CDC / RDC · All levels

MTBF & Synchronizer Math

Metastability & Synchronizers: Metastability cannot be eliminated, only pushed beyond mission lifetime by adequate settle time, stage count, and frequency-aware design.

What this topic teaches

MTBF & Synchronizer Math focuses on closing CDC/RDC risk with mechanism-level reasoning. Metastability cannot be eliminated, only pushed beyond mission lifetime by adequate settle time, stage count, and frequency-aware design. Senior signoff depends on proving behavior with targeted evidence, not just clearing tool warnings.

The senior-engineer question

When MTBF target vs product FIT budget, synchronizer latency budget regresses, can you classify the hazard, identify accountable owners, and choose the smallest fix or waiver backed by evidence?

diagram
CDC/RDC SIGNOFF FLOW — MTBF & Synchronizer Math

crossing inventory + reset map
          |
          v
crossing classification (level/pulse/bus/reset)
          |
          v
structure + protocol + reset checks
          |
          v
critical issues + waiver review
          |
          v
fix / validate / regress / signoff

Picture the crossing behavior

Draw the behavior before touching tools. These visuals are the expected whiteboard baseline for reviews and interviews.

MTBF intuition

diagram
METASTABILITY MODEL

clock edge samples async input near transition
  -> first flop may metastabilize
  -> settle window before second flop sample

More settle time + better tau => higher MTBF.

Crossing sequence

diagram
CROSSING FLOW — MTBF & Synchronizer Math

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: MTBF target vs product FIT budget, synchronizer latency budget

Ownership layers

diagram
CDC/RDC OWNERSHIP LAYERS — MTBF & Synchronizer Math

layer                 owns                            common failure
------------------    -----------------------------   -----------------------------
design intent         crossing architecture           wrong topology selected
protocol semantics    req/ack, fifo, ordering        liveness/deadlock bugs
reset behavior        assert/deassert sequencing      boot instability
analysis setup        tool rules + waivers            false confidence
signoff governance    risk acceptance + dashboard     stale critical waivers

Evidence to collect

  • Primary metric: MTBF target vs product FIT budget, synchronizer latency budget.

  • Primary artifact: MTBF worksheet, synchronizer cell characterization, frequency assumptions.

  • Owners to involve: CDC owner, library owner, architecture owner.

  • At least one reproducer tied to mode/reset/traffic context.

  • Decision record: fix, waive, or escalate with rationale.

Ownership map

diagram
OWNERSHIP MAP — MTBF & Synchronizer Math

artifact                  owner
----------------------    -------------------------
design intent           CDC owner
verification evidence   library owner
signoff decision        architecture owner

Every open CDC/RDC issue needs one accountable owner before waiver or fix.

Subpages in this topic

Each topic includes mechanism, I/O contract, metrics, debug, worked example, pitfalls, interview drills, checklist, theory, design tradeoffs, expanded case study, walkthrough, comparison matrix, software view, and silicon impact.

Key takeaways

  • Classify crossing/reset hazards before proposing fixes.

  • Pair structural results with protocol/reset behavioral proof.

  • Treat waivers as bounded risk contracts, not cleanup shortcuts.

Common pitfalls

  • Mass-waiving warnings near tapeout.

  • Assuming local IP cleanliness guarantees SoC behavior.

  • Skipping reconvergence and reset stress after CDC fixes.

CDC/RDC deep dive

Metastability is managed risk, not eliminated risk.

Concept diagram

diagram
METASTABILITY FLOW

async event -> first sample may metastabilize
 -> settle window
 -> downstream sample confidence

Metric graph

diagram
MTBF TREND

target MTBF ---------
current design   ____/

Reports and artifacts

  • MTBF assumptions

  • synchronizer inventory

  • crossing class summary

  • critical waivers

Mini case study

Pulse sync chosen for a level signal caused intermittent stuck state under voltage stress.

Debug branches

  • Validate crossing class first

  • Check pulse width assumptions

  • Audit synchronizer template usage

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.