SZL Parsers

Helpers for decoding System Status List records returned by Client.read_szl() and AsyncClient.read_szl().

Parsers for S7 System Status List (SZL) records.

The SZL is the Siemens mechanism for reading diagnostic and identification data from an S7 CPU. Each SZL ID has its own record layout. These helpers take a parsed S7SZL and decode it into the corresponding typed structure.

Both snap7.client.Client and snap7.async_client.AsyncClient use these helpers so offset and field fixes only have to be made in one place (see discussion #700).

snap7.szl.parse_cp_info_szl(szl: S7SZL) → S7CpInfo[source]

Decode SZL 0x0131 (communication processor info) into an S7CpInfo.

Layout: four big-endian uint16 fields.

snap7.szl.parse_cpu_info_szl(szl: S7SZL) → S7CpuInfo[source]

Decode SZL 0x001C (component identification) into an S7CpuInfo.

Field offsets are relative to the start of the SZL data buffer and match the layout produced by real S7-300/1500 CPUs. See PR #692 for the offset correction and discussion #700 for context on the async follow-up that made these helpers necessary.

snap7.szl.parse_order_code_szl(szl: S7SZL) → S7OrderCode[source]

Decode SZL 0x0011 (module order code + firmware version) into S7OrderCode.

Real PLCs prepend a 4-byte partial-list header (LengthDR + NDR) followed by variable-length records whose layout differs by PLC generation:

S7-1200/1500 (structured records with 2-byte index prefix):

  • 0x0001: main catalog code (MLFB) — version at fixed offsets 23/24/25

  • 0x0002: legacy firmware block (fallback, same fixed offsets)

  • 0x0007: installed firmware — always preferred (matches TIA Portal)

  • 0x0081: boot loader version — ignored (does not reflect firmware)

S7-300 (flat ASCII text stream, no record IDs):

Records contain continuous text (e.g. “CPU 315-2 PN/DP…6ES7…”). The MLFB is located by searching for “6ES7” and the version follows at a fixed offset from the MLFB start.

Note

This is a breaking change from python-snap7 2.x, which returned the boot loader version (record 0x0081) on S7-1500. That version does not match the installed firmware shown in TIA Portal. Confirmed by Siemens documentation and real-hardware testing on S7-1516F, S7-1510SP, S7-1214C, and S7-318.

snap7.szl.parse_protection_szl(szl: S7SZL) → S7Protection[source]

Decode SZL 0x0232 (protection level) into an S7Protection.

Layout: five big-endian uint16 fields.