This Design Advisory covers the readback CRC functionality in 7 Series and UltraScale/UltraScale+ devices after a Configuration Fallback has occurred.
Issue:
The readback CRC (POST_CRC) does not operate when a golden/fallback bitstream is loaded by a configuration error+fallback condition from a SPI/BPI(2) flash.
Affected devices(1):
- 7 Series FPGAs
- UltraScale and UltraScale+ FPGAs
Affected system - when ALL of the following are true with an affected device:
- FPGA configuration by SPI or BPI(2) mode from a flash memory
- FPGA, flash memory, and bitstreams set for config MultiBoot (via IPROG) and fallback (BITSTREAM.CONFIG.CONFIGFALLBACK ENABLE)
- POST_CRC enabled (or use of the Soft Error Mitigation IP or the Security Monitor IP) in the fallback bitstream
Notes:
- Zynq 7000 and Zynq UltraScale+ MPSoC devices are NOT affected
- BPI Exception: Systems using BPI mode MultiBoot+fallback and FPGA RS[1:0] pins to select a flash address range for bitstream loading instead of the embedded IPROG command are NOT affected.
Customer impact:
When a fallback occurs due to an issue with an update bitstream and instead loads/runs the golden/fallback bitstream in an affected system, the POST_CRC does not operate in the fallback bitstream.
This can result in undetected soft errors or undetected configuration memory changes. The Soft Error Mitigation (SEM) controller and Security Monitor (SecMon) IP depend on POST_CRC.
Use of these IPs will indicate that the readback CRC issue has occurred.
The SEM controller IP detects the readback CRC issue during its startup and will not deassert its status_initialization signal.
The Security Monitor IP will detect the readback CRC issue during its startup self tests and will not assert its SM_INIT_DONE signal.