Skip to content
VLSI Mentor

UART · Module 15

Error Injection and Corrupted-Frame Testing

Six injected faults driven into a receiver, the measured detection matrix showing two that raise no error status at all, and a glitch sweep locating the exact window in which a spike is visible.

Injecting an error is easy. Proving that something noticed is the work, and the two are often conflated: a suite that injects six fault kinds and passes has demonstrated that it can produce six waveforms, not that six failures are detectable.

This chapter drives each injected fault into a receiver and records what reports it. Two of the six raise no error status at all — and the reasons are different, instructive, and both correct behaviour.

1. The Six Faults, and What Each One Is For

The injector is the one built in Chapter 14.2: one enumerated selector, six kinds, each mapped to a requirement from Chapter 14.1 §2.

SelectorWhat it does to the wireRequirement
ERR_NONEnothing — the control case—
ERR_PARITYinverts the parity bitR5
ERR_STOPholds the stop interval at SPACER4
ERR_SHORT_STOPhalf a stop bit, then a new startR4
ERR_GLITCHa narrow spike inside a data bitR6
ERR_BREAKholds SPACE far past a frameR7

ERR_NONE is not filler. It is the control: without it, a suite in which everything reports an error looks identical to a suite that is working.

2. The Detection Matrix

Each fault driven into the receiver of Chapter 14.4, 8E1, one frame each, carrying 0xA5:

Azvya Education Pvt. Ltd.VLSI Mentor
Snippet
  fault            frames  data_ok  parity_err  framing_err
  --------------   ------  -------  ----------  -----------
  NONE                  1      yes           -            -
  PARITY                1      yes         YES            -
  STOP                  1      yes           -          YES
  SHORT_STOP            2      yes           -            -
  GLITCH                1      yes           -            -
  BREAK                 1      yes           -          YES

Three rows behave as a status-register-based test would expect. Two do not, and they are the interesting ones.

3. The Two That Raise No Error

ERR_SHORT_STOP — detected by counting, not by a flag

Look at the frames column: 2, where every other row is 1.

The fault truncates the stop bit to half a bit and then drives a new start. The receiver finishes its frame normally — correct data, legal stop, no error — and then sees a falling edge where idle should be, and begins framing a second character out of what follows.

Azvya Education Pvt. Ltd.VLSI Mentor
Snippet
  SHORT_STOP            2      yes           -            -

No status bit reports this, and none should: the first frame genuinely was well-formed. What is wrong is that one frame was sent and two were received, which is a property of the stream, not of any frame in it.

The detection is arithmetic: frames observed must equal frames driven. That is a scoreboard check (14.5) and it is the only thing in the environment that can see this fault.

ERR_GLITCH — not detected, and correctly so

Azvya Education Pvt. Ltd.VLSI Mentor
Snippet
  GLITCH                1      yes           -            -

One frame, correct data, no errors. The spike happened and changed nothing.

That is not a missed detection. It is Chapter 5.4's subject measured from outside: a receiver samples each bit once, at the centre, and a disturbance that does not cover the sampling instant is invisible by construction. Whether a glitch matters is entirely a question of where it sits.

A flowchart showing how each of the six injected UART faults is detected. An injected fault is applied to the line and the first question is whether it changes the value sampled at a bit centre. If it does not, as with a glitch away from the sampling instant, nothing detects it and nothing should. If it does, the next question is whether the resulting frame is still well formed. If the frame is malformed, a status bit reports it: a parity error for an inverted parity bit, a framing error for a stop interval held at space, and a framing error again for a break. If the frame is still well formed but the stream has changed, as when a short stop produces a spurious second frame, no status bit applies and only a scoreboard comparing frames driven against frames observed can detect it.noyesnoyesInjected faulton the lineChanges asampled bit?Nothing detectsit — and nothingshouldFrame stillwell formed?A status bitreports itOnly the frame COUNTchangedOnly ascoreboard seesit
Figure 1 — how each injected fault is detected, and by what. Three end at a status bit, one at a frame count and one at nothing at all. The branch that matters is on the left: a fault that leaves every frame well-formed cannot be reported by any per-frame flag.

4. Locating the Glitch Window

"A glitch matters if it covers the sampling instant" is a claim, and it is measurable. A 6%-wide spike was swept across a data bit in 5% steps, and the byte checked each time:

Azvya Education Pvt. Ltd.VLSI Mentor
Snippet
  glitch start (fraction of a bit) -> byte corrupted?
    0.00  ->      clean
    0.25  ->      clean
    0.35  ->      clean
    0.40  ->      clean
    0.45  ->  CORRUPTED
    0.50  ->      clean
    0.55  ->      clean
    0.75  ->      clean
    0.90  ->      clean
  corrupting window: 0.45 .. 0.45 of a bit

One position out of nineteen. A spike starting at 0.45 spans 0.45 to 0.51 and therefore covers the sample at 0.50; every other placement misses it.

5. What the Waveforms Look Like

Injected parity error

12 cycles
A timing trace of an eight-bit even-parity frame carrying A5 with an injected parity error. The line begins at mark and falls for the start bit. The eight data bits follow least significant first, carrying the value A5 correctly and untouched by the injection. The parity slot, which should carry a zero because A5 contains four ones and even parity therefore needs no correction, instead carries a one. The stop bit returns to mark and is legal. The receiver delivers the byte A5 correctly and raises its parity error flag, because the specification requires the byte to be delivered regardless of the parity verdict.flaggedflaggedparity slot invertedparity slot invertedbyte still deliveredbyte still deliveredintervalidlestartd0d1d2d3d4d5d6d7parstoprx lineexpected101010010101parity errt0t1t2t3t4t5t6t7t8t9t10t11
Figure 2 — an injected parity error, 8E1 carrying 0xA5. The data bits are untouched and arrive correctly; only the parity slot is inverted. The byte is still delivered, which is the receiver's documented behaviour, and the parity flag is what carries the verdict. The `expected` row is the line a correct 8E1 transmission of 0xA5 would have produced; it differs from the driven line in the parity slot and nowhere else.

Injected framing error

11 cycles
A timing trace of an eight-bit frame with an injected framing error. The start bit and the eight data bits are driven correctly, carrying the value 3C. At the stop interval, where the line must return to mark, the injector holds it at space instead. The receiver samples the stop interval, finds space where mark was required, and raises its framing error flag. The data bits were unaffected, so the byte 3C is still recovered and delivered alongside the error verdict.framingframingSPACE where MARK is requiredSPACE where MARK isrequiredintervalidlestartd0d1d2d3d4d5d6d7stoprx lineexpected10001111001frame errt0t1t2t3t4t5t6t7t8t9t10
Figure 3 — an injected framing error. The stop interval is held at space instead of mark. The data bits are again untouched and the byte is delivered; what the receiver reports is that the frame did not end the way a frame must. The byte 0x3C is still delivered alongside the error verdict.

6. Verification

Inject a control. ERR_NONE proves the environment is not reporting errors that were never injected. A suite where every frame raises something is indistinguishable from a broken checker.

Check the frame COUNT, not only the frame contents. ERR_SHORT_STOP produces a well-formed frame and a spurious extra one; nothing per-frame can see it.

Do not require corrupted frames to be discarded. Every row of the matrix delivers its byte, deliberately. A test asserting rejection fails a correct receiver.

Sweep a positional fault; never inject it at one offset. The glitch damages at 1 of 19 positions. A fixed-offset test passes on a receiver with no noise rejection whatever, 95% of the time.

Map each fault to the mechanism that detects it, and expect some to map to nothing. Two of six are undetectable by status bits, and both for good reasons. A detection matrix with a tick in every cell has usually been written by choosing faults the status register already covers.

7. Debugging

8. Understanding Check

9. Summary

Injecting a fault is not the same as proving it is detected, and the detection matrix is how the difference is made visible.

Six faults: three report a status bit, one reports only as a frame count, one reports nothing, and one is the control.

Every fault delivers its byte, which is the receiver's documented behaviour and would fail a test written to expect rejection.

ERR_SHORT_STOP is a property of the stream, not of a frame — one driven, two observed — so only a scoreboard can see it.

ERR_GLITCH damages at 1 of 19 swept positions, a window exactly as wide as the spike, because a single sample is a point. A fixed-offset glitch test passes 95% of the time on a receiver with no noise rejection at all.

A detection matrix with a tick in every cell is suspicious: it usually means the faults were chosen to match the status bits that already exist.

10. What Comes Next

Chapter 15.5 applies the same treatment to the stresses that are not single-frame events: deliberate baud error, reset asserted mid-traffic, and the FIFO boundaries — including the one that hid a real defect through an entire verification suite.

Browse the full path on the UART tutorials index. For the injector these faults come from, read back to Chapter 14.2.

Continue learning

Where this fits

Part of the UART curriculum.