Low Power Verification · All levels

Legal and Illegal PST Transition Checks: Mechanism

Mechanism for Legal and Illegal PST Transition Checks.

Mechanism to understand

Mechanism for Legal and Illegal PST Transition Checks is anchored on Illegal transition escape rate, transition-checker latency to first error, and percentage of legal arcs exercised with pass/fail evidence.. Convert observations into mechanism-backed and owner-bound actions.

Transition correctness is not only about start and end states; it depends on guards, temporal ordering, and confirmation events on each arc. Verification therefore encodes every legal PST arc with required preconditions (for example quiescent interconnect, save-ack observed, debug override cleared) and postconditions (such as supply good, isolation release, restore complete) while asserting that all non-enumerated arcs remain unreachable. Illegal transition checks must include both direct jumps and multi-step shortcuts created by overlapping requests, because concurrent software writes or interrupt-driven exits can collapse intended two-hop paths into electrically unsafe single-hop behavior. Advanced checkers track arc provenance, so when a violation occurs they identify which guard was bypassed, which handshake timed out, and whether recovery logic masked the violation by forcing a fallback state after corruption was already possible.

  • Name first boundary where expected transition behavior diverges.

  • Prove mechanism with one high-confidence evidence packet.

  • Assign owner for smallest reversible mitigation.

Execution flow

diagram
LOW-POWER VERIFICATION FLOW - Legal and Illegal PST Transition Checks

power intent and mode definitions
      |
      v
domain controls and transition sequencing
      |
      v
simulation behavior (isolation, retention, corruption)
      |
      v
assertions and coverage evidence
      |
      v
triage, bounded fix, and signoff closure

Low-power verification deep dive

Power-state correctness is a protocol contract: legal transitions, robust sequencing, and safe concurrent event handling.

Concept diagram

diagram
PST CONTROL LOOP

state request -> legality check -> handshake sequencing -> mode entry -> monitored exit

Metric graph

diagram
STATE RISK MIX

illegal transitions     ██████
sequence race bugs      █████
stable mode paths       ████████

Metrics and artifacts to collect

  • PST legality matrix

  • illegal transition histogram

  • entry/exit handshake coverage

  • mode sequencing anomaly log

Mini case study

A sporadic low-power failure closed only after proving a wake-versus-thermal race in PMU transition sequencing.

Debug branches

  • Validate legal state graph first.

  • Stress concurrent control events and asynchronous wakeups.

  • Bind fixes to explicit transition and owner contracts.

Senior review question

Ask: what exact low-power transition boundary failed first, and which artifact proves the closure claim reproducibly?

Key takeaways

  • Tie each LPV claim to a concrete transition boundary and one proving artifact.

  • Prefer minimal reversible fixes with explicit owner and rollback criteria.

Common pitfalls

  • Treating power-aware failures as random before boundary classification.

  • Waiving X-prop failures before proving impact and root cause.

  • Declaring closure without deterministic replay across key modes.

Mechanism deep dive

Mechanism detail: Transition correctness is not only about start and end states; it depends on guards, temporal ordering, and confirmation events on each arc. Verification therefore encodes every legal PST arc with required preconditions (for example quiescent interconnect, save-ack observed, debug override cleared) and postconditions (such as supply good, isolation release, restore complete) while asserting that all non-enumerated arcs remain unreachable. Illegal transition checks must include both direct jumps and multi-step shortcuts created by overlapping requests, because concurrent software writes or interrupt-driven exits can collapse intended two-hop paths into electrically unsafe single-hop behavior. Advanced checkers track arc provenance, so when a violation occurs they identify which guard was bypassed, which handshake timed out, and whether recovery logic masked the violation by forcing a fallback state after corruption was already possible.

Strong explanations tie transition semantics directly to observed failures.