BA/BF/FG PCM in Ghidra

Ford information and tools can be found here
User avatar
pman92
Posts: 667
Joined: Thu May 03, 2012 12:50 pm
Location: Castlemaine, Vic

BA/BF/FG PCM in Ghidra

Post by pman92 »

I've been playing around with BA/BF/FG stuff in Ghidra recently and thought I would post up a very basic getting started guide. Until recently I had never used ghidra or done any disassembly and I'm surprised how easy it actually was once I jumped in (its just very very time consuming).

I've attached 2x .pspec files I created for MPC555 (BA 1472k black oak) and MPC565 (BF/FG 1024k spanish oak).
These are just copies of the ppc 32bit big endian with memory blocks defined, which makes it quicker and easier to open and analyze new files.

These need to go into the ghidra install directory > Ghidra > Processors > PowerPC > data > languages folder.
You'll also need to edit the "ppc.ldefs" file in the same directory, and add them in there as well:

Code: Select all

  <language processor="PowerPC"
            endian="big"
            size="32"
            variant="MPC555"
            version="1.6"
            slafile="ppc_32_be.sla"
            processorspec="ppc_32_mpc555.pspec"
            manualindexfile="../manuals/PowerPC.idx"
            id="PowerPC:BE:32:MPC555">
    <description>NXP MPC555 32-bit big endian</description>
    <compiler name="default" spec="ppc_32_be.cspec" id="default"/>
    <external_name tool="gnu" name="powerpc:MPC5XX"/>
    <external_name tool="IDA-PRO" name="ppc"/>
    <external_name tool="DWARF.register.mapping.file" name="ppc.dwarf"/>
    <external_name tool="qemu" name="qemu-ppc"/>
    <external_name tool="qemu_system" name="qemu-system-ppc"/>
  </language>

  <language processor="PowerPC"
            endian="big"
            size="32"
            variant="MPC565"
            version="1.6"
            slafile="ppc_32_be.sla"
            processorspec="ppc_32_mpc565.pspec"
            manualindexfile="../manuals/PowerPC.idx"
            id="PowerPC:BE:32:MPC565">
    <description>NXP MPC565 32-bit big endian</description>
    <compiler name="default" spec="ppc_32_be.cspec" id="default"/>
    <external_name tool="gnu" name="powerpc:MPC5XX"/>
    <external_name tool="IDA-PRO" name="ppc"/>
    <external_name tool="DWARF.register.mapping.file" name="ppc.dwarf"/>
    <external_name tool="qemu" name="qemu-ppc"/>
    <external_name tool="qemu_system" name="qemu-system-ppc"/>
  </language>

Once you've imported the binary, don't analyze the file yet. The first step is to find and set the r2/r13 TOC/SDA registers.
They're very easy to find:
- go to (press "G") address 10000. This is the start of the actual strategy contents. Everything before this is the bootloader and cannot be written over OBD.
- hit "D" to disassemble. You should see 4 instructions which are loading an address into the CTR register and branching to it.
- double click the branch instruction to follow it. About a dozen lines down you will see the r2/r13 register initialization, eg:

Code: Select all

        00018e84 3c 40 00 0e     lis        r2,0xe
        00018e88 38 42 76 a0     addi       r2,r2,0x76a0                                     R2 = "0xE0000+0x76A0" = E76A0
        00018e8c 3d a0 00 40     lis        r13,0x40
        00018e90 39 ad f0 00     subi       r13,r13,0x1000                                   R13 = "0x40000-0x1000" = 0x3FF000 
Ctrl+A to select all, Right click > set register value.
Set r2 and r13 to the values you found.

From there you're pretty much setup and ready to go.

Once thing I am not completely sure about is the memory layout for 1472k black oak (I've mainly been playing with spanish).
All the datasheets I can find indicate MPC555 has 448k of flash memory, obviously these have 1mb more. You'll find my pspec file above doesn't account for this.
You'll also see them referencing RAM addresses outside / above where the datasheet indicates RAM is.
Maybe someone else knows exactly how memory regions should be configured for 1472k black oak?
You do not have the required permissions to view the files attached to this post.
hjtrbo
Posts: 353
Joined: Tue Jul 06, 2021 8:57 am
cars: VF2 R8 LSA
FG XR6T
HJ Ute w/RB25DET

Re: BA/BF/FG PCM in Ghidra

Post by hjtrbo »

Very cool, thank you. Tested it out on a virgin Spanish Oak bin and it works as advertised
User avatar
AngelMarc
Posts: 612
Joined: Sat Apr 08, 2023 11:23 am
cars: A CB450 running to 8,000RPM with a P59.

Re: BA/BF/FG PCM in Ghidra

Post by AngelMarc »

Something to look into for NGC4 when I have enough free time to devote the brain power and struggle through.
Don't stress specific units.
SoullessShadow
Posts: 91
Joined: Fri Jan 11, 2019 6:15 am
cars: Ba Futura Wagon - Been turboed since 2009
3 x Celica GT4s 1 is a Group A
ST141 Corona - 3sgte swap is planned
EP71 Toyota Starlet Turbo S
A few e36 BMW's
Location: Victoria

Re: BA/BF/FG PCM in Ghidra

Post by SoullessShadow »

I just happened to be playing around with Ghidra already and some raw bins I was able to pull from my car and come across this thread.

Every time I edit the directory to add these .pspec it either doesnt show or breaks the directory for PowerPC altogether.

I must be messing something up. It is late but seems a simply copy paste job :comp:
peter351
Posts: 24
Joined: Mon Nov 09, 2015 6:04 am

Re: BA/BF/FG PCM in Ghidra

Post by peter351 »

pman92 wrote: Sat Jul 19, 2025 8:37 am I've been playing around with BA/BF/FG stuff in Ghidra recently and thought I would post up a very basic getting started guide. Until recently I had never used ghidra or done any disassembly and I'm surprised how easy it actually was once I jumped in (its just very very time consuming).

I've attached 2x .pspec files I created for MPC555 (BA 1472k black oak) and MPC565 (BF/FG 1024k spanish oak).
These are just copies of the ppc 32bit big endian with memory blocks defined, which makes it quicker and easier to open and analyze new files.

These need to go into the ghidra install directory > Ghidra > Processors > PowerPC > data > languages folder.
You'll also need to edit the "ppc.ldefs" file in the same directory, and add them in there as well:

Code: Select all

  <language processor="PowerPC"
            endian="big"
            size="32"
            variant="MPC555"
            version="1.6"
            slafile="ppc_32_be.sla"
            processorspec="ppc_32_mpc555.pspec"
            manualindexfile="../manuals/PowerPC.idx"
            id="PowerPC:BE:32:MPC555">
    <description>NXP MPC555 32-bit big endian</description>
    <compiler name="default" spec="ppc_32_be.cspec" id="default"/>
    <external_name tool="gnu" name="powerpc:MPC5XX"/>
    <external_name tool="IDA-PRO" name="ppc"/>
    <external_name tool="DWARF.register.mapping.file" name="ppc.dwarf"/>
    <external_name tool="qemu" name="qemu-ppc"/>
    <external_name tool="qemu_system" name="qemu-system-ppc"/>
  </language>

  <language processor="PowerPC"
            endian="big"
            size="32"
            variant="MPC565"
            version="1.6"
            slafile="ppc_32_be.sla"
            processorspec="ppc_32_mpc565.pspec"
            manualindexfile="../manuals/PowerPC.idx"
            id="PowerPC:BE:32:MPC565">
    <description>NXP MPC565 32-bit big endian</description>
    <compiler name="default" spec="ppc_32_be.cspec" id="default"/>
    <external_name tool="gnu" name="powerpc:MPC5XX"/>
    <external_name tool="IDA-PRO" name="ppc"/>
    <external_name tool="DWARF.register.mapping.file" name="ppc.dwarf"/>
    <external_name tool="qemu" name="qemu-ppc"/>
    <external_name tool="qemu_system" name="qemu-system-ppc"/>
  </language>

Once you've imported the binary, don't analyze the file yet. The first step is to find and set the r2/r13 TOC/SDA registers.
They're very easy to find:
- go to (press "G") address 10000. This is the start of the actual strategy contents. Everything before this is the bootloader and cannot be written over OBD.
- hit "D" to disassemble. You should see 4 instructions which are loading an address into the CTR register and branching to it.
- double click the branch instruction to follow it. About a dozen lines down you will see the r2/r13 register initialization, eg:

Code: Select all

        00018e84 3c 40 00 0e     lis        r2,0xe
        00018e88 38 42 76 a0     addi       r2,r2,0x76a0                                     R2 = "0xE0000+0x76A0" = E76A0
        00018e8c 3d a0 00 40     lis        r13,0x40
        00018e90 39 ad f0 00     subi       r13,r13,0x1000                                   R13 = "0x40000-0x1000" = 0x3FF000 
Ctrl+A to select all, Right click > set register value.
Set r2 and r13 to the values you found.

From there you're pretty much setup and ready to go.

Once thing I am not completely sure about is the memory layout for 1472k black oak (I've mainly been playing with spanish).
All the datasheets I can find indicate MPC555 has 448k of flash memory, obviously these have 1mb more. You'll find my pspec file above doesn't account for this.
You'll also see them referencing RAM addresses outside / above where the datasheet indicates RAM is.
Maybe someone else knows exactly how memory regions should be configured for 1472k black oak?


Hi Pman92, nice work pman92 any further updates on "BA/BF/FG PCM in Ghidra " ?

You have a wide audience, over 2197 views following this post only.

Cheers
User avatar
pman92
Posts: 667
Joined: Thu May 03, 2012 12:50 pm
Location: Castlemaine, Vic

Re: BA/BF/FG PCM in Ghidra

Post by pman92 »

SoullessShadow wrote: Thu Sep 17, 2026 2:35 pm I just happened to be playing around with Ghidra already and some raw bins I was able to pull from my car and come across this thread.

Every time I edit the directory to add these .pspec it either doesnt show or breaks the directory for PowerPC altogether.

I must be messing something up. It is late but seems a simply copy paste job :comp:
They aren't compatible with the latest version of ghidra. Compare them to the latest ppc pspec files supplied with ghidra, you will see the parts I added. It isn't much and you'll be able to copy them over fairly easily
SoullessShadow
Posts: 91
Joined: Fri Jan 11, 2019 6:15 am
cars: Ba Futura Wagon - Been turboed since 2009
3 x Celica GT4s 1 is a Group A
ST141 Corona - 3sgte swap is planned
EP71 Toyota Starlet Turbo S
A few e36 BMW's
Location: Victoria

Re: BA/BF/FG PCM in Ghidra

Post by SoullessShadow »

Yep okay completely spaced on that. Pretty sure I've managed to port those settings into the new version. I'm specifically looking at Black Oak stuff as that's what's in my car.

Would the .pspec file not being setup for the 1472k black oak stop me from being able to find the r2/r13 TOC/SDA registers at 10000??

when I try to find them I dont seem to get a clean lis,addi - lis,subi for r2 or 13

get some li, addi for r0 and r30 but yeah im sure im doing something incorrect this isn't exactly something I have enough knowledge on to troubleshoot very well