This document defines the architecture of OpenFibre, a fully featured SpaceFibre IP core. Together with
ECSS-E-ST-50-11C it is the complete basis for an implementation: it fixes the building blocks, their interfaces, the
ECSS requirements each block owns and the Open Logic entities each block is built from. It contains no code.
Physical layer adaptation: serialiser/deserialiser (SerDes) abstraction, loss of signal, serial loopback control.
Lane layer, one instance per lane.
Multi-Lane layer with 1 to 4 lanes (ECSS allows up to 16), including asymmetric links,
unidirectional lanes and hot redundant lanes.
Data Link layer with all features: up to 32 virtual channels, all quality of service (QoS) mechanisms, broadcast,
scrambling, error recovery, link reset.
Network layer service interface of a SpaceFibre node (packet and broadcast message transfer, optional virtual network
mapping).
Management Information Base (MIB) and its register interface.
Clocking, reset, fault tolerance and the verification architecture.
The first supported target is the AMD Versal AI Core XCVC1902 (part xcvc1902-vsva2197-2MP-e-S)
on the VCK190 evaluation board, with the 4 lanes on GTY transceivers routed to the QSFP connector of the board. Further
devices and boards are added through a new Physical adapter (PA-1) and board constraints only; nothing above the
Physical adapter depends on the target (section 7.6).
OpenFibre is an open SpaceFibre implementation that is based on the Open Logic VHDL Library. The code lives in
open-space-hdl/openfibre under the PSI HDL Library License, Version
1.0, the licence of Open Logic. Open Logic is pinned to the tag 4.7.0-ft.1 (9fea4eb) of the branch
fault-tolerant of open-space-hdl/open-logic-ft, the fault-tolerant fork of Open Logic. The line rate is 6.25 Gbit/s
per lane.
Requirement references are ECSS clause numbers with the requirement letter, for example ECSS 5.7.7.1a. A range such as
5.7.7.2.1 to 5.7.7.2.4 means all requirements of those clauses.
Coding conventions: those of Open Logic (naming, two-process style, synchronous high-active resets, VSG rules), entity
prefix ofb_, VHDL library openfibre; see conventions.md.
"FT" (fault-tolerant) means the Open Logic olo_ft_* entities: SECDED ECC on every RAM, TMR on every clock domain
crossing.
Term
Meaning
VC
Virtual channel (ECSS 5.7.2)
FCT
Flow control token (ECSS 5.3.5.2)
ERB
Error recovery buffer (ECSS 5.7.7.1)
MAC
Medium access controller (ECSS 5.7.4)
N-Char
Data character or EOP / EEP of a packet (ECSS 5.3.7.1)
A fully featured SpaceFibre port implements five protocol layers and a management information base (ECSS 5.2).
OpenFibre covers every row of the table below except the routing switch, with the Multi-Lane layer limited to 4 lanes.
Layer
Function
ECSS clauses
Network
Packet transfer of a node: packet format, sending, receiving
5.8.5 to 5.8.7, 6.2.2
Network
Virtual networks: mapping of virtual networks to VCs
5.8.3
Network
Broadcast messages, broadcast channels
5.8.12, 6.2.3
Network
Routing switch, addressing, group adaptive routing, multicast
5.8.8 to 5.8.11
Data Link
Virtual channels, output and input VC buffers, up to 32 VCs
5.7.2, 6.3.2
Data Link
VC flow control with FCTs and multipliers
5.7.3, 5.3.5.2
Data Link
Medium access control and QoS: scheduled QoS (64 time-slots), precedence, bandwidth credit, priority, integrated QoS
5.7.4.1 to 5.7.4.7, 6.3.4
Data Link
Broadcast flow control
5.7.5
Data Link
Framing: encapsulation, sequence numbers, CRC-16 and CRC-8, idle frames
5.7.6.1, 5.7.6.3 to 5.7.6.7, 5.3.5.1, 5.3.8
Data Link
EM emission mitigation: data scrambling, idle frame scrambling
5.7.6.2
Data Link
Error recovery: ERB, ACK / NACK / FULL / RETRY, receive error state machine
5.7.7, 5.3.5.3
Data Link
Data word identification, control word precedence
5.7.8, 5.3.10
Data Link
Link reset state machine and link reset actions
5.7.9, 5.7.10
Multi-Lane
Multi-Lane link of 1 to 16 lanes, bypass for one lane
5.6.1 to 5.6.3
Multi-Lane
Distribution into rows, concentration
5.6.4, 5.6.5
Multi-Lane
Lane alignment with ACTIVE, ALIGN and PAD words, alignment FIFO, alignment state machine
5.6.6, 5.6.7, 5.3.4
Multi-Lane
Asymmetric links, unidirectional lanes, hot redundant lanes
5.6.8 to 5.6.10
Lane
Lane initialisation and standby state machine, RXERR counter
5.5.2
Lane
Data signalling rate compensation (SKIP), IDLE words, parallel loopback
5.5.3 to 5.5.5
Lane
Symbol and word synchronisation, receive synchronisation state machine
5.5.6 to 5.5.8
Lane
Lane control words, 8B/10B, RXERR
5.3.2, 5.3.3, 5.3.6
Physical
Serialisation, serial loopback, data signalling rate, loss of signal
5.4.2, 6.4
MIB
Configuration and status parameters, management service
5.9, 6.5
Three properties of the standard shape the architecture more than any single feature:
The Multi-Lane layer sits between the Data Link and the Lane layers and makes the Data Link layer independent of
the number of lanes (ECSS 5.6.1). With one lane it is a bypass (ECSS 5.6.3), so a design that leaves it out has no
place to add lanes later.
Error recovery and QoS both act on the transmit order of frames: the MAC chooses which VC sends next, the ERB may
resend frames in a different place of the stream. Both must be designed around the same frame boundary and word
interface.
Everything that is "received" in the standard is an event, not a level: an FCT, a capability, an ACK. A received
capability stored as a level, for example, would reset the link again on every lane re-initialisation.
The internal structure follows from the standard and from the drivers above. Each goal is implemented by a principle of
section 5 or by the verification architecture of section 9.
Goal
Implementation
Defined handshakes between blocks
Every internal data path is a valid / ready stream (P2)
Correct state semantics
Received conditions are one-cycle events with a defined source; every register has a specified reset value (P4)
One protocol function per block
A block implements one ECSS function; no clause is owned by two blocks (P1)
Room for every feature of the standard
The layer and block structure follows ECSS 5.2 completely; bypass paths make features optional (P6)
Few, proven clock domain crossings
Four clock domains, every crossing an Open Logic FT entity (P3)
Fault tolerance
FT entities for all RAMs and crossings, safe state machines (P5)
One reset concept
Power-on reset brought into each domain; link reset and lane reset are synchronous commands (P4)
Fast verification at every level
Unit, layer and core benches at word and row level, regression in CI (section 9)
One management interface
All parameters in a register file behind one AXI4-Lite port (P7)
One Lane layer for every transceiver
A generic datapath width instead of one copy per width (P6)
Ten principles govern every block of the core; each implements a goal of section 4.
ID
Principle
Rule for the implementation
P1
One protocol function per block
A block implements one ECSS function (a clause or a state machine). Its specification names the clauses it owns; no clause is owned by two blocks.
P2
Streams everywhere
Every data path between blocks is a valid / ready stream with Last = end of frame and a sideband for K flags and metadata (Open Logic AXI4-Stream conventions). No read-enable with implied latency, no threshold handshakes.
P3
Few clock domains, proven crossings
Three internal domains per port (lane clock per lane, core clock, management clock) plus the user clock. Every crossing is built from Open Logic FT entities: olo_ft_fifo_async for data, olo_ft_cc_bits for levels, ofb_cc_pulse (handshake over olo_ft_cc_bits) for events, olo_ft_cc_reset for resets.
P4
Explicit state semantics
An ECSS "received" condition is a one-cycle event from the block that decodes it. Every state register has a specified reset value. Resets follow the Open Logic convention: synchronous and high-active inside every block; olo_ft_cc_reset brings the power-on reset into each clock domain. Link reset and lane reset are synchronous commands.
P5
Fault tolerance by construction
All RAMs are olo_ft_ram_* (SECDED ECC), long-lived buffers use the scrubbing variants, all crossings are TMR. State machines use safe encoding with a defined recovery state. ECC events are counted in the MIB.
P6
Scalable by generics, optional by bypass
Lanes 1 to 4, VCs 1 to 32, broadcast channels, QoS mechanisms and scrambling are generics. A feature that is disabled is removed at elaboration or bypassed, never left half connected. One Lane layer serves all transceivers through a generic datapath width.
P7
One management interface
All configuration and status parameters of ECSS 5.9 live in one register file behind one AXI4-Lite port, generated from a single register description (VHDL package, documentation, C header, test model).
P8
Verifiable in isolation
Each block has a transaction-level specification and a unit test bench that drives only its ports. Layer benches connect real blocks with reference models; tests never reach into the hierarchy.
P9
Reuse before design
A function available in Open Logic (FIFO, RAM, CRC, PRBS, arbiter, width converter, crossing, AXI4-Lite slave) is instantiated, not rewritten. Custom logic is limited to the SpaceFibre protocol functions.
P10
Proven structures
A word interface between the Data Link, Multi-Lane and Lane layers, vendor code only in the physical adaptation, one AXI4-Stream user port per VC, a receive check pipeline that passes only valid frames to the VC buffers, and an error recovery buffer of a word RAM plus an item list.
OpenFibre follows the ECSS protocol stack one to one: a Network interface, a Data Link layer, a Multi-Lane layer that
is always present (a bypass for one lane), one Lane layer and one Physical adapter per lane, and a Management
Information Base that reaches every layer. Data moves between layers as valid / ready streams; the Data Link layer works
on rows of words, so its protocol logic does not depend on the number of lanes.
The transmit path runs down the left two columns from the VC ports to the SerDes, the receive path up the right two
columns; the two tinted bands are the only data crossings between clock domains, and the MIB bus on the right reaches
every layer.
The Multi-Lane layer is always instantiated; with NumLanes_g = 1 it reduces to the bypass of ECSS 5.6.3
One Data Link layer for 1 to 4 lanes; lanes are added without a change of the Data Link layer
D2
The Data Link datapath carries one row per beat: up to MaxDataLanes_g data words (4), or one Data Link control word
ECSS 5.6.4.1d, note 1: control words are processed at a rate independent of the number of lanes. The row width follows the maximum number of data-sending lanes (MaxDataLanes_g), not the number of physical lanes (NumLanes_g); both are 4. When the data-sending lane parameter is set lower at run time, the further active lanes are hot redundant lanes (ECSS 5.6.10d, e)
D3
Data frame CRC-16 and data scrambling are computed per lane (per column) in the Multi-Lane layer; CRC-8, sequence numbers and polarity stay in the Data Link layer
ECSS 5.6.4.2c, 5.6.4.2d and 5.6.4.2h require the CRC-16 and scrambling per data-sending lane
D4
The error recovery buffer stores frames before sequence numbering and CRC
Resent frames get new sequence numbers (ECSS 5.7.7.2.4c.2)
D5
Four clock domains: user, core, lane, management
Few crossings; every crossing at a layer or buffer boundary
D6
One Lane layer with 1 or 2 words per lane clock cycle
One implementation for transceivers with 32-bit and 64-bit interfaces
D7
Precedence of control words and frames (ECSS 5.3.10c) is decided in two places only: the Data Link transmit scheduler (RETRY to idle frame) and the Lane layer (SKIP, LOST_SIGNAL, STANDBY) with the Multi-Lane layer (ALIGN, ACTIVE)
Each insertion point owns a contiguous part of the precedence list
D8
The user width of a VC port is NumLanes_g x 32 bit (32, 64 or 128 bit) and MaxDataLanes_g equals NumLanes_g; rows of fewer data-sending lanes are packed in DT-1 and DR-6
A 32-bit port would limit one VC to the bandwidth of one lane
D9
The protocol state machines use safe encoding with a defined recovery state, without TMR; the olo_ft_* crossings keep their TMR synchronisers
TMR stays where Open Logic provides it (P5); a state machine recovers from an upset through its recovery state and the protocol (link reset, error recovery)
D10
SCHEDULE.request (ECSS 6.3.4) comes from the NI-4 user port; a generic adds the time-slot start by a received broadcast message of a configurable type (off by default)
The source of the time-slot start depends on the network
NumLanes_g x 32-bit N-Chars (32 to 128 bit, D8), one K flag per byte in TUSER (EOP, EEP, Fill)
AXI4-Stream
Broadcast stream
User and Network interface
One broadcast message (8 bytes); broadcast channel, B_TYPE, DELAYED and LATE flags in TUSER
AXI4-Stream
Frame source stream (one per source)
VC / broadcast buffers and transmit scheduler
Row of N-Chars with valid mask, Last = end of packet or 64-word frame limit
Valid / ready
Transmit row stream
Data Link and Multi-Lane layers
One row: up to MaxDataLanes_g x (32 bit + 4 K flags) with a word mask, or one control word; replicate flag (word 0 goes to every data-sending lane: control words, broadcast and idle frame words)
Valid / ready through olo_ft_fifo_async
Receive row stream
Multi-Lane and Data Link layers
One aligned row, or one control word; per-column CRC-16 result on EDF rows; RXERR flag
Valid, no back-pressure (the Data Link layer is never slower than the link)
The asynchronous reset of the core is synchronised into each domain by one olo_ft_reset_gen per domain
(triplicated synchroniser chains); inside the blocks all resets are synchronous and high-active (Open Logic
convention). The Interface Reset of ECSS 5.7.9.2 is a
configuration reset of the MIB and the Data Link layer, not a system reset. Link reset (ECSS 5.7.10) and LaneReset (ECSS
5.5.2) are synchronous commands with a defined effect per block, listed in each block specification of section 7.
The core has 39 building blocks in seven groups. Each block below lists its responsibility, the Open Logic entities it
is built from and the ECSS requirements it owns (P1: no clause is owned twice). A block specification for the
implementation adds, per block, the port list, the register reset values and the effect of link reset and LaneReset
(P4).
Applies the Data Link part of the precedence list (RETRY down to idle frame), inserts broadcast frames, ACK / NACK and FCTs inside data frames, stops new frames on received FULL
olo_base_arb_prio
5.3.10c items 6 to 15, 5.3.10i to o, 5.3.10q to s
DT-6
Frame assembler
SDF / EDF, SBF / EBF, SIF and idle words; data frames of at most MaxDataLanes_g x 64 words; idle frame PRBS
olo_base_prbs
5.7.6.1, 5.7.6.2.3, 5.7.6.6, 5.3.5.1 to 5.3.5.3, 5.3.8, 5.6.4.2i
DT-7
Error recovery buffer
Stores data frames, broadcast frames and FCTs until acknowledged; ACK deletes, NACK starts RETRY and resend in sequence order; FULL when no room for a full frame; protocol error on an ACK / NACK outside the buffer
Transmit sequence counter and polarity, CRC-8 of broadcast frames, FCT, ACK, NACK, FULL, SIF
olo_base_crc
5.7.6.3.1, 5.7.6.5, 5.3.5.1.2
The transmit order is DT-5, DT-6, DT-7, DT-8: resent frames pass the stamper again and get new sequence numbers and the
inverted polarity (D4). The data frame CRC-16 is added later, per lane, in the Multi-Lane layer (D3).
7.3 Data Link layer, receive path and control (CoreClk)¶
ID
Block
Responsibility
Open Logic
ECSS
DR-1
Word identification
Data word identification state machine on rows, frame length limits, control word decoding into one-cycle events
none (state machine)
5.7.8 (decodes the words of 5.3.5)
DR-2
Frame checker
CRC-8 check, receive sequence counter and polarity, combines the per-lane CRC-16 results of the EDF row
olo_base_crc
5.7.6.3.2, 5.7.6.4 (result), 5.7.6.5
DR-3
Receive error handler
Receive error state machine, ACK and NACK requests to DT-5
none (state machine)
5.7.7.3, 5.7.7.2.1, 5.7.7.2.2
DR-4
Control word dispatcher
Received FCT to DT-2, ACK / NACK to DT-7, FULL to DT-5; each as an event with its sequence number
none
none owned (feeds 5.7.3.1, 5.7.7.2.3, 5.7.7.2.4)
DR-5
Frame buffer
Stores the words of the current frame, commits it on a valid end, drops it on an error, RETRY or link reset
olo_ft_fifo_packet (write-side drop)
5.7.6.7
DR-6
Input VC buffer (x NumVc_g)
Frame to VC demultiplexing, rows to user words, CoreClk to UserClk crossing, FCT requests, overflow detection, EEP after link reset only for a packet read in part
olo_ft_fifo_async, olo_base_wconv_xn2n
5.7.2.3, 5.7.3.2, 5.7.10a.4 to a.7
DR-7
Broadcast input buffer
Received broadcast messages to NI-3
olo_ft_fifo_async
none owned (receive side of 5.7.5 and 5.8.12)
DC-1
Link reset controller
Link reset state machine; capability events from the Multi-Lane layer, not stored levels; drives link reset of all Data Link blocks
none (state machine)
5.7.9, 5.7.10b
DC-2
Data Link statistics
Counts frames, control words, errors and retries per type as events for the MIB
TxEn / RxEn per lane, TxOnly, RxOnly, FarEndActive and LaneReset per lane, data-sending, data-receiving and hot redundant lanes, capability exchange with the Data Link layer, status for the MIB
none (per-lane state)
5.6.1, 5.6.2, 5.6.8, 5.6.9 except 5.6.9.1a and b, 5.6.10 except 5.6.10c and g
ML-2
Row distributor
Splits a row over the data-sending lanes; replicates control words (the EDF carries its own CRC per lane); PAD before the EDF; replicates broadcast and idle words; SKIP on all lanes at once; IDLE rows when the Data Link layer has no row; inserts ALIGN and ACTIVE; PRBS on hot redundant lanes; bypass with one lane
Data scrambling of one lane, CRC-16 of the data words of one lane, CRC-16 placed in that lane's EDF; PAD words excluded
olo_base_prbs, olo_base_crc
5.7.6.2.1, 5.7.6.4, 5.6.4.2c to g
ML-4
Column decoder (x lane)
Unscrambling and CRC-16 check of one lane, result attached to the EDF
olo_base_prbs, olo_base_crc
5.7.6.2.2, 5.7.6.4, 5.6.4.2h
ML-5
Lane alignment
One alignment FIFO per lane, ALIGN detection, alignment state machine (Not Ready, Near-End Ready, Both-Ends Ready), FIFO overflow handling
olo_ft_fifo_sync (x lane)
5.6.5a, 5.6.5b, 5.6.6.1, 5.6.6.3, 5.6.6.4, 5.6.7
ML-6
Row concentrator
Reads aligned rows, removes PAD, checks valid and invalid rows, passes one control word per row, replaces an invalid row by one RXERR
none
5.6.5c to f, 5.6.6.2, 5.6.4.1e
The column blocks (ML-3, ML-4) are the only place that sees individual lanes inside a frame, so adding or removing lanes
(ECSS 5.6.4.2d, note 1) never reaches the Data Link layer.
Lane initialisation state machine with all states, receive polarity inversion, LaneStart / AutoStart, TxOnly / RxOnly behaviour; the far-end capability is reported as an event when three identical INIT3 are received
none (state machine)
5.5.2.1, 5.5.2.3 to 5.5.2.13
LN-2
Lane transmitter
INIT1 / INIT2 / INIT3 with their PRBS data words, STANDBY, LOST_SIGNAL, IDLE and SKIP; SKIP insertion for rate compensation; Lane layer part of the precedence list
olo_base_prbs, olo_base_pl_stage
5.3.3, 5.5.3, 5.5.4, 5.3.10a, 5.3.10b, 5.3.10c items 1 to 3 and 16, 5.3.10d to f, 5.3.10p
LN-3
Lane receiver
Word synchronisation, receive synchronisation state machine, lane control word detection, RXERR generation and the RXERR word counter, SKIP removal
none
5.5.6 (when not in the transceiver), 5.5.7, 5.5.8, 5.3.6, 5.5.2.2
LN-4
Parallel loopback
Loops the transmit words back to the receiver inside the Lane layer
none
5.5.5
One Lane layer serves every transceiver: the generic WordsPerCycle_g (1 or 2) covers 32-bit and 64-bit transceiver
interfaces (D6).
AMD Versal GTY of the VCK190 first (ofb_pa_gty, Versal Transceivers Wizard); other SerDes later: serialisation, near-end and far-end serial loopback (PMA loopbacks of the transceiver, enabled through the MIB), data signalling rate, loss of signal (receiver electrical idle, synchronised), bit synchronisation status (comma alignment), polarity control; PHYSICAL_CONTROL and PHYSICAL_STATUS service; PRBS generator and checker of the transceiver for the bit error rate test (MG-5)
olo_ft_sync
5.4.1, 5.4.2, 5.4.2.1 to 5.4.2.4, 6.4
PA-2
8B/10B codec
Transceiver hardware codec when present, otherwise a soft codec; code and disparity errors to LN-3
none (no Open Logic codec; custom block)
5.3.2
PA-3
Receive elastic buffer
Transceiver clock correction on SKIP (Versal GTY), or a soft buffer from RxClk(i) to LaneClk with SKIP deletion for SerDes without clock correction
olo_ft_fifo_async (soft buffer)
none owned (SKIP removal of 5.5.3 for LN-2)
This is the only group with vendor code (P10). Its interface is the symbol stream of section 6, so a new FPGA family
needs a new PA-1 and nothing else.
All configuration and status parameters, generated from one register description (hdl/ofb_mib/regs/ofb_regs.yml, tools/regmap.py); configuration crosses to the other domains as quasi-static levels
olo_axi_lite_slave, olo_ft_cc_bits
5.9.1 to 5.9.4, 6.5
MG-2
Event counters
One counter per event type and direction (frames, FCT, ACK, NACK, FULL, RETRY, RXERR, errors), sticky error flags, interrupt
ofb_cc_pulse
none owned (status counters of 5.9.4 for MG-1)
MG-3
EDAC monitor
Collects the SEC / DED flags of every FT RAM and FIFO, counts them, raises an interrupt, drives error injection for tests
olo_ft_ecc_monitor_axi
none (fault tolerance, P5)
MG-4
Clock and reset
Power-on reset, reset synchronisation per domain, Interface Reset as configuration reset
olo_ft_reset_gen
none owned (configuration reset of 5.7.9.2 for DC-1)
MG-5
PRBS test
Per lane: pattern selection of the PRBS generator and checker of the Physical adapter (PA-1), lock status, counters of checked words and of words with errors (bit error rate measurement on the electrical link, bypassing 8B/10B)
Every RAM of the core is an olo_ft_* RAM or FIFO with SECDED ECC, and every clock domain crossing is an olo_ft_*
crossing with TMR synchronisers; stateless or purely combinational helpers use the olo_base_* entities. Custom logic
is left only for the SpaceFibre protocol functions: state machines, framing, alignment and the error recovery
controller.
Open Logic entity
Used in
Purpose
olo_ft_fifo_async
DT-1, DT-3, DR-6, DR-7, Data Link to Multi-Lane crossing, PA-3, MIB control crossings
ECSS VC buffers and every data crossing; ECC on the buffer RAM, TMR on the pointer and reset crossings
olo_ft_fifo_sync
ML-5
Alignment FIFO per lane (all lanes share LaneClk)
olo_ft_fifo_packet
DR-5
Receive frame buffer: write-side drop of a frame that fails a check (In_Drop), store and forward
olo_ft_ram_sdp_scrub
DT-7
Error recovery buffer words: frames may wait long for an ACK, the scrubber removes accumulated single errors
The core is verified with VUnit and UVVM in a seven-phase module workflow (requirements, architecture, verification
plan, RTL, testbenches, verification, integration; see conventions.md), which maps to
ECSS-E-ST-20-40C: every building block of section 7 is a module with its own specification, verification plan,
testbench and verification report, and layer, core and target tests cross the seams between the blocks. Every test case
names the ECSS clauses it verifies, so the traceability matrix of section 10 is produced by the regression. Word- and
row-level benches find protocol defects in seconds to minutes; a bit-serial simulation with the transceiver model takes
hours and checks only selected properties, so it is reserved for the two target simulations.
Level
Scope
Bench
Checks
Regression tier
Unit
One block of section 7 (for example DT-7, ML-5, LN-1)
<block>_th.vhd (UVVM engine, clocks, DUT, VVCs) and <block>_tb.vhd (VUnit runner, one run("test_...") per test ID of the verification plan)
UVVM checks and scoreboards; directed test cases, whose completeness the code coverage shows
Every commit
Layer
One layer with real blocks (Data Link, Multi-Lane with 1 to 4 lanes, Lane)
UVVM VVCs model the neighbouring layers at word or row level (reference model)
Frame and packet scoreboards, protocol monitors on the internal streams
Every commit
Core (seams)
Two cores back to back through a lane channel model at the symbol stream (behavioural PA model, no vendor transceiver model)
Random traffic on all VCs and broadcast channels, QoS configurations; channel VVC with bit errors, lost and duplicated words, lane skew, lane loss, lane add and remove
End-to-end packet integrity and order, no loss outside link resets, QoS bandwidth and latency bounds, recovery after every injected error; functional coverage of the traffic mix and of the injected faults
Nightly: a VUnit configuration enabled by an environment variable, with a fast self-skipping stub in the default tier
Target
Core with the vendor transceiver model (PA-1), and hardware
Exactly two simulations with the GTY model: one PA-1 wrapper test, and one top-level end-to-end test as the last step; lab tests on the VCK190 against STAR-Dundee equipment
Link initialisation, throughput, interoperability on each target
VUnit (run.py at the repository root) discovers and runs every test and is the CI regression. UVVM supplies the
verification building blocks: VVCs and BFMs (axistream_vvc for the VC ports, custom SpaceFibre word and row VVCs for
the layer boundaries), alert and log handling, check_value / await_value, constrained randomisation (t_rand) and
functional coverage (func_cov_pkg). No other randomisation or coverage framework.
One reference model of SpaceFibre at word and row level, written in VHDL as UVVM VVCs with the UVVM generic
scoreboard, serves the layer and core benches as driver, far end and scoreboard. It is the executable form of this
document and of the ECSS clauses.
Simulators: GHDL for every test that does not need the GTY model, so that many simulations run in parallel and CI
can run them; QuestaSim for code coverage (coverage.md). The two GTY simulations run in the AMD Vivado
simulator, which ships the compiled transceiver models.
Repository layout of the process: hdl/<module>/src, tb and docs per module, where a module is one layer or one
group of blocks of section 7 and every block keeps its own entity and unit testbench; open-logic/ and uvvm/ as git
submodules. Each block has specification.md, architecture.md, verification_plan.md and verification_report.md;
the requirement IDs of a block specification reference the ECSS clauses it owns (section 10).
Stream interfaces: random back-pressure (UVVM ready_low_* settings), back-to-back frames, throughput measured
against the lane rate, simultaneous transmit and receive.
Negative tests for every checker (CRC, sequence number, frame structure, alignment, credit overflow, protocol errors):
the fault comes from the bench (corrupted word, wrong sequence number, ACK outside the buffer), never from an RTL
mutation; increment_expected_alerts makes the test pass only when the check fires.
Partner-shape replay: the far-end model sends what real SpaceFibre equipment sends (control words inside frames,
retries, lane skew), not only convenient sequences.
Operational sequences: link start-up, lane reset, link reset, standby and error recovery exactly as the MIB
programming sequence prescribes.
Full-payload comparison of every packet and broadcast message.
Constrained random traffic with coverpoints on packet size, VC, QoS mode, error type and lane configuration; every
ECSS requirement also keeps a directed test for traceability.
Fault tolerance: SEC and DED injection through the ErrInj_* ports of every FT RAM and FIFO, injection during
traffic, scrubber effectiveness on the ERB, and a synthesis report check that the TMR crossings kept their triplicated
cells.
Tests observe ports and the MIB only (P8); the MG-2 counters make internal events visible, so no test depends on
hierarchical names.
A failed check fails the test; a test cannot pass with a failed step.
Every commit passes the full default-tier regression.
PA-1 is the only block with vendor transceiver code and is cut at the symbol stream. Every test except the two target
simulations runs with a behavioural PA model, without the slow GTY model. The target simulations run in the AMD
Vivado simulator (tools/run_xsim.py).
Every ECSS clause in the scope of section 1 has exactly one owner block; where a clause has a transmit and a receive
half, each half has its own owner. "First verified at" names the lowest verification level (section 9) at which the
clause can be fully checked. The compliance matrix, generated from this table, the module
specifications and the verification plans, lists the requirements and test cases of every clause.
ECSS clause
Title
Owner
Also involved
First verified at
5.3.2
8B/10B encode / decode
PA-2
LN-3
Unit
5.3.3
Lane control words
LN-2 (send), LN-3 (detect)
Unit
5.3.4
Multi-Lane control words
ML-2 (send)
ML-5, ML-6 (detect)
Unit
5.3.5.1
Framing control words
DT-6 (send)
DR-1 (detect)
Unit
5.3.5.1.2
Sequence number
DT-8
DR-2
Unit
5.3.5.2
Flow control word (FCT)
DT-6
DR-1, DR-4
Unit
5.3.5.3
Error recovery control words
DT-6
DT-7, DR-1
Unit
5.3.6
RXERR
LN-3
ML-6, DR-1
Unit
5.3.7, 5.3.9
Characters, packets
NI-1
DR-6
Unit
5.3.8
Frames
DT-6
DR-1
Layer
5.3.10a, b, c1 to c3, c16, d to f, p
Precedence, Lane layer part
LN-2
Unit
5.3.10c4, c5, g, h
Precedence, Multi-Lane part
ML-2
Unit
5.3.10c6 to c15, i to o, q to s
Precedence, Data Link part
DT-5
DT-7
Layer
5.4.1, 5.4.2, 5.4.2.1 to 5.4.2.4
Physical layer interface, serialisation, bit synchronisation status, serial loopback, rate, loss of signal
PA-1
LN-1, MG-1
Target
5.5.2.1, 5.5.2.3 to 5.5.2.13
Lane initialisation and standby
LN-1
ML-1
Unit
5.5.2.2
RXERR word counter
LN-3
MG-2
Unit
5.5.3
Data signalling rate compensation
LN-2 (insert SKIP)
PA-3 or LN-3 (remove)
Layer
5.5.4
IDLE words
LN-2
Unit
5.5.5
Parallel loopback
LN-4
Unit
5.5.6
Symbol synchronisation
LN-3
PA-1 (transceiver comma alignment)
Target
5.5.7, 5.5.8
Word synchronisation, receive synchronisation state machine
LN-3
Unit
5.6.1, 5.6.2
Multi-Lane responsibilities, Multi-Lane link
ML-1
MG-1
Layer
5.6.3
Multi-Lane bypass
ML-2
ML-6
Layer
5.6.4.1a to d, 5.6.4.2a, b
Rows, laning of data frames, PAD
ML-2
ML-6
Layer
5.6.4.2c to h
Per-lane scrambling and CRC-16
ML-3 (send), ML-4 (receive)
DR-2
Unit
5.6.4.2i
Maximum data frame length
DT-6
DR-1
Layer
5.6.4.3 to 5.6.4.5, 5.6.9.1a, b, 5.6.10c, g
Laning of broadcast, idle and lane control words; sending ACTIVE; hot redundant lane words
ML-2
Layer
5.6.5a, b
Alignment FIFOs
ML-5
Unit
5.6.5c to f, 5.6.4.1e
Concentration into rows
ML-6
Unit
5.6.6.1, 5.6.6.3, 5.6.6.4
Alignment, ACTIVE and ALIGN, alignment FIFO
ML-5
ML-2
Layer
5.6.6.2
Valid and invalid rows
ML-6
Unit
5.6.7
Alignment state machine
ML-5
Unit
5.6.8, 5.6.9 except 5.6.9.1a, b
Asymmetric links, unidirectional lanes
ML-1
LN-1, ML-2
Core
5.6.10 except 5.6.10c, g
Hot redundant lanes
ML-1
ML-2
Core
5.7.2.1, 5.7.2.2
Virtual channels, output VC buffer
DT-1
NI-1
Unit
5.7.2.3
Input VC buffers
DR-6
NI-1
Unit
5.7.3.1
Output VC flow control
DT-2
DR-4
Layer
5.7.3.2
Input VC flow control
DR-6
DT-5
Layer
5.7.4.1 to 5.7.4.7
Medium access control and QoS
DT-4
NI-4, DT-5
Core
5.7.5
Broadcast flow control
DT-3
DR-7
Layer
5.7.6.1
Data encapsulation
DT-6
Unit
5.7.6.2.1
Data scrambling
ML-3
Unit
5.7.6.2.2
Data unscrambling
ML-4
Unit
5.7.6.2.3
Idle frame scrambling
DT-6
ML-2
Unit
5.7.6.3.1
Sequence numbers on transmission
DT-8
DT-7
Unit
5.7.6.3.2
Sequence numbers on reception
DR-2
Unit
5.7.6.4
CRC for data frame
ML-3 (send), ML-4 (check)
DR-2
Unit
5.7.6.5
CRC for broadcast frame, FCT, ACK, NACK, SIF
DT-8 (send), DR-2 (check)
Unit
5.7.6.6
Idle frames
DT-6
DT-5
Unit
5.7.6.7
Frame reception
DR-5
DR-1
Layer
5.7.7.1
Error recovery buffer
DT-7
Unit
5.7.7.2.1, 5.7.7.2.2
Sending ACKs and NACKs
DR-3
DT-5
Layer
5.7.7.2.3, 5.7.7.2.4
Receiving ACKs and NACKs
DT-7
DR-4
Unit
5.7.7.3
Receive error state machine
DR-3
Unit
5.7.8
Data word identification state machine
DR-1
Unit
5.7.9
Link reset state machine
DC-1
ML-1
Unit
5.7.10a1 to a3
Link reset, output VC side
DT-1
NI-1
Layer
5.7.10a4 to a7
Link reset, input VC side (EEP rules)
DR-6
NI-1
Layer
5.7.10b
Link reset, Data Link actions
DC-1
DT-6, DT-7, DT-8, DR-1, DR-2
Layer
5.8.3
Virtual networks
NI-2
MG-1
Unit
5.8.5 to 5.8.7, 5.8.13
Packet format, sending and receiving packets, nodes
Foundations: stream interface package, register description and generator, UVVM reference model (VVCs, scoreboard),
VUnit run script and CI with unit and layer benches.
Single-lane core on the VCK190: PA, LN, ML in bypass, Data Link without QoS and with 8 VCs. Exit
criterion: link and traffic with STAR-Dundee equipment on the VCK190.
Complete Data Link layer: QoS (DT-4), 32 VCs, data scrambling, virtual networks, schedule service.
Multi-Lane: 2 and 4 lanes with alignment, then asymmetric links, unidirectional and hot redundant lanes.
Hardening: fault injection campaigns, resource and timing closure on the target FPGAs, qualification documentation.