Hi,
We're bringing up a board with the FS85 (fail-safe SBC) and the fail-safe state machine never leaves INIT_FS (FS_STATES.FSM_STATE stays at 6 / INIT_FS indefinitely, even though the MCU sends a continuous watchdog refresh at the configured window period).
Per the datasheet (Rev 9, §14.3, p.18): "The first good watchdog refresh closes the INIT_FS." On our part, OTP_CFG_ASIL.WD_DIS = 1 (watchdog monitoring disabled by OTP).
Supporting register reads while stuck (all consistent with the watchdog evaluation logic simply never running):
Question: Is it expected/documented that WD_DIS = 1 structurally prevents ever leaving INIT_FS (since the "good watchdog refresh" event that closes INIT_FS can never be generated when the WD is OTP-disabled)? Or is there an alternate documented path to close INIT_FS and reach NORMAL_FS when the watchdog is disabled by OTP?
Datasheet section 14.1/14.3 states VALID_WD = 0 "when the WD is disabled by OTP", but doesn't explicitly state the consequence on the INIT_FS -> WAIT_ABIST2 transition. Any clarification, or a pointer to the relevant application note, would be appreciated.
Thanks, Sophie
Hello sobo
Good day!
During my research, I found information on a similar case, and I am reviewing it with a colleague who was responsible for its review; however, given the nature of the case, you will need to open a ticket on our official website so that we can share information more freely and securely.
Thanks for your understanding.
Have a great day and best of luck.