fix(flash): route CP PLC subcomponents to their own flash regions #15

Merged
outlandnish merged 1 commit from feat/cp-plc-flash-module-bytes into feat/vapi-layout 2026-09-06 12:13:33 -05:00
Owner

The CP PLC modem subcomponents were mapped to module byte 0x00, which the CP
bootloader validates against the app window [0x8000,0xe0000] — so flashing
cpPlcFw (@0x100000) / cpPlcPib (@0xe0000) would fail NRC 0x31.

RE of the 2026 CP bootloader (cpbl, FUN_00001d3c) shows the WDBI 0x0102
module byte gates the RequestDownload window:

  • 0x08 → [0x100000, 0x200000] cpPlcFw
  • 0x06 → [0xe0000, 0x100000] cpPlcPib

Fix sets those bytes in flash_scripts/_ecu_map.py (+ corrects the _groups.py
comment). No other wiring needed — dfu.py phase 4 and the can_live ODIN
UPDATE_PLC path both resolve the module byte via get_script, so Update_PLC
now flashes the modem correctly from both.

Fails safe: a wrong module byte NRCs (0x31); it cannot mis-target a region.

Note: verified against the 2026 bootloader; the 2020/2022 resident bootloader's
window map is unverified (same fail-safe applies).

🤖 Generated with Claude Code

The CP PLC modem subcomponents were mapped to module byte 0x00, which the CP bootloader validates against the app window [0x8000,0xe0000] — so flashing cpPlcFw (@0x100000) / cpPlcPib (@0xe0000) would fail NRC 0x31. RE of the 2026 CP bootloader (`cpbl`, `FUN_00001d3c`) shows the WDBI 0x0102 module byte gates the RequestDownload window: - `0x08` → `[0x100000, 0x200000]` cpPlcFw - `0x06` → `[0xe0000, 0x100000]` cpPlcPib Fix sets those bytes in `flash_scripts/_ecu_map.py` (+ corrects the `_groups.py` comment). No other wiring needed — `dfu.py` phase 4 and the can_live ODIN `UPDATE_PLC` path both resolve the module byte via `get_script`, so `Update_PLC` now flashes the modem correctly from both. Fails safe: a wrong module byte NRCs (0x31); it cannot mis-target a region. Note: verified against the 2026 bootloader; the 2020/2022 resident bootloader's window map is unverified (same fail-safe applies). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
cpPlcFw/cpPlcPib were mapped to module byte 0x00, which the CP bootloader
validates against the app window [0x8000,0xe0000]; a RequestDownload at the
modem regions (cpPlcFw @0x100000, cpPlcPib @0xe0000) fails NRC 0x31.

Per the CP bootloader RequestDownload window validator (cpbl 2026,
FUN_00001d3c) the WDBI 0x0102 module byte gates the allowed address range:
0x08 -> [0x100000,0x200000] (cpPlcFw), 0x06 -> [0xe0000,0x100000] (cpPlcPib).

Resolves through dfu.py phase4 and the can_live ODIN UPDATE_PLC path
unchanged (both take the module byte from get_script). Fails safe: a wrong
byte NRCs, it cannot mis-target another region.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
outlandnish merged commit d0b882eac2 into feat/vapi-layout 2026-09-06 12:13:33 -05:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
outlandnish/tm3diag!15
No description provided.