Add validated SAI/O2 device-flag checkbox editor
Reversed the device-flag mechanism (l.java lc() + ee bit logic) and validated the flag locations against a real reference map: 20188Map2009AIRBOXBONNY (explicitly "NO SAI, NO O2 SENSORS"). Diffing its flat ROM vs stock 20188 isolated exactly three byte-boolean flags that flip 1->0: 0x53801 SAI (= base + fe[33] + 0x00) 0x53818 O2 sensor (+ 0x17) 0x53819 O2 sensor (2) (+ 0x18) 1 = enabled, 0 = disabled. Neither stock map could reveal these (both have SAI+O2 on); the delete map was the key. See research/reference-maps/DEVICES.md. Viewer: the Triumph-tables tab now has a Device flags panel — checkboxes reflect the loaded map's real state (stock: all on; delete map: all off), toggling flips the byte, and "Export edited .hex" re-encodes the distribution format. The decode->edit->encode round-trip is byte-exact (verified). The caXX header bytes are map-ID metadata, not a cal checksum; the ECU-flash checksum is applied at write time.
This commit is contained in:
52
tunie/research/reference-maps/DEVICES.md
Normal file
52
tunie/research/reference-maps/DEVICES.md
Normal file
@@ -0,0 +1,52 @@
|
||||
# Device-enable flags (SAI / O2 / lambda) — validated
|
||||
|
||||
## How they were found
|
||||
|
||||
Both stock reference maps (20187, 20188) have SAI and O2 **active**, so diffing
|
||||
them can't reveal the delete flags. The confirmation came from a community map
|
||||
that explicitly disables them:
|
||||
|
||||
`20188Map2009AIRBOXBONNY.hex` — "Bonneville, aftermarket exhaust, mechanical
|
||||
odometer, NO AIR BOX, K&N, British Custom mufflers, **NO SAI, NO O² SENSORS**".
|
||||
Same base as stock 20188, so the diff isolates the deletes.
|
||||
|
||||
Diff (flat ROM) of that map vs stock 20188 = 0.36%, split into:
|
||||
- the fuel tables (airbox/K&N enrichment — expected), and
|
||||
- a small cluster in the device-config region at **0x53801…0x53819**.
|
||||
|
||||
## The flags
|
||||
|
||||
They are a **byte-boolean array** at flat-ROM `base + fe[33]` (= `0x50000 + 0x3801
|
||||
= 0x53801`), one byte per device, **1 = enabled, 0 = disabled**.
|
||||
|
||||
The delete map changed exactly three bytes from 1 → 0:
|
||||
|
||||
| Flat-ROM offset | Stock | Deleted | Device |
|
||||
|---|---|---|---|
|
||||
| `0x53801` | 1 | 0 | **SAI** (Secondary Air Injection) |
|
||||
| `0x53818` | 1 | 0 | **O2 sensor** |
|
||||
| `0x53819` | 1 | 0 | **O2 sensor (2)** |
|
||||
|
||||
SAI is the first flag in the array; the two O2 sensors are the last two —
|
||||
consistent with the `Devices` resource order (SAI = index 0; O2 Sensor / O2
|
||||
Sensor (2)). The three-byte change matching "NO SAI, NO O²" is unambiguous.
|
||||
|
||||
To disable a device: set its byte to `0`. (The `0x5369C`/`0x536AB` bytes that
|
||||
also changed are idle/open-loop trim that comes with removing the O2 feedback,
|
||||
not device-enable flags.)
|
||||
|
||||
## Editing / export
|
||||
|
||||
The downloaded `.hex` format's integrity is the `dc` stream cipher + the unpack
|
||||
directory; the `caXX` bytes in the header/tail are map-ID metadata, **not** a
|
||||
calibration checksum. So a device toggle = flip the byte in the flat ROM, re-pack
|
||||
to the decoded layout, and `dc`-encode back to `.hex`. (The separate *ECU flash*
|
||||
checksum is computed at flash time and is out of scope for the read/edit tool.)
|
||||
|
||||
## Confidence
|
||||
|
||||
- Flag **locations** (0x53801 / 0x53818 / 0x53819) and semantics (1/0): **validated**
|
||||
against a real NO-SAI-NO-O2 map.
|
||||
- SAI-vs-O2 **labeling** of the three bytes: strong (order + delete semantics);
|
||||
final SAI-only-vs-O2-only separation would need a single-delete reference map or
|
||||
a DTC/bench check.
|
||||
Reference in New Issue
Block a user