GM 16216588 - Hacking

American Delco GM ECUs and PCMs, ALDL, OBD 1.5.
ronniejoe
Posts: 1
Joined: Mon Feb 01, 2016 5:06 am
cars: 1967 Chevrolet Camaro SS/RS
1967 Chevrolet C10
1995 Chevrolet Suburban LS K2500
1995 Chevrolet K1500
1999 Chevrolet Tahoe
1995 GMC Suburban K1500
1974 AMC Jeep CJ5
2000 Chevrolet K3500 DRW Crew Cab Long Bed

Re: GM 16216588 - Hacking

Post by ronniejoe »

Hi, This has been a great read, but since it has been a long time with no posts, I'm guessing something didn't work out? Would really be nice to know what you found out.

Thanks.
SickFinga
Posts: 16
Joined: Mon Aug 05, 2024 6:31 am

Re: GM 16216588 - Hacking

Post by SickFinga »

Does anyone know if this has a recovery boot pin? Bricked one with a Tech 2 reflash. Trying to see if it can be recovered
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: GM 16216588 - Hacking

Post by antus »

There is no such thing as a recovery boot bin. When we do that we are grounding an address pin to corrupt the communication between the chip and the processor so it looks like the contents of the chip is corrupted which triggers the built in recovery mode. What this means is that it opens the door when the chip is in a good state. If the PCM is corrupted it should just enter recovery mode on its own. So if you are not seeing that, it is unlikely to work. You can try grounding some flash chip address pins momentarily to see what happens, probably try between A7 and A13 or so. But be careful grounding things can easily blow things up if you bridge pins or ground the wrong thing. Also because this PCM has flash pins scrambled, you might need to try all the address pins to see if you can find one that has the right effect. Chances are that it is too old and that functionality was not developed, though.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
SickFinga
Posts: 16
Joined: Mon Aug 05, 2024 6:31 am

Re: GM 16216588 - Hacking

Post by SickFinga »

antus wrote: Mon Dec 08, 2025 11:51 pm There is no such thing as a recovery boot bin. When we do that we are grounding an address pin to corrupt the communication between the chip and the processor so it looks like the contents of the chip is corrupted which triggers the built in recovery mode. What this means is that it opens the door when the chip is in a good state. If the PCM is corrupted it should just enter recovery mode on its own. So if you are not seeing that, it is unlikely to work. You can try grounding some flash chip address pins momentarily to see what happens, probably try between A7 and A13 or so. But be careful grounding things can easily blow things up if you bridge pins or ground the wrong thing. Also because this PCM has flash pins scrambled, you might need to try all the address pins to see if you can find one that has the right effect. Chances are that it is too old and that functionality was not developed, though.
Ah, I understand now. I tried all of the A-pins with no success. It seems my only option is to clone the flash from a working PCM. However, based on what I’ve read in this thread, reading and writing the AN28F010 is a complicated process and very few programmers support this flash.
SickFinga
Posts: 16
Joined: Mon Aug 05, 2024 6:31 am

Re: GM 16216588 - Hacking

Post by SickFinga »

I read the 28F010 flash. The bricked one was just filled with FD FF. I copied data off the known good flash, wrote it, soldered the flash in and it still doesn't want to work. Does this mean the processor got corrupted as well?
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: GM 16216588 - Hacking

Post by antus »

My guess is it'd be an electrical problem. Unlikely to be a processor problem unless you know it got exposed to too much voltage somewhere. Does the flash look corrupted? I'd expect it to, there is a tool back on page 6 here that can scramble / descramble. Might be worth doing to see if you can make your bin look sensible. Note that the flash read might also be byte swapped so you might need an additional swapab first.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
SickFinga
Posts: 16
Joined: Mon Aug 05, 2024 6:31 am

Re: GM 16216588 - Hacking

Post by SickFinga »

antus wrote: Mon Dec 15, 2025 12:28 am My guess is it'd be an electrical problem. Unlikely to be a processor problem unless you know it got exposed to too much voltage somewhere. Does the flash look corrupted? I'd expect it to, there is a tool back on page 6 here that can scramble / descramble. Might be worth doing to see if you can make your bin look sensible. Note that the flash read might also be byte swapped so you might need an additional swapab first.
Well, I think the issue was with my original soldering job. I copied the data from the original flash into the corrupted flash chip. Soldered the corrupted flash chip into the known good PCM and it worked. I soldered the flash chip from a known good PCM into the PCM that got corrupted and it also works now.

I actually did use your code to check the flash read and the end result looked fine. I had your code converted to PHP using ChatGPT. Can you run your code to see if the unscrambled result is the same?

Also, I looked through the bin and couldn't find the VIN. To my surprise, PCMs retained their original VINs. Where is the VIN stored on this PCM?


Code: Select all

<?php
// Address line descrambler by antus/pcmhacking.net
// PHP port of the original C code

define('BIN_SIZE', 128 * 1024);

// --- helper functions ---

function getbit(int $data, int $bit): int {
    return ($data & (1 << $bit)) ? 1 : 0;
}

function setbit(int $data, int $bit): int {
    return $data | (1 << $bit);
}

// --- load bin ---

$inputFile  = '16216588.bin';
$outputFile = '16216588-fixed.bin';

$bin = file_get_contents($inputFile);
if ($bin === false || strlen($bin) !== BIN_SIZE) {
    fwrite(STDERR, "Couldn't open bin or invalid size\n");
    exit(1);
}

// convert string to byte array
$binBytes = array_values(unpack('C*', $bin));
$target   = array_fill(0, BIN_SIZE, 0);

// --- address line map ---
$map = range(0, 16);

// A1-A13, A2-A12, A3-A11, A10-A14 swapped
$map[1]  = 13;
$map[2]  = 12;
$map[3]  = 11;
$map[10] = 14;

$map[11] = 3;
$map[12] = 2;
$map[13] = 1;
$map[14] = 10;

// --- descramble ---
for ($i = 0; $i < 0x20000; $i++) {
    $t = 0;

    // set each bit from the mapped source bit
    for ($g = 0; $g < 17; $g++) {
        if (getbit($i, $g)) {
            $t = setbit($t, $map[$g]);
        }
    }

    $target[$i] = $binBytes[$t];
}

// --- save output bin ---
$out = '';
foreach ($target as $byte) {
    $out .= chr($byte);
}

if (file_put_contents($outputFile, $out) === false) {
    fwrite(STDERR, "Couldn't write output bin\n");
    exit(1);
}

echo "Done.\n";


You do not have the required permissions to view the files attached to this post.
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: GM 16216588 - Hacking

Post by antus »

Yep the bin matches the output from my code. I also updated the code back on page 1 to fix an insignificant error compiling the code with a more modern c compiler (define main as returning an int).
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
SickFinga
Posts: 16
Joined: Mon Aug 05, 2024 6:31 am

Re: GM 16216588 - Hacking

Post by SickFinga »

SQ is the SQUAD wrote: Thu Feb 20, 2020 12:03 am how did the 2x20 connector end up working out?
Not the OP, but I tried the same stand offs for the in-circuit reading.

Pins 1, 2, 22 and 24 do not go to any of those pads.
Pins 1 and 24 have pads right next to the flash chip. Pins 2 and 22 are on the other side of the PCB.

The bad news is no matter what I tried, I can't read this flash in circuit. I tried powering the PCM from the connectors with Vcc connected and disconnected. Unfortunately, I got nothing.