I think I'm finally making sense of this thing. I still can't quite square it up with the datasheet, but the code at least makes some logical sense now.
The ME 9.6.1 function reference had this to say about the memory layout.
We know what the 3 data areas are. That's the calibration segments for engine operation, system and speedometer. The two flash areas are likely boot and operating system.E69 and E77 controllers have 3 data areas and only one internal flash. The internal flash however is splitted in two adress areas. This requires the definition of 5 areas in tc9con.h for SY_CVNSIZE=4. The first two areas specify the two code areas of the internal flash. The following three areas define the range of the three data areas.
Then I went and looked at the memory map from the A2L file. I'm pretty sure it's for an E55, but it gave me an idea of how the memory could be split up. It also gave me some ideas about the calibration region and why that doesn't match up.
Combine that with some comments other people have made, and some function pointer tables I found, and this seems to work.
Boot is just empty space since we don't have that. There are cross references into that area though.
Operating system uses data from the bin file. Load the bin file into Ghidra, set the base address to 0x20000, offset to 0x0 and length to 0x1A2000.
Open the file, skip the auto analyze for now, and set the registers as described before.
Now go to File > Add to Program, and select the bin file again. Set the block name to calibration, the base address to 0x5C2000, and the length to 0x3C000. This puts R13 nicely near the beginning of the calibration space.
Create the RAM addresses as shown in the screenshot. I think the ExtRAM might be an EEPROM.
The diagnostic mode table at 0x29194 should give a nice place to start looking at some standardized code. You don't need any weird offsets for the address pointers. They just work as-is. Here's a sample.
Code: Select all
Diag_Mode_tbl1_00029194 XREF[1]: 00029298(*)
00029194 3e ff ff ff undefined4 3EFFFFFFh
00029198 ff ff ff ff undefined4 FFFFFFFFh
0002919c 00 0f 1f c8 addr Diag_Mode3E_000f1fc8
000291a0 00 00 00 00 undefined4 00000000h
000291a4 00 00 00 00 undefined4 00000000h
000291a8 1a 81 ff ff undefined4 1A81FFFFh
000291ac ff ff ff ff undefined4 FFFFFFFFh
000291b0 00 08 48 e0 addr Diag_Mode1A_ECUID_000848e0
000291b4 00 00 00 00 undefined4 00000000h
000291b8 00 00 00 00 undefined4 00000000h
000291bc 1a 8e ff ff undefined4 1A8EFFFFh
000291c0 ff ff ff ff undefined4 FFFFFFFFh
000291c4 00 08 48 e0 addr Diag_Mode1A_ECUID_000848e0
000291c8 00 00 00 00 undefined4 00000000h
000291cc 00 00 00 00 undefined4 00000000h
000291d0 1a ff ff ff undefined4 1AFFFFFFh
000291d4 ff ff ff ff undefined4 FFFFFFFFh
000291d8 00 0f 07 38 addr Diag_Mode1A_general_000f0738
000291dc 00 00 00 00 undefined4 00000000h
000291e0 00 00 00 00 undefined4 00000000h
