CDC / RDC · All levels

MTBF & Synchronizer Math: Debug Playbook

Debug Playbook for MTBF & Synchronizer Math.

Debug playbook

Debug Playbook for MTBF & Synchronizer Math focuses on MTBF target vs product FIT budget, synchronizer latency budget. The goal is to convert issue observations into mechanism-backed closure decisions.

CDC/RDC debug is about finding the earliest violated assumption. Start with intent and context before touching low-level signal traces.

Root-cause tree

diagram
ROOT-CAUSE TREE — MTBF & Synchronizer Math

crossing failure observed
        |
   reproducible?
     /        \
   no          yes
   |            |
stress mode   classify issue
expansion       /      |      \
            synchronizer protocol reset/reconvergence
                 |         |           |
            MTBF fit    liveness    release ordering
  1. Freeze RTL/config/tool tags for reproducibility.

  2. Reproduce in smallest mode/reset/traffic scenario.

  3. Classify mechanism: synchronizer, protocol, reset, reconvergence, or governance.

  4. Collect one decisive artifact that proves the class.

  5. Pick minimal fix or bounded waiver.

  6. Run targeted and full-regression matrices before closure.

Review memo template

diagram
STAFF CDC/RDC REVIEW MEMO — Metastability & Synchronizers / MTBF & Synchronizer Math

1. Symptom
   - Failing metric: MTBF target vs product FIT budget, synchronizer latency budget
   - Context: <mode, traffic, reset state, corner>
   - Risk class: <critical/high/medium/low>
   - Database tags: <rtl, config, assertions, tool setup>

2. Mechanism hypothesis
   - Primary mechanism: Metastability cannot be eliminated, only pushed beyond mission lifetime by adequate settle time, stage count, and frequency-aware design.
   - Competing hypothesis: <false warning / protocol bug / reset order / reconvergence>
   - Missing evidence: <assertion, waveform, formal proof, stress replay>

3. Proposed action
   - Minimal reversible change: <sync/protocol/reset/waiver decision>
   - Expected metric movement: <critical count delta>
   - Regression risk: throughput, boot, latency, mode interaction

4. Signoff
   - Re-run artifact: MTBF worksheet, synchronizer cell characterization, frequency assumptions
   - Required owners: CDC owner, library owner, architecture owner
   - Final decision: fix, bounded waiver, or escalate

CDC/RDC deep dive

Metastability is managed risk, not eliminated risk.

Concept diagram

diagram
METASTABILITY FLOW

async event -> first sample may metastabilize
 -> settle window
 -> downstream sample confidence

Metric graph

diagram
MTBF TREND

target MTBF ---------
current design   ____/

Reports and artifacts

  • MTBF assumptions

  • synchronizer inventory

  • crossing class summary

  • critical waivers

Mini case study

Pulse sync chosen for a level signal caused intermittent stuck state under voltage stress.

Debug branches

  • Validate crossing class first

  • Check pulse width assumptions

  • Audit synchronizer template usage

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

Metastability cannot be eliminated, only pushed beyond mission lifetime by adequate settle time, stage count, and frequency-aware design.

Metric: MTBF target vs product FIT budget, synchronizer latency budget