Referring to Figure 3-9, the safe state of the TMS320F2838x MCU is defined as the one in which:
TMS320F2838x MCU Reset is asserted
Power supply to TMS320F2838x MCU is disabled using an external supervisor as a result of Level 3 check failure. In general, a power supply failure is not considered in detail in this analysis as it is assumed that the system level functionality exists to manage this condition.
External system is informed using one of TMS320F2838x MCU’s IO pins as a result of Level 2 check failure (for example, ERRORSTS pin is asserted).
Output of the TMS320F2838x MCU driving the actuator is forced to inactive mode as a result of Level 2 check failure (for example, GPIO pins corresponding to the mission function is tri-stated).
Figure 3-9 TMS320F2838x MCU Safe State Definition
Figure 3-10 TMS320F2838x MCU Device Operating States