CAN bus/The message/When a frame goes wrong
Lesson 9 of 12 · in 3D and VR

When a frame goes wrong

Five kinds of error are detected, announced with an error flag and retried. Two counters in every device decide when it must go quiet, and the last stage is its own state called bus off.

Lonely BinaryUpdated 2026-10-085 min readNo board required

View it in VR

Lesson 9 of the CAN bus course opens in a VR headset, on a table in front of you, and a voice starts three seconds after you arrive. Type this short address into the browser on a headset such as Meta Quest or Apple Vision Pro, and press Enter VR. No headset? Press Start the lesson: the same lesson, full screen.

learn.lonelybinary.com/vr/can/9

Five ways to be wrong

A device checks every frame it sends or receives for five kinds of error. A bit error is a sender reading on the rail something other than what it sent. A stuff error is six equal bits in the stuffed part. A check error is a received check that does not match the bits. A form error is a fixed field that is not as it should be. An acknowledgement error is a slot that nobody answered.

The error flag

A device that finds an error announces it with an error flag, and the frame is discarded by everyone. The sender then tries again. An error-active device sends an active flag, which is dominant, so every other device sees it. An error-passive device sends a passive flag, which is recessive and cannot override anything.

Two counters

Each device keeps a transmit error counter and a receive error counter. In the main case, a failed send adds 8 to the transmit counter, a bad receive adds 1 to the receive counter, and a good frame takes 1 off. There are exceptions, and the lone sender of lesson seven is one. Because failure costs eight and success repays one, an occasional failure is forgiven and a run of them climbs quickly.

Active, passive, bus off

Below 128 on both counters a device is error active. At 128 on either one it becomes error passive: it still sends, but its flag is recessive and it waits longer between its own messages. When the transmit counter reaches 256 the device is bus off. At eight per failure that is 32 failed sends in a row.

Bus off is the device's own controller taking it off the rail. Nobody threw it off, and it says nothing about the sensor behind it. It does not come back by itself: software has to start the recovery, and the controller then waits for a long quiet stretch on the rail before counting from zero.

What is not an error

CAN checks that a frame arrived intact, not that its content makes sense. A silly temperature with a correct check passes every test.

Common mistakes

  • Reading bus off as a broken sensor. It follows from transmit errors on the rail, such as a wiring fault or a mismatched bit rate. A bad reading with a good check never counts.
  • Expecting a bus off device to return unaided. It stays off until software restarts it.
  • Assuming every error flag is heard. An active flag is dominant and overrides the frame; a passive one is recessive and may pass unnoticed.

Edit this page — content/fundamentals/can/when-a-frame-goes-wrong.mdx

Discuss this article

Ask about this page. The answer stays here, on the page it belongs to, for whoever hits the same wall next.

Browse Fundamentals on the forum →