# ECP5 CFS fabric-gate record — 2026-08-28

## Result and scope

Company-authored physical-board engineering evidence: a volatile SRAM image on
the Lattice ECP5-5G Evaluation Board routed the soft CPU's only gate-command
interface through the NEORV32 Custom Functions Subsystem (CFS). GPIO was not
instantiated in this image. The fabric owned the eight onboard LED outputs and
returned a three-bit, read-only gate status through CFS. Raw UART was captured
before JTAG loading and retained as the primary observation instrument.

The raw record reported:

```
safe=0
permit=1
timeout=2
invalid=4
pass=cfs_doorbell,timeout_fail_closed,malformed_fail_closed,readback=ok
```

The image was loaded over JTAG into volatile SRAM only. The gate withdrew
permit after 480,000 fabric-clock cycles (40 ms at the 12 MHz test clock) and
failed closed on a malformed command. Implementation tooling reported a
98.01 MHz routed-clock estimate; this is not a physical frequency measurement.

## Scope

An LED-only prototype result in volatile SRAM on the ECP5 evaluation board. The later fabric safety-policy records add a physical arm condition and a non-renewable lockout to this gate.

## Reproducibility

The completed internal record is
`evidence/runs/2026-08-28-ecp5-fabric-gate-cfs-001/manifest.json`. It retains
the frozen CFS/top-level/firmware inputs, successful bitstream and build log,
raw UART capture, tool versions, hashes, loader log, and the pre-load failed
build caused by CFS dependency ordering.
