Skip to content

Real-Time Clock, Diagnostics & Watchdog

Energy management and tariff calculations require mathematically verifiable timestamps. The RTC & Diagnostics Subsystem guarantees timing accuracy and system health monitoring across all operational states.


1. Real-Time Clock & Trusted Time Bootstrap

The converter features a dedicated hardware RTC (NXP PCF8523 or Maxim DS3231) backed by a lithium coin-cell battery (CR1220):

flowchart TD
    Boot["Converter Boot / Reset"] --> ReadRTC["Read Hardware RTC via I2C"]
    ReadRTC --> ValidateBCD{"Is RTC Date Valid &
Year >= 2026?"} ValidateBCD -->|Yes| SetClock["Set System Clock
(Trusted Time = TRUE)"] ValidateBCD -->|"No / Corrupt"| FlagUntrusted["Set System Clock to Epoch Fallback
(Trusted Time = FALSE)"] SetClock --> CheckNTP{"Wi-Fi Connected &
NTP Server Reachable?"} FlagUntrusted --> CheckNTP CheckNTP -->|Yes| SyncNTP["Query NTP Server
(Smooth Slew Rate Adjustment)"] SyncNTP --> UpdateRTC["Write Fresh Calibrated Timestamp to RTC"] CheckNTP -->|"No / Offline"| ContinueRunning["Continue Running on RTC Battery Clock"]

Trusted Time Invariant

  • Energy Cooperative Requirement: Polish energy billing regulations require timestamped meter samples to verify 15-minute consumption and generation blocks.
  • Trusted Time Flag: In every telemetry record, the boolean field trusted_time indicates whether the timestamp is backed by a verified RTC or calibrated NTP source. If the battery is exhausted and NTP is unavailable, records are flagged as untrusted, alerting operators to replace the coin cell.

2. Hardware Watchdog Timer

The converter utilizes the RP2350 internal hardware watchdog:

  • Timeout Window: Fixed at 8,000 milliseconds (8 seconds).
  • Feeding Mechanism: The high-priority Diagnostics task checks all active FreeRTOS task health flags (Modbus task, Storage task, Network task). The watchdog is fed only when all tasks report healthy iteration counters.
  • Deadlock Recovery: If any task locks in an infinite loop or encounters a hardware bus stall, the watchdog forces a clean hardware reset within 8 seconds, recording the fault in the non-volatile diagnostic log.

3. Diagnostic Alarms & Health Monitoring

The firmware maintains continuous health monitoring exposed in the /api/status endpoint:

Alarm CodeSeverityTrigger ConditionAutomated Remediation
ALARM_RTC_BATTERY_LOWWarningRTC battery voltage $< 2.5\text{ V}$Flag telemetry as warning; notify installer.
ALARM_SD_CORRUPTEDErrorAES-256-GCM tag mismatch on blockAutomatic sector repair from secondary mirror.
ALARM_SD_MISSINGWarningMicroSD card unseated or unformattedSwitch to internal LittleFS FIFO exclusively.
ALARM_MODBUS_BUS_STALLError10 consecutive timeouts across busReset RS-485 transceiver via GPIO power cycle.
ALARM_LOGIN_LOCKOUTSecurity5 invalid PIN attemptsEnforce 15-minute authentication lockout.