AXI clock-domain-crossing bridge
Why
When two parts of a chip run on different clocks, data crossing between them can be corrupted in ways that show up rarely and at random. Those are the bugs that ship. Proving the crossing is safe is the whole job.
How
I designed the bridge, sized its safety margin from a failure-rate target instead of the usual rule of thumb, and then built two independent testbenches to break it: an open-source one and a full industry-style one on a commercial simulator. The design passed with every behaviour on the checklist seen at least once and zero failures.
What came out
100%, functional coverage, zero failures, on two independent testbenches.
What broke
Three defects in the design and one in the test. A loop between the FIFO status flags and the pointer logic that never settled, fixed by registering the flags. A sampling race that missed a handshake signal. A file the two open-source simulators accepted and the commercial one rejected, for a declaration-order rule that neither open tool enforces. And a coverage bin that turned out to be labelling a valid address as unmapped, which was a bug in my test, not the design.