The two supplements, and where the eight comes from
Worth reading first: Counting one rectangle, twice · Two dials at once.
The law of quadratic reciprocity is a statement about two odd primes, and it has a hole in the middle of it exactly where the most useful cases live.
To evaluate for a general , the practical route is to factor and use that the symbol is multiplicative — — so the whole problem reduces to the symbols of the primes dividing , and to the symbol of when is negative. The main law handles an odd prime against an odd prime. It says nothing whatever about , because is not a prime, and nothing about , because the rectangle the proof counts has by points in it and makes one side empty.
So two cases are left over, and they are called the supplements. They are not corollaries. Each needs its own count, and the two counts do not look alike.
Half the residues, and the criterion that sorts them
Before either supplement, one fact about the ground they stand on. Among the non-zero residues modulo an odd prime, exactly half are squares. That is not a numerical coincidence: squaring is two-to-one on the non-zero residues, since and have the same square and nothing else does, so the image has exactly elements.
Euler’s criterion turns that structural fact into a test. Raising a non-zero residue to the power gives an element whose square is , so the answer is or , and it is exactly for the squares. The reason is that the non-zero residues form a cyclic group: pick a generator , write , and is exactly when is even, which is exactly when is a square.
So the Legendre symbol is a homomorphism from the non-zero residues onto , and that single sentence is where multiplicativity comes from. A group of residues drawn as a cycle makes the picture immediate: the squares are the even positions round the cycle, and a product of two odd positions is even.
Everything below is the same criterion evaluated at two particular values of , and the interest is entirely in how the answers depend on .
The first supplement, in one line
Euler’s criterion says that . Put and the right-hand side is , which is when is even and when it is odd.
That is the whole argument. is even exactly when is divisible by four, so
There is nothing to draw and nothing to count, because Euler’s criterion has already done the work. What is worth noticing is how little the argument uses: it never mentions which numbers are squares, only that raising to the power sorts the residues into two halves and that lands in one of them for an arithmetic reason.
The same statement through Gauss’s lemma takes slightly longer and is more informative, so it is worth doing. The lemma counts how many of land in the top half of the residues modulo , and the symbol is minus one to that count. For , which is , the multiples are , and the -th one is . That sits above exactly when , which is every in the range. So the fold count is — all of them — and the symbol is again.
Two routes, one answer, and the second one says why the modulus is four: the count runs over half the residues, and whether half of is even is a question about modulo four.
The second supplement is a different shape
For the multiples are , and the ones that fold are those exceeding . The -th multiple is , and means . So the number of folds is
and the symbol is minus one to that.
Evaluate that expression at the four classes of modulo eight and the pattern comes out. Take : and , so the count is , which is even, and is a square modulo . Take : and , so the count is , which is odd, and is not. Running the four cases gives
The eight is not decoration. It arrives because the count involves , and the parity of that floor depends on modulo eight rather than modulo four — one more halving in the argument buys one more doubling in the modulus. Anyone who has watched the first supplement land on four and expects the second to land there too is making a reasonable guess and is wrong, and the reason is visible in the arithmetic rather than mysterious.
Why a rectangle cannot produce this
The lattice-point proof of the main law is a beautiful thing and it genuinely cannot reach these two cases. Its rectangle has columns and rows, and its whole content is that the diagonal of slope misses every lattice point — which is true because and are distinct primes and so coprime.
Put and the rectangle has rows, which is not a number of rows. Put and there is no rectangle at all. The proof is not merely inconvenient in these cases; the object it counts does not exist.
That is worth dwelling on, because it is a common shape. A counting argument is bounded by what it counts, and when the boundary is reached the honest response is a second argument rather than a stretched first one. Gauss’s lemma survives here precisely because it counts something that still exists — a list of multiples and how many fold — for any multiplier at all, prime or not.
The two supplements together
The multiplicativity of the symbol means the two supplements combine, and the combination is where the modulus eight earns its keep. Since , the class of modulo eight decides all three of , and at once.
Reading down the columns, the primes have both symbols positive, and they are exactly the primes for which , and are all squares. Those are the primes over which the arithmetic is most generous, and they are the ones where several classical theorems become easy at once.
The class has and , so their product is : the two failures cancel. A statement of the form neither of these is a square, so their product is is exactly the kind of thing the symbol makes routine and that direct computation makes tedious.
What each supplement is really about
The first supplement is the condition for the field of residues modulo to contain a square root of — that is, an element with . Where it holds, the residues behave like a place where the complex numbers can partly live, and the primes that are sums of two squares are exactly these. The two statements are the same statement: has a solution precisely when is a square modulo , because a factorisation of in the Gaussian integers is what a square root of modulo produces.
That equivalence is the single most useful consequence in elementary number theory of anything on this ladder, and it is worth stating as a chain: , therefore is a square modulo , therefore is not prime in , therefore . Each arrow is a small theorem and the composite is a classification.
The middle arrow is the one doing real work. Knowing modulo means divides in the Gaussian integers while dividing neither factor — so is not prime there, and a non-trivial factorisation of into Gaussian integers, multiplied by its conjugate, is . Every step of that is elementary and the whole of it fits in a paragraph, which is a good deal for a classification of the primes.
The second supplement is the condition for to exist among the residues, and its natural home is the ring in the same way. The reason it lands modulo eight rather than modulo four is that has a subtler ramification at the prime two than does — but that sentence is a summary of a later subject, and the count above is a complete proof that needs none of it.
A worked case, since the symbols compose
Take the question: is a square modulo ?
Split it. .
The first supplement: , so .
The second: , so .
The main law for : both are , so the two symbols are opposite, and .
The product is , so is a square modulo . Checking directly: , and ; . Rather than search, note that the answer is and trust the machinery — which is the point of having it. For the record, and , so is the root, and the computation above never needed to find it.
That last observation is the real content of the whole apparatus. The Legendre symbol answers is there a square root without producing one, and the two questions have wildly different costs. A quantity cheap to compute beside a quantity expensive to compute is the shape of a good deal, and here the cheap quantity is a handful of congruence conditions.
How often each case happens
A congruence condition invites a question about density, and here the answer is as even as it could be. The primes are equidistributed among the classes modulo eight that can contain them — , , and , since the other four classes are even — so each of the four cases takes a quarter of the primes in the long run. Dirichlet’s theorem on primes in arithmetic progressions is what says the classes are non-empty; the equidistribution is a refinement of it.
At two hundred the counts are not yet a quarter each, and the wobble is real rather than an artefact of a small sample: the race between residue classes has its own literature, and one class can lead another for a very long time. What is guaranteed is the limit, and nothing about how quickly it is approached.
The practical consequence is that both supplements are needed about equally often. There is no dominant case to memorise and no shortcut worth having; the four rules — for , for — are the whole of it, and they are short enough to be worth knowing outright.
One asymmetry does survive. The class , where both symbols are positive, is a quarter of the primes and carries more than a quarter of the interest, because it is where several independent conditions hold at once. A prime in that class is a sum of two squares, has as a square, and has as one — three separate facts made available by two rules and their product.
Where they came from, and in what order
The chronology is instructive because it runs the opposite way from the logic. Fermat announced the two-square theorem — every prime modulo is a sum of two squares — in 1640, and left no proof. Euler spent seven years on it and finished in 1749, and the argument he found is essentially the chain above run in reverse: he proved the first supplement in order to get the representation.
So the supplement arrived as a lemma for a theorem about squares of integers, half a century before anybody stated a general law of reciprocity. Legendre introduced the symbol in 1785 and gave the supplements their modern shape; Gauss proved the main law in 1796 and put all three together. The tidy modern presentation, in which the main law is stated first and the supplements are appended, inverts the order of discovery entirely.
That inversion is normal and it is worth naming. A subject’s logical spine is assembled after the fact, from results found for unrelated reasons, and the tidy order is a pedagogical artefact rather than a history. Reading it as history produces the impression that Euler was proving a special case of something he had never heard of.
The one place the modern order does better is in explaining the moduli. Presented as Euler presented it, the appearance of is an arithmetic accident of one calculation. Presented as a fold count beside the fold count for , the and the sit next to each other and the difference between them is visible: one more division in the argument, one more doubling in the answer.
What the pictures cannot show
The tables are finite and the claims are not. Fourteen primes agreeing with a congruence condition is fourteen instances, and the argument that makes it a theorem is the fold count above, which no drawing displays. The figures check the claim at every row they hold and then stop, which is exactly as far as a table can go.
The fold count is drawn nowhere. The last column of the hero is a number, and the walk that produced it — through multiples, testing each against — happens inside the generator. A picture of that walk for one prime would be the same picture the first rung already draws for a general multiplier, and repeating it here would add a figure and no argument.
And nothing here explains the eight. The count produces it, the table confirms it, and the sentence about gestures at where the explanation lives. A reader who wants to know why two behaves differently from every odd prime has to leave elementary number theory, and the honest thing is to say so rather than to dress the count up as an explanation.
Where the ladder goes next
The supplements complete the toolkit: with the main law, the two of them, and multiplicativity, any Legendre symbol whatever can be evaluated by a chain of reductions that terminates. What they do not do is explain why the law is true, and the rest of this ladder is about that.
The next rung finds the symbol somewhere it has no business being — in the sign of a shuffle, where multiplication by is read as a rearrangement of the residues and the parity of its crossings turns out to be the symbol. That is the same bit of information arriving through the theory of permutations rather than through counting lattice points, and the coincidence is not one.
Sideways, the Chinese remainder theorem is what makes the Jacobi symbol behave, and the divisor structure of a number is what the multiplicativity above is a shadow of.
What is worth carrying away
A theorem’s exceptions are usually where its proof ran out rather than where its statement did.
Reciprocity is stated for two odd primes because the rectangle in its proof needs two odd primes to exist. The cases left over are not deeper or shallower than the main law; they are the cases a different count reaches, and the different count is a page long. What makes them interesting is that they land on different moduli — four for and eight for — and that difference is not an accident of the proof but a fact about how those two numbers sit inside larger rings.
The habit worth taking is to ask, of any theorem with a hypothesis, what the hypothesis is doing. Here it is holding up a rectangle. Remove it and the rectangle collapses, and the honest response is to find something else to count.
What links here
Computed from the collection, not written here: the essays that point at this one.
Shares its objects with
Essays that name at least two of the same things, and that neither author linked.
- Numbers that wrap — both name modular arithmetic, parity, primes
- One sum, squared two ways — both name legendre symbol, quadratic reciprocity, quadratic residue
- Distance is a picture — both name modular arithmetic, parity
- Eighteen people, and the seventeen that escape — both name modular arithmetic, quadratic residue
- Numbers that are their own parts — both name counting-two ways, primes
- One way to factor, and no other — both name counting-two ways, primes
Named objects
A dashed tag is an object no other essay names yet.
Counting-two waysGauss lemmaGaussian integersLegendre symbolModular arithmeticParityPrimesQuadratic reciprocityQuadratic residueSums of two squares