WO-08 — Rad engine and prototype

7 October 2026 · Branch wo-08-rad from wo-03b-count-bound (3f28c67). Implementation, gates, measurements, and Claude’s independent review are complete (PASS). Owner approval/merge remain pending.

Approved rules and scope

  • #11 resolved: candidate(i)=u64_LE(i)||zero[8], numeric i<j<S; accept every distinct qualifying pair from one nonce. S is an explicit runtime policy; benchmark S=2^20. Upper eight candidate bytes must be zero.

  • #12 resolved, wording only: “expected cost under the optimal full-scan strategy.” The benchmark measures that strategy; it does not establish a new optimality theorem or prove undisclosed work by a miner.

  • #13 resolved, rule change: collision block requires the next byte tier strictly above Z_base: 8*(floor(Z_base/8)+1). Base 41 → 48; base 48 → 56. Owner instruction is authoritative while Claude updates CHAIN-DESIGN §4. The prior floor-based trigger is not used. At base 128 the next tier is 136, which a 128-bit match cannot reach; the helper never wraps to zero.

  • Older decision-log items 4–10 remain deferred to Sunday by the owner. No new unresolved consensus choice was introduced in this implementation.

No S, Z_base or Z_commit activation constant is hard-coded in the library. Window/parent and policy come from the caller. Later work orders supply validated chain state, ASERT, address semantics, transaction authorization and payouts. Commitment work here is the exact hash/work helper and measurement, not WO-09’s full commitment protocol. No install, push or merge was performed.

Built

  • e46/include/e46/rad.hpp, e46/src/rad.cpp: stamp, candidate encoding, Z-level, byte tier/next collision tier, exact 82-byte Rad serialization and parsing, Rad ID, contextual verifier and validated Merkle-event adapter.

  • rad_cli: line-oriented differential-test interface; not a consensus wire protocol. checked_event() verifies before deriving ID/body for WO-03b.

  • rad_bench: full-domain sort/group miner returning all distinct pairs, including pairs sharing a nonce; maximum four workers; serial commit trials.

  • rad_analyze.py: observed counts/rates and explicitly modelled block-frequency estimates. See e46/tools/RAD-README.md for commands and scope.

  • Golden reference/vectors frozen first in commit 9494b41; existing work-order golden files untouched. New vectors include numeric 255<256 (opposite bytewise LE ordering), boundary domains, exact Z, all 129 next-tier cases, 1,000 seeded contexts, exhaustive toy fixtures and 100 commitment hashes.

Test evidence

All evidence is in e46/reports/wo08-20261007.

  • Final release and ASan/UBSan suites each passed 16/16 tests; full test logs are e46/reports/wo08-20261007/release-final.txt and sanitize-final.txt.

  • Differential checks: frozen inputs plus 1,000 fresh seeded inputs, altered owner/parent/window/nonce/candidates/Z, malformed lengths and type, equality, reversed order, nonzero upper bytes, derived IDs and bound single-event roots.

  • Unit checks cover all leading-zero counts 0–128, policy bounds, short parser inputs, duplicate events, Merkle inclusion and wrong-count rejection.

  • Exhaustive toy scan compares every returned pair across four nonces against Python, including multiple pairs per nonce; passed release and sanitizers.

  • LLVM libFuzzer + ASan/UBSan: 1,969,558 executions in 31 seconds, no finding. This is bounded fuzz coverage, not proof of parser correctness.

  • Independently rehashed every full-size reported Rad and commitment hit in Python; measured-pairs-verified.json.

Paradox A: actual formats measured

Apple M1, release build, four Rad workers; no other benchmark/test job ran during this full scan. 64 nonce domains × 1,048,576 candidates = 67,108,864 candidate hashes, in 176.9143 seconds including sorting, pair construction and checks. Throughput 379,330 candidate hashes/s aggregate. Each table is 24 MiB, about 96 MiB for four tables, excluding allocator/process overhead.

Rad candidate hashes use 48 bytes / 648 RL steps. Rad IDs use 64 bytes / 840 steps. Commitment work uses 55 bytes / 744 steps. No 12-byte throughput was substituted. The pilot’s one-worker scan took 10.6035 seconds while a test job was active; use the isolated full run for reported throughput.

Minimum Z

Observed qualifying pairs

Ideal expected pairs in 64 domains

Estimated Rads / 150 s from observed rate

39

59

64.000

50.024

40

30

32.000

25.436

41

11

16.000

9.327

42

3

8.000

2.544

43

1

4.000

0.848

Measurement labels: counts and elapsed times are MEASURED. Ideal expectations use independent uniform 128-bit outputs and S*(S−1)/2^(Z+1) per domain. Rates per block are ESTIMATES at a constant 150-second interval, this machine’s rate, and inclusion of every valid Rad; no network or block-production simulation ran.

Calibration recommendation: retain 41 as the provisional experiment input; 11 hits are too few to fix a network constant. Its observed 9.33 Rads/block is slightly below the 10–30 objective; the ideal model at measured throughput predicts 13.56. Z=40 is a measured alternative (~25.44/block). Neither is silently activated here; runtime parameters allow subsequent calibration on the intended hardware and network hashrate. The candidate domain decision fixes the puzzle shape, not a universal real-world rate.

New next-tier collision-block frequency

At Z_base=41, the trigger is 48. There were zero observed Z≥48 pairs. Therefore this run establishes no measured finite collision-block interval. The uniform-output expectation is only 0.125 trigger pairs in these 64 puzzles, so zero is unsurprising under that model.

Combining measured scan throughput with the ideal-output model predicts about 0.106 trigger arrivals per 150 seconds. With independent Poisson arrivals and all triggers included, P(collision block)=1−exp(−lambda) ≈ 0.10056, or a mean 9.94 blocks between collision blocks. That is a MODEL ESTIMATE, not a measured 10-block cadence. The zero-hit Poisson 95% upper trigger rate is ~0.01693/s, a loose bound demonstrating how little this short run says about the rare tier. Network hashrate, parent/window changes, inclusion and actual output structure can change the result. This report preserves the zero observation rather than inventing a rare hit or treating the model as proof.

Commitment stamp, runtime Z_commit=18

16 serial searches of the exact 55-byte format took 53.8346 seconds total and 4,757,497 hashes (~88,372/s). Per-search mean 3.3647 s, median 1.6934 s, range 0.0952–9.1684 s. Each accepted nonce/hash is in full-scan.json and was verified in Python. Ideal mean attempts is 2^18=262,144; observed mean is 297,344. Retain 18 as provisional; no absolute timing guarantee or CPU-independent delay is inferred. These are stamp searches, not QTL unlock tests.

Independent review

Claude reviewed the existing wo-08-rad worktree at HEAD 9494b41 and returned PASS for code, tests, and evidence. The review changed no files. It confirmed the frozen WO-08 golden files match HEAD, all 10 recorded source hashes match, and the release and ASan/UBSan suites each passed 16/16 on Linux x86-64.

Claude’s fresh differential exam used seed 6200253984267246961: 30,978 release and 8,897 sanitizer comparisons against the frozen Python reference, with zero mismatches. Fresh small-domain scans matched independent Python enumeration; 649 valid/forged Rad variant queries had zero mismatches; and replay of the recorded full scan reproduced its events, histograms, and commitment searches. The review also reported no findings from its additional 5-million-case ASan / UBSan mutator run. These checks were performed by Claude, not rerun here.

The review identified the three stale decision-#13 statements in CHAIN-DESIGN §4 and §6. The owner-authorized patch is Claude outputs/CHAIN-DESIGN-decision13.patch and has been applied. The review’s other documentation observations remain non-blocking and unchanged; decisions 4–10 remain Open. No commit or merge has been made, and WO-14 has not started.

Reproduction / limits / handoff

See RAD-README.md, raw full-scan.json, summary.json, environment.json and gate logs. No sampled result establishes RL security, strategy optimality, or production consensus safety. Rads intentionally use partial matches; complete 128-bit hash collisions were not claimed here.

The learning map is a dated snapshot; MAPS/WO08-decisions-12-13-update.md supersedes its old open notes. Decision log #11–13 are resolved. Claude’s review passed; owner approval/merge remain pending. Do not start WO-14 before the owner’s next order.