SoC Integration · All levels

HW/SW Boot Contract

Memory Maps & I/O: Boot contracts formalize reset defaults, strap behavior, secure-boot expectations, and firmware ordering dependencies.

What this topic teaches

HW/SW Boot Contract is about making top-level contracts measurable and enforceable. Boot contracts formalize reset defaults, strap behavior, secure-boot expectations, and firmware ordering dependencies. The hard part is proving owner accountability and reproducibility under schedule pressure.

The senior-engineer question

When first-boot success rate, boot regression frequency moves, can you identify the first broken boundary, responsible owner, and smallest reversible fix with complete regression scope?

diagram
SOC INTEGRATION STACK — HW/SW Boot Contract

program contract (scope, milestones, ownership)
        |
        v
architecture contract (budgets, interfaces, assumptions)
        |
        v
implementation contract (rtl, timing, physical, package)
        |
        v
validation contract (bring-up, workload, signoff evidence)
        |
        v
release contract (manifest, waivers, tapeout decision)

Debug rule: always identify which contract layer broke first.

Picture the integration flow

Start by drawing boundaries and ownership before diving into logs. The diagrams below are the whiteboard models to reproduce in reviews.

Boot contract timeline

diagram
BOOT CONTRACT

ROM init -> security checks -> PLL enable -> peripheral init -> OS handoff

Each stage requires hardware defaults and software assumptions to match.

Integration sequence

diagram
SOC INTEGRATION FLOW — HW/SW Boot Contract

requirements + budgets
        |
        v
IP handoff + collateral check
        |
        v
integration build + bring-up smoke
        |
        v
cross-domain signoff evidence
        |
        v
tapeout readiness decision

Metric in focus: first-boot success rate, boot regression frequency

Layer ownership

diagram
SOC INTEGRATION LAYERS — HW/SW Boot Contract

layer               owns                          failure mode
-----------------   ---------------------------   ------------------------
architecture        partition + contracts         impossible budgets
ip handoff          models + collateral           integration mismatch
fabric/clock/reset  global behavior               domain deadlock
physical/package    route + SI/PI + IO            late closure churn
signoff process     manifests + waivers           non-reproducible claims
program governance  owners + escalations          schedule collapse

Evidence to collect

  • Primary metric: first-boot success rate, boot regression frequency.

  • Primary artifact: boot contract doc, ROM/bootloader checklist, power-on trace.

  • Owners to include: firmware lead, security lead, integration lead.

  • Manifest baseline and revision for every claim.

  • One focused repro and one full-system regression result.

Ownership map

diagram
OWNERSHIP MAP — HW/SW Boot Contract

artifact             owner
-----------------    -----------------
primary owner     firmware lead
co-owner          security lead
review owner      integration lead

No top-level issue should remain ownerless beyond one review cycle.

Subpages in this topic

Each topic includes 15 subpages: mechanism, inputs/outputs, reports, debug, worked example, pitfalls, interview, checklist, theory, design space, expanded case study, walkthrough, comparison matrix, software view, and silicon PPA impact.

Key takeaways

  • Tie every integration claim to a baseline manifest and owner.

  • Fix the first broken boundary before broad optimizations.

  • Regression scope is part of the fix, not a follow-up task.

Common pitfalls

  • Comparing results across changing baselines.

  • Unowned risks hidden behind green aggregate metrics.

  • Waiving high-impact issues without expiry and revalidation.

SoC deep dive

Address, interrupt, and IO contracts are where hardware/software alignment is won or lost.

Concept diagram

diagram
HW/SW CONTRACT
address map + interrupt model + io defaults -> firmware behavior

Metric graph

diagram
BOOT REGRESSION SOURCES
map churn █████
reset defaults ████
driver mismatch ███

Reports and artifacts

  • address decode audit

  • interrupt latency report

  • IO bring-up checklist

  • boot contract review

Mini case study

A map alias issue caused sporadic peripheral misconfiguration despite clean block-level tests.

Debug branches

  • Freeze address map baseline

  • Audit reset defaults

  • Validate firmware assumptions

Senior review question

Ask: what baseline, owner, and artifact prove this topic is truly closed?

Key takeaways

  • State baseline manifest and owner with every closure metric.

  • Run cross-domain regression after every top-level fix.

Common pitfalls

  • Comparing results across different manifests.

  • Unowned issues slipping through review cycles.

  • Waiving risks without expiry and validation plan.