WEBVTT

1
00:00:00.000 --> 00:00:03.474
The receiver accepts a bad request at edge 2.

2
00:00:03.474 --> 00:00:08.340
Sticky records the error afterward, and the
system resets later.

3
00:00:08.340 --> 00:00:12.941
The alert works, but it cannot withdraw the
accepted request.

4
00:00:12.941 --> 00:00:17.538
We put detection and response beside the
accepting edge.

5
00:00:17.792 --> 00:00:21.041
A detector identifies an abnormal condition.

6
00:00:21.041 --> 00:00:25.419
Local blocking prevents this block from releasing
the operation.

7
00:00:25.419 --> 00:00:31.127
An alert transports the report to system policy,
which might interrupt, wipe or reset.

8
00:00:31.127 --> 00:00:35.257
These are different events and can have different
latency.

9
00:00:35.542 --> 00:00:38.172
Our storage upset follows edge f.

10
00:00:38.172 --> 00:00:41.990
The corrupted permission first appears at edge
f+1.

11
00:00:41.990 --> 00:00:47.717
Detection appears at f+1+D, where D is an integer
delay from zero through four.

12
00:00:47.717 --> 00:00:51.102
System blocking starts R further edges later.

13
00:00:51.102 --> 00:00:55.783
The chosen request accepts only at its specified
edge.

14
00:00:56.042 --> 00:00:59.894
These are teaching edge counts, not OpenTitan
measurements.

15
00:00:59.894 --> 00:01:03.617
Its alert handler documents escalation as a
system mechanism.

16
00:01:03.617 --> 00:01:09.307
A product must derive its latency bound from
implementation and timing evidence, including the

17
00:01:09.307 --> 00:01:11.272
source-to-consumer path.

18
00:01:11.542 --> 00:01:17.442
At edge 2 with f=1 and D=0, current bad is true
but old sticky is false.

19
00:01:17.442 --> 00:01:24.042
Local policy requires both current bad and old
sticky to be clear, so it blocks.

20
00:01:24.042 --> 00:01:28.242
Sticky-only policy reads old sticky and accepts.

21
00:01:28.242 --> 00:01:33.696
The sticky register then updates after the
already recorded acceptance.

22
00:01:33.958 --> 00:01:38.254
With D=1, even local policy lacks a detection at
edge 2.

23
00:01:38.254 --> 00:01:45.020
The corrupted grant is already visible, so the
request commits before detection at edge 3.

24
00:01:45.020 --> 00:01:51.958
Adding a current-error gate helps only after that
current error is actually available.

25
00:01:52.208 --> 00:01:54.891
System-only policy waits until f+1+D+R.

26
00:01:54.891 --> 00:01:59.715
A later reset may stop additional work and
support recovery, but it cannot undo an

27
00:01:59.715 --> 00:02:01.204
irreversible delivery.

28
00:02:01.204 --> 00:02:07.158
Report first unauthorized acceptance separately
from later successful alert propagation.

29
00:02:07.417 --> 00:02:12.337
The storage campaign has one persistent upset
after f in 0.

30
00:02:12.337 --> 00:02:12.433
.

31
00:02:12.433 --> 00:02:12.626
5.

32
00:02:12.626 --> 00:02:13.108
D is 0.

33
00:02:13.108 --> 00:02:13.204
.

34
00:02:13.204 --> 00:02:14.842
4, request edge is 0.

35
00:02:14.842 --> 00:02:14.938
.

36
00:02:14.938 --> 00:02:17.732
8, and R=2 in the exhaustive table.

37
00:02:17.732 --> 00:02:20.236
The observation ends at edge 8.

38
00:02:20.236 --> 00:02:21.970
Sticky starts false.

39
00:02:21.970 --> 00:02:27.263
The image reference and all non-target
detection/response circuitry remain trusted.

40
00:02:27.542 --> 00:02:34.120
The final-grant experiment is separate: storage
remains correct and only grant is inverted at the

41
00:02:34.120 --> 00:02:35.196
accepting edge.

42
00:02:35.196 --> 00:02:39.269
Earlier local blocking cannot control that
downstream force.

43
00:02:39.269 --> 00:02:45.017
It does not test faults inside request buffers or
the accepting mechanism itself.

44
00:02:45.292 --> 00:02:51.111
Clock/reset faults, alert-link failures,
clear/wipe ordering, subcycle pulses and analog

45
00:02:51.111 --> 00:02:53.957
sensors lie outside this two-state edge model.

46
00:02:53.957 --> 00:02:59.221
A trusted detector is an assumption, not proof
that physical detection arrives in time.

47
00:02:59.221 --> 00:03:03.292
Real propagation must settle before the accepting
edge.

48
00:03:03.542 --> 00:03:08.127
Start with f=1, D=0, request edge 2 and local
policy.

49
00:03:08.127 --> 00:03:12.712
Step to edge 2: bad is true, sticky false, commit
false.

50
00:03:12.712 --> 00:03:17.696
Change to sticky policy and export the
unauthorized trace.

51
00:03:17.696 --> 00:03:20.886
Then return to local and raise D to one.

52
00:03:20.886 --> 00:03:25.234
The first request now bypasses even local
blocking.

53
00:03:25.500 --> 00:03:33.227
Executed tests swept 810 storage timing traces
across six fault edges, five delays, nine request

54
00:03:33.227 --> 00:03:35.706
edges and three policies at R=2.

55
00:03:35.706 --> 00:03:40.204
A second system-only sweep covered 1,350 traces
with R=0.

56
00:03:40.204 --> 00:03:40.295
.

57
00:03:40.295 --> 00:03:40.479
4.

58
00:03:40.479 --> 00:03:43.233
Local and sticky policies ignore R.

59
00:03:43.233 --> 00:03:49.228
An independent interval assertion checks when
acceptance is unsafe; direct edge witnesses

60
00:03:49.228 --> 00:03:50.519
anchor that formula.

61
00:03:50.519 --> 00:03:55.962
The corrupt flag is a separate timing model, not
a detector connected to lessons 4–9.

62
00:03:56.250 --> 00:04:00.200
No-fault authorized controls accept under all
three policies.

63
00:04:00.200 --> 00:04:02.630
No-fault unauthorized controls reject.

64
00:04:02.630 --> 00:04:08.325
A request before corruption has no unauthorized
acceptance because the faulty permission is not

65
00:04:08.325 --> 00:04:11.172
yet visible; a request after blocking is denied.

66
00:04:11.172 --> 00:04:15.635
Those two no-commit causes should have different
explanations.

67
00:04:15.917 --> 00:04:17.901
The RTL/SVA sketch is uncompiled.

68
00:04:17.901 --> 00:04:22.025
It requires an explicit combinational timing path
and trusted final consumer.

69
00:04:22.025 --> 00:04:27.194
A system response requirement should separately
bound detection-to-alert and alert-to-action,

70
00:04:27.194 --> 00:04:28.918
plus verify sustained blocking.

71
00:04:28.918 --> 00:04:36.224
Lesson 11 adds reset, clock, CDC and lifecycle
boundaries; those subjects remain planned here.

72
00:04:36.500 --> 00:04:41.486
One storage upset after edge f; detection f+1+D;
request edge 0.

73
00:04:41.486 --> 00:04:41.574
.

74
00:04:41.574 --> 00:04:43.613
8; system response R later.

75
00:04:43.613 --> 00:04:46.887
Final-grant forcing runs separately.

76
00:04:47.167 --> 00:04:52.788
Node ran 810 three-policy timing traces at R=2,
plus 1,350 system traces at R=0.

77
00:04:52.788 --> 00:04:52.869
.

78
00:04:52.869 --> 00:04:57.076
4, interval checks, a grant witness and
authorized controls.

79
00:04:57.076 --> 00:05:00.339
Timing closure and RTL remain unverified.

80
00:05:00.625 --> 00:05:06.824
Two-state sampling excludes propagation, CDC,
analog sensor latency, alert-link faults and

81
00:05:06.824 --> 00:05:08.523
reset/wipe details.
