CDC / RDC · All levels

CDC Protocol Verification: Inputs & Outputs

Inputs & Outputs for CDC Protocol Verification.

Inputs and outputs contract

Inputs & Outputs for CDC Protocol Verification focuses on assertion pass rate, liveness coverage, CDC protocol bug escape rate. The goal is to convert issue observations into mechanism-backed closure decisions.

Treat CDC/RDC signoff as a contract across architecture, RTL, DV, and signoff governance. Most late surprises are contract mismatches, not tooling gaps.

diagram
INPUTS
  - crossing inventory with intent classification
  - reset tree and release dependency model
  - protocol assumptions and assertion package
  - CDC/RDC tool configuration + waiver policy

OUTPUTS
  - severity-tagged open issue list
  - protocol/reset proof evidence
  - owner-assigned closure plan
  - signoff or escalation memo

Crossing sequence

diagram
CROSSING FLOW — CDC Protocol Verification

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate

Ownership map

diagram
OWNERSHIP MAP — CDC Protocol Verification

artifact                  owner
----------------------    -------------------------
design intent           verification lead
verification evidence   formal owner
signoff decision        CDC lead

Every open CDC/RDC issue needs one accountable owner before waiver or fix.

CDC/RDC deep dive

Protocol correctness is the bridge between structural clean and functional safe.

Concept diagram

diagram
PROTOCOL FLOW

intent -> transport protocol -> synchronization -> destination acceptance

Metric graph

diagram
PROTOCOL ISSUE BURNDOWN

open issues: 20 -> 11 -> 5 -> 0

Reports and artifacts

  • FIFO pointer proofs

  • req/ack liveness

  • pulse miss checks

  • protocol assertions

Mini case study

Async FIFO empty/full logic looked correct until gray decode mismatch appeared during reset overlap.

Debug branches

  • Pointer sync audit

  • formal liveness checks

  • reset interaction review

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

CDC closure requires proving protocol safety and liveness, not only structural synchronizer presence.

Metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate