}0a000 {2{f THE COMPLETE AMIGA 1.3 ROM DISASSEMBLY {1{a {a Okay, how many of you guys used to own Sinclair Spectrums? How many of you used to use them for serious purposes? (Coding! :-) How many of you remember the book by Melbourne House called "The complete Spectrum ROM Disassembly"? That's what has inspired me to totally rip the guts out of that lump of silicon that Commodore call OS1.3 If any Workbench 2.0 owners want to run a similiar series, then write to to me (Terminator) at the address at the end of this article. Please also contact me if you want to assist with the 1.3 disassembly. Note, that due to the immense size of this disassembly, there is no way that it could be printed in one issue. (I have currently disassembled from $fc0000 to $fe0000 and it's over 600k!) I have currently only started commenting from $fc0000 to $fd0000 If I make any mistakes in the comments, then please let me know. This article will be serialised until it is complete, that is unless we fail to stir up any interest in this series. If you want it to stay, then let us know! We need to know what you want to see!!! After the entire ROM disassembly has been completed, Destiny will release it seperatly from Satanic Rites (Probably on 2 disks!) Ok, enough crap talk, lets get on with that disassembly! *NOTE: That I have replaced absolute addresses with labels. * $FC00D2 becomes FC00D2 1.3ROM.S (Part #1) FC0000 MOVE.B (A1),-(A0) ; unknown purpose JMP FC00D2 ; Jump to reset routine dc.l $0000FFFF dc.l $00220005 FC0010 dc.w $0022 ; Exec version dc.w $0002 dc.l $FFFFFFFF exec34228Oct1 dc.b 'exec 34.2 (28 Oct 1987)',$D,$A,0 dc.l $0000FFFF dc.w $FFFF dc.b 13 dc.b 10 dc.b 10 dc.b 'AMIGA ROM Operating System and Libraries',$D,$A dc.b 'Copyright (C) 1985, Commodore-Amiga, Inc.',$D,$A dc.b 'All Rights Reserved.',$D,$A,0 dc.b 0 execlibrary dc.b 'exec.library',0,0 dc.w $0000 FC00B6 dc.w $4AFC ; RT_Matchword dc.l $FC00B6 ; Struct resident. dc.l $FC3276 ; RT_Endskip dc.b $00 ; RT_Flags dc.b $22 ; RT_Version (34) dc.b $09 ; RT_Type (Library) dc.b $78 ; RT_Pri (+120) dc.l ExecLibrary ; RT_Name dc.l exec34228Oct1 ; RT_Idstring dc.l $FC00D2 ; RT_Init dc.w $4e70 ญญญญญ The reset routine. ญญญญญ FC00D2 LEA $40000,SP ; Repoint stack MOVE.L #$20000,D0 ; Length of delay (delay probably to ; ensure that drives have stopped FC00DE SUBQ.L #1,D0 ; decrement delay BGT.S FC00DE ; continue delay LEA FC0000(PC),A0 ; First address in ROM LEA $F00000,A1 ; additional ROM module CMP.L A1,A0 ; are contents the same? BEQ.S FC00FE ; if so, f00000 is a copy LEA FC00FE(PC),A5 ; Address of reset routine CMP.W #$1111,(A1) ; Is first word in $f00000 = $1111 BNE.S FC00FE ; If not, go to reset routine JMP 2(A1) ; Jump to $f00002. Hey! Why not place a ; reset cartridge here ? ($f00000) FC00FE MOVE.B #3,$BFE201 ; Set DDR(a) to output (lower 2 bits) MOVE.B #2,$BFE001 ; Turn off power LED LEA $DFF000,A4 ; custom chip base address MOVE.W #$7FFF,D0 ; bitmask for all OFF MOVE.W D0,$09A(A4) ; Intena MOVE.W D0,$09C(A4) ; Intreq MOVE.W D0,$096(A4) ; Dmacon MOVE.W #$0200,$100(A4) ; Bplcon0 - No planes or sprites, Color on MOVE.W #0,$0110(A4) ; Bitplane 1 data (RGB output) MOVE.W #$0444,$180(A4) ; Background Colour MOVE.W #8,A0 ; Destination address for reset code MOVE.W #$2D,D1 ; Number of bytes to copy LEA FC05B4(PC),A1 ; Address of more reset code FC0142 MOVE.L A1,(A0)+ ; Copy reset code DBRA D1,FC0142 ; Continue copying BRA FC3100 ; Check if a guru is present FC014C MOVE.L 4,D0 ; Get current execbase value BTST #0,D0 ; Is it a word value? BNE.S FC01CE ; No, recalculate execbase base ! MOVE.L D0,A6 ; Copy execbase ADD.L $26(A6),D0 ; Add ChkBase NOT.L D0 ; Invert the value BNE.S FC01CE ; If its not 0, then recalculate execbase MOVEQ #0,D1 ; Clear Register to be used as checksum LEA $22(A6),A0 ; SoftVer - Start of vectors to be summed MOVEQ #$18,D0 ; Number of vectors FC0168 ADD.W (A0)+,D1 ; Add each vector to a running total DBRA D0,FC0168 ; Loop until copied NOT.W D1 ; Invert the value BNE.S FC01CE ; Execbase is wrong. Recalculate MOVE.L $2A(A6),D0 ; Get ColdCapture contents BEQ.S FC0184 ; It is set to 0 so skip this... MOVE.L D0,A0 ; Get address of resetresident code LEA FC0184(PC),A5 ; Return address after ColdCapturecode CLR.L $2A(A6) ; Clear coldCapture JMP (A0) ; Activate code Coldcapture WAS pointing to ญญญญญ At this point, we jump to wherever Coldcapture pointed to ญญญญญ When we exit from the custom routine, we return here... FC0184 BCHG #1,$BFE001 ; Invert current PowerLED status MOVE.L FC0010(PC),D0 ; ROM exec version CMP.L $14(A6),D0 ; execversion from execbase BNE.S FC01CE ; if not the same, recalculate MOVE.L $3E(A6),A3 ; MaxLocMem CMP.L #$80000,A3 ; top of chip ram = $80000? BHI.S FC01CE ; Higher, recalculate execbase CMP.L #$40000,A3 ; only 256k chipram? BCS.S FC01CE ; No we have more! MOVE.L $4E(A6),A4 ; MaxExtMem MOVE.L A4,D0 ; Copy BEQ FC0240 ; No extended memory? CMP.L #$DC0000,A4 ; Ends at $dc0000? BHI.S FC01CE ; No! Higher! CMP.L #$C40000,A4 ; Ends at $c40000 BCS.S FC01CE ; No we have more! MOVE.L A4,D0 ; Copy (again?) AND.L #$3FFFF,D0 ; mask out unwanted crap BEQ.S FC0240 ; left with nothing? This routine recalculates the Execbase structure. FC01CE LEA $400,A6 SUB.W #$FD8A,A6 ; Determine Execbase base LEA $C00000,A0 LEA $DC0000,A1 LEA FC01EA(PC),A5 BRA FC061A FC01EA MOVE.L A4,D0 BEQ.S FC0208 MOVE.L #$C00000,A6 SUB.W #$FD8A,A6 MOVE.L A4,D0 LEA $C00000,A0 LEA FC0208(PC),A5 BRA FC0602 FC0208 LEA 0,A0 LEA $200000,A1 LEA FC021A(PC),A5 BRA FC0592 FC021A CMP.L #$40000,A3 BCS.S FC0238 MOVE.L #0,0 MOVE.L A3,D0 LEA $C0,A0 LEA FC0240(PC),A5 BRA FC0602 FC0238 MOVE.W #$C0,D0 BRA FC05B8 FC0240 LEA $DFF000,A0 ; Custom chipbase MOVE.W #$7FFF,$096(A0) ; Turn off all DMA MOVE.W #$0200,$100(A0) ; No bitplanes MOVE.W #0,$110(A0) ; Bitplane data MOVE.W #$888,$180(A0) ; background colour LEA $54(A6),A0 ; IntVecs (Execbase) MOVEM.L $222(A6),D2-D4 ; KickCheckSum MOVEQ #0,D0 ; Data to fill memory with MOVE.W #$7D,D1 ; amount of memory to clear FC026E MOVE.L D0,(A0)+ ; clear Interupt vectors DBRA D1,FC026E ; Keep clearing mem MOVEM.L D2-D4,$222(A6) ; Restore KickCheckSum MOVE.L A6,4 ; Insert correct Execbase pointer into 4 MOVE.L A6,D0 ; Copy Execbase NOT.L D0 ; Invert MOVE.L D0,$26(A6) ; Store in Chkbase (Execbase) MOVE.L A4,D0 BNE.S FC028C MOVE.L A3,D0 FC028C MOVE.L D0,SP MOVE.L D0,$36(A6) ; SysStkUpper SUB.L #$1800,D0 MOVE.L D0,$3A(A6) ; SysStkLower MOVE.L A3,$3E(A6) ; MaxLocMem MOVE.L A4,$4E(A6) ; MaxExtMem BSR FC3120 ; Update Last Alert BSR FC0546 OR.W D0,$128(A6) ; AttnFlags LEA FC02D2(PC),A1 ; Address of list of offsets FC02B4 MOVE.W (A1)+,D0 ; Get execbase offset BEQ FC033E ; If it's a zero then quit this routine LEA (A6,D0.W),A0 ; Move to the offset in Execbase MOVE.L A0,(A0) ADDQ.L #4,(A0) CLR.L 4(A0) MOVE.L A0,8(A0) MOVE.W (A1)+,D0 ; Get value MOVE.B D0,12(A0) BRA.S FC02B4 ; Get next entry FC02D2 dc.l $0142000A ; MemList dc.l $01500008 ; ResourceList dc.l $015E0003 ; DeviceList dc.l $017A0009 ; Liblist dc.l $01880004 ; PortList dc.l $01960001 ; TaskReady dc.l $01A40001 ; TaskWait dc.l $016C0002 ; IntrList dc.l $01B2000B ; SoftInts dc.l $01C2000B ; dc.l $01D2000B ; dc.l $01E2000B ; dc.l $01F2000B ; dc.l $0214000F ; SemaphoreList dc.w 0 FC030C dc.w $0900 dc.l FC00A8 ; Pointer to the text :- "exec.library" dc.w $0600 dc.l $0000024C dc.l $00220002 dc.l exec34228Oct1 dc.l 0 dc.w 1 ChipMemory dc.b 'Chip Memory',0 FastMemory dc.b 'Fast Memory',0 FC033E LEA FC2FF0(PC),A0 ; Pointer to TaskTrapCode MOVE.L A0,$130(A6) ; TaskTrapCode MOVE.L A0,$134(A6) ; TaskExceptCode MOVE.L #FC1D28,$138(A6) ; TaskExitCode MOVE.L #$FFFF,$13C(A6) ; TaskSignalAlloc MOVE.W #$8000,$140(A6) ; TaskTrapAlloc LEA 8(A6),A1 ; Execbase header LEA FC030C(PC),A0 ; Library header MOVEQ #12,D0 ; Size of header FC036A MOVE.W (A0)+,(A1)+ ; Copy header data DBRA D0,FC036A ; Do copy MOVE.L A6,A0 LEA FC1A7C(PC),A1 MOVE.L A1,A2 BSR FC15B2 MOVE.W D0,$10(A6) MOVE.L A4,D0 BEQ.S FC03A8 LEA $24C(A6),A0 LEA FastMemory(PC),A1 MOVEQ #0,D2 MOVE.W #5,D1 MOVE.L A4,D0 SUB.L A0,D0 SUB.L #$1800,D0 BSR FC1A26 LEA $400,A0 MOVEQ #0,D0 BRA.S FC03B2 FC03A8 LEA $24C(A6),A0 MOVE.L #$FFFFE800,D0 FC03B2 MOVE.W #3,D1 MOVE.L A0,A2 LEA ChipMemory(PC),A1 MOVEQ #-$A,D2 ADD.L A3,D0 SUB.L A0,D0 BSR FC1A26 MOVE.L A6,A1 BSR FC1448 LEA FC07B4(PC),A0 MOVE.L A0,A1 MOVE.W #8,A2 BRA.S FC03DE FC03D8 LEA (A0,D0.W),A3 MOVE.L A3,(A2)+ FC03DE MOVE.W (A1)+,D0 BNE.S FC03D8 MOVE.W $128(A6),D0 BTST #0,D0 BEQ.S FC041E LEA FC08B8(PC),A0 MOVE.W #8,A1 MOVE.L A0,(A1)+ MOVE.L A0,(A1)+ MOVE.L #FC08F6,-$1C(A6) MOVE.L #$42C04E75,-$210(A6) BTST #4,D0 BEQ.S FC041E MOVE.L #FC10C6,-$34(A6) MOVE.L #FC1124,-$3A(A6) FC041E BSR FC1298 LEA $DFF000,A0 ; Hardware base address MOVE.W #$8200,$96(A0) ; Dma MOVE.W #$C000,$9A(A0) ; Interupts MOVE.W #$FFFF,$126(A6) ; Sprite 1 pointer low word BSR FC2336 MOVEQ #0,D1 LEA $22(A6),A0 ; SoftVer MOVE.W #$16,D0 ; Size of code to checksum FC0448 ADD.W (A0)+,D1 ; increase checksum DBRA D0,FC0448 NOT.W D1 ; Invert checksum MOVE.W D1,$52(A6) ; Store in ChkSum (Execbase) LEA FC04CC(PC),A0 BSR FC195A MOVE.L D0,A2 LEA $1010(A2),A0 LEA 8(A0),A1 ADD.L #$10,D0 MOVE.L D0,$3A(A1) MOVE.L A0,$3E(A1) MOVE.L A0,$36(A1) MOVE A0,USP CLR.B 9(A1) MOVE.B 1,8(A1) MOVE.L #execlibrary,10(A1) LEA $4A(A1),A0 MOVE.L A0,(A0) ADDQ.L #4,(A0) CLR.L 4(A0) MOVE.L A0,8(A0) EXG A2,A1 BSR FC1614 EXG A2,A1 MOVE.L A1,$0114(A6) SUB.L A2,A2 MOVE.L A2,A3 BSR FC1C84 MOVE.L $0114(A6),A1 MOVE.B #2,15(A1) BSR FC163C AND.W #0,SR ADDQ.B #1,$0127(A6) JSR -$8A(A6) BRA.S FC0500 FC04CC dc.l 0 dc.l 0 dc.l 0 dc.l 1 dc.l $00010001 dc.l $00001064 FC04E4 dc.l FC0000 dc.l $01000000 dc.l FC0000 dc.l $01000000 dc.l F00000 dc.l F80000 dc.l $FFFFFFFF FC0500 LEA FC04E4(PC),A0 BSR FC093C MOVE.L D0,$012C(A6) ; ResModules BCLR #1,$BFE001 ; Turn on PowerLED MOVE.L $002E(A6),D0 ; CoolCapture BEQ.S FC051E ; If CoolCapture = 0 then skip this code MOVE.L D0,A0 ; Get CoolCApture entry JSR (A0) ; Jump to it ญญญญญ At this point we jump to wherever CoolCapture is pointing to FC051E MOVEQ #1,D0 MOVEQ #0,D1 BSR FC0B2C MOVE.L $32(A6),D0 ; WarmCapture BEQ.S FC0530 ; If WarmCapture = 0 then skip this code MOVE.L D0,A0 ; Copy Warmcapture entry JSR (A0) ; Jump to it. ญญญญญ Despite what it says in the Advanced system programmers guide, ญญญญญ Control is passed here to wherever Warmcapture points to. That's your lot for this month, next time, we'll be looking at exceptions, guru handlers, interupts and a few of the exec library routines. -Terminator. Terminator/Destiny 40, Heol Edward Lewis, Gelligaer, Mid Glamorgan, South Wales. CF8 8EJ