What it shows
A confidential exchange is only as private as every file it publishes. A design value can leak through a field name, a log line or a rounding, not only through the answer.
The record states the result this way:
The published record says, word for word (an excerpt)
Two organisations reach a joint engineering decision without either handing over the input that answers it, and the leak sweep took 13 of 39 private scalars in the committed artifact down to 0.
In plain words: in the committed files of the exchange, 13 of 39 private values were found leaking, and after the fixes 0 were. A sweep of 19 planted faults was each caught by the check aimed at it.
Why it matters
Companies that design packages together often cannot share their designs. A joint check that keeps each input private, and that has been swept for leaks with the results published, is a starting point for that kind of work.
What is ours, and what is not
Commitments and joint computation over private inputs are established ideas (see the prior art below). What is ours is this exchange for a packaging decision, and the leak sweep with its results.
Who should care
- Package and chip teams who need a joint check without sharing designs.
- Reviewers. The record states the leaks it found, and that a lossy encoding still defeats every scan.
The limits, in the record’s words
The published record says, word for word (an excerpt)
Commitment-based signoff, explicitly NOT zero-knowledge — the name is honest. Status is in-progress, not done.
The published record says, word for word (an excerpt)
A lossy 4-significant-figure encoding defeats every scan, disclosed.
In plain words: this is not zero-knowledge, it is work in progress, and a value encoded lossily, to a few significant figures, gets past every scan the sweep runs. The leak counts are for the committed files of this exchange, not a guarantee about any other.
Open source for this step
Tools and datasets we publish for the package step of building a multi-chip package. They are the checkers around this work, not a copy of the result itself.
- physics-lint: One command that checks a folder of physics models against a fixed set of named physical rules, with findings straight into CI.
- maxwell-lint: Flags a coupling extractor whose answers no passive set of conductors could produce.
- sparam-lint: Is your signal-response model physically possible? Five physical laws checked from the command line.
- interval-core: The interval arithmetic core behind our proofs over whole families of layouts.
- touchstone-tools: Read, write and convert Touchstone files, the standard text files that record how signals pass through a package's connections, and refuse to write one that cannot be read back.
- physics-lint-mcp: The physics checks, callable by an AI agent.
- physics-lint-action: A GitHub Action that fails the build when a model breaks one of a fixed set of named physical rules.
- Signal-response validity corpus: A labelled corpus of physically invalid signal-response networks, and a scorer that grades any checker against it.
- screening-ceiling: The screening-ceiling family as an open dataset.