Clocks, resets, and clock-domain crossing¶
Clocking and CDC errors can produce hardware failures that simulation does not reproduce. Treat them as architecture, not cleanup.
The Basys 3 system clock¶
The board oscillator supplies 100 MHz on package pin W5:
set_property PACKAGE_PIN W5 [get_ports clk_i]
set_property IOSTANDARD LVCMOS33 [get_ports clk_i]
create_clock -period 10.000 -name sys_clk [get_ports clk_i]
One cycle is 10 ns. A count of 100,000,000 cycles represents one second, subject to oscillator tolerance.
Use clock enables for slower activity¶
Generate a one-cycle tick:
process(clk_i)
begin
if rising_edge(clk_i) then
tick_o <= '0';
if reset_i = '1' then
counter_q <= 0;
elsif counter_q = G_DIVISOR - 1 then
counter_q <= 0;
tick_o <= '1';
else
counter_q <= counter_q + 1;
end if;
end if;
end process;
All dependent registers remain on clk_i and update only when tick_o='1'.
Use a Clocking Wizard/MMCM/PLL when you truly need a different clock frequency, phase, jitter filtering, or dedicated clock output.
Reset strategy¶
Specify:
- Polarity.
- Synchronous or asynchronous assertion.
- Synchronous or asynchronous release.
- Minimum duration.
- Which state elements must reset.
- Behavior immediately after release.
Synchronous reset¶
process(clk_i)
begin
if rising_edge(clk_i) then
if reset_i = '1' then
state_q <= IDLE;
else
state_q <= state_d;
end if;
end if;
end process;
Advantages: reset timing is analyzed like other data and release is naturally aligned to the clock.
Asynchronous assertion, synchronous release¶
Use an architecture appropriate to the device and review tool guidance. Conceptually, assertion immediately places logic in reset, while a small synchronizer ensures release occurs on safe clock edges.
Do not feed an asynchronously released reset directly across many clock domains.
Metastability¶
If an asynchronous input changes near a receiving flip-flop edge, that flip-flop may take an unpredictable time to resolve to 0 or 1. RTL simulation normally cannot show analog metastability.
A two-flop synchronizer reduces the probability that metastability reaches functional logic:
signal sync_ff : std_logic_vector(1 downto 0) := (others => '0');
attribute ASYNC_REG : string;
attribute ASYNC_REG of sync_ff : signal is "TRUE";
process(clk_i)
begin
if rising_edge(clk_i) then
sync_ff(0) <= async_i;
sync_ff(1) <= sync_ff(0);
end if;
end process;
sync_o <= sync_ff(1);
The attribute helps implementation recognize and place the synchronizer appropriately.
Warning
A two-flop synchronizer is for a single level that remains stable long enough. It does not safely transfer an arbitrary multi-bit bus or a short pulse.
CDC patterns¶
| Crossing | Recommended pattern |
|---|---|
| Slow/stable single bit | Two or more synchronizer flops |
| Pulse to faster domain | Pulse synchronizer or toggle scheme |
| Pulse to slower domain | Stretch, toggle, or handshake |
| Multi-bit control word | Handshake; hold data stable while control crosses |
| Continuous data stream | Asynchronous FIFO |
| Counter/status snapshot | Gray-coded counter or handshake snapshot |
Multi-bit incoherence¶
Synchronizing every bit of a bus independently does not guarantee the receiving domain sees one coherent word. Different bits can settle on different cycles.
Transfer a bus using:
- Valid/acknowledge handshake.
- Asynchronous FIFO.
- Gray code when only one bit changes per step.
- Vendor CDC macro designed for the use case.
Buttons: synchronize then debounce¶
Synchronization handles clock-domain safety. Debouncing handles repeated mechanical transitions. The usual order is:
The debouncer accepts a new level only after it has remained unchanged for a configured number of cycles.
CDC analysis¶
Use:
Inspect every reported crossing. Vendor XPM CDC macros can improve structure recognition and encode tested patterns. Follow current AMD documentation for parameters and simulation assertions.
CDC constraints¶
Constraints must match the architecture:
- Define every clock.
- Define generated clocks.
- Declare truly asynchronous clock relationships where appropriate.
- Apply CDC-specific exceptions narrowly.
- Preserve synchronizer identification.
Do not hide an unsafe crossing with a broad false path.
CDC review checklist¶
- Every register belongs to an identified clock domain.
- Every signal crossing domains has an explicit transfer method.
- No raw button/switch directly controls synchronous state.
- Multi-bit buses are not independently synchronized.
- Short pulses cannot be missed.
- Resets are safely released in each domain.
-
report_cdcfindings are understood. - Timing exceptions match the CDC design.