VOGONS


First post, by jdredd

User metadata
Rank Newbie
Rank
Newbie

yah yah i know...

I picked up a NCR 486 , Model 3230 A week or so ago, and found the BIOS... lacking. No boot order. No boot from CD. Limited on HDD size. Pain to even set hard drive, ect.
So I read my chip, fed Claude the file, and had it decompiled.
After that recompiled, and burned the chip and it worked. Very promising.

Then went work on that. First thing was missing USERHDD.exe to set a custom hard drive . After that worked, I figured what else can we do?
Apparently... a lot!

Fixes to the original BIOS
• Boots without a hard disk and without a CMOS battery. A keyboard check could drop the stock BIOS into NCR's factory burn-in mode, where F1 did nothing.
• An attached CD-ROM no longer stalls POST for ~30 seconds or shows up as a phantom hard disk.
• "Press F1 / Press ENTER" error prompts now continue on their own after a short countdown.
• After lost settings (dead battery), hard disks default to Automatic instead of "Not installed", so the drive is still found.
• A drive set to Automatic but not connected is skipped quietly instead of giving "Disk controller failure".
• "PROCESSOR SPEED" now shows the real, measured clock. The stock BIOS printed a CMOS byte nothing ever set.
• Setup accepts two-digit years 00–79 as 2000–2079.
Booting
• Blue boot screen with coloured messages, credits and a start-up chime (can be switched off in Setup)
• End-of-POST system summary: CPU and measured MHz, memory, caches, drives, ports, video, boot order
• F8 boot menu: boot once from floppy, hard disk, CD-ROM, or a card's own boot ROM
• Saved boot order, like later BIOSes: put the devices in any order and switch each on or off
• Boot from CD-ROM (El Torito): DOS/Win9x boot CDs and Linux/FreeDOS/Win2000-style CDs, with its own ATAPI CD-ROM driver
• Works with cards that take over booting, such as the PicoMEM: the boot menu and boot order still decide
Hard disks
• Hard disk setup screen, which replaces NCR's lost USERHDD.EXE utility
• Large-disk (LBA) support: disks over the old 504 MB limit, up to 8.4 GB for DOS and up to 128 GB through the INT 13h extensions (FAT32, Win95 OSR2/98)
F10 Tools menu (built into the unused part of the chip)
• System information with measured CPU speed
• Drives and devices with IDE model names
• Memory map and option ROMs
• Memory test covering all memory with five patterns
• CMOS viewer
• NCR's hidden floppy drive test <---- really interesting as it was in the BIOS but not exposed easily. Ctrl-D at end of post is how it was reached. Possibly a NCR service thing?
• Hard disk setup, boot menu and boot order
• Chipset settings for the board's UMC 82C480 chipset: ISA bus clock, I/O recovery time, DRAM and L2 cache wait states. A fail-safe skips the new settings if a boot with them doesn't finish, and holding Shift skips them once.
• Chipset register viewer

How it was done
The ROM was disassembled, and every change is a small NASM assembly patch that checks the original bytes it replaces. Each patch was tested by running the real ROM code in an emulator against simulated hard disks, CD-ROMs (real ISO images) and memory, with over 300 automated checks, before the chip was burned with an EPROM programmer.

Video of old vs new @ https://www.youtube.com/watch?v=7n-stwXmWIA&feature=youtu.be

I found this really neat as was able to get features and tools that didn't exist. Like booting from a CD didn't exist. Now it does.

Repo over @ https://github.com/jdredd87/ncr-486-3230-bios to inspect everything.

I found this really interesting and actually learned a few things along the way. BIOS and such was always kind of A mystery to me. Never got into it. Mostly because when this was a thing I was still A kid and didn't have anything about it and as I got older, lost interest. Now I have interest again and find this really fun again. Unlocking possibilities of what could have been.

Reply 1 of 1, by rasz_pl

User metadata
Rank l33t
Rank
l33t

O, thats right up my early 90s Bioses alley 😀. Loving all the Bios enhancements!

disk - "Now a disk set to **Automatic** that holds more and supports LBA gets large-disk mode, the way a 1995 Phoenix or Award BIOS does it" did LLM get confused?
https://github.com/jdredd87/ncr-486-3230-bios … s_rom.asm#L6688
"LBA and holds more is switched to large-disk mode" it keeps calling it "**Large-disk (LBA) mode**"? L in LBA doesnt stand for Large, its Logical 😀 What LLM calls here "large-disk mode" is just LBA translation. LBA mode does translation indeed, but that would only work for drives natively supporting LBA.
Meaning no actual ECHA/LARGE translation added by patches. There was a tiny gap around 1990-93 of drives >528MB with no LBA support, this is why every decent nineties bios needs 3 modes - CHS, ECHS/Large (translation), and LBA (again translation).
https://www.vogonswiki.com/index.php/Storage# … 994%20%2D%20528
https://aeb.win.tue.nl/linux/Large-Disk-4.html
LBA first showed up in ATA drafts in late 1992 https://www.os2museum.com/wp/historical-ata-standard-drafts/

How tiny? I think it might have been several drives 😀 'CORPORATE SYSTEMS CENTER Hard Drive Bible'
7th edition 1994 https://oldcrap.org/wp-content/uploads/2023/0 … dition-1994.pdf
8th edition 1996 https://vtda.org/books/Computing/Hardware/CSC … %20-%201996.pdf
lists for example CP-3544 CP-3554 both exceeding 1024x16x63 limit and both pre October 1992 LBA defining ATA standard, it also gives some stupid CMOS non working settings for them.
But thats just nitpicking 😀

video bios at E000h - mobo doesnt bother remapping to standard C000h? 😮

ram test not testing first 64KB - Zenith bios for example temporarily backs up BDA for the duration of ram test and clears interrupts, after test completion copies BDA back, reinitializes IVT and restores interrupts

ram test methodology - https://github.com/ki3v/xtramtest implements much better algos worth copying

Now about the tooling used, this looks useful https://github.com/jdredd87/ncr-486-3230-bios … in/tools/emu.py I was looking for an easy to setup custom platforms emu I could attach a debugger into, this might just be enough until I find proper one with debugger support. I was hoping it could be transpiled into html/js live bios demo
... until I realized its powered by Unicorn aka qemu :] and there already is js port https://github.com/AlexAltea/unicorn.js
Extending it to support random programs is soo easy 😮. For example https://theretroweb.com/motherboards/s/icl-ergopro-e452-e652 bios download contains floppy image with dosflash.exe which refused to load with dosemu.py looping on int21 gettime, I guessed it keeps calling gettime in infinite loop because it expects time to advance for some stupid reason so I patched it with:

		elif ah == 0x2C:								   # get time
now = datetime.datetime.now()
cx_val = (now.hour << 8) | now.minute
dx_val = (now.second << 8) | (now.microsecond // 10000)
self.set_regs(cx=cx_val, dx=dx_val)

and bam

dosflash.exe,  version 1.14 Copyright FUJITSU ICL Computers Limited.

Pretty awesome, didnt know about Unicorn before today 😀

I had this idea stuck in my head for some time of a BIOS zoo combining all my dissasembled bioses into a place where one could see how they all looked like (menus/available options etc), running original code directly in js would be even better but I dont want full PC emu. Unicorn might just be the ticket 😀

I read before how Claude prefers to manually disassemble binaries even if one provides sourcecode, pretty wild to see it build custom python disassembler using Capstone on the spot 😮 back in the day people needed something like Sourcer and tons of knowledge. Myself I slave it out in IDA.

Once again, pretty awesome result. 👍

ps: just notices in my subscriptions that 'Bits und Bolts' slopped his own bios enhancement today 😀 https://www.youtube.com/watch?v=TC04gsM37g0 same exact tech stack, very similar methods used https://github.com/BitsUndBolts/SOYO_SY-019L1_504_Patch Claude seems to have a strong preference for Unicorn/Nasm and this coding style, or reuses previous sessions for similar tasks 😀

https://github.com/raszpl/sigrok-disk FM/MFM/RLL decoder
https://github.com/raszpl/FIC-486-GAC-2-Cache-Module (AT&T Globalyst)
https://github.com/raszpl/386RC-16 ram board
https://github.com/raszpl/Zenith_ZBIOS Zenith Z-386 MFM-300 ZBIOS disassembly