Physical defects, modeled faults, errors, and failures are different layers
Objective: What exact modeled target, activation, propagation path, protocol edge, observation, denominator, and unsupported silicon claim define “Physical defects, modeled faults, errors, and failures are different layers”?
A defect is a physical deviation, a fault is an abstract model, an error is an incorrect internal state, and a failure is externally unacceptable behavior; one defect may map to several faults or none in a chosen model. Design for testability changes a design so manufactured instances can be controlled, observed, classified, and debugged under a declared test protocol. The reasoning chain always names the functional specification, inserted test structure, test mode and clock/reset sequence, fault or defect model, generated stimulus, observation point, expected response, comparator or tester decision, and coverage denominator. A passing pattern set is evidence about modeled targets under exact assumptions; it is never automatic proof that silicon is defect-free.
The local DFT contract is “Every test claim names physical risk, modeled fault universe, activation and propagation assumptions, observation rule, and external pass/fail contract.” Its invariant is “Detection of a modeled fault requires a good/faulty response difference at a declared observation under the applied protocol.” First solve a small netlist or memory instance by hand: activate one modeled fault, justify every implication, propagate a distinguishable effect to an observation point, and account for capture and unload timing. Then compare automation against the hand oracle. The failure boundary “A 99% stuck-at result does not say 99% of all possible physical defects are detected.” stays explicit because structural coverage, pattern simulation, physical timing, tester application, diagnosis, yield, reliability, and field quality are separate evidence layers.
Detection of a modeled fault requires a good/faulty response difference at a declared observation under the applied protocol. The invariant applies only to the named design revision, test structures, protocol, clocks, libraries, fault universe, constraints, modes, patterns, and simulation or tester assumptions. It does not by itself establish unmodeled-defect coverage, defect level, yield, escape rate, lifetime, field reliability, or production economics.
Select one physical mechanism and one abstraction such as stuck-at or transition. At derivation step 1, retain the fault identity, good and faulty values, justification or propagation condition, cycle/edge, scan cell or memory address, masking state, expected observation, and the exact checker.
Construct good and faulty circuit behaviors under identical stimulus. At derivation step 2, retain the fault identity, good and faulty values, justification or propagation condition, cycle/edge, scan cell or memory address, masking state, expected observation, and the exact checker.
Propagate a differing value to a sampled output and classify detection. At derivation step 3, retain the fault identity, good and faulty values, justification or propagation condition, cycle/edge, scan cell or memory address, masking state, expected observation, and the exact checker.
A bridge makes an internal node wrong, but the output is masked. Is the applied pattern detecting it? Before revealing the trace, predict activation, propagation, capture edge, observable signature, coverage classification, and one physical or tester risk.
- The physical defect causes an internal error in this case. At trace step 1, record mode, clock/reset event, stimulus bit or operation, internal good/faulty state, response channel, expected comparison, and accumulated status.
- No good/faulty difference reaches the sampled output. At trace step 2, record mode, clock/reset event, stimulus bit or operation, internal good/faulty state, response channel, expected comparison, and accumulated status.
- Under the declared observation rule, the pattern does not detect it. At trace step 3, record mode, clock/reset event, stimulus bit or operation, internal good/faulty state, response channel, expected comparison, and accumulated status.
Result: The pattern is non-detecting for that modeled observation. Accept the result only after structural audit, independent pattern simulation, coverage reconciliation, functional equivalence or mode isolation, relevant timing/power/physical checks, format conversion checks, and a targeted injected fault that fails at the expected cycle and observation point.