I'm working on learning Ghidra and the E38's functions. Starting from the 4088 OS, since that's what is on the two E38's I have.
Initial disassembly has gone well using the information posted here on the forums, and an XDF from UniversalPatcher. I'm using Claude to reason my way through the code, and a spreadsheet I found from the internet of E38 pinouts with main processor pin assignments.
Since the DTC tables are known and the DTC codes they match to are known, that's where I've started. I'm going through the whole DTC and MIL system to work out how and where all the bits work, so that I can re-purpose these PCMs for non-automotive tasks (like generator control where RPM maintenance is the big task, or boat engine control where I have infinite radiator)
Eventually I want to work my way through the whole OS...assuming I don't completely burn out. The goal is to be able to build a new, hardware compatible OS, although some base functions could be borrowed or at least heavily cribbed from.
Right now, I have found and named the following functions: "Process_DTC", the main process handler that starts the whole DTC check process, "Process_DTC_Actions" which acts upon the bits set by "Process_DTC", Update_DTC_RuntimeStatus, which I don't have all worked out but I suspect it's the check function to see how many times the DTC has been flagged or not flagged, to turn on or turn off the MIL, and then "Evaluate_Diagnostic_State" which works with "Process_DTC" to check the 7 possible flagged bits for each DTC, and then feeds "Evaluate_DTC_StatusGroup" which then determines if the DTC needs to trigger things like reduced power, flash the MIL, illuminate steady the MIL, or turn off an already lit MIL.
There's quite a few more that need to be stepped through and mapped before I solidify up the names. Once the MIL behavior chain is well understood, I'm going to use the DTC codes for various sensors to work backwards and map out each sensor from the ADC read through up to the DTC set.
E38 Documentation attempt - Starting from the DTC functions.
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
-
fl0wl0w
- Posts: 32
- Joined: Thu Jun 21, 2018 4:44 pm
- cars: L83/8L90 swapped 2013 W204 Mercedes, 1986 LS3 Swapped BMW E30, 1995 LS swapped GMC Truck, Custom Vehicle
Re: E38 Documentation attempt - Starting from the DTC functions.
Most of us start our de-compilation efforts with mapping OBD2 PIDs and DTC tables. It's a known place to start and work back from and learn the tool and how the code is structured.
Fully mapping out the entire OS is a near impossible feat. AI helps alot, but it is an absurd amount of functions. Most people just focus on their goal and map out just what is needed. Even the big tuning tools leave most of the calibration unmapped. That's why segment swaps are a thing. You will find many calibration parameters that hook up to just odd functions that add 5 here and 6 over there and enable 1 function here and flips a bit there just to find out it's dead code that never gets called from anywhere or is disabled by some other parameter.
For custom OS there are a couple options.
1. You can patch the OS to fit your application, but most patches are just to turn things off or skip over portions of code. For more complex patches you will want to setup a C/C++ toolchain so that you can generate assembly from functions and tweak and add those to the OS.
2. The other option is to setup a C/C++ toolchain and build a completely new OS. This is a lot more difficult than you might expect. Especially if you want as many features as something like the stock GM OS supports. Many have tried and so far I have not seen anyone with a successful from scratch OS. (At least not on modern GM stuff) For one the NXP "SDK" is nothing more than a register map, so don't expect any easy to setup peripherals. There are also a bunch of subsystems that communicate over SPI that have little to no publicly available documentation. And there is also the eTPU which is its own co processor inside the NXP MPC that does all of the realtime heavy lifting.
I am attempting option 2 on an E78 and already have custom code on the flash running some basic programs to develop my HAL so I can run my EFIGenie software package on it. I have CAN, Digital, and Analog all working and am working on Interrupts and Timers next. I did look at the E38 initially, but the 32KB of SRAM i felt was not enough to run my hardware agnostic software. Whatever software someone is looking to run on the E38 will need to be more tightly coupled and memory statically allocated in order to fit everything one might want in an ECU. You can get an E78 with connectors for less than $50 on ebay. Pretty much the same price as an E38. The only downside is there are not cheap engine harnesses like there are for the E38. You can find my repo here https://github.com/FL0WL0W/EFIGenieE78
PS: This may have just been an example, but the generator control could probably be achieved just using the GMW8762 PTO CAN messages.
Fully mapping out the entire OS is a near impossible feat. AI helps alot, but it is an absurd amount of functions. Most people just focus on their goal and map out just what is needed. Even the big tuning tools leave most of the calibration unmapped. That's why segment swaps are a thing. You will find many calibration parameters that hook up to just odd functions that add 5 here and 6 over there and enable 1 function here and flips a bit there just to find out it's dead code that never gets called from anywhere or is disabled by some other parameter.
For custom OS there are a couple options.
1. You can patch the OS to fit your application, but most patches are just to turn things off or skip over portions of code. For more complex patches you will want to setup a C/C++ toolchain so that you can generate assembly from functions and tweak and add those to the OS.
2. The other option is to setup a C/C++ toolchain and build a completely new OS. This is a lot more difficult than you might expect. Especially if you want as many features as something like the stock GM OS supports. Many have tried and so far I have not seen anyone with a successful from scratch OS. (At least not on modern GM stuff) For one the NXP "SDK" is nothing more than a register map, so don't expect any easy to setup peripherals. There are also a bunch of subsystems that communicate over SPI that have little to no publicly available documentation. And there is also the eTPU which is its own co processor inside the NXP MPC that does all of the realtime heavy lifting.
I am attempting option 2 on an E78 and already have custom code on the flash running some basic programs to develop my HAL so I can run my EFIGenie software package on it. I have CAN, Digital, and Analog all working and am working on Interrupts and Timers next. I did look at the E38 initially, but the 32KB of SRAM i felt was not enough to run my hardware agnostic software. Whatever software someone is looking to run on the E38 will need to be more tightly coupled and memory statically allocated in order to fit everything one might want in an ECU. You can get an E78 with connectors for less than $50 on ebay. Pretty much the same price as an E38. The only downside is there are not cheap engine harnesses like there are for the E38. You can find my repo here https://github.com/FL0WL0W/EFIGenieE78
PS: This may have just been an example, but the generator control could probably be achieved just using the GMW8762 PTO CAN messages.
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
Re: E38 Documentation attempt - Starting from the DTC functions.
I'm aware that it's a monumental project-and I know I probably won't fully document the whole thing. Really, there's a lot that I won't need to do at all, but only need to get AI to verify someone else's published work.
A lot of the code doesn't need to change-I just need to know things like how to change the number of cylinders, turn off cylinder banks, select specific injection outputs to change injection timing (There are some 90* V4 engines that I want to run for generator service), same for ignition, adding in select-able trigger wheel patterns (May be able to do this one with a set of different patches) and the big one-I want to implement a real speed-density table system, or at least understand the existing virtual VE system enough to build a tuning tool to do better than what I've worked with in HPT. A lot of the old generators and stationary engines are carbed, and swapping to a speed-density system means not needing to plumb in a MAF when the original air cleaner might be the easiest fit.
Another HUGE thing-if I can figure out how to get a class 2 serial line back into the E38 (probably missing the hardware to actually do it...)then it opens up a lot of possibilities. I see E38 PCM's for under $20 on a regular basis, but E67's and even E40's are going for $80-$150+
Maybe I'll get there, maybe I won't. But I'm getting back into playing with these PCM's again, and I'm learning the new tools.
A lot of the code doesn't need to change-I just need to know things like how to change the number of cylinders, turn off cylinder banks, select specific injection outputs to change injection timing (There are some 90* V4 engines that I want to run for generator service), same for ignition, adding in select-able trigger wheel patterns (May be able to do this one with a set of different patches) and the big one-I want to implement a real speed-density table system, or at least understand the existing virtual VE system enough to build a tuning tool to do better than what I've worked with in HPT. A lot of the old generators and stationary engines are carbed, and swapping to a speed-density system means not needing to plumb in a MAF when the original air cleaner might be the easiest fit.
Another HUGE thing-if I can figure out how to get a class 2 serial line back into the E38 (probably missing the hardware to actually do it...)then it opens up a lot of possibilities. I see E38 PCM's for under $20 on a regular basis, but E67's and even E40's are going for $80-$150+
Maybe I'll get there, maybe I won't. But I'm getting back into playing with these PCM's again, and I'm learning the new tools.
-
antus
- Site Admin
- Posts: 10014
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: E38 Documentation attempt - Starting from the DTC functions.
I know someone who has done generator control software before. Its not much beyond just letting the engine idle with a target rpm and electronic throttle. maybe you need some minor changes to stop it stalling and be happy to wind the throttle out more as load goes up. maybe its closer to a cruise controll application.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
Re: E38 Documentation attempt - Starting from the DTC functions.
Yes-that is most of it. Basically needs to be able to kick on when the incoming line drops, then the PCM needs to take over and idle it, then bump idle and send a line out to engage the field windings, and be able to catch the engine as it loads up. I've done this with the P66 controllers by abusing the air conditioning code, and it worked but was never really as good as the old mechanical governor and magneto. It still works, but will often get into a loop where it hunts for engine speed when the load varies, and as the engine speed varies and the voltage wobbles, the load wobbles...
Lots of ag engines, fire pump engines, generator engines all basically run at steady state. For me though, the issue is the engine configurations are typically I-6, I-8, or V4, because I'm the "weird engine guy" for my area. I don't goof around with rotaries, though, but mainly due to not wanting to get sucked into playing with the spinning doritos of doom.
I dug into the P66 V6 code here with Charlay86, and then when he didn't have time anymore I dug way into it for a while, until I wrecked the truck and destroyed the engine. If I wanted to play with flashing something that I drive often, I'd do this for the E40 in my Canyon, but I'm looking at upgrading the canyon to a 3.0L V-4 eventually, and if I can get one of these E38's running a V4 generator engine, it'll definitely run the truck.
Lots of ag engines, fire pump engines, generator engines all basically run at steady state. For me though, the issue is the engine configurations are typically I-6, I-8, or V4, because I'm the "weird engine guy" for my area. I don't goof around with rotaries, though, but mainly due to not wanting to get sucked into playing with the spinning doritos of doom.
I dug into the P66 V6 code here with Charlay86, and then when he didn't have time anymore I dug way into it for a while, until I wrecked the truck and destroyed the engine. If I wanted to play with flashing something that I drive often, I'd do this for the E40 in my Canyon, but I'm looking at upgrading the canyon to a 3.0L V-4 eventually, and if I can get one of these E38's running a V4 generator engine, it'll definitely run the truck.
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
Re: E38 Documentation attempt - Starting from the DTC functions.
Picked up almost all the sensor inputs now, and am starting to get a good idea of the SRAM arrangement. Next on the list is the CAN and SPI systems, which I fully expect to be a nightmare full of black holes and deep pits.
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
Re: E38 Documentation attempt - Starting from the DTC functions.
Output of the last few days' work. Might be helpful to someone.
Code: Select all
This file lists every symbol in the Ghidra project that has been given a
real, descriptive name (i.e. everything NOT still sitting at its default
FUN_xxxxxxxx / DAT_xxxxxxxx / thunk_FUN_xxxxxxxx auto-generated name).
Addresses are program-relative hex offsets into the 2MB binary image.
Two notes on naming conventions used throughout:
- A "Possibly_" prefix means the identification is a strong working
hypothesis, not fully proven.
- "Handle_Service_XX_*" names refer to GMLAN/UDS diagnostic Service ID
handlers (see project summary section 3).
================================================================================
SECTION 1 — NAMED FUNCTIONS (140 total)
================================================================================
Address Name
-------- ----------------------------------------------------------------
00000100 TrampolineTable_Entry_0
00000344 Initial_R2_R13_Setup
00000450 Init_MMU_And_Cache
000026dc Verify_Master_Boot_Configuration
00003550 Wait_For_BootHandshakeByte_OrHalt
00008310 Add_Offset_OverflowChecked
00008368 Subtract_Offset_Saturating
000083c4 Check_Value_IsZero
000083fc Possibly_FlashOp_CompletionCallback_CheckEq1
00008434 Check_Status_Equals_2
0000846c Check_Status_Equals_1
000084a4 Check_SecondaryStatus_IsZero
000084dc Check_ThirdStatus_IsZero
00008514 Check_ThirdStatus_Equals_1
0000854c Check_FourthStatus_IsZero
00008584 Check_FifthStatus_Equals_1
000085bc Check_SixthStatus_Equals_1
000085f4 Check_FifthStatus_IsZero
0000862c Check_SeventhStatus_IsZero
00008664 Check_SeventhStatus_Equals_1
0000869c Check_EighthStatus_Equals_1
000086d4 Check_EighthStatus_Equals_2
0000870c Check_EighthStatus_IsZero
00008744 Check_SixthStatus_IsZero
0000877c Check_NinthStatus_Equals_1
000087b4 Check_FifthStatus_Equals_2
000115a4 Update_ByteDelta_Accumulator
00011638 Update_HalfwordSum_Accumulator
000116d8 Update_ByteSum_CheckSum
0001391c Scale_ToByte_Generic
00013954 Normalize_toByte_0_255
0001495c Add_u16_saturate
00018a0c Dispatch_Flash_Operation
00019b88 Clear_FlashController_ActiveBit
00019bb0 ISR_FlashOperation_Complete
00019d24 Possibly_ISR_Secondary
00019dec Acknowledge_Priority_Condition
00019e30 ISR_MainScheduler_Tick
0001a384 Configure_TouCAN_AB_BitTiming
0001a5a4 Write_TouCAN_MessageBuffer_Entry
0001a80c Toggle_TouCAN_AB_FreezeMode
000219a0 Compute_Plausibility_Window_16bit
00021a40 Compute_Plausibility_Window_32bit
00021acc Write_TPU_Channel_CalConfig
00021afc Reset_TPU_Channel_FuncSelect
00021b20 Clear_TPU_Channel_Field4
00021b3c Clear_TPU_Channel_FieldC
00021b58 Write_TPU_Channel_FieldA
00021b90 Reset_TPU_Channel_Sequence
00021c6c Init_TPU_Channel_Full
00022484 Compute_CRC32_FlashVerify_Bare
00022844 Validate_Command_Signature
00022894 Build_Command_Response
0002294c Dispatch_Command_Packet
00022a70 Check_FlashVerify_Status
00022ae0 Compute_CRC32_FlashVerify
0002de80 Capture_MAF_TPU_B_Channel0_RawPeriod
00030a94 Verify_TouCAN_AB_BitTiming_Config
00037158 ADC_Raw_Counter_Read
00037178 Read_Timer2_Scaled
0003a7f0 Possibly_MAF_Raw_Counter_Read
0003d318 Read_PerCylinder_KnockValue_Template
00046c40 START_HERE_TOMORROW [NOTE: session bookmark, not a real identification]
00057b64 Configure_TouCAN_AB_DiagnosticMailboxes
0006ad1c Capture_FreezeFrame_FuelLevel
0006b4a0 Process_APP1_Plausibility
0006b83c Process_APP2_Plausibility
0006b96c Process_APP_Correlation
0006db78 Possibly_Build_Comm_Message_Structure
00073448 Poll_GMLAN_Channels_And_Dispatch
0007d884 Evaluate_AFM_CylDeact_DTC_Group
00089380 Update_MIL_Request_Bits
00089428 Evaluate_MIL_Bit_For_Entry
000898f0 Update_DTC_RuntimeStatus
00089944 Process_DTC_Actions
0008a26c Process_DTC
0008b2ac Handle_Service_03_ReadDTCs
0008b8b0 Count_TypeAB_DTC_RuntimeBit4
0008cc20 Get_DTC_Gate1
0008cc2c Process_DTC_Monitor_Readiness
0008d734 Get_DTC_Gate2
0008debc Handle_Service_04_ClearDTCs
0008df38 Handle_Service_10_DiagnosticSessionControl
0008eb00 Possibly_Airflow_Estimate_MasterValidity
00091a80 Possibly_Airflow_Estimate_OutputFilter
00091de8 Possibly_VE_Airflow_DynamicEstimator
000946f0 Process_FuelComposition_Plausibility
00094988 Capture_FreezeFrame_BARO
000b10d8 Process_OilPressure_Plausibility
000b11ac Process_OilPressure_LowPressureDuration
000b9adc Select_CamPhaser_SecondAxis_Input
000be3d8 Capture_FreezeFrame_RawCrankCounter
000c2214 possible_init_reset_state_001
000d9fa0 Capture_FreezeFrame_EGRError
000f2080 Capture_FreezeFrame_PID
000f216c Create_Or_Update_FreezeFrame_FailureRecord
000f2f0c Handle_Service_02_FreezeFrameData
000f3b50 Saturating_Float_Int16Conversion
000f426c Float_Normalize_Clamp_0_1
000f42a4 Normalized_Temp_Sensor_Lookup_Routine
000f4efc Float_Interpolate_Table_Lookup
000f4ff8 IAT_Curve_Stage2_BoundedLookup
000f5120 Bilinear_Table_Lookup_2Axis
000fd6a4 Possible_O2SLOC_Bitmask
0011952c Process_Knock_Counters
0011cb90 Calculate_Fuel_Quantity
0011ce20 Possibly_Crank_Period_Rate_Calc
0012209c Capture_FreezeFrame_MAF
00130680 Process_Misfire_Detection
0013681c Handle_Service_01_ShowCurrentData
00137418 Handle_Service_22_ReadDataByIdentifier
0013798c Handle_Service_2C_DynamicallyDefineDataID
00138b04 Lookup_PID_DispatchTable_Index
0013b170 Handle_Service_34_RequestDownload
0013b588 Handle_Service_27_SecurityAccess
0013cca4 Handle_Service_3E_TesterPresent
0013cdb0 Send_Diagnostic_NegativeResponse
0013d174 Lookup_GMLAN_Service_Index
0013d1e8 Dispatch_GMLAN_Service_Request
0013d2b4 Dispatch_GMLAN_Request_Channel
00144690 Capture_FreezeFrame_O2S_B1S1
001446f0 Capture_FreezeFrame_O2S_B1S2
00144734 Capture_FreezeFrame_O2S_B2S1
00144794 Capture_FreezeFrame_O2S_B2S2
00145da0 Write_Uint16_As_2BigEndian
0014d26c Trigger_CamPhaser_ExtendedFailureRecord
0014d3b4 CamPhaser_Control_And_Plausibility
00154d94 Capture_FreezeFrame_Ignition1Voltage
001629c0 Capture_FreezeFrame_SparkAdv
00167594 Possibly_Crank_RPM_Timing_Window
00168608 Possibly_Crank_Event_Cluster_Calc
00170ec0 Process_EOT_TFT_Duration
00180198 Possibly_Capture_TAC_ExtendedFailureRecord
0018106c Capture_Extra_FreezeFrame_Specific_DTC
00184080 Process_TAC_Plausibility
0018614c Capture_FreezeFrame_TP
00186190 Capture_FreezeFrame_CommandedEGR
00196794 Capture_FreezeFrame_VSS
00197a80 Evaluate_Diagnostic_State
003fe800 BootBlock_RamTemplate_Dest
================================================================================
SECTION 2 — NAMED GLOBAL DATA / REGISTER LABELS (130 total)
================================================================================
Address Name Size Xrefs
-------- ------------------------------------------ ------ -----
003f81e4 runtime_status 1 B 144
003f84ec DAT_DTC_MasterEnable 1 B 5
00240c14 DAT_DTC_Gate2Flag 1 B 5
003fcbd9 DAT_DTC_SuspendFlag 1 B 123
00240e34 ECT_Value 2 B 10
003fe12c IAT_Value 2 B 9
0024173a RPM_Raw 2 B 13
0024173e RPM_Active 2 B 277
00241728 RPM_SyncFlag 1 B 7
003fce30 MAP_Raw 2 B 5
003fce24 MAP_Active 2 B 50
003f9df4 System_Checksum_Accumulator 2 B 324
00240c94 VE_Estimate_Accumulator_1 4 B 4
00240d18 VE_Estimate_Accumulator_2 4 B 4
00240c78 VE_TableSelector_Index 2 B 16
00240d5c VE_Estimator_ModeFlag 1 B 4
003fdba2 VE_Estimator_EnableFlag 1 B 11
00240d44 VE_Estimator_Counter 2 B 6
003fd14c MAF_Value 4 B 15
003fca74 VE_DebounceFlag_A 1 B 19
003fca75 VE_DebounceFlag_B 1 B 12
00240d04 VE_Debounce_Counter_1 2 B 5
00240cea VE_Debounce_Counter_2 2 B 5
00240ca0 VE_State_Compare_A 2 B 5
003fdba0 VE_Reference_Compare_Value 2 B 22
00240cdc VE_LastValue_Compare 2 B 3
00240c64 VE_Plausibility_Flag 1 B 5
00240cc0 VE_History_Value_0 4 B 3
00240cc4 VE_History_Value_1 4 B 3
00240cc8 VE_History_Value_2 4 B 2
00240cbc VE_History_Source_Extra 4 B 5
00240ce4 VE_Compare_Value_B 4 B 3
00240c91 VE_PlausibilityFlag_1 1 B 3
00240c92 VE_PlausibilityFlag_2 1 B 3
00240c98 VE_Estimate_MatureFlag 1 B 5
00240c61 VE_DebounceCounter1_CompareFlag 1 B 5
003fd15c MAF_Counter_Previous_1 2 B 2
003fd15e MAF_Counter_Previous_2 2 B 2
00240c3e Airflow_Estimate_CompoundValidityFlag 1 B 2
00240c3f Airflow_Estimate_FinalGoFlag 1 B 4
00240c5d Airflow_Estimate_SecondaryFlag 1 B 4
00240c7c Airflow_Estimate_Fresh_Value1 4 B 7
00240c80 Airflow_Estimate_Fresh_Value2 4 B 8
00240c68 Airflow_Estimate_Final1 4 B 6
00240c6c Airflow_Estimate_Final2 4 B 7
003fc8e4 Possibly_Engine_RunState_Mode 2 B 86
003fe122 Possibly_Widely_Used_Temperature_Proxy 2 B 71
003fcb98 VSS_Value 2 B 3
003fe406 SparkAdvance_Value 2 B 16
003fc82e TP_Value 2 B 11
003fe102 BARO_Value 2 B 4
003fc8be O2S_B1S1_Voltage 2 B 35
003fc8c0 O2S_B1S2_Voltage 2 B 3
003fc8c4 O2S_B2S1_Voltage 2 B 15
003fc8c6 O2S_B2S2_Voltage 2 B 3
003fca7e O2S_B1_TrimRelated 2 B 8
003fca80 O2S_B2_TrimRelated 2 B 6
003fcbd2 Ignition1Voltage_Value 2 B 69
0024287a Knock_Bank1_Counter 1 B 5
0024287b Knock_Bank2_Counter 1 B 6
00243868 Knock_RuntimeGateFlag 1 B 40
003fa0b0 Knock_MasterEnable_Flag 2 B 14
003fa0b6 Knock_PerCylinder_Value_Array 2 B 9
003fb432 Knock_PerCylinder_Reset_Array 2 B 6
003fe5e6 APP1_Value 2 B 7
0024291a APP1_Value_Alt 2 B 4
003fe5e8 APP2_Value 2 B 7
0024291c APP2_Value_Alt 2 B 4
003fe5ea APP1_Correlation_Value 2 B 7
003fe5ec APP2_Correlation_Value 2 B 7
003fe5d4 APP_Correlation_DynamicLimit 2 B 3
002413ca OilPressure_Value 2 B 7
002413e2 OilPressure_LowPressureAccumulator 2 B 5
00243b74 EOT_TFT_DurationAccumulator 2 B 6
00243b84 EOT_TFT_CompareValue 2 B 10
00243b8c EOT_TFT_CompareValue_Long 4 B 5
003fe5fa FuelLevel_Value 2 B 3
003f88a8 EGRError_Value 2 B 27
00241729 Possibly_Secondary_Sync_Flag 1 B 9
003fd78c Possibly_Crank_Period_Rate_Output 4 B 8
0040d164 Possibly_Timing_Mode_Selector ? 0
0040d19e Possibly_Timing_SmoothedValue ? 0
0040d179 Possibly_Timing_OutputFlag ? 0
003fcef4 Possibly_Timing_Threshold 2 B 23
00243a66 Possibly_Crank_Event_0 2 B 5
00243a68 Possibly_Crank_Event_1 2 B 3
00243a6a Possibly_Crank_Event_2 2 B 1
00243a6c Possibly_Crank_Event_3 2 B 3
00243a6e Possibly_Crank_Event_4 2 B 5
00242bb4 Possibly_Misfire_StateMode 2 B 11
00242c33 Possibly_Misfire_NewEventFlag 1 B 6
00242c34 Possibly_Misfire_ConditionFlag 1 B 5
00242c10 Possibly_Misfire_CountThreshold 1 B 8
00243524 CamPhase_Estimate_Array 4 B 4
00243610 CamPhaser_Counter_Array 2 B 7
00243620 CamPhaser_RecordedFlag_Array 1 B 2
0040d550 Possibly_CamPhaser_SecondInput ? 0
0024360c CamPhaser_DisableFlag_Array ? 2
003fd78c Timing_Rate_3 4 B 8 [alias of Possibly_Crank_Period_Rate_Output - same address]
0040d7b0 FuelQuantity_Output ? 0
003fcb76 Possibly_FuelCalc_SecondInput 2 B 174
003fd784 Timing_Rate_1 4 B 13
003fd788 Timing_Rate_2 4 B 9
0024035e CommStruct_Field_Base 2 B 3
003fa35c CRC32_BootBlock_Result 4 B 3
003fa360 CRC32_OS_FirstBlock_Result 4 B 3
003fa358 FlashVerify_StatusFlag1 1 B 2
003fa359 FlashVerify_StatusFlag2 1 B 2
003fa34c CommandDispatch_PacketPtr 4 B 6
003fa348 CommandDispatch_ResponsePtr 4 B 8
003fa356 TPU_Channel_SharedBaseValue 2 B 3
00304500 TPU_Channel_ConfigBlock_Base ? 3
00304400 TPU_Channel_ControlReg_Base ? 97
00304418 TPU_StatusPoll_Register ? 84
0030450e TPU_Channel_StatusReadback ? 4
00305180 FlashController_ConfigBlock ? 40
003fa364 CommandDispatch_Table ? 1
003fb260 FlashOp_BusyState 2 B 69
003fb262 FlashOp_PendingMask 2 B 158
003fb264 FlashOp_CallbackPtr 4 B 15
003fa084 SchedulerISR_StateVar 2 B 8
003fa4c0 Scheduler_ActiveTasksMask 4 B 38
003fa55c Scheduler_TaskExecutionCounters 2 B 19
003fe814 Possibly_MMU_FeatureFlag 2 B 4
003fe818 BootBlock_BSS_Start 4 B 2
003fe812 Possibly_BootFeatureFlag_2 2 B 4
00307080 TouCAN_A_MCR ? 19
00307480 TouCAN_B_MCR ? 19
00307100 TouCAN_A_MessageBuffers ? 0
00307500 TouCAN_B_MessageBuffers ? 0
================================================================================
SECTION 3 — PHYSICAL PIN <-> CONFIRMED HARDWARE ADDRESS CROSS-REFERENCE
================================================================================
This is NOT a full pinout (see the CSV files for that — every physical pin's
wire/circuit/MCU-port assignment is documented there). This section lists
ONLY the pins where a specific memory-mapped register or capture location
has actually been traced and confirmed in the disassembly. This list is
intentionally short — most physical pins have a known MCU port label
(e.g. "B_AN51", "A_TPUCH8") from the pinout CSVs but have NOT yet been
correlated to a specific hex address in code.
Connector/Pin Function MCU Port Confirmed Address Notes
------------- -------------------------------- ----------- ----------------- -----
X1 Pin 41 MAF Sensor Signal B_TPUCH0 00304504 Raw period capture register, read by Capture_MAF_TPU_B_Channel0_RawPeriod (0002de80)
X1 Pin 40 Fuel Composition Sensor Signal B_TPUCH6 NOT YET FOUND Confirmed target channel; register not yet located. (FlexFuel, not populated in US wiring harnesses. See project summary item 6.)
X1 Pin 27 High Speed GMLAN Serial Data (-) GMHS-L 00307080 (TouCAN_A_MCR) Via TouCAN A/B controllers, not a
X1 Pin 28 High Speed GMLAN Serial Data (+) GMHS-H 00307480 (TouCAN_B_MCR) direct 1:1 pin-to-register mapping. 00307100/00307500 (message buffers)
Known but NOT yet traced to a specific address (targets for future work):
- X1 Pin 71 Vehicle Speed Sensor (VSS) High B_TPUCH1/2 -- (VSS_Value's filter chain traced back to FUN_00173a64 cluster; true raw HW register not reached)
- X2 Pin 68 CKP Sensor Signal A_TPUCH1/2 -- (TPU-A, not yet investigated)
- X2 Pin 62 CMP Sensor B Signal A_TPUCH7 -- (TPU-A, not yet investigated)
- X2 Pin 64 CMP Sensor A Signal A_TPUCH8 -- (TPU-A, not yet investigated)
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
Re: E38 Documentation attempt - Starting from the DTC functions.
Got my universal plug OBD2 bench harness built and working today. Using the OBDX Pro VX, I have connected to and read out the flash from my two E38 PCMs, but I think they both have the same OS and report as being a Pontiac file...but one was pulled from a 2008 Malibu 3500 V6 and the other was pulled from a 2007 Silverado 6.0L V8.
I also have a P12 from a Trailblazer 4.2L I6, an E67 from a Trailblazer 4.2L I6, and an E78 from a 2014 Chevy Trax to play with, although I need to find another blue plug for the E67 before I can play with that one.
I also have a P12 from a Trailblazer 4.2L I6, an E67 from a Trailblazer 4.2L I6, and an E78 from a 2014 Chevy Trax to play with, although I need to find another blue plug for the E67 before I can play with that one.
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
Re: E38 Documentation attempt - Starting from the DTC functions.
Currently finishing up the last onboard flash routines. Hunted down all the voltage sensing inputs, traced out all the voltage-gated/locked functions, like reflash lockouts.
Looking into the possibility of using the internal RAM-To-Flash functions, combined with RAM injection, to do live tuning.
Looking into the possibility of using the internal RAM-To-Flash functions, combined with RAM injection, to do live tuning.
-
Xnke
- Posts: 59
- Joined: Thu Sep 24, 2015 3:42 am
Re: E38 Documentation attempt - Starting from the DTC functions.
The factory test-mode gate is triggered by presenting wide-open-throttle on both throttle position sensors, pedal-at-rest on both APP sensors, and normal ignition voltage — on X1 pins 19, 29, 32 and X2 pins 58, 63, 65. That will enable the factory test mode-of what that does, I am not sure what all will go on when you get into that mode.