Part Number: F29H850TU
Hello!
I am just designing a simple circuit for a safety critical application, which must still be safe even in case of a single fault. The task is to drive a simple relay, powered from a 24V rail, which is normally active before the MCU is supplied. Now the fault that is causing me headache is a short circuit from drain to gate of the driving MOSFET:

In this case I would end up with a clamping current flowing into the GPIO and being limited only by R1. While in the powered state this wouldn't cause any issues under the assumption that the clamping current is <=2mA, things might be different during startup. On page 141 of the datasheet I read the following statement:

Obviously, this requirement is violated the first time the MCU is powered after the described fault occured. Now I am wondering, what will happen in such a case? Do I have to assume, that the MCU is chaotically switching its pins, or will it die in a safe way?
Thank you very much!
Best regards!
Christoph Egger