16206304 and less important 1623019 from poland

European GM ECUs and PCMs
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: 16206304 and less important 1623019 from poland

Post by antus »

yep looks like its just 160 baud like the fso software in dosbox is using. you could try winaldl with your interface, but I think the software you have shows all the available data. there is patents for the d1927a. 4 wire interface is ref high, ref low, bypass amd ignition. module generates spark then when ecm is happy rpm is fast enough for the ecm timing to work it uses bypass to turn off the modules built in spark and it starts using the ecms spark. on ours cutover is 400rpm.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: 16206304 and less important 1623019 from poland

Post by antus »

https://patents.google.com/patent/US4711226A/en
https://patents.google.com/patent/US4750467A/en

I am not absolutelymcertain this is the right system, I have these details noted from another thread a long long time ago but its not clear how to validate it. To the best of my knowledge its right, or perhaps its the 6cyl version of the same thing.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
gabriel0
Posts: 13
Joined: Sun Jul 17, 2022 10:19 pm
cars: FSO CARO

Re: 16206304 and less important 1623019 from poland

Post by gabriel0 »

Thank you so much for dissasembly the code. Is it possible to add 8192 to this eprom with no other changes like ignition, fuel maps?

And where can i find what exactly eprom contains? Just generally like fuel map, processor code, malf-s, what else?

And about DIS module, almost always its broken power transistor(mosfet?) the biggest one at the end of module, but it is unrepairable because of epoxy resin which all modules was filled.

Edit, there was probably two manuractures of it. I found one that was filled just by sticky gel.
9521358400_1471709862.jpg
You do not have the required permissions to view the files attached to this post.
Last edited by gabriel0 on Sat Jul 30, 2022 12:42 pm, edited 2 times in total.
This engine converts fuel into heat and noise.
The car is propelled by exhaust gas blast from the exhaust pipe.
User avatar
pman92
Posts: 667
Joined: Thu May 03, 2012 12:50 pm
Location: Castlemaine, Vic

Re: 16206304 and less important 1623019 from poland

Post by pman92 »

Your probably better off finding the maps and migrating to $12P. I'm not 100% sure how you would go about doing that though
User avatar
charlay86
Posts: 586
Joined: Thu Sep 17, 2009 4:00 am
cars: VT S1 SS (L67)
Location: Perth, WA

Re: 16206304 and less important 1623019 from poland

Post by charlay86 »

In the disassembly you find the 160 baud serial handler and then find the table of parameters that it points to. Since you know which byte is tps%, ECT, MAP, rpm, spark advance etc you can find where each variable is located in ram. That will get you quite deep into the program.
User avatar
gabriel0
Posts: 13
Joined: Sun Jul 17, 2022 10:19 pm
cars: FSO CARO

Re: 16206304 and less important 1623019 from poland

Post by gabriel0 »

Hello after few years :study:

Now its the time when i'm checking the original maps, studying hc11 and all the stuff i need for know this ecu better.

Can anybody explain me, why GMCKS.exe says that my bin file from 16206304 have wrong checksum?
what could be the reasons, like misread eprom, different checksum for this particular one ecu, or anything else?

Somebody said that there is no answer for 8192 speed, but that means, the checksum should be good?

here again the bin
poldolot.BIN
You do not have the required permissions to view the files attached to this post.
This engine converts fuel into heat and noise.
The car is propelled by exhaust gas blast from the exhaust pipe.
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: 16206304 and less important 1623019 from poland

Post by antus »

The bin looks fine. It's probably modified by a 3rd party OEM. There is a notice at 0x5000

Code: Select all

TNO Road Vehicles Research Institute 1986,1991 ***  T0386FS VERSION 05, 13-04-95 
This company doesn't have anything to do with our operating systems and TO386FS doesnt match the 4 letter broadcast codes the Delco bins use either. So its related but not 100% the same standards.

So they might have moved or changed something, or CMCKS might be for be for another countries bins. The file read looks fine. I can see the reset vectors at the end, the calibration data looks likely right (can see tables earlier in the bin), the file isn't 2 copies of the same data which would have happened if you read off the end of the chip.

Sorry I think Im repeating myself, I googled that operating system and top hit was me saying the same thing a few posts above, a couple of years ago :) I'll have to re-read from the start to see where we are at.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: 16206304 and less important 1623019 from poland

Post by antus »

Try putting OSE12P on it and see if it starts talking 8192 baud. viewtopic.php?f=27&t=356
If it does, you have a very supportable and programable ECM. Since it doesn't seem to be talking 8192 in the car it seems to be engine only and is unlikely to cause other problems, other than getting an initial tune in there set up correctly.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
gabriel0
Posts: 13
Joined: Sun Jul 17, 2022 10:19 pm
cars: FSO CARO

Re: 16206304 and less important 1623019 from poland

Post by gabriel0 »

Hello.
Thanks for answer. If i remember correctly, this ecu is almost the same as '305 or similar to 165? I'm actually not so deep into it what they are. We checked connections to the "8192" chip, and everything was fine, but no answer from ecu.
Also here nobody even said about "data read and clear error codes", just "BLINKING CHECK ENGINE" and almost nobody know about 160 baud data stream. The program that can read this is only for DOS and COM port otherwise it wont work on any emulated dosbox or usb-com.

now i'm more into processor and how it works, i'm larning assembler and want to know more about the electronics.
When i buy some stuff to reprogram the memory, i'll surely check 8192.

Now i'm interested if i correctly disassembled the bin. I have like 1412 entry points with one extra vector somewhere in the middle. If i add vectors at $9100 nothing happens, When i add vectors at $A000 i have 1500+ entry points and some part of the code looks like its doubled.
I mean, does adding vectors is showing where disassembler must start to search, or its showing the bits of the adress where it should start to search?
But still it looks like the eprom is multiplied somehow? Just for some emergency mode it has few different funcions and other stuff looks the same, or if the original memory is faulty?

do you know any threads here where i can learn more about processor and code?
This engine converts fuel into heat and noise.
The car is propelled by exhaust gas blast from the exhaust pipe.
User avatar
antus
Site Admin
Posts: 10012
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: 16206304 and less important 1623019 from poland

Post by antus »

We do know. The ECM looks exactly the same as ours. We dont know where the tables are in yours, the data stream. But the '808 has a 160 baud data stream (and missing the SXR chip for 8192 baud). For us its the same as the later one that has that chip and has the SXR. It does have 8192 baud. Vlad also pointed out all the chips were marked the same. What we did was run the newer operating system on the older computer. Its very likely your ECM is exactly the same as ours. If that is true, you can get 8192 and very well defined operating system, with a lot of extra features in 12P. All you have to do is try it. If it works, you've instantly gone from the lest defined ECM to the most defined ECM and gained 8192. So follow the link and get the bin. If it works, boom! happy days.

Vectors yes, they are entry points the CPU uses. In particular there is the one for boot, and the interupt vectors. If the disassembler you are using doesnt follow them by default (depend on what you're using) you can also go to the address and tell it to start searching there. You will be able to learn things, if that is your goal, but it will be a very long road compared to the 12p option.

You can also try this for 160 baud. It works for our factory operating system, but we normally upgrade it as it is very slow and limited. https://winaldl.joby.se/
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396