2835
Corrupted Data in Production Records
XL200

If Eclipse communication is enabled in the XL, every XL originated error or warning message is supposed to be logged via production records. There were reports of these production records having invalid data in them that would cause Eclipse or Express problems in parsing the message. This resulted in the controller going offline until the offending production record was manually deleted from the controller.

This problem was originaly reported in reference to the Error text provided by PLC error or operator messages. The code was trusting that PLC programmers would follow the spec. Careless programming could result in NULL, STX, ETX or dollarsign characters being in the production record in unexpected places.

Validation code was added to protect from careless programming. The XL code was also reviewed for other conditions that could result in unexpected data being logged in a production record. This resulted in additional changes.

The error text is validated and modified in the following manner.

  1. PLC's are supposed to tell the XL the length of the string followed by the string characters. If they mistakenly use null terminated strings, the NULL character, if not removed, can cause issues with production record parsing. The location of any found NULL character is used to override the length of the string sent by the PLC.
  2. Any character, besides a carriage return, having an ASCII value less than 0x20 (the space character) is replaced with a space character. This eliminates STX, ETX characters an other non-human readable characters. Carriage returns are left for formatting purposes.
  3. Dollar signs are also replaced with spaces since the Eclipse protocol uses dollar signs as a field delimiter.

For some unkown reason the error text was being truncated at the first period encountered. This truncation was removed.

The production record was being generated after the operator cleared the on screen error. This was not a bug but it gave a false sense of event order in the production record log. It also contributed to the likelyhood of a different design choice becoming a bug that could have resulted in corrupted data. The production record is now generated imediately prior, effectively at the same time as, the error message being displayed on the screen

The error text from the PLC was being stored in static variables. A pointer to the static variable was being sent to the User Interface task. Multiple errors in rapid succession could have resulted in the error text being modified before or during the UI displaying the error and before or during the production record being created. The error text is now stored in dynamically allocated arrays that must be deleted by the UI task after they are no longer needed. This eliminates any race conditions the use of static memory variables allowed.

Model Version Released
XL2OL 4.33.00 11/10/2015
XL2CL 4.33.00 11/10/2015
XL220OL 4.08.00 11/14/2016
XL2OL 3.70.00 11/10/2015
XL2CL 3.70.00 11/10/2015