Welcome Anonymous !

Everything you need to modify your ride
 

GM Technical Document Discussion

GM ALDL Logging and Scanning

A place to discuss the technical documents for GM vehicles such as Holden, Chevrolet, Opel, Vauxhall, Buick, Cadilac and Daewoo
Forum rules
To gain access to the Invite Only forum you must be invited by a member of that forum. That member will PM the mods or admins (NOT you) saying that they nominate you for access. THEY will be responsible for your actions. If you don't post and just leech info, you will BOTH be removed. Dont send a PM to the moderators or admins asking for access, you really dont want to see the result. If you submit information, you may simply be invited :)

Postby TazzI » Sat May 19, 2012 6:46 pm

This thread is to discuss and learn about ALDL logging/scanning/hacking.

I picked up my ALDL today, works perfectly!, bought one from VL400 over at delco hacking, I highly recommend him, great bloke!

I am using efilive4 for the logging.

I don't know a whole lot about ALDL logging... yet but here is the first log, engine off, accessories on:
Code: Select all
31:30.886: Scan for chatter...
31:30.886: Waiting for Aldl bus silence of at least 26ms...
31:30.935: (31:30.935)$20,$55,$8B
31:30.951: (31:30.939)$21,$5F,$09,$3C,$1B,$00,$00,$00,$00,$00,$00,$56,$CA
31:30.953: (31:30.953)$90,$55,$1B
31:30.967: (31:30.955)$91,$59,$03,$10,$00,$00,$03
31:30.983: (31:30.969)$A0,$55,$0B
31:30.985: (31:30.985)$A1,$58,$02,$0D,$00,$F8
31:30.999: (31:30.999)$11,$5D,$07,$FF,$10,$40,$06,$00,$00,$00,$36
31:31.015: (31:31.015)$B8,$57,$6A,$A9,$DE
31:31.047: (31:31.031)$40,$58,$E5,$5E,$06,$1F
31:31.063: (31:31.049)$41,$68,$12,$00,$00,$00,$5D,$50,$00,$00,$70,$F0,$30,$00,$00,$10,$00,$00,$00,$00,$00,$F8
31:31.079: (31:31.079)$20,$55,$8B
31:31.095: (31:31.082)$21,$5F,$09,$3C,$1B,$00,$00,$00,$00,$00,$00,$56,$CA
31:31.097: (31:31.097)$08,$55,$A3
31:31.159: (31:31.143)$B8,$57,$6A,$A9,$DE
31:31.175: (31:31.175)$40,$58,$E5,$5E,$06,$1F
31:31.207: (31:31.177)$41,$68,$12,$00,$00,$00,$5D,$50,$00,$00,$70,$F0,$30,$00,$00,$10,$00,$00,$00,$00,$00,$F8
31:31.209: (31:31.209)$A8,$55,$03
31:31.223: (31:31.223)$20,$55,$8B
31:31.255: (31:31.239)$21,$5F,$09,$3C,$1B,$00,$00,$00,$00,$00,$00,$56,$CA
31:31.257: (31:31.257)$90,$55,$1B
31:31.271: (31:31.259)$91,$59,$03,$10,$00,$00,$03
31:31.274: (31:31.273)$A0,$55,$0B
31:31.287: (31:31.287)$A1,$58,$02,$0D,$00,$F8
31:31.303: (31:31.289)$11,$5D,$07,$FF,$10,$40,$06,$00,$00,$00,$36
31:31.319: (31:31.319)$B8,$57,$6A,$A9,$DE
31:31.335: (31:31.335)$40,$58,$E5,$5E,$06,$1F
31:31.367: (31:31.337)$41,$68,$12,$00,$00,$00,$5D,$50,$00,$00,$70,$F0,$30,$00,$00,$10,$00,$00,$00,$00,$00,$F8
31:31.383: (31:31.369)$20,$55,$8B
31:31.399: (31:31.385)$21,$5F,$09,$3C,$1B,$00,$00,$00,$00,$00,$00,$56,$CA
31:31.401: (31:31.401)$08,$55,$A3
31:31.447: (31:31.447)$B8,$57,$6A,$A9,$DE
31:31.554: (31:31.554)$40,$58,$E5,$5E,$06,$1F
31:31.557: (31:31.557)$41,$68,$12,$00,$00,$00,$5D,$50,$00,$00,$70,$F0,$30,$00,$00,$10,$00,$00,$00,$00,$00,$F8
31:31.559: (31:31.559)$A8,$55,$03
31:31.561: (31:31.561)$20,$55,$8B
31:31.563: (31:31.563)$21,$5F,$09,$3C,$1B,$00,$00,$00,$00,$00,$00,$56,$CA
31:31.565: (31:31.565)$90,$55,$1B
31:31.575: (31:31.567)$91,$59,$03,$10,$00,$00,$03
31:31.587: (31:31.587)$A0,$55,$0B
31:31.593: (31:31.593)$A1,$58,$02,$0D,$00,$F8
31:31.607: (31:31.597)$11,$5D,$07,$FF,$10,$40,$06,$00,$00,$00,$36
31:31.623: (31:31.623)$B8,$57,$6A,$A9,$DE
31:31.639: (31:31.639)$40,$58,$E5,$5E,$06,$1F

I also have putty, although when I log in this, I get strange letters and symbols instead of numbers.. not sure if its configured properly.
User avatar
TazzI
Moderator
 
Posts: 986
Images: 2
Joined: Thu Dec 22, 2011 8:02 pm
Has thanked: 16 times
Been thanked: 41 times

Postby jezzab » Sat May 19, 2012 7:13 pm

Your seeing the characters no the hex value. they are the same but you are seeing the ASCII equivalent

use the OSE Flash Tool from Delco hacking. You can send and log the packets
Daily Ute - 2009 Holden VE SSV Ute Single Turbo (IQ, E3 Cluster, EDI) - 586rwhp
Drag Ute - 2002 Holden VU SS Twin Turbo - 1010rwhp [SOLD]

All VE/VF Module reprogramming. Remote programming with flash box
http://www.facebook.com/jsbperformance
User avatar
jezzab
Site Admin
 
Posts: 1032
Joined: Sun Nov 20, 2011 9:42 pm
Location: Melbourne
Has thanked: 42 times
Been thanked: 26 times

Postby TazzI » Sat May 19, 2012 7:35 pm

Ohhh alright, thought I was reading aribic or something!

Just got the tool, think Ill be using this from now on.
User avatar
TazzI
Moderator
 
Posts: 986
Images: 2
Joined: Thu Dec 22, 2011 8:02 pm
Has thanked: 16 times
Been thanked: 41 times

Postby TazzI » Mon May 21, 2012 2:21 am

Alright so beginning to understand the 'meanings' of each byte.
use an easy example..
F4 57 01 04 B0
F4 : the device ID that you are addressing
57 : the length of the data in the message (don't quite understand what '57' exactly means.. 57 bytes?)
01 : is the aldl mode, eg 1 which requests dataframes
04 : message number requested (particular section requested?)
B0 : checksum (I calculate this weird..is there a proper way?)

checksum = (FF - F4 - 57 - 01 - 04) = AF +1 = B0

Devices I know so far..
PCM - $F7
BCM - $F1
User avatar
TazzI
Moderator
 
Posts: 986
Images: 2
Joined: Thu Dec 22, 2011 8:02 pm
Has thanked: 16 times
Been thanked: 41 times

Postby gruntly69 » Mon May 21, 2012 9:41 am

FAR OUT TAZZ!!!

Your doing better than I , i've had this stuff for a while but haven't used the OSE tool for this yet as I don't know enough about it!

But yeah I think your on the money!
gruntly69
Contributor
 
Posts: 152
Joined: Mon Mar 12, 2012 11:41 am
Has thanked: 0 time
Been thanked: 1 time

Postby gruntly69 » Mon May 21, 2012 9:48 am

Just to add a cross reference between the 2 forums, hope admin doesn't mind:

http://delcohacking.net/forums/viewtopic.php?f=10&t=219

A lot of good info there from VL400 there & other wise dudes!
gruntly69
Contributor
 
Posts: 152
Joined: Mon Mar 12, 2012 11:41 am
Has thanked: 0 time
Been thanked: 1 time

Postby ZerOne » Mon May 21, 2012 11:17 am

Thanks for the link Gruntly69

We Definitely don't mind at all.... :D
Delco hacking is an awesome web site, and there are a LOT of wise people on there !!!!!
Please feel free to post up any other links you find to be helpful !!!!

I will and try and read up on the ALDL protocol and see if I can help at out as well...
(No that I understand the 29Bit Protocol a little bit better)...
I will check out the above link and see if I am able to pick up on anything and help out...

Pity that GM couldn't stick to the one protocol...
It just means more things to learn and play with Lol...
User avatar
ZerOne
Site Admin
 
Posts: 1285
Images: 16800
Joined: Thu Aug 19, 2010 1:25 pm
Location: Sydney Australia
Has thanked: 14 times
Been thanked: 36 times

Postby gruntly69 » Mon May 21, 2012 12:39 pm

Just went through some notes I have & looks like dash cluster could be $F2, but not sure if thats VT-VX or VY-VZ?

the 2nd value looks like it's accessing between 56 to 5A & then some at 67?

again, i'm not sure what this all means?
gruntly69
Contributor
 
Posts: 152
Joined: Mon Mar 12, 2012 11:41 am
Has thanked: 0 time
Been thanked: 1 time

Postby TazzI » Mon May 21, 2012 4:20 pm

Any notes you have and post up on his will be great!, Wonder if theres a standard "read all" command for all devices. I am yet to have a look at the tuning side of things, see what device is called for and adjusted. Just did a quick skim on that, seems you need to ask for the seed/key from the pcm/bcm (one of those) then send the same key back to unlock so one can use mode 2 (i think) and tune?.... I shall investigate delco more to understand whats the go with that!

F2,my vy hasnt sent a F2 command yet, havent logged with car on though, going through the log I posted up+ some messages with some delco guys, 40/41 are cluster related,as noted for VT/VX clusters as well. I just don't see why the 40/41 messages would be cluster.. as they are doing nothing. Thought they would be something more to security or SRS maybe (checking there status), or radio, as the car was off, only accessories where on.

Its frustrating getting so much information in one hit, have to use excel to analyse the data. So Im hacking up a quick program to analyse the incoming packets, and filter them so that it is simply:

Device ID Message Counter

So I can keep track of what is being sent plus can see what command/packet is sent when I click mode ect,should only occur once. Not sure how Ill go with filtering real time streaming.. Well have to start somewhere!

I attempted using a serial sniffer progam and told it to filter specific messages out but didn't quite do its job.. hmm more to come.
User avatar
TazzI
Moderator
 
Posts: 986
Images: 2
Joined: Thu Dec 22, 2011 8:02 pm
Has thanked: 16 times
Been thanked: 41 times

Postby TazzI » Mon May 21, 2012 4:44 pm

Proper way of calculating the checksum: 'it is just a 2s compliment of the bytes in the frame. Sum the bytes, take the lower 8bits and subtract from 0x100.'
User avatar
TazzI
Moderator
 
Posts: 986
Images: 2
Joined: Thu Dec 22, 2011 8:02 pm
Has thanked: 16 times
Been thanked: 41 times

Next

Return to GM Technical Document Discussion

  • View new posts
  • View unanswered posts
  • Who is online
  • In total there are 3 users online :: 0 registered, 0 hidden and 3 guests (based on users active over the past 5 minutes)
  • Most users ever online was 564 on Mon Jan 20, 2020 9:00 am
  • Users browsing this forum: No registered users and 3 guests