Skip to content
PodcastsEducationHacker Public Radio

Hacker Public Radio

Hacker Public Radio
Hacker Public Radio
Latest episode

358 episodes

  • Hacker Public Radio

    HPR4738: Programmable Logic Controls - Episode 4

    30/09/2026
    This show has been flagged as Clean by the host.

    --------------------







    01 Introduction







    This is the fourth episode in an 8 part series.







    02



    In the previous episode we looked at the Allen Bradley PLC2, one of the very early successful Programmable Logic Controllers.







    In this episode we will look at another early PLC, the Siemens S5 series, and use it as an example of both how PLCs became more sophisticated, as well as an example of a different approach to the overall software architecture.







    Again, I will only touch on this topic lightly, this is not a course on how to program PLCs.



    However, I will give you enough technical detail to give you are rough idea of what they were like.







    --------------------







    03 S5 Historical Background







    Siemens are the largest PLC vendor on a global basis, and have been since the early days.







    Their first PLC was the S3, released in 1975, two years before Allen Bradley released the PLC2.



    There seems to be almost no information available on the S3, so I can't say much about it.







    In 1978 or 1979, sources are unclear about the exact date, Siemens released the S5 series.



    This was a huge step forward in capability and was the foundation of their PLC product line until replaced by the S7 series in the mid 1990s.







    In this episode I will focus on the U series, which were an upgrade to the original S5.







    --------------------







    04 A Complete Family of PLCs







    Fully developed, the Siemens S5 series was a complete family of products covering the entire size spectrum from smallest to largest.



    Siemens covered the entire industrial control market, and there was almost nothing they didn't have somewhere in their catalogue.



    You could spend an entire career using nothing but Siemens products for everything.







    05



    At the lowest end were the S5-100 series, consisting of the S5-100, 102, 103, 90, and 95.



    These covered everything from the small "shoebox" all in one form factor to ones which overlapped the mid range in terms of capability except for their compact I/O cards which were smaller and slower than the full size models.







    The S5-115 formed the mid range, coming in a "full size" form factor in terms of packaging and rack size.



    The S5-135 and S5-155 extended the S5-115 in terms of speed and memory.







    06



    In this episode I will focus on the lower end S5-100 series for the sake of simplicity, and will not make any reference to any additional capabilities of the larger models.



    It will be much too time consuming and confusing to try to cover everything, and there wouldn't be much point to it.







    --------------------







    07 Data Memory Types







    If you recall the previous episode, the Allen Bradley PLC2 had a data table, or memory system, that was a single linear range of memory with all I/O and internal capabilities mapped into fixed numerical addresses.



    Allen Bradley were to abandon this approach in their later PLC5 series introduced in the mid to late 1980s, but we won't cover that here.







    The Siemens S5 series however took the approach of having different types of memory addresses for different purposes.







    I will describe those for the S5-100 series now.







    08 Input and Output Addresses



    The standard I/O modules for these compact PLCs had 8 inputs or 8 outputs per I/O module.







    These module plugged into a flat bus (as opposed to an enclosed rack) with slots numbered from 0 through 31 in decimal.



    Each of these slots had an associated byte number, and each I/O point on the individual modules had a bit number.







    09



    Input and output addresses had the following format.



    Letter , number, decimal point, number.







    The letter was either I or Q.



    I indicated inputs.



    Q indicated outputs.



    The first number was the byte number, which corresponded to the physical I/O module slot.



    The second number was the bit number within the byte, starting from zero.







    10



    So "I2.3" indicated an input module located in the third slot (numbered from zero) and addressed the fourth input (numbered from zero) on that module.







    Outputs worked the same way.



    For example "Q 5.1"







    11



    Analogue modules could be located slots 0 through 7.



    Analogue if you recall, refers to voltages which have varying levels rather than just on or off, and can represent things like temperature.



    Each analogue module was assigned 8 bytes per slot, starting at address 64 and going up to 127.



    In practice many of these so called "analogue" modules had nothing to do with actual analogue voltages, but rather any advanced module which needed more address space was used here.



    Even later high density digital I/O used these addresses.







    12



    Each of these addresses could be addressed as bytes or words.



    In this case input bytes were indicated by an "IB" prefix, and input words were indicated by a "IW" prefix.



    Output bytes used a "QB" prefix and output words used a "QW" prefix.







    13 Flags



    Flags are individual bits of internal memory that are used for storing intermediate logic values.



    These began with an "F" prefix.



    An S5-103 had a total of 2048, numbered from F0.0 to F255.7.







    14 Counters



    Counters started with a "C" prefix.



    An S5-103 had 128 of these numbered from C0 to C127.







    15 Timers



    Timers started with a "T" prefix.



    An S5-103 had 128 of these numbered from T0 to T127.







    16 Data Blocks



    Programs needing to deal with byte and word memory could create what were known as "Data Blocks".



    These were blocks of PLC memory that could be created as the discretion of the programmer.



    An S5-103 could have a maximum of 254 data blocks numbered from DB2 to DB255.



    Two additional data blocks were reserved for the PLC's internal operations.



    Data blocks could contain up to 255 16 bit words.







    17



    However, the actual number and size of data blocks would in practice be limited by available memory.



    Even 20 kilo bytes was considered to be a large memory, and this had to be shared with the program.



    A data block would be "called" to make it the current data block.



    Then individual words would be addressed with the "DW" prefix.



    For example "DW5".







    --------------------







    18 Program Blocks







    If you recall with the PLC2, there was a "main" program and a series of optional numbered subroutines.







    In the S5, programs were split into "blocks".







    These were



    Organization Blocks



    Program Blocks



    Function Blocks



    Sequence Blocks







    An S5-103 could have up to 256 of each of these blocks.







    19 Organization Blocks



    When the PLC started up, it would look for Organization Block 1 and begin execution there.



    You could consider this to be the equivalent of the "main" function in a C program.



    Organization blocks had an OB prefix.



    For example OB1.



    With a very simple program in a very small S5 PLC, all of the program logic could be simply put in OB1.



    However, with larger programs , it was convention to put the logic in subroutines and simply have OB1 call each subroutine.







    20 Program Blocks



    These had a PB prefix.



    For example PB10.



    Normal ladder logic style programming would go in these.



    It was convention to split up a program into pieces and put piece in its own program block.



    Normal practice was to have a program block correspond to a particular part of the machine.







    21 Function Blocks



    These had an FB prefix.



    For example FB64.



    Function blocks differed from program blocks in that they could take parameters.



    This allowed you to write an FB that performed some sort of complex data transforms and re-use it by calling it with different parameters.



    Some instructions could only be used in FBs, not in other types of blocks.



    There were also built in FBs in some CPU models which performed certain operations such as converting BCD (or Binary Coded Decimal) to normal integer.







    22 Sequence Blocks



    These has an SB prefix.



    For example, SB25.



    These were like PBs, but were intended for controlling sequences of operations where each SB performed as single step of the sequence and multiple blocks were used for a sequence.







    --------------------







    23 Programming Languages











    The S5 series offered four different programming languages.







    These were



    Ladder (abbreviated as LAD)



    Statement List (abbreviated as STL)



    Control System Flowchart (abbreviated as SCF)



    GRAPH 5







    24



    You should be familiar with ladder if you listened to previous episodes.



    Briefly however, it is a graphical programming language which followed the appearance of electrical ladder wiring diagrams which were familiar to engineers, technicians and electricians working with manufacturing equipment.







    25



    Statement List is a text based programming language which resembles an assembly language for an abstract processor architecture.



    Boolean logic results were calculated and saved on a stack, while integer values were operated on directly from memory or in two accumulators, ACCU1 and ACCU 2.







    26



    Control System Flowchart is a graphical language that takes the form of rectangular blocks with one or more inputs and an output.



    These blocks are laid out on a screen and then wired together rather like logic gates in a electronic schematic.







    27



    GRAPH 5 is Siemens' implementation of the GRAFCET (Graphe Fonctionnel de Commande Étapes Transitions) IEC 60848 flow chart standard.



    The IEC are the International Electrotechnical Commission, an international standards organization.







    28



    I will focus on Ladder and Statement List, as these were by far the most commonly used and we have limited time to discuss the S5.







    --------------------







    29 Statement List



    As mentioned above, Statement List can be thought of as the assembly language for an abstract CPU architecture.



    The firmware in the S5 PLC will run the instructions in an interpreter.







    30 The RLO



    Boolean or bit oriented instructions operate on a logic stack known as the RLO, or Result of Logic Operation.



    Boolean operations typically take one operand.



    When a boolean operation is executed, if the RLO is empty it simply loads the operand onto the RLO.



    If the RLO is not empty, then the instruction is executed using the operand and the RLO, and the result replaces the value on the top of the RLO stack.



    Some boolean instructions do not take an operand, but rather work on the two topmost values on the RLO.



    If you are familiar with languages such as FORTH, this should sound very familiar.







    31 The Accumulators



    Word oriented instructions work on two accumulators, ACCU 1 and ACCU 2.



    A load instruction will load a word or byte value from a memory location or a constant into ACCU 1.



    The value that was in ACCU 1 then gets shifted into ACCU 2.



    A transfer instruction will write the value in ACCU 1 to memory.



    The remaining word oriented instructions will operate on the values in ACCU 1 and ACCU 2, and place their result in ACCU 1, overwriting the existing contents.



    So for example, an add instruction will add the value in ACCU 2 to the value in ACCU 1, leaving the sum in ACCU 1.







    32 Ladder



    As mentioned above, ladder is a graphical programming language which has the appearance of an electrical control ladder diagram as used with actual relays.



    The is by far the most common programming language used with PLCs.



    A ladder program however is just another way of presenting statement list.







    33



    To put it another way, a statement list program can be displayed on a computer screen as either lines of text, or a graphical symbols laid out in a meaningful pattern.







    All valid ladder programs can be represented as statement list.



    However, not all valid statement list sequences can be represented as ladder.



    Statement list is inherently more flexible than ladder, which means that you simply can't always translate both ways fully.







    34



    None the less, most typical control logic can be represented as ladder, and ladder is the preferred representation as it is quicker to understand at a glance when debugging a software or hardware problem.







    On the other hand, some statement list instructions have no ladder equivalent, or the algorithm may not lend itself to being represented in ladder.







    In these cases normal practice is to put the simple control logic in ladder in Program Blocks, and put the non-translatable statement list logic in Function Blocks.







    35 Control System Flowchart and GRAPH 5



    Like ladder, CSF and GRAPH 5 are actually implemented in statement list, and many of the considerations mentioned above apply to those as well.



    However, I won't go into any further detail on these here.







    --------------------











    36 Programming Software and Hardware







    There were two ways of entering a program into an S5 PLC.



    One way was the hand held programming terminal.



    The other was via the STEP 5 programming software.







    37 Hand Held Terminal



    Like many if not most PLC vendors, Siemens sold a hand held programming terminal.



    There were a series of these, an example being the PG 605.



    This was a box like a large calculator which had buttons and a small display.



    The buttons corresponded to various instructions and a numeric keypad, and the display would show the current instruction being entered.



    To use it you would plug a cable attached to the hand held terminal into the programming port on the front of the PLC CPU module.



    You could then enter or view the program, one instruction at a time.







    38 STEP 5 Programming Software



    The other way of programming was to use software running on a PC.



    Siemens called their software STEP 5.



    This was an integrated editing and debugging program.



    Originally it ran on CP/M.







    39



    Siemens sold their own portable PCs with the software preloaded, and with additional built in hardware features such as an EPROM burner.



    These computers were also known as "PGs".







    STEP 5 was later ported to MS-DOS by running it on a CP/M emulator which people would use to run it on an off the shelf PC such as a laptop.



    Later still a native MS-DOS port was produced.







    40



    This had modes for Statement List. Ladder, and Control System Flowchart.



    GRAPH 5 was a separate program.







    You could toggle between STL, LAD, and CSF modes, and if the software could translate what was there form one mode to another, it would.







    41



    The PC would be connected to the PLC by a cable which had an interface box in the middle.



    This could be used to download a program to the PLC,



    upload a program to take a backup,



    modify a running program,



    or debug a running program.











    --------------------







    42 Instructions







    I won't list all the instructions, as that would take too long.



    I will instead give a brief overview of them.



    I will deliberately skip over obscure instructions that would take too long to explain.







    43 Basic Operations







    Boolean Operations



    There is a full set of boolean operations including and, and not, or, or not, set, reset, and assign.



    The assign operation would assign the RLO value to the address of the specified operand.







    44 Load and Transfer



    The Load instruction would load the value of a memory address word or byte or a constant into accumulator 1.



    There are about 2 dozen variations on the load instruction.







    The transfer operation would write a word or byte from accumulator 1 into memory.



    There are about a dozen variations of the transfer operation.







    45 Timers and Counters



    There are 5 different types of timers.



    Timers take the value in accumulator 1 as their preset when started.







    There are up counters and down counters, which count up and down respectively.



    Again, these take the value in accumulator 1 as the preset.







    46 Arithmetic Operations



    The only native arithmetic operations in the S5-100U series are addition and subtraction.



    These add or subtract the values in accumulator 1 and 2.



    Another set of add instructions allows adding a constant.



    However, the 103 and 95 CPUs offered integer multiple and divide as integrated function blocks, FB242 and FB243.



    You would call these function blocks with the desired parameters and they would return their results in other parameters.







    47 Comparison Operations



    There are a complete set of integer comparison operations which operate on the values in the two accumulators.



    These include greater than, greater than or equal to, etc.



    The boolean result is saved on the RLO.







    48 Block Call and Return



    There is a complete set of unconditional and conditional call operations to call all of the various types of blocks.



    There are also unconditional and conditional return operations.



    Calling a data block makes it the current data block, for load and transfer operations on data words







    49 NOP or No Op



    As implied these instructions have no result.







    50 Stop



    This stops the program executing







    51 Binary Word Operations



    These operate on words in the accumulators.



    These include AND, OR, XOR, Shift Left, and Shift Right.







    52 Bit Operations



    These test, set, or reset individual bits in data words or in timers and counters.







    53 Conversion Instructions



    There are instructions to perform one's complement or two's complement of the value in accumulator 1.







    54 Jump Operations



    There are unconditional and conditional operations to jump forward or back to a label.



    This is equivalent to a GOTO operation.











    55 Indirect Addressing or "DO" operations



    These instructions allow jumping to a block or selecting a data word or flag word according to a number stored in another address.



    Essentially, these instructions are like pointers.











    56 Miscellaneous



    There are also various other instructions that do things like copy blocks of words,



    or swap the contents of the accumulators,







    57 Other Instructions



    There are still more instructions which I have skipped over as it would take too much time to explain them.











    58 Instruction Summary



    As you can see the S5 PLC offers a very comprehensive set of operations which go well beyond what most people would think of as what a PLC does.



    This is a very powerful instruction set.







    59



    On the one hand this is a good thing, as you can do nearly anything.



    On the other hand, this is a bad thing, as some people take this as license to do nearly anything.



    In the hands of the wrong person, this results in a complex mass of spaghetti code that not even the person who wrote it can figure out later.







    60



    This goes against the philosophy of PLC programming, which is to make things as simple and obvious as possible.



    With a PLC program, perfection is achieved not when it has as many advanced features as possible, but rather when it is not possible to make it any simpler.







    61



    While Siemens gave the programmer a range of powerful low level instructions from which he could construct nearly anything, many other vendors took a different approach.



    They instead studied what was needed in major market segments and provided the programmer with instructions that operated at a higher level of abstraction, allowing programs to be written in less time and with fewer instructions.











    --------------------







    62 Execution Speed



    Execution speed of instructions varied depending on the PLC CPU model.



    Here are some typical values for the low end S5-100 series CPUs.







    63



    A boolean AND instruction executed in 70 microseconds on a S5-100U,



    or in 4 microseconds on an S5-102U,



    or in 1.6 microseconds on an S5-103U.







    64



    Adding two words in the accumulators executed in 55 microseconds on a S5-100U,



    or in 23 microseconds on an S5-102U,



    or in 1.6 microseconds on an S5-103U.







    65



    The S5-103U had a custom logic coprocessor chip, known as the M5.



    Instructions that were executed on the M5 coprocessor tended to take a uniform 1.6 microseconds.



    However, complex instructions that were not executed on the M5 coprocessor were often slower than on CPUs that didn't have a coprocessor, such as the 100 or 102.



    I suspect this is due to some sort of overhead relating to coordination of the two processors.







    66



    However, most instructions in a normal program are boolean logic, so very fast boolean execution time is what matters.







    Since every instruction is executed every scan cycle, large programs require faster instruction execution in order to keep up with demand.







    --------------------







    67 The S7 Series Replaces the S5







    In the mid 1990s, Siemens began introducing the S7 series which would ultimately replace the S5, although that took a number of years to happen.







    68



    The hardware was all new, but from a programmer's perspective, the S7 was an evolution of the S5.



    Some statement list instructions were dropped and others were added.



    Most of the basic concepts however remained the same.



    Porting an S5 program to an S7 was a complete re-write, but it was a fairly straightforward one.







    69



    The exception to this was the S7-200 series, which came into Siemens from the outside as part of their take over of of the PLC division of Texas Instruments.



    The S7-200 was an American knock off of a Japanese PLC and sold as a German product.



    It was none the less an excellent PLC and sold in very large numbers.



    The S7-200 was eventually replaced by something that was compatible with the rest of the S7 line







    70



    The S7 series has gone through a number of hardware revisions and remains Siemens' main PLC line today.







    It can via the S5 trace its lineage back to the 1970s and the early days of PLCs.







    --------------------







    71 Other Developments







    Japanese PLC Vendors



    I haven't covered any Japanese PLC vendors in the same way that I covered the PLC2 or S5.



    I had planned on doing another episode on one but I don't think it would really add much to what we have already discussed.



    However, PLCs from Japan are among the top sellers world wide and are generally very highly regarded.







    72 Pace of Innovation



    In terms of general history across the industry, in the early days of PLCs evolution was fairly rapid.



    Later on, innovation slowed down as compatibility with the existing install base became a bigger factor.



    Technology has become fairly static, but that isn't necessarily a bad thing from a business perspective.



    I will return to this subject later however.







    --------------------







    73 Conclusion







    In this episode we covered the Siemens S5 series of PLCs.



    We covered the history of the S5,



    it memory and addressing,



    the different types of subroutines,



    programming languages,



    the instructions,



    and how it was succeeded by the S7 series.







    74



    We saw how PLCs had rapidly evolved from their very early relay-replacement origins to become powerful programmable devices.







    In the next episode we will look at I/O modules and how they allow a PLC CPU to interface to hardware and control machines.







    75



    This has been the fourth episode in an 8 part series.







    --------------------





    Provide feedback on this episode.
  • Hacker Public Radio

    HPR4737: Keep spare parts for Ethernet run

    29/09/2026
    This show has been flagged as Clean by the host.



    Quick show on what I used to run 25 feet of Ethernet cable



    Amazon



    Cable Matters 10Gbps Snagless Cat 6 Ethernet



    Cable, 25ft, Blue 24 AWG Bare Copper, Gold-Plated



    RJ45, PoE++, 550MHz



    Other supplies



    • 1/2 inch length of blue pex tubing from local hardware store





    Leftover from previous project





    • Electrical tape



    • Extendable pole which has a clamp and a trigger mechanism for use with wasp spray



    • Hyper Tough 3/4 inch Hex Shank Spade Drill Bit



    • Random Hyper Tough (maybe 3/8 inch) drill bit All purpose



    • White silicone sealant



    Reference





    hpr4654 :: What's in my component Box?




    Images





    First part of cable run, internet router side.




    Ethernet cable, with electrical tape to pex pipe.




    Extension pole with pex pipe attached by electrical tape.




    Angle cut on pex pipe.




    Taped pex pipe with cable, ready to feed to other side.




    Extension to other side of the mobile home.




    Success! Fed through the other side.




    8 foot extension, suitable to hang an antenna.




    Silicone to seal the holes.




    Provide feedback on this episode.
  • Hacker Public Radio

    HPR4736: How to replace the battery in a car key fob

    28/09/2026
    This show has been flagged as Clean by the host.

    Replacing battery



    Remove the emergency key



    Pry open the fob around the seam with a blunt knife or similar



    Note the polarity of the battery, ie which way up the battery is.



    Replace the battery and close.

















    Emergency usage



    Use the emergency key to enter the car.



    Hold the key fob to the Start/Stop button



    Press the Start/Stop button







    Links











    https://en.wikipedia.org/wiki/Nissan_Micra#Fifth_generation_(K14;_2016)






    https://en.wikipedia.org/wiki/Button_cell






    https://en.wikipedia.org/wiki/Near-field_communication






    https://www.youtube.com/watch?v=IBP5EEm1oSI












    Provide feedback on this episode.
  • Hacker Public Radio

    HPR4735: hpr4715 :: friedcamp interviews part 5: Yvon Masyn

    25/09/2026
    This show has been flagged as Clean by the host.



    https://www.instructables.com/member/masynmachien/






    https://www.masynmachien.be/






    https://www.instagram.com/masynmachien/












    Provide feedback on this episode.
  • Hacker Public Radio

    HPR4734: HPR Beer Garden 20 - TuxJam Half-cut Special

    24/09/2026
    This show has been flagged as Clean by the host.

    The usual trio of
    Dave
    ,
    Kevie
    and
    Paul
    meet up for the first time in person and are joined by
    Al
    ,
    Andrew
    ,
    Joe
    and Rainy. The meet up was for the
    TuxJam Half-cut
    live event in Manchester. Rather than the usual style of show this is a (mostly) unedited recording of the beers that we are trying and general yarns around the table. We were interrupted by a yelling numpty, a middle-aged boy racer and a tram (these were edited out), but otherwise the recording is pretty much as is. The show was recorded outside the
    Sureshot Brewery Taproom
    .







    Connect with the guys on Untappd:







    Dave






    Paul






    Kevie










    The intro sounds for the show are used from:







    https://freesound.org/people/mixtus/sounds/329806/






    https://freesound.org/people/j1987/sounds/123003/






    https://freesound.org/people/greatsoundstube/sounds/628437/










    Upcoming beers:





    Mild



    Bitter



    Pale Ale



    Provide feedback on this episode.
More Education podcasts
About Hacker Public Radio
Hacker Public Radio is an podcast that releases shows every weekday Monday through Friday. Our shows are produced by the community (you) and can be on any topic that are of interest to hackers and hobbyists.
Podcast website

Listen to Hacker Public Radio, Begin Again with Davina McCall and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features