S1a

advance & analogy — a study fork that walks past the netlist's edge, toward the physics underneath.

advance & analogy —— 一個走出網表邊緣、朝底下物理前進的研究分支。

The golden engine (S1) proved a binary switch-level netlist can match real silicon on 141 + 147 hardware-verified tests. S1a asks the next question: what is the minimum necessary physics to model the residue the netlist cannot express — and can we fill the gap between switch level and circuit/device level, one principled mechanism at a time?

黃金引擎(S1)已證明:二值開關級網表能在 141 + 147 顆硬體驗證測試上追平真矽。S1a 問下一個問題:要描述網表表達不了的那些殘餘,「最小必要的物理」是什麼 —— 我們能不能用一個個有原理的機制,把 switch-level 與 circuit/device-level 之間的縫填起來?

⬇ Download S1a benchmark⬇ 下載 S1a benchmark 工具 S1a CLI referenceS1a 參數手冊 ← Back to AprVisual← 回 AprVisual 主站 GitHubGitHub

Benchmark package benchmark-s1a-2026.07.25 · Windows C#, self-contained (no .NET install), corrected netlist · the full S1a engine — mechanisms always armed (golden checksum 0x41244C26C45EDD32 @ 300k, always full-armed — no raw mode; the raw S1 core is the separate S1 benchmark). Fork scaffolded 2026-07-17.Benchmark 包 benchmark-s1a-2026.07.25 · Windows C#、self-contained(免裝 .NET)、修正版網表 · 是完整 S1a 引擎 —— 機制恆武裝(金 checksum 0x41244C26C45EDD32 @ 300k,永遠全武裝、無 raw 模式;raw S1 核心是獨立的 S1 benchmark)。分支建立於 2026-07-17。

What this is這是什麼A study, not a product一場 study,不是一個產品

S1a is research-natured: an extended implementation that deliberately probes and challenges the physical and analog boundary of the netlist abstraction. The name's a carries a double meaning — advance, because it moves past where the golden engine stops; and analogy, in both senses of the word 類比: the electronic one (analog signals, charge, delay, drive strength) and the methodological one (modelling by physical analogy instead of by per-case patching).

S1a 是研究性質的:一個刻意去探測、挑戰網表抽象之物理與類比邊界的延伸實作。名字裡的 a 是雙關 —— advance(進階),因為它走過黃金引擎停下的地方;以及 analogy(類比),取「類比」一詞的兩面:電子的那面(analog:訊號、電荷、延遲、驅動強度),和方法的那面(用物理類推建模,而不是逐案打補丁)。

The division of labour is strict. S1 remains the untouched golden engine — fastest, bit-exact, the reference every experiment is measured against. S1a is a full fork (src/AprVisual.S1A/) that trades speed for principled physics, on purpose. Every mechanism lands behind its own switch, and every step is validated against three anchors: the golden checksum, the 141-test AccuracyCoin suite, and the 147-ROM regression.

分工是嚴格的。S1 保持不動,仍是黃金引擎 —— 最快、bit-exact、所有實驗的參考基準。S1a 是完整分支(src/AprVisual.S1A/),刻意用速度換有原理的物理。每個機制都躲在自己的開關後面,每一步都對三個錨驗證:金 checksum、141 顆 AccuracyCoin、147 顆回歸。

Why it exists為什麼存在The gap in the abstraction ladder抽象階梯上的那道縫

Simulation lives on a ladder. Each rung knows more physics and pays more compute. The strange thing about the rung we live on — the switch-level netlist — is how empty the space below it is: between "transistors as on/off switches" and "transistors as differential equations" there is a factor-of-millions cost cliff, and almost nobody builds there.

模擬活在一座階梯上。每一階懂得更多物理、付出更多計算。我們住的這一階 —— 開關級網表 —— 奇怪的地方在於它下面有多:從「電晶體是開關」到「電晶體是微分方程」之間,是數百萬倍的成本斷崖,而幾乎沒有人在那個空間裡蓋東西。

S1a's thesis: that gap is not empty because it is useless — it is empty because nobody had both a fast switch-level engine and a hardware-verified measuring stick to build it against. We now have both.

S1a 的命題:那道縫不是因為沒用才空著 —— 是因為從來沒有人同時擁有一個快速的開關級引擎一把硬體驗證的量尺,可以邊蓋邊對答案。現在我們兩樣都有了。

What we measured量到了什麼The campaign evidence: the gap has a shape戰役證據:那道縫有形狀

Two accuracy campaigns (288 hardware-verified tests) mapped the boundary empirically. The findings that define S1a's work list:

兩場精度戰役(288 顆硬體驗證測試)把邊界實測了出來。定義 S1a 工作清單的發現:

The plan計畫Seven mechanisms and a detection pass七個機制與一輪偵測

Mechanism機制Physics it restores還原的物理
M1Conductance-weighted resolution電導加權群解析ratioed drive fights (W/L)比例式驅動對抗(W/L)
M2Charge storage & decay電荷儲存與衰減bus hold, dynamic cells, on-die open-bus latch decay (not the board last-byte — that's M5e)匯流排保持、動態 cell、晶粒內 open-bus latch 衰減(不是板級 last-byte —— 那是 M5e)
M3RC propagation delayRC 傳播延遲cross-chip & long-line latency (timing-annotated netlist + geometry priors)跨晶片與長線延遲(時序標註網表 + 幾何先驗)
M4Sub-cycle transparent latches亞週期透明閂鎖closing-edge races, feedback loops關門沿賽跑、回授迴圈
M5Board-level component library板級元件庫TTL/CMOS parts around the dies晶粒周圍的 TTL/CMOS 零件
M5eBoard parasitic bus-hold板級寄生匯流排保持the capacitor nobody placed: open-bus last-byte on the external data bus (chartered 2026-07-18, design TBD)沒有人放的電容:外部資料匯流排的 open-bus last-byte(2026-07-18 立案,設計待議)
M6Power-on state & phase上電狀態與相位the boot lottery, CPU/PPU alignment開機抽籤、CPU/PPU 對齊
M7Canonical renumbering正準重編號determinism under graph changes圖變更下的決定論

Before any mechanism: Phase 0, the detection pass — six programmable structural scanners (latch races, cross-chip samplers, mid-flight aborts, feedback loops, geometry ranking, glitch capture) that enumerate where the physics matters, so mechanisms are built for measured targets, not guesses. The goal metric is not "zero shims" — it is zero hand-written special cases.

任何機制之前:Phase 0,偵測 pass —— 六個可程式化的結構掃描器(閂鎖賽跑、跨晶片取樣、中途廢止、回授迴圈、幾何排名、毛刺捕捉),先列舉物理在哪裡要緊,讓機制為量測過的目標而蓋、不是為猜測而蓋。目標指標不是「零 shim」—— 是零手寫特例

→ Cross-cutting read: Do the mechanisms transfer? — which of M1–M7 would help another analog-digital chip, and which are the NES's own (physics class vs implementation site).→ 延伸閱讀:機制帶得走嗎? —— M1–M7 哪些對別的類比-數位晶片有用、哪些是 NES 專屬(物理類別 vs 實作位置)。

The toolbox解析工具箱One Python per mechanism, one article per Python一個機制一隻 Python,一隻 Python 一篇專文

Each mechanism M1–M7 gets an analysis program (in s1a/py/, stdlib-only, bring-your-own netlist files): it either detects structure in the netlist or computes physical reference parameters from transdefs/segdefs geometry. Each program is paired with a standalone deep-dive article — principles first, SVG figures from real runs, and an explicit account of which shims the mechanism will let us retire.

M1–M7 每個機制配一隻解析程式(放在 s1a/py/,只用標準函式庫、自備網表檔):它要嘛偵測網表結構,要嘛從 transdefs/segdefs 幾何算出物理參考參數。每隻程式配一篇獨立深入專文 —— 先講原理,配真實跑出來的 SVG 圖,並明說這個機制將讓哪些 shim 退役

Netlist provenance — the figures use the CORRECTED netlist. All figures and JSON here are computed on the curated data/system-def/ netlist, not the raw upstream Visual6502 dump. The raw 2A03 extraction dropped two real pull-down transistors (the R4015 read-decode a1 term restored as t13032b, and an ACLK-phase device t14634b) — devices whose geometry is present in segdefs but that the extraction missed. The un-patched netlist is therefore inherently distorted: analysing it would mis-model the APU register-read decode. The corrected 2A03 carries 10,918 devices (raw: 10,916); the 2C02 needed no patch (a geometry audit found zero misses). The aggregate statistics barely move, but the analyses stand on the netlist the engine actually simulates, not the flawed source. 網表出處 —— 圖用的是「修正版」網表。這裡所有圖與 JSON 都是用整理過的 data/system-def/ 網表算的,不是上游 Visual6502 的原始傾印。原始 2A03 抽取漏掉了兩顆真實的下拉管(R4015 讀取解碼的 a1 項,以 t13032b 補回;以及一顆 ACLK 相位器件 t14634b)—— 這些器件的幾何在 segdefs 裡明明存在,只是抽取時漏了。所以未修正的網表本來就是失真的:拿它分析會把 APU 暫存器讀取解碼模型錯。修正版 2A03 有 10,918 顆器件(原始:10,916);2C02 不需補丁(幾何稽核零漏)。aggregate 統計幾乎不動,但分析站在引擎真正模擬的網表上,不是有瑕疵的來源上。

Staged, always verified. This is deliberately long-running work, not a big bang. The ritual per package: analysis script → article → (on the user's go) S1A engine mechanism → retire the shim → full gates every single time: golden checksum with the mechanism off, AC 141/141 + the 147-ROM regression with it on. A shim removed without verification didn't happen. Working ledger: MD/S1a/02_解析工具箱_網站專文_shim退役_長期TODOLIST.md.

分段走,步步驗證。這是刻意的長線工作,不是大爆炸。每組工作包的節奏:解析程式 → 專文 →(使用者發令後)S1A 引擎機制 → 拔 shim → 每一次都過完整驗證閘:機制關 = 金 checksum 不變;機制開 = AC 141/141 + 147 回歸不退步。拔了 shim 沒驗證 = 沒發生。工作總帳:MD/S1a/02_解析工具箱_網站專文_shim退役_長期TODOLIST.md

PythonArticle專文Detects / computes偵測 / 計算Shims targeted瞄準的 shimShim retired @shim 拔除 commitStatus狀態
M2m2_charge_wins.pyWho wins when nothing is driving?電容誰輸誰贏? per-node physical capacitance from die polygons + gate W×L; re-runs every floating-pair election vs the engine's connection-count proxy — 10.3% flip, 12.5% are walk-order lotteries (9,682 pairs, both dies)從晶粒多邊形 + 閘極 W×L 算每節點物理電容;把每場浮接對選舉對引擎連接數代理重投 —— 10.3% 翻盤、12.5% 是走訪順序抽籤(兩晶粒 9,682 對) io_db decay · OpenBus → M5e* · OamBlankEdge · DL689c8fd
io_db decay retired (timestamp-decay mechanism)io_db 衰減退役(時戳衰減機制)
1 retired退役 1
M1m1_device_census.pyThe die's strength vocabulary晶粒的強度詞彙 transdefs W/L for all 27,788 devices → device classes + a 19/16-class half-octave strength lattice (top-8 > 93%); the 4:1 audit derives the missing depletion-load strength (S ≈ 0.58/0.95); 538 driver-vs-driver fight sites, 194 within 2× — incl. io_db, ale, the db/ab pads27,788 顆器件的 transdefs W/L → 器件分類 + 19/16 級半八度強度格(前 8 級 > 93%);4:1 稽核反推遺失的負載強度(S ≈ 0.58/0.95);538 個驅動對驅動打架點、194 個在 2× 內 —— 含 io_db、ale、db/ab pad LxaMagic · AluLatchd237bf6
M1_LXA retired LxaMagic (default-flipped; AluLatch retired via the M4 edge-latch hold verdict).M1_LXA 退役 LxaMagic(預設翻轉;AluLatch 由 M4 edge-latch 的 hold 判決退役)。
1 retired退役 1
M3m3_elmore_binner.pyEvery net gets a clock每張網都有自己的時鐘 per-net Elmore τ composed from the first two studies (R from M1's W/L, C from M2's areas): 11,343 nets binned, ~5% delay-island candidates; slowest nets = the CPU↔PPU interface + clock trees + pads; median rise/fall 6.4×/3.9× (textbook 4:1); only 0.45% of nets can do dot-339's 16/18 — follow-up tool m3_inversion_parity.py tested the parity explanation: inconclusive (shortest-path parity is endpoint-dependent, 1 odd / 3 even) — an honestly-open anomaly用前兩份普查組成 per-net Elmore τ(R 來自 M1 的 W/L、C 來自 M2 的面積):11,343 張網分級,~5% 延遲島候選;最慢網 = CPU↔PPU 介面 + 時鐘樹 + pad;中位 rise/fall 6.4×/3.9×(教科書 4:1);只有 0.45% 的網做得到 dot-339 的 16/18 —— 後續工具 m3_inversion_parity.py 測了奇偶解釋:無結論(最短路徑奇偶對端點敏感,1 奇/3 偶)—— 誠實保持開放的異常 the four delay shims' constants四顆延遲 shim 的常數live
M4m4_latch_scan.pyEvery latch on two dies兩顆晶粒上的每一個閂鎖 pure topology, zero priors: 11,379 latch structures (2,494 pure cells + 8,129 gated + 2,348 cross-coupled incl. the 2,114 no-pull-up OAM cells, found structurally); 1,473 tight closing-edge races; self-validated — 8/11 campaign sites re-found, misses explained純拓撲零先驗:11,379 個閂鎖結構(純 cell 2,494 + 帶驅動 8,129 + 交叉耦合 2,348,含被結構自己點名的 2,114 個無上拉 OAM cell);1,473 場緊湊關門賽跑;自我驗證 —— 戰役站點 11 找回 8,漏抓有解釋 DL · DmcLatch · Dmc4015Abort · FrameIrq · Dbl2007 · OamDmaPpuBus + the transient half of+ 瞬態半邊的 OamBlankEdged237bf6
edge-latch primitive (3 verdicts: data-wins / hold / transparent) + the P1/P4/P6 rows — DmcLatch, AluLatch, FrameIrq, Dbl2007, OamDmaPpuBus, OamBlankEdge, Dmc4015Abort, PpuAleReadFeedback all RETIRED (default-flipped 2026-07-20; AC 141/141 + 147 146/1). DL alone stays.edge-latch 原語(3 判決:data-wins / hold / transparent)+ P1/P4/P6 列 —— DmcLatch、AluLatch、FrameIrq、Dbl2007、OamDmaPpuBus、OamBlankEdge、Dmc4015Abort、PpuAleReadFeedback 全 RETIRED(2026-07-20 預設翻轉;AC 141/141 + 147 146/1)。只剩 DL。
8 retired退役 8
M5m5_board_inventory.pyThe board as a circuit把主機板當電路 the system as 13 modules, 82 connections: boundary census (die↔die = 4 buses = the whole CPU/PPU interface), part inventory (74LS373 = 82 tr — the ALERead boss, real switch-level), and the structurally-undrivable controller auto-flagged (nes-pad's 4021/pslatch reverse-driven chain)系統 = 13 模組、82 連線:邊界普查(晶粒↔晶粒 = 4 條匯流排 = 整個 CPU/PPU 介面)、零件清單(74LS373 = 82 tr,ALERead 魔王、真開關級)、結構性不可驅動手把自動標記(nes-pad 的 4021/pslatch 反驅鏈) BoardOctalLatch · behavioural joypad行為層手把 · M5e: OpenBus last-byte (chartered)M5e:OpenBus last-byte(立案)live
M6m6_interface_census.pyWhere phase can hurt相位會咬人的地方 P2 scan: 173 interface nodes → BFS → 203 counter-comparators → 66 phase-sensitive interfaces; the four M6 bosses re-found by pure structure. Engine mechanism landed (M6×M3, env M6X): one (trigger, gate, delay, window) table replaces the dot-339 + BGSerialIn + even_odd clamp shims — 8-arm bit-safe, retirement undecidable in isolation (in-suite verification queued)P2 掃描:173 介面節點 → BFS → 203 計數器比較器 → 66 個相位敏感介面;四個 M6 魔王純結構重找。引擎機制已落地(M6×M3,env M6X):一張 (trigger, gate, delay, window) 表取代 dot-339 + BGSerialIn + even_odd 三顆 clamp shim —— 8 臂 bit-safe,退役孤立不可判(套內驗證排隊中) dot-339 · BGSerialIn · even_odd (M6×M3) + reset-hold · power_up_palette (phase selector, unbuilt)dot-339 · BGSerialIn · even_odd(M6×M3)+ reset-hold · power_up_palette(相位選擇器,未建)d237bf6
M6×M3 retired dot-339, BGSerialIn, even_odd (default-flipped; AC 141/141 + 147 146/1). reset-hold / power_up_palette (the INTRINSIC phase selector) stay.M6×M3 退役 dot-339、BGSerialIn、even_odd(預設翻轉;AC 141/141 + 147 146/1)。reset-hold / power_up_palette(INTRINSIC 相位選擇器)留著。
3 retired退役 3
M7m7_canonical_key.pyEnding the lottery終結抽籤 canonical key (class, layeredArea, structHash, degree); resolves 18% of ties on the PPU, 52% on the CPU, unifies the big replicated cell arrays (OAM/palette); finds name-symmetry ≠ structural symmetry (db bits are context-wired)正準鍵 (class, layeredArea, structHash, degree);解掉 PPU 18% / CPU 52% 平手,統一大型複製 cell 陣列(OAM/palette);發現名稱對稱 ≠ 結構對稱(db 位元 context-wired) (D-class lottery root)(D 類樂透根源)live

The "shim retired @" column is this ledger's proof-of-work. It stays "—" until the corresponding S1A mechanism has landed and the shim is actually removed; only then does it record the commit — and a commit only qualifies after passing the full gates: golden checksum unchanged with the mechanism off, AC 141/141 + the 147-ROM regression not regressing with it on.「shim 拔除 commit」欄是這本帳的存證欄。在對應的 S1A 機制落地、shim 真正拔掉之前,一律是「—」;拔掉後才記下那個 commit —— 而且 commit 要先過完整驗證閘才算數:機制關 = 金 checksum 不變;機制開 = AC 141/141 + 147 顆回歸不退步。

*One reclassification — OpenBus. It was first planned here under M2 (charge storage & decay). The retirement experiments overturned that: the open-bus last byte is held by the parasitic capacitance of the board's data bus — a node on neither die, absent from our segdefs geometry — so M2 charge arbitration (control FAIL 1) and the full M4 latch stack (control FAIL 1) both proved unable to reach it. It is reclassified to M5e, the board-level bus-hold charter, and stands as the shim ledger's one documented ceiling. The whole load-bearing behaviour is the last-byte replay: no on-die mechanism — not M2 charge, not the full M4 latch stack, not M3 delay — retires any part of it, so OpenBus appears under none of them, only M5e. *一次改判 —— OpenBus。它原本規劃在 M2(電荷儲存與衰減)底下。試拔實驗推翻了:open-bus 的 last byte 由主機板資料匯流排的寄生電容保持 —— 一個不在任何一顆晶粒上、我們 segdefs 幾何裡根本沒有的節點 —— 所以 M2 電荷裁決(對照 FAIL 1)與 M4 閂鎖全 stack(對照 FAIL 1)都證明碰不到它。它被改判到 M5e(板級 bus-hold 立案),並成為 shim 總帳裡唯一記錄在案的天花板。它承重的行為整個就是 last-byte 重播:沒有任何晶粒內機制 —— M2 電荷、M4 閂鎖全 stack、M3 延遲都不行 —— 能退役它的任何一部分,所以 OpenBus 出現在它們任何一個底下,只在 M5e。

On the die在晶粒上The Mx structures, lit up on the real siliconMx 結構,點亮在真實矽上

Every toolbox census above is a number — 2,114 OAM cells, 538 fight sites, 66 phase interfaces. This is where those numbers become places. Each page renders the real 2A03/2C02 layout (the segment polygons the switch-level engine simulates) live in your browser — drag to pan, wheel to zoom, hover any cell — and highlights the nodes that mechanism's detector flags, by category. One shared viewer (adapted from Visual6502's renderer); each page differs only in which detector's output it overlays.

上面每一份工具箱普查都是一個數字 —— 2,114 個 OAM cell、538 個打架點、66 個相位介面。這裡就是那些數字變成位置的地方。每頁把真實的 2A03/2C02 佈局(開關級引擎模擬的 segment 多邊形)在你瀏覽器裡即時渲染 —— 拖曳平移、滾輪縮放、停在任一 cell 上 —— 並依類別標出該機制偵測器點名的節點。一個共用檢視器(改編自 Visual6502 的渲染器);每頁只差在疊哪個偵測器的輸出。

Structural patterns — discrete graph structures結構性 pattern —— 離散圖結構

Physical heatmaps — shaded by a continuous quantity (background layers start off)物理熱度圖 —— 用連續物理量著色(背景層預設關)

Layout data is derived from the Visual 2A03/2C02 netlist (CC-BY-NC-SA); generated by WebSite/s1a/layout/gen_layout.py, detectors by the toolbox scripts' --dump-nodes.佈局資料衍生自 Visual 2A03/2C02 網表(CC-BY-NC-SA);由 WebSite/s1a/layout/gen_layout.py 生成,偵測器來自工具箱腳本的 --dump-nodes

The shim ledgershim 總帳Every patch, its purpose, and its honest fate每一個補丁,它的目的,以及它誠實的下場

A shim is a small, honest, test-mode override that supplies a behaviour the binary switch-level model structurally cannot express. The accuracy campaigns accumulated ~18 of them to reach 141/141 + 146/147. S1a's job is to replace each with a principled mechanism — but only where verification proves it. This ledger is the truth table: what each shim was for, and which of five fates it met. Where a mechanism fails to retire a shim, that is not hidden — it is recorded as a result, because a precisely-characterized ceiling is as valuable as a retirement.

shim 是一個小而誠實的測試模式覆蓋,補上二值開關級模型結構上表達不了的行為。精度戰役累積了約 18 個才達到 141/141 + 146/147。S1a 的工作是把每個換成有原理的機制 —— 但只在驗證證明得了的地方。這本總帳是真值表:每個 shim 為了什麼、以及它落到五種下場的哪一種。機制沒能退役某個 shim 的地方,不會被藏起來 —— 它被記成一個結果,因為一個精確刻畫的天花板,和一次退役一樣有價值。

Re-verified at K=1 (2026-07-19). The earlier verdicts were set during a window of tooling-configuration risk — the same conditions that briefly mis-scored the S1 baseline itself (an omitted ALEREAD_MUX env, and isolated control arms run at the wrong boot alignment K=0 instead of the campaign's K=1). So the foundation was re-certified first (AC 141/141 + 147 146/1 on the latest build), then every test-derived verdict below was re-run at K=1 on the rebuilt engine with each ROM's catalog flags applied (28 arms). The classifications held — headline correction: even_odd, UNDECIDABLE → PROVEN (its K=0 "hc-identical spectator" reading was a wrong-alignment artifact; at K=1 the control fails on 10-even_odd_timing and M6X replaces it), and OamDmaPpuBus's decidable control confirmed (FAIL). A follow-up discriminating-ROM hunt — finding a better isolated test, as even_odd's 10 was — then crossed two more: BGSerialIn → PROVEN (via AccuracyCoin_BGSerialInReal) and Dbl2007 → decidable (via double_2007_read, seconds vs the 2-h #67). The toolbox census numbers (M1–M7, deterministic on the corrected netlist) never needed re-checking. K=1 已重驗(2026-07-19)。先前的判決是在一段「工具參數有風險」的期間確立的 —— 正是後來連 S1 基礎本身都短暫算錯分的同一種條件(漏設 ALEREAD_MUX env;孤立對照臂跑在錯的開機對齊 K=0 而非戰役的 K=1)。所以先把基礎重新認證(最新 build 上 AC 141/141 + 147 146/1),再把下方每一個「test 跑出來的」判決用 K=1 在重建引擎上、帶每顆 ROM 的 catalog 旗標重跑(28 臂)。分類全數站得住 —— 頭條更正:even_odd,UNDECIDABLE → PROVEN(它 K=0 的「hc 逐位相同旁觀者」是錯對齊的假象;K=1 下對照在 10-even_odd_timing 失敗、M6X 取代得了),OamDmaPpuBus 的可判對照也確認(FAIL)。接著一輪鑑別 ROM 獵捕 —— 像 even_odd 的測試 10 那樣找更好的孤立測試 —— 又跨掉兩顆:BGSerialIn → PROVEN(靠 AccuracyCoin_BGSerialInReal)、Dbl2007 → 可判(靠 double_2007_read,秒級對比 #67 的 2h)。工具箱的普查數字(M1–M7,修正版網表上確定性算出)從頭到尾不需重驗。
In-suite milestone passed 141/141 (2026-07-20). The all-mechanisms retirement run — all eight built mechanisms armed at once (M4_EDGE · M6X · M4·P1 · M1_LXA · M4_FI · M4_OE · M3_ABORT · PPU_ALE_FB), every shim they supersede turned off — clears the full 141-test AccuracyCoin suite with zero regressions. This is the broad in-suite regression the isolated three-arm protocol structurally cannot do. Twelve shims are now RETIRED — default-flipped and re-verified (2026-07-20): DmcLatch · AluLatch (M4_EDGE) · even_odd · BGSerialIn · dot-339 (M6×M3) · Dbl2007 · OamDmaPpuBus (M4·P1) · LXA (M1) · FrameIrq (M4·P6) · OamBlankEdge (M4_OE) · Dmc4015Abort (M3) · PpuAleReadFeedback (M4·P4) — each has an isolated or in-suite discriminating control and this broad 141/141. The three final control arms have now finished (2026-07-20) and all three discriminate: dot-339 control 140/141, OamBlankEdge 138/141, and PpuAleReadFeedback drives the engine to non-convergence — so all three join the cleared set. The default-flip is now done and verified: on the S1A fork the eight mechanisms are armed unconditionally in every mode — and since the 2026-07-22 refactor there is no opt-out at all: the per-mechanism NO_* toggles and --no-shims were removed, and the raw switch-level engine is the separate S1 fork. The full regression passes both suites — AC 141/141 · 147 146/1 (only the pre-existing known cpu_dummy_writes_oam deviation), re-verified on the refactored engine 2026-07-22; the benchmark now runs the full engine too (golden 0x41244C26C45EDD32). DL stays deliberately deferred (a localized inertial-delay settle guard; the general fix is architectural) and OpenBus is the documented CEILING — the two structural residues. 套內 milestone 過關 141/141(2026-07-20)。全機制退役跑 —— 八個已建機制一次全開(M4_EDGE · M6X · M4·P1 · M1_LXA · M4_FI · M4_OE · M3_ABORT · PPU_ALE_FB)、它們取代的 shim 全部關掉 —— 在完整 141 顆 AccuracyCoin 套測試裡零退步通過。這是孤立三段論結構上做不到的套內廣回歸。十二顆 shim 現在已退役 —— 預設翻轉並重新驗證(2026-07-20):DmcLatch · AluLatch(M4_EDGE)· even_odd · BGSerialIn · dot-339(M6×M3)· Dbl2007 · OamDmaPpuBus(M4·P1)· LXA(M1)· FrameIrq(M4·P6)· OamBlankEdge(M4_OE)· Dmc4015Abort(M3)· PpuAleReadFeedback(M4·P4)—— 每顆都有孤立或套內的鑑別對照,加上這次廣回歸 141/141。最後三個對照臂已跑完(2026-07-20),三顆全部鑑別成功:dot-339 對照 140/141、OamBlankEdge 138/141、PpuAleReadFeedback 讓引擎不收斂 —— 三顆全數加入可拔集。預設翻轉現在已完成並驗證:在 S1A fork 上,八個機制在每個模式無條件武裝 —— 2026-07-22 refactor 後已無任何關閉開關:逐機制 NO_*--no-shims 都移除,raw 開關級引擎是獨立的 S1 fork。完整回歸兩套件都過 —— AC 141/141 · 147 146/1(只剩既有的 cpu_dummy_writes_oam 偏差),2026-07-22 已在 refactored 引擎上重新驗證;benchmark 現在也跑完整引擎(金 0x41244C26C45EDD32)。DL 維持刻意延後(局部 inertial-delay settle guard;通式修法架構級)、OpenBus 是有文件的 CEILING —— 兩個結構性殘留。

RETIRED mechanism replaces it, three-arm verified (shim PASS / no-shim FAIL / mechanism PASS).機制取代,三段論證(shim PASS / 拔 shim FAIL / 機制 PASS)。

PROVEN mechanism proven able to replace it (three-arm passes); default-flip pending the broad 141/147 regression.機制已證明可取代(三段論過);預設翻轉待 141/147 廣回歸。

UNDECIDABLE the mechanism expresses it, but no isolated test discriminates (the control passes without the shim) — retirement needs in-suite evidence.機制能表達,但沒有孤立測試能鑑別(對照組拔 shim 也過)—— 退役需套內證據。

CEILING a structural boundary no on-die mechanism can reach; the shim stays, and the reason is documented.晶粒內機制碰不到的結構邊界;shim 留住,理由記錄在案。

ACTIVE still a shim; its mechanism is designed but not yet built or verified.仍是 shim;機制已設計但尚未實作或驗證。

Two special-case fates, outside the retirement pipeline (see Special cases): CALIBRATED the mechanism is already live and in-suite proven — one empirically-tuned constant remains to derive rather than tune; INTRINSIC not a function of the netlist (an initial condition / external stimulus), so no computed mechanism applies — M7 makes it deterministic but cannot supply the value.兩個特殊個案下場,在退役流水線之外(見特殊個案):CALIBRATED 機制已運作、套內已證 —— 只剩一個經驗校準值待「從調變成」;INTRINSIC 不是網表的函數(初始條件/外部激勵),沒有可計算的機制適用 —— M7 讓它決定論化,但供不出值。

Which of the seven mechanisms appear here. This ledger is indexed by shim, so a mechanism shows up only where it replaces a specific shim's behaviour — you'll see M1 (LXA), M2, M3, M4, M6, and M5's board-net extension M5e (OpenBus). Two toolbox mechanisms have no row by nature: M5 (the board component library) models parts already in the netlist — the 74LS373, the 4021 — rather than fixing a shim; and M7 (canonical renumbering) is a cross-cutting determinism fix for the D-class boot lottery, with no single shim to replace. Their absence is a property of the ledger's shim-indexing, not a gap.七個機制裡,哪些會出現在這裡。這本總帳按 shim 列,所以一個機制只有在它取代某顆 shim 的行為時才會出現 —— 你會看到 M1(LXA)、M2、M3、M4、M6,以及 M5 的板網延伸 M5e(OpenBus)。有兩個工具箱機制天生沒有列:M5(板級元件庫)是把網表裡本來就有的零件 —— 74LS373、4021 —— 建模出來,不是拿來修 shim;而 M7(正準重編號)是針對 D 類開機抽籤的全域決定論修法,沒有任何單一 shim 可對應。它們的缺席是「總帳按 shim 索引」的性質,不是漏洞。

ShimshimWhat problem it solves解決什麼問題Mechanism機制Fate下場
io_db decaythe PPU open-bus latch leaks to 0 in ~600 ms when unrefreshed; floating nodes hold foreverPPU open-bus latch 不刷新時 ~600ms 漏到 0;浮接節點永遠保持M2 timestamp decayRETIRED 689c8fd
in-suite 141 confirmation running套內 141 確認跑中
DmcLatchDMC pcm_latch closing-edge race — the data should win (7-dmc_basics #19 reads $80)DMC pcm_latch 關門沿賽跑 —— 資料應贏(7-dmc_basics #19 讀 $80)M4 edge · data-winsRETIRED✓ default-flipped✓ 已翻轉
AluLatchALU input latch hold-time — the phi-boundary bus collapse must not leak into the latch (ANC/ALR/ARR)ALU 輸入閂鎖 hold-time —— φ 邊界匯流排崩塌不可漏進閂鎖(ANC/ALR/ARR)M4 edge · holdRETIRED✓ default-flipped✓ 已翻轉
dot-339$2001 rendering-enable arrives 24 hc late; the hpos=339 sprite-reset comparator fires one comparison early (StaleSprite T3)$2001 渲染致能晚到 24hc;hpos=339 精靈重置比較器早一次比較開火(StaleSprite T3)M6×M3 · ClampGateRETIRED✓ default-flipped✓ 已翻轉
Resolved in-suite (2026-07-20). Undecidable on every isolated ROM, but the frame-windowed in-suite control (dot-339 delay off, everything else at the certified baseline) FAILs one sub-test ($48F err3) at the late StaleSprite defender (f4133) that the certified 141/141 baseline passes — decidable. The M6×M3 mechanism replaces it (all-mechanisms milestone: 141/141). Three-arm complete: base PASS / control 140/141 / mechanism PASS. Default-flip pending.套內判定(2026-07-20)。每顆孤立 ROM 都不可判,但 frame 窗套內對照(dot-339 delay 關、其餘認證 baseline)在晚段 StaleSprite 防守題(f4133)FAIL 一題($48F err3),而認證 141/141 baseline 過 —— 可判。M6×M3 機制取代得了(全機制 milestone:141/141)。三段論齊:base PASS / 對照 140/141 / 機制 PASS。待預設翻轉。
BGSerialIn$2001-enable at the hpos%8 shifter-reload boundary is delayed 16 hc, so the reload is skipped$2001 致能在 hpos%8 移位器 reload 邊界延遲 16hc,reload 被跳過M6×M3 · ClampGateRETIRED✓ default-flipped✓ 已翻轉
discriminating-ROM hunt (2026-07-19): undecidable on AccuracyCoin_BGSerialIn, but on the untried AccuracyCoin_BGSerialInReal the 3-arm is clean — base PASS / NO_BGS_SHIM control FAIL (0/1) / M6X mechanism PASS. A better isolated test crossed it undecidable → proven (like even_odd 09→10); default-flip pending broad regression.鑑別 ROM 獵捕(2026-07-19):在 AccuracyCoin_BGSerialIn 上不可判,但換到還沒試過的 AccuracyCoin_BGSerialInReal 三段論乾淨 —— base PASS / NO_BGS_SHIM 對照 FAIL(0/1) / M6X 機制 PASS。一顆更好的孤立測試把它從不可判帶到已證(如 even_odd 09→10);預設翻轉待廣回歸。
even_odd$2001 write effect is 16 hc late in the vpos261 / hpos338-339 pre-render skip window$2001 寫效果在 vpos261 / hpos338-339 預渲染 skip 窗晚 16hcM6×M3 · DelayTransitionRETIRED✓ default-flipped✓ 已翻轉
re-verified K=1 (2026-07-19): on 10-even_odd_timing base PASS / no-delay control FAIL (#3 "clock skipped too late") / M6X mechanism PASS — decidable, and the mechanism replaces it. (09-even_odd_frames stays undecidable — its control passes.) The earlier "hc-identical spectator" reading was a K=0 wrong-alignment artifact; default-flip pending the broad regression.K=1 重驗(2026-07-19):在 10-even_odd_timing 上 base PASS / 拔延遲對照 FAIL(#3「clock skipped too late」) / M6X 機制 PASS —— 可判,而且機制取代得了它。(09-even_odd_frames 仍不可判 —— 對照組會過。)先前「hc 逐位相同旁觀者」是 K=0 錯對齊的假象;預設翻轉待廣回歸。
DL the DL/idl input latch captured a mid-settle bus glitch at a $4016/$4017 read (should track the settled bus)DL/idl 輸入閂鎖在 $4016/$4017 讀取捕捉了 mid-settle 匯流排毛刺(應追隨 settled 匯流排) M4 · transparent
localized inertial-delay guard
UNDECIDABLE
Frame-windowed in-suite controls pass at OpenBus (f52), ControllerClocking (f1481), and PPUOpenBus (f1611). The completed 141/141 all-mechanisms milestone reaches the late InternalDataBus region, but does not itself supply a no-DL discriminating failure, so DL remains deliberately scoped — a cost decision, not a dead end. Unlike the others (each retired by adding one M4/M6 row), DL resists a cheap global rule for three reasons: (1) “track the settled external bus” is correct only on an external read; at internal $4015 reads that bus is open-bus junk, so a global rule corrupts the real value; (2) a 2+-bit divergence is the capture-glitch signature, but a 1-bit divergence can be a legitimate controller-shift boundary; (3) the DL force and open-bus replay interact (both engaged = hang). The sound general repair is a two-phase / delta-cycle settle: evaluate a wave, commit repeatedly to quiescence, then let the transparent latch see its settled input. That changes core settle semantics, so it is a hot-path and S1A trace/checksum re-baselining project. M7 canonical renumbering is complementary D-class determinism work, not a DL cure: it removes accidental id-order variation, but can only make this glitch reproducible; it cannot establish which result matches silicon. A cheaper middle path is an auto-emitted transparent-latch settle guard driven from the actual pass-gate input, with correctly scoped input semantics. Until that work is scheduled, DL stays honestly UNDECIDABLE on the minimal-blast-radius $4016/$4017 shim with a 2-bit signature.frame 窗套內對照在 OpenBus(f52)、ControllerClocking(f1481)、PPUOpenBus(f1611)都通過。完成的全機制 141/141 milestone 已走到晚段 InternalDataBus 區域,但它本身沒有提供拔 DL 後會失敗的鑑別證據,因此 DL 仍刻意維持 scoped —— 是成本判斷,不是死路。跟其他幾顆(各補一個 M4/M6 row 就退役)不同,DL 抗拒便宜的全域規則,原因有三:(1)「追隨 settled 外部匯流排」只在外部讀取正確;內部 $4015 讀時該匯流排是 open-bus 垃圾,全域規則會覆寫真值;(2)差 2+ 位元才是 capture-glitch signature,差 1 位元可能是合法手把移位邊界;(3)DL force 與 open-bus replay 互咬(兩者同時觸發會 hang)。可靠的通則是兩階段 / delta-cycle settle:先 evaluate 一波、反覆 commit 到 quiescent,最後才讓透明閂鎖看見 settled input。這會改核心 settle 語意,因此是熱路徑與 S1A trace/checksum 重定基準工程。M7 正準重編號是互補的 D 類決定論工作,不是 DL 的單獨解:它移除偶然的 id-order 差異,最多只會讓毛刺可重現,不能判定哪個結果符合硬體。較便宜的中間路徑,是從實際 pass-gate input 自動 emit 透明閂鎖 settle guard,並正確限定輸入語意與範圍。在該工作排入前,DL 誠實維持 UNDECIDABLE,使用最小波及半徑的 $4016/$4017 + 2 位元 signature shim。
◆ a special case — the glitch is a simulation-discretization artifact, not a chip property. The repair direction is inertial-delay filtering: a general two-phase/delta-cycle settle or correctly scoped transparent-latch guards; M7 is determinism hygiene, not a DL cure.特殊個案之一 — 毛刺是模擬離散化假象、非晶片性質。修復方向是 inertial-delay filtering:通用的兩階段/delta-cycle settle,或正確限定範圍的透明閂鎖 guard;M7 是決定論衛生,不是 DL 解法。
OamBlankEdgea rendering-disable edge writes $FF into the no-pull-up OAM cells; hardware's inertia ignores the pulse關渲染邊沿把 $FF 寫進無上拉 OAM cell;硬體慣性忽略脈衝M4 · hold · M4_OERETIRED✓ default-flipped✓ 已翻轉
Resolved in-suite (2026-07-20). Undecidable on every isolated ROM, but the frame-windowed in-suite control (M4_OE off via NO_OAMEDGE_SHIM, else baseline) FAILs three sub-tests ($45B err10, $47B err2, $48F err2) at the late Address2004 / StaleSprite defenders that the certified 141/141 passes — clearly decidable. The M4_OE mechanism replaces it (milestone: 141/141). Three-arm complete: base PASS / control 138/141 / mechanism PASS. Default-flip pending.套內判定(2026-07-20)。每顆孤立 ROM 都不可判,但 frame 窗套內對照(NO_OAMEDGE_SHIM 關 M4_OE、其餘 baseline)在晚段 Address2004 / StaleSprite 防守題FAIL 三題($45B err10、$47B err2、$48F err2),而認證 141/141 過 —— 明確可判。M4_OE 機制取代得了(milestone:141/141)。三段論齊:base PASS / 對照 138/141 / 機制 PASS。待預設翻轉。
OpenBus (last byte)an open-bus read returns the last byte transferred on the pins, held by the external bus capacitanceopen-bus 讀取回傳接腳上最後傳輸的位元組,由外部匯流排電容保持M5e (chartered)(已立案)CEILING
for on-die mechanisms — M5e charters the board-net home對晶粒內機制而言 —— M5e 立案板網的家
◆ a special case — the last byte lives on an off-die board node, absent from the die geometry: a data gap, not a bug.特殊個案之一 — last byte 在晶粒外的板網節點、不在晶粒幾何裡:是資料缺口,不是 bug。
LXA magicthe $AB magic constant is a ratioed analog bus fight (AC vs data latch) → $FF on this silicon$AB magic 常數是比例式類比匯流排對抗(AC vs 資料閂鎖)→ 這批矽上是 $FFM1 · strengthRETIRED✓ default-flipped✓ 已翻轉
re-verified K=1 (2026-07-19): on 03-immediate base PASS / NO_LXA_SHIM control FAIL ("AB ATX") / M1_LXA mechanism PASS — the shim (an $AB LAE analog-merge force) is decidable on a fast isolated ROM, and the M1_LXA mechanism replaces it. Gate A golden unchanged; default-flip pending broad regression.K=1 重驗(2026-07-19):在 03-immediate 上 base PASS / NO_LXA_SHIM 對照 FAIL(「AB ATX」) / M1_LXA 機制 PASS —— 這顆 shim($AB LAE 類比合併強壓)在快速孤立 ROM 上可判,M1_LXA 機制取代得了它。Gate A 金不變;預設翻轉待廣回歸。
Dmc4015Aborta deferred $4015 disable aborts an in-flight DMC DMA (the kill signal travels a long internal path)延遲的 $4015 disable 中止進行中的 DMC DMA(kill 訊號走內部長路徑)P3 · M3_ABORTRETIRED✓ default-flipped✓ 已翻轉
now decidable in-suite (frame-windowed range-run to f1347): with NO_ABORT_SHIM the ExplicitDMAAbort + ImplicitDMAAbort sub-tests FAIL ($01→$0A, $09→$0A) — undecidable in isolation, load-bearing in-suite. Its M3_ABORT mechanism is built (promotes the shim); the control FAIL at f1347 is already recorded, and the in-suite 141 confirmation is running now (the all-mechanisms milestone at 689c8fd) with M3_ABORT armed — flips to PROVEN when that pass confirms the mechanism arm.現在套內可判(frame 窗 range-run 到 f1347):NO_ABORT_SHIM 時 ExplicitDMAAbort + ImplicitDMAAbort 兩題 FAIL($01→$0A、$09→$0A)—— 孤立不可判、套內承重。它的 M3_ABORT 機制已建(promote shim);f1347 的對照 FAIL 已記錄,套內 141 確認正在跑(全機制 milestone,689c8fd)M3_ABORT 已武裝 —— 該趟確認機制臂後翻 PROVEN。
FrameIrqa settle-internal pulse caught by an RS pair (latch race)settle 內脈衝被 RS 對咬(閂鎖賽跑)M4 · P6RETIRED✓ default-flipped✓ 已翻轉
re-verified K=1 (2026-07-19): on 3-irq_flag base PASS / NO_FRAMEIRQ_SHIM control FAIL (#6 "writing $00/$80 to $4017 shouldn't affect flag") / M4_FI mechanism PASS — the settle-internal frame-IRQ pulse is decidable on a fast isolated ROM, and the M4_FI mechanism replaces it. Gate A golden unchanged; default-flip pending broad regression.K=1 重驗(2026-07-19):在 3-irq_flag 上 base PASS / NO_FRAMEIRQ_SHIM 對照 FAIL(#6「寫 $00/$80 到 $4017 不該影響旗標」) / M4_FI 機制 PASS —— settle 內的 frame-IRQ 脈衝在快速孤立 ROM 上可判,M4_FI 機制取代得了它。Gate A 金不變;預設翻轉待廣回歸。
Dbl2007back-to-back $2007 reads inside the merge window collapse into one buffer advance合併窗內背靠背 $2007 雙讀塌成一次緩衝推進M4 · P1 · ClampBusRETIRED✓ default-flipped✓ 已翻轉
the hunt found a fast decidable defender (double_2007_read, seconds vs #67's ~2 h), so the mechanism could be built + verified cheaply: the M4·P1 ClampBus mechanism (env M4_P1) replaces the shim — base PASS / control FAIL (CRC 85CFD627 → D84F6815) / mechanism PASS with hc bit-identical to the shim (9,946,280). Gate A golden unchanged; OamDmaPpuBus folds into the same M4·P1 mechanism as a QueuedDrive row; default-flip pending broad regression.獵捕找到快速可判防守者(double_2007_read,秒級對比 #67 的 ~2h),所以機制能便宜地建 + 驗:M4·P1 ClampBus 機制(env M4_P1)取代 shim —— base PASS / 對照 FAIL(CRC 85CFD627 → D84F6815)/ 機制 PASS,hc 與 shim 逐位相同(9,946,280)。Gate A 金不變;OamDmaPpuBus 折進同一個 M4·P1 機制當 QueuedDrive 列;預設翻轉待廣回歸。
OamDmaPpuBus$4014 DMA writes to $2004 must hold the PPU I/O-bus data through OAM /WE$4014 DMA 寫 $2004 時 PPU I/O 匯流排資料須 hold 過 OAM /WEM4 · P1 · QueuedDriveRETIRED✓ default-flipped✓ 已翻轉
the M4·P1 QueuedDrive row (env M4_P1, sharing Dbl2007's ClampBus env) replaces the shim — #67 three-arm: base PASS / control FAIL (#67) / mechanism PASS with hc bit-identical to the shim (910,509,288). Gate A golden unchanged; default-flip pending broad regression.M4·P1 QueuedDrive 列(env M4_P1,與 Dbl2007 的 ClampBus 共 env)取代 shim —— #67 三臂:base PASS / 對照 FAIL(#67) / 機制 PASS,hc 與 shim 逐位相同(910,509,288)。Gate A 金不變;預設翻轉待廣回歸。
ALERead mux$2007 read access arrives one CPU cycle early vs the '373 latch capture window (a node-split phase mux, in-suite proven)$2007 讀取存取早一個 CPU cycle 於 '373 閂鎖捕捉窗(node-split 相位 mux,套內已證)M6 · node-splitCALIBRATED (own mechanism, live)(自有機制,已運作)
◆ a special case — mechanism built and in-suite proven; only the timing MUX_HC=13,13,25,44,52 is empirically calibrated (M3-anchorable, not yet derived).特殊個案之一 — 機制已建、套內已證;只有時序 MUX_HC=13,13,25,44,52 是經驗校準(M3 可錨定、尚未推導)。
PpuAleReadFeedbacka CHR-ROM read feeding back through the ALE path can re-trigger itself inside one settle (a P4 feedback loop); the guard breaks the cycleCHR-ROM 讀取經 ALE 路徑回授,可在一個 settle 內重新觸發自己(P4 回授環);guard 打斷這個環P4 · M4_P4RETIRED✓ default-flipped✓ 已翻轉
Resolved in-suite (2026-07-20) — the strongest form of decidable. The control (--no-ppu-ale-read-feedback-shim, else baseline) does not merely fail a sub-test: the engine hits non-convergence at ~f4350 (a "non-converging callback drain" — exactly the CHR-ROM feedback loop the guard exists to break). The shim is required to even simulate that sub-test. The M4·P4 mechanism (env PPU_ALE_FB, bit-identical) replaces it (milestone: 141/141). Three-arm: base PASS / control non-converges / mechanism PASS. Same inertial-delay family as DL — but removal hard-crashes here (strongly decidable) vs DL's converging glitch.套內判定(2026-07-20)—— 最強形式的可判。對照(--no-ppu-ale-read-feedback-shim、其餘 baseline)不只是某題 FAIL:引擎在 ~f4350 直接不收斂(「non-converging callback drain」—— 正是這 guard 要打斷的 CHR-ROM 回授環)。沒這顆 shim 連那顆子測試都模擬不了M4·P4 機制(env PPU_ALE_FB,逐位相同)取代得了(milestone:141/141)。三段論:base PASS / 對照不收斂 / 機制 PASS。與 DL 同 inertial-delay 家族 —— 但拔掉這顆硬崩(強決定),DL 則是收斂的 glitch。
PowerUpState · reset-holdpower-on register / palette state and CPU/PPU divider phase (the boot lottery, 4 alignments)上電暫存器 / palette 初態與 CPU/PPU 除頻相位(開機抽籤,4 種對齊)M6 · phase selectorINTRINSIC
◆ a special case — not a function of the netlist (an initial condition / external stimulus); M7 makes the boot deterministic but can't compute the values.特殊個案之一 — 不是網表的函數(初始條件/外部激勵);M7 讓開機決定論化,但算不出值。
Why one shim is a permanent ceiling. OpenBus's last byte is not an on-die node at all — it is the charge held by the package and board bus capacitance between the pins. No mechanism that lives inside the two dies (charge arbitration M2, latch verdicts M4, delay M3) can reach it, and the experiment confirms it: the full M4 mechanism stack with the behavioral replay removed still fails, and M2 arbitration failed the same test earlier. This byte belongs to a board-level bus model (M5's territory / an L3 data layer). Keeping the shim here is not a defeat — it is the correct boundary between what the silicon graph knows and what only the board does. See the glitch-immunity study for the full experiment. 為什麼有一個 shim 是永久天花板。OpenBus 的 last byte 根本不是晶粒內的節點 —— 它是接腳之間封裝與主機板匯流排電容保持的電荷。任何活在兩顆晶粒內部的機制(電荷裁決 M2、閂鎖判決 M4、延遲 M3)都碰不到它,而實驗證實了:M4 全機制堆疊去掉行為重播仍失敗,M2 裁決也敗在同一測試。這個位元組屬於板級匯流排模型(M5 的地盤 / L3 資料層)。這裡留住 shim 不是失敗 —— 它是「矽電路圖知道的」與「只有主機板知道的」之間正確的邊界。完整實驗見毛刺免疫研究
Why some shims are "undecidable", not failures. DL, OamBlankEdge, and dot-339 each have a working mechanism (M4 transparent / M4 hold / M6×M3), and each is bit-safe — every mechanism-on run passes and the neighbours don't regress. But on every isolated ROM tried, the control (shim removed) also passes, because these shims defend scenarios that only arise mid-suite — so there is no test that fails without the shim, and the isolated protocol cannot judge them. Yet "undecidable" can be an artifact of testing the wrong ROM: even_odd already crossed to PROVEN at the K=1 re-check (its control FAILs on 10-even_odd_timing), and a discriminating-ROM hunt (2026-07-19) crossed two more — BGSerialIn to PROVEN (control FAIL on AccuracyCoin_BGSerialInReal, M6×M3 replaces it) and Dbl2007 to PROVEN (control fails on double_2007_read — seconds, vs the ~2 h #67 — and the M4·P1 ClampBus mechanism now replaces it hc-identical). The three named above survived that hunt, so they needed in-suite evidence over the full 141-test suite — which has now run (2026-07-20): the all-mechanisms milestone (689c8fd) passes 141/141, and frame-windowed in-suite controls crossed dot-339 and OamBlankEdge to PROVEN (their controls fail at the late StaleSprite / Address2004 defenders — 140/141 and 138/141 — that the certified baseline passes). Only DL now remains beyond the isolated protocol, and it is deferred by choice (a localized inertial-delay settle guard; the general fix is architectural), not by failure. Honest status beats a fabricated retirement. 為什麼有些 shim 是「不可判」而非失敗。DL、OamBlankEdge、dot-339 各自都有能動的機制(M4 transparent / M4 hold / M6×M3),而且都是 bit-safe —— 每個機制開的跑法都過、鄰居也不退步。但在試過的每一顆孤立 ROM,對照組(拔掉 shim)通過,因為這些 shim 防守的場景只在套內出現 —— 沒有會因拔 shim 而失敗的測試,孤立協定就判不了它們。然而「不可判」可能是測錯 ROM 的假象:even_odd 已在 K=1 重確認時跨到 PROVEN(它的對照在 10-even_odd_timing 會 FAIL),而一輪鑑別 ROM 獵捕(2026-07-19)又跨掉兩顆 —— BGSerialIn 到 PROVEN(對照在 AccuracyCoin_BGSerialInReal FAIL、M6×M3 取代)、Dbl2007 到 PROVEN(對照在 double_2007_read 上失敗 —— 秒級,對比 #67 的 ~2h —— 而 M4·P1 ClampBus 機制現在 hc 逐位相同地取代它)。上面點名的三顆撐過了獵捕,所以需要套內、跑滿 141 顆的證據 —— 而現在已經跑完(2026-07-20):全機制 milestone(689c8fd)過 141/141,而 frame 窗套內對照把 dot-339 與 OamBlankEdge 跨到 PROVEN(它們的對照在晚段 StaleSprite / Address2004 防守題失敗 —— 140/141 與 138/141 —— 而認證 baseline 過)。現在只剩 DL 在孤立協定之外,而它是刻意延後(局部 inertial-delay settle guard;通式修法架構級)、不是失敗。誠實的狀態勝過捏造的退役。

→ The full methodology, with the control-arm data re-verified at K=1 — including how even_odd crossed from "spectator" to decidable/PROVEN when the boot alignment was fixed: The decidability boundary — when can you retire a shim by testing it alone?→ 完整方法論,對照臂資料已在 K=1 下重驗 —— 含 even_odd 在修正開機對齊後如何從「旁觀者」跨進可判/PROVEN:可判定性的邊界 —— 什麼時候你能靠單獨測試退役一個 shim?

Beyond the toolbox工具箱之外Four cases structure and physics can't cleanly reduce結構與物理化約不了的四個個案

The S1a toolbox reduces most shims the same way: read the topology (M4 latches, M6 phase), compute a physical parameter (M1 strength, M2 capacitance, M3 delay), and a principled mechanism replaces the override. Four cases escape that pipeline — each for a different reason, and naming the reason precisely is itself the result. They line up as a spectrum, from fundamentally uncomputable to essentially solved with one knob left.

S1a 工具箱化約大部分 shim 的方式都一樣:讀拓撲(M4 閂鎖、M6 相位)、算一個物理參數(M1 強度、M2 電容、M3 延遲),有原理的機制就取代覆蓋。有四個個案躲掉這條流水線 —— 各自理由不同,而把理由講精確本身就是結果。它們排成一道光譜,從「本質算不出」到「基本解決、只剩一個旋鈕」。

PowerUpState · reset-hold  not a function of the netlist不是網表的函數

A node's power-up value depends on threshold mismatch, parasitic capacitance and the supply ramp — analog and manufacturing-variable. Structure can't give it; physical params give only relative strengths, not the random settling. The real chip itself powers up differently each time (hence the inherently-indeterminate power_up_palette test), and reset-hold is the board's external RESET timing, not a chip-internal property. M7 makes the boot deterministic (it ends the ordering lottery) but does not compute the values — these are an initial condition / external stimulus. The reachable part (2026-07-20 consult): the CPU/PPU divider phase is a verifiable coin-flip — trace the reset pad's fan-out and no gate path reaches the clock-divider latches, so the alignment is simply whatever it powered up as; and a Monte-Carlo initialization (randomize the symmetric cross-coupled loops, settle to quiescence) bounds the physically-reachable power-up set — moving it from "assumed" to "characterized".

節點的開機值取決於閾值失配、寄生電容、電源上升 —— 類比且製程變異。結構給不出;物理參數只給相對強弱、不給隨機沉澱。真晶片自己每次開機都不同(所以有本質不定的 power_up_palette 測試),而 reset-hold 是板子的外部 RESET 時序、不是晶片內部性質。M7 讓開機決定論化(終結排序抽籤)但不算出值 —— 這是初始條件/外部激勵。可達的部分(2026-07-20 諮詢):CPU/PPU divider 相位是可驗證的 coin-flip —— trace reset pad 的 fan-out,沒有閘路徑到 clock-divider latch,所以相位就是開機當下的樣子;而 Monte-Carlo 初始化(把對稱交叉耦合環隨機灌值、settle 到 quiescent)可界定物理可達的開機態集合 —— 把它從「假設」升成「界定」。

OpenBus (last byte)  off-die — a data gap晶粒外 —— 資料缺口

The last byte is held by the parasitic capacitance of the package + board data bus — a node on neither die, absent from our segdefs geometry. Every on-die mechanism (M2 charge, the full M4 latch stack, M3 delay) was tried and failed to reach it. The physical quantity is real but lives outside the netlists we have; it belongs to a board-level bus model (M5e's charter). A documented ceiling — the correct boundary between what the silicon graph knows and what only the board does. Yet the decay is grounded (2026-07-20 consult): a first-principles estimate — C ≈ 20 pF (die pad + DIP40 lead + PCB trace + cart edge + ROM input) discharging through ~100 pA of reverse leakage, C·ΔV/I ≈ 700 ms — lands almost exactly on the empirical ~600 ms M2 decay, confirming behavioral replay as the right abstraction, not a fudge.

last byte 由封裝 + 板子資料匯流排的寄生電容保持 —— 一個不在任何一顆晶粒、我們 segdefs 幾何裡沒有的節點。每個晶粒內機制(M2 電荷、M4 閂鎖全堆疊、M3 延遲)都試過、都碰不到。物理量真實存在,但在我們手上的網表之外;它屬於板級匯流排模型(M5e 立案)。是記錄在案的天花板 —— 「矽電路圖知道的」與「只有主機板知道的」之間正確的邊界。但衰減是有依據的(2026-07-20 諮詢):第一性原理估算 —— C ≈ 20pF(die pad + DIP40 lead + PCB 走線 + 卡帶邊 + ROM 輸入)經 ~100pA 反向漏電放電,C·ΔV/I ≈ 700ms —— 幾乎正中經驗的 ~600ms M2 衰減,證明 behavioral replay 是對的抽象、不是唬弄。

DL (input data latch)  mechanizable, but architectural可機制化,但架構級

DL's glitch is not a property of the chip — the real latch's analog inertia has no glitch. It is a discrete-settle artifact (a node-id ordering lottery, same family as DMC/LAE). Structure does see it (M4 classifies idl as transparent) and physics says the chip is correct; the fix is to stop the simulation producing the artifact — and it has a name (2026-07-20 consult): inertial-delay filtering. The sound general form is a two-phase / delta-cycle settle: evaluate a wave, commit repeatedly to quiescence, then let the latch see its input. That changes the core solver semantics, so it is a hot-path performance and S1A trace/checksum re-baselining project. The cheap localized form is a settle guard — defer just that latch until its input group is stable — which is exactly what the current shim approximates, so it is a standard event-sim technique, not an ad-hoc patch. M7 is complementary, not an alternative: it removes arbitrary id-order variance, but cannot supply inertia or establish which deterministic result matches silicon. Strength-prioritized contention (M1) may even dissolve the transient at the root. It stays a scoped shim as a cost decision, pending the general guard. Not a wall — a bill.

DL 的毛刺不是晶片的性質 —— 真閂鎖的類比慣性沒有毛刺。它是離散 settle 的假象(node-id 排序抽籤,跟 DMC/LAE 同家族)。結構看得到(M4 把 idl 分類成 transparent)、物理上晶片是對的;修法是讓模擬別產生這個假象 —— 而它有個正式名字(2026-07-20 諮詢):inertial-delay filtering(慣性延遲濾波)。可靠的通式是兩階段 / delta-cycle settle:先 evaluate 一波、反覆 commit 到 quiescent,讓閂鎖看見輸入。這會改核心 solver 語意,因此是熱路徑效能與 S1A trace/checksum 重定基準工程。便宜的局部版是 settle guard —— 只把那顆 latch 延到它的輸入群穩定才取值 —— 這正是現行 shim 在做的,所以它是標準事件模擬技術、不是臨時補丁M7 是互補項,不是替代方案:它移除任意的 id-order 差異,但不能提供慣性,也不能判定哪個固定結果符合硬體。按驅動強度優先的 contention(M1)甚至可能從根拔掉暫態。目前先當 scoped shim,是成本判斷,等通式 guard。不是牆,是帳單。

ALERead mux  computation-guided calibration計算引導的校準

Here the structure is fully present — the 74LS373 octal latch is real switch-level (M5, 82 transistors), the AD-bus node-split is principled. Only the phase timing MUX_HC=13,13,25,44,52 is empirically calibrated. Elmore delay (M3, composed with the '373 in M5) can validate and anchor those five values — as it did for dot-339 ("0.45% of nets can do 16/18") — but the sharper result is a decomposition (worked example below): only two of the five are physical, one is the phase error itself, and two are architectural — so it is far less "calibrated" than it looks. Required for 141/141; kept opt-in (ALEREAD_MUX) because the node-split is a load-time graph change. The least special of the four — essentially solved, one calibration left to derive rather than tune.

這裡結構完全在 —— 74LS373 八位元閂鎖是真開關級(M5,82 顆電晶體)、AD 匯流排 node-split 有原理。只有相位時序 MUX_HC=13,13,25,44,52 是經驗校準。Elmore 延遲(M3,與 M5 的 '373 合成)能驗證與錨定那 5 個值 —— 就像 dot-339(「0.45% 的 net 做得到 16/18」)—— 把 5 個自由旋鈕壓成 M3 預測的比例 + 一個 scale,但釘不死精確 hc(Elmore ±幾十 %,而 mux 窗是引擎對淨延遲的抽象)。它是 141/141 的必需品;保持 opt-in(ALEREAD_MUX)因為 node-split 是載入期改圖。四個裡最不特殊的 —— 基本解決,只剩一個校準待「從調變成算」。

The spectrum. PowerUpState is out of reach in principle; OpenBus is out of reach for lack of board-level data; DL is reachable but architecturally expensive; ALERead mux is reached, pending only that its timing be derived rather than tuned. Four different walls — and three of them are honest boundaries, not bugs.這道光譜。PowerUpState 原則上算不到;OpenBus 因缺板級資料而算不到;DL 到得了但架構級的貴;ALERead mux 已到得了,只差把時序從「調」變成「算」。四面不同的牆 —— 其中三面是誠實的邊界,不是 bug。

Worked example — decomposing MUX_HC (verified 2026-07-20)實作範例 —— 拆解 MUX_HC(2026-07-20 驗證)

Are the five tuned constants really irreducible? We checked. First, the engine's half-cycle is pinned from our own run data: a control run logged hc = 1,715,304,000 at simulated second 39.93 → 42.96 MHz = exactly 2× the NTSC master clock, so 1 hc = 23.28 ns (half a master cycle; 1 PPU dot = 8 hc, 1 CPU cycle = 24 hc = 3 dots). With that, the five values stop looking arbitrary:

那五個手調常數真的化約不了嗎?我們查了。先把引擎的半週期從我們自己的 run 資料釘死:一個對照 run 記錄到模擬第 39.93 秒時 hc = 1,715,304,00042.96 MHz = 恰好 2× NTSC master clock,所以 1 hc = 23.28 ns(半個 master;1 PPU dot = 8 hc,1 CPU cycle = 24 hc = 3 dots)。有了它,那五個值就不再任意:

hcnsCPU-cycdotswhat it is它是什麼
133030.541.6physical — AD-bus rising edge: a weak depletion pull-up driving ~20 pF of package + board capacitance物理 —— AD 匯流排上升沿:弱 depletion 上拉驅動 ~20pF 封裝+板電容
133030.541.6— the second settle window, same scale—— 第二個 settle 窗,同尺度
255821.043.1the phase error itself — 1 CPU cycle = 3 dots; this is the "$2007 read arrives one CPU cycle early" that the mux corrects, not a delay相位誤差本身 —— 1 CPU cycle = 3 dots;這就是 mux 要修的「$2007 讀取早一個 CPU cycle」,不是延遲
4410241.835.5architectural — a swallow/replay scheduling window, µs-scale, far too large for any net delay架構級 —— swallow/replay 排程窗,µs 級,遠大於任何淨延遲
5212102.176.5— the second scheduling window extent—— 第二個排程窗範圍

The physics checks out: a weak depletion pull-up (~30 kΩ) into 20 pF crosses the 2.0 V input threshold in 306 ns = 13.2 hc — the 13's are the real AD-bus rising settle (the falling edge, through a strong pull-down, is 18 ns = 0.8 hc, far too fast to be a knob). The 25 is not a delay at all — it is the documented 1-CPU-cycle / 3-dot scheduling misalignment, the very error the mux exists to correct. Only 44 and 52 are genuinely tuned: swallow/replay window extents at the µs scale, expressible as offsets from the phase error rather than derived from RC. So five hand-tuned knobs reduce to two computed-physics values, one known phase constant, and two architectural window extents — not irreducible after all.

物理對得上:弱 depletion 上拉(~30kΩ)驅動 20pF 在 306ns = 13.2 hc 穿越 2.0V 輸入閾值 —— 那兩個 13 就是 AD 匯流排真正的上升 settle(下降沿走強下拉是 18ns = 0.8 hc,快到不可能當旋鈕)。25 根本不是延遲 —— 它是有文件記載的 1 CPU cycle / 3 dot 排程錯位,正是 mux 存在要修的那個誤差。只有 44 和 52 是真的靠調:swallow/replay 窗的範圍,µs 尺度,可表示為相位誤差的 offset 而非 RC 推導。所以五個手調旋鈕化約成 兩個計算物理值、一個已知相位常數、兩個架構窗範圍 —— 終究不是不可約。

Method refined via a mixed-signal timing-expert consult (Gemini, 2026-07-20) and verified against our own run data; full transcript in MD/suggest/2026-07-20-gemini-m3-mux-hc. To fully derive rather than tune, the next step is a boundary micro-SPICE of the PPU AD pad → 20 pF board → '373 → CPU receiver, quantized to hc. Full deep dive with the worked arithmetic and diagrams.方法經混合訊號時序專家諮詢(Gemini,2026-07-20)精煉、並對我們自己的 run 資料驗證;全文見 MD/suggest/2026-07-20-gemini-m3-mux-hc。要完全推導(而非調),下一步是 PPU AD pad → 20pF 板 → '373 → CPU receiver 的 boundary micro-SPICE,量化成 hc。完整深入專文,含逐步算式與圖

Deep dives深入專文One issue, taken all the way down一個 issue,一路挖到底

Some issues earn a full worked-through article — the physics from scratch, every arithmetic step, with diagrams — not a single table row. This is where they live.

有些 issue 值得一篇完整推導的專文 —— 從頭的物理、每一步算式、附圖 —— 而不是一列表格。它們放在這裡。

#1 · The ALERead mux — where does MUX_HC = 13,13,25,44,52 come from?ALERead mux —— MUX_HC = 13,13,25,44,52 從哪來?  2026-07-20

Five hand-tuned constants, reconstructed from first principles: the engine's half-cycle verified as 23.28 ns from its own run log; the 13 computed as a 306 ns RC rising-edge settle (weak depletion pull-up into ~20 pF); the 25 shown to be the 1-CPU-cycle / 3-dot phase error itself; the 44/52 pinned as architectural windows. Four of the five stop being magic numbers. With SVG timing + RC diagrams and every step of the arithmetic.五個手調常數,從第一性原理重建:引擎的半週期從自身 run log 驗證為 23.28 ns;13 算成 306 ns 的 RC 上升沿 settle(弱 depletion 上拉驅 ~20pF);25 證明是 1-CPU-cycle / 3-dot 相位誤差本身;44/52 釘成架構窗。五個裡四個不再是魔術數字。附 SVG 時序 + RC 圖與每一步算式。

#2 · Open bus — the capacitor nobody placedOpen bus —— 沒有人放的電容  CEILING 2026-07-20

The last byte, held on a board node that is on neither die, slowly leaking to 0 over ~600 ms. Derives the decay from first principles and shows it is linear, not RC exponential (constant-current junction leakage: t = C·ΔV / I → ~30 M hc); explains why the byte rots bit-by-bit (the per-line waterfall); gives the full lazy-timestamp implementation and refresh rule; and lays out the path from tuned to computed — with an honest floor (leakage is exponentially temperature-dependent, so there is no single true threshold). SVG diagrams of the off-die node and the per-bit decay.最後那個位元組,保持在一個不在任何一顆晶粒的板子節點上,~600ms 內緩慢漏到 0。從第一性原理推導衰減、證明它是線性、非 RC 指數(定電流 junction 漏電:t = C·ΔV / I → ~30M hc);解釋為什麼位元組一位一位地爛(逐線瀑布);給出完整懶惰時戳實作與 refresh 規則;鋪陳從調到算的路 —— 附誠實地板(漏電溫度指數相關,所以沒有單一真閾值)。附晶粒外節點與逐位元衰減的 SVG 圖。

#3 · Can the NES tell you the room temperature?NES 能告訴你室溫嗎?  SENSOR 2026-07-20

The open-bus decay from #2, run backwards: write a byte, time how long it survives, read the temperature off the decay clock — 7.2 % per °C, huge for a sensor. Covers the one non-obvious trick (you cannot poll a CPU-bus address — instruction fetches refresh it; you must read the PPU internal latch through $2002's low 5 bits); one-point calibration (the Ea slope is a law of physics, only the offset is per-console); and the fatal flaw — the PPU cooks itself +30–40 °C, so it's a die thermometer, and only a cold-boot read in the first few seconds gives the room. With the 6502 log₂ ROM, the DRAM/cold-boot-attack prior art, and an inverse calculator: feed it a decay time, it reads back the temperature.把 #2 的 open-bus 衰減倒著跑:寫一個位元組、量它活多久、從衰減時鐘讀出溫度 —— 每 °C 差 7.2%,對感測器來說很大。涵蓋那個不明顯的訣竅(你不能輪詢 CPU 匯流排位址 —— 指令抓取會刷新它;必須透過 $2002 低 5 位讀 PPU 內部閂鎖);一點校準(Ea 斜率是物理定律,只有 offset 逐台不同);以及致命缺陷 —— PPU 把自己煮熱 +30–40 °C,所以它是晶粒溫度計,只有冷開機最初幾秒的讀值才是室溫。附 6502 log₂ ROM、DRAM/cold-boot-attack 前例,和一個反向計算器:餵它衰減時間,它讀回溫度。

#4 · Running the thermometer — the AprNes tool + test ROM把溫度計跑起來 —— AprNes 工具 + test ROM  BUILT & RUN 2026-07-20

#3 on paper; this one builds it. We gave our fast reference emulator (AprNes) the open-bus decay model with a real temperature knob (--openbus-temp <°C> + --dump-mem), wrote a stock NROM test ROM that primes the PPU latch, tight-polls $2002, counts the decay, and prints 25.0 DEGREE CELSIUS — with the count→°C inversion done with no 6502 multiply/divide/float (a precomputed 0.1 °C lookup table + a 9-step power-of-two binary search + subtraction BCD, per a Gemini consult). Real frame captures at 0/25/50 °C, the round-trip table (exact 0–40 °C), and an honest limits section: warm-end resolution is measurement-limited (43 & 44 °C both read 43.5), range clamps, per-model calibration, die-vs-room. A technical validation, not a precision instrument.#3 在紙上;這篇把它做出來。我們給快速參考模擬器(AprNes)裝上 open-bus 衰減模型與真的溫度旋鈕(--openbus-temp <°C> + --dump-mem),寫了一顆原廠 NROM test ROM:給 PPU 閂鎖充電、緊輪詢 $2002、數衰減、印出 25.0 DEGREE CELSIUS —— 而 count→°C 反推完全不用 6502 乘除法/浮點(預算 0.1 °C 查表 + 9 步 2 冪次二分搜 + 連減 BCD,依 Gemini 諮詢)。附 0/25/50 °C 真實幀截圖、round-trip 表(0–40 °C 精確)、以及誠實極限:暖端解析度受量測限制(43、44 °C 都讀 43.5)、範圍 clamp、逐模型校準、晶粒 vs 室溫。技術驗證,非精密儀器。

#5 · The last mile — 2C02 pixel to picture最後一哩 —— 2C02 像素到畫面  ROADMAP 2026-07-20

A roadmap (not yet built): our switch-level 2C02 stops at palette indices, but a real NES emits an analog composite waveform a 1990 TV turns into a fuzzy, dot-crawling picture. Maps the whole missing stretch — the on-die resistor-ladder video DAC (no R-2R; Pin 21), the 12-phase encoding (6× colourburst, so dot crawl is automatic), emphasis-as-pull-down, the board amp (Q1 2SA937 + Q2 2SC2021), the composite waveform with lidnariq's measured voltages, and the TV decode chain (sync-sep LM1881 · Y/C · burst-PLL demod · YIQ→RGB). Key gotcha: the 2C02 shifts phase 120°/line, so a standard comb filter FAILS — you must use a notch. Lays out doing it ourselves: tap the DAC control nodes, a 21.477 MHz lookup sidecar, and our own NTSC decoder (no borrowed libraries) with a staged MVP. Two hardware-engineer consults; honest that it's a presentation layer, not built.路線圖(還沒做):我們的開關級 2C02 停在調色盤索引,但真 NES 輸出類比 composite 波形、由 1990 年電視變成模糊、點狀蠕動的畫面。標出整段缺的路 —— 晶片內電阻梯視訊 DAC(非 R-2R;Pin 21)、12 相位編碼(colourburst 6 倍,所以 dot crawl 自動產生)、emphasis 即下拉、主機板放大器(Q1 2SA937 + Q2 2SC2021)、含 lidnariq 量測電壓的 composite 波形、以及電視解碼鏈(sync-sep LM1881 · Y/C · burst-PLL 解調 · YIQ→RGB)。關鍵陷阱:2C02 每行偏 120°,標準 comb filter 會壞 —— 必須用 notch。鋪陳自己做:接出 DAC 控制節點、21.477MHz 查表 sidecar、以及自己寫的 NTSC 解碼器(不借用函式庫)+ 分階段 MVP。兩次硬體諮詢;誠實標明它是呈現層、還沒實作。

#6 · The other last mile — channel values to sound另一條最後一哩 —— 聲道值到聲音  ROADMAP 2026-07-20

The audio counterpart to #5 (also a roadmap): our switch-level 2A03 stops at five channel values, but a real NES drains current from two open-drain pins, mixes them through a famously non-linear network, and abuses a 74HCU04 logic inverter as an op-amp to make line-level sound. Maps the whole chain — the on-die non-linear DAC (Blargg's pulse/TND formulas, and why it compresses: paralleled NMOS-to-ground switches in a divider with the 100 Ω pull-ups), the board mix (20 k / 12 k / 1 µF / 74HCU04), the filters (90 / 440 Hz HPF · 14 kHz LPF), cartridge expansion audio, and AV-vs-RF. Lays out doing the DSP ourselves (no Nes_Snd_Emu, no Mesen copy): tap the DAC gate nodes, a 1.789 MHz sidecar, first-order IIRs, and our own band-limited polyphase decimator to 48 kHz (never decimate a square wave raw). Two SVGs (the chain + the non-linear mix curve); honest that it's a not-yet-built presentation layer.#5 的音訊對應(一樣是路線圖):我們的開關級 2A03 停在五個聲道值,但真 NES 從兩支開漏極腳吸電流、經一個著名的非線性網路混音、再把一顆 74HCU04 邏輯反相器當 op-amp 逼出 line-level 聲音。標出整條鏈 —— 晶片內非線性 DAC(Blargg 的 pulse/TND 公式,以及為什麼會壓縮:並聯對地 NMOS 開關 + 100Ω 上拉的分壓)、主機板混音(20k / 12k / 1µF / 74HCU04)、濾波器(90 / 440Hz 高通 · 14kHz 低通)、卡帶擴充音訊、AV vs RF。鋪陳自己寫 DSP(不用 Nes_Snd_Emu、不抄 Mesen):接出 DAC 閘極節點、1.789MHz sidecar、一階 IIR、以及自己寫的帶限 polyphase decimator 到 48kHz(方波絕不能生抽)。兩張 SVG(鏈 + 非線性混音曲線);誠實標明是還沒做的呈現層。

The other half另一半Built in public, taught as it goes公開地蓋,邊蓋邊教

S1a develops on two legs. One is engineering: the fork, the mechanisms, the regressions. The other is education: this site will accumulate technical and semi-academic articles that document the process honestly — the physics primers, the dead ends, the falsified hypotheses, the measurements with error bars. The campaign already showed the format works: a negative result rigorously written up (the last test) later produced its own refutation (breaking the ceiling) — and both articles stayed up, because the correction is the lesson.

S1a 用兩條腿走路。一條是工程:分支、機制、回歸。另一條是教育:這個站會累積技術與半學術性的專文,誠實記錄過程 —— 物理入門、死路、被證偽的假設、帶誤差棒的量測。戰役已經證明這個format行得通:一個嚴謹寫下的負面結果(《最後一顆》)後來生出了它自己的反駁(《打破天花板》)—— 而兩篇都留在站上,因為更正就是那堂課。

Planned write-ups (the working queue): the 16/18 rise-fall parity audit (a falsifiable prediction from the geometry consult); building the per-net Elmore binner and what the die's histogram looks like; auto-detecting every transparent latch on two dies; how a ratioed NMOS fight actually resolves; the board as a circuit; and a running lab-notebook series as each mechanism lands.

已排隊的專文(工作佇列):16/18 rise-fall 奇偶稽核(幾何諮詢給出的可證偽預言);打造 per-net Elmore 分級器、看看晶粒的直方圖長什麼樣;自動偵測兩顆晶粒上的每一個透明閂鎖;比例式 NMOS 對抗實際怎麼分勝負;把主機板當電路;以及每個機制落地時的實驗筆記系列。

Foundations考古文庫The investigations that created S1a催生 S1a 的那些調查

S1a was not designed on a whiteboard — it condensed out of casework. These five articles (on the main site) are the archaeology: each documents a real investigation that hit the netlist's boundary, and together they define the gap this fork studies.

S1a 不是在白板上設計出來的 —— 它是從一件件案子裡凝結出來的。這五篇(在主站上)就是考古紀錄:每篇都是一場撞上網表邊界的真實調查,合起來定義了這個分支要研究的那道縫。

Also essential context: the AccuracyCoin report (the thirteen-chapter war record, 141/141) and the 147-ROM report card — the measuring sticks every S1a mechanism must keep satisfying.

同樣是必要脈絡:AccuracyCoin 報告(十三章戰記,141/141)與 147 顆成績單 —— 每個 S1a 機制都必須持續滿足的量尺。

Where we are走到哪了Status & roadmap現況與路線

Design documents (Traditional Chinese) live in the repo: MD/S1a/00 (master plan, M1–M7) and MD/S1a/01 (timing-annotated netlist, detection patterns, geometry priors).設計文件(繁中)在 repo:MD/S1a/00(總綱,M1–M7)與 MD/S1a/01(時序標註網表、偵測 pattern、幾何先驗)。