Verification IP & Protocol Compliance ยท All levels

Error Injection and Negative Testing

Protocol Checkers & Assertion Strategy: Compliance requires proving correct behavior under illegal stimulus, parity/ECC faults, timeout paths, and recovery sequences. Error-injection checkers validate that monitors, scoreboards, and DUT responses remain coherent when the bus enters degraded modes.

What this topic teaches

Error Injection and Negative Testing turns VIP theory into production-grade review decisions. Compliance requires proving correct behavior under illegal stimulus, parity/ECC faults, timeout paths, and recovery sequences. Error-injection checkers validate that monitors, scoreboards, and DUT responses remain coherent when the bus enters degraded modes.

The main objective is to identify where the first loss starts in the memory service path, prove it with reproducible traces, and close with the smallest owner-controlled fix.

Senior VIP work is less about isolated register tuning and more about cross-layer causality: traffic shape, command stream legality, bank behavior, PHY margin, and field reliability must agree before signoff.

Senior-engineer framing question

When negative-test coverage closure and DUT error-response pass rate regresses, can you prove whether the first failure is locality collapse, timing-window pressure, scheduler fairness loss, lane-margin drift, or reliability policy overhead?

diagram
VIP CELL DIAGRAM - Error Injection and Negative Testing

                bitline (BL)
                    |
           +--------+--------+
wordline --| access transistor|-- storage capacitor (Ccell)
           +--------+--------+
                    |
                  ground

Read:   BL precharge -> WL on -> tiny delta-V -> sense amp amplifies
Write:  drive BL -> WL on -> charge/discharge Ccell -> WL off

Focus: link physical state changes to service-level latency and bandwidth outcomes
Metric tracked: negative-test coverage closure and DUT error-response pass rate

Architecture and timing visuals

Draw the mechanism before tuning knobs. These visuals are optimized for design reviews, bring-up triage, and interview whiteboards.

VIP agent and checker flow (Error Injection Checks)

diagram
VIP FLOW - Error Injection Checks

testcase -> sequencer -> driver -> DUT interface
              |                    |
              v                    v
           monitor <-------- bus activity
              |
              v
        checker / scoreboard -> compliance evidence

Coverage and compliance lens (Error Injection Checks)

diagram
COMPLIANCE LENS - Error Injection Checks

spec clause -> test -> checker -> coverage bin -> evidence artifact
                      |
                      v
               waiver/deviation register (if gap)

Array hierarchy context

diagram
ARRAY HIERARCHY MAP - Error Injection and Negative Testing

[Channel]
   |
[DIMM/Package]
   |
[Rank]
   |
[Bank Group]
   |
[Bank]
   |
[Subarray]
   |
[Row + Column Decode]
   |
[Cell Mat + Sense Amps]

Lens: map locality decisions to activate/precharge cost.

Command timing context

diagram
COMMAND TIMING DIAGRAM - Error Injection and Negative Testing

time --->    t0      t1      t2      t3      t4      t5
cmd bus   |  ACT  |   RD  |   WR  |  PRE  |  REF  |  ACT
row state | open  | open  | open  | close | all   | open

key checks:
- ACT->RD >= tRCD
- RD data return >= CL
- WR->PRE >= tWR
- PRE->ACT >= tRP

Controller queue context

diagram
CONTROLLER QUEUE VIEW - Error Injection and Negative Testing

read queue : [R12 bank0 row88] [R13 bank2 row88] [R14 bank0 row12]
write queue: [W44 bank3 row90] [W45 bank3 row90]

scheduler tick:
1) prioritize ready row hits
2) cap write-drain burst
3) age outstanding reads

issue stream:
cycle 40 -> RD bank0 row88 (hit)
cycle 41 -> RD bank2 row88 (parallel bank group)
cycle 42 -> ACT bank0 row12 (miss prepare)

Ownership layers

diagram
MEMORY OWNERSHIP LAYERS - Error Injection and Negative Testing

artifact area     owner
----------------  ----------------------------
architecture    VIP architect
controller FW   verification lead
verification    protocol owner
silicon bringup compliance engineer

Rule: every signoff metric has a named accountable owner.

Evidence to collect before changing knobs

Fast closure comes from complete evidence packets, not from isolated counter wins. Every recommendation should carry a metric, artifact, owner, and rollback-safe validation plan.

  • Primary metric: negative-test coverage closure and DUT error-response pass rate.

  • Primary artifact: negative-test matrix, fault-response log, and recovery sequence trace.

  • Owners to include: VIP architect, verification lead, protocol owner, compliance engineer, silicon validation owner.

  • One reproducible failing traffic slice plus one stable comparator capture.

  • One command legality timeline that isolates first failing transition.

  • One margin or reliability packet when PHY or RAS behavior is implicated.

Bandwidth-latency operating lens

diagram
BANDWIDTH vs LATENCY CURVE - Error Injection and Negative Testing

latency
  ^
  |  low-load region
  |      *
  |        *
  |          *
  |            *         knee
  |              *      *
  |                *   *
  |                  ***
  +----------------------------------------------> bandwidth demand
     stable QoS          queue growth / saturation

Use the knee to set safe operating headroom.

Root-cause decision tree

diagram
ROOT CAUSE TREE - Error Injection and Negative Testing

negative-test coverage closure and DUT error-response pass rate regressed
        |
reproducible with fixed seed?
      /               \
    no                 yes
    |                   |
testbench noise    localize bottleneck
                    /              \
               command path       data path
                 |                  |
             scheduler/FSM      PHY/timing/noise
                 |                  |
             timing limits      training/calibration

Stop at first failing mechanism, then patch and re-measure.

Key takeaways

  • Prove first failing transition before touching broad tuning policies.

  • Tie command-level behavior to application-visible QoS outcomes.

  • Close with accountable owner, rollback criteria, and corner validation.

Common pitfalls

  • Optimizing average GB/s while p99 latency and fairness degrade.

  • Comparing traces without fixed firmware, timing profile, and thermal tags.

  • Declaring closure without reliability and retrain robustness checks.

VIP deep dive

SVA and procedural checkers, temporal protocol rules, error-injection validation, and debug strategies for high-signal protocol closure.

Concept diagram

diagram
VIP SECTION - Protocol Checkers & Assertion Strategy

testcase -> agents -> checkers -> coverage -> evidence

Metric graph

diagram
checker noise vs real violations trend

Reports and artifacts

  • checker hit report

  • coverage closure sheet

  • compliance trace matrix

  • regression health snapshot

Mini case study

A profile drift caused false checker storms until configuration hashes were locked in CI.

Debug branches

  • Reproduce with locked seed and profile

  • Isolate checker vs scoreboard vs DUT paths

  • Map failure to spec clause and owner

Senior review question

Ask: which latency, bandwidth, and reliability evidence proves this VIP topic is closed under real traffic?

Key takeaways

  • Always tie controller and PHY counter shifts to application latency and throughput outcomes.

  • Lock firmware timing profile, thermal condition, and DIMM state before comparing VIP captures.

Common pitfalls

  • Chasing peak bandwidth while ignoring p99 latency and fairness tails.

  • Changing timing guardbands without separating SI noise from scheduling issues.

  • Declaring closure without reliability gates, fault injection, and regression replay.