antus wrote:Most excellent. I had a feeling it was seed + key 0000. There must be some code in the factory OS that implements FFFF = 0000. Maybe they know FFFF is a blank prom but wanted 0000 to signal unlocked because the suits in the office were confused by FFFF.... And that code does it to both seed and key. I can't see any other reason we'd get this seed and key, but its proven.
Hiya, I think it is a simple XOR to check if output register "matches".
Thing is 0000 does not match FFFF, but somehow seed and key both become 0000 when they have FFFF on the flash. Special case. It doesn't matter, its just an observation.
When pcm is unlocked it sends 0000 for seed. Maybe if it is FFFF it is also unlocked since it can`t be FFFF by gm specs so it also sends 0000 for seed. Some test can be done to omit unlocking, to confirm the theory.
In this case we know flash has FFFF for seed and key (as the whole segment is erased). We know it is locked, and we receive 0000 for seed. We must send 0000 for key before we can upload. There is not really a question here, it is fact. When seed and key are FFFF in flash, they become 0000 and 0000 somehow and still requires unlock. It doesn't matter how, I was just commenting there must be code that does it in these PCMs.
antus wrote:In this case we know flash has FFFF for seed and key (as the whole segment is erased). We know it is locked, and we receive 0000 for seed. We must send 0000 for key before we can upload. There is not really a question here, it is fact. When seed and key are FFFF in flash, they become 0000 and 0000 somehow and still requires unlock. It doesn't matter how, I was just commenting there must be code that does it in these PCMs.
I will need to look that in disassembly to uncover the mystery.