CDC / RDC · All levels

MTBF & Synchronizer Math: Worked Example

Worked Example for MTBF & Synchronizer Math.

Worked example

Worked Example for MTBF & Synchronizer Math focuses on MTBF target vs product FIT budget, synchronizer latency budget. The goal is to convert issue observations into mechanism-backed closure decisions.

A milestone review shows MTBF target vs product FIT budget, synchronizer latency budget. Teams disagree on severity. The right move is to isolate one representative issue, prove mechanism class, and decide fix or waiver with explicit residual risk.

Crossing under inspection

diagram
CROSSING FLOW — MTBF & Synchronizer Math

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: MTBF target vs product FIT budget, synchronizer latency budget

MTBF intuition

diagram
METASTABILITY MODEL

clock edge samples async input near transition
  -> first flop may metastabilize
  -> settle window before second flop sample

More settle time + better tau => higher MTBF.
  1. Capture warning, waveform, and owning module context.

  2. Tag mode/reset/traffic state for the failure.

  3. Validate assumptions against spec and assertions.

  4. Compare outcome with MTBF worksheet, synchronizer cell characterization, frequency assumptions.

  5. Choose one reversible action and define regression upfront.

Did the action work?

diagram
BEFORE / AFTER — MTBF & Synchronizer Math

open critical issues
  ^
  |  o baseline
  |     o after fix batch
  |         o after protocol proof
  |             o signoff-ready
  +---------------------------------> closure iteration

Track issue burn-down with evidence quality, not only count.

CDC/RDC deep dive

Metastability is managed risk, not eliminated risk.

Concept diagram

diagram
METASTABILITY FLOW

async event -> first sample may metastabilize
 -> settle window
 -> downstream sample confidence

Metric graph

diagram
MTBF TREND

target MTBF ---------
current design   ____/

Reports and artifacts

  • MTBF assumptions

  • synchronizer inventory

  • crossing class summary

  • critical waivers

Mini case study

Pulse sync chosen for a level signal caused intermittent stuck state under voltage stress.

Debug branches

  • Validate crossing class first

  • Check pulse width assumptions

  • Audit synchronizer template usage

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

Metastability cannot be eliminated, only pushed beyond mission lifetime by adequate settle time, stage count, and frequency-aware design.

Metric: MTBF target vs product FIT budget, synchronizer latency budget