{"id":2779,"job_id":5873,"problem_id":6,"lane_id":34,"type":"measure","user_id":76,"model":"auto","provider":"unknown","report_md":"# All-zeros: one-pass M4 solve+reinject is a measured negative; random scalar search to 7/32\n\nMeasured first. Platform prior best 11/32 (submission #6); published reference 14/32 (Beneri). This run’s best verified own candidates: **7/32** (submissions #25, #26). No claim to beat 11 or 14.\n\n## Hypothesis\n\nReturn 2668 gives the exact free-M4 classes for final blocks and the step-61 equation for H0. Return 2630 showed one-pass terminal-word repair fails for ASCII self-match because reinjection changes earlier M4 uses (steps 5/24/38). **Hypothesis for all-zeros:** on single-block lengths with fully free M4 (residue r∈20..55), solving that equation for H0=0 and reinjecting M4 into message bytes 16..19 still yields score≥8 (exact H0=0) above the generic ~16⁻⁸ rate per outer trial, because unconstrained bytes remove the ASCII obstruction of 2630.\n\n## Experiment\n\n1. **Frozen-tail oracle.** Run 60 steps on a message, solve M4*, continue steps 60..63 with M4* without recomputing earlier steps → H0=0 always. Algebra is correct when late state is frozen.\n2. **Reinjection arm.** For L=52, 100 000 uniform random messages: solve M4* from each message’s late state, overwrite bytes 16..19, full RFC1321 MD5 via `hashlib`. Count exact H0 and score histogram.\n3. **Baseline.** Same 100 000 messages without repair (identical draws).\n4. **Random search (separate C code).** Scalar xorshift64* search, full MD5, several L∈{24,32,40,48,52,55}, ~5×10⁸ total trials on Linux aarch64 (≈2.5×10⁶ hashes/s, gcc -O3).\n\n## Results (numbers)\n\n| Arm | trials | score≥1 | ≥2 | ≥3 | ≥4 | ≥5 | ≥6 | exact H0 |\n|---|---:|---:|---:|---:|---:|---:|---:|---:|\n| Baseline random L=52 | 100 000 | 6294 | 393 | 27 | 1 | 0 | 0 | — |\n| M4 solve+reinject L=52 | 100 000 | 6298 | 397 | 33 | 1 | 1 | 1 | **0** |\n| Expected ~trials/16ᵏ | 100 000 | 6250 | 391 | 24 | 1.5 | 0.1 | 0.006 | ~0 |\n\nReinjection never produced H0=0 in 100 000 trials. Score histograms match the baseline and the geometric model within sampling noise. The single reinjection score-6 is not an advantage claim.\n\nC random search histograms also match 16⁻ᵏ (e.g. L=48, 2×10⁸ trials: ≥6:10, ≥7:1). Best digests:\n\n- sub #25: score 7, 32-byte input, digest `0000000238ce2182809ef46548c4f992`\n- sub #26: score 7, 48-byte input, digest `00000009d78ac4582da42fae5cccc414`\n\nplus seven verified score-6 own candidates (#27–#33).\n\n## What this shows about MD5\n\nChanging M4 to satisfy the step-61 H0 equation **does not survive** recomputation of steps 5/24/38 on the free-byte all-zeros domain. The self-match negative of 2630 is not an ASCII artifact; it is message-word dependence. Cheap A-word zeros need a method that preserves the late state (neutral bits / tunnels / multi-pass repair), not one-pass reinjection.\n\nRandom single-block search remains a calibrated baseline: ~2.5M full hashes/s on this 2-core aarch64 VM; reaching 7/32 required O(10⁸) trials, consistent with 16⁷.\n\n## Next run\n\nTry a **state-preserving** repair: after solving M4*, adjust neutral bits in words that are not used between the early M4 uses and step 61 (Klima-style tunnels / Q9 family already used for throughput in T8), and measure P(H0=0) per charged trial against this random baseline. Do not repeat one-pass reinjection.\n\n## OUTCOMES.md entry (proposed)\n\n| Track | Method | Budget and hardware | Best reached | Return |\n| --- | --- | --- | --- | --- |\n| All zeros | One-pass free-M4 step-61 solve+reinject vs random (L=52, 1e5); scalar random search multi-L | ~0.02 CPU-h Python + ~0.09 CPU-h C on Linux aarch64 2-core; ~5e8 C hashes | 7/32 (subs #25,#26); reinject exact H0 0/1e5 (negative) | (this return) |\n","patch":null,"cpu_hours":0.12,"hashes":{"random_search.c":"035bac2f7160cdb18085efbd8e72b1a0f56a3d635c5cf913081b77c378981fa6","m4_reinject_urandom_100k.json":"90622a187a6a026c7c22ff5ea5da3964f4fe33f83a10350dd64c09c3b52c09d5"},"author_rung":"measured","status":"accepted","final_rung":"verified","created_at":"2026-10-10T18:57:05.952Z","repo_url":null,"commit":null,"cites":{"files":["4c11763bd94a308481596b407004ea1ca2d783beb65cda4b783162fda31eefb1","f337d57a0031d0a750484f40bc689a3bc2e6b38f652c3ae594ca9a70f123454a","9a99ff4952b52dbc35e0c54f017678d26ebb9b3d4477a50f322a7b138a00b5bc","035bac2f7160cdb18085efbd8e72b1a0f56a3d635c5cf913081b77c378981fa6","90622a187a6a026c7c22ff5ea5da3964f4fe33f83a10350dd64c09c3b52c09d5"],"handles":[],"returns":[2668,2643,2630,2702,2762],"messages":[]},"tokens":{"log":"summary","input":0,"models":{},"output":0,"source":"none","entries":0,"cache_read":0,"cache_write":0,"observed_models":[]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"# Recipe: reproduce best candidate (submission #25, score 7)\n\n## Best candidate\n\n- `input_hex`: `62098dbc4b430fbc9a540dbfd5039c95e22c245606e6f8f573ae9e4ccafb1428`\n- `digest`: `0000000238ce2182809ef46548c4f992`\n- Length: 32 bytes\n- Found by: `random_search` L=32 seed=`0x7EADER02` trial=24204891\n\n## Commands\n\nFrom an unpacked copy of the uploaded `random_search.c`:\n\n```bash\ngcc -O3 -o random_search random_search.c\n./random_search 200000000 32 0x7EADER02\n# Expect a BEST 7 line containing the input_hex above.\npython3 reference.py md5-zero-bytes1024-v1 62098dbc4b430fbc9a540dbfd5039c95e22c245606e6f8f573ae9e4ccafb1428\n# -> score 7, digest 0000000238ce2182809ef46548c4f992\n```\n\n`<project base>/docs/verifier/reference.py` is the served verifier. Runtime on the author machine: ~75 s for 2×10⁸ trials (~2.66×10⁶ hashes/s).\n\n## M4 reinjection negative\n\n```bash\npython3 - <<'PY'\n# see uploaded m4_reinject_urandom_100k.json for counts; re-run:\n# the experiment script in the return files (m4_reinject_experiment logic)\nPY\n```\n\nArtifact `m4_reinject_urandom_100k.json` records baseline vs repair histograms and `exact_h0: 0`.","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":"2026-10-10T18:57:05.952Z","effort":null,"also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":null,"department_id":"dept_fa6dbf79354b8806abb61eec","run_id":"run_a7419dd35088e539169f2abb","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"research_evidence":null,"transcript_mode":"summary","known_work":null,"work_disposition":null,"handle":"aasper03","job_brief":"Study what makes the first output word of MD5 small, and use it to reach more leading zeros than generic search would at your budget. Ideas to test: freedom from extra message blocks, neutral bits and message modification from collision attacks applied to the output instead of a difference, early abort on the final additions. Start from the algorithm, not the search. Read research/OUTCOMES.md (what was tried, with what result) and research/QUESTIONS.md, then state one hypothesis about MD5's structure that would make this track cheaper than generic search, and why you expect it. Test it with the smallest experiment that could refute it, against a measured baseline on the same machine. Submit the best candidates the experiment produced. The report is a finding: the hypothesis, the experiment, what it showed about MD5 (positive or negative, with numbers), and what the next run should try. End the report with an entry for research/OUTCOMES.md (track, method, budget and hardware, best reached, what it shows). If the run used only a known tool or plain search, report it as a baseline measurement.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":2781,"handle":"aasper03","status":"accepted"},{"id":2790,"handle":"Benjaminsen","status":"recorded"},{"id":2795,"handle":"aasper03","status":"accepted"},{"id":2801,"handle":"aasper03","status":"accepted"},{"id":2810,"handle":"aasper03","status":"accepted"},{"id":2837,"handle":"aasper03","status":"recorded"}],"route_dependents":[],"research_url":null,"transcript_url":"/projects/md5/return/2779/transcript","files":[{"sha256":"4c11763bd94a308481596b407004ea1ca2d783beb65cda4b783162fda31eefb1","name":"report.md","bytes":3701},{"sha256":"f337d57a0031d0a750484f40bc689a3bc2e6b38f652c3ae594ca9a70f123454a","name":"recipe.md","bytes":1128},{"sha256":"9a99ff4952b52dbc35e0c54f017678d26ebb9b3d4477a50f322a7b138a00b5bc","name":"transcript_summary.md","bytes":1983},{"sha256":"035bac2f7160cdb18085efbd8e72b1a0f56a3d635c5cf913081b77c378981fa6","name":"random_search.c","bytes":4128},{"sha256":"90622a187a6a026c7c22ff5ea5da3964f4fe33f83a10350dd64c09c3b52c09d5","name":"m4_reinject_urandom_100k.json","bytes":1484}],"decided_by_author_handle":false,"reviews":[],"decisions":[{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #25 (md5-zero-bytes1024-v1, 7): the recomputation is the check on a record challenge","decided_at":"2026-10-10T18:57:05.952Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]}],"decision":{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #25 (md5-zero-bytes1024-v1, 7): the recomputation is the check on a record challenge","decided_at":"2026-10-10T18:57:05.952Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]},"report_sha256":"4c11763bd94a308481596b407004ea1ca2d783beb65cda4b783162fda31eefb1","research_authority":{"witness_status":"verified input","research_status":"research report unreviewed","scopes":[]},"research_links":[],"duplicates":[],"cited_messages":[]}