Introduction

Hilbert’s tenth problem over the rational numbers asks for a decision procedure for rational zeros of polynomials with integer coefficients. The number of variables is part of the input.

Theorem 1.1. There is no algorithm which, given a polynomial f∈Z[X1,…,Xn]f \in\mathbb{Z}[X_1,\ldots,X_n], with nn part of the input, decides whether ff has a zero in Qn\mathbb{Q}^n.

Historical setting

Hilbert’s tenth problem, as stated in his 1900 list of mathematical problems, asks for a finite procedure deciding whether a polynomial equation with integer coefficients has a solution in the ordinary integers [31], Problem 10]. Its negative resolution grew out of a much stronger description of polynomial equations. A relation on the positive integers is recursively enumerable if an algorithm can list exactly its satisfying tuples. It is Diophantine if membership can be expressed by the existence of additional positive integers satisfying a polynomial equation with integer coefficients. Thus a Diophantine description expresses a condition entirely through polynomial solvability.

Davis, Putnam, and Robinson proved in 1961 that every recursively enumerable relation has such a representation if exponentiation is also allowed. They reduced the ordinary polynomial representation theorem to a growth criterion for a Diophantine relation [14], Theorem and Corollary 3]. Matiyasevich supplied the required growth in 1970 through a Diophantine description of a Fibonacci relation, completing the theorem that every recursively enumerable relation on the positive integers is Diophantine [37]. The equivalent all-integer decision problem is therefore undecidable. This representation theorem explains the strength of the result: integer polynomial equations can encode arbitrary recursively enumerable conditions.

Letting the unknowns range over Q\mathbb{Q} changes the decision problem. Enumerating rational tuples will eventually find any rational zero, but gives no answer for an equation without one. A possible transfer of the integer theorem would be an existential definition of membership in Z\mathbb{Z} using only the ring operations of Q\mathbb{Q}. One could then replace each integer unknown by a rational unknown subject to that membership condition, obtaining an equivalent rational existential question. More generally, a Diophantine model of integer arithmetic represents the integers by a Diophantine subset of some Qk\mathbb{Q}^k, with Diophantine relations for addition and multiplication. Such a model also translates integer equations into rational existential questions [8], Definition 3.1 and Observation 3.3]. Here the defining polynomial equations and all their witnesses are interpreted over Q\mathbb{Q}. These constructions are sufficient routes to undecidability; the decision problem does not require its solution to produce either one.

Julia Robinson showed in 1949 that the integers are first-order definable in the rationals using addition and multiplication. Her formula uses both universal and existential quantifiers, and her work also proves undecidability of the full first-order theory of rational arithmetic [60], Theorems 3.1 and 4.2]. Later work reduced the quantifier complexity. Poonen defined Z\mathbb{Z} in Q\mathbb{Q} by a positive formula with two universal quantifiers followed by seven existential quantifiers [54], Theorem 4.1]. Koenigsmann then gave a universal definition of Z\mathbb{Z}; equivalently, its complement in Q\mathbb{Q} is Diophantine. His result also implies undecidability of the ∀∃\forall\exists theory [33], Theorem 1 and Corollaries 2–3]. These results give substantial control of definitions inside Q\mathbb{Q}, but do not supply the existential membership condition for the direct transfer above.

The distinction between a Diophantine model and undecidability also has a geometric setting. Mazur conjectured that, for a variety over Q\mathbb{Q}, the closure of its rational points in its real points has only finitely many connected components [38], Conjecture 3]. He observed that this conjecture would rule out a Diophantine definition of Z\mathbb{Z} in Q\mathbb{Q}. Cornelissen and Zahidi showed that it would also rule out a Diophantine model of integer arithmetic in a finite Cartesian power of Q\mathbb{Q} [8], Theorem 3.6]. These obstructions to definitions and models do not by themselves rule out a negative answer to the rational decision problem.

One approach studies the subrings Z[S−1]⊆Q\mathbb{Z}[S^{-1}] \subseteq\mathbb{Q}, whose denominators use only primes in SS. Poonen constructed disjoint recursive sets of primes T1,T2T_1,T_2, each of natural density zero, such that positive-integer arithmetic has a Diophantine model in Z[S−1]\mathbb{Z}[S^{-1}] whenever S⊇T1S \supseteq T_1 and S∩T2=∅S \cap T_2 = \varnothing. Hilbert’s tenth problem is undecidable for every such ring. Taking SS to be the complement of T2T_2 gives a recursive set of density one and a proper subring of Q\mathbb{Q} [53], Theorem 1.3]. The construction uses selected multiples of a point on a rank-one elliptic curve whose real coordinates approximate integers.

Eisenträger, Miller, Park, and Shlapentokh later constructed computably presentable subrings Z[S−1]\mathbb{Z}[S^{-1}], including examples in which SS has density one, whose Hilbert’s tenth problem is Turing equivalent to that over Q\mathbb{Q} [19], Theorem 3.17]. For these examples, a Turing reduction from integer solvability would already give a Turing reduction from integer solvability to the rational field problem. The density of the inverted primes alone therefore does not settle the relation to the field problem.

Elliptic curves also give a transfer between rings of integers of number fields. Poonen proved that, for F⊆KF \subseteq K, an elliptic curve E/FE/F with

rank⁡E(F)=rank⁡E(K)=1\operatorname{rank} E(F) = \operatorname{rank} E(K) = 1

makes OF\mathcal{O}_F Diophantine in OK\mathcal{O}_K [52], Theorem 1]. If Z\mathbb{Z} is already Diophantine in OF\mathcal{O}_F, undecidability transfers to OK\mathcal{O}_K. Mazur and Rubin pursued this route through quadratic twists and Selmer groups, conditional on the conjectured evenness of dim⁡F2Sha⁡(E/L)[2]\dim_{\mathbb F_2}\operatorname{Sha}(E/L)[2]. Assuming this for every elliptic curve over every number field, they obtained undecidability for every infinite finitely generated Z\mathbb{Z}-algebra [39], Theorem 1.13, Corollary 1.14, and Theorem 8.1].

This number-field program has recently been completed unconditionally. Koymans and Pagano combined two-descent with additive combinatorics to prove that Z\mathbb{Z} is Diophantine in the ring of integers of every number field, and that Hilbert’s tenth problem is undecidable for every infinite finitely generated Z\mathbb{Z}-algebra [34]. Alpöge, Bhargava, Ho, and Shnidman gave another route: for every quadratic extension K/FK/F of number fields, they construct an abelian variety over FF with positive rank unchanged over KK, and deduce that Z\mathbb{Z} is Diophantine in every number-field ring of integers [2], Theorem 1.1 and Corollary 1.2]. The field Q\mathbb{Q} is not a finitely generated Z\mathbb{Z}-algebra, so these results concern a different class of rings from the field in Theorem 1.1.

The elliptic approach also illuminates nearby rational decision problems. In a rank-one group, a multiple nPnP of a nontorsion point can represent the integer nn, and local coordinates or heights can reveal arithmetic information about that index. Cornelissen and Zahidi used elliptic divisibility sequences and existential valuation predicates in this direction. Under a conjectural odd primitive-divisor property for one such sequence, they obtained a Diophantine model of (Z,+,∣)(\mathbb{Z},+,\mid) and proved undecidability of a positive Π2\Pi_2 fragment with one universal quantifier [9], Conjecture 3.16 and Theorems 3.17 and 5.3]. The assertion with one universal quantifier uses the correction by Cornelissen and Shlapentokh [7], Remark 2.3 in the author version].

Garcia-Fritz, Pasten, and Vidaux instead adjoined predicates comparing the logarithmic heights of rational tuples to the rational ring language. In this expanded language they gave a positive existential interpretation of N\mathbb{N}, and hence proved undecidability; comparisons between tuples of length at most three suffice [22], Theorems 1.1–1.2]. Their construction uses elliptic canonical heights to encode consecutive squares. The present paper concerns ordinary rational polynomial solvability, and its height estimates enter the proof of that ordinary statement.

Proof strategy

Constant polynomials can be decided directly. For each nonconstant integral polynomial ff, we construct an effectively generated sequence of finite tests. Each test can be answered by finitely many rational-solvability queries, and the sequence satisfies

f has an integer zero⟺every test succeeds.f\text{ has an integer zero}\quad\Longleftrightarrow\quad\text{every test succeeds}.

An integer zero supplies witnesses for all the tests. If a rational-solvability algorithm existed, we could run two searches in parallel: enumeration of integer zeros, and enumeration of tests until one fails. The arithmetic work is to prove that a failed test exists whenever ff has no integer zero.

Suppose all the finite tests succeed. Compactness then gives a ring RR containing a zero a=(a1,…,an)\mathbf{a}=(a_1,\ldots,a_n) of ff, embedded in an elementary extension of the rational field; we use a tilde for embedded values and points. The ambient extension also carries the integer and valuation data, height functions, elliptic multiple maps, and functions for finite products used in the proof. The tests attach an elliptic point TaT_a to each a∈Ra\in R, compatibly with addition, and require TaT_a to be nonidentity when a≠0a\ne0. The embedded points lie in the transferred copy of a fixed infinite cyclic subgroup ZP\mathbb{Z}P of finite index in a rank-one elliptic group, with T1=PT_1=P. This defines unique indices

T~a=η(a)P,η(a)∈∗Z.\widetilde{T}_a=\eta(a)P,\qquad\eta(a)\in{}^{*}\mathbb{Z}.

Here ∗Z{}^{*}\mathbb{Z} is the ambient integer structure, whose elements may be nonordinary. The point axioms make η:R→∗Z\eta:R\to{}^{*}\mathbb{Z} injective and additive, with η(1)=1\eta(1)=1, but η\eta need not respect multiplication. Thus the modeled equation does not yet give an equation satisfied by the indices.

Two local comparisons address this obstruction. The primary test compares an embedded ring value with a quotient of truncated elliptic logarithms. The formal logarithm can recover the corresponding quotient of point indices once that quotient is integral at the prime. A second comparison, on the conjugate elliptic curve, supplies this control using only additivity of η\eta. Where the comparisons apply, they show that every a~\widetilde{a} is integral at the prime and agrees with η(a)\eta(a) to the prescribed precision. Each pair uses auxiliary choices that work for every ring element, which is essential for the later uniform bound.

The proof arranges these comparisons at primes detected by a height estimate. Fix the five rational points of P1\mathbf P^1 supplied by that estimate and primitive integral linear forms vanishing at them; call these the contact forms. For a rational point s=(u:v)s=(u:v) outside this set, written in coprime integer coordinates, let M(s)M(s) be the product, without repetition, of the nonexceptional primes at which one of these forms has odd valuation. We call the primes counted by M(s)M(s) its contact primes. The estimate bounds the absolute logarithmic Weil height by

h(s)≤HM(s)ch(s)\leq H M(s)^c

for fixed constants H,cH,c. This definition and estimate transfer to the ambient extension. At each prescribed precision, the theory represents every ring element as a sum of three fractions of ring elements, called slopes, and equips factors of their contact forms with the local conditions. A prime-pattern theorem supplies the required primes for these representations in the ordinary integer model. A separate existential condition controls the parity of possible denominator valuations outside a fixed finite set. In a model satisfying the tests, consider the three slopes supplied for any ring element at that precision. After the further fixed exclusions, the parity condition lets the proof apply the local comparisons at every contact prime of those slopes. Enlarging the exceptional set changes the height constant but preserves the exponent cc.

Set

δ=f(η(a1),…,η(an)),B=max⁡(1,∣η(a1)∣,…,∣η(an)∣).\delta=f\bigl(\eta(a_1),\ldots,\eta(a_n)\bigr),\qquad B=\max\bigl(1,|\eta(a_1)|,\ldots,|\eta(a_n)|\bigr).

If δ=0\delta=0, elementarity gives an ordinary integer zero of ff. Otherwise δ\delta is a nonzero ambient integer whose size is bounded by a fixed polynomial in BB. Choose one ordinary precision KK large enough in terms of the degree of ff and the exponent cc. For any A∈RA\in R, choose a tested representation at precision KK. Every contact prime of its slopes divides this same δ\delta to order at least KK, because all modeled root coordinates agree locally with their indices. The height estimate then bounds each slope height by a constant times BB. The logarithmic height inequality for their sum gives

h(A~)≪fBfor every A∈R,h(\widetilde{A})\ll_f B\qquad\text{for every }A\in R,

with one ordinary constant.

For each nonzero root coordinate aja_j, consider its attached point TajT_{a_j}. Applying the uniform bound to the ring elements representing x(Taj)x(T_{a_j}) gives h(x(η(aj)P))≪fBh(x(\eta(a_j)P))\ll_f B. The transferred canonical-height comparison for PP makes this height grow quadratically in ∣η(aj)∣|\eta(a_j)|. If B>1B>1, choose jj with ∣η(aj)∣=B|\eta(a_j)|=B; the two bounds give B2≪fBB^2\ll_f B. If B=1B=1, the required bound is immediate. Thus all root indices lie in an ordinary finite interval. Additivity and injectivity identify the modeled root coordinates with those ordinary integers, contradicting δ≠0\delta\ne0. This proves the finite-test equivalence and hence the undecidability theorem.

The detailed reduction in Section 2 makes these steps precise. Section 3 proves the pole-parity condition; its passage from two-descent data to rational points uses the pointwise 2-converse [48] and the Cassels–Tate pairing [6]. Section 4 proves the five-point height estimate. Its modularity step uses the odd regular Fontaine–Mazur theorem at 2 [49], whose statement has no hypothesis on the residual image. Section 5 proves the rank-one and local elliptic results, and Section 6 supplies the prime patterns and simultaneous local witnesses for the ordinary integer model. Section 7 gives Turing degree 0′0' and the quartic normal form.

At rational primes, valuations are normalized by vq(q)=1v_q(q)=1, with vq(0)=+∞v_q(0)=+\infty. The support of a nonzero rational number is the set of primes dividing its numerator or denominator in lowest terms. The notation X≪YX\ll Y means X≤CYX\le CY for a positive constant depending only on the fixed data in the statement; additional dependencies are indicated when they occur.

Finite rational tests for integer solvability

We construct the finite rational tests announced in the introduction and prove that success of every test forces an ordinary integer zero. The construction has an ordinary integer model. Conversely, compactness will embed a model of all the tests in an elementary extension of Q\mathbb{Q}, where arithmetic restrictions on its ring values will force an integer solution. The later sections prove the arithmetic inputs used here.

The elliptic point data first give an additive assignment of integer indices. A local comparison will recover those indices from ring values and determine the two local test conditions.

Elliptic indices and the local comparison

Fix the number field, involution, and elliptic curve

F=Q(2),d=75−532,E: y2=x3−d2x,F={\mathbb{Q}}(\sqrt2),\qquad d=75-53\sqrt2,\qquad E:\ y^2=x^3-d^2x,

where σ\sigma is the nontrivial automorphism of F/QF/\mathbb{Q}. The following result, proved in Section 5, supplies the integer indices.

Proposition 2.1. The group E(F)E(F) has rank one. Consequently there exist a positive integer mm and a nontorsion point P∈E(F)P \in E(F) such that

mE(F)=ZP.mE(F) = \mathbb{Z}P.

We fix such mm and PP once and for all.

We now describe the point data that the recursive theory will impose. Let RR be an integral domain of characteristic zero for which 2∉Frac⁡(R)\sqrt{2} \notin\operatorname{Frac}(R), and write

RF=R[2],FR=Frac⁡(R)(2).R_F = R[\sqrt{2}], \qquad F_R = \operatorname{Frac}(R)(\sqrt{2}).

For each a∈Ra \in R, consider a point Ta∈E(FR)T_a \in E(F_R) subject to

T0=O,T1=P,Ta+a′=Ta+Ta′(a,a′∈R),Ta∈mE(FR)(a∈R),a≠0⟹Ta is finite and x(Ta)y(Ta)≠0.\begin{gathered} T_0=O,\qquad T_1=P,\qquad T_{a+a'}=T_a+T_{a'}\quad(a,a'\in R),\\ T_a\in mE(F_R)\quad(a\in R),\\ a\ne0\Longrightarrow T_a\text{ is finite and }x(T_a)y(T_a)\ne0. \end{gathered}

The theory will supply six unary ring-valued functions x0,x1,x2,y0,y1,y2x_0,x_1,x_2,y_0,y_1,y_2. For a≠0a \ne0, they are required to satisfy x2(a)y2(a)≠0x_2(a)y_2(a) \ne0 and

x(Ta)=x0(a)+x1(a)2x2(a),y(Ta)=y0(a)+y1(a)2y2(a).x(T_a) = \frac{x_0(a) + x_1(a)\sqrt{2}}{x_2(a)}, \qquad y(T_a) = \frac{y_0(a) + y_1(a)\sqrt{2}}{y_2(a)}.

Their values at a=0a = 0 are unrestricted, since T0=OT_0 = O. In the integer model we will take Ta=aPT_a = aP. Representing the coordinates by ring elements will also let a uniform height bound on RR control their heights.

For the arithmetic analysis, consider an elementary extension of the ordinary many-sorted structure containing Q,Z,R,F{\mathbb{Q}},{\mathbb{Z}},{\mathbb{R}},F, the prime and valuation relations, the height functions, the elliptic multiple maps, and the finite-product functions. We call elements of the original structure ordinary; starred sorts satisfy the same first-order statements with ordinary parameters. For the moment, suppose that RR embeds in the rational sort ∗Q{}^{*}\mathbb{Q} of such an extension. Its fraction-field interpretation embeds FRF_R in ∗F{}^{*}F. A tilde denotes the image of a ring element, field element, or point. Later compactness will supply an extension and an embedded ring with these properties.

The identity mE(F)=ZPmE(F) = \mathbb{Z}P transfers to this extension: every point of mE(∗F)mE({}^{*}F) has a unique expression nPnP, with n∈∗Zn \in{}^{*}\mathbb{Z}. Define

Ta~=η(a)P.\widetilde{T_a} = \eta(a)P.

The group-law axioms give

η(a+a′)=η(a)+η(a′),η(1)=1.\eta(a+a') = \eta(a) + \eta(a'), \qquad\eta(1) = 1.

If η(a)=0\eta(a) = 0, then Ta=OT_a = O, and the finite-point axiom forces a=0a = 0. Thus η:R→∗Z\eta:R \to{}^{*}\mathbb{Z} is injective and additive. Conjugating (2.4) gives Ta~σ=η(a)Pσ\widetilde{T_a}^{\sigma} = \eta(a)P^{\sigma}. We make no assumption about η(aa′)\eta(aa').

For nonzero h∈Rh \in R, the index ratio of ThaT_{ha} and ThT_h is η(ha)/η(h)\eta(ha)/\eta(h), which need not equal η(a)\eta(a). We will recover this ratio locally from point parameters, and use a second comparison to identify it with η(a)\eta(a) to the required precision.

For a finite point with y≠0y \ne0, put z=−x/yz=-x/y, and set z(O)=0z(O)=0. Every nonzero multiple of PP avoids the two-torsion points, so z(nP)z(nP) is defined for every integer nn. Write

ℓ(Z)=Z+∑t≥2ctZt∈F[[Z]],ℓK(Z)=Z+∑2≤t≤KctZt\ell(Z)=Z+\sum_{t\ge2}c_tZ^t\in F[[Z]],\qquad\ell_K(Z)=Z+\sum_{2\le t\le K}c_tZ^t

for the formal logarithm in this parameter and its truncation through degree KK. The truncations are effectively computable from the fixed equation. Section 5 proves the following uniform statements about integer multiples of the fixed FF-rational points P,PσP,P^\sigma.

Proposition 2.2. There is a fixed finite set of rational primes SES_E with the following properties. Let p∉SEp\notin S_E, let vv be any place of FF above pp, normalized by v(p)=1v(p)=1, and let n,n′∈Zn,n'\in\mathbb{Z}, with n′≠0n'\ne0. Assume nP,n′PnP,n'P reduce to OO at vv. Then

v(z(nP)z(n′P))=vp(n/n′).v\left(\frac{z(nP)}{z(n'P)}\right)=v_p(n/n').

For every integer K≥1K\ge1, if in addition p>K+1p>K+1 and vp(n/n′)≥0v_p(n/n')\ge0, then ℓK(z(n′P))≠0\ell_K(z(n'P))\ne0 and

v(ℓK(z(nP))ℓK(z(n′P))−nn′)≥K.v\left(\frac{\ell_K(z(nP))}{\ell_K(z(n'P))}-\frac{n}{n'}\right)\ge K.

Both assertions also hold at the same place vv after replacing E,P,ℓKE,P,\ell_K by Eσ,Pσ,ℓKσE^\sigma,P^\sigma,\ell_K^\sigma and imposing the corresponding reduction-to-OO hypotheses on the conjugate points. Here and below the valuation of zero is +∞+\infty, so n=0n=0 is included.

The two estimates provide different kinds of local information. Equation (2.6) determines the valuation of an index ratio from the point parameters without assuming that the ratio is integral. Once an index ratio is known to be integral, (2.7) approximates it by a ratio of finite polynomial evaluations. The next lemma combines both forms of control.

Reduction to OO has its usual valuation meaning, transferred to the elementary extension. Only the stated assertions about integer multiples of the fixed FF-rational points P,PσP,P^\sigma and evaluations of the finite polynomials ℓK,ℓKσ\ell_K,\ell_K^\sigma are transferred; no infinite formal series is evaluated in the extension.

Lemma 2.3 (Local comparison). Let K≥1K\ge1 be an ordinary integer. Let qq be a prime of the ambient integer sort ∗Z{}^*\mathbb{Z}, possibly nonordinary, with q∉SEq\notin S_E and q>K+1q>K+1, and let v∗v_* be a place of ∗F{}^*F above qq, normalized by v∗(q)=1v_*(q)=1. Suppose there are nonzero h,j0∈Rh,j_0\in R, chosen independently of aa, such that for every a∈Ra\in R:

(i) The points T~h,T~ha\widetilde{T}_h,\widetilde{T}_{ha} reduce to OO at v∗v_*, the value ℓK(z(T~h))\ell_K(z(\widetilde{T}_h)) is nonzero, and

v∗(ℓK(z(T~ha))ℓK(z(T~h))−a~)≥K.v_*\left(\frac{\ell_K(z(\widetilde{T}_{ha}))}{\ell_K(z(\widetilde{T}_h))}-\widetilde{a}\right)\ge K.

(ii) The points T~j0σ\widetilde{T}_{j_0}^\sigma and T~(h−4)aσ\widetilde{T}_{(h-4)a}^\sigma reduce to OO on the conjugate curve at the same place v∗v_*, and

v∗(z(T~(h−4)aσ)z(T~j0σ))≥K.v_*\left(\frac{z(\widetilde{T}_{(h-4)a}^\sigma)}{z(\widetilde{T}_{j_0}^\sigma)}\right)\ge K.

Then every a~\widetilde{a} is integral at qq, and

vq(a~−η(a))≥K(a∈R).v_q(\widetilde{a}-\eta(a))\ge K\qquad(a\in R).

Here z(O)=0z(O)=0. The denominator in (ii) is nonzero because j0≠0j_0\ne0 and the nonzero points in (2.2) have nonzero xx- and yy-coordinates.

Proof. Transfer the formal-parameter valuation equality of Proposition 2.2 to the conjugate points at v∗v_*. The comparison in (ii) gives

vq(η((h−4)a)η(j0))≥K.v_q\left(\frac{\eta((h-4)a)}{\eta(j_0)}\right) \ge K.

The denominator is a nonzero ambient integer, so its qq-valuation is nonnegative. Consequently

vq(η((h−4)a))≥K.v_q(\eta((h-4)a)) \ge K.

Put Va=η(ha)V_a=\eta(ha). Additivity applied to (h−4)a=ha−4a(h-4)a=ha-4a, including the case a=1a=1, gives

Va≡4η(a)(modqK),V1≡4(modqK).V_a \equiv4\eta(a) \pmod{q^K}, \qquad V_1 \equiv4 \pmod{q^K}.

Since q≠2q\ne2, V1V_1 is a qq-unit. The ambient integers Va,η(a)V_a,\eta(a) are qq-integral, and hence

Va/V1 is q-integral,Va/V1≡η(a)(modqK).V_a/V_1\text{ is }q\text{-integral},\qquad V_a/V_1\equiv\eta(a)\pmod{q^K}.

The primary points have indices V1V_1 and VaV_a. They reduce to OO, the denominator index is nonzero, and their ratio is now known to be integral. The truncated-logarithm assertion of Proposition 2.2 therefore gives

v∗(ℓK(z(T~ha))ℓK(z(T~h))−VaV1)≥K.v_*\left(\frac{\ell_K(z(\widetilde{T}_{ha}))}{\ell_K(z(\widetilde{T}_h))}-\frac{V_a}{V_1}\right)\ge K.

The comparison in (i) relates this same logarithm ratio to a~\widetilde{a}. Combining it with the last display and (2.9) proves the required congruence, since v∗v_* restricts to vqv_q on ∗Q{}^{*}\mathbb{Q}. It also proves qq-integrality of a~\widetilde{a}. Zero numerator indices are covered by the convention vq(0)=+∞v_q(0)=+\infty.

The same hh must serve every aa, because the calculation uses both aa and 1. We will impose ring-language versions of these comparisons and obtain their valuation hypotheses at primes detected by a height estimate.

Contact primes and ordinary integer witnesses

Throughout the paper, hh denotes the absolute logarithmic Weil height. The next input identifies primes whose product controls the height of a rational point. It is proved in Section 4.

Theorem 2.4 (Five-point height estimate). There exist five distinct points C⊂P1(Q)\mathcal C\subset\mathbf P^1(\mathbb Q), including ∞\infty, a finite set SS of rational primes, and constants H,c>0H,c>0 with the following property. For each b∈Cb\in\mathcal C, choose a primitive integral linear form Lb(U,V)L_b(U,V) vanishing at bb, with L∞(U,V)=VL_\infty(U,V)=V. For s=(u:v)∈P1(Q)∖Cs=(u:v)\in\mathbf P^1({\mathbb{Q}})\setminus\mathcal C, let MS(s)M_S(s) be the product, taken without repetition, of primes q∉Sq\notin S for which at least one of the integers

vq(Lb(u,v))−min⁡{vq(u),vq(v)},b∈C,v_q(L_b(u,v))-\min\{v_q(u),v_q(v)\},\qquad b\in\mathcal C,

is odd. Here vq(q)=1v_q(q)=1 and vq(0)=+∞v_q(0)=+\infty. Then

h(s)≤HMS(s)c.{h}(s)\le H M_S(s)^c.

Multiplying (u,v)(u,v) by a nonzero rational scalar adds the same valuation to both terms in (2.10), so each contact order is independent of the chosen homogeneous coordinates. It is nonnegative after scaling the coordinates to be integral and primitive at qq. With fixed primitive integral coordinates, the nonzero integers Lb(u,v)L_b(u,v) have only finitely many prime divisors, so the product defining MS(s)M_S(s) is finite.

For a positive integer KK and a nonzero integer ee satisfying MS(s)K∣eM_S(s)^K \mid e, the estimate gives

h(s)≤H∣e∣c/K.{h}(s)\le H|e|^{c/K}.

In the reduction, the same polynomial error will play the role of ee for representations of every ring element. This is why the exponent cc must be fixed, although its precise value is not needed. The following immediate consequence permits the further fixed exclusions needed by the local tests.

Corollary 2.5. If S′⊃SS' \supset S is any fixed finite set of primes, then

h(s)≤H(∏q∈S′∖Sq)cMS′(s)c(s∈P1(Q)∖C).{h}(s)\le H\left(\prod_{q\in S'\setminus S}q\right)^c M_{S'}(s)^c \qquad(s\in\mathbf P^1({\mathbb{Q}})\setminus\mathcal C).

In particular enlarging the exceptional set changes the constant but leaves the exponent unchanged.

Proof. Every prime counted by MS(s)M_S(s) is either counted by MS′(s)M_{S'}(s) or belongs to S′∖SS'\setminus S. Thus MS(s)≤(∏q∈S′∖Sq)MS′(s)M_S(s) \le\left(\prod_{q\in S'\setminus S}q\right)M_{S'}(s), and Theorem 2.4 applies. □

To apply this estimate uniformly, the theory will write each ring element as a sum of three fractions and impose local conditions on factors of their contact forms. The following ordinary integer result supplies witnesses for those axioms. It is a direct consequence of the prime-pattern lemma and the Chinese remainder calculation proved in Section 6.

Corollary 2.6 (Ordinary contact representations). Let K⊂Z>0\mathcal K \subset\mathbb{Z}_{>0} be the finite multiplier set supplied by Lemma 6.1 in Section 6. It has the following property. For every integer K≥1K \ge1, every A∈ZA \in\mathbb{Z}, and every real lower bound Y0>0Y_0 > 0, there exist integers u1,u2,vu_1,u_2,v, with v≠0v \ne0, such that, on setting u3=Av−u1−u2u_3=Av-u_1-u_2, the following hold.

(1) Representation and primes. Each of the thirteen numbers*

v,Lb(ui,v)(1≤i≤3, b∈C∖{∞})v,\qquad L_b(u_i,v)\quad(1\le i\le3,\ b\in\mathcal C\setminus\{\infty\})

equals εkr\varepsilon k r, where ε∈{1,−1}\varepsilon\in\{1,-1\}, k∈Kk\in\mathcal K, and r>Y0r>Y_0 is a positive rational prime. Every such rr splits in FF, is a prime of good reduction for both EE and EσE^\sigma, lies outside SES_E, and satisfies r>K+1r>K+1.

(2) Witnesses at each place. For each occurrence of a prime rr in this list and each of the two places vrv_r of FF above it, there are nonzero integers h,j0h,j_0, chosen independently of a∈Za\in\mathbb Z, such that every a∈Za\in\mathbb Z satisfies conditions (i) and (ii) of Lemma 2.3 in the ordinary setting: take R=ZR=\mathbb Z, its identity embedding in the ordinary structure, Ta=aPT_a=aP, q=rq=r, and v∗=vrv_*=v_r, normalized by vr(r)=1v_r(r)=1. In this specialization the tildes disappear. The choices of h,j0h,j_0 may differ at different occurrences and at the two places.

The set K\mathcal K is independent of K,A,Y0K,A,Y_0.

The two places in part (2) are the two residue branches above a split prime. At either one, conditions (i) and (ii) use the two conjugate curves at that same place. If p\mathfrak p is the prime ideal of Z[2]\mathbb Z[\sqrt{2}] corresponding to vrv_r, its valuation ring is (Z[2])p(\mathbb Z[\sqrt{2}])_{\mathfrak p}, with uniformizer rr. Thus the two valuation inequalities in part (2) are exactly membership in rK(Z[2])pr^K(\mathbb Z[\sqrt{2}])_{\mathfrak p}; for a finite indicated point, reduction to OO is equivalent to 1/x∈r(Z[2])p1/x\in r(\mathbb Z[\sqrt{2}])_{\mathfrak p}. We now encode these ordinary witnesses by formulas that also make sense for a general ring.

A recursive theory with an ordinary integer model

Let T\mathcal{T} be a theory in a countable recursive expansion of the language of rings. Its ring RR is required to be an integral domain of characteristic zero with 2∉Frac⁡(R)\sqrt{2} \notin\operatorname{Frac}(R). Add the six unary ring-valued functions above. Interpret T0T_0 as OO and, for a≠0a \ne0, require the two fractions in (2.3) to define the coordinates of Ta∈E(FR)T_a \in E(F_R), with both denominators nonzero. Impose the point conditions (2.2).

Use the five points C\mathcal C, primitive contact forms LbL_b, and finite multiplier set K\mathcal{K} of the preceding inputs. For each ordinary integer K≥1K \ge1, add the following representation axiom. For every A∈RA \in R there exist u1,u2,v∈Ru_1,u_2,v \in R, with v≠0v \ne0, such that, on setting

u3=Av−u1−u2,u_3 = Av-u_1-u_2,

each member of

v,Lb(ui,v)(1≤i≤3, b∈C∖{∞})v,\qquad L_b(u_i,v)\quad(1 \le i \le3,\ b \in C \setminus\{\infty\})

equals εkr\varepsilon kr, where ε∈{1,−1}\varepsilon\in\{1,-1\}, k∈Kk \in\mathcal{K}, and r∈Rr \in R has the following properties. The choices of rr and its auxiliary data are made separately for the different members of the list.

First require r≠0r \ne0, rRrR proper, and R/rRR/rR a field. Require Br∈RB_r \in R satisfying

Br2≡2(modrR),2Br invertible in R/rR.B_r^2 \equiv2 \pmod{rR},\qquad2B_r\text{ invertible in }R/rR.

These conditions define two maximal ideals of RFR_F:

p±=ker⁡(RF⟶R/rR, 2⟼±Br).\mathfrak{p}_{\pm}=\ker\left(R_F\longrightarrow R/rR,\ \sqrt{2}\longmapsto\pm B_r\right).

They are the two residue branches to be tested. In the integer model they correspond to the two places of FF above a supplied split prime rr. In a general model they are defined by the quotient field, independently of an ambient valuation.

For each p∈{p+,p−}\mathfrak{p}\in\{\mathfrak{p}_+,\mathfrak{p}_-\}, require nonzero h,j0∈Rh,j_0\in R, chosen at that branch and independently of aa, such that the following hold for every a∈Ra\in R. A point is called formal for this localization if it is OO, or if 1/x∈r(RF)p1/x\in r(R_F)_{\mathfrak{p}}.

(i) The points Th,ThaT_h,T_{ha} are formal for this localization, ℓK(z(Th))≠0\ell_K(z(T_h))\ne0, and

ℓK(z(Tha))ℓK(z(Th))−a∈rK(RF)p.\frac{\ell_K(z(T_{ha}))}{\ell_K(z(T_h))}-a \in r^K(R_F)_{\mathfrak p}.

(ii) The points Tj0σ,T(h−4)aσT_{j_0}^{\sigma},T_{(h-4)a}^{\sigma} are formal for the conjugate curve at the same localization, and

z(T(h−4)aσ)z(Tj0σ)∈rK(RF)p.\frac{z(T_{(h-4)a}^{\sigma})}{z(T_{j_0}^{\sigma})}\in r^{K}(R_F)_{\mathfrak{p}}.

Here z(O)=0z(O)=0, and the denominator in (2.16) is nonzero by j0≠0j_0\ne0 and (2.2). The pairs h,j0h,j_0 may differ between the two branches. The scheme contains every ordinary KK; the termination proof will later select a single precision after ff is fixed.

All these conditions have recursive first-order expressions in RR. The absence of 2\sqrt{2} from Frac⁡(R)\operatorname{Frac}(R) is expressed by

∀a,b∈Rb≠0⟹a2≠2b2.\forall a,b\in R\quad b\ne0\Longrightarrow a^2\ne2b^2.

Elements of RFR_F are pairs of ring elements, and elements of FRF_R are fractions (A+B2)/D(A+B\sqrt{2})/D, with A,B,D∈RA,B,D\in R and D≠0D\ne0. Equations with fixed coefficients in FF can therefore be separated into two coordinates and cleared of denominators. The elliptic group law, including the identity and exceptional addition cases, is given by finitely many field equations and inequations. Membership in mE(FR)mE(F_R) is expressed by existential coordinates for a point whose mm-multiple is the prescribed point. These conditions are ring formulas under the same interpretation.

Saying that R/rRR/rR is a field means that 1∉rR1 \notin rR and every element outside rRrR has an inverse modulo rRrR. For D′∈FRD' \in F_R, the assertion

D′∈ri(RF)p±D'\in r^i(R_F)_{\mathfrak p_\pm}

means that D′=riX/YD'=r^iX/Y for some X,Y∈RFX,Y\in R_F such that the evaluation of YY under 2↦±Br\sqrt{2}\mapsto\pm B_r is nonzero modulo rRrR, hence a unit in that field. These representations and inverse conditions are expressed by ring quantifiers. The exponent ii is fixed in each axiom; neither variable exponentiation nor a valuation function is part of T\mathcal{T}.

Lemma 2.7. The theory T\mathcal{T} is recursive and has a model whose ring is Z\mathbb{Z}. In this model Ta=aPT_a=aP for every integer aa.

Proof. The ring and elliptic axioms hold for Z\mathbb{Z} with Ta=aPT_a=aP. For nonzero aa, the coordinates lie in FF and admit integer numerator and denominator representatives; choose arbitrary integer values for the six coordinate functions at a=0a=0. Nonzero multiples of the nontorsion point PP avoid OO and the two-torsion points, so their xx- and yy-coordinates are nonzero.

Fix K≥1K\ge1 and A∈ZA\in\mathbb{Z}. Corollary 2.6 supplies (2.12) with the required fixed multipliers and positive split primes. For each such rr, the quotient Z/rZ\mathbb{Z}/r\mathbb{Z} is a field. Splitness supplies a root BrB_r of 22 modulo rr, and 2Br2B_r is invertible because rr is odd. The ideals (2.14) correspond to the two places above rr. At each one, the corollary supplies nonzero h,j0h,j_0, fixed for all integers aa, with the required formal points and both valuation comparisons. Its localization interpretation gives exactly (2.15) and (2.16). Thus every representation axiom holds.

The coefficients of ℓK\ell_K are computable from the fixed equation, and the interpretations and axiom schemes above are effective. The finite sets, fixed integers, rational coefficients, and coordinates of PP are finitely many exact constants that can be hardcoded in the theory. Their existence suffices for the existence of the decision procedure constructed below; no effective search for those fixed choices is required. No list of all true arithmetic sentences is used.

Finite rational tests and compactness

The finite tests will also impose a positive existential condition on every ring value. This input holds on all integers and controls the parity of possible poles; Section 3 constructs it.

Proposition 2.8. There are a positive existential formula Φ(b)\Phi(b) in the language of rings, with fixed rational coefficients, and a finite set S1S_1 of rational primes such that:

  1. Q⊨Φ(b)\mathbb{Q}\models\Phi(b) for every b∈Zb\in\mathbb{Z};

  1. if b∈Q×b\in\mathbb{Q}^{\times} and Q⊨Φ(b)\mathbb{Q}\models\Phi(b), then, for every q∉S1q\notin S_1, the inequality vq(b)<0v_q(b)<0 implies vq(b)∈2Zv_q(b)\in2\mathbb{Z}.

The second property does not rule out even pole orders. Its later use rests on a simple product observation. If q∉S1q\notin S_1 and nonzero a,c∈Qa,c\in\mathbb{Q} satisfy Φ(a)\Phi(a) and Φ(ac)\Phi(ac), with both vq(a)v_q(a) and vq(ac)v_q(ac) negative, then

vq(c)=vq(ac)−vq(a)∈2Z.v_q(c)=v_q(ac)-v_q(a)\in2\mathbb{Z}.

Section 2.5 applies this observation when Φ\Phi holds on every element of the ring supplied by the finite tests.

An integer zero can therefore supply rational witnesses for all the conditions imposed below. In the converse direction, pole parity will connect a contact prime in the ambient integer structure to one of the tested localizations of the embedded ring.

Assume that an algorithm decides rational solvability of integral polynomials. Given f∈Z[X1,…,Xn]f \in\mathbb{Z}[X_1,\ldots,X_n], the constant case can be settled immediately, so assume ff is nonconstant. Add constants a=(a1,…,an)\mathbf{a}=(a_1,\ldots,a_n) and the equation f(a)=0f(\mathbf{a})=0 to TT, and Skolemize the resulting theory. This is effective for a recursive first-order theory: after prenex conversion, each existential quantifier is replaced by a function of the preceding universal variables. All resulting function symbols are ring-valued. The Skolemized axioms are universal sentences with quantifier-free matrices.

A ground term is a term with no variables, built from the named constants using the ring operations and added functions in this language. A compatible assignment of values to all ground terms will interpret the added functions on the ring of term values. Enumerate these terms, associate a rational variable to each, and enumerate the following constraints:

  • (a) the constants 00, 11 and the ring operations have their usual values;

  • (b) equal input tuples have equal outputs for each function symbol;

  • (c) every ground instance of every universal axiom holds;

  • (d) the value of every ground term satisfies the positive existential formula Φ\Phi from Proposition 2.8.

The witnesses for Φ\Phi in (d) are auxiliary rational variables. They are not values of additional functions of the ring and do not create new ground terms subject to (d). The same distinction applies to the inverse variables introduced only when translating a finite test to polynomial equations; they are not added to the term-generated ring.

Every finite initial part of this list is decidable by the assumed rational-solvability algorithm. Indeed, after introducing the witnesses for Φ\Phi, the finite collection is an existential Boolean combination of polynomial equalities and inequations. An inequation g≠0g \ne0 becomes gy=1gy=1 with a new variable; a finite Boolean formula can be put into disjunctive normal form; and a conjunction g1=⋯=gs=0g_1=\cdots=g_s=0 is equivalent over Q\mathbb{Q} to ∑igi2=0\sum_i g_i^2=0. Clearing fixed rational denominators gives finitely many integral polynomial queries.

If any test fails, report that ff has no integer zero. This answer is sound: an integer zero extends the model of Lemma 2.7 and admits Skolem functions; all its ground-term values are integers and hence satisfy Φ\Phi.

Lemma 2.9. If every finite rational test succeeds, there exist an ambient elementary extension of the many-sorted structure specified in §2.1, a model RR of T\mathcal T, a tuple a∈Rn\mathbf{a} \in R^n with f(a)=0f(\mathbf{a})=0, and an embedding R↪∗QR \hookrightarrow{}^{*}\mathbb{Q} into its rational sort such that every element of the image satisfies Φ\Phi.

Proof. Take the ordinary many-sorted structure specified in §2.1, with all the indicated functions and relations. Expand this ambient structure by constants naming all ordinary elements in their respective sorts. Its elementary diagram consists of all first-order sentences in its language that are true in the expanded structure. Use this diagram and add constants assigning a value to every ground term of the Skolemized ring language, the ring and functionality constraints, all ground universal instances, and Φ\Phi for each term value. Every finite subset has a model: its finitely many constraints are among a successful rational test, and they can be interpreted in the ordinary structure. Finitely many sentences of its elementary diagram are already true there. The compactness theorem therefore supplies a simultaneous assignment in an elementary extension; see [36].

Let RR be the set of values of the ground terms. Constraint (a) makes it a subring of ∗Q{}^*\mathbb{Q}. Interpret each added function by applying its symbol to representative ground terms. Constraint (b) makes the result independent of representatives. Every element of RR is represented by a ground term, so (c) implies every universal Skolemized axiom in RR. Its reduct is the required model of T\mathcal{T}, and (d) gives the pole-parity condition on every element. The interpretation of fraction fields extends the embedding to FR↪∗FF_R \hookrightarrow{}^*F.

The ambient diagram is used only in this existence argument. It is not required to be recursive and is never queried by the finite rational tests.

We now analyze any model and embedding supplied by Lemma 2.9. All starred objects refer to its one ambient extension. The point conditions give the additive injection η\eta of (2.4)-(2.5).

Odd valuations select a tested branch

The height radical supplies primes of the ambient integer sort, whereas the tests are imposed at ideals above an element r∈Rr \in R. We now connect these two kinds of data. Fix an ordinary precision K≥1K \ge1. Enlarge the finite exceptional set SS in the height estimate to a finite set SKS_K containing: the exceptional set for Φ\Phi, the supports of all multipliers in K\mathcal{K}, the primes needed to keep the contact forms distinct with their required unit determinants, the bad or ramified primes of the elliptic data and FF, and the finitely many primes excluded by Proposition 2.2 at precision KK.

Write MK(s)=MSK(s)M_K(s) = M_{S_K}(s) for the radical with these larger exceptions. Corollary 2.5 keeps the exponent unchanged: if M(s)=MS(s)M(s) = M_S(s) is the original radical, then

M(s)≤(∏q∈SK∖Sq)MK(s),h(s)≤HKMK(s)cM(s)\le\left(\prod_{q\in S_K\setminus S}q\right)M_K(s), \qquad {h}(s)\le H_K M_K(s)^c

with an ordinary constant HKH_K. Enlarge cc to a positive integer once and for all if necessary.

Choose the representation axiom at precision KK for any A∈RA \in R, and put s~i=(u~i:v~)\widetilde{s}_i = (\widetilde{u}_i:\widetilde{v}). All its contact forms are nonzero, so s~i∉C\widetilde s_i\notin\mathcal C. Consider any ambient prime qq counted in some MK(s~i)M_K(\widetilde{s}_i). Here and below a radical, prime, or valuation on starred sorts is the transfer of its ordinary definition.

Let t=min⁡{vq(u~i),vq(v~)}t = \min\{v_q(\widetilde{u}_i), v_q(\widetilde{v})\}. At q∉SKq \notin S_K, the minimum of the valuations of the five contact forms equals tt: all their coefficients are integral and a pair has unit determinant. Since some contact depth is odd, these five valuations cannot all have the same parity. In particular one of them is odd. For its expression εkr\varepsilon kr in (2.12), kk is a qq-unit, and hence

vq(r~) is odd.v_q(\widetilde{r})\text{ is odd.}

The odd valuation links this ring element rr to the ambient prime qq, but it does not make the tested localization a subring of the ambient valuation ring: RR may have denominators at qq. We will quotient the value group by the convex subgroup generated by the negative valuations of nonzero ring elements. Pole parity ensures that the odd value of rr survives positively in this quotient. The center of the resulting valuation will then select one of the two tested branches.

Lemma 2.10. For the prime qq and element rr in (2.18), there is a branch p∈{p+,p−}\mathfrak{p} \in\{\mathfrak{p}_+,\mathfrak{p}_-\} of that representation axiom and an ambient place v∗v_* of ∗F{}^*F over qq such that, for every ordinary integer l≥1l \ge1 and every D′∈FRD' \in F_R,

D′∈rl(RF)p⟹v∗(D~′)≥l.D'\in r^l(R_F)_{\mathfrak p} \quad\Longrightarrow\quad v_*(\widetilde D')\ge l.

Every point formal for this tested localization actually reduces to OO for v∗v_*.

Proof. Let JJ be the convex subgroup of ∗Z{}^*\mathbb{Z} generated by the negative values of vqv_q on R~∖{0}\widetilde{R}\setminus\{0\}. Thus γ∈J\gamma\in J if ∣γ∣|\gamma| is bounded by a finite sum of absolute values of such negative values. This definition is external; we will use it only to construct a valuation on the embedded ring, not as part of an algorithm or a transferred formula.

Every valuation of a nonzero ring element that lies in JJ is even. If J=0J=0, this is immediate. Otherwise, given a≠0a\ne0 with vq(a~)∈Jv_q(\widetilde{a})\in J, finite products of ring elements having negative value give b∈R∖{0}b\in R\setminus\{0\} with vq(b~)<−∣vq(a~)∣v_q(\widetilde{b})<-|v_q(\widetilde{a})|. Both b~\widetilde{b} and a~b~\widetilde{a}\widetilde{b} have negative valuation. The soundness of Φ\Phi, transferred from Proposition 2.8, says that these two valuations are even. Their difference vq(a~)v_q(\widetilde{a}) is therefore even as well.

By (2.18), vq(r~)v_q(\widetilde{r}) is outside JJ; it is positive, because every negative ring value lies in JJ. Extend vqv_q to an ambient place v∗v_* on ∗F{}^*F. Outside the fixed ramified primes, its value group is still ∗Z{}^*\mathbb{Z} with the same normalization, by transfer of the corresponding ordinary place facts. Coarsen it to the ordered quotient ∗Z/J{}^*\mathbb{Z}/J, obtaining w∗w_*. This coarsened valuation is nonnegative on R~\widetilde{R}: all its negative original values become zero. It is also nonnegative on R~F\widetilde{R}_F, since 2\sqrt{2} is integral.

The pullback of the center on the embedded RFR_F is

p={x∈RF:w∗(x~)>0}.\mathfrak{p}=\{x\in R_F:w_*(\widetilde{x})>0\}.

It is a proper prime ideal, and it contains rr because w∗(r~)>0w_*(\widetilde{r})>0. On the other hand,

RF/rRF≃(R/rR)[X]/(X2−2)≃(R/rR)×(R/rR),R_F/rR_F\simeq(R/rR)[X]/(X^2-2) \simeq(R/rR)\times(R/rR),

where the last isomorphism uses Br2=2B_r^2=2 and the invertibility of 2Br2B_r. A prime of this product is one of its two maximal ideals. Consequently p\mathfrak{p} is exactly one of the tested branch ideals p±\mathfrak{p}_{\pm}.

If D′=rlX/YD'=r^lX/Y as in (2.17), then Y∉pY\notin\mathfrak{p}, so its image has w∗w_*-value zero. Thus

w∗(D~′)≥lw∗(r~).w_*(\widetilde{D}')\ge l w_*(\widetilde{r}).

For D′=0D'=0, (2.19) is automatic. Otherwise, if J=0J=0, the displayed inequality gives v∗(D~′)≥lvq(r~)≥lv_*(\widetilde{D}')\ge l v_q(\widetilde{r})\ge l. If J≠0J\ne0, its convexity implies that it contains every ordinary integer. A positive value in the ordered quotient is represented by an ambient integer larger than every element of JJ; the same inequality again gives v∗(D~′)≥lv_*(\widetilde{D}')\ge l.

Finally, a tested finite formal point has 1/x∈r(RF)p1/x\in r(R_F)_{\mathfrak{p}}, so its actual xx-valuation is negative. At the good integral model this is exactly the condition for reduction to OO. The identity point has that reduction as well.

Index congruences at every contact prime

Proposition 2.11. Fix an ordinary K≥1K\ge1 and use the exceptional set SKS_K above. Choose a representation supplied at precision KK for an arbitrary A∈RA\in R, and put s~i=(u~i:v~)\widetilde{s}_i=(\widetilde{u}_i:\widetilde{v}). For every prime qq of ∗Z{}^*\mathbb{Z} counted by any MK(s~i)M_K(\widetilde{s}_i), and every a∈Ra\in R, the element a~\widetilde{a} is integral at qq and

vq(a~−η(a))≥K.v_q(\widetilde{a}-\eta(a))\ge K.

Proof. The odd-contact argument selects a factor rr with odd qq-valuation. Lemma 2.10 supplies one of its tested branches and a place v∗v_* above qq. At this branch the theory supplies nonzero h,j0h,j_0, fixed for all a∈Ra\in R. Every tested formal point is an actual formal point at v∗v_*, for its own curve. The same lemma sends the memberships (2.15) and (2.16) to the two valuation comparisons of Lemma 2.3, each at precision KK and at this same place. The primary logarithm denominator is nonzero by its axiom and the embedding; the conjugate parameter denominator is nonzero by j0≠0j_0\ne0 and the point conditions. Finally q∉SKq\notin S_K ensures q∉SEq\notin S_E and q>K+1q>K+1. All hypotheses of Lemma 2.3 therefore hold, and it gives the assertion.

The height contradiction

Proposition 2.12. Let f∈Z[X1,…,Xn]f \in\mathbb{Z}[X_1,\ldots,X_n] be nonconstant. If every finite system of rational constraints constructed in §2.4 for ff is solvable, then ff has a zero in Zn\mathbb{Z}^n.

Proof. Choose the model supplied by Lemma 2.9, with its root tuple a\mathbf{a} and the additive map η\eta of (2.4)–(2.5). Set

δ=f(η(a1),…,η(an))∈∗Z.\delta=f(\eta(a_1),\ldots,\eta(a_n))\in{}^*\mathbb{Z}.

If δ=0\delta=0, the ambient integer sort satisfies ∃x∈Zn f(x)=0\exists\mathbf{x}\in\mathbb{Z}^n\ f(\mathbf{x})=0; by elementarity the ordinary integers satisfy that sentence. It remains to consider δ≠0\delta\ne0.

Write

B=max⁡(1,∣η(a1)∣,…,∣η(an)∣),D=max⁡(1,deg⁡f).B=\max(1,|\eta(a_1)|,\ldots,|\eta(a_n)|),\qquad D=\max(1,\deg f).

For an ordinary constant Cf>0C_f>0, transfer of the elementary polynomial bound gives

∣δ∣≤CfBD.|\delta|\le C_fB^D.

Choose an ordinary integer K≥cDK\ge cD, where cc is the fixed positive integer exponent of the height estimate. All exceptions and constants below refer to this fixed KK.

Figure 1 summarizes how the chosen representations for all A∈RA\in R use the same δ\delta.

Diagram showing the use of one nonzero delta for every A in R

Figure 1. The use of one nonzero δ\delta for every A∈RA\in R. All slopes shown come from the representation chosen at the fixed ordinary precision KK, and MKM_K uses the fixed exceptional set for KK. The comparison holds for every a∈Ra\in R, so it applies to the fixed root tuple. The implied constant in the final bound is ordinary and independent of AA and a\mathbf{a}.

For any A∈RA\in R, take its representation at precision KK and any prime qq counted in any MK(s~i)M_K(\widetilde s_i). Proposition 2.11 applies to each aja_j. Both the embedded coordinates and their integer indices are qq-integral. Since f(a~)=0f(\widetilde{\mathbf a})=0 in the ambient field and the coefficients of ff are integers, their coordinatewise congruences give

vq(δ)≥K.v_q(\delta)\ge K.

For each fixed slope, (2.23) now holds for every ambient prime counted by its radical. This is the internal universal premise in the transfer of the ordinary divisibility fact: if every prime in a squarefree product divides an integer to order at least KK, then the KKth power of that product divides the integer. Using the transferred finite-product function gives

MK(s~i)K∣δ.M_K(\widetilde s_i)^K\mid\delta.

The coarsenings may have been chosen externally one prime at a time; only the universal assertion just established enters this transferred implication. Although AA and its representation were arbitrary, the integer δ\delta is the same for all of them. As δ≠0\delta\ne0, (2.24) and (2.22) give

MK(s~i)c≤∣δ∣c/K≤Cfc/KBcD/K≪fB.M_K(\widetilde s_i)^c \le |\delta|^{c/K} \le C_f^{c/K}B^{cD/K}\ll_f B.

The height estimate therefore implies

h(s~i)≪fB.{h}(\widetilde s_i)\ll_f B.

Since v≠0v \ne0 and u1+u2+u3=Avu_1+u_2+u_3=Av, the ordinary logarithmic height inequality for a sum of three numbers, transferred to the ambient structure, gives

h(A~)=h ⁣(u~1v~+u~2v~+u~3v~)≤∑i=13h(s~i)+log⁡3≪fB(A∈R).{h}(\widetilde A) ={h}\!\left(\frac{\widetilde u_1}{\widetilde v} +\frac{\widetilde u_2}{\widetilde v} +\frac{\widetilde u_3}{\widetilde v}\right) \le\sum_{i=1}^3{h}(\widetilde s_i)+\log3 \ll_f B \qquad(A\in R).

The implicit constant is ordinary and independent of AA and of the root tuple. The dependence on ff comes only from its degree and coefficients and the resulting fixed choice of KK. For each nonzero aja_j, formula (2.3) expresses x(Taj)x(T_{a_j}) using the three ring elements x0(aj),x1(aj),x2(aj)x_0(a_j),x_1(a_j),x_2(a_j), with x2(aj)≠0x_2(a_j)\ne0. Applying (2.26) to these three elements and using the logarithmic height inequalities over the fixed number field FF gives

h(x(η(aj)P))≪fB.{h}(x(\eta(a_j)P))\ll_f B.

Canonical height on the fixed elliptic curve gives, for ordinary integer n≠0n\ne0, and hence for ambient integer indices by transfer,

h(x(nP))=2h^(P)n2+O(1),h^(P)>0;{h}(x(nP))=2\widehat h(P)n^2+O(1), \qquad\widehat h(P)>0;

see [67]. The error term is uniformly bounded for the fixed curve and point. If B>1B>1, choose a maximizing nonzero index in (2.21). Equations (2.27)–(2.28) give

2h^(P)B2≤CB+C′2\widehat h(P)B^2\le C B+C'

for ordinary constants, so BB is bounded by an ordinary constant. This is also true if B=1B=1. Every element of ∗Z{}^*\mathbb{Z} in an ordinary finite interval is an ordinary integer, by transfer of the finite description of that interval. Thus η(aj)=nj∈Z\eta(a_j)=n_j\in\mathbb{Z} for each jj. By additivity and η(1)=1\eta(1)=1, η(nj)=nj\eta(n_j)=n_j; injectivity then gives aj=nja_j=n_j in RR. The relation f(a)=0f(\mathbf a)=0 is consequently an ordinary integer solution. In the case currently under consideration this also contradicts δ≠0\delta\ne0.

Proof of Theorem 1.1. Constant polynomials can be decided directly. For nonconstant ff, if every finite rational test succeeds, Proposition 2.12 gives an integer zero. Therefore, when ff has no integer zero, some finite test must fail. Run the finite-test search and enumeration of integer tuples in parallel, allocating successive finite test steps to each. The enumeration terminates when a zero exists; the test search terminates when none exists. Their answers are sound. Rational decidability would therefore give integer decidability, contradicting the Davis–Putnam–Robinson–Matiyasevich theorem [14, 37].

An existential condition excluding odd poles

We prove Proposition 2.8, used in the finite rational tests of Section 2. It requires a positive existential condition that holds on all integers and restricts the denominators of any rational number satisfying it. Square classes below mean classes in the multiplicative group modulo squares.

Earlier existential formulas make related valuation information accessible on restricted sets of primes. For a fixed global field KK of characteristic different from 2 and a fixed quadratic extension L/KL/K, Demeyer and Van Geel give an existential formula which, for nonzero x,y∈Kx,y \in K, is equivalent to

vp(x) odd⟹vp(x/y2)>0for every nonarchimedean prime p inert in L/K.v_{\mathfrak p}(x)\ \text{odd} \quad\Longrightarrow\quad v_{\mathfrak p}(x/y^2)>0 \qquad \text{for every nonarchimedean prime \(\mathfrak p\) inert in \(L/K\)}.

They also permit a fixed finite union of such inert-prime sets [18] [Theorem 14 and Corollary 15 in the author version]. Cornelissen and Zahidi use related odd-valuation predicates in their elliptic-divisibility approach [9] [Sections 3.3 and 3.11]. The existential definitions of Demeyer and Van Geel control the chosen inert primes. Proposition 2.8 instead supplies the stated one-sided restriction outside a fixed finite exceptional set.

We first define a formula from finite multiplier lists and prove the pole restriction. We then choose the lists once and for all and prove integer completeness by realizing the same square class on two elliptic curves.

The formula and the pole restriction

For now, let M⊂Q×\mathcal{M} \subset\mathbb{Q}^{\times} be a finite nonempty list, and for each m∈Mm \in\mathcal{M} let Dm⊂Q×\mathcal D_m\subset{\mathbb{Q}}^\times be a finite nonempty list. The construction below associates a formula Φ\Phi to these lists. Let S1S_1 be a finite set containing 2, 3, and the supports of every member of all the lists. We will make one fixed choice of the lists in the next subsection.

For l∈Q×l \in\mathbb{Q}^{\times}, write

El:y2=x(x−l)(x+3l).E_l:\quad y^2=x(x-l)(x+3l).

The three roots are distinct, so this is an elliptic curve with its point at infinity OO as origin. Define Φ(b)\Phi(b) to hold if b=0b=0, or if b≠0b\ne0 and, for some m∈Mm\in\mathcal{M}, md∈Dmm_d\in\mathcal D_m, and t,e∈Qt,e\in\mathbb{Q}, the following conditions hold:

d=mdb,b′=mb,U=b1−dt21+dt2,H′=b′(b′−U2),d=m_db,\qquad b'=mb,\qquad U=b\frac{1-dt^2}{1+dt^2},\qquad H'=b'(b'-U^2),
1+dt2≠0,eH′≠0,1+dt^2\ne0,\qquad eH'\ne0,

and each of EeE_e and EeH′E_{eH'} has a rational point whose xx-coordinate belongs to b′Q×2b'\mathbb{Q}^{\times2}.

For each fixed choice of the lists, this is a positive existential formula. The choices of multipliers are finite disjunctions. A nonzero condition a≠0a\ne0 is the existential equation az=1az=1; the condition on xx is expressed by x=b′z2x=b'z^2 with z≠0z\ne0. Introduce UU as a variable and multiply its defining equality by 1+dt21+dt^2. All remaining conditions are polynomial equalities with fixed rational coefficients, which can be cleared to integer coefficients.

Lemma 3.1. For any finite lists as above, if b∈Q×b\in\mathbb{Q}^{\times} satisfies Φ(b)\Phi(b) and q∉S1q\notin S_1, then vq(b)<0v_q(b)<0 implies vq(b)∈2Zv_q(b)\in2\mathbb{Z}.

Proof. Suppose that q∉S1q\notin S_1, that witnesses for Φ(b)\Phi(b) have been chosen, and that k=vq(b)<0k=v_q(b)<0 is odd. The multipliers are qq-adic units, so vq(d)=vq(b′)=kv_q(d)=v_q(b')=k. If t=0t=0, then U=bU=b. If t≠0t\ne0, the valuation vq(dt2)=k+2vq(t)v_q(dt^2)=k+2v_q(t) is odd and hence nonzero. When this valuation is positive, both 1−dt21-dt^2 and 1+dt21+dt^2 are units. When it is negative, both have valuation vq(dt2)v_q(dt^2). In either case vq(U)=kv_q(U)=k. Since 2k<k2k<k,

vq(b′−U2)=2k,vq(H′)=3k.v_q(b'-U^2)=2k,\qquad v_q(H')=3k.

Consequently vq(e)v_q(e) and vq(eH′)v_q(eH') have opposite parities. Let ll be the one of these two parameters whose valuation is even, say vq(l)=2av_q(l)=2a. Replacing

l=q2aL,x=q2aX,y=q3aYl=q^{2a}L,\qquad x=q^{2a}X,\qquad y=q^{3a}Y

gives Y2=X(X−L)(X+3L)Y^2=X(X-L)(X+3L) with L∈Zq×L\in\mathbb{Z}_q^\times and does not change the square class of xx.

Every nonzero XX on this unit-parameter curve has even valuation. Indeed, if vq(X)<0v_q(X)<0, all three factors have valuation vq(X)v_q(X), so the right side has valuation 3vq(X)3v_q(X). If vq(X)>0v_q(X)>0, the other two factors are units because q≠3q\ne3, so its valuation is vq(X)v_q(X). In both cases this valuation must be even. The case vq(X)=0v_q(X)=0 already has the desired parity. This contradicts x∈b′Qq×2x\in b'\mathbb{Q}_q^{\times2}, since vq(b′)=kv_q(b')=k is odd.

Preparing integer witnesses

We now choose the multiplier lists so that the formula also holds on every integer. These lists will be fixed independently of the input bb. Choose a finite list M⊂Q×\mathcal{M}\subset\mathbb{Q}^{\times} with the following property: for every b∈Q×b\in\mathbb{Q}^{\times}, some m∈Mm\in\mathcal{M} makes

b′=mb>0,b′∈Q2×2,b′∈ the unit nonsquare class of Q3×.b'=mb>0,\qquad b'\in\mathbb{Q}_2^{\times2},\qquad b'\in\text{ the unit nonsquare class of }\mathbb{Q}_3^\times.

Here the last condition means that b′b' has even 3-adic valuation and nonsquare unit part. Such a list exists because R×/R×2\mathbb{R}^{\times}/\mathbb{R}^{\times2}, Q2×/Q2×2\mathbb{Q}_2^{\times}/\mathbb{Q}_2^{\times2}, and Q3×/Q3×2\mathbb{Q}_3^{\times}/\mathbb{Q}_3^{\times2} are finite, their classes are open, and weak approximation supplies a rational representative for each specified finite tuple of classes. For each m∈Mm\in\mathcal{M}, set

S(m)={2,3}∪Supp⁡(m).S(m)=\{2,3\}\cup\operatorname{Supp}(m).

The same argument gives a finite list Dm⊂Q×\mathcal{D}_m\subset\mathbb{Q}^{\times} such that, for any b≠0b\ne0, some md∈Dmm_d\in\mathcal{D}_m makes

d=mdb>0,d∈Qq×2(q∈S(m)).d=m_db>0,\qquad d\in\mathbb{Q}_q^{\times2}\quad(q\in S(m)).

Use these fixed lists in Φ\Phi, and fix S1S_1 containing 22, 33, and all their supports as above. The normalizations (3.3)–(3.4) are used only to select entries m,mdm,m_d for an integer input; they are not additional conjuncts of Φ\Phi. Lemma 3.1 already proves the pole restriction for this choice.

Fix b∈Z∖{0}b\in\mathbb{Z}\setminus\{0\} and choose m,mdm,m_d so that (3.3) and (3.4) hold. We choose tt to serve two purposes. The value UU should be small at the places where dd was made a local square, while at primes outside S(m)S(m) where vq(b′)v_q(b') is odd it should retain the valuation of bb. These properties will make H′H' a local square at every prime where vq(b′)v_q(b') is odd, and b′b' a local square at every prime where vq(H′)v_q(H') is odd.

At the real place and at every q∈S(m)q\in S(m), choose a local solution of dt2=1dt^2=1. As tt tends to this solution, the rational function UU tends to zero: its denominator tends to the nonzero number 2. Thus, in sufficiently small neighborhoods, H′>0H'>0 at the real place, and

H′=b′2(1−U2b′)∈Qq×2(q∈S(m)),H'=b'^2\left(1-\frac{U^2}{b'}\right)\in\mathbb{Q}_q^{\times2}\qquad(q\in S(m)),

by openness of the local square subgroup. At every q∈Supp⁡(md)∖S(m)q\in\operatorname{Supp}(m_d)\setminus S(m), require tt to be so small that vq(dt2)>0v_q(dt^2)>0. Weak approximation satisfies all these conditions simultaneously with a rational tt. In particular 1+dt2≠01+dt^2\ne0 and H′>0H'>0.

Let β\beta, θ\theta be the unique positive squarefree integers representing the square classes of b′b', H′H', and let

B=Supp⁡(β),J=Supp⁡(θ).B = \operatorname{Supp}(\beta), \qquad J = \operatorname{Supp}(\theta).

Lemma 3.2. The sets BB, JJ are disjoint and avoid 22, 33. Moreover,

θ∈Qq×2(q∈B),β∈Qq×2(q∈J).\theta\in\mathbb{Q}_q^{\times2}\quad(q \in B), \qquad\beta\in\mathbb{Q}_q^{\times2}\quad(q \in J).

Both β\beta and θ\theta are squares in Q2×\mathbb{Q}_2^\times; at 33, θ\theta is a square and β\beta is a unit nonsquare. In particular B≠∅B \ne\varnothing.

Proof. The assertions at 22, 33 follow from the choices already made and are unchanged on replacing numbers by square-class representatives. At a prime q∈B∩S(m)q \in B \cap S(m), H′H' is a local square by construction. Now suppose q∈B∖S(m)q \in B \setminus S(m). Since mm is a unit at qq and bb is an integer, vq(b)=vq(b′)v_q(b) = v_q(b') is a positive odd integer. If q∉Supp⁡(md)q\notin\operatorname{Supp}(m_d) and t≠0t \ne0, then vq(dt2)=vq(b)+2vq(t)v_q(dt^2) = v_q(b) + 2v_q(t) is odd and nonzero, and the quotient (1−dt2)/(1+dt2)(1-dt^2)/(1+dt^2) is a unit, just as in Lemma 3.1. For t=0t = 0 this quotient is 11. If instead q∈Supp⁡(md)q\in\operatorname{Supp}(m_d), our additional smallness condition on tt also makes it a unit. Hence vq(U)=vq(b)v_q(U) = v_q(b), and

vq(U2/b′)=vq(b)>0.v_q(U^2/b') = v_q(b) > 0.

As qq is odd, 1−U2/b′1-U^2/b' is a local square. The displayed formula for H′H' proves the first assertion of (3.5), and also proves B∩J=∅B \cap J = \varnothing.

For the converse assertion, let q∈Jq \in J. Such a prime is outside S(m)S(m), since H′H' is square there, and vq(b′)v_q(b') is even because q∉Bq \notin B. If U=0U = 0, then H′=b′2H' = b'^2 and there is no such prime, so suppose U≠0U \ne0. Put

α=vq(b′),γ=2vq(U).\alpha= v_q(b'), \qquad\gamma= 2v_q(U).

Both are even. If α≠γ\alpha\ne\gamma, then vq(b′−U2)=min⁡(α,γ)v_q(b' - U^2) = \min(\alpha,\gamma) is even, contrary to the oddness of vq(H′)v_q(H'). Therefore α=γ\alpha= \gamma. Since vq(H′)=α+vq(b′−U2)v_q(H') = \alpha+ v_q(b' - U^2) is odd, cancellation is strict: vq(b′−U2)>αv_q(b' - U^2) > \alpha. Thus b′/U2∈1+qZqb'/U^2 \in1 + q\mathbb{Z}_q, a square in Qq×\mathbb{Q}_q^\times, proving that β\beta is square there. This argument also covers possible denominators in tt or UU. Finally β\beta cannot be 11, since its class at 33 is nonsquare.

Write H′=θc2H' = \theta c^2 with c∈Q×c \in\mathbb{Q}^\times. For every n∈Q×n \in\mathbb{Q}^\times the isomorphism

Enθ⟶EnH′,(x,y)⟼(c2x,c3y)E_{n\theta}\longrightarrow E_{nH'},\qquad (x,y)\longmapsto(c^2x,c^3y)

preserves xx-coordinate square classes. Thus, taking e=ne = n in the formula, it remains to find one nn for which both EnE_n and EnθE_{n\theta} have a rational point with nonzero xx-coordinate of class β\beta, the class of b′b'. We first give a criterion for one parameter ll, and then construct a single nn for which it applies to both twists.

A criterion for one twist

We recall the exact part of full two-descent that we use; see [67], Chapter X, Proposition 1.4, p. 315. For a split separable cubic y2=∏i=13(x−ei)y^2 = \prod_{i=1}^3(x-e_i) over a field kk of characteristic zero, choosing two roots identifies H1(k,E[2])H^1(k,E[2]) with (k×/k×2)2(k^\times/k^{\times2})^2. In the coordinate corresponding to eie_i, the Kummer map takes a point to the class of x−eix-e_i; at (ei,0)(e_i,0) the value is replaced by ∏j≠i(ei−ej)\prod_{j\ne i}(e_i-e_j), and at OO it is 11. The Kummer map is an injection of E(k)/2E(k)E(k)/2E(k) into this group. The group Sel⁡2(E/Q)\operatorname{Sel}_2(E/\mathbb{Q}) is the subgroup of rational pairs lying in the Kummer image at every completion. The standard Selmer exact sequence [67], Chapter X, Theorem 4.2, p. 333 is

0⟶E(Q)/2E(Q)⟶Sel⁡2(E/Q)⟶Sha(E/Q)[2]⟶0.0\longrightarrow E({\mathbb{Q}})/2E({\mathbb{Q}}) \longrightarrow\operatorname{Sel}_2(E/{\mathbb{Q}}) \longrightarrow{\mathop{\mathrm{Sha}}}(E/{\mathbb{Q}})[2]\longrightarrow0.

We use the coordinates (x+3l,x−l)(x + 3l, x - l) for ElE_l. For a finite rational point TT with x(T)∉{0,l,−3l}x(T) \notin\{0,l,-3l\}, the curve equation gives

[x(T)]=[x(T)+3l][x(T)−l].[x(T)] = [x(T) + 3l][x(T) - l].

Consequently, if the class (β,1)(\beta,1) is represented by a rational point and is distinct from the classes of all four rational two-torsion points, that point has the required nonzero xx-coordinate class β\beta. The next calculation identifies conditions that make (β,1)(\beta,1) the one additional Selmer direction beyond rational two-torsion.

For the Selmer graph-matrix viewpoint underlying this calculation, see Monsky’s appendix to Heath-Brown [30], Appendix, pp. 365–370. The matrix and simultaneous rank calculations below adapt that viewpoint to the present curve family.

At the primes dividing ll, the local square conditions will be recorded by binary residue symbols. For an odd prime qq and a qq-adic unit aa, write [a/q]∈F2[a/q] \in\mathbb{F}_2 for the nonsquare bit: it is 0 for a square residue and 1 for a nonsquare residue. For a finite set QQ of distinct primes different from 2, 3, indexed by ii, and a vector w∈F2Qw \in\mathbb{F}_2^Q, write DwD_w for the diagonal matrix with diagonal ww. Put

si=[−1/qi],λi=[3/qi],(Ku)i=∑j≠i[qj/qi](uj+ui),N=K+Ds.s_i = [-1/q_i], \qquad\lambda_i = [3/q_i], \qquad(K u)_i = \sum_{j \ne i} [q_j/q_i](u_j + u_i), \qquad N = K + D_s.

All matrices and vectors in this calculation are over F2\mathbb{F}_2. Write 1\mathbf{1} for the all-ones vector and 1B\mathbf{1}_B for the indicator of BB in QQ. Quadratic reciprocity gives

K+Kt=sst+Ds.K + K^{\mathsf{t}} = ss^{\mathsf{t}} + D_s.

In particular, if st1=1s^{\mathsf{t}}\mathbf{1} = 1, then

K1=Kt1=0,N=Kt+sst.K\mathbf{1} = K^{\mathsf{t}}\mathbf{1} = 0, \qquad N = K^{\mathsf{t}} + ss^{\mathsf{t}}.

The family y2=x(x−n)(x+3n)y^2 = x(x-n)(x+3n) also occurs in the study of π/3\pi/3- and 2π/32\pi/3-congruent numbers. Mokrani adapted Monsky matrices to these families [43]. For this family, Wei and Guo give a two-Selmer matrix formulation and write the same quadratic-reciprocity identity for the associated Rédei matrix as (3.9) [72], Section 4 and Theorem 6.2. The simultaneous kernel conditions for the two twists required here are constructed below.

Lemma 3.3. Let l>0l > 0 be squarefree, prime to 6, with l≡3(mod4)l \equiv3 \pmod{4} and l≡2(mod3)l \equiv2 \pmod{3}. Suppose that its support QQ contains the nonempty set BB of Lemma 3.2 and a prime outside BB, and suppose that

ker⁡K=⟨1,1B⟩,λ∉im⁡K.\ker K = \langle\mathbf{1}, \mathbf{1}_B\rangle, \qquad\lambda\notin\operatorname{im} K.

Then

dim⁡F2Sel⁡2(El/Q)=3,\dim_{\mathbb{F}_2} \operatorname{Sel}_2(E_l/\mathbb{Q}) = 3,

and (β,1)(\beta,1) is a Selmer class outside the subgroup of rational two-torsion classes, in Kummer coordinates (x+3l,x−l)(x + 3l,x - l).

Proof. In the stated coordinates, the points (l,0)(l,0) and (−3l,0)(-3l,0) have classes

τ1=(l,1),τ2=(3,−l),\tau_1 = (l,1), \qquad\tau_2 = (3,-l),

respectively. For example, the replacement coordinate at (l,0)(l,0) is (l+3l)l=4l2(l + 3l)l = 4l^2, and the replacement at (−3l,0)(-3l,0) is (−3l)(−4l)=12l2(-3l)(-4l) = 12l^2. These two classes are independent globally: ll is nonsquare, and the second coordinate of τ2\tau_2 is negative.

We first bound the Selmer group using necessary local conditions. Afterward we verify that (β,1)(\beta,1) lies in the actual local Kummer image everywhere. For any odd prime qq, the group El(Qq)/2El(Qq)E_l(\mathbb{Q}_q)/2E_l(\mathbb{Q}_q) has order four. To see this, choose an open formal subgroup HH on which multiplication by 22 is an isomorphism. The quotient G=El(Qq)/HG=E_l(\mathbb{Q}_q)/H is finite, and El(Qq)/2El(Qq)≃G/2GE_l(\mathbb{Q}_q)/2E_l(\mathbb{Q}_q)\simeq G/2G. Moreover El(Qq)[2]≃G[2]E_l(\mathbb{Q}_q)[2]\simeq G[2]: injectivity follows from H[2]=0H[2]=0, and a lift of any element of G[2]G[2] can be corrected by an element of HH, using the surjectivity of multiplication by 22 on HH. Finally ∣G/2G∣=∣G[2]∣=4|G/2G|=|G[2]|=4.

At an odd prime q∤3lq\nmid3l, the roots are integral and pairwise distinct modulo qq. If vq(x)<0v_q(x)<0, all three factors have that valuation, which must be even. If xx is integral, at most one factor has positive valuation, and that valuation must be even. The replacement classes at the roots are units as well. Hence the local Kummer image is contained in the subgroup of pairs having even coordinate valuations. This unramified subgroup has order four, so the containment is equality.

At a support prime qi∣lq_i\mid l, the valuation pairs of τ1\tau_1 and τ2\tau_2 are (1,0)(1,0) and (0,1)(0,1) modulo 22; therefore they generate the entire local image, again by its order four. At 33, ll is a unit nonsquare and −l-l is a square. Thus τ1\tau_1 and τ2\tau_2 have independent first-coordinate classes and square second coordinates. The local image at 33 is consequently

(Q3×/Q3×2)×{1}.(\mathbb{Q}_3^\times/\mathbb{Q}_3^{\times2})\times\{1\}.

At 22 we need the necessary condition that both Kummer coordinates have even valuation. For a point away from the roots with v2(x)<0v_2(x)<0, all three factors have valuation v2(x)v_2(x), so that valuation is even. If xx is integral and even, x+3lx+3l and x−lx-l are units. Suppose xx is odd. If x−l=2ux-l=2u with uu odd, then

(y/2)2=(l+2u)u(u+2l)≡l(mod8).(y/2)^2=(l+2u)u(u+2l)\equiv l\pmod{8}.

The right side is an odd unit congruent to 33 or 77 modulo 88, which is impossible for a square. In every remaining nonroot case, v2(x−l)≥2v_2(x-l)\ge2 and v2(x+3l)≥2v_2(x+3l)\ge2. Their difference is 4l4l, so their minimum valuation is 22. Since xx is a unit, their valuation sum is even, and hence both valuations are even. The root and identity classes also have even valuations, as follows from (3.12). This establishes the claimed necessary condition at 22; no sufficiency is being asserted.

At the real place the first coordinate is always positive. Indeed, for a nonroot real point the allowable xx intervals are (−3l,0)(-3l,0) and (l,∞)(l,\infty), and the replacement first coordinates at the roots are positive as well. The sign of the second coordinate therefore gives a homomorphism from the Selmer group to {±1}\{\pm1\}, and it is surjective because of τ2\tau_2. Its kernel, the classes with both coordinates positive, has index two. Every class in this kernel has a unique representative of the form

(3δ∏iqiui, ∏iqivi),δ∈F2,u,v∈F2Q.\left(3^\delta\prod_iq_i^{u_i},\ \prod_iq_i^{v_i}\right), \qquad \delta\in{\mathbb{F}}_2,\quad u,v\in{\mathbb{F}}_2^Q.

Here the good-prime restrictions and the even valuations at 22 exclude every other prime, and (3.13) excludes 33 from the second coordinate.

At qiq_i, compare (3.14) with the local torsion class

τ1uiτ2vi=(lui3vi,(−l)vi).\tau_1^{u_i}\tau_2^{v_i}=(l^{u_i3^{v_i}},(-l)^{v_i}).

The coordinate valuations already agree modulo 22. Requiring the resulting unit quotients to be squares gives exactly

Ku+Dλv=δλ,Nv=0.Ku+D_\lambda v=\delta\lambda,\qquad Nv=0.

For example the first unit quotient has nonsquare bit ∑j≠i[qj/qi](uj+ui)+(δ+vi)λi\sum_{j\ne i}[q_j/q_i](u_j+u_i)+(\delta+v_i)\lambda_i; the second has bit (Kv)i+sivi(Kv)_i+s_iv_i. The requirement that the second coordinate be square at 3 adds

(λ+s)tv=0,(\lambda+s)^{\mathsf t}v=0,

using [qi/3]=λi+si[q_i/3]=\lambda_i+s_i.

The residue assumptions imply st1=1s^{\mathsf t}\mathbf1=1 and λt1=0\lambda^{\mathsf t}\mathbf1=0. Equations (3.10) give

ker⁡N=ker⁡Kt∩s⊥.\ker N=\ker K^{\mathsf t}\cap s^\perp.

Indeed, left multiplying Nv=0Nv=0 by 1t\mathbf1^{\mathsf t} gives stv=0s^{\mathsf t}v=0, and the identity N=Kt+sstN=K^{\mathsf t}+ss^{\mathsf t} then gives the claim in both directions. By (3.11), ker⁡Kt\ker K^{\mathsf t} has dimension two. It contains 1\mathbf{1}, on which sts^{\mathsf t} is nonzero, so (3.17) is a line. The functional λt\lambda^{\mathsf t} is nonzero on ker⁡Kt\ker K^{\mathsf t} because λ∉im⁡K=(ker⁡Kt)⊥\lambda\notin\operatorname{im}K=(\ker K^{\mathsf t})^\perp. Since it vanishes on 1\mathbf{1}, it is nonzero on the complementary line (3.17). Equations (3.16) and (3.17) therefore force v=0v=0. The first equation in (3.15) now gives Ku=δλKu=\delta\lambda, so δ=0\delta=0 and u∈ker⁡K=⟨1,1B⟩u\in\ker K=\langle\mathbf{1},\mathbf{1}_B\rangle. There are at most four sign-normalized classes, and hence at most eight Selmer classes.

For equality, we verify that

γ=(β,1)\gamma=(\beta,1)

is an actual local Kummer class everywhere. At 2 and at the real place it is the identity class, since β\beta is a positive local square. At 3 it is τ1\tau_1, since β\beta and ll are both unit nonsquares. At qi∣lq_i\mid l, take u=1Bu=\mathbf{1}_B and v=0v=0: the comparison with τ1ui\tau_1^{u_i} has square coordinate quotients precisely because K1B=0K\mathbf{1}_B=0. At every other finite odd prime it is unramified, so lies in the local image already described. This proves γ∈Sel⁡2(El/Q)\gamma\in\operatorname{Sel}_2(E_l/\mathbb{Q}). It is neither the identity nor τ1\tau_1: BB is nonempty, and ll has a prime factor outside BB. It cannot equal τ2\tau_2 or τ1τ2\tau_1\tau_2, whose second coordinates are negative. Thus τ1,τ2,γ\tau_1,\tau_2,\gamma are three independent Selmer classes, and the upper bound is attained.

It remains to realize this particular Selmer class by a rational point. The consequence we use from Theorem 1.1 of [48] is the following: an elliptic curve C/QC/\mathbb{Q} with C(Q)[2]≠0C(\mathbb{Q})[2]\ne0 and corank⁡Z2Sel⁡2∞(C/Q)∈{0,1}\operatorname{corank}_{\mathbb{Z}_2}\operatorname{Sel}_{2^\infty}(C/\mathbb{Q})\in\{0,1\} has finite Sha(C/Q){\mathop{\mathrm{Sha}}}(C/{\mathbb{Q}}). The next proof verifies the full Selmer-corank hypothesis before applying it.

Lemma 3.4. Under the hypotheses of Lemma 3.3, the curve ElE_l has a rational point with nonzero xx-coordinate in βQ×2\beta\mathbb{Q}^{\times2}.

Proof. Put r=rank⁡El(Q)r=\operatorname{rank}E_l(\mathbb{Q}). Since ElE_l has full rational two-torsion, the Kummer sequence (3.7) and Lemma 3.3 imply

r+dim⁡F2Sha(El/Q)[2]=1.r+\dim_{{\mathbb{F}}_2}{\mathop{\mathrm{Sha}}}(E_l/{\mathbb{Q}})[2]=1.

This also controls the full 2-primary Selmer group before any finiteness conclusion. The usual exact sequence is

0⟶El(Q)⊗Q2/Z2⟶Sel⁡2∞(El/Q)⟶Sha(El/Q)[2∞]⟶0.0\longrightarrow E_l({\mathbb{Q}})\otimes{\mathbb{Q}}_2/{\mathbb{Z}}_2 \longrightarrow\operatorname{Sel}_{2^\infty}(E_l/{\mathbb{Q}}) \longrightarrow{\mathop{\mathrm{Sha}}}(E_l/{\mathbb{Q}})[2^\infty]\longrightarrow0.

These are cofinitely generated Z2\mathbb{Z}_2-modules. If the last group has corank tt, its structure is (Q2/Z2)t⊕F(\mathbb{Q}_2/\mathbb{Z}_2)^t\oplus F with FF finite, so t≤dim⁡F2Sha(El/Q)[2]t\le\dim_{{\mathbb{F}}_2}{\mathop{\mathrm{Sha}}}(E_l/{\mathbb{Q}})[2]. It follows from (3.18) that

0≤corank⁡Z2Sel⁡2∞(El/Q)=r+t≤1.0\le\operatorname{corank}_{\mathbb{Z}_2}\operatorname{Sel}_{2^\infty}(E_l/\mathbb{Q})=r+t\le1.

The curve has nonzero rational two-torsion, so [48] now applies and proves that Sha(El/Q){\mathop{\mathrm{Sha}}}(E_l/{\mathbb{Q}}) is finite. The Cassels–Tate pairing on this finite group is perfect and alternating. Alternation here uses the principal polarization represented by the rational divisor (O)(O); see [6]; see also [55], Section 1 and Corollary 9. For completeness, an alternating perfect pairing on a finite abelian 2-group forces an even number of cyclic factors. Choose an element xx of maximal order 2a2^a. Perfection supplies yy whose pairing with xx has exact order 2a2^a. The subgroup generated by x,yx,y is a nondegenerate copy of (Z/2aZ)2(\mathbb{Z}/2^a\mathbb{Z})^2, and the whole group is its direct sum with its orthogonal complement. Induction gives a decomposition into such paired cyclic factors. Hence

dim⁡F2Sha(El/Q)[2]is even.\dim_{{\mathbb{F}}_2}{\mathop{\mathrm{Sha}}}(E_l/{\mathbb{Q}})[2]\quad\text{is even}.

This conclusion uses the perfect pairing on the full finite 2-primary group; its restriction to the subgroup killed by 2 need not be perfect. Equation (3.18) therefore gives Sha(El/Q)[2]=0\mathop{\mathrm{Sha}}(E_l/\mathbb{Q})[2]=0 and r=1r=1.

The Kummer sequence now shows that γ=(β,1)\gamma=(\beta,1) is the class of a rational point TT. By Lemma 3.3 its class differs from all four two-torsion point classes. Thus TT is finite and none of x(T)x(T), x(T)−lx(T)-l, x(T)+3lx(T)+3l is zero. The curve equation gives, modulo squares,

[x(T)]=[x(T)+3l][x(T)−l]=β,[x(T)]=[x(T)+3l][x(T)-l]=\beta,

as required. 22

Remark 3.5. The unrestricted 2-converse [50], Theorem 1.1 can replace the pointwise theorem in the preceding proof. It gives finiteness of the whole Sha(El/Q){\mathop{\mathrm{Sha}}}(E_l/{\mathbb{Q}}) from the same full Selmer-corank bound, without any rational-two-torsion hypothesis.

One parameter for both twists

The criterion is now a condition on the prime support of one twist. We construct a single positive squarefree nn for which it holds both on the support of nn and on that of nθn\theta. The mutual local-square relations from Lemma 3.2 are what allow the second support to be added without disturbing the first construction.

Lemma 3.6. For β,θ,B,J\beta,\theta,B,J as in Lemma 3.2, there is a positive squarefree integer nn, prime to 6θ6\theta, whose support PP contains BB and at least one auxiliary prime outside BB, such that the following statements hold for both l=nl=n and l=nθl=n\theta. The number ll satisfies l≡3(mod4)l\equiv3\pmod{4} and l≡2(mod3)l\equiv2\pmod{3}. On its prime support Q=PQ=P or Q=P∪JQ=P\cup J, the matrices (3.8) satisfy (3.11).

Proof. Since β,θ\beta,\theta are odd squares at 2, their products of (−1)(-1)-symbols are 1. At 3, reciprocity gives [q/3]=[3/q]+[−1/q]=λq+sq[q/3]=[3/q]+[-1/q]=\lambda_q+s_q. Consequently

∑i∈Bsi=∑j∈Jsj=0,∑i∈Bλi=1,∑j∈Jλj=0.\sum_{i\in B}s_i=\sum_{j\in J}s_j=0,\qquad\sum_{i\in B}\lambda_i=1,\qquad\sum_{j\in J}\lambda_j=0.

The fixed BB–JJ symbols need not vanish individually. Their row sums, however, satisfy

∑j∈J[qj/qi]=0(i∈B),∑i∈B[qi/qj]=0(j∈J),\sum_{j\in J}[q_j/q_i]=0\quad(i\in B),\qquad\sum_{i\in B}[q_i/q_j]=0\quad(j\in J),

by (3.5).

Introduce one auxiliary prime q0q_0 of type (s0,λ0)=(1,1)(s_0,\lambda_0)=(1,1), and a set II of ∣B∣−1|B|-1 auxiliary primes of type (0,0)(0,0). These types can be imposed by the residue classes 7 and 1 modulo 12, respectively. We first prescribe all required Legendre symbols abstractly, and realize them by actual primes at the end. Until then, each unchosen symbol is a bit whose reverse is constrained by quadratic reciprocity; the matrix reciprocity identity therefore holds for every completion of these choices. On each of the sets

Q0=B∪I∪{q0},Q1=Q0∪J,Q_0 = B \cup I \cup\{q_0\}, \qquad Q_1 = Q_0 \cup J,

the total ss-sum is 1 and the total λ\lambda-sum is 0. The former gives l≡3(mod4)l \equiv3 \pmod{4}, while the sum of s+λs+\lambda gives l≡2(mod3)l \equiv2 \pmod{3} for the corresponding prime product.

We first show that, subject to K1B=0K\mathbf1_B=0, both matrix targets follow from one nonsingularity condition. Fix b∗∈Bb_* \in B and let aa have entries 1 at q0q_0, b∗b_* and 0 elsewhere. Thus

at1=0,at1B=1.a^{\mathsf t}\mathbf1=0,\qquad a^{\mathsf t}\mathbf1_B=1.

We shall impose K1B=0K\mathbf1_B=0 on both supports. Assuming this condition for the moment, set K#=K+λatK^\#=K+\lambda a^{\mathsf{t}}. The total symbol sums and (3.10) show that K#K^\# kills 1 on both sides, and

K#1B=λ.K^\#\mathbf1_B=\lambda.

Put

T=Id⁡−1Bat.T=\operatorname{Id}-\mathbf1_Ba^{\mathsf t}.

This is a projection onto a⊥a^\perp, with kernel ⟨1B⟩\langle\mathbf1_B\rangle, and it fixes 1. By (3.21),

K=K#T.K=K^\#T.

Suppose that ker⁡K#=⟨1⟩\ker K^\#=\langle\mathbf1\rangle. If Kx=0Kx=0, then Tx=c1Tx=c\mathbf1, so x=c1+(atx)1Bx=c\mathbf1+(a^{\mathsf t}x)\mathbf1_B; the converse follows from K1=K1B=0K\mathbf1=K\mathbf1_B=0. This gives the required kernel of KK. If Kx=λKx=\lambda, put y=Txy=Tx. Then aty=0a^{\mathsf{t}}y=0 and K#(y−1B)=0K^\#(y-\mathbf1_B)=0, so y−1B∈⟨1⟩y-\mathbf1_B\in\langle\mathbf1\rangle. Applying ata^{\mathsf{t}} would give −1=0-1=0, a contradiction. Thus λ∉im⁡K\lambda\notin\operatorname{im}K.

For either support, let MM be the matrix obtained from K#K^\# by deleting the q0q_0 row and column. It is enough to make MM nonsingular. Indeed, if K#x=0K^\#x=0, subtract xq01x_{q_0}\mathbf1 from xx. The resulting vector still lies in the kernel, has zero q0q_0 coordinate, and its remaining coordinates are killed by MM. Nonsingularity makes that vector zero, proving ker⁡K#=⟨1⟩\ker K^\#=\langle\mathbf1\rangle. We therefore have two tasks for the symbol choices: impose K1B=0K\mathbf1_B=0 and make these deleted matrices nonsingular on both supports.

For the smaller support, let CC be a BB-by-II matrix whose columns are a basis of the even-sum hyperplane

{x∈F2B:1Btx=0}.\{x\in{\mathbb{F}}_2^B:\mathbf1_B^{\mathsf t}x=0\}.

These columns will form the off-diagonal block of the deleted matrix. When ∣B∣=1|B|=1, CC is the empty matrix. Prescribe [qi/qb]=[qb/qi]=Cbi[q_i/q_b]=[q_b/q_i]=C_{bi} for b∈Bb\in B, i∈Ii\in I. Every other off-diagonal symbol incident with II is set to zero. Prescribe

[q0/qb]=∑i∈ICbi(b∈B),[q_0/q_b]=\sum_{i\in I}C_{bi}\qquad(b\in B),

and obtain reverse symbols by reciprocity. In particular [qb/q0]=[q0/qb]+sb[q_b/q_0]=[q_0/q_b]+s_b. The q0q_0–JJ symbols remain free.

These prescriptions ensure K1B=0K\mathbf1_B=0 on both supports. At a BB row, the terms from II and q0q_0 cancel, and the sum from JJ, when present, is zero by (3.20). At an II row the sum is a column sum of CC, hence zero. At the q0q_0 row it is the sum of all entries of CC plus ∑Bsb\sum_{B}s_b, again zero. At a JJ row it is zero by the second equality in (3.20). It therefore remains to make the deleted matrices nonsingular. On Q0Q_0, the deleted matrix has the form

M0=(ACCt0),1BtA1B=1.M_0=\begin{pmatrix}A&C\\ C^{\mathsf t}&0\end{pmatrix}, \qquad \mathbf1_B^{\mathsf t}A\mathbf1_B=1.

The equality follows from (3.21) and ∑Bλb=1\sum_B \lambda_b=1. The lower right block is zero since the only potentially nonzero symbols incident with II are in CC, whose column sums vanish. The added matrix λat\lambda a^{\mathsf t} changes neither off-diagonal block, because aa and λ\lambda both vanish on II. No symmetry of AA is required.

To prove M0M_0 nonsingular, let M0(x,y)t=0M_0(x,y)^{\mathsf t}=0. The second block equation says Ctx=0C^{\mathsf t}x=0. Since the columns of CC span the even-sum hyperplane, its annihilator is ⟨1B⟩\langle\mathbf{1}_B\rangle; hence x=c1Bx=c\mathbf{1}_B. Left multiplying the first block equation cA1B+Cy=0cA\mathbf{1}_B+Cy=0 by 1Bt\mathbf1_B^{\mathsf t} gives c=0c=0 by (3.23). The injectivity of CC then gives y=0y=0. This proof applies also when ∣B∣\lvert B\rvert is even; when ∣B∣=1\lvert B\rvert=1 it says simply that M0=(1)M_0=(1).

On adding JJ, the B,IB,I block of the deleted matrix stays equal to M0M_0. Indeed, the only possible changes to its diagonal are the BB-JJ row sums, which vanish by (3.20); all II-JJ symbols were set to zero. Now varying the bit [q0/qj][q_0/q_j] for one j∈Jj\in J also varies its reverse by the same bit, as their reciprocity discrepancy is fixed. After deleting the q0q_0 row and column, the only surviving change is a toggle of the jj-th diagonal entry. Thus these choices independently toggle the JJ-diagonal entries of the enlarged matrix. Its determinant is a multilinear polynomial in these bits whose coefficient of their full product is det⁡M0=1\det M_0=1. A nonzero multilinear polynomial over F2\mathbb{F}_2 cannot vanish at every point of the Boolean cube: this follows by induction on the number of variables, writing it as f0+Xf1f_0+Xf_1. Hence some choice makes the enlarged matrix nonsingular. If JJ is empty, the smaller-support calculation already suffices. The chosen bits do not affect the smaller matrix.

The deleted matrices are now nonsingular on both supports, so the preceding reduction proves (3.11) on both. Finally realize the prescribed symbols. Choose the auxiliary primes successively. At each step, specify the type modulo 1212 and the Legendre symbols modulo every already fixed prime in B∪JB\cup J or among the earlier auxiliary primes. Each symbol can be imposed by a nonzero residue modulo that prime; reverse symbols are consistent by the prescribed reciprocity rule. The Chinese remainder theorem gives a reduced residue class, and Dirichlet’s theorem supplies infinitely many primes in it. Excluding the finitely many previously used primes causes no difficulty. The resulting product n=∏q∈B∪I∪{q0}qn=\prod_{q\in B\cup I\cup\{q_0\}}q has all the asserted properties.

Completion of the proof of Proposition 2.8. The value b=0b=0 satisfies Φ\Phi by definition. For a nonzero integer bb, make the local choices preceding Lemma 3.2 and choose nn by Lemma 3.6. Both l=nl=n and l=nθl=n\theta satisfy the hypotheses of Lemma 3.4, so each curve has a point with nonzero xx-coordinate of class β\beta, which is also the class of b′b'. The isomorphism (3.6) sends the point on EnθE_{n\theta} to one on EnH′E_{nH'} with the same xx-coordinate square class. Taking e=ne=n gives the two points required in the definition of Φ\Phi, on EeE_e and EeH′E_{eH'}. This proves integer completeness, while Lemma 3.1 proves the asserted pole restriction.

A height bound from odd contact with five points

We prove Theorem 2.4, whose contact radical supplies the primes used in Section 2. For s∈P1(Q)∖Cs\in\mathbf P^1({\mathbb{Q}})\setminus\mathcal C, the target is

h(s)≤HMS(s)c,{h}(s)\le H M_S(s)^c,

where MS(s)M_S(s) is the squarefree product of the nonexceptional primes of odd contact with the five fixed points, as defined in that theorem.

Throughout this section, h{h} is the absolute logarithmic Weil height, and hFh_F is the original stable Faltings height. Unless another dependence is stated, constants depend only on the geometric objects and auxiliary levels fixed in the proof.

The geometric part of the proof constructs a finite cover π:Y→P1\pi:Y\to\mathbf P^1 with ramification index two exactly above C\mathcal C, carrying a family of principally polarized abelian surfaces. Outside fixed exceptional primes, the local equation becomes t=z2t=z^2 after a finite unramified extension. Thus only odd contact can ramify the splitting field of a rational fiber, as Lemma 4.1 makes precise. The polarized isomorphism class of the surfaces varies on each component, which also allows their Faltings height to control the base height (Lemma 4.2).

The surfaces carry quaternionic multiplication, and fibers above a common base point are isogenous. For a rational base point, this gives isogenies between a surface and its Galois conjugates. Fibers with extra endomorphisms have uniformly bounded height by complex multiplication. For the other fibers, a controlled splitting of the isogeny obstruction produces a two-dimensional Galois representation. Modularity and a conductor estimate give a weight-two newform whose level is bounded by a fixed power of MS(s)M_S(s). The surface is then an isogeny factor of the corresponding modular Jacobian over a field of degree O(MS(s))O(M_S(s)). Height bounds for that Jacobian and the quantitative isogeny theorem complete the estimate.

The five-point quaternionic quotient

We first construct the cover whose ramification will detect the odd contact orders in Theorem 2.4. Let B/QB/\mathbb{Q} be the indefinite quaternion algebra of discriminant 210=2⋅3⋅5⋅7210=2\cdot3\cdot5\cdot7, let O\mathcal{O} be a maximal order, and put G=B×G=B^\times. Fix B⊗QR≃M2(R)B\otimes_{\mathbb{Q}}\mathbf R\simeq M_2(\mathbf R). The quaternionic Shimura datum is (G,H±)(G,\mathfrak{H}^{\pm}), where the two half planes parametrize the conjugates of the elliptic-curve Hodge homomorphism. Its reflex field is Q\mathbb{Q}: over C\mathbf C its cocharacter has the usual GL2\mathrm{GL}_2 conjugacy class, and this class is invariant under the Galois action for the inner form GG.

We use canonical models and functoriality for Shimura varieties [16, 17]. In the form needed here, they give the model over the reflex field with complex points

G(Q)\(H±×G(Af)/K)G({\mathbb{Q}})\backslash \bigl(\mathfrak H^\pm\times G(\mathbf A_f)/K\bigr)

for a compact open subgroup KK, and define level maps and finite-adelic right actions over that field. We use the full Shimura varieties over Q\mathbb{Q}, including all their geometric components.

At maximal level, put

X=Sh⁡O^×(G,H±).X=\operatorname{Sh}_{\widehat{\mathcal{O}}^{\times}}(G,\mathfrak{H}^{\pm}).

This curve is proper because BB is a division algebra. Strong approximation for B1B^1, the reduced-norm theorem, and Nrd⁡(Op×)=Zp×\operatorname{Nrd}(\mathcal{O}_p^\times)=\mathbb{Z}_p^\times give

G(Af)=G(Q)+O^ ×.G(\mathbf A_f)=G({\mathbb{Q}})^+\widehat{\mathcal O}^{\,\times}.

Indeed, match the finite-adelic norm modulo Z^×\widehat{\mathbb{Z}}^\times by a positive rational reduced norm and then apply strong approximation to the norm-one part. There are also rational elements of negative norm, since no real place is ramified. Consequently XCX_{\mathbf C} is the connected compact curve

(O1/{±1})\H.(\mathcal{O}^1/\{\pm1\})\backslash\mathfrak{H}.

The uniformizing group has no nontrivial elliptic stabilizers. A noncentral norm-one unit fixing a point has integral trace of absolute value less than two, hence trace 00 or ±1\pm1. It would generate Q(i)\mathbb{Q}(i) or Q(−3)\mathbb{Q}(\sqrt{-3}). These fields cannot embed in BB, since they split at the ramified primes 55 and 77, respectively. The Eichler area formula, in the normalization of [68], Theorem 39.1.2, therefore gives

area⁡(X(C))2π=16∏p∣210(p−1)=8.\frac{\operatorname{area}(X(\mathbf C))}{2\pi} =\frac16\prod_{p\mid210}(p-1)=8.

There are no cusps or elliptic corrections, so 2g(X)−2=82g(X)-2=8 and g(X)=5g(X)=5.

The finite-adelic normalizer of O^\widehat{\mathcal{O}} induces the Atkin–Lehner group

W≃(Z/2Z)4\mathcal{W}\simeq(\mathbb{Z}/2\mathbb{Z})^{4}

over Q\mathbb{Q}. At a split prime, the normalizer is scalars times order units. At a division prime, its quotient by scalars and order units has order two, detected by parity of reduced-norm valuation. Finite adelic scalars act trivially, since Af×=Q×Z^×\mathbf A_f^\times={\mathbb{Q}}^\times\widehat{\mathbb{Z}}^\times. The resulting action is faithful: a generic domain point has rational stabilizer equal to the center, which accounts precisely for the scalars already removed. Let X∗=X/WX^{*}=X/\mathcal{W}.

The geometry of this discriminant-210 quotient has been tabulated before. Long, Maclachlan, and Reid list the signature (0;25;0)(0;2^{5};0), recording a genus-zero quotient with five elliptic cycles of order two and no cusps [35], Table 3. Nualart Riera gives genus 5 for the original curve and the five involution labels 30, 42, 70, 105, 210, and identifies the full quotient over Q\mathbb{Q} with P1\mathbf P^1 [47], Propositions 4.1–4.2. The calculation here recovers this fixed configuration and establishes the rational branch values used in the reduction.

A finite stabilizer of a point on a smooth characteristic-zero curve acts faithfully on its tangent line and is cyclic. Since every nonidentity element of W\mathcal{W} has order two, each nontrivial stabilizer has order two. If rr is the number of geometric branch values of X→X∗X\to X^{*}, Riemann–Hurwitz gives

2g(X∗)−2+r2=2g(X)−216=12.2g(X^{*})-2+\frac{r}{2}=\frac{2g(X)-2}{16}=\frac{1}{2}.

Thus r=5−4g(X∗)≤5r=5-4g(X^{*})\leq5.

We exhibit five different stabilizer labels. Take

m=30,42,70,105,210.m=30,42,70,105,210.

The field Q(−m)\mathbb{Q}(\sqrt{-m}) is nonsplit at every prime dividing 210. For the first three values, the only prime of 210 not dividing mm is respectively 7, 5, 3, and the residues of −m-m there are the nonsquares 5, 3, 2. For m=105m=105, the quadratic discriminant is −420-420, so 2 is ramified too. For m=210m=210, all four primes are ramified. The quaternion embedding criterion from Albert–Brauer–Hasse–Noether, as in [68], gives an embedding of each field in BB.

An embedded −m\sqrt{-m} lies in some maximal order: at split local places an integral element stabilizes a lattice, and at division places it lies in the unique maximal order. Intersecting these local orders gives a global maximal order containing the embedded element. Strong approximation implies that all maximal orders in this indefinite rational quaternion algebra are conjugate by B×B^{\times} [68], Theorems 28.2.10 and 28.2.11(b)), so a conjugate of the embedded element lies in our fixed O\mathcal{O}. It normalizes O\mathcal{O} because it is a unit at every prime outside 210, and at a division prime every element normalizes the unique maximal order. Its norm is mm and it fixes a point of H\mathfrak{H}, so it gives a fixed point of the involution wmw_m with the corresponding norm-parity label.

The five labels are different. A fiber of the quotient is one W\mathcal{W}-orbit, and the stabilizers along this orbit agree because W\mathcal{W} is abelian. Distinct labels thus yield distinct branch values, proving r≥5r\geq5. Equation (4.1) now forces r=5r=5 and g(X∗)=0g(X^{*})=0. There is exactly one branch value for each of the five labels. Every wmw_m is defined over Q\mathbb{Q}, so Galois preserves its uniquely labelled branch value. Each branch value is therefore individually rational. In particular X∗X^* is a genus-zero curve with a rational point, hence is isomorphic over Q\mathbb{Q} to P1\mathbf{P}^1. Fix an isomorphism sending one branch value to ∞\infty, and denote the five branch values by C\mathcal{C}.

The abelian surface family

We next pass to a fine level so that the cover carries abelian surfaces. The construction will provide a finite level map Y→XY \to X, unramified over XX, and a principally polarized abelian surface scheme A→Y\mathcal{A} \to Y. Write π\pi for the composite

Y⟶X⟶X∗≃P1,π:Y⟶P1.Y\longrightarrow X\longrightarrow X^*\simeq\mathbf P^1, \qquad \pi:Y\longrightarrow\mathbf P^1.

Every fiber Ay\mathcal{A}_{y} with y∈Y(Q‾)y \in Y(\overline{\mathbb{Q}}) will have an embedding B↪End⁡Q‾0(Ay)B\hookrightarrow\operatorname{End}^0_{\overline{\mathbb{Q}}}(\mathcal A_y) given by left multiplication. Fibers with the same image under π\pi will be geometrically isogenous, and the polarized moduli map will be nonconstant on every geometric component. We now construct the family and prove these properties.

Canonical-model functoriality associates algebraic maps to morphisms of Shimura data at compatible levels [16, 17]. A Siegel variety at principal level at least three carries the universal principally polarized abelian scheme. The required morphism to a Siegel datum comes from the following symplectic representation.

On the four-dimensional rational space V=BV = B, put

ρ(g)(x)=xg‾,ψ(x,y)=Trd⁡(Δxy‾),\rho(g)(x) = x\overline{g}, \qquad\psi(x,y) = \operatorname{Trd}(\Delta x\overline{y}),

where the bar is the standard quaternion involution and Δ\Delta is a pure quaternion with Δ2<0\Delta^{2} < 0. Such a rational Δ\Delta exists by real approximation in the trace-zero subspace. The identities Δ‾=−Δ\overline{\Delta} = -\Delta and cyclicity of reduced trace show that ψ\psi is alternating. It is nondegenerate because the reduced-trace pairing is nondegenerate and Δ\Delta is invertible. Moreover

ψ(xg‾,yg‾)=Nrd⁡(g)ψ(x,y).\psi(x\overline{g},y\overline{g}) = \operatorname{Nrd}(g)\psi(x,y).

Quaternion conjugation reverses products, as does composition of right multiplications; together these identities give ρ(gh)=ρ(g)ρ(h)\rho(gh) = \rho(g)\rho(h). Thus ρ\rho is a faithful symplectic-similitude representation.

The Hodge homomorphism makes VRV_{\mathbf R} a complex vector space by right multiplication. At a base point represented by J=(0−110)J=\left(\begin{smallmatrix}0&-1\\1&0\end{smallmatrix}\right), the associated real quadratic form is

ψ(x,xJˉ)=tr⁡(JΔxxt).\psi(x,x\bar J)=\operatorname{tr}(J\Delta xx^{\mathrm t}).

Since Δ\Delta has trace zero, JΔJ\Delta is symmetric, and its determinant is positive; it is therefore definite. Choose its sign on one half plane. Conjugation by G(R)G(\mathbf R) gives all the other complex structures, and the displayed similitude identity gives the corresponding definite sign on the other half plane as well. This is the two-component Siegel datum. A real scalar acts on VV with the homological weight of an elliptic curve, which is the required weight.

Choose a rational symplectic basis for VV. The standard lattice in that basis is self-dual for ψ\psi. Intersect a sufficiently small compact open subgroup of O^ ×\widehat{\mathcal O}^{\,\times} with the inverse image of a principal Siegel level, and call the resulting subgroup KYK_Y. Put

Y=Sh⁡KY(G,H±).Y=\operatorname{Sh}_{K_Y}(G,\mathfrak H^\pm).

The induced morphism from YY to the fine Siegel moduli scheme pulls back its universal family to the principally polarized abelian surface scheme A→Y\mathcal{A} \to Y. The self-dual lattice need not be preserved by the whole maximal order: the intersection of levels provides the integral moduli problem, while the rational Hodge structure retains the BB-action. Fix this level and family once and for all.

There may be finitely many geometric components of the smooth projective curve YY. The level map Y→XY \to X is unramified by the uniformization and the absence of elliptic stabilizers on XX. Consequently its composite π\pi has ramification index two at every point above C\mathcal C and index one elsewhere.

Every geometric fiber A=AyA=\mathcal A_y has left BB-multiplication in End⁡Q‾0(A)\operatorname{End}^0_{\overline{\mathbb Q}}(A). Left multiplication commutes with the right complex structures on VV; the equivalence between abelian varieties up to isogeny and their polarizable rational Hodge structures supplies the endomorphisms. Homomorphisms of abelian varieties defined over Q‾\overline{\mathbb Q} do not acquire new elements after extension to C\mathbf C [45].

For non-CM points, the moduli construction of Guitart and Molina gives a related description by compatible isogenies [29], Lemma 1, Corollary 2, and Section 3. For this fine-level family, the following Hodge argument gives the underlying geometric isogenies for all fibers needed here; compatible choices are made in the descent argument. Changing level or applying the normalizer changes the finite-adelic coordinate, while domain coordinates of fibers above a common point of X∗X^* can be identified up to G(Q)G(\mathbb{Q}). Their rational Hodge structures are therefore isomorphic, so the fibers are geometrically isogenous. In particular, if π(y)=s∈P1(Q)\pi(y)=s\in\mathbf P^1({\mathbb{Q}}), then π(gy)=g(s)=s\pi({}^g y)=g(s)=s and Ay\mathcal A_y is isogenous to each of its Galois conjugates.

Finally, the polarized moduli map of the family is nonconstant on every geometric component. Its complex structures vary in a half plane, whereas a fixed rational Hodge structure has only countably many presentations on the fixed rational space VV. Thus a component cannot have a single geometric isomorphism class of fibers.

Rational fibers and odd-contact ramification

The ramification index two now explains the parity in the theorem. We make precise how even contact with a branch value gives unramified local lifts, and record the good reduction of the resulting surfaces.

Enlarge a fixed finite set SS of rational primes whenever necessary in the following construction. All these enlargements depend only on the fixed curves, maps, and family, and occur before choosing ss. Include 2, primes at which the branch sections meet, and primes at which the chosen coordinates or the geometric models degenerate. Spread YY, P1\mathbf P^1, π\pi, and A\mathcal{A} over Z[S−1]\mathbb{Z}[S^{-1}] so that the curves are smooth and proper, π\pi is finite and étale away from the branch sections, and

π∗b=2Db\pi^*b = 2D_b

as relative Cartier divisors, with DbD_b the reduced inverse image, finite étale over the ground ring. The abelian scheme also spreads over this proper model of YY.

Lemma 4.1. For s∈P1(Q)∖Cs\in\mathbf P^1({\mathbb{Q}})\setminus\mathcal C, put M=MS(s)M = M_S(s). There is a Galois extension K0/QK_0/\mathbb{Q} of uniformly bounded degree splitting the fiber π−1(s)\pi^{-1}(s), unramified outside S∪{q:q∣M}S \cup\{q : q \mid M\}. Every fiber A=AyA=\mathcal A_y above ss is defined over K0K_0 and has good reduction at every place of K0K_0 outside SS.

Proof. The fiber has at most deg⁡π\deg\pi geometric points, so its splitting field is Galois of degree at most (deg⁡π)!(\deg\pi)!. Fix q∉Sq \notin S. If the reduction of ss avoids the branch sections, finite étaleness implies that the fiber is unramified at qq. Otherwise it meets exactly one branch section bb, and its contact order is

vq(Lb(u,v))−min⁡{vq(u),vq(v)}.v_q(L_b(u,v))-\min\{v_q(u),v_q(v)\}.

After a finite unramified local extension, all points of DbD_b over this reduction are defined, since DbD_b is finite étale. At each such point choose a formal coordinate zz cutting out DbD_b. If tt cuts out bb on the base, the divisor equality gives π∗t=z2e(z)\pi^*t = z^2e(z) with e(z)e(z) a unit. After a further unramified extension its residue has a square root, and Hensel’s lemma, since q≠2q \ne2, gives a square root of e(z)e(z) in the formal power-series ring. Replacing zz by ze(z)z\sqrt{e(z)} changes the local equation to t=z2t=z^2. Make this calculation at every point of DbD_b over the branch reduction, using a common further finite unramified extension.

If the contact order is even, a square root of t(s)t(s) is obtained over an unramified extension by extracting the square root of its unit part. Both local lifts at every such point are consequently unramified. By properness, every geometric point of the fiber specializes to one of the points of DbD_b just treated, so the whole fiber is unramified. This proves that ramification can occur only at the primes in the assertion.

Every K0K_0-point yy extends over the local valuation rings outside SS by properness of YY. Pulling back the spread abelian scheme along these sections gives good reduction of Ay\mathcal A_y. This also applies at places where K0/QK_0/\mathbb{Q} is ramified. Thus field ramification may occur at primes dividing MM, while good reduction over K0K_0 holds outside the fixed set SS.

This use of contact multiplicities has a classical specialization precedent. Darmon and Granville work with a fixed Galois cover of the projective line branched at 0,1,∞0,1,\infty. In that setting, their Proposition 3.2, credited there to Beckmann, relates divisibility of contact orders by branch indices to the absence of new ramification outside fixed bad primes in specialized fiber fields [11]. For the cover used here, the local equation t=z2t=z^2 makes the parity of the contact order relevant.

Comparison of base height and Faltings height

The fiber-field lemma identifies the primes that may ramify when a rational base point is lifted to the family. We also need to recover the height of that base point from the fiber. The next lemma depends only on the fixed family, and applies to every algebraic point of YY.

Lemma 4.2. For every y∈Y(Q‾)y \in Y(\overline{\mathbb{Q}}) one has

h(π(y))≤C(1+max⁡{0,hF(Ay)}),{h}(\pi(y))\le C\bigl(1+\max\{0,h_{\mathrm F}(\mathcal A_y)\}\bigr),

with a constant independent of yy and its field of definition.

Proof. We will use a theta-null map with two properties: its projective height agrees up to a fixed additive constant with Pazuki’s theta height hΘh_{\Theta} of the fiber, and the map is nonconstant on each component of a fixed cover of YY. Here hΘh_{\Theta} is the projective height of the theta-null point for the corresponding polarization and level [51]. The second property makes the pulled-back O(1)\mathcal{O}(1) ample on the covering curve. Comparing that ample height with the pullback of the base height gives

h(π(y))≪1+hΘ(Ay).{h}(\pi(y))\ll 1+h_\Theta(\mathcal A_y).

Pazuki’s comparison of theta and Faltings height will then prove the lemma. We first construct a map with the two stated properties.

For every fixed even integer r≥2r \ge2, the required algebraic theta data can be chosen after a finite cover of each geometric component of YY. Over a finite extension of its function field, choose a symmetric ample line bundle M\mathcal{M} representing the principal polarization, together with the theta data of [51]. These choices require only a finite extension: a representative of a geometric principal polarization can be made symmetric by translation, and the torsion points and finite theta data are defined after a finite extension. They spread over a dense open subset of the smooth projective covering curve, where the theta-null map is algebraic. The value of this map at a fiber is the zero-section point Θ(0)\Theta(0) constructed from Pazuki’s good choices of theta data; after complex uniformization of that fiber, [51], Sections 2.3.2–2.3.4] identifies this point, up to the finite coordinate ambiguity among good choices, with the characteristic Nullwerte displayed below. These covers and data may depend on rr; we will fix the final level after proving nonconstancy.

We next compare the projective height of this map with Pazuki’s theta height, uniformly in the fiber at any fixed rr. For a fiber A=AyA=\mathcal A_y and a period matrix τ\tau for its principal polarization, the characteristic coordinates can be taken to be

θ[a,b](τ,0)=∑n∈Z2exp⁡(πi(n+a)tτ(n+a)+2πi(n+a)tb),a,b∈(r−1Z2)/Z2.\theta[a,b](\tau,0)= \sum_{n\in{\mathbb{Z}}^2} \exp\bigl(\pi i(n+a)^{\mathrm t}\tau(n+a) +2\pi i(n+a)^{\mathrm t}b\bigr), \quad a,b\in(r^{-1}{\mathbb{Z}}^2)/{\mathbb{Z}}^2.

Start with a nonzero section of M\mathcal{M}, whose space of sections has dimension one, pull it back by [r][r], and use [r]∗M≃Mr2[r]^*\mathcal{M} \simeq\mathcal{M}^{r^2}. Translating by the theta group over representatives of A[r2]/A[r]A[r^2]/A[r] gives these coordinates. Changing the generating section multiplies all coordinates by one common scalar. Two symmetric representatives differ by a two-torsion element of Pic⁡0\operatorname{Pic}^0, which shifts the half-characteristic; these shifts are included because rr is even.

Put k=r2k = r^2. At the generic fiber of the chosen cover, let gxg_x denote the good theta-group lift of a kk-torsion point xx. These lifts satisfy the good-choice relation gxgy=ζx,ygx+yg_xg_y = \zeta_{x,y}g_{x+y} with ζx,y∈μk\zeta_{x,y} \in\mu_k. It gives g0∈μkg_0 \in\mu_k and, by iteration at kx=0kx = 0, gxk∈μkg_x^k \in\mu_k; hence gxk2=1g_x^{k^2} = 1. Choose ux=cxgxu_x = c_xg_x with ux2k=1u_x^{2k} = 1 by taking a 2k2k-th root of the central scalar (gx2k)−1(g_x^{2k})^{-1}. Since 2k∣k22k \mid k^2, we have cxk2=uxk2gx−k2=1c_x^{k^2} = u_x^{k^2}g_x^{-k^2} = 1. These finitely many roots can be chosen once after a finite constant extension of the function field and spread with the good data. We use these normalizations only to compare coordinates of the fixed good-choice theta-null map.

In analytic theta coordinates, a lift of translation by (m+τl)/k(m+\tau l)/k is given by shifting the argument and multiplying by

exp⁡(πiltτl/k+2πiltz).\exp(\pi i l^{\mathrm t}\tau l/k+2\pi i l^{\mathrm t}z).

Theta automorphy shows that its order divides 2k2k and that it permutes θ[a,b](τ,rz)\theta[a,b](\tau,rz), up to bounded-order roots of unity, by (a,b)↦(a+l/r,b+m/r)(a,b) \mapsto(a+l/r,b+m/r). Two lifts of the same translation whose 2k2k-th powers are one differ by a scalar in μ2k\mu_{2k}. Thus comparison with the algebraic uxu_x introduces a μ2k\mu_{2k} factor after the preceding μk2\mu_k^2 change from the good lift. All these coordinate roots of unity preserve projective height, as do permutations and a common scalar.

The customary Fourier change of theta basis is a fixed invertible matrix at this level, so it changes height by Or(1)O_r(1). Grouping r(n+a)r(n+a) modulo kk in (4.3) relates these coordinates blockwise by finite Fourier matrices to θ[e/k,0](kτ,0)\theta[e/k,0](k\tau,0), ee mod kk. There are r4r^4 independent sections, as required by h0(Mr2)=r4h^0(\mathcal{M}^{r^2}) = r^4, and their values are not all zero since Mr2\mathcal{M}^{r^2} is basepoint-free. Pazuki’s exact theta height uses the ℓ2\ell^2 projective height [51], Definition 2.6; its difference from the usual projective height is also bounded at this fixed level. These comparisons give one additive constant depending on rr, not on the fiber or its field of definition.

It remains to choose a level at which the theta-null map is nonconstant. The following argument avoids an assumption about generic injectivity of a particular theta map. Take a connected analytic disk with a fixed homology marking on which the period matrix varies. Suppose the projective vectors in (4.3) were constant at every sufficiently divisible even level. At a chosen period τ0\tau_0, select rational b0b_0 with θ[0,b0](τ0,0)≠0\theta[0,b_0](\tau_0,0) \ne0; such a b0b_0 exists since the function of real bb has constant Fourier coefficient one. Shrink the disk so its denominator stays nonzero. At a common level containing bb and b0b_0, projective constancy implies that

θ[0,b](τ,0)θ[0,b0](τ,0)\frac{\theta[0,b](\tau,0)}{\theta[0,b_0](\tau,0)}

is constant as τ\tau varies, for every rational bb. Density of rational bb, continuity, and absolute convergence of the theta series show that the functions of real bb for τ\tau and τ0\tau_0 are proportional. Their constant Fourier coefficients are one, so they are equal. Consequently every exp⁡(πintτn)\exp(\pi i n^{\mathrm t}\tau n) is constant. Taking n=ein=e_i and n=ei+ejn=e_i+e_j and using continuity forces τ\tau itself to be constant, a contradiction. A level with a nonconstant vector therefore exists. Nonconstancy persists at multiples of that level because the old characteristic coordinates occur among the new ones. A common even multiple works for the finitely many components.

Fix this common level, and make the preceding choices of covers and theta data at that level. The finitely many covering curves, maps, and open subsets are now fixed, and can all be defined over a fixed number field. On each base component, choose a smaller marked disk avoiding the branch values of the covers and the images of their omitted points, and take a connected lift to each covering curve above it. The selected holomorphic characteristic vector remains nonconstant on the smaller disk. If the theta-null map were constant on a covering curve, the preceding pointwise identification would confine that vector on the connected lift to a fixed finite set. Continuity and connectedness would then make it constant. Thus the theta-null map is nonconstant on each covering curve and extends across the omitted points. Its pullback of O(1)\mathcal{O}(1) has positive degree and is ample. A sufficiently large multiple of this line bundle minus the pullback by π\pi of OP1(1)\mathcal O_{\mathbf P^1}(1) also has positive degree. The height machine and the lower bound for an ample height on a projective curve therefore give

h(π(y))≤C(1+hΘ(Ay)){h}(\pi(y))\le C(1+h_\Theta(\mathcal A_y))

on the open where the theta data are defined [3]. Here hΘh_{\Theta} is Pazuki’s exact theta height; the bounded coordinate and projective-height comparisons have already been absorbed in (4.4). Pazuki uses the Deligne normalization

hFD(A)=hF(A)+dim⁡A2log⁡π;h_{\mathrm{F}}^{\mathrm{D}}(A)=h_{\mathrm{F}}(A)+\frac{\dim A}{2}\log\pi;

compare [51], Section 2.2 and [24], Section 2.3. Here hFh_{\mathrm{F}} is the original stable Faltings height. For the present surfaces the difference is the fixed constant log⁡π\log\pi.

For HΘ=max⁡{hΘ,1}H_{\Theta}=\max\{h_{\Theta},1\} and HD=max⁡{hFD,1}H_{\mathrm{D}}=\max\{h_{\mathrm{F}}^{\mathrm{D}},1\}, [51], Corollary 1.3(2) gives

∣HΘ−12HD∣≤C2log⁡(min⁡{HΘ,HD}+2),\left|H_{\Theta}-\frac{1}{2}H_{\mathrm{D}}\right| \le C_2\log(\min\{H_{\Theta},H_{\mathrm{D}}\}+2),

where C2C_2 depends only on dimension and level. Since log⁡(HD+2)≤2HD\log(H_{\mathrm{D}}+2)\le2H_{\mathrm{D}} and HD≤max⁡{hF,1}+log⁡πH_{\mathrm{D}}\le\max\{h_{\mathrm{F}},1\}+\log\pi for these surfaces, we obtain

hΘ≤C(1+max⁡{0,hF}).h_{\Theta}\le C(1+\max\{0,h_{\mathrm{F}}\}).

Combining this with (4.4) proves the assertion on the chosen open sets.

The omitted points on the fixed covering curves form a finite geometric set. Their base heights are bounded, and enlarging CC handles them. Absolute heights and stable Faltings heights are unchanged by field extension, so passing to points of the fixed covers introduces no dependence on their residue-field degrees. Taking the maximum over the finitely many components proves the lemma. □

Remark 4.3 (An alternative deduction on the compact moduli image). The same numerical comparison can alternatively be deduced by bounding the period term in Pazuki’s Theorem 1.1 for this family. That theorem compares hΘ−12hFDh_{\Theta}-\frac{1}{2}h_{\mathrm{F}}^{\mathrm{D}} with the average of logarithms of determinants of imaginary parts of Siegel-reduced periods, with bounded error at fixed dimension and level [51]. The determinant terms are bounded here. The moduli image is compact because YY is projective, and the minimum nonzero period length in the polarization metric has a positive lower bound on it. On the subgroup Z2\mathbb{Z}^{2} of the period lattice the metric has matrix (Im⁡τ)−1(\operatorname{Im}\tau)^{-1}. Minkowski’s theorem bounds det⁡Im⁡τ\det\operatorname{Im}\tau above in terms of that minimum length, and Siegel reduction bounds it below by a positive constant. These bounds hold at every embedding, because every conjugate belongs to the fixed compact moduli image. Theorem 1.1 and the same normalization conversion therefore also give hΘ≤C(1+max⁡{0,hF})h_{\Theta}\le C(1+\max\{0,h_{\mathrm{F}}\}).

A field of definition for homomorphisms

We now choose the fiber used in the arithmetic proof. Fix s∈P1(Q)∖Cs\in\mathbf P^1({\mathbb{Q}})\setminus\mathcal C, put M=MS(s)M=M_{S}(s) and T=S∪{q:q∣M}T=S\cup\{q:q\mid M\}, and choose yy above ss. Let A=AyA=\mathcal A_y and choose the splitting field K0K_{0} from Lemma 4.1. Since π\pi is defined over Q\mathbb{Q} and ss is rational, π(gy)=g(s)=s\pi({}^g y)=g(s)=s for every g∈GQg\in G_{\mathbb{Q}}. The common-base property of the family therefore makes the conjugates of AA geometrically isogenous. The descent argument needs all their homomorphisms over one Galois field. We can define them without losing the bounded degree or introducing ramification at further primes.

Lemma 4.4. There is a Galois extension L/QL/\mathbb{Q} containing K0K_{0}, of uniformly bounded degree, over which all geometric homomorphisms between all Galois conjugates of AA are defined. It is unramified outside TT.

Proof. There are boundedly many conjugates because they are defined over K0K_{0}. Let H\mathcal{H} be the direct sum of the geometric Hom groups indexed by all ordered pairs of these conjugates. This is a free abelian group of bounded rank. Galois transport gives a natural action of GQG_{\mathbb{Q}} on H\mathcal{H}, permuting the summands according to its action on the ordered pairs. The action of GK0G_{K_{0}} on H\mathcal{H} has finite image: a finite set of generators of the Hom groups is defined over a finite extension. Finite subgroups of GL⁡r(Z)\operatorname{GL}_{r}(\mathbb{Z}) have bounded order for bounded rr. Let LL be the fixed field of the kernel of this action inside GK0G_{K_0}. The transport action of GQG_{\mathbb{Q}}, together with normality of GK0G_{K_{0}}, makes that kernel normal in GQG_{\mathbb{Q}}. Thus L/QL/\mathbb{Q} is Galois and its degree is uniformly bounded.

At a place outside TT, the extension K0/QK_{0}/\mathbb{Q} is unramified and all the conjugates have good reduction. For a coefficient prime different from the residue characteristic, inertia acts trivially on their Tate modules and therefore on the Hom groups embedded faithfully between those modules. Thus L/K0L/K_{0} introduces no ramification there. □

All homomorphisms between conjugates, including the prescribed BB-action, are now defined over LL. Its degree is uniformly bounded, and it is unramified outside TT. Extending K0K_{0} to LL preserves good reduction of AA outside the fixed set SS. We now bound hF(A)h_{\mathrm{F}}(A) in terms of MM, beginning with its endomorphism algebra.

The endomorphism dichotomy and descent up to isogeny

The endomorphism algebra determines which comparison will give a height bound for AA. Put D=End⁡Q‾0(A)D=\operatorname{End}^0_{\overline{\mathbb Q}}(A), and let CBC_{B} be the centralizer of the prescribed left BB-action in DD. On rational homology the centralizer of left BB is right BB. A Hodge endomorphism in that centralizer must commute, over R\mathbf R, with the complex structure, whose centralizer in M2(R)M_2(\mathbf R) is C\mathbf C. Thus CBC_{B} is either Q\mathbb{Q} or an imaginary quadratic field kk contained in BB. More explicitly, a nonscalar rational element commuting with the complex structure generates such a quadratic field, and its real centralizer has dimension two, leaving no further possibilities.

Both cases use the following quantitative isogeny theorem to transfer a known height bound. If C1,C2C_{1},C_{2} are gg-dimensional abelian varieties over a number field k0k_{0} of degree dd, and are isogenous over an extension K/k0K/k_0, then there are KK-isogenies in both directions with degree at most

κ(C1)=((14g)64g2dmax⁡{hF(C1),log⁡d,1}2)1024g3.\kappa(C_1)=\left((14g)^{64g^2}d\max\{h_{\mathrm{F}}(C_1),\log d,1\}^2\right)^{1024g^3}.

This is [23], Theorem 1.4, with the definition on p. 2058. It uses the original stable Faltings height and requires neither semistability over k0k_0 nor a principal polarization. In our applications we take K=k0K=k_0. The stable height is additive on products and satisfies

hF(C2)≤hF(C1)+12log⁡deg⁡ϕfor an isogeny ϕ:C1⟶C2h_{\mathrm{F}}(C_2)\le h_{\mathrm{F}}(C_1)+\frac{1}{2}\log\deg\phi\quad\text{for an isogeny }\phi:C_1\longrightarrow C_2

[20]. We will always apply (4.5) to a source whose height has already been bounded.

If CB=kC_B=k, the central-simple-algebra double-centralizer calculation gives

D=B⊗Qk≃M2(k).D=B\otimes_{\mathbb{Q}}k\simeq M_2(k).

The last isomorphism holds because an embedded quadratic field is a maximal subfield of BB and splits it. Matrix idempotents, all defined over LL by Lemma 4.4, give A∼LE2A\sim_L E^2 for a CM elliptic curve E/LE/L: take the image of an integer multiple of a rank-one idempotent, and use the matrix units to identify the two elliptic factors up to isogeny. The degree of j(E)j(E) is at most [L:Q][L:\mathbb{Q}], hence is bounded. Complex multiplication theory identifies the degree of a singular modulus with the class number of its imaginary quadratic order. Class-number growth for imaginary quadratic fields and the formula for class numbers of orders imply that only finitely many such jj-invariants have bounded degree [10, 65]. Their stable elliptic heights, and therefore hF(E2)h_{\mathrm{F}}(E^2), are bounded. Apply (4.5) to the source E2E^2, with dimension two, bounded height, and bounded [L:Q][L:\mathbb{Q}], and then apply (4.6). This bounds hF(A)h_{\mathrm{F}}(A) uniformly. Lemma 4.2 already proves Theorem 2.4 for these fibers, since M≥1M\ge1. The finiteness invoked here need not be effective.

We henceforth treat the other case, CB=QC_B=\mathbb{Q}. The same double-centralizer calculation gives D=BD=B. One can check this calculation after an extension splitting BB: an algebra containing the full 2×22\times2 matrix units is a matrix algebra over their centralizer. Because BB is division, AA is absolutely simple; a proper isogeny factor would give a nontrivial idempotent in DD.

Our goal in this case is to find a primitive weight-two newform ff of level NN, a Galois extension L′/QL'/\mathbb{Q} containing LL, and an abelian variety D0/L′D_0/L' such that, for fixed constants C,a>0C,a>0,

[L′:Q]≤CM,N≤CMa,J1(N)∼L′A×D0.[L':\mathbb{Q}]\le CM,\qquad N\le CM^a,\qquad J_1(N)\sim_{L'} A\times D_0.

Once the height of this modular Jacobian has been bounded in terms of NN, the factorization will let us transfer the bound to AA over a field of controlled degree. We first use the conjugacy isogenies to construct a two-dimensional representation. Their discrepancy under composition will be reduced to a sign and then split with control on both the field degree and inertia.

Compatible-isogeny cocycles and their scalar splittings are part of the theory of Q\mathbb{Q}-curves and building blocks [59], Section 6[56], Chapters 4–5; compare [57], Section 4. The scalar cochain constructed below takes values among roots of unity of order O(M)O(M), and its inertia restrictions will control the modular level.

Put Γ=Gal⁡(L/Q)\Gamma=\operatorname{Gal}(L/\mathbb{Q}). For each g∈Γg\in\Gamma, choose a quasi-isogeny μg:gA→A\mu_g:{}^gA\to A, with μ1=1\mu_1=1, satisfying

μg gα=αμg(α∈B).\mu_g\,{}^g\alpha=\alpha\mu_g\qquad(\alpha\in B).

To obtain it, start with an isogeny between the fibers above the common rational point. Transporting the BB-action along this isogeny gives an automorphism of B=DB=D, which is inner by Skolem–Noether. Composing with the corresponding element of B×B^\times gives (4.7). All these maps are defined over LL by Lemma 4.4.

The maps μggμh\mu_g{}^g\mu_h and μgh\mu_{gh} have the same source and target and both intertwine the BB-actions. Their quotient therefore lies in the centralizer Q×\mathbb{Q}^\times:

μggμh=c(g,h)μgh,c(g,h)∈Q×.\mu_g{}^g\mu_h=c(g,h)\mu_{gh},\qquad c(g,h)\in\mathbb{Q}^\times.

For a quasi-isogeny, use the degree obtained by extending the geometric degree multiplicatively from isogenies. A rational scalar cc on a surface has degree c4c^4, so the last identity gives

∣c(g,h)∣=(deg⁡μgdeg⁡μhdeg⁡μgh)1/4.\lvert c(g,h)\rvert=\left(\frac{\deg\mu_g\deg\mu_h}{\deg\mu_{gh}}\right)^{1/4}.

Let ag=(deg⁡μg)−1/4a_g=(\deg\mu_g)^{-1/4} be the positive real algebraic fourth root. We extend the coefficient scalars in the isogeny category and put

μ~g=agμg∈Hom⁡L0(gA,A)⊗QQ‾.\widetilde\mu_g=a_g\mu_g \in\operatorname{Hom}_L^0({}^gA,A)\otimes_{\mathbb{Q}}\overline{\mathbb{Q}}.

Here Galois transports the Hom factor and acts trivially on the coefficient factor Q‾\overline{\mathbb{Q}}. The preceding degree identity now gives

μ~ggμ~h=ϵ(g,h)μ~gh,ϵ(g,h)=c(g,h)∣c(g,h)∣∈{±1}.\widetilde{\mu}_g{}^g\widetilde{\mu}_h=\epsilon(g,h)\widetilde{\mu}_{gh},\qquad\epsilon(g,h)=\frac{c(g,h)}{\lvert c(g,h)\rvert}\in\{\pm1\}.

Associativity makes ϵ\epsilon a normalized cocycle on Γ\Gamma; we inflate it to GQG_{\mathbb{Q}}. This is the obstruction in the isogeny version of Weil descent. The normalized discrepancy depends only on the sign of c(g,h)c(g,h), so we will not need bounds for the individual degrees deg⁡μg\deg\mu_g.

A scalar cochain with coboundary ϵ\epsilon will cancel this sign. On GLG_L the inflated cocycle is trivial, so the restriction of such a cochain will be a character. We seek one whose restricted character is conjugacy invariant and has controlled order: its kernel will then define a Galois field over which the corrected action agrees with the Tate action of AA. Control on inertia will also be needed to bound the modular level. The following splitting supplies both properties.

Lemma 4.5 (Controlled splitting of the sign obstruction). There is a finite Dirichlet character χ\chi of order m≤CMm\le CM, unramified outside TT, and a continuous cochain β:GQ→μ2m\beta:G_{\mathbb{Q}}\to\mu_{2m} such that

β2=χ,β(g)β(h)β(gh)=ϵ(g,h).\beta^2=\chi,\qquad\frac{\beta(g)\beta(h)}{\beta(gh)}=\epsilon(g,h).

The cochain can be chosen trivial on inertia at every prime outside TT. Its restriction to GLG_L is a conjugacy-invariant character. The local conductor of χ\chi at any fixed prime is bounded independently of ss, and χ\chi is tame at odd primes.

Proof. Identify H2(GQ,{±1})=Br⁡(Q)[2]H^2(G_{\mathbb{Q}},\{\pm1\})=\operatorname{Br}(\mathbb{Q})[2]. At a prime outside TT, the cocycle factors through the unramified quotient Z^\widehat{\mathbb{Z}}, which has cohomological dimension one on torsion coefficients. Its local class is therefore zero. We use local reciprocity and the Brauer local-global theorem in the form described in [64, 42, 41].

For a finite character χv\chi_v with values in Q‾×\overline{\mathbb{Q}}^\times with trivial coefficient action, its square-root obstruction ∂χv\partial\chi_v in H2(GQv,{±1})H^2(G_{\mathbb{Q}_v},\{\pm1\}) vanishes if and only if χv\chi_v has a continuous character square root. By reciprocity this is equivalent to its being trivial on the order-two subgroup of Qv×\mathbb{Q}_v^\times, that is, on −1-1. To verify the equivalence, use Zp×≃μp−1×Zp\mathbb{Z}_p^\times\simeq\mu_{p-1}\times\mathbb{Z}_p for odd pp, and Z2×≃{±1}×Z2\mathbb{Z}_2^\times\simeq\{\pm1\}\times\mathbb{Z}_2 at 22. A character of the infinite cyclic valuation factor has a square root by choosing a square root of its value on a uniformizer; the procyclic free factors also admit character square roots. The only obstruction in the finite cyclic torsion factors is the value on their element of order two. At the real place the same assertion follows directly from GR=Z/2ZG_{\mathbf R}={\mathbb{Z}}/2{\mathbb{Z}}.

At each odd finite prime with nonzero local class of ϵ\epsilon, choose an odd character modulo that prime, so its value at −1-1 is −1-1. At 2, if necessary, use the nontrivial character modulo 4. Their product is a global Dirichlet character χ\chi. Its local square-root obstruction matches that of ϵ\epsilon at every finite place. The real invariant matches too, because the sum of local invariants of a Brauer class is zero. Injectivity in the Brauer local-global theorem gives ∂χ=[ϵ]\partial\chi= [\epsilon].

Each odd-prime factor has order at most q−1q-1, and the factor at 2 has order two. Thus the order mm of their product satisfies

m≤2∏q∈T, q≠2(q−1)≤CM.m\le 2\prod_{q\in T,\ q\ne2}(q-1)\le C M.

The conductor at an odd prime divides that prime, and the conductor at 2 divides 4. Factors at other primes are unramified locally; this proves the stated local conductor assertions.

Choose a continuous set-theoretic square root of χ\chi, valued in μ2m\mu_{2m}. Equality of the obstruction classes allows its coboundary to be corrected to exactly ϵ\epsilon by a sign-valued continuous cochain. The resulting β\beta satisfies (4.9). On GLG_L the inflated cocycle is identically one, so β\beta restricts to a character. Its conjugacy invariance follows from the cochain identity: if u∈GLu \in G_L and g∈GQg \in G_{\mathbb{Q}}, then ϵ(g,u)=ϵ(gug−1,g)=1\epsilon(g,u)=\epsilon(gug^{-1},g)=1, and comparison of β(gu)\beta(gu) computed in these two ways gives β(gug−1)=β(u)\beta(gug^{-1})=\beta(u).

At an odd prime outside TT, inertia fixes LL, and χ\chi is unramified, so the restriction of β\beta to inertia is a sign character. Only finitely many such restrictions are nontrivial, because a continuous function to the finite set μ2m\mu_{2m} factors through a finite quotient of GQG_{\mathbb{Q}}. At an odd prime there is a unique nontrivial quadratic character of inertia: wild inertia is pro-odd and the tame quotient has a unique quotient of order two. Let dβd_\beta be a squarefree integer whose odd prime factors are precisely these offending primes. Multiplication of β\beta by the quadratic character of Q(dβ)\mathbb{Q}(\sqrt{d_\beta}) cancels all the unwanted inertia characters. This quadratic character is unramified away from those primes and possibly 2∈S2 \in S. Its square is one and its coboundary is one, so (4.9) and the restriction properties are preserved. Since {±1}⊂μ2m\{\pm1\} \subset\mu_{2m}, the corrected cochain still takes values in μ2m\mu_{2m}, whose elements have orders dividing 2m≤CM2m \le CM.

Two-dimensional representations and modularity

We construct representations at coefficient primes 2 and 3. The 2-adic one will yield a modular form. The 3-adic one will measure the conductor at 2, where the conductor comparison requires a coefficient prime different from the residue prime. This requires identifying both representations with the same newform.

Fix coefficient embeddings Q‾↪Q‾ℓ\overline{\mathbb{Q}} \hookrightarrow\overline{\mathbb{Q}}_\ell for ℓ=2,3\ell=2,3. On the covariant rational Tate module of AA with these extended coefficients put

Rℓ(g)=β(g)μ~gˉ∘g,g∈GQ,gˉ=g∣L.R_\ell(g)=\beta(g)\widetilde\mu_{\bar g}\circ g, \qquad g\in G_{\mathbb{Q}},\quad \bar g=g|_L.

Here gg first transports torsion points to gA{}^gA, and the quasi-isogeny returns them to AA. In a composition the discrepancy of the maps is ϵ(g,h)\epsilon(g,h), and the discrepancy of the scalar cochain is the same sign. Their product is one. Thus RℓR_\ell is a genuine continuous representation. All algebraic coefficients and the splitting of BB can be taken in one finite extension of Qℓ{\mathbb{Q}}_\ell for each ℓ\ell.

Equation (4.7) shows that RℓR_\ell commutes with BB. After coefficient extension, B⊗Q‾ℓ≃M2(Q‾ℓ)B \otimes\overline{\mathbb{Q}}_\ell\simeq M_2(\overline{\mathbb{Q}}_\ell); the matrix units then give

Rℓ≃rℓ⊕rℓR_\ell\simeq r_\ell\oplus r_\ell

for a two-dimensional representation rℓr_\ell. On GLG_L the quasi-isogeny in (4.10) is μ~1=1\widetilde{\mu}_1=1, so only the character β∣GL\beta|_{G_L} separates RℓR_\ell from the Tate action of AA. Define

GL′=ker⁡(β∣GL).G_{L'}=\ker(\beta|_{G_L}).

Conjugacy invariance of this character makes L′/QL'/\mathbb{Q} Galois, and its image has order at most 2m2m. Consequently

[L′:Q]≤2m[L:Q]≤CM.[L':\mathbb{Q}] \leq2m[L:\mathbb{Q}] \leq CM.

On GL′G_{L'}, the representation RℓR_\ell is exactly the Tate-module representation of AA, with coefficients extended. This field will allow us to recover an abelian factor over L′L'. Its degree may grow with MM; the local conductor argument will use LL, whose degree is uniformly bounded.

The modularity input is [49] in its exact form: every continuous irreducible odd two-dimensional 2-adic representation of GQG_{\mathbb{Q}}, unramified outside finitely many primes and de Rham at 2 with distinct Hodge–Tate weights, is a Tate twist of the representation associated with a classical cuspidal eigenform. There is no residual-image hypothesis in that statement. We now verify its hypotheses for r2r_2. The same arguments also give the properties of r3r_3 used below. The commutant and Hodge-decomposition arguments have antecedents in [59]; we apply them to the corrected action (4.10).

By Faltings’ semisimplicity and endomorphism theorems,

End⁡GL′(Vℓ(A))=End⁡L′(A)⊗Qℓ=B⊗Qℓ\operatorname{End}_{G_{L'}}(V_\ell(A))=\operatorname{End}_{L'}(A)\otimes\mathbb{Q}_\ell=B\otimes\mathbb{Q}_\ell

[20]. Therefore rℓ∣GL′r_\ell|_{G_{L'}} is semisimple with scalar commutant after algebraic coefficient extension, and is absolutely irreducible. So is rℓr_\ell.

The de Rham comparison theorem for smooth proper varieties, together with its Hodge–Tate decomposition, applies to AA over every completion of L′L' at its coefficient prime [61]; see also the corrected definitions in [62]. Since the covariant Tate module is dual to first étale cohomology, Vℓ(A)V_\ell(A) is de Rham with cyclotomic exponents 0,10,1, each twice. The de Rham property descends through finite local extensions [21]. Thus RℓR_\ell is de Rham over Qℓ\mathbb{Q}_\ell, and its decomposition (4.11) gives exponents 0,10,1, each once, for rℓr_\ell. Here the cyclotomic character has exponent 11 and Hodge–Tate weight −1-1.

For complex conjugation jj, the involution rℓ(j)r_\ell(j) cannot be scalar. If it were, (4.11) would make Rℓ(j)R_\ell(j) scalar too. Under comparison with Betti homology, μjˉ∘j\mu_{\bar j}\circ j is conjugation followed by a holomorphic quasi-isogeny. It exchanges the two nonzero Hodge subspaces, whereas a scalar preserves both. Multiplying by the nonzero algebraic coefficient in (4.10) does not change this fact. Hence the two eigenvalues of rℓ(j)r_\ell(j) are 11 and −1-1, and rℓr_\ell is odd.

At a prime outside T∪{ℓ}T\cup\{\ell\}, inertia fixes LL, AA has good reduction, and the corrected β\beta is trivial. Thus rℓr_\ell is unramified there. In particular it is ramified at only finitely many primes. All hypotheses of the stated modularity theorem now hold for r2r_2. Applying it realizes r2r_2 as a Tate twist of the representation associated with a classical cuspidal eigenform.

We use the arithmetic-Frobenius normalization in which a weight-kk form ff has good traces aq(f)a_q(f) and determinant ψfχcyck−1\psi_f\chi_{\mathrm{cyc}}^{k-1}. Its cyclotomic exponents are 0,k−10,k-1; the companion fixes this convention in [49]. The two exponents 0,10,1 of r2r_2 therefore force weight two and Tate shift zero. Thus r2r_2 is realized by the arithmetic 2-adic representation of a normalized primitive weight-two newform.

For comparison with a dual presentation, if an intermediate realization is written as Vf,2∨⊗χcycnV_{f,2}^{\vee} \otimes\chi_{\mathrm{cyc}}^n, then

Vf,2∨⊗χcycn≃Vg,2⊗χcycn+1−k,g=(f⊗ψf−1)new.V_{f,2}^{\vee}\otimes\chi_{\mathrm{cyc}}^n \simeq V_{g,2}\otimes\chi_{\mathrm{cyc}}^{n+1-k}, \qquad g=(f\otimes\psi_f^{-1})_{\mathrm{new}}.

Here gg is the primitive newform of the indicated finite-character twist. The target exponents 0, 1 give k=2k = 2, n=1n = 1 in this presentation, and hence arithmetic Tate exponent zero. Changing from arithmetic to geometric Frobenius inverts the evaluated eigenvalues; it does not dualize the representation. After this conversion when necessary, let ff denote the normalized primitive newform whose arithmetic 2-adic representation realizes r2r_2, and let NN be its level.

To use r3r_3 for the dyadic conductor of this level, we must identify it with the same algebraic conjugate of ff. A single algebraic trace, obtained from the good special fiber, will compare the two coefficient primes.

Lemma 4.6. The representation r3r_3 is the 3-adic representation of the same algebraic conjugate of ff that realizes r2r_2.

Proof. Fix a rational prime q∉T∪{2,3}q \notin T \cup\{2, 3\} with q∤Nq \nmid N, a place of Q‾\overline{\mathbb{Q}} above qq, and an arithmetic Frobenius gg in that decomposition group. These primes form a cofinite set, as needed for the Chebotarev argument below. The automorphism induced by gg on the residue field F‾q\overline{\mathbf F}_q is x↦xqx \mapsto x^q. Therefore the reduction of gA{}^gA is the Frobenius twist A~(q)\widetilde{A}^{(q)} of the same geometric special fiber A~\widetilde{A}. Specialization of prime-to-qq torsion identifies the action of gg with the relative Frobenius map A~→A~(q)\widetilde{A} \to\widetilde{A}^{(q)}. A multiple of μg‾\mu_{\overline{g}} extends over good reduction, and its reduction, after dividing by that integer, maps A~(q)\widetilde{A}^{(q)} back to A~\widetilde{A}. The composite is thus an element

uq=red⁡(μg‾)∘Frob⁡qrel∈End⁡0(A~).u_q = \operatorname{red}(\mu_{\overline{g}}) \circ\operatorname{Frob}^{\mathrm{rel}}_q \in\operatorname{End}^0(\widetilde{A}).

Here red⁡(μg‾)\operatorname{red}(\mu_{\overline{g}}) is reduction of the unnormalized quasi-isogeny; the scalar ag‾a_{\overline{g}} from degree normalization is inserted below.

The characteristic polynomial of an endomorphism of an abelian variety on rational Tate modules has rational coefficients and is independent of the coefficient prime. This applies to a rational endomorphism after clearing denominators [40]. Consequently

αq=12β(g)ag‾Tr⁡(uq)∈Q‾\alpha_q = \frac{1}{2}\beta(g)a_{\overline{g}}\operatorname{Tr}(u_q) \in\overline{\mathbb{Q}}

is a single algebraic number whose images at 2 and 3 are the traces of r2(g)r_2(g) and r3(g)r_3(g), respectively. The factor 1/21/2 comes from (4.11). This construction is independent of any comparison of coefficient-field degrees.

The identification of r2r_2 with the representation of ff selects an embedding of its Hecke field in Q‾\overline{\mathbb{Q}}. Injectivity of the fixed embedding Q‾↪Q‾2\overline{\mathbb{Q}} \hookrightarrow\overline{\mathbb{Q}}_2 then gives αq=aq(f)\alpha_q = a_q(f) as algebraic numbers at every good prime. Under the chosen embedding at 3, the same equalities hold. Chebotarev density and the character criterion for semisimple representations [40] identify r3r_3 with that member of the compatible system of ff [15]. Semisimplicity on our side follows already from irreducibility. □

A uniform bound for the modular level

Lemma 4.7. There are fixed constants C,a>0C, a > 0 such that

N≤CMa.N \leq C M^a.

Proof. For a primitive weight-two form, the local newform conductor is the exponent of qq in its primitive level. Local–global compatibility, with conductor preservation under the local correspondence, identifies this with the Artin-conductor exponent of its ℓ\ell-adic representation whenever q≠ℓq \ne\ell [5], Theorem A in Section 0.7, with the normalization in Section 0.5. The conductor includes the Weil–Deligne monodromy contribution. We use r2r_2 at all primes other than 2, and r3r_3 at 2, justified by Lemma 4.6. The exponent is zero at q∉Tq \notin T by the unramified assertion above.

First let q∈Tq \in T be larger than a fixed constant that includes all primes in SS, the primes 2, 3, and the uniform upper bound for [L:Q][L:\mathbb{Q}]. Wild inertia, a pro-qq group, acts trivially on LL. The surface has good reduction over LL at this prime, so wild inertia also acts trivially on its prime-to-qq Tate modules. On this subgroup β\beta is a character, and its square is the tame character χ\chi. Hence its wild restriction is sign-valued and must be trivial, as qq is odd. Formula (4.10) makes RℓR_\ell tame at qq, and hence rℓr_\ell is tame there as well. Its dimension is two, so its conductor exponent is at most two.

It remains to bound the exponents at the fixed finite set of smaller primes. Fix one of them, say qq, a place vv of LL above it, and put F=LvF=L_v. Let ℓ≠q\ell\ne q be the coefficient prime chosen above. Only finitely many embedded extensions F/QqF/\mathbb{Q}_q can occur, because their degrees are bounded. We seek a bound uqu_q, independent of ss, such that for every u>uqu > u_q the upper ramification group GQquG_{\mathbb{Q}_q}^u lies in GFG_F, is killed by the character β∣GF\beta|_{G_F}, and acts trivially on Vℓ(A)V_\ell(A). On such a group g∣L=1g|_L=1, so the quasi-isogeny in Rℓ(g)R_\ell(g) is also the identity. We obtain this bound by controlling the character and the Tate action over the finitely many possible fields FF.

First consider the character. By local reciprocity, the square of β∣GF\beta|_{G_F} corresponds to χ∘Norm⁡F/Qq\chi\circ\operatorname{Norm}_{F/\mathbb{Q}_q}. Although the global order of χ\chi may grow with MM, its conductor on Qq\mathbb{Q}_q-units is uniformly bounded: of the constructed Dirichlet factors only the factor at qq ramifies there. Choose an integer bb large enough, uniformly over the finitely many possibilities for FF, that this square character is trivial on UFb=1+mFbU_F^b=1+\mathfrak{m}_F^b and that the local logarithm identifies UFbU_F^b with mFb\mathfrak{m}_F^b. Then β(UFb)⊂{±1}\beta(U_F^b)\subset\{\pm1\}. For odd qq, squaring maps UFbU_F^b onto itself, and therefore β\beta kills UFbU_F^b. For q=2q=2, writing eF=vF(2)e_F=v_F(2) gives

(UFb)2=UFb+eF(U_F^b)^2=U_F^{b+e_F}

in these logarithmic coordinates. Thus β\beta kills a uniformly deeper unit group also at 2. Reciprocity gives a uniform upper ramification cut for this character. The quadratic correction in Lemma 4.5 does not affect the argument, because it leaves β2=χ\beta^2=\chi unchanged. An arbitrarily large unramified character order has no effect on a unit-filtration bound.

Next consider the Tate action. Choose a fixed prime p0≥3p_0\ge3, different from qq, and put

F1=F(A[p0]).F_1=F(A[p_0]).

Its degree satisfies [F1:F]≤∣GL⁡4(Fp0)∣[F_1:F]\le|\operatorname{GL}_4(\mathbb{F}_{p_0})|. The semistable reduction criterion says that inertia is unipotent over F1F_1 [66], Theorem 3.5. Its wild pro-qq subgroup has trivial action on Vℓ(A)V_\ell(A), since a compact unipotent subgroup of GL⁡4(Qℓ)\operatorname{GL}_4(\mathbb{Q}_\ell) has no nontrivial pro-qq subgroup when ℓ≠q\ell\ne q. Since both [F:Qq][F:\mathbb{Q}_q] and [F1:F][F_1:F] are bounded, the fields F1F_1 and their normal closures over Qq\mathbb{Q}_q also range over finite sets.

Choose an upper ramification cut over Qq\mathbb{Q}_q exceeding the breaks of all these finite field extensions and whose images under the finitely many relevant Herbrand inverse functions exceed the cuts for β∣GF\beta|_{G_F}. The subgroup and quotient rules for upper ramification groups then place every sufficiently high GQquG_{\mathbb{Q}_q}^u inside GFG_F, in the kernel of β∣GF\beta|_{G_F}, and in the wild Tate-module kernel over F1F_1 [64]. On this group μ~gˉ=μ~1=1\widetilde\mu_{\bar g}=\widetilde\mu_1=1, so (4.10) makes RℓR_\ell trivial there. Its decomposition (4.11) then makes rℓr_\ell trivial there as well. We have therefore obtained the required uniform upper cut uqu_q for rℓr_\ell, independent of ss. Its Swan conductor is at most 2uq2u_q. The remaining contribution from inertia invariants, including Weil–Deligne monodromy, is at most two because rℓr_\ell has dimension two. This bounds its full conductor exponent at the fixed prime.

The finitely many fixed primes contribute a constant to NN. Every remaining ramified prime divides MM and has exponent at most two, so their product contributes at most M2M^2. This proves (4.13), and the proof allows a=2a=2 after altering the fixed constant. The uniform local bounds use the bounded degree of LL; (4.12) supplies the degree of the field L′L' for the global isogeny estimate.

The modular factor and the final height bound

For elliptic curves over Q\mathbb{Q}, Murty and Pasten earlier obtained an effective O(Nlog⁡N)O(N\log N) bound for Faltings height in terms of the conductor, with applications to SS-unit equations [46], Theorems 1.1 and 7.1. The abelian-variety comparison used in this final step follows the modular height strategy of von Känel [70], Sections 1.2 and 5; see also [1]. The preceding descent and ramification arguments provide the point-dependent fields and the level bound needed to apply that strategy here.

Let J=J1(N)J=J_1(N). The weight-two Eichler–Shimura realization places r2r_2 in V2(J)⊗Q‾2V_2(J)\otimes\overline{\mathbb{Q}}_2 [58], Theorem 2.1 and the following weight-two realization. We will turn this shared constituent into a nonzero homomorphism A→JA\to J over L′L'. The next argument descends a Hom from the extended coefficient field to Q2\mathbb{Q}_2, giving the abelian factor over L′L' itself.

Lemma 4.8. There is an abelian variety D0/L′D_0/L' such that

J∼L′A×D0.J \sim_{L'} A \times D_0.

Proof. Put V=V2(A)V=V_2(A), W=V2(J)W=V_2(J), and H=GL′H=G_{L'}. After extending coefficients, VV is two copies of r2∣Hr_2|_H, while WW contains at least one copy. Hence Hom⁡H(V⊗Q‾2,W⊗Q‾2)≠0\operatorname{Hom}_H(V\otimes\overline{\mathbb{Q}}_2,W\otimes\overline{\mathbb{Q}}_2)\ne0. Invariants commute with coefficient extension in this situation. Indeed, in the finite-dimensional space Hom⁡Q2(V,W)\operatorname{Hom}_{\mathbb{Q}_2}(V,W) they are the intersection of the kernels of the linear equations expressing commutation with each h∈Hh\in H. Finitely many of these equations cut out that same intersection, by stabilization of dimensions. Kernels of this finite system commute with scalar extension. Thus

Hom⁡H(V,W)⊗Q‾2=Hom⁡H(V⊗Q‾2,W⊗Q‾2)≠0.\operatorname{Hom}_H(V,W)\otimes\overline{\mathbb{Q}}_2=\operatorname{Hom}_H(V\otimes\overline{\mathbb{Q}}_2,W\otimes\overline{\mathbb{Q}}_2)\ne0.

Faltings’ homomorphism theorem identifies Hom⁡H(V,W)\operatorname{Hom}_H(V,W) with Hom⁡L′(A,J)⊗Q2\operatorname{Hom}_{L'}(A,J)\otimes\mathbb{Q}_2, so an actual nonzero L′L'-homomorphism A→JA\to J exists. Absolute simplicity makes its kernel finite. Poincare complete reducibility over L′L' then gives the claimed factor [20, 45]. A single shared constituent was sufficient to produce the Hom; the resulting rational Tate-module injection automatically supplies its full required multiplicity. In particular dim⁡J≥2\dim J\ge2.

The controlled field, level, and factorization sought in the non-CM case are now established. We turn to the height of the modular Jacobian. Write g0=dim⁡Jg_0=\dim J. The modular group index bounds the degree of the map j:X1(N)→P1j:X_1(N)\to\mathbf P^1 by CN2CN^2. It is branched only over 0,1728,∞0,1728,\infty, so after rescaling the target it is a Belyi map. Riemann–Hurwitz, or the usual genus formula, also gives g0≤CN2g_0\le CN^2. Javanpeykar’s theorem [32], Theorem 1.1.1 and Section 2.3 for a smooth projective connected curve XX of genus g≥1g\ge1 bounds its Jacobian’s stable height in his convention by

13⋅106gdeg⁡B(X)5.13\cdot10^6 g\deg_B(X)^5.

Javanpeykar’s height here equals the original stable Faltings height of the Jacobian used in (4.5). The addition of (g/2)log⁡π(g/2)\log\pi in [32], Lemma 2.4.4 converts instead to the Deligne normalization hFDh_{\mathrm{F}}^{\mathrm{D}} of [24], Section 2.3. Thus no normalization correction is needed here; in either convention the difference is only O(g)O(g). Since Lemma 4.8 ensures g0≥2g_0 \ge2, the genus hypothesis applies. We obtain

g0≤CN2,max⁡{0,hF(J)}≤CN12.g_0 \le CN^2,\qquad\max\{0,h_{\mathrm{F}}(J)\} \le CN^{12}.

For the final comparison we choose a principally polarized complement. An abelian variety over a number field has a polarization defined over that field and is consequently isogenous there to its dual. When D0≠0D_0 \ne0, choose such a polarization over L′L'. Applying Zarhin’s trick to it gives a principal polarization over L′L' on

DZ=(D0×D0∨)4D_Z = (D_0 \times D_0^{\vee})^4

[74], Theorem 1.1(ii) and Remark 1.4; see also [4], proof of Corollary 3.2. If D0=0D_0 = 0, omit this factor and take all its height and dimension contributions below to be zero. In either case this choice of complement gives

C1=J8∼L′C2=A8×DZ.C_1 = J^8 \sim_{L'} C_2 = A^8 \times D_Z.

Both sides have dimension g=8g0g = 8g_0. Their common field has degree d=[L′:Q]≤CMd = [L' : \mathbb{Q}] \le CM, and the source has known stable height hF(C1)=8hF(J)h_{\mathrm{F}}(C_1) = 8h_{\mathrm{F}}(J). From (4.13) and (4.14),

g≤CM2a,max⁡{0,hF(C1)}≤CM12a.g \le CM^{2a},\qquad\max\{0,h_{\mathrm{F}}(C_1)\} \le CM^{12a}.

Applying (4.5) to this source gives an isogeny ϕ:C1→C2\phi: C_1 \to C_2 whose logarithmic degree is at most

log⁡deg⁡ϕ≤1024g3(64g2log⁡(14g)+log⁡d+2log⁡max⁡{hF(C1),log⁡d,1})≤CMC.\begin{aligned}\log\deg\phi &\le1024g^3\bigl(64g^2\log(14g)+\log d +2\log\max\{h_{\mathrm F}(C_1),\log d,1\}\bigr) \\ &\le C M^C.\end{aligned}

The last inequality follows by substituting the preceding bounds: every power of gg is a fixed power of MM, while the remaining logarithms are bounded by C(1+log⁡M)≤C′MC(1+\log M) \le C'M for M≥1M \ge1. This is the point at which the explicit dependence on dimension in the isogeny theorem is needed. The theorem is applied with source J8J^8, whose height is already bounded.

By additivity and (4.6),

8hF(A)+hF(DZ)≤hF(C1)+12log⁡deg⁡ϕ≤CMC.8h_{\mathrm{F}}(A) + h_{\mathrm{F}}(D_Z) \le h_{\mathrm{F}}(C_1) + \frac{1}{2}\log\deg\phi\le CM^C.

Bost’s lower bound applies to every abelian variety over a number field. For the complement DZD_Z chosen above, the form in [24], Corollary 8.4 gives

hFD(DZ)≥−12(dim⁡DZ)log⁡(2π).h_{\mathrm{F}}^{\mathrm{D}}(D_Z) \ge-\frac{1}{2}(\dim D_Z)\log(2\pi).

The normalization identity hFD=hF+12(dim⁡DZ)log⁡πh_{\mathrm{F}}^{\mathrm{D}} = h_{\mathrm{F}} + \frac{1}{2}(\dim D_Z)\log\pi therefore yields

hF(DZ)≥−12(dim⁡DZ)log⁡(2π2).h_{\mathrm{F}}(D_Z) \ge-\frac{1}{2}(\dim D_Z)\log(2\pi^2).

Since dim⁡DZ≤g≤CM2a\dim D_Z \le g \le CM^{2a}, it follows that

hF(A)≤CMC.h_{\mathrm{F}}(A) \le CM^C.

Neither a degree bound for the original μg\mu_g nor a bound for the degree of a field of coefficients has entered this estimate.

Completion of the proof of Theorem 2.4. For the arbitrary point ss fixed above, let A=AyA=\mathcal A_y be the chosen fiber. The CM case gave a uniform upper bound for hF(A)h_F(A); the other case gave (4.16). Applying Lemma 4.2 gives h(s)≤HMS(s)c{h}(s)\le H M_S(s)^c after enlarging fixed constants H,cH,c. All curves, levels, theta data, exceptional primes, and comparison constants were fixed independently of ss. This proves the theorem. Since MS(s)≥1M_S(s)\geq1, the exponent cc may, if desired, be increased to a positive integer.

Remark 4.9 (Related height bounds). Let UU be a nonempty open subscheme of Spec⁡OK\operatorname{Spec}\mathcal{O}_K for a number field KK. For fixed relative dimension and [K:Q][K:\mathbb{Q}], related work bounds stable Faltings height polynomially in the radical of the product of the absolute discriminant of KK and the norms of the prime ideals outside UU. Von Känel proves such a bound for abelian schemes over UU whose geometric generic fiber is simple, non-CM, and Q\mathbb{Q}-virtual of GL⁡2\operatorname{GL}_2-type, with conjugate isogenies compatible with all geometric endomorphisms [69] (Proposition 9.9). Von Känel and Kret treat the product-GL⁡2\operatorname{GL}_2-type class with GQG_{\mathbb{Q}}-isogenies and also abelian schemes with geometric CM [71] (Theorem 7.1).

The rank-one elliptic group and its local parameters

We prove Propositions 2.1 and 2.2, the two elliptic inputs used in Section 2.1. Recall the fixed data of (2.1):

F=Q(2),d=75−532,E: y2=x3−d2x,F={\mathbb{Q}}(\sqrt2),\qquad d=75-53\sqrt2,\qquad E:\ y^2=x^3-d^2x,

with σ\sigma the nontrivial automorphism of F/QF/\mathbb{Q}. The algebraic integer dd is positive at both real embeddings and has norm 77. In particular, d=(d)\mathfrak{d}=(d) is a prime ideal with residue field F7\mathbb{F}_7. In Section 6, we will choose split primes of good reduction for EE and its conjugate EσE^\sigma at which 77 is a nonsquare. The identity ddσ=7dd^\sigma=7 then makes their reductions quadratic twists with opposite Frobenius traces.

Proof of Proposition 2.1. The ring of integers is OF=Z[2]\mathcal{O}_F=\mathbb{Z}[\sqrt{2}]. Minkowski’s bound is 8/2=2<2\sqrt{8}/2=\sqrt{2}<2, so every ideal class contains an ideal of norm one. Thus OF\mathcal{O}_F is a principal ideal domain. The unit theorem gives ∣OF∗/OF∗2∣=4|\mathcal{O}_F^*/\mathcal{O}_F^{*2}|=4. The units −1-1 and 1+21+\sqrt{2} realize all four sign patterns at the real embeddings, so a totally positive unit is a square.

Consider the two-isogenous curve

E′: y2=x3+4d2x.E':\ y^2=x^3+4d^2x.

We use the usual two-isogeny descent, with isogenies φ:E→E′\varphi:E\to E' and φ^:E′→E\widehat{\varphi}:E'\to E whose composite is [2][2]; see [67], Chapter X, Proposition 4.7 and Example 4.9, pp. 336–337. Its homomorphisms

α:E(F)⟶F∗/F∗2,α′:E′(F)⟶F∗/F∗2\alpha:E(F)\longrightarrow F^*/F^{*2},\qquad\alpha':E'(F)\longrightarrow F^*/F^{*2}

send a point with nonzero xx to the class of xx, send the origin to 11, and send (0,0)(0,0) to the class of the linear coefficient in the equation. Their kernels are φ^E′(F)\widehat{\varphi}E'(F) and φE(F)\varphi E(F), respectively. In the present case

∣im⁡α∣ ∣im⁡α′∣=4 2rank⁡E(F).|\operatorname{im}\alpha|\,|\operatorname{im}\alpha'|=4\,2^{\operatorname{rank}E(F)}.

For completeness, EE has full rational two-torsion, and either point (±d,0)(\pm d,0) maps under φ\varphi to the nonidentity point of ker⁡φ^\ker\widehat{\varphi}. Hence the kernel of E′(F)/φE(F)→φ^E′(F)/2E(F)E'(F)/\varphi E(F)\to\widehat{\varphi}E'(F)/2E(F) is trivial. Taking indices in 2E(F)⊂φ^E′(F)⊂E(F)2E(F)\subset\widehat\varphi E'(F)\subset E(F) gives the left side of (5.1) as ∣E(F)/2E(F)∣|E(F)/2E(F)|, which is 2rank⁡E(F)+22^{\operatorname{rank}E(F)+2} by the Mordell–Weil Theorem.

If the linear coefficient of an equation y2=x3+cxy^2=x^3+cx is a unit at a finite place, then a nonzero xx has even valuation there. Indeed, when v(x)<0v(x)<0 the term x3x^3 has strictly smaller valuation than cxcx, while when v(x)>0v(x)>0 the term cxcx has strictly smaller valuation; an odd v(x)v(x) would give an odd valuation of y2y^2 in either case. Applied to EE, this shows that every class in im⁡α\operatorname{im}\alpha is supported, apart from its unit class, only at d\mathfrak d. The class number calculation therefore bounds the image by 4⋅2=84\cdot2=8. The torsion points already give the four distinct classes

1,−1,d,−d.1,-1,d,-d.

Let w=−5+42=d(1+2)3w=-5+4\sqrt{2}=d(1+\sqrt{2})^3. Direct calculation gives w3−w=−8dw^3-w=-8d, and consequently

Q=(−dw,22 d2)∈E(F).Q=(-dw,2\sqrt{2}\,d^2)\in E(F).

The element −dw-dw has opposite signs at the two real embeddings, whereas the four torsion classes have equal signs at both embeddings. Thus α(Q)\alpha(Q) is outside those four classes, proving ∣im⁡α∣=8|\operatorname{im}\alpha|=8.

We next prove im⁡α′={1}\operatorname{im}\alpha'=\{1\}. At both real embeddings, x3+4d2xx^3+4d^2x has the sign of xx, so every nonzero xx on E′E' is totally positive. The unit-coefficient argument excludes odd valuations away from the prime above 22 and d\mathfrak d. Normalize the valuation at the prime above 22 to have value group Z\mathbb{Z}. Then v(4d2)=4v(4d^2)=4. If v(x)v(x) were odd, the valuations 3v(x)3v(x) and 4+v(x)4+v(x) would be unequal and their minimum would be odd, again impossible for y2y^2. At d\mathfrak d the coefficient has valuation 22. An odd v(x)v(x) is impossible unless v(x)=1v(x)=1, by the same comparison. In that remaining case write x=dux=du with uu a local unit. The equation becomes

y2=d3u(u2+4).y^2=d^3u(u^2+4).

An even valuation would require u2+4≡0(modd)u^2+4\equiv0\pmod{\mathfrak d}. But −4=3-4=3 is not a square in F7\mathbb{F}_7. Thus all finite valuations of xx are even. Since OF\mathcal{O}_F is principal, xx is a square times a unit; total positivity makes that unit a square. The exceptional point (0,0)(0,0) also gives the trivial class 4d24d^2, and the origin does likewise. This proves the assertion about α′\alpha'. Equation (5.1) now gives rank⁡E(F)=1\operatorname{rank}E(F)=1.

Finally, choose mm divisible by the exponent of the finite torsion subgroup of E(F)E(F). The finitely generated group mE(F)mE(F) is torsion-free of rank one and therefore has a generator PP as claimed. □\square

Recall the parameter z=−x/yz=-x/y, with z(O)=0z(O)=0, and the formal logarithm and its degree-KK truncation

ℓ(Z)=Z+∑t≥2ctZt,ℓK(Z)=Z+∑2≤t≤KctZt.\ell(Z)=Z+\sum_{t\geq2}c_tZ^t,\qquad\ell_K(Z)=Z+\sum_{2\leq t\leq K}c_tZ^t.

Reading multiplication indices from elliptic coordinates has a precedent in Poonen’s rank-one Diophantine construction. His Lemma 9 reads divisibility of indices from denominators of elliptic multiples, and Lemma 11 uses the formal group to approximate an integer square by a quotient of coordinates [52]. Proposition 2.2 uses a truncated formal logarithm to approximate a quotient of indices. The paired local tests in the reduction use this comparison together with the conjugate curve.

The effective computation of the truncations in Section 2.1 can be made explicit. With w=−1/yw=-1/y one has

x=z/w,w=z3−d2zw2.x=z/w,\qquad w=z^3-d^2zw^2.

Successively solving this identity determines ww as a formal power series in zz; substitution in dx/(2y)dx/(2y) and termwise integration determines ℓ\ell. The formal group and its invariant differential have integral coefficients at every place of good integral reduction [67].

Proof of Proposition 2.2. Include 2, the primes of bad reduction of either equation, and the ramified primes of F/QF/\mathbb{Q} in SES_E. Let p∉SEp \notin S_E, let vv be a place above pp normalized by v(p)=1v(p)=1, and let n,n′∈Zn,n' \in\mathbb{Z}, with n′≠0n' \ne0 and both nP,n′PnP,n'P reducing to OO, as in the proposition. At this allowed place Fv/QpF_v/\mathbb{Q}_p is unramified, so its normalized value group is Z\mathbb{Z}. The kernel of reduction is the formal group on the maximal ideal. For a finite point on this integral good model, membership in that kernel is equivalent to v(x)<0v(x)<0; its parameter then has v(z)>0v(z)>0.

Write the invariant differential as (1+∑j≥1ajZj)dZ(1+\sum_{j\geq1}a_jZ^j)dZ, with aja_j integral at vv. Thus v(ct)≥−vp(t)v(c_t)\geq-v_p(t). If v(Z)≥1v(Z)\geq1, the term of degree t≥2t\geq2 in the logarithm has valuation at least tv(Z)−vp(t)>v(Z)tv(Z)-v_p(t)>v(Z) for p>2p>2, and these valuations tend to infinity. The logarithm consequently converges on the entire formal kernel, is a homomorphism there, and satisfies

v(ℓ(Z))=v(Z).v(\ell(Z))=v(Z).

These are also the standard formal-logarithm assertions of [67]; the displayed coefficient bound specifies the uniformity we require.

Set U=nPU=nP and V=n′PV=n'P. The identity [n′]U=[n]V[n']U=[n]V, entirely within the formal kernel, gives n′ℓ(z(U))=nℓ(z(V))n'\ell(z(U))=n\ell(z(V)). The point VV is nonzero, hence ℓ(z(V))≠0\ell(z(V))\ne0. Valuation preservation proves (2.6), including U=OU=O.

Now fix K≥1K\geq1 and suppose p>K+1p>K+1 and vp(n/n′)≥0v_p(n/n')\geq0. For every t>Kt>K,

t−1−vp(t)≥K.t-1-v_p(t)\geq K.

For t<pt<p this is immediate. For t≥pt\geq p, if j=vp(t)>0j=v_p(t)>0 then t−1−j≥pj−1−j≥p−2≥Kt-1-j\geq p^j-1-j\geq p-2\geq K; if j=0j=0 it is again immediate. Therefore, for v(Z)≥1v(Z)\geq1,

v(ℓ(Z)−ℓK(Z))≥v(Z)+K.v(\ell(Z)-\ell_K(Z))\geq v(Z)+K.

The inequality also holds at Z=0Z=0 with the stated convention. Put q=n/n′q=n/n'. The hypothesis vp(q)≥0v_p(q)\geq0 and (2.6) give v(z(U))≥v(z(V))v(z(U))\geq v(z(V)). The identity ℓ(z(U))=qℓ(z(V))\ell(z(U))=q\ell(z(V)) and (5.3) imply

v(ℓK(z(U))−qℓK(z(V)))≥v(z(V))+K.v\bigl(\ell_K(z(U))-q\ell_K(z(V))\bigr)\geq v(z(V))+K.

The same tail estimate gives v(ℓK(z(V)))=v(z(V))v(\ell_K(z(V)))=v(z(V)), in particular a nonzero denominator. Division proves (2.7). The proof applies verbatim to the conjugate equation and the polynomial ℓKσ\ell_K^\sigma.

The quantifiers in Proposition 2.2 are those used in Lemma 2.3: for each fixed KK, a single finite set of excluded rational primes works for all integer indices and all unramified places above the remaining primes. The transfer there concerns integer multiples of the fixed FF-rational points PP, PσP^\sigma and finite polynomial evaluations. No infinite series is evaluated in the elementary extension.

Prime patterns for the two conjugate local tests

This section proves Corollary 2.6, the ordinary coverage input used in the recursive theory. The raw prime-pattern result below supplies the reduction orders; its first consequence constructs the paired integer witnesses by the Chinese Remainder Theorem.

Retain the five points CC and the primitive integral forms LbL_b of Theorem 2.4, choosing L∞(U,V)=VL_\infty(U,V)=V. For integers A,u1,u2,vA,u_1,u_2,v with v≠0v\ne0, setting u3=Av−u1−u2u_3=Av-u_1-u_2 gives

A=u1v+u2v+u3v.A=\frac{u_1}{v}+\frac{u_2}{v}+\frac{u_3}{v}.

Evaluating the five contact forms on (ui,v)(u_i,v) gives the common value vv and four further values for each slope. We seek to express each of these thirteen entries as the product of a sign, a multiplier from one fixed finite set, and a positive prime at which the reduction orders of EE and EσE^\sigma permit simultaneous local tests.

Lemma 6.1 (Prime patterns). There is a finite set K⊂Z>0\mathcal K\subset{\mathbb{Z}}_{>0} such that, for every A∈ZA \in\mathbb{Z} and every real B>0B > 0, there exist integers u1,u2,vu_1,u_2,v, with v≠0v \ne0, for which, on setting u3=Av−u1−u2u_3 = Av-u_1-u_2, each of the thirteen numbers

v,Lb(uj,v)(1≤j≤3, b∈C∖{∞})v,\qquad L_b(u_j,v) \quad(1\le j\le3,\ b\in\mathcal C\setminus\{\infty\})

has the form ϵkr\epsilon kr, where ϵ∈{1,−1}\epsilon\in\{1,-1\}, k∈Kk\in\mathcal K, and r>Br > B is a positive rational prime. Every such prime splits in FF and is a prime of good reduction for both EE and EσE^\sigma. At either place of FF above rr, if d1,d2d_1,d_2 are the cardinalities of the reduction groups of E,EσE,E^\sigma over Fr\mathbb{F}_r, then

gcd⁡(d1,d2)∣4,r∤d1d2.\gcd(d_1,d_2) \mid4,\qquad r \nmid d_1d_2.

The set K\mathcal K is independent of AA and BB.

The listed values are nonzero, so the slopes (ui:v)(u_i:v) lie outside C\mathcal C. A prime counted by one of their contact radicals divides a listed contact value, because the corresponding normalized contact depth is positive and the coordinates are integral; unless it divides a member of K\mathcal K, it is therefore one of the selected primes rr.

Before proving the lemma, we record the consequence that explains its splitting and reduction-order conditions. Together with Proposition 2.2, they give two local tests at each place, with one pair of auxiliary integers at that place serving every integer aa.

Corollary 6.2 (Simultaneous integer tests). Fix an integer K≥1K \ge1 and a prime rr supplied by Lemma 6.1, large enough for Proposition 2.2 at precision KK. At each of the two places vv above rr there are nonzero integers h,j0h,j_0, chosen independently of a∈Za \in\mathbb{Z}, such that, for every a∈Za \in\mathbb{Z}:

  1. hPhP and haPhaP reduce to OO at vv, ℓK(z(hP))≠0\ell_K(z(hP)) \ne0, and

v(ℓK(z(haP))ℓK(z(hP))−a)≥K;v\left(\frac{\ell_K(z(haP))}{\ell_K(z(hP))}-a\right) \ge K;
  1. j0Pσj_0P^\sigma and (h−4)aPσ(h-4)aP^\sigma reduce to OO at the same place vv, and

v(z((h−4)aPσ)z(j0Pσ))≥K.v\left(\frac{z((h-4)aP^\sigma)}{z(j_0P^\sigma)}\right) \ge K.

The choices of h,j0h,j_0 may differ at the two places.

Proof. Let d1,d2d_1,d_2 be the two reduction orders at the chosen place. Choose j0=d2j_0=d_2. Since r∤d1r \nmid d_1 and gcd⁡(d1,d2)∣4\gcd(d_1,d_2) \mid4, the pair of integer congruences

h≡0(modd1),h≡4(modd2rK)h \equiv0 \pmod{d_1},\qquad h \equiv4 \pmod{d_2r^K}

is consistent. Choose a positive solution hh. Reduction orders show that all four indicated points are in the respective formal kernels, uniformly for a∈Za \in\mathbb{Z}. The logarithm congruence follows from Proposition 2.2 with indices ha,hha,h, whose ratio is aa. For the conjugate ratio use (2.6) on the conjugate curve:

v(z((h−4)aPσ)z(j0Pσ))=vr((h−4)ad2)≥K.v\left(\frac{z((h-4)aP^\sigma)}{z(j_0P^\sigma)}\right) = v_r\left(\frac{(h-4)a}{d_2}\right) \ge K.

The nonzero denominator follows because j0Pσj_0P^\sigma is nontorsion. Zero numerator indices are covered by the infinite-valuation convention. Finally, at these split unramified primes the valuation ring on FF is the localization of OF=Z[2]\mathcal{O}_F = \mathbb{Z}[\sqrt{2}] at the chosen prime ideal, and rr is a uniformizer. Thus every displayed inequality is exactly membership in rK(OF)pr^K(\mathcal{O}_F)_{\mathfrak{p}}. For a finite formal point, the condition v(x)<0v(x) < 0 equivalently places 1/x1/x in r(OF)pr(\mathcal{O}_F)_{\mathfrak{p}}, as used in the ring-language tests of Section 2.3.

Proof of Corollary 2.6. Fix K≥1K \ge1, A∈ZA \in\mathbb{Z}, and Y0>0Y_0 > 0. Choose a real threshold larger than Y0Y_0, K+1K+1, and every prime in the fixed finite set SES_E. Lemma 6.1 gives the thirteen contact values with primes above this threshold, using its one finite set K\mathcal{K}. These primes split in FF and are good for both curves. At each of the two places above each occurrence, Corollary 6.2 gives nonzero h,j0h,j_0, fixed for every integer aa, with its two formal-kernel conditions and valuation comparisons. In the identity embedding with Ta=aPT_a = aP, these are exactly conditions (i) and (ii) of Lemma 2.3. The final localization calculation in the proof of Corollary 6.2 gives the stated membership and finite-point interpretations. The choices are made separately at the different occurrences and places, as allowed. The fixed set K\mathcal{K} is independent of K,A,Y0K,A,Y_0 because the prime-pattern lemma makes it independent of AA and of the threshold.

We now prove Lemma 6.1. Constants with a subscript AA may depend on AA, a subsequently fixed real box, and the fixed contact forms, but not on the small-prime cutoff LL. The order of choices is: the finite multiplier set; then AA, a box and one initial congruence class; then LL; and finally a large dilation parameter XX.

Reduction orders and their possible common factors

Restrict attention to primes

r≡1(mod8),r≡3(mod7).r \equiv1 \pmod{8}, \qquad r \equiv3 \pmod{7}.

Quadratic reciprocity gives (2/r)=1(2/r) = 1, so rr splits in FF, and (7/r)=(r/7)=−1(7/r) = (r/7) = -1. At either chosen place above rr, the two nonzero reductions of dd and dσd^\sigma have product 77. They therefore represent opposite square classes in Fr∗{\mathbb{F}}_r^*. The curves EE and EσE^\sigma are the quadratic twists by these classes of E0:y2=x3−xE_0 : y^2 = x^3 - x, so their traces of Frobenius are opposite.

Here is the specific description of that trace which we need. Since r≡1(mod4)r \equiv1 \pmod{4}, the automorphism (x,y)↦(−x,iy)(x,y) \mapsto(-x,iy) of E0E_0 is defined over Fr\mathbb{F}_r and has square [−1][-1]. Its centralizer in the rational geometric endomorphism algebra is Q(i)\mathbb{Q}(i). Indeed, the faithful action of endomorphisms on an auxiliary two-dimensional rational Tate module bounds this centralizer by dimension two, while it already contains Q(i)\mathbb{Q}(i). More explicitly one may use the 3-adic Tate module for r>3r > 3, on which the minimal polynomial T2+1T^2 + 1 is irreducible and its matrix centralizer has dimension two. The faithful action remains injective after extending coefficients [67], Theorem III.7.4].

Frobenius commutes with this automorphism. Its characteristic polynomial is integral, and its determinant is rr; these are the usual degree and trace identities for elliptic endomorphisms [67], Proposition III.8.6 and Chapter V, §2]. It is thus an algebraic integer in Q(i)\mathbb{Q}(i), hence equals a+bia+bi for a,b∈Za,b \in\mathbb{Z}, with

a2+b2=r,a≠0.a^2 + b^2 = r, \qquad a \ne0.

The last condition follows because a rational prime is not a square. Consequently, in either order,

d1,d2=r+1±2a.d_1,d_2 = r+1 \pm2a.

Both orders are divisible by four, since both curves have full rational two-torsion over Fr\mathbb{F}_r. Their sum is 2(r+1)2(r+1), whose 2-adic valuation is exactly two by (6.3). Thus the 2-part of their greatest common divisor is exactly four. For sufficiently large rr, the Hasse bound gives 0<di<2r0<d_i<2r. Since 4∣di4\mid d_i and rr is odd, di≠rd_i\ne r, proving r∤dir\nmid d_i.

If an odd prime ll divides both orders, their sum and difference show that l∣r+1l\mid r+1 and l∣al\mid a. Equation (6.4) then gives

a≡0(modl),b2≡−1(modl).a \equiv0 \pmod{l}, \qquad b^2 \equiv-1 \pmod{l}.

In particular such an ll is 1 modulo 4. We shall first exclude small ll by congruences on r+1r+1, then use an upper sieve to remove the remaining primes rr satisfying these two local conditions.

A finite multiplier set and the initial residue conditions

Write Lb(U,V)=αbU+γbVL_b(U,V)=\alpha_b U+\gamma_b V for b≠∞b\ne\infty. Here αb≠0\alpha_b\ne0, gcd⁡(αb,γb)=1\gcd(\alpha_b,\gamma_b)=1, and αbγc−αcγb≠0\alpha_b\gamma_c-\alpha_c\gamma_b\ne0 for b≠cb\ne c. For an integer AA, put T=(u1,u2,v)T=(u_1,u_2,v) and denote the thirteen homogeneous forms in (6.1) by Fν(T)F_\nu(T), 1≤ν≤t=131\le\nu\le t=13. Their coefficient vectors, other than (0,0,1)(0,0,1), are

(αb,0,γb),(0,αb,γb),(−αb,−αb,αbA+γb).(\alpha_b,0,\gamma_b), \qquad(0,\alpha_b,\gamma_b), \qquad(-\alpha_b,-\alpha_b,\alpha_b A+\gamma_b).

Every vector is primitive, including the last one because gcd⁡(αb,αbA+γb)=1\gcd(\alpha_b,\alpha_bA+\gamma_b)=1. There is a fixed threshold p0p_0, independent of AA, above which any two vectors are linearly independent over Fp\mathbb{F}_p. Within one of the three families this follows from the fixed nonzero determinants of the LbL_b; between different families it follows from the three distinct directions (1,0),(0,1),(−1,−1)(1,0),(0,1),(-1,-1) in the first two coordinates. The form vv is independent of each remaining form whenever p∤αbp\nmid\alpha_b.

Choose once and for all a finite set S0S_0 consisting of all primes up to a sufficiently large threshold, including 2, 7, the exceptions just described, and all fixed bad primes needed for the elliptic curves. Increase the threshold so that p>2tp>2t and the later local-density estimates hold for every p∉S0p\notin S_0. Choose a fixed integer H0H_0 with t2−H0<1t2^{-H_0}<1. For any AA and any p∈S0p\in S_0, each primitive FνF_\nu maps (Z/pH0Z)3(\mathbb{Z}/p^{H_0}\mathbb{Z})^3 onto Z/pH0Z\mathbb{Z}/p^{H_0}\mathbb{Z}. The proportion of vectors for which pH0∣Fν(T)p^{H_0}\mid F_\nu(T) is therefore p−H0p^{-H_0}. Since tp−H0<1tp^{-H_0}<1, there is a vector class modulo pH0p^{H_0} on which none of the FνF_\nu is divisible by pH0p^{H_0}. Every lift of this class modulo pH0+3p^{H_0+3} has

vp(Fν(T))<H0(1≤ν≤t).v_p(F_\nu(T))<H_0 \qquad(1\le\nu\le t).

This proves the existence of the small-prime classes that we will select for a particular AA.

We next choose a finite catalogue of multipliers, without selecting AA or any of those classes. Put m2=8m_2=8 and mp=pm_p=p for odd p∈S0p\in S_0. Define units c2=1(mod8)c_2=1\pmod8, c7=3(mod7)c_7=3\pmod7, and cp=1(modp)c_p=1\pmod p for the remaining p∈S0p\in S_0. These are the desired residues of the positive primes in Lemma 6.1. A catalogue datum consists of integers and unit residues

epν∈{0,…,H0−1},ξpν∈(Z/mpZ)∗(p∈S0, 1≤ν≤t).e_{p\nu}\in\{0,\ldots,H_0-1\}, \qquad\xi_{p\nu}\in(\mathbb{Z}/m_p\mathbb{Z})^* \qquad(p\in S_0,\ 1\le\nu\le t).

For such a datum set k0ν=∏p∈S0pepνk_{0\nu}=\prod_{p\in S_0}p^{e_{p\nu}}. The Chinese Remainder Theorem and Dirichlet’s Theorem [12] allow us to choose distinct primes h1,…,ht∉S0h_1,\ldots,h_t\notin S_0, hence above the fixed threshold, with

hν≡cp−1ξpν(modmp)(p∈S0).h_\nu\equiv c_p^{-1}\xi_{p\nu}\pmod{m_p}\qquad(p\in S_0).

When the datum later comes from a chosen vector class, ξpν\xi_{p\nu} will be the signed unit remaining after the factors from S0S_0 have been removed. The congruence gives ξpνhν−1≡cp(modmp)\xi_{p\nu}h_\nu^{-1}\equiv c_p\pmod{m_p}, so division by the additional factor hνh_\nu gives the desired residue. There are only finitely many catalogue data. Fix one such tuple of primes for each datum and let K\mathcal{K} be the union of the resulting integers k0νhνk_{0\nu}h_\nu. Thus K\mathcal{K} is finite and is fixed before AA, the cutoff LL, and the dilation XX.

Now fix the integer AA for which the lemma is to be proved. Choose a bounded open rectangular box B\mathcal{B} of positive volume whose closure avoids the zero planes of all FνF_\nu, and let ϵν∈{1,−1}\epsilon_\nu\in\{1,-1\} be the sign of FνF_\nu on this box. For each p∈S0p \in S_0, choose one of the vector classes modulo pH0+3p^{H_0+3} supplied above and put epν=vp(Fν(T))e_{p\nu}=v_p(F_\nu(T)) on that class. These values do not depend on its representative. They define k0νk_{0\nu} as above. The class also determines the unit

ξpν=ϵνFν(T)pepν(k0νpepν)−1(modmp).\xi_{p\nu}=\epsilon_\nu\frac{F_\nu(T)}{p^{e_{p\nu}}}\left(\frac{k_{0\nu}}{p^{e_{p\nu}}}\right)^{-1}\pmod{m_p}.

Here the second factor is a unit modulo mpm_p, and the first quotient is known modulo pH0+3−epνp^{H_0+3-e_{p\nu}}, a modulus containing at least four powers of pp. In particular it determines the required residue even when p=2p=2 and mp=8m_p=8. Select the tuple hνh_\nu already fixed for this datum, and put kν=k0νhνk_\nu=k_{0\nu}h_\nu.

At p=hνp=h_\nu, impose Fν(T)=0(modp)F_\nu(T)=0\pmod p. On this plane, each other FjF_j is nonconstant. Each condition ϵjFj(T)=0\epsilon_jF_j(T)=0 or −kj-k_j removes at most one line, and at most 2(t−1)p<p22(t-1)p<p^2 points are removed. There is therefore a point satisfying

ϵjFj(T)≠0,−kj(modhν)(j≠ν).\epsilon_jF_j(T)\ne0,-k_j\pmod{h_\nu}\qquad(j\ne\nu).

Lift that point modulo p2p^2 so that

ϵνFν(T)/p≠0,−k0ν(modp).\epsilon_\nu F_\nu(T)/p\ne0,-k_{0\nu}\pmod p.

Such a lift exists because FνF_\nu is primitive, so varying the lift changes Fν(T)/pF_\nu(T)/p through all residues modulo pp. The Chinese Remainder Theorem combines these choices with the chosen classes at S0S_0 into one vector class modulo

W0=∏p∈S0pH0+3∏ν=1thν2.W_0=\prod_{p\in S_0}p^{H_0+3}\prod_{\nu=1}^{t}h_\nu^2.

On this class all

Ψν(T)=ϵνFν(T)/kν\Psi_\nu(T)=\epsilon_\nu F_\nu(T)/k_\nu

are integers and are nonzero modulo every prime dividing W0W_0. At a prime in S0S_0, the definition of ξpν\xi_{p\nu} and (6.7) give Ψν≡cp(modmp)\Psi_\nu\equiv c_p\pmod{m_p}. The conditions at each hjh_j give the remaining exclusions. Thus the divided forms equal 1 modulo 8 and 3 modulo 7, and avoid −1-1 modulo every odd prime dividing W0W_0. Notice also that W0/kνW_0/k_\nu is divisible by every prime dividing W0W_0. This extra divisibility will control the local factors of the prime-counting theorem.

Fix a smaller rectangular box B′\mathcal{B}' of positive volume with B′‾⊂B\overline{\mathcal{B}'}\subset\mathcal{B}. Since the signs agree with the forms on B\mathcal{B} and its closure avoids their zero planes, there are constants 0<cA<CA0<c_A<C_A such that

cAX≤Ψν(T)≤CAX(T∈XB, 1≤ν≤t).c_AX\leq\Psi_\nu(T)\leq C_AX\qquad(T\in X\mathcal{B},\ 1\leq\nu\leq t).

All choices for this AA, including W0W_0, are now fixed before choosing LL. The catalogue was finite, so W0W_0 ranges in a fixed finite set as AA varies.

A lower bound for the prime patterns

Let LL be a fixed cutoff larger than every prime dividing W0W_0, and put

W=W0∏p≤Lp∤W0p.W=W_0\prod_{\substack{p\le L\\p\nmid W_0}}p.

At each new prime p≤Lp\le L allow all residue classes of TT satisfying

ϵνFν(T)≠0,−kν(modp)(1≤ν≤t).\epsilon_\nu F_\nu(T)\ne0,-k_\nu\pmod p\quad(1\le\nu\le t).

At most 2t2t affine planes, each of p2p^2 points, are excluded. Thus if RW\mathcal{R}_W is the set of all allowed vector classes modulo WW, including the one fixed class modulo W0W_0, then

∣RW∣W3≥W0−3∏p≤Lp∤W0(1−2t/p)≥c0(log⁡L)−C0.\frac{|\mathcal R_W|}{W^3} \ge W_0^{-3}\prod_{\substack{p\le L\\p\nmid W_0}}(1-2t/p) \ge c_0(\log L)^{-C_0}.

The last bound follows by taking logarithms and using Mertens’ estimate ∑p≤Lp−1=log⁡log⁡L+O(1)\sum_{p\le L}p^{-1}=\log\log L+O(1) [73], equation (1.1) and Theorem 1. The constants can be fixed independently of LL; since W0W_0 ranges in a fixed finite set they could also be made independent of AA. Whenever Ψν(T)=r\Psi_\nu(T)=r is prime, these conditions and the initial conditions imply that no odd l≤Ll\le L divides r+1r+1. Such an ll cannot divide both orders in (6.5).

Let NA,L(X)N_{A,L}(X) be the number of T∈XB∩Z3T\in X\mathcal B\cap{\mathbb{Z}}^3 for which every Ψν(T)\Psi_\nu(T) is prime and all imposed congruences hold. We claim that

NA,L(X)≥cA(log⁡L)−C0X3(log⁡X)tN_{A,L}(X)\ge c_A(\log L)^{-C_0}\frac{X^3}{(\log X)^t}

for sufficiently large XX depending on A,LA,L, with cA>0c_A>0 independent of LL.

We use the following precise form of the Green–Tao–Ziegler theorem. For a fixed finite collection of integer affine-linear forms ψ1,…,ψt\psi_1,\ldots,\psi_t on Zd\mathbb{Z}^d whose nonzero linear parts are pairwise nonproportional, and a fixed dilating box where all values are positive, the von Mangoldt weighted count is

∑n∈DX∩Zd∏ν=1tΛ(ψν(n))=vol⁡(DX)∏pβp+o(Xd),\sum_{n\in\mathcal D_X\cap{\mathbb{Z}}^d}\prod_{\nu=1}^t\Lambda(\psi_\nu(n)) =\operatorname{vol}(\mathcal D_X)\prod_p\beta_p+o(X^d),

where

βp=(1−1/p)−tp−d#{n∈Fpd:ψν(n)≠0 for every ν}.\beta_p=(1-1/p)^{-t}p^{-d}\#\{n\in\mathbb{F}_p^d:\psi_\nu(n)\ne0\text{ for every }\nu\}.

Here all coefficients and the box are fixed before X→∞X\to\infty. This is the finite-complexity case of the Main Theorem of [28], combined with the Möbius–nilsequence theorem [25], Theorem 1.1 and the inverse theorem [26], Theorem 1.3, with its correction [27]. Pairwise nonproportional linear parts give finite complexity: for any chosen form, the other forms can be partitioned into singletons, none spanning it. The 2024 erratum corrects intermediate factorization and filtration statements and leaves the stated inverse theorem, and hence (6.13), unchanged.

For each T0∈RWT_0\in\mathcal{R}_W, use its representative in [0,W)3[0,W)^3 and write T=T0+WnT=T_0+Wn. The forms

ψν,T0(n)=ϵνFν(T0+Wn)/kν\psi_{\nu,T_0}(n)=\epsilon_\nu F_\nu(T_0+Wn)/k_\nu

have integer coefficients and pairwise nonproportional linear parts. Use n∈(X/W)B′n\in(X/W)\mathcal B'. For all sufficiently large XX, depending on A,LA,L, this entails T∈XBT\in X\mathcal B, uniformly over the finite set of representatives T0T_0. The volume in (6.13) is then vol⁡(B′)X3/W3\operatorname{vol}(\mathcal B')X^3/W^3.

At p∣Wp \mid W, the coefficients of the variable parts of every divided form vanish modulo pp, whereas their constant values are nonzero. Consequently βp=(1−1/p)−t≥1\beta_p=(1-1/p)^{-t}\ge1. At p∤Wp\nmid W, multiplication by WW and by kν−1k_\nu^{-1} is invertible. The zero sets of the forms are distinct affine hyperplanes, and each pair has an intersection of codimension two. Inclusion–exclusion, using only the first two terms for a uniform error, gives

p−3#{n:ψν,T0(n)≠0 (∀ν)}=1−t/p+Ot(p−2).p^{-3}\#\{n:\psi_{\nu,T_0}(n)\ne0\ (\forall\nu)\}=1-t/p+O_t(p^{-2}).

Thus βp=1+Ot(p−2)\beta_p=1+O_t(p^{-2}). Taking the original fixed threshold large enough, the product over any subset of these primes is bounded below by one fixed positive convergent product. This lower bound is independent of LL and T0T_0.

Prime powers in (6.13) are negligible. On a box of scale XX, there are O(X1/2log⁡X)O(X^{1/2}\log X) proper prime powers in the range of each nonconstant form, and at most OA,L(X2)O_{A,L}(X^2) lattice points for each prescribed value of that form, by solving for one coordinate. Their total weighted contribution is therefore OA,L(X5/2(log⁡X)t+1)=oA,L(X3)O_{A,L}(X^{5/2}(\log X)^{t+1})=o_{A,L}(X^3). For genuine prime values the weight is at most CA(log⁡X)tC_A(\log X)^t, by (6.9).

Sum (6.13) over the finitely many allowed progressions. For each fixed LL their errors still sum to oA,L(X3)o_{A,L}(X^3), while the W−3W^{-3} volume factor cancels the W3W^3 in the number of progressions in (6.11). The lower bound for the local-factor product, the removal of prime powers, and the bound on the prime weights therefore give (6.12), with a positive coefficient independent of LL. We require no uniformity in the little-oh error as AA or LL varies.

We must now remove the patterns for which some pair of reduction orders has an odd common factor l>Ll>L. For one form, we will bound the number of possible bad prime values by OA(X/(Llog⁡X))O_A(X/(L\log X)) plus terms of smaller order as X→∞X\to\infty for fixed LL. For each fixed bad value, a second count will bound the points on its affine fiber for which the other t−1t-1 forms remain prime by OA(X2/(log⁡X)t−1)O_A(X^2/(\log X)^{t-1}). The contribution from the term X/(Llog⁡X)X/(L\log X) is therefore OA(X3/(L(log⁡X)t))O_A(X^3/(L(\log X)^t)). This retains the factor (log⁡X)−t(\log X)^{-t} in (6.12) and introduces the saving 1/L1/L. The first count sieves the pairs (a,b)(a,b) in (6.4); the second sieves the two free coordinates on a fiber. Both use the following two-dimensional estimate.

An elementary upper sieve with uniform errors

Let PZ\mathcal{P}_Z be a set of primes at most ZZ, with forbidden subsets Ωp⊂Fp2\Omega_p\subset\mathbb{F}_p^2 having densities g(p)=∣Ωp∣/p2g(p)=|\Omega_p|/p^2 in (0,1/2)(0,1/2). Extend gg multiplicatively to squarefree integers supported on PZ\mathcal{P}_Z. Let x\mathbf x range over a square in Z2\mathbb{Z}^2 with nn integer choices in each coordinate. The simultaneous forbidden conditions at the primes dividing a squarefree integer ee hold at

n2g(e)+O(ne+e2)n^2g(e)+O(ne+e^2)

points, uniformly in the location of the square. Indeed the Chinese Remainder Theorem gives e2g(e)e^2g(e) residue classes, and the count in each differs from n2/e2n^2/e^2 by O(n/e+1)O(n/e+1).

The following estimate uses Selberg’s λ2\lambda^2 method [63]; compare [44], Section 3.2. We give the weights and error term needed for these two-dimensional boxes.

Lemma 6.3. The number of points in this square avoiding every Ωp\Omega_p is at most

n2G(Z)+O(nZ6+Z8),G(Z)=∑e≤Z squarefreep∣e⇒p∈PZ∏p∣eg(p)1−g(p).\frac{n^2}{G(Z)}+O(nZ^6+Z^8),\qquad G(Z)=\sum_{\substack{e\le Z\text{ squarefree}\\p\mid e\Rightarrow p\in\mathcal P_Z}} \prod_{p\mid e}\frac{g(p)}{1-g(p)}.

The error constant is absolute.

Proof. All integers in the sums that follow are squarefree and supported on PZ\mathcal{P}_Z. Put g∗(p)=(1−g(p))/g(p)g_*(p)=(1-g(p))/g(p) and extend it multiplicatively, with g(1)=g∗(1)=1g(1)=g_*(1)=1. For real weights λe\lambda_e supported on e≤Ze\le Z with λ1=1\lambda_1=1, the square

(∑e≤Zxmodp∈Ωp (p∣e)λe)2\left(\sum_{\substack{e\le Z\\ \mathbf x\bmod p\in\Omega_p\ (p\mid e)}}\lambda_e\right)^2

majorizes the indicator of avoiding all forbidden sets: at such a point only e=1e=1 contributes. Upon summing and applying (6.14), its main term divided by n2n^2 is ∑e,fλeλfg([e,f])\sum_{e,f}\lambda_e\lambda_f g([e,f]). The identity 1/g(d)=∑h∣dg∗(h)1/g(d)=\sum_{h\mid d}g_*(h) gives the diagonalization

∑e,fλeλfg([e,f])=∑hg∗(h)(∑e≤Zh∣eλeg(e))2.\sum_{e,f}\lambda_e\lambda_fg([e,f]) =\sum_hg_*(h) \left(\sum_{\substack{e\le Z\\h\mid e}}\lambda_eg(e)\right)^2.

Prescribe the inner sums to equal μ(h)/(G(Z)g∗(h))\mu(h)/(G(Z)g_*(h)). Finite Möbius inversion gives

λe=μ(e)G(Z)g(e)g∗(e)∑k≤Z/e(k,e)=1μ(k)2g∗(k).\lambda_e=\frac{\mu(e)}{G(Z)g(e)g_*(e)} \sum_{\substack{k\le Z/e\\ (k,e)=1}}\frac{\mu(k)^2}{g_*(k)}.

In particular λ1=1\lambda_1=1 and

∣λe∣≤1g(e)g∗(e)=∏p∣e(1−g(p))−1≤2ω(e)≤e.|\lambda_e|\le\frac{1}{g(e)g_*(e)}=\prod_{p\mid e}(1-g(p))^{-1}\le2^{\omega(e)}\le e.

Substitution in (6.16) gives 1/G(Z)1/G(Z). For the error at [e,f][e,f], use [e,f]≤ef[e,f]\le ef and ∣λeλf∣≤ef|\lambda_e\lambda_f|\le ef. Its sum is bounded by

O(n∑e,f≤Ze2f2+∑e,f≤Ze3f3)=O(nZ6+Z8),O\left(n\sum_{e,f\le Z}e^2f^2+\sum_{e,f\le Z}e^3f^3\right)=O(nZ^6+Z^8),

as required.

We shall always set Z=X1/100Z=X^{1/100}. Two consequences for G(Z)G(Z) will be useful. If PZ\mathcal{P}_Z contains all primes above a fixed threshold up to ZZ, and g(p)=s/p+Os(p−2)g(p)=s/p+O_s(p^{-2}) for a fixed positive integer ss, then

G(Z)≫(log⁡X)s.G(Z)\gg(\log X)^s.

If instead it contains the primes p≡1(mod4)p\equiv1\pmod4 above a fixed threshold up to ZZ, with at most one additional prime omitted, and g(p)=2/p+O(p−2)g(p)=2/p+O(p^{-2}), then

G(Z)≫log⁡X,G(Z)\gg\log X,

uniformly in that omitted prime. In these two estimates the implicit constants may depend on the fixed threshold and the fixed density estimates, as well as on ss, but not on XX or the omitted prime.

Here are details of the truncation behind both claims. For y=Zθy=Z^\theta, where θ>0\theta>0 will be fixed sufficiently small, the Euler product

D(y)=∏p≤yp∈PZ(1+g∗(p)−1)D(y)=\prod_{\substack{p\le y\\p\in\mathcal{P}_Z}}\left(1+g_*(p)^{-1}\right)

is respectively ≫(log⁡y)s\gg(\log y)^s or ≫log⁡y\gg\log y, by the ordinary and progression Mertens estimates [73], equation (1.1) and Theorem 1. In the latter case removing one prime loses at most a factor two because g(p)<1/2g(p)<1/2. In the expansion of D(y)D(y) give a squarefree ee weight 1/g∗(e)1/g_*(e). The weighted mean of log⁡e\log e equals

∑p≤yp∈PZg(p)log⁡p≪log⁡y.\sum_{\substack{p\le y\\p\in\mathcal{P}_Z}} g(p)\log p\ll\log y.

This uses ∑p≤y(log⁡p)/p≪log⁡y\sum_{p\le y}(\log p)/p\ll\log y, and the bound is uniform when a prime is omitted. For a small enough fixed θ\theta, Markov’s inequality shows that at least half the weight has e≤Ze\le Z. Those terms occur in G(Z)G(Z), proving both assertions.

Counting bad prime values

Fix one index ν\nu. All its possible prime values lie in the interval (6.9). Let BA,L(X)B_{A,L}(X) be the number of primes in that interval satisfying (6.3) for which the two orders have a common odd factor l>Ll>L. We claim

BA,L(X)≪AXLlog⁡X+X7/8+Xlog⁡X.B_{A,L}(X)\ll_A \frac{X}{L\log X}+X^{7/8}+\sqrt{X}\log X.

It suffices to count pairs (a,b)∈Z2(a,b)\in\mathbb{Z}^2 with ∣a∣,∣b∣≤CAX|a|,|b|\le C_A\sqrt{X}, a≠0a\ne0, for which a2+b2a^2+b^2 is a prime in the interval and (6.6) holds for some prime l>Ll>L. Every bad prime supplies such a pair. Overcounting pairs, and counting a pair several times if necessary, gives an upper bound.

First consider L<l≤X1/8L<l\le X^{1/8}. If −1-1 has no square root modulo ll, there are no pairs. Otherwise take each of its two roots b0b_0 and write

a=lU,b=b0+lV.a=lU,\qquad b=b_0+lV.

The relevant U,VU,V lie in an encompassing square with

n≍AX/l≫AX3/8n\asymp_A \sqrt{X}/l\gg_A X^{3/8}

integer choices in each coordinate, uniformly for these ll and for least nonnegative representatives b0b_0. Sieve by all sufficiently large primes p≡1(mod4)p\equiv1\pmod4, p≠lp\ne l, up to Z=X1/100Z=X^{1/100}. Modulo pp the substitution (U,V)↦(lU,b0+lV)(U,V)\mapsto(lU,b_0+lV) is an affine bijection, so the forbidden equation a2+b2=0a^2+b^2=0 has exactly 2p−12p-1 solutions: it is the union of two distinct lines meeting at one point. Thus

g(p)=2/p−1/p2,g(p)=2/p-1/p^2,

independently of l,b0l,b_0. Since the prime value a2+b2a^2+b^2 is ≍AX>Z\asymp_A X>Z, it avoids all these forbidden sets. Lemma 6.3 and (6.19) give O(n2/log⁡X+nZ6+Z8)O(n^2/\log X+nZ^6+Z^8) pairs. At the shortest possible squares,

nZ6+Z8n2/log⁡X≪A(log⁡X)(X6/100−3/8+X8/100−3/4)=oA(1).\frac{nZ^6+Z^8}{n^2/\log X}\ll_A(\log X)\left(X^{6/100-3/8}+X^{8/100-3/4}\right)=o_A(1).

The error is therefore absorbed uniformly before summing over ll. Each ll contributes OA(X/(l2log⁡X))O_A(X/(l^2\log X)), and summing over even all integers l>Ll>L gives OA(X/(Llog⁡X))O_A(X/(L\log X)).

For l>X1/8l>X^{1/8} use a lattice count without a sieve. Since a≠0a\ne0 and l∣al\mid a, necessarily l≤CAXl\le C_A\sqrt{X}, and the number of possible aa is OA(X/l)O_A(\sqrt{X}/l), with no additive constant. There are at most two classes for bb, giving OA(X/l+1)O_A(\sqrt{X}/l+1) possibilities. The count for one ll is thus

OA(X/l2+X/l).O_A(X/l^2+\sqrt{X}/l).

To sum it explicitly, split X1/8<l≤CAXX^{1/8}<l\le C_A\sqrt{X} into dyadic blocks D<l≤2DD<l\le2D. Even if every integer in a block were allowed, its contribution would be OA(X/D+X)O_A(X/D+\sqrt{X}). The first terms form a geometric sum OA(X7/8)O_A(X^{7/8}), while there are OA(log⁡X)O_A(\log X) blocks. Their total is OA(X7/8+Xlog⁡X)O_A(X^{7/8}+\sqrt{X}\log X). This proves (6.20) with constants independent of LL.

A uniform sieve on each affine fiber

For a fixed prime value r≍AXr\asymp_A X of the ν\nuth form, consider

Fν(T)=ϵνkνr.F_\nu(T)=\epsilon_\nu k_\nu r.

We claim that the number of T∈XB∩Z3T\in X\mathcal B\cap{\mathbb{Z}}^3 on this fiber for which all other Ψj(T)\Psi_j(T) are primes is

≪AX2(log⁡X)t−1,\ll_A \frac{X^2}{(\log X)^{t-1}},

uniformly in rr and independently of LL. In this upper bound we discard all the congruence conditions used for the lower bound.

Since FνF_\nu is primitive, an integral unimodular coordinate change makes it the first coordinate. The other two coordinates of every point of the fiber inside XBX\mathcal B lie in an encompassing square with n≍AXn\asymp_A X integer choices in each direction. The coordinate change depends on A,νA,\nu but not on r,Lr,L. Sieve by all primes up to Z=X1/100Z=X^{1/100} above a fixed sufficiently large threshold, excluding every prime dividing any multiplier. For all sufficiently large XX, every sieving prime differs from rr, so the fiber constant c=ϵνkνrc=\epsilon_\nu k_\nu r is nonzero modulo each such prime pp.

On the affine plane Fν=cF_\nu=c over Fp\mathbb{F}_p, every other FjF_j restricts to a nonconstant affine function, because FjF_j is not proportional to FνF_\nu. Furthermore the t−1t-1 zero lines of these restrictions are distinct. If two coincided, their affine functions would be scalar multiples on that plane. For some λ∈Fp∗\lambda\in\mathbb{F}_p^* and μ∈Fp\mu\in\mathbb{F}_p this would give the identity

Fj−λFk=μ(Fν−c).F_j-\lambda F_k=\mu(F_\nu-c).

The left side is homogeneous, so comparison of constant terms gives μc=0\mu c=0. Since c≠0c\ne0, one has μ=0\mu=0, contradicting the pairwise independence of Fj,FkF_j,F_k. This argument also covers the case that three ambient forms are jointly dependent: a nonzero constant shift then gives distinct parallel lines, rather than coincident ones.

The union of the t−1t-1 distinct zero lines has (t−1)p+Ot(1)(t-1)p+O_t(1) points. All must be avoided, since the other prime values have size ≍AX\asymp_A X and exceed the sieving primes; the multiplier is invertible modulo every sieving prime. Thus g(p)=(t−1)/p+Ot(p−2)g(p)=(t-1)/p+O_t(p^{-2}), uniformly in the fiber. Lemma 6.3 and (6.18) give

OA(X2(log⁡X)t−1+XZ6+Z8)=OA(X2(log⁡X)t−1),O_A\left(\frac{X^2}{(\log X)^{t-1}}+XZ^6+Z^8\right)=O_A\left(\frac{X^2}{(\log X)^{t-1}}\right),

which proves (6.23). All excluded sieving primes were fixed in advance of r,Lr,L, and residue-count errors are uniform in the position of the encompassing square. This proves the claimed uniformity.

Completing the prime-pattern construction

For each of the tt forms, multiply the number of its possible bad prime values in (6.20) by the uniform fiber bound (6.23). A union bound shows that at most

CAX3L(log⁡X)t+oA ⁣(X3(log⁡X)t)\frac{C_AX^3}{L(\log X)^t} +o_A\!\left(\frac{X^3}{(\log X)^t}\right)

of the prime patterns can have a common odd factor l>Ll > L in one of their pairs of reduction orders. More explicitly, the ratios of the two other terms to X3/(log⁡X)tX^3/(\log X)^t are OA(X−1/8log⁡X)O_A(X^{-1/8}\log X) and OA(X−1/2(log⁡X)2)O_A(X^{-1/2}(\log X)^2); both tend to zero. None of the constants in this upper estimate depends on LL.

Choose LL, after all data depending on AA have been fixed, large enough that

CA/L<12cA(log⁡L)−C0.C_A/L < \tfrac{1}{2}c_A(\log L)^{-C_0}.

This is possible because (log⁡L)C0/L→0(\log L)^{C_0}/L \to0. Then choose XX sufficiently large for (6.12), for all the upper estimates, and for the residual little-oh in (6.24) to be smaller than the remaining lower-bound coefficient. At least one prime pattern survives. Small common odd factors were already excluded by the CRT conditions, and all larger ones have just been removed. The 2-part and the prime-to-rr assertions proved from (6.5) now give (6.2). The primes have size at least cAXc_A X, so increasing XX makes all of them exceed any prescribed BB. This proves Lemma 6.1.

Together with Corollary 6.2, the prime-pattern lemma proves Corollary 2.6, completing the ordinary integer witnesses used in Section 2. The analysis there combines the tested representations with the parity, height, and elliptic inputs to turn success of all finite tests into an ordinary integer zero.

Turing degree and a quartic normal form

The finite-test reduction determines the Turing degree of rational solvability. A separate arithmetic-circuit conversion gives the same degree for two restricted forms of the input.

Corollary 7.1. With the usual effective coding, let H10(Q)\mathrm{H10}(\mathbb{Q}) be the set of integral polynomials having a rational zero, with the number of variables part of the input. Then H10(Q)\mathrm{H10}(\mathbb{Q}) has Turing degree 0′0', the degree of the halting problem. The same is true for each of the following restricted input problems:

(i) rational solvability for integral polynomials of total degree at most four;

(ii) given a nonempty finite list q1,…,qs∈Z[X1,…,XN]q_1,\ldots,q_s \in\mathbb{Z}[X_1,\ldots,X_N], each of total degree at most two, whether ∑i=1sqi2\sum_{i=1}^{s}q_i^2 has a zero in QN\mathbb{Q}^N.

No bound is imposed on the number of variables, the number of summands in (ii), or the coefficient heights.

Proof. Let H10(Z)\mathrm{H10}(\mathbb{Z}) denote the analogous set of integral polynomials having an integer zero. The parallel search in the proof of Theorem 1.1 in Section 2 can be run with an H10(Q)\mathrm{H10}(\mathbb{Q}) oracle in place of the hypothetical rational decision procedure. The finite tests of §2.4 are uniformly computable from ff and their indices once the fixed arithmetic data have been chosen, and each test uses finitely many oracle queries. The search therefore halts on every input, proving

H10(Z)≤TH10(Q),\mathrm{H10}(\mathbb{Z}) \leq_T \mathrm{H10}(\mathbb{Q}),

where ≤T\leq_T denotes Turing reducibility. The fixed choices used to define T\mathcal{T} are independent of ff, so this construction gives a single oracle machine.

The Davis–Putnam–Robinson–Matiyasevich theorem, in the form [13], applies to a positive-integer coding of the halting set. Its positive-integer witnesses can be replaced by 1+u12+u22+u32+u421+u_1^2+u_2^2+u_3^2+u_4^2, using the four-square theorem as in [13]. Specializing the parameter in the resulting fixed polynomial gives a computable many-one reduction of the halting set to H10(Z)\mathrm{H10}({\mathbb{Z}}). Integer solvability is itself computably enumerable by enumeration of integer tuples, so it has Turing degree 0′0'. Rational solvability is also computably enumerable: enumerate rational tuples and evaluate the input polynomial exactly. Every computably enumerable set is Turing reducible to the halting set. Together with the displayed oracle reduction, this proves that H10(Q)\mathrm{H10}({\mathbb{Q}}) has degree 0′0'.

For the degree restriction, we apply over Q\mathbb{Q} the algebraic normalization used in [13], Theorem 7.5. Given f∈Z[X1,…,Xn]f \in\mathbb{Z}[X_1,\ldots,X_n], effectively construct an arithmetic circuit evaluating ff, with input nodes, integral constant nodes, and addition and multiplication gates. Give every node vv a new variable YvY_v. For an input node XjX_j and a constant node cc, impose respectively

Yv−Xj=0,Yv−c=0.Y_v-X_j=0,\qquad Y_v-c=0.

For a sum or product node vv with incoming nodes u,wu,w, impose respectively

Yv−Yu−Yw=0,Yv−YuYw=0.Y_v-Y_u-Y_w=0,\qquad Y_v-Y_uY_w=0.

Finally impose Yout=0Y_{\mathrm{out}}=0 at the output node. This gives a nonempty finite list q1,…,qsq_1,\ldots,q_s of integral polynomials of total degree at most two in N=n+mN=n+m common variables Z=(X,Y)\mathbf Z=(\mathbf X,\mathbf Y), where mm is the number of circuit nodes. It also handles constant inputs. Induction through the circuit shows that each rational input tuple has a unique extension satisfying the gate equations, with output value f(X)f(\mathbf X). Since squares of rationals are nonnegative, it follows that

(∃x∈Qn) f(x)=0(\exists\mathbf x\in\mathbb Q^n)\ f(\mathbf x)=0
⟺(∃z∈QN) ⋀i=1s(qi(z)=0)\Longleftrightarrow\quad(\exists\mathbf z\in\mathbb Q^N)\ \bigwedge_{i=1}^s(q_i(\mathbf z)=0)
⟺(∃z∈QN) ∑i=1sqi(z)2=0.\Longleftrightarrow\quad(\exists\mathbf z\in\mathbb Q^N)\ \sum_{i=1}^s q_i(\mathbf z)^2=0.

Let S2S_2 denote the presented list problem in (ii), and let H≤4H_{\leq4} denote the problem in (i). Sending ff to the list (q1,…,qs)(q_1,\ldots,q_s), and then expanding its squared sum, gives computable many-one reductions

H10(Q)≤mS2≤mH≤4.\mathrm{H10}({\mathbb{Q}})\le_{\mathrm m}S_2 \le_{\mathrm m}H_{\le4}.

The expanded polynomial has integral coefficients and total degree at most four. Both target sets are computably enumerable by rational-tuple enumeration, so the reductions and the first part of the proof give Turing degree 0′0' for both.

The many-one reduction to the restricted problems starts from H10(Q)\mathrm{H10}({\mathbb{Q}}); the reduction from H10(Z)\mathrm{H10}({\mathbb{Z}}) remains a Turing reduction. This argument does not establish many-one completeness of H10(Q)\mathrm{H10}({\mathbb{Q}}). The list in (ii) is supplied as part of the input, so no recognition of sum-of-squares presentations is needed. The construction supplies no bound on the number of variables or coefficient heights, and it gives no single existential definition of Z\mathbb{Z} in Q\mathbb{Q}.

References

  1. [1]Alpöge, L. (2021). Modularity and effective Mordell I. https://arxiv.org/abs/2109.07917v2
  2. [2]Alpöge, L., Bhargava, M., Ho, W., & Shnidman, A. (2026). Rank stability in quadratic extensions and Hilbert's tenth problem for the ring of integers of a number field. In Inventiones Mathematicae (Vol. 243, pp. 1129–1139). https://doi.org/10.1007/s00222-025-01392-3
  3. [3]Bombieri, E., & Gubler, W. (2006). Heights in Diophantine Geometry (Vol. 4). Cambridge University Press. https://doi.org/10.1017/CBO9780511542879
  4. [4]Bost, J.-B. (1996). Périodes et isogénies des variétés abéliennes sur les corps de nombres (d'après D. Masser et G. Wüstholz). In Séminaire Bourbaki, Vol. 1994/95, Exposés 790–804 (Number 237, pp. 115–161). Société Mathématique de France. https://www.numdam.org/item/SB_1994-1995__37__115_0/numdam.org/item/SB_1994-1995__37__115_0
  5. [5]Henri Carayol. Sur les représentations l-adiques associées aux formes modulaires de Hilbert. Annales scientifiques de l’École Normale Supérieure, 19(3):409–468, 1986. doi:10.24033/asens.1512.DOI
  6. [6]J. W. S. Cassels. Arithmetic on curves of genus 1. IV. Proof of the Hauptvermutung. Journal für die reine und angewandte Mathematik, 211:95–112, 1962. doi:10.1515/crll.1962.211.95.DOI
  7. [7]Gunther Cornelissen and Alexandra Shlapentokh. Defining the integers in large rings of a number field using one universal quantifier. Journal of Mathematical Sciences (New York), 158(5):713–726, 2009. Originally published in Zapiski Nauchnykh Seminarov POMI 358 (2008), 199–223; author version arXiv:0708.3075v2, February 14, 2008. Author version. doi:10.1007/s10958-009-9404-4.DOI
  8. [8]Gunther Cornelissen and Karim Zahidi. Topology of Diophantine sets: remarks on Mazur’s conjectures. In Jan Denef, Leonard Lipshitz, Thanases Pheidas, and Jan Van Geel, editors, Hilbert’s Tenth Problem: Relations with Arithmetic and Algebraic Geometry, volume 270 of Contemporary Mathematics, pages 253–260. American Mathematical Society, Providence, RI, 2000. Author preprint dated June 20, 2000. doi:10.1090/conm/270/04377.DOI
  9. [9]Cornelissen, G., & Zahidi, K. (2007). Elliptic divisibility sequences and undecidable problems about rational points. In Journal für die reine und angewandte Mathematik (Vol. 613, pp. 1–33). https://arxiv.org/abs/math/0412473v3
  10. [10]Cox, D. A. (2013). Primes of the Form x^2+ny^2: Fermat, Class Field Theory, and Complex Multiplication (Second). John Wiley & Sons. https://doi.org/10.1002/9781118400722
  11. [11]Darmon, H., & Granville, A. (1995). On the equations z^m=F(x,y) and Ax^p+By^q=Cz^r. In Bulletin of the London Mathematical Society (Vol. 27, Number 6, pp. 513–543). https://doi.org/10.1112/blms/27.6.513
  12. [12]Davenport, H. (2000). Multiplicative Number Theory (Third, Vol. 74). Springer-Verlag. https://link.springer.com/book/9780387950976link.springer.com/book/9780387950976
  13. [13]Davis, M. (1973). Hilbert's tenth problem is unsolvable. In The American Mathematical Monthly (Vol. 80, Number 3, pp. 233–269). https://math.umd.edu/~mcl/Pubs/713/Diophantine.pdfmath.umd.edu/~mcl/Pubs/713/Diophantine.pdf
  14. [14]Martin Davis, Hilary Putnam, and Julia Robinson. The decision problem for exponential Diophantine equations. Annals of Mathematics, 74(3):425–436, 1961. doi:10.2307/1970289.DOI
  15. [15]Deligne, P. (1971). Formes modulaires et représentations ℓ-adiques. In Séminaire Bourbaki, Vol. 1968/69, Exposés 347–363 (Vol. 179, pp. 139–172). Springer-Verlag. https://www.numdam.org/item/SB_1968-1969__11__139_0/numdam.org/item/SB_1968-1969__11__139_0
  16. [16]Deligne, P. (1971). Travaux de Shimura. In Séminaire Bourbaki, Vol. 1970/71, Exposés 382–399 (Vol. 244, pp. 123–165). Springer-Verlag. https://www.numdam.org/item/SB_1970-1971__13__123_0/numdam.org/item/SB_1970-1971__13__123_0
  17. [17]Pierre Deligne. Variétés de Shimura: interprétation modulaire, et techniques de construction de modèles canoniques. In Automorphic Forms, Representations and L-Functions, Part 2, volume 33 of Proceedings of Symposia in Pure Mathematics, pages 247–289. American Mathematical Society, 1979. Source.DOI
  18. [18]Jeroen Demeyer and Jan Van Geel. An existential divisibility lemma for global fields. Monatshefte für Mathematik, 147(4):293–308, 2006. Author manuscript dated July 11, 2005. doi:10.1007/s00605-005-0342-z.DOI
  19. [19]Kirsten Eisenträger, Russell Miller, Jennifer Park, and Alexandra Shlapentokh. As easy as Q: Hilbert’s tenth problem for subrings of the rationals and number fields. Transactions of the American Mathematical Society, 369(11):8291–8315, 2017. doi:10.1090/tran/7075.DOI
  20. [20]Faltings, G. (1983). Endlichkeitssätze für abelsche Varietäten über Zahlkörpern. In Inventiones Mathematicae (Vol. 73, Number 3, pp. 349–366). https://doi.org/10.1007/BF01388432
  21. [21]Fontaine, J.-M. (1994). Représentations p-adiques semi-stables. In Fontaine, Jean-Marc (Ed.), Périodes p-adiques: Séminaire de Bures, 1988 (Number 223, pp. 113–184). Société Mathématique de France. https://www.numdam.org/item/AST_1994__223__113_0/numdam.org/item/AST_1994__223__113_0
  22. [22]Garcia-Fritz, N., Pasten, H., & Vidaux, X. (2025). Effectivity for existence of rational points is undecidable. In Journal of Number Theory (Vol. 276, pp. 81–97). https://doi.org/10.1016/j.jnt.2025.01.023
  23. [23]Éric Gaudron and Gaël Rémond. Polarisations et isogénies. Duke Mathematical Journal, 163(11):2057–2108, 2014. doi:10.1215/00127094-2782528.DOI
  24. [24]Éric Gaudron and Gaël Rémond. Théorème des périodes et degrés minimaux d’isogénies. Commentarii Mathematici Helvetici, 89(2):343–403, 2014. doi:10.4171/CMH/322.DOI
  25. [25]Ben Green and Terence Tao. The Möbius function is strongly orthogonal to nilsequences. Annals of Mathematics, 175(2):541–566, 2012. doi:10.4007/annals.2012.175.2.3.DOI
  26. [26]Ben Green, Terence Tao, and Tamar Ziegler. An inverse theorem for the Gowers U^{s+1}[N]-norm. Annals of Mathematics, 176(2):1231–1372, 2012. doi:10.4007/annals.2012.176.2.11.DOI
  27. [27]Green, B., Tao, T., & Ziegler, T. (2024). Erratum for An inverse theorem for the Gowers U^{s+1}[N]-norm. https://terrytao.wordpress.com/wp-content/uploads/2024/04/erratum-4.pdfterrytao.wordpress.com/wp-content/uploads/2024/04/erratum-4.pdf
  28. [28]Benjamin Green and Terence Tao. Linear equations in primes. Annals of Mathematics, 171(3):1753–1850, 2010. doi:10.4007/annals.2010.171.1753.DOI
  29. [29]Xavier Guitart and Santiago Molina. Parametrization of Abelian K-surfaces with quaternionic multiplication. Comptes Rendus. Mathématique, 347(23–24):1325–1330, 2009. doi:10.1016/j.crma.2009.09.025.DOI
  30. [30]Heath-Brown, D. R. (1994). The size of Selmer groups for the congruent number problem, II. In Inventiones Mathematicae (Vol. 118, pp. 331–370). https://doi.org/10.1007/BF01231536
  31. [31]David Hilbert. Mathematische Probleme. Vortrag, gehalten auf dem internationalen Mathematiker-Kongreß zu Paris 1900. Nachrichten von der Königlichen Gesellschaft der Wissenschaften zu Göttingen, Mathematisch-Physikalische Klasse, 1900(3):253–297, 1900. Source.gdz.sub.uni-goettingen.de/id/PPN252457811_1900
  32. [32]Ariyan Javanpeykar. Polynomial bounds for Arakelov invariants of Belyi curves. Algebra & Number Theory, 8(1):89–140, 2014. With an appendix by Peter Bruin. doi:10.2140/ant.2014.8.89.DOI
  33. [33]Koenigsmann, J. (2016). Defining ℤ in ℚ. In Annals of Mathematics (Vol. 183, Number 1, pp. 73–93). https://doi.org/10.4007/annals.2016.183.1.2
  34. [34]Peter Koymans and Carlo Pagano. Hilbert’s tenth problem via additive combinatorics. Journal of the American Mathematical Society, 2026. Published electronically August 10, 2026; arXiv:2412.01768v3 submitted November 24, 2025. doi:10.1090/jams/1081.DOI
  35. [35]D. D. Long, C. Maclachlan, and A. W. Reid. Arithmetic Fuchsian groups of genus zero. Pure and Applied Mathematics Quarterly, 2(2):569–599, 2006. doi:10.4310/PAMQ.2006.v2.n2.a9.DOI
  36. [36]David Marker. Model Theory: An Introduction, volume 217 of Graduate Texts in Mathematics. Springer, New York, 2002. doi:10.1007/b98860.DOI
  37. [37]Matiyasevich, Y. V. (1970). Diofantovost' perechislimykh mnozhestv. In Doklady Akademii Nauk SSSR (Vol. 191, Number 2, pp. 279–282). https://www.mathnet.ru/eng/dan35274mathnet.ru/eng/dan35274
  38. [38]Barry Mazur. Speculations about the topology of rational points: an up-date. Astérisque, (228):165–181, 1995. Source.numdam.org/item/AST_1995__228__165_0
  39. [39]Barry Mazur and Karl Rubin. Ranks of twists of elliptic curves and Hilbert’s tenth problem. Inventiones Mathematicae, 181(3):541–575, 2010. doi:10.1007/s00222-010-0252-0.DOI
  40. [40]Milne, J. S. (2008). Abelian Varieties. https://www.jmilne.org/math/CourseNotes/AV.pdfjmilne.org/math/CourseNotes/AV.pdf
  41. [41]Milne, J. S. (2013). Lectures on Étale Cohomology. https://www.jmilne.org/math/CourseNotes/LEC.pdfjmilne.org/math/CourseNotes/LEC.pdf
  42. [42]Milne, J. S. (2020). Class Field Theory. https://www.jmilne.org/math/CourseNotes/CFT.pdfjmilne.org/math/CourseNotes/CFT.pdf
  43. [43]Youcef Mokrani. Adaptation of Monsky matrices for θ-congruent numbers. International Journal of Number Theory, 16(2):377–396, 2020. Published online September 5, 2019. doi:10.1142/S1793042120500207.DOI
  44. [44]Hugh L. Montgomery and Robert C. Vaughan. Multiplicative Number Theory I: Classical Theory, volume 97 of Cambridge Studies in Advanced Mathematics. Cambridge University Press, 2007. doi:10.1017/CBO9780511618314.DOI
  45. [45]Mumford, D. (1970). Abelian Varieties (Vol. 5). Oxford University Press.
  46. [46]M. Ram Murty and Hector Pasten. Modular forms and effective Diophantine approximation. Journal of Number Theory, 133(11):3739–3754, 2013. doi:10.1016/j.jnt.2013.05.006.DOI
  47. [47]Joan Nualart Riera. On the Hyperbolic Uniformization of Shimura Curves with an Atkin–Lehner Quotient of Genus 0. PhD thesis, Universitat de Barcelona, October 2015. Title-page date October 2015; repository release February 3, 2016. Source.diposit.ub.edu/items/ece138ce-1523-4d59-90ae-b08826c454e8
  48. [48]OpenAI. (2026). A pointwise 2-converse for elliptic curves with rational two-torsion. https://github.com/openai/math/blob/main/preprints/A-pointwise-2-converse-for-elliptic-curves-with-rational-two-torsion-September-24-2026/paper.pdfgithub.com/openai/math/blob/main/preprints/A-pointwise-2-converse-for-elliptic-curves-with-rational-two-torsion-September-24-2026/paper.pdf
  49. [49]OpenAI. (2026). Fontaine–Mazur modularity at the prime 2. https://github.com/openai/math/blob/main/preprints/Fontaine-Mazur-modularity-at-the-prime-2-September-23-2026/paper.pdfgithub.com/openai/math/blob/main/preprints/Fontaine-Mazur-modularity-at-the-prime-2-September-23-2026/paper.pdf
  50. [50]OpenAI. (2026). Goldfeld's analytic density conjecture and the 2-converse for elliptic curves. https://github.com/openai/math/blob/main/preprints/Goldfelds-analytic-density-conjecture-and-the-2-converse-for-elliptic-curves-September-23-2026/paper.pdfgithub.com/openai/math/blob/main/preprints/Goldfelds-analytic-density-conjecture-and-the-2-converse-for-elliptic-curves-September-23-2026/paper.pdf
  51. [51]Fabien Pazuki. Theta height and Faltings height. Bulletin de la Société Mathématique de France, 140(1):19–49, 2012. doi:10.24033/bsmf.2623.DOI
  52. [52]Bjorn Poonen. Using elliptic curves of rank one towards the undecidability of Hilbert’s tenth problem over rings of algebraic integers. In Claus Fieker and David R. Kohel, editors, Algorithmic Number Theory: 5th International Symposium, ANTS-V, Sydney, Australia, July 2002, Proceedings, volume 2369 of Lecture Notes in Computer Science, pages 33–42. Springer-Verlag, Berlin, 2002. Source.DOI
  53. [53]Bjorn Poonen. Hilbert’s tenth problem and Mazur’s conjecture for large subrings of ℚ. Journal of the American Mathematical Society, 16(4):981–990, 2003. doi:10.1090/S0894-0347-03-00433-8.DOI
  54. [54]Bjorn Poonen. Characterizing integers among rational numbers with a universal-existential formula. American Journal of Mathematics, 131(3):675–682, 2009. doi:10.1353/ajm.0.0057.DOI
  55. [55]Bjorn Poonen and Michael Stoll. The Cassels–Tate pairing on polarized abelian varieties. Annals of Mathematics, 150(3):1109–1149, 1999. doi:10.2307/121064.DOI
  56. [56]Pyle, E. E. (1995). Abelian Varieties over ℚ with Large Endomorphism Algebras and Their Simple Components over ℚ [University of California, Berkeley]. https://math.berkeley.edu/~ribet/pyle_thesis.pdfmath.berkeley.edu/~ribet/pyle_thesis.pdf
  57. [57]Jordi Quer. Fields of definition of ℚ-curves. Journal de Théorie des Nombres de Bordeaux, 13(1):275–285, 2001. doi:10.5802/jtnb.321.DOI
  58. [58]Kenneth A. Ribet. Galois representations attached to eigenforms with nebentypus. In Jean-Pierre Serre and Don Bernard Zagier, editors, Modular Functions of One Variable V, volume 601 of Lecture Notes in Mathematics, pages 18–52. Springer, Berlin, Heidelberg, 1977. doi:10.1007/BFb0063943.DOI
  59. [59]Kenneth A. Ribet. Abelian varieties over ℚ and modular forms. In Algebra and Topology 1992, pages 53–79. Korea Advanced Institute of Science and Technology, Taejon, 1992. Preprint arXiv:alg-geom/9208002. Source.arxiv.org/abs/alg-geom/9208002
  60. [60]Julia Robinson. Definability and decision problems in arithmetic. The Journal of Symbolic Logic, 14(2):98–114, 1949. doi:10.2307/2266510.DOI
  61. [61]Peter Scholze. p-adic Hodge theory for rigid-analytic varieties. Forum of Mathematics, Pi, 1:e1, 1–77, 2013. Corollary 1.8; see also the 2016 corrigendum. doi:10.1017/fmp.2013.1.DOI
  62. [62]Peter Scholze. p-adic Hodge theory for rigid-analytic varieties—corrigendum. Forum of Mathematics, Pi, 4:e6, 2016. doi:10.1017/fmp.2016.4.DOI
  63. [63]Selberg, A. (1947). On an elementary method in the theory of primes. In Norske Videnskabers Selskab, Forhandlinger (Vol. 19, Number 18, pp. 64–67).
  64. [64]Jean-Pierre Serre. Local Fields, volume 67 of Graduate Texts in Mathematics. Springer-Verlag, New York, 1979. Translated from the French by Marvin Jay Greenberg. doi:10.1007/978-1-4757-5673-9.DOI
  65. [65]Carl Ludwig Siegel. Über die Classenzahl quadratischer Zahlkörper. Acta Arithmetica, 1(1):83–86, 1935. doi:10.4064/aa-1-1-83-86.DOI
  66. [66]Alice Silverberg and Yuri G. Zarhin. Semistable reduction and torsion subgroups of abelian varieties. Annales de l’Institut Fourier, 45(2):403–420, 1995. doi:10.5802/aif.1459.DOI
  67. [67]Joseph H. Silverman. The Arithmetic of Elliptic Curves, volume 106 of Graduate Texts in Mathematics. Springer, New York, second edition, 2009. doi:10.1007/978-0-387-09494-6.DOI
  68. [68]John Voight. Quaternion Algebras, volume 288 of Graduate Texts in Mathematics. Springer, Cham, 2021. doi:10.1007/978-3-030-56694-4.DOI
  69. [69]Rafael von Känel. Modularity and integral points on moduli schemes, 2013. arXiv:1310.7263v1, October 27, 2013; revised version 2, March 23, 2014. Source.DOI
  70. [70]von Känel, R. (2021). The effective Shafarevich conjecture for abelian varieties of GL_2-type. In Forum of Mathematics, Sigma (Vol. 9, pp. e39, 1–29). https://doi.org/10.1017/fms.2021.29
  71. [71]Rafael von Känel and Arno Kret. Integral points on coarse Hilbert moduli schemes, 2023. arXiv:2307.06944v1, July 13, 2023. Source.arxiv.org/abs/2307.06944v1
  72. [72]Tao Wei and Xuejun Guo. The rank of 2-Selmer group associate to θ-congruent numbers, 2022. arXiv:2210.01678v1, October 4, 2022. Source.arxiv.org/abs/2210.01678v1
  73. [73]Williams, K. S. (1974). Mertens' theorem for arithmetic progressions. In Journal of Number Theory (Vol. 6, pp. 353–359). https://doi.org/10.1016/0022-314X(74)90032-8
  74. [74]Yuri G. Zarhin. Abelian varieties, quaternion trick and endomorphisms. In Ivan Cheltsov, Xiuxiong Chen, Ludmil Katzarkov, and Jihun Park, editors, Birational Geometry, Kähler–Einstein Metrics and Degenerations, volume 409 of Springer Proceedings in Mathematics and Statistics, pages 857–864. Springer, Cham, 2023. Author version arXiv:2010.07995v5. doi:10.1007/978-3-031-17859-7_42.DOI

Paper details

Contents