As embedded systems grow increasingly complex, understanding exactly what software is doing at runtime is no longer optional it is essential. This is especially true for safety-critical systems, where developers need to know not only if software executes correctly, but exactly how it behaves over time, which architectural paths it takes, and how many cycles individual execution paths consume. The TRACE_FS demonstrator, developed within the European research project TRISTAN, tackles this challenge directly. It explores how hardware-assisted tracing can provide unprecedented execution visibility for RISC-V architectures.
For SYSGO and our project partners, this demonstrator is highly relevant because it unites the core pillars of dependable embedded systems development: Open RISC-V architectures, hardware-assisted tracing, real-time networking, and rigorous software analysis.
Proving the Pipeline: The TRACE_FS Demonstrator
The TRACE_FS demonstrator was built as part of TRISTAN (Together for RISc-V Technology and ApplicatioNs), an initiative focused on maturing the European RISC-V ecosystem. The project brings together hardware, software, and tooling to create industrial-quality building blocks.
The physical demonstrator acts as a proof of concept for an end-to-end trace transport pipeline. Implemented by our project partners on a Xilinx Kria KR260 FPGA board, the setup centers around the 32-bit EMSA5 RISC-V processor core, operating alongside the project's dedicated C-Trace unit.
This C-Trace unit monitors the software running on the EMSA5 core through a standardized RISC-V Trace Ingress Port (TIP). Instead of forcing the application software to perform heavy, time-altering instrumentation, execution is observed entirely at the hardware level. The unit converts the raw data into a timestamped, NEXUS-compatible trace stream.
This stream is then routed through a secured TSN trace link, transporting the data over Ethernet to an external workstation. This represents a significant architectural leap: Processor trace is no longer an isolated, short-distance debugging interface. It is now a fully networked component of the embedded infrastructure.
SYSGO's Contribution: Scaling Traceability to Application Cores
Within TRISTAN, hardware tracing is designed as a core-agnostic architecture. While the physical TRACE_FS demonstrator proves that this end-to-end transport pipeline works flawlessly on a 32-bit core, SYSGO focused on the next critical hurdle: Scaling this observability to complex, application-class processors.
SYSGO achieved this by developing the Trace Ingress Port (TIP) for the open-source CVA6 RISC-V core.
To support heavy workloads and complex operating systems like Linux, or RTOS and hypervisor environments like PikeOS and ELinOS the hardware must export retired instructions, exception states, and execution contexts directly from the pipeline without introducing stalls.
To validate this complex IP prior to physical silicon deployment, SYSGO verified the CVA6 TIP integration through rigorous post-synthesis simulation. This gate-level validation confirmed that the TIP successfully extracts execution data from the pipeline and generates conformant signals ready for downstream NEXUS trace units.
By achieving this simulation milestone and contributing the code upstream, SYSGO has proven that the tracing architecture demonstrated in TRACE_FS effortlessly scales to the high-performance cores required for next-generation embedded systems.
The Complete Trace Workflow
The demonstrator illustrates a seamless workflow, from hardware configuration to final timing analysis:
- Platform configuration: The FPGA is loaded with the bitstream containing the EMSA5 core and the C-Trace unit, followed by the demonstrator firmware
- Network setup: The TSN trace link is configured with the target workstation's MAC and IP addresses
- Trace initialization: The C-Trace unit is configured for the desired trace capture mode
- Data capture: A Python logging script is started on the workstation. As the RISC-V core is released from reset, the C-Trace unit generates NEXUS messages. These are packaged as UDP frames and streamed over the TSN link.
- Extraction and conversion: The NEXUS messages are extracted, converted into the Open CTXP format, and loaded into the analysis environment
From Visualization to Worst-Case Execution Time
Capturing the data is only half the battle. The demonstrator utilizes TimeWeaver for RISC-V to analyze the results.
While TimeWeaver allows developers to visualize call stacks and executed routines, its most critical capability for safety-critical software is worst-case execution time (WCET) estimation. The tool divides the trace into segments, mapping measured execution times onto the software’s control-flow graph. It then applies integer linear programming (ILP) to identify the longest possible execution path, providing a reliable upper bound for the system's WCET.
Why Hardware-assisted Tracing matters
Traditional debugging techniques often fall short in complex embedded environments. Software instrumentation inherently alters timing behavior, and standard debug interfaces offer limited visibility into long-running tasks. Simply knowing a system reached a certain state does not explain how it got there.
Hardware-assisted tracing bypasses these limitations. Because execution is observed passively by dedicated hardware, it is particularly valuable for understanding:
- Execution flow: Identifying exactly which routines and paths were taken
- Timing behavior: Measuring the exact cycle count of individual segments
- Scheduling behavior: Verifying when periodic tasks were actually dispatched
- WCET analysis: Providing empirical data to establish safe upper execution bounds
- Measurement coverage: Proving how comprehensively the software has been tested
Looking ahead: Maturing the RISC-V Ecosystem
TRACE_FS is more than an impressive technology demonstration; it is proof that the open European RISC-V ecosystem encompasses much more than just processor cores. It includes the entire surrounding infrastructure required to develop, integrate, and validate safe embedded systems.
The physical EMSA5 demonstrator validates the hardware capture and transport pipeline, while SYSGO’s CVA6 integration guarantees that this infrastructure is ready for complex systems. For developers of safety-critical embedded systems, this combination creates a much-needed bridge between what software is designed to do and what the processor actually does in the field.
Technical References
- TRISTAN: European research project expanding and industrializing the RISC-V ecosystem
- C-Trace: RISC-V trace IP used to observe processor execution and generate NEXUS-compatible streams
- EMSA5: 32-bit RISC-V processor core (Fraunhofer IPMS) used in the physical TRACE_FS demonstrator
- CVA6: 64-bit RISC-V processor core, featuring Trace Ingress Port (TIP) integration verified and contributed by SYSGO
- TSN-Trace-Link: Network-based trace transport infrastructure developed within TRISTAN
- TimeWeaver: Hybrid timing-analysis tool used to estimate worst-case execution time (www.absint.com/timeweaver)