# EXPECTED — `signoff-certificate-engine`

<!-- kit:claim witness="PYTHONPATH=. python3 scripts/audit/verify_certificate_v2_gate.py" extract="yield k/n=(\d+)/(\d+) ci=\[([0-9.]+),([0-9.]+)\] recomputed match=(\w+) gate-on-lower=(\w+)\s+\[3\] bound ([0-9.eE+-]+) \| empirical worst ([0-9.eE+-]+) \| sound=(\w+)" -->
<!-- repro:expect [{"group": 1, "equals": "350"}, {"group": 2, "equals": "400"}, {"group": 3, "near": 0.8385, "abs_tol": 0.00006}, {"group": 4, "near": 0.9058, "abs_tol": 0.00006}, {"group": 5, "equals": "True"}, {"group": 6, "equals": "True"}, {"group": 7, "near": 1.041e-07, "abs_tol": 1e-10}, {"group": 8, "max": 1.041e-07}, {"group": 9, "equals": "True"}] -->

**The claim** (`top40.json` rank 16, `CROWN_JEWELS_RESOLVED.md` §5): every number in a signoff certificate is bounded. No
field is an unqualified point estimate: the yield is an exact interval, and the S-parameter band is a certified bound.

**What this packet reproduces.** `verify_certificate_v2_gate.py` (§9 Gate 103) certifies one fixed design (d 70 µm,
p 350 µm, t 300 µm, EagleXG dk 5.0) with `genesis.signoff.certificate.certify`. It then recomputes the parts
independently:

| parsed group | expected | meaning |
|---|---|---|
| 1 / 2 | 350 / 400 | the yield count k/n the certificate carries |
| 3 / 4 | 0.8385 / 0.9058 | the certificate's 95% yield interval |
| 5 | True | that interval equals the textbook Clopper–Pearson interval recomputed with scipy, to 1e-12 |
| 6 | True | the manufacturing-yield gate is decided on the interval's lower bound |
| 7 | 1.041e-07 | the certified 2-norm bound on the S-matrix perturbation |
| 8 | at most the bound | the worst perturbation observed in a 60-draw Monte Carlo sweep inside the certified ball |
| 9 | True | sound: no sweep draw exceeds the bound |

**Tolerances.**
- k, n and the three verdicts are exact.
- The interval ends are printed to 4 decimals. The committed witness holds 0.8385413405693943 and
  0.9057814853134138, so ±0.00006 is the print rounding and nothing more. The gate itself checks agreement to 1e-12.
- The bound is printed to 4 significant figures (committed 1.040854337402733e-07); ±1e-10 is that rounding.
- The empirical worst case (1.940e-14 here) is not pinned. It depends on floating-point round-off in the MTL
  synthesis, and the claim is only that it stays at or below the bound.

**Not covered.** The certificate's other fields (the physics prediction itself) and the version number
(`dataroom/witness_quality.json`: "2 (version) — descriptive").

**Measured** 2026-09-17 in a tree holding exactly commit `a16c009b`: exit 0 in 4.4 s under the input tracer.
