CDC / RDC · All levels

Reset Deassertion CDC: Design Space

Design Space for Reset Deassertion CDC.

Design space exploration

For Reset Deassertion CDC, signoff options trade reliability, latency, and schedule.

Option A — conservative

  • Conservative synchronization: helps robustness

  • Risk: latency increase

  • Validate with: stress regressions

Option B — balanced

  • Balanced protocol design: helps throughput + safety

  • Risk: higher design effort

  • Validate with: formal + simulation

Option C — aggressive

  • Aggressive waiver posture: helps schedule relief

  • Risk: escape risk

  • Validate with: periodic waiver audit

Option D — refactor

  • Architectural refactor: helps long-term safety

  • Risk: schedule hit

  • Validate with: system bring-up

diagram
DESIGN SPACE — Reset Deassertion CDC
robustness <-> latency <-> complexity <-> schedule

Design pitfalls

  • Waive-first behavior

  • No owner for residual risk

Tradeoff curve

diagram
BEFORE / AFTER — Reset Deassertion CDC

open critical issues
  ^
  |  o baseline
  |     o after fix batch
  |         o after protocol proof
  |             o signoff-ready
  +---------------------------------> closure iteration

Track issue burn-down with evidence quality, not only count.

CDC/RDC deep dive

Reset release ordering is a first-order reliability contract.

Concept diagram

diagram
RESET RELEASE FLOW

assert global -> clocks stable -> sync release per domain -> first transaction

Metric graph

diagram
BOOT STABILITY

passes per 1k boots: 920 -> 980 -> 999

Reports and artifacts

  • reset dependency matrix

  • RDC warning classes

  • boot stress logs

  • waiver aging

Mini case study

Domain B released before producer A was valid, causing rare startup deadlock.

Debug branches

  • Correlate reset and clock timelines

  • verify async assert/sync release

  • exercise skewed release tests

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

Asynchronous assertion is usually safe, but reset deassertion must be synchronized per destination domain to prevent uncertain startup state capture.

Metric: reset release violations, metastability-on-release risk, boot instability