
5 Operating System
System Manual Modular Systems
Page 32 of 114
HI 800 191 E Rev. 2.02
Permanent faults on inputs or outputs
Temporary faults on inputs or outputs
Internal Faults
5.3.1
Permanent Faults on Inputs or Outputs
A fault on an input or output channel has not effect on the controller. The operating system only
considers the defective channel as faulty, and not the entire controller. The remaining safety
functions are not affected and remain active.
If the input channels are faulty, the operating system sends the safe value 0 or the initial value
for further processing.
Faulty output channels are set to the de-energized state by the operating system. If it is not
possible to only switch off a single channel, the entire output module is considered as faulty.
The operating system sets the fault status signal and reports the type of fault to the user
program.
If the controller is not able to switch off a given output and even the second switch-off option is
not effective, the controller enters the STOP state. The outputs are then switched off by the
watchdog of the processor system.
If faults are present in the I/O modules for longer than 24 hours, only the affected I/O modules
are permanently switched off by the controller.
5.3.2
Temporary Faults on Inputs or Outputs
If a fault occurs in an input or output module and disappears by itself, the operating system
resets the fault status and resumes normal operation.
The operating system statistically evaluates the frequency with which a fault occurs. If the
specified fault frequency is exceeded, it permanently sets the module status to
faulty
. In this
way, the module no longer operates, even if the fault disappears. The module is released and
the fault statistics are reset when the controller operating state switches from STOP to RUN.
This change acknowledges the module fault.
5.3.3
Internal Faults
In the rare case of an internal fault within the HIMatrix controller, the fault reaction depends on
the version of the operating system loaded into the controller:
Processor OS up to V6.44 for controllers, and up to V6.42 for remote I/Os:
The HIMatrix controller enters the ERROR STOP state, and all outputs adopt the safe (de-
energized) state. The HIMatrix controller must be restarted manually, e.g., using the
programming tool.
For controllers, processor OS V6.44 and higher, and for remote I/Os V6.42 and higher:
The HIMatrix controller is automatically started. Should an internal fault be detected again
within the first minute after start up, the HIMatrix controller will remain in the STOP/INVALID
CONFIGURATION state.
5.4
The Processor System
The processor system is the central component of the controller and communicates with the I/O
modules of the controller via the I/O bus.
The processor system monitors the sequence and the proper, logical execution of the operating
system and user program. The following functions are monitored with respect to time:
Hardware and software self-tests of the processor system
RUN cycle of the processor system (including the user program)
I/O tests and processing of I/O signals