12 KiB
Report: the day-key weakness class of the mixer M_r (lane adv-mixer-2)
Internal adversarial pass, not an independent review. Every sentence below that could be quoted carries that label.
Header
| Field | Value |
|---|---|
| Target commit | 017e703764 (class v4 sub-version 3, object byte 7) |
| Target | the per-day draw of ROT[0..7], MUL[0..15], RC[0..15] for M_r (spec 01 section 1.8.4), class v4 (x8, 72 applications per item) |
| Branch | adv-mixer-2 from build/master 7a7caa34, merged 04c4d9bc; plan 5704a7b3; harness ae3088a9 |
| Byte identity | git diff --quiet 017e7037... HEAD -- igneum-pow printed IDENTICAL at 7a7caa34 and at 04c4d9bc (the whole crate) |
| Harness | tools/attack/adv-mixer-2 (binary adv-mixer-2), igneum-pow by path, nothing re-implemented |
| Binary sha256 | 88f6a3edfffad166d35a3bcadcaff7907613e710b842cfcbe94fbb1601f7c37b (release, identical on both boxes, copied to /srv/builds/_adv-adv-mixer-2/bin/) |
| Boxes | igneum-build-1 and igneum-build-2, rustc 1.99.0; every sweep through /srv/builds/_bin/lease pool at class adv, 32 cores, --min 16, nice 10 |
| Logs | /srv/builds/_adv-adv-mixer-2/logs/ on each box; copies in docs/analysis/cryptanalysis/logs/adv-mixer-2/ |
| Price | chip-model-v3.md 5.2: 128 ops per application hoisted, 9,360 ops per item; the spec's 130 per application |
| Clock | UK time throughout |
What the per-day gain means, and for whom
The honest miner (any GPU) and the CPU verifier run memhard::mixer with the day's constants as operands: 16
multiplies, 16 XORs, 32 adds, 32 XORs, 32 rotates per application, the same instruction count on every day. A
multiplier unit costs the same for MUL = 3 as for MUL = 0x9E3779B9. So under chip-model-v3's op count (9,360 ops per
item, value-independent) the per-day gain is exactly 1.0 on every day for every GPU, for the verifier, and for a
chip with a general multiplier. The chip model credits hash rate only through that count.
The day's constants matter only to a datapath that bakes them in. An ASIC cannot be masked per day. An FPGA bitstream can be synthesised per day, and that is the only per-day attacker; its per-day gain is an AREA gain (fewer LUTs per multiplier, so more copies of the pipeline per device), which the chip model does not price as hash rate. The three cost models of this lane read that area:
| Model | What it measures | For whom | Gain over 1.1x on more than 2^-20 of days? |
|---|---|---|---|
| A, LUT shift-add (64 + sum of (w32 - 1)) | adder-equivalents per application with every multiplier as a canonical signed-digit shift-add chain; rotations and constant XORs free | a per-day FPGA build with multipliers in LUTs; not a wall-time gain for any chip | YES: P(cost A <= 205, gain >= 1.102x against the exact median 226) = 5.694e-4 = 2^-10.8 per day (exact, 16-fold convolution of the w32 table over all 2^31 odd constants; about 21 days per 100 years). 1.2x: 2^-28.8 (1 day in 2^28). 1.5x: under 2^-91 |
| B, certified shift-add | the same datapath with each multiplier at its certified optimal chain (exact for 1 to 4 adders, decomposition certificate for 5) | the same FPGA, closer to what a synthesiser achieves; an upper bound on the attacker's cost | PENDING (queue 03 and 04) |
| C, DSP | 16 / (16 - k) with k the words whose constant has a 2-adder chain and leaves its DSP block | a per-day FPGA build with multipliers in DSP blocks (value-independent) | NO: k >= 1 gives 1.067x on 3.123e-5 = 2^-15.0 of days; the first gain over 1.1x is k >= 2 (1.143x) on 4.57e-10 = 2^-31.0 |
| Chip model (ops per item) | 9,360 per item, value-independent | every GPU, the verifier, any chip with a general multiplier | NO: the gain is 1.0 on every day |
Threshold used: the brief's, a gain over 1.1x on more than 2^-20 of days. Model A crosses it by 9 binary orders; model C and the chip-model reading do not. The redraw rule below is proposed on the model A reading, because the census of a public calendar is the attacker's cheapest tool and a 10 percent area edge on 1 day in 1,750 is free to take even if it buys no hash rate against the chip model's attacker. The worst real calendar day with its date is queue 02 (PENDING).
Status board
| Q | Method | Known-failed shape | Gate | Result (numbers) | Status |
|---|---|---|---|---|---|
| Q0 plants | plant on the day-20729 draw with one field replaced, through the same classifier |
alleq, rot1, mul1, mul1all, rcrk0, weakday (all ROT equal and MUL = 1) | every plant lands in its class with its gain | all six fire: alleq -> "ROT all equal" (cost 219); mul1 -> "MUL any = 1", gain 1.1053x; mul1all and weakday -> cost 64, gain 3.61x, model C k = 16; rcrk0 -> "RC + rk = 0"; rot1 -> "ROT all 8 in {1,2,30,31}" | PASS |
| Q3 exact tail, model A | w32 over all 2^31 odd constants (exact), 16-fold convolution | the table must give 2 constants at w32 = 1 (1 and 2^32 - 1) and the mean must match the census | mean w32 11.1111; mean cost A 225.78, exact median 226; P(gain >= 1.05x) 4.72e-2; >= 1.1x 5.694e-4 (2^-10.8); >= 1.15x 1.66e-6 (2^-19.2); >= 1.2x 2.13e-9 (2^-28.8); >= 1.3x 2.07e-16; >= 1.5x under 2^-91 | FINDING (area reading), crosses 2^-20 | |
| Q3 exact, model C | exact 2-adder set (4,192 odd constants, 2^-19.0 per word) | the set must contain 1, 2^32 - 1, 2^s +- 1 | P(k >= 1) 3.12e-5 (gain 1.067x), P(k >= 2) 4.57e-10 (1.143x) | PASS (bound: under 2^-20 at 1.1x) | |
| Q1 census 2^24 | census --from 20729 --count 2^24 (32 structural classes, cost A histogram, model C) |
plants above | counts against the analytic expectation | queue 01, waiting in the box-2 lease pool since 21:22 UK | RUNNING |
| Q2 census 2^32 | census --count 2^32 |
plants above | the model A tail against the exact table | queue 06, waiting in the box-1 lease pool since 21:28 UK | RUNNING |
| Q4 the real calendar | calendar --from 20729 --years 100 (36,525 days: 3 October 2026 to 2126) |
the planted stream-shift pair must be found | worst day with date under A and C | queue 02 | RUNNING |
| Q5 cross-day structure | seed collisions, stream shifts by k in 1..72, shared MUL and RC values over the calendar | planted shift pair | counts against expectation | queue 02 | RUNNING |
| Q2 model B | scm-refine on the calendar, on the lowest 2^14 days of the 2^24 census, on a 2^16-day random sample |
the self-test constants (3, 5, 7, 9, 2^32 - 1, 2^31 + 1 at 1 adder; 45 at 2) | the certified-cost distribution and the cost B tail | queue 03, 04 | RUNNING |
| Q6 ROT diffusion | avalanche (1, 2, 3, 4, 8 applications; the 22 address bits) on the genesis day, the plants, the worst ROT days of the census |
plant rot1 and alleq must read weaker than the genesis day at 1 application | a per-day gain only if a bit-exact shortcut follows; else 0 with the diffusion numbers | queue 05 | RUNNING |
| Q7 redraw rule | redraw-census 2^24 and 2^28 days with the rule below |
--max-cost 0 must reproduce the real draw on 1,000 days (asserted in the binary) |
fraction redrawn; residual over 1.1x must be 0 | queue 07 | RUNNING |
| GPU rows | none needed | no row of this class depends on a GPU | BLOCKED (not applicable) |
Q7: the proposed redraw rule
Rule, for the day's parameter draw (spec 1.8.4): after the forty draws, compute cost A = 64 + sum over the sixteen MUL of (w32(MUL) - 1), and the count k of MUL values with a 2-adder chain. If cost A <= 205 (a model A gain of 1.1x or more against the median 226), or k >= 1, or the eight ROT are equal, continue the SAME SplitMix64 stream and draw all forty again; repeat until accepted. The honest miner and the verifier pay forty more 64-bit draws per redraw, once a day; nothing else changes; every accepted day is a day the current rule could have drawn.
| Quantity | Value |
|---|---|
| Fraction of days redrawn at least once (exact, models A and C) | 5.694e-4 + 3.123e-5 = 6.0e-4 (2^-10.7), about 22 days per 100 years |
| Fraction over 1.1x under model A after the rule | 0 by construction; measured by queue 07 over 2^24 and 2^28 days (PENDING) |
| Fraction over 1.1x under model C after the rule | 0 (k = 0 on every accepted day) |
| Chip-model reading after the rule | unchanged: 1.0 on every day before and after |
| What the rule does not fix | the seed is 64 bits of the day key (K[0], K[1]); the day is a pure function of the calendar; both stand; neither is a weakness of this class on the numbers above |
Sections per row
Q0 plants (PASS)
Command on box 1: nice -n 10 taskset -c 8-95 adv-mixer-2 plant (19:4x UK, 0.3 s; the only hand-started runs of
this lane were the three smoke runs before the lease rule of 20:22 UK). Log: logs/adv-mixer-2/smoke-plant.log. The
unplanted day 20729 (3 October 2026): ROT 6 25 5 25 29 11 9 21, cost A 219, classes "ROT same-word pair sums to 32"
(ROT[5] + ROT[7] = 32) and "any pair sums to 32".
Q3 exact tail (FINDING on the area reading)
Command on box 1: adv-mixer-2 exact --threads 40 (19:5x UK, 10.3 s wall, 173 CPU-s). Log: logs/adv-mixer-2/
exact-w32.log. The w32 table over all 2^31 odd constants:
| w32 | Constants | Fraction |
|---|---|---|
| 1 | 2 | 9.3e-10 |
| 2 | 118 | 5.5e-8 |
| 3 | 3,136 | 1.5e-6 |
| 4 | 49,608 | 2.3e-5 |
| 5 | 520,000 | 2.4e-4 |
| 6 | 3,805,120 | 1.8e-3 |
| 7 | 19,948,544 | 9.3e-3 |
| 8 | 75,681,408 | 3.5e-2 |
| 9 | 207,381,504 | 9.7e-2 |
| 10 | 405,171,200 | 0.189 |
| 11 | 550,371,328 | 0.256 |
| 12 | 498,774,016 | 0.232 |
| 13 | 282,427,392 | 0.132 |
| 14 | 89,686,016 | 4.2e-2 |
| 15 | 13,107,200 | 6.1e-3 |
| 16 | 557,056 | 2.6e-4 |
The exact cost A distribution (64 + the 16-fold convolution of w32 - 1), cumulative at the gain thresholds against the median 226 (the log's own threshold table was printed against a provisional 231 and is superseded by this one, computed from the log's per-cost table):
| Gain A | Cost A <= | P(day), exact | log2 | Days per 100 years |
|---|---|---|---|---|
| 1.05x | 215 | 4.717e-2 | -4.4 | 1,723 |
| 1.1x | 205 | 5.694e-4 | -10.8 | 20.8 |
| 1.15x | 196 | 1.660e-6 | -19.2 | 0.06 |
| 1.2x | 188 | 2.132e-9 | -28.8 | 0.00008 |
| 1.3x | 173 | 2.07e-16 | -52.1 | 0 |
| 1.5x | 150 | under 1e-27 | under -91 | 0 |
Reading: an FPGA built for the worst day in 100 years saves about 15 percent of its multiplier adders under model A (cost about 196 against 226); a chip, a GPU and the verifier save nothing. The planted weak day (cost 64) would be a 3.6x area gain; its probability under the real draw is 2^-27 for one MUL = 1 and under 2^-400 for all sixteen.
Ledger of rule changes during the run (box-hours stay honest)
| Time (UK) | Change | Effect on this lane |
|---|---|---|
| 19:22 | worktree cut from build/master 7a7caa34; IDENTICAL check | none |
| 19:32 | plan pushed 5704a7b3 | |
| 19:4x | SIGSTOP yield to builds dropped; nice 10 on cores 8 to 95 | run-box.sh rewritten before any sweep |
| 19:4x | logs out of the worktree mirror (/srv/builds/_adv-adv-mixer-2/) | adopted before any sweep |
| 19:40 to 19:50 | three smoke runs on box 1 by hand (plant 0.3 s, day, census 2^20 0.3 s, exact 10 s) | 0.05 box-hours |
| 20:22 | lease pool is the only way to start a sweep |
queue files rewritten; nothing of this lane was running |
| 20:40 | priority classes release > v5 > measure > adv; 32 cores --min 16 | queue files at 32/16 |
| 21:12 | box 2 open to adv-* | chain 01 to 05 started on box 2 at 21:22, chain 06 to 07 on box 1 at 21:28 |
Box-hours spent so far: 0.05 (the smoke runs). Pod-hours: 0. GPU: none.
Bound reached, honestly
Exact for model A and model C over the whole draw space (every odd constant counted, not sampled); the census rows, the real-calendar worst day, model B and the diffusion numbers are pending the lease pool. A longer pass would add model B certificates past 5 adders (an exact optimal-SCM table for all 2^31 constants) and a census over 2^36 days for the model A tail below 2^-28; neither changes the crossing above, which is exact.