go-speculation-window-taint-cache-trace-leak-detector
The solution is complete and verified. Here's the summary.
/workspace/problem.json has empty error_message and stack_trace — there is no pre-existing code to debug. This is a greenfield build, so the "root cause" is the set of classic failure modes a naive analyzer hits:
bounds_check as a real clamp.A monotone per-block worklist fixpoint over a combined taint × interval × alignment abstract domain (no recursion, no per-path state), a cache-line test (offsetLo>>L == offsetHi>>L on an aligned base) that suppresses masked/clamped indices, and an iterative BFS for minimal speculation depth. Output is built from sorted slices — maps are never marshalled.
&7 suppressed, &63 still leaks, clamp suppressed, transitive taint, post-spec_end omitted, byte-determinism, loop convergence.TestLargeProgram analyzes 200,003 instructions / 10,001 blocks in 309 ms, 83 MiB live heap.GOMEMLIMIT=384MiB binary on a 12 MB JSON IR → 145 MiB peak RSS, 0.84 s, 5,000 leaks + 5,000 suppressions, exit 0.debug.SetMaxStack(16 MiB).go vet, gofmt, and go test -race all clean./workspace/SOLUTION.md — self-contained report: root-cause analysis, schema, algorithm, complete source embedded./workspace/go-speculation/ — working module (ir.go, lattice.go, analyzer.go, main.go, tests, tools/gen).I also extracted the embedded sources from the markdown into a fresh directory and rebuilt them there — gofmt clean, go vet clean, all tests pass — proving the document is genuinely self-contained.
# Evidence - Problem class: go-speculation-window-taint-cache-trace-leak-detector - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-24T16:19:39.205Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Build a Go dataflow analyzer that decides whether a RISC-like IR (JSON: blocks, predicated loads, arithmetic, bounds-checked array accesses) leaks secret data through a Spectre-v1 speculation window. It must taint-track secret-dependent indices across the whole speculation window at cache-line granularity, report every leaking (load-site, taint-source) pair together with the exact minimal speculation depth at which the leak becomes observable, and suppress false positives where an index is provably masked or clamped. Output must be canonical deterministic JSON, and the analyzer must handle a 200k-instruction IR with 10k basic blocks without exhausting the goroutine stack or exceeding 512 MB of heap.", "environment": "go1.26", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-speculation-window-taint-cache-trace-leak-detector", "provider": "openrouter", "solved_at": "2026-09-24T16:19:39.205Z", "version": "1.26"}