Requirements¶
These are uds_session’s requirements, written against ISO 14229-2:2021. A table,
figure, clause or requirement cited here with no document named is that one’s; any other
document is named where it is cited.
What each document governs, in the order above:
Service interface — the primitives exchanged with the application and with the transport, the parameters they carry, and the mapping between them; also the sans-io binding and what rejection means, the timebase, what each role’s creation supplies, peer identity and the start-of-message pairing, and the classification of messages that every other document conditions on.
Timer model — what a timer is and when it expires, for every timer in the set.
Server session timer — the server’s
tS3_Servertimer, which keeps a non-default session active while the client that requested it continues to communicate.Server response timing — the server’s
tP2_Servertimer, which bounds the time the server may take to begin its response to a request it has received.Client response timing — the client’s
tP_Clienttimer, which bounds the time the client waits for the response to a request it has transmitted.Client session timer — the client’s
tS3_Clienttimer, which keeps the servers a client has moved out of the default session in that session.Client request spacing — the client’s
tP3_Client_PhysandtP3_Client_Functimers, which bound how soon the next request may be transmitted on a channel.Client error handling — what the client does when a request’s transmission fails, its reception fails, or its response window expires; also the channel reset and the keep-alive release, the two caller acts by which the application gives a server up.
Open questions — questions raised while authoring this set that are not yet settled, and agreed changes not yet made.
Status of this set¶
Draft. The set has been renumbered in document order: IDs run contiguously from
UDSS_LLR_0001 in the order the pages appear in the toctree above, and a new requirement
takes the next free number. Once a requirement reaches approved and is linked from
outside this repository, its ID is fixed for the life of the crate.
While the set is draft it carries an Open questions page, recording what is not yet
settled and why. It holds no requirements and contributes nothing to needs.json; it is
deleted when its last entry is answered.
All requirements¶
ID |
Title |
Status |
Integrity Level |
Target Level |
Origin |
Source |
|---|---|---|---|---|---|---|
The session layer performs no I/O |
draft |
QM |
D |
derived |
||
The crate compiles under no_std |
draft |
QM |
D |
derived |
||
The crate declares no dependency that performs I/O |
draft |
QM |
D |
derived |
||
The session layer allocates no memory |
draft |
QM |
D |
derived |
||
The crate contains no unsafe code |
draft |
QM |
D |
derived |
||
Every input is processed or rejected, and none aborts |
draft |
QM |
D |
derived |
||
The session layer is deterministic |
draft |
QM |
D |
derived |
||
All state lives in the instance or in caller-supplied storage |
draft |
QM |
D |
derived |
||
Every input is supplied by the caller |
draft |
QM |
D |
derived |
||
The inputs the caller supplies |
draft |
QM |
D |
derived |
||
Outputs are retrieved, not pushed |
draft |
QM |
D |
derived |
||
The outputs the session layer produces |
draft |
QM |
D |
derived |
||
The session layer retains no message payload |
draft |
QM |
D |
derived |
||
An output refers to caller-owned data |
draft |
QM |
D |
derived |
||
A rejected input produces no output and changes nothing |
draft |
QM |
D |
derived |
||
What a rejection report carries |
draft |
QM |
D |
derived |
||
The session layer reads no clock |
draft |
QM |
D |
derived |
||
A timestamp is a 32-bit unsigned count of milliseconds |
draft |
QM |
D |
derived |
||
An interval is the modular difference of two timestamps |
draft |
QM |
D |
derived |
||
Every input is accompanied by a timestamp |
draft |
QM |
D |
derived |
||
The service interface comprises three service primitives |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 6.1 |
|
The session layer exchanges four protocol data units with the transport layer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 6.3; ISO 14229-2:2021 7.3; ISO 14229-2:2021 9.2 Table 3 |
|
T_DataSOM.ind carries addressing and no result |
draft |
QM |
D |
derived |
||
T_Data.req carries the request's parameters |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.3; ISO 14229-2:2021 9.2 Table 3 |
|
T_Data.conf carries addressing and a result |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.6; ISO 14229-2:2021 7.3 |
|
The caller identifies the channel of every inbound indication at a client |
draft |
QM |
D |
derived |
||
An indication naming no channel, or no existing one, is rejected |
draft |
QM |
D |
derived |
||
The identified channel is not checked against the indication's addressing |
draft |
QM |
D |
derived |
||
An instance has one role, fixed at creation |
draft |
QM |
D |
derived |
||
The inputs a server rejects |
draft |
QM |
D |
derived |
||
The inputs a client rejects |
draft |
QM |
D |
derived |
||
What creation supplies |
draft |
QM |
D |
derived |
||
S_Data.req requests transmission of a message |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.4 |
|
S_Data.ind delivers a received message to the application |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.5 |
|
S_Data and S_Length are valid only on a successful reception |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.5 |
|
A received message is indicated to the application |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.3; ISO 14229-2:2021 7.5; ISO 14229-2:2021 8.10 |
|
S_Data.conf confirms a preceding S_Data.req |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.6 |
|
T_DataSOM.ind is not forwarded to the application |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.3 |
|
T_Data.conf is forwarded to the application |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.3; ISO 14229-2:2021 7.4 |
|
Protocol parameters are set through the service interface |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 6.1 |
|
Every timing parameter is a 32-bit value in the timestamp's unit |
draft |
QM |
D |
derived |
||
A parameter a timer loads has a fixed supply point and no default |
draft |
QM |
D |
derived |
||
A parameter may be set again at any time |
draft |
QM |
D |
derived |
||
Peer identity and its equality |
draft |
QM |
D |
derived |
||
First indication, completion and the start-of-message pairing |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 6.3; ISO 14229-2:2021 7.3; ISO 14229-2:2021 9.2 Table 3 |
|
Parameter validity in each service primitive |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.2 Table 1 |
|
Session layer parameters map onto transport layer parameters |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 7.3 Table 2 |
|
S_Mtype identifies the message type and the address information present |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.3 |
|
S_TAtype selects the communication model |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.4 |
|
S_TA carries the target address |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.5 |
|
S_SA carries the source address |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.6 |
|
S_AE carries the address extension |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.7; ISO 14229-2:2021 8.3 |
|
S_Length carries the length of S_Data |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.8 |
|
A length differing from the data supplied is rejected |
draft |
QM |
D |
derived |
||
S_Data carries the message data |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.9 |
|
S_Result reports the outcome of a service execution |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 8.10 |
|
Message classification is supplied by the caller |
draft |
QM |
D |
derived |
||
The kind required on a failed reception addressed to a server |
draft |
QM |
D |
derived |
||
The classification is associated with the transmission it describes |
draft |
QM |
D |
derived |
||
At most one association is outstanding per addressing |
draft |
QM |
D |
derived |
||
A request duplicating an outstanding association is rejected |
draft |
QM |
D |
derived |
||
A request for which no association is free is rejected |
draft |
QM |
D |
derived |
||
A confirmation matching no outstanding association is rejected |
draft |
QM |
D |
derived |
||
No association is outstanding on initialisation |
draft |
QM |
D |
derived |
||
Message classification values |
draft |
QM |
D |
derived |
||
An expected response count of zero is rejected |
draft |
QM |
D |
derived |
||
A keep-alive with a session selection on a request is rejected |
draft |
QM |
D |
derived |
||
A keep-alive with a session selection on a completion report is rejected |
draft |
QM |
D |
derived |
||
A classification stating no kind where one is required is rejected |
draft |
QM |
D |
derived |
||
A request at a client stating no expected response count is rejected |
draft |
QM |
D |
derived |
||
A final response stating neither solicited nor unsolicited is rejected |
draft |
QM |
D |
derived |
||
A classification or addressing not of the stated form is rejected |
draft |
QM |
D |
derived |
||
The session layer does not inspect message data |
draft |
QM |
D |
derived |
||
Completion of a request with no response is reported by the caller |
draft |
QM |
D |
derived |
||
A timer is either running or not running |
draft |
QM |
D |
derived |
||
A timer carries the value the parameter had when it was started |
draft |
QM |
D |
derived |
||
A timer expires when its loaded value is reached |
draft |
QM |
D |
derived |
||
Only a running timer expires |
draft |
QM |
D |
derived |
||
Expiry is evaluated only when a timestamp is supplied |
draft |
QM |
D |
derived |
||
The session layer reports when a timer could next expire |
draft |
QM |
D |
derived |
||
Timer expiries precede the input they accompany |
draft |
QM |
D |
derived |
||
The server keeps one session fact, one controlling client and one session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8; ISO 14229-1:2020 Annex J J.5.1 |
|
The server's initial session state |
draft |
QM |
D |
derived |
||
What changes the session fact, the controlling client and the session timer |
draft |
QM |
D |
derived |
||
A confirmed response selecting a non-default session starts the session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-1:2020 10.2.1 Figure 7; ISO 14229-1:2020 Annex J J.4 Table J.2 |
|
A completed session-selecting request without response starts the session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6 |
|
Session timer stops when a request from the controlling client begins |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6 |
|
Session timer restarts on a confirmed final response |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-5:2022 8.9.2 |
|
Session timer restarts on completion of a request with no response |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.1 |
|
A response-pending negative response does not restart the session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6 |
|
Unsolicited responses do not restart the session timer |
draft |
QM |
D |
ip-profile-standard |
ISO 14229-5:2022 8.9.2 |
|
Reception errors restart the session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.7 Table 10; ISO 14229-2:2021 10.1.4.1 Figure 12 |
|
A failed response transmission restarts the session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.7 Table 10; ISO 14229-5:2022 8.9.2 |
|
A failed response is not retransmitted |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.7 Table 10 |
|
The bypass keep-alive reloads a running session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.1.4.2 Figure 13; ISO 14229-2:2021 10.3 Figure 20; ISO 14229-1:2020 8.7.6 |
|
What the bypass keep-alive does not affect |
draft |
QM |
D |
derived |
||
Requests from other clients do not affect the session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 |
|
A selection of the default session disables the session timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-1:2020 10.2.2.2 Table 25; ISO 14229-1:2020 8.7.6 |
|
No request starts the session timer in the default session |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 10.1.4.1; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.3 Figure 20 |
|
Session timer expiry returns the server to the default session |
draft |
QM |
D |
derived |
||
The server uses a single response timer |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.1.1; ISO 14229-2:2021 9.6 Table 7 |
|
The server's response timer is initially not running |
draft |
QM |
D |
derived |
||
What changes the server's response timer |
draft |
QM |
D |
derived |
||
The server keeps a service in progress and a response-pending anchor |
draft |
QM |
D |
derived |
||
The server's initial service state |
draft |
QM |
D |
derived |
||
What it means to answer the service in progress |
draft |
QM |
D |
derived |
||
A service becomes in progress on its successful reception |
draft |
QM |
D |
derived |
||
A new request replaces the service in progress |
draft |
QM |
D |
derived |
||
A service ceases to be in progress |
draft |
QM |
D |
derived |
||
The anchor is set on a confirmed response-pending transmission |
draft |
QM |
D |
derived |
||
What changes the service in progress and the anchor |
draft |
QM |
D |
derived |
||
An unconfirmed response-pending message |
draft |
QM |
D |
derived |
||
The response timer starts on reception of a request |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.1.2 Figure 10 |
|
The response timer stops when a response is passed to the transport |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 10.1.2 Figure 10; ISO 14229-2:2021 10.1.3 Figure 11 |
|
The response timer stops on completion of a request with no response |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 10.3 Figure 19; ISO 14229-2:2021 10.3 Figure 20 |
|
A confirmed response-pending message opens the enhanced window |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.4 Figure 8; ISO 14229-2:2021 10.1.3 Figure 11 |
|
The server's response timer overrun is indicated to the application |
draft |
QM |
D |
derived |
||
A response-pending message is rejected while one is unconfirmed |
draft |
QM |
D |
derived |
||
Consecutive response-pending messages are spaced |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 4 |
|
The client uses one response timer per communication channel |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.6 Table 7 |
|
A channel exists from when the caller opens it |
draft |
QM |
D |
derived |
||
Duplicate channel addressing is rejected |
draft |
QM |
D |
derived |
||
A request naming no existing channel is rejected |
draft |
QM |
D |
derived |
||
A withdrawal naming no existing channel is rejected |
draft |
QM |
D |
derived |
||
Withdrawal is permitted at any time and discards the channel |
draft |
QM |
D |
derived |
||
What a channel's storage holds |
draft |
QM |
D |
derived |
||
A channel's initial state |
draft |
QM |
D |
derived |
||
A request becomes and ceases to be in progress |
draft |
QM |
D |
derived |
||
An input that ends the request is processed while it is in progress |
draft |
QM |
D |
derived |
||
A physical channel's start-of-message outlives the request |
draft |
QM |
D |
derived |
||
What changes a channel's response timer |
draft |
QM |
D |
derived |
||
The response timer has two reload parameters |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.1.4.1; ISO 14229-2:2021 10.2.4 |
|
A per-channel parameter setting identifies its channel |
draft |
QM |
D |
derived |
||
A parameter setting naming no existing or wrong-kind channel is rejected |
draft |
QM |
D |
derived |
||
The response timer starts on confirmation of a request expecting a response |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.1.2 Figure 10; ISO 14229-2:2021 10.3 Figure 20 |
|
A response on a physical channel closes the response window |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.4 Figure 8; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.1.1 Figure 9; ISO 14229-2:2021 10.1.2 Figure 10; ISO 14229-2:2021 10.1.3 Figure 11 |
|
A response on a functional channel extends the window; a failed reception closes it |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.2.1 Figure 14; ISO 14229-2:2021 10.2.2 Figure 15; ISO 14229-2:2021 10.2.3 Figure 16 |
|
Receiving every expected response closes the window |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3 Figure 19 |
|
A functional channel keeps a table of its responders |
draft |
QM |
D |
derived |
||
A responder's entry is created and released |
draft |
QM |
D |
derived |
||
An entry outlives the request only for its start-of-message |
draft |
QM |
D |
derived |
||
A channel's responder table is initially empty |
draft |
QM |
D |
derived |
||
A responder beyond the table's capacity is reported and not tracked |
draft |
QM |
D |
derived |
||
A response-pending response opens the enhanced window |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.4 Figure 8; ISO 14229-2:2021 10.1.3 Figure 11; ISO 14229-2:2021 10.2.3 Figure 16 |
|
The reload value in force on a functional channel |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 10.2.3 Figure 16; ISO 14229-2:2021 10.2.4 Figure 17 |
|
A responder's response-pending message is recorded outstanding |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 10.2.3 Figure 16; ISO 14229-2:2021 10.2.4 Figure 17 |
|
How one indication's effects on the value in force compose |
draft |
QM |
D |
derived |
||
The client's response timeout is indicated to the application |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.7 Table 9 |
|
The client keeps servers alive in one of two modes |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8 |
|
Functional keep-alive state and where it lives |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8 |
|
Physical keep-alive state and where it lives |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8 |
|
The session timer's reload parameter in each mode |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 5; ISO 14229-2:2021 9.6 Table 8 |
|
The client's initial session timer state |
draft |
QM |
D |
derived |
||
What changes the client's session timers and facts |
draft |
QM |
D |
derived |
||
Functional keep-alive engages on a confirmed session change |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.2.4 Figure 17 |
|
Functional keep-alive expiry requests a TesterPresent |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.2.4 Figure 17 |
|
Functional keep-alive restarts on the confirmed TesterPresent |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.2.4 Figure 17 |
|
Functional keep-alive disengages on return to the default session |
draft |
QM |
D |
derived |
||
Physical keep-alive engages on a confirmed session change |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.2 Figure 13 |
|
Physical keep-alive stops when a request is sent |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.2 Figure 13 |
|
Physical keep-alive restarts when an exchange completes |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.2 Table 4; ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.1.4.2 Figure 13; ISO 14229-1:2020 8.7.6 |
|
Physical keep-alive expiry requests a TesterPresent |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.5 Table 5; ISO 14229-2:2021 9.6 Table 8; ISO 14229-2:2021 10.1.4.2 Figure 13 |
|
Physical keep-alive disengages on return to the default session |
draft |
QM |
D |
derived |
||
The client keeps one spacing timer per channel |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.6 Table 7 |
|
Each channel has a spacing parameter |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.2 Table 4; ISO 14229-2:2021 10.3 |
|
When a spacing timer runs |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.3 |
|
A channel's spacing timer is initially not running |
draft |
QM |
D |
derived |
||
What changes a channel's spacing timer |
draft |
QM |
D |
derived |
||
Physical spacing starts on a confirmed request needing no response |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3; ISO 14229-2:2021 10.3 Figure 20 |
|
Functional spacing starts on any confirmed request |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3; ISO 14229-2:2021 10.3 Figure 19 |
|
A request on a channel whose spacing timer is running is rejected |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.6 Table 7; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3; ISO 14229-2:2021 10.3 Figure 19; ISO 14229-2:2021 10.3 Figure 20 |
|
The rejection states the time remaining |
draft |
QM |
D |
derived |
||
Each channel keeps a repeat count |
draft |
QM |
D |
derived |
||
A channel's repeat count is initially zero |
draft |
QM |
D |
derived |
||
What changes a channel's repeat count |
draft |
QM |
D |
derived |
||
Requests advance or reset the repeat count |
draft |
QM |
D |
derived |
||
A third repeat is rejected |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.7 Table 9 |
|
A functional channel finishes receiving before it carries another request |
draft |
QM |
D |
session-layer-standard |
ISO 14229-2:2021 9.2 Table 4; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.2.4 Figure 17 |
|
A rejection for a spent count or a response still arriving states which |
draft |
QM |
D |
derived |
||
The caller may reset a channel |
draft |
QM |
D |
derived |
||
An abandoned association stays outstanding |
draft |
QM |
D |
derived |
||
What a confirmation for an abandoned association does |
draft |
QM |
D |
derived |
||
A reset naming no existing channel is rejected |
draft |
QM |
D |
derived |
||
The caller may release a keep-alive |
draft |
QM |
D |
derived |
||
An open with no free slot or no unissued handle is rejected |
draft |
QM |
D |
derived |
||
The response-pending lead is a server parameter |
draft |
QM |
D |
derived |
||
A busy refusal answers no service |
draft |
QM |
D |
derived |
Outstanding integrity gap¶
Requirements whose substantiated level is below their target.
ID |
Title |
Integrity Level |
Target Level |
|---|---|---|---|
The session layer performs no I/O |
QM |
D |
|
The crate compiles under no_std |
QM |
D |
|
The crate declares no dependency that performs I/O |
QM |
D |
|
The session layer allocates no memory |
QM |
D |
|
The crate contains no unsafe code |
QM |
D |
|
Every input is processed or rejected, and none aborts |
QM |
D |
|
The session layer is deterministic |
QM |
D |
|
All state lives in the instance or in caller-supplied storage |
QM |
D |
|
Every input is supplied by the caller |
QM |
D |
|
The inputs the caller supplies |
QM |
D |
|
Outputs are retrieved, not pushed |
QM |
D |
|
The outputs the session layer produces |
QM |
D |
|
The session layer retains no message payload |
QM |
D |
|
An output refers to caller-owned data |
QM |
D |
|
A rejected input produces no output and changes nothing |
QM |
D |
|
What a rejection report carries |
QM |
D |
|
The session layer reads no clock |
QM |
D |
|
A timestamp is a 32-bit unsigned count of milliseconds |
QM |
D |
|
An interval is the modular difference of two timestamps |
QM |
D |
|
Every input is accompanied by a timestamp |
QM |
D |
|
The service interface comprises three service primitives |
QM |
D |
|
The session layer exchanges four protocol data units with the transport layer |
QM |
D |
|
T_DataSOM.ind carries addressing and no result |
QM |
D |
|
T_Data.req carries the request's parameters |
QM |
D |
|
T_Data.conf carries addressing and a result |
QM |
D |
|
The caller identifies the channel of every inbound indication at a client |
QM |
D |
|
An indication naming no channel, or no existing one, is rejected |
QM |
D |
|
The identified channel is not checked against the indication's addressing |
QM |
D |
|
An instance has one role, fixed at creation |
QM |
D |
|
The inputs a server rejects |
QM |
D |
|
The inputs a client rejects |
QM |
D |
|
What creation supplies |
QM |
D |
|
S_Data.req requests transmission of a message |
QM |
D |
|
S_Data.ind delivers a received message to the application |
QM |
D |
|
S_Data and S_Length are valid only on a successful reception |
QM |
D |
|
A received message is indicated to the application |
QM |
D |
|
S_Data.conf confirms a preceding S_Data.req |
QM |
D |
|
T_DataSOM.ind is not forwarded to the application |
QM |
D |
|
T_Data.conf is forwarded to the application |
QM |
D |
|
Protocol parameters are set through the service interface |
QM |
D |
|
Every timing parameter is a 32-bit value in the timestamp's unit |
QM |
D |
|
A parameter a timer loads has a fixed supply point and no default |
QM |
D |
|
A parameter may be set again at any time |
QM |
D |
|
Peer identity and its equality |
QM |
D |
|
First indication, completion and the start-of-message pairing |
QM |
D |
|
Parameter validity in each service primitive |
QM |
D |
|
Session layer parameters map onto transport layer parameters |
QM |
D |
|
S_Mtype identifies the message type and the address information present |
QM |
D |
|
S_TAtype selects the communication model |
QM |
D |
|
S_TA carries the target address |
QM |
D |
|
S_SA carries the source address |
QM |
D |
|
S_AE carries the address extension |
QM |
D |
|
S_Length carries the length of S_Data |
QM |
D |
|
A length differing from the data supplied is rejected |
QM |
D |
|
S_Data carries the message data |
QM |
D |
|
S_Result reports the outcome of a service execution |
QM |
D |
|
Message classification is supplied by the caller |
QM |
D |
|
The kind required on a failed reception addressed to a server |
QM |
D |
|
The classification is associated with the transmission it describes |
QM |
D |
|
At most one association is outstanding per addressing |
QM |
D |
|
A request duplicating an outstanding association is rejected |
QM |
D |
|
A request for which no association is free is rejected |
QM |
D |
|
A confirmation matching no outstanding association is rejected |
QM |
D |
|
No association is outstanding on initialisation |
QM |
D |
|
Message classification values |
QM |
D |
|
An expected response count of zero is rejected |
QM |
D |
|
A keep-alive with a session selection on a request is rejected |
QM |
D |
|
A keep-alive with a session selection on a completion report is rejected |
QM |
D |
|
A classification stating no kind where one is required is rejected |
QM |
D |
|
A request at a client stating no expected response count is rejected |
QM |
D |
|
A final response stating neither solicited nor unsolicited is rejected |
QM |
D |
|
A classification or addressing not of the stated form is rejected |
QM |
D |
|
The session layer does not inspect message data |
QM |
D |
|
Completion of a request with no response is reported by the caller |
QM |
D |
|
A timer is either running or not running |
QM |
D |
|
A timer carries the value the parameter had when it was started |
QM |
D |
|
A timer expires when its loaded value is reached |
QM |
D |
|
Only a running timer expires |
QM |
D |
|
Expiry is evaluated only when a timestamp is supplied |
QM |
D |
|
The session layer reports when a timer could next expire |
QM |
D |
|
Timer expiries precede the input they accompany |
QM |
D |
|
The server keeps one session fact, one controlling client and one session timer |
QM |
D |
|
The server's initial session state |
QM |
D |
|
What changes the session fact, the controlling client and the session timer |
QM |
D |
|
A confirmed response selecting a non-default session starts the session timer |
QM |
D |
|
A completed session-selecting request without response starts the session timer |
QM |
D |
|
Session timer stops when a request from the controlling client begins |
QM |
D |
|
Session timer restarts on a confirmed final response |
QM |
D |
|
Session timer restarts on completion of a request with no response |
QM |
D |
|
A response-pending negative response does not restart the session timer |
QM |
D |
|
Unsolicited responses do not restart the session timer |
QM |
D |
|
Reception errors restart the session timer |
QM |
D |
|
A failed response transmission restarts the session timer |
QM |
D |
|
A failed response is not retransmitted |
QM |
D |
|
The bypass keep-alive reloads a running session timer |
QM |
D |
|
What the bypass keep-alive does not affect |
QM |
D |
|
Requests from other clients do not affect the session timer |
QM |
D |
|
A selection of the default session disables the session timer |
QM |
D |
|
No request starts the session timer in the default session |
QM |
D |
|
Session timer expiry returns the server to the default session |
QM |
D |
|
The server uses a single response timer |
QM |
D |
|
The server's response timer is initially not running |
QM |
D |
|
What changes the server's response timer |
QM |
D |
|
The server keeps a service in progress and a response-pending anchor |
QM |
D |
|
The server's initial service state |
QM |
D |
|
What it means to answer the service in progress |
QM |
D |
|
A service becomes in progress on its successful reception |
QM |
D |
|
A new request replaces the service in progress |
QM |
D |
|
A service ceases to be in progress |
QM |
D |
|
The anchor is set on a confirmed response-pending transmission |
QM |
D |
|
What changes the service in progress and the anchor |
QM |
D |
|
An unconfirmed response-pending message |
QM |
D |
|
The response timer starts on reception of a request |
QM |
D |
|
The response timer stops when a response is passed to the transport |
QM |
D |
|
The response timer stops on completion of a request with no response |
QM |
D |
|
A confirmed response-pending message opens the enhanced window |
QM |
D |
|
The server's response timer overrun is indicated to the application |
QM |
D |
|
A response-pending message is rejected while one is unconfirmed |
QM |
D |
|
Consecutive response-pending messages are spaced |
QM |
D |
|
The client uses one response timer per communication channel |
QM |
D |
|
A channel exists from when the caller opens it |
QM |
D |
|
Duplicate channel addressing is rejected |
QM |
D |
|
A request naming no existing channel is rejected |
QM |
D |
|
A withdrawal naming no existing channel is rejected |
QM |
D |
|
Withdrawal is permitted at any time and discards the channel |
QM |
D |
|
What a channel's storage holds |
QM |
D |
|
A channel's initial state |
QM |
D |
|
A request becomes and ceases to be in progress |
QM |
D |
|
An input that ends the request is processed while it is in progress |
QM |
D |
|
A physical channel's start-of-message outlives the request |
QM |
D |
|
What changes a channel's response timer |
QM |
D |
|
The response timer has two reload parameters |
QM |
D |
|
A per-channel parameter setting identifies its channel |
QM |
D |
|
A parameter setting naming no existing or wrong-kind channel is rejected |
QM |
D |
|
The response timer starts on confirmation of a request expecting a response |
QM |
D |
|
A response on a physical channel closes the response window |
QM |
D |
|
A response on a functional channel extends the window; a failed reception closes it |
QM |
D |
|
Receiving every expected response closes the window |
QM |
D |
|
A functional channel keeps a table of its responders |
QM |
D |
|
A responder's entry is created and released |
QM |
D |
|
An entry outlives the request only for its start-of-message |
QM |
D |
|
A channel's responder table is initially empty |
QM |
D |
|
A responder beyond the table's capacity is reported and not tracked |
QM |
D |
|
A response-pending response opens the enhanced window |
QM |
D |
|
The reload value in force on a functional channel |
QM |
D |
|
A responder's response-pending message is recorded outstanding |
QM |
D |
|
How one indication's effects on the value in force compose |
QM |
D |
|
The client's response timeout is indicated to the application |
QM |
D |
|
The client keeps servers alive in one of two modes |
QM |
D |
|
Functional keep-alive state and where it lives |
QM |
D |
|
Physical keep-alive state and where it lives |
QM |
D |
|
The session timer's reload parameter in each mode |
QM |
D |
|
The client's initial session timer state |
QM |
D |
|
What changes the client's session timers and facts |
QM |
D |
|
Functional keep-alive engages on a confirmed session change |
QM |
D |
|
Functional keep-alive expiry requests a TesterPresent |
QM |
D |
|
Functional keep-alive restarts on the confirmed TesterPresent |
QM |
D |
|
Functional keep-alive disengages on return to the default session |
QM |
D |
|
Physical keep-alive engages on a confirmed session change |
QM |
D |
|
Physical keep-alive stops when a request is sent |
QM |
D |
|
Physical keep-alive restarts when an exchange completes |
QM |
D |
|
Physical keep-alive expiry requests a TesterPresent |
QM |
D |
|
Physical keep-alive disengages on return to the default session |
QM |
D |
|
The client keeps one spacing timer per channel |
QM |
D |
|
Each channel has a spacing parameter |
QM |
D |
|
When a spacing timer runs |
QM |
D |
|
A channel's spacing timer is initially not running |
QM |
D |
|
What changes a channel's spacing timer |
QM |
D |
|
Physical spacing starts on a confirmed request needing no response |
QM |
D |
|
Functional spacing starts on any confirmed request |
QM |
D |
|
A request on a channel whose spacing timer is running is rejected |
QM |
D |
|
The rejection states the time remaining |
QM |
D |
|
Each channel keeps a repeat count |
QM |
D |
|
A channel's repeat count is initially zero |
QM |
D |
|
What changes a channel's repeat count |
QM |
D |
|
Requests advance or reset the repeat count |
QM |
D |
|
A third repeat is rejected |
QM |
D |
|
A functional channel finishes receiving before it carries another request |
QM |
D |
|
A rejection for a spent count or a response still arriving states which |
QM |
D |
|
The caller may reset a channel |
QM |
D |
|
An abandoned association stays outstanding |
QM |
D |
|
What a confirmation for an abandoned association does |
QM |
D |
|
A reset naming no existing channel is rejected |
QM |
D |
|
The caller may release a keep-alive |
QM |
D |
|
An open with no free slot or no unissued handle is rejected |
QM |
D |
|
The response-pending lead is a server parameter |
QM |
D |
|
A busy refusal answers no service |
QM |
D |