CDC / RDC · All levels

CDC Protocol Verification

CDC Protocols & Handshakes: CDC closure requires proving protocol safety and liveness, not only structural synchronizer presence.

What this topic teaches

CDC Protocol Verification focuses on closing CDC/RDC risk with mechanism-level reasoning. CDC closure requires proving protocol safety and liveness, not only structural synchronizer presence. Senior signoff depends on proving behavior with targeted evidence, not just clearing tool warnings.

The senior-engineer question

When assertion pass rate, liveness coverage, CDC protocol bug escape rate regresses, can you classify the hazard, identify accountable owners, and choose the smallest fix or waiver backed by evidence?

diagram
CDC/RDC SIGNOFF FLOW — CDC Protocol Verification

crossing inventory + reset map
          |
          v
crossing classification (level/pulse/bus/reset)
          |
          v
structure + protocol + reset checks
          |
          v
critical issues + waiver review
          |
          v
fix / validate / regress / signoff

Picture the crossing behavior

Draw the behavior before touching tools. These visuals are the expected whiteboard baseline for reviews and interviews.

Safety + liveness

diagram
SAFETY: no duplicate / no drop
LIVENESS: every req eventually gets ack

Structural clean CDC is necessary, not sufficient.

Crossing sequence

diagram
CROSSING FLOW — CDC Protocol Verification

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate

Ownership layers

diagram
CDC/RDC OWNERSHIP LAYERS — CDC Protocol Verification

layer                 owns                            common failure
------------------    -----------------------------   -----------------------------
design intent         crossing architecture           wrong topology selected
protocol semantics    req/ack, fifo, ordering        liveness/deadlock bugs
reset behavior        assert/deassert sequencing      boot instability
analysis setup        tool rules + waivers            false confidence
signoff governance    risk acceptance + dashboard     stale critical waivers

Evidence to collect

  • Primary metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate.

  • Primary artifact: SVA package, formal liveness report, simulation stress matrix.

  • Owners to involve: verification lead, formal owner, CDC lead.

  • At least one reproducer tied to mode/reset/traffic context.

  • Decision record: fix, waive, or escalate with rationale.

Ownership map

diagram
OWNERSHIP MAP — CDC Protocol Verification

artifact                  owner
----------------------    -------------------------
design intent           verification lead
verification evidence   formal owner
signoff decision        CDC lead

Every open CDC/RDC issue needs one accountable owner before waiver or fix.

Subpages in this topic

Each topic includes mechanism, I/O contract, metrics, debug, worked example, pitfalls, interview drills, checklist, theory, design tradeoffs, expanded case study, walkthrough, comparison matrix, software view, and silicon impact.

Key takeaways

  • Classify crossing/reset hazards before proposing fixes.

  • Pair structural results with protocol/reset behavioral proof.

  • Treat waivers as bounded risk contracts, not cleanup shortcuts.

Common pitfalls

  • Mass-waiving warnings near tapeout.

  • Assuming local IP cleanliness guarantees SoC behavior.

  • Skipping reconvergence and reset stress after CDC fixes.

CDC/RDC deep dive

Protocol correctness is the bridge between structural clean and functional safe.

Concept diagram

diagram
PROTOCOL FLOW

intent -> transport protocol -> synchronization -> destination acceptance

Metric graph

diagram
PROTOCOL ISSUE BURNDOWN

open issues: 20 -> 11 -> 5 -> 0

Reports and artifacts

  • FIFO pointer proofs

  • req/ack liveness

  • pulse miss checks

  • protocol assertions

Mini case study

Async FIFO empty/full logic looked correct until gray decode mismatch appeared during reset overlap.

Debug branches

  • Pointer sync audit

  • formal liveness checks

  • reset interaction review

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.