CDC / RDC · All levels
Reset Sequencing: Comparison Matrix
Comparison Matrix for Reset Sequencing.
Comparison matrix
Reset strategies trade simplicity, safety margin, and bring-up time.
+------------------+----------------+----------------+----------------+
| Approach | Strength | Weakness | Best when |
+------------------+----------------+----------------+----------------+
| Conservative | safe | extra latency | high-risk crossings |
| Balanced | practical | more setup | most production paths |
| Aggressive | fast schedule | escape risk | late-stage crunch |
| Refactor | structural gain | long cycle | recurring failures |
+------------------+----------------+----------------+----------------+When to choose each approach
Select approach by silicon risk, not only schedule urgency
Interview traps
Global waiver spray
Unproven protocol assumptions
Evidence comparison
CDC/RDC EVIDENCE MATRIX — Reset Sequencing
+-----------------------+----------------------------+----------------------------+---------------------------+
| Evidence | Tells you | Does not prove | Next action |
+-----------------------+----------------------------+----------------------------+---------------------------+
| structural report | crossing topology class | protocol liveness | add assertions/formal |
| reset map | release dependencies | dynamic startup behavior | run reset stress tests |
| formal proof | bounded safety/liveness | real firmware sequence | correlate with simulation |
| simulation stress | observed mode behavior | full state-space closure | target unhit corners |
| waiver log | accepted residual risk | technical correctness | periodic revalidation |
+-----------------------+----------------------------+----------------------------+---------------------------+CDC/RDC deep dive
Reset release ordering is a first-order reliability contract.
Concept diagram
RESET RELEASE FLOW
assert global -> clocks stable -> sync release per domain -> first transactionMetric graph
BOOT STABILITY
passes per 1k boots: 920 -> 980 -> 999Reports and artifacts
reset dependency matrix
RDC warning classes
boot stress logs
waiver aging
Mini case study
Domain B released before producer A was valid, causing rare startup deadlock.
Debug branches
Correlate reset and clock timelines
verify async assert/sync release
exercise skewed release tests
Senior review question
Ask: what evidence proves this risk is closed for silicon, not just tool-clean?
Key takeaways
State crossing class, assumptions, and owner with every issue.
Run structural and dynamic regressions after each fix.
Common pitfalls
Treating all warnings as equivalent risk.
Waiving issues without containment evidence.
Skipping reset and reconvergence stress after CDC fixes.
Principal CDC/RDC review addendum
Reset ordering enforces dependency contracts so control domains and memories become valid before downstream consumers execute.
Metric: domain bring-up order violations, dependency deadlocks, reset latency