Research · Papers · The SHA-256 record and exact synthesis · MF-063
Invertibility of odd rotation sums in F2[x]/((x+1)^{2^r})
In F2[x]/((x+1)^{2^r}), every XOR sum of an odd number of cyclic rotations is invertible (s(1)=1), so SHA-256 Sigma0 has matrix rank 32
Published 2026-08-29
For everyone
Plain summary
MF-063 proves that certain combinations of bit rotations are completely reversible when the word length is a power of two. A cyclic rotation shifts bits in a binary word around in a loop, and XOR combines bits without carries. XORing an odd number of these rotations always produces a transformation that can be inverted with no loss of information.
The entry applies this fact to a registered two-round SHA-256 relation under fixed boundary conditions. For the test input with W0=-K0, W1=-K1, p0=not U, and p1=0, the output simplifies to (Sigma0(U), U, 0, ffffffff, 0, 0, 0, 0). The function Sigma0 has a full rank of 32, meaning all 32 independent bit directions survive. Even when the visible coordinate b2=U is dropped from observation, a full 32-bit hidden family of valid solutions (a gauge) remains intact in coordinate a2. The register records no prior art for this result.
Result
For the legal input
state=(0,ffffffff,0,0,0,0,0,0),
with
W0=-K0, W1=-K1, p0=not U, and p1=0,
the edge-relaxed two-round output is exactly
(Sigma0(U), U, 0, ffffffff, 0, 0, 0, 0).
For binary word length 2^r, every XOR sum of an odd number of cyclic rotations is invertible in
F2[x]/((x+1)^{2^r})
because s(1)=1. Consequently, SHA-256 Sigma0 has matrix rank 32, with basis digest b39f6587…6dcee447. Projecting away b2=U leaves a full-rank gauge in a2.
Setting and definitions
Let the binary word length be 2^r. In the polynomial ring F2[x]/((x+1)^{2^r}), cyclic rotation by k bit positions corresponds to multiplication by x^k. An XOR combination of rotations corresponds to a polynomial s(x). The element s(x) is a unit in this ring if and only if s(1)=1, which holds whenever s(x) contains an odd number of terms.
The SHA-256 instance operates on 32-bit words with state vector (a,b,c,d,e,f,g,h) initialized as specified. The symbols K0 and K1 denote round constants, while W0 and W1 denote message schedule inputs. The edge-relaxed relation applies the boundary conditions across two rounds. The coordinate b2=U is projected out, leaving the gauge observed entirely within coordinate a2.
Method
The algebraic invertibility of odd rotation sums in F2[x]/((x+1)^{2^r}) was proven by unit analysis at x=1. The SHA-256 specialization was validated by explicit rank decomposition of the Sigma0 matrix, yielding basis digest b39f6587…6dcee447.
Empirical verification relies on the receipt pipeline shared with MF-062: a 20,000-sample replay and an independent 100,000-sample C++ crosscheck, both passing with zero failures. The underlying test receipts and verification artifacts are provided in this paper's downloadable evidence pack.
Discussion
The algebraic invertibility theorem applies strictly to binary word lengths of power-of-two size 2^r. The SHA-256 corollary is scoped to the documented input state, constant assignments, and edge-relaxed two-round projection. Because Sigma0 has rank 32, eliminating b2=U leaves the full 32-bit gauge unobstructed in a2. The general algebraic lemma provides invertibility, and the explicit basis digest confirms the 32-bit SHA-256 instantiation. The register does not assert invertibility for non-power-of-two word lengths, arbitrary inputs, or broader multi-round closures.
Catalog note: this entry was remapped from package catalog ID MF-060 following an identifier collision with Lens A. MF-063 inherits the receipt bundle of MF-062. The register classifies this result as a structure theorem with no prior art recorded.
For everyone — the takeaway
What this means
The internal freedom observed in the two-round SHA-256 boundary model comes from a clean algebraic property: XORing an odd number of circular bit rotations never destroys information when word lengths are powers of two. In 32-bit SHA-256, the Sigma0 operation preserves all 32 independent bit directions. Dropping the output coordinate b2=U therefore leaves an entire 32-bit block of hidden variation in coordinate a2. This explains how full-word internal degrees of freedom survive round projections under the specified input constraints.
Register references
Entry: MF-063.
Receipts: same as MF-062 — CONT lens_r2b_majgauge_verification_receipt.json; CONT lens_r2b_independent_audit.json; package certificates/maj_gauge_maximal_defect.json.
Prior art: the register does not record this.
Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.
Evidence pack
Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 0 of 0 receipt files bundled (1 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.
Changelog
Last reviewed 2026-08-29
- 2026-08-29Published on this site.