CanLab/docs

CanLab

A desktop workstation for reverse-engineering a CAN bus. Load a capture, work out which bytes carry what, write the signal definitions down, check them against real frames, and export a DBC that other tools can read.

Watch it work

The guided tour

6:06

One pass through the whole tool against two real recordings. Start here. Open on YouTube, or download the MP4 with subtitles.

For each beat the frame pushes in on the control being described, dims the rest, rings it and captions it, then pulls back out. The rectangle is the widget's own geometry, read off the live window at record time, so a control that moves in a later build takes its callout with it.

It is a real analysis. The first capture turns out to be a marine NMEA 2000 bus rather than the J1939 that 29-bit identifiers usually suggest. The counter detector finds the sequence byte the specification defines without being told the protocol. A wind speed signal is defined, and the same two bytes are plotted both ways round: little-endian reads 0.72 to 0.87 m/s, big-endian claims 184 to 223.

The full walkthrough

Every tab, in four parts, recorded from the running application with captions on by default.

1. Loading a capture and finding structure

2:58

FRAMES, the ID panel and inspector, SIGNALS, counter and checksum detection, the checksum guesser, entropy boundaries.

2. Defining signals and checking them

2:40

DBC BUILDER and its bit grid, the live decode preview, PLOT, INTELLIGENCE, ML INTEL, DASHBOARD.

3. Timeline, code generation and exports

2:25

TIMELINE, CODE GEN, the five export formats, DIAGNOSTICS, security access.

4. The transmit gate, injection and live capture

3:23

ARM TX, INJECTION, replay, fuzzing, GATEWAY, OBD-II, the AI engine, live capture.

All the videos are generated rather than hand-recorded. The recorders drive a real main window under Qt's offscreen platform and call the same slots the buttons call, so a scene that stops working fails the run instead of quietly recording a stale screen.

What it is for

You have a capture from a vehicle bus and a few thousand frames of hex. The job is to work out which arbitration IDs matter, which bytes inside them move, which of those are actually signals rather than counters and checksums, what physical quantity each one represents, and then to write that down in a form other tools accept. CanLab is built around that loop.

What it is not

It is not a signal identifier. The analysis produces candidates ranked by heuristics, and a confidence figure is a match fraction over the frames you loaded, not a proof. Every result needs verifying against the vehicle before you rely on it. The project is a single-author effort, in beta, and has not been validated across a wide range of real vehicles. The limitations are listed plainly.

Before you connect to anything

CanLab can transmit on a CAN bus. Use it only on isolated bench setups: a benchtop ECU, vcan0, or dedicated lab hardware. Injecting or forwarding frames on a live vehicle bus can interfere with braking, steering and airbag systems. Read Safety first.

Try it without hardware

A sample capture ships with the source at canlab/sample_data/sample_kona_drive.csv: 6,610 frames across 10 arbitration IDs over 10 seconds, at rates from 1 Hz to 100 Hz. Every offline feature works on it, so you can go through the whole workflow before touching a vehicle.