Referring to Figure 4-8, the safe state of the TMS320F28P55x
MCU is defined as one in
which:
- The TMS320F28P55x MCU reset is
asserted
- The power supply to the TMS320F28P55x MCU is disabled using
an external supervisor as a result of a Level
3 check failure. In general, a power supply failure is not considered in detail in
this analysis since TI assumes that the system-level functionality exists to manage this
condition.
- The external system is informed using one of the
I/O pins of the TMS320F28P55x MCU as a result of a Level 2 check failure
(for example, ERRORSTS pin is asserted).
- The output of the TMS320F28P55x MCU driving the
actuator is forced to inactive mode as a
result of a Level 2 check failure (for example, the GPIO pins corresponding to the
mission function is in a
tri-state
condition).