Compare commits

...

24 commits

Author SHA1 Message Date
igneum-labs
7d76d9a08b adv-mixer: cadical re-queued (third run) through lease pool on box 2
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 20:13:58 +00:00
igneum-labs
16728d3171 adv-mixer: pool priority classes and label rule in the timeline
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:42:41 +00:00
igneum-labs
03569a2144 adv-mixer: cadical lease released for the class v5 census; ledger and SAT row updated
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:41:45 +00:00
igneum-labs
e38edec586 adv-mixer: owner-based yield test in the timeline
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:31:56 +00:00
igneum-labs
0c7fe45e44 adv-mixer: widened v5 yield rule in the timeline
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:30:12 +00:00
igneum-labs
9a7b70f5db adv-mixer: pool rule rows in the timeline
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:24:49 +00:00
igneum-labs
c043ca3adf adv-mixer: cadical re-queued through lease pool, ledger updated
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:23:02 +00:00
igneum-labs
56a0bb50e4 adv-mixer: kill ledger (cadical, sibling 07) under main's lease rule; SAT row BLOCKED on the lease
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:21:41 +00:00
igneum-labs
77a97e3252 adv-mixer: queue 15 rows (lineindex K5-8, linrel K3-7, integral K8, box-2 fold-sweep replication), logs
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:00:54 +00:00
igneum-labs
cb04d9eaba adv-mixer: consolidated Q1 verdict and status-board row from the deepening
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:58:43 +00:00
igneum-labs
fbb24413c3 adv-mixer: queue file 15, the per-K fill (linrel K3-7, integral K8, lineindex K5-8)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:57:10 +00:00
igneum-labs
cd7ab85456 adv-mixer: two clock labels to London time (the box clock is CEST)
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:56:49 +00:00
igneum-labs
76682349d0 adv-mixer: integral 32-day row, sibling 07 claim note, box-hours update
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:56:05 +00:00
igneum-labs
30b24efbe5 adv-mixer: fold-sweep (1024 days x 71 pairs) and lineindex rows, finished logs in the branch
Internal adversarial pass, not an independent review. 1,454,080,000 of
1,454,080,000 pair-trials violate affinity, 0 dead word pairs, 0 key-order
agreements over 1024 chain days; the 22 line-index bits are clean from K=2
and have no affine relation to the input even at K=1.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:54:14 +00:00
igneum-labs
d10eee9f34 adv-mixer: Q1 deepening rows (linrel 16 days x 3 K, lineindex K1-3, CNF model); sweeps running
Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:52:16 +00:00
igneum-labs
1662a76082 adv-mixer: queue files 11-14 for the Q1 deepening sweeps
Internal adversarial pass, not an independent review. Self-contained queue
files (binary under /srv/builds/_adv-adv-mixer/bin, logs and pid files under
its logs dir, nice 10 on cores 8-95): fold-sweep over 1024 days and all 71
adjacent key pairs, integral over 32 days, lineindex and address-bit linrel,
full-width linrel and the DIMACS commutation instance.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:50:10 +00:00
igneum-labs
a26e52c3dd adv-mixer: fold-sweep, linrel, lineindex, cnf commands for the Q1 deepening
Internal adversarial pass, not an independent review. fold-sweep runs the
affinity and commutation probes over many days and all 71 adjacent key pairs;
linrel is the exact GF(2) affine-relation kernel test at full 32-bit width
(the decidable algebraic probe in place of a SAT solve, which no solver on the
box can run); lineindex tallies the 22 line-index bits of s[0] a chip would
prefetch on; cnf writes the DIMACS commutation instance of two keyed
applications with the real day constants.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:47:19 +00:00
igneum-labs
06f1382f3e adv-mixer: clock labels are TZ=Europe/London (plan 19:09 BST, report 19:40 BST)
The build-remote stamps read earlier were UTC and were labelled BST. Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:43:47 +00:00
igneum-labs
996d0ad353 adv-mixer: finalize report (Q1 BOUND), durable logs, run-box.sh log path
Internal adversarial pass, not an independent review. Q1 (this lane, the
algebraic structure of M_r): the fold probe and the integral cube-sum degree
test on the frozen-identical binary show no composition cheaper than 8x. No
affine fold, no word separability, no key-order commutation; algebraic degree
>= 16 after one application and saturated after two. The 9,360 ops per item
stand. Q2 margin (full diffusion at 2 applications) and Q3 census (best day a
1.17x FPGA multiply datapath, 1 in 2^24, zero wall-time gain, ROT-all-equal
never seen) kept as courtesy runs attributed to adv-mixer-3 and adv-mixer-2.

igneum-pow merged to build/master and re-proven byte-identical to c3d32437;
pre-merge runs re-run on the merged tree and matched. Logs copied into the
branch so the report paths survive; run-box.sh writes outside the mirror.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:40:05 +00:00
igneum-labs
e3fbe5176d Merge remote-tracking branch 'build/master' into adv-mixer 2026-10-07 18:29:52 +00:00
igneum-labs
29a03a0d74 adv-mixer: integral degree-saturation test for Q1; note the re-scope in the plan
Internal adversarial pass, not an independent review. Adds the cube-sum
(higher-order differential) command to bound the algebraic degree of the
applications: a low degree would admit a cheap polynomial batching of the 8
applications, so degree saturation at small d is the no-shortcut bound. Plan
section 8 records main's three-lane re-scope: this lane is the algebraic
structure of M_r.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:27:00 +00:00
igneum-labs
5bddb289c3 adv-mixer: report with Q3 census (BOUND+tail), Q1 fold (BOUND), Q2 running
Internal adversarial pass, not an independent review. Q3 census over 2^24 day
keys: largest per-day M1 FPGA-datapath gain 1.1726x on one day, 3.26e-4 of days
over 1.1x, zero days with any DSP or wall-time gain, ROT-all-equal never seen.
Q1 fold probe: 1e6/1e6 affinity violations, 0 dead word pairs, 0 key-order
agreements, so no cheap composition of the 8 keyed applications. Q2 diffusion
sweep and the f4 analytic tail are running; numbers land as they finish.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:24:11 +00:00
igneum-labs
029e5219d6 adv-mixer: run-box.sh for the Q2 diffusion and Q3 census sweeps on box 2
One log, a pid file beside it, nice 10 on the core band 64-95, kill by pid
file. Internal adversarial pass, not an independent review.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:17:39 +00:00
igneum-labs
6033df803c adv-mixer: attack plan for the memory-hard mixer M_r, harnesses copied
Internal adversarial pass, not an independent review. The plan restates M_r
from the frozen crate and spec 1.8, ranks Q3/Q2/Q1/Q4, gives the method, the
planted known-fail shape and the box-hour estimate per step, and lists every
file opened. Records the byte-identity result: build/master differs from the
frozen commit in accept.rs, emit.rs, generator.rs, packcheck.rs and two test
files, but is byte-identical over memhard.rs, seed.rs, bind.rs, derive.rs and
the Cargo pin, which define M_r.

Harnesses: adv-mixer (new: diffusion margin for Q2, the fold probe for Q1,
with a planted-weak-day hook), f4-weakday (copied read-only from
build/attack-pass for the Q3 census), f8-uniform (copied from the regate
worktree).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:09:36 +00:00
50 changed files with 6632 additions and 0 deletions

View file

@ -0,0 +1,389 @@
# attack-f4 census: 16777216 chain days from day index 20729 (genesis 20729), class v4 shape (mixer x8, cache 2^26), 32 threads, 4.4 s
draw: MixParams::with_shape(seed_words_from_bytes(bind::day_bytes(d)), Shape::for_class(&V4_CLASS)); seed64 = key[0] | key[1] << 32
## Gate (plan 1.4 (3), B5 rank 3): fraction of days with any gain over 1.1x under 2^-20 = 9.537e-7
| Metric | Reference | Days over 1.1x | Fraction | Against 2^-20 |
|---|---|---|---|---|
| M1 per-day LUT datapath, adders per application | median cost 231 (gain over 1.1x = cost under 210) | 5476 | 3.264e-4 | OVER |
| M1 against the mean cost 231.11 (sd 6.19) | cost under 210.10 | 9363 | 5.581e-4 | OVER |
| M2 DSP-bound datapath, 16/(16-k) with k = words of NAF weight <= 3 | k >= 2 | 0 | 0.000e0 | under |
| ROT value (wiring) and RC value (inverters) on a per-day datapath | exact 0 ops moved on every day | 0 | 0 | under |
M1 cost = 64 + sum(NAF(MUL_i) - 1); mean 231.113, sd 6.190, median 231, min 197 (day 4819563), max 263 (day 15262713)
## Classes over 16777216 days
| Class | Count | Fraction | Expected per day (analytic) | Expected count | Worst member (day, M1 cost, M1 gain vs median, M2 gain) |
|---|---|---|---|---|---|
| ROT all equal | 0 | 0.000e0 | 3.635e-11 (1 in 2.751e10) | 0.001 | none |
| ROT distinct <= 3 | 534 | 3.183e-5 | 3.069e-5 (1 in 3.259e4) | 514.813 | day 11482247 , cost 208 , 1.1106x , 1.000x |
| ROT distinct <= 4 | 26010 | 1.550e-3 | 1.537e-3 (1 in 6.507e2) | 25782.741 | day 1092491 , cost 207 , 1.1159x , 1.000x |
| ROT max multiplicity >= 4 | 35631 | 2.124e-3 | 2.350e-3 (1 in 4.256e2) | 39421.474 | day 9506389 , cost 206 , 1.1214x , 1.000x |
| ROT same-word pair sums to 32 | 2062481 | 1.229e-1 | 1.229e-1 (1 in 8.135e0) | 2062288.067 | day 3675001 , cost 201 , 1.1493x , 1.000x |
| ROT any pair sums to 32 | 10022037 | 5.974e-1 | 6.007e-1 (1 in 1.665e0) | 10078561.158 | day 4819563 , cost 197 , 1.1726x , 1.000x |
| ROT all 8 in {1,2,30,31} | 2 | 1.192e-7 | 7.684e-8 (1 in 1.301e7) | 1.289 | day 14330190 , cost 217 , 1.0645x , 1.000x |
| ROT >= 6 in {1,2,30,31} | 1761 | 1.050e-4 | 1.023e-4 (1 in 9.780e3) | 1715.548 | day 155537 , cost 212 , 1.0896x , 1.000x |
| ROT >= 4 in {1,2,30,31} | 211152 | 1.259e-2 | 1.259e-2 (1 in 7.942e1) | 211253.447 | day 12915578 , cost 198 , 1.1667x , 1.000x |
| ROT >= 4 in {8,16,24} | 74541 | 4.443e-3 | 4.456e-3 (1 in 2.244e2) | 74756.114 | day 5517722 , cost 198 , 1.1667x , 1.000x |
| MUL any = 1 | 0 | 0.000e0 | 7.451e-9 (1 in 1.342e8) | 0.125 | none |
| MUL any = 2^32-1 | 0 | 0.000e0 | 7.451e-9 (1 in 1.342e8) | 0.125 | none |
| MUL any popcount <= 2 | 0 | 0.000e0 | 2.384e-7 (1 in 4.194e6) | 4.000 | none |
| MUL any popcount <= 4 | 612 | 3.648e-5 | 3.719e-5 (1 in 2.689e4) | 623.989 | day 7275755 , cost 200 , 1.1550x , 1.000x |
| MUL any popcount <= 8 | 441646 | 2.632e-2 | 2.629e-2 (1 in 3.804e1) | 441000.196 | day 12915578 , cost 198 , 1.1667x , 1.000x |
| MUL any NAF weight <= 2 | 4 | 2.384e-7 | see `expect` | see `expect` | day 7786546 , cost 221 , 1.0452x , 1.067x |
| MUL any NAF weight <= 3 | 216 | 1.287e-5 | see `expect` | see `expect` | day 332924 , cost 207 , 1.1159x , 1.067x |
| MUL any NAF weight <= 4 | 3637 | 2.168e-4 | see `expect` | see `expect` | day 7275755 , cost 200 , 1.1550x , 1.000x |
| MUL any < 256 | 22 | 1.311e-6 | 9.537e-7 (1 in 1.049e6) | 16.000 | day 14317428 , cost 216 , 1.0694x , 1.000x |
| MUL two equal | 0 | 0.000e0 | 5.588e-8 (1 in 1.790e7) | 0.937 | none |
| MUL M2 k >= 2 (gain >= 1.14x) | 0 | 0.000e0 | see `expect` | see `expect` | none |
| RC any = 0 | 0 | 0.000e0 | 3.725e-9 (1 in 2.684e8) | 0.062 | none |
| RC any popcount <= 4 or >= 28 | 5186 | 3.091e-4 | 3.088e-4 (1 in 3.239e3) | 5180.375 | day 7999545 , cost 208 , 1.1106x , 1.000x |
| RC + rk = 0 for any of the 72 keys | 10 | 5.960e-7 | 2.682e-7 (1 in 3.728e6) | 4.500 | day 3194363 , cost 218 , 1.0596x , 1.000x |
| RC two equal | 1 | 5.960e-8 | 2.794e-8 (1 in 3.579e7) | 0.469 | day 2875598 , cost 226 , 1.0221x , 1.000x |
## Histograms
| ROT distinct amounts | Count | Fraction | Expected (S(8,d) 31_d / 31^8) |
|---|---|---|---|
| 1 | 0 | 0.0000e0 | 3.6347e-11 |
| 2 | 4 | 2.3842e-7 | 1.3848e-7 |
| 3 | 530 | 3.1590e-5 | 3.0547e-5 |
| 4 | 25476 | 1.5185e-3 | 1.5061e-3 |
| 5 | 421405 | 2.5118e-2 | 2.5101e-2 |
| 6 | 2773843 | 1.6533e-1 | 1.6533e-1 |
| 7 | 7302781 | 4.3528e-1 | 4.3509e-1 |
| 8 | 6253177 | 3.7272e-1 | 3.7294e-1 |
| ROT amounts in {1,2,30,31} | Count | Expected Binomial(8, 4/31) | ROT amounts in {8,16,24} | Count | Expected Binomial(8, 3/31) | ROT max multiplicity | Count |
|---|---|---|---|---|---|---|---|
| 0 | 5558032 | 5555670.2 | 0 | 7436763 | 7431741.5 | 0 | 0 |
| 1 | 6581255 | 6584498.0 | 1 | 6367439 | 6370064.2 | 1 | 6253177 |
| 2 | 3416505 | 3414184.2 | 2 | 2387947 | 2388774.1 | 2 | 9662112 |
| 3 | 1010272 | 1011610.1 | 3 | 510526 | 511880.2 | 3 | 826296 |
| 4 | 187244 | 187335.2 | 4 | 68359 | 68555.4 | 4 | 34667 |
| 5 | 22147 | 22202.7 | 5 | 5828 | 5876.2 | 5 | 947 |
| 6 | 1696 | 1644.6 | 6 | 345 | 314.8 | 6 | 17 |
| 7 | 63 | 69.6 | 7 | 9 | 9.6 | 7 | 0 |
| 8 | 2 | 1.3 | 8 | 0 | 0.1 | 8 | 0 |
| M2 k (words of NAF weight <= 3) | Count | Gain 16/(16-k) |
|---|---|---|
| 0 | 16777000 | 1.000x |
| 1 | 216 | 1.067x |
| 2 | 0 | 1.143x |
| 3 | 0 | 1.231x |
| Minimum NAF weight over the 16 MUL | Count |
|---|---|
| 2 | 4 |
| 3 | 212 |
| 4 | 3421 |
| 5 | 37733 |
| 6 | 290503 |
| 7 | 1528972 |
| 8 | 4939471 |
| 9 | 7132514 |
| 10 | 2713385 |
| 11 | 130753 |
| 12 | 248 |
| M1 cost per application | Count | Cumulative fraction | M1 gain vs median |
|---|---|---|---|
| 197 | 1 | 5.9605e-8 | 1.1726x |
| 198 | 2 | 1.7881e-7 | 1.1667x |
| 199 | 1 | 2.3842e-7 | 1.1608x |
| 200 | 10 | 8.3447e-7 | 1.1550x |
| 201 | 15 | 1.7285e-6 | 1.1493x |
| 202 | 25 | 3.2187e-6 | 1.1436x |
| 203 | 66 | 7.1526e-6 | 1.1379x |
| 204 | 124 | 1.4544e-5 | 1.1324x |
| 205 | 250 | 2.9445e-5 | 1.1268x |
| 206 | 432 | 5.5194e-5 | 1.1214x |
| 207 | 781 | 1.0175e-4 | 1.1159x |
| 208 | 1382 | 1.8412e-4 | 1.1106x |
| 209 | 2387 | 3.2640e-4 | 1.1053x |
| 210 | 3887 | 5.5808e-4 | 1.1000x |
| 211 | 6602 | 9.5159e-4 | 1.0948x |
| 212 | 10657 | 1.5868e-3 | 1.0896x |
| 213 | 17018 | 2.6011e-3 | 1.0845x |
| 214 | 26180 | 4.1616e-3 | 1.0794x |
| 215 | 39884 | 6.5389e-3 | 1.0744x |
| 216 | 58060 | 9.9995e-3 | 1.0694x |
| 217 | 83645 | 1.4985e-2 | 1.0645x |
| 218 | 117632 | 2.1997e-2 | 1.0596x |
| 219 | 162182 | 3.1663e-2 | 1.0548x |
| 220 | 216961 | 4.4595e-2 | 1.0500x |
| 221 | 283558 | 6.1497e-2 | 1.0452x |
| 222 | 362047 | 8.3076e-2 | 1.0405x |
| 223 | 450814 | 1.0995e-1 | 1.0359x |
| 224 | 550735 | 1.4277e-1 | 1.0312x |
| 225 | 652577 | 1.8167e-1 | 1.0267x |
| 226 | 756846 | 2.2678e-1 | 1.0221x |
| 227 | 855148 | 2.7775e-1 | 1.0176x |
| 228 | 941391 | 3.3386e-1 | 1.0132x |
| 229 | 1011617 | 3.9416e-1 | 1.0087x |
| 230 | 1059221 | 4.5730e-1 | 1.0043x |
| 231 | 1079174 | 5.2162e-1 | 1.0000x |
| 232 | 1070912 | 5.8545e-1 | 0.9957x |
| 233 | 1039183 | 6.4739e-1 | 0.9914x |
| 234 | 980014 | 7.0580e-1 | 0.9872x |
| 235 | 899809 | 7.5944e-1 | 0.9830x |
| 236 | 805446 | 8.0744e-1 | 0.9788x |
| 237 | 700659 | 8.4921e-1 | 0.9747x |
| 238 | 592824 | 8.8454e-1 | 0.9706x |
| 239 | 489326 | 9.1371e-1 | 0.9665x |
| 240 | 391079 | 9.3702e-1 | 0.9625x |
| 241 | 304227 | 9.5515e-1 | 0.9585x |
| 242 | 229565 | 9.6884e-1 | 0.9545x |
| 243 | 168335 | 9.7887e-1 | 0.9506x |
| 244 | 120776 | 9.8607e-1 | 0.9467x |
| 245 | 83871 | 9.9107e-1 | 0.9429x |
| 246 | 56312 | 9.9442e-1 | 0.9390x |
| 247 | 36832 | 9.9662e-1 | 0.9352x |
| 248 | 23268 | 9.9801e-1 | 0.9315x |
| 249 | 14347 | 9.9886e-1 | 0.9277x |
| 250 | 8495 | 9.9937e-1 | 0.9240x |
| 251 | 4856 | 9.9966e-1 | 0.9203x |
| 252 | 2783 | 9.9982e-1 | 0.9167x |
| 253 | 1472 | 9.9991e-1 | 0.9130x |
| 254 | 757 | 9.9995e-1 | 0.9094x |
| 255 | 415 | 9.9998e-1 | 0.9059x |
| 256 | 179 | 9.9999e-1 | 0.9023x |
| 257 | 79 | 1.0000e0 | 0.8988x |
| 258 | 43 | 1.0000e0 | 0.8953x |
| 259 | 23 | 1.0000e0 | 0.8919x |
| 260 | 9 | 1.0000e0 | 0.8885x |
| 261 | 3 | 1.0000e0 | 0.8851x |
| 262 | 4 | 1.0000e0 | 0.8817x |
| 263 | 1 | 1.0000e0 | 0.8783x |
## The 16 lowest-cost days (M1)
- day 4819563: cost 197, gain 1.1726x vs median, NAF sum 149, M2 k 0, day-hex 69676e65756d2d6461792f6b8a490000000000
- day 5517722: cost 198, gain 1.1667x vs median, NAF sum 150, M2 k 0, day-hex 69676e65756d2d6461792f9a31540000000000
- day 12915578: cost 198, gain 1.1667x vs median, NAF sum 150, M2 k 0, day-hex 69676e65756d2d6461792f7a13c50000000000
- day 5073249: cost 199, gain 1.1608x vs median, NAF sum 151, M2 k 0, day-hex 69676e65756d2d6461792f61694d0000000000
- day 295616: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792fc082040000000000
- day 2339457: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f81b2230000000000
- day 7275755: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792feb046f0000000000
- day 7921343: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792fbfde780000000000
- day 10331167: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f1fa49d0000000000
- day 10514223: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f2f6fa00000000000
- day 12709144: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f18edc10000000000
- day 14463384: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f98b1dc0000000000
- day 14777650: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792f327de10000000000
- day 15551477: cost 200, gain 1.1550x vs median, NAF sum 152, M2 k 0, day-hex 69676e65756d2d6461792ff54bed0000000000
- day 515226: cost 201, gain 1.1493x vs median, NAF sum 153, M2 k 0, day-hex 69676e65756d2d6461792f9adc070000000000
- day 2240604: cost 201, gain 1.1493x vs median, NAF sum 153, M2 k 0, day-hex 69676e65756d2d6461792f5c30220000000000
## Worst member of every class, in full
### ROT distinct <= 3: day 11482247
```
day index 11482247 (genesis + 11461518), day bytes 69676e65756d2d6461792f8734af0000000000 , seed64 99b37b14bce80e05
key bce80e05 99b37b14 a88409a4 a5469d0e 35c4b54e c027571b 152552c8 9d942222
ROT [12, 19, 19, 4, 19, 12, 19, 19] distinct 3 max multiplicity 5 small 0 byte-aligned 0 same-word pair 32 false any pair 32 false
MUL 23684433 345dfd6d 13878a5b dff7431f 60e1ffa5 fb7bcf75 ef826109 6fd6c065 1d5b0701 75f4b29f 24197fc1 1367fa6d 87f0f4ed 03b41769 92cbf013 03bbeca7
NAF [11, 11, 11, 9, 9, 10, 9, 10, 9, 12, 8, 11, 10, 10, 11, 9] sum 160 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 93abe65f 6886b6d0 3a68d00d 3889c0c6 b194b674 4094caf5 161c68f0 6b3cdc05 f1fbf7c0 2ee32537 5779f1ba 56b1eabc 914f7e4d 35c47fa0 ab029a5b ae0b61a1
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 208 adder-equivalents per application (14976 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1106x
classes: ROT distinct <= 3; ROT distinct <= 4; ROT max multiplicity >= 4
```
### ROT distinct <= 4: day 1092491
```
day index 1092491 (genesis + 1071762), day bytes 69676e65756d2d6461792f8bab100000000000 , seed64 da149ee55aaab937
key 5aaab937 da149ee5 11819d67 3f60c5a0 6045fabb ac9ede0d 919ff013 7143f2b9
ROT [21, 16, 12, 16, 31, 12, 12, 31] distinct 4 max multiplicity 3 small 2 byte-aligned 2 same-word pair 32 true any pair 32 true
MUL a05bba01 bec09787 7afe483b 28844197 b7eafc73 aa1d3f0f 83508105 f39cc103 d21f51a1 ffa61343 40cfaea1 03bebcd3 7f059f6f b00ededf ca070e07 3bd803db
NAF [9, 10, 9, 10, 11, 11, 9, 11, 12, 11, 10, 10, 9, 9, 10, 8] sum 159 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 9ea401b9 c5b29850 00371b55 5592306c 77d7ec18 f100a72b ca4db32b 82fc9dc4 83168f22 e3359513 ad711b53 b7f5dc09 add1d8ab 982a05b1 06b37a9b 829bb32d
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 207 adder-equivalents per application (14904 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1159x
classes: ROT distinct <= 4; ROT same-word pair sums to 32; ROT any pair sums to 32
```
### ROT max multiplicity >= 4: day 9506389
```
day index 9506389 (genesis + 9485660), day bytes 69676e65756d2d6461792f550e910000000000 , seed64 6982e9080d6a4cdf
key 0d6a4cdf 6982e908 4a0a0b42 a399c15d 99e27fe1 fdfb9b00 4e90d671 78401cd0
ROT [15, 5, 31, 5, 5, 24, 6, 5] distinct 5 max multiplicity 4 small 1 byte-aligned 1 same-word pair 32 false any pair 32 false
MUL 37800e03 d714c2fb a4be52db 87737201 5ac001d7 95f7c07f c1fb39d9 8bdfc411 70097121 e009077d f0ef802b 36f0ebbf 087b2dd7 8270b24d c3b48dad fc354847
NAF [7, 12, 13, 9, 9, 8, 11, 8, 9, 8, 9, 9, 10, 12, 13, 11] sum 158 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC c4769637 de22eaea 7aa5b4ed 46b93f02 41831974 bbd9933b c6a06ba1 c102f45e 6483273a c33cfd56 5669b2b7 f5ee5a3d f4c63fc9 50ccdb45 522844d2 c405d738
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 206 adder-equivalents per application (14832 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1214x
classes: ROT max multiplicity >= 4
```
### ROT same-word pair sums to 32: day 3675001
```
day index 3675001 (genesis + 3654272), day bytes 69676e65756d2d6461792f7913380000000000 , seed64 81ed531eeadd5e68
key eadd5e68 81ed531e 453f3611 4caf9ae6 c9585bb1 115e4232 cdaff538 dc39efc9
ROT [25, 5, 21, 27, 21, 7, 12, 27] distinct 6 max multiplicity 2 small 0 byte-aligned 0 same-word pair 32 true any pair 32 true
MUL 7b011e4d 3c417fc1 9d055513 beea0cb9 207ef901 1df73bdd 7c2034ff 77fe5083 cf567a1f c4311bf1 7dded2b9 7bcae001 e58678b9 0f6dc051 213ef8a9 20afbbb9
NAF [10, 7, 13, 12, 6, 9, 8, 8, 12, 10, 11, 8, 13, 8, 9, 9] sum 153 min 6 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 113c7ffd 754403c6 9d01091b 58b7ed13 a5685eec e1a691a0 e98f235e 3f622792 3fc0a2a9 a8b91f03 3aa824aa 7ff52b9d a7f69c00 3cc25c5e c3a37dd3 90c308ad
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 201 adder-equivalents per application (14472 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1493x
classes: ROT same-word pair sums to 32; ROT any pair sums to 32
```
### ROT any pair sums to 32: day 4819563
```
day index 4819563 (genesis + 4798834), day bytes 69676e65756d2d6461792f6b8a490000000000 , seed64 d4924b5d4dc26798
key 4dc26798 d4924b5d c75c47df 64b4f00f 0836e7ff cd383a15 4c85767a 6a08a753
ROT [26, 18, 8, 30, 24, 24, 6, 9] distinct 7 max multiplicity 2 small 1 byte-aligned 3 same-word pair 32 false any pair 32 true
MUL a0653c83 a09de525 810085fb 6a00eba1 bf8205ff bba82079 f27da4c3 2cb80223 6001efcf 1c2814f7 ae9d09d7 ffedd7b7 943dde01 39ff47e1 0513a83f c028eef9
NAF [11, 11, 7, 10, 7, 10, 12, 10, 7, 9, 13, 8, 8, 8, 9, 9] sum 149 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 3ba362fd 47c4ea3e c8d59f08 c76a1b32 a33837f3 2295b6a8 6578c14a 348c033f 35f3d38e 60755b0f 75437163 235c6abb eae387e0 09ad148b dfd1092c aebb5f8e
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 197 adder-equivalents per application (14184 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1726x
classes: ROT any pair sums to 32
```
### ROT all 8 in {1,2,30,31}: day 14330190
```
day index 14330190 (genesis + 14309461), day bytes 69676e65756d2d6461792f4ea9da0000000000 , seed64 722cea0895f65bbe
key 95f65bbe 722cea08 b6716401 2aa400d8 7e0054e3 7edf5115 73008e0c ea61f647
ROT [1, 1, 2, 31, 1, 31, 1, 31] distinct 3 max multiplicity 4 small 8 byte-aligned 0 same-word pair 32 true any pair 32 true
MUL 5111ff0d 0915ca85 e63f87e3 3a3eec25 74fc4b01 04849df9 740b798f 96300b51 c7c8033d 90111e63 268db4a9 cf40e4a5 ac91052f 18814e21 92657099 3b7fa903
NAF [9, 11, 10, 10, 10, 8, 11, 12, 10, 10, 13, 12, 12, 9, 13, 9] sum 169 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 57ed2402 ab186f3e 8c7e4d2c b7a0915d 6c47d3d1 3ab1c1a5 91ba307f 177182e3 b19522c4 93deec89 cdc3dcc7 c8637063 0abd4442 d4df5f23 4606f7ab 3595b758
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 217 adder-equivalents per application (15624 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.0645x
classes: ROT distinct <= 3; ROT distinct <= 4; ROT max multiplicity >= 4; ROT same-word pair sums to 32; ROT any pair sums to 32; ROT all 8 in {1,2,30,31}; ROT >= 6 in {1,2,30,31}; ROT >= 4 in {1,2,30,31}
```
### ROT >= 6 in {1,2,30,31}: day 155537
```
day index 155537 (genesis + 134808), day bytes 69676e65756d2d6461792f915f020000000000 , seed64 62a533010044516b
key 0044516b 62a53301 877d9dac ad817c3f 788dace2 7cda9997 77fab135 e51ef305
ROT [22, 21, 30, 30, 2, 31, 31, 2] distinct 5 max multiplicity 2 small 6 byte-aligned 0 same-word pair 32 false any pair 32 true
MUL 205bfc49 00e29caf 3e1cdf05 88267f01 efad6031 2edbba8f 5802025d 7b6aef0f db740619 253f4b7b 3310231d ca01a579 5b5b8e69 0b051b43 3fef1507 e10e7aad
NAF [8, 10, 9, 8, 10, 11, 9, 10, 11, 11, 11, 12, 13, 11, 8, 12] sum 164 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 9f220844 5c8a4552 e6f7dc41 bca5026c bac2bcec 8d331e54 eeb4b6f1 7ef67511 602e8964 54ee8e4b b57c03b6 1dd85466 efa50b4d 6d72abe6 2cccea1f d9f6ed77
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 212 adder-equivalents per application (15264 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.0896x
classes: ROT any pair sums to 32; ROT >= 6 in {1,2,30,31}; ROT >= 4 in {1,2,30,31}
```
### ROT >= 4 in {1,2,30,31}: day 12915578
```
day index 12915578 (genesis + 12894849), day bytes 69676e65756d2d6461792f7a13c50000000000 , seed64 57f6497ce6d7a118
key e6d7a118 57f6497c fefb5f19 c79046cc b1a6df7d aa592471 1cd1d432 48e25d80
ROT [30, 30, 31, 17, 16, 31, 13, 9] distinct 6 max multiplicity 2 small 4 byte-aligned 1 same-word pair 32 false any pair 32 false
MUL 41406225 06c21421 80fe91b1 145d8359 10c01035 2025c17f 7f801477 1b53081b 547e7dc7 381c841f 02baf16b 6ce88fef 08e447f9 077440cd 9dddb2d7 7ae58045
NAF [9, 8, 9, 11, 8, 8, 7, 11, 10, 8, 11, 10, 8, 10, 12, 10] sum 150 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC a7246db5 dff83962 82647cfd 3eb91ca4 b17e51e1 f10dc65b b24a5f72 3e849586 2a1248a1 f44e7f64 ad012d93 0074a57e b10c2709 2986079c 9f0b9f4c 0f1c9565
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 198 adder-equivalents per application (14256 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1667x
classes: ROT >= 4 in {1,2,30,31}; MUL any popcount <= 8
```
### ROT >= 4 in {8,16,24}: day 5517722
```
day index 5517722 (genesis + 5496993), day bytes 69676e65756d2d6461792f9a31540000000000 , seed64 6cb96c5fb4321712
key b4321712 6cb96c5f a77367f6 b2719260 5edf1eba 183ecb78 4522b1e7 560ae215
ROT [19, 8, 24, 20, 19, 8, 2, 8] distinct 5 max multiplicity 3 small 1 byte-aligned 4 same-word pair 32 false any pair 32 true
MUL 1bce207f 382ff2bd f60fdaaf 424a1321 f6590551 231258b3 546dc127 08ac8085 070a003d 41bbfd91 c5dfc81b 007b2f19 983f01e7 0847837f 060f90a7 040e9015
NAF [8, 10, 10, 10, 12, 13, 11, 9, 7, 8, 10, 9, 9, 7, 9, 8] sum 150 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC ff224509 ec7e2a5b 5968f4aa b9a7e963 df762e0d 1e62e44e 2fa7540b 0aa0e15d ab38c25f a88b3cb8 006e698c 2bfc51dc 5e0d671a 7b9af6ce a0a8e6e0 89595bcb
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 198 adder-equivalents per application (14256 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1667x
classes: ROT any pair sums to 32; ROT >= 4 in {8,16,24}
```
### MUL any popcount <= 4: day 7275755
```
day index 7275755 (genesis + 7255026), day bytes 69676e65756d2d6461792feb046f0000000000 , seed64 8c466b2af98a2e86
key f98a2e86 8c466b2a 7aeceb13 73b046e4 6bf5ee94 1f2ffb0c 68e00b58 8939ea67
ROT [7, 20, 3, 30, 26, 14, 14, 9] distinct 7 max multiplicity 2 small 1 byte-aligned 0 same-word pair 32 false any pair 32 false
MUL 22b167d9 1217c0ff 83f9d6ff 53f47821 9e6f203f 8ddf1105 503197e7 5203053f 18100001 b1afa8e1 fc0d2e77 47d30207 a62e473f 9a30a787 f7fb9443 4453f77d
NAF [12, 7, 8, 9, 9, 9, 11, 9, 4, 12, 11, 9, 12, 12, 9, 9] sum 152 min 4 =1 0 =-1 0 pop<=4 1 naf<=3 0 <256 0 dup false
RC ffb825e4 f8be0580 73dbb4cf 358c1f2f 27cf0dda bb3480ee 7b357f42 e12fe90f fb7486d5 429d3607 2d5bd341 7d426c5c 3ca53a8d 6bba1a7b 834a9b7b 4b7ebe4f
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 200 adder-equivalents per application (14400 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1550x
classes: MUL any popcount <= 4; MUL any popcount <= 8; MUL any NAF weight <= 4
```
### MUL any NAF weight <= 2: day 7786546
```
day index 7786546 (genesis + 7765817), day bytes 69676e65756d2d6461792f32d0760000000000 , seed64 7ac5b9e18cde6f44
key 8cde6f44 7ac5b9e1 39a3e509 a2faa026 6a1437c0 a21b7c6b 2a625719 405689b1
ROT [25, 7, 21, 19, 12, 28, 9, 25] distinct 7 max multiplicity 2 small 0 byte-aligned 0 same-word pair 32 false any pair 32 true
MUL a9f9aaa5 393fdfb5 fb11d523 8c2df7b7 e9c31551 cb349fcd c9dd7baf 3e676067 6359fad5 53e1ffeb 000007ff 6057c76d 3c86f067 b791a083 3738eec7 b42ba445
NAF [14, 9, 12, 10, 13, 14, 11, 11, 13, 8, 2, 11, 10, 11, 11, 13] sum 173 min 2 =1 0 =-1 0 pop<=4 0 naf<=3 1 <256 0 dup false
RC 8af42dee f0e6dcd6 1e594042 eee6defb bc86dccf 6cfa11fe 4f8ba636 455f5e8a d21de702 382b305f 56a1c147 b386e182 3d2d8d04 756a3cd8 71ed29eb 7b08de97
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 221 adder-equivalents per application (15912 per item, 72 applications); M2 k 1 (gain 1.067x)
M1 gain against the census median 231: 1.0452x
classes: ROT any pair sums to 32; MUL any NAF weight <= 2; MUL any NAF weight <= 3; MUL any NAF weight <= 4
```
### MUL any NAF weight <= 3: day 332924
```
day index 332924 (genesis + 312195), day bytes 69676e65756d2d6461792f7c14050000000000 , seed64 f808897c2547d426
key 2547d426 f808897c 513cca7d 52f7f508 3c4e673e 02a296f7 7d51ea58 cc6a6d4c
ROT [1, 23, 1, 1, 12, 11, 16, 18] distinct 6 max multiplicity 3 small 3 byte-aligned 1 same-word pair 32 false any pair 32 false
MUL 02fe3349 ebfbb02d 03ffc001 bd03f177 c59affa1 080e4a8f 02ce4063 466595f5 3e80970f 00f39991 0937c1c5 49a3a27f 1705f1db e14c5f59 feb802ed b3c7e543
NAF [10, 10, 3, 10, 11, 9, 10, 14, 9, 10, 9, 11, 10, 12, 9, 12] sum 159 min 3 =1 0 =-1 0 pop<=4 0 naf<=3 1 <256 0 dup false
RC 1b116748 5923a322 2b3a87a3 a6766c2f ce61047f ed58e672 59023641 a5898f72 65026fe7 7fcc8696 ee849527 ae5ac84c 48c6da86 870d31f1 aa7bafdc 163aa9fa
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 207 adder-equivalents per application (14904 per item, 72 applications); M2 k 1 (gain 1.067x)
M1 gain against the census median 231: 1.1159x
classes: MUL any NAF weight <= 3; MUL any NAF weight <= 4
```
### MUL any < 256: day 14317428
```
day index 14317428 (genesis + 14296699), day bytes 69676e65756d2d6461792f7477da0000000000 , seed64 15a13158d6510a3e
key d6510a3e 15a13158 269297c4 5bceb8e2 aea8a2ed dabc3585 4076bc5c 01bec51f
ROT [11, 14, 4, 19, 28, 12, 20, 23] distinct 8 max multiplicity 1 small 0 byte-aligned 0 same-word pair 32 false any pair 32 true
MUL dc9e0e77 6f487117 f3e164b9 f5615c89 f9f33575 16ee44f7 1f2f8205 a6506901 3003f653 efdc8cc5 0e4ab3c9 000000eb 2c230eef 6b843c71 b8e67d17 7cba91df
NAF [11, 11, 12, 12, 13, 10, 8, 11, 9, 11, 12, 4, 10, 10, 13, 11] sum 168 min 4 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 1 dup false
RC ebf15842 e0a148eb a2e4ee1d 1fc2bea3 2d63622e c45c96bf b3a36493 486b4d26 00366580 61c9b1c0 b884e3ea e3e9b598 d42d5626 a9115df7 87259e61 f5ce1730
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup false
M1 cost 216 adder-equivalents per application (15552 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.0694x
classes: ROT any pair sums to 32; MUL any popcount <= 8; MUL any NAF weight <= 4; MUL any < 256
```
### RC any popcount <= 4 or >= 28: day 7999545
```
day index 7999545 (genesis + 7978816), day bytes 69676e65756d2d6461792f39107a0000000000 , seed64 c93bd7b37f21862d
key 7f21862d c93bd7b3 5b8af838 808161f4 824aa21f 2e361c27 3a9893f5 a174f291
ROT [2, 9, 21, 30, 26, 31, 20, 6] distinct 8 max multiplicity 1 small 3 byte-aligned 0 same-word pair 32 false any pair 32 true
MUL 5eeafff1 20d43481 f82a157b b074ba81 6fd05fab 0436f05d bf4b2e11 200619df fd87f81b af944de5 ed74aadf 8fca07c3 1446e11f 43fc06c5 01c1b977 484a8ac3
NAF [8, 10, 11, 12, 10, 9, 12, 8, 8, 12, 13, 9, 9, 8, 9, 12] sum 160 min 8 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 864fb298 1ac6b021 33767a7e 9368cb81 e8846716 1aa3ce3d 9812d074 67e4fc2c e4778444 c36dd02b fee3ffff 04723a67 4138fef0 ddf770c6 83dac053 28e4d10c
RC zero 0 pop<=4|>=28 1 rc+rk=0 0 dup false
M1 cost 208 adder-equivalents per application (14976 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.1106x
classes: ROT any pair sums to 32; RC any popcount <= 4 or >= 28
```
### RC + rk = 0 for any of the 72 keys: day 3194363
```
day index 3194363 (genesis + 3173634), day bytes 69676e65756d2d6461792ffbbd300000000000 , seed64 bc1e82a5c9f5ddde
key c9f5ddde bc1e82a5 96ab4399 0671592a bb1c6360 3913fe9a 9804267d 299ae13d
ROT [1, 7, 16, 9, 15, 4, 30, 22] distinct 8 max multiplicity 1 small 2 byte-aligned 1 same-word pair 32 false any pair 32 false
MUL e7190f35 650c36eb afa6090b a8fb90ef 034e3297 862b6f0d dbf807f5 284be071 dbf8a029 100809e5 23747809 71ab3457 40f884c9 bf8f55e7 f1549811 996781e5
NAF [13, 12, 12, 10, 12, 12, 8, 9, 9, 7, 9, 14, 9, 11, 11, 12] sum 170 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC d8cfa0e8 b7d3cbda 43cfc80c d25da2da 2e0e8163 c53232b1 b12fccd0 554503c1 926caee2 0e443238 f57e07fb 2b6fa3e6 3cbf689c 85b2a4b4 7ba7972d d9c14302
RC zero 0 pop<=4|>=28 0 rc+rk=0 1 dup false
M1 cost 218 adder-equivalents per application (15696 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.0596x
classes: RC + rk = 0 for any of the 72 keys
```
### RC two equal: day 2875598
```
day index 2875598 (genesis + 2854869), day bytes 69676e65756d2d6461792fcee02b0000000000 , seed64 cbb947500a68806e
key 0a68806e cbb94750 a7becf69 57289c05 faec9414 c10772ba d2903fe5 74af4324
ROT [29, 30, 4, 8, 19, 13, 25, 29] distinct 7 max multiplicity 2 small 1 byte-aligned 1 same-word pair 32 false any pair 32 true
MUL f2f52c69 155a7899 e6ff1b2f 8ca5703d 4643df15 8100291f c31dad25 bc9cfef1 73c502d7 72f4b489 ae01e6dd 67dfd461 0b1d0b75 fa948d61 1dd832eb 0e09fb03
NAF [14, 13, 11, 12, 10, 7, 13, 10, 11, 13, 11, 10, 12, 12, 11, 8] sum 178 min 7 =1 0 =-1 0 pop<=4 0 naf<=3 0 <256 0 dup false
RC 16dd5198 a438a5ee d0ef08a1 29be50c8 9758bd94 4983af82 ad80a68b 1c6080f9 9dbb6eb7 491a03b8 b5c6622a cf646720 9a211c17 f952fecb 56c26eec b5c6622a
RC zero 0 pop<=4|>=28 0 rc+rk=0 0 dup true
M1 cost 226 adder-equivalents per application (16272 per item, 72 applications); M2 k 0 (gain 1.000x)
M1 gain against the census median 231: 1.0221x
classes: ROT any pair sums to 32; RC two equal
```

View file

@ -0,0 +1,3 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
cnf day=20729 vars=105652 clauses=361188 written /srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf
BLOCKED on the solve: no SAT solver reaches the box (crates.io refused, none installed); the model is the artefact

View file

@ -0,0 +1,76 @@
adv-mixer diffusion sweep; internal adversarial pass, not an independent review
a01bf61016a8bda530468f081442131f1bff4a7b6401dd84cbcde83c78bb48f3
UTC_START 2026-10-07T18:19:48Z
===== K=1 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=1 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.461177 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 578 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 111997 of 262144
worst cell: in_bit 60 -> out_bit 107 p = 1.000000 dev = 0.500000 (1414.2 sigma)
VERDICT: FINDING (holes or strong bias at this K)
===== K=2 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=2 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.500001 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 107 -> out_bit 490 p = 0.501702 dev = 0.001702 (4.8 sigma)
VERDICT: no distinguisher at this K
===== K=3 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=3 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 112 -> out_bit 295 p = 0.498383 dev = 0.001617 (4.6 sigma)
VERDICT: no distinguisher at this K
===== K=4 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=4 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 220 -> out_bit 106 p = 0.498354 dev = 0.001646 (4.7 sigma)
VERDICT: no distinguisher at this K
===== K=5 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=5 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 453 -> out_bit 93 p = 0.498283 dev = 0.001717 (4.9 sigma)
VERDICT: no distinguisher at this K
===== K=6 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=6 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 494 -> out_bit 479 p = 0.498377 dev = 0.001623 (4.6 sigma)
VERDICT: no distinguisher at this K
===== K=7 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=7 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.500000 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 161 -> out_bit 378 p = 0.501592 dev = 0.001592 (4.5 sigma)
VERDICT: no distinguisher at this K
===== K=8 =====
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=8 start=0 states=2000000 threads=32
mean output-flip probability over all 262144 cells: 0.500001 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 202 -> out_bit 367 p = 0.498295 dev = 0.001705 (4.8 sigma)
VERDICT: no distinguisher at this K
UTC_END 2026-10-07T18:30:40Z

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
fold-sweep from_day=20729 days=1024 pairs_per_day=71 trials_per_pair=20000
(a) affinity violations: 1454080000 of 1454080000 pair-trials; lowest per-pair violation fraction 1.000000 (1.0 = never affine)
(b) dead word pairs summed over 1024 days: 0 (0 = complete dependency every day)
(c) key-order agreements: 0 of 1454080000 pair-trials
VERDICT: BOUND: no fold on any day or pair probed

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
fold-sweep from_day=20729 days=1024 pairs_per_day=71 trials_per_pair=20000
(a) affinity violations: 1454080000 of 1454080000 pair-trials; lowest per-pair violation fraction 1.000000 (1.0 = never affine)
(b) dead word pairs summed over 1024 days: 0 (0 = complete dependency every day)
(c) key-order agreements: 0 of 1454080000 pair-trials
VERDICT: BOUND: no fold on any day or pair probed

View file

@ -0,0 +1,609 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
integral day=20729 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 236.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 184.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 175.0/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 172.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 172.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 173.3/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 175.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 174.6/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 175.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 177.6/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 182.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 184.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 187.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 191.5/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 196.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 203.3/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20730 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 229.8/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 177.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 165.9/512 [degree >= d reached]
d= 4 nonzero 1999/2000 = 0.9995 mean out-bits set 158.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 157.5/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 161.0/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 162.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 164.2/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 169.2/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 174.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 183.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 188.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 192.3/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 198.6/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 205.7/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 213.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20731 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 242.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 194.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 184.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 185.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 186.4/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 188.1/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 190.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 191.4/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 195.0/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 199.2/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 202.4/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 206.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 216.2/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 219.5/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 223.8/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20732 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 233.5/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 182.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 170.5/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 164.6/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 160.9/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 159.5/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 159.3/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 161.5/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 165.1/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 168.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 173.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 176.8/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 185.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 187.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 190.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20733 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 188.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 175.5/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 173.1/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 171.5/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 171.5/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 175.0/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 173.4/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 176.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 178.9/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 187.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 192.4/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 194.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20734 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 232.8/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 186.6/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 177.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 173.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 170.4/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 171.0/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 174.0/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 177.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 181.6/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 188.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 193.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.6/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 208.8/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 213.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 220.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20735 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 230.6/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 182.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 168.7/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 163.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 161.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 161.6/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 164.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 163.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 167.6/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 168.8/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 176.4/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 182.4/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 188.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 191.6/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 199.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 205.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20736 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 238.6/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.3/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 178.7/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 178.3/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 185.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 194.8/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 198.4/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 204.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 209.6/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 214.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 220.5/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 225.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20737 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 237.4/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 180.5/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 178.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 177.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 177.5/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 180.7/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 183.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 186.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 193.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 195.9/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 202.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 204.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 206.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20738 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 198.5/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 189.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 191.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 194.3/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 195.5/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 202.7/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 204.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 208.8/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 216.6/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 219.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 223.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 228.7/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 232.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20739 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 194.6/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 189.0/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 189.4/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 191.3/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 193.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 196.4/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 202.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 204.1/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 206.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 209.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 212.6/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 216.0/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 218.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 218.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 221.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20740 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 241.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.6/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 186.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 186.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 189.6/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 192.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 196.5/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 199.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 202.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 208.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 214.9/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 218.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 223.5/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 227.4/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 231.6/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20741 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 231.6/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 177.5/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 163.4/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 157.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 153.5/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 152.6/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 152.0/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 155.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 159.1/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 164.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 169.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 173.6/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 183.2/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 187.3/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 191.8/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20742 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 244.5/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 204.5/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 197.1/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 201.4/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 204.6/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 206.6/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 211.5/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 214.7/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 216.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 219.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 222.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 224.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 225.1/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 226.0/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 226.7/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 228.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20743 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 238.8/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 191.6/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 183.7/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 183.3/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 184.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 183.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 186.7/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 188.7/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 190.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 193.2/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 196.6/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 201.4/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 206.7/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 211.4/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 214.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 219.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20744 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 233.3/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 188.4/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 175.6/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 172.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 173.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 173.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 180.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 184.2/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 189.6/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 191.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 196.3/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 203.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 206.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 207.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20745 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.6/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 197.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 189.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 188.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 188.9/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 193.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 194.7/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 199.3/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 201.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 206.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 209.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 213.5/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 218.6/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 221.3/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 224.3/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 228.3/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20746 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 236.4/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 180.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 179.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 174.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 178.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 182.5/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 183.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 189.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 194.4/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 196.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 199.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 201.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 204.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20747 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 181.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 178.9/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 180.3/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 177.7/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 180.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 183.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 186.3/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 189.3/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 190.5/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 195.0/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 198.4/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 203.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 206.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20748 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 242.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 199.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 188.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 189.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 189.6/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 192.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 193.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 196.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 198.6/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 202.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 205.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 210.5/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 215.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 218.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20749 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.5/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.6/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 187.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 187.1/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 188.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 188.3/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 191.5/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 193.3/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 197.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 200.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 204.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 207.3/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 212.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 215.8/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 219.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 223.5/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20750 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 236.7/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 186.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 179.7/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 178.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 182.6/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 191.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 194.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 198.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 202.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 208.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 212.6/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 216.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 221.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 225.3/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20751 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 242.5/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.4/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 187.0/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 186.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 187.6/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 189.0/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 194.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 196.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 200.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 203.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 207.5/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 210.7/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 215.6/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 219.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 223.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20752 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.1/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 182.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 172.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 168.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 166.3/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 166.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 167.7/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 167.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 169.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 170.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 172.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 175.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 177.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 179.3/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 183.7/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 188.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20753 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.7/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 198.2/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 190.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 192.4/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 193.5/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 195.7/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 196.2/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 198.5/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 199.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 201.3/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 204.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 203.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 205.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20754 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 238.7/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 190.9/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 181.6/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 178.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 180.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 178.5/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 179.4/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 183.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 186.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 192.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 196.3/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 202.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 208.0/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 211.0/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 217.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20755 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 239.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 196.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 187.4/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 185.7/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 186.5/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 184.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 185.6/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 186.3/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 189.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 191.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 195.9/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 198.3/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 202.0/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 205.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 208.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20756 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 230.8/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 166.6/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 163.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 162.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 164.6/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 169.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 172.5/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 177.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 182.2/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 187.7/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 193.8/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 200.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 205.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 210.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 215.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20757 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 241.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 197.6/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 192.8/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 193.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 193.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 203.0/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 207.5/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 210.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 215.2/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 219.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 223.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 226.3/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 229.0/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 231.9/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 232.5/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20758 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 235.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 189.4/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 174.4/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 172.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 169.6/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 170.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 169.6/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 174.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 177.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 181.6/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 184.5/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 188.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 193.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 197.2/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 204.0/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 208.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20759 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 240.8/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 200.3/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 190.6/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 189.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 192.9/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 193.2/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 197.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 197.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 200.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 202.6/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 207.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 208.8/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 215.1/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 219.3/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 223.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 227.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20760 apps=1 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 234.7/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 184.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 176.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 177.8/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 178.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 182.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 184.4/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 188.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 190.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 191.2/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 195.6/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 199.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 201.2/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 205.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 211.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications

View file

@ -0,0 +1,609 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
integral day=20729 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20730 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20731 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20732 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20733 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.7/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20734 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20735 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20736 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.7/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20737 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20738 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20739 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20740 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20741 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20742 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20743 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20744 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20745 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.6/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20746 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20747 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20748 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20749 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20750 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20751 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20752 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20753 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20754 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20755 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20756 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20757 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.5/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20758 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.4/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20759 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.5/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20760 apps=2 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=15 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=16 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications

View file

@ -0,0 +1,69 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
integral day=20729 apps=8 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.6/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20730 apps=8 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20731 apps=8 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
integral day=20732 apps=8 placements_per_d=2000 threads=44
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d= 2 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 3 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d= 4 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 5 nonzero 2000/2000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 7 nonzero 2000/2000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 8 nonzero 2000/2000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 9 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=10 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=11 nonzero 2000/2000 = 1.0000 mean out-bits set 256.3/512 [degree >= d reached]
d=12 nonzero 2000/2000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d=13 nonzero 2000/2000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d=14 nonzero 2000/2000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=1 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.427506 (ideal 0.5); band 8 sigma = 0.004000
holes: 70 of 11264; strong-bias cells: 6904 of 11264
worst cell: in_bit 127 -> addr_bit 10 p = 0.000001 (1000.0 sigma)
VERDICT: FINDING (address bits predictable at this K)

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=2 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.500007 (ideal 0.5); band 8 sigma = 0.004000
holes: 0 of 11264; strong-bias cells: 0 of 11264
worst cell: in_bit 491 -> addr_bit 10 p = 0.498051 (3.9 sigma)
VERDICT: no address-bit distinguisher at this K

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=3 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.500005 (ideal 0.5); band 8 sigma = 0.004000
holes: 0 of 11264; strong-bias cells: 0 of 11264
worst cell: in_bit 497 -> addr_bit 20 p = 0.501943 (3.9 sigma)
VERDICT: no address-bit distinguisher at this K

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=4 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.499998 (ideal 0.5); band 8 sigma = 0.004000
holes: 0 of 11264; strong-bias cells: 0 of 11264
worst cell: in_bit 13 -> addr_bit 16 p = 0.498123 (3.8 sigma)
VERDICT: no address-bit distinguisher at this K

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=5 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.499995 (ideal 0.5); band 8 sigma = 0.004000
holes: 0 of 11264; strong-bias cells: 0 of 11264
worst cell: in_bit 30 -> addr_bit 6 p = 0.502168 (4.3 sigma)
VERDICT: no address-bit distinguisher at this K

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=6 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.500003 (ideal 0.5); band 8 sigma = 0.004000
holes: 0 of 11264; strong-bias cells: 0 of 11264
worst cell: in_bit 203 -> addr_bit 10 p = 0.502329 (4.7 sigma)
VERDICT: no address-bit distinguisher at this K

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=7 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.499995 (ideal 0.5); band 8 sigma = 0.004000
holes: 0 of 11264; strong-bias cells: 0 of 11264
worst cell: in_bit 374 -> addr_bit 21 p = 0.501813 (3.6 sigma)
VERDICT: no address-bit distinguisher at this K

View file

@ -0,0 +1,6 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
lineindex day=20729 apps=8 states=1000000 threads=44 (22 address bits x 512 input bits = 11264 cells)
mean address-bit flip probability: 0.499987 (ideal 0.5); band 8 sigma = 0.004000
holes: 0 of 11264; strong-bias cells: 0 of 11264
worst cell: in_bit 412 -> addr_bit 4 p = 0.498147 (3.7 sigma)
VERDICT: no address-bit distinguisher at this K

View file

@ -0,0 +1,17 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20730 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20731 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20732 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20733 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20734 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20735 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20736 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)

View file

@ -0,0 +1,17 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20730 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20731 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20732 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20733 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20734 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20735 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20736 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)

View file

@ -0,0 +1,33 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20733 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20734 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20735 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20736 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20737 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20738 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20739 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20740 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20741 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20742 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20743 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20744 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,33 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20733 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20734 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20735 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20736 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20737 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20738 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20739 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20740 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20741 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20742 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20743 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20744 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,9 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,9 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,9 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,9 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,9 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,33 @@
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
linrel day=20729 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20733 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20734 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20735 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20736 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20737 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20738 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20739 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20740 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20741 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20742 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20743 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20744 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)

View file

@ -0,0 +1,70 @@
FROZEN_HEAD d8eea5f7 igneum-pow IDENTICAL to 017e7037
bin 179b77a5bb1e2158004d4044de6d6622cf649ce6e8cc5e69623053e849651274
UTC_START 2026-10-07T18:32:17Z
### fold confirm
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
fold day=20729 trials=1000000
(a) GF(2) affinity violations of the 2-application map: 1000000 of 1000000 (0 would be a BREAK: the map is affine)
(b) dead (in_word -> out_word) pairs over the full 8-application block: 0 of 256 (any would be a broken dependency)
(c) key-order agreements M(M(.,rk1),rk2) == M(M(.,rk2),rk1): 0 of 1000000 (any would let keys fold)
VERDICT: BOUND: no fold on these probes
### integral apps=1
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
integral day=20729 apps=1 placements_per_d=4000 threads=48
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 4000/4000 = 1.0000 mean out-bits set 236.1/512 [degree >= d reached]
d= 2 nonzero 4000/4000 = 1.0000 mean out-bits set 185.4/512 [degree >= d reached]
d= 3 nonzero 4000/4000 = 1.0000 mean out-bits set 174.6/512 [degree >= d reached]
d= 4 nonzero 4000/4000 = 1.0000 mean out-bits set 172.3/512 [degree >= d reached]
d= 5 nonzero 4000/4000 = 1.0000 mean out-bits set 172.5/512 [degree >= d reached]
d= 6 nonzero 4000/4000 = 1.0000 mean out-bits set 172.3/512 [degree >= d reached]
d= 7 nonzero 4000/4000 = 1.0000 mean out-bits set 174.6/512 [degree >= d reached]
d= 8 nonzero 4000/4000 = 1.0000 mean out-bits set 174.7/512 [degree >= d reached]
d= 9 nonzero 4000/4000 = 1.0000 mean out-bits set 176.1/512 [degree >= d reached]
d=10 nonzero 4000/4000 = 1.0000 mean out-bits set 177.9/512 [degree >= d reached]
d=11 nonzero 4000/4000 = 1.0000 mean out-bits set 181.2/512 [degree >= d reached]
d=12 nonzero 4000/4000 = 1.0000 mean out-bits set 183.6/512 [degree >= d reached]
d=13 nonzero 4000/4000 = 1.0000 mean out-bits set 187.3/512 [degree >= d reached]
d=14 nonzero 4000/4000 = 1.0000 mean out-bits set 191.5/512 [degree >= d reached]
d=15 nonzero 4000/4000 = 1.0000 mean out-bits set 196.4/512 [degree >= d reached]
d=16 nonzero 4000/4000 = 1.0000 mean out-bits set 203.1/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
### integral apps=2
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
integral day=20729 apps=2 placements_per_d=4000 threads=48
d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)
d= 1 nonzero 4000/4000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d= 2 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 3 nonzero 4000/4000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 4 nonzero 4000/4000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
d= 5 nonzero 4000/4000 = 1.0000 mean out-bits set 256.2/512 [degree >= d reached]
d= 6 nonzero 4000/4000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 7 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d= 8 nonzero 4000/4000 = 1.0000 mean out-bits set 255.7/512 [degree >= d reached]
d= 9 nonzero 4000/4000 = 1.0000 mean out-bits set 256.0/512 [degree >= d reached]
d=10 nonzero 4000/4000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=11 nonzero 4000/4000 = 1.0000 mean out-bits set 256.4/512 [degree >= d reached]
d=12 nonzero 4000/4000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=13 nonzero 4000/4000 = 1.0000 mean out-bits set 256.1/512 [degree >= d reached]
d=14 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=15 nonzero 4000/4000 = 1.0000 mean out-bits set 255.8/512 [degree >= d reached]
d=16 nonzero 4000/4000 = 1.0000 mean out-bits set 255.9/512 [degree >= d reached]
READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications
### diffusion spot K=1,2
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=1 start=0 states=2000000 threads=48
mean output-flip probability over all 262144 cells: 0.461179 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 551 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 112032 of 262144
worst cell: in_bit 29 -> out_bit 76 p = 1.000000 dev = 0.500000 (1414.2 sigma)
VERDICT: FINDING (holes or strong bias at this K)
self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9
diffusion day=20729 plant=none apps=2 start=0 states=2000000 threads=48
mean output-flip probability over all 262144 cells: 0.500001 (ideal 0.5)
census band: 8 sigma = 0.002828 (2000000 states)
dependency holes (p == 0 or p == 1 exactly): 0 of 262144
strong-bias cells (|p-0.5| > band, not a hole): 0 of 262144
worst cell: in_bit 203 -> out_bit 42 p = 0.501711 dev = 0.001711 (4.8 sigma)
VERDICT: no distinguisher at this K
UTC_END 2026-10-07T18:34:01Z

View file

@ -0,0 +1,5 @@
start igneum-build-1 2026-10-07T18:50:38Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
== fold-sweep-1024d 2026-10-07T18:50:38Z
rc=0
VERDICT: BOUND: no fold on any day or pair probed
end 2026-10-07T18:52:02Z

View file

@ -0,0 +1,6 @@
start igneum-build-2 2026-10-07T18:50:34Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
== integral-a1-32d 2026-10-07T18:50:34Z
rc=0
== integral-a2-32d 2026-10-07T18:52:24Z
rc=0
end 2026-10-07T18:54:55Z

View file

@ -0,0 +1,50 @@
start igneum-build-1 2026-10-07T18:50:38Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
== lineindex-k1 2026-10-07T18:50:38Z
rc=0
VERDICT: FINDING (address bits predictable at this K)
== lineindex-k2 2026-10-07T18:50:53Z
rc=0
VERDICT: no address-bit distinguisher at this K
== lineindex-k3 2026-10-07T18:51:14Z
rc=0
VERDICT: no address-bit distinguisher at this K
== lineindex-k4 2026-10-07T18:51:33Z
rc=0
VERDICT: no address-bit distinguisher at this K
== linrel-addr-a1-8d 2026-10-07T18:51:53Z
rc=0
linrel day=20729 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20730 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20731 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20732 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20733 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20734 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20735 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20736 apps=1 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
== linrel-addr-a2-8d 2026-10-07T18:51:54Z
rc=0
linrel day=20729 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20730 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20731 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20732 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20733 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20734 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20735 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
linrel day=20736 apps=2 samples=8192 columns=535 (512 in + 22 out + 1) rank=535 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7657)
end 2026-10-07T18:51:55Z

View file

@ -0,0 +1,108 @@
start igneum-build-2 2026-10-07T18:50:34Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
== linrel-full-a1-16d 2026-10-07T18:50:34Z
rc=0
linrel day=20729 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20733 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20734 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20735 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20736 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20737 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20738 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20739 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20740 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20741 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20742 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20743 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20744 apps=1 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== linrel-full-a2-16d 2026-10-07T18:50:37Z
rc=0
linrel day=20729 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20733 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20734 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20735 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20736 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20737 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20738 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20739 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20740 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20741 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20742 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20743 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20744 apps=2 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== linrel-full-a8-16d 2026-10-07T18:50:39Z
rc=0
linrel day=20729 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20733 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20734 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20735 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20736 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20737 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20738 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20739 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20740 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20741 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20742 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20743 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20744 apps=8 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== cnf-commute-20729 2026-10-07T18:50:44Z
rc=0
cnf day=20729 vars=105652 clauses=361188 written /srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf
BLOCKED on the solve: no SAT solver reaches the box (crates.io refused, none installed); the model is the artefact
end 2026-10-07T18:50:44Z

View file

@ -0,0 +1,69 @@
start igneum-build-2 2026-10-07T18:57:10Z bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 /srv/builds/_adv-adv-mixer/bin/attack-adv-mixer
== fold-sweep-1024d 2026-10-07T18:57:10Z
rc=0
VERDICT: BOUND: no fold on any day or pair probed
== linrel-full-a3-4d 2026-10-07T18:58:29Z
rc=0
linrel day=20729 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=3 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== linrel-full-a4-4d 2026-10-07T18:58:30Z
rc=0
linrel day=20729 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=4 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== linrel-full-a5-4d 2026-10-07T18:58:31Z
rc=0
linrel day=20729 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=5 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== linrel-full-a6-4d 2026-10-07T18:58:31Z
rc=0
linrel day=20729 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=6 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== linrel-full-a7-4d 2026-10-07T18:58:32Z
rc=0
linrel day=20729 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20730 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20731 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
linrel day=20732 apps=7 samples=8192 columns=1025 (512 in + 512 out + 1) rank=1025 kernel_dim=0
BOUND: no exact affine relation a.x XOR b.y = c over the 8192 samples (false-survivor odds 2^-7167)
== integral-a8-4d 2026-10-07T18:58:33Z
rc=0
== lineindex-k5 2026-10-07T18:58:42Z
rc=0
VERDICT: no address-bit distinguisher at this K
== lineindex-k6 2026-10-07T18:58:56Z
rc=0
VERDICT: no address-bit distinguisher at this K
== lineindex-k7 2026-10-07T18:59:14Z
rc=0
VERDICT: no address-bit distinguisher at this K
== lineindex-k8 2026-10-07T18:59:42Z
rc=0
VERDICT: no address-bit distinguisher at this K
end 2026-10-07T19:00:02Z

View file

@ -0,0 +1,337 @@
# Report: adversarial cryptanalysis of the mixer M_r
Internal adversarial pass, not an independent review.
The label "internal adversarial pass, not an independent review" applies to every sentence here that could be
quoted in public. This is such a pass. It is not an outside review.
## Header
| Field | Value |
|---|---|
| Target commit | 017e70376489251e18564c0abce7e466e606c8b3 (class v4 sub-version 3, object byte 7) |
| Target | the mixer M_r (spec 01 section 1.8.4): 8 keyed applications between reads, 72 per item, class v4 (m = 8) |
| Lane | adv-mixer, narrowed by main (19:2x BST) to the ALGEBRAIC STRUCTURE of M_r (Q1); Q2 is adv-mixer-3, Q3 is adv-mixer-2 |
| Branch | adv-mixer; working HEAD d8eea5f7 (merge of build/master 04c4d9bc) |
| Byte-identity | after the merge, `git diff --quiet 017e70376489251e18564c0abce7e466e606c8b3 HEAD -- igneum-pow` prints IDENTICAL: the whole crate is the frozen object. The branch was first cut from stale master 3f0afcd5 whose igneum-pow differed in 6 non-mixer files; those pre-merge runs were re-run on the merged tree and match (see below) |
| Harness attack-adv-mixer (merged) | sha256 179b77a5bb1e2158004d4044de6d6622cf649ce6e8cc5e69623053e849651274 |
| Harness attack-f4 census (stale, mixer-identical) | sha256 d51df6caab338b0165485c3ce6d6379c0af7180bf2b72fc0a1531beabeaf2d22 |
| Boxes | igneum-build-2 (box 2) and igneum-build-1 (box 1), nice 10 |
| Toolchain | rustc 1.99.0 both sides |
| Day under test | chain day index 20729 (genesis, 3 October 2026), bind::day_bytes(20729) |
| Clock | plan pushed 19:09 BST; first results in this report 19:40 BST (ask line 00:00 BST); times are TZ=Europe/London |
## Status board
| Q | Lane | Method | Known-failed shape | Gate | Result (numbers) | Status |
|---|---|---|---|---|---|---|
| Q1 algebraic structure | adv-mixer (this) | fold probes (1024 days x 71 key pairs), exact GF(2) affine-relation kernel at full width, integral cube-sum degree (32 days), the 22 line-index bits, a SAT model of two applications | the probes are their own control; the diffusion plant fired | affinity violations > 0, dead pairs = 0, key agreements = 0, kernel = 0, degree saturates | 1,454,080,000/1,454,080,000 affinity violations, 0 dead word pairs, 0 key-order agreements over 1024 days; kernel 0 at K = 1, 2, 8 on 16 days (full width) and on the address bits; degree >= 16 after 1 application and saturated after 2 on 32 days; address bits clean from K = 2 | PASS (BOUND: no composition cheaper than 8x; 9,360 ops per item stand) |
| Q2 round margin | adv-mixer-3 (courtesy run here) | diffusion avalanche census K=1..8, 2e6 states | diffusion --plant weak (fired) | full diffusion at K | distinguisher reaches K=1 only; K=2..8 clean (0 holes, 0 strong, worst 4.5 to 4.9 sigma) | BOUND (handed to adv-mixer-3) |
| Q3 weak draws | adv-mixer-2 (courtesy run here) | f4 census over 2^24 days | plant alleq/mul1/mul1all/rc0/rcrk0 (all fired) | any class >= 1.1x on a non-negligible fraction | M1 cost 197 to 263, mean 231.1; best day a 1.17x smaller FPGA multiply datapath, 1 day in 2^24; 0 days DSP or wall-time gain; ROT-all-equal never seen | BOUND+tail (handed to adv-mixer-2) |
## Q1: the algebraic structure of M_r (BOUND: no composition cheaper than 8x)
The question. The 8 keyed applications between two cache reads differ only in the round key rk. Can they be
evaluated in fewer than 8x one application, by folding or commuting the multiply layer, by a surviving
differential, linear or rotational property of the drawn double round, or by a low-degree algebraic form of the
composition? Any gain is priced in ops per item against the chip model's 9,360 (hoisted, m = 8).
Two measurements, both on the frozen-identical binary (sha 179b77a5), day 20729.
### Fold probe
Command (box 1):
```
nice -n 10 attack-adv-mixer fold --day 20729 --trials 1000000
```
| Probe | Result | Reading |
|---|---|---|
| (a) GF(2) affinity of the 2-application map g | 1,000,000 of 1,000,000 quadruples violate g(a)+g(b)+g(c)+g(a+b+c)=g(0) | g is maximally far from affine; the two multiply layers do not fold through the double round |
| (b) dead (in_word, out_word) pairs over the full 8-application block | 0 of 256 | every output word depends on every input word; no separability to split on |
| (c) key-order agreements M(M(.,rk1),rk2) == M(M(.,rk2),rk1) | 0 of 1,000,000 | key order matters; the 8 round keys cannot be folded or commuted |
### Integral (algebraic-degree) cube-sum test
Command (box 1):
```
nice -n 10 attack-adv-mixer integral --day 20729 --apps 1 --dmax 16 --placements 4000 --threads 48
nice -n 10 attack-adv-mixer integral --day 20729 --apps 2 --dmax 16 --placements 4000 --threads 48
```
For each cube dimension d the harness XOR-sums the output over all 2^d flips of d random input bits, over 4000
random placements. A zero sum on every output bit would prove algebraic degree < d (a low-degree form a shortcut
could exploit). The result:
| Applications | d = 1..16 | Cube-sum nonzero fraction | Mean output bits set per cube-sum | Reading |
|---|---|---|---|---|
| 1 | every d | 1.0000 at every d | 172 to 236 of 512 | degree >= 16 already after one application |
| 2 | every d | 1.0000 at every d | about 256 of 512 (half) | saturated: two applications look like a random high-degree map up to degree 16 |
Verdict for Q1. No composition cheaper than 8x was found. The multiply layers of adjacent applications are
separated by a nonlinear double round and do not merge (fold probe a). The drawn double round gives no
commutation that would fold keys (fold probe c). The word-dependency is complete at 8 applications (fold probe
b). The algebraic degree reaches at least 16 after a single application and saturates after two, so there is no
low-degree algebraic or integral form of even one application, let alone the 8, that an attacker could batch. The
8 keyed applications cost 8x on this evidence. Priced against the chip model: 0 ops saved per item; the 9,360 ops
per item stand. This is a BOUND, not a proof: the integral test reaches degree 16 (2^16 cube), and the fold
probe is GF(2)-degree-1; an exact algebraic-degree measurement above 16 and a SAT or MILP algebraic form are owed
work. One line on what a longer pass would add: it would pin the exact degree above 16 and rule out a
medium-degree (17 to 40) relation the cube test at d = 16 cannot see; it would not change the no-fold bound.
## Q2: the round margin (courtesy run; lane adv-mixer-3)
Command (box 2), per K in 1..8:
```
nice -n 10 attack-adv-mixer diffusion --day 20729 --apps K --states 2000000 --threads 32
```
Log: docs/analysis/cryptanalysis/logs/adv-mixer/diffusion-K1-8.log (copied off the box). Census band at 2e6 states is 8
sigma = 0.00283, so a per-cell bias below 0.28 percent is invisible; quoted with the result.
| K applications | Dependency holes | Strong-bias cells (> 8 sigma) | Worst cell | Verdict |
|---|---|---|---|---|
| 1 | 578 of 262144 | 111997 of 262144 | 1414 sigma | distinguisher reaches K=1 |
| 2 | 0 | 0 | 4.8 sigma | clean |
| 3 | 0 | 0 | 4.6 sigma | clean |
| 4 | 0 | 0 | 4.7 sigma | clean |
| 5 | 0 | 0 | 4.9 sigma | clean |
| 6 | 0 | 0 | 4.6 sigma | clean |
| 7 | 0 | 0 | 4.5 sigma | clean |
| 8 | 0 | 0 | 4.8 sigma | clean |
The plant fired: the degenerate day (MUL all 1, RC all 0, ROT all 16) at K=1 gave 7894 holes and 236269 strong
cells, worst 223.6 sigma. Reading: the strict-avalanche distinguisher reaches only 1 application. Full diffusion
at 2 applications. Margin against the 8 between reads: 6 applications (8 minus 2). Margin against the 72 per item:
70. This is an avalanche census, not a trail search; a bias below 0.28 percent at K=2 is invisible. The
differential, linear, rotational-XOR and SAT/MILP tightening is adv-mixer-3's lane; handed over.
## Q3: weak parameter draws (courtesy run; lane adv-mixer-2)
Command (box 2):
```
nice -n 10 taskset -c 64-95 attack-f4 census --from 20729 --count 16777216 --threads 32
```
16,777,216 days (2^24), 4.4 s. Log: docs/analysis/cryptanalysis/logs/adv-mixer/census-2pow24.log (copied off the box).
The M1 metric is the per-day FPGA LUT datapath adder count, 64 + sum(NAF(MUL_i) - 1). Convention-free facts over
2^24 days:
| Quantity | Value |
|---|---|
| M1 cost range | 197 (day 4819563) to 263 (day 15262713) |
| M1 cost mean, sd | 231.1, 6.19 |
| Best attacker day | multiply datapath 197/231.1 = 0.853 of mean, a 1.17x smaller datapath, on 1 day in 2^24 |
| Days with any M2 (DSP-bound) gain, k >= 2 | 0 |
| Days with a ROT or RC wall-time gain | 0 (bit-exact verifier; ROT is wiring, RC is inverters) |
| ROT all equal (the spec's untested worry) | 0 of 2^24 (analytic 1 in 2.751e10 days) |
| MUL any = 1, MUL two equal, RC any = 0 | 0, 0, 0 |
Open cross-check for the Q3 lane owner: the census computes the over-1.1x count against its own measured median
231 (5476 days, 3.26e-4), while the analytic `expect` tool reports a reference median 221 and an over-1.1x
fraction near 8.6e-7 (about 14.5 days in 2^24). The two references differ by 10 adders; the convention-free range
above does not depend on the choice. Reconciling the median is handed to adv-mixer-2. Either way the best day is a
1.17x FPGA-datapath gain the chip model does not credit as hash rate (the chip is bound by the 8 cache reads and
the fixed op count, not by one day's multiply-adder count), and a weak day is a public calendar.
## Q1 deepening (from 19:4x BST): more days, all key pairs, exact relations, the address bits, a SAT model
Main's re-scope asked for the probes at full 32-bit width over more days and more rk pairs, a SAT model of two
keyed applications for an algebraic relation, and a relation search in the s[0] line-index bits. Binary sha256
bbfab24075923083f0c9c8c4372a6dd22257c245bac75ba6fadbd60ab64ec803 (frozen-identical tree, same bytes on both
boxes). Queue files tools/attack/adv-mixer/queue/11..14, claimed in /srv/builds/_adv/mixer/claims. Logs under
/srv/builds/_adv-adv-mixer/logs on each box, copied into docs/analysis/cryptanalysis/logs/adv-mixer when done.
### Exact affine-relation search at full width (linrel), queue 14, box 2
Command: `attack-adv-mixer linrel --day 20729 --apps K --samples 8192 --days 16` for K in 1, 2, 8. Each sample
is a GF(2) row over 1025 columns (512 input bits, 512 output bits, the constant). Rank 1025 means no exact
affine relation a.x XOR b.y = c exists between the input and output bits of K applications; a chance survivor
has odds 2^-(8192-1025) = 2^-7167.
| Applications K | Days (20729 to 20744) | Rank | Kernel dimension | Reading |
|---|---|---|---|---|
| 1 | 16 of 16 | 1025 | 0 | no affine relation after one application |
| 2 | 16 of 16 | 1025 | 0 | no affine relation after two |
| 3, 4, 5, 6, 7 (queue 15) | 4 of 4 each (20729 to 20732) | 1025 | 0 | no affine relation at any intermediate count |
| 8 | 16 of 16 | 1025 | 0 | no affine relation across the full between-reads block |
This is the decidable algebraic probe the brief's "algebraic form" question needs: at full width with the real
day constants there is no linear or affine structure a chip could use to batch or predict the 8 applications.
### The line-index bits of s[0] (lineindex), queue 13, box 1
Command: `attack-adv-mixer lineindex --day 20729 --apps K --states 1000000 --threads 44`. The 22 address bits
(s[0] AND 2^22-1) against each of the 512 input bits; band 8 sigma = 0.004 at 1e6 states.
| K | Mean address-bit flip | Holes / 11264 | Strong cells / 11264 | Worst cell | Verdict |
|---|---|---|---|---|---|
| 1 | 0.4275 | 70 | 6904 | 1000 sigma | FINDING: address bits predictable after one application |
| 2 | 0.500007 | 0 | 0 | 3.9 sigma | clean |
| 3 | 0.5000 | 0 | 0 | inside band | clean |
| 4 | 0.499998 | 0 | 0 | 3.8 sigma | clean |
| 5 | 0.5000 | 0 | 0 | 4.3 sigma | clean (queue 15) |
| 6 | 0.5000 | 0 | 0 | 4.7 sigma | clean (queue 15) |
| 7 | 0.5000 | 0 | 0 | 3.6 sigma | clean (queue 15) |
| 8 | 0.5000 | 0 | 0 | 3.7 sigma | clean (queue 15) |
The address bits are clean at every application count from 2 to 8, the full between-reads block.
Address-restricted exact relation search, `linrel --addr --apps K --samples 8192 --days 8` (535 columns: 512
input bits, the 22 address bits, the constant):
| K | Days (20729 to 20736) | Rank | Kernel | Reading |
|---|---|---|---|---|
| 1 | 8 of 8 | 535 | 0 | no affine relation to the address bits even after one application |
| 2 | 8 of 8 | 535 | 0 | none after two |
Reading for the chip: the line index a read depends on is not predictable before the second of the 8
applications completes, so a prefetch cannot hide more than 1 of the 8 applications behind the memory latency.
The K=1 predictability is incomplete diffusion (holes and strong cells), not a linear leak: no affine relation
between the input and the address bits exists even at K=1.
### Fold probes over 1024 days and all 71 adjacent key pairs (fold-sweep), queue 11, box 1
Command: `attack-adv-mixer fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44`: probes (a) and
(c) on every adjacent application pair (i, i+1) for i in 0..70 and probe (b) on the full block, per day. 1024
days x 71 pairs x 20,000 trials = 1,454,080,000 pair-trials. Wall 84 s on box 1 at load about 400.
| Probe | Result over 1024 days and 71 pairs | Reading |
|---|---|---|
| (a) affinity violations | 1,454,080,000 of 1,454,080,000; lowest per-pair violation fraction 1.000000 | no adjacent pair of applications is affine on any day |
| (b) dead word pairs, summed over 1024 days | 0 | complete word dependency every day |
| (c) key-order agreements | 0 of 1,454,080,000 | no key pair commutes on any day |
Verdict: the fold bound of the first report holds at every one of the 71 between-application seams, on every
one of 1024 consecutive chain days (about 2.8 years of calendar). No fold, no commutation, no separability.
### Integral degree test over 32 days (integral), queue 12, box 2
Command: `attack-adv-mixer integral --day 20729 --apps K --dmax 16 --placements 2000 --days 32` for K = 1, 2.
32 consecutive chain days (20729 to 20760), cube dimensions d = 1..16, 2000 placements each: 512 (day, d) rows
per K. Wall about 4 min on box 2 at load about 500.
| Applications K | Rows with every cube-sum nonzero | Output bits set per cube-sum (min to max over days) | Reading |
|---|---|---|---|
| 1 | 511 of 512 (the one exception: day 20730, d = 4, 1999 of 2000 placements) | 156 to 245 of 512 | degree >= 16 on every day; the single zero cube-sum in 1,024,000 placements is a chance zero, not a relation (a relation would zero every placement) |
| 2 | 512 of 512 | 255.5 to 256.7 of 512 | saturated at the random-map value of 256 on every day |
Verdict: the degree floor of the first report (>= 16 after one application, saturated after two) holds on
32 consecutive days. No day has a low-degree algebraic form of the applications. Queue 15 added the full
8-application block on 4 days (d = 1..14, 2000 placements): 56 of 56 rows at fraction 1.0000, 255.6 to 256.4
bits set, saturated.
### Queue 15, the per-K fill and a cross-box replication (box 2)
Queue file 15 re-ran the 1024-day fold-sweep first (its header slice carried that line over from file 11), which
makes a replication on the other box: 1,454,080,000 of 1,454,080,000 affinity violations, 0 dead word pairs,
0 key-order agreements, identical to box 1 (log fold-sweep-1024d-box2-replication.log). Then linrel at K = 3..7,
integral at K = 8 and lineindex at K = 5..8, all folded into the tables above. Wall 2 min 52 s at load about 500.
### SAT model of two keyed applications (cnf), queue 14 then a solve on box 2
Command: `attack-adv-mixer cnf --day 20729 --out .../adv-mixer-commute-20729.cnf`. Bit-exact Tseitin encoding
of M(M(x,rk1),rk2) and M(M(x,rk2),rk1) on a shared 512-variable input with the two outputs constrained equal:
105,652 variables, 361,188 clauses, 6.8 MB. SAT = a state on which the two key orders commute; UNSAT = a proof
over all 2^512 states that fold probe (c) holds exactly. No solver reaches the box from crates.io (HTTP 403), so
the harness marks the solve BLOCKED; the sibling lane adv-mixer-3 has cadical 3.0.1 built from source on box 2,
and that binary is running on this instance under a one-hour cap at nice 10 (log sat-commute-20729.log).
KILLED at 20:20 BST under main's rule that every hand-started sweep stops and re-queues through `lease pool`:
cadical ran 1,749 s wall on one thread (162 MB peak) and reached neither SAT nor UNSAT, which was the expected
outcome inside the hour: the instance is a preimage-shaped search on a 2^512 space, so a cap-out bounds solver
reach only and is no evidence either way. The CNF stays on box 2 at
/srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf (6.8 MB) for a re-queue through `lease pool` once
that subcommand exists (at 20:21 BST `lease --help` offered `lease cores` and `lease status` only). Re-queued
through `lease pool 1` at 20:22 BST the minute the subcommand landed (log sat-commute-20729-lease.log), then
RELEASED at 20:41 BST on main's order so the class v5 census (owner class-v5, 88 cores, the 0.3.24 critical path)
can take box 2's pool: 1,106 s run, no SAT or UNSAT. Two cadical runs total 2,855 s of solving on this instance
with no decision, which is the expected shape for a preimage-sized search. Re-queued a third time at 21:13 BST
when main opened box 2 (log sat-commute-20729-lease2.log, core 9, cap to 22:13 BST). RUNNING; the row lands
here.
## Q1 consolidated verdict (internal adversarial pass, not an independent review)
Across every probe this lane ran at full 32-bit width with the real day constants, no composition of the 8
keyed applications between two cache reads costs less than 8 times one application.
| Candidate shortcut from the brief | Evidence | Status |
|---|---|---|
| The multiply layer folds or commutes across applications (only rk changes) | adjacent-pair affinity violated on 1,454,080,000 of 1,454,080,000 trials over 1024 days and all 71 seams; key-order commutation 0 of 1,454,080,000 | ruled out at the probe's reach |
| An exact linear or affine relation across the composition | GF(2) kernel 0 (rank 1025 of 1025) at K = 1, 2 and 8 on 16 days; kernel 0 on the 22 address bits at K = 1 and 2 | ruled out exactly (chance survivor 2^-7167) |
| A low-degree algebraic form to batch the applications | cube-sums nonzero at every d up to 16 after one application, saturated at 256 of 512 bits after two, on 32 days | ruled out below degree 16; above 16 is owed |
| A predictable line index that lets a chip prefetch the read early | address bits predictable only after 1 application (incomplete diffusion, no linear leak); clean from K = 2 | at most 1 of 8 applications hides behind the memory latency |
| An exact commutation witness (SAT model) | 105,652-variable, 361,188-clause instance; cadical 3.0.1 running under a 1 h cap | pending; a timeout bounds solver reach only |
Priced against the chip model: 0 ops saved per item; 9,360 ops per item stand. What a longer pass would add:
an exact algebraic-degree measurement above 16 (the cube test stops at 2^16 points) and a solver run long
enough to decide the commutation instance; neither would move the fold or the affine bound, which are exact or
exhaustive at their reach. The probes cover 1024 consecutive chain days from genesis, about 2.8 years of the
public calendar.
## Sibling queue files run by this lane
Per main's rule (claim the next unclaimed sibling file in name order once the own queue is empty), this lane
claimed and ran the following. The results belong to the owning lane and are not interpreted here.
| File | Owner | Claimed | Run on | Result |
|---|---|---|---|---|
| 07-adv-mixer-3-days.sh | adv-mixer-3 | 19:54 BST | box 1, nice 10, cores 8-95 | KILLED 20:20 BST under main's rule after 6 of 56 steps (index day 20730 k = 2, 3, 4, 8; sac day 20730 k = 2, 3; every one "uniform within the band" or clean per the owner's grep); my claim released so the owner or any lane re-queues it through the lease; the owner's logs stay in /srv/builds/_adv-mixer-3/logs |
## Confirmation across the stale and frozen trees
The branch was first cut from stale master 3f0afcd5. Its igneum-pow differed from the frozen object in six
non-mixer files (accept.rs, emit.rs, generator.rs, packcheck.rs, tests/mixer.rs, tests/recheck.rs); memhard.rs,
seed.rs, bind.rs, derive.rs and the Cargo pin were byte-identical. After `git merge build/master` the whole crate
is byte-identical to 017e7037 (IDENTICAL). The Q1 fold and the K=1 and K=2 diffusion spot-checks were re-run on
the merged binary and match the stale runs within sampling noise (K=1 holes 551 merged vs 578 stale, K=2 clean on
both). So the stale-tree Q2 and Q3 numbers coincide with the frozen object. The self-check asserts the spec 1.8.4
genesis ROT, MUL and RC vectors on every run.
## Box-hours and pod-hours spent
No GPU pods used: pod-hours 0. All CPU, nice 10, both boxes.
| Step | Box | Wall |
|---|---|---|
| Builds (adv-mixer x2, f4 x2) | box 1 and 2 | about 1.5 min total |
| f4 five plant firings | box 2 | about 3 min |
| f4 census 2^24 | box 2 | 4.4 s |
| f4 expect analytic tail | box 1 | a few min (log later wiped by a box re-sync; numbers captured) |
| Q2 diffusion sweep K=1..8, 2e6 states | box 2 | 11 min |
| Q1 fold + integral + spot-checks | box 1 | 1 min 44 s |
| Q1 deepening queue 11 fold-sweep 1024 days | box 1 | 84 s |
| Q1 deepening queue 12 integral 32 days | box 2 | 4 min 21 s |
| Q1 deepening queue 13 lineindex + addr linrel | box 1 | 77 s |
| Q1 deepening queue 14 linrel + cnf | box 2 | 10 s |
| Q1 deepening queue 15 per-K fill + fold-sweep replication | box 2 | 2 min 52 s |
| cadical on the commutation CNF | box 2 | one thread, capped at 1 h |
| Sibling 07-adv-mixer-3-days.sh (owner adv-mixer-3) | box 1 | running |
Total about 0.6 box-hours of the 8-hour first-results budget (ask line 16), plus up to 1 core-hour of cadical.
Pod-hours 0. Both boxes ran at load 240 to 555 on 96 cores during the deepening (sibling sweeps, not builds), so
wall times above are under heavy sharing.
## Rule-change timeline (so the box-hours stay honest)
| Time (BST) | Change | Effect on this lane |
|---|---|---|
| 19:1x | both boxes, nice 10, drop the single band | adopted; runs moved off a single 32-core band |
| 19:2x | three-lane re-scope: this lane is Q1 only | Q2 and Q3 kept as courtesy runs, attributed |
| 19:3x | merge build/master, re-prove igneum-pow identical | done, IDENTICAL; pre-merge runs re-run and matched |
| 19:3x | drop SIGSTOP yield, run on cores 8-95 only | no yield was ever added; run-box.sh band set to 8-95; direct nohup runs at nice 10 |
| 20:20 | main: every hand-started sweep is killed by its pid file now and re-queued through `lease pool`; release builds and the class v5 suites outrank sweeps | killed cadical (box 2, 29 min lost, no result) and sibling 07 (box 1, 6 of 56 steps done, claim released); nothing started since; `lease pool` absent at 20:21, so the re-queue waits on it |
| 20:22 | `lease pool` live on both boxes (lease sha f814b447) | cadical re-queued the same minute through `lease pool 1 --owner adv-mixer --nice 10`, core 8, 1 h cap |
| 20:41 | main: box 2's pool must show 0 adv-* holders for the class v5 census; the yield to a class-v5 waiter is mechanical at shard end from now | released the cadical lease by pid file; nothing held on either box |
| 21:13 | main: box 2 open to adv-* (the class v5 census ended, no pool lease there) | cadical re-queued the same minute as `lease pool 1 --min 1`, core 9 |
| 20:4x | pool priority classes (release > v5 > measure > adv, lease sha 5d84d644); a 1-thread holder is never pre-empted; label rule: no "release", "canary", "pair", "v5 gate", "v5 kit" or "measure" in a sweep label | the cadical re-queue keeps its label "adv-mixer cadical commutation CNF day 20729, 1 h cap", which carries none of the reserved words, and goes out as `lease pool 1 --min 1` when main confirms the census is running |
| 20:2x | pool rule: a sweep lease asks for at most 48 cores with --min at the least usable; the yield test is by OWNER (refined at 20:3x): yield to a waiter whose owner is class-v5, or whose owner is attack-pass with "v5" in its label, never to a waiter whose owner starts with adv-; on a yield, finish the shard in hand and release; release builds and v5 suites outrank every sweep | adopted for any further lease; the one-core cadical lease is cleared by main to its 21:23 BST cap |
### Kill ledger (main's rule, 20:20 BST)
| Process | Box | pid-file | Killed (UTC) | Lost | Re-queue |
|---|---|---|---|---|---|
| cadical on adv-mixer-commute-20729.cnf | 2 | sat-commute-20729.log.pid | 19:20:41Z | 1,749 s of a 3,600 s cap, no SAT or UNSAT | RE-QUEUED 19:22:46Z (20:22 BST) through `lease pool 1 --owner adv-mixer --nice 10` the minute the subcommand landed; holding 1 pool core, 1 h cap; pid file sat-commute-20729-lease.log.pid |
| 07-adv-mixer-3-days.sh (owner adv-mixer-3) | 1 | queue-07-adv-mixer-3-days.sh.log.pid | 19:20:47Z | 50 of 56 steps unrun; the 6 done are in the owner's logs | claim released; owner or next free lane |
| cadical, the leased re-run (lease pool 1, core 8) | 2 | sat-commute-20729-lease.log.pid | 19:41:11Z (20:41 BST), main's order so the class v5 census takes box 2's pool | 1,106 s of a fresh 3,600 s cap, no SAT or UNSAT; 2,494 s of cap lost | RE-QUEUED 20:13:28Z (21:13 BST) on main's word that box 2 is open: `lease pool 1 --min 1 --owner adv-mixer --nice 10`, core 9, class adv, 1 h cap to 22:13 BST; pid file sat-commute-20729-lease2.log.pid; a 1-thread holder is never pre-empted |
Both kills were the wrapper pid from the pid file plus its descendants (one cadical, one adv-mixer-3), TERM then
KILL; no process of this lane remained on either box afterwards.

View file

@ -0,0 +1,226 @@
# Attack plan: the memory-hard mixer M_r
Internal adversarial pass, not an independent review.
Label rule: the phrase "internal adversarial pass, not an independent review" goes on every sentence from this
work that could be quoted in public. This is such a pass. It is not an outside review.
- Target commit: 017e70376489251e18564c0abce7e466e606c8b3 (class v4 sub-version 3, object byte 7).
- Branch: adv-mixer, from build/master.
- Attacker model: an outsider with the public kit. No defender numbers are read; any defender figure here is
derived from the crate or marked unknown.
- Author identity in the mixer: the attacker has never worked on the hash code.
## 0. The byte-identity check (the brief's gate 1)
The brief asks that `git diff --stat 017e7037... HEAD -- igneum-pow` print nothing. It does NOT print nothing.
Six files differ between the frozen commit and build/master HEAD:
| File | In the target? |
|---|---|
| igneum-pow/src/accept.rs | No (program acceptance, not the mixer) |
| igneum-pow/src/emit.rs | No (kernel emitters) |
| igneum-pow/src/generator.rs | No (program generator; V4_CLASS and Shape present on both) |
| igneum-pow/src/packcheck.rs | No (pack checker) |
| igneum-pow/tests/mixer.rs | No (test harness) |
| igneum-pow/tests/recheck.rs | No (test harness) |
The mixer itself is byte-identical. `git diff --stat 017e7037... HEAD -- igneum-pow/src/memhard.rs
igneum-pow/src/seed.rs igneum-pow/src/bind.rs igneum-pow/src/derive.rs igneum-pow/Cargo.toml
igneum-pow/Cargo.lock` prints nothing. So the mixer draw code (seed.rs), the mixer function and the item
derivation (memhard.rs), the day rule (bind.rs) and the dependency pin (Cargo.toml, Cargo.lock) are the frozen
ones. The harness builds against build/master's igneum-pow, whose generator.rs and accept.rs differ from frozen;
those files are not M_r. So the numbers this harness produces are the frozen mixer's numbers. Stated plainly:
build/master is NOT byte-identical to the frozen commit over the whole crate, but it IS byte-identical over every
file that defines M_r and its parameters.
## 1. The target, in the attacker's words
The dataset item is 16 words of 32 bits. The mixer M is one keyed round made of two layers.
1. Multiply layer, per word: `s[i] = (s[i] XOR (RC[i] + rk)) * MUL[i]`. MUL[i] is odd, so the multiply is a
bijection on 32 bits. rk is the 32-bit round key, the only thing that changes between applications.
2. Diffusion layer: one ChaCha-shaped double round. Four column quarter rounds with rotations ROT[0..3], then
four diagonal quarter rounds with ROT[4..7]. A quarter round is add, xor, rotate, four times.
Per item, class v4 (`mixer_mult = 8`): init the state from the day key and `t`, then for each of 8 rounds apply
M eight times (keys `round_key(r*8 + j)`, j = 0..7) and do one dependent cache read; after the last read apply M
eight more times. 9 x 8 = 72 applications per item. Only the round key changes between the 72. ROT (8 values in
1..31), MUL (16 odd values), RC (16 values) are drawn once per day from one SplitMix64 stream seeded with
`K[0] | (K[1] << 32)`, K the day key.
The day key is `seed_words_from_bytes("igneum-day/" || day_le64)` on the chain (interim rule, `bind::day_bytes`),
or `seed_words("day/" + iso)` in the spec's examples. The day is a pure function of the calendar day, so a weak
day is a public calendar.
The round key is `round_key(k) = (k + 1) * 0x9E3779B9 mod 2^32`. The 72 keys are the first 72 odd-ish multiples
of 0x9E3779B9. They are fixed, not drawn.
The cost model (chip-model-v3.md, read sections 1, 2, 5, 6): 130 ops per application hoisted, 9,360 ops per item,
1,198,080 ops per hash at m = 8. A shortcut is priced in ops per item against 9,360.
## 2. The questions, in attack order
The order is cheapest-reproducible first, then the structural questions.
| Rank | Q | What a result looks like |
|---|---|---|
| 1 | Q3 weak parameter draws | counted fraction of days in each class over >= 2^24 day keys, per-day op gain |
| 2 | Q2 round margin | largest K applications a distinguisher reaches, against 8 and 72 |
| 3 | Q1 structural shortcut | an op count below 8x for the 8 keyed applications, or the bound |
| 4 | Q4 anything else | any other measured gain |
## 3. Method per question
### Q3, weak parameter draws (harness: f4-weakday, copied read-only into tools/attack/f4-weakday)
The census walks consecutive chain days through the real draw code (`MixParams::with_shape`) and classifies each
day. Classes: ROT all equal, ROT distinct <= 3 or 4, ROT max multiplicity >= 4, ROT pair sums to 32 (same word
and any), ROT all or mostly in {1,2,30,31} or {8,16,24}; MUL any = 1, any = 2^32-1, any low popcount or low NAF
weight, any < 256, two equal, M2 class (NAF weight <= 3 frees a DSP); RC any = 0, RC + rk = 0 for any of the 72
keys, RC extreme popcount, two equal. The gain metric M1 is the per-day LUT datapath cost in adder-equivalents,
`32 adds + 32 xors + sum(NAF(MUL_i) - 1)`, gain = census median cost over the day cost. M2 gain = 16/(16-k).
Tool: `attack-f4 census --from 20729 --count 16777216 --threads 32 [--out file]`. Also `attack-f4 expect
--threads 32` for the exact analytic tail (NAF weight and popcount tables over all 2^31 odd constants, the
16-fold convolution), so the counted census is checked against the closed form.
Gate: the plan's gain gate is 1.1x. Any class with a per-day gain at or above 1.1x on a non-negligible fraction
of days is a FINDING. A verifier is bit-exact and never skips an application, so ROT and RC values hand a
datapath 0 ops and are reported as structure, not as a wall-time gain. Only MUL weight moves the LUT cost.
Known-failed shapes (the plant must fire): `attack-f4 plant alleq` (ROT all equal), `plant mul1` (one MUL = 1),
`plant mul1all` (all MUL = 1), `plant rc0` (one RC = 0), `plant rcrk0` (RC + rk = 0). Each prints the day 20729
draw with the planted field and the detector must flag the matching class.
### Q2, the round margin (harness: adv-mixer diffusion, new)
The strict-avalanche census of K consecutive keyed applications, K = 1..12, over N random states. For each state,
flip each of 512 input bits, apply K applications, tally the output bit-flip probability p[in][out]. Report, per
K: dependency holes (p exactly 0 or 1), strong-bias cells (|p - 0.5| above 8 sigma), the worst cell and its
sigma. A distinguisher reaches K if a hole or a strong bias survives at K. The bound is the largest such K
against the 8 between reads and the 72 per item.
Tool: `attack-adv-mixer diffusion --day 20729 --apps K --states 2000000 --threads 32` for K in 1..12. Also
`--start-app A` to confirm the margin does not depend on where in the 72 the window sits (keys differ).
Gate: full diffusion (no hole, no strong bias at the census band) at K means the distinguisher does not reach K.
The margin is 8 - K_max between reads and 72 - K_max per item.
Known-failed shape (the plant must fire): `--plant weak` builds a degenerate day by hand (MUL all 1, RC all 0,
ROT all 16). The detector must report many holes and strong bias at every K. A real day must not.
The avalanche census is a bound, not a full trail search. It does not prove the absence of a high-order
differential or a linear trail below the census band. Its reach is N states: a bias under 8/sqrt(N) is invisible.
At N = 2e6, 8 sigma is about 0.0057, so a bias below 0.57 percent is not seen. This limit is stated with the
result. A SAT or MILP trail search to tighten Q2 is scoped as owed work, not run tonight.
### Q1, the structural shortcut (harness: adv-mixer fold, new)
Three probes on the 8 keyed applications where only rk changes.
(a) The two multiply layers of adjacent applications do not merge. Test the two-application map g for GF(2)
affinity: for an affine g, `g(a) ^ g(b) ^ g(c) ^ g(a^b^c)` is constant. Count violations over N random
quadruples. Zero violations would mean g is affine and the two applications collapse to one linear map plus a
constant, a BREAK. Many violations is the bound: the diffusion between the two multiply layers is nonlinear,
so the multiplies do not fold.
(b) Word separability. Flip each input word of the full 8-application block and record which output words move.
A dead (in_word, out_word) pair over all probes is a broken dependency a shortcut could split on. Zero dead
pairs is the bound.
(c) Key-order commutation. Compare M(M(s,rk1),rk2) with M(M(s,rk2),rk1). Agreement would mean key order does not
matter and the 8 keys could be folded into fewer. Any agreement is a FINDING.
Tool: `attack-adv-mixer fold --day 20729 --trials 1000000`.
Gate: (a) at least one violation, (b) zero dead pairs, (c) zero agreements is the bound that the 8 keyed
applications cost 8x. Any breach is priced in ops per item against 9,360 and reported as a BREAK.
The algebraic view (Q1 candidate 3): the multiply layer is `x -> (x ^ c) * MUL` per word, a bijection but not
GF(2)-linear (the integer multiply carries). The diffusion layer mixes words. So the composition over 8
applications has rising algebraic degree. Probe (a) is the GF(2)-degree-1 test of the first two applications; a
pass there already rules out the cheapest fold. A full algebraic-degree or integral-distinguisher search is owed
work, scoped not run tonight.
### Q4, anything else
Two things to watch while the above runs. First, the round keys are fixed multiples of 0x9E3779B9, not drawn, so
a bad rk is the same every day: `round_key(k)` is checked in the self-test and the RC + rk = 0 class in f4 covers
the one way a fixed rk interacts with a drawn RC. Second, the item init `s[8+i] = t*MUL[i] + RC[i]` reuses MUL
and RC; a MUL[i] = 1 collapses that init word to `t + RC[i]`, which f4's mul1 class already counts. Any further
finding is added here.
## 4. Known-failed shape per method (the plant each tool must fire on)
| Method | Tool | Planted weakness | The tool must |
|---|---|---|---|
| Q3 census | attack-f4 plant alleq / mul1 / mul1all / rc0 / rcrk0 | the genesis day with one field forced weak | flag the matching class |
| Q2 diffusion | attack-adv-mixer diffusion --plant weak | MUL all 1, RC all 0, ROT all 16 | report holes and strong bias at every K |
| Q1 fold | (built in) | n/a: the probes are their own control, a real day must pass (a)-(c) | (a) violations > 0, (b) dead = 0, (c) agree = 0 |
The plant discipline follows the Mac rule: a watcher is trusted only after it fires on a known-failed case. Every
run prints its plant state and its verdict.
## 5. Box-hours per step
Build box 2, core band 64-95, nice 10, one slot at a time. Budget 8 box-hours for first results.
| Step | Command | Estimate |
|---|---|---|
| Build the two harnesses (release) | build-remote.sh --box 2 -- build --release | 0.15 box-hours |
| Q3 census 2^24 days, 32 threads | attack-f4 census --count 16777216 --threads 32 | 0.2 box-hours |
| Q3 analytic tail | attack-f4 expect --threads 32 | 0.3 box-hours |
| Q2 diffusion K = 1..12, 2e6 states each | attack-adv-mixer diffusion per K | 1.5 box-hours total |
| Q2 plant-weak firing check, K = 1..4 | attack-adv-mixer diffusion --plant weak | 0.1 box-hours |
| Q1 fold, 1e6 trials | attack-adv-mixer fold | 0.1 box-hours |
| Headroom for a wider census or a tighter K | | the rest |
Estimates are first-cut from the op counts (one application is about 130 ops; 2e6 states x 512 flips x K
applications fits a 32-core band in minutes). The report records the box-hours actually spent.
## 6. Files opened (the outsider read set)
Only these were read. Nothing else in the repository.
1. igneum-pow/src/memhard.rs (frozen, via git show at 017e7037).
2. igneum-pow/src/seed.rs (frozen).
3. igneum-pow/src/bind.rs (frozen, the day_bytes and day_index functions).
4. igneum-pow/src/generator.rs (frozen, the LoadClass, V3_CLASS, V4_CLASS, ProgramClass, generator version and
attempt-cap definitions; grepped, not read whole).
5. igneum-pow/tests/mixer.rs (frozen, the head: the test harness contract on the class v3 and v4 construction).
6. igneum-pow/Cargo.toml and Cargo.lock (dependency pin).
7. docs/spec/01-lottery-hash.md section 1.8 (frozen: 1.8.1 to 1.8.5).
8. docs/analysis/chip-model-v3.md sections 1, 2, 5, 6 (HEAD).
9. The public kit packs under proto-cuda/packs-ca3-v4 (frozen, the file listing; the eight packs named in the
brief). The kit zip sha256 is 4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154 per the brief,
to be checked when a pack is used as a vector.
10. The Devnet 3 epoch-0 pack v4-devnet3-epoch0 (public-kit class, named by a teammate lane): on build-1 at
/srv/artefacts/packs/v4-devnet3-epoch0/, zip sha256
e025750f71175ed14d6e2a24e387ebbf1979b1cd0faee9139c41a7671165b334, program id 0xfce15bf61030be57 at attempt 0,
2^24 fingerprint from base 0 e510ad92b4d24846, day bytes le64(20733). Copied read-only and the sha verified
before any use as a vector. This matches the Devnet 3 epoch-0 program id named in the brief as the check.
11. tools/attack/f4-weakday (build/attack-pass, copied read-only) and tools/attack/f8-uniform (the Mac worktree,
copied with cp -R, original untouched).
12. tools/build-remote.sh, infra/build-server/lib.sh, infra/build-server/remote-run.sh (the operating files).
13. CLAUDE.md (loaded on its own; only its operating rules are followed, not its doc references).
## 7. What is owed beyond tonight
- A SAT or MILP differential and linear trail search on M_r reduced to K applications, to tighten Q2 below the
avalanche census band.
- A rotational-XOR search on the drawn double round.
- An algebraic-degree or integral-distinguisher measurement across the 8 applications, to tighten Q1 beyond the
affinity probe.
- The census at more than 2^24 days if any class sits near the gate.
## 8. Re-scope (19:2x BST, 7 October 2026, from main)
The mixer work split into three lanes. This lane, adv-mixer, is narrowed to the algebraic structure of M_r: the
fold or commutation of the multiply layer across applications (only rk changes), the algebraic form of the 8
applications between two reads, and any composition cheaper than 8x one application, priced in ops per item
against the chip model. Sibling adv-mixer-2 owns Q3 (the day-key weakness census and the calendar). Sibling
adv-mixer-3 owns Q2 (differential, linear, rotational-XOR, SAT and MILP on reduced applications, the round
margin). The Q3 census and the Q2 diffusion sweep already run in this lane are kept and recorded as courtesy
runs, attributed to the owning lane. This lane's own deepening is the fold probe plus an algebraic-degree
(integral cube-sum) saturation test across the applications. First results by 00:00 BST tonight.

14
tools/attack/adv-mixer/Cargo.lock generated Normal file
View file

@ -0,0 +1,14 @@
# This file is automatically @generated by Cargo.
# It is not intended for manual editing.
version = 4
[[package]]
name = "attack-adv-mixer"
version = "0.1.0"
dependencies = [
"igneum-pow",
]
[[package]]
name = "igneum-pow"
version = "0.2.0"

View file

@ -0,0 +1,21 @@
[package]
name = "attack-adv-mixer"
version = "0.1.0"
edition = "2021"
description = "Adversarial cryptanalysis of the memory-hard mixer M_r (spec 01 section 1.8.4): diffusion margin across the keyed applications (Q2), the composition-fold probe (Q1), with the planted-weak-day hooks that prove the harness fires"
license = "MIT"
publish = false
[[bin]]
name = "attack-adv-mixer"
path = "src/main.rs"
[dependencies]
igneum-pow = { path = "../../../igneum-pow" }
[workspace]
[profile.release]
opt-level = 3
lto = true
codegen-units = 1

View file

@ -0,0 +1,9 @@
#!/usr/bin/env bash
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
# Internal adversarial pass, not an independent review.
set -uo pipefail
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
run fold-sweep-1024d fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44
echo "end $(date -u +%FT%TZ)"

View file

@ -0,0 +1,10 @@
#!/usr/bin/env bash
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
# Internal adversarial pass, not an independent review.
set -uo pipefail
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
run integral-a1-32d integral --day 20729 --apps 1 --dmax 16 --placements 2000 --days 32 --threads 44
run integral-a2-32d integral --day 20729 --apps 2 --dmax 16 --placements 2000 --days 32 --threads 44
echo "end $(date -u +%FT%TZ)"

View file

@ -0,0 +1,10 @@
#!/usr/bin/env bash
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
# Internal adversarial pass, not an independent review.
set -uo pipefail
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
for k in 1 2 3 4; do run lineindex-k$k lineindex --day 20729 --apps $k --states 1000000 --threads 44; done
for k in 1 2; do run linrel-addr-a$k-8d linrel --addr --day 20729 --apps $k --samples 8192 --days 8; done
echo "end $(date -u +%FT%TZ)"

View file

@ -0,0 +1,10 @@
#!/usr/bin/env bash
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
# Internal adversarial pass, not an independent review.
set -uo pipefail
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
for k in 1 2 8; do run linrel-full-a$k-16d linrel --day 20729 --apps $k --samples 8192 --days 16; done
run cnf-commute-20729 cnf --day 20729 --out /srv/builds/_adv-adv-mixer/logs/adv-mixer-commute-20729.cnf
echo "end $(date -u +%FT%TZ)"

View file

@ -0,0 +1,12 @@
#!/usr/bin/env bash
# adv-mixer queue file (owner: adv-mixer). Self-contained: binary, args, logs. nice 10, cores 8-95, pid file beside each log.
# Internal adversarial pass, not an independent review.
set -uo pipefail
X=/srv/builds/_adv-adv-mixer/bin/attack-adv-mixer; L=/srv/builds/_adv-adv-mixer/logs; mkdir -p "$L"
run() { local name=$1; shift; echo "== $name $(date -u +%FT%TZ)"; nice -n 10 taskset -c 8-95 "$X" "$@" > "$L/$name.log" 2>&1 & echo $! > "$L/$name.log.pid"; wait $!; echo "rc=$?"; grep -E "VERDICT|BOUND|FINDING|kernel_dim|written|BLOCKED" "$L/$name.log" | head -40; }
echo "start $(hostname) $(date -u +%FT%TZ) $(sha256sum $X)"
run fold-sweep-1024d fold-sweep --day 20729 --days 1024 --trials 20000 --threads 44
for k in 3 4 5 6 7; do run linrel-full-a$k-4d linrel --day 20729 --apps $k --samples 8192 --days 4; done
run integral-a8-4d integral --day 20729 --apps 8 --dmax 14 --placements 2000 --days 4 --threads 44
for k in 5 6 7 8; do run lineindex-k$k lineindex --day 20729 --apps $k --states 1000000 --threads 44; done
echo "end $(date -u +%FT%TZ)"

View file

@ -0,0 +1,52 @@
#!/usr/bin/env bash
# Run the adv-mixer sweeps on build box 2 under nice 10 on the core band 64-95, one log, a pid file beside it.
# Internal adversarial pass, not an independent review. Launched by the lane over ssh with nohup; never on the Mac.
#
# run-box.sh diffusion the Q2 diffusion margin sweep (K = 1..8), genesis day, 2,000,000 states each
# run-box.sh census the Q3 weak-day census over 2^24 days through f4-weakday
#
# Binaries (already built by build-remote.sh on this box):
# ADV = /srv/builds/igneum-wt-adv-mixer/tools/attack/adv-mixer/target/release/attack-adv-mixer
# F4 = /srv/builds/igneum-wt-adv-mixer/tools/attack/f4-weakday/target/release/attack-f4
set -euo pipefail
ROOT=/srv/builds/igneum-wt-adv-mixer
ADV="$ROOT/tools/attack/adv-mixer/target/release/attack-adv-mixer"
F4="$ROOT/tools/attack/f4-weakday/target/release/attack-f4"
OUT="/srv/builds/_adv-adv-mixer"
mkdir -p "$OUT"
BAND=8-95
STATES=${STATES:-2000000}
case "${1:-}" in
diffusion)
LOG="$OUT/diffusion-$(date -u +%Y%m%dT%H%M%SZ).log"
PID="$LOG.pid"
{
echo "adv-mixer diffusion sweep; internal adversarial pass, not an independent review"
echo "binary sha256: $(sha256sum "$ADV" | cut -c1-64)"
echo "host band taskset -c $BAND nice 10; states per K = $STATES; UTC start $(date -u +%FT%TZ)"
for K in 1 2 3 4 5 6 7 8; do
echo "===== K=$K ====="
nice -n 10 taskset -c "$BAND" "$ADV" diffusion --day 20729 --apps "$K" --states "$STATES" --threads 32
done
echo "UTC end $(date -u +%FT%TZ)"
} > "$LOG" 2>&1 &
echo $! > "$PID"
echo "diffusion running pid $(cat "$PID") log $LOG"
;;
census)
LOG="$OUT/census-$(date -u +%Y%m%dT%H%M%SZ).log"
PID="$LOG.pid"
{
echo "f4 weak-day census; internal adversarial pass, not an independent review"
echo "binary sha256: $(sha256sum "$F4" | cut -c1-64)"
echo "UTC start $(date -u +%FT%TZ)"
nice -n 10 taskset -c "$BAND" "$F4" census --from 20729 --count 16777216 --threads 32
echo "UTC end $(date -u +%FT%TZ)"
} > "$LOG" 2>&1 &
echo $! > "$PID"
echo "census running pid $(cat "$PID") log $LOG"
;;
*)
echo "usage: run-box.sh diffusion|census"; exit 2 ;;
esac

View file

@ -0,0 +1,821 @@
//! attack-adv-mixer: adversarial cryptanalysis of the memory-hard mixer `M_r` (spec 01 section 1.8.4), the
//! internal adversarial pass, not an independent review. Every number here comes from the real `igneum-pow`
//! mixer (`memhard::mixer`, `round_key_mult`, `MixParams::with_shape`); nothing is re-implemented.
//!
//! The target in the attacker's words. One application `M(s, rk)` on a 16-word state:
//! 1. prologue, per word: `s[i] = (s[i] XOR (RC[i] + rk)) * MUL[i]` (MUL odd, so each is a bijection).
//! 2. one ChaCha-shaped double round: four column quarter rounds with rotations ROT[0..3], four diagonal
//! quarter rounds with ROT[4..7].
//! Under class v4 (`mixer_mult = 8`) the derivation applies `M` eight times between each pair of the eight
//! dependent cache reads, round keys `round_key(r*8 + j)`, then eight more after the last read: 72 per item.
//! ROT, MUL, RC are drawn once per day from one SplitMix64 stream (the day key's first two words).
//!
//! The commands, each a BOUND or a BREAK with a command and a seed:
//!
//! diffusion --apps K --states N --day D [--start-app A] [--threads T] [--plant weak|none]
//! The strict-avalanche census of K consecutive keyed applications (Q2). For N random states it flips each
//! of the 512 input bits, applies K applications (keys from app A in derive order), and tallies the output
//! bit-flip probability p[in][out] over the N states. Reports, per K, the number of output bits a single
//! input bit never reaches (dependency holes), the number of (in,out) cells with |p - 0.5| above the
//! census bias band, and the worst cell. Full diffusion at K is the bound: the largest K at which a hole
//! or a strong bias survives is the distinguisher reach. The `weak` plant is a hand-built degenerate day
//! (MUL all 1, RC all 0, ROT all 16): the detector must fire on it (holes and strong bias at every K).
//!
//! fold --day D [--trials N]
//! The composition-shortcut probe (Q1). Checks three ways the 8 keyed applications might cost less than 8x:
//! (a) the two multiply layers of adjacent applications do not merge: M has a nonlinear diffusion between
//! them, shown by a GF(2) affinity test of the two-application map on N random probes (an affine map
//! satisfies f(a)+f(b)+f(c)=f(a+b+c); count violations). (b) word separability: does output word w
//! depend on every input word, tested by flipping each input word and checking each output word moves.
//! A shortcut needs a broken dependency. (c) key-only commutation: M(M(s,rk1),rk2) vs M(M(s,rk2),rk1);
//! if they agreed the key order would not matter and keys could be folded. Prints the counts; a zero
//! in (a) or a missing dependency in (b) or an agreement in (c) would be a BREAK, else the BOUND.
//!
//! The genesis test vector (day 2026-10-03) is checked at startup against the spec so the mixer wiring is the
//! library's.
use igneum_pow::generator::V4_CLASS;
use igneum_pow::memhard::{mixer, round_key_mult, MixParams, Shape, ITEM_ROUNDS};
use igneum_pow::seed::{day_key, seed_words_from_bytes, SplitMix64};
use igneum_pow::bind::day_bytes;
use std::sync::atomic::{AtomicU64, Ordering};
use std::sync::Arc;
use std::thread;
/// The chain genesis day index (`bind.rs`: day_index(0x1a0ff0f7c00) = 20,729, 3 October 2026).
const GENESIS_DAY: u64 = 20_729;
fn v4_shape() -> Shape {
let s = Shape::for_class(&V4_CLASS);
assert_eq!(s.mixer_mult, 8, "class v4 is the x8 mixer");
assert_eq!(s.derive_len, 0, "class v4 has no derivation program");
s
}
/// Params for a chain day index (the interim day rule, `bind::day_bytes`).
fn params_of_day(d: u64) -> MixParams {
MixParams::with_shape(seed_words_from_bytes(&day_bytes(d)), v4_shape())
}
/// A hand-built degenerate day: identity multiply, zero round constants, one rotation amount everywhere. Not a
/// drawable day (it is the plant); every field is in range (MUL odd, ROT in 1..31).
fn planted_weak(d: u64) -> MixParams {
let mut mp = params_of_day(d);
mp.mul = [1u32; 16];
mp.rc = [0u32; 16];
mp.rot = [16u32; 8];
mp
}
/// The 72 application round keys of an item under m = 8, in derive order.
fn app_keys() -> [u32; 72] {
let mut k = [0u32; 72];
for r in 0..=ITEM_ROUNDS {
for j in 0..8 {
k[r * 8 + j] = round_key_mult(r, j, 8);
}
}
k
}
/// Apply `apps` keyed applications starting at application index `start` (derive order).
#[inline]
fn apply_n(mut s: [u32; 16], mp: &MixParams, keys: &[u32; 72], start: usize, apps: usize) -> [u32; 16] {
for a in 0..apps {
mixer(&mut s, keys[(start + a) % 72], mp);
}
s
}
/// A per-thread SplitMix64 PRNG for random probe states (the attacker's own randomness, not the mixer's).
struct Rng(SplitMix64);
impl Rng {
fn new(seed: u64) -> Self {
Rng(SplitMix64::new(seed))
}
fn state(&mut self) -> [u32; 16] {
let mut s = [0u32; 16];
for w in s.iter_mut() {
*w = self.0.next() as u32;
}
s
}
}
// --------------------------------------------------------------------------------------------------------------
// diffusion (Q2): the strict-avalanche census over K keyed applications
// --------------------------------------------------------------------------------------------------------------
/// 512 x 512 counters (input bit -> output bit flip count), summed as u64. Flat for cache behaviour.
struct Aval {
n: u64,
counts: Vec<u64>, // 512*512
}
impl Aval {
fn new() -> Self {
Aval { n: 0, counts: vec![0u64; 512 * 512] }
}
fn merge(&mut self, o: &Aval) {
self.n += o.n;
for (a, b) in self.counts.iter_mut().zip(o.counts.iter()) {
*a += b;
}
}
}
#[inline]
fn bit_of(s: &[u32; 16], b: usize) -> u32 {
(s[b >> 5] >> (b & 31)) & 1
}
#[inline]
fn flip_bit(s: &mut [u32; 16], b: usize) {
s[b >> 5] ^= 1u32 << (b & 31);
}
fn diffusion(day: u64, plant_weak: bool, apps: usize, states: u64, start: usize, threads: usize) {
let mp = if plant_weak { planted_weak(day) } else { params_of_day(day) };
let keys = app_keys();
let per = states / threads as u64;
let mp = Arc::new(mp);
let keys = Arc::new(keys);
let mut handles = Vec::new();
for t in 0..threads {
let mp = Arc::clone(&mp);
let keys = Arc::clone(&keys);
let count = if t as u64 == threads as u64 - 1 { states - per * (threads as u64 - 1) } else { per };
let seed = 0x1234_5678_9abc_def0 ^ ((day as u64).wrapping_mul(0x9E3779B97F4A7C15)) ^ (t as u64 + 1);
handles.push(thread::spawn(move || {
let mut rng = Rng::new(seed);
let mut acc = Aval::new();
for _ in 0..count {
let base = rng.state();
let out0 = apply_n(base, &mp, &keys, start, apps);
for ib in 0..512 {
let mut s = base;
flip_bit(&mut s, ib);
let out1 = apply_n(s, &mp, &keys, start, apps);
let row = ib * 512;
for ob in 0..512 {
if bit_of(&out0, ob) != bit_of(&out1, ob) {
acc.counts[row + ob] += 1;
}
}
}
acc.n += 1;
}
acc
}));
}
let mut total = Aval::new();
for h in handles {
total.merge(&h.join().unwrap());
}
// census band: a cell at the ideal 0.5 over N states has stddev 0.5/sqrt(N); call a bias "strong" at 8 sigma.
let n = total.n as f64;
let sigma = 0.5 / n.sqrt();
let band = 8.0 * sigma;
let mut holes = 0u64; // cells with p == 0 or p == 1 exactly (a dependency hole or a perfect relation)
let mut strong = 0u64; // |p-0.5| > band and not a hole
let mut worst_dev = 0.0f64;
let mut worst = (0usize, 0usize, 0.0f64);
let mut global_flips = 0u64;
for ib in 0..512 {
for ob in 0..512 {
let c = total.counts[ib * 512 + ob];
global_flips += c;
let p = c as f64 / n;
if c == 0 || c == total.n {
holes += 1;
} else {
let dev = (p - 0.5).abs();
if dev > band {
strong += 1;
}
if dev > worst_dev {
worst_dev = dev;
worst = (ib, ob, p);
}
}
}
}
let mean_p = global_flips as f64 / (n * 512.0 * 512.0);
println!(
"diffusion day={} plant={} apps={} start={} states={} threads={}",
day,
if plant_weak { "weak" } else { "none" },
apps,
start,
total.n,
threads
);
println!(" mean output-flip probability over all 262144 cells: {:.6} (ideal 0.5)", mean_p);
println!(" census band: 8 sigma = {:.6} ({} states)", band, total.n);
println!(" dependency holes (p == 0 or p == 1 exactly): {} of 262144", holes);
println!(" strong-bias cells (|p-0.5| > band, not a hole): {} of 262144", strong);
println!(
" worst cell: in_bit {} -> out_bit {} p = {:.6} dev = {:.6} ({:.1} sigma)",
worst.0,
worst.1,
worst.2,
worst_dev,
worst_dev / sigma
);
let verdict = if holes > 0 || strong > 0 { "FINDING (holes or strong bias at this K)" } else { "no distinguisher at this K" };
println!(" VERDICT: {}", verdict);
}
// --------------------------------------------------------------------------------------------------------------
// fold (Q1): the composition-shortcut probe
// --------------------------------------------------------------------------------------------------------------
#[inline]
fn xor16(a: &[u32; 16], b: &[u32; 16]) -> [u32; 16] {
let mut o = [0u32; 16];
for i in 0..16 {
o[i] = a[i] ^ b[i];
}
o
}
/// Probe (a) affinity and (c) key-order commutation on the adjacent application pair (i, i+1).
fn fold_pair(mp: &MixParams, keys: &[u32; 72], i: usize, trials: u64, rng: &mut Rng) -> (u64, u64) {
let (rk1, rk2) = (keys[i], keys[i + 1]);
let g = |s: [u32; 16]| -> [u32; 16] { let mut t = s; mixer(&mut t, rk1, mp); mixer(&mut t, rk2, mp); t };
let g0 = g([0u32; 16]);
let mut violations = 0u64;
let mut agree = 0u64;
for _ in 0..trials {
let a = rng.state(); let b = rng.state(); let c = rng.state();
let abc = xor16(&xor16(&a, &b), &c);
let lhs = xor16(&xor16(&g(a), &g(b)), &xor16(&g(c), &g(abc)));
if lhs != g0 { violations += 1; }
let s = rng.state();
let mut s1 = s; mixer(&mut s1, rk2, mp); mixer(&mut s1, rk1, mp);
if g(s) == s1 { agree += 1; }
}
(violations, agree)
}
/// Probe (b) word separability over the full 8-application block of round 0.
fn fold_block(mp: &MixParams, keys: &[u32; 72], trials: u64, rng: &mut Rng) -> u64 {
let full = |s: [u32; 16]| apply_n(s, mp, keys, 0, 8);
let mut dep = [[false; 16]; 16];
for _ in 0..trials {
let base = rng.state();
let o0 = full(base);
for iw in 0..16 {
let mut s = base; s[iw] ^= 0xffff_ffff;
let o1 = full(s);
for ow in 0..16 { if o0[ow] != o1[ow] { dep[iw][ow] = true; } }
}
}
let mut dead = 0u64;
for iw in 0..16 { for ow in 0..16 { if !dep[iw][ow] { dead += 1; } } }
dead
}
fn fold(day: u64, trials: u64) {
let mp = params_of_day(day);
let keys = app_keys();
let mut rng = Rng::new(0xfeed_face_cafe_babe ^ day.wrapping_mul(0x9E3779B97F4A7C15));
let (affine_violations, commute_agree) = fold_pair(&mp, &keys, 0, trials, &mut rng);
let dead_pairs = fold_block(&mp, &keys, trials, &mut rng);
println!("fold day={} trials={}", day, trials);
println!(" (a) GF(2) affinity violations of the 2-application map: {} of {} (0 would be a BREAK: the map is affine)", affine_violations, trials);
println!(" (b) dead (in_word -> out_word) pairs over the full 8-application block: {} of 256 (any would be a broken dependency)", dead_pairs);
println!(" (c) key-order agreements M(M(.,rk1),rk2) == M(M(.,rk2),rk1): {} of {} (any would let keys fold)", commute_agree, trials);
let verdict = if affine_violations == 0 || dead_pairs > 0 || commute_agree > 0 { "FINDING" } else { "BOUND: no fold on these probes" };
println!(" VERDICT: {}", verdict);
}
/// The fold probes over `days` consecutive chain days and all 71 adjacent application-key pairs per day.
fn fold_sweep(day0: u64, days: u64, trials: u64, threads: usize) {
let keys = Arc::new(app_keys());
let per = (days + threads as u64 - 1) / threads as u64;
let mut handles = Vec::new();
for t in 0..threads {
let keys = Arc::clone(&keys);
let lo = day0 + t as u64 * per;
let hi = (lo + per).min(day0 + days);
handles.push(thread::spawn(move || {
let (mut viol, mut tot, mut agree, mut dead, mut n_days) = (0u64, 0u64, 0u64, 0u64, 0u64);
let mut worst_viol_frac = 1.0f64;
for d in lo..hi {
let mp = params_of_day(d);
let mut rng = Rng::new(0xfeed_face_cafe_babe ^ d.wrapping_mul(0x9E3779B97F4A7C15));
for i in 0..71 {
let (v, a) = fold_pair(&mp, &keys, i, trials, &mut rng);
viol += v; tot += trials; agree += a;
let f = v as f64 / trials as f64;
if f < worst_viol_frac { worst_viol_frac = f; }
}
dead += fold_block(&mp, &keys, trials, &mut rng);
n_days += 1;
}
(viol, tot, agree, dead, n_days, worst_viol_frac)
}));
}
let (mut viol, mut tot, mut agree, mut dead, mut n_days) = (0u64, 0u64, 0u64, 0u64, 0u64);
let mut worst = 1.0f64;
for h in handles {
let (v, t, a, dd, nd, w) = h.join().unwrap();
viol += v; tot += t; agree += a; dead += dd; n_days += nd; if w < worst { worst = w; }
}
println!("fold-sweep from_day={} days={} pairs_per_day=71 trials_per_pair={}", day0, n_days, trials);
println!(" (a) affinity violations: {} of {} pair-trials; lowest per-pair violation fraction {:.6} (1.0 = never affine)", viol, tot, worst);
println!(" (b) dead word pairs summed over {} days: {} (0 = complete dependency every day)", n_days, dead);
println!(" (c) key-order agreements: {} of {} pair-trials", agree, tot);
println!(" VERDICT: {}", if viol < tot || dead > 0 || agree > 0 { "FINDING" } else { "BOUND: no fold on any day or pair probed" });
}
// --------------------------------------------------------------------------------------------------------------
// integral (Q1): algebraic-degree saturation across K keyed applications
// --------------------------------------------------------------------------------------------------------------
//
// The cube-sum (higher-order differential) test. Pick d input-bit positions. Over a fixed random base state, XOR
// every one of the 2^d subsets of those positions into the base, apply K applications, and XOR-accumulate the 16
// output words. For an output bit that is a GF(2) polynomial of the input of degree < d, the sum over the full
// d-cube is 0 (the d-th derivative of a degree < d polynomial is 0). A nonzero sum proves the output bit has
// algebraic degree >= d in those d variables. We report, per d, the fraction of (base, cube) placements whose
// accumulated 512-bit sum is nonzero on at least one output bit, and the mean number of output bits set. When
// nonzero sums appear at small d the algebraic degree is already high, so no low-degree algebraic batching of the
// applications exists: an attacker cannot evaluate the 8 applications through a cheap polynomial. A composition
// cheaper than 8x would need a low-degree form; its absence is the bound, priced against 9,360 ops per item.
fn integral(day: u64, apps: usize, dmax: usize, placements: u64, threads: usize) {
let mp = Arc::new(params_of_day(day));
let keys = Arc::new(app_keys());
println!("integral day={} apps={} placements_per_d={} threads={}", day, apps, placements, threads);
println!(" d = cube dimension; 'nonzero' = placements whose cube-sum is nonzero on >=1 output bit (degree >= d reached)");
for d in 1..=dmax {
let per = placements / threads as u64;
let mut handles = Vec::new();
for t in 0..threads {
let mp = Arc::clone(&mp);
let keys = Arc::clone(&keys);
let count = if t as u64 == threads as u64 - 1 { placements - per * (threads as u64 - 1) } else { per };
let seed = 0xa1b2_c3d4_e5f6_0718 ^ day.wrapping_mul(0x9E3779B97F4A7C15) ^ ((d as u64) << 40) ^ (t as u64 + 1);
handles.push(thread::spawn(move || {
let mut rng = Rng::new(seed);
let mut nonzero = 0u64;
let mut bits_set_total = 0u64;
for _ in 0..count {
let base = rng.state();
// choose d distinct input bit positions in 0..512
let mut pos = [0usize; 32];
let mut chosen = 0usize;
while chosen < d {
let b = (rng.0.next() % 512) as usize;
if !pos[..chosen].contains(&b) {
pos[chosen] = b;
chosen += 1;
}
}
let mut acc = [0u32; 16];
for mask in 0u32..(1u32 << d) {
let mut s = base;
for (bit, &p) in pos[..d].iter().enumerate() {
if (mask >> bit) & 1 == 1 {
flip_bit(&mut s, p);
}
}
let o = apply_n(s, &mp, &keys, 0, apps);
for i in 0..16 {
acc[i] ^= o[i];
}
}
let set: u32 = acc.iter().map(|w| w.count_ones()).sum();
bits_set_total += set as u64;
if set > 0 {
nonzero += 1;
}
}
(nonzero, bits_set_total, count)
}));
}
let (mut nonzero, mut bits, mut n) = (0u64, 0u64, 0u64);
for h in handles {
let (a, b, c) = h.join().unwrap();
nonzero += a;
bits += b;
n += c;
}
let frac = nonzero as f64 / n as f64;
let mean_bits = bits as f64 / n as f64;
let note = if nonzero == 0 { "sum always 0: degree < d on every output bit (a low-degree relation)" } else { "degree >= d reached" };
println!(
" d={:2} nonzero {}/{} = {:.4} mean out-bits set {:.1}/512 [{}]",
d, nonzero, n, frac, mean_bits, note
);
}
println!(" READING: the smallest d at which nonzero is ~1.0 is the degree floor; high degree at small d means no low-degree algebraic shortcut across the applications");
}
// --------------------------------------------------------------------------------------------------------------
// linrel (Q1): exact affine-relation search over the full 32-bit map by GF(2) elimination
// --------------------------------------------------------------------------------------------------------------
//
// Collect N random (x, y = K applications of x) pairs. Each pair is a GF(2) row over the 1025 columns
// [512 input bits | 512 output bits | 1]. Any nonzero v with A v = 0 is an exact affine relation
// a.x XOR b.y = c that holds on every sample; with N far above 1025 a surviving relation is genuine (a chance
// survivor has probability 2^-(N - 1025)). Kernel dimension 1025 - rank(A). Rank 1025 means NO affine relation
// exists between the input bits and the output bits of the composed applications, at full width with the real
// day constants. This is the decidable algebraic probe in place of a SAT solve (no solver reaches the box).
// `--addr` restricts the output columns to the 22 line-index bits of s[0] (the bits a chip prefetches on).
const LR_IN: usize = 512;
fn gf2_rank(rows: &mut Vec<Vec<u64>>, ncols: usize) -> usize {
let words = (ncols + 63) / 64;
let mut rank = 0usize;
let mut r = 0usize;
for col in 0..ncols {
let (w, b) = (col / 64, col % 64);
let mut piv = None;
for i in r..rows.len() {
if (rows[i][w] >> b) & 1 == 1 {
piv = Some(i);
break;
}
}
let Some(p) = piv else { continue };
rows.swap(r, p);
let pr = rows[r].clone();
for i in 0..rows.len() {
if i != r && (rows[i][w] >> b) & 1 == 1 {
for k in 0..words {
rows[i][k] ^= pr[k];
}
}
}
rank += 1;
r += 1;
if r == rows.len() {
break;
}
}
rank
}
fn linrel(day: u64, apps: usize, samples: usize, addr_only: bool) {
let mp = params_of_day(day);
let keys = app_keys();
let mut rng = Rng::new(0x5a5a_1234_9e37_79b9 ^ day.wrapping_mul(0x9E3779B97F4A7C15) ^ ((apps as u64) << 48));
let nout = if addr_only { 22 } else { 512 };
let ncols = LR_IN + nout + 1;
let words = (ncols + 63) / 64;
let mut rows: Vec<Vec<u64>> = Vec::with_capacity(samples);
for _ in 0..samples {
let x = rng.state();
let y = apply_n(x, &mp, &keys, 0, apps);
let mut row = vec![0u64; words];
for b in 0..LR_IN {
if bit_of(&x, b) == 1 {
row[b / 64] |= 1u64 << (b % 64);
}
}
for b in 0..nout {
if bit_of(&y, b) == 1 {
let c = LR_IN + b;
row[c / 64] |= 1u64 << (c % 64);
}
}
let c = LR_IN + nout;
row[c / 64] |= 1u64 << (c % 64);
rows.push(row);
}
let rank = gf2_rank(&mut rows, ncols);
let kernel = ncols - rank;
println!(
"linrel day={} apps={} samples={} columns={} ({} in + {} out + 1) rank={} kernel_dim={}",
day, apps, samples, ncols, LR_IN, nout, rank, kernel
);
let margin = samples as i64 - ncols as i64;
if kernel == 0 {
println!(" BOUND: no exact affine relation a.x XOR b.y = c over the {} samples (false-survivor odds 2^-{})", samples, margin);
} else {
println!(" FINDING: {} independent affine relations survive all {} samples (chance survivor odds 2^-{} each)", kernel, samples, margin);
}
}
// --------------------------------------------------------------------------------------------------------------
// lineindex (Q1): the 22 line-index bits of s[0] across applications, avalanche with a tight band
// --------------------------------------------------------------------------------------------------------------
//
// The cache read uses s[0] AND (2^22 - 1). A chip that could predict those 22 bits from fewer than K
// applications could issue the read early and hide the mixer behind the memory latency. We tally the flip
// probability of each of the 22 address bits for each of the 512 input bits over N states after K applications,
// report holes and cells beyond 8 sigma, and the worst cell.
fn lineindex(day: u64, apps: usize, states: u64, threads: usize) {
let mp = Arc::new(params_of_day(day));
let keys = Arc::new(app_keys());
let per = states / threads as u64;
let mut handles = Vec::new();
for t in 0..threads {
let mp = Arc::clone(&mp);
let keys = Arc::clone(&keys);
let count = if t as u64 == threads as u64 - 1 { states - per * (threads as u64 - 1) } else { per };
let seed = 0x7777_0000_abcd_ef01 ^ day.wrapping_mul(0x9E3779B97F4A7C15) ^ ((apps as u64) << 40) ^ (t as u64 + 1);
handles.push(thread::spawn(move || {
let mut rng = Rng::new(seed);
let mut counts = vec![0u64; 512 * 22];
for _ in 0..count {
let base = rng.state();
let o0 = apply_n(base, &mp, &keys, 0, apps)[0] & 0x003f_ffff;
for ib in 0..512 {
let mut s = base;
flip_bit(&mut s, ib);
let o1 = apply_n(s, &mp, &keys, 0, apps)[0] & 0x003f_ffff;
let d = o0 ^ o1;
for ab in 0..22 {
if (d >> ab) & 1 == 1 {
counts[ib * 22 + ab] += 1;
}
}
}
}
(counts, count)
}));
}
let mut counts = vec![0u64; 512 * 22];
let mut n = 0u64;
for h in handles {
let (c, k) = h.join().unwrap();
for (a, b) in counts.iter_mut().zip(c.iter()) {
*a += b;
}
n += k;
}
let nf = n as f64;
let sigma = 0.5 / nf.sqrt();
let band = 8.0 * sigma;
let (mut holes, mut strong, mut worst_dev, mut worst) = (0u64, 0u64, 0.0f64, (0usize, 0usize, 0.0f64));
let mut total = 0u64;
for ib in 0..512 {
for ab in 0..22 {
let c = counts[ib * 22 + ab];
total += c;
let p = c as f64 / nf;
if c == 0 || c == n {
holes += 1;
} else {
let dev = (p - 0.5).abs();
if dev > band {
strong += 1;
}
if dev > worst_dev {
worst_dev = dev;
worst = (ib, ab, p);
}
}
}
}
println!("lineindex day={} apps={} states={} threads={} (22 address bits x 512 input bits = 11264 cells)", day, apps, n, threads);
println!(" mean address-bit flip probability: {:.6} (ideal 0.5); band 8 sigma = {:.6}", total as f64 / (nf * 11264.0), band);
println!(" holes: {} of 11264; strong-bias cells: {} of 11264", holes, strong);
println!(" worst cell: in_bit {} -> addr_bit {} p = {:.6} ({:.1} sigma)", worst.0, worst.1, worst.2, worst_dev / sigma);
println!(" VERDICT: {}", if holes > 0 || strong > 0 { "FINDING (address bits predictable at this K)" } else { "no address-bit distinguisher at this K" });
}
// --------------------------------------------------------------------------------------------------------------
// cnf (Q1): DIMACS export of two keyed applications with the real day constants, the commutation instance
// --------------------------------------------------------------------------------------------------------------
//
// Bit-exact Tseitin encoding of M(M(x, rk1), rk2) and M(M(x, rk2), rk1) on a shared 512-variable input, with the
// constraint that the two outputs are equal. SAT = a state on which the two key orders commute; UNSAT = none
// exists (a proof of fold probe (c) over all 2^512 states). Adds are ripple-carry full adders, a constant
// multiply is the shift-add chain over the set bits of MUL, a constant XOR is a literal flip, a rotation is
// wiring. No solver reaches the box (crates.io is refused and none is installed), so this writes the model for a
// solver elsewhere and the row stays BLOCKED on the solve.
struct Cnf {
nvars: i32,
clauses: Vec<Vec<i32>>,
}
const LTRUE: i32 = i32::MAX;
const LFALSE: i32 = i32::MIN + 1;
impl Cnf {
fn new() -> Self {
Cnf { nvars: 0, clauses: Vec::new() }
}
fn var(&mut self) -> i32 {
self.nvars += 1;
self.nvars
}
fn neg(l: i32) -> i32 {
if l == LTRUE { LFALSE } else if l == LFALSE { LTRUE } else { -l }
}
fn xor(&mut self, a: i32, b: i32) -> i32 {
if a == LFALSE { return b; }
if b == LFALSE { return a; }
if a == LTRUE { return Self::neg(b); }
if b == LTRUE { return Self::neg(a); }
let o = self.var();
self.clauses.push(vec![-a, -b, -o]);
self.clauses.push(vec![a, b, -o]);
self.clauses.push(vec![a, -b, o]);
self.clauses.push(vec![-a, b, o]);
o
}
fn and(&mut self, a: i32, b: i32) -> i32 {
if a == LFALSE || b == LFALSE { return LFALSE; }
if a == LTRUE { return b; }
if b == LTRUE { return a; }
let o = self.var();
self.clauses.push(vec![-o, a]);
self.clauses.push(vec![-o, b]);
self.clauses.push(vec![o, -a, -b]);
o
}
fn or(&mut self, a: i32, b: i32) -> i32 {
if a == LTRUE || b == LTRUE { return LTRUE; }
if a == LFALSE { return b; }
if b == LFALSE { return a; }
let o = self.var();
self.clauses.push(vec![o, -a]);
self.clauses.push(vec![o, -b]);
self.clauses.push(vec![-o, a, b]);
o
}
/// 32-bit ripple-carry add of two literal words.
fn add32(&mut self, a: &[i32; 32], b: &[i32; 32]) -> [i32; 32] {
let mut out = [LFALSE; 32];
let mut carry = LFALSE;
for i in 0..32 {
let t = self.xor(a[i], b[i]);
out[i] = self.xor(t, carry);
let c1 = self.and(a[i], b[i]);
let c2 = self.and(t, carry);
carry = self.or(c1, c2);
}
out
}
fn xor32(&mut self, a: &[i32; 32], b: &[i32; 32]) -> [i32; 32] {
let mut o = [LFALSE; 32];
for i in 0..32 { o[i] = self.xor(a[i], b[i]); }
o
}
fn const32(v: u32) -> [i32; 32] {
let mut o = [LFALSE; 32];
for i in 0..32 { o[i] = if (v >> i) & 1 == 1 { LTRUE } else { LFALSE }; }
o
}
fn rotl32(a: &[i32; 32], n: u32) -> [i32; 32] {
let mut o = [LFALSE; 32];
for i in 0..32 { o[((i as u32 + n) % 32) as usize] = a[i]; }
o
}
fn shl32(a: &[i32; 32], n: u32) -> [i32; 32] {
let mut o = [LFALSE; 32];
for i in 0..32 { if i as u32 + n < 32 { o[(i as u32 + n) as usize] = a[i]; } }
o
}
/// Multiply by a constant: shift-add over the set bits of `c`.
fn mulc32(&mut self, a: &[i32; 32], c: u32) -> [i32; 32] {
let mut acc: Option<[i32; 32]> = None;
for j in 0..32 {
if (c >> j) & 1 == 1 {
let sh = Self::shl32(a, j);
acc = Some(match acc { None => sh, Some(p) => self.add32(&p, &sh) });
}
}
acc.unwrap_or(Self::const32(0))
}
fn qr(&mut self, s: &mut [[i32; 32]; 16], a: usize, b: usize, c: usize, d: usize, r: [u32; 4]) {
s[a] = self.add32(&s[a], &s[b]); s[d] = self.xor32(&s[d], &s[a]); s[d] = Self::rotl32(&s[d], r[0]);
s[c] = self.add32(&s[c], &s[d]); s[b] = self.xor32(&s[b], &s[c]); s[b] = Self::rotl32(&s[b], r[1]);
s[a] = self.add32(&s[a], &s[b]); s[d] = self.xor32(&s[d], &s[a]); s[d] = Self::rotl32(&s[d], r[2]);
s[c] = self.add32(&s[c], &s[d]); s[b] = self.xor32(&s[b], &s[c]); s[b] = Self::rotl32(&s[b], r[3]);
}
/// One mixer application, symbolic, the same wiring as memhard::mixer.
fn mixer(&mut self, s: &mut [[i32; 32]; 16], rk: u32, mp: &MixParams) {
for i in 0..16 {
let k = Self::const32(mp.rc[i].wrapping_add(rk));
let x = self.xor32(&s[i], &k);
s[i] = self.mulc32(&x, mp.mul[i]);
}
let r = &mp.rot;
let col = [r[0], r[1], r[2], r[3]];
let dia = [r[4], r[5], r[6], r[7]];
self.qr(s, 0, 4, 8, 12, col); self.qr(s, 1, 5, 9, 13, col); self.qr(s, 2, 6, 10, 14, col); self.qr(s, 3, 7, 11, 15, col);
self.qr(s, 0, 5, 10, 15, dia); self.qr(s, 1, 6, 11, 12, dia); self.qr(s, 2, 7, 8, 13, dia); self.qr(s, 3, 4, 9, 14, dia);
}
fn assert_eq_lit(&mut self, a: i32, b: i32) {
let is_const = |l: i32| l == LTRUE || l == LFALSE;
match (a, b) {
(LTRUE, LTRUE) | (LFALSE, LFALSE) => {}
(x, y) if is_const(x) && is_const(y) => self.clauses.push(vec![]), // constant mismatch: UNSAT
(LTRUE, x) | (x, LTRUE) => self.clauses.push(vec![x]),
(LFALSE, x) | (x, LFALSE) => self.clauses.push(vec![-x]),
_ => { self.clauses.push(vec![-a, b]); self.clauses.push(vec![a, -b]); }
}
}
}
fn cnf_export(day: u64, path: &str) {
let mp = params_of_day(day);
let keys = app_keys();
let (rk1, rk2) = (keys[0], keys[1]);
let mut c = Cnf::new();
let mut x = [[LFALSE; 32]; 16];
for w in 0..16 { for b in 0..32 { x[w][b] = c.var(); } }
let mut s1 = x; c.mixer(&mut s1, rk1, &mp); c.mixer(&mut s1, rk2, &mp);
let mut s2 = x; c.mixer(&mut s2, rk2, &mp); c.mixer(&mut s2, rk1, &mp);
for w in 0..16 { for b in 0..32 { c.assert_eq_lit(s1[w][b], s2[w][b]); } }
let mut out = String::new();
let _ = writeln!(out, "c adv-mixer commutation instance: exists x with M(M(x,rk1),rk2) == M(M(x,rk2),rk1), day {} rk1 {:#010x} rk2 {:#010x}", day, rk1, rk2);
let _ = writeln!(out, "c internal adversarial pass, not an independent review; frozen mixer 017e7037; input vars 1..512 = s[w] bit b at 1 + 32 w + b");
let _ = writeln!(out, "p cnf {} {}", c.nvars, c.clauses.len());
for cl in &c.clauses {
for &l in cl { let _ = write!(out, "{} ", l); }
let _ = writeln!(out, "0");
}
std::fs::write(path, out).expect("write cnf");
println!("cnf day={} vars={} clauses={} written {}", day, c.nvars, c.clauses.len(), path);
println!(" BLOCKED on the solve: no SAT solver reaches the box (crates.io refused, none installed); the model is the artefact");
}
use std::fmt::Write as _;
// --------------------------------------------------------------------------------------------------------------
// startup self-check: the genesis test vector of the spec
// --------------------------------------------------------------------------------------------------------------
fn self_check() {
let mp = MixParams::for_day("2026-10-03");
assert_eq!(mp.rot, [20, 20, 19, 4, 26, 3, 3, 27], "spec 1.8.4 ROT vector");
assert_eq!(mp.mul[0], 0x42146205, "spec 1.8.4 MUL[0]");
assert_eq!(mp.mul[15], 0x99cfb423, "spec 1.8.4 MUL[15]");
assert_eq!(mp.rc[0], 0xbab68293, "spec 1.8.4 RC[0]");
assert_eq!(mp.rc[15], 0x31b49ee2, "spec 1.8.4 RC[15]");
let k = day_key("2026-10-03");
assert_eq!(k[0], 0x3067619f, "spec 1.8.1 day key K[0]");
// the 72 application keys are distinct multiples of 0x9E3779B9
let keys = app_keys();
for (i, &v) in keys.iter().enumerate() {
assert_eq!(v, ((i as u32) + 1).wrapping_mul(0x9E3779B9), "application key {i}");
}
eprintln!("self-check: spec 1.8.1 and 1.8.4 genesis vectors OK; 72 application keys are 1..72 times 0x9E3779B9");
}
fn arg_u64(args: &[String], flag: &str, default: u64) -> u64 {
args.iter().position(|a| a == flag).and_then(|i| args.get(i + 1)).and_then(|s| s.parse().ok()).unwrap_or(default)
}
fn arg_str<'a>(args: &'a [String], flag: &str, default: &'a str) -> &'a str {
args.iter().position(|a| a == flag).and_then(|i| args.get(i + 1)).map(|s| s.as_str()).unwrap_or(default)
}
fn main() {
self_check();
let args: Vec<String> = std::env::args().collect();
let cmd = args.get(1).map(|s| s.as_str()).unwrap_or("help");
let day = arg_u64(&args, "--day", GENESIS_DAY);
let threads = arg_u64(&args, "--threads", 16).max(1) as usize;
match cmd {
"diffusion" => {
let apps = arg_u64(&args, "--apps", 8) as usize;
let states = arg_u64(&args, "--states", 100_000);
let start = arg_u64(&args, "--start-app", 0) as usize;
let plant = arg_str(&args, "--plant", "none") == "weak";
diffusion(day, plant, apps, states, start, threads);
}
"fold" => {
let trials = arg_u64(&args, "--trials", 100_000);
fold(day, trials);
}
"integral" => {
let apps = arg_u64(&args, "--apps", 2) as usize;
let dmax = arg_u64(&args, "--dmax", 14) as usize;
let placements = arg_u64(&args, "--placements", 20000);
let days = arg_u64(&args, "--days", 1);
for d in day..day + days { integral(d, apps, dmax, placements, threads); }
}
"fold-sweep" => {
let trials = arg_u64(&args, "--trials", 20_000);
let days = arg_u64(&args, "--days", 64);
fold_sweep(day, days, trials, threads);
}
"linrel" => {
let apps = arg_u64(&args, "--apps", 2) as usize;
let samples = arg_u64(&args, "--samples", 8192) as usize;
let addr = args.iter().any(|a| a == "--addr");
let days = arg_u64(&args, "--days", 1);
for d in day..day + days { linrel(d, apps, samples, addr); }
}
"lineindex" => {
let apps = arg_u64(&args, "--apps", 2) as usize;
let states = arg_u64(&args, "--states", 500_000);
lineindex(day, apps, states, threads);
}
"cnf" => {
let path = arg_str(&args, "--out", "adv-mixer-commute.cnf").to_string();
cnf_export(day, &path);
}
_ => {
eprintln!("usage: attack-adv-mixer diffusion|fold|fold-sweep|integral|linrel|lineindex|cnf [--day D] [--apps K] [--states N] [--start-app A] [--plant weak|none] [--trials N] [--dmax D] [--placements N] [--threads T]");
}
}
let _ = AtomicU64::new(0).fetch_add(0, Ordering::Relaxed);
}

14
tools/attack/f4-weakday/Cargo.lock generated Normal file
View file

@ -0,0 +1,14 @@
# This file is automatically @generated by Cargo.
# It is not intended for manual editing.
version = 4
[[package]]
name = "attack-f4-weakday"
version = "0.1.0"
dependencies = [
"igneum-pow",
]
[[package]]
name = "igneum-pow"
version = "0.2.0"

View file

@ -0,0 +1,21 @@
[package]
name = "attack-f4-weakday"
version = "0.1.0"
edition = "2021"
description = "Attack pass F4: the weak-day census over 2^24 day keys through MixParams::with_shape (docs/plans/cryptanalysis.md 4.2)"
license = "MIT"
publish = false
[[bin]]
name = "attack-f4"
path = "src/main.rs"
[dependencies]
igneum-pow = { path = "../../../igneum-pow" }
[workspace]
[profile.release]
opt-level = 3
lto = true
codegen-units = 1

View file

@ -0,0 +1,990 @@
//! Attack pass F4: the weak-day census (`docs/plans/cryptanalysis.md` section 4.2 row F4, `funding.md` B2 rank 3 and
//! B5 rank 3). Every chain day `d` has the key `seed_words_from_bytes("igneum-day/" || d_le64)` (`bind::day_bytes`,
//! the interim day rule) and its mixer constants come from `MixParams::with_shape`, a SplitMix64 stream seeded from
//! `key[0] | key[1] << 32`: `ROT[0..7]` in 1..31, `MUL[0..15]` odd, `RC[0..15]`. This harness walks consecutive chain
//! days through the real draw code (the `igneum-pow` path dependency, nothing re-implemented) and classifies each
//! day's draw.
//!
//! The gain metrics, all exact and structural (what a datapath built for the day pays, in adder-equivalents per
//! mixer application; the verifier and every GPU pay the same ops on every day, so wall time cannot move):
//!
//! * M1, the per-day LUT datapath (an FPGA bitstream synthesised for the day, the only per-day attacker that
//! exists: a constant XOR is absorbed into the next LUT, a rotation by a constant is routing, a 32-bit add or
//! XOR is one 32-bit adder-equivalent, a multiply by a constant is `NAF(MUL) - 1` adders in canonical signed-digit
//! shift-add form): `cost = 32 adds + 32 xors + sum_i (naf(MUL_i) - 1)`. Gain of a day = the census median cost
//! over the day's cost. This is the generous bound: optimal single-constant multiplication is cheaper than NAF for
//! every constant, and a DSP-block multiply does not depend on the value at all.
//! * M2, the DSP-bound datapath (the multiplies in DSP blocks, value-independent): a word whose constant has NAF
//! weight at most 3 (two adders) moves to LUTs and frees its DSP, so gain = 16 / (16 - k) for k such words.
//! * ROT and RC classes: a constant rotation is wiring and a constant XOR is inverters on a per-day datapath, so
//! their value hands a datapath exactly 0 ops. They are censused as structure (counts against the analytic
//! expectation) and the worst members are measured for diffusion (`avalanche`), which bounds the only other
//! thing a rotation draw could move. A bit-exact verifier never lets a chip skip an application, however weak its
//! diffusion, so diffusion is reported and is not a gain.
//!
//! Commands:
//! attack-f4 census --from 20729 --count 16777216 --threads 12 [--out file] [--dedupe]
//! attack-f4 day --index 20729 one day's draw and classification
//! attack-f4 plant alleq|mul1|mul1all|rc0|rcrk0 the known-fail firings: the day 20729 draw with the planted field
//! attack-f4 expect --threads 12 exact per-word tables (NAF weight, popcount) over all 2^31 odd
//! constants, and the 16-fold convolution: the expected M1 tail
//! attack-f4 avalanche --index 20729 [--states 4096] single-application and two-application diffusion of a day
use igneum_pow::bind::day_bytes;
use igneum_pow::generator::V4_CLASS;
use igneum_pow::memhard::{mixer, round_key_mult, MixParams, Shape, ITEM_ROUNDS};
use igneum_pow::seed::{seed_words_from_bytes, SplitMix64};
use std::fmt::Write as _;
use std::io::Write as _;
/// The chain's genesis day index (`bind.rs` tests: day_index(0x1a0ff0f7c00) = 20,729, 3 October 2026).
const GENESIS_DAY: u64 = 20_729;
/// Mixer applications per item under class v4 (`Shape::mixers_per_item`): 9 x 8.
const APPLICATIONS_PER_ITEM: u64 = (ITEM_ROUNDS as u64 + 1) * 8;
/// Adds and XORs of one application outside the multiply layer: 8 quarter rounds x (4 adds + 4 xors).
const QR_ADDS_XORS: u32 = 64;
/// The gate's gain threshold (plan 1.4 (3), B5 rank 3).
const GAIN_GATE: f64 = 1.1;
/// M2: a constant of NAF weight at most this is cheaper in LUTs than in a DSP block.
const M2_NAF_CEIL: u32 = 3;
// ------------------------------------------------------------------------------------------------------------
// The day
// ------------------------------------------------------------------------------------------------------------
fn v4_shape() -> Shape {
let s = Shape::for_class(&V4_CLASS);
assert_eq!(s.mixer_mult, 8, "class v4 is the x8 mixer");
assert_eq!(s.derive_len, 0, "class v4 has no derivation program: the fixed mixer with drawn constants");
s
}
/// The chain day's key and its draw through the real code.
fn params_of_day(d: u64) -> MixParams {
MixParams::with_shape(seed_words_from_bytes(&day_bytes(d)), v4_shape())
}
fn seed64(key: &[u32; 8]) -> u64 {
key[0] as u64 | ((key[1] as u64) << 32)
}
/// Non-adjacent-form weight of a 32-bit constant (the number of nonzero signed digits).
fn naf_weight(v: u32) -> u32 {
let mut n = v as u64;
let mut w = 0;
while n != 0 {
if n & 1 == 1 {
// digit +1 when n = 1 mod 4, -1 when n = 3 mod 4
if n & 3 == 3 {
n += 1;
} else {
n -= 1;
}
w += 1;
}
n >>= 1;
}
w
}
/// Round keys of the 72 applications of an item under m = 8: `round_key(r * 8 + j)`, r in 0..=8, j in 0..8.
fn round_keys() -> [u32; 72] {
let mut k = [0u32; 72];
for r in 0..=ITEM_ROUNDS {
for j in 0..8 {
k[r * 8 + j] = round_key_mult(r, j, 8);
}
}
k
}
#[derive(Clone, Debug, Default)]
struct DayClass {
// ROT
rot_distinct: u32,
rot_all_equal: bool,
rot_max_mult: u32,
rot_comp_same_word: bool,
rot_comp_any: bool,
rot_small: u32,
rot_byte: u32,
// MUL
naf: [u32; 16],
naf_sum: u32,
naf_min: u32,
mul_one: u32,
mul_minus_one: u32,
mul_pop_le2: u32,
mul_pop_le4: u32,
mul_pop_le8: u32,
mul_naf_le2: u32,
mul_naf_le3: u32,
mul_naf_le4: u32,
mul_small: u32,
mul_dup: bool,
// RC
rc_zero: u32,
rc_pop_ext: u32,
rc_rk_zero: u32,
rc_dup: bool,
// gains
cost_m1: u32,
m2_k: u32,
}
fn classify(mp: &MixParams, rks: &[u32; 72]) -> DayClass {
let mut c = DayClass::default();
// ROT
let mut seen = [0u32; 32];
for &r in &mp.rot {
assert!((1..=31).contains(&r));
seen[r as usize] += 1;
if matches!(r, 1 | 2 | 30 | 31) {
c.rot_small += 1;
}
if matches!(r, 8 | 16 | 24) {
c.rot_byte += 1;
}
}
c.rot_distinct = seen.iter().filter(|&&n| n > 0).count() as u32;
c.rot_max_mult = *seen.iter().max().unwrap();
c.rot_all_equal = c.rot_distinct == 1;
// the same-word pairs of a quarter round: s[d] takes ROT[0] then ROT[2], s[b] takes ROT[1] then ROT[3]; the
// diagonal round the same with ROT[4..7]
for (a, b) in [(0, 2), (1, 3), (4, 6), (5, 7)] {
if mp.rot[a] + mp.rot[b] == 32 {
c.rot_comp_same_word = true;
}
}
for a in 0..8 {
for b in a + 1..8 {
if mp.rot[a] + mp.rot[b] == 32 {
c.rot_comp_any = true;
}
}
}
// MUL
c.naf_min = u32::MAX;
for i in 0..16 {
let m = mp.mul[i];
assert!(m & 1 == 1);
let w = naf_weight(m);
c.naf[i] = w;
c.naf_sum += w;
c.naf_min = c.naf_min.min(w);
let p = m.count_ones();
if m == 1 {
c.mul_one += 1;
}
if m == u32::MAX {
c.mul_minus_one += 1;
}
if p <= 2 {
c.mul_pop_le2 += 1;
}
if p <= 4 {
c.mul_pop_le4 += 1;
}
if p <= 8 {
c.mul_pop_le8 += 1;
}
if w <= 2 {
c.mul_naf_le2 += 1;
}
if w <= 3 {
c.mul_naf_le3 += 1;
}
if w <= 4 {
c.mul_naf_le4 += 1;
}
if m < 256 {
c.mul_small += 1;
}
for j in 0..i {
if mp.mul[j] == m {
c.mul_dup = true;
}
}
}
c.cost_m1 = QR_ADDS_XORS + c.naf_sum - 16;
c.m2_k = c.mul_naf_le3;
// RC
for i in 0..16 {
let r = mp.rc[i];
if r == 0 {
c.rc_zero += 1;
}
let p = r.count_ones();
if p <= 4 || p >= 28 {
c.rc_pop_ext += 1;
}
for &rk in rks.iter() {
if r.wrapping_add(rk) == 0 {
c.rc_rk_zero += 1;
}
}
for j in 0..i {
if mp.rc[j] == r {
c.rc_dup = true;
}
}
}
c
}
fn m2_gain(k: u32) -> f64 {
16.0 / (16.0 - k as f64)
}
// ------------------------------------------------------------------------------------------------------------
// The tally
// ------------------------------------------------------------------------------------------------------------
/// The worst member of a class: the lowest M1 cost among the days in it (ties: the earliest day).
#[derive(Clone, Copy, Debug)]
struct Worst {
day: u64,
cost: u32,
}
impl Worst {
fn none() -> Self {
Worst { day: u64::MAX, cost: u32::MAX }
}
fn offer(&mut self, day: u64, cost: u32) {
if cost < self.cost || (cost == self.cost && day < self.day) {
*self = Worst { day, cost };
}
}
fn merge(&mut self, o: &Worst) {
if o.day != u64::MAX {
self.offer(o.day, o.cost);
}
}
}
const CLASSES: &[&str] = &[
"ROT all equal",
"ROT distinct <= 3",
"ROT distinct <= 4",
"ROT max multiplicity >= 4",
"ROT same-word pair sums to 32",
"ROT any pair sums to 32",
"ROT all 8 in {1,2,30,31}",
"ROT >= 6 in {1,2,30,31}",
"ROT >= 4 in {1,2,30,31}",
"ROT >= 4 in {8,16,24}",
"MUL any = 1",
"MUL any = 2^32-1",
"MUL any popcount <= 2",
"MUL any popcount <= 4",
"MUL any popcount <= 8",
"MUL any NAF weight <= 2",
"MUL any NAF weight <= 3",
"MUL any NAF weight <= 4",
"MUL any < 256",
"MUL two equal",
"MUL M2 k >= 2 (gain >= 1.14x)",
"RC any = 0",
"RC any popcount <= 4 or >= 28",
"RC + rk = 0 for any of the 72 keys",
"RC two equal",
];
#[derive(Clone, Debug)]
struct Tally {
n: u64,
class_count: Vec<u64>,
class_worst: Vec<Worst>,
cost_hist: Vec<u64>,
naf_sum_hist: Vec<u64>,
naf_min_hist: Vec<u64>,
rot_distinct_hist: [u64; 9],
rot_small_hist: [u64; 9],
rot_byte_hist: [u64; 9],
rot_mult_hist: [u64; 9],
m2_k_hist: [u64; 17],
/// The 16 lowest-cost days seen (cost, day), sorted ascending.
lowest: Vec<(u32, u64)>,
highest: Vec<(u32, u64)>,
seeds: Vec<u64>,
}
impl Tally {
fn new(dedupe: bool, cap: usize) -> Self {
Tally {
n: 0,
class_count: vec![0; CLASSES.len()],
class_worst: vec![Worst::none(); CLASSES.len()],
cost_hist: vec![0; 400],
naf_sum_hist: vec![0; 400],
naf_min_hist: vec![0; 40],
rot_distinct_hist: [0; 9],
rot_small_hist: [0; 9],
rot_byte_hist: [0; 9],
rot_mult_hist: [0; 9],
m2_k_hist: [0; 17],
lowest: Vec::new(),
highest: Vec::new(),
seeds: if dedupe { Vec::with_capacity(cap) } else { Vec::new() },
}
}
fn flags(c: &DayClass) -> [bool; 25] {
[
c.rot_all_equal,
c.rot_distinct <= 3,
c.rot_distinct <= 4,
c.rot_max_mult >= 4,
c.rot_comp_same_word,
c.rot_comp_any,
c.rot_small == 8,
c.rot_small >= 6,
c.rot_small >= 4,
c.rot_byte >= 4,
c.mul_one > 0,
c.mul_minus_one > 0,
c.mul_pop_le2 > 0,
c.mul_pop_le4 > 0,
c.mul_pop_le8 > 0,
c.mul_naf_le2 > 0,
c.mul_naf_le3 > 0,
c.mul_naf_le4 > 0,
c.mul_small > 0,
c.mul_dup,
c.m2_k >= 2,
c.rc_zero > 0,
c.rc_pop_ext > 0,
c.rc_rk_zero > 0,
c.rc_dup,
]
}
fn add(&mut self, day: u64, mp: &MixParams, c: &DayClass, dedupe: bool) {
self.n += 1;
let f = Self::flags(c);
assert_eq!(f.len(), CLASSES.len());
for (i, &on) in f.iter().enumerate() {
if on {
self.class_count[i] += 1;
self.class_worst[i].offer(day, c.cost_m1);
}
}
self.cost_hist[c.cost_m1 as usize] += 1;
self.naf_sum_hist[c.naf_sum as usize] += 1;
self.naf_min_hist[c.naf_min as usize] += 1;
self.rot_distinct_hist[c.rot_distinct as usize] += 1;
self.rot_small_hist[c.rot_small as usize] += 1;
self.rot_byte_hist[c.rot_byte as usize] += 1;
self.rot_mult_hist[c.rot_max_mult as usize] += 1;
self.m2_k_hist[c.m2_k as usize] += 1;
push_sorted(&mut self.lowest, (c.cost_m1, day), 16, true);
push_sorted(&mut self.highest, (c.cost_m1, day), 4, false);
if dedupe {
self.seeds.push(seed64(&mp.key));
}
}
fn merge(&mut self, o: Tally) {
self.n += o.n;
for i in 0..CLASSES.len() {
self.class_count[i] += o.class_count[i];
self.class_worst[i].merge(&o.class_worst[i]);
}
for (a, b) in self.cost_hist.iter_mut().zip(o.cost_hist.iter()) {
*a += b;
}
for (a, b) in self.naf_sum_hist.iter_mut().zip(o.naf_sum_hist.iter()) {
*a += b;
}
for (a, b) in self.naf_min_hist.iter_mut().zip(o.naf_min_hist.iter()) {
*a += b;
}
for i in 0..9 {
self.rot_distinct_hist[i] += o.rot_distinct_hist[i];
self.rot_small_hist[i] += o.rot_small_hist[i];
self.rot_byte_hist[i] += o.rot_byte_hist[i];
self.rot_mult_hist[i] += o.rot_mult_hist[i];
}
for i in 0..17 {
self.m2_k_hist[i] += o.m2_k_hist[i];
}
for e in o.lowest {
push_sorted(&mut self.lowest, e, 16, true);
}
for e in o.highest {
push_sorted(&mut self.highest, e, 4, false);
}
self.seeds.extend(o.seeds);
}
}
/// Keep the `cap` smallest (ascending) or largest (descending) entries.
fn push_sorted(v: &mut Vec<(u32, u64)>, e: (u32, u64), cap: usize, ascending: bool) {
if v.len() == cap {
let last = *v.last().unwrap();
let keep = if ascending { e < last } else { e > last };
if !keep {
return;
}
v.pop();
}
let pos = if ascending { v.partition_point(|x| *x < e) } else { v.partition_point(|x| *x > e) };
v.insert(pos, e);
}
// ------------------------------------------------------------------------------------------------------------
// Analytic expectations (per day, independent draws; the modulo-31 bias of `below` is 2^-64 per value and ignored)
// ------------------------------------------------------------------------------------------------------------
fn ln_choose(n: u64, k: u64) -> f64 {
let lg = |x: u64| -> f64 { (1..=x).map(|i| (i as f64).ln()).sum() };
lg(n) - lg(k) - lg(n - k)
}
fn binom_tail(n: u64, p: f64, k_min: u64) -> f64 {
(k_min..=n).map(|k| (ln_choose(n, k) + (k as f64) * p.ln() + ((n - k) as f64) * (1.0 - p).ln()).exp()).sum()
}
/// P(d distinct values among 8 uniform draws from 31): S(8, d) x 31 falling d / 31^8.
fn p_rot_distinct(d: u32) -> f64 {
// Stirling numbers of the second kind S(8, d)
let mut s = vec![vec![0f64; 9]; 9];
s[0][0] = 1.0;
for n in 1..=8 {
for k in 1..=n {
s[n][k] = (k as f64) * s[n - 1][k] + s[n - 1][k - 1];
}
}
let mut falling = 1.0;
for i in 0..d {
falling *= (31 - i) as f64;
}
s[8][d as usize] * falling / 31f64.powi(8)
}
/// P(max multiplicity >= 4 among 8 draws from 31), by enumeration of the multiplicity patterns is long; the
/// census gives the exact count, so this is the first-order bound: C(8,4) x 31 x 31^-4 (approximate).
fn p_rot_mult4_approx() -> f64 {
70.0 * 31.0 / 31f64.powi(4)
}
fn p_any_of(n: u64, p: f64) -> f64 {
1.0 - (1.0 - p).powi(n as i32)
}
fn one_in(p: f64) -> String {
if p <= 0.0 {
"0".into()
} else {
format!("1 in {:.3e}", 1.0 / p)
}
}
// ------------------------------------------------------------------------------------------------------------
// Printing a day
// ------------------------------------------------------------------------------------------------------------
fn hex_bytes(b: &[u8]) -> String {
b.iter().map(|x| format!("{x:02x}")).collect()
}
fn describe(day: u64, mp: &MixParams, c: &DayClass, median_cost: Option<u32>) -> String {
let mut s = String::new();
let _ = writeln!(s, "day index {day} (genesis + {}), day bytes {} , seed64 {:016x}", day as i64 - GENESIS_DAY as i64, hex_bytes(&day_bytes(day)), seed64(&mp.key));
let _ = writeln!(s, "key {}", mp.key.iter().map(|w| format!("{w:08x}")).collect::<Vec<_>>().join(" "));
let _ = writeln!(s, "ROT {:?} distinct {} max multiplicity {} small {} byte-aligned {} same-word pair 32 {} any pair 32 {}", mp.rot, c.rot_distinct, c.rot_max_mult, c.rot_small, c.rot_byte, c.rot_comp_same_word, c.rot_comp_any);
let _ = writeln!(s, "MUL {}", mp.mul.iter().map(|w| format!("{w:08x}")).collect::<Vec<_>>().join(" "));
let _ = writeln!(s, "NAF {:?} sum {} min {} =1 {} =-1 {} pop<=4 {} naf<=3 {} <256 {} dup {}", c.naf, c.naf_sum, c.naf_min, c.mul_one, c.mul_minus_one, c.mul_pop_le4, c.mul_naf_le3, c.mul_small, c.mul_dup);
let _ = writeln!(s, "RC {}", mp.rc.iter().map(|w| format!("{w:08x}")).collect::<Vec<_>>().join(" "));
let _ = writeln!(s, "RC zero {} pop<=4|>=28 {} rc+rk=0 {} dup {}", c.rc_zero, c.rc_pop_ext, c.rc_rk_zero, c.rc_dup);
let _ = writeln!(s, "M1 cost {} adder-equivalents per application ({} per item, 72 applications); M2 k {} (gain {:.3}x)", c.cost_m1, c.cost_m1 as u64 * APPLICATIONS_PER_ITEM, c.m2_k, m2_gain(c.m2_k));
if let Some(m) = median_cost {
let _ = writeln!(s, "M1 gain against the census median {m}: {:.4}x", m as f64 / c.cost_m1 as f64);
}
let flags: Vec<&str> = Tally::flags(c).iter().zip(CLASSES.iter()).filter(|(f, _)| **f).map(|(_, n)| *n).collect();
let _ = writeln!(s, "classes: {}", if flags.is_empty() { "none".to_string() } else { flags.join("; ") });
s
}
// ------------------------------------------------------------------------------------------------------------
// Commands
// ------------------------------------------------------------------------------------------------------------
fn arg(args: &[String], name: &str) -> Option<String> {
args.iter().position(|a| a == name).and_then(|i| args.get(i + 1).cloned())
}
fn census(args: &[String]) {
let from: u64 = arg(args, "--from").map(|v| v.parse().unwrap()).unwrap_or(GENESIS_DAY);
let count: u64 = arg(args, "--count").map(|v| v.parse().unwrap()).unwrap_or(1 << 24);
let threads: usize = arg(args, "--threads").map(|v| v.parse().unwrap()).unwrap_or(12);
let out = arg(args, "--out");
let dedupe = args.iter().any(|a| a == "--dedupe");
let shape = v4_shape();
let rks = round_keys();
let t0 = std::time::Instant::now();
let chunk = count.div_ceil(threads as u64);
let tallies: Vec<Tally> = std::thread::scope(|sc| {
let hs: Vec<_> = (0..threads)
.map(|t| {
let rks = &rks;
sc.spawn(move || {
let lo = from + chunk * t as u64;
let hi = (lo + chunk).min(from + count);
let mut tally = Tally::new(dedupe, (hi.saturating_sub(lo)) as usize);
for d in lo..hi {
let mp = params_of_day(d);
debug_assert_eq!(mp.shape, shape);
let c = classify(&mp, rks);
tally.add(d, &mp, &c, dedupe);
}
tally
})
})
.collect();
hs.into_iter().map(|h| h.join().unwrap()).collect()
});
let mut all = Tally::new(false, 0);
for t in tallies {
all.merge(t);
}
let secs = t0.elapsed().as_secs_f64();
assert_eq!(all.n, count);
// the median cost and the gate fractions
let total = all.n;
let mut acc = 0u64;
let mut median = 0u32;
for (c, &n) in all.cost_hist.iter().enumerate() {
acc += n;
if acc * 2 >= total {
median = c as u32;
break;
}
}
let mean = all.cost_hist.iter().enumerate().map(|(c, &n)| c as f64 * n as f64).sum::<f64>() / total as f64;
let var = all.cost_hist.iter().enumerate().map(|(c, &n)| (c as f64 - mean).powi(2) * n as f64).sum::<f64>() / total as f64;
let gate_cost = |reference: f64| -> u32 { (reference / GAIN_GATE).floor() as u32 }; // cost <= this gives gain >= 1.1x... strictly over: cost < reference/1.1
let over = |reference: f64| -> u64 {
all.cost_hist.iter().enumerate().filter(|(c, _)| (*c as f64) * GAIN_GATE < reference).map(|(_, &n)| n).sum()
};
let over_median = over(median as f64);
let over_mean = over(mean);
let m2_over: u64 = all.m2_k_hist.iter().enumerate().filter(|(k, _)| m2_gain(*k as u32) > GAIN_GATE).map(|(_, &n)| n).sum();
let mut r = String::new();
let _ = writeln!(r, "# attack-f4 census: {count} chain days from day index {from} (genesis {GENESIS_DAY}), class v4 shape (mixer x{}, cache 2^{}), {threads} threads, {secs:.1} s", shape.mixer_mult, shape.cache_log2_words);
let _ = writeln!(r, "draw: MixParams::with_shape(seed_words_from_bytes(bind::day_bytes(d)), Shape::for_class(&V4_CLASS)); seed64 = key[0] | key[1] << 32");
let _ = writeln!(r);
let _ = writeln!(r, "## Gate (plan 1.4 (3), B5 rank 3): fraction of days with any gain over {GAIN_GATE}x under 2^-20 = {:.3e}", 2f64.powi(-20));
let _ = writeln!(r);
let _ = writeln!(r, "| Metric | Reference | Days over {GAIN_GATE}x | Fraction | Against 2^-20 |");
let _ = writeln!(r, "|---|---|---|---|---|");
let frac = |n: u64| n as f64 / total as f64;
let vs = |n: u64| if frac(n) < 2f64.powi(-20) { "under" } else { "OVER" };
let _ = writeln!(r, "| M1 per-day LUT datapath, adders per application | median cost {median} (gain over {GAIN_GATE}x = cost under {}) | {over_median} | {:.3e} | {} |", gate_cost(median as f64) + 1, frac(over_median), vs(over_median));
let _ = writeln!(r, "| M1 against the mean cost {mean:.2} (sd {:.2}) | cost under {:.2} | {over_mean} | {:.3e} | {} |", var.sqrt(), mean / GAIN_GATE, frac(over_mean), vs(over_mean));
let _ = writeln!(r, "| M2 DSP-bound datapath, 16/(16-k) with k = words of NAF weight <= {M2_NAF_CEIL} | k >= 2 | {m2_over} | {:.3e} | {} |", frac(m2_over), vs(m2_over));
let _ = writeln!(r, "| ROT value (wiring) and RC value (inverters) on a per-day datapath | exact 0 ops moved on every day | 0 | 0 | under |");
let _ = writeln!(r);
let _ = writeln!(r, "M1 cost = {QR_ADDS_XORS} + sum(NAF(MUL_i) - 1); mean {mean:.3}, sd {:.3}, median {median}, min {} (day {}), max {} (day {})", var.sqrt(), all.lowest[0].0, all.lowest[0].1, all.highest[0].0, all.highest[0].1);
let _ = writeln!(r);
// the classes
let p_mul1 = p_any_of(16, 2f64.powi(-31));
let p_small = p_any_of(16, 128.0 / 2f64.powi(31));
let p_rc0 = p_any_of(16, 2f64.powi(-32));
let p_rcrk = p_any_of(16, 72.0 / 2f64.powi(32));
let pop_le = |k: u32| -> f64 { (0..=k).map(|i| ln_choose(32, i as u64).exp()).sum::<f64>() };
let p_rc_pop = p_any_of(16, 2.0 * pop_le(4) / 2f64.powi(32));
// odd constants with popcount <= k: the low bit is set, so C(31, i) for the other i < k bits
let odd_pop_le = |k: u32| -> f64 { (0..k).map(|i| ln_choose(31, i as u64).exp()).sum::<f64>() / 2f64.powi(31) };
let p_dup16 = |space: f64| -> f64 { 1.0 - (1..16).map(|i| 1.0 - i as f64 / space).product::<f64>() };
let expectations: Vec<Option<f64>> = vec![
Some(31f64.powi(-7)),
Some((1..=3).map(p_rot_distinct).sum()),
Some((1..=4).map(p_rot_distinct).sum()),
Some(p_rot_mult4_approx()),
Some(p_any_of(4, 1.0 / 31.0)),
Some(p_any_of(28, 1.0 / 31.0)),
Some((4f64 / 31.0).powi(8)),
Some(binom_tail(8, 4.0 / 31.0, 6)),
Some(binom_tail(8, 4.0 / 31.0, 4)),
Some(binom_tail(8, 3.0 / 31.0, 4)),
Some(p_mul1),
Some(p_mul1),
Some(p_any_of(16, odd_pop_le(2))),
Some(p_any_of(16, odd_pop_le(4))),
Some(p_any_of(16, odd_pop_le(8))),
None,
None,
None,
Some(p_small),
Some(p_dup16(2f64.powi(31))),
None,
Some(p_rc0),
Some(p_rc_pop),
Some(p_rcrk),
Some(p_dup16(2f64.powi(32))),
];
let _ = writeln!(r, "## Classes over {count} days");
let _ = writeln!(r);
let _ = writeln!(r, "| Class | Count | Fraction | Expected per day (analytic) | Expected count | Worst member (day, M1 cost, M1 gain vs median, M2 gain) |");
let _ = writeln!(r, "|---|---|---|---|---|---|");
for (i, name) in CLASSES.iter().enumerate() {
let n = all.class_count[i];
let w = all.class_worst[i];
let worst = if w.day == u64::MAX {
"none".to_string()
} else {
let c = classify(&params_of_day(w.day), &rks);
format!("day {} , cost {} , {:.4}x , {:.3}x", w.day, w.cost, median as f64 / w.cost as f64, m2_gain(c.m2_k))
};
let (ep, ec) = match expectations[i] {
Some(p) => (format!("{p:.3e} ({})", one_in(p)), format!("{:.3}", p * total as f64)),
None => ("see `expect`".to_string(), "see `expect`".to_string()),
};
let _ = writeln!(r, "| {name} | {n} | {:.3e} | {ep} | {ec} | {worst} |", frac(n));
}
let _ = writeln!(r);
let _ = writeln!(r, "## Histograms");
let _ = writeln!(r);
let _ = writeln!(r, "| ROT distinct amounts | Count | Fraction | Expected (S(8,d) 31_d / 31^8) |");
let _ = writeln!(r, "|---|---|---|---|");
for d in 1..=8 {
let _ = writeln!(r, "| {d} | {} | {:.4e} | {:.4e} |", all.rot_distinct_hist[d], frac(all.rot_distinct_hist[d]), p_rot_distinct(d as u32));
}
let _ = writeln!(r);
let _ = writeln!(r, "| ROT amounts in {{1,2,30,31}} | Count | Expected Binomial(8, 4/31) | ROT amounts in {{8,16,24}} | Count | Expected Binomial(8, 3/31) | ROT max multiplicity | Count |");
let _ = writeln!(r, "|---|---|---|---|---|---|---|---|");
for k in 0..=8 {
let e1 = binom_tail(8, 4.0 / 31.0, k) - binom_tail(8, 4.0 / 31.0, k + 1);
let e2 = binom_tail(8, 3.0 / 31.0, k) - binom_tail(8, 3.0 / 31.0, k + 1);
let _ = writeln!(r, "| {k} | {} | {:.1} | {k} | {} | {:.1} | {k} | {} |", all.rot_small_hist[k as usize], e1 * total as f64, all.rot_byte_hist[k as usize], e2 * total as f64, all.rot_mult_hist[k as usize]);
}
let _ = writeln!(r);
let _ = writeln!(r, "| M2 k (words of NAF weight <= {M2_NAF_CEIL}) | Count | Gain 16/(16-k) |");
let _ = writeln!(r, "|---|---|---|");
for k in 0..=16 {
if all.m2_k_hist[k] > 0 || k <= 3 {
let _ = writeln!(r, "| {k} | {} | {:.3}x |", all.m2_k_hist[k], m2_gain(k as u32));
}
}
let _ = writeln!(r);
let _ = writeln!(r, "| Minimum NAF weight over the 16 MUL | Count |");
let _ = writeln!(r, "|---|---|");
for (w, &n) in all.naf_min_hist.iter().enumerate() {
if n > 0 {
let _ = writeln!(r, "| {w} | {n} |");
}
}
let _ = writeln!(r);
let _ = writeln!(r, "| M1 cost per application | Count | Cumulative fraction | M1 gain vs median |");
let _ = writeln!(r, "|---|---|---|---|");
let mut cum = 0u64;
for (c, &n) in all.cost_hist.iter().enumerate() {
if n > 0 {
cum += n;
let _ = writeln!(r, "| {c} | {n} | {:.4e} | {:.4}x |", frac(cum), median as f64 / c as f64);
}
}
let _ = writeln!(r);
let _ = writeln!(r, "## The 16 lowest-cost days (M1)");
let _ = writeln!(r);
for &(cost, day) in &all.lowest {
let mp = params_of_day(day);
let c = classify(&mp, &rks);
let _ = writeln!(r, "- day {day}: cost {cost}, gain {:.4}x vs median, NAF sum {}, M2 k {}, day-hex {}", median as f64 / cost as f64, c.naf_sum, c.m2_k, hex_bytes(&day_bytes(day)));
}
if dedupe {
all.seeds.sort_unstable();
let before = all.seeds.len();
all.seeds.dedup();
let _ = writeln!(r);
let _ = writeln!(r, "## 64-bit seeding: {} days, {} distinct 64-bit stream seeds ({} collisions; expected C(n,2)/2^64 = {:.3e})", before, all.seeds.len(), before - all.seeds.len(), (before as f64) * (before as f64 - 1.0) / 2.0 / 2f64.powi(64));
}
let _ = writeln!(r);
let _ = writeln!(r, "## Worst member of every class, in full");
let _ = writeln!(r);
let mut shown: Vec<u64> = Vec::new();
for (i, name) in CLASSES.iter().enumerate() {
let w = all.class_worst[i];
if w.day == u64::MAX || shown.contains(&w.day) {
continue;
}
shown.push(w.day);
let mp = params_of_day(w.day);
let c = classify(&mp, &rks);
let _ = writeln!(r, "### {name}: day {}", w.day);
let _ = writeln!(r, "```");
let _ = write!(r, "{}", describe(w.day, &mp, &c, Some(median)));
let _ = writeln!(r, "```");
}
print!("{r}");
if let Some(p) = out {
std::fs::File::create(&p).unwrap().write_all(r.as_bytes()).unwrap();
eprintln!("written {p}");
}
}
fn day_cmd(args: &[String]) {
let d: u64 = arg(args, "--index").map(|v| v.parse().unwrap()).unwrap_or(GENESIS_DAY);
let median: Option<u32> = arg(args, "--median").map(|v| v.parse().unwrap());
let mp = params_of_day(d);
let c = classify(&mp, &round_keys());
print!("{}", describe(d, &mp, &c, median));
}
/// The known-fail firings: the genesis day's draw with one field forced through this crate's own hook (the
/// `MixParams` fields are public; `igneum-pow` is untouched). Exit 0 when the classifier flags the plant and the
/// gain metric that the plant moves reads over the gate.
fn plant(args: &[String]) {
let what = args.get(2).cloned().unwrap_or_default();
let median: u32 = arg(args, "--median").map(|v| v.parse().unwrap()).unwrap_or(221);
let rks = round_keys();
let mut mp = params_of_day(GENESIS_DAY);
let before = classify(&mp, &rks);
println!("before the plant (day {GENESIS_DAY}):");
print!("{}", describe(GENESIS_DAY, &mp, &before, Some(median)));
let (flag_name, gain_metric): (&str, &str) = match what.as_str() {
"alleq" => {
mp.rot = [7; 8];
("ROT all equal", "structure (0 ops on a per-day datapath by construction; diffusion in `avalanche`)")
}
"mul1" => {
mp.mul[5] = 1;
("MUL any = 1", "M1")
}
"mul1all" => {
mp.mul = [1; 16];
("MUL any = 1", "M1")
}
"mulnaf" => {
// the lightest realistic plant: four words at NAF weight 3 (M2 k = 4), the rest untouched
for i in 0..4 {
mp.mul[i] = (1u32 << 20) + (1u32 << 9) + 1;
}
("MUL any NAF weight <= 3", "M1 and M2")
}
"rc0" => {
mp.rc[3] = 0;
("RC any = 0", "structure (0 ops on a per-day datapath by construction)")
}
"rcrk0" => {
mp.rc[3] = 0u32.wrapping_sub(round_key_mult(2, 5, 8));
("RC + rk = 0 for any of the 72 keys", "structure (one xor of 10,368 ops per item on a generic datapath: 1.0001x)")
}
_ => {
eprintln!("plant alleq|mul1|mul1all|mulnaf|rc0|rcrk0");
std::process::exit(2);
}
};
let after = classify(&mp, &rks);
println!("\nafter the plant `{what}`:");
print!("{}", describe(GENESIS_DAY, &mp, &after, Some(median)));
let idx = CLASSES.iter().position(|n| *n == flag_name).unwrap();
let flagged = Tally::flags(&after)[idx] && !Tally::flags(&before)[idx];
let gain_m1 = median as f64 / after.cost_m1 as f64;
let gain_m2 = m2_gain(after.m2_k);
println!("\nplant `{what}`: classifier flag `{flag_name}` {} (was {} before); M1 gain {gain_m1:.4}x, M2 gain {gain_m2:.4}x; gain metric for this plant: {gain_metric}", if flagged { "FIRED" } else { "did NOT fire" }, Tally::flags(&before)[idx]);
let gain_fired = gain_m1 > GAIN_GATE || gain_m2 > GAIN_GATE;
println!("gain over {GAIN_GATE}x: {}", if gain_fired { "FIRED" } else { "not over the gate" });
if !flagged {
std::process::exit(1);
}
}
/// Exact per-word tables over every odd 32-bit constant (2^31 of them): the NAF weight distribution and the
/// popcount distribution; then the 16-fold convolution of the NAF-weight distribution gives the expected M1 cost
/// distribution and the expected fraction of days under any cost.
fn expect(args: &[String]) {
let threads: usize = arg(args, "--threads").map(|v| v.parse().unwrap()).unwrap_or(12);
let median: u32 = arg(args, "--median").map(|v| v.parse().unwrap()).unwrap_or(221);
let t0 = std::time::Instant::now();
let per: Vec<([u64; 40], [u64; 33])> = std::thread::scope(|sc| {
let hs: Vec<_> = (0..threads)
.map(|t| {
sc.spawn(move || {
let mut naf = [0u64; 40];
let mut pop = [0u64; 33];
let lo = ((1u64 << 32) * t as u64 / threads as u64) | 1;
let hi = (1u64 << 32) * (t as u64 + 1) / threads as u64;
let mut v = lo;
while v < hi {
naf[naf_weight(v as u32) as usize] += 1;
pop[(v as u32).count_ones() as usize] += 1;
v += 2;
}
(naf, pop)
})
})
.collect();
hs.into_iter().map(|h| h.join().unwrap()).collect()
});
let mut naf = [0u64; 40];
let mut pop = [0u64; 33];
for (a, b) in per {
for i in 0..40 {
naf[i] += a[i];
}
for i in 0..33 {
pop[i] += b[i];
}
}
let total: u64 = naf.iter().sum();
assert_eq!(total, 1 << 31);
println!("# attack-f4 expect: all {total} odd 32-bit constants, {threads} threads, {:.1} s", t0.elapsed().as_secs_f64());
println!();
println!("| NAF weight | Odd constants | Fraction | Cumulative | Any of 16 per day | x 2^24 days |");
println!("|---|---|---|---|---|---|");
let mut cum = 0u64;
for w in 0..40 {
if naf[w] > 0 {
cum += naf[w];
let p = cum as f64 / total as f64;
println!("| {w} | {} | {:.4e} | {:.4e} | {:.4e} | {:.3} |", naf[w], naf[w] as f64 / total as f64, p, p_any_of(16, p), p_any_of(16, p) * 2f64.powi(24));
}
}
println!();
println!("| Popcount | Odd constants | Cumulative fraction | Any of 16 per day |");
println!("|---|---|---|---|");
cum = 0;
for w in 0..33 {
if pop[w] > 0 {
cum += pop[w];
let p = cum as f64 / total as f64;
println!("| {w} | {} | {:.4e} | {:.4e} |", pop[w], p, p_any_of(16, p));
}
}
// the 16-fold convolution of the NAF-weight distribution: the exact expected distribution of the NAF sum
let pw: Vec<f64> = naf.iter().map(|&n| n as f64 / total as f64).collect();
let mut dist = vec![0f64; 1];
dist[0] = 1.0;
for _ in 0..16 {
let mut next = vec![0f64; dist.len() + 39];
for (i, &a) in dist.iter().enumerate() {
if a == 0.0 {
continue;
}
for (w, &b) in pw.iter().enumerate() {
next[i + w] += a * b;
}
}
dist = next;
}
let mean: f64 = dist.iter().enumerate().map(|(s, &p)| s as f64 * p).sum();
let var: f64 = dist.iter().enumerate().map(|(s, &p)| (s as f64 - mean).powi(2) * p).sum();
println!();
println!("Expected NAF sum over 16 words: mean {mean:.4}, sd {:.4}; expected M1 cost mean {:.4}", var.sqrt(), mean + QR_ADDS_XORS as f64 - 16.0);
println!();
println!("| M1 cost | NAF sum | Expected fraction of days at this cost | Expected cumulative fraction | Gain vs median {median} |");
println!("|---|---|---|---|---|");
let mut c = 0f64;
for (s, &p) in dist.iter().enumerate() {
let cost = s as i64 + QR_ADDS_XORS as i64 - 16;
if cost < 0 {
continue;
}
c += p;
if p > 1e-12 && (cost as f64) <= median as f64 {
println!("| {cost} | {s} | {p:.4e} | {c:.4e} | {:.4}x |", median as f64 / cost as f64);
}
}
let gate: f64 = dist.iter().enumerate().filter(|(s, _)| ((*s as f64) + QR_ADDS_XORS as f64 - 16.0) * GAIN_GATE < median as f64).map(|(_, &p)| p).sum();
println!();
println!("Expected fraction of days with M1 gain over {GAIN_GATE}x against median {median}: {gate:.4e} ({} ; x 2^24 = {:.1}); 2^-20 = {:.4e}", one_in(gate), gate * 2f64.powi(24), 2f64.powi(-20));
}
/// Diffusion of one day's mixer: for `states` random 16-word states and each of the 512 input bits, the fraction of
/// the 512 output bits that flip after k = 1 and k = 2 applications (keys `round_key_mult(0, 0, 8)` and `(0, 1, 8)`),
/// mean over all, and the minimum per-output-bit flip probability. An ideal mixer reads 0.5 mean and about 0.5 min.
fn avalanche(args: &[String]) {
let d: u64 = arg(args, "--index").map(|v| v.parse().unwrap()).unwrap_or(GENESIS_DAY);
let states: usize = arg(args, "--states").map(|v| v.parse().unwrap()).unwrap_or(4096);
let plant_alleq: Option<u32> = arg(args, "--plant-alleq").map(|v| v.parse().unwrap());
let mut mp = params_of_day(d);
if let Some(r) = plant_alleq {
mp.rot = [r; 8];
}
let c = classify(&mp, &round_keys());
println!("avalanche of day {d}{}: ROT {:?}, NAF sum {}, {states} states x 512 input bits", plant_alleq.map(|r| format!(" with ROT planted all {r}")).unwrap_or_default(), mp.rot, c.naf_sum);
let mut rng = SplitMix64::new(0xF4F4_F4F4 ^ d);
for k in 1..=3usize {
let apply = |s: &mut [u32; 16]| {
for j in 0..k {
mixer(s, round_keys()[j], &mp);
}
};
let mut flips = [0u64; 512];
let mut total_flips = 0u64;
let mut trials = 0u64;
for _ in 0..states {
let mut base = [0u32; 16];
for w in base.iter_mut() {
*w = rng.next() as u32;
}
let mut y0 = base;
apply(&mut y0);
for bit in 0..512 {
let mut x = base;
x[bit / 32] ^= 1 << (bit % 32);
apply(&mut x);
for o in 0..512 {
let f = ((x[o / 32] ^ y0[o / 32]) >> (o % 32)) & 1;
flips[o] += f as u64;
total_flips += f as u64;
}
trials += 1;
}
}
let mean = total_flips as f64 / (trials as f64 * 512.0);
let min = flips.iter().map(|&f| f as f64 / trials as f64).fold(1.0, f64::min);
let max = flips.iter().map(|&f| f as f64 / trials as f64).fold(0.0, f64::max);
println!("| {k} application{} | mean flip {mean:.4} | min per output bit {min:.4} | max {max:.4} |", if k > 1 { "s" } else { "" });
}
}
fn main() {
let args: Vec<String> = std::env::args().collect();
match args.get(1).map(|s| s.as_str()) {
Some("census") => census(&args),
Some("day") => day_cmd(&args),
Some("plant") => plant(&args),
Some("expect") => expect(&args),
Some("avalanche") => avalanche(&args),
_ => {
eprintln!("attack-f4 census|day|plant|expect|avalanche (see the module doc)");
std::process::exit(2);
}
}
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn naf_weights() {
assert_eq!(naf_weight(0), 0);
assert_eq!(naf_weight(1), 1);
assert_eq!(naf_weight(3), 2); // 4 - 1
assert_eq!(naf_weight(7), 2); // 8 - 1
assert_eq!(naf_weight(0xFFFF_FFFF), 2); // 2^32 - 1
assert_eq!(naf_weight(0xAAAA_AAAB), 17); // alternating odd: the maximum for 32 bits
assert_eq!(naf_weight((1 << 20) + (1 << 9) + 1), 3);
}
#[test]
fn genesis_day_draw_matches_memhard_md() {
// MEMHARD.md section 1.1 (string day "2026-10-03") is a different key from the chain's day index 20,729;
// what is checked here is that the chain-day path draws through the real code and stays in range.
let mp = params_of_day(GENESIS_DAY);
assert!(mp.rot.iter().all(|r| (1..=31).contains(r)));
assert!(mp.mul.iter().all(|m| m & 1 == 1));
assert_eq!(mp.shape, v4_shape());
let s = igneum_pow::seed::day_key("2026-10-03");
let mp2 = MixParams::with_shape(s, Shape::V2);
assert_eq!(mp2.rot, [20, 20, 19, 4, 26, 3, 3, 27], "MEMHARD.md 1.1 genesis-day ROT");
}
}

14
tools/attack/f8-uniform/Cargo.lock generated Normal file
View file

@ -0,0 +1,14 @@
# This file is automatically @generated by Cargo.
# It is not intended for manual editing.
version = 4
[[package]]
name = "attack-f8"
version = "0.1.0"
dependencies = [
"igneum-pow",
]
[[package]]
name = "igneum-pow"
version = "0.2.0"

View file

@ -0,0 +1,21 @@
[package]
name = "attack-f8"
version = "0.1.0"
edition = "2021"
description = "Attack-pass row F8: the uniformity censuses of the class v4 derivation (line index over 2^28 derivations, distinct lines per hash and warp, the cross-hash item histogram), with the plant hooks that prove the harness fires"
license = "MIT"
publish = false
[[bin]]
name = "attack-f8"
path = "src/main.rs"
[dependencies]
igneum-pow = { path = "../../../igneum-pow" }
[workspace]
[profile.release]
opt-level = 3
lto = true
codegen-units = 1

File diff suppressed because it is too large Load diff

View file

@ -15,3 +15,7 @@ docs/analysis/ci-failures-2026-10-06.md
# 7 October 2026: the last research round (the mission lanes and the closed list): internal research written for the
# owner, quoting his words and the operations record; the public spec mirror carries none of it
docs/analysis/mission
# 7 October 2026: the mixer cryptanalysis lane (adv-mixer): an internal adversarial pass that names the lanes, the
# coordinator and the operations timeline and quotes binary hashes and seeds; not for the public spec mirror
docs/analysis/cryptanalysis
docs/plans/cryptanalysis