Skip to content

v0.5.0

Latest

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:39
b80a980

Module Name: communication
Release Tag: v0.5.0
Origin Release Tag: v0.4.0
Release Commit Hash: b80a980
Release Date: 2026-10-01

Overview

The communication module provides a generic communication frontend with an IPC binding for use in the S-CORE project.

The module is available as a Bazel module in the S-CORE Bazel registry: https://github.com/eclipse-score/bazel_registry/tree/main/modules/score_communication

Disclaimer

This release is not intended for production use, as it does not include a safety argumentation or a completed safety assessment.
The work products compiled in the safety package are created with care according to the S-CORE process. However, as a non-profit, open-source organization, the project cannot assume any liability for its content.

For details on the features, see https://eclipse-score.github.io/score/main/features/communication/index.html

Improvements

Runtime / API

  • Skeleton-side and proxy-side bindings are now type-erased. EventDataStorage is type-erased, and SkeletonEventBinding and GenericSkeletonEventBinding (and the proxy-side equivalents) are separated and unified at binding level. Generic and typed proxies/skeletons now share one binding implementation. (#897, #1079, #1161)
  • tracing::TypeErasedSamplePtr was removed and replaced by impl::SamplePtr<void>. (#1229)
  • Event data type alignment is exposed through a new API based on memory::DataTypeSizeInfo. GatewayApplication now uses the real alignment instead of a hardcoded 0. (#931)
  • Add-on mw::com configurations can be loaded after the application configuration. Only service definitions are merged, and only if they do not conflict. Internal configuration structures were restructured to minimise locking. (#930, integration test: #1030)
  • Subscription state in LoLa no longer uses a lock. It uses std::atomic access instead. (#1230)
  • Added OffsetRef<T> next to OffsetPtr<T> for reference semantics in shared memory. The bounds check for pointed-to objects was extracted into a shared function. (#1073, #1103)
  • TransactionLogId is now an alias of GlobalConfiguration::ApplicationId, which removes platform-specific uid_t issues. (#1146)
  • Several APIs that propagated exceptions despite noexcept were corrected (MISRA RULE-18-5-1). This also changes test expectations: std::bad_alloc is now thrown instead of terminating. (#1202)

Gateway

  • New QEMU hypervisor transport layer for the LoLa gateway (transport-layer.id: "qemu_hypervisor"). It uses an ivshmem-plain shared-memory BAR for a zero-copy data plane, with the TCP-based bidirectional transport as control plane. (#921, #1108)
  • Gateway transport-layer messages now own their data, via a new GatewayEventInfo type. (#1039)

Configuration

  • Flatbuffers schema as single source of truth for the configuration. Includes a JSON-schema generator, a JSON→fbs converter and a schema drift/roundtrip test. Enabled via --config=flatbuffers, off by default. (#738)

Build, toolchains and warnings

  • C++ toolchains upgraded (score_bazel_cpp_toolchains up to 1.0.4). The score toolchain now enables optimization and fortify. Warning handling was reworked as cc_features. More warnings were enabled and fixed, including -Wconversion and MISRA-supporting warnings. (#1134, #1144, #1147, #1156, #1172, #1179, #1115, #1061, #1065, #1218, #968, #972, #1165, #1112, #964)
  • Migrated off deprecated APIs and runtime initialisation. (#1164, #1162, #1170, #1034)
  • Dependency updates and cleanups: baselibs 0.2.12 → 0.2.14, S-CORE C++ policies from BCR, score_docs_as_code no longer a direct dependency, memory/shared dependency cleanup. (#1043, #1191, #1201, #1110, #1136, #1196, #1234, #1089, #1098, #1183)
  • More harmonised --config= options. (#1111)
  • Rust: formatting infrastructure introduced and Rust code formatted (30 files). Baselibs Rust targets migrated, and Rust edition tags removed. (#1037, #1129, #1050, #1117)

Quality, static analysis and CI

  • Large clang-tidy cleanup campaign. Findings were fixed across ~50 PRs, e.g. #1003 (60 files), #992, #1000, #1001, #1012, #1014, #1015, #1185, #1207, #1208 and #1227. clang-tidy configuration was refined (external repos excluded, #995).
  • MISRA/CodeQL: RULE-7-0-5 signedness fixes (40 files), RULE-0-1-2, RULE-9-4-2 and RULE-18-5-1 fixes. Documented deviations were added for RULE-6-8-3, RULE-8-2-3 and RULE-21-6-3. (#1011, #1206, #982, #1202, #983, #984, #977, #1078)
  • CodeQL MISRA pack resolution works offline without mutating $HOME. SARIF report generation was fixed. (#1081, #1217)
  • Coverage reporter no longer fails for tests without C++/Rust coverage data. (#1157)
  • CI: flaky-test detection is sharded, workflows no longer block when cancelled, and review-checklist bot fixes were made. (#1082, #963, #978, #979)

Testing

  • Large expansion of integration tests: skeleton/proxy method move semantics, an all-service-elements test (events, fields, methods), disabling field set/get, mixed-criticality fields, a bigdata core-dump extraction, and a QEMU PCI fix for flaky ITF tests. (#659, #820, #1018, #857, #858, #739, #1108, #1034, #1052)
  • Tests were split into public-API tests and impl tests (45 files). (#1010)

Documentation, requirements and safety artifacts

  • mw/com dependability requirements were split along the high-level architecture and per unit. Generic proxy/skeleton service element requirements were split and moved. (#1007, #1008, #1033, #1027, #1040)
  • Assumed system requirements were reworked. score_tooling was updated to 2.2.2. (#1101, #1075)
  • Safety Sentinel: unit/component Bazel targets were added, architectural design fixed, and generic skeleton/proxy removed from the binding level. The static design now uses a coarser component architecture, and SOME/IP was removed from it. FTA for stop_offer was reworked. (#1068, #1193, #1069, #1173, #1145)
  • Docs: tutorial uses Sphinx tag-referencing markers, message_passing public_api.puml was fixed, the documentation project was renamed, and the release template verification steps were updated. (#1131, #1056, #1133, #1005, #1009, #969)

Bug Fixes

  • Fixed static destruction order fiasco in MemoryResourceRegistry and SharedMemoryFactoryImpl (nifty-counter idiom). (#884)
  • Fixed the proxy method rvalue-extraction test helper. (#1052)
  • Removed duplicated and error-prone OnProxyMethodUnsubscribe logic. (#1058)
  • Gateway: fixed a dangling-buffer risk for ProvideServiceRequest (messages own their data) and the hardcoded event alignment. (#1039, #931)
  • Fixed the platform-specific uid_t transaction-log ID handling (partial fix for #1105). (#1146)
  • Fixed missing build dependencies and the QNX QEMU PCI module lookup. (#1089, #1183, #1108)
  • Fixed missing-break switch terminators (MISRA RULE-9-4-2) and return-value handling in sample apps. (#982, #1213, #1200)
  • Fixed the coverage reporter, SARIF generation and the review-checklist bot. (#1157, #1217, #978)

Compatibility

Performed Verification

  • Unit test execution on host with all supported toolchains
  • Build and test on QNX8 x86_64
  • Thread sanitized unit test execution
  • Address, undefined-behavior, and leak sanitized unit test execution
  • Static analysis / linting (clang-tidy, clippy, ruff) via the Aspect CLI, with findings uploaded to GitHub Code Scanning
  • CodeQL MISRA C++ compliance analysis on both Linux and QNX (--config=qnx), merged into a single compliance report
  • Code coverage report generation (llvm-cov) across the C++ test suite
  • Documentation build and packaging (Sphinx) for the release version

Known Issues

Build / ecosystem compatibility

  • Bazel 9+ is not supported. The supported range is 8.6 ≤ Bazel < 9 (.bazelversion: 8.7.0). (#694)
  • rules_python 2.x is not supported. The module pins 1.8.5. (#695)
  • Build can fail with toolchain resolution errors or dependency mismatches against latest main. (#336)
  • Active downstream patch: score_baselibs is patched with a QNX8 poll workaround (third_party/score_baselibs/restore_qnx8_poll_workaround.patch), pending a fix in the QNX SDP (see eclipse-score/bazel_cpp_toolchains#68). It is applied via single_version_override in the root MODULE.bazel. Consumers using this module as a non-root module must apply an equivalent override themselves.
  • Dev-only workarounds: score_itf and hedron_compile_commands are pinned via git_override, and rules_doxygen is patched. These affect local development and CI only, not consumers.

Runtime / API

  • Unsubscribe failures in EventSubscriptionControl::Unsubscribe() are treated as fatal and call std::terminate(). (#722)
  • Calling a method from within another method's callback handler is not possible. (#767)
  • File descriptors opened when offering a service are not created with CLOEXEC and leak into forked/exec'd children. (#1064)
  • The deprecated GetSampleSize() has not yet been removed. (#975)
  • Lola transaction-log invalid-ID sentinel can differ between QNX and Android domains (only partially addressed by #1146). (#1105)

Gateway

  • GatewayApplication terminates unexpectedly when a skeleton/proxy pair is stopped and the skeleton restarted. (#1116)
  • Multi-VM topology and VM restart/gateway recovery are not yet supported. (#1141, #1140)

Rust API

  • Rust Method/Field APIs, E2E protection and the mock runtime are not yet implemented. (#782, #781, #1062, #579, #490)
  • ConsumerDescriptor::get_instance_identifier returns InstanceSpecifier. (#1080)

Quality / tooling

  • Many integration tests are tracked as flaky (label flaky-test, e.g. #1168, #1107, #1097, #1096).
  • CodeQL loses location information for some findings and ignores some production sources. (#1104, #751)
  • api_surface --check-docs crashes with KeyError: 'file' when undocumented symbols exist. (#1053)
  • The communication documentation is not included in the Reference Integration. (#805)
  • Buildifier CI setup misses some issues. (#1236)

Upgrade Instructions

Backward compatibility with the previous release is not guaranteed.

Public API changes (score/mw/com/api_surface.lock.json) compared to v0.4.0:

  • Added: runtime::AddConfiguration(const RuntimeConfiguration&) and runtime::AddConfiguration(score::json::Any), both returning Result<void>, for loading add-on configurations (#930). GenericProxyEvent::GetDataTypeSizeInfo() returns memory::DataTypeSizeInfo (#931). Converting constructors and Swap overloads between SamplePtr<T> / SampleAllocateePtr<T> of different sample types were added.
  • Deprecated: GenericProxyEvent::GetSampleSize() is now [[deprecated]]. Use GetDataTypeSizeInfo().Size() instead.
  • Signature changes:
    • runtime::ResolveInstanceIDs now takes const InstanceSpecifier& instead of by value (#1003).
    • GenericProxyEvent::SetReceiveHandler, UnsetReceiveHandler and Unsubscribe are no longer noexcept (#1202). They may now propagate exceptions, so callers that relied on noexcept must adapt.
    • Binding-related constructors of GenericProxyEvent and GenericSkeletonEvent now take the unified ProxyEventBinding / SkeletonEventBinding types, and SkeletonEventBase's constructor takes an additional std::optional<InitializeSampleCallback>. These are relevant only to code constructing events directly (#897, #1079, #1161).

Contact Information

For any questions or support, please raise an issue/discussion.