Results from the ASIC puzzle Jane Street published the solution to its August ASIC reverse-engineering puzzle, revealing that the chip is a hardware checker for an 11x11 Star Battle ("Two Not Touch") puzzle that accepts 121 cycles of inputs and emits the string "(* TWO STARS *)" on success. The firm received about 400 submissions from more than 30 countries, with most solvers using KLayout, Yosys and Z3 alongside custom tools written in Python, Rust, C++, OCaml, Haskell and Odin. The chip was designed with the SKY130 open-source standard cell library using the LibreLane toolchain, and its output strings are obfuscated with a small LFSR driven off the game board. In August, we published a puzzle https://blog.janestreet.com/can-you-reverse-engineer-an-asic/ that handed you the final GDS layout of a small chip and asked you to work out what it did. We supplied the physical layout, but not a netlist or internal signal names, and it was up to you to reverse-engineer the internals. This post reveals what the chip does and explores the different ways you solved it, with shout-outs to some of our favorite submissions. The submissions We received about 400 submissions from more than 30 countries, the bulk from the US, India, the UK and Australia. Entrants included high school students, researchers, working engineers and retirees. Most solvers used KLayout, Yosys and Z3 alongside custom tools many AI-written implemented in Python, Rust, C++, OCaml, Haskell and even Odin. The solution As many of you discovered, the chip is a hardware checker for an 11x11 Star Battle puzzle, also known as “Two Not Touch”. The goal is to place exactly two stars in each row, column, and colored region. No two stars can touch, even diagonally The chip accepts 121 cycles of inputs, with each input indicating whether to place a star in the corresponding square. It then runs several parallel checks on these inputs: - A 2-bit counter for each row and every column, requiring that each has exactly 2 stars - A 121-bit ROM mapping squares to regions, and a 2-bit counter for each region, requiring that each has exactly 2 stars - A delay line for tracking nearby squares to ensure that two stars never touch, including diagonally. - A counter for the total number of stars, used to produce certain Easter egg outputs The puzzle checks are then ANDed together to produce the success signal. The output generator stores its strings in ROM. To prevent the solution from showing up as plaintext, it is obfuscated with a small LFSR driven based off the game board though that didn’t stop some of you from attacking the LFSR Once success is achieved, the output logic deobfuscates the solution string and emits it TWO STARS Most incorrect solutions emit the string “TRY AGAIN”, but a few trigger the Easter eggs listed below. The puzzle chip was designed using the SKY130 open-source standard cell library, using the LibreLane toolchain. How you solved it Below, we walk through the steps involved in solving the puzzle, with examples from some of our favorite writeups. Extracting the netlist from the layout The first step was to extract a gate-level netlist from the GDS layout. To make it a little easier to get started, we left the cell names such as sky130 fd sc hd nand2 2 in the GDS files, allowing the use of the LVS