CDC / RDC · All levels
CDC Protocol Verification: Theory Deep Dive
Theory Deep Dive for CDC Protocol Verification.
Foundational theory
CDC Protocol Verification anchors CDC Protocols & Handshakes. CDC closure requires proving protocol safety and liveness, not only structural synchronizer presence. Senior signoff discussions tie every warning to mechanism class, operational mode, and risk containment evidence.
Core concepts explained
CDC closure requires proving protocol safety and liveness, not only structural synchronizer presence.
Primary metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate
Primary artifact: SVA package, formal liveness report, simulation stress matrix
Owners: verification lead, formal owner, CDC lead
Distinguish structural cleanliness from functional correctness.
Tie every waiver to silicon-risk framing and expiry.
Why this matters at signoff
At tapeout, unresolved CDC/RDC issues become latent reliability bugs. Protocols, not flops alone, guarantee coherent transfer across domains.
Mental model
SAFETY: no duplicate / no drop
LIVENESS: every req eventually gets ack
Structural clean CDC is necessary, not sufficient.Worked intuition
Classify crossing intent and direction.
Name clock/reset relationship assumptions.
Inspect primary metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate.
Collect structural plus dynamic evidence.
Differentiate real hazard from tool noise.
Pick smallest safe fix and define regression matrix.
Document signoff rationale or waiver ownership.
Common misconceptions
CDC clean report means protocol is proven.
All resets are equivalent if assertion works.
Gray code alone guarantees FIFO correctness.
Waivers are harmless schedule shortcuts.
Visual reinforcement
Safety + liveness
SAFETY: no duplicate / no drop
LIVENESS: every req eventually gets ack
Structural clean CDC is necessary, not sufficient.Layer responsibilities
CDC/RDC OWNERSHIP LAYERS — CDC Protocol Verification
layer owns common failure
------------------ ----------------------------- -----------------------------
design intent crossing architecture wrong topology selected
protocol semantics req/ack, fifo, ordering liveness/deadlock bugs
reset behavior assert/deassert sequencing boot instability
analysis setup tool rules + waivers false confidence
signoff governance risk acceptance + dashboard stale critical waiversCDC/RDC deep dive
Protocol correctness is the bridge between structural clean and functional safe.
Concept diagram
PROTOCOL FLOW
intent -> transport protocol -> synchronization -> destination acceptanceMetric graph
PROTOCOL ISSUE BURNDOWN
open issues: 20 -> 11 -> 5 -> 0Reports and artifacts
FIFO pointer proofs
req/ack liveness
pulse miss checks
protocol assertions
Mini case study
Async FIFO empty/full logic looked correct until gray decode mismatch appeared during reset overlap.
Debug branches
Pointer sync audit
formal liveness checks
reset interaction review
Senior review question
Ask: what evidence proves this risk is closed for silicon, not just tool-clean?
Key takeaways
State crossing class, assumptions, and owner with every issue.
Run structural and dynamic regressions after each fix.
Common pitfalls
Treating all warnings as equivalent risk.
Waiving issues without containment evidence.
Skipping reset and reconvergence stress after CDC fixes.
Theory reinforcement
Protocols, not flops alone, guarantee coherent transfer across domains.