FA-15081 / Numerics / Open access
Baby step giant step logarithm: giant exponent reconstruction · case 01
The exact baby step giant step logarithm result violates the stated contract at giant exponent reconstruction.
ROOT CAUSE
The giant exponent reconstruction step uses i+baby[v] instead of i*m+baby[v].
VERIFIED REPAIR
Use i*m+baby[v] at the giant exponent reconstruction step.
Unsuccessful approach: The partial repair i*m-baby[v] still violates the giant exponent reconstruction invariant.
Case contract
Input [g,h,p], p prime and nonzero g,h; return least e>=0 with g^e=h mod p or None.
Why this case matters
Exact discrete arithmetic with observable algorithmic state; no floating point approximation is used.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
g,h,p=x;m=math.isqrt(p-1)+1
baby={};v=1
for j in range(m):
if v not in baby:baby[v]=j
v=v*g%p
factor=pow(pow(g,m,p),-1,p)
v=h
answers=[]
for i in range(m+1):
if v in baby:
e=i+baby[v]
if pow(g,e,p)==h:answers.append(e)
v=v*factor%p
return min(answers) if answers else None
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 3, 11], 8), ([2, 2, 3], 1), ([1, 1, 3], 0), ([22, 22, 23], 1), ([1, 2, 3], None), ([2, 1, 3], 0), ([1, 1, 5], 0), ([1, 2, 5], None)], [([2, 5, 11], 4), ([4, 4, 5], 1), ([1, 1, 3], 0), ([22, 22, 23], 1), ([4, 2, 5], None), ([4, 3, 5], None), ([1, 1, 7], 0), ([1, 2, 7], None)], [([2, 6, 11], 9), ([3, 2, 7], 2), ([1, 1, 3], 0), ([22, 22, 23], 1), ([3, 3, 7], 1), ([3, 4, 7], 4), ([3, 5, 7], 5), ([3, 6, 7], 3)], [([2, 7, 11], 7), ([3, 5, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([6, 2, 7], None), ([6, 3, 7], None), ([6, 4, 7], None), ([6, 5, 7], None)], [([2, 9, 11], 6), ([5, 2, 7], 4), ([1, 1, 3], 0), ([22, 22, 23], 1), ([2, 3, 11], 8), ([2, 4, 11], 2), ([2, 5, 11], 4), ([2, 6, 11], 9)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | None | 8 | Failed |
| explicit oracle 1 | 1 | 1 | Passed |
| explicit oracle 2 | 0 | 0 | Passed |
| explicit oracle 3 | 1 | 1 | Passed |
| explicit oracle 4 | None | None | Passed |
| explicit oracle 5 | 0 | 0 | Passed |
| explicit oracle 6 | 0 | 0 | Passed |
| explicit oracle 7 | None | None | Passed |
SHA-256 / bc12b3e02588bacac154a01fcda7c7e895b20dabe10758034798c8ba35ba49fd
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
g,h,p=x;m=math.isqrt(p-1)+1
baby={};v=1
for j in range(m):
if v not in baby:baby[v]=j
v=v*g%p
factor=pow(pow(g,m,p),-1,p)
v=h
answers=[]
for i in range(m+1):
if v in baby:
e=i*m-baby[v]
if pow(g,e,p)==h:answers.append(e)
v=v*factor%p
return min(answers) if answers else None
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 3, 11], 8), ([2, 2, 3], 1), ([1, 1, 3], 0), ([22, 22, 23], 1), ([1, 2, 3], None), ([2, 1, 3], 0), ([1, 1, 5], 0), ([1, 2, 5], None)], [([2, 5, 11], 4), ([4, 4, 5], 1), ([1, 1, 3], 0), ([22, 22, 23], 1), ([4, 2, 5], None), ([4, 3, 5], None), ([1, 1, 7], 0), ([1, 2, 7], None)], [([2, 6, 11], 9), ([3, 2, 7], 2), ([1, 1, 3], 0), ([22, 22, 23], 1), ([3, 3, 7], 1), ([3, 4, 7], 4), ([3, 5, 7], 5), ([3, 6, 7], 3)], [([2, 7, 11], 7), ([3, 5, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([6, 2, 7], None), ([6, 3, 7], None), ([6, 4, 7], None), ([6, 5, 7], None)], [([2, 9, 11], 6), ([5, 2, 7], 4), ([1, 1, 3], 0), ([22, 22, 23], 1), ([2, 3, 11], 8), ([2, 4, 11], 2), ([2, 5, 11], 4), ([2, 6, 11], 9)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 8 | 8 | Passed |
| explicit oracle 1 | -1 | 1 | Failed |
| explicit oracle 2 | 0 | 0 | Passed |
| explicit oracle 3 | -1 | 1 | Failed |
| explicit oracle 4 | None | None | Passed |
| explicit oracle 5 | 0 | 0 | Passed |
| explicit oracle 6 | 0 | 0 | Passed |
| explicit oracle 7 | None | None | Passed |
SHA-256 / 4759fc600ba19b0508ab33fd155141d909c1d95c570389a1f758671f973869cb
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
g,h,p=x;m=math.isqrt(p-1)+1
baby={};v=1
for j in range(m):
if v not in baby:baby[v]=j
v=v*g%p
factor=pow(pow(g,m,p),-1,p)
v=h
answers=[]
for i in range(m+1):
if v in baby:
e=i*m+baby[v]
if pow(g,e,p)==h:answers.append(e)
v=v*factor%p
return min(answers) if answers else None
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 3, 11], 8), ([2, 2, 3], 1), ([1, 1, 3], 0), ([22, 22, 23], 1), ([1, 2, 3], None), ([2, 1, 3], 0), ([1, 1, 5], 0), ([1, 2, 5], None)], [([2, 5, 11], 4), ([4, 4, 5], 1), ([1, 1, 3], 0), ([22, 22, 23], 1), ([4, 2, 5], None), ([4, 3, 5], None), ([1, 1, 7], 0), ([1, 2, 7], None)], [([2, 6, 11], 9), ([3, 2, 7], 2), ([1, 1, 3], 0), ([22, 22, 23], 1), ([3, 3, 7], 1), ([3, 4, 7], 4), ([3, 5, 7], 5), ([3, 6, 7], 3)], [([2, 7, 11], 7), ([3, 5, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([6, 2, 7], None), ([6, 3, 7], None), ([6, 4, 7], None), ([6, 5, 7], None)], [([2, 9, 11], 6), ([5, 2, 7], 4), ([1, 1, 3], 0), ([22, 22, 23], 1), ([2, 3, 11], 8), ([2, 4, 11], 2), ([2, 5, 11], 4), ([2, 6, 11], 9)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 8 | 8 | Passed |
| explicit oracle 1 | 1 | 1 | Passed |
| explicit oracle 2 | 0 | 0 | Passed |
| explicit oracle 3 | 1 | 1 | Passed |
| explicit oracle 4 | None | None | Passed |
| explicit oracle 5 | 0 | 0 | Passed |
| explicit oracle 6 | 0 | 0 | Passed |
| explicit oracle 7 | None | None | Passed |
SHA-256 / 9d19f8f18364eba9659baccd9f33f1629dbc2497077add22f2f1cb718f03343b
Verification & scope
A deterministic bounded teaching model. Inputs are restricted to the explicit contract; this is not a production algebra library. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:39:23.234026+00:00.
Case digest / f1bb2564643b7736ff9637de9b015637abce1251626ee77ef2dade61d25bae08