Research · Papers · Direct sums, wedges and the p14 frontier · MF-105
The live p14 frontier and its doubly conditional row saving
p14 existence is LIVE/UNKNOWN; 817 named copy-swap cells survive; −477 rows requires p14 and rank(I+A)=3
Published 2026-08-29
For everyone
Plain summary
When optimizing hash functions for zero-knowledge proofs, the main goal is to cut the number of multiplication steps. For the two-column carry operation in SHA-256, researchers tested whether 14 multiplications (a target called p14) would be enough.
This entry records a snapshot of that search. After filtering out circuit layouts that cannot work, 817 candidate configurations remained open. The solver neither found a working 14-multiplication circuit nor proved that one is impossible. A projected saving of 477 constraint rows depends on two open conditions: finding a working circuit and proving an algebraic rank condition on its linear layers. Later work on the same day expanded this search.
Result
The existence of a 14-multiplication realization (p14) for the Cartesian two-column carry in GF(2) XAG synthesis remains open (LIVE/UNKNOWN).
Across the direct-sum decomposition screens in this snapshot:
- Exactly 817 named copy-swap cells survive without contradiction.
- No replayed p14 circuit witness exists.
- No global impossibility proof for p14 exists.
- The potential saving of −477 R1CS rows requires both an explicit p14 circuit realization and the linear condition rank(I+A) = 3.
Setting and definitions
The target is the XOR-free multiplicative complexity of the Cartesian two-column carry in SHA-256 over GF(2).
Multiplicative complexity MC(f) is the minimum number of AND gates needed to synthesize Boolean map f over {AND, XOR, NOT}. In R1CS pipelines, GF(2) linear operations cost zero, whereas AND gates incur constraint rows.
Decomposition candidates are partitioned into named copy-swap cells across direct-sum wedges. A cell is closed when a solver establishes unsatisfiability (UNSAT) for its structural obligation under polynomial or SAT encodings. A cell survives when neither a satisfying assignment nor an unsatisfiability certificate is verified.
Method
Candidate cells were translated into structural obligations under the GF(2) XAG cost model. Scoped closures and intersection tests were verified by automated solvers under evidence tier P + FC (Proof + Fully Checked).
Surviving candidates were aggregated under tier N/E (Non-evidence / Open). Timeouts, sampled model failures, and incomplete search branches were recorded strictly as non-evidence rather than negative proofs.
Structural obligations, wedge boundaries, and survivor intersections are recorded in:
- SYNTH-M-P14.md
- staged7/pro-request3-return/sha256_p14_wedge_frontier_report.json
- prover-p14a-scratch/graded_obligations_receipt.json
- prover-p14a-scratch/completion_evidence_aggregate.json
- synth-m-scratch/recompute_p14_intersection_receipt.json (SHA-256 f0af215bc5c35a3618b1de61b2ca0a8a04126ff325264c38f1872c07718c2425)
- zkgolf-decomp/synth-m-scratch/p14_scope_audit_receipt.json (SHA-256 126df31c97d46fc2acc2f032336b2a304fa56282a075cc3e3258b0d1ccd3d3ac)
Discussion
This entry records the state of the p14 frontier at the close of the initial screening pass, superseding earlier three-orbit and twelve-cell partition summaries.
The survival of 817 cells means only that the initial screens could not eliminate these branches. Without a synthesized witness, the −477 row saving cannot be claimed as an achieved reduction.
The snapshot is preserved verbatim in technical content under the curation protocol and was superseded later the same day by the second-wave census in MF-124. No claim of priority or discovery is made.
For everyone — the takeaway
What this means
This snapshot marks the point where automated elimination ran out of easy answers. It lists which circuit designs were ruled out and which 817 cases still need analysis. The projected reduction in proof size remains unverified until someone builds a 14-multiplication circuit or proves that none can exist.
Register references
- Register Entry: MF-105
- Reports:
- zkgolf-decomp/reports/SYNTH-M-P14.md
- zkgolf-decomp/SD-RESEARCH-UPDATE-REPORT.md
- Receipt Artifacts:
- staged7/pro-request3-return/sha256_p14_wedge_frontier_report.json
- prover-p14a-scratch/graded_obligations_receipt.json
- prover-p14a-scratch/completion_evidence_aggregate.json
- zkgolf-decomp/synth-m-scratch/recompute_p14_intersection_receipt.json (SHA-256 f0af215bc5c35a3618b1de61b2ca0a8a04126ff325264c38f1872c07718c2425)
- zkgolf-decomp/synth-m-scratch/p14_scope_audit_receipt.json (SHA-256 126df31c97d46fc2acc2f032336b2a304fa56282a075cc3e3258b0d1ccd3d3ac)
Every artifact named above is bundled in, or hashed by, this paper's evidence pack below.
Evidence pack
Everything needed to check this entry against its receipts: the register text, a manifest with a SHA-256 hash for every named receipt, and 2 of 4 receipt files bundled (13 KB). Anything not bundled is still hashed in the manifest and lives in the compute-box working trees.
Changelog
Last reviewed 2026-08-29
- 2026-08-29Published on this site.