A watchdog is useful only when feeding it proves the system is healthy.

The weak design

A weak design pets the watchdog from a periodic loop. That loop may keep running while critical application logic, device I/O or communication has already failed, so the watchdog is fed all the way through the failure.

The stronger design

A stronger Embedded Linux design gates each feed on explicit health signals:

  • Critical application progress
  • Required device and I/O responses
  • System resource health
  • Recovery-state completion

When the conditions fail

When those conditions fail, stop feeding and let the watchdog perform a controlled reset. Preserve the reset cause, so that the next boot can distinguish watchdog recovery from a power-on reset.

The objective is not to avoid every reset. It is to recover predictably from an unrecoverable state.

Designing for recovery on a custom board?

A watchdog is one part of a recoverable platform. See how it fits with A/B updates and rollback, and our Embedded Linux development services.

Talk to us