docs/CONTEXT.md captures the entire reverse-engineering effort in one place: KWP2000 protocol, AES-128 seed/key, the map format (dc decrypt -> flat-ROM unpack -> directory -> fe table pointers), the fuel/ignition table map, the validated SAI/O2 device flags, checksums, hardware, and a per-finding confidence table. docs/ROADMAP.md covers open-sourcing (legal/IP posture on proprietary maps and the AES keys, repo hygiene, packaging/CI, community) and the technical path to tuning the bike (first contact -> ROM dump -> calibration model -> write path -> editor), with immediate next steps and a risk register. Top-level README refreshed to describe the whole project (tool + viewer + research) and point at docs/.
54 lines
2.8 KiB
Markdown
54 lines
2.8 KiB
Markdown
# tunie
|
|
|
|
Open, offline tooling for the **Triumph Keihin ECU** (2010 Bonneville T100, 865cc,
|
|
Renesas SH7054, mechanical odometer) — a from-scratch, reverse-engineered
|
|
alternative to the closed TuneECU app. Read the ECU, decode and view its
|
|
fuel/ignition maps, understand the device flags, and (eventually) tune it.
|
|
|
|
> **Independent interoperability research on hardware I own.** Contains no TuneECU
|
|
> source — only original code and documented findings. Proprietary map binaries are
|
|
> never committed (see `.gitignore`).
|
|
|
|
## What's here
|
|
|
|
- **`src/tunie/`** — a **read-only** KWP2000 diagnostic tool (K-Line/FTDI or
|
|
Bluetooth ELM327). Cannot write to the ECU by construction; `safety.py` refuses
|
|
every flash service before it hits the wire. `pip install -e .`, then `tunie info
|
|
--port …`. Verified frames in `tests/verify_protocol.py`.
|
|
- **`viewer/tunie-viewer.html`** — a self-contained page (no server, no deps) that
|
|
drops in a real map `.hex`, **decrypts and unpacks it, and renders the real
|
|
fuel/ignition tables** with RPM/throttle axes, an A→B diff, and SAI/O2 device
|
|
checkboxes. Build with `viewer/build_viewer.py`; `download_maps.py` + `serve.py`
|
|
add a catalogue dropdown.
|
|
- **`research/`** — the reverse engineering: AES-128 seed/key
|
|
(`keihin_seedkey.py`), and the map format — decrypt, flat-ROM unpack, table map,
|
|
and validated SAI/O2 flags (`reference-maps/`).
|
|
- **`docs/`** — start here for the full picture.
|
|
|
|
## Read the docs
|
|
|
|
- **[docs/CONTEXT.md](docs/CONTEXT.md)** — everything reverse-engineered and built,
|
|
with per-finding confidence levels. The one file to read.
|
|
- **[docs/ROADMAP.md](docs/ROADMAP.md)** — open-sourcing plan + the technical path to
|
|
actually tuning the bike + next steps + risk register.
|
|
- `STATUS.md`, `viewer/FORMAT.md`, `research/FINDINGS.md`,
|
|
`research/reference-maps/{README,TABLES,DEVICES}.md` — deeper per-topic writeups.
|
|
|
|
## Status (short version)
|
|
|
|
Software + reverse engineering are well along and **validated against real map
|
|
files**: the protocol, the AES seed/key, the map decryption, the flat-ROM unpack,
|
|
the fuel/ignition table locations, and the SAI (confirmed) / O2 (probable) device
|
|
flags. **Nothing has touched the real ECU yet** — first contact is blocked on
|
|
wiring a cable to the Triumph diagnostic connector. The write/flash path is future
|
|
work (see the roadmap).
|
|
|
|
## Safety
|
|
|
|
- The diagnostic tool is read-only; it can't brick the ECU.
|
|
- The **real** risk is electrical: confirm the Triumph connector pinout before
|
|
plugging any cable in (the 2010 twins don't use a standard OBD-II socket).
|
|
- Device flags are **not** a tune on their own — disabling O2 forces open-loop and
|
|
needs matching fuel enrichment. Prefer flashing a complete, matching delete map
|
|
over hand-toggling a stock one. See `docs/CONTEXT.md` §7.
|