← All Verification IP
Automotive Networking

Preemption / PFC

An independent clean-room Ethernet PFC link-partner Bus Functional Model — this wave covers the PFC half of the catalog’s planned Preemption/PFC entry only (see the explicit scope note at…

Request this VIP →Browse all VIP
shippingGroup Automotive NetworkingStandard IEEE 802.3br (frame preemption), IEEE 802.1Qbb (Priority Flow Control)

Available now — real, tested verification collateral, not a roadmap placeholder.

Verification IP is not safety-rated. These are testbench components — no ASIL target, no FMEDA, no IP-XACT, no safety-mechanism interface. They exist to help you verify a design, not to carry a safety argument. The safety soft-IP catalog is over here.

The deliverable

What you get

Bus-functional model
An independent driver for the protocol, written clean-room from the public specification — not derived from our own RTL, so it is a genuine second source.
Passive protocol checker
A monitor that watches the bus and asserts the spec’s rules continuously, so a violation fails the run where it happens rather than downstream.
Self-checking interop testbench
A one-command testbench that drives the model against real RTL and hard-checks the result — reproduce every claim on day one.

An independent clean-room Ethernet PFC link-partner Bus Functional Model — this wave covers the PFC half of the catalog’s planned Preemption/PFC entry only (see the explicit scope note at the end of this summary). Unlike the point-to-point/multi-drop control buses vip-avsbus/vip-smbus/vip-pmbus build on, PFC is a BYTE-STREAM protocol (a passive rx_data/rx_valid/rx_last tap plus a standard valid/ready tx_data/tx_valid/tx_ready/tx_last source), so this BFM’s primitives are new, not bit-serial — one clk-cycle-per-byte drive pulse on the RX side (with a caller-chosen idle GAP between bytes, both back-to-back and gapped/realistic-MAC-timing variants exercised) and a registered-capture TX sink that drains the paired eth_pfc IP’s own generated frames under REAL varying tx_ready backpressure. The 34-byte PFC frame layout (DA/SA/Ethertype/Opcode/priority-enable-vector/8×2-byte pause-quanta) is this catalog’s own clean-room documentation of the public 802.1Qbz/802.3x Annex 31D shape, read from eth_pfc‘s own header comment (not guessed, not copied from its internal parsing code) — same AoU as eth_pfc itself carries. SEND_PFC_FRAME builds a well-formed frame from a caller-supplied priority-enable-vector and 8 quanta values, with independent bad-DA/bad-Ethertype/bad-Opcode corruption flags for negative testing; SEND_NON_PFC drives ordinary non-PFC-shaped traffic. A passive protocol checker independently reconstructs every RX and TX frame off the DUT’s real link pins with its own from-scratch byte-position decode (sharing no code or instance with the BFM) — on the RX side (BFM-driven, so nothing to police there) it exposes its own commit/fault classification for the interop TB to cross-check against the DUT’s real RXQ_RB0-7/STATUS/err_code CSR state; on the TX side (DUT-driven, so genuinely policeable) it independently enforces that tx_data/tx_valid/tx_last hold stable across every stalled cycle, that every FIXED-shape byte (DA/SA-placeholder/Ethertype/Opcode) matches the public spec regardless of CSR content on every generated frame, and that a generated frame is EXACTLY 34 bytes. This second-source effort ran clean against eth_pfc: 0 checker violations across a single-priority RX pause assert/countdown/release, a multi-priority RX load with independent countdowns and independent release times, a REFRESH (overwrite, not accumulate — confirmed both from a clean start and mid-countdown), a 0-quanta frame (confirmed immediate release, pause never asserts), a malformed frame with each of DA/Ethertype/Opcode individually corrupted (DA-wrong correctly reproduces real PFC’s own non-PFC-traffic semantics — silently ignored, no fault; Ethertype-wrong/Opcode-wrong correctly hit the genuine protocol-fault path, err_code 3, confirmed no register update), ordinary non-PFC traffic correctly ignored, and TX-side frame generation under real varying tx_ready backpressure (byte-exact against the CSR-configured ENABLE_VEC/QUANTA0-7), with no false ASIL-B self-check trip (err_code 1/2/9) at any point. Explicitly out of scope this wave: full IEEE 802.3br/802.1Qbu frame preemption (the byte-level MAC-merge/fragment/verify mechanism the catalog’s Preemption/PFC entry also nominally names) — no preemption BFM or checker logic is attempted here, inherited directly from eth_pfc‘s own documented v1 scope note (ip/tsn_switch/ has zero byte-level datapath to build real frame preemption from), not a limitation specific to this VIP; real Ethernet FCS/CRC32 (neither the paired DUT nor this BFM generates or checks one — digital-protocol-layer-only convention); real 512-bit-time quantum calibration (the paired DUT’s QUANTUM_TICK_DIV is a documented scaled functional-model value, not the real spec’s unit); and integration into tsn_switch/gmac (both untouched, exactly as eth_pfc itself is not integrated into either).

Key Features

Standards & Compliance

IEEE 802.3br (frame preemption), IEEE 802.1Qbb (Priority Flow Control)

Pairs With

Built to lean against these catalog IPs during integration:

Interested in the Preemption / PFC VIP?

Deliverables, the file manifest, and licensing terms are shared under a mutual NDA.

Talk to us →See related VIP

Verification IP is testbench collateral and is deliberately not safety-rated: no ASIL target, no FMEDA, and no IP-XACT descriptor. It carries no functional-safety claim.

circuit-design.space · +1-971-357-1400 · anovickis@circuit-design.space