Failure Modes#

Coverage: 24.3% (17 of 70 items OK)

[MISSING] TRLC Failuremode Communication.AnyFunctionBlocksLongerThanExpected

Any API of mw::com (LoLa) blocks longer than expected (or indefinite)


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:20:26

[MISSING] TRLC Failuremode Communication.InMemoryConfigurationWrong

The in-memory (cpp representation) does not match the on file-system JSON configuration.


Traces to:

  • unknown tracing target req mw.com.Runtime.Initialize


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:31:26

[MISSING] TRLC Failuremode Communication.FunctionCalledFromMultipleThreads

Any API is called within multiple threads concurrently without any further synchronization.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:42:26

[MISSING] TRLC Failuremode Communication.GeneratedCodeDoesNotMatchGenerationInputs

Proxys and Skeletons as data-types are generated using the aragen and not handwritten, may not match to the input (Meta-Model).


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:53:26

[MISSING] TRLC Failuremode Communication.MisusedApis

APIs are invoked in either an invalid context or non public APIs are invoked.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:64:26

[MISSING] TRLC Failuremode Communication.CreationOfSkeletonNotPossible

It is not possible to create a skeleton instance


Traces to:

  • unknown tracing target req mw.com.Skeleton.Create


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:79:34

[MISSING] TRLC Failuremode Communication.ServiceOfferedWithoutInitialFieldValue

A service is offered, although at least one of its field has no initial value set by the provider.


Traces to:

  • unknown tracing target req mw.com.Skeleton.OfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:93:34

[MISSING] TRLC Failuremode Communication.ServiceNotOffered

A skeleton service is offering a service, but the service is silently not offered. Note: offered in this case means, that it is also connectable


Traces to:

  • unknown tracing target req mw.com.Skeleton.OfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:104:34

[MISSING] TRLC Failuremode Communication.ServiceOfferedOnWrongBinding

A skeleton is offering a service on the wrong binding. Meaning, the service is not offered on the intended binding, but on an unintended one.


Traces to:

  • unknown tracing target req mw.com.Skeleton.OfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:115:34

[MISSING] TRLC Failuremode Communication.ServiceOfferedUnderWrongIds

A skeleton is offering a service with wrong identifiers. This can include a service id, a instance id or also the service version.


Traces to:

  • unknown tracing target req mw.com.Skeleton.OfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:126:34

[MISSING] TRLC Failuremode Communication.OffersAlreadyOfferedService

A skeleton offers a service that was already offered. Either by another process or by itself.


Traces to:

  • unknown tracing target req mw.com.Skeleton.OfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:137:34

[MISSING] TRLC Failuremode Communication.ServiceOnlyPartiallyOffered

A skeleton offers a service, which is not visible to all consumers, but only to parts of them.


Traces to:

  • unknown tracing target req mw.com.Skeleton.OfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:148:34

[MISSING] TRLC Failuremode Communication.ServiceOfferingNotStopped

A skeleton offered a service, but the stop offering did not work.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:162:34

[MISSING] TRLC Failuremode Communication.ServiceOnlyPartiallyStopOffered

A skeleton stop offers a service, but the service is still seen a partial set of consumers.


Traces to:

  • unknown tracing target req mw.com.Skeleton.StopOfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:172:34

[MISSING] TRLC Failuremode Communication.ServiceStopOfferedOnWrongBinding

A skeleton is stop offering a service on the wrong binding. Meaning, the service is still offered on the actual binding.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:183:34

[MISSING] TRLC Failuremode Communication.ServiceStopOfferingWrongIds

A skeleton is stop offering a service under wrong IDs. This can include a service id, a instance id or also the service version.


Traces to:

  • unknown tracing target req mw.com.Skeleton.StopOfferService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:194:34

[MISSING] TRLC Failuremode Communication.TooFewMemoryAllocated

The event allocation allocates too few memory (including no memory at all).


Traces to:

  • unknown tracing target req mw.com.Event.Allocate


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:218:34

[MISSING] TRLC Failuremode Communication.WronglyAlignedMemoryAllocated

The memory for an event/field is allocated in a wrongly aligned manner.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:229:34

[MISSING] TRLC Failuremode Communication.TooMuchMemoryAllocated

There is too much memory allocated for one event/field


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:240:34

[MISSING] TRLC Failuremode Communication.AllocatesAlreadyAllocatedMemory

The memory for an event/field is allocated from already allocated memory (not free memory).


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:251:34

[MISSING] TRLC Failuremode Communication.SendingEventChangesUserData

A call to send manipulates the data that was provided by the caller.


Traces to:

  • unknown tracing target req mw.com.Event.Send


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:265:34

[MISSING] TRLC Failuremode Communication.SendingAnEventOrFieldSendsDataOnlyPartially

Data that is send by the user, only reaches partially the consumer. This can happen in two ways, only a partial number of consumers see the data or all consumers see only partial data.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:276:34

[MISSING] TRLC Failuremode Communication.SendingEventOnlyPartiallyNotifiesConsumer

When data is sent, consumers that have a callback registered, are only partially notified.


Traces to:

  • unknown tracing target req mw.com.Event.Send


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:287:34

[MISSING] TRLC Failuremode Communication.SendingEventSendsToWrongConsumer

An event or field is sent to the wrong consumer.


Traces to:

  • unknown tracing target req mw.com.Event.Send


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:298:34

[MISSING] TRLC Failuremode Communication.SendingAnEventOrFieldSendsSameSampleNtimes

Instead of sending a sample (one data point) only once, it is send multiple times.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:309:34

[MISSING] TRLC Failuremode Communication.SendingEventDoesNotFreeResources

Resources in the middleware that have been allocated with a previous allocation, are not freed after returning from send/update.


Traces to:

  • unknown tracing target req mw.com.Event.Send


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:320:34

[MISSING] TRLC Failuremode Communication.WrongResourcesFreed

A destruction of one skeleton instances, frees the resources of another skeleton instance.


Traces to:

  • unknown tracing target req mw.com.Skeleton.Destroy


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:334:34

[MISSING] TRLC Failuremode Communication.NoResourcesFreed

The resources allocated on construction and during operation are not freed on destruction.


Traces to:

  • unknown tracing target req mw.com.Skeleton.Destroy


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:345:34

[MISSING] TRLC Failuremode Communication.EarlyCleanUp

Resources are freed while still being used.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:356:34

[MISSING] TRLC Failuremode Communication.StartFindServiceCallbackCalledUnexpectedly

The user-provided callback is invoked, even though it should not be invoked.


Traces to:

  • unknown tracing target req mw.com.Proxy.StartFindService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:426:34

[MISSING] TRLC Failuremode Communication.ServiceNotFound

A proxy does not find a service instance, even though it was offered by a skeleton.


Traces to:

  • unknown tracing target req mw.com.Proxy.FindService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:440:34

[MISSING] TRLC Failuremode Communication.WrongServiceFound

A proxy instance finds a wrong service. This could be either a wrong service instance or a completely wrong service.


Traces to:

  • unknown tracing target req mw.com.Proxy.FindService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:451:34

[MISSING] TRLC Failuremode Communication.ServiceIsFoundButDoesNotExist

Finding a service, returns a service, even though no service instance was offered.


Traces to:

  • unknown tracing target req mw.com.Proxy.FindService


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:465:34

[MISSING] TRLC Failuremode Communication.StartedFindServiceIsNotStopped

A user called “StartFindService” with a given handler, and since “StopFindService” does not work, services can still be found.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:480:34

[MISSING] TRLC Failuremode Communication.WrongStartfindserviceIsStopped

The handle provided to StopFindService, is identified as another one and thus stops the wrong service discovery query.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:491:34

[MISSING] TRLC Failuremode Communication.DoesNotSubscribe

A proxy does not subscribe to a skeleton. Thus, a skeleton does not know that a proxy is interested in data.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:525:34

[MISSING] TRLC Failuremode Communication.ReceiveHandlerNotInvoked

A proxy has set a receive handler and a skeleton is updating an event, but the receive handler is never invoked.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:539:34

[MISSING] TRLC Failuremode Communication.ReceiveHandlerInvokedWithWrongEvent

A receive handler registered for an event, gets called because of an update of an different event.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:550:34

[MISSING] TRLC Failuremode Communication.ReceiveHandlerInvokedMultipleTimes

A receive handler is invoked multiple times, even though only one event update happend.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:560:34

[MISSING] TRLC Failuremode Communication.ReceiveHandlerInvokedWithoutEventNotification

A receive handler is invoked, even though no event update happend.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:571:34

[MISSING] TRLC Failuremode Communication.UsesToManySampleptr

User is already max. sample count SamplePtr, but we are still handing out SamplePtrs in callback F().


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:605:34

[MISSING] TRLC Failuremode Communication.ReturnsWrongSampleCount

Value returned by GetNewSample() does not match with the number of calls to callback F().


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:616:34

[MISSING] TRLC Failuremode Communication.SucceedsDespiteAnError

A user calls GetNewSamples() on a proxy instance and receives a sample count, even though he should have received an error.


Traces to:

  • unknown tracing target req mw.com.Event.GetNewSamples

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:627:34

[MISSING] TRLC Failuremode Communication.ReturnsWrongFreeSampleCount

A user has already M SamplePtr in use from a max. announced number N, but GetFreeSampleCount() returns a different value than N-M.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:642:34

[MISSING] TRLC Failuremode Communication.UnsubscribesFromWrongEvent

A user unsubscribes from an event, but the unsubscribe is silently carried out on another event.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:666:34

[MISSING] TRLC Failuremode Communication.DoesNotImplicitRemoveReceiveHandler

A proxy has registered a receive handler and unsubscribes, this should lead to the case that a receive handler is no longer called. In this failure mode, the receive handler would still be called.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:677:34

[MISSING] TRLC Failuremode Communication.IncompleteMapOfEvents

The user gets presented not all events the generic proxy supports.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:703:38

[MISSING] TRLC Failuremode Communication.TheSizeReturnedIsBiggerThenTheActualValue

The user receives a size, that is bigger then the actual value.


Traces to:

  • unknown tracing target req mw.com.GenericProxyEvent.GetSampleSize


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:717:38

[MISSING] TRLC Failuremode Communication.TheSizeReturnedIsSmallerThenTheActualSize

The user receives a size, that is smaller then the actual value.


Traces to:

  • unknown tracing target req mw.com.GenericProxyEvent.GetSampleSize

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:728:38

[MISSING] TRLC Failuremode Communication.WrongIndicationIfFormatIsSerialized

A user, using HasSerializedFormat(), receives the wrong value.


Traces to:

  • unknown tracing target req mw.com.GenericProxyEvent.HasSerializedFormat

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:740:38

[MISSING] TRLC Failuremode Communication.FreesWrongResources

A SampleAllocateePtr or SamplePtr free the wrong resources associated with them.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:820:34

[MISSING] TRLC Failuremode Communication.DoesNotReserveResources

A SamplePtr or SampleAllocateePtr do not increase their respective ref-counts and thus avoid data changes.


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:831:34

[MISSING] TRLC Failuremode Communication.DoesNotUpdateFreeSampleCountCorrectly

When a SamplePtr gets created or destroyed for a given event instance, the Free Sample Count of this instance doesn’t get updated accordingly


Traces to:

  • missing reference to Root Causes


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:842:34

[OK] TRLC Failuremode Communication.MemoryAllocatedInWrongSection

The memory for an event is allocated in the wrong memory section (e.g. in Heap, another Shared Memory segment or the stack).


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:208:34

[OK] TRLC Failuremode Communication.WrongMethodInArgsUsed

Unintended input arguments are used in a service method call. Therefore, the method call gets executed with wrong input data.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:376:34

[OK] TRLC Failuremode Communication.WrongMethodCalled

Either the wrong user provided method handler is called or no user handler is called at all. Therefore, the method call results are invalid/garbage.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:392:34

[OK] TRLC Failuremode Communication.WrongResultsProvided

The result of a method call is either not provided in the expected location, leaving uninitialized data in the expected location or it is provided in an inconsistent state. Therefore, the method call results are invalid/garbage.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:410:34

[OK] TRLC Failuremode Communication.SubscribeToWrongEvent

A service proxy subscribes to a wrong event. This either means that this event does not exist at all, is offered by another service instance, another event in the current instance or a completely different service.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:505:34

[OK] TRLC Failuremode Communication.SubscribeWithWrongMaxSampleCount

A proxy instance subscribes to an event to with a wrong sample count, meaning a different one that was provided by the user.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:515:34

[OK] TRLC Failuremode Communication.CallbackNotInvokedDespiteSamplesAvailable

GetNewSamples() gets called on an event with a callback F, but the callback gets called not at all, although at least one new sample is available.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:585:34

[OK] TRLC Failuremode Communication.CallbackInvokedWithWrongData

A proxy receives a sample pointer via callback F(), but the data does not contain the expected one.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:595:34

[OK] TRLC Failuremode Communication.DoesNotUnsubscribe

A proxy is subscribed to an event, tries to unsubscribe, but silently fails to unsubscribe.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:656:34

[OK] TRLC Failuremode Communication.MapContainingNonexistentEvents

The map that is visible to the user, contains events that are not actually existing (e.g. in the configuration).


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:693:38

[OK] TRLC Failuremode Communication.MethodCallBlocksLongerThanExpected

A call to a service-method on the client/consumer side blocks longer than expected (or indefinite). This is a specific instance of FailureMode [AnyFunctionBlocksLongerThanExpected], but since with service-methods we have concrete root causes in the form of message-passing behaviour and behaviour of user-provided handler, we have this specific failure mode.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:756:34

[OK] TRLC Failuremode Communication.WrongMethodInArgsProvided

Unintended input arguments are provided to a service method call. Therefore, the method call gets executed with wrong input data.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:773:34

[OK] TRLC Failuremode Communication.WrongReturnValueUsed

Unintended results are provided from a service method call. Therefore, the caller of the method works on wrong data.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:790:34

[OK] TRLC Failuremode Communication.DoesNotFreeResourcesOnDestruction

A SampleAllocateePtr or SamplePtr is destroyed, which should lead to a freeing of resources, but caused by a fault they are not freed.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:810:34

[OK] TRLC Failuremode Communication.ReturnsWrongData

On dereferenciation of a SamplePtr or SampleAllocateePtr wrong data is returned.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:853:34

[OK] TRLC Failuremode Communication.MethodSignatureElementPtrWrongTarget

On de-referencing of a MethodSignatureElementPtr wrong data is returned.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:873:34

[OK] TRLC Failuremode Communication.MethodSignatureElementPtrFailsToFree

On destruction of a MethodSignatureElementPtr wrong memory is freed or not freed at all.


Traces to:


Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:888:34