VOGONS


DIY Bios Modding guide Jan Steunebrink k6-2+/3+ 128gb

Topic actions

Reply 460 of 470, by Oerg866

User metadata
Rank Member
Rank
Member

Hello Jan,

thank you very much for your input!

Oh shoot, I knew I forgot something:

    ORG offset CODECAVE_ROMCopyright1
AMDCheck5x86:
; Previous condition holds true, so in case we land here from there
; skip our ammended checks
jz short AMDCheck5x86_Exit

cmp ax, 04E0h ; 4E0 = 5x86 Write Through
jnz short AMDCheck5x86_Not5x86_WT
mov dh, 030h ; 4x multi, Green CPU
jmp short AMDCheck5x86_SetID

AMDCheck5x86_Not5x86_WT:
cmp ax, 04F0h ; 4F0 = 5x86 Write Back
jnz short AMDCheck5x86_Exit
mov dh, 038h ; 4x multi, Green CPU, Write Back

AMDCheck5x86_SetID:
mov dl, ((CPU_5X86_STRING_TABLE_INDEX * 2) OR 081h)

AMDCheck5x86_Exit:
call CMOS_ApplyCPUFeatureBits
retn

CODECAVE_ROMCopyright1 = $

This should properly distinguish between WB and WT now. For the sake of keeping the effort to a minimum, I will refrain from overwriting other bits for now 😁

Best
Eric

EDIT:

Hidden menu item @ F4A37: STANDARD CMOS SETUP / Daylight Saving
Hidden menu item @ F58D6: BIOS FEATURES SETUP / Virus Warning
Hidden menu item @ F596C: BIOS FEATURES SETUP / Boot Up Floppy Seek
Hidden menu item @ F599E: BIOS FEATURES SETUP / Boot Up System Speed
Hidden menu item @ F5A66: BIOS FEATURES SETUP / System BIOS Shadow
Hidden menu item @ F5AE3: BIOS FEATURES SETUP / E0000-E7FFF Shadow
Hidden menu item @ F5AFC: BIOS FEATURES SETUP / E8000-EFFFF Shadow
Hidden menu item @ F6236: CHIPSET FEATURES SETUP / MA Drive Capacity
Hidden menu item @ F629A: CHIPSET FEATURES SETUP / DRAM Write Burst
Hidden menu item @ F62B3: CHIPSET FEATURES SETUP / Slow Refresh
Hidden menu item @ F62CC: CHIPSET FEATURES SETUP / Hidden Refresh
Hidden menu item @ F62E5: CHIPSET FEATURES SETUP / Internal Cache WB/WT
Hidden menu item @ F637B: CHIPSET FEATURES SETUP / Fast Reset Emulation
Hidden menu item @ F6394: CHIPSET FEATURES SETUP / Fast Reset Latency
Hidden menu item @ F63AD: CHIPSET FEATURES SETUP / Latch Local Bus
Hidden menu item @ F63C6: CHIPSET FEATURES SETUP / Local Bus Ready
Hidden menu item @ F63DF: CHIPSET FEATURES SETUP / Memory Hole Size
Hidden menu item @ F63F8: CHIPSET FEATURES SETUP / DMA Clock
Hidden menu item @ F6411: CHIPSET FEATURES SETUP / Memory Relocation
Hidden menu item @ F683B: POWER MANAGEMENT SETUP / PM Mode
Hidden menu item @ F6854: POWER MANAGEMENT SETUP / Break Switch
Hidden menu item @ F6903: POWER MANAGEMENT SETUP / Auto Doze
Hidden menu item @ F6935: POWER MANAGEMENT SETUP / Auto Standby

This BIOS has a lot of hidden options. That is inexcusable behavior and needs to be rectified immediately.

Reply 461 of 470, by Oerg866

User metadata
Rank Member
Rank
Member

If anyone wants to test it, my mod BIOS for the SY-025L is available here, provisionally, because everything may be broken 😀 we'll see

https://github.com/oerg866/TRW-BiosMods/tree/main/SOYO_025L

@Jan:

By the way, my notes are available here: https://github.com/oerg866/TRW-BiosMods/wiki/ … x-hacking-notes

Growing that document is a very slow process because doing is more fun than documenting. :^)

Reply 462 of 470, by Oerg866

User metadata
Rank Member
Rank
Member

Hello again!

Sorry for the spam 😀

But I think I found another slight bug in this BIOS.

The option for Internal Cache WB/WT is tied to a menu callback for the Chipset Features Setup page:

BIOS_F:5E28                 MenuItemCallback <offset stru_F62E5, offset loc_F675E>

That function is a little weird:

BIOS_F:675E MenuChipsetSetup_HandleInternalCacheWBWT: ; DATA XREF: BIOS_F:5E28↑o
BIOS_F:675E cmp al, 55h ; 'U'
BIOS_F:6760 jz short loc_F6770
BIOS_F:6762 call MenuChipsetSetup_CMOSIsWBCPU_Buggy
BIOS_F:6765 jz short loc_F6772
BIOS_F:6767 cmp al, 14h
BIOS_F:6769 jz short loc_F6770
BIOS_F:676B call DisableMenuItem
BIOS_F:676E stc
BIOS_F:676F retn

The function this calls goes like this:

BIOS_F:8E94 MenuChipsetSetup_CMOSIsWBCPU_Buggy proc near
BIOS_F:8E94 ; CODE XREF: BIOS_F:6762↑p
BIOS_F:8E94 ; sub_F8DAD+15↑p ...
BIOS_F:8E94 mov al, 0BDh
BIOS_F:8E96 call ReadCMOSByte_2
BIOS_F:8E99 and al, 7Eh
BIOS_F:8E9B nop
BIOS_F:8E9C nop
BIOS_F:8E9D cmp al, 24h ; '$'
BIOS_F:8E9F jz short locret_F8EAB
BIOS_F:8EA1 cmp al, 26h ; '&'
BIOS_F:8EA3 jz short locret_F8EAB
BIOS_F:8EA5 cmp al, 16h
BIOS_F:8EA7 jz short locret_F8EAB
BIOS_F:8EA9 cmp al, 18h
BIOS_F:8EAB
BIOS_F:8EAB locret_F8EAB: ; CODE XREF: MenuChipsetSetup_CMOSIsWBCPU_Buggy+B↑j
BIOS_F:8EAB ; MenuChipsetSetup_CMOSIsWBCPU_Buggy+F↑j ...
BIOS_F:8EAB retn
BIOS_F:8EAB MenuChipsetSetup_CMOSIsWBCPU_Buggy endp

This has some hardcoded CPU IDs that CMOS 3F is checked against, which obviously doesn't work well for us now.

I propose this change:

    ORG offset MenuChipsetSetup_CMOSIsWBCPU_Buggy
mov al, 0BFh
call ReadCMOSByte
and al, 08h
cmp al, 08h
retn

This reads CMOS byte 3F instead of 3D and then checks if the WB bit is set.

At least on my 5x86, this works correctly and reveals the menu item when the CPU is ran in WB mode.

Do you agree roughly with this finding / idea?

Thanks a ton!
Eric

Reply 464 of 470, by Chkcpu

User metadata
Rank Oldbie
Rank
Oldbie

Hi Eric,

The 1995 Award socket 3 BIOS usually has automatic L1 cache WB enable logic. So you probably don’t have to change anything.

But to be sure, I looked at how the G3 BIOS handles this.
At POST_32 a call is made to the function that actualy programs the SiS471 chipset register 50h bit 4 to enable the L1 cache WB protocol.
This function starts at F000:A5FA and is a combined function that handles the BIOS options for Memory Hole Size and Internal Cache WT/WB mode. The L1 WT/WB control starts at location F000:A649.

F000:A649			loc_1398:					;  xref F000:A605, A641
F000:A649 60 pusha ; Save all regs
F000:A64A E8 E847 call Chk_Cx486S_DX ; (8E94)
F000:A64D 3C 3C cmp AL, 3Ch ; '<'
F000:A64F 74 43 je short loc_1400 ; Jump if equal
F000:A651 F6 46 3F 08 test byte ptr [BP+3Fh], 8
F000:A655 75 3D jnz short loc_1400 ; Jump if not zero
F000:A657 .BE 62E5 mov SI, offset CHIP_feat_ctl_A ; (F000:62E5=8)
F000:A65A E8 771B call check_feature ; (1D78)
F000:A65D 32 E4 xor AH, AH ; Zero register
F000:A65F 0A C0 or AL, AL ; Zero ?
F000:A661 74 33 jz short loc_1401 ; Jump if zero
F000:A663 E8 E82E call Chk_Cx486S_DX ; (8E94)
F000:A666 74 06 jz short loc_1399 ; Jump if zero
F000:A668 3C 14 cmp AL, 14h
F000:A66A 74 28 je short loc_1400 ; Jump if equal
F000:A66C EB 28 jmp short loc_1401 ; (A696)
F000:A66E loc_1399: ; xref F000:A666
F000:A66E B1 C2 mov CL, 0C2h
F000:A670 E8 F461 call Read-chip_reg ; (9AD4)
F000:A673 24 FB and AL, 0FBh
F000:A675 E8 F46D call sub_413 ; (9AE5)
F000:A678 0F 20 C0 mov EAX, CR0 ; Mov reg-control reg
F000:A67B 66| 0D 20000000 or EAX, 20000000h
F000:A681 0F 22 C0 mov CR0, EAX ; Mov reg-control reg
F000:A684 E8 F44D call Read-chip_reg ; (9AD4)
F000:A687 0C 16 or AL, 16h
F000:A689 E8 F459 call sub_413 ; (9AE5)
F000:A68C E8 F456 call sub_413 ; (9AE5)
F000:A68F 0C 10 or AL, 10h
F000:A691 E8 F451 call sub_413 ; (9AE5)
F000:A694 loc_1400: ; xref F000:A64F, A655, A66A
F000:A694 B4 10 mov AH, 10h
F000:A696 loc_1401: ; xref F000:A661, A66C
F000:A696 B1 50 mov CL, 50h ; 'P'
F000:A698 E8 F439 call Read-chip_reg ; (9AD4)
F000:A69B 24 EF and AL, 0EFh
F000:A69D 0A C4 or AL, AH
F000:A69F E8 F43E call Write-chip_reg ; (9AE0)
F000:A6A2 61 popa ; Restore all regs
F000:A6A3 F8 clc ; Clear carry flag
F000:A6A4 C3 retn
Set_L1_WB endp

Twice a call is made to the function at F000:8E94 that you named “MenuChipsetSetup_CMOSIsWBCPU_Buggy”. I called this function: Chk_Cx486S_DX.
This function just reads CMOS_3D to check for a Cx486s, Cx486S2, Cx486DX, or Cx486DX2 CPU. On exit it leaves the BIOS_up_ID in AL and sets the zero flag if one of these Cyrix CPUs was found.
This function is called a total of 10 times in this BIOS, so changing it may have an undesired effect. 😉

Following the code from F000:A649, I see that the chipset is directly programmed for L1 WB when a P24D (i486DX2WB) is present, or when CMOS_3F bit 3 is set. This takes care of the automatic L1 WB setting on all Intel and AMD WB capable CPUs, including the Am5x86 due to your mods. The only exception is the iDX4WB, which is not supported by this BIOS.
For other CPUs, the code then continues at F000:A657 to program the L1 WB mode for the P24T (POD83) and Cyrix 486S(2)/DX(2) CPUs, depending on the setting of the Internal Cache WT/WB BIOS option. The Cyrix CPUs get a special handling here due to their software controllable WT/WB mode for the L1 cache.

Now it becomes clear why the function you called MenuChipsetSetup_HandleInternalCacheWBWT at F000:675E causes the Internal Cache WT/WB option to show only for the P24T and Cyrix CPUs. For all other CPUs this option is hidden because user interaction is not required due to the automated function.

So I believe you are good and your proposed change of the “buggy” function is not required. 😀

Cheers, Jan

CPU Identification utility
The Unofficial K6-2+ / K6-III+ page

Reply 465 of 470, by Chkcpu

User metadata
Rank Oldbie
Rank
Oldbie

Here is the CPU support list of the 03/1995 Rev G3 BIOS, with all CMOS_3Dh and CMOS_3Fh values after the BIOS has completed the CPU detection.
It also shows the detection method and sequence.
I thought this would help with the understanding of the BIOS code in the previous replies.

The attachment Award BIOS CPU list 03-95.pdf is no longer available

Jan

CPU Identification utility
The Unofficial K6-2+ / K6-III+ page

Reply 466 of 470, by Oerg866

User metadata
Rank Member
Rank
Member

Thanks for your analysis!

My board behaved weirdly, but I may be misremembering, here's what happened:

I was getting 1300ish realtics in doom with the 5x86 at 160 FSB.

After I exposed that menu option, it was set to write thru, then I changed it to write back and it brought the realtics down to 1220.

I need to verify this but I think there may still be something to keeping this option visible even if the CPU doesn't match.

By the way Jan, would you be okay with me adding some of your notes to my BIOS modding wiki pages? I completely understand if not 😀

Reply 467 of 470, by Chkcpu

User metadata
Rank Oldbie
Rank
Oldbie
Oerg866 wrote on 2026-08-10, 16:14:
Thanks for your analysis! […]
Show full quote

Thanks for your analysis!

My board behaved weirdly, but I may be misremembering, here's what happened:

I was getting 1300ish realtics in doom with the 5x86 at 160 FSB.

After I exposed that menu option, it was set to write thru, then I changed it to write back and it brought the realtics down to 1220.

I need to verify this but I think there may still be something to keeping this option visible even if the CPU doesn't match.

I wrote earlier that the Internal Cache WT/WB option was hidden for all Intel and AMD socket 3 CPUs, except the P24T, because user interaction for this BIOS option is not required.
But I should add that WT/WB software control for these CPUs is actually not possible!

As you probably know, the L1 cache WT/WB control on all WB capable Intel and AMD socket 3 CPUs is controlled by CPU pin B13 (pin T1 on the P24T). This WB/WT# pin must be pulled up to Vcc via the appropriate jumper to get the L1 cache in WB mode. If this pin is not connected, an internal pull-down resistor will keep the L1 cache in the WT mode.
Only Cyrix design CPUs have software controlled WT/WB logic.

The reason that the Internal Cache WT/WB option is still available on the P24T is because this CPU doesn’t change its CPUID Signature when in WB mode. So the BIOS is unable to tell if the CPU uses WB mode and the user has to set the Internal Cache WT/WB option to match the jumper setting on the board, bringing the chipset programming in line with the hardware setting.

So changing the Internal Cache WT/WB option setting on the Am5x86 shouldn’t have any effect.

By the way Jan, would you be okay with me adding some of your notes to my BIOS modding wiki pages? I completely understand if not 😀

Yes, it is okay when you add my notes to your BIOS modding wiki pages.
I promised you my disassembly listing of the G3 BIOS, and here it is.

The attachment 25P2-G3.zip is no longer available

I’m still using the DOS based Soucer disassembler and the listing is a 132 column text-file that uses tabs instead of spaces. But Windows Notepad will display it just fine.
Included in the zip is the definition file I wrote to get this disassembly listing of the G3 BIOS. The BIOS Data Area definitions and the Bootblock structures come from Soucer. All other labels are made up by me.

Greetings, Jan

CPU Identification utility
The Unofficial K6-2+ / K6-III+ page

Reply 468 of 470, by Oerg866

User metadata
Rank Member
Rank
Member

Hi Jan

Lots of great stuff there - I'm way slower than you that's for sure 😂

Anyway apologies for my confusion and doubts, the option indeed has no effects on performance, so it must have been another option I set by mistake.

Thanks for helping clear that up, I'll revert this change!

I'll also check my function namings in the pattern matcher against yours, to see if I misunderstood something somewhere

I do have to say, with yours and also after the modifications also with my bios, this board absolutely screams. Never before have I been able to max out the timing settings on this 5x86 at fsb 40.

Best
Eric

Reply 469 of 470, by Oerg866

User metadata
Rank Member
Rank
Member

Hello Jan! 😀

I have now used both BIOSes extensively on my machine with great success, but there's still two things I notice that are different between them:

1. In some applications, such as the Windows 95 Setup program, the mouse spazzes out on movement in my BIOS for a few seconds before returning normal. I could imagine that there's some initialization of the EBDA that is skipped if the BIOS is built without PS/2 support, that I also need to replicate. So I need to follow the execution paths of both BIOSes in IDA and see where the difference lies.

2. Floppy disk access is really slow in my BIOS compared to yours. It's not broken, it's just quite slow 😀 Do you have any idea what could cause this?

Thank you and have a great weekend!

Eric

Reply 470 of 470, by Chkcpu

User metadata
Rank Oldbie
Rank
Oldbie
Oerg866 wrote on 2026-08-14, 19:55:
Hello Jan! :) […]
Show full quote

Hello Jan! 😀

I have now used both BIOSes extensively on my machine with great success, but there's still two things I notice that are different between them:

1. In some applications, such as the Windows 95 Setup program, the mouse spazzes out on movement in my BIOS for a few seconds before returning normal. I could imagine that there's some initialization of the EBDA that is skipped if the BIOS is built without PS/2 support, that I also need to replicate. So I need to follow the execution paths of both BIOSes in IDA and see where the difference lies.

2. Floppy disk access is really slow in my BIOS compared to yours. It's not broken, it's just quite slow 😀 Do you have any idea what could cause this?

Thank you and have a great weekend!

Eric

Hello Eric,

1. I’m interested in what you will find when following the execution path in both BIOSes, regarding the PS/2 mouse support. Other than a performance difference due to different chipset setup between the G3 and J1 BIOS, I wouldn’t know what could cause this mouse stutter.

2. Slow floppy access in the G3 BIOS is also very strange. Could this be caused by a similar chipset setup issue?

Because the hardware didn’t change, only the BIOS, a check on how each BIOS programs the chipset could reveal a possible cause.
The old DOS tool CTCHIPZ will show you the programming of each chipset register.
Although the original Ctchipz.zip package came with a SiS471.CFG configuration file, I’ve made an improved version named SiS471G.CFG. Here is a copy.
In the zip I’ve also packed the CTCHIP34.EXE and the Ctchipz.doc files.

The attachment Ctchipz-SIS471G.zip is no longer available

Curious how this would work-out, I’ve ran both BIOS versions in an emulated SiS471 machine in 86Box, set the processor to Am5x86-133, and made a log of the chipset register settings with the commands:
CTCHIP34 SIS471G > G3.LOG respectively CTCHIP34 SIS471G > J1.LOG
Note that for the G3 BIOS I used your mod6a version.

Comparing the Log-files I noticed that the G3 BIOS set slower timings for SRAM, DRAM, and ISA Bus Frequency, than the J1 BIOS.
I had performed a LOAD SETUP DEFAULTS before making the chipset logs, so the chipset Auto configuration was Enabled.
I looked specifically at chipset reg 50h bits7,6 (DRAM Speed), reg 51h bits 1,0 (Cache Write and Read cycles), reg 58 bit 6 (DRAM Waitstate), and reg 60h bits 7..5 (ISA BUSCLK). Most notable is the G3’s default 7.159 MHz BUSCLK setting for any FSB speed, while the J1 BIOS uses the optimum FSB/ISA divider to get an 8 to 8.333 MHz BUSCLK.

Clearly the G3 BIOS is more conservative with its timings than de J1 BIOS, and I found the J1 timings optimal.
But by Disabling the G3’s Auto configuration and setting the optimal settings manually, I could get the same chipset register programming as from the J1 BIOS. I also set Power Management on User Define to get the same SMM registers programming.

Perhaps you are already using the manual chipset settings in the G3 BIOS. If so, most of the above is not applicable. But by matching the G3 chipset registers setup with the J1’s, you should get the same performance for your PS/2 mouse and floppy. If not, then there must be a difference in the execution path.

Jan

CPU Identification utility
The Unofficial K6-2+ / K6-III+ page