Research · Papers · The SHA-256 record and exact synthesis · MF-062

Exact fibre cardinality of the two-round SHA-256 edge-relaxed relation

p0 = b xor (U-P), p1 = p0 xor ((a xor b) and (a xor b xor c xor U)), P = T1 + Sigma0(a) mod 2^32 yields b_(t+2)=U and fibre cardinality 2^32

Published 2026-08-29

For everyone

Plain summary

Fix the input to a two-round SHA-256 step and pick any 32-bit word U. Even after enforcing the boundary equations of the two-round relation, exactly 2^32 internal variable assignments remain compatible with that choice. Because the projected output fibre holds this full set of assignments, one 32-bit intermediate value stays completely unconstrained behind the visible output. The algebraic parameterization generating these assignments was verified across 20,000 random samples and crosschecked in C++ across 100,000 samples with zero failures. The register records no prior art for this result.

Result

For every fixed two-round SHA-256 input and every word U, the parameterization

p0 = b xor (U-P)

and

p1 = p0 xor ((a xor b) and (a xor b xor c xor U)),

where

P = T1 + Sigma0(a) mod 2^32,

satisfies both the first addition and the edge row. The standard SHA shift exposes b_(t+2)=U. Consequently, the projected output fibre has cardinality exactly 2^32, retaining a full 32-bit free intermediate for every U.

This statement is exact for the fixed input under the registered edge-relaxed relation, providing both the assignment count and its closed algebraic realization.

Setting and definitions

The relation operates over 32-bit words a, b, c, p0, p1, and U, with terms T1 and Sigma0(a). Bitwise operations are xor and and; arithmetic addition and subtraction are evaluated modulo 2^32.

The edge-relaxed relation enforces the first addition and the edge row within the parameterized form, followed by the ordinary SHA shift. Projection deletes hidden coordinates absent from the output view. The fibre of a fixed projected output is the set of hidden assignments compatible with it; fibre cardinality measures this set.

Method

The result was derived by explicit algebraic parameterization: the closed forms for p0 and p1 with P = T1 + Sigma0(a) mod 2^32 satisfy the first addition and edge row, while the standard shift yields b_(t+2)=U.

Two replay suites verified the parameterization with zero failures: a 20,000-sample run and an independent 100,000-sample C++ audit. Verification receipts and the corresponding certificate are available in this paper's downloadable evidence pack.

Discussion

MF-062 is a structural theorem strictly scoped to a fixed two-round SHA-256 input, an arbitrary word U, and the edge-relaxed projection. It establishes the exact count of compatible hidden assignments and demonstrates the survival of a full 32-bit intermediate degree of freedom. It asserts no bounds for multi-round extensions, computational complexity, or alternate closure mechanisms.

Register history notes that package catalog ID MF-059 collided with Lens A and was remapped to MF-062. No prior art is recorded. Extending these properties to broader constructions or concrete solver reductions requires separate registration.

For everyone — the takeaway

What this means

When you fix the boundary equations across two rounds of SHA-256, picking the next output word does not lock down the internal state. Exactly 2^32 internal configurations still match that single output. Even when an edge relation appears tightly constrained from the outside, an entire 32-bit word of internal freedom survives intact. Both empirical verification suites confirmed this without error. The result applies strictly to this two-round boundary relation, with no broader claims or prior art recorded in the register.

Register references

Entry: MF-062.

Receipts: CONT lens_r2b_majgauge_verification_receipt.json; CONT lens_r2b_independent_audit.json; package certificates/maj_gauge_maximal_defect.json.

Prior art: the register does not record this.

Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.

Evidence pack

Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 3 of 3 receipt files bundled (7 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.

Download evidence.zip

Changelog

Last reviewed 2026-08-29

  • 2026-08-29Published on this site.

Related in this programme