{
  "_doc": "One result, read from the codebase’s own files at the commit named here. Every value is that file’s own, copied verbatim; nothing here is written by hand. A value replaced by {withheld: true, sha256_of_value, bytes} is committed by its sha256 instead of published, for the reason it states, and is never edited. Each whole source file is committed by sha256 below, and its bytes are published only where its visibility says so. The codebase is named by the public subject its files are published under.",
  "lane": "wireless-pqc",
  "repository": "wireless-pqc",
  "commit": "c5f34eda4cc9f7f86308a5db1cfa75efcd4c6841",
  "portfolio_id": "wireless-pqc:netlist-equivalence-422",
  "id": "netlist-equivalence-422",
  "attestation_row": {
    "attested_at": "2026-10-03",
    "attestor": "03-wifipqc",
    "repository": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "6f37ed958c37482bf7ee04acba61df04492fe3186c1ba6c10b77519cd450c69f",
      "bytes": 7
    },
    "source_doc": "CROWN_JEWELS_RESOLVED.md",
    "source_doc_sha256": "e90dc2b52a6d04ebdf103d7262d9ef1f6336f4b8a0ff518b9dbf308bc810fe8e",
    "state": "attested",
    "top_n": 26,
    "note_sha256": "c1af3e3220ffc4290cc975a79bf85d216638fd8abd3f4d8e7e67f6f5af0aff3b",
    "ids_in_row": 26,
    "file": "dataroom/TOP_N_ATTESTATION.jsonl",
    "line": 1
  },
  "claim_source": {
    "receipt": "wireless-pqc/dataroom/top40.json",
    "sha256": "5b765e618185384adc31381c60605ec146bb0f0c1c7352424a8929d2c0d98f14",
    "field": "entries[14].claim",
    "file": "dataroom/top40.json"
  },
  "top40_entry": {
    "id": "netlist-equivalence-422",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "7c6cd84cc4a264a5291f8ab9750f4b659a54ba4cc90bfb1c0f2d960be72ded08",
      "bytes": 31
    },
    "rank": 15,
    "native_rank": 8,
    "title": "Formal netlist equivalence for the admission engine, through technology mapping: the published sky130 netlist proved equivalent to the RTL, 274 of 274 $equiv cells",
    "claim": "Formal netlist equivalence for the admission engine through technology mapping: the sky130_fd_sc_hd netlist whose area and delay are published is proved equivalent to the RTL, 274 of 274 $equiv cells, over SkyWater's own functional cell models; the synth step alone is also proved, 422 of 422 $equiv cells over yosys simcell models.",
    "scope": "Covers every input to the mapped netlist. WireLoad = none: no place-and-route, no parasitics, no OpenSTA, no sign-off corner, no tape-out. The 4816.17 ps / ~207 MHz figure must never travel without that caveat.",
    "limits": "4816.17 ps ≈ 207.6 MHz must never travel without WireLoad = \"none\". No place-and-route, no parasitics, no OpenSTA, no sign-off corner, no tape-out. The second area figure in the same block — 8744.64 — is abc's internal unit, not µm²; the µm² figure is 14850.4928 and belongs to this module alone. Both proofs are yosys equiv_make + equiv_induct with state elements matched by name: from any state in which the matched flip-flops agree, the designs agree on every input sequence -- two-valued (no X), not a reset-reachability proof, no timing. The 274 (gates.formal_netlist_equivalence.mapped_netlist, since 2026-09-24) is the netlist file whose cells, area and delay are published, read against SkyWater's functional Verilog models of the 67 sized cells it uses, vendored unmodified with per-file sha256 in hw/pqc_admit/lib/sky130_fd_sc_hd_models/MANIFEST.json (google/skywater-pdk-libs-sky130_fd_sc_hd at ac7fb61f06e6); yosys cannot parse the two UDP tables the flip-flop models use, so two stand-ins written in this repository are used and are checked against those tables in iverilog over every two-valued case. The 422 is the synth step alone, against yosys simcell models, and no plant has yet moved it. The yosys version is now recorded in the artifact. Superseded wording, kept in this entry's claim_history: the sky130 mapping was \"a separate gate\" that no proof covered.",
    "artifact_path": "artifacts/native/pqc_admit_ci.json",
    "witness_command": "make pqc-admit-gate",
    "witness_result": {
      "status": "RAN",
      "exit": 0,
      "line": "WITNESS netlist-equivalence-422: OK -- the sky130-mapped netlist: 274 of 274 $equiv cells proved over SkyWater's cell models, the number the claim states",
      "seconds": 20.9,
      "run_at": "2026-09-24T17:23:16Z",
      "owner_gated": false,
      "reason": null,
      "run_of_record": "clean clone at HEAD (S03, dataroom/witness_quality_20260913/clean_clone_baseline.json)"
    },
    "third_party_axis": "B",
    "facts": {
      "ran_with_receipt": true,
      "third_party_graded": true,
      "negative_control_stated": false,
      "ip_class_known": false,
      "reproduce_command": true,
      "regenerates": false
    },
    "fact_count": 3,
    "repro_command": "make pqc-admit-gate",
    "ip_class": null,
    "ip_class_basis": "no source in this repository states an IP class for this entry; never guessed"
  },
  "witness_quality_entry": {
    "id": "netlist-equivalence-422",
    "portfolio_id": {
      "withheld": true,
      "why": "a working-directory name (R8)",
      "sha256_of_value": "7c6cd84cc4a264a5291f8ab9750f4b659a54ba4cc90bfb1c0f2d960be72ded08",
      "bytes": 31
    },
    "title": "Formal netlist equivalence for the admission engine, through technology mapping: the published sky130 netlist proved equivalent to the RTL, 274 of 274 $equiv cells",
    "claim": "Formal netlist equivalence for the admission engine through technology mapping: the sky130_fd_sc_hd netlist whose area and delay are published is proved equivalent to the RTL, 274 of 274 $equiv cells, over SkyWater's own functional cell models; the synth step alone is also proved, 422 of 422 $equiv cells over yosys simcell models.",
    "class": "ASSERTING",
    "why": {
      "withheld": true,
      "why": "uses a word the published record keeps for its own process (S3.1-DIALECT)",
      "sha256_of_value": "e5cc6ec3519ea510a8dd5b15cfb666068d091a3b606fc3a6c1e254a09d32f025",
      "bytes": 1226
    },
    "witness_command": "make pqc-admit-gate",
    "clean_clone": {
      "exit": 0,
      "status": "RAN",
      "seconds": 20.9,
      "first_line": "PASS 14/14 pqc_admit gates",
      "last_line": "WITNESS netlist-equivalence-422: OK -- the sky130-mapped netlist: 274 of 274 $equiv cells proved over SkyWater's cell models, the number the claim states",
      "artifact_rewritten": false,
      "dirtied": [],
      "run_at": "2026-09-24T17:23:16Z",
      "reason": null
    },
    "planted_defects": [
      {
        "index": 0,
        "what": "the RTL allocates regardless of the decision (alloc_en tied to 1): the RTL no longer matches the C engine's audit log",
        "falsifies": "property: RTL == reference engine",
        "decisive": true,
        "planted": [
          {
            "path": "hw/pqc_admit/rtl/pqc_admit.v",
            "diff": "'    assign alloc_en = decision_authorises;' -> \"    assign alloc_en = 1'b1;\" (x1 of 1)"
          }
        ],
        "exit": 2,
        "seconds": 27.8,
        "last_line": "make: *** [pqc-admit-gate] Error 1",
        "failure_moved_by": null
      },
      {
        "index": 1,
        "what": "S02 coverage sweep, ATTEMPTED AND FAILED TO MOVE THE FIGURE: an `opt -full` pass added to hw/pqc_admit/syn/equiv_sky130.ys before equiv_opt. Re-measured with the artifact read back: equiv_cells and proved_by_induction are 422 either way, as they are with `synth -noalumacc`. The count is a property of the RTL equiv_make pairs, not of the synthesis options, so this exit 0 says NOTHING about whether 422 is bound -- it is recorded so the next reader does not repeat it",
        "falsifies": "number: 422 of 422 $equiv cells -- NOT PLANTED SUCCESSFULLY by this pass, so the figure is UNMEASURED and cannot be asserted bound. equiv_cells is parsed out of yosys's log and compared with nothing at HEAD; two plants were tried and the artifact read back after each (an extra full optimisation pass before equiv_opt, and disabling alu/macc inference) and 422 did not move, because the count is a property of the RTL that equiv_make pairs rather than of the synthesis options. The witness now asserts 422 outright (EXPECT_EQUIV_CELLS, tools/check_pqc_admit.py), but that binding is itself untested: no planted defect has made it go red. Unmeasured is not bound.",
        "decisive": false,
        "planted": [
          {
            "path": "hw/pqc_admit/syn/equiv_sky130.ys",
            "diff": "'proc\\nopt_expr\\n' -> 'proc\\nopt_expr\\nopt -full\\n' (x1 of 1)"
          }
        ],
        "exit": 0,
        "seconds": 20.9,
        "last_line": "WITNESS netlist-equivalence-422: OK -- the sky130-mapped netlist: 274 of 274 $equiv cells proved over SkyWater's cell models, the number the claim states",
        "failure_moved_by": null
      },
      {
        "index": 2,
        "what": {
          "withheld": true,
          "why": "uses a word the published record keeps for its own process (S3.1-DIALECT)",
          "sha256_of_value": "846b985f2243ef2b9bac4812a8cfd12287ad8294b66bb634f923893bebbfc13d",
          "bytes": 476
        },
        "falsifies": "property: the technology-mapped sky130 netlist whose area and delay are published is formally equivalent to the RTL -- the mapped proof (syn/equiv_sky130_mapped.ys) must fail: measured 183 of 274 $equiv pairs unproven",
        "decisive": true,
        "planted": [
          {
            "path": "hw/pqc_admit/syn/synth_sky130.ys",
            "diff": "'opt_clean -purge\\n' -> 'chtype -map sky130_fd_sc_hd__nor2_1 sky130_fd_sc_hd__nand2_1\\nopt_clean -purge\\n' (x1 of 1)"
          }
        ],
        "exit": 2,
        "seconds": 21.5,
        "last_line": "make: *** [pqc-admit-gate] Error 1",
        "failure_moved_by": null
      },
      {
        "index": 3,
        "what": "PLAN5-S3 P3.4: a synthesis option moves the mapped proof's pair count -- `opt_clean -purge` -> `opt_clean` in synth_sky130.ys keeps more named nets in the published netlist (cells 1987 and area 14850.4928 unchanged), so equiv_make pairs 422 signals instead of 274 and all 422 are proved",
        "falsifies": "number: 274 of 274 $equiv cells for the sky130-mapped netlist -- the figure MOVES under this plant (274 -> 422, read back from the artifact), and the witness asserts 274 (EXPECT_MAPPED_EQUIV_CELLS, tools/check_pqc_admit.py), so this is a measured binding, not a reading",
        "decisive": false,
        "planted": [
          {
            "path": "hw/pqc_admit/syn/synth_sky130.ys",
            "diff": "'opt_clean -purge\\n' -> 'opt_clean\\n' (x1 of 1)"
          }
        ],
        "exit": 2,
        "seconds": 40.6,
        "last_line": "make: *** [pqc-admit-gate] Error 2",
        "failure_moved_by": null
      }
    ],
    "measured": true,
    "stale_claims_ref": null
  },
  "packet": null,
  "measured": {
    "measured": true,
    "basis": "planted_defects[].exit = 2",
    "exit": 2,
    "defect_rejected": true
  },
  "register": {
    "truth_state": "attested",
    "truth_line": 175,
    "measured_per_register": false,
    "witness_class_per_register": "ASSERTING",
    "ip_class_public": "unknown",
    "ip_class_sha256": "b23a6a8439c0dde5515893e7c90c1e3233b8616e634470f20dc4928bcf3609bc",
    "ip_class_source": "TOP_N_CROWN_JEWELS.md:72 @ c5f34eda4cc9",
    "receipt": "register/CROWN_JEWELS_TRUTH.md",
    "receipt_sha256": "79ca50c3472bae4ebd179ed533456325be8e0e9027739787bfba9f06442fc39b",
    "ip_class_receipt": "register/ip_class.jsonl",
    "ip_class_receipt_sha256": "1cd70f508c6b79f941e894144715088f18fcd31092e56e98a4cf6be526d9e724"
  },
  "withheld_fields": [
    {
      "field": "top40.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "witness_quality.portfolio_id",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    },
    {
      "field": "witness_quality.why",
      "codes": [
        "PROCESS_NARRATION"
      ]
    },
    {
      "field": "witness_quality.planted_defects[2].what",
      "codes": [
        "PROCESS_NARRATION"
      ]
    },
    {
      "field": "attestation_row.repository",
      "codes": [
        "LANE_DIRECTORY_NAME"
      ]
    }
  ],
  "sources": {
    "attestation": {
      "receipt": "wireless-pqc/dataroom/TOP_N_ATTESTATION.jsonl",
      "source": "dataroom/TOP_N_ATTESTATION.jsonl",
      "commit": "c5f34eda4cc9f7f86308a5db1cfa75efcd4c6841",
      "sha256": "cf3ea9a5f950428ca05e7d6678bf2e529c0265fb250c8fc0c91a4049d06ff2d4",
      "bytes": 3364,
      "visibility": "sealed"
    },
    "top40": {
      "receipt": "wireless-pqc/dataroom/top40.json",
      "source": "dataroom/top40.json",
      "commit": "c5f34eda4cc9f7f86308a5db1cfa75efcd4c6841",
      "sha256": "5b765e618185384adc31381c60605ec146bb0f0c1c7352424a8929d2c0d98f14",
      "bytes": 196287,
      "visibility": "sealed"
    },
    "witness_quality": {
      "receipt": "wireless-pqc/dataroom/witness_quality.json",
      "source": "dataroom/witness_quality.json",
      "commit": "c5f34eda4cc9f7f86308a5db1cfa75efcd4c6841",
      "sha256": "ad621a72648f0d2b485d163eccc92082ac3f36cb731c7b5bca8103983a157bd7",
      "bytes": 180480,
      "visibility": "sealed"
    },
    "repro_index": {
      "receipt": "wireless-pqc/repro/INDEX.json",
      "source": "repro/INDEX.json",
      "commit": "c5f34eda4cc9f7f86308a5db1cfa75efcd4c6841",
      "sha256": "378fd4a3ce4f44403b7c9ca6a3f19c11895831f892736376c90cf9423037f9eb",
      "bytes": 26512,
      "visibility": "sealed"
    }
  }
}
