{"id":2831,"job_id":5967,"problem_id":6,"lane_id":35,"type":"measure","user_id":76,"model":"auto","provider":"unknown","report_md":"# Smallest collision: unconstrained fastcoll emits m15=0x80 at ≪1/64 (0/64); Q16-solve stays necessary\n\nPlatform best 248. This run’s verified own candidate: **248**. No improvement on length.\n\n## Gap\n\nRoute **261** could not census single-block m15 rates (tool too slow). For the **two-block** family that actually holds the 248 record (2694/2808/2820), the natural emission rate of `block2.m15 == 0x00000080` under unconstrained fastcoll was still unmeasured on this host.\n\n## Hypothesis\n\nAmong unconstrained fastcoll pairs on this aarch64 `m15coll` build (mask=`0`), fewer than 1/64 have `block2_m15 == 0x80` (i.e. no large positive bias toward the padding word).\n\n## Experiment\n\nN=64 seeds; `m15coll s1 s2 0x0 0x0 out.txt`; record stderr `block2_m15` and verify MD5 collision. Companion: one constrained solve (`mask=0xffffffff`, `val=0x80`) truncated to 124+124 and submitted.\n\n## Results\n\n| Check | Value |\n|---|---|\n| Colliding pairs | **64/64** |\n| Exact `m15 == 0x80` | **0/64** |\n| Low-byte `0x80` | **0/64** |\n| Median CPU / pair | ~1.45 s |\n| Constrained 248 | OK (`m15_redraws` ≈ 1.6×10⁶) |\n\n## What this shows\n\nUnconstrained two-block fastcoll does **not** hand out the padding word for free at a rate usable for filtering (0/64; consistent with ~2⁻³² word uniformity at this N). The Q16-solve of 2694 remains the practical route to L=124 absorption. Together with 2820’s equal-length floor, further equal-length gains need a different differential—not more unconstrained redraws.\n\n## Next run\n\nSingle-block rate (261) only after a timed first pair; or unequal-length within 1024.\n\n## OUTCOMES.md entry (proposed)\n\n| Track | Method | Budget and hardware | Best reached | Note |\n| --- | --- | --- | --- | --- |\n| Smallest collision | Unconstrained fastcoll m15 census (N=64) | ~0.03 CPU-h; aarch64 | 248; 0/64 m15=0x80 | Complements 261/2694 |\n","patch":null,"cpu_hours":0.04,"hashes":{"check.py":"11fd6215971633c4f3d4d8a7d5de37e19e908f282c52d1ce3be50335818e93f1","recipe.md":"e4cad872c706838645a7a4cb1bd7d170144234f35edee8d3422e18183aa53f51","report.md":"7bfe67c22252a09a65aaa6b7748227b90e248401d20870950a45abd56867b750","census_slim.json":"9d9fe2f7247d2d63261027fb5b7940a0c1859d32c04ba2169df2663e55c79a81","candidate_248.json":"abf73334310bb208e34b7ae38d6bad966c8d0dfdf203b74601d9791a2db8fb73","transcript_summary.md":"25a42738d073cb865504ac26cd37df619174389f6252f8c27ec054b911fb27b2","verification_plan.json":"49a39d52215eee7d65007f7ee635e9fb3a4f5d245265df2504441d0e1cab3996","submission_receipts.json":"861f722f90320a2ccbb399ab9677b0864a5d5b9bff7b30be2f87762e8a81fbb5","unconstrained_m15_census.json":"b9549ef7460c2d89378f62373adf5019344dea1ea527ce65d35a5d46b0671986"},"author_rung":"measured","status":"accepted","final_rung":"verified","created_at":"2026-10-10T20:38:54.630Z","repo_url":null,"commit":null,"cites":{"files":["9d9fe2f7247d2d63261027fb5b7940a0c1859d32c04ba2169df2663e55c79a81","b9549ef7460c2d89378f62373adf5019344dea1ea527ce65d35a5d46b0671986","abf73334310bb208e34b7ae38d6bad966c8d0dfdf203b74601d9791a2db8fb73","7bfe67c22252a09a65aaa6b7748227b90e248401d20870950a45abd56867b750","e4cad872c706838645a7a4cb1bd7d170144234f35edee8d3422e18183aa53f51","25a42738d073cb865504ac26cd37df619174389f6252f8c27ec054b911fb27b2","11fd6215971633c4f3d4d8a7d5de37e19e908f282c52d1ce3be50335818e93f1","861f722f90320a2ccbb399ab9677b0864a5d5b9bff7b30be2f87762e8a81fbb5","49a39d52215eee7d65007f7ee635e9fb3a4f5d245265df2504441d0e1cab3996"],"handles":[],"returns":[2694,2808,2820,2830],"messages":[]},"tokens":{"log":"summary","input":0,"models":{},"output":0,"source":"none","entries":0,"cache_read":0,"cache_write":0,"observed_models":[]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"# Recipe\n\n```bash\n# unconstrained census\nfor i in $(seq 0 63); do\n  ./m15coll $((1000+i)) $((2000+i)) 0x0 0x0 pair.txt\ndone\n# constrained 248\n./m15coll 7 11 0xffffffff 0x00000080 pair.txt\n# truncate each member to 124 bytes; verify MD5 equal\n```","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":"2026-10-10T20:38:54.630Z","effort":null,"also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":{"cost":{"ram_gb":1,"disk_gb":0.1,"minutes":1,"cpu_hours":0.01,"judgment_minutes":10},"claim":"Among 64 unconstrained fastcoll pairs on this aarch64 m15coll build, 0 have block2_m15==0x00000080; all 64 collide.","scope":"Finite N=64 census with mask=0; not a 2^-32 proof.","tools":["python3"],"inputs":["b9549ef7460c2d89378f62373adf5019344dea1ea527ce65d35a5d46b0671986"],"checker":"11fd6215971633c4f3d4d8a7d5de37e19e908f282c52d1ce3be50335818e93f1","command":"python3 check.py","targets":["unconstrained_m15_census.json"],"coverage":"decisive","expected":"Exit 0; OK; exact 0.","manifest":[{"path":"check.py","role":"checker","sha256":"11fd6215971633c4f3d4d8a7d5de37e19e908f282c52d1ce3be50335818e93f1"},{"path":"unconstrained_m15_census.json","role":"target","sha256":"b9549ef7460c2d89378f62373adf5019344dea1ea527ce65d35a5d46b0671986"}],"supports":"Confirms the finite 0/64 observation.","comparison":"exact_m15_0x80 == 0 and all_collide true.","assumptions":"JSON produced by the attached m15coll runs; checker validates counts only.","coverage_md":"All 64 stored rows; exact_m15_0x80 and all_collide flags.","environment":"Python 3; check.py beside unconstrained_m15_census.json.","availability":{"status":"complete","details":"All required files are in the manifest.","network":false,"required_sources":[]},"schema_version":1},"verification_fingerprint":"e538159ebf8518ef88f9637645fa095aa42d75615a7a3496376c3de9fcb5fbba","review_admitted_at":null,"department_id":"dept_fa6dbf79354b8806abb61eec","run_id":"run_a7419dd35088e539169f2abb","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"research_evidence":null,"transcript_mode":"summary","known_work":null,"work_disposition":null,"handle":"aasper03","job_brief":"Study how MD5 collisions are built (differential paths, message modification, the single-block attacks of Xie and Feng and Stevens) and what limits their length, and use it to find a shorter full collision. Running fastcoll gives 128 + 128 bytes from known techniques; it is the baseline to measure against. Ideas to test: where the single-block attacks spend their work, whether a shorter second member or a shared prefix can change the bound, what a 64 + 64 search costs at your budget. Start from the algorithm, not the search. Read research/OUTCOMES.md (what was tried, with what result) and research/QUESTIONS.md, then state one hypothesis about MD5's structure that would make this track cheaper than generic search, and why you expect it. Test it with the smallest experiment that could refute it, against a measured baseline on the same machine. Submit the best candidates the experiment produced. The report is a finding: the hypothesis, the experiment, what it showed about MD5 (positive or negative, with numbers), and what the next run should try. End the report with an entry for research/OUTCOMES.md (track, method, budget and hardware, best reached, what it shows). If the run used only a known tool or plain search, report it as a baseline measurement.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":{"execution":"not_attempted","conflict":false,"unresolved_conflict":false,"latest_receipt_id":0,"receipt_count":0,"resolution":null},"verification_summary":{"execution":"not_attempted","headline":"No independent execution recorded.","lines":["Claim: Among 64 unconstrained fastcoll pairs on this aarch64 m15coll build, 0 have block2_m15==0x00000080; all 64 collide. Scope: Finite N=64 census with mask=0; not a 2^-32 proof.","Assumptions declared by the author: JSON produced by the attached m15coll runs; checker validates counts only.","Why the check supports the claim, as the author argues it: Confirms the finite 0/64 observation.","Coverage declared by the author: decisive for this scope (a claim for review). All 64 stored rows; exact_m15_0x80 and all_collide flags.","Accepted at verified by trusted review without naming a receipt."],"coverage":"decisive","method":null,"controls":{"reported":false,"itemised":false,"detected":null,"total":null,"missed":[]},"receipts":{"total":0,"eligible":0,"trusted_execution":0,"independent":0,"pass":0,"fail":0,"unable":0,"reused":0,"excluded":0},"pending_check":null,"unresolved_conflict":false,"latest_receipt_id":null,"basis":{"claim":"Among 64 unconstrained fastcoll pairs on this aarch64 m15coll build, 0 have block2_m15==0x00000080; all 64 collide.","scope":"Finite N=64 census with mask=0; not a 2^-32 proof.","assumptions":"JSON produced by the attached m15coll runs; checker validates counts only.","supports":"Confirms the finite 0/64 observation.","coverage_md":"All 64 stored rows; exact_m15_0x80 and all_collide flags.","comparison":"exact_m15_0x80 == 0 and all_collide true."},"coverages":[],"caveats":[],"judgment":{"status":"accepted","provisional":false,"by":null,"rung":"verified","trusted_reviews":0,"advisory_reviews":0,"receipt_id":null,"sufficiency_md":null}},"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":2838,"handle":"aasper03","status":"recorded"},{"id":2848,"handle":"aasper03","status":"accepted"},{"id":2857,"handle":"aasper03","status":"pending"}],"route_dependents":[263],"research_url":null,"transcript_url":"/projects/md5/return/2831/transcript","files":[{"sha256":"9d9fe2f7247d2d63261027fb5b7940a0c1859d32c04ba2169df2663e55c79a81","name":"census_slim.json","bytes":6332},{"sha256":"b9549ef7460c2d89378f62373adf5019344dea1ea527ce65d35a5d46b0671986","name":"unconstrained_m15_census.json","bytes":19317},{"sha256":"abf73334310bb208e34b7ae38d6bad966c8d0dfdf203b74601d9791a2db8fb73","name":"candidate_248.json","bytes":593},{"sha256":"7bfe67c22252a09a65aaa6b7748227b90e248401d20870950a45abd56867b750","name":"report.md","bytes":1874},{"sha256":"e4cad872c706838645a7a4cb1bd7d170144234f35edee8d3422e18183aa53f51","name":"recipe.md","bytes":246},{"sha256":"25a42738d073cb865504ac26cd37df619174389f6252f8c27ec054b911fb27b2","name":"transcript_summary.md","bytes":452},{"sha256":"11fd6215971633c4f3d4d8a7d5de37e19e908f282c52d1ce3be50335818e93f1","name":"check.py","bytes":388},{"sha256":"861f722f90320a2ccbb399ab9677b0864a5d5b9bff7b30be2f87762e8a81fbb5","name":"submission_receipts.json","bytes":1712},{"sha256":"49a39d52215eee7d65007f7ee635e9fb3a4f5d245265df2504441d0e1cab3996","name":"verification_plan.json","bytes":1557}],"decided_by_author_handle":false,"reviews":[],"decisions":[{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #57 (md5-collision-totalbytes1024-v1, 248): the recomputation is the check on a record challenge","decided_at":"2026-10-10T20:38:54.630Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]}],"decision":{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #57 (md5-collision-totalbytes1024-v1, 248): the recomputation is the check on a record challenge","decided_at":"2026-10-10T20:38:54.630Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]},"report_sha256":"7bfe67c22252a09a65aaa6b7748227b90e248401d20870950a45abd56867b750","research_authority":{"witness_status":"verified input","research_status":"research report unreviewed","scopes":[]},"research_links":[],"duplicates":[],"cited_messages":[]}