EtherCAT Startup: DC Clock Synchronization, Drive-Config Reliability, and Diagnostics
MAJOR IMPROVEMENT TO DC CLOCK SYNCHRONIZATION TIME AT STARTUP Two changes cut worst-case synchronization from tens of seconds to under one second:
Convergence-based clock stabilization. Startup used to propagate the reference clock with a fixed 10,000 writes (a magic number copied from the reference driver), costing the same few seconds every boot no matter how many drives were present. It now propagates the clock while polling each drive's System Time Difference register and stops as soon as every drive has settled within tolerance and stayed there, auto-scaling to the actual network. A single drive converges in a fraction of the writes and a one-drive setup skips it entirely; the 8-drive ctrlX measured 2,350 writes / 421 ms instead of the old fixed multi-second loop.
Robust phase-lock detector (leaky accumulator). The master's check for whether it is locked to the drive clock used to require a run of consecutive in-tolerance cycles and reset to zero on any single out-of-tolerance cycle. On a busy multi-drive network, occasional send-jitter spikes kept resetting that run, so lock time grew exponentially: an 8-drive segment could take 25,000+ cycles (about 25 s), within 5 s of the 30 s timeout that aborts startup. Replaced with an accumulator that gains on good cycles and only leaks slightly on bad ones, making lock time scale linearly with jitter instead of exponentially. It now locks in about 250 cycles (about 0.28 s) even on the noisy 8-drive segment, removing a real risk of startup timing out and failing to come up.
FIXED INTERMITTENT DRIVE-CONFIGURATION FAILURES DURING MULTI-DRIVE STARTUP The EtherCAT mailbox reads and writes that configure each drive were using a 20 ms response timeout (EC_TIMEOUTSAFE, which is actually meant for wireless frame return) instead of the 700 ms mailbox timeout that operation is supposed to use. With eight ctrlX drives coming up together, a drive occasionally took just over 20 ms to answer; the controller gave up early, and the drive's late reply then landed in the next transaction's slot, shifting the whole message stream by one and failing a drive timing-parameter write (S-0-1007). Corrected all 49 mailbox calls (SoE and CoE) to the proper timeout. As a backstop, the shared communication library now recognizes and discards a stale or mismatched reply and re-reads for the correct one, so even a rare slow drive cannot desynchronize the setup sequence. Startup is now clean, error-free, and quicker.
MADE THE STARTUP TIMING READ-OUTS ACCURATE The clock-sync lock time was being sampled well after the lock actually happened, which made it look far slower than reality; it now captures the true time-to-lock and reports it in both cycles and milliseconds. Jitter and cycle-deviation figures are reset at the moment of lock, so the operating numbers reflect steady running rather than the momentary startup transient. The stabilization step also now reports how long it took.
PRODUCTION CLEANUP AND REDUCED STARTUP NOISE Removed a diagnostic read of parameter S-0-0028 (a drive missed-frame counter) that neither supported Bosch drive family implements; it only logged a "no such parameter" error every boot for a value nothing used. Bench-only diagnostic probes were placed behind a compile switch so they do not run in production, and a leftover manual tuning enable was removed.
| Model | Version | Released |
|---|---|---|
| XL2OL | 5.110.0 | 9/28/2026 |
| XL2CL | 5.110.0 | 9/28/2026 |
| XL220OL | 5.110.0 | 9/28/2026 |
| XL220CL | 5.110.0 | 9/28/2026 |