Machine-generated from validation/manifest.yaml. CI regenerates this on every run (--check) and fails if a peripheral model changed after a board's last silicon capture without a dated drift_ack (--drift). Tiers: 🟢 silicon · 🟡 manual-smoke · ⚪ structural.
| Board | Tier | Last silicon capture | Newest model | Status |
|---|---|---|---|---|
nrf52840 |
🟢 silicon-verified | 2026-06-17 | 2026-07-27 | ⚠ drift acked 2026-07-27 (re-capture pending) |
seeed-xiao-nrf52840-sense |
🟢 silicon-verified | 2026-06-17 | 2026-07-27 | ⚠ drift acked 2026-07-27 (re-capture pending) |
stm32h563 |
🟢 silicon-verified | 2026-06-22 | 2026-07-28 | ⚠ drift acked 2026-07-28 (re-capture pending) |
esp32c3 |
🟢 silicon-verified | 2026-06-17 | 2026-07-28 | ⚠ drift acked 2026-07-28 (re-capture pending) |
nucleo-l476rg |
🟢 silicon-verified | 2026-06-20 | 2026-07-28 | ⚠ drift acked 2026-07-28 (re-capture pending) |
nucleo-l073rz |
🟢 silicon-verified | 2026-06-20 | 2026-07-28 | ⚠ drift acked 2026-07-28 (re-capture pending) |
stm32f103 |
🟢 silicon-verified | 2026-06-20 | 2026-07-28 | ⚠ drift acked 2026-07-28 (re-capture pending) |
stm32f407 |
🟢 silicon-smoke | 2026-06-20 | 2026-07-28 | ⚠ drift acked 2026-07-28 (re-capture pending) |
esp32s3 |
🟢 silicon-verified | 2026-07-15 | 2026-07-28 | ⚠ drift acked 2026-07-28 (re-capture pending) |
stm32f401 |
🟡 smoke-manual | — | 2026-07-28 | no silicon capture |
stm32wba52 |
🟡 smoke-manual | — | 2026-07-27 | no silicon capture |
nrf52832 |
⚪ structural | — | 2026-07-23 | no silicon capture |
rp2040 |
⚪ structural | — | 2026-07-28 | no silicon capture |
nrf5340 |
🔵 sim-validated (deep model, no HW diff) | — | 2026-07-27 | no silicon capture |
stm32h735 |
🔵 sim-validated (deep model, no HW diff) | — | 2026-07-28 | no silicon capture |
stm32f411ceu6 |
🔵 sim-validated (deep model, no HW diff) | — | 2026-07-28 | no silicon capture |
esp32 |
⚪ structural | — | 2026-06-28 | no silicon capture |
mkw41z4 |
🔵 sim-validated (deep model, no HW diff) | — | 2026-07-28 | no silicon capture |
nrf54l15 |
🔵 sim-validated (deep model, no HW diff) | — | 2026-07-21 | no silicon capture |
stm32g474re |
🔵 sim-validated (deep model, no HW diff) | — | 2026-07-25 | no silicon capture |
stm32wb55 |
🔵 sim-validated (deep model, no HW diff) | — | 2026-07-27 | no silicon capture |
ci-fixture-riscv |
⚪ structural | — | 2026-03-09 | no silicon capture |
- Doc:
docs/boards/nrf52840.md· Chip:configs/chips/nrf52840.yaml - Silicon: 2026-06-17 on ST-LINK V2 (J37S7) — conformance 16/16; mmio 16/16; GPIO P0 22/0, P1 23/0; onboarding 22/22; POWER 10/0, SPIS 19/0, TWIS 20/0, RTC0 12/0, TIMER0 16/0; SPIM0/CCM/full-register clean
- offline (CI): nrf52_conformance::conformance_sim (digest vs frozen 2026-06-09 capture)
- offline (CI): nrf52_mmio_diff / nrf52_gpio_conformance (sim halves)
- Drift status: ⚠ drift acked 2026-07-27 (re-capture pending)
- Doc:
docs/boards/seeed-xiao-nrf52840-sense.md· Chip:configs/chips/nrf52840.yaml - Note: Same silicon as nrf52840 (the bench board IS a Seeed XIAO nRF52840 Sense).
- Silicon: 2026-06-17 on ST-LINK V2 (J37S7) — rides the nrf52840 full register sweep (16/16) re-confirmed 2026-06-17
- offline (CI): nrf52.rs xiao_* (manifest build, GPIO task regs, SPIM0 EasyDMA)
- Drift status: ⚠ drift acked 2026-07-27 (re-capture pending)
- Doc:
docs/boards/stm32h563.md· Chip:configs/chips/stm32h563.yaml - Silicon: 2026-06-22 on STLINK-V3 (USB 0483:374e, NUCLEO-H563ZI, dapdirect AP1 recipe) — FLASH program-behaviour live-diff run on the board 2026-06-22 (drives real program/erase over SWD): write buffer (NSSR.WBNE) accumulates a 16-byte quad-word, commits + sets EOP only on completion; a misaligned quad-word raises INCERR alone and commits nothing; program-over-not-erased is permitted and ANDs the bits (no PGSERR); flags clear via NSCCR (0x30), not by writing NSSR. The sim H5 flash error-flag + read-while-write fidelity gates were CORRECTED to match this capture (earlier datasheet model was wrong on all four points). Prior MMIO/reset diff (h563_mmio_diff + h563_parity_diff + h563_class_diff, 0 divergence) still holds.
- offline (CI): h563_conformance (5 tests vs frozen 2026-06-10..12 captures)
- offline (CI): h563_mmio_diff::{h563_mmio_sim_only,h563_parity_sim_only,h563_class_sim_only}
- Drift status: ⚠ drift acked 2026-07-28 (re-capture pending)
- Doc:
docs/boards/esp32c3.md· Chip:configs/chips/esp32c3.yaml - Note: Reset-state oracle, not behavioural. ~40 peripherals declared (NOT 6 as the prose doc says).
- Silicon: 2026-06-17 on USB-JTAG (built-in, openocd-esp32) — re-verified live — reset oracle re-captured live 2026-06-17: 1123/1123 static registers match committed baseline (13 deltas all in per-chip efuse + live USB-device state, none in the asserted set); esp32c3_reset_values_match_silicon passes
- offline (CI): esp32c3_reset_conformance::esp32c3_reset_values_match_silicon (79 regs; 366/423 overlap matched silicon)
- Drift status: ⚠ drift acked 2026-07-28 (re-capture pending)
- Doc:
docs/boards/nucleo-l476rg.md· Chip:configs/chips/stm32l476.yaml - Note: Register diff covers RCC/GPIO/SPI1/TIM2 (15 mmio cases + 104-pattern parity sweep), NOT a full-chip sweep — the prose doc's 'every peripheral exercised' is still an overstatement; this is the honest scope.
- Silicon: 2026-06-20 on STLINK-V2.1 (USB 0483:374b serial 0670FF…1747, NUCLEO-L476RG onboard) — Live re-capture after the v0.17.0 merge: l476_mmio_diff + l476_parity_diff pass (15 mmio + 104 parity), 0 divergence. Supersedes the 2026-06-19 drift_ack.
- offline (CI): l476_mmio_diff::{l476_mmio_sim_only,l476_parity_sim_only}
- offline (CI): firmware_survival L476 cases (UART byte stream)
- Drift status: ⚠ drift acked 2026-07-28 (re-capture pending)
- Doc:
docs/boards/nucleo-l073rz.md· Chip:configs/chips/stm32l073.yaml - Note: Register diff covers RCC/GPIO/SPI1/TIM2/TIM21 (20 mmio cases) — not a full-chip sweep. Caught + fixed a real model bug: L0 TIM2 was declared 32-bit (L4 assumption); genuine L0 TIM2 is 16-bit, yaml corrected to width:16.
- Silicon: 2026-06-20 on ST-LINK V2.1 (NUCLEO-L073RZ over SWD) — Live re-capture after the v0.17.0 merge: l0_mmio_diff 20/20, 0 divergence (RCC/GPIO/SPI1/TIM2/TIM21, incl. the TIM2-16-bit fix). Supersedes the 2026-06-19 drift_ack.
- offline (CI): stm32l0_mmio_diff::{l0_mmio_sim_only,l0_parity_sim_only}
- offline (CI): firmware_survival L073 smoke case
- Drift status: ⚠ drift acked 2026-07-28 (re-capture pending)
- Doc:
docs/boards/stm32f103.md· Chip:configs/chips/stm32f103.yaml - Note: Prose doc is STALE-PESSIMISTIC: lists SPI/TIM/ADC/CAN/RTC/IWDG/WWDG as 'not modeled' — all are modeled AND silicon-pinned.
- Silicon: 2026-06-20 on ST-LINK V2.1 (USB 0483:374b), genuine STM32F103 — Live re-capture after the v0.17.0 bxcan/clock-gating merge: stm32f1_mmio_diff 102/102 (24 reset + 26 R/W + 52 sweep), 0 divergence, and f103_conformance digest matches silicon. Supersedes the 2026-06-19 drift_ack. (Earlier capture caught + fixed a classic SPI CR1 bug masking CRCNEXT bit 12 — 0xEFFF vs silicon 0xFFFF.)
- offline (CI): stm32f1_mmio_diff::{f1_reset_sim_only,f1_mmio_sim_only,f1_parity_sim_only,f1_sweep_sim_only}
- offline (CI): f103_conformance::conformance_sim (digest)
- Drift status: ⚠ drift acked 2026-07-28 (re-capture pending)
- Doc:
docs/boards/stm32f407.md· Chip:configs/chips/stm32f407.yaml - Note: examples/nucleo-f407-i2c/VALIDATION.md badges '✅ Hardware-validated 2026-05-11' but I²C/UART/GPIO models were rewritten in June with no re-capture — STALE.
- Silicon: 2026-06-20 on ST-LINK/V2 (USB 0483:3748, IDCODE 0x10016413) — connect-under-reset (firmware was holding SWD), adapter 480 kHz — Live re-capture after the v0.17.0 merge: stm32f4_mmio_diff 37/37 (2 reset + 31 sweep + 4 behaviour), 0 divergence. Caught + fixed a real model bug: F407 silicon does NOT latch SPI1 CR1 bit 12 (CRCNEXT) — writes 0xFFFF, reads 0xEFFF — vs F103 which keeps it writable; spi.rs now applies a per-part cr1_mask (F4 0xEFFF). Supersedes the 2026-06-19 drift_ack. (I²C/UART models still smoke-tier — not in the mmio diff.)
- offline (CI): stm32f4_mmio_diff::{f4_reset_sim_only,f4_sweep_sim_only,f4_behavior_sim_only}
- offline (CI): firmware_survival F407 smoke + i2c cases (sim-self-pinned)
- Drift status: ⚠ drift acked 2026-07-28 (re-capture pending)
- Doc:
docs/boards/esp32s3.md· Chip:configs/chips/esp32s3.yaml - Note: Deep model: 35 peripheral models + full Xtensa LX7 JIT; boots real firmware in sim (green e2e i2c_tmp102/hello_world/xtensa_exec/e-paper). Silicon anchor is reset-state (9 regs) on the firmware-path bus. KNOWN GAPS: (1) broader register + behavioural silicon diff still future work; (2) declarative from_config path falls back to generic ARM peripherals for type:i2c — the coded S3 models only wire via configure_xtensa_esp32s3; (3) full-firmware bring-up rides ~60 boot/ROM/WiFi thunks (FIDELITY.md).
- Silicon: 2026-07-15 on USB-JTAG built-in (ESP32-S3-Zero, USB 303a:1001, openocd-esp32, Tensilica tap 0x120034e5) — Live OpenOCD re-capture on 2026-07-15: connected ESP32-S3 rev 0.2 (MAC 9c:13:9e:f4:40:c0), both Xtensa JTAG taps examined, and reset-state windows captured for UART0, GPIO, I2C0, RMT, MCPWM0, TIMG0, SYSTIMER, GDMA, SYSTEM, and RTC_CNTL.
- offline (CI): esp32s3_reset_conformance (9 reset regs vs live silicon, firmware-path bus)
- offline (CI): e2e_i2c_tmp102 / e2e_hello_world / xtensa_exec / e2e_esp32_epaper (sim)
- Drift status: ⚠ drift acked 2026-07-28 (re-capture pending)
- Doc:
docs/boards/stm32f401.md· Chip:configs/chips/stm32f401.yaml - Note: UART2 'smoke pass' is a manual runbook (examples/nucleo-f401re/VALIDATION.md) + a CI build step — no automated UART assertion.
- Silicon: none — not validated against real hardware.
- Drift status: no silicon capture
- Doc:
docs/boards/stm32wba52.md· Chip:configs/chips/stm32wba52.yaml - Note: LPUART1 'smoke pass' is a manual runbook only; no automated test anywhere. Cortex-M33 TrustZone/radio/crypto not modeled.
- Silicon: none — not validated against real hardware.
- Drift status: no silicon capture
- Doc:
docs/boards/nrf52832.md· Chip:configs/chips/nrf52832.yaml - Note: Chip yaml declares UART0 only. UART0 smoke test + empty-assertion survival test exist; no silicon.
- Silicon: none — not validated against real hardware.
- Drift status: no silicon capture
- Doc:
docs/boards/rp2040.md· Chip:configs/chips/rp2040.yaml - Note: Behavioural models for clocks/resets (RESET_DONE/PLL-LOCK/XOSC-STABLE), the 64-bit free-running TIMER, SIO GPIO (drive/readback round-trip) + hardware spinlocks (SPINLOCK0..31 try-lock/release), PL022 SPI0 (loopback transfer), DW_apb_i2c I2C0 (no-slave address-NACK abort), the XIP_SSI flash controller (boot2 QSPI bring-up: SSI shift engine + W25Q-style RDSR/WREN/WRSR responder, so the stage-2 bootloader and pico-sdk flash_enable_xip_via_boot2 complete), a TBMAN storage stub (running_on_fpga probe), and the PL011 UART0 console. Each is exercised by the tier-1 fixture (tests/fixtures/tier1/rp2040.elf) which reports clock/timer/gpio/spi/i2c PASS over UART. PIO0 is declared but has no test coverage. No silicon bench.
- Silicon: none — not validated against real hardware.
- Drift status: no silicon capture
- Doc:
docs/boards/nrf5340.md· Chip:configs/chips/nrf5340.yaml - Note: Application core (Cortex-M33). Boots UNMODIFIED upstream Zephyr v3.7 hello_world (board nrf5340dk/nrf5340/cpuapp) end to end and prints its banner over the UARTE0 EasyDMA console — asserted by firmware_survival::test_nrf5340_zephyr_survival, with the ELF-independent clock/alias twin in tests/nrf5340_clock_boot.rs. Reuses the shared Nordic CLOCK/UARTE/RTC behavioural models at the 0x5000_0000 non-secure peripheral alias; the whole boot is bus-violation-free (LABWIRED_TRACE_VIOLATIONS=1). Network core, radio, TrustZone/SPU enforcement, and analog trims are not modeled (FICR/UICR/regulator/trim blocks are benign stubs). No nRF5340 silicon diff — no bench board.
- Silicon: none — not validated against real hardware.
- offline (CI): firmware_survival::test_nrf5340_zephyr_survival (real Zephyr ELF boots + banner)
- offline (CI): nrf5340_clock_boot (HFCLK/LFCLK started-event polls + non-secure alias mapping)
- Drift status: no silicon capture
- Doc:
docs/boards/stm32h735.md· Chip:configs/chips/stm32h735.yaml - Note: STM32H735VG — the FIRST fully-modelled Cortex-M7 chip in LabWired. H7-family (RM0468: GPIO @ 0x5802_0000, RCC @ 0x5802_4400, flash interface @ 0x5200_2000, DBGMCU @ 0x5C00_1000), 1 MiB flash, DTCM/AXI SRAM. Introduces a new H7 RCC register layout (rcc.rs Stm32H7 — enable block 0xD4..0xF4, BDCR 0x70, CSR 0x74, oscillator/PLL ready gating + source-ready-gated SYSCLK switch) and reuses the shared H7/H5 peripheral IP (gpio stm32v2, uart stm32v2, spi stm32h5, i2c h5, timer). The tier-1 fixture (tests/fixtures/tier1/stm32h735.elf) drives raw-register self-tests and reports clock/gpio/timer/pwm/i2c/spi/wdt/irq PASS + a working UART over USART3. SIM-DERIVED: every reset value/behaviour is reference-manual-derived — there is NO H735 bench part and NO silicon diff. H7 DMA/ADC/RTC/FDCAN and PWR/FLASH VOSRDY/bank-2 fidelity are not modelled (documented in the chip yaml).
- Silicon: none — not validated against real hardware.
- offline (CI): tier1 fixture (clock/gpio/timer/pwm/i2c/spi/wdt/irq PASS + uart via TIER1 done)
- offline (CI): io-smoke (examples/stm32h735-smoke: asserts the TIER1 transcript over UART)
- offline (CI): chip_conformance (estate OK — no peripheral window faults)
- Drift status: no silicon capture
- Doc:
docs/boards/stm32f411.md· Chip:configs/chips/stm32f411ceu6.yaml - Note: STM32F411CEU6 (WeAct Black Pill) — same silicon row as the STM32F401 (RM0383 vs RM0368: identical peripheral bases and IRQ numbers) with three deltas: 512 KiB flash, 128 KiB SRAM, and the extra SPI5 instance @ 0x4001_5000 IRQ 85. Required NO new peripheral model and NO new RCC layout: the F411 RCC offsets (AHB1ENR 0x30, APB1ENR 0x40, APB2ENR 0x44) were read out of the vendored SVD and are byte-identical to the shipped stm32f4 profile, and SPI5 reuses the existing classic-SPI IP. The tier-1 fixture (tests/fixtures/tier1/stm32f411.elf) drives raw-register self-tests and reports clock/gpio/timer/i2c/spi/adc/wdt/rtc PASS plus a working UART over USART2; its spi check covers SPI1 AND SPI5. SIM-DERIVED: there is NO F411 bench part, NO ST-Link capture and NO silicon diff — every value comes from ST's CMSIS header (stm32f411xe.h) and modm-io's F411 SVD. THREE THINGS ARE EXPLICITLY UNVERIFIED AND MUST NOT BE READ AS CLAIMS: (1) the DBGMCU IDCODE is in neither source, so dbg ships as a stub with NO IDCODE and none was invented (F401CDU6's 0x10016433 is F401's); (2) the Black Pill LED PC13 / button PA0 pinout is carried over from the F401 board and is a board-level fact no chip source can settle; (3) the 100 MHz max SYSCLK is unrepresentable in the schema (the stm32f4 RCC model derives no frequency) and is documentation only. Clock gating is declared only for TIM2/ADC1/SPI1/SPI5 — the four gates the fixture proves; every other block responds unclocked, the same modelling gap the F401 descriptors carry. DMA1/2 stay stubs because the F4 stream controller is not the modelled F1/L4 channel IP. SPI5's clock-gate bit (RCC_APB2ENR bit 20) is header-only: no public F411 SVD declares an SPI5EN field, so the fixture's spi check is its only executable evidence.
- Silicon: none — not validated against real hardware.
- offline (CI): tier1 fixture (clock/gpio/timer/i2c/spi/adc/wdt/rtc PASS + uart via TIER1 done)
- offline (CI): io-smoke (examples/stm32f411ceu6-blackpill: asserts the TIER1 transcript over USART2)
- offline (CI): chip_conformance (estate OK — no peripheral window faults)
- offline (CI): register_coverage (scanned against the vendored modm-io SVD, 56 IRQs)
- Drift status: no silicon capture
- Doc:
docs/boards/esp32.md· Chip:configs/chips/esp32.yaml - Note: Original ESP32 (dual-core Xtensa LX6). Exercised via the tier-1 fast-boot fixture only (tests/fixtures/tier1/esp32.elf); no dedicated firmware_survival case and no silicon bench.
- Silicon: none — not validated against real hardware.
- Drift status: no silicon capture
- Doc:
docs/boards/mkw41z4.md· Chip:configs/chips/mkw41z4.yaml - Note: NXP KW41Z (Cortex-M0+ BLE + 802.15.4). Boots bare-metal smoke firmware, the vendor NXP HAL clock/UART bring-up path, UNMODIFIED upstream Zephyr v3.7 hello_world (board frdm_kw41z), and a Zephyr FXOS8700 I2C + Nokia5110/PCD8544 LCD demo end to end (firmware_survival::kw41z_smoke/kw41z_nxp/kw41z_zephyr/kw41z_zephyr_fxos8700/kw41z_lcd_activity), with a deterministic register-level twin in tests/kw41z_clock_boot.rs. No KW41Z silicon diff — no bench part.
- Silicon: none — not validated against real hardware.
- offline (CI): firmware_survival::kw41z_smoke / kw41z_nxp / kw41z_zephyr / kw41z_zephyr_fxos8700 / kw41z_lcd_activity
- offline (CI): kw41z_clock_boot (MCG/RSIM clock bring-up, register-level)
- Drift status: no silicon capture
- Doc:
docs/boards/nrf54l15.md· Chip:configs/chips/nrf54l15.yaml - Note: RRAM-based (NVM at 0x0, 1524 KB; 256 KB SRAM, initial SP at 0x2004_0000) rather than flash. Boots a bare smoke fixture and UNMODIFIED upstream Zephyr hello_world through the real nrfx/Zephyr boot path (TAMPC approtect gate, nRF54L CLOCK XO/LFCLK, GRTC, nRF54L-generation UARTE DMA.TX) — firmware_survival::nrf54l15_smoke/nrf54l15_zephyr. No nRF54L15 silicon diff — no bench board.
- Silicon: none — not validated against real hardware.
- offline (CI): firmware_survival::nrf54l15_smoke / nrf54l15_zephyr
- Drift status: no silicon capture
- Doc:
docs/boards/stm32g474re.md· Chip:configs/chips/stm32g474re.yaml - Note: STM32G474RE (Cortex-M4, RM0440). Boots UNMODIFIED upstream Zephyr hello_world (board nucleo_g474re) via firmware_survival::stm32g474_zephyr, and covered by the tier-1 fast-boot fixture (tests/fixtures/tier1/stm32g474re.elf). No G474 silicon diff — no bench part.
- Silicon: none — not validated against real hardware.
- offline (CI): firmware_survival::stm32g474_zephyr
- Drift status: no silicon capture
- Doc:
docs/boards/stm32wb55.md· Chip:configs/chips/stm32wb55.yaml - Note: Dual-core STM32WB55 (Cortex-M4 app core + Cortex-M0+ CPU2). Boots UNMODIFIED upstream Zephyr hello_world end to end via firmware_survival::stm32wb55_zephyr, exercising the HSEM inter-core lock (granted to CPU1) and the RCC BDCR LSE path. No WB55 silicon diff — no bench part.
- Silicon: none — not validated against real hardware.
- offline (CI): firmware_survival::stm32wb55_zephyr
- Drift status: no silicon capture
- Doc:
docs/boards/ci-fixture-riscv.md· Chip:configs/chips/ci-fixture-riscv.yaml - Note: Synthetic RV32I fixture used only to exercise the RISC-V core in firmware_survival::riscv_ci_fixture; not a real board, no silicon claim of any kind.
- Silicon: none — not validated against real hardware.
- Drift status: no silicon capture