SPI · Module 1
Master, Slave, and Signal Ownership
Which device is allowed to drive SCLK, MOSI, MISO and CS at each instant, why a shared return line can carry only one driver, and why signal ownership is an electrical question separate from what the transferred bits mean.
Chapter 1.1 ended with an interface: one device owns the clock and the selection, data has a dedicated line in each direction, and a peripheral is chosen by asserting its select line. That sentence quietly assumed something it never established — that for each of those wires, somebody in particular is allowed to drive it, and everybody else is not.
That assumption is the whole of this chapter, and it is not a formality. A logic output is not a variable that several pieces of code may assign. It is a transistor structure physically connected to a copper net. Two of them driving opposite values onto the same net is not a disagreement the protocol resolves later; it is a short between a supply and a ground through two output stages, happening in real time, on your board.
So before shift registers, before full duplex, before a single mode: who is allowed to drive each wire, and when?
1. The Question a Shared Wire Forces
Take the simplest possible arrangement — one master, one slave, four wires — and ask what has to be true for it to work at all.
Each wire is a net with at least one driver (an output stage actively forcing the net high or low) and at least one receiver (an input sampling it). For the net to carry information, exactly one driver must be active on it at any moment when the value matters. Not "usually one." Exactly one.
This is a stronger requirement than it first appears, because it has to hold not just during a transfer but at every instant in between — while the bus is idle, while the master is switching from one peripheral to another, during reset, and in the moments just after a device is selected or released. Every one of those is a moment where a second driver could appear, and the protocol has nothing to say about it afterwards. The rule has to be respected by construction.
2. Master, Slave, and the Other Vocabulary
One device sets the pace of an SPI exchange: it generates the clock, decides when a transfer starts and ends, and selects which device is being addressed. Everything else on the link responds. Those two roles are conventionally called master and slave.
Many current specifications, vendors and teams write controller and peripheral for exactly the same two roles, and you will meet both vocabularies — sometimes in the same design, where a datasheet says controller/peripheral while the RTL port names say master/slave. The mapping is one-to-one: master ↔ controller, slave ↔ peripheral. This curriculum uses master and slave because the majority of the parts and register maps you will actually read still do, and consistency matters more here than fashion.
What matters technically is that the role is not a label — it is a statement about which drivers a device owns. Everything in this chapter follows from that.
3. The Ownership Map
Here is the whole answer for a conventional single-slave link, before the reasoning behind it.
Read the arrows, not the names. Three signals leave the master and arrive at the slave. One leaves the slave and arrives at the master. That single reversal is where all the interesting engineering is, and the rest of this chapter earns each direction rather than asking you to remember the picture.
4. SCLK — the Master's Timing Reference
Driven by the master. Received by the slave.
This is not a convention that could plausibly have gone the other way. Chapter 1.1 established that SPI transmits its timing rather than asking both ends to agree on a rate in advance, and that the master is the device that decides when a transfer happens. Put those together and the master must be the one generating SCLK: the device that chooses when an exchange occurs is necessarily the device that supplies the edges defining it. A slave that generated its own clock would be deciding when it is spoken to.
Two qualifications keep this accurate.
Owning SCLK does not mean driving it continuously. In most implementations SCLK only toggles while a transfer is in progress and sits at an inactive level in between. The master still owns the net the entire time — it is the only device with a driver on it — but ownership and activity are different things, which §10 develops properly.
The inactive level is configuration, not a constant. Whether SCLK rests high or low between transfers is one of the two configuration bits that define an SPI mode, and it must match what the device expects. Which level, which edge launches, which edge captures, and how the four modes fall out of two bits is Module 3, and deriving any of it here would be answering a question you have not been given yet.
5. MOSI — Direction, Not Meaning
Driven by the master. Received by the slave.
The name expands to master out, slave in, and that expansion is the complete content of the name: it tells you which device has the driver and which has the receiver. It tells you nothing else.
In particular it does not make MOSI a write channel. What actually travels on it is whatever the device's transaction format puts there — an opcode, an address, a register index, a mode byte, padding while the master waits for a response, or genuine write data. A flash read command is issued on MOSI and returns nothing on MOSI at all; the useful data comes back on the other wire. Calling MOSI "the write line" would make that ordinary transaction sound like a contradiction.
Hold the discipline that Chapter 1.1 introduced: SPI specifies signalling far more strongly than it specifies meaning. MOSI is a signalling fact. The meaning of the bits on it is a device fact.
6. MISO — the Line the Master Does Not Drive
Driven by the selected slave. Sampled by the master.
This is the one reversal in the figure, and it is the only signal in a conventional SPI link whose driver is not permanently assigned to one device. With a single slave that distinction is easy to miss, because there is only one candidate driver and it can simply drive all the time. The moment a second slave exists, the picture changes completely.
On a typical multi-slave board, SCLK, MOSI and MISO are shared nets and each slave gets its own select line. Sharing SCLK and MOSI is harmless — the master is still the only driver on them, and an unselected slave simply ignores what it receives. Sharing MISO is not harmless, because every slave connected to it has an output stage on that net. If each one drove whenever it felt like it, the net would have several active drivers at once and would carry nothing trustworthy.
So the rule that makes a shared return line possible is an ownership rule: a slave may drive MISO only while it is selected, and must release the net otherwise. Releasing means switching its output stage off entirely — presenting a high impedance to the net rather than a logic level, so the net is left free for whoever legitimately owns it. An unselected device is not driving a quiet zero; it is not driving at all.
You now have the principle, which is what the rest of Module 1 needs. How a slave implements that release — the output-enable logic, the exact moment it must let go relative to the clock and the select edge, and what happens in the overlap if it lets go too late — is the subject of Module 8, and the RTL for it is Module 14. The principle is: one net, one owner, enforced by selection.
7. CS — Selection and the Transaction Boundary
Driven by the master. Received by the slave.
It is tempting to read chip select as a simple enable bit, and that reading is too weak in two ways.
First, CS is how SPI addresses devices at all. Chapter 1.1 made the point that SPI transmits no device address — the master does not send "device 2," it asserts device 2's select line. Selection is physical, which is precisely why it is the mechanism that enforces MISO ownership in §6. The line that says you are being spoken to is the same line that says you may drive the return path.
Second, CS commonly marks the boundary of a transaction, not merely the fact that a device is enabled. Many devices treat the assertion of CS as the start of a new transaction, count the clocks that follow, and treat its deassertion as the end — resetting their internal position so that the next assertion starts cleanly from an opcode again. On such a device, a frame is not defined by how many bits were sent; it is defined by what happened between two CS edges. This is why a master that leaves CS asserted across what it thinks are two separate transactions can confuse a device that considers it one long one.
The convention is active-low, usually written CS_n (or SS_n, or nCS) — the line rests high and the master pulls it low to select. Treat that as a strong convention rather than a law: the polarity, the required setup before the first clock edge, the hold after the last, and the minimum time the line must be released between transactions are all device parameters, and they come from the datasheet. Module 2 builds that timing properly.
Finally, the scaling consequence. SCLK, MOSI and MISO can be shared across every device on the bus. CS generally cannot, because its entire job is to distinguish one device from the others. So N slaves conventionally means three shared signals plus N select lines — the arithmetic from Chapter 1.1, now with a reason attached rather than a diagram. The interesting failures that come with several devices — glitches on a select line, two selects asserted at once, a device releasing MISO too slowly — are Module 8.
8. Ownership Is Not Meaning
Two questions about the same wire have different answers and different owners, and keeping them apart is one of the more durable habits this curriculum can give you.
The electrical question: who is allowed to drive this net right now? The answer comes from the SPI topology and the selection state. It is the subject of this chapter, it is the same for every device on the bus, and violating it is a hardware fault.
The device question: what do the bits on it currently mean? The answer comes from the part's datasheet. It differs between a flash and a sensor on the same four wires, it changes from phase to phase within a single transaction, and getting it wrong produces wrong data rather than a damaged net.
The two are genuinely independent. MOSI is electrically the master's at every instant of a transfer, while what it carries migrates from opcode to address to padding to write data. MISO is electrically the selected slave's, while what it carries may be a status byte, register contents, flash data, an identification code — or nothing meaningful at all, because during the opcode and address phases the device has not yet been told what to answer. Those cycles still have a driver. They just do not have useful content.
9. What Two Drivers Actually Do
It is worth being concrete about why the ownership rule is not merely tidy.
A conventional SPI output is push-pull: it contains a device that can pull the net up toward the supply and another that can pull it down toward ground, and exactly one of them is on when the output drives. That structure is what makes SPI fast — a driven net moves quickly in both directions, with no pull-up resistor limiting the rise.
Now put two such outputs on one net and have them disagree. One is pulling the net up, the other is pulling it down. There is no arbitration, no negotiation and nothing clever in between: there is a conducting path from the supply, through one output stage, along the net, through the other output stage, to ground. The consequences follow from that and are worth stating carefully:
- The logic level becomes untrustworthy. The net settles at whatever intermediate voltage the two contending stages produce, which may land in the region where a receiver's answer is not defined. It may read high, it may read low, and it may differ between the two receivers on the same net.
- Current flows that the design did not budget for, through structures sized for driving a capacitive load rather than another driver. How much, and how long a part tolerates it, are device and condition dependent — a real reliability concern, and not something to convert into a dramatic claim about instant destruction. Consult the part's absolute-maximum ratings rather than a tutorial.
- Signal integrity on the rest of the bus suffers, because a contending net is drawing current in a way the power and return paths were not designed around.
The durable point is not the failure mode. It is this: a logic output cannot be treated as an abstract variable that several writers may assign. Software resolves concurrent writes with a rule; hardware resolves them with physics. An ownership protocol is what stands between the two, and on SPI that protocol is chip select.
10. Idle Is Not Ownerless
A common mental slip is to assume that when nothing is happening, nothing owns the wires. Ownership and activity are separate.
Between transactions, with no slave selected: the master still owns CS and holds it inactive — it is not that CS has no driver, it is that its driver is holding the deasserted level. The master still owns SCLK, holding it at the inactive level its configuration specifies, not toggling. The master still owns MOSI, holding whatever level its implementation leaves there — and note that this level is genuinely implementation-defined, so do not build an expectation on it. And MISO should have no active driver at all, because no slave is selected, which is the one case where a conventional SPI net legitimately sits with nothing driving it.
Separating who owns the driver from what level the net currently carries pays off twice later. In RTL it is the difference between a registered output value and an output-enable term — two different pieces of logic that fail in different ways. On a bench it is the difference between "this line is low" and "this line is being held low by somebody", which is frequently the question that actually identifies a fault.
11. Why an RTL Designer Cares
Ownership is the chapter where an interface becomes a port list. Everything above translates directly into port directions and output-enable logic, and it translates differently depending on which role the block plays.
An SPI master has sclk, mosi and cs_n as outputs driven by its own logic — the clock by its divider, MOSI by its transmit path, CS by its transaction control — and miso as a plain input it samples. All three outputs are unconditional: the master drives them whenever it is powered and out of reset, because nothing else on the bus can. There is no output-enable question anywhere in a conventional master, which is a large part of why a master is the easier of the two blocks to build.
An SPI slave reverses all of it. sclk, mosi and cs_n become inputs, and miso becomes the one output — and it is not an unconditional output. It is a tri-state output, which in RTL means two separate signals that are designed and verified separately: the data value to present, and the output enable that decides whether to present it at all. On an FPGA or in an SoC that pair is what reaches the I/O buffer, and getting the value right while getting the enable wrong produces a board that is electrically broken while looking functionally fine in a naive simulation.
That asymmetry — a master with three unconditional outputs, a slave with one conditional one — is the single most useful thing to carry out of this chapter into the design modules. The master's implementation is Module 13; the slave's, including the output-enable logic and exactly when it must assert and release, is Module 14.
The rule, in RTL
The entire ownership rule for MISO is one conditional drive. It is worth seeing, because the gap between "a slave drives MISO only while selected" and the hardware that enforces it is genuinely this small — and because the shape of it is what §11 means by a data value and an enable being two different things.
// Fragment: the output stage only. The bit being presented comes from the
// slave's shift register (Chapter 1.3); the complete slave, including where
// shift_msb comes from and the clocking it lives in, is Module 14.
module spi_miso_drive (
input logic cs_n, // active-low select, driven by the master
input logic shift_msb, // the bit this slave's register is presenting
output logic miso // tri-state: a VALUE and an ENABLE, not one signal
);
assign miso = (cs_n == 1'b0) ? shift_msb : 1'bz;
endmoduleThe testbench checks the half that a data-comparison test never would: that the line is genuinely released — not driven to a convenient zero — when this device is not selected, and that it stays released no matter what the register underneath is doing.
module spi_miso_drive_tb;
logic cs_n, shift_msb;
wire miso;
int errors = 0;
spi_miso_drive dut (.cs_n(cs_n), .shift_msb(shift_msb), .miso(miso));
initial begin
// Deselected: the line must be high-Z, NOT a driven level.
cs_n = 1'b1; shift_msb = 1'b1; #1;
if (miso !== 1'bz) begin $error("deselected but driving %b", miso); errors++; end
// Still deselected: changing the register must not reach the pin.
shift_msb = 1'b0; #1;
if (miso !== 1'bz) begin $error("deselected but driving %b", miso); errors++; end
// Selected: the presented bit reaches the pin, both polarities.
cs_n = 1'b0; shift_msb = 1'b1; #1;
if (miso !== 1'b1) begin $error("selected, expected 1, got %b", miso); errors++; end
shift_msb = 1'b0; #1;
if (miso !== 1'b0) begin $error("selected, expected 0, got %b", miso); errors++; end
// Released again on deselection — the transition that matters most.
cs_n = 1'b1; #1;
if (miso !== 1'bz) begin $error("not released on deselect, got %b", miso); errors++; end
if (errors == 0) $display("PASS: driven only while selected, high-Z otherwise");
else $display("FAIL: %0d errors", errors);
$finish;
end
endmodule module spi_miso_drive (
input cs_n,
input shift_msb,
output miso
);
assign miso = (cs_n == 1'b0) ? shift_msb : 1'bz;
endmodule module spi_miso_drive_tb;
reg cs_n, shift_msb;
wire miso;
integer errors = 0;
spi_miso_drive dut (.cs_n(cs_n), .shift_msb(shift_msb), .miso(miso));
initial begin
cs_n = 1'b1; shift_msb = 1'b1; #1;
if (miso !== 1'bz) begin $display("ERROR deselected but driving %b", miso); errors = errors + 1; end
shift_msb = 1'b0; #1;
if (miso !== 1'bz) begin $display("ERROR deselected but driving %b", miso); errors = errors + 1; end
cs_n = 1'b0; shift_msb = 1'b1; #1;
if (miso !== 1'b1) begin $display("ERROR selected, expected 1, got %b", miso); errors = errors + 1; end
shift_msb = 1'b0; #1;
if (miso !== 1'b0) begin $display("ERROR selected, expected 0, got %b", miso); errors = errors + 1; end
cs_n = 1'b1; #1;
if (miso !== 1'bz) begin $display("ERROR not released on deselect, got %b", miso); errors = errors + 1; end
if (errors == 0) $display("PASS: driven only while selected, high-Z otherwise");
else $display("FAIL: %0d errors", errors);
$finish;
end
endmodule library ieee;
use ieee.std_logic_1164.all;
entity spi_miso_drive is
port (
cs_n : in std_logic; -- active-low select, driven by the master
shift_msb : in std_logic; -- the bit this slave's register presents
miso : out std_logic -- 'Z' is the released state
);
end entity spi_miso_drive;
architecture rtl of spi_miso_drive is
begin
-- std_logic carries 'Z' as a value, so the release is expressible directly.
miso <= shift_msb when cs_n = '0' else 'Z';
end architecture rtl; library ieee;
use ieee.std_logic_1164.all;
entity spi_miso_drive_tb is
end entity spi_miso_drive_tb;
architecture sim of spi_miso_drive_tb is
signal cs_n : std_logic := '1';
signal shift_msb : std_logic := '1';
signal miso : std_logic;
begin
dut : entity work.spi_miso_drive
port map (cs_n => cs_n, shift_msb => shift_msb, miso => miso);
stim : process
variable errors : natural := 0;
begin
wait for 1 ns; -- deselected, register = 1
if miso /= 'Z' then
report "deselected but driving" severity error; errors := errors + 1;
end if;
shift_msb <= '0'; wait for 1 ns; -- still deselected
if miso /= 'Z' then
report "deselected but driving" severity error; errors := errors + 1;
end if;
cs_n <= '0'; shift_msb <= '1'; wait for 1 ns;
if miso /= '1' then
report "selected, expected 1" severity error; errors := errors + 1;
end if;
shift_msb <= '0'; wait for 1 ns;
if miso /= '0' then
report "selected, expected 0" severity error; errors := errors + 1;
end if;
cs_n <= '1'; wait for 1 ns; -- the transition that matters
if miso /= 'Z' then
report "not released on deselect" severity error; errors := errors + 1;
end if;
if errors = 0 then
report "PASS: driven only while selected, high-Z otherwise" severity note;
else
report "FAIL" severity error;
end if;
wait;
end process stim;
end architecture sim;Three notes on what this fragment does and does not establish. The value and the enable are separate: shift_msb is the data, cs_n is the enable, and §11's point is that these are designed and verified independently — a correct value with a wrong enable is an electrically broken board that a data test passes. The release must be tested explicitly, which is why the testbench checks 1'bz rather than merely checking the driven levels; a design that drove zero instead of releasing would pass a value-only test and contend on a real bus. And this is only the output stage — where shift_msb comes from, how it is timed against SCLK, and how a slave copes with a clock it does not own are Chapter 1.3 and Modules 14 and 15.
12. Why a Verification Engineer Cares
Ownership creates a class of checks that data comparison alone will never perform, and the reason is worth stating sharply.
Correct data with illegal ownership is still a design bug. A scoreboard that only compares expected against received bytes will happily pass a transfer in which two slaves were driving MISO and their values happened to agree, or in which a slave drove the net while unselected but nobody happened to be listening. The transaction "worked." The hardware is broken.
Simulation actively hides this. A tri-state net with two drivers resolves by the language's rules — to a defined value if they agree, to an unknown if they do not — and neither outcome is an error the simulator reports. Worse, a testbench that models a slave's MISO as a plain output rather than a properly enabled tri-state removes the symptom entirely, so the environment reports a clean run on a design that would contend on real silicon.
So an SPI environment has to check ownership as a first-class property, separately from data:
- Exactly one select is asserted at any moment a transfer is in progress — never two, and never none.
- Only the selected slave drives the return path, and an unselected slave's output enable is inactive.
- The return path has exactly one driver whenever the master samples it, and is not left contended or floating at a moment where its value is used.
- Observed direction matches the configured topology — a monitor that reconstructs a transfer should also confirm that the device it attributes the data to is the device that was actually selected.
These are ownership assertions, and they are cheap to write and disproportionately valuable. Building them properly — the interface model, the monitor that reconstructs a transfer from pins, and the assertions above — is Modules 16 and 17.
13. Why an FPGA Engineer Cares
The role an FPGA plays decides its pin directions, and the two cases are not mirror images in difficulty.
FPGA as master — the common case. sclk, mosi and one cs_n per attached device are ordinary outputs; miso is an ordinary input. Every pin direction is fixed at synthesis, nothing is bidirectional, and the I/O constraints are correspondingly simple. This is how an FPGA reaches its configuration flash, a converter, or a sensor.
FPGA as slave — the case that needs care. sclk, mosi and cs_n become inputs and miso becomes an output that must be released when the FPGA is not selected. In the fabric that means driving both a data signal and an output-enable signal into the I/O buffer, so the pin can present high impedance. If the design drives MISO unconditionally, the FPGA contends with every other device on that shared net for as long as the board is powered — a fault that no amount of functional simulation will show you, because it is not in the functional model.
There is a second consequence of being the slave, and this chapter deliberately only names it: as a slave, the FPGA does not own SCLK. The signal timing its transfers arrives from outside, unrelated to the system clock the rest of the design runs on, starting and stopping at moments the design does not choose. That is a clock-domain and I/O-timing problem decided at architecture time, and it is the subject of Module 15.
14. Common Misconceptions
15. Reason It Through
Work this before reading the answers. It is the shape of a real bring-up failure.
An FPGA is the SPI master for two devices on one board: a serial flash and an ADC.
SCLK,MOSIandMISOare shared nets reaching both parts; each part has its own select line,CS_FLASHandCS_ADC. The FPGA assertsCS_ADConly, clocks a transfer, and reads back a value that is not a plausible conversion result.
With only CS_ADC asserted, which device is allowed to drive MISO? The ADC, and only the ADC. Selection is what confers the right to drive the shared return path, so the flash — unselected — must have its output released. The ADC's is the one output stage that should be active on that net.
Now suppose the flash is driving MISO anyway, because its output enable is wrong. Which rule broke? The exclusivity rule from §6: one shared net, one owner, enforced by selection. Note the fault is not that the flash sent the wrong data. The flash has no business sending data at all here. It committed an ownership violation, not a content error.
Why can the master not trust the sampled value? Because the net no longer carries one device's output. It carries the result of two output stages contending, which settles at whatever voltage they produce between them — possibly a valid-looking level, possibly not, and not reliably either across temperature and supply. A value read off a contended net is not a wrong answer from the ADC; it is not an answer at all.
Why is this still an electrical problem in the case where both devices happen to drive the same bit? This is the part worth slowing down for. When both drive high, or both drive low, the sampled value is correct and the transfer looks like it worked — so the bug hides, and hides best on the data patterns you are most likely to test with. But the contention is real regardless of agreement: two output stages are switched on to the same net, and on the very next bit where they disagree you get a conducting path from supply to ground and an undefined level. The intermittency is not luck; it is data-dependent, which is exactly the property that makes such bugs survive bring-up and appear later in the field.
What should have caught it? In RTL: MISO's output enable is a distinct signal from MISO's value, and it must be gated by selection — a slave whose enable does not depend on CS is broken by construction, however correct its data path. In verification: the ownership assertions from §12 — at most one select asserted, and at most one driver on the return path at any sampled instant. Both are cheap. Neither is implied by a data scoreboard, which is precisely why "the bytes matched" is not a sufficient result.
16. Understanding Check
17. Summary
In a conventional SPI link the master drives SCLK, MOSI and CS, and the selected slave drives MISO. Three signals flow one way, one flows the other, and that asymmetry is the entire ownership model.
Those directions are statements about which output stage is switched on, not about what the transferred bits mean. MOSI is electrically the master's throughout a transfer while its content moves from opcode to address to padding to data; MISO is electrically the selected slave's while its content may be a register value, flash data, or nothing meaningful at all. The electrical question is answered by the topology and the selection state; the meaning question is answered by the device's datasheet. Keeping them apart is what lets you tell a wrong-data bug from a wrong-driver bug.
The rule that makes a shared bus possible is exclusivity: one net, one owner. SCLK and MOSI are safe to share because the master is their only driver. MISO is safe to share only because selection decides who may drive it and every unselected device releases the net. Break that and two push-pull outputs contend — an indeterminate level, unbudgeted current, and a fault that hides whenever the contending devices happen to agree.
Finally, ownership persists through idleness. With nothing selected the master still owns CS, SCLK and MOSI and holds them at inactive levels; only MISO legitimately sits undriven. Who owns the driver and what level the net carries are different questions, and in RTL they become different signals: an output value, and an output enable.
18. What Comes Next
This chapter answered who drives each wire. Chapter 1.3 — The Shift-Register Mental Model answers the next one: what hardware behaviour actually moves a bit out on one line while another bit arrives on the other, on the same clock edge. Ownership tells you which device has the driver; the shift-register model tells you where the bit it is driving came from and where the bit it receives is going. Chapter 1.4 then settles what full duplex really means, which is where the last of the MOSI-is-write intuition finally goes.
Browse the path on the SPI curriculum index, or revisit Why SPI Exists for the argument this chapter builds on. For the same ownership discipline applied where a bus is shared by design rather than by selection, see Manager, Subordinate and Interconnect; for a link that solves the driver problem with open-drain outputs and a wired-AND instead of exclusive selection, see Why I²C Exists.
Continue learning
Related tutorials
- Related topic
MISO Output Enable and Release
Asserting late costs a bit; releasing late puts two output stages on one wire. Why the enable is a register rather than a fast combinational path, how the gap requirement depends on the neighbouring device, why two identical slaves never contend, and an output stage verified in three HDLs against a slow and a fast peer.
- Related topic
USB vs SPI
SPI selects a peripheral with a wire routed at layout time and USB with an address the host assigned — so a chip-select contention is invisible to every slave (0 of 11) while a duplicate USB address is detected every time (274 of 274).
- Related topic
Bus Topologies and Daisy-Chain
What the four-wire model costs as devices are added: shared clock and data with one select per device, or a daisy chain that turns several peripherals into one long shift ring. Pin arithmetic, ownership consequences, and why chaining is a device property.
- Related topic
CS-to-SCLK and SCLK-to-CS Timing
Chip select has timing requirements of its own: the lead before the first clock edge, the lag after the last, and the minimum deselect between transactions. Why violating them breaks a transfer whose every SCLK edge was correct.
