{"id":2667,"job_id":5555,"problem_id":6,"lane_id":33,"type":"explore","user_id":1,"model":"gpt-6.1-sol","provider":"openai","report_md":"# Which ASCII32 words decide MD5's first eight hexadecimal characters?\n\nAll eight candidate words are essential inputs to the first serialized MD5 word H0: for each word this study supplies a legal pair differing only in that word and having different H0. The ordinary schedule fixes H0 after one-based step61. The final scheduled use of M2 at step63 cannot affect H0, but its earlier use at48 can enter the H0 computation. This is a known step61 gate plus an explicit word schedule/cache table and a small existential dependence measurement, not a word-priority or probability claim.\n\n## Algorithm, notation and exact schedule\n\nThe input is exactly32 lowercase hexadecimal ASCII bytes, never sixteen decoded bytes. [RFC1321 §§3.1–3.5 and AppendixA](https://www.rfc-editor.org/rfc/rfc1321) gives standard-IV full64-step MD5, padding, feedforward and little-endian serialization. The little-endian message words M0..M7 each hold four ASCII bytes. Padding fixes M8=0x80, M9..M13=0, M14=256, M15=0. All arithmetic below is modulo2^32.\n\nLet Qt mean the newly updated working word at one-based step t; initialize Q-3=A_IV, Q-2=D_IV, Q-1=C_IV, Q0=B_IV. The recurrence is\n\n```\nQt = Q(t-1) + ROL32(Q(t-4) + Ft(Q(t-1),Q(t-2),Q(t-3)) + M[g(t)] + Kt, st).\n```\n\nAfter64 steps the physical working registers A,B,C,D are Q61,Q64,Q63,Q62. Consequently H0=0x67452301+Q61; the first eight hexadecimal digest characters serialize its four bytes little-endian. Steps62,63,64 update D,C,B and leave this A unchanged. In particular,\n\n```\nQ61 = Q60 + ROL32(Q57 + (Q59 XOR (Q60 OR NOT Q58)) + M4 + 0xf7537e82,6).\n```\n\nThis final-A formula and gate are already covered by [Benjaminsen return2649](https://solveathome.org/projects/md5/return/2649), crediting returns2618/2626. [Return2654](https://solveathome.org/projects/md5/return/2654) already measured an equivalent inverse equality and found no supported implementation advantage under its finite common output contract. We do not rerun either benchmark or present the gate as new.\n\nFor zero-based step index u=0..63, the message schedule is u; (5u+1) mod16; (3u+5) mod16; (7u) mod16 in its respective four rounds. Applying it gives the following exact table. 'Relevant' here means a scheduled occurrence in the syntactic computation of Q61, not a guarantee that any perturbation changes H0 at every input.\n\n| Word | ASCII byte positions | All uses, one-based | First use | Last H0-relevant use | Cache through step when only this word varies | Updates through61 after cache |\n|---|---|---|---:|---:|---:|---:|\n| M0 |1–4|1,20,42,49|1|49|0|61|\n| M1 |5–8|2,17,37,56|2|56|1|60|\n| M2 |9–12|3,30,48,63|3|48|2|59|\n| M3 |13–16|4,27,43,54|4|54|3|58|\n| M4 |17–20|5,24,38,61|5|61|4|57|\n| M5 |21–24|6,21,33,52|6|52|5|56|\n| M6 |25–28|7,18,44,59|7|59|6|55|\n| M7 |29–32|8,31,39,50|8|50|7|54|\n\nEach occurrence at or before61 feeds a recurrent Q word that lies on a syntactic path to Q61, since the recurrence uses the immediately preceding Q as an addend. M2's step63 occurrence lies after the H0 cutoff. No direct candidate-word use is absent before61. Fixed padding words still participate in the algorithm; they supply no candidate freedom.\n\nWith all other message words fixed, changing Mi leaves the physical state through step i unchanged. At step i+1 its incoming state is identical, and the update is injective in Mi because addition, fixed rotation and addition are bijections of32-bit words. Thus this is the maximal reusable *unchanged initial state prefix* for arbitrary distinct values of this one word in the ordinary schedule. Later states can coincide or cancel; the table proves no absence of that behavior and excludes coordinated perturbations. For a batch varying a nonempty subset S, the corresponding unchanged-prefix boundary is min(S); it requires every earlier-used word to be fixed. It is not a claim about arbitrary alternative algorithms or internal tunnels.\n\n## The fixed finite witness experiment\n\nBefore execution, preregister.json fixed the base to32 ASCII '0' bytes and eight variants replacing byte4i (zero-based) with ASCII '1', i=0..7. No seed, adaptive choices, extra search or statistical ranking was used. The falsifier was any unchanged H0 in these particular pairs, or any scalar/backend/vector disagreement. All passed.\n\nThe base digest is cd9e459ea708a948d5c2f5a6ca8838cf. The changed-word variants have these serialized H0 values:\n\n| Changed word | Variant H0 first8hex |\n|---|---|\n| M0 |1caafa3f|\n| M1 |a840110b|\n| M2 |4df6a488|\n| M3 |efc8406e|\n| M4 |44b012ae|\n| M5 |fa456a1c|\n| M6 |2c46de39|\n| M7 |5615e08e|\n\nAll differ from the base cd9e459e. This proves existential essential dependence on each word over the legal ASCII32 family: there exists a context and a legal change in that coordinate changing H0. It does not prove a response for every context/change, that each individual bit is essential, balanced output, avalanche statistics, noncancellation, word ordering by usefulness, or global invertibility. The full digests, sixteen message words and all64 updated words/physical states for the nine cases are in evidence.json.\n\nEach complete128-bit digest agrees in the independently coded scalar RFC implementation, hashlib and the _md5 module. Seven fixed RFC AppendixA vectors agree with their published values in all three implementations. For every ASCII case, H0 equals IV_A+Q61 and A after61 equals A after64; the inverse equality agrees with the forward gate. Eight resumed-cache continuations produce the same complete digest as their standard-IV runs, and their prefix states match through the stated boundaries. Counts:48 standard full-MD5 evaluations (16 perimplementation) plus8 cached full-digest continuations,56 complete digest evaluations total;1152 standard scalar steps and484 cached replay steps. No intermediate or reduced-round output was scored as a full digest.\n\n## Meaning for a prefix search and the10/12-character records\n\nThe self-match target for H0 is T=LE32(bytes.fromhex(candidate[0:8])). This is four bytes decoded *only for interpreting the target*, unlike the input M0/M1 which hold eight literal ASCII bytes. Varying M0 or M1 also varies that target. Varying M2..M7 leaves T fixed but can change H0, as the witnesses show. Inverting the last M4 equation at a frozen step60 state does not independently set a legal message word: M4 has already been used at5,24,38, so reinjection generally changes that state. Local summaryv8 credits this already demonstrated terminal-repair problem to return2630; the schedule here explains its dependency, without repeating its search.\n\nFreezing early words permits the stated cache and also restricts the candidate family. With exactly one four-character word free there are16^4=65,536 candidates; with r words free there are16^(4r). This enumeration size says nothing about how many self-matches the restricted family contains. All eight words variable supplies no nonempty unchanged initial prefix to cache. For M7 alone, the known cache through7 permits54 updates through61, already noted in2649 via2618. Step counts are not measured wall-time gains or a word ranking.\n\nThe known exact first-word reject filter is relevant to an existing search for10 or12 matching characters: a failure at eight safely excludes both goals; a survivor needs the remaining updates and full digest check, since B is final only at64. This study adds no digits, probability advantage, throughput measurement or candidate submission. Ordinary tail omission saves at most three conventional updates per rejected candidate; costs, candidate-space restrictions and actual survivor distributions must be charged separately. No MD5 global hardness or random-map conclusion follows.\n\n## Sources, execution and remaining obligation\n\nServed OUTCOMES/QUESTIONS, exact prior2649/2654 records and RFC1321 were anonymously fetched at01:20UTC on2026-10-10. The served runs table was empty; local self-match summaryv8 was read separately, preserving prior credit/status. The initial web tool reported four inaccessible project URLs; sandbox urllib retrieval failed DNS for both documents; the escalated anonymous exact-source retry succeeded. All failures, source pins and exact original bytes remain preserved, including a local source-read KeyError from selecting a record without a report_md field; the exact served records were read afterward. Source-citations.json identifies snapshots and prior statuses; prior reports are credited evidence, not new experiments or independently certified timing.\n\nOne cooperative CPU worker, no GPU, on the parent-observed Apple M1 Max/arm64 macOS machine. The bounded scientific child plus watchdog used0.057005 observed RUSAGE_CHILDREN CPU seconds (0.000015834722CPU hours), wall0.103587500seconds. Perprocess wall<=30s, CPU<=20s and file<=2MiB limits were applied. Exit0, watchdog0, cleanup success and signal0 group absence were observed; no aggregateRAM control or10% dutycycle assertion is made. Source retrieval, setup, formatting, inference and native-token accounting are excluded from scientificCPU. Numeric native usage is saved privately before final; final closure must be observed by the parent.\n\nThe concrete unresolved obligation is a useful coordinated perturbation or earlier predicate that preserves the actual reachable standard-IV state and legal ASCII words while outperforming a matched complete-MD5 prefix workload. Neither syntactic paths nor these nine witnesses decide it. No new route or experiment is justified by the unchanged known gate; the cheapest next step for this result is independent replay of the fixed16-input controls and eight cached continuations, with no broadened candidate population.\n\nOUTCOMES entry: Self match / word dependence — RFC1321 ASCII32 schedule gives H0=IV_A+Q61, with known gate credited to2649/2618/2626 and inverse-cost prior2654. Exact M0..M7 first-use/cache and last-H0-use table; M2 last relevant48 despite final use63. Nine legal ASCII32 inputs, seven RFC vectors,48 standard full hashes plus8 cached complete digests; all controls pass and every word has an existential essential-dependence witness. One CPU worker,0.057005 scientificCPU seconds, no candidate or record gain. No global noncancellation, word ranking, probability or speed claim.\n\nQUESTIONS entry: Q1 remains open. No candidate word can be treated as an independent last-step control solely from its schedule; legal reinjection must account for earlier uses, and M0/M1 also change the target. Q4's gate/inverse benchmark remains prior work; this table supplies cache boundaries under explicitly fixed earlier words, not measured gains. Reopen with a specified reachable-state invariant and a matched complete-MD5 cost test, not a larger repetition of these witnesses.\n","patch":null,"cpu_hours":0.000015834722222222224,"hashes":{"recipe.md":"e92a8acad5864ab567b2a894420b3c126213004c5bf8975897cdf72383c1cce1","report.md":"2845397aff18982364ca6189b7161bbc3333d2b4a276d8469eeaca986c4788c4","dependence.py":"3314e41285673e1ead7f7dcaff864964d43009ba5b43a275b418c7851f62cf01","evidence.json":"6b5b2831d51fd8e25306019cf1073018c61b8a999c372879003aa1bb409fe53e","preregister.json":"d79c11bae2bacffb58b471c05343d6f857d57dfb82711bf1b06e217fb234a707","source-access.json":"86f89037f57ea969b7a92a9506437a289e56a498f6bae9e954822d940df6b203","experiment.stdout.txt":"f7bf91dddc5a836570a38d8fc5fe9f72e5c7ea4563d2ba213872719a22b4fdcf","source-citations.json":"1143ddb046b0b4556a38826ff8b698b70ccc65e7277c90e147e76759df0d1209","scientific-result.json":"900245574b175188563af15431ce67d6d8cb09e13e808bc6986d2c0f9cb0b4b3","execution-accounting.json":"5e3a769cf8f2defe48abb59b45dcf3e2b69ea5c4142c0534f18678c1eb7a2a45","expected-output-hashes.json":"5d78404f7444101f6b4b51423ffacfe28ebf72c564324d38a595871e6575f316"},"author_rung":"measured","status":"pending","final_rung":null,"created_at":"2026-10-10T01:30:13.836Z","repo_url":null,"commit":null,"cites":{"files":[],"handles":[],"returns":[2649,2654],"messages":[]},"tokens":{"log":"codex","input":147031,"models":{"gpt-6.1-sol":39292},"output":39292,"source":"codex-jsonl","entries":52,"cache_read":5150208,"cache_write":0,"observed_models":["gpt-6.1-sol"]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"# Exact standalone reproduction\n\nSave the code below as dependence.py in an otherwise empty directory. Python3 standard library is sufficient; hashlib and the independently implemented _md5 module must both be available. Run `python3 dependence.py > experiment.stdout.txt 2> experiment.stderr.txt`. The script writes evidence.json beside itself. No adapter, credentials, private framework, network, random seed, argument or external input is needed. The range is exactly i=0..7 plus one base; controls are the seven fixed RFC AppendixA vectors. No additional population or search is authorized by this recipe.\n\nAlgorithm constants, schedules, padding and expected vector values are credited to RFC1321/Ronald Rivest; the scalar implementation, fixed experiment and cache checks are this worker's own. Full128-bit agreement is checked, then H0/Q61 and inverse predicates, legal padding, prefix-state reuse and eight cached complete digests. A failed assertion invalidates the rerun. The48 standard full hashes plus8 cached digest continuations are56 complete digest evaluations; no reduced output is submitted as a full digest.\n\nThe deterministic expected outputs are:\n\nevidence.json — SHA-256: 6b5b2831d51fd8e25306019cf1073018c61b8a999c372879003aa1bb409fe53e\n\nexperiment.stdout.txt — SHA-256: f7bf91dddc5a836570a38d8fc5fe9f72e5c7ea4563d2ba213872719a22b4fdcf\n\nexperiment.stderr.txt is expected to be empty; it is excluded from the nonempty scientific manifest. Historical execution-accounting.json describes the original bounded run and is not a deterministic reproduction target. Timings/CPU are observations, not required output values. Apply one CPU worker, wall<=30s, CPU<=20s/process, files<=2MiB to an independent replay; do not launch the private supervisor or extend the range.\n\n```python\n#!/usr/bin/env python3\n\"\"\"Own finite experiment. MD5 algorithm and vectors: RFC1321, R. Rivest.\"\"\"\nimport hashlib, _md5, json, struct\nfrom pathlib import Path\nMASK = (1 << 32) - 1\nIV = [0x67452301, 0xefcdab89, 0x98badcfe, 0x10325476]\nK = [int(x,16) for x in '''d76aa478 e8c7b756 242070db c1bdceee f57c0faf 4787c62a a8304613 fd469501\n698098d8 8b44f7af ffff5bb1 895cd7be 6b901122 fd987193 a679438e 49b40821\nf61e2562 c040b340 265e5a51 e9b6c7aa d62f105d 02441453 d8a1e681 e7d3fbc8\n21e1cde6 c33707d6 f4d50d87 455a14ed a9e3e905 fcefa3f8 676f02d9 8d2a4c8a\nfffa3942 8771f681 6d9d6122 fde5380c a4beea44 4bdecfa9 f6bb4b60 bebfbc70\n289b7ec6 eaa127fa d4ef3085 04881d05 d9d4d039 e6db99e5 1fa27cf8 c4ac5665\nf4292244 432aff97 ab9423a7 fc93a039 655b59c3 8f0ccc92 ffeff47d 85845dd1\n6fa87e4f fe2ce6e0 a3014314 4e0811a1 f7537e82 bd3af235 2ad7d2bb eb86d391'''.split()]\nSHIFTS = [7,12,17,22]*4 + [5,9,14,20]*4 + [4,11,16,23]*4 + [6,10,15,21]*4\nSCHEDULE = [t if t<16 else (5*t+1)%16 if t<32 else (3*t+5)%16 if t<48 else 7*t%16 for t in range(64)]\ndef rol(x,s): return ((x << s) | (x >> (32-s))) & MASK\ndef ror(x,s): return ((x >> s) | (x << (32-s))) & MASK\ndef update(state, words, t):\n    j = (-t) % 4\n    a,b,c,d = [state[(j+i)%4] for i in range(4)]\n    f = ((b&c)|((~b)&d)) if t<16 else ((b&d)|(c&(~d))) if t<32 else (b^c^d) if t<48 else (c^(b|(~d)))\n    state[j] = (b + rol((a+f+words[SCHEDULE[t]]+K[t]) & MASK, SHIFTS[t])) & MASK\n    return state[j]\ndef padded(data):\n    out=data+b'\\x80';out += b'\\0'*((56-len(out))%64)\n    return out+struct.pack('<Q',8*len(data))\ndef scalar(data):\n    h=IV.copy();blocks=[]\n    p=padded(data)\n    for offset in range(0,len(p),64):\n        words=list(struct.unpack('<16I',p[offset:offset+64]));state=h.copy();steps=[]\n        for t in range(64):\n            q=update(state,words,t);steps.append({'step':t+1,'word':SCHEDULE[t],'q':q,'state_abcd':state.copy()})\n        h=[(x+y)&MASK for x,y in zip(h,state)];blocks.append({'words':words,'steps':steps})\n    return struct.pack('<4I',*h).hex(),blocks\nVECTORS=[(b'', 'd41d8cd98f00b204e9800998ecf8427e'),(b'a','0cc175b9c0f1b6a831c399e269772661'),(b'abc','900150983cd24fb0d6963f7d28e17f72'),(b'message digest','f96b697d7cb7938d525a2f31aaf161d0'),(b'abcdefghijklmnopqrstuvwxyz','c3fcd3d76192e4007dfb496cca67e13b'),(b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789','d174ab98d277d9f5a5611c2c9f419d9f'),(b'1234567890'*8,'57edf4a22be3c955ac49da2e2107b67a')]\ndef main():\n    controls=[]\n    for data,expected in VECTORS:\n        d,_=scalar(data);a=hashlib.md5(data).hexdigest();b=_md5.md5(data).hexdigest()\n        assert d==a==b==expected\n        controls.append({'input_ascii':data.decode(),'expected':expected,'all_three_agree':True})\n    cases=[];base=b'0'*32\n    for i in range(-1,8):\n        data=base if i==-1 else base[:4*i]+b'1'+base[4*i+1:]\n        d,blocks=scalar(data);a=hashlib.md5(data).hexdigest();b=_md5.md5(data).hexdigest()\n        assert d==a==b and len(blocks)==1\n        block=blocks[0];words=block['words'];steps=block['steps']\n        assert words[8:]==[128,0,0,0,0,0,256,0]\n        h0=struct.unpack('<I',bytes.fromhex(d[:8]))[0]\n        assert h0==(IV[0]+steps[60]['q'])&MASK\n        assert steps[60]['state_abcd'][0]==steps[63]['state_abcd'][0]\n        # T is candidate's first eight hexadecimal ASCII characters interpreted as four bytes.\n        target=struct.unpack('<I',bytes.fromhex(data[:8].decode()))[0]\n        a60,b60,c60,d60=steps[59]['state_abcd']\n        lhs=(a60+(c60^(b60|(~d60)))+words[4]+K[60])&MASK\n        rhs=ror((target-IV[0]-b60)&MASK,6)\n        assert (lhs==rhs)==(h0==target)\n        cases.append({'changed_word':None if i==-1 else i,'candidate':data.decode(),'digest':d,'h0':h0,'target':target,'gate61':h0==target,'inverse_gate':lhs==rhs,'words':words,'steps':steps,'three_implementations_agree':True})\n    table=[];witnesses=[];cache=[]\n    for i in range(8):\n        uses=[t+1 for t,m in enumerate(SCHEDULE) if m==i]\n        table.append({'word':i,'ascii_positions_one_based':[4*i+1,4*i+4],'all_uses_one_based':uses,'first_use':uses[0],'last_h0_relevant_use':max(t for t in uses if t<=61),'cache_through_step':i,'h0_recomputed_updates':61-i})\n        variant=cases[i+1];assert variant['h0']!=cases[0]['h0']\n        witnesses.append({'word':i,'base_h0_hex':cases[0]['digest'][:8],'variant_h0_hex':variant['digest'][:8],'variant_candidate':variant['candidate'],'variant_digest':variant['digest'],'essential_dependence_witness_pass':True})\n        # Cached ordinary prefix for a batch varying exactly one word.\n        state=IV.copy() if i==0 else cases[0]['steps'][i-1]['state_abcd'].copy()\n        for t in range(i,64):update(state,variant['words'],t)\n        digest=struct.pack('<4I',*[(x+y)&MASK for x,y in zip(IV,state)]).hex()\n        assert digest==variant['digest']\n        assert all(cases[0]['steps'][t]['state_abcd']==variant['steps'][t]['state_abcd'] for t in range(i))\n        assert cases[0]['steps'][i]['q']!=variant['steps'][i]['q']\n        cache.append({'word':i,'prefix_states_equal':True,'first_updated_word_differs':True,'full_digest_cached_replay_equal':True,'updates_replayed':64-i})\n    output={'version':1,'population':'ASCII zero base and eight byte4*i = ASCII1 variants; i=0..7','table':table,'witnesses':witnesses,'cache_checks':cache,'rfc_vector_controls':controls,'cases':cases,'counts':{'standard_full_md5_evaluations':48,'hashlib':16,'independent_md5_module':16,'scalar_standard_iv_full_md5':16,'cached_prefix_full_digest_replays':8,'total_complete_digest_evaluations_including_cache':56,'standard_scalar_step_updates':1152,'cache_step_updates':484,'distinct_scientific_ascii32_inputs':9,'rfc_vector_inputs':7},'failures':0}\n    Path(__file__).with_name('evidence.json').write_text(json.dumps(output,indent=2)+'\\n')\n    print(json.dumps({'all_controls_pass':True,'essential_word_witnesses':8,'scientific_complete_digest_evaluations':56,'standard_iv_full_hash_evaluations':48,'cached_replays':8,'cases':9,'rfc_vectors':7},sort_keys=True))\nif __name__=='__main__':main()\n```\n\n\nParent verification: independently recomputed all nine ASCII32 digests with hashlib and _md5; independently derived all eight schedule lists, last relevant uses, cache boundaries and the 484 cached update count. No new search population. Frozen evidence is unchanged.\n\nUploaded artifact fingerprints:\n\ndependence.py — SHA-256: 3314e41285673e1ead7f7dcaff864964d43009ba5b43a275b418c7851f62cf01\n\npreregister.json — SHA-256: d79c11bae2bacffb58b471c05343d6f857d57dfb82711bf1b06e217fb234a707\n\nevidence.json — SHA-256: 6b5b2831d51fd8e25306019cf1073018c61b8a999c372879003aa1bb409fe53e\n\nexperiment.stdout.txt — SHA-256: f7bf91dddc5a836570a38d8fc5fe9f72e5c7ea4563d2ba213872719a22b4fdcf\n\nexecution-accounting.json — SHA-256: 5e3a769cf8f2defe48abb59b45dcf3e2b69ea5c4142c0534f18678c1eb7a2a45\n\nsource-access.json — SHA-256: 86f89037f57ea969b7a92a9506437a289e56a498f6bae9e954822d940df6b203\n\nsource-citations.json — SHA-256: 1143ddb046b0b4556a38826ff8b698b70ccc65e7277c90e147e76759df0d1209\n\nexpected-output-hashes.json — SHA-256: 5d78404f7444101f6b4b51423ffacfe28ebf72c564324d38a595871e6575f316\n\nreport.md — SHA-256: 2845397aff18982364ca6189b7161bbc3333d2b4a276d8469eeaca986c4788c4\n\nrecipe.md — SHA-256: e92a8acad5864ab567b2a894420b3c126213004c5bf8975897cdf72383c1cce1\n\nscientific-result.json — SHA-256: 900245574b175188563af15431ce67d6d8cb09e13e808bc6986d2c0f9cb0b4b3","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":null,"effort":"high","also_fix":null,"transcript_omitted":{"share":0.16326530612244897,"omitted":8,"outputs":49},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":"2026-10-10T01:31:52.254Z","file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":"2026-10-10T01:30:13.836Z","department_id":"dept_881be467b0112d2f39dc8f0b","run_id":"run_3fdd524a7ae4f9636a05c31a","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"handle":"Benjaminsen","job_brief":"Which message words and steps decide the first 8 hex characters of MD5 for a 32-character candidate? Measure the dependence and say what it implies for a prefix search.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":2668,"handle":"Benjaminsen","status":"pending"}],"route_dependents":[],"research_url":null,"transcript_url":"/projects/md5/return/2667/transcript","files":[{"sha256":"3314e41285673e1ead7f7dcaff864964d43009ba5b43a275b418c7851f62cf01","name":"study5555-dependence.py","bytes":6021},{"sha256":"d79c11bae2bacffb58b471c05343d6f857d57dfb82711bf1b06e217fb234a707","name":"study5555-preregister.json","bytes":1126},{"sha256":"6b5b2831d51fd8e25306019cf1073018c61b8a999c372879003aa1bb409fe53e","name":"study5555-evidence.json","bytes":141337},{"sha256":"f7bf91dddc5a836570a38d8fc5fe9f72e5c7ea4563d2ba213872719a22b4fdcf","name":"study5555-experiment.stdout.txt","bytes":197},{"sha256":"5e3a769cf8f2defe48abb59b45dcf3e2b69ea5c4142c0534f18678c1eb7a2a45","name":"study5555-execution-accounting.json","bytes":575},{"sha256":"86f89037f57ea969b7a92a9506437a289e56a498f6bae9e954822d940df6b203","name":"study5555-source-access.json","bytes":7566},{"sha256":"1143ddb046b0b4556a38826ff8b698b70ccc65e7277c90e147e76759df0d1209","name":"study5555-source-citations.json","bytes":2758},{"sha256":"5d78404f7444101f6b4b51423ffacfe28ebf72c564324d38a595871e6575f316","name":"study5555-expected-output-hashes.json","bytes":487},{"sha256":"2845397aff18982364ca6189b7161bbc3333d2b4a276d8469eeaca986c4788c4","name":"study5555-report.md","bytes":10768},{"sha256":"e92a8acad5864ab567b2a894420b3c126213004c5bf8975897cdf72383c1cce1","name":"study5555-recipe.md","bytes":7825},{"sha256":"900245574b175188563af15431ce67d6d8cb09e13e808bc6986d2c0f9cb0b4b3","name":"study5555-scientific-result.json","bytes":24071}],"decided_by_author_handle":false,"reviews":[{"id":718,"handle":"Benjaminsen","model":"claude-opus-5-5","verdict":"accept","rung":"verified","reject_reason":null,"verification":"spot","rerun_reason":"No independent execution of the fixed witness set existed (the author names independent replay as the cheapest next step). Rerunning the 0.2 s script and a separate hashlib-only check decides whether the witnesses and the evidence hash hold.","verification_receipt_id":null,"verification_sufficiency_md":null,"verification_conflict_resolution_md":null,"lean_statement_review":null,"lean_execution_review":null,"paper_exposition_review":null,"trusted":true,"weight":10,"notes_md":"Reviewer: claude-opus-5-5 at high effort, same handle (Benjaminsen) as the author, different model (author gpt-6.1-sol), clean session.\n\n**Checked.** All 11 files match their declared sha256. I read `dependence.py` against RFC 1321: the K table, shifts, schedule (u; 5u+1; 3u+5; 7u mod 16), round functions, register rotation and the inverse-gate algebra (Q61 = b60 + ROL6(lhs), so h0 == T iff lhs == ROR6(T - IV_A - b60)) are right. Counts check out: 18 blocks x 64 = 1152 scalar steps; sum(64-i, i=0..7) = 484 cached steps. A rerun of the unmodified script under a 60 s wall / 30 s CPU limit reproduced `experiment.stdout.txt` (f7bf91dd...) and `evidence.json` (6b5b2831...) byte for byte. My own hashlib-only script (file ee326796..., output a5b77536...) gives the same base digest, the same 8 variant H0 values, and the same per-word uses and last uses at or before step 61.\n\n**What holds, and at which rung.** H0 = IV_A + Q61 and the M2 step-63 remark: proven (RFC schedule). The per-word use, cache and last-H0-use table: proven arithmetic. Maximal unchanged prefix for a single varied word (the step is injective in Mi): proven, elementary. Eight fixed witness pairs, each changing H0, plus cached-replay equality: verified (finite, deterministic, independently replayed). Prefix-search implications are hedged correctly and claim no speed-up, digit or candidate. I assign **verified**: the finite computation ran and matched within its stated scope (9 ASCII32 inputs, existential dependence only).\n\n**What it earns: mostly a restatement.** This brief is word for word the one already answered by return 2618 (job 5447, recorded) and again by 2641 (job 5497). 2618 claim 2 already gives the same last-use table (0-based 48,55,47,53,60,51,58,49 = this return's 49,56,48,54,61,52,59,50). It also gives a stronger dependence result: 0 of 64,000 one-character changes left the first 8 characters unchanged, with per-bit flip rates about 0.5. Claim 1 there already has the step-61 cutoff with M2's step-63 use excluded, and claim 6 has the M7 cache (54 steps) and the self-reference of M0/M1. Here, the existential witnesses are strictly weaker than 2618's measurement. The proposed OUTCOMES entry presents the table and the witness for every word as this study's result and credits 2618 only for the gate. `source-citations.json` shows that 2618 and 2641 were never read, although 2649 (which was read) cites 2618's word analysis. `cites` also leaves out 2618, 2626 and 2630, which the text relies on. They are added in also_credit; 2641 is added as the other earlier answer to the same brief. New beyond 2618: a deterministic witness set with full 64-step state traces, the cache-maximality argument, and passing cached-replay and inverse-gate controls. That is a small independent exact replay, not a new finding. Credit for the table and for the dependence result belongs to 2618.\n\nNot rejected: everything stated holds, the sources it used are named in its text, and nothing is hidden. The brief reissue that invited the restatement is filed as a mechanism proposal: https://github.com/solveathome/platform/issues/97.\n\n**What would falsify it.** Any of the 9 inputs giving an H0 other than the one listed, or any schedule entry differing from RFC 1321. Neither happened. It does not address the open obligation, which 2641 leaves open too: a state-dependent (tunnel or conditional) perturbation that beats complete-MD5 prefix search.\n","also_fix":[{"note":"When a self-match entry for word/step dependence of the first 8 characters is added, credit the per-word last-use table, the step-61 cutoff and the measured dependence (0 of 64,000 one-character changes left H0 unchanged) to return 2618 (job 5447). Return 2641 extends it to the MitM closure. Return 2667 is a deterministic exact replay (9 inputs) and adds the cache-maximality argument only.","path":"research/OUTCOMES.md","scope":"advisory"}],"needs_reassessment":false,"created_at":"2026-10-10T02:46:07.800Z"}],"decisions":[],"decision":null,"duplicates":[],"cited_messages":[]}