Skip to content

[cpp-LIN-18] E2E sequence-gap detector resynchronizes after a single flagged error, weakening gap detection over a burst #46

Description

@SoundMatt

Location: src/safety/e2e.cpp (Receiver::unwrap, ~lines 116-125)

Finding: When the E2E receiver detects a sequence gap, it updates its stored last-seen-sequence value to the newly-arrived (unexpected) sequence number before raising the sequence-gap error. The next frame received is then compared against this already-advanced value, so if the shifted counter continues consistently from that point (whether from a persistent fault or a deliberately-crafted stream), the gap is only reported once and every subsequent frame is silently accepted as if it were in order. Typical end-to-end protection state machines keep a separate error/monitoring window rather than immediately resynchronizing to whatever sequence number just triggered the fault, precisely so a sustained anomaly keeps being flagged rather than being accepted after one report.

Recommendation: Consider not advancing the stored last-sequence value on a rejected frame (or track consecutive-error state) so that a persistent out-of-sequence stream keeps being flagged rather than resyncing after a single report. Document whichever E2E profile semantics is chosen.

Filed from the 2026-07-29 ecosystem audit register; independently re-verified against current HEAD before filing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions