fix(flash): route CP PLC subcomponents to their own flash regions #15
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/cp-plc-flash-module-bytes"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The CP PLC modem subcomponents were mapped to module byte 0x00, which the CP
bootloader validates against the app window [0x8000,0xe0000] — so flashing
cpPlcFw (@0x100000) / cpPlcPib (@0xe0000) would fail NRC 0x31.
RE of the 2026 CP bootloader (
cpbl,FUN_00001d3c) shows the WDBI 0x0102module byte gates the RequestDownload window:
0x08→[0x100000, 0x200000]cpPlcFw0x06→[0xe0000, 0x100000]cpPlcPibFix sets those bytes in
flash_scripts/_ecu_map.py(+ corrects the_groups.pycomment). No other wiring needed —
dfu.pyphase 4 and the can_live ODINUPDATE_PLCpath both resolve the module byte viaget_script, soUpdate_PLCnow flashes the modem correctly from both.
Fails safe: a wrong module byte NRCs (0x31); it cannot mis-target a region.
Note: verified against the 2026 bootloader; the 2020/2022 resident bootloader's
window map is unverified (same fail-safe applies).
🤖 Generated with Claude Code