Real-Time Clock, Diagnostics & Watchdog
Energy management and tariff calculations require mathematically verifiable timestamps. The RTC & Diagnostics Subsystem guarantees timing accuracy and system health monitoring across all operational states.
1. Real-Time Clock & Trusted Time Bootstrap
The converter features a dedicated hardware RTC (NXP PCF8523 or Maxim DS3231) backed by a lithium coin-cell battery (CR1220):
flowchart TD
Boot["Converter Boot / Reset"] --> ReadRTC["Read Hardware RTC via I2C"]
ReadRTC --> ValidateBCD{"Is RTC Date Valid &
Year >= 2026?"}
ValidateBCD -->|Yes| SetClock["Set System Clock
(Trusted Time = TRUE)"]
ValidateBCD -->|"No / Corrupt"| FlagUntrusted["Set System Clock to Epoch Fallback
(Trusted Time = FALSE)"]
SetClock --> CheckNTP{"Wi-Fi Connected &
NTP Server Reachable?"}
FlagUntrusted --> CheckNTP
CheckNTP -->|Yes| SyncNTP["Query NTP Server
(Smooth Slew Rate Adjustment)"]
SyncNTP --> UpdateRTC["Write Fresh Calibrated Timestamp to RTC"]
CheckNTP -->|"No / Offline"| ContinueRunning["Continue Running on RTC Battery Clock"]
Trusted Time Invariant
- Energy Cooperative Requirement: Polish energy billing regulations require timestamped meter samples to verify 15-minute consumption and generation blocks.
- Trusted Time Flag: In every telemetry record, the boolean field
trusted_timeindicates whether the timestamp is backed by a verified RTC or calibrated NTP source. If the battery is exhausted and NTP is unavailable, records are flagged as untrusted, alerting operators to replace the coin cell.
2. Hardware Watchdog Timer
The converter utilizes the RP2350 internal hardware watchdog:
- Timeout Window: Fixed at 8,000 milliseconds (8 seconds).
- Feeding Mechanism: The high-priority Diagnostics task checks all active FreeRTOS task health flags (Modbus task, Storage task, Network task). The watchdog is fed only when all tasks report healthy iteration counters.
- Deadlock Recovery: If any task locks in an infinite loop or encounters a hardware bus stall, the watchdog forces a clean hardware reset within 8 seconds, recording the fault in the non-volatile diagnostic log.
3. Diagnostic Alarms & Health Monitoring
The firmware maintains continuous health monitoring exposed in the /api/status endpoint:
| Alarm Code | Severity | Trigger Condition | Automated Remediation |
|---|---|---|---|
ALARM_RTC_BATTERY_LOW | Warning | RTC battery voltage $< 2.5\text{ V}$ | Flag telemetry as warning; notify installer. |
ALARM_SD_CORRUPTED | Error | AES-256-GCM tag mismatch on block | Automatic sector repair from secondary mirror. |
ALARM_SD_MISSING | Warning | MicroSD card unseated or unformatted | Switch to internal LittleFS FIFO exclusively. |
ALARM_MODBUS_BUS_STALL | Error | 10 consecutive timeouts across bus | Reset RS-485 transceiver via GPIO power cycle. |
ALARM_LOGIN_LOCKOUT | Security | 5 invalid PIN attempts | Enforce 15-minute authentication lockout. |