FAILURE MAP
← Case archive

FA-15831 / Numerics / Open access

Tonelli shanks square root: order halving correction · case 01

The exact tonelli shanks square root result violates the stated contract at order halving correction.

Verified by executionVariant 1 · 8 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The order halving correction step uses pow(c,1<<(m-i),p) instead of pow(c,1<<(m-i-1),p).

VERIFIED REPAIR

Use pow(c,1<<(m-i-1),p) at the order halving correction step.

Unsuccessful approach: The partial repair pow(c,m-i-1,p) still violates the order halving correction invariant.

Case contract

Input [a,p], odd prime p and nonzero quadratic residue a; return smaller of two square roots modulo p. Bounds: p<=97.

Why this case matters

Exact discrete arithmetic with observable algorithmic state; no floating point approximation is used.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
    a,p=x
    q=p-1;s=0
    while q%2==0:q//=2;s+=1
    z=2
    while pow(z,(p-1)//2,p)!=p-1:z+=1
    c=pow(z,q,p);r=pow(a,(q+1)//2,p);t=pow(a,q,p);m=s
    for _ in range(20):
     if t==1:break
     i=1;v=t*t%p
     while i<m and v!=1:v=v*v%p;i+=1
     if i>=m:return None
     b=pow(c,1<<(m-i),p)
     r=r*b%p;t=t*b*b%p;c=b*b%p;m=i
    return min(r,p-r)
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([4, 5], 2), ([1, 5], 1), ([96, 97], 22), ([1, 7], 1), ([2, 7], 3), ([4, 7], 2), ([1, 11], 1), ([3, 11], 5)], [([4, 13], 2), ([12, 13], 5), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([10, 13], 6), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([12, 13], 5), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([2, 17], 6), ([5, 29], 11), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
    check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
explicit oracle 0None2Failed
explicit oracle 111Passed
explicit oracle 2None22Failed
explicit oracle 311Passed
explicit oracle 433Passed
explicit oracle 522Passed
explicit oracle 611Passed
explicit oracle 755Passed

SHA-256 / cc76f99b5e38c8531ed3ed0869f08717e9580026e8539e7a552ea5c2b0b3b7b9

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
    a,p=x
    q=p-1;s=0
    while q%2==0:q//=2;s+=1
    z=2
    while pow(z,(p-1)//2,p)!=p-1:z+=1
    c=pow(z,q,p);r=pow(a,(q+1)//2,p);t=pow(a,q,p);m=s
    for _ in range(20):
     if t==1:break
     i=1;v=t*t%p
     while i<m and v!=1:v=v*v%p;i+=1
     if i>=m:return None
     b=pow(c,m-i-1,p)
     r=r*b%p;t=t*b*b%p;c=b*b%p;m=i
    return min(r,p-r)
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([4, 5], 2), ([1, 5], 1), ([96, 97], 22), ([1, 7], 1), ([2, 7], 3), ([4, 7], 2), ([1, 11], 1), ([3, 11], 5)], [([4, 13], 2), ([12, 13], 5), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([10, 13], 6), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([12, 13], 5), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([2, 17], 6), ([5, 29], 11), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
    check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
explicit oracle 0None2Failed
explicit oracle 111Passed
explicit oracle 2None22Failed
explicit oracle 311Passed
explicit oracle 433Passed
explicit oracle 522Passed
explicit oracle 611Passed
explicit oracle 755Passed

SHA-256 / fccc2d8e9974dbc363bf767a4dfb796934100b73351e1367a3871fc6ca6314da

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json
import math
import itertools
from fractions import Fraction
N = 1
observations = []
def solve(x):
    a,p=x
    q=p-1;s=0
    while q%2==0:q//=2;s+=1
    z=2
    while pow(z,(p-1)//2,p)!=p-1:z+=1
    c=pow(z,q,p);r=pow(a,(q+1)//2,p);t=pow(a,q,p);m=s
    for _ in range(20):
     if t==1:break
     i=1;v=t*t%p
     while i<m and v!=1:v=v*v%p;i+=1
     if i>=m:return None
     b=pow(c,1<<(m-i-1),p)
     r=r*b%p;t=t*b*b%p;c=b*b%p;m=i
    return min(r,p-r)
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
fixtures = [[([4, 5], 2), ([1, 5], 1), ([96, 97], 22), ([1, 7], 1), ([2, 7], 3), ([4, 7], 2), ([1, 11], 1), ([3, 11], 5)], [([4, 13], 2), ([12, 13], 5), ([1, 5], 1), ([96, 97], 22), ([2, 17], 6), ([4, 17], 2), ([8, 17], 5), ([9, 17], 3)], [([10, 13], 6), ([8, 17], 5), ([1, 5], 1), ([96, 97], 22), ([2, 23], 5), ([3, 23], 7), ([4, 23], 2), ([6, 23], 11)], [([12, 13], 5), ([15, 17], 7), ([1, 5], 1), ([96, 97], 22), ([16, 29], 4), ([20, 29], 7), ([22, 29], 14), ([23, 29], 9)], [([2, 17], 6), ([5, 29], 11), ([1, 5], 1), ([96, 97], 22), ([18, 31], 7), ([19, 31], 9), ([20, 31], 12), ([25, 31], 5)]]
for i, (args, expected) in enumerate(fixtures[N-1]):
    check("explicit oracle %d" % i, solve(args), expected)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
explicit oracle 022Passed
explicit oracle 111Passed
explicit oracle 22222Passed
explicit oracle 311Passed
explicit oracle 433Passed
explicit oracle 522Passed
explicit oracle 611Passed
explicit oracle 755Passed

SHA-256 / 5e018d961ea4c0ffe0ee2c0039dc4922e33046322e5fe3653a32df3b7f672e36

Verification & scope

A deterministic bounded teaching model. Inputs are restricted to the explicit contract; this is not a production algebra library. This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:39:30.781334+00:00.

Case digest / c7dc7a491024605aa0e265d4afdbe9c6140378ea4264de31ee4ccea7785ae6b8