PCM Hammer P12 development

They go by many names, P01, P10, P12, P59, E38, VPW, '0411 etc.
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer fails on P12

Post by Gampy »

Code: Select all

#if defined P12
#define SIM_BASE        0x00FFFA30
#else
#define SIM_BASE        0x00FFFA00
#endif
#define SIM_CSBARBT     (*(unsigned short *)(SIM_BASE + 0x48)) // CSRBASEREG, boot chip select, chip select base addr boot ROM reg,
															   // must be updated to $0006 on each update of flash CE/WE states
#define SIM_CSORBT      (*(unsigned short *)(SIM_BASE + 0x4a)) // CSROPREG, Chip select option boot ROM reg., $6820 for normal op
#define SIM_CSBAR0      (*(unsigned short *)(SIM_BASE + 0x4c)) // CSBASEREG, chip selects
#define SIM_CSOR0       (*(unsigned short *)(SIM_BASE + 0x4e)) // CSOPREG, *Chip select option reg., $1060 for normal op, $7060 for accessing flash chip
#define HARDWARE_IO     (*(unsigned short *)(0xFFFFE2FA))      // Hardware I/O reg
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer fails on P12

Post by antus »

thanks. are there any changes to flash_amd.c or is that still stock?
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer fails on P12

Post by Gampy »

Same thing done to the other two functions are the only changes ...

The code is extremely stock.

Code: Select all

Only in ../Test Builds/P12/Kernels/Kernels: Current.diff
diff -aEbwBiur -X '../Test Builds/P12/Kernels/Kernel-diff.exclude' Kernels/common-readwrite.c ../Test Builds/P12/Kernels/Kernels/common-readwrite.c
--- Kernels/common-readwrite.c	2021-01-29 09:32:23.970935000 -0500
+++ ../Test Builds/P12/Kernels/Kernels/common-readwrite.c	2022-03-04 06:01:59.825799000 -0500
@@ -64,8 +62,11 @@
 ///////////////////////////////////////////////////////////////////////////////
 void SendWriteSuccess(unsigned char code)
 {
-	// Send response
+#if defined P12
+	MessageBuffer[0] = 0x6C;
+#else
 	MessageBuffer[0] = 0x6D;
+#endif
 	MessageBuffer[1] = 0xF0;
 	MessageBuffer[2] = 0x10;
 	MessageBuffer[3] = 0x76;
diff -aEbwBiur -X '../Test Builds/P12/Kernels/Kernel-diff.exclude' Kernels/common.c ../Test Builds/P12/Kernels/Kernels/common.c
--- Kernels/common.c	2022-01-15 14:51:22.409295399 -0500
+++ ../Test Builds/P12/Kernels/Kernels/common.c	2022-02-28 03:39:48.829369000 -0500
@@ -26,8 +26,12 @@
 {
 	WATCHDOG1 = 0x55;
 	WATCHDOG1 = 0xAA;
+#if defined P01 || defined P04
 	WATCHDOG2 &= 0x7F;
 	WATCHDOG2 |= 0x80;
+#elif defined P12
+	WATCHDOG2 ^= 0x80;
+#endif
 }
 
 ///////////////////////////////////////////////////////////////////////////////
diff -aEbwBiur -X '../Test Builds/P12/Kernels/Kernel-diff.exclude' Kernels/common.h ../Test Builds/P12/Kernels/Kernels/common.h
--- Kernels/common.h	2021-12-19 17:41:26.237953561 -0500
+++ ../Test Builds/P12/Kernels/Kernels/common.h	2022-02-27 23:41:35.381360000 -0500
@@ -15,6 +15,7 @@
 typedef int            int32_t;
 
 #ifndef DLC_CONFIGURATION
+  #if defined P01
 	#define DLC_CONFIGURATION          (*(unsigned char *)0x00FFF600)
 	#define DLC_INTERRUPTCONFIGURATION (*(unsigned char *)0x00FFF606)
 	#define DLC_TRANSMIT_COMMAND       (*(unsigned char *)0x00FFF60C)
@@ -23,6 +24,25 @@
 	#define DLC_RECEIVE_FIFO           (*(unsigned char *)0x00FFF60F)
 	#define WATCHDOG1                  (*(unsigned char *)0x00FFFA27)
 	#define WATCHDOG2                  (*(unsigned char *)0x00FFD006)
+  #elif defined P04
+    #define DLC_CONFIGURATION          (*(unsigned char *)0x00FFE800)
+    #define DLC_INTERRUPTCONFIGURATION (*(unsigned char *)0x00FFE800)
+    #define DLC_TRANSMIT_COMMAND       (*(unsigned char *)0x00FFE800)
+    #define DLC_TRANSMIT_FIFO          (*(unsigned char *)0x00FFE801)
+    #define DLC_STATUS                 (*(unsigned char *)0x00FFE800)
+    #define DLC_RECEIVE_FIFO           (*(unsigned char *)0x00FFE801)
+    #define WATCHDOG1                  (*(unsigned char *)0x00FFFA27)
+    #define WATCHDOG2                  (*(unsigned char *)0x00FFC006)
+  #elif defined P12
+    #define DLC_CONFIGURATION          (*(unsigned char *)0x00FFF600)
+    #define DLC_INTERRUPTCONFIGURATION (*(unsigned char *)0x00FFF606)
+    #define DLC_TRANSMIT_COMMAND       (*(unsigned char *)0x00FFF60C)
+    #define DLC_TRANSMIT_FIFO          (*(unsigned char *)0x00FFF60D)
+    #define DLC_STATUS                 (*(unsigned char *)0x00FFF60E)
+    #define DLC_RECEIVE_FIFO           (*(unsigned char *)0x00FFF60F)
+    #define WATCHDOG1                  (*(unsigned char *)0x00FFFA55)
+    #define WATCHDOG2                  (*(unsigned char *)0x00FFFA21)
+  #endif
 #endif
 
 ///////////////////////////////////////////////////////////////////////////////
diff -aEbwBiur -X '../Test Builds/P12/Kernels/Kernel-diff.exclude' Kernels/flash-amd.c ../Test Builds/P12/Kernels/Kernels/flash-amd.c
--- Kernels/flash-amd.c	2020-11-23 13:52:17.375198000 -0500
+++ ../Test Builds/P12/Kernels/Kernels/flash-amd.c	2022-03-04 06:00:25.164153000 -0500
@@ -17,7 +17,11 @@
 	SIM_CSORBT = 0x6820;
 
 	// Switch to flash into ID-query mode.
+#if defined P12
+	SIM_CSOR0 = 0xF322;
+#else
 	SIM_CSOR0 = 0x7060;
+#endif
 	COMMAND_REG_AAA = 0xAAAA;
 	COMMAND_REG_554 = 0x5555;
 	COMMAND_REG_AAA = 0x9090;
@@ -30,8 +34,11 @@
 
 	// Switch back to standard mode.
 	FLASH_BASE = READ_ARRAY_COMMAND;
+#if defined P12
+	SIM_CSOR0 = 0xA332;
+#else
 	SIM_CSOR0 = 0x1060;
-
+#endif
 	return id;
 }
 
@@ -46,7 +53,11 @@
 	uint16_t volatile * flashBase = (uint16_t*)address;
 
 	// Tell the chip to erase the given block.
+#if defined P12
+	SIM_CSOR0 = 0xF322;
+#else
 	SIM_CSOR0 = 0x7060;
+#endif
 	COMMAND_REG_AAA = 0xAAAA;
 	COMMAND_REG_554 = 0x5555;
 	COMMAND_REG_AAA = 0x8080;
@@ -100,7 +111,11 @@
 	// Return to array mode.
 	*flashBase = 0xF0F0;
 	*flashBase = 0xF0F0;
+#if defined P12
+	SIM_CSOR0 = 0xA332;
+#else
 	SIM_CSOR0 = 0x1060;
+#endif
 
 	return status;
 }
@@ -124,7 +139,11 @@
 
 		if (!testWrite)
 		{
+#if defined P12
+			SIM_CSOR0 = 0xF322;
+#else
 			SIM_CSOR0 = 0x7060;
+#endif
 			COMMAND_REG_AAA = 0xAAAA;
 			COMMAND_REG_554 = 0x5555;
 			COMMAND_REG_AAA = 0xA0A0;
@@ -154,7 +173,11 @@
 			{
 				*address = 0xF0F0;
 				*address = 0xF0F0;
+#if defined P12
+				SIM_CSOR0 = 0xA332;
+#else
 				SIM_CSOR0 = 0x1060;
+#endif
 			}
 
 			return errorCode;
@@ -167,7 +190,11 @@
 		unsigned short* address = (unsigned short*)startAddress;
 		*address = 0xF0F0;
 		*address = 0xF0F0;
+#if defined P12
+	SIM_CSOR0 = 0xA332;
+#else
 		SIM_CSOR0 = 0x1060;
+#endif
 	}
 
 	return 0;
diff -aEbwBiur -X '../Test Builds/P12/Kernels/Kernel-diff.exclude' Kernels/flash.h ../Test Builds/P12/Kernels/Kernels/flash.h
--- Kernels/flash.h	2020-12-10 18:38:49.096283000 -0500
+++ ../Test Builds/P12/Kernels/Kernels/flash.h	2022-03-03 14:26:14.222558000 -0500
@@ -2,7 +2,11 @@
 // Functions for erasing and writing flash
 ///////////////////////////////////////////////////////////////////////////////
 
+#if defined P12
+#define SIM_BASE        0x00FFFA30
+#else
 #define SIM_BASE        0x00FFFA00
+#endif
 #define SIM_CSBARBT     (*(unsigned short *)(SIM_BASE + 0x48)) // CSRBASEREG, boot chip select, chip select base addr boot ROM reg,
 															   // must be updated to $0006 on each update of flash CE/WE states
 #define SIM_CSORBT      (*(unsigned short *)(SIM_BASE + 0x4a)) // CSROPREG, Chip select option boot ROM reg., $6820 for normal op
@@ -54,6 +58,7 @@
 uint8_t Intel_WriteToFlash(unsigned int payloadLengthInBytes, unsigned int startAddress, unsigned char *payloadBytes, int testWrite);
 
 // Functions prefixed with Amd1024 work with this chip ID
+#define FLASH_ID_AMD_AM29BL802C 0x00012281 // AM29BL802C
 #define FLASH_ID_AMD_1024  0x00012258
 
 uint32_t Amd_GetFlashId();
diff -aEbwBiur -X '../Test Builds/P12/Kernels/Kernel-diff.exclude' Kernels/write-kernel.c ../Test Builds/P12/Kernels/Kernels/write-kernel.c
--- Kernels/write-kernel.c	2021-12-19 17:41:26.238953419 -0500
+++ ../Test Builds/P12/Kernels/Kernels/write-kernel.c	2022-03-03 14:40:51.694234000 -0500
@@ -266,7 +266,8 @@
 	case FLASH_ID_INTEL_1024:
 		return Intel_WriteToFlash(payloadLengthInBytes, startAddress, payloadBytes, testWrite);
 
-	case FLASH_ID_AMD_1024:
+	case FLASH_ID_AMD_1024:        // P01/P59
+  case FLASH_ID_AMD_AM29BL802C:  // P12 1m
 		return Amd_WriteToFlash(payloadLengthInBytes, startAddress, payloadBytes, testWrite);
 
 	default:
@@ -293,11 +294,12 @@
 
 	switch (MessageBuffer[3])
 	{
+#if !defined P12
 	case 0x20:
 		LongSleepWithWatchdog();
 		Reboot(0xCC000000 | iterations);
 		break;
-
+#endif
 	case 0x34:
 		HandleWriteRequestMode34();
 		ClearBreadcrumbBuffer();
@@ -458,10 +460,17 @@
 
 		lastMessage = iterations;
 		lastActivity = iterations;
-
+#if defined P12
+		// Did the tool just request a reboot?
+		if (MessageBuffer[3] == 0x20)
+		{
+			break;
+		}
+#endif
 		ProcessMessage(iterations);
 	}
-
+#if !defined P12
 	// This shouldn't happen. But, just in case...
	Reboot(0xFF000000 | iterations);
+#endif
 }
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer fails on P12

Post by antus »

I reckon the value going in to SIM_CSOR0 is not correct to set the hardware up properly for an erase. Since we know SIM_CSOR0 is at FFFA7E, we can look for writes to that address in the stock bin, and hopefully use that to find the code that writes the vin changes to the other parameter block, and see how it sets up that register.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer fails on P12

Post by antus »

I think the code here is setting program mode:

Code: Select all

ROM:000D885E 3D78 FA7E FFEC                                          move.w  ($FFFFFA7E).w,-$14(a6)
ROM:000D8864 08EE 0004 FFEC                                          bset    #4,-$14(a6)
ROM:000D886A 31EE FFEC FA7E                                          move.w  -$14(a6),($FFFFFA7E).w
And your writing F322 to SIM_CSOR0 which is probably triggering command mode but not enabling programming.

A quick check on the calculator shows F322 is this, which... and im not certain Im reading with the same endianness, and I assume the most right hand side is bit zero, and if so.. then bit 4 is set to zero by the kernel. It likely does something like enable programming voltage (I havnt read the data sheet about that part yet) and would be required for erase and write but not chip identification or burst mode where we got the value from.

Also I've just renamed the thread to label it as a development thread, I think this is a good example of the process and that'll make it easier for others to find it in the future.
You do not have the required permissions to view the files attached to this post.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer P12 development

Post by Gampy »

The m68k is big endian, you flipped them in the binary, so you need to flip them back ... At least that's how this ignoramus sees it!

I just built a kernel with,

Code: Select all

			uint32_t value = SIM_CSOR0;

			MessageBuffer[0] = 0x6C;
			MessageBuffer[1] = 0xF0;
			MessageBuffer[2] = 0x10;
			MessageBuffer[3] = 0x7D;
			MessageBuffer[4] = 0x04;
			MessageBuffer[5] = (char)(value >> 24);
			MessageBuffer[6] = (char)(value >> 16);
			MessageBuffer[7] = (char)(value >> 8);
			MessageBuffer[8] = (char)(value >> 0);
			WriteMessage(MessageBuffer, 9, Complete);
Using 3D04 ... VPW Explorer is modded, it has a Kernel Loader tab now, The Explorer tab (the original tab) has the ability to send 6C 10 F0 3D 04 ... It should respond with the default value in SIM_CSOR0.
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer P12 development

Post by antus »

this is where we need a thumbs up button, but since we dont have it you get a whole post plus words :thumbup:
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
kur4o
Posts: 1146
Joined: Sun Apr 10, 2016 11:20 am

Re: PCM Hammer P12 development

Post by kur4o »

I finally managed to figure some stuff from the gm flash routine.

At ffff203c is the code to unlock chip erase/program
At ffff2020 is the code to lock chip erase/program
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer P12 development

Post by Gampy »

I don't know what link is ...

The erase code in the GM flash routine is sub_FF206E, in the Os it's sub_D884C
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
kur4o
Posts: 1146
Joined: Sun Apr 10, 2016 11:20 am

Re: PCM Hammer P12 development

Post by kur4o »

You need to configure some registers before erasing/program. The equivalent of vpp voltage apply in intel chips.
LInk is a link , link a register to stack and than use variables stored from the link address in stack.