How to prevent MCU reset loop and go to Deep-Failsafe

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to prevent MCU reset loop and go to Deep-Failsafe

Jump to solution
9,974 Views
tam11
Contributor II

Hi
I am using FS26 and FS84 for 2 different AUTOSAR projects. Both have same problem.

In theory when FLT_ERR_CNT reaches maximum value, then SBC must enter into Deep fail safe mode. But this seems unreachable when some fault occurs during runtime (e.g. watchdog fault).

Its because SW is initialized with FLT_ERR_CNT cleared and FS0B released.


Lets assume below scenario:
1. A program flow issue occurs during run time 2 min after start (e.g. an unexpected infinite loop) which causes watchdog error.
2. So in SBC watchdog timeout happens which resets MCU and SBC goes for INIT_FS mode.
3. SW initializes SBC (FLT_ERR_CNT cleared and FS0B released)
4. Step 1 repeats.

What is correct strategy to avoid such uncontrolled MCU reset loop and go to Deep failsafe when such scenario occurs?

I am looking for solution for both FS26 and FS84.

Thanks

Labels (4)
1 Solution
9,877 Views
guoweisun
NXP TechSupport
NXP TechSupport

guoweisun_0-1700746251032.png

This above can be configured as 00 or 01 which do not affect the RSTB.

guoweisun_1-1700746418469.png

 

If WD error counter always =max, the fault error counter will increase into max then enter into deep FS mode.

 

View solution in original post

0 Kudos
Reply
13 Replies
4,678 Views

Hello tam11,

There are flags on the FS_DIAG_SAFETY1 register that allow you to identify when there is an watchdog issue.
After the reset, check these bit fields:

Miguel_Mannes_Hilleshiem_2-1761223827213.png

 

To avoid being stuck on that loop, you have to change the choices when running your software.

Here some hints on how to detect your MCU might be on that loop.

1 - Write on FS26 memory a key that represents your start-up attempt number

 -> at first start-up with Battery fail, read the memory (NULL?) and write a know different value.

 -> at next reset, read the memory, if the value is your know value, it means the device was reset. Change the value to the first software debug mode and change your flow (disable a resource?) to try avoid the blocking loop.

Miguel_Mannes_Hilleshiem_0-1761144790856.png

 

If you go to DFS:

1 - Check wake-up source on FS26 M_WIO_FLG > WUEVENT[3:0].

 -> If Battery fail, do your normal configuration and software execution.

 -> If DFS recovery, you might be in that case.

Miguel_Mannes_Hilleshiem_0-1761144166639.png

2 - Read M_SYS_CFG -> RETRY_CNT[7:0] to check the total number of retries attempts (value).

 -> If your device is at the first retry attempt (first restart) then do something, if is the second, do something else.

Do not clear the retry counter RETRY_CNT[7:0] using RETRY_CLR.

Miguel_Mannes_Hilleshiem_1-1761144373081.png

Hope this helps you.

Miguel.

0 Kudos
Reply
8,504 Views
tam11
Contributor II

This topic is incorrectly marked as SOLVED by NXP which will mislead to other readers.

Still there is no solution provided to the question raised.

0 Kudos
Reply
9,932 Views
guoweisun
NXP TechSupport
NXP TechSupport

About your question:

During the run mode of SBC, if it has watchdog fault and the  FLT_ERR_CNT reaches maximum value then SBC enter into LPOFF or assert RSTB, you don't need this function, right?

0 Kudos
Reply
9,911 Views
tam11
Contributor II

Thanks for reply.

During the run mode of SBC, if it has watchdog fault and the  FLT_ERR_CNT reaches maximum value then SBC enter into LPOFF or assert RSTB, you don't need this function, right?

When FLT_ERR_CNT reaches maximum value SBC enters into Deep Fail safe mode (not LPOFF).

When watchdog fault occurs, I want to do the reset. This part is OK.

But after the reset SW re-initializes SBC and clears the FLT_ERR_CNT (as recommended in datasheet).

So FLT_ERR_CNT will never reach in maximum value. This part is problem. Because we will end up in reset loop if same watchdog fault happens again and again.

tam11_0-1700734617301.png

 

0 Kudos
Reply
9,904 Views
guoweisun
NXP TechSupport
NXP TechSupport

That should be protection for MCU and system, you need enter into debug mode the update the software during this condition.

 

 

 

0 Kudos
Reply
9,898 Views
tam11
Contributor II

@guoweisun, Didn't understood what that means. Do you mean enter into debug mode and re-flash software ?

0 Kudos
Reply
9,894 Views
guoweisun
NXP TechSupport
NXP TechSupport

If your assumption case happened, the system stuck in the reset endless which remind you to update software.

0 Kudos
Reply
9,891 Views
tam11
Contributor II

Well this scenario is not for test on my desk where I re-flash the software quickly. It can be actual scenario in a car driving on the road.

We are using this SBC for safety reasons (safety critical system in car) . So it should not let system stuck in the endless reset. It must go to safe state (which is Deep-failsafe I guess).

0 Kudos
Reply
9,878 Views
guoweisun
NXP TechSupport
NXP TechSupport

guoweisun_0-1700746251032.png

This above can be configured as 00 or 01 which do not affect the RSTB.

guoweisun_1-1700746418469.png

 

If WD error counter always =max, the fault error counter will increase into max then enter into deep FS mode.

 

0 Kudos
Reply
9,871 Views
tam11
Contributor II

This above can be configured as 00 or 01 which do not affect the RSTB.

Generating a RESET on watchdog error few times is required and expected. It gives MCU or software some chance to recover. So I can't configure those setting.

Problem here is the FLT_ERR_CNT. By SBC design, it is required to clear this counter at SW initialization to enter SBC into Normal mode.

So if watchdog error is not gone --> FLT_ERR_CNT will never reach maximum value --> SBC will never go to Deep-failsafe --> system stuck in endless reset loop.

I hope I have explained this clearly in original question.

 

0 Kudos
Reply
9,868 Views
guoweisun
NXP TechSupport
NXP TechSupport

During the INIT phase also need clear the fault error counter, but if the WD always errors at this time the fault error counter also increase to MAX value then lead it into Deep-FS mode.

 

Tags (1)
0 Kudos
Reply
9,864 Views
tam11
Contributor II

Ok. We are just going round-and-round in the discussion.

I think I tried my best to explain the problem. Sorry if it wasn't clear enough.

 

0 Kudos
Reply
9,861 Views
guoweisun
NXP TechSupport
NXP TechSupport

Excluding the INIT phase WD error, assumption WD no error in the INIT phase and enter into normal mode successfully, at the normal mode the WD error happens again then RSTB assert LOW then enter into INIT phase again and again,that' your condition right?

0 Kudos
Reply
%3CLINGO-SUB%20id%3D%22lingo-sub-1761386%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3EHow%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1761386%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHi%3CBR%20%2F%3EI%20am%20using%20FS26%20and%20FS84%20for%202%20different%20AUTOSAR%20projects.%20Both%20have%20same%20problem.%3C%2FP%3E%3CP%3EIn%20theory%20when%20FLT_ERR_CNT%20reaches%20maximum%20value%2C%20then%20SBC%20must%20enter%20into%20Deep%20fail%20safe%20mode.%20But%20this%20seems%20unreachable%20when%20some%20fault%20occurs%20during%20runtime%20(e.g.%20watchdog%20fault).%3C%2FP%3E%3CP%3EIts%20because%20SW%20is%20initialized%20with%26nbsp%3BFLT_ERR_CNT%20cleared%20and%20FS0B%20released.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3ELets%20assume%20below%20scenario%3A%3CBR%20%2F%3E1.%20A%20program%20flow%20issue%20occurs%20during%20run%20time%202%20min%20after%20start%20(e.g.%20an%20unexpected%20infinite%20loop)%20which%20causes%20watchdog%20error.%3CBR%20%2F%3E2.%20So%20in%20SBC%20watchdog%20timeout%20happens%20which%20resets%20MCU%20and%20SBC%20goes%20for%20INIT_FS%20mode.%3CBR%20%2F%3E3.%20SW%20initializes%20SBC%20(FLT_ERR_CNT%20cleared%20and%20FS0B%20released)%3CBR%20%2F%3E4.%20Step%201%20repeats.%3C%2FP%3E%3CP%3EWhat%20is%20correct%20strategy%20to%20avoid%20such%20uncontrolled%20MCU%20reset%20loop%20and%20go%20to%20Deep%20failsafe%20when%20such%20scenario%20occurs%3F%3C%2FP%3E%3CP%3EI%20am%20looking%20for%20solution%20for%20both%20FS26%20and%20FS84.%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1761386%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3EFS65%26amp%3BFS45%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EFS85%26amp%3BFS84%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EFSBC%2BPMIC%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EFunctional%20Safety%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2190843%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2190843%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EHello%20tam11%2C%3C%2FP%3E%0A%3CP%3EThere%20are%20flags%20on%20the%26nbsp%3BFS_DIAG_SAFETY1%20register%20that%20allow%20you%20to%20identify%20when%20there%20is%20an%20watchdog%20issue.%3CBR%20%2F%3EAfter%20the%20reset%2C%20check%20these%20bit%20fields%3A%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_2-1761223827213.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_2-1761223827213.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F362348i7E19D1BD352D9944%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Miguel_Mannes_Hilleshiem_2-1761223827213.png%22%20alt%3D%22Miguel_Mannes_Hilleshiem_2-1761223827213.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3ETo%20avoid%20being%20stuck%20on%20that%20loop%2C%20you%20have%20to%20change%20the%20choices%20when%20running%20your%20software.%3C%2FP%3E%0A%3CP%3EHere%20some%20hints%20on%20how%20to%20detect%20your%20MCU%20might%20be%20on%20that%20loop.%3C%2FP%3E%0A%3CP%3E1%20-%20Write%20on%20FS26%20memory%20a%20key%20that%20represents%20your%20start-up%20attempt%20number%3C%2FP%3E%0A%3CP%3E%26nbsp%3B-%26gt%3B%20at%20first%20start-up%20with%20Battery%20fail%2C%20read%20the%20memory%20(NULL%3F)%20and%20write%20a%20know%20different%20value.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B-%26gt%3B%20at%20next%20reset%2C%20read%20the%20memory%2C%20if%20the%20value%20is%20your%20know%20value%2C%20it%20means%20the%20device%20was%20reset.%20Change%20the%20value%20to%20the%20first%20software%20debug%20mode%20and%20change%20your%20flow%20(disable%20a%20resource%3F)%20to%20try%20avoid%20the%20blocking%20loop.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_0-1761144790856.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_0-1761144790856.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F362142i2325741E575A2CBD%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Miguel_Mannes_Hilleshiem_0-1761144790856.png%22%20alt%3D%22Miguel_Mannes_Hilleshiem_0-1761144790856.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EIf%20you%20go%20to%20DFS%3A%3C%2FP%3E%0A%3CP%3E1%20-%20Check%20wake-up%20source%20on%20FS26%26nbsp%3BM_WIO_FLG%20%26gt%3B%26nbsp%3BWUEVENT%5B3%3A0%5D.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B-%26gt%3B%20If%20Battery%20fail%2C%20do%20your%20normal%20configuration%20and%20software%20execution.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B-%26gt%3B%20If%20DFS%20recovery%2C%20you%20might%20be%20in%20that%20case.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_0-1761144166639.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_0-1761144166639.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F362139iFB61393F7113F3FB%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Miguel_Mannes_Hilleshiem_0-1761144166639.png%22%20alt%3D%22Miguel_Mannes_Hilleshiem_0-1761144166639.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E2%20-%20Read%20M_SYS_CFG%20-%26gt%3B%26nbsp%3BRETRY_CNT%5B7%3A0%5D%20to%20check%26nbsp%3Bthe%20total%20number%20of%20retries%20attempts%20(value).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B-%26gt%3B%20If%20your%20device%20is%20at%20the%20first%20retry%20attempt%20(first%20restart)%20then%20do%20something%2C%20if%20is%20the%20second%2C%20do%20something%20else.%3C%2FP%3E%0A%3CP%3EDo%20not%20clear%20the%26nbsp%3Bretry%20counter%20RETRY_CNT%5B7%3A0%5D%20using%26nbsp%3BRETRY_CLR.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_1-1761144373081.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22Miguel_Mannes_Hilleshiem_1-1761144373081.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F362141iEDA27F7884702E67%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Miguel_Mannes_Hilleshiem_1-1761144373081.png%22%20alt%3D%22Miguel_Mannes_Hilleshiem_1-1761144373081.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EHope%20this%20helps%20you.%3C%2FP%3E%0A%3CP%3EMiguel.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1917601%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1917601%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EThis%20topic%20is%20incorrectly%20marked%20as%20SOLVED%20by%20NXP%20which%20will%20mislead%20to%20other%20readers.%3C%2FP%3E%3CP%3EStill%20there%20is%20no%20solution%20provided%20to%20the%20question%20raised.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762792%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762792%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EExcluding%20the%20INIT%20phase%20WD%20error%2C%20assumption%20WD%20no%20error%20in%20the%20INIT%20phase%20and%20enter%20into%20normal%20mode%20successfully%2C%20at%20the%20normal%20mode%20the%20WD%20error%20happens%20again%20then%20RSTB%20assert%20LOW%20then%20enter%20into%20INIT%20phase%20again%20and%20again%2Cthat'%20your%20condition%20right%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762788%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762788%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CSPAN%3EOk.%20W%3CSPAN%3Ee%20are%20just%20going%20round-and-round%20in%20the%20discussion.%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20think%20I%20tried%20my%20best%20to%20explain%20the%20problem.%20Sorry%20if%20it%20wasn't%20clear%20enough.%3C%2FSPAN%3E%3C%2FP%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762768%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762768%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EDuring%20the%20INIT%20phase%20also%20need%20clear%20the%20fault%20error%20counter%2C%20but%20if%20the%20WD%20always%20errors%20at%20this%20time%20the%20fault%20error%20counter%20also%20increase%20to%20MAX%20value%20then%20lead%20it%20into%20Deep-FS%20mode.%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762765%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762765%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CEM%3EThis%20above%20can%20be%20configured%20as%2000%20or%2001%20which%20do%20not%20affect%20the%20RSTB.%3C%2FEM%3E%3C%2FP%3E%3CP%3EGenerating%20a%20RESET%20on%20watchdog%20error%20%3CSTRONG%3Efew%20times%3C%2FSTRONG%3E%20is%20required%20and%20expected.%20It%20gives%20MCU%20or%20software%20some%20chance%20to%20recover.%20So%20I%20can't%20configure%20those%20setting.%3C%2FP%3E%3CP%3EProblem%20here%20is%20the%20FLT_ERR_CNT.%20By%20SBC%20design%2C%20it%20is%20required%20to%20clear%20this%20counter%20at%20SW%20initialization%20to%20enter%20SBC%20into%20Normal%20mode.%3C%2FP%3E%3CP%3ESo%20if%20watchdog%20error%20is%20not%20gone%20--%26gt%3B%20FLT_ERR_CNT%20will%20never%20reach%20maximum%20value%20--%26gt%3B%20SBC%20will%20never%20go%20to%20Deep-failsafe%20--%26gt%3B%20system%20stuck%20in%20endless%20reset%20loop.%3C%2FP%3E%3CP%3EI%20hope%20I%20have%20explained%20this%20clearly%20in%20original%20question.%3C%2FP%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762746%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762746%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22guoweisun_0-1700746251032.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22guoweisun_0-1700746251032.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F251284iD628A0A09F04AEC9%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22guoweisun_0-1700746251032.png%22%20alt%3D%22guoweisun_0-1700746251032.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EThis%20above%20can%20be%20configured%20as%2000%20or%2001%20which%20do%20not%20affect%20the%20RSTB.%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22guoweisun_1-1700746418469.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22guoweisun_1-1700746418469.png%22%20style%3D%22width%3A%20291px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F251285i4C51680AA2B0922F%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22guoweisun_1-1700746418469.png%22%20alt%3D%22guoweisun_1-1700746418469.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CP%3EIf%20WD%20error%20counter%20always%20%3Dmax%2C%20the%20fault%20error%20counter%20will%20increase%20into%20max%20then%20enter%20into%20deep%20FS%20mode.%3C%2FP%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762712%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762712%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EWell%20this%20scenario%20is%20not%20for%20test%20on%20my%20desk%20where%20I%20re-flash%20the%20software%20quickly.%20It%20can%20be%20actual%20scenario%20in%20a%20car%20driving%20on%20the%20road.%3C%2FP%3E%3CP%3EWe%20are%20using%20this%20SBC%20for%20safety%20reasons%20(safety%20critical%20system%20in%20car)%20.%26nbsp%3BSo%20it%20should%20not%20let%20s%3CSPAN%3Eystem%20stuck%20in%20the%20endless%20reset.%20It%20must%20go%20to%20safe%20state%20(which%20is%20Deep-failsafe%20I%20guess).%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762707%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762707%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EIf%20your%26nbsp%3Bassumption%20case%20happened%2C%20the%20system%20stuck%20in%20the%20reset%20endless%20which%20remind%20you%20to%20update%20software.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762703%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762703%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F138749%22%20target%3D%22_blank%22%3E%40guoweisun%3C%2FA%3E%2C%20Didn't%20understood%20what%20that%20means.%20Do%20you%20mean%20enter%20into%20debug%20mode%20and%20re-flash%20software%20%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762684%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762684%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EThat%20should%20be%20protection%20for%20MCU%20and%20system%2C%20you%20need%20enter%20into%20debug%20mode%20the%20update%20the%20software%20during%20this%20condition.%3C%2FP%3E%0A%3CBR%20%2F%3E%0A%3CBR%20%2F%3E%0A%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762615%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762615%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3E%3CSPAN%3EThanks%20for%20reply.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CEM%3EDuring%20the%20run%20mode%20of%20SBC%2C%20if%20it%20has%20watchdog%20fault%20and%20the%26nbsp%3B%26nbsp%3BFLT_ERR_CNT%20reaches%20maximum%20value%20then%20SBC%20enter%20into%20LPOFF%20or%20assert%20RSTB%2C%20you%20don't%20need%20this%20function%2C%20right%3F%3C%2FEM%3E%3C%2FP%3E%3CP%3EWhen%26nbsp%3BFLT_ERR_CNT%20reaches%20maximum%20value%20SBC%20enters%20into%20Deep%20Fail%20safe%20mode%20(not%26nbsp%3BLPOFF).%3C%2FP%3E%3CP%3EWhen%20watchdog%20fault%20occurs%2C%20I%20want%20to%20do%20the%20reset.%20This%20part%20is%20OK.%3C%2FP%3E%3CP%3EBut%20after%20the%20reset%20SW%20re-initializes%20SBC%20and%20clears%20the%26nbsp%3BFLT_ERR_CNT%20(as%20recommended%20in%20datasheet).%3C%2FP%3E%3CP%3ESo%26nbsp%3BFLT_ERR_CNT%20will%20never%20reach%20in%20maximum%20value.%20This%20part%20is%20problem.%20Because%20we%20will%20end%20up%20in%20reset%20loop%20if%20same%26nbsp%3Bwatchdog%20fault%20happens%20again%20and%20again.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22tam11_0-1700734617301.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22tam11_0-1700734617301.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Fcommunity.nxp.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F251262iE95F3073617315AF%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22tam11_0-1700734617301.png%22%20alt%3D%22tam11_0-1700734617301.png%22%20%2F%3E%3C%2Fspan%3E%3C%2FSPAN%3E%3C%2FP%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1762353%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%20translate%3D%22no%22%3ERe%3A%20How%20to%20prevent%20MCU%20reset%20loop%20and%20go%20to%20Deep-Failsafe%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1762353%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EAbout%20your%20question%3A%3C%2FP%3E%0A%3CP%3EDuring%20the%20run%20mode%20of%20SBC%2C%20if%20it%20has%20watchdog%20fault%20and%20the%26nbsp%3B%3CSPAN%3E%26nbsp%3BFLT_ERR_CNT%20reaches%20maximum%20value%20then%20SBC%20enter%20into%20LPOFF%20or%20assert%20RSTB%2C%20you%20don't%20need%20this%20function%2C%20right%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E