CDC / RDC · All levels

CDC Protocol Verification: Worked Example

Worked Example for CDC Protocol Verification.

Worked example

Worked Example for CDC Protocol Verification focuses on assertion pass rate, liveness coverage, CDC protocol bug escape rate. The goal is to convert issue observations into mechanism-backed closure decisions.

A milestone review shows assertion pass rate, liveness coverage, CDC protocol bug escape rate. Teams disagree on severity. The right move is to isolate one representative issue, prove mechanism class, and decide fix or waiver with explicit residual risk.

Crossing under inspection

diagram
CROSSING FLOW — CDC Protocol Verification

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate

Safety + liveness

diagram
SAFETY: no duplicate / no drop
LIVENESS: every req eventually gets ack

Structural clean CDC is necessary, not sufficient.
  1. Capture warning, waveform, and owning module context.

  2. Tag mode/reset/traffic state for the failure.

  3. Validate assumptions against spec and assertions.

  4. Compare outcome with SVA package, formal liveness report, simulation stress matrix.

  5. Choose one reversible action and define regression upfront.

Did the action work?

diagram
BEFORE / AFTER — CDC Protocol Verification

open critical issues
  ^
  |  o baseline
  |     o after fix batch
  |         o after protocol proof
  |             o signoff-ready
  +---------------------------------> closure iteration

Track issue burn-down with evidence quality, not only count.

CDC/RDC deep dive

Protocol correctness is the bridge between structural clean and functional safe.

Concept diagram

diagram
PROTOCOL FLOW

intent -> transport protocol -> synchronization -> destination acceptance

Metric graph

diagram
PROTOCOL ISSUE BURNDOWN

open issues: 20 -> 11 -> 5 -> 0

Reports and artifacts

  • FIFO pointer proofs

  • req/ack liveness

  • pulse miss checks

  • protocol assertions

Mini case study

Async FIFO empty/full logic looked correct until gray decode mismatch appeared during reset overlap.

Debug branches

  • Pointer sync audit

  • formal liveness checks

  • reset interaction review

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

CDC closure requires proving protocol safety and liveness, not only structural synchronizer presence.

Metric: assertion pass rate, liveness coverage, CDC protocol bug escape rate