E78 Kernel and Hardware

E38 E92 and many others. Approximately 2007 and newer
fl0wl0w
Posts: 32
Joined: Thu Jun 21, 2018 4:44 pm
cars: L83/8L90 swapped 2013 W204 Mercedes, 1986 LS3 Swapped BMW E30, 1995 LS swapped GMC Truck, Custom Vehicle

E78 Kernel and Hardware

Post by fl0wl0w »

I thought I would start a new thread for this since there is not much information here about E78. I shared some of my kernel endeavors about E92 on another thread, but I am transitioning my focus to E78 because the hardware fits my goals better and is a bit easier to chew on than the E92.

The Hardware
  • The E78 ECM uses an MPC5566 MCU from NXP/Freescale.
  • It also has a companion ASIC that does some voltage level translation, input/output protection, and an external watchdog. So far I don't see any evidence that this has its own firmware image like the E38 does with it's slave MCU. I don't have any SPS tools to try and see what it is doing or grab its kernel to verify. I am keeping my efforts away from any other tools.
  • The hardware does differ slightly between the V8 version and the Inline 4 version. The Inline 4 version only populates 4 injector drivers and only 2 O2 sensor heater drivers (1 bank). That is what is obvious, I have not looked to see if the ignition outputs are missing any series resistors or anything else. Hoping those are the only differences. There are a bunch of low side drivers that are identical to the Injector drivers (This will be important later). There are at least 20 low side drivers in the Inline 4 hardware and 24 with V8 hardware.
  • Looking at the firmware bin that I currently have. There are a few hardware revision bits. One of the bits controls subtracting an offset from the ADC. The other bits control changing a couple pins. I think those are actually enabling/disabling a console output, but have not looked further.
The Kernel
So far I have created a functioning read Kernel for E78. I have not worked up the courage to do a write to flash, but that will happen soon since I saved off my shadow password and can bootpin into a recovery when I inevitably brick it. I have written to RAM from kernel and that works fine. I have not integrated interrupts in the Kernel like I did for E92 and I am just letting the gm bootloader service the eMIOS interrupt which keeps the watchdogs happy. I will have to move everything over to read kernel if I want to write to bootloader flash (I think failing to do this is why so many people have accidentally bricked their ECMs when trying to implement writing to flash). The kernel implements actual UDS rather than the GM flavor. It also implements LZ4 compression which just about doubles the transfer rate.
https://github.com/FL0WL0W/KernelMPC5566

The Tool
I am using my own tool to load the kernel. It is ESP32C6 hardware I designed for some can translation stuff that I am using because it's what I have available. The code is kind of a scratchpad at the moment depending on which ECU i am working on, but it will get a UI and some usability improvements in the future. Think WiFi webpage UI where you don't have to install any software on your machine. (I know this will likely trigger members who don't think WiFi/Bluetooth is reliable enough for a flashing tool, but all the ECU communication stuff is done on the ESP32 in C and not up in Javascript) I might port it over to the meatpi wican module or make my own hardware that also supports VPW and other stuff. I know this is a barrier to entry for a lot of fellow members with their J2534 passthrough. If you want to take the kernel and implement the tool side in PCMHammer or something open source that is fine by me.
https://github.com/FL0WL0W/ESP32-ECU-Flasher

The Goal
My actual goal is to port over the rest of my EmbeddedIOServices repository so I can write applications to run on the ECM. This could pretty much be anything. I.E. CAN Translator, CAN Expander, Boost or Nitrous controller, Injector flow rate tester, IOT light switch, etc. My initial goal of course will be to get EFIGenie running. I have used EFIGenie for a few things already. It runs a CAN translator in my Mercedes to translate the car to L83. It runs a CAN expander in my Factor Five GTM to translate the E38 can messages to the analog gauges. It has even run an LS4 engine. There is also no reason it can't run any engine as long as you write the Crank/Cam decoder for it. Since the E78 hardware has a bunch of low side drivers, There is also no reason even the Inline 4 hardware couldn't run a V8 engine, or even more cylinders. Also the WiFi tool starts to make more sense because the EFIGenie configuration software is a web app. The entire suite can be packaged up into a single tool without having to install any software and can run on any device (Linux, Windows, Android, Iphone, etc.)
https://github.com/FL0WL0W/EmbeddedIOServices
https://github.com/FL0WL0W/EFIGenie
https://github.com/FL0WL0W/EFIGenieEditor

The Hurdles
  • Implementing the rest of the EmbeddedIOServices is straight forward. The MPC reference manual is very thorough, and using AI should breeze through this task. (It already did for the CAN Service). Even though I am using AI to create the structure, I go through and make modifications and verify what it is doing is correct. It often gets confused or makes silly mistakes and needs a gentle nudge in the right direction. Especially to get it to write code that I am happy with as far as structure and implementation.
  • eTPU is a somewhat complicated beast, but there are tools from NXP that make using it easier. The first iteration will not even use the eTPU. Proper interrupt priority setup should make software scheduling good enough. This is how most aftermarket ECUs operate and I have already demonstrated this works well on less capable microcontrollers. Verified through bench testing using an oscilloscope as well as actually running an engine.
  • Figuring out exactly what the ASIC does. I have figured out enough to keep it happy, but knowing what all of the bits transferred over SPI do will be helpful in integrating all of the functions. I have some theories on what the ASIC does. From E92 we know it acts as an external watchdog. The rest of the bits I think are for either setting direction control for signals and/or enabling 5V reference supplies.
  • MCU pinout. This will be figured out looking at the firmware as well as tracing out signals through the board. There are a ton of test points that make this task easier. Then it will be writing test software to toggle these pins to verify
User avatar
morfi
Posts: 32
Joined: Wed Jan 22, 2025 7:17 pm
cars: Insignia 2014

Re: E78 Kernel and Hardware

Post by morfi »

This is big. I dont have E78 myself (and I'm doing flashing only through J2534) so I won't be able to play around with it but I support it with both my hands for the opensource effort.
Image
Image
Image
fl0wl0w
Posts: 32
Joined: Thu Jun 21, 2018 4:44 pm
cars: L83/8L90 swapped 2013 W204 Mercedes, 1986 LS3 Swapped BMW E30, 1995 LS swapped GMC Truck, Custom Vehicle

Re: E78 Kernel and Hardware

Post by fl0wl0w »

The ASIC has been kicking my ass, but i have found out a bunch in the past week.

Non ASIC SPI discoveries

What I thought was the ASIC with a watchdog before on DSPI-D PCS0 is actually the main power supply chip that is used on a ton of these MPC designs. you have to constantly hit this watchdog or it will reset the processor, that also explains it's 5 VREF outputs and then the IO enable output that goes to the ASIC. For the spark, the ASIC only needed this IO enable signal. probably something to do with the initialization messages that the stock firmware has already loaded onto the ASIC before we loaded our ram application (we will get to that later). All in all this protocol was very basic and easy to copy. I don't think there is anything else unknown about this part.

There is also secondary small MCU that is used for security (I think). I just had AI copy what the stock firmware was doing for now and will come back to learn more about it later. Anyways it has outputs on it to disable injectors and fuel pump. I don't think there was any specific IMMO messages that had to be sent to it (since this is stock firmware that does not have IMMO disabled and it still enabled the injectors on startup). The communication for this lives on DSPI-D PCS1. There is most likely some way to write new firmware to this like there is on E38, but idk if that is required to figure out yet for what i want to do.

There is a SPI going over to the ETC controller as well. I think this is just for status, but it might have an enable or something too. I think there is also enable from the secondary MCU. This is still quite a bit of ways away before i care about making it work.

Non ASIC other discoveries

Ignition outputs for 8 cylinders are missing the series resistors on the 4 cylinder version. I was hoping they would still be on there, but i guess the 1 cent GM saved on each ECU to remove a handful of resistors adds up.

I back tracked a few of the digital inputs to their respective digital pins. I didn't know this before, but the analog pin inputs can only be read as analog on the MPC, So i will have to get that working to map all of those as well. some of the digital inputs go through the ASIC like the cam and crank sensors.

ASIC details

The ASIC is actually common part between E78 and E92. Other ECMs probably use it too, but these are the only 2 i know about right now.

The ASIC has a configuration and diagnostic spi bus that is rather complex with a lot of message. There is an identify message that tells you what revision it is which has very slight change in the setup, but mostly similar. Then there is a main configuration message that transfers a block of about 18 words (36 bytes) over to the ASIC. Then it looks like there are also a few messages the MPC sends over that update these registers and they have a fairly similar structure. There is a sequence of messages that have to be sent, read, resent, on a loop of about 12ms as sort of a keep alive. This was super important because the fuel injector enable pin is actually bi directional and if this keep alive goes away, it will pull this back low. Then there is a diagnostic read message sent every 3ms. Still more work to do to figure out what the structure of the configuration is.

The ASIC also has a 21 bit spi input coming from the MPC using DSPI A and C. the output of C is fed into A. C contributes 16 bits and A contributes 5 bits. I am pretty sure these are for miscellaneous outputs like fuel pump, and slow stuff. It is the fastest SPI operating at about 16mhz and constantly transfers the 21 bits with a cycle time of 2us. So you can still get some decently fast/precise outputs from this. just not as fast and precise as you can get from the discretes controlling the spark and injectors. It may still be good enough for injectors so there is still hope to running a second bank of injectors, but it isn't as straight forward as i originally though.

The ASIC also seems to be the Knock Detector, does something with the O2s, and might do something more with the cam/crank sensors.


Anyways, at this point i have the injector pins and the ignition pins toggling from the kernel. Need to do some code cleanup and organization. Then work on understanding the ASIC protocol more and mapping the high speed spi to the ASIC into it's related outputs.
fl0wl0w
Posts: 32
Joined: Thu Jun 21, 2018 4:44 pm
cars: L83/8L90 swapped 2013 W204 Mercedes, 1986 LS3 Swapped BMW E30, 1995 LS swapped GMC Truck, Custom Vehicle

Re: E78 Kernel and Hardware

Post by fl0wl0w »

Another progress update.

I refactored a lot of stuff to compartmentalize all of the findings and make the code generally more readable. This also makes AI more efficient since it can ignore most files and focus on whatever tasks i give it.

I was able to place the custom firmware on flash and have it executed by the stock bootloader. After booted to the custom firmware application it can reset back to bootloader and load Kernels like normal. It took quite a few tries so i made sure to read out the shadow password before hand so i could use bootmode to flash. I used IOTerminal to burn the firmware to flash because my primary goal is not exactly to make a Read/Write Kernel. However IOTerminal is slow so i will probably add write capabilities to the Kernel soon to speed up firmware iteration cycles. Then release the kernel and start a new repo for the EFIGenie porting.

I have ADC working now and mapped out all of the ADC pins from the connector back to the MPC. All of the O2 sensors pass through the Delphi ASIC and use the eQADC external mux feature to select between them on 2 MPC Analog inputs. By default, bank 1 and 2 sensor 1 are selected. Bank 1/2 sensor 2 has to be selected through the MAx mux pins. Additionally, there are 4 more inputs to the Delphi ASIC that are muxed to 1 MPC Analog input. By default the Clutch/Brake sensor passes through, but there are 3 other pins that are muxed as well. the other 3 are not defined in any pinouts so they are bonus pins. In total we have 29 Analog inputs mapped out. There should be 4 more related to O2 sensor current as well as a couple more for knock sensor diagnostics. The knock sensors go to the Delphi ASIC as well and I think all of the knock detection is packaged into it so that will take a lot of effort if we want to make it work (Not a priority right now).

Next step is to get interrupts working again and hook them up to the DigitalService as well as the TimerService scheduler. Then build the wrapper services to translate pins from the external connectors to MPC pads. Once that is done i should be able to run EFIGenie firmware on it and bench test performance.

I have a V8 E78 ordered and on the way. Mainly so I could get some proper connectors to make a bench setup rather than the individual pins i have hooked up to the E78 right now. I will end up using it to run an engine on EFIGenie for my death kart. The engine already runs on EFIGenie using custom hardware I designed, but reusing OEM hardware with custom firmware is the way of the future. You can buy these OEM ECMs on ebay for cheaper than you can buy the components to build custom hardware.
https://www.youtube.com/watch?v=jJOaTFBkKEE
User avatar
antus
Site Admin
Posts: 10014
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: E78 Kernel and Hardware

Post by antus »

Thanks for posting. I ordered an E78 a couple of weeks ago, still waiting for it to arrive, but am interested to look in to this as well, from the perspective of pcmhammer. Watching with interest.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
fl0wl0w
Posts: 32
Joined: Thu Jun 21, 2018 4:44 pm
cars: L83/8L90 swapped 2013 W204 Mercedes, 1986 LS3 Swapped BMW E30, 1995 LS swapped GMC Truck, Custom Vehicle

Re: E78 Kernel and Hardware

Post by fl0wl0w »

Spent some time and finished the Kernel. It successfully reads, writes, and provides SHA256 hashes for each flash block so you only have to erase and program changed blocks. With LZ4 compression and erase/program queuing, it can write the entire flash with a stock bin file (- the bootloader since the sha256 matches) in about 67 seconds.

I moved all the other test stuff out of the Kernel and moved it to a different repository

Kernel: https://github.com/FL0WL0W/KernelMPC5566
EFIGenieE78: https://github.com/FL0WL0W/EFIGenieE78
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E78 Kernel and Hardware

Post by Xnke »

Picked up a 4 cylinder turbo version of this one today-except that the service number, 4-letter application code, and part number all cross to the Corvette, not the Cruze I pulled it from. Also the connectors are MUCH nicer on the cruze than the other car I pulled the first set of connectors from.

It's out in the garage with the rest of them, or I'd post the numbers tonight. It was half-price day at the pull-a-part yard, so I picked up an E78, two E67s, an E39, another E38, and another T42. I was going to pick up another E38 but I figure two is enough until I brick one.

Didn't find an E40 today, though.