CDC / RDC · All levels

Reset Deassertion CDC

Reset Domain Crossing: Asynchronous assertion is usually safe, but reset deassertion must be synchronized per destination domain to prevent uncertain startup state capture.

What this topic teaches

Reset Deassertion CDC focuses on closing CDC/RDC risk with mechanism-level reasoning. Asynchronous assertion is usually safe, but reset deassertion must be synchronized per destination domain to prevent uncertain startup state capture. Senior signoff depends on proving behavior with targeted evidence, not just clearing tool warnings.

The senior-engineer question

When reset release violations, metastability-on-release risk, boot instability regresses, can you classify the hazard, identify accountable owners, and choose the smallest fix or waiver backed by evidence?

diagram
CDC/RDC SIGNOFF FLOW — Reset Deassertion CDC

crossing inventory + reset map
          |
          v
crossing classification (level/pulse/bus/reset)
          |
          v
structure + protocol + reset checks
          |
          v
critical issues + waiver review
          |
          v
fix / validate / regress / signoff

Picture the crossing behavior

Draw the behavior before touching tools. These visuals are the expected whiteboard baseline for reviews and interviews.

Async assert, sync release

diagram
reset_n (global) ----> assert immediately
                  |
                  +--> per-domain release synchronizer

Unsynchronized deassertion can metastabilize startup flops.

Crossing sequence

diagram
CROSSING FLOW — Reset Deassertion CDC

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: reset release violations, metastability-on-release risk, boot instability

Ownership layers

diagram
CDC/RDC OWNERSHIP LAYERS — Reset Deassertion CDC

layer                 owns                            common failure
------------------    -----------------------------   -----------------------------
design intent         crossing architecture           wrong topology selected
protocol semantics    req/ack, fifo, ordering        liveness/deadlock bugs
reset behavior        assert/deassert sequencing      boot instability
analysis setup        tool rules + waivers            false confidence
signoff governance    risk acceptance + dashboard     stale critical waivers

Evidence to collect

  • Primary metric: reset release violations, metastability-on-release risk, boot instability.

  • Primary artifact: reset tree map, release synchronizer audit, RDC report.

  • Owners to involve: reset architect, CDC owner, RTL owner.

  • At least one reproducer tied to mode/reset/traffic context.

  • Decision record: fix, waive, or escalate with rationale.

Ownership map

diagram
OWNERSHIP MAP — Reset Deassertion CDC

artifact                  owner
----------------------    -------------------------
design intent           reset architect
verification evidence   CDC owner
signoff decision        RTL owner

Every open CDC/RDC issue needs one accountable owner before waiver or fix.

Subpages in this topic

Each topic includes mechanism, I/O contract, metrics, debug, worked example, pitfalls, interview drills, checklist, theory, design tradeoffs, expanded case study, walkthrough, comparison matrix, software view, and silicon impact.

Key takeaways

  • Classify crossing/reset hazards before proposing fixes.

  • Pair structural results with protocol/reset behavioral proof.

  • Treat waivers as bounded risk contracts, not cleanup shortcuts.

Common pitfalls

  • Mass-waiving warnings near tapeout.

  • Assuming local IP cleanliness guarantees SoC behavior.

  • Skipping reconvergence and reset stress after CDC fixes.

CDC/RDC deep dive

Reset release ordering is a first-order reliability contract.

Concept diagram

diagram
RESET RELEASE FLOW

assert global -> clocks stable -> sync release per domain -> first transaction

Metric graph

diagram
BOOT STABILITY

passes per 1k boots: 920 -> 980 -> 999

Reports and artifacts

  • reset dependency matrix

  • RDC warning classes

  • boot stress logs

  • waiver aging

Mini case study

Domain B released before producer A was valid, causing rare startup deadlock.

Debug branches

  • Correlate reset and clock timelines

  • verify async assert/sync release

  • exercise skewed release tests

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.