Timing, Setup/Hold & Metastability
The previous page described flip-flop behavior in ideal terms: the clock edge arrives, D is sampled, Q updates. Real silicon doesn't work quite that cleanly — gates have physical propagation delay, signals need time to settle, and a flip-flop sampled at exactly the wrong instant can produce an output that is, for a while, neither a valid 0 nor a valid 1. This page covers the timing rules that keep real sequential circuits reliable, and what happens when those rules are broken.
Setup time and hold time
A flip-flop doesn't sample D for free at an infinitely precise instant — internally, the master latch needs D to already be stable for some time before the clock edge, and needs it to stay stable for some time after, in order to reliably latch the correct value.
- Setup time (
t_su) — the minimum timeDmust be stable before the active clock edge. - Hold time (
t_h) — the minimum timeDmust remain stable after the active clock edge.
The hatched region straddling the rising edge is the forbidden window: t_su before the edge, t_h after it. D must not change anywhere inside it.
Together, t_su and t_h define a small forbidden window straddling the clock edge during which D must not change. As long as the circuit driving D guarantees it stays outside that window, the flip-flop is guaranteed to capture a clean, correct value. A setup violation (D changes too close before the edge) or a hold violation (D changes too soon after the edge) both risk the same failure mode: metastability, covered below.
Clock-to-Q delay
Clock-to-Q delay (t_CQ) is the time between the active clock edge and the flip-flop's output actually reflecting the newly sampled value — the flip-flop's own internal propagation delay. This matters for timing closure between chained sequential stages: in a design with two flip-flops separated by combinational logic, the signal has to leave the first flip-flop (t_CQ), propagate through all the intervening combinational gates (t_combinational), and arrive at the second flip-flop with enough margin to satisfy its setup time — all within one clock period:
t_clock_period ≥ t_CQ + t_combinational + t_setup(next stage)
This inequality is the entire basis of maximum clock frequency: the fastest a synchronous design can run is bounded by its slowest such path (the critical path) between any two flip-flops. Faster clock, less time available for combinational logic in between — which is exactly why deeply pipelined designs (many flip-flop stages with little logic between each) can run at much higher clock frequencies than a design that crams a lot of combinational work between consecutive flip-flops.
Clock skew
The timing-closure inequality above quietly assumes both flip-flops see the clock edge at the same instant. In real silicon they don't: the clock signal has to physically route to every flip-flop, and different routes have different wire lengths and buffer delays. Clock skew is the difference in clock-edge arrival time between two sequential elements that are supposed to be on the same clock.
Skew isn't automatically bad — its effect depends on direction. If the receiving flip-flop's clock edge arrives later than the launching flip-flop's (positive skew, in the direction of data flow), that extra delay effectively adds to the time available for the combinational logic in between, which helps meet setup time — but it eats directly into the receiving flip-flop's hold-time margin, since data now has less time after its own edge before the receiving edge arrives. Negative skew does the reverse: it tightens the setup margin while giving hold more room. Because a single skew value can't help both timing checks at once, real clock-tree design is a deliberate balancing act, not just "make the clock arrive everywhere as simultaneously as possible."
Metastability
If D changes inside the forbidden setup/hold window — often because it's an asynchronous signal (one not derived from, or synchronized to, this flip-flop's own clock, such as a button press or a signal crossing in from a different clock domain) — the flip-flop's internal feedback loop can be driven to a voltage level that is neither a valid logic-0 nor a valid logic-1: a genuinely indeterminate, unstable state called metastability.
A metastable flip-flop will eventually resolve to a valid 0 or 1 — the feedback loop's own gain pulls it toward one rail or the other — but how long that takes is not bounded, and which value it resolves to is not predictable. Left with too little time to resolve, a metastable output can propagate downstream as a mid-rail voltage that different gates interpret differently, causing different parts of a circuit to disagree about what value was actually sampled — a failure mode that's rare per-event but can happen on any asynchronous input, on any clock edge, for the entire operating life of the chip.
This isn't a design flaw that can be engineered away entirely — it's a fundamental consequence of feeding an analog, continuously-variable signal into a circuit built on the assumption of two discrete states — but it can be managed down to an acceptably low failure rate. The standard technique is a synchronizer: chaining two (or more) flip-flops in series on the receiving clock domain, feeding the asynchronous signal only into the first one.
The first flip-flop is the one that might go metastable, but it's given a full clock period to resolve before its (by-then almost certainly valid) output is sampled again by the second flip-flop. Each additional synchronizer stage exponentially reduces the probability that metastability survives long enough to propagate further — two stages is the conventional minimum for reliable designs, with three used in higher-frequency or higher-reliability systems. The key discipline this technique depends on: only ever feed an asynchronous signal into the first flip-flop of a synchronizer chain, never directly into ordinary logic — asynchronous inputs anywhere else in a synchronous design are exactly the scenario setup/hold time exists to warn against.
What's next
With single-bit storage and its timing rules established, the next page scales up from a single flip-flop to registers and shift registers — groups of flip-flops that store and move multi-bit values as a unit.