PCM Hammer P12 development
-
Gampy
- Posts: 2332
- Joined: Fri Dec 14, 2018 9:38 pm
Re: PCM Hammer P12 development
Tech2 did the first one, I did the second one ...
Intelligence is in the details!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
-
darkman5001
- Posts: 275
- Joined: Fri Dec 17, 2021 10:15 pm
- cars: 2005 Yukon, 2004 Suburban, 2001 Tahoe, 2002 Envoy, 2006 Envoy, 2003 Lincoln LS
- Location: New Jersey, USA
Re: PCM Hammer P12 development
The first P12 was taken down by a corrupt flash from the tech2 which the tech2 received the flash from TIS2000 running on a virtual machine. Something must have went wrong with the virtual machine. I used that 1st P12 to dismantle for inspection and research into it's circuity and chips. Second P12 happened during some testing. I installed TIS2000 to a Toughbook, and was able to recover this second P12 with the Tech2.Cincinnatus wrote:When and what took down the PCM? Also wondering is there an older version of tech2win that will use the pcmcia card files for flashing?
The PCMCIA card bins are available to flash to the cards for the Tech2 but can also be used with tech2win, however it is my understanding that programming can not be done with tech2win, only a physical tech2.
-
Gampy
- Posts: 2332
- Joined: Fri Dec 14, 2018 9:38 pm
Re: PCM Hammer P12 development
Is this a fair statement ...
With the P01/P59, it's upload a kernel, it takes completely over, obeys commands sent to it and responds accordingly ... When done the unit is Rebooted!
As we know so far with the P12, it's upload the tools and instructions how to handle the accompanying data, then leaves it to it's own devices!
Meaning it does the update, all we do is provide the tools, instructions and data to do so.
With the P01/P59, it's upload a kernel, it takes completely over, obeys commands sent to it and responds accordingly ... When done the unit is Rebooted!
As we know so far with the P12, it's upload the tools and instructions how to handle the accompanying data, then leaves it to it's own devices!
Meaning it does the update, all we do is provide the tools, instructions and data to do so.
Intelligence is in the details!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
-
kur4o
- Posts: 1146
- Joined: Sun Apr 10, 2016 11:20 am
Re: PCM Hammer P12 development
If we are talking for factory reflash, that is correct.Gampy wrote:Is this a fair statement ...
With the P01/P59, it's upload a kernel, it takes completely over, obeys commands sent to it and responds accordingly ... When done the unit is Rebooted!
As we know so far with the P12, it's upload the tools and instructions how to handle the accompanying data, then leaves it to it's own devices!
Meaning it does the update, all we do is provide the tools, instructions and data to do so.
If we use custom made tools for flashing, it doesn`t matter.
With gm flash the boot block 0-4000 stay constant and never updates during flash. It may be good but maybe not that good. In case you update a OS that have different application 2.4l vs later 4.2, hardware is the same, boot block differs. No way to update OS without boot block. Maybe we can start making library of p12 stock files.
-
darkman5001
- Posts: 275
- Joined: Fri Dec 17, 2021 10:15 pm
- cars: 2005 Yukon, 2004 Suburban, 2001 Tahoe, 2002 Envoy, 2006 Envoy, 2003 Lincoln LS
- Location: New Jersey, USA
Re: PCM Hammer P12 development
I can say this, after I am on the computer in SPS, depending on what update the stand-alone PC software is at, there are a bunch of calibrations updates since previous updates, or I have the option to update these. In my experience with the software, I can also update the operating system as well. I know that different operating system versions can be used on a particular PCM. Actually I can reprogram any programmable module in the whole vehicle with this software. I can even reprogram a factory radio to work in Europe. These calibration options are available for each module as well as each module having its own operating system. Example: The P10 I am working on right now had 3 operating systems. There was 12577956 with a description "Operating System". Then the second is 12579357 with a description "New software to improve generic scan tool operation." Then the last and most current version is 12588012 with the description "New software to improve idle stability."
-
antus
- Site Admin
- Posts: 10016
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: PCM Hammer P12 development
@kur4o you are right. This is different from the P01 an P59 in how the factory do it. I guess they had their reasons but it seems more complicated and more error prone compared to how the earlier PCMs do it. I dont see any reason why we should try and emulate the P12 factory method. It'll be simpler and more reliable for us to port the P01/P59 code to the P12. Perhaps we need to add something to silence the slave cpu, but we dont need to make something overly complex like the factory tools.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
Tazzi
- Posts: 3626
- Joined: Thu May 17, 2012 10:53 am
- cars: VE SS Ute
- Location: WA
Re: PCM Hammer P12 development
Ok, do we know if the kernel is crashing when it’s trying to write? Or just comes back saying failed?
If the p12 kernel is able to go in an infinite loop without crashing… and it was also able to erase a section.. I would not think the slave Cpu is a problem with it all.
The fact it erased.. shows the correct commands and addressing was performed.
If the slave was interfering then I would expect it would get part way through writing before crashing or failing, but it hasn’t even attempted to write a single byte successfully.
Does there need to be a pause after unlocking, before writing?
If the p12 kernel is able to go in an infinite loop without crashing… and it was also able to erase a section.. I would not think the slave Cpu is a problem with it all.
The fact it erased.. shows the correct commands and addressing was performed.
If the slave was interfering then I would expect it would get part way through writing before crashing or failing, but it hasn’t even attempted to write a single byte successfully.
Does there need to be a pause after unlocking, before writing?
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726

Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726

-
Gampy
- Posts: 2332
- Joined: Fri Dec 14, 2018 9:38 pm
Re: PCM Hammer P12 development
Yes kur4o, I was talking about factory technique ...
I personally have never even thought about trying to emulate the factory technique ... I have from the very first success, been on the same road as the P01/P59 technique!
I believe it is the way to go ... Take control, do it yourself!
And I believe it can be done this way.
Why would they allow erase, but not write ... they wouldn't. I think we still have a bit flipped wrong!
The big question is: What bit!
I do keep having reads done purposely to ensure it's cleanly erased and not a partial write.
It's always clean ...
The PC sends Erase, when the PC receives Success, it then sends the Write, so there is a bit of a delay just in the technique.
The kernel code writes a word, then tries to read that word back and compare it to what was written, that is where it fails ...
The kernel is NOT crashing ... It is still alive after the failed write!
BTW, knowing we can recover is a HUGE relief to me ... So darkman5001 Thank you very much for getting that working!
I personally have never even thought about trying to emulate the factory technique ... I have from the very first success, been on the same road as the P01/P59 technique!
I believe it is the way to go ... Take control, do it yourself!
And I believe it can be done this way.
Sounds like an echo, I have been screaming the same thing!Tazzi wrote:If the p12 kernel is able to go in an infinite loop without crashing… and it was also able to erase a section.. I would not think the slave Cpu is a problem with it all.
Why would they allow erase, but not write ... they wouldn't. I think we still have a bit flipped wrong!
The big question is: What bit!
I completely agree!Tazzi wrote:If the slave was interfering then I would expect it would get part way through writing before crashing or failing, but it hasn’t even attempted to write a single byte successfully.
I do keep having reads done purposely to ensure it's cleanly erased and not a partial write.
It's always clean ...
By the nature of the design there is a fair delay between the two already, I could add more just to verify very easily.Tazzi wrote:Does there need to be a pause after unlocking, before writing?
The PC sends Erase, when the PC receives Success, it then sends the Write, so there is a bit of a delay just in the technique.
The kernel code writes a word, then tries to read that word back and compare it to what was written, that is where it fails ...
Code: Select all
uint8_t Amd_WriteToFlash(unsigned int payloadLengthInBytes, unsigned int startAddress, unsigned char *payloadBytes, int testWrite)
{
char errorCode = 0;
unsigned short status;
unsigned short* payloadArray = (unsigned short*) payloadBytes;
unsigned short* flashArray = (unsigned short*) startAddress;
for (unsigned index = 0; index < payloadLengthInBytes / 2; index++)
{
unsigned short volatile *address = &(flashArray[index]);
unsigned short value = payloadArray[index];
if (!testWrite)
{
+#if defined P12
+ SIM_CSOR0 |= 0x4;
+#else
SIM_CSOR0 = 0x7060;
+#endif
COMMAND_REG_AAA = 0xAAAA;
COMMAND_REG_554 = 0x5555;
COMMAND_REG_AAA = 0xA0A0;
*address = value; // <-------------------------------------- Writes the word
}
char success = 0;
for(int iterations = 0; iterations < 0x1000; iterations++)
{
ScratchWatchdog();
uint16_t read = testWrite ? value : *address; // <------------ Reads the written word
if (read == value) // <--------------------------------------- Compares the two words
{
success = 1;
break;
}
}
if (!success)
{
// Return flash to normal mode and return the error code.
errorCode = 0xAA; // <--------------------------------------- Returned ERROR CODE!
if (!testWrite)
{
*address = 0xF0F0;
*address = 0xF0F0;
+#if defined P12
+ SIM_CSOR0 = 0xA332;
+#else
SIM_CSOR0 = 0x1060;
+#endif
}
return errorCode;
}
}
if (!testWrite)
{
// Return flash to normal mode.
unsigned short* address = (unsigned short*)startAddress;
*address = 0xF0F0;
*address = 0xF0F0;
+#if defined P12
+ SIM_CSOR0 = 0xA332;
+#else
SIM_CSOR0 = 0x1060;
+#endif
}
return 0;
}
BTW, knowing we can recover is a HUGE relief to me ... So darkman5001 Thank you very much for getting that working!
Intelligence is in the details!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
-
Tazzi
- Posts: 3626
- Joined: Thu May 17, 2012 10:53 am
- cars: VE SS Ute
- Location: WA
Re: PCM Hammer P12 development
Where it does this:
SIM_CSOR0 |= 0x4;
If this is related to control those pins, there will need to be a delay for it to take effect.
SIM_CSOR0 |= 0x4;
If this is related to control those pins, there will need to be a delay for it to take effect.
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726

Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726

-
Gampy
- Posts: 2332
- Joined: Fri Dec 14, 2018 9:38 pm
Re: PCM Hammer P12 development
I can definitely try that ...
Obviously the others haven't needed it, and erase works, it's the same way.
Obviously the others haven't needed it, and erase works, it's the same way.
Intelligence is in the details!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
It is easier not to learn bad habits, then it is to break them!
If I was here to win a popularity contest, their would be no point, so I wouldn't be here!