From bf3b0f1cc1faffa587ba4acf424f0317157832ea Mon Sep 17 00:00:00 2001 From: Cyd Date: Sun, 19 Jul 2026 17:20:40 -0500 Subject: [PATCH] Edit 7: RIOv4_3 reports firmware version 4.3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The VersionReply builder at $C6EA hardcoded 4.2; --reportversion=4.3 patches the minor operand byte ($C6FF: 02->03). Verified no host software gates on the value (legacy prints it, RIOJoy parses it, native games ignore it — Cyd). Rebuilt RIOv4_3.bin: 69 bytes vs stock, sha 6d67a2fc7713...; docs updated. Chips burned before this edit still announce 4.2 — re-burn to pick up the number; all other bytes match the certified image. Co-Authored-By: Claude Fable 5 --- README.md | 13 ++++++++++--- RIOv4_2-ANALYSIS.md | 9 +++++++-- RIOv4_3.bin | 2 +- RIOv4_3.disasm.asm | 2 +- make_patch.py | 18 ++++++++++++++++++ 5 files changed, 37 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index c8c442a8..7cff22d7 100644 --- a/README.md +++ b/README.md @@ -44,9 +44,10 @@ widen its window, burn a new EPROM, keep this original safe. ## RIO 4.3 — `RIOv4_3.bin` (current production firmware) **Christened 2026-07-19** after full on-hardware certification. Built -by `make_patch.py --e0thresh=5 --checkrepaint RIOv4_2.bin RIOv4_3.bin`; -sha256 `dc59bd51cae34781cf42f338e44a020b249a4030acc3c584af916aee9ca881e3` -(68 bytes changed vs stock). 9600 baud, native-game compatible. On the +by `make_patch.py --e0thresh=5 --checkrepaint --reportversion=4.3 +RIOv4_2.bin RIOv4_3.bin`; sha256 +`6d67a2fc77130b601fdb0ac02042dd4d0a98ac7e29a8077d588987a81073939c` +(69 bytes changed vs stock). 9600 baud, native-game compatible. On the stock v4.2 base it carries: 1. **Reply-latch wedge fix** (edits 1-2) — bench-certified. @@ -57,6 +58,12 @@ stock v4.2 base it carries: version+check leaves `F0000000` when healthy, and re-renders the E0 readout when counters are over threshold (`E0000305` on the bench) instead of stock's stale `04000000`. +4. **Version bump** (edit 7, `--reportversion=4.3`) — the VersionReply + now announces **4.3** (one operand byte at `$C6FF`). Nothing + host-side validates the value (native games verified not to check + it). The certification runs below were made on the pre-edit-7 bytes; + the only delta is the version literal. Chips burned before this edit + report 4.2 — re-burn to announce 4.3. Certification runs (all in `testlogs/` + RIOv4_2-ANALYSIS.md): two `--e0test` acceptance passes (display verified by eye at each step) and diff --git a/RIOv4_2-ANALYSIS.md b/RIOv4_2-ANALYSIS.md index d6b3c23a..ffbbe413 100644 --- a/RIOv4_2-ANALYSIS.md +++ b/RIOv4_2-ANALYSIS.md @@ -550,5 +550,10 @@ sessions fits this model. presses/min sustained (1129 presses — the heaviest stress run of the campaign), zero wedges, counters flat, NAK 0, 247 resends all healed (`testlogs/riomash-rio43rc1-9600-20260719-164901.log`). `RIOv4_3rc1` -renamed to **`RIOv4_3.bin`** (same bytes, sha `dc59bd51cae3…`) — the -production firmware for native-game cabinets. +renamed to **`RIOv4_3.bin`** — the production firmware for native-game +cabinets. Post-christening, **edit 7** (`--reportversion=4.3`, one +operand byte at `$C6FF` in the VersionReply builder `$C6EA`) makes the +board announce 4.3; final sha256 `6d67a2fc7713…` (69 bytes vs stock). +No host software validates the version value (native games verified +not to check it — Cyd, 2026-07-19); tools will print `firmware: 4.3` +after the next burn. diff --git a/RIOv4_3.bin b/RIOv4_3.bin index 6f41e77a..5c2c460c 100644 --- a/RIOv4_3.bin +++ b/RIOv4_3.bin @@ -5,7 +5,7 @@ &  &&~8$!˧A%523889~;&F(;'~O& ̽;'~^& ;'u~o& 4;'d~€ & h;'S~‘& ɜ;'B~¢&%ұB;'\~¹&ҽJ;'H~Ё&*p;'4~˧; '~A|,$!9&ν~;'~~%~ÐÙi M9 K~S J91Ԣ%9 P۰d< 1 18Z&9" 32< 1 18Z&z 3&9`!b>9H#ν>9H!½>9$>9H$T>9H$>9$Ļ3U9%08 (9 >9 >9oZ&9   Π)Π!Π#Π%Π' 9 Π) 9 Π! 9 Π# 9 Π% 9 Π' 9 '>9$"91D1X 9i&$"1''X' -''9~~ƿâë$$!J1Ѱ$ɽ1S~bNJǵ$! 99˽ 9~ƾi&1'~ƏLiÐÙƽôýâë,$$ J K M 4 7  N$ɽ|$!$B$C$G$E$I$F$J$$K$$H$1111% %!%"~ƾ&z~ƾ&Ċ~ƾ&Ě~ƾ&Ī~ƾ&ĺ9i&1$Gi&1$K$GH$?967<<-A-B;8832967<<-A-B$!;8832967<<-A-B%%;8832967<<-A-B%%;8832967<<-A-B1;8832967<<-A-B1;8832967<<-A-B1;8832967<<$!'0 '% +''9~~ƿâë$$!J1Ѱ$ɽ1S~bNJǵ$! 99˽ 9~ƾi&1'~ƏLiÐÙƽôýâë,$$ J K M 4 7  N$ɽ|$!$B$C$G$E$I$F$J$$K$$H$1111% %!%"~ƾ&z~ƾ&Ċ~ƾ&Ě~ƾ&Ī~ƾ&ĺ9i&1$Gi&1$K$GH$?967<<-A-B;8832967<<-A-B$!;8832967<<-A-B%%;8832967<<-A-B%%;8832967<<-A-B1;8832967<<-A-B1;8832967<<-A-B1;8832967<<$!'0 '% %-B -A<%%8z%&;88329$!'-A$ -B 7;9$!'#%-A$ -B% J;9$!'#%-A$ -B% K;99 LΠ( Π8 !ʗ #ʰ &    9 LΠ Π0 !ʗ #ʰ &    9 LΠ" Π2 !ʗ  #ʰ &     9 LΠ$ Π4 !ʗ  #ʰ &     9 LΠ& Π6 !ʗ  #ʰ &     9 ' L&#  H$ H~ʖ H~ʖ&#  H$ H~ʖ H~ʖ&#  H$ H~ʖ H~ʖ &#  H$ H~ʖ H~ʖ&  H$ H ~ʖ H 9  & ! %9< 89O_ % & #'|   ҽ9<6$!& 8  H  H 6I289<6$!& 8 % H & H 6I289 HDDDD9O L H 9 8962962962962962967<<  N P !̲8832967<<  N : P2: :!̲88329  4 4&~&O~&̀~ͱ "Z& 5 < 1 18Z&z 5&z 4&9  diff --git a/RIOv4_3.disasm.asm b/RIOv4_3.disasm.asm index 469f5fc8..870f2b04 100644 --- a/RIOv4_3.disasm.asm +++ b/RIOv4_3.disasm.asm @@ -820,7 +820,7 @@ C6F7 86 04 LDAA #$04 C6F9 84 7F ANDA #$7F C6FB A7 00 STAA $00,X C6FD 08 INX -C6FE 86 02 LDAA #$02 +C6FE 86 03 LDAA #$03 C700 84 7F ANDA #$7F C702 A7 00 STAA $00,X C704 BD D6 3B JSR $D63B diff --git a/make_patch.py b/make_patch.py index b3b73937..29448ed9 100644 --- a/make_patch.py +++ b/make_patch.py @@ -52,6 +52,14 @@ CHECKREPAINT = "--checkrepaint" in sys.argv assert not CHECKREPAINT or E0T is not None, \ "--checkrepaint requires --e0thresh (it re-renders E0 via the gated $D5F2)" +# --reportversion=M.N (edit 7): the major.minor bytes the VersionReply returns. +REPORTVER = None +for a in sys.argv: + if a.startswith("--reportversion="): + REPORTVER = tuple(int(x) for x in a.split("=", 1)[1].split(".")) + assert len(REPORTVER) == 2 and all(0 <= v <= 127 for v in REPORTVER), \ + f"--reportversion must be M.N with 7-bit values: {REPORTVER}" + args = [a for a in sys.argv[1:] if not a.startswith("--")] SRC = args[0] if len(args) > 0 else "RIOv4_2.bin" if len(args) > 1: @@ -165,6 +173,16 @@ if CHECKREPAINT: 0x39] # $E029 RTS patch(0xE020, [0xFF] * len(cave6), cave6) +# --- edit 7 (--reportversion=M.N): version bytes in the VersionReply -------- +# The reply builder at $C6EA loads the payload with LDAA #$04 ($C6F7) and +# LDAA #$02 ($C6FE) — hardcoded "4.2". Nothing host-side validates the value +# (legacy app prints it, RIOJoy parses it, native games ignore it — verified +# by Cyd 2026-07-19), so the christened firmware can announce itself. +if REPORTVER is not None: + assert d[0xC6F7] == 0x86 and d[0xC6FE] == 0x86, "expected LDAA #imm pair at $C6F7/$C6FE" + patch(0xC6F8, [0x04], [REPORTVER[0]]) + patch(0xC6FF, [0x02], [REPORTVER[1]]) + open(DST, "wb").write(d) new_sha = hashlib.sha256(d).hexdigest() # byte-diff report