okay so i guess it dosent matter which bin we use anyway as the boot is ff or nonexistent between the two, only thing thatll make it easier using the new one, is that the cal dosent start at 1A2000, we can go to the offset/base address everyone uses 1C2000/5C2000 as it has that 20000 already. but not hard to use the old one anyway.
but everything your saying about the cal segment makes sense.
and yeah im trying not to get caught up with info from the e55 or other bosch ecu's, but if i do find anything of interest ill let you guys know incase it helps.
and if you could send that function sheet that would be awesome, i thought i struck gold when i found the link but saw it was expired ahaha
and kur4o thanks for those files, i havent looked at the e69 diss yet, but i wonder becuase as you were saying the e77 seems to be the "little sister" to the e69, if concepts from the e69 would translate over to the e77.
and i noticed your bin that you said says "me9.6.1 MPC561", im guessing thats a e69 bin?
also this dual mapping i tried to look into it but couldnt fully understand it, from what i got it can map certain parts of the internal flash to an external area, but also only works in a small range in the beginning of the flash.
and i know i keep saying it but i really appreciate the support and all the help, theres no way i would of gotten even close to the amount of work you guys have done
Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
-
Lucasperks06
- Posts: 42
- Joined: Tue Jun 09, 2026 8:09 am
- cars: Cammed ve alloytec
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
You do not have the required permissions to view the files attached to this post.
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
I think I've pretty conclusively nailed down the memory map when the ECU is running. I went and picked up an E77 out of an 08 Equinox (service PN 12623327) this weekend and ran some mode 23 memory tests on it.
I checked the calibrations using the normal GM 1A diagnostic commands and verified they were the latest for that car.
12619585 OS
12622676 Engine
12621261 System
12622677 Speedo
So then I used mode 23 to read the raw calibration part numbers from where we'd expect them to be in the memory space. Everything matched up. Calibration part numbers were returned in ASCII and matched what I expected based on the mode 1A output.
This tells us the OS and calibration segment headers are exactly where we expect them to be.
The bootloader region is blocked from mode 23 reads BTW. I'm pretty sure I know how to patch the OS to get around that. I have a few other things to try first though.
If I did my homework right, I should be able to flash this with the same OS and calibrations Lucasperks06 is using. He's got a different hardware service number than what I have. I'm hoping it'll be similar enough that it'll at least boot up and work for bench testing.
At some point I may take this apart and try to dump the raw flash chip, but that'll be further down the road.
I checked the calibrations using the normal GM 1A diagnostic commands and verified they were the latest for that car.
12619585 OS
12622676 Engine
12621261 System
12622677 Speedo
So then I used mode 23 to read the raw calibration part numbers from where we'd expect them to be in the memory space. Everything matched up. Calibration part numbers were returned in ASCII and matched what I expected based on the mode 1A output.
Code: Select all
>23 00020005 0008
7E8 10 0D 63 00 02 00 05 31
7E8 21 32 36 31 39 35 38 35
>23 005c2005 0008
7E8 10 0D 63 00 5C 20 05 31
7E8 21 32 36 32 32 36 37 36
>23 005ecf2d 0008
7E8 10 0D 63 00 5E CF 2D 31
7E8 21 32 36 32 31 32 36 31
>23 005eef1d 0008
7E8 10 0D 63 00 5E EF 1D 31
7E8 21 32 36 32 32 36 37 37
The bootloader region is blocked from mode 23 reads BTW. I'm pretty sure I know how to patch the OS to get around that. I have a few other things to try first though.
If I did my homework right, I should be able to flash this with the same OS and calibrations Lucasperks06 is using. He's got a different hardware service number than what I have. I'm hoping it'll be similar enough that it'll at least boot up and work for bench testing.
At some point I may take this apart and try to dump the raw flash chip, but that'll be further down the road.
-
hjtrbo
- Posts: 353
- Joined: Tue Jul 06, 2021 8:57 am
- cars: VF2 R8 LSA
FG XR6T
HJ Ute w/RB25DET
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
That is conclusive evidence. Very nice sir!
-
Lucasperks06
- Posts: 42
- Joined: Tue Jun 09, 2026 8:09 am
- cars: Cammed ve alloytec
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
this is awesome news thanks so much man.
and also the photos of the ecu i sent on the last page are not my ecu, its from an earlier e77, i can get a photo of mine if need be but thought id clear that up just incase there was any confusion about the hardware service number.
but im very keen on any updates

and also the photos of the ecu i sent on the last page are not my ecu, its from an earlier e77, i can get a photo of mine if need be but thought id clear that up just incase there was any confusion about the hardware service number.
but im very keen on any updates
-
kur4o
- Posts: 1145
- Joined: Sun Apr 10, 2016 11:20 am
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
Just a warning that these bosch POS have some hidden checksums,Gatecrasher wrote: Mon Jun 22, 2026 4:29 am
The bootloader region is blocked from mode 23 reads BTW. I'm pretty sure I know how to patch the OS to get around that. I have a few other things to try first though.
Range is infront of checksum pairs.
Code: Select all
Searching Bosch Inv checksum addresses...
Address: 000A0008: 139069C8 EC6F9637
Address: 000A0018: 178BCC6B E8743394
Address: 000A0028: 2080DEB0 DF7F214F
Address: 000A0038: 1131B9D6 EECE4629
Address: 000A0048: 112E600F EED19FF0
Address: 000A0058: 12DD9BC0 ED22643F
Address: 000A0068: 128C7D9D ED738262
Address: 000A0078: 12013AB5 EDFEC54A
Address: 000A0088: 11F43291 EE0BCD6E
Address: 000A0098: 121BC8C8 EDE43737
Address: 000A00A8: 224394B7 DDBC6B48
Address: 000A00B8: 3FFFC000 C0003FFF
Address: 000A00C8: 3FFFC000 C0003FFF
Address: 000A00D8: 135BDE7D ECA42182
Address: 000A00E8: 1135EC63 EECA139C
Address: 000A00F8: 10A43C5A EF5BC3A5
Address: 000A0108: 3B97CBF2 C468340D
Address: 000A0118: 126AB918 ED9546E7
Address: 000A0128: 133CEB59 ECC314A6
Address: 000A0138: 126A3226 ED95CDD9
Address: 000A0148: 16767E6C E9898193
Address: 000A0158: 160EEC89 E9F11376
Address: 000A0168: 146A75D5 EB958A2A
Address: 000A0178: 1546195A EAB9E6A5
Address: 000A0188: 16A18A92 E95E756D
Address: 000A0198: 161E8893 E9E1776C
Address: 000A01A8: 15FD8672 EA02798D
Address: 000A01B8: 1390833E EC6F7CC1
Address: 000A01C8: 14CF17AA EB30E855
Address: 000A01D8: 1573814A EA8C7EB5
Address: 000A01E8: 13D04FDD EC2FB022
Address: 000A01F8: 1395AD20 EC6A52DF
Address: 000A0208: 12909F3B ED6F60C4
Address: 000A0218: 12F4FE4C ED0B01B3
Address: 000A0228: 126768A2 ED98975D
Address: 000A0238: 135F156E ECA0EA91
Address: 000A0248: 11DE24CF EE21DB30
Address: 000A0258: 12999250 ED666DAF
Address: 000A0268: 126CB77A ED934885
Address: 000A0278: 130994E8 ECF66B17
Address: 000A0288: 1396A70B EC6958F4
Address: 000A0298: 12D85E76 ED27A189
Address: 000A02A8: 13FFB414 EC004BEB
Address: 000A02B8: 14D2DEB0 EB2D214F
Address: 000A02C8: 13F0DF0A EC0F20F5
Address: 000A02D8: 156521DD EA9ADE22
Address: 000A02E8: 1697B889 E9684776
Address: 000A02F8: 150D6B1B EAF294E4
Address: 000A0308: 146456BF EB9BA940
Address: 000A0318: 28AA3C45 D755C3BA
Address: 000A0328: 3FFFC000 C0003FFF
Address: 000A0338: 1FFFE000 E0001FFF
Address: 000A0348: 1FFFE000 E0001FFF
Address: 000A0358: 3FFCBF99 C0034066
Address: 000A0368: 7EB0D1AC 814F2E53
Address: 001C3418: 008CDDB4 FF73224B
Address: 001C3428: 0095C412 FF6A3BED
Address: 001C3438: 16CEF730 E93108CF
Address: 001C3448: 98AE44BE 6751BB41
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
I knew the Germans liked their checksums, but I didn't know it was that bad. 
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
I also found this. It's the boundaries for the GM checksums. I don't know why it's got the raw flash addresses instead of the mapped addresses, nor do I know how it switches reading between the two. That's part of the mystery that needs to be solved. It's part of mode 36 and that operates during special conditions, so I'm sure that's part of it.
Code: Select all
pChksum_start_addr XREF[2]: Diag_Mode36_do_GM_checksum_00087
Diag_Mode36_do_GM_checksum_00087
00088d98 00 02 00 02 undefined4 00020002h OS block, GM checksum range start
pChksum_end_addr XREF[2]: Diag_Mode36_do_GM_checksum_00087
Diag_Mode36_do_GM_checksum_00087
00088d9c 00 1f ff ff undefined4 001FFFFFh OS block, GM checksum range end
pChksum_loc_addr XREF[1]: Diag_Mode36_do_GM_checksum_00087
00088da0 00 02 00 00 addr Segment_00020000_OS OS block, GM checksum location
00088da4 00 1c 20 02 undefined4 001C2002h Engine op cal, GM checksum range start
00088da8 00 1e cf 27 undefined4 001ECF27h Engine op cal, GM checksum range start
00088dac 00 1c 20 00 undefined4 001C2000h Engine op cal, GM checksum location
00088db0 00 1e cf 2a undefined4 001ECF2Ah System cal, GM checksum range start
00088db4 00 1e ef 17 undefined4 001EEF17h System cal, GM checksum range end
00088db8 00 1e cf 28 undefined4 001ECF28h System cal, GM checksum location
00088dbc 00 1e ef 1a undefined4 001EEF1Ah Speedo cal, GM checksum range start
00088dc0 00 1e ff ff undefined4 001EFFFFh Speedo cal, GM checksum range end
00088dc4 00 1e ef 18 undefined4 001EEF18h Speedo cal, GM checksum location
-
kur4o
- Posts: 1145
- Joined: Sun Apr 10, 2016 11:20 am
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
Interesting find. I did look for such table but never found it. It can be used for GM checksums,
First you do bosch checksums, some are inclusive of range and it was nightmare to figure how it is calculated. Than on top of it you fix GM checksums.
If you manage to find some references to bosch checksum tables will be great find, and finally some full support can be added for checksums.
First you do bosch checksums, some are inclusive of range and it was nightmare to figure how it is calculated. Than on top of it you fix GM checksums.
If you manage to find some references to bosch checksum tables will be great find, and finally some full support can be added for checksums.
-
Gatecrasher
- Posts: 435
- Joined: Fri Apr 24, 2020 8:09 pm
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
I think I've got a strong start into figuring the checksums out. There's one really tricky bit though. At least one block is recursive. The checksummed area includes the checksum itself.
With that said, I'm not sure it matters on this ECM. It looks like the crazy Bosch checksums only apply to the OS and bootloader. You'd only need it if you were doing a custom OS. The calibration segments only seem to use the GM checksums and OBD2 CVNs. I might still try to figure it out though.
I'm really interested in bench service mode too.
With that said, I'm not sure it matters on this ECM. It looks like the crazy Bosch checksums only apply to the OS and bootloader. You'd only need it if you were doing a custom OS. The calibration segments only seem to use the GM checksums and OBD2 CVNs. I might still try to figure it out though.
I'm really interested in bench service mode too.
-
kur4o
- Posts: 1145
- Joined: Sun Apr 10, 2016 11:20 am
Re: Help Getting Started With Ghidra For MPC562 ME9.6.1 VE E77 LY7
These are part of the cal area
Address: 001C3418: 008CDDB4 FF73224B
Address: 001C3428: 0095C412 FF6A3BED
Address: 001C3438: 16CEF730 E93108CF
Address: 001C3448: 98AE44BE 6751BB41
When you sum both checksum and add 1 you got 00 for result. First 4 bytes are sum of range second 4 bytes are complement of first 4 bytes. Inclusive range was something stupid to figure, but did some headache first.
If ranges are not that much UP can have the ranges hardcoded to do.
The main issue I had is figure xreferences to these tables so the address of them is easily identifiable by code lookup. Still no clue about it.
Address: 001C3418: 008CDDB4 FF73224B
Address: 001C3428: 0095C412 FF6A3BED
Address: 001C3438: 16CEF730 E93108CF
Address: 001C3448: 98AE44BE 6751BB41
When you sum both checksum and add 1 you got 00 for result. First 4 bytes are sum of range second 4 bytes are complement of first 4 bytes. Inclusive range was something stupid to figure, but did some headache first.
If ranges are not that much UP can have the ranges hardcoded to do.
The main issue I had is figure xreferences to these tables so the address of them is easily identifiable by code lookup. Still no clue about it.