SINTRAN III Carving + MON-Call RE — Status + Handoff¶
Full path: SINTRAN/CARVING-HANDOFF.md
(WSL: SINTRAN/CARVING-HANDOFF.md)
THIS IS THE LIVING STATUS DOCUMENT for the carving / MON-call / segment / NPL RE effort. It is the single place that answers "where are we?". See the maintenance rule in section 6 — it must be updated whenever a MON call, a segment, or NPL code is analysed.
Last status refresh: 2026-07-15 Version under analysis: L-VSX-500 (L07) Current priority: ND-500 <-> ND-100 communication interface (section 4a) — driven by the RetroCore emulator goal of recreating the 5MPM handshake.
ND-500 work has its own status doc¶
SINTRAN/ND500/ND500-STATUS-AND-INDEX.md(ND500\ND500-STATUS-AND-INDEX.md) That file is the ND-500 status of record + master document index: the evidence register, the 5MPM message layout, the level-12 GOSW gap, the poisoned priors, and links to every ND-500 document and artifact. If the work is ND-500, update that file, not this one. This file owns ND-100 dispatch, segment coverage, and the overall MON-call counts.OUTPUT LOCATION RULE¶
Everything goes under
E:\Dev\Ronny\NDInsight\. The D: drive is NOT a destination.D:\ND\t\re\is a one-off delivery snapshot from an earlier session, kept only as a historical reference. Never write to it. Where D: is mentioned below, it is a read-only relic — and its prose is known stale (section 1a).
This effort is separate from the live SCSI-mount debugging, which lives in
SINTRAN/Devices/SCSI/ and works on running-K traces, not the static carve.
0a. Tooling / regeneration log¶
2026-07-31 - nd100-dis missing-offset bug fixed; ALL L07 segments-ref regenerated.
nd100-dis was dropping the displacement operand of the post-indexed load/store forms
LDATX / LDXTX / LDDTX / LDBTX / STATX / STZTX / STDTX (e.g. word 143330 printed as bare
LDATX instead of LDATX 3; only NONZERO offsets were affected - a zero offset correctly prints
no operand). The fix is live in /usr/local/bin/nd100-dis. Every carved listing made before this
had wrong operands on those lines.
- Regenerated (clean, correct): all L-VSX-500
re/segments-ref/<SEG>/bundles viapython3 make-segment-ref.py L-VSX-500 --all(byte-swap to LE + correct base handled by the script). Verified:006-S3FS.asm026017 143330 LDATX 3. Segments 130B-141B skip (no load address = un-installed subsystems). - Standalone / sub-range listings - now fixed too:
re/006-S3FS.dis,re/003-S3CP.dis,resident/SINTRAN-DATA_commoncode.dis- fully re-disassembled with the fixed tool (whole segment; header notes the regen).re/030-S3SM5.dis- already regenerated by the team earlier the same day (its own header says so).re/kernel-carving/SCSI-DRIVER/_disklayer.dis(2 lines) and_inqui.dis(1 line) - surgically patched: bareLDDTX->LDDTX 4/LDDTX 2(offsets decoded with the fixed tool, not hand- computed; all otherLDATX/etc. there are offset-0 and were already correct).SINTRAN/ND500/nd-500-mon/nd-500-mon-j04.prog.asm- 3 lines patched:STATX->STATX 4.
- Third pass - the ANNOTATED analysis listings (207 lines, 23 files). The
--allregen covers onlysegments-ref/, and the second pass covered the standalone.dis. That left every hand-annotated.ASM/.txtanalysis listing still printing bare mnemonics. A tree-wide scan (excludingReference-Manuals/, which is vendor text) found 207 stale lines; all are now fixed and a re-scan reports zero. These were surgically patched, not regenerated - regenerating would delete the hand annotations. Only the mnemonic token was replaced, so comments and column alignment are preserved, and offset-0 lines were left untouched. Replacement text was decoded by the FIXED TOOL (a word->text map built by runningnd100-disover the 31 distinct words), never hand-computed - same rule as the second pass. The patch is idempotent.re/segments-ref/SINTRAN-DATA_commoncode/SINTRAN-DATA_commoncode.asm(138) - missed by the--allregen even though the siblingresident/...commoncode.diswas regenerated. Worth checking whethermake-segment-ref.py --allskips the resident bundle generally.re/mon-analysis/157B, 201B, 304B, 305B, 320B, 321B, 345B, 144B, 505B, 511B, 512B, 513B;re/mon-emulation/144B-MAGTP;re/kernel-carving/SCSI-DISKLAYER-COMPLETE (10), FUNCTION-42-RETURN;re/ND500-SYSTEM-MONITOR/ND500-3022-IOX-DRIVER (4), FUNCS-file-process;re/domino-nucleus-io/a-data-nkini (14), a-snucl-enkic (7), a-conki-040765, a-enucl-ncall, a-nkget-nkick.
- What the third pass CHANGED IN MEANING (these are analysis claims, not just text):
re/ND500-SYSTEM-MONITOR/ND500-3022-IOX-DRIVER.ASM051215-051230- offsets are 7, 7, 6, 2 (051226is offset-0). Without them the run read as a read-modify-write of ONE 3022 register; it is actually a multi-word structure walk atX+8touching words +7, +6, +0, +2. Re-read any conclusion drawn from this routine - it is MON 60B / item-0 territory.re/mon-analysis/157B-SegmentToPageTable070014/070067/070072- offsets 6, 7, 3. The existing annotations already said(X+disp), i.e. the analyst knew the field existed but could not see its value. This is a page-table walk, so WHICH word is read is the whole claim.- [OPEN]
re/ND500-HANDLERS-OVERLAY.md:181annotates141634 143340 LDATXasA := 5RECE (received-trap register). The offset is 4, so it loads5RECE+4, not5RECE. Line 78 derives the claim from NPL*5RECE@3, which matches neither. NOT yet resolved against bytes - do not treat either reading as verified. (That file is a.md, so the sweep did not touch it; the listing line inside it is still the old bare form.)
- DELETED 2026-07-31:
re/006-S3FS.annotated.dis. It was disassembled from a DIFFERENT, half-length carve (27136 words) whose BYTES diverge from the current.bin(its026017decodes toLDA ,B 1, not the realLDATX 3) - so it was not merely stale-offset, it was WRONG content for the current image and misleading to keep. Its 3853 inline labels were all symbol-table derived (FCSTA/VSXGE/INIQ etc. from FILSYS-SYMBOLS / SYMBOL-2-LIST), NOT unique hand analysis, and the correct carvesegments-ref/006-S3FS/006-S3FS.asmalready inserts every in-range symbol as a>>> NAME(TABLE)marker. Deleted rather than re-annotated: nothing unique was lost, andsegments-ref/006-S3FS/006-S3FS.asmis the authoritative replacement (correct bytes, fixed offsets, symbol-annotated).
0. Where the output lives¶
| What | Path |
|---|---|
| FULL working tree — 156 call folders | tools/sintran-segment-carver/versions/L-VSX-500/re/mon-analysis/ |
| Master MON index (full, authoritative) | tools/sintran-segment-carver/versions/L-VSX-500/re/MON-CALL-INDEX.md |
| Curated delivery mirror — 35 folders | D:\ND\t\re\mon-analysis\ |
| Delivery-mirror index (SUBSET — see section 1a) | D:\ND\t\re\MON-CALL-INDEX.md |
| Golden-path folder spec | D:\ND\t\re\mon-analysis\GOLDEN-PATH.md |
| Verified parameter contracts | D:\ND\t\re\TASK-05-results.md |
| Carved segments, all versions | tools/sintran-segment-carver/versions/{K,L,M}-VSX-500/segments/ |
| Symbol tables per version | SINTRAN/NPL-SOURCE/SYMBOLS/{K03,L07,M06}/ |
| ND-500 subject docs | SINTRAN/ND500/ |
| NC-oracle deliverables | SINTRAN/ND500/mon-oracle-for-NC/ |
| Carve method | tools/sintran-segment-carver/EXTRACTING-SEGMENTS.md, EXTRACTING-RESIDENT-CODE.md |
Exemplar folder = 317B-ExecuteCommand/ — the only one built on the corrected dispatch model.
Do NOT copy 005B-ReadScratchFile/'s Dispatch section; it still shows the retired fictional model.
1. CURRENT STATUS (audited 2026-07-15)¶
1.1 MON-call coverage (ND-100 side)¶
MON calls implemented in L07: 216. Folders that exist: 156.
| Status | Count | Meaning |
|---|---|---|
byte-verified |
1 | Folder fully rebuilt on the corrected model. 317B only. |
worker VERIFIED; dispatch needs rewrite |
87 | The MCTAB[N] worker word is byte-verified, but the folder body still documents the fictional GOTAB -> CALLPROC dispatch. |
WORKER CHANGED |
34 | MCTAB disagrees with the folder's worker. These folders are WRONG - but see the audit note below: all 34 now carry an in-folder correction banner. |
NO FOLDER |
94 | Implemented in L07, never analysed. |
Read that honestly: worker VERIFIED is a claim about ONE carved word, not about the folder.
Only 1 of 216 folders is actually trustworthy end to end.
STALE-MARKER AUDIT 2026-08-01 - the WORKER CHANGED folders are SAFE TO OPEN. Mechanically
checked every one of the 34 folders the index flags as WORKER CHANGED: all 34 carry an
in-folder correction banner, zero missing. So a reader who opens a folder directly - without
going via this index - is warned that its old worker is wrong. The folder BODIES still need
rebuilding, which is unchanged; the point of the audit is that none of them silently teaches the
disproven GOTAB -> CALLPROC worker.
Same audit on the three known poisoned priors across the whole tree: the fabricated TAG-code
protocol, WIOM, and "the swapper is control-store microcode". Every surviving mention is
a correction or a retraction - no document still teaches any of them as current.
SINTRAN\Emulator\DETAILED-TAG-MECHANISM-EXPLANATION.md,
Operations\SINTRAN\ND500-MONITOR-CALL-ARCHITECTURE.md and
Developer\MON\calls\60B_N500M_Hardware_Mapping.md all carry explicit banners.
Recorded so this audit is not repeated. It was prompted by finding five stale markers in the ND-5000 octobus docs the same day, where corrections had been written into the file where the work happened and never into the files that repeat the claim.
Folders documenting MON numbers not present in MCTAB — may be documenting nothing, need audit:
155B, 175B, 176B, 177B, 324B.
1.2 Segment coverage¶
~60 segments are carved. Only 4 were ever disassembled (006-S3FS, 025-S3IRPIT,
026-S3IMPIT, 030-S3SM5), plus 003-S3CP / 044-S3IDPIT referenced by address only.
Consequence — read this before ever writing "uncarved": when a doc says a routine or table is "resident and uncarved", that has almost always meant nobody looked in the other 56 segments. Check them before concluding anything is absent. This is the single most repeated error in this effort.
Not yet promoted into re/segments-ref/ (referenced by address only, no .asm):
003-S3CP (holds UECOM/COMSB/UELOG) and 044-S3IDPIT (holds MCTAB).
1.3 ND-500 status — the honest version¶
The full index's ND-500 table asserts in prose that ND-500 calls were "never affected by the GOTAB bug ... always byte-verified". That claim is unsupported: the ND-500 table has no worker column, no segment column and no per-row status. Do not rely on it.
What is actually true, verified from the folders themselves:
Byte-verified and symbol-pinned (the handler BODIES):
STAPR=140356B (500B) · NSTOP=140511B (501B) · NINST=141272B / XNINS=141277B (503B) ·
OSTRS=141205B (504B) · GERRC=141633B (505B) · 5SIBM=141716B (506B) · SWMC=142153B (510B) ·
DVIO=141027B (511B) · A5XMS=142253B (512B) · B5XMS=142253B (513B — same body as 512B) ·
M5TMO=140563B (514B, in 026-S3IMPIT, load 32000B) · 5MTRA=143445B (515B).
NOT byte-proven — the gap that matters: every MON 5xxB -> handler LINK. The level-12 GOSW
table mapping 5CMNO-L12MIN to the handler is claimed resident-and-uncarved. The entire 500B-523B
ordering comes from ONE NPL line range (MP-P2-N500.NPL:1385-1390) — and NPL is a different
revision than the carved bytes. So: bodies real, dispatch unproven.
Inverted case (264B, 265B, 266B, 416B, 420B): S3SM5 0x60 vector routing IS
byte-proven, but the bodies decode only partially.
Byte-proven ABSENT (S3SM5 vector slot = 0000): 425B (0x28a), 426B (0x28c),
427B (0x28e), 436B (0x29c), 437B (0x29e). For 436B/437B the GOTAB hit is a
coincidental index into the device table (DT85W/DT86R) — not a handler. Servicing point NOT LOCATED.
60B-N500M: GOTAB[60B]=000000 fall-through is byte-proven. Symbol N500M=030416B lands in a
data/ASCII region — real servicing is in the separate ND-500-MONITOR / MP-P2-N500 back-end,
outside this carve. Its ~67-subfunction table is manual-sourced, not byte-sourced.
Missing 5MPM interface facts (blocking the emulator):
- Offsets for MCNO, SMCNO, FUNCV, KFLIP, NUMPA, N5STA — "not found in symbol files".
- Status-code VALUES MSGN500 / WAITING / ANSWER / 5ERANSWER — absent from NPL. Manual hint
only (0=free, 1=to-ND500, 2=in-process, 3=answer, 4=error), unverified.
- The 5STDRIV -> CHN5STATUS -> DECOMESS -> MCHANDEL chain: NPL-documented, never located
in carved bytes.
Known-good ND-500 values (symbol-verified): MOCAL=1, TRAPC=2, 5FMOC=3; MICFU
3STAR=23B, 3MONC=24B, 3TRAC=25B, 3WMON=26B, 3MONO=34B, 33MON=46B; STOPR at message
offset 000011B; TRAPN at 000016B; STOPREASON = bits 10-14 of RSTA5, mask 037000B.
1.3a ND-500 interface carve — DONE (2026-07-15)¶
The ND-100 <-> ND-500 communication interface has been reverse-engineered end to end from the
carved L07 bytes. The full path command -> thunk -> gateway -> MON 60 -> N500M 5IFUNC ->
FPT2ENTRY -> FUNCS[code] -> ND-500 op is mapped and byte-verified, and the control-store gate
that blocked the emulator is solved (return RSTA5 STATUS bit 9 5CLOST clear). Both sides:
- ND-100 -> ND-500 (MON 60B / N500M worker):
tools/sintran-segment-carver/versions/L-VSX-500/re/mon-analysis/60B-N500M/— 47 subfunction folders + the5IFUNCtable + a caller-vs-worker cross-analysis. - ND-500 system monitor (S3SM5 side):
tools/sintran-segment-carver/versions/L-VSX-500/re/ND500-SYSTEM-MONITOR/— theFUNCSoperation table, the3022IOX driver + byte-validated register map, the control-store gate fix, the5MPMmessage + activation, the level-12 return path, and allFUNCSroutine bodies. - Status of record:
SINTRAN/ND500/ND500-STATUS-AND-INDEX.md.
This supersedes the older "60B-N500M lives outside the carve" conclusion in section 1.3 and the
phase-1 items in section 4a (kept below for their evidence-register detail).
1.4 POISONED PRIOR — active bug in the emulator¶
The "TAG code" protocol (codes 8/9/16 = MonitorCall / PageFault / OperationComplete) documented in
SINTRAN\Emulator\ND500-QUICK-REFERENCE.md, DETAILED-TAG-MECHANISM-EXPLANATION.md, and implemented in
RetroCore's NDBusND500IF.cs, is FABRICATED. It exists neither in the ND hardware nor in
SINTRAN. Recorded in ND500-L-RELEASE-RE-TASK-HANDOFF.md. It must be removed and replaced with the
real 5MPM handshake once section 4a lands.
1.4a SCSI ENTER-DIRECTORY mount bug — RESOLVED (2026-07-14, verified live)¶
Not a SINTRAN bug: RetroCore's ND-100 RDIV (141600) early-returned on overflow without writing A/D,
so the mount's geometry-check division (UHLIM/2)/divisor read a zero quotient and aborted with 243B
before block 0 was read. Fixed (always write A/D, then set Z); mount works. Full write-up:
tools\sintran-segment-carver\versions\L-VSX-500\re\kernel-carving\RCBLO\README.md section 4.
1.5 File-name abbreviation matcher — CARVED (2026-07-16)¶
The SINTRAN file-name subpart abbreviation/matching algorithm (used by OPEN/FOPEN and the whole
FILSYS name/list family) is byte-verified. Full write-up:
tools\sintran-segment-carver\versions\L-VSX-500\re\segments-ref\006-S3FS\FLPAR-MDEAB-FILENAME-RESOLVER-CARVE.md.
Result: matching is character-prefix via one shared comparator COMPS @041552 (supplied
string is a prefix of the stored string = match; exact match distinguished; -(55) = positional/
empty subpart that matches any value in that slot; *(52) = wildcard; '(47) = string terminator).
Each name class scanner (GDIRI dir, GNAMI name/device, GOBJI file) counts COMPS matches:
exact wins outright; else 0 -> "No such", 1 -> unique, >1 -> "Ambiguous". Verified file codes from
GOBJI @056326: 056 no-such / unique / 057 ambiguous (056576-056607). Callers use the
SPUSH/SPOP (003752/003776) reentrant-stack multi-return skip-count (MIN ,B4) convention.
Two poisoned priors corrected here: (1) the request's assumption that 0111=ambiguous is WRONG
— ambiguous-file is 057; 0111/0113 are a separate access/type classifier in MDEAB's ,B27
bit-tree. (2) An interim draft's "numeric not prefix" claim was a misread of GOBJI's hash pre-filter;
the definitive compare is COMPS and it IS a prefix match.
Still OPEN: GOBJI hash-prefilter field layout (entry[42]/[44]) - low value, implementers may omit the pre-filter; FLPAR descriptor output layout - not needed for external resolvers.
0106-0114 DECODED (2026-07-17): the MDEAB ,B27 bit-tree codes are the ACCESS-DENIED error
family (ND-60.050.06 p.286): 070 not-directory, 0106 not-write, 0110 not-write+append,
0111 not-read, 0112 not-R+W+common, 0113 not-R+W, 0114 not-R+common. ,B27 = requested
access mask, bit0..4 = R/W/A/C/D. GFIAC@057771 reads the granted side from file entry[43B]
(owner/friend/public select via GUSEN/GUSEI/RUSER/RUSEB) and returns (access>>12B)&17B.
Addendum 2026-07-17 (byte-decoded 041624-041706, closing the - edge cases): if the STORED
name ends before its next - while the supplied name still has a - subpart -> NO MATCH
(041624-041627, checked every skip iteration). A match that used a positional - can only be
PREFIX, never EXACT (041664->041666->041613). ,B12 = -(field width): budget exhaustion in
the main loop = EXACT (full-field equality); during a B-skip = NO MATCH. Field width is
caller-supplied (GNAMI passes SAT 20 = 16 chars). Also corrected: GNAMI does a LINEAR scan
(,B22 += 16B = entry stride) and UNPACKS the stored name for COMPS - the earlier "hash bucket
+16 / packs 7 chars" wording was wrong.
1.6 Background logout machinery + the "FS RT flag" loop — CARVED (2026-07-17)¶
Answer to the live SCSI-boot loop (RELEASE-USER re-running ~4/s forever):
SINTRAN\Devices\SCSI\CARVE-ANSWER-FS-RT-FLAG.md. Key results, all byte-verified in
003-S3CP/013-S3SCP (identical copies) unless marked:
- The "FS RT program main loop" is BLOGO @066663B (background LOGOUT, SYMBOL-1-LIST), loop body 066671B; tail jumps to XBLOG @041554B (pointer cell 066754B = 041554B). SYMBOL-1-LIST is hereby validated for the 041xxx-067xxx S3CP range (XBLOG exact pointer match + LOGOU/XLOGO/ALOGO/BILCM boundary coherence + existing UECOM anchor).
- The state flag is background-datafield word ,B -103; complete writer sweep = 11 writers. 1 <- login (CCCOM 061722B); 2 <- request posters (MODE 102677B, LOGDI 103001B); 0 <- five sites ALL gated on flag==2/even; -1 <- BLOGO 066725B + abort path 067010B. No -1 -> done writer exists; -1 is the resting logged-out state. Re-runs are driven by the router 050045B-050053B (flag 1 or -1 -> JMP I via ptr 050200B = BLOGO) on every activation. The emulator bug is a re-activation loop, not a missing flag write.
- BLOGO gate-calls FILSYS RLUSE @115020B via inline-argument convention (JPL I through a pointer cell holding gate 016561B; next word = FILSYS target; inline args at 066734B / 067005B / 067274B all = 115020B). RLUSE decrements user-entry word +25B once, NO zero guard (115057B-115066B); helper calls = TUSEN 053174B / RUSER 053246B / WUSER 053410B. RUSCN @106562B is the increment twin (106636B-106645B).
- POISONED PRIOR: "main loop ~ CHNUS+25B" (FILSYS symbol) was numeric coincidence - FILSYS link space == 006-S3FS carve VAs (RRLUS/RLUSE twin-entry proof) and the loop bytes are not in S3FS. Also: the live boot disk is a DIFFERENT SINTRAN generation than this carve (P-relative literals and one RLUSE B-frame offset differ; in-page offsets incompatible) - anchor live<->carve by hex fingerprint only, never by constant offset.
1.7 MON 50B OPEN quoted-filename semantics — CARVED (2026-07-17)¶
For the nd500x linker/NC bring-up. Answer doc: SINTRAN\ND500\CARVE-ANSWER-OPEN-QUOTED-FILENAME.md.
Byte-verified in 006-S3FS unless noted:
MCTAB[50B] = 103034B = OPFIL(044-S3IDPIT; validated vs RDISK/MAGTP slots; slot 200B is 0 in this build). Chain: OPFIL -> FCON@067002B -> FFILE@065144B -> GCFIL@064670B.- GCFIL is the quote handler: first char '"' (test 064677B) -> strip-by-copy -> dispatch
CROBJ@063726B (create); unquoted -> GFILI@057173B (lookup only, NO create path in
its pointer pool).
NAME;"n"-> CRNEW@064410B. No flag - routine dispatch. - CROBJ: GOBJI error 056B/057B -> create (COBJE@061502B + CNEWV@063313B); lookup success T!=0 -> error 076B "File already exists" (064040B). Quoted = create ONLY if absent; existing quoted file is an ERROR, never truncate/overwrite/open-as-is.
- Unquoted missing = 056B "No such file name" for EVERY access code - write-open-creates does not exist in SINTRAN III. Emulator auto-create is non-standard, confirmed.
- SEPUS@043100B skips one leading quote before
(USER)(quote wraps the WHOLE spec); SEPFS@042622B treats any interior quote as error 021B.
1.8 Unqualified OPEN: current-user -> (SYSTEM) fallback is SINTRAN-internal — CARVED (2026-07-18)¶
For the nd500x / mon_path.c author. Answer doc:
tools\sintran-segment-carver\versions\L-VSX-500\re\segments-ref\006-S3FS\CARVE-ANSWER-UNQUALIFIED-OPEN-USER-SYSTEM-FALLBACK.md.
Byte-verified in 006-S3FS:
- An unqualified 50B OPEN does NOT search "current user only."
GFILI@057173Bscans the caller's default directory first (filled byGDEFD@055263B), and on 56B "No such file name" it walks the directory table viaGDIRT@050124Band finally scans the (SYSTEM) directory viaGSYSI@055540B(SYSTEM index resolved by NAME viaGMUSI@054527B, not a hardcoded user number).GFILIcallsGOBJI@056326Btwice: first 057263B, again (under SYSTEM) 057443B. - The fallback is INTERNAL to the file system (GFILI in 006-S3FS), NOT the linker's job. A caller
does not prepend
(SYSTEM); SINTRAN does the second scan itself. - Gated by
,B40 == -1(057414B-057417B): if a user is named explicitly,,B40 != -1and the fallback is suppressed -> only that user's directory searched. [V structure; the exact SEPOB setter of,B40= still OPEN, but the BEHAVIOUR is confirmed by the manual.] GFIAC@057771B(friend/public/ring access) is a post-resolution permission gate run by the open worker AFTER the entry is found — it does NOT steer which user/dir is name-searched.- Independent confirmation: ND-60.050.06 SINTRAN III Users Guide lines 1720-1724 states the rule verbatim (own directory first, then user SYSTEM; a named user restricts to that user). The carve pins WHERE the rule lives (GFILI) and proves it is file-system-internal.
Full GFILI body carved (2026-07-18):
tools\...\re\segments-ref\006-S3FS\GFILI-COMPLETE-CARVE.md - complete instruction-level walk of
GFILI@057173B-057504B (all pointer cells resolved, frame-local map, stage A-F flow). Two upgrades
from the fallback answer doc, now [V]:
- The ,B40 fallback gate is byte-proven: at 057213B-057217B GFILI re-reads spec char[0] via
GETCH, and if it is '(' (a (USER) prefix) it zeroes ,B40; the SYSTEM fallback at 057414B
runs only when ,B40 == -1. This is the mechanism behind Users-Guide rule "named user -> only that
user". (Was [OPEN].)
- GFIAC@057771B is NOT referenced anywhere in GFILI's body (every pointer cell listed) -
confirming GFILI is lookup-only and access-checking is a separate caller stage. (Was [I].)
- Also mapped: GFILI calls SPUSH/SEPOB/GETCH/SEPFS/GOBJI(x2)/GVERS/GNEXV/GDIRT/GSYSI/SPOP; version
chain = GVERS(parse)+GNEXV(walk entry keys +41B/+44B). Version numeric semantics still OPEN.
1.9 DOMINO / NUCLEUS / octobus-driver I/O stack — CARVED (2026-07-19)¶
Three byte-verified carve docs in
tools\sintran-segment-carver\versions\L-VSX-500\re\domino-nucleus-io\
(BDIO-DOMINO-DRIVER-CARVE.md, OCTOBUS-DRIVER-ROUTINES-CARVE.md,
NUCLEUS-PRIMITIVES-CARVE.md + NUCLEUS-SEGMENTS-RECON.md + annotated
listings a-*.txt). Context/plan doc:
SINTRAN\ND5000\OCTOBUS-DEVICE-CONTROLLERS-ANALYSIS-AND-EMULATION-PLAN-2026-07-19.md.
The ND-500 status doc carries the full fact blocks (section 0e there).
NEXT CARVES SCHEDULED (2026-07-20, SCSI-DIOC plan
SINTRAN\ND5000\SCSI-DIOC-OCTOBUS-EMULATION-PLAN-2026-07-20.md phase S0):
ALL FOUR DONE 2026-07-20: S0-1 CONKI, S0-2 DOMDF initializer, S0-3 NKSE
segment-105 interior, S0-4 PROMAN auto-run (fact blocks below).
Remaining [OPEN] tail: DRPRT/DLPRT symbol->sub-offset pin (SYMBOL-2-LIST
NKMBU pinning or live create-port capture); freelist-head master offset
(runtime global, zero on disk); full NCALL per-word map (live
round-trip); fn 11B-14B worker bodies.
105-S3INKSE NUCLEUS server interior — CARVED (2026-07-20, S0-3) [V]:
the segment is a PLANC-compiled program (runtime lib at 112xxx; frame
stubs 112541 ENTER / 112576 LEAVE / 112570 ERRETURN - worker addresses
appear as data words after call sites, not jump operands). doNuc
dispatcher @037033 [V]: linear SAT-ladder on request word +12,
functions 1..14B, full fn->worker table dd-verified; default ->
"doNuc: unknown func=" @040101 + " Nucleus FATAL Error" @040062.
*fn 10B = 047432 = descriptor CREATE/provision [V] - the SIN-F5a/c
port-number writer: sets port +20 (KICKDEST/remote station), +30
(OWNID/port-number identity block), +2 OWNER, +4 FREELINK via field-set
helpers 070345/070422/070477/070560 - offsets MATCH the kernel-verified
port layout (7-item coherence check vs NUCLEUS-PRIMITIVES-CARVE.md
section 4 PASSED, no divergence). ACONV number->ID = 056332
(ID = number<<6 + base, error 101004 ILLNO); validity/free walker
057631; allocator front-end 063371/063464; NCALL client wrappers
072263/073207/073266 confirm the request skeleton {state, word-count,
caller-id block, param, >=7-word reply}. RECON targets: 1 DONE,
2 PARTIAL (freelist head [OPEN]), 3 PARTIAL (skeleton only), 5 [OPEN].
Doc: re\domino-nucleus-io\NKSE-SERVER-INTERIOR-CARVE.md
(+ 6 a-nkse-105-*.txt listings). Results land in domino-nucleus-io\ and
get folded back into this section per the standing rule. NOTE the
2026-07-20 correction: the host->remote NUCLEUS kick is byte-verified
kick 1 (NUCKI); "kick 5" is only the manual's kick-NAME table - never
wire kick 5 on the NUCLEUS path.
CONKI / KICKENT — CARVED (2026-07-20, S0-1) [V]: CONKI @040765
(SYMBOL-1-LIST; 017-S3SMPIT = 026-S3IMPIT, base 032000B) registers
KICKENT[T] := (DLEVE=A, DFADD=B) in the ring-X octobus INPUT controller's
kick table (pointer table at input-df[-13], bank at df[-14]). Arg
meanings PROVEN: T = kick number (1..17B), A = DLEVE dispatch code =
octal PIL level (12B->lvl10, 13B->lvl11, 14B->lvl12), X = ring,
B = datafield. HEADLINE: NKINI calls CONKI(T=1, A=14B, X=0, B=125144),
and the receive path (decoder 035555 -> kick dispatch 036047
KICKENT[frame & 17B] -> code-14B arm 036233) fires PIL level 12 with
P := mem[125143] = 044747 = DKICK — incoming octobus KICK 1 dispatches
to DKICK, matching the send side (NKICK -> SKICK kick 1) end to end.
Receiver masks the frame with 17B: kicks 20B-37B ALIAS 0-17B. Kick
dispatch codes: 0-2 datafield driver activation via 013552, 5 fire
level 5, 12B/13B/14B activate PIL 10/11/12. ECONID @040467 is a separate
body (ident lists at df[-7]), no shared helper. Corrected lead: cells
007341/007342 are the CBPOOL free-list head/count, NOT CONKI
registration cells. Remaining [OPEN]: cell 007347 level-pending mask
semantics; OLINK busy-chain drain point; which subsystems register DLEVE
codes 0-2/5. Doc: re\domino-nucleus-io\CONKI-KICKENT-CARVE.md
(+ a-conki-040765.txt).
DOMDF initializer — CARVED (2026-07-20, S0-2) [V]: the initializer is
the FILSYS DOMINO pool/port module in 006-S3FS (= 012-S3SFS), VA
133203-137000, base 026000B (35 FILSYS sibling symbols on parallel PROC
entries = overlay proof) - NOT resident init, NOT NUCST, NOT userland.
QUINI @134206 (lazy, guard DOMDF+15) creates the local NUCLEUS port
via MON 347 fn 1 (DCRPR, T=3) -> DOMDF.DLPRT(041103); writes
DSVER(041104):=1, DOMDF+21:=30B; creates one NUCLEUS message per disk
queue element (BFQUE 033341..EFQUE 036350, stride 37B) storing DMSID at
elem+13. PDF.DRPRT written by GPOOL @133343 / RGPOO @133701 / RCPOO
@134516, value = DOPPR @136352 = MON 347 fn 3 open-port-by-NAME (pool
name lookup); same routines fill PDF.DIPOO/OPAIX/ARESZ from the connect
answer (answer layout [OPEN] -> segment-105 carve). MON 347 wrapper
family byte-mapped (CRPRT/OPPRT/CRMSG/CLPRT T=1; DCRPR/DOPPR/DCRMS/DCLPR
T=3; SNMSG/RCMSG/REMSG/WRMSG X=1/2/3); GVACD scans devnos 2260B-2277B.
DISPROVEN: the "DSVER+32..67 static header" - those words are the
generated zero tail + ADOML lock + NKMBU start, swept along because the
70B/76B transfer windows exceed the 32B-word record; DON'T CARE for the
DIOC. The SCSI unit/LUN binding = PDF.DRPRT (per-pool named port) +
DXPOO/OPAIN in each message, resolved DIOC-side. On-disk DOMDF is zero
except +2..3 and +6=074246 REBDIO pre-planted at generation [V].
POISONED PRIOR killed: BDTMU=075326/BDTMV=075356 bodies are in the RPIT
overlay (016-S3SRPIT), NOT MPIT (MPIT bytes there are XMSG code); they
queue the pool DF and start RT RECST @075225 -> FILSYS RGPOOL/RCPOOL.
Doc: re\domino-nucleus-io\DOMDF-INITIALIZER-CARVE.md
(+ a-domdf-init-006-s3fs.txt; 90 words dd-reproduced).
PROMAN auto-run — RESOLVED (2026-07-20, S0-4) [V]: PROMAN does NOT run
at boot on this image. An emulated SCSI DIOC at stations 10B-13B gets
NO EchoTest/IdentY/SetBxP/BxDoLd/RegMod/Go-On traffic. Decisive: live
@LIST-RT-PROGRAMS shows PROMAN 14615B PASSIVE P-REG=0B (never executed;
same for NKSERV/NKNAME/EVMESG/BOPCOM/MTSERV; calibration XROUT/XMFIDO
did run); pack BIGDISK0-L.IMG has NO (SYSTEM)PMA-CONFIG / PMA- images /
DOMINO kit. Segment identity string-proven: 120/121 = PROMAN ("PROMAN
started", "(SYSTEM)PMA-CONFIG", boot-error ladder, module table incl.
"SCSI"), 124/125 = BOPCOM. [NPL-V] no kernel auto-start exists;
OCSTART/NUCST only allocate memory. NEW find [V, consumer OPEN]: a
server-start table in the command processor (003-S3CP @0xbb60 /
013-S3SCP @0xc360) = (RTdesc,flag) pairs NKSERV,2 NKNAME,0 PROMAN,2
EVMESG,0 BOPCOM,2 MTSERV,2 — its consumer/flag semantics/gate are
[OPEN]; it did not fire this boot. Answer flips only if PROMAN is
deliberately started AND MF-bus crate interrogation (or PMA-CONFIG)
reports the DIOC AND PMA- images are installed; re-open if the harness
ever emulates crate interrogation. Doc:
re\domino-nucleus-io\PROMAN-AUTORUN-RECON.md.
BDIO / DOMINO block-I/O driver [V]:
- Overlay: 017-S3SMPIT (= 026-S3IMPIT, byte-identical, cmp = 0 diffs),
base 032000B — NOT 065-S3SIPIT (decodes to garbage there). Proven by 9
SUBR siblings (BDMTR 073454 / BDMFU 073565 / MBUIL 073700 / DCNVA 073750 /
SSBDI 074000 / BDTRA 074012 / BD12T 074024 / STRBD 074072 / REBDI 074246,
SYMBOL-2) + 40 literal-pool symbol hits, 13 anchors dd-reproduced.
- STRBDIO builds the BDIO message in the global DOMDF=041064 record
(body at DSVER = DOMDF+20 = 041104B), function codes read=166B (size
74B) / write=167B (70B) / compare=213B (70B), sends via nucleus gates
NKWRI 043411 / NKSEN 042171, waits WT12 033616 with DOMDF.NFUNC(+6)
= REBDI as continuation; REBDIO drains NKREC 043076 / NKREA 043375
(read-back max 76B), decodes DSSTS -> HSTAT (-2 nucleus reject SINEC
1661, -4 device error SINEC 1662 + BDTMU retry, -5 = statuses
104031B/104651B/104622B).
- DCNVA 073750: DOMINO byte addr = ((nd100_word_addr -
(N500D.ADRZERO << 10dec)) << 1) | bit31; bias cached by SELF-MODIFYING
the entry word to 124012 (JMP). N500D=051767, ADRZERO=+60.
- NPL = MP-P2-DISK-START.NPL (different revision, +237B shift, logic 1:1).
- BDIO record = ABSTrans message; address model (2026-07-23)
[domino-nucleus-io/BDIO-ADDRESS-MODEL-FINDINGS-2026-07-23.md +
QUDF-ABPA2-PRODUCER-CARVE-2026-07-23.md]: record fields map to ABSTrans
ABFUN/MEMA1/ABP21/ABP31 (ND-820023). (a) The DOMINO memory address DMYAD is
window-relative once bit 31 is stripped -> mpmByte = mpmStart + (DMYAD &
0x7FFFFFFF) (ADRZERO cancels since mpmStart = ADRZERO2048) [V-derived].
(b) The media address DSTBL (=ABP21) is copied VERBATIM into QUDF.ABPA2 by
GAPFU 000744B / GAPFD 034006B (LDD I,B 2 / STD ,X 17, xxd-verified) and
by MBUILD; the DOMINO BDMTR path SKIPS the SMD TOSECT geometry conversion
-> DSTBL is a LOGICAL 2KB-page/block index, disk byte offset = DSTBL2048,
length = DNRPG*2048 [V driver path]. Consumed by RetroCore BdioRecord.cs.
Octobus driver routine set [V] (one-liner; full block in ND-500 doc): SKICK/MBSEND/OMBREAD + XKICK500/5OMBREAD/MFPREPARE/CON5IDENT/5MTRANS/ 5MRDTRANS byte-carved in 026-S3IMPIT. MBSEND has NO IOXT — it queues a CBPOOL buffer and fires level 13 (P:=SOCTW 036342); 037320 is SKICK's direct-TX IOXT block. Max multibyte length 255 bytes. L07 SAMSON stations are 70-77B (LN5DEST=77; M06's 73 is a different build).
- NUCLEUS kernel (DOMINO message passing) [V]:
- - Overlay: NK primitives in 017-S3SMPIT = 026-S3IMPIT* (base 032000B),
- NOT 003-S3CP, NOT the NKSE segments (104/105 hold the server program).
- Proven by call-target density (21 family targets / 64 pointer hits) +
- uniform prologue.
- - Byte-proven kernel structures (octal word offsets): master block (+2
- descr-table ID, +7 count, +20 kick-table ID, +25 version, +74/76 health
- flags); descriptors = 40B-word records (LOCK+0, TYPE+1, OWNER+2..3);
- port (+10 MESS HEAD, +12 MESS TAIL, +14 KICKLINK, +16 KICK HEAD,
- +20 KICK DEST = octobus station, +21 INQUEUE, +22 KICK PROC/EVENTS,
- +30 OWNID) — order matches ND-820026 fig 25 exactly; message (+10 LINK,
- +12 BUFFERPOINTER, +14 HOMEPORT, +21 OWNINDEX); buffer (+23 SIZE,
- +25 LENGTH, data +26B); kick table = 14B-word entries per octobus
- station (KHEAD+0, KTAIL+2, KLOCK+4).
- - Kick path [V]: NKSEND -> port+20 == own station ? SETEV local (16-way)
- NKICK enqueue + (only when queue was empty) SKICK(A=1=NUCKI kick, X=0, T=station). Receive: DKICK 044747 drains the own-station entry.
- MON 347B = NUCLEUS: MCTAB[347B]=047072 [V] =
SERVE(MON-CALL-INDEX name "MGDAE" is a flat-table collision; overlay is MPIT not 003-S3CP — index row needs the fix). - Locking: physical TSET = opcode 140516 (nd100-dis "USER1"), lock value 070000B, 020 retries with master+74/76 health-flag abort.
- [OPEN]: ENKIC=047526 (N500-SYMBOLS, ACCP family) resolves in NO carved overlay tried; server-side structures (hash array, freelists, NCALL mailbox map) need a segment-105 carve — recon + target list in NUCLEUS-SEGMENTS-RECON.md.
Poisoned prior (recorded per rule below): the MCTAB validation example "MON 200B -> XMSG 007516B" used in section 3 did NOT reproduce — MCTAB[200B] = 000000 in 044-S3IDPIT [V] (coherent: MON 200B XMSG is a GOTAB level-14 fast call, its slot in MCTAB is empty, as section 1.7 already noted). Validation slots are now 005B/144B/317B/347B.
1a. Index discrepancy (resolved 2026-07-15 — do not re-panic)¶
The D: index prose says "Six rows changed worker: 15B, 45B, 120B, 304B, 313B, 327B". The E: index
marks 34. This is not a factual contradiction. The D: file is the 35-folder delivery subset;
the E: file is the full 156. The D: prose is additionally stale — its own table already shows seven
changed (15B, 45B, 51B, 120B, 304B, 313B, 327B) plus 42B flipped from "absent" to
OLDOP=103037B.
The E: full index is authoritative. The D: mirror is a delivery snapshot; treat its prose as stale.
Confirmed worker corrections: 15B -> SETUP=103417 · 42B -> OLDOP=103037 (NOT absent) ·
45B -> BDBRK=002235 · 51B -> GBRKD=014263 · 120B -> XWFIL=026407 · 304B -> MAPSI=103675 ·
313B -> IBRSI=110543 · 327B -> MFFSC=111563 · 312B -> MOINF=032600 · 317B -> UECOM=050701.
2. Two separate efforts (split confirmed)¶
| Effort | What | Version | Data | Home |
|---|---|---|---|---|
| A. Carving + MON RE (this doc) | static RE of the SINTRAN image | L07 (+K03/M06 carves) | carved .bin + NPL symbols |
E:\...\versions\L-VSX-500\re\ |
| B. SCSI mount bug (separate) | why @ENTER-DIRECTORY fails on SCSI |
K-VSX-500 running trace | live opcode+register traces | SINTRAN/Devices/SCSI/ |
Do not conflate them — different versions, different data, different methods.
3. CRITICAL GOTCHAS (learned the hard way — do not repeat)¶
- VERSION <-> SYMBOL ALIGNMENT. Binary and symbol table must be the same version or every name
is wrong. Proven: binary
K-VSX-500<-> symbolsK03(K03ENDIR=127774/RCBLO=032433land onSTD Iprologues in K).L07symbols do NOT fit K (ENDIR=140176lands on mid-routine junk). - NPL source is a DIFFERENT revision than the carved L bytes. Use NPL for logic, never as authoritative bytes. Carved bytes are ground truth.
- Overlays: the same virtual address decodes in many segments. An address is meaningless without knowing which segment is mapped. Pick the segment by structural coherence — take 2-3 sibling symbols and find the segment where ALL land on parallel entries. Never by "it disassembles to something".
nd100-distakes little-endian input — byte-swap the big-endian carve first. Always confirm a disassembled opcode word equals the source word before trusting the mnemonic.- Honest status only. Mark VERIFIED (from bytes) vs INFERRED. Never upgrade a subagent's or the
NPL's claim to VERIFIED without checking bytes yourself. Never fabricate
.ASM/.bin. - A table is only "the" table if its known slots match. Validate against 2-3 independently known
entries first. GOTAB: slot 0 =
MFELL 072114B, slot 1 =M1 071633B, slot 2 =M2 071635B. MCTAB:MON 005B -> RDISK 102021B,MON 144B -> MAGTP 026354B,MON 347B -> SERVE 047072B(NUCLEUS; [V 2026-07-19]); the 317B slot is also validated (value in the 317B-ExecuteCommand golden-path folder). The OLD example "MON 200B -> XMSG 007516B" is WRONG — MCTAB[200B] = 000000 [V 2026-07-19] (XMSG is a GOTAB level-14 fast call); see section 1.9. - "Symbol lands on a
021xxx STD Iprologue" is NOT a universal entry test. Handlers reached by a dispatchJMPhave no link to save and noSTD I(UECOM=050701Bstarts146141 RADD CLD SL DD). Use that test for JPL-called routines only. - "Uncarved" usually means "nobody looked." See section 1.2. 56 segments have never been disassembled.
- Reproduce every offset with
ddbefore publishing it. Never publish a computed offset.
3a. THE ND-100 MON DISPATCH MODEL (corrected 2026-07-13 — byte-verified)¶
The previous model ("GOTAB[N] -> uncarved CALLPROC -> worker") was wrong. There is no
uncarved bridge. Full derivation: D:\ND\t\re\mon-analysis\317B-ExecuteCommand\README.md.
MON N -> ENT14 072167B level-14 entry (in 017-S3SMPIT / 026-S3IMPIT, NOT commoncode)
-> X := MEM[MGOTA + N] MGOTA = 071233B ; 072256B LDX I ,X 20
-> JMP ,X (072260B) a DIRECT JUMP - no call, no bridge
-> GOTAB[N]:
32 of 256 slots = resident fast handlers (MON 1B, 2B, 21B-24B, 63B,
163B, 200B XMSG, 310B, 346B-377B); arm B-level via IOB14=071660B
224 of 256 slots = MFELL 072114B
-> MFELL: IRW 20 DX (pass MON number) ; IRW 20 DP := CALLP 032201B ; MST PID/PIE
== a program-LEVEL switch (this is the thing once called "CALLPROC")
-> CALLP on the monitor level
-> MCTAB[N] MCTAB / 9MCTA = 005620B, in segment 044-S3IDPIT
-> worker
MCTAB@005620Bis the real monitor-call table, one word per MON number, indexed by N. 216 of 256 slots populated; every populated slot lands on a named L07 symbol.GOTABis NOT the monitor-call table — level-14 fast path only. It isMFELLfor 224 of 256 calls, so it cannot identify a call.- Commoncode's
071233Bis NOT the GOTAB (slot 0 =000000, slot 1 =120303B). Everything derived from it — every112xxx/120xxx/121xxx"GOTAB entry" in the old index, and the shipped NC oracle values for MON 312B/317B — was wrong and has been corrected. - MON 312B (MOINF) returns
MCTAB[N], notGOTAB[N]. ENT14,CALLP,MOINFdo not resolve in the commoncode carve but do in the PIT segments. SYMBOL-1-LIST03xxxx/07xxxxcode addresses describe the PIT-mapped resident image, not that carve.
4. PLAN — remaining work, in priority order¶
Agreed priority (2026-07-15): ND-500 interface first; cleanup limited to what ND-500 touches. Goal: recreate the ND-100 <-> ND-500 communication in the RetroCore emulator.
4a. PHASE 1 — the ND-500 <-> ND-100 interface (ACTIVE PRIORITY)¶
Detailed plan + evidence register: ND500\ND500-STATUS-AND-INDEX.md section 6.
Keep ND-500 detail there; this is the summary.
The MON-call bodies are largely NOT what the emulator needs. The handshake is — in both directions:
- ND-100 -> ND-500 = MON 60B (
N500M) across the 3022 bus. ITEM 0, TOP PRIORITY. Essentially everyND-500-MONcommand reaches the ND-500 through this one call, so without it the emulator can answer the ND-500 but cannot drive it.MCTAB[60B] -> N500M=030416Bis byte-verified but the body has never been disassembled; the prior "lives outside the carve" conclusion shows the wrong-overlay signature (gotcha 3) and is probably wrong. CarveN500Mand every dependency recursively, down to the 3022 bus registers. External decode ofND-500-MON:PROG(REPORTED) found exactly ONEMON 60site and zeroIOXT— so SINTRAN owns the bus registers and this is the only door. See ND-500 doc section 3a. - ND-500 -> ND-100 = the level-12 / 5MPM path. Items 1-7 below.
Close these, in order:
- Disassemble the never-touched ND-500 segments.
030-S3SM5(has.asm, verify it),062-S3SSM5,046-S3S5PIT,050-S3I5PIT,020-S3SDT5,021-S3NMS5, plus025-S3IRPIT/026-S3IMPIT. Promote each intore/segments-ref/<seg>/with.asm+.symbols.txt+.meta.md. - Byte-locate the level-12 GOSW table. This is the #1 gap — it turns every 5xx link from
NPL-guess into byte-fact. Validate it against known slots before trusting it (gotcha 6):
index 0 must be
STAPR=140356B, index 1NSTOP=140511B, index 11DVIO=141027B. - Byte-locate
5STDRIV,CHN5STATUS,DECOMESS,MCHANDEL. NPL citesMP-P2-N500.NPL:659, 730-759, 803-818, 1251-1406for logic — bytes are authority. - Recover the 5MPM message-block layout from bytes: offsets of
MCNO,SMCNO,FUNCV,KFLIP,NUMPA,N5STA. Known already:STOPR@000011B,TRAPN@000016B. - Recover the real status-code values (
MSGN500,WAITING,ANSWER,5ERANSWER) from the compare instructions inCHN5STATUS. The 0..4 manual hint is unverified — prove or kill it. - Recover the return path
MONICO(NPLCC-P2-N500.NPL:363-372: writeFUNCV,KFLIP,MICFU=3MONCO, statusMSGN500,PSTAT=5ACTIVE,XACTRDY,LCON5=5) from bytes. - Then fix the emulator: remove the fabricated TAG protocol from
NDBusND500IF.cs(section 1.4) and implement the byte-verified handshake. Write the interface spec doc as the deliverable.
4b. PHASE 2 — ND-500-touching cleanup only (agreed scope)¶
- Rewrite the Dispatch sections of the ND-500 call folders onto the corrected model / real GOSW.
- Finish the partially-decoded bodies:
264B,265B,266B,416B,420B. - Locate the 436B/437B servicing point (byte-proven absent from S3SM5; the
GOTABhits are coincidental device-table indices). - Reconcile
ND500-MONITOR-CALL-MECHANISM.mdagainstND500-L-RELEASE-RE-TASK-HANDOFF.md— they disagree on whether the MICFU values are known. - Audit the ND-500 table in the full index: give it a real worker/segment/status column, and delete the unsupported "always byte-verified" prose.
4c. DEFERRED (explicitly not now)¶
- The 87 stale-dispatch ND-100 folders; the 34
WORKER CHANGEDfolders; the 94 missing folders. - Promote
003-S3CP+044-S3IDPITintosegments-ref/(unblocks resident-worker rows). - Disassemble
MOINF(032600B) and confirm from bytes that it readsMCTAB[N](currently INFERRED; this is what the NC oracle promises other teams). - Audit the 5 folders whose MON numbers are absent from MCTAB (
155B,175B,176B,177B,324B). - Task #13 — Phase 2 deep ND-500 monitor disassembly (
S3SM5param contracts,S3SSM5/M06). - Task #27 — carve user-selected MON groups (file-system, directory, disk-io, octobus/graphics).
- Task #29 — find what creates the SCSI last-block layout (create-directory / format writer).
- Recover real L bytes for folders currently backed only by NPL-source
.ASM. - RE the ND-500 bus / Octobus hardware interface.
- RE the SCSI / floppy / CD-ROM drivers —
NPL-SOURCE\NPL\IP-P2-SCSI-DISK.NPL,IP-P2-SCSI-DRIV.NPL,IP-P2-DISK-START.NPL. - RE SINTRAN III filesystem internals — existing output
SINTRAN/Filesystem/. - Housekeeping: stale
S3SM5disassembly prompt; commit carver/tool work; commit thend500-disfix.
4d. Open ND-500 questions (from ND500-L-RELEASE-RE-TASK-HANDOFF.md)¶
- Q2 (highest value, = 4a.5) — message status code values.
- Q3 — the USER side of the monitor-to-driver interface: which MON calls the background monitor
issues, with which parameter blocks. The
:PROGside is undocumented. - Q6 — does
ND-500-MON:PROGever IOX the 3022 directly, or is register access confined to resident SINTRAN? (spec predicts the latter) — unconfirmed. - Q1 (211305 floppy contents) · Q4 (
SWAPPER-K:PSEG/DSEG— first real ND-500-side code) · Q5 (segment capability word; contradiction C9: 11-bit vs 12-bit segment field) · Q7 (microcode image — artifact NOT FOUND onF:\ND).
5. Tooling¶
nd100-dis lives in WSL (/usr/local/bin/nd100-dis) and takes little-endian input.
python3 is WSL-only; on Windows use python.exe. The Bash tool in Claude Code is Git Bash,
not WSL — /mnt/e paths do NOT resolve there. Use PowerShell with E:\... paths, or invoke
wsl explicitly.
# disassemble segment SEG (octal load base L, decimal Ld) around [lo..hi]
python3 -c "d=bytearray(open('SEG.bin','rb').read());d[0::2],d[1::2]=d[1::2],d[0::2];open('/tmp/x.le','wb').write(d)"
nd100-dis -a -o -b Ld /tmp/x.le | awk '$1>=lo && $1<=hi'
Instruction-semantics ground truth: the nd100x emulator (~/repos/nd100x), nd500x (~/repos/nd500x),
and Ghidra SLEIGH (E:\Dev\Ronny\ghidra-nd100).
6. MAINTENANCE RULE — how to keep this document true¶
This document is the status of record. Update it IN THE SAME change as the analysis work.
Update it whenever any of these happen:
| Trigger | What to update here |
|---|---|
| A MON call is analysed / rebuilt / corrected | The counts in section 1.1; move the call out of NO FOLDER / WORKER CHANGED; if it is an ND-500 call, update section 1.3 |
A segment is disassembled or promoted to segments-ref/ |
Section 1.2 — the "only 4 disassembled" statement and the not-yet-promoted list |
| NPL code is analysed | Note it where it is used as evidence, and re-mark any claim it upgrades or contradicts. NPL never makes anything VERIFIED (gotcha 2) |
| A table / address / offset is byte-proven | Section 1.3 (ND-500) or 3a (ND-100); add known-slot values to gotcha 6 |
| A claim is disproven | Delete it and say so. Do not leave it hedged. Section 1.4 is the model for recording a poisoned prior |
| A phase-1 item lands | Tick it in 4a and move the next item up |
Rules for edits:
- Never upgrade a status without checking bytes yourself. VERIFIED means "I read the bytes".
- Counts must come from the full index (E:\...\versions\L-VSX-500\re\MON-CALL-INDEX.md), not
from the D: delivery mirror (section 1a).
- When this document and a per-call folder disagree, this document names the winner explicitly —
it does not leave both standing.
- Keep the honest counts. A number that flatters the effort is worse than no number.
Owner note: the live SCSI-mount investigation (effort B) is at a good stopping point documented in
SINTRAN/Devices/SCSI/mount-gate-diff.md and
SINTRAN/Devices/SCSI/scsi-open-last-block-read.md; it does not depend on the
carving thread except for the create-directory writer (task #29).