Great Watchdog Timers For Embedded Systems (2016)
ganssle.com
ganssle.com
Many lifetimes ago, as a freshly baked software engineer, I had a strong interest in Embedded Systems. Juggling interrupts, wrangling registers, counting clock cycles, banging bits, reading sensors, often in raw assembly so as to fit into limited flash memory was my idea of fun.
So much so that I was contemplating doing a Master's degree in that area. However, I couldn't find a US University with a good program for that. I had seen Jack being very active on a few embedded-related forums, and on a lark, I emailed him for advice.
And he responded! He gave me very sound advice, effectively explaining that graduate research in Embedded Systems is quite distinct from the actual low-level work that happens in the industry. This explained why I hadn't found any of the programs appealing. I took his advice gratefully and pursued a different area for my Master's, which shaped the rest of my career. Thanks again, Jack!
I always intended to come back to Embedded Systems at some point, but unfortunately it never worked out. Partially because embedded engineers are criminally underpaid for the complexity of the work they do. As the article hints, writing software that runs reliably in arbitrarily harsh environments on low-cost, cheap, quirky hardware with extremely constrained resources is a different level of challenging.
Especially if such watchdog has the ability to switch to a secondary or third backup...
edit: Shoutout to wildzzz for pointing out ISL706ARH Active Rad-Hard, 5.0V/3.3V µ-Processor Supervisory Circuits
One of my favorite blogs on the topic https://ferd.ca/the-zen-of-erlang.html that does a great job of covering how Erlang approached the topic, lots of learnings that can be applied more broadly.
Reminds me of an article I read a few years ago about designing systems to detect when (human) train drivers fall asleep at the wheel. Apparently it was an arms race for a long time: Designers kept coming up with increasingly complicated tasks for drivers to complete to signal their conscious state, like tapping buttons with their hands or feet at various time intervals, while drivers, for their part, kept figuring out ways to perform those tasks while actually functionally unconscious...
You have a similar situation as train drivers when you inadvertently kick the watchdog in an infinite loop. Or when a newbie thinks there's nothing wrong with it kicking it in some long loop.
I wish they delved into this a little deeper; was it because the WDT disables with one op? That does seem quite risky on its own