16206304 and less important 1623019 from poland
-
antus
- Site Admin
- Posts: 10012
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: 16206304 and less important 1623019 from poland
yep looks like its just 160 baud like the fso software in dosbox is using. you could try winaldl with your interface, but I think the software you have shows all the available data. there is patents for the d1927a. 4 wire interface is ref high, ref low, bypass amd ignition. module generates spark then when ecm is happy rpm is fast enough for the ecm timing to work it uses bypass to turn off the modules built in spark and it starts using the ecms spark. on ours cutover is 400rpm.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
antus
- Site Admin
- Posts: 10012
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: 16206304 and less important 1623019 from poland
https://patents.google.com/patent/US4711226A/en
https://patents.google.com/patent/US4750467A/en
I am not absolutelymcertain this is the right system, I have these details noted from another thread a long long time ago but its not clear how to validate it. To the best of my knowledge its right, or perhaps its the 6cyl version of the same thing.
https://patents.google.com/patent/US4750467A/en
I am not absolutelymcertain this is the right system, I have these details noted from another thread a long long time ago but its not clear how to validate it. To the best of my knowledge its right, or perhaps its the 6cyl version of the same thing.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
gabriel0
- Posts: 13
- Joined: Sun Jul 17, 2022 10:19 pm
- cars: FSO CARO
Re: 16206304 and less important 1623019 from poland
Thank you so much for dissasembly the code. Is it possible to add 8192 to this eprom with no other changes like ignition, fuel maps?
And where can i find what exactly eprom contains? Just generally like fuel map, processor code, malf-s, what else?
And about DIS module, almost always its broken power transistor(mosfet?) the biggest one at the end of module, but it is unrepairable because of epoxy resin which all modules was filled.
Edit, there was probably two manuractures of it. I found one that was filled just by sticky gel.
And where can i find what exactly eprom contains? Just generally like fuel map, processor code, malf-s, what else?
And about DIS module, almost always its broken power transistor(mosfet?) the biggest one at the end of module, but it is unrepairable because of epoxy resin which all modules was filled.
Edit, there was probably two manuractures of it. I found one that was filled just by sticky gel.
You do not have the required permissions to view the files attached to this post.
Last edited by gabriel0 on Sat Jul 30, 2022 12:42 pm, edited 2 times in total.
This engine converts fuel into heat and noise.
The car is propelled by exhaust gas blast from the exhaust pipe.
The car is propelled by exhaust gas blast from the exhaust pipe.
-
pman92
- Posts: 667
- Joined: Thu May 03, 2012 12:50 pm
- Location: Castlemaine, Vic
Re: 16206304 and less important 1623019 from poland
Your probably better off finding the maps and migrating to $12P. I'm not 100% sure how you would go about doing that though
-
charlay86
- Posts: 586
- Joined: Thu Sep 17, 2009 4:00 am
- cars: VT S1 SS (L67)
- Location: Perth, WA
Re: 16206304 and less important 1623019 from poland
In the disassembly you find the 160 baud serial handler and then find the table of parameters that it points to. Since you know which byte is tps%, ECT, MAP, rpm, spark advance etc you can find where each variable is located in ram. That will get you quite deep into the program.
-
gabriel0
- Posts: 13
- Joined: Sun Jul 17, 2022 10:19 pm
- cars: FSO CARO
Re: 16206304 and less important 1623019 from poland
Hello after few years
Now its the time when i'm checking the original maps, studying hc11 and all the stuff i need for know this ecu better.
Can anybody explain me, why GMCKS.exe says that my bin file from 16206304 have wrong checksum?
what could be the reasons, like misread eprom, different checksum for this particular one ecu, or anything else?
Somebody said that there is no answer for 8192 speed, but that means, the checksum should be good?
here again the bin
Now its the time when i'm checking the original maps, studying hc11 and all the stuff i need for know this ecu better.
Can anybody explain me, why GMCKS.exe says that my bin file from 16206304 have wrong checksum?
what could be the reasons, like misread eprom, different checksum for this particular one ecu, or anything else?
Somebody said that there is no answer for 8192 speed, but that means, the checksum should be good?
here again the bin
You do not have the required permissions to view the files attached to this post.
This engine converts fuel into heat and noise.
The car is propelled by exhaust gas blast from the exhaust pipe.
The car is propelled by exhaust gas blast from the exhaust pipe.
-
antus
- Site Admin
- Posts: 10012
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: 16206304 and less important 1623019 from poland
The bin looks fine. It's probably modified by a 3rd party OEM. There is a notice at 0x5000
This company doesn't have anything to do with our operating systems and TO386FS doesnt match the 4 letter broadcast codes the Delco bins use either. So its related but not 100% the same standards.
So they might have moved or changed something, or CMCKS might be for be for another countries bins. The file read looks fine. I can see the reset vectors at the end, the calibration data looks likely right (can see tables earlier in the bin), the file isn't 2 copies of the same data which would have happened if you read off the end of the chip.
Sorry I think Im repeating myself, I googled that operating system and top hit was me saying the same thing a few posts above, a couple of years ago
I'll have to re-read from the start to see where we are at.
Code: Select all
TNO Road Vehicles Research Institute 1986,1991 *** T0386FS VERSION 05, 13-04-95
So they might have moved or changed something, or CMCKS might be for be for another countries bins. The file read looks fine. I can see the reset vectors at the end, the calibration data looks likely right (can see tables earlier in the bin), the file isn't 2 copies of the same data which would have happened if you read off the end of the chip.
Sorry I think Im repeating myself, I googled that operating system and top hit was me saying the same thing a few posts above, a couple of years ago
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
antus
- Site Admin
- Posts: 10012
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: 16206304 and less important 1623019 from poland
Try putting OSE12P on it and see if it starts talking 8192 baud. viewtopic.php?f=27&t=356
If it does, you have a very supportable and programable ECM. Since it doesn't seem to be talking 8192 in the car it seems to be engine only and is unlikely to cause other problems, other than getting an initial tune in there set up correctly.
If it does, you have a very supportable and programable ECM. Since it doesn't seem to be talking 8192 in the car it seems to be engine only and is unlikely to cause other problems, other than getting an initial tune in there set up correctly.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
gabriel0
- Posts: 13
- Joined: Sun Jul 17, 2022 10:19 pm
- cars: FSO CARO
Re: 16206304 and less important 1623019 from poland
Hello.
Thanks for answer. If i remember correctly, this ecu is almost the same as '305 or similar to 165? I'm actually not so deep into it what they are. We checked connections to the "8192" chip, and everything was fine, but no answer from ecu.
Also here nobody even said about "data read and clear error codes", just "BLINKING CHECK ENGINE" and almost nobody know about 160 baud data stream. The program that can read this is only for DOS and COM port otherwise it wont work on any emulated dosbox or usb-com.
now i'm more into processor and how it works, i'm larning assembler and want to know more about the electronics.
When i buy some stuff to reprogram the memory, i'll surely check 8192.
Now i'm interested if i correctly disassembled the bin. I have like 1412 entry points with one extra vector somewhere in the middle. If i add vectors at $9100 nothing happens, When i add vectors at $A000 i have 1500+ entry points and some part of the code looks like its doubled.
I mean, does adding vectors is showing where disassembler must start to search, or its showing the bits of the adress where it should start to search?
But still it looks like the eprom is multiplied somehow? Just for some emergency mode it has few different funcions and other stuff looks the same, or if the original memory is faulty?
do you know any threads here where i can learn more about processor and code?
Thanks for answer. If i remember correctly, this ecu is almost the same as '305 or similar to 165? I'm actually not so deep into it what they are. We checked connections to the "8192" chip, and everything was fine, but no answer from ecu.
Also here nobody even said about "data read and clear error codes", just "BLINKING CHECK ENGINE" and almost nobody know about 160 baud data stream. The program that can read this is only for DOS and COM port otherwise it wont work on any emulated dosbox or usb-com.
now i'm more into processor and how it works, i'm larning assembler and want to know more about the electronics.
When i buy some stuff to reprogram the memory, i'll surely check 8192.
Now i'm interested if i correctly disassembled the bin. I have like 1412 entry points with one extra vector somewhere in the middle. If i add vectors at $9100 nothing happens, When i add vectors at $A000 i have 1500+ entry points and some part of the code looks like its doubled.
I mean, does adding vectors is showing where disassembler must start to search, or its showing the bits of the adress where it should start to search?
But still it looks like the eprom is multiplied somehow? Just for some emergency mode it has few different funcions and other stuff looks the same, or if the original memory is faulty?
do you know any threads here where i can learn more about processor and code?
This engine converts fuel into heat and noise.
The car is propelled by exhaust gas blast from the exhaust pipe.
The car is propelled by exhaust gas blast from the exhaust pipe.
-
antus
- Site Admin
- Posts: 10012
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: 16206304 and less important 1623019 from poland
We do know. The ECM looks exactly the same as ours. We dont know where the tables are in yours, the data stream. But the '808 has a 160 baud data stream (and missing the SXR chip for 8192 baud). For us its the same as the later one that has that chip and has the SXR. It does have 8192 baud. Vlad also pointed out all the chips were marked the same. What we did was run the newer operating system on the older computer. Its very likely your ECM is exactly the same as ours. If that is true, you can get 8192 and very well defined operating system, with a lot of extra features in 12P. All you have to do is try it. If it works, you've instantly gone from the lest defined ECM to the most defined ECM and gained 8192. So follow the link and get the bin. If it works, boom! happy days.
Vectors yes, they are entry points the CPU uses. In particular there is the one for boot, and the interupt vectors. If the disassembler you are using doesnt follow them by default (depend on what you're using) you can also go to the address and tell it to start searching there. You will be able to learn things, if that is your goal, but it will be a very long road compared to the 12p option.
You can also try this for 160 baud. It works for our factory operating system, but we normally upgrade it as it is very slow and limited. https://winaldl.joby.se/
Vectors yes, they are entry points the CPU uses. In particular there is the one for boot, and the interupt vectors. If the disassembler you are using doesnt follow them by default (depend on what you're using) you can also go to the address and tell it to start searching there. You will be able to learn things, if that is your goal, but it will be a very long road compared to the 12p option.
You can also try this for 160 baud. It works for our factory operating system, but we normally upgrade it as it is very slow and limited. https://winaldl.joby.se/
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396