Uplander/montana/relay locked bcm
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
Successfully connected up BDM to target had to use bi-directional logic level converter. Here is a dump trying to get the memory addressing correct! Anyone help with this?
Here is the script I'm using to dump and target manual.
<Test>
<Name>9S12XS128</Name>
<Cat>Other</Cat>
<Protocol>BDMHCS12</Protocol>
<Endian>Big</Endian>
<sprogram>1</sprogram>
<Memorys>
<Memory>
<Name>Flash</Name>
<Type>1</Type>
<Address>0x7E0000</Address>
<Size>0x20000</Size>
</Memory>
</Memorys>
</Test>
You do not have the required permissions to view the files attached to this post.
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
Something is definitely wrong with it I don't think the vin should be repeated so much
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
This seems like it might be the EEProm section were the vin and millage are but my Dashboard Service tool v1.8 doesn't seem to like it, anyone know what size it should be and how it should start? This should have 300694 kms on it. Where is the kms stored?
You do not have the required permissions to view the files attached to this post.
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
These are the only sps files I can find from 2007 uplander the 2008 and 2009 do not have any factory programing yet the module seems very similar, does this look anything like my code on the 2009?
You do not have the required permissions to view the files attached to this post.
-
antus
- Site Admin
- Posts: 10016
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: Uplander/montana/relay locked bcm
havnt opened the files but os and cal would be as labeled, possibly as a segment rather than a bin as thats how gm think about it in their tools. amd utility file is usually the flash kernel that runs in ram to provide the flash functionality and enough code to handle communications.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
Yes but the code isn’t available from sps for my year, but nis that I have a half decent dump of mine, I am hoping to use the utility file as is, and use the 07 os/cal as a template to split up my dump to make a proper flashable file for my 09!antus wrote: Tue Jul 02, 2024 11:34 pm havnt opened the files but os and cal would be as labeled, possibly as a segment rather than a bin as thats how gm think about it in their tools. amd utility file is usually the flash kernel that runs in ram to provide the flash functionality and enough code to handle communications.
But I can’t quite see where my os/cal start and end in order to do this?
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
This is truly amazing !! Will see what this can do!antus wrote: Tue Jul 02, 2024 4:40 am Here it is. gcc -o t2rip t2tip.c to compile with gnu c from a command line. Quick and dirty, bin file name is hard coded. You can probably clean it up, but its enough to get the files out on to a PC. Make a directory "bin" where you run it, and it'll put the files in there.
Code: Select all
// t2rip // antus @ pcmhacking.net // Licensed under the GPL V2 #include <stdio.h> void dump(char *fn, int start, int length); FILE *bin; FILE *out; main() { int i; int page; unsigned int offset; unsigned int size; unsigned int sum; unsigned char entry[0x26]; if ((bin=fopen("Holden_157.bin", "rb"))==NULL) { printf("Couldnt open bin\n"); return -1; } for (i=0; i<256; i++) { fseek (bin, 0x18+(i*0x26), SEEK_SET); fread(entry, 0x26, 1, bin); if (entry[0]==0xFF) break; page=entry[15]; offset =entry[16]<<24; offset+=entry[17]<<16; offset+=entry[18]<<8; offset+=entry[19]; size =entry[20]<<24; size+=entry[21]<<16; size+=entry[22]<<8; size+=entry[23]; offset-=0x200000; sum=entry[24]<<8; sum+=entry[25]; printf ("%s\t page %2d start %8X size %8X sum %04X\n", entry, page, offset, size, sum); dump(entry, (page*0x100000)+offset, size); } } void dump(char *fn, int start, int length) { int j; char f[25]={"bin/"}; if (fn[0]==0) { printf("Deleted file... skipping\n"); return; } for (j=0; (fn[j]!=0x20 && fn[j]!=0); j++) f[j+4]=fn[j]; out=fopen(f, "wb"); printf("dumping %s from %X to %X\n", fn, start, start+length); for (j=start; j<start+length; j++) { fseek(bin, j, SEEK_SET); fputc(fgetc(bin),out); } fclose(out); }
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
I don’t quite fully understand this yet but seems quite interesting!! Thanks again for the help!! You are amazing for figuring this all out!antus wrote: Tue Jul 02, 2024 4:52 am And here is what it does. I think .dwn are the executable files.
Looking inside boot.dwn it does look like the vector table that maps to 0x00000 in the P01 etc. And it appears to contain the init code, including the code that waits for a download from a PC if its a 'blank' card. By blank I mean has boot.dwn but not anything more than that. So just enough to pull a bin from SPS/TIS. Its small enough that disassembling that would probably give a pretty good understanding of what hardware is in the tech2 and where to address it.
How useful is is this? Not sure. Its doable, but its a lot of work. You might learn more about the tech2 than anyone else, but still not answer the specific question you started with. You might be able to figure out some of the other files by inspecting their contents directly and not going the disassembly route.
Code: Select all
[root@vm t2rip]# gcc -o t2rip t2rip.c [root@vm t2rip]# ./t2rip CALIBRAT0.SPS page 28 start 0 size 100000 sum FFFF dumping CALIBRAT0.SPS from 1C00000 to 1D00000 CALIBRAT1.SPS page 23 start 0 size 100000 sum FFFF dumping CALIBRAT1.SPS from 1700000 to 1800000 CALIBRAT2.SPS page 24 start 0 size 100000 sum FFFF dumping CALIBRAT2.SPS from 1800000 to 1900000 CALIBRAT3.SPS page 25 start 0 size 100000 sum FFFF dumping CALIBRAT3.SPS from 1900000 to 1A00000 CALIBRAT4.SPS page 26 start 0 size 100000 sum FFFF dumping CALIBRAT4.SPS from 1A00000 to 1B00000 CALIBRAT5.SPS page 27 start 0 size 100000 sum FFFF dumping CALIBRAT5.SPS from 1B00000 to 1C00000 info.inf page 0 start 1FF00 size 21 sum 09C1 dumping info.inf from 1FF00 to 1FF21 ECU.EXT page 16 start 0 size 73CA sum 375F dumping ECU.EXT from 1000000 to 10073CA t2cfg.dwn page 0 start 1FFB0 size 8 sum 02B0 dumping t2cfg.dwn from 1FFB0 to 1FFB8 expire.dat page 0 start 1FFB8 size 48 sum 43FA dumping expire.dat from 1FFB8 to 20000 devschp.ext page 0 start 20000 size 43746 sum AF59 dumping devschp.ext from 20000 to 63746 T1APPS.DWN page 1 start 0 size 2B7E4 sum A2B8 dumping T1APPS.DWN from 100000 to 12B7E4 DEVDYNM.EXT page 1 start 40000 size 72BF6 sum F052 dumping DEVDYNM.EXT from 140000 to 1B2BF6 SCENCONV.DWN page 2 start 0 size 7F0E4 sum FA97 dumping SCENCONV.DWN from 200000 to 27F0E4 datastrm.ext page 3 start 0 size 8AB1E sum 0800 dumping datastrm.ext from 300000 to 38AB1E SCENS.DWN page 4 start 0 size D631E sum B39B dumping SCENS.DWN from 400000 to 4D631E t3apps.dwn page 5 start 0 size DE89A sum 41D7 dumping t3apps.dwn from 500000 to 5DE89A candiapp.blk page 7 start 20000 size AB74 sum 3DAB dumping candiapp.blk from 720000 to 72AB74 graphics.ext page 7 start 30000 size 7C1C sum 2A2F dumping graphics.ext from 730000 to 737C1C api.dwn page 7 start 80000 size 3E240 sum D7E0 dumping api.dwn from 780000 to 7BE240 opsys.dwn page 7 start C0000 size 37FE8 sum 027B dumping opsys.dwn from 7C0000 to 7F7FE8 boot.dwn page 7 start F7FE8 size 4000 sum 2465 dumping boot.dwn from 7F7FE8 to 7FBFE8 vci_init.dwn page 7 start FBFE8 size 1FF8 sum 1215 dumping vci_init.dwn from 7FBFE8 to 7FDFE0 opschk.dwn page 7 start FDFE8 size 1FF8 sum DA41 dumping opschk.dwn from 7FDFE8 to 7FFFE0 nonsps.ext page 8 start C0000 size BE9B sum 2923 dumping nonsps.ext from 8C0000 to 8CBE9B EPID.EXT page 12 start 0 size FA006 sum AB7A dumping EPID.EXT from C00000 to CFA006 PSTRTHDR.EXT page 13 start 0 size 3480A sum 429D dumping PSTRTHDR.EXT from D00000 to D3480A fffr.ext page 13 start 40000 size 715AC sum 02D2 dumping fffr.ext from D40000 to DB15AC PSTRUCT1.EXT page 14 start 0 size 7D004 sum 5139 dumping PSTRUCT1.EXT from E00000 to E7D004 PSTRUCT2.EXT page 14 start 80000 size 7D002 sum 784B dumping PSTRUCT2.EXT from E80000 to EFD002 PSTRUCT4.EXT page 15 start 0 size 7D004 sum A5C6 dumping PSTRUCT4.EXT from F00000 to F7D004 CPID.EXT page 15 start 80000 size 3AB96 sum CC9A dumping CPID.EXT from F80000 to FBAB96 SCENLST1.EXT page 17 start 0 size 2F900 sum 91AD dumping SCENLST1.EXT from 1100000 to 112F900 PSTRUCT3.EXT page 17 start 80000 size 7D002 sum 7186 dumping PSTRUCT3.EXT from 1180000 to 11FD002 DATADISP.EXT page 18 start 0 size D4F18 sum 6481 dumping DATADISP.EXT from 1200000 to 12D4F18 DISPCONV.DWN page 19 start 0 size A62 sum 7852 dumping DISPCONV.DWN from 1300000 to 1300A62 SCENMSG.EXT page 19 start 40000 size AB026 sum E27C dumping SCENMSG.EXT from 1340000 to 13EB026 DISPCONV.EXT page 20 start 0 size 4C29A sum 1348 dumping DISPCONV.EXT from 1400000 to 144C29A screens.ext page 20 start 80000 size 48868 sum 3F31 dumping screens.ext from 1480000 to 14C8868 T3APPS2.DWN page 21 start 0 size 7AE60 sum F63D dumping T3APPS2.DWN from 1500000 to 157AE60 vinproc.ext page 28 start 0 size C7A1C sum C15C dumping vinproc.ext from 1C00000 to 1CC7A1C DDEPID.EXT page 29 start 0 size 65A38 sum CF14 dumping DDEPID.EXT from 1D00000 to 1D65A38 tableapp.ext page 29 start 80000 size 4DA86 sum CA84 dumping tableapp.ext from 1D80000 to 1DCDA86 EPID1.EXT page 30 start 0 size 2BBB0 sum 2843 dumping EPID1.EXT from 1E00000 to 1E2BBB0 PSTRUCT5.EXT page 30 start 80000 size 55558 sum 2AD7 dumping PSTRUCT5.EXT from 1E80000 to 1ED5558 SEV.EXT page 31 start 40000 size 180F6 sum CD27 dumping SEV.EXT from 1F40000 to 1F580F6 docen.ext page 0 start 80000 size 387C2 sum 60CE dumping docen.ext from 80000 to B87C2 strhdren.ext page 6 start 0 size 5CD4E sum 33AB dumping strhdren.ext from 600000 to 65CD4E strngsen.ext page 16 start 40000 size 6045C sum 25A7 dumping strngsen.ext from 1040000 to 10A045C 1252font.dwn page 7 start 0 size 1000 sum C168 dumping 1252font.dwn from 700000 to 701000 [root@vm t2rip]# ls -l bin total 20432 -rw-r--r--. 1 root root 4096 Jul 2 14:21 1252font.dwn -rw-r--r--. 1 root root 254528 Jul 2 14:21 api.dwn -rw-r--r--. 1 root root 16384 Jul 2 14:21 boot.dwn -rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT0.SPS -rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT1.SPS -rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT2.SPS -rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT3.SPS -rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT4.SPS -rw-r--r--. 1 root root 1048576 Jul 2 14:21 CALIBRAT5.SPS -rw-r--r--. 1 root root 43892 Jul 2 14:21 candiapp.blk -rw-r--r--. 1 root root 240534 Jul 2 14:21 CPID.EXT -rw-r--r--. 1 root root 872216 Jul 2 14:21 DATADISP.EXT -rw-r--r--. 1 root root 568094 Jul 2 14:21 datastrm.ext -rw-r--r--. 1 root root 416312 Jul 2 14:21 DDEPID.EXT -rw-r--r--. 1 root root 470006 Jul 2 14:21 DEVDYNM.EXT -rw-r--r--. 1 root root 276294 Jul 2 14:21 devschp.ext -rw-r--r--. 1 root root 2658 Jul 2 14:21 DISPCONV.DWN -rw-r--r--. 1 root root 311962 Jul 2 14:21 DISPCONV.EXT -rw-r--r--. 1 root root 231362 Jul 2 14:21 docen.ext -rw-r--r--. 1 root root 29642 Jul 2 14:21 ECU.EXT -rw-r--r--. 1 root root 179120 Jul 2 14:21 EPID1.EXT -rw-r--r--. 1 root root 1024006 Jul 2 14:21 EPID.EXT -rw-r--r--. 1 root root 72 Jul 2 14:21 expire.dat -rw-r--r--. 1 root root 464300 Jul 2 14:21 fffr.ext -rw-r--r--. 1 root root 31772 Jul 2 14:21 graphics.ext -rw-r--r--. 1 root root 33 Jul 2 14:21 info.inf -rw-r--r--. 1 root root 48795 Jul 2 14:21 nonsps.ext -rw-r--r--. 1 root root 8184 Jul 2 14:21 opschk.dwn -rw-r--r--. 1 root root 229352 Jul 2 14:21 opsys.dwn -rw-r--r--. 1 root root 215050 Jul 2 14:21 PSTRTHDR.EXT -rw-r--r--. 1 root root 512004 Jul 2 14:21 PSTRUCT1.EXT -rw-r--r--. 1 root root 512002 Jul 2 14:21 PSTRUCT2.EXT -rw-r--r--. 1 root root 512002 Jul 2 14:21 PSTRUCT3.EXT -rw-r--r--. 1 root root 512004 Jul 2 14:21 PSTRUCT4.EXT -rw-r--r--. 1 root root 349528 Jul 2 14:21 PSTRUCT5.EXT -rw-r--r--. 1 root root 520420 Jul 2 14:21 SCENCONV.DWN -rw-r--r--. 1 root root 194816 Jul 2 14:21 SCENLST1.EXT -rw-r--r--. 1 root root 700454 Jul 2 14:21 SCENMSG.EXT -rw-r--r--. 1 root root 877342 Jul 2 14:21 SCENS.DWN -rw-r--r--. 1 root root 297064 Jul 2 14:21 screens.ext -rw-r--r--. 1 root root 98550 Jul 2 14:21 SEV.EXT -rw-r--r--. 1 root root 380238 Jul 2 14:21 strhdren.ext -rw-r--r--. 1 root root 394332 Jul 2 14:21 strngsen.ext -rw-r--r--. 1 root root 178148 Jul 2 14:21 T1APPS.DWN -rw-r--r--. 1 root root 8 Jul 2 14:21 t2cfg.dwn -rw-r--r--. 1 root root 503392 Jul 2 14:21 T3APPS2.DWN -rw-r--r--. 1 root root 911514 Jul 2 14:21 t3apps.dwn -rw-r--r--. 1 root root 318086 Jul 2 14:21 tableapp.ext -rw-r--r--. 1 root root 8184 Jul 2 14:21 vci_init.dwn -rw-r--r--. 1 root root 817692 Jul 2 14:21 vinproc.ext
-
antus
- Site Admin
- Posts: 10016
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: Uplander/montana/relay locked bcm
Do you mean comparing Flash_2024_07_02_11_44_31.bin?
Comparing that to the os and cal bin, and looking for similar patches near the ends, I used the giant block of ? to get them closer to alignment, then a couple of 0000s to get it on by byte. Can see there is enough similar when doing that to know you are barking up the right tree. But due to the file size differences you are going to have to to figure out the segments, and undertake some guess work. Maybe you can change a setting in one, and then try and find and line up that part of the bin only. You might be able to operate on a smaller chunk without going as far as understanding the whole segment. The similar chunk doesn't run for too long in either direction before they get out of sync again so the OS has changed enough between them to add some complexity.
I also notice there are several AA 55 which is often used as a marker or signature in the flash image, also 55 AA AA 55, same deal. The reason engineers use these values is because in binary AA = 10101010 and 55 = 01010101. They probably could use anything, but they often like those kinds of numbers. Those numbers might be start or end of segments. But there isnt a lot of other hints to work out how the flash read might be converted from bin to segments.
Comparing that to the os and cal bin, and looking for similar patches near the ends, I used the giant block of ? to get them closer to alignment, then a couple of 0000s to get it on by byte. Can see there is enough similar when doing that to know you are barking up the right tree. But due to the file size differences you are going to have to to figure out the segments, and undertake some guess work. Maybe you can change a setting in one, and then try and find and line up that part of the bin only. You might be able to operate on a smaller chunk without going as far as understanding the whole segment. The similar chunk doesn't run for too long in either direction before they get out of sync again so the OS has changed enough between them to add some complexity.
I also notice there are several AA 55 which is often used as a marker or signature in the flash image, also 55 AA AA 55, same deal. The reason engineers use these values is because in binary AA = 10101010 and 55 = 01010101. They probably could use anything, but they often like those kinds of numbers. Those numbers might be start or end of segments. But there isnt a lot of other hints to work out how the flash read might be converted from bin to segments.
You do not have the required permissions to view the files attached to this post.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
04colyZQ8
- Posts: 536
- Joined: Thu Jan 16, 2014 2:41 am
- cars: 2004 Colorado 4.8L swap
86/90 Jimmy 6.5L diesel swap
80 Chevrolet Silverado TBI swap
88dodge W100 LPG conversion
Re: Uplander/montana/relay locked bcm
Thanks! Yes I also see a module part number at the beginning of the the 2007 file that is not what I expected? I thought it would be the os number.
It would be great if I had a dump of the 07 bcm to compare the entire flash verses the sps files.
I’m going to run the utility file only on my 09 bcm, then try to dump the ram. Then I can see the kernel and were it goes.
I’m having a hard time getting a decant disassembly with ghidra it doesn’t have my exact processor listed. I’m trying a 16 bit hcs12, not sure…
It would be great if I had a dump of the 07 bcm to compare the entire flash verses the sps files.
I’m going to run the utility file only on my 09 bcm, then try to dump the ram. Then I can see the kernel and were it goes.
I’m having a hard time getting a decant disassembly with ghidra it doesn’t have my exact processor listed. I’m trying a 16 bit hcs12, not sure…