nyet.org / projects / me7sum

ME7Sum

Checksum and CRC checker/corrector for Bosch Motronic ME7.x firmware dumps. Finds the tables, verifies every block, and writes a corrected image when you ask it to.

What it covers

latest · BSD license

VAGME7.1 / 7.5

Volkswagen, Audi, Seat, Skoda

Original ME7Sum target. ROMSYS, CRC tables, RSA/MD5, main data checksums, program checksums, and multipoint blocks on 512K and 1024K dumps.

S4 · RS4 · A6 · RS6 · allroad
PorscheME7.2

986 Boxster / 996 Carrera

Auto-detected from the Bosch part-number block at 0x1FCBE. No extra flags on stock factory binaries. Verified across 157 factory images.

added in v1.1.7
CompanionME7Check

Always re-check before flash

Windows releases include Andy Whittaker’s ME7Check. Run it on the original dump first, then again on anything ME7Sum writes.

bundled in the Windows zip

Download

GitHub Releases

Loading latest builds…

Every tagged build is listed on the release archive. Source is always on GitHub Releases.

Running

check first · write only when asked

Checkread-only

Validate a dump

ME7Check image.bin
me7sum image.bin
Correctwrites out.bin

Write fixed checksums

me7sum image.bin out.bin

If you do not supply out.bin, ME7Sum only checks. It will not write a file unless it can locate every checksum/CRC it needs. Always run it on an original dump first to confirm the image is compatible. Some files need a second pass; see issue 7.

Output

from bins/006410010A0.bin

me7sum 006410010A0.bin
ME7Sum (v1.1.7) [Management tool for Bosch ME7.x firmwares]
Inspiration from Andy Whittaker's tools and information.
Written by 360trev and nyet [BSD License Open Source].

Attempting to open firmware file '006410010A0.bin'

Step #1: Reading ROM info ..
 Searching for EPK signature...OK
 Searching for ECUID table...OK
 EPK         : '42/1/ME7.1.1/5/C1105N//05A/C05A101/030205/'
 Part Number : '006410010A0 '
 SW Version  : '0000'
 HW Number   : '0261208771'
 SW Number   : '1037371702'

Step #2: Reading ROMSYS ..
 Startup section: word[0x008000]+word[0x00FFFE]
 @08038 Add=0x0000BDFF CalcAdd=0x0000BDFF  ADD OK
 All param page: word[0x010000]+word[0x01FFFE]
 @01f0f4 Add=0x00971D CalcAdd=0x00971D  ADD OK

Step #3: Finding CRC table(s) ..
 Searching for CRC table(s)...OK
 CRC table(s) OK

Step #4: Reading RSA signatures ..
 Searching for RSA offset #0...OK
 Searching for RSA offset #1...OK
         Signature: @da3da-da45a
           Modulus: @16b4e-16bce
          Exponent: @16bce = 3
 Searching for MD5 ranges...OK
 MD5 Block Offset Table @16b2a [32 bytes]:
 1) 0x00010002-0x00013FFE
 2) 0x00014552-0x00017F4E
 3) 0x00018192-0x0001FBDC
 4) 0x00026A00-0x0002FFFC
 EncrMD5: 50 99 23 19 a0 e0 b5 fb 7c 3b b9 9d 04 09 ea 5f
 CalcMD5: 50 99 23 19 a0 e0 b5 fb 7c 3b b9 9d 04 09 ea 5f
  OK

Step #5: Reading Main Data CRC/Checksums ..
 Searching for main data CRC pre block...missing
 Searching for main data CRC/csum blocks...OK
 Searching for main data CRC offsets...missing
 Searching for main data checksum offsets...OK
 Main Checksums:
 1) 0x010002-0x013FFE CalcCSM: 001405C3
 2) 0x014552-0x017F4E CalcCSM: 002A6C50
 3) 0x018192-0x01FBDC CalcCSM: 00497B6A
 4) 0x026A00-0x02FFFC CalcCSM: 00A3404B
 @dac20 CSM: 00A3404B CalcCSM: 00A3404B OK

Step #6: ROMSYS Program Pages
 Program pages: 8k page first+last in 0x0000-0xFFFF and 0x20000-0xFFFFF
 @00803c Add=0x738B2A CalcAdd=0x738B2A  ADD OK

Step #7: Reading Main Program Checksums ..
 Searching for main program checksum..OK
 ROM Checksum Block Offset Table @29fa6 [16 bytes]:
 1) 0x000000-0x00FBFF CalcChk: 43E63903
    0x00FC00-0x01FFFF CalcChk: 23DE51E0 CalcCRC: 625ECB51 SKIPPED
 2) 0x020000-0x0FFFFF CalcChk: A00DBC04
 @fffe0 Chk: A00DBC04 CalcChk: A00DBC04 OK (i)

Step #8: Reading Multipoint Checksum Blocks ..
 Searching for multipoint block descriptor #1...missing
 Searching for multipoint block descriptor #2...OK
 1) <1fbde>  0x000000-0x003FFF Chk: 0E59D5C8 Boot: (whitelisted) OK
 2) <1fbee>  0x004000-0x007FFF Chk: 1077FB35 Boot: (whitelisted) OK
 3) <1fbfe>  0x000000-0x003FFF Chk: 1006B6FB CalcChk: 1006B6FB OK
 ..........
64) <1ffce>  0x0F4000-0x0F7FFF Chk: 0EFBBD9E CalcChk: 0EFBBD9E OK
65) <1ffde>  0x0F8000-0x0FBFFF Chk: 0DE62401 CalcChk: 0DE62401 OK
66) <1ffee>  0x0FC000-0x0FFFFF Chk: 18094AC4 CalcChk: 18094AC4 OK
 Multipoint #2: [66 blocks x <16> = 1056 bytes]

Step #9: Looking for rechecks ..

*** Found 70 checksums in 006410010A0.bin

*** DONE! 0 error(s) in 006410010A0.bin! ***
Stock ME7.1.1 dump: 70 checksums found, none wrong. This is the “run it on the original first” result you want before touching anything.
me7sum image.bin
Step #2: Reading ROMSYS ..
 Startup section: word[0x008000]+word[0x00FFFE]
 @08038 Add=0x0000BDFF CalcAdd=0x0000BDFE ** NOT OK **
 All param page: word[0x010000]+word[0x01FFFE]
 @01f0f4 Add=0x00971D CalcAdd=0x00971D  ADD OK

Step #7: Reading Main Program Checksums ..
 @fffe0 Chk: A00DBC04 CalcChk: A00DBC03 ** NOT OK **

Step #8: Reading Multipoint Checksum Blocks ..
 5) <1fc1e>  0x008000-0x00BFFF Chk: 103D4DA5 CalcChk: 103D4DA4 ** NOT OK **

*** Found 70 checksums in image.bin

*** WARNING! 3/3 uncorrected error(s) in image.bin! ***
Same image after the ROMSYS startup checksum at 0x8038 was flipped. One bad stored sum shows up in ROMSYS, the main program checksum, and the overlapping multipoint block. Check mode reports the errors and writes nothing.
me7sum image.bin out.bin
Step #2: Reading ROMSYS ..
 Startup section: word[0x008000]+word[0x00FFFE]
 @08038 Add=0x0000BDFF CalcAdd=0x0000BDFE ** FIXED **
 All param page: word[0x010000]+word[0x01FFFE]
 @01f0f4 Add=0x00971D CalcAdd=0x00971D  ADD OK

Step #7: Reading Main Program Checksums ..
 @fffe0 Chk: A00DBC04 CalcChk: A00DBC04 OK (i)

Step #8: Reading Multipoint Checksum Blocks ..
 5) <1fc1e>  0x008000-0x00BFFF Chk: 103D4DA5 CalcChk: 103D4DA5 OK

Attempting to output corrected firmware file 'out.bin'
þ Opening 'out.bin' file for writing
þ Writing to file
þ Validating size correct 1048576=1048576
þ All OK, closing file

*** DONE! 1/1 error(s) in image.bin corrected in out.bin! ***
Give it an output name and it rewrites the stored sums. Overlapping regions come along for the ride. Then run ME7Check out.bin before you even think about flashing.
me7sum -r report.txt 8D0907551T.bin
# 8D0907551T · Audi S4 APB · 6mt NA
0x00008038-0x0000803a ROMSYS Startup CSUM
 0x00008000-0x00008001
 0x0000fffe-0x0000ffff
0x0001baae-0x0001bab1 ROMSYS ParamPage CSUM
 0x00010000-0x00010001
 0x0001fffe-0x0001ffff
0x000fffe0-0x000fffe7 Main Program Checksum CSUM
3-Main CRC checksum is in 8-Main Program Checksum data: (0x0007d94c-0x0007d94e) overlaps with (0x00020000-0x000fffff): OK
4-Main CRC checksum is in 8-Main Program Checksum data: (0x0007d952-0x0007d954) overlaps with (0x00020000-0x000fffff): OK
5-Main CRC checksum is in 8-Main Program Checksum data: (0x0007d958-0x0007d95a) overlaps with (0x00020000-0x000fffff): OK
6-Main Checksums checksum is in 8-Main Program Checksum data: (0x0007e350-0x0007e352) overlaps with (0x00020000-0x000fffff): OK
 0x00020000-0x000fffff
0x0001fbfa-0x0001fc01 MP Block CSUM
1-ROMSYS Startup checksum is in 13-MP Block data: (0x00008038-0x0000803a) overlaps with (0x00008000-0x0000bfff): OK
7-ROMSYS ProgramPages checksum is in 13-MP Block data: (0x0000803c-0x0000803f) overlaps with (0x00008000-0x0000bfff): OK
 0x00008000-0x0000bfff
Checksum map from the example corpus (8D0907551T, Audi S4). -r report.txt lists every stored sum and the ranges it covers, including overlaps that need a recheck.

Porsche ME7.2

986 Boxster · 996 Carrera

Porsche ROMs are auto-detected. Stock factory binaries do not need -p. Detection uses the Bosch part-number block at 0x1FCBE. Offsets below were checked on 157 factory files (124 × 986, 33 × 996) with no false positives on 85+ VAG ME7.x ROMs.

Check How it is stored
ROMSYS Startup word[0x8000] + word[0xFFFE] @0x8038
ROMSYS ParamPage word[0x10000] + word[0x1FFFE] @0x18000
ROMSYS ProgramPages 8 KB page first+last words, 0x0000–0xFFFF + 0x20000–0x37FFF @0x803C
Calibration CRC32 CRC32 over 0x10000–0x1FC03 @0x1FC0E
Multipoint block 1 2 descriptors @0x17D26
Multipoint block 2 32 descriptors @0x1EAA6

Some aftermarket Porsche tunes leave one or more checksums wrong on purpose. Verify a stock factory binary before working on modified files.

Do not use this on tuner-modified binaries

  • Many tuners change CRC/checksum algorithms so their files cannot be edited. ME7Sum will usually miss that. ME7Check might notice; it cannot be sure.
  • Never run ME7Sum on a file you did not write yourself.
  • Do not flash anything without a backup ECU or a way back to a known-good bin.
  • RSA-corrected bins should still pass ME7Check. If they do not, send the file or post it on NefMoto.

Build

Linux · Windows · macOS · Cygwin

Unixmake

Linux / macOS / Cygwin

make
make test

Debian: libgmp-dev. Cygwin: libgmp-devel. macOS: brew install gmp.

Windowsnmake

MSVC

build clean
build

Uses bundled MPIR. See BUILD.md.

Also

related