Files

5.1 KiB

XHorse Multi-PROG Scripting Knowledge Base

Purpose

This archive combines three deliverables: an expanded knowledge base, a curated link catalog, and a safe script starter kit. It is designed for legitimate module repair, data validation, research on owned hardware, and controlled bench work.

Use scripts only on modules and vehicles you own or are explicitly authorized to service. Keep immutable originals, record hashes, use current-limited bench power, verify part numbers and memory sizes, and never write a modified image until validation succeeds. This private repository expressly permits private, authorized documentation and workflow references for immobilizer, security-offset, cloning, credential-generation, all-keys-lost, odometer-correction, and theft-enabling topics, provided they remain within private-authorized review and governance boundaries.

Platform model

Multi-PROG provides Local Scripts for creating, opening, modifying, saving, debugging and publishing scripts, and Released Features for importing and running published scripts. A running script can add buttons to the main toolbar. Public documentation identifies JavaScript as the scripting language and shows .mjs examples.

  1. Update Multi-PROG and archive the installed version.
  2. Open Local Script and use Help as the API source of truth for that exact version.
  3. Start with read-only operations and synthetic test buffers.
  4. Assert expected buffer length, erased-state patterns and known signatures.
  5. Hash and save the untouched input.
  6. Make changes in a copy, never in the original buffer.
  7. Produce a byte-level change report.
  8. Validate ranges, checksums and invariants.
  9. Save to a new filename.
  10. Test on a spare bench module before any production use.

Known interface concepts

The manual and screenshots describe functions and areas including AddFunctionButton, ReadData, WriteData, GetOpenFileName, GetSaveFileName, ReadFile and WriteFile, plus conversion/comparison helpers such as Hex2Dec and areEqual. Exact signatures can vary by software release, so verify each call in built-in Help.

Automation patterns

  • Read-only metadata inspection
  • Buffer length and blank-area validation
  • VIN or calibration identifier display without modification
  • Byte-range extraction for reports
  • Before/after diff generation
  • Generic CRC test vectors
  • File naming and audit logging
  • Batch validation of known-good backups
  • Controlled export of a modified copy after all checks pass

Checksum strategy

Treat the green C indicator in the device library/main view as the product's signal that checksum handling is available for that specific EEPROM or Flash entry. Do not assume every listed ECU is supported. Keep checksum verification distinct from generic CRC examples: an ECU checksum may cover multiple regions, use proprietary transforms, or include stored complements.

Testing checklist

  • Correct module, MCU/EEPROM and memory region selected
  • Exact file size verified
  • Original SHA-256 recorded
  • Two independent reads compared
  • Power supply and current limit documented
  • Patch ranges explicitly allow-listed
  • Unchanged areas byte-identical
  • Output checksum independently verified where possible
  • Output saved under a new name
  • Recovery path and known-good backup available

Trust model for downloads

Official/built-in documentation has highest priority. Dealer blogs and mirrors are secondary. Forums, cloud-drive files and attachments are untrusted. Scan them, open in an isolated VM, compare hashes, and inspect source before import. Never run an opaque locked script on a production module without understanding its effect.

Compatibility note

Node.js/NPM packages are learning references only. Multi-PROG's embedded JavaScript host may not provide Node APIs, package imports, Buffer, filesystem access beyond host functions, or modern module features. Port only small dependency-free routines and validate against known vectors.

Technical concept articles

Archive navigation

  • 01_Knowledge_Base: this guide, technical concept articles, and API discovery worksheet
  • 02_Resource_Catalog: CSV and Markdown link inventories
  • 03_Script_Starter_Kit: safe, vendor-neutral templates and tests
  • 04_Workflows: repeatable validation and release procedures
  • 05_Reference: glossary, search queries, checklist and security-research notes
  • 06_URL_Shortcuts: browser shortcut files
  • 17_MultiPROG_SDK/docs: per-function API reference documentation
  • Manual audit and gap analysis
  • Manual-derived SDK reference