When a write is interrupted
The situation nobody documents and everybody eventually meets. What state the controller is actually in, what recovers it, and the three decisions made before the write that determine how bad it is.
There is a remarkable silence in this industry around what happens when a write does not complete. Tool manufacturers describe the risk as minimal if procedures are followed – which is true and is not an answer. Search for what to do afterwards and you find forum threads, some of them helpful and most of them about cars.
So here is the situation described plainly, for machinery.
What state the controller is actually in
A write is not a single event. The controller erases a region of memory and then programs the new content into it. An interruption therefore does not leave you with “the old software” or “the new software” – it leaves you with whatever the operation had got to, and where that falls determines almost everything about what follows.
| Where it stopped | Typical state | Typical route back |
|---|---|---|
| Before erase began | Controller untouched | Establish the cause, then retry |
| During calibration programming | Bootloader and core software intact, calibration region incomplete | Often recoverable through the same access method |
| During core software programming | Controller may no longer communicate normally | Usually needs bench or boot access, and the original file |
| During bootloader region | Worst case – the part that makes recovery possible is itself incomplete | Boot-level work, replacement, or cloning to a known-good unit |
The pattern worth internalising: the further down the stack the interruption reaches, the deeper the access you need to get back. A machine that could be worked on through the diagnostic port before the failure frequently cannot be afterwards. That is the real cost of an interrupted write – not the file, the access.
The backup question, which is more complicated than it looks
Everyone says take a backup first. Fewer people check whether one was actually taken.
Autotuner documents that backups are created automatically on boot and bench reads – and explicitly not on OBD reads. They land in a folder under the user’s documents directory, named with date, tool serial, machine and method, as a compressed archive for master tools and an encrypted file for slaves.
Alientech’s position is less clear from public documentation. Cloud backup management is sold as a separate paid option, and distributor guidance advises creating your own folder structure per vehicle – which is not what you would write if comprehensive automatic local backups were the default. Whether and where KESS3 stores an automatic local original is not something we could establish from published sources, and it is worth confirming with your dealer rather than discovering after the fact.
The combination that catches people out: newly released OBD protocols for agricultural platforms, used on machines in the field, where an OBD read may not have produced a backup at all. The convenience of port access and the absence of an automatic backup arrive together, and the second one is invisible until it matters.
Before writing, know where your original is. Not “the tool probably saved it” – know.
What recovery actually exists
Retry through the same access method
Where the interruption did not reach the core software, the controller often still communicates enough to accept another attempt. Both major tools describe recovery or resume behaviour for interrupted operations, though neither documents its limits in any detail. This is the good outcome and it is the common one when the cause was a momentary supply sag rather than a disconnection.
Escalating to bench or boot
Where port access is gone, the route back is physical. This is the point at which an interrupted write stops being a software problem and becomes a removal job, with everything that implies for the machine’s downtime.
Cloning to a replacement unit
Alientech in particular presents cloning as its answer to failed and replaced controllers – transferring the contents of an original unit into an identical replacement, new or used. For machinery this is genuinely useful, because a dealer-supplied replacement controller is frequently a programming event in its own right with days of waiting attached. Cloning is documented as available on a number of off-highway protocols; it is not available on all of them.
Mail-in services – and what they are not
Autotuner operates a mail-in service for its supported platforms, published at €250 in Europe and $399 in the United States as of September 2026, with the work done within 24 hours of arrival and total turnaround typically two to three days. It covers one agricultural controller pair in its published catalogue.
It is important to be clear about what this service is: it is a preparation service for supported platforms, not a rescue service for controllers that failed mid-write. Its published exclusions include physically opened units and damaged connector pins. Alientech publishes no equivalent service at all.
The blunt version: neither major tool manufacturer publishes a recovery service, a price, or a turnaround for a controller that failed during a write. There is support, and support may well solve it. But there is no published product for the situation, which means the planning for it has to happen before the write, not after.
Three decisions made before the write
Almost everything about how bad an interrupted write turns out was decided beforehand. Three things in particular:
- Is there a verified original, and do you know where it is? Not assumed – verified. This is the single decision that separates an afternoon from a week.
- Is the supply capable of holding voltage under load for the whole operation? Supply failure is the most common cause of the situation this page describes. See power supply for ECU programming.
- Is this the right moment? Not before a shift change, not with a machine that needs to move, not on a connection you are unsure of, not at the end of a long day. A write is a few minutes of not being interrupted, and the discipline is in choosing when those minutes happen.
A second read before writing
One more point, because it is specific and it catches experienced people. Autotuner instructs users to perform a fresh read immediately before writing rather than relying on a file read earlier, because the manufacturer may have updated the controller in the meantime. Writing content built against a software state the controller has since left is a documented route to a machine that will not communicate afterwards.
On machinery this is more relevant than it sounds, not less. Connected machines receive software updates, and a machine that sat in the yard for three weeks between the read and the appointment is not necessarily in the state you read.
What we can help with
- Original software for the exact controller and software version, so a machine can be returned to a defined state
- Establishing what state a controller is actually in after a failed operation, before anything else is attempted
- Machines that were worked on elsewhere and came back worse – this is a large part of what we do
- Off-highway platforms that are not well served by generic file portals
Tell us the machine, the controller, the software version and what happened. If it is not something we can help with, we will say so.
Frequently asked questions
Is the ECU destroyed if a write is interrupted?
Usually not. Where the interruption reached determines the outcome: an interruption during calibration programming is frequently recoverable through the same access method, while one that reaches the core software or bootloader region typically requires bench or boot access to resolve. Physical destruction is rare; loss of easy access is common.
Does my tool always save the original file?
No, and this is worth checking rather than assuming. Autotuner documents automatic backups on boot and bench reads but explicitly not on OBD reads. For other tools the behaviour is not always published. Establish where your originals are stored before you need one.
Can the manufacturer recover it?
A dealer can generally reprogram a controller, and on machinery that is a scheduled, chargeable event with the machine standing still – which is the outcome most workshops are trying to avoid. It is a route back, not a free one.
What is the most common cause?
Loss of supply during the operation. Not tool failure, not a bad file – voltage that sagged under load partway through, on a battery that measured perfectly well before it started.
Machine down after a failed write?
Tell us the machine, the ECU and what you are seeing. You get an honest assessment of what is realistic before you order a single part.
Related in our knowledge base
Byte Performance develops ECU software for agricultural, construction and forestry machinery and works with machinery dealers and professional workshops. The information on this page is general technical guidance and does not replace diagnosis on the machine. Emission control systems are subject to different legal requirements in different markets; the operator is responsible for compliance in their own market.