FA-15766 / Numerics / Open access
Montgomery residue product: negative modulus inverse · case 01
The exact montgomery residue product result violates the stated contract at negative modulus inverse.
ROOT CAUSE
The negative modulus inverse step uses pow(m,-1,R) instead of (-pow(m,-1,R))%R.
VERIFIED REPAIR
Use (-pow(m,-1,R))%R at the negative modulus inverse step.
Unsuccessful approach: The partial repair (-pow(R,-1,m))%m still violates the negative modulus inverse invariant.
Case contract
Input [a,b,m,R], odd modulus m<R and R power of2, 0<=a,b<m; return a*b*R^-1 modulo m using Montgomery reduction.
Why this case matters
Exact discrete arithmetic with observable algorithmic state; no floating point approximation is used.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
a,b,m,R=x
nprime=pow(m,-1,R)
t=a*b
u=(t*nprime)%R
v=(t+u*m)//R
if v>=m:v-=m
return v
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([1, 1, 3, 8], 2), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([0, 1, 3, 8], 0), ([0, 2, 3, 8], 0), ([1, 0, 3, 8], 0), ([1, 2, 3, 8], 1), ([2, 0, 3, 8], 0)], [([1, 2, 3, 8], 1), ([1, 3, 7, 8], 3), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([1, 3, 5, 8], 1), ([1, 4, 5, 8], 3), ([2, 0, 5, 8], 0), ([2, 1, 5, 8], 4)], [([2, 1, 3, 8], 1), ([2, 1, 7, 8], 2), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([0, 0, 7, 8], 0), ([0, 1, 7, 8], 0), ([0, 2, 7, 8], 0), ([0, 3, 7, 8], 0)], [([1, 1, 5, 8], 2), ([2, 5, 7, 8], 3), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([2, 3, 7, 8], 6), ([2, 4, 7, 8], 1), ([2, 6, 7, 8], 5), ([3, 0, 7, 8], 0)], [([1, 2, 5, 8], 4), ([3, 2, 7, 8], 6), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([4, 6, 7, 8], 3), ([5, 0, 7, 8], 0), ([5, 1, 7, 8], 5), ([5, 2, 7, 8], 3)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 1 | 2 | Failed |
| explicit oracle 1 | 0 | 0 | Passed |
| explicit oracle 2 | 24 | 1 | Failed |
| explicit oracle 3 | 0 | 0 | Passed |
| explicit oracle 4 | 0 | 0 | Passed |
| explicit oracle 5 | 0 | 0 | Passed |
| explicit oracle 6 | 2 | 1 | Failed |
| explicit oracle 7 | 0 | 0 | Passed |
SHA-256 / 6943f97e9febb8b790a87eb40408947533bffa511511bb3ddc5174694638df19
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
a,b,m,R=x
nprime=(-pow(R,-1,m))%m
t=a*b
u=(t*nprime)%R
v=(t+u*m)//R
if v>=m:v-=m
return v
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([1, 1, 3, 8], 2), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([0, 1, 3, 8], 0), ([0, 2, 3, 8], 0), ([1, 0, 3, 8], 0), ([1, 2, 3, 8], 1), ([2, 0, 3, 8], 0)], [([1, 2, 3, 8], 1), ([1, 3, 7, 8], 3), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([1, 3, 5, 8], 1), ([1, 4, 5, 8], 3), ([2, 0, 5, 8], 0), ([2, 1, 5, 8], 4)], [([2, 1, 3, 8], 1), ([2, 1, 7, 8], 2), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([0, 0, 7, 8], 0), ([0, 1, 7, 8], 0), ([0, 2, 7, 8], 0), ([0, 3, 7, 8], 0)], [([1, 1, 5, 8], 2), ([2, 5, 7, 8], 3), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([2, 3, 7, 8], 6), ([2, 4, 7, 8], 1), ([2, 6, 7, 8], 5), ([3, 0, 7, 8], 0)], [([1, 2, 5, 8], 4), ([3, 2, 7, 8], 6), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([4, 6, 7, 8], 3), ([5, 0, 7, 8], 0), ([5, 1, 7, 8], 5), ([5, 2, 7, 8], 3)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 0 | 2 | Failed |
| explicit oracle 1 | 0 | 0 | Passed |
| explicit oracle 2 | 20 | 1 | Failed |
| explicit oracle 3 | 0 | 0 | Passed |
| explicit oracle 4 | 0 | 0 | Passed |
| explicit oracle 5 | 0 | 0 | Passed |
| explicit oracle 6 | 1 | 1 | Passed |
| explicit oracle 7 | 0 | 0 | Passed |
SHA-256 / dc13e7333adea4a36c0993e296ec918611a8eb243029c8f3ad18b5be742fd63a
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
a,b,m,R=x
nprime=(-pow(m,-1,R))%R
t=a*b
u=(t*nprime)%R
v=(t+u*m)//R
if v>=m:v-=m
return v
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([1, 1, 3, 8], 2), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([0, 1, 3, 8], 0), ([0, 2, 3, 8], 0), ([1, 0, 3, 8], 0), ([1, 2, 3, 8], 1), ([2, 0, 3, 8], 0)], [([1, 2, 3, 8], 1), ([1, 3, 7, 8], 3), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([1, 3, 5, 8], 1), ([1, 4, 5, 8], 3), ([2, 0, 5, 8], 0), ([2, 1, 5, 8], 4)], [([2, 1, 3, 8], 1), ([2, 1, 7, 8], 2), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([0, 0, 7, 8], 0), ([0, 1, 7, 8], 0), ([0, 2, 7, 8], 0), ([0, 3, 7, 8], 0)], [([1, 1, 5, 8], 2), ([2, 5, 7, 8], 3), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([2, 3, 7, 8], 6), ([2, 4, 7, 8], 1), ([2, 6, 7, 8], 5), ([3, 0, 7, 8], 0)], [([1, 2, 5, 8], 4), ([3, 2, 7, 8], 6), ([0, 0, 3, 8], 0), ([30, 30, 31, 32], 1), ([4, 6, 7, 8], 3), ([5, 0, 7, 8], 0), ([5, 1, 7, 8], 5), ([5, 2, 7, 8], 3)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 2 | 2 | Passed |
| explicit oracle 1 | 0 | 0 | Passed |
| explicit oracle 2 | 1 | 1 | Passed |
| explicit oracle 3 | 0 | 0 | Passed |
| explicit oracle 4 | 0 | 0 | Passed |
| explicit oracle 5 | 0 | 0 | Passed |
| explicit oracle 6 | 1 | 1 | Passed |
| explicit oracle 7 | 0 | 0 | Passed |
SHA-256 / 22ab811508af9e658f6f02b0a3f3ce5e3aeb6c6f08d280310946c171ef57e6e3
Verification & scope
A deterministic bounded teaching model. Inputs are restricted to the explicit contract; this is not a production algebra library. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:39:30.113819+00:00.
Case digest / 151d2c6a1adf1ca7129de4f9bf2e22646e43d999bb9bcc997ab5b775eec62949