A few more minor clues:
I believe this is using HC11 MCUs (two of them); I assume pinned the same as the F1 variant. I'll refer to U1 as the one nearest the flash memory or knock filter and U2 as the other. The ALDL communication goes into U1 at PD0/RxD. The PCM diagnostics appears to be wired into U2 at PB5/ADDR13.
Which would suggest this is a digital input and not analog. There's a 3k pull-up resistor so I suspect PCM diagnostics would need to be pulled to ground to accomplish anything. That said, seeing as how the PCM diagnostic line isn't tied to the same MCU reading the ALDL data, I have my doubts it has anything to do with waking up the port. Unfortunately the Isuzu FSM says nothing about the use of the pin so maybe this is a bit of a dead end.
I got a copy of Ghidra to disassemble the code, but disassembly is all new to me so I'm not expecting any revelations soon. Seeing as how this has a 1 Mb memory, but uses HC11 MCUs I would assume it's fair to think that the flash memory is split up between the two MCUs. Antus has mentioned this sort of thing before, but I was curious about how it does this.
For the most part the Data and Address pins all connect directly to U1. A16 passes through a 100 ohm resistor to the nearest P77AG IC (tan in the photo above). This also splits off to some other circuit by a via that I haven't chased yet. I haven't quite figured out how U2 reads from the flash yet. So far I know that PC0/Data0 connects with the 40854 IC, but I haven't been able to find any endpoints for the other data pins.
Probing around on U2 I actually don't see any activity on the Data and Address pins at all. It's pretty well silent with exception to pins PE7/AN7, PE6/AN6, PE3/AN3, and PE2/AN2 which appear to have some sort of communication passing over them. Is it possible that U2 isn't accessing the flash memory at all and relying on its internal ROM?
99 Isuzu 3.5 anyone know about these ECUs?
-
Maxzillian
- Posts: 9
- Joined: Sat Nov 29, 2025 8:36 pm
- cars: 2000 Isuzu Vehicross
1987 Chrysler Conquest (LFX Swap) - Location: Wichita, KS
-
antus
- Site Admin
- Posts: 10012
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: 99 Isuzu 3.5 anyone know about these ECUs?
first need to figure out what cpu it is. if its 68k then pcm hammer can be adapted if we can figure out load address, watch dog, cop, for read then flash voltage for write. if its hc11 then flash kernel will be from scratch. a log of a write with factory tools should answer everything. that bin and some experimentation with a dissassembler should answer cpu and if it is 68k probably everything else except load address.
For what its worth I recent bought one of these so have it on hand but havnt found a factory tool to write it or time so far. Also a bit hesitant to test on my ecm when I only have 1 and need it for the car. Would gladly test read though, or write with factory tools.
For what its worth I recent bought one of these so have it on hand but havnt found a factory tool to write it or time so far. Also a bit hesitant to test on my ecm when I only have 1 and need it for the car. Would gladly test read though, or write with factory tools.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
Maxzillian
- Posts: 9
- Joined: Sat Nov 29, 2025 8:36 pm
- cars: 2000 Isuzu Vehicross
1987 Chrysler Conquest (LFX Swap) - Location: Wichita, KS
Re: 99 Isuzu 3.5 anyone know about these ECUs?
While I'm still getting up to speed about all this disassembly stuff I happened to stumble across what appears to be some handlers for the ALDL communication. In the first half of the flash at 0x665E appears to be a function that is responding to address 0xF4 and handling what I think is solely Mode 5 (enter download mode) and Mode 6 (address of routine to execute), but I still have no luck knocking on that door.
Code: Select all
**************************************************************
* FUNCTION *
**************************************************************
undefined __asmA SerialTask(void)
undefined B:1 <RETURN>
SerialTask XREF[7]: 665a(c), 6687(j), 668f(j),
669d(j), 66c9(j), 66dc(j),
SerialErrorCheckAndRead:6713(j)
665e ce 10 00 LDX #DAT_1000 Load index register X with 0x1000
6661 86 04 LDAA #0x4 Load accumulator A with 0x4
6663 a7 2d STAA offset DAT_102d,IX Store accumulator A to 0x102d
6665 ec 2e LDD offset DAT_102e,IX Load double accumulator D with 0
6667 4f CLRA clear accumulator A
6668 b7 1a f5 STAA DAT_CheckSumBuffer Store accumulator A to CheckSumB
LAB_666b XREF[1]: 6672(j)
666b 1c 2d 02 BSET offset DAT_102d,IX,0x2 Set bits at 0x102d to 0x02
666e 8d 77 BSR SerialErrorCheckAndRead Branch to subroutine
6670 81 e0 CMPA #0xe0 Compare A to 0xe0
6672 25 f7 BCS LAB_666b Branch if carry set, jump 0xf7 b
ECU address is 0xF4?
6674 81 f4 CMPA #0xf4 Compare A to 0xf4
6676 27 13 BEQ is_F4 Jump to label if address is 0xf4
6678 8d 6d BSR SerialErrorCheckAndRead Branch to subroutine
667a 80 54 SUBA #0x54 Subtract dlc offset from A
667c b7 1a f6 STAA DAT_DataLength Store DLC to 0x1af6
LAB_667f XREF[1]: 6684(j)
667f 8d 66 BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
6681 7a 1a f6 DEC DAT_DataLength Decrement memory byte 0x1af6
6684 26 f9 BNE LAB_667f Branch if not = zero, 0x677d
6686 5d TSTB Test B for zero or minus
6687 26 d5 BNE SerialTask Branch if not zero, 0x675c
6689 20 5b BRA LAB_DoNothingAndReturn Branch always 0x66e4
is_F4 XREF[1]: 6676(j)
668b 8d 5a BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
668d 80 56 SUBA #0x56
668f 25 cd BCS SerialTask Go back to beginning if result i
6691 b7 1a f6 STAA DAT_DataLength = FFh
6694 8d 51 BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
6696 81 05 CMPA #0x5
6698 26 13 BNE LAB_66ad Branch if mode is not 0x5 (enter
669a 8d 4b BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
669c 5d TSTB Checksum? Test B for zero or minus
669d 26 bf BNE SerialTask Branch if not equal to zero 0x675e
669f 14 d8 80 BSET DAT_00d8,0x80 = FFh
66a2 c6 01 LDAB #0x1
66a4 18 ce 1a f7 LDY #DAT_1af7 = FFh
66a8 bd 67 24 JSR Mode6Resp?
66ab 20 39 BRA LAB_DoNothingAndReturn Must be a placeholder because th
LAB_66ad XREF[1]: 6698(j)
66ad 81 06 CMPA #0x6
LAB_66af XREF[1]: 66af(j)
66af 26 fe BNE LAB_66af
66b1 8d 34 BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
66b3 b7 1a f8 STAA DAT_1af8 = FFFFh
66b6 7a 1a f6 DEC DAT_DataLength = FFh
66b9 8d 2c BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
66bb b7 1a f9 STAA DAT_1af8+1
66be 7a 1a f6 DEC DAT_DataLength = FFh
66c1 18 fe 1a f8 LDY DAT_1af8 = FFFFh
66c5 18 8c 03 80 CPY #0x380
66c9 22 93 BHI SerialTask
LAB_66cb XREF[1]: 66d5(j)
66cb 8d 1a BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
66cd 18 a7 00 STAA 0x0,IY
66d0 18 08 INY
66d2 7a 1a f6 DEC DAT_DataLength = FFh
66d5 26 f4 BNE LAB_66cb
66d7 8d 0e BSR SerialErrorCheckAndRead undefined SerialErrorCheckAndRea
66d9 5d TSTB
66da 27 03 BEQ LAB_66df
66dc 7e 66 5e JMP SerialTask
LAB_66df XREF[1]: 66da(j)
66df 18 fe 1a f8 LDY DAT_1af8 = FFFFh
66e3 18 ad 00 JSR 0x0,IX
LAB_DoNothingAndReturn XREF[2]: 6689(j), 66ab(j)
66e6 39 RTS
-
Maxzillian
- Posts: 9
- Joined: Sat Nov 29, 2025 8:36 pm
- cars: 2000 Isuzu Vehicross
1987 Chrysler Conquest (LFX Swap) - Location: Wichita, KS
Re: 99 Isuzu 3.5 anyone know about these ECUs?
Little more success on the research front. So I've found where the SCI registers are configured and it's set up for Mode 1 (1 start bit, 9 data bits, and 1 stop bit) as well as "Wake up by address mark". If I understand right this is a little unusual for 8192 baud ALDL?
So what does that look like? It is that every data byte is 9 bits with only the very first one with the address having the most significant bit set to 1? I can't imagine this would be very straight-forward to test waters with a normal serial terminal and I don't think HSE supports such a format?
I can confirm it is in fact set up for 8192 baud.
So what does that look like? It is that every data byte is 9 bits with only the very first one with the address having the most significant bit set to 1? I can't imagine this would be very straight-forward to test waters with a normal serial terminal and I don't think HSE supports such a format?
I can confirm it is in fact set up for 8192 baud.
-
antus
- Site Admin
- Posts: 10012
- Joined: Sat Feb 28, 2009 10:34 am
- cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007
Re: 99 Isuzu 3.5 anyone know about these ECUs?
I'd probably ignore that configuration. ALDL device ID F4 is used in other 90s ECMs so that sounds correct. But 8192 is standard serial no start bit, 8 data bits 1 stop bit, so for some reason that start bit and 9 data bits looks incorrect. When I am disassembly I find its helpful to not attempt to understand everything on the fast pass, even at all, if it doesn't make sense yet just move on and it'll either make sense later or if its not relevant it'll just save you time. Best thing to do is flash it with SPS and log the process, then examine the logs. That'll show you everything you need including unlock process, seed/key sample and load address and you can disassemble the flash kernel which will contain everything needed with a much smaller surface area to understand.
I'll also add that this tool will reflash a VX/VY commodore flash based PCM, which is a similar generation to the 99 Isuzu 3.5 you are looking at, over ALDL. I think it is even device ID F4. The process is likely to be very similar. There is even a small chance it'll just work out of the box. It might be worth a try, at least to read it. viewtopic.php?t=82
I'll also add that this tool will reflash a VX/VY commodore flash based PCM, which is a similar generation to the 99 Isuzu 3.5 you are looking at, over ALDL. I think it is even device ID F4. The process is likely to be very similar. There is even a small chance it'll just work out of the box. It might be worth a try, at least to read it. viewtopic.php?t=82
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
Maxzillian
- Posts: 9
- Joined: Sat Nov 29, 2025 8:36 pm
- cars: 2000 Isuzu Vehicross
1987 Chrysler Conquest (LFX Swap) - Location: Wichita, KS
Re: 99 Isuzu 3.5 anyone know about these ECUs?
Sorry, I meant to say OSE instead of HSE earlier. It was one of the very first things I tried when I started poking at this PCM. What I've come across seems to make sense and along with the SCI control register it's also setting the baud rate in the same block of code. The baud rate settings seem to math out correctly so that's partly why I gave so much stock to the control register settings.
Unfortunately I don't have a SPS and won't for quite some time so in the meantime I'm just exploring what I can.
Unfortunately I don't have a SPS and won't for quite some time so in the meantime I'm just exploring what I can.
-
kur4o
- Posts: 1145
- Joined: Sun Apr 10, 2016 11:20 am
Re: 99 Isuzu 3.5 anyone know about these ECUs?
Data is sent on SPI to external chip that handle the ALDL communication on hardware level.
I am not sure you need to explore ALDL that much. It is there to keep compatibility with other modules that are aldl and exchange data with pcm, like abs, sir,bcm.
Other functions are crippled to some basic function. maybe some data logging can be made.
Flashing is done via VPW line.
The bin is bank stacked 4 32kb parts, meaning 1 st part 32kb are used with 2nd 3rd and 4th 32kb. so in dissasembly you have 3 fifferent bins.
1+ 2
1+ 3
1+ 4
You have to disassemble all in different sessions and link common data.
The most important part is find the registers that triggers the switching in case you want to figure how to read and write, bank switching should be well understood.
Flashing will be very similar to 96-96 LT1 PCM, there is very good indepth info and some gearhead-efi.com, you can contact Tom H there to gather some info or try to port some of the tools he made to 3.5 isuzu.
I am not sure you need to explore ALDL that much. It is there to keep compatibility with other modules that are aldl and exchange data with pcm, like abs, sir,bcm.
Other functions are crippled to some basic function. maybe some data logging can be made.
Flashing is done via VPW line.
The bin is bank stacked 4 32kb parts, meaning 1 st part 32kb are used with 2nd 3rd and 4th 32kb. so in dissasembly you have 3 fifferent bins.
1+ 2
1+ 3
1+ 4
You have to disassemble all in different sessions and link common data.
The most important part is find the registers that triggers the switching in case you want to figure how to read and write, bank switching should be well understood.
Flashing will be very similar to 96-96 LT1 PCM, there is very good indepth info and some gearhead-efi.com, you can contact Tom H there to gather some info or try to port some of the tools he made to 3.5 isuzu.
-
Maxzillian
- Posts: 9
- Joined: Sat Nov 29, 2025 8:36 pm
- cars: 2000 Isuzu Vehicross
1987 Chrysler Conquest (LFX Swap) - Location: Wichita, KS
Re: 99 Isuzu 3.5 anyone know about these ECUs?
I really appreciate the insight; I had seen some earlier posts about the BIN being stacked like that, but hadn't loaded it into Ghidra that way. It had pulled in the first 64kb as one chunk and, for the most part, this seemed to produce some reasonable results. I tried pulling in the last 64kb and it detected hardly any code at all so what you said likely explains why.
So what's the purpose of this? Is this some sort of "hack" to make the MCU effectively do three different processes semi-simultaneously?
I had thought about the 96-97 LT1 as I had that platform at one time, but I also recalled those had a two board PCM with two Flash memory chips. Because of that I had pretty well dismissed going down that route, but the irony is I'm using my Jet DST (Tunercat) interface to poke at the VPW comm.
So what's the purpose of this? Is this some sort of "hack" to make the MCU effectively do three different processes semi-simultaneously?
I had thought about the 96-97 LT1 as I had that platform at one time, but I also recalled those had a two board PCM with two Flash memory chips. Because of that I had pretty well dismissed going down that route, but the irony is I'm using my Jet DST (Tunercat) interface to poke at the VPW comm.
Last edited by Maxzillian on Sun Dec 21, 2025 8:49 pm, edited 2 times in total.
-
pman92
- Posts: 667
- Joined: Thu May 03, 2012 12:50 pm
- Location: Castlemaine, Vic
Re: 99 Isuzu 3.5 anyone know about these ECUs?
Sounds like a limit imposed by a 16 bit address space.Maxzillian wrote: Sun Dec 21, 2025 7:25 pm Sow what's the purpose of this? Is this some sort of "hack" to make the MCU effectively do four different processes semi-simultaneously?
I've never used them myself, but apparently Ghidra has memory "overlays" you can use.
-
Maxzillian
- Posts: 9
- Joined: Sat Nov 29, 2025 8:36 pm
- cars: 2000 Isuzu Vehicross
1987 Chrysler Conquest (LFX Swap) - Location: Wichita, KS
Re: 99 Isuzu 3.5 anyone know about these ECUs?
It definitely is, Ghidra is configured to only go up to 0xFFFF for the HC11 so it chops the binary off at that point. I may need to tweak some definitions because this hard limit makes it really difficult to set up the memory map as necessary, but that does look like a useful tool.