CDC / RDC · All levels
MTBF & Synchronizer Math: Comparison Matrix
Comparison Matrix for MTBF & Synchronizer Math.
Comparison matrix
Synchronizer choices trade latency, reliability, and proof burden.
+------------------+----------------+----------------+----------------+
| Approach | Strength | Weakness | Best when |
+------------------+----------------+----------------+----------------+
| Conservative | safe | extra latency | high-risk crossings |
| Balanced | practical | more setup | most production paths |
| Aggressive | fast schedule | escape risk | late-stage crunch |
| Refactor | structural gain | long cycle | recurring failures |
+------------------+----------------+----------------+----------------+When to choose each approach
Select approach by silicon risk, not only schedule urgency
Interview traps
Global waiver spray
Unproven protocol assumptions
Evidence comparison
CDC/RDC EVIDENCE MATRIX — MTBF & Synchronizer Math
+-----------------------+----------------------------+----------------------------+---------------------------+
| Evidence | Tells you | Does not prove | Next action |
+-----------------------+----------------------------+----------------------------+---------------------------+
| structural report | crossing topology class | protocol liveness | add assertions/formal |
| reset map | release dependencies | dynamic startup behavior | run reset stress tests |
| formal proof | bounded safety/liveness | real firmware sequence | correlate with simulation |
| simulation stress | observed mode behavior | full state-space closure | target unhit corners |
| waiver log | accepted residual risk | technical correctness | periodic revalidation |
+-----------------------+----------------------------+----------------------------+---------------------------+CDC/RDC deep dive
Metastability is managed risk, not eliminated risk.
Concept diagram
METASTABILITY FLOW
async event -> first sample may metastabilize
-> settle window
-> downstream sample confidenceMetric graph
MTBF TREND
target MTBF ---------
current design ____/Reports and artifacts
MTBF assumptions
synchronizer inventory
crossing class summary
critical waivers
Mini case study
Pulse sync chosen for a level signal caused intermittent stuck state under voltage stress.
Debug branches
Validate crossing class first
Check pulse width assumptions
Audit synchronizer template usage
Senior review question
Ask: what evidence proves this risk is closed for silicon, not just tool-clean?
Key takeaways
State crossing class, assumptions, and owner with every issue.
Run structural and dynamic regressions after each fix.
Common pitfalls
Treating all warnings as equivalent risk.
Waiving issues without containment evidence.
Skipping reset and reconvergence stress after CDC fixes.
Principal CDC/RDC review addendum
Metastability cannot be eliminated, only pushed beyond mission lifetime by adequate settle time, stage count, and frequency-aware design.
Metric: MTBF target vs product FIT budget, synchronizer latency budget