Wire Smokescreen blinding into sp_validation on the fork's theory-backend protocol: three sp_validation theory_fn backends through one ConcealDataVector call, a fixed CCL-native amplitude draw calibrated to an S8 envelope, and a custody scheme that publishes a hash commitment while the seed and truths stay encrypted at rest.
Desired end state
Custody. OS-entropy seed → blind → publish sha256(seed) plus config digest → encrypt seed and truths (smokescreen.encryption, no firecrown dependency) → strip seed_smokescreen, stamp concealed=True plus a blind label. Unblind verifies the hash before subtracting. The commitment binds (seed, config).
Derived statistics. COSEBIs and pure-E/B are re-derived, never shifted — re-run through the pipeline estimators on the blinded ξ±. Covariances never change. The pure-EB seam follows the pipeline's edge-based bounds.
On the fork protocol.
- The amplitude-shift envelope is expressed through the fork's fixed CCL-native draw (order-independent, local
default_rng), calibrated on the sp_validation side to an equivalent S8 amplitude.
- Three theory backends through one
ConcealDataVector call — coarse ξ±, fine-grid ξ±, and pseudo-Cℓ (W @ ΔCℓ_EE) — each a theory_fn callable supplied by this issue, overriding the fork's built-in default CCL backend (which does not know the master layout or IA config). Our backends are plain CCL callables that compute exactly our fiducial.
- Cross-backend consistency: the same hidden cosmology through two theory callables agrees to machine precision (~1e-10).
CAMB↔CCL cross-check (folded-in test). A theory-consistency test — same cosmology, same n(z), ξ± on our θ grid within tolerance. It must settle the σ8-for-CCL vs A_s-for-CAMB amplitude convention (σ8-matching is load-bearing: nominal A_s leaves σ8 ~3% off and blows the comparison to ~9–10%), and halofit_version strings must match on both stacks (mead2020 vs mead2020_feedback differ several percent at k≳1). Observed floor on the single-bin synthetic fixture: ξ+ 0.21% / ξ− 0.10% against 0.5%/1.0% tolerances.
Acceptance
- B-mode estimators are unchanged under blinding on mocks, to the estimator's numerical floor.
- The fork blinds a real sp_validation
sacc_io file end-to-end.
- The cross-backend and CAMB↔CCL consistency tests pass at the stated tolerances.
— Opus on behalf of Cail.
Wire Smokescreen blinding into sp_validation on the fork's theory-backend protocol: three sp_validation
theory_fnbackends through oneConcealDataVectorcall, a fixed CCL-native amplitude draw calibrated to an S8 envelope, and a custody scheme that publishes a hash commitment while the seed and truths stay encrypted at rest.Desired end state
Custody. OS-entropy seed → blind → publish sha256(seed) plus config digest → encrypt seed and truths (
smokescreen.encryption, no firecrown dependency) → stripseed_smokescreen, stampconcealed=Trueplus a blind label. Unblind verifies the hash before subtracting. The commitment binds (seed, config).Derived statistics. COSEBIs and pure-E/B are re-derived, never shifted — re-run through the pipeline estimators on the blinded ξ±. Covariances never change. The pure-EB seam follows the pipeline's edge-based bounds.
On the fork protocol.
default_rng), calibrated on the sp_validation side to an equivalent S8 amplitude.ConcealDataVectorcall — coarse ξ±, fine-grid ξ±, and pseudo-Cℓ (W @ ΔCℓ_EE) — each atheory_fncallable supplied by this issue, overriding the fork's built-in default CCL backend (which does not know the master layout or IA config). Our backends are plain CCL callables that compute exactly our fiducial.CAMB↔CCL cross-check (folded-in test). A theory-consistency test — same cosmology, same n(z), ξ± on our θ grid within tolerance. It must settle the σ8-for-CCL vs A_s-for-CAMB amplitude convention (σ8-matching is load-bearing: nominal A_s leaves σ8 ~3% off and blows the comparison to ~9–10%), and
halofit_versionstrings must match on both stacks (mead2020 vs mead2020_feedback differ several percent at k≳1). Observed floor on the single-bin synthetic fixture: ξ+ 0.21% / ξ− 0.10% against 0.5%/1.0% tolerances.Acceptance
sacc_iofile end-to-end.— Opus on behalf of Cail.