CanLab/docs

Safety

CanLab can put frames on a CAN bus. This page is about what stops it doing that by accident, and, just as importantly, where that protection ends.

Bench use only

Use the transmit features only on isolated setups: a benchtop ECU, vcan0, or dedicated lab hardware. Injecting or forwarding frames on a live vehicle bus can interfere with braking, steering and airbag systems. A vehicle on jack stands with the engine running is still a live vehicle.

The ARM TX gate

There is one global toggle in the toolbar, ARM TX, and it is off when the application starts. While it is off, the paths below refuse to transmit. They also re-check on every frame, so turning it off stops a run that is already going rather than merely preventing the next one.

PathWhere
Signal injection, single and loopingINJECTION → INJECT
Replay of a captureINJECTION → REPLAY
Trigger-driven sendsINJECTION → TRIGGERS
Actuator sweepINJECTION → SAFETY SCAN
FuzzerINJECTION → FUZZ
Scripted test sequencesINJECTION → TEST SEQUENCE
Gateway forwardingGATEWAY
UDS Clear DTCDIAGNOSTICS
The REST /inject endpointNeeds the API token and ARM TX
What the gate does not cover

Ordinary diagnostic reads put request frames on the bus without checking ARM TX: the UDS scans and identifier reads, OBD-II polling, and ISO-TP requests. This is deliberate, on the grounds that they only read ECU state, but it means disarmed is not the same as silent. If you need the tool to emit nothing at all, disconnect the bus.

The other guards

  • A warning you have to accept on first launch. The acceptance is remembered, so it appears once.
  • The UDS service scan is read-only by default. It probes only services that read. Destructive ones, such as ECU reset and clear diagnostics, are skipped unless you tick Include destructive services and confirm. Those do exactly what their names say.
  • Security-access brute force is rate limited and stops the moment the ECU reports its attempt limit. Tripping that counter can lock a module until it is power cycled, and on some modules permanently.
  • The actuator sweep has a watchdog. Give it an arbitration ID that should keep appearing; if that ID goes silent, the sweep aborts on the assumption that something upstream has cut out.
  • Plugins do not run until you enable them. See plugins.

Working safely

  1. Start on a virtual bus

    Everything except real ECU responses works on vcan0. Get your injection payloads right there first. See hardware interfaces for the three commands that set one up.

  2. Then a bench ECU on its own

    One module, its own power, its own bus segment, terminated properly. Nothing else on the wire that you would mind confusing.

  3. Watch before you write

    Capture and analyse first. If you do not know what a message normally carries, you cannot tell whether your injected version is plausible.

  4. Arm deliberately, disarm immediately

    Turn ARM TX on for the moment you need it and off again after. It is a toggle rather than a per-action prompt precisely so that leaving it armed is a visible state.

If you are testing a real vehicle

That is beyond what this project is built or tested for, and nothing here should be read as a recommendation to do it. If you do, the parts that matter are the ones this tool cannot give you: a way to cut power quickly, a vehicle that cannot move, and somebody else present. Reading is a much smaller risk than writing, and most reverse engineering is reading.