HNHacker News
TopNewBestAskShowJobs

ajenner

493 karma · joined July 29, 2011

submissionscomments
ajenner··on 60fps Video on a CGA? – The GlyphBlaster
As trollbridge said, there isn't enough VRAM in the CGA to have 200 rows of 80 columns (2 bytes per cell - one for character and one for attribute). But it can be done in 40-column mode. As the CRTC can only do 128 rows unattended, it requires the CPU to be involved (reprogramming the CRTC several times per frame on particular scanlines) but 8088 MPH and Area 5150 did such things.
ajenner··on 80386 Barrel Shifter
I haven't published it yet as there are still some rough edges to clear up, but if you email me (andrew@reenigne.org) I'll send you the current work-in-progress (the same one that nand2mario is working from).
ajenner··on 8086 Microcode Browser
I wrote a program called xtce-trace (https://www.reenigne.org/software/xtce_trace.zip ) to do just this (albeit non-interactively - you just give it a program and it will generate a cycle-by-cycle trace of which lines of microcode are executed). GloriousCow aka Daniel Balsom recently fixed some of its bugs and turned it into an actual emulator (https://github.com/dbalsom/XTCE-Blue ), though it's not finished yet so there's no binary release at the moment.
ajenner··on The microcode and hardware in the 8086 processor that perform string operations
It's not - the "DA" means that the write happens to the ES segment, while "DS" means that the read happens from the DS segment. The use of different segments for the source and destination gives these instructions extra flexibility.
ajenner··on Undocumented 8086 Opcodes part 1 (2017)
Yes, it pops the stack value into the CS register. But it doesn't update the PC as well - it'll continue to point to the offset (in the old CS) of the instruction after the "POP CS". So whatever code is in the new CS, it has to be "compatible" with the code in the old CS, in terms of the instructions starting in the right place. However, it's even more complicated than that because the prefetch queue is not flushed, so the exact address where it switches over will be unpredictable. For certain very specific scenarios it could potentially be useful to speed up conditional execution by eliminating those prefetch queue flushes, though.
ajenner··on Mel's Hack – The Missing Bits
There's a POP instruction in the loop that pops to a memory location addressed by a register. When that register contains the address of the final JMP instruction, the latter gets overwritten by a forward JMP.
ajenner··on Mel's Hack – The Missing Bits
A more recent example of an finite loop with no exit condition can be found in the credits section of the 2015 demoscene production "8088 MPH". The loop (which can be found at https://www.reenigne.org/blog/8088-pc-speaker-mod-player-how... under "v:") has two jumps (one conditional, one unconditional) both backwards, and runs with interrupts disabled. The CPU's instruction pointer stays within that block until the end of the routine - there's no wraparound to make a forward jump from a backward one.
ajenner··on Area 5150: 8088 MPH gets a successor
I used the DOSBox debugger to debug several of the effects during the making of Area 5150, but other than that I used real hardware. 86Box is probably the most accurate one at the moment but still isn't accurate enough to run the entire demo correctly.
ajenner··on Area 5150: 8088 MPH gets a successor
Most of the tricks in the demo should work unmodified (or could be made to work) on most CGA implementations of the era. Some clones had slightly different font ROMs so it would look a little bit wrong on those. The final lake effect (and the ripply picture shortly before it) use very tight cycle counting so probably won't work on anything except a genuine IBM PC/XT and CGA. Some effects (like the radial fire effect and the voxel landscape) should work on just about anything. The Amstrad PC1512 will have trouble with any effect that modifies the CRTC timing registers as it doesn't have a fully programmable CRTC and always generates a 15.7kHz/59.92Hz 640x200 image. I don't have personal experience with the Tandy 1000 and don't know how compatible it is off the top of my head.
ajenner··on Area 5150: 8088 MPH gets a successor
Yes, I'm reenigne from the demo. Feel free to contact me at andrew@reenigne.org.

I'm not sure what you're doing with the colour mixing on that page but I'm wondering if you're just applying a gamma curve to the mixed result. This is what I meant:

sRGB interpolation:

  r_final = r_1*x + r_2*(1-x)
  g_final = g_1*x + g_2*(1-x)
  b_final = b_1*x + b_2*(1-x)
linear RGB interpolation:

  r_final = 255*((((r_1/255)^2.2)*x + ((r_2/255)^2.2)*(1-x))^(1/2.2))
  g_final = 255*((((g_1/255)^2.2)*x + ((g_2/255)^2.2)*(1-x))^(1/2.2))
  b_final = 255*((((b_1/255)^2.2)*x + ((b_2/255)^2.2)*(1-x))^(1/2.2))
The real gamma correction formula is actually slightly more complicated than that because it's linear up until the sRGB value is about 10 then then follows a ^2.4 curve but the difference is too small to notice.
ajenner··on Area 5150: 8088 MPH gets a successor
There's a difference between linear interpolation of sRGB values (what you're doing on your page) and linear interpolation of linear RGB values (which gives better results). This is the explanation that made it all fall into place for me: http://www.ericbrasseur.org/gamma.html?i=1 . The linear RGB colour space is also a linear transformation of the CIELAB space so doing the interpolation in this space is equivalent to transforming to CIELAB space, doing the interpolation there, and then transforming back.

However, for the purposes of Area 5150 I think the differences between sRGB interpolation and linear RGB interpolation would have been too subtle to notice since there are only 6 * 16 * 16 = 1536 dithered colour/pattern combinations to choose from in the first place - the error introduced by that quantisation is likely larger than the sRGB vs. linear RGB difference. But I used linear RGB anyway, just to be correct about it.

ajenner··on Area 5150: 8088 MPH gets a successor
As I remember it, the term "XT class" was used back in the day to distinguish between "AT class" PCs and those prior - i.e. to mean an IBM PC, XT or comparable machine. So (weirdly enough) the 5150 was considered XT class despite predating the XT (they're almost identical as far as software is concerned anyway). The term "PC class" wasn't a thing because PC came to be shorthand for any IBM PC/XT/AT or later x86 machine. Some more powerful machines like the Amstrad PC1512 (with an 8MHz 8086) were also considered XT class - these machines could run games like Bruce Lee and Digger which were designed for the PC/XT (and which were too fast on AT and later machines), though the gameplay was quicker than they were designed for so were extra-challenging.
ajenner··on Area 5150: 8088 MPH gets a successor
The C000 segment was used for the EGA/VGA extension ROM. I'm guessing that using D000-EFFF would be unnecessary (because of the planar addressing squeezing 256kB of video memory into a 64kB address space), inconvenient (because the addresses wouldn't be contiguous - EGA and VGA were designed to coexist with either CGA or monochrome adapters in B000-BFFF) and (for VGA) insufficient - you'd still not have enough to map the entire 256kB of VRAM linearly. I also expect that IBM's engineers didn't want to take up all the extension ROM space because then it wouldn't be possible to add EMS cards, network cards, and whatever else ended up being mapped there. Though 192kB of write-only video memory in that space would be an interesting design!
ajenner··on Area 5150: 8088 MPH gets a successor
The programmatic transitions between still images use linear RGB space, which is the correct way to interpolate between two colours. The maths behind it is pretty simple - essentially just reversing the gamma correction from normal (0-255) sRGB space before the interpolation and redoing it for the final colour (no need to get into the hairy areas of LAB or perceptual colour spaces for this). Once we know the colour we want, we choose the character (from a list of 6) and attribute which most closely matches that colour. Of course, it's all done using lots of lookup tables so that we can process several hundred character cells per frame.
ajenner··on Area 5150: 8088 MPH gets a successor
Thanks! The 3D hills are no less 3D than any other 3D scene displayed on a 2D monitor. It's a heightmap (of a real place) rendered with correct perspective.

Getting the samples to output at the correct time during the end titles required a painstaking amount of cycle-counting, measuring, and iteration.

ajenner··on Area 5150: 8088 MPH gets a successor
The demo is about 500kB at the moment. We're hoping to fit the final version onto a single 360kB floppy but didn't quite get that working in time for the party. A 3.5" floppy should work fine.
ajenner··on Area 5150: 8088 MPH gets a successor
I did actually use this debugging technique while making a couple of the effects of Area 5150 (the lake effect at the end, and the one two effects before that).
ajenner··on 8086 Microcode Disassembled
The b and t files are the bottom and top halves of the 9 "chunks" of the decoder above the main microcode ROM. The l* and r* files are the left and right halves of the four horizontal slices of the main ROM. I split them up that way because bitract needs the bits to be regularly spaced in both the horizontal and vertical directions.

Thanks - glad you enjoyed it!

ajenner··on 8086 Microcode Disassembled
The translation.txt file is the contents of the translation ROM which tells the CPU where in the microcode to go for long jumps, calls and EA decoding. The key.txt file has the details of all the mnemonics.

"000" - this is just a line number "A CD F H J L OPQR U" - these are the actual bits from the ROM. "R -> tmpb" - this is a move operation (each microcode instruction can do a move as well as something else) copying the value from "R" (a register described by the word length bit and either the R field or the RM field of the modrm byte depending on the direction bit) to "tmpb" (an internal register not accessible from the user-level ISA). "4 none WB,NX" - a type 4 instruction (bookkeeping) that tells the CPU that the next instruction is the last one in the microcode burst (NX) unless a write back (WB) to memory is needed. "0100010??.00" - this is the bit pattern by which this line of microcode is addressed. This one means opcodes 0x88-0x8b. "MOV rm<->r" - a comment added to say what this set of opcodes actually corresponds to x86 assembler, or what it does if it's a subroutine.

ajenner··on 8086 Microcode Disassembled
I don't think there's anything on the chip that could compute a checksum of the microcode ROM contents. It could be some kind of copyright message perhaps, though I don't know how it's encoded and it's only 42 bits long so there isn't much space for anything meaningful.
ajenner··on 8086 Microcode Disassembled
I have just learned from dreNorteR on VCF that it no effect on a 286 but has a different, unexpected, and useful effect on a 186! http://www.vcfed.org/forum/showthread.php?76657-8088-8086-mi...
ajenner··on 8086 Microcode Disassembled
Probably not entirely a coincidence - Ken Shirriff is doing a series on the 8086 which may account for at least one of the other articles you've noticed. My disassembly was only possible because of Ken's high-resolution photos of the die with the metal layer removed - that's why it took me until now to do it.
ajenner··on 8086 Microcode Disassembled
Microcode instruction sets have different engineering trade-offs to the user-visible ISA. In microcode, memory bandwidth isn't such an issue so microcode instructions can be relatively wide (21 bits compared to 8 for the 8086).

The microcode can also be relatively difficult to write. For example, in the 8086 microcode I saw one place where there is a "DEC2 tmpc" microinstruction (subtract 2 from tmpc), then tmpc is loaded after that, after which the correct result is available (this makes sense when you think about how the ALU works on the chip, but in any normal ISA you have to load the values into the operands before you perform operations on them).

There's nothing in the 8086 microcode which creates any temporary undetermined states as far as I can tell but there may be combinations of microinstructions which could create a race condition.

ajenner··on 8086 Microcode Disassembled
According to https://en.wikipedia.org/wiki/Intel_8086: "The architecture was defined by Stephen P. Morse with some help and assistance by Bruce Ravenel (the architect of the 8087) in refining the final revisions. Logic designer Jim McKevitt and John Bayliss were the lead engineers of the hardware-level development team and Bill Pohlman the manager for the project." I expect the microcode was developed in tandem with the rest of the chip, so probably took about 2 years.
ajenner··on 8086 Microcode Disassembled
Yes, exactly - the logic that implements the simpler instructions directly as special-purpose gates rather than microcode.
ajenner··on 8086 Microcode Disassembled
Author here if anyone has any questions.
ajenner··on Reverse-engineering the 8086's Arithmetic/Logic Unit from die photos
It might be different on an Intel 8088. What I saw was two bytes loaded from the bus (at the address that was left in the IND register) placed in ES or DS, and the offset part was loaded from a second hidden register that contained the previous word read from or written to the bus (excluding instruction fetches).

Glad the sniffer logs were useful! I have been using them pretty regularly for debugging and profiling things.

ajenner··on Reverse-engineering the 8086's Arithmetic/Logic Unit from die photos
I have written code for a cycle-exact 8088 emulator https://github.com/reenigne/reenigne/blob/master/8088/xtce/x... which handles all the invalid opcodes the same way that real hardware does. There is more potentially-useful way of observing TMP and IND that doesn't involve jumping to code that you might not control: use the LDS or LES opcodes with mod=11.
ajenner··on Every 7.8μs your computer’s memory has a hiccup
Modern graphics systems are too flexible for this - you can reprogram the graphics memory layout in such a way that would break the refreshing. But this technique was used on early PCs (with CGA graphics) and many of the 80s microcomputers.
ajenner··on Dulles Airport Surprises Passengers with Facial-Recognition Boarding
The system then compares the photo to a gallery that includes images of that person—either their passport photo for U.S. citizens or the photo taken of foreign nationals when they entered the country.

So those of us with dual nationality, who enter the US on our US passports and leave on our foreign passports, are going to get screwed. Lovely.

Page 1 of 3Next →