XXH32: 8-byte pair at 1 - 2^-17, 2^16-way families, long-input loop differential

Key model: XXH32(input, len, seed) with a uniformly random 32-bit seed (xxHash v0.8.3; SMHasher3 XXH-32). Scores use L = number of 8-byte words of the longer message.

What is checked

xxh32_witness.c (self-contained transcription of SMHasher3 hashes/xxhash.cpp; checks the SMHasher3 verification value 0x6FD78385 first):

loop_xxmur.c (upstream xxhash.h v0.8.3; checks all four SMHasher3 values first): position-independent loop differential, lane l of stripes s, s+1: word (s, l) += P2^-1 = 0xb6c92f47, word (s+1, l) += -2^13 * P1 * P2^-1 = 0x981d2000. It fails exactly when the low 19 bits of V = acc + w * P2 are all ones, so eps = 1 - 2^-19 at any position. Exhaustive check at 256 B (offsets 180 and 196): exactly 8,192 of the 2^32 seeds fail (4,294,959,104 collide), every failure predicted by the model; seed 0 collides (f2247a10), back-solved seed 0x0b867048 fails. Random positions at 256 B .. 1 MB and disjoint-slot sets (2^16 in 64 KB, 64/64 keys; 2^10 in 1 MB, 32/32) agree with the model.

Build and run

cc -std=c11 -O2 -o xxh32_witness xxh32_witness.c -lm
./xxh32_witness 13 0x32 --exhaustive     # about 15 s

mkdir -p upstream && curl -sL -o upstream/xxhash.h https://raw.githubusercontent.com/Cyan4973/xxHash/v0.8.3/xxhash.h
cc -std=c11 -O2 -pthread -Iupstream -o loop_xxmur loop_xxmur.c -lm
THREADS=8 ./loop_xxmur exh32 256
THREADS=8 ./loop_xxmur rand xxh32 65536 262144

Logs: logs/xxh32_witness.log, logs/loop_xxmur_xxh32.log.