Lighting nodes and network facts
Node and network facts for the Mac lighting controller
Researched 2026-09-26 from manuals, standards and Apple documentation. No device was contacted and no packet was sent.
Labels used on every claim: - FACT means the cited document says it. - INFERENCE means it follows from cited facts but no document says it directly. - NOT DOCUMENTED means the manual or standard is silent and the device must be checked by hand. - Confidence is high, moderate, low or unknown.
Sources
| Key | Document | URL |
|---|---|---|
| NETRON-UG | Obsidian NETRON EN4 EP4 EN12 EN12-45 User Guide, doc v4.5, 2022-05-25 (covers firmware V2.4 and V2.6) | https://d295jznhem2tn9.cloudfront.net/ItemRelatedFiles/12368/NETRON%20EN4%20EP4%20EN12%20EN12-45%20-%20USER%20GUIDE%202022-05-25.pdf |
| NETRON-QS | NETRON EN4 EP4 EN12 quick start and safety guide | https://www.bhphotovideo.com/lit_files/840743.pdf |
| OBS-F1 | Obsidian forum, "EN4 sACN Priority Issue" (Obsidian staff reply) | https://forum.obsidiancontrol.com/t/en4-sacn-priority-issue/7263 |
| OBS-F2 | Obsidian forum, "Bug? HTP-merge when using sACN with different priorities" (EP4, firmware V2.4 img, V2.6 nfw) | https://forum.obsidiancontrol.com/t/bug-htp-merge-when-using-sacn-with-different-priorities/6759 |
| OBS-F3 | Obsidian forum, "Merging" | https://forum.obsidiancontrol.com/t/merging/7805 |
| OBS-F4 | Obsidian forum, "EN4 DMX Merge Documentation" | https://forum.obsidiancontrol.com/t/en4-dmx-merge-documentation/7264 |
| PK-11 | Pknight CR011R instruction manual (Manuals+ copy, published 2024-10-25, firmware V2.5 shown) | https://manuals.plus/pknight/cr011r-artnet-bi-directional-dmx-ethernet-lighting-controller-interface-manual |
| PK-11b | Pknight CR011R user manual, second Manuals+ copy (lists defaults) | https://manuals.plus/m/579e40c29aedbd267309fe8909484ec9745cd97b0a168553de7291d34d059519 |
| PK-21 | Pknight CR021R manual (sibling 2-universe model, same vendor defaults) | https://pknight.cc/myfiles/usermanual/CR021R_Manual_book.pdf |
| E131 | ANSI E1.31-2016 (full text, free from ESTA) | https://tsp.esta.org/tsp/documents/docs/E1-31-2016.pdf |
| E131-2018 | ANSI E1.31-2018 preview (table of contents only) | https://webstore.ansi.org/preview-pages/ESTA/preview_ANSI+E1.31-2018.pdf |
| SACN-RS | Rust sacn crate, cites Stream_Terminated as E1.31-2018 section 6.2.6 |
https://docs.rs/sacn/latest/sacn/packet/index.html |
| ETC-PAP | ETC, "Difference between sACN per-address and per-port priority" | https://support.etcconnect.com/ETC/Networking/General/Difference_between_sACN_per-address_and_per-port_priority |
| AN4 | Art-Net 4 specification, Protocol Release V1.4, Document Revision 1.4dp, 2025-10-23 (official URL is behind a captcha; the Wayback copy was read) | https://art-net.org.uk/downloads/art-net.pdf and https://web.archive.org/web/2025id_/https://art-net.org.uk/downloads/art-net.pdf |
| TN3179 | Apple TN3179 "Understanding local network privacy", revised 2026-02-17 | https://developer.apple.com/documentation/technotes/tn3179-understanding-local-network-privacy |
| DF-778457 | Apple forums, "Sequoia 'local network' permission failure from launch agent" | https://developer.apple.com/forums/thread/778457 |
| DF-760964 | Apple forums, "Unclear working of Local Network Privacy feature on macOS Sequoia" (DTS on Terminal and daemons) | https://developer.apple.com/forums/thread/760964 |
| DF-765285 | Apple forums, "POSIX sendto fails due to Sequoia's new LAN Privacy" | https://developer.apple.com/forums/thread/765285 |
| DF-774160 | Apple forums, "macOS 15.3 Local Network Permission regressions" | https://developer.apple.com/forums/thread/774160 |
| DF-782922 | Apple forums, "intermittent multicast socket failures, new to Sequoia" | https://developer.apple.com/forums/thread/782922 |
| DF-707183 | Apple forums, "169.254.255.255 doesn't broadcast?" (DTS: use IP_BOUND_IF) | https://developer.apple.com/forums/thread/707183 |
| QA1357 | Apple Technical Q&A QA1357, mixing link-local and routable addresses (archived, old) | https://developer.apple.com/library/archive/qa/qa1357/_index.html |
| XNU-IN | xnu bsd/netinet/in.h |
https://github.com/apple-oss-distributions/xnu/blob/main/bsd/netinet/in.h |
| XNU-OUT | xnu bsd/netinet/ip_output.c |
https://github.com/apple-oss-distributions/xnu/blob/main/bsd/netinet/ip_output.c |
| XNU-MC | xnu bsd/netinet/in_mcast.c |
https://github.com/apple-oss-distributions/xnu/blob/main/bsd/netinet/in_mcast.c |
| RFC3927 | IPv4 link-local addresses | https://www.rfc-editor.org/rfc/rfc3927 |
| NET-SON | .NET SocketOptionName enum | https://learn.microsoft.com/en-us/dotnet/api/system.net.sockets.socketoptionname?view=net-8.0 |
| NET-RAW | .NET Socket.SetRawSocketOption | https://learn.microsoft.com/en-us/dotnet/api/system.net.sockets.socket.setrawsocketoption?view=net-8.0 |
| NET-PAL | dotnet/runtime pal_networking.c, release/8.0 |
https://github.com/dotnet/runtime/blob/release/8.0/src/native/libs/System.Native/pal_networking.c |
| NET-24340 | dotnet/runtime #24340, MulticastInterface on macOS | https://github.com/dotnet/runtime/issues/24340 |
| NET-118654 | dotnet/runtime #118654, MulticastInterface test fails on macOS 26 beta | https://github.com/dotnet/runtime/issues/118654 |
| MA-REQ | grandMA3 onPC system requirements (manual 2.3) | https://help.malighting.com/grandMA3/2.3/HTML/onpc_system_requirements.html |
| MA-DMX | grandMA3 "Network and How to Output DMX" (manual 2.2) | https://help.malighting.com/grandMA3/2.2/HTML/qsg_output_dmx.html |
1. Obsidian NETRON EN4
1.1 Per-port settings. FACT, high (NETRON-UG, DMX PORTS menu, p. 19): each port has Mode (Disable, Input, Output), Universe 1 to 32767, Protocol (Art-Net, sACN, None), FrameRate 10 to 40, RDM enable, Merge (OFF, HTP, LTP, Toggle, Backup), Clone, Range and Offset. Merge option text: - OFF: "The merger is disabled." - HTP: "The sources are merged by Highest Takes Precedence." - LTP: "The sources are merged by Last Takes Precedence." - Toggle: "The complete source Universe is switched as soon as a single value changes." - Backup: "The merge universe is activated if the main universe has no valid traffic."
1.2 sACN priority is honoured. FACT, moderate (OBS-F1, Obsidian staff): "DMX Value 0 with Priority 100 wins over any DMX value and Priority 90", and "DMX 0 is not off, that is still a valid value." The user guide itself never mentions sACN priority. NOT DOCUMENTED in NETRON-UG.
1.3 Equal priority. FACT, moderate (OBS-F3): "HTP is the default merge of two sACN sources with the same priority." OBS-F4 says the port Merge setting ships OFF and is changed to HTP to merge two sACN streams. What the port does with two equal-priority sACN sources while Merge is OFF is NOT DOCUMENTED (unknown).
1.4 Known priority bug. FACT that it was reported, moderate (OBS-F2): an EP4 on firmware V2.4 img and V2.6 nfw, fed by sources at priorities 101 and 109, alternated between an HTP merge and the higher-priority source every one to two seconds. It happened when the lower-priority source was the only one present at node boot. No Obsidian fix is posted in that thread. INFERENCE, moderate: the EN4 shares that firmware family, so priority takeover and handback must be tested on this unit's firmware.
1.5 Loss of data. FACT, high (NETRON-UG, SYSTEM menu, p. 21 to 22): one device-wide Signal Loss setting. - Hold Last Look with a timer of Forever, 0 s, 10 s, 30 s, 1 m, 5 m, 10 m or 60 m. "The last incoming values continue to be sent on the ports until the time is expired." - After the timer, one of: Fade to 0 over 0 to 60 s ("(30s)" is shown, read as the default fade time), start Cue X, or Disable DMX ("DMX traffic is turned off on all ports"). - Startup has its own choice: run a Cue, or "Wait for Data" ("No DMX is sent until valid data is received"). - The factory default Signal Loss choice and timer are NOT DOCUMENTED. Factory reset "reload[s] NETRON Preset 1". - Whether Signal Loss fires per source, or only when every source on a port is gone, is NOT DOCUMENTED. INFERENCE, moderate: it is a port-level fallback that applies only when no valid source remains. - How the node treats an sACN Stream_Terminated packet is NOT DOCUMENTED.
1.6 Art-Net and sACN on one port. FACT, high (NETRON-UG p. 19): Protocol is chosen per port as Art-Net, sACN or None. INFERENCE, high: a port set to sACN does not use Art-Net data and the reverse, so the two protocols never merge on one port. No sentence in the guide states this outright.
1.7 IP address. FACT, high (NETRON-UG, IP ADDRESS menu, p. 20): - Factory setting is "a unique 2.x.x.x address", restored after every reset. The EP4 alone defaults to 2.0.0.1. - Modes: DHCP IP ("waits for a DHCP server address. After 30s it assigns itself a unique 169.254.x.x address but continues to monitor DHCP server requests"), Automatic 2.x, 10.x, 192.x and 172.x (all shown with mask 255.0.0.0), and Custom IP with any address and mask. "The device does not check the validity of address and subnet values." - FACT, high (NETRON-QS): "All settings are available from the integrated web page." Settings are also on the front display and encoder. - INFERENCE, high: the room node at 169.254.20.48 is in DHCP IP mode with no DHCP server on its wire. Plugged into the 192.168.1.0/24 LAN with a DHCP server, it would take a lease. A Custom IP such as 192.168.1.x/24 can be set from the web page or front panel. - INFERENCE, high: 169.254.20.48 sits on the PC's own Ethernet port, so the Mac cannot reach it unless the Mac joins that same wire through a switch.
1.8 ArtPoll and RDM. FACT, high (NETRON-UG, Presets table): RDM is "Yes" on every port in Art-Net presets and "not supported" in sACN presets. The guide never mentions ArtPoll or ArtPollReply. INFERENCE, moderate: as an Art-Net node it answers ArtPoll, because AN4 requires every node to reply. Per-address priority (0xDD) support is NOT DOCUMENTED.
2. Pknight CR011R
2.1 Protocols. FACT, high (PK-11): "bi-direction artnet controller CR011R which can convert the Artnet network data package into DMX512 data or DMX512 data into Artnet", "a powerful mini box with artnet 4". FACT, moderate (PK-11b, via search excerpt): "Support Art-Net I, II and III". sACN (E1.31) is never mentioned. INFERENCE, high: Art-Net only, no sACN.
2.2 Merge with two Art-Net sources. NOT DOCUMENTED in PK-11. INFERENCE, low: if it follows AN4, it HTP-merges two source IPs (HTP is the AN4 default), holds a vanished source for 10 s, and ignores a third source (see 4.3). Budget firmware may not merge at all.
2.3 Data loss behaviour. NOT DOCUMENTED (unknown). AN4 lets a node report hold, zero, full or scene failsafe (see 4.4), but PK-11 says nothing about it.
2.4 Default IP and configuration. - FACT, moderate (PK-11b, via search excerpt): default IP 10.201.6.100, mask 255.0.0.0, broadcast 10.255.255.255. - FACT, high (PK-21): the sibling CR021R ships with the same 10.201.6.100 / 255.0.0.0 defaults. - FACT, high (PK-11): set up "via the Oled display and four buttons, no need any application or browser". The menu covers Local IP, Subnet Mask (23 preset masks), Port Universe 0 to 15, SubNet 0 to 15, Net 0 to 127, Transmit mode ("Artnet -> dmx" or "Artnet <- dmx"), MAC, Version and Default Set. Hold Enter for 3 s to save. - FACT, high (PK-11): Table 1 recommends 2.x, 10.x or 192.168.x.x/24, so a 192.168.1.x/24 address is supported. - DHCP is NOT DOCUMENTED. INFERENCE, moderate: the CR011R is static only. - There is no web page. FACT, high: the manual says no browser is needed.
2.5 ArtPoll reply. NOT DOCUMENTED directly. FACT, high (PK-11): the startup text can be renamed through DMX-Workshop ("Name Your Buddy"). INFERENCE, moderate: DMX-Workshop finds nodes by ArtPoll and renames them by ArtAddress, so the unit answers ArtPoll and accepts ArtAddress.
3. ANSI E1.31 (sACN)
All FACT, high, from E131 (2016 text). SACN-RS places Stream_Terminated at section 6.2.6 of the 2018 edition. The 2018 full text was not read (E131-2018 is a preview only). Confidence that the 2018 wording matches: moderate.
3.1 Priority (6.2.3): "No priority outside the range of 0 to 200 shall be transmitted"; the field is "0-200, default of 100". "Sources that do not support variable priority shall transmit a priority of 100." A receiver "shall treat data from packets with the highest priority as the definitive data for that universe."
3.2 Equal priority (6.2.3.1 to 6.2.3.4): - Several sources at the highest active priority is normal. A single-source receiver hits a "sources exceeded condition". - HTP merge is described as "the single most common merging algorithm". For moving lights, "HTP is often highly inappropriate". - First-source-wins arbitration "is not recommended". - Merge ability and the maximum source count "shall be declared in user documentation for the device". NETRON-UG does not declare them (see 1.3).
3.3 Stream_Terminated (6.2.6 Options, bit 6): "Three packets containing this bit set to 1 shall be sent by sources upon terminating sourcing of a universe. Upon receipt of a packet containing this bit set to a value of 1, a receiver shall enter network data loss condition. Any property values in an E1.31 Data Packet containing this bit shall be ignored." The bit shows "that such termination is not a fault condition."
3.4 Network data loss (6.7.1 and Appendix A): data loss means no packets from a source for E131_NETWORK_DATA_LOSS_TIMEOUT = 2.5 seconds, or a Stream_Terminated packet. It is per source and per universe.
3.5 Output on loss (10.2.2): a gateway must offer a mode that stops DMX output immediately when every source of a universe is lost. It "may supplement this required mode with alternative operating modes", for example hold-last-look.
3.6 Keep-alive (6.6.2): a source that suppresses unchanged data sends three identical packets, then a keep-alive every 800 to 1000 ms.
3.7 Preview_Data (6.2.6, bit 7): data "intended for use in visualization or media server preview applications and shall not be used to generate live output."
3.8 Per-address priority (0xDD). FACT, high (E131 6.2.3.2): START code DDh gives slot-by-slot priority before an HTP merge. FACT, moderate (ETC-PAP): support is optional. A receiver without it ignores the whole 0xDD packet and uses the per-port priority. Priority 0 on an address means "ignore the level data for this address". NETRON support is NOT DOCUMENTED.
3.9 CID (5.6): "The CID shall be a UUID ... compliant with RFC 4122". "Each piece of equipment should maintain the same CID for its entire lifetime". Receivers tell sources apart by CID (6.2.3).
4. Art-Net 4
All FACT, high, from AN4 Rev 1.4dp.
4.1 ArtPoll (ArtPoll section): "The ArtPoll packet is used to discover the presence of other Controllers, Nodes and Media Servers." The receiver's only action is "Send ArtPollReply". Controllers broadcast ArtPoll every 2.5 to 3 s and may treat a node as gone after 3 s with no reply. Port 0x1936 (6454). Directed broadcast to 2.255.255.255 or 10.255.255.255. "Art-Net packets should not be broadcast to the Limited Broadcast address of 255.255.255.255." INFERENCE, high: ArtPoll cannot change DMX output. ArtPollReply is unicast only in Art-Net 4.
4.2 Packets that do change a node. ArtAddress commands include AcCancelMerge (0x01), AcFailHold, AcFailZero, AcFailFull, AcFailScene (0x08 to 0x0b), AcFailRecord (0x0c), AcMergeLtp0 to 3 (0x10 to 0x13), AcMergeHtp0 to 3 (0x50 to 0x53, "HTP (default)"), AcArtNetSel0 to 3 (0x60 to 0x63) and AcAcnSel0 to 3 (0x70 to 0x73). Failsafe, merge and direction settings "should be retained by the node during power cycling". ArtIpProg can program the IP address.
4.3 Merge (Data Merging): - A node detects a merge when ArtDmx for one Port-Address arrives from two IPs, and "should document the approach" it uses. - "Merge is implemented in either LTP or HTP mode as specified by the ArtAddress packet"; HTP is the default. - "If either (but not both) sources of ArtDmx stop, the failed source is held in the merge buffer for 10 seconds." If it does not return, the node leaves merge mode. - "If both sources of ArtDmx fail, the output holds the last merge result." - "Merging is limited to two sources, any additional sources will be ignored by the Node." - AcCancelMerge lets the next ArtDmx sender take sole control, and other IPs are discarded.
4.4 When the only controller stops. ArtPollReply Status3 bits 7 and 6 report the failsafe state: 00 hold last state, 01 all zero, 10 all full, 11 failsafe scene. Bit 5 says whether failsafe is programmable. AN4 gives no default and no timeout for failsafe. Art-Net has no stream-terminate packet. INFERENCE, high: a controller cannot hand an Art-Net node back cleanly; the node keeps doing whatever its failsafe or merge rules say.
5. macOS Local Network privacy
All FACT, high, from TN3179 unless marked.
5.1 Scope. It applies from macOS 15. A local network is "an IP network associated with a broadcast-capable network interface" (Wi-Fi, Ethernet; not cellular or VPN). "All multicast addresses (224.0.0.0/4 ...) and the IPv4 broadcast address (255.255.255.255) are local network addresses." The checks sit "deep in the networking stack" and cover BSD sockets and every API on top. - Needs access: sending UDP unicast, multicast or broadcast; connecting a UDP socket; outgoing TCP; receiving multicast or broadcast. - Does not need access: receiving unicast UDP; accepting incoming TCP. - Link-local 169.254/16 on Ethernet is a local network. TN3179 uses 169.254.0.0/16 as its own example.
5.2 Who is exempt on macOS. "Any daemon started by launchd", "Any program running as root", and "Command-line tools run from Terminal or over SSH, including any child processes they spawn". "The exception for launchd daemons doesn't apply to launchd agents."
5.3 Responsible code. A helper spawned by an app is charged to the app, which gets the alert and the System Settings entry. A LaunchAgent not installed with SMAppService should set AssociatedBundleIdentifiers in its plist. Identity comes from the code signature and the main executable's UUID. Ad hoc or unsigned code is tracked unreliably, so sign with an Apple-issued identity.
- FACT, moderate (DF-774160): one developer still got a prompt for the agent binary even with AssociatedBundleIdentifiers and a matching Team ID.
- FACT, moderate (DF-778457): a script worked from Terminal but failed with "no route to host" as a user LaunchAgent. Homebrew's ad hoc signed nc failed; Apple's nc worked.
5.4 Short-lived processes. "macOS fails to display the local network alert when a process with a very short lifespan performs a local network operation (FB16131937)." Denial can also happen "immediately, before the user has responded to the alert", so retry.
5.5 Admin override (macOS 15.5 and later). Set AllowedEthernetLocalNetworkAddresses and AllowedWiFiLocalNetworkAddresses (domain com.apple.network.local-network, CIDR strings) with sudo, then restart. Every program can then reach those networks whatever its privilege state. Example given: 169.254.0.0/16.
5.6 Failure mode.
- FACT, moderate (DF-765285, DF-778457, DF-782922): sendto fails with EHOSTUNREACH, errno 65, "No route to host". It can fail on the first call before the user answers.
- FACT, high (TN3179): there is no general API to test for access (FB8711182). NWConnection shows localNetworkDenied.
- FACT, high (TN3179): there is no way to reset a program's state to undetermined on macOS (FB14944392).
5.7 Loopback. INFERENCE, high: loopback is not a broadcast-capable interface, so 127.0.0.1 is not a local network address under the 5.1 definition. TN3179 has no sentence saying "loopback is exempt". INFERENCE, moderate: an unsandboxed app that talks only to 127.0.0.1 never triggers the prompt, unless a library it loads touches the LAN. TN3179 warns that third-party libraries are a common cause of unexpected alerts.
5.8 macOS 26. TN3179 was revised 2026-02-17 and names no macOS 26 change. FACT, moderate (NET-118654): a .NET MulticastInterface test began failing with EINVAL on a macOS 26 beta. Whether that holds on 26.3 is unknown.
Conclusion for a launchd-started server (INFERENCE, high). A LaunchDaemon (system domain, root) is exempt and needs no prompt. A LaunchAgent in the user's session is not exempt. It needs one of these:
- a stable Apple-signed identity, ideally inside an app bundle, plus AssociatedBundleIdentifiers, and one user approval;
- or the 5.5 admin defaults covering the lighting subnets.
Tests run from Terminal or SSH pass even when the agent will fail, so they prove nothing about the agent.
6. macOS routing with two interfaces
6.1 Link-local unicast. - FACT, high (XNU-OUT source comment): "IPv4 LLAs are never scoped in the current implementation." - FACT, low (QA1357, archived and old): link-local was "only active on the primary interface". - FACT, moderate (DF-707183, Apple DTS): with several interfaces up, specify the interface, "especially for the link-local address because multiple interfaces can be running link-local address simultaneously". - INFERENCE, moderate: an unbound socket sends to 169.254.x.x through the single unscoped 169.254 route, normally the highest-ranked service in Set Service Order. That may be the wrong port. Binding fixes it.
6.2 Multicast 239.255.x.x. FACT, high (XNU-OUT): when the socket has a multicast interface set (imo_multicast_ifp), that interface is used. Otherwise the route lookup chooses. INFERENCE, high: with no IP_MULTICAST_IF, sACN multicast leaves on the default-route interface, usually Wi-Fi. FACT, moderate (DF-782922): intermittent multicast send and receive failures with errno 65 were reported on Sequoia.
6.3 Limited broadcast 255.255.255.255. FACT, high (XNU-OUT): the kernel clones a host route with the RTF_BROADCAST flag. INFERENCE, moderate: unbound, it goes out the primary interface only. FACT, moderate (DF-707183): 169.254.255.255 directed broadcast did not work as expected, and DTS advised IP_BOUND_IF.
6.4 Forcing the interface.
- FACT, high (XNU-IN): IP_BOUND_IF = 25 (int, interface index, level IPPROTO_IP). It scopes all of the socket's output to that interface. IP_MULTICAST_IF = 9. IP_MULTICAST_IFINDEX = 66.
- FACT, high (XNU-MC): IP_MULTICAST_IF accepts a 4-byte in_addr (the interface's IPv4 address) or a 12-byte ip_mreqn with an index. An in_addr in 0.0.0.0/8 is read as an interface index (RFC 1724). Binding the socket to a local IPv4 address sets the source, and xnu then scopes the route to that address's interface (XNU-OUT source selection path; INFERENCE, moderate for LLAs).
6.5 What .NET 8 exposes.
- FACT, high (NET-SON): SocketOptionName.MulticastInterface = 9, plus Broadcast, MulticastLoopback, MulticastTimeToLive and ReuseAddress. There is no member for IP_BOUND_IF.
- FACT, high (NET-RAW): Socket.SetRawSocketOption(level, name, bytes) exists from .NET 5 for options with no enum member. So IP_BOUND_IF is SetRawSocketOption(0, 25, BitConverter.GetBytes(ifIndex)).
- FACT, high (NET-PAL): on macOS, MulticastInterface maps straight to IP_MULTICAST_IF with the caller's 4 bytes. Passing the interface IPv4 address bytes works. Passing IPAddress.HostToNetworkOrder(index) also works because of the 0.0.0.0/8 rule in 6.4.
- Socket.Bind(new IPEndPoint(localAddr, 0)) gives the bind-to-address route.
6.6 Known .NET pitfalls on macOS.
- NET-24340 (open since 2017): MulticastInterface set to the loopback index fails on macOS.
- NET-118654: MulticastInterface set to "any" throws EINVAL on macOS 26 beta 6.
- Local Network denial surfaces as SocketException HostUnreachable (errno 65), which reads like a routing fault.
7. grandMA3 onPC on Apple silicon
FACT, high (MA-REQ): grandMA3 onPC runs on macOS 12 Monterey or later and lists Apple M1 or later in its requirements. Catalina and Big Sur stop at 2.1.1.5; High Sierra and Mojave stop at 1.8.8.2. FACT, high (MA-DMX): "We are not permitted to output anything from the grandMA3 onPC software unless we have some grandMA3 hardware that unlocks parameters", including over Art-Net and sACN. An onPC system is capped at 4,096 parameters. The current release number was not confirmed (unknown). INFERENCE, high: onPC on this Mac cannot drive the room without an MA onPC node or wing.
What this means for the Mac controller
- Stay silent by default. Never send sACN or Art-Net until a person explicitly takes control. Any Mac sACN above priority 100 wins the whole universe, zeros included (1.2, 3.1).
- Take control at priority 150 on sACN, not 100. At 100 the result depends on the port's Merge setting, which is HTP or undefined (1.3, 3.2). HTP lets the Mac raise levels but never lower them, and it scrambles moving-light parameters. 150 leaves room below the 200 cap (3.1).
- Keep streaming while in control. Send full frames at 30 to 40 fps, never slower than one frame per second. A gap of 2.5 s drops the Mac, and the PC's look reappears (3.4, 3.6).
- RELEASE sends three Stream_Terminated packets per universe, then stops. Nothing is sent after that (3.3). The NETRON should then fall back to the PC's priority 100 stream at once. If the packets are lost, the Mac's last look stays for up to 2.5 s (3.4).
- Handback on the NETRON is not proven. Its handling of Stream_Terminated and per-source loss is undocumented, and a priority flip-flop bug was reported on V2.4 and V2.6 firmware (1.4, 1.5). Test the handback by hand, as in rule 12, before relying on it.
- Use one persistent CID per install. Generate the UUID once, store it, and reuse it. A new CID per launch looks like a new source and can briefly double-count under merge (3.9).
- Never send ArtAddress, ArtIpProg or any Art-Net configuration packet. They can change merge mode, failsafe, protocol selection and IP, and the node keeps those changes across power cycles (4.2). ArtPoll is safe for discovery (4.1).
- Art-Net nodes cannot be released cleanly (4.3, 4.4). - A second Art-Net source HTP-merges with the Mac. - When the Mac stops, its levels stay in the merge for 10 s. - If the Mac was the only source, the node keeps its failsafe state, which is probably hold-last-look forever on the CR011R (2.3, unknown). - RELEASE on Art-Net must first send the agreed house look, then stop.
- Bind every socket to an interface. - Pick the interface whose subnet contains the node. - Set IP_BOUND_IF (level 0, option 25) through SetRawSocketOption and bind to that interface's address. - For sACN multicast, also set MulticastInterface to that interface's IPv4 address. - Never rely on the default route for 169.254/16 or 239.255/16 (6.1 to 6.5). - Use directed broadcast, such as 192.168.1.255 or 2.255.255.255, for ArtPoll, never 255.255.255.255 (4.1, 6.3).
- Run the transmitter where Local Network privacy cannot silently block it.
- Option one is a root LaunchDaemon.
- Option two is a signed app-bundle LaunchAgent with
AssociatedBundleIdentifiersand a one-time approval. - Option three is the admin defaults listing 192.168.1.0/24 and 169.254.0.0/16, on macOS 15.5 or later.
- Treat errno 65 at
sendtoas "permission" first, "route" second. - A UI that only talks to the server on 127.0.0.1 needs no permission (5.2 to 5.7).
- Reach the NETRON on purpose.
- Today the node sits at 169.254.20.48 on the PC's private wire (1.7).
- The Mac must join that wire through a switch, or the node must move to a 192.168.1.x address from its web page.
- Moving it changes how the PC reaches it, so agree on that with whoever runs the room PC first.
-
Check these by hand on the NETRON web page before the first live use (1.1, 1.5, 1.8):
- firmware version;
- the port's Protocol (sACN) and Universe;
- the port's Merge mode (OFF, HTP, LTP, Toggle or Backup);
- the Signal Loss action and timer;
- the Startup action;
- the IP mode.
Then run three live tests with the PC streaming: - The Mac at priority 150 takes over. - Three Stream_Terminated packets hand control back within one second. - Pulling the Mac's cable hands back after about 2.5 s.
Record each result in DECISIONS.md. 13. Check these by hand on the CR011R front panel: IP, mask, Net, SubNet, Universe and Transmit mode "Artnet -> dmx". Also watch what the output does 10 s and 60 s after the Mac stops sending (2.2, 2.3).