RE paperConfirmed

Reverse engineering paper #1 — the export Sealion 7 has no navigation engine

The export head unit carries no map engine at all. Navigation is the phone's, projected — and that changes what an app on this car can and cannot do.

BYD LabVerified 4 min read

Domestic BYD unit Export Sealion 7 OneCore map engine NDS map database no map engine Android Auto · CarPlay phone the export unit is a display — every route is computed on the phone

Our own app. Sealion 7 Pilot is developed by BYD Lab. It is held to the same standards as every other app on this site — read with that in mind.

Tested on

Vehicle
BYD Sealion 7 · Morocco
Head-unit version
51.1.4.2606220.1
Android
11
Verified

Every assumption anyone makes about writing software for a Sealion 7 depends on this one fact, and it is not the fact most people assume.

Question#

Does an export-market Sealion 7 head unit run BYD’s own navigation engine — the one the domestic cars ship — or does it not have one at all?

Environment#

Decompiled read-only with jadx 1.5.5 from APKs pulled off the unit: BydSpotifyMusic.apk, CarAdapterService.apk, ClusterCommService.apk and ts-ncm-service.apk. Probed on the car over adb with pm, dumpsys and getprop. The unit identifies as ro.product.model = BYD AUTO, ro.product.device = DX_BYD_AUTO, ro.hardware = qcom — a Qualcomm SA8155-class platform running Android 11, with a ThunderSoft (“ts”) software layer on top.

Observation#

There is no turn-by-turn application on the car. A package listing and a launcher-activity query return no Neusoft, no OneCore and no Telenav map activity. The only launcher entry with a map-ish name is com.telenav.scoutivi.spotify.byd, and reading it shows it is a Spotify client with car controls attached — its Application class is BYDApplication, it bundles BYD’s vehicle SDK, and it draws no map.

What is installed is a complete projection stack: com.ts.androidauto.app with com.ts.androidauto.projectionservice for Android Auto, and com.ts.carplay.app / com.ts.carplay for CarPlay.

Evidence#

For contrast, here is what the domestic stack looks like. This part is the surviving record of an earlier decompile of BydMapLauncher.apk (v9.26.16.2b-G_NEU); that APK is not installed on this export unit and was not re-obtained, so it is reported as previously found rather than re-verified.

Interpretation#

Two different navigation stacks carry the BYD badge, and they have almost nothing in common.

The domestic one is a full on-board engine: it owns the position filter, the dead reckoning, the map matching and the car marker. Everything hard about vehicle positioning happens inside a native library on the head unit.

The export one is not a smaller version of that. It is the absence of that. On this car the head unit is a display, an input surface and a provider of vehicle signals — and every piece of navigation logic runs on a phone, in Google Maps or Apple Maps, behind a projection link.

Result#

Confirmed: the export Sealion 7 head unit has no on-board navigation engine. Navigation is delivered entirely by phone projection. Map matching, smoothing, dead reckoning, U-turn handling and divided-road logic all happen in the phone application; none of it exists on the car.

Three consequences follow for anyone writing software for this unit, and they are the reason the rest of this series exists:

  • An app that wants to navigate on this car is the navigation app. Nothing on the unit will map-match a position for it, and there is no engine to ask.
  • The unit is still a rich source of vehicle signals, and those are worth having — paper #2 is the catalogue.
  • The instrument cluster is reachable, but not through anything a domestic BYD app would use — the export unit routes through a different service entirely (paper #7).

Limitations#

One car, one market (Morocco), one head-unit build. Other export markets have not been checked and may ship a different package set; an EU or GCC car could plausibly carry a navigation app this one does not. Nothing here says anything about domestic Chinese units beyond the labelled record above, which was not re-verified.

The domestic-stack description is a second-hand record of our own earlier work, not a fresh decompile. Its native parameter names and thresholds are reported as previously found.

Reproduction#

On a car with adb reachable (our guide covers getting there):

Shell
adb shell pm list packages | grep -iE 'neusoft|onecore|navi|map|telenav'
adb shell cmd package query-activities -a android.intent.action.MAIN -c android.intent.category.LAUNCHER
adb shell getprop ro.product.device
adb shell getprop ro.build.fingerprint

The first command should return no navigation engine. The second lists everything the launcher can start — read it in full rather than grepping, because the interesting result here is an absence, and an absence does not match a pattern.