2400341_en-US

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

2400341_en-US

2400341_en-US

Behaviour discrepancy of FS6500 IO2_3/FCCU fault between Debug mode and Normal mode
Hi!
 
The IO2_3 pin of FS6500 is connected to the MCU FCCU.
 
In DEBUG mode, one single FCCU fault trigger leads to an immediate reset.
 
In Normal operating mode, one single FCCU fault trigger causes the SBC to enter Deep Fail-Safe (DFS) mode.
Could you help confirm whether this behavior is expected?
My understanding: The IO2_3 fault will increment the Fault Error Counter. The safety responses (RSTB pulse, FS0B assertion or DFS transition) should only take place once the Fault Error Counter exceeds the configured threshold (3 or 6).
Re: Behaviour discrepancy of FS6500 IO2_3/FCCU fault between Debug mode and Normal mode
Hi Peter,
Thanks a lot for your clarification.
 
I have a further question.
 
I searched the FS6500 datasheet and RM thoroughly, yet there is little documentation introducing the safety mechanism strategy triggered by IO2_3 FCCU fault, as well as the corresponding IMPACT register configuration.
Previously I thought IO2_3 fault will increment the Fault Error Counter, and safety actions take effect after the counter hits the threshold. According to your reply, IO2/IO3 fault triggers safety response directly.
 
Could you tell me which chapter of the manual covers the configuration of direct safety reaction for IO2/IO3?
Best regards
Re: Behaviour discrepancy of FS6500 IO2_3/FCCU fault between Debug mode and Normal mode

Hello,

This behavior can be expected if the SBC is not in the same operating condition in both tests.
Please distinguish between:

  • MCU debug mode, for example debugger attached to the MPC device, and
  • FS6500 debug mode, which is entered through the FS6500 DEBUG pin.

When the FS6500 is in debug mode, the watchdog still runs internally, but it does not affect device operation by asserting reset or fail-safe pins. Therefore, the behavior observed during debug can differ from standalone/normal operation. This mode is intended to allow software debugging without the SBC continuously resetting the system.
In normal operation, the FS6500 fail-safe state machine monitors the configured safety inputs/reactions. If IO_2/IO_3 are used for the MCU FCCU error output monitoring, then an FCCU fault can be detected by the SBC and the configured reaction can be executed, for example assertion of FS0B/RSTB depending on the configuration.
So the different behavior between debug and standalone mode is not necessarily an MCU FCCU issue. It is most likely caused by the FS6500 being in debug mode, or by a difference in the SBC initialization/configuration between the two cases.

The Fault Error Counter is typically associated with mechanisms such as watchdog supervision and fail-safe state machine handling. A safety-critical fault reported by the FCCU should trigger its configured reaction directly rather than being accumulated until the counter reaches its threshold.
Therefore, the observed behavior of an immediate safety response is consistent with the intended safety concept.

Best regards,

Peter

Re: Behaviour discrepancy of FS6500 IO2_3/FCCU fault between Debug mode and Normal mode

Hello,

The key point is that the FS6500 treats IO2/IO3 FCCU monitoring differently from most other fault sources.

The description is not located in the FCCU fault-reaction (IMPACT) tables, but rather in the FS6500 fail-safe fault management documentation.

According to the FS6500 documentation, IO_23 error detection (FCCU) is listed among the fault sources that always increment the Fault Error Counter and cannot be configured out. The documentation explicitly separates it from the configurable fault sources.

Therefore, the behavior observed with an IO2/IO3 fault is not governed solely by the IMPACT register settings that are used for configurable fail-safe reactions. The IO2/IO3 FCCU monitor is part of the dedicated FCCU supervision path of the SBC and is handled by the fail-safe state machine.

The relevant section to review is the FS6500 documentation chapter "Fault error counter", which states:

Best regards,

Peter

タグ(1)
評価なし
バージョン履歴
最終更新日:
1週間前
更新者: