Trace circuit, semiconductor device, tracer, trace system, trace method

The trace circuit in the semiconductor device addresses the challenge of tracing program memory read addresses by outputting trace data based on the program counter's state, enabling effective debugging and code coverage analysis without requiring a trace memory inside the LSI.

JP7690088B2Active Publication Date: 2025-06-09ROHM CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024077940
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-10-18
Filing Date
2024-05-13
Publication Date
2025-06-09
Estimated Expiration
2040-10-16

AI Technical Summary

Technical Problem

Existing trace circuit technologies require a trace memory inside the LSI or output of all address buses outside the LSI, making it difficult to trace the read address of a program memory from outside a semiconductor device, especially when branch destination addresses cannot be narrowed down.

Method used

A trace circuit integrated in a semiconductor device with a microprocessor, which outputs a trace clock and n-bit trace data to the outside. The trace data is used as different output values based on the program counter's state, and after temporarily stopping the microprocessor's state machine, the branch destination address or interrupt destination address is divided and output as trace data.

Benefits of technology

Enables simple and complete tracing of the read address of a program memory from outside the semiconductor device without the need for a trace memory inside the LSI, allowing for effective debugging and code coverage analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007690088000001
    Figure 0007690088000001
  • Figure 0007690088000002
    Figure 0007690088000002
  • Figure 0007690088000003
    Figure 0007690088000003
Patent Text Reader

Abstract

To easily and completely trace read addresses of a program memory from outside a device.SOLUTION: A trace circuit 120 is integrated in a semiconductor device 100 along with a microprocessor 110 including an m-bit program counter (PC) 116 (where 2≤m), and externally outputs trace data (trace_data) in synchronization with a trace clock (trace_clk). The trace circuit 120 changes an output value of the trace data (trace_data) that is externally output in response to operation of the program counter 116.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention disclosed in this specification relates to a trace circuit.

Background Art

[0002] In an LSI equipped with a microprocessor (such as a CPU [central processing unit]) that performs program operations, there is a demand to trace the program operations from outside the LSI, that is, to know how the program has operated.

[0003] The reason is to find the cause of a defect where the program is not operating as expected, or to investigate the code coverage (whether it is a test that covers all the code) in the program operation test.

[0004] To meet the above demand, it is necessary to know how the CPU reads the instruction codes on the program memory, in other words, to trace the read address of the program memory inside the CPU.

[0005] As an example of the prior art related to the above, Patent Document 1 and Patent Document 2 can be cited.

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0007] However, in Patent Document 1, a trace storage means (trace memory) is required inside the LSI. Or, it is necessary to output all address buses outside the LSI.

[0008] Also, in Patent Document 2, since only part of the information is output outside the LSI when a branch instruction is executed, it is necessary to analyze the branch destination address outside the LSI. Therefore, when the branch destination address cannot be narrowed down to one from among the branch destination address candidates, tracing becomes impossible.

[0009] In view of the above problems found by the inventors of the present application, the invention disclosed in this specification aims to provide a trace circuit for simply and completely tracing the read address of a program memory from outside a semiconductor device.

Means for Solving the Problems

[0010] The trace circuit disclosed in this specification is integrated in a semiconductor device together with a microprocessor having an m-bit program counter, and is a trace circuit that outputs a trace clock and n-bit (where 2 ≤ n ≤ m) trace data to the outside. When the program counter is unchanged, the trace data is used as a first output value in synchronization with the trace clock. When the program counter is incremented, the trace data is used as a second output value in synchronization with the trace clock. When the program counter is loaded, the trace data is used as a third output value in synchronization with the trace clock. After temporarily stopping the state machine of the microprocessor, the branch destination address or interrupt destination address loaded into the program counter is divided and output as the trace data (first configuration).

[0011] Note that the trace circuit having the above first configuration generates a status signal that becomes the first output value when the program counter is unchanged, becomes the second output value when the program counter is incremented, and becomes the third output value when loaded into the program counter; a counter that starts operating when the status signal becomes the third output value and stops operating when the divided output period of the branch destination address or the interrupt destination address ends; and a selector that selects the status signal as the trace data while the counter is stopped and selects a part of the branch destination address or the interrupt destination address as the trace data while the counter is operating. It is preferably configured (second configuration).

[0012] Further, in the trace circuit having the above second configuration, the status generation unit preferably has a configuration (third configuration) that monitors an internal control signal of the microprocessor and generates the status signal.

[0013] Further, in the trace circuit having any one of the first to third configurations, the trace clock is preferably a drive clock of the microprocessor (fourth configuration).

[0014] In addition, the semiconductor device disclosed in this specification is configured (fifth configuration) by integrating a trace circuit having any one of the first to fourth configurations; and a microprocessor that reads an instruction code from a program memory using the output value of the program counter as a read address, and decodes and executes the instruction code.

[0015] Note that in the semiconductor device having the above fifth configuration, the microprocessor preferably has a pipeline structure (sixth configuration).

[0016] In addition, the tracer disclosed in this specification is externally attached to a semiconductor device having the above-described fifth or sixth configuration, monitors the trace data in synchronization with the trace clock, and outputs the trace result of the read address by simulating the program counter (seventh configuration).

[0017] Note that the tracer having the above-described seventh configuration includes a simulated program counter; a decoder that keeps the simulated program counter unchanged when the trace data is the first output value, increments the simulated program counter when the trace data is the second output value, and sequentially stores the branch destination address or the interrupt destination address that is subsequently divided and input into the simulated program counter when the trace data is the third output value; a latch that captures the output value of the simulated program counter as a fixed value in synchronization with the trace clock except during the divided input period of the branch destination address or the interrupt destination address; and a trace memory that stores the fixed values sequentially captured by the latch as the trace result (eighth configuration).

[0018] In addition, the trace system disclosed in this specification has a configuration (ninth configuration) including a semiconductor device having the above-described fifth or sixth configuration; a tracer having the above-described seventh or eighth configuration; and a host that displays, stores, and analyzes the trace result.

[0019] Furthermore, the trace program disclosed in this specification is executed on a computer, and the input unit, display unit, storage unit, and arithmetic unit of the computer are respectively operated as the input means, display means, storage means, and analysis means of the trace result, so that the computer functions as the host in the trace system having the above-described ninth configuration (tenth configuration).

Advantages of the Invention

[0020] According to the trace circuit disclosed in this specification, it is possible to simply and completely trace the read address of the program memory from the outside of the semiconductor device.

Brief Description of the Drawings

[0021]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Embodiments for Carrying Out the Invention

[0022] <Trace System> Figure 1 is a diagram showing the overall configuration of the trace system. The trace system X in this configuration example includes an LSI 100, a tracer 200, and a host 300.

[0023] The LSI 100 is an example of a semiconductor device equipped with a CPU 110. Note that the LSI 100 has a function of externally outputting one trace clock trace_clk and n-bit (for example, n = 2) trace data trace_data synchronized with this to the tracer 200 in order to simply and completely trace the program operation (= read address of the program memory) of the CPU 110 from the outside (details will be described later).

[0024] The tracer 200 is an example of an adapter (debug tool) externally attached to the LSI 100. It monitors the trace data trace_data in synchronization with the trace clock trace_clk, and by simulating the program counter inside the CPU 110, it obtains the trace result trace_result of the read address described above and outputs it to the host 300 (details will be described later). As the communication means between the tracer 200 and the host 300, USB [universal serial bus] etc. can be preferably used.

[0025] The host 300 receives the input of the trace result trace_result from the tracer 200 and performs its display, storage, analysis, etc. For example, when using a personal computer as the host 300, a trace program 310 executed on the personal computer is prepared, and the input section (such as a USB port), display section (such as an LCD [liquid crystal display]), storage section (such as an HDD [hard disc drive], SSD [solid state drive]), and arithmetic section (such as a CPU, DSP [digital signal processor]) of the personal computer are made to function as the input means, display means, storage means, and analysis means of the trace result trace_result, respectively.

[0026] Note that it is desirable that the above tracer 200 and trace program 310 be provided together with the LSI 100.

[0027] <lsi> FIG. 2 is a diagram showing a configuration example of the LSI 100. In the LSI 100 of this configuration example, a trace circuit 120 is integrated together with the CPU 110 described above.

[0028] The CPU 110 is an example of a microprocessor that performs a program operation in synchronization with a drive clock CLK (for example, 100 MHz), and includes a state machine 111, a decode / execution unit 112, an increment unit 113, a branch destination address storage unit 114, a selector 115, a program counter (PC) 116, and a program memory 117.

[0029] The state machine 111 is a 3-bit sequential circuit (logic circuit) that controls the state transition of the CPU 110, and can take a maximum of eight operating states state (FETCH, WAIT_KEEP, TRACE, PRE_FETCH, etc.). The TRACE state is one of the newly introduced operating states state with the implementation of the trace circuit 120. Although details will be described later, while the trace circuit 120 divides and outputs the branch destination address or interrupt destination address loaded into the program counter 116 as trace data trace_data, the state machine 111 is temporarily stopped in the TRACE state.

[0030] The decode / execution unit 112 reads an instruction code from the program memory 117 using the output value pc_reg of the program counter 116 as a read address, decodes the instruction code, and executes it.

[0031] The increment unit 113 increases the output value pc_reg of the program counter 116 by a predetermined increment value and outputs it.

[0032] The branch destination address storage unit 114 holds the branch destination address or interrupt destination address output from the decode / execution unit 112 when loading it into the program counter 116.

[0033] Selector 115 selectively outputs to program counter 116 the output of either the increment section 113 or the branch destination address storage section 114 in response to internal control signals (e.g., PC load instruction pc_load and PC increment instruction pc_inc) output from the decode / execute section 112.

[0034] For example, when pc_inc = "H" (= logical level at the time of PC increment), the output of the increment section 113 is selectively output to the program counter 116. As a result, when the CPU 110 has a pipeline structure, the program counter 116 is incremented in parallel with the decode / execute of the instruction code. Or, when the CPU 110 does not have a pipeline structure, the program counter 116 is incremented after the decode / execute of the instruction code.

[0035] On the other hand, when pc_load = "H" (= logical level at the time of PC load), the output of the branch destination address storage section 114 is selectively output to the program counter 116. Therefore, for example, when any of the interrupt instructions NMI [non-maskable interrupt] and IRQ [interrupt request], jump instructions JMP (absolute / relative), subroutine call instruction CALL, and return instructions RET and RETI are executed, resulting in pc_load = "H", the branch destination address or interrupt destination address is loaded into the program counter 116.

[0036] The program counter 116 is an m-bit (e.g., m = 16) register that operates in synchronization with the drive clock CLK. Note that the output value pc_reg of the program counter 116 is used as the read address of the program memory 117.

[0037] The program memory 117 is a storage means for storing the instruction codes of the CPU 110. Note that the instruction code read out according to the read address (pc_reg) is decoded / execute by the aforementioned decode / execute section 112.

[0038] The trace circuit 120 is a new functional block that externally outputs one trace clock trace_clk and n-bit (where 2 ≤ n ≤ m, for example, n = 2) trace data trace_data synchronized with this to the tracer 200, and includes a status generation unit 121, a counter 122, and a selector 123.

[0039] Note that as the above trace clock trace_clk, the drive clock CLK of the CPU 110 may be used as it is.

[0040] The status generation unit 121 operates in synchronization with the trace clock trace_clk, monitors the internal control signals of the CPU 110 (for example, the PC load instruction pc_load and the PC increment instruction pc_inc), and generates a 2-bit status signal status.

[0041] More specifically, the status signal status becomes the first output value "0d (00b)" when the program counter 116 is unchanged (pc_load = "L" and pc_inc = "L"), the second output value "1d (01b)" when the program counter 116 is incremented (pc_inc = "H"), and the third output value "2d (10b)" when loaded into the program counter 116 (pc_load = "H"). Regarding the fourth output value "3d (11b)" of the status signal status, it may be set as a reserved value (unused value).

[0042] The counter 122 is a 4-bit pulse counter. The counter 122 starts the pulse counting operation of the trace clock trace_clk when the status signal status becomes the third output value "2d (10b)", that is, when a load to the program counter 116 occurs. Also, when the count value trace_count reaches a predetermined value (for example, 8d (1000b)), that is, when the divided output period of the branch destination address or the interrupt destination address (details will be described later) ends, the counter 122 stops the pulse counting operation and resets the count value trace_count to 0.

[0043] Selector 123 selects either the status signal status or the output value pc_reg (the maximum of which is n bits) of program counter 116 according to the operating state of counter 122 (whether the count value trace_count is 0), and outputs it as trace data trace_data.

[0044] More specifically, when counter 122 is stopped (trace_count = 0), the status signal status is output as trace data trace_data. On the other hand, when counter 122 is operating (trace_count ≠ 0), the output value pc_reg of program counter 116 (= a part of the branch destination address or interrupt destination address) is sequentially output as trace data trace_data.

[0045] Note that in order to completely output the branch destination address or interrupt destination address as trace data trace_data, it is desirable to set the state machine 111 of CPU 110 to a paused state (TRACE state) when counter 122 is operating (trace_count ≠ 0).

[0046] With the trace circuit 120 having the above configuration, with a very simple circuit configuration, when the program counter 116 is unchanged, the trace data trace_data is set to the first output value "0d (00b)" in synchronization with the trace clock trace_clk, when the program counter 116 is incremented, the trace data trace_data is set to the second output value "1d (01b)" in synchronization with the trace clock trace_clk, when the program counter 116 is loaded, the trace data trace_data is set to the third output value "2d (10b)" in synchronization with the trace clock trace_clk, and after temporarily stopping the state machine 111 of CPU 110, the branch destination address or interrupt destination address loaded into the program counter 116 can be split and output as trace data trace_data. This will be described in detail below with reference to the flowchart.

[0047] <Trace operation (LSI side)> Figure 3 is a flowchart showing an example of the trace operation in LSI 100 (particularly the trace circuit 120). When the trace operation starts, in step S11, it is determined whether the program counter 116 has been incremented (whether pc_inc = "H"). Here, if the determination is no, the flow proceeds to step S12, and if the determination is yes, the flow proceeds to step S14.

[0048] When the determination in step S11 is no, in step S12, it is determined whether the program counter 116 has been changed (branched or interrupted) (whether pc_load = "H"). Here, if the determination is no, the flow proceeds to step S13, and if the determination is yes, the flow proceeds to step S15.

[0049] When the determination in step S12 is no, it is necessary to inform the tracer 200 that the program counter 116 remains unchanged. Therefore, in step S13, the trace data trace_data is set to the first output value "0d (00b)". Then, the flow returns to step S11.

[0050] On the other hand, when the determination in step S11 is yes, it is necessary to inform the tracer 200 that the program counter 116 has been incremented. Therefore, in step S14, the trace data trace_data is set to the second output value "1d (01b)". Then, the flow returns to step S11.

[0051] Also, when the determination in step S12 is yes, it is necessary to inform the tracer 200 that a load to the program counter 116 has occurred. Therefore, in step S15, the trace data trace_data is set to the third output value "2d (10b)".

[0052] Furthermore, when loading into the program counter 116, it is necessary to convey the branch destination address or the interrupt destination address to the tracer 200. Therefore, in the subsequent steps S16 to S18, the split output of the branch destination address or the interrupt destination address is performed.

[0053] Specifically, first in step S16, the pulse counting operation of the trace clock trace_clk by the counter 122 is started, and the state machine 111 of the CPU 110 is set to the pause state (TRACE state).

[0054] Next, in step S17, in synchronization with the trace clock trace_clk, a part of the branch destination address or the interrupt destination address is split and output as trace data trace_data.

[0055] Next, in step S18, it is determined whether or not the count value trace_count of the counter 122 has reached a predetermined value, that is, whether or not the counting in the split output period has ended.

[0056] For example, when the output value pc_reg (= branch destination address or interrupt destination address) of the program counter 116 is 16 bits and the trace data trace_data is 2 bits, in order to output all the bit values of the branch destination address or the interrupt destination address, at least 8 pulses of the trace clock trace_clk are required.

[0057] If the NO determination is made in step S18, the flow returns to step S17 and the split output of the branch destination address or the interrupt destination address continues. On the other hand, if the YES determination is made, the flow proceeds to step S19.

[0058] In step S19, the count value trace_count of the counter 122 is reset to 0, and the state machine 111 of the CPU 110 is restored from the pause state (TRACE state). After that, the flow returns to step S11 and the above series of operations are repeated.

[0059] <Tracers> FIG. 4 is a diagram showing a configuration example of the tracer 200. The tracer 200 of this configuration example includes a decoder 201, an increment unit 202, a selector 203, an analog program counter 204, a latch 205, and a trace memory 206.

[0060] The decoder 201 monitors the trace data trace_data in synchronization with the trace clock trace_clk, and controls each part (such as the selector 203 and the latch 205) of the tracer 200.

[0061] Specifically, when the trace data trace_data is the first output value "0d (00b)", the decoder 201 keeps the analog program counter 204 unchanged. When the trace data trace_data is the second output value "1d (01b)", the decoder 201 increments the analog program counter 204. When the trace data trace_data is the third output value "2d (10b)", the decoder 201 controls the selector 203 so that the branch destination address or interrupt destination address that is subsequently split-input is sequentially stored in the analog program counter 204.

[0062] In addition, the decoder 201 generates a definite value fetch instruction signal fetch_inst based on the monitoring result of the trace data trace_data, and controls whether to capture the output value pc_count of the analog program counter 204 as the analog PC definite value dump_pc by the latch 205.

[0063] The increment unit 202 increases the output value pc_count of the analog program counter 204 by a predetermined increment value and outputs it.

[0064] The selector 203 selectively outputs any one of the trace data trace_data, the output value of the increment unit 113, and the output value pc_count of the analog program counter 204 to the analog program counter 204.

[0065] More specifically, when the trace data trace_data is the first output value "0d (00b)", the output value pc_count of the simulation program counter 204 is selectively output to the simulation program counter 204 in order to keep the simulation program counter 204 unchanged. Note that the simulation program counter 204 may be kept unchanged by prohibiting the fetch operation of the simulation program counter 204.

[0066] On the other hand, when the trace data trace_data is the second output value "1d (01b)", the output value of the increment part 113 is selectively output to the simulation program counter 204 in order to increment the simulation program counter 204.

[0067] Also, when the trace data trace_data is the third output value "2d (10b)", the trace trace_data is selectively output to the simulation program counter 204 so that the branch destination address or interrupt destination address that is subsequently divided and input is sequentially stored in the simulation program counter 204.

[0068] The simulation program counter 204 is an m-bit (for example, m = 16) register that operates in synchronization with the trace clock trace_clk and simulates the program counter 116 of the CPU 110.

[0069] The latch 205 takes in the output value pc_count of the simulation program counter 204 as the simulation PC determination value dump_pc in synchronization with the trace clock trace_clk except during the divided input period of the branch destination address or interrupt destination address (details will be described later). Note that the operation enable / disable of the latch 205 is determined based on the determination value fetch instruction signal fetch_inst. More specifically, when fetch_inst = "H", the latch operation is permitted, while when fetch_inst = "L", the latch operation is prohibited.

[0070] The trace memory 206 stores the analog PC determination value dump_pc sequentially captured by the latch 205 as the trace result trace_result. Regarding the output operation of the trace result trace_result, for example, it may be output at any time in response to a request from the host 300, or it may be output periodically every time a certain amount is buffered.

[0071] In this way, if a configuration is such that from the LSI 100 (especially the trace circuit 120), one trace clock trace_clk and n-bit (for example, n = 2) trace data trace_data synchronized with this are externally output, and the program counter 116 of the CPU 110 is simulated using the tracer 200 externally attached to the LSI 100, it is not necessary to implement a trace memory in the LSI 100. Therefore, without increasing the overhead of the LSI 100, the program operation (read address) of the CPU 110 can be traced simply and completely with a small number of pins.

[0072] Note that in order to trace the program operation of the CPU 110 synchronized with the high-speed drive clock CLK (for example, 100 MHz), it can be said that the hardware processing of the tracer 200 operating in synchronization with the trace clock trace_clk (= drive clock CLK) is essential.

[0073] <Trace operation (tracer side)> FIG. 5 is a flowchart showing an example of the trace operation in the tracer 200. When the trace operation starts, in step S21, first, the output value pc_count of the simulated program counter 204 is initialized.

[0074] For example, when starting a trace from the beginning of a program, usually, since the output value pc_reg of the program counter 116 starts from 0, the output value pc_count of the simulation program counter 204 may be initialized to 0. On the other hand, when starting a trace from the middle of a program, since it is sufficient to temporarily break the program operation at the address where the trace is to be started and record trace data after resuming the program operation, the output value pc_count of the simulation program counter 204 may be initialized to the address at the time of the break.

[0075] Next, in step S22, it is determined whether the trace data trace_data input from the LSI 100 is the second output value "1d (01b)". Here, if a no determination is made, the flow proceeds to step S23, and if a yes determination is made, the flow proceeds to step S25.

[0076] If a no determination is made in step S22, in step S23, it is determined whether the trace data trace_data input from the LSI 100 is the third output value "2d (10b)". Here, if a no determination is made, the flow proceeds to step S24, and if a yes determination is made, the flow proceeds to step S26.

[0077] If a no determination is made in step S23, it is considered that the trace data trace_data input from the LSI 100 is the first output value "0d (00b)". Therefore, in step S24, after the simulation program counter 204 is made invariant, the flow is returned to step S22.

[0078] On the other hand, if a yes determination is made in step S22, in step S25, after the simulation program counter 204 is incremented, the flow is returned to step S22.

[0079] Also, when a YES determination is made in step S23, it is necessary to load the branch destination address or the interrupt destination address into the simulation program counter 204. Therefore, in steps S26 and S27, the split input of the branch destination address or the interrupt destination address is performed.

[0080] Specifically, first in step S26, a part (2 bits) of the branch destination address or the interrupt destination address that is split-input as the trace data trace_data is stored in the corresponding bit of the simulation program counter 204.

[0081] Next, in step S27, it is determined whether all the bit values of the branch destination address or the interrupt destination address have been stored in the simulation program counter 204, that is, whether the split input of the branch destination address or the interrupt destination address is completed.

[0082] If a NO determination is made in step S27, the flow returns to step S26 and the split input of the branch destination address or the interrupt destination address is continued. On the other hand, if a YES determination is made, the flow proceeds to step S28.

[0083] In step S28, the output value pc_count of the simulation program counter 204 is determined as the simulation PC fixed value dump_pc. Then, the flow returns to step S22 and the above series of operations are repeated.

[0084] <Trace operation (entire system)> FIG. 6 is a timing chart showing a specific example of the trace operation in the entire trace system X. In order from the top, the PC load instruction pc_load, the PC increment instruction pc_inc, the output value pc_reg of the program counter 116, the trace clock trace_clk, the trace data trace_data, the count value trace_count of the counter 122, the operating state state of the state machine 111, the output value pc_count of the simulation program counter 204, the definite value fetch instruction signal fetch_inst, and the simulation PC definite value dump_pc are depicted.

[0085] Note that in FIG. 6, it is assumed that the CPU 110 has a three-stage pipeline structure. That is, in the CPU 110, the signal processing for one instruction code is decomposed into three unit signal processes (fetch (F), decode (D), execute (E)), and each is independently processed in parallel. However, the number of stages of the pipeline structure may be two stages, or four or more stages. Of course, the CPU 110 may not have a pipeline structure.

[0086] Also, in FIG. 6, it is assumed that the CPU 110 is an 8-bit CPU and the instruction code is for 16 bits. However, the number of bits of the CPU 110 and the number of bits of the instruction code are not limited to this.

[0087] FIG. 7 is a diagram showing an example (partial excerpt) of the program code used for the trace operation in FIG. 6. In the program code illustrated here, various instructions (JMPC, HLT, STR, LDR, SDR, CALL, RET, and OR, etc.) are described at each of the addresses 0x0000 to 0x0058.

[0088] Hereinafter, with appropriate reference to FIGS. 6 and 7, the trace operation in the entire trace system X will be roughly classified into four periods T1 to T4 and each will be described in detail.

[0089] First, focus on the period T1 (= time t1 to t6). In the period T1, pc_load = "L" and pc_inc = "H". Therefore, the output value pc_reg of the program counter 116 is incremented by "+2" synchronously with the trace clock trace_clk (= driving clock CLK) (0C → 0E → 10 → 12 → 14 → 16).

[0090] Note that the increment value of the program counter 116 is "+2" because the CPU 110 is an 8-bit CPU and the instruction code is for 16 bits, so the read address of the program memory 117 is incremented by 2 bytes at a time. Thus, the increment value of the program counter 116 is determined according to the bit number of the CPU 110 and the bit number of the instruction code.

[0091] Also, as described above, the CPU 110 has a three-stage pipeline structure. Therefore, for example, the LDR instruction at the address 0x000C fetched at time t1 is decoded at time t2 and executed at time t3. The same applies to other instructions basically. However, due to the execution of branch instructions or interrupt instructions, instructions that were being fetched or decoded simultaneously in parallel may be discarded without being executed. Of course, this is not the case for CPUs without a pipeline structure or CPUs with a deep pipeline stage count.

[0092] Also, in the period T1, the trace data trace_data becomes the second output value "1" (= PC increment). At this time, the counter 122 is in a non-operating state (trace_count = 0), and the operating state state of the state machine 111 becomes the FETCH state.

[0093] Also, in the period T1, the output value pc_count of the simulated program counter 204 is incremented by "+2" with a 1-clock delay from the output value pc_reg of the program counter 116 (0A → 0C → 0E → 10 → 12 → 14).

[0094] Also, in period T1, fetch_inst = "H". Therefore, the simulated PC determined value dump_pc is incremented by " + 2" with a 1 - clock delay from the output value pc_count of the simulated program counter 204 (08 → 0A → 0C → 0E → 10 → 12).

[0095] Next, focus on period T2 (= time t6~t8). At time t6, when the CALL instruction at address 0x0012 (= a branch instruction for calling a subroutine) is executed, pc_inc = "L", and at the subsequent time t7, pc_load = "H". Further, at the subsequent time t8, the branch destination address 0x004C is fetched as the output value pc_reg of the program counter 116. At this time, the trace data trace_data switches from the previous second output value "1" (= PC increment) to the first output value "0" (= PC unchanged), and then subsequently switches to the third output value "2" (= PC change (branch)). Also, the operating state state of the state machine 111 switches from the FETCH state to the WAIT_KEEP state.

[0096] Also, in period T2, the output value pc_count of the simulated program counter 204 becomes an unchanged value (retaining the previous "14"). Further, since fetch_inst = "L", the simulated PC determined value dump_pc also becomes an unchanged value (retaining the previous "12").

[0097] Next, focus on period T3 (= time t8~t16). When the trace data trace_data becomes the third output value "2" (= PC change (branch)), the split output of the branch destination address 0x004C (= 0000 0000 0100 1100) starts from the next cycle.

[0098] More specifically, at time t8, the pulse counting operation of counter 122 (= incrementing the count value trace_count) is started, and while this pulse counting operation continues, in synchronization with the trace clock trace_clk, the branch destination address 0x004C is split and output as 2-bit trace data trace_data (refer to the hatched area in the figure).

[0099] For example, when the output value pc_reg of program counter 116 (= branch destination address or interrupt destination address) is 16 bits and the trace data trace_data is 2 bits, in order to output all the bit values of the branch destination address or interrupt destination address, at least 8 pulses of the trace clock trace_clk are required. If the trace data trace_data is extended to 4 bits, it only takes 4 pulses, if extended to 8 bits, it only takes 2 pulses, and if extended to 16 bits (i.e., n = m), it only takes 1 pulse.

[0100] Also, at this time, in order to completely output all the bit values of the branch destination address 0x004C, the operating state state of the state machine 111 is set to the TRACE state (temporary stop state).

[0101] On the other hand, the branch destination address 0x004C, which is split and input 2 bits at a time as the trace data trace_data, is sequentially stored in the simulation program counter 204.

[0102] Figure 8 is a diagram showing the split input operation of the branch destination address, depicting the transitions of the count value trace_counter of counter 122, the output value pc_counter of the simulation program counter 204, and the trace data trace_data respectively. Hereinafter, the split input operation of the branch destination address 0x004C (= 0000 0000 0100 1100) will be described with appropriate reference to the previously shown Figure 6.

[0103] When trace_counter = "0", pc_counter = "0000 0000 0001 0100 (0x0014)" (see time t7 in Figure 6).

[0104] When trace_counter = "1", among the 16-bit branch destination address 0x004C, the first bit value and the second bit value ([1:0] = "0d (00b)") are input as 2-bit trace data trace_data to the first bit value and the second bit value of the simulation program counter 204 respectively. As a result, pc_counter = "0000 0000 0001 0100b (0x0014)" (see time t8 in Figure 6).

[0105] When trace_counter = "2", among the 16-bit branch destination address 0x004C, the third bit value and the fourth bit value ([3:2] = "3d (11b)") are input as 2-bit trace data trace_data to the third bit value and the fourth bit value of the simulation program counter 204 respectively. As a result, pc_counter = "0000 0000 0001 1100b (0x001C)" (see time t9 in Figure 6).

[0106] When trace_counter = "3", among the 16-bit branch destination address 0x004C, the fifth bit value and the sixth bit value ([5:4] = "0d (00b)") are input as 2-bit trace data trace_data to the fifth bit value and the sixth bit value of the simulation program counter 204 respectively. As a result, pc_counter = "0000 0000 0000 1100b (0x000C)" (see time t10 in Figure 6).

[0107] When trace_counter = "4", among the 16-bit branch destination address 0x004C, the 7th bit value and the 8th bit value ([7:6] = "1d(01b)") are used as 2-bit trace data trace_data and are respectively input to the 7th bit value and the 8th bit value of the simulation program counter 204. As a result, pc_counter = "0000 0000 0100 1100b (0x004C)" (see time t11 in Figure 6).

[0108] When trace_counter = "5", among the 16-bit branch destination address 0x004C, the 9th bit value and the 10th bit value ([9:8] = "0d(00b)") are used as 2-bit trace data trace_data and are respectively input to the 9th bit value and the 10th bit value of the simulation program counter 204. As a result, pc_counter = "0000 0000 0100 1100b (0x004C)" (see time t12 in Figure 6).

[0109] When trace_counter = "6", among the 16-bit branch destination address 0x004C, the 11th bit value and the 12th bit value ([11:10] = "0d(00b)") are used as 2-bit trace data trace_data and are respectively input to the 11th bit value and the 12th bit value of the simulation program counter 204. As a result, pc_counter = "0000 0000 0100 1100b (0x004C)" (see time t13 in Figure 6).

[0110] When trace_counter = "7", among the 16-bit branch destination address 0x004C, the 13th bit value and the 14th bit value ([13:12] = "0d(00b)") are used as 2-bit trace data trace_data and are respectively input to the 13th bit value and the 14th bit value of the simulation program counter 204. As a result, pc_counter = "0000 0000 0100 1100b (0x004C)" (see time t14 in Figure 6).

[0111] When trace_counter = "8", among the 16-bit branch destination address 0x004C, the 15th bit value and the 16th bit value ([15:14] = "0d(00b)") are input into the 15th bit value and the 16th bit value of the simulation program counter 204 respectively as 2-bit trace data trace_data. As a result, pc_counter = "0000 0000 0100 1100b (0x004C)" (see time t15 in Figure 6).

[0112] In this way, the 16-bit branch destination address 0x004C is divided and input into the simulation program counter 204 in 8 parts of 2 bits each.

[0113] Returning to Figure 6, focusing on period T4 (= time t16~t19), the detailed description of the trace operation will be continued.

[0114] At time t16, when the divided output of the branch destination address 0x004C is completed, the count value trace_count of the counter 122 returns to 0, and the state machine 111 resumes from the TRACE state (temporary stop state) through the PRE_FETCH state to the FETCH state.

[0115] Note that at time t16, in response to the decoding of the LDR instruction of the branch destination address 0x004C, pc_inc = "H". Therefore, the output value pc_reg of the program counter 116 is incremented by " + 2" synchronously with the trace clock trace_clk (= driving clock CLK) from the next cycle (4C → 4E → 50 → 52 →...).

[0116] Also, in period T4, the trace data trace_data becomes the second output value "1" (= PC increment). Therefore, the output value pc_count of the simulation program counter 204 is incremented by " + 2" from the branch destination address 0x004C written in period T3 (4C → 4E → 50 →...).

[0117] Also, in period T4, when "trace_data = '1'" (= PC increment) continues for two consecutive cycles, "fetch_inst = 'H'", and the output value "pc_count" (= 0x004C) of the simulation program counter 204 is latched as the simulation PC determined value "dump_pc". Thereafter, the simulation PC determined value "dump_pc" is incremented by "+2" with a one-clock delay from the output value "pc_count" of the simulation program counter 204 (4C → 4E →...).

[0118] The reason for determining the output value "pc_count" of the simulation program counter 204 as the simulation PC determined value "dump_pc" when "trace_data = '1'" continues for two consecutive cycles is that CPU 110 has a three-stage pipeline structure, and the read instruction code is executed only when the PC increment occurs twice consecutively.

[0119] Figure 9 is a diagram showing the execution result of the program code (Figure 7). As shown in this figure, CPU 110 executes the instruction codes at each address in the order of... → 0x0008 → 0x000A → 0x000C → 0x000E → 0x0010 → 0x0012 → 0x004C → 0x004E → 0x0050 →....

[0120] On the other hand, as shown in the previous Figure 6, the simulation PC determined value "dump_pc" changes in the order of... → 0x0008 → 0x000A → 0x000C → 0x000E → 0x0010 → 0x0012 → 0x004C → 0x004E → 0x0050 →.... That is, the simulation PC determined value "dump_pc" obtained by the tracer 200 exactly matches the execution result of the above-described program code.

[0121] Therefore, according to the tracer system X described so far, it is possible to completely understand the program operation of CPU 110.

[0122] <Other Variants> In addition, the various technical features disclosed in this specification can be variously modified without departing from the gist of the technical creation in addition to the above embodiments. That is, the above embodiments should be considered as illustrative in all respects and not restrictive, and the technical scope of the present invention is not limited to the above embodiments, but should be understood to include all modifications belonging to the meaning and scope equivalent to the claims.

Industrial Applicability

[0123] The invention disclosed in this specification can be used, for example, for debugging microprocessors implemented in various information processing devices (such as smartphones, game devices, car navigation systems, etc.).

Explanation of Signs

[0124] 100 LSI (semiconductor device) 110 CPU (microprocessor) 111 State machine 112 Decode / execution unit 113 Increment unit 114 Branch destination address storage unit 115 Selector 116 Program counter 117 Program memory 120 Trace circuit 121 Status generation unit 122 Counter 123 Selector 200 Tracer 201 Decoder 202 Increment unit 203 Selector 204 Simulated program counter 205 Latch 206 Trace memory 300 Host 310 Trace program X Trace system< / lsi>

Claims

1. A trace circuit integrated in a semiconductor device together with a microprocessor having an m-bit (2≦m) program counter, for outputting trace data to an external device in synchronization with a trace clock, comprising: an output value of the trace data to be externally output is changed in response to an operation of the program counter; When the program counter is unchanged, the trace data is set as a first output value in synchronization with the trace clock; when the program counter is incremented, the trace data is set as a second output value in synchronization with the trace clock; when loading the trace data into the program counter, the trace data is set as a third output value in synchronization with the trace clock, a state machine of the microprocessor is temporarily stopped, and the branch destination address or the interrupt destination address loaded into the program counter is divided and output as the trace data; A trace circuit configured as follows:

2. 2. The trace circuit of claim 1, wherein the trace data is configured to be n bits, where 2≦n≦m.

3. a status generating unit that generates a status signal that becomes the first output value when the program counter is unchanged, that becomes the second output value when the program counter is incremented, and that becomes the third output value when loaded into the program counter; a counter that starts an operation when the status signal becomes the third output value and stops an operation when a divided output period of the branch destination address or the interrupt destination address expires; a selector that selects the status signal as the trace data while the counter is stopped, and selects a part of the branch destination address or the interrupt destination address as the trace data while the counter is operating; 3. The tracing circuit of claim 1 or 2, configured to comprise:

4. A trace circuit according to any one of claims 1 to 3; the microprocessor; A semiconductor device comprising:

5. 5. The semiconductor device according to claim 4, wherein said microprocessor is configured to read an instruction code from a program memory using an output value of said program counter as a read address, and to decode and execute the instruction code.

6. 6. A tracer configured to receive the trace clock and the trace data from the semiconductor device according to claim 4, monitor the trace data, and output a trace result.

7. A tracer configured to receive the trace clock and the trace data from a semiconductor device configured to include the trace circuit according to claim 3 and the microprocessor, monitor the trace data, and output a trace result, A simulated program counter; a decoder which leaves the simulated program counter unchanged when the trace data is the first output value, increments the simulated program counter when the trace data is the second output value, and sequentially stores the branch destination address or the interrupt destination address which is subsequently divided and input in the simulated program counter when the trace data is the third output value; a latch that captures an output value of the simulated program counter as a definite value in synchronization with the trace clock, except for a divided input period of the branch destination address or the interrupt destination address; a trace memory for storing the determined values ​​sequentially fetched into the latch as trace results; The tracer is configured to include:

8. A semiconductor device according to claim 4 or 5, A tracer according to claim 6 or 7; a host for displaying, storing, and analyzing the trace results; A tracing system comprising:

Citation Information

Patent Citations

  • Firmware executing address tracer

    JP1991240839A

  • Tracing device for program counter

    JP2000172531A

  • Trace information collection device, trace information processor and trace information collection method

    JP2011100388A

  • Address trace method

    JP2727947B2

  • Debugging system and information storage medium

    JP3775462B2