CDC / RDC · All levels

Reset Deassertion CDC: Worked Example

Worked Example for Reset Deassertion CDC.

Worked example

Worked Example for Reset Deassertion CDC focuses on reset release violations, metastability-on-release risk, boot instability. The goal is to convert issue observations into mechanism-backed closure decisions.

A milestone review shows reset release violations, metastability-on-release risk, boot instability. Teams disagree on severity. The right move is to isolate one representative issue, prove mechanism class, and decide fix or waiver with explicit residual risk.

Crossing under inspection

diagram
CROSSING FLOW — Reset Deassertion CDC

source clock domain -> launch signal -> crossing structure -> destination sample
      |                    |                 |                    |
   source FF           protocol           sync / fifo         destination FF

Key metric: reset release violations, metastability-on-release risk, boot instability

Async assert, sync release

diagram
reset_n (global) ----> assert immediately
                  |
                  +--> per-domain release synchronizer

Unsynchronized deassertion can metastabilize startup flops.
  1. Capture warning, waveform, and owning module context.

  2. Tag mode/reset/traffic state for the failure.

  3. Validate assumptions against spec and assertions.

  4. Compare outcome with reset tree map, release synchronizer audit, RDC report.

  5. Choose one reversible action and define regression upfront.

Did the action work?

diagram
BEFORE / AFTER — Reset Deassertion CDC

open critical issues
  ^
  |  o baseline
  |     o after fix batch
  |         o after protocol proof
  |             o signoff-ready
  +---------------------------------> closure iteration

Track issue burn-down with evidence quality, not only count.

CDC/RDC deep dive

Reset release ordering is a first-order reliability contract.

Concept diagram

diagram
RESET RELEASE FLOW

assert global -> clocks stable -> sync release per domain -> first transaction

Metric graph

diagram
BOOT STABILITY

passes per 1k boots: 920 -> 980 -> 999

Reports and artifacts

  • reset dependency matrix

  • RDC warning classes

  • boot stress logs

  • waiver aging

Mini case study

Domain B released before producer A was valid, causing rare startup deadlock.

Debug branches

  • Correlate reset and clock timelines

  • verify async assert/sync release

  • exercise skewed release tests

Senior review question

Ask: what evidence proves this risk is closed for silicon, not just tool-clean?

Key takeaways

  • State crossing class, assumptions, and owner with every issue.

  • Run structural and dynamic regressions after each fix.

Common pitfalls

  • Treating all warnings as equivalent risk.

  • Waiving issues without containment evidence.

  • Skipping reset and reconvergence stress after CDC fixes.

Principal CDC/RDC review addendum

Asynchronous assertion is usually safe, but reset deassertion must be synchronized per destination domain to prevent uncertain startup state capture.

Metric: reset release violations, metastability-on-release risk, boot instability