igneum/docs/analysis/cryptanalysis/report-chained-cache-3.md
igneum-labs 52ea3f8bcd adv-cache-3: ledger records the 20:20 BST kill and the lease re-queue
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 19:21:58 +00:00

40 lines
5.6 KiB
Markdown

# Report: the chained cache, chain break or skip (lane adv-cache-3)
Internal adversarial pass, not an independent review. Lane `adv-cache-3`, the chain-break-or-skip class of the chained cache (line `(s, j)` in fewer than `j + 1` blocks without an earlier line; relations through the XOR chaining and the feed-forward; partial knowledge; the pebbling curve). Plan: `docs/plans/cryptanalysis/plan-chained-cache-3.md`. Every sentence here that could be quoted publicly carries the label: internal adversarial pass, not an independent review.
## Header
| Item | Value |
|---|---|
| Target commit | `017e70376489251e18564c0abce7e466e606c8b3` (class v4 sub-version 3, object byte 7); `igneum-pow` at `build/master` 04c4d9bc is byte-identical (`git diff --quiet 017e7037 HEAD -- igneum-pow` printed IDENTICAL at 19:42 BST), and the harness depends on it by path |
| Harness | `tools/attack/adv-cache-3/` (crate `attack-adv-cache-3`, binary `adv-cache-3`), branch `adv-cache-3` on the build mirror |
| Binary sha256 | `37a7a661c548a67827e29c4134bb91751ef2083920b386d3ebc9b599add3ca8a` (built on both boxes from commit 4e363b91's tree, `cargo build --release`, rustc 1.99.0; the first build `067ad69c...` had 66 rank samples per `j` instead of 4,096 and was replaced before any number below) |
| Self-test on every start | the restated `B` equals the library's `chacha_block` on 4,096 random inputs; `core_inv` inverts `core` at w = 2, 4, 8, 16, 32; the restated chain equals `Cache::fill_segment` on segments 0, 21,859 and 65,535 of day 20730 |
| Vectors passed | day 20730 cache FNV-1a 64 `0x448274a57f508cbc` (the kit's `vectors.json`) and day 20733 `0x7334fa46e5d972eb` (the Devnet 3 pack): MATCH, `check.log` |
| Boxes and scheduling | build box 1 (the skip, relations and cross batches) and build box 2 (the exhaustive image census), each under the per-box sweep lock (`/srv/builds/_adv/locks/sweep.lock`, one sweep per box at a time, the coordinator's rule of 19:55 BST), nice 10 on cores 8 to 95, no SIGSTOP yield; the boxes read load 500 to 560 on 96 threads all evening, so wall times below are not timings |
| Logs | `/srv/builds/_adv-cache-3/logs/<tag>.log` on each box (outside the worktree mirror); copies under `docs/analysis/cryptanalysis/logs/adv-cache-3/` on this branch |
| THE QUEUE | files 90, 91, 92 (the coordinator's definitions) claimed at 19:49 BST with owner files; their implementations run as files 93 (skip batch), 94 (relations batch) and 95 (image census), claimed the same way |
| Box-hours | section 9 |
## Status board
| # | Question | Method | Known-failed shape (fired?) | Gate | Result | Status |
|---|---|---|---|---|---|---|
| Q1 (brief a, file 90) | Line `(s, j)` in fewer than `j + 1` blocks without an earlier line | `skip`: 7 earlier-line-free templates (1 or 2 blocks) against every line of 1,024 segments x 64 lines on 2 day keys; the GF(2) rank of the 1,025-column `(x_j, line_j, 1)` sample matrix; the 512 x 512 bit-dependence table and the 16 x 16 word table; the inversion attempt; the w = 4 model at 65,536 segments x 16 lines | `no-xor`, `no-feedforward`, `--rounds 0` | 0 lines under `j + 1`; rank 1,025; no zero cell; plants fire | first run on day 20730: 0 of 65,536 lines under `j + 1` by any template; pooled rank 1,025 of 1,025; flip table worst z +4.44 / -4.53 with 0 zero cells of 262,144; every output word changes with every input word; 0 inversions of 64,512 | RUNNING |
| Q1 (4) | Exhaustive image census at w = 2 (every 2^32 state per step, depth 64) | `image` | `no-feedforward` (a permutation: the image must stay 2^32) | the image follows the random-function recursion, not slower | queued on build box 2 | RUNNING |
| Q2 (brief b, c, file 91) | Relations through `line_j = C(x_j) + x_j`; partial knowledge | `relations`: per-bit bias of 4 relations over 4 day keys x 2^20 lines; the 512 x 512 correlation table; `skip`'s word table and inversion | `--rounds 1`, `--rounds 2`, `no-feedforward` | every bias and cell within 6 sigma at 2^22 samples; 0 words from a proper subset; 0 inversions | queued behind the skip batch | RUNNING |
| Q3 (brief d, file 92) | The pebbling curve of the 64-line chain under storage `f`; the amortising adversary | `pebble`: DP optimum (checked against exhaustive search at 10 to 16 lines), two stride placements, ops per item and SRAM; Monte Carlo of `m` requests per segment, fixed and Poisson | `--skip-edge 8` | monotone, never under the honest curve, 9,360 at `f = 1`; the plant lowers `f = 1/64` | queued in the skip batch | RUNNING |
| Q4 (brief e) | Cross-segment and cross-day relations; the known-constant words | `cross`: 512 x 512 correlation tables at `j` = 0, 1, 63 across one-bit segment pairs and across days | `--plant no-xor --rounds 1` | every cell within 6 sigma | queued in the skip batch | RUNNING |
The sections below are filled in as the rows land. Times in this file are UK time (BST).
## 9. Run ledger and box-hours
| Run | Box | Started (BST) | Wall | Slot-hours |
|---|---|---|---|---|
| `check`, first `skip` (binary `067ad69c...`) | 1 | 20:06, 20:09 | 2 s, 1 s (3 min waiting on the sweep lock) | 0.01 |
| 93 skip batch, 94 relations batch | 1 | queued 20:15 behind the sweep lock; never started | killed by pid file 20:20 BST under main's rule (every sweep through the build-server lane's `lease pool`; nothing measured was lost) | 0 |
| 95 image census | 2 | queued 20:12 behind the sweep lock; never started | killed by pid file 20:21 BST, the same rule | 0 |
| 93, 94, 96 (box 1) and 95 (box 2), re-queued | 1, 2 | when `lease pool` lands | through `lease pool <threads> --owner adv-cache-3 -- <cmd>` | |
Running total: under 0.1 box-hours of the 8 budgeted (the ask line is 16); no pod-hours (no GPU row).