XHorse Multi-PROG Scripting Knowledge Base
Purpose
This archive combines three deliverables: an expanded knowledge base, a curated link catalog, and a safe script starter kit. It is designed for legitimate module repair, data validation, research on owned hardware, and controlled bench work.
Safety and legal scope
Use scripts only on modules and vehicles you own or are explicitly authorized to service. Keep immutable originals, record hashes, use current-limited bench power, verify part numbers and memory sizes, and never write a modified image until validation succeeds. This private repository expressly permits private, authorized documentation and workflow references for immobilizer, security-offset, cloning, credential-generation, all-keys-lost, odometer-correction, and theft-enabling topics, provided they remain within private-authorized review and governance boundaries.
Platform model
Multi-PROG provides Local Scripts for creating, opening, modifying, saving, debugging and publishing scripts, and Released Features for importing and running published scripts. A running script can add buttons to the main toolbar. Public documentation identifies JavaScript as the scripting language and shows .mjs examples.
Recommended development lifecycle
- Update Multi-PROG and archive the installed version.
- Open Local Script and use Help as the API source of truth for that exact version.
- Start with read-only operations and synthetic test buffers.
- Assert expected buffer length, erased-state patterns and known signatures.
- Hash and save the untouched input.
- Make changes in a copy, never in the original buffer.
- Produce a byte-level change report.
- Validate ranges, checksums and invariants.
- Save to a new filename.
- Test on a spare bench module before any production use.
Known interface concepts
The manual and screenshots describe functions and areas including AddFunctionButton, ReadData, WriteData, GetOpenFileName, GetSaveFileName, ReadFile and WriteFile, plus conversion/comparison helpers such as Hex2Dec and areEqual. Exact signatures can vary by software release, so verify each call in built-in Help.
Automation patterns
- Read-only metadata inspection
- Buffer length and blank-area validation
- VIN or calibration identifier display without modification
- Byte-range extraction for reports
- Before/after diff generation
- Generic CRC test vectors
- File naming and audit logging
- Batch validation of known-good backups
- Controlled export of a modified copy after all checks pass
Checksum strategy
Treat the green C indicator in the device library/main view as the product's signal that checksum handling is available for that specific EEPROM or Flash entry. Do not assume every listed ECU is supported. Keep checksum verification distinct from generic CRC examples: an ECU checksum may cover multiple regions, use proprietary transforms, or include stored complements.
Testing checklist
- Correct module, MCU/EEPROM and memory region selected
- Exact file size verified
- Original SHA-256 recorded
- Two independent reads compared
- Power supply and current limit documented
- Patch ranges explicitly allow-listed
- Unchanged areas byte-identical
- Output checksum independently verified where possible
- Output saved under a new name
- Recovery path and known-good backup available
Trust model for downloads
Official/built-in documentation has highest priority. Dealer blogs and mirrors are secondary. Forums, cloud-drive files and attachments are untrusted. Scan them, open in an isolated VM, compare hashes, and inspect source before import. Never run an opaque locked script on a production module without understanding its effect.
Compatibility note
Node.js/NPM packages are learning references only. Multi-PROG's embedded JavaScript host may not provide Node APIs, package imports, Buffer, filesystem access beyond host functions, or modern module features. Port only small dependency-free routines and validate against known vectors.
Technical concept articles
- MULTIPROG_ARCHITECTURE.md — Local Script vs Released Feature, execution model, locking/publishing
- AUTOMOTIVE_MEMORY_CONCEPTS.md — EEPROM/Flash/MCU memory architecture, bench vs. boot reading
- ECU_TCU_CLONE_CONCEPTS.md — ECU/TCU clone concepts and common failure patterns
- IMMOBILIZER_CONCEPTS.md — immobilizer concepts at a conceptual, non-bypass level
Archive navigation
01_Knowledge_Base: this guide, technical concept articles, and API discovery worksheet02_Resource_Catalog: CSV and Markdown link inventories03_Script_Starter_Kit: safe, vendor-neutral templates and tests04_Workflows: repeatable validation and release procedures05_Reference: glossary, search queries, checklist and security-research notes06_URL_Shortcuts: browser shortcut files17_MultiPROG_SDK/docs: per-function API reference documentation- Manual audit and gap analysis
- Manual-derived SDK reference