Files
amethyst/cli/tests/sno
Claude a1f97a0452 feat: Cantor roots and region keys, matching the reference
Step 2 of the region-bag plan. Amethyst now derives the same §7.2 keys the rest
of the network derives: the conformance harness is 12 of 12, its new section
comparing 16 region keys and their coordinate decodes against cyberspace-cli —
§9.8's london, nyc and origin plus §7.7's ideaspace point, at heights 0, 1, 4
and 8. A key is a consensus value, so that agreement is the whole point: a byte
of difference is a bag they hid that we cannot open.

CantorTree is §4.5 and §4.6 — the aligned subtree whose boundaries arithmetic
fixes rather than anyone's movement, which is what lets two people in the same
neighbourhood compute the same root without communicating, which is what makes
§7 work at all. Folded leaf by leaf against a stack of partial roots rather
than a level at a time: same root either way, but a level holds every leaf at
once and the stack holds height + 1 numbers. It refuses above height 20 as both
references do, because one height further is twice the leaves and a root twice
as wide and the number is a stranger's to choose.

The big integer went the long way round and the plan now records why. It was
written portable and used everywhere, on the argument that two implementations
of a consensus value is two chances to disagree. Measurement reversed that:
portable Kotlin is 3 to 10 times slower than java.math.BigInteger on the
operands a Cantor tree reaches, because multiplyToLen is a HotSpot intrinsic,
and §7's feasibility is a number. So UBigInt is an expect class wrapping
BigInteger on jvmAndroid and PortableUBigInt on nativeMain, which covers Apple
and Linux together.

A wrapper and not a typealias, for one reason: the reference hashes
int_to_bytes_be_min, and BigInteger.toByteArray() is two's complement, so it
grows a 0x00 sign byte whenever the top bit is set — half of all numbers. An
alias would have fed that byte to SHA-256 and produced a key nobody else
derives.

What makes two implementations safe is that the disagreement is testable.
PortableUBigIntDifferentialTest runs every operation against BigInteger over
random inputs at fifteen widths from 0 to 352,000 bits, straddling the
Karatsuba threshold both ways, and asserts the two actuals agree with each
other — including on the bytes, which is where the alias would have gone wrong
silently. CantorTreeBenchmark folds a whole subtree both ways and compares the
roots, which is where a stack off-by-one would live rather than in the
arithmetic, and keeps the cost on the record because the budget model the UI
will quote is read straight off it.

Also amy cyberspace coord|region, so the comparison runs in a shell script
rather than only in a test, and one correction to the plan's cost model: the
combine dominates above about height 8, roughly ten times an axis root at the
same height, so a sweep priced by its tree builds under-quotes badly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JwXApJjoZYtkD3sPRWbPNa
2026-09-23 00:57:49 +00:00
..