CHIP DESIGN · COURSE

Embedded Firmware & Hardware–Software Co-Design

Turn a software-visible SoC specification into reproducible firmware and hardware evidence. Define register side effects, address maps, endianness, barriers, and atomic ownership from one generated contract. Bring the chip from reset vector through ROM, linker image, authenticated boot, stacks, memory, clocks, and early diagnostics. Build driver state machines, interrupts, timeouts, DMA ownership, cache maintenance, IOMMU teardown, and recovery without races or stale epochs. Verify firmware against independent bus and state oracles, hardware–software coverage, fault injection, emulation, and long workloads. Implement lifecycle-aware secure boot, transactional A/B update under arbitrary power loss, rollback, debug and manufacturing permissions. Qualify manufacturing firmware, calibration, identifiers, logs, performance, DVFS, watchdog, and telemetry. Finish with one independently reviewed release that boots, transfers, diagnoses, updates, recovers, and states exactly which silicon claims remain outside firmware evidence.

Before this course: Completed Computer Architecture; RTL Design; Functional Verification; SoC Integration & Hardware Security; Advanced SoC Verification; Tapeout; EDA Automation; and IP Qualification. Requires C or Rust, assembly reading, linker/build basics, concurrency, caches, virtual memory, cryptographic API concepts, and Python/shell automation. Production ROM signing keys, proprietary debuggers, emulators, tester access, irreversible OTP, and fabricated silicon require controlled lawful external resources and are not supplied.

COURSE FACTSStage, chapters, units, prerequisite, and outcome
Chapter 1

A register is a timed protocol endpoint, not just an address

Objective: For “A register is a timed protocol endpoint, not just an address,” which frozen inputs determine the result, what is the first independently observable claim, and which mutation proves the check is alive?

Fields can be read/write, read-only, write-one-to-clear/set, read-to-clear, self-clearing, sticky, reserved, shadowed, locked, aliased, atomic, privileged, or hardware-updated. This lesson uses the route “build the smallest observable case.” Begin with a hand-checkable instance before invoking automation: name the state that enters the step, the transformation that is permitted, the observation that must change, and the evidence that would falsify the claim. Define software-visible state, access semantics, ordering, atomicity, errors, resets, concurrency, and generated artifacts from one executable source. Connect every abstraction back to the physical structure or executable evidence it represents, and state where that representation stops being reliable.

A register is a timed protocol endpoint, not just an address has a reviewable contract: RTL, bus adapter, register generator, documentation, headers, firmware accessors, verification model, reset values, permissions, and side effects agree cycle by cycle. Name the applicable scope, identities, units, conditions, exclusions, threshold, evidence source, owner, and change rule before using the result. Separate control-plane success from design evidence: a process can exit zero while consuming the wrong revision, skipping work, reusing stale output, suppressing a violation, or publishing an incomplete artifact. Firmware performs read-modify-write on a write-one-to-clear status field and unintentionally clears a second pending event. The learner must identify the first divergence and repair the dependency, not merely rerun until a dashboard becomes green.

RTL, bus adapter, register generator, documentation, headers, firmware accessors, verification model, reset values, permissions, and side effects agree cycle by cycle. This invariant is accepted only for the named candidate and declared environment; any changed input invalidates every dependent result until reconstruction proves otherwise.

Freeze the exact objects, conditions, units, and source evidence in the worked case “Trace two pending status bits, a firmware acknowledgement of one bit, and a simultaneous new hardware event.” First freeze the candidate and predict the expected observation without reading a generated summary.

Apply the stated physical or engineering model, showing each transformation and preserving values that fail, are missing, or remain outside the model. Then execute the smallest transformation, retaining raw standard output, standard error, exit status, generated files, and resource use.

Compare the derived observation with “RTL, bus adapter, register generator, documentation, headers, firmware accessors, verification model, reset values, permissions, and side effects agree cycle by cycle.” and identify the first downstream decision invalidated by the failure boundary. Finally reconcile the observation with the invariant, inject the named failure, and verify that the expected consumer refuses the corrupted or stale state.

Trace two pending status bits, a firmware acknowledgement of one bit, and a simultaneous new hardware event. Before revealing the trace, predict the exact command or state transition, expected exit and artifact status, first checker that should react, and minimum safe recovery.

  1. Freeze the exact objects, conditions, units, and source evidence in the worked case “Trace two pending status bits, a firmware acknowledgement of one bit, and a simultaneous new hardware event.”
  2. Apply the stated physical or engineering model, showing each transformation and preserving values that fail, are missing, or remain outside the model.
  3. Compare the derived observation with “RTL, bus adapter, register generator, documentation, headers, firmware accessors, verification model, reset values, permissions, and side effects agree cycle by cycle.” and identify the first downstream decision invalidated by the failure boundary.

Result: The accessor writes an explicit one-bit mask; the other and newly arriving event remain pending under the declared priority. Accept the result only after a clean second execution reproduces the decisive artifact and a targeted mutation fails at the predicted boundary.