Research · Papers · The quadratic hull and its defects · MF-065
Exact number of quadratic equations for a unique common zero in GF(2)^32
Forcing g₀=...=g₃₁=0 over GF(2) with degree ≤ 2 equations without auxiliary variables requires and is satisfied by exactly 16 equations
Published 2026-08-29
For everyone
Plain summary
Audience: a smart reader with no domain knowledge.
MF-065 determines the exact number of quadratic equations needed to force 32 binary error flags to zero without using helper variables. The error values serve directly as coordinate variables. Under these rules, 16 equations are both necessary and sufficient to isolate the all-zero state. The lower bound follows from the Chevalley-Warning theorem: 15 or fewer quadratic equations over 32 variables have a total degree of at most 30, which makes it impossible to leave exactly one valid solution. For sufficiency, pairing the variables as (1+g_2j)(1+g_2j+1)=1 accepts only (0,0). Exhaustive checks verify this behavior up to 16 bits. Across 32 round pairs, the construction yields an abstract ledger of 512 rows. The status for SHA remains UNKNOWN because its majority-function residuals are quadratic rather than direct coordinates.
Result
Let g_0,...,g_31 be 32 gauge residuals acting as affine coordinates over GF(2). In the absence of auxiliary variables, forcing the unique zero
g_0=...=g_31=0
with equations of degree at most two requires and is satisfied by exactly 16 equations. Sufficiency is given by
(1+g_{2j})(1+g_{2j+1})=1, for j=0,...,15.
The lower bound follows from the Chevalley-Warning theorem: if r<=15, the degree sum is at most 30, so the common-zero count over GF(2) cannot equal 1 mod 2, ruling out a unique common zero in GF(2)^32. Exhaustive unique-zero checks verify the construction through 16 bits. Evaluated over 32 round pairs, the abstract ledger totals 512 rows. This is an abstract bound; application to SHA remains UNKNOWN because current SHA Maj residuals are quadratic expressions rather than affine coordinates.
Setting and definitions
All variables live in GF(2). A gauge residual g_i is one of the 32 values forced to zero, treated directly as an affine coordinate. Auxiliary variables are additional helper variables introduced into the constraint system; none are permitted in this model.
Equations have degree at most two, meaning every monomial contains at most two variables. A unique common zero is an assignment where all equations evaluate to true at exactly one point in the coordinate space. The pairing equation (1+g_a)(1+g_b)=1 forces its two coordinate residuals to zero simultaneously. A round pair is one of 32 paired units over which the constraint block is evaluated. The current Maj residuals are the quadratic residual expressions of the SHA majority operation.
Method
The lower bound applies the classical Chevalley-Warning theorem. In GF(2)^32, a system of r<=15 equations of degree at most two has total degree at most 30. Because 30 < 32, the number of common zeros is even, which precludes a unique common zero.
Sufficiency is established by 16 disjoint pairing equations: (1+g_{2j})(1+g_{2j+1})=1 for j=0,...,15. Each equation admits only (g_{2j}, g_{2j+1}) = (0,0). Exhaustive testing confirms unique-zero enforcement through 16 bits. Replicating the 16-equation block across 32 round pairs generates the 512-row abstract ledger. Supporting verification receipts and test output are provided in this paper's downloadable evidence pack.
Discussion
The bound is tight within the abstract model: 16 equations are necessary and sufficient to force 32 affine coordinates to zero using degree-two constraints without auxiliary variables. Over 32 round pairs, this corresponds to a 512-row ledger.
This result does not yield a SHA construction. SHA Maj residuals are quadratic polynomials rather than direct affine coordinates, so the SHA instance remains UNKNOWN and cannot be inferred from this abstract ledger. Curation corrections: NONE. Lower bound: classical Chevalley-Warning theorem. The register records no separate prior-art position.
For everyone — the takeaway
What this means
Audience: no domain knowledge again.
MF-065 solves an exact resource-allocation problem for circuit constraints. If you have 32 on/off error flags and must clear them all using rules that inspect at most two flags at a time, you cannot do it with 15 rules or fewer—a classical mathematical parity theorem proves you will always leave multiple configurations valid. But 16 rules, each linking a disjoint pair of flags, isolate the all-zero state completely. Stacking this rule block across 32 round pairs gives 512 total constraint rows. However, using this in a real hash function like SHA is still an open question (status UNKNOWN) because the error expressions in SHA are already quadratic, violating the assumption that each flag is a simple, direct coordinate.
Attribution and prior art
Prior art: The lower bound is based on the classical Chevalley-Warning theorem, and no separate prior-art position is claimed.
Register references
Entry: MF-065.
Receipts: package certificates/quadratic_gauge_pairing.json; CONT lens_r2b_majgauge_verification_report.md.
Prior art: classical Chevalley-Warning theorem; the register does not record a separate prior-art position.
Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.
Evidence pack
Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 2 of 2 receipt files bundled (6 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.
Changelog
Last reviewed 2026-08-29
- 2026-08-29Published on this site.