Framing protocols look simple on the clean path. A transmitter adds boundaries, counters, markers, parity, or checksums. Receiving logic finds that structure, rebuilds the payload, and forwards trusted data. This interpretation remains valid only while the observed framing agrees with internal state.
At startup, input may begin on a frame boundary, partway through a frame, during idle, or with malformed data. A locked design faces the same uncertainty after a local reset, missing marker, unexpected boundary, or framing violation. Until enough evidence establishes a valid phase, incoming symbols may qualify alignment but cannot be trusted as payload.
Resynchronization revokes the stale interpretation, invalidates affected state, searches the live input, and qualifies a new framing epoch. The interface contract defines how output behaves while trust is low and which state survives. Tests must therefore cover clean startup, acquisition from arbitrary phase, and loss of lock while upstream traffic continues.
The hidden state behind a frame
Once qualified, frame boundaries anchor the block's view of word phase, marker spacing, or lane identity. The same epoch governs partial datapath words, qualification history, and protocol counters. Every state element derived from that boundary needs an explicit recovery policy.
Wrong framing can leave this state internally consistent but semantically wrong. A partial word can mix epochs, a counter can advance from the wrong boundary, or a lane can assume the wrong position. Payload may still look legal after trust should have been removed.
In the IEEE 802.3 PCS layer, alignment markers help receivers establish alignment, identify and reorder lanes, and deskew the aggregate stream. A matching word is only candidate evidence. Its position and lane interpretation must also agree with current state.
FlexO framing also relies on recurring structure at several levels, including lane alignment markers, frame and multiframe indications, overhead fields, and CRC checks. Candidate evidence becomes trusted framing only when the surrounding observations agree.
In a recent project, we built an alignment marker (AM) aligner around this pattern. The block searches for a known marker, confirms later markers at the expected positions, and reports trust only after qualification. PCS and FlexO give markers different meanings, but both can lose agreement with state while payload remains plausible.
Recovery requires invalidation, not necessarily a state with that name. Logic can return directly from lock to search if the transition revokes aligned status and clears old state. A cleanup state is useful only when invalidation spans multiple cycles, such as when draining buffered data or completing a cross-domain handshake.
Why the failure is subtle
Clean vector tests start the generator at its first item, the DUT at reset, and the checker with an empty history. They prove that a legal stream maps to a legal result and catch ordinary transformation bugs.
Resynchronization failures live between clean epochs. We have encountered them in boundary timing, lock management, deskew, and local resets under traffic. Restarting the testbench can hide them: the generator rewinds to a convenient boundary, the checker forgets the bad epoch, and the scoreboard no longer has to account for invalidated outputs. That proves clean reset, not recovery while the surrounding stream continues.
Define the recovery contract
Write the recovery contract before writing the test. It should answer:
- What event invalidates the current framing epoch?
- Which state resets immediately, which state drains, and which state persists?
- Is a transfer on the reset assertion edge accepted, and which accepted inputs must be preserved?
- How does the interface represent untrusted output?
- What evidence creates a candidate, establishes trust, and removes it?
- Which reset domains can change independently?
Lock and unlock thresholds are one way to make that decision. In our AM alignment logic, a configurable number of markers at expected positions establishes lock. A matching marker at the expected position clears the consecutive-miss count. Misses below the unlock threshold preserve lock; reaching it revokes lock and returns to search. Payload can remain well formed after framing evidence becomes untrustworthy.
Another protocol may accept one delimiter, combine checks, or rely on sideband. A lossless transport may require buffering, replay, or backpressure. These choices govern state retention, output handling, and checker policy. The diagram is a pattern, not a universal receiver architecture.
Keep the epoch alive
In our framed IP tests, the source generator, external checker, adapters, and an inverse reference model are constructed once. One scenario releases the receiver at an arbitrary stream phase and checks that trust remains low until qualification. Another establishes stable traffic, then corrupts framing or resets only DUT state.
The Lightweight RTL Verification Flow with cocotb gives each model explicit state ownership. Our cocotb tests maintain that separation across the complete scenario.
A DUT reset clears only the RTL and same-direction model state owned by that receiver. The source, external checker, inverse model, and adapters retain their state. The source does not rewind: an unaccepted item remains pending, while accepted inputs in flight follow the reset contract. The external checker keeps its lock history and error and resynchronization counters. If reset requires a quiet interface, handshakes can pause without discarding external traffic state.
That separation exposes real recovery behavior. Report early or late boundaries at the accepted transfer, not when a stalled input presents a signal. Exercise match and mismatch thresholds instead of forcing the checker from reset to trusted payload. Scoreboards should discard only outputs invalidated by the reset contract.
For a receiver using thresholds, the following directed sequence makes the contract visible:
- Acquire lock and prove a clean window.
- Inject fewer mismatches than the unlock criterion and confirm that lock persists.
- Reach the criterion and confirm that the receiver revokes trust.
- Restore valid framing without restarting the source and require bounded reacquisition.
- Prove another clean persistence window.
Protocols without thresholds use the same sequence with their own lock and invalidation events.
Recovery requires more than the first plausible output. Acquisition finds enough structure to trust state; persistence confirms that trust across later protocol traffic.
Measure in protocol units: frames, marker periods, codeword groups, packets, or another meaningful boundary. Avoid cycle waits unless the contract uses cycles. Bound every wait with an explicit failure: no lock, no output, no frame completion, no counter increment, or no stable window.
A recovery test may allow errors during the invalid epoch, but error and resynchronization counters should remain unchanged during a clean persistence window. This distinguishes expected disruption from unstable recovery.
Use more than one view
A framed stream supports several oracles. A forward model checks exact output shape, and its state follows the DUT reset. The inverse model consumes RTL output and checks whether it recovers the original payload. An RTL loopback checks that both production directions interoperate across their real interfaces and reset domains, but common-mode errors can still round-trip.
The same verification flow still applies, but the scenarios are chosen around the state owned by the protocol: boundary timing, lock acquisition, unlock behavior, buffered data, sideband alignment, and recovery after local reset.
Make recovery a measurable contract
Resynchronization is an explicit contract between receiver behavior and verification, not a universal state machine. The receiver invalidates stale state, reacquires from live input, and marks output trust; the source retains its sequence, and the checker retains its memory. Making invalidation, survival, and reacquisition explicit turns recovery into measurable protocol behavior and prevents a local disturbance from becoming a permanent system failure.