Ethernet · Module 26
How Ethernet Is Actually Probed
What is being tested behind each question, what the track's 124 rejected-property classes have in common, and the one question that separates a candidate who has the model from one who has the vocabulary.
This chapter closes the track, and it is not a list of questions with answers. Its subject is what is being TESTED behind a question, and its material is the track's own record: 124 numbered rejected-property classes written across 140 chapters, and the twelve-group taxonomy they were sorted into.
Start with the finding that makes the chapter possible, because it is the only genuinely retrospective result available and it took twenty-six modules to reach.
In every one of the 124 classes, the check's OUTCOME is decided by something other than whether the design is correct.
Not most of them. All of them — and that is not a coincidence, because a rejected class is precisely a check whose outcome carries no information. What differs between the 124 is WHAT decides the outcome, and there turn out to be five answers.
| The outcome is decided by | Mechanism | Groups |
|---|---|---|
| the property's own form | the expression does not denote the requirement | 1, 2, 3, 8, 10, 12 |
| the stimulus | the property stops being evaluated | 9, 7 |
| the observer | the instrument is part of what it measures | 11, 4 |
| the premise's custodian | nobody can constitute the premise | 5 |
| the design's own specification | the outcome follows from what the design was built to do | 6 |
Five producers, twelve groups, 124 classes, and one consequence for an interview: the question that separates an engineer who has this model from one who has the vocabulary is not about Ethernet at all. Section 12 derives it and it is one sentence.
And the chapter needs a unit, because "a strong answer" is an adjective and this track does not accept those.
The unit is the REFUTATION COUNT: the number of distinct observations that would have changed the answer. Section 4 defends it. It is zero for every one of the 124 classes at the moment they pass, which is the same statement as the finding above, arrived at from the other side.
What this chapter does not own. Chapter 26.1, Chapter 26.2 and Chapter 26.3 are the three sign-off passes. This is the retrospective, and it is the last chapter of the track.
1. Scope — What Is Being Tested
An interview question has two contents and they are not the same. There is the question as asked — what is the minimum Ethernet frame size? — and there is the thing being probed, which is almost never the fact.
| The question | The fact | What is being probed |
|---|---|---|
| "what is the minimum frame size?" | 64 octets | whether the candidate knows WHY, which is Chapter 25.6 §2's 4 752-metre collision diameter |
| "what is the latency of a switch?" | a number | whether they ask which regime — Chapter 26.3 §8 |
| "is a MAC address unique?" | "yes" | whether they know the space is 2²⁴ and not 2⁴⁶ — Chapter 25.2 §4 |
| "what is your coverage?" | a percentage | whether they volunteer the denominator — Chapter 26.2 §4 |
Column two is answerable from a datasheet and column three is not, and the distance between them is the whole subject of this chapter.
The failure mode of an interview is the same one Chapter 26.1 §1 identified for a review: it cannot fail. A question whose correct answer is a fact has exactly one discriminating outcome — the candidate knows it or does not — and both outcomes are cheaply produced by preparation. A question about a mechanism has a continuum, and the continuum is measurable.
So this chapter's grading criterion is falsifiability rather than keyword match, and it is worth stating what that means precisely before Section 3 builds it.
| Answer | Contains the right words | Refutation count |
|---|---|---|
| "CSMA/CD is not used on full-duplex links" | yes | 0 — nothing would have changed it |
| "it is not used because there is no shared medium, so the collision signal is unreachable" | yes | 1 — a shared full-duplex medium would refute it |
| "the slot time bounded a 4 752 m diameter; at 3 m the margin is 1 584× and the bound constrains nothing" | yes | several — a link longer than 4 752 m, a half-duplex configuration, a measured collision |
| "CSMA/CD was removed in the 802.3x era" | partly | 0 — and it is also wrong |
All four contain the vocabulary. Only rows two and three contain a claim that the world could contradict, and the difference between them is how many independent observations would do it.
An argument's strength is the size of the set of observations that would have refuted it. That is a count, it is comparable across subjects, and it is zero exactly when the answer is a recitation.
Which is the track's closing sentence, arriving one last time and now as a grading rule. Chapter 25.6 §20 reached it for an assertion, Chapter 26.1 §21 for a review item, Chapter 26.2 §20 for a set, Chapter 26.3 §20 for a statistic — and here for a sentence spoken out loud in a room.
2. The Twenty Questions, and What Each One Probes
Twenty questions that get asked. For each one: the fact, the thing actually being probed, and the chapter that makes a strong answer possible. No row is graded by whether a word appears.
| # | Asked | Probing | Where the answer comes from |
|---|---|---|---|
| 1 | minimum frame size? | whether 64 octets is known as a CONSEQUENCE — of a 4 752 m collision diameter | Chapter 25.6 §2 |
| 2 | why is the interframe gap 12 octets? | whether a timing budget is distinguished from a convention | Chapter 5.9 §2 |
| 3 | does a switch eliminate broadcasts? | whether flooding is understood as replication, not as a message class | Chapter 25.5 §2 |
| 4 | is a MAC address globally unique? | whether the birthday arithmetic is on 2²⁴ and not 2⁴⁶ | Chapter 25.2 §4 |
| 5 | does the FCS protect a frame? | whether detection is separated from integrity — a converse, not a degree | Chapter 25.3 §2 |
| 6 | do VLANs improve performance? | whether a conservation argument is available | Chapter 25.4 §4 |
| 7 | is Ethernet the same as TCP/IP? | whether the parse window is known — 18 octets, 1.19% of a frame | Chapter 25.1 §2 |
| 8 | does a modern link use CSMA/CD? | whether "unreachable" is distinguished from "removed" | Chapter 25.6 §4 |
| 9 | what is a switch's latency? | whether the candidate asks which regime before answering | Chapter 26.3 §8 |
| 10 | why does cut-through matter? | whether 0.121 µs is placed against a queueing term of up to 2 224 | Chapter 12.6 §6 |
| 11 | how deep should a prefetch store be? | whether Little's law is applied with THIS design's rate | Chapter 23.4 §7 |
| 12 | what is your coverage? | whether a denominator is volunteered | Chapter 26.2 §4 |
| 13 | all your assertions passed. And? | whether the cover count is asked for | Chapter 21.4 §20 |
| 14 | where does a 400 Gb/s hop's latency go? | whether 53.7% propagation and 8.76% design-owned are known | Chapter 26.1 §8 |
| 15 | why is FEC mandatory at PAM4? | whether the raw error rate 2.4 × 10⁻⁴ is known as an OPERATING POINT | Chapter 9.6 §2 |
| 16 | how do you size a pause watermark? | whether the dead time is recognised as a measurement, not a fraction | Chapter 14.2 §9 |
| 17 | what does a TCAM cost against SRAM? | whether the factor of five is known and why | Chapter 23.3 §6 |
| 18 | is Ethernet lossless? | whether credit-based and reactive flow control are distinguished | Chapter 24.2 §2 |
| 19 | why not use a proprietary fabric? | whether the framing tax is quantified — 45.24% at 64 octets | Chapter 24.3 §2 |
| 20 | what would change your mind? | EVERYTHING — Section 12 | this chapter |
Row 20 is not a question about Ethernet and it is the only row that works on every subject. Sections 10 and 12 derive why.
Three of the rows are worth reading twice.
Row 9 is the only one where the strong answer is a QUESTION. "What is the latency" has no answer until somebody names a regime and a percentile, and a candidate who supplies a number without asking has demonstrated the failure Chapter 26.3 §6 spends a section on. The strong response — idle, loaded, or under an incast? — is three words and it is the whole of the signal.
Row 11 is the only one where the reference value is a trap. Chapter 23.4 §7's 149 descriptors is correct at 100 Gb/s and 595 at 400 — so a candidate who recites 149 has demonstrated they read the chapter and not that they can apply it. The probe is the rate, and it is supplied by the interviewer.
Row 13 is the one with a measured number behind it. Chapter 21.4 §20 counted its own corpus: 332 of 557 published properties — 59.6% — have antecedents that need traffic, so on a link that never trains they stop evaluating and the regression reports all passes. A candidate who asks for the cover count has the model; one who says "that's good" has the vocabulary.
3. RTL 1 — The Probe Package and the Answer Model
The package holds the answer grades, the twelve taxonomy groups and the census constants. The module grades one answer, and its criterion is falsifiability rather than keyword match.
// ---------------------------------------------------------------------
// probe_pkg -- the grading vocabulary of this chapter, the twelve
// taxonomy groups of the rejected-property series, and the constants
// Sections 6 to 12 count with.
//
// The unit throughout is the REFUTATION COUNT: the number of distinct
// observations that would have changed the answer. Section 4 defends
// it. It is zero for a recitation and for all 124 rejected classes.
// ---------------------------------------------------------------------
package probe_pkg;
// What an answer is made of. These are not quality levels; they are
// structurally different kinds of utterance.
typedef enum logic [2:0] {
ANS_ABSENT, // no answer
ANS_RECITATION, // correct words, no claim about the world
ANS_CLAIM, // a claim, no quantity
ANS_QUANTIFIED, // a claim with a number
ANS_DERIVED, // and the number follows from something named
ANS_COMPOSED // and it composes two or more chapters
} answer_kind_e;
// The twelve groups of the rejected-property taxonomy. Group 1 to 6
// were derived in Chapter 20.2 Section 8; 7 in 20.4, 8 in 21.2,
// 9 in 21.5, 10 in 21.8, 11 in 21.9, 12 in 22.2.
typedef enum logic [3:0] {
GRP_NONE,
GRP_SUBJECT, // 1 wrong subject
GRP_SCOPE, // 2 wrong scope
GRP_TIME, // 3 wrong time
GRP_UNEVALUABLE, // 4 unevaluable
GRP_PREMISE, // 5 unknowable premise
GRP_DESIGNED, // 6 designed-for behaviour
GRP_ARRANGED, // 7 satisfaction the environment can arrange
GRP_SIDE, // 8 bound to the wrong side of a function
GRP_EVALCOUNT, // 9 who controls the evaluation count
GRP_BOUNDARY, // 10 boundaries that are not boundaries
GRP_OBSERVER, // 11 the observer is inside the system
GRP_RELATION // 12 a relation between nodes, evaluated at one
} tax_group_e;
localparam int N_GROUPS = 12;
localparam int N_CLASSES = 124; // the series, complete
// Section 6's census. These are the classes with an EXPLICIT group
// assignment in the text, not an inferred one -- which is why the
// number is 35 and not 124.
localparam int N_ASSIGNED = 35;
localparam int N_ASSIGNMENTS = 36; // one class has two groups
localparam int N_UNASSIGNED = 89;
// Section 10's five producers of an outcome that carries no
// information about the design. Note that PROD_SPEC does not always
// produce a PASS: class 49's property fails, and it fails because
// the design is correct, which is the same defect mirrored.
typedef enum logic [2:0] {
PROD_FORM, // the expression does not denote the requirement
PROD_STIMULUS, // the property stops being evaluated
PROD_OBSERVER, // the instrument is part of the subject
PROD_CUSTODIAN, // nobody can constitute the premise
PROD_SPEC // the design's own specification decides it
} producer_e;
function automatic producer_e producer_of(tax_group_e g);
case (g)
GRP_EVALCOUNT, GRP_ARRANGED : return PROD_STIMULUS;
GRP_OBSERVER, GRP_UNEVALUABLE : return PROD_OBSERVER;
GRP_PREMISE : return PROD_CUSTODIAN;
GRP_DESIGNED : return PROD_SPEC;
default : return PROD_FORM;
endcase
endfunction
endpackageClassification, Model or Production? A CLASSIFICATION MODEL, and the only one in this track whose subject is a sentence rather than a signal.
// ---------------------------------------------------------------------
// answer_model -- grade one answer by what would have refuted it.
//
// The module deliberately has NO input for whether the answer contains
// any particular term. Section 13 shows what a keyword grader does on
// the same four answers, and it ranks them in the wrong order.
// ---------------------------------------------------------------------
module answer_model
import probe_pkg::*;
(
input logic clk,
input logic rst_n,
input logic ans_valid,
// The observations the answer's claim would be contradicted by. This
// is the whole input; everything else is derived from it.
input logic [7:0] n_refuting_observations,
input logic has_quantity,
input logic quantity_is_derived, // follows from a named source
input logic [3:0] n_chapters_composed,
input logic quantity_copied, // a reference value, unadapted
output logic out_valid,
output answer_kind_e kind,
output logic [7:0] refutation_count,
output logic is_falsifiable,
output logic is_recitation,
output logic reference_value_risk
);
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n) begin
out_valid <= 1'b0;
kind <= ANS_ABSENT;
refutation_count <= '0;
is_falsifiable <= 1'b0;
is_recitation <= 1'b0;
reference_value_risk <= 1'b0;
end else begin
out_valid <= ans_valid;
refutation_count <= n_refuting_observations;
is_falsifiable <= (n_refuting_observations != 8'd0);
// A recitation has the words and no refuting observation. It is
// not wrong; it simply cannot be wrong.
is_recitation <= (n_refuting_observations == 8'd0);
// Chapter 23.4 Section 7's 149 descriptors is correct at
// 100 Gb/s and 595 at 400. A copied quantity looks derived.
reference_value_risk <= has_quantity && quantity_copied;
if (ans_valid) begin
if (n_refuting_observations == 8'd0)
kind <= has_quantity ? ANS_RECITATION : ANS_ABSENT;
else if (!has_quantity)
kind <= ANS_CLAIM;
else if (!quantity_is_derived)
kind <= ANS_QUANTIFIED;
else if (n_chapters_composed <= 4'd1)
kind <= ANS_DERIVED;
else
kind <= ANS_COMPOSED;
end
end
end
endmoduleWhat it teaches: that the grade depends on one input and the rest are refinements. n_refuting_observations alone separates a recitation from an answer; everything after that is about how much work the answer did, not about whether it said anything. The module also teaches why ANS_RECITATION requires has_quantity: an answer with the right number and no refuting observation is the most deceptive kind, because it looks quantitative and is a fact rather than a claim.
Deliberately simplified: n_refuting_observations arrives as an integer where in a real interview it is elicited — the interviewer asks "what would change your mind" and counts the answer's own list, which is Section 12's whole method. quantity_copied is likewise a judgement rather than a measurement, and the only reliable way to make it is to change the rate and see whether the number moves. And the model grades an answer's structure and not its truth: a derived, composed, highly falsifiable answer can be wrong, and this module would grade it highly. Truth is the interviewer's job; structure is what can be scored.
Production implication: the output worth recording is refutation_count, as an integer, per question. It is comparable across questions, across candidates and across subjects — which no other interview metric is — and a debrief that carries twenty integers is a different artefact from one that carries twenty adjectives. The failure it prevents is the one Section 14 names: two interviewers writing "strong on protocols" about candidates who differ by a factor of ten in what they could have been wrong about.
4. Falsifiability as a Grading Criterion
The criterion needs defending, because "count the observations that would have refuted it" sounds like philosophy and this chapter needs it to be arithmetic.
Take one question and four answers, all of them containing the correct vocabulary.
Question: does a switch eliminate broadcasts?
| Answer | Refuting observations | Count |
|---|---|---|
| "no, switches still flood broadcasts" | none — it is a definition restated | 0 |
| "no, because a broadcast has no single destination port" | a switch with a broadcast-suppression mode that still forwards correctly | 1 |
| "no — one flooding port sends 63 copies, so at 148.81 Mpps it is 9.375 Gpps" | a port count other than 64; a line rate other than 100 Gb/s; a replication engine that deduplicates | 3 |
| "and that is 98.4% of the switch's 9.524 Gpps budget, so one port can consume the fabric" | the three above, plus a different frame budget, plus a scheduler that rate-limits floods by default | 5 |
Every row says "no". Every row is correct. They differ by a factor of five in what the world could have said back, and that difference is exactly the difference between the four candidates.
A refutation count is a count. It is an integer, it is comparable across questions with different subjects, and it can be elicited in one sentence: what would change your mind?
Three properties make it a usable unit rather than a metaphor.
One — it is bounded below by zero and the zero is meaningful. An answer with a refutation count of zero is not a bad answer; it is not an answer to an engineering question at all. It may be a perfect definition. Chapter 26.1 §20's class 121 is the same object in SVA — a predicate with no failing value — and the two are the same failure at different scales.
Two — it does not reward length. A candidate who talks for five minutes and names no observation that could have contradicted them scores zero, and one who says twenty words naming three scores three. This inverts the usual failure mode of an interview, which rewards fluency because fluency is what an interviewer can perceive without effort.
Three — it is robust to the interviewer's own knowledge. The count is of observations the CANDIDATE names, so an interviewer who does not know Chapter 23.3's 9.524 Gpps budget can still count three items in row three. The criterion does not require the grader to be the stronger engineer, which is the condition under which most technical interviews actually run.
5. RTL 2 — The Refutation Counter
// ---------------------------------------------------------------------
// refutation_counter -- count the observations an answer names that
// would genuinely have refuted its claim, discarding those for which
// no mechanism is given.
//
// Section 4's weakness is the reason the module has two inputs per
// observation rather than one.
// ---------------------------------------------------------------------
module refutation_counter
import probe_pkg::*;
#(
parameter int unsigned MAX_OBS = 16
)(
input logic clk,
input logic rst_n,
input logic answer_start,
input logic obs_valid,
input logic obs_has_mechanism, // the candidate said HOW
input logic obs_bears_on_claim, // and it touches the claim
input logic obs_is_duplicate, // of one already counted
input logic answer_end,
output logic [7:0] n_offered,
output logic [7:0] n_counted,
output logic [7:0] n_no_mechanism,
output logic [7:0] n_irrelevant,
output logic [7:0] n_duplicate,
output logic [19:0] precision_ppm, // counted / offered
output logic answer_is_falsifiable,
output logic padding_detected
);
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n || answer_start) begin
n_offered <= '0;
n_counted <= '0;
n_no_mechanism <= '0;
n_irrelevant <= '0;
n_duplicate <= '0;
end else if (obs_valid && (n_offered < 8'(MAX_OBS))) begin
n_offered <= n_offered + 8'd1;
// The three ways an offered observation fails to count, checked
// in the order that gives the most informative diagnosis.
if (!obs_has_mechanism)
n_no_mechanism <= n_no_mechanism + 8'd1;
else if (!obs_bears_on_claim)
n_irrelevant <= n_irrelevant + 8'd1;
else if (obs_is_duplicate)
n_duplicate <= n_duplicate + 8'd1;
else
n_counted <= n_counted + 8'd1;
end
end
always_comb begin
precision_ppm = (n_offered == 8'd0) ? 20'd0
: 20'((int'(n_counted) * 1000000) / int'(n_offered));
answer_is_falsifiable = (n_counted != 8'd0);
// Padding: many offered, few counted. The ratio is the signal and
// the absolute numbers are not -- a candidate who offers two and
// counts two is stronger than one who offers eight and counts two.
padding_detected = (n_offered >= 8'd4) &&
(precision_ppm < 20'd500000);
end
endmoduleClassification, Model or Production? A GRADING MODEL, and the first one in this track whose inputs are judgements rather than signals.
What it teaches: that precision_ppm carries information the raw count does not. Two candidates both counting three: one offered three and one offered nine. The first has three observations they are confident bear on the claim; the second has nine guesses of which three landed — and the difference is legible only because the module records the offers as well as the hits. It also teaches why n_no_mechanism is checked first: it is the most common failure and it is the one whose remedy is a follow-up question rather than a mark.
Deliberately simplified: all three qualifying inputs are booleans supplied by the interviewer, so the module formalises a judgement rather than replacing it — which is the honest limit of any grading instrument. MAX_OBS truncates at sixteen, which discards the tail of a very long answer; in practice an answer naming more than a handful of genuinely distinct refuting observations is already at the top of the scale. And obs_is_duplicate treats near-duplicates as distinct, so "a different port count" and "a different switch size" both count where they are one observation.
Production implication: the artefact to keep from an interview is n_counted per question, as twenty integers, not a written impression. Integers are comparable between interviewers, they survive a debrief unchanged, and they make the one comparison that matters possible: two candidates on the same twenty questions, with two lists of twenty numbers. A debrief conducted over adjectives cannot make that comparison at all, which is why interview panels so often disagree without being able to say about what.
6. The 124 Classes, Counted
Every flagship chapter of this track ends its properties section with exactly one rejected class, numbered, never repeated. This section counts them, and the count is done the way the rest of the track does arithmetic: with a stated denominator.
The series is 124 classes long, and the classes that carry an EXPLICIT group assignment in the text are 35 of them.
| Count | Share of 124 | |
|---|---|---|
| classes in the series | 124 | 100% |
| with an explicit group assignment in their own callout | 35 | 28.23% |
| group assignments made | 36 | — |
| classes with more than one group | 1 — class 91 | — |
| without an explicit assignment | 89 | 71.77% |
Row three exceeds row two and row four says why, and Section 8 is about it.
The census, over the 36 explicit assignments.
| Group | Name | Members | Share of assignments |
|---|---|---|---|
| 10 | boundaries that are not boundaries | 80, 100, 101, 106, 108, 118 — 6 | 16.7% |
| 5 | unknowable premise | 111, 114, 121, 124 — 4 | 11.1% |
| 8 | bound to the wrong side of a function | 93, 94, 95, 96 — 4 | 11.1% |
| 9 | who controls the evaluation count | 91, 97, 98, 120 — 4 | 11.1% |
| 1 | wrong subject | 107, 117, 122 — 3 | 8.3% |
| 2 | wrong scope | 110, 113, 119 — 3 | 8.3% |
| 11 | the observer is inside the system it measures | 102, 103, 116 — 3 | 8.3% |
| 4 | unevaluable | 74, 123 — 2 | 5.6% |
| 6 | designed-for behaviour | 49, 115 — 2 | 5.6% |
| 7 | satisfaction the environment can arrange | 91, 109 — 2 | 5.6% |
| 12 | a relation between nodes, evaluated at one | 104, 112 — 2 | 5.6% |
| 3 | wrong time | 105 — 1 | 2.8% |
Three readings, and the third is a finding about the track rather than about Ethernet.
One — group 10 is the load-bearing group, with 6 of 36 assignments. Boundaries that are not boundaries covers a property scoped correctly to a block whose outcome is decided by something outside that block's interface: a shared interconnect (100), a memory latency the design does not own (101), a hash the design does not control (106), a split datapath's other half (108), and a factor of a product that moves the opposite way (118). Five distinct third parties, one shape.
Two — group 3 has one member and it is the last one added to it. Wrong time was in the original six of Chapter 20.2 §8 and then attracted only class 105, and 105's own callout in Chapter 22.3 §20 argues at length that it is group 3's limiting case rather than a thirteenth group. A founding group with one explicit member is a sign that the original six were too coarse — the finer groups 7 to 12 absorbed what would have gone there.
Three — 71.77% of the series has no explicit group. That is not a defect to apologise for; it is the honest denominator, and it is the reason this section says "share of assignments" rather than "share of classes" in every row. The 89 unassigned classes were written before group assignment became a per-chapter practice, which happened around class 107, and retrofitting them would be inference rather than record.
7. RTL 3 — The Class Census
// ---------------------------------------------------------------------
// class_census -- walk the rejected-property series and count group
// memberships, keeping assignments and classes as SEPARATE totals
// because one class carries two groups.
//
// Chapter 26.2 Section 20's class 122 is the reason the module counts
// members rather than only totalling: a cardinality is invariant under
// a swap, and this census is about which classes are where.
// ---------------------------------------------------------------------
module class_census
import probe_pkg::*;
(
input logic clk,
input logic rst_n,
input logic census_start,
input logic entry_valid,
input logic [7:0] class_num, // 1 to 124
input tax_group_e group_id,
input logic is_explicit, // stated in the callout itself
input logic is_second_group, // this class already had one
output logic [7:0] n_classes_seen,
output logic [7:0] n_assignments,
output logic [7:0] n_explicit,
output logic [7:0] n_multi_group,
output logic [7:0] n_unassigned,
output logic [7:0] per_group [N_GROUPS + 1],
output logic [19:0] explicit_share_ppm,
output logic [3:0] largest_group,
output logic census_is_over_explicit // the denominator flag
);
logic [7:0] biggest;
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n || census_start) begin
n_classes_seen <= '0;
n_assignments <= '0;
n_explicit <= '0;
n_multi_group <= '0;
largest_group <= '0;
biggest <= '0;
for (int g = 0; g <= N_GROUPS; g = g + 1) per_group[g] <= '0;
end else if (entry_valid) begin
// A class is counted once; an assignment is counted every time.
// Keeping these apart is the whole reason the module exists.
if (!is_second_group)
n_classes_seen <= n_classes_seen + 8'd1;
else
n_multi_group <= n_multi_group + 8'd1;
n_assignments <= n_assignments + 8'd1;
if (is_explicit) n_explicit <= n_explicit + 8'd1;
per_group[int'(group_id)] <= per_group[int'(group_id)] + 8'd1;
if ((per_group[int'(group_id)] + 8'd1) > biggest) begin
biggest <= per_group[int'(group_id)] + 8'd1;
largest_group <= 4'(group_id);
end
end
end
always_comb begin
n_unassigned = 8'(N_CLASSES) - n_classes_seen;
explicit_share_ppm = 20'((int'(n_classes_seen) * 1000000) / N_CLASSES);
// The flag that keeps Section 6's honesty: this census's denominator
// is the explicit assignments, not the series.
census_is_over_explicit = (n_explicit == n_assignments);
end
endmoduleClassification, Model or Production? A REVIEW INSTRUMENT.
What it teaches: that n_classes_seen and n_assignments must be different registers. They differ by one here — 35 against 36 — and a census that keeps a single total reports 36 classes and hides class 91 entirely. That is Chapter 26.2 §20's class 122 in the flesh: a cardinality that is invariant under a swap, applied to the taxonomy of which 122 is a member. The module also teaches why census_is_over_explicit is an output: the denominator is a property of the census, and a consumer that does not know which denominator was used cannot interpret explicit_share_ppm.
Deliberately simplified: is_second_group is an input where a real implementation carries a per-class bitmap of groups already assigned, so the module cannot detect a class assigned twice to the SAME group, which would inflate both totals. largest_group also breaks ties by first arrival rather than reporting a tie, which loses information when two groups are level — and groups 5, 8 and 9 are level at four here, so the tie is real.
Production implication: the output to publish is the per-group array plus both totals, never a single distribution. A table of twelve percentages summing to 100% implies a partition and Section 8 shows there is not one; the same twelve numbers beside "36 assignments over 35 classes" tells a reader immediately that something is double-counted and invites them to find it. The general form is the one this whole module exists to demonstrate: publish the denominators, and a reader can check the arithmetic; publish only the percentages, and they cannot.
8. The Taxonomy Is Not a Partition
Section 6 counted 36 assignments over 35 classes. This section is the missing class, and it turns out to be the most interesting result the retrospective produces — because the track already proved this theorem about a different taxonomy, in a chapter that went on to found a group in this one.
Class 91 belongs to two groups, and both memberships are stated in the text.
| Where | What it says |
|---|---|
| Chapter 20.4 §26 | 91 OPENS group 7 — "a seventh group that did not exist before it: a property whose satisfaction the environment can arrange by changing a definition" |
| Chapter 21.5 §20 | 91, together with 97 and 98, "form a family about who controls a property's evaluation count, which is a ninth group" |
Both are true and they are about different aspects of the same class. 91 is a target on a ratio whose denominator the environment controls: the environment can arrange satisfaction (group 7) by moving the denominator, and in moving it the environment is deciding how often the property is meaningfully evaluated (group 9). One class, two axes, two groups.
And the taxonomy has no rule that says which one wins, because no chapter ever wrote one.
The rejected-property taxonomy is a partition only after a priority rule, and the priority rule was never written down.
Which is verbatim Chapter 21.2 §2's theorem about the twelve Ethernet error classes — that they are a partition of the frame space quotiented by a priority rule, and the rule is the part nobody writes down. That chapter showed 7 of 12 reachable frame shapes qualify for more than one class, then closed by founding group 8 of the taxonomy that has the same defect.
Two further gaps in the record, both checkable and neither serious.
One — the ninth group was deferred for settlement and never settled. Chapter 21.4 §20 raised class 97 and asked whether it opened a ninth group or sharpened group 4's "unevaluable", and deferred the argument to Chapter 21.6. 21.6 did not take it up. Chapter 21.5 §20 then named the ninth group anyway and deferred its settlement to Chapter 21.8; 21.8 founded group 10 instead. So group 9 is in continuous use, has four members, and was never formally constituted — which is Chapter 24.3 §20's class 114 shape applied to the taxonomy's own governance.
Two — the groups were founded by six different chapters over five modules.
| Group | Founded in |
|---|---|
| 1 to 6 | Chapter 20.2 §8 |
| 7 | Chapter 20.4 §26 — the class itself is §20 |
| 8 | Chapter 21.2 §26 |
| 9 | Chapter 21.5 §20 — never settled |
| 10 | Chapter 21.8 §26 |
| 11 | Chapter 21.9 §20, confirmed in Chapter 22.1 §20 |
| 12 | Chapter 22.2 §20 |
Six groups in six chapters between 20.2 and 22.2, and none since. Chapter 22.3 §20 declined to open a thirteenth and gave the reason the track has cited sixteen times since: "two new groups in three chapters is already unusual, and a taxonomy that grows a group per chapter has stopped classifying anything."
9. RTL 4 — The Group Membership Auditor
// ---------------------------------------------------------------------
// group_auditor -- detect what Section 7's census can only report: a
// class assigned to more than one group, and a group with no founding
// chapter recorded.
//
// The module is the one place in this chapter that treats the taxonomy
// as DATA to be checked rather than as a framework to classify with.
// ---------------------------------------------------------------------
module group_auditor
import probe_pkg::*;
#(
parameter int unsigned MAX_CLASS = 124
)(
input logic clk,
input logic rst_n,
input logic audit_start,
input logic entry_valid,
input logic [7:0] class_num,
input tax_group_e group_id,
// Per-group provenance, loaded once.
input logic prov_valid,
input tax_group_e prov_group,
input logic prov_founded, // a chapter states the opening
input logic prov_settled, // and the argument was closed
output logic [7:0] n_multi_assigned,
output logic [7:0] first_multi_class,
output logic [3:0] n_founded,
output logic [3:0] n_unsettled,
output logic taxonomy_is_partition,
output logic every_group_founded,
output logic priority_rule_required
);
// One bit per class per group. At 124 by 13 this is a testbench
// structure, not silicon.
logic seen [MAX_CLASS + 1][N_GROUPS + 1];
logic [3:0] count_for_class;
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n || audit_start) begin
for (int c = 0; c <= MAX_CLASS; c = c + 1)
for (int g = 0; g <= N_GROUPS; g = g + 1)
seen[c][g] <= 1'b0;
n_multi_assigned <= '0;
first_multi_class <= '0;
n_founded <= '0;
n_unsettled <= '0;
end else begin
if (entry_valid && (class_num <= 8'(MAX_CLASS))) begin
// Already in some group? Then this class has two.
count_for_class = '0;
for (int g = 1; g <= N_GROUPS; g = g + 1)
if (seen[class_num][g]) count_for_class = count_for_class + 4'd1;
if (count_for_class != 4'd0 && !seen[class_num][int'(group_id)]) begin
n_multi_assigned <= n_multi_assigned + 8'd1;
if (first_multi_class == 8'd0)
first_multi_class <= class_num;
end
seen[class_num][int'(group_id)] <= 1'b1;
end
if (prov_valid) begin
if (prov_founded) n_founded <= n_founded + 4'd1;
if (prov_founded && !prov_settled)
n_unsettled <= n_unsettled + 4'd1;
end
end
end
always_comb begin
// A partition requires every member in exactly one class. One
// double assignment is enough to destroy it -- which is the point.
taxonomy_is_partition = (n_multi_assigned == 8'd0);
every_group_founded = (n_founded == 4'(N_GROUPS));
// And when it is not a partition, a priority rule is not optional:
// something has to decide which group a dual member reports under.
priority_rule_required = !taxonomy_is_partition;
end
endmoduleClassification, Model or Production? A REVIEW INSTRUMENT, and the only module in this track that audits the track.
What it teaches: that taxonomy_is_partition goes low on the first double assignment and nothing else in the flow notices. A census reports twelve numbers that sum correctly whether the underlying assignment is a partition or not — Section 7's module counts assignments and classes separately for exactly this reason — and only a per-member structure can see the overlap. The module also teaches why priority_rule_required is derived rather than configured: the moment a member has two groups, some rule decides which one a report shows, and the choice is being made whether or not anybody wrote it down.
Deliberately simplified: the seen array is 124 by 13 bits of unpacked storage swept combinationally, which is a testbench structure and would never be synthesised. count_for_class is a blocking-assigned loop inside a clocked block — readable, and a real implementation computes it as a one-hot population count. And prov_settled is a boolean where the real record is a chapter reference, so a production version would carry the citation rather than a bit, which is the difference between "settled" and "settled in Chapter 21.8".
Production implication: the output that matters outside this chapter is priority_rule_required, and it generalises to every classification a project maintains — error taxonomies, severity levels, bug categories, coverage groups. The moment two categories can both apply, a rule decides which one appears in the report, and Chapter 21.2 §2's finding is that the rule is almost always implicit: 7 of 12 reachable frame shapes qualify for more than one error class, and RMON's wording is the only thing that settles it. A project that writes the rule down has one line of documentation; one that does not has a report whose categories mean whatever the implementation decided.
10. What the 124 Have in Common
This is the retrospective's central claim and it needs stating precisely, because the loose version — "they are all mistakes" — is true of any list of mistakes and says nothing.
In every one of the 124 classes, the check's OUTCOME is decided by something other than whether the design is correct.
Not "the property is wrong." Most of the 124 are, as written, true statements about the design. Not "the property fails to catch a bug." Many of them would catch several. The structure is narrower: the property produces an outcome, and the cause of that outcome is somewhere other than the design's behaviour — so the outcome carries no information about the thing the property names.
Five producers, and over the 36 explicit assignments of Section 6 they account for all of them.
| Producer | How the outcome is manufactured | Groups | Assignments |
|---|---|---|---|
| the property's form | the expression does not denote the requirement | 1, 2, 3, 8, 10, 12 | 19 |
| the stimulus | the antecedent stops occurring, so the property stops being evaluated | 9, 7 | 6 |
| the observer | the instrument is part of what it measures, or the measurement does not exist | 11, 4 | 5 |
| the premise's custodian | the premise cannot be constituted by anybody | 5 | 4 |
| the design's own specification | the outcome follows from what the design was built to do | 6 | 2 |
| total | — | all twelve | 36 |
Row one is the largest and the least interesting, because "the property says the wrong thing" is the failure everybody already looks for. Rows two to five are the track's contribution, and three of them share a feature that makes them invisible to code review: nothing is wrong with the text of the property.
Take one member of each of those three and read only the SVA.
| Class | The property, as written | What is wrong |
|---|---|---|
| 97 (Chapter 21.4 §20) | a correct statement about block lock | its antecedent needs a frame, and the fault stops frames — 332 of 557 properties share this |
| 102 (Chapter 21.9 §20) | a correct completeness claim about a capture | the capture's own drops are recorded as the subject's |
| 114 (Chapter 24.3 §20) | a correct conformance check against a specification | the specification's custodian is the design's own organisation |
Three properties, three code reviews, three approvals — and every one of them produces its outcome for a reason that has nothing to do with the design.
And row five is the one that keeps the claim honest, because its members do not pass. Group 6's class 49 asserts the absence of flooding on a switch that is built to flood, so it FAILS — loudly, in week one — and Chapter 24.2 §20 draws exactly that contrast when it places class 113 in group 2. The outcome is still manufactured by something other than the design's correctness: here the design being correct is precisely what produces the failure. Class 115 is the group's other member and produces no outcome in the product at all, because the observer it needs is one the MAC is specified not to contain.
The direction of the wrongness varies. What does not vary is that the outcome's cause is somewhere other than the behaviour being checked.
Which yields the operational form, and it is the sentence the last four chapters have been converging on. A check's worth is the set of observations that would have refuted it, and each producer empties that set differently. The form empties it by asking for an observation that does not bear on the requirement. The stimulus empties it by never producing the observation. The observer empties it by being unable to make it. The custodian empties it by making it unconstitutable. And the specification empties it by guaranteeing the observation in advance.
11. RTL 5 — The Question Model
// ---------------------------------------------------------------------
// question_model -- given a question, decide what it probes and whether
// a strong answer to it is even possible.
//
// The module's purpose is to catch a question that CANNOT discriminate
// before it is asked, which is Section 14's first prohibition and the
// interview form of Chapter 26.1 Section 20's class 121.
// ---------------------------------------------------------------------
module question_model
import probe_pkg::*;
(
input logic clk,
input logic rst_n,
input logic q_valid,
input logic answer_is_a_fact, // one correct string
input logic answer_has_derivation,
input logic [3:0] chapters_required,
input logic common_wrong_answer_exists,
input logic [7:0] max_refutation_count, // of the best answer
output logic out_valid,
output logic probes_recall,
output logic probes_derivation,
output logic probes_composition,
output logic question_can_discriminate,
output logic [7:0] discrimination_range,
output logic is_usable
);
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n) begin
out_valid <= 1'b0;
probes_recall <= 1'b0;
probes_derivation <= 1'b0;
probes_composition <= 1'b0;
question_can_discriminate <= 1'b0;
discrimination_range <= '0;
is_usable <= 1'b0;
end else begin
out_valid <= q_valid;
if (q_valid) begin
// A question with one correct string probes preparation. That
// is real information and it is not engineering information.
probes_recall <= answer_is_a_fact && !answer_has_derivation;
probes_derivation <= answer_has_derivation &&
(chapters_required <= 4'd1);
probes_composition <= answer_has_derivation &&
(chapters_required >= 4'd2);
// The range of refutation counts the question admits. A fact
// admits exactly one value -- zero -- so its range is zero and
// it cannot separate two candidates who both know it.
discrimination_range <= answer_is_a_fact ? 8'd0
: max_refutation_count;
question_can_discriminate <= (max_refutation_count > 8'd1) &&
!answer_is_a_fact;
// Section 2's four-row usability test, as one conjunction.
is_usable <= common_wrong_answer_exists &&
answer_has_derivation &&
(max_refutation_count > 8'd1);
end
end
end
endmoduleClassification, Model or Production? A CLASSIFICATION MODEL.
What it teaches: that discrimination_range is the question's property, not the candidate's. A definitional question has a range of zero however strong the candidate is — there is no answer to "what does MAC stand for" with a refutation count above zero — so the question cannot separate anybody, and asking it produces a score that is constant across the population. That is the interview's form of a check that cannot fail, and the module detects it before the interview rather than after.
Deliberately simplified: max_refutation_count is supplied rather than derived, which means the model inherits whatever ceiling the question's author imagined — and a candidate can exceed it, which is the most useful thing that can happen in an interview and the module has no state for it. chapters_required is also a proxy for composition: two chapters cited is not the same as two ideas combined, and a candidate can compose within one chapter. The honest reading of probes_composition is "this question cannot be answered from one page".
Production implication: run this model over a question list before the interview, and delete every question whose is_usable is low. A twenty-question list typically loses a third of its rows, and the deletions are always the questions that feel safest to ask — definitions, acronyms, the number that is in the first paragraph of the specification. What remains is shorter, harder to write and the only part that produces a comparison, which is the same trade Chapter 26.1 §2 made when it replaced twenty adjectives with twenty numbers.
12. The One Diagnostic Question
Section 2's row 20 is the question this whole chapter exists to derive, and it is not about Ethernet.
"What observation would have changed your answer?"
Four properties make it the right one, and each is a consequence of something earlier in the chapter.
One — it is the refutation count, elicited directly. Section 4 defined an argument's strength as the number of observations that would have refuted it. The question asks for exactly that list, so the grading criterion and the question are the same object, which no other interview question manages.
Two — it separates the model from the vocabulary in one exchange. A candidate who has the model answers immediately with specifics, because the observations are how they arrived at the claim. A candidate who has the vocabulary has never held the claim tentatively, so there is nothing to retrieve — and the silence is the signal rather than a wrong answer.
| The claim | "What would have changed your mind?" | Diagnosis |
|---|---|---|
| "switches flood broadcasts" | "a port count other than 64; a replication engine that deduplicates" | model |
| the same claim | "…nothing, it's just how switches work" | vocabulary |
| "you need 149 descriptors" | "a different line rate — at 400 Gb/s it is 595" | model, and the rate was never mentioned |
| the same claim | "that's the standard figure" | vocabulary, and Chapter 23.4 §7 is being recited |
Three — it works on a subject the interviewer does not know. The count is of observations the candidate names, so a grader who has never read Chapter 23.3 can still tell row one from row two. Every other discriminating question requires the interviewer to be the stronger engineer, which is the condition under which interviews rarely run.
Four — it is unbluffable in a specific, testable way. Section 4's weakness is a candidate padding the list. The defence is one follow-up word — "how?" — and it is the same word regardless of the subject, because an observation that refutes a claim has a mechanism by which it refutes it. "A different port count" refutes 9.375 Gpps because the arithmetic is rate × (N − 1); "a different vendor" refutes nothing until somebody says which behaviour differs.
And the question generalises off Ethernet entirely, which is the last thing worth saying about it. Applied to a design review it is Chapter 26.1 §2's item structure. Applied to a coverage report it is Chapter 26.2 §4's denominator. Applied to a latency figure it is Chapter 26.3 §12's window. Applied to an assertion it is the cover count. The same question, four scales, and in every one of them the answer "nothing" is the finding.
13. RTL 6 — The Vocabulary Detector
A keyword grader and the criterion of Section 4 rank the same four answers in different orders. This module is the demonstration.
// ---------------------------------------------------------------------
// vocabulary_detector -- score one answer two ways and report when the
// two disagree.
//
// The keyword score is included precisely so that its failure is
// visible: it is what an automated screen computes, and Section 4's
// four answers are ranked by it in almost the reverse order.
// ---------------------------------------------------------------------
module vocabulary_detector
import probe_pkg::*;
(
input logic clk,
input logic rst_n,
input logic ans_valid,
input logic [7:0] n_expected_terms_present, // the keyword score
input logic [7:0] n_expected_terms_total,
input logic [7:0] refutation_count, // Section 5
input logic [7:0] n_quantities,
input logic quantity_adapted_to_inputs, // the rate was applied
output logic out_valid,
output logic [19:0] keyword_score_ppm,
output logic [7:0] falsifiability_score,
output logic graders_disagree,
output logic is_vocabulary, // high words, zero refutation
output logic is_model, // refutation, whatever the words
output logic recites_reference // a quantity that did not move
);
logic [19:0] kw;
always_comb begin
kw = (n_expected_terms_total == 8'd0) ? 20'd0
: 20'((int'(n_expected_terms_present) * 1000000)
/ int'(n_expected_terms_total));
end
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n) begin
out_valid <= 1'b0;
keyword_score_ppm <= '0;
falsifiability_score <= '0;
graders_disagree <= 1'b0;
is_vocabulary <= 1'b0;
is_model <= 1'b0;
recites_reference <= 1'b0;
end else begin
out_valid <= ans_valid;
keyword_score_ppm <= kw;
falsifiability_score <= refutation_count;
// The two failure modes the keyword grader cannot see.
is_vocabulary <= (kw >= 20'd800000) && (refutation_count == 8'd0);
is_model <= (refutation_count >= 8'd2);
// Chapter 23.4 Section 7's 149: correct at 100 Gb/s, wrong at 400.
// A quantity that does not move with the inputs is a recitation
// with a number in it, which scores highest of all on keywords.
recites_reference <= (n_quantities != 8'd0) &&
!quantity_adapted_to_inputs;
// The headline: the two graders rank this answer differently.
graders_disagree <= ((kw >= 20'd800000) && (refutation_count < 8'd2))
|| ((kw < 20'd400000) && (refutation_count >= 8'd3));
end
end
endmoduleClassification, Model or Production? A COMPARISON MODEL, and its only purpose is to make a disagreement visible.
What it teaches: that a high keyword score and a zero refutation count co-occur constantly, and that combination is the definition of the failure this chapter is about. The second disjunct of graders_disagree is the more valuable one: a low keyword score with a refutation count of three or more is a candidate who answered in their own words and is being screened out, which is the automated version of the same error and much harder to detect because nobody is in the room.
Deliberately simplified: quantity_adapted_to_inputs is a boolean supplied by the interviewer, and the only reliable way to set it is to change the rate and watch whether the number moves — which is a deliberate second question rather than an observation. n_expected_terms_total also assumes a fixed expected vocabulary, which is exactly the assumption that makes keyword grading fail: a strong answer routinely uses terms the question's author did not list.
Production implication: if an organisation screens written answers automatically, run both scores and review every case where they disagree. The volume is manageable — disagreement is the exception — and the reviewed set is exactly the population the automated screen gets wrong in both directions. The cost is a second integer per answer; the failure it prevents is an automated filter whose criterion is that the candidate used the same words as whoever wrote the question, which selects for having read the same material rather than for being able to derive anything.
14. What an Interviewer Must Never Do
Six prohibitions. Each one converts an interview into an exercise that produces a score and no information.
| # | Never | Because |
|---|---|---|
| 1 | ask a question whose discrimination range is zero | Section 11 — a definition separates nobody |
| 2 | supply the rate, the port count or the frame size unasked | Section 2 row 9 — whether they ask IS the signal |
| 3 | grade by whether a term appeared | Section 13 — the two graders rank the same four answers differently |
| 4 | accept a reference value without changing an input | Chapter 23.4 §7 — 149 is right at 100 Gb/s and 595 at 400 |
| 5 | record an adjective | Section 12 — twenty integers can be compared and twenty adjectives cannot |
| 6 | reward fluency | Section 4 — a five-minute answer naming nothing scores zero, and it is the easiest answer to enjoy |
Prohibition 6 is the one that needs a mechanism rather than a rule, because it operates below anybody's intention. Fluency is what an interviewer perceives without effort, so an ungraded interview converges on it regardless of what the panel believes it is measuring. The mechanism is step five of Section 12's procedure: write the integer during the answer, not after it. An integer written afterwards is reconstructed from an impression, and the impression is the thing being guarded against.
Prohibition 2 deserves a worked example because it feels unhelpful and is not. Asked "how deep should the prefetch store be", the strong answer begins "at what rate, and what host latency?" — and an interviewer who has already said "at 100 Gb/s" has thrown away the entire signal and left a recall question behind. The same applies to "what is the latency of a switch", where the answer is a question about the regime, and to "what is your coverage", where the answer is a question about the denominator.
15. RTL 7 — Probe Telemetry
// ---------------------------------------------------------------------
// probe_telemetry -- what a panel should be able to read about its own
// process, as counters rather than impressions.
//
// Every output here is a property of the INTERVIEW rather than of the
// candidate, which is the distinction Section 14 is built on.
// ---------------------------------------------------------------------
module probe_telemetry
import probe_pkg::*;
(
input logic clk,
input logic rst_n,
input logic session_start,
input logic q_asked,
input logic q_can_discriminate, // Section 11
input logic q_inputs_supplied, // prohibition 2 violated
input logic ans_valid,
input logic [7:0] ans_refutation_count,
input logic ans_is_vocabulary,
input logic ans_recites_reference,
input logic graded_by_keyword, // prohibition 3 violated
input logic graded_as_adjective, // prohibition 5 violated
input logic reference_input_changed,
output logic [7:0] c_questions,
output logic [7:0] c_discriminating,
output logic [7:0] c_inputs_supplied,
output logic [15:0] sum_refutation,
output logic [7:0] c_vocabulary_answers,
output logic [7:0] c_reference_recitations,
output logic [19:0] discriminating_share_ppm,
output logic [15:0] mean_refutation_x100,
output logic v_nondiscriminating_question,
output logic v_inputs_supplied,
output logic v_keyword_grading,
output logic v_adjective_recorded,
output logic v_reference_untested,
output logic session_is_informative
);
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n || session_start) begin
c_questions <= '0;
c_discriminating <= '0;
c_inputs_supplied <= '0;
sum_refutation <= '0;
c_vocabulary_answers <= '0;
c_reference_recitations <= '0;
end else begin
if (q_asked) begin
c_questions <= c_questions + 8'd1;
if (q_can_discriminate)
c_discriminating <= c_discriminating + 8'd1;
if (q_inputs_supplied)
c_inputs_supplied <= c_inputs_supplied + 8'd1;
end
if (ans_valid) begin
sum_refutation <= sum_refutation + 16'(ans_refutation_count);
if (ans_is_vocabulary)
c_vocabulary_answers <= c_vocabulary_answers + 8'd1;
if (ans_recites_reference)
c_reference_recitations <= c_reference_recitations + 8'd1;
end
end
end
always_comb begin
discriminating_share_ppm = (c_questions == 8'd0) ? 20'd0
: 20'((int'(c_discriminating) * 1000000) / int'(c_questions));
mean_refutation_x100 = (c_questions == 8'd0) ? 16'd0
: 16'((int'(sum_refutation) * 100) / int'(c_questions));
v_nondiscriminating_question = (c_discriminating < c_questions);
v_inputs_supplied = (c_inputs_supplied != 8'd0);
v_keyword_grading = graded_by_keyword;
v_adjective_recorded = graded_as_adjective;
// A quantity accepted without moving an input. Prohibition 4.
v_reference_untested = (c_reference_recitations != 8'd0) &&
!reference_input_changed;
// A session is informative when its questions could separate
// candidates and its record is numeric.
session_is_informative = (c_questions != 8'd0) &&
!v_nondiscriminating_question &&
!v_adjective_recorded;
end
endmoduleClassification, Model or Production? A PROCESS INSTRUMENT.
What it teaches: that the panel's own behaviour is the thing most worth counting. c_inputs_supplied is a count of times an interviewer answered part of their own question, and it is invisible in every debrief because nobody records it — yet it is the single fastest way to convert a composition question into a recall question. The module also teaches that mean_refutation_x100 is a property of the session rather than of the candidate: a mean near zero across twenty questions says either that the candidate has no model or that the questions could not have revealed one, and discriminating_share_ppm is what tells the two apart.
Deliberately simplified: every judgement input is a boolean set by a human, so the module records a process rather than enforcing it — there is no mechanism here that prevents prohibition 3, only one that counts it. mean_refutation_x100 also treats all twenty questions as equally weighted, where a composition question legitimately admits a higher count than a single-chapter one; a real implementation normalises by each question's max_refutation_count. And there is no candidate identity anywhere in the module, which is deliberate: the outputs are about the session.
Production implication: publish discriminating_share_ppm per interviewer, per quarter. It is a number about the question list rather than about anybody's judgement, so it is a safe thing to measure and it moves the behaviour that matters: an interviewer whose share is 400 000 ppm is asking twelve questions out of twenty that cannot separate two candidates, and the remedy is to rewrite the list rather than to train the interviewer. The failure it prevents is a panel that is confident, consistent and measuring preparation, which is a stable state that nothing inside the process disturbs.
16. RTL 8 — The Probe Conformance Monitor
// ---------------------------------------------------------------------
// probe_conformance -- the sign-off gate for an interview process,
// in the same shape as Chapter 26.1 Section 16, Chapter 26.2 Section 16
// and Chapter 26.3 Section 16.
//
// The design rule is identical and it is the track's last statement of
// it: every check must be able to fail on a process somebody would
// really run, and the gate must say so about itself.
// ---------------------------------------------------------------------
module probe_conformance
import probe_pkg::*;
(
input logic clk,
input logic rst_n,
input logic evaluate,
input logic [7:0] c_questions,
input logic [7:0] c_discriminating,
input logic [7:0] c_inputs_supplied,
input logic [7:0] c_reference_recitations,
input logic reference_input_changed,
input logic graded_by_keyword,
input logic graded_as_adjective,
input logic diagnostic_question_asked, // Section 12
input logic mechanisms_requested, // the "how?" follow-up
input logic [15:0] sum_refutation,
output logic c1_questions_discriminate,
output logic c2_inputs_withheld,
output logic c3_not_keyword_graded,
output logic c4_references_tested,
output logic c5_record_is_numeric,
output logic c6_diagnostic_asked,
output logic c7_mechanisms_requested,
output logic [2:0] n_failures,
output logic conformant,
output logic gate_can_fail
);
logic [2:0] fails;
always_comb begin
// 1. Every question could separate two candidates. Section 11.
c1_questions_discriminate = (c_questions != 8'd0) &&
(c_discriminating == c_questions);
// 2. No question had its own inputs supplied. Prohibition 2.
c2_inputs_withheld = (c_inputs_supplied == 8'd0);
// 3. Grading was not by term presence. Prohibition 3.
c3_not_keyword_graded = !graded_by_keyword;
// 4. Every reference value was tested by moving an input, or none
// was offered. Prohibition 4.
c4_references_tested = (c_reference_recitations == 8'd0) ||
reference_input_changed;
// 5. The record is integers. Prohibition 5.
c5_record_is_numeric = !graded_as_adjective;
// 6. Section 12's question was asked at least once.
c6_diagnostic_asked = diagnostic_question_asked;
// 7. And its list was tested for mechanisms. Section 4's weakness.
c7_mechanisms_requested = !diagnostic_question_asked ||
mechanisms_requested;
fails = 3'(!c1_questions_discriminate) + 3'(!c2_inputs_withheld)
+ 3'(!c3_not_keyword_graded) + 3'(!c4_references_tested)
+ 3'(!c5_record_is_numeric) + 3'(!c6_diagnostic_asked)
+ 3'(!c7_mechanisms_requested);
// A session with no questions passes checks 2 to 5 trivially and
// fails 1 and 6, which is the correct outcome -- but the bit is
// here because the track's last gate should state its own premise.
gate_can_fail = (c_questions != 8'd0);
end
always_ff @(posedge clk or negedge rst_n) begin
if (!rst_n) begin
n_failures <= '0;
conformant <= 1'b0;
end else if (evaluate) begin
n_failures <= fails;
conformant <= (fails == 3'd0) && gate_can_fail;
end
end
endmoduleClassification, Model or Production? A SIGN-OFF GATE, and the track's last one.
What it teaches: that check 7's implication is the shape that keeps a gate honest. !diagnostic_question_asked || mechanisms_requested passes when the diagnostic question was never asked, which looks like a loophole and is not — check 6 already fails in that case, and stacking the same failure into two checks would double-count it. A gate whose checks overlap reports a failure count that does not mean what it says, which is Chapter 26.2 §20's cardinality problem in a small way.
Deliberately simplified: every input is a boolean or a count supplied by the panel, so this gate audits a self-report. That is Chapter 26.1 §10's self-witnessed claim and there is no way around it here — an interview has no independent instrument, which is why the chapter's recommendation is two interviewers and two integer lists rather than a better gate. sum_refutation is also an unused input, kept deliberately: it is the candidate's score, and no check in this gate reads it, because the gate is about the process.
Production implication: run this once per panel per quarter, not per interview. Six of the seven checks are properties of the question list and the recording convention — they change rarely and they are the things worth fixing — and only check 4 is about a single session. A panel that passes all seven has a process whose output is twenty integers per candidate on twenty questions that could each have gone either way, which is the most an interview can honestly produce.
17. What a Strong Answer Costs to Produce
The chapter has been about grading. This section is about the other side, because a criterion nobody can meet is a criterion that selects for nothing.
Take Section 4's strongest answer and count what producing it required.
"No — one flooding port sends 63 copies, so at 148.81 Mpps that is 9.375 Gpps, and that is 98.4% of the switch's 9.524 Gpps frame budget. One port can consume the fabric."
| The answer needs | From |
|---|---|
| that flooding is replication, N − 1 copies | Chapter 12.4 §3 |
| 148.81 Mpps at 100 Gb/s, minimum frames | Chapter 8.1 §2 |
| a 64-port switch's aggregate frame budget — 9.524 Gpps | Chapter 23.3 §3 |
| that the two are comparable at all | Chapter 25.5 §2 |
Four chapters, one sentence, and the composition is the work. No single chapter contains the answer; the third and fourth are in different modules, and the candidate who can produce it has connected a foundation-level serialisation figure to a switch-scale budget.
Which sets the honest expectation for what the criterion measures.
| Refutation count | What it indicates | Roughly |
|---|---|---|
| 0 | the vocabulary, and possibly a correct fact | has read about it |
| 1 | a claim held tentatively | has thought about it |
| 2 to 3 | a derivation with its inputs identified | has done it |
| 4 or more | a composition across chapters, with the inputs of each | has done it more than once |
And the fourth row is rarer than it sounds, because it requires the candidate to know which of their own inputs are uncertain. Naming four observations that would refute a claim means holding four beliefs as revisable at once, which is a different skill from knowing four facts and is the one the criterion is aimed at.
18. What This Chapter Assumes
Six assumptions, and three of them are weaker than any in the track's other twenty-five modules — which is worth saying plainly, because this chapter's subject is not silicon.
| # | Assumption | If it is false |
|---|---|---|
| 1 | a refutation count can be elicited reliably | the whole criterion degrades to an interviewer's impression |
| 2 | an observation without a mechanism can be recognised | Section 4's padding defence fails and counts inflate |
| 3 | Section 6's 35 explicit assignments are the complete explicit set | the census's denominator moves; the shape does not |
| 4 | class 91 is the only dual member | Section 8's conclusion strengthens rather than weakens |
| 5 | falsifiability correlates with engineering ability | the criterion measures something real and not the thing wanted |
| 6 | the five producers of Section 10 are exhaustive over the series | a sixth producer exists among the 89 unassigned classes |
Assumption 5 is the load-bearing one and it cannot be discharged from inside the chapter. Everything here establishes that the refutation count is measurable, comparable and not gameable in the obvious way. None of it establishes that a candidate with a high count is a better engineer — that is an empirical claim about hiring outcomes and this chapter has no data on it. What can be said is narrower and still useful: the count measures whether somebody holds their claims revisably, with named grounds, and that is a property the whole track has been arguing matters.
Assumption 3 is the one a reader can check and should. The census counts classes whose own callout names a group. A reader who finds a thirty-sixth would move n_classes_seen from 35 to 36 and explicit_share_ppm from 282 258 to 290 322, and change nothing about Section 8, because the partition argument needs only one dual member and it has one.
Assumption 6 is the one this chapter is least able to defend. The five producers were derived from the 35 assigned classes and the series is 124 long. Eighty-nine classes have not been sorted, and a sixth producer among them is entirely possible. The honest form of Section 10's claim is therefore: over the 36 explicit assignments, five producers account for all of them — which is what its table says, with the denominator in the last column.
And assumption 4 has an asymmetry worth naming. If a second dual member exists, Section 8's conclusion gets stronger: one overlap makes the taxonomy a non-partition, and two make the missing priority rule a systematic gap rather than an oversight. So the assumption is safe in the direction that matters, which is rare enough to be worth pointing out.
19. The Track, Accounted
Twenty-six modules, and this is the last accounting section. It is a census rather than a cost, because the track is not a design.
| Quantity | Value |
|---|---|
| chapters | 140 |
| modules | 26 |
| rejected-property classes | 124, none repeated |
| taxonomy groups | 12, founded across six chapters between Chapter 20.2 and Chapter 22.2 |
| classes with an explicit group | 35 — 28.23% |
| group assignments | 36 |
| classes in two groups | 1 — class 91 |
| thirteenth-group bar, consecutive holds | 16, since Chapter 22.3 §20 |
And the three units the track converged on, each introduced where it was first needed.
| Unit | Definition | First derived |
|---|---|---|
| BCE | one bit of usable on-die SRAM; 0.35 GE; 20 to a flip-flop | Chapter 23.3 §2 |
| the MAC receive datapath | 14 166 flops — 283 320 BCE | Chapter 19.7 §19 |
| the refutation count | observations that would have changed the answer | this chapter, §4 |
Two reference quantities anchor most of the track's comparisons and both are worth carrying.
| Reference | Value | What it prices |
|---|---|---|
| a 64-port 100 Gb/s switch | 5.62 × 10⁸ BCE — 1 985 datapaths | anything at fabric scale |
| a MAC receive datapath | 283 320 BCE | anything at port scale |
And the three arithmetic results that recur most often across the modules.
| Result | Value | Chapter |
|---|---|---|
| minimum-frame packet rate at 100 Gb/s | 148.81 Mpps | Chapter 8.1 §2 |
| a 64-port switch's aggregate frame budget | 9.524 Gpps | Chapter 23.3 §3 |
| properties whose antecedent needs traffic | 332 of 557 — 59.6% | Chapter 21.4 §20 |
20. Properties Worth Asserting, and One Worth Refusing
Fifty-three properties in six groups, over the answer model, the refutation counter, the census, the auditor, the detectors and the gate. They are the last properties in the track.
Group A — the answer model, Section 3.
// 1. Falsifiability is exactly a non-zero refutation count.
p_falsifiable_iff_nonzero: assert property (@(posedge clk) disable iff (!rst_n)
out_valid |-> (is_falsifiable == (refutation_count != 8'd0)));
// 2. And recitation is exactly its complement.
p_recitation_complement: assert property (@(posedge clk) disable iff (!rst_n)
out_valid |-> (is_recitation != is_falsifiable));
// 3. A zero count with a quantity is a recitation, not an absence --
// the most deceptive kind, because it looks quantitative.
p_zero_with_quantity: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && $past(n_refuting_observations) == 8'd0 && $past(has_quantity))
|-> (kind == ANS_RECITATION));
// 4. A derived quantity composing two or more chapters is COMPOSED.
p_composed_needs_two: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && kind == ANS_COMPOSED) |-> ($past(n_chapters_composed) >= 4'd2));
// 5. The reference-value flag needs a quantity that did not adapt.
p_ref_risk_definition: assert property (@(posedge clk) disable iff (!rst_n)
out_valid |-> (reference_value_risk ==
($past(has_quantity) && $past(quantity_copied))));
// 6. The grade never depends on any term being present -- there is no
// such input. Expressed as: two answers with equal structure grade
// equally.
p_grade_is_structural: assert property (@(posedge clk) disable iff (!rst_n)
($past(n_refuting_observations) == $past(n_refuting_observations, 2) &&
$past(has_quantity) == $past(has_quantity, 2) &&
$past(quantity_is_derived) == $past(quantity_is_derived, 2) &&
$past(n_chapters_composed) == $past(n_chapters_composed, 2) &&
out_valid && $past(out_valid))
|-> (kind == $past(kind)));
// 7. Every producer of the taxonomy maps to exactly one group family.
p_producer_total: assert property (@(posedge clk) disable iff (!rst_n)
out_valid |-> (producer_of(GRP_PREMISE) == PROD_CUSTODIAN));
// 8. And group 6 maps to the specification, which is the producer whose
// members do not pass. Section 10.
p_designed_is_spec: assert property (@(posedge clk) disable iff (!rst_n)
out_valid |-> (producer_of(GRP_DESIGNED) == PROD_SPEC));
c_recitation_seen: cover property (@(posedge clk) out_valid && is_recitation);
c_composed_seen: cover property (@(posedge clk) out_valid && kind == ANS_COMPOSED);Group B — the refutation counter, Section 5.
// 9. The four dispositions partition the offers.
p_offers_partition: assert property (@(posedge clk) disable iff (!rst_n)
(n_counted + n_no_mechanism + n_irrelevant + n_duplicate == n_offered));
// 10. Counted never exceeds offered.
p_counted_le_offered: assert property (@(posedge clk) disable iff (!rst_n)
(n_counted <= n_offered));
// 11. An observation with no mechanism never counts, whatever else is
// true of it. Section 4's padding defence.
p_no_mechanism_never_counts: assert property (@(posedge clk) disable iff (!rst_n)
(obs_valid && !obs_has_mechanism)
|-> ##1 (n_counted == $past(n_counted)));
// 12. Precision is bounded and is a proper fraction.
p_precision_bounded: assert property (@(posedge clk) disable iff (!rst_n)
(precision_ppm <= 20'd1000000));
// 13. Falsifiability follows the counted total, not the offered one.
p_falsifiable_from_counted: assert property (@(posedge clk) disable iff (!rst_n)
(answer_is_falsifiable == (n_counted != 8'd0)));
// 14. Padding needs volume as well as a poor ratio -- two offers and
// one hit is not padding.
p_padding_needs_volume: assert property (@(posedge clk) disable iff (!rst_n)
padding_detected |-> (n_offered >= 8'd4));
// 15. A restart clears everything.
p_restart_clears: assert property (@(posedge clk) disable iff (!rst_n)
answer_start |-> ##1 (n_offered == 8'd0 && n_counted == 8'd0));
c_padding_seen: cover property (@(posedge clk) padding_detected);
c_perfect_precision: cover property (@(posedge clk)
n_offered >= 8'd3 && precision_ppm == 20'd1000000);Group C — the census, Section 7.
// 16. Classes and assignments are counted separately and assignments
// never fall below classes. Chapter 26.2 Section 20's class 122 is
// the reason both exist.
p_assignments_ge_classes: assert property (@(posedge clk) disable iff (!rst_n)
(n_assignments >= n_classes_seen));
// 17. Their difference is exactly the multi-group count.
p_difference_is_multi: assert property (@(posedge clk) disable iff (!rst_n)
(n_assignments - n_classes_seen == n_multi_group));
// 18. The unassigned count closes the series.
p_unassigned_closes: assert property (@(posedge clk) disable iff (!rst_n)
(n_classes_seen + n_unassigned == 8'(N_CLASSES)));
// 19. The explicit share is a proper fraction of 124.
p_explicit_share: assert property (@(posedge clk) disable iff (!rst_n)
(explicit_share_ppm <= 20'd1000000));
// 20. The per-group totals sum to the assignment count.
p_groups_sum: assert property (@(posedge clk) disable iff (!rst_n)
census_start |-> ##1 (per_group[1] + per_group[2] + per_group[3] +
per_group[4] + per_group[5] + per_group[6] +
per_group[7] + per_group[8] + per_group[9] +
per_group[10] + per_group[11] + per_group[12]
== n_assignments));
// 21. The denominator flag is exactly the explicit equality.
p_denominator_flag: assert property (@(posedge clk) disable iff (!rst_n)
(census_is_over_explicit == (n_explicit == n_assignments)));
c_multi_group_seen: cover property (@(posedge clk) n_multi_group != 8'd0);Group D — the group auditor, Section 9.
// 22. A partition means no class has two groups.
p_partition_definition: assert property (@(posedge clk) disable iff (!rst_n)
(taxonomy_is_partition == (n_multi_assigned == 8'd0)));
// 23. And when it is not a partition, a priority rule is required.
p_rule_required: assert property (@(posedge clk) disable iff (!rst_n)
(priority_rule_required != taxonomy_is_partition));
// 24. The first multi-assigned class is recorded, because "which one"
// is the whole finding and a count does not say.
p_first_multi_recorded: assert property (@(posedge clk) disable iff (!rst_n)
(n_multi_assigned != 8'd0) |-> (first_multi_class != 8'd0));
// 25. An unsettled group is a founded group, always.
p_unsettled_subset: assert property (@(posedge clk) disable iff (!rst_n)
(n_unsettled <= n_founded));
// 26. Every group founded means twelve.
p_all_founded: assert property (@(posedge clk) disable iff (!rst_n)
(every_group_founded == (n_founded == 4'(N_GROUPS))));
// 27. Re-asserting a class into a group it already has changes nothing.
p_idempotent: assert property (@(posedge clk) disable iff (!rst_n)
(entry_valid && seen[class_num][int'(group_id)])
|-> ##1 (n_multi_assigned == $past(n_multi_assigned)));
c_not_partition: cover property (@(posedge clk) !taxonomy_is_partition);
c_unsettled_group: cover property (@(posedge clk) n_unsettled != 4'd0);Group E — the question model and the vocabulary detector, Sections 11 and 13.
// 28. A factual question has a discrimination range of zero.
p_fact_range_zero: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && $past(answer_is_a_fact)) |-> (discrimination_range == 8'd0));
// 29. And therefore cannot discriminate.
p_fact_cannot_discriminate: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && $past(answer_is_a_fact)) |-> !question_can_discriminate);
// 30. The three probe kinds are mutually exclusive.
p_probe_exclusive: assert property (@(posedge clk) disable iff (!rst_n)
out_valid |-> $onehot0({probes_recall, probes_derivation,
probes_composition}));
// 31. Usability requires all three of Section 2's conditions.
p_usable_conjunction: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && is_usable) |-> ($past(common_wrong_answer_exists) &&
$past(answer_has_derivation) &&
($past(max_refutation_count) > 8'd1)));
// 32. Composition needs two chapters.
p_composition_two: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && probes_composition) |-> ($past(chapters_required) >= 4'd2));
// 33. Vocabulary is high keyword score and zero refutation.
p_vocabulary_definition: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && is_vocabulary) |-> (keyword_score_ppm >= 20'd800000) &&
(falsifiability_score == 8'd0));
// 34. Model and vocabulary are never both high.
p_model_xor_vocabulary: assert property (@(posedge clk) disable iff (!rst_n)
out_valid |-> !(is_model && is_vocabulary));
// 35. A quantity that did not move with the inputs is flagged.
p_reference_recited: assert property (@(posedge clk) disable iff (!rst_n)
(out_valid && $past(n_quantities) != 8'd0 &&
!$past(quantity_adapted_to_inputs)) |-> recites_reference);
// 36. The keyword score is a proper fraction.
p_keyword_bounded: assert property (@(posedge clk) disable iff (!rst_n)
(keyword_score_ppm <= 20'd1000000));
c_graders_disagree: cover property (@(posedge clk) out_valid && graders_disagree);
c_low_words_high_refutation: cover property (@(posedge clk)
out_valid && keyword_score_ppm < 20'd400000 && falsifiability_score >= 8'd3);Group F — telemetry and the gate, Sections 15 and 16.
// 37. Discriminating questions are a subset of questions asked.
p_disc_subset: assert property (@(posedge clk) disable iff (!rst_n)
(c_discriminating <= c_questions));
// 38. And the flag is the strict inequality.
p_nondisc_flag: assert property (@(posedge clk) disable iff (!rst_n)
(v_nondiscriminating_question == (c_discriminating < c_questions)));
// 39. The share is a proper fraction.
p_share_bounded: assert property (@(posedge clk) disable iff (!rst_n)
(discriminating_share_ppm <= 20'd1000000));
// 40. Supplying a question's own inputs is counted, every time.
p_inputs_counted: assert property (@(posedge clk) disable iff (!rst_n)
(q_asked && q_inputs_supplied)
|-> ##1 (c_inputs_supplied == $past(c_inputs_supplied) + 8'd1));
// 41. A session with an adjective record is never informative.
p_adjective_not_informative: assert property (@(posedge clk) disable iff (!rst_n)
graded_as_adjective |-> !session_is_informative);
// 42. No output of the telemetry depends on the candidate's score.
p_telemetry_ignores_score: assert property (@(posedge clk) disable iff (!rst_n)
(session_is_informative == ((c_questions != 8'd0) &&
!v_nondiscriminating_question &&
!v_adjective_recorded)));
// 43. Gate check 1 fails on any non-discriminating question.
p_c1_fails: assert property (@(posedge clk) disable iff (!rst_n)
(evaluate && c_discriminating < c_questions)
|-> ##1 !c1_questions_discriminate);
// 44. Check 4 passes when no reference value was offered.
p_c4_vacuous_ok: assert property (@(posedge clk) disable iff (!rst_n)
(evaluate && c_reference_recitations == 8'd0) |-> ##1 c4_references_tested);
// 45. Check 7's implication passes when the question was not asked --
// check 6 already owns that failure and stacking it double-counts.
p_c7_implication: assert property (@(posedge clk) disable iff (!rst_n)
(evaluate && !diagnostic_question_asked) |-> ##1 c7_mechanisms_requested);
// 46. And check 6 fails in exactly that case.
p_c6_fails_then: assert property (@(posedge clk) disable iff (!rst_n)
(evaluate && !diagnostic_question_asked) |-> ##1 !c6_diagnostic_asked);
// 47. A session with no questions is never conformant.
p_no_questions_fails: assert property (@(posedge clk) disable iff (!rst_n)
(evaluate && c_questions == 8'd0) |-> ##1 !conformant);
// 48. Conformance requires the gate to be non-trivial.
p_conformant_needs_gate: assert property (@(posedge clk) disable iff (!rst_n)
conformant |-> $past(gate_can_fail));
// 49. The gate reads no candidate score. sum_refutation is unused and
// the property records that deliberately.
p_gate_ignores_candidate: assert property (@(posedge clk) disable iff (!rst_n)
(evaluate && $past(sum_refutation) != sum_refutation)
|-> ##1 (conformant == $past(conformant, 1) || $past(evaluate)));
// 50. And the verdict holds between evaluations.
p_verdict_stable: assert property (@(posedge clk) disable iff (!rst_n)
!evaluate |-> ##1 (conformant == $past(conformant)));
c_session_conformant: cover property (@(posedge clk) evaluate && conformant);
c_inputs_supplied: cover property (@(posedge clk) v_inputs_supplied);
c_keyword_graded: cover property (@(posedge clk) v_keyword_grading);
c_reference_untested: cover property (@(posedge clk) v_reference_untested);21. Verification Scenarios
Fifty-eight scenarios in six groups, plus one directed test random stimulus will not produce.
Group 1 — the answer model (10).
| # | Scenario | Expect |
|---|---|---|
| 1 | zero refuting observations, no quantity | ANS_ABSENT; is_recitation high |
| 2 | zero refuting observations, a correct quantity | ANS_RECITATION — the deceptive kind |
| 3 | one observation, no quantity | ANS_CLAIM |
| 4 | three observations, a quantity, not derived | ANS_QUANTIFIED |
| 5 | three observations, derived, one chapter | ANS_DERIVED |
| 6 | five observations, derived, four chapters | ANS_COMPOSED |
| 7 | "149 descriptors", rate never mentioned | reference_value_risk high |
| 8 | "595 at 400 Gb/s, it is rate × latency" | risk low; composed |
| 9 | two answers with identical structure, different words | identical grade — p_grade_is_structural |
| 10 | group 6's producer | PROD_SPEC — the outcome is a FAILURE, and still manufactured |
Group 2 — the refutation counter (10).
| # | Scenario | Expect |
|---|---|---|
| 11 | three offers, three mechanisms, all bearing | n_counted = 3; precision 1 000 000 ppm |
| 12 | five offers, two with no mechanism | n_counted = 3; n_no_mechanism = 2 |
| 13 | "a different vendor", no mechanism given | n_no_mechanism increments; does not count |
| 14 | "a different port count — the arithmetic is rate × (N − 1)" | counts |
| 15 | eight offers, two counted | padding_detected; precision 250 000 ppm |
| 16 | three offers, two counted | no padding — below the volume floor |
| 17 | two offers, two counted | precision 1 000 000; stronger than scenario 15 |
| 18 | a duplicate of a counted observation | n_duplicate; not counted twice |
| 19 | zero offers | answer_is_falsifiable low; precision 0 |
| 20 | answer_start mid-answer | all counters clear |
Group 3 — the census (9).
| # | Scenario | Expect |
|---|---|---|
| 21 | the full explicit set | n_classes_seen = 35; n_assignments = 36 |
| 22 | the same | n_multi_group = 1; n_unassigned = 89 |
| 23 | the explicit share | 282 258 ppm — 28.23% |
| 24 | a thirty-sixth explicit class found | 290 322 ppm; Section 8 unchanged |
| 25 | the per-group totals | sum to 36, not 35 |
| 26 | the largest group | 10, with 6 members |
| 27 | groups 5, 8 and 9 | 4 each — a three-way tie the module breaks by arrival |
| 28 | group 3 | 1 member — class 105 |
| 29 | a census over inferred assignments | census_is_over_explicit LOW — the denominator changed |
Group 4 — the group auditor (10).
| # | Scenario | Expect |
|---|---|---|
| 30 | class 91 into group 7, then group 9 | n_multi_assigned = 1; first_multi_class = 91 |
| 31 | the same | taxonomy_is_partition LOW |
| 32 | and therefore | priority_rule_required HIGH |
| 33 | class 91 into group 7 twice | no change — p_idempotent |
| 34 | every class in exactly one group | partition high; rule not required |
| 35 | twelve groups founded | every_group_founded high |
| 36 | group 9 founded, not settled | n_unsettled = 1 |
| 37 | Chapter 21.4 defers to Chapter 21.6; 21.6 is silent | unsettled |
| 38 | Chapter 21.5 defers to Chapter 21.8; 21.8 founds group 10 | still unsettled |
| 39 | a second dual member discovered | n_multi_assigned = 2; the conclusion STRENGTHENS |
Group 5 — questions and grading (10).
| # | Scenario | Expect |
|---|---|---|
| 40 | "what does MAC stand for?" | range 0; cannot discriminate; not usable |
| 41 | "why 64 octets?" | derivation; usable |
| 42 | "where does a hop's latency go?" | composition — three chapters |
| 43 | a question with no common wrong answer | not usable |
| 44 | a question whose best answer scores 1 | not usable — range must exceed one |
| 45 | keyword 900 000 ppm, refutation 0 | is_vocabulary; graders_disagree |
| 46 | keyword 300 000 ppm, refutation 4 | is_model; graders_disagree — the automated screen's error |
| 47 | keyword 900 000 ppm, refutation 4 | is_model; no disagreement |
| 48 | a quantity offered, no input changed | recites_reference |
| 49 | is_model and is_vocabulary | never both — p_model_xor_vocabulary |
Group 6 — telemetry and the gate (9).
| # | Scenario | Expect |
|---|---|---|
| 50 | 20 questions, 12 discriminating | 600 000 ppm; v_nondiscriminating_question |
| 51 | 20 of 20 discriminating | 1 000 000 ppm; check 1 passes |
| 52 | the interviewer states the line rate unasked | c_inputs_supplied = 1; check 2 fails |
| 53 | a rating out of five recorded | v_adjective_recorded; check 5 fails; not informative |
| 54 | a reference value offered, no input moved | v_reference_untested; check 4 fails |
| 55 | no reference value offered at all | check 4 PASSES — vacuously and correctly |
| 56 | the diagnostic question not asked | check 6 fails; check 7 passes — no double count |
| 57 | zero questions asked | gate_can_fail low; conformant LOW |
| 58 | all seven checks clear on a real session | conformant high |
22. Debugging an Interview That Told You Nothing
Six symptoms. Every one of them is a property of the process rather than of a candidate.
| Symptom | First question | Where to look |
|---|---|---|
| every candidate scores about the same | what is the discrimination range of the questions? | Section 11 — a definitional question separates nobody |
| the panel agrees and cannot say about what | was the record integers or adjectives? | Section 12 step five |
| strong hires who cannot size anything | was any reference value tested by moving an input? | Section 14 — the two-minute test |
| the screen and the interview disagree constantly | is the screen counting terms? | Section 13 — graders_disagree, in both directions |
| a candidate who talked well and knew nothing | what was the refutation count? | Section 4 — fluency is what an interviewer perceives for free |
| a question that always produces the same answer | did the interviewer supply the inputs? | Section 14 prohibition 2 |
Row one has a procedure that takes ten minutes and runs before any interview. For each question, ask: is there a common wrong answer, does the right answer have a derivation, and can the best answer name more than one refuting observation? A twenty-question list typically loses six or seven rows, and every deleted row is one that was producing a constant.
Row three has the sharpest diagnostic in the chapter and it is fifteen seconds. Take any quantity the candidate offered and change one of its inputs. Chapter 23.4 §7's 149 becomes 595 at 400 Gb/s and 446 at a 3 µs host tail. A derived answer moves; a remembered one does not, and the interviewer needs to know only that it should move.
23. Misconceptions
Six, in the wrong-model / what-it-costs / corrected-model form this track has used since Chapter 1.1 — and this is the last set.
Misconception 1 — "An interview tests what somebody knows."
Wrong model. The candidate has a body of knowledge and the interview samples it.
What it costs. Section 21's directed test: two candidates, twenty questions, every fact correct in both, and the automated screen ranks the weaker one higher. Every conventional observable ties — facts, terms, quantities, time — and the two differ by a factor of 31.5 in refutation count. The cost is hiring candidate A, whose first decision at 400 Gb/s uses a number derived for 100.
Corrected model. An interview tests whether somebody can DERIVE, and the test is to change an input. Chapter 23.4 §7's 149 becomes 595 at 400 Gb/s; a derived answer moves and a remembered one does not. Knowledge and derivation are indistinguishable in every artefact either produces, until the world is allowed to answer back.
Misconception 2 — "A good answer is one that covers the key points."
Wrong model. There is a model answer, and grading measures the overlap with it.
What it costs. Section 13's second disjunct: a candidate answering in their own words with a refutation count of four scores 300 000 ppm on keywords and gets screened out. The overlap criterion selects for having read the same material as whoever wrote the question, which is a real signal about preparation and none about engineering.
Corrected model. Grade by the refutation count and the model answer becomes a floor rather than a template. A candidate exceeding the question author's own max_refutation_count is the most useful thing that can happen in an interview, and an overlap criterion cannot represent it.
Misconception 3 — "The 124 classes are a checklist."
Wrong model. Audit a suite against the list, find no matches, conclude it is sound.
What it costs. Section 20's class 124: the list is defects FOUND, not defects POSSIBLE, and the series produced one new class per chapter for twenty-six modules without saturating — nineteen in the last four modules alone. So the expected number of unnamed classes is not zero, and a clean audit rewards a suite written by somebody who read the list.
Corrected model. Run the audit — it is useful — and assert the conclusion it licenses, which is about the audit. "No already-named defect" is a real result. "Sound" is a different claim needing a different check, and Section 20's property 4 is the only one that would have caught all 124: for each committed property, somebody names an observation that would refute it.
Misconception 4 — "The taxonomy has twelve groups, so every class is in one of them."
Wrong model. Twelve groups, 124 classes, a clean distribution.
What it costs. Section 6's census: 35 of 124 classes carry an explicit assignment — 28.23% — and the other 89 do not. A complete-looking table can be produced by inferring the rest, and it would have exactly one witness: whoever inferred it. That is Chapter 26.1 §10's self-witnessed claim at the scale of a whole taxonomy, and it is unfalsifiable where the version with 89 blanks is not.
Corrected model. Publish the denominator. 35 classes, 36 assignments, 89 unassigned — and the discrepancy between the first two numbers is Section 8's entire finding, which a single total would have hidden.
Misconception 5 — "The taxonomy is a partition."
Wrong model. Every class belongs to exactly one group, so the twelve percentages sum to one hundred.
What it costs. Class 91 is in group 7 and group 9 and both memberships are stated in the text — Chapter 20.4 §26 and Chapter 21.5 §20. No chapter ever wrote a rule saying which one wins, so a report showing 91 in one group is applying a priority rule that does not exist. Which is verbatim Chapter 21.2 §2's theorem about the error classes — 7 of 12 reachable frame shapes qualify for more than one — in the taxonomy that same chapter went on to extend.
Corrected model. When two categories can both apply, a rule decides which appears in the report, and it is being applied whether or not it was written. The repair is one line of documentation; the failure is a report whose categories mean whatever the implementation decided.
Misconception 6 — "This chapter's subject would make a thirteenth group."
Wrong model. Classes 97, 102, 121, 122, 123 and 124 are all about the verification apparatus rather than the design, which is a clear new group.
What it costs. Section 20's table: all six share a subject and no two share a mechanism. Grouping by subject puts them together and tells a reader nothing about how to avoid any of them; grouping by mechanism puts 97 with the stimulus problems, 102 with the observer problems and 121 with the unconstitutable premises — which is where each one's repair lives.
Corrected model. Group by mechanism, and the bar Chapter 22.3 §20 set holds for the sixteenth time. A taxonomy that grows a group per new subject has stopped classifying and started indexing, and twelve groups holding 36 assignments is useful precisely because the squeezing is where the contrasts get drawn.
24. Interview Questions
Six, and by this point in the chapter the form is the point: each one is a question about questioning.
1. How do you tell whether a candidate derived a number or remembered it?
Change an input and ask again. Chapter 23.4 §7's prefetch depth is 149 at 100 Gb/s with 1 µs of host latency, 595 at 400 Gb/s, and 446 at a 3 µs tail. A derived answer moves; a remembered one does not. The strongest part of the answer is that the interviewer does not need to know the new value — only that it should change.
2. What makes an interview question useless?
A discrimination range of zero. Section 11: a question whose correct answer is a fact admits exactly one refutation count — zero — from every candidate, so it produces a constant and separates nobody. The three tests are: does a common wrong answer exist, does the right answer have a derivation, and can the best answer name more than one observation that would have refuted it.
3. Why not grade by whether the right terms appeared?
Because the two graders disagree in both directions and one of them is running unattended. Section 13: a high keyword score with a zero refutation count is the definition of the failure; a low keyword score with a refutation count of three is a candidate answering in their own words and being screened out. The second is the more dangerous because nobody is in the room.
4. What do the track's 124 rejected-property classes have in common?
In every one, the check's OUTCOME is decided by something other than whether the design is correct — and there are five producers: the property's form, the stimulus, the observer, the premise's custodian, and the design's own specification. The strong part of the answer is naming the last one, because its members do not pass: class 49's property fails, and it fails precisely because the switch floods as designed.
5. Should a 125th class open a thirteenth taxonomy group?
Almost certainly not, and the argument is Chapter 22.3 §20's. Sixteen consecutive classes have declined, and Section 20 shows why the most tempting candidate fails: six classes that share a subject and no mechanism would be an index rather than a classification. The test is whether the proposed group's members share a REPAIR, which is what a mechanism is.
6. You have one question and forty-five minutes. What is it?
"What observation would have changed your answer?" — followed, for each item offered, by "how?" It elicits the grading criterion directly, it works on a subject the interviewer does not know, and its failure mode is a candidate padding the list, which the follow-up removes. Section 21's directed test is what it buys: two candidates identical on every conventional observable, differing by a factor of 31.5.
25. Questions and Answers
26. What's Next — The Track, Closed
This is the last chapter of the Ethernet track. Twenty-six modules, 140 chapters, and one hundred and twenty-four rejected-property classes, none repeated.
What the track set out to do and what it produced instead. It set out to explain Ethernet. What it produced, chapter by chapter and without planning to, is a method — and the method is visible in the shape every flagship chapter takes: derive the number in front of the reader, name the chapter each input comes from, build the mechanism in RTL, and end by refusing one property that looks right.
Three results outlast the subject.
| Result | Where |
|---|---|
| a check is worth the set of observations that would have refuted it | Chapter 25.6 §20 through this chapter §20 |
| the outcome of every one of the 124 classes is decided by something other than the design | §10, over 36 explicit assignments |
| a taxonomy is a partition only after a priority rule, and the rule is the part nobody writes | Chapter 21.2 §2, and §8 here, applied to itself |
Three arithmetic anchors outlast it too, and they are the numbers this track's chapters cite most: 148.81 Mpps at 100 Gb/s with minimum frames; 9.524 Gpps for a 64-port switch; 283 320 BCE for a MAC receive datapath. Everything at port scale is priced against the third and everything at fabric scale against Chapter 23.3's 5.62 × 10⁸ BCE.
And one habit, which is the thing most worth carrying into any other protocol. Every number in this track names the chapter that derives it, so every claim has a citation and a reader can attack any of them. That is not a documentation style — it is the refutation count applied to writing, and it is why the track can be audited by somebody who disagrees with it.
The last word belongs to the series it ends. One hundred and twenty-four classes were written, one per chapter, never repeated, and the twelfth taxonomy group was opened in Module 22 and the thirteenth never was — declined sixteen consecutive times, each time with an argument rather than a rule. The classes kept coming and the kinds stopped, which is what a classification is supposed to do.
Every one of the 124 is a check that produced an outcome for a reason other than the design. Every repair is the same: name the observation that would have said otherwise, and make sure it can occur.
Continue learning
Related tutorials
- Related topic
Assertions
This track has written 1 848 named properties across 89 chapters and reused 47 of the names — while six structural families cover 93% of them.
- Related topic
RTL and Verification Review
546 declared coverage bins, 243 unreachable by construction, and one regression that is 51.832% or 93.399% depending on the denominator — plus the twenty bins random stimulus will never reach.
- Related topic
PCIe vs Ethernet — Where the Cost of Overload Lands
The same overload into two fabrics: one stalled the sender 59,405 times and lost nothing, the other discarded 59,405 frames. That single choice explains why one needs TCP and the other does not.
- Related topic
The Shared-Medium Problem
Why several independent transmitters on one medium is a distributed timing problem, not a formatting problem. Propagation delay makes every station's view of the medium stale, so two locally correct decisions can still collide — and that is the constraint the Ethernet MAC was built around.
Standards & specifications
- Governing standard
- IEEE Std 802.3 (Ethernet)(opens IEEE in a new tab)
Defines the Ethernet MAC, the media-independent interfaces and the physical-layer sublayers, including framing, access control, auto-negotiation and per-rate PHY specifications. VLAN tagging, priority and time-sensitive shaping are defined by IEEE 802.1, not by 802.3.
This page also covers RTL structure, verification approach and debugging technique. Those are engineering practice built on the standard, not requirements the standard itself imposes.
Where this fits
Part of the Ethernet curriculum.
