SIMT感知的锁步验证与功能覆盖率收敛方法:面向开源RISC-V GPGPU的UVM 1.2环境
SIMT-Aware Lockstep Verification and Functional-Coverage Closure Methodology for an Open-Source RISC-V GPGPU: A UVM 1.2 Environment
- Minia University(米尼亚大学)
- Siliconarts, Inc.(硅艺有限公司)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文提出UVM 1.2环境与方法论,为开源RISC-V GPGPU(Vortex)提供参考模型检查、SIMT锁步比较和三层功能覆盖率,实现98.1%覆盖率并发现多处真实缺陷,补充模糊测试以量化签核。
AI中文摘要:
开源RISC-V GPGPU(如Vortex)随附定向内核回归测试,但缺乏参考模型检查、功能覆盖率模型或签核纪律。本文提出了一种UVM 1.2环境和方法论,以弥补这一差距。该环境用角色反转的代理封装了一个总线主控SIMT待测设计(DUT),将Vortex的功能模拟器(SimX)作为基于DPI-C的每配置黄金模型集成,并通过两个注入合格的检查器给出裁决:一个双向端状态计分板和一个在五条SIMT对齐规则下的每指令、每通道锁步比较器。一种两遍加载值馈送机制使无栅栏的多核竞争程序可实现指令粒度验证(在5,432次退休中残余为零),并明确了中断时序边界。一个三层覆盖率模型增加了据我们所知首个用于RTL GPU验证的SIMT功能覆盖率层(发散深度、存储体冲突、合并类别),在机器生成且由RTL引用的排除项和阻塞式豁免完整性门控下,其自身各层闭合于98.1%的covergroup-bin/94.7%的总覆盖率(ISA层单独:83.1%的bin/89.3%的加权);一个未受刺激的D扩展细化不影响任何功能bin,仅降低总数。检查深度在比较双方都暴露了真实缺陷:一个JALR LSB ISA偏差、一个非缩放看门狗常量(已在上游修复)、通过恢复被静默的断言发现的重置中继X窗口、通过故障注入证明的缺失AXI错误路径,以及锁步本身发现的参考模型取指错误。FuzzGPU(USENIX Security 2026)是同一DUT上的并发RTL GPU模糊测试器,两者互补:模糊测试发现错误,本方法论量化签核;两者独立发现了JALR偏差。所有发现都记录在带证据引用的寄存器中;每个数字都有来源,方法的边界被明确说明而非豁免。
英文摘要:
Open-source RISC-V GPGPUs such as Vortex ship with directed-kernel regressions but no reference-model checking, functional-coverage model, or sign-off discipline. This paper presents a UVM 1.2 environment and methodology that closes that gap. The environment wraps a bus-master SIMT DUT with role-inverted agents, integrates Vortex's functional simulator (SimX) as a per-configuration golden model over DPI-C, and renders verdicts via two injection-qualified checkers: a bidirectional end-state scoreboard and a per-instruction, per-lane lockstep comparator under five SIMT alignment rules. A two-pass load-value feed makes racy fenceless multi-core programs instruction-granularity verifiable (residual zero over 5,432 retirements), with the interrupt-timing boundary stated. A three-layer coverage model adds, to our knowledge, the first published SIMT functional-coverage layer for RTL GPU verification (divergence depth, bank conflicts, coalescing classes), closing its own layers at 98.1% covergroup-bin / 94.7% total (ISA layer separately: 83.1% bins / 89.3% weighted) under machine-generated, RTL-cited exclusions and a blocking waiver-integrity gate; an unstimulated D-extension elaboration affects no functional bin, only lowering totals. The checking depth surfaced real defects on both sides of the comparison: a JALR LSB ISA deviation, a non-scaling watchdog constant (since fixed upstream), a reset-relay X window found by restoring a silenced assertion, a missing AXI error path proven by fault injection, and a reference-model fetch bug found by the lockstep itself. FuzzGPU (USENIX Security 2026), a concurrent RTL GPU fuzzer on the same DUT, is complementary: fuzzing finds bugs, this methodology quantifies sign-off; both independently found the JALR deviation. All findings ship in an evidence-cited register; every number carries provenance and the method's boundaries are stated rather than waived.