Skip to content

olo_ft_reset_gen

Back to Entity List

Status Information

VHDL Source: olo_ft_reset_gen

Description

This component is a TMR-hardened reset generator. A single-event upset (SEU) on any flip-flop of the component neither asserts the reset nor shortens a reset pulse.

It is the fault-tolerant counterpart of olo_base_reset_gen with the same interface and the same behavior: it generates reset pulses of a specified minimum duration after FPGA configuration and upon request (reset input), detects the reset input asynchronously and always de-asserts the reset synchronously. Assertion is asynchronous or synchronous, depending on the users choice.

In a design with several clock domains, one olo_ft_reset_gen per clock domain synchronizes the reset of that domain. Without TMR, an upset in the reset synchronizer of a domain resets the whole domain.

Note: Because the reset input is detected asynchronously, it is important that this input is glitch-free.

WARNING: Reset assertion upon FPGA configuration relies on the target technology supporting specific FF initialization state. For technologies which do not support specifying FF initialization state (e.g. Microchip devices) an external reset signal must be connected to RstIn. See olo_base_reset_gen for details.

Generics

Name Type Default Description
RstPulseCycles_g positive 3 Minimum duration of the reset pulse in clock cycles
Range: 3 ... 2^31-1
RstInPolarity_g std_logic '1' Polarity of RstIn.
'1' - Active High
'0' - Active Low
AsyncResetOutput_g boolean false True = RstOut is asserted asynchronously (RstIn is forwarded even in absence of Clk activity)
False = RstOut is asserted synchronously (upon Clk rising edge).
SyncStages_g positive 2 Number of synchronization stages for the multi-stage synchronizer in case of AsyncResetOutput_g=false.
This generic is not having any effect for AsyncResetOutput_g=true.
Range: 2 ... 4

Interfaces

Name In/Out Length Default Description
Clk in 1 - Clock
RstOut out 1 - Reset output (high-active, synchronous to Clk)
Note: The output is always high-active according to Open Logic guidelines.
RstIn in 1 not RstInPolarity_g Reset input. The reset is detected asynchronously - any glitches on this signal lead to a reset pulse being generated.
The input is optional. If reset shall only be asserted after FPGA configuration, it can be left floating (limited to target technologies supporting specifying the FF initialization state).

Architecture

The architecture follows olo_base_reset_gen with every register triplicated:

RstIn -+-> RstSyncChain[A] -> DsSync[A] -+
       +-> RstSyncChain[B] -> DsSync[B] -+-> vote -> RstSync -+-> pulse prolongation -> vote -> RstOut
       +-> RstSyncChain[C] -> DsSync[C] -+                     |   (PulseCnt[A,B,C],
                                                               |    RstPulse[A,B,C])
  • Reset synchronizers: three independent chains. Each chain is set asynchronously by RstIn and shifts in '0' after the reset input is released. For AsyncResetOutput_g=false, three independent multi-stage synchronizers (DsSync) follow. The outputs of the three chains are combined by a majority voter. An upset in one chain is shifted out after a few clock cycles and masked by the voter in the meantime.
  • Pulse prolongation (only for RstPulseCycles_g > 3): counter and pulse register are triplicated. The next value of every copy is computed from the voted state, so an upset copy is repaired at the next clock edge.
  • Output: the voted pulse register (for AsyncResetOutput_g=true combined with the voted output of the reset synchronizers, so the reset is also forwarded in the absence of clock activity).

Limitations

  • TMR masks one upset per register and clock cycle. Two upsets in different copies within the time an upset needs to be shifted out of a synchronizer chain (or to be repaired) are not masked.
  • The three chains sample the release of RstIn independently, so they may release one clock cycle apart. The voted output releases with the second chain.
  • The voters are not triplicated. The design targets upsets of storage elements (SEU), not single-event transients in combinational logic.

Synthesis Attributes

  • syn_radhardlevel = "none" at the architecture level prevents tools like Synplify (Microchip Libero) from triplicating the already-triplicated registers.
  • dont_touch, dont_merge, preserve, syn_preserve and syn_keep on all TMR copies prevent the synthesis tool from merging the copies. The synchronizer chains additionally carry the attributes of olo_base_reset_gen (shreg_extract, syn_srlstyle, async_reg).

The entity requires roughly three times the flip-flops of olo_base_reset_gen plus the voters.

Constraints

The same constraints as for olo_base_reset_gen apply: a set_false_path (or set_max_delay -datapath_only) constraint for the RstIn input and, for AsyncResetOutput_g=false, a set_max_delay -datapath_only of one clock period from RstSyncChain to DsSync.

The register names match olo_base_reset_gen, so in AMD Vivado its scoped constraint file can be used: read_xdc -ref olo_ft_reset_gen <path>/src/base/tcl/olo_base_reset_gen.tcl. Note that the scoped constraints for automatic constraining are only loaded for the olo_base entities.