CDC / RDC · All levels
Reset Deassertion CDC: Debug Playbook
Debug Playbook for Reset Deassertion CDC.
Debug playbook
Debug Playbook for Reset Deassertion CDC focuses on reset release violations, metastability-on-release risk, boot instability. The goal is to convert issue observations into mechanism-backed closure decisions.
CDC/RDC debug is about finding the earliest violated assumption. Start with intent and context before touching low-level signal traces.
Root-cause tree
ROOT-CAUSE TREE — Reset Deassertion CDC
crossing failure observed
|
reproducible?
/ \
no yes
| |
stress mode classify issue
expansion / | \
synchronizer protocol reset/reconvergence
| | |
MTBF fit liveness release orderingFreeze RTL/config/tool tags for reproducibility.
Reproduce in smallest mode/reset/traffic scenario.
Classify mechanism: synchronizer, protocol, reset, reconvergence, or governance.
Collect one decisive artifact that proves the class.
Pick minimal fix or bounded waiver.
Run targeted and full-regression matrices before closure.
Review memo template
STAFF CDC/RDC REVIEW MEMO — Reset Domain Crossing / Reset Deassertion CDC
1. Symptom
- Failing metric: reset release violations, metastability-on-release risk, boot instability
- Context: <mode, traffic, reset state, corner>
- Risk class: <critical/high/medium/low>
- Database tags: <rtl, config, assertions, tool setup>
2. Mechanism hypothesis
- Primary mechanism: Asynchronous assertion is usually safe, but reset deassertion must be synchronized per destination domain to prevent uncertain startup state capture.
- Competing hypothesis: <false warning / protocol bug / reset order / reconvergence>
- Missing evidence: <assertion, waveform, formal proof, stress replay>
3. Proposed action
- Minimal reversible change: <sync/protocol/reset/waiver decision>
- Expected metric movement: <critical count delta>
- Regression risk: throughput, boot, latency, mode interaction
4. Signoff
- Re-run artifact: reset tree map, release synchronizer audit, RDC report
- Required owners: reset architect, CDC owner, RTL owner
- Final decision: fix, bounded waiver, or escalateCDC/RDC deep dive
Reset release ordering is a first-order reliability contract.
Concept diagram
RESET RELEASE FLOW
assert global -> clocks stable -> sync release per domain -> first transactionMetric graph
BOOT STABILITY
passes per 1k boots: 920 -> 980 -> 999Reports and artifacts
reset dependency matrix
RDC warning classes
boot stress logs
waiver aging
Mini case study
Domain B released before producer A was valid, causing rare startup deadlock.
Debug branches
Correlate reset and clock timelines
verify async assert/sync release
exercise skewed release tests
Senior review question
Ask: what evidence proves this risk is closed for silicon, not just tool-clean?
Key takeaways
State crossing class, assumptions, and owner with every issue.
Run structural and dynamic regressions after each fix.
Common pitfalls
Treating all warnings as equivalent risk.
Waiving issues without containment evidence.
Skipping reset and reconvergence stress after CDC fixes.
Principal CDC/RDC review addendum
Asynchronous assertion is usually safe, but reset deassertion must be synchronized per destination domain to prevent uncertain startup state capture.
Metric: reset release violations, metastability-on-release risk, boot instability