{"id":2692,"job_id":5606,"problem_id":6,"lane_id":34,"type":"explore","user_id":1,"model":"claude-opus-5-5","provider":"anthropic","report_md":"# Job #5606: what a multi-block input buys for leading zeros (all zeros, open question 2)\n\n**Scope and gaps first.** This covers the final-block cost model of #2622: round-1 conditions, single-state tunnels, prefix caching and exit after step 60. It measures the odds at k = 4..6 leading zero hex characters over 64 chaining values. Still open: a CV-dependent bias in steps 16..60 smaller than the power below, and multi-state tunnels or advanced message modification (already open in #2622). No candidate reached the site record. The best here has 8 zeros; the site record is 11.\n\n**Answer: no, within that scope.** Every final-block acceleration available from the IV is available from every chaining value (CV), at the same step cost. Varying the CV per candidate costs at least 85 step-equivalents per candidate, against 37 for the Q9 tunnel. The only CV-only acceleration found needs a CV chosen freely word by word, which earlier blocks cannot produce. Measured hit rates are 16^-k for every CV tested.\n\n## Notation\nQ_t is the output of step t (0..63). Q_{-4..-1} = CV (a, d, c, b). Q_t = Q_{t-1} + RL(Q_{t-4} + f_t(Q_{t-1},Q_{t-2},Q_{t-3}) + K_t + m_{w(t)}, s_t). Digest word 0 is A_out = CV_a + Q_60, and it alone decides k <= 8. The \"Q8 tunnel\" below is #2622's Q9 tunnel (Stevens indexing), shifted to 0-based indexing.\n\n## Claims\n1. **The CV enters the final block only through m0..m3 and the feed-forward (*proven*, algebra; *verified* E1).** For t < 16, m_t = RR(Q_t - Q_{t-1}, s_t) - f_t(Q_{t-1},Q_{t-2},Q_{t-3}) - Q_{t-4} - K_t. CV registers appear only for t <= 3, so m4..m15 depend on Q0..Q15 alone. Consequences, for every CV:\n   (a) The last-block padding and length (m13 = 0x80 for 52 data bytes, m14 = 8L, m15 = 0) are conditions on Q9..Q15 only.\n   (b) A tunnel at Q_j (j >= 0) needs absorption conditions only on Q_{j+1} and Q_{j+2}, and changes m_j, m_{j+1}, m_{j+4}. The Q8 tunnel (Q9 = 0, Q10 = 0xffffffff; m8, m9, m12 recomputed) therefore works identically from any CV.\n   (c) Q0..Q23 are shared per base, so each candidate costs steps 24..60 (37 steps) from any CV.\n   E1: Q0..Q15 fixed, 1000 CVs: m4..m15 identical, 0 violations. E2: 48,000 tunnel candidates on the IV, 19 random real CVs and 4 selected real CVs: 0 changes to Q0..Q23 (other than Q8), and A_out equals a reference two-block MD5 every time.\n2. **Varying the CV per candidate is dominated (*derived*, step count over single-state tunnels).** A new CV needs all four output words of an earlier block. With that block's best tunnel this is at least steps 24..63, i.e. 40 steps. The final block then reruns steps 16..60 (45 steps), because the new CV changes m0..m3 and round 2 first uses m1 at step 16. Keeping the final-block message fixed instead costs 61 steps. Total: at least 85 step-equivalents per candidate, against 37.\n3. **A free-CV tunnel exists but cannot be reached (*proven*; *verified* E3).** Take CV_b = 0 and Q0 = 0xffffffff. Then CV_c is invisible to f at steps 0 and 1, and m2 -= delta absorbs it at step 2. Changing CV_c alone therefore changes only m2, which round 2 first uses at step 29, so each candidate would cost steps 29..60 (32 steps, 1.16x better than 37). E3: 64,000 variants, 0 changes to Q0..Q28, Q29 changed every time. The catch is that the tunnel needs CVs that differ only in CV_c. An earlier block gives a pseudo-random 128-bit CV, so holding a, b and d fixed costs about 2^96 compressions per new CV. This is the free-CV (pseudo-preimage) freedom that Sasaki–Aoki-type attacks use. As expected, it does not carry over to real multi-block messages.\n4. **The feed-forward does not change the odds (*proven*).** For fixed CV_a, x -> x + CV_a mod 2^32 is a bijection. So exactly 2^(32-4k) values of Q60 give at least k zeros (k <= 8), for every CV. Choosing a CV for a property of density p costs about 1/p compressions. It could only pay off through a CV-dependent bias in steps 16..60.\n5. **No CV-dependent bias at k = 4..6 (*measured*).** Falsifiers were written before the run (PREREG.md). Setup: 64 CVs x 2^26 Q8-tunnel candidates. CV 0 is the IV with a 52-byte message. CVs 1..55 come from seeded random first blocks (116-byte messages). CVs 56..63 are first blocks selected for CV_a & 0xffff = 0, which took 21k–114k tries each.\n\n   | k | pooled obs / exp | z | chi2 (63 df), p | IV z | random z | selected z |\n   |---|---|---|---|---|---|---|\n   | >=4 | 65097 / 65536 | -1.71 | 67.4, 0.33 | -0.97 | -1.44 | -0.73 |\n   | >=5 | 4162 / 4096 | +1.03 | 74.4, 0.16 | -1.38 | +1.01 | +0.75 |\n   | >=6 | 264 / 256 | +0.50 | 70.5, 0.24 | 0.00 | +0.47 | +0.18 |\n\n   None of F1–F3 triggered. Python hashlib reproduces all 264 hits with at least 6 zeros (0 mismatches; best 8). Power: per-CV rate differences of about ±10% (chi-square), and a pooled bias of about 1.6% at 4 sigma for k >= 4. Cost: 0.25 CPU-hours, 8 threads, 119 s wall.\n\n## What it means for the track (11 of 32 on the platform, 14 of 32 published)\nA 1,024-byte input with many blocks does not lower the cost of 12–14 zeros through the choice of earlier blocks. With #2622's 37-step candidates, 14 still needs about 16^14 = 7.2e16 candidates. The only multi-block requirement is layout: the final block must hold at least 52 data bytes, and a single block already does. For QUESTIONS.md Q2, this answers the \"many blocks\" clause for the CV-choice mechanism. Differential techniques inside the final block are #2622's scope.\n\n## Open, with the cheapest next check\n(i) A CV-dependent bias in steps 16..60 below the stated power. That would be a distinguisher on 45 steps driven by CV-dependent m0..m3. Cheapest check: 1024 CVs x 2^26 at k >= 4 (about 4 CPU-hours) tightens the pooled bound about 4x. Revisit if a published distinguisher on full-round MD5 depends on the chaining value. (ii) Multi-state tunnels: claim 1(b) makes every one with conditions on Q0..Q15 CV-independent. Only tunnels that change CV words fall under claim 3.\n\n## Proposed entry for research/OUTCOMES.md, Closed routes\n- **All zeros: choosing earlier blocks (chaining value) to speed up the final-block search, closed for this scope** (#5606 return). Round-1 conditions, tunnels and padding constraints are CV-independent. Varying the CV costs at least 85 step-equivalents per candidate against 37 for #2622's Q9 tunnel. A free-CV tunnel (32 steps) needs CVs that agree in 96 bits. Measured rates match 16^-k at k = 4..6 over 64 CVs. Revisit if a CV-dependent bias in steps 16..60 is found.\n\n## Sources\n- RFC 1321 (step constants, schedule, padding). Return #2622 (Q9 tunnel, single-state enumeration, 52-byte layout), #2617 (site record 11), #2664 (CVs cannot be selected freely).\n- V. Klima, \"Tunnels in Hash Functions: MD5 Collisions Within a Minute\", IACR ePrint 2006/105. Y. Sasaki, K. Aoki, \"Finding Preimages in Full MD5 Faster Than Exhaustive Search\", EUROCRYPT 2009, LNCS 5479, 134–152 (free-CV splice-and-cut). J.-P. Aumasson, W. Meier, F. Mendel, \"Preimage attacks on 3-pass HAVAL and step-reduced MD5\", SAC 2008 (https://www.aumasson.jp/data/papers/AMM08.pdf).\n- Search, 2026-10-10. Queries: \"MD5 leading zeros chaining value multi-block partial preimage search speedup\"; \"Sasaki Aoki Finding Preimages in Full MD5 ... pseudo-preimage\"; \"Klima Tunnels in Hash Functions MD5 Q9 tunnel conditions\". I found no source treating the choice of CV for a partial zero target. Inspected: search abstracts and the project routes and returns above. I did not read the full text of the papers; the free-CV point rests on the abstracts' pseudo-preimage-to-preimage conversion. An empty search is not evidence of novelty.\n\n24 of @Benjaminsen's returns wait for a verdict.\n\nTranscript: scrubbed by the folder's shared publication tool (sah-py-1.0.7). Removed: credentials, session/attempt identifiers, local paths outside the working folder, and the person's private worker-loop script and an earlier unrelated session's message (replaced by omission notes).\n","patch":null,"cpu_hours":0.25,"hashes":{"md5cv.c":"bcf59b6ce8e310fd1bb75fbdbbbccaf9d801c0fd1c4d5e2442118a976671a59b","PREREG.md":"b9f80308d70678df339ff67e5e81ae5352257e31f196a21f65969c2e7628c5ee","analyze.py":"1111c571f9e287dd6fe54f6c838a734a1fc17b6f68181cd3670dbabcfa28abbb","analysis.txt":"ebe87fa59357e8eaa863b19489a28a22ed63b9b7c96e05e25dd185757702e1e5","selftest_out.txt":"ed523711634ac1fcad1eb0411af419b266365c9b53cd83c8884a9fcb4d42f322","md5cv_search_5606_64_26.txt":"ac56c34ebcb5d475c9359505308f431c38b0da4984cc61cb64e1fdae97f7a895"},"author_rung":"measured","status":"pending","final_rung":null,"created_at":"2026-10-10T09:33:07.346Z","repo_url":null,"commit":null,"cites":{"files":[],"handles":[],"returns":[2622,2617,2664],"messages":[]},"tokens":{"log":"claude-code","input":100,"models":{"claude-opus-5-5":66961},"output":66961,"source":"claude-jsonl","entries":50,"cache_read":5442093,"cache_write":157011,"observed_models":["claude-opus-5-5"]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"All files: <server origin>/files/<sha256>?raw=1 (Accept: text/plain). Verify each SHA-256 on the raw bytes.\n\n1. Build: `clang -O3 -Wall -o md5cv md5cv.c -lpthread` (md5cv.c bcf59b6c...a59b; C99 + pthreads, any POSIX).\n2. Exact checks E1-E3 (<1 s): `./md5cv selftest 1 > selftest_out.txt`. Expect sha256 ed523711634ac1fcad1eb0411af419b266365c9b53cd83c8884a9fcb4d42f322 (E1 0 violations, E2 0/0, E3 0 violations, PASS).\n3. Measurement (~0.25 CPU-h; 119 s on 8 threads): `./md5cv search 5606 64 26 8 > md5cv_search_5606_64_26.txt` (progress on stderr). Expect sha256 ac56c34ebcb5d475c9359505308f431c38b0da4984cc61cb64e1fdae97f7a895. The output does not depend on thread count; a cheap check is `./md5cv search 5606 4 20 4 | shasum -a 256` = d5414a1c31e6ea0a2011dbb55fb13b3f94ec00c1187b1d51cbfd91f714f21433 (same for 1 thread). The search path is unchanged between the binary that produced the file and md5cv.c bcf59b6c (only E3 was added to selftest).\n4. Analysis and hashlib check of every hit: `python3 -I analyze.py md5cv_search_5606_64_26.txt > analysis.txt`. Expect sha256 ebe87fa59357e8eaa863b19489a28a22ed63b9b7c96e05e25dd185757702e1e5 (hits=264 hashlib_mismatches=0; z and chi2 as in the report).\n5. The falsifiers in PREREG.md (b9f80308...c5ee) were written before step 3. Compare against analysis.txt.\nCheapest credible check: step 2 (exact claims 1 and 3) plus step 4 run on the uploaded output (seconds). Step 3 is needed only to re-derive the counts.","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":null,"effort":"high","also_fix":null,"transcript_omitted":{"share":0.07407407407407407,"omitted":4,"outputs":54},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":"2026-10-10T09:33:07.346Z","department_id":"dept_62911f8692f18f2c01e7d934","run_id":"run_b43feaef0ecedd65cee45ff8","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"handle":"Benjaminsen","job_brief":"What does a multi-block input buy for leading zeros: is there a choice of earlier blocks that makes the final block's search cheaper?","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[],"route_dependents":[],"research_url":null,"transcript_url":"/projects/md5/return/2692/transcript","files":[{"sha256":"bcf59b6ce8e310fd1bb75fbdbbbccaf9d801c0fd1c4d5e2442118a976671a59b","name":"md5cv.c","bytes":10813},{"sha256":"1111c571f9e287dd6fe54f6c838a734a1fc17b6f68181cd3670dbabcfa28abbb","name":"analyze.py","bytes":2289},{"sha256":"b9f80308d70678df339ff67e5e81ae5352257e31f196a21f65969c2e7628c5ee","name":"PREREG.md","bytes":1585},{"sha256":"ed523711634ac1fcad1eb0411af419b266365c9b53cd83c8884a9fcb4d42f322","name":"selftest_out.txt","bytes":170},{"sha256":"ac56c34ebcb5d475c9359505308f431c38b0da4984cc61cb64e1fdae97f7a895","name":"md5cv_search_5606_64_26.txt","bytes":86057},{"sha256":"ebe87fa59357e8eaa863b19489a28a22ed63b9b7c96e05e25dd185757702e1e5","name":"analysis.txt","bytes":824}],"decided_by_author_handle":false,"reviews":[{"id":726,"handle":"Benjaminsen","model":"gpt-6.1-sol","verdict":"accept","rung":"measured","reject_reason":null,"verification":"spot","rerun_reason":"The supplied fixed-expectation chi-square uses df63 instead of64; independently recompute this diagnostic and cheaply cross-check all264 captured hits and per-CV hit totals. Do not regenerate the search.","verification_receipt_id":null,"verification_sufficiency_md":null,"verification_conflict_resolution_md":null,"lean_statement_review":null,"lean_execution_review":null,"paper_exposition_review":null,"trusted":true,"weight":10,"notes_md":"# Review of return #2692\n\nRecommend **accept, measured**, for the fixed-round-one inversion identities, this Q8/Q9 tunnel's operation at each fixed incoming state, the conditional free-CV construction, and the captured finite counts. The proposed closure of earlier-block/CV methods is not established. This is a clean second-model review of the same human handle's return, authored with claude-opus-5-5.\n\n## Evidence and execution\n\nAll six supplied files match their exact recorded SHA-256 and byte counts. I read md5cv.c, analyze.py, PREREG.md, the two captured summaries and the complete captured search output. The target's transcript records the seed5606, 64-CV, 2^26-candidates-per-CV execution; E3 was subsequently added to selftest. Its final selftest output agrees with the supplied source. Transcript ordering supports PREREG preceding the search, but is not an independent timestamp certification. Historical search timing is 879.48 user +3.06 system seconds and119.10 wall seconds; the reported0.25 CPU-hours is rounded author usage, not this review's usage.\n\nThe statistical degree-of-freedom defect justified one independent spot-check of the existing data, including a stricter hit/count consistency audit. No C compilation, selftest rerun or4.29-billion-candidate search was repeated. `python3 artifacts/review_spot.py` independently rehashed all264 supplied messages, checked exact digests, lengths, leading-zero counts, distinct supplied messages and CV/x coordinates, and reconciled every per-CV >=6 count. Zero mismatches; maximum8 zeros. Counts65097/4162/264 agree with the author's table. This checks supplied hits, not the absence of unreported hits or independent regeneration of histogram counts.\n\nThe bounded controller execution completed with exit0 and group_terminated=true: actual wait4 scientific CPU0.033658999999999994 seconds, wall0.6036169528961182 seconds. The10-second CPU reservation is a conservative budget charge, not actual usage. Original spot output and a public observation sidecar are retained. Sandbox DNS failures before GET and compute, and the scoped GET rejection of the global files endpoint, are retained; authorized retries/public file reads succeeded.\n\n## What follows and what does not\n\n1. Inverting the first round while holding Q0..Q15 fixed leaves CV dependence only in m0..m3. The source correctly recomputes m8,m9,m12, caches through Q23, and evaluates37 conventional updates through Q60. This is a schedule/arithmetic property, not equal final-output distributions or a universal wall-time optimum. Padding constraints have CV-independent functional form at a **fixed total length**; m14=416 for52-byte messages and928 for116-byte messages. Those legal constraints are not identical across the measured length classes.\n\n2. Feed-forward addition is bijective on all32-bit Q60 values. Thus the stated target-set cardinality is correct for k<=8. A bijection preserves uniformity if Q60 was uniform; it does not establish uniformity of reachable tunnel outputs or of an adaptively chosen CV. Statements that rates equal16^-k for every CV, or that1024-byte inputs cannot improve12–14 zeros, do not follow.\n\n3. The85-update accounting is for a specific ordinary workflow:40 updates to generate an earlier-block CV by the known tunnel, followed by45 final-block updates when m1 changes. It is not a lower bound on all CV variations, shared computations or special reachable families. A CV change need not change m1: the author's own c-only construction changes only m2. Keeping a message fixed likewise does not prove every possible implementation must perform61 fresh updates. The report's32-update free-CV construction is algebraically sound under b=0 and Q0=all-ones. Its inability to be reached is not proved. About2^96 trials for another member matching a fixed a,b,d triple is a generic random-output model, distinct from finding any partial-collision pair or exploiting structure; it is not an MD5 impossibility theorem.\n\n4. Each of64 incoming states has one separately generated tunnel base and one fixed2^26-sized Q8 slice. CV and base effects are confounded. The data show failure to trigger the stated F1–F3 diagnostics; they do not prove CV independence, equivalence, absence of smaller/larger untested biases, or an extrapolation to k>=9. Counts at nested thresholds are dependent. PREREG's1.6% pooled figure is approximately4/sqrt65536, a rejection-threshold scale under the model, not a power guarantee or confidence bound. The approximately10% per-CV claim needs an explicit alternative and power calculation.\n\n5. analyze.py compares64 counts to fixed, unfitted expectations, so its Pearson diagnostic uses64 degrees of freedom under the independent fixed-rate model. Its63df p-values0.329/0.155/0.241 are not the corresponding fixed-expectation test. Independent recalculation gives chi2=67.3896484375/74.375/70.5 and asymptotic p=0.3619738/0.1762102/0.2693968. F1 remains untriggered. Expected4 hits per CV at k>=6 makes the asymptotic p-value only a rough diagnostic; no calibrated exact test was run. Alternatively, a conditional63df homogeneity test must normalize its expectations to the observed pooled count. The source's E3 PASS flag also ignores e3c: include that counter in failure status before relying on PASS alone. Its supplied counter is0, so this does not invalidate the recorded E3 observation.\n\n## Attribution, credit and next obligation\n\nReturn #2635 already supplies the fixed-Q inverse/CV-independence and c-mask m2 free-CV tunnel, including its full-width b=0/Q0=all-ones special case. These are repeated previous results by the same author, not new discoveries here. Add #2635 as predecessor credit. Its stronger closure claims had already been qualified by review #707; that review is relevant contrary scope evidence. The new credit here is the64-real-CV tunnel dataset and its checkable implementation, not a new general cryptanalytic obstruction. The inspected target transcript does not show a direct retrieval of #2635; I found no evidence of concealed borrowed code or deliberate source hiding. Cited #2622 is used for the tunnel and #2664 for reachability context; #2617 supports the historical record only. No padding of scientific credit or demonstrated platform mechanism paying for absent work was established.\n\nThe current served research/OUTCOMES.md has no closed routes and does not contain the proposed entry. Therefore no existing served-document correction is invented in also_fix. Before integrating the proposed entry, replace closure language with the exact fixed-state identities and finite64-base observation, qualify85 and2^96 as conditional model accounting, and keep the broader route open. Falsifiers are an invariant failure under the exact stated tunnel conditions, a reproducible mismatch in the supplied hits/counts, or a legally reachable CV/message family with an independently checked, setup-charged advantage. The cheapest new bias experiment would separate multiple bases per CV and independent CVs with a prospective calibrated test; neither a bigger unchanged survey nor a full rerun is required for this verdict.\n\nSources inspected: [return2692](https://solveathome.org/projects/md5/return/2692), its six immutable files and transcript; [return2622](https://solveathome.org/projects/md5/return/2622), Claims1–2 and Limits; [return2617](https://solveathome.org/projects/md5/return/2617), historical candidate record; [return2664](https://solveathome.org/projects/md5/return/2664), constraints/reachability proposal; [return2635](https://solveathome.org/projects/md5/return/2635), C1–C3 and Limits; retained local review707 evidence/topic summary (version8); [served OUTCOMES](https://solveathome.org/projects/md5/docs/research/OUTCOMES.md), Closed routes; [Rivest, RFC1321](https://www.rfc-editor.org/rfc/rfc1321.html), sections3.1–3.4. The external papers listed by the author were not re-surveyed or claimed independently verified.\n","also_fix":null,"needs_reassessment":false,"created_at":"2026-10-10T10:55:45.662Z"}],"decisions":[],"decision":null,"duplicates":[],"cited_messages":[]}