v2.8 · RNG PRE-SUBMISSION PACKAGE v1.2
RAIN RNG · PRE-SUBMISSION PACKAGE · v1.2 · 2026-09-14 09:34 UTC

RAIN RNG — Pre-Submission Package for accredited test labs

Everything a GLI / BMM / iTech / eCOGRA reviewer asks for under GLI CSR §2.2 — RNG description, source, collection tools, statistical evidence with raw logs, reproducible build, process documents — published as-is, with the gaps stated. RNG component only (@rain/rng-core, @rain/rng-session, @rain/rng-node, rng-py, lab/). Not in this package: the casino contracts, games and Outperform markets.

NOT CERTIFIEDSELF-RUN EVIDENCEJOBS STILL RUNNING — COUNTS ARE LIVE, NOT ROUNDEDREPRODUCIBLE No laboratory has evaluated this package yet. Every number below was produced by us, on our hardware, with the tools in the zip; a lab will re-run them. Numbers marked in progress are read from the running jobs' checkpoints at build time.

1STATUS — PROVEN · IN PROGRESS · PENDING EXTERNAL

From LAB-SUBMISSION-REQUIREMENTS §7 (20 artifacts: HAVE 13 · PARTIAL 5 · MISSING 2), REVIEW-RESPONSE-R1 and lab/results/PROGRESS.md. "Proven" means: in the repository, reproducible with the shipped tools.

✅PROVEN — IN REPO, REPRODUCIBLE

  • RNG description in GLI-19 §3 vocabulary, §3.3.2 a/b/c explicit — RNG-DESCRIPTION
  • Source complete, readable, git history; vendored engines un-minified
  • Reproducible build: 214 dist files fingerprinted, lab:verify-build passes ×2 — BUILD
  • Collection tools (final-outcome + raw, production code path, seeded, checkpointed, adversarial modes)
  • Dieharder chacha20 90 P / 5 W / 0 F on 61/80 combos (stream, never rewinds)
  • NIST STS 1000 × 10⁶ bits: 188/188 both mechanisms, 0 uniformity fails
  • TestU01 SmallCrush 15/15 both mechanisms
  • Scaled outcomes chacha20: 10⁸ per game (dice, roulette, coin, reel), 2 × 10⁶ decks, 3 × 10⁸ adversarial — 8.04 × 10⁸, all total-χ² pass at α = .01
  • Scaling proof (intBelow exact; legacy % N bias < N/2²⁵⁶) — SCALING-PROOF
  • §3.3.2(c) one-pager — STATE-MODIFICATION
  • Runtime KATs (11 vectors, NIST CAVP HMAC_DRBG + RFC 8439 + RAIN stream) before first use / 24 h / /selftest; output inhibited on failure
  • Real-network latency measured (Virginia → Oregon), 4,000/4,000 rounds, 0 errors — REPORT
  • Process docs: key management, incident response, change control, SDLC, hosting/HA/DR, security program; CI + CODEOWNERS + governance in repo

⏳IN PROGRESS — RUNNING, COUNTS LIVE

  • Dieharder hmac-drbg: 52/80 combos done — 83 PASSED / 3 WEAK / 0 FAILED. Remaining: rgb_lagged_sum ntuples (28 combos, ≈ 0.44·(n+1) GB each ≈ 250 GB total). Why slow: HMAC_DRBG through the full ceremony path yields ≈ 1 MB/s per core; a lab host finishes it with the same resumable runner.
  • Dieharder chacha20: rgb_lagged_sum 14–32 (19 combos, ≈ 200 GB) deliberately not run — budget; runner resumable.
  • hmac-drbg 10⁸-per-game outcomes (results/outcomes/hmac-1e8/): 270,000,000 scaled outcomes reached so far —
    gameoutcomes so farstatus
    dice60,000,000in progress — 600,000 / 1,000,000 rounds (60 %)
    roulette70,000,000in progress — 700,000 / 1,000,000 rounds (70 %)
    coin70,000,000in progress — 700,000 / 1,000,000 rounds (70 %)
    slot-reel70,000,000in progress — 700,000 / 1,000,000 rounds (70 %)
    The completed hmac sets (2 × 10⁷ per game, 2.0 × 10⁸ total incl. legacy comparisons) are already analysed in the report.
  • TestU01 Crush / BigCrush: not run (137 GB / 1.1 TB of words; 10–70 h at our producer rate). Stream runner shipped; documented as not run, not as passed.
  • Contract bytecode fingerprint: no solc in the lab environment; RngAnchor.sol undeployed → anchoring path not "final".

⬜PENDING EXTERNAL — NOT IN OUR HANDS

  • Branch protection + second maintainer. Settings written out in GOVERNANCE; must be applied by a GitHub org owner; repo is single-maintainer today. CI file sits at .github/workflows-pending/ on the mirror (PAT lacks workflow scope).
  • Penetration test — not contracted. Scope and annual cadence fixed in SECURITY-PROGRAM §2.
  • External contract + node audit — not contracted; cadence per deployment / per major version.
  • Laboratory evaluation — this package is what we would hand over at the pre-submission call; no lab engaged yet.
  • Docker HA run (2 workers + Postgres + LB, SIGKILL mid-run): ha-test.sh shipped, not executed — no Docker/root here; Render's LB gives no kill-one-instance handle.
  • npm publish decision — packages pack cleanly (npm pack --dry-run), names free; publishing is the owner's call — PUBLISHING.

2HEADLINE EVIDENCE

Two mechanisms are evaluated separately (GLI-19 §4.5.1): hmac-drbg (SP 800-90A HMAC_DRBG/SHA-256) and chacha20 (RFC 8439), both keyed per round from r_k = keccak256(pRev_k ‖ hRev_k ‖ sessionSeed ‖ sessionId ‖ k). Full tables with p-values: REPORT-STATISTICAL.
SUITECHACHA20HMAC-DRBGNOTE
Dieharder 3.31.1, full -a battery, stream input (-g 200, never rewinds)90 PASSED / 5 WEAK / 0 FAILED
61/80 combos · ≈ 73 GB consumed
83 PASSED / 3 WEAK / 0 FAILED
52/80 combos · IN PROGRESS
Not run: rgb_lagged_sum tail (data volume). A 4 GB file-mode run was found to rewind 19× and is quarantined, not evidence (§9 of the report).
NIST SP 800-22 STS 2.1.2 — 1000 sequences × 10⁶ bits, all 15 tests, default parameters188/188 result lines in CI · 0 uniformity P < 10⁻⁴188/188 · 0 uniformity failsOne private STS tree per mechanism; first chacha run discarded (shared experiments dir) and re-run.
TestU01 1.2.3 SmallCrush15/15, p ∈ [0.06, 0.96]15/15, p ∈ [0.09, 0.92]Crush / BigCrush not run (137 GB / 1.1 TB). Runner shipped.
Scaled outcomes after intBelow/shuffle — χ² total, blocked-χ² KS (100 blocks), serial lags 1–8, runs, coupon, reel interplay10⁸ per game dice · roulette · coin · reel stops; 2 × 10⁶ decks (1.04 × 10⁸ placements); 3 × 10⁸ adversarial dice → 8.04 × 10⁸2 × 10⁷ per game (2.0 × 10⁸ total incl. legacy % N comparisons); 10⁸ sets in progress: 270,000,000 so farEvery total-distribution χ² passes at α = .01 for every game, both mechanisms, all adversarial modes. Isolated single-statistic exceedances (e.g. lag-4 |z| 3.07/3.29 in two chacha adversarial sets) at the rate ≈ 15 statistics × 1 % predicts; not shared across sets.
Fisher–Yates shuffle52×52 card×position table χ² (2601 d.f.): chacha p = 0.1000, hmac p = 0.2708 · per-position KS · adjacency · first-card — all passProof of 1/52! in SCALING-PROOF.
Adversarial player input (GLI-19 §4.5.2(e) defence)3 modes — fixed, zero, grind — 10⁸ dice each (chacha) + 2 × 10⁷ each (hmac): statistically indistinguishable from the honest set on every aggregate statisticThe player can add entropy but cannot bias: hRev_k is committed and unknown.
Reproducible build214 files SHA-256 in FINGERPRINTS.json; npm run lab:verify-build passes twice on the reference machine; CI re-checks driftNo solc here → contract bytecode not fingerprinted.
Runtime KATs / self-test11 known-answer vectors (NIST CAVP HMAC_DRBG ×4, FIPS/RFC, RAIN stream vectors both mechanisms) before first reveal, every 24 h, GET /selftest; RNG endpoints 503 in error state; fingerprint check vs manifestSP 800-90A §11.3; GLI-19 §2.3.2.

REAL-NETWORK LATENCY — UNMODIFIED @rain/rng-node ON RENDER (GCP us-west1, OREGON, BEHIND CLOUDFLARE) · CLIENT AWS us-east-1 (VIRGINIA) · 1,000 SPINS PER RUN · 0 ERRORS

ANIMATION GAPTRANSPORTPIPELINING OFF — p50 / p95 (ms)PIPELINING ON — p50 / p95 (ms)READING
0 ms (no animation — pathological)HTTPS keep-alive87.8 / 102.086.7 / 100.1Honest boundary: with nothing to hide behind, ON ≈ OFF. Pipelining overlaps the round trip; it cannot beat physics.
WebSocket76.9 / 100.172.4 / 83.6
60 ms (headline — harsher than any real slot)HTTPS keep-alive88.5 / 101.836.0 / 49.0Critical path ≈ max(0, RTT − animation): ≈ 90 ms RTT − 60 ms gap → ≈ 30 ms visible. p99 119.3 → 67.5 (HTTP), 101.5 → 57.9 (WS).
WebSocket91.1 / 100.223.3 / 39.7
1,000 ms (a real reel; 300 spins)HTTPS keep-alive87.7 / 103.91.2 / 1.6RTT ≪ animation → the network leaves the critical path; what remains is local settle + DRBG (single-digit ms). The reveal is already there.
WebSocket71.2 / 85.11.0 / 1.5

Application RTT baseline (GET /healthz keep-alive) p50 ≈ 101–108 ms on a transcontinental path — a pessimistic placement; an operator co-locating within one region would see ≈ 10–30 ms. Not shown: concurrent-player throughput, Postgres-backed persistence, browser → operator → node chains. Raw: results.json, results-gap0.json, results-gap1000.json, loadtest-*.txt, network-baseline.txt, deploy-manifest.txt — in the zip. Full write-up: REPORT.

3PACKAGE INDEX — MAPPED TO GLI COMPOSITE SUBMISSION REQUIREMENTS v2.0 §2.2

Every document is rendered here with the site chrome and shipped verbatim (markdown) in the zip and on the mirror branch. The markdown is the document of record.
GLI CSR §2.2 ITEMDOCUMENT(S)STATUS
Package indexlab/README · EVIDENCE-INDEXHAVE
RNG Source Code — final, complete, compilable, commented, edit history, binariespackages/rng-core, rng-session, rng-node, rng-py on the mirror branch ↗ · CHANGELOGHAVE (RngAnchor.sol undeployed)
RNG Final Outcome Collection Tool + Raw Output Collection Toollab/tools/collect-outcomes.mjs, collect-raw.mjs, analyze-outcomes.mjs, suite runners — in the zip; described in lab/READMEHAVE
RNG Description and Documentation (GLI-19 §3 order; §3.3.2 a/b/c)RNG-DESCRIPTION · docs/RNG · STATE-MODIFICATIONHAVE
Technical Source Code Description ("instantiation to final outcome") + every reductionSCALING-INVENTORY · SCALING-PROOFHAVE
Statistical data analysis with raw outputsREPORT-STATISTICAL · EVIDENCE-INDEX · raw logs in the zip (Dieharder per-test logs, STS finalAnalysisReport + experiments, SmallCrush logs, outcome analyses); raw .bin/.csv listed belowHAVE, self-run; hmac Dieharder + 10⁸ sets in progress
Software verification (lab recompiles; signatures match)BUILD · FINGERPRINTS.jsonHAVE
Runtime self-verification (GLI-19 §2.3.2; SP 800-90A §11.3)packages/rng-node/src/selftest.ts (mirror) · RNG-DESCRIPTION §10HAVE
Platform items §2.9 / §2.11 — change control, SDLC, key management, incidents, hosting/HA/DRprocess/CHANGE-CONTROL · process/SDLC · process/KEY-MANAGEMENT · process/INCIDENT-RESPONSE · process/HOSTING-HA-DRHAVE ×3 · PARTIAL (change control, SDLC: single maintainer, CI not yet executed on GitHub) · PARTIAL (HA test not run)
Pen-test / external audit (GLI-19 App. B.9; §6)process/SECURITY-PROGRAMMISSING — third parties; not contracted, said so
Repository controls (GLI-19 App. B)docs/GOVERNANCE · .github/workflows/ci.yml, CODEOWNERS (mirror)PARTIAL — org owner must apply
Integration / hosting the counterpartydocs/INTEGRATION-OPERATOR · docs/HOUSE-NODEHAVE
Readiness & requirements analysisdocs/LAB-READINESS · docs/LAB-SUBMISSION-REQUIREMENTS—
Engineering evidence (not a §2.2 item)Real-network latencyHAVE
Review record · distributionREVIEW-RESPONSE-R1 · PUBLISHING—
Game description / pay tablesout of RNG scope — game configs vendored in packages/games/vendorPARTIAL (not this package)

4DOWNLOADS — WITH SHA-256

Hashes computed at build time from the files served here. Also in SHA256SUMS.txt. Verify: sha256sum -c SHA256SUMS.txt.
FILEWHATSIZESHA-256
rain-rng-package-v1.2.ziplab/ — every document, tool (source), result summary, per-test Dieharder logs + .DONE markers, STS finalAnalysisReport/freq/RUN, SmallCrush logs, outcome analyses + meta, run logs, process docs, top-level docs/, CI + CODEOWNERS (raw .bin / big .csv excluded — listed below)1.6 MB30326467dffcb090da48f231a05fc9feed44c3f957b4c0cc98beb9d32e02f66f
rain-rng-package-v1.2-sts-experiments-chacha.zipcompanion: NIST STS experiments/ tree for chacha20 (stats.txt + results.txt of all 15 tests, 1000 sequences)5.0 MBdee3fff16949e5e79b79036ed9125b705d77ce1e65e41dd5b5f4c71bb7f5c93b
rain-rng-package-v1.2-sts-experiments-hmac.zipcompanion: NIST STS experiments/ tree for hmac-drbg5.0 MB20e0071f7b55de5048226682aaf488c4fd9962dc87d8a5a15f3c13e2447236c1
RAIN-RNG-Whitepaper-v1.2.pdfWhitepaper v1.2 (PDF) — adds the real-network pipelining measurement2.1 MB00e157874d242a5fbbfb8eb07fa176a85e37e010723b16e9f163895aee7e6151
RAIN-RNG-Whitepaper-v1.2.mdWhitepaper v1.2 (Markdown source)103 kB53786135d277ade66a847107c689c75b24b55ad9c5ed2f65e1bc345068aabc14
FINGERPRINTS.jsonreproducible-build manifest — SHA-256 of 214 dist files, toolchain pins25 kBf5d6754fe298f38f7792480056da3f959e3be30f1fae43d78da95147937a2990
EXCLUDED-ARTIFACTS.tsvsize + sha256 of every raw artifact not in the zip3 kBf8ae48c38e23a47954e804974aef15ca1a127308403ae1df0d0841c7965f2276
RAIN-RNG-Whitepaper-v1.1.pdfhistory2.1 MB2cd6805b35941cbb1955e0021e98aacd2a2d2b8da075eec64c611cbd42887b77
RAIN-RNG-Whitepaper-v1.0.pdfhistory1.8 MBb5d37bb492d08226c773c7947ac0e396eff38fcc4c25fd9d2441e7a540374075

NOT IN THE ZIP — RAW ARTIFACTS (25 files, NaN GB)

The raw generator output and the full outcome CSVs are too large for a static site. They are available on request (object-storage link) and — more usefully for a lab — regenerable bit-for-bit with the shipped tools from the recorded seeds (results/raw/<mech>/SEED-BIG, SEED-STREAM; per-set masterSeed in each .meta.json). Files still being written (hmac-1e8/*.csv) are hashed at their state at build time and will change.

PATHSIZESHA-256 (at build)
pathNaN Bsha256 — raw artifacts excluded from rain-rng-package-v1.2.zip; regenerable from recorded seeds with lab/tools; available on request. Hashes taken 2026-09-14T09:27Z; hmac-1e8/*.csv were still being written.
lab/results/outcomes/chacha/card-shuffle.csv309.0 MBe3bc8929b97b4809e784c5b30b7c8b9e73d75287ceb20753786d32cb5ed053b7
lab/results/outcomes/chacha/coin.csv208.2 MBac1ae962777fa6377520f1eacb8a679731dbd8e591aa707bb7d2b9d6959c2b92
lab/results/outcomes/chacha/dice-adv-fixed.csv300.2 MB5641c43b0a801c824cd4f181e2c833685f38a4903bcd2b5b7892cff5406df532
lab/results/outcomes/chacha/dice-adv-grind.csv300.2 MB8820089b500552d73d52b30da689be9dd100b92d4e551e11cbaa17bbea43f287
lab/results/outcomes/chacha/dice-adv-zero.csv300.2 MBb70f396edb29539d61ed70a74895f1c32a30563f362e8122748ddab6291c9373
lab/results/outcomes/chacha/dice.csv300.2 MB6d2cb8b6e016147aac4829626b70f7b249853858a2cccbba63b9c0b02460ec0e
lab/results/outcomes/chacha/roulette.csv281.2 MB275e34e074a96ee3dd99382a9be59b56b532115b5be7d1fc2e33d5a892fc74ec
lab/results/outcomes/chacha/slot-reel.csv414.4 MBc9640dac566a5aaae6a1899417559f6fa51a61c798e782e79e0934ed860c3ed0
lab/results/outcomes/hmac-1e8/coin.csv IN PROGRESS140.5 MB41b6c3b25024153d56de8f965715301e1ad2bdfcb3641efaa3b4ac2dc64d1396
lab/results/outcomes/hmac-1e8/dice.csv IN PROGRESS194.1 MBb088909456040649cd5d198bc704f2c2afa6f06d9257f42472bfbb267c85219a
lab/results/outcomes/hmac-1e8/roulette.csv IN PROGRESS189.8 MB81b9f723198e9004b8ee9803c8b5328fb69746efc63291d42739aad3c331dce7
lab/results/outcomes/hmac-1e8/slot-reel.csv IN PROGRESS281.6 MB64d7f63b4e171a92ed2afdeaaf275730dce179aea9b4d152ced0c56f00cf9262
lab/results/outcomes/hmac/card-shuffle.csv61.5 MBab41d8dab1e9883244c87f43b78ed00fd59529553dc3e2a98b96b8bed2b07208
lab/results/outcomes/hmac/coin.csv41.6 MB724570642927323c03a88ee311c833ad2162e169f164c370e7604d6ea617d7fb
lab/results/outcomes/hmac/dice-adv-fixed.csv60.0 MB72dbda59833d15b19b7abd3ea54fd90c5b864d5a5f187656544714c1df2af1e9
lab/results/outcomes/hmac/dice-adv-grind.csv60.0 MB438f5121fabc2558570f9d0713fd01f1e308f9eaad7029edd2b4cfded76d0a77
lab/results/outcomes/hmac/dice-adv-zero.csv60.0 MBf30e9890bea64cbc5fdaa55f6a68b8928b1747b044e87357e67a231304587918
lab/results/outcomes/hmac/dice.csv60.0 MB0a7155e7f1e98c36e6407b20de57ce9028c057ff6e1eb839ccfcb74ec54a5107
lab/results/outcomes/hmac/legacy-dice.csv248.1 MBca2af5cde45010fa214d3efad80b99282d7c8d15ded30037679b944a0fcd6cff
lab/results/outcomes/hmac/legacy-roulette.csv244.3 MB36300947bc4ffe3f6d56d6805269681418cb552dad8c2b9dffeb0ede67a756da
lab/results/outcomes/hmac/roulette.csv56.1 MB110bef6e427f854f23b4762977a53d5b26cf4754d7613e2d669140c33b1e9c81
lab/results/outcomes/hmac/slot-reel.csv81.1 MB90a5d336c3b18ca3029844e5aaca59aa93bf5cc9967f46b104585d821840b8f9
lab/results/raw/chacha/raw-32gbit.bin4000.0 MBd8b314f6a9b8726238cdbd8b8b04c947de17eb4f009c4fee75b01a6d3e07dfda
lab/results/raw/hmac/raw-32gbit.bin4000.0 MB68a170a0fb14a4746c8acbcf4ac36e32eb2a807d8f0c9b240ab51028662e43d3

▸FOR AUDITORS

  • Repository: github.com/Quecko-Org/rain-playmarket-fe-dev · branch sdk-v2 ↗ — a mirror branch (force-pushed snapshot) on an existing org repo; a dedicated repository is pending. Mirror head 0e891111d0c6; source-of-truth commit for this page 9636833236e4ac4898c00cdfa995afffe1da1a60 (lab counters refreshed after the mirror push — the mirror lags by the running-job refreshes only).
  • Build & test:
    git clone -b sdk-v2 https://github.com/Quecko-Org/rain-playmarket-fe-dev.git rain-sdk-v2 && cd rain-sdk-v2
    npm ci && npm run build && npm run typecheck
    npm test                      # unit: KATs (FIPS 180-4, RFC 4231, NIST CAVP HMAC_DRBG ×32, RFC 8439, keccak), ceremony, crash-persistence, selftest, e2e
    npm run test:py               # Python mirror byte-identical (26 pytest)
    npm run lab:verify-build      # rebuild → SHA-256 of 214 dist files == lab/FINGERPRINTS.json (run it twice)
    bash lab/tools/status.sh      # what the lab jobs did / are doing
  • Re-run the evidence: lab/tools/run-dieharder-stream.sh <mech> <workers> (resumable), run-sts.sh, run-testu01-crush-stream.sh, run-outcomes.sh; report regenerates with report-tables.sh fill.
  • Verify a live round without any of this: walkthrough with an Arbiscan example.
  • Contact: via the operator address in the deployment log / rainsandbox.xyz; disclosure policy and SLAs in SECURITY-PROGRAM.

▸FOR LABS — PRE-SUBMISSION QUESTIONS WE WANT ANSWERED

From LAB-SUBMISSION-REQUIREMENTS §8 step 9. Every lab offers a pre-submission call; these are the points we would put on the agenda.

  1. Player-supplied entropy classification. How will you treat the player's pRev_k under GLI-19 §4.5.2(e) ("associated equipment shall not influence or modify the behaviors of the game's RNG") and AGCO 4.26 ("impervious to the player")? Our position: the player can add entropy but cannot bias — one-page proof in STATE-MODIFICATION / RNG-DESCRIPTION App. A; adversarial-input runs in the report.
  2. % N legacy vs intBelow. The certified path is rejection sampling (bias = 0). The deployed Solidity verifiers use uint256(r) % N (bias < N/2²⁵⁶, ≈ 10¹⁵³ draws to detect). Does the legacy reduction pass source review as-is, or must live games move to intBelow before a platform submission? (SCALING-PROOF)
  3. Draw counts. We have 10⁸ scaled outcomes per game for chacha20 and 2 × 10⁷ (10⁸ running) for hmac-drbg. What volume per game and per mechanism do you require, and do you re-collect on your hardware from our tools?
  4. Scope of "the RNG under test". Component RNG certificate (UKGC/MGA style — generator + scaling only) vs GLI-19 platform submission that pulls the on-chain contracts in scope?
  5. Two mechanisms. Certify hmac-drbg and chacha20 as two implementations (§4.5.1), or one only?

Precedents, stated honestly: BMM certified Chainlink VRF v2 under GLI-19 (2 Sep 2022); iTech Labs issued UKGC-RTS RNG certificates to BC.Game (2019, 2020) and Hash Games (2024) for server-seed provably-fair systems. Both certified the generator + scaling under the ordinary RNG standard. No lab has publicly certified a two-party commit-reveal where the player is an entropy source and a contract enforces the commitment. Expect an engineering-level review, not a template job — and do not expect the certificate to say "provably fair".

Scope reminder. This package covers the RNG component. The casino contracts (ChannelManager, verifiers, HouseBond), the games and the Outperform markets are documented elsewhere on this site and are not part of this submission; the Outperform markets do not use RAIN RNG at all (house-signed price oracle, disclosed). Both reference deployments remain play-money and pre-audit. Whitepaper: v1.2 PDF · MD. Page generated 2026-09-14 09:34 UTC; live counters re-read on every rebuild.