{"_id":"@emdzej/nfsx-bootmode","_rev":"3-739c30eb7877dc7b4c3ffef281b82b31","name":"@emdzej/nfsx-bootmode","dist-tags":{"latest":"0.4.0"},"versions":{"0.1.0":{"name":"@emdzej/nfsx-bootmode","version":"0.1.0","_id":"@emdzej/nfsx-bootmode@0.1.0","maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"homepage":"https://github.com/emdzej/nfsx#readme","bugs":{"url":"https://github.com/emdzej/nfsx/issues"},"dist":{"shasum":"e16eac969af23b9cae367ef603f8fbeacab443c6","tarball":"https://registry.npmjs.org/@emdzej/nfsx-bootmode/-/nfsx-bootmode-0.1.0.tgz","fileCount":51,"integrity":"sha512-ofYnAkJxB5TQJwpq+E6m+t6KeOYrww617ul/eFz6Cx9OHFz1yWpSy3fr5ty5yinJZOp1Dx6SIhj6Acl+7mE+bg==","signatures":[{"sig":"MEUCIQDKGMI++R627iF+08Up8Fkpack+b5z1UFrDhtXIoqLSAwIgZbpWVwWDTT+mT+kRrdakNaOj3cLlswf6TEx1O/BGNds=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":210317},"main":"dist/index.js","type":"module","_from":"file:emdzej-nfsx-bootmode-0.1.0.tgz","types":"dist/index.d.ts","scripts":{"test":"vitest run --passWithNoTests","build":"tsc -p tsconfig.json","clean":"rm -rf dist .turbo *.tsbuildinfo","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"emdzej","email":"michal@jaskolski.pro"},"_resolved":"/private/var/folders/7h/x_w_580x4s9dq3sq11tpvzkwy3nbj8/T/1d97bc6f15b9edd3cdc1c1c7126aa517/emdzej-nfsx-bootmode-0.1.0.tgz","_integrity":"sha512-ofYnAkJxB5TQJwpq+E6m+t6KeOYrww617ul/eFz6Cx9OHFz1yWpSy3fr5ty5yinJZOp1Dx6SIhj6Acl+7mE+bg==","repository":{"url":"git+https://github.com/emdzej/nfsx.git","type":"git","directory":"packages/nfsx-bootmode"},"_npmVersion":"11.14.1","description":"Bootmode flashing for Infineon C167-based ECUs (BMW MS42/MS43, Bosch ME 7.2). Implements the C167 silicon BSL handshake and the MiniMon-style RAM monitor command protocol over K-line / ASC0 serial.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"serialport":"^12.0.0","@emdzej/nfsx-flash-data":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","@types/node":"^22.13.1"},"_npmOperationalInternal":{"tmp":"tmp/nfsx-bootmode_0.1.0_1780306018979_0.8139214462758828","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@emdzej/nfsx-bootmode","version":"0.2.0","_id":"@emdzej/nfsx-bootmode@0.2.0","maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"homepage":"https://github.com/emdzej/nfsx#readme","bugs":{"url":"https://github.com/emdzej/nfsx/issues"},"dist":{"shasum":"fbea6b4578a4274455e9a346da2c370c1b43b391","tarball":"https://registry.npmjs.org/@emdzej/nfsx-bootmode/-/nfsx-bootmode-0.2.0.tgz","fileCount":51,"integrity":"sha512-SxEbl0Dn3mYm/Me5SC32+hT4idPDutSzu0GejKVMPsQiJvJjyNH3un/s3QmAyt6EsLDRPKj3sY19QtSyZa3PNQ==","signatures":[{"sig":"MEYCIQDFBJUuM9kpHRuY3ArQewmA81S5uIBDouXnSpdds9/HyAIhAKA6sjvArH0lncUOKgMSBj2eZafCkCXg/T6WX5vsRP06","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":210317},"main":"dist/index.js","type":"module","_from":"file:emdzej-nfsx-bootmode-0.2.0.tgz","types":"dist/index.d.ts","scripts":{"test":"vitest run --passWithNoTests","build":"tsc -p tsconfig.json","clean":"rm -rf dist .turbo *.tsbuildinfo","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"emdzej","email":"michal@jaskolski.pro"},"_resolved":"/private/var/folders/7h/x_w_580x4s9dq3sq11tpvzkwy3nbj8/T/e300496c9be987a0fda619ef1b47c855/emdzej-nfsx-bootmode-0.2.0.tgz","_integrity":"sha512-SxEbl0Dn3mYm/Me5SC32+hT4idPDutSzu0GejKVMPsQiJvJjyNH3un/s3QmAyt6EsLDRPKj3sY19QtSyZa3PNQ==","repository":{"url":"git+https://github.com/emdzej/nfsx.git","type":"git","directory":"packages/nfsx-bootmode"},"_npmVersion":"11.14.1","description":"Bootmode flashing for Infineon C167-based ECUs (BMW MS42/MS43, Bosch ME 7.2). Implements the C167 silicon BSL handshake and the MiniMon-style RAM monitor command protocol over K-line / ASC0 serial.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"serialport":"^12.0.0","@emdzej/nfsx-flash-data":"0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","@types/node":"^22.13.1"},"_npmOperationalInternal":{"tmp":"tmp/nfsx-bootmode_0.2.0_1780342472808_0.8537919860735874","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@emdzej/nfsx-bootmode","version":"0.4.0","description":"Bootmode flashing for Infineon C167-based ECUs (BMW MS42/MS43, Bosch ME 7.2). Implements the C167 silicon BSL handshake and the MiniMon-style RAM monitor command protocol over K-line / ASC0 serial.","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./node":{"types":"./dist/node.d.ts","default":"./dist/node.js"},"./bundled/*":"./bundled/*"},"type":"module","dependencies":{"serialport":"^12.0.0","@emdzej/nfsx-flash-data":"0.4.0"},"devDependencies":{"@types/node":"^22.13.1","vitest":"^2.1.8"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/emdzej/nfsx.git","directory":"packages/nfsx-bootmode"},"scripts":{"build":"tsc -p tsconfig.json","test":"vitest run --passWithNoTests","test:watch":"vitest","typecheck":"tsc --noEmit","clean":"rm -rf dist .turbo *.tsbuildinfo"},"_id":"@emdzej/nfsx-bootmode@0.4.0","bugs":{"url":"https://github.com/emdzej/nfsx/issues"},"homepage":"https://github.com/emdzej/nfsx#readme","_integrity":"sha512-trQtg0jCzXywH41FHcu6/J9FQojsLirxbqaN8lMSPh2g7TcAbnfDW+Ve4S4jzsu/2wEOOewmbNhhSyeIvREOIQ==","_resolved":"/private/var/folders/7h/x_w_580x4s9dq3sq11tpvzkwy3nbj8/T/1a585d991ebd5318e98adc4262c0312c/emdzej-nfsx-bootmode-0.4.0.tgz","_from":"file:emdzej-nfsx-bootmode-0.4.0.tgz","_nodeVersion":"22.22.1","_npmVersion":"11.16.0","dist":{"integrity":"sha512-trQtg0jCzXywH41FHcu6/J9FQojsLirxbqaN8lMSPh2g7TcAbnfDW+Ve4S4jzsu/2wEOOewmbNhhSyeIvREOIQ==","shasum":"c8e257bcf43fd40821ada436975c22a91f0086cb","tarball":"https://registry.npmjs.org/@emdzej/nfsx-bootmode/-/nfsx-bootmode-0.4.0.tgz","fileCount":67,"unpackedSize":216796,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCDlH3O4SWrioVduAalWFIrSs/6/Xp6job1PGTKQ00ySgIgNhDdGPNNwIkWD+zxSeksBvVEIxll0Ir7NHiuW7qHSDM="}]},"_npmUser":{"name":"emdzej","email":"michal@jaskolski.pro"},"directories":{},"maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/nfsx-bootmode_0.4.0_1783345237278_0.5066079367550285"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-01T09:26:58.809Z","modified":"2026-07-06T13:40:37.497Z","0.1.0":"2026-06-01T09:26:59.144Z","0.2.0":"2026-06-01T19:34:32.949Z","0.4.0":"2026-07-06T13:40:37.406Z"},"bugs":{"url":"https://github.com/emdzej/nfsx/issues"},"homepage":"https://github.com/emdzej/nfsx#readme","repository":{"type":"git","url":"git+https://github.com/emdzej/nfsx.git","directory":"packages/nfsx-bootmode"},"description":"Bootmode flashing for Infineon C167-based ECUs (BMW MS42/MS43, Bosch ME 7.2). Implements the C167 silicon BSL handshake and the MiniMon-style RAM monitor command protocol over K-line / ASC0 serial.","maintainers":[{"name":"emdzej","email":"michal@jaskolski.pro"}],"readme":"# @emdzej/nfsx-bootmode\n\nBootmode (Infineon C167 BSL) flashing for BMW MS42 / MS43 engine ECUs\nand Bosch ME 7.2 — anything built on the C16x / ST10 family. Bypasses\nDS2 entirely: at power-on with the BOOT pin grounded, the C167 mask\nROM enters its silicon Bootstrap Loader; this package uploads\n**MiniMon** (Christian Perschl / Infineon AP16064) into the MCU's\ninternal RAM and then drives the standard MiniMon command set to\nread, erase, and program the AMD AM29F400B flash chip.\n\n> ⚠️ **Bench programming only.** The C167 BOOT pin isn't exposed on\n> the OBD-II connector; this only works against an ECU pulled from\n> the vehicle and wired to a bench harness (12 V, GND, K-line, BOOT\n> pin to ground at power-up).\n\n## What's in the package\n\n- **Bundled binaries** (`bundled/`) — verbatim from MiniMon v2.30:\n  - `LOADK.hex` — 32-byte primary loader (C167 BSL hard-caps this size)\n  - `MINIMONK.hex` — secondary monitor (~394 bytes)\n  - `A29F400B.hex` — AMD AM29F400B flash driver\n  - `manifest.json` — SHA-256 hashes; verified at runtime before any\n    bytes go on the wire (`verifyBundleIntegrity()`)\n  - `README.md` — provenance + license details\n- **Intel HEX parser** (`parseIntelHex`, `flattenIntelHex`) — type 00 /\n  01 / 02 / 03 / 04 / 05 records with checksum verification\n- **Serial transport** (`NodeBootmodeTransport`, `MockBootmodeTransport`)\n  — 8N1 at chosen baud, byte-by-byte echo verify\n- **Handshake** (`performHandshake`) — the auto-baud `0x00` probe,\n  BSL identification byte check, two-stage loader upload with\n  per-byte echo verification and stage-boundary acknowledge bytes\n- **MiniMon client** (`MinimonClient`) — the six primitive commands\n  with `A_ACK1` / `A_ACK2` framing:\n  - `0x82` `C_WRITE_WORD`, `0xCD` `C_READ_WORD`\n  - `0x84` `C_WRITE_BLOCK`, `0x85` `C_READ_BLOCK`\n  - `0x9F` `C_CALL_FUNCTION` (8 register words in/out)\n  - `0x33` `C_GETCHECKSUM`\n- **Flash driver wrapper** (`FlashDriver`) — uploads the AM29F400B\n  driver into RAM and exposes `unlock` / `eraseSector` / `eraseRange` /\n  `programBlock` / `getState` via `C_CALL_FUNCTION` with the FC\n  sub-commands (`0x00` program, `0x01` erase, `0x06` get-state,\n  `0x11` unlock)\n- **Session orchestrators** — `readFullFlash`, `writeFullFlash`,\n  `probeBootmode` for end-to-end flows\n\n## Install\n\n```bash\npnpm add @emdzej/nfsx-bootmode\n```\n\nThe CLI front-end lives in `@emdzej/nfsx-cli` (`nfsx bootmode …`); see\n[the nfsx README](../../README.md) and `nfsx bootmode --help`.\n\n## Programmatic usage\n\n```ts\nimport {\n  probeBootmode,\n  readFullFlash,\n  writeFullFlash,\n  verifyBundleIntegrity,\n  C167CR_BSL_ID,\n} from '@emdzej/nfsx-bootmode';\n\n// 1. Optional: verify the bundled MiniMon blobs match their SHA-256.\nconst integrity = verifyBundleIntegrity();\nif (!integrity.allValid) throw new Error('bundled blobs corrupted');\n\n// 2. Probe — handshake + read flash chip ID, then disconnect.\nconst id = await probeBootmode(\n  {\n    device: '/dev/cu.usbserial-XXXX',\n    baud: 19200,\n    defaultTimeoutMs: 2000,\n    expectedBslId: C167CR_BSL_ID, // 0xC5 for MS42/MS43\n  },\n  (p) => console.error(`[${p.stage}] ${p.message}`),\n);\nconsole.log(`flash mfr=0x${id.manufacturer.toString(16)} dev=0x${id.device.toString(16)}`);\n\n// 3. Dump 512 KB.\nconst dump = await readFullFlash({\n  device: '/dev/cu.usbserial-XXXX',\n  baud: 19200,\n  defaultTimeoutMs: 5000,\n});\nawait fs.writeFile('dump.bin', dump);\n\n// 4. Write 512 KB (this is destructive).\nconst image = await fs.readFile('modified.bin');\nconst result = await writeFullFlash(image, {\n  device: '/dev/cu.usbserial-XXXX',\n  baud: 19200,\n  defaultTimeoutMs: 5000,\n});\nconsole.log(result); // { verified: true }\n```\n\n## How it works (the short version)\n\n1. **Power on the bench-wired ECU with BOOT pin grounded** — the C167\n   mask ROM enters BSL instead of jumping to flash, listens on ASC0\n   for the auto-baud calibration byte.\n2. **Host sends `0x00`** — the BSL uses its bit pattern\n   (`0 00000000 1`) to measure the bit time and configure its UART\n   divider to the host's chosen baud.\n3. **BSL replies with the C16x derivative ID byte** — `0xC5` for the\n   C167CR in MS42/MS43, `0xAA` for the C167 used in ME 7.x.\n4. **Host uploads exactly 32 bytes** (the `LOADK.hex` primary loader)\n   byte-by-byte with echo verification — the BSL hard-caps at 32.\n5. **BSL jumps to the primary** — primary reads the rest of the\n   `MINIMONK.hex` stream, copies it to a larger RAM region, and jumps\n   there. Each stage signals completion with a known ACK byte\n   (`I_LOADER_STARTED = 0x01`, `I_APPLICATION_STARTED = 0x03`).\n6. **MiniMon is now in charge** — the host uploads `A29F400B.hex` into\n   RAM via `C_WRITE_BLOCK`, then drives erase/program through\n   `C_CALL_FUNCTION` with `FC_UNLOCK` → `FC_ERASE` → `FC_PROG` →\n   readback verify via `C_READ_BLOCK`.\n\nFull protocol-level explanation in\n[`docs/raw-ds2-flashing.md` §7](../../docs/raw-ds2-flashing.md) of the\nparent repo.\n\n## Provenance and licensing\n\nThe three bundled `.hex` files are unmodified copies from the MiniMon\nv2.30 distribution by Christian Perschl, distributed by Infineon as\nfreeware. See [`bundled/README.md`](bundled/README.md) for full\nprovenance, license terms, and integrity details.\n\nReferences:\n\n- [MiniMon project page](http://www.perschl.at/minimon/)\n- [Infineon AP16064 — MiniMon application note](https://www.infineon.com/assets/row/public/documents/10/47/ap1606412-minimon.pdf?fileId=db3a3043133ffd300113444e0b810219)\n- [Infineon AP16012 — C16x Bootstrap Loader](https://www.infineon.com/dgdl/ap1601210_Bootstrap_Loader_IDB.pdf?fileId=db3a304318a6cd680118cb945a2140bc)\n- [EcuProg7/C167BootTool](https://github.com/EcuProg7/C167BootTool) — independent open-source host implementation (GPL v3)\n\n## Status\n\nCode paths and tests are complete; **not yet validated against a real\nbench ECU**. The first real-hardware run will be the user's; bring a\nbackup BIN and an extra ECU. The host-side code aborts on echo\nmismatch, BSL-ID mismatch, or any handshake stage failure rather than\nproceeding into a half-written state.\n","readmeFilename":"README.md"}