84 KiB
Report: adversarial pass on the program acceptance rule (class v4 sub-version 3)
internal adversarial pass, not an independent review
- Target commit:
017e703764(class v4 sub-version 3, object byte 7). - Crate built: igneum-pow at the frozen commit (this worktree's igneum-pow/ is reset to it; build/master diverged by 635 deletions and is not used). Harness: tools/attack/adv-accept (depends on igneum-pow by path).
- Re-base (19:3x BST): build/master moved to
7a7caa34whose igneum-pow IS the frozen object; merged at 8748e955ceb48be5a6cbf7f8718a4884d3de9828;git diff --quiet 017e7037 HEAD -- igneum-powprints IDENTICAL. Nothing measured here was on a stale tree: igneum-pow/ had been reset to the frozen object before the first build. - Binary sha256 (first build, box 2): e3d35f4464937f91aac0648e2ee7134f33c85c7aa314b87b33f91059dedc6682 (adv-accept single-binary build); the two-binary build (adv-accept, adv-live = the unmodified f8 harness) sha256 is logged per box in the run sections below.
- Boxes: igneum-build-1 (CPU-bound sweeps, by the coordinator's order) and igneum-build-2 (shard 0, already there). nice 10 on every idle core, the capacity layer's yield (run-box.sh). Logs under /srv/builds/igneum-wt-adv-accept/adv/ on each box (spared from the checkout clean by .igneum-scratch-spare; the first 10k log on box 2 was wiped by a rebuild before the spare existed and is void anyway: old labels, old binary).
- Lane scope since 19:2x BST: THE BYPASS (Q1, Q2, Q5). Q3 is lane adv-accept-3's, Q4 lane adv-accept-2's.
- Seed space: the attack-pass F8 label space (program k = seed_words("igneum-attack-f8/program/k"), era
".../era/k"), so
adv-live warps --program kmeasures the live hot set of exactly the program the sweep reports. - rustc 1.99.0 both sides. First results by 8 October 2026 18:00 UTC. GPU: not available, so any per-card hash-rate confirmation of a gain is BLOCKED and said so.
- Box-hours spent: about 15.1 (running time, both boxes; the standing table carries the breakdown). Budget 8, crossed at about 02:15 BST; the coordinator's line then ran the shards on to 16 box-hours or 10:15 BST, whichever first. The last shard ended at 09:37 BST and the sweep closed at 09:47 BST with nothing holding or waiting on either box.
Draw-path validation (must pass before any claim)
The shared devnet epoch-0 class v4 program drawn through Epoch::chain_program(ProgramClass::V4) has
program id a785001687d8688a at attempt 1 (class mx8-erad810f22d+sh256x27), which matches the frozen
pack proto-cuda/packs-ca3-v4/v4-devnet-epoch0/program.json and the brief. So my draw path is the
chain's. Command: adv-accept derive-check on box 2. Devnet 3 epoch-0 (id fce15bf61030be57) derive
check is owed once I copy its program.json read-only from build-1.
Status board
| Q | Method | Known-failed shape (must fire) | Gate | Result | Status |
|---|---|---|---|---|---|
| Q1 | Steering/hot set: the chain's class v4 draw over the F8 label space (shards of 100k seeds; 19:27 BST to 19:4x BST under the SIGSTOP yield, since 19:4x BST nice 10 on cores 8-95, no yield), the stand-in per-site ratio at 256 units as the proxy, the live hot set by the unmodified f8 harness (adv-live) on the lowest-ratio seeds and on a consecutive-seed census | adv-live const-item plant FLAGGED (21.8x, X_1% +6.49); clean control 0.9996x PASS | X_f >= f flags a hot set; gain = implied on-die SRAM copy size | 796,042 accepted programs drawn (final, 09:47 BST); nine pass the rule and flag the f8 hot-set test at 2^24 nonces (100767, 4346, 5245, 1738, 170, 106924, 107022, 122960, 228763; X_0.1% +0.102% to +0.221%, 1.54x to 2.24x), 100767 also under the class v5 dataset; 37 lowest stand-in-ratio seeds live: 22 beyond the f8 1.2x gate, 9 hot sets; 20 random: 1 beyond, 0 hot sets; every hot set is 1 MB of items holding 0.26 to 0.41% of reads: gain 1.002x; the class v5 floor at 0.995 refuses all nine read at 2^20 (0.9809 to 0.9919) | FINDING, bounded: a program-dataflow distinguisher (site 6, a near-zero source under the 1% (c') limit) that survives the class v5 dataset; not an exploitable bypass; the 256-unit selector is weak (7 of 12 false positives); shards and 23 live rows re-queued in the lease pool |
| Q2 | Stand-in gap: a validated mirror runs the rule's own units on the closed form and on the live dataset; per-site ratio at 2^20 and the (c) metrics compared | zero-dataset plant: live 0.9733 REJECT against closed accept (fired) | any false accept that reads a hot set on the live set | 54 programs: max per-site gap 0.0004 (the 2^20 sampling noise), mean min-ratio gap 0.00002, 0 verdict disagreements, (c) metrics agree to 0.019 of 128 | BOUND |
| Q3 | Row 90 (exhaustion census) claimed by this lane, owner adv-accept-3 (unspawned): every candidate of 10,000 seeds through the real rule, first failing part recorded | forced-exhaust plant hit the cap and printed the last-resort program (accepted as drawn, no lossy op) | P(exhaust) bounded; last resort characterised | 20,000 seeds, 42,711 rejections: (a') 83.5%, (a) 11.6%, (b) 3.0%, (c'') 1.1%, the rest under 1%; per-candidate rejection 0.681 flat across attempts; P(exhaust) 2e-43; 0 exhaustions; max attempt 28 | BOUND (owner adv-accept-3, unspawned) |
| Q4 | Handed to lane adv-accept-2 | HANDED OVER | |||
| Q5 | Generator distinguishers over accepted programs: lossy last write, register-set collapse, the per-site ratio tail against the 0.98 floor | the five lowest-ratio seeds reproduce as live tail programs (done); F8 p15/p18/p19/p56 reproduction owed | a structural shape that lowers the live distinct-item count | first 864: lossy last write in 83%, 0 register collapse, min ratio 0.9986 at 256 units; at 2^20 the tail reaches 0.9832 (floor 0.98) | RUNNING |
| Q6 | Fixed (c) sample grindability; live-size invariance of the (c) verdict | BOUND unless something fires | not started | PENDING |
The plant (known-failed shape for the harness itself) fired: planting an or write of a load's
source register immediately before the load makes the rule reject with "(a') load at 1 reads r4, not
fresh by dataflow in the loop's steady state". So the harness reads the real rule, not a copy.
Command: adv-accept plant --seed 0 on box 2.
Q1 and Q5: the accepted-program sweep (RUNNING, sharded)
Ten shards of 100,000 seeds (k = 2..1,000,001 of the F8 label space), each
adv-accept sweep --seed-start S --seeds 100000 --threads 96 --ratio-units 256 --out /srv/builds/igneum-wt-adv-accept/adv/sweep-sNN.txt, started through run-box.sh (nice 10, yield to
builds, pid/pgid/yield pid files beside the log). Shard 00 (S = 2) on box 2, started 19:27 BST. Shard 01
(S = 100,002) on box 1, started 19:30 BST. Shards 02..09 sit as self-contained scripts in
/srv/builds/_adv/accept/queue/ on box 2 (claim by mkdir under claims/), to be run back to back on
whichever box has idle cores. Every row is written as it lands, so a partial shard is data.
Live hot set (the measure the chip model prices): adv-live warps --program k --nonces N (the
unmodified f8 harness: the day's items derived into a table, the cross-hash item histogram, the
hot-set test X_f >= f against the window-model control, the 6-sigma test, library agreement checks).
Known-failed shape run first: --plant const-item on program 2 at 10^6 nonces (box 1, 19:30 BST, log
adv/live-plant-p2.log) beside its clean control (adv/live-control-p2.log). The plant must be FLAGGED
and the control clear before any live number below is trusted.
Seeds: epoch bytes = LE words of seed_words_from_bytes("igneum-attack-f8/program/k"), era bytes of ".../era/k"; each drawn through the chain path generate_era(V4_CLASS, V3_ALLOWED), which runs the full attempt loop and the real acceptance rule.
Per accepted program the sweep records: attempt, program id, the closed-form distinct-item mean per hash (the rule's own (c) metric; 128 is ideal, the rule floor is a mean above 120), the minimum per-site distinct-index ratio at 256 units (the (c'') metric sampled cheaply; the enforced floor is 0.98 at 2^20 units), the saturated-final count and the output-bias max.
This is the closed-form proxy for Q1 and the headroom characterization for Q5. The live-dataset hot set (the memory-hard cache, items derived into a table, the cross-hash histogram with the hot-set test) is the next run and is what the chip model prices; the closed-form distinct mean is a cheap upper bound on how concentrated an accepted program can be on the stand-in.
Numbers land here when the run finishes (first results by 8 October 18:00 UTC).
Results as they land
Tool validation (box 1, 19:30 BST, 10^6 nonces each, about 30 s per run on 32 threads)
| Run | Hot-set test (window-model control) | Top 0.1% share ratio over the window model | 6-sigma | Verdict |
|---|---|---|---|---|
adv-live warps --program 2 --plant const-item (known-failed shape) |
f 1%: S_f 8.58%, E_f 2.09%, X_f +6.49% (X_f/f 6.49) HOT SET | 21.80x (flat control 26.85x) | FLAGGED | FLAGGED |
adv-live warps --program 2 (clean control) |
f 1%: S_f 2.56%, E_f 2.09%, X_f +0.47% (X_f/f 0.47) no hot set | 0.9996x (flat 1.2312x, the window layer) | clear | PASS |
The plant fires and the control is clean, so the live hot-set numbers below are trusted. Logs adv/live-plant-p2.log and adv/live-control-p2.log on box 1.
Sweep shard 01, first 864 accepted programs (box 1, seeds 100,002..., read at 19:33 BST)
| Metric | Value |
|---|---|
| Attempt histogram 0..9 | 273, 191, 134, 90, 59, 38, 34, 12, 7, 11; max 26 |
| Min per-site distinct-index ratio at 256 units | 0.9986 (floor 0.98 at 2^20; every row above 0.998) |
| Programs with a lossy (or/mul/mulhi) last write to an output register | 715 of 864 (83%) |
| Programs writing fewer than 8 registers | 0 |
| Last-resort programs | 0 |
| Lowest-ratio seeds (live hot set queued) | 100211 (0.9986), 100629 (0.9987), 100064, 100767 (0.9988), 100159 |
Reading: on the stand-in the accepted population sits 0.02 above the 0.98 floor at this sample size; the floor leaves headroom (Q5), and no accepted program in this sample comes near it. Whether any of the lossy-last-write programs concentrate reads on the LIVE set is what the live census answers.
Rule change in the method column (box-hours honesty)
19:27 BST to 19:4x BST: shards ran under the capacity layer's SIGSTOP yield and were paused almost the whole time (a build slot held nearly continuously on both boxes). Ruling at 19:4x BST: yield dropped, every sweep at nice 10 on cores 8-95 (cores 0-7 reserved for release builds, the seed and the observer). Shards 00 and 01 SIGCONTed and re-pinned at 19:4x BST. Box-hours before the ruling: about 0.1 of running time.
Live hot set of the five lowest-ratio shard-01 programs (box 1, 19:37 BST, 10^6 nonces each)
All five pass the rule (they are the chain's accepted programs). Log logs/adv-accept/live-lowratio-s01.log. Columns: the f8 gate (top 0.1% share over the window-model control, gate 1.2x), the hot-set excess X_f at f = 0.1% and 1% (a hot set needs X_f >= f), the windowed 6-sigma test, the hottest item and its traced source.
| Seed | id | attempt | closed ratio (256 u) | top 0.1% over window model | X_0.1% / X_1% | 6-sigma (buckets64) | hottest item, reads, share, source |
|---|---|---|---|---|---|---|---|
| 100211 | d07885a437e237c7 | 0 | 0.9986 | 1.08x | +0.026% / +0.049% | +42.4 sigma FLAGGED | 0x454585, 1238 (0.0010%), site instr 4 reads r0 one-zero-bit, writer load@3 |
| 100629 | 37c849d9741c5994 | 0 | 0.9987 | 1.01x | +0.003% / +0.015% | +5.6 within | 30 reads, none |
| 100064 | 2442abf9d56f6611 | 2 | 0.9988 | 1.17x | +0.044% / +0.189% | +77.3 sigma FLAGGED | 54 reads; the flag is a 256-item bucket at p43 (iteration 2, site 11, instr 33) holding 0.048% of that position's reads against 0.0061% expected (8x) |
| 100767 | 9d68e6286fc817d4 | 2 | 0.9988 | 1.34x BEYOND the 1.2x gate | +0.087% / +0.138% | +68.0 sigma FLAGGED | 0x000000, 1677 (0.0013%), site instr 6 reads r6 = zero, writer mad@4; saturated-source share 0.013% at that position (the (c') limit is 1%) |
| 100159 | 573d650159a8b04e | 3 | 0.9988 | 1.07x | +0.020% / +0.124% | +37.5 sigma FLAGGED | 37 reads, none |
| p2 control (19:30 BST) | f8 seed 2 | 0.9996x | +0.00% / +0.47% (flat) | clear | 32 reads |
Reading, as an attacker. (1) The stand-in ratio does correlate with live concentration: four of the five lowest-ratio seeds flag the windowed 6-sigma test at 10^6 nonces where the random control is clear, and one sits beyond the f8 gate. (2) The concentration is NOT a hot set a chip can use: the top 0.1% of items (16.7k items, 1 MB) take at most 0.34% of reads against 0.26% expected; the hottest single item takes 0.0013% of reads. An on-die copy of these items saves under 0.1% of DRAM reads: no row of chip-model-v3.md moves. (3) The mechanism is the known one, a near-saturated source (zero, or one bit off all ones) at one site in one iteration, below the (c') 1% limit (0.013% here), so (c') never fires, and the per-site ratio at 0.98 is loose enough (these sit at 0.9986) that (c'') never fires either.
FINDING (bounded): seed 100767 at 2^24 nonces passes the rule and flags the f8 hot-set test (box 1, 19:4x BST)
Reproduce in one command, from the frozen crate (017e7037) with the unmodified f8-uniform harness built as
adv-live (tools/attack/adv-accept, cargo build --release):
adv-live warps --program 100767 --nonces 16777216 --threads 32 --diag 1 --validate sample --out <dir>
The program is the chain's class v4 draw for epoch seed bytes = the little-endian words of
seed_words_from_bytes("igneum-attack-f8/program/100767") =
74484b391756fc49568cdd716bcfd839a55d31a45633c223c65c7f2ab4617fd4 and era seed bytes = the same of
"igneum-attack-f8/era/100767" = 7a65a05391dcd87b8fdaf7f74813aa17c6e13f7c56a03da2aaa6176987ef038b
(f8's program_spec(k) for k >= 2; adv-accept gap --seeds 100767 prints the same id), through
generate_era(V4_CLASS, V3_ALLOWED): attempt 2, program id 9d68e6286fc817d4, class
mx8-era763e5847+sh256x27, day bytes "igneum-day/" || 20730_le64 (f8's default day). The run's log is
logs/adv-accept/live-confirm-16m.log in this branch (copied from box 1,
/srv/builds/_adv-adv-accept/live-confirm-16m.log); the harness checks its mirror against Epoch::hash_warp
on 64 warps plus every 997th (0 mismatches in the log). Accepted by every part of the rule: it is the
program try_generate_class returns for the seed (attempt 0 and 1 rejected).
| Measure | Value | Uniform / control |
|---|---|---|
| Hot-set test f = 0.1% | S_f 0.303%, E_f 0.148%, X_f +0.155%, X_f/f 1.55: HOT SET | X_f >= f fires |
| Hot-set test f = 0.5%, 1% | X_f +0.266% (X/f 0.53), +0.325% (0.33): no hot set | |
| Top 0.1% share over the window-model control | 2.05x (0.5%: 1.37x, 1%: 1.23x); flat control 2.31x | f8 gate 1.2x; population 0.998x to 1.043x (14 random accepted programs, census, 10^6 nonces) |
| Windowed 6-sigma, 64-item buckets | largest bucket +294.8 sigma | population +4.4 to +30.6 at 10^6 nonces |
| Hot items (top 0.1% = 17,034 items, 1.0 MB) | 6,579,906 of 2,147,483,648 reads (0.306%) | 0.148% expected |
| Top 8 items | 0x000000 (29,355 reads), 0x200000, 0x300000, 0x180000, 0x100000, 0x080000, 0x380000, 0x0c0000: multiples of 2^19, read almost only from site 6 in every iteration | |
| Site attribution | site 6 (instr 23, src r6, quarter window) puts 3.35% of its reads into the hot items; site 7 (instr 32, src r0) 0.41%; every other site 0.00 to 0.21% (expected 0.10%) | |
| Site 6 source | r6, last written by mad at instr 4; saturated (zero) in 0.0126% of evaluations at that position (the (c') limit is 1%); the hot items are the images of small source values under the era stride |
Gain, priced against chip-model-v3.md section 5.7: an on-die copy of the top 0.1% of items (1 MB of SRAM) serves 0.31% of this program's loads instead of 0.15%, so it removes 0.16% of DRAM reads. The f = 1 chip's rate is lanes over latency per read; 0.16% fewer reads is a gain of 1.002x. No row moves. The rule has let through a program with a measurable, attributable hot set, and the hot set is worthless to a chip. The distinguisher is real; the bypass is not exploitable at this size.
The other three lowest-ratio seeds at 2^24 nonces (same log): all BEYOND the f8 1.2x gate on the live set, none a hot set by X_f >= f.
| Seed | top 0.1% over window model | X_0.1% (X/f) | 6-sigma | hot-set verdict |
|---|---|---|---|---|
| 100211 | 1.33x | +0.066% (0.66) | FLAGGED | clear |
| 100064 | 1.63x | +0.094% (0.94) | FLAGGED | clear |
| 100159 | 1.29x | +0.048% (0.48) | FLAGGED | clear |
| 23 random accepted programs (census, 10^6 nonces) | 0.998x to 1.043x, 0 over 1.2x | 5 of 14 flagged weakly (+6 to +31) |
So the stand-in's per-site ratio, read at 256 units in the sweep, is a working proxy for live concentration: the five lowest of 4,600 all fail the f8 gate on the live set while the population passes it. A seed-steering attacker (lane adv-accept-3's question) has a cheap selector. What it buys is the number above: a 1 MB hot set holding 0.3% of reads.
What a larger search adds: the sweep ranks seeds by the stand-in ratio, and the worst of 4,600 accepted programs gave X_0.1% = 0.155%. If the tail scales as the extreme of the population, 10^6 seeds reach a few times that, still under 1% of reads. The census over consecutive seeds (random accepted programs) says how often the hot-set test fires in the population; that number lands below.
The selector's base rate (rows read at 01:08 BST, 8 October: 269,250 accepted programs, 46 shard files de-duplicated by seed)
The stand-in per-site ratio at 256 units, over every accepted program (one row per seed; every seed of the F8 label space yields an accepted program through the chain draw):
| Quantile | min | 0.1% | 1% | median | max |
|---|---|---|---|---|---|
| ratio | 0.9811 | 0.9981 | 0.9993 | 0.9999 | 1.0000 |
| Threshold | Programs under it | Tries per hit |
|---|---|---|
| ratio < 0.9990 | 1,567 of 269,250 | 1 in 172 |
| ratio < 0.9980 (the lowest 25 measured live sat at or under this) | 271 | 1 in 994 |
| ratio < 0.9970 | 119 | 1 in 2,263 |
| ratio < 0.9960 | 70 | 1 in 3,846 |
| ratio < 0.9950 | 17 | 1 in 15,838 |
Over the 269,250: accepted attempt 0..11 = 86,535, 58,888, 39,382, 26,829, 18,609, 12,389, 8,531, 5,805, 3,937, 2,683, 1,764, 1,216; max 32; mean 2.121; last-resort programs 0; a lossy last write to an output register in 224,724 (83.5 percent); register-set collapse 0. Of the ten lowest (148927 at 0.9811, 228763 at 0.9820, 638990 at 0.9879, 122960, 130488, 150347, 19921, 29307, 623492 at 0.9921, 34501), seven are measured live and at 2^20 (two concentrate live: 122960 a hot set, 29307 a single hot item; five are clean live, the floor's false refusals) and three surfaced after the 23:50 count (228763, 638990, 623492) and are queued live and at 2^20.
Cost of the selector: one chain draw per try (about 3 s of one core: the accepted attempt's 2^20 ratio pass dominates) plus a 256-unit ratio read (milliseconds). A seed-steering attacker who can choose among epoch seeds needs about 1,000 candidate seeds per seed under 0.9980, where the live hot-set rate was 7 of 25.
Row 90 (owner adv-accept-3, unspawned; claimed): the attempt loop, the cap and the last resort
Known-failed shape fired (box 2, 19:50 BST, adv-accept attempts --seed-start 2 --seeds 3 --force-exhaust,
log adv/attempts-plant.log): with every verdict read as a rejection the loop hits its cap and hands the
last-resort program, which the tool prints and re-checks. The three last-resort programs (cap 8 under the
plant): every or, mul and mulhi rewritten to xor (op mix xor 17 to 19, load 16, 0 lossy ops, 8 registers
written), and the real rule accepts each one as drawn (distinct mean 127.86 to 128.00, 0 saturated, bias
max 58 to 66). Reading: the last resort is predictable (a deterministic function of attempt 256's draw) and
is NOT weak by the rule's own measures; it is a program with no lossy op at all, which the live hot-set
measure has not yet been run on (owed). The 20k-seed census of real attempts (per-part rejections, cap
reached, P(exhaust)) is running (attempts-20k.log); its numbers land here.
The defender's question 3: the concentration at the acceptance's own 2^20 sample (box 2, 20:4x BST)
adv-accept gap --seeds 100767,100211,100064,100159,100629,2,3664 (lease 32, log logs/adv-accept/gap-rep8.log
when it ends): per site, over the rule's own 4,096 units x 32 lanes x 8 iterations = 2^20 random-nonce
evaluations, the share of the site's reads that land on word indices read 8 or more times (a uniform site on
a 2^26-word window repeats an index 2 or 3 times at most, so this share is 0.000 percent for a clean site).
| Program | the low site | distinct-index ratio closed / live | reads on indices read >= 8 times, closed / live | every other site |
|---|---|---|---|---|
| 100767 (the exemplar) | site 6 (instr 23, r6) | 0.9919 / 0.9920 | 0.168% / 0.151% | 0.000% |
| 100211 | site 9 (instr 31) | 0.9907 / 0.9908 | 0.186% / 0.179% | 0.000% |
| 100064 | min site 0.9832 / 0.9831 | under 0.01% at every site | ||
| 100159 | min site 0.9834 / 0.9832 | under 0.01% at every site | ||
| 100629 | min site 0.9834 / 0.9834 | under 0.01% at every site | ||
| 2 (control) | none under 0.9999 | 0.000% everywhere | ||
| 3664 (the lowest 256-unit read, 0.9945) | min site 6 at 0.9944 / 0.9943 | under 0.01% | its 256-unit read was not noise: the 2^20 ratio agrees |
All seven done (log logs/adv-accept/gap-rep8.log). Two of the seven carry a site with over 0.1 percent of its reads on heavily repeated indices (100767 site 6, 100211 site 9); the other low-ratio programs reach 0.983 at 2^20 through spread repeats under 0.01 percent per site, a different shape: a site that is slightly less than uniform everywhere rather than one hot image.
So the concentration the sequential 2^24 run shows (site 6 putting 3.35 percent of its reads into the top 0.1 percent of ITEMS, 17k items) appears at the acceptance's own random-nonce sample as 0.17 percent of site 6's reads on heavily repeated WORD indices and a ratio of 0.9919: the two readings agree once items (16 words each, 2^24 of them) are told from words (2^28), and the rule's sample does see it; its floor at 0.98 is set below it.
Two mechanisms, not one (sibling input from adv-cache-2, 23:1x BST, and this lane's check)
adv-cache-2 reports (their measurement, not re-run here) a mechanism for the mild biased-site class: with
load_index = rotl(x * M, R) then the 28-bit mask and an odd M, the low bits of the product are a
function of the low bits of x alone, so a source whose low bits carry a product's law (P(bit 0) = 1/4, bit 1
3/8, bit 2 7/16, measured on Devnet 3 site 0 and their era-drawn-10 site 7) carries that bias into address
bits R, R+1, R+2; with R = 29 (the devnet era) those bits sit above the mask and vanish, with R in 1..27 they
land in the item index. Their controlled pair (one base program under two eras) reads 1.00x to 1.01x under
R = 29 and 1.06x to 1.51x under R of 3 to 22; 5 of their 50 programs read over 1.2x at one site.
This lane's check, from the era line each live run prints (logs in logs/adv-accept/):
| Live verdict | seeds and their era rotation R |
|---|---|
| hot set by X_f >= f (8) | 100767 R 28, 4346 R 19, 5245 R 29, 1738 R 29, 170 R 29, 106924 R 11, 107022 R 30, 122960 R 10 |
| beyond the gate, no hot set (10) | R = 31, 9, 7, 2, 10, 5, 28, 27, 25, 5 |
| clean low-ratio seeds (6) | R = 3, 24, 1, 4, 9, 28 |
| random clean (17) | R = 27, 14, 1, 13, 30, 5, 21, 29, 1, 18, 20, 27, 9, 25, 4, 11, 17 |
adv-cache-2's correction (23:2x BST): rotl by R sends product bit b to address bit (b + R) mod 32, so the 28-bit mask cuts product bits 28 - R to 31 - R; R of 28, 29 and 30 cut the biased bits 0 to 2 (R = 31 keeps bit 1 at address bit 0), and R in 1..27 keeps them inside the index, so 28 of 31 rotations let the law through; the devnet era's R = 29 is a lucky one (its 32 programs read clean against 8 of 20 drawn-era programs with a site over 1.04x). They also name a second sub-class: a warp-uniform source (a high product of two small words is 0 in every lane and the shuffles keep the lanes equal) at about one warp in 16,000, which reads as one item taken 512 times by 16 whole warps (their era-fixed-20 and era-drawn-20, site 11, 1.22x to 1.26x); the rule's lane-constant test (c) runs 64 units and cannot see a 1-in-16,000 event. Their new seed: era-drawn-17 (epoch "igneum-adv-cache-2/epoch/17", era ".../era/17", R = 11, attempt 1, id 5d2d50b934b23e2d), site 0 at 1.21x. Chip gain of both sub-classes: nil (0.05 percent of a hash's reads).
Reading: five of the eight hot sets carry R of 28 to 30, where the product-law bits are cut by the mask, so
the hot-set class is not adv-cache-2's mechanism. It is the near-saturated-source class: a source that
reaches zero or all-ones maps to ONE item whatever M and R (zero gives index 0: item 0x000000 is the hottest
in 100767, 4346, 5245 and 170; all-ones gives the fixed image of -M), and that is why these programs
concentrate hundreds of thousands of reads on a few items where the product-law class spreads a 1.1x to 1.5x
excess over a window. The two live-clean shapes (106924 at R 11, 107022 at R 30) are a third, smaller
set with neither signature traced. For the rule: the per-site distinct-index ratio catches the first class
(0.9821 to 0.9919 at 2^20, all refused by 0.995) and misses the second (0.9992 to 0.9997); the second class
is the stride's and is what a change to load_index (R restricted, or the low product bits folded) would
address, not a floor.
The class v5 floor at 0.995 against the measured concentrations (main's five-program job, box 2, 21:35 BST)
adv-accept gap --day 20733 --hex <devnet3>:<devnet3>:devnet3-epoch0-v4 and adv-accept gap --day 20730 --seeds 4346,5245,106924,107022 --hex <era-fixed-20> --hex <era-drawn-2>, each through lease pool 8 --min 4 (logs logs/adv-accept/gap-five-d20733.log, gap-five-d20730.log, gap-hot2.log). The minimum per-site
distinct-index ratio at the acceptance's own 2^20 sample, against the class v5 floor (c''') of 0.995:
| Program | id, attempt | min site | ratio closed / live | against 0.995 | live concentration measured |
|---|---|---|---|---|---|
| seed 4346 (this lane) | bbb38e847011c354, 2 | 2 (instr 19) | 0.9840 / 0.9839 | refused | hot set, X_0.1% +0.178%, 2.24x |
| seed 5245 | beaad44840bb9e4e, 5 | 8 (instr 37) | 0.9831 / 0.9833 | refused | hot set, +0.129%, 1.86x |
| seed 106924 | 8aa3c604dba9d11b, 1 | 10 (instr 45) | 0.9821 / 0.9823 | refused | hot set, +0.221%, 2.21x (the second shape) |
| seed 107022 | 0fd1d15a8bd627d4, 1 | 10 (instr 44) | 0.9877 / 0.9876 | refused | hot set, +0.138%, 1.82x (the second shape) |
| seed 100767 (earlier read) | 9d68e6286fc817d4, 2 | 6 (instr 23) | 0.9919 / 0.9920 | refused | hot set, +0.155%, 2.05x |
| seed 1738 (gap-hot3.log, build-1, 21:37 BST) | 33ece54e2df5ea44, 4 | 13 (instr 54) | 0.9868 / 0.9870 | refused | hot set, +0.102%, 1.68x |
| seed 170 (gap-hot4.log, build-1, 21:48 BST) | 53a02a7c9c9b86f3, 4 | 2 (instr 11) | 0.9880 / 0.9877 | refused | hot set, +0.143%, 2.02x |
| seed 122960 (gap-122960.log, build-2, 22:41 BST; the deepest tail seed) | 4be7393ab6c84802, 0 | 12 (instr 45, src r6, full window) | 0.9824 / 0.9822; 1.31% of the site's reads on indices read 8 or more times | refused | hot set, +0.111%, 1.54x; hottest item 0.022% of all reads |
| seed 130488 (gap-newlow5.log, box 2, 23:08 BST) | 24d5e6511a1b83dc | 5 | 0.9898 | refused | CLEAN live: 1.0002x, X_0.1% +0.000% (a false refusal) |
| seed 19921 | fe35af21bc43a4cc | 4 | 0.9912 | refused | CLEAN live: 1.0005x (a false refusal) |
| seed 600738 | ef6d49f3871af472 | 8 | 0.9934 | refused | CLEAN live: 1.0002x (a false refusal) |
| seed 602822 | d8b5571c7abc80df | 3 | 0.9951 | at or above 0.995: passes | CLEAN live: 1.0003x (a true pass) |
| seed 148927 (gap-deep4.log, box 2, 23:23 BST; the lowest 256-unit read of 143,734) | c789fe5789ea71f0 | 0 | 0.9814 | refused | CLEAN live: 1.0028x (a false refusal) |
| seed 150347 | 23bc0a65fff5682b | 3 | 0.9896 | refused | CLEAN live: 1.0000x (a false refusal) |
| seed 34501 | 8b048a553cb6de4c | 0 | 0.9929 | refused | CLEAN live: 0.9998x (a false refusal) |
| seed 29307 | 0243919aa1b29078 | 1 (instr 3, src r3) | 0.9912 | refused | beyond the gate at 1.29x, no hot set by X_f; one item takes 0.027% of all reads (the third shape) |
| seed 228763 (gap-tail3.log, box 2, 01:12 BST) | 2c4be0f6dc44c423 | 9 (instr 32, src r0) | 0.9809 (the lowest minimum site of the pass) | refused | HOT SET, +0.118%, 1.82x; one item takes 0.057% of all reads (the third shape at scale) |
| seed 638990 | 682d8a67caf20d92 | 2 (instr 15, src r0) | 0.9872 | refused | beyond at 1.51x, no hot set; one item at 0.027% (the third shape) |
| seed 623492 | 283fa56f84e945f7 | 0 | 0.9922 | refused | CLEAN live: 1.0002x (a false refusal) |
| Devnet 3 epoch 0, class v4 | fce15bf61030be57, 0 (day 20733) | 0 (instr 3, src r6) | 0.9992 / 0.9993 | AT OR ABOVE: a residual the floor misses | adv-cache-2: site 0 bit law P(bit 0..2 = 1) = 0.250 / 0.375 / 0.4375, chi2/dof 3.70 at 2^26 |
| adv-cache-2 era-fixed-20 | 11f9f955b21d56c9, 1 | 11 (instr 46) | 0.9997 / 0.9997 | AT OR ABOVE: a residual | adv-cache-2: top 0.1% 1.26x its window control, one item read 512 times |
| adv-cache-2 era-drawn-2 | 7ceb797d31eedb3e, 0 | 13 (instr 55) | 0.9992 / 0.9993 | AT OR ABOVE: a residual | adv-cache-2: chi2/dof 2.04, top 0.1% 1.27x |
Reading. The floor at 0.995 refuses every program whose live hot set passes the f8 test X_f >= f (all nine of this lane's, minimum sites 0.9809 to 0.9919) and both single-item programs (29307, 638990). It also refuses programs with NO live concentration: of the twelve deepest 256-unit seeds read at 2^20, seven (130488, 19921, 600738, 148927, 150347, 34501, 623492) read 0.9814 to 0.9934 at their minimum site and are clean on the live set (0.9998x to 1.0028x of the window model, X_0.1% at 0.000 percent), one (602822) passes at 0.9951 and is clean, and four (122960, 29307, 228763, 638990) are refused and concentrate live. So the (c'') statistic, repeated word indices at one site over 2^20 random nonces, measures a stand-in deficiency that on the live set is usually spread thin (many indices read twice or three times, no item above the noise in the top 0.1 percent) and only sometimes a hot set; the six are the floor's false refusals, the population its 2.4 percent clean rejection rate pays, and each costs the chain one redraw and nothing else. The 256-unit proxy and the 2^20 read agree on these deep seeds (148927: 0.9811 and 0.9814), so the proxy's weakness at the extreme is not sampling noise but this: a low ratio is not a hot set. The floor does not reach the three milder concentrations (top 0.1 percent share 1.26x to 1.27x, chi2/dof 2 to 3.7) whose minimum site reads 0.9992 to 0.9997, inside the clean population's spread at 2^20 (clean median 0.9999, clean first percentile about 0.9993 over 29,032 programs). Devnet 3's own first program is one of those three. What those residuals are worth to a chip: a 1.26x share of the top 0.1 percent of items is 0.19 percent of reads on 1 MB against 0.15 expected, a gain of 1.0004x; they are distinguishers at the chi-square level, not hot sets, and no floor on the distinct-index ratio that keeps the clean rejection rate near 2.4 percent reaches them. The 1738 hot set's ratio (gap-hot3 on build-1) lands when its lease gets cores.
Row 90 result (owner adv-accept-3, unspawned; claimed by this lane): the attempt loop over 20,000 seeds (box 2, 23:22 and 01:33 BST)
adv-accept attempts --seed-start 2 --seeds 10000 and --seed-start 10002 --seeds 10000, each at
--threads 32 through lease pool 32 --min 16 (logs logs/adv-accept/attempts-10k-a.log and -b.log, rows
attempts-10k-a.txt and -b.txt): every candidate of every seed walked through the real rule, the first
failing part recorded; 940 s and 1,112 s on 32 cores. The two halves agree to a tenth of a percent on
every share, so the table carries their sum.
| Measure | Value (20,000 seeds; the halves in brackets) |
|---|---|
| Seeds, accepted, exhausted | 20,000, 20,000, 0 (cap 256) |
| Rejected candidates | 42,711 (21,119 and 21,592); per-candidate rejection probability 0.681 (0.6787, 0.6835) |
| Rejection by part, all candidates | (a') unfresh 83.5%, (a) stale 11.6%, (b) no injecting write 3.0%, (c'') low-entropy site 1.1% (459), (c) constant bit 0.4%, (c) saturated 0.3%, (c') saturated source 0.05%, (c) distinct addresses 0.04%, (c) lane-constant 0, (c) bias 0, (c'') repeated 0 (not wired) |
| Attempt 0 | 20,000 candidates, 13,507 rejected (67.5%) |
| Attempts 1, 2, 3 | 67.8%, 68.3%, 69.7% rejected: the per-attempt rate does not drift |
| Accepted-attempt histogram 0..11 | 6,493, 4,346, 2,901, 1,890, 1,411, 906, 648, 452, 284, 234, 141, 86; max 28 (one seed); mean 2.136 |
| P(256 consecutive rejections) if attempts are independent | 0.681^256 = 2e-43 |
| Closed-form distinct-item mean of the accepted programs | 127.95 of 128; minimum 123.67 (the floor is 120) |
Reading. Rule (a') does the work: five of six rejections are the dataflow freshness check at the draw's boundary, (a) and (b) one in seven, and the dynamic parts under 2 percent together, with (c'') the largest of them at 1.1 percent (238 candidates, the per-site floor at 0.98). The per-attempt rejection rate is flat at 68 percent across attempts 0 to 3, so attempts are independent draws and the cap of 256 is unreachable in practice (8e-44 per seed; the devnet at one epoch an hour would need 10^39 years). The last resort is therefore a path no chain reaches by chance; it is reachable only by a rule that rejects everything (the plant above), and what it hands over is a program with no lossy op that the rule accepts as drawn. For an attacker who steers the seed: the attempt index adds no freedom beyond the seed (each attempt is a fresh seed-word set), and the accepted attempt's distribution is the same for every seed, so nothing in the attempt scheme is a lever. Owner adv-accept-3 (unspawned); rows 91 and 92 are theirs.
Q2, the stand-in gap: first bound (box 2, 19:46 BST, adv-accept gap)
Tool: a mirror interpreter with per-site index capture, run on the rule's own base nonces (seed-keyed
acceptance stream) with init words = seed words, once on the closed-form dataset and once on the LIVE
memory-hard dataset (day 20730, the kit's day). Validation on every program: the mirror's 32 hashes equal
the library's hash_warp on 8 units on both datasets, and the mirror's closed-form per-site distinct counts
equal the library's distinct_indices_v4 on all 4096 units. Known-failed shape --plant zero-dataset
(every live word 0): live min ratio 0.9733, verdict live REJECT against closed accept, live distinct
mean 115.99 against 128.00: the tool reports a gap when there is one. Logs adv/gap-plant.log, gap-first.log.
| Seed | id | min per-site ratio closed (2^20) | min live (2^20) | largest site gap | (c) on 64 units: distinct mean, saturated, bias max (closed / live) | verdict closed / live |
|---|---|---|---|---|---|---|
| 100767 (the finding) | 9d68e6286fc817d4 | 0.9919 | 0.9920 | +0.0002 | 127.714, 0, 82 / 127.730, 1, 53 | accept / accept |
| 2 (control) | 8a0047b2eb071ade | 0.9999 | 0.9999 | -0.0002 | 128.000, 1, 56 / 128.000, 0, 57 | accept / accept |
| 100211 | d07885a437e237c7 | 0.9907 | 0.9908 | +0.0002 | 128.000, 0, 61 / 128.000, 0, 57 | accept / accept |
| 100064 | 2442abf9d56f6611 | 0.9832 | 0.9831 | +0.0002 | 128.000, 11, 64 / 128.000, 6, 51 | accept / accept |
Reading. The per-site index distribution is set by the program and the register init, and the dataset words it folds in act as fresh randomness on both sides: the closed form and the live set give the same ratio to 2 parts in 10,000 at 2^20 evaluations, and the same (c) verdicts. No stand-in gap to steer into on these four. Also: the cheap 256-unit proxy did rank real tail programs, and 100064 sits 0.0032 above the 0.98 floor at 2^20, so the floor is live in the population tail, not idle.
Q2 BOUND over 50 consecutive accepted programs (seeds 3..52, box 2, 20:0x BST, adv-accept gap --seeds 3,...,52 --threads 32, log logs/adv-accept/gap-50.log; about 10 s per program):
| Measure over 50 programs, 800 site rows, 2^20 evaluations per site | Value |
|---|---|
| Largest closed-vs-live gap in any site's distinct-index ratio | 0.0004 |
| Mean of (closed min ratio - live min ratio) | 0.00002 |
| Verdict disagreements under the 0.98 floor | 0 of 50 (min closed 0.9927, min live 0.9928) |
| (c) on 64 units: largest closed-vs-live gap in distinct mean per hash | 0.019 of 128 |
| (c) saturated finals: sum of (closed - live) over 50 | -21 of 16,384 x 50 (noise about the 0 line) |
| Either side over the saturation limit (164) or the bias limit (136) | 0 |
Bound: on 54 accepted programs the stand-in and the live dataset agree on every verdict and on every per-site ratio to 4 parts in 10,000, which is the sampling noise of a 2^20 draw (one standard deviation of the distinct count is about 90 of 1,040,000, or 0.0001 in the ratio). The threshold-edge disagreements the spec reports (39 in 100,000) are consistent with this spread; a program would have to sit within 0.0004 of the floor for the two sides to disagree, and nothing an attacker chooses moves the live side away from the closed side by more than that, because the words folded in are uniform on both. Steering through the gap is not available. What a longer pass adds: more programs near the floor to count the edge cases, which the sweep's ratio column already locates (rows under 0.9810 at 256 units, then a 2^20 gap read on each).
Widened live confirmation: the 20 lowest and 20 random (RUNNING, 2^24 nonces each)
- box 1, 19:5x BST:
adv-live warps --program k --nonces 16777216 --threads 48 --diag 1for the 20 lowest stand-in-ratio seeds of the 16,337 (3664, 103378, 105756, 6610, 106474, 4765, 106700, 4346, 5245, 101905, 1605, 1738, 105371, 6842, 838, 3387, 103265, 170, 106924, 107022; ratios 0.9945 to 0.9980), log live-low20-16m.log. This row answers the defender's false-positive question: of the lowest 20 (plus the five already confirmed), how many are NOT beyond 1.2x live. - box 2, 19:5x BST: the same at 32 threads for 20 random accepted seeds (4107, 101710, 101886, 6132, 105915, 5133, 1932, 2328, 3665, 101643, 1352, 100521, 106359, 4905, 102519, 101697, 106740, 327, 1180, 101805; ratios 0.9994 to 0.9999), log live-random20-16m.log: the control for the correlation.
| Seed | stand-in ratio (256 u) | live top 0.1% over window model | X_0.1% (X/f) | hot set |
|---|---|---|---|---|
| 3664 (lowest of 16,337) | 0.9945 | 1.311x BEYOND | +0.074% (0.74) | clear |
| 103378 | 0.9960 | 1.157x within | +0.028% (0.28) | clear |
| 105756 | 0.9960 | 0.9996x within | -0.000% (0.00) | clear |
| 6610 | 0.9960 | 1.062x within | +0.010% (0.10) | clear |
| 106474 | 0.9960 | 0.9996x within | -0.000% (0.00) | clear |
| 4765 | 0.9960 | 1.020x within | +0.003% (0.03) | clear |
| 106700 | 0.9960 | 1.0006x within | +0.000% (0.00) | clear |
| 4346 | 0.9968 | 2.241x BEYOND | +0.178% (1.78) | HOT SET |
| 5245 | 0.9970 | 1.857x BEYOND | +0.129% (1.29) | HOT SET |
| 101905 | 0.9973 | 1.336x BEYOND | +0.050% (0.50) | clear |
| 1605 | 0.9976 | 1.367x BEYOND | +0.054% (0.54) | clear |
| 1738 | 0.9977 | 1.678x BEYOND | +0.102% (1.02) | HOT SET |
| 105371 | 0.9977 | 1.369x BEYOND | +0.070% (0.70) | clear |
| 6842 | 0.9979 | 1.205x BEYOND | +0.036% (0.36) | clear |
| 838 | 0.9979 | 1.331x BEYOND | +0.054% (0.54) | clear |
| 327 (random) | 0.9999 | 1.0000x within | +0.000% | clear |
| 1180 (random) | 0.9999 | 1.0008x within | +0.000% | clear |
| 101805 (random) | 0.9999 | 1.046x within | +0.009% | clear |
Tally at 21:17 BST, 20 random rows complete and 20 of the lowest 25 measured, all at 2^24 nonces:
| Set | n | beyond the f8 1.2x gate | hot set (X_f >= f) |
|---|---|---|---|
| lowest stand-in-ratio seeds (the selector) | 20 | 13 (65%) | 4 (100767, 4346, 5245, 1738) |
| random accepted seeds (the control) | 20 | 1 (5%) | 0 |
Selector enrichment 13x on the gate (65 against 5 percent, binomial error about 11 points at n = 20) and 4 of 20 against 0 of 20 on the hot-set test. The false-positive rate of the 256-unit selector against the gate is 7 of 20.
The chain's last six (21:27 BST), completing the lowest 25:
| Seed | stand-in ratio (256 u) | live top 0.1% over window model | X_0.1% (X/f) | hot set |
|---|---|---|---|---|
| 3387 | 0.9979 | 1.670x BEYOND | +0.092% (0.92) | clear |
| 103265 | 0.9980 | 1.2000x at the gate (within) | +0.035% (0.35) | clear |
| 170 | 0.9980 | 2.016x BEYOND | +0.143% (1.43) | HOT SET |
| 106924 | 0.9980 | 2.208x BEYOND | +0.221% (2.21) | HOT SET |
| 107022 | 0.9980 | 1.816x BEYOND | +0.138% (1.38) | HOT SET |
| 100629 (re-read at 2^24) | 0.9987 | 1.119x within | +0.018% (0.18) | clear |
Final tally at 2^24 nonces (21:30 BST):
| Set | n | beyond the f8 1.2x gate | hot set (X_f >= f) | largest X_0.1% |
|---|---|---|---|---|
| lowest 25 stand-in-ratio seeds of 29,032 (the selector) | 25 | 17 (68%) | 7 (100767, 4346, 5245, 1738, 170, 106924, 107022) | +0.221% (106924) |
| random accepted seeds (the control) | 20 | 1 (5%) | 0 | +0.065% (105915) |
The five lowest of the 88,051 (box 2, 22:05 BST, 2^24 nonces, --diag 1, log live-newlow5-16m.log):
| Seed | stand-in ratio (256 u) | live top 0.1% over window model | X_0.1% (X/f) | hot set |
|---|---|---|---|---|
| 122960 (the lowest of 88,051) | 0.9885 | 1.543x BEYOND | +0.111% (1.11) | HOT SET |
| 130488 | 0.9890 | 1.0002x within | +0.000% | clear |
| 19921 | 0.9914 | 1.0005x within | +0.000% | clear |
| 600738 | 0.9930 | 1.0002x within | +0.000% | clear |
| 602822 | 0.9942 | 1.0003x within | +0.000% | clear |
Seed 122960 (id 4be7393ab6c84802): the hot 0.1 percent (19,159 items) holds 0.343 percent of reads; its hottest item 0x81ad88 takes 475,616 reads, 0.022 percent of all reads from one item, 16 times the hottest item of 100767; traced to site instr 4 reading r4 = all-ones, last writer shfl@3; site 12 (instr 45, src r6, full window) sends 2.17 percent of its reads into the hot set with a saturated-source share of 0.353 percent, a third of the (c') 1 percent limit, the closest to that limit seen. The other four lowest by the 256-unit read are clean live (1.0002x to 1.0005x), so the 256-unit proxy is noise at its own extreme: the 2^20 ratio the rule computes is the real selector (their 2^20 reads are in the floor table when they land).
The four lowest of the 143,734 not yet measured (box 2, 23:19 BST, 2^24 nonces, --diag 1, log live-deep4-16m.log):
| Seed | stand-in ratio (256 u) | live top 0.1% over window model | X_0.1% (X/f) | hot set | note |
|---|---|---|---|---|---|
| 148927 (the lowest of 143,734) | 0.9811 | 1.0028x within | +0.000% | clear | clean live |
| 150347 | 0.9897 | 1.0000x within | -0.000% | clear | clean live |
| 29307 | 0.9914 | 1.291x BEYOND | +0.055% (0.55) | clear | hottest item 0x349d07 takes 579,069 reads, 0.027% of ALL reads, the largest single item of the night; no saturated or one-bit source maps to it; site 1 (instr 3, src r3, full window) 0.99% of its reads into the hot set |
| 34501 | 0.9929 | 0.9998x within | -0.000% | clear | clean live |
Seed 29307 is a third shape: one item takes 0.027 percent of all reads from a source that is neither zero, all-ones nor one bit off either, and the rest of the program is uniform, so the f8 test (which asks for a 0.1 percent SET) does not fire while the gate does. For a chip it is one 64-byte item, worth 0.027 percent of DRAM reads: nothing. For the rule it is the shape the per-site ratio reads most cheaply (one value repeated 579k times in 2^24 x 8 evaluations at one site), and its 2^20 ratio is in the queued gap read.
The three tail seeds that surfaced after the 23:50 count (box 2, 01:11 BST, 2^24 nonces, --diag 1, log live-tail3-16m.log):
| Seed | stand-in ratio (256 u) | live top 0.1% over window model | X_0.1% (X/f) | hot set | note |
|---|---|---|---|---|---|
| 228763 | 0.9820 | 1.820x BEYOND | +0.118% (1.18) | HOT SET | the ninth; hottest item 0xe2cc96 takes 1,218,380 reads, 0.057% of ALL reads, the largest single item of the pass (40x 100767's); no saturated or one-bit source maps to it; site 9 (instr 32, src r0, half window) 2.19% of its reads into the hot set, saturated-source share 0.000% |
| 638990 | 0.9879 | 1.506x BEYOND | +0.079% (0.79) | clear | one item 0xa67942 takes 581,502 reads (0.027% of all), the third shape again; site 2 (instr 15, src r0, quarter window) 1.84% |
| 623492 | 0.9921 | 1.0002x within | +0.000% | clear | clean live |
The third shape now has three members (29307, 638990, 228763): one item taking 0.03 to 0.06 percent of all
reads from a source that is neither zero nor all-ones nor one bit off, twice from a load reading r0 (the
register the iteration samples as sel), with the rest of the program uniform. For a chip it is one
64-byte item; for the rule it is one repeated index at one site, which the 2^20 ratio reads (29307 at
0.9912; the two new ones are in the gap-tail3 read).
So the stand-in tail is where the live hot sets live: 7 of 25 against 0 of 20 (the binomial error at n = 20 puts the control's rate under 15 percent), 8 of 30 with the five deepest, 8 of 34 with the four deepest of 143,734, and 9 of 37 with the three that surfaced in the 269,250; the 256-unit proxy below 0.995 is as often clean as hot (six of the twelve deepest reads are clean). Every hot set is of the same size class: the top 0.1 percent of items (about 1 MB) holding 0.28 to 0.37 percent of reads against 0.15 expected. Gain to a chip holding that 1 MB on die: 1.002x at the largest. The selector's false-positive rate against the gate: 8 of 25.
Reading at 21:1x BST (the re-submitted chain's first four, build-1, 2^24 nonces, --diag 1): two more hot sets. The lowest-16 live set now reads 9 beyond the f8 gate of 16 (56 percent) and 3 hot sets by X_f >= f (100767, 4346, 5245) against 1 beyond of 17 random and 0 hot sets; the hot-set rate among the stand-in tail is 3 of 16 against 0 of 17. Seed 4346's excess (+0.178 percent at f = 0.1 percent) is the largest seen: still a 1 MB item set holding about 0.33 percent of reads, gain about 1.002x. The distinguisher is real and repeatable; its price does not move.
Attribution of the two new hot sets (log live-low14-16m.log, copied to logs/adv-accept/ at the chain's end):
| Seed, id, attempt | hot items (top 0.1%) and their reads | hottest item and traced source | sites carrying it |
|---|---|---|---|
| 4346, bbb38e847011c354, attempt 2 | 17,103 items, 0.326% of reads | 0x000000 with 97,943 reads (0.0046% of all); site instr 4 reads r4 = zero, last writer mad@1 | site 2 (instr 19, src r1, full window) puts 2.17% of its reads into the hot set; sites 8 and 9 (instrs 44 and 49) 0.67% each; largest saturated-source share 0.044% at site 2 |
| 5245, beaad44840bb9e4e, attempt 5 | 16,899 items, 0.281% of reads | 0x000000 with 47,936 reads (0.0022% of all); site instr 7 reads r2 = zero, last writer load@6 | site 8 (instr 37, src r2, quarter window) puts 3.36% of its reads into the hot set; the top 8 items are again multiples of 2^19 |
The same mechanism each time: one load site whose source register reaches zero (or a value near zero or all-ones) in a few hundredths of a percent of evaluations, under the (c') 1 percent limit, with the era stride mapping those values to a fixed item set; item 0x000000 is the hottest in all three programs.
The four hot sets of the chain's second half (same log), two of each shape:
| Seed, id, attempt | hot items (top 0.1%) and their reads | hottest item and traced source | the site | shape |
|---|---|---|---|---|
| 1738, 33ece54e2df5ea44, attempt 4 | 17,107 items, 0.256% of reads | 0xc00000, 38,597 reads; site instr 7 reads r3 one bit set, last writer load@6 | site 13 (instr 54, src r6, quarter window) 2.34% of its reads; saturated source 0.012% | near-saturated source |
| 170, 53a02a7c9c9b86f3, attempt 4 | 16,792 items, 0.285% | 0x000000, 37,780 reads; site instr 8 reads r2 = zero, last writer sub@6 | site 2 (instr 11, src r1, half window) 3.04%; saturated 0.016% | near-saturated source |
| 106924, 8aa3c604dba9d11b, attempt 1 | 16,951 items, 0.407% of reads (the largest) | 0x6e9c4c, 19,020 reads; NO saturated or one-bit source maps to it | site 10 (instr 45, src r4, full window) 4.70% of its reads; saturated source 0.000% | a second shape: a low-entropy source band that is not saturation |
| 107022, 0fd1d15a8bd627d4, attempt 1 | 16,782 items, 0.307% | 0xbd2a43, 24,317 reads; no saturated source maps to it | site 10 (instr 44, src r3, half window) 2.84%; saturated 0.000% | the second shape |
The second shape matters for the rule's design: in 106924 and 107022 the hot items are not the images of zero or all-ones, so the (c') saturated-source count reads 0.000 percent at the site and only the per-site distinct-index ratio (c'') sees them; a floor set on that ratio is the one instrument that catches both shapes. Their 2^20 ratios are in the gap reads below when they land. | 1352 (random) | 0.9999 | 1.057x within | +0.009% | clear | | 100521 (random) | 0.9999 | 1.153x within | +0.025% (0.25) | clear | | 106359 (random) | 0.9999 | 1.0001x within | +0.000% | clear | | 4905 (random) | 0.9999 | 1.012x within | +0.002% | clear | | 102519 (random) | 0.9999 | 0.9999x within | -0.000% | clear | | 4107 (random) | 0.9999 | 1.0004x within | +0.000% | clear | | 101710 (random) | 0.9998 | 1.0034x within | +0.001% | clear | | 101886 (random) | 0.9998 | 1.0000x within | +0.000% | clear | | 6132 (random) | 0.9999 | 0.9996x within | -0.000% | clear | | 105915 (random, the lowest ratio of the random 20) | 0.9994 | 1.399x BEYOND | +0.065% (0.65) | clear | | 5133 (random) | 0.9999 | 1.0215x within | +0.004% | clear | | 1932 (random) | 0.9999 | 1.0024x within | +0.000% | clear | | 2328 (random) | 0.9999 | 1.0025x within | +0.000% | clear | | 3665 (random) | 0.9998 | 1.0002x within | +0.000% | clear | | 101643 (random) | 0.9999 | 1.0017x within | +0.000% | clear | | (17 lowest and 10 random rows land as the runs end, 20:2x BST) | | | | |
Base rate, corrected at 20:20 BST: at 2^24 nonces the f8 gate fires on random accepted programs too. Of the first 10 random seeds, 1 (105915) is beyond 1.2x at 1.40x, and it is the one with the lowest stand-in ratio of the random set (0.9994 against 0.9998 to 0.9999 for the other nine). So "beyond 1.2x at 2^24" has a base rate near 1 in 10 among accepted programs (the 10^6-nonce census read 0 of 47 beyond because the gate is sharper at 2^24), and the selector's 6 of 8 is an enrichment of about 6x over that base rate, not a clean separation. The hot-set test proper (X_f >= f) has fired on 1 of 18 programs measured at 2^24 (100767).
Reading at 20:25 BST (final for tonight's rows; corrected: 100629 was within at 10^6, 1.011x), honestly: the 256-unit selector is weak. Of the 12 lowest-ratio seeds measured live (100211, 100064, 100767, 100159, 100629, then 3664, 103378, 105756, 6610, 106474, 4765, 106700), 5 are beyond the f8 1.2x gate and 7 are not; the random control is 1 of 11 beyond (105915 at 1.40x). The five that are beyond are four of the first five (256-unit ratios 0.9986 to 0.9988, 2^20 ratios 0.9832 to 0.9919) and 3664 (0.9945); the seven that are not include five that sit LOWER on the 256-unit read (0.9960), which says the 256-unit read is noise-dominated at that level (one standard deviation of a 65,536-evaluation distinct count is about 0.001 in the ratio) and the real selector is the 2^20 ratio the rule itself computes (2.8 s per candidate: 100064's 0.9832, 100211's 0.9907 and 100767's 0.9919 are genuinely low; 3664's 2^20 ratio is in the re-queued gap read). So: selector enrichment about 4.6x over the base rate (42 percent beyond against 9 percent), false-positive rate 7 of 12 on the 256-unit read; the error on both is binomial at n = 12 and n = 11, about plus or minus 14 points. The hot-set test proper (X_f >= f) fired on 1 of 22 programs measured at 2^24 (100767), and on none of the 11 random.
Confirming row for the class v5 acceptance floor (c'''): pre-floor draw against post-floor refusal (box 2, 20:36 BST)
Not a class v5 finding. Does seed 100767 (id 9d68e6286fc817d4 under class v4) still read hot when the dataset is class v5's state-derived one? Tool: tools/attack/adv-accept-v5 (the same f8 harness over the vendored igneum-pow of branch class-v5 at 25c8063f, read-only input, which is the class v5 crate BEFORE commit ab6f980b: it has no per-site floor (c''') yet). Under that pre-floor crate the class v5 draw of the seed lands on attempt 2, id 2fd83dbae09c366d, the same base program and era as the v4 id. Under the frozen class v5 rule (ab6f980b and later) the defender reports the same seed is REFUSED at attempt 2 by the new per-site floor (c'''), which names site 6 at 0.991, and the v5 draw lands on attempt 4, id 734fbb8e3e4cd20f (stated by the class v5 lane; not derived here). So this row measures the pre-floor program on the v5 dataset and shows what the floor was built to refuse: generator 5; the dataset XORs the window's state leaf into every item before the first mixer. State stream: the Devnet 3 v5 pack's state.igsd1 (inputs/v5-dn3-epoch0-state.igsd1, 11 records, root 7e37a9fb...a311, leaves fnv f141bfee2a8b11b0), the only public state stream. Commands, through the lease pool (lease 32, 16 cores taken), log logs/adv-accept/v5-exemplar.log:
adv-live-v5 warps --program 100767 --nonces 1000000 --plant const-item --state <stream> (known-failed shape)
adv-live-v5 warps --program 100767 --nonces 16777216 --diag 1 --validate sample --state <stream>
| Measure | class v4 (live-confirm-16m.log) | class v5 with the state leaves | plant (const-item, 10^6) |
|---|---|---|---|
| Hash agreement with the library's Epoch::hash_warp | 0 mismatches | 589 warps, 0 mismatches | skipped under the plant |
| Hot-set test f = 0.1% | X_f +0.15503%, X/f 1.55, HOT SET | X_f +0.15514%, X/f 1.55, HOT SET | X_f +6.32%, X/f 63 |
| Top 0.1% share over the window model | 2.0455x | 2.0462x | 25.7x |
| Windowed 6-sigma, largest 64-item bucket | +294.8 | +298.3 | +332,226 |
| Hot items (top 0.1%) and their reads | 17,034 items, 0.3064% of reads | 17,086 items, 0.3071% of reads | |
| Top 8 items | 0x000000 (29,355), 0x200000, 0x300000, 0x180000, 0x100000, 0x080000, 0x380000, 0x0c0000 | the same eight: 0x000000 (29,722), 0x200000, 0x300000, 0x180000, 0x100000, 0x0c0000, 0x080000, 0x380000 | 0x001234 (the plant) |
| Site attribution | site 6 3.350%, site 7 0.414% | site 6 3.358%, site 7 0.415% | |
| Hottest item's traced source | site instr 6, r6 = zero, writer mad@4 | the same |
Reading. The state leaf changes every dataset WORD, and the hot set does not move by a part in a thousand: the concentration is a property of the program's register dataflow at site 6 (r6 reaching zero through the mad at instruction 4 in about 0.013 percent of evaluations, then the era stride mapping small values to items at multiples of 2^19), not of the dataset's values. Any dataset keyed the same way through the same load address function inherits it. So the class v5 change does not touch this finding; what would is a rule on the program (the (c') saturation limit at 1 percent sits 80x above this program's 0.013 percent, and the 0.98 per-site floor sits 0.012 below its 0.9919) or a load address that does not map small sources to a fixed item set. Price unchanged: 1 MB of on-die items serves 0.31 percent of loads, gain 1.002x, no row of chip-model-v3.md moves under either class.
Rule change 19:55 BST (box-hours honesty)
The bounded class became 88 cores per box in total across all lanes: no new sweep starts except under the
per-box lock flock /srv/builds/_adv/locks/sweep.lock, one sweep per box at a time; the running shards 00
and 01 finish as they are; my adv-live confirmations and the row-90 census count against the ceiling, so
nothing new starts until they end. Shards 02 to 09, the class-v5 check and any re-run go through the lock.
Live hot-set census (RUNNING)
- box 2, 19:5x BST:
adv-live census --programs 2..201 --nonces 1000000 --threads 32(200 consecutive accepted programs of shard 00's range: the random sample), log adv/live-census-s00-2-201.log. - box 1, 19:5x BST:
adv-live warps --program k --nonces 1000000for the five lowest-ratio shard-01 seeds, log adv/live-lowratio-s01.log.
Ledger: the kill of 20:21 BST and the re-queue through the lease
Main's rule (relayed 20:2x BST): no sweep, census or verdict run on a box except through the build-server
lane's lease pool <threads> -- cmd (landing within the quarter hour); hand-started binaries killed by their
pid files now, not left to finish; release builds and the class v5 suites outrank every sweep tonight.
| Run | Box | Killed at (UK) | Reached | Lost | Re-queue |
|---|---|---|---|---|---|
| sweep shard 00 (seeds 3847..) | build-2 | 20:21:20 | 7,944 rows (plus 3,812 of part 0) | the rest of the shard | lease pool, from the frontier seed |
| sweep shard 01 (seeds 104649..) | build-1 | 20:21:13 | 6,943 rows (plus 4,622 of part 0) | the rest of the shard | lease pool, from the frontier seed |
| live census, 10^6 nonces, programs 2..201 | build-2 | 20:21:18 | 51 programs (32 in the mirror copy, 19 after) | programs 53..201 | lease pool |
| 20 lowest at 2^24 | build-1 | 20:21:12 | 6 of 20 | 14 rows | lease pool |
| 20 random at 2^24 | build-2 | 20:21:19 | 11 of 20 | 9 rows | lease pool |
| row 90 attempts census, 20k seeds | build-2 | 20:21:17 | no summary (prints at the end) | the whole run | lease pool, with progress lines added first |
| class v5 exemplar (queue 10), repeated-index read (queue 11) | build-2 | 20:21:52 | never ran (waiting on the sweep lock) | nothing | lease pool |
Accepted programs in hand after the kill: 23,319 distinct seeds (11,755 of shard 00 up to seed 11829; 11,564 of shard 01 up to 111630; 138 seeds in flight at the kills are gaps below the frontiers). Every partial row above stays in this report as partial. Box-hours running before the kill: about 2.9.
Re-queue through lease pool (live on both boxes from 20:22 BST; every lease at most 48 cores, --min 16;
the pool rule: release builds and the class v5 suites outrank every sweep, and a waiter labelled "v5 gate"
or "v5 kit" means finish the shard in hand and release):
| Order | Run | Box | Queued (UK) | Lease |
|---|---|---|---|---|
| 1 | 14 remaining lowest-ratio seeds plus 100629, 2^24, --diag 1 | build-1 | 20:25:04 | 48 / min 16 |
| 1 | 9 remaining random seeds, 2^24 | build-2 | 20:25:11 | 32 / 16 |
| 2 | class v5 exemplar: const-item plant at 10^6, then 100767 at 2^24 with --diag 1, state = the Devnet 3 v5 pack's stream | build-2 | 20:25:11 | 32 / 16 |
| 3 | repeated-index gap read (seeds 100767, 100211, 100064, 100159, 100629, 2, 3664) | build-2 | 20:25:11 | 32 / 16 |
| 4 | row 90 attempts census, 20k seeds (after the rebuild with progress lines) | build-1 | 20:27:12 | 48 / 16 |
| 5 | shard 00 from seed 11830 (88,172 seeds); shards 02, 04, 06, 08 | build-2 | 20:2x | 32 / 16 each |
| 5 | shard 01 from seed 111631 (88,371 seeds); shards 03, 05, 07, 09 | build-1 | 20:2x | 32 / 16 each |
At 20:25 BST the pool on build-2 had 0 free cores (adv-accept-3 and another lane ahead in the queue); my leases wait their turn. At 20:28 BST: all 15 of my leases wait with 0 free cores on both boxes (build-1: 12 leases of other lanes holding, 10 waiting; build-2: 3 holding, 11 waiting; load 100 and 89). Nothing of mine runs; the lease waits up to 2 h and then gives up, so a lease that never gets cores by 22:25 BST is re-queued again and says so here. The 00:00 BST reading carries the partial rows above if no cores free.
Yield rule widened at 20:3x BST: whenever lease status shows a waiter whose owner is class-v5 or whose
label contains "v5" (the v5 census is queued as "class v5 c3 census"), any run of mine HOLDING pool cores is
ended by its pgid file and re-queued at the back of the pool (a sweep from its frontier seed, its rows kept;
a live chain minus the programs already done). I do this by hand from the status polls; nothing changes
while my leases are waiters. Refined at 20:3x BST: the test is by OWNER: yield to a waiter whose owner is
class-v5, or whose owner is attack-pass with "v5" in its label; never to a waiter whose owner starts with
adv- (so my own "v5-exemplar" label and the sibling lanes' leases are not yield triggers).
Yield executed 20:41 BST on box 2 (the class v5 (c''') census, owner class-v5, 88 cores, waiting since 20:39 behind my leases): ended by pgid file live-random9-16m (6 of 9 done), gap-rep8 (7 of 7 done, nothing lost) and sweep-s02 (2,474 rows kept, frontier 202482); withdrawn by pid the four waiting shards and the re-queues made a moment earlier; box 2 then showed 0 holders and 0 waiters of mine at 20:41:38. By main's order I take no lease on box 2 until the census is confirmed running; the box-2 order then resumes (3 random seeds, shard 02 from 202482, shard 00 from 11830, shards 04/06/08). Build-1 unchanged.
Ranked lease (build-server lane, 20:40 BST, lease sha 5d84d644): classes release > v5 > measure > adv; an adv holder above 32 threads is pre-empted after a higher class has waited 120 s; holders at 32 or fewer never are; waiters started under the old tool are unranked. So at 20:42:52 BST on build-1 I killed my six old waiters by pgid file and re-submitted each once at 32 threads with --min 16 (the 14-seed live chain, row 90, shards 03/05/07/09); the holder sweep-s01b (32 cores, 2,134 rows at that moment) stays. No label of mine contains a promoted word; the "v5-exemplar" tag is retired (its run is complete) and any re-run will be tagged class5-exemplar.
20:44 BST: box 2 shows the class v5 census holding 48 of 88 pool cores since 20:41:55 (10 s after my release). My box-2 queue stayed withdrawn until the coordinator's word.
21:13 BST: box 2 opened to adv-* (the census ended, no pool lease there, load 11); the box-2 queue re-submitted through the ranked lease at 32/16 in order: the 3 remaining random seeds, shard 02 from 202482, shard 00 from 11830, shards 04/06/08. The yield stays mechanical: a class-v5 or attack-pass v5-labelled waiter means release at shard end unasked.
21:26 to 21:36 BST, clearances for the decisive 2^20 reads (main's five-program job and my 1738 read were starved behind my own shard holders): box 2, ended sweep-s00b (4,482 rows kept as part 1, frontier 16319) and withdrew the waiting shards, then ended sweep-s02 (9,642 rows kept, frontier 212128) and withdrew again, so gap-hot2 took 8 cores at 21:31 and the two five-program leases ran at 21:32 to 21:35; re-queued at 21:36: s02c from 212128, s00c from 16319, s04/06/08. Box 1, ended sweep-s05 (2,124 rows kept, frontier 502127) and withdrew attempts-20k and the shards, then ended sweep-s01b (27,131 rows kept as part 1, frontier 138766), re-queued s01c from 138766 plus attempts-20k, s05 from 502127, s03/07/09; gap-hot3 still waited at 21:36 (other lanes' adv waiters ahead by arrival). Every end was by pgid file; no rows were lost (every sweep writes its rows as they land); the inline-deletion rule of 21:33 BST touches nothing here (run-box.sh has no rm and no truncation inside a bash -c string; the clearances renamed logs with mv).
21:50 BST: build-1, ended sweep-s07 (6,076 rows kept as part 1, frontier 706081) so row 90 (attempts-20k, next of mine by arrival) can take cores before 00:00; the freed cores went to another lane's adv holder first, so attempts-20k still waits by arrival; s07b re-queued from 706081. Sweep rows on the boxes at 21:50: about 46,700 on build-1 and 36,400 on build-2 across all shard files (with the frontier overlaps of the re-launches), to be de-duplicated by seed for the 00:00 count.
21:54 BST: build-2, ended sweep-s06 (3,873 rows kept as part 1, frontier 603875) and withdrew the waiting s04 and s08 so the live hot-set chain on the five new lowest seeds of 88,051 (122960, 130488, 19921, 600738, 602822; stand-in ratios 0.9885 to 0.9942) queues ahead of them; s06b from 603875, s04 and s08 re-queued behind it. Build-1: the 2^20 ratio read of the same five queued at 8 cores, min 4 (gap-newlow5).
22:07 to 22:18 BST, box 2: the mechanical yield fired. At 22:08 an attack-pass "v5 gate" waiter (class v5)
appeared while I held three sweeps; main's order followed at 22:17 (the F8 gate on the frozen class v5 tip,
two halves of 32 at min 24, cannot start because the pool pre-empts only above 32 threads). Ended by pgid
file: sweep-s02c (9,406 rows kept, frontier 221536, ended 22:07 to make room for the 122960 read),
sweep-s00c (13,176 rows, frontier 29496), sweep-s06b (5,914 rows, frontier 609791), sweep-s04 (601 rows,
frontier 400603), sweep-s08 (no rows yet). Box 2 read 0 sweep holders of mine at 22:17:57 and both F8
halves held 32 and 30 cores. Kept on box 2: gap-122960 at 8 cores (the decisive 2^20 read of the deepest hot
set), queued at 22:06 and still waiting for cores at 22:18 (its first 600 s window passed with no DONE line;
a blank summary from that window is not a result and is not reported). The box-2 shards re-queue from their
frontiers once the halves finish. Rule from here, mechanical: on any box where lease status shows a class
v5 waiter, an adv-accept lease releases at its shard end whatever its size.
22:20 BST, build-1: the same rule fired there (9 class-v5 or v5-labelled attack-pass waiters). Ended by pgid file: sweep-s01c (11,842 rows kept, frontier 150610) and the row-90 census attempts-20k at 12,500 of 20,000 seeds (it writes its rows only at its end, so those seeds are lost and are re-run). Re-queued at 32/16: sweep-s01d from 150610, and the census as two halves of 10,000 (attempts-10k-a from seed 2, -b from 10002) so a future release keeps a half. Build-1 then read 0 sweep holders of mine.
22:21 BST rule (build-server lane, lease sha ce30e357): a release or v5 waiter that has waited 120 s
pre-empts adv holders at any size, oldest first, SIGTERM at the shard boundary; the lane re-queues the same
line. My sweeps already keep every row as it lands and re-queue from the frontier; the gap tool prints per
program (about 15 s each). The row-90 census wrote its rows only at its end, so it is changed (22:2x BST)
to write each accepted row as it lands and to print the running per-part rejection totals and the
accepted-attempt histogram at every 500-seed tick; the two queued halves were ended by pgid file before the
rebuild and are re-queued with the new binary (done 22:24 BST: attempts-10k-a from seed 2 and -b from
10002, 32/16 on build-1). The box-2 shards re-queue automatically from their recorded frontiers (s00 from
29496, s02 from 221536, s06 from 609791, s04 from 400603, s08 from 800002) the minute lease status on box 2
shows no class v5 lease or waiter.
22:43 BST, box 2: by main's allowance (one shard at 24 may run beside the two F8 halves) sweep-s00d started
from 29496 at 24 cores, min 16; the other four shards wait on a watcher that fires when the class v5 work
clears. Record of a slip: the loop that ended the earlier full-clearance watcher matched its own command
line (the grep pattern sat in it, the pgrep self-match class of the standing rules) and ended its own shell
before the start; the start was re-issued and verified by lease status (queued 22:43:59, 0 free at that
moment). Every lease of this lane holding or waiting on either box is re-queueable from its recorded
frontier; the frontiers file is /srv/builds/_adv-adv-accept/frontiers.txt on each box.
23:03 BST, box 2: the class v5 work cleared (the F8 halves done, no class-v5 lease or waiter) and the four remaining shards re-queued from their frontiers at 32/16: s02d from 221536, s06c from 609791, s04b from 400603, s08 from 800002; s00d (24 cores) had run beside the halves since 22:43.
23:05 BST, build-1: the pool held 11 attack-pass leases and my arrival order put four shards ahead of the two named deliverables (row 90's halves and the five new-lowest 2^20 ratios), so sweep-s09 was ended by pgid file (11,977 rows kept as part 1, frontier 911979) and the four shard waiters withdrawn, leaving gap-newlow5 and attempts-10k-a/-b as my only waiters there; the shards re-queued behind them (s09b from 911979, s05 from 502127, s03 from 300002, s07b from 706081, s01d from 150610).
23:07 BST: build-1's pool stayed held by attack-pass (the freed cores went to adv-cache-2 by arrival), so the two deliverables moved to box 2: gap-newlow5 (the five new-lowest 2^20 ratios, 8 cores) and attempts-10k-a (row 90's first half, 32 cores) took cores there at 23:07:30 after I ended sweep-s00d (9,617 rows kept as part 1, frontier 39114) and withdrew the four box-2 shard waiters; the box-2 shards re-queued behind them (s00e from 39114, s02d, s06c, s04b, s08 from their frontiers). Row 90's second half (attempts-10k-b) and the five build-1 shards wait on build-1.
23:10 to 23:12 BST, box 2: the four unmeasured deep-tail seeds (148927, 150347, 29307, 34501) queued as a 2^24 live chain (32/16) and a 2^20 read (8/4) ahead of my shard waiters (the four waiting shards withdrawn and re-queued behind); sweep-s00e then ended by pgid file (its rows kept as part 1, frontier recorded in frontiers.txt) so the chain takes cores; s00f re-queued from that frontier. The freed cores went to my own re-queued sweep-s02d by arrival, so at 23:12 it too was ended (343 rows kept, frontier 221880; s02e re-queued) and live-deep4 took 23 cores; gap-deep4 (8, min 4) waits beside it.
23:20 BST, box 2: the deep-4 live chain done (rows above); gap-deep4 still waited behind my own re-queued sweep-s00f, so s00f was ended (rows kept, frontier recorded; s00g re-queued) and gap-deep4 takes its cores. Record: row 90's first half on box 2 (attempts-10k-a, 8,000 of 10,000 at 23:20) runs box 2's binary from before the pre-emption-safe change (that rebuild went to build-1 only), so it prints progress without the running totals and writes its rows at its end; it is minutes from done and is left to finish; box 2 is rebuilt now for any later run (done 23:21 BST).
23:22 BST, box 2: the freed cores went to my re-queued sweep-s08 rather than gap-deep4 (the pool's order among adv waiters is not strictly by arrival), so every shard of mine on box 2 was ended or withdrawn (s08 at 346 rows, frontier 800349) until gap-deep4 held its 8 cores, then the five shards re-queued from their frontiers (s08 from 800349, s06c from 609791, s04b from 400603, s02e from 221880, s00g from 40822).
23:28 BST, box 2: the mechanical yield fired again (a class-v5 waiter, "c3 reading on listed programs", 16 cores, while my shards s08, s06c and s02e held cores). Ended by pgid file: s08 (2,894 rows kept, frontier 803254), s06c (2,055, frontier 611854), s02e (1,641, frontier 223522); s04b and s00g withdrawn before any row; the waiter held 6 cores within seconds; the five shards re-queued from their frontiers at 23:29. Box 2 then read 0 holders of mine.
01:04 BST (8 October), box 2: the class v5 lane asked for cores for its release-class pinned-packs test
and the full igneum-pow suite (waiting since 00:55 with 0 free; my three holders sat at or under the
32-thread line where the pool's pre-emption did not reach them). Ended by pgid file: sweep-s08 (46,044 rows
kept, frontier 849304) and sweep-s06c (40,679 rows kept, frontier 652538); my two adv waiters (s04b, s00g)
withdrawn so they do not take the freed cores; sweep-s02e (23 cores) left running. The four shards re-queue
from their frontiers once the v5 runs hold cores (or after 20 minutes). Record: at 01:04 and 01:07 BST
lease status on box 2 showed no class-v5 or release waiter or holder at all, so the v5 lane's two runs
go through another path than the pool (the bounded suite slot, most likely) and the 64 freed cores stood
free; at 01:07 the live chain on the three tail seeds that surfaced after the 23:50 count (228763, 638990,
623492) took 32 of them, with their 2^20 read queued beside it at 8 cores.
01:13 BST, build-1: none of my leases left; row 90's second half (queued 21:24) and the five build-1 shards (queued 23:05) reached the lease's 2 h give-up behind the 12 attack-pass holders without ever taking cores, so build-1 gave this lane nothing from 20:42 BST on. Box 2 had room (load 49, no class v5 lease), so at 01:14 row 90's second half (attempts-10k-b, seeds 10002 to 20001) and the five shards (s09b from 911979, s05b from 502127, s03 from 300002, s07b from 706081, s01d from 150610) were queued there at 32/16, behind sweep-s02e; the four box-2 shards yielded at 01:04 re-queued at 01:25 BST (s08 from 849304, s06c from 652538, s04b from 400603, s00g from 40822) after the watcher's 20-minute window passed with no class v5 or release lease ever appearing in the pool listing.
Ledger, 8 October after the reading
01:33 BST, box 2: row 90's second half (attempts-10k-b) finished, 1,112 s on 32 cores; merged above.
01:52 BST, box 2 (coordinator's order): adv-accept-3's Q4d (spec read-back against 56eebc0d, 16 cores) was
the only waiter with 0 free and this lane held 87 of the 88 pool cores. Ended sweep-s09b by pgid file
(8,251 rows kept, frontier 920229); Q4d took the 16 cores 61 s after queueing. Re-queued the remainder as
sweep-s09c from 920230 (79,772 seeds), 32/16, behind Q4d. The other holders (s02e 23, s05b 16, s06c 32)
stayed; s04b took 16 cores at 01:57 BST when they came free.
About 02:15 BST: box-hours crossed the plan's 8 (running time). The reading went to the coordinator at 03:25 BST with the count and the choice (shards run on in the pool's gaps, or end at their frontiers). Until told otherwise they run on.
03:24 BST: the owner-rule yield watcher closed its window on both boxes with no trigger (no class-v5 or v5-labelled attack-pass waiter appeared); restarted on box 2 only, nothing of this lane holds on build-1.
03:25 BST, box 2: sweep-s03, sweep-s07b and sweep-s01d had given up after the pool's 2 h wait without a row. Re-queued from their frontiers as sweep-s03b (from 300002, 100,000 seeds), sweep-s07c (from 706081, 93,921) and sweep-s01e (from 150610, 49,392), 32/16. Queue on box 2 at 03:26 BST: holders s02e, s05b, s06c, s04b; waiters s08, s00g, s09c, s01e, s03b, s07c. Accepted programs on disk 408,067 (80,234 build-1, 327,833 box 2, ranges disjoint).
03:2x BST, coordinator's call on line 16: the shards run on in the pool's gaps under the mechanical yield until this lane's running box-hours reach 16 or main says stop, whichever first. At 16 every shard ends by pgid file at its frontier, the sweep is written as partial at that count with the frontiers in this ledger, pushed, and the final line (tip, box-hours, count, tally) goes to the coordinator. No new row type: the shards only tighten the count. At about one box-hour per hour of holding, 16 falls at about 10:10 BST if the shards hold without a gap; a monitor on this side reads the holders every five minutes and accrues only the minutes with a holder.
04:56 BST (coordinator's order under the no-gaps rule): build-1 read load 22 with no adv lease and a free pool while sweep-s01e and sweep-s07c waited behind this lane's own four holders on box 2. Withdrew both waiters on box 2 by pgid file (0 rows each) and submitted them on build-1 at 32/16 from the same frontiers (s01e from 150610, 49,392 seeds; s07c from 706081, 93,921). s01e took 32 cores in 1 s; s07c waited with 8 free. The box 2 holders stay. The owner-rule yield watcher runs on build-1 as well. Ranges stay disjoint per box, so nothing double-counts. Running box-hours 10.6 at 04:54 BST.
04:57 BST, reversal from main within the minute: build-1 carries the attack-pass lane's F1 census (release class, 2 days 19 hours banked, nothing on disk until its end, projected to about 10:00 BST) and this lane's shards push that projection. Ended sweep-s01e on build-1 by pgid file (603 rows kept, frontier 151222) and withdrew sweep-s07c's waiter (no rows); build-1 then read 0 leases and no process of the lane; the build-1 watcher stopped. Re-queued on box 2 as sweep-s01f from 151222 (48,780 seeds) and sweep-s07c from 706081.
04:58 BST, order from main: the attack-pass flush known-failed test (4,000 programs, lease pool 16 --min 8) waited at 1 free behind this lane's holders on box 2. Ended sweep-s05b by pgid file (46,460 rows kept,
frontier 548586); the test took its 16 cores 5 s later. Re-queued as sweep-s05c from 548586 (51,416
seeds). Also at 04:58: sweep-s02e and sweep-s06c had finished their ranges (exit 0, 16,641 s and 7,421 s);
sweep-s08 and sweep-s00g had given up after the pool's 2 h wait without a row and are re-queued as
sweep-s08d from 849304 (50,698) and sweep-s00h from 40822 (59,180). Box 2 at 04:59 BST: holders s03b 27,
s04b 16, s09c 28 cores; waiters s05c, s01f, s07c, s08d, s00h.
05:22 BST: the box 2 yield watcher closed its window with no trigger and was restarted. Box 2 then held s03b 27, s04b 16, s09c 28 and s05c 17 cores (s05c took its cores at 05:08 BST when the F1 flush test ended) with s01f, s07c, s08d and s00h waiting. Box-hours 11.0 at 05:19 BST.
Closing entry, 09:47 BST 8 October (the founder's default through main: end at 10:15 BST or 16 box-hours)
Nothing to end: at 09:45 BST both boxes read 0 adv-accept leases and no process of the lane. The shards finished or gave up on their own before the deadline. Every row file on both boxes checked: every row's first field is a seed, no odd rows.
| Shard | Range swept | How it ended |
|---|---|---|
| 00 | 2..40885 | parts 0 to g; s00h (from 40822) gave up after the pool's 2 h wait, 0 rows; 40886..100001 unswept (59,116 seeds) |
| 01 | 100002..200001 | complete: parts on build-1 to 151222, s01f on box 2 to the end (exit 0, 12,685 s) |
| 02 | 200002..300001 | complete: s02e exit 0 (16,641 s) |
| 03 | 300002..400001 | complete: s03b exit 0 (19,701 s) |
| 04 | 400002..500001 | complete: s04b exit 0 (28,921 s from queueing, the last to end, 09:37 BST) |
| 05 | 500002..600001 | complete: s05c exit 0 (14,233 s) |
| 06 | 600002..700001 | complete: s06c and s06d exit 0 |
| 07 | 700002..706080 | s07c gave up twice (box 2, 2 h wait) and was ended on build-1 after 72 s with 0 rows; 706081..800001 unswept (93,921) |
| 08 | 800002..849303 | s08d gave up (2 h wait), 0 rows; 849304..900001 unswept (50,698) |
| 09 | 900002..1000001 | complete: s09c exit 0 (16,996 s) |
Distinct accepted programs across both boxes: 796,042 (build-1 80,835, box 2 724,727, the s05b range present on both; seeds-by-file listing in logs/adv-accept/). Seeds covered by the ranges: 796,265; the 223 short are the seeds in flight at the kills, as the 20:21 BST ledger says. Box-hours at the close: about 15.1 (the monitor's 355 holding minutes on the 9.2 base). Every shard log, both frontier ledgers and the monitor log are copied under logs/adv-accept/sweep-build-server, sweep-build-server-2 and box-hours-monitor.log. The row files stay on the boxes under /srv/builds/_adv-adv-accept/ (about 800,000 rows).
Final tally of the bypass: 9 live hot sets, all from the stand-in tail (37 lowest-ratio programs measured live at 2^24 nonces, 22 beyond the f8 1.2x gate), 0 among 20 random; each a single hot item of about 1 MB worth at most 1.002x to a chip. The class v5 per-site floor at 0.995 refuses all 9 (minimum sites 0.9809 to 0.9919), misses 3 mild concentrations of at most 1.0004x, and refuses 7 clean programs of the 12 deepest. BOUND, no BREAK; internal adversarial pass, not an independent review.
Where the pass stands: the 00:00 BST reading (count refreshed 01:08 BST, 8 October; pool state at 23:50 BST)
| Item | Reading |
|---|---|
| Box-hours spent (running time, both boxes, nice 10; pod-hours 0, no GPU, no pod) | about 15.1 at the close (9.2 at 03:25 BST, then a five-minute monitor accruing only the minutes with a holder on either box, 355 minutes to the last shard's end at 09:37 BST; logs/adv-accept/box-hours-monitor.log; the 8 crossed at about 02:15 BST): the two 88-thread shards for 1.9 h of wall under contention until the 20:21 kill, then shards at 32 or fewer cores through the lease pool with repeated releases to the class v5 work (every release by pgid file, rows kept, re-queued from the recorded frontier); two adv-live confirmation chains, the 10^6-nonce census (51 programs), 34 live rows at 2^24 of the stand-in tail plus 20 random, the gap tool on 61 programs plus 17 decisive 2^20 reads, row 90 on 20,000 seeds, the class v5 exemplar check |
| Q1, the bypass: bound reached | 796,042 distinct accepted programs drawn through the chain path by the close at 09:47 BST (79.6 percent of the 10^6 planned; 41 shard files across the two boxes de-duplicated by seed; the three unswept ranges are in the closing ledger entry; 269,250 by 01:08 BST and 46 shard files de-duplicated by seed; 182,646 at the 23:50 reading; at 23:50 three shards of mine held 87 cores on build-2 and the rest waited: build-1's pool stayed held by attack-pass from 20:42 on, so row 90's second half and four shards never ran there). Nine pass every part of the rule and flag the f8 hot-set test on the LIVE dataset at 2^24 nonces (100767, 4346, 5245, 1738, 170, 106924, 107022, 122960, 228763: X_0.1% +0.102 to +0.221 percent, 1.54x to 2.24x over the window model), all nine in the lowest 37 stand-in-ratio seeds; 20 random accepted programs: 1 beyond the f8 gate, 0 hot sets. Every hot set is the top 0.1 percent of items (about 1 MB) holding 0.26 to 0.41 percent of reads against 0.15 expected: an on-die copy saves under 0.3 percent of DRAM reads, gain 1.002x at the largest; no row of chip-model-v3.md moves. Mechanism: a load site whose source reaches zero or all-ones (or one bit off) in hundredths of a percent of evaluations, under the (c') 1 percent limit, mapped by the era stride to one fixed item (item 0x000000 the hottest in four); two further shapes seen (a low-entropy band without saturation; one constant image from a non-saturated source, seed 29307). The exemplar reads the same hot set under the class v5 dataset (the pre-floor draw) |
| Q1 against the class v5 per-site floor at 0.995 | all 9 live hot sets refused (minimum sites 0.9809 to 0.9919 at the acceptance's own 2^20 sample); 3 mild concentrations missed (Devnet 3 epoch 0 site 0 at 0.9992, adv-cache-2's era-fixed-20 at 0.9997 and era-drawn-2 at 0.9992: about 1.0004x to a chip, adv-cache-2's rotation class); 7 clean-live programs refused and 1 clean passed among the 12 deepest 256-unit seeds (the floor's 2.4 percent clean rejection) |
| The selector | the 256-unit stand-in ratio enriches the live gate 13x (17 beyond of the lowest 25 against 1 of 20 random) and finds the hot sets (8 of 34 against 0 of 20), with false positives 8 of 25 on the gate and 26 of 34 on the hot-set test; below 0.995 it is not sampling noise but a different fact: a low ratio is a thin spread of repeated indices, not a hot set. The 2^20 ratio the rule computes is the real selector; one chain draw costs about 3 s of one core and a seed under 0.998 costs about 1,000 draws |
| Q2, the stand-in gap: bound reached | 54 programs plus 17 decisive reads: closed-form and live per-site ratios agree to 0.0004 at 2^20 (the sampling noise), 0 verdict disagreements, (c) metrics agree to 0.019 of 128; the zero-dataset plant fires. No steering through the gap |
| Q5, distinguishers | a lossy last write to an output register in 83.5 percent of 269,250 accepted programs, no live effect beyond Q1's; register-set collapse 0; the 0.98 floor is live in the tail (0.9811 at 256 units, 0.9814 at 2^20 seen) |
| Row 90 (owner adv-accept-3, unspawned; claimed) | 20,000 seeds: rejection by part (a') 83.5, (a) 11.6, (b) 3.0, (c'') 1.1, the rest under 1 percent; per-candidate rejection 0.681 flat across attempts; P(exhaust) 2e-43; 0 exhaustions; max attempt 28; the last resort reachable only by a rule that rejects everything (plant fired) and then accepted as drawn |
| BLOCKED | per-card hash-rate confirmation of any gain (no GPU tonight); priced analytically against chip-model-v3.md |
| Partial, named as partial | the sweep closed at 796,042 of 10^6 seeds (three ranges unswept, 203,735 seeds, plus 223 seeds in flight at the kills; every hot set found is in the 1.002x class the v5 floor refuses); 37 of the stand-in tail and 20 random measured live; row 90 complete at 20,000; the 2^20 read of seed 3664 and the live attribution of the clean deep seeds not taken further |
| What a longer pass adds | the other 73 percent of the 10^6 seeds, the 2^20 ratio (not the 256-unit proxy) as the ranking, and a live row for every seed under 0.985 at 2^20: more rows of the same three shapes, not a different answer unless a seed reads a hot set over 1 percent of reads, which 269,250 draws and 54 live rows did not produce. The open design question is adv-cache-2's: the stride rotation that lets a product's low bits into the item index, a load_index change rather than a floor |
Running notes
- Box-hours and commands are logged in each section with the seed, so every claim is reproducible by re-running the exact command on box 2.
- No cargo on the Mac. Pushes to the build mirror only. Commits as igneum-labs.