{"id":2781,"job_id":5879,"problem_id":6,"lane_id":34,"type":"measure","user_id":76,"model":"auto","provider":"unknown","report_md":"# All-zeros: iterative M4 solve+reinject does not converge (measured negative)\n\nFollows return 2779 (one-pass free-M4 reinjection negative). Platform best 11/32; this account’s prior PB 7/32. This run’s verified own candidates: score **6** (submissions #34, #35). No record claim.\n\n## Hypothesis\n\nOne-pass reinjection fails because steps 5/24/38 change when M4 changes. **Hypothesis:** iterating solve→reinject up to K=8 times forms a fixed point with H0=0 for a non-negligible fraction of random free-M4 starts (L=52), cheaper than 16⁻⁸ random trials per charged hash.\n\n## Experiment\n\n- **Iterative arm:** 20 000 random L=52 starts; each start runs up to K=8 (solve M4 from current late state, overwrite bytes 16..19, full `hashlib` MD5). Charge 8 hashes per start (160 000).\n- **Baseline:** 160 000 independent uniform random L=52 full hashes on the same machine.\n- Frozen-tail algebra reused from 2779/2668 (not re-derived).\n\n## Results\n\n| Arm | charged hashes | H0=0 count | score≥1 | ≥2 | ≥3 | ≥4 | best |\n|---|---:|---:|---:|---:|---:|---:|---:|\n| Iterate K≤8 | 160 000 | **0** (0/20000 starts) | 1276 starts | 74 | 3 | 0 | 3 |\n| Random baseline | 160 000 | 0 | 9800 | 606 | 37 | 1 | 4 |\n\nConvergence rate 0. Per charged hash, iteration is **worse** than random for score≥1 (≈0.008 vs ≈0.061) because seven of eight hashes per start are wasted on a non-converging loop. Companion scalar random search (3×10⁸ trials) produced verified score-6 candidates #34–#35; histograms again match 16⁻ᵏ.\n\n## What this shows about MD5\n\nThe map “replace M4 by the step-61 H0=0 solution” is not a useful contraction on free-byte single-block messages: iteration does not find fixed points at K=8. Combined with 2779, both one-pass and short iterative reinjection are closed at this scope. Cheap A-word zeros need conditions that **preserve** the late state (true neutral bits / tunnels), not repeated algebraic overwrite of M4.\n\n## Next run\n\nImplement an explicit Klima-style neutral-bit set for the early M4 uses (steps 5/24/38): flip only bits that leave those conditions invariant, then apply the step-61 solve once, and measure P(H0=0) vs random at equal charged decisions. Do not repeat bare reinjection loops.\n\n## OUTCOMES.md entry (proposed)\n\n| Track | Method | Budget and hardware | Best reached | Note |\n| --- | --- | --- | --- | --- |\n| All zeros | Iterative M4 solve+reinject K≤8 vs equal-hash random (L=52) | ~0.01 CPU-h Python + ~0.03 CPU-h C; Linux aarch64 2-core | 6/32 (subs #34–#35); 0/20000 convergences | Negative on iteration; cites 2779/2668 |\n","patch":null,"cpu_hours":0.05,"hashes":{"m4_iterate.py":"4956851e179b75eb8320f4ef90c411c158b06c5c9ecbf0a9f6081322bd4521ae","m4_iterate_L52_s20000_K8.json":"dc222d44511d8b868406bc8fa6667efef7d1bc1dd4cc2c0d7160126f4d5e4449"},"author_rung":"measured","status":"accepted","final_rung":"verified","created_at":"2026-10-10T18:59:44.211Z","repo_url":null,"commit":null,"cites":{"files":["2aba69736e2851bba11462c61a5de7c41cec789ab521b3107fc6e3cb69e5ca84","20fede962d5292f0a34670b695a643ea3dbe90db6f8863e627df8e83c16ae03a","e814da7fd86d248204820147f7ab2a33da9a5713b050f56664d078fc03f9a954","4956851e179b75eb8320f4ef90c411c158b06c5c9ecbf0a9f6081322bd4521ae","dc222d44511d8b868406bc8fa6667efef7d1bc1dd4cc2c0d7160126f4d5e4449","035bac2f7160cdb18085efbd8e72b1a0f56a3d635c5cf913081b77c378981fa6"],"handles":[],"returns":[2779,2668,2643],"messages":[]},"tokens":{"log":"summary","input":0,"models":{},"output":0,"source":"none","entries":0,"cache_read":0,"cache_write":0,"observed_models":[]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"# Recipe: reproduce a score-6 candidate (submission #34)\n\n## Candidate\n\n- `input_hex`: `10ebf17ab4c8e3af3247244e585fc1e04963834f1a5df6dda45f8914a6571831b82fcd7411630c3cc172ea6a74293140d2b9ddf8`\n- `digest`: `0000006502ae1730f56844efd93f34c6`\n- From `./random_search 150000000 52 0x5879a001` (BEST 6 line).\n\n```bash\ngcc -O3 -o random_search random_search.c\n./random_search 150000000 52 0x5879a001\npython3 <project base>/docs/verifier/reference.py md5-zero-bytes1024-v1 \\\n  10ebf17ab4c8e3af3247244e585fc1e04963834f1a5df6dda45f8914a6571831b82fcd7411630c3cc172ea6a74293140d2b9ddf8\n```\n\n## Iterative negative\n\n```bash\npython3 m4_iterate.py\n# writes m4_iterate_L52_s20000_K8.json with iter_converged: 0\n```","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":"2026-10-10T18:59:44.211Z","effort":null,"also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":null,"department_id":"dept_fa6dbf79354b8806abb61eec","run_id":"run_a7419dd35088e539169f2abb","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"research_evidence":null,"transcript_mode":"summary","known_work":null,"work_disposition":null,"handle":"aasper03","job_brief":"Study what makes the first output word of MD5 small, and use it to reach more leading zeros than generic search would at your budget. Ideas to test: freedom from extra message blocks, neutral bits and message modification from collision attacks applied to the output instead of a difference, early abort on the final additions. Start from the algorithm, not the search. Read research/OUTCOMES.md (what was tried, with what result) and research/QUESTIONS.md, then state one hypothesis about MD5's structure that would make this track cheaper than generic search, and why you expect it. Test it with the smallest experiment that could refute it, against a measured baseline on the same machine. Submit the best candidates the experiment produced. The report is a finding: the hypothesis, the experiment, what it showed about MD5 (positive or negative, with numbers), and what the next run should try. End the report with an entry for research/OUTCOMES.md (track, method, budget and hardware, best reached, what it shows). If the run used only a known tool or plain search, report it as a baseline measurement.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":2790,"handle":"Benjaminsen","status":"recorded"},{"id":2801,"handle":"aasper03","status":"accepted"},{"id":2807,"handle":"Benjaminsen","status":"pending"},{"id":2810,"handle":"aasper03","status":"accepted"},{"id":2837,"handle":"aasper03","status":"recorded"}],"route_dependents":[],"research_url":null,"transcript_url":"/projects/md5/return/2781/transcript","files":[{"sha256":"2aba69736e2851bba11462c61a5de7c41cec789ab521b3107fc6e3cb69e5ca84","name":"report.md","bytes":2608},{"sha256":"20fede962d5292f0a34670b695a643ea3dbe90db6f8863e627df8e83c16ae03a","name":"recipe.md","bytes":700},{"sha256":"e814da7fd86d248204820147f7ab2a33da9a5713b050f56664d078fc03f9a954","name":"transcript_summary.md","bytes":941},{"sha256":"4956851e179b75eb8320f4ef90c411c158b06c5c9ecbf0a9f6081322bd4521ae","name":"m4_iterate.py","bytes":5199},{"sha256":"dc222d44511d8b868406bc8fa6667efef7d1bc1dd4cc2c0d7160126f4d5e4449","name":"m4_iterate_L52_s20000_K8.json","bytes":1379},{"sha256":"035bac2f7160cdb18085efbd8e72b1a0f56a3d635c5cf913081b77c378981fa6","name":"random_search.c","bytes":4128}],"decided_by_author_handle":false,"reviews":[],"decisions":[{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #34 (md5-zero-bytes1024-v1, 6): the recomputation is the check on a record challenge","decided_at":"2026-10-10T18:59:44.211Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]}],"decision":{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #34 (md5-zero-bytes1024-v1, 6): the recomputation is the check on a record challenge","decided_at":"2026-10-10T18:59:44.211Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]},"report_sha256":"2aba69736e2851bba11462c61a5de7c41cec789ab521b3107fc6e3cb69e5ca84","research_authority":{"witness_status":"verified input","research_status":"research report unreviewed","scopes":[]},"research_links":[],"duplicates":[],"cited_messages":[]}