Introduction

Let EE be an elliptic curve over Q\mathbb{Q}. Write

a(E)=ord⁡s=1L(E,s),r(E)=rank⁡ZE(Q),c2(E)=corank⁡Z2Sel⁡2∞(E/Q).a(E)=\operatorname{ord}_{s=1} L(E,s),\qquad r(E)=\operatorname{rank}_{\mathbb{Z}} E(\mathbb{Q}),\qquad c_2(E)=\operatorname{corank}_{\mathbb{Z}_2}\operatorname{Sel}_{2^\infty}(E/\mathbb{Q}).

The Selmer group uses the local Kummer conditions at every place. Its corank includes both the Mordell–Weil rank and any divisible 2-primary contribution from the Tate–Shafarevich group. Modularity supplies the analytic continuation and functional equation of L(E,s)L(E,s) [7].

Theorem 1.1 (The 2-converse). For every elliptic curve E/QE/\mathbb{Q} with c2(E)∈{0,1}c_2(E) \in\{0,1\},

a(E)=r(E)=c2(E),Sha⁡(E/Q) is finite.a(E)=r(E)=c_2(E),\qquad{\operatorname{Sha}}(E/\mathbb{Q})\text{ is finite.}

There is no restriction on reduction type, complex multiplication, rational torsion, or rational isogenies. The hypothesis concerns the full 2-power Selmer corank; a Mordell–Weil rank bound alone does not give it.

For a nonzero squarefree integer dd, let E(d)E^{(d)} denote the quadratic twist of EE, and set

D(X)={d∈Z:0<∣d∣≤X, d squarefree}.\mathcal{D}(X)=\{d\in\mathbb{Z}:0<|d|\leq X,\ d\text{ squarefree}\}.

Thus positive and negative parameters are counted together and ordered by absolute value. A residue class can fix the sign of the functional equation; the half-density statement below concerns the full set D(X)\mathcal{D}(X).

Theorem 1.2 (Goldfeld’s analytic density conjecture). For every elliptic curve E/QE/\mathbb{Q} and each j∈{0,1}j\in\{0,1\},

lim⁡X→∞#{d∈D(X):a(E(d))=j}#D(X)=12.\lim_{X\to\infty}\frac{\#\{d\in\mathcal{D}(X):a(E^{(d)})=j\}}{\#\mathcal{D}(X)}=\frac{1}{2}.

Consequently the twists of analytic rank at least two have density zero. For a density-one set of signed squarefree parameters dd, the analytic and Mordell–Weil ranks of E(d)E^{(d)} agree and its whole Tate–Shafarevich group is finite.

The theorem follows by combining the pointwise 2-converse with Smith’s distribution of full 2-power Selmer coranks [69], Theorem 1.1. Section 14 gives the deduction, including the passage from integer to squarefree parameters. The main work of this paper is the pointwise converse.

Consequences and companion results

The converse has a finite-descent consequence. Put

d2(E)=dim⁡F2Sel⁡2(E/Q)−dim⁡F2E(Q)[2].d_2(E)=\dim_{\mathbb{F}_2}\operatorname{Sel}_2(E/\mathbb{Q})-\dim_{\mathbb{F}_2}E(\mathbb{Q})[2].

Corollary 1.3 (A finite Selmer criterion). If d2(E)∈{0,1}d_2(E)\in\{0,1\}, then

a(E)=r(E)=c2(E)=d2(E),Sha⁡(E/Q) is finite,Sha⁡(E/Q)[2∞]=0.a(E)=r(E)=c_2(E)=d_2(E),\qquad{\operatorname{Sha}}(E/\mathbb{Q})\text{ is finite},\qquad{\operatorname{Sha}}(E/\mathbb{Q})[2^\infty]=0.

Thus a finite 2-descent can certify the analytic rank and the vanishing of the entire 2-primary Tate–Shafarevich group in these two cases. The proof uses the alternating Cassels–Tate pairing to pass from d2(E)d_2(E) to the full Selmer corank, and is given in Section 14.

The density theorem resolves the frequency assertion for analytic ranks zero and one. The mean analytic-rank assertion requires additional control: a set of density zero can still contribute to the rank-weighted average. The separate companion OpenAI [56] proves the required analytic tail estimate and, together with Theorem 1.2, obtains mean analytic rank 1/21/2 in the same signed squarefree ordering.

A subsequent companion [55] extends the pointwise converse to every prime pp: full pp-power Selmer corank r∈{0,1}r \in\{0,1\} forces analytic and Mordell–Weil ranks rr and finiteness of the whole Tate–Shafarevich group. Its proof uses the 2-converse and analytic twist densities established here.

The rank and finiteness assertions are distinct from the Birch–Swinnerton–Dyer leading-coefficient formula. The pointwise two-primary formula of OpenAI [57], combined with the Selmer-corank densities in the proof of Theorem 1.2, gives the exact two-primary formula on a density-one set of signed squarefree twists. Their common analytic and Mordell–Weil ranks are zero and one with density 1/21/2 each. This consequence is OpenAI [57]; its leading-coefficient assertion concerns the valuation at 2.

Goldfeld’s conjecture and analytic nonvanishing

Birch and Swinnerton-Dyer’s comparisons of rational points with central LL-values led to the conjectural equality of algebraic and analytic rank [3]. The conjecture also predicts finiteness of Sha⁡(E/Q)\operatorname{Sha}(E/\mathbb{Q}) and a formula for the leading coefficient [72]. Goldfeld’s original 1979 formulation asks for the mean analytic order in a family parametrized by quadratic-field discriminants [30]. The density formulation predicts that analytic ranks zero and one each occur half the time. Our counting convention throughout is the signed squarefree set D(X)\mathcal{D}(X).

The analytic study of quadratic twists produced both nonzero central values and simple central zeros. Bump–Friedberg–Hoffstein and Murty–Murty supplied auxiliary twists with the nonvanishing needed in Heegner-point arguments; Iwaniec and Perelli–Pomykała developed quantitative estimates for central derivatives [8, 35, 51, 59]. Ono–Skinner obtained a lower bound of order X/log⁡XX/\log X for the number of nonvanishing central values among twists by fundamental discriminants DD with 0<∣D∣≤X0 < |D| \le X [54]. More recently, Kumar–Mallesham–Sharma–Singh sharpened derivative nonvanishing estimates through second moments, and Kriz–Nordentoft improved central-value lower bounds for curves with no rational two-torsion [44] [43]. These quantitative results yield many twists without by themselves giving a positive proportion for every fixed curve.

Positive proportions were obtained in special families. James proved analytic-rank-zero proportions for particular curves, and Vatsal proved positive proportions of both analytic ranks zero and one for X0(19)X_0(19) [36] [75]. Kriz–Li proved both positive proportions for every rational elliptic curve admitting a rational 3-isogeny [42]. In the congruent-number family, Tian’s Heegner-point work gives rank one and odd-order Tate–Shafarevich group in specified subfamilies [73]. Genus-period and genus-point congruences, followed by Selmer statistics, give further analytic density results [67, 74]. These arguments connect coefficient congruences and arithmetic statistics with analytic nonvanishing, a connection also central to the present proof.

The statistical input used here has its own progression. Smith first established higher 2-power Selmer distributions for curves with full rational two-torsion and no rational cyclic subgroup of order four [68]. His subsequent work treated the irreducible residual case and further rational two-isogeny cases [70, 71]. The unrestricted theorem gives full Selmer coranks zero and one with density 1/21/2 each for every rational elliptic curve [69]. Its analytic corollary assumes Birch–Swinnerton–Dyer [69]. We use the Selmer theorem itself and supply the pointwise analytic implication through

Theorem 1.1.

The Selmer converse problem

Gross–Zagier and Kolyvagin established the forward implication: analytic rank at most one gives equality with the Mordell–Weil rank and finiteness of the whole Tate–Shafarevich group [31, 40]; see also the combined formulation in Skinner [65], §1. The Gross–Zagier formula relates a central derivative to the height of a Heegner point, and Kolyvagin’s derived classes control the Selmer group. A converse must produce analytic nonvanishing from Selmer information.

Cyclotomic Iwasawa theory gave rank-zero converses at good ordinary odd primes in the work of Skinner–Urban, under residual irreducibility and ramification hypotheses [66]. Skinner and Wei Zhang proved rank-one converse criteria through Heegner points and derived classes, under their respective reduction, residual-image and local hypotheses [65, 82]. Burungale–Castella–Skinner subsequently removed the auxiliary ramification conditions in the good ordinary, residually irreducible case for p>3p > 3 [13], Theorem 1.2.2 and the discussion following Remark 1.2.3. At good supersingular primes p>3p > 3, Castella–Wan obtained the rank-one Selmer-corank implication for semistable curves [17], Theorem A.

Reducible residual representations call for a different Iwasawa-theoretic comparison. Castella–Grossi–Lee–Skinner proved the corank-zero and corank-one converses at good ordinary Eisenstein primes p>2p > 2, with local isogeny character neither trivial nor cyclotomic [18], Theorem E. Keller–Yin treated potentially good ordinary reduction at odd Eisenstein primes without that character exclusion [39], Theorem B. These results enlarge the allowed residual representations while retaining conditions on the prime and its reduction type.

The CM theory includes substantial results at the prime two. Burungale–Tian proved the rank-one converse at good ordinary primes p>3p > 3 [11]; Burungale–Castella–Skinner–Tian included the small ordinary primes under an additional conductor hypothesis [10], Theorem A. Ressler and Yu obtained the small-prime good-ordinary result without that conductor condition; see Yu’s Theorem 1 and the attribution in Burungale–Castella–Skinner–Tian, Remark C [10, 81]. Burungale–Skinner’s combined ordinary formulation includes p=2p = 2, and their good supersingular CM theorem also permits p=2p = 2 under an additional surjectivity condition on Selmer localization at pp [9], Theorems A.3 and A.1.

In corank zero, Burungale–Tian’s theorem covers every rational CM elliptic curve at every prime, without a reduction restriction [12], Theorem 1.1. Combined with Smith’s unrestricted distribution, it therefore already gives the analytic-rank-zero half for every CM twist family. Their Theorem 1.2 gives rank zero for almost all positive squarefree n≡1,2,3(mod8)n \equiv1, 2, 3 \pmod8 in the congruent-number family ny2=x3−xny^2 = x^3 - x. Kriz’s preprint states a converse for curves with CM by the full ring of integers at the unique ramified prime of the CM field, and derives analytic densities for restricted CM families, including congruent-number curves [41], Theorems 1.1 and 10.17. Its dyadic pointwise statement concerns the CM fields Q(i)\mathbb{Q}(i) and Q(−2)\mathbb{Q}(\sqrt{-2}). Together with Smith’s distribution theorem, the stated dyadic converse would yield both half-density conclusions for quadratic twists of every curve with CM by either of these maximal orders. Theorem 1.1 treats the full 2-power Selmer corank for every rational elliptic curve, in both ranks zero and one.

Proof strategy

Fix the curve under consideration. We construct finite binary families of twists

hx=∏q∈Q(q∗)λq(x),q∗=(−1/q)q,x∈F2b,h_x = \prod_{q \in Q} (q^*)^{\lambda_q(x)}, \qquad q^* = (-1/q)q, \qquad x \in\mathbb{F}_2^b,

{#eq:1} where QQ is a finite set of distinct good odd primes and the λq\lambda_q are linear forms. The parameter at x=0x = 0 is 1. The families have the same local twisting classes at every fixed bad place. Their nonzero vertices have analytic order zero or one, according to the corank of the fixed curve. A scalar determinant coordinate attached to the relevant class and Selmer complex has a nonzero central specialization there, with uniformly bounded 2-adic valuation. Bounded integral interpolation then recovers nonvanishing at the missing vertex 0.

At corank zero, the interpolated class is a Beilinson–Kato class and its central specialization detects L(E,1)L(E,1) [38]. At corank one, it is a Heegner class over an imaginary quadratic field K=Q(k)K = \mathbb{Q}(\sqrt{k}), whose height detects

[L(E,s)L(E(k),s)]s=1′.\left[L(E,s)L(E^{(k)},s)\right]'_{s=1}.

An analytically nonvanishing companion E(k)E^{(k)} makes the Selmer corank over KK equal to one. The argument retains integral Kummer conditions at 2 and every bad prime. The rational Iwasawa input is used in its stated scope; the uniform integral estimates at 2 are proved in Sections 13 and 12. The Heegner construction is related to Howard’s Kolyvagin-system framework [34]; the integral bounds required here are established with the local conditions and uniformity stated in this paper.

The finite families are built from modular coefficients. Waldspurger’s formula supplies the even-sign coefficients [77]. In odd sign, reductions of genus Heegner sums give weighted ternary theta coefficients at increasing finite precisions. A uniform lower bound allows a least normalized valuation to be selected. In the even case this is a minimum among the coefficients of one form. In the odd case it is a minimum over bounded-weight sequences as the precision increases; each finite collection of tests is then realized at a sufficiently high actual precision. A test attaining the minimum detects the required analytic order and gives a uniform upper bound. Weight-two Hecke traces turn these coefficient tests into contraction and deletion rules for finite configurations of primes.

There are two exhaustive residual cases. If E[2]E[2] is reducible, its invariant line is a rational point of order two. Graphs encode prescribed quadratic residue symbols between auxiliary primes. The resulting finite construction makes two separate coefficient tests nonzero together at every nonzero binary vertex. The odd argument fixes one companion field before the dimension grows. In this branch, the even construction first supplies the lower bound needed to normalize the odd coefficient test. If E[2]E[2] is irreducible, local Selmer equations give matrices over F2\mathbb{F}_2. Subtracting a correction determined by finitely many local types makes these matrices symmetric; their nullities still give a lower bound on the Selmer dimension up to a fixed cost. Removing one selected prime or pair of primes, or retaining it with either of two allowed local choices, gives three configurations. Their coefficient tests satisfy the same sum-zero relation as the corresponding matrix determinants. This relation does not identify the coefficient test with the determinant. We group the configurations into blocks and arrange that the matrix entries between distinct blocks vanish. A nonzero coefficient test bounds the matrix kernel, and hence the number of singular blocks in the finite configuration. Fixing a configuration with a maximal number of such blocks lets us arrange nonzero tests at every nonzero binary vertex. An additional alternating-matrix construction supplies a companion with uniformly bounded prime count and Selmer length.

Two parts of the argument have uses beyond this assembly. The interpolation algebra clears denominators through a bounded complex, so the required congruence precision is independent of the number of new primes. The graph construction treats the coefficient tests as polynomials in prescribed residue symbols and makes separately nonzero tests nonzero together. Its proof retains squared variables until after multiplying their highest-degree parts. Neither construction presupposes the desired nonvanishing at the base.

Organization. Section 2 records the rank implications and local conventions. Section 3 states the two arithmetic transfer criteria, the lower bounds needed to normalize coefficients, and auxiliary nonvanishing with prescribed local conditions. Sections 4 and 5 turn analytic nonvanishing into coefficient tests and prime-substitution identities. Section 6 develops the graph construction used in the rational-torsion converse of Section 7. Section 8 supplies the Selmer matrices for the irreducible converse in Section 9. The remaining main-text sections prove the arithmetic inputs: Section 10 establishes auxiliary nonvanishing, Section 11 develops the common finite-complex and binary transfer arguments, and Sections 12 and 13 construct the cyclotomic and Heegner determinant coordinates and prove their integral bounds. Finally, Section 14 assembles the unrestricted result and its density and finite-descent consequences.

Selmer ranks and local conventions

We first record the arithmetic implications used to pass between curves and to interpret the final analytic nonvanishing. They apply to every elliptic curve over Q\mathbb{Q}.

Throughout, we use Mordell–Weil finite generation and the positive definiteness of the canonical height modulo torsion over number fields [49], Chapter IV, finite-basis theorem, Theorem 4.7, Remark 4.12, and Theorem 6.1].

Lemma 2.1 (Ranks and the forward implication). For an elliptic curve A/QA/\mathbb{Q} there is an exact sequence

0⟶A(Q)⊗Q2/Z2⟶Sel⁡2∞(A/Q)⟶Sha⁡(A/Q)[2∞]⟶0.0 \longrightarrow A(\mathbb{Q}) \otimes\mathbb{Q}_{2}/\mathbb{Z}_{2} \longrightarrow\operatorname{Sel}_{2^\infty}(A/\mathbb{Q}) \longrightarrow{\operatorname{Sha}}(A/\mathbb{Q})[2^\infty] \longrightarrow0.

In particular

c2(A)=r(A)+corank⁡Z2Sha⁡(A/Q)[2∞].c_{2}(A) = r(A) + \operatorname{corank}_{\mathbb{Z}_{2}} {\operatorname{Sha}}(A/\mathbb{Q})[2^\infty].

If a(A)≤1a(A) \le1, then r(A)=a(A)r(A) = a(A), the whole group Sha⁡(A/Q){\operatorname{Sha}}(A/\mathbb{Q}) is finite, and c2(A)=a(A)c_{2}(A) = a(A).

Proof. The finite Kummer exact sequences are

0⟶A(Q)/2nA(Q)⟶Sel⁡2n(A/Q)⟶Sha⁡(A/Q)[2n]⟶0.0 \longrightarrow A(\mathbb{Q})/2^{n}A(\mathbb{Q}) \longrightarrow\operatorname{Sel}_{2^{n}}(A/\mathbb{Q}) \longrightarrow{\operatorname{Sha}}(A/\mathbb{Q})[2^{n}] \longrightarrow0.

Their direct limit gives the displayed sequence; taking coranks gives the identity. The last assertion is the Gross–Zagier–Kolyvagin forward theorem [31, 40]; see also its unrestricted formulation in Skinner [65], §1.

Lemma 2.2 (Parity and change of curve). For every elliptic curve A/QA/\mathbb{Q} with root number ε(A)\varepsilon(A),

(−1)c2(A)=ε(A).(-1)^{c_{2}(A)} = \varepsilon(A).

A rational isogeny preserves a(A)a(A), r(A)r(A) and c2(A)c_{2}(A). For a quadratic field K=Q(k)K = \mathbb{Q}(\sqrt{k}),

corank⁡Z2Sel⁡2∞(A/K)=c2(A)+c2(A(k)).\operatorname{corank}_{\mathbb{Z}_{2}} \operatorname{Sel}_{2^\infty}(A/K) = c_{2}(A) + c_{2}(A^{(k)}).

Proof. The parity statement is the p=2p = 2 case of Dokchitser and Dokchitser [25], Theorem 1.4, equivalently Theorem 4.19]. At p=2p = 2 this is Monsky’s theorem [50]. Isogenies and their duals induce maps respecting every local Kummer condition; their composites are multiplication by their fixed degree. After rationalization these maps preserve ranks and coranks. Their LL-functions agree by isogeny invariance.

Restriction to KK and the two conjugation projections 1+c1+c and 1−c1-c give maps between Sel⁡2∞(A/K)\operatorname{Sel}_{2^\infty}(A/K) and the sum of the Selmer groups of AA and A(k)A^{(k)} over Q\mathbb{Q}, with composites multiplication by 22. They respect local Kummer images, so rationalization gives the corank identity. An integral direct sum is not needed. □

Lemma 2.3 (The residual alternatives). The representation E[2]E[2] is reducible over F2\mathbb{F}_2 if and only if E(Q)[2]≠0E(\mathbb{Q})[2]\ne0. In that case it is an extension of two trivial F2\mathbb{F}_2-representations. Otherwise its image is C3C_3 or S3S_3 in GL⁡2(F2)\operatorname{GL}_2(\mathbb{F}_2). Quadratic twisting leaves this representation unchanged.

Proof. An invariant line over F2\mathbb{F}_2 has a unique nonzero vector, which must be fixed. Conversely a rational point of order two spans an invariant line. Both that line and the one-dimensional quotient are trivial, since F2×={1}\mathbb{F}_2^\times=\{1\}. The irreducible subgroups of GL⁡2(F2)≃S3\operatorname{GL}_2(\mathbb{F}_2)\simeq S_3 are C3C_3 and S3S_3. Finally a quadratic character reduces to 11 modulo $2. □

The distinction here is irreducibility over F2\mathbb{F}_2, rather than absolute irreducibility: the cyclic cubic case is included. In the rational-torsion case we may first replace the curve by a rationally isogenous one with full rational two-torsion, if such a curve exists. Otherwise, for any chosen rational two-isogeny E→E′E\to E', both Q(E[2])\mathbb{Q}(E[2]) and Q(E′[2])\mathbb{Q}(E'[2]) are quadratic. Lemma 2.2 justifies this choice before any constructions.

Finite lengths and twisting data

All valuations above 22 are normalized by v(2)=1v(2)=1, with v(0)=+∞v(0)=+\infty. For a finite Z2\mathbb{Z}_2-module MM, its length is log⁡2#M\log_2\#M. The corank of a cofinitely generated discrete Z2\mathbb{Z}_2-module is the rank of its Pontryagin dual. Its quotient by the maximal divisible subgroup is finite. This finite quotient must be distinguished from finiteness of the original group.

A fixed support SS is a finite set of primes containing 22 and all primes of bad reduction; it is enlarged explicitly when necessary. Write NN for the conductor of EE. A local filter specifies a real sign and unit squareclasses at SS for a variable odd fundamental discriminant prime to SS. The empty discriminant h=1h=1 denotes the untwisted curve. We also write E(h)E^{(h)} for twisting by a rational squareclass. For an odd prime pp, the signed prime discriminant is p∗=(−1/p)pp^*=(-1/p)p. Products of distinct p∗p^* are odd fundamental discriminants, with the empty product interpreted as 11.

For an odd fundamental discriminant hh prime to 2N2N, the coprime-twist root-number formula is

ε(E(h))=ε(E)χh(−N)\varepsilon(E^{(h)})=\varepsilon(E)\chi_h(-N)

[61] Section 11. Thus matching unit squareclasses at the primes dividing 2N2N and opposite real signs give opposite functional signs: the values of χh(N)\chi_h(N) agree, whereas χh(−1)=sgn⁡(h)\chi_h(-1)=\operatorname{sgn}(h). This verifies the sign condition when choosing the auxiliary partners below.

Put T=T2(E)T=T_2(E) and V=E[2]V=E[2]. Frobenius is arithmetic, and ap(E)=p+1−#E(Fp)a_p(E)=p+1-\#E(\mathbb{F}_p) at a good prime. For hh prime to SS, set

tp=dim⁡F2VFr⁡p,w(h)=12∑p∣∣h∣tp.(1)t_p=\dim_{\mathbb{F}_2}V^{\operatorname{Fr}_p},\qquad w(h)=\frac{1}{2}\sum_{p\mid|h|}t_p. \tag*{(1)}

The residual identity, a transposition and a rotation of order three have tp=2,1,0t_p=2,1,0, respectively. We call these split, simple and root primes; their weights are $1,1/2,0. Only types present in the residual image are used. Quadratic residue symbols written additively take the values 0,1∈F20, 1 \in\mathbb{F}_2, corresponding to +1,−1+1, -1.

Whenever its group is finite, write

s(h)=length⁡Z2Sha⁡(E(h)/Q)[2∞].s(h) = \operatorname{length}_{\mathbb{Z}_2} {\operatorname{Sha}}(E^{(h)}/\mathbb{Q})[2^\infty].

This includes every twist already proved to have analytic rank zero or one. It also includes a base of Selmer corank zero, since its full 2-primary Selmer group is then finite. We make no whole-Sha finiteness assertion at such a base until analytic nonvanishing has been established.

Let ΩE+\Omega_E^+ be a positive real period and let ΩE−\Omega_E^- be the positive magnitude of a nonzero anti-invariant period. Put

L(h)=∣h∣L(E(h),1)ΩEsgn⁡(h).(2)\mathcal{L}(h) = \frac{\sqrt{|h|}L(E^{(h)},1)}{\Omega_E^{\operatorname{sgn}(h)}}. \tag*{(2)}

Valuations refer to this algebraic period-normalized value at a chosen place above 2. Changes of the fixed period, modular parametrization or isogeny affect valuations by bounded constants. All parametrizations send the cusp ∞\infty to the origin. Replacing (2) by the central value divided by a Néron real period of E(h)E^{(h)} changes a finite valuation by OE(1)O_E(1): the differential changes by the usual twisting factor, and there are only finitely many twisting classes at 2.

Every uniform bound below specifies its fixed data. Constants may depend on the curve, a chosen fixed twist and finite local preparation; they may not depend on the subsequent cube dimension or the number of new primes. At finite precision, the sizes of primes realizing a specified configuration may depend on that entire configuration. A limiting construction will only be used through its finite realizations.

Lemma 2.4 (Finite descent and corank). Let FF be the quotient of Sha⁡(E/Q)[2∞]{\operatorname{Sha}}(E/\mathbb{Q})[2^\infty] by its maximal divisible subgroup. Then

d2(E)=c2(E)+dim⁡F2F[2],dim⁡F2F[2] is even.d_2(E) = c_2(E) + \dim_{\mathbb{F}_2} F[2], \qquad\dim_{\mathbb{F}_2} F[2]\text{ is even}.

Thus d2(E)∈{0,1}d_2(E) \in\{0,1\} implies c2(E)=d2(E)c_2(E) = d_2(E) and F=0F = 0.

Proof. The finite Kummer sequence at n=1n = 1 gives d2(E)=r(E)+dim⁡F2Sha⁡(E/Q)[2]d_2(E) = r(E) + \dim_{\mathbb{F}_2} {\operatorname{Sha}}(E/\mathbb{Q})[2]. The divisible subgroup is a direct sum of copies of Q2/Z2\mathbb{Q}_2/\mathbb{Z}_2 and splits as an abstract abelian subgroup. Its 2-torsion dimension is its corank. Lemma 2.1 therefore gives the displayed identity. The Cassels–Tate pairing on FF is perfect. For an elliptic curve, the rational divisor [O][O] defining its principal polarization makes the pairing alternating [46]. A finite abelian 2-group with such a pairing is an orthogonal sum of pairs of cyclic groups of equal order: choose an element of maximal order, pair it with an element detecting that order, split off their nondegenerate plane, and continue. Hence its 2-rank is even. A finite 2-group with zero 2-rank is zero, proving the last assertion. □

Arithmetic estimates for finite twist families

The pointwise converse will follow by placing the given curve at the zero vertex of a large finite family of twists. We arrange analytic nonvanishing at every other vertex, together with an upper bound on a normalized valuation. The estimates in this section explain which normalization is needed and what must be uniform as the family grows. Their proofs occupy Sections 11, 12 and 13.

Fix E/QE/\mathbb{Q} of conductor NN and retain the local weights w(h)w(h), finite Sha lengths s(h)s(h), and period-normalized values L(h)L(h) of Section 2. In particular s(h)s(h) is defined at a corank-zero base and at every twist already known to have analytic rank zero or one. All valuations satisfy v(2)=1v(2)=1.

A binary family has the form

hx=h0∏q∈Q(q∗)λq(x),x∈F2b,q∗=(−1/q)q,h_x=h_0\prod_{q\in\mathcal{Q}}(q^*)^{\lambda_q(x)},\qquad x\in\mathbb{F}_2^b,\qquad q^*=(-1/q)q,

where the new primes are distinct and prime to 2Nh02Nh_0, and each λq\lambda_q is linear. The old factors of h0h_0 remain at every vertex; no new factor is present at zero. We will hold the required local squareclasses fixed while bb grows. Both the set of primes and their sizes may depend on bb.

Here is the common transfer mechanism. For families satisfying the hypotheses of the transfer theorems below, the arithmetic proofs attach power series

ux(t)∈Z2[[t]][1/2]u_x(t)\in\mathbb{Z}_2[[t]][1/2]

to the vertices, using a common family of cochain models and compatible trivializations of the determinant lines. The differences of these coordinates therefore have a fixed meaning. Their constant terms detect the central value in rank zero or a Heegner point in rank one. If the analytic nonvanishing sought at the base fails, then u0(0)=0u_0(0)=0. The nonzero vertices instead satisfy v(ux(0))≤B1v(u_x(0))\leq B_1 with B1B_1 independent of bb. The denominator analysis proves that, for every fixed integer mm and sufficiently large bb, some x≠0x\ne0 satisfies

v(ux(0)−u0(0))≥m.v\bigl(u_x(0)-u_0(0)\bigr)\geq m.

Taking m>B1m>B_1 contradicts these two assertions. The work is to obtain this congruence with a dimension threshold independent of the number of new primes. Section 11 does so after the new local blocks have been eliminated from the Selmer complex: a clearing factor for the remaining bounded complex makes finitely many coefficient congruences sufficient. Only that clearing factor needs a uniform pole bound; the numerator may involve the whole prime set.

Transfer of a central value

For a twist with nonzero central value, put

D(h)=v(L(h))−2w(h)−s(h).(3)D(h)=v(L(h))-2w(h)-s(h). \tag*{(3)}

The subtraction records the local contributions of the ramified primes and the finite Selmer contribution. In the cyclotomic proof, Kato’s class and the invariant line at the real place form the determinant coordinate uxu_x. Its central valuation differs from D(hx)D(h_x) by a fixed bounded amount. Thus an upper bound on DD is exactly the arithmetic input to the preceding contradiction.

Theorem 3.1 (Cyclotomic missing vertex). There is a constant CEC_E, depending only on EE, with the following property. Fix an odd fundamental discriminant h0h_0, prime to 2N2N, with c2(E(h0))=0c_2(E(h_0))=0. Suppose that for arbitrarily large bb there is a family

hx=h0∏q∈Q(q∗)λq(x),x∈F2b,λq∈(F2b)∗,(4)h_x=h_0\prod_{q\in\mathcal{Q}}(q^*)^{\lambda_q(x)},\qquad x\in\mathbb{F}_2^b,\qquad\lambda_q\in(\mathbb{F}_2^b)^*, \tag*{(4)}

where Q\mathcal{Q} consists of distinct primes outside 2Nh02Nh_0, q∗=(−1q)qq^* = \left(\frac{-1}{q}\right)q, and every hxh_x has the same sign and the same local squareclasses at 2N2N. Assume that a constant BB, independent of bb, satisfies

L(E(hx),1)≠0,D(hx)≤B(x≠0).L(E^{(h_x)},1) \ne0,\qquad D(h_x) \le B \qquad(x \ne0).

If E[2]E[2] is irreducible, assume also that some LL, independent of bb, satisfies

v2(q2−1)≤L(q∈Q).(5)v_2(q^2-1) \le L \qquad(q \in\mathcal{Q}). \tag*{(5)}

Then L(E(h0),1)≠0L(E^{(h_0)},1) \ne0 and

D(h0)≤B+CE.D(h_0) \le B+C_E.

The necessary dimension may depend on h0h_0, its finite Selmer group, and the bound in (5); CEC_E does not.

The final constant CEC_E bounds the specialization error. The finite Selmer group of the base and, in the irreducible case, the bound on v2(q2−1)v_2(q^2-1) affect how large a cube is needed, but not this transferred error. We shall construct the nonzero vertices so that v(L(hx))≤2w(hx)+Cv(\mathcal{L}(h_x)) \le2w(h_x)+C; since s(hx)≥0s(h_x) \ge0, this supplies the hypothesis on D(hx)D(h_x).

Transfer of a Heegner point

In corank one the coordinate comes from a Heegner point. The family must also carry a companion twist whose central value is nonzero. We first specify the two Heegner constructions whose indices enter the estimates.

Let K=Q(k)K = \mathbb{Q}(\sqrt{k}), where k<0k < 0 is an odd fundamental discriminant and every prime dividing 2N2N splits in KK. We omit the two fields with extra units and, if EE has complex multiplication, its CM field. Fix a nonzero modular parametrization X0(N)→EX_0(N) \to E, translated so that the cusp ∞\infty maps to the origin, and compatible orientations of the Heegner points yc∈E(Hc)y_c \in E(H_c), where HcH_c is the ring class field of conductor cc. The Manin–Drinfeld theorem makes the images of cusp differences torsion [26]. Since the modular curve and parametrization are fixed, one integer kills all these images and removes cuspidal ambiguities.

If χe∣GK\chi_e|_{G_K} is a primitive ring class character of conductor cc, write Pc(e)P_c(e) for the character sum of ycy_c. Equivalently, twist over HcH_c and trace to E(e)(K)E^{(e)}(K). If this latter group has rank one, j(Pc(e))j(P_c(e)) is the valuation of its index on the free rank-one lattice. Passing between this lattice and the rank-one lattice of the contributing curve among E(e)(Q)E^{(e)}(\mathbb{Q}) and E(ek)(Q)E^{(ek)}(\mathbb{Q}) changes the index by a bounded amount: restriction and addition or subtraction of conjugates have composites multiplication by 22.

We use two choices of data:

genus data: k=hh∗k=hh_*, (h,h∗)=1(h,h_*)=1, e=h∗e=h_*, c=1c=1, h∗h_* fixed;

ring data: (k,h)=1(k,h)=1, e=he=h, c=∣h∣c=|h|.

The character in genus data is unramified. In ring data, restriction at each q∣hq\mid h has conductor exponent one: this follows by pulling the quadratic character back under the local norm. Thus these are the asserted primitive ring class conductors.

Proposition 3.2 (Comparison of the two Heegner constructions). For either set of data,

h^(Pc(e))=CEc∣k∣[L(E(e),s)L(E(ek),s)]s=1′.(6)\widehat{h}(P_c(e))=C_Ec\sqrt{|k|}\left[L(E^{(e)},s)L(E^{(ek)},s)\right]'_{s=1}. \tag*{(6)}

with a fixed nonzero constant determined by the parametrization and height conventions. In particular, a simple zero of the product gives total Mordell–Weil rank one and finite Shafarevich–Tate groups.

Suppose hh has analytic rank one, and use genus data with a fixed partner h∗h_{\ast} of analytic rank zero and ring data with a possibly varying kk, where L(Ehk,1)≠0L(E^{hk},1)\ne0. Then

2j(P∣h∣(h))−2j(P1(h∗))=ν(L(hk))+OE,h∗(1).(7)2j(P_{\lvert h\rvert}(h))-2j(P_1(h_{\ast}))=\nu(\mathcal{L}(hk))+O_{E,h_{\ast}}(1). \tag*{(7)}

Here the two points are formed in their respective quadratic fields. If instead h∗h_{\ast} has analytic rank one and L(Eh,1)≠0L(E^h,1)\ne0, genus data give

2j(P1(h∗))=ν(L(h))+OE,h∗(1).(8)2j(P_1(h_{\ast}))=\nu(\mathcal{L}(h))+O_{E,h_{\ast}}(1). \tag*{(8)}

The genus construction varies the quadratic field Q(hh∗)\mathbb{Q}(\sqrt{hh_{\ast}}) while holding h∗h_{\ast} fixed. It is the construction detected by the odd coefficients below. Interpolation instead uses the ring construction: within one binary family the field KK is common to every vertex. Equation (7) converts a genus-index estimate and an even central-value estimate into the ring-index estimate needed for transfer. The field KK may change when a new family is chosen.

Theorem 3.3 (Heegner interpolation). Fix EE and an initial discriminant h0h_0. Consider families hxh_x, x∈F2bx\in\mathbb{F}_2^b, obtained from h0h_0 by adjoining new prime factors with linear activation functions on F2b\mathbb{F}_2^b. No old factor is removed; the signed factor belonging to an odd prime qq is q∗=(−1/q)qq^{\ast}=(-1/q)q. Suppose the local twisting classes at 2N2N are constant. For each family let kk define an imaginary field satisfying the standing Heegner conditions, with (k,hx)=1(k,h_x)=1 for every xx. Each new prime must either split in KK or satisfy tq=0t_q=0.

Assume that the following bounds are fixed independently of bb:

(i) a bound for ω(k)\omega(k);

(ii) a bound for the length of the finite quotient of Sel⁡2∞(E(h0)/K)\operatorname{Sel}_{2^\infty}(E^{(h_0)}/K) by its divisible subgroup;

(iii) a constant BB.

Assume this base Selmer group has corank one. Suppose, for every x≠0x\ne0, the product L(Ehx,s)L(Ehxk,s)L(E^{h_x},s)L(E^{h_xk},s) has a simple zero and

2j(P∣hx∣(hx))−4w(hx)−s(hx)−s(hxk)≤B.(9)2j(P_{\lvert h_x\rvert}(h_x))-4w(h_x)-s(h_x)-s(h_xk)\le B. \tag*{(9)}

Then, for sufficiently large bb, the base product has a simple zero. The dimension threshold depends only on the fixed base and the displayed bounds, not on the number or sizes of the new primes. The field KK may vary with the family.

In these ring data, the relevant normalized quantity is

2j(P∣h∣(h))−4w(h)−s(h)−s(hk).2j(P_{\lvert h\rvert}(h))-4w(h)-s(h)-s(hk).

We use the theorem to prove nonvanishing at the base. In our applications, the genus-index and even central-value estimates will give 2j(P∣hx∣(hx))≤4w(hx)+C2j(P_{\lvert h_x\rvert}(h_x))\le4w(h_x)+C at every nonzero vertex. Subtracting the nonnegative Sha lengths supplies the required upper bound.

The finite-quotient condition allows two uses of the theorem. The rational-two-torsion argument fixes KK before increasing bb. The irreducible argument lets KK vary and verifies the following criterion.

Lemma 3.4. The finite-quotient bound in (3.3) holds if KK belongs to a fixed finite collection. It also holds if E(h0)E^{(h_0)} is fixed with Selmer corank one, the curves E(h0k)E^{(h_0k)} have analytic rank zero with bounded s(h0k)s(h_0k), and ω(k)\omega(k) is bounded.

Lower bounds and the coefficient constructions

The transfer criteria ask for upper bounds at a well-chosen set of twists. To find those twists, we first need lower bounds on all the normalized coefficients under consideration. In even sign a least normalized valuation can then be selected, and a coefficient attaining it gives both analytic nonvanishing and an upper bound with a constant independent of the prime support. In odd sign the coefficients come at increasing finite precision: the minimum is defined through bounded-weight sequences, and each use is realized on a finite collection of indices.

For the even coefficient construction, Section 4 relates twice a coefficient valuation to v(L(h))v(\mathcal{L}(h)) up to a fixed constant. For the odd construction it relates the coefficient valuation to the genus index. The following three lower estimates supply the normalizations, with different roles in the two residual cases.

When E[2]E[2] is reducible, the cyclotomic argument supplies the even lower estimate directly. By Lemma 2.3, the representation is then an extension of two trivial modules.

Theorem 3.5 (Cyclotomic lower bound). Suppose that E[2]E[2] is an extension of two trivial F2\mathbb{F}_2-modules. There is a constant CEC_E such that every odd fundamental discriminant hh prime to 2N2N with L(E(h),1)≠0L(E^{(h)},1) \ne0 satisfies

v(L(h))≥2w(h)+s(h)−CE.(10)v(\mathcal{L}(h)) \ge2w(h) + s(h) - C_E. \tag*{(10)}

The constant is independent of the number and sizes of the primes that divide hh.

When E[2]E[2] is irreducible, the genus construction supplies the lower estimate for either sign. With an analytic-rank-zero fixed partner, it bounds the odd genus index. With an analytic-rank-one fixed partner, (8) turns it into the even central-value bound.

Theorem 3.6 (Genus bound). In genus data, suppose the product in (6) has a simple zero and E[2]E[2] is irreducible. Then, uniformly in hh,

2j(P1(h∗))≥2w(h)+s(h)−OE,h∗(1).2j(P_1(h_*)) \ge2w(h) + s(h) - O_{E,h_*}(1).

In proving the uniform estimate, one may omit the finitely many hh for which KK meets Q(E[2])\mathbb{Q}(E[2]) nontrivially.

The remaining case is the odd coefficient construction with rational two-torsion. Here the genus estimate just stated is unavailable. We use instead the following ring estimate, whose residual representation is unrestricted.

Theorem 3.7 (Ring bound). In ring data, suppose the product in (6) has a simple zero, every q∣hq \mid h splits in KK, and ω(k)≤a\omega(k) \le a, where ω\omega counts distinct prime factors. Then

2j(P∣h∣(h))≥4w(h)+s(h)+s(hk)−OE,a(1).(11)2j(P_{\lvert h\rvert}(h)) \ge4w(h) + s(h) + s(hk) - O_{E,a}(1). \tag*{(11)}

There is no irreducibility assumption on E[2]E[2].

The passage from this ring estimate to an odd genus estimate is part of Proposition 7.7. The even coefficient construction first provides, for each already rank-one twist hh in the positive filter, a companion parameter k′k' satisfying the ring-bound hypotheses: it is negative, odd fundamental, coprime to 2Nh2Nh, a local square at every prime of 2Nh2Nh, and defines a nonexceptional imaginary field. Its prime count is bounded, and the companion obeys L(E(hk′),1)≠0L(E^{(hk')},1) \ne0 and

v(L(hk′))≤2w(hk′)+s(hk′)+C.v(\mathcal{L}(hk')) \le2w(hk') + s(hk') + C.

Substitute this upper bound into (7) and the ring lower bound. Since w(hk′)=w(h)+w(k′)w(hk') = w(h) + w(k') and w(k′)w(k') is bounded, the result is

2j(P1(h∗))≥2w(h)+s(h)−C′.2j(P_1(h_*)) \ge2w(h) + s(h) - C'.

Only then is the odd coefficient system normalized in the reducible branch. Thus the lower-bound dependencies are

irreducible genus bound ⟶\longrightarrow even and odd coefficient bounds,

reducible cyclotomic bound ⟶\longrightarrow even coefficients, then bounded companions,

ring bound and those companions ⟶\longrightarrow reducible odd coefficient bound.

The reducible odd normalization is therefore available after the even companion construction. The all-split hypothesis belongs to the ring lower bound used here. The Heegner transfer criterion retains its stated alternative for new primes with tq=0t_q = 0.

Auxiliary twists in prescribed local classes

The coefficient constructions also require an auxiliary twist with specified local classes. For even sign the number of its prime factors must remain bounded as the local conditions vary. The following nonvanishing result supplies both kinds of partner; its proof is given in Section 10.

Proposition 3.8 (Auxiliary nonvanishing). Let E/QE/\mathbb{Q} have conductor NN, and let SS be a finite set of primes containing the prime divisors of 2N2N. Prescribe a real sign σ∈{1,−1}\sigma\in\{1,-1\} and a unit squareclass cp∈Zp×/(Zp×)2c_p \in\mathbb{Z}_p^\times/(\mathbb{Z}_p^\times)^2 for each p∈Sp \in S. Suppose that these data are realized by an odd fundamental discriminant, and that twists in this filter have root number ϵ\epsilon. For every finite set BB of primes there are odd fundamental discriminants DD of arbitrarily large absolute value such that

sign⁡(D)=σ,[D]p=cp (p∈S),p∤D (p∈B),\operatorname{sign}(D) = \sigma,\qquad[D]_p = c_p\ (p \in S),\qquad p \nmid D\ (p \in B),

Moreover:

(i) If ϵ=1\epsilon= 1, they can be chosen with L(E(D),1)≠0L(E^{(D)},1) \ne0 and ω(∣D∣)≤5\omega(|D|) \le5.

(ii) If ϵ=−1\epsilon= -1, they can be chosen with L′(E(D),1)≠0L'(E^{(D)},1) \ne0, so the central zero is simple.

The bound five in (i) is independent of EE, SS, BB and the prescribed classes. In either case, every prime factor of DD can be required to exceed any previously fixed bound.

Coefficients that detect analytic rank

The interpolation theorems require nonvanishing with a uniform valuation bound at the nonzero vertices of a cube. We encode both requirements in one binary coefficient: it is one when a modular coefficient has the least normalized valuation. Waldspurger’s formula supplies the even-sign coefficients; reduction of genus Heegner sums supplies the odd-sign coefficients at finite precision. We prove their modular and arithmetic properties separately before choosing this normalization.

Filters and prime weights

Fix E/QE/\mathbb{Q} and a finite set SS containing the primes of 2N2N and the ramification set of F=Q(E[2])F = \mathbb{Q}(E[2]). Additional fixed primes may be included. A filter consists of a sign σ∈{1,−1}\sigma\in\{1,-1\} and unit squareclasses at the primes in SS, imposed on positive squarefree integers DD prime to SS, so that

h=σDh=\sigma D

is an odd fundamental discriminant and the functional sign of E(h)E^{(h)} is constant. Multiplication by squares of units preserves the local conditions. We impose these conditions on all Fourier indices, not only on squarefree ones. Projections onto the required unit squareclasses are finite combinations of quadratic coefficient twists and coprimality projections; they enlarge the level only at SS.

For p∉Sp \notin S, the action on V=E[2]V=E[2] has the following three types:

typeFr⁡p∣V\operatorname{Fr}_p \mid Vweight
split1111
simplean element of order 221/21/2
rootan element of order 3300

Table 1.

Thus w(D)=12∑p∣Ddim⁡F2VFr⁡p=w(h)w(D)=\frac{1}{2}\sum_{p\mid D}\dim_{\mathbb{F}_2}V^{\operatorname{Fr}_p}=w(h). The fractional part of w(D)w(D) is constant on a filter: it is determined by the quadratic discriminant character of the residual representation. For an arbitrary squarefree set of primes we use the same additive weight. Signs are encoded by p∗=(−1/p)pp^*=(-1/p)p, so that h=∏p∣Dp∗h=\prod_{p\mid D}p^*.

We use the ordinary theta multiplier cubed in weight 3/23/2. A finite idele unit character and its Dirichlet character are related by the reciprocal convention: if a finite Schwartz function obeys f(ux)=α(u)f(x)f(ux)=\alpha(u)f(x), its scalar classical character on the lower-right entry is associated to α−1\alpha^{-1}. All valuations satisfy v(2)=1v(2)=1.

The even coefficient system

Proposition 4.1 (Even coefficients). Fix a nonempty filter with even functional sign. There are a holomorphic weight-3/23/2 cusp form

g=∑n≥1a(n)qng=\sum_{n\geq1}a(n)q^n

of level supported on SS, after enlarging exponents at those primes, and finite-order characters ψ,η\psi,\eta of 22-power order, with ψ/η\psi/\eta quadratic, having the following properties.

(i) The coefficients vanish off the filter and, for p∉Sp\notin S,

a(p2n)=(η(p)ap(E)−ψ(p)(−n/p))a(n)−pη(p)2a(n/p2).a(p^2n)=\bigl(\eta(p)a_p(E)-\psi(p)(-n/p)\bigr)a(n)-p\eta(p)^2a(n/p^2).

As usual a coefficient with a nonintegral index is zero.

(ii) After normalizing at one nonzero squarefree index, every squarefree coefficient in the filter is a rational number times a root of unity of 22-power order. For a fixed nonzero squarefree index D0D_0,

2v(a(D)a(D0))=v(L(σD)L(σD0))(12)2v\left(\frac{a(D)}{a(D_0)}\right)=v\left(\frac{L(\sigma D)}{L(\sigma D_0)}\right) \tag*{(12)}

whenever a(D)≠0a(D)\ne0.

Equivalently, there is a constant cgc_g, independent of DD, such that

2v(a(D))=v(L(h))+cg.(13)2v(a(D))=v(L(h))+c_g. \tag*{(13)}

In particular a(D)≠0a(D)\ne0 if and only if L(E(h),1)≠0L(E^{(h)},1)\ne0.

(iii) After the fixed auxiliary exclusions described below, there is a constant CgC_g such that, at every nonzero squarefree coefficient,

v(a(D))≥w(D)+12s(h)−Cg.(14)v(a(D)) \ge w(D) + \frac{1}{2}s(h) - C_g. \tag*{(14)}

The constants depend on the fixed curve, filter and auxiliary choices, and not on DD or its number of prime factors.

Proof. We first choose the packet member and its local characters. We then establish the rationality up to phase needed for valuation comparisons, apply the coefficient-square formula, and deduce the uniform lower bound from the interpolation estimates.

Use the Shimura packet attached to the integral-weight newform of E(−σ)E^{(-\sigma)}. In the classical convention its positive Fourier index DD tests the twist by χ−D\chi_{-D}, hence the curve E(σD)E^{(\sigma D)}. The packet and Fourier coefficient results of Waldspurger [76, 77] apply to the cuspidal packet orthogonal to unary theta series. Their local uniqueness and global multiplicity assertions are summarized in [78], Sections 3.1 and 5.1. A nonzero central value in the filter exists by Proposition 3.8. It selects a globally occurring packet member with nonzero Fourier functional at that index. At good odd primes choose spherical vectors; at infinity choose the holomorphic vector of weight 3/23/2.

We explain the choices at a prime of SS. Let λD\lambda_D be a nonzero local Fourier functional and start with a vector on which it is nonzero. Average upper-unipotent translates against the inverse additive character of frequency DD. If the averaging compact subgroup is sufficiently large, its translate by a unit scale uu can contribute only when u2u^2 is sufficiently close to 1. The surviving scales are consequently small neighborhoods of 1 and −1-1. Local constancy then permits projection onto a unit character which matches the forced action of −1-1, without killing the Fourier value: the contributions of the two neighborhoods add. Such a character may be chosen to have 2-power order. Indeed only its parity is prescribed, and the 2-primary quotient of the unit group realizes either possible parity. Upper averaging at integral frequency gives period one, and lower-unipotent invariance holds at sufficiently large depth. These vectors therefore give a classical form at a level supported on SS. The parity conditions combine correctly by automorphy. The subsequent squareclass projections preserve its character. Write that character as ψ\psi.

In the theta-multiplier convention the good eigenvalues of the packet are ψ(p)\psi(p) times those of E(−σ)E^{(-\sigma)}. Set η=ψχ−σ\eta=\psi\chi_{-\sigma}. Then ψ/η\psi/\eta is quadratic and the weight-3/23/2 Hecke formula gives (4.1).

We need more than algebraicity of the coefficients. After normalization at one squarefree index, their nonzero squarefree valuations must be integers, so that a strict valuation inequality gains a full factor of 2, even when the character field is ramified. We prove this by showing that every such coefficient is rational up to a phase of 2-power order. At the fixed level, the weight-3/23/2 cusp space with character ψ\psi has a basis over the field of character values, and coefficient conjugation changes ψ\psi to its conjugate [64], Section 2, Lemma 4(3)–(4), pp. 658–659. The good Hecke equations and the vanishing of coefficients off the filter are linear equations over Q(ψ,η)\mathbb{Q}(\psi,\eta). In a finite-dimensional space, finitely many of these equations cut out their full common kernel. The constructed complex vector has a nonzero coefficient at a squarefree index D0D_0 of the filter, so this coefficient functional is nonzero on some algebraic vector in that kernel. Choose such a vector. It remains orthogonal to unary theta series: at good primes their eigenvalues have absolute value p+1p+1, whereas the prescribed eigenvalues have absolute value at most 2p2\sqrt{p} by Hasse’s bound [60], Section 2, Lemma 2.1, and Corollary 5.2.

We use Waldspurger [77], Corollary 2, pp. 483–484 to compare Fourier coefficients. Its hypothesis (H1) holds for every nonzero classical eigenspace used here, by Proposition 2 of that paper. The final paragraph of the corollary’s proof removes (H2) when the indices lie in the same local squareclass at every level prime. Our filters retain this condition at 2 as well as at the odd primes.

Let uu be an automorphism of Q‾\overline{\mathbb{Q}} acting by an odd power ee on the 2-power characters, and put ν=η(e−1)/2\nu=\eta^{(e-1)/2}. The coefficient conjugate gug^u and coefficient twist g⊗νg\otimes\nu have exactly the same character and good Hecke system, since

ψν2=ψηe−1=ψe,ην2=ηe.\psi\nu^2=\psi\eta^{e-1}=\psi^e,\qquad\eta\nu^2=\eta^e.

They may be compared at a common level supported on SS, in the same good Hecke eigenspace WW, and both have a nonzero D0D_0-coefficient. Let ℓn:W→C\ell_n:W\to\mathbb{C} denote the nnth Fourier-coefficient functional. Waldspurger’s corollary applies to every f∈Wf\in W and gives

ℓD(f)2=CDℓD0(f)2.\ell_D(f)^2=C_D\ell_{D_0}(f)^2.

where CDC_D is independent of ff. If CD=0C_D=0, then ℓD=0\ell_D=0. Otherwise choose cD∈Cc_D\in\mathbb{C} with cD2=CDc_D^2=C_D and factor the identity as

(ℓD−cDℓD0)(ℓD+cDℓD0)=0.(\ell_D-c_D\ell_{D_0})(\ell_D+c_D\ell_{D_0})=0.

The polynomial ring on WW is an integral domain, so one factor vanishes identically. Thus the two coefficient functionals are proportional on the whole space, including oldvectors and linear combinations. In particular the two forms have the same ratio of their DD- and D0D_0-coefficients.

It follows, for ξ=a(D)/a(D0)\xi=a(D)/a(D_0), that

u(ξ)=ν(D/D0)ξ.u(\xi)=\nu(D/D_0)\xi.

The local squareclass conditions imply η(D/D0)=z2\eta(D/D_0)=z^2 for a value zz in the group of values of η\eta. Consequently u(ξ/z)=ξ/zu(\xi/z)=\xi/z for every uu, so ξ/z∈Q\xi/z\in\mathbb{Q}. This proves the phase assertion.

With our characters and period normalization, its identity of coefficient squares is

(a(D)a(D0))2=ψ(D/D0)L(σD)L(σD0).(15)\left(\frac{a(D)}{a(D_0)}\right)^2=\psi(D/D_0)\frac{\mathcal{L}(\sigma_D)}{\mathcal{L}(\sigma_{D_0})}. \tag*{(15)}

Here ψ(D/D0)=ψ(D)ψ(D0)−1\psi(D/D_0)=\psi(D)\psi(D_0)^{-1} has valuation zero; the factor D/D0\sqrt{D/D_0} in the classical central-value comparison is incorporated in L\mathcal{L}. The local unit squareclasses at SS agree; at a good prime the spherical squarefree factor is one at both valuations zero and one [77]. There is consequently no extra product over the prime factors of DD. Taking valuations gives Equation (12), hence Equation (13). The same identity, compared with the nonzero coefficient at D0D_0, gives the asserted equivalence of vanishing. The corresponding rational-square statement for central values is Vignéras’s rationality theorem, recalled in Waldspurger [78]. If E[2]E[2] is an extension of trivial modules, combine Equation (13) with Theorem 3.5. If E[2]E[2] is irreducible, choose a fixed odd fundamental discriminant h∗h_* of opposite infinite sign, of analytic rank one, whose local characters agree with those of hh at 2N2N. Proposition 3.8 supplies such a choice. Exclude its prime factors from the filter and choose its support to avoid the finitely many exceptional genus fields. The reverse genus comparison in Proposition 3.2 and Theorem 3.6 give the same lower bound. These are fixed exclusions and constants, proving Equation (14) in both cases. ∲襪

Odd coefficients from reduction of Heegner traces

The odd construction combines reduction of Heegner points with the ternary quadratic forms attached to definite quaternion orders. We use Deuring’s reduction correspondence in the oriented form of Cornut–Jetchev, together with the Eichler-order and ternary-form description of Jetchev–Kane [21, 24, 37]. The weights below retain the genus character and the local orientations, so that the resulting Fourier coefficients recover the reduced genus sum at finite precision.

Fix now a nonempty filter of odd functional sign. Choose an odd fundamental h∗h_* of opposite infinite sign, with L(E(h∗),1)≠0L(E^{(h_*)},1) \ne0, whose local characters agree with those of hh at 2N2N. Exclude its primes. We may choose ∣h∗∣>3|h_*| > 3 and include in its support a prime outside the exceptional imaginary quadratic discriminants. Thus all genus fields below have only the units {1,−1}\{1,-1\} and avoid the CM field of EE. Write

k=hh∗<0,KD=Q(k),PD=P1(h∗).k=hh_*<0,\qquad K_D=\mathbb{Q}(\sqrt{k}),\qquad P_D=P_1(h_*).

The point PDP_D is the character sum of the conductor-one Heegner point for KDK_D. We fix the modular parametrization φ\varphi with φ(∞)=0\varphi(\infty)=0, so the constants in its Hecke and Atkin–Lehner relations are torsion. At a simple zero of E(h)E^{(h)}, its free line is that of E(h)E^{(h)}, up to the fixed-degree identifications in Proposition 3.2. Below, the product derivative means the derivative at s=1s=1 of L(E(h),s)L(E(h∗),s)L(E^{(h)},s)L(E^{(h_*)},s).

Proposition 4.2 (Odd coefficients under a genus-index bound). Assume that a constant C∗C_* satisfies

j(PD)≥w(D)+12s(h)−C∗(16)j(P_D)\ge w(D)+\frac{1}{2}s(h)-C_* \tag*{(16)}

for every hh in the filter with a simple zero. There are arbitrarily large precisions MM, good odd primes ℓ\ell outside the fixed support, and holomorphic weight-3/2 forms gM=∑aM(n)qng_M=\sum a_M(n)q^n, of level supported on S∪{ℓ}S\cup\{\ell\}, with the following properties.

(i) The additional filter at ℓ\ell is

(h∗ℓ)=−σ,(hℓ)=σ,ρT(Fr⁡ℓ)≡C(mod2M),(17)\left(\frac{h_*}{\ell}\right)=-\sigma,\qquad\left(\frac{h}{\ell}\right)=\sigma,\qquad\rho_T(\operatorname{Fr}_{\ell})\equiv C\pmod{2^M}, \tag*{(17)}

where CC is the action of a complex conjugation. In particular ℓ≡−1(mod2M)\ell\equiv-1\pmod{2^M}.

(ii) After a fixed harmless decrease in the working precision, the forms satisfy Equation (4.1) modulo that precision, with characters ηM,ψM\eta_M,\psi_M of 2-power order and quadratic ratio. Their squarefree coefficients have the form of a 2-power phase times an integer modulo 2M2^M.

(iii) If a coefficient is visible, meaning v(aM(D))<Mv(a_M(D))<M, then E(h)E^{(h)} has a simple zero and

j(PD)≤v(aM(D))+C1.(18)j(P_D)\le v(a_M(D))+C_1. \tag*{(18)}

For every admissible DD the coefficient lower bound is

v(aM(D))≥min⁡{M,w(D)+12s(h)−C2}(19)v(a_M(D))\ge\min\left\{M,w(D)+\frac{1}{2}s(h)-C_2\right\} \tag*{(19)}

when the product derivative is nonzero; if it is zero, the coefficient is zero modulo 2M2^M. Here C1,C2C_1,C_2 are independent of ℓ,M,D\ell,M,D.

(iv) A fixed squarefree witness DwD_w in the original filter is admissible at every chosen ℓ\ell and has v(aM(Dw))v(a_M(D_w)) bounded as M→∞M\to\infty.

For irreducible E[2]E[2], the hypothesis is Theorem 3.6. For rational two-torsion, the positive filters used in the pointwise argument have this bound by Proposition 7.7, using only the even source. An arbitrary twist is first absorbed into the fixed curve, so only these positive filters are needed there.

Proof. The proof has three stages. A reduction map detects one fixed nonzero genus point at arbitrarily high precisions. Weighted theta series then supply holomorphic forms with the required Hecke recurrence. Finally, an exact comparison with genus sums transfers point divisibility and the assumed lower bound to their squarefree coefficients.

The reduction map and a detecting sequence. Choose a nonzero integral row bb with bC=σbbC=\sigma b. Under Equation (17), finite-field Kummer theory gives

κM:E(Fℓ2)⟶H1(Fℓ2,E[2M])=E[2M]/(Fr⁡ℓ2−1)E[2M]=E[2M].\kappa_M:E(\mathbb{F}_{\ell^2})\longrightarrow H^1(\mathbb{F}_{\ell^2},E[2^M])=E[2^M]/(\operatorname{Fr}_{\ell}^2-1)E[2^M]=E[2^M].

The last identification is evaluation at arithmetic Frobenius squared. Put λM=bκM\lambda_M=b\kappa_M. This map has Frobenius sign σ\sigma.

Choose hw=σDwh_w=\sigma D_w in the original filter with a simple zero, using Proposition 3.8. A fixed multiple of its genus point is a nonzero point on the rational curve E(hw)E(h_w). Its division cocycle has open translation image on the kernel of the Tate action, even after fixed finite auxiliary fields have been adjoined. Here is the relevant argument. The translation image is a Galois-stable Z2\mathbb{Z}_2-submodule of the Tate module. Its rational span is nonzero: otherwise the point’s Kummer class would factor through the Tate image; that image has a central nonidentity scalar, which kills its rational first cohomology, contradicting Kummer injectivity. The rational Tate representation is irreducible by Serre [62], since End⁡Q(E)=Z\operatorname{End}_{\mathbb{Q}}(E)=\mathbb{Z}. This includes curves with geometric complex multiplication, whose nonreal endomorphisms are not defined over Q\mathbb{Q}. The scalar Lie-algebra assertion of Bogomolov [5], followed by local logarithm and exponential, supplies the required nonidentity scalar. The nonzero stable span is therefore the whole Tate module. The translation image consequently contains a full lattice. Passing to a finite-index subgroup preserves this fact.

Take an element acting as CC on TT and as complex conjugation on the fixed quadratic character fields, and modify it by such a translation. On the twisted module for hwh_w, its action is σC\sigma C; at its square the cocycle includes 1+σC1+\sigma C. Projection by bb is twice the corresponding nonzero row. We can therefore arrange nonzero detection with a fixed finite valuation. Chebotarev, applied at successive finite precisions to this fixed compatible Galois element and its division data, supplies arbitrarily large primes satisfying Equation (17), also with h=hwh=h_w, and the asserted bounded detection. A congruence on the target curve’s Frobenius is all that is required. The supersingular objects used next are points of the modular curve, not an additional reduction hypothesis on EE.

Supersingular values and local weights. Let BB be the quaternion algebra ramified at ℓ\ell and infinity, and let RR be an Eichler order of level NN. Supersingular pairs on X0(N)X_0(N) are parametrized by

B×\B^×/R^×.B^\times\backslash\widehat{B}^{\times}/\widehat{R}^{\times}.

They are defined over Fℓ2\mathbb{F}_{\ell^2}. The reduction and Eichler order descriptions apply to arbitrary NN prime to ℓ\ell; see [37], Sections 1.1–1.2 and 2.5. For a representative zz write Rz=B∩zR^z−1R_z=B\cap z\widehat{R}z^{-1} and let PM(z)P_M(z) be the reduced modular-parametrization value followed by λM\lambda_M. The cusp differences have torsion image by Drinfeld [26], Section 1. Multiply the parametrization once by a fixed integer LL killing the cuspidal constants in its Hecke and Atkin–Lehner relations and the bounded-degree torsion occurring in genus sums. This choice is independent of D,ℓ,MD,\ell,M.

The resulting PMP_M has good Brandt eigenvalues ap(E)a_p(E), level Atkin–Lehner eigenvalues wpew_{p^e} for pe∥Np^e\Vert N, and eigenvalue σ\sigma for the right uniformizer at ℓ\ell. These identities hold modulo 2M2^{M}. Choose integer representatives of its values when making an ordinary characteristic-zero theta series.

On B0B^{0}, the trace-zero subspace, use the positive definite quadratic form Q(x)=−x2=Nrd⁡(x)Q(x)=-x^{2}=\operatorname{Nrd}(x). Our aim is to make the squarefree coefficient aM(D)a_{M}(D) equal, modulo 2M2^{M} and up to a phase of 22-power order, to a fixed integer multiple of

λM(red⁡ℓ(LPD)).\lambda_{M}\bigl(\operatorname{red}_{\ell}(LP_{D})\bigr).

We will identify its terms with optimal embeddings of OKD\mathcal{O}_{K_{D}}. Their local orientations give several copies of the genus sum. The weights must make those copies contribute equally, while their unit-scaling law must give a scalar modular character. The weighted trace calculation below will determine the exact multiplier.

Define a finite compactly supported, locally constant weight f=∏fpf=\prod f_{p} as follows; a value not satisfying a listed condition is zero.

(a) Away from 2Nh∗ℓ2Nh_{*}\ell, require order integrality and put fp=1f_{p}=1.

(b) At 22, require (1+x)/2(1+x)/2 to be integral and x2x^{2} to be a split fundamental unit squareclass. At pe∥Np^{e}\parallel N, require the split fundamental unit type and its order embedding. The cyclic Eichler level line selects one of the two eigenroots rr of xx; weight it by a 22-power unit character ηp(r)\eta_{p}(r) with

ηp(−1)=wpeχh∗(p)e.\eta_{p}(-1)=w_{p^{e}}\chi_{h_{*}}(p)^{e}.

If p=2p=2, use the selected summand of (1+x)/2(1+x)/2, whose eigenvalues (1+r)/2(1+r)/2 and (1−r)/2(1-r)/2 differ by the odd unit rr. Scaling by an odd uu sends this operator to u(1+x)/2+(1−u)/2u(1+x)/2+(1-u)/2 and preserves that summand; its selected root for uxux is urur. Thus the weight changes by η2(u)\eta_{2}(u), even when the two eigenvalue parities interchange. If 2∤N2\nmid N, impose only the stated integrality restriction.

(c) At p∣h∗p\mid h_{*} require integral xx with determinant of valuation one. Its reduction is nonzero nilpotent. On that orbit use the sign which transforms by (det⁡u/p)(\det u/p) under conjugation by u∈GL⁡2(Zp)u\in\operatorname{GL}_{2}(\mathbb{Z}_{p}). This sign exists because the stabilizer of a nonzero nilpotent has the form aI+bXaI+bX and determinant a2a^{2}. Scaling xx by a unit uu changes this sign by (u/p)(u/p).

(d) At ℓ\ell require integral unit norm and the unramified quadratic type. Choose a basis of the trace-zero line in Fℓ2\mathbb{F}_{\ell^{2}} and weight the nonzero residue on that line by its Legendre symbol relative to the basis.

All these conditions may be imposed at finite depth. They are stable under unit scaling. Right order-unit conjugation changes ff by the inverse of χh∗∘Nrd⁡\chi_{h_{*}}\circ\operatorname{Nrd}, exactly canceling the norm character below. At ℓ\ell, order units commute on the residue field, while a uniformizer negates its trace-zero line. Since ℓ≡−1(mod4)\ell\equiv-1\pmod{4}, the latter weight changes by −1-1.

Write αB=∏pαp\alpha_{B}=\prod_{p}\alpha_{p} for the finite unit-scaling character, so that f(ux)=αB(u)f(x)f(ux)=\alpha_{B}(u)f(x). Define the classical Dirichlet character ηB\eta_{B} by

ηB(d)=∏pαp(d)for integers d prime to the support.\eta_{B}(d)=\prod_{p}\alpha_{p}(d)\qquad\text{for integers $d$ prime to the support.}

The associated finite idele character restricts to αB−1\alpha_{B}^{-1} on the ramified unit groups, in accordance with our reciprocal convention. Both characters are even. Indeed their value on −1-1 is

(∏pe∥Nwpeχh∗(p)e)χh∗(−1)(−1)=1,\left(\prod_{p^{e}\parallel N}w_{p^{e}}\chi_{h_{*}}(p)^{e}\right)\chi_{h_{*}}(-1)(-1)=1,

by the even functional sign of E(h∗)E(h_{*}). The characters have 22-power order.

Transformation and good Hecke relation. Choose a fixed positive integer c0c_0 divisible by the orders of all unit groups which occur. Such a choice is uniform: a unit group of a rational definite quaternion order has bounded order. Form

HM(n)=c0∑zPM(z)χh∗(Nrd⁡z)∣Rz×∣∑x∈B0−x2=nf(z−1xz),HM(τ)=∑n≥1HM(n)qn.(20)H_M(n)=c_0\sum_z\frac{P_M(z)\chi_{h_*}(\operatorname{Nrd} z)}{\lvert R_z^\times\rvert}\sum_{\substack{x\in B^0\\-x^2=n}}f(z^{-1}xz),\qquad H_M(\tau)=\sum_{n\geq1}H_M(n)q^n. \tag*{(20)}

The norm character is trivial on rational B×B^\times, since its rational reduced norms are positive. The right transformation just checked makes Equation (20) independent of the representatives.

For scalar modularity, apply the Weil representation of (B0,Q)(B^0,Q) to ff and the Gaussian at infinity [80]. At a finite prime, with the additive character of conductor Zp\mathbb{Z}_p, the local formulas are [58], Section 4.3, pp. 1965–1966

ω(n(b))fp(x)=ep(bQ(x))fp(x),\omega(n(b))f_p(x)=e_p(bQ(x))f_p(x),
ω(m(u))fp(x)=γp(u)∣u∣p3/2fp(ux),ω(w)fp=γpfp^.\omega(m(u))f_p(x)=\gamma_p(u)\lvert u\rvert_p^{3/2}f_p(ux),\qquad\omega(w)f_p=\gamma_p\widehat{f_p}.

Here n(b)=(1b01)n(b)=\begin{pmatrix}1&b\\0&1\end{pmatrix}, m(u)=diag⁡(u,u−1)m(u)=\operatorname{diag}(u,u^{-1}), and ww is the Weyl element. Integral bb fixes fpf_p, since QQ is integral on its support. Choose a lattice of translation invariance for fpf_p; its dual contains the support of fp^\widehat{f_p}. For sufficiently large apa_p, the form papQp^{a_p}Q is integral on that dual lattice. Thus n(p−apb)n(p^{-a_p}b) fixes fp^\widehat{f_p}, and conjugation by ww proves invariance under sufficiently deep lower unipotents. This argument also works at 22 and at arbitrary finite character depth.

Compare with the threefold ordinary-theta reference line, using the same additive character and lifts. In a presentation B=(−a,−b)B=(-a,-b), the quadratic form is aX2+bY2+abZ2aX^2+bY^2+abZ^2. The ratio of its diagonal Weil factor to the reference factor is

(a,u)p(b,u)p(ab,u)p=((ab)2,u)p=1.(a,u)_p(b,u)_p(ab,u)_p=((ab)^2,u)_p=1.

This calculation holds also over Q2\mathbb{Q}_2. The remaining local diagonal scalar is therefore αp(u)\alpha_p(u). Upper unipotents, diagonal units, and sufficiently deep lower unipotents generate the required local Γ0\Gamma_0 subgroup: explicitly, for aa a unit,

(abcd)=n− ⁣(−ca)m(a)n ⁣(ba).\begin{pmatrix}a&b\\c&d\end{pmatrix}=n^-\!\left(-\frac{c}{a}\right)m(a)n\!\left(\frac{b}{a}\right).

Choose the depths also to serve the ordinary-theta reference line and the character conductors. The central ambiguity of the metaplectic lifts cancels in the comparison, since both representations have the same odd central action. At the chosen depth, aa is congruent to d−1d^{-1} modulo the character conductor, so the local right eigenvalue is αp(d)−1\alpha_p(d)^{-1}. Classical restriction uses the inverse finite component and consequently gives the character ηB(d)\eta_B(d). Conjugation by zz preserves QQ and commutes with the Weil action, so all summands have this same level and scalar character. At good odd primes the lattice is spherical. The Gaussian gives weight 3/23/2, and positive definiteness gives holomorphy at every cusp. Thus HMH_M is a classical form of level supported on 2Nh∗ℓ2N h_*\ell.

At a prime p∤2Nh∗ℓp\nmid2N h_*\ell, the neighbor relation has Hecke eigenvalue

ηB(p)χh∗(p)ap(E).\eta_B(p)\chi_{h_*}(p)a_p(E).

The factor χh∗(p)\chi_{h_*}(p) comes from the reduced norm of a Brandt neighbor and ηB(p)\eta_B(p) from scaling at the other primes.

The multiplicities can be read directly in a matrix order. Put y=pxy=px. If yy is primitive and Q(y)Q(y) is divisible by p2p^2, its nonzero nilpotent reduction has a unique invariant line; in a basis adapted to that line the other off-diagonal entry is divisible by p2p^2, so exactly one neighbor makes y/py/p integral. If y/py/p is integral, its reduction has 1+(−Q(y/p)/p)1+(-Q(y/p)/p) invariant lines, except that a zero reduction has a further pp lines. These are precisely the middle and last terms of the weight-3/2 Hecke recurrence. The factors ∣RZ×∣−1\lvert R_{\mathbb{Z}}^{\times}\rvert^{-1} are the orbit-stabilizer factors making the Brandt transfer valid. Since the eigenrelation for PMP_M holds modulo 2M2^M, so does this relation for HMH_M.

Put d=∣h∗∣d=\lvert h_*\rvert. The weights force Q(x)Q(x) to be divisible by dd. Before the final filter projections, the series with coefficients aM(n)=HM(dn)a_M(n)=H_M(dn) is the same weighted theta sum for Q/dQ/d. Its ternary determinant changes by d−3d^{-3}, whose squareclass is dd; hence the scalar character acquires (d/⋅)(d/\cdot). Substitution of dndn in the good-prime recurrence leaves ηBχh∗\eta_B\chi_{h_*} unchanged. Now apply the filter projections. Extraction of these multiples changes the character to ψM=ηB(∣h∗∣/⋅)\psi_M=\eta_B(\lvert h_*\rvert/\cdot), while ηM=ηBχh∗\eta_M=\eta_B\chi_{h_*} is the good eigenvalue character. Their quotient is quadratic. The neighbor relation therefore becomes (4.1). Every operation has level supported on S∪{ℓ}S\cup\{\ell\}.

The weighted trace identity. The form and its recurrence are now constructed. We next identify a squarefree coefficient with the reduction of the original genus sum, keeping the orientation multiplicities and unit stabilizers explicit.

For a squarefree DD in the filter, put n=∣h∗∣D=−kn=\lvert h_*\rvert D=-k. An xx counted in (20) is exactly an optimal embedding of the full order OKD\mathcal{O}_{K_D} into RzR_z, by sending k\sqrt{k} to xx. At 2 the generator is (1+k)/2(1+\sqrt{k})/2, which is why the integrality condition above is necessary. At a split level prime there are two choices of cyclic level orientation, and at ℓ\ell there are two choices of unramified quadratic orientation. There is one local orbit at the remaining primes. The split-level assertion follows by decomposing a stable lattice into its two idempotent summands: a cyclic quotient of order pep^e forces all of that quotient into one summand. The division-prime assertion follows from the two reduced-norm parity cosets. At primes outside 2Nh∗ℓ2Nh_*\ell, stable lattices are the fractional ideals of the quadratic order, giving the single local orbit.

Fix one orientation tuple and a rational embedding x0x_0. The corresponding global optimal-embedding orbits are parametrized by Pic⁡(OKD)\operatorname{Pic}(\mathcal{O}_{K_D}). Explicitly, once one adelic representative z0z_0 is fixed, the representatives are za=az0z_a=az_0 with a∈K^D×a\in\widehat{K}_D^\times; changing aa by KD×K_D^\times or O^KD×\widehat{\mathcal{O}}_{K_D}^{\times} gives exactly the same class. Because aa commutes with x0x_0, the Schwartz factor is constant along this class-group orbit. Its remaining relative weight is

χh∗(Nrd⁡a)=χh∗(Norm⁡KD/Qa).\chi_{h_*}(\operatorname{Nrd}a)=\chi_{h_*}(\operatorname{Norm}_{K_D/\mathbb{Q}}a).

the unramified genus character. This computation establishes the weighted identity, rather than merely an unweighted correspondence.

For completeness the stabilizer factor is also exact. Each orbit of embeddings in a given RzR_z has ∣Rz×/OKD×∣=∣Rz×∣/2\lvert R_z^\times/\mathcal{O}_{K_D}^\times\rvert=\lvert R_z^\times\rvert/2 elements. Thus its contribution after division by ∣Rz×∣\lvert R_z^\times\rvert is one half of the corresponding class-group term. These are oriented embeddings, not conjugate pairs: xx and −x-x have opposite orientations at ℓ\ell and cannot be conjugate by an order unit, whose residue conjugation on Fℓ2\mathbb{F}_{\ell^2} is trivial. CM reduction at the inert prime identifies these terms with the reductions of the Heegner points and commutes with ideal action; the cyclic subgroup carries the selected level orientation. Fixing the residue-field identification at ℓ\ell retains its orientation in the reduction-to-embedding correspondence of Deuring [24]; see [21], arXiv version 1, Theorem 3.1, Corollary 3.2, and Section 3.6, Remark 1 and [37], Sections 2.4–2.6 and 4.1]. The former remark explains that forgetting this identification identifies conjugate embeddings. Here both orientations remain in the theta sum.

Choose the initial orientation to agree with the Heegner point defining PDP_D. The constant weight on its orbit is a phase ζM(D)∈μ2∞\zeta_M(D) \in\mu_{2^\infty}, since all its local weights are units. Changing orientation at pe∥Np^e \Vert N multiplies the Schwartz factor by wpeχh∗(p)ew_{p^e}\chi_{h^*}(p)^e, and multiplies the norm-character-weighted parametrization value by the same sign. At ℓ\ell both signs are −1-1, since σχh∗(ℓ)=−1\sigma_{\chi_{h^*}}(\ell) = -1. Hence every one of the 2ω(N)+12^{\omega(N)+1} orientation tuples contributes the same term. With the fixed multiplier LL already incorporated into PMP_M, the comparison is consequently

aM(D)=c02ω(N)ζM(D)λM(red⁡ℓ(LPD))(mod2M).a_M(D) = c_0 2^{\omega(N)}\zeta_M(D)\lambda_M\left(\operatorname{red}_{\ell}(LP_D)\right) \pmod{2^M}.

The initial basis at ℓ\ell and initial orientation affect only ζM(D)\zeta_M(D). Formula (4.11) specifies the normalization using a character sum, with no class-number denominator. All rational multipliers are fixed independently of DD and ℓ\ell.

If the product derivative is zero, Gross–Zagier makes PDP_D torsion. The fixed multiplier kills it: genus sums and their twist comparisons are defined over biquadratic fields. The torsion of a fixed elliptic curve in degree at most four is uniformly bounded, as one sees by reducing its prime-to-residue-characteristic torsion at two fixed good primes of distinct residue characteristic; the residue degrees are at most four. Thus the coefficient is zero at the stated precision. If the derivative is nonzero, write the point against the free twist line. Division by 2j(PD)2^{j(P_D)} on that line implies the same divisibility after reduction and λM\lambda_M, up to the fixed-degree comparison and the fixed multiplier. Conversely, a visible image bounds j(PD)j(P_D) above by its visible valuation plus a fixed constant. Equation (4.11) proves Equations (18) and (19), using Equation (16). Gross–Zagier–Kolyvagin then gives the simple zero and finite Sha when the coefficient is visible. The detecting construction for DwD_w supplies the final assertion. Fixed denominators or multipliers only reduce MM by a fixed amount; reindexing the precisions gives the formulation stated. □\square

The least normalized depth

We now minimize the coefficient valuation after subtracting the prime weight w(D)w(D). This normalization is fixed before any prime array is chosen. Attainment of the minimum will detect analytic rank and bound the finite Selmer contribution; for the odd source this is interpreted through the bounded-weight sequences and finite realizations below.

For the even source, first rescale gg so that a(D0)=1a(D_0)=1 at one nonzero squarefree index. Its nonzero squarefree valuations are then integers by Proposition 4.1. Set

δ=min⁡{v(a(D))−w(D)},A(D)={1,v(a(D))=δ+w(D),0,otherwise,(21)\delta= \min\{v(a(D))-w(D)\}, \qquad A(D) = \begin{cases} 1, & v(a(D))=\delta+w(D),\\ 0, & \text{otherwise}, \end{cases} \tag*{(21)}

with A(D)=0A(D)=0 off the filter. The minimum exists: the lower bound is uniform, visible valuations are integers after normalization, the fractional part of the weight is fixed, and a nonzero witness exists.

For the odd source fix a nonprincipal ultrafilter U\mathcal{U} on its sequence of precisions. Consider all sequences DMD_M of admissible indices for which w(DM)w(D_M) is bounded and v(aM(DM))v(a_M(D_M)) is visible on an ultrafilter-large set. For each such sequence, its normalized depth has a lower bound in a discrete set. Let δ\delta be the least depth attainable on an ultrafilter-large set. This least depth exists and is attained: the uniform lower bound bounds it below, discreteness gives a least value, and the fixed witness bounds the possible minimum above. For a bounded-weight admissible sequence D=(DM)\mathbf{D}=(D_M), define

A(D)=1⟺{M:v(aM(DM))=δ+w(DM)}∈U,A(\mathbf{D})=1 \quad\Longleftrightarrow\quad\{M:v(a_M(D_M))=\delta+w(D_M)\}\in\mathcal{U},

and set A(D)=0A(\mathbf{D}) = 0 otherwise. We suppress the sequence notation when discussing finite configurations; each application uses their simultaneous finite realizations, as proved below.

For the odd source, a least weight supporting a unit symbol is minimized among the same bounded-weight sequences that attain depth δ\delta. After restricting to an ultrafilter-large set, the weight of such a sequence may be held constant, since it lies in a bounded subset of 12Z≥0\frac{1}{2}\mathbb{Z}_{\geq0}. The set of these constant weights is nonempty and has a least element mm. If unit symbols of weight below mm occurred on an ultrafilter-large set of stages, choosing one such index at each stage would contradict the definition of mm.

Lemma 4.3 (Uniformity at a fixed weight bound). For every fixed WW, on an ultrafilter-large set of sufficiently high precisions,

v(aM(D))≥δ+w(D)v(a_M(\mathcal{D})) \geq\delta+ w(\mathcal{D})

for every admissible index with w(D)≤Ww(\mathcal{D}) \leq W, with valuations truncated at the working precision. Any finite list of stabilized symbol assertions of bounded weight is realized simultaneously at such precisions. The definition allows arbitrarily many weight-zero root factors.

Proof. If the first assertion failed on an ultrafilter-large set, choose a violating DMD_M at each of those levels. Their weights are bounded by WW and their normalized depths lie in a fixed bounded discrete range. After selecting one depth on an ultrafilter-large set, they contradict the definition of δ\delta. For a finite collection of stabilized bits, intersect their ultrafilter-large realization sets. A bound on weight, rather than on the number or size of primes, is all that this argument uses. At weights beyond the chosen bound, the truncated lower estimate of Proposition (12) still supplies any prescribed bounded-depth divisibility test once the weight is sufficiently large. No claim of one finite level valid for all unbounded weights is made.

Proposition 4.4 (Detection by a unit symbol). For either coefficient source, A(D)=1A(\mathcal{D}) = 1 implies the prescribed analytic order: zero in the even case and one in the odd case. At every such index,

v(L(h))≤2w(D)+Cin the even case,(22)v(\mathcal{L}(h)) \leq2w(\mathcal{D}) + C \qquad\text{in the even case,} \tag*{(22)}
j(PD)≤w(D)+Cin the odd case,(23)j(P_{\mathcal{D}}) \leq w(\mathcal{D}) + C \qquad\text{in the odd case,} \tag*{(23)}
s(h)≤C,dim⁡F2Sel⁡2(E(h)/Q)≤C.(24)s(h) \leq C,\qquad\dim_{\mathbb{F}_2}\operatorname{Sel}_2(E^{(h)}/\mathbb{Q}) \leq C. \tag*{(24)}

The constants are fixed after choosing the original curve, filter, coefficient normalization and genus partner. For the odd source they are independent of the detecting prime and the working precision, and of the number and size of active primes. Statements about its symbols are used through finite realizations as in Lemma 4.3.

Proof. In the even case substitute v(a(D))=δ+w(D)v(a(\mathcal{D})) = \delta+ w(\mathcal{D}) into Equations (13) and (14). In the odd case use a precision greater than the finitely many tested depths and apply Equations (18) and (19). The constant δ\delta is fixed and the comparison constants are uniform, proving the first inequalities and the bound on s(h)s(h). At these indices the analytic order is established, so Gross–Zagier–Kolyvagin gives the same algebraic rank and finite Sha [31, 40]. The exact sequence for 2-Selmer then bounds its dimension by that rank, the fixed bound on rational 2-torsion, and the 2-primary length of Sha. This proves the final assertion without making any finiteness assumption at an index where the analytic order has not yet been detected.

Trace identities and prime substitutions

We now turn the least-depth coefficients into rules for replacing, contracting, and deleting primes. The input is a coefficient system from Section 4, with fixed support SS, characters η,ψ\eta,\psi, expansion g=∑n≥1a(n)qng=\sum_{n\ge1}a(n)q^n, minimum depth δ\delta, and symbol A(D)∈F2A(D)\in\mathbb{F}_2, extended by zero off its filter. The coefficient lower bounds and the rational leading units proved there are essential hypotheses. A unit symbol has the analytic interpretation of Proposition 4.4.

Put F=Q(E[2])F=\mathbb{Q}(E[2]). A prime outside SS is called split, simple, or a root according as its action on E[2]E[2] is the identity, a transposition, or an element of order three; its weight is respectively 11, 1/21/2, or 00. The same terminology will be used for Galois elements, according to their image in Gal⁡(F/Q)\operatorname{Gal}(F/\mathbb{Q}). A nonroot is an element of either of the first two types. A finite set of primes and its squarefree product will occasionally be denoted by the same letter. Thus U/pU/p means deletion of pp from UU, not deletion of a prime power from an arbitrary integer.

An oriented Frobenius label in an extension LL of FF means a rational arithmetic Frobenius lift in Gal⁡(L/Q)\operatorname{Gal}(L/\mathbb{Q}), with a chosen place and its residual image in Gal⁡(F/Q)\operatorname{Gal}(F/\mathbb{Q}) retained. At a simple prime this is the lift gg of the transposition, not only the Frobenius g2g^2 of the residue-degree-two place of FF.

For the odd source, fix the finite operator patterns, their weight bounds, and all integer divisions required by the intended tests before choosing an actual stage. The primes realizing those patterns may depend on the stage. The lemma below distinguishes the sharp estimate on a prescribed bounded range of squarefree weights from integrality at every Fourier index. Both are needed to form the integral weight-two trace lattice. At a chosen stage the detecting prime belongs to SS, and the level, coefficient field, and characteristic-zero lift are fixed. Recurrences hold modulo the working precision before division.

Normalized coefficient operators

Let UU be a finite set of nonroot primes outside SS. Write

Up(∑nc(n)qn)=∑nc(pn)qn,Vp(∑nc(n)qn)=∑nc(n)qpn,U_p\left(\sum_n c(n)q^n\right)=\sum_n c(pn)q^n,\qquad V_p\left(\sum_n c(n)q^n\right)=\sum_n c(n)q^{pn},

and define

BU=2−⌈δ+w(U)⌉∏p∈U(Up−η(p)Vp)g,eU=⌈δ+w(U)⌉−δ−w(U).(25)B_U=2^{-\lceil\delta+w(U)\rceil}\prod_{p\in U}(U_p-\eta(p)V_p)g,\qquad e_U=\lceil\delta+w(U)\rceil-\delta-w(U). \tag*{(25)}

The factors commute. We say that UU has matching parity if δ+w(U)\delta+w(U) is integral, and opposite parity otherwise. Equivalently, w(U)w(U) has, or does not have, the fractional part prescribed by the filter. Consequently eU=0e_U=0 or 1/21/2, respectively.

These operations increase the level at a newly introduced pp only to exponent one. In fact, VpV_p changes the character by (p/⋅)(p/\cdot) and raises the level by pp, while on that raised level Up=Up2VpU_p=U_{p^2}V_p. We denote the resulting character of BUB_U by ψU\psi_U. At a good prime q∉S∪Uq\notin S\cup U the coefficient recurrence remains

BU[q2n]=(η(q)aq(E)−ψU(q)(−n/q))BU[n]−qη(q)2BU[n/q2].B_U[q^2n]=\left(\eta(q)a_q(E)-\psi_U(q)(-n/q)\right)B_U[n]-q\eta(q)^2B_U[n/q^2].

For the odd source, Equation (5.2) is read modulo 2M−⌈δ+w(U)⌉2^{M-\lceil\delta+w(U)\rceil} when MM is the working recurrence precision before normalization. As usual, a coefficient with nonintegral index is zero. The equality of the good eigenvalue before and after VpV_p can also be seen directly: its new middle character contains (p/q)(p/q), which cancels the factor (p/q)(p/q) arising from the change of coefficient index.

Lemma 5.1 (Coefficient bound and first shell). Write an index prime to SS uniquely as

n=Jrm2,J⊆U,r squarefree,(r,U)=1,n = Jr m^{2}, \qquad J \subseteq U, \qquad r\ \text{squarefree}, \qquad(r,U)=1,

and put D=(U/J)rD=(U/J)r.

For the even source, BUB_U has integral coefficients and satisfies the following assertions at every index. For the odd source, fix bounds on w(U)w(U) and on the squarefree weights to be tested, and fix an integer K≥0K \ge0. There is a larger cutoff WW and an ultrafilter-large set of arbitrarily high stages at which BUB_U is integral at every index, the assertions below hold whenever w(D)≤Ww(D) \le W, and

v(BU[n])≥Kif w(D)>W.v(B_U[n]) \ge K \qquad\text{if } w(D)>W.

These choices are uniform over prime realizations with the prescribed weight bounds. The coefficient BU[n]B_U[n] is zero unless DD belongs to the filter. Within the range just specified, it satisfies

v(BU[n])≥w(r)+#{p∈J:p simple}2−eU.(26)v(B_U[n]) \ge w(r) + \frac{\#\{p\in J:p\ \text{simple}\}}{2} - e_U. \tag*{(26)}

At a split prime p∈Jp\in J, the factor contributed by the difference operator, after removing its character phase and one factor of 22, is

cp(D)=ap(E)−(ψ/η)(p)(−D/p)−12(mod2).(27)c_p(D)=\frac{a_p(E)-(\psi/\eta)(p)(-D/p)-1}{2}\pmod{2}. \tag*{(27)}

This is independent of the exponent of pp in mm. At a simple prime p∈Jp\in J, (27) holds for the first shell, that is, when p∤mp\nmid m.

Proof. The good-prime recurrence of Section 4 expresses every relevant coefficient in terms of the squarefree coefficient a(D)a(D). After removing the factor η(p)s\eta(p)^s, the multipliers for powers p2sp^{2s} are determined by

b0=1,b1=ap(E)−(ψ/η)(p)(−D/p),bs+1=ap(E)bs−pbs−1.b_0=1,\qquad b_1=a_p(E)-(\psi/\eta)(p)(-D/p),\qquad b_{s+1}=a_p(E)b_s-pb_{s-1}.

If p∣Dp\mid D, the Legendre symbol in b1b_1 is zero. The recurrences at different primes commute and their multipliers multiply.

For p∈U/Jp\in U/J the difference operator contributes bs−bs−1b_s-b_{s-1}, with b−1=0b_{-1}=0. Here p∣Dp\mid D, so b1=ap(E)b_1=a_p(E) is even. Modulo 2 the sequence alternates between 1 and 0, and every such difference is odd. For p∈Jp\in J we have p∤Dp\nmid D; now b0b_0 and b1b_1 are odd and every bsb_s is odd. The difference bs+1−bsb_{s+1}-b_s is therefore even.

For the more precise assertion at a split prime put a=ap(E)a=a_p(E) and κ=(ψ/η)(p)(−D/p)∈{1,−1}\kappa=(\psi/\eta)(p)(-D/p)\in\{1,-1\}. Since E[2]E[2] is rational over Fp\mathbb{F}_p, a≡p+1(mod4)a\equiv p+1\pmod{4}. If Δs=bs+1−bs\Delta_s=b_{s+1}-b_s, the recurrence gives

Δs+1=aΔs−pΔs−1(s≥1).\Delta_{s+1}=a\Delta_s-p\Delta_{s-1}\qquad(s\ge1).

Every Δs\Delta_s is even, whence Δs+1≡Δs−1(mod4)\Delta_{s+1}\equiv\Delta_{s-1}\pmod{4}. Directly,

Δ1−Δ0=a2−aκ−2a+2κ+1−p≡0(mod4).\Delta_1-\Delta_0=a^2-a\kappa-2a+2\kappa+1-p\equiv0\pmod{4}.

Thus Δs/2≡(a−κ−1)/2(mod2)\Delta_s/2\equiv(a-\kappa-1)/2\pmod{2} for every ss. For a simple prime this last formula is still the defining calculation at s=0s=0, which is all that will be required.

Put dU=⌈δ+w(U)⌉d_U=\lceil\delta+w(U)\rceil. Whenever the sharp squarefree bound v(a(D))≥δ+w(D)v(a(D))\ge\delta+w(D) is available, the factors just computed give at least one further factor of 22 for each p∈Jp\in J. Hence

v(BU[n])≥δ+w(D)+#J−dU=w(r)+#{p∈J:p simple}2−eU.v(B_U[n])\ge\delta+w(D)+\#J-d_U=w(r)+\frac{\#\{p\in J:p\text{ simple}\}}{2}-e_U.

For an allowed squarefree class this expression is integral, since δ+w(D)\delta+w(D) is integral. Its only possible negative value before this parity condition is imposed is −1/2-1/2, so it is nonnegative. For the even source the sharp bound holds at every squarefree index, which proves all-index integrality and the displayed estimate.

For the odd source, let u0u_0 bound w(U)w(U). Every prime in UU is a nonroot, so #U≤2u0\#U\le2u_0 and the normalizing exponents dUd_U are bounded. Proposition 4.2 gives a constant CC such that at every admissible squarefree index

v(aM(D))≥min⁡{M,w(D)−C}.v(a_M(D))\ge\min\{M,w(D)-C\}.

This includes the case of zero product derivative, when the coefficient vanishes modulo $2^M$. Choose WW above the prescribed tested weights and so large that W−C−dU>KW-C-d_U>K for all permitted UU. By Lemma 4.3, on an ultrafilter-large set of stages the sharp squarefree bound holds simultaneously for every DD with w(D)≤Ww(D)\le W. Take an arbitrarily high stage in this set, with precision exceeding all the fixed normalizations, the first-shell tests, and δ+W+2u0\delta+W+2u_0, and such that M−dU≥KM-d_U\ge K for every permitted $U.

The recurrences and operator identities for this source hold modulo the working precision. Their multipliers are integral, so iteration through any square exponent leaves errors in the same precision ideal. After dividing by 2dU2^{d_U}, the possible error has valuation at least M−dUM-d_U. Thus the sharp calculation above is valid throughout the bounded range. Outside that range the same calculation with the coarse squarefree bound gives

v(BU[n])≥min⁡{M−dU,w(D)−C+#J−dU}≥K.v(B_U[n])\ge\min\{M-d_U,w(D)-C+\#J-d_U\}\ge K.

This proves integrality at every index of the actual form, while asserting the sharp estimate only on the specified bounded range. There is no restriction on the number of weight-zero root factors. Coefficients excluded by the filter are zero. Every removed phase is a value of η\eta, hence a unit reducing to 11 at the chosen prime above 22. □\square

At equality, the normalized leading coefficient is A(D)A(D) times the displayed shell factors. In particular it is zero when A(D)=0A(D)=0. For the odd source this assertion is used for the finite stabilized symbol evaluations realized at the chosen stage. All omitted-prime comparisons use the same source gg and minimum δ\delta.

In later coefficientwise divisions, choose KK to cover the largest additional division and the desired final divisibility. If a least-weight argument also requires all lower-weight symbols to vanish, that condition holds simultaneously on an ultrafilter-large set: a failure would select a bounded-weight sequence contradicting the stabilized minimum. Intersect that set with the one in the lemma. The bounded range then supplies the sharp calculation and any required zero symbols; the coefficients beyond the cutoff already have all the necessary factors of 22. Consequently all coefficientwise divisions and vanishings used below hold on actual integral forms at one chosen stage for each finite collection of tests. No stage is required to work for every unbounded configuration.

Removing unary coefficients

The coefficient bound identifies the terms that can survive at the lowest valuation. For matching UU in the rational-torsion case, these lie on finitely many square classes. Subtracting the corresponding unary theta series will permit one further integral division by 2.

Suppose first that E(Q)[2]≠0E(\mathbb{Q})[2] \ne0. There are then no root primes. For matching UU, define

ΘJ=∑m>0(m,∏s∈Ss)=1η(m)χ−4(m)imqJm2,\Theta_J = \sum_{\substack{m>0 \\ (m,\prod_{s\in S}s)=1}} \eta(m)\chi_{-4}(m)^{i}m q^{Jm^2},
HU=12(BU−∑J⊆UJ split onlyBU[J]ΘJ)(28)H_U = \frac{1}{2}\left(B_U-\sum_{\substack{J\subseteq U \\ J\text{ split only}}}B_U[J]\Theta_J\right) \tag*{(28)}

where i∈{0,1}i \in\{0,1\} is chosen so that ηχ−4i\eta\chi_{-4}^{i} is odd. For opposite UU, set HU=BUH_U=B_U. Except where a further division is explicitly made in Lemma 5.9, in the irreducible case we also set HU=BUH_U=B_U.

Lemma 5.2. The form in Equation (28) is integral. Each ΘJ\Theta_J is a weight-3/2 unary theta form with character

ηχ−4i(−J/⋅),\eta\chi_{-4}^{i}(-J/\cdot),

whose new level primes are the primes of JJ, each to exponent one. Its character differs from ψU\psi_U by a quadratic character.

Proof. In matching parity the right side of Equation (26) can be zero only if r=1r=1 and JJ consists of split primes. At these indices Equation (27), together with the odd squared-index multipliers at primes outside UU, gives

BU[Jm2]≡BU[J]η(m)(mod2).B_U[Jm^2]\equiv B_U[J]\eta(m)\pmod{2}.

The coefficient of ΘJ\Theta_J at Jm2Jm^2 has precisely this residue: the common phase η(m)\eta(m) is retained on both sides, while χ−4(m)im\chi_{-4}(m)^i m is an odd integer. Thus this is divisibility by 2, not merely by mm in a ramified coefficient ring. Different squarefree JJ have disjoint such supports. The numerator in Equation (28) is consequently divisible by 2 coefficientwise.

Put β=ηχ−4i\beta=\eta\chi_{-4}^{i}, and let β0\beta_0 be its primitive inducing character, of conductor rr supported on SS. The unary theta transformation [60] gives

ΘJ0=∑m>0β0(m)mqJm2∈S3/2(4r2J,β0(−4J/⋅)).\Theta_J^0=\sum_{m>0}\beta_0(m)m q^{Jm^2}\in S_{3/2}\left(4r^2J,\beta_0(-4J/\cdot)\right).

Removing the terms with s∣ms\mid m applies 1−sβ0(s)Vs21-s\beta_0(s)V_{s^2}, where Vs2=Vs2V_{s^2}=V_s^2. Thus

ΘJ=∏s∈S(1−sβ0(s)Vs2)ΘJ0.\Theta_J=\prod_{s\in S}(1-s\beta_0(s)V_{s^2})\Theta_J^0.

Writing PS=∏s∈SsP_S=\prod_{s\in S}s, every term in this product has theta parameter Jd2Jd^2 for some d∣PSd\mid P_S. The same transformation formula places all terms at level 4r2JPS24r^2JP_S^2, with character β0(−4J/⋅)\beta_0(-4J/\cdot) on the units of that level. This is the displayed character ηχ−4i(−J/⋅)\eta\chi_{-4}^{i}(-J/\cdot). Since JJ is prime to SS, each fresh prime in JJ still occurs in the level to exponent one. Finally ψU/η\psi_U/\eta is quadratic, as is χ−4i(−J/⋅)\chi_{-4}^{i}(-J/\cdot), proving the last assertion.

Weight-two traces

We next express coefficient tests as traces of Galois representations. The trace identities will give relations among the tests; the level-prime identity will compare a test with the one obtained by omitting a prime.

Multiply the integral half-integral-weight form under consideration by

θ=1+2∑m≥1qm2.\theta= 1 + 2 \sum_{m \ge1} q^{m^2}.

This produces a weight-two modular form with the same reduced expansion. Choose a finite extension of Q2\mathbb{Q}_2 containing all coefficient fields and character values needed at the fixed level, and denote its ring of integers and maximal ideal by O\mathcal{O} and m\mathfrak{m}.

The characteristic-zero decomposition by the Hecke operators away from the level supplies commuting operators

t(u), d(u),u∈GQ,t(u),\ d(u), \qquad u \in G_{\mathbb{Q}},

by taking the traces and determinants of the corresponding two-dimensional Galois representations. For cuspidal systems these are the weight-two representations of Deligne; for Eisenstein systems they are the sums of the two defining characters. At a good arithmetic Frobenius, t(Fr⁡q)t(\operatorname{Fr}_q) is the ordinary weight-two TqT_q, and the determinant is the cyclotomic character times the diamond character. We use the existence and good-prime compatibility of these representations in their characteristic-zero form [23], §3, (3.9)–(3.12), and Theorem 4.9, and local-global compatibility [15], Theorem (A), §0.7. We take the contragredients of the cohomological representations in these references, so arithmetic Frobenius has trace aqa_q and determinant qq times the diamond eigenvalue.

Here is a precise integral framework for the reductions that follow. Take the finite-dimensional sum of these characteristic-zero systems, retaining their multiplicity spaces, that contains the vector under consideration and its diamond transforms. Its integral Fourier lattice is finite over O\mathcal{O}: finitely many coefficients already give an injective map of this space, and the lattice embeds in the corresponding finite free O\mathcal{O}-module. Good Hecke operators preserve integral expansions. Diamonds do so as well. For the subtracted vector this last claim follows from the formula

⟨u⟩HU=ψU(u)HU+12∑JBU[J](ψU(u)−η(u)χ−4(u)i(−Ju))ΘJ.\langle u\rangle H_U = \psi_U(u)H_U + \frac{1}{2}\sum_J B_U[J]\left(\psi_U(u)-\eta(u)\chi_{-4}(u)^i\left(\frac{-J}{u}\right)\right)\Theta_J.

each parenthesis is zero or twice a unit. The same observation applies after multiplying by θ\theta.

Traces at arbitrary Galois elements are limits of good Frobenius traces on this finite lattice. Indeed, continuity gives a common finite quotient at any prescribed accuracy, and Chebotarev gives a good prime in each required conjugacy class. Its size is unrestricted, and it may avoid any specified finite list of indices and primes. This proves integrality of all the traces and determinants used below, not only of the good Hecke operators with which the construction began.

Let T\mathcal{T} be the resulting commutative operator algebra on the reduced orbit of the vector. Equality means equality of every Fourier coefficient after any further indicated operator products. We retain this algebra, including its possible nilpotents.

Lemma 5.3 (Trace identities and fresh-prime tests). In this reduced operator algebra,

d(u)t(v)=t(v),t(u)t(v)=t(uv)+t(uv−1),t(1)=0.d(u)t(v)=t(v), \qquad t(u)t(v)=t(uv)+t(uv^{-1}), \qquad t(1)=0.

A coefficient of a product of traces can be tested by replacing its arguments with Frobenius elements at distinct fresh primes avoiding the coefficient index. If the index is nn and those primes are q1,…,qaq_1,\ldots,q_a, the test is the reduced coefficient at nq1⋯qanq_1\cdots q_a. Determinants may be applied first.

Proof. For a weight-two form ff, the good-prime formula is

(Tqf)[n]=f[qn]+q(⟨q⟩f)[n/q].(T_qf)[n] = f[qn] + q(\langle q\rangle f)[n/q].

When q∤nq \nmid n the second term is absent. Choosing the successive test primes distinct and avoiding nn proves the coefficient assertion. Chebotarev and continuity, on the finite lattice just described, allow these choices for arbitrary trace arguments at any required accuracy.

All the diamond characters are of 2-power order. On a form with one character its determinant therefore reduces to the identity. For a subtracted vector the displayed diamond formula leaves, in addition, only unary contributions ΘJθ\Theta_J\theta. A fresh trace kills each such contribution modulo m\mathfrak m: its coefficient test has index nqnq with q∤nJq \nmid nJ, and cannot have the squarefree part JJ. The same argument applies after any further tests. This proves d(u)t(v)=t(v)d(u)t(v) = t(v).

For two invertible 2-by-2 matrices the characteristic-zero identity is

tr⁡(A)tr⁡(B)=tr⁡(AB)+det⁡(B)tr⁡(AB−1).\operatorname{tr}(A)\operatorname{tr}(B) = \operatorname{tr}(AB) + \det(B)\operatorname{tr}(AB^{-1}).

Apply it to every characteristic-zero system and use the determinant identity just proved. Finally, t(1)=2t(1) = 2 before reduction.

The bounds of Lemma 5.1 are particularly well suited to these tests: an added prime contributes its nonnegative weight, and additional root primes contribute no weight. A zero established by one of these bounds consequently remains zero after all the further tests used here. In the moving-precision case all the preceding constructions are made at the actual fixed level of the chosen stage. The required divisibility is uniform at the specified weight cutoff; continuity is used only in a finite-dimensional space at that stage.

The only level-prime identity we need is the following. We distinguish the weight-two operator Up(2)\mathrm{U}_p^{(2)} from the earlier half-integral-weight notation, although both extract pp-multiples in their respective Fourier expansions.

Lemma 5.4 (Inertia and a level operator). For p∈Up \in U, choose a place over pp, an inertia element τp\tau_p on which the ramified quadratic character is −1-1, and a corresponding arithmetic Frobenius lift ϕp\phi_p. On the characteristic-zero space under consideration, before reduction, one has

Up(2)(t(gτpϕp)−t(gϕp))=d(ϕp)(t(gτp)−t(g)).(29)\mathrm{U}_p^{(2)}\bigl(t(g\tau_p\phi_p)-t(g\phi_p)\bigr) = d(\phi_p)\bigl(t(g\tau_p)-t(g)\bigr). \tag*{(29)}

The identity commutes with further good traces. After reduction it therefore evaluates a difference at coefficient 1 by the corresponding difference at coefficient pp.

Proof. At pp the summands in question are either old from a level omitting pp, or have conductor exponent one and primitive ramified quadratic diamond character. For the former the representation is unramified, so both trace differences are zero, irrespective of the action of Up(2)\mathrm{U}_p^{(2)} on the old multiplicity space.

For the latter, local-global compatibility identifies the local representation with a principal series with one unramified and one ramified character; its monodromy is zero. In a basis of these two lines write

ρ(τp)=(100−1),ρ(ϕp)=(λ00μ).\rho(\tau_p) = \begin{pmatrix} 1 & 0 \\ 0 & -1 \end{pmatrix}, \qquad \rho(\phi_p) = \begin{pmatrix} \lambda& 0 \\ 0 & \mu \end{pmatrix}.

The level eigenvalue is λ\lambda, the Frobenius eigenvalue on the unramified line, and d(φp)=λμd(\varphi_p)=\lambda\mu. If the lower-right entry of ρ(g)\rho(g) is zz, the two trace differences are −2zμ-2z\mu and −2z-2z, respectively. Both sides of (29) are −2zλμ-2z\lambda\mu. The Eisenstein calculation is the identical calculation on its pair of characters. Copies old at other primes do not change it.

These are all the possibilities: the new level has exponent one at pp, with ramified quadratic determinant, so the Steinberg case with unramified determinant does not enter. A unary summand with p∉Jp\notin J is old from a level omitting pp; with p∈Jp\in J it has the same ramified quadratic local character. Thus the preceding classification also covers (28).

Finally apply (5.6) to remove the determinant from the right side after reduction. Taking coefficient 1 on the left is taking coefficient pp before Up(2)U_p^{(2)}.

Rules when there is rational two-torsion

We now apply the common trace identities to the rational-torsion case. The coefficient bounds first restrict the Galois data on which a symbol can depend. The level-prime identity then determines how the symbol changes when one of those data is varied.

An elementary extension of a number field means a compositum of quadratic extensions. Whenever a ramification support is specified, only extensions unramified outside that support are included. For finite support the resulting elementary extension is finite. Labels below are Frobenius specifications in these extensions, with a chosen place when an orientation over FF is needed. They always include the fixed rational local conditions that specify the filter.

Proposition 5.5 (Rational trace and contraction rules). Suppose E(Q)[2]≠0E(\mathbb{Q})[2]\ne0.

(i) For matching UU, on the subtracted vector HUH_U,

t(g)t(u)=0(u split).t(g)t(u)=0 \qquad(u\ \text{split}).

The trace on split elements factors through the elementary extension of FF supported on S∪US\cup U. For opposite UU, on BUB_U, every product of two traces is zero, and traces factor through the rational elementary extension supported there.

(ii) If U∪{q}U\cup\{q\} has the parity of the filter, its symbol is read at coefficient 1 by t(Fr⁡q)t(\operatorname{Fr}_q) on HUH_U for split qq, and on BUB_U for simple qq.

(iii) Fix p∈Up\in U and put g=Fr⁡qg=\operatorname{Fr}_q. Replacing gg by gτpg\tau_p changes the symbol, additively in F2\mathbb{F}_2, by

A((U/p)∪{q′}),Fr⁡q′∼gφp,(30)A\bigl((U/p)\cup\{q'\}\bigr),\qquad\operatorname{Fr}_{q'}\sim g\varphi_p, \tag*{(30)}

if pp and qq are not both simple. The label of q′q' is required only away from the omitted primes and carries their product labels. The replacement uses the original source with level support S∪(U/p)S\cup(U/p): the whole rational prime pp is omitted, including both places over it if pp splits in FF. If both endpoints are simple, the change is zero.

(iv) A split vertex with trivial label relative to the level with that vertex omitted has symbol zero.

Proof. For matching UU, two fresh tests, one of them split, add weight at least 3/23/2 to (26). The allowed valuation is integral, so the numerator has valuation at least 2. After the division in (28) it still vanishes modulo m\mathfrak{m}; fresh tests kill its unary terms. For opposite UU, two nonroot tests add weight at least 1, leaving at least 1/21/2 after subtracting eUe_U, and hence at least 1 at an allowed coefficient. This proves the two product vanishings on the entire reduced orbit.

The trace identities show why these vanishings give the stated elementary quotients. If uu is split, apply the identity to t(gu)t(u)t(gu)t(u) to obtain t(gu2)=t(g)t(gu^{2}) = t(g). The subgroup generated by squares in GFG_F has elementary quotient, since a group of exponent two is abelian. In the opposite case the same calculation applies to every u∈GQu \in G_{\mathbb{Q}}. Ramification outside the level is absent from the characteristic-zero representations and remains absent in the quotient.

For a split qq, its added weight is 1: at coefficient qq the division by 2 in HUH_U places the coefficient exactly at the normalized detection depth. There is no unary term at that index. For simple qq, eU=1/2e_U = 1/2 already gives that depth on BUB_U. The character phases reduce to 1, proving (ii).

For (iii), apply Lemma 5.4 at coefficient 1, so that its left side is a coefficient-pp test. Replace its trace arguments by fresh primes with Frobenius gτpϕpg_{\tau_p}\phi_p and gϕpg_{\phi_p}. Put V=U/pV = U/p. For X=U,VX = U,V, set nX=⌈δ+w(X)⌉n_X = \lceil\delta+ w(X)\rceil and let mXm_X be one in matching parity and zero otherwise. After a fresh trace kills the unary terms, the shell multiplier relative to the omitted-source test is

21+nV−nU−mU+mVcp(D′),D′=Vq′,Fr⁡q′∼gϕp.2^{1+n_V-n_U-m_U+m_V}c_p(D'), \qquad D' = Vq', \qquad\operatorname{Fr}_{q'} \sim g_{\phi_p}.

The exponent is zero for split pp, and also for simple pp with matching UU. It is one for simple pp with opposite UU, precisely the simple–simple case. This checks all integer divisions in the contraction rule. For simple pp only the first shell is used. The change ψU/ψV=(p/⋅)\psi_U/\psi_V = (p/\cdot) is already included in that shell calculation; all remaining phases reduce to one.

In the first three cases the shell is therefore cp(D′)A(D′)c_p(D')A(D'). Both fresh Frobenius elements have the same image in the omitted source: that source is built from the original modular form, the same η\eta, ψ\psi, δ\delta, and the operators at VV, so it is unramified at the entire rational prime pp. Inertia at either place over pp acts trivially on its symbol. The ramified quadratic coordinate of τp\tau_p reverses the Legendre sign in cpc_p, whose additive change is one. The difference of the two shell values is consequently A(D′)A(D'), proving Equation (30).

If both primes are simple, their residual images are the same transposition, so gϕpg_{\phi_p} is split. The shell now has positive valuation after normalization and contributes zero. Finally (iv) is (ii) with t(Fr⁡q)=t(1)=0t(\operatorname{Fr}_q) = t(1) = 0 in the relevant elementary quotient.

The contraction rules control changes in existing vertices. The next calculation gives a way to add two simple vertices while preserving the symbol.

Proposition 5.6 (Insertion of a pair of simple primes). Suppose E(Q)[2]≠0E(\mathbb{Q})[2] \ne0 and UU has matching parity. Let a rational elementary label, relative to SS and all existing split vertices, be realized by a simple prime qq with

#E(Fq)≡2(mod4).\#E(\mathbb{F}_q) \equiv2 \pmod{4}.

Inserting two fresh simple primes with this same label leaves A(U)A(U) unchanged. Their mutual simple-edge label, and their labels against other simple vertices, do not affect this assertion.

Proof. First test t(Fr⁡q)2t(\operatorname{Fr}_q)^2 on matching HUH_U. The weight-two Hecke formula at coefficient 1 gives, after reduction,

HU[q2]+q(⟨q⟩HU)[1].H_U[q^2] + q(\langle q\rangle H_U)[1].

Only the J=1J=1 unary term can contribute at 1 or q2q^2. Write b=BU[1]b = B_U[1], ϵ=χ−4(q)\epsilon= \chi_{-4}(q), and κ=(ψU/η)(q)\kappa= (\psi_U/\eta)(q). Substituting Equation (5.2) and the two characters in Equation (28), the preceding expression is the reduction of

bη(q)2(aq(E)+κ(q−ϵ)−qϵi(1+ϵ)).(31)b\frac{\eta(q)}{2}\left(a_q(E)+\kappa(q-\epsilon)-q\epsilon^i(1+\epsilon)\right). \tag*{(31)}

For q≡3(mod4)q \equiv3 \pmod{4} the parenthesis divided by 2 is aq(E)/2a_q(E)/2 modulo 2. For q≡1(mod4)q \equiv1 \pmod{4} it is aq(E)/2+1a_q(E)/2+1. In either case it equals (q+1−aq(E))/2=#E(Fq)/2(q+1-a_q(E))/2=\#E(\mathbb{F}_q)/2 modulo 2. Since bb reduces to A(U)A(U), this proves that the squared trace has coefficient (#E(Fq)/2)A(U)(\#E(\mathbb{F}_q)/2)A(U).

By Lemma 5.3, replace the two copies of this trace by distinct fresh primes realizing the same operator tests. Their product coefficient reads the symbol with the two primes inserted. To pass to any other pair with the labels in the statement, vary one prime at a time. After omitting that simple prime the opposite-parity test of Proposition 5.5 depends only on rational elementary labels. Its changes against other simple primes are zero by the simple–simple case of the same proposition. Thus only the fixed support and existing split labels need be matched. Fresh intermediate primes can match both old and new finite specifications, so that no collision of vertices is required. The assumed odd value of #E(Fq)/2\#E(\mathbb{F}_q)/2 completes the proof.

An elementary character on root elements

Assume now that E[2]E[2] is irreducible. Its image is either cyclic of order three or S3S_3. The reduced trace algebra need not be a field: the order-two units below can have nontrivial nilpotent parts. We therefore retain the algebra, rather than replacing it by its residue field.

Lemma 5.7 (Root character). On matching BUB_U one has t(u)=0t(u)=0 for every nonroot uu. On opposite BUB_U one has t(u)=0t(u)=0 for split uu and t(g)t(u)=0t(g)t(u)=0 for two simple elements. In either parity,

t(u)2=1(u a root).t(u)^2=1 \qquad(u\ \text{a root}).

The traces factor through an extension of Gal⁡(F/Q)\operatorname{Gal}(F/\mathbb{Q}) by an elementary kernel over FF. Moreover, there is a multiplicative character α:GQ→T×\alpha:G_{\mathbb{Q}}\to T^\times into the reduced trace algebra, unramified outside S∪US\cup U, such that

α(u)2=1for all u,t(u)=α(u)(u a root).\alpha(u)^2=1 \quad\text{for all }u,\qquad t(u)=\alpha(u)\quad(u\ \text{a root}).

In particular α\alpha factors through a rational elementary extension with that ramification support.

Proof. The trace vanishings follow from (26). In matching parity, one nonroot test adds at least 1/21/2 and hence gives an integral valuation at least 1. In opposite parity, either a split test or two simple tests add at least 1, again leaving positive integral valuation after the loss eU=1/2e_U=1/2.

For a root test, use the same fresh prime qq twice, avoiding the coefficient index, rather than two distinct primes. The weight-two Hecke formula and (5.2) give the identity operator modulo m\mathfrak{m}: aq(E)a_q(E) is odd, and the middle quadratic-character term cancels the diamond term modulo 2. This proves t(u)2=1t(u)^2=1 by continuity for every root uu. For completeness, it suffices to check indices prime to the chosen qq; each particular index permits such a choice of qq with the prescribed finite trace data.

Since split traces vanish in both parities, t(gu2)=t(g)t(gu^2)=t(g) for u∈GFu\in G_F. Thus the traces factor through the quotient by the squares of GFG_F. At any fixed accuracy the trace action is on a finite lattice modulo m\mathfrak{m}, so we may work in a finite quotient

1⟶H⟶Γ⟶Gal⁡(F/Q)⟶11\longrightarrow H\longrightarrow\Gamma\longrightarrow\operatorname{Gal}(F/\mathbb{Q})\longrightarrow1

with HH elementary abelian. Choose an order-three lift RR of a rotation. Such a lift exists because the inverse image of the order-three subgroup is an extension by a finite 2-group. The trace identity with the identity element gives t(R)=t(R−1)=t(R2)t(R)=t(R^{-1})=t(R^2). Applying it to R,R2R,R^2 gives t(R)t(R2)=t(1)+t(R−1)=t(R)t(R)t(R^2)=t(1)+t(R^{-1})=t(R); the left side is 1. Hence

t(R)=t(R2)=1.t(R)=t(R^2)=1.

For a∈Ha\in H set

α(a)=t(aR)=t(aR2).\alpha(a)=t(aR)=t(aR^2).

The equality follows from t(a)=0t(a)=0 and the trace identity with RR. Conjugacy invariance by an element b∈Hb\in H implies that α\alpha is unchanged on multiplying its argument by bR(b)−1bR(b)^{-1}. It therefore factors through the coinvariants H/[H,R]H/[H,R]. Also it is invariant under conjugation by RR. The trace product now gives

α(a)α(b)=t(aR)t(bR)=t(aR(b)R2)+t(ab−1)=α(aR(b))=α(ab).\alpha(a)\alpha(b)=t(aR)t(bR)=t(aR(b)R^2)+t(ab^{-1})=\alpha(aR(b))=\alpha(ab).

The last equality uses the coinvariant invariance just proved; the split term is zero. Since aRaR is a root, α(a)2=1\alpha(a)^2=1.

For cyclic residual image, this already extends to Γ\Gamma by setting α(R)=1\alpha(R)=1. For S3S_3, choose a transposition lift ss normalizing ⟨R⟩\langle R\rangle. It can be obtained from any transposition lift by conjugating its order-three complement by an element of HH. Thus sRs−1=R−1sRs^{-1}=R^{-1} and s2∈Hs^2\in H. Conjugacy of traces shows that α\alpha on HH is invariant under ss. In both parities we have t(s)t(sR)=0t(s)t(sR)=0, either because each factor is zero or by the two-simple product rule. Its trace identity reads

0=α(s2)+t(R)=α(s2)+1.0=\alpha(s^2)+t(R)=\alpha(s^2)+1.

Therefore the extension defined by α(s)=1\alpha(s)=1 respects the relation for s2s^2, as well as conjugation and the relations in ⟨R⟩\langle R\rangle. It is the required multiplicative order-two character, and agrees with the trace on both root cosets. At the fixed stage, choose one common finite quotient through which the traces and residual representation factor, and pull back the character constructed there. No canonical choice across quotients is needed. Unramifiedness outside the level is preserved.

Irreducible deletion rules and minimal labels

The root character replaces products of root traces by a single multiplicative value. We now combine that fact with the level-prime identity to compute changes at nonroot vertices. The last lemma applies these rules at the least weight where a symbol is nonzero.

The total root label is the product of the rational elementary labels of all root primes being used. It includes the fixed-support conditions and the rational quadratic labels against the active nonroot vertices. Its discriminant coordinate is trivial in the quadratic quotient of S3S_3; for cyclic residual image there is no such coordinate.

Proposition 5.8 (Irreducible substitution rules). Suppose E[2]E[2] is irreducible.

(i) On matching BUB_U, coefficient 1 of a product of root traces reads AA on the union of UU and those roots. It depends on the roots only through their total rational elementary label relative to S∪US\cup U. Any finite collection of roots, including the empty collection, may be replaced in this test by one virtual root with that label.

(ii) Changing the Legendre bit of that root against a split vertex pp has additive derivative equal to deletion of pp, with its rational labels away from pp transferred to the total root label. Changing the root bit against a simple vertex has derivative zero. (iii) To vary a simple vertex qq, omit it and use opposite BVB_V, retaining the other root probes. At another simple vertex pp, choose Frobenius lifts gg and ϕp\phi_p for qq and pp. If their transposition images are different, the derivative under g↦gτpg \mapsto g\tau_p deletes both pp and qq and transfers their rational labels to the root total. If their transposition images are equal, the derivative is zero.

(iv) In the test in (iii), variation at a split pp is given by the first-shell factors cpc_p times symbols of merged configurations whose weight is one less. It consequently vanishes whenever all symbols of that lower weight vanish.

All these assertions preserve every specified label at the other vertices, and use the chosen place for inertia and Frobenius.

Proof. Root primes have weight zero. Thus the fresh-prime tests at coefficient 1 of matching BUB_U are precisely the normalized coefficients defining AA. Lemma 5.7 makes the product of root traces equal to the value of α\alpha on their total elementary label. A rotation survives every compatible elementary specification: an elementary quotient cannot eliminate the order-three subgroup, and in the S3S_3 case the only compatibility condition is its trivial image in the quadratic quotient. Chebotarev therefore supplies the claimed single virtual root, even for the empty total label.

For (ii), apply Lemma 5.4 with gg a root. If pp is split then gϕpg\phi_p is a root. The coefficient with J={p}J = \{p\} has zero cost in (26); its first shell is cpc_p times the symbol with pp deleted. The latter is unramified at pp and is the same in the two tests, while cpc_p changes by 1. Multiplication of Frobenius labels by ϕp\phi_p is exactly the transfer of the deleted vertex’s rational labels to the root. If pp is simple, gϕpg\phi_p is simple, and its weight 1/21/2 plus the 1/21/2 contributed by JJ puts the shell above the testing depth. The derivative is then zero.

For (iii), eV=1/2e_V = 1/2. When the two transpositions differ, gϕpg\phi_p is a rotation, and the 1/21/2 contribution from the simple prime in J={p}J = \{p\} exactly cancels eVe_V. The shell again equals cpc_p times the omitted-pp symbol, now with both simple vertices removed and their product represented by a root. The Legendre flip proves the asserted derivative. For equal transpositions their product is split; its additional weight 1 forces the shell to vanish.

Finally, if pp is split and gg simple, then gϕpg\phi_p is simple. The pp-shell is at the first-shell depth and is expressed by (27) with D′=(V/p)q′D' = (V/p)q' and the retained root probes. Its nonroot weight is

w(V)−1+12=(w(V)+12)−1.w(V) - 1 + \frac{1}{2} = \left(w(V) + \frac{1}{2}\right) - 1.

This is one less than the original weight. In particular both shell terms vanish when symbols of that weight vanish. The comparison omitting pp is unramified there. Root probes can be matched on the rational elementary support throughout, which proves the final label assertion as well. □

At the least nonzero weight, every lower-weight term in the preceding rules vanishes. This removes the dependence on internal edge labels; the remaining assertion keeps both the fixed-support labels and the total root label.

Lemma 5.9 (Transfer at the least nonzero weight). Suppose E[2]E[2] is irreducible, and let mm be the least weight of an index on the filter with nonzero symbol. At weight mm, the dependence on each nonroot vertex is only through its oriented rational Frobenius lift in the Galois group over Q\mathbb{Q} of the maximal elementary extension of FF unramified outside SS, together with the requirement on the total root label. In particular, replacing the nonroot vertices by fresh vertices with those same fixed-support labels preserves the symbol, irrespective of their internal edge labels, provided the root total is matched. The assertion allows simultaneous changes using disjoint intermediate configurations. Proof. Every symbol of weight less than mm is zero. For a simple vertex, Proposition 5.8 therefore makes its inertia derivatives at every other active nonroot vertex zero: different transpositions give a lower-weight deletion, equal transpositions give zero directly, and a split vertex gives a lower-weight merged configuration. Its labels against root vertices are immaterial by the simple case of the root derivative rule. These statements hold for conjugates of inertia too, because the Frobenius and inertia calculation is made at a chosen place and may be conjugated. Starting with the elementary extension over FF supported on S∪VS \cup V, killing the inertia at the active vertices leaves exactly fixed-support elementary labels. This proves the assertion for a simple vertex.

For a split vertex qq, let VV be the other nonroot vertices, so w(V)=m−1w(V) = m - 1 and VV still has matching parity. We first claim that BVB_V is divisible by 22 integrally. In (26), an entry of cost zero has rr consisting only of roots and JJ consisting only of split primes. Its underlying squarefree class has weight

w(V)−#J<m.w(V) - \#J < m.

Its symbol is zero. The shell formula at every split prime, valid at all exponents, therefore adds one more factor of 22 to the normalized coefficient. All other allowed entries already have positive integral cost. This proves the claim, including at arbitrarily large coefficient indices.

Use now HV=BV/2H_V = B_V/2. Two split traces give zero on HVH_V: their added weight 22 in (26) still leaves one factor of 22 after this division. The trace restricted to split elements consequently factors through the elementary kernel over FF, by the same square-invariance argument as before. Coefficient 11 with the new split trace and the retained root probes reads the symbol at weight mm.

Apply Lemma 5.4 at p∈Vp \in V to this divided vector. The element gϕpg\phi_p has the type of pp, because gg is split. Its pp-shell is cpc_p times a symbol of weight m−1m - 1, whether pp is split or simple; for a simple pp only the first shell is used. For a simple pp the normalization can be checked directly: J={p}J = \{p\} and the new simple probe contribute 1/2+1/2=11/2 + 1/2 = 1 to (26). Writing nV=δ+w(V)n_V = \delta+ w(V), the divided shell is

2cp(D′)a(D′)2nV+1=cp(D′)a(D′)2nV,w(D′)=w(V)=m−1.\frac{2c_p(D')a(D')}{2^{n_V+1}} = c_p(D')\frac{a(D')}{2^{n_V}}, \qquad w(D') = w(V) = m - 1.

The omitted set V/pV/p has opposite parity, but its ceiling normalization is still nVn_V. Thus this is exactly its unit-symbol test, with no fractional loss. Both compared values are zero. Every such inertia derivative therefore vanishes, leaving only the fixed-support elementary label.

No character α\alpha on this further divided vector is needed. Use actual matched root probes in both tests. At weight mm, their changes against a split vertex are already zero by the split root-deletion rule, because its deletion has weight m−1m - 1. They can therefore be matched while the nonroot vertex is moved. Moving vertices successively, using fresh intermediate copies when necessary, proves the joint assertion without imposing old internal edge labels.

For a moving coefficient system, minimality is used on a fixed bounded weight range. A failure of the required lower-weight vanishing on an ultrafilter-large set of stages would give a bounded-weight sequence contradicting the stabilized minimum. Choose the actual stage as in Lemma 5.1, with the additional division by 22 included among its fixed division bounds. Its coarse estimate controls all larger weights, and its integral square-index recurrence controls every shell. Thus the preceding coefficientwise arguments apply to the actual forms at that stage. The argument does not require mm to be integral.

Summary and finite realization

We collect the rules in the form used to construct finite prime arrays. The analytic meaning of a nonzero symbol is unchanged; this section has established which substitutions preserve it or compute its change.

Theorem 5.10 (Symbol rules). For either coefficient source of Propositions 4.1 and 4.2, assume its stated coefficient lower bound and use its normalized symbol and filter. Then the following rules hold for finite configurations of primes outside the level support.

(i) With rational two-torsion, the elementary-label factorizations, contraction except in the simple–simple case, and isolation by a trivial split label are those of Proposition 5.5. A pair of identical simple labels realized with #E(Fq)/2\#E(\mathbb{F}_q)/2 odd can be inserted without changing the symbol, as in Proposition 5.6.

(ii) With irreducible E[2]E[2], all root probes combine into one total rational elementary label. A root-bit derivative at a split vertex deletes that vertex, while at a simple vertex it is zero. The derivative between two simple vertices deletes both when their transposition images are different, and is zero when they are equal. The remaining simple–split shell has weight one less. These are the rules of Proposition 5.8.

(iii) At the least weight supporting a nonzero symbol in the irreducible case, each nonroot may be moved with only its fixed-support elementary Frobenius label prescribed; internal edges impose no further condition on the value, subject to matching the total root label. This is Lemma 5.9.

The analytic and finite-Selmer consequences of a nonzero symbol remain those of Proposition 4.4. In the odd source the rules mean finite tests at arbitrarily high stages chosen in the ultrafilter-large sets of the prescribed stabilization.

Proof. The preceding propositions prove the assertions. For one application, put the finitely many Galois modules and operator tests in a common finite quotient at the required precision. Chebotarev then gives simultaneously fresh Frobenius representatives. The omitted source is unramified at the whole omitted prime, whereas its ramified rational quadratic coordinate is exactly the Legendre flip in the shell formula. These are therefore substitutions with all other labels held fixed.

The arithmetic compatibility of an entire array is addressed in the following sections. The present assertions concern each finite array; in the odd case choose a sufficiently high actual stage in the required ultrafilter-large intersection. Arbitrarily many weight-zero roots cause no additional depth loss, because the coefficient bound is uniform at a fixed weight and their traces combine through one total elementary label.

Prime graphs and simultaneous unit coefficients

The coefficient symbols will now be regarded as functions of finitely many quadratic residue bits. We first identify the arithmetic data that those bits record and explain how the trace calculation becomes a finite difference. This gives polynomials whose derivatives contract prime labels. We then adjoin auxiliary vertices so that one or two nonzero coefficient polynomials take the value 11 at every nonzero address of a binary cube.

The two-polynomial case is needed for the odd converse: the odd symbol tests hh, while an even symbol tests a quadratic companion khkh. Separate nonzero polynomials need not have a common unit evaluation; for example, zz and 1+z1+z do not. The auxiliary vertices change the polynomials by controlled contraction operators. The arithmetic input is the rational contraction and isolation rules of Theorem 5.10, including omission of an entire rational prime. The same argument applies to any coefficient test with these rules, such as the restricted even test constructed in Section 7.5.

Encoding quadratic residue symbols by graphs has a precedent in the congruent-number problem: Feng–Xiong express descent conditions through prime graphs and the ranks of their binary Laplacians [27]. Here the graphs record coefficient-symbol rules, and their oriented contractions produce simultaneous unit values.

Prime labels and their realization

Let FF be Q\mathbb{Q} or a quadratic field. The applications use F=Q(E[2])F = \mathbb{Q}(E[2]) when this field is quadratic, and also an auxiliary quadratic field when E[2]E[2] is rational. Fix a finite set SS of rational primes containing 2 and the ramification support of the fixed data. Enlarge SS so that prime ideals above it generate the class group of FF, and let SFS_F include these places and the infinite places. Set

VS(F)={α∈F×/F×2:vp(α)≡0(mod2) for p∉SF}.V_S(F) = \left\{\alpha\in F^\times/F^{\times2} : v_{\mathfrak p}(\alpha) \equiv0 \pmod{2}\text{ for }\mathfrak p \notin S_F\right\}.

The valuation sequence expresses this as an extension of the squareclasses of SFS_F-units by a subgroup of the 2-torsion of the SFS_F-class group; in particular, it is finite-dimensional over F2\mathbb{F}_2 [47]. Write FS(2)=F(VS(F))F_S^{(2)} = F(\sqrt{V_S(F)}).

A split vertex is a rational prime p∉Sp \notin S split in FF, with an orientation p∣p\mathfrak p \mid p when FF is quadratic. Choose a generator πp\pi_{\mathfrak p} whose divisor outside SFS_F is p\mathfrak p; this is possible by the class-group condition. Use its conjugate for the other orientation. Then

NF/Q(πp)=pup,up a signed rational S-unit.(32)N_{F/\mathbb{Q}}(\pi_{\mathfrak p}) = p u_p,\qquad u_p\text{ a signed rational }S\text{-unit}. \tag*{(32)}

For F=QF = \mathbb{Q}, use the generator pp. In the quadratic case an inert rational prime is a simple vertex, with rational generator pp. A split vertex has its fixed Frobenius label on FS(2)F_S^{(2)}; a simple vertex has rational fixed-support labels. A type may also specify local squareclasses, support valuation parities, real signs, and finite ray conditions on its generator. Prescribed types must be compatible and individually realizable. A filter fixes the total rational labels and sign of the signed-prime product, where p∗=(−1/p)pp^* = (-1/p)p.

Write quadratic residue symbols additively in F2\mathbb{F}_2. Between two split vertices in the quadratic case there are two independent forward bits: the residues of πp\pi_{\mathfrak p} and πp‾\overline{\pi_{\mathfrak p}} at the chosen place of the other vertex. Hilbert reciprocity and the types determine the reverse bits. Their sum, with the fixed correction in (32), gives the rational norm bit. If an endpoint is simple, or if F=QF = \mathbb{Q}, there is one rational forward bit. Vertices, types, and these bits form an arithmetic graph; there is no self-residue datum.

For the coefficient symbols, the vertices are the prime factors of the Fourier index. Their types fix the support and elementary Frobenius conditions, while the edge bits record the remaining quadratic residue tests. Varying an edge leaves those types and the total filter unchanged. The next calculation explains the resulting contraction rule.

For the standard rational-two-torsion symbol of Proposition 5.5, take split primes p,qp,q and let UU contain pp but not qq, with matching parity. Write V=U/pV = U/p and g=Frqg = \mathrm{Fr}_q. By Proposition 5.5,

A(Uq)=[t(g)HU][1].A(Uq) = [t(g)H_U][1].

Changing one residue bit from pp to qq replaces gg by gτpg\tau_p, where τp\tau_p is the corresponding inertia element. The level identity (5.7) moves the difference to the coefficient at pp. Its two first-shell values are

cp(D′)A(D′),(cp(D′)+1)A(D′),D′=Vq′,Fr⁡q′∼gϕp.c_p(D')A(D'),\qquad(c_p(D')+1)A(D'),\qquad D'=Vq',\qquad\operatorname{Fr}_{q'}\sim g\phi_p.

The omitted source is unramified at the whole prime pp, so its value A(D′)A(D') is the same in the two terms. Their sum is A(D′)A(D'). Thus, if zz is the changed edge bit,

A∣z=0+A∣z=1=A(Vq′).A\big|_{z=0}+A\big|_{z=1}=A(Vq').

Here q′q' is a fresh prime carrying the product labels of pp and qq; it replaces two vertices by one. Its integer value is not the product pqpq.

In the quadratic field, the two choices of oriented bit correspond to using πpπq\pi_p\pi_q or πp‾ πq‾\overline{\pi_p}\,\overline{\pi_q} as a product template, up to the choice of output orientation. The template adds the support labels and the external residue bits in the indicated orientations. There is no internal residue attached to the new vertex. Omitting pp removes both places above that rational prime from the source, so a second difference in the other oriented bit gives zero. Split–simple contraction has the same interpretation with rational product data; a simple–simple difference is zero.

To use these formulas on arbitrary arrays of bits, we must know that the arrays and the product templates have prime representatives, and that different representatives give the same symbol. The following lemma supplies both facts.

Lemma 6.1 (Finite realization and product labels). Fix finitely many old vertices and individually realizable new types. Every choice of independent forward bits is realized by distinct fresh primes, avoiding any given finite set. Further fixed local tests may be included in SS.

A split cluster may be represented by the product of its oriented generators, with conjugations prescribed along a contraction tree; its support types and external bits are the corresponding sums. A cluster containing one simple vertex has the corresponding rational product data. These products may be replaced by fresh prime representatives. For a symbol satisfying the omitted-vertex dependence of Theorem 5.10, the graph data determine its value, and these replacements preserve the contracted symbol.

Proof. The displayed generators account for every relevant radical. Let UU be a finite set of new rational primes and UFU_F the places above them. From a squareclass with even valuations outside SF∪UFS_F\cup U_F subtract the generators at the primes of UFU_F where its valuation is odd. The remainder lies in VS(F)V_S(F). At an inert prime its rational generator has valuation one at the unique place of FF. Thus the fixed labels and residue bits determine every elementary Frobenius test with this ramification support.

For a new split vertex, start with a template π0\pi_0 of its type, at a prime ideal p0\mathfrak p_0 away from the old vertices. Weak approximation gives a∈F×a\in F^\times sufficiently close to 11 at SFS_F, positive at the specified real places, and with residues at the old prime ideals chosen so that aπ0a\pi_0 has the prescribed quadratic residues. Use a ray modulus containing deep enough powers of SFS_F, all old prime ideals, and the real places. A prime ideal q\mathfrak q in the ray class of (a)p0(a)\mathfrak p_0 satisfies

q=(ab)p0,b≡1(modray modulus).\mathfrak q=(ab)\mathfrak p_0,\qquad b\equiv1\pmod{\text{ray modulus}}.

Then abπ0ab\pi_0 has the desired divisor and type. The prime ideals in this ray class have positive Dirichlet density [48], Chapter V, Theorem 2.5]. For s>1s>1, the sum of (Nq)−s(N\mathfrak q)^{-s} over prime ideals of residue degree greater than one is at most 2∑pp−2s2\sum_p p^{-2s}, which stays bounded as s↓1s\downarrow1. The corresponding sum over the ray class diverges. Hence that class contains infinitely many degree-one primes. Outside the fixed ramification support these give split rational primes, and finite exclusions remove finitely many choices.

At an old inert prime, prescribe instead the norm of the residue in Fp2×\mathbb{F}_{p^2}^{\times}. Its norm onto Fp×\mathbb{F}_p^{\times} is surjective. For a new simple vertex all conditions are rational congruences, including the inert class in FF; the Chinese remainder theorem and Dirichlet’s theorem apply. Successive selection realizes the whole graph. Reciprocity determines reverse bits, since the support Hilbert symbols are fixed and only the two endpoint residues remain. Taking norms gives (32), with no extra independent condition.

The same construction applies to a product template. It preserves its support data and its residues at every remaining vertex; no internal residue is imposed on the replacement. For a simple cluster use rational congruences for the norm labels. To check the rational filter in a split cluster, write π=∏iπi\pi=\prod_i\pi_i and π′=abπ\pi'=ab\pi for its replacement. The multiplier abab is a square unit at SFS_F and positive at real places. Consequently

Nπ=(∏ipi)u,Nπ′=quN\pi=\left(\prod_i p_i\right)u,\qquad N\pi'=qu

have the same signed rational SS-unit uu: its valuations and sign agree. Thus q/∏ipi=N(ab)q/\prod_i p_i=N(ab) is locally square at the rational support. The condition at 22 also identifies q∗q^* with ∏ipi∗\prod_i p_i^* in the fixed tests. This verifies preservation of the norm correction.

Finally, compare two disjoint realizations of the same graph. Insert fresh bridge vertices with matching bits to both realizations and replace vertices one at a time. The omitted-vertex Frobenius tests agree by the radical description above, so the symbol values agree. A preliminary bridge removes any overlap. This proves both graph dependence and invariance under the product replacements. □\square

Consequently, fixing the vertex types gives a well-defined function AGA_G of the independent forward edge bits; choose any prime realization of the graph GG and evaluate its coefficient symbol. Lemma 6.1 makes the result independent of that choice. We will write its unique multilinear polynomial as PP. Equation (6.2) says that a derivative of PP evaluates the contracted graph.

A split vertex is primary if its generator is a square unit at every finite place of SFS_F and positive at every real place. The principal ray class realizes such types. Reciprocity makes their fixed radical labels trivial, and their signed rational contributions are squares in the fixed tests. Including stationary vertex primes in those tests makes primary incidences to them neutral. Including the support of a quadratic discriminant kk ensures that every primary prime splits in Q(k)\mathbb{Q}(\sqrt{k}).

Two symbols may use different fixed-support tests or read only rational norm labels from this same graph. We call these compatible projections when they forget fixed-label coordinates or take norm data, preserve primary vertices, and commute with the omitted-vertex product substitution. In the norm projection either oriented-bit toggle changes the rational bit once. Thus one physical edge difference induces the specified difference for each symbol; it need not give the same polynomial for both symbols.

Definition 6.2 (Witnesses and permitted partitions). A witness is a finite graph with symbol 11. A graph is partitionable if it admits a partition into nonempty clusters, each containing at most one simple vertex, and oriented contraction trees whose contracted graph is a witness. The contraction trees are part of the data; this definition makes no assertion about a Selmer group.

For a two-isogenous curve with quadratic field F′=Q(E′[2])F'=\mathbb{Q}(E'[2]), a simple vertex is good if it is inert in both FF and F′F'. A donor is split in FF and inert in F′F'. Attaching a donor turns a simple vertex split in F′F' into a good one. These are conditions on finite labels; their supply will be established in the arithmetic application.

Forests as finite-difference operators

For an edge bit zz, put Δzf=f∣z=0+f∣z=1\Delta_z f = f|_{z=0} + f|_{z=1}. Every function on a finite binary cube has a unique multilinear polynomial over F2\mathbb{F}_2; Δz\Delta_z is its formal derivative. Differences therefore commute and satisfy Δz2=0\Delta_z^2 = 0.

Lemma 6.3 (Oriented forests). Assume the contraction, isolation, and omitted-prime assertions of Theorem 5.10. Differentiation along a tree contracts it, adding product labels and external incidences; the result is zero if the tree contains two simple vertices. A collection of edge variables containing a cycle has zero derivative, including when its orientations are incompatible. The two oriented variables on one pair form a cycle of length two.

Proof. The one-edge rule is the symbol contraction identity, with product replacement supplied by Lemma 6.1. Induction contracts a tree: split–split mergers remain split, split–simple mergers remain simple, and merging two simple components gives zero. A root orientation determines all relative orientations along the tree. Its product template uses support types and external bits, not the differentiated internal bits.

For the two variables on a split pair p,qp,q, differentiate first in one inertia bit over pp. The resulting symbol omits the entire rational prime pp, so its elementary extension is unramified at both places over pp. The derivative in the other oriented bit is zero. Repeated use of the same variable gives zero by Δz2=0\Delta_z^2 = 0.

For a longer cycle, contract a spanning path. The closing edge becomes internal to one cluster and changes neither its support label nor an incidence to a remaining vertex. The omitted-endpoint argument just given therefore kills its derivative. Conjugating the product only changes its orientation; it does not restore the omitted endpoint or create a self-residue.

For example, after contracting aligned edge 1212, the two bits from its product to vertex 33 are t0=z130+z230t_0 = z_{13}^0 + z_{23}^0 and t1=z131+z231t_1 = z_{13}^1 + z_{23}^1, up to fixed type corrections. An aligned edge 2323 differentiates t0t_0. The closing edge 3131 differentiates either t0t_0 again, giving zero, or t1t_1, giving the omitted-endpoint zero. Every longer cycle reduces to these cases. Further differences commute with this zero derivative.

Call the original vertices terminals; any stationary external vertices retain their types and incidences. Fix their vertex types and a realizable baseline graph. Write z=(ze)z = (z_e) for the independent toggles of the terminal–terminal bits, and let P(z)P(z) be the terminal symbol. A network adjoins primary vertices and specified incidences involving them. It adds no terminal–terminal edge: the original bits zz remain parameters. All unspecified primary incidences are neutral. Within each network fix a consistent orientation at each terminal. Different networks may use different alignments.

Write y=(ye)y = (y_e) for the bits on the added incidences, and let f(z,y)f(z,y) be the symbol of the enlarged graph. We shall express f(z,1)f(z,1) as a finite-difference operator applied to P(z)P(z). The differences in yy first contract the added graph; the forest rule then expresses each surviving term as differences in the original variables zz.

For example, join one primary vertex rr to two permitted terminals a,ba,b, in a fixed alignment. Expanding in its two added incidences gives four terms. The term with no difference is zero because rr is isolated. Each one-edge difference contracts rr onto one terminal and leaves the original symbol PP, so these two terms cancel in F2\mathbb{F}_2. The two-edge tree contracts the terminal pair and gives ΔzazbP\Delta_{z_a z_b}P. Thus this path acts exactly as the terminal difference Δzazb\Delta_{z_a z_b}. The path has two added edges, but its operator has contraction degree one. In general, a component meeting tt terminals has terminal contraction degree t−1t-1.

The lowest two operator degrees can be read from a matrix. Index the internal primary vertices by II, let eije_{ij} be their internal edge bits, and let cac_a be the incidence column from them to terminal aa. The grounded Laplacian is the symmetric matrix over F2\mathbb{F}_2 with

Qij=eij(i≠j),Qii=∑j≠ieij+∑a(ca)i.Q_{ij}=e_{ij}\quad(i\ne j),\qquad Q_{ii}=\sum_{j\ne i}e_{ij}+\sum_a(c_a)_i.

Equivalently,

Q1=∑aca.(33)Q\mathbf{1}=\sum_a c_a. \tag*{(33)}

Thus prescribed off-diagonal entries and terminal columns realize a given symmetric QQ precisely when this row-sum identity holds. For the one-primary-vertex path above, Q=(0)Q=(0) and ca=cb=(1)c_a=c_b=(1).

The coefficients below are instances over F2\mathbb{F}_2 of the all-minors matrix-tree theorem [19], §1, eq:2; we include the incidence-matrix proof needed here.

Lemma 6.4 (Network expansion). A network satisfies f(z,1)=NP(z)f(z,1)=\mathcal{N}P(z), where N\mathcal{N} is a sum of terminal finite-difference operators indexed by forests. In each surviving forest term, every component containing an internal primary vertex meets a terminal. A component meeting tt terminals has contraction degree t−1t-1; a component containing two simple terminals acts as zero. Networks with disjoint internal vertices and no edges between them multiply as operators on the same PP. In particular, degree greater than deg⁡P\deg P annihilates it.

For the grounded Laplacian QQ and terminal columns cac_a defined above, the constant and the pair-contraction coefficients are

det⁡Q,caTadj⁡(Q)cb(a≠b).(34)\det Q,\qquad c_a^{\mathsf T}\operatorname{adj}(Q)c_b\quad(a\ne b). \tag*{(34)}

The latter multiplies the terminal difference in the selected alignment; a prohibited pair multiplies the zero operator.

Proof. For the set E0E_0 of added incidences, keep the terminal variables zz fixed and expand in the variables yy:

f(z,1)=∑T⊆E0(ΔΔTyf)(z,0).f(z,1)=\sum_{T\subseteq E_0}\left(\Delta^y_{\Delta_T}f\right)(z,0).

Lemma 6.3 removes cycles. A component meeting no terminal contracts to an isolated primary vertex, so isolation removes it, including an untouched primary vertex. In a surviving component the primary labels and external primary bits are trivial. Its contracted label and external incidences are thus exactly those obtained by contracting its terminals in the original graph. A terminal tree with the same relative orientations gives that operator, of degree t−1t-1.

Expanding two disjoint networks gives composition: product labels agree in either order, and any resulting cycle vanishes. Polynomial differentiation then proves the degree bound. This reasoning also verifies compatibility with projections at every degree. Norms commute with oriented products, primary norm corrections are neutral, and either oriented toggle induces its rational toggle on the original terminal polynomial. Repeated projected differences or prohibited simple mergers give zero. Forgetting fixed-label coordinates commutes with the same products.

For the coefficients, write the Laplacian of the added network as L=DDtL = DD^{\mathsf{t}}, where each incidence column has ones at its edge endpoints. Let II and AA be the internal and terminal sets. Cauchy–Binet for Q=LI,IQ = L_{I,I} counts edge sets whose incidence matrix becomes invertible after deleting the terminal rows. They are exactly forests with one terminal in each component: cycles give dependent columns, a component with no deleted row gives dependent rows, and a tree with one row deleted is invertible by leaf removal. These are the degree-zero terms.

Apply Cauchy–Binet instead to row set I∪{a}I \cup\{a\} and column set I∪{b}I \cup\{b\}. Each component must contain one root from each of A∖{a}A \setminus\{a\} and A∖{b}A \setminus\{b\}. Thus a,ba,b lie together and every other terminal lies in its own component. The corresponding minor is

det⁡(Qcbcat0)=catadj⁡(Q)cb.\det\begin{pmatrix} Q & c_b \\ c_a^{\mathsf{t}} & 0 \end{pmatrix} = c_a^{\mathsf{t}} \operatorname{adj}(Q)c_b.

The corner is zero because there is no added terminal–terminal edge. Signs disappear in characteristic two, and the adjugate identity remains valid when QQ is singular. □\square

Selecting one address

An address is x∈F2bx \in\mathbb{F}_2^b, where b≥1b \ge1. A vertex with activation λ∈(F2b)∗\lambda\in(\mathbb{F}_2^b)^* is present when λ(x)=1\lambda(x) = 1. Fix a nonzero target x∗x_\ast and an edge bit zz joining terminals a0,a1a_0,a_1 active there. Either all terminals are always present, or all have nonzero linear activations with at least one terminal for each nonzero linear form. For one symbol we need a derivative as the leading term at x∗x_\ast and a constant term 11 elsewhere. For two symbols we must also account for a derivative allocated to just one factor; the second network includes a binary parameter for this purpose. We construct these two networks by prescribing their constant and degree-one terms; the final degree count will remove every higher term.

Choose a dual basis λ1,…,λb\lambda_1,\ldots,\lambda_b with λi(x∗)=1\lambda_i(x_\ast) = 1 for every ii. Indeed, start with λ1(x∗)=1\lambda_1(x_\ast) = 1 and add it to a basis of the annihilator of x∗x_\ast. Make bb groups of three primary vertices, with all three vertices in group ii activated by λi\lambda_i. The physical coordinate vectors index these actual vertices. In each three-dimensional coordinate space choose a computational basis (ei,ui,vi)(e_i,u_i,v_i) with ei=(1,1,1)e_i = (1,1,1). Prescribe a symmetric form QQ by making the eie_i orthonormal and orthogonal to all uj,vju_j,v_j, and using on the remaining coordinates

H(T,B)=(0TTtB).(35)H(T,B) = \begin{pmatrix} 0 & T \\ T^{\mathsf{t}} & B \end{pmatrix}. \tag*{(35)}

Convert this form to its matrix in the physical vertex coordinates, which we also denote by QQ. Write QJQ_J for the restriction to the physical coordinates in groups JJ.

The column hi=Qeih_i = Qe_i represents the covector dual to eie_i. Since the coordinate changes do not mix groups, hih_i is supported on group ii; it is independent of T,BT,B. Attach this incidence column to a terminal of activation λi\lambda_i, or to any fixed terminal in the stationary case. When the active groups are JJ, the sum of these anchor columns is

∑i∈Jhi∣J=QJ1J,\sum_{i \in J} h_i|_J = Q_J \mathbf{1}_J,

since 1J=∑i∈Jei\mathbf{1}_J = \sum_{i \in J} e_i. Use the off-diagonal physical entries of QQ as the internal edge bits. Equation (33) then gives the prescribed diagonal as well: the anchors make the actual grounded Laplacian equal to QJQ_J at every address, even after groups have disappeared.

Also attach the same column cc to a0,a1a_0,a_1. If their moving activations α,β\alpha,\beta differ, attach it to a terminal of activation α+β\alpha+\beta as well. The additional column sum is always zero:

(α(x)+β(x)+(α+β)(x))c=0.\bigl(\alpha(x)+\beta(x)+(\alpha+\beta)(x)\bigr)c=0.

The third terminal is absent at x∗x_\ast. Equal activations, or two stationary terminals, require only the first two columns. Coincident terminal roles mean addition of columns. Hence these attachments preserve the grounding at every restriction.

Write O≥dO_{\ge d} for a sum of contraction operators of degrees at least dd. This denotes a filtration, not a numerical estimate. Figure 1 depicts the group-level cycle and path used in the two programs when b=4b=4.

Cycle and path diagrams showing the off-diagonal patterns of $T-I$ for the two programs when $b=4$

Figure 1. The off-diagonal patterns of T−IT-I for the two programs when b=4b=4. The vertices represent groups, not the individual primary vertices of the network. A proper group restriction breaks the cycle; the path from 1 to 4 survives only when every group is present.

Lemma 6.5 (Two address programs). With these activations and grounding, there are the following networks:

  1. A singular program SS such that

Sx∗=Δz+O≥2,Sx=1+O≥1(x≠x∗).S_{x_\ast}=\Delta_z+O_{\ge2},\qquad S_x=1+O_{\ge1}\quad(x\ne x_\ast).
  1. Two nonsingular programs on the same sites, indexed by ε∈F2\varepsilon\in\mathbb{F}_2, such that

Nx(ε)=1+O≥1,Nx(1)+Nx(0)={Δz+O≥2,x=x∗,O≥2,x≠x∗.\mathcal{N}^{(\varepsilon)}_x=1+O_{\ge1},\qquad\mathcal{N}^{(1)}_x+\mathcal{N}^{(0)}_x= \begin{cases} \Delta_z+O_{\ge2}, & x=x_\ast,\\ O_{\ge2}, & x\ne x_\ast. \end{cases}

All new sites have nonzero activation and are absent at 0. Unspecified incidences, including those to stationary external vertices, may remain neutral.

Proof. For the first program, take T=I+PT=I+P, with PP the cyclic permutation matrix, and let BB be diagonal with exactly one nonzero entry. Every proper principal restriction of PP is a union of directed paths, hence nilpotent. Thus TJT_J and H(TJ,BJ)H(T_J,B_J) are invertible for proper JJ, including the empty restriction, whose determinant is 1.

On all groups, ker⁡T\ker T and ker⁡Tt\ker T^{\mathsf{t}} are spanned by 1\mathbf{1}. A radical vector of HH has v=t1v=t\mathbf{1}; summing Ttu+Bv=0T^{\mathsf{t}}u+Bv=0 gives t=0t=0, since 1tB1=1\mathbf{1}^{\mathsf{t}}B\mathbf{1}=1. Hence QQ has radical generated by

r=∑iui.r=\sum_i u_i.

Its adjugate is rrtrr^{\mathsf{t}}: it is nonzero of rank one, symmetry identifies its factors with the kernel, and the only nonzero scalar in F2\mathbb{F}_2 is 1.

Take cc dual to u1u_1, so ctr=1c^{\mathsf{t}}r=1. All anchors annihilate rr. At x∗x_\ast the only terminal columns pairing nontrivially with rr are therefore those of a0,a1a_0,a_1. Formula (6.4) gives constant zero and precisely Δz\Delta_z in degree one. Every other address has a proper group subset and constant 1, since the activation forms form a basis. For b=1b=1, T=0T=0 and B=(1)B=(1) give the same radical.

For the second program take T=I+LT = I + L, where LL is the consecutive lower shift, and Bε=εEbbB_{\varepsilon} = \varepsilon E_{bb}. Every group restriction of TT is invertible, and

H(T,B)−1=(T−tBT−1T−tT−10).(36)H(T,B)^{-1} = \begin{pmatrix} T^{-\mathsf{t}}BT^{-1} & T^{-\mathsf{t}} \\ T^{-1} & 0 \end{pmatrix}. \tag*{(36)}

Again take cc dual to u1u_1. On groups JJ, the change in ctQJ−1cc^{\mathsf{t}}Q_J^{-1}c is ((TJ−1)b1)2((T_J^{-1})_{b1})^2, interpreted as zero if an endpoint is absent. The expansion (I+LJ)−1=I+LJ+LJ2+⋯(I+L_J)^{-1}=I+L_J+L_J^2+\cdots shows that this is 1 exactly when the entire path 1,…,b1,\ldots,b survives, namely at x∗x_*. Pairings with anchors do not change, since QJ−1hi=eiQ_J^{-1}h_i=e_i and ei,hi,ce_i,h_i,c are independent of ε\varepsilon. At the target the balancing terminal is absent, leaving only the changed pair a0,a1a_0,a_1. All determinants are 1. Lemma 6.4 proves the assertion, also for the single-vertex path b=1b=1.

Simultaneous units on a punctured cube

The preceding programs control only two degrees of their operators. To make this sufficient, at each address we spend exactly the degree of a chosen top monomial. Any additional contraction then vanishes. For two symbols, the same accounting uses the ordinary product of their top homogeneous parts. The multiplication is performed before imposing the Boolean relation z2=zz^2=z, so one occurrence of zz in each factor remains two contraction requirements.

Theorem 6.6 (Address lemma). Assume the contraction, isolation, and whole-prime omission rules of Proposition 5.5, or the same rules for another symbol, together with the realization freedoms of Lemma 6.1. Let b≥1b\geq1 and consider either of the following terminal arrangements:

  1. One symbol on a nonempty set of always active terminals, whose polynomial in the independent pair bits is nonzero.

  1. One or two symbols on terminals with nonzero linear activations, including a terminal for every nonzero linear form. At each x≠0x\ne0, each symbol separately is a nonzero polynomial in the active bits. The symbols may have stationary external data and may read compatible projections of a common graph.

At every x≠0x\ne0, assume that the active terminal data and the stationary external data obey each required filter. Then finitely many primary auxiliaries with nonzero linear activations, and one realizable assignment of graph bits, make all the symbols 1 at every x≠0x\ne0. No auxiliary is present at 0. All may satisfy fixed splitting and neutral-incidence conditions included in their primary type.

A nonzero evaluation or a nonzero iterated edge difference suffices for the polynomial hypothesis. In particular, a partition as in Definition 6.2 suffices in the stationary case.

Proof. Fix a common realizable baseline for the terminal bits and regard their toggles as variables; omit variables invisible to a symbol. A nonzero iterated difference implies a nonzero polynomial, while every nonzero polynomial has a top monomial with coefficient 1. By Lemma 6.3, this also proves the assertion about partitions.

For one symbol, let PxP_x have degree dxd_x at x≠0x\ne0 and choose a monomial of degree dxd_x with coefficient 1. For each of its variables attach a separate singular program targeted at xx, all with disjoint internal vertices. At address xx, its own dxd_x programs have zero constant, so they consume at least dxd_x contraction degrees. Any extra degree from any program kills PxP_x. Only the selected degree-one terms of these programs and the constants of the others survive, giving the chosen coefficient 1. A nonzero constant polynomial needs no program. Stationary anchors give the same argument for always active terminals. For two symbols, write their polynomials at xx as Px,RxP_x,R_x, of degrees dx,exd_x,e_x. Multiply their top homogeneous parts in the ordinary ring F2[z1,…,zm]\mathbb{F}_2[z_1,\ldots,z_m], before imposing Boolean relations. This ring is a domain, so choose a coefficient 11 at a monomial

Mx=∏zzνxz,νxz∈{0,1,2},∑zνxz=dx+ex.M_x=\prod_z z^{\nu_{xz}},\qquad\nu_{xz}\in\{0,1,2\},\qquad\sum_z\nu_{xz}=d_x+e_x.

For each exponent two add one singular program targeted at xx; for each exponent one add one nonsingular program, with its own parameter εxz∈F2\varepsilon_{xz}\in\mathbb{F}_2. Keep all internal sets disjoint. Let

Φ(ε)=∏x≠0(final value of Px)(final value of Rx).\Phi(\varepsilon)=\prod_{x\ne0}(\text{final value of }P_x)(\text{final value of }R_x).

We show that ∑εΦ(ε)=1\sum_{\varepsilon}\Phi(\varepsilon)=1, which implies that one choice makes every factor 1.

Expand the operators by contraction degree. At its target a singular program has zero constant in both factors, so it consumes at least one degree in each. A nonsingular program has constant 1 independent of its parameter. Summing that parameter cancels a term using only its constants everywhere; a surviving term must consume at least one degree somewhere for that program. The total of these minimum costs is

D=∑x≠0(dx+ex).D=\sum_{x\ne0}(d_x+e_x).

A nonzero term cannot consume more, since some factor would then be differentiated beyond its degree. Every surviving term therefore uses each minimum cost exactly.

Thus a singular program contributes precisely Δz\Delta_z in each factor at its target and constants elsewhere. A nonsingular program contributes degree one in exactly one factor. Summing its parameter kills that contribution away from its target and gives Δz\Delta_z at the target; every other occurrence contributes the common constant 1. In particular, no higher forest coefficient remains.

At one address put Zi={z:νxz=i}Z_i=\{z:\nu_{xz}=i\} for i=1,2i=1,2, and write zJ=∏z∈Jzz_J=\prod_{z\in J}z. The surviving allocation sum is

∑J⊆Z1[zZ2zJ]Pxtop[zZ2zZ1∖J]Rxtop=[Mx](PxtopRxtop)=1.\sum_{J\subseteq Z_1}[z_{Z_2}z_J]P_x^{\mathrm{top}}[z_{Z_2}z_{Z_1\setminus J}]R_x^{\mathrm{top}}=[M_x](P_x^{\mathrm{top}}R_x^{\mathrm{top}})=1.

Wrong-degree coefficients are zero. Since the total degree is DD and no factor exceeds its degree, each factor receives its full degree; its derivative is exactly the displayed coefficient, independent of the baseline. Allocations at distinct addresses are independent, so their product is 1. This covers constant factors too. For instance, if both top forms are zz, their ordinary product is z2z^2: a singular program differentiates each once. Boolean reduction would lose that allocation.

Choose parameters with Φ=1\Phi=1 and realize the resulting finite graph by Lemma 6.1. Primary types preserve the filters and the stipulated neutral incidences and splitting conditions. Nonzero linear activations ensure that no new vertex appears at 0. □

For a stabilized symbol this is a finite construction at each dimension. First choose bb, the terminal data, and all networks; their weights and coefficient tests then have a finite bound. Select an actual stage where the numerical bounds and the finitely many stabilized symbol evaluations hold for that range. The required precision may grow with bb. The unit-valuation constant, however, is the constant of the coefficient construction and must be independent of bb; the forest argument supplies no additional uniformity assertion.

The converse with rational two-torsion

We prove the pointwise converse for curves with E(Q)[2]≠0E(\mathbb{Q})[2] \ne0. The finite graph construction supplies binary families with a unit coefficient at every nonzero address. Cyclotomic interpolation settles the even case. For the odd case we first establish the missing lower bound for the moving coefficient system, then keep one nonvanishing quadratic companion fixed throughout the interpolation.

Fix such a curve E/QE/\mathbb{Q}. We use the prime weights w(h)w(h), normalized values L(h)\mathcal{L}(h), and finite 22-primary Shafarevich–Tate lengths s(h)s(h) from the preceding sections. The corank c2(E(h))c_2(E^{(h)}) is a different quantity: a corank-zero base has finite s(h)s(h) before analytic nonvanishing is known. All new primes are odd primes of good reduction. A filter fixes the real sign and the local unit squareclasses at a finite support containing 2N2N, and may exclude any further fixed finite set.

For a signed parameter hh, write A(h)A(h) for the symbol at the positive index ∣h∣|h| on its chosen filter. We will use two bounds attached to a unit coefficient:

A(h)=1 in the even system⟹L(E(h),1)≠0,v(L(h))≤2w(h)+C,A(h)=1 in the odd system⟹a(E(h))=1,j(Ph)≤w(h)+C.\begin{aligned} A(h) = 1 \text{ in the even system} &\Longrightarrow L(E^{(h)},1) \ne0,\qquad v(\mathcal{L}(h)) \le2w(h) + C,\\ A(h) = 1 \text{ in the odd system} &\Longrightarrow a(E^{(h)}) = 1,\qquad j(P_h) \le w(h) + C. \end{aligned}

Here PhP_h is the genus Heegner sum with a fixed analytic-rank-zero partner h∗h_\ast, and j(Ph)j(P_h) is its free-line index valuation. The first bound is available from the even coefficient construction and Theorem 3.5. We use the second only after Proposition 7.7 has supplied the arithmetic lower bound required to normalize the odd system. The contraction and isolation identities are those of Theorem 5.10; their finite graph consequences were proved in Section 6.

Write jh(k)=j(P∣h∣(h))j_h(k) = j(P_{|h|}(h)) for the ring-class index over K=Q(k)K = \mathbb{Q}(\sqrt{k}). Theorem 3.7 states that, if k<0k < 0 is an odd fundamental discriminant with (k,2Nh)=1(k,2Nh) = 1, has at most AA prime factors, is square at 2Nh2Nh, and defines a nonexceptional imaginary field, and the twists h,hkh,hk have analytic orders one and zero, then

2jh(k)≥4w(h)+s(h)+s(hk)−CE,A.(37)2j_h(k) \ge4w(h) + s(h) + s(hk) - C_{E,A}. \tag*{(37)}

All coefficient and interpolation constants depend on the fixed curve, its parametrization, and fixed local data. A bound on ω(k)\omega(k) may enter CE,AC_{E,A}; the sizes of its primes do not. The finite networks, required coefficient precision, and prime sizes may depend on the binary dimension. The unit bounds in Equations eq:7.1 and eq:7.2 may not.

By Lemma 2.2, an isogeny preserves analytic rank and Selmer corank. If the isogeny class contains a curve with full rational two-torsion, we use that curve. Otherwise choose a rational two-isogeny E→E′E \to E' and write F=Q(E[2])F = \mathbb{Q}(E[2]), F′=Q(E′[2])F' = \mathbb{Q}(E'[2]); both fields are quadratic. A prime split in FF is called split, and one inert in FF is called simple. Their weights are respectively 11 and 1/21/2. A simple prime is good if it is also inert in F′F'. At such a prime

#E(Fp)≡2(mod4).(38)\#E(\mathbb{F}_p) \equiv2 \pmod4. \tag*{(38)}

Indeed there is exactly one nonzero rational two-torsion point in the reduction. If the group order were divisible by four, its two-primary subgroup would contain a rational point of order four. Its image under the two-isogeny would supply an E′E' rational two-torsion point different from the dual kernel, contradicting inertness in F′F'. Thus the good-twin rule applies. When F=F′F = F', every simple prime is good.

Seeds and finite supplies

The word “label” below means an individually realizable fixed-support elementary Frobenius label, with orientations when required. It does not include a self-residue of a prime generator. All contractions and comparisons are those of Theorem 5.10 and Lemma 6.3.

Lemma 7.1 (Minimum seeds). 1. In an all-split alphabet, suppose a unit symbol has a nonempty witness. At the least positive vertex count rr of such a witness, all mutual edge bits are immaterial. The symbol is determined by the individual fixed-support labels. This remains true if the empty configuration is a unit, provided no contraction to the empty configuration is used.

  1. In the quadratic case, suppose the symbol has a nonzero witness, the alphabet is closed under the allowed contractions, and it contains the good twin operations. There are r≥0r \ge0 and s1≥1s_1 \ge1 such that for every s≥s1s \ge s_1 of the permitted simple parity, the minimum split count of a unit with ss simple vertices is rr. At these counts all edge bits are immaterial. A chosen minimum seed may be padded by arbitrarily many good twin pairs.

The assertions also hold for a stabilized moving odd symbol, with every particular finite list of uses made at a sufficiently advanced stage.

Proof. For the first assertion, a derivative in an edge of an rr-vertex graph is a symbol on r−1r-1 vertices. If r≥2r \ge2, this graph remains nonempty and has value zero by minimality. If r=1r=1, there is no edge. The omitted-vertex description then leaves exactly the fixed-support labels.

For the second assertion let r(s)r(s) be the minimum split count at simple count ss, with value +∞+\infty when no witness exists. Once a finite value occurs, good-twin insertion gives r(s+2)≤r(s)r(s+2) \le r(s). A nonincreasing sequence of nonnegative integers stabilizes. Choose s1≥1s_1 \ge1 in that range. A derivative of an edge with a split endpoint reduces the split count and preserves the simple count; it is therefore zero at the minimum. A simple–simple derivative is zero by the symbol rule. Twin insertion gives the last assertion.

For the moving system, take the minimum and the nonincreasing sequence in the stabilized profile. Each comparison just used involves bounded vertex counts. A failure on an ultrafilter-large set of stages at any one such bound would produce a bounded-weight sequence contradicting that minimum. Thus any fixed finite collection holds on an ultrafilter-large intersection of stages, from which an arbitrarily high stage may be chosen. No assertion about every sufficiently high stage, or about all unbounded counts at one stage, is needed.

Recall that a list is partitionable when a permitted contraction forest has a unit symbol as its output. Its terminal polynomial is then nonzero, since the indicated iterated finite difference is nonzero.

Lemma 7.2 (Finite label reserves). Fix a minimum seed and a finite label alphabet.

  1. In the all-split rational alphabet, a list with the same total label as the seed and sufficiently many copies of its labels is partitionable.

  1. In the quadratic alphabet, retain rr split anchors with the seed labels. Suppose there are sufficiently many simple vertices of the required parity and sufficiently many split reserves of each realizable rational shift. If F≠F′F \ne F', also suppose

Δ=#{p:p split in F and inert in F′}−#{p:p inert in F and split in F′}>C0.(39)\Delta= \#\{p : p\text{ split in }F\text{ and inert in }F'\} -\#\{p : p\text{ inert in }F\text{ and split in }F'\} > C_0. \tag*{(39)}

Here C0C_0 depends only on the anchors and the reserves. Then all other split vertices can be attached to simple vertices so that the result is the minimum seed and good twin pairs. The twins may match a prescribed finite enrichment of the rational labels. The base simple labels may be specified on any projection on which the required total agrees.

All reserve requirements depend only on the finite alphabets, seed, and projection. They do not depend on the original list length.

Proof. In the first case retain the first r−1r-1 seed labels and merge all other vertices to the last cluster. Sufficient copies ensure that this cluster is nonempty. Its label is forced by the total, hence is the last seed label. Lemma 7.1 makes its unknown edges immaterial.

For the second case, the rational labels of split attachments form the subgroup with trivial FF-coordinate. They act transitively on the simple coset, so every prescribed change of a simple label has a realizable split shift. Reserve sufficiently many representatives of every such shift. Remove these reserves and the anchors from the donor pool. If F≠F′F \ne F', (39), with C0C_0 exceeding the number removed, leaves a distinct donor for each bad simple vertex. Attach these donors; every simple vertex is now good. If F=F′F = F', this operation was unnecessary.

Pair equal enriched good labels. By withholding a bounded number of pairs, leave between s1s_1 and s1+C1s_1+C_1 unpaired vertices, with the correct parity; C1C_1 depends only on the number of enriched labels. Use reserved shifts to turn the excess unpaired vertices into good pairs and to set the first s1−1s_1-1 base positions to the desired seed labels. The seed labels themselves need not all be good. Attach every remaining nonanchor split vertex to the last base position. Its projected label is forced by the total, the anchors, the other base positions, and the twin pairs. It is the required last seed label. Each cluster contains one simple vertex, so every contraction is permitted. Only a bounded number of reserve shifts was used.

When incidences to a retained split anchor are needed only to remove twins, they can be prescribed after the contracted labels are fixed, by the independent terminal-edge realization. Fixed stationary vertices instead enter the finite label enrichment from the outset. These two uses do not increase the number of label types with the original list length.

Lemma 7.3 (Neutral packets). For any of the finite reserve problems above with prescribed rational total zero, one can choose a finite packet of terminal labels with rational total zero such that every nonempty union of copies of the packet has the required supplies. In the quadratic case with F≠F′F \ne F', its donor surplus may be made arbitrarily large. Compatible fixed splitting conditions may be included whenever the needed individual labels and shifts remain realizable.

Proof. Choose ample copies of every required label, including anchors and shifts. When the quadratic fields F,F′F,F' are distinct, add enough donors to exceed all the losses from the other labels and the prescribed reserve margin. When F=F′F = F', every simple vertex is already good. Duplicate every full label in the resulting list. Duplication gives total zero in every rational elementary coordinate and preserves any strict donor surplus. Choose the margins so that after reserving the finitely many anchors in any one packet, the union of any positive number of packets still meets the reserve requirements. All labels are realized by distinct fresh primes; duplication never means repeating an actual prime factor.

The even converse and its uniform estimate

Proposition 7.4 (Even original base). If c2(E)=0c_2(E)=0, then a(E)=0a(E)=0.

Proof. Parity gives even functional sign. Fix an even symbol on the filter of 1, including all auxiliary class-group tests. If its value at 1 is a unit, analytic nonvanishing is already detected. Otherwise use a nonempty minimum seed in the full-torsion case, or a stabilized quadratic seed in the other case.

For each bb, assign a neutral packet from Lemma 7.3 to every nonzero linear form on Fb2\mathbb{F}_b^2, and activate its primes by that form. At every nonzero address at least one packet is active; their union satisfies the reserve problem and has a nonzero terminal polynomial. At zero no terminal is active. The single-symbol case of Theorem 6.6 adds primary auxiliaries and makes the symbol a unit at every nonzero address. All local classes remain those of 1. Equation (7.1) gives the uniform bound at all nonzero vertices. Theorem 3.1, applied at the original corank-zero base, now gives a(E)=0a(E)=0.

Proposition 7.5 (Partitionable even estimate). Fix an even unit symbol on a prescribed filter. For every partitionable parameter hh on its filter with c2(E(h))=0c_2(E^{(h)})=0,

L(h)≠0,v(L(h))−2w(h)−s(h)≤C.(40)\mathcal{L}(h)\ne0,\qquad v(\mathcal{L}(h))-2w(h)-s(h)\le C. \tag*{(40)}

The constant depends only on the symbol and fixed local data.

Proof. If the parameter has no prime factors, the only contraction is the identity, so partitionability means that the empty symbol itself is a unit. Equation (7.1) then proves the assertion directly. Otherwise the stationary terminal set is nonempty. Keep the prime factors of hh stationary. The iterated edge difference along the defining contraction forest is 1, so their terminal polynomial is nonzero. The stationary one-symbol case of Theorem 6.6 gives arbitrarily large binary cubes based at hh, with only primary new primes, whose other addresses have unit symbol. Equation (7.1) and s(hx)≥0s(h_x)\ge0 give the uniform upper bound required by the cyclotomic transfer. The base corank is zero, so Theorem 3.1 gives (7.6). A base-dependent dimension threshold does not affect the asserted constant.

The lower bound needed for odd coefficients

The even estimate also supplies the arithmetic hypothesis of Proposition 4.2. For an already analytic-rank-one parameter hh, we choose a companion k′=k′(h)k'=k'(h) with boundedly many prime factors and estimate the central value at hk′hk'. Comparing the ring and genus Heegner sums then bounds j(Ph)j(P_h) from below. The companion in this argument may vary with hh; the odd coefficient system has not yet been normalized.

To compare the two fixed isogenous curves E,E′E,E', add subscripts to s,w,Ls,w,\mathcal{L}. At a parameter hh already known to have analytic rank zero, both twists have finite Tate–Shafarevich groups by the forward theorem. Cassels's isogeny formula for the arithmetic BSD quotient [16], as explained in Tate [72], [Theorem 2.1 and the following discussion], gives

sE(h)+2wE(h)=sE′(h)+2wE′(h)+OE,E′(1).(41)s_E(h)+2w_E(h)=s_{E'}(h)+2w_{E'}(h)+O_{E,E'}(1). \tag*{(41)}

Indeed, at an active odd good prime the component-group valuation is tpt_p for the corresponding curve, so the active Tamagawa valuations sum to twice its weight. At the fixed support only finitely many local twisting classes occur. Differential, period, and torsion ratios are bounded by the fixed isogeny and its reverse, and the rank-zero regulator is 1. These account for the bounded error in (7.7). The isogeny identity applies to the known finite groups and does not assume the BSD value formula.

The two twists have the same LL-function. Their fixed normalizing periods therefore give v(L(E(h)))−v(L(E′(h)))=ΩE,E′(1)v(L(E(h))) - v(L(E'(h))) = \Omega_{E,E'}(1), uniformly in hh. Combining this with (41) shows that v(L(h))−2w(h)−s(h)v(L(h)) - 2w(h) - s(h) changes by a uniformly bounded amount. Consequently (40) transfers in either direction with one constant, even when the choice between the two fixed isogeny orientations depends on hh.

Lemma 7.6 (A bounded companion for a varying odd parameter). Fix a positive odd-sign filter and a negative genus partner h∗h_\ast with L(E(h∗),1)≠0L(E^{(h_\ast)},1) \ne0, chosen using Proposition 3.8 and then excluded from the variable parameters. There are constants A,CA,C such that every hh on this filter of analytic order one admits a negative odd fundamental discriminant k′k' for which

  1. (k′,2Nh)=1(k',2Nh)=1, k′k' is a square at every place of 2Nh2Nh, and Q(k′)\mathbb{Q}(\sqrt{k'}) is nonexceptional;

  2. ω(k′)≤A\omega(k') \le A;

  3. L(E(hk′),1)≠0L(E^{(hk')},1) \ne0 and

v(L(hk′))≤2w(hk′)+s(hk′)+C.(42)v(L(hk')) \le2w(hk') + s(hk') + C. \tag*{(42)}

Proof. Choose the class-group support and all other fixed label tests before varying hh. Prepare an even negative-index symbol for each possible total type at this support, and for both isogeny orientations if needed. There are finitely many such preparations. The positive index ∣hk′∣|hk'| has nonzero total rational type: its negative-discriminant parity is already nontrivial among the tests at 2. Thus in the full-torsion case a unit seed has positive count. In the quadratic case use the stabilized seed of Lemma 7.1.

When F≠F′F \ne F', interchanging the isogeny orientation interchanges the two counts in (39). Select the orientation with initial balance at least zero. The existing donors can then pay for arbitrarily many existing bad simples. They do not have to be supplied by new primes.

Let RR be the absolute prime-count bound in Proposition 3.8. Insert in k′k' a finite dummy supply that meets the anchors, minimum simple count, and reserve requirements for every one of the finitely many prepared symbols. When the quadratic fields F,F′F,F' are distinct, add donor slack paying for every reserved loss, the new dummy bad simples, and a further possible loss of RR from the later rough factor. Add a fresh ramified prime if needed to exclude the exceptional imaginary fields. The number of dummy primes is bounded independently of hh. Their labels and initial incidences may be chosen by Lemma 6.1.

Absorb hh and the dummy product into the curve. Apply Proposition 3.8 to complete k′k' by a squarefree factor coprime to all primes already used. Prescribe its sign and its local unit classes so that the final k′k' is an odd negative fundamental discriminant, is a square at 2Nh2Nh, and has the required original local classes at 2N2N. These conditions are reduced congruences at the level of the absorbed curve. Additional fixed primes may be excluded. The lemma makes the central value at hk′hk' nonzero with at most RR new factors. Its size threshold may depend on hh and all these congruences; RR does not.

No particular resulting unit class at the auxiliary class-group support was assumed in advance: dummy supplies were prepared for every possible total there. For the actual total, Lemma 7.2 makes hk′hk' partitionable. Analytic nonvanishing gives Selmer corank zero by the forward theorem. Proposition 7.5 therefore gives (42), with the isogeny comparison above if the other orientation was used. The finite preparation and the bound on dummy and rough factors give A,CA,C independent of hh.

Proposition 3.2 compares the genus sum PhP_h with the ring-class sum over K=Q(k)K=\mathbb{Q}(\sqrt{k}):

2jh(k)−2j(Ph)=v(L(hk))+O(1)(43)2j_h(k) - 2j(P_h) = v(L(hk)) + O(1) \tag*{(43)}

whenever the two twists have analytic orders one and zero. The error is uniform in hh for fixed kk, and uniform in hh, kk when ω(k)\omega(k) is bounded and the prescribed local classes are retained. Thus the same comparison applies to the bounded companions just constructed.

Proposition 7.7 (Uniform lower bound for the odd detector). Every analytically rank-one hh in the fixed positive filter satisfies

2j(Ph)≥2w(h)+s(h)−C.(44)2j(P_h) \ge2w(h) + s(h) - C. \tag*{(44)}

In particular j(Ph)≥w(h)−Cj(P_h) \ge w(h) - C uniformly in hh and its prime count.

Proof. Choose k′k' by Lemma 7.6. Combine (7.3), (7.9), and (7.8). Since the factors are coprime, w(hk′)=w(h)+w(k′)w(hk') = w(h) + w(k'), and w(k′)≤ω(k′)≤Aw(k') \le\omega(k') \le A. Hence

2j(Ph)≥4w(h)+s(h)+s(hk′)−v(L(hk′))−C≥2w(h)+s(h)−2w(k′)−C≥2w(h)+s(h)−C′.\begin{aligned} 2j(P_h) &\ge4w(h) + s(h) + s(hk') - v(\mathcal{L}(hk')) - C \\ &\ge2w(h) + s(h) - 2w(k') - C \\ &\ge2w(h) + s(h) - C'. \end{aligned}

Only even symbols and independently nonvanishing companions were used. Thus this proof precedes, and does not assume, the odd minimum-depth normalization.

A fixed companion for the odd converse

Suppose the functional sign is odd. By Proposition 7.7, the odd coefficient system can now be normalized on the positive filter of 1. Fix its old support and genus partner h∗h_\ast. Its moving detecting prime ℓ\ell has not become an extra fixed support requirement.

Choose a separate even symbol for negative discriminants square at 2N2N, excluding the fixed odd support, the relevant torsion ramification, and the exceptional imaginary fields. Choose a unit kk of that symbol. Then L(E(k),1)≠0L(E^{(k)}, 1) \ne0. Fix this kk and K=Q(k)K = \mathbb{Q}(\sqrt{k}) for the rest of the construction, before choosing any cube dimension. Its fresh ramification makes it independent of the old fixed label extensions. At sufficiently advanced stages ℓ\ell avoids kk. The intrinsic odd label tests continue to omit the primes of kk. When the odd symbol already detects the base, the converse follows directly. We henceforth consider the remaining case, in which the odd symbol has the nonempty seed described above.

For the moving odd source, fix its stabilized minimum depth and seed profiles before constructing packets. A bounded-weight seed has boundedly many vertices here, since every prime has weight at least 1/21/2. For each fixed field used in the labels, permitting ramification above the one moving prime ℓ\ell adds only boundedly many dimensions to its elementary squareclass space. Identify these spaces compatibly with their fixed projections and stabilize the finitely many seed and label profiles. The reserve bounds of Lemma 7.2 are uniform over these profiles, so the packet constructions below have a fixed size. They are finite tables of labels; their prime representatives will be chosen at an actual coefficient stage after the networks and their weight bounds have been specified.

Our remaining task is to construct, for every binary dimension, a family in which the odd test at hh and an even test at hkhk are simultaneously units away from the zero address. Every new prime will split in this single field KK. For quadratic FF, the good-twin rule makes the unit at kk a nonzero even test on additional prime configurations. With full rational two-torsion, the restriction to KK-split primes can instead leave only the empty configuration at the original minimum depth. The next construction supplies a nonempty witness in exactly that case; its extra division changes the valuation estimate by a fixed constant.

A nonempty witness with full rational two-torsion

Lemma 7.8 (Recurrence congruences). Let pp be odd, a≡p+1(mod4)a \equiv p+1 \pmod{4}, and let

b0=1,b1=a−κ,bs+1=abs−pbs−1.b_0=1,\qquad b_1=a-\kappa,\qquad b_{s+1}=ab_s-pb_{s-1}.

If κ=±1\kappa=\pm1, then bs+1−bsb_{s+1}-b_s is even and

bs+1−bs2≡a−κ−12(mod2)(s≥0).\frac{b_{s+1}-b_s}{2}\equiv\frac{a-\kappa-1}{2}\pmod{2}\qquad(s\geq0).

If κ=0\kappa=0, put b−1=0b_{-1}=0; then bs−bs−1b_s-b_{s-1} is odd for every s≥0s\geq0. Finally, for κ=1\kappa=1, if a≡p+1(mod2m)a\equiv p+1\pmod{2^m} then bs≡ps(mod2m)b_s\equiv p^s\pmod{2^m} for every s≥0s\geq0.

Proof. Modulo 2 the recurrence is bs+1=bs−1b_{s+1}=b_{s-1}. Its initial values prove the parity assertions. For ds=bs+1−bsd_s=b_{s+1}-b_s, the recurrence for dsd_s is the same. Directly, d1−d0≡(p−1)(p−κ)≡0(mod4)d_1-d_0\equiv(p-1)(p-\kappa)\equiv0\pmod{4} when κ=±1\kappa=\pm1. Thus ds/2d_s/2 is constant modulo 2. The last assertion follows by substituting the sequence psp^s in the recurrence and checking its first two terms. □\square

Lemma 7.9 (Nonempty KK-split witness). Suppose E[2]E[2] is rational. Choose a negative unit kk of a fixed even symbol for EE, prime to all previous fixed support and to the ramification support of E[8]E[8]. Put K=Q(k)K=\mathbb{Q}(\sqrt{k}), chosen nonexceptional. Let S0S_0 contain 2N2N, the primes of kk, and primes generating the class group of KK. On the positive filter of 1 square at S0S_0, there is an even unit test on nonempty products of primes split in KK with these properties:

  1. it has a nonempty witness;

  2. it satisfies the oriented split contraction and primary-isolation rules over KK, for contractions with nonempty output;

  3. a unit at DD implies

L(E(kD),1)≠0,v(L(kD))≤2ω(D)+Ck.(45)L(E^{(kD)},1)\ne0,\qquad v(\mathcal{L}(kD))\leq2\omega(D)+C_k. \tag*{(45)}

The proof uses Lemmas 5.3 and 5.4 to construct a further divided coefficient test.

Proof. Let a0(n)a_0(n) be the coefficients of the original negative-index form for EE. Since kk attains its least normalized depth, v(a0(∣k∣D)/a0(∣k∣))≥ω(D)v(a_0(|k|D)/a_0(|k|))\geq\omega(D) whenever kDkD lies on its filter. Use the ordinary even coefficient form for E(k)E^{(k)}, normalized by a(1)=1a(1)=1, on the positive filter of 1 square at S0S_0. The two exact comparisons in (12) give

2v(a(D))=v(DL(E(kD),1)L(E(k),1))=2v(a0(∣k∣D)a0(∣k∣)).2v(a(D))=v\left(\frac{\sqrt{D}L(E^{(kD)},1)}{L(E^{(k)},1)}\right)=2v\left(\frac{a_0(|k|D)}{a_0(|k|)}\right).

Indeed, the period and the factor ∣k∣\sqrt{|k|} cancel in the old ratio, and the new period cancels in the new ratio. Enlarging S0S_0 only restricts the allowed DD, so the original minimum still gives

v(a(D))≥ω(D)(46)v(a(D))\geq\omega(D) \tag*{(46)}

at every allowed squarefree DD.

If equality holds at a nonempty product of KK-split primes, use the usual even bit, projected from oriented KK-labels to rational labels. It has all the required properties by Theorem 5.10. We therefore assume for the rest of the proof that equality never occurs there. By the rational-phase assertion in Proposition 4.1, normalization by a(1)=1a(1)=1 makes each nonzero squarefree coefficient a rational number times a root of unity. Its valuation is an integer, not just an element of the possibly ramified coefficient field’s discrete value group. Thus strict inequality implies

v(a(D))≥ω(D)+1(47)v(a(D)) \ge\omega(D) + 1 \tag*{(47)}

for every nonempty allowed all-KK-split DD.

Write g=∑a(n)qng=\sum a(n)q^n for the form. Its characters satisfy ψ/η=χ−4\psi/\eta=\chi_{-4}; since the scalar character ψ\psi is even, η\eta is odd. For a set UU of KK-split primes put

BU=2−∣U∣∏p∈U(Up−η(p)Vp)g,ΘJ=∑m>0(m,S0)=1η(m)mqJm2.B_U=2^{-|U|}\prod_{p\in U}(U_p-\eta(p)V_p)g,\qquad\Theta_J=\sum_{\substack{m>0\\(m,S_0)=1}}\eta(m)m q^{Jm^2}.

All expansions retain the prescribed support sieves. The ordinary divided form is

HU=12(BU−∑J⊆UBU[J]ΘJ).H_U=\frac{1}{2}\left(B_U-\sum_{J\subseteq U}B_U[J]\Theta_J\right).

Here BU[J]B_U[J] denotes its coefficient at the squarefree index JJ.

The mod-8 consequence. We first prove

ap(E(k))≡p+1(mod8)(48)a_p(E^{(k)})\equiv p+1\pmod{8} \tag*{(48)}

for every allowed good pp split in KK.

Put f=H{p}θf=H_{\{p\}}\theta and apply its trace at a Frobenius lift ϕp\phi_p, testing coefficient p2p^2. The terms B{p}θB_{\{p\}}\theta and Θ{p}θ\Theta_{\{p\}}\theta have the same character, whose pp-part is primitive quadratic. Thus they have no pp-old constituent. On their conductor-one ramified principal-series constituents the identity is

Up2t(ϕp)=Up3+d(ϕp)Up.U_p^2t(\phi_p)=U_p^3+d(\phi_p)U_p.

The remaining term Θ∅θ\Theta_{\varnothing}\theta is unraised, and obeys the ordinary good-prime coefficient identity. Consequently

(t(ϕp)f)[p2]=f[p3]+(d(ϕp)f)[p].(t(\phi_p)f)[p^2]=f[p^3]+(d(\phi_p)f)[p].

Replace the trace by a fresh split prime p′p' with the same finite data, including every support-unit test. At each rational quadratic character unramified outside S0S_0, a Frobenius lift at pp has the character value of pp. Hence the matched p′p' has the same value, and pp′pp' has value 11. Equivalently, p′p' has the same unit squareclasses as pp at all places of S0S_0, so their product is square at all of them, including 22. Since ϕp∈GK\phi_p\in G_K, the new prime is also split in KK. Its coefficient on the left tests pp′pp'; by (47) it is zero modulo the maximal ideal after the two divisions. To check the determinant term, let d1,d0d_1,d_0 be the determinant scalars on the raised and unraised character spaces. Then

d(ϕp)f=d1f+B{p}[1]2(d1−d0)Θ∅θ.d(\phi_p)f=d_1f+\frac{B_{\{p\}}[1]}{2}(d_1-d_0)\Theta_{\varnothing}\theta.

The character difference (d1−d0)/2(d_1-d_0)/2 is integral. Also f[p]≡H{p}[p]=0f[p]\equiv H_{\{p\}}[p]=0 modulo the maximal ideal, since Θ{p}[p]=1\Theta_{\{p\}}[p]=1, whereas (Θ∅θ)[p]≡Θ∅[p]=0(\Theta_{\varnothing}\theta)[p]\equiv\Theta_{\varnothing}[p]=0 because θ≡1\theta\equiv1 and pp is nonsquare. Thus (d(ϕp)f)[p]=0(d(\phi_p)f)[p]=0 after reduction. This cancellation uses the two character spaces together.

On the right, the indices pp and p3p^3 in B{p}B_{\{p\}} have underlying squarefree index 11; they involve only a(1),a(p2),a(p4)a(1),a(p^2),a(p^4). The J=∅J=\varnothing unary term has no coefficient at either nonsquare index. Thus no other squarefree coefficient contributes there. For a=ap(E(k))a=a_p(E^{(k)}), the phase-free square coefficients are 11, a−1a-1, a(a−1)−pa(a-1)-p. Hence the remaining coefficient is, up to a unit,

H{p}[p3]=a2−2a−p+1−p(a−2)4=(a−1)(a−p−1)4.H_{\{p\}}[p^3]=\frac{a^2-2a-p+1-p(a-2)}{4}=\frac{(a-1)(a-p-1)}{4}.

This quotient is rational. Its vanishing in the residue field therefore gives a positive integral 22-adic valuation, so it is divisible by 2. Full rational two-torsion makes aa even, so a−1a-1 is odd; this proves (48). No individual total filter condition on pp was needed: its matched prime p′p' makes pp′pp' lie on the filter, and the square-index terms on the right come from 1.

One further division by 2. Define

H~U=14(BU−∑J⊆UBU[J]ΘJ).(49)\widetilde{H}_U=\frac{1}{4}\left(B_U-\sum_{J\subseteq U}B_U[J]\Theta_J\right). \tag*{(49)}

We verify integrality at every coefficient. Write a test index uniquely as Jrm2Jrm^2, where J⊆UJ\subseteq U and rr is squarefree and disjoint from UU. The underlying squarefree coefficient is at D=(U/J)rD=(U/J)r. Removing the unit phases, a prime of U/JU/J contributes an odd factor bs−bs−1b_s-b_{s-1} with κ=0\kappa=0, and a prime of JJ contributes bs+1−bsb_{s+1}-b_s with κ=(D/p)\kappa=(D/p). Thus

v(BU[Jrm2])≥ω(r)(50)v(B_U[Jrm^2])\geq\omega(r) \tag*{(50)}

by (46), with one additional unit of valuation when DD is nonempty and all its primes split in KK.

If r≠1r\ne1 and all primes of DD split in KK, the last inequality is at least ω(r)+1≥2\omega(r)+1\geq2. If DD contains an inert prime, then rr contains at least two: the total rational KK-character is trivial on the filter, and all primes of UU split. Then (50) is again at least 2. No unary term has this squarefree part. This proves divisibility by 4 for r≠1r\ne1.

Suppose r=1r=1 and J≠UJ\ne U. Then D=U/JD=U/J is nonempty and all split, so BU[J]B_U[J] is even. This cancellation can be checked without dividing by a leading multiplier, which may be zero. Factor from both shell coefficients the common phase and the scalar 2−∣U∣+∣J∣a(U/J)2^{-|U|+|J|}a(U/J), whose valuation is at least 1 by (47). The remaining factors are the odd differences at U/JU/J, the integral divided differences at JJ, and the ordinary square-index factors outside UU. By Lemma 7.8, their product is congruent modulo 2 to the product of their leading values, even when one of those values is zero modulo 2. Since mm is odd, multiplication by mm preserves this congruence. The common scalar supplies the second factor 2. Retaining the phase η(m)\eta(m) therefore gives

BU[Jm2]≡BU[J]η(m)m(mod4).B_U[Jm^2]\equiv B_U[J]\eta(m)m\pmod{4}.

This is exactly the cancellation with BU[J]ΘJB_U[J]\Theta_J.

Finally let J=UJ=U, so D=1D=1. At a prime outside UU the recurrence gives bs≡ps(mod4)b_s\equiv p^s\pmod{4}. At a prime of UU, (48) gives bs≡ps(mod8)b_s\equiv p^s\pmod{8}, and hence

bs+1−bs2≡ap−22ps(mod4).\frac{b_{s+1}-b_s}{2}\equiv\frac{a_p-2}{2}p^s\pmod{4}.

Multiplying these congruences, again retaining the phases, gives BU[Um2]≡BU[U]η(m)m(mod4)B_U[Um^2]\equiv B_U[U]\eta(m)m\pmod{4}. This proves integrality in the last case and establishes (49). Diamonds preserve this lattice: when J≠UJ\ne U, BU[J]B_U[J] is even and the quadratic character difference supplies another factor 2; when J=UJ=U, the characters agree exactly.

The new symbol and its witness. Multiply (49) by ordinary theta and use the integral trace operators. Two fresh traces in GKG_K give zero after reduction at every coefficient. To see this, start with an arbitrary test index Jrm2Jrm^2 and choose the two fresh primes outside that index and the level. The filter imposes χK(D)=1\chi_K(D)=1; since UU is all split, the number of inert factors in rr is either zero or at least two. The fresh traces replace rr by rq1q2rq_1q_2, with both qiq_i split. In the first case the valuation after division by 4 is at least ω(r)+2+1−2=ω(r)+1≥1\omega(r)+2+1-2=\omega(r)+1\geq1. In the second case it is at least ω(r)+2−2=ω(r)≥2\omega(r)+2-2=\omega(r)\ge2. The unary terms disappear under these fresh tests. Additional fresh GKG_K traces only improve these estimates, so vanishing holds on the entire reduced trace orbit. The trace identity therefore gives

t(gu2)=t(g)(g,u∈GK)t(gu^2)=t(g) \qquad(g,u\in G_K)

on this reduced trace orbit. Thus the tests factor through the elementary extension of KK unramified off the level.

A single fresh KK-split trace at coefficient 11 reads the bit

A~(D)=(2−ω(D)−1a(D) with its phase removed) mod 2(51)\widetilde{A}(D)=\left(2^{-\omega(D)-1}a(D)\text{ with its phase removed}\right)\bmod2 \tag*{(51)}

for a nonempty all-split configuration. The contraction rule follows from the same integral local identity as in Lemma 5.4. For completeness its first shell, with p∈Up\in U and a fresh trace qq, has underlying configuration D′=(U/p)qD'=(U/p)q, which is still nonempty, and its reduction is

cp(D′)A~(D′),cp(D′)=ap−(D′/p)−12 mod 2.c_p(D')\widetilde{A}(D'),\qquad c_p(D')=\frac{a_p-(D'/p)-1}{2}\bmod2.

Changing the oriented inertia bit changes cpc_p once. The omitted-prime identity gives the product label and removes the entire rational prime pp from the new ramification support. Consequently its repeated contraction has precisely the forest interpretation of Lemma 6.3. An omitted-vertex label equal to the identity has trace zero, which is primary isolation. No contraction to the empty configuration has occurred.

It remains to prove that this deeper test has a witness. Fresh ramification gives K⊈Q(E[8])K\not\subseteq\mathbb{Q}(E[8]). By Chebotarev there is a good prime pp inert in KK and trivial on the original E[8]E[8]. Then

p≡1(mod8),ap(E)≡−2(mod8).p\equiv1\pmod8,\qquad a_p(E)\equiv-2\pmod8.

On H~∅\widetilde{H}_{\varnothing}, whose coefficient at 11 is zero, test t(u)2t(u)^2 at coefficient 11, where u=Fr⁡pu=\operatorname{Fr}_p. The square coefficient and matching unary character give, up to a unit,

ap(E(k))−1−p4 mod 2=1.\frac{a_p(E^{(k)})-1-p}{4}\bmod2=1.

The determinant term at coefficient 11 cancels. In characteristic two, t(u2)=t(u)2t(u^2)=t(u)^2, so a single trace in GKG_K is nonzero. A fresh prime realizing this finite trace test is split in KK. Moreover u2u^2 is trivial on every rational quadratic character, so the prime lies on the required total rational filter. It is a nonempty witness for (51). Finally the exact coefficient ratio gives (45), with the additional depth at most one.

Lemma 7.10 (Orientation correction). Let KK be imaginary quadratic, let S0S_0 contain 22 and its ramification support, and let V0V_0 be the elementary label space over KK unramified off S0S_0. Complex conjugation acts on V0V_0 by cc. If the rational total of an oriented prime configuration is zero on every rational quadratic character unramified off S0S_0, then its oriented total belongs to (1+c)V0(1+c)V_0. A reserved supply containing every label allows its orientations to be flipped to realize any prescribed change in (1+c)V0(1+c)V_0.

Proof. Complex conjugation has order two outside GKG_K, so GQ=GK⋊⟨c⟩G_{\mathbb{Q}}=G_K\rtimes\langle c\rangle. A cc-invariant quadratic character of GKG_K extends by giving cc value zero. At a rational prime outside S0S_0, inertia lies in GKG_K and the character is trivial there; thus its extension remains unramified outside S0S_0. The assumed total therefore annihilates (V0∗)c(V_0^*)^c.

For a finite vector space with involution, the annihilator of ker⁡(1+c∗)=(V0∗)c\ker(1+c^*)=(V_0^*)^c is im⁡(1+c)\operatorname{im}(1+c). This proves the first assertion. Flipping a vertex of label vv changes its oriented label from vv to cvcv, and hence changes the total by (1+c)v(1+c)v. Reserve one representative for every preimage needed to express the desired element of the image. Their independent flips give the second assertion. These flips preserve every rational norm label.

Common packets and rank-one interpolation

Proposition 7.11 (Families with a fixed companion). With the fixed odd coefficient system and companion kk chosen in Section 7.4, suppose the odd symbol at 11 is zero. There is a constant CC with the following property. For every b≥1b \ge1 there are distinct primes outside 2Nk2Nk and the fixed supports of both coefficient tests, with nonzero linear activations, such that their signed products hxh_x, x∈F2bx \in\mathbb{F}_2^b, satisfy h0=1h_0 = 1. Every hxh_x is positive and has the fixed local classes of 11, and every new prime splits in K=Q(k)K = \mathbb{Q}(\sqrt{k}). The primes also avoid the detecting prime of the actual odd coefficient stage. In particular (hx,k)=1(h_x,k) = 1 for every xx. For every x≠0x \ne0,

a(Ehx)=1,L(Ehxk,1)≠0,a(E^{h_x}) = 1,\qquad L(E^{h_xk},1) \ne0,

and

j(Phx)≤w(hx)+C,v(L(hxk))≤2w(hx)+C.j(P_{h_x}) \le w(h_x) + C,\qquad v(\mathcal{L}(h_xk)) \le2w(h_x) + C.

The constant CC and the discriminant kk are independent of bb.

Proof. We construct common terminal packets, individually split in KK, such that the odd terminal polynomial and an even terminal polynomial testing hkhk are separately nonzero at each nonzero address.

First suppose F,F′F,F' are quadratic. Keep the original even symbol evaluated on hkhk, treating the vertices of kk as stationary external data. Enrich the rational labels of the hh-vertices by the primes of kk. Their total there and at the even support is required to be zero. Let VV be the resulting rational elementary label space, including the FF, F′F' and KK coordinates and all relations among these characters. The allowed simple labels form the affine set {v∈V:χF(v)=1, χK(v)=0}\{v \in V : \chi_F(v) = 1,\ \chi_K(v) = 0\}, in additive notation. The difference of any two of its elements belongs to ker⁡χF∩ker⁡χK\ker\chi_F \cap\ker\chi_K, precisely the realizable rational labels of the permitted split attachments. Translation by this subgroup is therefore transitive. The fields F,F′F,F' are unramified outside the old support, whereas KK has a fresh ramified prime; thus KK is independent of their compositum. When F≠F′F \ne F', this realizes both the good-simple pattern (1,1,0)(1,1,0) and the donor pattern (0,1,0)(0,1,0) in their three coordinates. When F=F′F = F', all simple labels are good.

For the old odd projection, take a normal closure of its finite label extension, including the moving prime ℓ\ell at any stage realizing the stabilized profile. It is unramified outside the old support and ℓ\ell. Once ℓ\ell avoids kk, a prime ramified in KK remains outside that set. Hence KK has trivial intersection with this normal closure, and every old odd label can be realized together with splitting in KK. This applies also to oriented split anchors over FF. The added stationary kk coordinates may have relations, but they are already included in VV; they do not impose extra requirements on the omitted odd projection.

Use packets with the required simple supply and reserves in this kernel, and with sufficiently large donor slack when F≠F′F \ne F'. For the even test, take no split anchors. Correct all bad simples to good ones, pair equal enriched labels, and retain a nonempty good base pair. Use reserves to match the pair and the remaining good pairs, and attach every leftover split vertex to the last base position. Its label is forced by total zero. The output is a collection of good twin pairs, each matching also at every split vertex of kk. Twin insertion into the unit at kk proves that this output has even symbol one. Thus the even terminal polynomial is nonzero.

For the odd test, project away the newly added tests at kk. The same packets contain enough split anchors, simple vertices and reserve shifts to contract to the stabilized odd seed and good pairs, by Lemma 7.2. Its total on that projection is the prescribed zero total. Incidences between the retained anchors and the good pairs can be set after contraction, by independent edge choices. The odd polynomial is therefore nonzero as well. This odd test does not include the stationary vertices of kk.

Now suppose the curve has full rational two-torsion. Use the even test of Lemma 7.9, with KK-oriented labels on its support S0S_0, and let v1,…,vrv_1,\ldots,v_r be a minimum nonempty witness. Its oriented total v1+⋯+vrv_1+\cdots+v_r lies in (1+c)V0(1+c)V_0, by Lemma 7.10. Choose packets containing ample copies of every needed even label, all odd seed labels on their rational projection, and orientation-shifting reserves. In the common compositum, restriction to the even label extension is surjective, so each even label has a lift. Each intrinsic odd label also has a lift fixing KK: fresh ramification gives K∩Lodd=QK\cap L_{\mathrm{odd}}=\mathbb{Q}, and the moving odd prime avoids kk. Extending these elements to the common compositum gives the required lifts. Take sufficiently many lifts for each projection separately, without prescribing their other projection. Duplicate each full label, so the packet has rational total zero.

For the even contraction, retain anchors with labels v1,…,vr−1v_1,\ldots,v_{r-1}. After reserving these anchors, use orientation flips to make the total equal to ∑vi\sum v_i; this is possible by Lemma 7.10. Merge all remaining vertices into the last cluster. Its label is vrv_r. The cluster is nonempty, and the minimum nonempty count makes the output a unit independently of its mutual edges. For the odd contraction, use its rational projection. Every odd seed label lifts to a KK-split prime because KK was freshly ramified outside its intrinsic support. Retain all but the last odd seed label and merge the remainder. Total zero gives the last label, so this is also a unit. Orientation correction is conjugation over Q\mathbb{Q}, which preserves every rational quadratic label, including those at the moving odd prime. Adding kk to the common support has not added it to the intrinsic odd projection.

In both cases put a sufficient common packet at every nonzero linear form on F2b\mathbb{F}_2^b. Each nonzero address has two separately nonzero terminal polynomials. Theorem 6.6 supplies primary auxiliaries split in KK (and FF in the quadratic case), neutral at the stationary primes of kk, and makes both symbols one at every nonzero address. The auxiliary generators are primary at every support coordinate used by either projection. Thus the odd and even graph identities remain identities on the same common terminal polynomial data. All active products hh are positive and square at the fixed tests, and all their primes split in KK.

For each fixed bb, the terminal tables and networks now give a finite list of coefficient tests and a maximum weight. Choose the working precision after these bounds are fixed. Finer ray neighborhoods affect prime realization but do not enlarge the elementary label alphabet. Lemma 4.3 and Theorem 5.10 realize the required divisibilities and symbol identities on an ultrafilter-large intersection of stages. At an arbitrarily high actual stage in that intersection, realize the finite graphs by distinct primes. The unit-depth constants and the companion kk were fixed before bb was chosen, and therefore remain uniform in these realizations.

At each nonzero address the odd unit detects analytic rank one and gives j(Ph)≤w(h)+Cj(P_h)\le w(h)+C. The even unit detects L(E(hk),1)≠0L(E^{(hk)},1)\ne0 and gives ν(L(hk))≤2w(hk)+C\nu(\mathcal{L}(hk))\le2w(hk)+C, or the bound (7.11) in the full-torsion case. The fixed quantity 2w(k)2w(k) is absorbed into CC. These are the asserted estimates.

Proposition 7.12 (Odd original base). If fC2(E)=1f_{C_2}(E)=1, then a(E)=1a(E)=1.

Proof. Parity gives odd functional sign. Proposition 7.7 therefore permits the odd normalization used above. If its symbol at 1 is a unit, it already gives a(E)=1a(E)=1. Otherwise apply Proposition 7.11 for arbitrarily large bb. At every nonzero address its estimates and Proposition 3.2, with the fixed kk, give

2jh(k)≤4w(h)+C.2j_h(k)\le4w(h)+C.

The finite Sha lengths there are nonnegative. Hence 2jh(k)−4w(h)−s(h)−s(hk)≤C2j_h(k)-4w(h)-s(h)-s(hk)\le C, as required for Heegner interpolation.

At address zero, L(E(k),1)≠0L(E^{(k)},1)\ne0 gives c2(E(k))=0c_2(E^{(k)})=0 by Lemma 2.1. Lemma 2.2 gives

corank⁡Z2Sel⁡2∞(E/K)=c2(E)+c2(E(k))=1.\operatorname{corank}_{\mathbb{Z}_2}\operatorname{Sel}_{2^\infty}(E/K)=c_2(E)+c_2(E^{(k)})=1.

Since KK is fixed, the finite quotient of this base Selmer group has a fixed length. Theorem 3.3 makes L(E,s)L(E(k),s)L(E,s)L(E^{(k)},s) have a simple zero. Its second factor is nonzero at 1, so a(E)=1a(E)=1.

Theorem 7.13 (The rational-two-torsion converse). Let E/QE/\mathbb{Q} satisfy E(Q)[2]≠0E(\mathbb{Q})[2]\ne0 and c2(E)=corank⁡Z2Sel⁡2∞(E/Q)∈{0,1}c_2(E)=\operatorname{corank}_{\mathbb{Z}_2}\operatorname{Sel}_{2^\infty}(E/\mathbb{Q})\in\{0,1\}, with the local Kummer conditions at every place. Then

ord⁡s=1L(E,s)=c2(E).\operatorname{ord}_{s=1}L(E,s)=c_2(E).

There is no restriction on the rational isogeny configuration, complex multiplication, or reduction at 2 or at the bad primes.

Proof. The initial isogeny choice preserves both quantities and covers both rational two-torsion configurations. Proposition 7.4 proves the corank-zero case. In the corank-one case, Proposition 7.7 supplies the coefficient normalization, and Proposition 7.12 proves analytic rank one using a companion fixed before the binary dimension grows.

Selmer matrices and three-state relations

Assume that V=E[2]V=E[2] is irreducible, and write F=Q(V)F=\mathbb{Q}(V) and G=Gal⁡(F/Q)∈{C3,S3}G=\operatorname{Gal}(F/\mathbb{Q})\in\{C_3,S_3\}. The symbol rules will be useful because a unit symbol bounds the 2-Selmer dimension. We now express local Selmer conditions by a binary matrix and make that bound constrain the number of singular blocks. The second half of the section develops the elementary matrix operations needed to apply this constraint.

Write the Weil pairing additively, and choose a basis of VV in which its matrix is

J=(0110).J=\begin{pmatrix}0&1\\1&0\end{pmatrix}.

Fix a finite set SS containing 2, 3, the bad primes, all auxiliary exclusions, and rational primes whose prime ideals generate the class groups of every subfield of FF. Local specifications at SS will also include the archimedean places. The detecting prime ℓ\ell for an odd coefficient system is kept separate: all generators below have valuation zero there. This separation keeps the set of support types finite as ℓ\ell varies. We shall apply the construction to a fixed curve, after absorbing any initial quadratic twist into EE.

Global classes and local equations

At a split prime pp, choose a place of FF and put Hp=1H_p=1. At a simple prime, choose a place with Frobenius a specified transposition cc and put Hp=⟨c⟩H_p=\langle c\rangle. Set

Fp′=FHp,Vp=VHp.F'_p=F^{H_p},\qquad V_p=V^{H_p}.

Thus VpV_p has dimension two or one, respectively. The chosen place lies above a degree-one prime PpP_p of Fp′F'_p. By the choice of SS, there is πp∈(Fp′)×\pi_p\in(F'_p)^\times whose divisor away from SS is PpP_p. For x∈Vpx\in V_p define

Cp(x)=cor⁡Fp′/Q(χπpx)∈H1(Q,V).(52)C_p(x)=\operatorname{cor}_{F'_p/\mathbb{Q}}(\chi_{\pi_p x})\in H^1(\mathbb{Q},V). \tag*{(52)}

Here χπp\chi_{\pi_p} is the quadratic Kummer character; its product with xx is a cocycle because HpH_p fixes xx.

The inertia coordinate of Cp(x)C_p(x) at pp is xx, and all its other inertia coordinates outside SS vanish. Indeed, local restriction–corestriction has exactly one ramified summand, at the degree-one place where πp\pi_p has valuation one. These coordinates therefore make the classes for distinct pp independent. A root prime has VFr⁡p=0V^{\operatorname{Fr}_p}=0 and contributes no coordinates.

Let hh be a twist containing the active nonroot primes in its discriminant. At a good odd prime pp ramified in hh, inertia identifies the local Kummer condition with VpV_p. To see surjectivity, halve a Frobenius-fixed two-torsion point over the maximal unramified extension. The ramified twisting involution negates its half, so the resulting Kummer inertia is that two-torsion point. The Kummer condition has dimension dim⁡Vp\dim V_p by local duality, giving the asserted isomorphism.

Fix arithmetic Frobenius lifts ϕp\phi_p. A second local coordinate is unramified evaluation at ϕp\phi_p, modulo Frobenius coboundaries. Let Kp(x)(ϕp)K_p(x)(\phi_p) be this coordinate for the Kummer lift of inertia xx. It is determined by E[4]E[4] and the local twisting squareclass. Define the block matrix BB by

Bqp(y,x)=⟨Cp(x)(ϕq),y⟩−1p=q⟨Kp(x)(ϕp),y⟩,x∈Vp,y∈Vq.(53)B_{qp}(y,x)=\langle C_p(x)(\phi_q),y\rangle-1_{p=q}\langle K_p(x)(\phi_p),y\rangle,\qquad x\in V_p,\quad y\in V_q. \tag*{(53)}

Thus Bx=0Bx=0 is exactly the collection of active-prime Selmer equations for ∑pCp(xp)\sum_p C_p(x_p). Changing the unramified unit part of the twist adds JJ to a split diagonal block. On a simple line it changes nothing, since the Weil pairing restricts to zero on a one-dimensional space.

Record in the type hph_p the subgroup HpH_p and the squareclasses of πp\pi_p at the places over SS, including signatures. Only finitely many types occur. Finer generator neighborhoods will be used to reproduce self entries, but they are not part of this type alphabet and do not enter its codimension cost. Global reciprocity gives

Bqp+Bpqt=b(hq,hp).(54)B_{qp}+B_{pq}^{t}=b(h_q,h_p). \tag*{(54)}

where bb is the sum of the local cup pairings at SS. Indeed, at an active prime decompose each class into its Kummer lift and its unramified difference. Both planes are isotropic, and the cross pairing is unramified evaluation paired with inertia. The terms at pp and qq give the left side; the sum over all places is zero. Elsewhere outside SS the classes are unramified, so the local pairing vanishes. This includes ℓ\ell, where the generators have unit valuation. The same calculation shows that b(h,h)b(h,h) is alternating.

Prescribing the matrix entries

We next prove that the off-diagonal entries and the rational Legendre bits can be varied independently. The latter bits will control split diagonals without disturbing the other blocks. The class-field inputs are ray-class reciprocity, the Hilbert product formula, and Chebotarev [53]; see also Milne [48].

Lemma 8.1 (Realization of finite matrix prescriptions). Fix finitely many individually admissible oriented prime templates, including generator neighborhoods at SS, any additional finite places, and oriented Frobenius on E[4]E[4] and fixed quadratic-radical extensions unramified outside that support. At arbitrarily fresh primes these templates admit the following simultaneous prescriptions.

  1. Between distinct vertices, one direction of the double-coset residue bits is free and reciprocity determines the reverse direction. The available matrix blocks are all binary matrices for two split vertices in the S3S_3 case, and JF4J\mathbb{F}_4 in the C3C_3 case, with the rotation algebra identified with F4\mathbb{F}_4. For split–simple vertices the full vector space is available, and for simple–simple vertices the scalar entry is available.

  1. The rational Legendre bit between the absolute primes is independent of the matrix block, subject to rational reciprocity in the reverse direction.

  1. Repeating a template fixes its simple self entry and its split self block modulo a scalar multiple of JJ. A sufficiently primary split template with trivial E[4]E[4]-Frobenius has self block in F2J\mathbb{F}_2J.

Here primary means sufficiently close to 11 at the finite places of SS and totally positive at the real places. New cross-bit prescriptions are made outside the support. All assertions concern finite configurations; an additional moving prime ℓ\ell may be included among the prescribed places.

Proof. Off-diagonal entries. Restriction–corestriction in (52) gives, for distinct vertices,

Bqp(y,x)=∑g∈Hq\G/Hpepq(g)⟨gx,y⟩.B_{qp}(y,x)=\sum_{g\in H_q\backslash G/H_p}e_{pq}(g)\langle gx,y\rangle.

The bit epq(g)e_{pq}(g) is the quadratic residue of gπpg\pi_p at the oriented qq-place in FHq∩gHpg−1F^{H_q\cap gH_pg^{-1}}. Indeed, pair local transfer with the HqH_q-invariant vector yy; the orbit length [Hq:Hq∩gHpg−1][H_q:H_q\cap gH_pg^{-1}] is precisely the residue degree in the norm calculation. In this intermediate field, each of πq\pi_q and gπpg\pi_p has its off-support divisor at a single prime: its oriented Frobenius generates the subgroup fixing the generator. Hilbert reciprocity therefore relates epq(g)e_{pq}(g) to eqp(g−1)e_{qp}(g^{-1}), with correction only at SS.

For a new vertex the independent forward bits are residue conditions at distinct primes of its own field Fp′F'_p. Move an initial template away from the old primes and choose a degree-one prime in the ray class whose quotient generator has the prescribed neighborhoods at SS, real signs, and nonzero residues at those old primes. Multiplying the template generator by this quotient gives the required new generator. These conditions also preserve the admissible fixed Frobenius data: changes by local units at old primes are trivial on the intersection with extensions unramified outside the fixed support. Chebotarev thus imposes the ray and fixed-label conditions simultaneously. Prime ideals of degree greater than one over Q\mathbb{Q} have density zero among prime ideals of Fp′F'_p, so requiring degree one loses no admissible class. The same argument permits additional finite support, including ℓ\ell. Reverse bits are then determined by reciprocity. Rational norm bits at already chosen root primes may be imposed as additional residue conditions in the ray modulus: finite-field norm maps are surjective, and these primes contribute no matrix coordinates.

Matrix span and the norm bit. The norm to Q\mathbb{Q} writes the rational absolute-prime Legendre bit as the sum of the double-coset bits, plus a fixed support-unit correction. For two split vertices the matrices in (8.4) are JgJ_g. They span Mat⁡2(F2)\operatorname{Mat}_2(\mathbb{F}_2) for S3S_3 and JF4J\mathbb{F}_4 for C3C_3. A nontrivial rotation satisfies 1+R+R2=01+R+R^2=0: changing these three bits fixes the matrix and changes their sum. For split–simple vertices, the three nonzero vectors or dual vectors likewise span the full space and have the same odd relation. For two simple vertices, the matching double coset has zero pairing and the other has nonzero pairing. The first bit changes the norm bit alone. This proves (i) and (ii).

Self entries. The nonidentity double cosets in self-transfer are unramified at the oriented prime. The identity term is a scalar times the pairing and is therefore zero on a simple line. At a split vertex the two rotation terms have fixed sum by reciprocity; changing both alters the block only by a scalar multiple of JJ. Every other term has an involution representative τ\tau exchanging the oriented place with another one. For a simple vertex this includes a transposition other than cc representing the nonmatching self double coset.

Work in FτF^\tau and put

α=πpτπp,β=πp+τπp,F=Fτ(Dτ).\alpha=\pi_p\tau\pi_p,\qquad\beta=\pi_p+\tau\pi_p,\qquad F=F^\tau(\sqrt{D_\tau}).

The distinct divisors of πp\pi_p and τπp\tau\pi_p ensure β≠0\beta\ne0. If v0v_0 is the place below the oriented prime, the residue symbol of τπp\tau\pi_p there is (α,β)v0(\alpha,\beta)_{v_0}: α\alpha has valuation one and β\beta is a unit with the required residue. Outside S∪{v0}S\cup\{v_0\}, α\alpha is a unit. When β\beta is a unit, both (α,β)v(\alpha,\beta)_v and (−Dτ,β)v(-D_\tau,\beta)_v vanish. When β\beta has positive valuation, put γ=(πp−τπp)/Dτ∈Fτ\gamma=(\pi_p-\tau\pi_p)/\sqrt{D_\tau}\in F^\tau. The identity

β2−4α=Dτγ2\beta^2-4\alpha=D_\tau\gamma^2

shows that α\alpha has residue squareclass −Dτ-D_\tau; the two symbols are again equal. At v0v_0, (−Dτ,β)v0=0(-D_\tau,\beta)_{v_0}=0. Reciprocity applied to both symbols gives, in additive notation,

(α,β)v0=∑v∈S((α,β)v+(−Dτ,β)v).(\alpha,\beta)_{v_0}=\sum_{v\in S}\bigl((\alpha,\beta)_v+(-D_\tau,\beta)_v\bigr).

At finite support places the right side is locally constant in a sufficiently small neighborhood of the template. At a real place where F/FτF/F^\tau is complex, α\alpha and −Dτ-D_\tau are positive. At a split real place, opposite signs of πp\pi_p and τπp\tau\pi_p make the two terms cancel; equal signs determine their sum. Thus signatures suffice, without archimedean size restrictions. For a primary template, α\alpha is a square at the finite support places and β\beta has the squareclass of 22. The support sum becomes ∑v∈S(−Dτ,2)v=0\sum_{v\in S}(-D_\tau,2)_v=0, since the terms outside SS vanish. The involution terms are therefore zero. Together with the local Kummer lift determined by E[4]E[4], this proves (iii).

Symmetrization and the Selmer bound

The realization lemma supplies the allowable matrix blocks. We now remove their fixed-support reciprocity defect and compare the resulting kernels with actual Selmer classes. The fixed support types, stationary environment and additional local conditions will account for the loss in dimension.

Choose a matrix rule L(h,h′)L(h,h') in the available block spans such that

L(h,h′)+L(h′,h)t=b(h,h′).(55)L(h,h')+L(h',h)^{\mathsf{t}}=b(h,h'). \tag*{(55)}

For distinct types, choose either direction using Equation (54). For equal types, the right side is alternating. It is a matrix plus its transpose in the full span; in the rotation span use R+R−1=1R+R^{-1}=1 after multiplication by JJ. On a simple line it is zero. Choose L=0L=0 when one type is primary and trivial at SS, since then its support pairings vanish. Define, on every pair including the diagonal,

Mqp=Bqp−L(hq,hp).M_{qp}=B_{qp}-L(h_q,h_p).

The matrix MM is symmetric. Lemma 8.1 allows zero cross-MM entries between prescribed blocks independently of their internal entries.

A stationary environment consists of the fixed coordinates outside the variable blocks; its dimension is the number of those coordinates.

Proposition 8.2 (Nullity forces Selmer dimension). Fix the curve, support types, a bound for the number of additional constrained places, and a bound for the dimension of a stationary environment. Partition a finite configuration into blocks with zero cross-MM entries, and denote their matrices by MiM_i. There is a constant depending only on these fixed data such that

dim⁡F2Sel⁡2(E(h)/Q)≥∑idim⁡F2ker⁡Mi−C.(56)\dim_{\mathbb F_2}\operatorname{Sel}_2(E^{(h)}/\mathbb Q) \ge\sum_i \dim_{\mathbb F_2}\ker M_i - C. \tag*{(56)}

At a unit coefficient symbol the sum of nullities, and hence the number of singular blocks, is therefore uniformly bounded. The bound works for both coefficient sources and is independent of the moving prime ℓ\ell.

Proof. On ⨁iker⁡Mi\bigoplus_i \ker M_i, impose

∑p: hp=hxp=0for each type h,(57)\sum_{p:\,h_p=h} x_p=0 \quad\text{for each type } h, \tag*{(57)}

using the fixed orientation and basis to identify coordinates of the same type. These equations have codimension at most ∑hdim⁡Vh\sum_h \dim V_h. They kill the correction in every row, since that correction is

∑hL(hq,h)∑p: hp=hxp.\sum_h L(h_q,h)\sum_{p:\,h_p=h} x_p.

Thus Bx=0Bx=0 at all block positions. Set the environment coordinates to zero and impose its row conditions, losing at most its dimension. The Selmer conditions at SS and the additional constrained places have bounded total codimension in local H1H^1. At every remaining good place the classes satisfy the unramified Kummer condition; at a root prime local cohomology is zero. Their sums are therefore Selmer classes, and independent inertia coordinates make the map injective. This proves (56).

At a unit symbol, Proposition 4.4 bounds the Selmer dimension, giving the remaining assertions. The type constraints use only the fixed SS; a condition at the single moving prime contributes a uniformly bounded local dimension.

Three states on two coordinates

We have obtained two kinds of information from an arithmetic prime configuration: its coefficient symbol and a matrix whose nullity bounds its Selmer dimension from below. To compare configurations, we now vary exactly two coordinates at a time. Both the symbol and the determinant obey one common three-state relation. They remain different functions; the relation gives linearity, not their equality. The bounded number of singular blocks at a unit symbol will be the additional input used in the next section.

A site consists of either one split vertex or an ordered pair of simple vertices, and always supplies two matrix coordinates. At a split site use the three states

absent,  present with diagonal QQ,  present with diagonal Q+JQ+J.

The rational Legendre bit of the aggregate root selects the two present diagonals. At a simple-pair site use absence of both vertices and two present variants differing in their nonmatching cross bit. Replace the second prime by a prime with the same template, self data, norm data, and outside cross bits. Its matching bit with the first prime must also change to keep the rational norm bit fixed; that bit has zero matrix contribution. Thus the two present matrices again differ by the symmetric toggle on their coordinate pair. Require all alternatives to agree against alternatives at other sites. These are finite simultaneous prescriptions allowed by Lemma 8.1.

In comparing states, keep fixed the total parameter label at the fixed support: the product of the labels of the active sites and the aggregate roots. The aggregate-root label itself changes when a site is deleted, absorbing the deleted labels.

Lemma 8.3 (The site relations). Fix the total parameter label at the fixed support and the diagonal choices at the other present sites. In each state choose aggregate roots restoring this label, compatibly with an order-three residual Frobenius, and preserving those diagonals. For either coefficient symbol, its three values at one site sum to zero. The same holds for det⁡M\det M, with empty determinant one. Consequently both functions extend linearly to the tensor product of one copy of F2\mathbb{F}_2 per site, whose three nonzero vectors represent the three states. These factors encode evaluations, not vectors of VV.

Proof. For a split site this is the root-deletion rule of Theorem 5.10. Deletion transfers the removed vertex’s rational labels to the aggregate root. Signed prime discriminants preserve the unit twist, and hence the diagonal, at every remaining prime.

For a simple-pair site, omit the varied second prime from its opposite-parity trace test. In an extension of GG by an elementary kernel, two lifts of its transposition cc are conjugate by the kernel exactly when their difference lies in the image of 1+c1+c. Dually, this means agreement on the cc-fixed radical squareclasses. Besides fixed-support radicals, these are generated by products of the orbit generators gπpg_{\pi_p} over cc-orbits: their off-support divisors are independent and conjugation permutes them. Singleton orbits test matching bits. A two-element orbit has product in FcF^c; its symbol at the varying degree-one prime is, by the residue norm, the symbol of one factor in FF, namely the nonmatching bit.

The variants agree on support radicals and the orbit tests for every other vertex. At the first prime they change both matching and nonmatching bits. Modulo the image of 1+c1+c, their difference is therefore the product of inertia in the matching transposition orientation and inertia in the other orientation. Apply these substitutions successively. The matching-orientation derivative is zero; the different-transposition derivative deletes the pair by Theorem 5.10. Multiplication by inertia leaves the residual transposition unchanged. The intermediate Frobenius test is realized by Chebotarev; it need not be a site variant. The resulting root has rotation image and transfers the pair’s rational labels to the aggregate. Labels elsewhere are unchanged. At simple vertices root probes are immaterial; at split vertices the common rational labels preserve the diagonals. Matched actual probes, or their aggregate, are available because their discriminant character is trivial. This proves the symbol relation.

For the determinant, reverse every permutation cycle of length at least three. The resulting terms cancel in characteristic two, leaving only involutions. Toggling the symmetric entries (i,j),(j,i)(i,j),(j,i) changes exactly the terms containing (ij)(ij), whose sum is the determinant with coordinates i,ji,j deleted. This includes the split JJ-shift. Finally, the three-state relation in each factor is precisely linearity on its three nonzero binary vectors. □

Lemma 8.4 (Binary tensor span). Let W=⨂i=1rWiW=\bigotimes_{i=1}^{r}W_i, where each WiW_i has dimension two over F2\mathbb{F}_2, and let 0≠f∈W∗0\ne f\in W^*. The nonzero pure tensors annihilated by ff span ker⁡f\ker f. Thus if pure tensors e,te,t satisfy f(e)=f(t)=1f(e)=f(t)=1, then tt is ee plus a sum of pure zeros of ff.

Proof. It suffices to show that a functional gg vanishing on the pure zeros of ff is either 00 or ff. Induct on rr, the case r=0r=0 being immediate. Slice at the three nonzero vectors of the last factor, numbering so that f3=f1+f2f_3=f_1+f_2 and g3=g1+g2g_3=g_1+g_2. If fi=0f_i=0, then gi=0g_i=0 because the smaller pure tensors span. Otherwise induction gives gi=ϵifig_i=\epsilon_i f_i for a binary scalar ϵi\epsilon_i. If all three fif_i are nonzero, f1,f2f_1,f_2 are independent, so the sum identities force all ϵi\epsilon_i to agree. If one fif_i vanishes, the other two, and their gig_i, agree. All three cannot vanish. Hence g=0g=0 or g=fg=f. □

Take f=det⁡Mf = \det M and let ee be the all-absent state. Every invertible state is the empty state plus a sum of singular pure states. Moreover, on any selected set of active sites, some choice of pair toggles makes MM invertible: the iterated determinant difference over all selected pairs is the empty determinant, one. These facts turn the Selmer nullity bound into a constraint on symbol evaluations.

Making one address singular

The final construction singles out one nonzero vector of a binary cube. Every position is activated by a linear form, as required for interpolation; auxiliary split sites repair the matrix at all other nonzero vectors.

Lemma 8.5 (A block address program). Let M∗M_\ast be the singular matrix of a finite site state, and let DD be a sum of its pair toggles such that N∗=M∗+DN_\ast= M_\ast+ D is invertible. For b≥2b \ge2 and 0≠x∗∈F2b0 \ne x_\ast\in\mathbb{F}_2^b, one can add finitely many primary split sites, each activated by a linear form, so that:

  • all sites present in the original state have activation l0l_0, with l0(x∗)=1l_0(x_\ast) = 1;

  • no site is active at zero, and at x∗x_\ast precisely the original state M∗M_\ast remains;

  • the matrix is invertible at every other nonzero address;

  • the active auxiliary matrix is always invertible, and its Schur complement contributes DD exactly when the original sites are active and x≠x∗x \ne x_\ast.

All entries use the freedoms of Lemma 8.1.

Proof. Choose a basis y=(y1,…,yb−1)y = (y_1,\ldots,y_{b-1}) for the forms annihilating x∗x_\ast and complete it by l0l_0. Then y=0y = 0 exactly at 0,x∗0,x_\ast. For each required toggle and each nonzero η∈F2b−1\eta\in\mathbb{F}_2^{b-1}, choose a basis of forms all equal to one at η\eta. Such a basis is obtained from a form uu with u(η)=1u(\eta) = 1 by adding uu to a basis of the annihilator of η\eta. Its unique simultaneous all-one solution is η\eta.

Construct a path with r=b−1r = b - 1 steps, using two new split positions at each step, both activated by the corresponding basis form. In scalar block notation, where a scalar denotes that scalar times JJ, put

P=(0TTtBe),T=I+lower consecutive shift.(58)P = \begin{pmatrix} 0 & T \\ T^{\mathsf{t}} & B_e \end{pmatrix}, \qquad T = I + \text{lower consecutive shift}. \tag*{(58)}

The near and far endpoints are steps 11 and rr. The matrix BeB_e has one nonzero diagonal entry at the far endpoint. Restrict both sides to active steps, retaining only the original consecutive edges. The restricted TT is triangular with diagonal one, so PP is invertible, with scalar inverse

P−1=(−T−tBeT−1T−tT−10).P^{-1} = \begin{pmatrix} -T^{-\mathsf{t}} B_e T^{-1} & T^{-\mathsf{t}} \\ T^{-1} & 0 \end{pmatrix}.

Couple the addressed coordinate pair by JJ to the first side at the near endpoint. Such a pairing is available also for two simple lines. Solving Tv=enearTv = e_{\mathrm{near}} propagates one to the far endpoint exactly when every step is active; a missing step interrupts the consecutive shift. The Schur contribution is consequently JJ on a complete path and zero otherwise, including when the near endpoint is absent.

For each nonzero yy, exactly one path, the one indexed by η=y\eta= y, is complete. Their direct sum supplies the toggle when y≠0y \ne0 and supplies zero when y=0y = 0. Repeat for each toggle in DD, with zero mutual cross-MM entries. The actual matrices are the scalar matrices tensored with JJ, so the same inverse calculation gives the asserted binary Schur complements. All blocks lie in the permitted spans, and primary diagonals are 00 or JJ.

At x∗x_\ast the auxiliary sites are absent and l0=1l_0=1, leaving M∗M_\ast. At any other nonzero address with l0=1l_0=1, eliminating the auxiliary sites leaves M∗+D=N∗M_\ast+D=N_\ast. If l0=0l_0=0, only the invertible auxiliary matrix remains. Every activation is linear and vanishes at zero.

The converse when E[2]E[2] is irreducible

The local matrices now supply the families needed for interpolation. We shall arrange that a coefficient symbol is a unit at every nonzero vertex of a binary cube, with all added primes absent at zero. The key observation is that a unit evaluation has only boundedly many singular matrix blocks. A maximal list of such blocks will therefore force all the required unit evaluations. In the odd case, a second construction supplies simultaneous nonvanishing for an auxiliary even symbol.

Theorem 9.1 (The irreducible converse). Let E/QE/\mathbb{Q} be an elliptic curve for which E[2]E[2] is irreducible as a GQG_{\mathbb{Q}}-module. If

c2(E)=corank⁡Z2Sel⁡2∞(E/Q)∈{0,1},c_2(E)=\operatorname{corank}_{\mathbb{Z}_2}\operatorname{Sel}_{2^\infty}(E/\mathbb{Q})\in\{0,1\},

then ord⁡s=1L(E,s)=c2(E)\operatorname{ord}_{s=1}L(E,s)=c_2(E).

The curve is fixed throughout. Every constant may depend on it and on the finite choices specified below, all made before the cube dimension grows. The result applies pointwise to any quadratic twist by taking that twist as the initial curve.

Finite evaluation tables and ordered profiles

A block is a finite set of the three-state sites of Section 8, together with their prescribed matrix entries. A state chooses one of the three alternatives at each site. Its evaluated matrix MsM_s deletes the coordinates of absent sites and applies the toggles of the chosen active alternatives. The empty state has determinant 11. We call a state singular when det⁡Ms=0\det M_s=0.

The matrix and the coefficient symbol give different information about such a state. The raw matrix BB records the active-prime Selmer equations; MM is the symmetric matrix obtained after the fixed-support correction. The symbol still depends on the arithmetic realization, even when those matrix entries have been prescribed. What links them is Proposition 8.2: a symbol value 11 permits only boundedly many singular blocks. We shall first stabilize the remaining arithmetic dependence and then use this bound.

Fix a normalized coefficient symbol AA on the filter of the parameter 11. For the odd source retain its condition at the moving detecting prime ℓ\ell. Consider an actual finite array of blocks, numbered in increasing order, with M=0M=0 between different blocks. For chosen indices i1<⋯<iji_1<\cdots<i_j and states s1,…,sjs_1,\ldots,s_j, write

E(i1,…,ij;s1,…,sj)∈F2\mathcal{E}(i_1,\ldots,i_j;s_1,\ldots,s_j)\in\mathbb{F}_2

for its coefficient-symbol value. Each table entry uses its own aggregate-root probe, which restores the total support label of 11 and gives the chosen diagonals at active split sites. Root substitution makes its value independent of the probe with these data. The calibration below will realize all entries used by a cube with one common set of linearly activated root primes. The total label, rather than the aggregate root’s own label, is fixed: deleting a site transfers that site’s labels to the root. The substitution rules therefore preserve this value when an unused site or an empty block is deleted. In particular, the empty table entry is A(1)A(1).

There are two independent indices in these tables. Inside each block, site slots specify where a state and its addressing paths can be put. The indices i1<⋯<iji_1 < \cdots< i_j specify ordered copies of the whole block. We will use a common countable library of site slots in every copy, closed under the finite addressing constructions of Lemma 8.5. A state in this library uses only finitely many sites, with every other site absent. A word is an ordered finite list of states from this library, with empty states omitted. An ordered profile assigns a value to each such word, consistently with the three-state relations in each block. The next lemma constructs one by stabilizing finite tables: its value depends on the ordered states, but not on which increasing list of block indices carries them. It asserts no invariance under permuting the states.

Lemma 9.2 (A finitely realizable ordered profile). For the fixed symbol AA, there is a countable library of site slots in each block and an ordered profile with the following properties.

(i) Every prescribed finite part is realized by an array of distinct primes with the data of Lemma 8.1. For the odd symbol, it is realized at arbitrarily advanced stages of the prescribed precision stabilization.

(ii) A word evaluation depends on the states and on their order, and not on the particular distinct block indices used to place them. The tensor relations hold separately in all of its blocks.

(iii) The site library contains a transferred minimal-weight unit witness and the primary split sites needed for every finite collection of requests in Lemma 8.5.

(iv) For a constant CC independent of the finite array, a unit evaluation contains at most CC singular blocks.

Couplings to finitely many fixed primes, kept outside the address symbol, may be prescribed in advance. In the even case, all primes may also satisfy a bound on v2(p2−1)v_2(p^2-1) independent of the finite array.

We first derive the consequence of this lemma. Its proof follows the saturation argument and explains how the ordered values retain finite arithmetic realizations, including for the moving odd source.

Lemma 9.3 (Saturation of a punctured cube). For the profile in Lemma 9.2, either the empty word has value 11, or there is a fixed finite word WW of singular blocks with value 11 such that, for every sufficiently large bb, an addressed family has symbol 11 at every nonzero point of F2b\mathbb{F}_2^b and has all sites absent at zero. Every such finite cube is arithmetically realizable.

Proof. In the tensor space of a block, every nonsingular state is the empty state plus a sum of singular states, by Lemma 8.4. Expand the transferred unit witness this way. Some word consisting entirely of singular blocks, possibly the empty word, has value 11.

The lengths of all such words are bounded by Lemma 9.2(iv). Choose one of maximal length mm. If m=0m=0, the empty word has value 11. Otherwise fix one particular maximizing word

W=(W1,…,Wm).W=(W_1,\ldots,W_m).

Each WiW_i uses finitely many slots. These slots, and thus their total number, are fixed before bb grows. A bound on the number of blocks alone would not give this conclusion.

For each a∈F2b∖{0}a\in\mathbb{F}_2^b\setminus\{0\}, place a copy of WW in its original block order. Address its iith block to aa using Lemma 8.5. At aa the state is exactly WiW_i, with every path site absent. At every other nonzero address the evaluated block is nonsingular, and at zero it is empty. All these finitely many programs are available in the recursive slot list. At a nonzero address xx, expand every block outside the copy designated for xx as empty plus singular states. Choosing the empty state in every such block leaves WW in its original order, hence gives 1. Every other term contains its mm singular blocks and at least one additional singular block, so maximality forces its value to be zero. This includes alternatives involving path slots: maximality was taken over the whole slot profile. Multilinearity therefore gives 1 at xx. All evaluations use one finite restriction of the profile, which is realizable by Lemma 9.2.

Proof of Lemma 9.2. The witness and available slots. Begin with the nonroot positions of a minimal-weight unit witness. The minimum-transfer rule in Theorem 5.10 moves them to fresh primes while retaining their fixed-support Frobenius labels. Neither prescribed internal couplings nor couplings to stationary primes change this transfer: the latter primes are outside the coefficient index. The total simple parity is even, so pair its simple positions into sites. Fix admissible generator templates, including support squareclasses and self types, for this pattern.

At each finite stage place a fresh copy of the pattern in every block to be colored. First apply Lemma 5.9 with matched actual root probes. The nonroot support labels are unchanged, so retaining the aggregate root’s support label restores the same total parameter label. Adjust only its bits at active vertices to give the prescribed diagonals. By Proposition 5.8(ii), a split root-bit derivative deletes weight one and vanishes below the minimal weight, while a simple root-bit derivative is zero. Thus every singleton witness still has value 1, even after all internal and cross-block entries have been prescribed. For the odd symbol, make the transfer at the actual coefficient level and retain the witness’s labels at the detecting prime. Thus the witness entry of every singleton color is 1 before taking homogeneous restrictions.

We now enlarge the site library inside each block. For every finite list of earlier site slots and every finite list of addressing requests on it, allocate fresh primary split site slots realizing all those requests. Programs used together receive distinct path slots. Set every undesignated coupling to earlier slots equal to zero in MM. This gives a countable formal list, since there are countably many finite requests. Any finite set of requested slots, together with its finitely many predecessors, is realizable by Lemma 8.1. The two simple-pair variants have identical outside bits and the prescribed internal toggle; the aggregate root supplies the split diagonal alternatives. Corresponding types have the same reciprocity correction LL, so a forward entry B=M+LB = M + L gives the required reverse entry as well. In every alternative impose M=0M = 0 between blocks.

Order-invariant evaluations. Fix the first qq sites of the common library. There are finitely many states on these sites, and their matrix entries have been prescribed. For each j≤qj \le q, color an increasing jj-tuple of block indices by the finite table of values E(i1,…,ij;s1,…,sj)\mathcal{E}(i_1,\ldots,i_j;s_1,\ldots,s_j) on these states. There are finitely many colors. Apply finite Ramsey successively for these finitely many arities. Starting with sufficiently many blocks gives a homogeneous list of any prescribed finite length.

Let the lengths, arities, and slot cutoffs tend to infinity. At each fixed cutoff there are only finitely many possible color vectors. Successive subsequences and a diagonal subsequence make every finite vector constant. These compatible values define the ordered profile. Every finite restriction occurs in an original finite array. The tensor identities, deletion rules, and unit witness survive because each involves only such a restriction.

For the odd symbol, carry out this construction along its fixed nonprincipal ultrafilter of coefficient precisions. The witness has bounded weight, so its fixed-SS generator squareclasses and binary self data have only finitely many possibilities; first stabilize these data. Finer ray-neighborhood depths are realization data and need not stabilize. Impose the extra labels at ℓ\ell at each actual level. For every fixed weight bound, Lemma 4.3 gives an ultrafilter-large set on which all required lower bounds and smaller-weight vanishing assertions hold. Otherwise one could choose a violating index of that bounded weight at each failing level, contradicting the definitions of the least depth or the least witness weight. More explicitly, let GqG_q be an ultrafilter-large set on which the witness, cutoff lower bounds, and minimal-weight vanishing assertions needed for the qqth finite coloring hold. Choose precisions Mq→∞M_q \to\infty in ⋂j≤qGj\bigcap_{j \leq q} G_j, and apply finite Ramsey there. Stabilize the finitely many colors and take the diagonal construction above. The extracted subsequence need not itself be ultrafilter-large: every finite restriction occurs at arbitrarily high precisions, which is the required conclusion. We assert no single level valid at all weight bounds, and choose no infinite array of primes.

The bound on singular blocks. Proposition 8.2 and the uniform unit-symbol bound in Proposition 4.4 bound the sum of the block nullities. Each singular block contributes at least one. The type alphabet and its correction cost depend on the fixed support SS. The moving place ℓ\ell and any bounded stationary environment contribute only the bounded additional local cost allowed in Proposition 8.2; they do not enlarge that alphabet as the array grows. This proves (iv) in every finite realization, and therefore in the profile.

For the final even-symbol assertion, choose fixed templates at sufficient 2-adic precision for the witness and its simple variants, and a fixed sufficiently primary template for the path sites. Refine each rational residue class to a finite precision determining a finite value of v2(p2−1)v_2(p^2 - 1). Only finitely many templates occur. Cross-bit conditions at new odd primes do not change these residues. The same argument will apply to the root primes used below.

Local calibration and the even case

The preceding argument determines the symbol values. We next realize all its local twist classes simultaneously, while keeping each prime’s activation linear in the cube coordinates.

Lemma 9.4 (Calibration by root primes). The cubes in Lemma 9.3 admit realizations by signed squarefree parameters

hx=∏p(p∗)fp(x),x∈F2b,h0=1,h_x = \prod_p (p^*)^{f_p(x)}, \qquad x \in\mathbb{F}_2^b,\qquad h_0 = 1,

where each fp:F2b→F2f_p : \mathbb{F}_2^b \to\mathbb{F}_2 is linear. The prescribed local classes and diagonal choices hold at every assignment. Moreover, hxh_x may be required to be a local square at any prescribed finite set of stationary primes. Calibration adds only root primes, whose invariant dimension tpt_p is zero. In the even case, all added primes may satisfy a bound on v2(p2−1)v_2(p^2 - 1) independent of $b.

Proof. The address and path programs already give a linear activation form for each nonroot prime. Both primes of a simple site have the same form, so their total simple parity vanishes coefficient by coefficient. For each coordinate xjx_j, add a fresh root prime qjq_j, active when xj=1x_j = 1. Choose its rational radical label at the support to cancel the coefficient of xjx_j in the total nonroot label. The paired-simple condition makes the residual discriminant obstruction to a rotation label zero. Lemma 8.1 and root substitution in Theorem 5.10 therefore allow these choices.

The same roots supply the diagonal choices. At a nonroot split prime pp, the unit twist from the other nonroot primes is a linear function of xx. A desired constant diagonal bit on the active set of pp is represented by that constant times fpf_p. The correction needed is therefore linear, say ∑jcpjxj\sum_j c_{pj}x_j. Give qjq_j the Legendre bit cpjc_{pj} at pp. These bits are independently prescribable for the different pp; simple positions need no diagonal correction. At each stationary prime, choose the root bits to cancel the existing unit twist coefficient by coefficient. To check compatibility, let LL be the compositum of the rational quadratic fields recording these finite tests. The fresh-prime radical classes are independent of the support classes by their valuations. Moreover, F∩L=QF \cap L = \mathbb{Q} for G=C3G = C_3; for G=S3G = S_3 it is at most the residual discriminant field. Thus agreement on the already matched discriminant coordinate is the only additional condition for a rotation in Gal⁡(F/Q)\operatorname{Gal}(F/\mathbb{Q}). Chebotarev supplies the required roots.

Using signed prime discriminants gives the prescribed quadratic characters at every place, including infinity and 2. At each xx, the nonroot states and their internal data are those of its table entry. The product of the active root primes has the support label and the bits at active split primes of the aggregate-root probe in the corresponding table entry. Its bits at simple primes do not change the symbol. Root substitution in Theorem 5.10 therefore identifies A(∣hx∣)A(\lvert h_x\rvert) with that profile value. The same comparison includes x=0x = 0, where the root collection is empty and all added primes are absent. Finally, root support labels lie in a fixed finite set, so fixed rational 2-adic residue refinements determine v2(qj2−1)v_2(q_j^2-1). The extra conditions, ramified at fresh odd primes, are compatible with these refinements as in Lemma 9.2.

Proof of Theorem 9.1 when c2(E)=0c_2(E) = 0. By Lemma 2.2, the functional equation has sign +1+1. We use the even coefficient source on the filter of 1. To obtain its lower bound, choose an auxiliary twist of analytic rank one, with opposite infinity sign and matching local classes at 2N2N, by nonvanishing in these fixed local classes (Proposition 3.8). Exclude its prime support and the exceptional quadratic fields as in Proposition 4.1. The reverse genus comparison and Theorem 3.6 give the lower bound required there. Fix this partner, the exclusions, and the normalized even symbol before choosing the profile or cube dimension.

If the empty word is a unit, Proposition 4.4 gives L(E,1)≠0L(E,1) \ne0. Otherwise Lemmas 9.3 and 9.4 give arbitrarily large cubes with unit symbol at all x≠0x \ne0. At each such point,

L(Ehx,1)≠0,v(L(hx))−2w(hx)−s(hx)≤CA,L(E^{h_x},1) \ne0,\qquad v(L(h_x))-2w(h_x)-s(h_x)\le C_A,

where CAC_A depends only on the fixed normalized symbol. The local classes are fixed and the added-prime valuations v2(p2−1)v_2(p^2-1) are bounded independently of bb. These are precisely the remaining hypotheses of Theorem 3.1, which yields L(E,1)≠0L(E,1) \ne0.

A bounded companion for the odd cube

Assume c2(E)=1c_2(E) = 1. Parity gives functional sign −1-1, so the address symbol AA is odd and its filter is the filter of 1. Choose its fixed genus partner of analytic rank zero, with opposite infinity sign and matching classes at 2N2N, by Proposition 3.8. The irreducible genus bound supplies the coefficient lower estimate. Choose also an even symbol A0A_0 on a fixed filter of negative odd fundamental discriminants kk for which 2N2N splits in Q(k)\mathbb{Q}(\sqrt{k}). It has no condition at the moving prime ℓ\ell. Its complementary genus partner has analytic rank one and is chosen by the same nonvanishing proposition. Fix these partners, all excluded prime supports and exceptional fields, and both coefficient normalizations.

If A(1)=1A(1) = 1, unit-symbol detection already gives the desired analytic rank. Otherwise the following construction supplies every arithmetic hypothesis needed for varying-field Heegner interpolation.

Proposition 9.5 (An odd cube with a bounded even companion). For the fixed symbols AA, A0A_0 just chosen, suppose A(1)=0A(1)=0. There is a constant CC such that, for every sufficiently large bb, one can find an odd negative fundamental discriminant kk and a finite family

hx=∏p(p∗)fp(x),x∈F2b,fp:F2b⟶F2 linear,h_x=\prod_p (p^*)^{f_p(x)},\qquad x\in\mathbb{F}_2^b,\qquad f_p:\mathbb{F}_2^b\longrightarrow\mathbb{F}_2\ \text{linear},

with the following properties.

(i) The primes are distinct good odd primes outside the fixed exclusions; h0=1h_0=1, and every hxh_x has the local squareclasses of $1 at the fixed support and at infinity. Each hxh_x is coprime to kk. The field K=Q(k)K=\mathbb{Q}(\sqrt{k}) satisfies the standing Heegner conditions.

(ii) The prime support of kk has cardinality at most CC. At every nonroot prime p∣∏xhxp\mid\prod_x h_x, the parameter kk is a local square. At every nonroot prime q∣kq\mid k, every hxh_x is a local square.

(iii) The simultaneous symbol values are

A0(∣k∣)=1,A(∣hx∣)=A0(∣khx∣)=1(x≠0).A_0(\lvert k\rvert)=1,\qquad A(\lvert h_x\rvert)=A_0(\lvert kh_x\rvert)=1\quad(x\ne0).

Consequently E(k)E^{(k)} has analytic rank zero and s(k)≤Cs(k)\le C.

For the odd source, these assertions mean simultaneous actual tests at arbitrarily high admissible precisions after bb and its finite set of tests have been fixed. The constant CC is independent of bb, that precision, and all moving primes. The parameter kk may vary with the finite realization.

The construction uses the even symbol twice: at kk to control the base Selmer group over KK, and at khxkh_x to make the product have a simple zero at every nonzero vertex. We first condition A0A_0 by a fixed singular prefix. Only after this conditioning will its later values become determinants.

Lemma 9.6 (A determinant-conditioned prefix). For the fixed even symbol A0A_0, there are a finite list aa of singular blocks and an environment consisting of at most one simple vertex with the following property. Fix these vertices and their split diagonal entries. Let zz be any further block of tensor sites whose alternatives all have B=LB=L to every block of aa. Choose aggregate root data preserving the prefix diagonals and the fixed total label. Then

A0(a,z)=det⁡Mz.A_0(a,z)=\det M_z.

The left side includes the fixed environment. Its couplings need only be compatible with the tensor alternatives.

Proof. If the filter of A0A_0 has odd simple parity, retain one simple vertex of a unit witness as the environment; otherwise take the environment empty. The remaining simple positions have even parity, so pair them into sites and put all variable positions of the witness in one block. Allow aggregate roots with the prescribed total class throughout.

Consider all actual finite configurations with this environment and a list of singular blocks, with B=LB=L between blocks, at which A0=1A_0=1. This collection, allowing an empty list, is nonempty. Indeed, if the witness block is nonsingular, expand it as empty plus singular states by Lemma 8.4; some resulting term has value 1. Proposition 8.2 bounds the lengths of these lists, since the environment has fixed dimension cost. Choose an actual maximizing list aa and fix all its primes, singular matrices, and diagonal choices. Only this one finite list is retained; no bound on the sizes of arbitrary maximizing blocks is asserted.

For a proposed further block, fixing the prefix and environment gives a multilinear symbol functional ff. It vanishes on every singular pure state zz, for otherwise appending zz contradicts maximality. Also f(∅)=1f(\varnothing)=1, because its aggregate root preserves the total label and the prefix diagonal data of the maximizing evaluation. Singular pure states span the kernel of the determinant functional by Lemma 8.4, and the empty state has determinant 1. Hence f=det⁡f=\det, proving (9.1). Maximality here is over actual singular states. It requires no alternative choice for any fixed prefix prime against a later prime.

The number of surviving copies

Fix a nonempty maximal singular unit word W=(W1,…,Wm)W=(W_1,\ldots,W_m) in an odd profile, as in Lemma 9.3. Write

M=⨁i=1mMi,D=⨁i=1mDi,N=M+D.M=\bigoplus_{i=1}^{m}M_i,\qquad D=\bigoplus_{i=1}^{m}D_i,\qquad N=M+D.

where DiD_i is a sum of site toggles making Mi+DiM_i+D_i invertible. The matrix NN is invertible and DD is alternating. Their common coordinate space UU has even dimension, fixed with the word.

Lemma 9.7 (Address copies with even total activation). For every b≥2b\ge2, the address construction for WW may be chosen so that its symbol is 1 at every nonzero xx and all sites are absent at zero. At a nonzero xx, eliminating its invertible path sites leaves the designated copy of MM and an odd number of copies of NN. The different copies have zero mutual MM-entries.

Proof. For every a≠0a\ne0 choose a linear form lal_a with

la(a)=1,∑a≠0la=0(59)l_a(a)=1,\qquad\sum_{a\ne0}l_a=0 \tag*{(59)}

To obtain these forms, begin with arbitrary choices satisfying the first condition. Allowed changes at a form its annihilator. The annihilators of two distinct nonzero addresses are distinct hyperplanes and span the entire dual space. Changes at those two addresses can therefore cancel the initial sum.

Activate all word sites in the copy designated for aa by lal_a, and use a basis of the annihilator of aa for its path coordinates in Lemma 8.5. The saturation proof is unchanged. At a nonzero xx, the designated copy leaves MM. Each other active copy leaves NN, and a copy with la(x)=0l_a(x)=0 leaves only invertible paths. Equation (59) says that the total number of active copies is even. The designated copy is active, so an odd number of other copies remain.

A bounded interface

We will couple every surviving copy to the same fixed collection of split sites. When two NN-copies are eliminated, their contributions to that collection cancel in characteristic two. Thus the calculation reduces to one MM-copy, one NN-copy, and the fixed collection. The following lemma chooses its couplings; its dimension depends on WW and not on the number of addresses.

Lemma 9.8 (Alternating interface repair). *Let UU be an even-dimensional vector space over F2\mathbb{F}_2, let NN be symmetric and invertible on UU, and let DD be alternating. There are at most dim⁡U\dim U linear maps bi:U→F22b_i: U \to\mathbb{F}_2^2 such that, on writing J=(0110)J=\begin{pmatrix}0&1\\1&0\end{pmatrix} and H=∑ibitJbiH=\sum_i b_i^tJb_i, the matrix

S(H)=(DNNN+H)S(H)=\begin{pmatrix}D&N\\N&N+H\end{pmatrix}

is invertible. If UU has the rotation-field structure F4d\mathbb{F}_4^d occurring in the cyclic cubic case, the maps may be chosen F4\mathbb{F}_4-linear from UU to the field line F4=F22\mathbb{F}_4=\mathbb{F}_2^2.

Proof. Start with H=0H=0, and write π2:U⊕U→U\pi_2: U\oplus U\to U for projection to the second coordinate. For every HH, this projection is injective on ker⁡S(H)\ker S(H): if (u,0)(u,0) belongs to the kernel, then Nu=0Nu=0, so u=0u=0. The update H↦H+btJbH\mapsto H+b^tJb adds the alternating form (bπ2)tJ(bπ2)(b\pi_2)^tJ(b\pi_2) to S=S(H)S=S(H). We show how to choose an update reducing every nonzero kernel.

If dim⁡ker⁡S≥2\dim\ker S\ge2, choose bb of rank 2 on π2(ker⁡S)\pi_2(\ker S). Take a complement of ker⁡S\ker S and modify its basis vectors by kernel vectors so that bπ2b\pi_2 vanishes on the new complement. The restriction of SS to that complement remains nondegenerate. The update is zero there and in its cross pairings, and has rank 2 on ker⁡S\ker S. Hence it decreases the nullity by exactly 2.

Suppose instead that ker⁡S=⟨k⟩\ker S=\langle k\rangle is one-dimensional. Let dSd_S denote the diagonal vector. Since ztSz=dStzz^tSz=d_S^tz for every binary symmetric matrix, dSd_S annihilates the kernel and lies in the image of SS. Choose ss with Ss=dSSs=d_S. We shall use

dSts=rank⁡S(mod2).(60)d_S^ts=\operatorname{rank}S\pmod2. \tag*{(60)}

To prove it, restrict to a nondegenerate complement of the radical, with invertible symmetric matrix AA and diagonal vector dAd_A. The left side is dAtA−1dAd_A^tA^{-1}d_A. Off-diagonal terms cancel in pairs, leaving ∑i(A−1)iiAii\sum_i(A^{-1})_{ii}A_{ii}. Applying the same cancellation to tr⁡(A−1A)\operatorname{tr}(A^{-1}A) identifies this with dim⁡A\dim A modulo 2, proving Equation (60).

Since the ambient dimension is even and the kernel has dimension one, dSts=1d_S^ts=1. The alternating matrices DD and HH have zero diagonal, so dSd_S is supported on the second coordinates. Consequently π2(s)\pi_2(s) and π2(k)\pi_2(k) are binary-independent: otherwise the former would be zero or equal to the latter, forcing dSts=0d_S^ts=0. Choose bb sending them to independent vectors of F22\mathbb{F}_2^2.

Let zz belong to the kernel after this update. Self-pairing gives dStz=0d_S^tz=0. Pairing the updated equation with kk gives

(bπ2(k))tJ(bπ2(z))=0.(b\pi_2(k))^tJ(b\pi_2(z))=0.

Pairing with ss gives the same equation with ss in place of kk, since stSz=dStz=0s^tSz=d_S^tz=0. Their independent images force bπ2(z)=0b\pi_2(z)=0. The updated equation then reduces to Sz=0Sz=0, so zz is a multiple of kk. As bπ2(k)≠0b\pi_2(k)\ne0, this multiple is zero. The update has made SS invertible.

Both choices of bb remain possible under the field-linear restriction. Two binary-independent vectors u,v∈F4du,v\in\mathbb{F}_4^d are either field-independent, in which case a field-linear map can send them to any binary basis of F4\mathbb{F}_4, or satisfy v=αuv=\alpha u with α∈F4∖F2\alpha\in\mathbb{F}_4\setminus\mathbb{F}_2. In the latter case any field-linear map nonzero on uu gives binary-independent images. These maps are allowed by the rotation-field or diagonal spans, and the preceding argument applies to the underlying binary forms.

Finally, injectivity of π2\pi_2 bounds every kernel dimension by dim⁡U\dim U. Each update strictly decreases it, so at most dim⁡U\dim U maps are required.

Proof of Proposition 9.5. Choose the prefix and possible one-coordinate environment from Lemma 9.6 and fix all their primes. Build the odd address profile disjoint from them, with B=LB=L to every prefix block. The alternatives at a simple pair have identical compatible outside bits against the environment. Include these stationary primes among the local-square conditions in Lemma 9.4.

Since A(1)=0A(1)=0, Lemma 9.3 supplies a nonempty maximal singular unit word WW. Fix it once. It determines UU, MM, DD, NN before bb is chosen.

Choose the maps of Lemma 9.8 for this fixed pair (N,D)(N,D). Let JintJ_{\mathrm{int}} be the direct sum of one standard JJ-block for each map, and let GG be the matrix obtained by stacking the maps JbiJb_i. Then

GtJint−1G=∑ibitJbi=H.G^{t}J_{\mathrm{int}}^{-1}G=\sum_i b_i^{t}Jb_i=H.

For a given bb, use Lemma 9.7 to obtain the address programs and then calibrate their support labels and diagonals by root primes.

Lemma 8.1 realizes these couplings by a fixed number of primary split interface positions, with the field-linear restriction when required.

Only now, for each actual finite address array, construct the auxiliary parameter kk. Its support consists of the stationary prefix, its possible environment, fresh primes for the fixed number of interface positions, and one fresh root prime. Prescribe B=LB=L between the interface and the prefix blocks. In the matrix MM of the further block, couple the interface by zero to the path sites and by the same matrix GG to the word coordinates of every address copy. Keep all other bits of the simple variants identical.

Require hxh_x to be a local square at every interface prime for every xx. This is compatible with the matrix entries: the rational norm bits against address primes are independently prescribable, so their coefficients against the activation forms can be made zero. Include the already chosen address root primes in these conditions; they need only rational norm bits. Treat them as additional residue places in Lemma 8.1. The independent matrix and norm prescriptions concern the nonroot primes, and the further norm conditions occur at disjoint root primes. Their quadratic radicals, ramified at those fresh primes, create no relation with the preceding extensions, which are unramified there. Root calibration has already made hxh_x a local square at the prefix and environment primes.

Choose the last root prime of kk to satisfy four requirements: restore the fixed total support class; make kk negative and split at 2N2N; make kk a local square at every nonroot address prime; and give the prescribed diagonals at the prefix and interface. These are simultaneous finite rational radical conditions. Their residual discriminant coordinate is compatible with a rotation, because the environment accounts for any odd simple parity of the filter and the remaining variable simple positions are paired. The arithmetic realization lemma therefore supplies the prime. All new primes can be taken fresh, so kk is squarefree, coprime to every hxh_x, and avoids the excluded fields. Address root primes need no splitting condition, since their invariant dimension is zero.

These choices preserve all matrices needed for the two symbols. At every actual assignment, the address matrices for A0A_0 equal those for AA, since the extra twist by kk is a local unit square at every nonroot address prime. The prefix and interface matrices also stay fixed as xx varies. In the tensor evaluations used in Equation (9.1), aggregate roots preserve these same diagonal choices.

At zero, the further block is just the interface and has invertible matrix JintJ_{\mathrm{int}}. Equation (9.1) therefore gives

A0(∣k∣)=1.A_0(|k|)=1.

At a nonzero address, eliminate the invertible paths. There remains one copy of MM and an odd number of copies of NN, each coupled to the interface by GG. Eliminate the NN-copies in pairs: each pair has invertible matrix N⊕NN\oplus N and contributes $GN^{-1}G^{t}+GN^{-1}G^{t}=0 to the interface. Retain the one unpaired copy. Eliminating the interface then reduces invertibility of the further block to invertibility of

(M+HHHN+H).\begin{pmatrix} M+H & H \\ H & N+H \end{pmatrix}.

The substitution (u,v)=(u′,u′+v′)(u,v)=(u',u'+v') transforms this matrix by congruence to

(M+NNNN+H)=S(H),\begin{pmatrix} M+N & N \\ N & N+H \end{pmatrix}=S(H),

which is invertible by Lemma 9.8. A second application of (9.1) yields

A0(∣khx∣)=1for every x≠0.(61)A_0(\lvert kh_x\rvert)=1\quad\text{for every }x\ne0. \tag*{(61)}

The odd symbol is also 1 by saturation. The support of kk consists of the fixed prefix and environment, at most dim⁡U\dim U interface primes, and one root prime. Its cardinality is bounded independently of bb. The symbol A0(∣k∣)=1A_0(\lvert k\rvert)=1 gives analytic rank zero and a uniform bound for s(k)s(k) by Proposition 4.4.

For each fixed finite profile restriction, first fix its weight bound and the finite list of symbol and operator comparisons. Choose a sufficiently high actual odd-source level, and realize the address array there as above. Keeping all these address primes fixed, place the required Galois data in a common finite quotient and choose only the fresh interface primes and final root prime of kk to meet the remaining matrix and norm prescriptions. All the unit-symbol tests then hold at once. All constants were fixed with the symbols, prefix and word. This proves the proposition.

Completion of the odd case

Completion of the proof of Theorem 9.1. Apply Proposition 9.5. It gives ω(k)\omega(k) and s(k)s(k) bounded independently of bb, with E(k)E^{(k)} of analytic rank zero. For K=Q(k)K=\mathbb{Q}(\sqrt{k}), Lemma 3.4 gives

corank⁡Z2Sel⁡2∞(E/K)=1\operatorname{corank}_{\mathbb{Z}_2}\operatorname{Sel}_{2^\infty}(E/K)=1

and bounds the length of its finite quotient by the divisible part uniformly in kk. Its hypotheses hold because EE is the fixed corank-one curve, the other twist has rank zero with bounded s(k)s(k), and ω(k)\omega(k) is bounded. This step does not assume finiteness of the Tate–Shafarevich group of EE.

For x≠0x\ne0, the two unit symbols give analytic rank one for E(hx)E^{(h_x)} and analytic rank zero for E(khx)E^{(kh_x)}. Their coefficient comparisons also give uniform bounds

j(P1(h∗))≤w(hx)+C1,v(L(khx))≤2w(khx)+C2.j(P_1(h_*))\le w(h_x)+C_1,\qquad v(L(kh_x))\le2w(kh_x)+C_2.

Here h∗h_* is the fixed genus partner of the odd symbol. The genus point P1(h∗)P_1(h_*) is formed over Q(hxh∗)\mathbb{Q}(\sqrt{h_xh_*}), so the point varies with xx while h∗h_* remains fixed. Coprimality gives w(khx)=w(k)+w(hx)w(kh_x)=w(k)+w(h_x). Proposition 3.2 first yields 2j(P∣hx∣(hx))≤4w(hx)+2w(k)+O(1)2j(P_{\lvert h_x\rvert}(h_x))\le4w(h_x)+2w(k)+O(1). Since w(k)≤ω(k)w(k)\le\omega(k) is uniformly bounded, this becomes

2j(P∣hx∣(hx))≤4w(hx)+C3.(62)2j(P_{\lvert h_x\rvert}(h_x))\le4w(h_x)+C_3. \tag*{(62)}

Subtracting the nonnegative finite lengths s(hx)+s(khx)s(h_x)+s(kh_x) gives the uniform upper bound in Theorem 3.3.

We have also imposed every other hypothesis of that theorem: KK is imaginary and split at 2N2N; each hxh_x is coprime to kk; h0=1h_0=1; signed prime discriminants are activated by linear forms; the local classes at 2N2N are fixed; and each added prime either splits in KK or is a root prime with tp=0t_p=0. For each fixed finite cube, take a sufficiently high precision from its realization set so that all its unit-symbol tests hold at once. The constants depend only on the already fixed normalized symbols, prefix, and word, not on bb.

The varying-field uniformity in Theorem 3.3 therefore applies to these cubes of arbitrarily large dimension. It gives a simple zero at 11 for L(E,s)L(E(k),s)L(E,s)L(E^{(k)},s). The second factor is nonzero by (9.5), so L(E,s)L(E,s) has a simple zero. This proves the remaining case c2(E)=1c_2(E)=1.

Proof of auxiliary nonvanishing

We prove Proposition 3.8. The even-sign assertion follows from [33] after one preliminary twist. For the odd-sign assertion we retain the prescribed local conditions throughout a derivative first-moment calculation.

Proof of Proposition 3.8(i). An odd fundamental discriminant is squarefree and congruent to 11 modulo 44, so c2c_2 is represented by u2∈{1,5}u_2 \in\{1,5\} modulo 88. For odd p∈Sp \in S, choose a nonzero residue upu_p representing cpc_p. The Chinese remainder theorem and Dirichlet’s theorem give a prime q∉S∪Bq \notin S \cup B satisfying

q≡σu2(mod8),σq≡up(modp)(p∈S, p≠2).q \equiv\sigma u_2 \pmod8,\qquad\sigma q \equiv u_p \pmod p\quad(p \in S,\ p \ne2).

Then D0=σqD_0=\sigma q is an odd fundamental discriminant in the prescribed filter. Put A=E(D0)A=E^{(D_0)} and let NAN_A be its conductor. Thus ϵ(A)=1\epsilon(A)=1.

The theorem of Hoffstein–Luo [33] gives infinitely many odd fundamental discriminants hh such that

L(A(h),1)≠0,ω(∣h∣)≤4,L(A^{(h)},1)\ne0,\qquad\omega(|h|)\le4,

and χh(p)=1\chi_h(p)=1 at every prime in the fixed finite set consisting of S∪B∪{q}S \cup B \cup\{q\} and the prime divisors of NAN_A. The twisting formula for the root number gives

1=ϵ(A(h))=ϵ(A)χh(−NA)=sign⁡(h),1=\epsilon(A^{(h)})=\epsilon(A)\chi_h(-N_A)=\operatorname{sign}(h),

so h>0h>0. For odd pp the condition χh(p)=1\chi_h(p)=1 says that hh is a unit square in Qp\mathbb{Q}_p. At 22, odd fundamentality and χh(2)=1\chi_h(2)=1 give h≡1(mod8)h\equiv1\pmod8, which has the same meaning. Since q∤hq\nmid h, the product D=D0hD=D_0h is squarefree and congruent to 11 modulo 44. It retains the prescribed sign and squareclasses and avoids BB. Finally,

E(D)≃A(h),ω(∣D∣)=1+ω(h)≤5.E^{(D)}\simeq A^{(h)},\qquad\omega(|D|)=1+\omega(h)\le5.

Distinct choices of hh give distinct DD.

An odd-sign witness in a fixed progression

We retain the modulus of the local conditions throughout the first-moment calculation. Iwaniec’s derivative moment [35], Theorem on p. 367 and Sections 6–10, treats the negative-discriminant split family. The following argument allows any fixed admissible progression. It makes no uniformity assertion as that progression varies.

Lemma 10.1 (Odd first moment). Let ff be the weight-two newform of an elliptic curve of conductor NN, with its LL-function normalized to have center 1/21/2. Fix HH divisible by 8 and NN, a reduced class aa (mod HH), and σ∈{1,−1}\sigma\in\{1,-1\} with σa≡1\sigma a \equiv1 (mod 4). Suppose the twists with n>0n>0 squarefree and n≡an\equiv a (mod HH) have root number −1-1. For every nonnegative, nonzero Φ∈Cc∞((1,2))\Phi\in C^\infty_c((1,2)), there are c>0c>0, c1∈Rc_1\in\mathbb{R}, and an absolute η>0\eta>0 such that

∑n>0 squarefreen≡a (H)L′(1/2,f⊗χσn)Φ(n/X)=cXlog⁡X+c1X+Of,H,a,σ,Φ(X1−η).\sum_{\substack{n>0\ \mathrm{squarefree}\\ n\equiv a\ (H)}} L'(1/2,f\otimes\chi_{\sigma n})\Phi(n/X)=cX\log X+c_1X+O_{f,H,a,\sigma,\Phi}(X^{1-\eta}).

Consequently this progression contains arbitrarily large nn whose twists have a simple central zero.

Proof. Write L(s,f)=∑m≥1λ(m)m−sL(s,f)=\sum_{m\geq1}\lambda(m)m^{-s}, so ∣λ(m)∣≤τ(m)|\lambda(m)|\leq\tau(m), where τ\tau is the divisor function, and put Q=N/(2π)Q=\sqrt{N}/(2\pi). In estimates below, constants may depend on the fixed data in the Lemma; all unspecified power exponents are absolute. The proof separates two issues: preserving the fixed progression while removing the squarefree condition, and controlling the frequencies after Poisson summation. The zero frequency will give a positive main term of order Xlog⁡XX\log X; the other frequencies and the discarded square divisors must together have a power-saving bound. We keep the modulus HH fixed throughout these steps. Set

V(y)=12πi∫(2)ez2Γ(1+z)y−zdzz2.V(y)=\frac{1}{2\pi i}\int_{(2)}e^{z^2}\Gamma(1+z)y^{-z}\frac{dz}{z^2}.

The conductor of the twist is Nn2Nn^2. Its odd functional equation gives

L′(1/2,f⊗χσn)=2∑m≥1λ(m)χσn(m)mV(mQn).(63)L'(1/2,f\otimes\chi_{\sigma n})=2\sum_{m\geq1}\frac{\lambda(m)\chi_{\sigma n}(m)}{\sqrt{m}}V\left(\frac{m}{Qn}\right). \tag*{(63)}

Indeed, shift the defining completed integral across its double pole and use the functional equation. The central value is zero, so the derivative of the completion contributes no additional term. Use the right side of Equation (63) to define A(n)A(n) also for nonsquarefree n≡an\equiv a (mod HH).

Large square divisors. We first record the precise large-sieve input. For every ρ>0\rho>0 and fixed 0<δ<1/40<\delta<1/4,

∑0<t≤Z squarefreeσt fundamental, (t,2N)=1∣L(1/2+δ+iv,f⊗χσt)∣2≪f,ρ,δZ1+ρ(1+∣v∣)Cρ,δ.(64)\sum_{\substack{0<t\leq Z\ \mathrm{squarefree}\\ \sigma t\ \mathrm{fundamental},\ (t,2N)=1}}\left|L(1/2+\delta+iv,f\otimes\chi_{\sigma t})\right|^2\ll_{f,\rho,\delta} Z^{1+\rho}(1+|v|)^{C_{\rho,\delta}}. \tag*{(64)}

To justify this consequence of the quadratic large sieve, its form in [32], Theorem 1 is

∑t≤Z odd,squarefree∣∑u≤U odd,squarefreebu(tu)∣2≪ϵ(ZU)ϵ(Z+U)∑u∣bu∣2.\sum_{\substack{t\leq Z\ \mathrm{odd,squarefree}}}\left|\sum_{\substack{u\leq U\ \mathrm{odd,squarefree}}}b_u\left(\frac{t}{u}\right)\right|^2\ll_\epsilon(ZU)^\epsilon(Z+U)\sum_u|b_u|^2.

Quadratic reciprocity permits either orientation of the symbol after separating classes modulo 4. In a Dirichlet polynomial with coefficients λ(m)m−1/2\lambda(m)m^{-1/2}, write m=ur2m=ur^2, uu squarefree. For each rr, χσt(r2)\chi_{\sigma t}(r^2) restricts tt to (t,r)=1(t,r)=1; discard that restriction only after taking absolute squares. Since ∣λ(ur2)∣≤τ(u)τ(r2)|\lambda(ur^2)|\leq\tau(u)\tau(r^2), Minkowski’s inequality bounds the square root of the moment by

(ZU)O(ϵ)∑r≤UZ+U/r2r≪(ZU)O(ϵ)(Z+U).(65)(ZU)^{O(\epsilon)}\sum_{r\leq\sqrt{U}}\frac{\sqrt{Z+U/r^2}}{r}\ll(ZU)^{O(\epsilon)}(\sqrt{Z}+\sqrt{U}). \tag*{(65)}

The powers of primes dividing 2N2N contribute convergent geometric sums. On a dyadic interval t≍Tt \asymp T, the approximate functional equation has length U≪fT(1+∣v∣)CU \ll_f T(1+|v|)^C, apart from rapidly decreasing tails. The main sum’s additional factor m−δm^{-\delta} improves partial summation. The dual sum loses at most UδU^\delta in coefficients, but its functional-equation multiplier contributes T−2δT^{-2\delta}, up to a fixed power of 1+∣v∣1+|v|. Thus it incurs no positive power of TT. Mellin inversion separates the smooth conductor weights; the gamma factors give integrable decay in the Mellin variables. Applying Equation (65) with sufficiently small ϵ\epsilon, and summing dyadic intervals, proves Equation (64).

Expand μ2(n)=∑d2∣nμ(d)\mu^2(n)=\sum_{d^2\mid n}\mu(d) and retain d≤Yd\le Y, where 1≤Y≤X1\le Y\le\sqrt{X}. The omitted contribution is

Oρ(X1+ρ/Y).O_\rho(X^{1+\rho}/Y).

Here are the details for the nonsquarefree terms. Write n=tv2n=tv^2 with tt squarefree. An omitted term has v>Yv>Y, with at most τ(v)\tau(v) choices of dd. Also σt\sigma t is fundamental, (tv,2N)=1(tv,2N)=1, and

χσn(m)=χσt(m)1(m,v)=1.\chi_{\sigma n}(m)=\chi_{\sigma t}(m)\mathbf{1}_{(m,v)=1}.

On a Mellin line ℜz=δ>0\Re z=\delta>0, the series defining A(tv2)A(tv^2) therefore uses

L(1/2+z,f⊗χσt)∏p∣v(1−λ(p)χσt(p)p1/2+z+χσt(p)2p1+2z).L(1/2+z,f\otimes\chi_{\sigma t})\prod_{p\mid v}\left(1-\frac{\lambda(p)\chi_{\sigma t}(p)}{p^{1/2+z}}+\frac{\chi_{\sigma t}(p)^2}{p^{1+2z}}\right).

The product is Oϵ(vϵ)O_\epsilon(v^\epsilon). By Cauchy’s inequality and Equation (64), the sum of the absolute LL-values over t≤2X/v2t\le2X/v^2 is O((X/v2)1+ϵ(1+∣ℑz∣)C)O((X/v^2)^{1+\epsilon}(1+|\Im z|)^C). The remaining Mellin factors are bounded by O(Xδ)O(X^\delta) times a rapidly decreasing function of ℑz\Im z. Choose δ\delta and ϵ\epsilon sufficiently small in terms of ρ\rho. Absorbing the divisor count and these small powers gives X1+ρ∑v>Yv−2≪X1+ρ/YX^{1+\rho}\sum_{v>Y}v^{-2}\ll X^{1+\rho}/Y, as claimed. The double pole in the kernel is harmless on this fixed positive line.

Poisson summation. For (d,H)=1(d,H)=1 put J=d2J=d^2 and cJ≡aJ−1(modH)c_J\equiv aJ^{-1}\pmod H. Let T(J)T(J) be the sum of A(n)Φ(n/X)A(n)\Phi(n/X) over n≡a(modH)n\equiv a\pmod H with J∣nJ\mid n, without a squarefree restriction. Writing m=m1qm=m_1q with m1∣H∞m_1\mid H^\infty and (q,H)=1(q,H)=1, put κ(m1)=χσa(m1)\kappa(m_1)=\chi_{\sigma a}(m_1) and

Gν(q)=∑y mod q(yq)e(νy/q),W(z,R)=∫0∞Φ(x)V(zQx)e(−Rx) dx,G_\nu(q)=\sum_{y\bmod q}\left(\frac{y}{q}\right)e(\nu y/q),\qquad W(z,R)=\int_0^\infty\Phi(x)V\left(\frac{z}{Qx}\right)e(-Rx)\,dx,

where e(x)=e2πixe(x)=e^{2\pi ix}. Poisson summation gives

T(J)=2XHJ∑m1∣H∞λ(m1)κ(m1)m1∑(q,H)=1λ(q)q3/2(σJHq)∑ν∈ZGν(q)e(νcJq‾/H)W(m1qX,νXHJq).(66)T(J)=\frac{2X}{HJ}\sum_{m_1\mid H^\infty}\frac{\lambda(m_1)\kappa(m_1)}{\sqrt{m_1}}\sum_{\substack{(q,H)=1}}\frac{\lambda(q)}{q^{3/2}}\left(\frac{\sigma JH}{q}\right)\sum_{\nu\in\mathbb{Z}}G_\nu(q)e(\nu c_J\overline q/H)W\left(\frac{m_1q}{X},\frac{\nu X}{HJq}\right). \tag*{(66)}

where qq‾≡1(modH)q\overline q\equiv1\pmod H and Gν(1)=1G_\nu(1)=1. For clarity, the Chinese remainder theorem evaluates the finite sum as

∑xmodHqx≡cJ (H)(xq)e(νx/(Hq))=e(νcJq‾/H)(Hq)Gν(q).\sum_{\substack{x\bmod Hq\\x\equiv c_J\ (H)}}\left(\frac{x}{q}\right)e(\nu x/(Hq))=e(\nu c_J\overline q/H)\left(\frac{H}{q}\right)G_\nu(q).

Multiplication by (σJ/q)(\sigma J/q) yields Equation (66); this factor vanishes when (q,J)>1(q,J)>1.

The zero frequency. The Gauss sum G0(q)G_0(q) is zero unless qq is a square, when it is φ(q)\varphi(q). Define

Hp(z)=1+(1−p−1)∑r≥1λ(p2r)p−r(1+2z),FJ(z)=∏p∤HJHp(z),H_p(z)=1+(1-p^{-1})\sum_{r\geq1}\lambda(p^{2r})p^{-r(1+2z)},\qquad F_J(z)=\prod_{p\nmid HJ}H_p(z),
LH(z)=∑m1∣H∞λ(m1)κ(m1)m1−1/2−z,Φ^0(z)=∫0∞Φ(x)xz dx.L_H(z)=\sum_{m_1\mid H^\infty}\lambda(m_1)\kappa(m_1)m_1^{-1/2-z},\qquad\widehat{\Phi}_0(z)=\int_0^\infty\Phi(x)x^z\,dx.

Mellin inversion expresses the zero-frequency contribution as

T0(J)=2XHJ12πi∫(2)ez2Γ(1+z)(QX)zΦ^0(z)LH(z)FJ(z)dzz2.(67)T_0(J)=\frac{2X}{HJ}\frac{1}{2\pi i}\int_{(2)}e^{z^2}\Gamma(1+z)(QX)^z\widehat{\Phi}_0(z)L_H(z)F_J(z)\frac{dz}{z^2}. \tag*{(67)}

At a good prime, let αpβp=1\alpha_p\beta_p=1 and ∣αp∣=∣βp∣=1|\alpha_p|=|\beta_p|=1. The identity

∑r≥0λ(p2r)xr=1+x(1−αp2x)(1−βp2x)\sum_{r\geq0}\lambda(p^{2r})x^r=\frac{1+x}{(1-\alpha_p^2x)(1-\beta_p^2x)}

shows that Hp(z)H_p(z) is the symmetric-square Euler factor at 1+2z1+2z times a polynomial 1+O(p−2−4ℜz+p−2−2ℜz)1+O(p^{-2-4\Re z}+p^{-2-2\Re z}). The correction product converges absolutely near ℜz≥−1/16\Re z\geq-1/16. To omit a prime dividing JJ, omit its correction factor and insert an inverse symmetric-square Euler polynomial; this introduces no poles at zeros of HpH_p. These omitted factors cost at most JBJ^B on that strip. The finite Euler product LHL_H is holomorphic there. Symmetric-square continuation, its functional equation, and polynomial strip bounds now allow the shift to ℜz=−1/16\Re z=-1/16, with error

T0(J)=RJ(X)+O(JBX1−1/16),T_0(J)=R_J(X)+O(J^B X^{1-1/16}),

where RJ(X)R_J(X) is the residue of the integrand in (67), including its factor 2X/(HJ)2X/(HJ). For this analytic input see [29]; in the CM case the untwisted symmetric square is a product of nontrivial Dirichlet and Hecke-character LL-functions, so the same continuation holds near 1.

The sum of the residues, with dd extended to infinity, has coefficient function

M(z)=ez2Γ(1+z)QzΦ^0(z)LH(z)∏p∣H(Hp(z)−p−2).M(z)=e^{z^2}\Gamma(1+z)Q^z\widehat{\Phi}_0(z)L_H(z)\prod_{p\mid H}(H_p(z)-p^{-2}).

The product is interpreted by its symmetric-square factorization and an absolutely convergent correction. It is holomorphic near zero. Moreover M(0)>0M(0)>0. Indeed

Fpev:=1+p−1(1−αp2/p)(1−βp2/p)>0,Hp(0)=p−1+(1−p−1)Fpev>p−1.F_p^{\mathrm{ev}}:=\frac{1+p^{-1}}{(1-\alpha_p^2/p)(1-\beta_p^2/p)}>0,\qquad H_p(0)=p^{-1}+(1-p^{-1})F_p^{\mathrm{ev}}>p^{-1}.

All the fixed local factors in LH(0)L_H(0) are positive, and L(1,sym⁡2f)>0L(1,\operatorname{sym}^2 f)>0 by the Rankin–Selberg residue formula. The remaining correction factors are positive and form a convergent product. The full residue is therefore

2XH(M(0)log⁡X+M′(0)),c=2M(0)H>0.(68)\frac{2X}{H}(M(0)\log X+M'(0)),\qquad c=\frac{2M(0)}{H}>0. \tag*{(68)}

Extending the residue sum costs Oρ(X1+ρ/Y)O_\rho(X^{1+\rho}/Y): its terms contain d−2∏p∣dHp(0)−1d^{-2}\prod_{p\mid d}H_p(0)^{-1}, and this product, as well as its differentiated version, is Oϵ(dϵ(1+log⁡d))O_\epsilon(d^\epsilon(1+\log d)). The resulting d−2+ϵd^{-2+\epsilon} tail also justifies differentiating the residue sum.

The nonzero frequencies. The zero frequency has now supplied the positive main term. We next bound the remaining frequencies uniformly in the square divisor JJ by a fixed power of JJ, so that summation over the retained square divisors will preserve a power saving in XX. We prove the bound

T≠0(J)≪JBX7/8.(69)T_{\ne0}(J) \ll J^{B}X^{7/8}. \tag*{(69)}

For odd qq, set ϵq=1\epsilon_q=1 or ii according as q≡1q\equiv1 or 33 (mod 44), and G~ν(q)=ϵq−1Gν(q)\widetilde{G}_{\nu}(q)=\epsilon_q^{-1}G_{\nu}(q). Quadratic reciprocity makes G~ν\widetilde{G}_{\nu} multiplicative in qq. As 4∣H4\mid H, the phase ϵqe(νcJq‾/H)\epsilon_q e(\nu cJ\overline{q}/H) is a function on (Z/HZ)×(\mathbb{Z}/H\mathbb{Z})^\times. Expand it in Dirichlet characters ψ\psi (mod HH); every expansion coefficient has absolute value at most one. For ν≠0\nu\ne0, consider

Dψ,J,ν(s)=∑(q,H)=1λ(q)qsG~ν(q)q(σJHνq)ψ(q).D_{\psi,J,\nu}(s)=\sum_{(q,H)=1}\frac{\lambda(q)}{q^s}\frac{\widetilde{G}_{\nu}(q)}{\sqrt{q}}\left(\frac{\sigma JH\nu}{q}\right)\psi(q).

At p∤2HJνp\nmid2HJ\nu, its local factor is 1+λ(p)ξ(p)p−s1+\lambda(p)\xi(p)p^{-s}, where ξ(q)=ψ(q)(σJHνq)\xi(q)=\psi(q)\left(\frac{\sigma JH\nu}{q}\right) is a Dirichlet character. Multiplication by the inverse GL2\mathrm{GL}_2 Euler factor leaves

1+(1−λ(p)2)ξ(p)2p−2s+λ(p)ξ(p)3p−3s.1+(1-\lambda(p)^2)\xi(p)^2p^{-2s}+\lambda(p)\xi(p)^3p^{-3s}.

These factors converge absolutely for ℜs>1/2\Re s>1/2.

The exceptional primes cause only a fixed power loss. For an odd prime pp, put v=vp(ν)v=v_p(\nu). Direct summation over residue lifts gives

Gν(pr)={φ(pr),r even, r≤v,−pr−1,r even, r=v+1,ϵppr−1/2(ν/pr−1p),r odd, r=v+1,0,otherwise.G_{\nu}(p^r)= \begin{cases} \varphi(p^r), & r\text{ even},\ r\le v,\\ -p^{r-1}, & r\text{ even},\ r=v+1,\\ \epsilon_p p^{r-1/2}\left(\dfrac{\nu/p^{r-1}}{p}\right), & r\text{ odd},\ r=v+1,\\ 0, & \text{otherwise}. \end{cases}

For even rr this is the Ramanujan sum. For odd rr, the sum of the lifts vanishes unless pr−1∣νp^{r-1}\mid\nu, and the primitive quadratic Gauss sum then gives the formula. Thus the local sum is a polynomial; on ℜs≥3/4\Re s\ge3/4 its absolute value is at most ∑r≥0(r+1)p−r/4≤C0\sum_{r\ge0}(r+1)p^{-r/4}\le C_0. The inverse Euler polynomial is also bounded absolutely. Primes dividing JJ remove the local sum altogether. Passing to the primitive character underlying ξ\xi introduces only such inverse Euler polynomials. Hence

Dψ,J,ν(s)=L(s,f⊗ξprim)Cψ,J,ν(s),D_{\psi,J,\nu}(s)=L(s,f\otimes\xi^{\mathrm{prim}})C_{\psi,J,\nu}(s),

where Cψ,J,νC_{\psi,J,\nu} is holomorphic for ℜs>1/2\Re s>1/2 and bounded on ℜs≥3/4\Re s\ge3/4 by (2J∣ν∣)C(2J|\nu|)^C. Indeed the exceptional-prime cost is at most C1ω(Jν)C_1^{\omega(J\nu)}, and the other corrections have summable O(p−3/2)O(p^{-3/2}) errors there. The conductor of ξprim\xi^{\mathrm{prim}} is at most 4HJ∣ν∣4HJ|\nu|. The twisted cusp-form LL-function is entire; its functional equation and polynomial strip bounds therefore give

∣Dψ,J,ν(3/4+it)∣≪f,H(J∣ν∣)C(1+∣t∣)C.|D_{\psi,J,\nu}(3/4+it)|\ll_{f,H}(J|\nu|)^C(1+|t|)^C.

The exponents are absolute because the degree and weight are fixed.

It remains to sum these bounds without losing the power saving. The kernel and integration by parts in xx give, for fixed r,sr,s and every K>0K>0,

∣(z∂z)r(R∂R)sW(z,R)∣≪r,s,K(1+z)−K(1+∣R∣)−K(1+∣log⁡z∣).|(z\partial_z)^r(R\partial_R)^sW(z,R)|\ll_{r,s,K}(1+z)^{-K}(1+|R|)^{-K}(1+|\log z|).

The logarithm accounts for the double pole when zz tends to zero. On the actual sums z≥X−1z \ge X^{-1}. For a fixed small ρ>0\rho> 0, insert smooth cutoffs z≪Xρz \ll X^\rho and ∣R∣≪Xρ|R| \ll X^\rho. The discarded part is negligible: use ∣Gν(q)∣≤q|G_\nu(q)| \le q and

∑ν∈Z(1+∣ν∣X/(HJq))−K≪H1+Jq/X\sum_{\nu\in\mathbb{Z}} (1+|\nu|X/(HJq))^{-K} \ll_H 1+Jq/X

to obtain a polynomial absolute majorant in X,JX,J for (66). More explicitly, its absolute value is Oϵ(X3/2+ϵlog⁡X)O_\epsilon(X^{3/2+\epsilon}\log X), uniformly for J≥1J \ge1: the qq-sums contribute (X/m1)1/2+ϵ+(J/X)(X/m1)3/2+ϵ(X/m_1)^{1/2+\epsilon}+(J/X)(X/m_1)^{3/2+\epsilon}, and the remaining m1∣H∞m_1 \mid H^\infty sums converge. For z>1z>1, absorb the positive logarithm into an arbitrarily small power of zz in this calculation. On either discarded tail, increasing KK in (10.12) supplies an arbitrarily large factor X−ρKX^{-\rho K}. The retained nonzero-frequency range satisfies

m1q≪X1+ρ,0<∣ν∣≪HJX2ρ,q≫HX1−ρ/J.m_1q \ll X^{1+\rho}, \qquad0<|\nu| \ll_H JX^{2\rho}, \qquad q \gg_H X^{1-\rho}/J.

Partition the qq-sum into smooth segments q≍Tq \asymp T. By (10.12), the finitely many derivative norms needed for Mellin inversion of the segment’s weight are O(XC′ρ)O(X^{C'\rho}), uniformly in m1,J,ν,Tm_1,J,\nu,T. Mellin inversion uses Dψ,J,ν(1+s)TsD_{\psi,J,\nu}(1+s)T^s. Shift its contour to ℜs=−1/4\Re s=-1/4; the factorization above shows that no pole is crossed. Equation (10.11) and the vertical decay of the weight’s Mellin transform give

∑qλ(q)qG~ν(q)q(σJHq)ν/qψ(q)W∗(q/T)≪(J∣ν∣)CXC′ρT−1/4.(70)\sum_q \frac{\lambda(q)}{q}\frac{\widetilde{G}_\nu(q)}{\sqrt{q}}\left(\frac{\sigma JH}{q}\right)^{\nu/q}\psi(q)W_*(q/T) \ll(J|\nu|)^C X^{C'\rho}T^{-1/4}. \tag*{(70)}

Here W∗W_* includes the dyadic and cutoff factors and both arguments of the original weight; their logarithmic derivatives are controlled by (10.12). The sum over m1m_1 is bounded since

∑m1∣H∞∣λ(m1)∣m1≤∏p∣H(1−p−1/2)−2<∞.\sum_{m_1\mid H^\infty}\frac{|\lambda(m_1)|}{\sqrt{m_1}}\le\prod_{p\mid H}(1-p^{-1/2})^{-2}<\infty.

Equation (10.13) bounds the dyadic sum of T−1/4T^{-1/4} by OH(J1/4X−1/4+ρ/4)O_H(J^{1/4}X^{-1/4+\rho/4}), even if its formal lower endpoint is below one. Also

∑0<∣ν∣≪HJX2ρ(J∣ν∣)C≪HJ2C+1X2(C+1)ρ.\sum_{0<|\nu|\ll_H JX^{2\rho}}(J|\nu|)^C\ll_H J^{2C+1}X^{2(C+1)\rho}.

Multiplying these estimates by X/JX/J from (66) proves T≠0(J)≪JBX3/4+C′′ρT_{\ne0}(J)\ll J^B X^{3/4+C''\rho}. Choose ρ\rho absolutely small enough that C′′ρ≤1/8C''\rho\le1/8. This proves (69).

Conclusion. Sum the zero- and nonzero-frequency errors over d≤Yd\le Y, with J=d2J=d^2. Together with the large-square and residue tails, the total error is

O(Y2B+1X1−κ+X1+ρ/Y),κ=1/16,O\left(Y^{2B+1}X^{1-\kappa}+X^{1+\rho}/Y\right),\qquad\kappa=1/16,

after enlarging BB. Choose an absolute δ0>0\delta_0>0 with (2B+1)δ0<κ/2(2B+1)\delta_0<\kappa/2, put Y=Xδ0Y=X^{\delta_0}, and choose the tail exponent 0<ρ<δ0/40<\rho<\delta_0/4. Both errors are O(X1−η)O(X^{1-\eta}) for an absolute η>0\eta>0. Equation (68) proves (10.1). Its leading coefficient is positive, so some derivative is nonzero in every sufficiently large dyadic interval. The odd functional equation already forces the central value to vanish, proving the final assertion.

Proof of Proposition 3.8(ii). Choose HH divisible by 8N8N and by all primes in S∪BS \cup B. The prescribed squareclasses and sign determine a reduced class a(modH)a \pmod H with σa≡1(mod4)\sigma a \equiv1 \pmod4, by the Chinese remainder theorem. At a prime in B∖SB\setminus S, choose any nonzero residue. Then every positive squarefree n≡a(modH)n \equiv a \pmod H gives an odd fundamental discriminant D=σnD=\sigma n in the prescribed filter and prime to every member of BB. Lemma 10.1 supplies arbitrarily large such nn with L′(E(D),1)≠0L'(E(D),1) \ne0.

Transfer on a binary cube

Both analytic arguments will produce one determinant coordinate at each vertex of a binary cube. The following algebra transfers a bounded valuation at every nonzero vertex to the zero vertex. Its essential feature is that the required dimension depends on a bounded number of coefficients, even when the family involves arbitrarily many primes.

Put Λ=Z2[[t]]\Lambda=\mathbb{Z}_2[[t]] and O=Λ(2)O=\Lambda_{(2)}. Let G≃(Z/2Z)bG \simeq(\mathbb{Z}/2\mathbb{Z})^b and R=Λ[G]R=\Lambda[G]. Index the sign homomorphisms G→{±1}G \to\{\pm1\} by x∈F2bx \in\mathbb{F}_2^b, with x=0x=0 the augmentation. For an element or matrix over O[G]O[G], a subscript xx denotes evaluation at this character. The proofs first control Laurent coefficients, then clear determinant denominators, and finally use the parity of the number of solutions of low-degree equations on the cube.

Lemma 11.1 (Laurent expansions). For M≥1M \ge1,

O/2MO≃(Z/2MZ)((t)).O/2^M O \simeq(\mathbb{Z}/2^M\mathbb{Z})((t)).

Thus an element of OO has a unique expansion ∑n∈Zantn\sum_{n\in\mathbb{Z}} a_n t^n with an∈Z2a_n \in\mathbb{Z}_2 and v(an)→∞v(a_n) \to\infty as n→−∞n \to-\infty. Its OO-valuation is min⁡nv(an)\min_n v(a_n).

Proof. If s∈Λ∖(2)s \in\Lambda\setminus(2), write s=thv1+2w1s=t^h v_1+2w_1, with v1∈Λ×v_1 \in\Lambda^\times and w1∈Λw_1 \in\Lambda. Modulo 2M2^M its inverse is a geometric expansion of length MM in 2w1/(thv1)2w_1/(t^h v_1). It is a Laurent series with finite negative support. Conversely every Laurent series with finite negative support lies in the localization of Λ\Lambda modulo 2M2^M, since tt is invertible there. Taking inverse limits proves the expansion statement. Reduction modulo successive powers of 22 proves the valuation formula.

Lemma 11.2 (A uniform pole bound for Schur elimination). Let A1,…,AmA_1,\ldots,A_m be square matrices over Λ\Lambda with nonzero residual determinants and ord⁡t(det⁡Aj)≤h\operatorname{ord}_t(\det A_j) \le h. Put A=diag⁡(A1,…,Am)A=\operatorname{diag}(A_1,\ldots,A_m). If B=A+2E1B=A+2E_1 with E1E_1 a matrix over Λ\Lambda, then BB is invertible over OO. Modulo 2M2^M, every entry of B−1B^{-1} has no powers below −Mh-Mh, independently of mm and of the matrix sizes. The same bound holds for a Schur complement D=P−QB−1SD=P-QB^{-1}S when P,Q,SP,Q,S have entries in Λ\Lambda.

In particular, suppose a block over RR augments to AA. It is invertible over O[G]O[G], and the assertion applies uniformly at all sign evaluations. If the lower off-diagonal block SS augments to zero, the Schur complement augments to the old block PP.

Proof. Write det⁡Aj=thjvj+2wj\det A_j=t^{h_j}v_j+2w_j, where hj≤hh_j\le h, vj∈Λ×v_j\in\Lambda^\times, and wj∈Λw_j\in\Lambda. Put

Cj=adj⁡(Aj)thjvj,C=diag⁡(C1,…,Cm).C_j=\frac{\operatorname{adj}(A_j)}{t^{h_j}v_j},\qquad C=\operatorname{diag}(C_1,\ldots,C_m).

Every entry of CC has pole at most hh. We have BC=1+2F1BC=1+2F_1, with every entry of F1F_1 having pole at most hh. Consequently

B−1≡C∑j=0M−1(−2F1)j(mod2M).B^{-1}\equiv C\sum_{j=0}^{M-1}(-2F_1)^j \pmod{2^M}.

The jjth summand has pole at most (j+1)h≤Mh(j+1)h \le Mh. The number of summands in a matrix product does not increase a valuation or pole bound. Multiplication by power-series matrices likewise introduces no negative powers. This proves the first assertion.

The ring O[G]O[G] is local with maximal ideal generated by 22 and the augmentation ideal of GG. The residual determinant of the proposed block is that of AA, a unit over F2((t))\mathbb{F}_2((t)), so the block is invertible. Each sign evaluation differs from augmentation by a matrix divisible by 22 with entries in Λ\Lambda. Apply the first assertion to it. The final assertion is the Schur formula with S0=0S_0=0.

A bounded clearing factor

Lemma 11.3 (A bounded clearing factor). Let DD be a based bounded complex of finite free O[G]O[G]-modules, of total graded rank at most rr, whose augmentation D0D_0 is a complex over Λ\Lambda. Suppose that the rational specialization of D0D_0 at t=0t=0 has one of the following cohomology patterns:

  1. dimension one in degrees one and two, and zero elsewhere;

  1. dimension two in degree one, and zero elsewhere.

Suppose that the total torsion length in the integral specialized cohomology is at most h1h_1.

In case (i), take an integral degree-one cycle zz and a closed functional λ∈2−a0(D2)∗\lambda\in2^{-a_0}(D^2)^*, and suppose each character constituent over the fraction field of OO is either acyclic or has pattern (i). Let uxu_x be the determinant tensor of their cohomology classes, with value zero in the acyclic case. In case (ii), take two cycles whose denominator exponents sum to at most a0a_0, suppose each constituent has pattern (ii), and let uxu_x be their wedge determinant coordinate. One may multiply these coordinates by any one element η∈O[G]\eta\in O[G].

Then there are f,d∈O[G]f,d \in O[G] with dx=fxuxd_x=f_xu_x at every character, such that ff is 2a02^{a_0} times a polynomial of bounded degree in the differential entries of DD, the degree depending only on rr. Moreover

f0∈Λ,f0(0)≠0,v(f0(0))≤C(r,h1,a0).f_0 \in\Lambda,\qquad f_0(0)\ne0,\qquad v(f_0(0))\le C(r,h_1,a_0).

If, at every fixed precision, the entries of DxD_x have a uniform bound on negative Laurent support, then so do the fxf_x. No such assertion is required for dxd_x, for the cycles, or for η\eta.

Proof. Over Z2\mathbb{Z}_2, put the specialized complex into a sum of free cohomology terms and one-dimensional two-term complexes with differentials 2aj2^{a_j}, by elementary-divisor decomposition. The sum of the positive aja_j is at most h1h_1. Lift the constant integral basis changes to DD. Cancel the same pivot positions formally, retaining their pivot numerators as denominators. The number of operations is bounded by rr. Each pivot and basis change is rational in the differential entries. Let P1P_1 be a product of sufficiently high powers of the successive pivot numerators so that every denominator in these changes and in the determinant comparison divides P1P_1. Its degree is bounded in terms of rr; its specialization P1,0(0)P_{1,0}(0) is nonzero with valuation bounded in terms of r,h1r,h_1. Increase the powers once more if needed to give all final expressions the same denominator.

Over O[G][1/P1]O[G][1/P_1], case (i) leaves a complex [O[G]→δO[G]][O[G] \xrightarrow{\delta} O[G]] in degrees one and two. Let α,β\alpha,\beta be the projected cycle and closed functional. Their determinant tensor, including the cancelled-pivot determinant factor, is a rational expression in D,z,2a0λD,z,2^{a_0}\lambda. If a field constituent has δ≠0\delta\ne0, the cycle identity δ=0\delta=0 gives α=0\alpha=0, so the same expression yields the stipulated zero coordinate. In case (ii) the remaining complex is O[G]2[−1]O[G]^2[-1] and its coordinate is the determinant of the two projected cycles times the pivot determinant factor. In either case, after denominator clearing, for every constituent on which P1,x≠0P_{1,x}\ne0 we have

ux=2−a0ηxQ1,x/P1,x,Q1∈O[G].u_x=2^{-a_0}\eta_xQ_{1,x}/P_{1,x},\qquad Q_1\in O[G].

Set f=2a0P12f=2^{a_0}P_1^2 and d=ηP1Q1d=\eta P_1Q_1. This gives dx=fxuxd_x=f_xu_x on those constituents. Where a pivot numerator first vanishes, P1,x=0P_{1,x}=0, and both sides of the cleared identity are zero. Thus the identity holds on every character. Since ff involves only the bounded number of differential entries in the pivot calculation, its degree, augmentation valuation and pole bounds are as asserted. The factor η\eta has been placed in dd, never in ff.

The preceding lemmas isolate the denominator problem: after eliminating new blocks, the clearing factor uses a complex of bounded size. The remaining task is to match finitely many coefficients at zero and at some nonzero vertex. The next lemma gives that match once the cube has sufficiently many coordinates.

Lemma 11.4 (Finite coefficient congruences). Let A1(x),…,Aq(x)∈Z2A_1(x),\ldots,A_q(x)\in\mathbb{Z}_2 each be one specified Laurent coefficient of the evaluation of an element of O[G]\mathcal{O}[G]. If

b>q(2M−1−1),b>q(2^{M-1}-1),

there is x≠0x\ne0 such that Ai(x)≡Ai(0)(mod2M)A_i(x)\equiv A_i(0)\pmod{2^M} for every ii.

Proof. For one coefficient write

A(x)=∑g∈Gag(−1)g⋅x=∑S⊆{1,…,b}cSxS,xS=∏i∈Sxi,2∣S∣∣cS.A(x)=\sum_{g\in G}a_g(-1)^{g\cdot x}=\sum_{S\subseteq\{1,\ldots,b\}}c_Sx_S,\qquad x_S=\prod_{i\in S}x_i,\qquad2^{|S|}\mid c_S.

The last divisibility follows by expanding each sign as a product of 1−2xi1-2x_i. The jjth binary digit of z∈Z2z\in\mathbb{Z}_2 is δj(z)=(z2j) mod 2\delta_j(z)=\binom{z}{2^j}\bmod2; this holds on nonnegative integers by binary expansion and then on Z2\mathbb{Z}_2 by continuity. In the ring of functions on the binary cube with coefficients in F2[[Z]]\mathbb{F}_2[[Z]],

(1+Z)A(x)=(1+Z)c∅∏S≠∅(1+xS((1+Z)cS−1)).(1+Z)^{A(x)}=(1+Z)^{c_{\varnothing}}\prod_{S\ne\varnothing}\left(1+x_S\left((1+Z)^{c_S}-1\right)\right).

The nonconstant factor indexed by SS starts at degree at least 2∣S∣2^{|S|} in ZZ. A term contributing to Z2jZ^{2^j}, for j≥1j\ge1, therefore has Boolean degree at most

∑S∣S∣≤∑S2∣S∣−1≤2j−1.\sum_S|S|\le\sum_S2^{|S|-1}\le2^{j-1}.

The zeroth digit is constant. The congruences in the statement are thus equations over F2\mathbb{F}_2 of total degree at most q∑j=1M−12j−1=q(2M−1−1)q\sum_{j=1}^{M-1}2^{j-1}=q(2^{M-1}-1), all vanishing at zero. For completeness, the number of their common zeros is even: modulo two it is the sum over the cube of the product of 1+Q1+Q over all defining equations QQ. Every monomial has degree below bb, hence omits a variable and sums to zero. This is the Chevalley–Warning argument [20, 79]. The zero solution therefore has a nonzero companion.

We now apply these coefficient congruences to the cleared identity dx=fxuxd_x=f_xu_x. Only the bounded negative support of fxf_x is prescribed; for dxd_x we will match its constant coefficient alone. This distinction keeps the required number of congruences independent of the numerator’s other coefficients.

Lemma 11.5 (Transfer through a bounded clearing factor). Let f,d∈O[G]f,d\in\mathcal{O}[G] and let ux∈Λ[1/2]u_x\in\Lambda[1/2] satisfy dx=fxuxd_x=f_xu_x at each character. Suppose f0∈Λf_0\in\Lambda and c0=v(f0(0))<∞c_0=v(f_0(0))<\infty. Fix M>c0M>c_0, and suppose every fx mod 2Mf_x\bmod2^M has no powers below −L(M)-L(M). If

b>(L(M)+2)(2M−1−1),b>(L(M)+2)(2^{M-1}-1),

some x≠0x \ne0 satisfies

v(ux(0)−u0(0))≥M−2c0.v(u_x(0)-u_0(0)) \ge M-2c_0.

Consequently, when c0c_0 and each L(M)L(M) have bounds independent of the family, a uniform upper bound v(ux(0))≤B1v(u_x(0)) \le B_1 at all nonzero vertices forces v(u0(0))≤B1v(u_0(0)) \le B_1 for all sufficiently large bb. The base value itself is allowed to vary with the family.

Proof. Apply Lemma 11.4 to the coefficients of fxf_x in degrees −L(M),…,0-L(M),\ldots,0 and to the constant coefficient of dxd_x. At the supplied nonzero solution, every negative coefficient of fxf_x is divisible by 2M2^M, and its constant coefficient is congruent to f0(0)f_0(0). Therefore its constant coefficient has valuation c0c_0, and vO(fx)≤c0v_{\mathcal O}(f_x) \le c_0. Since dx∈Od_x \in O, the identity dx=fxuxd_x=f_xu_x gives vO(ux)≥−c0v_{\mathcal O}(u_x) \ge-c_0; the same bound holds for u0u_0. By Lemma 11.1, all their coefficients are in 2−c0Z22^{-c_0}\mathbb{Z}_2. Both have zero negative coefficients because they lie in Λ[1/2]\Lambda[1/2].

The convergent constant-term convolution gives

[t0]dx≡([t0]fx)ux(0)(mod2M−c0),[t0]d0=f0(0)u0(0).[t^0]d_x \equiv([t^0]f_x)u_x(0) \pmod{2^{M-c_0}}, \qquad[t^0]d_0=f_0(0)u_0(0).

Combine these identities with the imposed coefficient congruences and divide by f0(0)f_0(0). This proves Equation (11.2). For the consequence, choose one integer M>max⁡{c∗,B1+2c∗}M>\max\{c_*,B_1+2c_*\}, where c∗c_* bounds c0c_0, and then take bb above Equation (11.1). If the base valuation exceeded B1B_1, the transferred nonzero valuation would also exceed B1B_1, a contradiction. The pivot valuation affects the required precision and dimension, but not the transferred upper bound.

Finite cochain models

The arithmetic applications also need finite free complexes that retain maps to the original cochains. The following algebraic construction provides these models and transports their comparison diagrams. It applies before any determinant coordinate is chosen.

Lemma 11.6 (Finite Artin models). Let (A,m,k)(A,\mathfrak m,k) be an Artin local ring, and let DD be a complex of flat AA-modules. Suppose H∗(D⊗Ak)H^*(D\otimes_A k) is finite dimensional and supported in [a,b][a,b]. There is a bounded finite free complex CC, with

rank⁡ACj=dim⁡kHj(D⊗Ak),\operatorname{rank}_A C^j=\dim_k H^j(D\otimes_A k),

and a strong deformation retraction

i:C⟶D,p:D⟶C,pi=1,1−ip=dh+hd.i:C\longrightarrow D,\qquad p:D\longrightarrow C,\qquad pi=1,\qquad1-ip=dh+hd.

Thus maps to the original complex, as well as maps between finite models, are available. Any fixed finite collection of chain maps, homotopies, triangles, and perfect pairings can be transported to these models.

Proof. Flat modules over an Artin local ring are free, including modules of infinite rank. Here is a useful version of the argument. Lift a basis of M/mMM/\mathfrak mM to a flat module MM, and map the corresponding free module to MM. Its cokernel is zero because m\mathfrak m is nilpotent. Flatness shows that the kernel has zero reduction, and nilpotence again makes the kernel zero.

Split the residual complex as its cohomology, with zero differential, plus contractible two-term disks. Lift all the graded bases. These lifts are graded isomorphisms: an inverse modulo m\mathfrak m lifts to an inverse by a finite geometric series. Let d0d_0 be the lifted disk differential and write d=d0+ϵd=d_0+\epsilon. All coefficients of ϵ\epsilon belong to m\mathfrak m. For the disk contraction (i0,p0,h0)(i_0,p_0,h_0), arrange h02=h0i0=p0h0=0h_0^2=h_0i_0=p_0h_0=0 and 1−i0p0=d0h0+h0d01-i_0p_0=d_0h_0+h_0d_0. The operators 1+h0ϵ1+h_0\epsilon and 1+ϵh01+\epsilon h_0 have finite geometric inverses. The homological perturbation lemma gives explicit contraction maps; we record the formulas to retain their compatibility with the arithmetic diagrams [22], Sections 2.2–2.4 and 3.2. The perturbation identities give the differential

dC=p0ϵ(1+h0ϵ)−1i0d_C=p_0\epsilon(1+h_0\epsilon)^{-1}i_0

on the lifted residual cohomology, and give

i=(1+h0ϵ)−1i0,p=p0(1+ϵh0)−1,h=h0(1+ϵh0)−1.i=(1+h_0\epsilon)^{-1}i_0,\qquad p=p_0(1+\epsilon h_0)^{-1},\qquad h=h_0(1+\epsilon h_0)^{-1}.

Substitution, using (d0+ϵ)2=0(d_0+\epsilon)^2=0, proves the asserted contraction identities. These calculations are valid for infinite disk sums: each operator is a module homomorphism and every geometric series terminates at the nilpotence exponent of m\mathfrak m.

Transport a map ff as p′fip'f i, retaining the contraction homotopies for compositions. A quasi-isomorphism between bounded free complexes has a contractible cone and a homotopy inverse. This transports finite diagrams, including triangles and perfect dualities.

Cyclotomic interpolation at analytic rank zero

The cyclotomic argument transfers a nonzero central value across a binary family. Its input is a uniform upper bound for the normalized valuations at every nonzero vertex. Its output is nonvanishing at a corank-zero base. The class used here is Kato’s zeta class, and the additional variable is the real cyclotomic Z2\mathbb Z_2-extension of Q\mathbb Q.

Retain T=T2(E)T=T_2(E) and put V2=T⊗Z2Q2V_2=T\otimes_{\mathbb Z_2}\mathbb Q_2. The local weights, finite Sha lengths and period normalization are those of Section 2, and D(h)D(h) is defined in (3). We prove Theorems 3.5 and 3.1 with their stated distinction between the uniform specialization error and the dimension threshold for a fixed base.

For a two-dimensional representation over F2\mathbb F_2, reducibility is equivalent to being an extension of trivial modules. These are therefore the two exhaustive residual cases. The proof has three stages: construct a class in a fixed integral lattice, identify its central determinant, and apply the binary congruences. Residual reducibility makes the cyclotomic complex free after localization at (2)(2); the irreducible case instead uses the bounded clearing factor of Lemma 11.3.

The positive cyclotomic complex

At the coefficient prime 2, the real place must be included in the cochain construction. The positive complex defined below removes the real cochains and retains their connecting invariant line. We will combine this fixed line with the zeta class to form the determinant whose central value detects nonvanishing at a corank-zero base.

Put

Γ=Gal⁡(Q∞/Q),Λ=Z2[[Γ]]=Z2[[t]],O=Λ^(2),Ω=O/2O=F2((t)),\Gamma=\operatorname{Gal}(\mathbb Q_\infty/\mathbb Q),\qquad\Lambda=\mathbb Z_2[[\Gamma]]=\mathbb Z_2[[t]],\qquad\mathcal O=\widehat{\Lambda}_{(2)},\qquad\Omega=\mathcal O/2\mathcal O=\mathbb F_2((t)),

where a generator of Γ\Gamma corresponds to 1+t1+t. The completion is 2-adic. An element of O\mathcal O has a finite negative Laurent part modulo every 2M2^M, but need not have a value at t=0t=0. Every central evaluation below is made on a rational Iwasawa class or on an element of Λ[1/2]\Lambda[1/2] before extending coefficients to O\mathcal O.

For a family in (4), let G=(Z/2Z)bG=(\mathbb Z/2\mathbb Z)^b have characters indexed by x∈F2bx\in\mathbb F_2^b, and let ψ:GQ→G\psi:G_{\mathbb Q}\to G be its universal quadratic character: evaluation at xx is χx/h0\chi_x/h_0. Put

R=Λ[G],T=T⊗Z2RR=\Lambda[G],\qquad T=T\otimes_{\mathbb Z_2}R

with the fixed twist χh0\chi_{h_0}, the universal twist ψ\psi, and the inverse cyclotomic action. One may replace GG by the actual image of ψ\psi and subsequently extend scalars. In a family in Theorem 3.1, a nonzero character trivial on that image already gives the conclusion directly.

Let SS be the set of primes dividing 2Nh0∏q∈Qq2Nh_0\prod_{q\in\mathcal{Q}}q. For q∈Qq\in\mathcal{Q}, write gq∈Gg_q\in G for its inertia element, so x(gq)=(−1)λq(x)x(g_q)=(-1)^{\lambda_q(x)}. Use continuous cochains with their completed coefficient topology, and set

CS+(T)=Cone⁡(RΓ(GQ,S,T)⟶RΓ(R,T))[−1].(71)C_S^+(\mathbb{T})=\operatorname{Cone}\bigl(R\Gamma(G_{\mathbb{Q},S},\mathbb{T})\longrightarrow R\Gamma(\mathbb{R},\mathbb{T})\bigr)[-1]. \tag*{(71)}

The real complex here uses ordinary cochains in nonnegative degrees. There are no imposed local conditions at the finite places. We write CS(T)=RΓ(GQ,S,T)C_S(\mathbb{T})=R\Gamma(G_{\mathbb{Q},S},\mathbb{T}) for the unmodified complex. Throughout this section, ordinary global cohomology means this unmodified cohomology; it imposes no ordinary-reduction hypothesis at 22.

Lemma 12.1. The complex in Equation (71) is perfect over RR and computes derived coefficient specializations. There is a class a∈H1(CS+(T))a\in H^1(C_S^+(\mathbb{T})) whose rational span is the real-place summand. Its integral index in that summand depends only on EE and the fixed real sign.

Proof. Here are the finiteness and coefficient issues in the use of global cochains. For a finite coefficient quotient of RR, continuous cochains are filtered unions of finite products of free coefficient modules. Refinement of finite partitions makes these modules flat; over an Artin local coefficient ring they are free. For finite residual coefficients, global cohomology is finite in each degree, and restriction to the real places is an isomorphism in degrees greater than two, by the real-place clause of global duality [52] §5.7.1.7. Thus the residual fiber has bounded amplitude and finite-dimensional cohomology. The same amplitude bound holds for every finite coefficient module, by a composition series and the cohomology long exact sequence.

This gives a bounded finite free model as follows. Over the residue field split off the acyclic disks, leaving its finitely many cohomology spaces. Lift each invertible disk differential over an Artin coefficient quotient and cancel it. Invertibility of a lifted inverse follows from nilpotence of the maximal ideal. Equivalently one can perform this on a free resolution; a minimal free model cannot have an additional term whose reduction has zero cohomology, because its residual differential is zero. Hence the remaining ranks are the finite residual ranks and are bounded independently of the coefficient quotient. Minimal models identified by a homotopy equivalence over an Artin local ring are isomorphic. Lifting their changes of basis therefore makes these models compatible along R/mnR/\mathfrak{m}^n. Taking the inverse limit gives a bounded finite free model over RR. The cochain construction with finite free coefficients and the same cancellation also proves derived base change. This is a fixed-SS argument; it does not assert uniform bounds on the number of generators as SS varies.

All the characters of the family have the same real sign, so the action at the real place is the fixed action on Tχh0T\chi_{h_0} extended to RR. Choose a nonzero vector in its integral invariant line. Its connecting image in the fiber is aa. There are no global invariant vectors in the rational elliptic representation, and consequently this connecting map is injective rationally. The choice and its index are fixed. Notice also that H1(R,T)H^1(\mathbb{R},\mathbb{T}) is killed by 22; thus twice any ordinary cohomology class lifts to the positive complex. The real-place global duality input is its corrected form at 22 [52] §§5.7.1–5.7.5; the invariant line and the lifting assertion follow from the long exact sequence of this ordinary-real cone. Complete real Tate cochains, used in the duality formulation, become acyclic after inverting 22 and would not retain this invariant line.

Fixed-form zeta classes and the integral coefficient map

To control denominators as the tame support grows, we construct every class in the cohomological lattice of one fixed modular form. Let ff be the fixed weight-two form of EE, and choose its fixed integral cohomological lattice, with the Tate twist making its rational representation V2V_2. Kato’s classes (8.1.2)–(8.1.3), for a fixed symbol ξ∈SL⁡2(Z)\xi\in\operatorname{SL}_2(\mathbb{Z}), exist for arbitrary mm and any SS containing the prime factors of mNmN. The trace in Section 8.9 is a homomorphism into the lattice

Z2[Gal⁡(Q(μm)/Q)]⊗V2,Z2(Y1(N))(1).\mathbb{Z}_2[\operatorname{Gal}(\mathbb{Q}(\mu_m)/\mathbb{Q})] \otimes V_{2,\mathbb{Z}_2}(Y_1(N))(1).

Section 8.11 then projects to the lattice of the fixed form. Proposition 8.12 supplies its norm relations. These assertions hold at the coefficient prime 2 [38], Sections 5.1, 8.1, 8.9–8.12. In particular, the auxiliary modular-curve level used to define a trace does not become the level of the projected newform.

Choose an isomorphism of the resulting fixed rational representation with V2V_2. A single power 2cE2^{c_E} sends its integral lattice into TT. Choose fixed symbols with nonzero projections on the required period lines; their existence and the construction with both signs are made explicit in [38], Sections 13.6 and 13.9. Taking a fixed linear combination, if needed, costs another fixed denominator.

The following integral coefficient map encodes the binary family. Choose m=∣h0∣∏q∈Qqm = \lvert h_0\rvert\prod_{q\in\mathbb{Q}} q, which is odd and divisible by the conductors of all the tame characters in the family, including χh0\chi_{h_0}. At a sufficiently large cyclotomic level write Am,n=Gal⁡(Q(μm2n)/Q)A_{m,n} = \operatorname{Gal}(\mathbb{Q}(\mu_{m2^n})/\mathbb{Q}) and let Γn\Gamma_n be its quotient in the real cyclotomic tower. Shapiro identifies the cohomology of the cyclotomic field with global cohomology with induced group-ring coefficients. Push the class along the ring homomorphism

Z2[Am,n]⟶Z2[Γn×G],[σ]⟼χh0(σ)[σ∣Γn][ψ(σ)].(72)\mathbb{Z}_2[A_{m,n}] \longrightarrow\mathbb{Z}_2[\Gamma_n \times G], \qquad[\sigma] \longmapsto\chi_{h_0}(\sigma)[\sigma|_{\Gamma_n}][\psi(\sigma)]. \tag*{(72)}

Use inverse actions on both sides if this is required by the chosen Shapiro convention. This is a homomorphism of integral coefficient modules and acts on actual cohomology classes. It requires neither division by ∣G∣\lvert G\rvert nor surjectivity of a cohomological specialization map. The prime 2 belongs to the fixed omitted support, so Proposition 8.12 gives exact norm compatibility as nn increases. The pushed classes therefore give an integral smoothed Iwasawa class with coefficients in TT, up to the single fixed power 2cE2^{c_E}.

We have placed all character constituents in the lattice of the same modular form. The next normalization issue is smoothing: its removal must be harmless both after localization at (2) and at the central value t=0t = 0. These are distinct requirements, checked next.

We next remove smoothing. In weight two and with r=r′=1r = r' = 1, its factors are

(c2−cσc)(d2−dσd).(c^2 - c\sigma_c)(d^2 - d\sigma_d).

This is the specialization of [38], Theorem 6.6 and (4.2.4). Choose a fixed e≥max⁡(2,v2(N))e \geq\max(2, v_2(N)), increasing it to accommodate the finitely many fixed symbol levels. The Chinese remainder theorem permits c,d>1c,d > 1, prime to 6Nm6Nm, such that

c,d≡1(mod3Noddm),c,d≡1+2e(mod2e+1).c,d \equiv1 \pmod{3N_{\mathrm{odd}}m}, \qquad c,d \equiv1 + 2^e \pmod{2^{e+1}}.

Their tame actions in (72) are trivial. If σc\sigma_c acts in Γ\Gamma as (1+t)κ(c)(1+t)^{\kappa(c)}, then v2(κ(c))=e−2v_2(\kappa(c)) = e - 2. Modulo the maximal ideal of O[G]\mathcal{O}[G] its smoothing factor is

1−(1+t)κ(c)≠0in F2((t)).1 - (1+t)^{\kappa(c)} \ne0 \quad\text{in } \mathbb{F}_2((t)).

It is therefore a unit in O[G]\mathcal{O}[G]. Its central value is c(c−1)c(c-1), of valuation exactly ee. The same statements hold for dd and for inverse-translate conventions. Thus unsmoothing introduces neither a 2-adic denominator at (2)(2) nor a growing central denominator. The integers c,dc,d vary with mm; the congruences fix the needed valuations, not their exact cyclotomic group elements.

Denote the resulting rational ordinary class by zSz_S. Kato [38] applies to k=2k=2, r=r′=1r=r'=1. In the character constituent xx, its central reciprocity formula reads

v2(exp⁡2∗zS,x(0))=v2(L(hx))+∑q∈Qq∤hxv2(#E(hx)(Fq))+OE(1)(73)v_2\left(\exp^*_{2} z_{S,x}(0)\right)=v_2\left(\mathcal{L}(h_x)\right)+\sum_{\substack{q\in Q\\q\nmid h_x}}v_2\left(\#E^{(h_x)}(\mathbb{F}_q)\right)+O_E(1) \tag*{(73)}

when the value is nonzero, and a zero central value gives a zero dual exponential. The omitted primes dividing 2N2N are included in the error. To check the normalization, the character sum in (72) is the unnormalized sum, as in Kato’s trace. Its tame quadratic Gauss sum supplies ∣hx∣\sqrt{\lvert h_x\rvert} up to a root of unity. Tame conductors and their Gauss sums are 2-adic units. The period vector is the fixed symbol vector of ff. More explicitly, in the required sign line write the period represented by δ(f,1,ξ)±\delta(f,1,\xi)^{\pm} as cξ±ΩE±c_{\xi}^{\pm}\Omega_E^{\pm}. The nonzero scalar cξ±c_{\xi}^{\pm} is fixed: the character-sum formula of [38] uses this same δ(f,1,ξ)±\delta(f,1,\xi)^{\pm} for every tame character. The tame character enters through its LL-value and Gauss sum, not through a newly chosen period vector. The comparison with the minimal differential of E(hx)E^{(h_x)} at 2 has bounded valuation, because there are only finitely many local twisting classes there. At a good unused prime the omitted factor is

1−aq(E)χhx(Fr⁡q)q+1q=#E(hx)(Fq)q;1-\frac{a_q(E)\chi_{h_x}(\operatorname{Fr}_q)}{q}+\frac{1}{q}=\frac{\#E^{(h_x)}(\mathbb{F}_q)}{q};

at a good ramified prime the local LL-factor is 1. These account for every varying factor in (73).

Rational divisibility and the local Euler corrections

We now exclude poles of the zeta determinant away from (2) and account for every omitted Euler factor. Write A=Λ[1/2]A=\Lambda[1/2]. Theorem 12.5(3) of [38] is a height-one divisibility over AA; its possible local H2H^2 correction comes from the arithmetic place 2. It need not be supported at the Iwasawa ideal (2)(2). The global groups there use j∗j_* outside that prime. The stronger integral assertion of Theorem 12.5(4) is not used. For a non-CM elliptic curve the characteristic-zero image condition is supplied by the open image theorem, independently of the residual image. For CM the required rational statement at every prime, including 2, is supplied by [12]. Neither statement asserts uniform integrality in a quadratic group ring. The rational cohomology statements, including Kato [38], Theorem 12.4, give rank one in degree one and torsion in degree two, with no other positive cohomological rank. The real-place modification adds its invariant line. Hence every generic character constituent of the positive complex has rank two in degree one and no other positive rank.

Fix a character constituent hh and write Vh=V2χhV_h=V_2\chi_h. Let Cj∗C_{j_*} be the rational Iwasawa complex in Kato’s formulation and CSC_S the rational full global complex. At an odd prime put

Wq=H1(Iq,Vh).W_q=H^1(I_q,V_h).

The localization triangle has local cone

Qq=RΓ(GFq,Wq⊗A(Γ))[−1]=[Wq⊗A→1−γqFr⁡WqWq⊗A](74)Q_q=R\Gamma(G_{\mathbb{F}_q},W_q\otimes A(\Gamma))[-1] =\left[W_q\otimes A\xrightarrow{1-\gamma_q\operatorname{Fr}_{W_q}}W_q\otimes A\right] \tag*{(74)}

in degrees one and two. Here γq\gamma_q denotes the scalar cyclotomic Frobenius in the chosen convention. Its exponent is nonzero. Consequently Dq=det⁡(1−γqFr⁡Wq)D_q=\det(1-\gamma_q\operatorname{Fr}W_q) is a nonzero element of AA, and the map in (74) is injective. This remains true after localization at a height-one prime dividing DqD_q: localization does not mean reduction modulo that prime. Thus

H1(Qq)=0,length⁡ApH2(Qq)p=vp(Dq).H^1(\mathbb{Q}_q)=0,\qquad\operatorname{length}_{A_{\mathfrak{p}}}H^2(\mathbb{Q}_q)_{\mathfrak{p}}=v_{\mathfrak{p}}(D_q).

The long exact sequence gives

H1(Cj∗)≃H1(CS),H^1(C_{j_*})\simeq H^1(C_S),
0⟶H2(Cj∗)⟶H2(CS)⟶⨁q∈S∖{2}H2(Qq)⟶H3(Cj∗).(75)0\longrightarrow H^2(C_{j_*})\longrightarrow H^2(C_S)\longrightarrow\bigoplus_{q\in S\setminus\{2\}}H^2(\mathbb{Q}_q)\longrightarrow H^3(C_{j_*}). \tag*{(75)}

In particular, the length of H2(CS)H^2(C_S) is at most the length of H2(Cj∗)H^2(C_{j_*}) plus the sum of the local lengths. No assertion that H3(Cj∗)H^3(C_{j_*}) vanishes is required here.

At a good unused prime, Wq=Vh(−1)W_q=V_h(-1), so, on including the quadratic Frobenius sign in ZZ,

Dq=Pq(Z),Pq(Z)=1−aq(E)qZ+1qZ2.(76)D_q=P_q(Z),\qquad P_q(Z)=1-\frac{a_q(E)}{q}Z+\frac{1}{q}Z^2. \tag*{(76)}

At a good active prime, inertia acts by −1-1 on VhV_h. Its rational inertia cohomology is zero, so Wq=0W_q=0 and Dq=1D_q=1.

At fixed bad primes the general expression is H1(Iq,Vh)H^1(I_q,V_h) in (74). Replacing it indiscriminately by VhIq(−1)V_h^{I_q}(-1) would be incorrect. For example, at split multiplicative reduction,

VhIq=Q2(1),H1(Iq,Vh)=Q2(−1),V_h^{I_q}=\mathbb{Q}_2(1),\qquad H^1(I_q,V_h)=\mathbb{Q}_2(-1),

and the correct determinant is 1−γq/q1-\gamma_q/q, with nonzero central value. The incorrect replacement would give 1−γq1-\gamma_q. In general Dq(0)≠0D_q(0)\ne0 follows from local duality and the Weil pairing: H2(Qq,Vh)=H0(Qq,Vh)∗=0H^2(\mathbb{Q}_q,V_h)=H^0(\mathbb{Q}_q,V_h)^*=0, since elliptic torsion over a local field is finite. The fixed bad-prime corrections therefore have nonzero central values for every reduction type.

Let zBK,hz_{\mathrm{BK},h} denote a generator of the rational Kato zeta line in its real cyclotomic component. The rational comparison with the fixed-form class constructed above is made only after taking the character constituent. Both global Iwasawa H1H^1 modules have rank one. Their reciprocity laws at cyclotomic finite-order characters agree up to the omitted Euler factors, a nonzero constant, and a group-like unit. This follows by coprime Gauss-sum factorization and the fixed period comparison; restricting conductor exponents to either fixed parity removes any factor χh(2)n\chi_h(2)^n. Infinitely many of these tests have nonzero central value by cyclotomic nonvanishing, as used in [38], Theorem 13.5(2). After clearing the finitely many denominators of the scalar ratio, the difference is a power series vanishing at infinitely many finite-order characters. Weierstrass preparation forces that difference to be zero. This proves the generic comparison without identifying the integral lattices of varying twisted newforms. Its nonzero scalar in Q2\mathbb{Q}_2 may depend on hh and need not have a uniformly bounded 2-valuation: every such scalar is a unit of AA and does not affect height-one divisibility over AA. The uniform integral and central bounds instead concern the actual fixed-form class and the fixed period vector in (73).

Equations (75)–(76) now show exactly how the imprimitive factors enter divisibility. At any height-one p\mathfrak{p} of AA, enlarging the global complex increases its degree-two length by at most ∑qvp(Dq)\sum_q v_{\mathfrak{p}}(D_q), whereas multiplying the rank-one zeta generator by ∏qDq\prod_q D_q adds exactly that quantity to its index. To cover Kato’s coefficient-prime correction, multiply the class also by a fixed element F2∈ΛF_2 \in\Lambda divisible over AA by the characteristic ideal of the relevant local HIw2H^2_{\mathrm{Iw}}. It may be chosen with F2(0)≠0F_2(0) \ne0. Indeed derived local control gives

HIw2(Q2,Tχh)Γ⊗Q2=H2(Q2,Vh)=0,H^2_{\mathrm{Iw}}(\mathbb{Q}_2,T\chi_h)_{\Gamma}\otimes\mathbb{Q}_2=H^2(\mathbb{Q}_2,V_h)=0,

so the characteristic ideal has no factor tt. Local twisting classes at 2 are fixed, and one element covers their finite set.

Likewise any additional fixed Euler factors in the rational comparison can be cleared by a fixed product with nonzero central value, using the actual blocks (74). Denote the total fixed multiplier by FEF_E. Multiplying by it only changes the fixed constants in (73) and the integrality bound. For the corrected class, still written zSz_S, we have at every height-one p\mathfrak p of AA

length⁡ApH2(CS)p≤length⁡Ap(H1(CS)/AzS,h)p.\operatorname{length}_{A_{\mathfrak p}} H^2(C_S)_{\mathfrak p}\leq\operatorname{length}_{A_{\mathfrak p}}\left(H^1(C_S)/Az_{S,h}\right)_{\mathfrak p}.

There is an integral convention check for the varying unused primes. In O[G]\mathcal O[G], both Pq(Z)P_q(Z) and Z2Pq(Z−1)Z^2P_q(Z^{-1}) are units: their reductions are nonzero polynomials evaluated at the nonconstant cyclotomic Frobenius. The identity

Pq(Z)−Z2Pq(Z−1)=q−1q(1−Z2)P_q(Z)-Z^2P_q(Z^{-1})=\frac{q-1}{q}(1-Z^2)

shows that their ratio rqr_q is 1 modulo 2. If gqg_q is the universal inertia element, then

Uq=1+rq−12(1+gq)∈O[G]×U_q=1+\frac{r_q-1}{2}(1+g_q)\in\mathcal O[G]^\times

is integral. At an active character it is 1; at an unused character it is rqr_q. Its unused central value is 1, since Z=±1Z=\pm1 there. Thus inverse Frobenius conventions can be reconciled before character evaluation, without a denominator for each prime. Products of these units have the same property. The resulting rational character coordinates have the Euler convention in (12.8).

Lemma 12.2 (Fixed-lattice zeta class). For every binary family and its ramification set SS, the corrected class zSz_S satisfies the central reciprocity formula (73) and the rational divisibility (12.8). For some cE≥0c_E\geq0 depending only on EE,

2cEzS∈H1(CS(T)⊗RO[G]).2^{c_E}z_S\in H^1\left(C_S(T)\otimes_{\mathcal R}\mathcal O[G]\right).

The same exponent works for all SS, binary families, and fixed factors h0h_0 with the specified local classes. Here the displayed cohomology is derived scalar extension of the Iwasawa complex.

Proof. The integral coefficient map uses the fixed-form lattice and no character averages. Unsmoothing and every varying-prime convention correction are units over O[G]\mathcal O[G]. The multiplier FEF_E is fixed. The preceding construction therefore gives the displayed assertion with a fixed exponent, as well as the two stated comparison formulas.

The determinant and its central specialization

The zeta class now has two controls: rational divisibility will exclude poles of its determinant coordinate away from (2), and the fixed lattice bounds the class’s integral denominator at (2). We next identify its determinant coordinate at t=0t=0. This is the step that converts those cohomological controls into a statement about D(h)D(h).

Choose a basis of the invertible RR-module det⁡R−1CS+(T)\det_R^{-1} C_S^+(\mathrm{T}); RR is local, so such a basis exists. Lift 2zS2z_S to rational positive cohomology and take its wedge with aa. The factor 22 is fixed, and two lifts differ by a real-place class, which does not change this wedge. Let uxu_x be its generic determinant coordinate, including the fixed multiplier FEF_E above. The real-place summand introduces no height-one torsion over AA. Thus (12.8) says that uxu_x has no pole at any height-one prime of Λ\Lambda except possibly (2)(2). Since Λ\Lambda is normal,

ux∈Λ[1/2]for every x.(77)u_x \in\Lambda[1/2] \qquad\text{for every } x. \tag*{(77)}

The two cycles have a common denominator bounded by a fixed power 2Cint2^{C_{\mathrm{int}}} after extension to O[G]\mathcal{O}[G]. This follows from Lemma 12.2 and the factor 22 needed for the lift.

Proposition 12.3 (Central determinant formula). There is a constant ClocC_{\mathrm{loc}}, depending only on the fixed curve and local classes, with the following property. Suppose c2(E(hx))=0c_2(E^{(h_x)})=0. If L(E(hx),1)=0L(E^{(h_x)},1)=0, then ux(0)=0u_x(0)=0; if L(E(hx),1)≠0L(E^{(h_x)},1)\ne0, then

∣v2(ux(0))−D(hx)∣≤Cloc.(78)\left|v_2(u_x(0))-D(h_x)\right| \le C_{\mathrm{loc}}. \tag*{(78)}

The rational positive complex at t=0t=0 has cohomology only in degree one, of dimension two, so these are specializations of the same determinant.

Proof. Abbreviate Th=T2E(hx)T_h=T_2E^{(h_x)} and Ah=E(hx)[2∞]A_h=E^{(h_x)}[2^\infty]. Use the integral Kummer subgroup

Kv=im⁡(E(hx)(Qv)2∧⟶H1(Qv,Th))K_v=\operatorname{im}\left(E^{(h_x)}(\mathbb{Q}_v)^{\wedge}_2 \longrightarrow H^1(\mathbb{Q}_v,T_h)\right)

at every finite place. For v≠2v\ne2 it is all of H1(Qv,Th)H^1(\mathbb{Q}_v,T_h). One way to see this integrally is the inverse-limit Kummer exact sequence: its quotient is T2H1(Qv,E(hx))T_2H^1(\mathbb{Q}_v,E^{(h_x)}), which is zero because local Tate duality identifies the 2-primary local Weil–Châtelet group with the dual of the finite 2-completion of the local point group. At 22 the quotient

L2=H1(Q2,Th)/K2L_2=H^1(\mathbb{Q}_2,T_h)/K_2

is a free rank-one Z2\mathbb{Z}_2-module. The same Kummer sequence and local Tate duality identify it with the Z2\mathbb{Z}_2-dual of the free part of E(hx)(Q2)2∧E^{(h_x)}(\mathbb{Q}_2)^{\wedge}_2.

The dual exponential identifies L2⊗Q2L_2\otimes\mathbb{Q}_2 with the one-dimensional de Rham target. To specify its integral comparison, put

B2=E(hx)(Q2)2∧/tors⁡.B_2=E^{(h_x)}(\mathbb{Q}_2)^{\wedge}_2/\operatorname{tors}.

and choose a minimal differential ωh\omega_h. The Bloch–Kato exponential agrees with the Kummer image of the classical elliptic exponential, which is the inverse of the formal logarithm on a sufficiently small open subgroup. This comparison holds for every reduction type [4], Definition 3.10 and Example 3.11. The dual exponential is the adjoint of that exponential under local Tate duality [2], §II and Proposition II.5. Extend the formal logarithm to the rationalized local point group and write log⁡ωh(B2)=λhZ2\log_{\omega_h}(B_2)=\lambda_h\mathbb{Z}_2. The integral identification L2=Hom⁡Z2(B2,Z2)L_2=\operatorname{Hom}_{\mathbb{Z}_2}(B_2,\mathbb{Z}_2) then gives

exp⁡2∗(L2)=λh−1Z2ωh,\exp_2^*(L_2)=\lambda_h^{-1}\mathbb{Z}_2\omega_h,

using the Weil-pairing identification of the de Rham target with Q2ωh\mathbb{Q}_2\omega_h. Thus the relative lattice valuation is fixed by the local curve and differential. Since only finitely many local twist classes occur, these valuations are uniformly bounded.

The assumption on the Selmer corank implies that the compact finite Selmer group is torsion and that the discrete finite Selmer group has length s(hx)s(h_x). Rational Poitou–Tate consequently identifies ordinary global H1H^1 with the singular line at 2, and gives ordinary global H2=0H^2=0 rationally. Adding the real invariant line gives the claimed dimension two in degree one. This equals the generic rank, so derived base change of the perfect complex specializes its determinant without a change of rational cohomological rank.

Here is the integral length calculation. Let JJ be the image of the free part of global H1(GQ,S,Th)H^1(G_{\mathbb{Q},S},T_h) in L2L_2, and put i=length⁡(L2/J)i=\operatorname{length}(L_2/J). The compact/discrete Poitou–Tate sequence for the mutually orthogonal Kummer conditions contains

0⟶L2/J⟶Sel⁡2∞(E(hx)/Q)∨⟶H2(GQ,S,Th)⟶⨁q∈SH2(Qq,Th)⟶H0(Q,Ah)∨⟶0.0 \longrightarrow L_2/J \longrightarrow\operatorname{Sel}_{2^\infty}(E^{(h_x)}/\mathbb{Q})^\vee\longrightarrow H^2(G_{\mathbb{Q},S},T_h) \longrightarrow\bigoplus_{q\in S} H^2(\mathbb{Q}_q,T_h) \longrightarrow H^0(\mathbb{Q},A_h)^\vee\longrightarrow0.

with the usual real Tate-cohomology terms inserted. Those terms are killed by 2 and have dimensions bounded by the fixed dimension of TT. Taking lengths and using local duality gives

length⁡H2(GQ,S,Th)=s(hx)−i+∑q∈Slength⁡H0(Qq,Ah)+OE(1).(79)\operatorname{length} H^2(G_{\mathbb{Q},S},T_h)=s(h_x)-i+\sum_{q\in S}\operatorname{length} H^0(\mathbb{Q}_q,A_h)+O_E(1). \tag*{(79)}

This sequence follows from integral Poitou–Tate duality with the finite Kummer conditions and the real Tate-cohomology correction [52]. The free real invariant line is already accounted for by aa; only the bounded real torsion terms enter the error above. No unramified condition replaces the Kummer condition at a bad prime. Global torsion is bounded by its injection into E(hx)(Q2)[2∞]E^{(h_x)}(\mathbb{Q}_2)[2^\infty], whose order is bounded by the fixed local twisting classes. The finite terms at 2 and at fixed bad primes are bounded for the same reason. Passing between ordinary and positive cohomology changes only these bounded real and global torsion terms.

Suppose first that the central value is nonzero. The coordinate of zS,x(0)z_{S,x}(0) in the free global line has valuation

v2(exp⁡2∗zS,x(0))−i+OE(1).v_2(\exp_2^* z_{S,x}(0))-i+O_E(1).

For the inverse determinant, torsion in degree two subtracts its length and torsion in degree one adds its length. This sign can be checked on the complex [Z2→2aZ2][\mathbb{Z}_2 \xrightarrow{2^a} \mathbb{Z}_2] in degrees one and two: its inverse determinant lattice maps to 2aZ22^a\mathbb{Z}_2 in the rational determinant. A vector’s coordinate thus loses aa. Using (79), the two appearances of ii cancel, leaving

v2(ux(0))=v2(exp⁡2∗zS,x(0))−s(hx)−∑q∈Slength⁡H0(Qq,Ah)+OE(1).v_2(u_x(0))=v_2(\exp_2^*z_{S,x}(0))-s(h_x)-\sum_{q\in S}\operatorname{length} H^0(\mathbb{Q}_q,A_h)+O_E(1).

At an active good prime, quadratic inertia acts by −1-1 on the Tate module. Its invariants on AhA_h are therefore exactly E[2]E[2], and taking Frobenius invariants gives length tqt_q. At an unused good prime, reduction identifies the local 2-primary torsion with E(hx)(Fq)[2∞]E^{(h_x)}(\mathbb{F}_q)[2^\infty], of length v2(#E(hx)(Fq))v_2(\#E^{(h_x)}(\mathbb{F}_q)). These unused terms cancel exactly those in (73). The active terms, including the primes of h0h_0, sum to 2w(hx)2w(h_x). All other terms have already been bounded independently of the growing support. This proves (78).

If the central value is zero, reciprocity makes the dual exponential zero. The rational ordinary specialization then satisfies the finite condition at 2, and it satisfies the finite conditions elsewhere automatically. It lies in the rational finite Selmer group, which is zero. Its wedge with the real-place class is therefore zero. The constant-rank determinant specialization proves ux(0)=0u_x(0)=0.

Residual freeness and the lower bound

The central formula expresses D(h)D(h) through the determinant valuation. When the residual representation is an extension of trivial modules, we can bound that valuation directly: the positive complex becomes a free rank-two module in degree one after extension to O[G]\mathcal{O}[G]. The fixed-lattice class then supplies the lower bound without any loss from a growing ramification support.

Lemma 12.4 (Residual concentration). If E[2]E[2] is an extension of two trivial F2\mathbb{F}_2-modules, then there is an isomorphism in the derived category

CS+(T)⊗RO[G]≃O[G]2[−1].C_S^+(\mathbb{T}) \otimes_R \mathcal{O}[G] \simeq\mathcal{O}[G]^2[-1].

Proof. The ring O[G]\mathcal{O}[G] is local, with residue field Ω\Omega obtained by setting 2=02 = 0 and every g=1g = 1. Thus the quadratic characters disappear. Since E[2]E[2] has a filtration with trivial factors, it is enough first to compute the positive residual complex for the trivial representation.

Let KnK_n be the real cyclotomic layer of degree dn=2nd_n = 2^n. The number of finite primes of KnK_n above a fixed SS is bounded with nn: at 22 there is total ramification, and the Frobenius of each fixed odd prime has nonzero image in Γ\Gamma. The 22-ranks of the class groups of KnK_n are also bounded. Let XX be the inverse limit, under norm maps, of their 22-primary class groups. The unique prime above 22 is totally ramified in this tower, so class-field-theoretic control gives

XΓ2n≃Cl⁡(Kn)[2∞].X_{\Gamma^{2^n}} \simeq\operatorname{Cl}(K_n)[2^\infty].

[63] Proposition 3.2.11 and Remark 3.2.12. Ferrero–Washington gives μ(X)=0\mu(X) = 0 for this abelian tower [28]. The Iwasawa structure theorem then makes XX finitely generated over Z2\mathbb{Z}_2, so all its coinvariants have uniformly bounded 22-rank. Passing to the quotient SS-class groups preserves this upper bound.

The signature map of units in KnK_n is surjective. For n≥1n \ge1, let ζ\zeta be a primitive 2n+22^{n+2}th root and put ϵ=1+ζ+ζ−1\epsilon= 1 + \zeta+ \zeta^{-1}. If f1(X)=X2−2f_1(X) = X^2 - 2 and fn+1(X)=fn(X2−2)f_{n+1}(X) = f_n(X^2 - 2), then fnf_n is the minimal polynomial of ζ+ζ−1\zeta+ \zeta^{-1} and fn(−1)=−1f_n(-1) = -1. Hence NKn/Q(ϵ)=−1N_{K_n/\mathbb{Q}}(\epsilon) = -1. Its signature vector has odd augmentation. The embeddings form a regular set for the cyclic 22-group Gal⁡(Kn/Q)\operatorname{Gal}(K_n/\mathbb{Q}), whose group algebra over F2\mathbb{F}_2 is local. A vector with odd augmentation is a unit in this group algebra, so its translates span every signature. For n=0n = 0 the assertion follows from the unit −1-1.

The signature calculation supplies the real-place surjectivity needed for the positive complex. The class-group and support terms are bounded along the tower. We can therefore identify the one cohomological degree whose dimension grows with the layer degree, and then recover the rank after inverting tt.

Kummer theory now determines the cohomological growth. Writing sns_n for the number of finite support places and cnc_n for the 22-rank of the SS-class group, one has

dim⁡H1(GKn,S,μ2)=dn+sn+cn.\dim H^1(G_{K_n,S},\mu_2) = d_n + s_n + c_n.

The real degree-one restriction is surjective by the signature result. In degree two, the Kummer sequence has class-group term of dimension cnc_n and Brauer term. The Brauer invariants at the real and finite support places have their single sum relation. Since a finite support place above 22 is present, restriction of the Brauer term to the real places is surjective and has kernel of dimension sn−1s_n - 1. Thus the degree-two kernel of restriction to infinity is bounded. Restriction is an isomorphism in higher degrees by global duality. The degree-zero restriction is injective. The cohomology of the positive fiber is therefore bounded in every degree except one; its degree-one dimension is dn+OS(1)d_n + O_S(1).

Apply Lemma 12.1 modulo 2. Derived specialization to the nnth layer is specialization modulo t2nt^{2^n}. For a perfect complex over F2[[t]]\mathbb{F}_2[[t]], the universal-coefficient exact sequence shows that a rank-rr cohomology module contributes r2n+O(1)r2^n+O(1) to these dimensions; the torsion terms contribute only O(1)O(1). It follows that after inverting tt the trivial-constituent fiber has dimension one in degree one and vanishes in every other degree. Extensions preserve this concentration, so the fiber for E[2]E[2] has dimension two in degree one. A minimal finite free complex over the local ring O[G]\mathcal{O}[G] has zero residual differentials. The concentration just proved forces all its terms except the rank-two term in degree one to vanish. No denominator is introduced by this exact freeness statement.

Proof of Theorem 3.5. Apply Lemma 12.4 to the single discriminant hh. The fixed-lattice construction and the free complex give 2Cintuh∈O2^{C_{\mathrm{int}}}u_h\in\mathcal{O} with CintC_{\mathrm{int}} depending only on EE. (77) also gives uh∈Λ[1/2]u_h\in\Lambda[1/2]. Since O∩Λ[1/2]=Λ\mathcal{O}\cap\Lambda[1/2]=\Lambda, it follows that v(uh(0))≥−Cintv(u_h(0))\ge-C_{\mathrm{int}}. Analytic rank zero supplies Selmer corank zero by the forward theorem of Gross–Zagier–Kolyvagin. Proposition 12.3 now gives D(h)≥−Cint−ClocD(h)\ge-C_{\mathrm{int}}-C_{\mathrm{loc}}. All constants come from the fixed form, the fixed real period line, or the finitely many local twisting classes at 2N2N.

Transfer to the base

It remains to prove the missing-vertex theorem. Residual freeness gives a single integral family in the reducible case. In the irreducible case we instead need a bounded clearing factor after eliminating the new local blocks. The bound on v2(q2−1)v_2(q^2-1) enters precisely here: the next lemma controls the negative Laurent powers in those inverse blocks at each fixed precision.

Lemma 12.5. Suppose that qq is an added prime and v2(q2−1)≤Lv_2(q^2-1)\le L. At augmentation G→1G\to1, the inverse singular Frobenius block contributed by qq has, modulo each fixed 2M2^M, negative Laurent support bounded in terms of LL and MM. This bound is independent of qq.

Proof. Identify Γ\Gamma with 1+4Z21+4\mathbb{Z}_2 using a fixed generator. If γq=(1+t)αq\gamma_q=(1+t)^{\alpha_q} is the image of arithmetic Frobenius at qq, then

v2(αq)=v2(q2−1)−3v_2(\alpha_q)=v_2(q^2-1)-3

when the generator is 55; changing the generator multiplies αq\alpha_q by a unit. In particular αq≠0\alpha_q\ne0. The singular quotient is represented by a block of bounded size whose determinant is the Euler polynomial in (76). Modulo 22, with z=(1+t)αqz=(1+t)^{\alpha_q}, it is

1+a‾qz+z2.1+\overline{a}_qz+z^2.

If a‾q=1\overline{a}_q=1, its constant coefficient is 11. If a‾q=0\overline{a}_q=0, it is (1+z)2(1+z)^2, whose tt-order is 2v2(αq)+1≤2L−22^{v_2(\alpha_q)+1}\le2^{L-2}. Thus the inverse determinant has uniformly bounded pole order modulo 22. Lift its inverse modulo 2M2^M by a geometric expansion of length at most MM. Each term contains only a bounded number of inverse residual factors, and all numerators have nonnegative powers of tt. The adjugate formula gives the same bound for every entry of the inverse block.

Proof of Theorem 3.1. At every nonzero vertex, analytic rank zero gives c2(E(hx))=0c_2(E^{(h^x)})=0 by the forward rank-zero theorem. Thus Proposition 12.3 applies at every vertex. First assume E[2]E[2] is an extension of trivial modules. Lemma 12.4 and the fixed-lattice construction give 2Cintu∈O[G]2^{C_{\mathrm{int}}}u\in\mathcal{O}[G]. Moreover, the character coordinates of uu are in Λ[1/2]\Lambda[1/2].

Fourier inversion, performed rationally, shows u∈Λ[1/2][G]u \in\Lambda[1/2][G]; intersecting coefficientwise with O[G]\mathcal{O}[G] gives

2Cint⁡u∈Λ[G].(80)2^{\operatorname{Cint}}u \in\Lambda[G]. \tag*{(80)}

The coefficients at t=0t = 0 therefore obey the bounded-degree Boolean congruences of Lemma 11.4. For any fixed precision and sufficiently large bb, there is a nonzero xx for which ux(0)u_x(0) agrees with u0(0)u_0(0) to that precision. The fixed multiplier in (80) affects the required precision but has no dependence on bb.

Now suppose E[2]E[2] is irreducible. At augmentation, represent the positive complex as the old complex, with ramification set excluding QQ, extended by the direct sum of singular blocks at the new primes. The differential is upper triangular with the old complex as subcomplex. The finite-model argument of Lemma 11.6 lifts this model over RR: stabilize the finite free models and lift their graded changes of basis. These lifts are invertible because the augmentation ideal lies in the Jacobson radical. Cancel all additional lifted unit disks before retaining the old-plus-singular grading; their augmented cross terms are zero, so the remaining augmentation is exactly the prescribed block model. Thus no stabilization disk enlarges the old complex. Lemma 11.2 then applies to this block model. All the new blocks are invertible over O[G]\mathcal{O}[G]: modulo its maximal ideal their Frobenius determinants are nonzero in Ω\Omega. Schur elimination leaves a complex of bounded size. Its augmentation is the fixed old complex, and its entries have bounded negative Laurent support modulo each fixed 2M2^M. Under the determinant-line identification, write

u=ηubd,η∈O[G]×,u = \eta u_{\mathrm{bd}}, \qquad\eta\in\mathcal{O}[G]^\times,

where ubdu_{\mathrm{bd}} is the coordinate on this bounded complex and η\eta is the determinant factor of the eliminated blocks. No uniform Laurent bound on η\eta is needed.

The pole bound remains uniform as primes are added. At augmentation the inverse new block is a direct sum of the inverses in Lemma 12.5. At any character its perturbation has entries divisible by 2 and no negative powers of tt. Modulo 2M2^M, the inverse uses a geometric series of length at most MM, independently of the number of blocks. Each product therefore uses a bounded number of inverse entries. Sums of an arbitrary number of such terms cannot decrease the nonarchimedean valuation or the common lower Laurent bound. This is the required bound for Schur elimination.

At t=0t = 0 the old positive complex has rational cohomology only in degree one, of dimension two, by Proposition 12.3 at h0h_0. Its finite torsion and all old local data are fixed. Choose boundary pivots there, leaving those two free coordinates. Their sizes and valuations may depend on h0h_0 but not on bb. Apply the determinant clearing argument of Lemma 11.3 to the wedge of the two bounded-integral cycles a,2zsa, 2zs on the remaining complex. Its allowance for an arbitrary factor η\eta puts the eliminated-block factor into the numerator alone. It yields

d=fu∈O[G],f∈O[G],f0∈Λ,f0(0)≠0.(81)d = fu \in\mathcal{O}[G], \qquad f \in\mathcal{O}[G], \qquad f_0 \in\Lambda,\quad f_0(0) \ne0. \tag*{(81)}

For each fixed MM, the negative Laurent support of fxf_x mod 2M2^M is bounded independently of bb and xx. The clearing factor is a polynomial of bounded degree in the remaining bounded-size matrix, with the pivot denominators cleared by adjugates. Neither the eliminated-block unit, the zeta class nor dd is required to have a uniform bound on its negative Laurent support.

Equation (77) ensures that every uxu_x has no negative tt-powers. Thus all hypotheses of Lemma 11.5 hold for Equation (81). In particular, for each fixed precision and sufficiently large bb, some nonzero xx satisfies the corresponding central congruence between ux(0)u_x(0) and u0(0)u_0(0). The dependence on h0h_0 enters the required precision and dimension, through v(f0(0))v(f_0(0)), and not the eventual valuation comparison.

In either residual case let CC bound the absolute error in (78). The nonzero vertices have v(ux(0))≤B+Cv(u_x(0)) \le B+C. If L(E(h0),1)=0L(E^{(h_0)},1)=0, the central coordinate at zero is zero, and a congruence of precision larger than B+CB+C is impossible. Hence the central value is nonzero. If D(h0)>B+2CD(h_0)>B+2C, then v(u0(0))>B+Cv(u_0(0))>B+C, giving the same contradiction. This proves (3.5) with CE=2CC_E=2C. Only the specialization error determines this final loss; all pivot and pole bounds determine how large a cube is needed.

Heegner points and transfer

We prove the Heegner comparison, the genus and ring bounds, and the interpolation criterion stated in Section 3. The point and its paired functional define one determinant coordinate. Its central value measures the point index after the Selmer and local contributions have been subtracted. Local switches then control its divisors. An outer limit supplies the uniform ring bound when residual irreducibility is unavailable; a universal binary family supplies interpolation.

Height and base Selmer comparisons

Retain the genus and ring data, character sums Pc(e)P_c(e), and lattice indices of Section 3. We first justify the two comparisons used there.

Proof of Proposition 3.2. The explicit Gross–Zagier formula for ring classes [14], Theorem 1.1, pp. 2524–2525 applies. Automorphic induction of the quadratic character gives the product in (6). Discriminant and conductor are prime to NN, and the classical split Heegner hypothesis holds; consequently the shared-prime corrections in the general formula are absent. The unit-index convention is constant in the fields retained here. With a character sum, solving the formula for the height gives exactly c∣k∣c\sqrt{|k|}, as in (6). The forward Gross–Zagier–Kolyvagin theorem gives the rank and finiteness assertion [31, 40].

For (7), both free points are compared with the free line on E(h)(Q)E^{(h)}(\mathbb{Q}). Its regulator cancels from the ratio of their heights, since absolute canonical height is unchanged by twist identification. This height invariance follows from the canonical-height limit and the degree formula for heights under morphisms [49], Chapter IV, Lemmas 4.1 and 4.5–4.6, and Remark 4.12. The remaining variable factor is ∣hk∣L(E(hk),1)\sqrt{|hk|}L(E^{(hk)},1); its infinity sign is that of h∗h_*. Period and lattice changes have bounded 2-valuation. If the rank-one line is instead that of the fixed curve E(hk)E^{(hk)}, its regulator is fixed and the same calculation gives (8).

Proof of Lemma 3.4. Restriction, twisting, and addition or subtraction of conjugates give maps in both directions between the Selmer group over KK and

Sel⁡2∞(E(h0)/Q)⊕Sel⁡2∞(E(h0k)/Q)\operatorname{Sel}_{2^\infty}(E^{(h_0)}/\mathbb{Q}) \oplus\operatorname{Sel}_{2^\infty}(E^{(h_0k)}/\mathbb{Q})

whose composites are multiplication by 2. They induce isogenies on divisible subgroups. On the finite quotients the kernel of either induced map is killed by 2: subtract an element of the divisible subgroup to lift a divisible image, and then use the composite. The generator dimensions are uniformly bounded. Indeed the mod-2 Selmer group over KK is bounded by Kummer cohomology over K(E[2])K(E[2]); this is a quadratic extension of a fixed field with a bounded number of ramified primes. Kummer theory bounds the generator number of the corresponding pro-2 group over the fixed field, and the index-two subgroup bound preserves a uniform bound. The fixed local support includes that of h0h_0. The finite quotient on the displayed product is bounded by hypothesis; therefore its counterpart over KK has bounded length as well. For a finite collection of fields, finiteness of each quotient is enough.

Integral models and ring-class deformation

The determinant argument uses characters of increasing conductor. We construct their cochain limits together with maps to the original cochains. These maps will let us detect limiting Selmer classes by Galois evaluation and choose local switches. Later we retain the same maps through the outer limit needed for the ring bound.

Write T=T2ET = T_2 E and Λ=Z2[[t]]\Lambda= \mathbb{Z}_2[[t]]. For a quadratic squareclass hh, put Th=T⊗χhT^h = T \otimes\chi_h. The imaginary quadratic field KK satisfies the split Heegner hypothesis at 2N2N. We omit the two fields with extra units and, when EE has complex multiplication, its CM field. A quadratic character χ\chi comes from a quadratic twist over Q\mathbb{Q}. We use

Ai=(Z/2iZ)[t]/(ti).A_i = (\mathbb{Z}/2^i\mathbb{Z})[t]/(t^i).

The same constructions work over Ai[G]A_i[G] and Λ[G]\Lambda[G], where GG is a fixed finite elementary abelian 22-group and the additional character has values in GG. Statements uniform in the number of generators of GG will be identified separately; finite-diagram compactness by itself is a statement for fixed GG.

Finite models with their cochain maps

The general finite-model construction is Lemma 11.6. We apply it to the following arithmetic cochains and retain its actual contractions throughout.

For a profinite group and a finite free coefficient module over an Artin local ring AA, continuous inhomogeneous cochains are flat: locally constant functions are the filtered union of the modules of functions on finite clopen partitions, and these modules are finite free. Their reduction is the cochain complex with reduced coefficients. The same observations apply to restrictions, mapping cones, and local conditions given by finite free complexes. In the applications below the groups are Galois groups of totally imaginary number fields or nonarchimedean local fields. Their 22-cohomological dimension and the usual finiteness theorems give the bounded residual cohomology required in Lemma 11.6.

For an inner limit, the quadratic field KK, the active conductor support, the finite group GG, and the number of derivative primes are fixed. The residual representation is E[2]E[2]: all the scalar characters and group-like coefficients become trivial in the residue field. Put F=K(E[2])F = K(E[2]). The number of places of FF in the permitted set SiS_i is bounded even when its auxiliary primes move. Kummer theory bounds H1(GF,Si,F2)H^1(G_{F,S_i},\mathbb{F}_2) by the SiS_i-units modulo squares and Cl⁡(F)[2]\operatorname{Cl}(F)[2]; their dimensions are bounded by the unit rank, #Si\#S_i, and the fixed class-group dimension. Hochschild–Serre for the fixed group Gal⁡(F/K)\operatorname{Gal}(F/K) then bounds the residual global H1H^1 for E[2]E[2]. The global Euler characteristic bounds H2H^2, and H0H^0 is already bounded. Local cohomology and the specified local conditions have bounded residual dimensions, since the local degrees of KK are at most two and the number of places is bounded. Thus the target Selmer cones over KK have uniformly bounded finite-model ranks in this inner limit. This bound may depend on the fixed active support; the stronger outer bound is proved in Lemma 13.15. No rank bound is asserted for cochains over the growing ring-class fields, or for the induced modules in their Shapiro descriptions.

Lemma 13.1 (Limits of finite diagrams). Suppose diagrams of bounded finite free complexes over AiA_i, or over Ai[G]A_i[G], have a common bounded cohomological degree interval and bounded ranks in every degree. Include the chain homotopies and inverses for every asserted identity or equivalence. Along a cofinal subsequence, or a nonprincipal ultrafilter, their matrices converge to the same diagram of perfect complexes over Λ\Lambda or Λ[G]\Lambda[G].

Moreover, the contractions into the original cochains may be retained for the evaluation construction in Lemma 13.7. Adding finitely many new objects or maps does not require changing already chosen models for the old objects. Finite-stage arithmetic operations with unbounded source complexes are permitted when only finitely many of their outputs, and the witnesses to their identities, are retained in the bounded target complexes.

Proof. There are finitely many possible graded ranks. Fix them on an ultrafilter-large set. At a fixed precision jj, all matrix entries belong to the finite ring AjA_j (or Aj[G]A_j[G]), so have unique ultrafilter limits. These limits are compatible as jj varies. Matrix identities, including the homotopy-inverse identities, are finite polynomial identities and pass to the limit. New models and maps may be mapped to old models by their already fixed contractions. Passing to any slower cofinal precision has the same old limits. For the all-sequence evaluation statements below, fix this ultrafilter once and for all, and keep the original contraction at every stage. Later arithmetic diagrams must extend these same stages. Restriction to an ultrafilter-large set and passage to slower cofinal coefficient precision preserve every old evaluation on every old group sequence. Thus later operations use the same stage diagrams and ultrafilter, preserving the arithmetic maps already constructed.

Here is the last assertion in cochain terms. Let DiD_i be an original target cochain complex, with contraction (ιi,πi,hi)(\iota_i,\pi_i,h_i) onto its bounded finite model CiC_i. Perform transfer and scalar weighting at stage ii before applying this contraction. A resulting cycle zi′∈Di1z'_i \in D_i^1 gives zi=πizi′∈Ci1z_i=\pi_i z'_i\in C_i^1, and

zi′−ιizi=d(hizi′).z'_i-\iota_i z_i=d(h_i z'_i).

Thus its relation to the original arithmetic cocycle is retained by the original contraction. If an identity in the target is ui′−vi′=dwi′u'_i-v'_i=dw'_i, retain the vectors πiui′,πivi′,πiwi′\pi_i u'_i,\pi_i v'_i,\pi_i w'_i; the corresponding identity is still exact. For identities involving maps between target complexes, use the transported maps πifiιi\pi_i f_i\iota_i and their contraction homotopies, so that the same assertion includes the required boundary corrections. Local lifts, closed degree-two functionals, and witnesses to specialization, duality and switch identities are treated in the same way. They are finitely many vectors or matrices of bounded size. Their entries, as well as the differentials, therefore have simultaneous limits. Neither a free model of the arithmetic source nor the entire transfer map from that source is included in the limiting diagram. Any precision lost in a finite-stage calculation is accounted for before retaining these vectors; passing to the same slower cofinal precision for the whole diagram preserves all its identities.

The finite models now retain both the original cochains and their comparison maps. We next specify the local conditions on those cochains. The point is to retain the actual Kummer images at every place dividing 2N2N; the determinant comparisons will use their integral orthogonality, not just the rational Selmer ranks.

Integral local conditions and duality

Lemma 13.2 (Integral Kummer local condition). Let FF be a finite extension of a nonarchimedean local field of characteristic zero, and let B/FB/F be any elliptic curve. Put MF=B(F)2∧=lim⁡←nB(F)/2nB(F)M_F = B(F)^{\wedge}_2 = \lim\limits_{\leftarrow n} B(F)/2^nB(F). There is a perfect local condition

UF=MF[−1]⟶RΓ(F,T2B).U_F = M_F[-1] \longrightarrow R\Gamma(F,T_2B).

For every n≥1n \ge1, derived reduction has

H0(UF⊗LZ/2n)=B(F)[2n],H1(UF⊗LZ/2n)=B(F)/2nB(F).H^0(U_F \otimes^{\mathbf L} \mathbb{Z}/2^n) = B(F)[2^n], \qquad H^1(U_F \otimes^{\mathbf L} \mathbb{Z}/2^n) = B(F)/2^nB(F).

Its map in degree zero is the isomorphism onto H0(F,B[2n])H^0(F,B[2^n]), and its map in degree one is the finite Kummer injection. The condition is its own exact orthogonal complement under local Tate duality, for every reduction type and with no hypothesis on B[2]B[2].

Proof. The local analytic description of B(F)B(F) shows that MFM_F is a finitely generated Z2\mathbb{Z}_2-module. Its torsion is the finite group B(F)[2∞]B(F)[2^\infty]. Consequently MFM_F has a free resolution of length at most one. Also H0(F,T2B)=0H^0(F,T_2B)=0, since B(F)[2∞]B(F)[2^\infty] has bounded exponent. The integral Kummer injection into H1(F,T2B)H^1(F,T_2B) therefore defines the displayed morphism using the truncation in degrees at most one of RΓ(F,T2B)R\Gamma(F,T_2B).

Tensor the free resolution of MFM_F with Z/2n\mathbb{Z}/2^n. Its two cohomology groups are MF[2n]M_F[2^n] and MF/2nMFM_F/2^nM_F. The inverse limits of the ordinary Kummer sequences identify their maps as asserted.

For orthogonality, compose cup product and the Weil pairing with the local invariant map. A morphism

MF[−1]⊗LMF[−1]⟶Z2[−2]M_F[-1] \otimes^{\mathbf L} M_F[-1] \longrightarrow\mathbb{Z}_2[-2]

is determined by its homomorphism MF⊗MF⟶Z2M_F \otimes M_F \longrightarrow\mathbb{Z}_2: the possible Tor⁡1\operatorname{Tor}_1 is in degree one and gives no extra degree-zero morphism to this target. The indicated homomorphism vanishes, because the finite Kummer image annihilates itself at every level by local Tate duality. Choose a nullhomotopy in free models. The induced morphism

RΓ(F,T2B)/UF⟶RHom⁡Z2(UF,Z2)[−2]R\Gamma(F,T_2B)/U_F \longrightarrow R\operatorname{Hom}_{\mathbb{Z}_2}(U_F,\mathbb{Z}_2)[-2]

is a quasi-isomorphism. This can be checked after reduction modulo 22: degree one is the perfect pairing of the finite Kummer quotient with the Kummer image, and degree two is dual to B(F)[2]B(F)[2]. Its perfect cone is therefore zero by derived Nakayama. This proves exact orthogonality and also its compatibility with derived reduction. This is precisely the finite-module duality input of [52].

Where the scalar deformation is trivial, extend this local condition by derived scalar extension to AiA_i or Ai[G]A_i[G]. At an unramified good prime use the inflated residue-field complex

Uv=[M→Fr⁡v−1M]in degrees 0,1.U_v = [M \xrightarrow{\operatorname{Fr}_v-1} M] \quad\text{in degrees } 0,1.

Its quotient in full local cochains is the singular local complex. The full local condition is the identity on local cochains, and its orthogonal strict condition is zero. At a derivative prime the conditions used later are the following specified truncations instead. In its split local model write

Lv=D0⊕(Fv⊕Sv)[−1]⊕D2[−2],L_v = D^0 \oplus(F_v \oplus S_v)[-1] \oplus D^2[-2],

where the differential is zero, D0D^0 is dual to D2D^2, and the finite and transverse planes Fv,SvF_v,S_v are each isotropic. Put

Ustr=D0,Urel=D0⊕(Fv⊕Sv)[−1],UF=D0⊕Fv[−1],US=D0⊕Sv[−1].U_{\mathrm{str}} = D^0,\qquad U_{\mathrm{rel}} = D^0 \oplus(F_v \oplus S_v)[-1],\qquad U_F = D^0 \oplus F_v[-1],\qquad U_S = D^0 \oplus S_v[-1].

Then Ustr=UrelU_{\mathrm{str}} = U_{\mathrm{rel}} and each plane condition is its own orthogonal complement. Every displayed condition maps isomorphically onto local H0H^0 and injectively into local H1H^1. Thus they satisfy precisely the detection hypotheses used below. Their finite arithmetic realization and the isotropic-plane nullhomotopies are part of the derivative construction; these truncated conditions are not identified with the full local condition.

For a finite permitted set SS the Selmer complex is, by definition,

CS=Cone⁡(RΓ(GK,S,M)⊕⨁v∈SUv⟶⨁v∈SRΓ(Kv,M))[−1].C_S = \operatorname{Cone}\left(R\Gamma(G_{K,S}, M) \oplus\bigoplus_{v \in S} U_v \longrightarrow\bigoplus_{v \in S} R\Gamma(K_v, M)\right)[-1].

At 2N2N take the Kummer conditions just constructed. Restriction and localization triangles are the triangles of this cone. The finite rings AiA_i and Ai[G]A_i[G] are Frobenius coefficient rings; alternatively the duality maps may be checked after reduction to their residue field. Exact local orthogonality and global duality therefore give

CS≃RHom⁡(CS⊥,Ai)[−3],(82)C_S \simeq R\operatorname{Hom}(C_S^\perp, A_i)[-3], \tag*{(82)}

with the appropriate dual representation. This application uses the orthogonality hypotheses of [52]; the theorem is not being used to assert the existence of a varying-prime limit. Complex places contribute zero Tate complexes. If the character is inverted by the nontrivial automorphism of K/QK/\mathbb{Q}, conjugate transport followed by the Weil pairing identifies the two representations over the same scalar ring. All maps and nullhomotopies in this paragraph are finite diagrams to which Lemma 13.1 applies.

The moving conductor character

The conductor character must preserve the local conditions at 2N2N while making the new local terms invertible after reduction modulo 22 and inversion of tt. The following proposition supplies those local values. Its separate bounds on Tate Frobenius control the contribution of the moving prime when we later specialize to t=0t = 0.

Proposition 13.3 (Ring-class characters with prescribed local values). Fix finitely many split primes of KK above odd rational primes, outside 2N2N, and orient one prime in each conjugate pair. There are distinct split rational primes rir_i avoiding all the fixed data and characters

ξi:Gal⁡(Hri/K)⟶Z/2niZ,ni⟶∞,\xi_i:\operatorname{Gal}(H_{r_i}/K) \longrightarrow\mathbb{Z}/2^{n_i}\mathbb{Z}, \qquad n_i \longrightarrow\infty,

such that ξi\xi_i is surjective on the inertia quotient at rir_i, is zero at the primes above 2N2N, and has odd value at each prescribed oriented prime. We can require ri→1r_i \to1 in Z2\mathbb{Z}_2 and

v2(2+ari(E)),v2(2−ari(E)),v2det⁡(1±Fr⁡ri∣T)≤cE.(83)v_2(2+a_{r_i}(E)), \quad v_2(2-a_{r_i}(E)), \quad v_2\det(1 \pm\operatorname{Fr}_{r_i}\mid T) \leq c_E. \tag*{(83)}

The constant cEc_E is independent of the list and of KK.

Proof. We give the compatibility argument before imposing the Tate condition. Choose prime ideals p1,…,ps\mathfrak{p}_1,\ldots,\mathfrak{p}_s with pairwise disjoint conjugate pairs, including the oriented prescribed primes and the primes above 2N2N, and enough additional split prime ideals to generate Cl⁡(K)\operatorname{Cl}(K). Such additional ideals may avoid any fixed finite set. Put weight wj=1w_j = 1 at a prescribed odd prime and wj=0w_j = 0 at every additional prime and every prime above 2N2N. The conjugate weight is −wj-w_j. Let

R=ker⁡(Zs⟶Cl⁡(K)),(84)R = \ker(\mathbb{Z}^s \longrightarrow\operatorname{Cl}(K)), \tag*{(84)}

choose a basis m(a)m^{(a)} of RR, and choose βa∈K×\beta_a \in K^\times with (βa)=∏jpjmj(a)(\beta_a)=\prod_j \mathfrak{p}_j^{m_j^{(a)}}. Work first over F∞=K(μ2∞)F_\infty=K(\mu_{2^\infty}) and adjoin 2n2^n-th roots of the finitely many βa/βa‾\beta_a/\overline{\beta_a}. Prescribe on these roots the multipliers

ζ2n−∑jmj(a)wj.\zeta_{2^n}^{-\sum_j m_j^{(a)}w_j}.

The minus sign fixes the choice of connecting map in the ring-class sequence and could be reversed throughout. These prescriptions respect every Kummer relation. Indeed, if

∏a(βa/βa‾)ba∈(F∞×)2n,\prod_a(\beta_a/\overline{\beta_a})^{b_a}\in(F_\infty^\times)^{2^n},

take its valuation at a prime above each pj\mathfrak{p}_j of nonzero weight. These odd primes are unramified in F∞/KF_\infty/K. Thus 2n2^n divides ∑abamj(a)\sum_a b_a m_j^{(a)} for each such jj, proving the required compatibility of (13.4). Primes over 2 have weight zero and impose no division by a ramification index. Units impose no additional weighted relation. Kummer duality supplies the prescribed automorphism of the radical extension over F∞F_\infty.

At a rational prime rr split in a sufficiently large finite cyclotomic subfield, the power-residue character of Fr×F_r^\times is surjective onto μ2n\mu_{2^n}. The split ring-class exact sequence is

1⟶(OK/rOK)×/(Z/rZ)×⟶Pic⁡(Z+rOK)⟶Cl⁡(K)⟶1.1 \longrightarrow(\mathcal{O}_K/r\mathcal{O}_K)^\times/(\mathbb{Z}/r\mathbb{Z})^\times\longrightarrow\operatorname{Pic}(\mathbb{Z}+r\mathcal{O}_K) \longrightarrow\operatorname{Cl}(K) \longrightarrow1.

The excluded extra-unit fields are the only source of a unit correction. The first group is Fr×F_r^\times with a principal relation measured by β/β‾\beta/\overline{\beta} at the oriented prime over rr. Consequently (13.4) says exactly that its primitive power-residue character extends to the class group with the specified values wjw_j. More explicitly, the inertia group and the chosen ideal classes present the ring-class group, and the basis of RR lists its additional relations. We have imposed those relations on the inertia character itself; we have not divided by a class-group order to extend a previously fixed character. Thus this construction introduces no denominator, even when the class number has a large 2-part. The class group and the number of prescribed primes change the finite Chebotarev extension, but not the integrality of the character. Since the ring-class extension is unramified at 2N2N, value zero on Frobenius means that the resulting local character is trivial there. Conjugation acts by inversion.

We now show that imposing these finitely many radical conditions cannot force either forbidden Tate trace. In the non-CM case the image of GK(μ2∞)G_K(\mu_{2^\infty}) is an open subgroup of SL⁡2(Z2)\operatorname{SL}_2(\mathbb{Z}_2), by the fixed-prime open-image theorem and the cyclotomic determinant identity [62]: the image is the intersection of the open image of GKG_K with the determinant-one subgroup. Its index in the corresponding fixed-EE image changes by at most two when KK changes. Its commutator subgroup contains a fixed open subgroup UEU_E of SL⁡2(Z2)\operatorname{SL}_2(\mathbb{Z}_2). One may see uniformity by starting with a principal congruence subgroup in the fixed image: every index-two subgroup contains its squares, and the commutators of the resulting fixed congruence subgroup are open. Because the radical extension over F∞F_\infty is abelian, these commutators act trivially on it. Hence every permitted Tate coset contains a translate of UEU_E.

For completeness, in the CM case let MM be the CM field. The image over KM(μ2∞)KM(\mu_{2^\infty}) contains a fixed open subgroup of the norm-one Cartan; the index changes by a bounded factor, as [KM:Q]≤4[KM:\mathbb{Q}]\le4. Choose γ∈GKM\gamma\in G_{KM} with χcyc(γ)=54=625\chi_{\mathrm{cyc}}(\gamma)=5^4=625. This is possible uniformly: the cyclotomic image of GKMG_{KM} has index at most four in Z2×\mathbb{Z}_2^\times, so contains fourth powers. On the radical Galois group, conjugation by γ\gamma is raising to 625, because all the radicands lie in KK. On the Tate image over KMKM, conjugation is trivial. Therefore

γuγ−1u−625,u∈GKM(μ2∞),\gamma u\gamma^{-1}u^{-625},\qquad u\in G_{KM(\mu_{2^\infty})},

fixes every prescribed radical and acts on TT as ρT(u)−624\rho_T(u)^{-624}. Raising to the fixed nonzero power 624 carries an open subgroup of the one-dimensional norm-one Cartan onto an open subgroup. This proves the required uniform kernel statement also in the CM case. The open Cartan image used here is the CM part of the usual ℓ\ell-adic image theorem [62], Chapter IV, §2.2, Remark, p. IV-13.

On a coset of an open subgroup of SL⁡2\operatorname{SL}_2, trace is not identically 2 or −2-2. The same holds on a coset of an open norm-one Cartan subgroup; on the other Cartan-normalizer component trace is zero. The relevant determinant-one sets are compact and have finitely many cosets modulo the fixed open subgroup. Choose in each coset an element whose trace is neither forbidden value. The largest of the finitely many resulting valuations is a constant depending only on EE.

Finally restrict the prescribed radical automorphism and such a Tate lift to a finite Galois extension, including as many roots of unity as required. Chebotarev gives infinitely many rational primes with this Frobenius class; choose the place over the prime to realize the chosen representative. They split in KK and have arbitrarily high prescribed congruence to 1. Since det⁡(1±Frob⁡r)=1±ar+r\det(1 \pm\operatorname{Frob}_r) = 1 \pm a_r + r, a congruence precision larger than the fixed trace bound gives all of (13.3). All these conditions concern a finite extension at each stage.

Choose nin_i large enough that 1+t1+t has order dividing 2ni2^{n_i} in A×A^\times, and put Ψi=(1+t)ξi\Psi_i=(1+t)^{\xi_i}. For example ni≥2in_i \ge2i is sufficient. Orient the inertia generator to act by 1+t1+t; the prescribed split Frobenius exponents remain odd in the limit. Use global cochains unramified outside 2N2N, rir_i, the active conductor primes and the derivative primes already retained. At 2N2N use the Kummer conditions above and elsewhere outside the conductors use the unramified condition. Reduction modulo tt, with the unramified condition restored at rir_i, gives the ordinary fixed-field complex; retain its comparison map at every finite stage.

Lemma 13.4 (Acyclic relaxed local complexes). For a primitive character constituent, let CC denote the limiting Selmer complex with full conditions at rr and at its active good conductor primes, and the prescribed Kummer, unramified or derivative conditions elsewhere. The limiting full local complexes are acyclic over every height-one residue field of Λ\Lambda of characteristic zero. At (2), with residue field Ω=F2((t))\Omega= \mathbb{F}_2((t)), the rr-complex is acyclic, as are the complexes at active split primes with odd prescribed Frobenius exponent of the deformation character and at active primes qq with tq=0t_q=0. At each of these acyclic relaxed places, the full and orthogonal strict conditions agree on the indicated test. If every relaxed place is acyclic at that test and the remaining local conditions are self-dual, global duality makes the Selmer complex self-dual. The Selmer complex has no global invariants on these tests.

Proof. Use tame inertia and unramified Frobenius, or the Hochschild–Serre complex for these two procyclic directions. At rr, inertia minus one is multiplication by tt times a unit. It is invertible on all the indicated fields except the characteristic-zero fiber t=0t=0. There, r→1r \to1, and the two remaining Frobenius differentials have nonzero determinant by (13.3), including either sign of the quadratic twist. The bound also ensures that the integral local torsion at this central fiber has bounded length.

At an active odd conductor prime, inertia of the quadratic character acts by −1-1. Its differential is thus −2-2 and is invertible in characteristic zero. In characteristic two the quadratic character disappears. At a split prime the Frobenius action is zBzB, where B∈GL⁡2(F2)B \in\operatorname{GL}_2(\mathbb{F}_2) and z=(1+t)az=(1+t)^a has odd a∈Z2a \in\mathbb{Z}_2. Its coefficient of tt is one, so zz is nonconstant. No nonzero polynomial over the finite constant field vanishes at zz. Thus both Frobenius complexes, with operators zB−1zB-1 and q−1zB−1q^{-1}zB-1, are invertible over Ω\Omega; here q=1q=1 in the residue field. No irreducibility assumption is used.

If tq=0t_q = 0, the rational residual Frobenius BB has order three. At a split place the operator is again zB−1zB - 1, invertible whether zz is nonconstant or z=1z = 1. At an inert place the ring-class Frobenius is trivial, since the ideal (q)(q) is principal, and the Tate Frobenius is B2B^2, which also has no eigenvalue one. These observations give the additional tq=0t_q = 0 assertion.

The orthogonal full and strict conditions agree at each place where full local cochains are acyclic. When this holds at every relaxed place and the remaining local conditions are self-dual, (82) gives global self-duality. Global invariants in characteristic two are excluded by the nontrivial rr-inertia scalar. In characteristic zero the same argument works unless the scalar is trivial; in that case T⊗Q2T \otimes\mathbb{Q}_2 over GKG_K is absolutely irreducible. For non-CM curves this follows from the open image, and for CM curves from the open Cartan and its nontrivial normalizer component, since KK is not the CM field. Lemma 13.7 below realizes these actions on the limiting complex as well. On the self-dual tests, duality pairs degrees one and two.

The Heegner determinant and its central value

The point index is not itself the quantity transferred across a growing family. Each new conductor prime changes the local Selmer terms as well as the point. We combine these changes in a determinant coordinate. Its central valuation will be twice the point index, less the finite Selmer length and the conductor contribution. This formula reduces the index estimates to lower bounds for the determinant coordinate.

Retain a primitive genus or ring instance from Section 3, with point Pc(e)P_c(e) over KK. Use the conductor characters just constructed, taking ni≥2in_i \ge2i, and the representations TχeΨiT\chi_e\Psi_i. Retain the same auxiliary primes and the same fixed inner ultrafilter, now denoted Uin\mathcal{U}_{\mathrm{in}}.

The Selmer complex CC is a coefficientwise limit of the corresponding finite free cochain models along Uin\mathcal{U}_{\mathrm{in}}. It has the integral Kummer condition at 2N2N, the full condition at rir_i and the active good conductor primes, and the unramified condition at all other permitted finite places. Here the full condition means that no restriction is imposed on local cochains. Section 13.2 and Lemma 13.4 constructed the local models, their duality maps, and the comparison at t=0t = 0. We use these concrete complexes and maps; cohomologically equivalent complexes without the comparison maps would not suffice for the later prime choices. Over Frac⁡(Λ)\operatorname{Frac}(\Lambda), the modified full local complexes are acyclic, so the full conditions agree with their orthogonal strict conditions. Global duality, followed by conjugate transport and the Weil pairing, therefore gives a perfect pairing

H1(C⊗ΛFrac⁡(Λ))×H2(C⊗ΛFrac⁡(Λ))⟶Frac⁡(Λ).H^1(C \otimes_{\Lambda} \operatorname{Frac}(\Lambda)) \times H^2(C \otimes_{\Lambda} \operatorname{Frac}(\Lambda)) \longrightarrow\operatorname{Frac}(\Lambda).

Here conjugation in K/QK/\mathbb{Q} inverts the ring-class character. These are the pairing and identification supplied by (82) and Lemma 13.4.

Fix the single integer multiplier LL of Lemma 13.12. It depends on the curve, parametrization and fixed local types, and clears descent and local Kummer ambiguities for the complete conductor. In particular its valuation does not grow with the number of primes. The following construction and formulas include that multiplier throughout.

At each finite stage transfer the Kummer class of ycriy_{cr_i} from HcriH_{cr_i} to KK with the specified scalar coefficients, using LycriL y_{cr_i}. Complete the finite coset sum before contracting its target cocycle and local Kummer lifts into the models over KK. The resulting cycles PiP_i, with their contraction witnesses, give P∈H1(C)P \in H^1(C) by Lemma 13.1. Local Kummer conditions at 2N2N are preserved because Ψi\Psi_i is trivial there. At the center of the iith finite model, the norm relation has the factor

bi=ari−χe(Frob⁡ri)−χe(Frob⁡r‾i),ri=rir‾i,b_i=a_{r_i}-\chi_e(\operatorname{Frob}_{r_i})-\chi_e(\operatorname{Frob}_{\overline{r}_i}),\qquad r_i=r_i\overline{r}_i,
Pi∣t=0=εibiκ(LPc(e)).(85)P_i\big|_{t=0}=\varepsilon_i b_i\kappa(LP_c(e)). \tag*{(85)}

where κ\kappa denotes the Kummer class in the central comparison and εi\varepsilon_i is a unit; the equality is taken modulo the finite coefficient precision. Since χe\chi_e is defined over Q\mathbb{Q}, its values at the conjugate Frobenius elements agree; explicitly, bi=ari−2χe(ri)b_i=a_{r_i}-2\chi_e(r_i). To retain the central identity at the cochain level, let BiB_i be the reduction of a fixed finite model of the ordinary Kummer complex over KK, and let βi:Bi→Ci/(t)\beta_i:B_i\to C_i/(t) be its comparison map to the relaxed central complex. Choose a cycle qiq_i representing κ(LPc(e))\kappa(LP_c(e)). The finite norm relation gives a boundary witness viv_i in the target model such that

Pi mod t−εibiβi(qi)=dvi.P_i\bmod t-\varepsilon_i b_i\beta_i(q_i)=dv_i.

Retain βi,qi,vi\beta_i,q_i,v_i, and the target contraction homotopies on the same stages and at the same coefficient precision as PiP_i. Retain these units in the same ultrafilter UinU_{\mathrm{in}} as all the comparison maps. Then b=lim⁡Uinbib=\lim_{U_{\mathrm{in}}}b_i has bounded valuation by Equation (83), and ε=lim⁡Uinεi\varepsilon=\lim_{U_{\mathrm{in}}}\varepsilon_i is a unit. Thus P∣t=0=εbκ(LPc(e))P|_{t=0}=\varepsilon b\kappa(LP_c(e)), with b≠0b\ne0. The special complex differs from the ordinary Kummer complex only by the active-prime relaxed quotients and the limit of the singular quotient at the single moving prime rir_i, the latter of bounded length. Inflation from the complexes omitting rir_i gives this comparison. All modified local complexes are rationally acyclic at the center, so pairings agree there as well.

If the product has a simple zero, its rational special fiber has one-dimensional cohomology in degrees one and two, and PP specializes nontrivially by Gross–Zagier. The generic dimensions are at most these special dimensions. Moreover, the long exact sequence for multiplication by tt shows that H1(C[1/2])[t]=0H^1(C[1/2])[t]=0, since the special H0H^0 vanishes. A torsion class that disappeared over the generic field would be killed by a power of tt after localization at (t)(t); hence the nonzero special class cannot disappear. Thus the generic ranks are one in degrees one and two, PP spans H1H^1, and the rational rank is constant at t=0t=0. If only base Selmer corank one is known, the same dimension bound gives generic ranks at most one; a zero generic point is allowed.

Definition 13.5. Choose an integral basis of det⁡Λ−1C\det_\Lambda^{-1}C. In generic rank one, the element formed by PP in H1H^1 and the functional ⟨P,⋅⟩\langle P,\cdot\rangle on H2H^2 determines a scalar u(C,P)∈Frac⁡(Λ)u(C,P)\in\operatorname{Frac}(\Lambda) in that basis. Put u=0u=0 if P=0P=0 or the generic rank is zero. Integral changes of determinant basis multiply uu by a unit.

In the simple-zero case, constancy of the rational cohomology rank at t=0t=0 makes uu regular in the local ring Λ(t)\Lambda_{(t)}. Its value u(0)∈Q2u(0)\in\mathbb{Q}_2 is therefore already defined. This specialization takes place at (t)(t); the stronger assertion u∈Λ[1/2]u\in\Lambda[1/2] will follow from the divisor estimates below.

The determinant has a simple integral interpretation. On a rank-one free Selmer line, the point and its paired functional each contribute the point’s index. Torsion in degree two subtracts its length from the coordinate in the inverse determinant lattice. For example, the complex [Z2→2aZ2][\mathbb{Z}_2\xrightarrow{2^a}\mathbb{Z}_2] in degrees one and two has inverse determinant lattice mapping to 2aZ22^a\mathbb{Z}_2 in the rational determinant. The coordinate of a fixed rational tensor therefore loses aa in valuation. The next lemma carries out this calculation with the actual local Kummer conditions. It also compares the Selmer length over KK with those of the two rational twists.

Lemma 13.6 (Central determinant valuation). For a simple-zero instance,

v(u(0))=2j(Pc(e))−length⁡Sha⁡(E(e)/K)[2∞]−∑q∣c∑v∣qtv+OE(1),v(u(0)) = 2j(P_c(e)) - \operatorname{length} {\operatorname{Sha}}(E^{(e)}/K)[2^\infty] - \sum_{q\mid c}\sum_{v\mid q} t_v + O_E(1),
tv=dim⁡F2E[2]Fr⁡v.(86)t_v = \dim_{\mathbb{F}_2} E[2]^{\operatorname{Fr}_v}. \tag*{(86)}

Furthermore,

length⁡Sha⁡(E(e)/K)[2∞]+∑q∣c∑v∣qtv=s(e)+s(ek)+∑q∣ktq+2∑q∣ctq+OE(1).(87)\operatorname{length} {\operatorname{Sha}}(E^{(e)}/K)[2^\infty] + \sum_{q\mid c}\sum_{v\mid q} t_v = s(e) + s(e^k) + \sum_{q\mid k} t_q + 2\sum_{q\mid c} t_q + O_E(1). \tag*{(87)}

The constants include the one fixed class multiplier and the bounded local contribution at the moving prime rir_i.

Proof. The ordinary integral Kummer complex over KK is self-dual. Its H1H^1 is the compact Selmer module, and the torsion in H2H^2 has the length of the finite quotient of the discrete Selmer group by its divisible subgroup. This follows by derived base change to Q2/Z2\mathbb{Q}_2/\mathbb{Z}_2: the local complexes give exactly the discrete Kummer conditions. In the present simple-zero case that finite quotient is Sha⁡(E(e)/K)[2∞]{\operatorname{Sha}}(E^{(e)}/K)[2^\infty]. Duality pairs the free parts in degrees one and two perfectly. Torsion in degrees one and three costs a bounded amount, by global torsion and duality. The uniform torsion bound here comes from a fixed nonidentity Tate scalar acting trivially on every ring-class field in the construction: its scalar minus one annihilates that torsion. Lemma 13.8 constructs this scalar, and the descent argument of Lemma 13.12 uses the same bound.

At an active odd conductor place inertia acts by minus identity. All integral H1H^1 is Kummer, and the relaxed quotient contributes only H2(Kv,Te)H^2(K_v,T^e) in degree two. Its length is tvt_v, by local duality and the fixed 2-torsion. At the moving prime rir_i the contribution is bounded by (83). The generic pairings specialize to the ordinary Kummer pairing because the modified local complexes are rationally acyclic at the center. Thus the free determinant tensor has valuation twice the point index, whereas torsion in degree two contributes negative length to the inverse determinant. Together with (85), this proves (86). The specialization is at constant rational cohomology rank, so no specialization torsion is being substituted for the point.

For (87), apply the isogeny invariance of the BSD quotient to quadratic Weil restriction and E(e)×E(ek)E^{(e)} \times E^{(e^k)}[72] (Theorem 2.1 and the preceding discussion). All the groups in this comparison are finite apart from the known rank-one lattices; no BSD equality is assumed. The forward and reverse isogenies have composites multiplication by 2. Consequently the rank-one lattice indices, height ratios, torsion ratios and period ratios contribute bounded 2-powers. For periods, the pullback indices of Néron differentials at 2 are bounded by those composites; real kernels and component ratios are bounded as well.

The remaining terms are the Tamagawa numbers. A ramified quadratic twist of good reduction at an odd prime qq has type I0∗I_0^* and component number one plus the number of roots of its reduced auxiliary cubic [1] (Theorem 4.1, tbl:4 and proof, Case 3). To identify this number, write a good integral model as y2=f(x)y^2=f(x), retaining the quadratic term, and the twisting parameter as d=πud=\pi u. The auxiliary cubic is uˉ3fˉ(T/uˉ)\bar{u}^3\bar{f}(T/\bar{u}); it is separable and its roots correspond to the nonzero rational two-torsion points. Thus the component number is #E[2]Fr⁡q\#E[2]^{\operatorname{Fr}_q} and its 2-valuation is tqt_q. This argument also applies in residue characteristic 3. Its connected reduction is unipotent. Some inertia element acts by −1-1 on the twisted 2-adic representation, so its local 2-primary torsion is precisely its Frobenius-fixed 2-torsion. Over an unramified extension the same formula holds with the Frobenius of the enlarged residue field. At unramified or split places, Weil-restriction component numbers are the products over v∣qv \mid q. At a prime q∣kq \mid k outside 2N2N, the curve over KK has good reduction and its Weil restriction has connected special fiber. Indeed, Weil restriction of its Néron model is the Néron model of the restriction of the curve [6]. Its special fiber has the original connected elliptic fiber as quotient, with connected vector-group layers from ramification. Exactly one rational twist has the ramified component factor. At a conductor prime q∣cq \mid c, the two rational twists give a combined valuation 2tq2t_q, and the corresponding contribution over KK is ∑v∣qtv\sum_{v\mid q} t_v. All places above 2N2N have bounded local contributions. These are precisely the terms of Equation (87).

In a simple-zero genus instance, the fixed partner absorbs the terms involving h∗h_*, while c=1c=1 and k=hh∗k=hh_*. The displayed formulas therefore identify

v(u(0))=2j(P1(h∗))−2w(h)−s(h)+OE,h∗(1).v(u(0))=2j(P_1(h_*))-2w(h)-s(h)+O_{E,h_*}(1).

In a simple-zero ring instance with ω(k)≤a\omega(k)\leq a, the discriminant term is bounded and the conductor term is 4w(h)4w(h), giving

v(u(0))=2j(P∣h∣(h))−4w(h)−s(h)−s(hk)+OE,a(1).v(u(0))=2j(P_{\lvert h\rvert}(h))-4w(h)-s(h)-s(hk)+O_{E,a}(1).

The ring identity also applies to the interpolation families in which an added nonsplit prime has tq=0t_q=0; such a prime contributes no weight. The all-split hypothesis is needed for the uniform ring lower bound. These formulas explain both the lower-bound statements and the normalization in Heegner interpolation. To prove the lower bounds, we must show that uu has no negative divisor away from (2)(2) and has a uniformly bounded negative divisor at (2)(2) in the stated cases. We will construct integral local switches that preserve its determinant valuation, and use inner detection to choose switches lowering excess Selmer rank. The uniform ring estimate will require an additional characteristic-zero limit; the universal binary family will instead require a bounded clearing factor after the new local blocks have been removed.

The main intermediate estimate is

vp(u)≥0(ht⁡p=1, p≠(2)),v(2)(u)≥−OE,h∗(1)in genus data with irreducible E[2],v(2)(u)≥−OE,a(1)in ring data with ω(k)≤a and all active primes split.(88)\begin{aligned} v_{\mathfrak p}(u)&\geq0 &&(\operatorname{ht}\mathfrak p=1,\ \mathfrak p\ne(2)),\\ v_{(2)}(u)&\geq-O_{E,h_*}(1) &&\text{in genus data with irreducible }E[2],\\ v_{(2)}(u)&\geq-O_{E,a}(1) &&\text{in ring data with }\omega(k)\leq a\text{ and all active primes split.} \tag*{(88)} \end{aligned}

To construct the switches used in these estimates, we first retain enough Galois evaluation data to select their derivative primes.

Evaluation and the exact kernel

The determinant estimates require switches that detect the excess Selmer dimension at a height-one test. To choose switching primes, we must still detect a nonzero limiting Selmer class by Galois evaluation. The next two lemmas first retain that detection under coefficient specialization, then restrict it to sequences acting trivially on the full Tate module, all ring-class fields, and the quadratic characters in use.

Lemma 13.7 (Evaluation on arbitrary Galois sequences). Fix KK and a sequence of finite cochain constructions above. Keep the contraction maps into the original global cochains. Let ΓK=∏iGK\Gamma_K=\prod_i G_K and Γ=ΓK⋊⟨τ⟩⊂∏iGQ\Gamma=\Gamma_K\rtimes\langle\tau\rangle\subset\prod_i G_{\mathbb{Q}}, with simultaneous complex conjugation τ\tau. Thus ΓK\Gamma_K has index two in Γ\Gamma; the larger unrestricted product of rational Galois groups is not used for induction. The matrix limit defines a coefficient action of ΓK\Gamma_K on Λ2\Lambda^2. For every field LL receiving a map from Λ\Lambda, there is a natural injection

H1(C⊗ΛL)⟶Habs1(ΓK,L2),H^1(C\otimes_{\Lambda}L)\longrightarrow H^1_{\mathrm{abs}}(\Gamma_K,L^2),

where the right side denotes abstract crossed-homomorphism classes. Here CC may be the global complex or a Selmer complex whose local conditions contain all local degree-zero invariants and inject into local H1H^1. The same statement holds for the induced representation of Γ\Gamma.

The evaluation maps and their degree-two cochain identities exist for every group sequence and commute with coefficient extension.

Proof. Let CiC_i be a finite model and let ιi\iota_i be its chosen map to the original global cochains, using the projection from the Selmer cone when appropriate. For every g=(gi)g=(g_i) and h=(hi)h=(h_i) define matrices

ei0:Ci0→Ai2,eg,i1:Ci1→Ai2,eg,h,i2:Ci2→Ai2e_i^0:C_i^0\to A_i^2,\qquad e_{g,i}^1:C_i^1\to A_i^2,\qquad e_{g,h,i}^2:C_i^2\to A_i^2

by evaluating ιi\iota_i in degrees zero, one, and two. Their source ranks are fixed and their entries belong to AiA_i. Thus each has a coefficientwise ultrafilter limit, for every choice of g,hg,h. The same fixed ultrafilter defines these limits for all g,hg,h. Likewise ρ(g)=lim⁡iρi(gi)\rho(g)=\lim_i\rho_i(g_i) is a representation. The original cochain identities imply

eg1d=(ρ(g)−1)e0,(89)e_g^1d=(\rho(g)-1)e^0, \tag*{(89)}
eg,h2d=ρ(g)eh1−egh1+eg1.(90)e_{g,h}^2d=\rho(g)e_h^1-e_{gh}^1+e_g^1. \tag*{(90)}

All identities pass to the limit because their matrix expressions have finitely many terms. A cycle x∈C1⊗Lx\in C^1\otimes L consequently gives the crossed homomorphism g↦eg1(x)g\mapsto e_g^1(x), and a boundary gives a coboundary.

We prove injectivity in a way that also controls base change. At each finite stage let k=F2k=\mathbf{F}_2 be the residual field. Choose a space of representatives for residual H1H^1. Evaluate pairs (c,m)(c,m), where cc is in this space and m∈k2m\in k^2, by bc(g)−(ρ(g)−1)mb_c(g)-(\rho(g)-1)m. The intersection of the kernels of all these evaluations consists precisely of pairs (0,m)(0,m) with mm an invariant. Since the vector space is finite dimensional, a list of at most dim⁡H1+2\dim H^1+2 elements already has this intersection. For these elements evaluation is a chain map

Ci⟶Di=[Ai2→((ρi(gj)−1))j(Ai2)d]C_i\longrightarrow D_i=\left[A_i^2\xrightarrow{\left((\rho_i(g_j)-1)\right)_j}(A_i^2)^d\right]

in degrees zero and one, inducing an isomorphism on residual H0H^0 and an injection on residual H1H^1. For Selmer complexes this uses the exact sequence of (13.1): the indicated local degree-zero isomorphisms give H0(Ci)=Hglob0H^0(C_i)=H^0_{\mathrm{glob}} and H1(Ci)↪Hglob1H^1(C_i)\hookrightarrow H^1_{\mathrm{glob}} residually.

Retain these matrices and their chosen group-element sequences. The residual global and local complexes, and the local conditions, have no negative cohomology. The cone definition therefore gives Hn(C⊗k)=0H^n(C\otimes k)=0 for n<0n<0. Put Q=Cone⁡(C→D)Q=\operatorname{Cone}(C\to D). The long exact sequence gives Hn(Q⊗k)=0H^n(Q\otimes k)=0 for n<−1n<-1; its groups in degrees −1-1 and 00 vanish because the detecting map is an isomorphism on H0H^0 and injective on H1H^1. Any H3(C⊗k)H^3(C\otimes k) contributes in degree two of this cone, so causes no negative-degree obstruction. Successively cancel the unit differential blocks of QQ. This gives a homotopy-equivalent bounded free complex starting in degree one. For any Λ\Lambda-algebra LL, its ordinary tensor product computes Q⊗ΛLLQ\otimes_\Lambda^L L and still starts in degree one; no flatness is needed. Thus the long exact sequence makes H1(C⊗L)→H1(D⊗L)H^1(C\otimes L)\to H^1(D\otimes L) injective. A crossed cocycle that is a coboundary on all of ΓK\Gamma_K is in particular a coboundary on the detecting list, proving the desired injection. For induction the same proof has coefficient rank four and the detecting bound is dim⁡H1+4.□\dim H^1+4. \quad\square

Lemma 13.8 (The exact common kernel). *In the notation of Lemma 13.7, let HH be the group of sequences each of whose entries acts trivially on the full Tate module, on all ring-class fields of KK, and on the quadratic characters in use. Restriction from the crossed classes in that Lemma to HH is injective at every characteristic-zero test. It is also injective at the residual (2)(2) test. The characteristic-zero annihilator needed for this assertion can be chosen with a fixed finite 22-valuation depending only on EE, also as KK varies.

Proof. The Tate image contains an open subgroup of scalar homotheties, both in the CM and non-CM cases. Choose once and for all g∈GQg \in G_{\mathbb{Q}} with Tate action u1u1, where u∈1+4Z2u \in1+4\mathbb{Z}_2 and u≠1u \ne1. Its square belongs to every quadratic subgroup. Put

z=g2τg2τ−1.z = g^2\tau g^2\tau^{-1}.

The generalized dihedral property of every ring-class extension implies that zz is ring-class trivial. It is also trivial on every quadratic character, and its Tate action is the fixed scalar u4u^4. For every sequence in ΓK\Gamma_K, its commutator with the constant sequence zz is in the exact group HH, since its Tate commutator and all its abelian character images are trivial. Thus zz is central in ΓK/H\Gamma_K/H and acts on the coefficients by u4u^4.

Here the elementary central-scalar argument suffices. If a crossed cocycle bb is defined on a group with such a central element, comparison of b(zg)b(zg) and b(gz)b(gz) gives

(u4−1)b(g)=(g−1)b(z).(u^4-1)b(g)=(g-1)b(z).

In characteristic zero this makes bb a coboundary. Inflation–restriction then gives injectivity on HH. The valuation of u4−1u^4-1 is fixed.

In characteristic two choose, at each stage, inertia at rir_i mapping onto the chosen generator of ξi\xi_i. Its Tate action is trivial and its ring-class images commute, so the resulting sequence is central in ΓK/H\Gamma_K/H and acts on MM by 1+t1+t. Its scalar minus one is invertible in F2((t))\mathbb{F}_2((t)).

For the induced representation WW, first restrict to ΓK\Gamma_K. There W=M⊕MτW=M\oplus M^\tau, and this inertia sequence acts on the summands by 1+t1+t and (1+t)−1(1+t)^{-1}. Hence WΓK=0W^{\Gamma_K}=0. Inflation–restriction for the index-two inclusion gives an injection H1(Γ,W)→H1(ΓK,W)H^1(\Gamma,W)\to H^1(\Gamma_K,W), even in characteristic two. Apply the central-scalar calculation separately to the two summands to obtain injection on restriction to HH. The same argument works in characteristic zero with the fixed scalar u4u^4. Throughout, HH is defined by exact actions at every stage.

Lemma 13.9 (Irreducibility on the characteristic-zero tests). On an inner characteristic-zero test where Ψ2≠1\Psi^2\ne1, the four-dimensional representation induced from TχΨT\chi\Psi is absolutely irreducible. If Ψ2=1\Psi^2=1 on an inner test, it splits as two inequivalent absolutely irreducible quadratic twists.

Proof. The two induced summands are distinguished by rr-inertia, whose scalars are Ψ\Psi and Ψ−1\Psi^{-1}. On either summand, multiplying the Tate matrices by scalars does not alter invariant subspaces. The Tate representation restricted to GKG_K is absolutely irreducible under the exclusions already specified. These facts give absolute irreducibility of the induction when the two inertia characters differ.

If Ψ2=1\Psi^2=1, extension across conjugation gives the two quadratic twists. They are inequivalent, since a quadratic self-twist of the Tate representation here would make its restriction to GKG_K reducible over an algebraic closure. In the CM case this would force KK to be the CM field, which was excluded.

Lemma 13.10 (Simultaneous finite Chebotarev realization). For any element uu of an exact kernel in Lemma 13.8, derivative primes can be chosen, at increasing finite precision, whose rational Frobenius is τu\tau u on all retained data. Their finite localization is evaluation on (τu)2(\tau u)^2. The assertion is compatible with any fixed finite list of previous derivative operations. Proof. At one Artin stage, a coordinate of a cochain in the image of a finite model is a locally constant function. The finitely many coordinates being used factor through one finite quotient of the absolute Galois group. Enlarge it to contain the Tate action at the required precision, the finitely many ring-class fields and quadratic characters currently in use, and all old finite data. Chebotarev realizes the conjugacy class of τu\tau u on this finite quotient, with a chosen place realizing the desired representative [48]. It gives a rational prime inert in KK, outside the old finite set. Because uu is exactly Tate-trivial, its Frobenius tends to ρT(τ)\rho_T(\tau); in particular aℓ→0a_\ell\to0 and ℓ→−1\ell\to-1. Because uu is exactly ring-class trivial, the square Frobenius on the KK-prime is the identity on every retained ring-class field. The unramified local coordinate is therefore the stated Frobenius-square evaluation.

Repeat at each finite stage with increasing precision. All conditions remain finite, and no density bound or prime-size bound is required. Previously imposed finite diagrams are unchanged.

In induced-module notation, restriction to the exact kernel is additive. For a crossed cocycle bb and an exact-kernel element uu,

b((τu)2)=(1+τ)b(u).b((\tau u)^2)=(1+\tau)b(u).

Indeed τ2=1\tau^2=1, uu acts trivially on the coefficients, and the cocycle identity cancels the two occurrences of b(τ)b(\tau). Projection to either induced summand identifies im⁡(1+τ)\operatorname{im}(1+\tau) with a two-dimensional coefficient module, also in characteristic two.

The local switch and its integral determinant

Fix a complex conjugation τ\tau and write CτC_\tau for its action on TT. The next two Lemmas construct the integral local switches and the classes that pass through them. Their finite-level formulas are needed before applying the limit constructions above.

Lemma 13.11 (The split local model.) Let a sequence of inert good primes ℓ\ell have rational Frobenius lifts tending on TT to a fixed complex conjugation CτC_\tau. At the unique prime of KK above ℓ\ell, the limiting local complex has

H0=M,H1=F⊕S=M⊕M,H2=M,(91)H^0=M,\qquad H^1=F\oplus S=M\oplus M,\qquad H^2=M, \tag*{(91)}

with zero differentials in a free split model. Here M=T⊗ΛM=T\otimes\Lambda with the relevant scalar coefficient structure. The two degree-one coordinates of a cocycle are

f(c)=c(γ2),s(c)=c(σ),(92)f(c)=c(\gamma^2),\qquad s(c)=c(\sigma), \tag*{(92)}

where σ\sigma is an oriented pro-22 tame generator. The plane conditions F={s=0}F=\{s=0\} and S={f=0}S=\{f=0\} include H0H^0 and exclude H2H^2. Each is its own orthogonal complement for conjugate-Weil duality. The strict condition H0H^0 and the relaxed condition H0⊕H1[−1]H^0\oplus H^1[-1] are mutually dual. All four inclusions can be equipped with compatible integral duality triangles.

Proof. The prime-to-ℓ\ell local cochains are computed by the tame inertia and residue-field directions. In these two directions the differentials are formed from inertia minus one and Frobenius minus one, with the usual Frobenius action on tame inertia. On MM, inertia is trivial at the derivative prime. The square of a rational Frobenius is trivial on every ring-class character. In the limit it is also the identity on TT, while ℓ2\ell^2 tends to one. Thus both differentials become zero, giving (91).

Here is a finite-precision check of the pairing, needed at 2. At a retained quotient killed by 2a2^a, impose also q=ℓ2≡1(mod2a+1)q = \ell^2 \equiv1 \pmod{2^{a+1}}, as well as trivial Frobenius-square action on the coefficient module at this quotient. The tame two-generator complex then has zero differentials, with the coordinates in (13.12). Its degree-one scalar generators are the unramified and tame characters. More explicitly, use the presentation ϕσϕ−1σ−q=1\phi\sigma\phi^{-1}\sigma^{-q} = 1. After augmentation with trivial coefficient action its Fox resolution has terms of ranks 1, 2, 1, with d0=0d^0 = 0 and d1=(0,1−q)d^1 = (0,1-q), in the ordered finite and tame coordinates. The diagonal from the same resolution has zero pure-finite term, unit mixed terms, and pure-tame coefficient ±(q2)\pm\binom{q}{2}. The latter coefficient is the augmented second derivative of σ−q\sigma^{-q} together with its adjacent σ\sigma in the relation. Both 1−q1-q and (q2)\binom{q}{2} vanish modulo 2a2^a under the imposed congruence. Thus this is an actual split complex and an actual pure-plane zero pairing at the retained precision. The field contains the 2a+12^{a+1}-st roots of unity, so −1-1 is a 2a2^a-th power. The norm-residue identity (x,x)=(x,−1)(x,x)=(x,-1) for the 2a2^a-Hilbert symbol therefore makes the square of each scalar generator zero. The two generators form a basis; local Tate duality makes their cross pairing a unit. The same calculation applies coefficientwise to the free Artin coefficient module, including its nilpotent tt and quadratic variables. Thus the pure plane restrictions are already zero at every retained quotient. All these congruences can be imposed simultaneously with the derivative Frobenius conditions by increasing their precision. Taking the compatible limit proves integral vanishing of the pure squares. It is not deduced from skew symmetry in characteristic two.

Equivalently, in the limiting tame presentation ϕσϕ−1=σq\phi\sigma\phi^{-1}=\sigma^q with q→1q\to1, the rank-(1, 2, 1) resolution specializes to the exterior resolution for two procyclic directions. The finite Hilbert-symbol calculation specifies the cup product on its split cohomology and rules out a hidden square term. Conjugation transports the finite Tate coordinate by CτC_\tau and the singular coordinate by −Cτ-C_\tau, with possible scalar units coming from the orientations. Consequently the cross pairing is

β(x,y)=ϵ⟨x,Cτy⟩,ϵ∈Λ×,x∈F, y∈S,(93)\beta(x,y)=\epsilon\langle x,C_\tau y\rangle,\qquad\epsilon\in\Lambda^\times,\qquad x\in F,\ y\in S, \tag*{(93)}

where ⟨ , ⟩\langle\ ,\ \rangle is the perfect alternating Weil form. This proves the assertions about orthogonal complements. Since the restrictions of this explicit pairing to either pure plane are zero as maps of the split complexes, their isotropy homotopies may be chosen to be zero. Only a product of two degree-one terms could map to the degree-two local invariant target; the degree-zero terms introduce no additional restriction. These zero homotopies agree on the strict subcomplex. These are the actual orthogonality data required in the Selmer duality construction [52], Theorem 6.3.4; the compatibility assertion is therefore an assertion about these displayed complexes and maps. Lemma 13.1 is used to retain this finite diagram together with the unchanged local data.

For a finite set II of derivative primes, let CIC_I be obtained from CC by replacing the finite plane condition FF by SS at each prime of II, retaining all other local conditions. The classes below use the same multiplier LL already included in PP; in particular, P∅=PP_{\varnothing}=P.

Lemma 13.12 (Descent and the switch at 2). Suppose that the finite ring-class transfers are performed before retaining their target cycles and witnesses as in Lemma 13.1. There is one integer L≠0L\ne0, depending on the fixed curve, parametrization and fixed local types, such that the classes obtained from the Heegner derivatives of LL times the point satisfy, for every finite switched set II,

PI∈H1(CI),f(PI∪{ℓ})=0,s(PI∪{ℓ})=Cτf(PI).(94)P_I\in H^1(C_I),\qquad f(P_{I\cup\{\ell\}})=0,\qquad s(P_{I\cup\{\ell\}})=C_\tau f(P_I). \tag*{(94)}

The same LL works for every number of active and derivative primes. The previously imposed singular conditions are retained.

Proof. We first descend the derivative classes using one multiplier for the complete conductor, and verify their Kummer conditions at 2N2N. We then compute both local coordinates in (94). The last step retains these classes and identities in the same bounded target cochain diagrams used for evaluation.

Choose the orientations coherently. The relative ring-class group at an inert prime ℓ\ell is cyclic of order ℓ+1\ell+1. For distinct new primes these groups form a product: the ring-class exact sequence has kernel the product of the local residue-unit quotients, and the only global units here are 11, −1-1, whose images in these quotients are trivial. Set

Dℓ=∑i=1ℓiσℓi,DI=∏ℓ∈IDℓ.D_\ell=\sum_{i=1}^{\ell}i\sigma_\ell^i,\qquad D_I=\prod_{\ell\in I}D_\ell.

Direct multiplication gives

(σℓ−1)Dℓ=(ℓ+1)−∑i=0ℓσℓi.(95)(\sigma_\ell-1)D_\ell=(\ell+1)-\sum_{i=0}^{\ell}\sigma_\ell^i. \tag*{(95)}

The Hecke correspondence and reduction of its CM isogenies give, for every class-group translate,

Tr⁡(ycrn)=aℓycrn/ℓ,y~crn=Fr⁡ℓy~crn/ℓ.(96)\operatorname{Tr}(y_{\mathfrak{c}\mathfrak{r}n})=a_\ell y_{\mathfrak{c}\mathfrak{r}n/\ell},\qquad\widetilde{y}_{\mathfrak{c}\mathfrak{r}n}=\operatorname{Fr}_\ell\widetilde{y}_{\mathfrak{c}\mathfrak{r}n/\ell}. \tag*{(96)}

These are the point relations, not an application of a residual irreducibility theorem. A fixed multiple of the parametrization removes cuspidal terms.

There is a uniform bound on the 22-primary torsion over the union of the ring-class fields in use. To see this, choose a fixed nonidentity scalar homothety of infinite order in the 22-adic Tate image. Square a lift so that it belongs to every quadratic subgroup under consideration. Multiply it by its conjugate under complex conjugation. Its action on each ring-class field is trivial, because conjugation inverts the abelian ring-class action, while its action on TT is still a fixed nonidentity scalar. If 2e2^e annihilates its scalar minus one up to a unit, then 2e2^e kills the torsion in question. The existence of this fixed scalar, including the CM case, is the Tate-image input used in Lemma 13.8.

Work first with coefficients modulo 2a2^a. Require aℓa_\ell and ℓ+1\ell+1 to vanish to a precision substantially larger than aa. Equations (95) and (96) then make the derivative Kummer class invariant under the relative ring-class group. In the inflation–restriction sequence, both the obstruction to descent and the ambiguity of descent are killed by 2e2^e, since their coefficient module is killed by 2e2^e. Multiplication by 22e2^{2e} therefore gives a descent independent of this ambiguity: descend 2e2^e times the class and multiply its lift by 2e2^e. There is no repetition of this factor for individual primes; descent is performed once from the field with the complete conductor.

The global descent has cost only the fixed factor 22e2^{2e}, regardless of the number of derivative primes. It remains to ensure that the descended class satisfies the Kummer condition at every fixed bad place; this is a separate local descent issue.

At a place over 2N2N these descent extensions are unramified. Here is the local descent argument, valid also for even extension degree and for toric or additive reduction. Let F′/FF'/F be a finite unramified extension with group GG, and write k′/kk'/k for its residue extension. The successive formal-group quotients Ej(F′)/Ej+1(F′)E_j(F')/E_{j+1}(F') are additive copies of k′k'. The normal basis theorem makes each a cohomologically trivial GG-module, without a restriction on ∣G∣|G|. Every finite quotient E1(F′)/Ej(F′)E_1(F')/E_j(F') is therefore cohomologically trivial. The inverse systems of these finite groups and their invariant groups satisfy the Mittag–Leffler condition. Taking inverse limits in finite GG-cochains consequently gives H1(G,E1(F′))=0H^1(G,E_1(F'))=0. Let E/OF\mathcal{E}/\mathcal{O}_F be the Néron model and put E~0=Ek0\widetilde{E}^0=\mathcal{E}^0_k, a smooth geometrically connected commutative algebraic group over the finite field kk. Lang’s finite-extension cocycle theorem [45] gives H1(G,E~0(k′))=0H^1(G,\widetilde{E}_0(k'))=0. The smooth reduction sequence then gives H1(G,E0(F′))=0H^1(G,E^0(F'))=0. Let Φ=Ek/E~0\Phi=E_k/\widetilde{E}^0 be the finite étale component-group scheme. Each fiber over a point of Φ(k′)\Phi(k') is a torsor under E~k′0\widetilde{E}^0_{k'}, and hence has a k′k'-point by Lang [45]. Smooth lifting therefore makes E(F′)→Φ(k′)E(F')\to\Phi(k') surjective. Hence

H1(G,E(F′))↪H1(G,Φ(k′)).H^1(G,E(F'))\xhookrightarrow{} H^1(G,\Phi(k')).

Existence of the smooth finite-type model and smooth lifting follow from Bosch et al. [6]. The right side is killed by the exponent of Φ(k‾)\Phi(\overline{k}). By inflation–restriction, the left side is exactly the kernel of H1(F,E)→H1(F′,E)H^1(F,E)\to H^1(F',E). Thus the same fixed exponent makes a class in H1(F,E[2a])H^1(F,E[2^a]) Kummer whenever its restriction is Kummer. Néron models commute with unramified base extension [6], so their geometric component groups are unchanged. Only the finitely many fixed local twisting types at 2N2N occur, so the product of these component exponents is bounded independently of the conductor and of the extension degree. Include this product, the single descent factor 22e2^{2e}, and the parametrization factor in LL. Thus the descended class has the integral Kummer condition at 2N2N. No good-ordinary or semistability condition was used. Transfer with the scalar character preserves this condition because Ψ=1\Psi=1 there.

The single multiplier LL now gives descent with the required Kummer conditions. We next prove the finite-to-singular identity itself. Both coordinates matter: the singular coordinate must become CτfC_\tau f, while the new finite coordinate must vanish at the retained precision.

Here is the local calculation, including the division by two. Apply the derivatives at all primes other than ℓ\ell, and write X,YX,Y for the resulting lower and upper points. Put Fℓ=Fr⁡ℓF_\ell=\operatorname{Fr}_\ell. The lower field splits at the KK-prime (ℓ)(\ell), since that ideal is principal. Reduction therefore gives Fℓ2X=XF_\ell^2X=X. The following Frobenius-polynomial identities are taken on the reduction; good odd-prime reduction is injective on the 22-primary torsion coordinates being compared. If QQ is a 2a2^a-division point of LXLX, the finite coordinate of its Kummer class is

f=(Fℓ2−1)Q=(aℓFℓ−(ℓ+1))Q.(97)f=(F_\ell^2-1)Q=(a_\ell F_\ell-(\ell+1))Q. \tag*{(97)}

We give the descent-cocycle calculation of the other coordinate. Choose ZZ with 2aZ=LDℓY2^aZ=LD_\ell Y, and choose the descended cocycle bb so that on the upper-field Galois group it is b(g)=(g−1)Zb(g)=(g-1)Z. A change by the already bounded descent ambiguity has no effect on the eventual limit. The crossed identity gives

U=(σℓ−1)Z−b(σℓ)∈E(Hcm).U=(\sigma_\ell-1)Z-b(\sigma_\ell)\in E(H_{\mathrm{cm}}).

For gg in the upper-field Galois group, compare the two expansions of b(gσℓ)b(g\sigma_\ell); they give gU=UgU=U. Moreover,

2aU=L((ℓ+1)Y−aℓX).2^aU=L((\ell+1)Y-a_\ell X).

Both integers ℓ+1,aℓ\ell+1,a_\ell are divisible by 2a2^a. Consequently

U0=Lℓ+12aY−Laℓ2aXU_0=L\frac{\ell+1}{2^a}Y-L\frac{a_\ell}{2^a}X

is an actual upper-field point with the same 2a2^a-multiple as UU. Thus U−U0U-U_0 is upper-field torsion of bounded exponent. This comparison with an actual integer quotient is what bounds the ambiguity; arbitrary division points would not give this bound. Reduction makes σℓ\sigma_{\ell} act trivially and Y~=FℓX~\widetilde{Y}=F_{\ell}\widetilde{X}. Therefore reduction of b(σℓ)=−Ub(\sigma_{\ell})=-U gives its singular coordinate

s=(aℓ−(ℓ+1)Fℓ)Q(98)s=(a_{\ell}-(\ell+1)F_{\ell})Q \tag*{(98)}

up to the uniformly bounded descent torsion already described. The Frobenius polynomial yields the exact operator identity

(Fℓ−aℓ)(aℓFℓ−(ℓ+1))=aℓ−(ℓ+1)Fℓ.(99)(F_{\ell}-a_{\ell})(a_{\ell}F_{\ell}-(\ell+1))=a_{\ell}-(\ell+1)F_{\ell}. \tag*{(99)}

Thus s=(Fℓ−aℓ)fs=(F_{\ell}-a_{\ell})f; when aℓa_{\ell} vanishes at the retained torsion precision, this is s=Fℓfs=F_{\ell}f. Taking the Frobenius limit gives s=Cτfs=C_{\tau}f.

If γ\gamma is the chosen rational Frobenius lift, its image in the generalized-dihedral ring-class Galois group lies outside the abelian subgroup, so γ2\gamma^{2} acts trivially on the full upper ring-class field. The same lift therefore computes the descended finite Kummer coordinate from the reduced point over the common residue field Fℓ2\mathbb{F}_{\ell^{2}}. For the new finite coordinate, reduction of the derivative point is

∑i=1ℓiFℓX=ℓ(ℓ+1)2FℓX.(100)\sum_{i=1}^{\ell}iF_{\ell}X=\frac{\ell(\ell+1)}{2}F_{\ell}X. \tag*{(100)}

The finite Kummer coordinate consequently vanishes modulo 2a2^{a} if v2(ℓ+1)≥a+1v_{2}(\ell+1)\geq a+1. The additional 11 is essential at 22. It is imposed in the choice of the next precision, and does not multiply the class by a new denominator. Bounded torsion ambiguities disappear on passing from E[2a]E[2^{a}] to E[2m]E[2^{m}] with a−m≥ea-m\geq e. Choose aa and the Frobenius precision successively faster than mm.

The calculation is compatible with every translate in the transfer: transport the place and its Frobenius before applying that translate. The scalar weight on the lower and upper class is identical. Applying the same calculation at each ℓ∈I\ell\in I proves the earlier singular conditions as well.

The local formulas now give the switch. To use it in the rank-reduction argument, we must retain more than its cohomology class: the transferred target cycles, local lifts and degree-two cochain identities must extend the original finite diagrams. We record this compatibility next.

Here the transfer itself is integral at the cochain level. For a finite Artin coefficient ring AA, let Δ=Gal⁡(Hcr/K)\Delta=\operatorname{Gal}(H_{cr}/K), through which the finite scalar and quadratic characters factor. Shapiro’s cochain map and the coefficient homomorphism

A[Δ]⟶A,[σ]⟼χe(σ)Ψ(σ)A[\Delta]\longrightarrow A,\qquad[\sigma]\longmapsto\chi_{e}(\sigma)\Psi(\sigma)

send the descended class to the desired twisted class. For a universal quadratic family, replace the quadratic value by its group element in A[G]A[G], also including the fixed base character. Choose inverse actions on both sides when using that Shapiro convention. Explicitly, these are the finite coset sums with the indicated scalar weights; there is no division by #Δ\#\Delta. These maps and their degree-zero and degree-two compatibility formulas are used at this finite stage, before passage to a bounded target model. Naturality of restriction and Kummer corestriction supplies the local lifts. At 2N2N the scalar character is trivial, so these are precisely the Kummer conditions of the indicated quadratic twist.

More explicitly, in the universal case let ν:Δ⟶G\nu:\Delta\longrightarrow G be the additional quadratic character. Perform the coefficient map

Ai[Δ]⟶Ai[G],[σ]⟼χh0(σ)Ψi(σ)[ν(σ)]A_{i}[\Delta]\longrightarrow A_{i}[G],\qquad[\sigma]\longmapsto\chi_{h_{0}}(\sigma)\Psi_{i}(\sigma)[\nu(\sigma)]

and the finite coset sum before any character evaluation. This gives one cycle over Ai[G]A_i[G], with its local lifts. Every sign evaluation Ai[G]→AiA_i[G] \to A_i sends this cycle and these lifts to the corresponding weighted construction, because it commutes with finite sums and differentials. After contraction, compare an evaluated target model with its already chosen scalar model using their maps to the same original target cochains. Retain these comparison matrices and their contraction homotopies for all the finitely many characters of this fixed GG. No character idempotent or division by a class-group order is used. At t=0t=0 the split-prime norm multiplier on this universal cycle is

ari−2χh0(ri)[ν(Fr⁡ri)].a_{r_i}-2\chi_{h_0}(r_i)[\nu(\operatorname{Fr}_{r_i})].

The two conjugate Frobenius values of ν\nu agree because each quadratic character comes from Q\mathbb{Q}. Evaluation at the character corresponding to hh therefore gives exactly ari−2χh(ri)a_{r_i}-2\chi_h(r_i), with the central boundary witness described above.

Finally contract only the resulting target cycles, local lifts and boundary witnesses into the models over KK. Retain the target comparison maps, the split local Fox complexes, their zero isotropy homotopies, and their duality and switch identities in degrees zero, one and two. The proof of Lemma 13.1 shows explicitly how to transport these identities and their witnesses. In particular the unbounded cochains over HcrH_{cr} and the full Shapiro maps are not objects or maps of this limiting diagram. When a further derivative prime is selected, extend the same original finite-stage diagram and its contraction maps, using the same inner ultrafilter. Do not construct an unrelated cohomologically equivalent old complex. The earlier evaluations, including all degree-two cocycle identities, are consequently retained by the same contraction maps after each new switch. For a fixed finite set of switches and fixed GG, the target rank bounds above apply. Lemma 13.1 therefore applies to these extended target diagrams at their common retained precision. Their limiting classes give (13.14). The displayed local formulas agree with the calculation underlying [34], Proposition 1.7.4; Howard’s odd-prime global hypotheses are not being asserted at 2.

Lemma 13.13 (Preservation of the determinant coordinate). Let OO be a height-one discrete valuation ring at which the complexes and switching conditions are self-dual. Suppose the generic Selmer group for a set II has rank one and is spanned by PIP_I, and v0=f(PI)v_0=f(P_I) is nonzero at the next derivative prime. Then the switched generic group has rank one and is spanned by PI∪{ℓ}P_{I\cup\{\ell\}}, and

vO(uI)=vO(uI∪{ℓ}).(101)v_O(u_I)=v_O(u_{I\cup\{\ell\}}). \tag*{(101)}

This assertion does not require a primitive localization in either integral plane.

Proof. Compare the strict condition and the relaxed condition of Lemma 13.11. Their complexes are dual. Over the fraction field, the image of relaxed H1H^1 in F⊕SF\oplus S is self-annihilating by Poitou–Tate, hence two-dimensional. Strict H1H^1 is zero because the original rank-one group localizes nontrivially. The relaxed image meets FF in the line spanned by v0v_0 and, by Equation (94), meets SS in the nonzero line spanned by CFv0C_Fv_0. Its intersection with either plane is therefore exactly a line. This proves the rank and spanning assertions.

For the integral determinant comparison let A=PIA=P_I and B=PI∪{ℓ}B=P_{I\cup\{\ell\}} be a field basis of relaxed H1H^1. The dual basis A∨,B∨A^\vee,B^\vee belongs to strict H2H^2. In the triangle adding F[−1]F[-1] to the strict complex, the map F→Hstr2F\to H^2_{\mathrm{str}} pairs a vector xx against the relaxed localization. By Equations (93) and (94), it is a unit times ⟨x,v0⟩B∨\langle x,v_0\rangle B^\vee. The remaining H2H^2 quotient maps to A∨A^\vee. Choose xx mapping to B∨B^\vee. Although v0v_0 and xx need not be integral separately, the volume of the ordered basis (v0,x)(v_0,x) of FF is a unit of OO, precisely because its symplectic pairing is a unit. For SS use CFv0C_Fv_0 and a preimage of A∨A^\vee; its volume is again a unit. The two determinant tensors thus map, up to units, to the same tensor in the strict determinant, using A∨∧B∨A^\vee\wedge B^\vee. All triangles and plane lattices in this comparison are integral. Their determinant isomorphisms consequently give (101), including any torsion or localization-index contribution.

Rank reduction and nonnegative divisors

The derivative-prime reduction follows the Kolyvagin-system argument of Howard [34] (Lemmas 1.5.3 and 1.6.4). We carry its switches through integral Selmer complexes and preserve their determinant coordinate. The local calculation and descent above supply the characteristic-two pairing and one fixed multiplier; the argument below supplies the uniformity as the conductor varies.

We now prove the first two bounds in (88). A height-one specialization can have larger Selmer dimension than the generic rank-one line. Local switches will remove that excess dimension while preserving the determinant valuation. At test dimension one, integrality is immediate. At the coefficient prime (2) this argument uses residual irreducibility and therefore applies here to genus data.

Use the sequence groups ΓK⊂Γ\Gamma_K \subset\Gamma of Lemma 13.7, and write H\mathcal{H} for the exact kernel of Lemma 13.8. Over the relevant test field, put W=Ind⁡ΓKΓ(TχeΨ)W = \operatorname{Ind}_{\Gamma_K}^{\Gamma}(T\chi_e\Psi). Lemma 13.10 realizes finite localization as the projection of (1+τ)b(u′)(1+\tau)b(u'), for u′∈Hu' \in\mathcal{H}, to one induced summand. Restriction to H\mathcal{H} is injective by Lemma 13.8, and evaluation there is additive and Galois-equivariant. The image of 1+τ1+\tau is a copy of the two-dimensional summand, also in characteristic two.

Lemma 13.14 (Rank reduction at a height-one prime). Suppose a primitive instance has generic cohomology of rank at most one in degrees one and two, zero elsewhere, and PP spans H1H^1 when it is nonzero. Then the first line of (88) holds. These hypotheses hold in every simple-zero instance and also at the base of Theorem 3.3. The second line holds in genus data with irreducible E[2]E[2], with a bound independent of the number of active or derivative primes.

Proof. There is nothing to prove if u=0u=0. Otherwise the generic rank is one and PP is nonzero. Localize, and if convenient complete, at a height-one prime. Test its residue field; at (2) do this argument only in genus data with irreducible residual representation. Suppose first that Ψ2≠1\Psi^2 \ne1 on the field. Then WW is irreducible. Inertia at rr distinguishes its two induced summands. On one summand, irreducibility of TT over KK comes from open image or the CM normalizer in characteristic zero, and from the assumed residual irreducibility at (2). In the latter case we have omitted the fields meeting Q(E[2])\mathbb{Q}(E[2]) nontrivially. The cyclic cubic residual case remains irreducible over F2(t)\mathbb{F}_2(t), with a possibly quadratic commuting field. Constant Tate matrix images are realized on the sequence group; scalar character twists do not change this irreducibility.

Let the test Selmer H1H^1 have dimension s≥2s \ge2. Include the reduction of a primitive generator of the generic free H1H^1 lattice among two independent classes. We can arrange that their localization has rank two. To see this, if the classes are independent over the commuting field of WW, simplicity and the injective restriction in Lemma 13.8 imply that the field span of their joint evaluations on H\mathcal{H} is the whole of W⊕WW \oplus W. Otherwise a nontrivial equivariant linear relation would vanish on restriction, and hence on the original classes. Projection by 1+τ1+\tau therefore spans all pairs in the two-dimensional localization space. Some actual evaluation pair has nonzero determinant: a homogeneous quadratic vanishing on an additive group vanishes on its field span, since its polar form vanishes on every pair from the group. This argument is valid in characteristic two as well. If the classes are dependent over the commuting field but independent over the ground field, projection commutes with that field action on the graph of τ\tau. At the residual prime (2)(2), in the cyclic cubic case, this commuting field is F4((t))\mathbb{F}_4((t)): rational complex conjugation has trivial residual image, so the commuting-field action is the same on the two induced summands. If the second class is α\alpha times the first, with α\alpha outside F2((t))\mathbb{F}_2((t)), a nonzero projected evaluation vv gives the ground-field-independent pair v,αvv,\alpha v. Thus this case also gives rank-two localization.

Choose the derivative prime realizing that evaluation. Its localization is nonzero on the primitive generic generator. The relaxed image on the test fiber is self-annihilating of dimension two, and contains all of FF because the finite localization has rank two. It is therefore FF. Switching to SS lowers test H1H^1 dimension by two. Generically, Lemmas 13.12 and 13.13 keep rank one, a nonzero class, and the same determinant valuation.

It remains to treat Ψ2=1\Psi^2=1, which occurs here only in characteristic zero. Extend Ψ\Psi across τ\tau and split into the two conjugation signs. Conjugation on the cochains includes 1+t↦(1+t)−11+t \mapsto(1+t)^{-1}, which is trivial on this fiber. The fixed Kummer conditions and relaxed conditions are preserved. At previously switched places the split local model has diagonal conjugation action on f,sf,s, so its plane conditions are preserved too. The induced representation now splits into two nonisomorphic absolutely irreducible twists. Finite and singular localization each have one line per sign. Within a sign the pairing is a symmetric hyperbolic pairing of those two isotropic lines; the signs are orthogonal.

If both Selmer signs occur, the restriction argument just used gives rank-two localization by choosing one class of each sign, with a nonzero component of the primitive generator among them. If only one sign occurs and s>1s>1, choose rank-one localization nonzero on that generator. The relaxed image has a self-annihilating line in each sign. In the sign hit this is the finite line; in the other it must be the singular line, since a symmetric hyperbolic plane in characteristic zero has exactly these two isotropic lines. The switch preserves the total dimension but introduces the other sign: the old strict kernel has dimension s−1≥1s-1\ge1 and the new singular line contributes the second sign. A subsequent rank-two switch reduces dimension. Iteration reaches test rank one; it cannot pass below one, because the generic rank-one class has been retained throughout.

At test rank one the minimal self-dual complex over the DVR has one free term in each of degrees one and two and zero differential; there are no invariants. An integral class and its integral dual functional therefore give an integral determinant coordinate. Reversing the switches gives the first assertion. At (2)(2) the initial fixed descent and local multiples cost a bounded valuation, independent of every subsequent switch. This proves the second assertion with the stated uniformity.

Uniformity without residual irreducibility

Only the ring-data bound at eq:2 remains. Residual irreducibility is not assumed, so the preceding argument on that residue field does not cover every instance. We first bound the model sizes and retain evaluation through a second limit. These constructions turn a hypothetical sequence of unbounded negative determinant valuations into a characteristic-zero outer limit. There the retained evaluation maps permit rank reduction and force a bounded denominator, giving a contradiction.

Lemma 13.15 (Uniform residual sizes). *Suppose ω(disc⁡K)≤A\omega(\operatorname{disc} K)\le A, the local twisting classes at 2N2N belong to a fixed finite list, and all active conductor primes are split with odd Frobenius exponent of the deformation character. After localization and completion at (2)(2), the minimal free ranks of the Selmer complexes are bounded in terms of EE, AA, and the number of retained derivative primes. They do not depend on the number of active conductor primes.

Proof. Reduce first over F2[[t]]\mathbb{F}_2[[t]]. The quadratic character is now trivial. Removing the active conductor primes from the permitted ramification set changes the global complex by their singular local complexes. These, and their unramified local complexes, are acyclic after inverting tt, by Lemma [13]. The resulting smaller-support complex, including its comparison maps, can be constructed at the original Artin stages before taking the limit. Its support consists of 2N2N, rr, and the retained derivative primes. Its F2((t))\mathbb{F}_2((t)) cohomology dimensions are bounded by those at t=0t=0: choose a minimal finite free model over F2[[t]]\mathbb{F}_2[[t]].

Here is a uniform bound for the latter residual cohomology. Put F=Q(E[2])F = \mathbb{Q}(E[2]), a fixed field. Then FK/FFK/F is at most quadratic. Enlarge the allowed set of primes of FF by those ramified in KK. Its cardinality is bounded by a constant depending on EE, AA and the number of derivative primes. Kummer theory bounds the number of generators of the maximal pro-22 Galois group over FF unramified outside this set, using the fixed unit group, the fixed 22-class group, and the allowed valuations. The subgroup defining FKFK has index at most two; the elementary Schreier bound bounds its generator number. Every finite Galois 22-extension of FKFK with this ramification has Galois closure of 22-power degree over FF, so this subgroup indeed controls the required pro-22 extensions of FKFK.

Over FKFK the residual Tate module is trivial. Restriction and inflation–restriction therefore bound the residual H1H^1 over KK. The H0H^0 bound is immediate, and the global Euler characteristic or global duality bounds H2H^2. The local terms at the remaining bounded set have bounded dimensions, with degrees of the local fields at most two over the fixed rational local fields. At 2N2N there are only finitely many local quadratic twisting classes. The same bounds apply to the Selmer cone. Lemma [11] now bounds the minimal ranks. Determinant valuations will require a separate argument.

Evaluation through the outer limit

The preceding evaluation argument concerns one inner construction over a fixed KK. The ring bound must also be uniform when KK and the conductor vary. When all active primes split and ω(k)\omega(k) is bounded, Lemma [13] bounds the model sizes after any fixed number of derivative operations. The next proposition shows that passing to a second limit of such models preserves detection, including classes represented only by approximate cycles before that limit.

Proposition 13.16 (Integral evaluation through the outer limit). Let CjC_j be any family of the preceding limiting complexes, completed over Oj=Λ(2)\mathcal{O}_j = \Lambda_{(2)}, possibly for different quadratic fields KjK_j. Suppose their minimal ranks are bounded. Assume a common bounded cohomological degree interval. Keep the actual evaluation matrices and transport them to the minimal models through integral contractions. For a nonprincipal ultrafilter U\mathcal{U}, put

O∞=(∏UOj)/a,a={(xj):{j:v2(xj)≥n}∈U for every n}.\mathcal{O}_{\infty} = \left(\prod_{\mathcal{U}} \mathcal{O}_j\right)\big/\mathfrak{a}, \qquad \mathfrak{a} = \{(x_j): \{j:v_2(x_j)\ge n\}\in\mathcal{U}\text{ for every }n\}.

Then O∞\mathcal{O}_{\infty} is a DVR with uniformizer 22 and a characteristic-zero fraction field L∞L_{\infty}. The outer H1H^1 over L∞L_{\infty} injects into crossed classes on the inner quadratic sequence group product, or its extension by one simultaneous complex conjugation for the induced representation. Its restriction to the product of their exact common kernels is injective. All arbitrary-sequence degree-two evaluation identities survive. These conclusions also hold after retaining any fixed finite collection of additional integral diagrams.

Proof. A nonzero element of the quotient has a representative whose valuations are bounded on an ultrafilter-large set. A finite partition then makes its valuation equal to a single integer nn on such a set. It is 2n2^n times a unit. Products add these finite valuations, so the quotient is a domain, and every nonzero ideal has an element of smallest valuation. It is consequently a DVR. The integer 2n2^n is nonzero for every nn, so its fraction field has characteristic zero.

For each jj, all-sequence evaluation maps originally have entries in Λ\Lambda. Extension to Oj\mathcal{O}_j and composition with an integral contraction still give integral matrices. Thus evaluation on any sequence of inner group elements has an entrywise image in O∞\mathcal{O}_\infty. Equations (13.9) and (13.10) survive for all such sequences. In particular, if an outer cycle is represented by vectors xjx_j for which djxjd_jx_j has valuation tending to infinity, the evaluation of djxjd_jx_j does too: the degree-two evaluation matrix is integral. Thus an outer cycle gives an exact crossed cocycle even when its representatives are only approximate inner cycles.

Over the inner residue field Ωj\Omega_j, choose a detecting list as in Lemma 13.7; its length is at most dim⁡ΩjH1(Cj⊗Ωj)+rank⁡M\dim_{\Omega_j} H^1(C_j \otimes\Omega_j) + \operatorname{rank} M. These lengths are bounded. Include in the integral diagrams the evaluation map to its two-term complex and a contraction of its cone to a complex starting in degree one. Such a contraction uses only unit pivots over Oj\mathcal{O}_j and has bounded graded sizes. All its matrices, including inverses and homotopies, are integral and pass to the quotient. Its cone still starts in degree one after extension to L∞L_\infty. This proves injectivity just as in Lemma 13.7.

Let HjH_j be the inner exact kernel. In the product of the quadratic sequence groups, the central elements of Lemma 13.8 give a central element modulo ∏jHj\prod_j H_j with scalar u4u^4. Since u4−1u^4-1 remains nonzero in O∞\mathcal{O}_\infty, the same calculation gives restriction injectivity. For the induced representation first restrict to the quadratic subgroup, as in Lemma 13.8. Additional finite diagrams pass through the same entrywise operations.

Lemma 13.17 (Irreducibility in the outer limit). On the outer characteristic-zero test, Ψ\Psi has infinite order and the four-dimensional representation induced from TχΨT\chi\Psi is absolutely irreducible.

Proof. The inner irreducibility argument requires a uniform finite witness to survive this limit. The images of the quadratic subgroups have index at most two in the fixed compact 2-adic Tate image. A compact 2-adic analytic group is topologically finitely generated and hence has only finitely many closed subgroups of index at most two. Choose one on an ultrafilter-large set. Its absolutely irreducible representation has finitely many matrices spanning M2(Q2)M_2(\mathbb{Q}_2); the determinant expressing this spanning property is a fixed nonzero 2-adic number. Every one of these Tate matrices is realized by choices of Galois elements in each component. Their accompanying character scalars are units and do not change the spanning assertion. Its determinant remains nonzero in L∞L_\infty. This proves absolute irreducibility in that field. Also 1+t1+t has infinite order already in every Ωj\Omega_j: for a nonzero integer nn, the first nonzero term of (1+t)n−1(1+t)^n-1 occurs in finite degree. It remains a unit modulo 22 in every component, so no such power becomes one in the outer field.

The two induced summands therefore have different inertia scalars, Ψ\Psi and Ψ−1\Psi^{-1}, and the induction is absolutely irreducible as in Lemma 13.9.

Lemma 13.18 (Prime realization through the outer limit). The finite Chebotarev realization of Lemma 13.10 is compatible with Proposition 13.16 and with any fixed finite list of previous derivative operations.

Proof. Apply Lemma 13.10 at each finite stage. For an outer sequence do this separately for each inner sequence, retaining the relevant finite evaluation matrices and degree-two identities before taking the outer quotient. Approximate inner cycles cause no problem, by the integrality calculation in Proposition 13.16. Previously imposed finite diagrams are unchanged.

Theorem 13.19 (Compatibility of the limit constructions). The finite free models, ring-class characters, local conditions and pairings constructed above can be retained simultaneously. Their inner limits have the stated height-one acyclicity and all-sequence cohomology detection. For all-split ring data with bounded ω(disc⁡K)\omega(\operatorname{disc} K), the residual model sizes are bounded independently of the active conductor support. Their outer limits retain arbitrary evaluations, exact-kernel injectivity and finite Chebotarev realization after any fixed number of additional integral arithmetic operations.

Proof. Use Lemma 11.6 at each finite stage and keep the same contractions and ultrafilter as in Lemma 13.1. Perform the finite ring-class transfer and weighting first, retaining only the resulting bounded target cycles and witnesses as in that lemma; no limit of the growing Shapiro source is taken. The local assertions and uniform residual sizes are Lemmas 13.2, 13.4 and 13.15; the required characters come from Proposition 13.3. Lemmas 13.7 and 13.8 give inner detection. Proposition 13.16 and Lemma 13.18 preserve it through the outer limit and later finite operations. Every retained identity is an identity of actual integral matrices. The finite derivative classes and local identities of Lemma 13.12 are among the integral arithmetic target diagrams retained in these operations, including the central norm relation before and after sign evaluation.

Lemma 13.20 (Uniform determinant bound in ring data). For simple-zero ring data with every active conductor prime split in KK and ω(k)≤a\omega(k) \le a, the coordinate of Definition 13.5 satisfies

v(2)(u)≥−CE,a,v_{(2)}(u) \ge-C_{E,a},

where CE,aC_{E,a} is independent of hh and KK. There is no residual irreducibility assumption. This is the last line of Equation (88).

Proof. Put O=Λ^(2)O = \widehat{\Lambda}_{(2)}. By Lemma 13.15, after any fixed number of derivative switches the minimal OO-models have bounded size in terms of EE, aa and that number, independently of hh. The full local complexes at rr and the active split primes are contractible over OO, and the switched planes are integrally self-dual. Thus the class and its paired closed functional have a common bounded clearing exponent, supplied by the fixed descent multiplier and the retained global duality map.

Suppose the asserted lower bound fails. Choose instances with vO(u)→−∞v_O(u) \to-\infty. Cancel disks over OO and take an outer limit of their bounded free models. Transport the class, closed functional, evaluations and the retained comparison and switch maps through these integral contractions, applying the same contractions to their boundary witnesses. Only the resulting bounded target vectors and matrices enter the outer diagram; the eliminated list of active-place complexes does not. Concretely, take the ultraproduct of their valuation rings and quotient by the ideal of sequences whose valuation tends to infinity. The resulting ring O∞O_\infty is a DVR with uniformizer 22: a nonzero sequence has a finite valuation on an ultrafilter-large set and is that power of 22 times a unit. Its fraction field has characteristic zero. All integral matrix identities, duality diagrams, and the local switch diagrams pass to this limit.

Proposition 13.16 gives injective evaluation on the outer sequence group and on its exact common kernel. This includes outer cycles represented by approximate inner cycles, since their coboundaries are evaluated by integral degree-two matrices. The fixed central scalar remains different from one in the outer field. Lemma 13.17 gives absolute irreducibility of the induced representation there: the scalar 1+t1+t has infinite order and distinguishes the two summands.

Each individual minimal OO-complex is a square complex in degrees one and two, by self-duality and the absence of residual invariants. Choose a primitive vector in its generic kernel. Such vectors survive the outer limit, so outer H1H^1 has rank at least one. If its rank exceeds one, choose rank-two localization by the absolutely irreducible evaluation argument in Lemma 13.14, making it nonzero on one of these primitive vectors. The inner Chebotarev construction realizes the corresponding sequences of derivative primes. At each original Artin stage retain the old contractions and evaluations, adjoin the new local and derivative diagrams, and pass through the same inner and outer ultrafilters. Slower cofinal coefficient precision is permitted; independent reconstruction of the old diagrams is not. For an ultrafilter-large set of instances the localization is generically nonzero. Lemma 13.13 preserves the valuations tending to minus infinity, while the outer rank falls by two. The new complexes and integral classes obey the same bounds, with only the now fixed finite number of added derivative primes.

The process must reach outer rank one: ranks are finite and cannot fall below one while the primitive kernel vector is retained. At this stage some maximal boundary minor is nonzero over the outer fraction field. Its valuation is consequently bounded in the individual DVRs on an ultrafilter-large set. Split that minor over their fraction fields. The entries of the class and duality maps are integral and their common initial multipliers are bounded. The formula for their determinant coordinate, or the elementary-divisor decomposition, then has a lower valuation bound depending on this minor and the bounded complex size. The Heegner classes themselves need not survive the outer limit: a numerator tending to zero only increases its valuation. It is the primitive kernel vector that preserves rank, and the boundary minor that bounds the denominators. This contradicts vO(u)→−∞v_O(u) \to-\infty, and proves the uniform estimate. □

Proof of Theorems 3.6 and 3.7. By Lemmas 13.14 and 13.20, the element uu has nonnegative valuation away from (2) and a uniformly bounded negative valuation at (2). Normality of Λ\Lambda implies that a fixed power of 2 times uu belongs to Λ\Lambda. Its central value therefore has the same lower valuation bound.

In genus data, s(h∗)s(h_\ast) and the weight of h∗h_\ast are fixed, c=1c=1, and k=hh∗k=hh_\ast. Equations (86) and (87) give Equation (3.11). The excluded intersection fields are finite in number, since an irreducible two-division field has at most one quadratic subfield. In ring data, the sum over q∣kq\mid k is bounded by 2ω(k)2\omega(k), whereas 2∑q∣htq=4ω(h)2\sum_{q\mid h}t_q=4\omega(h). The same equations give Equation (11). □

The universal Heegner class

For interpolation we combine the non-(2) divisor estimate and the central valuation formula with a universal binary family. The characterwise coordinates must have a uniformly controlled clearing factor. We first remove the norm and local determinant factors belonging to primes unused at a character, then eliminate the new-prime blocks before choosing that clearing factor.

Recall the binary coefficient rings:

G≃(Z/2Z)b,R=Λ[G],O=Λ^(2).G \simeq(\mathbb{Z}/2\mathbb{Z})^b,\qquad R=\Lambda[G],\qquad O=\widehat{\Lambda}_{(2)}.

We work with the universal quadratic character over RR for the family in Theorem 3.3. At a new prime qq let gq∈Gg_q\in G be its inertia bit: at a character xx, it evaluates to −1-1 when is active and to 1 when it is unused. Choose the conductor character of Proposition 13.3 with odd exponents at all the new split primes. In the universal complex relax at every new prime and at the old active primes, and take the trace class pp from the conductor containing all new primes, together with rr and the old conductor. As in the proof of Lemma 13.12, form its Ai[G]A_i[G]-weighted target cycle at each finite stage, together with its local lifts and boundary witnesses, before evaluating any sign character. Apply the limit construction for this fixed GG to those target data; the source ring-class cochains do not enter the limiting diagram. Choose an integral determinant basis and write urelu_{\mathrm{rel}} for the characterwise determinant coordinate.

Lemma 13.21 (Removing the unused-prime factors). There is η∈O[G]\eta\in O[G] such that u=ηurelu=\eta u_{\mathrm{rel}} agrees at each character with the primitive determinant coordinate up to a Λ\Lambda-unit. In particular, uχ∈Λ[1/2]u_{\chi} \in\Lambda[1/2]. If the base product derivative is zero, then u0(0)=0u_0(0)=0. At the nonzero vertices,

v(uχ(0))≤B+OE,h0,a(1),(102)v(u_{\chi}(0)) \le B+O_{E,h_0,a}(1), \tag*{(102)}

where aa bounds ω(k)\omega(k).

Proof. At an unused prime, the norm relation multiplies the primitive point class by

eq={aq,q inert in K,aq−z−z−1,q split in K.e_q= \begin{cases} a_q, & q\text{ inert in }K,\\ a_q-z-z^{-1}, & q\text{ split in }K. \end{cases}

where z=χh0Ψz=\chi_{h_0}\Psi times the universal quadratic scalar at an oriented Frobenius. The relaxed singular quotient contributes

lq=∏v∣qdet⁡(1−qv−1ηv(Fr⁡v)Fr⁡v∣T),l_q=\prod_{v\mid q}\det\left(1-q_v^{-1}\eta_v(\operatorname{Fr}_v)\operatorname{Fr}_v\mid T\right),

where qvq_v is the residue cardinality and ηv\eta_v denotes the full scalar character. Thus urelu_{\mathrm{rel}} differs from the primitive coordinate by eq2/lqe_q^2/l_q, up to a Λ\Lambda-unit. This follows from the localization triangle with its integral determinant isomorphism; the pairing comparison is made over the fraction field. Choose conjugate-compatible Frobenius lifts in these formulas, taking the square of rational Frobenius at an inert place, and extend the expressions universally over O[G]O[G].

Both eqe_q and lql_q are units in O[G]O[G]. At a split prime, the odd Frobenius exponent gives a nonconstant scalar in F2((t))\mathbb{F}_2((t)); at an inert new prime, the hypothesis tq=0t_q=0 gives an odd trace. Moreover, already in the group ring, lq≡eq2(mod2)l_q\equiv e_q^2\pmod2. In the split case the residual identity is

(1+aqz+z2)(1+aqz−1+z−2)=aq2+z2+z−2=(aq+z+z−1)2.(1+a_qz+z^2)(1+a_qz^{-1}+z^{-2})=a_q^2+z^2+z^{-2}=(a_q+z+z^{-1})^2.

In the inert case the Frobenius-square polynomial gives aq2a_q^2. Here the group-like quadratic scalars have square one, so the identities hold before sign evaluation. Consequently

η=∏q new(1+lq/eq2−12(1+gq))(103)\eta=\prod_{q\ \mathrm{new}}\left(1+\frac{l_q/e_q^2-1}{2}(1+g_q)\right) \tag*{(103)}

belongs to O[G]O[G]. Its factor is lq/eq2l_q/e_q^2 at unused characters and 1 at active characters. It makes the required correction without an idempotent denominator for each prime.

For all the primitive constituents, generic cohomology has rank at most one. At nonzero vertices this follows from the simple-zero assumption. At the base it follows from Selmer corank one; a nonzero generic class then spans the possible rank-one group. Hence Lemma (94) applies to every nonzero primitive determinant coordinate. Its nonnegative valuations away from (2)(2) imply membership in Λ[1/2]\Lambda[1/2], by normality. The same assertion is automatic for a zero coordinate.

If the base derivative vanishes, Equation (6) makes the specialized point torsion. Either its generic determinant coordinate is zero or the specialization is at constant rational rank one and its degree-one class is zero there. In either case u0(0)=0u_0(0) = 0. At a nonzero vertex use Equations (86) and (87). Subtracting the two Sha⁡\operatorname{Sha} lengths and 4w(hx)4w(h_x) leaves precisely the expression bounded in Equation (9), together with bounded terms at kk, the old support and rr. This gives Equation (102).

The corrected coordinates have the required upper bounds at nonzero vertices and vanish at the center if the base derivative vanishes. To apply binary transfer, we still need f,d∈O[G]f,d \in O[G] with dx=fxuxd_x = f_xu_x at every character. The required controls are a bound on v(f0(0))v(f_0(0)) and, at each fixed precision, a bound on the negative Laurent support of every fxf_x. The next lemma obtains those bounds from the old complex, whose size is bounded, rather than from the full growing conductor.

Lemma 13.22 (A uniform clearing factor for the Heegner family). For the element uu of Lemma 13.21, there are f,d∈O[G]f,d \in O[G] with dx=fxuxd_x = f_xu_x at every character, f0∈Λf_0 \in\Lambda, and v(f0(0))v(f_0(0)) uniformly bounded. For each fixed MM, the negative Laurent support of every fxf_x mod 2M2^M has a bound independent of bb and of the number of new primes.

Proof. First make the pairing functional integral up to a bounded multiplier. The class pp is integral. Lift 2a0p2^{a_0}p to the complex strict at the relaxed places and use integral duality against the relaxed complex. At rr and every new prime the full local complex over O[G]O[G] is contractible: its reduction at the maximal ideal is acyclic, by the local calculation in Lemma 13.4 and the root-type alternative. At the old active primes its cohomology is killed by a bounded power of 22, because inertia is minus identity. The old support is fixed. Thus a0a_0 is bounded independently of the new primes. After inverting 22, lifting is canonical. We obtain a closed representative of the paired functional over 2−a0O[G]2^{-a_0}O[G].

At augmentation, present the complex as the old complex, with no new primes, extended by the direct sum of their singular complexes. Each singular complex is a bounded-size block in degrees one and two, with differential AqA_q and determinant lq,0l_{q,0}. The differential is upper triangular with the old complex as a subcomplex. This graded free model lifts to RR: stabilize the finite free models, identify their augmentations, and lift the corresponding graded changes of basis. The lifts are invertible because the augmentation ideal lies in the Jacobson radical. Cancel the additional lifted unit disks before retaining the old-plus-singular grading. Their augmented cross terms are zero, so cancellation leaves precisely the displayed augmented model; the added disks do not enlarge its old part. The old model has bounded size, since h0h_0 is fixed and ω(k)\omega(k) is bounded. Indeed, the fixed-field Kummer and Schreier argument in Lemma 13.15, now retaining the fixed primes of h0h_0, bounds the residual global and local dimensions uniformly for ω(k)\omega(k) bounded. This size bound is separate from the central torsion-length bound used below.

Over O[G]O[G] the entire new-prime block is invertible. Schur elimination leaves a complex DD of the bounded old size, with augmentation exactly the old complex. For each AqA_q, the order of its residual determinant at t=0t = 0 is bounded uniformly. At a split prime this follows from the odd Frobenius exponent and the degree-two Frobenius polynomial; at a root-type prime the constant term is already nonzero. Every sign evaluation of the lifted block is its augmentation plus a matrix divisible by 22 with power-series entries. Therefore Lemma 11.2 bounds the negative Laurent support of the entries of every DxD_x modulo each fixed 2M2^M, independently of the number of blocks.

The integral central specialization of the old complex is controlled by the ordinary base Kummer complex, the fixed old conductor primes, and the bounded singular contributions at rr. Its rational H1H^1 and H2H^2 both have dimension one. Its torsion lengths are bounded by the finite Selmer quotient assumed in Theorem 3.3, together with bounded global torsion and these local contributions. Choose its elementary-divisor bases at the center and lift. Apply case (i) of Lemma 11.3 to DD, the projected cycle and paired functional. The eliminated large block contributes an O[G]O[G]-unit to the determinant, and the multiplier in (103) belongs to O[G]O[G]. Include both in the allowed factor η\eta of that lemma, so neither enters the clearing factor ff. The lemma gives d=fud = fu, a bounded central valuation for f0f_0, and the asserted pole bounds for fxf_x.

Proof of Theorem 3.3. The primitive ring-class product has odd functional-equation sign under the standing Heegner conditions. Suppose the base product does not have a simple zero. Its first derivative then vanishes. By Lemma 13.21, u0(0)=0u_0(0) = 0, whereas every nonzero vertex has central determinant valuation bounded by one constant B1B_1 independent of the family. By Lemma 13.22, the hypotheses of Lemma 11.5 hold with uniform central and pole bounds. Choose its fixed precision larger than B1B_1 plus twice the central bound, and then take the cube dimension sufficiently large. It supplies a nonzero vertex whose central valuation exceeds B1B_1, a contradiction. Thus the base product has a simple zero.

The unrestricted converse and Goldfeld’s densities

The two residual constructions now give the pointwise theorem. The density statement then requires only Smith’s Selmer distribution and an elementary change of counting convention.

Proof of Theorem 1.1. By Lemma 2.3, either E(Q)[2]≠0E(\mathbb{Q})[2] \ne0 or E[2]E[2] is irreducible. Theorem 7.13 proves a(E)=c2(E)a(E) = c_2(E) in the first case, and Theorem 9.1 proves it in the second. Both use the local Kummer conditions defining the corank in the statement. The isogeny choices in the rational-torsion proof preserve that corank and the LL-function by Lemma 2.2. Thus every curve in the theorem has analytic rank zero or one. Lemma 2.1 supplies the Mordell–Weil rank equality and finiteness of the whole Tate–Shafarevich group.

Proof of Corollary 1.3. Lemma 2.4 gives c2(E)=d2(E)c_2(E) = d_2(E) and shows that Sha⁡(E/Q)[2∞]\operatorname{Sha}(E/\mathbb{Q})[2^\infty] is divisible. Theorem 1.1 gives the rank equalities and whole-Sha finiteness. A finite divisible 2-group is zero, so its 2-primary part vanishes.

Lemma 14.1 (From integer to squarefree parameters). Let P\mathcal{P} be a property of nonzero signed integers unchanged by multiplication by an integer square. Suppose

A(X)=#{n∈Z:0<∣n∣≤X, P(n)}=2δX+o(X).A(X) = \#\{n \in\mathbb{Z} : 0 < |n| \le X,\ \mathcal{P}(n)\} = 2\delta X + o(X).

Then

S(X)=#{d∈D(X):P(d)}=2δζ(2)X+o(X).S(X) = \#\{d \in\mathcal{D}(X) : \mathcal{P}(d)\} = \frac{2\delta}{\zeta(2)} X + o(X).

In particular the property has density δ\delta among signed squarefree parameters ordered by absolute value.

Proof. Every nonzero integer has a unique expression n=m2dn=m^2d with m>0m>0 and dd signed squarefree. Thus

A(X)=∑m≤XS(X/m2),S(X)=∑m≤Xμ(m)A(X/m2).A(X)=\sum_{m\le\sqrt{X}}S(X/m^2),\qquad S(X)=\sum_{m\le\sqrt{X}}\mu(m)A(X/m^2).

The second equality follows by substituting the first and using ∑m∣rμ(m)=1r=1\sum_{m\mid r}\mu(m)=1_{r=1}. For a fixed integer MM, the terms with m≤Mm\le M, divided by XX, tend to 2δ∑m≤Mμ(m)/m22\delta\sum_{m\le M}\mu(m)/m^2. The remaining absolute contribution is at most

2X∑m>Mm−2,2X\sum_{m>M}m^{-2},

because A(Y)≤2⌊Y⌋≤2YA(Y)\le2\lfloor Y\rfloor\le2Y. First let XX and then MM tend to infinity. The absolutely convergent series ∑μ(m)/m2=1/ζ(2)\sum\mu(m)/m^2=1/\zeta(2) proves the formula. Applying it to the property always true gives #D(X)∼2X/ζ(2)\#\mathcal{D}(X)\sim2X/\zeta(2), proving the density assertion.

Proof of Theorem 1.2. Smith’s theorem states that, for every fixed elliptic curve E/QE/\mathbb{Q} and j=0,1j=0,1 [69],

#{n∈Z:0<∣n∣≤X, c2(E(n))=j}=X+o(X).\#\{n\in\mathbb{Z}:0<|n|\le X,\ c_2(E^{(n)})=j\}=X+o(X).

Quadratic twisting depends only on the squareclass, so Lemma 14.1 gives density 1/21/2 for each corank among the signed squarefree parameters.

For j=0,1j=0,1, Theorem 1.1 gives c2(E(d))=j⇒a(E(d))=jc_2(E^{(d)})=j\Rightarrow a(E^{(d)})=j, while Lemma 2.1 gives the converse implication. The analytic-rank counts therefore equal the corresponding corank counts exactly. The two densities sum to one. Their complement, the twists of analytic rank at least two, has density zero, and Lemma 2.1 gives the final rank and finiteness assertions on the density-one union.

References

  1. [1]Alexander J. Barrios, Manami Roy, Nandita Sahajpal, Darwin Tallana, Bella Tobin, and Hanneke Wiersema. Local data of elliptic curves under quadratic twist. Research in Number Theory, 11, 2025. doi: 10.1007/s40993-025-00650-w. URL https://link.springer.com/article/10.1007/s40993-025-00650-w. Article 75, 39 pp.DOI
  2. [2]Laurent Berger. Bloch and Kato’s exponential map: three explicit formulas. Documenta Mathematica, Extra Volume Kato:99–129, 2003. doi: 10.4171/DMS/3/3. URL https://ems.press/books/dms/250/4889.DOI
  3. [3]Bryan J. Birch and H. P. F. Swinnerton-Dyer. Notes on elliptic curves. II. Journal für die reine und angewandte Mathematik, 218:79–108, 1965. doi:10.1515/crll.1965.218.79.
  4. [4]Spencer Bloch and Kazuya Kato. L-functions and Tamagawa numbers of motives. In The Grothendieck Festschrift, Vol. I, volume 86 of Progress in Mathematics, pages 333–400. Birkhäuser Boston, Boston, MA, 1990. doi: 10.1007/978-0-8176-4574-8_9. URL https://math.stanford.edu/~conrad/ BSDseminar/refs/BKTamagawa.pdf.
  5. [5]Fedor A. Bogomolov. Points of finite order on an Abelian variety. Mathematics of the USSR-Izvestiya, 17(1):55–72, 1981. doi: 10.1070/IM1981v017n01ABEH001329. URL https://www.mathnet.ru/eng/im1843. Russian original published in 1980.DOI
  6. [6]Siegfried Bosch, Werner Lütkebohmert, and Michel Raynaud. Néron Models, volume 21 of Ergebnisse der Mathematik und ihrer Grenzgebiete, 3. Folge. Springer, Berlin–Heidelberg, 1990. doi: 10.1007/978-3-642-51438-8. URL https://link.springer.com/book/10.1007/978-3-642-51438-8.DOI
  7. [7]Christophe Breuil, Brian Conrad, Fred Diamond, and Richard Taylor. On the modularity of elliptic curves over ℚ: wild 3-adic exercises. Journal of the American Mathematical Society, 14(4):843–939, 2001. doi: 10.1090/S0894-0347-01-00370-8. URL https://www.ams.org/jams/2001-14-04/S0894-0347-01-00370-8/S0894-0347-01-00370-8.pdf.DOI
  8. [8]Daniel Bump, Solomon Friedberg, and Jeffrey Hoffstein. Nonvanishing theorems for L-functions of modular forms and their derivatives. Inventiones Mathematicae, 102 (3):543–618, 1990. doi: 10.1007/BF01233440. URL https://wstein.org/papers/bib/bump-friedberg-hoffstein-nonvanishing.pdf.DOI
  9. [9]Ashay Burungale and Christopher Skinner. A p-converse theorem for CM elliptic curves, 2024. URL https://arxiv.org/abs/2210.10730v3. Appendix A, pp. 51–54, to L. Alpöge, M. Bhargava and A. Shnidman, Integers expressible as the sum of two rational cubes, version 3.
  10. [10]Ashay Burungale, Francesc Castella, Christopher Skinner, and Ye Tian. p∞-Selmer groups and rational points on CM elliptic curves. Annales mathématiques du Québec, 46:325–346, 2022. doi: 10.1007/s40316-022-00203-y.DOI
  11. [11]Ashay A. Burungale and Ye Tian. p-converse to a theorem of Gross–Zagier, Kolyvagin and Rubin. Inventiones Mathematicae, 220(1):211–253, 2020. doi: 10.1007/s00222-019-00929-7.DOI
  12. [12]Ashay A. Burungale and Ye Tian. A rank zero p-converse to a theorem of Gross–Zagier, Kolyvagin and Rubin. Annals of Mathematics, 203(1):1–13, 2026. doi: 10.4007/annals.2026.203.1.1. URL https://annals.math.princeton.edu/2026/203-1/p01. Theorem numbering follows arXiv:2506.03465v2 (https://arxiv.org/abs/2506.03465v2).
  13. [13]Ashay A. Burungale, Francesc Castella, and Christopher Skinner. Base change and Iwasawa main conjectures for GL₂. International Mathematics Research Notices, 2025 (8):rnaf082, 2025. doi: 10.1093/imrn/rnaf082. URL https://web.math.ucsb.edu/~castella/BCS-print.pdf.DOI
  14. [14]Li Cai, Jie Shu, and Ye Tian. Explicit Gross–Zagier and Waldspurger formulae. Algebra & Number Theory, 8(10):2523–2572, 2014. doi: 10.2140/ant.2014.8.2523. URL https://msp.org/ant/2014/8-10/ant-v8-n10-p05-p.pdf.DOI
  15. [15]Henri Carayol. Sur les représentations ℓ-adiques associées aux formes modulaires de Hilbert. Annales scientifiques de l’École Normale Supérieure, 19(3):409–468, 1986. doi: 10.24033/asens.1512. URL https://www.numdam.org/item/10.24033/asens.1512/.DOI
  16. [16]J. W. S. Cassels. Arithmetic on curves of genus 1. VIII. On conjectures of Birch and Swinnerton-Dyer. Journal für die reine und angewandte Mathematik, 217:180–199, 1965. doi: 10.1515/crll.1965.217.180. URL https://doi.org/10.1515/crll.1965.217.180.
  17. [17]Francesc Castella and Xin Wan. Perrin-Riou’s main conjecture for elliptic curves at supersingular primes. Math. Annalen, 389:2595–2636, 2024. doi: 10.1007/s00208-023-02711-w.DOI
  18. [18]Francesc Castella, Giada Grossi, Jaehoon Lee, and Christopher Skinner. On the anti-cyclotomic Iwasawa theory of rational elliptic curves at Eisenstein primes. Inventiones Mathematicae, 227(2):517–580, 2022. doi: 10.1007/s00222-021-01072-y.DOI
  19. [19]Seth Chaiken. A combinatorial proof of the all minors matrix tree theorem. SIAM Journal on Algebraic and Discrete Methods, 3(3):319–329, 1982. doi: 10.1137/0603033.DOI
  20. [20]Claude Chevalley. Démonstration d’une hypothèse de M. Artin. Abhandlungen aus dem Mathematischen Seminar der Universität Hamburg, 11:73–75, 1935. doi: 10.1007/BF02940714. URL https://doi.org/10.1007/BF02940714.
  21. [21]Christophe Cornut and Dimitar Jetchev. Liftings of reduction maps for quaternion algebras. Bulletin of the London Mathematical Society, 45(2):370–386, 2013. doi: 10.1112/blms/bds098. URL https://arxiv.org/abs/1012.0725v1. Preprint locators refer to arXiv:1012.0725v1.
  22. [22]Marius Crainic. On the perturbation lemma, and deformations, 2004. URL https://arxiv.org/abs/math/0403266v1. Version 1, 16 March 2004.
  23. [23]Pierre Deligne. Formes modulaires et représentations ℓ-adiques. In Séminaire Bourbaki, 1968/69, volume 179 of Lecture Notes in Mathematics, pages 139–172. Springer, Berlin, 1971. URL https://www.numdam.org/item/SB_1968-1969__11__139_0/. Exposé 355, February 1969.
  24. [24]Max Deuring. Die Typen der Multiplikatorenringe elliptischer Funktionenkörper. Abhandlungen aus dem Mathematischen Seminar der Hansischen Universität, 14:197–272, 1941. doi: 10.1007/BF02940746. URL https://doi.org/10.1007/BF02940746.
  25. [25]Tim Dokchitser and Vladimir Dokchitser. On the Birch–Swinnerton-Dyer quotients modulo squares. Annals of Mathematics, 172(1):567–596, 2010. doi: 10.1007/annals.2010.17.567. URL https://annals.math.princeton.edu/wp-content/uploads/annals-v172-n1-p11-p.pdf.
  26. [26]V. G. Drinfeld. Two theorems on modular curves. Functional Analysis and Its Applications, 7(2):155–156, 1973. doi: 10.1007/BF01078890. URL https://www.mathnet.ru/rus/faa4222. Russian original: Funktsional. Anal. i Prilozhen. 7(2), 83–84.DOI
  27. [27]Keqin Feng and Maosheng Xiong. On elliptic curves y² = x³ − n²x with rank zero. Journal of Number Theory, 109(1):1–26, 2004. doi: 10.1016/j.jnt.2003.12.015.DOI
  28. [28]Bruce Ferrero and Lawrence C. Washington. The Iwasawa invariant μₚ vanishes for abelian number fields. Annals of Mathematics, 109(2):377–395, 1979. doi: 10.2307/1971116. URL https://doi.org/10.2307/1971116.
  29. [29]Stephen Gelbart and Hervé Jacquet. A relation between automorphic representations of GL(2) and GL(3). Annales scientifiques de l’École Normale Supérieure, 11(4):471–542, 1978. doi:10.24033/asens.1355.
  30. [30]Dorian Goldfeld. Conjectures on elliptic curves over quadratic fields. In Melvyn B. Nathanson, editor, Number Theory, Carbondale 1979, volume 751 of Lecture Notes in Mathematics, pages 108–118. Springer, Berlin, 1979. doi: 10.1007/BFb0062705. URL https://www.math.columbia.edu/~goldfeld/ConjecturesonEllipticCurves.pdf.
  31. [31]Benedict H. Gross and Don B. Zagier. Heegner points and derivatives of L-series. Inventiones Mathematicae, 84(2):225–320, 1986. doi: 10.1007/BF01388809. URL https://wiki.epfl.ch/waldspurger/documents/gross-zagier.pdf.DOI
  32. [32]D. R. Heath-Brown. A mean value estimate for real character sums. Acta Arithmetica, 72(3):235–275, 1995. doi: 10.4064/aa-72-3-235-275. URL https://doi.org/10.4064/aa-72-3-235-275.
  33. [33]Jeffrey Hoffstein and Wenzhi Luo. Nonvanishing of L-series and the combinatorial sieve. Mathematical Research Letters, 4(2–3):435–444, 1997. doi: 10.4310/MRL.1997.v4.n3.a12. URL https://www.intlpress.com/site/pub/files/_fulltext/journals/mrl/1997/0004/0003/MRL-1997-0004-0003-a012.pdf. With an appendix by David E. Rohrlich.DOI
  34. [34]Benjamin Howard. The Heegner point Kolyvagin system. Compositio Mathematica, 140(6):1439–1472, 2004. doi:10.1112/S0010437X04000569; text at arXiv:1202.6340v1.DOI
  35. [35]Henryk Iwaniec. On the order of vanishing of modular L-functions at the critical point. Journal de théorie des nombres de Bordeaux, 2(2):365–376, 1990. doi: 10.5802/jtnb.33. URL https://www.numdam.org/item/JTNB_1990__2_2_365_0/.DOI
  36. [36]Kevin James. L-series with nonzero central critical value. Journal of the American Mathematical Society, 11(3):635–641, 1998. doi: 10.1090/S0894-0347-98-00263-X. URL https://www.math.clemson.edu/~kevja/PAPERS/JAMS.pdf.DOI
  37. [37]Dimitar Jetchev and Ben Kane. Equidistribution of Heegner points and ternary quadratic forms. Mathematische Annalen, 350(3):501–532, 2011. doi: 10.1007/s00208-010-0568-5. URL https://arxiv.org/abs/0908.3905v1. Section numbering follows arXiv:0908.3905v1.
  38. [38]Kazuya Kato. p-adic Hodge theory and values of zeta functions of modular forms. In Pierre Berthelot, Jean-Marc Fontaine, Luc Illusie, Kazuya Kato, and Michael Rapoport, editors, Cohomologie p-adiques et applications arithmétiques (III), number 295 in Astérisque, pages 117–290. Société Mathématique de France, 2004. URL https://www.numdam.org/item/AST_2004__295__117_0/.
  39. [39]Timo Keller and Mulun Yin. p-converse theorems for elliptic curves of potentially good ordinary reduction at Eisenstein primes, 2024. arXiv:2410.23241v1.arxiv.org/abs/2410.23241
  40. [40]V. A. Kolyvagin. Euler systems. In Pierre Cartier, Luc Illusie, Nicholas M. Katz, Gérard Laumon, Yuri I. Manin, and Kenneth A. Ribet, editors, The Grothendieck Festschrift, Volume II, volume 87 of Progress in Mathematics, pages 435–483. Birkhäuser, Boston, 1990. URL https://link.springer.com/chapter/10.1007/978-0-8176-4575-5_11. Linked chapter is the 2007 reprint.
  41. [41]Daniel Kriz. Supersingular main conjectures, Sylvester’s conjecture and Goldfeld’s conjecture, 2022. URL https://arxiv.org/abs/2002.04767v5. Version 5; first posted in 2020.
  42. [42]Daniel Kriz and Chao Li. Goldfeld’s conjecture and congruences between Heegner points. Forum of Mathematics, Sigma, 7:e15, 2019. doi: 10.1017/fms.2019.9. 80 pp.DOI
  43. [43]Daniel Kriz and Asbjørn Christian Nordentoft. Horizontal p-adic L-functions, 2025. URL https://arxiv.org/abs/2310.20678v3. Version 3; first posted in 2023.
  44. [44]Sumit Kumar, Kummari Mallesham, Prahlad Sharma, and Saurabh Kumar Singh. Moments of derivatives of modular L-functions. The Quarterly Journal of Mathematics, 75(2):715–734, 2024. doi: 10.1093/qmath/haae028. URL https://arxiv.org/abs/2303.16864v2. Preprint locators refer to arXiv:2303.16864v2.
  45. [45]Serge Lang. Algebraic groups over finite fields. American Journal of Mathematics, 78 (3):555–563, 1956. doi: 10.2307/2372673.DOI
  46. [46]J. S. Milne. Arithmetic Duality Theorems. BookSurge, second edition, 2006. author’s electronic edition.
  47. [47]J. S. Milne. Algebraic number theory, 2020. URL https://www.jmilne.org/math/CourseNotes/ANT.pdf. Version 3.08, July 19, 2020.
  48. [48]J. S. Milne. Class field theory, 2020. URL https://www.jmilne.org/math/CourseNotes/CFT.pdf. Version 4.03, August 6, 2020.
  49. [49]J. S. Milne. Elliptic Curves. World Scientific, second edition, 2021. URL https://www.jmilne.org/math/Books/EC2.pdf. Author’s electronic version.
  50. [50]Paul Monsky. Generalizing the Birch–Stephens theorem. I. Modular curves. Mathematische Zeitschrift, 221:415–420, 1996. doi: 10.1007/PL00004518. URL https://link.springer.com/article/10.1007/PL00004518.DOI
  51. [51]M. Ram Murty and V. Kumar Murty. Mean values of derivatives of modular L-series. Annals of Mathematics, 133(3):447–475, 1991. doi: 10.2307/2944316. URL https://mast.queensu.ca/~murty/murty-murty-annals.pdf.DOI
  52. [52]Jan Nekovář. Selmer complexes, volume 310 of Astérisque. Société Mathématique de France, 2006. ISBN 978-2-85629-227-3. doi: 10.24033/ast.717. URL https://www.numdam.org/item/AST_2006__310__R1_0/.
  53. [53]Jürgen Neukirch. Algebraic Number Theory, volume 322 of Grundlehren der mathematischen Wissenschaften. Springer, Berlin, 1999. doi: 10.1007/978-3-662-03983-0. URL https://link.springer.com/book/10.1007/978-3-662-03983-0. Translated from the German by Norbert Schappacher.DOI
  54. [54]Ken Ono and Christopher Skinner. Non-vanishing of quadratic twists of modular L-functions. Inventiones Mathematicae, 134(3):651–660, 1998. doi: 10.1007/s002220050275. URL https://uva.theopenscholar.com/files/ken-ono/files/037_8.pdf.DOI
  55. [55]OpenAI. The Selmer converse for elliptic curves at every prime. OpenAI Math Release preprint OAI:The-Selmer-converse-for-elliptic-curves-at-every-prime-September-24-2026, 2026.
  56. [56]OpenAI. The mean analytic rank of quadratic twists of elliptic curves. OpenAI Math Release preprint OAI:The-mean-analytic-rank-of-quadratic-twists-of-elliptic-curves-September-23-2026, 2026.
  57. [57]OpenAI. The two-primary Birch–Swinnerton-Dyer formula in Selmer corank at most one. OpenAI Math Release preprint OAI:The-two-primary-Birch-Swinnerton-Dyer-formula-in-Selmer-corank-at-most-one-September-24-2026, 2026.
  58. [58]Aprameyo Pal and Carlos de Vera-Piquero. Pullbacks of Saito–Kurokawa lifts and a central value formula for degree 6 L-series. Documenta Mathematica, 24:1935–2036, 2019. doi: 10.4171/DM/719. URL https://ems.press/journals/dm/articles/8965649.DOI
  59. [59]Alberto Perelli and Jacek Pomykala. Averages of twisted elliptic L-functions. Acta Arithmetica, 80(2):149–163, 1997. doi: 10.4064/aa-80-2-149-163. URL https://matwbn.icm.edu.pl/ksiazki/aa/aa80/aa8024.pdf.DOI
  60. [60]Soma Purkait. On Shimura’s decomposition. arXiv:1205.7086v2 [math.NT], 2013. URL https://arxiv.org/abs/1205.7086v2. Version 2, 4 April 2013; first posted in 2012.
  61. [61]Maksym Radziwiłł and K. Soundararajan. Moments and distribution of central L-values of quadratic twists of elliptic curves. Inventiones Mathematicae, 202(3):1029–1068, 2015. doi: 10.1007/s00222-015-0582-z. URL https://www.math.mcgill.ca/radziwill/QuadraticTwists.pdf.DOI
  62. [62]Jean-Pierre Serre. Abelian ℓ-adic representations and elliptic curves. W. A. Benjamin, New York, 1968. URL https://www.math.mcgill.ca/darmon/courses/18-19/gs/serre-mcgill.pdf. McGill University lecture notes, written with the collaboration of Willem Kuyk and John Labute.
  63. [63]Romyar Sharifi. Iwasawa theory. Author’s lecture notes, n.d. URL https://www.math.ucla.edu/~sharifi/iwasawa.pdf. Undated; version accessed 23 September 2026.
  64. [64]Goro Shimura. The critical values of certain zeta functions associated with modular forms of half-integral weight. Journal of the Mathematical Society of Japan, 33(4):649–672, 1981. doi: 10.2969/jmsj/03340649. URL https://www.jstage.jst.go.jp/article/jmath1948/33/4/33_4_649/_pdf.DOI
  65. [65]Christopher Skinner. A converse to a theorem of Gross, Zagier, and Kolyvagin. Annals of Mathematics, 191(2):329–354, 2020. doi: 10.4007/annals.2020.191.2.1. primary text.DOI
  66. [66]Christopher Skinner and Eric Urban. The Iwasawa main conjectures for GL₂. Inventiones Mathematicae, 195(1):1–277, 2014. doi: 10.1007/s00222-013-0448-1.DOI
  67. [67]Alexander Smith. The congruent numbers have positive natural density, 2016. URL https://arxiv.org/abs/1603.08479v2. Version 2, 29 March 2016.
  68. [68]Alexander Smith. 2∞-Selmer groups, 2∞-class groups, and Goldfeld’s conjecture, 2017. URL https://arxiv.org/abs/1702.02325v2. Version 2.
  69. [69]Alexander Smith. The Birch and Swinnerton-Dyer conjecture implies Goldfeld’s conjecture, 2025. URL https://arxiv.org/abs/2503.17619v1. arXiv:2503.17619, version 1.
  70. [70]Alexander Smith. The distribution of ℓ∞-Selmer groups in degree ℓ twist families I. Journal of the American Mathematical Society, 39(1):1–72, 2026. doi: 10.1090/jams/1062. URL https://arxiv.org/abs/2207.05674v2. Preprint locators refer to arXiv:2207.05674v2.
  71. [71]Alexander Smith. The distribution of ℓ∞-Selmer groups in degree ℓ twist families II. Journal of the American Mathematical Society, 39(2), 2026. URL https://arxiv.org/abs/2207.05143v2. Preprint locators refer to arXiv:2207.05143v2.
  72. [72]John Tate. On the conjectures of Birch and Swinnerton-Dyer and a geometric analog. Séminaire Bourbaki, 9:415–440, 1966. URL https://www.numdam.org/item/SB_1964-1966__9__415_0/. Exposé 306.
  73. [73]Ye Tian. Congruent numbers and Heegner points. Cambridge Journal of Mathematics, 2(1):117–161, 2014. doi: 10.4310/CJM.2014.v2.n1.a4.DOI
  74. [74]Ye Tian, Xinyi Yuan, and Shou-Wu Zhang. Genus periods, genus points and congruent number problem. Asian Journal of Mathematics, 21(4):721–774, 2017. doi: 10.4310/AJM.2017.v21.n4.a5. URL https://intlpress.com/site/pub/files/_fulltext/journals/ajm/2017/0021/0004/AJM-2017-0021-0004-a005.pdf.DOI
  75. [75]Vinayak Vatsal. Rank-one twists of a certain elliptic curve. Mathematische Annalen, 311(4):791–794, 1998. doi: 10.1007/s002080050209. URL https://www.math.ubc.ca/~vatsal/research/der.PDF.DOI
  76. [76]Jean-Loup Waldspurger. Correspondance de Shimura. Journal de Mathématiques Pures et Appliquées, 59(1):1–132, 1980.
  77. [77]Jean-Loup Waldspurger. Sur les coefficients de Fourier des formes modulaires de poids demi-entier. Journal de Mathématiques Pures et Appliquées, 60(4):375–484, 1981. URL https://mate.dm.uba.ar/~nsirolli/files/waldspurger.pdf.
  78. [78]Jean-Loup Waldspurger. Correspondances de Shimura. In Zbigniew Ciesielski and Czesław Olech, editors, Proceedings of the International Congress of Mathematicians, Warszawa, 1983, volume 1, pages 525–531, Warszawa and Amsterdam, 1984. PWN–Polish Scientific Publishers and Elsevier Science Publishers. URL https://www.imj-prg.fr/wp-content/uploads/2020/prix/waldspurger1983.pdf.
  79. [79]Ewald Warning. Bemerkung zur vorstehenden arbeit. Abhandlungen aus dem Mathematischen Seminar der Universität Hamburg, 11:76–83, 1935. doi: 10.1007/BF02940715. URL https://doi.org/10.1007/BF02940715.
  80. [80]André Weil. Sur certains groupes d’opérateurs unitaires. Acta Mathematica, 111:143–211, 1964. doi: 10.1007/BF02391012. URL https://doi.org/10.1007/BF02391012.
  81. [81]Qiyao Yu. p-converse to a theorem of Gross–Zagier, Kolyvagin, and Rubin for small primes. Senior thesis, California Institute of Technology, 2021. URL https://thesis.caltech.edu/14225/. Theorem 1, p. 2; acknowledgements, p. iii.
  82. [82]Wei Zhang. Selmer groups and the indivisibility of Heegner points. Cambridge Journal of Mathematics, 2(2):191–253, 2014. doi: 10.4310/CJM.2014.v2.n2.a2.DOI

Paper details

Contents