igneum/docs/plans/cryptanalysis/in-house-pass.md
2026-10-07 20:29:16 +00:00

170 lines
43 KiB
Markdown

# The in-house adversarial pass on the lottery hash
> Internal adversarial pass, not an independent review. 7 October 2026, 19:1x BST (nine lanes from 19:2x BST on the project lead's word through main: "push the cryptanalysis tonight, we have the capacity"), the crypto-engage lane on the project lead's correction through main: nothing goes outside. No firms, no paid lots, no briefs to anyone. The three targets of Counter ASIC 3.0 item 3 (the mixer `M_r`, the chained cache, the acceptance rule) are attacked by three lanes that have never worked on the hash code, under the outsider rule below. The only outside check that remains is the disclosure prize, staged (section 10).
## 0. One page
| Item | State |
|---|---|
| What was planned until 18:5x BST | Three external lots (`docs/plans/cryptanalysis.md` on branch `cryptanalysis`, `docs/plans/funding.md` row "Independent cryptanalysis") with firm shortlists and price rows |
| the project lead's correction (through main, 7 October, evening) | Nothing goes outside. No firms, no paid lots, no briefs to anyone. The lane becomes the in-house adversarial pass on the same three targets |
| The pass | Nine adversarial lanes, three per target on three question classes each, each given only what an outsider would have, each writing an attack plan first and then a report in the attack-pass shape |
| The defender | The Counter ASIC lane; main rules disputes |
| The clock | Plans within two hours of start (the first three) or one hour (the six of 19:2x BST); first results from every lane by 00:00 BST tonight |
| The label | "internal adversarial pass, not an independent review" on every public sentence |
| The outside check | The disclosure prize, USD 50,000, approved 7 October 09:5x UK, STAGED until escrow, the entity address and the project lead's publish word; nothing public names it until then |
## 1. The target, exactly
| Piece | Value |
|---|---|
| The frozen object | `igneum-pow` at commit `017e70376489251e18564c0abce7e466e606c8b3` on branch `ca3-v4-amend` (tag `audit-freeze-2026-10-07`); byte-identical on `master` since `cf7d6ccb` |
| The class | Class v4 sub-version 3: `PROGRAM_SUBVERSION_V4 = 3`, object byte 7 |
| The rules in the object | (a') dataflow freshness to a fixpoint; the shared-operand rule in the draw; (c'') the per-site distinct-index ratio at 0.98 over 2^20 evaluations; the 256-attempt cap and the deterministic last-resort draw |
| Program ids | The shared devnet's epoch-0 id `a785001687d8688a` (the kaspa-pow pairing pin); Devnet 3's epoch-0 id `fce15bf61030be57` (attempt 0, sub-version 3) |
| The kit | `packs-ca3-v4-sub3` zip, sha256 `4f2445c50c58d76a5544023492d8b858d0b07c5e372d31f9c90c4ce51f829154`, eight packs: the contents of `proto-cuda/packs-ca3-v4/` at the frozen commit (`mx8-devnet-epoch0` the class v3 control, `v4-devnet-epoch0`, `v4-era-0` to `v4-era-5`) |
| The Devnet 3 pack | `v4-devnet3-epoch0` (zip sha256 `e025750f71175ed14d6e2a24e387ebbf1979b1cd0faee9139c41a7671165b334`, 12 files, program.json `0xfce15bf61030be57` at attempt 0), on build-1 at `/srv/artefacts/packs/v4-devnet3-epoch0/` and `.zip`; Metal and Apple OpenCL fingerprint `e510ad92b4d24846` at 2^24 from base 0; exported under igneum-pow `874e945d` (byte-identical to `017e7037`) over Devnet 3's genesis with day bytes le64(20733); public-kit class, verified by this lane on build-1 at 19:1x BST |
| The dataset under attack | Spec `docs/spec/01-lottery-hash.md` 1.8: ChaCha12 cache fill in 2^16 segments of 64 chained lines; the ARX-multiply mixer with per-day `ROT`, `MUL`, `RC` from a 64-bit SplitMix64 seed; `m = 8`, 72 applications per item, 8 dependent cache reads |
| The acceptance rule under attack | Spec 1.4.6 as the code `igneum-pow/src/accept.rs` implements it at the frozen commit (the code is the truth where the spec lags it) |
## 2. The nine lanes
Three per target, one question class each, from funding.md's ranked list for that target. The first three were spawned at 19:1x BST and re-scoped at 19:2x BST; the six others were spawned at 19:2x BST.
| Lane | Target | Question class | Branch | Worktree | Plan | Report | Plan due (BST) |
|---|---|---|---|---|---|---|---|
| adv-mixer | mixer `M_r` | the algebraic structure: the fold of the multiply layer, the composition of 8 applications | `adv-mixer` | `igneum-wt-adv-mixer` | `plan-mixer.md` | `report-mixer.md` | 21:10 |
| adv-mixer-2 | mixer `M_r` | the day-key weakness class: weak `ROT`, `MUL`, `RC` draws, the 2^24 census, the calendar | `adv-mixer-2` | `igneum-wt-adv-mixer-2` | `plan-mixer-2.md` | `report-mixer-2.md` | 20:25 |
| adv-mixer-3 | mixer `M_r` | the statistical distinguisher and the round margin: differential, linear, rotational-XOR, SAT or MILP on reduced applications | `adv-mixer-3` | `igneum-wt-adv-mixer-3` | `plan-mixer-3.md` | `report-mixer-3.md` | 20:25 |
| adv-cache | chained cache | the recompute shortcut: the honest curve from `f = 1/64` to 1, a cheaper fill, the chip's recompute cost | `adv-cache` | `igneum-wt-adv-cache` | `plan-chained-cache.md` | `report-chained-cache.md` | 21:10 |
| adv-cache-2 | chained cache | the partial-state or hot-set attack: line-index uniformity over 2^28, hot lines and items, steering | `adv-cache-2` | `igneum-wt-adv-cache-2` | `plan-chained-cache-2.md` | `report-chained-cache-2.md` | 20:25 |
| adv-cache-3 | chained cache | the chain-break or skip: a line under `j + 1` blocks, relations through the chaining and the feed-forward, pebbling | `adv-cache-3` | `igneum-wt-adv-cache-3` | `plan-chained-cache-3.md` | `report-chained-cache-3.md` | NOT YET SPAWNED at 19:26 BST (the session's 20-subagent cap); spawned when a slot frees, plan due one hour after |
| adv-accept | acceptance rule | the bypass: passes (a) to (c'') on the stand-in with locality on the live dataset; the stand-in gap; distinguishers that pass | `adv-accept` | `igneum-wt-adv-accept` | `plan-acceptance-rule.md` | `report-acceptance-rule.md` | 21:10 |
| adv-accept-2 | acceptance rule | header grinding for locality: header bytes and nonce against DRAM rows, lines and items; cost against gain | `adv-accept-2` | `igneum-wt-adv-accept-2` | `plan-acceptance-rule-2.md` | `report-acceptance-rule-2.md` | 20:25 |
| adv-accept-3 | acceptance rule | exhaustion or steering of the draw: the 256-attempt cap, the last-resort draw, seed steering, the program id | `adv-accept-3` | `igneum-wt-adv-accept-3` | `plan-acceptance-rule-3.md` | `report-acceptance-rule-3.md` | NOT YET SPAWNED at 19:26 BST (the session's 20-subagent cap); spawned when a slot frees, plan due one hour after |
Plans live in `docs/plans/cryptanalysis/`, reports in `docs/analysis/cryptanalysis/`. Each lane's branch was cut from the build mirror's `master` and is pushed to the build mirror only; GitHub is dark tonight. BASE CORRECTION (main, 19:4x BST, from the hash lane): build-2's mirror master was stale (`a4bca198`, pre-fix) until 18:25:42Z, and the first branches were cut from `3f0afcd5`, whose `igneum-pow` differs from the frozen object by 6 files (verified by this lane: 30 insertions, 635 deletions). Every lane merges build-1's `master` (`7a7caa34` or later; `001e32ec` is the earliest good tip) before any run or report and proves `git diff --quiet 017e7037 HEAD -- igneum-pow` identical, stating the commit in its plan; anything built or measured on a stale tree is void. `crypto-engage` itself merged `7a7caa34` at 19:27 BST (355ac2ae, identical).
## 3. The rule set
### 3.1 What a lane receives (the outsider's inputs, and nothing else)
| Input | Where the lane reads it |
|---|---|
| The crate `igneum-pow/` (src, tests, Cargo files) at the frozen commit | `master`'s copy, verified byte-identical with `git diff --stat 017e7037 HEAD -- igneum-pow` printing nothing; the result stated in the plan |
| The spec `docs/spec/01-lottery-hash.md` at the frozen commit | `git show 017e7037:docs/spec/01-lottery-hash.md` |
| The chip model `docs/analysis/chip-model-v3.md` sections 1, 2, 5 and 6 | the worktree's HEAD |
| The public kit: the eight packs | `proto-cuda/packs-ca3-v4/` at the frozen commit; the zip sha256 above |
| The two program ids and the Devnet 3 pack | stated in the lane's prompt; the pack read from build-1 (`/srv/artefacts/packs/v4-devnet3-epoch0/`, sha256 above), handed to the lanes at 19:1x BST after their start |
| The attack harnesses `tools/attack/f8-uniform` and the F4 census `tools/attack/f4-weakday` | f4-weakday from `build/attack-pass`; f8-uniform from the Mac worktree `igneum-wt-attack-regate` (that branch is not on the mirror); copied, never edited in place |
| The operating files needed to run anything | `tools/build-remote.sh`, `infra/build-server/lib.sh`, `infra/build-server/remote-run.sh` |
| Sibling lanes' plans and reports | `git fetch build adv-<target>-<n>`, the files under `docs/plans/cryptanalysis/` and `docs/analysis/cryptanalysis/` only; siblings are outsiders too |
### 3.2 What a lane does not receive
| Withheld | Why |
|---|---|
| `docs/plans/counter-asic-3-status.md` (section 7c and all) | the defender's reasoning on AP-F8-1, the localisation, the cost lines |
| `docs/fud-ledger.md`, `docs/fud-fixes.md` | the ledger entries on AP-F8 and every earlier finding |
| `docs/analysis/attack-pass/*` and `docs/analysis/attack-pass-2026-10.md` | the hash lane's and the attack-pass lane's notes and results |
| `docs/analysis/ca3-v4-uniform.md`, `docs/plans/mixer-x4.md`, `docs/analysis/weak-program-census-2026-10-03.md`, `proto-metal/MEMHARD.md` | defender's analyses |
| `docs/plans/funding.md`, `docs/plans/cryptanalysis.md`, this file | the ranked questions as the defender ranked them, the known gaps as the defender knows them |
| `git log`, commit messages, other branches and worktrees, `site/` | commit messages carry the defender's reasoning; the site carries the defender's numbers |
Known leaks, stated: `CLAUDE.md` loads on its own in every lane (operating rules; the lane follows no pointer from it into other docs); the harness sources carry doc comments written by the attack-pass lane. Each plan lists every file the lane opened, so the defender can read what the lane knew.
### 3.3 How a lane states a result
A result is a BREAK (a method with a measured or counted gain, reproducible from the command and the seed) or a BOUND (what was searched, with what tools, how far it reached, the margin left). "Nothing found" counts only with its effort stated in box-hours and tools. Every number carries its command, its seed and its log path on the box.
## 4. The budget and the no-gaps rule
Standing rule from the project lead through main (7 October 2026, 19:1x BST), binding: no gaps between tasks.
| Rule | What it means for a lane |
|---|---|
| Every idle core on both boxes | A lane runs on build-1 and build-2 together, on every idle core, at nice 10, no core band; release builds and the class v5 suites keep priority. the project lead's read at 19:4x BST: build-1 at 11 percent, build-2 at 56; his word is both near max, so CPU-bound sweeps go to build-1 explicitly (`--box 1`) and both boxes stay above 80 percent until the queue is empty; the build-server lane raises the lease pool to about 88 cores per box |
| Yield to builds | RETIRED at 19:3x BST (adv-accept's exception: a build slot is held nearly continuously on both boxes, so the SIGSTOP yield of the capacity layer kept every sweep in state T and "both boxes above 80 percent" was unreachable). In its place the build-server lane's rule (19:4x BST): every bounded run at nice 10 on cores 8 to 95 only (`taskset -c 8-95`; cores 0 to 7 reserved for release builds, the seed and the observer), `-j 88` through `tools/build-remote.sh`, the router spilling to the other box at no free slot or a 1-minute load above 80, a pinned measurement leasing its exact cores with `/srv/builds/_bin/lease cores <set> --label "..." --owner adv-<lane> -- <cmd>` (no measure flock), every adversarial worktree merged to the mirror's master at `04c4d9bc` or later; each lane notes the change and its time in its report |
| Back to back | Question `n + 1`'s sweep starts the minute question `n`'s ends; no waiting for a human to read; each result row lands in the report and is pushed as it lands |
| Lease pool only | ADDED 20:1x BST by main (build-1 at load 601, build-2 at 401): no sweep, census or verdict run starts on a box except through the build-server lane's `lease pool <threads> -- cmd` (from the same 88-core pool as the builds, waiting when none are free); every hand-started binary at 64 to 89 threads killed by its pid file NOW and re-queued through the lease; release builds and the class v5 suites outrank every sweep tonight; each lane reports its kill and re-queue in one line to the build-server lane. Relayed verbatim to all eight live lanes at 20:1x BST; the pod is not a box and adv-accept-2's measurement continues. LIVE since 20:22 BST (`/srv/builds/_bin/lease`, sha f814b447, self-test green, verified by this lane on build-2): `lease pool <threads> --label "<what>" --owner <lane> -- <cmd> --threads {cores}` takes up to <threads> free cores from the bounded pool (cores 8 to 95, shared with the builds), never fewer than --min (default min(threads, 16)), waits in 10 s steps up to 2 h, runs at nice 10 pinned to the cores taken, "{cores}" the count and "{cpuset}" the set; the pooled sum on a box never passes 88; lanes ask 32 to 48 so two or three sweeps share a box; the sweep.lock is dropped. Load after the kills: build-1 224, build-2 121 at 20:22 BST. Relayed to all eight live lanes at 20:2x BST. POOL RANKING (main, 20:2x BST): the release builds and the class v5 suites outrank every sweep; an adversarial lease asks for at most 48 cores with --min at the least usable, and yields (finishes the shard in hand, releases) whenever `lease status` shows a waiter labelled "v5 gate" or "v5 kit"; widened at 20:30 BST (the v5 census queued as "class v5 c3 census" with no gate label and nobody yielded) and then fixed to the OWNER at 20:3x BST (the word "v5" also matched adv-accept's own exemplar sweep): yield to a waiter whose owner is class-v5, or whose owner is attack-pass with "v5" in the label, never to an adv-* waiter; BOX 2 CLOSED to adv-* at 20:4x BST by main's order (the (c''') census, owner class-v5, 88 cores, about 9 minutes, the 0.3.24 critical path, blocked by adv-accept at 32 + 31 + 23 cores and adv-mixer at 1, with eleven adv-* waiters): every adv-* holder on box 2 releases at its shard end (partials kept), every adv-* waiter withdraws, no adv-* lease on box 2 until the v5 lane reports the census running, then resume in order; build-1 the same if the v5 lane asks; from now the yield is MECHANICAL: an adv-* lane that sees a class-v5 waiter releases at its shard end unasked; relayed to all nine lanes in one line each; the census RUNNING at 20:41:55 BST on 48 of 88 cores; every adv-* lane confirmed 0 holders and 0 waiters on box 2 except adv-cache-2's 40-core lease taken 19 s before it (ordered released); box 2 stays closed to adv-* until the census ENDS. At 20:49 BST the coordinator ended adv-cache-2's 40-core lease by its exact pids (seven minutes past the order, the lane silent since 20:23), then its box 2 drain (drain.pid; it had started the next 40-core item the moment the first died) and that lease; box 2 read 0 adv-* holders at 20:49 BST with the census alone on the pool; logged in /srv/builds/_adv/coordinator.log. The census ENDED by 21:12 BST (no pool lease on box 2, load 11); box 2 REOPENED to adv-* at 21:12 BST: every lane re-submits at `lease pool 32 --min 16`, class adv, with the mechanical yield; adv-mixer-2 and adv-accept-2 move their build-1-starved runs there (build-1's pool held by attack-pass's class-v5 chunks). POOL CLASSES (the build-server lane, 20:40 BST, lease sha 5d84d644): release > v5 > measure > adv; a higher class is served first whatever the arrival order; an adv holder above 32 threads is pre-empted by SIGTERM after a higher class has waited 120 s (newest first, one per 120 s, /srv/builds/_log/preempt.log) and the lane re-queues the same line; holders at 32 threads or fewer are never pre-empted; old waiters re-submitted once; no sweep label carries "release", "canary", "pair", "v5 gate", "v5 kit" or "measure"; adv-cache-3, holding 87 of build-2's 88 pool cores since 20:22 BST, ordered to release at the end of its current shard so the v5 (c''') census takes build-2 |
| One sweep per box | SUPERSEDED by the lease rule above at 20:1x BST. Was: added 19:5x BST (build-1 at load 496, build-2 at 527 on 96 cores: oversubscription, not the near max asked for; the bounded class is 88 cores per box in total, not per sweep): every new sweep from every lane runs under `flock /srv/builds/_adv/locks/sweep.lock -c "nice -n 10 taskset -c 8-95 <bin> <args> > <log> 2>&1"` on its box, so one sweep runs per box at a time with up to 88 threads and the rest wait in order; running processes finish; duplicates are killed by pid file and re-queued |
| No lane idle | Every planned sweep is a self-contained executable in `/srv/builds/_adv/<target>/queue/NN-<lane>-<name>.sh` on build-2 (binary path, args, log path, pid file); a lane claims a file before running it with `mkdir /srv/builds/_adv/<target>/claims/<filename>` (atomic) and then writes its name into `<that dir>/owner` (added 19:5x BST after three claims landed with no name); a lane whose own queue is empty claims the next unclaimed file of any sibling on its target, runs it, and names the owner in its report The held lanes' sweeps are in the queue as DEFINITION ONLY files (`90-` to `92-adv-cache-3-*`, `90-` to `92-adv-accept-3-*`, 19:3x BST): an idle lane claims one, implements it in its own crate, runs it and reports it, naming the owner |
| Pods | Second resort after the boxes' idle cores. The fleet's rules (the fleet lane, 18:26Z): no CPU-only pod type exists; every pod is a RunPod GPU pod (secure, or a 3090 or 4090 community; Vast unreliable tonight), image nvidia/cuda 12.8.1 on Ubuntu 24.04, 40 GB disk, vCPUs with the card (4 to 16), rented by `oneshot.py rent <label> <lane> <hours> [gpu-type] [min_vcpu] [min_ram_gb]` with the purpose and lane in the registry row, destroyed on "done", at <hours>, or by the idle meter; long runs under setsid nohup with a pid file under /root/fleet/out/. Spend at 18:26Z: USD 413.32 of the 1,000 UK-day ceiling (work 165.55, leak 247.77), the standing fleet about USD 197 a day. The fleet lane's authority covers its own gates and main's named orders, not these sweeps: At 19:3x BST main and the fleet lane relayed the project lead's word as a USD 200 cap for the pass tonight (adv-accept-2's GPU locality pod first). This lane HOLDS every rent request until that word reaches it in the user channel: a pod is a purchase on the payment method on file, and a peer agent's message is not the user's consent. When it arrives, each request goes to the fleet lane as purpose + lane + hours + pod type; the fleet lane destroys each pod at the end of its sweep and reports at each USD 100; this lane reports to main at USD 100 and at the cap |
| First results | Every lane's report carries first results by 00:00 BST, 8 October, with the box-hours and pod-hours spent, the bound reached honestly, and one line on what a longer pass would add (not a reason to wait) |
| The box-hour line is a reading | 8 box-hours per lane, 24 in all, is read and reported to main when crossed, not a stop; 16 per lane, 48 in all, is the ask line |
| Exceptions only | The coordinator reports to main only exceptions (a lane blocked, a box contended with a build, a leak of a withheld input) and clock readings (each plan's arrival, each first result, the spend crossing 16 box-hours or USD 100 of pods) |
| Lanes | First results | Ask line | Notes |
|---|---|---|---|
| adv-mixer, -2, -3 | 8 box-hours each | 16 each | the algebraic search; the 2^24 day-key census; SAT and MILP on reduced applications |
| adv-cache, -2, -3 | 8 box-hours each | 16 each | the curve; one 256 MiB fill per day key and the 2^28 census (memory stated per run); small-scale exhaustive chain models |
| adv-accept, -2, -3 | 8 box-hours each | 16 each | the 10^6-seed searches sharded across idle cores; the header search; the exhaustion census |
| Total | 72 box-hours (a reading; 24 was the three-lane line main approved at 19:1x BST) | 144 (ask) | a box-hour is one 32-core slot-equivalent for one hour |
Box 2 at 18:5x BST: load 23 on 96 cores, 3 slots free. Build-1 is the busier box (gates and release builds); nice 10 is what keeps those ahead. A run over 10 minutes is built through `tools/build-remote.sh` (`--box 1` or `--box 2`, whichever has a free slot) and started on the box with `nohup`, `nice -n 10`, a pid file beside its log under `/srv/builds/_adv-<lane>/` on each box, NEVER inside the worktree mirror `/srv/builds/igneum-wt-<worktree>/` (build-remote.sh's source sync deletes anything there that is not in the tree; adv-cache lost its first logs to it at 19:16 BST); finished logs copied into `docs/analysis/cryptanalysis/logs/<lane>/` on the branch; killed by pid file only. No GPU tonight: a GPU measurement is BLOCKED and says so. Nothing runs on the Mac.
## 5. Deliverables
| Deliverable | Content | When |
|---|---|---|
| The attack plan | The target restated from the spec and code in the lane's own words; the questions in the lane's order; the method and tool per question; the known-failed shape per method (a planted weakness the tool must fire on); the box-hour estimate per step; every file opened | within two hours of start |
| The report, attack-pass shape | A header with the target commit, the binary's sha256 and the box; a status board with one row per question (method, known-failed shape, gate, result with numbers, status PASS / RUNNING / BLOCKED / FINDING); one section per row with the exact command, the seed, the log path and the numbers | first results by tomorrow evening UK; pushed as it grows |
| Attack code | Under `tools/attack/adv-<lane>/`, its own crate depending on `igneum-pow` by path; the originals of f8-uniform and f4-weakday untouched | with the report |
## 6. Review
| Role | Who | What |
|---|---|---|
| Defender | The Counter ASIC lane | Reproduces every BREAK from the command and the seed before any ruling; checks every BOUND's effort statement against the box logs; reads each plan's opened-files list against section 3.2 and voids a lane's result that used a withheld input |
| Ruling | Main | Disputes between a lane and the defender; what a confirmed finding moves (section 9); extensions of the box-hour ceiling |
| Coordinator | This lane | Spawns and clocks the lanes, keeps this file, collects the reports, writes the ledger rows when main says so |
A finding is not a failure of the pass. It is the reason the pass exists.
## 7. The clock
| Step | UK time |
|---|---|
| Lanes spawned | 7 October 2026, 19:1x BST |
| Plans pushed to the mirror | the first three by 21:10 BST, the six of 19:2x BST by 20:25 BST, 7 October |
| First results in each report | by 00:00 BST, 8 October (every lane) |
| Defender's read of each report | within 24 hours of its first results |
| Disputes to main | as they arise; ruling before any public sentence moves |
## 8. The label
Every sentence about this pass that could be quoted in public carries "internal adversarial pass, not an independent review". The site, the litepaper and `docs/evidence.md` row 17 said "the cryptanalysis plan buys three external lots" and "the three cryptanalysis lots are the next test"; main lands the replacement. No public text names a firm, a price or an engagement.
## 9. What a finding moves
| Case | What moves | Cost |
|---|---|---|
| A BREAK confirmed before the public testnet's vectors freeze | A parameter or a shape on the v4 seam, or a class v5 rule; the packs and the 96-vector sets re-cut through the seam, the verifier re-measured against the 10 ms gate, the soundness suite re-run, the cross-vendor fingerprints re-taken | hours of agent work; one PC job per vendor; no chain event |
| A BREAK confirmed after the testnet's first miner | A class change behind its activation height with the six gates and the two-publish rollout | an announced reset on the testnet; on mainnet the governance event the plan exists to avoid |
| A BOUND only | The chip model's "ops per hash" input carries an internal effort bound in place of "no cryptanalysis"; it is labelled internal, never "reviewed" | the box-hours only |
## 10. What this pass is not
It is not an independent review and is never called one. Nothing is sent outside, nothing is paid, nobody is contacted. The disclosure prize (USD 50,000 for a reproduced break of the published hash class, approved by the project lead 7 October 2026, 09:5x UK) is the only outside check and stays STAGED: announced only when escrowed, only when the entity's registered address exists on its documents, and only on the project lead's publish word. The entity is not yet named in the repository beyond the launch pack's "Igneum Labs LTD". Until the word, `grep -ci "50,000" site/*.html` is 0 and `disclosure prize` stays in `site/forbidden-strings.txt`.
## 11. The coordinator's own inputs (defender side, not given to the lanes)
`docs/plans/funding.md` (the row and the brief), `docs/plans/cryptanalysis.md` on branch `cryptanalysis` (sections 1, 3.3, 3.4, 4.2), `docs/plans/counter-asic-3-status.md` section 7c, `docs/plans/release-0.3.22.md`, `docs/analysis/attack-pass-2026-10.md` (the report shape), `docs/plans/build-server.md` sections 7 and 7.0, `infra/build-server/lib.sh`, `tools/build-remote.sh`, the spec at the frozen commit, `docs/plans/launch-pack.md` and `docs/plans/testnet-go.md` LG-13.
## 12. The board (clock readings and the defender's lines; UK time; box file times read in CEST, one hour ahead)
| Lane | Plan on the mirror | First results | Defender's line | Box-hours |
|---|---|---|---|---|
| adv-mixer | 1d720654, 19:09 BST | e35556af, 19:40 BST: Q1 algebraic structure BOUND (fold probe 1e6 of 1e6 affinity violations, 0 of 256 dead word pairs, 0 of 1e6 key-order agreements; integral degree at least 16 after one application, saturated after two; 9,360 ops per item stand); courtesy readings on Q2 (full diffusion at 2 applications, margin 6 of 8) and Q3 (2^24 days, best day 1.17x FPGA multiply datapath, 1 in 2^24, no DSP or wall-time gain) | pending | 0.4 |
| adv-mixer-2 | 5704a7b3, 19:32 BST (IDENTICAL at 7a7caa34 and 04c4d9bc; about 4 box-hours estimated) | tip ae3088a9, 21:3x BST (first word from the lane since spawn): harness built on both boxes (binary 88f6a3ed, outside the mirror), two chains waiting at class adv, 32 threads (box 2: the 2^24 census, the calendar, the small-constant-multiplier calendar and tail, avalanche; box 1: the 2^32 census and the redraw census); nothing hand-started beyond three sub-11 s smoke runs. Rows in hand: the exact 32-bit weight tail by convolution gives P(gain A at or above 1.1x) = 2^-7.9 per day (A to be defined against the chip model in the row: a chip wall-time or DSP gain, or a per-day FPGA datapath-area gain, which the model does not credit as rate; a redraw rule is proposed); model C exact P(k at least 1) = 2^-15.0; all six plants fire. The coordinator wrongly chased this plan as overdue between 20:25 and 20:32 BST | pending | |
| adv-mixer-3 | 37a08b6c, 19:4x BST | rows committed before the 20:21 BST kill (3cb6c1df and later): line-index bits uniform at 0 to 8 applications on day 20729; the SAC and linear bands clean at 2 to 8 applications on both days (a k = 1 statistic exists, the known single-application diffusion); rotational-XOR clean at 1 to 4 on both days; SAT at 1 application; THE ROUND MARGIN AS IT STANDS: no statistic survives 2 of the 8 applications between reads. Lost to the kill: SAC at 5 to 8 and its 2^27 rows, the 2^28 SAC-zero rows on 20733, the index census on 20733 at 2 to 8, CaDiCaL at 2 to 4; re-queued as queue 17 through the lease. Earlier: sweeps on both boxes from 19:42 and 19:47 BST (index census, SAC, differential, linear, rotational-XOR on days 20729 and 20733; the SAT model under CaDiCaL 3.0.1) | pending | |
| adv-cache | 476e4516, 19:04 BST | 2c7bb6b4, 19:33 BST; FINAL 49ef7747, 19:50 BST: every row BOUND, every plant fired (the recompute curve monotone toward the full store, f = 1/2 at 1.26x the ops and 0.875x of the full-store chip's rate under equal silicon; no cheaper fill; chain avalanche full at every j; line index uniform over 160 day keys and about 1.6 x 10^10 reads; batching loses to the stride store from 32 MiB) | 19:5x BST, NO DISPUTE: Q1b, Q1c and Q4 stand as BOUND from the defender (the curve equals logs/queue-a/curve.log row for row; target 017e7037; ledger honest; energy columns from chip-model-v3 5.2); Q2 and Q3 were measured before the re-scope and stand as readings for adv-cache-2 to confirm or contradict, not as its verdict | 0.55 |
| adv-cache-2 | 3d9bcece, 19:31 BST | tip 46551013, 21:2x BST: the 2^35-read line census PASS over 272 days; the 16,384-day weak-day scan PASS; the site finding is now a CLASS: 3 of 432 load sites (Devnet 3 site 0; era-fixed-20 site 11; era-drawn-2 site 13) concentrate item reads 1.26x to 1.45x at their top 0.1 percent, each attributed to the shadow block's last write to the load's source register (mul: the product low-bit law 0.25, 0.375, 0.4375 on bits 0 to 2, measured exactly; mulhi: a 52x hi16 bucket and one item read by 16 whole warps; sub), worth 0.03 to 0.1 percent of a hash's reads each; handed to adv-accept's freshness question in the report. Earlier: first rows 19:5x BST (report being pushed): tip 4f470d40 at 20:23 BST, about 0.95 box-hours, killed its one running census at 20:20 BST (11 of 32 drawn programs kept as partial), re-queue pending on the lease; two FINDING rows for the defender: Devnet 3 load site 0 (instruction 3) non-uniform at the item level (chi2/dof 3.70 at 2^26, top 0.1 percent at 1.449x its control, a fixed per-item weight from iteration 1, a low-bit bias of its source register; worth 0.1 percent of a hash's reads to a store); and the chip model's f = 0.25 and f = 0.5 partial-store rows overstate the recompute share at the measured window hit rates (0.883x and 0.838x of its ops per hash at the mean; 0.56x for Devnet 3's half; the full-store verdict unchanged). Earlier: Q1 line census at 2^31 reads PASS (segments +4.84 sigma against a control at +4.24; top 1 percent of lines 1.1198 against 1.1196 percent); Q3 steering PASS (worst cell 3.95 sigma); Q2 Devnet 3 at 2^24 nonces: fingerprint e510ad92b4d24846 reproduced through its mirror, items and lines clear against the window-model control (1.003x), one load site (site 0, instruction 3) non-uniform at chi2/dof 1.67 and 1.29x at its top 0.1 percent, worth 0.03 percent of a hash's reads; the window layer puts 36 to 45 percent of reads in one aligned quarter (model exact to 4 digits), being priced against the chip model's partial rows | pending | |
| adv-cache-3 | 9fdd4031, 19:49 BST | report 091edc34, 20:29 BST, 0.04 slot-hours; FINDING, bookkeeping not a break: the exact pebbling optimum (DP, checked against exhaustive search at 10 to 16 lines) sits under the "hold every k-th line" curve the chip model and adv-cache's Q1b table use: 16.0 against 31.5 blocks per read at f = 1/64 (the one held line belongs at line 32, not line 0), 10.5 against 15.5 at 2/64, 6.09 against 7.5 at 4/64, 3.17 against 3.5 at 8/64, 1.45 against 1.5 at 16/64, equal from f = 1/2; so a chip holding 1/64 of the cache pays 9.3x the item's ops, not 17.4x; at f = 1/2 nothing moves and the SRAM column stands (a line owed in chip-model-v3 and in adv-cache's table). Plant caveat stated: the per-bit bias and 512 x 512 correlation statistics do not fire at one or two double rounds (worst 4.5 sigma at 2^16 lines); the firing known-failed shapes for the relation class are the GF(2) rank (1,004 of 1,025 at one double round, 17 at zero), the flip table (6,985 zero cells at one double round) and no-feedforward on the inversion; a larger flip table is being added. First rows 20:2x BST: every gate PASS, every plant fired (0 of 65,536 lines under j + 1 at 64 and at 1,024 lines on two day keys; GF(2) rank 1,025 of 1,025 at j = 1, 2, 32, 63, 1,023; no zero cell in the 512 x 512 dependence table; 0 inversions; feed-forward relations over 4 days x 2^20 lines worst bias 3.58 sigma, worst correlation cell 4.83 sigma of 262,144; the pebbling optimum curve monotone with 9,360 ops at f = 1, the skip-edge plant fires; cross-segment and cross-day worst 5.00 sigma); its 87-core build-2 lease released at 20:24:38 BST for the v5 census, the w = 2 image census partial at depth 8 of 64, the rest queued behind any v5 waiter. Earlier: its three definitions (90 to 92) claimed 19:49:54 BST, by itself on the timing (owner files were not yet the rule); adv-cache offers its chain-skip, pebble and ffrel implementations on branch adv-cache as a harness, and does not run them | pending | |
| adv-accept | d2bc4dc8, 19:1x BST | a22d5ba0, 19:51 BST, FINDING-class row: one accepted class v4 program (F8 label-space seed 100767, id 9d68e6286fc817d4, attempt 2) passes every part of the frozen rule and flags the f8 hot-set gate on the live dataset at 2^24 nonces (X at 0.1 percent +0.155, X/f 1.55, top 0.1 percent at 2.05x the window model, 6-sigma +295); the four lowest stand-in-ratio seeds of 4,600 accepted programs all beyond 1.2x live (1.29x to 2.05x), 23 random accepted programs at most 1.043x; attribution one load site (instruction 23, source r6, quarter window) sending 3.35 percent of its reads to items at multiples of 2^19, (c') saturation 0.013 percent there; the lane's price: a 1 MB hot copy serves 0.31 percent of loads instead of 0.15, a 1.002x gain, no chip-model row moves; "a real distinguisher and a cheap seed selector, not an exploitable bypass". Q2 stand-in gap BOUND so far (agreement to 2e-4 at 2^20 on 4 programs plus a firing plant; 50-program widening running). 20:06 BST, tip 12e0e9fa: Q2 BOUND landed on 54 accepted programs (closed-form and live per-site ratios agree to 0.0004 at 2^20, mean min-ratio gap 0.00002, 0 verdict disagreements, (c) metrics agree to 0.019 of 128; no steering through the stand-in gap); the selector read widened and honest: of the 8 lowest-ratio seeds measured live, 6 beyond the 1.2x gate and 2 not (103378 at 1.157x, 105756 at 0.9996x), so the 256-unit stand-in ratio is a noisy selector at the 0.996 level; random control 0 of 4 beyond (max 1.0034x); 17 lowest and 16 random rows running at about 7 minutes each; the class v5 exemplar check and the repeated-index read queued behind the lock. Row 90 (adv-accept-3's attempts census) claimed and running. Killed every run at 20:21 BST (both shards, both adv-live chains, the census, the attempts census), 0 binaries alive, partial kept: 23,321 accepted-program rows, 17 live rows at 2^24 (11 lowest-ratio seeds: 6 beyond 1.2x, 5 within; 11 random: 1 beyond), Q2 BOUND on 54; re-queue order through the lease: the shards from their frontiers, the 14 and 9 remaining live rows, the class v5 exemplar check, the repeated-index read, row 90 | 19:5x BST, FINDING CONFIRMED, bounded, no dispute on the numbers (read against live-confirm-16m.log): (c'') passes at ratio 0.9988, inside the clean spread, the shape of the four-seed tail AP-F8-1 left unattributed; the source is zero in 0.0126 percent of evaluations (under (c')'s 1 percent) and the hot items are the images of small source values under the era stride; the class is a value-level constant from a lineage-fresh writer (a mad at instruction 4), which neither the lineage rule nor the per-site ratio at 2^20 reaches. NEW and the finding's substance: the stand-in ratio is a cheap seed selector without the live dataset, and one member of the unattributed tail is now attributed by value. Routing: FINDING (bounded) on class v4 sub-version 3, no change to the frozen object, chip gain nil; the fix question (a value-level source test at the live-dataset scale, or a per-site hot-item test in acceptance) goes to class v5 / 0.3.23 beside AP-F4-1 and AP-F1-1; taken to main as an exception. Asked of the lane's final: the selector's false-positive rate over at least 20 low-ratio seeds; whether the seed reads hot under class v5's state-derived dataset. ANSWERED 20:37 BST: under class v5 (vendored class-v5 igneum-pow, generator 5, id 2fd83dbae09c366d, dataset keyed by the Devnet 3 v5 pack's state stream) at 2^24 nonces the seed reads the SAME hot set as under v4 (X at 0.1 percent +0.15514 against +0.15503, 2.046x against 2.045x, the same eight hottest items at multiples of 2^19, site 6 at 3.36 percent of its reads; plant fired at 25.7x; 589 warps agree with the library): the concentration is the program's dataflow at site 6 plus the era stride, not the dataset's values, so class v5's dataset change does not touch the finding and the price stays 1.002x; the acceptance-side fix is the only lever. DEFENDER'S READ, 20:4x BST: taken, and it is the CONFIRMING ROW for the class v5 fix (c'''), NOT a v5 finding: id 2fd83dbae09c366d is the pre-(c''') class v5 draw at attempt 2 (the vendored class-v5 igneum-pow before ab6f980b); under the frozen v5 rule the same seed is refused at attempt 2 by (c''') naming site 6 at 0.991 and the draw lands on attempt 4 (734fbb8e3e4cd20f), as the v5 lane's known-failed test read green at 20:33 BST; the lever is the acceptance floor, now 0.995 keyed on the state flag; the number still owed on the fix is the census's clean rejection rate, from the v5 lane. SELECTOR TALLY at 2^24, 21:1x BST (the re-submitted chain got build-1 cores at about 20:55): of the 16 lowest stand-in-ratio seeds, 9 beyond the 1.2x gate and 3 HOT SETS by the f8 test (100767; 4346 at X 0.1 percent +0.178, X/f 1.78, 2.24x the window model; 5245 at +0.129, 1.29, 1.86x); of 17 random accepted programs, 1 beyond and 0 hot sets; each hot set about 1 MB of items holding 0.3 percent of reads, gain about 1.002x: the distinguisher is real and repeatable, the bypass not exploitable. The class v5 (c''') census (the v5 lane, ended 21:03 BST): 2.435 percent of accepted programs rejected by the 0.995 floor. Whether the floor closes the CLASS rests on two numbers still owed (21:1x BST): the minimum-site ratio of seeds 4346 and 5245 at the acceptance's 2^20 sample; 100767 reads 0.9919 and is refused; a seed at or above 0.995 while hot live is a residual the floor misses and goes on the board as such. WIDENED by main at 21:2x BST to FIVE programs (4346, 5245, Devnet 3's epoch-0 program fce15bf61030be57 at site 0, adv-cache-2's era-fixed 20 at site 11 and era-drawn 2 at site 13): one `lease pool 8` job through adv-accept's gap tool, each read as under 0.995 (refused by (c''')) or at or above it (a residual the floor misses); the results go to main and the v5 lane the minute they land; the board's class line reads "the floor closes the class" only on those five numbers, because Devnet 3's own first program is one of them. The class in the record: one class, a value-level property of the load's source register written by the shadow block's mul, mulhi or sub (or by the base program, as for 100767), 3 of 432 sites plus 100767, 0.03 to 0.3 percent of a hash's reads each, chip gain at most 1.002x | about 1.6 |
| adv-accept-2 | 9b86d4e2, 19:4x BST | FINAL 92168536, 21:17 BST (natural end; 0 processes, leases or queue entries on either box): the 1e8-hash tail per real program sits on the windowed baseline down to 3e-7 (deepest unit 51 of 4,096 rows, 7 past the baseline's own deepest, net 3e-7x priced); the rotate-identity repeat class is in 21.0 percent of 300 accepted drawn programs, under 0.1 percent of loads on the worst, absent from the two real programs. Earlier final 3df22a4c, 20:42 BST: BOUND with one 0.1 percent per-program FINDING (drawn program 0x5d7cc2b09fc6922a repeats a word across load sites 1 and 5 in 1.55 percent of hashes per iteration: the only write between them is a rotate by a register amount, the identity 1 in 32, and site 1's quarter window lies inside site 5's half window; header-independent; admitted by the 120-of-128 floor); about 0.7 core-hours and 0.3 pod-hours; a 1e-6 tail and a 300-program prevalence census of the repeat class append when the pool serves them. Earlier: tip 74b8f3a1, 20:2x BST: Q1 to Q4 all landed, BOUND, with one per-program FINDING at 0.1 percent; the A6000 card row: the best header-ground groups read +0.09 percent dependent-read throughput at 15 hashes each against random, the const-site plant +6.3 percent (log logs/adv-accept-2/gpu-rowbench-a6000-2048x200.log); one more leased run follows for the 1e-6 tail and a prevalence census of the finding. Earlier rows (tip 9e8b1326): the two real programs and 8 drawn ones match the windowed random baseline at mean, min and the 1e-3, 1e-4 and 1e-5 tails for 2 KiB rows, 8 KiB rows, 64 B lines and items, per hash and per unit (closed form and live agree); one-bit header flips move 100.00 percent of the 4,096 unit addresses (the header-blind plant reads 0.0000); 2 to 4 of 16 load sites in iteration 0 are header-predictable, none later; both plants fire; the pod measures one point (dependent-read throughput of the best header-ground units from 1e7 hashes against random units and the two planted-clustering programs), "done" expected about 22:45 BST. "done" given at 20:2x BST; destroyed 20:27 BST and verified absent from the provider: 0.58 hours, USD 0.31 (plus a duplicate the fleet's retry loop rented the same minute and destroyed within two minutes, about USD 0.02). The pass's pod ledger: one pod, USD 0.33 in all, none originated by this lane; nothing of the pass remains on the fleet. Reading from the code: the header reaches the hash only through the init words (bind.rs) and never the program or the dataset, so a found header fixes one 32-lane group and a grind cannot amortise; GPU per-card confirmation BLOCKED, bound analytic; a GPU pod for the one BLOCKED confirmation was rented by the fleet lane under the word it holds (not by this lane): RunPod secure RTX A6000 48 GB, READY 20:06 BST, 3 hours, USD 1.59, registry label adv-accept-2-pls4, destroyed on the lane's "done"; the SSH line routed to the lane at 20:0x BST | pending | |
| adv-accept-3 | 57fd32ea, 19:58 BST (spawned 19:5x BST after three attempts at the subagent cap) | report v1 cde2562f, 20:24 BST: 0 verdict disagreements between the code and a second interpretation over 2,546 attempt verdicts of 792 seeds; the (c'') f64 compare cannot flip a verdict at the shipped constants (margins 0.32 to 0.44 counts, 0 of 2^20 disagree); FINDING, documentation class: program.json's program_id_derivation string and spec 1.4.6 omit the "sub/" || 3_le16 suffix the code appends under generator 4 (text-derived id 30956569d8f3d8d7 for Devnet 3 against the pack's fce15bf61030be57), so a second client written from the text would disagree on every program id; the code is the consensus, the text and the exporter string are wrong; queue 93 to 99 re-queued through `lease pool 40` at 20:24 BST | pending | |
Beside the nine lanes (the attack-pass lane, the defender's side, for the record): F4 on class v5 PASS at igneum-pow class-v5 e4f1f275 over 2^24 chain days (M2 0 of 2^24 over 1.1x; M1 the same bounded tail as class v4; the census byte-identical because the day-key draw depends on the mixer shape alone); F8 on v5 read about 20:55 BST; F1 and F9 at 10^5 seeds after (10^6 is fifty hours through (c'')).
Box readings: 19:5x BST both boxes at load 280 to 350; 19:55 BST build-1 496 / 391 / 252 and build-2 527 / 469 / 290 on 96 cores (adv-accept two 89-thread shards and three adv-live confirmations, adv-mixer-3 six processes on build-1 and two plus two CaDiCaL on build-2, adv-cache-2 81 and 19 threads): oversubscription; the per-box sweep lock added and every lane told. adv-cache FINAL 555c3e42 (19:55 BST): idle, done; its implementations of adv-cache-3's three sweeps offered in its section 8a, not run.