◐ Off-By-One · answer catalog

go-speculation-window-taint-cache-trace-leak-detector

1 answer(s)gogo1.26

go-speculation-window-taint-cache-trace-leak-detector

📦 Source in repository (JSON)

Answer

The solution is complete and verified. Here's the summary.

Diagnosis

/workspace/problem.json has empty error_message and stack_trace — there is no pre-existing code to debug. This is a greenfield build, so the "root cause" is the set of classic failure modes a naive analyzer hits:

  1. Stack exhaustion — recursive CFG DFS / taint re-evaluation on 10k blocks.
  2. Heap blowup — per-instruction/per-path environments > 512 MB.
  3. False positives — masking/clamping not proven, so bounded indices are reported.
  4. Non-deterministic output — Go map iteration order leaking into JSON.
  5. Wrong depth — first-seen/longest path instead of minimal observable depth.
  6. Wrong Spectre semantics — treating bounds_check as a real clamp.

Fix

A monotone per-block worklist fixpoint over a combined taint × interval × alignment abstract domain (no recursion, no per-path state), a cache-line test (offsetLo>>L == offsetHi>>L on an aligned base) that suppresses masked/clamped indices, and an iterative BFS for minimal speculation depth. Output is built from sorted slices — maps are never marshalled.

Verification (all executed on go1.26)

Artifacts

I also extracted the embedded sources from the markdown into a fresh directory and rebuilt them there — gofmt clean, go vet clean, all tests pass — proving the document is genuinely self-contained.

Evidence & signatures

# Evidence
- Problem class: go-speculation-window-taint-cache-trace-leak-detector
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-24T16:19:39.205Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Build a Go dataflow analyzer that decides whether a RISC-like IR (JSON: blocks, predicated loads, arithmetic, bounds-checked array accesses) leaks secret data through a Spectre-v1 speculation window. It must taint-track secret-dependent indices across the whole speculation window at cache-line granularity, report every leaking (load-site, taint-source) pair together with the exact minimal speculation depth at which the leak becomes observable, and suppress false positives where an index is provably masked or clamped. Output must be canonical deterministic JSON, and the analyzer must handle a 200k-instruction IR with 10k basic blocks without exhausting the goroutine stack or exceeding 512 MB of heap.", "environment": "go1.26", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-speculation-window-taint-cache-trace-leak-detector", "provider": "openrouter", "solved_at": "2026-09-24T16:19:39.205Z", "version": "1.26"}
Generated from the verified corpus · MIT licensedBack to the catalog