FA-15821 / Numerics / Open access
Tonelli shanks square root: initial root exponent · case 01
The exact tonelli shanks square root result violates the stated contract at initial root exponent.
ROOT CAUSE
The initial root exponent step uses pow(a,q//2,p) instead of pow(a,(q+1)//2,p).
VERIFIED REPAIR
Use pow(a,(q+1)//2,p) at the initial root exponent step.
Unsuccessful approach: The partial repair pow(a,(p+1)//4,p) still violates the initial root exponent invariant.
Case contract
Input [a,p], odd prime p and nonzero quadratic residue a; return smaller of two square roots modulo p. Bounds: p<=97.
Why this case matters
Exact discrete arithmetic with observable algorithmic state; no floating point approximation is used.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
a,p=x
q=p-1;s=0
while q%2==0:q//=2;s+=1
z=2
while pow(z,(p-1)//2,p)!=p-1:z+=1
c=pow(z,q,p);r=pow(a,q//2,p);t=pow(a,q,p);m=s
for _ in range(20):
if t==1:break
i=1;v=t*t%p
while i<m and v!=1:v=v*v%p;i+=1
if i>=m:return None
b=pow(c,1<<(m-i-1),p)
r=r*b%p;t=t*b*b%p;c=b*b%p;m=i
return min(r,p-r)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 7], 3), ([3, 13], 4), ([1, 5], 1), ([96, 97], 22), ([4, 5], 2), ([1, 7], 1), ([4, 7], 2), ([1, 11], 1)], [([4, 7], 2), ([10, 13], 6), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([3, 11], 5), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([4, 11], 2), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([5, 11], 4), ([6, 29], 8), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 2 | 3 | Failed |
| explicit oracle 1 | 3 | 4 | Failed |
| explicit oracle 2 | 1 | 1 | Passed |
| explicit oracle 3 | 22 | 22 | Passed |
| explicit oracle 4 | 2 | 2 | Passed |
| explicit oracle 5 | 1 | 1 | Passed |
| explicit oracle 6 | 3 | 2 | Failed |
| explicit oracle 7 | 1 | 1 | Passed |
SHA-256 / b91799da5ce440340e36f60e7f61c01fbd36fea463dc7fca9b99a0a3acf0fa98
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
a,p=x
q=p-1;s=0
while q%2==0:q//=2;s+=1
z=2
while pow(z,(p-1)//2,p)!=p-1:z+=1
c=pow(z,q,p);r=pow(a,(p+1)//4,p);t=pow(a,q,p);m=s
for _ in range(20):
if t==1:break
i=1;v=t*t%p
while i<m and v!=1:v=v*v%p;i+=1
if i>=m:return None
b=pow(c,1<<(m-i-1),p)
r=r*b%p;t=t*b*b%p;c=b*b%p;m=i
return min(r,p-r)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 7], 3), ([3, 13], 4), ([1, 5], 1), ([96, 97], 22), ([4, 5], 2), ([1, 7], 1), ([4, 7], 2), ([1, 11], 1)], [([4, 7], 2), ([10, 13], 6), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([3, 11], 5), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([4, 11], 2), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([5, 11], 4), ([6, 29], 8), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 3 | 3 | Passed |
| explicit oracle 1 | 1 | 4 | Failed |
| explicit oracle 2 | 1 | 1 | Passed |
| explicit oracle 3 | 22 | 22 | Passed |
| explicit oracle 4 | 2 | 2 | Passed |
| explicit oracle 5 | 1 | 1 | Passed |
| explicit oracle 6 | 2 | 2 | Passed |
| explicit oracle 7 | 1 | 1 | Passed |
SHA-256 / ba7c67c431da6cca8fb1297a81ce34a908c977e6f59f81ffc7240aab3af5eb21
3 / The verified repair
Exit 0"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
a,p=x
q=p-1;s=0
while q%2==0:q//=2;s+=1
z=2
while pow(z,(p-1)//2,p)!=p-1:z+=1
c=pow(z,q,p);r=pow(a,(q+1)//2,p);t=pow(a,q,p);m=s
for _ in range(20):
if t==1:break
i=1;v=t*t%p
while i<m and v!=1:v=v*v%p;i+=1
if i>=m:return None
b=pow(c,1<<(m-i-1),p)
r=r*b%p;t=t*b*b%p;c=b*b%p;m=i
return min(r,p-r)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([2, 7], 3), ([3, 13], 4), ([1, 5], 1), ([96, 97], 22), ([4, 5], 2), ([1, 7], 1), ([4, 7], 2), ([1, 11], 1)], [([4, 7], 2), ([10, 13], 6), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([3, 11], 5), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([4, 11], 2), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([5, 11], 4), ([6, 29], 8), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| explicit oracle 0 | 3 | 3 | Passed |
| explicit oracle 1 | 4 | 4 | Passed |
| explicit oracle 2 | 1 | 1 | Passed |
| explicit oracle 3 | 22 | 22 | Passed |
| explicit oracle 4 | 2 | 2 | Passed |
| explicit oracle 5 | 1 | 1 | Passed |
| explicit oracle 6 | 2 | 2 | Passed |
| explicit oracle 7 | 1 | 1 | Passed |
SHA-256 / c13c0bab4d954e04aa75096ad6cb91fb10156d1c0fdc7fe448c6e69d4691ab26
Verification & scope
A deterministic bounded teaching model. Inputs are restricted to the explicit contract; this is not a production algebra library. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:39:30.667794+00:00.
Case digest / 801975088fb741dc4c0793a9bd55f180421b0f66a2d27f7f1151de950b6e10e5