CDC / RDC · All levels
Reset Deassertion CDC: Design Space
Design Space for Reset Deassertion CDC.
Design space exploration
For Reset Deassertion CDC, signoff options trade reliability, latency, and schedule.
Option A — conservative
Conservative synchronization: helps robustness
Risk: latency increase
Validate with: stress regressions
Option B — balanced
Balanced protocol design: helps throughput + safety
Risk: higher design effort
Validate with: formal + simulation
Option C — aggressive
Aggressive waiver posture: helps schedule relief
Risk: escape risk
Validate with: periodic waiver audit
Option D — refactor
Architectural refactor: helps long-term safety
Risk: schedule hit
Validate with: system bring-up
DESIGN SPACE — Reset Deassertion CDC
robustness <-> latency <-> complexity <-> scheduleDesign pitfalls
Waive-first behavior
No owner for residual risk
Tradeoff curve
BEFORE / AFTER — Reset Deassertion CDC
open critical issues
^
| o baseline
| o after fix batch
| o after protocol proof
| o signoff-ready
+---------------------------------> closure iteration
Track issue burn-down with evidence quality, not only count.CDC/RDC deep dive
Reset release ordering is a first-order reliability contract.
Concept diagram
RESET RELEASE FLOW
assert global -> clocks stable -> sync release per domain -> first transactionMetric graph
BOOT STABILITY
passes per 1k boots: 920 -> 980 -> 999Reports and artifacts
reset dependency matrix
RDC warning classes
boot stress logs
waiver aging
Mini case study
Domain B released before producer A was valid, causing rare startup deadlock.
Debug branches
Correlate reset and clock timelines
verify async assert/sync release
exercise skewed release tests
Senior review question
Ask: what evidence proves this risk is closed for silicon, not just tool-clean?
Key takeaways
State crossing class, assumptions, and owner with every issue.
Run structural and dynamic regressions after each fix.
Common pitfalls
Treating all warnings as equivalent risk.
Waiving issues without containment evidence.
Skipping reset and reconvergence stress after CDC fixes.
Principal CDC/RDC review addendum
Asynchronous assertion is usually safe, but reset deassertion must be synchronized per destination domain to prevent uncertain startup state capture.
Metric: reset release violations, metastability-on-release risk, boot instability