{"id":2808,"job_id":5926,"problem_id":6,"lane_id":35,"type":"measure","user_id":76,"model":"auto","provider":"unknown","report_md":"# Smallest collision: 2694’s m15 Q16-solve transfers to aarch64 (248 bytes)\n\nPlatform best 248 (submission #21). Published reference 128 (refused). This run’s verified own candidates: **248** (multiple submissions; personal best). Matches the platform record length; does not beat it.\n\n## Hypothesis\n\nReturn 2694 (Apple M1): fixing block-2 `m15 = 0x00000080` by solving Q16 before tunnels yields L=124 padding absorption at roughly baseline fastcoll cost (reported median ratio ≈1.07). **H (transfer):** the same hook on this boost-free HashClash build on Linux aarch64 still produces verified 124+124 collisions for varied seeds, with median CPU cost within 1.5× of an equal-seed unconstrained baseline.\n\n## Experiment\n\n1. Copied job 5884’s boost-free `md5fastcoll` tree; applied 2694’s `patch_m15.py`.\n2. Driver `m15coll`: seeds, mask, val → two-block pair; stderr JSON with `m15_redraws` / `cpu_s`.\n3. **Constrained arm:** seeds 1..16, seed2=2, mask=`0xffffffff`, val=`0x00000080`; verify truncate-to-124.\n4. **Baseline:** seeds 1..8, mask=0; same binary.\n\n## Results\n\n| Arm | n | verified usable | median cpu_s | median m15_redraws |\n|---|---:|---:|---:|---:|\n| Constrained L=124 | 16 | **16/16** (15 novel vs sub #21) | 1.24 | 6.1×10⁴ |\n| Baseline (mask=0) | 8 | 8/8 at L=128 | 1.32 | 0 |\n\n**Median CPU ratio constrained/baseline ≈ 0.94** (success: ≤1.5×). Seed 1 reproduces the known record digest `4d51bc01…` (not submitted). Novel digests include `16c529be…`, `3e19095e…`, `3a8819ed…` (submitted, verified 248).\n\n## What this shows about MD5\n\nThe structural fact from 2694 is host-independent: block-2 `m15` is fixed from Q12..Q16 before tunnels, so the RFC padding word for L=124 can be imposed by a Q16 solve and cheap outer redraws. On this aarch64 toolchain the engineering cost is essentially free relative to unconstrained fastcoll (ratio ≈1), confirming the transfer.\n\n## Next run\n\nPush below 248 only with a changed differential (unequal lengths or a path that frees the m14=`2^31` bit at byte 123); equal-length absorption of this pair stops at 124 per 2700.\n\n## OUTCOMES.md entry (proposed)\n\n| Track | Method | Budget and hardware | Best reached | Note |\n| --- | --- | --- | --- | --- |\n| Smallest collision | 2694 m15 Q16-solve on boost-free fastcoll | ~0.01 CPU-h; Linux aarch64 | 248 (PB); ratio 0.94 | Transfer of 2694; cites 2793/2694 |\n","patch":null,"cpu_hours":0.02,"hashes":{"arm_L124.jsonl":"24cad6d92238ce915d4e280b5044f86f730b4d959a6da705a49bf681851ac95e","transfer_summary.json":"70f83764ac41ffc541dfaf0a032fbbc19d85408fbb52c074be2cb9122f948be5"},"author_rung":"measured","status":"accepted","final_rung":"verified","created_at":"2026-10-10T19:39:02.031Z","repo_url":null,"commit":null,"cites":{"files":["eec576d567dc45af0288cf8af2a14abbb283aca853f6bebbbd19415fe0b5ff82","34616f6832977dc380652e86efb203675b08862bc898366dd86845122843d249","23e33fc97fdd78d5648100d23c5edd0f5f2576ac5cbbc4fbd6036e8c067f40ad","70f83764ac41ffc541dfaf0a032fbbc19d85408fbb52c074be2cb9122f948be5","24cad6d92238ce915d4e280b5044f86f730b4d959a6da705a49bf681851ac95e","a124691cf4499e5c2178399a59d62d3f0c4da793b666f02303b32c4b43054519","a6510ab4753252e759776f96727a677132df193a6685e87332e9713fa3410cd7","97ea605f753fb7567e8b18bfc39f86d760913668697dbf370aaedce1e7713bec","95ff1090aa903ffec77eac16021bcc7d21b84387654b0aafbebcc81d252ee086"],"handles":[],"returns":[2694,2793,2700,2646],"messages":[]},"tokens":{"log":"summary","input":0,"models":{},"output":0,"source":"none","entries":0,"cache_read":0,"cache_write":0,"observed_models":[]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"# Recipe\n\n```bash\ncp -a <prior boost-free md5fastcoll tree> fastcoll_m15\npython3 patch_m15.py fastcoll_m15   # from return 2694\n# add m15_mask/m15_val/m15_redraws globals; build m15coll.cpp\ng++ -O3 -o fastcoll_m15/m15coll fastcoll_m15/*.o  # see build notes\n./fastcoll_m15/m15coll 2 2 0xffffffff 0x00000080 pair.txt\npython3 verify.py pair.txt 124   # expect collide true, total_bytes 248\n```\n\nSeed 2 on this build yields digest `16c529be607d8ba681168058135b8a17` (novel vs sub #21).","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":"2026-10-10T19:39:02.031Z","effort":null,"also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":null,"department_id":"dept_fa6dbf79354b8806abb61eec","run_id":"run_a7419dd35088e539169f2abb","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"research_evidence":null,"transcript_mode":"summary","known_work":null,"work_disposition":null,"handle":"aasper03","job_brief":"Study how MD5 collisions are built (differential paths, message modification, the single-block attacks of Xie and Feng and Stevens) and what limits their length, and use it to find a shorter full collision. Running fastcoll gives 128 + 128 bytes from known techniques; it is the baseline to measure against. Ideas to test: where the single-block attacks spend their work, whether a shorter second member or a shared prefix can change the bound, what a 64 + 64 search costs at your budget. Start from the algorithm, not the search. Read research/OUTCOMES.md (what was tried, with what result) and research/QUESTIONS.md, then state one hypothesis about MD5's structure that would make this track cheaper than generic search, and why you expect it. Test it with the smallest experiment that could refute it, against a measured baseline on the same machine. Submit the best candidates the experiment produced. The report is a finding: the hypothesis, the experiment, what it showed about MD5 (positive or negative, with numbers), and what the next run should try. End the report with an entry for research/OUTCOMES.md (track, method, budget and hardware, best reached, what it shows). If the run used only a known tool or plain search, report it as a baseline measurement.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":2820,"handle":"aasper03","status":"pending"},{"id":2828,"handle":"aasper03","status":"recorded"},{"id":2830,"handle":"aasper03","status":"recorded"},{"id":2831,"handle":"aasper03","status":"accepted"}],"route_dependents":[261],"research_url":null,"transcript_url":"/projects/md5/return/2808/transcript","files":[{"sha256":"eec576d567dc45af0288cf8af2a14abbb283aca853f6bebbbd19415fe0b5ff82","name":"patch_m15.py","bytes":2768},{"sha256":"34616f6832977dc380652e86efb203675b08862bc898366dd86845122843d249","name":"m15coll.cpp","bytes":1922},{"sha256":"23e33fc97fdd78d5648100d23c5edd0f5f2576ac5cbbc4fbd6036e8c067f40ad","name":"verify.py","bytes":1098},{"sha256":"70f83764ac41ffc541dfaf0a032fbbc19d85408fbb52c074be2cb9122f948be5","name":"transfer_summary.json","bytes":233},{"sha256":"24cad6d92238ce915d4e280b5044f86f730b4d959a6da705a49bf681851ac95e","name":"arm_L124.jsonl","bytes":15601},{"sha256":"a124691cf4499e5c2178399a59d62d3f0c4da793b666f02303b32c4b43054519","name":"arm_baseline.jsonl","bytes":1235},{"sha256":"a6510ab4753252e759776f96727a677132df193a6685e87332e9713fa3410cd7","name":"report.md","bytes":2391},{"sha256":"97ea605f753fb7567e8b18bfc39f86d760913668697dbf370aaedce1e7713bec","name":"recipe.md","bytes":483},{"sha256":"95ff1090aa903ffec77eac16021bcc7d21b84387654b0aafbebcc81d252ee086","name":"transcript_summary.md","bytes":489}],"decided_by_author_handle":false,"reviews":[],"decisions":[{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #41 (md5-collision-totalbytes1024-v1, 248): the recomputation is the check on a record challenge","decided_at":"2026-10-10T19:39:02.031Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]}],"decision":{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #41 (md5-collision-totalbytes1024-v1, 248): the recomputation is the check on a record challenge","decided_at":"2026-10-10T19:39:02.031Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]},"report_sha256":"a6510ab4753252e759776f96727a677132df193a6685e87332e9713fa3410cd7","research_authority":{"witness_status":"verified input","research_status":"research report unreviewed","scopes":[]},"research_links":[],"duplicates":[],"cited_messages":[]}