What it shows
A printing check that holds for each tile on its own does not automatically hold for the region: light from one tile spills into its neighbours. A combined check has to account for that spill, and say how large it may be.
The record states the result this way:
The published record says, word for word (an excerpt)
Per-tile certificates compose into a regional certificate with an explicit bounded cross-tile optical coupling residual, with 0 soundness violations over 18,432 checks.
In plain words: the per-tile checks are combined into one check for the region, with a stated allowance for the spill between tiles. Over 18,432 test comparisons, the combined check recorded no soundness violation, 0 violations. A larger region is then covered by checking more tiles, not by a larger simulation, as long as the spill stays within the stated allowance.
Why it matters
Printing checks with a guarantee are useful only if they reach the size of a real layout. Combining small checks with a stated allowance for their interaction is one way to get there without a simulation of the whole region at once.
What is ours, and what is not
Solving a large problem in pieces and accounting for the interaction between them is a standard idea (see the prior art below). What is ours is this combination of per-tile printing checks, the Lean-checked combining step, and the measured spill allowance.
Who should care
- Lithography and mask-verification teams who need checks that scale to large regions.
- Reviewers. The allowance for spill between tiles is measured, not proved, and the page says so.
The limits, in the record’s words
The published record says, word for word (an excerpt)
Finite battery. The composition lemma is kernel-checked in Lean (GateCore.regionSafe_all) but the optical coupling bound it consumes is measured, not proven. Simulator-relative.
The published record says, word for word (an excerpt)
Certified area grows by proof rather than by a bigger imager, under the stated coupling bound and at the stated grid. The epsilon ladder is measured, not assumed.
In plain words: the combining step is proved, but the allowance for spill between tiles is measured, so the combined check is only as good as that measurement. The test comparisons are a finite set, and everything is relative to our own printing simulator at its stated grid, not to a printed wafer.
Open source for this step
Tools and datasets we publish for the print step of building a multi-chip package. They are the checkers around this work, not a copy of the result itself.
- cert-atlas: A labelled set of forged lithography certificates, scored on wrong accepts and wrong rejects alike, so a checker that accepts everything or rejects everything cannot score well.
- lcert-verify: A checker for our lithography certificates that needs only Python's standard library.
- lcert-verify-web: The same verifier in the browser: zero dependencies, nothing uploaded.
- equiv-receipt: A small file that records why two versions of a circuit compute the same thing, which anyone can re-check without our tools.
- prereg (pre-registration primitive): Write your acceptance criteria down, hash them, then measure — a tiny pre-registration primitive.
- certified-mcp: Lets an AI agent ask our certificate checker for a yes-or-no answer, instead of judging a certificate itself.
- lcert-build: Builds a certificate bundle from your own analysis results, so anyone can re-check the verdict; it computes nothing itself.
- certified-kit: One install and one command for the whole certificate-checking toolkit.
- certified-oss: The map of the certificate tools: a recorded verdict is a claim to be checked, never an input to be trusted.
- cert-verifier: Drop a lithography certificate bundle and verify it in your browser.