Industrial protocols

32-bit floats in Modbus: ABCD, CDAB, BADC and DCBA byte orders

Why a perfectly valid register pair turns into nonsense, how IEEE 754 single precision is split across two registers and how to find the right byte and word order.

One number, four bytes

A 32-bit IEEE 754 single-precision number has one sign bit, an 8-bit exponent and a 23-bit fraction. Written as four bytes from most to least significant, the value 123.456 is 42 F6 E9 79. Call those bytes A, B, C and D.

A Modbus register holds only 16 bits, so the number is split across two registers. Modbus fixes the order of the two bytes inside a register (high byte first on the wire), but it does not say which of the two registers carries the high half of a 32-bit value. Each vendor decides, and that is where the trouble starts.

The four common layouts

LayoutCommon nameFirst registerSecond register
ABCDBig-endian0x42F60xE979
CDABWord-swapped (little-endian word order)0xE9790x42F6
BADCByte-swapped within each word0xF6420x79E9
DCBALittle-endian0x79E90xF642

The names are conventions, and different manufacturers use different words for the same layout. Always describe a device by the actual register contents, as in the table, instead of relying on a label.

What the wrong order looks like

If the device sends 123.456 as CDAB (E979 42F6) but your software decodes ABCD, the result is not slightly off. It is absurd:

Device sendsRegisters on the wireDecoded as ABCD
ABCD42F6 E979123.456
CDABE979 42F6−1.88 × 10²⁵
BADCF642 79E9−9.86 × 10³²
DCBA79E9 F6421.52 × 10³⁵

Values of astronomical magnitude, or values that are plausible only because the true value happens to be small, are a strong hint that the byte or word order is wrong. Be careful with the second case: a wrong order can still produce a believable number for some inputs, so one successful reading is not proof.

How to find the right order

  1. Read a value you know. Use a setpoint you wrote yourself, or a quantity with an obvious value such as the ambient temperature.
  2. Decode all four layouts. Paste the two register values into the PLC data type converter and compare the four results. Only one will be sensible.
  3. Confirm with a second value. Choose one with a different magnitude, and a negative one if the process allows it, because a wrong layout can coincide with the right one for special values.
  4. Record it. Write the layout into the register map for that device and block, next to the address, the data type and the scaling.

Some devices expose a configuration setting for word order. If yours does, change it deliberately and document the setting, because a firmware reset can bring back the default.

The same issue applies beyond floats

  • INT32 and UINT32 have the same four layouts and fail the same way: a counter that jumps by 65,536 when it should step by 1 is usually a word-order problem.
  • 64-bit values (doubles, large counters) span four registers and allow even more permutations. Treat them with the same discipline.
  • Strings pack two characters per register; the character order inside a register can also differ between devices.

Scale integers instead of guessing floats

Many field devices avoid the problem by exposing a 16-bit integer with a documented scale, for example a temperature of 2345 meaning 23.45 °C. That halves the number of ways to go wrong. When you have the choice, prefer the integer plus scale, and apply the scale once, at the edge, with the factor written in the register map. The industrial data converter applies scaling to register data and exports the result as CSV or JSON.

Where to go next

Start with the basics of Modbus addressing and function codes, then use the register map validation checklist to make byte order, signedness and scaling part of every commissioning.

THE NEXT STEP

From calculation to implementation.

Let’s look at your machine, your data flow or your production goal together. Describe your situation in a few sentences and the ASP Dijital team will reply by email.

Talk to ASP Dijital