Skip to content
VLSI Mentor

SPI · Module 8

MISO Contention and Multiple Slaves Selected

What two active drivers do to a shared net: why the level is undefined rather than wrong, how much current flows, why damage ranges from a corrupted bit to a destroyed output stage, and why contention can be detected but never implemented.

Chapters 8.3 and 8.4 were both about preventing one thing. This chapter is about what that thing actually is.

Two slaves are selected, both reach their data phase, and both enable their MISO drivers. One is driving high and the other low. What is on the wire?

The honest answer is nothing you can reason about digitally, and that is what makes this chapter different from every other in the track.

1. Two Drivers, One Net

A CMOS output stage driving high connects the pin to the supply through a conducting transistor. Driving low connects it to ground through another. Their on-resistances are small — typically tens of ohms.

Put one of each on the same net and you have connected the supply to ground through two transistors in series:

Azvya Education Pvt. Ltd.VLSI Mentor
Snippet
   V_supply ──[ A's pull-up, ~25 Ω ]──┬──[ B's pull-down, ~25 Ω ]── ground
                                      │
                                    MISO

Three consequences follow, and they are usually discussed in the wrong order.

The voltage is a divider, not a logic level. With equal on-resistances the net sits near half the supply — around 1.65 V on a 3.3 V bus. That is not a one and not a zero; it is in the forbidden band where a receiver's output is genuinely undefined.

Current flows, and it is not small.

Azvya Education Pvt. Ltd.VLSI Mentor
Snippet
   I = 3.3 V / (25 Ω + 25 Ω) = 66 mA

Sixty-six milliamps through output stages designed for a few milliamps of signalling current. That is the part people underestimate.

Nothing reports it. SPI has no bus-error mechanism (Chapter 4.1 §2). The master samples the undefined level, gets something, and proceeds.

2. What the Master Actually Samples

This is where contention stops being a clean abstraction.

A level near mid-supply is in the receiver's undefined region. What the master's input buffer does with it is not specified: it may read one, may read zero, may oscillate, and may do different things on different chips, temperatures and supply voltages.

Two practical consequences.

Contention does not reliably produce an obvious failure. If the two drivers happen to agree on a bit, the net is driven to a valid level by both and the data is correct. Contention corrupts only the bits where the two devices disagree — so a contending bus can pass a test whose data happens to be similar on both devices, and fail unpredictably on other data.

It is not deterministic across units. Two boards with the same fault behave differently because their input thresholds and drive strengths differ. That is the signature people describe as "one board works and one does not" when the real answer is that both are broken and one is closer to a threshold.

3. Seen as a Waveform

While both drive, the net has no value

10 cycles
Two slave output enables overlapping. While both are asserted the MISO net is shown as unknown. Before and after the overlap, one driver at a time produces defined levels, and at the end neither drives and the net is high impedance.both drivingboth drivingoe_aoe_bmisoXXt0t1t2t3t4t5t6t7t8t9
Figure 1 — an overlap between two drivers. While both enables are asserted the net has no defined value: the two output stages are fighting and the level sits between the logic thresholds. The X is the honest representation — not a third logic state, but the absence of a meaningful one.

4. The Damage, in Three Tiers

Contention is often described as though it always destroys hardware, or always merely corrupts data. Both are wrong; the outcome depends on duration.

Nanoseconds — a wrong bit. A brief overlap during a handover corrupts whichever bits were being sampled. No lasting harm; the current spike is short and the energy is negligible. This is by far the most common case and it presents purely as data corruption.

Microseconds to milliseconds — heat and supply disturbance. A sustained overlap — two devices selected for a whole transaction — draws tens of milliamps continuously. That is enough to warm the output stages measurably, and enough to disturb the supply rail on a board with modest decoupling, which can then upset other circuits. The symptom is often not on the SPI bus at all.

Continuous — destruction. A permanently mis-wired or mis-configured select (Chapter 8.1 §9) means the fight never stops. Output stages have a maximum current rating and an absolute maximum they survive briefly; continuous contention exceeds the first and approaches the second. Devices do fail this way, usually over hours or days rather than instantly, which makes the causal link easy to miss.

The practical reading: transient contention is a data-integrity problem and sustained contention is a reliability problem, and they need different responses. The first is fixed by turnaround timing; the second usually means something is wired or configured wrong.

5. The Fight, Drawn

A block diagram of MISO contention. Slave A drives the net high through its high-side transistor while slave B drives it low through its low-side transistor, forming a current path from supply to ground. The master's input samples the midpoint level.Slave Adriving HIGH — pull-up onSlave Bdriving LOW — pull-down onMISO net≈ half supply — neitherband≈ 66 mAsupply to ground,continuousMaster inputundefined — may read eithersourcessinksthrough bothsamples12
Figure 2 — two output stages contending. Slave A's high-side transistor and slave B's low-side transistor are both conducting, forming a low-resistance path from supply to ground through the shared net. The master's input sees the divider's midpoint, which is in neither logic band.

6. Why This Chapter Has No RTL

Deliberate, and for a reason that differs from every other RTL absence in this track.

The earlier absences were about scope — Chapter 4.1 described a specification's silence, and Chapters 5.4 and 6.5 described procedures performed by engineers. This one is different: contention is not a digital phenomenon at all.

Two drivers fighting is an analogue event whose outcome is a voltage determined by transistor on-resistances, supply, temperature and process. There is no RTL for it because RTL describes logic values, and the whole point is that the net has no logic value. A module that "implemented contention" would have to invent a digital answer to a question whose honest answer is that there isn't one.

What is buildable is everything around it: the hardware that prevents it (Chapters 8.1, 8.3 and 8.4 are all contention-prevention modules), and the verification machinery that detects it, which is §7.

The x in Figure 1 is the closest a digital model gets, and it is worth being precise about what it means: not a third logic state, but a marker meaning this model cannot tell you. That is exactly the right thing for a simulator to say here.

7. Detecting It in Verification

Contention is invisible in a naive testbench and trivially visible in a correctly built one. The difference is entirely in how the shared net is modelled.

The net must be wired, not multiplexed. Chapter 8.2 §6 made this point; here is why it matters so much. A multiplexer selecting one slave's output by chip select resolves what the real bus cannot — two drivers produce a clean value instead of a conflict, so the failure mode is structurally unreachable.

Azvya Education Pvt. Ltd.VLSI Mentor
spi_miso_bus.sv — a net that reports conflict instead of resolving it
   // Each slave drives z when not enabled. Two simultaneous drivers resolve
   // to X, which is the simulator saying "no defined value" -- the same
   // statement the real bus makes with a mid-supply voltage.
   wire miso;
   assign miso = slave0_oe ? slave0_do : 1'bz;
   assign miso = slave1_oe ? slave1_do : 1'bz;
   assign miso = slave2_oe ? slave2_do : 1'bz;

   pullup (miso);   // the board's resistor: defines the undriven level

   // Detect the CAUSE, not just the symptom. An X only appears when the two
   // drivers DISAGREE; if they happen to agree, the net is cleanly driven
   // and the contention is invisible in the data (§2). Counting enables
   // catches it either way.
   always_comb begin
       int n = slave0_oe + slave1_oe + slave2_oe;
       if (n > 1)
           `uvm_error("CONTENTION",
               $sformatf("%0d slaves driving MISO simultaneously", n))
   end

The comment on the second check is the important one. Watching for X is not sufficient, because contention with agreeing data produces a perfectly clean level. Counting enabled drivers catches every overlap, including the ones whose data happens to match — which are the overlaps that let a bug survive a regression.

Azvya Education Pvt. Ltd.VLSI Mentor
spi_contention.sva — the property, and the window it must cover
   // At most one driver, at every instant. Sampling only at SCLK edges would
   // miss an overlap that occurs between them -- and a turnaround overlap
   // (Chapter 8.4) is precisely an event between bit times.
   a_single_driver : assert property (
       @(posedge sys_clk) disable iff (!rst_n)
           $countones({slave0_oe, slave1_oe, slave2_oe}) <= 1)
       else $error("MISO contention");

   // At most one SELECT, which is the upstream cause. Catching it here names
   // the bug; catching it at the drivers only names the consequence.
   a_single_select : assert property (
       @(posedge sys_clk) disable iff (!rst_n)
           $countones(~cs_n_vector) <= 1)
       else $error("more than one slave selected");

Sampling on the system clock rather than on SCLK is deliberate: a turnaround overlap happens between bit times, so an SCLK-sampled assertion can step right over it.

Coverage must include the agreeing-data case, because that is the one that hides:

Azvya Education Pvt. Ltd.VLSI Mentor
spi_contention_cg.sv — cover the overlaps that do not show up as X
   covergroup spi_contention_cg @(posedge sys_clk);
       cp_drivers : coverpoint $countones({s0_oe, s1_oe, s2_oe}) {
           bins none = {0};
           bins one  = {1};
           bins two  = {2};      // must be reachable in a negative test
       }

       // When two drive, do they agree? Disagreement shows as X; agreement
       // is invisible in the data and is the case that survives regression.
       cp_agreement : coverpoint (s0_do == s1_do) iff (s0_oe && s1_oe) {
           bins disagree = {0};   // visible
           bins agree    = {1};   // INVISIBLE -- the dangerous bin
       }

       cp_duration : coverpoint contention_cycles {
           bins transient = {[1:4]};      // handover overlap
           bins sustained = {[5:$]};      // a selection bug
       }
   endgroup

8. Why an FPGA or ASIC Engineer Cares

Series resistors bound the damage. A 100 Ω resistor in series with each device's MISO output limits contention current to roughly 3.3 / (25 + 100 + 100 + 25) ≈ 13 mA instead of 66 mA — a five-fold reduction that converts a destructive fault into a survivable one. The cost is a slower edge into the net's capacitance, which at low SPI rates is free and at high rates is a real trade. On a board with several devices sharing MISO it is cheap insurance.

Drive strength matters in both directions. A lower drive-strength setting reduces contention current and slows edges. On a shared net with modest speed requirements, the lowest drive that meets timing is the right default — it is the same decision as series resistors, made in configuration rather than in components.

Never tie two outputs together "because only one is ever active". This is the recurring temptation, and it is the same error as sharing a select line (Chapter 8.1 §8). The design works until the assumption is violated by a reset sequence, a power-up ordering, or a firmware bug — and then it fails destructively rather than functionally.

Watch power-up ordering. Before a device is configured, its pins may default to outputs. Two devices powering up together can both drive MISO before either has been told not to. Pull-ups, series resistors and a deliberate reset sequence all help; assuming the problem away does not.

On an ASIC, contention on an internal bus is worse than on a board. There are no series resistors, the on-resistances are lower, and the current density in a narrow metal line can approach electromigration limits. Internal tri-state buses have largely been replaced by multiplexers for exactly this reason, and the same reasoning applies to any internal net you are tempted to share.

9. Failure Signature — Warm Device and Data That Depends on the Pattern

Symptom. A board with several SPI devices returns intermittently wrong data. One device is noticeably warm to the touch. The corruption depends on what is being read: some patterns come back clean and others do not, reproducibly, and the boundary between them looks arbitrary.

What the pattern dependence establishes, and it is the key clue. Data-dependent corruption with no timing dependence is not noise, not margin, and not a mode problem — all of those corrupt patterns indiscriminately. It is §2's signature exactly: contention corrupts only the bits where two drivers disagree, so a byte both devices would have driven identically arrives correct while one they differ on arrives wrong.

That single observation distinguishes contention from essentially every other failure in this track.

The warmth corroborates it. Tens of milliamps through an output stage is dissipation the device was not designed for. A warm SPI device with no other explanation is contention until proven otherwise.

Plausible mechanisms.

  • Two selects asserted at once — a decoder without an enable (Chapter 8.1 §11), a mask-based select driver with a software bug, or two devices sharing a select line.
  • A device that never releases MISO — an active-high select driven active-low, or a non-tri-state output.
  • Turnaround overlap (Chapter 8.4) — but that is transient and would not produce sustained warmth.

The discriminating observation. Measure the MISO net's voltage with a scope while the fault occurs. A level sitting near half supply is definitive — no correctly functioning digital net ever rests there, and no other failure mode produces it. If MISO shows clean rails, contention is eliminated and the pattern dependence needs a different explanation.

Then find which devices by measuring the select lines with the bus idle (Chapter 8.1 §9), remembering that "asserted" is each line's own active level.

Why the investigation goes wrong. Because intermittent, data-dependent corruption reads as a signal-integrity problem and the team reaches for termination and layout. Contention is not a signal-integrity problem — it is two devices both being correct about a bus they have been told, wrongly, that they own. The warmth is the clue that separates them and it is often noticed only after days of probing edges.

10. Common Misconceptions

11. Reason It Through

Work this before reading the answer.

A four-device SPI bus uses a 2-to-4 decoder with no enable for chip select — the arrangement Chapter 8.1 §11 warned about. All four devices work individually. The bus runs for months in the field. Then units begin returning with one specific device failed — always the same position in the design — while the other three still work.

What is happening, and why that device?

Start from the decoder. Without an enable, one output is always asserted, so one device is always selected. Between transactions, whichever code the index pins happen to hold selects a device, and that device drives MISO continuously.

Where is the contention? During a switch. The decoder moves from one output to another with no all-deselected state (Chapter 8.1 §11), so the outgoing device's driver and the incoming one's overlap for the turnaround interval the design never provides. That is transient contention on every single device switch — thousands or millions of times a day.

Why one specific device, though? Two effects compound, and this is the part worth reasoning through.

It is the one selected at idle. Between transactions the index pins rest at some value — often all-zeros after reset, or whatever the last transaction left. Whichever device that code selects is driving MISO all the time the bus is idle, which on a typical system is most of the time. Every other device's contention exposure is limited to switching events; this one's is continuous whenever another device is switched to.

It takes both sides of every fight. When the master switches away from the idle device, that device is the outgoing driver. When it switches back, that device is the incoming one. It participates in roughly twice as many overlaps as any other device on the bus.

Why months rather than immediately? Because each overlap is brief. The damage is cumulative — repeated current spikes stressing the output stage — so the failure is a wear-out mechanism rather than an immediate one. That is exactly why the causal link is so easy to miss: by the time a unit fails, the design has been "working" for months and the decoder is the last thing anyone suspects.

What would have revealed it before shipping? Three things, in increasing order of effort.

A multi-slave simulation with a wired MISO net would have flagged the overlap on the first device switch — §7's driver count, not the X, because the overlap is brief and the data often agrees.

A scope on MISO during a device switch shows the mid-supply level for the overlap duration.

Measuring supply current with the bus idle shows the constant draw of the permanently-selected device driving into whatever the net's other loads are.

The fix, and the lesson. The fix is a decoder with an enable, which restores the all-deselected state and removes both the continuous selection and the switching overlap. The lesson is that a design with no idle state has no safe state — and that a fault which is brief, intermittent and non-fatal per occurrence can still be fatal cumulatively, which makes "it works" a much weaker statement than it appears over a product's lifetime.

12. Understanding Check

13. Summary

Two active drivers on one net connect supply to ground through two conducting transistors. The result is not a wrong logic level but no logic level — a voltage near mid-supply, in the forbidden band, with roughly 66 mA flowing on a 3.3 V bus through stages designed for a few milliamps.

What a receiver reports from that level is unspecified, and varies with chip, temperature and supply — which is why two boards with the same fault behave differently.

Contention corrupts only the bits where the drivers disagree. Bits they agree on arrive correct, so a contending bus can pass a regression whose data happens to match.

The damage is a function of duration: nanoseconds corrupt a bit, microseconds warm the part and disturb the rail, and continuous contention destroys output stages over hours or days — cumulative wear-out, which is why the causal link is so often missed.

There is no RTL for contention, and for a different reason than this track's other absences: it is not a digital phenomenon. The net has no logic value, so there is nothing to implement. What is buildable is prevention — Chapters 8.1, 8.3 and 8.4 are all prevention modules — and detection.

Detection requires the net to be wired rather than multiplexed, and requires counting enabled drivers rather than watching for X, because agreeing data hides the overlap entirely.

On hardware, series resistors and low drive strength bound the current, power-up ordering deserves attention, and a mid-supply reading on MISO is the one measurement that settles the diagnosis outright.

14. What Comes Next

Contention needs two devices selected at once. Chapter 8.6 — CS Glitches and False Selection examines the most common way that happens without anyone intending it: a noise event on a select line that a device interprets as a frame. The chapter covers what a glitch does to a device's internal state, why the half-selected device it leaves behind is worse than an obviously broken one, and the glitch filter — genuinely distinct from a synchroniser — that rejects it, in all three HDLs.

Continue learning