The deliverable
What you’re licensing
OpenHW OBI v1.5 master to TileLink Uncached-Lightweight manager protocol bridge — single-clock, single-outstanding, ASIL-B safety layer. It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
Synthesizable RTL
Portable, vendor-neutral SystemVerilog that drops onto your existing SoC fabric — no foundry or EDA-tool lock-in.
Per-IP FMEDA report
SPFM / LFM / PMHF computed against the ASIL target per ISO 26262-5 — the quantitative analysis your assessor asks for.
Safety manual
Assumptions of use, the safety mechanisms and their diagnostic coverage — written to drop straight into your safety case.
IP-XACT + integration docs
A machine-readable descriptor plus register and integration documentation for fast, low-risk bring-up.
Self-checking testbench
A self-checking testbench and a one-command build, so you can reproduce every claim on day one.
Overview
obi_to_tl_ul is a lightweight, single-outstanding-transaction bridge that connects an OBI (Open Bus Interface v1.5) master — typically an OpenHW CV32E40S / CV64A RISC-V core — to a TileLink Uncached Lightweight (TL-UL) interconnect fabric.
Key Features
- Single-outstanding OBI req/gnt ↔︎ TL-UL a_valid/a_ready + d_valid/d_ready mapping via a three-state FSM (ST_IDLE→ST_REQ→ST_RESP); the OBI grant is purely combinational (obi_gnt_o = ST_IDLE) for latency-optimal accept
- Opcode mapping: we=0 → GET(4); we=1, be=4’hF → PutFullData(0); we=1, partial be → PutPartialData(1); a_size fixed at 3’d2 (32-bit word), a_param always 3’b000
- Single clock domain, no CDC — verified directly against the RTL port list: one clk/rst_n pair drives every register, including both diverse-DMR shadows; a differing TL-UL fabric clock requires an external CDC shim upstream of this bridge
- Even parity on the latched request (addr_q/we_q/be_q grouped, plus wdata_q) — err_code 1 catches an upset that would otherwise silently corrupt an address, flip a write into a read, or corrupt a byte mask
- Diverse-DMR FSM lockstep: an independent next-state cone recomputes state_cmpl_q = ~state_q and flags any divergence from the live FSM — err_code 9
- Outstanding-request timeout watchdog (TIMEOUT_CYCLES, default 256 cycles) on the ST_REQ/ST_RESP window — err_code 4 catches a hung TL-UL target instead of stalling the OBI master forever
- Diverse-DMR read-data-forward shadow (obi_rdata_cmpl = ~tl_d_data, decoded on an independent path) closes the same-cycle obi_rdata_o = tl_d_data pass-through’s single-point gap with zero added read latency — err_code 2; TL-D d_corrupt/d_denied also forward to obi_err_o and the monitor as err_code 5/6
Standards & Compliance
OpenHW Group OBI v1.5; TileLink Uncached-Lightweight (TL-UL); ISO 26262 ASIL-B SEooC
Functional Safety
ASIL-B (SEooC) · SPFM 90.75% · LFM 89.34% · PASS
ISO 26262:2018 · FMEDA available · Safety Manual included
Register Map
See datasheet for full register reference.
Getting Started
// Minimal instantiation
obi_to_tl_ul #(
.ADDR_W(6)
) u_obi_to_tl_ul (
.clk (clk),
.rst_n (rst_n),
// APB4
.p_paddr (paddr),
.p_psel (psel),
.p_penable (penable),
.p_pwrite (pwrite),
.p_pwdata (pwdata),
.p_prdata (prdata),
.p_pready (pready),
// Safety
.err_clear (1'b0),
.err_valid (err_valid),
.err_code (err_code)
);
Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.