Referring to Figure 4-8, the safe state of the TMS320F28P65x MCU is defined as the one in which:
- TMS320F28P65x MCU Reset is asserted.
- Power supply to TMS320F28P65x MCU is disabled using an external supervisor as a result of Level 3 check failure. In general, a power supply failure is not considered in detail in this analysis as it is assumed that the system level functionality exists to manage this condition.
- External system is informed using one of
TMS320F28P65x MCUs IO pins as a result of Level 2 check failure (for example,
ERRORSTS pin is asserted).
- Output of the TMS320F28P65x MCU driving the
actuator is forced to inactive mode as a result of Level 2 check failure (for
example, GPIO pins corresponding to the mission function are tri-stated).