DRAM & Memory Design · All levels

Patrol Scrub and RAS Policy

Reliability, ECC & Security: Patrol scrub proactively reads and rewrites DRAM lines so single-bit faults are corrected before accumulating into multi-bit uncorrectable events; RAS policy balances scrub aggressiveness against bandwidth and power overhead.

What this topic teaches

Patrol Scrub and RAS Policy turns DRAM theory into production-grade review decisions. Patrol scrub proactively reads and rewrites DRAM lines so single-bit faults are corrected before accumulating into multi-bit uncorrectable events; RAS policy balances scrub aggressiveness against bandwidth and power overhead.

The main objective is to identify where the first loss starts in the memory service path, prove it with reproducible traces, and close with the smallest owner-controlled fix.

Senior DRAM work is less about isolated register tuning and more about cross-layer causality: traffic shape, command stream legality, bank behavior, PHY margin, and field reliability must agree before signoff.

Senior-engineer framing question

When scrub interval coverage, latent fault dwell time, corrected-before-failure ratio regresses, can you prove whether the first failure is locality collapse, timing-window pressure, scheduler fairness loss, lane-margin drift, or reliability policy overhead?

diagram
DRAM CELL DIAGRAM - Patrol Scrub and RAS Policy

                bitline (BL)
                    |
           +--------+--------+
wordline --| access transistor|-- storage capacitor (Ccell)
           +--------+--------+
                    |
                  ground

Read:   BL precharge -> WL on -> tiny delta-V -> sense amp amplifies
Write:  drive BL -> WL on -> charge/discharge Ccell -> WL off

Focus: link physical state changes to service-level latency and bandwidth outcomes
Metric tracked: scrub interval coverage, latent fault dwell time, corrected-before-failure ratio

Architecture and timing visuals

Draw the mechanism before tuning knobs. These visuals are optimized for design reviews, bring-up triage, and interview whiteboards.

Patrol scrub wheel scheduler

diagram
PATROL SCRUB SCHEDULER

address space ring:
[0x0000] -> [0x1000] -> [0x2000] -> ... -> [end] -> wrap
    |          |          |
   read+ecc   read+ecc   read+ecc
      |          |          |
   rewrite if corrected bit observed

policy knobs:
- scrub interval
- bandwidth cap
- thermal-aware pacing

Latent fault accumulation timeline

diagram
LATENT FAULT TIMELINE

t0      t1      t2      t3
|-------|-------|-------|
 bit flip A      bit flip B (same word)

without scrub:
  A stays latent until access -> may become UE at t3
with scrub:
  A corrected before B arrives -> avoid UE conversion

Array hierarchy context

diagram
ARRAY HIERARCHY MAP - Patrol Scrub and RAS Policy

[Channel]
   |
[DIMM/Package]
   |
[Rank]
   |
[Bank Group]
   |
[Bank]
   |
[Subarray]
   |
[Row + Column Decode]
   |
[Cell Mat + Sense Amps]

Lens: map locality decisions to activate/precharge cost.

Command timing context

diagram
COMMAND TIMING DIAGRAM - Patrol Scrub and RAS Policy

time --->    t0      t1      t2      t3      t4      t5
cmd bus   |  ACT  |   RD  |   WR  |  PRE  |  REF  |  ACT
row state | open  | open  | open  | close | all   | open

key checks:
- ACT->RD >= tRCD
- RD data return >= CL
- WR->PRE >= tWR
- PRE->ACT >= tRP

Controller queue context

diagram
CONTROLLER QUEUE VIEW - Patrol Scrub and RAS Policy

read queue : [R12 bank0 row88] [R13 bank2 row88] [R14 bank0 row12]
write queue: [W44 bank3 row90] [W45 bank3 row90]

scheduler tick:
1) prioritize ready row hits
2) cap write-drain burst
3) age outstanding reads

issue stream:
cycle 40 -> RD bank0 row88 (hit)
cycle 41 -> RD bank2 row88 (parallel bank group)
cycle 42 -> ACT bank0 row12 (miss prepare)

Ownership layers

diagram
MEMORY OWNERSHIP LAYERS - Patrol Scrub and RAS Policy

artifact area     owner
----------------  ----------------------------
architecture    firmware owner
controller FW   system architect
verification    SRE / fleet reliability owner
silicon bringup TBD

Rule: every signoff metric has a named accountable owner.

Evidence to collect before changing knobs

Fast closure comes from complete evidence packets, not from isolated counter wins. Every recommendation should carry a metric, artifact, owner, and rollback-safe validation plan.

  • Primary metric: scrub interval coverage, latent fault dwell time, corrected-before-failure ratio.

  • Primary artifact: scrub scheduler log, CE aging report, patrol coverage audit.

  • Owners to include: firmware owner, system architect, SRE / fleet reliability owner.

  • One reproducible failing traffic slice plus one stable comparator capture.

  • One command legality timeline that isolates first failing transition.

  • One margin or reliability packet when PHY or RAS behavior is implicated.

Bandwidth-latency operating lens

diagram
BANDWIDTH vs LATENCY CURVE - Patrol Scrub and RAS Policy

latency
  ^
  |  low-load region
  |      *
  |        *
  |          *
  |            *         knee
  |              *      *
  |                *   *
  |                  ***
  +----------------------------------------------> bandwidth demand
     stable QoS          queue growth / saturation

Use the knee to set safe operating headroom.

Root-cause decision tree

diagram
ROOT CAUSE TREE - Patrol Scrub and RAS Policy

scrub interval coverage, latent fault dwell time, corrected-before-failure ratio regressed
        |
reproducible with fixed seed?
      /               \
    no                 yes
    |                   |
testbench noise    localize bottleneck
                    /              \
               command path       data path
                 |                  |
             scheduler/FSM      PHY/timing/noise
                 |                  |
             timing limits      training/calibration

Stop at first failing mechanism, then patch and re-measure.

Key takeaways

  • Prove first failing transition before touching broad tuning policies.

  • Tie command-level behavior to application-visible QoS outcomes.

  • Close with accountable owner, rollback criteria, and corner validation.

Common pitfalls

  • Optimizing average GB/s while p99 latency and fairness degrade.

  • Comparing traces without fixed firmware, timing profile, and thermal tags.

  • Declaring closure without reliability and retrain robustness checks.

DRAM deep dive

Reliability closure combines ECC policy, scrub cadence, and disturbance mitigation like row-hammer controls.

Concept diagram

diagram
RELIABILITY LOOP

error detect -> ECC correct/report -> scrub/retire policy -> monitor recurrence

Metric graph

diagram
ERROR MANAGEMENT TREND

correctable events    ███████
silent-data-risk      ██
unrecoverable events  █

Reports and artifacts

  • correctable/uncorrectable error trend

  • scrub interval effectiveness report

  • row-hammer monitor log

  • fault-injection coverage summary

Mini case study

Relaxed scrub interval improved bandwidth in test but allowed burst correctables to cluster into service-visible latency spikes.

Debug branches

  • Segment ECC events by bank, rank, and temperature

  • Tune scrub cadence with workload-aware idle windows

  • Verify row-hammer mitigation using adversarial patterns

Senior review question

Ask: which latency, bandwidth, and reliability evidence proves this DRAM topic is closed under real traffic?

Key takeaways

  • Always tie controller and PHY counter shifts to application latency and throughput outcomes.

  • Lock firmware timing profile, thermal condition, and DIMM state before comparing DRAM captures.

Common pitfalls

  • Chasing peak bandwidth while ignoring p99 latency and fairness tails.

  • Changing timing guardbands without separating SI noise from scheduling issues.

  • Declaring closure without reliability gates, fault injection, and regression replay.