Files
samplez/tunie/research/reference-maps/DEVICES.md
uhryniuk eaa804fc35 Add validated SAI/O2 device-flag checkbox editor
Reversed the device-flag mechanism (l.java lc() + ee bit logic) and validated the
flag locations against a real reference map: 20188Map2009AIRBOXBONNY (explicitly
"NO SAI, NO O2 SENSORS"). Diffing its flat ROM vs stock 20188 isolated exactly
three byte-boolean flags that flip 1->0:

  0x53801  SAI            (= base + fe[33] + 0x00)
  0x53818  O2 sensor      (+ 0x17)
  0x53819  O2 sensor (2)  (+ 0x18)

1 = enabled, 0 = disabled. Neither stock map could reveal these (both have SAI+O2
on); the delete map was the key. See research/reference-maps/DEVICES.md.

Viewer: the Triumph-tables tab now has a Device flags panel — checkboxes reflect
the loaded map's real state (stock: all on; delete map: all off), toggling flips
the byte, and "Export edited .hex" re-encodes the distribution format. The
decode->edit->encode round-trip is byte-exact (verified). The caXX header bytes
are map-ID metadata, not a cal checksum; the ECU-flash checksum is applied at
write time.
2026-08-11 08:04:13 -05:00

2.2 KiB

Device-enable flags (SAI / O2 / lambda) — validated

How they were found

Both stock reference maps (20187, 20188) have SAI and O2 active, so diffing them can't reveal the delete flags. The confirmation came from a community map that explicitly disables them:

20188Map2009AIRBOXBONNY.hex — "Bonneville, aftermarket exhaust, mechanical odometer, NO AIR BOX, K&N, British Custom mufflers, NO SAI, NO O² SENSORS". Same base as stock 20188, so the diff isolates the deletes.

Diff (flat ROM) of that map vs stock 20188 = 0.36%, split into:

  • the fuel tables (airbox/K&N enrichment — expected), and
  • a small cluster in the device-config region at 0x53801…0x53819.

The flags

They are a byte-boolean array at flat-ROM base + fe[33] (= 0x50000 + 0x3801 = 0x53801), one byte per device, 1 = enabled, 0 = disabled.

The delete map changed exactly three bytes from 1 → 0:

Flat-ROM offset Stock Deleted Device
0x53801 1 0 SAI (Secondary Air Injection)
0x53818 1 0 O2 sensor
0x53819 1 0 O2 sensor (2)

SAI is the first flag in the array; the two O2 sensors are the last two — consistent with the Devices resource order (SAI = index 0; O2 Sensor / O2 Sensor (2)). The three-byte change matching "NO SAI, NO O²" is unambiguous.

To disable a device: set its byte to 0. (The 0x5369C/0x536AB bytes that also changed are idle/open-loop trim that comes with removing the O2 feedback, not device-enable flags.)

Editing / export

The downloaded .hex format's integrity is the dc stream cipher + the unpack directory; the caXX bytes in the header/tail are map-ID metadata, not a calibration checksum. So a device toggle = flip the byte in the flat ROM, re-pack to the decoded layout, and dc-encode back to .hex. (The separate ECU flash checksum is computed at flash time and is out of scope for the read/edit tool.)

Confidence

  • Flag locations (0x53801 / 0x53818 / 0x53819) and semantics (1/0): validated against a real NO-SAI-NO-O2 map.
  • SAI-vs-O2 labeling of the three bytes: strong (order + delete semantics); final SAI-only-vs-O2-only separation would need a single-delete reference map or a DTC/bench check.