A real synthesis and place-and-route pass on this RTL, routed on the open Nangate45 / FreePDK45 PDK — evidence the block closes physically, not just in simulation. Target-PDK timing, area, and power sign-off figures are shared under NDA.
The deliverable
What you’re licensing
APB4 mailbox + test-and-set spinlock unit for safety-island ↔ application-core handshakes, ASIL-B via resident parity + complementary-DMR. It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
Synthesizable RTL
Portable, vendor-neutral SystemVerilog that drops onto your existing SoC fabric — no foundry or EDA-tool lock-in.
Per-IP FMEDA report
SPFM / LFM / PMHF computed against the ASIL target per ISO 26262-5 — the quantitative analysis your assessor asks for.
Safety manual
Assumptions of use, the safety mechanisms and their diagnostic coverage — written to drop straight into your safety case.
IP-XACT + integration docs
A machine-readable descriptor plus register and integration documentation for fast, low-risk bring-up.
Self-checking testbench
A self-checking testbench and a one-command build, so you can reproduce every claim on day one.
Mbox — Introduction
What it is
mbox is a multicore mailbox and hardware spinlock/semaphore unit: NMBOX 32-bit mailboxes for post/consume message passing with an IRQ doorbell, plus NLOCK hardware test-and-set spinlocks, behind one APB4 slave with ASIL-B parity and complementary-DMR safety instrumentation.
Key Features
NMBOX 32-bit post/consume mailboxes: a write posts a message (sets valid, raises mbox_irq if IRQ-enabled), a read returns it and clears valid (consume/ack semantics)
NLOCK hardware test-and-set spinlocks: a single atomic APB read acquires the lock and returns the previous value; a write of 0 releases it — classic HW mutex, no software CAS loop needed
mbox_irq is the level-OR of valid & IRQ_EN across all mailboxes, so a consuming read of the posted mailbox always clears that source’s contribution
ASIL-B resident + delivered-read parity on every mailbox word (checked continuously across all NMBOX words and again on the value actually leaving the read mux) → err_code 1/2
ASIL-B complementary-DMR shadows on lock state, valid bits, and the IRQ-enable register, plus a diverse decode/read-mux copy catching a misrouted mailbox or lock access → err_code 9
Zero-wait-state APB4 slave (p_pready=1, p_pslverr=0); every access completes in one cycle, no FSM
Standards & Compliance
AMBA APB4 (ARM IHI 0024); ISO 26262 ASIL-B SEooC
Functional Safety
ASIL-B (SEooC) · SPFM 95.69% · LFM 99.00% · PASS
ISO 26262:2018 · FMEDA available · Safety Manual included
Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Applications
Where it fits
Typically deployed in RISC-V SoCs that need a safety-grade core, boot, memory, debug, and interrupt platform.
The case
Why license it, not build it
Skip 12–18 months
The FMEDA and the safety case are already generated. You integrate a finished safety element — you don’t stand up a safety-IP program to originate one.
One vendor, one safety story
Every block in the catalog shares the same safety architecture, fault-reaction model, and FMEDA methodology — so subsystems roll up cleanly.
Verified, not vapor
The RTL builds and passes today; the safety metrics come from analysis and fault injection against real RTL, not a datasheet promise.
Interested in Inter-Core Mailbox + Hardware Spinlock?
Pricing, the per-IP FMEDA, safety manual, and RTL data room are shared under a mutual NDA.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.