Announcement
Collapse
No announcement yet.
Any DCT owners changed their final drive / diff ratio?
Collapse
X
-
Is it sufficient to change the value at 0x271FE from 4E 0C (3.15) to 24 0E (3.62), save the file and flash back to the car?
-
I'm also interested in assisting.
From what i've read the 3.45 dct works fine, it's the 3.62 that creates problems. However, it seems like a few tuners are able to edit this and make it work properly. I am sure this is not rocket science, but as usual the very few tuners who spent a few hours figuring this out aren't about to tell us abour ir
I wish the xhp dct software worked on the e9x dct. It would be nice to have faster than gts software shifts
Leave a comment:
-
Originally posted by Tomba View Post
I am really impressed what you and tera do and hope I can educate myself to such level program/disassembling wise. Keep up the good work
And yes, someone offered me an A2L file for M3 DKG but wanted too much money for it. He was quite offended when I told him that. I am confident a new offer by someone else will come in the future.
Most people selling A2L files think they are god, I refuse to play that way. If a new offer comes and you want to contribute in payment of it, just drop me a PM.
Leave a comment:
-
Yes im interested.
I am preparing own xdf based on analysis. Shiftmaps, logic keys, limits described. Now shift speed and torque corrections. Pressure next.
Leave a comment:
-
And yes, someone offered me an A2L file for M3 DKG but wanted too much money for it. He was quite offended when I told him that. I am confident a new offer by someone else will come in the future.
Most people selling A2L files think they are god, I refuse to play that way. If a new offer comes and you want to contribute in payment of it, just drop me a PM.
Leave a comment:
-
Originally posted by olza View Postterra nope. this is how i thinking it is stored.
0x1F200 is "compiler bootloader" public signature key. seed key is at 0x1F100. 0-1FFFF boot.
data signature is at 0x3FE00 - this is what bmw checks after data reflash. 20000 - 3FFFF data
code signature is at 0x40100. 40000 - 16FFFF code...
Leave a comment:
-
Originally posted by Tomba View Post
I used MagicMotorsport FLEX. After I have written the file with different differential ratio the read was exactly the same.
Do you have A2L or disassembled this?
terra nope. this is how i thinking it is stored.
0x1F200 is "compiler bootloader" public signature key. seed key is at 0x1F100. 0-1FFFF boot.
data signature is at 0x3FE00 - this is what bmw checks after data reflash. 20000 - 3FFFF data
code signature is at 0x40100. 40000 - 16FFFF code...
also there are some hashes in a code for "realtime" code consistency checks. but leave them alone.
Tomba is there A2L for sale somewhere? id like to look. because of too much tables.Last edited by olza; 11-17-2020, 11:55 AM.
Leave a comment:
-
Originally posted by olza View Postyes. Did you use your tool to rewrite data? M3/gts version differs with 135/335 not only final ratio, but also wheel factor and other system variables.
Do you have A2L or disassembled this?
Leave a comment:
-
Originally posted by Tomba View Post
Changed it and works. No limp mode or error codes!
Do you know how to disable error codes?
Leave a comment:
-
olza, do you know what the second 1024-bit RSA key is for? In the full binary posted earlier I see 2: One at 0x1F200 and the other at 0x5A7F8. The first one seems to be what's actually used to validate the signatures. Can't figure out what the second one is used for.
I do have the complete factorization (and therefore the corresponding private key) of the second one, but I just don't know what it's useful for.
Leave a comment:
-
Okay, i can write now changed data to DCT via winkfpt.
So they who have non-stock final gear, or want something else - pm me.
- Likes 1
Leave a comment:
-
Originally posted by Tomba View Post
I don't have a car by hand currently. But can do this once I am working again.
I can change the final drive ratio and read out the memory again after flashing. I suspect they (magicmotorsport) bypass RSA themself. At least as far as I know they do this on Fxx DMEs as well. First flash takes 5-8 minutes. One after that mostly 2 or less minutes. I haven't flashed any DCT yet.Last edited by olza; 10-08-2020, 09:26 AM.
Leave a comment:
Leave a comment: