An isolated research harness for combining three already-existing systems without changing any of them:
- the full-round recovery backend supplies immutable evidence and exact confirmation;
- O1 supplies bounded recurrent evidence accumulation;
- O1-O supplies deterministic operator composition and failure memory.
This directory is a sibling of the active repositories. It never writes into
arx-carry-leak, f8-causal-cryptanalysis, fullround-key-recovery, O1, or O1-O.
Published evidence is consumed only through SHA-256-verified, read-only adapters.
The live research cockpit is STATUS.md. It points to the last immutable
run, the strongest supported claim, active uncertainty and the ranked next action.
Historical outcomes—including negative mechanisms—are indexed in
RESULTS_INDEX.md and the append-only files under research/.
This repository is the complete defensive publication of the cryptO1
research line. It publishes executable mechanisms, frozen configurations,
source-bound run capsules, positive results, negative results, and the exact
limits of each claim under Apache-2.0. Git history and immutable artifact
manifests are part of the evidence record.
The self-contained defensive publication, claim boundary, reproduction guide and citation metadata define the initial public release.
The repository does not currently claim an exact attacker-valid recovery of an unknown 256-bit ChaCha20 key, a practical break of ChaCha20, or global exhaustion of its key space. It does establish bounded-state 256-bit retention, fresh full-round rank transfer, exact Full-256 safe branch pruning and exclusion-stream mechanisms, plus a reproducible solver-native causal-memory architecture. Every stronger claim remains gated on exact public ChaCha20 verification.
The active target is no longer a progressively wider residual-key benchmark. Every serious target is standard twenty-round ChaCha20 plus feed-forward with all 256 key bits unknown. Deployment sees only public counter, nonce and output. It may also evaluate keys it generated itself and inspect those candidate traces; target round states, carry paths and key labels are training-only.
The execution path is effect-first:
public target -> new all256 evidence -> O1 completion/beam -> exact A325/A526 entry gate -> unchanged residual backend -> public ChaCha verification. Key NLL,
fixed-complement correctness, exact-containing beam rank and verified recovery are
the progress metrics; infrastructure and synthetic mechanism passes are not SOTA.
The complete attacker contract and architecture are in O1-256 Living Inverse. The W52 mechanisms were inspected read-only and are summarized in the 2026-07-17 transfer map. The post-O1C-0016 continuous fast/slow learner and learned picker are specified in O1 Online Möbius Controller.
O1C-0068 produced 190 globally novel exact score-threshold exclusions from
one complementary Full-256 reader call. O1C-0073 then produced 311 novel
exclusions, and O1C-0074 retained the complete immutable 550-clause causal
attic while keeping the live projection bounded at K=256 clauses. These are
real attacker-visible search constraints, not an exact recovery claim.
O1C-0079 completed the first central decision-instance ownership run on the
same public Full-256 relation. The native call consumed exactly 128 conflicts
in 176,794 us at 390,922,240 bytes peak RSS. All 549 proposed decisions
were level-bound and released with zero live or omitted tokens; the sealed
11-row prefix activated and the frontier became reachable. It nevertheless
returned zero prunes, zero new clauses, zero model and no key. The archived
runner initially marked the mechanism inactive because a substring audit
mistook the safe descriptor never-returned-ever for legacy state. The
checksum-preserving zero-call erratum corrects only those operational axes to
DECISION_OWNERSHIP_QUALIFIED_PREFIX_MECHANISM_ONLY; science remains negative.
The exact resume point is an exact child-bound crossing reader on fresh Page 7: intervene only when one public admissible child bound is strictly below the frozen threshold. No budget scaling or replay of Page 6 is authorized. See STATUS.md and the O1C-0079 interpretation.
The sections below retain the earlier architecture lineage and are historical, not current resume instructions.
The strongest immutable architecture attempt is now O1C-0017. From 330 anonymous
raw channels, a bounded reveal-delayed O1 reader autonomously discovered one hidden
oriented channel and retained all 256 addressed readings in its Bit-Vault. On 16
untouched synthetic full-width episodes it obtains 3286/4096 bits,
+42.308742 bits mean compression and 80.224609% accuracy, with all 16 targets
positive. It beats signal ablation by 46.701393 bits, shifted-label learning by
42.764897 and its own raw end-of-stream O1 field by 47.231321. Classification:
MECHANISM_PASS.
O1C-0018 has now executed that architecture on deterministic known-key standard
twenty-round ChaCha20 paired-proof pools while hiding all 256 key bits from the
target-time reader. The raw learned Bit-Vault is negative on both disjoint
DEVELOPMENT targets (-1.284644 mean bits), so the frozen classification is
NO_RAW_SIGNAL_PICKER_UNINTERPRETABLE. The early true-reward picker nevertheless
is positive on both targets at W1 (+0.326847/+0.160175) and beats its shifted-
reward control in all six target-by-checkpoint cells.
Deterministic post-reveal replay explains the boundary. Hard coverage contributes
0.5 to the first score while learned reward is about 0.00195; the hash-32
shortlist and compulsory breadth therefore own almost the entire route. The reader
also adds an already cumulative O1 query repeatedly, and the critic mixes credits
from changing reader versions. O1C-0018 forensics
turn these failures into the O1C-0019 design: same-coordinate multiresolution
packets, learned incremental/gated evidence, reader-SHA-bound stationary credit,
all-address public preview, soft no-starvation attention and learned stopping.
The strongest sealed cryptanalytic attempt remains O1C-0016. It froze exact h96
and a fixed equal-logit h96+h65 successor before attacking 32 entirely new
OS-random sealed keys using only public counter/nonce/output. The ensemble obtains
4093/8192 bits and -0.078249 bit/key, with 11/32 positive targets and a
-0.080225 margin over shuffled (z=-0.555); no exact key is emitted.
Classification: NOT_REPLICATED / DO_NOT_PROMOTE.
The full lifecycle is nevertheless validated: 680/680 capsule members verify, every commitment and independently recomputed output matches, all resource gates pass, and the live target state remains 67,584 bytes. O1C-0015 remains an immutable operational failure whose 32 burned targets will never be replayed; O1C-0016 uses an entirely separate panel and supplies its valid scientific answer.
The main breadcrumb is not another coordinate to freeze. Per-target primary-h65
and matched-shuffled compression correlate 0.999905, while O1C-0014-to-0016
coordinate transfer is approximately zero. The global unary readers saw a
repeatable public-instance difficulty/amplitude field but did not learn hidden-key
orientation. The post-reveal audit
therefore motivated the zero-fresh-entropy O1C-0017 integration gate, which passed
every frozen control. O1C-0018 then completed the full-round transition and found
an early true-versus-shifted policy breadcrumb without a raw reader pass. O1C-0019
now gives learned utility real agency and aligns the trained readout with its live
update. Fresh sealed entropy remains closed until artifact-only cross-fits win.
The initial benchmark deliberately separates three questions that are easy to confound:
- Closed-gate storage qualification. Once relevance has already been decided, can a fixed state retain 256 binary bindings through a long haystack?
- Evidence amplification. If each public observation already contains a weak, independent bit signal, does a streaming accumulator amplify it? Does the same apparent per-observation accuracy fail when errors are correlated?
- Information-flow safety. Can a typed operator chain produce a frozen target-blind order while structurally rejecting any path that uses a revealed model or target secret?
It does not claim that a full-round cipher exposes such a signal. O1C-0018 is the first direct observability test and does not pass its raw-signal gate.
The full-context attention arm is an explicitly invalid O(T) attack but an exact
harness ceiling. The direct 256-register vault is an intentionally honest bounded
baseline. It is constant in stream length, but it is a position-indexed register
bank and therefore does not
demonstrate holographic compression. The holographic arm receives the same number
of scalar cells (128 complex channels = 256 real scalars), while the undersized
CountSketch arm is a capacity control. Precision and serialized byte size are still
reported separately before any efficiency claim; equal cell count is not equal
information budget.
The current haystack transition is an explicit ideal no-op for bounded arms. This isolates storage capacity and holographic crosstalk; it does not claim to have trained O1's selective input gate. Learned unified-token routing is the next memory stage, not a hidden property of this smoke test.
The package pins NumPy 2.2.6 because exact reproduction of the historical
Direct12 floating-point reader is part of the evidence contract; the remaining
harness uses the Python standard library.
python3 -m venv .venv
.venv/bin/pip install -r requirements-dev.txt
.venv/bin/pip install -e .
PYTHONPATH=src .venv/bin/python -m pytest -q \
tests/test_o1c79_decision_ownership_v1.py \
tests/test_joint_score_sieve_v20.py \
tests/test_o1c79_apple8_decision_ownership_prepare.py \
tests/test_o1c79_apple8_decision_ownership_run.py
.venv/bin/o1-crypto-lab benchmark \
--config configs/quick.json \
--output runs/quick.json
.venv/bin/o1-crypto-lab living-inverse-foundation \
--config configs/living_inverse_foundation_v1.json
.venv/bin/o1-crypto-lab full256-paired-sensor \
--config configs/full256_paired_causal_sensor_v1.jsonInstall -e '.[train]' instead of -e . for the historical learned-O1 tests.
Some archived experiments deliberately bind an exact CPython build and source
closure; their freeze tests are provenance checks, not portable smoke tests.
Inspect the operator compiler and its leakage rejection:
.venv/bin/o1-crypto-lab compose
.venv/bin/o1-crypto-lab boundaryReplay the supplied real O1-O session as normalized evidence without importing or executing any generated program. This optional command expects a local checkout of DT-Foss/O1-O; substitute its real path:
.venv/bin/o1-crypto-lab replay-o1o \
--session /path/to/O1-O/2026-02-18_013412 \
--output runs/o1o-2026-02-18-replay.json \
--include-eventsThe replay intentionally distinguishes generation success, process success,
capability evidence and mission progress. Raw stdout/stderr is never copied into
the O1 stream; only its length and an unsalted integrity fingerprint remain until a
domain-specific parser has validated its semantics. That fingerprint is not a
confidentiality guarantee for guessable output. engagement_report.json contributes
hashed aggregate retry/recovery/chaining counts, and every normalized event is fed
neutrally into a capped TargetModel without being mislabeled as research success.
The February format did not retain explicit retry-parent IDs, so the replay reports
aggregate topology rather than inventing edges.
Verify a published snapshot before an adapter reads it:
.venv/bin/o1-crypto-lab verify-source \
--root ../fullround-key-recovery \
--manifest ../fullround-key-recovery/provenance/ARTIFACTS.sha256 \
--output runs/fullround-source-verification.jsonRun the manifest-pinned Stage-3 ingestion and frozen retrospective reader protocol:
.venv/bin/o1-crypto-lab stage3-ingest \
--config configs/stage3_a296_a297_ingest_v1.json
.venv/bin/o1-crypto-lab stage3-reader \
--config configs/stage3_reader_retrospective_v1.jsonEach command creates a new read-only directory named
runs/YYYYMMDD_HHMMSS_O1C-.../ with RUN.md, exact config and command,
environment, metrics, logs, checkpoints, retained artifacts and a complete
SHA-256 manifest. Attempt IDs are permanently reserved and cannot overwrite a
prior result. Verify any capsule with:
.venv/bin/o1-crypto-lab verify-run runs/<capsule-name>Recompute the label-using O1C-0018 diagnostics without generating a target or changing any model state:
PYTHONPATH=src .venv/bin/python \
-m o1_crypto_lab.full256_online_real_forensics \
--capsule runs/20260717_152827_O1C-0018_full256-online-real-gate-dev-v1The Direct12 dependency chain originally lived in a dirty sibling worktree. It is therefore curated honestly into its own immutable capsule instead of being called a clean Fullround-manifest artifact:
.venv/bin/o1-crypto-lab direct12-snapshot \
--config configs/direct12_source_snapshot_v1.jsonReproduce the frozen 133-to-532 trajectory reader from that capsule, then run the bounded-memory mechanism tournament:
.venv/bin/o1-crypto-lab direct12-reproduce \
--config configs/direct12_reproduction_v1.json
.venv/bin/o1-crypto-lab bounded-memory-tournament \
--config configs/bounded_memory_tournament_v1.json
.venv/bin/o1-crypto-lab corrected-codec-bridge \
--config configs/corrected_codec_bridge_v1.json
.venv/bin/o1-crypto-lab upstream-ising-freeze \
--config configs/upstream_ising_retrospective_v1.jsonThe tournament compares global Walsh state, sixteen fixed low4/high8 slot banks, and a dense 2–8-bit integer Bit-Vault. O1-O sees only A348 target-blind fidelity, serialized online-state bytes, update work and clip counts. It persists one future template before the A349 score member is opened; all complete A349 orders are then persisted before the separate A348 truth API is called. Direct candidate tables and full spectral banks remain clearly labeled ceilings and cannot win the mechanism gate. The dense Bit-Vault is a full-rank 4,080-register mechanism, not a claim of sublinear capacity.
The corrected-codec bridge reproduces A355/A356 exactly and retains the selected 6-bit DC-complete bank only as a validation ceiling. Its 4,096 spectral degrees of freedom are information-equivalent to the fixed candidate table, and its 8,014-byte maximum serialized logical state is larger than the matched 3,918-byte direct baseline.
The upstream freeze replaced the dense final-field representation with a
12-register unary solver-evidence memory. Its conservative logical-state bound is
266 bytes and its frozen binary is 162 bytes. The complete target-blind A355 panel
contained 672 orders; the frozen decoder ranked the retrospective target at 73,
but the exact conditional random-label tail was 2431/4096 = 0.593505859375.
That is a structurally eligible compact mechanism and a negative efficacy result,
not SOTA. The same decoder emitted a complete A356 order before any A356 target or
outcome read, but A356 still came from the same opened source capsule and is not a
source-unseen holdout. That planned narrow W46 follow-up is now superseded.
O1C-0008 instead freezes the full-256 public-output attacker type, separately typed
teacher labels, exact traced relation generator, six Contrast-Key families, sealed
full-256 broker and the complete non-recovery progress vector. The unary decoder
remains one matched baseline inside the new architecture.
The expensive immutable-snapshot integration gates are opt-in:
O1_CRYPTO_DIRECT12_REAL=1 \
.venv/bin/python -m unittest discover -s tests -v
O1_CRYPTO_CORRECTED_REAL=1 \
.venv/bin/python -m unittest discover -s tests -v
O1_CRYPTO_UPSTREAM_REAL=1 \
.venv/bin/python -m unittest discover -s tests -v- No imports from the dirty live O1, O1-O, or
arx-carry-leaktrees. - Runtime experiment bytes are confined to
runs/. A separate symlink-safe writer may update only the seven enumerated cockpit Markdown files at the lab root and underresearch/; it cannot write arbitrary lab or sibling paths. - CPU-only by default. MPS/GPU use requires a short explicit resource-checked window and cannot compete with the active sibling recovery queue.
- No target label, recovered model, post-reveal rank, or target-internal state may
flow into a
TARGET_BLIND_ORDER. - Training-time internal round states may teach an operator, but evaluation-time features must be public or recomputable from public equations under an explicitly billed candidate assumption.
- Every learned operator is selected on training/validation keys, frozen and hashed,
then evaluated once on disjoint test keys with matched controls. The lifecycle is
enforced as
DISCOVERY -> FROZEN -> TEST_CONSUMED -> AUDIT; the exact proposal and plan hashes are bound at freeze time. - State size, external-index growth, samples and total cipher/solver work are reported
separately.
O(1)always means constant in stream length unless another axis is named explicitly.
See Architecture, O1-256 Living Inverse, Experiment ladder, and Scientific boundaries. The first reproducible smoke-test measurements are recorded in First results.
configs/ deterministic benchmark configurations
docs/ architecture, gates and claim boundaries
provenance/ lab-owned byte ledgers and source-boundary records
research/ hypotheses, append-only attempts, breadcrumbs, next actions
src/o1_crypto_lab/ memory, composer, replay, TargetModel, adapters and CLI
tests/ unit, leakage and reproducibility gates
runs/ immutable timestamped capsules (ignored by Git, never overwritten)
The design is derived from the Apache-2.0 O1 and O1-O projects. No source from their offensive modules is executed or imported here; only the domain-agnostic bounded-state, typed-composition, verification and failure-memory ideas are used.