CDC / RDC · All levels

Async FIFO CDC: Design Space

Design Space for Async FIFO CDC.

Design space exploration

For Async FIFO CDC, signoff options trade reliability, latency, and schedule.

Option A — conservative

  • Conservative synchronization: helps robustness

  • Risk: latency increase

  • Validate with: stress regressions

Option B — balanced

  • Balanced protocol design: helps throughput + safety

  • Risk: higher design effort

  • Validate with: formal + simulation

Option C — aggressive

  • Aggressive waiver posture: helps schedule relief

  • Risk: escape risk

  • Validate with: periodic waiver audit

Option D — refactor

  • Architectural refactor: helps long-term safety

  • Risk: schedule hit

  • Validate with: system bring-up

diagram
DESIGN SPACE — Async FIFO CDC
robustness <-> latency <-> complexity <-> schedule

Design pitfalls

  • Waive-first behavior

  • No owner for residual risk

Tradeoff curve

diagram
BEFORE / AFTER — Async FIFO CDC

open critical issues
  ^
  |  o baseline
  |     o after fix batch
  |         o after protocol proof
  |             o signoff-ready
  +---------------------------------> closure iteration

Track issue burn-down with evidence quality, not only count.

CDC/RDC deep dive

Protocol correctness is the bridge between structural clean and functional safe.

Concept diagram

diagram
PROTOCOL FLOW

intent -> transport protocol -> synchronization -> destination acceptance

Metric graph

diagram
PROTOCOL ISSUE BURNDOWN

open issues: 20 -> 11 -> 5 -> 0

Reports and artifacts

  • FIFO pointer proofs

  • req/ack liveness

  • pulse miss checks

  • protocol assertions

Mini case study

Async FIFO empty/full logic looked correct until gray decode mismatch appeared during reset overlap.

Debug branches

  • Pointer sync audit

  • formal liveness checks

  • reset interaction review

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

Async FIFOs decouple domains with gray-coded pointers and synchronized status logic; correctness depends on pointer math, full/empty rules, and reset behavior.

Metric: overflow/underflow risk, pointer synchronization integrity, latency throughput