Control Measures
================
**Coverage:** 0.0% (0 of 37 items OK)
.. _lobster-item-c09ab6ba064b6b4be3bfd86615bc13b1dc4b3b09:
.. dropdown:: [MISSING] TRLC Aou Communication.MonotonicSemiDynamicMemoryAllocation
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that enough memory is configured for shared memory instances, in order that LoLa can perform all necessary allocations (e.g. push-back on a Vector).
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:18:14 `__
.. _lobster-item-03755f47f104d28e7fe53aa173dc846a90b7245b:
.. dropdown:: [MISSING] TRLC Aou Communication.CorrectlyConfiguredMaximumNumberOfSubscriber
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that correct maximum number of subscriber is configured for each event for each service instance.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:27:14 `__
.. _lobster-item-03c9bfe31f15a81bb199c3ebf8dd8e669844d948:
.. dropdown:: [MISSING] TRLC Aou Communication.CorrectlyConfiguredMaximumNumberOfMaximumElementsPerSubscriber
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that correct maximum number of elements per subscriber is configured for each event for each service instance.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:36:14 `__
.. _lobster-item-af3c037c428c5a93a56fe79321d7fa14d5e856e7:
.. dropdown:: [MISSING] TRLC Aou Communication.CorrectlyConfiguredAsilLevel
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that the ASIL Level on process level and per service instance is correctly configured.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:45:14 `__
.. _lobster-item-48ea83513f2164d575b1f763301c484afef47396:
.. dropdown:: [MISSING] TRLC Aou Communication.OnlyLoLaSupportedTypes
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that only types that are supported by LoLa are transmitted.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:54:14 `__
.. _lobster-item-090e0c3ac2555e9e6a60f0c505d5f917220e598e:
.. dropdown:: [MISSING] TRLC Aou Communication.NoApisFromImplementationNamespace
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that no API calls from the implementation namespace (e.g \`impl\`) are directly invoked or types from within are directly used.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:63:14 `__
.. _lobster-item-2730efd553472a7c8043c58cd8d70c34f989aead:
.. dropdown:: [MISSING] TRLC Aou Communication.NoGuaranteesForNotifications
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that a miss behavior of event notification will not harm a safety goal.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:72:14 `__
.. _lobster-item-f84291a2a5b817a11052a1e4eefd54f574fe0d6a:
.. dropdown:: [MISSING] TRLC Aou Communication.CheckingForPossibleMessageOverflow
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that a message overflow, which results in message loss will not harm a safety goal. If this is not possible, a check for message overflow and necessary actions need to be performed.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:81:14 `__
.. _lobster-item-a273cb29ca24337db37b635e869a20dbe1cc7a1f:
.. dropdown:: [MISSING] TRLC Aou Communication.DifferentUserForAsilAndQmProcesses
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that processes with a different ASIL shall be executed within different user-ids.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:90:14 `__
.. _lobster-item-b0f818390578ee9c1b3368bc62f5b8b5fd327cfb:
.. dropdown:: [MISSING] TRLC Aou Communication.ConfigOnASafeFilesystem
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that any configuration item that is read at runtime by LoLa is stored on a safety certified filesystem (according to the highest supported safety level).
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:99:14 `__
.. _lobster-item-d282b2ab507a0aac473809e222ea0eb9a17b4f60:
.. dropdown:: [MISSING] TRLC Aou Communication.NoStaticContextSupport
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that LoLa is not used within static context within C++.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:108:14 `__
.. _lobster-item-583647845938e3a0dfd85bdcdf6ab2372f9c1711:
.. dropdown:: [MISSING] TRLC Aou Communication.NoGuaranteeInAvailabilityOfServices
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that no safety goal is harmed, because a service instance is not found.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:117:14 `__
.. _lobster-item-c1f0bccfc5d58df87db5ab22c9ad5d92cb25cc53:
.. dropdown:: [MISSING] TRLC Aou Communication.NoNotificationOnTerminationOfProducer
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that termination (either gracefully or due to a malfunction) of a producer will not lead to a violation of a safety goal.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:126:14 `__
.. _lobster-item-85ae54b86d4721bf2a1844e44c46f5b0d68dcda5:
.. dropdown:: [MISSING] TRLC Aou Communication.CheckForNullptrOnAllocate
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be checked if Allocate() on an event will return a nullptr. If a nullptr is returned, the system shall transition to safe state.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:135:14 `__
.. _lobster-item-777fbf9cc9fcf07d709eb07f9430a28521631545:
.. dropdown:: [MISSING] TRLC Aou Communication.OneProducerOnlyOneAllocateePtr
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that at any time a producer instance per event only holds one AllocateePtr.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:144:14 `__
.. _lobster-item-72ce560e84643e38a5df3fe8f94d32b8688dd40d:
.. dropdown:: [MISSING] TRLC Aou Communication.NoCopySendWhileHoldingAllocateePtr
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that Send(const& value) is not invoked while an AllocateePtr is held.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:153:14 `__
.. _lobster-item-2d312ad1c0569e6bcfde0310cb820c7ab9cfe3f3:
.. dropdown:: [MISSING] TRLC Aou Communication.NoneReentrantMethodsPerEventInstance
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that any LoLa API that is bound to a specific event instance is not called in a reentrant manner.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:162:14 `__
.. _lobster-item-c012c0506fc8580cf0682752eb5394380b787f3d:
.. dropdown:: [MISSING] TRLC Aou Communication.SkeletonAliveWhileItsAllocateePtrBeingUsed
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that a Skeleton instance is still alive while any AllocateePtr returned by it is used.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:171:14 `__
.. _lobster-item-b97c4c4f2999e9b6953386bde558da0edc790852:
.. dropdown:: [MISSING] TRLC Aou Communication.EventSubscriptionActiveWhileHoldingSamplePtr
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that Unsubscribe() isn't called on a proxy event instance as long as any SamplePtr provided by it, is still held. Also the corresponding proxy instance shall be kept alive as on destruction it would implicitly call Unsubscribe().
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:180:14 `__
.. _lobster-item-e26cbb3987a7a87169215ea4df3447b488624bab:
.. dropdown:: [MISSING] TRLC Aou Communication.NoneTerminatingCallbacks
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that any callback passed to LoLa for invocation is not throwing.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:189:14 `__
.. _lobster-item-32e286b3c7b03bed02ea9f039a0945f16de32c19:
.. dropdown:: [MISSING] TRLC Aou Communication.ValidCallbacksWhileProxyAlive
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that all callbacks passed towards LoLa are valid as long as the associated proxy is alive.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:198:14 `__
.. _lobster-item-5258f29d1992309b5e6e873a96c48dceef264477:
.. dropdown:: [MISSING] TRLC Aou Communication.QualityOfDataIsDependentOnProducer
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that the necessary quality of data is produced by the respective skeleton process.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:207:14 `__
.. _lobster-item-566dc08d1d36a5ba4a57b8482476bfa1ba4cb621:
.. dropdown:: [MISSING] TRLC Aou Communication.ValidityOfPointerOnLoLaPointer
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that no pointer, pointing to the memory of a SamplePtr or AllocateePtr is used once the SamplePtr or AllocateePtr are invalid.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:216:14 `__
.. _lobster-item-f9873daf9de1d83293285c8f2f92f503b875610e:
.. dropdown:: [MISSING] TRLC Aou Communication.LoLaMemoryOnlyAccessedThroughLoLa
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that no other code accesses the mapped memory managed by LoLa.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:225:14 `__
.. _lobster-item-84c6fec0909f196f7186f59a544754a20074f106:
.. dropdown:: [MISSING] TRLC Aou Communication.NoSharedMemoryAllocationInNamespaceLola
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that no other code creates shared memory segments beginning with "lola".
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:234:14 `__
.. _lobster-item-b02bb36c510303a5b1fc0b07ac89690b58264bd1:
.. dropdown:: [MISSING] TRLC Aou Communication.OnlyQnx71Supported
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that any application containing LoLa is only executed on QNX Safe Operating System 7.1.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:243:14 `__
.. _lobster-item-de6435ba884bf76fdb6815f895f724a42454adb3:
.. dropdown:: [MISSING] TRLC Aou Communication.LoLaSpecificQnxMessagingEndPointsOnlyAccessedThroughLoLa
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that the LoLa specific QNX Message Passing end-points are only accessed through LoLa APIs.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:252:14 `__
.. _lobster-item-a58288e3a0a15222c144baacbda2737052a09cc6:
.. dropdown:: [MISSING] TRLC Aou Communication.AragenNotSafe
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
Input artifacts shall be manually reviewed for correctness
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:261:14 `__
.. _lobster-item-61321fcf37d44bc8ed6e65059ec863aceae30549:
.. dropdown:: [MISSING] TRLC Aou Communication.UnsupportedDataTypes
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that neither variants nor maps are sent via LoLa.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:270:14 `__
.. _lobster-item-b2430fe3e08b0bb0b6339ce57de7393f3efcdc5b:
.. dropdown:: [MISSING] TRLC Aou Communication.NoGuaranteeOnExecutionTime
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
There is no guarantee on the execution time of any function call provided by LoLa.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:279:14 `__
.. _lobster-item-10dd73fc05a1b460273b780afd0d43251c65b441:
.. dropdown:: [MISSING] TRLC Aou Communication.UsageOfConfigurationOversubscription
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
If event instance "oversubscription" is enabled, LoLa makes no warranty that proxies/consumers can't suffer from data loss! It is the responsibility of the user to adapt scheduling/event-data access in a way that no data-loss happens.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:288:14 `__
.. _lobster-item-fc0b478a32eda807e0318927ac7e087fb0e57608:
.. dropdown:: [MISSING] TRLC Aou Communication.SameCompilerSettingsForProviderAndConsumerSide
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
All compiler settings having influence on the binary representation of data exchanged via {{mw::com}}/{{LoLa}} (event, field, service-method payloads) have to be identical for compilation of code containing {{mw::com}} proxies and skeletons, which communicate.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:297:14 `__
.. _lobster-item-95b3e4587895d128fc833bbc261f9e5c083bc005:
.. dropdown:: [MISSING] TRLC Aou Communication.EventOrFieldReceptionViaGenericProxyNeedsSpecificCare
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
When receiving event or field data via untyped {{GenericProxyEvent}} or {{GenericProxyField}}, care has to be taken when accessing the corresponding {{SamplePtr}} delivered by calls to {{GetNewSamples()}}: When casting it to the expected type, it needs to be checked that no access behind the size returned by {{GetSampleSize()}} will happen.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:305:14 `__
.. _lobster-item-5e1ffd99c0ec68986de86fec69da42e53effd453:
.. dropdown:: [MISSING] TRLC Aou Communication.CorrectlyConfiguredEventsFieldsPerServiceType
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that all safety relevant events/fields in the service type are the same in all configurations.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:313:14 `__
.. _lobster-item-58cde65152979042d0d828ee3af633ba8b642daa:
.. dropdown:: [MISSING] TRLC Aou Communication.NoGuaranteesForTimelyMethodCallExecution
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that a blocking method call will not harm a safety goal.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:322:14 `__
.. _lobster-item-70d1ddc0709d252030648d9da0dee88ee2cfc789:
.. dropdown:: [MISSING] TRLC Aou Communication.MethodInArgPtrMatches
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
It shall be ensured that the memory locations of the method call in-arguments provided at the caller side are exactly the same as the memory locations as used at the callee side.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:331:14 `__
.. _lobster-item-a83740b20ac222d904aa6e21021c45c5810d8c08:
.. dropdown:: [MISSING] TRLC Aou Communication.NoGuaranteeOnSubscriptionStateCorrectness
:open:
:class-title: sd-bg-danger sd-text-white
.. pull-quote::
For safety critical use cases, an application must treat a SubscriptionState of kSubscribed or kSubscriptionPending (returned by GetSubscriptionState() or reported by the SubscriptionStateChangeHandler) as the same.
.. raw:: html
**Traces to:**
.. card::
:class-card: lobster-issue-card
* missing reference to Root Causes
.. raw:: html
**Source:** `score/mw/com/dependability/safety\_analysis/aou.trlc:340:14 `__