Failure Modes#
Coverage: 24.3% (17 of 70 items OK)
[MISSING] TRLC Failuremode Communication.AnyFunctionBlocksLongerThanExpected
Any API of mw::com (LoLa) blocks longer than expected (or indefinite)
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:20:26
[MISSING] TRLC Failuremode Communication.InMemoryConfigurationWrong
The in-memory (cpp representation) does not match the on file-system JSON configuration.
Traces to:
unknown tracing target req mw.com.Runtime.Initialize
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:31:26
[MISSING] TRLC Failuremode Communication.FunctionCalledFromMultipleThreads
Any API is called within multiple threads concurrently without any further synchronization.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:42:26
[MISSING] TRLC Failuremode Communication.GeneratedCodeDoesNotMatchGenerationInputs
Proxys and Skeletons as data-types are generated using the aragen and not handwritten, may not match to the input (Meta-Model).
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:53:26
[MISSING] TRLC Failuremode Communication.MisusedApis
APIs are invoked in either an invalid context or non public APIs are invoked.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:64:26
[MISSING] TRLC Failuremode Communication.CreationOfSkeletonNotPossible
It is not possible to create a skeleton instance
Traces to:
unknown tracing target req mw.com.Skeleton.Create
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:79:34
[MISSING] TRLC Failuremode Communication.ServiceOfferedWithoutInitialFieldValue
A service is offered, although at least one of its field has no initial value set by the provider.
Traces to:
unknown tracing target req mw.com.Skeleton.OfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:93:34
[MISSING] TRLC Failuremode Communication.ServiceNotOffered
A skeleton service is offering a service, but the service is silently not offered. Note: offered in this case means, that it is also connectable
Traces to:
unknown tracing target req mw.com.Skeleton.OfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:104:34
[MISSING] TRLC Failuremode Communication.ServiceOfferedOnWrongBinding
A skeleton is offering a service on the wrong binding. Meaning, the service is not offered on the intended binding, but on an unintended one.
Traces to:
unknown tracing target req mw.com.Skeleton.OfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:115:34
[MISSING] TRLC Failuremode Communication.ServiceOfferedUnderWrongIds
A skeleton is offering a service with wrong identifiers. This can include a service id, a instance id or also the service version.
Traces to:
unknown tracing target req mw.com.Skeleton.OfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:126:34
[MISSING] TRLC Failuremode Communication.OffersAlreadyOfferedService
A skeleton offers a service that was already offered. Either by another process or by itself.
Traces to:
unknown tracing target req mw.com.Skeleton.OfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:137:34
[MISSING] TRLC Failuremode Communication.ServiceOnlyPartiallyOffered
A skeleton offers a service, which is not visible to all consumers, but only to parts of them.
Traces to:
unknown tracing target req mw.com.Skeleton.OfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:148:34
[MISSING] TRLC Failuremode Communication.ServiceOfferingNotStopped
A skeleton offered a service, but the stop offering did not work.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:162:34
[MISSING] TRLC Failuremode Communication.ServiceOnlyPartiallyStopOffered
A skeleton stop offers a service, but the service is still seen a partial set of consumers.
Traces to:
unknown tracing target req mw.com.Skeleton.StopOfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:172:34
[MISSING] TRLC Failuremode Communication.ServiceStopOfferedOnWrongBinding
A skeleton is stop offering a service on the wrong binding. Meaning, the service is still offered on the actual binding.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:183:34
[MISSING] TRLC Failuremode Communication.ServiceStopOfferingWrongIds
A skeleton is stop offering a service under wrong IDs. This can include a service id, a instance id or also the service version.
Traces to:
unknown tracing target req mw.com.Skeleton.StopOfferService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:194:34
[MISSING] TRLC Failuremode Communication.TooFewMemoryAllocated
The event allocation allocates too few memory (including no memory at all).
Traces to:
unknown tracing target req mw.com.Event.Allocate
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:218:34
[MISSING] TRLC Failuremode Communication.WronglyAlignedMemoryAllocated
The memory for an event/field is allocated in a wrongly aligned manner.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:229:34
[MISSING] TRLC Failuremode Communication.TooMuchMemoryAllocated
There is too much memory allocated for one event/field
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:240:34
[MISSING] TRLC Failuremode Communication.AllocatesAlreadyAllocatedMemory
The memory for an event/field is allocated from already allocated memory (not free memory).
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:251:34
[MISSING] TRLC Failuremode Communication.SendingEventChangesUserData
A call to send manipulates the data that was provided by the caller.
Traces to:
unknown tracing target req mw.com.Event.Send
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:265:34
[MISSING] TRLC Failuremode Communication.SendingAnEventOrFieldSendsDataOnlyPartially
Data that is send by the user, only reaches partially the consumer. This can happen in two ways, only a partial number of consumers see the data or all consumers see only partial data.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:276:34
[MISSING] TRLC Failuremode Communication.SendingEventOnlyPartiallyNotifiesConsumer
When data is sent, consumers that have a callback registered, are only partially notified.
Traces to:
unknown tracing target req mw.com.Event.Send
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:287:34
[MISSING] TRLC Failuremode Communication.SendingEventSendsToWrongConsumer
An event or field is sent to the wrong consumer.
Traces to:
unknown tracing target req mw.com.Event.Send
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:298:34
[MISSING] TRLC Failuremode Communication.SendingAnEventOrFieldSendsSameSampleNtimes
Instead of sending a sample (one data point) only once, it is send multiple times.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:309:34
[MISSING] TRLC Failuremode Communication.SendingEventDoesNotFreeResources
Resources in the middleware that have been allocated with a previous allocation, are not freed after returning from send/update.
Traces to:
unknown tracing target req mw.com.Event.Send
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:320:34
[MISSING] TRLC Failuremode Communication.WrongResourcesFreed
A destruction of one skeleton instances, frees the resources of another skeleton instance.
Traces to:
unknown tracing target req mw.com.Skeleton.Destroy
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:334:34
[MISSING] TRLC Failuremode Communication.NoResourcesFreed
The resources allocated on construction and during operation are not freed on destruction.
Traces to:
unknown tracing target req mw.com.Skeleton.Destroy
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:345:34
[MISSING] TRLC Failuremode Communication.EarlyCleanUp
Resources are freed while still being used.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:356:34
[MISSING] TRLC Failuremode Communication.StartFindServiceCallbackCalledUnexpectedly
The user-provided callback is invoked, even though it should not be invoked.
Traces to:
unknown tracing target req mw.com.Proxy.StartFindService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:426:34
[MISSING] TRLC Failuremode Communication.ServiceNotFound
A proxy does not find a service instance, even though it was offered by a skeleton.
Traces to:
unknown tracing target req mw.com.Proxy.FindService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:440:34
[MISSING] TRLC Failuremode Communication.WrongServiceFound
A proxy instance finds a wrong service. This could be either a wrong service instance or a completely wrong service.
Traces to:
unknown tracing target req mw.com.Proxy.FindService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:451:34
[MISSING] TRLC Failuremode Communication.ServiceIsFoundButDoesNotExist
Finding a service, returns a service, even though no service instance was offered.
Traces to:
unknown tracing target req mw.com.Proxy.FindService
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:465:34
[MISSING] TRLC Failuremode Communication.StartedFindServiceIsNotStopped
A user called “StartFindService” with a given handler, and since “StopFindService” does not work, services can still be found.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:480:34
[MISSING] TRLC Failuremode Communication.WrongStartfindserviceIsStopped
The handle provided to StopFindService, is identified as another one and thus stops the wrong service discovery query.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:491:34
[MISSING] TRLC Failuremode Communication.DoesNotSubscribe
A proxy does not subscribe to a skeleton. Thus, a skeleton does not know that a proxy is interested in data.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:525:34
[MISSING] TRLC Failuremode Communication.ReceiveHandlerNotInvoked
A proxy has set a receive handler and a skeleton is updating an event, but the receive handler is never invoked.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:539:34
[MISSING] TRLC Failuremode Communication.ReceiveHandlerInvokedWithWrongEvent
A receive handler registered for an event, gets called because of an update of an different event.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:550:34
[MISSING] TRLC Failuremode Communication.ReceiveHandlerInvokedMultipleTimes
A receive handler is invoked multiple times, even though only one event update happend.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:560:34
[MISSING] TRLC Failuremode Communication.ReceiveHandlerInvokedWithoutEventNotification
A receive handler is invoked, even though no event update happend.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:571:34
[MISSING] TRLC Failuremode Communication.UsesToManySampleptr
User is already max. sample count SamplePtr, but we are still handing out SamplePtrs in callback F().
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:605:34
[MISSING] TRLC Failuremode Communication.ReturnsWrongSampleCount
Value returned by GetNewSample() does not match with the number of calls to callback F().
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:616:34
[MISSING] TRLC Failuremode Communication.SucceedsDespiteAnError
A user calls GetNewSamples() on a proxy instance and receives a sample count, even though he should have received an error.
Traces to:
unknown tracing target req mw.com.Event.GetNewSamples
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:627:34
[MISSING] TRLC Failuremode Communication.ReturnsWrongFreeSampleCount
A user has already M SamplePtr in use from a max. announced number N, but GetFreeSampleCount() returns a different value than N-M.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:642:34
[MISSING] TRLC Failuremode Communication.UnsubscribesFromWrongEvent
A user unsubscribes from an event, but the unsubscribe is silently carried out on another event.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:666:34
[MISSING] TRLC Failuremode Communication.DoesNotImplicitRemoveReceiveHandler
A proxy has registered a receive handler and unsubscribes, this should lead to the case that a receive handler is no longer called. In this failure mode, the receive handler would still be called.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:677:34
[MISSING] TRLC Failuremode Communication.IncompleteMapOfEvents
The user gets presented not all events the generic proxy supports.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:703:38
[MISSING] TRLC Failuremode Communication.TheSizeReturnedIsBiggerThenTheActualValue
The user receives a size, that is bigger then the actual value.
Traces to:
unknown tracing target req mw.com.GenericProxyEvent.GetSampleSize
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:717:38
[MISSING] TRLC Failuremode Communication.TheSizeReturnedIsSmallerThenTheActualSize
The user receives a size, that is smaller then the actual value.
Traces to:
unknown tracing target req mw.com.GenericProxyEvent.GetSampleSize
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:728:38
[MISSING] TRLC Failuremode Communication.WrongIndicationIfFormatIsSerialized
A user, using HasSerializedFormat(), receives the wrong value.
Traces to:
unknown tracing target req mw.com.GenericProxyEvent.HasSerializedFormat
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:740:38
[MISSING] TRLC Failuremode Communication.FreesWrongResources
A SampleAllocateePtr or SamplePtr free the wrong resources associated with them.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:820:34
[MISSING] TRLC Failuremode Communication.DoesNotReserveResources
A SamplePtr or SampleAllocateePtr do not increase their respective ref-counts and thus avoid data changes.
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:831:34
[MISSING] TRLC Failuremode Communication.DoesNotUpdateFreeSampleCountCorrectly
When a SamplePtr gets created or destroyed for a given event instance, the Free Sample Count of this instance doesn’t get updated accordingly
Traces to:
missing reference to Root Causes
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:842:34
[OK] TRLC Failuremode Communication.MemoryAllocatedInWrongSection
The memory for an event is allocated in the wrong memory section (e.g. in Heap, another Shared Memory segment or the stack).
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:208:34
[OK] TRLC Failuremode Communication.WrongMethodInArgsUsed
Unintended input arguments are used in a service method call. Therefore, the method call gets executed with wrong input data.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:376:34
[OK] TRLC Failuremode Communication.WrongMethodCalled
Either the wrong user provided method handler is called or no user handler is called at all. Therefore, the method call results are invalid/garbage.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:392:34
[OK] TRLC Failuremode Communication.WrongResultsProvided
The result of a method call is either not provided in the expected location, leaving uninitialized data in the expected location or it is provided in an inconsistent state. Therefore, the method call results are invalid/garbage.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:410:34
[OK] TRLC Failuremode Communication.SubscribeToWrongEvent
A service proxy subscribes to a wrong event. This either means that this event does not exist at all, is offered by another service instance, another event in the current instance or a completely different service.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:505:34
[OK] TRLC Failuremode Communication.SubscribeWithWrongMaxSampleCount
A proxy instance subscribes to an event to with a wrong sample count, meaning a different one that was provided by the user.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:515:34
[OK] TRLC Failuremode Communication.CallbackNotInvokedDespiteSamplesAvailable
GetNewSamples() gets called on an event with a callback F, but the callback gets called not at all, although at least one new sample is available.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:585:34
[OK] TRLC Failuremode Communication.CallbackInvokedWithWrongData
A proxy receives a sample pointer via callback F(), but the data does not contain the expected one.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:595:34
[OK] TRLC Failuremode Communication.DoesNotUnsubscribe
A proxy is subscribed to an event, tries to unsubscribe, but silently fails to unsubscribe.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:656:34
[OK] TRLC Failuremode Communication.MapContainingNonexistentEvents
The map that is visible to the user, contains events that are not actually existing (e.g. in the configuration).
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:693:38
[OK] TRLC Failuremode Communication.MethodCallBlocksLongerThanExpected
A call to a service-method on the client/consumer side blocks longer than expected (or indefinite). This is a specific instance of FailureMode [AnyFunctionBlocksLongerThanExpected], but since with service-methods we have concrete root causes in the form of message-passing behaviour and behaviour of user-provided handler, we have this specific failure mode.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:756:34
[OK] TRLC Failuremode Communication.WrongMethodInArgsProvided
Unintended input arguments are provided to a service method call. Therefore, the method call gets executed with wrong input data.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:773:34
[OK] TRLC Failuremode Communication.WrongReturnValueUsed
Unintended results are provided from a service method call. Therefore, the caller of the method works on wrong data.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:790:34
[OK] TRLC Failuremode Communication.DoesNotFreeResourcesOnDestruction
A SampleAllocateePtr or SamplePtr is destroyed, which should lead to a freeing of resources, but caused by a fault they are not freed.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:810:34
[OK] TRLC Failuremode Communication.ReturnsWrongData
On dereferenciation of a SamplePtr or SampleAllocateePtr wrong data is returned.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:853:34
[OK] TRLC Failuremode Communication.MethodSignatureElementPtrWrongTarget
On de-referencing of a MethodSignatureElementPtr wrong data is returned.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:873:34
[OK] TRLC Failuremode Communication.MethodSignatureElementPtrFailsToFree
On destruction of a MethodSignatureElementPtr wrong memory is freed or not freed at all.
Traces to:
Source: score/mw/com/dependability/safety_analysis/failure_modes.trlc:888:34