Low Power / UPF · All levels
UPF Formal Checks
Low Power Verification: Formal engines validate low-power connectivity and control correctness exhaustively for classes of bugs difficult to hit in simulation.
What this topic teaches
UPF Formal Checks translates low-power intent into release-grade evidence. Formal engines validate low-power connectivity and control correctness exhaustively for classes of bugs difficult to hit in simulation. The practical challenge is proving policy correctness under real transitions and ensuring each owner closes their layer without semantic drift.
The senior-engineer question
When formal LP property pass rate, unreachable isolation condition count, and retention proof completeness regresses, can you identify the failing transition, policy owner, implementation evidence, and minimum regression that proves closure?
POWER INTENT FLOW — UPF Formal Checks
architecture intent
|
v
UPF objects (domain/supply/state/strategy)
|
v
RTL + synthesis + PD interpretation
|
v
verification + signoff evidence
|
v
release decision
Primary metric: formal LP property pass rate, unreachable isolation condition count, and retention proof completenessPicture the low-power flow
Start with domain/state diagrams before diving into logs. These are the models to sketch in design and interview reviews.
Formal low-power proof scope
FORMAL LP CHECKS
prove isolation active when source OFF
prove retained regs restore before use
prove forbidden crossings unreachable
prove control signal originates in AON domainDomain map
POWER DOMAIN MAP — UPF Formal Checks
+------------------- always_on -------------------+
| PMU / control / retention rail |
+---------+----------------------------+----------+
| |
+--------v---------+ +--------v---------+
| domain_A | | domain_B |
| switchable |<------->| switchable |
| iso/ret controls | crossings require policy |
+------------------+ +------------------+
Domain boundaries are policy boundaries, not drawing boundaries.State transition path
STATE TRANSITIONS — UPF Formal Checks
ON --save--> RETENTION --off--> OFF
^ | |
| +----restore<--------+
+--------------------power_up--------+
Guard checks:
- isolation asserted before OFF
- restore before functional traffic
- reset policy consistent with retained stateOwnership layers
LP OWNERSHIP LAYERS — UPF Formal Checks
layer owns typical failure
------------------ --------------------------- --------------------------
architecture domain strategy infeasible power states
UPF intent policy objects + bindings wrong/missing policy
implementation LP cell insertion/routing illegal physical behavior
verification transition scenarios uncovered LP bug
signoff governance waiver + release decisions late escape to siliconEvidence to collect
Primary metric: formal LP property pass rate, unreachable isolation condition count, and retention proof completeness.
Primary artifact: formal LP app report, property dashboard, and proof-waiver log.
Owners to bring into review: formal owner, UPF owner, verification lead.
One failing transition timeline with state markers and control signals.
One report snippet proving policy intent versus implementation behavior.
Ownership map
OWNERSHIP MAP — UPF Formal Checks
artifact owner
---------------- -----------------
intent policy formal owner
implementation UPF owner
verification verification lead
Escapes happen when ownership is implicit.Subpages in this topic
Each topic is taught across mechanism, inputs/outputs, reports, debug, worked example, pitfalls, interview, checklist, theory, design space, expanded case study, walkthrough, comparison matrix, software view, and silicon impact.
Key takeaways
Always name the transition context for every low-power metric.
Bind each policy decision to a specific owner and artifact.
Re-run LP simulation, formal, and implementation checks after changes.
Common pitfalls
Treating static pass reports as transition closure.
Fixing symptoms without checking policy binding and sequence order.
Shipping with ambiguous ownership on open LP violations.
Low-power deep dive
Transition-centric verification closes LP risk better than active-mode-centric regressions.
Concept diagram
VERIFY LOOP
transition matrix -> simulation + formal -> coverage -> closureMetric graph
COVERAGE CLOSURE
state transitions covered ███████████
isolation activation █████████
retention restore paths ████████Reports and artifacts
state coverage
formal LP properties
isolation coverage
LP bug triage dashboard
Mini case study
Coverage looked high, but one untested OFF->RUN transition hid a restore race.
Debug branches
Rank by transition criticality
Correlate PMU logs with failures
Escalate unproven properties
Senior review question
Ask: what transition evidence proves this topic is closed, and which owner signs it?
Key takeaways
State transition context must accompany every low-power metric claim.
Intent changes require simulation, formal, and implementation re-validation.
Common pitfalls
Comparing results from mismatched UPF revisions.
Assuming static checks replace transition validation.
Shipping with aged waivers and unclear ownership.
Execution drill pack 1
Use this pack to rehearse low-power closure on low-power/low-power-verification/upf-formal-checks: transition framing, policy ownership, implementation evidence, and release confidence.
Transition checklist
State transition explicitly named with legal source/target states.
Crossing and domain ownership are mapped and agreed.
Policy controls are traced to always-on source logic.
Waveform bookmarks align controls with state timestamps.
Review prompts
Which policy object is first to deviate from intent?
Which owner can apply the smallest reversible fix?
What regression matrix proves no collateral damage?
Which waiver conditions would still block release?
Evidence capsule
LP EVIDENCE CAPSULE 1
PATH: low-power/low-power-verification/upf-formal-checks
STATE WINDOW: <from -> to>
POLICY OBJECT: <isolation / retention / shifter / switch>
OWNER: <name>
PRIMARY ARTIFACT: <report/waveform/formal result>
RELEASE DECISION: <close / bounded waiver / escalate>Execution drill pack 2
Use this pack to rehearse low-power closure on low-power/low-power-verification/upf-formal-checks: transition framing, policy ownership, implementation evidence, and release confidence.
Transition checklist
State transition explicitly named with legal source/target states.
Crossing and domain ownership are mapped and agreed.
Policy controls are traced to always-on source logic.
Waveform bookmarks align controls with state timestamps.
Review prompts
Which policy object is first to deviate from intent?
Which owner can apply the smallest reversible fix?
What regression matrix proves no collateral damage?
Which waiver conditions would still block release?
Evidence capsule
LP EVIDENCE CAPSULE 2
PATH: low-power/low-power-verification/upf-formal-checks
STATE WINDOW: <from -> to>
POLICY OBJECT: <isolation / retention / shifter / switch>
OWNER: <name>
PRIMARY ARTIFACT: <report/waveform/formal result>
RELEASE DECISION: <close / bounded waiver / escalate>Execution drill pack 3
Use this pack to rehearse low-power closure on low-power/low-power-verification/upf-formal-checks: transition framing, policy ownership, implementation evidence, and release confidence.
Transition checklist
State transition explicitly named with legal source/target states.
Crossing and domain ownership are mapped and agreed.
Policy controls are traced to always-on source logic.
Waveform bookmarks align controls with state timestamps.
Review prompts
Which policy object is first to deviate from intent?
Which owner can apply the smallest reversible fix?
What regression matrix proves no collateral damage?
Which waiver conditions would still block release?
Evidence capsule
LP EVIDENCE CAPSULE 3
PATH: low-power/low-power-verification/upf-formal-checks
STATE WINDOW: <from -> to>
POLICY OBJECT: <isolation / retention / shifter / switch>
OWNER: <name>
PRIMARY ARTIFACT: <report/waveform/formal result>
RELEASE DECISION: <close / bounded waiver / escalate>Execution drill pack 4
Use this pack to rehearse low-power closure on low-power/low-power-verification/upf-formal-checks: transition framing, policy ownership, implementation evidence, and release confidence.
Transition checklist
State transition explicitly named with legal source/target states.
Crossing and domain ownership are mapped and agreed.
Policy controls are traced to always-on source logic.
Waveform bookmarks align controls with state timestamps.
Review prompts
Which policy object is first to deviate from intent?
Which owner can apply the smallest reversible fix?
What regression matrix proves no collateral damage?
Which waiver conditions would still block release?
Evidence capsule
LP EVIDENCE CAPSULE 4
PATH: low-power/low-power-verification/upf-formal-checks
STATE WINDOW: <from -> to>
POLICY OBJECT: <isolation / retention / shifter / switch>
OWNER: <name>
PRIMARY ARTIFACT: <report/waveform/formal result>
RELEASE DECISION: <close / bounded waiver / escalate>Execution drill pack 5
Use this pack to rehearse low-power closure on low-power/low-power-verification/upf-formal-checks: transition framing, policy ownership, implementation evidence, and release confidence.
Transition checklist
State transition explicitly named with legal source/target states.
Crossing and domain ownership are mapped and agreed.
Policy controls are traced to always-on source logic.
Waveform bookmarks align controls with state timestamps.
Review prompts
Which policy object is first to deviate from intent?
Which owner can apply the smallest reversible fix?
What regression matrix proves no collateral damage?
Which waiver conditions would still block release?
Evidence capsule
LP EVIDENCE CAPSULE 5
PATH: low-power/low-power-verification/upf-formal-checks
STATE WINDOW: <from -> to>
POLICY OBJECT: <isolation / retention / shifter / switch>
OWNER: <name>
PRIMARY ARTIFACT: <report/waveform/formal result>
RELEASE DECISION: <close / bounded waiver / escalate>Execution drill pack 6
Use this pack to rehearse low-power closure on low-power/low-power-verification/upf-formal-checks: transition framing, policy ownership, implementation evidence, and release confidence.
Transition checklist
State transition explicitly named with legal source/target states.
Crossing and domain ownership are mapped and agreed.
Policy controls are traced to always-on source logic.
Waveform bookmarks align controls with state timestamps.
Review prompts
Which policy object is first to deviate from intent?
Which owner can apply the smallest reversible fix?
What regression matrix proves no collateral damage?
Which waiver conditions would still block release?
Evidence capsule
LP EVIDENCE CAPSULE 6
PATH: low-power/low-power-verification/upf-formal-checks
STATE WINDOW: <from -> to>
POLICY OBJECT: <isolation / retention / shifter / switch>
OWNER: <name>
PRIMARY ARTIFACT: <report/waveform/formal result>
RELEASE DECISION: <close / bounded waiver / escalate>Execution drill pack 7
Use this pack to rehearse low-power closure on low-power/low-power-verification/upf-formal-checks: transition framing, policy ownership, implementation evidence, and release confidence.
Transition checklist
State transition explicitly named with legal source/target states.
Crossing and domain ownership are mapped and agreed.
Policy controls are traced to always-on source logic.
Waveform bookmarks align controls with state timestamps.
Review prompts
Which policy object is first to deviate from intent?
Which owner can apply the smallest reversible fix?
What regression matrix proves no collateral damage?
Which waiver conditions would still block release?
Evidence capsule
LP EVIDENCE CAPSULE 7
PATH: low-power/low-power-verification/upf-formal-checks
STATE WINDOW: <from -> to>
POLICY OBJECT: <isolation / retention / shifter / switch>
OWNER: <name>
PRIMARY ARTIFACT: <report/waveform/formal result>
RELEASE DECISION: <close / bounded waiver / escalate>