Embedded Linux ·
A watchdog is only useful when feeding it proves the system is healthy
A watchdog is useful only when feeding it proves the system is healthy.
The weak design
A weak design pets the watchdog from a periodic loop. That loop may keep running while critical application logic, device I/O or communication has already failed, so the watchdog is fed all the way through the failure.
The stronger design
A stronger Embedded Linux design gates each feed on explicit health signals:
- Critical application progress
- Required device and I/O responses
- System resource health
- Recovery-state completion
When the conditions fail
When those conditions fail, stop feeding and let the watchdog perform a controlled reset. Preserve the reset cause, so that the next boot can distinguish watchdog recovery from a power-on reset.
The objective is not to avoid every reset. It is to recover predictably from an unrecoverable state.