Timing signoff proves the circuit is fast enough. Physical verification proves the layout can be manufactured (DRC), that it is the circuit you meant to build (LVS), that nothing is electrically unsafe such as a floating gate (ERC), and that the power grid and wires survive real current (IR drop and EM). A block can meet timing in every corner and still be unbuildable or fail in the field, so tapeout needs both gates.
DRC checks the layout geometry against the foundry manufacturing rules. LVS checks that the devices and connections extracted from the layout match the reference netlist. ERC checks for electrically unsafe connections, such as floating gates or untied wells, that can exist even when layout and netlist agree.
A runset, often called a deck, is the program IC Validator executes: layer assignments, database checks and every design rule coded as PXL functions. The foundry writes and qualifies it for a specific process node and version, and the design team runs it without editing the rules. Checking against the wrong node, the wrong version or a locally modified copy is a real way to tape out a violating layout.
LVS compares two netlists: the reference netlist the design was built from and a netlist IC Validator extracts from the layout geometry. It matches devices and their types and properties, how the device terminals connect into nets, and the ports at the top and at each equivalence point. It does not look at timing or rule spacing, only whether the layout is the same circuit.
The usual LVS failures are shorts, opens, missing or extra devices, and port or label mismatches. Shorts and opens come mostly from routing and ECO edits, device mismatches from wrong cell versions or wrong views at stream-out, and port problems from text labels. ICC2 can catch routing-level shorts and opens early; IC Validator gives the signoff answer.
LVS only asks whether the layout matches the reference netlist. If the reference itself contains an electrical hazard, such as an unused gate input left unconnected, the layout faithfully reproduces it and LVS passes. ERC checks the extracted circuit for hazards like floating gates, so it fails on exactly the case LVS cannot see.
Stream-out writes the finished layout as a GDSII or OASIS file, the format signoff tools and the foundry read. The file must contain the full layout: top-level routing and power, the real standard-cell and macro geometry merged in, metal fill, pin text, and every shape on the layer and datatype numbers the foundry expects. Anything missing or mis-mapped is invisible to signoff, so a clean check on an incomplete stream proves nothing.
Read `cell.RESULTS` (ICV) first; the guide calls it the starting point for analyzing a run. Its header says `RESULTS: CLEAN` (ICV) or `RESULTS: NOT CLEAN` (ICV) for DRC, and `LVS Compare Results: PASS | FAIL` (ICV) plus a DRC-and-extraction line for LVS. Then go to `cell.LAYOUT_ERRORS` (ICV) for DRC detail, `cell.LVS_ERRORS` (ICV) for LVS detail and `cell.sum` (ICV) for run statistics.
A standalone run is one shell command: `icv` (ICV), the layout file, its format, the top cell and the runset. For DRC that is `icv -i top.gds -f GDSII -c top drc_runset.rs` (ICV). For LVS you use the LVS runset and add the reference netlist with `-s top.sp -sf SPICE` (ICV). The runset, not a command option, decides whether the run is DRC or LVS.
IC Validator In-Design runs the IC Validator engine from inside ICC2 on the saved design library, through commands such as `signoff_check_drc` (ICC2), so you can find and fix violations without leaving implementation. A standalone run is the `icv` (ICV) command line on a GDS or OASIS file. In-Design is the fixing loop; standalone on the final stream is the signoff record.
Point ICC2 at the IC Validator installation, set the foundry runset with `signoff.check_drc.runset` (ICC2), save the block because IC Validator reads the on-disk data, and run `signoff_check_drc` (ICC2). Results go to the run directory as `block.RESULTS` (ICC2) and `block.LAYOUT_ERRORS` (ICC2), and the error data file `signoff_check_drc.err` (ICC2) is stored in the design library for the error browser and automatic fixing.
Filler cells fill the empty sites in standard-cell rows so that power rails, wells and implant layers run continuously and density rules on the base layers are met. The placement must be legal first: the guide says to confirm this with `check_legality` (ICC2) before insertion. After insertion, fillers must be connected to the power and ground nets with `connect_pg_net -automatic` (ICC2).
A decap filler is a capacitor between VDD and VSS that supplies local charge when nearby cells switch, which reduces dynamic voltage drop. A plain filler only keeps rails and wells continuous. Decaps are not free: each one leaks, and with modern thin gate oxides that leakage adds up, so at the finishing stage you place decaps where dynamic IR needs them and plain fillers elsewhere.
Chemical mechanical polishing flattens each metal layer, and it removes material unevenly when metal density varies across the die. Density rules check the fraction of each window covered by metal, with a minimum and a maximum, and often a limit on how much density can change between neighbouring windows. Metal fill adds floating shapes in empty areas so every window meets those limits.
Metal fill adds floating metal next to, above and below signal wires, and every piece adds capacitance. That changes the parasitics and so the delays, usually slowing paths. If you fill while timing is still moving, each timing fix disturbs the fill and each fill pass disturbs timing, so the ICC2 guide says the block should be close to meeting timing, with few or no DRC violations, before fill goes in.
An isolated via is a via with no neighbouring via close enough to meet the technology's requirement. Lithography and etch are tuned for vias that sit in a pattern, so a lone cut prints with more size variation and is more likely to come out resistive or open, and one open via on a signal net is a dead net. In ICC2 you set the search range per via layer and run `signoff_fix_isolated_via -check_only true` (ICC2) before you let the tool change anything.
IR drop is the voltage lost across the resistance of the power grid when current flows through it, V = I x R added up along the path from the pad or bump to each cell's power pin. The ground side does the same in reverse, so VSS at the cell sits slightly above zero. The cell therefore runs on less than the nominal supply, its drive current falls, and paths that were timed at the library voltage come out slower than signoff assumed.
Static IR drop uses each cell's average current over a cycle, so it shows the DC drop caused by grid resistance and is good at finding weak straps, missing vias and poor supply placement. Dynamic IR drop follows the current as it changes in time, when many cells switch together near a clock edge, so it catches short, deep dips shaped by decap, grid capacitance and the package. Run static first as a grid-quality check, then dynamic once placement, the clock tree and timing windows are real.
IR drop is acceptable when every loss the cell can see fits inside the voltage margin the library was characterised for. The rule is: grid drop (Vmax - Vmin on the supply net), plus ground rise, plus external supply variation, must be less than the gap between nominal VDD and the worst-case voltage used in the standard-cell library. If the slow corner is characterised at 0.72 V for a 0.80 V supply, everything together must fit in 80 mV.
EM signoff compares the current density in every wire segment, and the current per cut in every via, against the foundry's limits, and it can do that for three kinds of current: average, RMS and peak. Average current drives the slow drift of metal atoms that eventually opens a line, RMS tracks Joule heating, and peak guards against short high-current pulses. Static analysis only knows the average, dynamic analysis can check all three, and `perform emcheck` (RH) runs AVG, RMS, PEAK or all, with all as the default.
Taps are ideal voltage sources placed on the PG network to stand in for the pads, bumps or block pins that feed it; every drop in the rail analysis is measured from them. They are virtual models, not part of the design, so a tap only does something if it touches a PG shape on its layer. A tap with no conductive path to the supply network has no effect on the analysis, and `create_taps` (ICC2) warns about it with RAIL-305.
A missing via is a place where two PG shapes on different layers overlap but have no via in the overlap, and an unconnected pin shape is a PG pin that has no continuous physical path to an ideal voltage source. RedHawk Fusion finds both: set the options with `set_missing_via_check_options` (ICC2), save the block, then run `analyze_rail -voltage_drop static -check_missing_via -nets {VDD VSS}` (ICC2). The command reference says `-check_missing_via` requires `-voltage_drop`. Do it after the power structure is built and before `place_opt` (ICC2).
Read an IR map as a picture of current flowing out from the supply points: the drop should grow smoothly from each tap toward the far and busy regions. The RedHawk manual lists what to look for: how many hotspots there are and whether they are where you expect, unexpected colour jumps that suggest missing straps or connections, unexpected black areas that mean missing data or connections, and whether the colour change from source to hotspot makes sense. In ICC2, load the map with `open_rail_result` (ICC2) after a RedHawk Fusion run.
IR drop is current times resistance, and the current comes from power calculation. If the libraries, activity or timing data behind the power numbers are wrong or missing, the currents are wrong, and a grid can look clean only because it is being fed too little current. So power is calculated and checked first, then the grid is extracted and analysed: `perform pwrcalc` (RH), `perform extraction` (RH), `perform analysis -static` (RH), or in ICC2 the rail library files and inputs are set before `analyze_rail` (ICC2).
ESD checks confirm that every pad has a low-resistance discharge path through protection clamps, so a static discharge during handling, test or assembly flows through the clamps instead of through thin gate oxide. Latch-up checks confirm that well and substrate taps and guard rings are close enough that the parasitic PNPN structure inside CMOS cannot switch on and short VDD to VSS. Both protect against failures that timing, LVS and ordinary spacing checks do not see, and both are signed off with foundry rules and resistance-based checks.
DFM checks are foundry rules that go past the DRC minimums: larger via enclosures, redundant vias, longer line ends, wider spacing where there is room, and pattern matching for shapes known to lower yield. A layout that misses a recommended rule can still be built, so the foundry does not make these pass or fail; each fix buys yield at a cost in area, tracks or timing. You apply them where they are cheap and skip or waive them where they would hurt the design.
A tapeout handoff is the final layout plus the evidence that it is clean: a merged GDSII or OASIS stream with every cell, macro and fill shape, the final DRC, LVS and ERC results with an approved waiver list, IR and EM signoff reports, and whatever constraints or documents the foundry or chip owner requires. The stream must be the exact data that was verified, so it is written once from the final block and every signoff run points at that file. Any edit afterwards means rerunning the checks.
Once masks are made, the layout cannot be patched: a defect that escapes means new masks, a new wafer run and months before corrected silicon is back. Advanced-node mask sets are very expensive, and the schedule loss often costs more than the masks because the product misses its market window. So physical signoff treats every unexplained DRC, LVS, ERC, IR or EM result as a blocker until it is fixed or formally waived.
Temperature changes the numbers every other signoff check depends on. Hotter metal has higher resistance, so IR drop grows; EM limits are tied to temperature and allowed current falls as metal heats; and leakage rises with temperature, adding power and more heat. Thermal analysis, run in ICC2 with Kelvin through `analyze_thermal` (ICC2), shows where the die is hotter than the temperature the other analyses assumed.
A block leaves physical verification only when every check has run on the final data and is clean or formally waived: DRC clean or waived, LVS PASS, ERC clean, antenna clean, density met, isolated vias fixed, IR drop and EM inside budget, and fill and extraction redone after the last change with timing rechecked. The order matters, because fill and ECOs change the layout; the checks must come after the last edit, not before it.
Fix power-to-ground shorts first, then power-to-signal, then signal-to-signal, and only then look at label and text shorts. A short merges two schematic nets into one extracted net, so a single bad jog can produce hundreds of unmatched devices. Use the LVS Short Finder output from IC Validator to see the exact polygon path between the two labels, and confirm routing-level shorts in ICC2 before you stream out again.
An open means the pins of one net are not connected by its shapes, so one schematic net extracts as two or more layout nets. A floating shape is a piece of a net that touches none of its pins. Find both in ICC2 with `check_lvs` (ICC2) using full error counts and detailed open locations, fix power nets before signal nets, then confirm in IC Validator.
LVS uses text labels to give extracted nets their names and to anchor the top-level ports to the schematic. If a label lands on the wrong layer, misses its shape or sits on a shape of another net, the compare starts from a wrong or missing anchor. The result is a text open, a text short or unused text, and the rest of the compare often fails around it.
A black box tells LVS to treat a macro as a cell with pins only, so the compare checks how the top level connects to those pins and skips the macro contents. IC Validator declares black boxes through the `lvs_black_box_options()` (ICV) runset function, which you can also add from a file with `-e` (ICV). The risk is that anything wrong inside the macro, including a stale GDS version, is never checked by your run.
An equivalence point is a pairing of a schematic cell with a layout cell that LVS compares as its own unit. Hierarchical LVS compares these pairs separately, so an error is reported against a small cell instead of the whole chip. IC Validator takes pairs from `equiv_options()` (ICV), from a file passed with `-e` (ICV), or generates its own, and writes the list it used to `equiv.run` (ICV).
Hierarchical verification checks each repeated cell once and reports its errors once, so it is the default for full-chip DRC and LVS. Flat verification sees every shape in its final context but costs far more runtime and memory and repeats every error per instance. You flatten selectively: a cell whose checks depend heavily on its surroundings, a small block where optimization is not worth it, or a debug run.
Give IC Validator more CPUs and let it decide how to use them. Standalone runs take hosts and CPU counts through `-host_init` (ICV) and can take more mid-run through `-host_add` (ICV). ICC2 In-Design runs use one process by default, so you set `set_host_options -target ICV` (ICC2) before running signoff DRC.
By default `signoff_check_drc` (ICC2) reads the design view for the top-level block and standard cells, but only the pin information from the frame view for macros and I/O pads. The frame view is an abstraction, so shapes inside a macro that a top-level route could violate against are not there to check. You swap in real data through merged stream files, layout views or design views, in that order of precedence.
The layer mapping file tells IC Validator In-Design which runset layer each ICC2 technology layer becomes. You point to it with `signoff.physical.layer_map_file` (ICC2). For `signoff_check_drc` (ICC2) it is needed whenever the technology file and the foundry runset use different layer numbers, and Live DRC requires it.
`signoff_check_drc -auto_eco true` (ICC2) checks only the areas changed since the previous signoff DRC run. It works only after a previous run and only while the change is below `signoff.check_drc.auto_eco_threshold_value` (ICC2), which defaults to 20 percent. Above that you are back to a full-block run, and final signoff is always a full run.
`signoff_fix_drc` (ICC2) has Zroute fix signoff DRC violations found by IC Validator, then rechecks with IC Validator. By default it runs an initial signoff check, two repair loops, skips rules with more than 1000 violations, runs five detail-route iterations after fixing, and saves the result as a design view named `block_ADR_#` (ICC2). It writes `result_summary.rpt` (ICC2) to the working directory.
Zroute can fix only top-level violations, so the check that feeds auto-fix should report only those. Setting `signoff.check_drc.ignore_child_cell_errors` (ICC2) to true makes `signoff_check_drc` (ICC2) write only top-level errors to the error data. Child-cell errors still exist and need their own check and owner.
An odd cycle is a loop of an odd number of shapes, each too close to the next to share a mask, so no two-colour assignment works. At signoff you fix all other routing rules first with the double-patterning rules unselected, then run a separate fix pass on only the double-patterning rules with `signoff.fix_drc.custom_guidance` (ICC2) set to dpt. A final full signoff check confirms both.
Live DRC runs IC Validator with the foundry runset on what is displayed in the ICC2 layout window, so you can check a hand edit or ECO area in seconds. It needs IC Validator P-2019.06 or later, a runset in `signoff.check_drc_live.runset` (ICC2) and a layer map in `signoff.physical.layer_map_file` (ICC2). It is a local debug tool, not a replacement for full signoff DRC.
A heat map shows where violations are dense instead of listing them one by one, so thousands of errors turn into a few clusters with a likely shared cause. In ICC2 you turn it on with `signoff.check_drc.enable_icv_explorer_mode` (ICC2) before `signoff_check_drc` (ICC2); it needs IC Validator P-2019.06 or later and an IC Validator NXT licence. Standalone, IC Validator Explorer DRC runs the high-priority checks first and opens its results with a heat map in VUE.
In IC Validator you classify each accepted error once, export the classifications to an error classification database (cPYDB), and import that database into later runs through the `match_errors` (ICV) argument of `error_options()` (ICV). An error comes back pre-classified only when it matches an entry in the cPYDB, so anything new or changed still shows up unclassified. For hierarchical matching, run with `-pec EXPLODE` (ICV), especially on the run that creates the cPYDB.
Use `remove_stdcell_fillers_with_violation` (ICC2), which checks filler instances against routing and deletes only the ones with violations. Run it first with `-check_only true` (ICC2) to see what it would remove, then in removal mode, and repeat until it reports that it deleted 0 cell instances. Removing one filler can expose a violation on its neighbour, so one pass is often not enough.
It is a filler flow in which ICC2 picks the filler for each gap from the threshold-voltage types of the cells on its left and right. You label VT types with `set_cell_vt_type` (ICC2), write rules with `set_vt_filler_rule` (ICC2) and insert with `create_vtcell_fillers` (ICC2). The guide says this flow is typically used only for established foundry nodes; the other method is the standard `create_stdcell_fillers` (ICC2) flow.
Decap fillers add decoupling but also leak, so you decide how much of the empty space becomes decap and which VT flavour it uses. `create_stdcell_fillers -type_utilization` (ICC2) sets an insertion percentage per filler group, `-fill_remaining` (ICC2) fills what is left from the `-lib_cells` (ICC2) cells that are not in those groups, and `-leakage_vt_order` (ICC2) makes the tool choose the lowest-leakage filler that legalizes.
Remove and refill fill only where the ECO touched, then re-check DRC, density and timing. `signoff_create_metal_fill -auto_eco true` (ICC2) does this automatically when less than 20 percent of the block changed since the last fill run, and `-remove_by_rule drc_auto` (ICC2) removes track-based fill that now causes DRC violations. A plain `-mode remove` (ICC2) takes out all fill, TCD structures included, unless you restrict it with `-select_layers` (ICC2).
A MiM capacitor is two special conducting plates with an insulator between them, built between two regular metal layers such as M8 and M9, and usually connected between power and ground to steady the supply. Because it sits in the upper stack, it adds decoupling without using standard-cell row area. In ICC2, `create_mim_capacitor_array` (ICC2) places an array of a MiM library cell at a fixed x and y pitch, and by default it ignores standard cells, macros, placement blockages and voltage areas.
Point ICC2 at the RedHawk or RedHawk-SC executable with `rail.product` (ICC2) and `rail.redhawk_path` (ICC2), set the rail input options, create taps, and run `analyze_rail -voltage_drop static -nets {VDD VSS}` (ICC2). ICC2 writes the GSR and run script, RedHawk does extraction, power and the solve, and results return to the rail database, where `open_rail_result` (ICC2) loads maps and `report_rail_result` (ICC2) writes text. EM follows on the final grid with `analyze_rail -voltage_drop static -electromigration -nets {VDD VSS}` (ICC2).
In the RedHawk TCL shell you import the design through a GSR file, build the database with `setup design` (RH), calculate power with `perform pwrcalc` (RH), extract the power and ground networks with `perform extraction -power -ground` (RH), and solve with `perform analysis -static` (RH). EM is a separate step, because RedHawk does not check it during simulation unless the ENABLE_AUTO_EM keyword is set, and `perform emcheck` (RH) reports it. Standalone RedHawk needs an Ansys licence.
Vectorless analysis has no simulation vectors: RedHawk builds a realistic worst-case switching scenario from toggle rates, timing windows and the known average power, so it covers cases you never simulated but rests on those settings. VCD-based analysis replays switching from a gate-level simulation with timing, so it is exact for that activity and blind to activity the testbench missed. Standalone RedHawk runs them with `perform analysis -vectorless` (RH) and `perform analysis -vcd` (RH); in ICC2 the modes are `analyze_rail -voltage_drop dynamic_vectorless` (ICC2) and `analyze_rail -voltage_drop dynamic_vcd` (ICC2).
IR drop is resistance times current, so a badly connected cell that happens to draw little current can pass an IR check. Minimum path resistance ignores current and reports the resistance of the least-resistive path from each pin to its taps, which exposes structural weaknesses such as a missing via or a single thin connection. It runs with `analyze_rail -nets {VDD VSS} -min_path_resistance` (ICC2) in Fusion, and with `perform min_res_path` (RH) or `perform gridcheck` (RH) in standalone RedHawk.
PG EM analysis compares the current density in every power and ground segment and via against the layer limits in the technology file and reports it as a ratio. In ICC2 you set `rail.tech_file` (ICC2) and run `analyze_rail -voltage_drop static -electromigration -nets {VDD VSS}` (ICC2); in standalone RedHawk you run `perform emcheck` (RH) after the analysis in AVG, RMS or PEAK mode. Anything over 100% needs wider metal, more vias, or less current through that segment.
You either lower the resistance between the taps and the weak cells or lower the current they draw at once. The grid options are wider straps, extra straps or via stacks, and PG augmentation, where `signoff_create_pg_augmentation` (ICC2) uses a RedHawk Fusion voltage drop result to add PG shapes in free space through IC Validator. In standalone RedHawk, `mesh fix` (RH) and `mesh optimize` (RH), driven by GSR keywords, work out new strap widths and write an ECO file that still has to be implemented in the layout.
Clock buffers switch on every clock edge, within a narrow time window, and usually drive large loads, so they draw big current pulses at the same moment. Packed into one small area, they pull that charge through the same rails, vias and local decap, and the local supply dips far more than the block average suggests. Spreading clock buffers evenly, and placing decap next to the ones that must stay close, keeps the drop down.
ICC2 runs Kelvin thermal analysis with `analyze_thermal` (ICC2) after you open the block and set the thermal application options. Most options have defaults, but `thermal.tech_file` (ICC2) must be provided in the basic flow, while power and metal profiles are generated in memory if you do not supply them. You then view the temperature map in the GUI and use `report_thermal_qor -threshold 35.9` (ICC2) to list results above a temperature in Celsius.
Start with shorts, and among shorts start with power to ground. One VDD-to-VSS short merges both supplies into a single extracted net, so every cell in the block stops matching and one defect shows up as thousands of errors. Clear supply shorts, then signal shorts, then opens, then device and label problems, rerunning after each class, because the count usually collapses long before you reach the bottom of the list.
Don't start fixing. A flood that large almost always comes from a few root causes, so first group the violations by rule and by region, then ask what changed. Fill, a macro abstract that differs from its GDS, and a rule deck or layer map that does not match the design are the usual suspects. Only after the cause is known do you decide what `signoff_fix_drc` (ICC2) can repair and what must be fixed upstream.
DRC checks shapes against geometric rules and LVS checks connectivity against the netlist. Neither checks how the chip behaves electrically over time or under real activity. Dynamic IR under real vectors, EM lifetime, ESD discharge paths, litho hotspots that pass rule checks, density gradients and thermal hotspots all sit outside those two runs, so each needs its own analysis and its own owner.
The two runs are not checking the same data. By default `signoff_check_drc` (ICC2) reads the design view for the top block and standard cells but only the pin information from the frame view of macros and pads, while standalone IC Validator reads every polygon in the merged GDS. Any macro geometry that the frame view abstracts away, such as internal metal near the edge, is invisible to the ICC2 run.
First prove it with extraction that includes the real fill, then repair only around the nets that lost slack. Remove fill around critical nets with `signoff_create_metal_fill -mode remove` (ICC2) using `-nets` or a setup slack threshold, reinsert with timing-driven spacing, and recheck density and timing. Never rip out fill block-wide to recover a few picoseconds.
`signoff_fix_isolated_via` (ICC2) looks for a neighbour within the range you set per via layer, and if none exists it adds a fixing via using dummy fill as the landing. It tries three methods in a fixed order: a via between an existing non-wide net shape and fill, then a line-end extension plus via, then a via between a wide metal shape and fill. On very congested or very sparse blocks it may not fix them all, and by default it also skips clock and PG nets.
Diagnose before choosing. If the hotspot shows in static analysis and the resistance from the cells to the taps is high, the grid is the cause and needs more metal or vias. If the grid is fine but many high-current cells sit together, spread or downsize them. If static is clean and only dynamic analysis shows the droop, decap is the right fix, because decap does nothing for an average-current drop.
Size decap from the charge the hot region pulls in one switching event and the droop you can accept, then place it next to the cells that switch, not evenly across the die. Every decap leaks, so the target is the least capacitance that brings the worst window inside budget. Let RedHawk identify the hot instances, add decap there, and remove decap that analysis shows is doing nothing.
EM fails when current density in a wire or via exceeds the limit, so you either spread the current over more metal or send less current through that segment. Widening the strap, adding a parallel strap, enlarging the via array, and moving current sources or taps all work, but each costs tracks, capacitance, or placement change. Pick by whether the violation is in the wire or in the vias, and by what the surrounding routing can give up.
Use vectorless analysis to find weak areas across the whole design, then sign off with VCD windows chosen for the highest power and the fastest change in current, not whatever the testbench happened to dump. The danger is optimistic vectors: a reset sequence or a light test gives a clean result that real traffic never matches. Document which windows were run and why each is the worst for its mode.
RedHawk Fusion is built for fast in-design rail analysis, not for every signoff feature. The ICC2 guide states it does not support hierarchical analysis or dynamic analysis with lumped or SPICE packages, analyses only the current scenario of an MCMM design by default, and does not support signal EM or inrush current analysis. Some signoff features can be enabled in ICC2 with RedHawk signoff licenses; anything outside that list needs standalone RedHawk.
RedHawk Fusion analyses only the current design scenario by default, so multiple scenarios need rail scenarios. Enable them with app options, mark the design scenarios for IR drop, create each rail scenario with `create_rail_scenario` (ICC2) before configuring it with `set_rail_scenario` (ICC2), then run them together with `analyze_rail -rail_scenarios` (ICC2). Pick scenarios by current, not by timing corner names.
The die grid is only part of the supply path. Package and bump resistance add DC drop that static analysis must include, and package inductance adds L di/dt droop during current steps that only dynamic analysis with a package model shows. A run with ideal taps assumes a perfect supply at the bumps and can look clean while the real chip droops.
A gated domain has two IR problems ungated logic does not. When on, current flows through the switch cells, so their on-resistance adds drop between the always-on supply and the virtual supply. At wake-up, the whole domain capacitance charges at once and the rush current can pull down the always-on rail that neighbouring logic depends on. Switch sizing trades the first against the second, and daisy chaining spreads the turn-on over time.
ESD signoff checks that the metal between each pad or bump and its clamp is low-resistance enough to carry a discharge without damaging the gates it protects. RedHawk's PathFinder builds a clamp database, then `perform esdcheck` (RH) measures bump-to-bump loop resistance, bump-to-clamp and clamp-to-clamp resistance and other rule types against limits in a rules file. DRC and LVS can confirm a clamp exists and is connected, but not that its path is strong enough.
ICC2 prevents odd cycles in what it can see: its own routes, pins and cell abstracts. Signoff checks the full layout, including macro internals, cell metal that the abstract simplifies, and fill added late, so odd cycles that span those shapes appear only there. Wrong mask mapping between ICC2 and the runset shows up the same way. Fix other rules first, then run DP fixing as its own pass.
Add compute before you remove checks. IC Validator scales across CPUs and hosts with `-host_init` (ICV), `-host_add` (ICV) and `-host_elastic` (ICV), keeps hierarchical processing on so repeated cells are checked once, and caches the compiled runset between runs. Then find the few checks that dominate runtime and fix their cause. Incremental and rule-subset runs help during iteration, but the final signoff run is full.
Electromigration speeds up sharply with temperature, so the current a wire can carry for its lifetime drops as it gets hotter. An EM check run at a nominal temperature passes wires that fail in the hot parts of the die. Run thermal analysis first, then set the EM temperature to the hot-region value, or check hot regions separately.
The physical gate proves that the exact GDS going to the fab is manufacturable and electrically sound. Full-chip DRC and LVS on the final merged GDS with the released runset, ESD and ERC checks, IR and EM signoff, and a reviewed waiver list must all be closed, each with a named owner. Timing is signed separately through the timing gate, which `eco-final-signoff-gate` covers.
Incremental checks are fine for DRC and fill while you iterate, but connectivity is global, so LVS always runs in full. After the ECO, run incremental signoff DRC on the changed areas, remove and repair fill that now conflicts, rerun full LVS, and rerun IR and EM where current or metal changed. Before tapeout, run full-chip DRC on the final GDS, since incremental runs only look where things changed.