Skip to content

t27c silicon: read the die's DNA into the signed receipt -- R3-2 slice 2, reader half (Refs #7452) - #7570

Merged
gHashTag merged 1 commit into
masterfrom
claude/die-read-t2-7452
Oct 7, 2026
Merged

gHashTag merged 1 commit into
masterfrom
claude/die-read-t2-7452

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Refs #7452. Epic #6655, Round 3 item 2. Follows #7484, which landed the verification half.

What

  • specs/verified/die_binding.t27 now owns the bench reader:
    • DNA_READER is device_dna.t27's openocd recipe as one -c script.
    • reader_raw parses the tagged output.
    • cables_listed counts --scan-usb lines, which feeds dna_read_allowed.
  • t27c silicon reads the DNA before any load and again after the run. The receipt carries device_dna only when both reads name the same die. Otherwise the field is null.

Own language

All of the logic is in .t27. The only hand-written Rust is bootstrap/src/service.rs +36/-1, which runs two commands and holds no rule. That file is listed in tools/policy/foreign-exceptions.txt. bootstrap/gen/rust/verified/die_binding.rs is t27c output.

Verified on the Railway lab (rebased onto master 2749341)

  • t27c test-report specs/verified/die_binding.t27: 20/20 pass, 0 fail, 0 of 20 vacuous.
  • t27c gen-rust output is byte-identical to the committed bootstrap/gen/rust/verified/die_binding.rs.
  • t27c seal --verify: all hashes MATCH.
  • The tests parse the bench's own openocd output (captured 2026-10-07) back to DNA_OBSERVED.
  • 19 hand mutants: 18 killed, 1 equivalent (documented in the spec).

No eFUSE write and no PUF. The reader only reads.

🤖 Generated with Claude Code

die_binding.t27 now owns the bench reader: DNA_READER is device_dna.t27's
openocd recipe as one -c script, reader_raw parses its tagged output,
cables_listed counts --scan-usb lines for dna_read_allowed. Tests tie
every opcode, the IR length, the IDCODE and the cable to device_dna.t27,
and parse the bench's own openocd output (2026-10-07) back to
DNA_OBSERVED. test-report 20/20, 0 vacuous; 19 hand mutants, 18 killed,
1 equivalent (documented in the spec).

`t27c silicon` reads the DNA before any load and again after the run;
the receipt carries device_dna only when both reads name one die, else
null. Hand Rust: service.rs +36/-1 (two commands, no rule).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gHashTag

gHashTag commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Bench run 2026-10-07, live on the die. One cable (openFPGALoader --scan-usb lists one 0x0403:0x6014), board 0:2, IDCODE 0x3636093. t27c built from this branch (toolchain t27c-bootstrap@0.4.0+bf1fa1de5). Fresh local receipt key cc9d5273b6dd2cf2, one verifier nonce for all three runs.

  • DNA_READER run directly with openocd, twice: FUSE_DNA 41ab0a4f 2a19bf18 and XSC_DNA 30835614 fe54337e, identical both times and the same strings this spec's test parses.
  • t27c silicon specs/fpga/ternary_link.t27 with --pnr-seed 1, 7 and 42:
    • Every run: A1 Done=0 on the wrong part, B1 Done=1, B2 0xa5a532bf, clauses=1111, ok=1.
    • Every run printed DNA 050d58218fd9854 (FUSE_DNA and XSC_DNA agree, before and after the run). That equals DNA_OBSERVED (0x50d58218fd9854) in device_dna.t27.
    • Every receipt is signed and carries device_dna.
  • t27c run-record --challenge <nonce>: 3 of 3 receipts, word=PASS, auth=FRESH. Die is NAMED, never device-rooted, as die_binding.t27 says. The first missing item is RUN_PRODUCER_MISMATCH: master's fpga_ZeroDSP_TernaryLink.json seal (2026-08-30) has no built_by, so no receipt can cite it. The reader is right to refuse it; re-sealing with a built_by is a separate step.

No eFUSE and no write of any kind. The reader issues only DNA reads and BYPASS.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-07 17:03:20 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 38
PRs with All Checks Green 12
READY 1
FAILING 38
PENDING 0
NO CHECKS YET 0

These columns do not partition: 1 + 38 + 0 + 0 = 39, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=66b6e1375e37 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

owner-approved-foreign Owner-approved exception to the only-t27 rule: hand-written foreign code allowed in this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant