- try power cycling now instead of going to faulty immediately
- after too many power cycles in a short time frame, go to faulty
- new FDIR/recovery helper which is generic
- new failure variants for fault injection: transient failures to test
that a power cycles could fix the issue
Add satrs::fdir::FaultCounter, an FSFW-style error threshold counter:
counts faults, decrements over time when faults stop, and reports
when a threshold is exceeded. Two variants for now, mirroring the
hk.rs helper pattern:
- FaultCounterStd, backed by std::time::Instant
- FaultCounterEmbassy, backed by embassy_time::Instant (embassy-time
feature), with an optional defmt::Format impl gated on the defmt
feature
Add satrs::health::HealthTableMapSync::default() for easy construction
of a shared, global health table.
Wire both into the example app's MGM device handler as the first real
FDIR use case:
- the minisim MGM model gains SpiFaultMode (None/AllZeros/AllOnes) and
a SetSpiFault request, so a stuck SPI bus can be injected for testing,
independent of switch state
- MgmHandlerLis3Mdl::poll_sensor checks the SPI transfer result: a
comm timeout or an all-1s stuck-bus reply (the same pattern the sim
already uses for "device off") counts as a fault. Above threshold,
the component is marked Faulty in a HealthTableMapSync shared from
main.rs. This logic lives in the device handler, not the SPI comm
layer, since deciding what a failed transfer means for FDIR is a
handler concern.
- an all-0s reply is deliberately not treated as a fault, since it
collides with a legitimate zero-field reading