Blog
[one spec so far; two of the three receipts share an operator; CI does not yet skip silicon checks by receipt] One t27 spec, ternary_link, was checked on three different FPGA chips on three machines, one of them driven from 410 ms away, and the answers agree. Each chip is named by its device DNA and signed its answer to one challenge; run-record calls the run citable (INDEP_DIES). A second chip found a bug the first could not. The point: with a citable hardware verdict, the rule in reuse.t27 lets a silicon check run once per spec version and toolchain, and everyone else check the receipts in seconds.

One t27 spec has now been checked on three different FPGA chips, on three machines, and the three answers agree. Each chip is named by its own device DNA. Each signed its answer to the same one-time challenge. Our run-record tool calls the result citable. This is R3-3, and it changes what a hardware check costs: it becomes something you run once per version and then reuse, instead of something every build repeats.
The spec is specs/fpga/ternary_link.t27. t27c 0.5.1 turns it into a bitstream with the open toolchain (yosys, nextpnr-xilinx, prjxray), loads it into the FPGA's SRAM, and reads the answer back over JTAG: 0xa5a532bd, all four clauses true, ok=1. Before that, every run loads a bitstream built for the wrong part, and the chip must refuse it (Done 0). That control stops a board that answers yes to everything from passing.
[measured] Die A, 050d58218fd9854, is on the owner's bench. Die B, 0389c0c2d85e85c, is on operator B's bench. Die C, 050a5824d85e85c, is on Phil's PC. All three answered the verifier's challenge e61798b7…, and the key of the machine that ran each one signed its receipt. run-record reads the three receipts in seconds: run complete, all fresh, every die named, independence INDEP_DIES, citable.
Phil's board sits on a Windows PC with no FPGA toolchain. Instead of building one there, operator B's Linux lab borrowed only his JTAG cable, over USB/IP inside a private Tailscale network. Phil, his own Claude and the owner all agreed to this in the open first (t27#7669). The bitstream took about 70 minutes to load at a 410 ms round trip, and the whole run took about 2.5 hours. The first attempt found an empty JTAG chain: the board had USB power but not its 12 V supply.
Die B read its DNA, but its receipt came back without one. Our spec expected the last 7 bits of the fuse copy of the DNA to be 0x4F. That was true of die A only: die B has 0x37. One die cannot show that a constant is really per-die. The fix (t27#7761) became t27c 0.5.1, and all three receipts were made with it.
specs/verified/reuse.t27 already says when a built artifact may be reused instead of rebuilt. Five parts must match: the spec's bytes, the seals of everything it imports, the toolchain, the build configuration, and a PASS verdict. A part that was never recorded counts as different. For software this already pays off: CI tests only the specs a change can affect (specs/ci/affected.t27).
For hardware, the weak part was the fifth one. A PASS on one board might be a lucky board, a mislabelled bench or a bug that only one chip hides, as die B just showed. R3-3 is the first hardware verdict strong enough to be that fifth part: three distinct dies, fresh signed receipts, and a run record that a verdict may cite.
[measured] On a local bench, a silicon check of ternary_link costs about a minute of place-and-route (60.75 s on die A) plus the load. Remotely it took hours. Once the verdict is citable, the check has to run once per spec version and toolchain, not once per build, per machine or per contributor. Everyone else checks the receipts, which takes seconds. As more specs get runs like this one, the cost of verifying a change grows with what the change touches, not with the size of the corpus.
There is one spec so far. CI does not yet skip a silicon check by citing a receipt: wiring reuse.t27 into the pipeline is the next step. Dies B and C were signed with keys from one operator's machines, so the run reaches INDEP_DIES, not INDEP_OPERATORS. And a device DNA is a name, not a secret, so no receipt here is rooted in the device itself.
Work with me
I audit RTL and build independent, bit-exact models, then take the result through synthesis and, when useful, onto an Artix-7 board. The first conformance module is free.