Requirements

These are uds_session’s requirements, written against ISO 14229-2:2021. A table, figure, clause or requirement cited here with no document named is that one’s; any other document is named where it is cited.

What each document governs, in the order above:

  • Service interface — the primitives exchanged with the application and with the transport, the parameters they carry, and the mapping between them; also the sans-io binding and what rejection means, the timebase, what each role’s creation supplies, peer identity and the start-of-message pairing, and the classification of messages that every other document conditions on.

  • Timer model — what a timer is and when it expires, for every timer in the set.

  • Server session timer — the server’s tS3_Server timer, which keeps a non-default session active while the client that requested it continues to communicate.

  • Server response timing — the server’s tP2_Server timer, which bounds the time the server may take to begin its response to a request it has received.

  • Client response timing — the client’s tP_Client timer, which bounds the time the client waits for the response to a request it has transmitted.

  • Client session timer — the client’s tS3_Client timer, which keeps the servers a client has moved out of the default session in that session.

  • Client request spacing — the client’s tP3_Client_Phys and tP3_Client_Func timers, which bound how soon the next request may be transmitted on a channel.

  • Client error handling — what the client does when a request’s transmission fails, its reception fails, or its response window expires; also the channel reset and the keep-alive release, the two caller acts by which the application gives a server up.

  • Open questions — questions raised while authoring this set that are not yet settled, and agreed changes not yet made.

Status of this set

Draft. The set has been renumbered in document order: IDs run contiguously from UDSS_LLR_0001 in the order the pages appear in the toctree above, and a new requirement takes the next free number. Once a requirement reaches approved and is linked from outside this repository, its ID is fixed for the life of the crate.

While the set is draft it carries an Open questions page, recording what is not yet settled and why. It holds no requirements and contributes nothing to needs.json; it is deleted when its last entry is answered.

All requirements

ID

Title

Status

Integrity Level

Target Level

Origin

Source

UDSS_LLR_0001

The session layer performs no I/O

draft

QM

D

derived

UDSS_LLR_0002

The crate compiles under no_std

draft

QM

D

derived

UDSS_LLR_0003

The crate declares no dependency that performs I/O

draft

QM

D

derived

UDSS_LLR_0004

The session layer allocates no memory

draft

QM

D

derived

UDSS_LLR_0005

The crate contains no unsafe code

draft

QM

D

derived

UDSS_LLR_0006

Every input is processed or rejected, and none aborts

draft

QM

D

derived

UDSS_LLR_0007

The session layer is deterministic

draft

QM

D

derived

UDSS_LLR_0008

All state lives in the instance or in caller-supplied storage

draft

QM

D

derived

UDSS_LLR_0009

Every input is supplied by the caller

draft

QM

D

derived

UDSS_LLR_0010

The inputs the caller supplies

draft

QM

D

derived

UDSS_LLR_0011

Outputs are retrieved, not pushed

draft

QM

D

derived

UDSS_LLR_0012

The outputs the session layer produces

draft

QM

D

derived

UDSS_LLR_0013

The session layer retains no message payload

draft

QM

D

derived

UDSS_LLR_0014

An output refers to caller-owned data

draft

QM

D

derived

UDSS_LLR_0015

A rejected input produces no output and changes nothing

draft

QM

D

derived

UDSS_LLR_0016

What a rejection report carries

draft

QM

D

derived

UDSS_LLR_0017

The session layer reads no clock

draft

QM

D

derived

UDSS_LLR_0018

A timestamp is a 32-bit unsigned count of milliseconds

draft

QM

D

derived

UDSS_LLR_0019

An interval is the modular difference of two timestamps

draft

QM

D

derived

UDSS_LLR_0020

Every input is accompanied by a timestamp

draft

QM

D

derived

UDSS_LLR_0021

The service interface comprises three service primitives

draft

QM

D

session-layer-standard

ISO 14229-2:2021 6.1

UDSS_LLR_0022

The session layer exchanges four protocol data units with the transport layer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 6.3; ISO 14229-2:2021 7.3; ISO 14229-2:2021 9.2 Table 3

UDSS_LLR_0023

T_DataSOM.ind carries addressing and no result

draft

QM

D

derived

UDSS_LLR_0024

T_Data.req carries the request's parameters

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.3; ISO 14229-2:2021 9.2 Table 3

UDSS_LLR_0025

T_Data.conf carries addressing and a result

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.6; ISO 14229-2:2021 7.3

UDSS_LLR_0026

The caller identifies the channel of every inbound indication at a client

draft

QM

D

derived

UDSS_LLR_0027

An indication naming no channel, or no existing one, is rejected

draft

QM

D

derived

UDSS_LLR_0028

The identified channel is not checked against the indication's addressing

draft

QM

D

derived

UDSS_LLR_0029

An instance has one role, fixed at creation

draft

QM

D

derived

UDSS_LLR_0030

The inputs a server rejects

draft

QM

D

derived

UDSS_LLR_0031

The inputs a client rejects

draft

QM

D

derived

UDSS_LLR_0032

What creation supplies

draft

QM

D

derived

UDSS_LLR_0033

S_Data.req requests transmission of a message

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.4

UDSS_LLR_0034

S_Data.ind delivers a received message to the application

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.5

UDSS_LLR_0035

S_Data and S_Length are valid only on a successful reception

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.5

UDSS_LLR_0036

A received message is indicated to the application

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.3; ISO 14229-2:2021 7.5; ISO 14229-2:2021 8.10

UDSS_LLR_0037

S_Data.conf confirms a preceding S_Data.req

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.6

UDSS_LLR_0038

T_DataSOM.ind is not forwarded to the application

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.3

UDSS_LLR_0039

T_Data.conf is forwarded to the application

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.3; ISO 14229-2:2021 7.4

UDSS_LLR_0040

Protocol parameters are set through the service interface

draft

QM

D

session-layer-standard

ISO 14229-2:2021 6.1

UDSS_LLR_0041

Every timing parameter is a 32-bit value in the timestamp's unit

draft

QM

D

derived

UDSS_LLR_0042

A parameter a timer loads has a fixed supply point and no default

draft

QM

D

derived

UDSS_LLR_0043

A parameter may be set again at any time

draft

QM

D

derived

UDSS_LLR_0044

Peer identity and its equality

draft

QM

D

derived

UDSS_LLR_0045

First indication, completion and the start-of-message pairing

draft

QM

D

session-layer-standard

ISO 14229-2:2021 6.3; ISO 14229-2:2021 7.3; ISO 14229-2:2021 9.2 Table 3

UDSS_LLR_0046

Parameter validity in each service primitive

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.2 Table 1

UDSS_LLR_0047

Session layer parameters map onto transport layer parameters

draft

QM

D

session-layer-standard

ISO 14229-2:2021 7.3 Table 2

UDSS_LLR_0048

S_Mtype identifies the message type and the address information present

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.3

UDSS_LLR_0049

S_TAtype selects the communication model

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.4

UDSS_LLR_0050

S_TA carries the target address

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.5

UDSS_LLR_0051

S_SA carries the source address

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.6

UDSS_LLR_0052

S_AE carries the address extension

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.7; ISO 14229-2:2021 8.3

UDSS_LLR_0053

S_Length carries the length of S_Data

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.8

UDSS_LLR_0054

A length differing from the data supplied is rejected

draft

QM

D

derived

UDSS_LLR_0055

S_Data carries the message data

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.9

UDSS_LLR_0056

S_Result reports the outcome of a service execution

draft

QM

D

session-layer-standard

ISO 14229-2:2021 8.10

UDSS_LLR_0057

Message classification is supplied by the caller

draft

QM

D

derived

UDSS_LLR_0058

The kind required on a failed reception addressed to a server

draft

QM

D

derived

UDSS_LLR_0059

The classification is associated with the transmission it describes

draft

QM

D

derived

UDSS_LLR_0060

At most one association is outstanding per addressing

draft

QM

D

derived

UDSS_LLR_0061

A request duplicating an outstanding association is rejected

draft

QM

D

derived

UDSS_LLR_0062

A request for which no association is free is rejected

draft

QM

D

derived

UDSS_LLR_0063

A confirmation matching no outstanding association is rejected

draft

QM

D

derived

UDSS_LLR_0064

No association is outstanding on initialisation

draft

QM

D

derived

UDSS_LLR_0065

Message classification values

draft

QM

D

derived

UDSS_LLR_0066

An expected response count of zero is rejected

draft

QM

D

derived

UDSS_LLR_0067

A keep-alive with a session selection on a request is rejected

draft

QM

D

derived

UDSS_LLR_0068

A keep-alive with a session selection on a completion report is rejected

draft

QM

D

derived

UDSS_LLR_0069

A classification stating no kind where one is required is rejected

draft

QM

D

derived

UDSS_LLR_0070

A request at a client stating no expected response count is rejected

draft

QM

D

derived

UDSS_LLR_0071

A final response stating neither solicited nor unsolicited is rejected

draft

QM

D

derived

UDSS_LLR_0072

A classification or addressing not of the stated form is rejected

draft

QM

D

derived

UDSS_LLR_0073

The session layer does not inspect message data

draft

QM

D

derived

UDSS_LLR_0074

Completion of a request with no response is reported by the caller

draft

QM

D

derived

UDSS_LLR_0075

A timer is either running or not running

draft

QM

D

derived

UDSS_LLR_0076

A timer carries the value the parameter had when it was started

draft

QM

D

derived

UDSS_LLR_0077

A timer expires when its loaded value is reached

draft

QM

D

derived

UDSS_LLR_0078

Only a running timer expires

draft

QM

D

derived

UDSS_LLR_0079

Expiry is evaluated only when a timestamp is supplied

draft

QM

D

derived

UDSS_LLR_0080

The session layer reports when a timer could next expire

draft

QM

D

derived

UDSS_LLR_0081

Timer expiries precede the input they accompany

draft

QM

D

derived

UDSS_LLR_0082

The server keeps one session fact, one controlling client and one session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8; ISO 14229-1:2020 Annex J J.5.1

UDSS_LLR_0083

The server's initial session state

draft

QM

D

derived

UDSS_LLR_0084

What changes the session fact, the controlling client and the session timer

draft

QM

D

derived

UDSS_LLR_0085

A confirmed response selecting a non-default session starts the session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-1:2020 10.2.1 Figure 7; ISO 14229-1:2020 Annex J J.4 Table J.2

UDSS_LLR_0086

A completed session-selecting request without response starts the session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6

UDSS_LLR_0087

Session timer stops when a request from the controlling client begins

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6

UDSS_LLR_0088

Session timer restarts on a confirmed final response

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-5:2022 8.9.2

UDSS_LLR_0089

Session timer restarts on completion of a request with no response

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.1

UDSS_LLR_0090

A response-pending negative response does not restart the session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6

UDSS_LLR_0091

Unsolicited responses do not restart the session timer

draft

QM

D

ip-profile-standard

ISO 14229-5:2022 8.9.2

UDSS_LLR_0092

Reception errors restart the session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.7 Table 10; ISO 14229-2:2021 10.1.4.1 Figure 12

UDSS_LLR_0093

A failed response transmission restarts the session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.7 Table 10; ISO 14229-5:2022 8.9.2

UDSS_LLR_0094

A failed response is not retransmitted

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.7 Table 10

UDSS_LLR_0095

The bypass keep-alive reloads a running session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.1.4.2 Figure 13; ISO 14229-2:2021 10.3 Figure 20; ISO 14229-1:2020 8.7.6

UDSS_LLR_0096

What the bypass keep-alive does not affect

draft

QM

D

derived

UDSS_LLR_0097

Requests from other clients do not affect the session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5

UDSS_LLR_0098

A selection of the default session disables the session timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-1:2020 10.2.2.2 Table 25; ISO 14229-1:2020 8.7.6

UDSS_LLR_0099

No request starts the session timer in the default session

draft

QM

D

session-layer-standard

ISO 14229-2:2021 10.1.4.1; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.3 Figure 20

UDSS_LLR_0100

Session timer expiry returns the server to the default session

draft

QM

D

derived

UDSS_LLR_0101

The server uses a single response timer

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.1.1; ISO 14229-2:2021 9.6 Table 7

UDSS_LLR_0102

The server's response timer is initially not running

draft

QM

D

derived

UDSS_LLR_0103

What changes the server's response timer

draft

QM

D

derived

UDSS_LLR_0104

The server keeps a service in progress and a response-pending anchor

draft

QM

D

derived

UDSS_LLR_0105

The server's initial service state

draft

QM

D

derived

UDSS_LLR_0106

What it means to answer the service in progress

draft

QM

D

derived

UDSS_LLR_0107

A service becomes in progress on its successful reception

draft

QM

D

derived

UDSS_LLR_0108

A new request replaces the service in progress

draft

QM

D

derived

UDSS_LLR_0109

A service ceases to be in progress

draft

QM

D

derived

UDSS_LLR_0110

The anchor is set on a confirmed response-pending transmission

draft

QM

D

derived

UDSS_LLR_0111

What changes the service in progress and the anchor

draft

QM

D

derived

UDSS_LLR_0112

An unconfirmed response-pending message

draft

QM

D

derived

UDSS_LLR_0113

The response timer starts on reception of a request

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.1.2 Figure 10

UDSS_LLR_0114

The response timer stops when a response is passed to the transport

draft

QM

D

session-layer-standard

ISO 14229-2:2021 10.1.2 Figure 10; ISO 14229-2:2021 10.1.3 Figure 11

UDSS_LLR_0115

The response timer stops on completion of a request with no response

draft

QM

D

session-layer-standard

ISO 14229-2:2021 10.3 Figure 19; ISO 14229-2:2021 10.3 Figure 20

UDSS_LLR_0116

A confirmed response-pending message opens the enhanced window

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.4 Figure 8; ISO 14229-2:2021 10.1.3 Figure 11

UDSS_LLR_0117

The server's response timer overrun is indicated to the application

draft

QM

D

derived

UDSS_LLR_0118

A response-pending message is rejected while one is unconfirmed

draft

QM

D

derived

UDSS_LLR_0119

Consecutive response-pending messages are spaced

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 4

UDSS_LLR_0120

The client uses one response timer per communication channel

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.6 Table 7

UDSS_LLR_0121

A channel exists from when the caller opens it

draft

QM

D

derived

UDSS_LLR_0122

Duplicate channel addressing is rejected

draft

QM

D

derived

UDSS_LLR_0123

A request naming no existing channel is rejected

draft

QM

D

derived

UDSS_LLR_0124

A withdrawal naming no existing channel is rejected

draft

QM

D

derived

UDSS_LLR_0125

Withdrawal is permitted at any time and discards the channel

draft

QM

D

derived

UDSS_LLR_0126

What a channel's storage holds

draft

QM

D

derived

UDSS_LLR_0127

A channel's initial state

draft

QM

D

derived

UDSS_LLR_0128

A request becomes and ceases to be in progress

draft

QM

D

derived

UDSS_LLR_0129

An input that ends the request is processed while it is in progress

draft

QM

D

derived

UDSS_LLR_0130

A physical channel's start-of-message outlives the request

draft

QM

D

derived

UDSS_LLR_0131

What changes a channel's response timer

draft

QM

D

derived

UDSS_LLR_0132

The response timer has two reload parameters

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.1.4.1; ISO 14229-2:2021 10.2.4

UDSS_LLR_0133

A per-channel parameter setting identifies its channel

draft

QM

D

derived

UDSS_LLR_0134

A parameter setting naming no existing or wrong-kind channel is rejected

draft

QM

D

derived

UDSS_LLR_0135

The response timer starts on confirmation of a request expecting a response

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.1.2 Figure 10; ISO 14229-2:2021 10.3 Figure 20

UDSS_LLR_0136

A response on a physical channel closes the response window

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.4 Figure 8; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.1.1 Figure 9; ISO 14229-2:2021 10.1.2 Figure 10; ISO 14229-2:2021 10.1.3 Figure 11

UDSS_LLR_0137

A response on a functional channel extends the window; a failed reception closes it

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.2.1 Figure 14; ISO 14229-2:2021 10.2.2 Figure 15; ISO 14229-2:2021 10.2.3 Figure 16

UDSS_LLR_0138

Receiving every expected response closes the window

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3 Figure 19

UDSS_LLR_0139

A functional channel keeps a table of its responders

draft

QM

D

derived

UDSS_LLR_0140

A responder's entry is created and released

draft

QM

D

derived

UDSS_LLR_0141

An entry outlives the request only for its start-of-message

draft

QM

D

derived

UDSS_LLR_0142

A channel's responder table is initially empty

draft

QM

D

derived

UDSS_LLR_0143

A responder beyond the table's capacity is reported and not tracked

draft

QM

D

derived

UDSS_LLR_0144

A response-pending response opens the enhanced window

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.4 Figure 8; ISO 14229-2:2021 10.1.3 Figure 11; ISO 14229-2:2021 10.2.3 Figure 16

UDSS_LLR_0145

The reload value in force on a functional channel

draft

QM

D

session-layer-standard

ISO 14229-2:2021 10.2.3 Figure 16; ISO 14229-2:2021 10.2.4 Figure 17

UDSS_LLR_0146

A responder's response-pending message is recorded outstanding

draft

QM

D

session-layer-standard

ISO 14229-2:2021 10.2.3 Figure 16; ISO 14229-2:2021 10.2.4 Figure 17

UDSS_LLR_0147

How one indication's effects on the value in force compose

draft

QM

D

derived

UDSS_LLR_0148

The client's response timeout is indicated to the application

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.1.2; ISO 14229-2:2021 9.7 Table 9

UDSS_LLR_0149

The client keeps servers alive in one of two modes

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8

UDSS_LLR_0150

Functional keep-alive state and where it lives

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8

UDSS_LLR_0151

Physical keep-alive state and where it lives

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8

UDSS_LLR_0152

The session timer's reload parameter in each mode

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 5; ISO 14229-2:2021 9.6 Table 8

UDSS_LLR_0153

The client's initial session timer state

draft

QM

D

derived

UDSS_LLR_0154

What changes the client's session timers and facts

draft

QM

D

derived

UDSS_LLR_0155

Functional keep-alive engages on a confirmed session change

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.6 Table 8; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.2.4 Figure 17

UDSS_LLR_0156

Functional keep-alive expiry requests a TesterPresent

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.2.4 Figure 17

UDSS_LLR_0157

Functional keep-alive restarts on the confirmed TesterPresent

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.1.4.1 Figure 12; ISO 14229-2:2021 10.2.4 Figure 17

UDSS_LLR_0158

Functional keep-alive disengages on return to the default session

draft

QM

D

derived

UDSS_LLR_0159

Physical keep-alive engages on a confirmed session change

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.2 Figure 13

UDSS_LLR_0160

Physical keep-alive stops when a request is sent

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 10.1.4.2 Figure 13

UDSS_LLR_0161

Physical keep-alive restarts when an exchange completes

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.2 Table 4; ISO 14229-2:2021 9.5; ISO 14229-2:2021 9.5 Table 6; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.1.4.2 Figure 13; ISO 14229-1:2020 8.7.6

UDSS_LLR_0162

Physical keep-alive expiry requests a TesterPresent

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.5 Table 5; ISO 14229-2:2021 9.6 Table 8; ISO 14229-2:2021 10.1.4.2 Figure 13

UDSS_LLR_0163

Physical keep-alive disengages on return to the default session

draft

QM

D

derived

UDSS_LLR_0164

The client keeps one spacing timer per channel

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.6 Table 7

UDSS_LLR_0165

Each channel has a spacing parameter

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.2 Table 4; ISO 14229-2:2021 10.3

UDSS_LLR_0166

When a spacing timer runs

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 10.3

UDSS_LLR_0167

A channel's spacing timer is initially not running

draft

QM

D

derived

UDSS_LLR_0168

What changes a channel's spacing timer

draft

QM

D

derived

UDSS_LLR_0169

Physical spacing starts on a confirmed request needing no response

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3; ISO 14229-2:2021 10.3 Figure 20

UDSS_LLR_0170

Functional spacing starts on any confirmed request

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3; ISO 14229-2:2021 10.3 Figure 19

UDSS_LLR_0171

A request on a channel whose spacing timer is running is rejected

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 3; ISO 14229-2:2021 9.6 Table 7; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.3; ISO 14229-2:2021 10.3 Figure 19; ISO 14229-2:2021 10.3 Figure 20

UDSS_LLR_0172

The rejection states the time remaining

draft

QM

D

derived

UDSS_LLR_0173

Each channel keeps a repeat count

draft

QM

D

derived

UDSS_LLR_0174

A channel's repeat count is initially zero

draft

QM

D

derived

UDSS_LLR_0175

What changes a channel's repeat count

draft

QM

D

derived

UDSS_LLR_0176

Requests advance or reset the repeat count

draft

QM

D

derived

UDSS_LLR_0177

A third repeat is rejected

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.7 Table 9

UDSS_LLR_0178

A functional channel finishes receiving before it carries another request

draft

QM

D

session-layer-standard

ISO 14229-2:2021 9.2 Table 4; ISO 14229-2:2021 9.7 Table 9; ISO 14229-2:2021 10.2.4 Figure 17

UDSS_LLR_0179

A rejection for a spent count or a response still arriving states which

draft

QM

D

derived

UDSS_LLR_0180

The caller may reset a channel

draft

QM

D

derived

UDSS_LLR_0181

An abandoned association stays outstanding

draft

QM

D

derived

UDSS_LLR_0182

What a confirmation for an abandoned association does

draft

QM

D

derived

UDSS_LLR_0183

A reset naming no existing channel is rejected

draft

QM

D

derived

UDSS_LLR_0184

The caller may release a keep-alive

draft

QM

D

derived

UDSS_LLR_0185

An open with no free slot or no unissued handle is rejected

draft

QM

D

derived

UDSS_LLR_0186

The response-pending lead is a server parameter

draft

QM

D

derived

UDSS_LLR_0187

A busy refusal answers no service

draft

QM

D

derived

Outstanding integrity gap

Requirements whose substantiated level is below their target.

ID

Title

Integrity Level

Target Level

UDSS_LLR_0001

The session layer performs no I/O

QM

D

UDSS_LLR_0002

The crate compiles under no_std

QM

D

UDSS_LLR_0003

The crate declares no dependency that performs I/O

QM

D

UDSS_LLR_0004

The session layer allocates no memory

QM

D

UDSS_LLR_0005

The crate contains no unsafe code

QM

D

UDSS_LLR_0006

Every input is processed or rejected, and none aborts

QM

D

UDSS_LLR_0007

The session layer is deterministic

QM

D

UDSS_LLR_0008

All state lives in the instance or in caller-supplied storage

QM

D

UDSS_LLR_0009

Every input is supplied by the caller

QM

D

UDSS_LLR_0010

The inputs the caller supplies

QM

D

UDSS_LLR_0011

Outputs are retrieved, not pushed

QM

D

UDSS_LLR_0012

The outputs the session layer produces

QM

D

UDSS_LLR_0013

The session layer retains no message payload

QM

D

UDSS_LLR_0014

An output refers to caller-owned data

QM

D

UDSS_LLR_0015

A rejected input produces no output and changes nothing

QM

D

UDSS_LLR_0016

What a rejection report carries

QM

D

UDSS_LLR_0017

The session layer reads no clock

QM

D

UDSS_LLR_0018

A timestamp is a 32-bit unsigned count of milliseconds

QM

D

UDSS_LLR_0019

An interval is the modular difference of two timestamps

QM

D

UDSS_LLR_0020

Every input is accompanied by a timestamp

QM

D

UDSS_LLR_0021

The service interface comprises three service primitives

QM

D

UDSS_LLR_0022

The session layer exchanges four protocol data units with the transport layer

QM

D

UDSS_LLR_0023

T_DataSOM.ind carries addressing and no result

QM

D

UDSS_LLR_0024

T_Data.req carries the request's parameters

QM

D

UDSS_LLR_0025

T_Data.conf carries addressing and a result

QM

D

UDSS_LLR_0026

The caller identifies the channel of every inbound indication at a client

QM

D

UDSS_LLR_0027

An indication naming no channel, or no existing one, is rejected

QM

D

UDSS_LLR_0028

The identified channel is not checked against the indication's addressing

QM

D

UDSS_LLR_0029

An instance has one role, fixed at creation

QM

D

UDSS_LLR_0030

The inputs a server rejects

QM

D

UDSS_LLR_0031

The inputs a client rejects

QM

D

UDSS_LLR_0032

What creation supplies

QM

D

UDSS_LLR_0033

S_Data.req requests transmission of a message

QM

D

UDSS_LLR_0034

S_Data.ind delivers a received message to the application

QM

D

UDSS_LLR_0035

S_Data and S_Length are valid only on a successful reception

QM

D

UDSS_LLR_0036

A received message is indicated to the application

QM

D

UDSS_LLR_0037

S_Data.conf confirms a preceding S_Data.req

QM

D

UDSS_LLR_0038

T_DataSOM.ind is not forwarded to the application

QM

D

UDSS_LLR_0039

T_Data.conf is forwarded to the application

QM

D

UDSS_LLR_0040

Protocol parameters are set through the service interface

QM

D

UDSS_LLR_0041

Every timing parameter is a 32-bit value in the timestamp's unit

QM

D

UDSS_LLR_0042

A parameter a timer loads has a fixed supply point and no default

QM

D

UDSS_LLR_0043

A parameter may be set again at any time

QM

D

UDSS_LLR_0044

Peer identity and its equality

QM

D

UDSS_LLR_0045

First indication, completion and the start-of-message pairing

QM

D

UDSS_LLR_0046

Parameter validity in each service primitive

QM

D

UDSS_LLR_0047

Session layer parameters map onto transport layer parameters

QM

D

UDSS_LLR_0048

S_Mtype identifies the message type and the address information present

QM

D

UDSS_LLR_0049

S_TAtype selects the communication model

QM

D

UDSS_LLR_0050

S_TA carries the target address

QM

D

UDSS_LLR_0051

S_SA carries the source address

QM

D

UDSS_LLR_0052

S_AE carries the address extension

QM

D

UDSS_LLR_0053

S_Length carries the length of S_Data

QM

D

UDSS_LLR_0054

A length differing from the data supplied is rejected

QM

D

UDSS_LLR_0055

S_Data carries the message data

QM

D

UDSS_LLR_0056

S_Result reports the outcome of a service execution

QM

D

UDSS_LLR_0057

Message classification is supplied by the caller

QM

D

UDSS_LLR_0058

The kind required on a failed reception addressed to a server

QM

D

UDSS_LLR_0059

The classification is associated with the transmission it describes

QM

D

UDSS_LLR_0060

At most one association is outstanding per addressing

QM

D

UDSS_LLR_0061

A request duplicating an outstanding association is rejected

QM

D

UDSS_LLR_0062

A request for which no association is free is rejected

QM

D

UDSS_LLR_0063

A confirmation matching no outstanding association is rejected

QM

D

UDSS_LLR_0064

No association is outstanding on initialisation

QM

D

UDSS_LLR_0065

Message classification values

QM

D

UDSS_LLR_0066

An expected response count of zero is rejected

QM

D

UDSS_LLR_0067

A keep-alive with a session selection on a request is rejected

QM

D

UDSS_LLR_0068

A keep-alive with a session selection on a completion report is rejected

QM

D

UDSS_LLR_0069

A classification stating no kind where one is required is rejected

QM

D

UDSS_LLR_0070

A request at a client stating no expected response count is rejected

QM

D

UDSS_LLR_0071

A final response stating neither solicited nor unsolicited is rejected

QM

D

UDSS_LLR_0072

A classification or addressing not of the stated form is rejected

QM

D

UDSS_LLR_0073

The session layer does not inspect message data

QM

D

UDSS_LLR_0074

Completion of a request with no response is reported by the caller

QM

D

UDSS_LLR_0075

A timer is either running or not running

QM

D

UDSS_LLR_0076

A timer carries the value the parameter had when it was started

QM

D

UDSS_LLR_0077

A timer expires when its loaded value is reached

QM

D

UDSS_LLR_0078

Only a running timer expires

QM

D

UDSS_LLR_0079

Expiry is evaluated only when a timestamp is supplied

QM

D

UDSS_LLR_0080

The session layer reports when a timer could next expire

QM

D

UDSS_LLR_0081

Timer expiries precede the input they accompany

QM

D

UDSS_LLR_0082

The server keeps one session fact, one controlling client and one session timer

QM

D

UDSS_LLR_0083

The server's initial session state

QM

D

UDSS_LLR_0084

What changes the session fact, the controlling client and the session timer

QM

D

UDSS_LLR_0085

A confirmed response selecting a non-default session starts the session timer

QM

D

UDSS_LLR_0086

A completed session-selecting request without response starts the session timer

QM

D

UDSS_LLR_0087

Session timer stops when a request from the controlling client begins

QM

D

UDSS_LLR_0088

Session timer restarts on a confirmed final response

QM

D

UDSS_LLR_0089

Session timer restarts on completion of a request with no response

QM

D

UDSS_LLR_0090

A response-pending negative response does not restart the session timer

QM

D

UDSS_LLR_0091

Unsolicited responses do not restart the session timer

QM

D

UDSS_LLR_0092

Reception errors restart the session timer

QM

D

UDSS_LLR_0093

A failed response transmission restarts the session timer

QM

D

UDSS_LLR_0094

A failed response is not retransmitted

QM

D

UDSS_LLR_0095

The bypass keep-alive reloads a running session timer

QM

D

UDSS_LLR_0096

What the bypass keep-alive does not affect

QM

D

UDSS_LLR_0097

Requests from other clients do not affect the session timer

QM

D

UDSS_LLR_0098

A selection of the default session disables the session timer

QM

D

UDSS_LLR_0099

No request starts the session timer in the default session

QM

D

UDSS_LLR_0100

Session timer expiry returns the server to the default session

QM

D

UDSS_LLR_0101

The server uses a single response timer

QM

D

UDSS_LLR_0102

The server's response timer is initially not running

QM

D

UDSS_LLR_0103

What changes the server's response timer

QM

D

UDSS_LLR_0104

The server keeps a service in progress and a response-pending anchor

QM

D

UDSS_LLR_0105

The server's initial service state

QM

D

UDSS_LLR_0106

What it means to answer the service in progress

QM

D

UDSS_LLR_0107

A service becomes in progress on its successful reception

QM

D

UDSS_LLR_0108

A new request replaces the service in progress

QM

D

UDSS_LLR_0109

A service ceases to be in progress

QM

D

UDSS_LLR_0110

The anchor is set on a confirmed response-pending transmission

QM

D

UDSS_LLR_0111

What changes the service in progress and the anchor

QM

D

UDSS_LLR_0112

An unconfirmed response-pending message

QM

D

UDSS_LLR_0113

The response timer starts on reception of a request

QM

D

UDSS_LLR_0114

The response timer stops when a response is passed to the transport

QM

D

UDSS_LLR_0115

The response timer stops on completion of a request with no response

QM

D

UDSS_LLR_0116

A confirmed response-pending message opens the enhanced window

QM

D

UDSS_LLR_0117

The server's response timer overrun is indicated to the application

QM

D

UDSS_LLR_0118

A response-pending message is rejected while one is unconfirmed

QM

D

UDSS_LLR_0119

Consecutive response-pending messages are spaced

QM

D

UDSS_LLR_0120

The client uses one response timer per communication channel

QM

D

UDSS_LLR_0121

A channel exists from when the caller opens it

QM

D

UDSS_LLR_0122

Duplicate channel addressing is rejected

QM

D

UDSS_LLR_0123

A request naming no existing channel is rejected

QM

D

UDSS_LLR_0124

A withdrawal naming no existing channel is rejected

QM

D

UDSS_LLR_0125

Withdrawal is permitted at any time and discards the channel

QM

D

UDSS_LLR_0126

What a channel's storage holds

QM

D

UDSS_LLR_0127

A channel's initial state

QM

D

UDSS_LLR_0128

A request becomes and ceases to be in progress

QM

D

UDSS_LLR_0129

An input that ends the request is processed while it is in progress

QM

D

UDSS_LLR_0130

A physical channel's start-of-message outlives the request

QM

D

UDSS_LLR_0131

What changes a channel's response timer

QM

D

UDSS_LLR_0132

The response timer has two reload parameters

QM

D

UDSS_LLR_0133

A per-channel parameter setting identifies its channel

QM

D

UDSS_LLR_0134

A parameter setting naming no existing or wrong-kind channel is rejected

QM

D

UDSS_LLR_0135

The response timer starts on confirmation of a request expecting a response

QM

D

UDSS_LLR_0136

A response on a physical channel closes the response window

QM

D

UDSS_LLR_0137

A response on a functional channel extends the window; a failed reception closes it

QM

D

UDSS_LLR_0138

Receiving every expected response closes the window

QM

D

UDSS_LLR_0139

A functional channel keeps a table of its responders

QM

D

UDSS_LLR_0140

A responder's entry is created and released

QM

D

UDSS_LLR_0141

An entry outlives the request only for its start-of-message

QM

D

UDSS_LLR_0142

A channel's responder table is initially empty

QM

D

UDSS_LLR_0143

A responder beyond the table's capacity is reported and not tracked

QM

D

UDSS_LLR_0144

A response-pending response opens the enhanced window

QM

D

UDSS_LLR_0145

The reload value in force on a functional channel

QM

D

UDSS_LLR_0146

A responder's response-pending message is recorded outstanding

QM

D

UDSS_LLR_0147

How one indication's effects on the value in force compose

QM

D

UDSS_LLR_0148

The client's response timeout is indicated to the application

QM

D

UDSS_LLR_0149

The client keeps servers alive in one of two modes

QM

D

UDSS_LLR_0150

Functional keep-alive state and where it lives

QM

D

UDSS_LLR_0151

Physical keep-alive state and where it lives

QM

D

UDSS_LLR_0152

The session timer's reload parameter in each mode

QM

D

UDSS_LLR_0153

The client's initial session timer state

QM

D

UDSS_LLR_0154

What changes the client's session timers and facts

QM

D

UDSS_LLR_0155

Functional keep-alive engages on a confirmed session change

QM

D

UDSS_LLR_0156

Functional keep-alive expiry requests a TesterPresent

QM

D

UDSS_LLR_0157

Functional keep-alive restarts on the confirmed TesterPresent

QM

D

UDSS_LLR_0158

Functional keep-alive disengages on return to the default session

QM

D

UDSS_LLR_0159

Physical keep-alive engages on a confirmed session change

QM

D

UDSS_LLR_0160

Physical keep-alive stops when a request is sent

QM

D

UDSS_LLR_0161

Physical keep-alive restarts when an exchange completes

QM

D

UDSS_LLR_0162

Physical keep-alive expiry requests a TesterPresent

QM

D

UDSS_LLR_0163

Physical keep-alive disengages on return to the default session

QM

D

UDSS_LLR_0164

The client keeps one spacing timer per channel

QM

D

UDSS_LLR_0165

Each channel has a spacing parameter

QM

D

UDSS_LLR_0166

When a spacing timer runs

QM

D

UDSS_LLR_0167

A channel's spacing timer is initially not running

QM

D

UDSS_LLR_0168

What changes a channel's spacing timer

QM

D

UDSS_LLR_0169

Physical spacing starts on a confirmed request needing no response

QM

D

UDSS_LLR_0170

Functional spacing starts on any confirmed request

QM

D

UDSS_LLR_0171

A request on a channel whose spacing timer is running is rejected

QM

D

UDSS_LLR_0172

The rejection states the time remaining

QM

D

UDSS_LLR_0173

Each channel keeps a repeat count

QM

D

UDSS_LLR_0174

A channel's repeat count is initially zero

QM

D

UDSS_LLR_0175

What changes a channel's repeat count

QM

D

UDSS_LLR_0176

Requests advance or reset the repeat count

QM

D

UDSS_LLR_0177

A third repeat is rejected

QM

D

UDSS_LLR_0178

A functional channel finishes receiving before it carries another request

QM

D

UDSS_LLR_0179

A rejection for a spent count or a response still arriving states which

QM

D

UDSS_LLR_0180

The caller may reset a channel

QM

D

UDSS_LLR_0181

An abandoned association stays outstanding

QM

D

UDSS_LLR_0182

What a confirmation for an abandoned association does

QM

D

UDSS_LLR_0183

A reset naming no existing channel is rejected

QM

D

UDSS_LLR_0184

The caller may release a keep-alive

QM

D

UDSS_LLR_0185

An open with no free slot or no unissued handle is rejected

QM

D

UDSS_LLR_0186

The response-pending lead is a server parameter

QM

D

UDSS_LLR_0187

A busy refusal answers no service

QM

D