Low Power Verification · All levels
Detecting Unintended State Loss Scenarios
Retention & Restore: Unintended state loss often hides in corner transitions where retention assumptions are invalidated by reset, clock, or software sequencing. Verification should classify state into retained, recomputed, checkpointed, and software-reinitialized categories, then prove each category behaves correctly across all supported power modes. Scenario design must include rapid power cycling, nested domain dependencies, retention bypass modes, and warm-reset during restore to expose cases where logic appears alive but architectural state is silently stale or zeroed. Checkers should detect both direct value loss and derived symptoms such as illegal FSM state, inconsistent cache tags, or protocol context mismatches after wake. End-to-end scoreboards that compare pre-sleep intent with post-wake architectural invariants are essential to catch losses that do not manifest as immediate signal mismatches.
What this topic teaches
Detecting Unintended State Loss Scenarios converts LPV concepts into staff-level verification decisions. Unintended state loss often hides in corner transitions where retention assumptions are invalidated by reset, clock, or software sequencing. Verification should classify state into retained, recomputed, checkpointed, and software-reinitialized categories, then prove each category behaves correctly across all supported power modes. Scenario design must include rapid power cycling, nested domain dependencies, retention bypass modes, and warm-reset during restore to expose cases where logic appears alive but architectural state is silently stale or zeroed. Checkers should detect both direct value loss and derived symptoms such as illegal FSM state, inconsistent cache tags, or protocol context mismatches after wake. End-to-end scoreboards that compare pre-sleep intent with post-wake architectural invariants are essential to catch losses that do not manifest as immediate signal mismatches.
Senior-engineer framing question
When Escaped state-loss incident rate per power mode and observability coverage of non-retained critical state. regresses, can you isolate first failing low-power boundary, prove it with artifacts, assign owners, and close with rollback-safe validation?
LOW-POWER VERIFICATION FLOW - Detecting Unintended State Loss Scenarios
power intent and mode definitions
|
v
domain controls and transition sequencing
|
v
simulation behavior (isolation, retention, corruption)
|
v
assertions and coverage evidence
|
v
triage, bounded fix, and signoff closureEvidence to collect
Primary metric: Escaped state-loss incident rate per power mode and observability coverage of non-retained critical state..
Primary artifact: State survivability campaign report covering mode matrix, invariant checks, and residual risk signoff decisions..
Owners to include: system validation owner, low-power verification owner, software bring-up owner, quality/signoff owner.
One reproducible failing scenario and one stable comparator run.
One fixed metadata run with branch and configuration tags locked.
Ownership layers
OWNERSHIP LAYERS - Detecting Unintended State Loss Scenarios
+----------------------+--------------------------------+--------------------------------+
| Team | Primary responsibility | Closure artifact |
+----------------------+--------------------------------+--------------------------------+
| system validation owner | scenario intent and closure | review rationale memo |
| low-power verification owner | transition and boundary contract | timeline + assertion packet |
| software bring-up owner | regression signoff readiness | validation matrix + risk note |
+----------------------+--------------------------------+--------------------------------+Decision matrix
EVIDENCE MATRIX - Detecting Unintended State Loss Scenarios
+-----------------------------+--------------------------------+--------------------------------+---------------------------+
| Evidence | Tells you | Does not prove | Next action |
+-----------------------------+--------------------------------+--------------------------------+---------------------------+
| transition timeline traces | first failing LP phase | complete root-cause ownership | correlate with intent map |
| UPF-aware assertion logs | contract violations by phase | silicon product impact | map to scenario severity |
| corruption/X classification | actionable vs noisy failures | legal transition completeness | replay key mode corners |
| save/restore snapshots | state integrity movement | isolation correctness | pair with crossing checks |
| before-after regressions | mitigation movement quality | long-tail stability | run full matrix |
+-----------------------------+--------------------------------+--------------------------------+---------------------------+Key takeaways
Start with transition-boundary classification before broad methodology changes.
Tie each LPV claim to one proving artifact and one owner action.
Close with validation matrix and rollback trigger for signoff safety.
Common pitfalls
Waiving failures before first-failure boundary classification.
Changing intent, RTL, and checkers in one step and losing causality.
Declaring closure on local runs without broader replay coverage.
Low-power verification deep dive
Retention closure requires proving end-to-end state lifecycle through save, off, and restore windows.
Concept diagram
RETENTION LIFECYCLE
save request -> state capture -> power off -> power on -> restore -> traffic resumeMetric graph
RETENTION STABILITY
restore mismatch █████
save timing defects ████
stable wake cycles ███████Metrics and artifacts to collect
retention save/restore timing report
pre/post state diff matrix
multi-cycle retention stress summary
state-loss bug trend by mode
Mini case study
A corruption issue persisted until retention checks compared multi-cycle state snapshots rather than single wake events.
Debug branches
Track save acknowledgement against actual state capture.
Validate restore completion before functional traffic resumes.
Run repeated sleep/wake cycles to expose drift.
Senior review question
Ask: what exact low-power transition boundary failed first, and which artifact proves the closure claim reproducibly?
Key takeaways
Tie each LPV claim to a concrete transition boundary and one proving artifact.
Prefer minimal reversible fixes with explicit owner and rollback criteria.
Common pitfalls
Treating power-aware failures as random before boundary classification.
Waiving X-prop failures before proving impact and root cause.
Declaring closure without deterministic replay across key modes.