igneum/docs/analysis/cryptanalysis/logs/adv-cache-3/pebble.log
2026-10-07 19:28:55 +00:00

37 lines
4.3 KiB
Text

lease: holding 88 pool cores (8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95, waited 0 s): adv-cache-3 pebble
[2026-10-07T19:22:57Z] adv-cache-3 pebble (internal adversarial pass, not an independent review)
[2026-10-07T19:22:57Z] self-test: restated B equals chacha_block on 4,096 inputs; core_inv inverts core at w = 2, 4, 8, 16, 32; the restated chain equals Cache::fill_segment on segments 0, 21859, 65535 of day 20730
[2026-10-07T19:22:57Z] pebble: lines 64 exhaustive check up to 16 lines, Monte Carlo 1000000 trials per point, skip edge none (the plain path)
[2026-10-07T19:22:57Z] exhaustive n=10 k=1: optimum 2.5000 blocks per read, DP 2.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=10 k=2: optimum 1.5000 blocks per read, DP 1.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=10 k=4: optimum 0.7000 blocks per read, DP 0.7000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=12 k=1: optimum 3.0000 blocks per read, DP 3.0000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=12 k=2: optimum 1.8333 blocks per read, DP 1.8333 AGREE
[2026-10-07T19:22:57Z] exhaustive n=12 k=4: optimum 0.9167 blocks per read, DP 0.9167 AGREE
[2026-10-07T19:22:57Z] exhaustive n=14 k=1: optimum 3.5000 blocks per read, DP 3.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=14 k=2: optimum 2.1429 blocks per read, DP 2.1429 AGREE
[2026-10-07T19:22:57Z] exhaustive n=14 k=4: optimum 1.0714 blocks per read, DP 1.0714 AGREE
[2026-10-07T19:22:57Z] exhaustive n=16 k=1: optimum 4.0000 blocks per read, DP 4.0000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=16 k=2: optimum 2.5000 blocks per read, DP 2.5000 AGREE
[2026-10-07T19:22:57Z] exhaustive n=16 k=4: optimum 1.3125 blocks per read, DP 1.3125 AGREE
[2026-10-07T19:22:57Z] static curve (blocks per uniform read; ops per item = 9,360 + 8 x blocks x 608; SRAM = f x 128 mm^2 at the N5 headline of chip-model-v3 section 2):
[2026-10-07T19:22:57Z] f=k/64 | k held | DP optimum (plain path) | stride offset 0 | stride offset step-1 | best over the planted graph (k=1 exhaustive, else local search) | ops per item at the optimum | SRAM mm^2
[2026-10-07T19:22:57Z] 1/64 | 1 | 16.0000 | 31.5000 | 31.5000 | 16.0000 | 87184 | 2.0
[2026-10-07T19:22:57Z] 2/64 | 2 | 10.5000 | 15.5000 | 15.5000 | 10.5000 | 60432 | 4.0
[2026-10-07T19:22:57Z] 4/64 | 4 | 6.0938 | 7.5000 | 7.5000 | 6.0938 | 39000 | 8.0
[2026-10-07T19:22:57Z] 8/64 | 8 | 3.1719 | 3.5000 | 3.5000 | 3.1719 | 24788 | 16.0
[2026-10-07T19:22:57Z] 16/64 | 16 | 1.4531 | 1.5000 | 1.5000 | 1.4531 | 16428 | 32.0
[2026-10-07T19:22:57Z] 32/64 | 32 | 0.5000 | 0.5000 | 0.5000 | 0.5000 | 11792 | 64.0
[2026-10-07T19:22:57Z] 64/64 | 64 | -0.0000 | 0.0000 | 0.0000 | -0.0000 | 9360 | 128.0
[2026-10-07T19:22:57Z] static curve: monotone in f YES; f = 1 reads 9360 ops per item (gate 9,360); planted graph under the path optimum at some f: NO PASS
[2026-10-07T19:22:57Z] amortising adversary (Monte Carlo 1000000 trials): blocks per read with m requests in one segment, one walk per gap from the nearest held line to the deepest request; the stride store at offset step-1 (the DP optimum's shape for k >= 2)
[2026-10-07T19:22:57Z] f=k/64 | m=1 | m=2 | m=4 | m=8 | m=16 | m=64 | Poisson m=1 | Poisson m=8 | Poisson m=64
[2026-10-07T19:22:58Z] 1/64 | 31.523 | 21.072 | 12.670 | 7.046 | 3.733 | 0.976 | 23.242 | 6.948 | 0.975
[2026-10-07T19:22:58Z] 2/64 | 15.487 | 12.938 | 9.550 | 6.095 | 3.466 | 0.951 | 13.236 | 5.899 | 0.950
[2026-10-07T19:22:58Z] 4/64 | 7.498 | 6.896 | 5.889 | 4.484 | 2.939 | 0.902 | 6.931 | 4.325 | 0.899
[2026-10-07T19:22:58Z] 8/64 | 3.498 | 3.363 | 3.113 | 2.694 | 2.085 | 0.804 | 3.369 | 2.619 | 0.801
[2026-10-07T19:22:58Z] 16/64 | 1.500 | 1.472 | 1.420 | 1.324 | 1.157 | 0.614 | 1.474 | 1.303 | 0.612
[2026-10-07T19:22:58Z] 32/64 | 0.500 | 0.496 | 0.489 | 0.474 | 0.445 | 0.317 | 0.496 | 0.471 | 0.316
[2026-10-07T19:22:59Z] 64/64 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000 | 0.000
[2026-10-07T19:22:59Z] cross-check points: the plain path with nothing held at m = 1 must read 32.5 (E[j] + 1); sibling adv-cache measured 23.84, 7.06 and 0.99 blocks per read on real addresses at Poisson m = 1, 8, 64 with nothing held (its batch rows)
lease: released 88 pool cores after 2 s, exit 0