Acceleration Method and System for Chisel Bounded Model Checking Based on Control Flow and Data Flow Information
By utilizing the program's control flow and data flow information in the Chisel hardware design verification framework, the assertion-based slice and migration system generation is carried out, and the variable selection strategy of the SMT solver is optimized, which solves the problems of inefficient verification and lack of targeted optimization in the existing technology, and achieves more efficient hardware design verification.
Patent Information
- Application Number
- CN202411799932.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2044-12-09
AI Technical Summary
In the existing Chisel hardware design verification framework, the SMT solver failed to effectively utilize the control flow and data flow information in the program during the verification process, resulting in low verification efficiency and lack of targeted optimization strategies.
By compiling the program to be verified, we obtain the FIRRTL intermediate representation and abstract syntax tree, obtain branch structure information and data flow diagram, perform assertion-based slices, generate a migration system, and combine control flow and data flow information for detection, optimize the variable selection strategy of the SMT solver.
The BMC verification efficiency of Chisel hardware design has been significantly improved. The experimental results show that the total solution time on riscv-mini and Nutshell processors has been significantly reduced, and the effect of combining control flow and data flow optimization is more significant.
Smart Images

Figure CN119720883B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of formal verification of hardware design, and particularly relates to an acceleration method and system for Chisel bounded model checking based on control flow and data flow information. Background Art
[0002] Chisel is an open-source hardware construction language for hardware design proposed by the University of California, Berkeley, which is embedded in the Scala language. This enables hardware developers to utilize the language features and programming paradigms of Scala to construct complex hardware modules. Since Scala is an object-oriented and functional language, Chisel allows users to describe circuits more concisely, perform modular and parametric design, and has been widely used in the design of RISC-V processors, such as Rocket Chip and NutShell. To ensure the correctness of hardware design, formal verification techniques such as bounded model checking (BMC) are used to verify the correctness of the design.
[0003] Bounded model checking is a technique commonly used in formal verification. In hardware verification, it aims to verify whether a hardware design satisfies a property within a given number of clock cycles. BMC explores all feasible circuit executions within a finite number of clock cycles in a symbolic manner and checks whether the circuit behavior violates the property. The behavior of a circuit can be defined as the transition relationship between circuit states. BMC unfolds the transition relationship k (k is a predefined bound) times to obtain a set of SMT formulas, which are input to an SMT solver for solution. If the solver gives a set of satisfiable assignments, it proves that the property can be violated; otherwise, it proves that the circuit satisfies the given property within the first k clock cycles. BMC has been introduced into the hardware design generated by Chisel.
[0004] Currently, most SMT solvers (including Z3) work based on the DPLL(T) framework. As Figure 1 shown, DPLL(T) first performs a boolean abstraction on the input formula, replaces the atomic formulas in the formula with boolean variables, and solves the formula by combining a SAT solver and a theory solver. DPLL(T) iteratively assigns values to variables by selecting a boolean variable and performing unit clause propagation. If there is no conflict after all boolean variables are assigned, and it is checked by the theory solver that the theory is not violated, the solution is valid; otherwise, when a conflict occurs, it backtracks and makes a new decision until a conflict-free solution is found or it is determined that there is no solution. In this process, the order in which boolean variables are selected has a great impact on the solving efficiency.
[0005] The formal verification process of the existing Chisel hardware design verification framework ChiselTest is as follows: compile the Chisel program into the FIRRTL intermediate representation, then convert it into a transition system, and the transition system is further encoded into the SMT2 format through BMC. The SMT solver is usually used as the backend solver. However, the SMT solver is for general constraint solving and cannot obtain high-level information in the program, while the control flow and data flow information in the program can be used in the variable selection strategy of the solver to improve the solving efficiency.
[0006] Therefore, the existing verification technologies mainly have the following disadvantages:
[0007] 1) Low verification efficiency: The SMT solver used as the backend by the ChiselTest verification framework uses a general algorithm for constraint solving, fails to utilize the high-level structural information in the program, has a large search space, and low solving efficiency.
[0008] 2) Lack of targeted optimization strategies: The control flow information in the program can be used to guide the search process of the SMT solver; performing data flow analysis on the program can apply program slicing to directly reduce the space of the program to be verified. Summary of the Invention
[0009] Aiming at the main problems existing in the prior art, which are low verification efficiency and lack of optimization methods for Chisel BMC verification, the present invention provides a method and system for accelerating Chisel bounded model checking based on control flow and data flow information, aiming to accelerate the BMC verification process of the hardware design generated by Chisel by utilizing the control flow and data flow information in the program.
[0010] To achieve the above object, the technical solution of the present invention includes the following content.
[0011] A method for accelerating Chisel bounded model checking based on control flow and data flow information, the method includes:
[0012] Compile the program to be verified to obtain the FIRRTL intermediate representation during the compilation process and the FIRRTL abstract syntax tree of the program to be verified;
[0013] According to the FIRRTL abstract syntax tree, obtain the branch structure information of the program to be verified; wherein, the branch structure information includes: the order between branch conditions or the edge information of the branch condition graph;
[0014] Combine the FIRRTL abstract syntax tree to perform assertion-based slicing on the program to be verified and retain the FIRRTL intermediate representation related to the assertion; wherein, the assertion is obtained based on the Chisel program.
[0015] Generate a transition system S based on the FIRRTL intermediate representation related to assertions;
[0016] Detect the program to be verified based on the transition system S and the branch structure information.
[0017] Furthermore, in combination with the FIRRTL abstract syntax tree, perform assertion-based slicing on the program to be verified and retain the FIRRTL intermediate representation related to assertions, including:
[0018] Traverse the FIRRTL abstract syntax tree to establish a data flow graph;
[0019] Perform graph reachability analysis on the data flow graph and, based on the analysis results, obtain the set of signals within the assertion and the nodes on which the signals depend; among them, the signals include: ports and registers.
[0020] For any FIRRTL intermediate representation, if the signals referenced by the FIRRTL intermediate representation are not within the set of signals within the assertion and the nodes on which the signals depend, then do not retain the FIRRTL intermediate representation.
[0021] Furthermore, according to the FIRRTL abstract syntax tree, obtain the branch structure information of the program to be verified, including:
[0022] Identify the branch structure in the FIRRTL abstract syntax tree and establish a branch structure graph with branch conditions as nodes and branch nesting relationships as edges;
[0023] Perform a topological sort on the branch structure graph to obtain the order between branch conditions;
[0024] Number the branch conditions according to the order between the branch conditions and store them through the FIRRTL built-in data structure annotation;
[0025] Or,
[0026] Identify the branch structure in the FIRRTL abstract syntax tree and establish a branch structure graph with branch conditions as nodes and branch nesting relationships as edges,
[0027] Store the edge information in the branch structure graph in the FIRRTL built-in data structure annotation; each edge in the branch structure graph corresponds to an annotation in the FIRRTL built-in data structure annotation.
[0028] Furthermore, the detection of the program to be verified based on the transition system S and the branch structure information includes:
[0029] Encode the branch structure information into the transition system S to obtain the transition system S′ ;
[0030] After expanding the migration system S ′ by k steps, it is encoded into an SMT file;
[0031] Use a solver to solve the SMT file to obtain the detection result of the program to be verified.
[0032] Further, when the branch structure information is the order between branch conditions, encode the branch structure information into the migration system S to obtain the migration system S ′ , including:
[0033] Obtain the nodes corresponding to the branch conditions in the migration system S from the FIRRTL built-in data structure annotation;
[0034] Modify the identifier of this node to obtain the migration system S ′ .
[0035] Further, when the branch structure information is the edge information of the branch condition graph, encode the branch structure information into the migration system S to obtain the migration system S ′ , including:
[0036] Traverse the annotation list of the FIRRTL built-in data structure annotation to locate each edge of the branch condition graph to the corresponding node in the migration system S;
[0037] Encode the edge information into the node identifier of the migration system S to obtain the migration system S ′ .
[0038] Further, the step of expanding the migration system S ′ by k steps includes:
[0039] Obtain the number m of branch nodes in the migration system S ′ ;
[0040] Based on the number m of branch nodes, the identifiers of the nodes in the migration system S ′ and the expansion step number i, modify the identifiers of the nodes in the migration system S ′ to obtain the expansion result of the migration system S ′ .
[0041] Furthermore, the solver includes: an SMT solver, a boolector solver, or an improved SMT solver; wherein, the improved SMT solver is to obtain the corresponding branch variables based on the order between branch conditions when making a decision to select Boolean variables in the DPLL(T) framework, and the process of obtaining the order between branch conditions includes:
[0042] In the case where the branch structure information is the order between branch conditions, obtaining based on the identifiers of the nodes in the expansion result of the transition system S ′ ;
[0043] In the case where the branch structure information is the edge information of the branch condition graph, obtaining the edge information based on the identifiers of the nodes in the expansion result of the transition system S ′ and, after reconstructing the branch condition graph according to the edge information, obtaining the order between branch conditions based on the reconstructed branch condition graph.
[0044] An acceleration system for Chisel bounded model checking based on control flow and data flow information, the system includes:
[0045] A program compilation module, configured to compile the program to be verified to obtain the FIRRTL intermediate representation during the compilation process and the FIRRTL abstract syntax tree of the program to be verified;
[0046] A control flow analysis module, configured to obtain the branch structure information of the program to be verified according to the FIRRTL abstract syntax tree; wherein, the branch structure information includes: the order between branch conditions or the edge information of the branch condition graph;
[0047] A data flow analysis module, configured to perform assertion-based slicing on the program to be verified in combination with the FIRRTL abstract syntax tree, and retain the FIRRTL intermediate representation related to the assertion; wherein, the assertion is obtained based on the Chisel program;
[0048] A system generation module, configured to generate a transition system S based on the FIRRTL intermediate representation related to the assertion;
[0049] A program detection module, configured to perform detection on the program to be verified based on the transition system S and the branch structure information.
[0050] An electronic device, the electronic device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the acceleration method for Chisel bounded model checking based on control flow and data flow information described in any one of the above is implemented.
[0051] Compared with the prior art, the present invention has at least the following beneficial effects.
[0052] 1) The present invention reduces the search space by preferentially selecting branch variables during decision-making. Experiments show that the total solution time of the present invention on two open-source processors, riscv-mini and Nutshell, has been reduced from 27670.00 s to 8899.62 s.
[0053] 2) The present invention performs slicing in combination with data flow information. By deleting statements unrelated to the assertion to be verified, the scale of the program to be verified is reduced. Experiments show that through data flow optimization, the total solution time of the present invention on two open-source processors, riscv-mini and Nutshell, has been reduced from 27670.00 s to 17812.36 s; the combination with control flow optimization has reduced it from 27670.00 s to 7425.20 s. Brief Description of the Drawings
[0054] Figure 1 It is a framework diagram of DPLL(T).
[0055] Figure 2 It is a flowchart of the acceleration method for bounded model checking of Chisel based on control flow and data flow information. Detailed Embodiment
[0056] The present invention will be described in detail below with reference to the drawings and embodiments. It should be noted that the described embodiments are only intended to facilitate the understanding of the present invention and do not impose any limitation on it.
[0057] The present invention is implemented based on the Chisel compiler FIRRTL, the ChiselTest framework, and the Z3 SMT solver, and its process is as Figure 2 shown, and specifically includes the following steps.
[0058] Step 1: Analyze the program control flow information in the High FIRRTL stage.
[0059] Add a compilation process to the FIRRTL compiler, traverse the FIRRTL abstract syntax tree to identify the branch structure therein (such as when...otherwise...), use the branch condition as a node and the branch nesting relationship as an edge to establish a branch structure diagram. Perform a topological sort on the branch structure diagram to obtain the order between branch conditions. Number the branch conditions according to this order and store them through the FIRRTL built-in data structure annotation, so that the information can be passed down throughout the compilation process.
[0060] Step 2: Perform program slicing based on assertions in the low FIRRTL stage, and only retain the signals related to the assertions.
[0061] Traverse the FIRRTL abstract syntax tree, build a data flow graph, and obtain the set of signals within the assertion and their dependent nodes through graph reachability analysis. For all FIRRTL intermediate representations, if the signals (ports, registers, etc.) they reference are not within the set of assertion signals and their dependent nodes, they are not retained.
[0062] Step 3: Encode the branch structure information into the transition system.
[0063] After generating the transition system, traverse the annotation list, find the corresponding nodes in the transition system for each annotation, extract the node sequence information, and the encoding is achieved by modifying the node identifiers in the transition system. For example, if the sequence number of node T is 5, then change its identifier to T_#5.
[0064] Step 4: Extend the branch structure information to k cycles.
[0065] During the BMC verification process, ChiselTest unfolds the transition system by k steps and encodes it into SMT. For the i-th step of the unfolding, modify the variable encoding T_#j to T_#j’, where j’ = i*m + j and m is the number of branch nodes.
[0066] Step 5: Use a solver for solving.
[0067] The backend solver can select different solvers and implement the corresponding decision heuristics within the DPLL(T) framework therein, such as solvers like SMT and boolector.
[0068] In one embodiment, the smt file encoded by ChiselTest is passed into the Z3 SMT solver for solving. In the SMT solver, when making a decision in the DPLL framework, a boolean variable is selected and the value of this boolean variable is decided. The present invention modifies the method of selecting variables when making a decision: when not all branch variables have been decided, preferentially select branch variables, and the order of selecting branch variables follows the order encoded in the variable identifier.
[0069] In addition, since the purpose of the encoding in step 3 is to transfer control flow information to the solver, the encoding method can be changed. Therefore, the present invention also provides another embodiment. The difference between this embodiment and the above-mentioned embodiment is that during control flow analysis, the branch structure diagram is stored in the annotation, and each edge of the branch structure diagram corresponds to an annotation. As the compilation process progresses, these annotations are passed through various stages. After generating the transition system, traverse the annotation list, and according to each annotation, locate the corresponding node in the transition system, and encode the edges stored in the annotation into the transition system node identifiers. During solving, use the encoded information to restore the branch structure diagram in the solver and calculate the order between variables in the solver.
[0070] In summary, the present invention inserts a compilation process in the FIRRTL compiler to obtain control flow information, establish a branch structure diagram, topologically sort branch variables, and use it as the basis for determining the decision order for subsequent input to the solver. In the solver, the decision-making process is modified to determine the decision order based on the order between variables deduced in advance. The branch structure actually contains the following information: when the Boolean variable represented by the when branch condition is decided to be true or false, the Boolean variables represented by the statements in the block should also be assigned the same Boolean value. Therefore, preferentially selecting branch variables can cause the statements in the block to be assigned values simultaneously, otherwise more assignment combinations may need to be explored. In addition, the hardware's final connection semantics indicate that the last connection in multiple connection operations on the same signal takes effect. This results in that when connecting the same signal within multiple sibling when statement blocks, the when branch variable at the last position should be preferentially decided.
[0071] The present invention combines control flow optimization and data flow optimization. In addition to proposing to use program control flow information to accelerate BMC solving, the present invention also introduces a data flow-based slicing technique on this basis, by deleting statements irrelevant to the assertion to be verified, narrowing the code fragment to be verified, and directly reducing the program space to be verified.
[0072] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Those skilled in the art should understand that any modifications, equivalent replacements, or improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention, and the protection scope is defined by the claims.
Claims
1. A Chisel bounded model detection acceleration method based on control flow and data flow information, characterized in that: The method comprises: Compile the program to be verified to obtain the FIRRTL intermediate representation in the compilation process and the FIRRTL abstract syntax tree of the program to be verified; According to the FIRRTL abstract syntax tree, the branch structure information of the program to be verified is obtained; wherein the branch structure information includes: the order between branch conditions or the edge information of the branch condition graph, and the branch structure information of the program to be verified according to the FIRRTL abstract syntax tree is obtained, including: Identify the branch structure in the FIRRTL abstract syntax tree, and build a branch structure graph with branch conditions as nodes and branch nesting relationships as edges; Perform topological sorting on the branch structure graph to obtain the order between branch conditions; The branch conditions are numbered according to the order between the branch conditions and stored through the FIRRTL built-in data structure annotation; or, Identify the branch structure in the FIRRTL abstract syntax tree, and use the branch conditions as nodes and the branch nesting relationships as edges to build a branch structure graph. The edge information in the branch structure graph is stored in the FIRRTL built-in data structure annotation; wherein each edge of the branch structure graph corresponds to an annotation in the FIRRTL built-in data structure annotation; In combination with the FIRRTL abstract syntax tree, the program to be verified is sliced based on assertions, and the FIRRTL intermediate representation related to the assertions is retained; wherein the assertions are obtained based on Chisel programs, and the FIRRTL abstract syntax tree is combined with the FIRRTL abstract syntax tree, the program to be verified is sliced based on assertions, and the FIRRTL intermediate representation related to the assertions is retained, including: Traverse the FIRRTL abstract syntax tree and build a data flow graph; Performing graph reachability analysis on the data flow graph, and obtaining signals in the assertion and a set of nodes on which the signals depend based on the analysis results; wherein the signals include: ports and registers; For any FIRRTL intermediate representation, if the signals referenced by the FIRRTL intermediate representation are not in the set of signals in the assertion and the signal dependency nodes, the FIRRTL intermediate representation is not retained; Generate a migration system S based on the FIRRTL intermediate representation associated with the assertion; The program to be verified is detected based on the migration system S and the branch structure information.
2. The method according to claim 1, characterized in that Detecting the program to be verified based on the migration system S and the branch structure information includes: The branch structure information is encoded into the migration system S to obtain the migration system S ′ ; Migrate system S ′ After k steps of expansion, it is encoded into an SMT file; The SMT file is solved using a solver to obtain a detection result of the program to be verified.
3. The method according to claim 2, characterized in that In the case where the branch structure information is the order between branch conditions, the branch structure information is encoded into the migration system S to obtain the migration system S ′ ,include: Obtain the node corresponding to the branch condition in the migration system S from the FIRRTL built-in data structure annotation; Modify the node identifier to obtain the migration system S ′ .
4. The method according to claim 2, characterized in that: In the case where the branch structure information is the side information of the branch condition graph, the branch structure information is encoded into the migration system S to obtain the migration system S ′ ,include: Traversing the annotation list of the FIRRTL built-in data structure annotation to locate each edge of the branch structure graph to a corresponding node in the migration system S; Encode the edge information into the node identifier of the migration system S, and obtain the migration system S ′ .
5. The method according to claim 2, characterized in that: The migration system S ′ Expand k steps, including: Get Migration System S ′ The number of branch nodes in m; Based on the number m of branch nodes, the migration system S ′ The identifier of the node and the expansion step number i in the middle, modify the migration system S ′ The identifier of the node in the migration system S ′ The expansion result.
6. The method according to claim 2, characterized in that The solver includes: an SMT solver, a boolector solver or an improved SMT solver; wherein the improved SMT solver is to obtain corresponding branch variables based on the order between branch conditions when the DPLL (T) framework makes a decision to select a Boolean variable and when all branch variables have not been decided, the process of obtaining the order between branch conditions includes: In the case where the branch structure information is the order between branch conditions, based on the migration system S ′ Get the identifier of the node in the expansion result; In the case where the branch structure information is the side information of the branch condition graph, based on the migration system S ′ The edge information is obtained by using the identifier of the node in the expansion result, and after reconstructing the branch condition graph according to the edge information, the order between the branch conditions is obtained based on the reconstructed branch condition graph.
7. A Chisel bounded model detection acceleration system based on control flow and data flow information, characterized in that: The system comprises: A program compilation module is used to compile the program to be verified, and obtain the FIRRTL intermediate representation in the compilation process and the FIRRTL abstract syntax tree of the program to be verified; A control flow analysis module, configured to obtain branch structure information of the program to be verified according to the FIRRTL abstract syntax tree; wherein the branch structure information includes: the order between branch conditions or the edge information of the branch condition graph, and the obtaining of the branch structure information of the program to be verified according to the FIRRTL abstract syntax tree includes: Identify the branch structure in the FIRRTL abstract syntax tree, and build a branch structure graph with branch conditions as nodes and branch nesting relationships as edges; Perform topological sorting on the branch structure graph to obtain the order between branch conditions; The branch conditions are numbered according to the order between the branch conditions and stored through the FIRRTL built-in data structure annotation; or, Identify the branch structure in the FIRRTL abstract syntax tree, and use the branch conditions as nodes and the branch nesting relationships as edges to build a branch structure graph. The edge information in the branch structure graph is stored in the FIRRTL built-in data structure annotation; wherein each edge of the branch structure graph corresponds to an annotation in the FIRRTL built-in data structure annotation; A data flow analysis module, used for combining the FIRRTL abstract syntax tree, slicing the program to be verified based on assertions, and retaining the FIRRTL intermediate representation related to the assertions; wherein the assertions are obtained based on Chisel programs, and combining the FIRRTL abstract syntax tree, slicing the program to be verified based on assertions, and retaining the FIRRTL intermediate representation related to the assertions, includes: Traverse the FIRRTL abstract syntax tree and build a data flow graph; Performing graph reachability analysis on the data flow graph, and obtaining signals in the assertion and a set of nodes on which the signals depend based on the analysis results; wherein the signals include: ports and registers; For any FIRRTL intermediate representation, if the signals referenced by the FIRRTL intermediate representation are not in the set of signals in the assertion and the signal dependency nodes, the FIRRTL intermediate representation is not retained; A system generation module is used to generate a migration system S based on the FIRRTL intermediate representation related to the assertion; A program detection module is used to detect the program to be verified based on the migration system S and the branch structure information.
8. An electronic device, characterized in that: The electronic device comprises: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the Chisel bounded model detection acceleration method based on control flow and data flow information as described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Conversion and verification method and device for Chisel high-level circuit design
CN118428285A
Integrated circuit design using metadata
WO2023163814A1