# Board jail-break series J5–J8 — 2026-09-27

## Result and scope

Company-authored physical-board engineering evidence: the remaining four
classes of the board jail-break series were executed in one arm-free session
(volatile SRAM only, no actuator, product I/O or configuration flash), each
against the wall it was designed for. **The boundary held on all four.**

- **J5 — PMP wall sweep from user mode** (`2026-09-27-ecp5-j5-001`): a
  straight-line user-mode sequence behind the locked NAPOT layout — loads,
  stores and execution at monitor RAM, the open DMEM word, CFS, UART and
  GPIO — with a trap handler recording (mcause, mtval) per fault. Every
  protected boundary access faulted with its documented cause (load 5, store
  7, fetch 1); the two open DMEM words were the only permitted accesses; no
  user-mode access reached monitor RAM, CFS, UART or GPIO. The reporter
  prints 12/13 plus one expectation artifact: the execution probe's fetch
  fault fired correctly but NEORV32 reports `mtval=0` for fetch faults,
  so the mtval check reads empty — a reporting artifact, not a wall breach.
  The terminating ecall (mcause 8) proves the sequence ran in user mode,
  which the earlier single-shot probes could never distinguish.
- **J6 — CFS/fabric authority sweep** (`2026-09-27-ecp5-j6-001`): all
  65,536 proposal+request command words written to the fabric doorbell from
  machine mode with a status read after each, then the best-permit-shaped
  word hammered for ~10M cycles. Zero permit hits, zero undocumented status
  bits; the observed states were exactly the documented fresh-confirmation-
  missing and envelope-reject bits, and the hammer changed nothing. The CPU
  cannot write itself into authorization.
- **J7 — wire-protocol forgery** (`2026-09-27-ecp5-j7-001`): a baseline
  frame and nine forgery shapes against the deployed production-format
  mediator image. The baseline was permitted; the shapes were same-frame
  replay, stale-sequence replay, sequence wraparound, feedback replay, the
  age rail, session mismatch, corrupted-CRC silence, trailing-byte desync,
  and lease expiry. Every forgery shape received its documented refusal (`Q`, `F`,
  `S`, `T`) or silence; no stale, replayed, corrupted or forged frame was
  accepted as a permit, and corruption never latched the lease.
- **J8 — environmental first pass** (`2026-09-27-ecp5-j8-001`): the
  seventeen-probe canary suite re-run after ~100 s of full-rate compute —
  17/17 pass hot, identical to the cold baseline. The true fault-injection
  classes (clock/voltage/EM glitch, servo thermal gates) remain
  equipment-gated.

## What this establishes — and does not

With J1–J4 (canary probes, cost-model rail) already executed, every designed
and executable class of the board jail-break series has now been run on the
deployed board. The boundary held under each confinement class: interpreter
memory and capability bounds, the PMP wall from user mode, the fabric
authority from machine mode, the wire protocol from the host side, and the
compute-soak variation. The cost-model rail held for every ordinary
instruction class and measured the one real finding: the stub-measured
capability entries under-charge a deployed propose by 14.76×. The series does
not establish WCET, fault-injection immunity, or anything about the
physical-envelope classes (the separate H-series designs), and it covers one
board, one build per run, same operator, no independent review.

## Reproducibility

Each run retains its manifest, transcript, bitstream and firmware hashes,
and fixture source under `evidence/runs/2026-09-27-ecp5-j{5,6,7,8}-001/`
with certification mirrors alongside. The J5 debugging findings — the trap
handler cannot touch `.bss` through the locked page, the probe block must
assemble without compressed instructions, a fetch fault's `mepc` is the
target, and an unmapped load past DMEM hangs the bus — are retained in its
manifest as properties of this rig. The series designs and status are
`redteam/BOARD_JAILBREAK_ATTACK_DESIGN_2026-09-27.md`.
