CDC / RDC · All levels

Multi-bit CDC Hazards: Inputs & Outputs

Inputs & Outputs for Multi-bit CDC Hazards.

Inputs and outputs contract

Inputs & Outputs for Multi-bit CDC Hazards focuses on data coherence violations, reconvergence warning count, escaped protocol bugs. The goal is to convert issue observations into mechanism-backed closure decisions.

Treat CDC/RDC signoff as a contract across architecture, RTL, DV, and signoff governance. Most late surprises are contract mismatches, not tooling gaps.

diagram
INPUTS
  - crossing inventory with intent classification
  - reset tree and release dependency model
  - protocol assumptions and assertion package
  - CDC/RDC tool configuration + waiver policy

OUTPUTS
  - severity-tagged open issue list
  - protocol/reset proof evidence
  - owner-assigned closure plan
  - signoff or escalation memo

Crossing sequence

diagram
CROSSING FLOW — Multi-bit CDC Hazards

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: data coherence violations, reconvergence warning count, escaped protocol bugs

Ownership map

diagram
OWNERSHIP MAP — Multi-bit CDC Hazards

artifact                  owner
----------------------    -------------------------
design intent           RTL owner
verification evidence   CDC owner
signoff decision        IP integration owner

Every open CDC/RDC issue needs one accountable owner before waiver or fix.

CDC/RDC deep dive

Metastability is managed risk, not eliminated risk.

Concept diagram

diagram
METASTABILITY FLOW

async event -> first sample may metastabilize
 -> settle window
 -> downstream sample confidence

Metric graph

diagram
MTBF TREND

target MTBF ---------
current design   ____/

Reports and artifacts

  • MTBF assumptions

  • synchronizer inventory

  • crossing class summary

  • critical waivers

Mini case study

Pulse sync chosen for a level signal caused intermittent stuck state under voltage stress.

Debug branches

  • Validate crossing class first

  • Check pulse width assumptions

  • Audit synchronizer template usage

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

Independent bit synchronization causes skew and data incoherency; buses need protocolized transfer (FIFO, handshake, token, or encoded sequencing).

Metric: data coherence violations, reconvergence warning count, escaped protocol bugs