2 | every d | 1.0000 at every d | about 256 of 512 (half) | saturated: two applications look like a random high-degree map up to degree 16 |
|
||||
|
||||
Verdict for Q1. No composition cheaper than 8x was found. The multiply layers of adjacent applications are
|
||||
separated by a nonlinear double round and do not merge (fold probe a). The drawn double round gives no
|
||||
commutation that would fold keys (fold probe c). The word-dependency is complete at 8 applications (fold probe
|
||||
b). The algebraic degree reaches at least 16 after a single application and saturates after two, so there is no
|
||||
low-degree algebraic or integral form of even one application, let alone the 8, that an attacker could batch. The
|
||||
8 keyed applications cost 8x on this evidence. Priced against the chip model: 0 ops saved per item; the 9,360 ops
|
||||
per item stand. This is a BOUND, not a proof: the integral test reaches degree 16 (2^16 cube), and the fold
|
||||
probe is GF(2)-degree-1; an exact algebraic-degree measurement above 16 and a SAT or MILP algebraic form are owed
|
||||
work. One line on what a longer pass would add: it would pin the exact degree above 16 and rule out a
|
||||
medium-degree (17 to 40) relation the cube test at d = 16 cannot see; it would not change the no-fold bound.
|
||||
|
||||
## Q2: the round margin (courtesy run; lane adv-mixer-3)
|
||||
|
||||
Command (box 2), per K in 1..8:
|
||||
```
|
||||
nice -n 10 attack-adv-mixer diffusion --day 20729 --apps K --states 2000000 --threads 32
|
||||
```
|
||||
Log: docs/analysis/cryptanalysis/logs/adv-mixer/diffusion-K1-8.log (copied off the box). Census band at 2e6 states is 8
|
||||
sigma = 0.00283, so a per-cell bias below 0.28 percent is invisible; quoted with the result.
|
||||
|
||||
| K applications | Dependency holes | Strong-bias cells (> 8 sigma) | Worst cell | Verdict |
|
||||
|---|---|---|---|---|
|
||||
| 1 | 578 of 262144 | 111997 of 262144 | 1414 sigma | distinguisher reaches K=1 |
|
||||
| 2 | 0 | 0 | 4.8 sigma | clean |
|
||||
| 3 | 0 | 0 | 4.6 sigma | clean |
|
||||
| 4 | 0 | 0 | 4.7 sigma | clean |
|
||||
| 5 | 0 | 0 | 4.9 sigma | clean |
|
||||
| 6 | 0 | 0 | 4.6 sigma | clean |
|
||||
| 7 | 0 | 0 | 4.5 sigma | clean |
|
||||
| 8 | 0 | 0 | 4.8 sigma | clean |
|
||||
|
||||
The plant fired: the degenerate day (MUL all 1, RC all 0, ROT all 16) at K=1 gave 7894 holes and 236269 strong
|
||||
cells, worst 223.6 sigma. Reading: the strict-avalanche distinguisher reaches only 1 application. Full diffusion
|
||||
at 2 applications. Margin against the 8 between reads: 6 applications (8 minus 2). Margin against the 72 per item:
|
||||
70. This is an avalanche census, not a trail search; a bias below 0.28 percent at K=2 is invisible. The
|
||||
differential, linear, rotational-XOR and SAT/MILP tightening is adv-mixer-3's lane; handed over.
|
||||
|
||||
## Q3: weak parameter draws (courtesy run; lane adv-mixer-2)
|
||||
|
||||
Command (box 2):
|
||||
```
|
||||
nice -n 10 taskset -c 64-95 attack-f4 census --from 20729 --count 16777216 --threads 32
|
||||
```
|
||||
16,777,216 days (2^24), 4.4 s. Log: docs/analysis/cryptanalysis/logs/adv-mixer/census-2pow24.log (copied off the box).
|
||||
|
||||
The M1 metric is the per-day FPGA LUT datapath adder count, 64 + sum(NAF(MUL_i) - 1). Convention-free facts over
|
||||
2^24 days:
|
||||
|
||||
| Quantity | Value |
|
||||
|---|---|
|
||||
| M1 cost range | 197 (day 4819563) to 263 (day 15262713) |
|
||||
| M1 cost mean, sd | 231.1, 6.19 |
|
||||
| Best attacker day | multiply datapath 197/231.1 = 0.853 of mean, a 1.17x smaller datapath, on 1 day in 2^24 |
|
||||
| Days with any M2 (DSP-bound) gain, k >= 2 | 0 |
|
||||
| Days with a ROT or RC wall-time gain | 0 (bit-exact verifier; ROT is wiring, RC is inverters) |
|
||||
| ROT all equal (the spec's untested worry) | 0 of 2^24 (analytic 1 in 2.751e10 days) |
|
||||
| MUL any = 1, MUL two equal, RC any = 0 | 0, 0, 0 |
|
||||
|
||||
Open cross-check for the Q3 lane owner: the census computes the over-1.1x count against its own measured median
|
||||
231 (5476 days, 3.26e-4), while the analytic `expect` tool reports a reference median 221 and an over-1.1x
|
||||
fraction near 8.6e-7 (about 14.5 days in 2^24). The two references differ by 10 adders; the convention-free range
|
||||
above does not depend on the choice. Reconciling the median is handed to adv-mixer-2. Either way the best day is a
|
||||
1.17x FPGA-datapath gain the chip model does not credit as hash rate (the chip is bound by the 8 cache reads and
|
||||
the fixed op count, not by one day's multiply-adder count), and a weak day is a public calendar.
|
||||
|
||||
## Q1 deepening (from 19:4x BST): more days, all key pairs, exact relations, the address bits, a SAT model
|
||||
|
||||
Main's re-scope asked for the probes at full 32-bit width over more days and more rk pairs, a SAT model of two
|
||||
keyed applications for an algebraic relation, and a relation search in the s[0] line-index bits. Binary sha256
|
||||
bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 (frozen-identical tree, same bytes on both
|
||||
boxes). Queue files tools/attack/adv-mixer/queue/11..14, claimed in /srv/builds/_adv/mixer/claims. Logs under
|
||||
/srv/builds/_adv-adv-mixer/logs on each box, copied into docs/analysis/cryptanalysis/logs/adv-mixer when done.
|
||||
|
||||
### Exact affine-relation search at full width (linrel), queue 14, box 2
|
||||
|
||||
Command: `attack-adv-mixer linrel --day 20729 --apps K --samples 8192 --days 16` for K in 1, 2, 8. Each sample
|
||||
is a GF(2) row over 1025 columns (512 input bits, 512 output bits, the constant). Rank 1025 means no exact
|
||||
affine relation a.x XOR b.y = c exists between the input and output bits of K applications; a chance survivor
|
||||
has odds 2^-(8192-1025) = 2^-7167.
|
||||
|
||||
| Applications K | Days (20729 to 20744) | Rank | Kernel dimension | Reading |
|
||||
|---|---|---|---|---|
|
||||
| 1 | 16 of 16 | 1025 | 0 | no affine relation after one application |
|
||||
| 2 | 16 of 16 | 1025 | 0 | no affine relation after two |
|
||||
| 3, 4, 5, 6, 7 (queue 15) | 4 of 4 each (20729 to 20732) | 1025 | 0 | no affine relation at any intermediate count |
|
||||
| 8 | 16 of 16 | 1025 | 0 | no affine relation across the full between-reads block |
|
||||
|
||||
This is the decidable algebraic probe the brief's "algebraic form" question needs: at full width with the real
|
||||
day constants there is no linear or affine structure a chip could use to batch or predict the 8 applications.
|
||||
|
||||
### The line-index bits of s[0] (lineindex), queue 13, box 1
|
||||
|
||||
Command: `attack-adv-mixer lineindex --day 20729 --apps K --states 1000000 --threads 44`. The 22 address bits
|
||||
(s[0] AND 2^22-1) against each of the 512 input bits; band 8 sigma = 0.004 at 1e6 states.
|
||||
|
||||
| K | Mean address-bit flip | Holes / 11264 | Strong cells / 11264 | Worst cell | Verdict |
|
||||
|---|---|---|---|---|---|
|
||||
| 1 | 0.4275 | 70 | 6904 | 1000 sigma | FINDING: address bits predictable after one application |
|
||||
| 2 | 0.500007 | 0 | 0 | 3.9 sigma | clean |
|
||||
| 3 | 0.5000 | 0 | 0 | inside band | clean |
|
||||
| 4 | 0.499998 | 0 | 0 | 3.8 sigma | clean |
|
||||
| 5 | 0.5000 | 0 | 0 | 4.3 sigma | clean (queue 15) |
|
||||
| 6 | 0.5000 | 0 | 0 | 4.7 sigma | clean (queue 15) |
|
||||
| 7 | 0.5000 | 0 | 0 | 3.6 sigma | clean (queue 15) |
|
||||
| 8 | 0.5000 | 0 | 0 | 3.7 sigma | clean (queue 15) |
|
||||
|
||||
The address bits are clean at every application count from 2 to 8, the full between-reads block.
|
||||
|
||||
Address-restricted exact relation search, `linrel --addr --apps K --samples 8192 --days 8` (535 columns: 512
|
||||
input bits, the 22 address bits, the constant):
|
||||
|
||||
| K | Days (20729 to 20736) | Rank | Kernel | Reading |
|
||||
|---|---|---|---|---|
|
||||
| 1 | 8 of 8 | 535 | 0 | no affine relation to the address bits even after one application |
|
||||
| 2 | 8 of 8 | 535 | 0 | none after two |
|
||||
|
||||
Reading for the chip: the line index a read depends on is not predictable before the second of the 8
|
||||
applications completes, so a prefetch cannot hide more than 1 of the 8 applications behind the memory latency.
|
||||
The K=1 predictability is incomplete diffusion (holes and strong cells), not a linear leak: no affine relation
|
||||
between the input and the address bits exists even at K=1.
|
||||
|
||||
### Fold probes over 1024 days and all 71 adjacent key pairs (fold-sweep), queue 11, box 1
|
||||
|
||||
Command: `attack-adv-mixer fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44`: probes (a) and
|
||||
(c) on every adjacent application pair (i, i+1) for i in 0..70 and probe (b) on the full block, per day. 1024
|
||||
days x 71 pairs x 20,000 trials = 1,454,080,000 pair-trials. Wall 84 s on box 1 at load about 400.
|
||||
|
||||
| Probe | Result over 1024 days and 71 pairs | Reading |
|
||||
|---|---|---|
|
||||
| (a) affinity violations | 1,454,080,000 of 1,454,080,000; lowest per-pair violation fraction 1.000000 | no adjacent pair of applications is affine on any day |
|
||||
| (b) dead word pairs, summed over 1024 days | 0 | complete word dependency every day |
|
||||
| (c) key-order agreements | 0 of 1,454,080,000 | no key pair commutes on any day |
|
||||
|
||||
Verdict: the fold bound of the first report holds at every one of the 71 between-application seams, on every
|
||||
one of 1024 consecutive chain days (about 2.8 years of calendar). No fold, no commutation, no separability.
|
||||
|
||||
### Integral degree test over 32 days (integral), queue 12, box 2
|
||||
|
||||
Command: `attack-adv-mixer integral --day 20729 --apps K --dmax 16 --placements 2000 --days 32` for K = 1, 2.
|
||||
32 consecutive chain days (20729 to 20760), cube dimensions d = 1..16, 2000 placements each: 512 (day, d) rows
|
||||
per K. Wall about 4 min on box 2 at load about 500.
|
||||
|
||||
| Applications K | Rows with every cube-sum nonzero | Output bits set per cube-sum (min to max over days) | Reading |
|
||||
|---|---|---|---|
|
||||
| 1 | 511 of 512 (the one exception: day 20730, d = 4, 1999 of 2000 placements) | 156 to 245 of 512 | degree >= 16 on every day; the single zero cube-sum in 1,024,000 placements is a chance zero, not a relation (a relation would zero every placement) |
|
||||
| 2 | 512 of 512 | 255.5 to 256.7 of 512 | saturated at the random-map value of 256 on every day |
|
||||
|
||||
Verdict: the degree floor of the first report (>= 16 after one application, saturated after two) holds on
|
||||
32 consecutive days. No day has a low-degree algebraic form of the applications. Queue 15 added the full
|
||||
8-application block on 4 days (d = 1..14, 2000 placements): 56 of 56 rows at fraction 1.0000, 255.6 to 256.4
|
||||
bits set, saturated.
|
||||
|
||||
### Queue 15, the per-K fill and a cross-box replication (box 2)
|
||||
|
||||
Queue file 15 re-ran the 1024-day fold-sweep first (its header slice carried that line over from file 11), which
|
||||
makes a replication on the other box: 1,454,080,000 of 1,454,080,000 affinity violations, 0 dead word pairs,
|
||||
0 key-order agreements, identical to box 1 (log fold-sweep-1024d-box2-replication.log). Then linrel at K = 3..7,
|
||||
integral at K = 8 and lineindex at K = 5..8, all folded into the tables above. Wall 2 min 52 s at load about 500.
|
||||
|
||||
### SAT model of two keyed applications (cnf), queue 14 then a solve on box 2
|
||||
|
||||
Command: `attack-adv-mixer cnf --day 20729 --out .../adv-mixer-commute-20729.cnf`. Bit-exact Tseitin encoding
|
||||
of M(M(x,rk1),rk2) and M(M(x,rk2),rk1) on a shared 512-variable input with the two outputs constrained equal:
|
||||
105,652 variables, 361,188 clauses, 6.8 MB. SAT = a state on which the two key orders commute; UNSAT = a proof
|
||||
over all 2^512 states that fold probe (c) holds exactly. No solver reaches the box from crates.io (HTTP 403), so
|
||||
the harness marks the solve BLOCKED; the sibling lane adv-mixer-3 has cadical 3.0.1 built from source on box 2,
|
||||
and that binary is running on this instance under a one-hour cap at nice 10 (log sat-commute-20729.log).
|
||||
KILLED at 20:20 BST under main's rule that every hand-started sweep stops and re-queues through `lease pool`:
|
||||
cadical ran 1,749 s wall on one thread (162 MB peak) and reached neither SAT nor UNSAT, which was the expected
|
||||
outcome inside the hour: the instance is a preimage-shaped search on a 2^512 space, so a cap-out bounds solver
|
||||
reach only and is no evidence either way. The CNF stays on box 2 at
|
||||
/srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf (6.8 MB) for a re-queue through `lease pool` once
|
||||
that subcommand exists (at 20:21 BST `lease --help` offered `lease cores` and `lease status` only). Re-queued
|
||||
through `lease pool 1` at 20:22 BST the minute the subcommand landed (log sat-commute-20729-lease.log), then
|
||||
RELEASED at 20:41 BST on main's order so the class v5 census (owner class-v5, 88 cores, the 0.3.24 critical path)
|
||||
can take box 2's pool: 1,106 s run, no SAT or UNSAT. Two cadical runs total 2,855 s of solving on this instance
|
||||
with no decision, which is the expected shape for a preimage-sized search. Re-queued a third time at 21:13 BST
|
||||
when main opened box 2 (log sat-commute-20729-lease2.log, core 9, cap to 22:13 BST). RUNNING; the row lands
|
||||
here.
|
||||
|
||||
## Q1 consolidated verdict (internal adversarial pass, not an independent review)
|
||||
|
||||
Across every probe this lane ran at full 32-bit width with the real day constants, no composition of the 8
|
||||
keyed applications between two cache reads costs less than 8 times one application.
|
||||
|
||||
| Candidate shortcut from the brief | Evidence | Status |
|
||||
|---|---|---|
|
||||
| The multiply layer folds or commutes across applications (only rk changes) | adjacent-pair affinity violated on 1,454,080,000 of 1,454,080,000 trials over 1024 days and all 71 seams; key-order commutation 0 of 1,454,080,000 | ruled out at the probe's reach |
|
||||
| An exact linear or affine relation across the composition | GF(2) kernel 0 (rank 1025 of 1025) at K = 1, 2 and 8 on 16 days; kernel 0 on the 22 address bits at K = 1 and 2 | ruled out exactly (chance survivor 2^-7167) |
|
||||
| A low-degree algebraic form to batch the applications | cube-sums nonzero at every d up to 16 after one application, saturated at 256 of 512 bits after two, on 32 days | ruled out below degree 16; above 16 is owed |
|
||||
| A predictable line index that lets a chip prefetch the read early | address bits predictable only after 1 application (incomplete diffusion, no linear leak); clean from K = 2 | at most 1 of 8 applications hides behind the memory latency |
|
||||
| An exact commutation witness (SAT model) | 105,652-variable, 361,188-clause instance; cadical 3.0.1 running under a 1 h cap | pending; a timeout bounds solver reach only |
|
||||
|
||||
Priced against the chip model: 0 ops saved per item; 9,360 ops per item stand. What a longer pass would add:
|
||||
an exact algebraic-degree measurement above 16 (the cube test stops at 2^16 points) and a solver run long
|
||||
enough to decide the commutation instance; neither would move the fold or the affine bound, which are exact or
|
||||
exhaustive at their reach. The probes cover 1024 consecutive chain days from genesis, about 2.8 years of the
|
||||
public calendar.
|
||||
|
||||
## Sibling queue files run by this lane
|
||||
|
||||
Per main's rule (claim the next unclaimed sibling file in name order once the own queue is empty), this lane
|
||||
claimed and ran the following. The results belong to the owning lane and are not interpreted here.
|
||||
|
||||
| File | Owner | Claimed | Run on | Result |
|
||||
|---|---|---|---|---|
|
||||
| 07-adv-mixer-3-days.sh | adv-mixer-3 | 19:54 BST | box 1, nice 10, cores 8-95 | KILLED 20:20 BST under main's rule after 6 of 56 steps (index day 20730 k = 2, 3, 4, 8; sac day 20730 k = 2, 3; every one "uniform within the band" or clean per the owner's grep); my claim released so the owner or any lane re-queues it through the lease; the owner's logs stay in /srv/builds/_adv-mixer-3/logs |
|
||||
|
||||
## Confirmation across the stale and frozen trees
|
||||
|
||||
The branch was first cut from stale master 3f0afcd5. Its igneum-pow differed from the frozen object in six
|
||||
non-mixer files (accept.rs, emit.rs, generator.rs, packcheck.rs, tests/mixer.rs, tests/recheck.rs); memhard.rs,
|
||||
seed.rs, bind.rs, derive.rs and the Cargo pin were byte-identical. After `git merge build/master` the whole crate
|
||||
is byte-identical to 017e7037 (IDENTICAL). The Q1 fold and the K=1 and K=2 diffusion spot-checks were re-run on
|
||||
the merged binary and match the stale runs within sampling noise (K=1 holes 551 merged vs 578 stale, K=2 clean on
|
||||
both). So the stale-tree Q2 and Q3 numbers coincide with the frozen object. The self-check asserts the spec 1.8.4
|
||||
genesis ROT, MUL and RC vectors on every run.
|
||||
|
||||
## Box-hours and pod-hours spent
|
||||
|
||||
No GPU pods used: pod-hours 0. All CPU, nice 10, both boxes.
|
||||
|
||||
| Step | Box | Wall |
|
||||
|---|---|---|
|
||||
| Builds (adv-mixer x2, f4 x2) | box 1 and 2 | about 1.5 min total |
|
||||
| f4 five plant firings | box 2 | about 3 min |
|
||||
| f4 census 2^24 | box 2 | 4.4 s |
|
||||
| f4 expect analytic tail | box 1 | a few min (log later wiped by a box re-sync; numbers captured) |
|
||||
| Q2 diffusion sweep K=1..8, 2e6 states | box 2 | 11 min |
|
||||
| Q1 fold + integral + spot-checks | box 1 | 1 min 44 s |
|
||||
|
||||
| Q1 deepening queue 11 fold-sweep 1024 days | box 1 | 84 s |
|
||||
| Q1 deepening queue 12 integral 32 days | box 2 | 4 min 21 s |
|
||||
| Q1 deepening queue 13 lineindex + addr linrel | box 1 | 77 s |
|
||||
| Q1 deepening queue 14 linrel + cnf | box 2 | 10 s |
|
||||
| Q1 deepening queue 15 per-K fill + fold-sweep replication | box 2 | 2 min 52 s |
|
||||
| cadical on the commutation CNF | box 2 | one thread, capped at 1 h |
|
||||
| Sibling 07-adv-mixer-3-days.sh (owner adv-mixer-3) | box 1 | running |
|
||||
|
||||
Total about 0.6 box-hours of the 8-hour first-results budget (ask line 16), plus up to 1 core-hour of cadical.
|
||||
Pod-hours 0. Both boxes ran at load 240 to 555 on 96 cores during the deepening (sibling sweeps, not builds), so
|
||||
wall times above are under heavy sharing.
|
||||
|
||||
## Rule-change timeline (so the box-hours stay honest)
|
||||
|
||||
| Time (BST) | Change | Effect on this lane |
|
||||
|---|---|---|
|
||||
| 19:1x | both boxes, nice 10, drop the single band | adopted; runs moved off a single 32-core band |
|
||||
| 19:2x | three-lane re-scope: this lane is Q1 only | Q2 and Q3 kept as courtesy runs, attributed |
|
||||
| 19:3x | merge build/master, re-prove igneum-pow identical | done, IDENTICAL; pre-merge runs re-run and matched |
|
||||
| 19:3x | drop SIGSTOP yield, run on cores 8-95 only | no yield was ever added; run-box.sh band set to 8-95; direct nohup runs at nice 10 |
|
||||
| 20:20 | main: every hand-started sweep is killed by its pid file now and re-queued through `lease pool`; release builds and the class v5 suites outrank sweeps | killed cadical (box 2, 29 min lost, no result) and sibling 07 (box 1, 6 of 56 steps done, claim released); nothing started since; `lease pool` absent at 20:21, so the re-queue waits on it |
|
||||
| 20:22 | `lease pool` live on both boxes (lease sha f814b447) | cadical re-queued the same minute through `lease pool 1 --owner adv-mixer --nice 10`, core 8, 1 h cap |
|
||||
| 20:41 | main: box 2's pool must show 0 adv-* holders for the class v5 census; the yield to a class-v5 waiter is mechanical at shard end from now | released the cadical lease by pid file; nothing held on either box |
|
||||
| 21:13 | main: box 2 open to adv-* (the class v5 census ended, no pool lease there) | cadical re-queued the same minute as `lease pool 1 --min 1`, core 9 |
|
||||
| 20:4x | pool priority classes (release > v5 > measure > adv, lease sha 5d84d644); a 1-thread holder is never pre-empted; label rule: no "release", "canary", "pair", "v5 gate", "v5 kit" or "measure" in a sweep label | the cadical re-queue keeps its label "adv-mixer cadical commutation CNF day 20729, 1 h cap", which carries none of the reserved words, and goes out as `lease pool 1 --min 1` when main confirms the census is running |
|
||||
| 20:2x | pool rule: a sweep lease asks for at most 48 cores with --min at the least usable; the yield test is by OWNER (refined at 20:3x): yield to a waiter whose owner is class-v5, or whose owner is attack-pass with "v5" in its label, never to a waiter whose owner starts with adv-; on a yield, finish the shard in hand and release; release builds and v5 suites outrank every sweep | adopted for any further lease; the one-core cadical lease is cleared by main to its 21:23 BST cap |
|
||||
|
||||
### Kill ledger (main's rule, 20:20 BST)
|
||||
|
||||
| Process | Box | pid-file | Killed (UTC) | Lost | Re-queue |
|
||||
|---|---|---|---|---|---|
|
||||
| cadical on adv-mixer-commute-20729.cnf | 2 | sat-commute-20729.log.pid | 19:20:41Z | 1,749 s of a 3,600 s cap, no SAT or UNSAT | RE-QUEUED 19:22:46Z (20:22 BST) through `lease pool 1 --owner adv-mixer --nice 10` the minute the subcommand landed; holding 1 pool core, 1 h cap; pid file sat-commute-20729-lease.log.pid |
|
||||
| 07-adv-mixer-3-days.sh (owner adv-mixer-3) | 1 | queue-07-adv-mixer-3-days.sh.log.pid | 19:20:47Z | 50 of 56 steps unrun; the 6 done are in the owner's logs | claim released; owner or next free lane |
|
||||
| cadical, the leased re-run (lease pool 1, core 8) | 2 | sat-commute-20729-lease.log.pid | 19:41:11Z (20:41 BST), main's order so the class v5 census takes box 2's pool | 1,106 s of a fresh 3,600 s cap, no SAT or UNSAT; 2,494 s of cap lost | RE-QUEUED 20:13:28Z (21:13 BST) on main's word that box 2 is open: `lease pool 1 --min 1 --owner adv-mixer --nice 10`, core 9, class adv, 1 h cap to 22:13 BST; pid file sat-commute-20729-lease2.log.pid; a 1-thread holder is never pre-empted |
|
||||
|
||||
Both kills were the wrapper pid from the pid file plus its descendants (one cadical, one adv-mixer-3), TERM then
|
||||
KILL; no process of this lane remained on either box afterwards.
|
||||
226
docs/plans/cryptanalysis/plan-mixer.md
Normal file
226
docs/plans/cryptanalysis/plan-mixer.md
Normal file
|
|
@ -0,0 +1,226 @@
|
|||
# Attack plan: the memory-hard mixer M_r
|
||||
|
||||
Internal adversarial pass, not an independent review.
|
||||
|
||||
Label rule: the phrase "internal adversarial pass, not an independent review" goes on every sentence from this
|
||||
work that could be quoted in public. This is such a pass. It is not an outside review.
|
||||
|
||||
- Target commit: 017e70376489251e18564c0abce7e466e606c8b3 (class v4 sub-version 3, object byte 7).
|
||||
- Branch: adv-mixer, from build/master.
|
||||
- Attacker model: an outsider with the public kit. No defender numbers are read; any defender figure here is
|
||||
derived from the crate or marked unknown.
|
||||
- Author identity in the mixer: the attacker has never worked on the hash code.
|
||||
|
||||
## 0. The byte-identity check (the brief's gate 1)
|
||||
|
||||
The brief asks that `git diff --stat 017e7037... HEAD -- igneum-pow` print nothing. It does NOT print nothing.
|
||||
Six files differ between the frozen commit and build/master HEAD:
|
||||
|
||||
| File | In the target? |
|
||||
|---|---|
|
||||
| igneum-pow/src/accept.rs | No (program acceptance, not the mixer) |
|
||||
| igneum-pow/src/emit.rs | No (kernel emitters) |
|
||||
| igneum-pow/src/generator.rs | No (program generator; V4_CLASS and Shape present on both) |
|
||||
| igneum-pow/src/packcheck.rs | No (pack checker) |
|
||||
| igneum-pow/tests/mixer.rs | No (test harness) |
|
||||
| igneum-pow/tests/recheck.rs | No (test harness) |
|
||||
|
||||
The mixer itself is byte-identical. `git diff --stat 017e7037... HEAD -- igneum-pow/src/memhard.rs
|
||||
igneum-pow/src/seed.rs igneum-pow/src/bind.rs igneum-pow/src/derive.rs igneum-pow/Cargo.toml
|
||||
igneum-pow/Cargo.lock` prints nothing. So the mixer draw code (seed.rs), the mixer function and the item
|
||||
derivation (memhard.rs), the day rule (bind.rs) and the dependency pin (Cargo.toml, Cargo.lock) are the frozen
|
||||
ones. The harness builds against build/master's igneum-pow, whose generator.rs and accept.rs differ from frozen;
|
||||
those files are not M_r. So the numbers this harness produces are the frozen mixer's numbers. Stated plainly:
|
||||
build/master is NOT byte-identical to the frozen commit over the whole crate, but it IS byte-identical over every
|
||||
file that defines M_r and its parameters.
|
||||
|
||||
## 1. The target, in the attacker's words
|
||||
|
||||
The dataset item is 16 words of 32 bits. The mixer M is one keyed round made of two layers.
|
||||
|
||||
1. Multiply layer, per word: `s[i] = (s[i] XOR (RC[i] + rk)) * MUL[i]`. MUL[i] is odd, so the multiply is a
|
||||
bijection on 32 bits. rk is the 32-bit round key, the only thing that changes between applications.
|
||||
2. Diffusion layer: one ChaCha-shaped double round. Four column quarter rounds with rotations ROT[0..3], then
|
||||
four diagonal quarter rounds with ROT[4..7]. A quarter round is add, xor, rotate, four times.
|
||||
|
||||
Per item, class v4 (`mixer_mult = 8`): init the state from the day key and `t`, then for each of 8 rounds apply
|
||||
M eight times (keys `round_key(r*8 + j)`, j = 0..7) and do one dependent cache read; after the last read apply M
|
||||
eight more times. 9 x 8 = 72 applications per item. Only the round key changes between the 72. ROT (8 values in
|
||||
1..31), MUL (16 odd values), RC (16 values) are drawn once per day from one SplitMix64 stream seeded with
|
||||
`K[0] | (K[1] << 32)`, K the day key.
|
||||
|
||||
The day key is `seed_words_from_bytes("igneum-day/" || day_le64)` on the chain (interim rule, `bind::day_bytes`),
|
||||
or `seed_words("day/" + iso)` in the spec's examples. The day is a pure function of the calendar day, so a weak
|
||||
day is a public calendar.
|
||||
|
||||
The round key is `round_key(k) = (k + 1) * 0x9E3779B9 mod 2^32`. The 72 keys are the first 72 odd-ish multiples
|
||||
of 0x9E3779B9. They are fixed, not drawn.
|
||||
|
||||
The cost model (chip-model-v3.md, read sections 1, 2, 5, 6): 130 ops per application hoisted, 9,360 ops per item,
|
||||
1,198,080 ops per hash at m = 8. A shortcut is priced in ops per item against 9,360.
|
||||
|
||||
## 2. The questions, in attack order
|
||||
|
||||
The order is cheapest-reproducible first, then the structural questions.
|
||||
|
||||
| Rank | Q | What a result looks like |
|
||||
|---|---|---|
|
||||
| 1 | Q3 weak parameter draws | counted fraction of days in each class over >= 2^24 day keys, per-day op gain |
|
||||
| 2 | Q2 round margin | largest K applications a distinguisher reaches, against 8 and 72 |
|
||||
| 3 | Q1 structural shortcut | an op count below 8x for the 8 keyed applications, or the bound |
|
||||
| 4 | Q4 anything else | any other measured gain |
|
||||
|
||||
## 3. Method per question
|
||||
|
||||
### Q3, weak parameter draws (harness: f4-weakday, copied read-only into tools/attack/f4-weakday)
|
||||
|
||||
The census walks consecutive chain days through the real draw code (`MixParams::with_shape`) and classifies each
|
||||
day. Classes: ROT all equal, ROT distinct <= 3 or 4, ROT max multiplicity >= 4, ROT pair sums to 32 (same word
|
||||
and any), ROT all or mostly in {1,2,30,31} or {8,16,24}; MUL any = 1, any = 2^32-1, any low popcount or low NAF
|
||||
weight, any < 256, two equal, M2 class (NAF weight <= 3 frees a DSP); RC any = 0, RC + rk = 0 for any of the 72
|
||||
keys, RC extreme popcount, two equal. The gain metric M1 is the per-day LUT datapath cost in adder-equivalents,
|
||||
`32 adds + 32 xors + sum(NAF(MUL_i) - 1)`, gain = census median cost over the day cost. M2 gain = 16/(16-k).
|
||||
|
||||
Tool: `attack-f4 census --from 20729 --count 16777216 --threads 32 [--out file]`. Also `attack-f4 expect
|
||||
--threads 32` for the exact analytic tail (NAF weight and popcount tables over all 2^31 odd constants, the
|
||||
16-fold convolution), so the counted census is checked against the closed form.
|
||||
|
||||
Gate: the plan's gain gate is 1.1x. Any class with a per-day gain at or above 1.1x on a non-negligible fraction
|
||||
of days is a FINDING. A verifier is bit-exact and never skips an application, so ROT and RC values hand a
|
||||
datapath 0 ops and are reported as structure, not as a wall-time gain. Only MUL weight moves the LUT cost.
|
||||
|
||||
Known-failed shapes (the plant must fire): `attack-f4 plant alleq` (ROT all equal), `plant mul1` (one MUL = 1),
|
||||
`plant mul1all` (all MUL = 1), `plant rc0` (one RC = 0), `plant rcrk0` (RC + rk = 0). Each prints the day 20729
|
||||
draw with the planted field and the detector must flag the matching class.
|
||||
|
||||
### Q2, the round margin (harness: adv-mixer diffusion, new)
|
||||
|
||||
The strict-avalanche census of K consecutive keyed applications, K = 1..12, over N random states. For each state,
|
||||
flip each of 512 input bits, apply K applications, tally the output bit-flip probability p[in][out]. Report, per
|
||||
K: dependency holes (p exactly 0 or 1), strong-bias cells (|p - 0.5| above 8 sigma), the worst cell and its
|
||||
sigma. A distinguisher reaches K if a hole or a strong bias survives at K. The bound is the largest such K
|
||||
against the 8 between reads and the 72 per item.
|
||||
|
||||
Tool: `attack-adv-mixer diffusion --day 20729 --apps K --states 2000000 --threads 32` for K in 1..12. Also
|
||||
`--start-app A` to confirm the margin does not depend on where in the 72 the window sits (keys differ).
|
||||
|
||||
Gate: full diffusion (no hole, no strong bias at the census band) at K means the distinguisher does not reach K.
|
||||
The margin is 8 - K_max between reads and 72 - K_max per item.
|
||||
|
||||
Known-failed shape (the plant must fire): `--plant weak` builds a degenerate day by hand (MUL all 1, RC all 0,
|
||||
ROT all 16). The detector must report many holes and strong bias at every K. A real day must not.
|
||||
|
||||
The avalanche census is a bound, not a full trail search. It does not prove the absence of a high-order
|
||||
differential or a linear trail below the census band. Its reach is N states: a bias under 8/sqrt(N) is invisible.
|
||||
At N = 2e6, 8 sigma is about 0.0057, so a bias below 0.57 percent is not seen. This limit is stated with the
|
||||
result. A SAT or MILP trail search to tighten Q2 is scoped as owed work, not run tonight.
|
||||
|
||||
### Q1, the structural shortcut (harness: adv-mixer fold, new)
|
||||
|
||||
Three probes on the 8 keyed applications where only rk changes.
|
||||
|
||||
(a) The two multiply layers of adjacent applications do not merge. Test the two-application map g for GF(2)
|
||||
affinity: for an affine g, `g(a) ^ g(b) ^ g(c) ^ g(a^b^c)` is constant. Count violations over N random
|
||||
quadruples. Zero violations would mean g is affine and the two applications collapse to one linear map plus a
|
||||
constant, a BREAK. Many violations is the bound: the diffusion between the two multiply layers is nonlinear,
|
||||
so the multiplies do not fold.
|
||||
|
||||
(b) Word separability. Flip each input word of the full 8-application block and record which output words move.
|
||||
A dead (in_word, out_word) pair over all probes is a broken dependency a shortcut could split on. Zero dead
|
||||
pairs is the bound.
|
||||
|
||||
(c) Key-order commutation. Compare M(M(s,rk1),rk2) with M(M(s,rk2),rk1). Agreement would mean key order does not
|
||||
matter and the 8 keys could be folded into fewer. Any agreement is a FINDING.
|
||||
|
||||
Tool: `attack-adv-mixer fold --day 20729 --trials 1000000`.
|
||||
|
||||
Gate: (a) at least one violation, (b) zero dead pairs, (c) zero agreements is the bound that the 8 keyed
|
||||
applications cost 8x. Any breach is priced in ops per item against 9,360 and reported as a BREAK.
|
||||
|
||||
The algebraic view (Q1 candidate 3): the multiply layer is `x -> (x ^ c) * MUL` per word, a bijection but not
|
||||
GF(2)-linear (the integer multiply carries). The diffusion layer mixes words. So the composition over 8
|
||||
applications has rising algebraic degree. Probe (a) is the GF(2)-degree-1 test of the first two applications; a
|
||||
pass there already rules out the cheapest fold. A full algebraic-degree or integral-distinguisher search is owed
|
||||
work, scoped not run tonight.
|
||||
|
||||
### Q4, anything else
|
||||
|
||||
Two things to watch while the above runs. First, the round keys are fixed multiples of 0x9E3779B9, not drawn, so
|
||||
a bad rk is the same every day: `round_key(k)` is checked in the self-test and the RC + rk = 0 class in f4 covers
|
||||
the one way a fixed rk interacts with a drawn RC. Second, the item init `s[8+i] = t*MUL[i] + RC[i]` reuses MUL
|
||||
and RC; a MUL[i] = 1 collapses that init word to `t + RC[i]`, which f4's mul1 class already counts. Any further
|
||||
finding is added here.
|
||||
|
||||
## 4. Known-failed shape per method (the plant each tool must fire on)
|
||||
|
||||
| Method | Tool | Planted weakness | The tool must |
|
||||
|---|---|---|---|
|
||||
| Q3 census | attack-f4 plant alleq / mul1 / mul1all / rc0 / rcrk0 | the genesis day with one field forced weak | flag the matching class |
|
||||
| Q2 diffusion | attack-adv-mixer diffusion --plant weak | MUL all 1, RC all 0, ROT all 16 | report holes and strong bias at every K |
|
||||
| Q1 fold | (built in) | n/a: the probes are their own control, a real day must pass (a)-(c) | (a) violations > 0, (b) dead = 0, (c) agree = 0 |
|
||||
|
||||
The plant discipline follows the Mac rule: a watcher is trusted only after it fires on a known-failed case. Every
|
||||
run prints its plant state and its verdict.
|
||||
|
||||
## 5. Box-hours per step
|
||||
|
||||
Build box 2, core band 64-95, nice 10, one slot at a time. Budget 8 box-hours for first results.
|
||||
|
||||
| Step | Command | Estimate |
|
||||
|---|---|---|
|
||||
| Build the two harnesses (release) | build-remote.sh --box 2 -- build --release | 0.15 box-hours |
|
||||
| Q3 census 2^24 days, 32 threads | attack-f4 census --count 16777216 --threads 32 | 0.2 box-hours |
|
||||
| Q3 analytic tail | attack-f4 expect --threads 32 | 0.3 box-hours |
|
||||
| Q2 diffusion K = 1..12, 2e6 states each | attack-adv-mixer diffusion per K | 1.5 box-hours total |
|
||||
| Q2 plant-weak firing check, K = 1..4 | attack-adv-mixer diffusion --plant weak | 0.1 box-hours |
|
||||
| Q1 fold, 1e6 trials | attack-adv-mixer fold | 0.1 box-hours |
|
||||
| Headroom for a wider census or a tighter K | | the rest |
|
||||
|
||||
Estimates are first-cut from the op counts (one application is about 130 ops; 2e6 states x 512 flips x K
|
||||
applications fits a 32-core band in minutes). The report records the box-hours actually spent.
|
||||
|
||||
## 6. Files opened (the outsider read set)
|
||||
|
||||
Only these were read. Nothing else in the repository.
|
||||
|
||||
1. igneum-pow/src/memhard.rs (frozen, via git show at 017e7037).
|
||||
2. igneum-pow/src/seed.rs (frozen).
|
||||
3. igneum-pow/src/bind.rs (frozen, the day_bytes and day_index functions).
|
||||
4. igneum-pow/src/generator.rs (frozen, the LoadClass, V3_CLASS, V4_CLASS, ProgramClass, generator version and
|
||||
attempt-cap definitions; grepped, not read whole).
|
||||
5. igneum-pow/tests/mixer.rs (frozen, the head: the test harness contract on the class v3 and v4 construction).
|
||||
6. igneum-pow/Cargo.toml and Cargo.lock (dependency pin).
|
||||
7. docs/spec/01-lottery-hash.md section 1.8 (frozen: 1.8.1 to 1.8.5).
|
||||
8. docs/analysis/chip-model-v3.md sections 1, 2, 5, 6 (HEAD).
|
||||
9. The public kit packs under proto-cuda/packs-ca3-v4 (frozen, the file listing; the eight packs named in the
|
||||
brief). The kit zip sha256 is 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154 per the brief,
|
||||
to be checked when a pack is used as a vector.
|
||||
10. The Devnet 3 epoch-0 pack v4-devnet3-epoch0 (public-kit class, named by a teammate lane): on build-1 at
|
||||
/srv/artefacts/packs/v4-devnet3-epoch0/, zip sha256
|
||||
e025750f71175ed14d6e2a24e387ebbf1979b1cd0faee9139c41a7671165b334, program id 0xfce15bf61030be57 at attempt 0,
|
||||
2^24 fingerprint from base 0 e510ad92b4d24846, day bytes le64(20733). Copied read-only and the sha verified
|
||||
before any use as a vector. This matches the Devnet 3 epoch-0 program id named in the brief as the check.
|
||||
11. tools/attack/f4-weakday (build/attack-pass, copied read-only) and tools/attack/f8-uniform (the Mac worktree,
|
||||
copied with cp -R, original untouched).
|
||||
12. tools/build-remote.sh, infra/build-server/lib.sh, infra/build-server/remote-run.sh (the operating files).
|
||||
13. CLAUDE.md (loaded on its own; only its operating rules are followed, not its doc references).
|
||||
|
||||
## 7. What is owed beyond tonight
|
||||
|
||||
- A SAT or MILP differential and linear trail search on M_r reduced to K applications, to tighten Q2 below the
|
||||
avalanche census band.
|
||||
- A rotational-XOR search on the drawn double round.
|
||||
- An algebraic-degree or integral-distinguisher measurement across the 8 applications, to tighten Q1 beyond the
|
||||
affinity probe.
|
||||
- The census at more than 2^24 days if any class sits near the gate.
|
||||
|
||||
## 8. Re-scope (19:2x BST, 7 October 2026, from main)
|
||||
|
||||
The mixer work split into three lanes. This lane, adv-mixer, is narrowed to the algebraic structure of M_r: the
|
||||
fold or commutation of the multiply layer across applications (only rk changes), the algebraic form of the 8
|
||||
applications between two reads, and any composition cheaper than 8x one application, priced in ops per item
|
||||
against the chip model. Sibling adv-mixer-2 owns Q3 (the day-key weakness census and the calendar). Sibling
|
||||
adv-mixer-3 owns Q2 (differential, linear, rotational-XOR, SAT and MILP on reduced applications, the round
|
||||
margin). The Q3 census and the Q2 diffusion sweep already run in this lane are kept and recorded as courtesy
|
||||
runs, attributed to the owning lane. This lane's own deepening is the fold probe plus an algebraic-degree
|
||||
(integral cube-sum) saturation test across the applications. First results by 00:00 BST tonight.
|
||||
14
tools/attack/adv-mixer/Cargo.lock
generated
Normal file
14
tools/attack/adv-mixer/Cargo.lock
generated
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
# This file is automatically @generated by Cargo.
|
||||
# It is not intended for manual editing.
|
||||
version = 4
|
||||
|
||||
[[package]]
|
||||
name = "attack-adv-mixer"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"igneum-pow",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "igneum-pow"
|
||||
version = "0.2.0"
|
||||
21
tools/attack/adv-mixer/Cargo.toml
Normal file
21
tools/attack/adv-mixer/Cargo.toml
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
[package]
|
||||
name = "attack-adv-mixer"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
description = "Adversarial cryptanalysis of the memory-hard mixer M_r (spec 01 section 1.8.4): diffusion margin across the keyed applications (Q2), the composition-fold probe (Q1), with the planted-weak-day hooks that prove the harness fires"
|
||||
license = "MIT"
|
||||
publish = false
|
||||
|
||||
[[bin]]
|
||||
name = "attack-adv-mixer"
|
||||
path = "src/main.rs"
|
||||
|
||||
[dependencies]
|
||||
igneum-pow = { path = "../../../igneum-pow" }
|
||||
|
||||
[workspace]
|
||||
|
||||
[profile.release]
|
||||
opt-level = 3
|
||||
lto = true
|
||||
codegen-units = 1
|
||||
9
tools/attack/adv-mixer/queue/11-adv-mixer-fold-sweep.sh
Executable file
9
tools/attack/adv-mixer/queue/11-adv-mixer-fold-sweep.sh
Executable file
|
|
@ -0,0 +1,9 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
|
||||
# Internal adversarial pass, not an independent review.
|
||||
set -uo pipefail
|
||||
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
|
||||
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
|
||||
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
|
||||
run fold-sweep-1024d fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44
|
||||
echo "end $(date -u +%FT%TZ)"
|
||||
10
tools/attack/adv-mixer/queue/12-adv-mixer-integral-days.sh
Executable file
10
tools/attack/adv-mixer/queue/12-adv-mixer-integral-days.sh
Executable file
|
|
@ -0,0 +1,10 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
|
||||
# Internal adversarial pass, not an independent review.
|
||||
set -uo pipefail
|
||||
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
|
||||
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
|
||||
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
|
||||
run integral-a1-32d integral --day 20729 --apps 1 --dmax 16 --placements 2000 --days 32 --threads 44
|
||||
run integral-a2-32d integral --day 20729 --apps 2 --dmax 16 --placements 2000 --days 32 --threads 44
|
||||
echo "end $(date -u +%FT%TZ)"
|
||||
10
tools/attack/adv-mixer/queue/13-adv-mixer-lineindex.sh
Executable file
10
tools/attack/adv-mixer/queue/13-adv-mixer-lineindex.sh
Executable file
|
|
@ -0,0 +1,10 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
|
||||
# Internal adversarial pass, not an independent review.
|
||||
set -uo pipefail
|
||||
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
|
||||
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
|
||||
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
|
||||
for k in 1 2 3 4; do run lineindex-k$k lineindex --day 20729 --apps $k --states 1000000 --threads 44; done
|
||||
for k in 1 2; do run linrel-addr-a$k-8d linrel --addr --day 20729 --apps $k --samples 8192 --days 8; done
|
||||
echo "end $(date -u +%FT%TZ)"
|
||||
10
tools/attack/adv-mixer/queue/14-adv-mixer-linrel-cnf.sh
Executable file
10
tools/attack/adv-mixer/queue/14-adv-mixer-linrel-cnf.sh
Executable file
|
|
@ -0,0 +1,10 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
|
||||
# Internal adversarial pass, not an independent review.
|
||||
set -uo pipefail
|
||||
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
|
||||
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
|
||||
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
|
||||
for k in 1 2 8; do run linrel-full-a$k-16d linrel --day 20729 --apps $k --samples 8192 --days 16; done
|
||||
run cnf-commute-20729 cnf --day 20729 --out /srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf
|
||||
echo "end $(date -u +%FT%TZ)"
|
||||
12
tools/attack/adv-mixer/queue/15-adv-mixer-fill.sh
Executable file
12
tools/attack/adv-mixer/queue/15-adv-mixer-fill.sh
Executable file
|
|
@ -0,0 +1,12 @@
|
|||
#!/usr/bin/env bash
|
||||
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
|
||||
# Internal adversarial pass, not an independent review.
|
||||
set -uo pipefail
|
||||
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
|
||||
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
|
||||
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
|
||||
run fold-sweep-1024d fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44
|
||||
for k in 3 4 5 6 7; do run linrel-full-a$k-4d linrel --day 20729 --apps $k --samples 8192 --days 4; done
|
||||
run integral-a8-4d integral --day 20729 --apps 8 --dmax 14 --placements 2000 --days 4 --threads 44
|
||||
for k in 5 6 7 8; do run lineindex-k$k lineindex --day 20729 --apps $k --states 1000000 --threads 44; done
|
||||
echo "end $(date -u +%FT%TZ)"
|
||||
52
tools/attack/adv-mixer/run-box.sh
Executable file
52
tools/attack/adv-mixer/run-box.sh
Executable file
|
|
@ -0,0 +1,52 @@
|
|||
#!/usr/bin/env bash
|
||||
# Run the adv-mixer sweeps on build box 2 under nice 10 on the core band 64-95, one log, a pid file beside it.
|
||||
# Internal adversarial pass, not an independent review. Launched by the lane over ssh with nohup; never on the Mac.
|
||||
#
|
||||
# run-box.sh diffusion the Q2 diffusion margin sweep (K = 1..8), genesis day, 2,000,000 states each
|
||||
# run-box.sh census the Q3 weak-day census over 2^24 days through f4-weakday
|
||||
#
|
||||
# Binaries (already built by build-remote.sh on this box):
|
||||
# ADV = /srv/builds/igneum-wt-adv-mixer/tools/attack/adv-mixer/target/release/attack-adv-mixer
|
||||
# F4 = /srv/builds/igneum-wt-adv-mixer/tools/attack/f4-weakday/target/release/attack-f4
|
||||
set -euo pipefail
|
||||
ROOT=/srv/builds/igneum-wt-adv-mixer
|
||||
ADV="$ROOT/tools/attack/adv-mixer/target/release/attack-adv-mixer"
|
||||
F4="$ROOT/tools/attack/f4-weakday/target/release/attack-f4"
|
||||
OUT="/srv/builds/_adv-adv-mixer"
|
||||
mkdir -p "$OUT"
|
||||
BAND=8-95
|
||||
STATES=${STATES:-2000000}
|
||||
|
||||
case "${1:-}" in
|
||||
diffusion)
|
||||
LOG="$OUT/diffusion-$(date -u +%Y%m%dT%H%M%SZ).log"
|
||||
PID="$LOG.pid"
|
||||
{
|
||||
echo "adv-mixer diffusion sweep; internal adversarial pass, not an independent review"
|
||||
echo "binary sha256: $(sha256sum "$ADV" | cut -c1-64)"
|
||||
echo "host band taskset -c $BAND nice 10; states per K = $STATES; UTC start $(date -u +%FT%TZ)"
|
||||
for K in 1 2 3 4 5 6 7 8; do
|
||||
echo "===== K=$K ====="
|
||||
nice -n 10 taskset -c "$BAND" "$ADV" diffusion --day 20729 --apps "$K" --states "$STATES" --threads 32
|
||||
done
|
||||
echo "UTC end $(date -u +%FT%TZ)"
|
||||
} > "$LOG" 2>&1 &
|
||||
echo $! > "$PID"
|
||||
echo "diffusion running pid $(cat "$PID") log $LOG"
|
||||
;;
|
||||
census)
|
||||
LOG="$OUT/census-$(date -u +%Y%m%dT%H%M%SZ).log"
|
||||
PID="$LOG.pid"
|
||||
{
|
||||
echo "f4 weak-day census; internal adversarial pass, not an independent review"
|
||||
echo "binary sha256: $(sha256sum "$F4" | cut -c1-64)"
|
||||
echo "UTC start $(date -u +%FT%TZ)"
|
||||
nice -n 10 taskset -c "$BAND" "$F4" census --from 20729 --count 16777216 --threads 32
|
||||
echo "UTC end $(date -u +%FT%TZ)"
|
||||
} > "$LOG" 2>&1 &
|
||||
echo $! > "$PID"
|
||||
echo "census running pid $(cat "$PID") log $LOG"
|
||||
;;
|
||||
*)
|
||||
echo "usage: run-box.sh diffusion|census"; exit 2 ;;
|
||||
esac
|
||||
821
tools/attack/adv-mixer/src/main.rs
Normal file
821
tools/attack/adv-mixer/src/main.rs
Normal file
|
|
@ -0,0 +1,821 @@
|
|||
//! attack-adv-mixer: adversarial cryptanalysis of the memory-hard mixer `M_r` (spec 01 section 1.8.4), the
|
||||
//! internal adversarial pass, not an independent review. Every number here comes from the real `igneum-pow`
|
||||
//! mixer (`memhard::mixer`, `round_key_mult`, `MixParams::with_shape`); nothing is re-implemented.
|
||||
//!
|
||||
//! The target in the attacker's words. One application `M(s, rk)` on a 16-word state:
|
||||
//! 1. prologue, per word: `s[i] = (s[i] XOR (RC[i] + rk)) * MUL[i]` (MUL odd, so each is a bijection).
|
||||
//! 2. one ChaCha-shaped double round: four column quarter rounds with rotations ROT[0..3], four diagonal
|
||||
//! quarter rounds with ROT[4..7].
|
||||
//! Under class v4 (`mixer_mult = 8`) the derivation applies `M` eight times between each pair of the eight
|
||||
//! dependent cache reads, round keys `round_key(r*8 + j)`, then eight more after the last read: 72 per item.
|
||||
//! ROT, MUL, RC are drawn once per day from one SplitMix64 stream (the day key's first two words).
|
||||
//!
|
||||
//! The commands, each a BOUND or a BREAK with a command and a seed:
|
||||
//!
|
||||
//! diffusion --apps K --states N --day D [--start-app A] [--threads T] [--plant weak|none]
|
||||
//! The strict-avalanche census of K consecutive keyed applications (Q2). For N random states it flips each
|
||||
//! of the 512 input bits, applies K applications (keys from app A in derive order), and tallies the output
|
||||
//! bit-flip probability p[in][out] over the N states. Reports, per K, the number of output bits a single
|
||||
//! input bit never reaches (dependency holes), the number of (in,out) cells with |p - 0.5| above the
|
||||
//! census bias band, and the worst cell. Full diffusion at K is the bound: the largest K at which a hole
|
||||
//! or a strong bias survives is the distinguisher reach. The `weak` plant is a hand-built degenerate day
|
||||
//! (MUL all 1, RC all 0, ROT all 16): the detector must fire on it (holes and strong bias at every K).
|
||||
//!
|
||||
//! fold --day D [--trials N]
|
||||
//! The composition-shortcut probe (Q1). Checks three ways the 8 keyed applications might cost less than 8x:
|
||||
//! (a) the two multiply layers of adjacent applications do not merge: M has a nonlinear diffusion between
|
||||
//! them, shown by a GF(2) affinity test of the two-application map on N random probes (an affine map
|
||||
//! satisfies f(a)+f(b)+f(c)=f(a+b+c); count violations). (b) word separability: does output word w
|
||||
//! depend on every input word, tested by flipping each input word and checking each output word moves.
|
||||
//! A shortcut needs a broken dependency. (c) key-only commutation: M(M(s,rk1),rk2) vs M(M(s,rk2),rk1);
|
||||
//! if they agreed the key order would not matter and keys could be folded. Prints the counts; a zero
|
||||
//! in (a) or a missing dependency in (b) or an agreement in (c) would be a BREAK, else the BOUND.
|
||||
//!
|
||||
//! The genesis test vector (day 2026-10-03) is checked at startup against the spec so the mixer wiring is the
|
||||
//! library's.
|
||||
|
||||
use igneum_pow::generator::V4_CLASS;
|
||||
use igneum_pow::memhard::{mixer, round_key_mult, MixParams, Shape, ITEM_ROUNDS};
|
||||
use igneum_pow::seed::{day_key, seed_words_from_bytes, SplitMix64};
|
||||
use igneum_pow::bind::day_bytes;
|
||||
use std::sync::atomic::{AtomicU64, Ordering};
|
||||
use std::sync::Arc;
|
||||
use std::thread;
|
||||
|
||||
/// The chain genesis day index (`bind.rs`: day_index(0x1a0ff0f7c00) = 20,729, 3 October 2026).
|
||||
const GENESIS_DAY: u64 = 20_729;
|
||||
|
||||
fn v4_shape() -> Shape {
|
||||
let s = Shape::for_class(&V4_CLASS);
|
||||
assert_eq!(s.mixer_mult, 8, "class v4 is the x8 mixer");
|
||||
assert_eq!(s.derive_len, 0, "class v4 has no derivation program");
|
||||
s
|
||||
}
|
||||
|
||||
/// Params for a chain day index (the interim day rule, `bind::day_bytes`).
|
||||
fn params_of_day(d: u64) -> MixParams {
|
||||
MixParams::with_shape(seed_words_from_bytes(&day_bytes(d)), v4_shape())
|
||||
}
|
||||
|
||||
/// A hand-built degenerate day: identity multiply, zero round constants, one rotation amount everywhere. Not a
|
||||
/// drawable day (it is the plant); every field is in range (MUL odd, ROT in 1..31).
|
||||
fn planted_weak(d: u64) -> MixParams {
|
||||
let mut mp = params_of_day(d);
|
||||
mp.mul = [1u32; 16];
|
||||
mp.rc = [0u32; 16];
|
||||
mp.rot = [16u32; 8];
|
||||
mp
|
||||
}
|
||||
|
||||
/// The 72 application round keys of an item under m = 8, in derive order.
|
||||
fn app_keys() -> [u32; 72] {
|
||||
let mut k = [0u32; 72];
|
||||
for r in 0..=ITEM_ROUNDS {
|
||||
for j in 0..8 {
|
||||
k[r * 8 + j] = round_key_mult(r, j, 8);
|
||||
}
|
||||
}
|
||||
k
|
||||
}
|
||||
|
||||
/// Apply `apps` keyed applications starting at application index `start` (derive order).
|
||||
#[inline]
|
||||
fn apply_n(mut s: [u32; 16], mp: &MixParams, keys: &[u32; 72], start: usize, apps: usize) -> [u32; 16] {
|
||||
for a in 0..apps {
|
||||
mixer(&mut s, keys[(start + a) % 72], mp);
|
||||
}
|
||||
s
|
||||
}
|
||||
|
||||
/// A per-thread SplitMix64 PRNG for random probe states (the attacker's own randomness, not the mixer's).
|
||||
struct Rng(SplitMix64);
|
||||
impl Rng {
|
||||
fn new(seed: u64) -> Self {
|
||||
Rng(SplitMix64::new(seed))
|
||||
}
|
||||
fn state(&mut self) -> [u32; 16] {
|
||||
let mut s = [0u32; 16];
|
||||
for w in s.iter_mut() {
|
||||
*w = self.0.next() as u32;
|
||||
}
|
||||
s
|
||||
}
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
// diffusion (Q2): the strict-avalanche census over K keyed applications
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
|
||||
/// 512 x 512 counters (input bit -> output bit flip count), summed as u64. Flat for cache behaviour.
|
||||
struct Aval {
|
||||
n: u64,
|
||||
counts: Vec<u64>, // 512*512
|
||||
}
|
||||
impl Aval {
|
||||
fn new() -> Self {
|
||||
Aval { n: 0, counts: vec![0u64; 512 * 512] }
|
||||
}
|
||||
fn merge(&mut self, o: &Aval) {
|
||||
self.n += o.n;
|
||||
for (a, b) in self.counts.iter_mut().zip(o.counts.iter()) {
|
||||
*a += b;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[inline]
|
||||
fn bit_of(s: &[u32; 16], b: usize) -> u32 {
|
||||
(s[b >> 5] >> (b & 31)) & 1
|
||||
}
|
||||
#[inline]
|
||||
fn flip_bit(s: &mut [u32; 16], b: usize) {
|
||||
s[b >> 5] ^= 1u32 << (b & 31);
|
||||
}
|
||||
|
||||
fn diffusion(day: u64, plant_weak: bool, apps: usize, states: u64, start: usize, threads: usize) {
|
||||
let mp = if plant_weak { planted_weak(day) } else { params_of_day(day) };
|
||||
let keys = app_keys();
|
||||
let per = states / threads as u64;
|
||||
let mp = Arc::new(mp);
|
||||
let keys = Arc::new(keys);
|
||||
let mut handles = Vec::new();
|
||||
for t in 0..threads {
|
||||
let mp = Arc::clone(&mp);
|
||||
let keys = Arc::clone(&keys);
|
||||
let count = if t as u64 == threads as u64 - 1 { states - per * (threads as u64 - 1) } else { per };
|
||||
let seed = 0x1234_5678_9abc_def0 ^ ((day as u64).wrapping_mul(0x9E3779B97F4A7C15)) ^ (t as u64 + 1);
|
||||
handles.push(thread::spawn(move || {
|
||||
let mut rng = Rng::new(seed);
|
||||
let mut acc = Aval::new();
|
||||
for _ in 0..count {
|
||||
let base = rng.state();
|
||||
let out0 = apply_n(base, &mp, &keys, start, apps);
|
||||
for ib in 0..512 {
|
||||
let mut s = base;
|
||||
flip_bit(&mut s, ib);
|
||||
let out1 = apply_n(s, &mp, &keys, start, apps);
|
||||
let row = ib * 512;
|
||||
for ob in 0..512 {
|
||||
if bit_of(&out0, ob) != bit_of(&out1, ob) {
|
||||
acc.counts[row + ob] += 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
acc.n += 1;
|
||||
}
|
||||
acc
|
||||
}));
|
||||
}
|
||||
let mut total = Aval::new();
|
||||
for h in handles {
|
||||
total.merge(&h.join().unwrap());
|
||||
}
|
||||
|
||||
// census band: a cell at the ideal 0.5 over N states has stddev 0.5/sqrt(N); call a bias "strong" at 8 sigma.
|
||||
let n = total.n as f64;
|
||||
let sigma = 0.5 / n.sqrt();
|
||||
let band = 8.0 * sigma;
|
||||
let mut holes = 0u64; // cells with p == 0 or p == 1 exactly (a dependency hole or a perfect relation)
|
||||
let mut strong = 0u64; // |p-0.5| > band and not a hole
|
||||
let mut worst_dev = 0.0f64;
|
||||
let mut worst = (0usize, 0usize, 0.0f64);
|
||||
let mut global_flips = 0u64;
|
||||
for ib in 0..512 {
|
||||
for ob in 0..512 {
|
||||
let c = total.counts[ib * 512 + ob];
|
||||
global_flips += c;
|
||||
let p = c as f64 / n;
|
||||
if c == 0 || c == total.n {
|
||||
holes += 1;
|
||||
} else {
|
||||
let dev = (p - 0.5).abs();
|
||||
if dev > band {
|
||||
strong += 1;
|
||||
}
|
||||
if dev > worst_dev {
|
||||
worst_dev = dev;
|
||||
worst = (ib, ob, p);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
let mean_p = global_flips as f64 / (n * 512.0 * 512.0);
|
||||
println!(
|
||||
"diffusion day={} plant={} apps={} start={} states={} threads={}",
|
||||
day,
|
||||
if plant_weak { "weak" } else { "none" },
|
||||
apps,
|
||||
start,
|
||||
total.n,
|
||||
threads
|
||||
);
|
||||
println!(" mean output-flip probability over all 262144 cells: {:.6} (ideal 0.5)", mean_p);
|
||||
println!(" census band: 8 sigma = {:.6} ({} states)", band, total.n);
|
||||
println!(" dependency holes (p == 0 or p == 1 exactly): {} of 262144", holes);
|
||||
println!(" strong-bias cells (|p-0.5| > band, not a hole): {} of 262144", strong);
|
||||
println!(
|
||||
" worst cell: in_bit {} -> out_bit {} p = {:.6} dev = {:.6} ({:.1} sigma)",
|
||||
worst.0,
|
||||
worst.1,
|
||||
worst.2,
|
||||
worst_dev,
|
||||
worst_dev / sigma
|
||||
);
|
||||
let verdict = if holes > 0 || strong > 0 { "FINDING (holes or strong bias at this K)" } else { "no distinguisher at this K" };
|
||||
println!(" VERDICT: {}", verdict);
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
// fold (Q1): the composition-shortcut probe
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
|
||||
#[inline]
|
||||
fn xor16(a: &[u32; 16], b: &[u32; 16]) -> [u32; 16] {
|
||||
let mut o = [0u32; 16];
|
||||
for i in 0..16 {
|
||||
o[i] = a[i] ^ b[i];
|
||||
}
|
||||
o
|
||||
}
|
||||
|
||||
/// Probe (a) affinity and (c) key-order commutation on the adjacent application pair (i, i+1).
|
||||
fn fold_pair(mp: &MixParams, keys: &[u32; 72], i: usize, trials: u64, rng: &mut Rng) -> (u64, u64) {
|
||||
let (rk1, rk2) = (keys[i], keys[i + 1]);
|
||||
let g = |s: [u32; 16]| -> [u32; 16] { let mut t = s; mixer(&mut t, rk1, mp); mixer(&mut t, rk2, mp); t };
|
||||
let g0 = g([0u32; 16]);
|
||||
let mut violations = 0u64;
|
||||
let mut agree = 0u64;
|
||||
for _ in 0..trials {
|
||||
let a = rng.state(); let b = rng.state(); let c = rng.state();
|
||||
let abc = xor16(&xor16(&a, &b), &c);
|
||||
let lhs = xor16(&xor16(&g(a), &g(b)), &xor16(&g(c), &g(abc)));
|
||||
if lhs != g0 { violations += 1; }
|
||||
let s = rng.state();
|
||||
let mut s1 = s; mixer(&mut s1, rk2, mp); mixer(&mut s1, rk1, mp);
|
||||
if g(s) == s1 { agree += 1; }
|
||||
}
|
||||
(violations, agree)
|
||||
}
|
||||
|
||||
/// Probe (b) word separability over the full 8-application block of round 0.
|
||||
fn fold_block(mp: &MixParams, keys: &[u32; 72], trials: u64, rng: &mut Rng) -> u64 {
|
||||
let full = |s: [u32; 16]| apply_n(s, mp, keys, 0, 8);
|
||||
let mut dep = [[false; 16]; 16];
|
||||
for _ in 0..trials {
|
||||
let base = rng.state();
|
||||
let o0 = full(base);
|
||||
for iw in 0..16 {
|
||||
let mut s = base; s[iw] ^= 0xffff_ffff;
|
||||
let o1 = full(s);
|
||||
for ow in 0..16 { if o0[ow] != o1[ow] { dep[iw][ow] = true; } }
|
||||
}
|
||||
}
|
||||
let mut dead = 0u64;
|
||||
for iw in 0..16 { for ow in 0..16 { if !dep[iw][ow] { dead += 1; } } }
|
||||
dead
|
||||
}
|
||||
|
||||
fn fold(day: u64, trials: u64) {
|
||||
let mp = params_of_day(day);
|
||||
let keys = app_keys();
|
||||
let mut rng = Rng::new(0xfeed_face_cafe_babe ^ day.wrapping_mul(0x9E3779B97F4A7C15));
|
||||
let (affine_violations, commute_agree) = fold_pair(&mp, &keys, 0, trials, &mut rng);
|
||||
let dead_pairs = fold_block(&mp, &keys, trials, &mut rng);
|
||||
println!("fold day={} trials={}", day, trials);
|
||||
println!(" (a) GF(2) affinity violations of the 2-application map: {} of {} (0 would be a BREAK: the map is affine)", affine_violations, trials);
|
||||
println!(" (b) dead (in_word -> out_word) pairs over the full 8-application block: {} of 256 (any would be a broken dependency)", dead_pairs);
|
||||
println!(" (c) key-order agreements M(M(.,rk1),rk2) == M(M(.,rk2),rk1): {} of {} (any would let keys fold)", commute_agree, trials);
|
||||
let verdict = if affine_violations == 0 || dead_pairs > 0 || commute_agree > 0 { "FINDING" } else { "BOUND: no fold on these probes" };
|
||||
println!(" VERDICT: {}", verdict);
|
||||
}
|
||||
|
||||
/// The fold probes over `days` consecutive chain days and all 71 adjacent application-key pairs per day.
|
||||
fn fold_sweep(day0: u64, days: u64, trials: u64, threads: usize) {
|
||||
let keys = Arc::new(app_keys());
|
||||
let per = (days + threads as u64 - 1) / threads as u64;
|
||||
let mut handles = Vec::new();
|
||||
for t in 0..threads {
|
||||
let keys = Arc::clone(&keys);
|
||||
let lo = day0 + t as u64 * per;
|
||||
let hi = (lo + per).min(day0 + days);
|
||||
handles.push(thread::spawn(move || {
|
||||
let (mut viol, mut tot, mut agree, mut dead, mut n_days) = (0u64, 0u64, 0u64, 0u64, 0u64);
|
||||
let mut worst_viol_frac = 1.0f64;
|
||||
for d in lo..hi {
|
||||
let mp = params_of_day(d);
|
||||
let mut rng = Rng::new(0xfeed_face_cafe_babe ^ d.wrapping_mul(0x9E3779B97F4A7C15));
|
||||
for i in 0..71 {
|
||||
let (v, a) = fold_pair(&mp, &keys, i, trials, &mut rng);
|
||||
viol += v; tot += trials; agree += a;
|
||||
let f = v as f64 / trials as f64;
|
||||
if f < worst_viol_frac { worst_viol_frac = f; }
|
||||
}
|
||||
dead += fold_block(&mp, &keys, trials, &mut rng);
|
||||
n_days += 1;
|
||||
}
|
||||
(viol, tot, agree, dead, n_days, worst_viol_frac)
|
||||
}));
|
||||
}
|
||||
let (mut viol, mut tot, mut agree, mut dead, mut n_days) = (0u64, 0u64, 0u64, 0u64, 0u64);
|
||||
let mut worst = 1.0f64;
|
||||
for h in handles {
|
||||
let (v, t, a, dd, nd, w) = h.join().unwrap();
|
||||
viol += v; tot += t; agree += a; dead += dd; n_days += nd; if w < worst { worst = w; }
|
||||
}
|
||||
println!("fold-sweep from_day={} days={} pairs_per_day=71 trials_per_pair={}", day0, n_days, trials);
|
||||
println!(" (a) affinity violations: {} of {} pair-trials; lowest per-pair violation fraction {:.6} (1.0 = never affine)", viol, tot, worst);
|
||||
println!(" (b) dead word pairs summed over {} days: {} (0 = complete dependency every day)", n_days, dead);
|
||||
println!(" (c) key-order agreements: {} of {} pair-trials", agree, tot);
|
||||
println!(" VERDICT: {}", if viol < tot || dead > 0 || agree > 0 { "FINDING" } else { "BOUND: no fold on any day or pair probed" });
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
// integral (Q1): algebraic-degree saturation across K keyed applications
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
//
|
||||
// The cube-sum (higher-order differential) test. Pick d input-bit positions. Over a fixed random base state, XOR
|
||||
// every one of the 2^d subsets of those positions into the base, apply K applications, and XOR-accumulate the 16
|
||||
// output words. For an output bit that is a GF(2) polynomial of the input of degree < d, the sum over the full
|
||||
// d-cube is 0 (the d-th derivative of a degree < d polynomial is 0). A nonzero sum proves the output bit has
|
||||
// algebraic degree >= d in those d variables. We report, per d, the fraction of (base, cube) placements whose
|
||||
// accumulated 512-bit sum is nonzero on at least one output bit, and the mean number of output bits set. When
|
||||
// nonzero sums appear at small d the algebraic degree is already high, so no low-degree algebraic batching of the
|
||||
// applications exists: an attacker cannot evaluate the 8 applications through a cheap polynomial. A composition
|
||||
// cheaper than 8x would need a low-degree form; its absence is the bound, priced against 9,360 ops per item.
|
||||
|
||||
fn integral(day: u64, apps: usize, dmax: usize, placements: u64, threads: usize) {
|
||||
let mp = Arc::new(params_of_day(day));
|
||||
let keys = Arc::new(app_keys());
|
||||
println!("integral day={} apps={} placements_per_d={} threads={}", day, apps, placements, threads);
|
||||
println!(" d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)");
|
||||
for d in 1..=dmax {
|
||||
let per = placements / threads as u64;
|
||||
let mut handles = Vec::new();
|
||||
for t in 0..threads {
|
||||
let mp = Arc::clone(&mp);
|
||||
let keys = Arc::clone(&keys);
|
||||
let count = if t as u64 == threads as u64 - 1 { placements - per * (threads as u64 - 1) } else { per };
|
||||
let seed = 0xa1b2_c3d4_e5f6_0718 ^ day.wrapping_mul(0x9E3779B97F4A7C15) ^ ((d as u64) << 40) ^ (t as u64 + 1);
|
||||
handles.push(thread::spawn(move || {
|
||||
let mut rng = Rng::new(seed);
|
||||
let mut nonzero = 0u64;
|
||||
let mut bits_set_total = 0u64;
|
||||
for _ in 0..count {
|
||||
let base = rng.state();
|
||||
// choose d distinct input bit positions in 0..512
|
||||
let mut pos = [0usize; 32];
|
||||
let mut chosen = 0usize;
|
||||
while chosen < d {
|
||||
let b = (rng.0.next() % 512) as usize;
|
||||
if !pos[..chosen].contains(&b) {
|
||||
pos[chosen] = b;
|
||||
chosen += 1;
|
||||
}
|
||||
}
|
||||
let mut acc = [0u32; 16];
|
||||
for mask in 0u32..(1u32 << d) {
|
||||
let mut s = base;
|
||||
for (bit, &p) in pos[..d].iter().enumerate() {
|
||||
if (mask >> bit) & 1 == 1 {
|
||||
flip_bit(&mut s, p);
|
||||
}
|
||||
}
|
||||
let o = apply_n(s, &mp, &keys, 0, apps);
|
||||
for i in 0..16 {
|
||||
acc[i] ^= o[i];
|
||||
}
|
||||
}
|
||||
let set: u32 = acc.iter().map(|w| w.count_ones()).sum();
|
||||
bits_set_total += set as u64;
|
||||
if set > 0 {
|
||||
nonzero += 1;
|
||||
}
|
||||
}
|
||||
(nonzero, bits_set_total, count)
|
||||
}));
|
||||
}
|
||||
let (mut nonzero, mut bits, mut n) = (0u64, 0u64, 0u64);
|
||||
for h in handles {
|
||||
let (a, b, c) = h.join().unwrap();
|
||||
nonzero += a;
|
||||
bits += b;
|
||||
n += c;
|
||||
}
|
||||
let frac = nonzero as f64 / n as f64;
|
||||
let mean_bits = bits as f64 / n as f64;
|
||||
let note = if nonzero == 0 { "sum always 0: degree < d on every output bit (a low-degree relation)" } else { "degree >= d reached" };
|
||||
println!(
|
||||
" d={:2} nonzero {}/{} = {:.4} mean out-bits set {:.1}/512 [{}]",
|
||||
d, nonzero, n, frac, mean_bits, note
|
||||
);
|
||||
}
|
||||
println!(" READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications");
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
// linrel (Q1): exact affine-relation search over the full 32-bit map by GF(2) elimination
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
//
|
||||
// Collect N random (x, y = K applications of x) pairs. Each pair is a GF(2) row over the 1025 columns
|
||||
// [512 input bits | 512 output bits | 1]. Any nonzero v with A v = 0 is an exact affine relation
|
||||
// a.x XOR b.y = c that holds on every sample; with N far above 1025 a surviving relation is genuine (a chance
|
||||
// survivor has probability 2^-(N - 1025)). Kernel dimension 1025 - rank(A). Rank 1025 means NO affine relation
|
||||
// exists between the input bits and the output bits of the composed applications, at full width with the real
|
||||
// day constants. This is the decidable algebraic probe in place of a SAT solve (no solver reaches the box).
|
||||
// `--addr` restricts the output columns to the 22 line-index bits of s[0] (the bits a chip prefetches on).
|
||||
|
||||
const LR_IN: usize = 512;
|
||||
|
||||
fn gf2_rank(rows: &mut Vec<Vec<u64>>, ncols: usize) -> usize {
|
||||
let words = (ncols + 63) / 64;
|
||||
let mut rank = 0usize;
|
||||
let mut r = 0usize;
|
||||
for col in 0..ncols {
|
||||
let (w, b) = (col / 64, col % 64);
|
||||
let mut piv = None;
|
||||
for i in r..rows.len() {
|
||||
if (rows[i][w] >> b) & 1 == 1 {
|
||||
piv = Some(i);
|
||||
break;
|
||||
}
|
||||
}
|
||||
let Some(p) = piv else { continue };
|
||||
rows.swap(r, p);
|
||||
let pr = rows[r].clone();
|
||||
for i in 0..rows.len() {
|
||||
if i != r && (rows[i][w] >> b) & 1 == 1 {
|
||||
for k in 0..words {
|
||||
rows[i][k] ^= pr[k];
|
||||
}
|
||||
}
|
||||
}
|
||||
rank += 1;
|
||||
r += 1;
|
||||
if r == rows.len() {
|
||||
break;
|
||||
}
|
||||
}
|
||||
rank
|
||||
}
|
||||
|
||||
fn linrel(day: u64, apps: usize, samples: usize, addr_only: bool) {
|
||||
let mp = params_of_day(day);
|
||||
let keys = app_keys();
|
||||
let mut rng = Rng::new(0x5a5a_1234_9e37_79b9 ^ day.wrapping_mul(0x9E3779B97F4A7C15) ^ ((apps as u64) << 48));
|
||||
let nout = if addr_only { 22 } else { 512 };
|
||||
let ncols = LR_IN + nout + 1;
|
||||
let words = (ncols + 63) / 64;
|
||||
let mut rows: Vec<Vec<u64>> = Vec::with_capacity(samples);
|
||||
for _ in 0..samples {
|
||||
let x = rng.state();
|
||||
let y = apply_n(x, &mp, &keys, 0, apps);
|
||||
let mut row = vec![0u64; words];
|
||||
for b in 0..LR_IN {
|
||||
if bit_of(&x, b) == 1 {
|
||||
row[b / 64] |= 1u64 << (b % 64);
|
||||
}
|
||||
}
|
||||
for b in 0..nout {
|
||||
if bit_of(&y, b) == 1 {
|
||||
let c = LR_IN + b;
|
||||
row[c / 64] |= 1u64 << (c % 64);
|
||||
}
|
||||
}
|
||||
let c = LR_IN + nout;
|
||||
row[c / 64] |= 1u64 << (c % 64);
|
||||
rows.push(row);
|
||||
}
|
||||
let rank = gf2_rank(&mut rows, ncols);
|
||||
let kernel = ncols - rank;
|
||||
println!(
|
||||
"linrel day={} apps={} samples={} columns={} ({} in + {} out + 1) rank={} kernel_dim={}",
|
||||
day, apps, samples, ncols, LR_IN, nout, rank, kernel
|
||||
);
|
||||
let margin = samples as i64 - ncols as i64;
|
||||
if kernel == 0 {
|
||||
println!(" BOUND: no exact affine relation a.x XOR b.y = c over the {} samples (false-survivor odds 2^-{})", samples, margin);
|
||||
} else {
|
||||
println!(" FINDING: {} independent affine relations survive all {} samples (chance survivor odds 2^-{} each)", kernel, samples, margin);
|
||||
}
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
// lineindex (Q1): the 22 line-index bits of s[0] across applications, avalanche with a tight band
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
//
|
||||
// The cache read uses s[0] AND (2^22 - 1). A chip that could predict those 22 bits from fewer than K
|
||||
// applications could issue the read early and hide the mixer behind the memory latency. We tally the flip
|
||||
// probability of each of the 22 address bits for each of the 512 input bits over N states after K applications,
|
||||
// report holes and cells beyond 8 sigma, and the worst cell.
|
||||
|
||||
fn lineindex(day: u64, apps: usize, states: u64, threads: usize) {
|
||||
let mp = Arc::new(params_of_day(day));
|
||||
let keys = Arc::new(app_keys());
|
||||
let per = states / threads as u64;
|
||||
let mut handles = Vec::new();
|
||||
for t in 0..threads {
|
||||
let mp = Arc::clone(&mp);
|
||||
let keys = Arc::clone(&keys);
|
||||
let count = if t as u64 == threads as u64 - 1 { states - per * (threads as u64 - 1) } else { per };
|
||||
let seed = 0x7777_0000_abcd_ef01 ^ day.wrapping_mul(0x9E3779B97F4A7C15) ^ ((apps as u64) << 40) ^ (t as u64 + 1);
|
||||
handles.push(thread::spawn(move || {
|
||||
let mut rng = Rng::new(seed);
|
||||
let mut counts = vec![0u64; 512 * 22];
|
||||
for _ in 0..count {
|
||||
let base = rng.state();
|
||||
let o0 = apply_n(base, &mp, &keys, 0, apps)[0] & 0x003f_ffff;
|
||||
for ib in 0..512 {
|
||||
let mut s = base;
|
||||
flip_bit(&mut s, ib);
|
||||
let o1 = apply_n(s, &mp, &keys, 0, apps)[0] & 0x003f_ffff;
|
||||
let d = o0 ^ o1;
|
||||
for ab in 0..22 {
|
||||
if (d >> ab) & 1 == 1 {
|
||||
counts[ib * 22 + ab] += 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
(counts, count)
|
||||
}));
|
||||
}
|
||||
let mut counts = vec![0u64; 512 * 22];
|
||||
let mut n = 0u64;
|
||||
for h in handles {
|
||||
let (c, k) = h.join().unwrap();
|
||||
for (a, b) in counts.iter_mut().zip(c.iter()) {
|
||||
*a += b;
|
||||
}
|
||||
n += k;
|
||||
}
|
||||
let nf = n as f64;
|
||||
let sigma = 0.5 / nf.sqrt();
|
||||
let band = 8.0 * sigma;
|
||||
let (mut holes, mut strong, mut worst_dev, mut worst) = (0u64, 0u64, 0.0f64, (0usize, 0usize, 0.0f64));
|
||||
let mut total = 0u64;
|
||||
for ib in 0..512 {
|
||||
for ab in 0..22 {
|
||||
let c = counts[ib * 22 + ab];
|
||||
total += c;
|
||||
let p = c as f64 / nf;
|
||||
if c == 0 || c == n {
|
||||
holes += 1;
|
||||
} else {
|
||||
let dev = (p - 0.5).abs();
|
||||
if dev > band {
|
||||
strong += 1;
|
||||
}
|
||||
if dev > worst_dev {
|
||||
worst_dev = dev;
|
||||
worst = (ib, ab, p);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
println!("lineindex day={} apps={} states={} threads={} (22 address bits x 512 input bits = 11264 cells)", day, apps, n, threads);
|
||||
println!(" mean address-bit flip probability: {:.6} (ideal 0.5); band 8 sigma = {:.6}", total as f64 / (nf * 11264.0), band);
|
||||
println!(" holes: {} of 11264; strong-bias cells: {} of 11264", holes, strong);
|
||||
println!(" worst cell: in_bit {} -> addr_bit {} p = {:.6} ({:.1} sigma)", worst.0, worst.1, worst.2, worst_dev / sigma);
|
||||
println!(" VERDICT: {}", if holes > 0 || strong > 0 { "FINDING (address bits predictable at this K)" } else { "no address-bit distinguisher at this K" });
|
||||
}
|
||||
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
// cnf (Q1): DIMACS export of two keyed applications with the real day constants, the commutation instance
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
//
|
||||
// Bit-exact Tseitin encoding of M(M(x, rk1), rk2) and M(M(x, rk2), rk1) on a shared 512-variable input, with the
|
||||
// constraint that the two outputs are equal. SAT = a state on which the two key orders commute; UNSAT = none
|
||||
// exists (a proof of fold probe (c) over all 2^512 states). Adds are ripple-carry full adders, a constant
|
||||
// multiply is the shift-add chain over the set bits of MUL, a constant XOR is a literal flip, a rotation is
|
||||
// wiring. No solver reaches the box (crates.io is refused and none is installed), so this writes the model for a
|
||||
// solver elsewhere and the row stays BLOCKED on the solve.
|
||||
|
||||
struct Cnf {
|
||||
nvars: i32,
|
||||
clauses: Vec<Vec<i32>>,
|
||||
}
|
||||
const LTRUE: i32 = i32::MAX;
|
||||
const LFALSE: i32 = i32::MIN + 1;
|
||||
impl Cnf {
|
||||
fn new() -> Self {
|
||||
Cnf { nvars: 0, clauses: Vec::new() }
|
||||
}
|
||||
fn var(&mut self) -> i32 {
|
||||
self.nvars += 1;
|
||||
self.nvars
|
||||
}
|
||||
fn neg(l: i32) -> i32 {
|
||||
if l == LTRUE { LFALSE } else if l == LFALSE { LTRUE } else { -l }
|
||||
}
|
||||
fn xor(&mut self, a: i32, b: i32) -> i32 {
|
||||
if a == LFALSE { return b; }
|
||||
if b == LFALSE { return a; }
|
||||
if a == LTRUE { return Self::neg(b); }
|
||||
if b == LTRUE { return Self::neg(a); }
|
||||
let o = self.var();
|
||||
self.clauses.push(vec![-a, -b, -o]);
|
||||
self.clauses.push(vec![a, b, -o]);
|
||||
self.clauses.push(vec![a, -b, o]);
|
||||
self.clauses.push(vec![-a, b, o]);
|
||||
o
|
||||
}
|
||||
fn and(&mut self, a: i32, b: i32) -> i32 {
|
||||
if a == LFALSE || b == LFALSE { return LFALSE; }
|
||||
if a == LTRUE { return b; }
|
||||
if b == LTRUE { return a; }
|
||||
let o = self.var();
|
||||
self.clauses.push(vec![-o, a]);
|
||||
self.clauses.push(vec![-o, b]);
|
||||
self.clauses.push(vec![o, -a, -b]);
|
||||
o
|
||||
}
|
||||
fn or(&mut self, a: i32, b: i32) -> i32 {
|
||||
if a == LTRUE || b == LTRUE { return LTRUE; }
|
||||
if a == LFALSE { return b; }
|
||||
if b == LFALSE { return a; }
|
||||
let o = self.var();
|
||||
self.clauses.push(vec![o, -a]);
|
||||
self.clauses.push(vec![o, -b]);
|
||||
self.clauses.push(vec![-o, a, b]);
|
||||
o
|
||||
}
|
||||
/// 32-bit ripple-carry add of two literal words.
|
||||
fn add32(&mut self, a: &[i32; 32], b: &[i32; 32]) -> [i32; 32] {
|
||||
let mut out = [LFALSE; 32];
|
||||
let mut carry = LFALSE;
|
||||
for i in 0..32 {
|
||||
let t = self.xor(a[i], b[i]);
|
||||
out[i] = self.xor(t, carry);
|
||||
let c1 = self.and(a[i], b[i]);
|
||||
let c2 = self.and(t, carry);
|
||||
carry = self.or(c1, c2);
|
||||
}
|
||||
out
|
||||
}
|
||||
fn xor32(&mut self, a: &[i32; 32], b: &[i32; 32]) -> [i32; 32] {
|
||||
let mut o = [LFALSE; 32];
|
||||
for i in 0..32 { o[i] = self.xor(a[i], b[i]); }
|
||||
o
|
||||
}
|
||||
fn const32(v: u32) -> [i32; 32] {
|
||||
let mut o = [LFALSE; 32];
|
||||
for i in 0..32 { o[i] = if (v >> i) & 1 == 1 { LTRUE } else { LFALSE }; }
|
||||
o
|
||||
}
|
||||
fn rotl32(a: &[i32; 32], n: u32) -> [i32; 32] {
|
||||
let mut o = [LFALSE; 32];
|
||||
for i in 0..32 { o[((i as u32 + n) % 32) as usize] = a[i]; }
|
||||
o
|
||||
}
|
||||
fn shl32(a: &[i32; 32], n: u32) -> [i32; 32] {
|
||||
let mut o = [LFALSE; 32];
|
||||
for i in 0..32 { if i as u32 + n < 32 { o[(i as u32 + n) as usize] = a[i]; } }
|
||||
o
|
||||
}
|
||||
/// Multiply by a constant: shift-add over the set bits of `c`.
|
||||
fn mulc32(&mut self, a: &[i32; 32], c: u32) -> [i32; 32] {
|
||||
let mut acc: Option<[i32; 32]> = None;
|
||||
for j in 0..32 {
|
||||
if (c >> j) & 1 == 1 {
|
||||
let sh = Self::shl32(a, j);
|
||||
acc = Some(match acc { None => sh, Some(p) => self.add32(&p, &sh) });
|
||||
}
|
||||
}
|
||||
acc.unwrap_or(Self::const32(0))
|
||||
}
|
||||
fn qr(&mut self, s: &mut [[i32; 32]; 16], a: usize, b: usize, c: usize, d: usize, r: [u32; 4]) {
|
||||
s[a] = self.add32(&s[a], &s[b]); s[d] = self.xor32(&s[d], &s[a]); s[d] = Self::rotl32(&s[d], r[0]);
|
||||
s[c] = self.add32(&s[c], &s[d]); s[b] = self.xor32(&s[b], &s[c]); s[b] = Self::rotl32(&s[b], r[1]);
|
||||
s[a] = self.add32(&s[a], &s[b]); s[d] = self.xor32(&s[d], &s[a]); s[d] = Self::rotl32(&s[d], r[2]);
|
||||
s[c] = self.add32(&s[c], &s[d]); s[b] = self.xor32(&s[b], &s[c]); s[b] = Self::rotl32(&s[b], r[3]);
|
||||
}
|
||||
/// One mixer application, symbolic, the same wiring as memhard::mixer.
|
||||
fn mixer(&mut self, s: &mut [[i32; 32]; 16], rk: u32, mp: &MixParams) {
|
||||
for i in 0..16 {
|
||||
let k = Self::const32(mp.rc[i].wrapping_add(rk));
|
||||
let x = self.xor32(&s[i], &k);
|
||||
s[i] = self.mulc32(&x, mp.mul[i]);
|
||||
}
|
||||
let r = &mp.rot;
|
||||
let col = [r[0], r[1], r[2], r[3]];
|
||||
let dia = [r[4], r[5], r[6], r[7]];
|
||||
self.qr(s, 0, 4, 8, 12, col); self.qr(s, 1, 5, 9, 13, col); self.qr(s, 2, 6, 10, 14, col); self.qr(s, 3, 7, 11, 15, col);
|
||||
self.qr(s, 0, 5, 10, 15, dia); self.qr(s, 1, 6, 11, 12, dia); self.qr(s, 2, 7, 8, 13, dia); self.qr(s, 3, 4, 9, 14, dia);
|
||||
}
|
||||
fn assert_eq_lit(&mut self, a: i32, b: i32) {
|
||||
let is_const = |l: i32| l == LTRUE || l == LFALSE;
|
||||
match (a, b) {
|
||||
(LTRUE, LTRUE) | (LFALSE, LFALSE) => {}
|
||||
(x, y) if is_const(x) && is_const(y) => self.clauses.push(vec![]), // constant mismatch: UNSAT
|
||||
(LTRUE, x) | (x, LTRUE) => self.clauses.push(vec![x]),
|
||||
(LFALSE, x) | (x, LFALSE) => self.clauses.push(vec![-x]),
|
||||
_ => { self.clauses.push(vec![-a, b]); self.clauses.push(vec![a, -b]); }
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn cnf_export(day: u64, path: &str) {
|
||||
let mp = params_of_day(day);
|
||||
let keys = app_keys();
|
||||
let (rk1, rk2) = (keys[0], keys[1]);
|
||||
let mut c = Cnf::new();
|
||||
let mut x = [[LFALSE; 32]; 16];
|
||||
for w in 0..16 { for b in 0..32 { x[w][b] = c.var(); } }
|
||||
let mut s1 = x; c.mixer(&mut s1, rk1, &mp); c.mixer(&mut s1, rk2, &mp);
|
||||
let mut s2 = x; c.mixer(&mut s2, rk2, &mp); c.mixer(&mut s2, rk1, &mp);
|
||||
for w in 0..16 { for b in 0..32 { c.assert_eq_lit(s1[w][b], s2[w][b]); } }
|
||||
let mut out = String::new();
|
||||
let _ = writeln!(out, "c adv-mixer commutation instance: exists x with M(M(x,rk1),rk2) == M(M(x,rk2),rk1), day {} rk1 {:#010x} rk2 {:#010x}", day, rk1, rk2);
|
||||
let _ = writeln!(out, "c internal adversarial pass, not an independent review; frozen mixer 017e7037; input vars 1..512 = s[w] bit b at 1 + 32 w + b");
|
||||
let _ = writeln!(out, "p cnf {} {}", c.nvars, c.clauses.len());
|
||||
for cl in &c.clauses {
|
||||
for &l in cl { let _ = write!(out, "{} ", l); }
|
||||
let _ = writeln!(out, "0");
|
||||
}
|
||||
std::fs::write(path, out).expect("write cnf");
|
||||
println!("cnf day={} vars={} clauses={} written {}", day, c.nvars, c.clauses.len(), path);
|
||||
println!(" BLOCKED on the solve: no SAT solver reaches the box (crates.io refused, none installed); the model is the artefact");
|
||||
}
|
||||
|
||||
use std::fmt::Write as _;
|
||||
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
// startup self-check: the genesis test vector of the spec
|
||||
// --------------------------------------------------------------------------------------------------------------
|
||||
|
||||
fn self_check() {
|
||||
let mp = MixParams::for_day("2026-10-03");
|
||||
assert_eq!(mp.rot, [20, 20, 19, 4, 26, 3, 3, 27], "spec 1.8.4 ROT vector");
|
||||
assert_eq!(mp.mul[0], 0x42146205, "spec 1.8.4 MUL[0]");
|
||||
assert_eq!(mp.mul[15], 0x99cfb423, "spec 1.8.4 MUL[15]");
|
||||
assert_eq!(mp.rc[0], 0xbab68293, "spec 1.8.4 RC[0]");
|
||||
assert_eq!(mp.rc[15], 0x31b49ee2, "spec 1.8.4 RC[15]");
|
||||
let k = day_key("2026-10-03");
|
||||
assert_eq!(k[0], 0x3067619f, "spec 1.8.1 day key K[0]");
|
||||
// the 72 application keys are distinct multiples of 0x9E3779B9
|
||||
let keys = app_keys();
|
||||
for (i, &v) in keys.iter().enumerate() {
|
||||
assert_eq!(v, ((i as u32) + 1).wrapping_mul(0x9E3779B9), "application key {i}");
|
||||
}
|
||||
eprintln!("self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9");
|
||||
}
|
||||
|
||||
fn arg_u64(args: &[String], flag: &str, default: u64) -> u64 {
|
||||
args.iter().position(|a| a == flag).and_then(|i| args.get(i + 1)).and_then(|s| s.parse().ok()).unwrap_or(default)
|
||||
}
|
||||
fn arg_str<'a>(args: &'a [String], flag: &str, default: &'a str) -> &'a str {
|
||||
args.iter().position(|a| a == flag).and_then(|i| args.get(i + 1)).map(|s| s.as_str()).unwrap_or(default)
|
||||
}
|
||||
|
||||
fn main() {
|
||||
self_check();
|
||||
let args: Vec<String> = std::env::args().collect();
|
||||
let cmd = args.get(1).map(|s| s.as_str()).unwrap_or("help");
|
||||
let day = arg_u64(&args, "--day", GENESIS_DAY);
|
||||
let threads = arg_u64(&args, "--threads", 16).max(1) as usize;
|
||||
match cmd {
|
||||
"diffusion" => {
|
||||
let apps = arg_u64(&args, "--apps", 8) as usize;
|
||||
let states = arg_u64(&args, "--states", 100_000);
|
||||
let start = arg_u64(&args, "--start-app", 0) as usize;
|
||||
let plant = arg_str(&args, "--plant", "none") == "weak";
|
||||
diffusion(day, plant, apps, states, start, threads);
|
||||
}
|
||||
"fold" => {
|
||||
let trials = arg_u64(&args, "--trials", 100_000);
|
||||
fold(day, trials);
|
||||
}
|
||||
"integral" => {
|
||||
let apps = arg_u64(&args, "--apps", 2) as usize;
|
||||
let dmax = arg_u64(&args, "--dmax", 14) as usize;
|
||||
let placements = arg_u64(&args, "--placements", 20000);
|
||||
let days = arg_u64(&args, "--days", 1);
|
||||
for d in day..day + days { integral(d, apps, dmax, placements, threads); }
|
||||
}
|
||||
"fold-sweep" => {
|
||||
let trials = arg_u64(&args, "--trials", 20_000);
|
||||
let days = arg_u64(&args, "--days", 64);
|
||||
fold_sweep(day, days, trials, threads);
|
||||
}
|
||||
"linrel" => {
|
||||
let apps = arg_u64(&args, "--apps", 2) as usize;
|
||||
let samples = arg_u64(&args, "--samples", 8192) as usize;
|
||||
let addr = args.iter().any(|a| a == "--addr");
|
||||
let days = arg_u64(&args, "--days", 1);
|
||||
for d in day..day + days { linrel(d, apps, samples, addr); }
|
||||
}
|
||||
"lineindex" => {
|
||||
let apps = arg_u64(&args, "--apps", 2) as usize;
|
||||
let states = arg_u64(&args, "--states", 500_000);
|
||||
lineindex(day, apps, states, threads);
|
||||
}
|
||||
"cnf" => {
|
||||
let path = arg_str(&args, "--out", "adv-mixer-commute.cnf").to_string();
|
||||
cnf_export(day, &path);
|
||||
}
|
||||
_ => {
|
||||
eprintln!("usage: attack-adv-mixer diffusion|fold|fold-sweep|integral|linrel|lineindex|cnf [--day D] [--apps K] [--states N] [--start-app A] [--plant weak|none] [--trials N] [--dmax D] [--placements N] [--threads T]");
|
||||
}
|
||||
}
|
||||
let _ = AtomicU64::new(0).fetch_add(0, Ordering::Relaxed);
|
||||
}
|
||||
14
tools/attack/f4-weakday/Cargo.lock
generated
Normal file
14
tools/attack/f4-weakday/Cargo.lock
generated
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
# This file is automatically @generated by Cargo.
|
||||
# It is not intended for manual editing.
|
||||
version = 4
|
||||
|
||||
[[package]]
|
||||
name = "attack-f4-weakday"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"igneum-pow",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "igneum-pow"
|
||||
version = "0.2.0"
|
||||
21
tools/attack/f4-weakday/Cargo.toml
Normal file
21
tools/attack/f4-weakday/Cargo.toml
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
[package]
|
||||
name = "attack-f4-weakday"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
description = "Attack pass F4: the weak-day census over 2^24 day keys through MixParams::with_shape (docs/plans/cryptanalysis.md 4.2)"
|
||||
license = "MIT"
|
||||
publish = false
|
||||
|
||||
[[bin]]
|
||||
name = "attack-f4"
|
||||
path = "src/main.rs"
|
||||
|
||||
[dependencies]
|
||||
igneum-pow = { path = "../../../igneum-pow" }
|
||||
|
||||
[workspace]
|
||||
|
||||
[profile.release]
|
||||
opt-level = 3
|
||||
lto = true
|
||||
codegen-units = 1
|
||||
990
tools/attack/f4-weakday/src/main.rs
Normal file
990
tools/attack/f4-weakday/src/main.rs
Normal file
|
|
@ -0,0 +1,990 @@
|
|||
//! Attack pass F4: the weak-day census (`docs/plans/cryptanalysis.md` section 4.2 row F4, `funding.md` B2 rank 3 and
|
||||
//! B5 rank 3). Every chain day `d` has the key `seed_words_from_bytes("igneum-day/" || d_le64)` (`bind::day_bytes`,
|
||||
//! the interim day rule) and its mixer constants come from `MixParams::with_shape`, a SplitMix64 stream seeded from
|
||||
//! `key[0] | key[1] << 32`: `ROT[0..7]` in 1..31, `MUL[0..15]` odd, `RC[0..15]`. This harness walks consecutive chain
|
||||
//! days through the real draw code (the `igneum-pow` path dependency, nothing re-implemented) and classifies each
|
||||
//! day's draw.
|
||||
//!
|
||||
//! The gain metrics, all exact and structural (what a datapath built for the day pays, in adder-equivalents per
|
||||
//! mixer application; the verifier and every GPU pay the same ops on every day, so wall time cannot move):
|
||||
//!
|
||||
//! * M1, the per-day LUT datapath (an FPGA bitstream synthesised for the day, the only per-day attacker that
|
||||
//! exists: a constant XOR is absorbed into the next LUT, a rotation by a constant is routing, a 32-bit add or
|
||||
//! XOR is one 32-bit adder-equivalent, a multiply by a constant is `NAF(MUL) - 1` adders in canonical signed-digit
|
||||
//! shift-add form): `cost = 32 adds + 32 xors + sum_i (naf(MUL_i) - 1)`. Gain of a day = the census median cost
|
||||
//! over the day's cost. This is the generous bound: optimal single-constant multiplication is cheaper than NAF for
|
||||
//! every constant, and a DSP-block multiply does not depend on the value at all.
|
||||
//! * M2, the DSP-bound datapath (the multiplies in DSP blocks, value-independent): a word whose constant has NAF
|
||||
//! weight at most 3 (two adders) moves to LUTs and frees its DSP, so gain = 16 / (16 - k) for k such words.
|
||||
//! * ROT and RC classes: a constant rotation is wiring and a constant XOR is inverters on a per-day datapath, so
|
||||
//! their value hands a datapath exactly 0 ops. They are censused as structure (counts against the analytic
|
||||
//! expectation) and the worst members are measured for diffusion (`avalanche`), which bounds the only other
|
||||
//! thing a rotation draw could move. A bit-exact verifier never lets a chip skip an application, however weak its
|
||||
//! diffusion, so diffusion is reported and is not a gain.
|
||||
//!
|
||||
//! Commands:
|
||||
//! attack-f4 census --from 20729 --count 16777216 --threads 12 [--out file] [--dedupe]
|
||||
//! attack-f4 day --index 20729 one day's draw and classification
|
||||
//! attack-f4 plant alleq|mul1|mul1all|rc0|rcrk0 the known-fail firings: the day 20729 draw with the planted field
|
||||
//! attack-f4 expect --threads 12 exact per-word tables (NAF weight, popcount) over all 2^31 odd
|
||||
//! constants, and the 16-fold convolution: the expected M1 tail
|
||||
//! attack-f4 avalanche --index 20729 [--states 4096] single-application and two-application diffusion of a day
|
||||
|
||||
use igneum_pow::bind::day_bytes;
|
||||
use igneum_pow::generator::V4_CLASS;
|
||||
use igneum_pow::memhard::{mixer, round_key_mult, MixParams, Shape, ITEM_ROUNDS};
|
||||
use igneum_pow::seed::{seed_words_from_bytes, SplitMix64};
|
||||
use std::fmt::Write as _;
|
||||
use std::io::Write as _;
|
||||
|
||||
/// The chain's genesis day index (`bind.rs` tests: day_index(0x1a0ff0f7c00) = 20,729, 3 October 2026).
|
||||
const GENESIS_DAY: u64 = 20_729;
|
||||
/// Mixer applications per item under class v4 (`Shape::mixers_per_item`): 9 x 8.
|
||||
const APPLICATIONS_PER_ITEM: u64 = (ITEM_ROUNDS as u64 + 1) * 8;
|
||||
/// Adds and XORs of one application outside the multiply layer: 8 quarter rounds x (4 adds + 4 xors).
|
||||
const QR_ADDS_XORS: u32 = 64;
|
||||
/// The gate's gain threshold (plan 1.4 (3), B5 rank 3).
|
||||
const GAIN_GATE: f64 = 1.1;
|
||||
/// M2: a constant of NAF weight at most this is cheaper in LUTs than in a DSP block.
|
||||
const M2_NAF_CEIL: u32 = 3;
|
||||
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
// The day
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
|
||||
fn v4_shape() -> Shape {
|
||||
let s = Shape::for_class(&V4_CLASS);
|
||||
assert_eq!(s.mixer_mult, 8, "class v4 is the x8 mixer");
|
||||
assert_eq!(s.derive_len, 0, "class v4 has no derivation program: the fixed mixer with drawn constants");
|
||||
s
|
||||
}
|
||||
|
||||
/// The chain day's key and its draw through the real code.
|
||||
fn params_of_day(d: u64) -> MixParams {
|
||||
MixParams::with_shape(seed_words_from_bytes(&day_bytes(d)), v4_shape())
|
||||
}
|
||||
|
||||
fn seed64(key: &[u32; 8]) -> u64 {
|
||||
key[0] as u64 | ((key[1] as u64) << 32)
|
||||
}
|
||||
|
||||
/// Non-adjacent-form weight of a 32-bit constant (the number of nonzero signed digits).
|
||||
fn naf_weight(v: u32) -> u32 {
|
||||
let mut n = v as u64;
|
||||
let mut w = 0;
|
||||
while n != 0 {
|
||||
if n & 1 == 1 {
|
||||
// digit +1 when n = 1 mod 4, -1 when n = 3 mod 4
|
||||
if n & 3 == 3 {
|
||||
n += 1;
|
||||
} else {
|
||||
n -= 1;
|
||||
}
|
||||
w += 1;
|
||||
}
|
||||
n >>= 1;
|
||||
}
|
||||
w
|
||||
}
|
||||
|
||||
/// Round keys of the 72 applications of an item under m = 8: `round_key(r * 8 + j)`, r in 0..=8, j in 0..8.
|
||||
fn round_keys() -> [u32; 72] {
|
||||
let mut k = [0u32; 72];
|
||||
for r in 0..=ITEM_ROUNDS {
|
||||
for j in 0..8 {
|
||||
k[r * 8 + j] = round_key_mult(r, j, 8);
|
||||
}
|
||||
}
|
||||
k
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, Default)]
|
||||
struct DayClass {
|
||||
// ROT
|
||||
rot_distinct: u32,
|
||||
rot_all_equal: bool,
|
||||
rot_max_mult: u32,
|
||||
rot_comp_same_word: bool,
|
||||
rot_comp_any: bool,
|
||||
rot_small: u32,
|
||||
rot_byte: u32,
|
||||
// MUL
|
||||
naf: [u32; 16],
|
||||
naf_sum: u32,
|
||||
naf_min: u32,
|
||||
mul_one: u32,
|
||||
mul_minus_one: u32,
|
||||
mul_pop_le2: u32,
|
||||
mul_pop_le4: u32,
|
||||
mul_pop_le8: u32,
|
||||
mul_naf_le2: u32,
|
||||
mul_naf_le3: u32,
|
||||
mul_naf_le4: u32,
|
||||
mul_small: u32,
|
||||
mul_dup: bool,
|
||||
// RC
|
||||
rc_zero: u32,
|
||||
rc_pop_ext: u32,
|
||||
rc_rk_zero: u32,
|
||||
rc_dup: bool,
|
||||
// gains
|
||||
cost_m1: u32,
|
||||
m2_k: u32,
|
||||
}
|
||||
|
||||
fn classify(mp: &MixParams, rks: &[u32; 72]) -> DayClass {
|
||||
let mut c = DayClass::default();
|
||||
// ROT
|
||||
let mut seen = [0u32; 32];
|
||||
for &r in &mp.rot {
|
||||
assert!((1..=31).contains(&r));
|
||||
seen[r as usize] += 1;
|
||||
if matches!(r, 1 | 2 | 30 | 31) {
|
||||
c.rot_small += 1;
|
||||
}
|
||||
if matches!(r, 8 | 16 | 24) {
|
||||
c.rot_byte += 1;
|
||||
}
|
||||
}
|
||||
c.rot_distinct = seen.iter().filter(|&&n| n > 0).count() as u32;
|
||||
c.rot_max_mult = *seen.iter().max().unwrap();
|
||||
c.rot_all_equal = c.rot_distinct == 1;
|
||||
// the same-word pairs of a quarter round: s[d] takes ROT[0] then ROT[2], s[b] takes ROT[1] then ROT[3]; the
|
||||
// diagonal round the same with ROT[4..7]
|
||||
for (a, b) in [(0, 2), (1, 3), (4, 6), (5, 7)] {
|
||||
if mp.rot[a] + mp.rot[b] == 32 {
|
||||
c.rot_comp_same_word = true;
|
||||
}
|
||||
}
|
||||
for a in 0..8 {
|
||||
for b in a + 1..8 {
|
||||
if mp.rot[a] + mp.rot[b] == 32 {
|
||||
c.rot_comp_any = true;
|
||||
}
|
||||
}
|
||||
}
|
||||
// MUL
|
||||
c.naf_min = u32::MAX;
|
||||
for i in 0..16 {
|
||||
let m = mp.mul[i];
|
||||
assert!(m & 1 == 1);
|
||||
let w = naf_weight(m);
|
||||
c.naf[i] = w;
|
||||
c.naf_sum += w;
|
||||
c.naf_min = c.naf_min.min(w);
|
||||
let p = m.count_ones();
|
||||
if m == 1 {
|
||||
c.mul_one += 1;
|
||||
}
|
||||
if m == u32::MAX {
|
||||
c.mul_minus_one += 1;
|
||||
}
|
||||
if p <= 2 {
|
||||
c.mul_pop_le2 += 1;
|
||||
}
|
||||
if p <= 4 {
|
||||
c.mul_pop_le4 += 1;
|
||||
}
|
||||
if p <= 8 {
|
||||
c.mul_pop_le8 += 1;
|
||||
}
|
||||
if w <= 2 {
|
||||
c.mul_naf_le2 += 1;
|
||||
}
|
||||
if w <= 3 {
|
||||
c.mul_naf_le3 += 1;
|
||||
}
|
||||
if w <= 4 {
|
||||
c.mul_naf_le4 += 1;
|
||||
}
|
||||
if m < 256 {
|
||||
c.mul_small += 1;
|
||||
}
|
||||
for j in 0..i {
|
||||
if mp.mul[j] == m {
|
||||
c.mul_dup = true;
|
||||
}
|
||||
}
|
||||
}
|
||||
c.cost_m1 = QR_ADDS_XORS + c.naf_sum - 16;
|
||||
c.m2_k = c.mul_naf_le3;
|
||||
// RC
|
||||
for i in 0..16 {
|
||||
let r = mp.rc[i];
|
||||
if r == 0 {
|
||||
c.rc_zero += 1;
|
||||
}
|
||||
let p = r.count_ones();
|
||||
if p <= 4 || p >= 28 {
|
||||
c.rc_pop_ext += 1;
|
||||
}
|
||||
for &rk in rks.iter() {
|
||||
if r.wrapping_add(rk) == 0 {
|
||||
c.rc_rk_zero += 1;
|
||||
}
|
||||
}
|
||||
for j in 0..i {
|
||||
if mp.rc[j] == r {
|
||||
c.rc_dup = true;
|
||||
}
|
||||
}
|
||||
}
|
||||
c
|
||||
}
|
||||
|
||||
fn m2_gain(k: u32) -> f64 {
|
||||
16.0 / (16.0 - k as f64)
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
// The tally
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
|
||||
/// The worst member of a class: the lowest M1 cost among the days in it (ties: the earliest day).
|
||||
#[derive(Clone, Copy, Debug)]
|
||||
struct Worst {
|
||||
day: u64,
|
||||
cost: u32,
|
||||
}
|
||||
|
||||
impl Worst {
|
||||
fn none() -> Self {
|
||||
Worst { day: u64::MAX, cost: u32::MAX }
|
||||
}
|
||||
fn offer(&mut self, day: u64, cost: u32) {
|
||||
if cost < self.cost || (cost == self.cost && day < self.day) {
|
||||
*self = Worst { day, cost };
|
||||
}
|
||||
}
|
||||
fn merge(&mut self, o: &Worst) {
|
||||
if o.day != u64::MAX {
|
||||
self.offer(o.day, o.cost);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
const CLASSES: &[&str] = &[
|
||||
"ROT all equal",
|
||||
"ROT distinct <= 3",
|
||||
"ROT distinct <= 4",
|
||||
"ROT max multiplicity >= 4",
|
||||
"ROT same-word pair sums to 32",
|
||||
"ROT any pair sums to 32",
|
||||
"ROT all 8 in {1,2,30,31}",
|
||||
"ROT >= 6 in {1,2,30,31}",
|
||||
"ROT >= 4 in {1,2,30,31}",
|
||||
"ROT >= 4 in {8,16,24}",
|
||||
"MUL any = 1",
|
||||
"MUL any = 2^32-1",
|
||||
"MUL any popcount <= 2",
|
||||
"MUL any popcount <= 4",
|
||||
"MUL any popcount <= 8",
|
||||
"MUL any NAF weight <= 2",
|
||||
"MUL any NAF weight <= 3",
|
||||
"MUL any NAF weight <= 4",
|
||||
"MUL any < 256",
|
||||
"MUL two equal",
|
||||
"MUL M2 k >= 2 (gain >= 1.14x)",
|
||||
"RC any = 0",
|
||||
"RC any popcount <= 4 or >= 28",
|
||||
"RC + rk = 0 for any of the 72 keys",
|
||||
"RC two equal",
|
||||
];
|
||||
|
||||
#[derive(Clone, Debug)]
|
||||
struct Tally {
|
||||
n: u64,
|
||||
class_count: Vec<u64>,
|
||||
class_worst: Vec<Worst>,
|
||||
cost_hist: Vec<u64>,
|
||||
naf_sum_hist: Vec<u64>,
|
||||
naf_min_hist: Vec<u64>,
|
||||
rot_distinct_hist: [u64; 9],
|
||||
rot_small_hist: [u64; 9],
|
||||
rot_byte_hist: [u64; 9],
|
||||
rot_mult_hist: [u64; 9],
|
||||
m2_k_hist: [u64; 17],
|
||||
/// The 16 lowest-cost days seen (cost, day), sorted ascending.
|
||||
lowest: Vec<(u32, u64)>,
|
||||
highest: Vec<(u32, u64)>,
|
||||
seeds: Vec<u64>,
|
||||
}
|
||||
|
||||
impl Tally {
|
||||
fn new(dedupe: bool, cap: usize) -> Self {
|
||||
Tally {
|
||||
n: 0,
|
||||
class_count: vec![0; CLASSES.len()],
|
||||
class_worst: vec![Worst::none(); CLASSES.len()],
|
||||
cost_hist: vec![0; 400],
|
||||
naf_sum_hist: vec![0; 400],
|
||||
naf_min_hist: vec![0; 40],
|
||||
rot_distinct_hist: [0; 9],
|
||||
rot_small_hist: [0; 9],
|
||||
rot_byte_hist: [0; 9],
|
||||
rot_mult_hist: [0; 9],
|
||||
m2_k_hist: [0; 17],
|
||||
lowest: Vec::new(),
|
||||
highest: Vec::new(),
|
||||
seeds: if dedupe { Vec::with_capacity(cap) } else { Vec::new() },
|
||||
}
|
||||
}
|
||||
|
||||
fn flags(c: &DayClass) -> [bool; 25] {
|
||||
[
|
||||
c.rot_all_equal,
|
||||
c.rot_distinct <= 3,
|
||||
c.rot_distinct <= 4,
|
||||
c.rot_max_mult >= 4,
|
||||
c.rot_comp_same_word,
|
||||
c.rot_comp_any,
|
||||
c.rot_small == 8,
|
||||
c.rot_small >= 6,
|
||||
c.rot_small >= 4,
|
||||
c.rot_byte >= 4,
|
||||
c.mul_one > 0,
|
||||
c.mul_minus_one > 0,
|
||||
c.mul_pop_le2 > 0,
|
||||
c.mul_pop_le4 > 0,
|
||||
c.mul_pop_le8 > 0,
|
||||
c.mul_naf_le2 > 0,
|
||||
c.mul_naf_le3 > 0,
|
||||
c.mul_naf_le4 > 0,
|
||||
c.mul_small > 0,
|
||||
c.mul_dup,
|
||||
c.m2_k >= 2,
|
||||
c.rc_zero > 0,
|
||||
c.rc_pop_ext > 0,
|
||||
c.rc_rk_zero > 0,
|
||||
c.rc_dup,
|
||||
]
|
||||
}
|
||||
|
||||
fn add(&mut self, day: u64, mp: &MixParams, c: &DayClass, dedupe: bool) {
|
||||
self.n += 1;
|
||||
let f = Self::flags(c);
|
||||
assert_eq!(f.len(), CLASSES.len());
|
||||
for (i, &on) in f.iter().enumerate() {
|
||||
if on {
|
||||
self.class_count[i] += 1;
|
||||
self.class_worst[i].offer(day, c.cost_m1);
|
||||
}
|
||||
}
|
||||
self.cost_hist[c.cost_m1 as usize] += 1;
|
||||
self.naf_sum_hist[c.naf_sum as usize] += 1;
|
||||
self.naf_min_hist[c.naf_min as usize] += 1;
|
||||
self.rot_distinct_hist[c.rot_distinct as usize] += 1;
|
||||
self.rot_small_hist[c.rot_small as usize] += 1;
|
||||
self.rot_byte_hist[c.rot_byte as usize] += 1;
|
||||
self.rot_mult_hist[c.rot_max_mult as usize] += 1;
|
||||
self.m2_k_hist[c.m2_k as usize] += 1;
|
||||
push_sorted(&mut self.lowest, (c.cost_m1, day), 16, true);
|
||||
push_sorted(&mut self.highest, (c.cost_m1, day), 4, false);
|
||||
if dedupe {
|
||||
self.seeds.push(seed64(&mp.key));
|
||||
}
|
||||
}
|
||||
|
||||
fn merge(&mut self, o: Tally) {
|
||||
self.n += o.n;
|
||||
for i in 0..CLASSES.len() {
|
||||
self.class_count[i] += o.class_count[i];
|
||||
self.class_worst[i].merge(&o.class_worst[i]);
|
||||
}
|
||||
for (a, b) in self.cost_hist.iter_mut().zip(o.cost_hist.iter()) {
|
||||
*a += b;
|
||||
}
|
||||
for (a, b) in self.naf_sum_hist.iter_mut().zip(o.naf_sum_hist.iter()) {
|
||||
*a += b;
|
||||
}
|
||||
for (a, b) in self.naf_min_hist.iter_mut().zip(o.naf_min_hist.iter()) {
|
||||
*a += b;
|
||||
}
|
||||
for i in 0..9 {
|
||||
self.rot_distinct_hist[i] += o.rot_distinct_hist[i];
|
||||
self.rot_small_hist[i] += o.rot_small_hist[i];
|
||||
self.rot_byte_hist[i] += o.rot_byte_hist[i];
|
||||
self.rot_mult_hist[i] += o.rot_mult_hist[i];
|
||||
}
|
||||
for i in 0..17 {
|
||||
self.m2_k_hist[i] += o.m2_k_hist[i];
|
||||
}
|
||||
for e in o.lowest {
|
||||
push_sorted(&mut self.lowest, e, 16, true);
|
||||
}
|
||||
for e in o.highest {
|
||||
push_sorted(&mut self.highest, e, 4, false);
|
||||
}
|
||||
self.seeds.extend(o.seeds);
|
||||
}
|
||||
}
|
||||
|
||||
/// Keep the `cap` smallest (ascending) or largest (descending) entries.
|
||||
fn push_sorted(v: &mut Vec<(u32, u64)>, e: (u32, u64), cap: usize, ascending: bool) {
|
||||
if v.len() == cap {
|
||||
let last = *v.last().unwrap();
|
||||
let keep = if ascending { e < last } else { e > last };
|
||||
if !keep {
|
||||
return;
|
||||
}
|
||||
v.pop();
|
||||
}
|
||||
let pos = if ascending { v.partition_point(|x| *x < e) } else { v.partition_point(|x| *x > e) };
|
||||
v.insert(pos, e);
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
// Analytic expectations (per day, independent draws; the modulo-31 bias of `below` is 2^-64 per value and ignored)
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
|
||||
fn ln_choose(n: u64, k: u64) -> f64 {
|
||||
let lg = |x: u64| -> f64 { (1..=x).map(|i| (i as f64).ln()).sum() };
|
||||
lg(n) - lg(k) - lg(n - k)
|
||||
}
|
||||
|
||||
fn binom_tail(n: u64, p: f64, k_min: u64) -> f64 {
|
||||
(k_min..=n).map(|k| (ln_choose(n, k) + (k as f64) * p.ln() + ((n - k) as f64) * (1.0 - p).ln()).exp()).sum()
|
||||
}
|
||||
|
||||
/// P(d distinct values among 8 uniform draws from 31): S(8, d) x 31 falling d / 31^8.
|
||||
fn p_rot_distinct(d: u32) -> f64 {
|
||||
// Stirling numbers of the second kind S(8, d)
|
||||
let mut s = vec![vec![0f64; 9]; 9];
|
||||
s[0][0] = 1.0;
|
||||
for n in 1..=8 {
|
||||
for k in 1..=n {
|
||||
s[n][k] = (k as f64) * s[n - 1][k] + s[n - 1][k - 1];
|
||||
}
|
||||
}
|
||||
let mut falling = 1.0;
|
||||
for i in 0..d {
|
||||
falling *= (31 - i) as f64;
|
||||
}
|
||||
s[8][d as usize] * falling / 31f64.powi(8)
|
||||
}
|
||||
|
||||
/// P(max multiplicity >= 4 among 8 draws from 31), by enumeration of the multiplicity patterns is long; the
|
||||
/// census gives the exact count, so this is the first-order bound: C(8,4) x 31 x 31^-4 (approximate).
|
||||
fn p_rot_mult4_approx() -> f64 {
|
||||
70.0 * 31.0 / 31f64.powi(4)
|
||||
}
|
||||
|
||||
fn p_any_of(n: u64, p: f64) -> f64 {
|
||||
1.0 - (1.0 - p).powi(n as i32)
|
||||
}
|
||||
|
||||
fn one_in(p: f64) -> String {
|
||||
if p <= 0.0 {
|
||||
"0".into()
|
||||
} else {
|
||||
format!("1 in {:.3e}", 1.0 / p)
|
||||
}
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
// Printing a day
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
|
||||
fn hex_bytes(b: &[u8]) -> String {
|
||||
b.iter().map(|x| format!("{x:02x}")).collect()
|
||||
}
|
||||
|
||||
fn describe(day: u64, mp: &MixParams, c: &DayClass, median_cost: Option<u32>) -> String {
|
||||
let mut s = String::new();
|
||||
let _ = writeln!(s, "day index {day} (genesis + {}), day bytes {} , seed64 {:016x}", day as i64 - GENESIS_DAY as i64, hex_bytes(&day_bytes(day)), seed64(&mp.key));
|
||||
let _ = writeln!(s, "key {}", mp.key.iter().map(|w| format!("{w:08x}")).collect::<Vec<_>>().join(" "));
|
||||
let _ = writeln!(s, "ROT {:?} distinct {} max multiplicity {} small {} byte-aligned {} same-word pair 32 {} any pair 32 {}", mp.rot, c.rot_distinct, c.rot_max_mult, c.rot_small, c.rot_byte, c.rot_comp_same_word, c.rot_comp_any);
|
||||
let _ = writeln!(s, "MUL {}", mp.mul.iter().map(|w| format!("{w:08x}")).collect::<Vec<_>>().join(" "));
|
||||
let _ = writeln!(s, "NAF {:?} sum {} min {} =1 {} =-1 {} pop<=4 {} naf<=3 {} <256 {} dup {}", c.naf, c.naf_sum, c.naf_min, c.mul_one, c.mul_minus_one, c.mul_pop_le4, c.mul_naf_le3, c.mul_small, c.mul_dup);
|
||||
let _ = writeln!(s, "RC {}", mp.rc.iter().map(|w| format!("{w:08x}")).collect::<Vec<_>>().join(" "));
|
||||
let _ = writeln!(s, "RC zero {} pop<=4|>=28 {} rc+rk=0 {} dup {}", c.rc_zero, c.rc_pop_ext, c.rc_rk_zero, c.rc_dup);
|
||||
let _ = writeln!(s, "M1 cost {} adder-equivalents per application ({} per item, 72 applications); M2 k {} (gain {:.3}x)", c.cost_m1, c.cost_m1 as u64 * APPLICATIONS_PER_ITEM, c.m2_k, m2_gain(c.m2_k));
|
||||
if let Some(m) = median_cost {
|
||||
let _ = writeln!(s, "M1 gain against the census median {m}: {:.4}x", m as f64 / c.cost_m1 as f64);
|
||||
}
|
||||
let flags: Vec<&str> = Tally::flags(c).iter().zip(CLASSES.iter()).filter(|(f, _)| **f).map(|(_, n)| *n).collect();
|
||||
let _ = writeln!(s, "classes: {}", if flags.is_empty() { "none".to_string() } else { flags.join("; ") });
|
||||
s
|
||||
}
|
||||
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
// Commands
|
||||
// ------------------------------------------------------------------------------------------------------------
|
||||
|
||||
fn arg(args: &[String], name: &str) -> Option<String> {
|
||||
args.iter().position(|a| a == name).and_then(|i| args.get(i + 1).cloned())
|
||||
}
|
||||
|
||||
fn census(args: &[String]) {
|
||||
let from: u64 = arg(args, "--from").map(|v| v.parse().unwrap()).unwrap_or(GENESIS_DAY);
|
||||
let count: u64 = arg(args, "--count").map(|v| v.parse().unwrap()).unwrap_or(1 << 24);
|
||||
let threads: usize = arg(args, "--threads").map(|v| v.parse().unwrap()).unwrap_or(12);
|
||||
let out = arg(args, "--out");
|
||||
let dedupe = args.iter().any(|a| a == "--dedupe");
|
||||
let shape = v4_shape();
|
||||
let rks = round_keys();
|
||||
let t0 = std::time::Instant::now();
|
||||
let chunk = count.div_ceil(threads as u64);
|
||||
let tallies: Vec<Tally> = std::thread::scope(|sc| {
|
||||
let hs: Vec<_> = (0..threads)
|
||||
.map(|t| {
|
||||
let rks = &rks;
|
||||
sc.spawn(move || {
|
||||
let lo = from + chunk * t as u64;
|
||||
let hi = (lo + chunk).min(from + count);
|
||||
let mut tally = Tally::new(dedupe, (hi.saturating_sub(lo)) as usize);
|
||||
for d in lo..hi {
|
||||
let mp = params_of_day(d);
|
||||
debug_assert_eq!(mp.shape, shape);
|
||||
let c = classify(&mp, rks);
|
||||
tally.add(d, &mp, &c, dedupe);
|
||||
}
|
||||
tally
|
||||
})
|
||||
})
|
||||
.collect();
|
||||
hs.into_iter().map(|h| h.join().unwrap()).collect()
|
||||
});
|
||||
let mut all = Tally::new(false, 0);
|
||||
for t in tallies {
|
||||
all.merge(t);
|
||||
}
|
||||
let secs = t0.elapsed().as_secs_f64();
|
||||
assert_eq!(all.n, count);
|
||||
|
||||
// the median cost and the gate fractions
|
||||
let total = all.n;
|
||||
let mut acc = 0u64;
|
||||
let mut median = 0u32;
|
||||
for (c, &n) in all.cost_hist.iter().enumerate() {
|
||||
acc += n;
|
||||
if acc * 2 >= total {
|
||||
median = c as u32;
|
||||
break;
|
||||
}
|
||||
}
|
||||
let mean = all.cost_hist.iter().enumerate().map(|(c, &n)| c as f64 * n as f64).sum::<f64>() / total as f64;
|
||||
let var = all.cost_hist.iter().enumerate().map(|(c, &n)| (c as f64 - mean).powi(2) * n as f64).sum::<f64>() / total as f64;
|
||||
let gate_cost = |reference: f64| -> u32 { (reference / GAIN_GATE).floor() as u32 }; // cost <= this gives gain >= 1.1x... strictly over: cost < reference/1.1
|
||||
let over = |reference: f64| -> u64 {
|
||||
all.cost_hist.iter().enumerate().filter(|(c, _)| (*c as f64) * GAIN_GATE < reference).map(|(_, &n)| n).sum()
|
||||
};
|
||||
let over_median = over(median as f64);
|
||||
let over_mean = over(mean);
|
||||
let m2_over: u64 = all.m2_k_hist.iter().enumerate().filter(|(k, _)| m2_gain(*k as u32) > GAIN_GATE).map(|(_, &n)| n).sum();
|
||||
|
||||
let mut r = String::new();
|
||||
let _ = writeln!(r, "# attack-f4 census: {count} chain days from day index {from} (genesis {GENESIS_DAY}), class v4 shape (mixer x{}, cache 2^{}), {threads} threads, {secs:.1} s", shape.mixer_mult, shape.cache_log2_words);
|
||||
let _ = writeln!(r, "draw: MixParams::with_shape(seed_words_from_bytes(bind::day_bytes(d)), Shape::for_class(&V4_CLASS)); seed64 = key[0] | key[1] << 32");
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "## Gate (plan 1.4 (3), B5 rank 3): fraction of days with any gain over {GAIN_GATE}x under 2^-20 = {:.3e}", 2f64.powi(-20));
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "| Metric | Reference | Days over {GAIN_GATE}x | Fraction | Against 2^-20 |");
|
||||
let _ = writeln!(r, "|---|---|---|---|---|");
|
||||
let frac = |n: u64| n as f64 / total as f64;
|
||||
let vs = |n: u64| if frac(n) < 2f64.powi(-20) { "under" } else { "OVER" };
|
||||
let _ = writeln!(r, "| M1 per-day LUT datapath, adders per application | median cost {median} (gain over {GAIN_GATE}x = cost under {}) | {over_median} | {:.3e} | {} |", gate_cost(median as f64) + 1, frac(over_median), vs(over_median));
|
||||
let _ = writeln!(r, "| M1 against the mean cost {mean:.2} (sd {:.2}) | cost under {:.2} | {over_mean} | {:.3e} | {} |", var.sqrt(), mean / GAIN_GATE, frac(over_mean), vs(over_mean));
|
||||
let _ = writeln!(r, "| M2 DSP-bound datapath, 16/(16-k) with k = words of NAF weight <= {M2_NAF_CEIL} | k >= 2 | {m2_over} | {:.3e} | {} |", frac(m2_over), vs(m2_over));
|
||||
let _ = writeln!(r, "| ROT value (wiring) and RC value (inverters) on a per-day datapath | exact 0 ops moved on every day | 0 | 0 | under |");
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "M1 cost = {QR_ADDS_XORS} + sum(NAF(MUL_i) - 1); mean {mean:.3}, sd {:.3}, median {median}, min {} (day {}), max {} (day {})", var.sqrt(), all.lowest[0].0, all.lowest[0].1, all.highest[0].0, all.highest[0].1);
|
||||
let _ = writeln!(r);
|
||||
|
||||
// the classes
|
||||
let p_mul1 = p_any_of(16, 2f64.powi(-31));
|
||||
let p_small = p_any_of(16, 128.0 / 2f64.powi(31));
|
||||
let p_rc0 = p_any_of(16, 2f64.powi(-32));
|
||||
let p_rcrk = p_any_of(16, 72.0 / 2f64.powi(32));
|
||||
let pop_le = |k: u32| -> f64 { (0..=k).map(|i| ln_choose(32, i as u64).exp()).sum::<f64>() };
|
||||
let p_rc_pop = p_any_of(16, 2.0 * pop_le(4) / 2f64.powi(32));
|
||||
// odd constants with popcount <= k: the low bit is set, so C(31, i) for the other i < k bits
|
||||
let odd_pop_le = |k: u32| -> f64 { (0..k).map(|i| ln_choose(31, i as u64).exp()).sum::<f64>() / 2f64.powi(31) };
|
||||
let p_dup16 = |space: f64| -> f64 { 1.0 - (1..16).map(|i| 1.0 - i as f64 / space).product::<f64>() };
|
||||
let expectations: Vec<Option<f64>> = vec![
|
||||
Some(31f64.powi(-7)),
|
||||
Some((1..=3).map(p_rot_distinct).sum()),
|
||||
Some((1..=4).map(p_rot_distinct).sum()),
|
||||
Some(p_rot_mult4_approx()),
|
||||
Some(p_any_of(4, 1.0 / 31.0)),
|
||||
Some(p_any_of(28, 1.0 / 31.0)),
|
||||
Some((4f64 / 31.0).powi(8)),
|
||||
Some(binom_tail(8, 4.0 / 31.0, 6)),
|
||||
Some(binom_tail(8, 4.0 / 31.0, 4)),
|
||||
Some(binom_tail(8, 3.0 / 31.0, 4)),
|
||||
Some(p_mul1),
|
||||
Some(p_mul1),
|
||||
Some(p_any_of(16, odd_pop_le(2))),
|
||||
Some(p_any_of(16, odd_pop_le(4))),
|
||||
Some(p_any_of(16, odd_pop_le(8))),
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
Some(p_small),
|
||||
Some(p_dup16(2f64.powi(31))),
|
||||
None,
|
||||
Some(p_rc0),
|
||||
Some(p_rc_pop),
|
||||
Some(p_rcrk),
|
||||
Some(p_dup16(2f64.powi(32))),
|
||||
];
|
||||
let _ = writeln!(r, "## Classes over {count} days");
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "| Class | Count | Fraction | Expected per day (analytic) | Expected count | Worst member (day, M1 cost, M1 gain vs median, M2 gain) |");
|
||||
let _ = writeln!(r, "|---|---|---|---|---|---|");
|
||||
for (i, name) in CLASSES.iter().enumerate() {
|
||||
let n = all.class_count[i];
|
||||
let w = all.class_worst[i];
|
||||
let worst = if w.day == u64::MAX {
|
||||
"none".to_string()
|
||||
} else {
|
||||
let c = classify(¶ms_of_day(w.day), &rks);
|
||||
format!("day {} , cost {} , {:.4}x , {:.3}x", w.day, w.cost, median as f64 / w.cost as f64, m2_gain(c.m2_k))
|
||||
};
|
||||
let (ep, ec) = match expectations[i] {
|
||||
Some(p) => (format!("{p:.3e} ({})", one_in(p)), format!("{:.3}", p * total as f64)),
|
||||
None => ("see `expect`".to_string(), "see `expect`".to_string()),
|
||||
};
|
||||
let _ = writeln!(r, "| {name} | {n} | {:.3e} | {ep} | {ec} | {worst} |", frac(n));
|
||||
}
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "## Histograms");
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "| ROT distinct amounts | Count | Fraction | Expected (S(8,d) 31_d / 31^8) |");
|
||||
let _ = writeln!(r, "|---|---|---|---|");
|
||||
for d in 1..=8 {
|
||||
let _ = writeln!(r, "| {d} | {} | {:.4e} | {:.4e} |", all.rot_distinct_hist[d], frac(all.rot_distinct_hist[d]), p_rot_distinct(d as u32));
|
||||
}
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "| ROT amounts in {{1,2,30,31}} | Count | Expected Binomial(8, 4/31) | ROT amounts in {{8,16,24}} | Count | Expected Binomial(8, 3/31) | ROT max multiplicity | Count |");
|
||||
let _ = writeln!(r, "|---|---|---|---|---|---|---|---|");
|
||||
for k in 0..=8 {
|
||||
let e1 = binom_tail(8, 4.0 / 31.0, k) - binom_tail(8, 4.0 / 31.0, k + 1);
|
||||
let e2 = binom_tail(8, 3.0 / 31.0, k) - binom_tail(8, 3.0 / 31.0, k + 1);
|
||||
let _ = writeln!(r, "| {k} | {} | {:.1} | {k} | {} | {:.1} | {k} | {} |", all.rot_small_hist[k as usize], e1 * total as f64, all.rot_byte_hist[k as usize], e2 * total as f64, all.rot_mult_hist[k as usize]);
|
||||
}
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "| M2 k (words of NAF weight <= {M2_NAF_CEIL}) | Count | Gain 16/(16-k) |");
|
||||
let _ = writeln!(r, "|---|---|---|");
|
||||
for k in 0..=16 {
|
||||
if all.m2_k_hist[k] > 0 || k <= 3 {
|
||||
let _ = writeln!(r, "| {k} | {} | {:.3}x |", all.m2_k_hist[k], m2_gain(k as u32));
|
||||
}
|
||||
}
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "| Minimum NAF weight over the 16 MUL | Count |");
|
||||
let _ = writeln!(r, "|---|---|");
|
||||
for (w, &n) in all.naf_min_hist.iter().enumerate() {
|
||||
if n > 0 {
|
||||
let _ = writeln!(r, "| {w} | {n} |");
|
||||
}
|
||||
}
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "| M1 cost per application | Count | Cumulative fraction | M1 gain vs median |");
|
||||
let _ = writeln!(r, "|---|---|---|---|");
|
||||
let mut cum = 0u64;
|
||||
for (c, &n) in all.cost_hist.iter().enumerate() {
|
||||
if n > 0 {
|
||||
cum += n;
|
||||
let _ = writeln!(r, "| {c} | {n} | {:.4e} | {:.4}x |", frac(cum), median as f64 / c as f64);
|
||||
}
|
||||
}
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "## The 16 lowest-cost days (M1)");
|
||||
let _ = writeln!(r);
|
||||
for &(cost, day) in &all.lowest {
|
||||
let mp = params_of_day(day);
|
||||
let c = classify(&mp, &rks);
|
||||
let _ = writeln!(r, "- day {day}: cost {cost}, gain {:.4}x vs median, NAF sum {}, M2 k {}, day-hex {}", median as f64 / cost as f64, c.naf_sum, c.m2_k, hex_bytes(&day_bytes(day)));
|
||||
}
|
||||
if dedupe {
|
||||
all.seeds.sort_unstable();
|
||||
let before = all.seeds.len();
|
||||
all.seeds.dedup();
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "## 64-bit seeding: {} days, {} distinct 64-bit stream seeds ({} collisions; expected C(n,2)/2^64 = {:.3e})", before, all.seeds.len(), before - all.seeds.len(), (before as f64) * (before as f64 - 1.0) / 2.0 / 2f64.powi(64));
|
||||
}
|
||||
let _ = writeln!(r);
|
||||
let _ = writeln!(r, "## Worst member of every class, in full");
|
||||
let _ = writeln!(r);
|
||||
let mut shown: Vec<u64> = Vec::new();
|
||||
for (i, name) in CLASSES.iter().enumerate() {
|
||||
let w = all.class_worst[i];
|
||||
if w.day == u64::MAX || shown.contains(&w.day) {
|
||||
continue;
|
||||
}
|
||||
shown.push(w.day);
|
||||
let mp = params_of_day(w.day);
|
||||
let c = classify(&mp, &rks);
|
||||
let _ = writeln!(r, "### {name}: day {}", w.day);
|
||||
let _ = writeln!(r, "```");
|
||||
let _ = write!(r, "{}", describe(w.day, &mp, &c, Some(median)));
|
||||
let _ = writeln!(r, "```");
|
||||
}
|
||||
print!("{r}");
|
||||
if let Some(p) = out {
|
||||
std::fs::File::create(&p).unwrap().write_all(r.as_bytes()).unwrap();
|
||||
eprintln!("written {p}");
|
||||
}
|
||||
}
|
||||
|
||||
fn day_cmd(args: &[String]) {
|
||||
let d: u64 = arg(args, "--index").map(|v| v.parse().unwrap()).unwrap_or(GENESIS_DAY);
|
||||
let median: Option<u32> = arg(args, "--median").map(|v| v.parse().unwrap());
|
||||
let mp = params_of_day(d);
|
||||
let c = classify(&mp, &round_keys());
|
||||
print!("{}", describe(d, &mp, &c, median));
|
||||
}
|
||||
|
||||
/// The known-fail firings: the genesis day's draw with one field forced through this crate's own hook (the
|
||||
/// `MixParams` fields are public; `igneum-pow` is untouched). Exit 0 when the classifier flags the plant and the
|
||||
/// gain metric that the plant moves reads over the gate.
|
||||
fn plant(args: &[String]) {
|
||||
let what = args.get(2).cloned().unwrap_or_default();
|
||||
let median: u32 = arg(args, "--median").map(|v| v.parse().unwrap()).unwrap_or(221);
|
||||
let rks = round_keys();
|
||||
let mut mp = params_of_day(GENESIS_DAY);
|
||||
let before = classify(&mp, &rks);
|
||||
println!("before the plant (day {GENESIS_DAY}):");
|
||||
print!("{}", describe(GENESIS_DAY, &mp, &before, Some(median)));
|
||||
let (flag_name, gain_metric): (&str, &str) = match what.as_str() {
|
||||
"alleq" => {
|
||||
mp.rot = [7; 8];
|
||||
("ROT all equal", "structure (0 ops on a per-day datapath by construction; diffusion in `avalanche`)")
|
||||
}
|
||||
"mul1" => {
|
||||
mp.mul[5] = 1;
|
||||
("MUL any = 1", "M1")
|
||||
}
|
||||
"mul1all" => {
|
||||
mp.mul = [1; 16];
|
||||
("MUL any = 1", "M1")
|
||||
}
|
||||
"mulnaf" => {
|
||||
// the lightest realistic plant: four words at NAF weight 3 (M2 k = 4), the rest untouched
|
||||
for i in 0..4 {
|
||||
mp.mul[i] = (1u32 << 20) + (1u32 << 9) + 1;
|
||||
}
|
||||
("MUL any NAF weight <= 3", "M1 and M2")
|
||||
}
|
||||
"rc0" => {
|
||||
mp.rc[3] = 0;
|
||||
("RC any = 0", "structure (0 ops on a per-day datapath by construction)")
|
||||
}
|
||||
"rcrk0" => {
|
||||
mp.rc[3] = 0u32.wrapping_sub(round_key_mult(2, 5, 8));
|
||||
("RC + rk = 0 for any of the 72 keys", "structure (one xor of 10,368 ops per item on a generic datapath: 1.0001x)")
|
||||
}
|
||||
_ => {
|
||||
eprintln!("plant alleq|mul1|mul1all|mulnaf|rc0|rcrk0");
|
||||
std::process::exit(2);
|
||||
}
|
||||
};
|
||||
let after = classify(&mp, &rks);
|
||||
println!("\nafter the plant `{what}`:");
|
||||
print!("{}", describe(GENESIS_DAY, &mp, &after, Some(median)));
|
||||
let idx = CLASSES.iter().position(|n| *n == flag_name).unwrap();
|
||||
let flagged = Tally::flags(&after)[idx] && !Tally::flags(&before)[idx];
|
||||
let gain_m1 = median as f64 / after.cost_m1 as f64;
|
||||
let gain_m2 = m2_gain(after.m2_k);
|
||||
println!("\nplant `{what}`: classifier flag `{flag_name}` {} (was {} before); M1 gain {gain_m1:.4}x, M2 gain {gain_m2:.4}x; gain metric for this plant: {gain_metric}", if flagged { "FIRED" } else { "did NOT fire" }, Tally::flags(&before)[idx]);
|
||||
let gain_fired = gain_m1 > GAIN_GATE || gain_m2 > GAIN_GATE;
|
||||
println!("gain over {GAIN_GATE}x: {}", if gain_fired { "FIRED" } else { "not over the gate" });
|
||||
if !flagged {
|
||||
std::process::exit(1);
|
||||
}
|
||||
}
|
||||
|
||||
/// Exact per-word tables over every odd 32-bit constant (2^31 of them): the NAF weight distribution and the
|
||||
/// popcount distribution; then the 16-fold convolution of the NAF-weight distribution gives the expected M1 cost
|
||||
/// distribution and the expected fraction of days under any cost.
|
||||
fn expect(args: &[String]) {
|
||||
let threads: usize = arg(args, "--threads").map(|v| v.parse().unwrap()).unwrap_or(12);
|
||||
let median: u32 = arg(args, "--median").map(|v| v.parse().unwrap()).unwrap_or(221);
|
||||
let t0 = std::time::Instant::now();
|
||||
let per: Vec<([u64; 40], [u64; 33])> = std::thread::scope(|sc| {
|
||||
let hs: Vec<_> = (0..threads)
|
||||
.map(|t| {
|
||||
sc.spawn(move || {
|
||||
let mut naf = [0u64; 40];
|
||||
let mut pop = [0u64; 33];
|
||||
let lo = ((1u64 << 32) * t as u64 / threads as u64) | 1;
|
||||
let hi = (1u64 << 32) * (t as u64 + 1) / threads as u64;
|
||||
let mut v = lo;
|
||||
while v < hi {
|
||||
naf[naf_weight(v as u32) as usize] += 1;
|
||||
pop[(v as u32).count_ones() as usize] += 1;
|
||||
v += 2;
|
||||
}
|
||||
(naf, pop)
|
||||
})
|
||||
})
|
||||
.collect();
|
||||
hs.into_iter().map(|h| h.join().unwrap()).collect()
|
||||
});
|
||||
let mut naf = [0u64; 40];
|
||||
let mut pop = [0u64; 33];
|
||||
for (a, b) in per {
|
||||
for i in 0..40 {
|
||||
naf[i] += a[i];
|
||||
}
|
||||
for i in 0..33 {
|
||||
pop[i] += b[i];
|
||||
}
|
||||
}
|
||||
let total: u64 = naf.iter().sum();
|
||||
assert_eq!(total, 1 << 31);
|
||||
println!("# attack-f4 expect: all {total} odd 32-bit constants, {threads} threads, {:.1} s", t0.elapsed().as_secs_f64());
|
||||
println!();
|
||||
println!("| NAF weight | Odd constants | Fraction | Cumulative | Any of 16 per day | x 2^24 days |");
|
||||
println!("|---|---|---|---|---|---|");
|
||||
let mut cum = 0u64;
|
||||
for w in 0..40 {
|
||||
if naf[w] > 0 {
|
||||
cum += naf[w];
|
||||
let p = cum as f64 / total as f64;
|
||||
println!("| {w} | {} | {:.4e} | {:.4e} | {:.4e} | {:.3} |", naf[w], naf[w] as f64 / total as f64, p, p_any_of(16, p), p_any_of(16, p) * 2f64.powi(24));
|
||||
}
|
||||
}
|
||||
println!();
|
||||
println!("| Popcount | Odd constants | Cumulative fraction | Any of 16 per day |");
|
||||
println!("|---|---|---|---|");
|
||||
cum = 0;
|
||||
for w in 0..33 {
|
||||
if pop[w] > 0 {
|
||||
cum += pop[w];
|
||||
let p = cum as f64 / total as f64;
|
||||
println!("| {w} | {} | {:.4e} | {:.4e} |", pop[w], p, p_any_of(16, p));
|
||||
}
|
||||
}
|
||||
// the 16-fold convolution of the NAF-weight distribution: the exact expected distribution of the NAF sum
|
||||
let pw: Vec<f64> = naf.iter().map(|&n| n as f64 / total as f64).collect();
|
||||
let mut dist = vec![0f64; 1];
|
||||
dist[0] = 1.0;
|
||||
for _ in 0..16 {
|
||||
let mut next = vec![0f64; dist.len() + 39];
|
||||
for (i, &a) in dist.iter().enumerate() {
|
||||
if a == 0.0 {
|
||||
continue;
|
||||
}
|
||||
for (w, &b) in pw.iter().enumerate() {
|
||||
next[i + w] += a * b;
|
||||
}
|
||||
}
|
||||
dist = next;
|
||||
}
|
||||
let mean: f64 = dist.iter().enumerate().map(|(s, &p)| s as f64 * p).sum();
|
||||
let var: f64 = dist.iter().enumerate().map(|(s, &p)| (s as f64 - mean).powi(2) * p).sum();
|
||||
println!();
|
||||
println!("Expected NAF sum over 16 words: mean {mean:.4}, sd {:.4}; expected M1 cost mean {:.4}", var.sqrt(), mean + QR_ADDS_XORS as f64 - 16.0);
|
||||
println!();
|
||||
println!("| M1 cost | NAF sum | Expected fraction of days at this cost | Expected cumulative fraction | Gain vs median {median} |");
|
||||
println!("|---|---|---|---|---|");
|
||||
let mut c = 0f64;
|
||||
for (s, &p) in dist.iter().enumerate() {
|
||||
let cost = s as i64 + QR_ADDS_XORS as i64 - 16;
|
||||
if cost < 0 {
|
||||
continue;
|
||||
}
|
||||
c += p;
|
||||
if p > 1e-12 && (cost as f64) <= median as f64 {
|
||||
println!("| {cost} | {s} | {p:.4e} | {c:.4e} | {:.4}x |", median as f64 / cost as f64);
|
||||
}
|
||||
}
|
||||
let gate: f64 = dist.iter().enumerate().filter(|(s, _)| ((*s as f64) + QR_ADDS_XORS as f64 - 16.0) * GAIN_GATE < median as f64).map(|(_, &p)| p).sum();
|
||||
println!();
|
||||
println!("Expected fraction of days with M1 gain over {GAIN_GATE}x against median {median}: {gate:.4e} ({} ; x 2^24 = {:.1}); 2^-20 = {:.4e}", one_in(gate), gate * 2f64.powi(24), 2f64.powi(-20));
|
||||
}
|
||||
|
||||
/// Diffusion of one day's mixer: for `states` random 16-word states and each of the 512 input bits, the fraction of
|
||||
/// the 512 output bits that flip after k = 1 and k = 2 applications (keys `round_key_mult(0, 0, 8)` and `(0, 1, 8)`),
|
||||
/// mean over all, and the minimum per-output-bit flip probability. An ideal mixer reads 0.5 mean and about 0.5 min.
|
||||
fn avalanche(args: &[String]) {
|
||||
let d: u64 = arg(args, "--index").map(|v| v.parse().unwrap()).unwrap_or(GENESIS_DAY);
|
||||
let states: usize = arg(args, "--states").map(|v| v.parse().unwrap()).unwrap_or(4096);
|
||||
let plant_alleq: Option<u32> = arg(args, "--plant-alleq").map(|v| v.parse().unwrap());
|
||||
let mut mp = params_of_day(d);
|
||||
if let Some(r) = plant_alleq {
|
||||
mp.rot = [r; 8];
|
||||
}
|
||||
let c = classify(&mp, &round_keys());
|
||||
println!("avalanche of day {d}{}: ROT {:?}, NAF sum {}, {states} states x 512 input bits", plant_alleq.map(|r| format!(" with ROT planted all {r}")).unwrap_or_default(), mp.rot, c.naf_sum);
|
||||
let mut rng = SplitMix64::new(0xF4F4_F4F4 ^ d);
|
||||
for k in 1..=3usize {
|
||||
let apply = |s: &mut [u32; 16]| {
|
||||
for j in 0..k {
|
||||
mixer(s, round_keys()[j], &mp);
|
||||
}
|
||||
};
|
||||
let mut flips = [0u64; 512];
|
||||
let mut total_flips = 0u64;
|
||||
let mut trials = 0u64;
|
||||
for _ in 0..states {
|
||||
let mut base = [0u32; 16];
|
||||
for w in base.iter_mut() {
|
||||
*w = rng.next() as u32;
|
||||
}
|
||||
let mut y0 = base;
|
||||
apply(&mut y0);
|
||||
for bit in 0..512 {
|
||||
let mut x = base;
|
||||
x[bit / 32] ^= 1 << (bit % 32);
|
||||
apply(&mut x);
|
||||
for o in 0..512 {
|
||||
let f = ((x[o / 32] ^ y0[o / 32]) >> (o % 32)) & 1;
|
||||
flips[o] += f as u64;
|
||||
total_flips += f as u64;
|
||||
}
|
||||
trials += 1;
|
||||
}
|
||||
}
|
||||
let mean = total_flips as f64 / (trials as f64 * 512.0);
|
||||
let min = flips.iter().map(|&f| f as f64 / trials as f64).fold(1.0, f64::min);
|
||||
let max = flips.iter().map(|&f| f as f64 / trials as f64).fold(0.0, f64::max);
|
||||
println!("| {k} application{} | mean flip {mean:.4} | min per output bit {min:.4} | max {max:.4} |", if k > 1 { "s" } else { "" });
|
||||
}
|
||||
}
|
||||
|
||||
fn main() {
|
||||
let args: Vec<String> = std::env::args().collect();
|
||||
match args.get(1).map(|s| s.as_str()) {
|
||||
Some("census") => census(&args),
|
||||
Some("day") => day_cmd(&args),
|
||||
Some("plant") => plant(&args),
|
||||
Some("expect") => expect(&args),
|
||||
Some("avalanche") => avalanche(&args),
|
||||
_ => {
|
||||
eprintln!("attack-f4 census|day|plant|expect|avalanche (see the module doc)");
|
||||
std::process::exit(2);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn naf_weights() {
|
||||
assert_eq!(naf_weight(0), 0);
|
||||
assert_eq!(naf_weight(1), 1);
|
||||
assert_eq!(naf_weight(3), 2); // 4 - 1
|
||||
assert_eq!(naf_weight(7), 2); // 8 - 1
|
||||
assert_eq!(naf_weight(0xFFFF_FFFF), 2); // 2^32 - 1
|
||||
assert_eq!(naf_weight(0xAAAA_AAAB), 17); // alternating odd: the maximum for 32 bits
|
||||
assert_eq!(naf_weight((1 << 20) + (1 << 9) + 1), 3);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn genesis_day_draw_matches_memhard_md() {
|
||||
// MEMHARD.md section 1.1 (string day "2026-10-03") is a different key from the chain's day index 20,729;
|
||||
// what is checked here is that the chain-day path draws through the real code and stays in range.
|
||||
let mp = params_of_day(GENESIS_DAY);
|
||||
assert!(mp.rot.iter().all(|r| (1..=31).contains(r)));
|
||||
assert!(mp.mul.iter().all(|m| m & 1 == 1));
|
||||
assert_eq!(mp.shape, v4_shape());
|
||||
let s = igneum_pow::seed::day_key("2026-10-03");
|
||||
let mp2 = MixParams::with_shape(s, Shape::V2);
|
||||
assert_eq!(mp2.rot, [20, 20, 19, 4, 26, 3, 3, 27], "MEMHARD.md 1.1 genesis-day ROT");
|
||||
}
|
||||
}
|
||||
14
tools/attack/f8-uniform/Cargo.lock
generated
Normal file
14
tools/attack/f8-uniform/Cargo.lock
generated
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
# This file is automatically @generated by Cargo.
|
||||
# It is not intended for manual editing.
|
||||
version = 4
|
||||
|
||||
[[package]]
|
||||
name = "attack-f8"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"igneum-pow",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "igneum-pow"
|
||||
version = "0.2.0"
|
||||
21
tools/attack/f8-uniform/Cargo.toml
Normal file
21
tools/attack/f8-uniform/Cargo.toml
Normal file
|
|
@ -0,0 +1,21 @@
|
|||
[package]
|
||||
name = "attack-f8"
|
||||
version = "0.1.0"
|
||||
edition = "2021"
|
||||
description = "Attack-pass row F8: the uniformity censuses of the class v4 derivation (line index over 2^28 derivations, distinct lines per hash and warp, the cross-hash item histogram), with the plant hooks that prove the harness fires"
|
||||
license = "MIT"
|
||||
publish = false
|
||||
|
||||
[[bin]]
|
||||
name = "attack-f8"
|
||||
path = "src/main.rs"
|
||||
|
||||
[dependencies]
|
||||
igneum-pow = { path = "../../../igneum-pow" }
|
||||
|
||||
[workspace]
|
||||
|
||||
[profile.release]
|
||||
opt-level = 3
|
||||
lto = true
|
||||
codegen-units = 1
|
||||
1745
tools/attack/f8-uniform/src/main.rs
Normal file
1745
tools/attack/f8-uniform/src/main.rs
Normal file
File diff suppressed because it is too large
Load diff
|
|
@ -15,3 +15,7 @@ docs/analysis/ci-failures-2026-10-06.md
|
|||
# 7 October 2026: the last research round (the mission lanes and the closed list): internal research written for the
|
||||
# owner, quoting his words and the operations record; the public spec mirror carries none of it
|
||||
docs/analysis/mission
|
||||
# 7 October 2026: the mixer cryptanalysis lane (adv-mixer): an internal adversarial pass that names the lanes, the
|
||||
# coordinator and the operations timeline and quotes binary hashes and seeds; not for the public spec mirror
|
||||
docs/analysis/cryptanalysis
|
||||
docs/plans/cryptanalysis
|
||||
|
|
|
|||
Loading…
Reference in a new issue