Repository navigation
Releases: hjtrbo/GM-ECU-Simulator
Release list
v0.5.1 (pre-release)
Pre-release. Framework-dependent: the target machine needs the .NET 9 Desktop Runtime.
What's new since v0.5.0
- Consolidated full-image bin per programming session. At session end the simulator now writes one positioned flash image (in addition to the existing per-$36 fragment captures), auto-saved to
%LOCALAPPDATA%\GmEcuSimulator\bins:- SPS
$34/$36flow: every$31-declared erase region is unioned into one image spanning[min start, max end), each region placed at its absolute offset, gaps left0xFF. Verified byte-for-byte against a real E38 source calibration. - PcmHammer kernel flow:
KernelFlashis dumped verbatim (already a positioned full image).
- SPS
- PcmHammer / PCMHacking.net flash-kernel command set. Shared kernel dispatch now serves the PcmHammer write kernel's own
$3Dquery/erase + custom$36flash-write block. - HardwareCan transport. Bridge the simulated bus to a physical CAN adapter.
- Log "Open folder" menu item is always enabled (no longer gated on the file-logging toggle).
Install
- Unzip anywhere.
- Run
ShimInstaller\Register.ps1 -Buildfrom an elevated PowerShell (or use the in-app J2534 -> Register as J2534 device... menu). - Start
GmEcuSimulator.exe. Any J2534 host now sees "GM ECU Simulator" in its device list.
v0.5.0 (pre-release)
GM ECU Simulator v0.5.0 (pre-release)
Framework-dependent build. The target machine needs the .NET 9 Desktop Runtime.
Changes since v0.4.2
-
GM flash-READ emulation ($35 / $36) - the simulator now answers flash reads for both real GM reader tools:
- E38 / E67 (PowerPCM_Flasher): native
$35RequestUpload ->$75, then each$36returns a 1024-byte block, cursor auto-advancing. - T43 (6Speed.T43 read-kernel):
$36sub$80@0x003FC430emits the$99"alive" handshake, then each$35streams a self-contained multi-frame block. - New "Read as" dropdown (E38/E67 vs T43) per ECU, under the security-module picker (GM persona only), persisted in the config. Flash bytes are served from the ECU's loaded
.bin(zero-filled past the image). - PowerPCM's end-of-read
$31 01 04CRC validate is honoured (CRC-16/CCITT-FALSE over the read image), so it reports "ok, valid".
- E38 / E67 (PowerPCM_Flasher): native
-
Protocol-stack architecture - the per-ECU "persona" model is replaced by composable protocol-stack bindings (J1979 / GMW3110 / UDS / transient SPS-kernel), resolved by CAN id + SID. About -> Protocols opens a read-only registry of which services each ECU answers versus NRCs.
-
Per-service dispatch checklist - the ECU Advanced tab now lets you toggle which SIDs each bound standard answers, modelling real-silicon fidelity (e.g. "the enhanced dispatcher doesn't answer
$2C"). Only the delta off the default is saved. -
Response-timing profile - per-ECU processing delay (P2 / P2*) with
7F nn 78ResponsePending heartbeats, plus a session-timeout (P3C / S3) override. Defaults to instant (byte-identical to before).
Install
- Extract the zip.
- Run
GmEcuSimulator.exe, or from an elevated PowerShell inside the extracted folder run.\ShimInstaller\Register.ps1to register the J2534 device (both 32-bit and 64-bit shims are included).
Contents
Flat bundle: GmEcuSimulator.exe + managed deps, both native shims (PassThruShim32.dll, PassThruShim64.dll), and ShimInstaller\ scripts.
v0.4.2 (pre-release)
GM ECU Simulator v0.4.2 (pre-release)
Framework-dependent build. The target machine needs the .NET 9 Desktop Runtime.
Changes since v0.4.1
- DMR datalog signal mapping - new
DmrValueEncoding/DmrSignalMappingmodel maps PCMTec/DMR rapid-packet datalog slots to signals, with an in-app editor and JSON persistence. - Shared CommonServices persona layer - common
$22/ identity handling factored out of the per-persona handlers so every persona answers shared DIDs (e.g. ForScan's$22 0200probe) consistently. - Ford UDS persona refinements - rename from the capture persona, RAM-read-zeros, multi-select PID grids.
- Virtual bus - frame timestamping and broadcast log tagging; ForScan connect-probe surfaced in the bus log.
- Installer rename - the
Installer\scripts directory is nowShimInstaller\(Register / Unregister / List / Publish-Release). The published bundle ships these flat beside the EXE;Register.ps1 -Buildresolves the bundled shims itself.
Install
- Extract the zip.
- Run
GmEcuSimulator.exe, or from an elevated PowerShell inside the extracted folder run.\ShimInstaller\Register.ps1to register the J2534 device (both 32-bit and 64-bit shims are included).
Contents
Flat bundle: GmEcuSimulator.exe + managed deps, both native shims (PassThruShim32.dll, PassThruShim64.dll), and ShimInstaller\ scripts.
v0.4.0 (pre-release)
v0.4.0 (pre-release)
New: Ford UDS flash-write support (ford-capture persona)
The ford-capture persona can now sit in front of a Ford PCM programming session
and accept the full UDS write sequence, capturing the streamed image to disk.
- $27 SecurityAccess via the new
ford-uds-accept-anymodule: 3-byte
(24-bit) seed, accept-any-key, with correct level pairing. No invented
seed/key algorithm - it accepts the tester's key rather than computing one,
per the donor-walker rule. - $11 ECUReset acknowledged and clears security / programming state.
- Flash write path:
$B1erase, then$34RequestDownload /
$36TransferData /$37RequestTransferExit. The streamed payload is
captured byte-for-byte to
%LOCALAPPDATA%\GmEcuSimulator\logs\ford-capture\ford_flash_write_*.bin
(validated by a SHA-256 match against a real PCM readback). - Validated end to end against PCMTec as the reference tester.
New: automatic wire capture
When a ford-capture persona is active, the bus logger force-starts for the
session, so the on-the-wire exchange is always recorded to bus_*.csv without
manually enabling file logging.
New: per-ECU flash-timing profile (all personas)
A real ECU's flash can take 30 s or more; the simulator's is near-instant.
Two new knobs in the ECU editor's Advanced section let you pace it:
- Xfer ms (
FlashTransferDelayMs) - defers each$36TransferData positive. - Erase ms (
FlashEraseDelayMs) - defers the erase positive.
Fixed
- ISO15765 filterless single-frame writes: a J2534 write with no flow-control
filter (e.g. the functional3E 80TesterPresent to0x7DF) now sends a
single frame instead of returningERR_NO_FLOW_CONTROL.
Install
Framework-dependent build - the target machine needs the .NET 9 Desktop Runtime.
Unzip and run Installer\Register.ps1 (elevated) to register the J2534 device, then
start GmEcuSimulator.exe. The bundle ships both native shims (32- and 64-bit) flat
beside the exe.
v0.3.0 (pre-release)
v0.3.0 (pre-release)
New: DBC-driven CAN broadcast
The simulator can now emit unsolicited application CAN traffic - the background
frames a passive logger expects, not just request/response diagnostics.
- Import a DBC per ECU (ECU editor -> CAN Broadcast -> Import DBC...). A scoped
picker lets you choose the transmitting module, then tick which of its messages
to broadcast; signals that match a live engine value are auto-mapped. - Bit-accurate packing of each signal at its DBC start bit / length, Motorola
or Intel byte order, signed/unsigned, with the DBC scale/offset. - Live or constant values: map each signal to a live engine signal (RPM, speed,
coolant, MAP, MAF, throttle, ...) so it tracks the active scenario, or pin a constant. - Free-form periods (per the DBC GenMsgCycleTime, editable) emitted while a J2534
host session is open, via the cross-channel broadcaster. - Save / Load a broadcast set as a standalone
*.dbc.json(the app's own editable
snapshot), alongside the raw-DBC import path. - Config schema bumped to v18 (additive: older configs load unchanged).
Docs
- README and manuals updated for the signal-centric ECU redesign.
Install
Framework-dependent build - the target machine needs the .NET 9 Desktop Runtime.
Unzip and run Installer\Register.ps1 (elevated) to register the J2534 device, then
start GmEcuSimulator.exe. The bundle ships both native shims (32- and 64-bit) flat
beside the exe.
v0.2.1 (pre-release)
GM ECU Simulator v0.2.1 (pre-release)
Framework-dependent build. The target machine needs the .NET 9 Desktop Runtime.
What's new since v0.2.0
- Signal-centric ECU model. The monolithic
EngineModelis replaced by anIEngineCharacterabstraction (GasV8Character/NaGasV8/BoostedGasV8, selected viaEngineCharacterRegistry), so PID values are synthesised from an engine personality rather than hardcoded. A newPidValueSourcemarks how each PID derives its value, with engine-model and mode selection surfaced in the editor. - Raw-CAN TCP transport. New
RawCanTcpServer+RawCanWire(ConnectionType) as an alternative to the named-pipe shim, with lifecycle, diagnostics, and reinit coverage. - Removed the legacy PID library responder/classifier. PID responses now flow through the signal layer.
- Release tooling.
Installer/Publish-Release.ps1produces the flat bundle layoutRegister.ps1expects (published EXE + both native shims +Installer\scripts at the bundle root).
Install
- Extract the zip.
- From an elevated PowerShell in the extracted folder:
.\Installer\Register.ps1(registers the shim as a J2534 v04.04 device, both bitnesses). - Run
GmEcuSimulator.exe.
v0.2.0 (pre-release)
First pre-release since v0.1.0 (20 commits). Flagged as pre-release: the multi-mode PID work is new and still settling.
Highlights
- Signal-centric ECU redesign - shared signal/identity/state layers with per-mode PID projections, replacing the single flat PID store.
- Multi-mode PID rows ($1A / $22 / $2D) in the editor, with per-mode sections and catalogue pickers for $1A/$22.
- OBD-II Mode $01 (J1979) support:
Service01Handlerplus a J1979 catalogue projection over the signal layer. - Dual diagnostic-stack tagging - every request is tagged Gmw3110 vs UDS, and UDS-only SIDs are stack-gated to match real E38/E67 silicon.
- Fix: editing a PID's Address in the editor now re-keys its per-mode store. Previously a $2D/$22 read against the edited address returned NRC $31 RequestOutOfRange even though the saved config looked correct.
Download
GmEcuSimulator-v0.2.0-win-x64.zip contains:
GmEcuSimulator/- the published WPF app (framework-dependent)shim/PassThruShim64.dll+shim/PassThruShim32.dll- the J2534 native shims, both bitnesses
Requires the .NET 9 Desktop Runtime. Register the shim via the app's J2534 -> Register as J2534 device... menu (elevates via UAC) or Installer/Register.ps1 from an elevated shell.