igneum/docs/analysis/cryptanalysis/report-acceptance-rule.md
igneum-labs 6d2eac61ef adv-accept: re-base onto build/master d21ca54a noted, sharded sweep and live runs recorded
igneum-pow at HEAD is IDENTICAL to the frozen object c3d32437 (and so is build/master's).
Shards 00 (box 2) and 01 (box 1) running under the yield script; shards 02..09 in the shared
queue; the adv-live const-item plant and its control running on box 1.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:31:21 +00:00

7.6 KiB

Report: adversarial pass on the program acceptance rule (class v4 sub-version 3)

internal adversarial pass, not an independent review

  • Target commit: 017e703764 (class v4 sub-version 3, object byte 7).
  • Crate built: igneum-pow at the frozen commit (this worktree's igneum-pow/ is reset to it; build/master diverged by 635 deletions and is not used). Harness: tools/attack/adv-accept (depends on igneum-pow by path).
  • Re-base (19:3x BST): build/master moved to 7a7caa34 whose igneum-pow IS the frozen object; merged at 8748e955ceb48be5a6cbf7f8718a4884d3de9828; git diff --quiet 017e7037 HEAD -- igneum-pow prints IDENTICAL. Nothing measured here was on a stale tree: igneum-pow/ had been reset to the frozen object before the first build.
  • Binary sha256 (first build, box 2): e3d35f4464937f91aac0648e2ee7134f33c85c7aa314b87b33f91059dedc6682 (adv-accept single-binary build); the two-binary build (adv-accept, adv-live = the unmodified f8 harness) sha256 is logged per box in the run sections below.
  • Boxes: igneum-build-1 (CPU-bound sweeps, by the coordinator's order) and igneum-build-2 (shard 0, already there). nice 10 on every idle core, the capacity layer's yield (run-box.sh). Logs under /srv/builds/igneum-wt-adv-accept/adv/ on each box (spared from the checkout clean by .igneum-scratch-spare; the first 10k log on box 2 was wiped by a rebuild before the spare existed and is void anyway: old labels, old binary).
  • Lane scope since 19:2x BST: THE BYPASS (Q1, Q2, Q5). Q3 is lane adv-accept-3's, Q4 lane adv-accept-2's.
  • Seed space: the attack-pass F8 label space (program k = seed_words("igneum-attack-f8/program/k"), era ".../era/k"), so adv-live warps --program k measures the live hot set of exactly the program the sweep reports.
  • rustc 1.99.0 both sides. First results by 8 October 2026 18:00 BST. GPU: not available, so any per-card hash-rate confirmation of a gain is BLOCKED and said so.
  • Box-hours spent so far: about 0.1 (one 7 s build, three short runs). Budget 8.

Draw-path validation (must pass before any claim)

The shared devnet epoch-0 class v4 program drawn through Epoch::chain_program(ProgramClass::V4) has program id a785001687d8688a at attempt 1 (class mx8-erad810f22d+sh256x27), which matches the frozen pack proto-cuda/packs-ca3-v4/v4-devnet-epoch0/program.json and the brief. So my draw path is the chain's. Command: adv-accept derive-check on box 2. Devnet 3 epoch-0 (id fce15bf61030be57) derive check is owed once I copy its program.json read-only from build-1.

Status board

Q Method Known-failed shape (must fire) Gate Result Status
Q1 Steering/hot set: draw accepted class v4 programs over >=10^6 seeds, measure the hot set of the 128 live loads per hash (share of reads on top 0.1% / 1% of items vs uniform) f8 const-item / quarter-lines / half-lines plant must FLAG; clean control within noise X_f >= f flags a hot set; gain = implied on-die SRAM copy size closed-form proxy sweep (10k seeds) running; live-dataset histogram owed RUNNING
Q2 Stand-in gap: compare the (c) metrics (distinct-address sum, saturation, bias, per-site ratio) on the closed form vs the live memory-hard dataset for accepted programs; count and bound false accepts a hand-built closed-form-accept / live-reject program must be reported as such any false accept that reads a hot set on the live set not started (rides on Q1 cache) PENDING
Q3 Attempt grinding + last resort: variance of the hot set across attempts of one seed vs across seeds; what last_resort_v4 (256-cap, or/mul/mulhi->xor, no (c) check) hands an attacker the forced last-resort program's live hot set must be measurable; derive check fce15bf61030be57 a predictable or weak accepted program the hot-set rule never sees not started PENDING
Q4 Header grinding for locality: vary H and nonce_hi (init words only), measure distinct DRAM rows / cache lines a 32-lane group touches, search cost vs clustering gain a harness-mirror patch making the address depend on I must let the search find a clustering header; the real path must not best clustering over a header budget, cost in hashes not started PENDING
Q5 Generator distinguishers: over accepted programs count lossy last writes, contractions, register-set collapse, low-entropy sites in the 0.98 tail; headroom of the floor reproduce the crate's ratio verdict: p15/p18/p19/p56 rejected, p23 attempt 1 accepted a structural shape that lowers the live distinct-item count per-site ratio distribution in the 10k sweep; F8 reproduction owed RUNNING
Q6 Fixed (c) sample grindability; live-size invariance of the (c) verdict a program tuned to the 2,048 fixed nonces but failing off-sample must be found or bounded BOUND unless something fires not started PENDING

The plant (known-failed shape for the harness itself) fired: planting an or write of a load's source register immediately before the load makes the rule reject with "(a') load at 1 reads r4, not fresh by dataflow in the loop's steady state". So the harness reads the real rule, not a copy. Command: adv-accept plant --seed 0 on box 2.

Q1 and Q5: the accepted-program sweep (RUNNING, sharded)

Ten shards of 100,000 seeds (k = 2..1,000,001 of the F8 label space), each adv-accept sweep --seed-start S --seeds 100000 --threads 96 --ratio-units 256 --out /srv/builds/igneum-wt-adv-accept/adv/sweep-sNN.txt, started through run-box.sh (nice 10, yield to builds, pid/pgid/yield pid files beside the log). Shard 00 (S = 2) on box 2, started 18:27Z. Shard 01 (S = 100,002) on box 1, started 18:30Z. Shards 02..09 sit as self-contained scripts in /srv/builds/_adv/accept/queue/ on box 2 (claim by mkdir under claims/), to be run back to back on whichever box has idle cores. Every row is written as it lands, so a partial shard is data.

Live hot set (the measure the chip model prices): adv-live warps --program k --nonces N (the unmodified f8 harness: the day's items derived into a table, the cross-hash item histogram, the hot-set test X_f >= f against the window-model control, the 6-sigma test, library agreement checks). Known-failed shape run first: --plant const-item on program 2 at 10^6 nonces (box 1, 18:30Z, log adv/live-plant-p2.log) beside its clean control (adv/live-control-p2.log). The plant must be FLAGGED and the control clear before any live number below is trusted.

Seeds: epoch bytes = LE words of seed_words_from_bytes("igneum-attack-f8/program/k"), era bytes of ".../era/k"; each drawn through the chain path generate_era(V4_CLASS, V3_ALLOWED), which runs the full attempt loop and the real acceptance rule.

Per accepted program the sweep records: attempt, program id, the closed-form distinct-item mean per hash (the rule's own (c) metric; 128 is ideal, the rule floor is a mean above 120), the minimum per-site distinct-index ratio at 256 units (the (c'') metric sampled cheaply; the enforced floor is 0.98 at 2^20 units), the saturated-final count and the output-bias max.

This is the closed-form proxy for Q1 and the headroom characterization for Q5. The live-dataset hot set (the memory-hard cache, items derived into a table, the cross-hash histogram with the hot-set test) is the next run and is what the chip model prices; the closed-form distinct mean is a cheap upper bound on how concentrated an accepted program can be on the stand-in.

Numbers land here when the run finishes (first results by 8 October 18:00 BST).

Running notes

  • Box-hours and commands are logged in each section with the seed, so every claim is reproducible by re-running the exact command on box 2.
  • No cargo on the Mac. Pushes to the build mirror only. Commits as igneum-labs.