From ffd5efe1383325b806bcf31be41679d96538775a Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 04:27:32 +0000 Subject: [PATCH 1/4] docs: state in every package README what is validated and what is not ADR 0001 (release checklist, item 5) requires each package README to say what has been validated and what has not, software doubles versus hardware. The nine READMEs carried the status block about the withdrawn 1.x releases but nothing on validation; the only statement was in the roadmap of the root README. Each README now has the same two-part section. What is validated is what the tests in this repository cover, named per package. What is not validated is stated per package too, and every one of them says that nothing has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references CanKit.Adapter.Virtual and no hardware adapter. Only claims that the test project supports are made. TX echo of real adapters is said to be modelled by a test double, and the UDS client is said to be tested against a simulation written from the same reading of the standard. Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01UWRpkQzKkNDYz3WiNgWvWU --- src/CanKit.Pro.Actor/README.md | 6 ++++++ src/CanKit.Pro.Addressing/README.md | 6 ++++++ src/CanKit.Pro.CANopen/README.md | 6 ++++++ src/CanKit.Pro.IsoTp/README.md | 6 ++++++ src/CanKit.Pro.J1939/README.md | 6 ++++++ src/CanKit.Pro.J1939Tp/README.md | 6 ++++++ src/CanKit.Pro.RawCan/README.md | 6 ++++++ src/CanKit.Pro.Reliability/README.md | 6 ++++++ src/CanKit.Pro.Uds/README.md | 6 ++++++ 9 files changed, 54 insertions(+) diff --git a/src/CanKit.Pro.Actor/README.md b/src/CanKit.Pro.Actor/README.md index f883b47f..c58714b6 100644 --- a/src/CanKit.Pro.Actor/README.md +++ b/src/CanKit.Pro.Actor/README.md @@ -11,6 +11,12 @@ tagged there is no listed version to install, so the `dotnet add package` line b nothing and the withdrawn releases come back only on an exact version pin. The public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** Single-mailbox ordering and the single-writer discipline in all three execution modes, the timer queue, the background-exception channel, dispose semantics and cancellation of a queued `PostAsync`, by the test suite in `tests/CanKit.Pro.Tests`. Time-dependent behaviour is tested on a virtual clock. + +**Not validated:** Real-time scheduling on a loaded production host: timers carry the operating system's scheduling latency and there is no hard real-time guarantee. The package handles no CAN frames, so hardware and foreign stacks do not apply to it. + This package has **no dependency on any other CanKit package** — it is a plain, reusable single-writer executor plus an event-driven timer queue. Protocol layers compose it; it does not know about CAN frames, buses, or adapters. diff --git a/src/CanKit.Pro.Addressing/README.md b/src/CanKit.Pro.Addressing/README.md index b781b797..d11f8414 100644 --- a/src/CanKit.Pro.Addressing/README.md +++ b/src/CanKit.Pro.Addressing/README.md @@ -12,6 +12,12 @@ tagged there is no listed version to install, so the `dotnet add package` line b nothing and the withdrawn releases come back only on an exact version pin. The public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** CAN-ID limits and construction, J1939 PGN/priority/PDU/source-address composition and decomposition, NAME fields and PGN classification, by unit tests in the test suite in `tests/CanKit.Pro.Tests`, against the values of the J1939 tables as this repository reads them. + +**Not validated:** The results have not been compared with a third-party J1939 implementation. The package handles no frames on a bus, so hardware does not apply to it. + This generalizes logic that previously only existed as one hard-coded case inside `IsoTpEndpoint.CreateNormalFixed` (a single fixed diagnostics PGN) into reusable helpers any protocol layer (ISO-TP, J1939, CANopen, ...) can call directly. diff --git a/src/CanKit.Pro.CANopen/README.md b/src/CanKit.Pro.CANopen/README.md index 0447bfe0..aa57f303 100644 --- a/src/CanKit.Pro.CANopen/README.md +++ b/src/CanKit.Pro.CANopen/README.md @@ -7,6 +7,12 @@ nothing and the withdrawn releases come back only on an exact version pin. The public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** The communication profile as this repository reads CiA 301 — SDO server and client, PDO, NMT, heartbeat, node and life guarding, SYNC, EMCY, EDS/DCF loading — by the test suite in `tests/CanKit.Pro.Tests`, against peers written for the tests (for example `PeerSdoLaboratory`) over `CanKit.Adapter.Virtual`. + +**Not validated:** CiA 301 conformance as a tester would judge it, and any real CANopen device or third-party master. Device descriptions are tested against files and descriptions written for the tests, not against ones shipped by real devices. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. + **CANopen (CiA 301)** node implementation for CanKit.Pro. Provides an in-process `ICanOpenNode` whose object dictionary carries the CiA 301 communication profile and drives the node's behaviour: an SDO server and client, a PDO engine with every transmission type of diff --git a/src/CanKit.Pro.IsoTp/README.md b/src/CanKit.Pro.IsoTp/README.md index ed1a1505..e0cc5b96 100644 --- a/src/CanKit.Pro.IsoTp/README.md +++ b/src/CanKit.Pro.IsoTp/README.md @@ -19,6 +19,12 @@ public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). CAN-FD long-payload cases still get the least coverage of the two halves. +## What is validated, and what is not + +**Validated:** The frame codec (unit and property tests), and the channel over `CanKit.Adapter.Virtual` loopback: segmentation, Flow Control (BS, STmin, Wait, Overflow), the N_As/N_Bs/N_Cr timers, reassembly, functional addressing and CAN-FD, by the test suite in `tests/CanKit.Pro.Tests`. STmin spacing is measured on the loopback with CI-tolerant bounds. + +**Not validated:** Conformance to ISO 15765-2 as a tester or a foreign ISO-TP stack would judge it, and STmin spacing on real adapters, where it also carries the adapter's own latency. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. + ## Scope - `IsoTpFrameCodec` — bounds-safe PCI parser, `BuildSingleFrame` / `BuildFirstFrame` / diff --git a/src/CanKit.Pro.J1939/README.md b/src/CanKit.Pro.J1939/README.md index 0254b6c9..6b6bd576 100644 --- a/src/CanKit.Pro.J1939/README.md +++ b/src/CanKit.Pro.J1939/README.md @@ -141,6 +141,12 @@ nothing and the withdrawn releases come back only on an exact version pin. The public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** PGN send and receive, SPN extraction and its indicator values, address claiming and its fallback, Request-PGN and periodic sends, by the test suite in `tests/CanKit.Pro.Tests`, between nodes of this implementation over `CanKit.Adapter.Virtual`. + +**Not validated:** Address-claim arbitration against third-party ECUs and behaviour on a real J1939 network. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. + ## Install ```bash diff --git a/src/CanKit.Pro.J1939Tp/README.md b/src/CanKit.Pro.J1939Tp/README.md index 3230ad33..91e29791 100644 --- a/src/CanKit.Pro.J1939Tp/README.md +++ b/src/CanKit.Pro.J1939Tp/README.md @@ -8,6 +8,12 @@ tagged there is no listed version to install, so the `dotnet add package` line b nothing and the withdrawn releases come back only on an exact version pin. The public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** TP.BAM and TP.CM sessions, the T1–T4 timers, Connection Abort codes and retransmission, by the test suite in `tests/CanKit.Pro.Tests`, between instances of this implementation over `CanKit.Adapter.Virtual`. + +**Not validated:** Interoperation with third-party J1939 nodes and J1939-21 conformance testing. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. + - **TP.BAM** (Broadcast Announce Message) — one sender pushes an up-to-1785-byte PDU to every node on the bus, no acknowledgement (FR-TP-030). - **TP.CM** (Connection Mode: RTS / CTS / EndOfMsgAck / Connection Abort) — point-to-point, with block-size negotiation and end-of-message acknowledgement (FR-TP-031). diff --git a/src/CanKit.Pro.RawCan/README.md b/src/CanKit.Pro.RawCan/README.md index 0179b7ea..865bd023 100644 --- a/src/CanKit.Pro.RawCan/README.md +++ b/src/CanKit.Pro.RawCan/README.md @@ -10,6 +10,12 @@ tagged there is no listed version to install, so the `dotnet add package` line b nothing and the withdrawn releases come back only on an exact version pin. The public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** Demultiplexing and subscriptions, filter overlap, TX confirmation and concurrency, by the test suite in `tests/CanKit.Pro.Tests`, over `CanKit.Adapter.Virtual` and in-repository bus doubles. + +**Not validated:** The behaviour of real adapters. TX echo as SocketCAN, Kvaser and Vector deliver it is modelled by a test double (`EchoWorlds`), not observed on those adapters; the "accepted by the driver" approximation for adapters without echo has not been checked against a real driver. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. + One `ICanBusService` wraps one `ICanBus` and turns its single `FrameObserved` RX stream into N independent, filtered, read-only `ISubscription`s — so several protocol instances (ISO-TP, J1939, CANopen, …) can each see their own view of the same bus **without competing over diff --git a/src/CanKit.Pro.Reliability/README.md b/src/CanKit.Pro.Reliability/README.md index 3629acfc..475a79c9 100644 --- a/src/CanKit.Pro.Reliability/README.md +++ b/src/CanKit.Pro.Reliability/README.md @@ -12,6 +12,12 @@ tagged there is no listed version to install, so the `dotnet add package` line b nothing and the withdrawn releases come back only on an exact version pin. The public surface can still change until then. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** Deadline expiry and the bus-state monitor, by the test suite in `tests/CanKit.Pro.Tests`, on a virtual clock and with bus states set in software on the virtual bus. + +**Not validated:** Bus-off and error-passive transitions as a real controller produces them. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. + This package depends only on `CanKit.Abstractions` (for `ICanBus`/`BusState`) and `CanKit.Pro.Actor` (for `IProtocolActor`). Every protocol instance already runs on a `ProtocolActor` (FR-RAW-020), so a deadline is not an independent standalone timer — it is scheduled through the actor's own diff --git a/src/CanKit.Pro.Uds/README.md b/src/CanKit.Pro.Uds/README.md index 07b83ced..99d22474 100644 --- a/src/CanKit.Pro.Uds/README.md +++ b/src/CanKit.Pro.Uds/README.md @@ -13,6 +13,12 @@ public surface can still change until then — `SendRawAsync`, the timing option NRC-mapping types most of all. See [Versioning](https://github.com/dborgards/CanKit.Pro/blob/main/docs/decisions/0001-versioning-and-api-stability.md). +## What is validated, and what is not + +**Validated:** The services listed under *Service coverage*, negative-response handling and the timing options, by the test suite in `tests/CanKit.Pro.Tests`, against `SimulatedUdsEcu` — an ECU simulation written in this repository from the same reading of ISO 14229-1 as the client — over `CanKit.Adapter.Virtual`. + +**Not validated:** Any real ECU, whose timing, negative-response usage and deviations from the standard the simulation does not reproduce, and conformance as a tester would judge it. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. + ## Service coverage (SRS FR-UDS-001..012) | SRS ID | Service | MVP support | From 1a09ebb9034299b635c0cae1a0ac46a51d2459df Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 04:47:21 +0000 Subject: [PATCH 2/4] docs: say what the STmin and bus-state tests actually run on Two statements in the new validation sections claimed more than the tests do. The IsoTp section said STmin spacing is measured on the loopback with CI-tolerant bounds. IsoTpStminTimingTests runs on a clock the test drives and brackets each interval exactly; nothing in it measures elapsed time, and its class documentation says so. The section now says that, and moves real-time STmin spacing to the not-validated half. The Reliability section said bus states are set in software on the virtual bus. BusStateMonitorTests.OpenBus returns a ControllableBus and the tests set that double's BusState directly; the virtual adapter only supplies its configuration. The section now names the double. Checking the other seven sections against the tests found three more that were looser than the suites: the Actor's time-dependent tests are only partly on a virtual clock, and the J1939 and J1939Tp suites run through ControllableBus as well as directly on the virtual adapter. Each is reworded to what the suites do. Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01UWRpkQzKkNDYz3WiNgWvWU --- src/CanKit.Pro.Actor/README.md | 2 +- src/CanKit.Pro.IsoTp/README.md | 4 ++-- src/CanKit.Pro.J1939/README.md | 2 +- src/CanKit.Pro.J1939Tp/README.md | 2 +- src/CanKit.Pro.Reliability/README.md | 2 +- 5 files changed, 6 insertions(+), 6 deletions(-) diff --git a/src/CanKit.Pro.Actor/README.md b/src/CanKit.Pro.Actor/README.md index c58714b6..49867e97 100644 --- a/src/CanKit.Pro.Actor/README.md +++ b/src/CanKit.Pro.Actor/README.md @@ -13,7 +13,7 @@ can still change until then. See [Versioning](https://github.com/dborgards/CanKi ## What is validated, and what is not -**Validated:** Single-mailbox ordering and the single-writer discipline in all three execution modes, the timer queue, the background-exception channel, dispose semantics and cancellation of a queued `PostAsync`, by the test suite in `tests/CanKit.Pro.Tests`. Time-dependent behaviour is tested on a virtual clock. +**Validated:** Single-mailbox ordering and the single-writer discipline in all three execution modes, the timer queue, the background-exception channel, dispose semantics and cancellation of a queued `PostAsync`, by the test suite in `tests/CanKit.Pro.Tests`. Much of the time-dependent behaviour is tested on a virtual clock; the rest measures real elapsed time. **Not validated:** Real-time scheduling on a loaded production host: timers carry the operating system's scheduling latency and there is no hard real-time guarantee. The package handles no CAN frames, so hardware and foreign stacks do not apply to it. diff --git a/src/CanKit.Pro.IsoTp/README.md b/src/CanKit.Pro.IsoTp/README.md index 2a1e56dc..beb3c3ca 100644 --- a/src/CanKit.Pro.IsoTp/README.md +++ b/src/CanKit.Pro.IsoTp/README.md @@ -21,9 +21,9 @@ CAN-FD long-payload cases still get the least coverage of the two halves. ## What is validated, and what is not -**Validated:** The frame codec (unit and property tests), and the channel over `CanKit.Adapter.Virtual` loopback: segmentation, Flow Control (BS, STmin, Wait, Overflow), the N_As/N_Bs/N_Cr timers, reassembly, functional addressing and CAN-FD, by the test suite in `tests/CanKit.Pro.Tests`. STmin spacing is measured on the loopback with CI-tolerant bounds. +**Validated:** The frame codec (unit and property tests), and the channel over `CanKit.Adapter.Virtual`, directly or through a controllable bus double: segmentation, Flow Control (BS, STmin, Wait, Overflow), the N_As/N_Bs/N_Cr timers, reassembly, functional addressing and CAN-FD, by the test suite in `tests/CanKit.Pro.Tests`. STmin pacing is tested on a clock the test drives, so the interval is checked exactly and no real elapsed time is measured. -**Not validated:** Conformance to ISO 15765-2 as a tester or a foreign ISO-TP stack would judge it, and STmin spacing on real adapters, where it also carries the adapter's own latency. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. +**Not validated:** Conformance to ISO 15765-2 as a tester or a foreign ISO-TP stack would judge it, and STmin spacing in real time, on any host or adapter, where it carries scheduling and adapter latency. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. ## Scope diff --git a/src/CanKit.Pro.J1939/README.md b/src/CanKit.Pro.J1939/README.md index 6b6bd576..e11ac6fe 100644 --- a/src/CanKit.Pro.J1939/README.md +++ b/src/CanKit.Pro.J1939/README.md @@ -143,7 +143,7 @@ public surface can still change until then. See ## What is validated, and what is not -**Validated:** PGN send and receive, SPN extraction and its indicator values, address claiming and its fallback, Request-PGN and periodic sends, by the test suite in `tests/CanKit.Pro.Tests`, between nodes of this implementation over `CanKit.Adapter.Virtual`. +**Validated:** PGN send and receive, SPN extraction and its indicator values, address claiming and its fallback, Request-PGN and periodic sends, by the test suite in `tests/CanKit.Pro.Tests`, between nodes of this implementation over `CanKit.Adapter.Virtual`, directly or through a controllable bus double. **Not validated:** Address-claim arbitration against third-party ECUs and behaviour on a real J1939 network. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. diff --git a/src/CanKit.Pro.J1939Tp/README.md b/src/CanKit.Pro.J1939Tp/README.md index 91e29791..db1070b5 100644 --- a/src/CanKit.Pro.J1939Tp/README.md +++ b/src/CanKit.Pro.J1939Tp/README.md @@ -10,7 +10,7 @@ can still change until then. See [Versioning](https://github.com/dborgards/CanKi ## What is validated, and what is not -**Validated:** TP.BAM and TP.CM sessions, the T1–T4 timers, Connection Abort codes and retransmission, by the test suite in `tests/CanKit.Pro.Tests`, between instances of this implementation over `CanKit.Adapter.Virtual`. +**Validated:** TP.BAM and TP.CM sessions, the T1–T4 timers, Connection Abort codes and retransmission, by the test suite in `tests/CanKit.Pro.Tests`, between instances of this implementation over `CanKit.Adapter.Virtual`, directly or through a controllable bus double. **Not validated:** Interoperation with third-party J1939 nodes and J1939-21 conformance testing. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. diff --git a/src/CanKit.Pro.Reliability/README.md b/src/CanKit.Pro.Reliability/README.md index 475a79c9..af5efa59 100644 --- a/src/CanKit.Pro.Reliability/README.md +++ b/src/CanKit.Pro.Reliability/README.md @@ -14,7 +14,7 @@ can still change until then. See [Versioning](https://github.com/dborgards/CanKi ## What is validated, and what is not -**Validated:** Deadline expiry and the bus-state monitor, by the test suite in `tests/CanKit.Pro.Tests`, on a virtual clock and with bus states set in software on the virtual bus. +**Validated:** Deadline expiry and the bus-state monitor, by the test suite in `tests/CanKit.Pro.Tests`, largely on a virtual clock, and with bus states set by a software-controlled bus double (`ControllableBus`, built on a virtual-adapter session) rather than reported by an adapter. **Not validated:** Bus-off and error-passive transitions as a real controller produces them. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. From df9c1d752a2c2ab2b973ddb8f00a5fe1a6f42942 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 04:53:35 +0000 Subject: [PATCH 3/4] docs: name the real echo double and describe the CANopen peers as they are Two more statements in the validation sections did not match the test project. The RawCan section named `EchoWorlds` as the test double that models the TX echo of SocketCAN, Kvaser and Vector. EchoWorlds.cs defines the EchoWorld enum and the EchoWorldFixture; the double is ControllableBus.EchoCapable, whose documentation is where those three adapters are named. The section now names it. The CANopen section offered PeerSdoLaboratory as an example of a peer written for the tests. It is a factory for test EDS/DCF descriptions and a helper that binds them to a node; it sends and receives nothing. The tests run between instances of the node itself and against raw frames they transmit, and the section says that instead. Checked again, name by name and claim by claim, against the test project: the UDS section said the ECU simulation was written from the same reading of the standard as the client, which nothing shows, and now says it is a scripted simulation whose responses each test defines. It also now says that some services are covered thinly. A doubled "in" in the Addressing section is removed. Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01UWRpkQzKkNDYz3WiNgWvWU --- src/CanKit.Pro.Addressing/README.md | 2 +- src/CanKit.Pro.CANopen/README.md | 2 +- src/CanKit.Pro.RawCan/README.md | 2 +- src/CanKit.Pro.Uds/README.md | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/src/CanKit.Pro.Addressing/README.md b/src/CanKit.Pro.Addressing/README.md index d11f8414..1169bad7 100644 --- a/src/CanKit.Pro.Addressing/README.md +++ b/src/CanKit.Pro.Addressing/README.md @@ -14,7 +14,7 @@ can still change until then. See [Versioning](https://github.com/dborgards/CanKi ## What is validated, and what is not -**Validated:** CAN-ID limits and construction, J1939 PGN/priority/PDU/source-address composition and decomposition, NAME fields and PGN classification, by unit tests in the test suite in `tests/CanKit.Pro.Tests`, against the values of the J1939 tables as this repository reads them. +**Validated:** CAN-ID limits and construction, J1939 PGN/priority/PDU/source-address composition and decomposition, NAME fields and PGN classification, by unit tests in `tests/CanKit.Pro.Tests`, against the values of the J1939 tables as this repository reads them. **Not validated:** The results have not been compared with a third-party J1939 implementation. The package handles no frames on a bus, so hardware does not apply to it. diff --git a/src/CanKit.Pro.CANopen/README.md b/src/CanKit.Pro.CANopen/README.md index aa57f303..7456f1c4 100644 --- a/src/CanKit.Pro.CANopen/README.md +++ b/src/CanKit.Pro.CANopen/README.md @@ -9,7 +9,7 @@ public surface can still change until then. See ## What is validated, and what is not -**Validated:** The communication profile as this repository reads CiA 301 — SDO server and client, PDO, NMT, heartbeat, node and life guarding, SYNC, EMCY, EDS/DCF loading — by the test suite in `tests/CanKit.Pro.Tests`, against peers written for the tests (for example `PeerSdoLaboratory`) over `CanKit.Adapter.Virtual`. +**Validated:** The communication profile as this repository reads CiA 301 — SDO server and client, PDO, NMT, heartbeat, node and life guarding, SYNC, EMCY, EDS/DCF loading — by the test suite in `tests/CanKit.Pro.Tests`, between instances of this implementation and against raw frames the tests send, over `CanKit.Adapter.Virtual`. **Not validated:** CiA 301 conformance as a tester would judge it, and any real CANopen device or third-party master. Device descriptions are tested against files and descriptions written for the tests, not against ones shipped by real devices. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. diff --git a/src/CanKit.Pro.RawCan/README.md b/src/CanKit.Pro.RawCan/README.md index 865bd023..a7958ef8 100644 --- a/src/CanKit.Pro.RawCan/README.md +++ b/src/CanKit.Pro.RawCan/README.md @@ -14,7 +14,7 @@ can still change until then. See [Versioning](https://github.com/dborgards/CanKi **Validated:** Demultiplexing and subscriptions, filter overlap, TX confirmation and concurrency, by the test suite in `tests/CanKit.Pro.Tests`, over `CanKit.Adapter.Virtual` and in-repository bus doubles. -**Not validated:** The behaviour of real adapters. TX echo as SocketCAN, Kvaser and Vector deliver it is modelled by a test double (`EchoWorlds`), not observed on those adapters; the "accepted by the driver" approximation for adapters without echo has not been checked against a real driver. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. +**Not validated:** The behaviour of real adapters. TX echo as SocketCAN, Kvaser and Vector deliver it is modelled by a test double (`ControllableBus.EchoCapable`), not observed on those adapters; the "accepted by the driver" approximation for adapters without echo has not been checked against a real driver. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. One `ICanBusService` wraps one `ICanBus` and turns its single `FrameObserved` RX stream into N independent, filtered, read-only `ISubscription`s — so several protocol instances (ISO-TP, diff --git a/src/CanKit.Pro.Uds/README.md b/src/CanKit.Pro.Uds/README.md index 99d22474..b3415442 100644 --- a/src/CanKit.Pro.Uds/README.md +++ b/src/CanKit.Pro.Uds/README.md @@ -15,7 +15,7 @@ NRC-mapping types most of all. See ## What is validated, and what is not -**Validated:** The services listed under *Service coverage*, negative-response handling and the timing options, by the test suite in `tests/CanKit.Pro.Tests`, against `SimulatedUdsEcu` — an ECU simulation written in this repository from the same reading of ISO 14229-1 as the client — over `CanKit.Adapter.Virtual`. +**Validated:** Each service listed under *Service coverage* (some of them thinly), negative-response handling and the timing options, by the test suite in `tests/CanKit.Pro.Tests`, against `SimulatedUdsEcu` — a scripted ECU simulation in this repository whose responses each test defines — over `CanKit.Adapter.Virtual`. **Not validated:** Any real ECU, whose timing, negative-response usage and deviations from the standard the simulation does not reproduce, and conformance as a tester would judge it. Nothing in this package has run against real CAN hardware, a conformance tester or a third-party implementation: the test project references `CanKit.Adapter.Virtual` and no hardware adapter. From 6e34911d47e7ca391363217cd59c40cee62c996d Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 30 Sep 2026 04:58:12 +0000 Subject: [PATCH 4/4] docs: limit the Actor validation claim to the modes each test uses The Actor section said mailbox ordering and the single-writer discipline are validated in all three execution modes. The tests do not do that: the ordering test runs in the default dedicated-thread mode, serialization under concurrent callers is tested in the dedicated-thread and thread-pool modes, and the synchronization-context tests cover marshaling, failure surfacing, timers and dispose, not ordering or concurrent serialization. The section now says which mode each property is tested in. The earlier count of references to the three modes in the test file had counted mentions, not what each test asserts. The other enumerations in the sections were compared against test method names this time rather than against hit counts in test bodies: the J1939-TP timers T1 to T4, ISO-TP's N_As, N_Bs and N_Cr, CANopen SYNC and EMCY, and the UDS services each have a test of that name or subject. Co-Authored-By: Claude Sonnet 5.5 Claude-Session: https://claude.ai/code/session_01UWRpkQzKkNDYz3WiNgWvWU --- src/CanKit.Pro.Actor/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/CanKit.Pro.Actor/README.md b/src/CanKit.Pro.Actor/README.md index 49867e97..60254704 100644 --- a/src/CanKit.Pro.Actor/README.md +++ b/src/CanKit.Pro.Actor/README.md @@ -13,7 +13,7 @@ can still change until then. See [Versioning](https://github.com/dborgards/CanKi ## What is validated, and what is not -**Validated:** Single-mailbox ordering and the single-writer discipline in all three execution modes, the timer queue, the background-exception channel, dispose semantics and cancellation of a queued `PostAsync`, by the test suite in `tests/CanKit.Pro.Tests`. Much of the time-dependent behaviour is tested on a virtual clock; the rest measures real elapsed time. +**Validated:** Mailbox ordering (dedicated-thread mode), serialization under concurrent callers (dedicated-thread and thread-pool modes), and, for the synchronization-context mode, marshaling through the supplied context, failure surfacing, timers and dispose — not its ordering or concurrent serialization. Also the timer queue, the background-exception channel, dispose semantics and cancellation of a queued `PostAsync`, by the test suite in `tests/CanKit.Pro.Tests`. Much of the time-dependent behaviour is tested on a virtual clock; the rest measures real elapsed time. **Not validated:** Real-time scheduling on a loaded production host: timers carry the operating system's scheduling latency and there is no hard real-time guarantee. The package handles no CAN frames, so hardware and foreign stacks do not apply to it.