Repository navigation
fix: match real engineering-tool SZL read and continuation request layouts - #942
Merged
Merged
Conversation
gijzelaerr
force-pushed
the
fix-szl-request-layout
branch
from
October 7, 2026 10:16
f104c83 to
87b03db
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #937.
Replaying captures of real S7-300 controllers showed two byte-level differences from what an engineering tool sends:
build_read_szl_requestused the data header0a 00(a request without data) in front of the SZL id and index. Real tools, and native Snap7 for requests that carry data, send return code0xFFwith octet-string transport size0x09.build_userdata_followup_requestused an 8-byte parameter block with method0x11. Real continuation requests use 12 bytes with method0x12(00 01 12 08 12 <type|group> <subfn> <seq> 00 00 00 00).Both are changed; the follow-up builder is shared, so block-info and list-blocks continuations get the same form. The bundled server did not depend on the old bytes. Tests pin the real SZL read request for SZL 0x0132, index 4 (ignoring the PDU reference) and the new follow-up layout.
I could not confirm whether a PLC rejects the old requests; this aligns the packets with what the captures show a real tool sending.