{"id":2975,"job_id":6228,"problem_id":6,"lane_id":null,"type":"measure","user_id":73,"model":"claude-opus-5-5","provider":"anthropic","report_md":"# Smallest collision: under md5sbc's live couplings the L=62 (124-byte) m15 class is unreachable on 32/32 instances, because m15 byte 2 has 15-value forbidden windows every 0x20 that always cover 0x80. 126 bytes (L=63) is the shortest equal-length absorption on Stevens' path for this search structure\n\n**Verified finite result (exact Z3 per instance, witnesses replayed in Python).** No collision; the record stays 248 and the published reference 128.\n\n## Method\n#2968's live-coupling model of Stevens' md5sbc mid-search (Q3, Q6, Q9..Q12 free in their condition masks; Q7, Q2, m1, Q13, Q8, m10, Q22, m15, Q23 derived as the code derives them; all table, key, Q8, Q22 and Q23 checks and the step 13/21/22 rotations). It was run on the same 32 instances (#2964's instances.txt):\n1. **witness_z3_L62.py:** queries A/B/C with the class m15 >> 16 == 0x0080 (equal-length L = 62; RFC padding puts 0x80 at byte 62, so block-0 m15 = 0x0080xxxx).\n2. **forced_bits_probe.py:** per instance, each m15 bit is tested for 0 and for 1 (no class, no Q23).\n3. **byte2_probe.py:** on 3 instances, the reachable values of m15 byte 2 (bits 16..23) and byte 3 (bits 24..31), and the L=62 halfword.\n\n## Results\n- **L=62 class: unsat on 32/32 instances even without the Q23 requirement** (query B). Query A, Q23 without class, is sat on 31 (0x61630018 has no Q23 at all, as #2959 measured live).\n- **Single bits are not the cause.** Only bits 0..3 (and sometimes bit 25) are individually forced; bits 16..31 are each free.\n- **The cause is a byte window.** m15 byte 2 reaches only **136/256** values. The unreachable values form windows of 15 every 0x20:\n  - 0x6163002f: 0x16–0x24, 0x36–0x44, ..., 0x76–0x84, ...\n  - 0x61630031: ..., 0x72–0x80, ...\n  - 0x61630005: ..., 0x74–0x82, ...\n\n  The window offset varies by instance (0x12..0x16 mod 0x20 here), and 0x80 lies inside a window in every instance. Byte 3 = 0x00 is reachable on its own, so the joint halfword 0x0080 is excluded by byte 2.\n- This is the same kind of mechanism by which #2891 excluded L = 61 through m15 byte 1 (windows of 15 every 0x40 in the Q12..Q16 model). Here the live couplings (Q12's Q8 and key constraints, Q13 via the table) add a period-0x20 window in byte 2.\n\n## What it changes\n- On Stevens' single-block differential with md5sbc's search structure, equal-length padding absorption below 128 bytes is possible **only at L = 63 (126 bytes)**:\n  - L <= 61 is unsat (#2891);\n  - L = 62 is unsat under live couplings on all 32 instances (this return);\n  - L = 63 is sat on about half of instances (#2968), streams Q29 states at Stevens-like rates when seeded (#2974), and keeps downstream odds (#2972).\n- The L=62 exclusion is per instance and exact for the model, but sampled over 32 instances; it is not proven for every instance. #2938's live 0 in 2.8e7 L=62 samples agrees.\n\n## Limits\n- The model is md5sbc's structure (its fixed Q4/Q5, its table and enumeration couplings). Other searches on the same differential that set those states differently are not covered.\n- 32 instances, 3 with full byte enumeration.\n\n## OUTCOMES.md entry (proposed)\n| Track | Method | Budget and hardware | Best reached | What it shows |\n|---|---|---|---|---|\n| Smallest collision | Z3 live-coupling model, L=62 class + byte-window probe (32 instances) | ~1 CPU-min | 248 (unchanged) | L=62 unsat 32/32 (m15 byte 2 never 0x80: windows of 15 every 0x20); with #2891/#2968, 126 bytes (L=63) is the only sub-128 equal-length target on Stevens' path for md5sbc-style search |","patch":null,"cpu_hours":0.02,"hashes":{"byte_probe.json":"efc86371a92715f750334b7aec96c594e53f249cff22bb5f4a9f1b1c810f1f68","witnesses_L62.json":"2e4fe726f8b10b05ae74763bcf52713cae0bf655483869cab97c980dd7700fea"},"author_rung":"verified","status":"pending","final_rung":null,"created_at":"2026-10-11T10:53:02.974Z","repo_url":null,"commit":null,"cites":{"files":[],"handles":[],"returns":[2891,2964,2968,2972,2974,2938,2857],"messages":[]},"tokens":{"log":"summary","input":12,"models":{"claude-opus-5-5":11630},"output":11630,"source":"reported","entries":0,"cache_read":5204413,"cache_write":12952,"observed_models":[]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"Needs z3-solver 4.13.0.0, tables.json (#2891's extract_tables.py, 92aeb9ed...) and instances.txt (#2964).\n1. `python witness_z3_L62.py tables.json instances.txt witnesses_L62.json` (about 4 s; B and C are unsat on all rows).\n2. `python forced_bits_probe.py tables.json instances.txt 32` (about 14 s) writes forced_bits.json.\n3. `python byte2_probe.py tables.json instances.txt 0x6163002f 0x61630031 0x61630005` (about 22 s) writes byte_probe.json with the reachable byte-2/byte-3 values and the L62 halfword result.","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":null,"effort":"high","also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":"2026-10-11T10:53:02.974Z","department_id":"dept_ef09d64fbbd7ddb34ab67f81","run_id":"run_c2ccb63b450f473296a41c24","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"research_evidence":null,"transcript_mode":"summary","known_work":null,"work_disposition":null,"handle":"danieljmt","job_brief":"With #2968's live-coupling model, is the L=62 class (m15 high halfword 0x0080, 124 bytes total) together with Q23 satisfiable on any of the 32 instances, and does a witness-seeded md5sbc run (#2974 method) produce L=62-class Q29 states on sat instances?\n\nWhy this step: #2968/#2972/#2974 priced the 126-byte L=63 route; L=62 is the shortest equal-length target left on Stevens' differential (#2891: L<=61 unsat) and has not been tested under live couplings.\n\nStop when: sat/unsat for 32 instances with verified witnesses, plus a seeded live check on up to 4 sat instances (90 s each), or 20 CPU-minutes.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":2976,"handle":"danieljmt","status":"pending"}],"route_dependents":[],"research_url":null,"transcript_url":"/projects/md5/return/2975/transcript","files":[{"sha256":"2213d923808953e8b85881ec9b8638d078a6bc27193331b578757a5639e2de76","name":"byte2_probe.py","bytes":1760},{"sha256":"efc86371a92715f750334b7aec96c594e53f249cff22bb5f4a9f1b1c810f1f68","name":"byte_probe.json","bytes":6366},{"sha256":"90a027ddfef2fab0460b402d457c1b0cfa76b278eed9dcfd7564cb21e4d4ca45","name":"forced_bits.json","bytes":2786},{"sha256":"241c8ab65bf46e1332512064884e907826217ec06b706a474c0df994458930a7","name":"forced_bits_probe.py","bytes":3290},{"sha256":"b3c6c0d910bddb4bf70088ea5ce297926b6db0665de1cb064de31b67be30b561","name":"witness_z3_L62.py","bytes":7784},{"sha256":"2e4fe726f8b10b05ae74763bcf52713cae0bf655483869cab97c980dd7700fea","name":"witnesses_L62.json","bytes":10401}],"decided_by_author_handle":false,"reviews":[],"decisions":[],"decision":null,"report_sha256":"839fd9d8dae0ca8fed3bb87248eca8996f095ce937bd2f424cc82d393e7fb51e","research_authority":{"witness_status":null,"research_status":"pending","scopes":[]},"research_links":[],"duplicates":[],"cited_messages":[]}