igneum/docs/analysis/cryptanalysis/report-mixer-2.md
igneum-labs 86bec7ec00 adv-mixer-2: report closed: redraw 2^28, final ledger and bound
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 22:36:54 +00:00

34 KiB

Report: the day-key weakness class of the mixer M_r (lane adv-mixer-2)

Internal adversarial pass, not an independent review. Every sentence below that could be quoted carries that label.

Header

Field Value
Target commit 017e703764 (class v4 sub-version 3, object byte 7)
Target the per-day draw of ROT[0..7], MUL[0..15], RC[0..15] for M_r (spec 01 section 1.8.4), class v4 (x8, 72 applications per item)
Branch adv-mixer-2 from build/master 7a7caa34, merged 04c4d9bc; plan 5704a7b3; harness ae3088a9
Byte identity git diff --quiet 017e7037... HEAD -- igneum-pow printed IDENTICAL at 7a7caa34 and at 04c4d9bc (the whole crate)
Harness tools/attack/adv-mixer-2 (binary adv-mixer-2), igneum-pow by path, nothing re-implemented
Binary sha256 88f6a3edfffad166d35a3bcadcaff7907613e710b842cfcbe94fbb1601f7c37b for queue 01, 02 and the exact run; b5d823aa14da80d0b02fc2e02666a70af1ce14fe464ad683be9616a4b5df5179 from 21:39 UK (the model B certificate restructured; census, exact, calendar code unchanged), identical on both boxes, at /srv/builds/_adv-adv-mixer-2/bin/
Boxes igneum-build-1 and igneum-build-2, rustc 1.99.0; every sweep through /srv/builds/_bin/lease pool at class adv, 32 cores, --min 16, nice 10
Logs /srv/builds/_adv-adv-mixer-2/logs/ on each box; copies in docs/analysis/cryptanalysis/logs/adv-mixer-2/
Price chip-model-v3.md 5.2: 128 ops per application hoisted, 9,360 ops per item; the spec's 130 per application
Clock UK time throughout

What the per-day gain means, and for whom

The honest miner (any GPU) and the CPU verifier run memhard::mixer with the day's constants as operands: 16 multiplies, 16 XORs, 32 adds, 32 XORs, 32 rotates per application, the same instruction count on every day. A multiplier unit costs the same for MUL = 3 as for MUL = 0x9E3779B9. So under chip-model-v3's op count (9,360 ops per item, value-independent) the per-day gain is exactly 1.0 on every day for every GPU, for the verifier, and for a chip with a general multiplier. The chip model credits hash rate only through that count.

The day's constants matter only to a datapath that bakes them in. An ASIC cannot be masked per day. An FPGA bitstream can be synthesised per day, and that is the only per-day attacker; its per-day gain is an AREA gain (fewer LUTs per multiplier, so more copies of the pipeline per device), which the chip model does not price as hash rate. The three cost models of this lane read that area:

Model What it measures For whom Gain over 1.1x on more than 2^-20 of days?
A, LUT shift-add (64 + sum of (w32 - 1)) adder-equivalents per application with every multiplier as a canonical signed-digit shift-add chain; rotations and constant XORs free a per-day FPGA build with multipliers in LUTs; not a wall-time gain for any chip YES: P(cost A <= 205, gain >= 1.102x against the exact median 226) = 5.694e-4 = 2^-10.8 per day (exact, 16-fold convolution of the w32 table over all 2^31 odd constants; about 21 days per 100 years). 1.2x: 2^-28.8 (1 day in 2^28). 1.5x: under 2^-91
B, certified shift-add the same datapath with each multiplier at its certified chain (exact for 1 to 4 adders, decomposition certificate for 5) the same FPGA, closer to what a synthesiser achieves; an upper bound on the attacker's cost per word NOT READ AS A GAIN: 12.3 percent of words are certified at 5 or fewer adders, 0.38 percent at 4 or fewer; the remaining 88 percent carry their model A cost, so cost B's spread between days is the certificate's reach, not the attacker's. What it does establish: a synthesiser's real per-day variation is smaller than model A's, because every certified word collapses to 5 whatever its w32 (7 to 13 in the tail days)
C, DSP 16 / (16 - k) with k the words whose constant has a 2-adder chain and leaves its DSP block a per-day FPGA build with multipliers in DSP blocks (value-independent) NO: k >= 1 gives 1.067x on 3.123e-5 = 2^-15.0 of days; the first gain over 1.1x is k >= 2 (1.143x) on 4.57e-10 = 2^-31.0
Chip model (ops per item) 9,360 per item, value-independent every GPU, the verifier, any chip with a general multiplier NO: the gain is 1.0 on every day

Threshold used: the brief's, a gain over 1.1x on more than 2^-20 of days. Model A crosses it by 9 binary orders; model C and the chip-model reading do not. The redraw rule below is proposed on the model A reading, because the census of a public calendar is the attacker's cheapest tool and a 10 percent area edge on 1 day in 1,750 is free to take even if it buys no hash rate against the chip model's attacker. The worst real calendar day is 29337 = 2050-04-28 (cost A 203, model A gain 1.113x, model C 1.0, chip model 1.0); the 15 days over 1.1x in 100 years are listed in Q4 below.

Status board

Q Method Known-failed shape Gate Result (numbers) Status
Q0 plants plant on the day-20729 draw with one field replaced, through the same classifier alleq, rot1, mul1, mul1all, rcrk0, weakday (all ROT equal and MUL = 1) every plant lands in its class with its gain all six fire: alleq -> "ROT all equal" (cost 219); mul1 -> "MUL any = 1", gain 1.1053x; mul1all and weakday -> cost 64, gain 3.61x, model C k = 16; rcrk0 -> "RC + rk = 0"; rot1 -> "ROT all 8 in {1,2,30,31}" PASS
Q3 exact tail, model A w32 over all 2^31 odd constants (exact), 16-fold convolution the table must give 2 constants at w32 = 1 (1 and 2^32 - 1) and the mean must match the census mean w32 11.1111; mean cost A 225.78, exact median 226; P(gain >= 1.05x) 4.72e-2; >= 1.1x 5.694e-4 (2^-10.8); >= 1.15x 1.66e-6 (2^-19.2); >= 1.2x 2.13e-9 (2^-28.8); >= 1.3x 2.07e-16; >= 1.5x under 2^-91 FINDING (area reading), crosses 2^-20
Q3 exact, model C exact 2-adder set (4,192 odd constants, 2^-19.0 per word) the set must contain 1, 2^32 - 1, 2^s +- 1 P(k >= 1) 3.12e-5 (gain 1.067x), P(k >= 2) 4.57e-10 (1.143x) PASS (bound: under 2^-20 at 1.1x)
Q1 census 2^24 census --from 20729 --count 2^24 (32 structural classes, cost A histogram, model C) plants above counts against the analytic expectation 16,777,216 days in 0.3 s on 24 leased cores: gain A >= 1.1x on 9,525 days (5.677e-4, 2^-10.8; exact 5.694e-4); >= 1.2x on 0; min cost 191 (1.183x, day 4819563); model C k >= 1 on 511 days (exact expectation 524), k >= 2 on 0; ROT all equal 0 (expected 6e-4); MUL = 1, MUL = -1, MUL involution, MUL two equal, RC = 0: 0 each; every class within its expectation (table below) PASS (census agrees with the exact table)
Q2 census 2^32 census --from 20729 --count 2^32 (every chain day for 11.7 million years) plants above the model A tail against the exact table 4,294,967,296 days in 615 s on 32 leased cores: gain A >= 1.1x on 2,445,332 days (5.693e-4; exact 5.694e-4); >= 1.2x on 6 days (1.40e-9; exact 2.13e-9); min cost 184 (1.228x, day 3783398695); model C k >= 1 on 133,584 (exact expectation 134,140), k >= 2 on 2 (expected 2.0, gain 1.143x); MUL = 1 on 36 days (expected 32), MUL = -1 on 38, RC = 0 on 11 (expected 16), RC + rk = 0 on 1,214 (expected 1,152), MUL two equal on 227 (expected 240), ROT all equal 0 (expected 0.16); every class within its expectation PASS (the exact table holds to 2^32)
Q4 the real calendar calendar --from 20729 --years 100 (36,525 days: 3 October 2026 to 3 October 2126) the planted stream-shift pair must be found (it was) worst day with date under A and C worst day 29337 = 2050-04-28, cost A 203, model A gain 1.113x (an FPGA area gain; 1.0 for every chip and GPU); 15 days over 1.1x in 100 years (exact expectation 20.8), none over 1.2x; model C: no day with k >= 1 in 100 years (expectation 1.1) FINDING (area reading only)
Q5 cross-day structure seed collisions, stream shifts by k in 1..72, shared MUL and RC values over the calendar planted shift pair (found) counts against expectation 64-bit seed collisions 0 (expected 3.6e-11); stream shifts 0 (expected 5.2e-9); MUL values shared between two days 77 (expected 79.5), RC 39 (39.8): chance, and a shared constant hands a datapath nothing (the other 39 draws differ) PASS (BOUND: nothing beyond chance)
Q2 model B scm-refine on the calendar (36,525 days), on the lowest 2^14 days of the 2^24 census, on a 2^16-day random sample the self-test constants (3, 5, 7, 9, 2^32 - 1, 2^31 + 1 at 1 adder; 45 at 2): all as expected the certified-cost distribution exact sets: 90 constants at 1 adder, 4,101 at 2, 185,223 at 3, 7,983,205 at 4 (0.38 percent of odd constants at 4 or fewer under the restricted form); random words certified at 5 or fewer: 12.3 percent; the rest uncertified. Cost B is a PARTIAL metric (a certified word costs 5, an uncertified one w32 - 1), so its between-day spread (sample: mean 219, min 176; calendar worst day 43959 = 2090-05-10 at B 181) is the certificate's selectivity, not a measured gain, and is not read as one PARTIAL (bound on the per-word chain length only)
Q6 ROT diffusion avalanche (1, 2, 3, 4, 8 applications; the 22 address bits; 1,024 states x 512 input bits) on the genesis day, the plants, the 7 worst ROT days of the census plant rot1 and weakday must read weaker than the genesis day at 1 application: they do (mean flip 0.345 and 0.324 against 0.461; 16,197 and 11,454 input-output pairs never flipped against 5,534) a per-day gain only if a bit-exact shortcut follows at 2 applications every day, planted days included, reads mean 0.500, every output bit between 0.42 and 0.58 (sampling spread of 1,024 states), address bits 0.500, no pair unflipped; 8 applications sit between reads. No day gives a shortcut; gain 0 PASS (BOUND)
Q7 redraw rule redraw-census 2^24 and 2^28 days with the rule below --max-cost 0 must reproduce the real draw on 1,000 days (asserted in the binary; passed) fraction redrawn; residual over 1.1x must be 0 2^24 days: 10,014 redrawn once (5.97e-4), 7 twice (4.2e-7), none three times; after the rule gain A >= 1.1x on 0 days (min cost 206, 1.097x), model C k = 0 on every day, ROT all equal 0; mean cost 225.79 (225.78 before), the 1.05x fraction 4.67e-2 (4.72e-2 before): the rule touches only the tail. 2^28 days: 161,258 redrawn once (6.01e-4), 87 twice (3.2e-7), 0 three times; after the rule 0 days over 1.1x, min cost 206 FINDING closed by the rule (after-fraction 0 on 2^24 and 2^28)
Q8 anything else watched while the rows ran; three observations, no box time n/a stated or measured (1) Lead time: the only per-day attacker is an FPGA bitstream synthesised for the day, and synthesis of a full-device design takes hours (approximate, from memory; no figure measured here). Under the interim day rule (bind::day_bytes, a pure function of the calendar) the attacker has unlimited lead; under the spec's own proposal O-1.10 (day bytes carry the first epoch seed of the day, known about 20 minutes ahead, section 1.12) a per-day bitstream cannot be ready in time, which removes the whole class without a redraw. (2) The mixer stream is seeded by 64 bits of the day key (K[0], K[1]); K[2..7] enter only the item init; no collision or shift was found in 100 years or 2^24 days, and the planted shift was. (3) The 72 round keys are fixed multiples of 0x9E3779B9; RC + rk = 0 happened on 10 of 2^24 days (expected 4.5, within Poisson) and costs a datapath nothing on either side PASS (stated)
GPU rows none needed no row of this class depends on a GPU BLOCKED (not applicable)

Q7: the proposed redraw rule

Rule, for the day's parameter draw (spec 1.8.4): after the forty draws, compute cost A = 64 + sum over the sixteen MUL of (w32(MUL) - 1), and the count k of MUL values with a 2-adder chain. If cost A <= 205 (a model A gain of 1.1x or more against the median 226), or k >= 1, or the eight ROT are equal, continue the SAME SplitMix64 stream and draw all forty again; repeat until accepted. The honest miner and the verifier pay forty more 64-bit draws per redraw, once a day; nothing else changes; every accepted day is a day the current rule could have drawn.

Quantity Value
Fraction of days redrawn at least once exact 5.694e-4 + 3.123e-5 = 6.0e-4 (2^-10.7), about 22 days per 100 years; measured over 2^24 days 5.97e-4 once, 4.2e-7 twice, never three times
Fraction over 1.1x under model A after the rule 0 measured over 2^24 and over 2^28 days (min cost 206, gain 1.097x). Before the rule, measured: 5.677e-4 (2^24 census), 5.693e-4 (2^32), 4.107e-4 (the 100-year calendar, 15 of 36,525 days)
Fraction over 1.1x under model C after the rule 0 (k = 0 on every accepted day)
Chip-model reading after the rule unchanged: 1.0 on every day before and after
What the rule does not fix the seed is 64 bits of the day key (K[0], K[1]); the day is a pure function of the calendar; both stand; neither is a weakness of this class on the numbers above
The alternative that removes the class the spec's O-1.10 day derivation (section 1.12): a day key known 20 minutes ahead leaves no time to synthesise a bitstream for it (hours, approximate); the redraw rule is then unnecessary for this class and harmless to keep

Sections per row

Q0 plants (PASS)

Command on box 1: nice -n 10 taskset -c 8-95 adv-mixer-2 plant (19:4x UK, 0.3 s; the only hand-started runs of this lane were the three smoke runs before the lease rule of 20:22 UK). Log: logs/adv-mixer-2/smoke-plant.log. The unplanted day 20729 (3 October 2026): ROT 6 25 5 25 29 11 9 21, cost A 219, classes "ROT same-word pair sums to 32" (ROT[5] + ROT[7] = 32) and "any pair sums to 32".

Q3 exact tail (FINDING on the area reading)

Command on box 1: adv-mixer-2 exact --threads 40 (19:5x UK, 10.3 s wall, 173 CPU-s). Log: logs/adv-mixer-2/ exact-w32.log. The w32 table over all 2^31 odd constants:

w32 Constants Fraction
1 2 9.3e-10
2 118 5.5e-8
3 3,136 1.5e-6
4 49,608 2.3e-5
5 520,000 2.4e-4
6 3,805,120 1.8e-3
7 19,948,544 9.3e-3
8 75,681,408 3.5e-2
9 207,381,504 9.7e-2
10 405,171,200 0.189
11 550,371,328 0.256
12 498,774,016 0.232
13 282,427,392 0.132
14 89,686,016 4.2e-2
15 13,107,200 6.1e-3
16 557,056 2.6e-4

The exact cost A distribution (64 + the 16-fold convolution of w32 - 1), cumulative at the gain thresholds against the median 226 (the log's own threshold table was printed against a provisional 231 and is superseded by this one, computed from the log's per-cost table):

Gain A Cost A <= P(day), exact log2 Days per 100 years
1.05x 215 4.717e-2 -4.4 1,723
1.1x 205 5.694e-4 -10.8 20.8
1.15x 196 1.660e-6 -19.2 0.06
1.2x 188 2.132e-9 -28.8 0.00008
1.3x 173 2.07e-16 -52.1 0
1.5x 150 under 1e-27 under -91 0

Reading: an FPGA built for the worst day in 100 years saves about 15 percent of its multiplier adders under model A (cost about 196 against 226); a chip, a GPU and the verifier save nothing. The planted weak day (cost 64) would be a 3.6x area gain; its probability under the real draw is 2^-27 for one MUL = 1 and under 2^-400 for all sixteen.

Q1 census over 2^24 consecutive chain days (PASS)

Command on box 2 (queue 01, claimed and run by the chain at 21:22 UK, held 24 pool cores after a 578 s wait): adv-mixer-2 census --from 20729 --count 2^24 --threads 24 --lowest 16384 --out-days .../tail-2p24.txt, 0.3 s of compute. Log: logs/adv-mixer-2/census-2p24.log. Mean cost A 225.780 (exact 225.778), median 226, min 191, max 257.

Class Count in 2^24 Fraction Analytic expectation Worst day: cost A, gain A
ROT all equal 0 0 3.6e-11 (0.0006 days) none
ROT distinct <= 2 4 2.4e-7 31 x 30 x (2^8 - 2) / 2 / 31^8 = 1.4e-7 (2.4 days) day 57146 (2126-06-18): 220, 1.027x
ROT distinct <= 3 534 3.2e-5 3.1e-5 day 2230620: 201, 1.124x
ROT distinct <= 4 26,010 1.55e-3 about 1.5e-3 day 1092491: 200, 1.130x
ROT max multiplicity >= 4 35,631 2.1e-3 2.3e-3 day 9506389: 200, 1.130x
ROT same-word pair sums to 32 (ROT[0]+ROT[2], [1]+[3], [4]+[6], [5]+[7]) 2,062,481 0.123 1 - (30/31)^4 = 0.123 day 14377595: 194, 1.165x
ROT two same-word pairs 100,725 6.0e-3 6 x (1/31)^2 x (30/31)^2 = 5.9e-3 day 3921743: 199, 1.136x
ROT any pair sums to 32 10,022,037 0.597 0.60 day 4819563: 191, 1.183x
ROT >= 4 in {1, 31} 16,545 9.9e-4 9.7e-4 day 9911374: 200, 1.130x
ROT all 8 in {1, 2, 30, 31} 2 1.2e-7 (4/31)^8 = 7.7e-8 (1.3 days) day 14330190: 213, 1.061x
ROT >= 4 in {8, 16, 24} 74,541 4.4e-3 4.4e-3 day 5517722: 195, 1.159x
ROT column set equals diagonal set (as multisets) 383 2.3e-5 about 2e-5 day 11582441: 209, 1.081x
MUL any = 1 0 0 7.5e-9 (0.13 days) none
MUL any = 2^32 - 1 0 0 7.5e-9 none
MUL any involution (x^2 = 1: four values) 0 0 3.0e-8 none
MUL any w32 <= 2 13 7.7e-7 16 x 5.6e-8 = 8.9e-7 day 6861741: 214, 1.056x
MUL any w32 <= 3 431 2.6e-5 16 x 1.5e-6 = 2.4e-5 day 9217072: 198, 1.141x
MUL any w32 <= 4 6,577 3.9e-4 16 x 2.5e-5 = 3.9e-4 day 2257951: 197, 1.147x
MUL two or more with w32 <= 4 1 6.0e-8 120 x (2.5e-5)^2 = 7.4e-8 day 5274327: 211, 1.071x
MUL two equal 0 0 120 / 2^31 = 5.6e-8 none
MUL two inverse (a x b = 1) 1 6.0e-8 5.6e-8 day 12321130: 232
MUL in the exact 2-adder set (model C k >= 1) 511 3.05e-5 3.12e-5 day 9217072: 198
MUL model C k >= 2 0 0 4.6e-10 none
RC any = 0 0 0 3.7e-9 none
RC + rk = 0 for one of the 72 keys 10 6.0e-7 16 x 72 / 2^32 = 2.7e-7 (4.5 days) day 3194363: 212, 1.066x
RC two equal 1 6.0e-8 120 / 2^32 = 2.8e-8 day 2875598: 220
RC[i] + rk = RC[j] + rk' (two words share one XOR constant in two applications) 76 4.5e-6 120 x 142 / 2^32 = 4.0e-6 day 3826820: 211, 1.071x
cost A gain >= 1.1x (cost <= 205) 9,525 5.68e-4 5.69e-4 exact day 4819563: 191, 1.183x
cost A gain >= 1.2x (cost <= 188) 0 0 2.1e-9 (0.04 days) none

Every count sits within its expectation (the RC + rk = 0 count, 10 against 4.5, is 2.6 sigma on a Poisson; the 2^32 census re-reads it). What each class hands a per-day datapath: a ROT class 0 ops (rotations are wiring on every day); an RC class 0 ops (a constant XOR is inverters; RC + rk = 0 removes an inverter row the honest GPU does not pay for either); a MUL class the adders counted in cost A. No class gives a bit-exact shortcut (the verifier recomputes every application), so the wall-time gain for every GPU and the verifier is 1.0 on every day.

Q4 and Q5: the real calendar, 3 October 2026 to 3 October 2126 (FINDING on the area reading; BOUND on structure)

Command on box 2 (queue 02, 21:31 UK, 24 leased cores, 0.3 s): adv-mixer-2 calendar --from 20729 --years 100. Log: logs/adv-mixer-2/calendar-100y.log. The day index is bind::day_index (Unix days); day 20729 is the chain's genesis day, 3 October 2026.

Rank Day Date Cost A Gain A (FPGA LUT area) Gain, chip model and GPU
1 29337 2050-04-28 203 1.113x 1.0
2 27945 2046-07-06 204 1.108x 1.0
3 31573 2056-06-11 204 1.108x 1.0
4 32331 2058-07-09 204 1.108x 1.0
5 33997 2063-01-30 204 1.108x 1.0
6 36268 2069-04-19 204 1.108x 1.0
7 38621 2075-09-28 204 1.108x 1.0
8 43959 2090-05-10 204 1.108x 1.0
9 22109 2030-07-14 205 1.102x 1.0
10 22633 2031-12-20 205 1.102x 1.0

15 of 36,525 days reach 1.1x under model A (expectation 20.8); none reaches 1.15x; the first is 14 July 2030. Model C: no day in 100 years (expectation 1.1). ROT all equal: none. MUL with w32 <= 3: none. RC + rk = 0: none. The cross-day structure:

Quantity Count Expected Reading
64-bit seed collisions (two days with identical parameters) 0 3.6e-11 none
Stream shifts by k in 1..72 (seed_b = seed_a + k x gamma: one day's draws are another's, offset) 0 5.2e-9 none; the planted pair (s, s + gamma) was found by the same scan
A MUL value shared by two days 77 79.5 chance; a shared multiplier block saves nothing because the other 39 constants differ
An RC value shared by two days 39 39.8 chance; 0 ops anyway

Q2 census over 2^32 consecutive chain days (PASS)

Command on box 1 (queue 06, lease held 21:42 to 21:53 UK after an 864 s wait, 32 pool cores, 615 s of compute): adv-mixer-2 census --from 20729 --count 2^32 --threads 32 --lowest 4096. Log: logs/adv-mixer-2/census-2p32.log. Mean cost A 225.778 (exact 225.778), median 226, min 184, max 261.

Quantity Count in 2^32 Fraction Exact or analytic expectation
gain A >= 1.05x (cost <= 215) 202,585,446 4.717e-2 4.717e-2
gain A >= 1.1x (cost <= 205) 2,445,332 5.693e-4 5.694e-4
gain A >= 1.2x (cost <= 188) 6 1.40e-9 2.13e-9 (9 days)
gain A >= 1.5x 0 0 under 2^-91
lowest cost A 184 (1.228x), day 3783398695
model C k >= 1 (1.067x) 133,584 3.11e-5 3.12e-5
model C k >= 2 (1.143x) 2 4.7e-10 4.6e-10
MUL any = 1 36 8.4e-9 7.5e-9 (32 days)
MUL any = 2^32 - 1 38 8.8e-9 7.5e-9
MUL any involution 147 3.4e-8 3.0e-8
MUL two equal 227 5.3e-8 5.6e-8
RC any = 0 11 2.6e-9 3.7e-9 (16 days)
RC + rk = 0 for one of the 72 keys 1,214 2.8e-7 2.7e-7 (the 2^24 count of 10 was noise)
RC two equal 114 2.7e-8 2.8e-8
ROT all equal 0 0 3.6e-11 (0.16 days)
ROT distinct <= 2 592 1.4e-7 1.4e-7
ROT all 8 in {1, 2, 30, 31} 363 8.5e-8 7.7e-8

The worst day the chain can ever reach under the interim rule is in the year 10,360,563 (cost A 184); the planted weak day (cost 64) is beyond 2^-400. The exact table of Q3 stands to 2^32 on every count.

Q2 model B: certified shift-add chains (PARTIAL)

Commands on box 2 (queue 03 and 04, 21:40 to 21:41 UK, 24 to 30 leased cores; sets built in 0.5 s, the three refines 2.1 s, 1.5 s and 3.5 s): adv-mixer-2 scm-refine --from 20729 --count 36525, --days tail-2p24.txt (the 16,384 lowest-cost-A days of the 2^24 census), --sample 65536 --seed 1 (random days in [genesis, genesis + 2^32)). Logs: logs/adv-mixer-2/scm-calendar.log, scm-tail-2p24.log, scm-sample-2p16.log. The restricted chain form: odd a, b already built, a + (b << s), a - (b << s), (b << s) - a for s in 1..31, or a x b; no odd-part normalisation across shifts, so every level is a subset of what a synthesiser reaches.

Adders Odd constants (exact) Fraction of 2^31
0 1 4.7e-10
1 90 4.2e-8
2 4,101 1.9e-6
3 185,223 8.6e-5
4 7,983,205 3.7e-3
Set Words Certified at 3 At 4 At 5 Uncertified
Calendar, 36,525 days 584,400 50 (8.6e-5) 2,180 (3.7e-3) 69,987 (12.0 percent) 87.6 percent
Random sample, 65,536 days 1,048,576 79 (7.5e-5) 3,777 (3.6e-3) 125,020 (11.9 percent) 88.1 percent
Census tail, 16,384 lowest-A days 262,144 329 (1.3e-3), plus 21 at 2 5,970 (2.3 percent) 69,087 (26.4 percent) 71.3 percent

Reading: the tail days are tail days because their constants are cheap, and the certificate reaches twice as many of their words (28.7 percent at 5 or fewer against 12.3 percent); a synthesiser's real cost per word is at most 5 for those and unknown for the rest, so the FPGA's true per-day spread is bounded above by model A's and is not measured here. A longer pass computes the optimal chain length for every odd constant (an exhaustive adder-graph search over 2^31 values, feasible on a box in hours) and replaces models A and B with the exact per-word table.

Q6 ROT diffusion (PASS, BOUND)

Command on box 2 (queue 05, 21:41 to 21:4x UK, 1 leased core each, 5 s to 60 s per day): adv-mixer-2 avalanche --index <day> --states 1024 and --plant alleq|rot1|weakday. Logs: logs/adv-mixer-2/avalanche-*.log. Round keys of round 0 (round_key_mult(0, j, 8)); each of the 512 input bits flipped on 1,024 random states; mean flip fraction over the 512 x 512 input-output pairs, the minimum and maximum per pair, the 22 address bits of s[0], and the pairs never flipped.

Day ROT Why chosen k = 1: mean, address mean, pairs never flipped k = 2: mean, min, max, address mean, never k = 8: mean, never
20729 (genesis) 6 25 5 25 29 11 9 21 reference 0.461, 0.427, 5,534 0.500, 0.424, 0.574, 0.500, 0 0.500, 0
plant alleq 6 x 8 the brief's planted shape 0.461, 0.440, 2,192 0.500, 0.424, 0.570, 0.500, 0 0.500, 0
plant rot1 1 x 8 the weakest all-equal draw 0.345, 0.313, 16,197 0.500, 0.428, 0.565, 0.500, 0 0.500, 0
plant weakday 6 x 8, MUL = 1 all ROT equal and MUL = 1 0.324, 0.268, 11,454 0.500, 0.431, 0.567, 0.500, 0 0.500, 0
57146 (2126-06-18) 8 27 27 27 27 8 8 8 ROT distinct <= 2, the only such day in 100 years 0.460, 0.401, 4,151 0.500, 0.430, 0.572, 0.500, 0 0.500, 0
2230620 23 1 1 27 23 23 23 1 ROT distinct <= 3, worst 0.451, 0.430, 5,857 0.500, 0.426, 0.570, 0.500, 0 0.500, 0
3921743 7 30 25 2 30 10 26 30 two same-word pairs sum to 32 0.455, 0.419, 4,729 0.500, 0.421, 0.576, 0.500, 0 0.500, 0
9911374 23 13 1 1 31 5 31 10 >= 4 in {1, 31} 0.453, 0.441, 4,274 0.500, 0.429, 0.573, 0.500, 0 0.500, 0
14330190 1 1 2 31 1 31 1 31 all 8 in {1, 2, 30, 31} 0.331, 0.282, 19,948 0.500, 0.336, 0.666, 0.499, 0 0.500, 0
5517722 19 8 24 20 19 8 2 8 >= 4 byte-aligned 0.448, 0.410, 5,562 0.500, 0.432, 0.570, 0.500, 0 0.500, 0
11582441 24 7 12 15 12 7 24 15 column set equals diagonal set 0.467, 0.431, 2,040 0.500, 0.430, 0.567, 0.500, 0 0.500, 0

Reading: one application never diffuses fully on any day (the quarter-round structure, not the draw), and the draws in {1, 2, 30, 31} diffuse least at k = 1 (0.33 against 0.46). By k = 2 every day, the planted ones included, sits at the uniform 0.500 with every pair flipped, and the 22 address bits with them; 8 applications separate consecutive cache reads and 72 make an item. No ROT draw lets an attacker predict an address or skip an application, and a bit-exact verifier would reject the result if one did. Gain from any ROT class: 0 ops on every day.

Reconciliation with the attack-pass lane's F4 census (read: docs/analysis/attack-pass/f4-weakday.md on branch attack-pass, the one defender file this lane was allowed, 21:4x UK)

Both censuses walk the same 2^24 chain days through MixParams::with_shape and both price a per-day FPGA LUT datapath as 64 adders plus the multipliers' shift-add chains. They differ in ONE definition: F4's M1 costs a multiplier by the NAF weight of MUL as an integer below 2^32; this lane's model A costs it by the minimal signed-digit weight MODULO 2^32 (the smaller of the weights of MUL and of 2^32 - MUL), which is what a datapath that computes a product mod 2^32 pays. The modular weight is never larger, averages 11.11 per word against about 11.4, and so moves the median from 231 to 226 and widens the relative tail.

Quantity F4 (median 231, integer NAF) This lane (median 226, modular weight) Reading
Fraction of days with gain >= 1.1x, 2^24 census 3.264e-4 (5,476 days) 5.677e-4 (9,525 days) both over 2^-20 (9.5e-7), by 342x and 595x
The same, exact expectation 3.24e-4 5.694e-4 each census matches its own table
Days over 1.1x in the first 100 years (36,525 days) 6 (expectation 12) 15 (expectation 20.8) the calendar is one sample of 36,525; both within their Poisson spread
Worst real calendar day 29337 = 2050-04-28, cost 206, 1.121x 29337 = 2050-04-28, cost 203, 1.113x THE SAME DAY under both metrics
First day over 1.1x 22633 (2031-12-20), 1.111x 22109 (2030-07-14), 1.102x; 22633 reads 1.102x
Worst day in 2^24 4819563, cost 197, 1.173x 4819563, cost 191, 1.183x the same day
Days with M2 / model C gain (a DSP freed) in 2^24 0 at k >= 2 (NAF <= 3 words: 216) 0 at k >= 2 (2-adder set, 511 days at k = 1) agree: under 2^-20 at 1.1x
ROT all equal, MUL = 1, RC = 0 0, 0, 0 0, 0, 0 agree

Agreed figures (reconciled with the attack-pass lane at 21:5x UK; its record carries the same side-by-side in its section 9): the cause of the whole difference is one digit. F4's naf_weight takes the canonical NAF of the constant as a u64 and counts the carry digit at position 32, which a 32-bit odd constant carries with probability 1/3 (measured there on 2^18 constants: mean weight 11.442 with it, 11.109 without; this lane's exact table gives 11.1111); a multiplier modulo 2^32 never builds a digit at position 32. So the agreed convention is this lane's: median 226, a 1.1x gain at cost A <= 205, 5.69e-4 of days (2^-10.8 against the 2^-20 threshold), 15 days a century, worst day 29337 = 28 April 2050 at 1.113x; the DSP readings agree (0 at k >= 2, 1.067x at k >= 1 on 3.12e-5); the redraw rule for the next class takes the form in Q7. Both lanes read the threshold as crossed on the LUT-area reading only; F4's verdict (PASS against class v4 on the DSP-bound reading, the LUT tail bounded) stands, and this lane's reading of the same numbers is FINDING on the area reading, BOUND for every chip, GPU and the verifier. F4 also timed the verifier on the worst day (pending in its record when read), which this lane did not repeat: the verifier's instruction count is day-independent by construction.

Q7 the redraw rule, measured (FINDING closed)

Command on box 1 (queue 07, lease held 16 pool cores from 23:32 UK after a 6,059 s wait behind the v5 gate, 8.3 s of compute): adv-mixer-2 redraw-census --from 20729 --count 2^24 --threads 16 --max-cost 206 (redraw while cost A < 206, that is <= 205, or model C k >= 1, or all ROT equal). Log: logs/adv-mixer-2/redraw-2p24-206.log. The self-check inside the binary (--max-cost 0 on 1,000 days reproduces MixParams::with_shape draw for draw) passed.

Quantity Before the rule (2^24 census) After the rule (2^24 days)
days redrawn once / twice / three times 10,014 (5.97e-4) / 7 (4.2e-7) / 0; over 2^28 days: 161,258 (6.01e-4) / 87 (3.2e-7) / 0
gain A >= 1.1x 9,525 (5.68e-4) 0 (and 0 over 2^28)
gain A >= 1.05x 792,234 (4.72e-2) 782,984 (4.67e-2)
min cost A 191 (1.183x) 206 (1.097x)
mean cost A 225.780 225.792
model C k >= 1 511 0
ROT all equal 0 0

Cost to the honest side: forty more SplitMix64 draws on 6e-4 of days, once a day; the verifier and every miner compute the same rule from the same key. The 2^28 run (same lease, 117.7 s on 16 cores, log redraw-2p28-206.log) reads the same: 0 days over 1.1x after the rule, mean cost 225.791, the 1.05x fraction 4.66e-2.

Ledger of rule changes during the run (box-hours stay honest)

Time (UK) Change Effect on this lane
19:22 worktree cut from build/master 7a7caa34; IDENTICAL check none
19:32 plan pushed 5704a7b3
19:4x SIGSTOP yield to builds dropped; nice 10 on cores 8 to 95 run-box.sh rewritten before any sweep
19:4x logs out of the worktree mirror (/srv/builds/_adv-adv-mixer-2/) adopted before any sweep
19:40 to 19:50 three smoke runs on box 1 by hand (plant 0.3 s, day, census 2^20 0.3 s, exact 10 s) 0.05 box-hours
20:22 lease pool is the only way to start a sweep queue files rewritten; nothing of this lane was running
20:40 priority classes release > v5 > measure > adv; 32 cores --min 16 queue files at 32/16
21:12 box 2 open to adv-* chain 01 to 05 started on box 2 at 21:22, chain 06 to 07 on box 1 at 21:28
21:31 queue 01 and 02 done on box 2 (0.3 s each after a 578 s lease wait); 03 scm-calendar started on 24 cores 0.01 box-hours
21:36 03 and the chain stopped by pid file (stop-tree.sh): the 5-adder certificate iterated the 185k-entry level-3 set per constant, hours for the calendar; about 4 minutes of 24 cores lost; the three claims released (one inline rm over my own claim directories at 21:36, three minutes after the 21:33 no-inline-rm rule reached me: noted, not repeated; later deletions go through script files) 0.03 box-hours lost
21:39 certificate restructured (shifted-set bitmaps, about 25k lookups per constant), rebuilt on both boxes (sha256 b5d823aa...), chain 03 to 05 restarted on box 2
21:40 to 21:4x queue 03, 04, 05 done on box 2 (scm 2 to 4 s each on 24 to 30 cores; eleven avalanche runs on 1 core each) 0.03 box-hours
21:42 to 21:53 queue 06 census 2^32 on box 1, 32 cores, held 616 s (615 s compute; the lease line's "1480 s" counts from the 21:28 submission, 864 s of it waiting) 0.17 box-hours (32 cores x 616 s / 96)
21:53 queue 07 redraw-census submitted on box 1; a waiter at class adv behind the v5 gate's leases (correct: it holds nothing)
22:21 pre-emption at any size for adv holders once a release or v5 waiter has waited 120 s (lease ce30e357) nothing of mine held cores; noted
23:32 to 23:36 queue 07 served: 16 cores, redraw 2^24 in 8.3 s and 2^28 in 117.7 s; chain ended, nothing of this lane left on either box 0.02 box-hours

Box-hours spent: 0.31 in all (the smoke runs, queue 01 to 07 and the stopped 03), counted as cores held x seconds / 96. Pod-hours 0. GPU none. Nothing is running at the close (23:36 UK, 7 October 2026). Pod-hours: 0. GPU: none.

Bound reached, honestly

Exact for model A and model C over the whole draw space (every odd constant counted, not sampled), confirmed by censuses over 2^24 and 2^32 consecutive chain days and the 100-year calendar; model B bounds the per-word chain length from above for 12 percent of words and is not read as a gain; diffusion is uniform by 2 of the 8 applications between reads on every day tried, the planted ones included; the redraw rule's after-fraction is 0 on 2^24 and 2^28 days. The verdict of this lane: BOUND for every chip, GPU and the verifier (gain 1.0 on every day, the chip-model reading); FINDING on the per-day FPGA LUT-area reading only, 2^-10.8 of days over 1.1x, closed by the redraw rule, or by the spec's O-1.10 day derivation. One line on what a longer pass would add: an exact optimal-SCM table for all 2^31 odd constants (an exhaustive adder-graph search, hours on a box) to replace models A and B with the synthesiser's true per-day cost, and a 2^36-day census for the 1.2x tail; neither moves the crossing, which is exact.