PCM Hammer P12 development

They go by many names, P01, P10, P12, P59, E38, VPW, '0411 etc.
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer P12 development

Post by Gampy »

kur4o wrote:LInk is a link , link a register to stack and than use variables stored from the link address in stack.
Thank you!

I'm also not sure what something like: var_14(a6)
Is ...
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
kur4o
Posts: 1146
Joined: Sun Apr 10, 2016 11:20 am

Re: PCM Hammer P12 development

Post by kur4o »

Lets say you link fff8 to a6

Than var_0 is at fff8 var_1 is at fff9 var_2 is at fffa
Just like a pointer to some address. You can treat that variables as memory address.
Var16(a6) moved to xxxx will mean copy content of var16 memory to xxxx address.
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer P12 development

Post by Gampy »

Thank you!

Need time to digest that ... :D
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer P12 development

Post by antus »

You probably will be able to get your head around it after some sleep (I think its close to sunrise there for you after a night of hacking!) but its sufficient to know you can just read it as var_14(anything) is variable 14, and you dont need think about the argument, or what its doing on the hardware level to provide more short term variables than it has registers. But I guess its clear that its using the stack to do it, rather than requiring memory management which the GM OS does not provide or hard coding addresses as globals which is wasteful on such a tight system.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer P12 development

Post by antus »

Even though I think were on to it, I just thought i'd post this decompilation of the bin flash erase command here incase its helpful. Not the best decompiler, its the ghidra decompiler running inside ida.

Code: Select all

uint32_t flash_erase(uint16_t *param_1) ; address of the block to erase
{
   int32_t iVar1;
   uint32_t uVar2;
   uint16_t uStack28;
   uint16_t uStack24;

   uStack24 = uRamfffffa7e | 0x1000; // SIM_CSOR0, 1000 = 0001 0000 0000 0000 = bit4?
   uRamfffffa7e = uStack24;
   _loc_AAA = 0xaaaa; // write AAAA to address AAA
   xRam00000554 = 0x5555; // write 5555 to address 554
   param_1[0x555] = 0x3030; // write 3030 to offset 555 inside the block to erase
   uRamffff6d40 = 0;
   sub_D8520();
   iVar1 = sub_D84B8();
   uRamffff6d38 = iVar1 + uRamffff6d38;
   pxRamffff6d3c = (__uint8*)(iVar1 + (int32_t)pxRamffff6d3c);
   uVar2 = sub_D8520();
   uRamffff6d40 = uVar2 + uRamffff6d40;
   if (14999 < uRamffff6d38) {
      xRamfffffa55 = 0xaa; // COP1
      uRamfffffa21 = uRamfffffa21 ^ 0x80; // COP2
      uRamffff6d38 = 0;
   }
   if ((__uint8*)0x3a97 < pxRamffff6d3c) {
      do {
      } while ((uRamfffffe18 & 0x30000000) != 0);
      do {
      } while (true);
   }
   do {
      if (3999999 < uRamffff6d40) {
         halt_unimplemented(); // ghidra dissassembler cant handle the opcodes
      }
      if ((char)*param_1 < '\0') {
         uStack28 = uRamfffffa7e & 0xefff;
         uRamfffffa7e = uStack28;
         return uVar2 & 0xffffff00;
      }
      if ((*param_1 & 0x20) != 0) {
         do {
         } while ((uRamfffffe18 & 0x30000000) != 0);
         do {
         } while (true);
      }
      iVar1 = sub_D84B8();
      uRamffff6d38 = iVar1 + uRamffff6d38;
      pxRamffff6d3c = pxRamffff6d3c + iVar1;
      uVar2 = sub_D8520();
      uRamffff6d40 = uVar2 + uRamffff6d40;
      if (14999 < uRamffff6d38) {
         xRamfffffa55 = 0xaa; // COP1
         uRamfffffa21 = uRamfffffa21 ^ 0x80; // COP2
         uRamffff6d38 = 0;
      }
   } while (pxRamffff6d3c < &loc_3A98);
   do {
   } while ((uRamfffffe18 & 0x30000000) != 0);
   do {
   } while (true);
}
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
Tazzi
Posts: 3626
Joined: Thu May 17, 2012 10:53 am
cars: VE SS Ute
Location: WA

Re: PCM Hammer P12 development

Post by Tazzi »

interesting it actually uses a variable loop for the watchdog. Guess that would be for speed to ensure its not running it none stop for speed purposes?
Your Local Aussie Reverse Engineer
Contact for Software/Hardware development and Reverse Engineering
Site:https://www.envyouscustoms.com
Mob:+61406 140 726
Image
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer P12 development

Post by antus »

Im thinking uRamffff6dx are likely hardware timers, and at this point its keyed off and persisting vin or other persistant changes to the flash and considering the engine is offline and its keyed off they might find it acceptable.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer P12 development

Post by Gampy »

I gotta fess up, I screwed up AGAIN!! and wasted a bunch of time ...

I forgot to give access to the kernel erase routines ...

Code: Select all

///////////////////////////////////////////////////////////////////////////////
// Erase the given block.
///////////////////////////////////////////////////////////////////////////////
void HandleEraseBlock()
{
   unsigned address = (MessageBuffer[5] << 16) + (MessageBuffer[6] << 8) + MessageBuffer[7];
   uint8_t status = 0;

   switch (flashIdentifier)
   {
      case FLASH_ID_INTEL_512:
      case FLASH_ID_INTEL_1024:
         status = Intel_EraseBlock(address);
         break;

      case FLASH_ID_AMD_1024:
+      case FLASH_ID_AMD_AM29BL802C:  // P12 1m
         status = Amd_EraseBlock(address);
         break;

      default:
         VariableSleep(2);
         SendReply(0, 0x05, 0xFF, 0xFF);
         return;
   }

   // The AllPro and ScanTool devices need a short delay to switch from
   // sending to receiving. Otherwise they'll miss the response.
   // Also, give the lock-flash operation time to take full effect, because
   // the signal quality is degraded and the AllPro and ScanTool can't read
   // messages when the PCM is in that state.
   VariableSleep(2);

   SendReply(1, 0x05, status, 0x00);
}
Note the line with the '+' in the left margin.

However it still fails ...

Looking back at a bit of disassembly posted by Antus,

Code: Select all

    ROM:000D885E 3D78 FA7E FFEC                                          move.w  ($FFFFFA7E).w,-$14(a6)
    ROM:000D8864 08EE 0004 FFEC                                          bset    #4,-$14(a6)
    ROM:000D886A 31EE FFEC FA7E                                          move.w  -$14(a6),($FFFFFA7E).w
bset #4 ... Wouldn't that translate to

Code: Select all

#define SIM_CSOR0 0xFFFFFA7E
SIM_CSOR0 |= 0x4;
Log,
[06:13:05:371] Processing range 020000-03FFFF
[06:13:05:382] Erasing.
[06:13:05:394] TX: 6C 10 F0 3D 05 02 00 00
[06:13:07:405] ReadMsgs OBDError: ERR_BUFFER_EMPTY
[06:13:07:406] Sending 'test device present' notification.
[06:13:07:407] TX: 8C FE F0 3F
[06:13:09:416] ReadMsgs OBDError: ERR_BUFFER_EMPTY
[06:13:09:416] Sending 'test device present' notification.
[06:13:09:417] TX: 8C FE F0 3F
[06:13:11:435] ReadMsgs OBDError: ERR_BUFFER_EMPTY
[06:13:11:435] Receive timed out. Attempt #3, Timeout #3.
[06:13:11:436] TX: 6C 10 F0 3D 05 02 00 00
[06:13:11:469] RX: 6C F0 10 7F 3D 05 02 00 00 11
[06:13:11:470] Received an unexpected response. Attempt #1, status Refused.
[06:13:13:475] ReadMsgs OBDError: ERR_BUFFER_EMPTY
[06:13:13:475] Sending 'test device present' notification.
[06:13:13:476] TX: 8C FE F0 3F
[06:13:15:485] ReadMsgs OBDError: ERR_BUFFER_EMPTY
[06:13:15:485] Sending 'test device present' notification.
[06:13:15:486] TX: 8C FE F0 3F
[06:13:17:497] ReadMsgs OBDError: ERR_BUFFER_EMPTY
[06:13:17:497] Receive timed out. Attempt #4, Timeout #3.
[06:13:17:498] Unable to erase flash memory: Error
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!
User avatar
antus
Site Admin
Posts: 10016
Joined: Sat Feb 28, 2009 10:34 am
cars: TX Gemini 2L Twincam 8psi
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Subaru WRX 2007

Re: PCM Hammer P12 development

Post by antus »

Yes, I think you're right on all accounts. I also think we need to rename the old FLASH_ID_AMD and FLASH_ID_INTEL for P01 and P59 to specifically name the chips for clarity going forward.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
User avatar
Gampy
Posts: 2332
Joined: Fri Dec 14, 2018 9:38 pm

Re: PCM Hammer P12 development

Post by Gampy »

Well shit ... Our bench PCM is now spitting out them freaking RX: 6C F0 10 A2 00 messages.

I'd say it really did finally try to erase and failed ...

I'm going to rearrange how PcmHammer handles recovery, to handle recovery first and foremost then move on to normal loading ...
This is something I have considered for a long time, it seems logical to me to first look for recovery messages, then proceed accordingly versus blindly going forth normally and only trying recovery if normal fails.

What else can I do ... Might as well try something, can't hurt.

I am open for suggestions on how we can continue ...
Intelligence is in the details!

It is easier not to learn bad habits, then it is to break them!

If I was here to win a popularity contest, their would be no point, so I wouldn't be here!