E38 Documentation attempt - Starting from the DTC functions.

E38 E92 and many others. Approximately 2007 and newer
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

I'm working on learning Ghidra and the E38's functions. Starting from the 4088 OS, since that's what is on the two E38's I have.

Initial disassembly has gone well using the information posted here on the forums, and an XDF from UniversalPatcher. I'm using Claude to reason my way through the code, and a spreadsheet I found from the internet of E38 pinouts with main processor pin assignments.

Since the DTC tables are known and the DTC codes they match to are known, that's where I've started. I'm going through the whole DTC and MIL system to work out how and where all the bits work, so that I can re-purpose these PCMs for non-automotive tasks (like generator control where RPM maintenance is the big task, or boat engine control where I have infinite radiator)

Eventually I want to work my way through the whole OS...assuming I don't completely burn out. The goal is to be able to build a new, hardware compatible OS, although some base functions could be borrowed or at least heavily cribbed from.

Right now, I have found and named the following functions: "Process_DTC", the main process handler that starts the whole DTC check process, "Process_DTC_Actions" which acts upon the bits set by "Process_DTC", Update_DTC_RuntimeStatus, which I don't have all worked out but I suspect it's the check function to see how many times the DTC has been flagged or not flagged, to turn on or turn off the MIL, and then "Evaluate_Diagnostic_State" which works with "Process_DTC" to check the 7 possible flagged bits for each DTC, and then feeds "Evaluate_DTC_StatusGroup" which then determines if the DTC needs to trigger things like reduced power, flash the MIL, illuminate steady the MIL, or turn off an already lit MIL.

There's quite a few more that need to be stepped through and mapped before I solidify up the names. Once the MIL behavior chain is well understood, I'm going to use the DTC codes for various sensors to work backwards and map out each sensor from the ADC read through up to the DTC set.
fl0wl0w
Posts: 32
Joined: Thu Jun 21, 2018 4:44 pm
cars: L83/8L90 swapped 2013 W204 Mercedes, 1986 LS3 Swapped BMW E30, 1995 LS swapped GMC Truck, Custom Vehicle

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by fl0wl0w »

Most of us start our de-compilation efforts with mapping OBD2 PIDs and DTC tables. It's a known place to start and work back from and learn the tool and how the code is structured.

Fully mapping out the entire OS is a near impossible feat. AI helps alot, but it is an absurd amount of functions. Most people just focus on their goal and map out just what is needed. Even the big tuning tools leave most of the calibration unmapped. That's why segment swaps are a thing. You will find many calibration parameters that hook up to just odd functions that add 5 here and 6 over there and enable 1 function here and flips a bit there just to find out it's dead code that never gets called from anywhere or is disabled by some other parameter.

For custom OS there are a couple options.
1. You can patch the OS to fit your application, but most patches are just to turn things off or skip over portions of code. For more complex patches you will want to setup a C/C++ toolchain so that you can generate assembly from functions and tweak and add those to the OS.
2. The other option is to setup a C/C++ toolchain and build a completely new OS. This is a lot more difficult than you might expect. Especially if you want as many features as something like the stock GM OS supports. Many have tried and so far I have not seen anyone with a successful from scratch OS. (At least not on modern GM stuff) For one the NXP "SDK" is nothing more than a register map, so don't expect any easy to setup peripherals. There are also a bunch of subsystems that communicate over SPI that have little to no publicly available documentation. And there is also the eTPU which is its own co processor inside the NXP MPC that does all of the realtime heavy lifting.

I am attempting option 2 on an E78 and already have custom code on the flash running some basic programs to develop my HAL so I can run my EFIGenie software package on it. I have CAN, Digital, and Analog all working and am working on Interrupts and Timers next. I did look at the E38 initially, but the 32KB of SRAM i felt was not enough to run my hardware agnostic software. Whatever software someone is looking to run on the E38 will need to be more tightly coupled and memory statically allocated in order to fit everything one might want in an ECU. You can get an E78 with connectors for less than $50 on ebay. Pretty much the same price as an E38. The only downside is there are not cheap engine harnesses like there are for the E38. You can find my repo here https://github.com/FL0WL0W/EFIGenieE78

PS: This may have just been an example, but the generator control could probably be achieved just using the GMW8762 PTO CAN messages.
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

I'm aware that it's a monumental project-and I know I probably won't fully document the whole thing. Really, there's a lot that I won't need to do at all, but only need to get AI to verify someone else's published work.

A lot of the code doesn't need to change-I just need to know things like how to change the number of cylinders, turn off cylinder banks, select specific injection outputs to change injection timing (There are some 90* V4 engines that I want to run for generator service), same for ignition, adding in select-able trigger wheel patterns (May be able to do this one with a set of different patches) and the big one-I want to implement a real speed-density table system, or at least understand the existing virtual VE system enough to build a tuning tool to do better than what I've worked with in HPT. A lot of the old generators and stationary engines are carbed, and swapping to a speed-density system means not needing to plumb in a MAF when the original air cleaner might be the easiest fit.

Another HUGE thing-if I can figure out how to get a class 2 serial line back into the E38 (probably missing the hardware to actually do it...)then it opens up a lot of possibilities. I see E38 PCM's for under $20 on a regular basis, but E67's and even E40's are going for $80-$150+

Maybe I'll get there, maybe I won't. But I'm getting back into playing with these PCM's again, and I'm learning the new tools.
User avatar
antus
Site Admin
Posts: 10013
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by antus »

I know someone who has done generator control software before. Its not much beyond just letting the engine idle with a target rpm and electronic throttle. maybe you need some minor changes to stop it stalling and be happy to wind the throttle out more as load goes up. maybe its closer to a cruise controll application.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

Yes-that is most of it. Basically needs to be able to kick on when the incoming line drops, then the PCM needs to take over and idle it, then bump idle and send a line out to engage the field windings, and be able to catch the engine as it loads up. I've done this with the P66 controllers by abusing the air conditioning code, and it worked but was never really as good as the old mechanical governor and magneto. It still works, but will often get into a loop where it hunts for engine speed when the load varies, and as the engine speed varies and the voltage wobbles, the load wobbles...

Lots of ag engines, fire pump engines, generator engines all basically run at steady state. For me though, the issue is the engine configurations are typically I-6, I-8, or V4, because I'm the "weird engine guy" for my area. I don't goof around with rotaries, though, but mainly due to not wanting to get sucked into playing with the spinning doritos of doom.

I dug into the P66 V6 code here with Charlay86, and then when he didn't have time anymore I dug way into it for a while, until I wrecked the truck and destroyed the engine. If I wanted to play with flashing something that I drive often, I'd do this for the E40 in my Canyon, but I'm looking at upgrading the canyon to a 3.0L V-4 eventually, and if I can get one of these E38's running a V4 generator engine, it'll definitely run the truck.
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

Picked up almost all the sensor inputs now, and am starting to get a good idea of the SRAM arrangement. Next on the list is the CAN and SPI systems, which I fully expect to be a nightmare full of black holes and deep pits.
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

Output of the last few days' work. Might be helpful to someone.

Code: Select all

This file lists every symbol in the Ghidra project that has been given a
real, descriptive name (i.e. everything NOT still sitting at its default
FUN_xxxxxxxx / DAT_xxxxxxxx / thunk_FUN_xxxxxxxx auto-generated name).
Addresses are program-relative hex offsets into the 2MB binary image.

Two notes on naming conventions used throughout:
  - A "Possibly_" prefix means the identification is a strong working
    hypothesis, not fully proven.
  - "Handle_Service_XX_*" names refer to GMLAN/UDS diagnostic Service ID
    handlers (see project summary section 3).

================================================================================
SECTION 1 — NAMED FUNCTIONS (140 total)
================================================================================
Address     Name
--------    ----------------------------------------------------------------
00000100    TrampolineTable_Entry_0
00000344    Initial_R2_R13_Setup
00000450    Init_MMU_And_Cache
000026dc    Verify_Master_Boot_Configuration
00003550    Wait_For_BootHandshakeByte_OrHalt
00008310    Add_Offset_OverflowChecked
00008368    Subtract_Offset_Saturating
000083c4    Check_Value_IsZero
000083fc    Possibly_FlashOp_CompletionCallback_CheckEq1
00008434    Check_Status_Equals_2
0000846c    Check_Status_Equals_1
000084a4    Check_SecondaryStatus_IsZero
000084dc    Check_ThirdStatus_IsZero
00008514    Check_ThirdStatus_Equals_1
0000854c    Check_FourthStatus_IsZero
00008584    Check_FifthStatus_Equals_1
000085bc    Check_SixthStatus_Equals_1
000085f4    Check_FifthStatus_IsZero
0000862c    Check_SeventhStatus_IsZero
00008664    Check_SeventhStatus_Equals_1
0000869c    Check_EighthStatus_Equals_1
000086d4    Check_EighthStatus_Equals_2
0000870c    Check_EighthStatus_IsZero
00008744    Check_SixthStatus_IsZero
0000877c    Check_NinthStatus_Equals_1
000087b4    Check_FifthStatus_Equals_2
000115a4    Update_ByteDelta_Accumulator
00011638    Update_HalfwordSum_Accumulator
000116d8    Update_ByteSum_CheckSum
0001391c    Scale_ToByte_Generic
00013954    Normalize_toByte_0_255
0001495c    Add_u16_saturate
00018a0c    Dispatch_Flash_Operation
00019b88    Clear_FlashController_ActiveBit
00019bb0    ISR_FlashOperation_Complete
00019d24    Possibly_ISR_Secondary
00019dec    Acknowledge_Priority_Condition
00019e30    ISR_MainScheduler_Tick
0001a384    Configure_TouCAN_AB_BitTiming
0001a5a4    Write_TouCAN_MessageBuffer_Entry
0001a80c    Toggle_TouCAN_AB_FreezeMode
000219a0    Compute_Plausibility_Window_16bit
00021a40    Compute_Plausibility_Window_32bit
00021acc    Write_TPU_Channel_CalConfig
00021afc    Reset_TPU_Channel_FuncSelect
00021b20    Clear_TPU_Channel_Field4
00021b3c    Clear_TPU_Channel_FieldC
00021b58    Write_TPU_Channel_FieldA
00021b90    Reset_TPU_Channel_Sequence
00021c6c    Init_TPU_Channel_Full
00022484    Compute_CRC32_FlashVerify_Bare
00022844    Validate_Command_Signature
00022894    Build_Command_Response
0002294c    Dispatch_Command_Packet
00022a70    Check_FlashVerify_Status
00022ae0    Compute_CRC32_FlashVerify
0002de80    Capture_MAF_TPU_B_Channel0_RawPeriod
00030a94    Verify_TouCAN_AB_BitTiming_Config
00037158    ADC_Raw_Counter_Read
00037178    Read_Timer2_Scaled
0003a7f0    Possibly_MAF_Raw_Counter_Read
0003d318    Read_PerCylinder_KnockValue_Template
00046c40    START_HERE_TOMORROW   [NOTE: session bookmark, not a real identification]
00057b64    Configure_TouCAN_AB_DiagnosticMailboxes
0006ad1c    Capture_FreezeFrame_FuelLevel
0006b4a0    Process_APP1_Plausibility
0006b83c    Process_APP2_Plausibility
0006b96c    Process_APP_Correlation
0006db78    Possibly_Build_Comm_Message_Structure
00073448    Poll_GMLAN_Channels_And_Dispatch
0007d884    Evaluate_AFM_CylDeact_DTC_Group
00089380    Update_MIL_Request_Bits
00089428    Evaluate_MIL_Bit_For_Entry
000898f0    Update_DTC_RuntimeStatus
00089944    Process_DTC_Actions
0008a26c    Process_DTC
0008b2ac    Handle_Service_03_ReadDTCs
0008b8b0    Count_TypeAB_DTC_RuntimeBit4
0008cc20    Get_DTC_Gate1
0008cc2c    Process_DTC_Monitor_Readiness
0008d734    Get_DTC_Gate2
0008debc    Handle_Service_04_ClearDTCs
0008df38    Handle_Service_10_DiagnosticSessionControl
0008eb00    Possibly_Airflow_Estimate_MasterValidity
00091a80    Possibly_Airflow_Estimate_OutputFilter
00091de8    Possibly_VE_Airflow_DynamicEstimator
000946f0    Process_FuelComposition_Plausibility
00094988    Capture_FreezeFrame_BARO
000b10d8    Process_OilPressure_Plausibility
000b11ac    Process_OilPressure_LowPressureDuration
000b9adc    Select_CamPhaser_SecondAxis_Input
000be3d8    Capture_FreezeFrame_RawCrankCounter
000c2214    possible_init_reset_state_001
000d9fa0    Capture_FreezeFrame_EGRError
000f2080    Capture_FreezeFrame_PID
000f216c    Create_Or_Update_FreezeFrame_FailureRecord
000f2f0c    Handle_Service_02_FreezeFrameData
000f3b50    Saturating_Float_Int16Conversion
000f426c    Float_Normalize_Clamp_0_1
000f42a4    Normalized_Temp_Sensor_Lookup_Routine
000f4efc    Float_Interpolate_Table_Lookup
000f4ff8    IAT_Curve_Stage2_BoundedLookup
000f5120    Bilinear_Table_Lookup_2Axis
000fd6a4    Possible_O2SLOC_Bitmask
0011952c    Process_Knock_Counters
0011cb90    Calculate_Fuel_Quantity
0011ce20    Possibly_Crank_Period_Rate_Calc
0012209c    Capture_FreezeFrame_MAF
00130680    Process_Misfire_Detection
0013681c    Handle_Service_01_ShowCurrentData
00137418    Handle_Service_22_ReadDataByIdentifier
0013798c    Handle_Service_2C_DynamicallyDefineDataID
00138b04    Lookup_PID_DispatchTable_Index
0013b170    Handle_Service_34_RequestDownload
0013b588    Handle_Service_27_SecurityAccess
0013cca4    Handle_Service_3E_TesterPresent
0013cdb0    Send_Diagnostic_NegativeResponse
0013d174    Lookup_GMLAN_Service_Index
0013d1e8    Dispatch_GMLAN_Service_Request
0013d2b4    Dispatch_GMLAN_Request_Channel
00144690    Capture_FreezeFrame_O2S_B1S1
001446f0    Capture_FreezeFrame_O2S_B1S2
00144734    Capture_FreezeFrame_O2S_B2S1
00144794    Capture_FreezeFrame_O2S_B2S2
00145da0    Write_Uint16_As_2BigEndian
0014d26c    Trigger_CamPhaser_ExtendedFailureRecord
0014d3b4    CamPhaser_Control_And_Plausibility
00154d94    Capture_FreezeFrame_Ignition1Voltage
001629c0    Capture_FreezeFrame_SparkAdv
00167594    Possibly_Crank_RPM_Timing_Window
00168608    Possibly_Crank_Event_Cluster_Calc
00170ec0    Process_EOT_TFT_Duration
00180198    Possibly_Capture_TAC_ExtendedFailureRecord
0018106c    Capture_Extra_FreezeFrame_Specific_DTC
00184080    Process_TAC_Plausibility
0018614c    Capture_FreezeFrame_TP
00186190    Capture_FreezeFrame_CommandedEGR
00196794    Capture_FreezeFrame_VSS
00197a80    Evaluate_Diagnostic_State
003fe800    BootBlock_RamTemplate_Dest

================================================================================
SECTION 2 — NAMED GLOBAL DATA / REGISTER LABELS (130 total)
================================================================================
Address     Name                                        Size    Xrefs
--------    ------------------------------------------  ------  -----
003f81e4    runtime_status                               1 B    144
003f84ec    DAT_DTC_MasterEnable                         1 B    5
00240c14    DAT_DTC_Gate2Flag                            1 B    5
003fcbd9    DAT_DTC_SuspendFlag                          1 B    123
00240e34    ECT_Value                                    2 B    10
003fe12c    IAT_Value                                    2 B    9
0024173a    RPM_Raw                                      2 B    13
0024173e    RPM_Active                                   2 B    277
00241728    RPM_SyncFlag                                 1 B    7
003fce30    MAP_Raw                                       2 B    5
003fce24    MAP_Active                                    2 B    50
003f9df4    System_Checksum_Accumulator                  2 B    324
00240c94    VE_Estimate_Accumulator_1                    4 B    4
00240d18    VE_Estimate_Accumulator_2                    4 B    4
00240c78    VE_TableSelector_Index                       2 B    16
00240d5c    VE_Estimator_ModeFlag                        1 B    4
003fdba2    VE_Estimator_EnableFlag                      1 B    11
00240d44    VE_Estimator_Counter                         2 B    6
003fd14c    MAF_Value                                    4 B    15
003fca74    VE_DebounceFlag_A                            1 B    19
003fca75    VE_DebounceFlag_B                            1 B    12
00240d04    VE_Debounce_Counter_1                        2 B    5
00240cea    VE_Debounce_Counter_2                        2 B    5
00240ca0    VE_State_Compare_A                           2 B    5
003fdba0    VE_Reference_Compare_Value                   2 B    22
00240cdc    VE_LastValue_Compare                         2 B    3
00240c64    VE_Plausibility_Flag                         1 B    5
00240cc0    VE_History_Value_0                           4 B    3
00240cc4    VE_History_Value_1                           4 B    3
00240cc8    VE_History_Value_2                           4 B    2
00240cbc    VE_History_Source_Extra                      4 B    5
00240ce4    VE_Compare_Value_B                           4 B    3
00240c91    VE_PlausibilityFlag_1                        1 B    3
00240c92    VE_PlausibilityFlag_2                        1 B    3
00240c98    VE_Estimate_MatureFlag                       1 B    5
00240c61    VE_DebounceCounter1_CompareFlag               1 B    5
003fd15c    MAF_Counter_Previous_1                       2 B    2
003fd15e    MAF_Counter_Previous_2                       2 B    2
00240c3e    Airflow_Estimate_CompoundValidityFlag        1 B    2
00240c3f    Airflow_Estimate_FinalGoFlag                 1 B    4
00240c5d    Airflow_Estimate_SecondaryFlag                1 B    4
00240c7c    Airflow_Estimate_Fresh_Value1                4 B    7
00240c80    Airflow_Estimate_Fresh_Value2                4 B    8
00240c68    Airflow_Estimate_Final1                      4 B    6
00240c6c    Airflow_Estimate_Final2                      4 B    7
003fc8e4    Possibly_Engine_RunState_Mode                2 B    86
003fe122    Possibly_Widely_Used_Temperature_Proxy       2 B    71
003fcb98    VSS_Value                                    2 B    3
003fe406    SparkAdvance_Value                           2 B    16
003fc82e    TP_Value                                     2 B    11
003fe102    BARO_Value                                   2 B    4
003fc8be    O2S_B1S1_Voltage                              2 B    35
003fc8c0    O2S_B1S2_Voltage                              2 B    3
003fc8c4    O2S_B2S1_Voltage                              2 B    15
003fc8c6    O2S_B2S2_Voltage                              2 B    3
003fca7e    O2S_B1_TrimRelated                            2 B    8
003fca80    O2S_B2_TrimRelated                            2 B    6
003fcbd2    Ignition1Voltage_Value                        2 B    69
0024287a    Knock_Bank1_Counter                          1 B    5
0024287b    Knock_Bank2_Counter                          1 B    6
00243868    Knock_RuntimeGateFlag                        1 B    40
003fa0b0    Knock_MasterEnable_Flag                       2 B    14
003fa0b6    Knock_PerCylinder_Value_Array                2 B    9
003fb432    Knock_PerCylinder_Reset_Array                2 B    6
003fe5e6    APP1_Value                                   2 B    7
0024291a    APP1_Value_Alt                                2 B    4
003fe5e8    APP2_Value                                   2 B    7
0024291c    APP2_Value_Alt                                2 B    4
003fe5ea    APP1_Correlation_Value                        2 B    7
003fe5ec    APP2_Correlation_Value                        2 B    7
003fe5d4    APP_Correlation_DynamicLimit                  2 B    3
002413ca    OilPressure_Value                             2 B    7
002413e2    OilPressure_LowPressureAccumulator            2 B    5
00243b74    EOT_TFT_DurationAccumulator                  2 B    6
00243b84    EOT_TFT_CompareValue                          2 B    10
00243b8c    EOT_TFT_CompareValue_Long                     4 B    5
003fe5fa    FuelLevel_Value                               2 B    3
003f88a8    EGRError_Value                                2 B    27
00241729    Possibly_Secondary_Sync_Flag                  1 B    9
003fd78c    Possibly_Crank_Period_Rate_Output             4 B    8
0040d164    Possibly_Timing_Mode_Selector                 ?      0
0040d19e    Possibly_Timing_SmoothedValue                 ?      0
0040d179    Possibly_Timing_OutputFlag                    ?      0
003fcef4    Possibly_Timing_Threshold                     2 B    23
00243a66    Possibly_Crank_Event_0                        2 B    5
00243a68    Possibly_Crank_Event_1                        2 B    3
00243a6a    Possibly_Crank_Event_2                        2 B    1
00243a6c    Possibly_Crank_Event_3                        2 B    3
00243a6e    Possibly_Crank_Event_4                        2 B    5
00242bb4    Possibly_Misfire_StateMode                    2 B    11
00242c33    Possibly_Misfire_NewEventFlag                 1 B    6
00242c34    Possibly_Misfire_ConditionFlag                1 B    5
00242c10    Possibly_Misfire_CountThreshold                1 B    8
00243524    CamPhase_Estimate_Array                       4 B    4
00243610    CamPhaser_Counter_Array                       2 B    7
00243620    CamPhaser_RecordedFlag_Array                  1 B    2
0040d550    Possibly_CamPhaser_SecondInput                ?      0
0024360c    CamPhaser_DisableFlag_Array                   ?      2
003fd78c    Timing_Rate_3                                  4 B    8   [alias of Possibly_Crank_Period_Rate_Output - same address]
0040d7b0    FuelQuantity_Output                           ?      0
003fcb76    Possibly_FuelCalc_SecondInput                 2 B    174
003fd784    Timing_Rate_1                                  4 B    13
003fd788    Timing_Rate_2                                  4 B    9
0024035e    CommStruct_Field_Base                         2 B    3
003fa35c    CRC32_BootBlock_Result                        4 B    3
003fa360    CRC32_OS_FirstBlock_Result                    4 B    3
003fa358    FlashVerify_StatusFlag1                       1 B    2
003fa359    FlashVerify_StatusFlag2                       1 B    2
003fa34c    CommandDispatch_PacketPtr                     4 B    6
003fa348    CommandDispatch_ResponsePtr                   4 B    8
003fa356    TPU_Channel_SharedBaseValue                   2 B    3
00304500    TPU_Channel_ConfigBlock_Base                  ?      3
00304400    TPU_Channel_ControlReg_Base                   ?      97
00304418    TPU_StatusPoll_Register                       ?      84
0030450e    TPU_Channel_StatusReadback                    ?      4
00305180    FlashController_ConfigBlock                   ?      40
003fa364    CommandDispatch_Table                         ?      1
003fb260    FlashOp_BusyState                             2 B    69
003fb262    FlashOp_PendingMask                           2 B    158
003fb264    FlashOp_CallbackPtr                           4 B    15
003fa084    SchedulerISR_StateVar                          2 B    8
003fa4c0    Scheduler_ActiveTasksMask                     4 B    38
003fa55c    Scheduler_TaskExecutionCounters               2 B    19
003fe814    Possibly_MMU_FeatureFlag                       2 B    4
003fe818    BootBlock_BSS_Start                            4 B    2
003fe812    Possibly_BootFeatureFlag_2                     2 B    4
00307080    TouCAN_A_MCR                                  ?      19
00307480    TouCAN_B_MCR                                  ?      19
00307100    TouCAN_A_MessageBuffers                       ?      0
00307500    TouCAN_B_MessageBuffers                       ?      0

================================================================================
SECTION 3 — PHYSICAL PIN <-> CONFIRMED HARDWARE ADDRESS CROSS-REFERENCE
================================================================================
This is NOT a full pinout (see the CSV files for that — every physical pin's
wire/circuit/MCU-port assignment is documented there). This section lists
ONLY the pins where a specific memory-mapped register or capture location
has actually been traced and confirmed in the disassembly. This list is
intentionally short — most physical pins have a known MCU port label
(e.g. "B_AN51", "A_TPUCH8") from the pinout CSVs but have NOT yet been
correlated to a specific hex address in code.

Connector/Pin   Function                          MCU Port     Confirmed Address   Notes
-------------   --------------------------------  -----------  -----------------   -----
X1 Pin 41       MAF Sensor Signal                 B_TPUCH0     00304504            Raw period capture register, read by Capture_MAF_TPU_B_Channel0_RawPeriod (0002de80)
X1 Pin 40       Fuel Composition Sensor Signal     B_TPUCH6     NOT YET FOUND       Confirmed target channel; register not yet located. (FlexFuel, not populated in US wiring harnesses. See project summary item 6.)
X1 Pin 27       High Speed GMLAN Serial Data (-)   GMHS-L       00307080 (TouCAN_A_MCR)   Via TouCAN A/B controllers, not a
X1 Pin 28       High Speed GMLAN Serial Data (+)   GMHS-H       00307480 (TouCAN_B_MCR)   direct 1:1 pin-to-register mapping. 00307100/00307500 (message buffers)

Known but NOT yet traced to a specific address (targets for future work):
  - X1 Pin 71   Vehicle Speed Sensor (VSS) High    B_TPUCH1/2   -- (VSS_Value's filter chain traced back to FUN_00173a64 cluster; true raw HW register not reached)
  - X2 Pin 68   CKP Sensor Signal                  A_TPUCH1/2   -- (TPU-A, not yet investigated)
  - X2 Pin 62   CMP Sensor B Signal                A_TPUCH7     -- (TPU-A, not yet investigated)
  - X2 Pin 64   CMP Sensor A Signal                A_TPUCH8     -- (TPU-A, not yet investigated)
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

Got my universal plug OBD2 bench harness built and working today. Using the OBDX Pro VX, I have connected to and read out the flash from my two E38 PCMs, but I think they both have the same OS and report as being a Pontiac file...but one was pulled from a 2008 Malibu 3500 V6 and the other was pulled from a 2007 Silverado 6.0L V8.

I also have a P12 from a Trailblazer 4.2L I6, an E67 from a Trailblazer 4.2L I6, and an E78 from a 2014 Chevy Trax to play with, although I need to find another blue plug for the E67 before I can play with that one.
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

Currently finishing up the last onboard flash routines. Hunted down all the voltage sensing inputs, traced out all the voltage-gated/locked functions, like reflash lockouts.

Looking into the possibility of using the internal RAM-To-Flash functions, combined with RAM injection, to do live tuning.
Xnke
Posts: 59
Joined: Thu Sep 24, 2015 3:42 am

Re: E38 Documentation attempt - Starting from the DTC functions.

Post by Xnke »

The factory test-mode gate is triggered by presenting wide-open-throttle on both throttle position sensors, pedal-at-rest on both APP sensors, and normal ignition voltage — on X1 pins 19, 29, 32 and X2 pins 58, 63, 65. That will enable the factory test mode-of what that does, I am not sure what all will go on when you get into that mode.