One minor nit, it's not halt-on-error, it's restart-on-error since the watchdog then restarts the system. The technical term for this is rejuvenation and it's standard practice in SCADA and similar to deal with this-shouldn't-happen error conditions.