Skip to main content

Coverage Closure

The CDV Loop ends with "repeat until signoff targets met" — the question this page actually answers. Closure isn't a single event; it's a process with its own predictable, nonlinear shape, and a real decision at the end of it that a coverage percentage alone never makes.

The closure curve isn't linear​

Coverage % rising quickly from broad, easy stimulus early on, then flattening near 100% as only hard corner cases remain, one at a time

Early in a project, broad directed and constrained-random stimulus closes large gaps fast — basic connectivity, common operating modes, the scenarios almost any reasonable test touches. What's left after that flattens the curve: corner cases, rare timing windows, hard-to-reach state combinations — each remaining hole needing its own targeted constraint refinement, directed test, or formal property, for shrinking return per hole. Budgeting the same rate of progress for the last 5% as the first 50% is a scheduling mistake made from misreading this shape, not a coverage problem.

Not every hole is the same kind of hole​

A remaining gap in a coverage report falls into one of two real categories, and treating them the same is the single most common closure mistake:

  • A genuine hole — a legal, reachable scenario the test suite simply hasn't hit yet. This has to be closed before signoff: refine constraints, add a directed test, or explain via formal why simulation alone can't reach it.
  • An illegal or unreachable bin — a combination that structurally can't happen given the design's actual constraints (an FSM transition arc that's architecturally impossible, a cross combination Functional Coverage Strategy already flagged as worth excluding). This doesn't get "closed" by testing harder — it gets waived, with the exclusion documented.
A waiver without a written justification is just a hidden hole

Every waiver should state explicitly why the excluded case can't happen or doesn't matter — not just that it was excluded. An undocumented waiver looks identical to a genuine hole someone quietly decided to stop worrying about, and six months later nobody, including the person who wrote it, can tell the difference.

A written justification alone isn't quite the whole safeguard, either — in practice a waiver is also a formal decision, not a unilateral one: the verification engineer proposing it and the design engineer who understands whether the excluded case is really structurally impossible both need to sign off, since only the design side can confirm a scenario the RTL's own structure genuinely can't produce.

Naming the difference in code: ignore_bins vs. illegal_bins​

SystemVerilog gives the "unreachable bin" category from above two distinct keywords, and mixing them up is a common, real mistake:

coverpoint mode {
ignore_bins reserved_mode = {3'b111}; // excluded from the % denominator; silent if ever hit
illegal_bins invalid_state = {3'b101}; // excluded from the % denominator; flags an error if ever hit
}

ignore_bins removes a value from the coverage percentage's denominator entirely — hitting it (if it somehow does happen) raises no error, it's simply not counted either way. illegal_bins also removes the value from the denominator, but additionally asserts that hitting it during simulation is itself a bug worth flagging — the value isn't just uninteresting, it should be structurally impossible. Using ignore_bins for a value that's actually illegal silently hides a real design bug if it ever fires; using illegal_bins for a value that's merely uninteresting (but legal) turns a harmless scenario into a false failure the moment a test happens to hit it.

Signoff is a decision, not a threshold​

It's tempting to treat "95% functional coverage" as a finish line. It isn't one, and treating it as one is a real, common mistake: coverage signoff is an engineering decision based on evidence, risk, and confidence — not an automatic trigger fired by a percentage. A project can reasonably sign off at 97% with every remaining gap genuinely, individually justified and documented. Another project hitting 99% with a handful of unexplained, unwaived holes in a safety-critical path has less real confidence behind that higher number. The percentage is evidence toward the decision, not a substitute for making it.

For a signoff decision to be defensible rather than arbitrary, the criteria need to be set before the project reaches the end, not invented under schedule pressure once it does: which coverage targets map to which spec requirements, what counts as acceptable residual risk, and what evidence (a waiver's written justification, a formal proof, a passing regression) is actually required to call a specific item closed. A later section covers exactly this decision in full, combining coverage with the other signals — bug-discovery rate, regression pass rate — that a coverage percentage alone can't see.

What's next​

Coverage-driven verification's iterative loop, both flavors of coverage, and the closure process are now covered end to end. Section C turns to a fundamentally different technique for gaining confidence in a design — one that doesn't sample stimulus at all: formal verification.