{"id":2793,"job_id":5884,"problem_id":6,"lane_id":35,"type":"measure","user_id":76,"model":"auto","provider":"unknown","report_md":"# Smallest collision: fastcoll baseline + padding-absorption filter (254 bytes)\n\nPlatform prior best 248 (submission #21). Published reference 128 (Stevens; published answers refused). This run’s verified own candidates: **254** (submission #36) and **256** (submission #37). Personal-best candidate is 254; does not beat 248.\n\n## Hypothesis\n\nReturn 2646: a two-block fastcoll pair with block-2 byte 127 = `0x80` truncates to a full collision of 127+127 = 254 bytes (padding absorption). **H:** on this Linux aarch64 build of HashClash `md5fastcoll`, the waiting time for that byte filter is consistent with ~Uniform byte / rate ≈ 1/256, and truncation preserves the collision.\n\n## Experiment\n\n1. Built a boost-free driver around HashClash `src/md5fastcoll` (Stevens).\n2. Unfiltered run → 128+128 collision (baseline).\n3. Seeded loop from `0x58842000`: generate pairs until `msg[127]==0x80`, truncate both to 127 bytes, verify MD5 equality.\n\n## Results\n\n| Item | Value |\n|---|---|\n| Trials to first byte127=`0x80` | **281** |\n| Wall time | **510.6 s** (~1.8 s/trial) |\n| Empirical rate | 1/281 ≈ 0.00356 (one hit; compatible with 1/256) |\n| Truncation check | MD5(a[:127]) = MD5(b[:127]) = `2268e1a315d8b0fd54de14bdbfa5e41b` |\n| Submissions | #36 total 254; #37 total 256 |\n\nNo attempt at the m15=`0x00000080` solve (248-byte route of return 2694); filter-only measurement.\n\n## What this shows\n\nPadding absorption works on this toolchain: the Wang/Stevens two-block differential leaves block-2 `m15` free enough that a one-byte filter yields a shorter full collision without retuning tunnels. Cost ≈ hundreds of fastcoll runs (~minutes on 1 core here), matching 2646’s “about 1 in 256” engineering picture. Beating 248 still needs the stronger m15 constraint (2694), not more plain filtering.\n\n## Next run\n\nPort 2694’s Q16/m15 solve into this boost-free driver and measure redraws-to-248 vs the 2^32 naive filter, on the same machine.\n\n## OUTCOMES.md entry (proposed)\n\n| Track | Method | Budget and hardware | Best reached | Note |\n| --- | --- | --- | --- | --- |\n| Smallest collision | HashClash md5fastcoll + byte127=`0x80` truncate | 281 runs, 511 s, Linux aarch64 2-core | 254 (sub #36); 256 baseline (#37) | Reproduces 2646 filter; cites Stevens |\n","patch":null,"cpu_hours":0.15,"hashes":{"filter_results.json":"f1ab441d1714f8dc59011a7db32f1bbe76ca6829e25f439362dcc5f7b9c7c0da"},"author_rung":"measured","status":"accepted","final_rung":"verified","created_at":"2026-10-10T19:18:23.293Z","repo_url":null,"commit":null,"cites":{"files":["f5b70fdede18e82d1914a7e03397a2806ebfabf0d11784d5884262f8aa2b4b70","6f3784e7db0387eb8a3aefa5c32d55d5a6ac7f54267c69f64de49e12f8ccba8d","03b64ddfcaaaadb71c169950b9f2f7b0244be8aca703f961c29c7b7e9ed8208e","f1ab441d1714f8dc59011a7db32f1bbe76ca6829e25f439362dcc5f7b9c7c0da","d8961b9c65d0bd3dff35dab4887af974cfdad677ed87f3fbc4d0d1d6d590da80","79329f50172cd5e20a621039137d50ea1ace5c7d823dc189dc90eb5858ade70d"],"handles":[],"returns":[2646,2694,2700],"messages":[]},"tokens":{"log":"summary","input":0,"models":{},"output":0,"source":"none","entries":0,"cache_read":0,"cache_write":0,"observed_models":[]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"# Recipe: reproduce submission #36 (254 bytes)\n\n## Build\n\n```bash\n# from uploaded fastcoll_build sources (HashClash md5fastcoll + driver.cpp/helpers.cpp)\ng++ -O3 -c md5.cpp block0.cpp block1.cpp block1wang.cpp \\\n  block1stevens00.cpp block1stevens01.cpp block1stevens10.cpp block1stevens11.cpp \\\n  helpers.cpp driver.cpp\ng++ -O3 -o fastcoll *.o\n```\n\n## Reproduce the pair\n\n```bash\n./fastcoll 0x58842118   # seed = 0x58842000 + 280\n# msg1.bin / msg2.bin are 128 bytes with byte127 == 0x80\npython3 - <<'PY'\nfrom pathlib import Path\nimport hashlib\na=Path('msg1.bin').read_bytes()[:127]\nb=Path('msg2.bin').read_bytes()[:127]\nassert a!=b and hashlib.md5(a).hexdigest()==hashlib.md5(b).hexdigest()\nprint(a.hex()); print(b.hex()); print(hashlib.md5(a).hexdigest())\nPY\n```\n\nExpected digest: `2268e1a315d8b0fd54de14bdbfa5e41b`. Runtime: order 1–few seconds for that seed alone; the discovery search was 281 sequential seeds (~511 s).","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":"2026-10-10T19:18:23.293Z","effort":null,"also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":null,"department_id":"dept_fa6dbf79354b8806abb61eec","run_id":"run_a7419dd35088e539169f2abb","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"research_evidence":null,"transcript_mode":"summary","known_work":null,"work_disposition":null,"handle":"aasper03","job_brief":"Study how MD5 collisions are built (differential paths, message modification, the single-block attacks of Xie and Feng and Stevens) and what limits their length, and use it to find a shorter full collision. Running fastcoll gives 128 + 128 bytes from known techniques; it is the baseline to measure against. Ideas to test: where the single-block attacks spend their work, whether a shorter second member or a shared prefix can change the bound, what a 64 + 64 search costs at your budget. Start from the algorithm, not the search. Read research/OUTCOMES.md (what was tried, with what result) and research/QUESTIONS.md, then state one hypothesis about MD5's structure that would make this track cheaper than generic search, and why you expect it. Test it with the smallest experiment that could refute it, against a measured baseline on the same machine. Submit the best candidates the experiment produced. The report is a finding: the hypothesis, the experiment, what it showed about MD5 (positive or negative, with numbers), and what the next run should try. End the report with an entry for research/OUTCOMES.md (track, method, budget and hardware, best reached, what it shows). If the run used only a known tool or plain search, report it as a baseline measurement.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":2800,"handle":"danieljmt","status":"recorded"},{"id":2804,"handle":"Benjaminsen","status":"recorded"},{"id":2808,"handle":"aasper03","status":"accepted"}],"route_dependents":[],"research_url":null,"transcript_url":"/projects/md5/return/2793/transcript","files":[{"sha256":"f5b70fdede18e82d1914a7e03397a2806ebfabf0d11784d5884262f8aa2b4b70","name":"report.md","bytes":2271},{"sha256":"6f3784e7db0387eb8a3aefa5c32d55d5a6ac7f54267c69f64de49e12f8ccba8d","name":"recipe.md","bytes":927},{"sha256":"03b64ddfcaaaadb71c169950b9f2f7b0244be8aca703f961c29c7b7e9ed8208e","name":"transcript_summary.md","bytes":884},{"sha256":"f1ab441d1714f8dc59011a7db32f1bbe76ca6829e25f439362dcc5f7b9c7c0da","name":"filter_results.json","bytes":1458},{"sha256":"d8961b9c65d0bd3dff35dab4887af974cfdad677ed87f3fbc4d0d1d6d590da80","name":"driver.cpp","bytes":1057},{"sha256":"79329f50172cd5e20a621039137d50ea1ace5c7d823dc189dc90eb5858ade70d","name":"helpers.cpp","bytes":1250}],"decided_by_author_handle":false,"reviews":[],"decisions":[{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #36 (md5-collision-totalbytes1024-v1, 254): the recomputation is the check on a record challenge","decided_at":"2026-10-10T19:18:23.293Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]}],"decision":{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #36 (md5-collision-totalbytes1024-v1, 254): the recomputation is the check on a record challenge","decided_at":"2026-10-10T19:18:23.293Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]},"report_sha256":"f5b70fdede18e82d1914a7e03397a2806ebfabf0d11784d5884262f8aa2b4b70","research_authority":{"witness_status":"verified input","research_status":"research report unreviewed","scopes":[]},"research_links":[],"duplicates":[],"cited_messages":[]}