make_patch.py gains --baud31250: one byte beyond the wedge patch — the SCI init operand at $D62B ($30 -> $02). BAUD $30 = /13 prescale, /1 divider (2MHz E / 208 = 9615); $02 = /1, /4 -> 31250 exactly, 3.3x faster. The init write also confirms the 8MHz crystal, which is why 19200/38400 are unreachable and why 62500/125k are left alone pending an ISR cycle count. - 24 bytes changed vs original (sha256 9f866cf3...); re-disassembly diff vs the classic patched image shows exactly the one operand line, and the classic build still reproduces 3fc8170c... (script regression-safe). - PC side: SerialPortTransport takes an optional baudRate (default 9600, runtime untouched); RioSerialMonitor + --mash accept --baud 31250. - Caveats documented in README/ANALYSIS: non-standard rate (FTDI-class adapters only, no 16550s); native games still speak 9600 so this chip is bench/RIOJoy-only; validate the wedge patch at 9600 first. 275 tests green; mash --selftest regression unchanged (FAIL/exit-1). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
53 lines
2.8 KiB
Markdown
53 lines
2.8 KiB
Markdown
# RIO board firmware
|
|
|
|
- **`RIOv4_2.bin`** — RIO cockpit I/O board firmware **v4.2**, dumped
|
|
2026-07-04 from one of our own boards' EPROM: an **AMD AM27C512-150**
|
|
(64K x 8 UV EPROM, 150ns — the image fills it exactly).
|
|
sha256 `60a88718835c654b6135dbec7721c40ef99dca07df2ad4b57eedeb24037a5f73`.
|
|
For the eventual patched burn: a pin-compatible Winbond W27C512
|
|
(electrically erasable, TL866-friendly) drops straight into the socket;
|
|
the original AMD chip gets labeled and preserved unmodified.
|
|
|
|
## First-look analysis (from the image alone, confirmed on hardware)
|
|
|
|
- MCU: **Toshiba TMP68HC11** (read off the chip; the code fingerprint
|
|
agrees — 6800-family opcodes with writes into the 68HC11 internal
|
|
register block at `$10xx`).
|
|
- Memory map: image is FF up to **0xC000**; 16KB of code occupies
|
|
`$C000-$FFFF` (EPROM mapped at the top of the HC11 address space).
|
|
- Startup at `$C000`: `SEI; LDS #$8000; STAA $1024 (TMSK2);
|
|
STAA $1022 (TMSK1); ...` then a long `JSR` init chain — textbook HC11
|
|
bring-up.
|
|
- Vector table (`$FFD6-$FFFF`, big-endian):
|
|
- `$FFFE` RESET → `$C000`
|
|
- **`$FFD6` SCI (serial) → `$D630`** — the entry point of the board's
|
|
receive/protocol interrupt handler. The suspected board-side
|
|
DISABLE_AND_DIE-style wedge (see RIO-NOTES.md: the board mirrors the
|
|
game's PCSPAK state machine, and mash-stress leaves the reply path
|
|
dead while the button/event path stays alive) is reachable from here.
|
|
- `$FFE4` → `$C1B2`, `$FFE6` → `$C18E` (timer output-compares); most
|
|
other vectors → `$DB07..$DB3D` stubs.
|
|
|
|
## Why this exists
|
|
|
|
The remaining RIO reliability issue is board-side: under button-mash
|
|
stress the board's reply/analog state machine wedges (RX dead, TX alive;
|
|
a button press or power cycle revives it), reproduced identically on two
|
|
different USB serial adapters. The game-side half of the protocol was
|
|
binary-patched for tolerance (BTL4OPT patches v2-v4); the board firmware
|
|
is the other half. Plan (RIO-NOTES.md "Board firmware patch plan"):
|
|
disassemble as 68HC11 from `$C000` with the vector entries as roots, find
|
|
the SCI state machine (protocol constants FC=ACK FD=NAK FE=RESTART
|
|
FF=IDLE, idle-reload-4 patterns), patch the early-ACK/error wedge path or
|
|
widen its window, burn a new EPROM, keep this original safe.
|
|
|
|
## Patched images (built by make_patch.py; see RIOv4_2-ANALYSIS.md)
|
|
|
|
- **`RIOv4_2_patched.bin`** — the reply-latch wedge fix, 23 bytes changed.
|
|
sha256 `3fc8170caf60e2580641724ff995176c93c4f2e706f31487beded8233142493f`.
|
|
- **`RIOv4_2_patched_31250.bin`** (`make_patch.py --baud31250`) — wedge fix
|
|
+ SCI retuned 9600 → 31250 baud (one more byte, `$D62B: 30→02`).
|
|
sha256 `9f866cf353d04906e1d3e3847b6375eaae251c987b656f68f093e61ba1bd545b`.
|
|
Bench/RIOJoy-only until the native games get baud patches; needs an
|
|
FTDI-class adapter (16550s can't make 31250). Test tools take `--baud 31250`.
|