ofb_multilane: Verification Report¶
1. Test results¶
Run on 2026-10-06 with GHDL 6.0.0 (mcode), VUnit 5.0.0.dev7, UVVM 2026.03.20: python run.py "*ofb_ml*"
"*ofb_multilane*".
| Testbench | Tests | Passed |
|---|---|---|
ofb_ml_codec_tb (ML-3, ML-4) |
10 | 10 |
ofb_multilane_tb (layer, one lane) |
6 | 6 |
ofb_ml_align_tb (ML-5, ML-6, four lanes) |
5 | 5 |
ofb_ml_link_tb (multi-lane link, configurations lanes2 and lanes4) |
11 x 2 | 22 |
Full regression of the repository: 193 of 193 tests pass (phase 5, after the code coverage closure and the functional coverage of the core).
2. Summary¶
All 43 test cases pass; every requirement of the specification is covered (see the verification plan). The column encoder reproduces ECSS Figures 5-42 and 5-44 bit-exactly, and the decoder restores them. VSG reports no errors and no warnings.
Mutation checks confirmed that the testbenches detect faults: a wrong byte enable of the EDF in the CRC unit fails TC-ML-01 and TC-ML-09; a scramble enable that is not held in Active fails TC-ML-21. Phase 4: each of the following faults fails the named test: the PAD row replaced by the replicated word (TC-ML-30, 4 lanes), a held ALIGN after alignment ignored (TC-ML-41), the 4 us rule removed (TC-ML-42), interleaved control words that flush the waiting data words (TC-ML-43), the maximum number of data-sending lanes ignored (TC-ML-33), no SKIP request (TC-ML-31), FarEndActive not cleared by an ACTIVE word (TC-ML-35). Phase 5: held words discarded in Not Ready (the defect found by TC-CORE-13) fail TC-ML-44; a poison mark that the distributor does not pass on fails TC-ML-46.
Code coverage (QuestaSim, docs/coverage.md): the first measurement showed five transitions of the frame state of the receiver (frame structure errors) and an incorrect ALIGN on a lane that is not data-receiving without a test. TC-ML-47 and the extension of TC-ML-42 cover them and passed without a design change; four branches remain, each justified in the coverage report.
Defects found during verification:
| Finding | Fix |
|---|---|
| TC-ML-24: the one-cycle link reset pulse of the sequencer did not cover a rising clock edge (testbench timing) | Sequencer aligned to the falling edge before the pulse |
| Found during the design of the link reset state machine: a capability change in the middle of Connected can make the far end miss the INIT3LinkResetFlag | Capability held while the lane is in Connected (TC-ML-25, mutation checked) |
| TC-ML-35: a receive-only lane enters Active from Connected without INIT3 (ECSS 5.5.2.10e.3), so its unscramble enable stayed at the reset value and the data of that lane were not unscrambled | Unscramble enable of a lane without its own capability taken from the last capability of any lane (ML-LM-15 extended) |
| TC-ML-32: with a skew of three words, a lane was aligned before the ALIGN word of the late lane had arrived; the late lane then joined the data-receiving lanes, which caused a Misaligned condition and an RXERR in Near-End Ready | The lanes count as aligned only when every active receiving lane has received an ALIGN word (Seen) |
| TC-ML-37: the distributor sent an IDLE row after every replicated word (the next row was only taken one cycle later); a bit error that turns an IDLE word of one lane into RXERR is a lane slip and causes a realignment | The next row is taken in the cycle in which the replicated word is sent (ECSS 5.6.4.5b: no IDLE words while rows are available) |
| TC-ML-40: the end of the word stream let a skew of four words align, since the early lane stopped writing; on a link words never stop | Test sequence continues with ACTIVE rows after the last ALIGN (testbench) |
| TC-ML-40: a gap in an early lane does not slip the lanes (the FIFO absorbs it) | Slip modelled as an additional word on one lane (testbench) |
| TC-CORE-13 (fault injection campaign of the core): after a lane slip at one end, words of the frames sent by that end were missing at the far end without any error: the distributor discarded its held words when Not Ready was entered, the far end only received ACTIVE words (Both-Ends Ready to Near-End Ready, no RXERR) and kept the frame, and the CRC-16 computed after the distributor did not reveal the missing words | Held words are kept in Not Ready and sent after the realignment (ML-DS-12, TC-ML-44); only a link reset discards them |
| TC-CORE-13: a double error in the transmit row crossing of the core corrupted a word before the CRC-16 was computed, the far end accepted the frame | Poison mark of the row through the distributor to the column encoders, which invert the CRC-16 of the frame (ML-DS-13, ML-ENC-08, TC-ML-45, TC-ML-46) |
Observations:
- The treatment of control words and broadcast frames inside a data frame (excluded from the CRC-16 and from scrambling, specification section 5) follows from the standard but is not shown in its examples; it is checked with STAR-Dundee equipment in the lab test of phase 2.
- A bit error that hits a word which the Lane layer removes (SKIP, IDLE) or the word before it (ECSS 5.5.7l turns the previous word into RXERR as well) adds a word to one lane: a lane slip, followed by a realignment. This is a property of the standard; the distributor avoids IDLE rows while rows are available.
- The SKIP interval of the link testbench is 300 words to exercise SKIP often; the default is 5000.