34 KiB
Report: the day-key weakness class of the mixer M_r (lane adv-mixer-2)
Internal adversarial pass, not an independent review. Every sentence below that could be quoted carries that label.
Header
| Field | Value |
|---|---|
| Target commit | 017e703764 (class v4 sub-version 3, object byte 7) |
| Target | the per-day draw of ROT[0..7], MUL[0..15], RC[0..15] for M_r (spec 01 section 1.8.4), class v4 (x8, 72 applications per item) |
| Branch | adv-mixer-2 from build/master 7a7caa34, merged 04c4d9bc; plan 5704a7b3; harness ae3088a9 |
| Byte identity | git diff --quiet 017e7037... HEAD -- igneum-pow printed IDENTICAL at 7a7caa34 and at 04c4d9bc (the whole crate) |
| Harness | tools/attack/adv-mixer-2 (binary adv-mixer-2), igneum-pow by path, nothing re-implemented |
| Binary sha256 | 88f6a3edfffad166d35a3bcadcaff7907613e710b842cfcbe94fbb1601f7c37b for queue 01, 02 and the exact run; b5d823aa14da80d0b02fc2e02666a70af1ce14fe464ad683be9616a4b5df5179 from 21:39 UK (the model B certificate restructured; census, exact, calendar code unchanged), identical on both boxes, at /srv/builds/_adv-adv-mixer-2/bin/ |
| Boxes | igneum-build-1 and igneum-build-2, rustc 1.99.0; every sweep through /srv/builds/_bin/lease pool at class adv, 32 cores, --min 16, nice 10 |
| Logs | /srv/builds/_adv-adv-mixer-2/logs/ on each box; copies in docs/analysis/cryptanalysis/logs/adv-mixer-2/ |
| Price | chip-model-v3.md 5.2: 128 ops per application hoisted, 9,360 ops per item; the spec's 130 per application |
| Clock | UK time throughout |
What the per-day gain means, and for whom
The honest miner (any GPU) and the CPU verifier run memhard::mixer with the day's constants as operands: 16
multiplies, 16 XORs, 32 adds, 32 XORs, 32 rotates per application, the same instruction count on every day. A
multiplier unit costs the same for MUL = 3 as for MUL = 0x9E3779B9. So under chip-model-v3's op count (9,360 ops per
item, value-independent) the per-day gain is exactly 1.0 on every day for every GPU, for the verifier, and for a
chip with a general multiplier. The chip model credits hash rate only through that count.
The day's constants matter only to a datapath that bakes them in. An ASIC cannot be masked per day. An FPGA bitstream can be synthesised per day, and that is the only per-day attacker; its per-day gain is an AREA gain (fewer LUTs per multiplier, so more copies of the pipeline per device), which the chip model does not price as hash rate. The three cost models of this lane read that area:
| Model | What it measures | For whom | Gain over 1.1x on more than 2^-20 of days? |
|---|---|---|---|
| A, LUT shift-add (64 + sum of (w32 - 1)) | adder-equivalents per application with every multiplier as a canonical signed-digit shift-add chain; rotations and constant XORs free | a per-day FPGA build with multipliers in LUTs; not a wall-time gain for any chip | YES: P(cost A <= 205, gain >= 1.102x against the exact median 226) = 5.694e-4 = 2^-10.8 per day (exact, 16-fold convolution of the w32 table over all 2^31 odd constants; about 21 days per 100 years). 1.2x: 2^-28.8 (1 day in 2^28). 1.5x: under 2^-91 |
| B, certified shift-add | the same datapath with each multiplier at its certified chain (exact for 1 to 4 adders, decomposition certificate for 5) | the same FPGA, closer to what a synthesiser achieves; an upper bound on the attacker's cost per word | NOT READ AS A GAIN: 12.3 percent of words are certified at 5 or fewer adders, 0.38 percent at 4 or fewer; the remaining 88 percent carry their model A cost, so cost B's spread between days is the certificate's reach, not the attacker's. What it does establish: a synthesiser's real per-day variation is smaller than model A's, because every certified word collapses to 5 whatever its w32 (7 to 13 in the tail days) |
| C, DSP | 16 / (16 - k) with k the words whose constant has a 2-adder chain and leaves its DSP block | a per-day FPGA build with multipliers in DSP blocks (value-independent) | NO: k >= 1 gives 1.067x on 3.123e-5 = 2^-15.0 of days; the first gain over 1.1x is k >= 2 (1.143x) on 4.57e-10 = 2^-31.0 |
| Chip model (ops per item) | 9,360 per item, value-independent | every GPU, the verifier, any chip with a general multiplier | NO: the gain is 1.0 on every day |
Threshold used: the brief's, a gain over 1.1x on more than 2^-20 of days. Model A crosses it by 9 binary orders; model C and the chip-model reading do not. The redraw rule below is proposed on the model A reading, because the census of a public calendar is the attacker's cheapest tool and a 10 percent area edge on 1 day in 1,750 is free to take even if it buys no hash rate against the chip model's attacker. The worst real calendar day is 29337 = 2050-04-28 (cost A 203, model A gain 1.113x, model C 1.0, chip model 1.0); the 15 days over 1.1x in 100 years are listed in Q4 below.
Status board
| Q | Method | Known-failed shape | Gate | Result (numbers) | Status |
|---|---|---|---|---|---|
| Q0 plants | plant on the day-20729 draw with one field replaced, through the same classifier |
alleq, rot1, mul1, mul1all, rcrk0, weakday (all ROT equal and MUL = 1) | every plant lands in its class with its gain | all six fire: alleq -> "ROT all equal" (cost 219); mul1 -> "MUL any = 1", gain 1.1053x; mul1all and weakday -> cost 64, gain 3.61x, model C k = 16; rcrk0 -> "RC + rk = 0"; rot1 -> "ROT all 8 in {1,2,30,31}" | PASS |
| Q3 exact tail, model A | w32 over all 2^31 odd constants (exact), 16-fold convolution | the table must give 2 constants at w32 = 1 (1 and 2^32 - 1) and the mean must match the census | mean w32 11.1111; mean cost A 225.78, exact median 226; P(gain >= 1.05x) 4.72e-2; >= 1.1x 5.694e-4 (2^-10.8); >= 1.15x 1.66e-6 (2^-19.2); >= 1.2x 2.13e-9 (2^-28.8); >= 1.3x 2.07e-16; >= 1.5x under 2^-91 | FINDING (area reading), crosses 2^-20 | |
| Q3 exact, model C | exact 2-adder set (4,192 odd constants, 2^-19.0 per word) | the set must contain 1, 2^32 - 1, 2^s +- 1 | P(k >= 1) 3.12e-5 (gain 1.067x), P(k >= 2) 4.57e-10 (1.143x) | PASS (bound: under 2^-20 at 1.1x) | |
| Q1 census 2^24 | census --from 20729 --count 2^24 (32 structural classes, cost A histogram, model C) |
plants above | counts against the analytic expectation | 16,777,216 days in 0.3 s on 24 leased cores: gain A >= 1.1x on 9,525 days (5.677e-4, 2^-10.8; exact 5.694e-4); >= 1.2x on 0; min cost 191 (1.183x, day 4819563); model C k >= 1 on 511 days (exact expectation 524), k >= 2 on 0; ROT all equal 0 (expected 6e-4); MUL = 1, MUL = -1, MUL involution, MUL two equal, RC = 0: 0 each; every class within its expectation (table below) | PASS (census agrees with the exact table) |
| Q2 census 2^32 | census --from 20729 --count 2^32 (every chain day for 11.7 million years) |
plants above | the model A tail against the exact table | 4,294,967,296 days in 615 s on 32 leased cores: gain A >= 1.1x on 2,445,332 days (5.693e-4; exact 5.694e-4); >= 1.2x on 6 days (1.40e-9; exact 2.13e-9); min cost 184 (1.228x, day 3783398695); model C k >= 1 on 133,584 (exact expectation 134,140), k >= 2 on 2 (expected 2.0, gain 1.143x); MUL = 1 on 36 days (expected 32), MUL = -1 on 38, RC = 0 on 11 (expected 16), RC + rk = 0 on 1,214 (expected 1,152), MUL two equal on 227 (expected 240), ROT all equal 0 (expected 0.16); every class within its expectation | PASS (the exact table holds to 2^32) |
| Q4 the real calendar | calendar --from 20729 --years 100 (36,525 days: 3 October 2026 to 3 October 2126) |
the planted stream-shift pair must be found (it was) | worst day with date under A and C | worst day 29337 = 2050-04-28, cost A 203, model A gain 1.113x (an FPGA area gain; 1.0 for every chip and GPU); 15 days over 1.1x in 100 years (exact expectation 20.8), none over 1.2x; model C: no day with k >= 1 in 100 years (expectation 1.1) | FINDING (area reading only) |
| Q5 cross-day structure | seed collisions, stream shifts by k in 1..72, shared MUL and RC values over the calendar | planted shift pair (found) | counts against expectation | 64-bit seed collisions 0 (expected 3.6e-11); stream shifts 0 (expected 5.2e-9); MUL values shared between two days 77 (expected 79.5), RC 39 (39.8): chance, and a shared constant hands a datapath nothing (the other 39 draws differ) | PASS (BOUND: nothing beyond chance) |
| Q2 model B | scm-refine on the calendar (36,525 days), on the lowest 2^14 days of the 2^24 census, on a 2^16-day random sample |
the self-test constants (3, 5, 7, 9, 2^32 - 1, 2^31 + 1 at 1 adder; 45 at 2): all as expected | the certified-cost distribution | exact sets: 90 constants at 1 adder, 4,101 at 2, 185,223 at 3, 7,983,205 at 4 (0.38 percent of odd constants at 4 or fewer under the restricted form); random words certified at 5 or fewer: 12.3 percent; the rest uncertified. Cost B is a PARTIAL metric (a certified word costs 5, an uncertified one w32 - 1), so its between-day spread (sample: mean 219, min 176; calendar worst day 43959 = 2090-05-10 at B 181) is the certificate's selectivity, not a measured gain, and is not read as one | PARTIAL (bound on the per-word chain length only) |
| Q6 ROT diffusion | avalanche (1, 2, 3, 4, 8 applications; the 22 address bits; 1,024 states x 512 input bits) on the genesis day, the plants, the 7 worst ROT days of the census |
plant rot1 and weakday must read weaker than the genesis day at 1 application: they do (mean flip 0.345 and 0.324 against 0.461; 16,197 and 11,454 input-output pairs never flipped against 5,534) | a per-day gain only if a bit-exact shortcut follows | at 2 applications every day, planted days included, reads mean 0.500, every output bit between 0.42 and 0.58 (sampling spread of 1,024 states), address bits 0.500, no pair unflipped; 8 applications sit between reads. No day gives a shortcut; gain 0 | PASS (BOUND) |
| Q7 redraw rule | redraw-census 2^24 and 2^28 days with the rule below |
--max-cost 0 must reproduce the real draw on 1,000 days (asserted in the binary; passed) |
fraction redrawn; residual over 1.1x must be 0 | 2^24 days: 10,014 redrawn once (5.97e-4), 7 twice (4.2e-7), none three times; after the rule gain A >= 1.1x on 0 days (min cost 206, 1.097x), model C k = 0 on every day, ROT all equal 0; mean cost 225.79 (225.78 before), the 1.05x fraction 4.67e-2 (4.72e-2 before): the rule touches only the tail. 2^28 days: 161,258 redrawn once (6.01e-4), 87 twice (3.2e-7), 0 three times; after the rule 0 days over 1.1x, min cost 206 | FINDING closed by the rule (after-fraction 0 on 2^24 and 2^28) |
| Q8 anything else | watched while the rows ran; three observations, no box time | n/a | stated or measured | (1) Lead time: the only per-day attacker is an FPGA bitstream synthesised for the day, and synthesis of a full-device design takes hours (approximate, from memory; no figure measured here). Under the interim day rule (bind::day_bytes, a pure function of the calendar) the attacker has unlimited lead; under the spec's own proposal O-1.10 (day bytes carry the first epoch seed of the day, known about 20 minutes ahead, section 1.12) a per-day bitstream cannot be ready in time, which removes the whole class without a redraw. (2) The mixer stream is seeded by 64 bits of the day key (K[0], K[1]); K[2..7] enter only the item init; no collision or shift was found in 100 years or 2^24 days, and the planted shift was. (3) The 72 round keys are fixed multiples of 0x9E3779B9; RC + rk = 0 happened on 10 of 2^24 days (expected 4.5, within Poisson) and costs a datapath nothing on either side |
PASS (stated) |
| GPU rows | none needed | no row of this class depends on a GPU | BLOCKED (not applicable) |
Q7: the proposed redraw rule
Rule, for the day's parameter draw (spec 1.8.4): after the forty draws, compute cost A = 64 + sum over the sixteen MUL of (w32(MUL) - 1), and the count k of MUL values with a 2-adder chain. If cost A <= 205 (a model A gain of 1.1x or more against the median 226), or k >= 1, or the eight ROT are equal, continue the SAME SplitMix64 stream and draw all forty again; repeat until accepted. The honest miner and the verifier pay forty more 64-bit draws per redraw, once a day; nothing else changes; every accepted day is a day the current rule could have drawn.
| Quantity | Value |
|---|---|
| Fraction of days redrawn at least once | exact 5.694e-4 + 3.123e-5 = 6.0e-4 (2^-10.7), about 22 days per 100 years; measured over 2^24 days 5.97e-4 once, 4.2e-7 twice, never three times |
| Fraction over 1.1x under model A after the rule | 0 measured over 2^24 and over 2^28 days (min cost 206, gain 1.097x). Before the rule, measured: 5.677e-4 (2^24 census), 5.693e-4 (2^32), 4.107e-4 (the 100-year calendar, 15 of 36,525 days) |
| Fraction over 1.1x under model C after the rule | 0 (k = 0 on every accepted day) |
| Chip-model reading after the rule | unchanged: 1.0 on every day before and after |
| What the rule does not fix | the seed is 64 bits of the day key (K[0], K[1]); the day is a pure function of the calendar; both stand; neither is a weakness of this class on the numbers above |
| The alternative that removes the class | the spec's O-1.10 day derivation (section 1.12): a day key known 20 minutes ahead leaves no time to synthesise a bitstream for it (hours, approximate); the redraw rule is then unnecessary for this class and harmless to keep |
Sections per row
Q0 plants (PASS)
Command on box 1: nice -n 10 taskset -c 8-95 adv-mixer-2 plant (19:4x UK, 0.3 s; the only hand-started runs of
this lane were the three smoke runs before the lease rule of 20:22 UK). Log: logs/adv-mixer-2/smoke-plant.log. The
unplanted day 20729 (3 October 2026): ROT 6 25 5 25 29 11 9 21, cost A 219, classes "ROT same-word pair sums to 32"
(ROT[5] + ROT[7] = 32) and "any pair sums to 32".
Q3 exact tail (FINDING on the area reading)
Command on box 1: adv-mixer-2 exact --threads 40 (19:5x UK, 10.3 s wall, 173 CPU-s). Log: logs/adv-mixer-2/
exact-w32.log. The w32 table over all 2^31 odd constants:
| w32 | Constants | Fraction |
|---|---|---|
| 1 | 2 | 9.3e-10 |
| 2 | 118 | 5.5e-8 |
| 3 | 3,136 | 1.5e-6 |
| 4 | 49,608 | 2.3e-5 |
| 5 | 520,000 | 2.4e-4 |
| 6 | 3,805,120 | 1.8e-3 |
| 7 | 19,948,544 | 9.3e-3 |
| 8 | 75,681,408 | 3.5e-2 |
| 9 | 207,381,504 | 9.7e-2 |
| 10 | 405,171,200 | 0.189 |
| 11 | 550,371,328 | 0.256 |
| 12 | 498,774,016 | 0.232 |
| 13 | 282,427,392 | 0.132 |
| 14 | 89,686,016 | 4.2e-2 |
| 15 | 13,107,200 | 6.1e-3 |
| 16 | 557,056 | 2.6e-4 |
The exact cost A distribution (64 + the 16-fold convolution of w32 - 1), cumulative at the gain thresholds against the median 226 (the log's own threshold table was printed against a provisional 231 and is superseded by this one, computed from the log's per-cost table):
| Gain A | Cost A <= | P(day), exact | log2 | Days per 100 years |
|---|---|---|---|---|
| 1.05x | 215 | 4.717e-2 | -4.4 | 1,723 |
| 1.1x | 205 | 5.694e-4 | -10.8 | 20.8 |
| 1.15x | 196 | 1.660e-6 | -19.2 | 0.06 |
| 1.2x | 188 | 2.132e-9 | -28.8 | 0.00008 |
| 1.3x | 173 | 2.07e-16 | -52.1 | 0 |
| 1.5x | 150 | under 1e-27 | under -91 | 0 |
Reading: an FPGA built for the worst day in 100 years saves about 15 percent of its multiplier adders under model A (cost about 196 against 226); a chip, a GPU and the verifier save nothing. The planted weak day (cost 64) would be a 3.6x area gain; its probability under the real draw is 2^-27 for one MUL = 1 and under 2^-400 for all sixteen.
Q1 census over 2^24 consecutive chain days (PASS)
Command on box 2 (queue 01, claimed and run by the chain at 21:22 UK, held 24 pool cores after a 578 s wait):
adv-mixer-2 census --from 20729 --count 2^24 --threads 24 --lowest 16384 --out-days .../tail-2p24.txt, 0.3 s of
compute. Log: logs/adv-mixer-2/census-2p24.log. Mean cost A 225.780 (exact 225.778), median 226, min 191, max 257.
| Class | Count in 2^24 | Fraction | Analytic expectation | Worst day: cost A, gain A |
|---|---|---|---|---|
| ROT all equal | 0 | 0 | 3.6e-11 (0.0006 days) | none |
| ROT distinct <= 2 | 4 | 2.4e-7 | 31 x 30 x (2^8 - 2) / 2 / 31^8 = 1.4e-7 (2.4 days) | day 57146 (2126-06-18): 220, 1.027x |
| ROT distinct <= 3 | 534 | 3.2e-5 | 3.1e-5 | day 2230620: 201, 1.124x |
| ROT distinct <= 4 | 26,010 | 1.55e-3 | about 1.5e-3 | day 1092491: 200, 1.130x |
| ROT max multiplicity >= 4 | 35,631 | 2.1e-3 | 2.3e-3 | day 9506389: 200, 1.130x |
| ROT same-word pair sums to 32 (ROT[0]+ROT[2], [1]+[3], [4]+[6], [5]+[7]) | 2,062,481 | 0.123 | 1 - (30/31)^4 = 0.123 | day 14377595: 194, 1.165x |
| ROT two same-word pairs | 100,725 | 6.0e-3 | 6 x (1/31)^2 x (30/31)^2 = 5.9e-3 | day 3921743: 199, 1.136x |
| ROT any pair sums to 32 | 10,022,037 | 0.597 | 0.60 | day 4819563: 191, 1.183x |
| ROT >= 4 in {1, 31} | 16,545 | 9.9e-4 | 9.7e-4 | day 9911374: 200, 1.130x |
| ROT all 8 in {1, 2, 30, 31} | 2 | 1.2e-7 | (4/31)^8 = 7.7e-8 (1.3 days) | day 14330190: 213, 1.061x |
| ROT >= 4 in {8, 16, 24} | 74,541 | 4.4e-3 | 4.4e-3 | day 5517722: 195, 1.159x |
| ROT column set equals diagonal set (as multisets) | 383 | 2.3e-5 | about 2e-5 | day 11582441: 209, 1.081x |
| MUL any = 1 | 0 | 0 | 7.5e-9 (0.13 days) | none |
| MUL any = 2^32 - 1 | 0 | 0 | 7.5e-9 | none |
| MUL any involution (x^2 = 1: four values) | 0 | 0 | 3.0e-8 | none |
| MUL any w32 <= 2 | 13 | 7.7e-7 | 16 x 5.6e-8 = 8.9e-7 | day 6861741: 214, 1.056x |
| MUL any w32 <= 3 | 431 | 2.6e-5 | 16 x 1.5e-6 = 2.4e-5 | day 9217072: 198, 1.141x |
| MUL any w32 <= 4 | 6,577 | 3.9e-4 | 16 x 2.5e-5 = 3.9e-4 | day 2257951: 197, 1.147x |
| MUL two or more with w32 <= 4 | 1 | 6.0e-8 | 120 x (2.5e-5)^2 = 7.4e-8 | day 5274327: 211, 1.071x |
| MUL two equal | 0 | 0 | 120 / 2^31 = 5.6e-8 | none |
| MUL two inverse (a x b = 1) | 1 | 6.0e-8 | 5.6e-8 | day 12321130: 232 |
| MUL in the exact 2-adder set (model C k >= 1) | 511 | 3.05e-5 | 3.12e-5 | day 9217072: 198 |
| MUL model C k >= 2 | 0 | 0 | 4.6e-10 | none |
| RC any = 0 | 0 | 0 | 3.7e-9 | none |
| RC + rk = 0 for one of the 72 keys | 10 | 6.0e-7 | 16 x 72 / 2^32 = 2.7e-7 (4.5 days) | day 3194363: 212, 1.066x |
| RC two equal | 1 | 6.0e-8 | 120 / 2^32 = 2.8e-8 | day 2875598: 220 |
| RC[i] + rk = RC[j] + rk' (two words share one XOR constant in two applications) | 76 | 4.5e-6 | 120 x 142 / 2^32 = 4.0e-6 | day 3826820: 211, 1.071x |
| cost A gain >= 1.1x (cost <= 205) | 9,525 | 5.68e-4 | 5.69e-4 exact | day 4819563: 191, 1.183x |
| cost A gain >= 1.2x (cost <= 188) | 0 | 0 | 2.1e-9 (0.04 days) | none |
Every count sits within its expectation (the RC + rk = 0 count, 10 against 4.5, is 2.6 sigma on a Poisson; the 2^32 census re-reads it). What each class hands a per-day datapath: a ROT class 0 ops (rotations are wiring on every day); an RC class 0 ops (a constant XOR is inverters; RC + rk = 0 removes an inverter row the honest GPU does not pay for either); a MUL class the adders counted in cost A. No class gives a bit-exact shortcut (the verifier recomputes every application), so the wall-time gain for every GPU and the verifier is 1.0 on every day.
Q4 and Q5: the real calendar, 3 October 2026 to 3 October 2126 (FINDING on the area reading; BOUND on structure)
Command on box 2 (queue 02, 21:31 UK, 24 leased cores, 0.3 s): adv-mixer-2 calendar --from 20729 --years 100.
Log: logs/adv-mixer-2/calendar-100y.log. The day index is bind::day_index (Unix days); day 20729 is the chain's
genesis day, 3 October 2026.
| Rank | Day | Date | Cost A | Gain A (FPGA LUT area) | Gain, chip model and GPU |
|---|---|---|---|---|---|
| 1 | 29337 | 2050-04-28 | 203 | 1.113x | 1.0 |
| 2 | 27945 | 2046-07-06 | 204 | 1.108x | 1.0 |
| 3 | 31573 | 2056-06-11 | 204 | 1.108x | 1.0 |
| 4 | 32331 | 2058-07-09 | 204 | 1.108x | 1.0 |
| 5 | 33997 | 2063-01-30 | 204 | 1.108x | 1.0 |
| 6 | 36268 | 2069-04-19 | 204 | 1.108x | 1.0 |
| 7 | 38621 | 2075-09-28 | 204 | 1.108x | 1.0 |
| 8 | 43959 | 2090-05-10 | 204 | 1.108x | 1.0 |
| 9 | 22109 | 2030-07-14 | 205 | 1.102x | 1.0 |
| 10 | 22633 | 2031-12-20 | 205 | 1.102x | 1.0 |
15 of 36,525 days reach 1.1x under model A (expectation 20.8); none reaches 1.15x; the first is 14 July 2030. Model C: no day in 100 years (expectation 1.1). ROT all equal: none. MUL with w32 <= 3: none. RC + rk = 0: none. The cross-day structure:
| Quantity | Count | Expected | Reading |
|---|---|---|---|
| 64-bit seed collisions (two days with identical parameters) | 0 | 3.6e-11 | none |
| Stream shifts by k in 1..72 (seed_b = seed_a + k x gamma: one day's draws are another's, offset) | 0 | 5.2e-9 | none; the planted pair (s, s + gamma) was found by the same scan |
| A MUL value shared by two days | 77 | 79.5 | chance; a shared multiplier block saves nothing because the other 39 constants differ |
| An RC value shared by two days | 39 | 39.8 | chance; 0 ops anyway |
Q2 census over 2^32 consecutive chain days (PASS)
Command on box 1 (queue 06, lease held 21:42 to 21:53 UK after an 864 s wait, 32 pool cores, 615 s of compute):
adv-mixer-2 census --from 20729 --count 2^32 --threads 32 --lowest 4096. Log: logs/adv-mixer-2/census-2p32.log.
Mean cost A 225.778 (exact 225.778), median 226, min 184, max 261.
| Quantity | Count in 2^32 | Fraction | Exact or analytic expectation |
|---|---|---|---|
| gain A >= 1.05x (cost <= 215) | 202,585,446 | 4.717e-2 | 4.717e-2 |
| gain A >= 1.1x (cost <= 205) | 2,445,332 | 5.693e-4 | 5.694e-4 |
| gain A >= 1.2x (cost <= 188) | 6 | 1.40e-9 | 2.13e-9 (9 days) |
| gain A >= 1.5x | 0 | 0 | under 2^-91 |
| lowest cost A | 184 (1.228x), day 3783398695 | ||
| model C k >= 1 (1.067x) | 133,584 | 3.11e-5 | 3.12e-5 |
| model C k >= 2 (1.143x) | 2 | 4.7e-10 | 4.6e-10 |
| MUL any = 1 | 36 | 8.4e-9 | 7.5e-9 (32 days) |
| MUL any = 2^32 - 1 | 38 | 8.8e-9 | 7.5e-9 |
| MUL any involution | 147 | 3.4e-8 | 3.0e-8 |
| MUL two equal | 227 | 5.3e-8 | 5.6e-8 |
| RC any = 0 | 11 | 2.6e-9 | 3.7e-9 (16 days) |
| RC + rk = 0 for one of the 72 keys | 1,214 | 2.8e-7 | 2.7e-7 (the 2^24 count of 10 was noise) |
| RC two equal | 114 | 2.7e-8 | 2.8e-8 |
| ROT all equal | 0 | 0 | 3.6e-11 (0.16 days) |
| ROT distinct <= 2 | 592 | 1.4e-7 | 1.4e-7 |
| ROT all 8 in {1, 2, 30, 31} | 363 | 8.5e-8 | 7.7e-8 |
The worst day the chain can ever reach under the interim rule is in the year 10,360,563 (cost A 184); the planted weak day (cost 64) is beyond 2^-400. The exact table of Q3 stands to 2^32 on every count.
Q2 model B: certified shift-add chains (PARTIAL)
Commands on box 2 (queue 03 and 04, 21:40 to 21:41 UK, 24 to 30 leased cores; sets built in 0.5 s, the three
refines 2.1 s, 1.5 s and 3.5 s): adv-mixer-2 scm-refine --from 20729 --count 36525, --days tail-2p24.txt (the
16,384 lowest-cost-A days of the 2^24 census), --sample 65536 --seed 1 (random days in [genesis, genesis + 2^32)).
Logs: logs/adv-mixer-2/scm-calendar.log, scm-tail-2p24.log, scm-sample-2p16.log. The restricted chain form: odd a,
b already built, a + (b << s), a - (b << s), (b << s) - a for s in 1..31, or a x b; no odd-part
normalisation across shifts, so every level is a subset of what a synthesiser reaches.
| Adders | Odd constants (exact) | Fraction of 2^31 |
|---|---|---|
| 0 | 1 | 4.7e-10 |
| 1 | 90 | 4.2e-8 |
| 2 | 4,101 | 1.9e-6 |
| 3 | 185,223 | 8.6e-5 |
| 4 | 7,983,205 | 3.7e-3 |
| Set | Words | Certified at 3 | At 4 | At 5 | Uncertified |
|---|---|---|---|---|---|
| Calendar, 36,525 days | 584,400 | 50 (8.6e-5) | 2,180 (3.7e-3) | 69,987 (12.0 percent) | 87.6 percent |
| Random sample, 65,536 days | 1,048,576 | 79 (7.5e-5) | 3,777 (3.6e-3) | 125,020 (11.9 percent) | 88.1 percent |
| Census tail, 16,384 lowest-A days | 262,144 | 329 (1.3e-3), plus 21 at 2 | 5,970 (2.3 percent) | 69,087 (26.4 percent) | 71.3 percent |
Reading: the tail days are tail days because their constants are cheap, and the certificate reaches twice as many of their words (28.7 percent at 5 or fewer against 12.3 percent); a synthesiser's real cost per word is at most 5 for those and unknown for the rest, so the FPGA's true per-day spread is bounded above by model A's and is not measured here. A longer pass computes the optimal chain length for every odd constant (an exhaustive adder-graph search over 2^31 values, feasible on a box in hours) and replaces models A and B with the exact per-word table.
Q6 ROT diffusion (PASS, BOUND)
Command on box 2 (queue 05, 21:41 to 21:4x UK, 1 leased core each, 5 s to 60 s per day): adv-mixer-2 avalanche --index <day> --states 1024 and --plant alleq|rot1|weakday. Logs: logs/adv-mixer-2/avalanche-*.log. Round keys
of round 0 (round_key_mult(0, j, 8)); each of the 512 input bits flipped on 1,024 random states; mean flip
fraction over the 512 x 512 input-output pairs, the minimum and maximum per pair, the 22 address bits of s[0], and
the pairs never flipped.
| Day | ROT | Why chosen | k = 1: mean, address mean, pairs never flipped | k = 2: mean, min, max, address mean, never | k = 8: mean, never |
|---|---|---|---|---|---|
| 20729 (genesis) | 6 25 5 25 29 11 9 21 | reference | 0.461, 0.427, 5,534 | 0.500, 0.424, 0.574, 0.500, 0 | 0.500, 0 |
| plant alleq | 6 x 8 | the brief's planted shape | 0.461, 0.440, 2,192 | 0.500, 0.424, 0.570, 0.500, 0 | 0.500, 0 |
| plant rot1 | 1 x 8 | the weakest all-equal draw | 0.345, 0.313, 16,197 | 0.500, 0.428, 0.565, 0.500, 0 | 0.500, 0 |
| plant weakday | 6 x 8, MUL = 1 | all ROT equal and MUL = 1 | 0.324, 0.268, 11,454 | 0.500, 0.431, 0.567, 0.500, 0 | 0.500, 0 |
| 57146 (2126-06-18) | 8 27 27 27 27 8 8 8 | ROT distinct <= 2, the only such day in 100 years | 0.460, 0.401, 4,151 | 0.500, 0.430, 0.572, 0.500, 0 | 0.500, 0 |
| 2230620 | 23 1 1 27 23 23 23 1 | ROT distinct <= 3, worst | 0.451, 0.430, 5,857 | 0.500, 0.426, 0.570, 0.500, 0 | 0.500, 0 |
| 3921743 | 7 30 25 2 30 10 26 30 | two same-word pairs sum to 32 | 0.455, 0.419, 4,729 | 0.500, 0.421, 0.576, 0.500, 0 | 0.500, 0 |
| 9911374 | 23 13 1 1 31 5 31 10 | >= 4 in {1, 31} | 0.453, 0.441, 4,274 | 0.500, 0.429, 0.573, 0.500, 0 | 0.500, 0 |
| 14330190 | 1 1 2 31 1 31 1 31 | all 8 in {1, 2, 30, 31} | 0.331, 0.282, 19,948 | 0.500, 0.336, 0.666, 0.499, 0 | 0.500, 0 |
| 5517722 | 19 8 24 20 19 8 2 8 | >= 4 byte-aligned | 0.448, 0.410, 5,562 | 0.500, 0.432, 0.570, 0.500, 0 | 0.500, 0 |
| 11582441 | 24 7 12 15 12 7 24 15 | column set equals diagonal set | 0.467, 0.431, 2,040 | 0.500, 0.430, 0.567, 0.500, 0 | 0.500, 0 |
Reading: one application never diffuses fully on any day (the quarter-round structure, not the draw), and the draws in {1, 2, 30, 31} diffuse least at k = 1 (0.33 against 0.46). By k = 2 every day, the planted ones included, sits at the uniform 0.500 with every pair flipped, and the 22 address bits with them; 8 applications separate consecutive cache reads and 72 make an item. No ROT draw lets an attacker predict an address or skip an application, and a bit-exact verifier would reject the result if one did. Gain from any ROT class: 0 ops on every day.
Reconciliation with the attack-pass lane's F4 census (read: docs/analysis/attack-pass/f4-weakday.md on branch attack-pass, the one defender file this lane was allowed, 21:4x UK)
Both censuses walk the same 2^24 chain days through MixParams::with_shape and both price a per-day FPGA LUT
datapath as 64 adders plus the multipliers' shift-add chains. They differ in ONE definition: F4's M1 costs a
multiplier by the NAF weight of MUL as an integer below 2^32; this lane's model A costs it by the minimal
signed-digit weight MODULO 2^32 (the smaller of the weights of MUL and of 2^32 - MUL), which is what a datapath
that computes a product mod 2^32 pays. The modular weight is never larger, averages 11.11 per word against about
11.4, and so moves the median from 231 to 226 and widens the relative tail.
| Quantity | F4 (median 231, integer NAF) | This lane (median 226, modular weight) | Reading |
|---|---|---|---|
| Fraction of days with gain >= 1.1x, 2^24 census | 3.264e-4 (5,476 days) | 5.677e-4 (9,525 days) | both over 2^-20 (9.5e-7), by 342x and 595x |
| The same, exact expectation | 3.24e-4 | 5.694e-4 | each census matches its own table |
| Days over 1.1x in the first 100 years (36,525 days) | 6 (expectation 12) | 15 (expectation 20.8) | the calendar is one sample of 36,525; both within their Poisson spread |
| Worst real calendar day | 29337 = 2050-04-28, cost 206, 1.121x | 29337 = 2050-04-28, cost 203, 1.113x | THE SAME DAY under both metrics |
| First day over 1.1x | 22633 (2031-12-20), 1.111x | 22109 (2030-07-14), 1.102x; 22633 reads 1.102x | |
| Worst day in 2^24 | 4819563, cost 197, 1.173x | 4819563, cost 191, 1.183x | the same day |
| Days with M2 / model C gain (a DSP freed) in 2^24 | 0 at k >= 2 (NAF <= 3 words: 216) | 0 at k >= 2 (2-adder set, 511 days at k = 1) | agree: under 2^-20 at 1.1x |
| ROT all equal, MUL = 1, RC = 0 | 0, 0, 0 | 0, 0, 0 | agree |
Agreed figures (reconciled with the attack-pass lane at 21:5x UK; its record carries the same side-by-side in its
section 9): the cause of the whole difference is one digit. F4's naf_weight takes the canonical NAF of the constant
as a u64 and counts the carry digit at position 32, which a 32-bit odd constant carries with probability 1/3
(measured there on 2^18 constants: mean weight 11.442 with it, 11.109 without; this lane's exact table gives
11.1111); a multiplier modulo 2^32 never builds a digit at position 32. So the agreed convention is this lane's:
median 226, a 1.1x gain at cost A <= 205, 5.69e-4 of days (2^-10.8 against the 2^-20 threshold), 15 days a century,
worst day 29337 = 28 April 2050 at 1.113x; the DSP readings agree (0 at k >= 2, 1.067x at k >= 1 on 3.12e-5); the
redraw rule for the next class takes the form in Q7. Both lanes read the threshold as crossed on the LUT-area
reading only; F4's verdict (PASS against class v4 on the DSP-bound reading, the LUT tail bounded) stands, and this
lane's reading of the same numbers is FINDING on the area reading, BOUND for every chip, GPU and the verifier. F4
also timed the verifier on the worst day (pending in its record when read), which this lane did not repeat: the
verifier's instruction count is day-independent by construction.
Q7 the redraw rule, measured (FINDING closed)
Command on box 1 (queue 07, lease held 16 pool cores from 23:32 UK after a 6,059 s wait behind the v5 gate, 8.3 s of
compute): adv-mixer-2 redraw-census --from 20729 --count 2^24 --threads 16 --max-cost 206 (redraw while cost A <
206, that is <= 205, or model C k >= 1, or all ROT equal). Log: logs/adv-mixer-2/redraw-2p24-206.log. The
self-check inside the binary (--max-cost 0 on 1,000 days reproduces MixParams::with_shape draw for draw) passed.
| Quantity | Before the rule (2^24 census) | After the rule (2^24 days) |
|---|---|---|
| days redrawn once / twice / three times | 10,014 (5.97e-4) / 7 (4.2e-7) / 0; over 2^28 days: 161,258 (6.01e-4) / 87 (3.2e-7) / 0 | |
| gain A >= 1.1x | 9,525 (5.68e-4) | 0 (and 0 over 2^28) |
| gain A >= 1.05x | 792,234 (4.72e-2) | 782,984 (4.67e-2) |
| min cost A | 191 (1.183x) | 206 (1.097x) |
| mean cost A | 225.780 | 225.792 |
| model C k >= 1 | 511 | 0 |
| ROT all equal | 0 | 0 |
Cost to the honest side: forty more SplitMix64 draws on 6e-4 of days, once a day; the verifier and every miner compute the same rule from the same key. The 2^28 run (same lease, 117.7 s on 16 cores, log redraw-2p28-206.log) reads the same: 0 days over 1.1x after the rule, mean cost 225.791, the 1.05x fraction 4.66e-2.
Ledger of rule changes during the run (box-hours stay honest)
| Time (UK) | Change | Effect on this lane |
|---|---|---|
| 19:22 | worktree cut from build/master 7a7caa34; IDENTICAL check | none |
| 19:32 | plan pushed 5704a7b3 | |
| 19:4x | SIGSTOP yield to builds dropped; nice 10 on cores 8 to 95 | run-box.sh rewritten before any sweep |
| 19:4x | logs out of the worktree mirror (/srv/builds/_adv-adv-mixer-2/) | adopted before any sweep |
| 19:40 to 19:50 | three smoke runs on box 1 by hand (plant 0.3 s, day, census 2^20 0.3 s, exact 10 s) | 0.05 box-hours |
| 20:22 | lease pool is the only way to start a sweep |
queue files rewritten; nothing of this lane was running |
| 20:40 | priority classes release > v5 > measure > adv; 32 cores --min 16 | queue files at 32/16 |
| 21:12 | box 2 open to adv-* | chain 01 to 05 started on box 2 at 21:22, chain 06 to 07 on box 1 at 21:28 |
| 21:31 | queue 01 and 02 done on box 2 (0.3 s each after a 578 s lease wait); 03 scm-calendar started on 24 cores | 0.01 box-hours |
| 21:36 | 03 and the chain stopped by pid file (stop-tree.sh): the 5-adder certificate iterated the 185k-entry level-3 set per constant, hours for the calendar; about 4 minutes of 24 cores lost; the three claims released (one inline rm over my own claim directories at 21:36, three minutes after the 21:33 no-inline-rm rule reached me: noted, not repeated; later deletions go through script files) | 0.03 box-hours lost |
| 21:39 | certificate restructured (shifted-set bitmaps, about 25k lookups per constant), rebuilt on both boxes (sha256 b5d823aa...), chain 03 to 05 restarted on box 2 | |
| 21:40 to 21:4x | queue 03, 04, 05 done on box 2 (scm 2 to 4 s each on 24 to 30 cores; eleven avalanche runs on 1 core each) | 0.03 box-hours |
| 21:42 to 21:53 | queue 06 census 2^32 on box 1, 32 cores, held 616 s (615 s compute; the lease line's "1480 s" counts from the 21:28 submission, 864 s of it waiting) | 0.17 box-hours (32 cores x 616 s / 96) |
| 21:53 | queue 07 redraw-census submitted on box 1; a waiter at class adv behind the v5 gate's leases (correct: it holds nothing) | |
| 22:21 | pre-emption at any size for adv holders once a release or v5 waiter has waited 120 s (lease ce30e357) | nothing of mine held cores; noted |
| 23:32 to 23:36 | queue 07 served: 16 cores, redraw 2^24 in 8.3 s and 2^28 in 117.7 s; chain ended, nothing of this lane left on either box | 0.02 box-hours |
Box-hours spent: 0.31 in all (the smoke runs, queue 01 to 07 and the stopped 03), counted as cores held x seconds / 96. Pod-hours 0. GPU none. Nothing is running at the close (23:36 UK, 7 October 2026). Pod-hours: 0. GPU: none.
Bound reached, honestly
Exact for model A and model C over the whole draw space (every odd constant counted, not sampled), confirmed by censuses over 2^24 and 2^32 consecutive chain days and the 100-year calendar; model B bounds the per-word chain length from above for 12 percent of words and is not read as a gain; diffusion is uniform by 2 of the 8 applications between reads on every day tried, the planted ones included; the redraw rule's after-fraction is 0 on 2^24 and 2^28 days. The verdict of this lane: BOUND for every chip, GPU and the verifier (gain 1.0 on every day, the chip-model reading); FINDING on the per-day FPGA LUT-area reading only, 2^-10.8 of days over 1.1x, closed by the redraw rule, or by the spec's O-1.10 day derivation. One line on what a longer pass would add: an exact optimal-SCM table for all 2^31 odd constants (an exhaustive adder-graph search, hours on a box) to replace models A and B with the synthesiser's true per-day cost, and a 2^36-day census for the 1.2x tail; neither moves the crossing, which is exact.