Safety Standards
The automotive and off-highway safety landscape. Click any expandable standard to explore its specification tree.
IEC 61508 is the umbrella - most domain-specific safety standards derive from it.
Physical and Data Link
J1939-11 Physical layer 250k Shielded twisted pair, 250 kbit/s
J1939-14 Physical layer 500k 500 kbit/s high-speed
J1939-21 Data link layer 29-bit ID = Priority(3)+EDP(1)+DP(1)+PF(8)+PS(8)+SA(8). 24-bit PGN addressing. Own transport protocol BAM/CMDT.
J1939-22 CAN FD data link variant Multi-PG over CAN FD. The CAN FD path for J1939.
Application and Management
J1939-71 Vehicle application layer PGN and SPN dictionary - the signal definitions
J1939-73 Diagnostics DM1..DMx messages. DTC = SPN + FMI. Basis for ISOBUS and WWH-OBD diagnostics.
J1939-81 Network management Address claim procedure (PGN 60928), NAME, dynamic addressing
J1939-02 Ag and forestry off-road profile Off-road machinery application profile
Stack Relationships
ISO 11898 Runs on CAN Mandatory CAN 2.0B extended (29-bit). J1939 permits no alternative data link.
ISO 11783 (ISOBUS) Ag derivative ISOBUS data link and diagnostics are derived from J1939-21 / -73
Specification Parts
ISO 14229-1 Services The diagnostic service set (request/response, NRCs)
ISO 14229-3 UDSonCAN CAN binding. Supersedes legacy ISO 15765-3.
ISO 14229-5 UDSonIP IP binding - pairs with DoIP (ISO 13400)
ISO 14229-7 UDSonLIN LIN binding
Transport Layer
ISO 15765-2 DoCAN / ISO-TP Segmentation + flow control on CAN. Present in Zephyr as CONFIG_ISOTP.
ISO 13400 DoIP Diagnostics over IP/Ethernet - transport for UDSonIP
Key Services (SIDs)
0x10 DiagnosticSessionControl default / extended / programming session
0x19 ReadDTCInformation fault codes, status, freeze frames
0x22 ReadDataByIdentifier read params by DID
0x27 SecurityAccess seed/key authentication
0x34/0x36/0x37 Firmware update sequence RequestDownload / TransferData / RequestTransferExit
0x3E TesterPresent session keep-alive heartbeat
Coding Standards & MISRA C
Zephyr enforces MISRA-C 2012 as a mandatory coding standard across the kernel and safety-relevant subsystems. All new code must comply.
MISRA-C 2012 in Zephyr
- 147 rules + 5 project-specific - all marked Required, not advisory. No optional rules.
- No dynamic memory allocation -
Dir 4.12:
malloc,free,reallocprohibited in safety-relevant code. - No undefined behavior - Rule 1.3: all code paths must have defined behavior per the C standard.
- Restricted standard library -
Only minimal libc functions permitted in the kernel. No
stdio.hin safety paths. - CERT C complementary - CERT C secure coding recommendations applied alongside MISRA.
Linumiz Quality Practices
- Static analysis on every commit - Automated MISRA-C checks in CI pipeline before merge.
- Hardware-in-the-loop verification - Every driver tested on physical silicon, not simulators. 98.76% CI pass rate 8,886 of 8,998 test cases passing.
- SEooC safety artifacts - 16 work products per component: safety requirements, architecture, traceability, test evidence. Developed to ISO 26262 ASIL D process.
- Implementation findings - 31 code-level findings identified and severity-classified. 4 HIGH severity requiring code changes before certification.
- Upstream-first development - All code submitted to mainline Zephyr, reviewed by Architecture WG. Community review adds an independent quality gate.
Safety Roadmap
Full roadmap ->Zephyr Community (Kernel)
IEC 61508 SIL 3 | Kernel only | No drivers, no BSP
Linumiz (Drivers & Platform)
Targeting ISO 26262 ASIL D | Drivers, arch, BSP | 16 work products per SEooC
Safety Process
Full details ->Zephyr Kernel (community-developed)
- - Threads & Scheduler
- - Semaphores, Mutexes, Queues
- - Memory Protection (abstract)
- - Interrupts & Timers
Linumiz Platform (SEooC)
- - Drivers: CAN, SPI, I2C, UART, ADC
- - Arch: MPU, fault/trap, CSA, IR
- - BSP: Initial platform: Infineon AURIX (extensible to any Zephyr-supported target)
- - CI/CD: Labwire (Part 8)
Safety Team
Full team ->Tier-1 background
End-to-end expertise
System integrator
IEC 61508 / ISO 26262