{"abstract":"The exact tonelli shanks square root result violates the stated contract at nonresidue subgroup generator.","category":"Numerics","checks":8,"contract":"Input [a,p], odd prime p and nonzero quadratic residue a; return smaller of two square roots modulo p. Bounds: p<=97.","evaluation_group":"s3-numerics-tonelli-shanks-square-root","failed_approach":"The partial repair pow(z,s,p) still violates the nonresidue subgroup generator invariant.","family":"s3-numerics-tonelli-shanks-square-root-nonresidue-subgroup-generator","id":"FA-15816","implementations":{"attempt":{"sha256":"46e3085791024f4d59572a04c12bbc7643a8d662fd84a015b4d700108f06d46d","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\nimport math\nimport itertools\nfrom fractions import Fraction\nN = 1\nobservations = []\ndef solve(x):\n    a,p=x\n    q=p-1;s=0\n    while q%2==0:q//=2;s+=1\n    z=2\n    while pow(z,(p-1)//2,p)!=p-1:z+=1\n    c=pow(z,s,p);r=pow(a,(q+1)//2,p);t=pow(a,q,p);m=s\n    for _ in range(20):\n     if t==1:break\n     i=1;v=t*t%p\n     while i<m and v!=1:v=v*v%p;i+=1\n     if i>=m:return None\n     b=pow(c,1<<(m-i-1),p)\n     r=r*b%p;t=t*b*b%p;c=b*b%p;m=i\n    return min(r,p-r)\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[([4, 13], 2), ([4, 5], 2), ([1, 5], 1), ([96, 97], 22), ([1, 7], 1), ([2, 7], 3), ([4, 7], 2), ([1, 11], 1)], [([10, 13], 6), ([12, 13], 5), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([12, 13], 5), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([4, 29], 2), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([5, 29], 11), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5), ([28, 31], 11)]]\nfor i, (args, expected) in enumerate(fixtures[N-1]):\n    check(\"explicit oracle %d\" % i, solve(args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"4277f78f30c482517593e0b535d11952ab8fb2c6ee53ee9c47a95bb28fb88c9d","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\nimport math\nimport itertools\nfrom fractions import Fraction\nN = 1\nobservations = []\ndef solve(x):\n    a,p=x\n    q=p-1;s=0\n    while q%2==0:q//=2;s+=1\n    z=2\n    while pow(z,(p-1)//2,p)!=p-1:z+=1\n    c=z%p;r=pow(a,(q+1)//2,p);t=pow(a,q,p);m=s\n    for _ in range(20):\n     if t==1:break\n     i=1;v=t*t%p\n     while i<m and v!=1:v=v*v%p;i+=1\n     if i>=m:return None\n     b=pow(c,1<<(m-i-1),p)\n     r=r*b%p;t=t*b*b%p;c=b*b%p;m=i\n    return min(r,p-r)\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[([4, 13], 2), ([4, 5], 2), ([1, 5], 1), ([96, 97], 22), ([1, 7], 1), ([2, 7], 3), ([4, 7], 2), ([1, 11], 1)], [([10, 13], 6), ([12, 13], 5), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([12, 13], 5), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([4, 29], 2), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([5, 29], 11), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5), ([28, 31], 11)]]\nfor i, (args, expected) in enumerate(fixtures[N-1]):\n    check(\"explicit oracle %d\" % i, solve(args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"fixed":{"sha256":"382e58420955eb0267f01926bfab1583d621a031e3b65cf7fe0869916c11d250","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\nimport math\nimport itertools\nfrom fractions import Fraction\nN = 1\nobservations = []\ndef solve(x):\n    a,p=x\n    q=p-1;s=0\n    while q%2==0:q//=2;s+=1\n    z=2\n    while pow(z,(p-1)//2,p)!=p-1:z+=1\n    c=pow(z,q,p);r=pow(a,(q+1)//2,p);t=pow(a,q,p);m=s\n    for _ in range(20):\n     if t==1:break\n     i=1;v=t*t%p\n     while i<m and v!=1:v=v*v%p;i+=1\n     if i>=m:return None\n     b=pow(c,1<<(m-i-1),p)\n     r=r*b%p;t=t*b*b%p;c=b*b%p;m=i\n    return min(r,p-r)\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\nfixtures = [[([4, 13], 2), ([4, 5], 2), ([1, 5], 1), ([96, 97], 22), ([1, 7], 1), ([2, 7], 3), ([4, 7], 2), ([1, 11], 1)], [([10, 13], 6), ([12, 13], 5), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([12, 13], 5), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([4, 29], 2), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([5, 29], 11), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5), ([28, 31], 11)]]\nfor i, (args, expected) in enumerate(fixtures[N-1]):\n    check(\"explicit oracle %d\" % i, solve(args), expected)\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":"A deterministic bounded teaching model. Inputs are restricted to the explicit contract; this is not a production algebra library. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"s3-numerics-tonelli-shanks-square-root-nonresidue-subgroup-generator","generated_at":"2026-09-29T14:39:30.492600+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Exact discrete arithmetic with observable algorithmic state; no floating point approximation is used.","repair":"Use pow(z,q,p) at the nonresidue subgroup generator step.","root_cause":"The nonresidue subgroup generator step uses z%p instead of pow(z,q,p).","sha256":"fff3d703272e9aa5c6be708aacd2a284497239ac852ba734ec957d04e7d37613","title":"Tonelli shanks square root: nonresidue subgroup generator · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verification":{"attempt":{"elapsed_ms":43.46,"exit_code":1,"observations":[{"actual":null,"check":"explicit oracle 0","expected":2,"passed":false},{"actual":null,"check":"explicit oracle 1","expected":2,"passed":false},{"actual":1,"check":"explicit oracle 2","expected":1,"passed":true},{"actual":null,"check":"explicit oracle 3","expected":22,"passed":false},{"actual":1,"check":"explicit oracle 4","expected":1,"passed":true},{"actual":3,"check":"explicit oracle 5","expected":3,"passed":true},{"actual":2,"check":"explicit oracle 6","expected":2,"passed":true},{"actual":1,"check":"explicit oracle 7","expected":1,"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"explicit oracle 0\", \"actual\": null, \"expected\": 2, \"passed\": false}, {\"check\": \"explicit oracle 1\", \"actual\": null, \"expected\": 2, \"passed\": false}, {\"check\": \"explicit oracle 2\", \"actual\": 1, \"expected\": 1, \"passed\": true}, {\"check\": \"explicit oracle 3\", \"actual\": null, \"expected\": 22, \"passed\": false}, {\"check\": \"explicit oracle 4\", \"actual\": 1, \"expected\": 1, \"passed\": true}, {\"check\": \"explicit oracle 5\", \"actual\": 3, \"expected\": 3, \"passed\": true}, {\"check\": \"explicit oracle 6\", \"actual\": 2, \"expected\": 2, \"passed\": true}, {\"check\": \"explicit oracle 7\", \"actual\": 1, \"expected\": 1, \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":40.24,"exit_code":1,"observations":[{"actual":null,"check":"explicit oracle 0","expected":2,"passed":false},{"actual":2,"check":"explicit oracle 1","expected":2,"passed":true},{"actual":1,"check":"explicit oracle 2","expected":1,"passed":true},{"actual":null,"check":"explicit oracle 3","expected":22,"passed":false},{"actual":1,"check":"explicit oracle 4","expected":1,"passed":true},{"actual":3,"check":"explicit oracle 5","expected":3,"passed":true},{"actual":2,"check":"explicit oracle 6","expected":2,"passed":true},{"actual":1,"check":"explicit oracle 7","expected":1,"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"explicit oracle 0\", \"actual\": null, \"expected\": 2, \"passed\": false}, {\"check\": \"explicit oracle 1\", \"actual\": 2, \"expected\": 2, \"passed\": true}, {\"check\": \"explicit oracle 2\", \"actual\": 1, \"expected\": 1, \"passed\": true}, {\"check\": \"explicit oracle 3\", \"actual\": null, \"expected\": 22, \"passed\": false}, {\"check\": \"explicit oracle 4\", \"actual\": 1, \"expected\": 1, \"passed\": true}, {\"check\": \"explicit oracle 5\", \"actual\": 3, \"expected\": 3, \"passed\": true}, {\"check\": \"explicit oracle 6\", \"actual\": 2, \"expected\": 2, \"passed\": true}, {\"check\": \"explicit oracle 7\", \"actual\": 1, \"expected\": 1, \"passed\": true}], \"passed\": false}\n"},"fixed":{"elapsed_ms":45.102,"exit_code":0,"observations":[{"actual":2,"check":"explicit oracle 0","expected":2,"passed":true},{"actual":2,"check":"explicit oracle 1","expected":2,"passed":true},{"actual":1,"check":"explicit oracle 2","expected":1,"passed":true},{"actual":22,"check":"explicit oracle 3","expected":22,"passed":true},{"actual":1,"check":"explicit oracle 4","expected":1,"passed":true},{"actual":3,"check":"explicit oracle 5","expected":3,"passed":true},{"actual":2,"check":"explicit oracle 6","expected":2,"passed":true},{"actual":1,"check":"explicit oracle 7","expected":1,"passed":true}],"passed":true,"stderr":"","stdout":"{\"observations\": [{\"check\": \"explicit oracle 0\", \"actual\": 2, \"expected\": 2, \"passed\": true}, {\"check\": \"explicit oracle 1\", \"actual\": 2, \"expected\": 2, \"passed\": true}, {\"check\": \"explicit oracle 2\", \"actual\": 1, \"expected\": 1, \"passed\": true}, {\"check\": \"explicit oracle 3\", \"actual\": 22, \"expected\": 22, \"passed\": true}, {\"check\": \"explicit oracle 4\", \"actual\": 1, \"expected\": 1, \"passed\": true}, {\"check\": \"explicit oracle 5\", \"actual\": 3, \"expected\": 3, \"passed\": true}, {\"check\": \"explicit oracle 6\", \"actual\": 2, \"expected\": 2, \"passed\": true}, {\"check\": \"explicit oracle 7\", \"actual\": 1, \"expected\": 1, \"passed\": true}], \"passed\": true}\n"}},"verified":true,"visibility":"public"}