// TEACHING INJECTION WRAPPER ONLY. Keep out of production RTL.
// fi_* controls must be stable before sampling. The campaign permits one
// event at one one-bit target per reset-to-edge-7 attempt, not simultaneous ports.
// State XOR modifies next state: sample old Q, then observe flipped new Q.
// No detector, synchronizer, physical upset model or reset-glitch defense.
module lesson02_fault_gate (
  input logic clk_i, rst_ni,
  input logic verify_done_i, auth_ok_i,
  input logic fetch_valid_i, fetch_ready_i,
  input logic fi_source_xor_i, fi_q_xor_i,
  input logic fi_state_xor_i, fi_grant_xor_i,
  output logic exec_grant_o, accepted_commit,
  output logic checked_q, result_q
);
  logic write_en, auth_seen, result_d, result_seen, grant_clean;
  assign write_en = verify_done_i && !checked_q;
  assign auth_seen = auth_ok_i ^ fi_source_xor_i;
  assign result_d = (write_en ? auth_seen : result_q) ^ fi_state_xor_i;
  always_ff @(posedge clk_i or negedge rst_ni) begin
    if (!rst_ni) begin
      checked_q <= 1'b0;
      result_q  <= 1'b0;
    end else begin
      if (write_en) checked_q <= 1'b1;
      result_q <= result_d;
    end
  end
  assign result_seen = result_q ^ fi_q_xor_i;
  assign grant_clean = checked_q && result_seen;
  assign exec_grant_o = grant_clean ^ fi_grant_xor_i;
  assign accepted_commit = fetch_valid_i && fetch_ready_i && exec_grant_o;
endmodule
