Files
NeoECU-Hardware/Architecture/IO_MODULES/DEAD_MAN.md
T
h3cx 0de94168f7 Initial function IO and power architecture
This commit contains the inital functional IO (engine controls and
general digital and analog IO excluding digital IO) and the initial
power architecture for the project
2026-08-29 21:18:45 +02:00

89 lines
4.4 KiB
Markdown

# Dead-Man Engine-Permit Interlock
## Purpose
This module provides the hardware run-permission path for the engine outputs.
The steering-wheel dead-man switch must be held to assert permission. Releasing
the switch, an open circuit, loss of a logic supply, or MCU reset must place
the engine outputs in their non-energising state independently of firmware.
This document defines the signal relationships and destinations only. Output
driver implementation is documented separately.
## Logic domains
| Signal | Domain | Active state | Default/fault state |
| --- | --- | --- | --- |
| `DEAD_MAN_SIG` | Protected 5 V logic | High: driver is holding the dead-man switch | Low: no permission |
| `MCU_RUN_PERMIT` | 3.3 V MCU logic | High: MCU permits engine operation | Low: no permission |
| `ENGINE_PERMIT` | 5 V logic | High: both hardware and MCU permit operation | Low: no permission |
| `MCU_INJECTOR_SIG` | 3.3 V MCU logic | High: requested injector on-time | Low: injector off |
| `SAFE_INJECTOR_SIG` | 5 V logic | High: permitted injector command | Low: injector off |
| `SAFE_IGNITION_INHIBIT` | 5 V logic | High: ignition output is inhibited | Low: ignition output is permitted |
| `DEAD_MAN_STATUS` | 3.3 V MCU input | High: observed dead-man asserted | Low: observed dead-man released/faulted |
`DEAD_MAN_SIG` is a harness-connected input. It shall be protected, filtered,
and given a default-low bias before entering the 5 V logic. The conditioning
must tolerate expected connector faults and transients without allowing a
fault to assert engine permission.
## Signal tree
The permission gates operate from `+5V_MAIN` and accept 3.3 V MCU logic
levels. Their outputs are 5 V logic levels.
```text
protected steering-wheel input
|
+--> protected 3.3 V observation path --> DEAD_MAN_STATUS --> MCU
|
+--> conditioned 5 V DEAD_MAN_SIG --+
AND --> ENGINE_PERMIT --+
MCU_RUN_PERMIT --------------------------------+ |
+--> ignition-permission inverter
| --> SAFE_IGNITION_INHIBIT
|
MCU_INJECTOR_SIG -------------------------------------------------------AND --> SAFE_INJECTOR_SIG
```
The logic equations are:
```text
ENGINE_PERMIT = DEAD_MAN_SIG AND MCU_RUN_PERMIT
SAFE_INJECTOR_SIG = ENGINE_PERMIT AND MCU_INJECTOR_SIG
SAFE_IGNITION_INHIBIT = NOT(ENGINE_PERMIT)
```
## Output destinations
| Logic output | Destination | Required behavior |
| --- | --- | --- |
| `ENGINE_PERMIT` | Hardware injection-command permission gate | Must prevent an injector command from reaching the injection output stage when low. |
| `SAFE_INJECTOR_SIG` | Dedicated injection output stage command input | The only injector on-command presented to the output stage. |
| `SAFE_IGNITION_INHIBIT` | Dedicated ignition output stage inhibit/enable input | Must inhibit the ignition output stage when high and permit it only when low. |
| `DEAD_MAN_STATUS` | STM32 digital input | Firmware observation, scheduling shutdown, telemetry, and diagnostics only; it is not the safety-critical shutoff path. |
## Fail-safe behavior
- `DEAD_MAN_SIG` must be low if the steering-wheel switch is released, its
wire opens, or its source is unavailable.
- `MCU_RUN_PERMIT` and `MCU_INJECTOR_SIG` must default low during reset,
boot, brownout, or an unpowered MCU. External bias components shall provide
these states during power sequencing.
- If `ENGINE_PERMIT` becomes low during an injection command,
`SAFE_INJECTOR_SIG` becomes low and removes the command from the injection
output stage.
- If `ENGINE_PERMIT` becomes low during an ignition dwell,
`SAFE_IGNITION_INHIBIT` becomes high and commands the ignition output stage
into its non-sparking shutdown behavior.
- If the 5 V permission logic loses power, the injection command input must
be externally biased low and the ignition output stage's inhibit input must
default to its inhibited state.
## Firmware responsibilities
The hardware path is authoritative; firmware cannot override a released
dead-man switch. Firmware shall nevertheless sample `DEAD_MAN_STATUS`, clear
pending injection and ignition schedules when it becomes invalid, and keep
`MCU_RUN_PERMIT` low except while engine operation is intentionally enabled.