Don't give me ideas.
Probably doable with the Fire 32, not the 28 though.
Everything I have it working with is the built in tunerpro plugin.
And a new one that works with honda tuning suite..... that was a headache, tunerpro was so much easier to make it just work.
OneROM
-
jxx
- Posts: 222
- Joined: Tue Oct 25, 2011 9:47 am
- cars: To many
- Location: Vic
-
vlad01
- Posts: 8549
- Joined: Mon Oct 08, 2012 8:41 am
- cars: VP I S
VP I executive
VP II executive
VP II executive #2 - Location: Kyneton, Vic
Re: OneROM
Ok, right, that makes sense now.
-
dimiras
- Posts: 2
- Joined: Tue Jan 10, 2023 1:39 am
- cars: BMW Z3 1.8 M42 Swap
Suzuki Jimny 1.3 g13bb
Re: OneROM
Would it be possible to have customizable baud rates?
I'm asking because I implemented a custom protocol for a bmw ecu and it would be nice to also have datalogging without an additional device
I'm asking because I implemented a custom protocol for a bmw ecu and it would be nice to also have datalogging without an additional device
-
jxx
- Posts: 222
- Joined: Tue Oct 25, 2011 9:47 am
- cars: To many
- Location: Vic
Re: OneROM
What baud?
I only implemented it as a proof of concept, I should probably drop it to 38400.
If i had a list of the major common brands/models I could add a few for the odd cases like ALDL.
The program isn't actually compiling a new binary to upload to the One rom, the serial modes are 6 precompiled images embeded in the .exe (0.1.3beta)
The flashtool is just taking a premade One Rom firmware, metadata, system plugin, rom image and uploading them to the correct spots in the RP2350 flash.
Unfortunately it's not just a simple switch to change the speed, each difference would mean a new base image.
I'm trying to keep it simple, small and not have it fetch images from online for extra options.
I only implemented it as a proof of concept, I should probably drop it to 38400.
If i had a list of the major common brands/models I could add a few for the odd cases like ALDL.
The program isn't actually compiling a new binary to upload to the One rom, the serial modes are 6 precompiled images embeded in the .exe (0.1.3beta)
The flashtool is just taking a premade One Rom firmware, metadata, system plugin, rom image and uploading them to the correct spots in the RP2350 flash.
Unfortunately it's not just a simple switch to change the speed, each difference would mean a new base image.
I'm trying to keep it simple, small and not have it fetch images from online for extra options.
-
dimiras
- Posts: 2
- Joined: Tue Jan 10, 2023 1:39 am
- cars: BMW Z3 1.8 M42 Swap
Suzuki Jimny 1.3 g13bb
Re: OneROM
I am using 187500 because its the fastest baud I can get with the 8051 at 12mhz from my bosch motronic.
I also wrote the same custom code for a friend that has a older bosch motronic from a alfa 33 which uses 156250 because the mcu is running at 10mhz.
We are using a kkl adapter connected to the diagnostic plug, it will be just one more usb connected to the pc.
I would still need to figure out where to connect the rx and tx pins inside the ecu.
Thanks a lot for the reply and for sharing your project!
I also wrote the same custom code for a friend that has a older bosch motronic from a alfa 33 which uses 156250 because the mcu is running at 10mhz.
We are using a kkl adapter connected to the diagnostic plug, it will be just one more usb connected to the pc.
I would still need to figure out where to connect the rx and tx pins inside the ecu.
Thanks a lot for the reply and for sharing your project!
-
jxx
- Posts: 222
- Joined: Tue Oct 25, 2011 9:47 am
- cars: To many
- Location: Vic
Re: OneROM
v0.1.4-alpha
EMU REV I firmware
Fxed bug in Com port 2 TX line with faster larger data chunks effecting all UART modes.
Changed NORMAL Com port 2 speed to 38400 8N1, more inline default for ECU's of the era.
Added HTS compatible protocol changes for Honda.
ALDL 8192 8N1 Enabled.
TX RX Inversion:
Bug: RP2350's GPIO INOVER/OUTOVER pad override can't switch fast enough at 8192 baud for alternating bit patterns.
Fix: Moved the inversion from the GPIO pad into the bridge as a per-byte XOR (uart_xform_tx/uart_xform_rx); GPIO INOVER/OUTOVER bits are no longer set.
Removed alpha release.
Latest Release now available in first post of thread with ALDL UART Inversion options enabled
viewtopic.php?p=138305#p138305
*****REMOVED_OLD_FILE*****onerom-emu-flashtool_0.1.4-alpha.zip
ChangeLog for both the Ostrich-compatible Firmware & Flashtool are also in the first post.
It's quite a long read, they contain a lot of info about everything that went into building both projects.
Bugs, stuff ups, improvements, info on protocols, it's all in there.
I can't see any major updates to this firmware and flashtool in the near future, I think i've squashed all the bugs and issues.
It's been a mission implementing the functionality and making it work.
If anyone finds bugs, let me know and i'll get onto them.
A heap of python scripts later confirming the One ROM is working with ALDL 8192 8N1 across another com port and physical loopback tests.
I didn't have a working benchtest ECU, i've smashed together an ALDL ECU Sim with AI assistance.
This is both ridiculous and amazing at what AI assistance can accomplish with the right prompts as a tool (and the odd swearing to stop it going in infinite loops fixing a bug and to find the right solution).
Not to mention learning different coding languages.
This was only testing the 2nd COM data port, nothing to do with the ROM emulator and ostrich protocol which were proven to work a while ago.
ECU Sim is connected to a USB to SERIAL on COM58
TX RX USB to Serial <--> RX TX One ROM
TunerPro RT data aquisition logging connected to 2nd UART on One ROM COM17
99% Sure this will work connected to a physical ECU/PCM TX and RX lines on the mainboard.
Not sure if this is useful to anyone but here's the ALDL ECU Sim
Basic 8192 baud 1227808/16176424/16183082 Sim, used a handful of adx & xdf files from the forum to wire its functions, not saying it's 100% perfect but was handy for my benchtest scenarios.
EMU REV I firmware
Fxed bug in Com port 2 TX line with faster larger data chunks effecting all UART modes.
Changed NORMAL Com port 2 speed to 38400 8N1, more inline default for ECU's of the era.
Added HTS compatible protocol changes for Honda.
ALDL 8192 8N1 Enabled.
TX RX Inversion:
Bug: RP2350's GPIO INOVER/OUTOVER pad override can't switch fast enough at 8192 baud for alternating bit patterns.
Fix: Moved the inversion from the GPIO pad into the bridge as a per-byte XOR (uart_xform_tx/uart_xform_rx); GPIO INOVER/OUTOVER bits are no longer set.
Removed alpha release.
Latest Release now available in first post of thread with ALDL UART Inversion options enabled
viewtopic.php?p=138305#p138305
*****REMOVED_OLD_FILE*****onerom-emu-flashtool_0.1.4-alpha.zip
ChangeLog for both the Ostrich-compatible Firmware & Flashtool are also in the first post.
It's quite a long read, they contain a lot of info about everything that went into building both projects.
Bugs, stuff ups, improvements, info on protocols, it's all in there.
I can't see any major updates to this firmware and flashtool in the near future, I think i've squashed all the bugs and issues.
It's been a mission implementing the functionality and making it work.
If anyone finds bugs, let me know and i'll get onto them.
A heap of python scripts later confirming the One ROM is working with ALDL 8192 8N1 across another com port and physical loopback tests.
I didn't have a working benchtest ECU, i've smashed together an ALDL ECU Sim with AI assistance.
This is both ridiculous and amazing at what AI assistance can accomplish with the right prompts as a tool (and the odd swearing to stop it going in infinite loops fixing a bug and to find the right solution).
Not to mention learning different coding languages.
This was only testing the 2nd COM data port, nothing to do with the ROM emulator and ostrich protocol which were proven to work a while ago.
ECU Sim is connected to a USB to SERIAL on COM58
TX RX USB to Serial <--> RX TX One ROM
TunerPro RT data aquisition logging connected to 2nd UART on One ROM COM17
99% Sure this will work connected to a physical ECU/PCM TX and RX lines on the mainboard.
Not sure if this is useful to anyone but here's the ALDL ECU Sim
Basic 8192 baud 1227808/16176424/16183082 Sim, used a handful of adx & xdf files from the forum to wire its functions, not saying it's 100% perfect but was handy for my benchtest scenarios.
## [0.1.3] - 2026-06-23
ChangeLog
### Added
- **`memcal_db` module** (183 entries: VN/VP, VR, VS, VT, VX). `lookup_by_bcc`, `lookup_by_filename`,
`lookup_by_pid`, `iter`.
BCC column shows the full 8-character code for entries with a known suffix, the 4-letter prefix otherwise.
**Memcal toolbar** (one row above the bin row): `[Search]` opens a searchable browser over the database.
`[Info]` (on the bin row, next to `Clear`) looks the loaded bin up by its 4-letter prefix.
Source mainly PCMhacking.net and a few other websites that had the same information, compiled together and compared.
- **Wire-signal invert + echo suppression** under the port row.
`Invert: TX / RX` are mutually-exclusive radio buttons (XOR each byte with 0xFF at the port boundary, default both off).
`Echo Suppress` is a separate checkbox (default off) for passive 1-wire adapters; dropped bytes are logged as
`Direction::Echo` for verification.
- **`Set Faults` scenario** — drives the per-frame auto-DTC scan to a known multi-code state (CTS 145°C, MAT -45°C,
MAP 8 kPa, O2 stuck + slow, RPM 2250 / TPS 0% correlation).
No `state.malfs` is set directly; the scan + correlation check are the test target.
Useful for verifying the debounce timers and the tune-gated enable bitfield work end-to-end.
### Changed
- **Bin row no longer shows the program-ID / version tag.** File name, size, `Load .bin...`, `Clear`, `Info` only.
ID and version moved to the `Info` popup.
- **Total: 168 unit tests across 12 source files + 4 integration tests** in `tests/integration.rs`.
ALDL ECU Simulator
====================
A wire-protocol responder for testing OBD-style scan tools against a configurable engine state, without a real ECM on the bench.
Requires a real COM port (a $5 USB-to-serial adapter works).
What's in this bundle
---------------------
ALDL_ECU_Simulator_GUI-0.x.x.exe - GUI version (recommended)
ALDL_ECU_Simulator_cli-0.x.x.exe - Command-line version
licence.txt - MIT licence terms
README.txt - this file
Quick start
-----------
GUI:
1. Plug in a USB-to-serial adapter (FTDI, CH340, etc.)
2. Double-click ALDL_ECU_Simulator_GUI-0.1.1.exe
3. Pick the COM port from the dropdown
4. Click Open
5. Point TunerPro RT (or your scan tool) at the other end of the
null-modem cable / adapter
CLI (headless / automated):
ALDL_ECU_Simulator_cli --port COM3
ALDL_ECU_Simulator_cli --port COM3 --rpm 2500 --clt 95
ALDL_ECU_Simulator_cli /? (show all options)
Default values
--------------
Baud rate: 8192 (ALDL protocol standard)
Profile: Commodore 3.8L V6
Engine RPM: 800 (idle)
Coolant: 90 deg C
Intake air: 25 deg C
Throttle: 0%
Battery: 14.0V
Supported scan-tool commands
-----------------------------
Mode 1 (live data):
Sub-id 0x00 full 56-byte petrol datastream
Sub-id 0x06 compact 8-byte Message 6
Sub-id 0x07 10-byte Message 6 Dyno Modified (TPS, VE, CTS)
Mode 4 (diagnostic):
Sub-id 0x03 read memory block (returns bytes from a loaded .bin)
Sub-id 0x40 fuel pump on / off
Sub-id 0x02 high-speed fan on / off
Sub-id 0x00 TCC on, 20deg spark override, BLM reset, return to
normal (distinguished by payload bytes)
Loading a calibration .bin (optional)
---------------------------------------
The simulator works without a .bin file (Mode 4 reads return zeros).
To test calibration reads:
1. Click "Load .bin..." in the GUI
2. Pick an .bin file (32 KB)
3. Send a Mode 4 read command from the scan tool
Troubleshooting
---------------
COM port not in the dropdown:
- Click Refresh
- Check the adapter is plugged in and the driver is installed
- Try a different USB port
"Failed to open COMx" error:
- Another program is using the port (close PuTTY, etc.)
- The port number is wrong (check Device Manager)
Scan tool doesn't get a response:
- Check the wiring (null-modem adapter between the two COM ports)
- Verify the baud rate matches (8192)
- Check the traffic tape in the GUI for incoming requests
Licence
-------
This software is released under the MIT Licence. See licence.txt for
the full text and third-party dependency attributions.
You do not have the required permissions to view the files attached to this post.
Last edited by jxx on Wed Jul 01, 2026 12:21 am, edited 2 times in total.
-
jxx
- Posts: 222
- Joined: Tue Oct 25, 2011 9:47 am
- cars: To many
- Location: Vic
Re: OneROM
One rom Fire 32 A 27C010 128K EMU
For RP2350B
Not compatible with fire 28.
No 2nd com port.
Have not tested in an ecu/pcm yet.
TunerPro read/write/verify
Verifies in GQ-4x
Sometimes doesn't verify until 2nd try, slight delay occasionally.
This should only effect initial uploads where the entire .bin is uploaded, future changes/edits should only update the changed 4K blocks.
May contain bugs, this is an early port.
Bench testing shows it should be fully functional.
VS & VT .bins
For RP2350B
Not compatible with fire 28.
No 2nd com port.
Have not tested in an ecu/pcm yet.
TunerPro read/write/verify
Verifies in GQ-4x
Sometimes doesn't verify until 2nd try, slight delay occasionally.
This should only effect initial uploads where the entire .bin is uploaded, future changes/edits should only update the changed 4K blocks.
May contain bugs, this is an early port.
Bench testing shows it should be fully functional.
VS & VT .bins
You do not have the required permissions to view the files attached to this post.
Last edited by jxx on Sun Jun 28, 2026 12:55 am, edited 5 times in total.
-
antus
- Site Admin
- Posts: 10014
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: OneROM
nice one, quick progress!
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
jxx
- Posts: 222
- Joined: Tue Oct 25, 2011 9:47 am
- cars: To many
- Location: Vic
Re: OneROM
Thanks.
Most of the 27C010 Fire 32 A options have not been tested.
COM2 Disabled and ALDL Normal (No Inversion) have been bench tested (ALDL Uart passthru with physical jumper loopback test passed).
Just compiled all the files with the suitable options and crossed my fingers.
Alpha release to make testing easier for anyone with the correct Onerom hardware.
Released as is, where is, a can of mortein on the bench may be useful.
Theory time:
Possible 27C020 & 27C040 modes, i don't see any use case for this though.
The One ROM bank select should work (refer to the original projects documentation https://github.com/piersfinlayson/one-rom)
The Uart 2 disabled should allow Sel A/B/C/D.
Uart 2 mode enabled uses Sel C/D pins, Sel A/B should work.
If these work it's a bonus, if they don't I'm sure it would require re-writing most of the code, I was not thinking about these options while trying to port this.
Redoing the entire EMU firmware code is Not something I intend to do, totally seperate to the Flashtool.
Flashtool 0.1.5-alpha According to the RP2350B datasheet these pins (unlike the pins used for uart on RP2350) are 5V tolerant (upto 5.5V).
Pin 47 - GPIO 38 - TX
Pin 48 - GPIO 39 - RX
# Changelog
## 0.1.5-alpha — 2026-06-22
- **27C010 (Fire 32 A) EPROM support** — third EPROM-type radio alongside 27C256/27C512.
Loads the Fire 32 firmware/metadata/plugin set (`assets/plugins/32/`). 19-bit mangle (L=17) scrambles the 128 KB logical image into a 512 KB served slot.
Total image: 640 KB (firmware 0x0, metadata 0xC000, plugin 0x10000, served 0x20000).
- **Z-Mode** — fourth MODE radio, Fire 32 A only. Ostrich Z-stream protocol (`Z W`/`Z R`, 256-byte blocks) on top of bare Ostrich.
TunerPro works unmodified. EPROM locked to 27C010; serial-port-2 row hidden (serial mode is built into the plugin). 3-line tooltip.
- **Fire 32 A asset set** — `OneROM_Firmware_32.bin` (48 KB), `OneROM_Metadata_32.bin` (16 KB), 7 `usb_emu_system_plugin_*_32.bin`
(NORMAL/DISABLED/ALDL-808/ALDL-inv ×3/OSTRICH_Z).
- **Metadata patch** — chip-type byte 0x0F and ASCII `"27C010"` written at `0xC128`/`0xC112` from the user's `RomType` selection.
- **Mode selection** — Standard/ALDL/Hts unchanged for Fire 28; Z-Mode appears in the row only when `rom_type == C010`.
Hts still locks to 27C256; Z-Mode locks to 27C010.
- **`build.rs` emits `assets.md`** — auto-generated selection table (firmware/metadata/plugin per Mode/cdc2/rom_type/inversion, with COM
port 2 baud rate) is written next to the binary on every build.
- **Mangle extended to L=17** — `mangle`/`demangle`/`detect_dump` now size-dispatch (L=15/16 → 64 KB served, L=17 → 512 KB served).
The byte-exact Fire 28 paths are unchanged.
Code: Select all
=== ASSET SELECTION TABLE ===
Auto-generated by build.rs on every build. Lists exactly which file in
assets/ (or assets/plugins/32/) is embedded for every UI selection,
together with the COM-port-2 baud rate the plugin drives.
--- Firmware + Metadata ---
+----------+------------------------------------------+------------------------------------------+
| rom_type | Firmware | Metadata |
+----------+------------------------------------------+------------------------------------------+
| C256 | assets/base_firmware.bin | assets/metadata.bin |
| C512 | assets/base_firmware.bin | assets/metadata.bin |
| C010 | assets/plugins/32/OneROM_Firmware_32.bin | assets/plugins/32/OneROM_Metadata_32.bin |
+----------+------------------------------------------+------------------------------------------+
--- Plugin - Fire 28 (C256 / C512) ---
+-----------+----------+-----------+------------+-----------------------------------+
| Mode (UI) | cdc2 | Inversion | COM port 2 | Plugin asset |
+-----------+----------+-----------+------------+-----------------------------------+
| Standard | DISABLED | - | - | assets/plugins/disabled.bin |
| Standard | NORMAL | - | 38400 8N1 | assets/plugins/normal.bin |
| Aldl | Aldl | none | 8192 8N1 | assets/plugins/aldl.bin |
| Aldl | Aldl | RX | 8192 8N1 | assets/plugins/aldl_rx_inv.bin |
| Aldl | Aldl | TX | 8192 8N1 | assets/plugins/aldl_tx_inv.bin |
| Aldl | Aldl | RX+TX | 8192 8N1 | assets/plugins/aldl_tx+rx_inv.bin |
| Hts | Hts | - | 38400 8N1 | assets/plugins/hts.bin |
+-----------+----------+-----------+------------+-----------------------------------+
--- Plugin - Fire 32 A (C010) ---
+-----------+----------+-----------+------------+------------------------------------------------------------------+
| Mode (UI) | cdc2 | Inversion | COM port 2 | Plugin asset |
+-----------+----------+-----------+------------+------------------------------------------------------------------+
| Standard | DISABLED | - | - | assets/plugins/32/usb_emu_system_plugin_DISABLED_32.bin |
| Standard | NORMAL | - | 38400 8N1 | assets/plugins/32/usb_emu_system_plugin_NORMAL_32.bin |
| Aldl | Aldl | none | 8192 8N1 | assets/plugins/32/usb_emu_system_plugin_ALDL_808_32.bin |
| Aldl | Aldl | RX | 8192 8N1 | assets/plugins/32/usb_emu_system_plugin_ALDL_808_RX_Inv_32.bin |
| Aldl | Aldl | TX | 8192 8N1 | assets/plugins/32/usb_emu_system_plugin_ALDL_808_TX_Inv_32.bin |
| Aldl | Aldl | RX+TX | 8192 8N1 | assets/plugins/32/usb_emu_system_plugin_ALDL_808_TXRX_Inv_32.bin |
| Z-Mode | Hts | - | 38400 8N1 | assets/plugins/32/usb_emu_system_plugin_OSTRICH_Z_32.bin |
+-----------+----------+-----------+------------+------------------------------------------------------------------+
--- Decorative (mode-independent) ---
+----------------------------+------------------------------+
| Slot | Asset |
+----------------------------+------------------------------+
| Settings panel graphic | assets/emu.png |
| Window/taskbar icon | assets/emu_title.png |
| About -> "One ROM Licence" | assets/onerom_license.md |
| About -> "EMU Licence" | assets/flashtool_license.txt |
+----------------------------+------------------------------+
Every row above is reachable from the current UI. No orphans.
You do not have the required permissions to view the files attached to this post.
-
themr.m
- Posts: 18
- Joined: Sun Jul 05, 2026 6:42 am
- cars: EK3
Re: OneROM
It is possible to add one mode equally to MODE: Standard but the Vendor ID is 0x01, so it can support one more software.