Forum

Notifications
Clear all

[Solved] S7-1500 ERROR LED on, diagnostics buffer area length error, CPU still in RUN

8 Posts
4 Users
0 Reactions
91 Views
(@kiran_s)
Trusted Member
Joined: 2 years ago
Posts: 48
Topic starter   [#198]

CPU 1516-3 PN/DP on a palletiser, TIA V16. The ERROR LED started flashing red last week and hasn't stopped, but the machine runs, the HMI runs, nothing is stopped.

The diagnostics buffer has the same entry hundreds of times:

"Area length error when reading. Global DB, DB number 120, byte address 4000. Block FC 45. Programming error."

Words may be slightly off, I'm reading it off a photo. I went online and did a STOP and RUN, the LED goes off and comes straight back, and a power cycle does the same. The site electrician says the CPU is faulty and wants to order one, and I can't explain the LED well enough to talk him out of it.

Is there a way to clear it without stopping the machine? Could someone explain what DB120 byte 4000 is telling me, so I've got something to say to him?


Advertisement

   
Quote
(@hkraus)
Eminent Member
Joined: 2 years ago
Posts: 25
 

Not faulty. That entry tells you the block and the byte offset, so it's a programming error, not hardware. What's in DB120 at byte 4000? An array, and what's its length?


Advertisement

   
ReplyQuote
(@kiran_s)
Trusted Member
Joined: 2 years ago
Posts: 48
Topic starter  

DB120 is an "Array[0..999] of Real", so 4000 bytes, and byte 4000 is one element past the end. FC45 reads it with an index that comes from an Int counter in a DB. The counter goes up by one each cycle and I'm not sure where it gets reset.



   
ReplyQuote
(@bram99)
Trusted Member
Joined: 1 year ago
Posts: 33
 

Sorry if this is basic, but would adding OB121 make it go away? I read that the programming error OB stops the error.



   
ReplyQuote
(@carav9)
New Member
Joined: 1 year ago
Posts: 0
 

OB121 decides what the CPU does when the error happens, it doesn't stop the error. On the 1500 the default without OB121 is already to keep running and log it, which is what you're seeing. Add an empty OB121 and the buffer entries most likely carry on.

The bug is the index. The counter runs past 999, FC45 reads element 1000, the buffer fills. Same bug on any platform, an array read with no bound check. Clamp the index before the read: if it's above 999, reset it to 0 or hold it at 999, whichever the logic means. What's the cycle of the OB that calls FC45, and is the counter reset anywhere at all?



   
ReplyQuote
(@hkraus)
Eminent Member
Joined: 2 years ago
Posts: 25
 

There is a writeup on this here: https://plctr.com/s7-1500-area-length-error-in-run/



   
ReplyQuote
(@kiran_s)
Trusted Member
Joined: 2 years ago
Posts: 48
Topic starter  

The counter is reset at 1000 in FC45, but the reset compare came after the array read in the same network. So for one scan each time round, the read used index 1000, one past the end.

Moved the compare above the read, downloaded, buffer quiet since last night. The ERROR LED went off after I did a STOP and RUN, and I'm not sure it would have cleared on its own.

Index one past the array, reset in the wrong order. The electrician has cancelled the CPU order. Thanks carav9.



   
ReplyQuote
(@hkraus)
Eminent Member
Joined: 2 years ago
Posts: 25
 

Off by one, reset after the read. Classic.



   
ReplyQuote
Share: