Assumptions of Use#

Communication.MonotonicSemiDynamicMemoryAllocation#

It shall be ensured that enough memory is configured for shared memory instances, in order that LoLa can perform all necessary allocations (e.g. push-back on a Vector).

Communication.CorrectlyConfiguredMaximumNumberOfSubscriber#

It shall be ensured that correct maximum number of subscriber is configured for each event for each service instance.

Communication.CorrectlyConfiguredMaximumNumberOfMaximumElementsPerSubscriber#

It shall be ensured that correct maximum number of elements per subscriber is configured for each event for each service instance.

Communication.CorrectlyConfiguredAsilLevel#

It shall be ensured that the ASIL Level on process level and per service instance is correctly configured.

Communication.OnlyLoLaSupportedTypes#

It shall be ensured that only types that are supported by LoLa are transmitted.

Communication.NoApisFromImplementationNamespace#

It shall be ensured that no API calls from the implementation namespace (e.g impl) are directly invoked or types from within are directly used.

Communication.NoGuaranteesForNotifications#

It shall be ensured that a miss behavior of event notification will not harm a safety goal.

Communication.CheckingForPossibleMessageOverflow#

It shall be ensured that a message overflow, which results in message loss will not harm a safety goal. If this is not possible, a check for message overflow and necessary actions need to be performed.

Communication.DifferentUserForAsilAndQmProcesses#

It shall be ensured that processes with a different ASIL shall be executed within different user-ids.

Communication.ConfigOnASafeFilesystem#

It shall be ensured that any configuration item that is read at runtime by LoLa is stored on a safety certified filesystem (according to the highest supported safety level).

Communication.NoStaticContextSupport#

It shall be ensured that LoLa is not used within static context within C++.

Communication.NoGuaranteeInAvailabilityOfServices#

It shall be ensured that no safety goal is harmed, because a service instance is not found.

Communication.NoNotificationOnTerminationOfProducer#

It shall be ensured that termination (either gracefully or due to a malfunction) of a producer will not lead to a violation of a safety goal.

Communication.CheckForNullptrOnAllocate#

It shall be checked if Allocate() on an event will return a nullptr. If a nullptr is returned, the system shall transition to safe state.

Communication.OneProducerOnlyOneAllocateePtr#

It shall be ensured that at any time a producer instance per event only holds one AllocateePtr.

Communication.NoCopySendWhileHoldingAllocateePtr#

It shall be ensured that Send(const& value) is not invoked while an AllocateePtr is held.

Communication.NoneReentrantMethodsPerEventInstance#

It shall be ensured that any LoLa API that is bound to a specific event instance is not called in a reentrant manner.

Communication.SkeletonAliveWhileItsAllocateePtrBeingUsed#

It shall be ensured that a Skeleton instance is still alive while any AllocateePtr returned by it is used.

Communication.EventSubscriptionActiveWhileHoldingSamplePtr#

It shall be ensured that Unsubscribe() isn’t called on a proxy event instance as long as any SamplePtr provided by it, is still held. Also the corresponding proxy instance shall be kept alive as on destruction it would implicitly call Unsubscribe().

Communication.NoneTerminatingCallbacks#

It shall be ensured that any callback passed to LoLa for invocation is not throwing.

Communication.ValidCallbacksWhileProxyAlive#

It shall be ensured that all callbacks passed towards LoLa are valid as long as the associated proxy is alive.

Communication.QualityOfDataIsDependentOnProducer#

It shall be ensured that the necessary quality of data is produced by the respective skeleton process.

Communication.ValidityOfPointerOnLoLaPointer#

It shall be ensured that no pointer, pointing to the memory of a SamplePtr or AllocateePtr is used once the SamplePtr or AllocateePtr are invalid.

Communication.LoLaMemoryOnlyAccessedThroughLoLa#

It shall be ensured that no other code accesses the mapped memory managed by LoLa.

Communication.NoSharedMemoryAllocationInNamespaceLola#

It shall be ensured that no other code creates shared memory segments beginning with “lola”.

Communication.OnlyQnx71Supported#

It shall be ensured that any application containing LoLa is only executed on QNX Safe Operating System 7.1.

Communication.LoLaSpecificQnxMessagingEndPointsOnlyAccessedThroughLoLa#

It shall be ensured that the LoLa specific QNX Message Passing end-points are only accessed through LoLa APIs.

Communication.AragenNotSafe#

Input artifacts shall be manually reviewed for correctness

Communication.UnsupportedDataTypes#

It shall be ensured that neither variants nor maps are sent via LoLa.

Communication.NoGuaranteeOnExecutionTime#

There is no guarantee on the execution time of any function call provided by LoLa.

Communication.UsageOfConfigurationOversubscription#

If event instance “oversubscription” is enabled, LoLa makes no warranty that proxies/consumers can’t suffer from data loss! It is the responsibility of the user to adapt scheduling/event-data access in a way that no data-loss happens.

Communication.SameCompilerSettingsForProviderAndConsumerSide#

All compiler settings having influence on the binary representation of data exchanged via {{mw::com}}/{{LoLa}} (event, field, service-method payloads) have to be identical for compilation of code containing {{mw::com}} proxies and skeletons, which communicate.

Communication.EventOrFieldReceptionViaGenericProxyNeedsSpecificCare#

When receiving event or field data via untyped {{GenericProxyEvent}} or {{GenericProxyField}}, care has to be taken when accessing the corresponding {{SamplePtr<void>}} delivered by calls to {{GetNewSamples()}}: When casting it to the expected type, it needs to be checked that no access behind the size returned by {{GetSampleSize()}} will happen.

Communication.CorrectlyConfiguredEventsFieldsPerServiceType#

It shall be ensured that all safety relevant events/fields in the service type are the same in all configurations.

Communication.NoGuaranteesForTimelyMethodCallExecution#

It shall be ensured that a blocking method call will not harm a safety goal.

Communication.MethodInArgPtrMatches#

It shall be ensured that the memory locations of the method call in-arguments provided at the caller side are exactly the same as the memory locations as used at the callee side.

Communication.NoGuaranteeOnSubscriptionStateCorrectness#

For safety critical use cases, an application must treat a SubscriptionState of kSubscribed or kSubscriptionPending (returned by GetSubscriptionState() or reported by the SubscriptionStateChangeHandler) as the same.