Clean sheet
CPU, cache hierarchy, chipset, graphics, peripherals, and board integration. Manuals, binaries, and original-hardware captures constrain the implementation.
02 / PURPOSE
Original PROM, IDE, IRIX, drivers, and applications define the system boundary. Printed inventory and isolated device tests do not.
CPU, caches, DMA, interrupts, graphics, storage, and Ethernet must remain correct together.
Preserve the failure. Find the first wrong boundary. Fix production RTL. Regress the machine.
CPU, cache hierarchy, chipset, graphics, peripherals, and board integration. Manuals, binaries, and original-hardware captures constrain the implementation.
Focused tests, full-system simulation, and FPGA builds use the same synthesizable modules.
Fills, writebacks, DMA snoops, posted I/O, interrupts, graphics, storage, and Ethernet overlap.
03 / uhfR4K
A clean-sheet 64-bit MIPS III processor for IP20. It executes the original PROM, standalone environment, IRIX kernel, Xsgi, and applications.
64-bit integer execution, forwarding, interlocks, architectural delay slots, precise exceptions, LL/SC, unaligned accesses, traps, and multi-cycle multiply/divide.
Mapped and unmapped segments, ASIDs, variable page masks, wired/random replacement, probe/read/write operations, Count/Compare, watch registers, and exact exception state.
Thirty-two 64-bit registers, single and double arithmetic, conversions, comparisons, control/status, rounding modes, flags, traps, and precise FPU exceptions. Every original IP20 IDE floating-point diagnostic passes on hardware.
Direct-mapped 32-byte lines, write-back data cache, fill and writeback sequencing, indexed and hit CACHE operations, aliases, and inclusion back-invalidations.
8,192 direct-mapped 128-byte lines in FPGA block RAM, dirty replacement, inclusion, tag operations, DMA intervention, write snoops, and uncached-access ordering.
Committed PC, registers, memory, HI/LO, and exception state are checked against independent architecture and floating-point vectors.
04 / IP20 SYSTEM
Original address maps, arbitration, DMA, interrupts, timing, and failure behavior.
CPU requests, posted GIO operations, main-memory access, graphics DMA, cache-coherent device DMA, programmable arbitration, interrupt delivery, and the DDR4 boundary.
WD33C93A SCSI, SEEQ 80C03 Ethernet, DSP host access, dual Z85130-compatible SCCs, 8254 timers, 93CS56 EEPROM, DP8572A-compatible RTC, and the interrupt masks and acknowledgement order used by IRIX.
REX command and raster state, VRAM, VC1 timing/SRAM/cursor, XMAP DID/CID lookup, Bt479 palette/DAC, and native scanout.
A synthesizable SCSI target performs command, status, data, and DMA phases against 512-byte SD sectors. The local EFS root is mounted read/write by unmodified IRIX.
The guest controller carries ordinary IRIX traffic. A separate raw-Ethernet management endpoint supplies observation and physical keyboard/mouse input without patching guest memory.
ALU, AGU, P/X/Y memories, decode, host interface, interrupts, DMA, REP and DO loops, and stock firmware execution are present in current source. Physical DSP diagnostics and the SSI-to-HDMI audio path remain open.
05 / METHOD
Fail before. Repair. Pass after. Regress. Prove the exact artifact on hardware.
INDEPENDENT ORACLE STACK
All original IP20 architecture diagnostics pass on hardware. Adapted vectors cover integer execution, 64-bit operations, branches, CP0, the 48-entry TLB, exceptions, LL/SC, caches, and FPU integration: 483 pass, zero fail.
All original IDE FPU diagnostics pass on hardware. SoftFloat/TestFloat uses the R4000 legacy NaN convention. All 92 applicable operation/rounding groups pass; 36 inapplicable groups are declared skips.
The original binaries, drivers, applications, and disassembly supply machine-specific tests. Every original IP20 IDE diagnostic passes except DSP and parity/ECC enforcement.
Framebuffer captures, transactions, registers, and workloads settle uncertain semantics. Specifications and original hardware outrank independent emulators.
Accepted REX/XMAP/DAC traffic is correlated with RB/VRAM, scanout, indexed-color resolution, DDR publication, fetch, and HDMI. Pixel-exact oracles cover primitives, textport, login, palettes, and application lifecycles.
CPU, cache, HPC, LG1, management, and DDR run with delayed responses and competing grants. Each accepted transaction retires once to its issuer.
Reduce the physical symptom to the smallest production-path test. It must fail before the change and pass after it. Expected results remain independent.
A proposed S-cache stage met 10 ns timing but broke tag-first snoops. The patch and its premise were discarded.
Tests bind to source and fixtures. Timing binds to a route. Hardware results bind to bitstream hashes and workloads.
Unidentified results are discarded.
06 / R4X00 COMPATIBILITY
A pre-existing MIPS core with a new PRId and a mustache can boot surprisingly far.
PRId does not add R4000 CP0, a 48-entry TLB, 64-bit exception rules, primary and secondary CACHE operations, a 1 MiB inclusive S-cache, or DMA intervention. uhfR4K implements them.
The mustache may be excellent. icache2 remains unmoved.
07 / CI, IMPLEMENTATION, DELIVERY
An exact clean commit is tested on Eclipse, implemented on Watson, collected with its reports and hashes, then accepted or rejected on the board.
Canonical Git, policy checks, CPU CI, production-RTL tests, full-system simulation, oracles, fixtures, and host tools.
An exact detached commit enters XSIM/XPM, memory-shape, OOC timing, CDC, synthesis, route, DRC, and bus-skew gates.
Source, constraints, reports, bitstream, probes, and hashes are collected before programming. Board results attach to that release.
Only clean commits enter implementation. Only collected, hashed releases reach the board. Hardware accepts or rejects the exact release.
08 / PHYSICAL IMPLEMENTATION
Exact KCU105 alpha 883c641, including DDR4 calibration/debug, capture, trace, management, BIST, and probes.
The 1 MiB S-cache and current on-chip PROM consume three quarters. Cache stays. PROM moves out of fabric.
The 16K×96 LG1 trace uses 43 RAMB36. Capture, BIST, telemetry, probes, and DDR calibration/debug are development infrastructure.
23,360 logic cells · 3,650 slices · 45 × 36 Kb BRAM · 80 DSP48E1
Cost reduction removes KCU105 DDR4 debug, HDMI capture, telemetry, recorders, BIST, probes, and fabric PROM. Structures may be serialized where IP20-visible order and timing permit.
uhfR4K, caches, MC/HPC behavior, LG1 semantics, and the stock-software boundary remain.
Device capacity: AMD DS180, 7 Series FPGAs Overview.
09 / CANONICAL RTL
Current synthesizable KCU105 product manifest.
cyan_simple_dual_port_ram.v79 lines · dual-port memorycyan_sync_byte_ram.v29 · byte-write memoryr4000_core.v4,099 lines · pipeline, CP0, retirementr4000_fpu.v4,622 · CP1r4000_scache.v3,042 · 1 MiB secondary cacher4000_dcache.v1,521 · primary D-cacher4000_icache.v1,154 · primary I-cacher4000_top.v654 · cache/CPU compositionr4000_tlb.v612 · 48-entry TLBr4000_muldiv.v555 · integer multiply/divider4000_alu.v112 · integer ALUmc.v1,764 · IP20 memory/GIO controllersd_spi_block.v902 · SD block transportscsi_raw_disk_target.v642 · SCSI targetsd_scsi_bridge.v602 · command/data bridgeip20_misc.v53 · board identificationscc_z8530.v1,888 · dual Z8530/Z85130 SCCshpc1.v1,782 · top-level HPC1.5hpc1_enet.v1,325 · SEEQ 80C03 Ethernetwd33c93.v809 · WD33C93A SCSI controllerhpc1_scsi_dma.v471 · SCSI DMAeeprom_93cs56.v318 · 93CS56 EEPROMhpc1_dma_arbiter.v278 · channel arbitrationint2.v244 · interrupt controllerdsp56001_core.v1,917 · execution/controldsp56001_decode.v974 · instruction decodedsp56001_alu.v542 · 56K arithmeticdsp56001_top.v514 · subsystem compositiondsp56001_mem.v334 · P/X/Y memorydsp56001_host.v325 · host interfacedsp56001_dma.v190 · normal DMAdsp56001_periph.v180 · peripherals/SSI boundarydsp56001_agu.v159 · address generationdsp56001_sram.v103 · external SRAMlg1_vc1_xmap_dac_scanout.v2,669 · timing, maps, DAC, scanoutlg1_rex_frontend.v2,232 · REX command/statelg1_rb_backend.v1,059 · pixel operationslg1_draw_iter.v1,037 · primitive iterationlg1_clean_core.v840 · LG1 compositionlg1_scanout_line_fetch.v395 · scanout fetchlg1_line_cache_64b.v330 · line cachelg1_rex_context_queue.v299 · accepted context orderinglg1_clean_line_core.v192 · line pathlg1_write_combiner_64b.v184 · VRAM write combininglg1_mem_line_adapter_64b.v122 · memory adaptationlg1_mem_arb_ssram.v103 · memory arbitrationlg1_vc1_ram_64k.v55 · VC1 SRAMip20_kcu_soc_core.v3,101 · complete SoC compositionkcu105_hdmi_frame_resampler.v1,552 · video publicationgmii_ethernet_mac.v1,315 · physical Ethernet MACcyan_mgmt_endpoint.v841 · independent control planemc_mig_bridge.v682 · MC to DDR4kcu105_adv7511_tx.v449 · HDMI transmitter controlcyan_cpu_island_bridge.v441 · 100/50 MHz transaction boundarykcu105_lg1_mig_bridge.v384 · LG1/DDR bridgekcu105_mig_app_arbiter.v333 · DDR ownershipcyan_sgi_input_device.v320 · SGI keyboard/mouse modelkcu105_sgmii_ethernet.v258 · PHY/SGMIIcyan_lg1_config_trace.v237 · accepted LG1 tracecyan_mgmt_frame_router.v231 · guest/management splitkcu105_lg1_capture_bist.v236 · capture validationcyan_frame_arbiter.v186 · frame ownershipcyan_hpc_dma_coordinator.v179 · HPC/MC quiescencekcu105_lg1_capture_reader.v178 · coherent capture readsip20_prom_rom.v170 · PROM memory boundarycyan_lg1_config_event_encoder.v78 · trace records// HPC is an always-real-time requester and preempts either
// long-burst owner. Its service pauses the active tenure.
if (dma_valid) begin
if (dma_ram_valid) begin
ram_addr <= dma_ram_idx;
ram_wdata <= dma_wdata;
ram_wmask <= dma_wmask;
ram_wen <= dma_write;
ram_valid <= 1'b1;
state <= S_DMA_RAM;
end else begin
// DMA to non-existent RAM — return zeros, complete
dma_rdata <= 64'h0;
dma_ready <= 1'b1;
state <= S_WAIT;
end
// Raw HPC demand reserves MC while the tag-first S-cache
// lookup resolves. No new CPU or VDMA external transfer
// may enter in that interval. A fill/writeback already
// serialized by the S-cache must drain, however, because
// the coherence lookup can depend on its completion.
end else if (arb_grant_vdma && !dma_rt_request) begin
if (!arb_owner_vdma) begin
arb_owner_vdma <= 1'b1;
arb_time_left <= lb_time;
endHPC is real-time. CPU and graphics DMA are long-burst. One serialized cache transfer may drain to avoid deadlock.
// A Primary-D intervention beat is accepted only when it owns the shared
// data-RAM write port. Queued DMA merges have priority in the mux below.
assign backinv_ready = (state == S_BACKINV_WAIT) &&
!snoop_update_ram_write;
// A DMA write can arrive after a fill has started but before the new tag
// is installed. Metadata lookup then cannot report a hit even though
// already-returned fill words may be stale. CDE zeroing has the same
// ownership window: the target tag is not installed until the final zero
// write. Queue DMA bytes exactly as for an installed-line hit and apply
// them after the fill/CDE RAM writes.
wire snoop_fill_match =
snoop_wr_accept &&
(state == S_DFILL || state == S_IFILL || state == S_CDE_ZERO ||
state == S_DONE) &&
(snoop_addr[31:7] == fill_addr[31:7]);
wire snoop_update_push =
(snoop_meta_hit_q || snoop_fill_match_q) &&
(snoop_meta_wmask_q != 8'h00);
wire snoop_update_pop = snoop_update_ram_write;
wire snoop_update_push_accept = snoop_update_push &&
(!snoop_update_full || snoop_update_pop);
// A completed DMA write is already visible in external RAM when its
// registered S-cache lookup and queued merge arrive. Hold an unaccepted
// CPU writeback until that merge reaches cache RAM, then re-prime the
// synchronous writeback word. Raw pending DMA reads are deliberately not
// part of this exclusion: MC may already own the CPU writeback.
wire writeback_dma_write_block = snoop_wr_accept || snoop_meta_req_q ||
snoop_update_pending;External DMA updates or invalidates the inclusive write-back S-cache, including the interval before the new tag is installed.
// Classification
wire s_is_nan_a = (s_exp_a == 8'hFF) && (s_man_a != 0);
wire s_is_nan_b = (s_exp_b == 8'hFF) && (s_man_b != 0);
wire s_is_inf_a = (s_exp_a == 8'hFF) && (s_man_a == 0);
wire s_is_inf_b = (s_exp_b == 8'hFF) && (s_man_b == 0);
// R4000 legacy NaN convention:
// mantissa MSB = 1 → SNaN, mantissa MSB = 0 → QNaN
wire s_is_snan_a = s_is_nan_a && s_man_a[22];
wire s_is_snan_b = s_is_nan_b && s_man_b[22];
wire s_is_qnan_a = s_is_nan_a && !s_man_a[22];
wire d_is_snan_a = d_is_nan_a && d_man_a[51];
wire d_is_snan_b = d_is_nan_b && d_man_b[51];
wire d_is_qnan_a = d_is_nan_a && !d_man_a[51];
// Default QNaN values (R4000 legacy: MSB=0 is quiet)
wire [31:0] s_default_qnan = 32'h7FBFFFFF;
wire [63:0] d_default_qnan = 64'h7FF7FFFFFFFFFFFF;
// Propagate the first NaN operand, quieted under that convention.
wire [31:0] s_prop_nan = s_is_nan_a ?
{fs_val[31], 8'hFF, 1'b0, fs_val[21:0]} :
{ft_val[31], 8'hFF, 1'b0, ft_val[21:0]};CP1 and SoftFloat/TestFloat use the R4000 convention. Native IDE FPU diagnostics and all 92 applicable external groups pass.
10 / KCU105 ALPHA
Physically tested bitstream, probes, hashes, and host input tools.
883c641a0c185af0ae9cc61501e8cbc616d8e3d29e6fe09283d74b5daeddac718d6535564492c7b8d8898ee884438c3f6233d20fThis is a research alpha supplied without warranty. It may hang, panic, corrupt removable-media contents, or even explode your FPGA. Use an expendable SD card and retain your source image elsewhere. No IRIX disk image is included.
HOST INPUT
cyanctl converts host events to SGI keyboard and five-byte mouse packets, queues them at serial-wire pace, and feeds the synthesized Z8530 receive path. PROM and IRIX receive normal bytes and interrupts. The management endpoint is independent of guest Ethernet.
sudo python3 tools/cyanctl.py input \ --interface ens18 text 'root' sudo python3 tools/cyanctl.py input \ --interface ens18 key enter sudo python3 tools/cyanctl.py input \ --interface ens18 mouse --buttons 0 --dx 24 --dy -8 destination 02:43:59:41:4e:01 EtherType 0x88b5 KBD_BYTES opcode 0x10 MOUSE_BYTES opcode 0x11 buttons 1=left 2=middle 4=right
11 / CURRENT STATE
Hardware results belong to 883c641. Later source admissions are listed separately.
Accepted on the downloadable release.
100.04 MHz, 64-bit MIPS III, CP0, 48-entry TLB, CP1, precise exceptions, stock PROM/IDE/IRIX.
8 KiB I/D caches; 1 MiB S-cache; indexed/hit CACHE; inclusion; dirty writeback; DMA intervention. TLB and icache2 pass.
128 MiB DDR-backed memory; CPU/GIO requests; posted writes; priority arbitration; coherent device access.
DMA ownership, interrupt masks and acknowledgement, timers, and IRIX programmed I/O.
Command, status, data, and HPC DMA to SD. Local EFS mounts read/write.
Descriptor DMA, packets, interrupts, physical MAC, routed IRIX traffic. Separate management plane.
Dual channels; console; paced SGI keyboard and five-byte mouse packets; receive FIFO interrupts.
Runtime clock and nonvolatile registers through HPC. External devices and canonical defaults remain open.
REX, RB, VRAM, VC1 timing/cursor, XMAP, DAC, Xsgi, and HDMI. VRAM, CID, VC1, SRAM, DAC, and REX diagnostics pass.
XDM, Xsgi, 4Dwm, Toolchest, System Manager, ObjectServer, storage, networking, and SCC input.
Board management, framebuffer capture, SCC/LG1 traces, exact-commit simulation, guarded programming, hash-locked releases.
Newer than the hardware alpha.
20 MHz core, P/X/Y memories, host port, interrupts, RTC/SRAM, normal DMA, REP/DO, installed firmware startup, driver command, and composed stock diagnostic pass production-RTL oracles.
Promotion gates and deferred reliability work.
Most applications match pixel-exact real-hardware replays. Managed private-colormap pressure can expose an Xsgi/4Dwm residency-reinstall edge.
Hardware IDE and S83audio; remaining ISA/ROM, fast vectors, nesting, folded DMA, SSI, SPDIF/ADV7511, playback.
Main-memory/cache parity and S-cache ECC: generation, storage, checking, injection, status, exceptions.
External EEPROM and battery backed clock support with finalized canonical NVRAM defaults.
Repeated clean boots, independent I/O load, native shutdown, stable graphics lifecycle.