Reset release is not one simultaneous instant across the chip. If permission crosses a clock domain or precedes startup checks, it may be used while the system appears to be booting.
Startup is a gated sequence
A hospital backup-power transfer makes the point: lights can be on before every ward has passed its checks. A controller waits for stable power, self-tests, and then enables selected outlets. A chip must likewise distinguish stable power, reset release, valid OTP/lifecycle data, ROM checks, and CPU fetch enable. These are separate events. The analogy only conveys staged readiness; it does not model asynchronous reset networks, metastability, or fused lifecycle states.
List reset assertion and deassertion in each domain. Asynchronous assertion can clear state promptly; deassertion is commonly synchronized to each destination clock to avoid recovery/removal violations. OpenTitan’s public lifecycle-controller theory describes waiting for OTP sensing, decoding and broadcasting lifecycle, then checking straps/ROM after stabilization. That is a design-specific document, not a timing guarantee for every product. Lifecycle controller.
A one-bit ready pulse sampled directly across domains may be missed. Synchronizing each bit of a multi-bit lifecycle bus independently can instead produce a combination that never existed because bits arrive on different cycles. Transfer data with a handshake or stable encoding, and authorize using reset state synchronized locally. For split reset groups, examine transactions and FIFO clearing while the producer is awake but the consumer is not. A CDC report is structural evidence; it does not prove lifecycle policy.
Counterexample: ROM check is complete in clk_sys, but clk_dbg has not yet observed synchronized check_done. If permission arrives first, the destination accepts debug too early. Assert at the actual debug-accept boundary, not only on the reset controller’s eventual state. The SVA below is a harness proposal, not compiled; every debug_accept requires stable lifecycle and a completed check.
Acceptance boundary
Test reset release order, pause or speed each domain, inject one-cycle cross-domain requests, repeat reset, and cover each lifecycle value. Positive controls must show that an authorized startup eventually becomes usable; safety checks must show no acceptance before prerequisites hold. An edge model cannot replace CDC/RDC analysis, reset-tree timing, power-ramp testing, or analog brownout validation.
Offline interactive lab
RTL / SVA review direction
These are property sketches: define the harness transaction, reset and oracle, then confirm sampling boundaries before binding to the design. They have not been compiled or proven.
assert property (@(posedge clk_dbg) disable iff (!rst_dbg_n)
debug_accept |-> reference_lifecycle_stable_sync && reference_rom_check_done_sync);
cover property (@(posedge clk_dbg) disable iff (!rst_dbg_n)
debug_accept && reference_lifecycle_stable_sync && reference_rom_check_done_sync);
reference_* signals belong to an oracle independent of the DUT. A synchronized flag only says the destination observed a state; it does not prove correct CDC or a legal source lifecycle.
This snippet does not prove CDC, timing, side-channel, or physical injection behavior; each requires its own tool evidence or measurement.
Check your reasoning
- Recognition — Which startup events must the design treat separately? Reasoning: Reset release, valid lifecycle data, ROM check completion, and CPU or debug acceptance are distinct events; one ready bit cannot stand in for all of them.
- Contrast — Why synchronize reset deassertion locally, but use a handshake for a multi-bit lifecycle value? Reasoning: A local reset synchronizer controls release timing in that domain. A handshake or stable encoded transfer preserves the relationship among multiple data bits.
- Scenario — On a common teaching timeline, permission reaches the destination first. Source check_done completes later and has not yet been observed through synchronization in clk_dbg. What should debug_accept do? Reasoning: It must remain low until the destination domain has observed the prerequisite. A weak policy that accepts the early permission is the counterexample.
- Failure diagnosis — What can happen if each bit of a lifecycle bus crosses through its own synchronizer? Reasoning: Different bits can arrive on different cycles, producing a combination that the source never sent. Use a coherent transfer protocol or a safely held encoding.
- Design risk / transfer — A producer restarts while a consumer and its FIFO remain active. What must the review establish? Reasoning: Define which reset groups may restart independently, how in-flight entries are invalidated or drained, and which transactions remain authorized. CDC/RDC structure alone does not prove that policy.
References
OpenTitan Lifecycle Controller
MY ACADEMY · LESSON FILM
Lesson video
The film explains this lesson’s data path. After a section, return to the interactive exercise and change the input or fault conditions. The animation presents a teaching model; it does not replace RTL simulation.
Swipe the film horizontally, or use the arrow keys to inspect the diagrams.
Diagram scope
Teaching model · Not RTL simulation or silicon testing
Common teaching timeline; not cycle-index comparison, metastability probability or STA
Narration uses a synthetic voice. Both the interaction and animation have model boundaries; interpret results using this lesson’s sources and validation scope.
Wrap-up: take this lesson into a design review
- Threat model and assumptions
During startup, debug permission and ROM check_done cross different clock domains. After the destination reset releases, permission may arrive before check_done is synchronized there.
- Why the design fails
The destination accepts debug permission before synchronized check_done; reset-release ordering and clock phase can let that path arrive first.
- Defenses
Synchronize reset release in each domain, handshake lifecycle/check status, and check stable conditions at acceptance.
- Validation and checks to perform
Cross phase/state enumeration, CDC/RDC structural checks, timing and positive startup controls; no RTL/formal/STA has run for this lesson.
- Limits and unverified claims
An edge model does not represent metastability probability, analog power, the actual reset tree or physical lifecycle fuses.
Try a changed assumption
Change destination frequency and add a CDC FIFO. Define which reset groups may restart independently and the minimum evidence required at acceptance.
This wrap-up summarizes the lesson’s teaching cases, references and experiment scope. Checks not reported as completed remain future work.