The deliverable
What you’re licensing
The multi-sharer, multi-outstanding point-of-coherency for a snoopable AMBA 5 CHI region — N_TXN pipelined coherent-read slots on a full… It is delivered as a licensable soft-IP block engineered as an ASIL-B Safety Element out of Context — not just RTL, but the complete functional-safety work package needed to carry it into an ISO 26262 program:
Synthesizable RTL
Portable, vendor-neutral SystemVerilog that drops onto your existing SoC fabric — no foundry or EDA-tool lock-in.
Per-IP FMEDA report
SPFM / LFM / PMHF computed against the ASIL target per ISO 26262-5 — the quantitative analysis your assessor asks for.
Safety manual
Assumptions of use, the safety mechanisms and their diagnostic coverage — written to drop straight into your safety case.
IP-XACT + integration docs
A machine-readable descriptor plus register and integration documentation for fast, low-risk bring-up.
Self-checking testbench
A self-checking testbench and a one-command build, so you can reproduce every claim on day one.
What it is
chi_hn_f_v5 is a synthesizable SystemVerilog AMBA 5 CHI Home Node (HN-F) that pipelines coherent traffic across N_TXN outstanding read slots while keeping full sharer-vector coherence — a {valid, tag, sharers[N_RNF], unique} directory, so more than one RN-F can hold a line Shared at once, not just a single owner.
Key Features
- Sharer-vector directory: {valid, tag, sharers[N_RNF], unique} per line, even-parity protected and checked on every CAM lookup (err_code 2)
- ReadShared adds a sharer (downgrading a unique owner via SnpShared first); ReadUnique runs a per-slot multi-snoop SnpUnique loop invalidating every other sharer, one at a time, within one transaction
- N_TXN-deep coherent-read pipeline (default 2): while one slot works its multi-snoop loop, another slot accepts + looks up + snoops a different line; per-line hazard stall is the only interlock (formally proven, a_hazard)
- Per-slot held-line inline SECDED (ecc_pkg, NW×64-bit words): the returned coherent line is corrected before being forwarded as TXDAT CompData; an uncorrectable double-bit is err_code 2, aggregated with the directory sharer-vector parity check
- SN-F read error surfaced as a fault AND propagated as a CHI RespErr (DataError) on CompData (err_code 3); outstanding-transaction watchdog (err_code 4); write-FSM complementary diverse-DMR shadow (err_code 9); config + request-address parity (err_code 1)
- Clean-only snoop responses in this tier (write-through RN-F shells assumed) — every coherent miss, including one that just invalidated a sharer, sources from the SN-F memory port; dirty/DCT forwarding is the chi_hn_f_v6 tier
- Formal bmc (write-FSM DMR, per-line hazard a_hazard, non-empty snoop set a_snoop_nz) plus a dedicated VIP-style single-writer/multiple-reader (SWMR) directory-coherency proof shared with the v6/v7 sharer-vector family
Standards & Compliance
Arm AMBA 5 CHI (Issue E); ISO 26262 ASIL-B SEooC
Functional Safety
ASIL-B (SEooC) · SPFM 90.11% · LFM 89.82% · PASS
ISO 26262:2018 · FMEDA available · Safety Manual included
Register Map
See datasheet for full register reference.
Getting Started
// Minimal instantiation
chi_hn_f_v5 #(
.ADDR_W(6)
) u_chi_hn_f_v5 (
.clk (clk),
.rst_n (rst_n),
// APB4
.p_paddr (paddr),
.p_psel (psel),
.p_penable (penable),
.p_pwrite (pwrite),
.p_pwdata (pwdata),
.p_prdata (prdata),
.p_pready (pready),
// Safety
.err_clear (1'b0),
.err_valid (err_valid),
.err_code (err_code)
);
Configure via the CTRL register after reset to enable the IP and set operating parameters. Monitor err_valid / err_code for any safety faults reported by the built-in safety monitor.
Figures are pre-silicon engineering-grade estimates for a Safety Element out of Context (SEooC); final ASIL sign-off is the integrator’s, supported under NDA. FMEDA and Safety Manual available under NDA.