STA Mastery · All levels
Exceptions & Audit Policy: Theory Deep Dive
Theory Deep Dive for Exceptions & Audit Policy.
Foundational theory
Exceptions & Audit Policy is central to Constraints & SDC Fundamentals. Timing exceptions remove pessimism only when justified; bad exceptions hide real paths and are a top signoff escape vector. Senior STA engineers always tie slack movement to corner, mode, constraint set, and parasitic view — not just a single report line.
Core concepts explained
Timing exceptions remove pessimism only when justified; bad exceptions hide real paths and are a top signoff escape vector.
Primary metric: false path count, multicycle path audit rate, exception waiver backlog
Primary artifact: exception report, constraint audit log, waiver manifest
Owners: STA lead, RTL owner, verification owner
Setup: max delay path; Hold: min delay path
WNS/TNS summarize tail risk across endpoints
Why this matters at signoff
At signoff, Exceptions & Audit Policy failures block tapeout or force risky ECO. SDC is the contract between RTL intent, synthesis, and signoff STA. Wrong analysis setup wastes weeks of PD effort.
Mental model
PATH FAILING TIMING
|
physically impossible?
/ \
yes no
| |
false_path multicycle?
(documented) / \
yes no
| |
set_multicycle fix RTL/PDWorked intuition
Name corner, mode, and view for the failing run.
Open false path count, multicycle path audit rate, exception waiver backlog and identify worst path group.
Read critical path: cell vs net, launch/capture clocks.
Check constraints on that path (exceptions, generated clocks).
Collect exception report, constraint audit log, waiver manifest and tag database versions.
Classify: constraint bug, view mismatch, or real path.
Propose minimal ECO and list MMMC+SI regression.
Common misconceptions
One typical corner is enough for signoff.
False paths can be applied broadly to green-wash violations.
Implementation WNS equals signoff WNS without view mapping.
Setup fix automatically preserves hold.
Visual reinforcement
Exception decision tree
PATH FAILING TIMING
|
physically impossible?
/ \
yes no
| |
false_path multicycle?
(documented) / \
yes no
| |
set_multicycle fix RTL/PDLayer responsibilities
STA OWNERSHIP LAYERS — Exceptions & Audit Policy
layer owns failure mode
---------------- -------------------------- ---------------------
constraints clocks, IO, exceptions false violations
implementation cells, nets, placement real path delay
extraction SPEF/RC corners view mismatch
signoff policy derate, MMMC matrix margin disputes
closure ECO order, regression fix breaks other cornerSTA deep dive
SDC quality determines whether STA measures reality or fiction.
Concept diagram
SDC FLOW
RTL clocks -> create_clock / generated_clock
board -> set_input/output_delay
exceptions -> false_path / multicycle (audited)
analysis -> report_timingMetric graph
CONSTRAINT QUALITY
audited exceptions ████████████████ good
stale IO delays ██████ risk
missing gen clock ████ high escapeReports and artifacts
clock report
uncertainty budget
IO delay coverage
exception audit log
Mini case study
1000 new failing paths overnight: SDC merge dropped a generated_clock on divider output. No PD change needed.
Debug branches
Diff SDC before ECO
Validate clocks on failing path
Audit false paths quarterly
Senior review question
Ask: what corner/mode/view proves this topic is closed or failing?
Key takeaways
State corner, mode, view, and database tag with every slack claim.
Run setup and hold plus MMMC regression after every ECO.
Common pitfalls
Comparing STA runs with different SPEF or SDC tags.
Broad false_path to green-wash violations.
Setup-only ECO without hold check.
Theory reinforcement
SDC is the contract between RTL intent, synthesis, and signoff STA.