(That was my first thought after reading 'death by design')
(That was my first thought after reading 'death by design')
For example the graphics back end of a video card is running its framebuffer memory at a different clock rate from the video dot clock, at some point pixel data has to move from one clock domain to the other - metastability failure might cause an occasional bad pixel on the screen, you can do the math, trade latency (and more gates) for reliability so that you see that pixel burble once a year.
Other times it could be worse - I worked on a chip where we did the math on whether the PCI interface would suffer synchroniser failure and what the worst case failure was (maybe bus lockup?), in the end the boss signed off on once a year ... which at the time was ~100 times the mean Win95 uptime
So we do sort of do that math, knowing that you can't 'fix' metastability issues, just make them rare