Referring to Figure 4-6, the Safe state of the TMS320F280013x MCU is defined as one in which:
- The TMS320F280013x MCU reset is asserted.
- The power supply to TMS320F280013x MCU is
disabled using an external supervisor as a result of Level 3 check failure. In
general, a power supply failure is not considered in detail in this analysis as
the assumption is that the system-level functionality exists to manage this
condition.
- The external system is informed using one of the
IO pins of the C2000 MCU as a result of Level 2 check failure (for example,
ERRORSTS pin is asserted).
- The output of the TMS320F280013x MCU driving the
actuator is forced to inactive mode as a result of Level 2 check failure (for
example, GPIO pins corresponding to the mission function is tri-stated).