The deliverable
What you’re licensing
The non-coherent (ReadNoSnp/WriteNoSnp) bandwidth tier beside the catalog’s coherent chi_hn_f — tagged… It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
Synthesizable RTL
Portable, vendor-neutral SystemVerilog that drops onto your existing SoC fabric — no foundry or EDA-tool lock-in.
Per-IP FMEDA report
SPFM / LFM / PMHF computed against the ASIL target per ISO 26262-5 — the quantitative analysis your assessor asks for.
Safety manual
Assumptions of use, the safety mechanisms and their diagnostic coverage — written to drop straight into your safety case.
IP-XACT + integration docs
A machine-readable descriptor plus register and integration documentation for fast, low-risk bring-up.
Self-checking testbench
A self-checking testbench and a one-command build, so you can reproduce every claim on day one.
What it is
chi_hn_f_mo is a synthesizable SystemVerilog CHI Home Node bandwidth tier: it handles only the two non-coherent (“NoSnp”) AMBA 5 CHI opcodes — ReadNoSnp and WriteNoSnp — but pipelines the reads.
Key Features
- Non-coherent-only opcode set — ReadNoSnp (6’h04) / WriteNoSnp (6’h1D) — no directory, no snoop channels, no coherence state to maintain
- Tagged, multi-outstanding read engine: N_OUT-deep outstanding table (default 4) with lowest-free-slot allocation; returning mem_rtxnid demultiplexes replies that may complete out of issue order
- 1-deep completion skid backpressures the SN-F (mem_rready = !cmp_val || txdat_acc) whenever the CHI-side TXDAT drain stalls — the SN-F adapter must hold its return, not drop it
- Single-outstanding write engine (DBIDResp → RXDAT data → SN-F store → Comp) sharing the one mem_req line with new reads by construction, not arbitration
- Inline per-64-bit SECDED (ecc_pkg) on the held read-completion line: single-bit upset corrected before CompData is driven, double-bit flagged uncorrectable (err_code 2)
- SN-F read error (mem_rerr) captured PER completion and surfaced both as a fault and as a CHI RespErr (DataError) on that read’s own CompData — never mis-attributed to a later read (err_code 3)
- ASIL-B: config/address parity (err_code 1), read-completion SECDED (err_code 2), outstanding-transaction watchdog (err_code 4), write-FSM diverse-DMR shadow (err_code 9); formal proves the tag-routing invariant (a_tag_val) and covers ≥2 simultaneously outstanding reads (c_multi)
Standards & Compliance
Arm AMBA 5 CHI (Issue E); ISO 26262 ASIL-B SEooC
Functional Safety
ASIL-B (SEooC) · SPFM 90.90% · LFM 89.65% · PASS
ISO 26262:2018 · FMEDA available · Safety Manual included
Register Map
See datasheet for full register reference.
Getting Started
// Minimal instantiation
chi_hn_f_mo #(
.ADDR_W(6)
) u_chi_hn_f_mo (
.clk (clk),
.rst_n (rst_n),
// APB4
.p_paddr (paddr),
.p_psel (psel),
.p_penable (penable),
.p_pwrite (pwrite),
.p_pwdata (pwdata),
.p_prdata (prdata),
.p_pready (pready),
// Safety
.err_clear (1'b0),
.err_valid (err_valid),
.err_code (err_code)
);
Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.