# ECP5 VM-to-policy physical-disarm record — 2026-08-29

## Result and scope

Company-authored physical-board engineering evidence: with the board's SW5-1
physical arm OFF, one volatile ECP5 image ran the loader, a bounded VM program,
and the monitor's permit/refusal path, then submitted a CFS request to the
fabric policy. Retained raw UART reported:

```
VM_POLICY_DISARM,vm_monitor=1,policy_status=4
VM_POLICY_DISARM_V1,pass=vm_monitor_request_blocked_by_physical_disarm
```

Status `4` is the policy's disarmed state. The result means the tested software
path reached its request point while the independently sourced board switch
remained authoritative in the fabric. The image was JTAG-loaded into volatile
SRAM only. No configuration flash, expansion pin, product I/O or actuator was
used.

## Scope

One instrument-captured path from loader/VM/monitor code to a physical-disarm rejection, with the interpreter, loader and monitor on one soft CPU, in volatile SRAM on the ECP5 evaluation board.

## Reproducibility

The completed internal record is
`evidence/runs/2026-08-29-ecp5-vm-policy-disarm-001/manifest.json`. It retains
frozen source inputs and hashes, the bitstream, routed build log, JTAG loader
log, tool versions, and raw UART capture. The report records the initial
duplicate-start-symbol build failure and the correction made before the only
board load.
## Record amendment — 2026-09-22

Deployment review found a transcription discrepancy in the run and
certification manifests for `captures/capture-status.txt`. Its retained bytes
(`load_status=0 capture_status=0`, followed by a newline) match the original
`captures/SHA256SUMS.txt` ledger. Both manifests now use that recorded hash:

- Previous manifest value: `94822b48ac317d59780e1b0f8fda11fcd662ce1dfda49b8f2fd6fd4e567057cf`
- Corrected value: `94822b48ac317d59780e1b258f48f2c2db8d1016529c331977520e286887a54d`

All 14 manifest-listed source inputs and artifacts were rehashed against the
retained files. No source, bitstream, log, capture, observation, result, or
claim scope was changed. This is a company-authored record correction, not
an independent validation or a new board run.
