How does the dual ECU redundancy work?
If the "active" ECU has a glitch that makes it do something nonsensical but doesn't detect an internal fault then how will the engine react? Does the "standby" ECU continuously monitor the active one to make sure that it is still working or it only take control if the active ECU detects a problem?
Consider a scenario:
- ECU 1 and 2 are powered on (both lane switches ON)
- A stray cosmic ray hits ECU 1 and a single bit in the internal map that deals in mixture is flipped
- No internal fault is detected by ECU 1 so it tries to run the engine dangerously rich
Would it destroy the engine or would ECU 2 say hey there's something fishy going on here and take control?
If it was 3 redundant systems then the solution would be obvious because they would all operate at once and if any of the three disagrees for any reason then it is the one glitching and it is disabled but in this case there's only 2. So how does the redundancy work?
https://www.redimec.com.ar/contenido/productos/pdf/1426604215_1.pdf is very scant on detail.