4.1 Functional Verification of the Digital Design
103
from the design and the testbench was rerun. An error was produced as expected and
the error was indicated to be at the point where the error had been introduced.
2
4.1.3.2 Clocking and Clock-Domain Crossing Verification
Signals crossing between two asynchronous clock domains might experience metastability, which could cause incorrect data to be generated [14]. Since the SAMPA design
employs four clock domains where some of the clocks might be asynchronous if multiple clocks are externally sourced, it is both important to code the design to avoid any
metastability and to do verification to confirm that all crossings have been checked.
The design uses two-register synchronizers for all signals passing between two clock
domains [14]. Pulsed signals passing from a fast clock domain to a slow one are converted to signals that toggle on a rising edge before being passed to the slow domain,
this still requires pulses to be separated by two or more cycles on the receiving end,
but does not require the signal to stay high for multiple cycles. Multi-bit signals
from counters without control signal are Gray-encoded before being passed between
clock domains to avoid capturing the wrong value if the signal is captured in the
receiving domain while some of the bits are still switching over from one value to
another. When a control signal is present in addition to the multi-bit signals, only the
control signal is synchronized and the data is expected to be valid for enough cycles
to sample valid data.
To avoid that signal are inadvertently being used in another clock domain without
first being synchronized, a coding convention has been employed. For modules where
multiple clock domains are present, the variable names of all signals have been
appended with a postfix indicating the clock domain that the signal belongs to, e.g.
signal_clkadc, this avoids that errors are introduced while coding, it also aids in
spotting these errors while reviewing the code.
To verify correct operation of the design with asynchronous clocks, the top-level
testbench was run with the device set to operate with all external clocks and the
input clocks set to frequencies that were not a factor of each other. The cell library
was modified so that when a metastability is detected in a flip-flop it will randomly
produce a 1 or a 0 on its output instead of outputting ‘X’ which will propagate through
the design and prevent further testing. The regular set of tests were run without issues.
Testbench verification will only catch a subset of the possible clock domain crossing issues so to additionally verify that all crossings have been covered, Mentor
Questa CDC [15] has been employed. This tool uses structural analysis of the code
to detect clock domains and synchronizers and can report on any potential failure
modes.
The Clock Domain Crossing (CDC) testing uncovered no specific issues, proving
that the employed design methodology prevented these issues.
2 Scan chain insertion and testing done by Bruno Sanches and Dionisio Carvalho, University of São
Paulo, Brazil.
103
from the design and the testbench was rerun. An error was produced as expected and
the error was indicated to be at the point where the error had been introduced.
2
4.1.3.2 Clocking and Clock-Domain Crossing Verification
Signals crossing between two asynchronous clock domains might experience metastability, which could cause incorrect data to be generated [14]. Since the SAMPA design
employs four clock domains where some of the clocks might be asynchronous if multiple clocks are externally sourced, it is both important to code the design to avoid any
metastability and to do verification to confirm that all crossings have been checked.
The design uses two-register synchronizers for all signals passing between two clock
domains [14]. Pulsed signals passing from a fast clock domain to a slow one are converted to signals that toggle on a rising edge before being passed to the slow domain,
this still requires pulses to be separated by two or more cycles on the receiving end,
but does not require the signal to stay high for multiple cycles. Multi-bit signals
from counters without control signal are Gray-encoded before being passed between
clock domains to avoid capturing the wrong value if the signal is captured in the
receiving domain while some of the bits are still switching over from one value to
another. When a control signal is present in addition to the multi-bit signals, only the
control signal is synchronized and the data is expected to be valid for enough cycles
to sample valid data.
To avoid that signal are inadvertently being used in another clock domain without
first being synchronized, a coding convention has been employed. For modules where
multiple clock domains are present, the variable names of all signals have been
appended with a postfix indicating the clock domain that the signal belongs to, e.g.
signal_clkadc, this avoids that errors are introduced while coding, it also aids in
spotting these errors while reviewing the code.
To verify correct operation of the design with asynchronous clocks, the top-level
testbench was run with the device set to operate with all external clocks and the
input clocks set to frequencies that were not a factor of each other. The cell library
was modified so that when a metastability is detected in a flip-flop it will randomly
produce a 1 or a 0 on its output instead of outputting ‘X’ which will propagate through
the design and prevent further testing. The regular set of tests were run without issues.
Testbench verification will only catch a subset of the possible clock domain crossing issues so to additionally verify that all crossings have been covered, Mentor
Questa CDC [15] has been employed. This tool uses structural analysis of the code
to detect clock domains and synchronizers and can report on any potential failure
modes.
The Clock Domain Crossing (CDC) testing uncovered no specific issues, proving
that the employed design methodology prevented these issues.
2 Scan chain insertion and testing done by Bruno Sanches and Dionisio Carvalho, University of São
Paulo, Brazil.
