FA-15086 / Numerics / Open access
Baby step giant step logarithm: giant group progression · case 01
The exact baby step giant step logarithm result violates the stated contract at giant group progression.
ROOT CAUSE
The giant group progression step uses (v+factor)%p instead of v*factor%p.
VERIFIED REPAIR
Use v*factor%p at the giant group progression step.
Unsuccessful approach: The partial repair factor%p still violates the giant group progression invariant.
Case contract
Input [g,h,p], p prime and nonzero g,h; return least e>=0 with g^e=h mod p or None.
Why this case matters
Exact discrete arithmetic with observable algorithmic state; no floating point approximation is used.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
g,h,p=x;m=math.isqrt(p-1)+1
baby={};v=1
for j in range(m):
if v not in baby:baby[v]=j
v=v*g%p
factor=pow(pow(g,m,p),-1,p)
v=h
answers=[]
for i in range(m+1):
if v in baby:
e=i*m+baby[v]
if pow(g,e,p)==h:answers.append(e)
v=(v+factor)%p
return min(answers) if answers else None
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 3, 5], 3), ([1, 1, 3], 0), ([22, 22, 23], 1), ([1, 2, 3], None), ([2, 1, 3], 0), ([2, 2, 3], 1), ([1, 1, 5], 0), ([1, 2, 5], None)], [([3, 2, 5], 3), ([3, 5, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([4, 2, 5], None), ([4, 3, 5], None), ([4, 4, 5], 1), ([1, 1, 7], 0)], [([3, 5, 7], 5), ([5, 3, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([3, 3, 7], 1), ([3, 4, 7], 4), ([3, 6, 7], 3), ([4, 1, 7], 0)], [([3, 6, 7], 3), ([2, 5, 11], 4), ([1, 1, 3], 0), ([22, 22, 23], 1), ([6, 2, 7], None), ([6, 3, 7], None), ([6, 4, 7], None), ([6, 5, 7], None)], [([5, 2, 7], 4), ([2, 9, 11], 6), ([1, 1, 3], 0), ([22, 22, 23], 1), ([2, 3, 11], 8), ([2, 4, 11], 2), ([2, 5, 11], 4), ([2, 6, 11], 9)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 7 | 3 | Failed |
| explicit oracle 1 | 0 | 0 | Passed |
| explicit oracle 2 | 1 | 1 | Passed |
| explicit oracle 3 | None | None | Passed |
| explicit oracle 4 | 0 | 0 | Passed |
| explicit oracle 5 | 1 | 1 | Passed |
| explicit oracle 6 | 0 | 0 | Passed |
| explicit oracle 7 | None | None | Passed |
SHA-256 / 96ffc689b31c920b7135a56614d348604df9932955565ca2ffdcd09009e452ae
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
g,h,p=x;m=math.isqrt(p-1)+1
baby={};v=1
for j in range(m):
if v not in baby:baby[v]=j
v=v*g%p
factor=pow(pow(g,m,p),-1,p)
v=h
answers=[]
for i in range(m+1):
if v in baby:
e=i*m+baby[v]
if pow(g,e,p)==h:answers.append(e)
v=factor%p
return min(answers) if answers else None
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 3, 5], 3), ([1, 1, 3], 0), ([22, 22, 23], 1), ([1, 2, 3], None), ([2, 1, 3], 0), ([2, 2, 3], 1), ([1, 1, 5], 0), ([1, 2, 5], None)], [([3, 2, 5], 3), ([3, 5, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([4, 2, 5], None), ([4, 3, 5], None), ([4, 4, 5], 1), ([1, 1, 7], 0)], [([3, 5, 7], 5), ([5, 3, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([3, 3, 7], 1), ([3, 4, 7], 4), ([3, 6, 7], 3), ([4, 1, 7], 0)], [([3, 6, 7], 3), ([2, 5, 11], 4), ([1, 1, 3], 0), ([22, 22, 23], 1), ([6, 2, 7], None), ([6, 3, 7], None), ([6, 4, 7], None), ([6, 5, 7], None)], [([5, 2, 7], 4), ([2, 9, 11], 6), ([1, 1, 3], 0), ([22, 22, 23], 1), ([2, 3, 11], 8), ([2, 4, 11], 2), ([2, 5, 11], 4), ([2, 6, 11], 9)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 7 | 3 | Failed |
| explicit oracle 1 | 0 | 0 | Passed |
| explicit oracle 2 | 1 | 1 | Passed |
| explicit oracle 3 | None | None | Passed |
| explicit oracle 4 | 0 | 0 | Passed |
| explicit oracle 5 | 1 | 1 | Passed |
| explicit oracle 6 | 0 | 0 | Passed |
| explicit oracle 7 | None | None | Passed |
SHA-256 / 025e6f2f481db01ed025358ba9853db73c75c5f9521700f2ea208db1838949fa
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
g,h,p=x;m=math.isqrt(p-1)+1
baby={};v=1
for j in range(m):
if v not in baby:baby[v]=j
v=v*g%p
factor=pow(pow(g,m,p),-1,p)
v=h
answers=[]
for i in range(m+1):
if v in baby:
e=i*m+baby[v]
if pow(g,e,p)==h:answers.append(e)
v=v*factor%p
return min(answers) if answers else None
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 3, 5], 3), ([1, 1, 3], 0), ([22, 22, 23], 1), ([1, 2, 3], None), ([2, 1, 3], 0), ([2, 2, 3], 1), ([1, 1, 5], 0), ([1, 2, 5], None)], [([3, 2, 5], 3), ([3, 5, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([4, 2, 5], None), ([4, 3, 5], None), ([4, 4, 5], 1), ([1, 1, 7], 0)], [([3, 5, 7], 5), ([5, 3, 7], 5), ([1, 1, 3], 0), ([22, 22, 23], 1), ([3, 3, 7], 1), ([3, 4, 7], 4), ([3, 6, 7], 3), ([4, 1, 7], 0)], [([3, 6, 7], 3), ([2, 5, 11], 4), ([1, 1, 3], 0), ([22, 22, 23], 1), ([6, 2, 7], None), ([6, 3, 7], None), ([6, 4, 7], None), ([6, 5, 7], None)], [([5, 2, 7], 4), ([2, 9, 11], 6), ([1, 1, 3], 0), ([22, 22, 23], 1), ([2, 3, 11], 8), ([2, 4, 11], 2), ([2, 5, 11], 4), ([2, 6, 11], 9)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 3 | 3 | Passed |
| explicit oracle 1 | 0 | 0 | Passed |
| explicit oracle 2 | 1 | 1 | Passed |
| explicit oracle 3 | None | None | Passed |
| explicit oracle 4 | 0 | 0 | Passed |
| explicit oracle 5 | 1 | 1 | Passed |
| explicit oracle 6 | 0 | 0 | Passed |
| explicit oracle 7 | None | None | Passed |
SHA-256 / c720e10c4aa1bec65918527cbb3bfc858ee8aba7092c4b62c7dc2e62179ad68a
Verification & scope
A deterministic bounded teaching model. Inputs are restricted to the explicit contract; this is not a production algebra library. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:39:23.273395+00:00.
Case digest / 13f39c2597372a8923077613e46fea05eb666b6bc4eb4874647b213ff4d4533f