Skip to content

Send EZSP v14+ multicasts and broadcasts without a NWK alias - #757

Open
zigpy-review-bot wants to merge 1 commit into
devfrom
zigpy-bot/v14-null-alias
Open

zigpy-review-bot wants to merge 1 commit into
devfrom
zigpy-bot/v14-null-alias

Conversation

@zigpy-review-bot

@zigpy-review-bot zigpy-review-bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Collaborator

The problem

EZSP v14+ sendMulticast and sendBroadcast were called with alias=0x0000 and sequence= the caller's APS TSN. The stack treats only SL_ZIGBEE_NULL_NODE_ID (0xFFFF) as "not an aliased source": for any other value — including the coordinator's own 0x0000 — it overwrites the NWK source and NWK sequence number of the outgoing frame with the supplied ones.

zigpy's TSNs are not a single counter: Group._send_sequence is per group, and the ZDO/application counters are separate again, all starting at zero. So unrelated frames left the coordinator carrying the same (NWK source, NWK sequence) pair, and routers dropped them as broadcast-transaction-table duplicates for the lifetime of the entry (9 s per the Zigbee PRO stack profile, 20 s on EmberZNet routers). The visible effect is group commands silently doing nothing — see #756 for a full reproduction, and the reporter's confirmation that patching the alias at runtime fixes it on a real network.

The fix

This passes alias=0xFFFF and sequence=0 (ignored without an alias source) for both calls, which lets the stack assign the NWK sequence number itself, as it does on EZSP v13 and older. bellows/zigbee/application.py discards the sequence these two calls return, so nothing depends on the old behaviour.

The stack takes that number from the single per-network NWK counter it also uses for the broadcasts it originates on its own (route requests, link status), so it cannot collide with those — whereas any host-chosen number sent under NWK source 0x0000 can, however it is counted. (From static analysis of the prebuilt EmberZNet 9.0.2 stack library; details in #756.)

Affected versions

Only v14+ is affected: the pre-v14 sendMulticast/sendBroadcast frames have no alias/nwkSequence fields at all (the Gecko SDK exposes aliasing through separate emberSendMulticastWithAlias/emberProxyBroadcast calls instead). The constant value is stable across both SDK generations — EMBER_NULL_NODE_ID is 0xFFFFu in the Gecko SDK and SL_ZIGBEE_NULL_NODE_ID is 0xFFFFu in the Simplicity SDK.

Fixes #756

`sendMulticast` and `sendBroadcast` were called with `alias=0x0000`. The
stack only treats `SL_ZIGBEE_NULL_NODE_ID` (0xFFFF) as "not aliased": any
other value makes it overwrite the NWK sequence number of the outgoing frame
with the provided one, which was zigpy's TSN. Those counters are kept per
group, per device and per application and all start at zero, so unrelated
frames left the coordinator with the same NWK source and sequence number and
were dropped by routers as broadcast duplicates.

Related: #756
@codecov

codecov Bot commented Sep 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.55%. Comparing base (15ccb49) to head (b8f7d39).

Additional details and impacted files
@@           Coverage Diff           @@
##              dev     #757   +/-   ##
=======================================
  Coverage   99.55%   99.55%           
=======================================
  Files          64       64           
  Lines        4284     4285    +1     
=======================================
+ Hits         4265     4266    +1     
  Misses         19       19           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

EZSP v14+: send_multicast passes alias=0x0000, so group commands are dropped as NWK duplicates

1 participant