[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: And the trace begins... Pick-A-Dilly Pair



The closer I get...the further I fall...
I'll be over the edge now...in no time at all...

Oh, wait.

Anyway, I'm frustratingly close. The first-phase loader is working, the title comes up fine (as much as it does for the original crack) and I get to the menu! - but actually trying to run the game kicks me back to the menu.

Let's look at the replacement for HELLO (here horizontally compressed so I can also fit in the disassembly of the original source with notes on the changes). Roll that beautiful bean footage!

0E00- EA        h2: nop         0E00- 78        SEI         ; disabled
0E01- A9 9C         lda  #<bye  0E01- A9 01     LDA  #$01   ; vector to
0E03- 8D F2 03      sta  $03F2  0E03- 8D F2 03  STA  $03F2  ;   ProDOS-8
0E06- A9 B5         lda  #>bye  0E06- A9 0E     LDA  #$0E   ;   exit code
0E08- 8D F3 03      sta  $03F3  0E08- 8D F3 03  STA  $03F3  ;   in loader
0E0B- 49 A5         eor  #$A5   0E0B- A9 AB     LDA  #$AB   ;   instead of
0E0D- 8D F4 03      sta  $03F4  0E0D- 8D F4 03  STA  $03F4  ;   to self.
0E10- 20 58 FC      jsr  $FC58  0E10- 20 58 FC  JSR  $FC58
0E13- 20 2F FB      jsr  $FB2F  0E13- 20 2F FB  JSR  $FB2F
0E16- A9 40         lda  #$40   0E16- A9 40     LDA  #$40
0E18- 85 E6         sta  $E6    0E18- 85 E6     STA  $E6
0E1A- 8D 5F 64      sta  $645F  0E1A- 8D 5F 64  STA  $645F
0E1D- 20 F2 F3      jsr  $F3F2  0E1D- 20 F2 F3  JSR  $F3F2
0E20- 20 D8 F3      jsr  $F3D8  0E20- 20 D8 F3  JSR  $F3D8
0E23- 2C 10 C0      bit  $C010  0E23- 2C 10 C0  BIT  $C010
0E26- 20 AF B3      jsr  ovl1   0E26- 20 81 0E  JSR  $0E81  ; new loader
0E29- 20 00 15  @1: jsr  $1500  0E29- 20 00 15  JSR  $1500
0E2C- 2C 5F 64      bit  $645F  0E2C- 2C 5F 64  BIT  $645F
0E2F- 10 0C         bpl  @3     0E2F- 10 0C     BPL  $0E3D
0E31- A2 20         ldx  #$20   0E31- A2 20     LDX  #$20
0E33- A9 00     @2: lda  #$00   0E33- A9 00     LDA  #$00
0E35- 20 A8 FC      jsr  $FCA8  0E35- 20 A8 FC  JSR  $FCA8
0E38- CA            dex         0E38- CA        DEX
0E39- D0 F8         bne  @2     0E39- D0 F8     BNE  $0E33
0E3B- F0 EC         beq  @1     0E3B- F0 EC     BEQ  $0E29
0E3D- 20 A4 15  @3: jsr  $15A4  0E3D- 20 A4 15  JSR  $15A4
0E40- EA            nop         0E40- A0 1A     LDY  #$1A  ; new loader
0E41- EA            nop
0E42- 20 DC B3      jsr  ovl2   0E42- 20 88 0E  JSR  $0E88
0E45- 2C 10 C0      bit  $C010  0E45- 2C 10 C0  BIT  $C010
0E48- 4C 94 15      jmp  $1594  0E48- 4C 94 15  JMP  $1594

The "ovl1" and "ovl2" code is placed in the memory usually used by DOS 3.3 and feature a series of macros which recycle code in the loader to do their dirty work. I can upload the rest of the source if need be.

Gah, I'm so frustrated.  So damn close!

-uso.