Verification IP & Protocol Compliance ยท All levels

Error Injection and Negative Testing: Debug Playbook

Debug Playbook for Error Injection and Negative Testing.

Debug playbook

Debug Playbook for Error Injection and Negative Testing focuses on negative-test coverage closure and DUT error-response pass rate. The purpose is to turn memory observations into mechanism-backed actions with explicit owners and release-safe validation.

VIP debug should narrow from broad symptom to one dominant mechanism. Avoid mixed-knob sweeps that produce accidental wins without causal confidence.

  1. Freeze workload seed, firmware image, timing profile, and thermal setup.

  2. Find first failing transition in command timeline.

  3. Classify mechanism: locality loss, legality pressure, queue policy, margin drift, or RAS behavior.

  4. Build focused reproducer for top hypothesis.

  5. Apply minimal reversible fix and define rollback gate.

  6. Re-run full performance + reliability matrix.

Debug decision tree

diagram
ROOT CAUSE TREE - Error Injection and Negative Testing

negative-test coverage closure and DUT error-response pass rate regressed
        |
reproducible with fixed seed?
      /               \
    no                 yes
    |                   |
testbench noise    localize bottleneck
                    /              \
               command path       data path
                 |                  |
             scheduler/FSM      PHY/timing/noise
                 |                  |
             timing limits      training/calibration

Stop at first failing mechanism, then patch and re-measure.

Review memo template

diagram
VIP REVIEW MEMO - Protocol Checkers & Assertion Strategy / Error Injection and Negative Testing

1. Symptom
   - Watched metric: negative-test coverage closure and DUT error-response pass rate
   - Failing traffic slice: <workload/phase/class>
   - First failing transition: <checker hit/row-conflict/turnaround/refresh/training>
   - Revision tags: <firmware/controller/timing/board/package>

2. Mechanism hypothesis
   - Primary mechanism: Compliance requires proving correct behavior under illegal stimulus, parity/ECC faults, timeout paths, and recovery sequences. Error-injection checkers validate that monitors, scoreboards, and DUT responses remain coherent when the bus enters degraded modes.
   - Competing hypotheses: <mapping, scheduling, PHY margin, SI/PI, reliability policy>
   - Missing evidence: <command trace, queue snapshot, lane margins, CE/UE logs>

3. Proposed action
   - Smallest reversible change: <policy/register/firmware/flow>
   - Expected movement: <p99 latency, effective bandwidth, stability>
   - Regression risk: fairness, thermal drift, training robustness, field reliability

4. Signoff
   - Re-run artifact: negative-test matrix, fault-response log, and recovery sequence trace
   - Required owners: VIP architect, verification lead, protocol owner, compliance engineer, silicon validation owner
   - Final decision: ship, bounded rollout, rollback, or escalate

VIP deep dive

SVA and procedural checkers, temporal protocol rules, error-injection validation, and debug strategies for high-signal protocol closure.

Concept diagram

diagram
VIP SECTION - Protocol Checkers & Assertion Strategy

testcase -> agents -> checkers -> coverage -> evidence

Metric graph

diagram
checker noise vs real violations trend

Reports and artifacts

  • checker hit report

  • coverage closure sheet

  • compliance trace matrix

  • regression health snapshot

Mini case study

A profile drift caused false checker storms until configuration hashes were locked in CI.

Debug branches

  • Reproduce with locked seed and profile

  • Isolate checker vs scoreboard vs DUT paths

  • Map failure to spec clause and owner

Senior review question

Ask: which latency, bandwidth, and reliability evidence proves this VIP topic is closed under real traffic?

Key takeaways

  • Always tie controller and PHY counter shifts to application latency and throughput outcomes.

  • Lock firmware timing profile, thermal condition, and DIMM state before comparing VIP captures.

Common pitfalls

  • Chasing peak bandwidth while ignoring p99 latency and fairness tails.

  • Changing timing guardbands without separating SI noise from scheduling issues.

  • Declaring closure without reliability gates, fault injection, and regression replay.

VIP atlas notes

Error Injection and Negative Testing should be read as an end-to-end VIP behavior, not as a single block definition. Production compliance closure reflects interactions between agents, checkers, coverage, and customer evidence before tapeout or IP release claims.

Compliance requires proving correct behavior under illegal stimulus, parity/ECC faults, timeout paths, and recovery sequences. Error-injection checkers validate that monitors, scoreboards, and DUT responses remain coherent when the bus enters degraded modes. VIP inefficiency is multiplicative: one weak checker enable, one hollow coverage bin, or one non-reproducible failure repeated across regressions can dominate signoff risk.