Commit tune maps and research so tunes are reachable from the phone

Removes the *.hex/maps_cache gitignore rule (explicit user call, reversing
the earlier no-redistribution stance) so the official TuneECU catalogue
maps, derived SAI/O2-delete composites, and the checksum/composition
tooling are actually available to pull up on a phone browser when using
the real TuneECU app. Also folds in tonight's KWP2000 fixes (TesterPresent
keep-alive, connect-failure cleanup, slow-init StartCommunication fix) and
the accumulated research docs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FP2GaxS9HkUdL5sLBnjKje
This commit is contained in:
2026-08-27 01:34:05 -05:00
parent 587f75eab4
commit 4aa5da53d2
98 changed files with 4148 additions and 49 deletions

View File

@@ -74,6 +74,19 @@ Ordered by dependency. Phases 1–2 are safe reads; 3+ is the write path.
- Cross-check the dump against our decrypt/unpack: a stock dump should reconstruct
to the same flat ROM as the matching `.hex`, validating the whole pipeline on the
real bike's data.
- **Before implementing this ourselves, reverse-engineer TuneECU's own Recovery
mode first** (Aug 2026 finding, `../research/TUNING_IMPL_PLAN.md`): TuneECU has
a dedicated Recovery function (`menu_recovery` in the decompile, dispatched
through the same mode-switch machinery as the rest of `m.java`'s `Ue()`), with a
multi-year, multi-ECU-family bug-fix history in the app's own changelog (5DM/7SM,
Dorsoduro/Shiver 750, Walbro, Ducati recovery bugs fixed 2019-2021) — real
evidence this isn't a trivial retry loop, it's hardened against failure modes
only discoverable across many real units. Extracting and understanding that
procedure statically, before ever attempting our own upload/write path on the
one ECU we have, meaningfully de-risks this phase. **Near-term (not blocked on
this):** use TuneECU's own app's "Read Map" for the actual first dump — this
reverse-engineering is prep for when `tunie` builds its own upload path for
real, not a prerequisite for getting one file off the bike today.
### B3. Finish the calibration model
- **Absolute scaling** for fuel and ignition (units), via an XDF cross-check (~€70
@@ -89,7 +102,28 @@ Ordered by dependency. Phases 1–2 are safe reads; 3+ is the write path.
the strongest lead. `miikasyvanen/FastECU` shows a full end-to-end flow.
- Finish **seed/key**: which of the 3 AES keys + the seed-block padding (one
captured pair from the bike/logging APK settles it).
- **ECU flash checksum** at write time.
- ~~**ECU flash checksum** at write time.~~ **Solved, Aug 2026** — see
`../research/reference-maps/checksum.py`. 16-bit sum-of-words over the
flat-ROM calibration region (`0x50000`-`0x60000`, the same range this
project's own `table_map.py` already uses), stored in the region's last 2
bytes. Validated against 6 real, unmodified, official downloads —
computed matches stored, exact, every time. **Caveat that keeps this from
being "done done":** this is the *app-side* checksum TuneECU computes for
its own map-info display (flags "*No-OEM"/"Error" on mismatch) —
confirmed it's not a hard gate on its own, since a real community file
with a stale (unrecomputed) checksum apparently still worked for people.
Whether the ECU's own bootloader *also* independently verifies something
during the actual `0x36` TransferData sequence is a separate, still-open
question — this solves "how do I produce a checksum TuneECU accepts as
valid," not necessarily "the ECU's own integrity check."
- **Head start already done (Aug 2026):** `../research/WRITE_PATH.md` traced
TuneECU's actual shared write/reprogram routine from the mode-flag entry
point down through the connection/retry driver into a 5-baud slow-init
bit-bang for the Triumph K-line address (`0xD5`) — real protocol detail,
not a plan. Traced as far as the post-slow-init handoff (unopened). Read
that before starting this section for real; it's ahead-of-time
reconnaissance done opportunistically while tracing Recovery mode
(`../research/RECOVERY_MODE.md`), not yet validated against a live ECU.
- **Recovery**: `v-ladimir/audprog` (AUD debugger) for SH705x un-brick via the PCB
debug pins — mandatory backstop when developing a flasher.
- Develop against a **spare/bench ECU**, on a stable supply, never the bike's only