CDC / RDC · All levels
Two-Flop Synchronizers in Practice: Worked Example
Worked Example for Two-Flop Synchronizers in Practice.
Worked example
Worked Example for Two-Flop Synchronizers in Practice focuses on single-bit CDC clean rate, pulse capture reliability, latency cycles. The goal is to convert issue observations into mechanism-backed closure decisions.
A milestone review shows single-bit CDC clean rate, pulse capture reliability, latency cycles. Teams disagree on severity. The right move is to isolate one representative issue, prove mechanism class, and decide fix or waiver with explicit residual risk.
Crossing under inspection
CROSSING FLOW — Two-Flop Synchronizers in Practice
source clock domain -> launch signal -> crossing structure -> destination sample
| | | |
source FF protocol sync / fifo destination FF
Key metric: single-bit CDC clean rate, pulse capture reliability, latency cyclesTwo-flop chain limits
SRC -----> [FF1] -----> [FF2] -----> DEST logic
async sample filtered sample
Valid for stable level signals.
Not sufficient for narrow pulses or multi-bit buses.Capture warning, waveform, and owning module context.
Tag mode/reset/traffic state for the failure.
Validate assumptions against spec and assertions.
Compare outcome with CDC structural report, RTL synchronizer pattern list, assertion checks.
Choose one reversible action and define regression upfront.
Did the action work?
BEFORE / AFTER — Two-Flop Synchronizers in Practice
open critical issues
^
| o baseline
| o after fix batch
| o after protocol proof
| o signoff-ready
+---------------------------------> closure iteration
Track issue burn-down with evidence quality, not only count.CDC/RDC deep dive
Metastability is managed risk, not eliminated risk.
Concept diagram
METASTABILITY FLOW
async event -> first sample may metastabilize
-> settle window
-> downstream sample confidenceMetric graph
MTBF TREND
target MTBF ---------
current design ____/Reports and artifacts
MTBF assumptions
synchronizer inventory
crossing class summary
critical waivers
Mini case study
Pulse sync chosen for a level signal caused intermittent stuck state under voltage stress.
Debug branches
Validate crossing class first
Check pulse width assumptions
Audit synchronizer template usage
Senior review question
Ask: what evidence proves this risk is closed for silicon, not just tool-clean?
Key takeaways
State crossing class, assumptions, and owner with every issue.
Run structural and dynamic regressions after each fix.
Common pitfalls
Treating all warnings as equivalent risk.
Waiving issues without containment evidence.
Skipping reset and reconvergence stress after CDC fixes.
Principal CDC/RDC review addendum
A two-flop chain lowers metastability propagation risk for level signals, but only when source assumptions, pulse width, and destination sampling are respected.
Metric: single-bit CDC clean rate, pulse capture reliability, latency cycles