Skip to content

DT-Foss/Cryptanalytic-Memory-Lab

Repository files navigation

Cryptanalytic Memory Lab (cryptO1)

An isolated research harness for combining three already-existing systems without changing any of them:

  • the full-round recovery backend supplies immutable evidence and exact confirmation;
  • O1 supplies bounded recurrent evidence accumulation;
  • O1-O supplies deterministic operator composition and failure memory.

This directory is a sibling of the active repositories. It never writes into arx-carry-leak, f8-causal-cryptanalysis, fullround-key-recovery, O1, or O1-O. Published evidence is consumed only through SHA-256-verified, read-only adapters.

The live research cockpit is STATUS.md. It points to the last immutable run, the strongest supported claim, active uncertainty and the ranked next action. Historical outcomes—including negative mechanisms—are indexed in RESULTS_INDEX.md and the append-only files under research/.

Public disclosure and claim boundary

This repository is the complete defensive publication of the cryptO1 research line. It publishes executable mechanisms, frozen configurations, source-bound run capsules, positive results, negative results, and the exact limits of each claim under Apache-2.0. Git history and immutable artifact manifests are part of the evidence record.

The self-contained defensive publication, claim boundary, reproduction guide and citation metadata define the initial public release.

The repository does not currently claim an exact attacker-valid recovery of an unknown 256-bit ChaCha20 key, a practical break of ChaCha20, or global exhaustion of its key space. It does establish bounded-state 256-bit retention, fresh full-round rank transfer, exact Full-256 safe branch pruning and exclusion-stream mechanisms, plus a reproducible solver-native causal-memory architecture. Every stronger claim remains gated on exact public ChaCha20 verification.

Active Moonshot: O1-256 Living Inverse

The active target is no longer a progressively wider residual-key benchmark. Every serious target is standard twenty-round ChaCha20 plus feed-forward with all 256 key bits unknown. Deployment sees only public counter, nonce and output. It may also evaluate keys it generated itself and inspect those candidate traces; target round states, carry paths and key labels are training-only.

The execution path is effect-first: public target -> new all256 evidence -> O1 completion/beam -> exact A325/A526 entry gate -> unchanged residual backend -> public ChaCha verification. Key NLL, fixed-complement correctness, exact-containing beam rank and verified recovery are the progress metrics; infrastructure and synthetic mechanism passes are not SOTA.

The complete attacker contract and architecture are in O1-256 Living Inverse. The W52 mechanisms were inspected read-only and are summarized in the 2026-07-17 transfer map. The post-O1C-0016 continuous fast/slow learner and learned picker are specified in O1 Online Möbius Controller.

Current result — 2026-07-20

O1C-0068 produced 190 globally novel exact score-threshold exclusions from one complementary Full-256 reader call. O1C-0073 then produced 311 novel exclusions, and O1C-0074 retained the complete immutable 550-clause causal attic while keeping the live projection bounded at K=256 clauses. These are real attacker-visible search constraints, not an exact recovery claim.

O1C-0079 completed the first central decision-instance ownership run on the same public Full-256 relation. The native call consumed exactly 128 conflicts in 176,794 us at 390,922,240 bytes peak RSS. All 549 proposed decisions were level-bound and released with zero live or omitted tokens; the sealed 11-row prefix activated and the frontier became reachable. It nevertheless returned zero prunes, zero new clauses, zero model and no key. The archived runner initially marked the mechanism inactive because a substring audit mistook the safe descriptor never-returned-ever for legacy state. The checksum-preserving zero-call erratum corrects only those operational axes to DECISION_OWNERSHIP_QUALIFIED_PREFIX_MECHANISM_ONLY; science remains negative.

The exact resume point is an exact child-bound crossing reader on fresh Page 7: intervene only when one public admissible child bound is strictly below the frozen threshold. No budget scaling or replay of Page 6 is authorized. See STATUS.md and the O1C-0079 interpretation.

The sections below retain the earlier architecture lineage and are historical, not current resume instructions.

The strongest immutable architecture attempt is now O1C-0017. From 330 anonymous raw channels, a bounded reveal-delayed O1 reader autonomously discovered one hidden oriented channel and retained all 256 addressed readings in its Bit-Vault. On 16 untouched synthetic full-width episodes it obtains 3286/4096 bits, +42.308742 bits mean compression and 80.224609% accuracy, with all 16 targets positive. It beats signal ablation by 46.701393 bits, shifted-label learning by 42.764897 and its own raw end-of-stream O1 field by 47.231321. Classification: MECHANISM_PASS.

O1C-0018 has now executed that architecture on deterministic known-key standard twenty-round ChaCha20 paired-proof pools while hiding all 256 key bits from the target-time reader. The raw learned Bit-Vault is negative on both disjoint DEVELOPMENT targets (-1.284644 mean bits), so the frozen classification is NO_RAW_SIGNAL_PICKER_UNINTERPRETABLE. The early true-reward picker nevertheless is positive on both targets at W1 (+0.326847/+0.160175) and beats its shifted- reward control in all six target-by-checkpoint cells.

Deterministic post-reveal replay explains the boundary. Hard coverage contributes 0.5 to the first score while learned reward is about 0.00195; the hash-32 shortlist and compulsory breadth therefore own almost the entire route. The reader also adds an already cumulative O1 query repeatedly, and the critic mixes credits from changing reader versions. O1C-0018 forensics turn these failures into the O1C-0019 design: same-coordinate multiresolution packets, learned incremental/gated evidence, reader-SHA-bound stationary credit, all-address public preview, soft no-starvation attention and learned stopping.

The strongest sealed cryptanalytic attempt remains O1C-0016. It froze exact h96 and a fixed equal-logit h96+h65 successor before attacking 32 entirely new OS-random sealed keys using only public counter/nonce/output. The ensemble obtains 4093/8192 bits and -0.078249 bit/key, with 11/32 positive targets and a -0.080225 margin over shuffled (z=-0.555); no exact key is emitted. Classification: NOT_REPLICATED / DO_NOT_PROMOTE.

The full lifecycle is nevertheless validated: 680/680 capsule members verify, every commitment and independently recomputed output matches, all resource gates pass, and the live target state remains 67,584 bytes. O1C-0015 remains an immutable operational failure whose 32 burned targets will never be replayed; O1C-0016 uses an entirely separate panel and supplies its valid scientific answer.

The main breadcrumb is not another coordinate to freeze. Per-target primary-h65 and matched-shuffled compression correlate 0.999905, while O1C-0014-to-0016 coordinate transfer is approximately zero. The global unary readers saw a repeatable public-instance difficulty/amplitude field but did not learn hidden-key orientation. The post-reveal audit therefore motivated the zero-fresh-entropy O1C-0017 integration gate, which passed every frozen control. O1C-0018 then completed the full-round transition and found an early true-versus-shifted policy breadcrumb without a raw reader pass. O1C-0019 now gives learned utility real agency and aligns the trained readout with its live update. Fresh sealed entropy remains closed until artifact-only cross-fits win.

What the first benchmark proves

The initial benchmark deliberately separates three questions that are easy to confound:

  1. Closed-gate storage qualification. Once relevance has already been decided, can a fixed state retain 256 binary bindings through a long haystack?
  2. Evidence amplification. If each public observation already contains a weak, independent bit signal, does a streaming accumulator amplify it? Does the same apparent per-observation accuracy fail when errors are correlated?
  3. Information-flow safety. Can a typed operator chain produce a frozen target-blind order while structurally rejecting any path that uses a revealed model or target secret?

It does not claim that a full-round cipher exposes such a signal. O1C-0018 is the first direct observability test and does not pass its raw-signal gate.

The full-context attention arm is an explicitly invalid O(T) attack but an exact harness ceiling. The direct 256-register vault is an intentionally honest bounded baseline. It is constant in stream length, but it is a position-indexed register bank and therefore does not demonstrate holographic compression. The holographic arm receives the same number of scalar cells (128 complex channels = 256 real scalars), while the undersized CountSketch arm is a capacity control. Precision and serialized byte size are still reported separately before any efficiency claim; equal cell count is not equal information budget.

The current haystack transition is an explicit ideal no-op for bounded arms. This isolates storage capacity and holographic crosstalk; it does not claim to have trained O1's selective input gate. Learned unified-token routing is the next memory stage, not a hidden property of this smoke test.

Run

The package pins NumPy 2.2.6 because exact reproduction of the historical Direct12 floating-point reader is part of the evidence contract; the remaining harness uses the Python standard library.

python3 -m venv .venv
.venv/bin/pip install -r requirements-dev.txt
.venv/bin/pip install -e .
PYTHONPATH=src .venv/bin/python -m pytest -q \
  tests/test_o1c79_decision_ownership_v1.py \
  tests/test_joint_score_sieve_v20.py \
  tests/test_o1c79_apple8_decision_ownership_prepare.py \
  tests/test_o1c79_apple8_decision_ownership_run.py
.venv/bin/o1-crypto-lab benchmark \
  --config configs/quick.json \
  --output runs/quick.json
.venv/bin/o1-crypto-lab living-inverse-foundation \
  --config configs/living_inverse_foundation_v1.json
.venv/bin/o1-crypto-lab full256-paired-sensor \
  --config configs/full256_paired_causal_sensor_v1.json

Install -e '.[train]' instead of -e . for the historical learned-O1 tests. Some archived experiments deliberately bind an exact CPython build and source closure; their freeze tests are provenance checks, not portable smoke tests.

Inspect the operator compiler and its leakage rejection:

.venv/bin/o1-crypto-lab compose
.venv/bin/o1-crypto-lab boundary

Replay the supplied real O1-O session as normalized evidence without importing or executing any generated program. This optional command expects a local checkout of DT-Foss/O1-O; substitute its real path:

.venv/bin/o1-crypto-lab replay-o1o \
  --session /path/to/O1-O/2026-02-18_013412 \
  --output runs/o1o-2026-02-18-replay.json \
  --include-events

The replay intentionally distinguishes generation success, process success, capability evidence and mission progress. Raw stdout/stderr is never copied into the O1 stream; only its length and an unsalted integrity fingerprint remain until a domain-specific parser has validated its semantics. That fingerprint is not a confidentiality guarantee for guessable output. engagement_report.json contributes hashed aggregate retry/recovery/chaining counts, and every normalized event is fed neutrally into a capped TargetModel without being mislabeled as research success. The February format did not retain explicit retry-parent IDs, so the replay reports aggregate topology rather than inventing edges.

Verify a published snapshot before an adapter reads it:

.venv/bin/o1-crypto-lab verify-source \
  --root ../fullround-key-recovery \
  --manifest ../fullround-key-recovery/provenance/ARTIFACTS.sha256 \
  --output runs/fullround-source-verification.json

Run the manifest-pinned Stage-3 ingestion and frozen retrospective reader protocol:

.venv/bin/o1-crypto-lab stage3-ingest \
  --config configs/stage3_a296_a297_ingest_v1.json
.venv/bin/o1-crypto-lab stage3-reader \
  --config configs/stage3_reader_retrospective_v1.json

Each command creates a new read-only directory named runs/YYYYMMDD_HHMMSS_O1C-.../ with RUN.md, exact config and command, environment, metrics, logs, checkpoints, retained artifacts and a complete SHA-256 manifest. Attempt IDs are permanently reserved and cannot overwrite a prior result. Verify any capsule with:

.venv/bin/o1-crypto-lab verify-run runs/<capsule-name>

Recompute the label-using O1C-0018 diagnostics without generating a target or changing any model state:

PYTHONPATH=src .venv/bin/python \
  -m o1_crypto_lab.full256_online_real_forensics \
  --capsule runs/20260717_152827_O1C-0018_full256-online-real-gate-dev-v1

The Direct12 dependency chain originally lived in a dirty sibling worktree. It is therefore curated honestly into its own immutable capsule instead of being called a clean Fullround-manifest artifact:

.venv/bin/o1-crypto-lab direct12-snapshot \
  --config configs/direct12_source_snapshot_v1.json

Reproduce the frozen 133-to-532 trajectory reader from that capsule, then run the bounded-memory mechanism tournament:

.venv/bin/o1-crypto-lab direct12-reproduce \
  --config configs/direct12_reproduction_v1.json
.venv/bin/o1-crypto-lab bounded-memory-tournament \
  --config configs/bounded_memory_tournament_v1.json
.venv/bin/o1-crypto-lab corrected-codec-bridge \
  --config configs/corrected_codec_bridge_v1.json
.venv/bin/o1-crypto-lab upstream-ising-freeze \
  --config configs/upstream_ising_retrospective_v1.json

The tournament compares global Walsh state, sixteen fixed low4/high8 slot banks, and a dense 2–8-bit integer Bit-Vault. O1-O sees only A348 target-blind fidelity, serialized online-state bytes, update work and clip counts. It persists one future template before the A349 score member is opened; all complete A349 orders are then persisted before the separate A348 truth API is called. Direct candidate tables and full spectral banks remain clearly labeled ceilings and cannot win the mechanism gate. The dense Bit-Vault is a full-rank 4,080-register mechanism, not a claim of sublinear capacity.

The corrected-codec bridge reproduces A355/A356 exactly and retains the selected 6-bit DC-complete bank only as a validation ceiling. Its 4,096 spectral degrees of freedom are information-equivalent to the fixed candidate table, and its 8,014-byte maximum serialized logical state is larger than the matched 3,918-byte direct baseline.

The upstream freeze replaced the dense final-field representation with a 12-register unary solver-evidence memory. Its conservative logical-state bound is 266 bytes and its frozen binary is 162 bytes. The complete target-blind A355 panel contained 672 orders; the frozen decoder ranked the retrospective target at 73, but the exact conditional random-label tail was 2431/4096 = 0.593505859375. That is a structurally eligible compact mechanism and a negative efficacy result, not SOTA. The same decoder emitted a complete A356 order before any A356 target or outcome read, but A356 still came from the same opened source capsule and is not a source-unseen holdout. That planned narrow W46 follow-up is now superseded. O1C-0008 instead freezes the full-256 public-output attacker type, separately typed teacher labels, exact traced relation generator, six Contrast-Key families, sealed full-256 broker and the complete non-recovery progress vector. The unary decoder remains one matched baseline inside the new architecture.

The expensive immutable-snapshot integration gates are opt-in:

O1_CRYPTO_DIRECT12_REAL=1 \
  .venv/bin/python -m unittest discover -s tests -v
O1_CRYPTO_CORRECTED_REAL=1 \
  .venv/bin/python -m unittest discover -s tests -v
O1_CRYPTO_UPSTREAM_REAL=1 \
  .venv/bin/python -m unittest discover -s tests -v

Integration contract

  • No imports from the dirty live O1, O1-O, or arx-carry-leak trees.
  • Runtime experiment bytes are confined to runs/. A separate symlink-safe writer may update only the seven enumerated cockpit Markdown files at the lab root and under research/; it cannot write arbitrary lab or sibling paths.
  • CPU-only by default. MPS/GPU use requires a short explicit resource-checked window and cannot compete with the active sibling recovery queue.
  • No target label, recovered model, post-reveal rank, or target-internal state may flow into a TARGET_BLIND_ORDER.
  • Training-time internal round states may teach an operator, but evaluation-time features must be public or recomputable from public equations under an explicitly billed candidate assumption.
  • Every learned operator is selected on training/validation keys, frozen and hashed, then evaluated once on disjoint test keys with matched controls. The lifecycle is enforced as DISCOVERY -> FROZEN -> TEST_CONSUMED -> AUDIT; the exact proposal and plan hashes are bound at freeze time.
  • State size, external-index growth, samples and total cipher/solver work are reported separately. O(1) always means constant in stream length unless another axis is named explicitly.

See Architecture, O1-256 Living Inverse, Experiment ladder, and Scientific boundaries. The first reproducible smoke-test measurements are recorded in First results.

Repository map

configs/                 deterministic benchmark configurations
docs/                    architecture, gates and claim boundaries
provenance/              lab-owned byte ledgers and source-boundary records
research/                hypotheses, append-only attempts, breadcrumbs, next actions
src/o1_crypto_lab/       memory, composer, replay, TargetModel, adapters and CLI
tests/                   unit, leakage and reproducibility gates
runs/                    immutable timestamped capsules (ignored by Git, never overwritten)

The design is derived from the Apache-2.0 O1 and O1-O projects. No source from their offensive modules is executed or imported here; only the domain-agnostic bounded-state, typed-composition, verification and failure-memory ideas are used.

About

cryptO1: bounded-state solver-native causal memory for reproducible full-round ChaCha20 research

Topics

Resources

License

Stars

2 stars

Watchers

0 watching

Forks

Packages

 
 
 

Contributors