Files
FPGA-Neural/hardware/v1/docs/validation/13-coerenza-datasheet.md
T
micheleandClaude Sonnet 5 dc0b331d3e feat(v2): scaffold hardware/v1 frozen baseline + M1 Neural Processor
Begins the V2 Neural Multiprocessor / Dataflow architecture per
docs/v2-description.md, per explicit user request to freeze V1 and
start V2 development, copying from V1 what's needed.

Scaffold:
- hardware/v1/: byte-exact, read-only copy of the current V1 codebase
  (rtl, testbenches, tools, constraints, a representative subset of
  synthesis results, and reference docs) -- verified identical via
  diff/cmp against the live top-level tree before being made
  filesystem-read-only. The live top-level tree is untouched and
  remains the project's "production" V1 (see hardware/v1/README.md
  and hardware/v2/logs/decisions.log DEC-0001 for why copy-not-move).
- hardware/v2/: mandatory structure (rtl/sim/constraints/synthesis/
  reports/scripts/logs/docs) plus the full logging system required by
  the spec (development/architecture/simulation/synthesis/timing/
  benchmark/decisions/experiments/errors.log).

M1 -- Neural Processor (hardware/v2/rtl/neural_processor.v):
- 8-stage pipelined perceptron unit (P_IN=8): input align, 8
  multipliers, 3-level adder tree, accumulator, bias+activation, INT8
  saturation. Genuine 1-tile/cycle throughput, not just a wider
  combinational datapath.
- 7-state FSM (NP_IDLE..NP_ERROR per docs/v2-description.md §6, with
  4 baseline states merged into NP_WAIT_OPERANDS -- see
  decisions.log DEC-0002); valid/ready/data/last stream interfaces
  per §7.
- Bit-exact vs the frozen hardware/v1/rtl/neuron_parallel.v + mac8.v
  + mac_unit.v: 7/7 tests pass (hardware/v2/sim/tb_neural_processor.v),
  covering regular/mixed-sign/extreme-INT8 vectors, both activations,
  a zero-idle-gap back-to-back-tiles throughput check, and an 8-tile
  job -- verified with Verilator (see below for why).
- Real synthesis + place&route (Yosys + nextpnr-ecp5): 0 CHECK
  problems, Fmax 183.12 MHz at ACC_WIDTH=32 (PASS at 80MHz, ~3x V1's
  isolated PARALLEL=8 Fmax of 61.71 MHz) and 176.21 MHz at ACC_WIDTH=24
  (a user-requested comparison experiment, also bit-exact-verified;
  see experiments.log EXP-0001/EXP-0002 and benchmark.log).

Three real bugs found and resolved during M1 development (full
diagnostic record in errors.log):
- Two independent, reproducible Icarus Verilog v13.0 scheduling
  defects (ERR-0001, ERR-0002) that silently produced wrong simulation
  results for standard sequential Verilog -- confirmed via Verilator
  5.050 giving correct results on the same minimal repros. Verilator
  is now the trusted simulator for hardware/v2/ (decisions.log
  DEC-0004); Icarus's affected protocol-violation check was removed
  from the RTL and deferred architecturally to the Neural Director
  (DEC-0003) rather than chased further.
- One real RTL bug (ERR-0003): last0 wasn't gated like valid0,
  letting a "last tile" tag leak into the pipeline ahead of its
  actual valid tile on back-to-back jobs. Fixed and verified.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013xXuuRUWZScuo1DeYJxs3v
2026-09-05 14:06:53 +02:00

2.4 KiB
Raw Blame History

C.13 — Coerenza datasheet↔RTL

Data: 2026-09-04.

Metodo

Il lavoro di allineamento datasheet↔RTL più recente (pinout pin-per-pin, bus SPI flash indipendente, opcode 0x40-0x47, Fmax aggiornata) è stato fatto in questa stessa sessione, appena prima dell'avvio di questa campagna di certificazione — non preso dalla parola. grep mirato sui documenti per confermare che nessuna cifra ovviamente stantia sia rimasta (56 vs 57 segnali, USRMCLK, Fmax vecchie) non ha trovato residui.

Scostamento reale trovato: i bug di questa campagna non sono (ancora) nel datasheet

Nessuno dei 7 bug trovati in questa campagna (BUG-001BUG-007) è menzionato nel datasheet o in docs/FPGA-NeuralNetwork-Engine.md — verificato con una ricerca mirata, non assunto. Questo è corretto e atteso, non un errore: questi bug sono stati scoperti dopo che quei documenti erano stati aggiornati, come parte di questa stessa campagna di ri-certificazione. Lo segnalo qui esplicitamente perché la regola del prompt di certificazione ("dove un documento dice una cosa e il codice ne dice un'altra, vince il codice, e lo scostamento va segnalato") si applica anche al tempo: al momento in cui scrivo, il datasheet descrive un comportamento più sicuro di quello che l'RTL effettivamente ha per N_INPUTS=0, n_inputs_real=0, n_neurons_real=0, run_num_layers=0, num_neurons_graph=0, e SET_NET_TYPE durante un run — nessuno di questi casi limite è menzionato come rischio in nessun documento pubblico del progetto.

Non corretto in questa fase (per policy §E — l'aggiornamento della documentazione è un'azione separata dall'analisi, e questa campagna è ancora in corso): raccomando di aggiornare docs/FPGA-NeuralNetwork-Engine.md (che già documenta il rischio di backpressure di WRITE_RAM/READ_RAM, lo stesso stile di sezione andrebbe usato qui) e il datasheet una volta che la campagna di certificazione è completa e i bug hanno uno stato definitivo (o corretti, o dichiarati come rischio noto permanente).

Verdetto

CERTIFICATO per l'allineamento sulle cifre/pinout/opcode (nessun residuo stantio trovato). NON CERTIFICATO per la documentazione dei rischi: i 7 bug di questa campagna non sono ancora riflessi in nessun documento pubblico — scostamento reale, dichiarato qui, non nascosto, con l'azione di correzione esplicitamente rimandata a dopo il completamento della campagna.