Low Power Verification · All levels

Save/Restore Handshake Sequencing

Retention & Restore: Save/restore sequencing must be verified as a protocol, not only as a waveform snapshot. The environment should assert legal ordering between save request, save acknowledge, isolation enable, clock gating, power switch transitions, and restore deassertion. Verification should model realistic controller jitter, firmware delays, and concurrent requests from neighboring domains so sequencing robustness is validated under system pressure. Critical checks include ensuring restore is blocked until clocks and supplies are stable, retained state is visible before dependent logic resumes, and no stale handshake from a prior cycle leaks into the next power event. Negative tests should intentionally inject early wake, missing save ack, and double-trigger conditions to prove recovery paths and watchdog behavior instead of assuming clean operation.

What this topic teaches

Save/Restore Handshake Sequencing converts LPV concepts into staff-level verification decisions. Save/restore sequencing must be verified as a protocol, not only as a waveform snapshot. The environment should assert legal ordering between save request, save acknowledge, isolation enable, clock gating, power switch transitions, and restore deassertion. Verification should model realistic controller jitter, firmware delays, and concurrent requests from neighboring domains so sequencing robustness is validated under system pressure. Critical checks include ensuring restore is blocked until clocks and supplies are stable, retained state is visible before dependent logic resumes, and no stale handshake from a prior cycle leaks into the next power event. Negative tests should intentionally inject early wake, missing save ack, and double-trigger conditions to prove recovery paths and watchdog behavior instead of assuming clean operation.

Senior-engineer framing question

When Handshake protocol compliance rate, save-to-off and restore-to-functional timing margin, and timeout escape count. regresses, can you isolate first failing low-power boundary, prove it with artifacts, assign owners, and close with rollback-safe validation?

diagram
LOW-POWER VERIFICATION FLOW - Save/Restore Handshake Sequencing

power intent and mode definitions
      |
      v
domain controls and transition sequencing
      |
      v
simulation behavior (isolation, retention, corruption)
      |
      v
assertions and coverage evidence
      |
      v
triage, bounded fix, and signoff closure

Evidence to collect

  • Primary metric: Handshake protocol compliance rate, save-to-off and restore-to-functional timing margin, and timeout escape count..

  • Primary artifact: Temporal handshake checker suite with protocol assertions, timeout diagnostics, and scenario-wise latency histograms..

  • Owners to include: power controller owner, firmware/power management owner, low-power verification owner, SoC integration owner.

  • One reproducible failing scenario and one stable comparator run.

  • One fixed metadata run with branch and configuration tags locked.

Ownership layers

diagram
OWNERSHIP LAYERS - Save/Restore Handshake Sequencing

+----------------------+--------------------------------+--------------------------------+
| Team                 | Primary responsibility         | Closure artifact               |
+----------------------+--------------------------------+--------------------------------+
| power controller owner | scenario intent and closure      | review rationale memo          |
| firmware/power management owner | transition and boundary contract | timeline + assertion packet    |
| low-power verification owner | regression signoff readiness     | validation matrix + risk note  |
+----------------------+--------------------------------+--------------------------------+

Decision matrix

diagram
EVIDENCE MATRIX - Save/Restore Handshake Sequencing

+-----------------------------+--------------------------------+--------------------------------+---------------------------+
| Evidence                    | Tells you                      | Does not prove                 | Next action               |
+-----------------------------+--------------------------------+--------------------------------+---------------------------+
| transition timeline traces  | first failing LP phase         | complete root-cause ownership  | correlate with intent map |
| UPF-aware assertion logs    | contract violations by phase   | silicon product impact         | map to scenario severity  |
| corruption/X classification | actionable vs noisy failures   | legal transition completeness  | replay key mode corners   |
| save/restore snapshots      | state integrity movement       | isolation correctness          | pair with crossing checks |
| before-after regressions    | mitigation movement quality    | long-tail stability            | run full matrix           |
+-----------------------------+--------------------------------+--------------------------------+---------------------------+

Key takeaways

  • Start with transition-boundary classification before broad methodology changes.

  • Tie each LPV claim to one proving artifact and one owner action.

  • Close with validation matrix and rollback trigger for signoff safety.

Common pitfalls

  • Waiving failures before first-failure boundary classification.

  • Changing intent, RTL, and checkers in one step and losing causality.

  • Declaring closure on local runs without broader replay coverage.

Low-power verification deep dive

Retention closure requires proving end-to-end state lifecycle through save, off, and restore windows.

Concept diagram

diagram
RETENTION LIFECYCLE

save request -> state capture -> power off -> power on -> restore -> traffic resume

Metric graph

diagram
RETENTION STABILITY

restore mismatch       █████
save timing defects    ████
stable wake cycles     ███████

Metrics and artifacts to collect

  • retention save/restore timing report

  • pre/post state diff matrix

  • multi-cycle retention stress summary

  • state-loss bug trend by mode

Mini case study

A corruption issue persisted until retention checks compared multi-cycle state snapshots rather than single wake events.

Debug branches

  • Track save acknowledgement against actual state capture.

  • Validate restore completion before functional traffic resumes.

  • Run repeated sleep/wake cycles to expose drift.

Senior review question

Ask: what exact low-power transition boundary failed first, and which artifact proves the closure claim reproducibly?

Key takeaways

  • Tie each LPV claim to a concrete transition boundary and one proving artifact.

  • Prefer minimal reversible fixes with explicit owner and rollback criteria.

Common pitfalls

  • Treating power-aware failures as random before boundary classification.

  • Waiving X-prop failures before proving impact and root cause.

  • Declaring closure without deterministic replay across key modes.