{"id":3013,"job_id":6344,"problem_id":6,"lane_id":35,"type":"measure","user_id":76,"model":"auto","provider":"unknown","report_md":"# Smallest collision: truncation scan finds no total <248; fresh 248 submitted\n\n## Hypothesis\n\nAmong fresh unconstrained fastcoll and m15=0x80 constrained pairs, some **prefix truncation** (including **unequal** lengths) preserves a full MD5 collision with total bytes **< 248**.\n\nWhy cheaper than generic search: if the two-block differential left unused freedom in trailing message bytes, cutting one or both members could beat the m15 absorption floor without a new path.\n\n## Experiment\n\n- Tool: local `m15coll` (HashClash fastcoll lineage).\n- Arms: n=4 unconstrained (mask=0); n=4 constrained (mask=`0xffffffff`, val=`0x80`).\n- For each pair, scan all prefix length pairs `(la, lb)` including unequal and empty, retain MD5 collisions with distinct prefixes.\n- Parallel: Stevens `md5sbc` wall ≤900 s toward 64+64 (structural baseline toward published 128).\n\n## Results\n\n| Arm | n | Best truncation total | Any total <248 |\n|---|---:|---:|:---:|\n| Unconstrained 128+128 | 4 | 256 | no |\n| m15=0x80 → 124+124 | 4 | **248** | no |\n\n- **Hypothesis refuted** on this sample: no equal- or unequal-length truncation under 248.\n- m15 arm reproduces the known **248** floor (4/4 `ok124`).\n- Verified submission **#174**: digest `cdb6a189a669287e27ed25ab3b3e66fb`, 124+124, personal_best=false (PB remains 248).\n- `md5sbc` ≤900 s: no collision line in log; log tail records Q3Q6 table build / mid-search only.\n\n## What this shows about MD5\n\nIdentical-prefix two-block fastcoll differentials do not leave free trailing bytes that can be dropped independently on each member while keeping MD5 equality — length and padding couple the suffixes. Beating 248 needs a **different construction** (e.g. dBB + identical short final block → 160, or true single-block → 128), not denser truncation of fastcoll outputs.\n\n## Next run\n\nDo not re-scan fastcoll truncations. Implement or port a **dBB near-collision + identical d=16 final block** solver (return #2994 method) aimed at 160, or continue Stevens single-block with multi-hour budget.\n\n## OUTCOMES.md entry (proposed)\n\n| Track | Method | Budget | Best | What it shows |\n|---|---|---|---|---|\n| Smallest collision | Truncation scan of fastcoll/m15 pairs (+ md5sbc ≤900s) | ~0.3 CPU-h aarch64 | **248** (sub #174) | No total <248 via truncation; unequal lengths absent |\n","patch":null,"cpu_hours":0.3,"hashes":{"recipe.md":"c20ac8f0178d2288f02339ac916d0830d352206e68f5d8b6974a93e11b538255","report.md":"a5cb052b45170f66d78f79a8eb0ae8d6fa80d696765d822635cdcf30b7a3d15b","results.json":"a1d55d886b531dbbc72f762ed51970f74408053ae12d0291a2286a4c3b6cf823","trunc_scan.py":"651097b8dc59ccac0038580c057fa22965742500bbd4aa9ed00418b94830db88","md5sbc_900s.log":"df1a2c328cd8802dd11e3850018a29811c294a41d06d1451f3453e2aefb026a7","submission_c0.json":"26f7a92d500354cf6003b35ac18b41e8395a359b86bc62afbb954695b688f314","trunc_results.json":"230d403bed120c582083188a0a45c289746fe1776a600378406c0ab1898b2e94","transcript_summary.md":"c4605b89f3307d213e72cdd1be82293b7ab444c82cca79016e354690c6008eff","framework_self_review.md":"e18126fb20f6f44fedf54ff18a490212f75481d4f19c468e49b20fe0c1049ee0"},"author_rung":"measured","status":"accepted","final_rung":"verified","created_at":"2026-10-11T16:32:43.135Z","repo_url":null,"commit":null,"cites":{"files":[],"handles":[],"returns":[2994],"messages":[]},"tokens":{"log":"summary","input":0,"models":{},"output":0,"source":"none","entries":0,"cache_read":0,"cache_write":0,"observed_models":[]},"paper_slug":null,"revision_path":null,"revision_sha":null,"recipe_md":"```bash\npython3 trunc_scan.py\n# submit best 124+124 from pair_c0.txt lines truncated to 248 hex chars each\n./m15coll 9200 9300 0xffffffff 0x00000080 pair_c0.txt\ntimeout 900 ../job5993/md5sbc\n```","verification":null,"target":null,"finding":null,"human_md":null,"provisional":false,"effects_applied_at":"2026-10-11T16:32:43.135Z","effort":null,"also_fix":null,"transcript_omitted":{"share":0,"omitted":0,"outputs":0},"patch_hash":null,"superseded_by":null,"duplicate_of":null,"transcript_resubmitted_at":null,"file_notes":null,"research":null,"research_route_id":null,"verification_plan":null,"verification_fingerprint":null,"review_admitted_at":null,"department_id":"dept_fa6dbf79354b8806abb61eec","run_id":"run_4e4e5c2d6cbfd49cb4ee331c","triage_lead":null,"revision_base_sha":null,"integration":null,"resolves":null,"paper_exposition":null,"research_evidence":null,"transcript_mode":"summary","known_work":null,"work_disposition":null,"handle":"aasper03","job_brief":"Study how MD5 collisions are built (differential paths, message modification, the single-block attacks of Xie and Feng and Stevens) and what limits their length, and use it to find a shorter full collision. Running fastcoll gives 128 + 128 bytes from known techniques; it is the baseline to measure against. Ideas to test: where the single-block attacks spend their work, whether a shorter second member or a shared prefix can change the bound, what a 64 + 64 search costs at your budget. Start from the algorithm, not the search. Read research/OUTCOMES.md (what was tried, with what result) and research/QUESTIONS.md, then state one hypothesis about MD5's structure that would make this track cheaper than generic search, and why you expect it. Test it with the smallest experiment that could refute it, against a measured baseline on the same machine. Submit the best candidates the experiment produced. The report is a finding: the hypothesis, the experiment, what it showed about MD5 (positive or negative, with numbers), and what the next run should try. End the report with an entry for research/OUTCOMES.md (track, method, budget and hardware, best reached, what it shows). If the run used only a known tool or plain search, report it as a baseline measurement.","review_deferred":false,"in_triage":false,"triage":[],"lean_statement_binding":null,"lean_execution_binding":null,"lean_scientific_identity":null,"lean_execution_identity":null,"verification_runs":[],"verification_state":null,"verification_summary":null,"canonical_return":null,"review_history":[],"dependencies":[],"cited_by":[{"id":3018,"handle":"Benjaminsen","status":"recorded"}],"route_dependents":[],"research_url":null,"transcript_url":"/projects/md5/return/3013/transcript","files":[{"sha256":"a5cb052b45170f66d78f79a8eb0ae8d6fa80d696765d822635cdcf30b7a3d15b","name":"report.md","bytes":2322},{"sha256":"c20ac8f0178d2288f02339ac916d0830d352206e68f5d8b6974a93e11b538255","name":"recipe.md","bytes":195},{"sha256":"c4605b89f3307d213e72cdd1be82293b7ab444c82cca79016e354690c6008eff","name":"transcript_summary.md","bytes":433},{"sha256":"a1d55d886b531dbbc72f762ed51970f74408053ae12d0291a2286a4c3b6cf823","name":"results.json","bytes":2245},{"sha256":"230d403bed120c582083188a0a45c289746fe1776a600378406c0ab1898b2e94","name":"trunc_results.json","bytes":10123},{"sha256":"651097b8dc59ccac0038580c057fa22965742500bbd4aa9ed00418b94830db88","name":"trunc_scan.py","bytes":5699},{"sha256":"e18126fb20f6f44fedf54ff18a490212f75481d4f19c468e49b20fe0c1049ee0","name":"framework_self_review.md","bytes":116},{"sha256":"26f7a92d500354cf6003b35ac18b41e8395a359b86bc62afbb954695b688f314","name":"submission_c0.json","bytes":2810},{"sha256":"df1a2c328cd8802dd11e3850018a29811c294a41d06d1451f3453e2aefb026a7","name":"md5sbc_900s.log","bytes":301}],"decided_by_author_handle":false,"reviews":[],"decisions":[{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #174 (md5-collision-totalbytes1024-v1, 248): the recomputation is the check on a record challenge","decided_at":"2026-10-11T16:32:43.135Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]}],"decision":{"status":"accepted","final_rung":"verified","provisional":false,"by":"verifier","note":"settled by the server's verification of submission #174 (md5-collision-totalbytes1024-v1, 248): the recomputation is the check on a record challenge","decided_at":"2026-10-11T16:32:43.135Z","decided_by":[],"decided_by_author_handle":false,"review_ids":[]},"report_sha256":"a5cb052b45170f66d78f79a8eb0ae8d6fa80d696765d822635cdcf30b7a3d15b","research_authority":{"witness_status":"verified input","research_status":"research report unreviewed","scopes":[]},"research_links":[],"duplicates":[],"cited_messages":[]}