??? 06/01/08 18:21 Read: times |
#155358 - A quote from "The Firmware Handbook": Responding to: ???'s previous message |
How the system recovers from a failure is at least as important as trying valiantly to make sure it can't fail from EMC in the first place, and I don't think enough attention is given to it.
"Assume that runaway microprocessors are controlled by a malevolent deity." The watchdog needs to make sure that the system doesn't kill anyone or tears itself to shreds in case the processor decides to run amok (if the two are mutually exclusive, not killing anyone should take priority. :) ). It would also be nice if it eventually recovered again, especially in cases where you can't send over a technician to push the reset button (satellite, space probe, Mars rover). |