Skip to main content

computist scan 35

  • PublicationApple Periodicals
  • Pages36
  • Sourcecomputist-scan-35.pdf
← Magazines computist scan 35
/ 36
Source: Internet Archive — Aggregated Apple-era periodicals, 1981–2012.
Page 1
Loading…
Text content (OCR)
Softkeys For: Hi-res Cribbage Olympic Decathlon F-15 Strike Eagle Masquerade The Hobbit Pooyan The Peffect Score The Money Manager Core: Installing a CPS Clock Driver Feature: Putting a new F8 on your Language Card USA $3.75 Canada/Mexico $7.00 All Others $13.25 (Page 26) COMPUTIST PO Box 110846-T Tacoma, WA 98411 Many of the articles publi ed in COMPUTIST detail the removal of copy protection schemes from commercial disks or contain information on copy protection and backup methods in general. We also print bit copy parameters, tips for adventure games, advanced playing techniques (APT’s) for arcade game fanatics and any other information which may be of use to the serious Apple user. COMPUTIST also contains a special CORE ses protection. Topics may include, but are not limited to: tutorials, hardware/software y programs. related to coy product reviews and application and ut ion which focuses on information not directly What Is A Softkey Anyway? Softkey is « term Which we coined to describe a procedure that removes. or at least circumvents, any copy protection on a particular disk. Once a softkey procedure has been performed, the resulting disk can usually be copied by the use of Apple's COPYA program (on the DOS 3.3 System Master Disk), Commands And Controls: In any article appearing in COMPUTIST, commands which a reader is required to perform are set apart from normal text by being indented and bold. An example is: PRIG Follow this with the RETURN key. The RETURN key must he pressed at the end of every such command unless otherwise specified. Control characters are ficated by being boxed. An ‘To complete this command, you must first type the number 6 and then place one finger on the CTRL key and one finger on the P key Requirements: Most of the programs and softkeys which appear in COMPUTIST requir the Apple I| series of computers and at least one disk drive with DOS 3.3, Occasionally, some programs and procedures have special requirements, ‘The prerequisites for deprotection techniques or programs will always be fisted at the beginning of the article under the **Requirements:"* heading Software Recommendations: The following pro- grams (or similar ones) are strongly recommended for readers who wish to obtain the most benefit from our articles: 1) Applesoft Program Editor such as Global Program Line Editor (GPLE) 2) Sector Editor such as DiskEdit, ZAP from Bag of Tricks or Tricky Dick from The CIA 3) Disk Search Utitity such as The Inspector. The Tracer from The CIA or The CORE Disk Searcher. 4) Assembler such as the S-C Assembler or Merlin/Big 5) yy Program suct as Copy |f Plus, Locksmith sential Data Duplicator 6) ible of producing normal sequential uch as Applewriter J[. Magic Window || or Screenwriter | You will also find COPYA, FID and MUFFIN from the DOS 3.3 System Master Disk useful Super LOB: This program has most recently appeared in COMPUTIST No. 32. Several softkey procedures will make use of a Super [OB controller, a small program that must be keyed into the middle of Super OB. The controller changes Super IB so that it can copy different disks. To get the latest version of this program, you may order COMPUTIST No. 32 as a back issue or order Program Library Disk No. 32 RESET Into The Monitor: Some softkey pro- ‘cedures require that the user be able to enter the Apple’s system monitor during the execution of a copy protected program. Check the following list to see what hardware you will need to obtain this ability. Apple |I Plus - Apple //e - Apple compatibles: |) Place an Integer BASIC ROM card in one of the Apple slots. 2) Use @ non-maskable interrupt (NMI) card such as Replay or Wildcard. Apple jf Plus - Apple compatibles: |) Install an F8 ROM with a modified RESET vector on the computer's motherboard us detailed in the “Modified ROMs” article of COMPUTIST No. 6 or the “Dual ROM’s™ article in COMPUTIST No. 19. Apple //e - Apple //c: Install a modified CD ROM on the computer's motherboard. Clay Harrell’s company (Cutting Bdge Ent.; Box 43234 Ren Cen Station-HC, Detroit, MI. 48243) sells a hardware device that will give you this ability. Making this modification to an Apple //c will void its warranty but the increased ability to remove copy protection may justify it Recommended Literature: The Apple }{ Reference Manual and DOS 3.3 manual are musts for any serious Apple user. Other helpful books include: Beneath Apple DOS, Don Worth and Pieter Lechner, Quality Software $19.95: mbly Language For The Applesoft Programmer, Roy Meyers and C.W. Finley, Addison Wesley. $16.95: and What's Where In The Apple William Lubert, Micro Ink., $24.95 Keying In Applesoft Programs: BASIC programs are printed in COMPUTIST in a format that is designed to minimize errors for readers who key in these programs. ‘To.understand this format, you must first understand the formatted LIST feature of Applesoft An illustration If you strike these k 10 HOME:REMCLEAR SCREEN a program will be stored in the computer's memory Strangely, this program will nor have a LIST that is exactly as you typed it. Instead, the LIST will look like this: 10 HOME : REM CLEAR SCR Programs don’t usually LIST the same as they were Keyed in because Applesoft inserts spaces into a program listing before and after every command word or mathematical operator. These spaces usually don't pose a problem except in line numbers which contain REM of DATA command words, The space inserted after these command words can be misleading. For example. if you want a program {0 ke this: 10 DATA 67,45,54,52 you would have to omit the space directly after the DATA ‘command word. If you were to key in the space directly after the DATA command word, the LIST of the program would look like this: 18 DATA 67,45,54,52 This LIST is different from the LIST you wanted. The number of spaces you key after DATA and REM command words is very important All of this brings us to the COMPUTIST LISTing format. In a BASIC LISTing. there are two types of spaces: spaces that don’t matter whether they are keyed oF not and spaces that must be keyed. Spaces that must. be keyed in are printed as delta characters (4). All other spaces in a COMPUTIST BASIC listing are put there for easier reading and it doesn’t matter whether you type them or not ‘There is one exception: If you want your checksums (See “Computing Checksums™ section) to match up. you ‘must not key in any spaces after a DATA command word unless they are marked by delta characters. Keying In Hexdumps: Machine language programs are printed in COMPUTIST as both source code and hexdumps. Only one of these formats need be keyed in to get a machine language program. Hexdumps are the shortest and easiest format to type in To key in hexdumps. you must first enter the monitor; CALL -151 Now key in the hexdump exactly as it appears in the magazine ignoring the four-digit checksum at the end of each line (a "°S" and four digits). If you hear a beep, ave a list you will know that you have typed something incorrectly and must retype that line When finished, return to BASIC with a E003 aber to BSAVE the program with the correct address and length parameters as given in Keying In Source Code the source cole portion of a machine language program is provided only to better explain the program's operation. Lf you wish to key it in, you will need an assembler. The S-C Assembler is used to ger all source code printed in COMPUTIST. Without this assembler. you will have to translate pieces of the source code into something your assembler will understand, A lable of $-C Assembler directives just lor this purpose was printed in COMPUTIST No. 17, To translate source code, you will need to understand the directives of your assembler and convert the directives used in the source code listing to similar directives used by your assembler Computing Checksums Checksums are four digit hexadecimal numbers which verity whether or not you keyed a program exactly as it was printed in COMPUTIST, There are two types of checksums: one created by the CHECKBIN program (for machine language programs) and the other created by the CHECKSOFT program (for BASIC programs), Both programs appeured in COMPUTIST No. | and The Best of Hardcore Computing. An update to CHECKSOFT appeared in COMPUTIST No. 18. Ifthe checksums these programs create on your computer match the checksums accompanying the program in the magazine, then you keyed in the program correctly. If not, the program is incorrect at the line where the first checksuin differs 1) To compute CHECKSOFT checksums: Get the checksums with & ‘And correct the program where the 2) To compute CHECKBIN checksums: CALL -151 BLOAD filename Install CHECKBIN at an out of the way place BRUN CHECKBIN, AS6000 4 the checksums by typing the starting address, riod and ending address of the file followed by xxn.axn JY] And correct the lines at which the checksums differ hecksums differ. Coping with COMPUTIST Welcome to COMPUTIST, a publication devoted to the serious user of Apple J[ and Apple J[ compatible computers. Our magazine contains information you are not likely to find in any of the other major journals dedicated to the Apple market. Our editorial policy is that we do NOT condone software piracy, but we do believe that honest users are entitled to backup commercial disks they have purchased. In addition to the security of a backup disk, the removal of copy protection gives the user the option of modifying application programs to meet his or her needs. New readers are advised to read this page carefully to avoid frustration when attempting to follow a softkey or when entering the programs printed in this issue, Ss... CO. ae Suggested Customer Total Title Publisher Retail Cost QTY Cost Recommended Literature: C1 Beneath Apple DOS (Book) Quality Software $19.95 $16.00 as C) Beneath Apple ProDOS (Book) Quality Software $19.95 $16.00 (] Disk Edit (Book of Softkeys vol 1) SoftKey $12.95 nad = Recommended Software: O Global Program Line Editor Beagle Bros $49.95 $35.25 “== (1 Super IOB (Issue No. 32 w/disk) SoftKey $10:95 “2 (Magic Window // (specify ]| or //e)Artsci $149.95 $106.00 ___ C1 Bag of Tricks II Quality Software $49.95 boo ae Miscellaneous Bargains O Dazzle Draw Broderbund $59.95 $47.50 ___ O F-15 Strike Eagle Microprose $34.95 $28.00 __ {] The Print Shop Broderbund $49.95 S875 SS te | Flight Simulator II Sublogic $49.95 $44.00 ____ (Night Mission Pinball Sublogic $34.95 930) 5 —— O) Exodus Ultima I Origin Systems $59.95 ick ee O Hitchhiker’s Guide to the Galaxy Infocom $39.95 $31.00 ___ O Witness Infocom $39.95 Oo ree 0 Dino Eggs Microlab $40.00 $20.00 ___ {) Zork IIL Infocom $44.95 $35.00 ___ Subtotal Shipping* Total “Domestic Shipping and Handling: $2.00 per item. Five or more items FREE. Name. == ID# Address City State Zip Country Phone xz @ - - - Exp. Signature CP35 To order, complete order form and mail to: COMPUTIST PO Box 110937-SOS Tacoma, WA 98411 Offer good while supplies last. Washington residents add 7.8% sales tax. Foreign orders inquire as to appropriate shipping and handling fees. Limited offer, expires December 31, 1986. FREE COMPUTIST YES! You Get 2 FREE ISSUES for every NEW subscriber that you sign up. We'll extend your current subscription by 2 issues for every new paid subscription you get to fill out the subscriber forms below. first Class subscribers MUST recruit First Class subscriptions to receive the 2 extra issues. This rule (same mailing class) also applies to Foreign rates. Standard US subscribers can recruit any new subscriptions and extend their standard subscriptions. US funds drawn on US bank. Send check/money order to: +COMPUTIST PO Box 110846-T Tacoma, WA 98411 BUT...F CURRENT SUBSCRIBER CURRENT SUBSCRIBER Add two issues to this subscription, D Add two issues to this subscription, Renew my subscription. Payment is enclosed Renew my subscription. Payment is enclosed, US: $20° US First Class: $24 © Can/Mex: $34 © Other Foreign: $60 OD US: $20 US First Class: $24 Can/Mex: $34 J Other Foreign: $60 Name, D4. Name = 1Db 4 Address Address a City State. Zip. City ‘State Zip. bees es Country Phone Country Phone Bp. ze J exp Signature uu — CP3S ‘Signature CPS If you let your subscription expire, you are considered a NEW subscriber If you let your subscription expire, you are considered a NEW subscriber and are NOT eligible for the free issues and are NOT eligible for the free issues NEW SUBSCRIBER NEW SUBSCRIBER Yes, I want to subscribe to your fine publication. Yes, I want to subscribe to your fine publication. CUS: $20 US First Class: $24 © Can/Mex: $34 (1) Other Foreign: $60 (DUS: $20 US First Class: $24] Can/Mex: $34 {11 Other Foreign: $60 Name Name ‘Addreas__—__— Address, City. State, py City. z State, Zip. Country = Phone Country Phone Exp. — Exp. Signature. cPas Signature == P35 Attention COMPUTIST Collectors The following back issues are practically gone. Once they have sold-out, they will no longer be available in magazine form to our readers. DLA softkeys | sensible Spetier | Exodus: Ultima III | Readers’ Softkeys | SoftPorn Adventure | The Einstein Compiler v5.3 | Mask of The Sun | Features | Copy ][ Plus (4.4C): Update Of An Old Friend | Parameter List For Essential Data ix Duptoaor l¢ Core il Ultimaker III | The Mapping of Ultima III | Ultima Il... The Rest Of The Picture | .. NORA, ie i, ill eco oe ORS DLS sofikeys | Laf Pak | Beyond Castle Wolfenstein | Transylvania | The Quest | Electronic Arts | Snooper Troops (Case 2) | DLM Software | Learning With Leeper | TellStar | Core | CSaver: The Advanced Way to Store Super IOB Controllers | Adding New Commands to DOS 3.3 | Fixing ProDOS 1.0.1 BSAVE Bug | Review | Enhancing Your ‘Apple IF Feature e|L Locksmith 5.0 and Locksmith Programming Langues | ZB’ Sofikeys | Choplifter | Mufplot | Flashcale | Karateka | Newsroom | E-Z Draw | Readers’ Softkeys | Gato | Dino Eggs | Pinball Construction Set | TAC | The Print Shop: Graphics Library DO Death In The Caribbean | Features | Using A.R.D. To esonkey Mars Cars | How To Be The Writemaster | Core | Wheel Of Money | ..........:-::ssssssessseesssseessserseseesssensneeess First Come, first served. Some issues may be slightly damaged. No reservations allowed, prepayment only with 2@®. To order, phone (206) 474-6750 or use the order form on page 31. For phone orders, please have subscriber ID number and ship-to address ready. Normal back issue rates apply to foreign orders. Washington State residents add 7.8% sales tax. This month's caver: Graphics front Penguli’s “Sword of Kuudash. Address all advertising inquiries to COMPUTIST, Advertising Department, PO Box 110816, Tacoma. WA 98411, Mail manuscripts to COMPUTIST, PO Box 110846-K, Tacoma, WA eat) ved, Copying dane for athar than personal or internal (without express written permission from the publisher pronibited The editorial statt assumes no liability or responsibility for the products advertised in the magazine. Any opinions expressed by the authors are not necessarily those of COMPUTIST magazine or SottKey Publishing Apple usually reters to an Apple || computer ands a trademark of Apple Computers, Inc SUBSCRIPTIONS: Mates (or 6 issues): U.S. $20, US. tet Class $24, Canada & Mexico $34, Foreign $60. Direct inquiries lo: COMPUTIST, Subscription Department, PO Box 08461, Tacoma, WA 98411, Please include address label with correspondence DOMESTIC DEALER RATES: Call (208) 474-5750 for more information Change Ot Address: Please allow 4 address to take effect. On postal | address and your most recent addr fo non-receipt of regular back issue ri COM PUTIST Managing Editor: Ruy Darrah Circulation: Debbie Holl Unc.. Seattle, WA COMPUTIST ¥ softkeys: 10 Hi-res Cribbage by William Hinger 12 Olympic Decathlon by Mare Lirette 14 Revisiting F-15 Strike Eagle by Jim Wallace 24 Masquerade by Steve and Rod Smith 28 The Hobbit by J. J. Gifford feature: 20 Putting a New F8 on Your Language Card If you'd rather not modify your motherboard to put an EPROM containing your own F8 then you can follow this procedure utilizing your language card. by Ken Burnell core: 16 Exploring ProDOS by installing a CPS Clock Driver Using this article, you can make your CPS multifunction card automatically stamp the time and date on every file you SAVE. by Paul Blumstein review: 22 The Senior PROM by Rober Knowles APT: 26 Sword of Kadash by John Della Pia departments: 4 Input 6 Most Wanted List 7 Readers’ Softkey & Copy Exchange Datasoft's Pooyan by Kevin Sartorelli, Mindscape’s The Perfes Windham Classics’ Alice in Wonderland by Charles Taylor Manager by P. J. Thompson, Hotfman Educational’s Good Sir Tech's Rescue Raiders hy Steve and Rod Sinith Score by PJ. Thompson erling Swift's The Money inking by P.J. Thompson Please address letters to: COMPUTIST Editorial Department PO Box 110846-K Tacoma, WA 98411 Include your name, address and phone number. Correspondence appearing in the INPUT section may be edited for clarity and space requirements. In addition, because of the great number of letters that we receive and the small size of our staff, a response to each letter is not guaranteed. Our technical staff is available for phone calls between 1:30 pm and 4:30 pm (PST) on Tuesdays and Thursdays only. Another Halley Project The softkey for the Halley Project you presented a few issues ago didn’t work when I tried it, but fortunately 1 was able to find a hew one that worked on my copy. RUN COPYA Press Reset when the slot and drive questions appear. Now type CALL -151 8 60 199 POKE 47426,24 249 POKE 47426,56 259 POKE 47426,56 RUN When finished, run your favorite disk editor and change track $11. sector $0, byte $9A to $1D (as in previous softkey). Done! Also, for those of you who love to mess. around with programs, the initial hi-res picture runs from track $@D, sector $0F through all of sectors SOE and SOF. Unfortunately, this picture is loaded in a very odd way. In even groups of eight lines, the two sets of four are switched! Fortunately, after a bit of sweating. I came up with a routine to fix it, Since the process is fairly simple, the routine is like a toggle. If you run it twice. it will return to ils original format. Hard to explain. Just try it. Converts page 2 ($4000) picture to new format on page | ($2000). 6000:A0 00 84 06 84 08 AD 40 6008:EA EA EA EA 85 07 B2 06 G010:AA AS 07 38 E9 40 EA EA 6018:C9 10 BO 05 18 69 30 90 6020.03 18 69 10 85 09 84 08 6028:8A 92 08 CO 00 DO 05 AS 6030:07 C9 60 DO 01 60 1) First, use-a Super 1OB controle: tracks D, E, and F onto a normally ini disk. 2) Then (this is the tricky part) build a TS list for this hi-res screen just like DOS would: increasing sectors, decreasing tracks. Also, make a catalog entry. Consult Beneath Apple Dos tor details. 3) Now make and save your own sercen on the same disk under the same name. This will insure that it falls on the same track. 4) Since DOS inserts 4 bytes at the beginning of each file, move the entire file ($2000-$3FFF) left 4 bytes. 5) Now mess it up with the subroutine above and save it again 6) Copy it back to the working copy. 7) Using your finest optic abilities (or the little scrap of paper that has the top 4 bytes of the picture), reconstruct these 4 bytes and place them on track SF. sector SF, using your favorite sector editor. (Note: it’s usually easier to do this if you intentionally leave the 8th line from the top blank because all you have to do then is just zero those bytes.) P.S. Those NOP’s don’t mean a thing. I was. revising the code and I didn’t want to recalculate all the relative branches. Also. this code is heavily 65C@2 dependent. John Clements San Francisco, CA Copy ][ Plus 6.0 on a Franklin I recently bought a copy of COPY JI Plus Version 6. I have a Franklin Ace 1000 and could not boot this program. I had to modify the code in order to run it. Here’s how to get ProDOS Version 1.1.1 or 1.0.1 running on your Franklin Ace 1000 or 1200: 1) Boot the ProDOS system disk. You will see a title screen with Apple’y copyright notice 4 COMPUTIST No. 35 2) When the system locks up, press the Reset key. You will jump into the monitor and see the prompt (#). 3) To start the drive and boot the disk under Version 1.1.1. type: 269E:EA EA 2000G 4) Under Version 1.0.1, type: 265B:EA EA 2000G You can make a permanent patch to Version 1.1.1 by typing: BLOAD PRODOS,A$2000,TSYS CALL -151 269E:EA EA BSAVE PRODOS,A$2000,L$3A00,TSYS Thope this helps some of you Franklin Users, Larry Altuna Staten Island. NY Another Blazing Paddles Was I happy when I received COMPUTIST No. 31. and saw a softkey for Blazing Paddles, thinking I would finally get a good backup, Well guess what happened... that’s right, I have a different version from the one you published However, by using the information from Frank Carone’s article and making some educated guesses, T was able to make a COPYA disk. Here’s the procedure. 1) Copy the disk with COPYA. 2) Use your favorite sector editor to change: TRACK SECTOR BYTE FROM TO 3) Write the change to the disk and you're done! You have a great magazine good work! keep up the Steve Rodgers Libby. MT Dollars and Sense Here’s a softkey for Dollars and Sense by Monogram. 1) Copy the disk with COPYA 2) Run a sector editor and go to track $0, sector $5. Enter the following values starting at byte $8c. EA A5 02 38 £9 40 85 04 A5 03 £9 00 85 05 AQ 3F Bl 04 91 02 88 10 F9 3) That's it. Dan Agnew Fairport, NY ProntoDOS Procedure ['m grateful to Tom Weishaar for putting the 65C02/ProntoDOS issue to bed and for letting us know about his newsletter (my check’s in the mail). T have a friend who read about the alleged incompatability of ProntoDOS and his new 65C02 and held off installing the chip - until [told him that there was no problem! Of course. it works fine. And speaking of my favorite “fast DOS”’, ProntoDOS - in COMPUTIST No. 30, you published a nice article by Phil Goetz, Increasing Your Disk Capacity, In the article, Phil told of a procedure to capture fifteen sectors from track two of a DOS 3.3 disk that might seem slightly messy for a beginner. There is a much easier way to do this if you want to use ProntoDOS, Since ProntoDOS only uses tracks zero, one and sector zero of track two, it is a natural to copy right onto a disk that has been INITed for thirty five tracks. Using this procedure would eliminate the need for step 2 in Phil’s article. The procedure would be done after the new disk was INITed in step 5 and would read as follows: 6) Use Copy | Plus to copy ProntoDOS to the new disk. Or use any bit-copy program copying only tracks 0-3. The patch in step 3 of the article covers patching the VTOC to show that only sector zero on track two is in use (bytes 40 and 41 on track $11 sector $00 are changed from their normal values of $00 00 [no sectors free] to SFF FE [only sector zero in usel) Anyone can have a disk with only the extra fifteen sectors on track two freed up by INITing a disk with ProntoDOS thusly: 1) Boot a disk with ProntoDOS installed on it 2) Reset the computer to get the Applesoft prompt. 3) Put a blank disk in drive 1 and type INITHELLO to INIT the disk with a program called HELLO, Note the space after INIT and HELLO was purposely left out as it’s optional! And that isn't in any Apple Company publication that I've ever read! Another hint when using ProntoDOS - a lot of people run into the problem of looking at the Boot Program Name using COPY J[ Plus. Well, you won't see il, and you get the message, “*NO- BOOT PROGRAM TO CHANGE” because the Boot Program is not in the usual DOS 3.3 spot on track SI. sector $9 at byte $75 ProntoDOS stores its boot program name at track 1. sector 7, byte $75 Jf you want to change the Boot Program Name, you've got two choices. Use a sector editor to change the name. Or. INIT a new disk with ProntoDOS using the desired name instead of HELLO, and copy over all your files from the old disk to the new one. Finally, what do you do if the desired Boot Program isn’t an Applesoft program but a binary program or a file you want to EXEC? Simple. according to Beneath Apple DOS, page 7-3, the byte at $S9E42 in a 48K DOS 3.3 should be 06. 34 or 14 for Applesoft/Integer, binary or EXEC files respectively. This byte is found on the DOS 3.3 disk on track 0, sector SOD, byte $42 and on the ProntoDOS disk two sectors behind that at track 0, sector SOB. byte $42. PLEASE publish more COMPUTIST! Khalid Abu Kabbous Kingdom of Saudi Arabia About Rescue Raiders First, Lam very glad there is a magazine for upple users like COMPUTIST. It is the only computer magazine I find worth subscribing to and the only magazine I find myself always anxious to receive in the mail. Keep up the good work. Next, though I’m not much of a hacker, I find I can easily type in codes from your magazine, Here are a few questions that I have. On page 6 of COMPUTIST No. 16, it mentions that to access the cheat mode on Rescue Raiders, you have to type in POPPY. It also mentions that different versions of the game might require different passwords. (On page 4 of COMPUTIST No. 26 it lists the password as ZIPPY). In issue 16, it also says that to find the password for your version of the game, look on track $OF, sector $9, bytes $A8 to $AC and read backwards, My friend and I both own copies of the game and when we read bytes $A8 to SAC on our disks we both get different garbage, though we both do have BOBBY PIN spelled backwards at bytes $70 to $77. But for both of our disks, when we typed the password in, none of the cheat features would work, The cheat features would only work if the disk was deprotected with the method used in issue 16, Then the cheat mode worked fine, but whenever you wanted to fire bullets to the right, the bullets would be pulled up into the air instead of coming down. Does any reader out there know how to fix this problem with their deprotected copy? Also, I have a copy of Graphics Expander by Springboard that I cannot backup properly. Tried your softkey for Newsroom on page 18 of COMPUTIST No. 23 on it and the program seems to run fine (even the Newsroom demo on it works) until after it checks to see if there's adisk in drive 2. Then the program just reboots. Finally, | have four games for the Apple made by Atarisoft. Galaxian, Jungle Hunt, Gremlins, and Centipede. I’ve tried everything to copy them but nothing seems to work. Any suggestions? Besides that, all the other softkeys I've tried from your magazine work. Again, keep up the good work!!! A Khan Canada Mr Kahn: Most Atarisofi sofiware can be copied by typing: B942:18 and RUNning COPYA. Silent Service Stuff 1 would like to see Silent Service by Microprose on your Most Wanted List, as it seems to be impossible to backup with EDD, Copy Jf Plus or Locksmith, or any other program I have a to. [tried to deprotect it by making a copy with EDD TQ-T23 and using a sector editor to change bytes starting with CA: from 20 3A DB to EA EA EA 60 on tracks 4 and 5 and sector 9 (both tracks) with partial success. This eliminated the message HARDWARE FAILURE but the message YOU HAVE RUN COMPUTIST No, 35 5 INTO AN ENEMY MINE invariably occu after about 5. to 1@ minutes of play. I have never received this message while using the original disk It is casy to tell if you are going to get the ENEMY MINE message while the program is louding, (after selecting the level), as it loads with an audible track change My manual is marked Change 1, 15 Sept 85 The same us in your article on page 4 of COMPU No. 30. The method by Mr Lemme does not work on my copy, or perhaps he did not use the copy long enough for the ENEMY MINE message to occur. I consider your publication the best Apple magazine on the market, with Nibble running second and inCider in third place, and I look forward to cach issue of COMPUTIST. Sheldon M. Atterbury Sierre Madre, CA Apple Only? Since no one seems to be arguing against retaining COMPUTIST as an Apple only magazine. I thought | would try and give a bit of an argument for the other side. My suggestion is that the magazine should be devoted to hackers (in the original sense of computer aficionados rather than vandals) and to open architecture computers. At the present time then this would mean that the magazine would be devoted mostly to Apple with small sections devoted to the IBM PC and clones and perhaps the Am Don't get me wrong, I like the Apple, and it will be around for a long time. But. nothing lasts forever, The Model T Ford was once the automotive equivalent of the Apple; however a magazine presently devoted to Model T Fords would haye relatively limited circulation. People who are seriously interested in computers will naturally progress towards machines that have 16 or 32 bit processors that can access a lot of memory quickly. Tam convinced that before long we will have computers with gigabytes of memory both on optical dises and in RAM that will permit an explosion of innovative programming that will make today’s programs seem childish by comparison. I don’t believe that Apple will be part of this explosion. There is one further consideration. The Apple market is presently saturated with relatively good programs considering the limitations of the Apples slow processor and small amount of memory However, the market for IBM PC programs presently wide open, Anyone who uses a PC knows that there is a tremendous market out there for innovative games that aren't merely re-written from other comuters, and especially for utilities. The utilities presently available for the PC are few in number, greatly overpriced, difficult to use and come with documentation which is verbose. confusing and incomplete. T might add that there is also a terrific market out there for people who crack IBM programs so that, for instance, they may be installed on a hard disk. (Jeff (my brother) tells me that most IBM programs are pretty easy to crack.) If the magazine were expanded by one double page for the IBM and otherwise remain the same size, I think that the interests of the die- hard Apple fanatics could be served as well as the interests of those of us who wish to move on to more powerful machines. David W. Rivet Canada About Autoduel This is probably a rather strange letter. It's a partial softkey for Autoduel by Origin tems. The softkey for Autoduel is very to the Ultima IV softkey by Mike si Roetman in COMPUTIST No. 28. Autoduel performs fine when you use this softkey except for when you wish to go to the Arena feature in the game. The disk just whirls on doing nothing. Maybe you or some other readers can solve this problem. 1) INITialize a disk with: INIT HELLO 2) Run Super [OB v1.5 with the Ultima IV controller in COMPUTIST No. 28. 3) type in this program. 18 PRINT CHRS(4) “BRUN BOAT” 4) Save this as your hello program on copy of Autoduel. SAVE HELLO 5) Make the following change to file called “gal P™ BLOAD SOAP CALL -151 1IAL:EA EA EA 11LAG:EA EA EA 11B8:B7 1IBA:E8 BSAVE SCA) P,A$800,L$C00 Dan Agnew Fairport, NY 6 COMPUTIST No. 35 Most Wanted t Lis Need help backing-up a particularly stubborn program? Send us the name of the program and its manufacturer and we'll add it to our Most Wanted List, a column (updated each issue) which helps to keep COMPUTIST readers informed of the programs for which softkeys are MOST needed. Send your requests to COMPUTIST Wanted List PO Box 110846-K Tacoma, WA 98411 If you know how to deprotect unlock, or modify any of the programs below, let us know. You'll be helping your fellow COMPUTIST readers and earning MONEY at the same time. Send the information to us in article form on a DOS 3.3 diskette Mouse Cale Apple Computer Apple Businexs Graphies Apple Computer Jane Arkironios Visiblend Microlab Catalyst Quark. Ine Gutenburg Jr. & Sr. Micromation LTD Prime Plotter Primeyott Corp. The Handlers. Silicon Valley Systems The Apple's Core: Parts 1-3) The Professor Fun Bunch Unicorn Willy Byte... Data Trek Cranston Manor Sierra On-Line oggle Broderbund Robot War Muse ABM. Muse Mychess IF) Datumost Story Tree Scholastic Agent U.S. Handicapping System Sports Judge Scholastic Dollars & Sense Monogram Echo Plus Agi Great Cross Country Road Race Activision iat Systmes Raster Blaster Budge Ine Odin Odestu Mabel’s Mantion Datamost Brain Bank The Obseyatory Under Fire Ayalon Hill Crimson Crown Penguin Crypt of Media Sir Tech EDD IV. Utilico Microware readers’ softkey & copy exchange Kevin Sartorelli’s softkey for... Pooyan Datasoft, Inc, 19808 Nordoff Chatsworth, CA 91311 Requirements: A blank disk At least 48K This method requires a RAM card to run the game as the title picture is stored there. If there is no RAM card the game will still run but there will be rubbish instead of the title picture. The softkey is given in a cookbook fashion to save space as the boot code trace is quite long. The first boot stage starts off with an illegal opcode that ignores the first two bytes ($801 and $802). The rest of the boot trace you should be able to follow, should you feel like it, by liberal use of the monitor **L** command 1) Boot a DOS 3.3 disk. Type FP to clear any BASIC program 2) Insert u blank disk in the drive and type INIT HELLO to create a slave disk with a null (empty) greeting program (needed later in the softkey). 3) Ga into the Monitor CALL -151 4) Insert the POOYAN disk into drive one. 5) Move the initial boot code from ROM to RAM. 6600<C600.C6FFM 6) Load the first boot stage from the disk. 66F8:0 60006 7) Turn off the drive. COE8 8) Alter the boot code. 6659:20 66F8:4C 2000<800.8FFM 9) Change where the code is stored. 209D:CA 20A0:A 20B3:0 10) Decode the second boot stage to $SAQ0. 2097G 11) Prepare to use our modified boot code. 12) Modify the boot code to. jump to our routine. A6C:4C 00 B7 13) Modify the next boot stage to jump back to our routine when finished B700:A9 4C 8D DA 64 A9 00 8D DB B709:04 A9 B8 8D DC 04 4C 84 04 14) Add code to save the text page. B800:A0 00 A2 04 BY 00 04 99 B808:00 34 C8 DO F7 EE 06 B8 B810:EE 09 B8 CA DO EE AD 82 B818:C0 4C 59 FF 15) Load in the main game and save the text page. 6600G 16) Turn off the drive again. COES 17) Move some code to a safe place A000<2000.26FFM 18) Clear the screen and HOME the cursor. FCS8G 19) Load in the title picture. 400<3400.37FFM 28:60 819CG 20) Move half the picture to $5000 and the other half up to $3000. 5000<3000.3FFEM 3000<2000.2FFEM 21) Restore the code moved in step 17, and pack other code into unused space. 2000< A000. A6FFM 2700<8D00.95FFM 4500<8A00.8CFFM 22) Type in some code to get the picture from the language card. 819C:AD 8@ C@ A9 E@ 8D AF 81 81A4:A9 20 8D B2 81 A2 20 AO 81AC:00 B9 60 EA 99 00 20 C8 81B4:D0 F7 EE AF 81 EE B2 81 8IBC:CA D@ EE AD 82 C@ AD C4 81C4:CO EE F4 03 60 23) Type in code to move the code to the correct places in memory and put the picture in the RAM card ® AD 81 CO A216 00 30 99 00 EO EE 0C 48 EE oF 4818:48 CA DO EE A2 10 B9 00 4820:50 99 00 F@ C8 DO F7 EE 4828:20 48 EE 23 48 CA Dé EE 4830:AD 82 CO A2 09 BY 06 27 4838:99 00 8D C8 D0 F7 EE 37 4840:48 EE 3A 48 CA DO EE A2 4848:03 B9 00 45 99 00 8A C8 4850:D0 F7 EE 4B 48 EE 4E 48 4858:CA D@ EE AD 57 C@ AD 54 4860;C® AD 52 CO AD 50 CO 4C 4868:00 60 24) Add a jump to our routine CED:4C 00 48 25) Boot the slave disk made at the beginning. BSAVE POOYAN,ASCED,LS7D03 26) Type BRUN POOYAN to play the game. P. J. Thompson’s softkey for... The Perfect Score Mindscape Software P.O. Box 506 Northampton, MA 01601 Requirements: Apple JI COPYA A sector editor Twelve blank disk sides The Perfect Score is a huge program written in the FORTH language for high school students preparing for the SATs. The verbal sections are quite easy while the math is fairly difficult. 1t is reasonably priced and not heavily protected. Although a bit copier cannot copy. it. modification of the protection code will wipe out any problems in backing up the program Here it is step-by-step: 1) Load COPYA and change the RWTS to ignore errors: V COPYA CALL -151 B942:18 3D0G 7 RUN COMPUTIST No. 35 7 readers’ softkey & copy exchange 2) Copy all twelve sides of The Perfect Score This may take a while because the sectors are written in a funny order 3) Start up your sector editor and make this patch on each disk Byte $0 $9 $40 $4 $0 $9 $41 $D4 $ $9 $42 $02 Thut’s all! ‘This skips the protection loaded upon hooting and is used constantly throughout the program. Enjoy this program and hope for a perfect score. ene Charles Taylor revisits... Alice in Wonderland Windham Classics One Kendall Square Cambridge, MA 02139 Requirements: Super IOB v1.5 One blank two-sided disk After reading Allan Migdal's softkey for Alice in Wonderland (COMPUTIST No. 29) I realized that I had a different version. The is that all main difference files are not di! CATALOGable by normal methods. Also, the boot program is HELLO, not STARTUP. Step by Step 1) Install the Super IOB controller below and use it to copy both sides of Alice in Wonderland. The address and data epilogues have been changed from DE AA to FF FF 2) Copy DOS from your DOS 3.3 system f aster to the boot side of the copy of Alice. Use Super IOB to copy tracks 0-2 or use something like Copy II Plus’ “Copy DOS option. That's all! I would like to present two better methods of “BRUNning STARTUP™ than the method used by Mr. Migdal in his softkey 1) Change the “‘hello”” program with Copy II Plus. This automatically makes the DOS changes necessary t0 BRUN programs on booting 2) Or, boot the DOS 3.3 master POKE 40514,52 Then type and INIT a disk with the name of the binary “hello” program. To EXEC a text file as the “hello” program, use POKE 40514,20. controller =WR FAST GOSUB 610 F PEEK HUA nai 8 COMPUTIST No. 35 1040 1K=PEEK (TRK ) :ST =PEEK (SCT ), 1050 HOME : PRINT "COPYDONE” : END 1060 DATA 255 255 255 255 GOTO1020 controller checksums Heed - $3568 ~ $2944 0 - $F372 @ - $A259 P. J. Thompson’s softkey for... The Money Manager| Sterling Swift Publishing Co. 7901 South I-35 Austin, TX 78744 Requirements: Apple J[ computer COPYA or equivalent A sector editor Two blank disks The Money Manager business made for educating the user. Although the copy protection is not extensive, it isn’t eusy to bit copy without parms. It checks for a totally illegal byte between two of the address headers, If we can avoid this routine. the program would be unprotected is 4 simulation’ of 1) Load COPYA or uny other sector copier and copy both disks on to your backup 2) Load up your sector editor and make the following patches to both disks: Track Sector B; $00 $08 $58 = $4C SEA $00 $08 $59 $65 $8D $00 $0B $54 $BC §8C . Thompson’s softkey for... | Good Thinking! Hoffman Educational Systems Requirements: 64K Apple II A sector editor Twelve blank disk sides readers’ softkey & copy exchange Good Thinking! is a new program written in Pascal designed to improve language among young kids. It can be copied normally but upon bootup the copy will not be accepted, After scanning the disk for a BD 8C CO (LDA $C08C,X), which is a common instruction used to read bytes off the disk, I made a small patch which bypasses the protection. This softkey is for Level One programs Here it is step-by-step. 1) Load COPYA or any other full disk copier. 2) Copy all twelve sides of the Good Thinking! disks. If you want to save a little room you can double side your disks 3) Boot up your sector editor 4) On each disk make the following patch at byte $B6 from $4C to $60. This will be done on a different sector for each disk. Here is a list of the disks and the corresponding sector to modify: CAUSE & EFFECT DRAWING CONCLUSIONS PREDICTING OUTCOMES GENERAL | ZATIONS WAIN IDEA TOPIC SENTENCES CLASSIFYING COMPAR | SON ANALOGIES If these sectors do not contain a 4C F8 00 (IMP S0OF8) at byte SB6 then it is the wrong sector. Bither check again or search your disk for a BD 8C C0. Make sure the sector in which you found those bytes are on a track greater than $3 and then do your patch. On the first two tracks these bytes are used constantly for the disk operating system. Hopefully you won't have to go through this mess but the softkey should work either way ee é tii HAHAH HE ann it [HRI Steve and Rod Smith’s patch for... Mockingboard Rescue Raiders Requirements: COPY Aable version of Rescue Raiders Sector Editor Those of you who own Mockingboards may have been a bit frustrated when after following the softkey for Rescue Raiders in COMPUTIST No. 16, When I tried it, 1 found that the program froze at the main screen Well, as it turns out, the program checks for a Mockingboard, but does not do anything with it after it’s found one, except hang. Here is an casy patch to apply to your backup that will eliminate the check and play the game without having to remove your Mockingboard With a sector editor, apply these changes to your backup Track Sector Byte Change to $1 $01 $02 Sco $15 $01 $05 $60 Perret) 1) ere COMPUTIST No. 35 S. Softkey for... i-Res by William Hinger On-Line Systems Req Hi-Res Cribbage A blank disk This game was released in 1980, and at that time there were a few holdouts who were still using DOS 3.2 in their machines. It is not surprising, therefore, that the disk was released in 13-sector format with a special boot sector for DOS 3,3 systems, In fact, the disk has a completely normal DOS, and if you inter the loading process with a CJC), you can catalog the disk and snoop through all the files there. If you load and list the Applesoft file named CRIBBAGE, you will see that it first loads and runs a binary file named HIRES. This file turns on the hi-res graphics and draws the title page. This file is not necessary as itis later completely overwritten when the next file is loaded. A binary file named BCRIBBAGE is then loaded at address $D00 with a length of $7FFF, which means that it extends in memory to $8CFF. (Locations $AA72 and SAA73 in DOS contain the start address of the most recently loaded binary file, and locations $AA60 and $AA61 contain the length of the most recently loaded program or file.) Then a binary file called EXTRA is loaded at $8D00 with a length of $600. They obviously could have made these one file with a simple patch to the save length parameter in DOS (A964:FF lets you BSAVE more than 32K at a time), but they didn’t. The last file loaded is a binary file named IF which is loaded at $300 with a length of SA. 10 After a couple of pokes. this file is called and starts the program. The firs ion in thi file is a JSR $7D64. This routin all memory between $800 and SCFF to zeros. The next instruction, JSR $8700, is the one which prints the menu and executes the program. Now, what we would like to do is save these files as one binary file which we can FID to another disk and execute with a BRUN. This will work as long as we have the original disk in the drive. But if we have transferred the files to another disk with a file transfer utility (such as MUFFIN to transfer the files to a 16 sector disk), the program will try to ac the disk and die a fast death in the middle of the menu. So we need to look a little further. If you look at the routine which starts at $8700, you can see that it repeats a cycle where it sets VTAB and CH and then calls a routine (at $7F27) which prints a line to the screen. This continues until just before it would print menu choice 5. Then instead of a JSR to $7F27, there is a JSR to $8FEQ. This is the protection routine, such as it is. It first does a call to a subroutine at $8FQ@ which unscrambles the code at $9000, calls the code at $9000, rescrambles the code at $9000 with another call to $8F00, and then finally modifies its own code so that the next time the menu is printed, the call to $8FEO encounters a JSR $7F27 and RTS. Examination of the code at $9000 will show that the program first loads track 0, sector @ into page 3 and then track 2, sector C into page 91. Since $9100 is in the middle of the EXTRA file, we can save this with the rest, but we need to make arrangements to save the code at $300 inside of our file. We can do this by moving it to $COO and then writing an entry routine which will reposition this code before calling the program. One more point needs to be addressed here. The menu choices which save a match and continue a previously saved match need to be COMPUTIST No. 35 eliminated. When I chose to update this program, I wanted it to be able to execute under either DOS 3.3 or ProDOS. These routines reud and write sectors directly to disk using direct calls to DOS 3.2 RWTS routines, and since a match is less important to me than just playing the game, I chose to eliminate these routines entirely. This involved changing some of the ASCII in page $80 (memory $8000) so that these choi no longer show up, and then changing the program so that it will not accept these choices. This is where most of the code you will need to enter to unprotect this program Will be placed. T then wrote a short routine which moved the code to page 3, set the graphics display, S4A and $4B in zero page to the values originally set by the Applesoft program, and then jumped to $300 to start the program. After saving the code as a binary file. I tried running it. Voila! When I ran the program, it looked great and ran fine on my old Apple J[. But before considering the task 10 be complete, I usually try it on the kids’ //c also, Good thing I did. The program died. Now the only thing that I could think of that would allow the program to run on my antique, yet would not allow it to run on the new //c would normally involve direct calls to a part of the monitor ROM which was changed during the various incarnations of the Apple JI family. So I traced through about 10 routines to find what I thought I was looking for. The culprit was found at $7ES4 and started with an LDA $E006. This was uscd as an ID byte to determine what flavor of BASIC was resident In my old machine, Applesoft would return $00 and Integer would return $85. Since I do have Applesoft ROMs in the machine, this would return a $00 and all would be fine. But SE006 on the //c would return a $89 and the program would mistake this for Integer BASIC and die Since I would always be running the program ona machine containing Applesoft. I disabled Cribbage the choice by having the routine load $00 into the accumulator instead of loading an ID byte. It now worked fine on both of my machines If by chance you are still using an Apple ][ with the Integer ROMs, you need to skip the step Which changes the code at $7E54. The step by step process follows, so do and enjoy! Step by Step 1) Initialize a blank DOS 3.3 disk with an empty HELLO program NEW INIT HELLO 2) Insert your original Cribbage disk and boot it PRH6 3) When the program has displayed the entire menu and the disk drive has quit spinning, interrupt the program by pressing Reset 4) Enter the monitor: CALL -151 5) Protect page 3 of memory from the boot €00<300.3FFM 6) Now boot the slave disk you created in step 1 6CP) 7) Modify the menu to: delete the SAVE MATCH and CONTINUE MATCH options CALL -I51 8088:CF D0 C5 D2 C1 D4 C9 CE 8090:C7 A@ C9 CE D3 D4 D2 DS 8098:C3 D4 C9 CF CE D3 AO AO 80A0:A0 8D B3 A@ AD AO C5 CE 80A8:C4 AO AO AO AO AO AO AO AO Ad AO AO AO AO AO AO 0 Ad AO AO 8D AQ AO AO AO AO A@ AO AO AO AO AO 80C8:A0 Ad AO A@ AO AO AO AO A@ AO Ad A@ A@ A@ AO 8D @ A® A@ AO AB AM AM 8D 8) Delete the jump to the protection routine 87BA:27 7F 9) Modify the choice subroutine to reflect the new menu: 87C. 4 8 F 87E7:FF 87EE:02 8808:BF 9D. 10) Enter a short startup routine BCO:8D 50 C@ 8D 52 Cé 8D 54 BC8:C@ 8D 57 C@ A9 OC 85 00 BDO:85 1 85 02 C6 00 Dé FC SS BD8:C6 1 DO F8 C6 02 DO F4 BI 00 BD 06 OC 9D 00 03 B) A D@ F7 A9 00 85 4A AY BFO:08 85 4B 4C 00 03 00 00 11) If your machine is a ][ Plus or newer, or if you have replaced the Integer ROMS in your Jl with FP BASIC ROMs, make the following A A9 00 12) Save the’ new file A964:FF 3D0G BSAVE CRIBBAG That's all there is to it, This 138 sector binary file can be moved using FID from your DOS 3.3 System Master at =iee Ee > SRI COMPUTIST No. 35 11 softkey for... by Mare Lirette Microsoft Corp, 10700 Northop Way POB 97200 Bellevue, WA 98009 Requirements: Super IOB v1.5 Apple | Plus or equivalent One disk drive (two are preferred) After several attempts at trying to unprotect my Olympic Decathlon disk I was only able to unprotect it last weck. ‘The main reason why I couldn't unprotect Olympic Decathlon was because is uses an old System of storing the information on the disk. After boot tracing and examining the read routine. 1 noticed that the tracks on the disk were written with 4 & 4 encoding. Standard DOS 3.3 and ProDOS uses 6 & 2 encoding. Refer to Beneath Apple DOS or ProDOS by Don Worth and Peter Lechner for a discussion of 4 & 4 encoding versus 6 & 2 Because the disk uses 4 & 4 encoding, it can only store 11 sectors per track The method of unprotecting the disk is to first tranfer the disk to a DOS 3.3 format (6 & 2 and then change its read routine to instead of reading 4 & 4. First Lused : to capture the Olympic Decathlon read routine. Then I wrote a Super IOB v1.5 controller that uses the Olympic Decathlon’s own read routine and normal DOS for writes. The resulting disk would not boot After examining the boot process of the original disk some more I decided that I would have to write my own loader routine and modify the read routine on the copy of Olympic Decathlon to use standard RWTS. So after some revisions to my controller and the creation of my LOADER file, it worked! The Cook Book 1) Key in the LOADER hexdump and the Super 1OB controller using the instructions on the CLS A Olympic Decathlon é# 12 COMPUTIST No. 35 inside front cover of this magazine and save them with BSAVE LOADER,A$9000,L36D. SAVE CON.OLYMPIC 2) We will now boot code trace your original Olympic Decathlon disk to capture its read routine. First write protect your original and enter the monitor. CALL. 3) Cpoy the disk controller card ROM in slot 6 to RAM 9600<C600.COFFM 4) Change this relocated boot ROM to put us into the monitor instead of executing the next stage of the boot 96F8:4C 59 FF 5) Execute this modified Boot @ and turn off the drive 9600G CHES 6) The disk drive will start up and clank. The cursor will then reappear. Now track @, sector © is loaded into memory, Change Boot 1 at $0800 to put us into the monitor instead of executing Boot 2. 826:4C 59 FF 7) Change Boot 0 to load track 0, sector @ into $9800 und execute Boot | at $0800. 9659:98 9OFB:4C 01 08 8) Execute Boot @ and 1 and turn off the drive 9600G COES 9) Now Boot 2 is loaded into memory. This is Olympic’s read routine. Boot your Super IOB disk and save this read routine C6006 BSAVE RWTS.OLYMPIC ,A$8900,L$900 10) We will now create a slightly modified boot strap code to load in Olympic Decathlon. Enter Decathlon the monitor and move the boot strap code to $3600. CALL -I51 3600<B600.BFFEM 11) Make the following modifications to this code so that it will load Olympic Decathlon correctly 36FE:B6 371 S7LAOF 373F:81 CO 20 93 FE 3748:00 89 37A0:C@ OA DO 05 AO OF STA E STE 3 A STEB:00 37FO:00 12) Return to Applesoft and save this modified boot strap to your Super IOB disk (exe) BSAVE RWTS.NORMAL ,A$3600,LSA00 13) Use the Super IB controller to copy Olympic Decathlon, Note that after track $22 is written, you will be asked to insert your Supe! IOB disk. This is so the controller can BLOAD the files you just created and write them to your deprotected copy LOADER 9000; AS OC 4A 8D EC B7 AS OD 9008; 80 EO B7 AS 08 80 Fl B7 9010; AS 00 8D B7 AS 03 85 6 03 EE Fl EE ED $0400 ED B7 CO OB D8 88 $9800 8D ED B7 EE EC B7 © $9F92 AS 02 DO E5 AD EC $73A4 85 05 £D B7 85 06 $0544 1 8D 9 B7 AQ = $8FAD 85 B7 AC ED B7 88 $7681 B 1120 POKE 48 controller 44 1000 REW OLYMPIC DECATHLON 1130 HOME FOR READ X : POKE A ,X : NEXT 1 POKE 39 GOSUB 61 +1. IF TK <LT THEN NEXT s) SI 5000 DATA 1 22 5010 DATA8 1 12.76 0,144 10010 PRINT CHR$ (4 16 GO: GO 9 149 176 :ST IB 610 :T B 610 169.77 ) "BLOAD* RWTS POKE BUF .44 ;MB = POKE BUF , 39 : MB. PRINT "THAT'S* ALL* FOLKS!" ; END 96 .133 11 133 3 169 OLYMPIC" controller checksums GOTO 103¢ 1070 AS = CHRS (7 ) + “INSERT* SUPER® 10B* DISK 1900 GOSUB 470 ; HOME : PRINT 1010 4 BLOAD* 1020 PRINT CHRS (4 1030 1040 CHRS 4 BLOAD* 1050 RTS. NORMAL. $3000" 1060 1100 AS =" |NSERT* TARGET® DISK* IN* DRIVE* " + 1070 STRS (D2) : GOSUB 470 . HOME 1080 1110ST=9 :TK=0 : POKE BUF .57 :MB=48 : GOSUB 610 : POKE 907 .238 % COMPUTIST No. 35 $3568 SEC74 SF80E SEAA7 $5610 1090 1100 1110 1120 1130 5000 5010 10010 - ~ $DE25 $643E $035) $24A3 - $4697 ~ $£913 SAQBE SCDE4 bg 13 revisiting F-15 by Jim Wallace MicroProse 120 Lakefront Drive Hunt Valley, MD 21030 Requirements: A blank disk Super IOB 1.5 Sector editor (optional) A copy program which will copy specific tracks (optional) As Mi | Ferreira and Ken Burnell (Input, COMPUTIST Nos. 28 and 29) indicate, there are other versions of F-15 Strike Eagle released which are different from Larry Jasonowicz’s (COMPUTIST No. 24). I also tried Larry’ softkey procedure with no success, His article was helpful. however, in softkeying the F-15 Thave. Perhaps some of my findings will help in softkeying still other versions. A quick check of the disk using CTA revealed a normal DOS 3.3 format except track $22 which appeared to be empty anyway. So I made a copy of F-15, tracks $00 through $21. I used this copy during my investigation and used the original for the final softkey. I decided to look for a catalog track, whose location is usually indicated in normal DOS 3.3 on track $01, sector $0B, byte $01. Finding the value $15, 1 initialized a blank disk with DOS 3.3, used a sector editor to change byte $01 of sector SOB, track $01, to $15 and then rebooted this disk. The F-15 copy could then be CATALOGed and the files loaded. I was interested in examining any file which louded into page $02. assuming that the protection would at least be similar to Larry’s version. The file “AS"’, located on track $10, sectors $0C and SOD, loaded into page $02. After loading it, I found that it also stored $CO at $0201 if a copy of the disk is detected and SDB if no error is encountered. To defeat this check, I simply changed the $CO to $DB (two locations (track $10, sector $0C, bytes $90 and S$9E) on the copy of F-15 which I had just made). Having made these changes, the game would progress up to the point of requesting you to enter a code number (explained in the F-15 manual). After the code was entered, the program bombed with a “HARDWARE FAILURE!” message. Noticing that disk access occurred after the code was entered, I suspected a nibble count or some unique signature on that problem track $22. So I rebooted and interrupted the process with a modified ROM (see previous issues of COMPUTIST) to search for disk access code (some reference to location $CO8C), This led me to the actual nibble count subroutine located from $5303 through $537B. (I later checked the catalog and found file “SCN.DTA" loaded into pages $50 through $53. However, don’t bother trying to load and read it (it's encoded and gets Exclusive-OR'ed after loading to reveal sensible duta)), Backtracking. I found the process begins at $5000. Without any further analysis of the code, I simply gave it a shot of “+18 60°" (encoded, of course) to indic: no errors found’* and return to the caller. No luck. Apparently there was something the subroutine generated which the caller looked for upon return. Looking through the routine, I found a couple of places where $21 is loaded and then the program jumps to what appeared to be its own SEEK subroutine (to move the disk arm to a specific track. See COMPUTIST No. 22, Super IOB 1.5 “Half-Tracks’* for more on this subject). $5000- 18 CLC $5001- 90 OF BCC $5012 $5003- 9A 5 $5004- 96 21 $5006- 61 60 14 COMPUTIST No. 35 $5008- 05 AA S$SO0A- 96 DE $500C- AA $500D- D5 AA $500F- AD DE AA $5142- AD 05 00 LDA $5005 $5145- 20 89 52 JSR $5289 $5148- AD 05 50 LDA $5005 $514B- 20 9B 51 JSR $5198 S514E- 20 7E 51 JSR $5I7E When a program uses a SEEK subroutine. 9.5 times out of 10 (decimal--not hex) it’s using half-tracks. A quick check of the original disk revealed a fully formatted track $21.5 with seemingly empty sectors. As a matter of fact, tracks $21, $21.5. and $22 appear identical-- and I do mean identical! Track $22 is formatted with a track ID of $21! After locating these tracks, the actual nibble count subroutine counts u specific number of bytes. then looks for a “9A 96 xx DE AA" sequence. $532A- AQ 54 LOY #$54 $532C- A9 00 LDA #900 $532E- BD 8C CO LDA S$CD8C,X $5331- 10 FB BPL $532E Read $54 + SFF bytes $5333- EA NOP $5334- 88 DEY. $5336- DO F7 BNE $532E $5337- BD 8C CO LDA SCO8C.X $533A- 10 FB BPL $5337 $533C- EA NOP $533D- C8 INY $533E- D0 F7 BNE $5337 $5340- BD 8C CO LDA $C98C.x $$343- 10 FB BPL $5349 $5345- A4 2A LOY $2A $5347- 00 05 BNE $534E $5349- CD 03 50 CMP $5003 $534C- 00 2C BNE $537A $534E- BD 8C CO LDA SC08C,x $5351- 10 FB BPL $534E Strike Eagle $5353- A4 2A LDY $24 $5355- 00 05 BNE $535C $5357- CD 04 05 CMP $5004 Read and compare the next tive bytes to "9A 96 xx DE AA" $630A= 00 1E BNE $537A $535C- BD 8C CO LDA C08C,X $535F- 10 FB BPL $536C $5361- EA NOP $5362- EA NOP $5363- EA NOP $5364- BD 8C CO LDA CO8C,X $5367- 10 FB BPL $5364 $5369- CD 10.50 CMP $5010 $536C- DO 9C BNE $537A $536E- BD 8C CO LDA Scesc $5371- 10 FB BPL $536E $5373- CD 11 50 CMP $5011 $5376- D0 02 BNE $537A $5378- 18 CLC $5379- 60 RTS $537A~ 38 SEC $537B- 60 RTS Hmmmm. The DE AA is the epilog of a normal DOS 3.3 sector. Checking the sectors on these tracks. again. with CIA Linguist revealed the “YA 96 9A DE AA” at the end of the sector $00 on each of these similar track: It's casily overlooked in the sea of **9 unless you're looking for it. Well. if 1 couldn't ignore the whole disk check routine, at least I could skip the actual nibble count. At $5151 the program branches to $51 if a good nibble count has occurred and steps are executed to indicate no error. The sole indication of no error is that the A register must contain $00 when returning to the caller The remaining code between $5165 through $517A will set up other conditions needed upon return whether an error was detected or not. With this information, I decided to change the code on page $51 as needed to skip the actual nibble count, As mentioned earlier. this routine is encoded on the disk. Each page of the routine must be EOR’ed with a different value for decoding. In case any of you want to CAUTIO! tes you see in RAM are offset bs tor of +4 when using your sector editor, For example, when you read in page $50 from track SOC, sector $07, byte $5020 that you see in RAM will be byte number $24 of your sector editor--not byte number $20. When DOS 3.3 stores binary files to the disk, it precedes the actual data with a two-byte address and a two-byte length. This **moves"* the rest of the data four bytes down the file Page Value $50 SA5 $51 $75 $52 $39 $53 S6E (One item I didn’t follow through on was figuring out why immediately after decoding. page numbers in the code are $60 through $63, then changed to $50 through $53 prior to execution. Another Caution: Take heed, ye who want to experiment further!) Making The Copy The sector editor method for making a F-15 backup is faster. Nearly everyone has a sector editor, but for anyone who does not, use the Super IOB method described later. 1) Copy the F-15 disk. tracks $00 through $21 or, if you can’t specify tracks, ignore errors on track $22. 2) Use your sector editor to make the following Track Sector Byte SC $06 $31 $32 $87 $2 $5C $55 $60 $5D $53, $0C S5E $17 $6E SOF $39 SF $60 $37 $93 S10 SOC $90 $cO SDB $9 $c@ SDB 3) Be sure to write cach sector back after making the changes The Super LOB Method 1) Initialize a blank disk with DOS 3.3. 2) Install the F-15 controller at the end of the article into Super [OB and use it to copy tracks $00 through $21 of the original disk. Super IOB will make the necessary sector edits on tracks SOC and $10, controller 1000 REM F-15 STRIKE EAGLE CONT 1010 TK=0 “LT = 34 :ST=15 :LS=15 :CD=IR : FAST =1 1020 GOSUB 490 : GOSUBG10-T1=TK :TK=PEEK (TRK ) 1: RESTORE - GOSUB 310 .TK = TL 1030 GOSUB 490 : GOSUB 610 : IF PEEK (TRK ) =LT THEN 1050 1040 TK=PEEK (TRK) :ST=PEEK (SCT) : GOTO 1020 1050 HOME . PRINT "DONE." ; END 5000 DATA 11* CHANGES 5010 DATA 12 6 49 57 12.6 50 45 5020 DATA 12 .6 51 ,20 12 6.92 109 5030 DATA 12 6 93 ,220 12 6,94 110 5040 DATA 12 6 95 248 12 6 96 ,147 5050 DATA 12 .6 .97 ,20 16 12 144 219 5060 DATA 16 12 ,158 219 controller checksums 1000 - $3568 5010 - S9E8E 1010 - $0715 $020 - $6508 10920 - $CE56 5030 - $D7AB 1030 - $7CE8 5040 ~ $1CA8 1040 - SDLCC ~ $3F50 1050 $33EF — $8768 5000 - SE34A ek eet lg COMPUTIST No. 35 15 Exploring ProDOS by Installing a.. CPS Clock Driver by Paul Blumstein If you own a Mountain Computer CPS clock card. this article will show you how you can use it as a ProDOS compatible clock. If you do not have a CPS clock. this article will provide you with insight into some of the inner workings of ProDOS that you will find useful to you whether you wish to write assembly language programs or as a starting point for further exploration. We shall explore ProDOS’s Machine Langu Interface and its Global Pages and we will discover how a system program is called and relocated Background About four years ago, Mountain Computer Incorporated revolutionized the Apple compatible peripheral card industry by introducing the “CPS Multifunction Card.” This card contained a bi-directional serial interface. a parallel interface and a clock/calendar, Its name, CPS, stands for its three functions: Clock, Parallel and Serial. This card was popular for two years until ProDOS arrived, making the clock function of little value, Many people still are using these cards to drive their modem or printer or both. Why A Clock? An excellent reason for owning a ProDOS compatible clock is that ProDOS will automatically place the date and time in directory entries. That information tells you when each file was first created and when it was last modified. Have you ever had two or more files with the same name on two different disks and wondered which one was the latest version? Or have backup files were current? Having a clock solves these problems ou ever needed to know whether your Another good reason to own a clock is that some applications will use your clock to make your life a little casier. For example, Apple’s AppleWorks program initially prompts you for a date. If you have a clock, it defaults to the current date. If you don’t have a clock, then it defaults to the last time you manually entered a date. Without a clock, this means that you will haye to re-enter a new date every time you boot on a different day. With a clock, AppleWorks will also display the time that your files were last updated in addition to the date Word Juggler. a word processor by Quark Incorporated, is another good example. It has functions that automatically print the date and time on your documents. When you use these functions without a clock. you must manually enter the date and time each time you boot When you do this. the time never changes. More and more ProDOS applications are be written to make use of a clock. It is especially frustrating when you have a clock inside your computer that you can’t usc, This frustration led me to create a clock driver that would access a CPS clock and fool ProDOS into thinking that I had a ProDOS compatible clock. By the way. you probably have noticed the name Thunderclock mentioned in ProDOS- related literature. That is because Apple designed ProDOS to be compatible with the Thunderclock clock ard made by Thunderware. Inc. All of the clock cards since 16 COMPUTIST No. 35 that time Thunde have been designed to be clock compatible. How a Program Accesses the Date The creators of ProDOS decided to create subroutines that could be accessed in a way that would be compatible across future versions. One of the problems with DOS 3.3 was that programmers accessed its subroutines directly. ‘That meant that Apple could not make any real modifications to DOS since everyone expected that everything would always be in the same place. ProDOS takes two steps to solve this problem: the Machine Language Interfi (MLI), and Global Pages. The MLI is a subroutine that has only one entry location: $BF00. An assembly language programmer executes a JSR instruction (similar toa BASIC GOSUB or CALL statement) to this location and passes parameters indicating what he would like ProDOS to do for him. For example, each of the ProDOS commands (like OPEN) have equivalent MLI calls. There are additional system functions that are only available through the MLI, The MLI call to get the system date and time (called GET__TIME), which we are about to explore, is one example of this, The System Global Page is page SBF (locations $BF00 through SBFFF). This page contains values. such as file buffer addresses. and JMP (jump) instructions (which are equivalent to BASIC’s GOTO statements). These instructions jump to-various areas of ProDOS. The BASIC Interpreter (which is the interface between ProDOS and Applesoft) also has u Global Page (page $BE). By having fixed locations on these Global Pages, both ProDOS. and the BASIC Interpreter can come out with ‘new versions without and any program that does not violate the rules will not be affected. New versions of ProDOS and the BASIC Interpreter merely change the values stored in these locations, but the locations, themselves. never change, If you are interested in more details on the MLI and these Global Pages, I recommend Beneath Apple ProDOS by Don Worth and Pieter Lechner (Brady Communications, Inc.. 1985, $19.95). That brings us to the clock. When any ProDOS program wishes to retrieve the date and/or time. it does it by issuing an MLI call (JSR $BFO0). By convention, this call is followed by a one byte function code and a two byte address that points to the location of a parameter list. When ProDOS is done with the call, program execution continues at the address immediately following the three bytes. The GET_TIME function code is $82. Since this call does not have any parameters, the two byte address after the function code has a value of zero, The assembly language code to get the system date and time is simply: JSR SBFOO —cal!_the MLI HS 82 GET.TIME code HS 0000 address of parmlist LDA continue program ProDOS responds by placing the current date and time, in binary, in locations $BF90 through SBF93. The time is stored in a 24-hour clock format with hours placed in location $BF93 and minutes placed in location $BF92. The date is more complex. The 5 right-most bits (known as the Least Significant Bits or LSBs) of location $BF90 contain the day of the month. Since we number bits from @ (on the right) to 7 (on the left), this would be bits @ through 4. The number of years since 1900 (i.e., 1986=86) occupy bits | through 7 of location SBF91. That leaves bits 5 through 7 of $BF90 to contain the LSBs of the month and bit 0 of $BF91 to contain the Most Significant Bit (MSB) of the month. Confused? Let's try an example using September 15, 1986 as today's date and 11:45 pm as the current time and figure out how this is stored (see Table 1). If you were to examine locations $BF90 and $BF91 with the monitor, you would see that it contains the values $2F and SAD, respectively, which is consistent with the bit pattern above. If the system doesn’t contain a compatible clock, the values at these locations do not change. They are initially zero and are changed whenever you “set the clock”’. That is why you can set a non-existent clock and retrieve the non-changing date and time until you re-boot, The Clock Driver Since different ProDOS versions can have the clock driver code in different locations, it needs a way of knowing where the driver currently is. Remember the Global Page? Locations S$BF07 and $BF08 contain the current address of the clock driver. (Always remember that an address has the low-value byte first). When ProDOS first boots, it looks for a compatible clock. If it finds one, it does two things. First. it places.a $4C (JMP instruction) at location $SBFO6. Then it modifies the driver so that the clock addresses within the driver point to the correct slot. If a compatible clock isn’t found, it places a $60 (RTS instruction) at $BF06 instead. When a program (or ProDOS itself) calls the MLI (at SBFO0) to retrieve the date. it uses a function code of $82. This tells it that it needs to execute the clock driver code. The MLI now does a JSR (Jump to SubRoutine) to SBF06. If a clock isn’t present, the RTS (ReTurn from Subroutine) instruction is executed and execution passes back to the MLI. If a clock is present. then the JMP (JuMP) instruction directs the processor to the driver code. The driver code accesses the clock, fills in locations SBF90 through $BF93, and performs an RTS which passes execution back to the MLI. The MLI then returns to the program. Solving the Big Problem Those of you that have a CPS Clock realize that ProDOS doesn’t recognize it. Even if it thought that the clock was compatible. the driver wouldn't work. That means that we must derive a way to fool ProDOS into thinking that we have a compatible clock and make it use a different driver, The problem wouldn't be too hard to solve if we were only going to use the clock for our own applications. In that case, all we would need to do is BLOAD our own driver into a location that know we is safe and change locations $BF06 through $BF08 to be a JMP- to our driver. Then, anytime ProDOS or our programs needed the time. it would use our driver to access our clock and everything would work just fine. But, we also want our store-bought programs. to use the clock. This is tricky for two reasons. First, we never know what parts of memory the application will use. perhaps all of it. Second. most applications do not have a BASIC Interpreter and do not allow us to leave the application itself. There is a solution! After ProDOS boots, it checks the catalog for the first system program with a name ending with *-.SYSTEM"*. By the Way, a system program is one whose file type is “SYS**. It is always a binary file that will run at $2000. At the end of the boot. ProDOS loads this program and passes execution to it with the JMP command. On our ProDOS User's Disk. this program is called BASIC.SYSTEM. On an application program, it could be called anything. The solution is to rename the SYSTEM program so that ProDOS won't find it and will find our own program, CLOCK.SYSTEM, instead. CLOCK.SYSTEM contains our homebrew clock driver and code to install it. The installation code first changes the RTS instruction at $BFQ6 to be a JMP instruction that ProDOS knows that a clock exists. Next, it changes all of the absolute addresses within the driver to be consistent with where we are going to move it. Then, it relocates the driver to the only safe place that we can move it: over the area where the old driver was. The final thing that we will do is execute the system program that would normally be executed right after ProDOS booted: the one we renamed. This gets more complex. CLOCK.SYSTEM would have to relocate itself somewhere else since the other system program also execut it $2000 und we would overwrite ourselves if we loaded it. Also. BLOAD and BRUN aren‘t currently available for us to use That would mean that we would have to write code to manually search the catalog and manually load it. All of this could be done. but would require w lot of extra work. Luckily. there is an easier solution. ProDOS. contains a section of code called QUIT which is accessed through the MLI. The QUIT code is designed to be used at the end of a system program to let the computer user execute another system program, By letting ProDOS do the work, we can save ourselves a lot of trouble, There is one problem though. The QUIT code requires you to enter the name of the next system program that you want to execute. That means a few extra keystrokes everytime you boot. Whenever I rename the .SYSTEM program, I call it **GO". That cuts down on the number of keystrokes, Also, by always using the same name. I do not have to remember what I called it on each disk. A Guided Tour The source code listing puts into practice everything that we have talked about. Most people place their CPS Cards into either slot 1 or 2. This listing is assembled for slot 2. If your card is in slot 1 (or any other slot, for that mutter) a few minor changes are needed, If you are using an assembler. simply change the “SLOT .EQ in the source code listing (next page) from a 2 to a | (or whatever the slot number is) and everything will assemble correctly. If you are going to type the program in through the monitor, change the $C2 to $C1 (or C followed by the slot number) at the following hex locations: 205E. 209D, 20A4, 20A7, 20BA, and 20BD. Since thi: system program, it must reside at address $2000. The driver code follows the installation code which is executed ut boot time. There are several ways to access the clock through assembly language. I chose the most direct method, which bypasses the built-in ROM program on the card and accesses the clock directly. The clock is accessed by writing commands to its address location and reading data from (or writing data to) its data location. These locations are $CxFE and $CxF9. respectively, where x is the slot number, Since time is always moving. we must hold the clock briefly while we read it. If we didn’t and it was, say. 2:59. we may retrieve the minutes and the clock may then become 3:00 just before we get the hours. We would then think that the time was 3:59. This hold function is performed at $205A and after completion, the clock is released at $2099. The rest of the program get h part of the date that it needs: and stores it at the previously mentioned locations. COMPUTIST No, 35 17 The RDCLK subroutine retrieves the tens place of each field, multiplies it by ten. then retrieves the ones place and adds it to the tens pluce. The multiplication is done by shifting two places to the left, adding back in the original number and shifting the result one place to the left, For example. if we are working on the minutes field and it is now 2:59, we will retrieve a5 for the tens place. Shifting to the left is the equivalent of multiplying by two since we have a binary machine. The first shift turns the 5 into w 10 (SA). The second shift turns it into a 20 (S14), Add ack in the original number. 5. gives uy 25 ($19) and the last shift turns this into a 5@ ($32). We then retrieve the ones position. which is a9, and add it to the 50 to give us 59 ($3B). Each value that we retrieve is returned from the clock in the rightmost nibble. except for the tens place of hours, where we only need the two LSBs. In that case we perform an AND instruction to mask out thase bits. The installation code changes $BFQ6 to be a JuMP instruction and then calculates where RDCLK will reside after relocation. It then changes each of the JSRs to RDCLK in the driver so that they will point to its new location. The next step is to bank in the language card RAM and overlay the new clock driver on top of the old driver. Finally. the installation code calls QUIT through the MLI (at $204C), Installing Our Masterpiece Either type in the machine code through the monitor or type in the assembly code (this is in S-C Assembler format), If you use an assembler under DOS 3.3 simply convert the resultant. bil file with the ProDOS CONVERT Utility. To make life simpler, call your program something other than CLOCK.SYSTEM (such as CPS.DRIVER) because it is not yet a system program. (ProDOS. won't let you BLOAD a system program so you would want to keep a binary version of it around for future use), Put your program onto your ProDOS User's Disk and place your target disk into drive 2, (You can also do this with one drive). Rename the current .SYSTEM program and save your program as. a .SYSTEM program. For example: 1) Make a backup copy of the disk you intend to install the clock driver on, Put away the original. NEVER modify your original disk 2) Boot ProDOS and enter BASIC. 3) Enter the monitor with CALL -151 and type in the hexdump (if you don’t assemble it). 4) Save the program to disk. BSAVE CPS.DRIVER,A$2000,L$C3 5) Locate the .SYSTEM program and rename it "GO. RENAME BASIC.SYSTEM,GO Table 1: Time/Date Storage FIELD DECIMAL HEX» # BITS BINARY COMMENT Month 9 9 4 1001 see below Day 15 F 5 Oil see below Year 86 36 7 1010118 see below Hour 23 7 8 90010111 Placed at $BF93 Minute 45 20 8 90101101 Placed at $BF92 <--—-SBF91----> <----$BF90-——-> _ ADDRESS 7654321076543210 BIT# 1010110100101111 BIT VALUE <---YEAR----> <-MON-> <--DAY--> FIELD NAME oa oe Q03A- TENS 0010- READ 0002- C2FE- C2F9- 003A- SLOT CLKADR CLKDATA TEMP BFA0— MLI 2000 2002 2005 2006 2009: 2008 2000 2010. 2012 2015 2018 2018: 2016: 2021 2023: 2026: 2029; 202C. 202F: 2032 2035: 2037. 203A 203C: 203F: 2042: 2044: 2047: 2049: START AS 4C 8D 06 BF 18 AD 07 BF 69 46 853A AD 08 BF 69 00 8D 63 20 8D 6E 20 8D 77 20 80 7F 20 80 92 20 AS 3A 8D 62 20 80 60 20 8D 76 20 80 7E 20 80 91 20 AD 07 BF 85 3A AD 08 BF 85 38 AD 88 CO AD 8B CO AQ 69 LOOP B9 59 20 91 3A 88 Source Code For CLOCK.SYSTEM CLOCK SYSTEM -- USE THE MCS CLOCK WITH PRODOS * REMEMBER TO RENAME THE ORIGINAL , SYSTEM FILE * P. BLUMSTEIN 1/86 * OR $2000 FQ $3A KEEP A WORKSPACE LOC EQ $10 CLOCK READ COMMAND EQ 2 EQ SLOT * $100+SCOFE EQ SLOT * $100+SCOF9 EQ $3A £Q $BFOO — MLI ENTRY POINT LOA #S4C STA $BFO6 cle LOA SBFO7 CALC ADDRESS OF RDCLK ADC #RDCLK-CLKSTART. STA TEMP LOA $BFO8 ADC #0 STA JSR1+2 STA JSR2+2 STA JSR3+2 STA JSR4+2 STA JSR5+2 LDA TEMP STA JSRI+1 STA JSR2+1 STA JSR3+1 STA JSR4+1 STA JSR5+1 LDA $BFO7 ‘STA TEMP LDA SBFO8 ‘STA TEMP+1 LOA $C08B LDA $C08B LOY #CLKEND-CLKSTART #BYTES TO MOVE-1 SETUP GLOBAL JUMP SET UP RELOC INFO ALLOW WRITE TO RAW LDA CLKSTART,Y OVERLAY CLOCK DRIVER: STA (TEMP) .Y DEY 18 COMPUTIST No. 35 6) Install the new clock driver as a SYSTEM 2044, 2040. 204F 2050 2052 2053 2054 2056: 2057: 2059 205A: 205C 205F 2061 2064 2067 2069: 2060: 206F 2072 2073 2075 2078 2078 2070: 2080 2081 2082 2083 2084 2087 208A; 2088 208E: 2090; 2093 2096: 2099 2098. 2096 209F 20A1 20A2 20A5 20A8 204A 20AC, 20AE 2080 2081 2082 2084 2085 2087 2088 2088 20BE 20c0 202 10 FB BPL LOOP 20 00 BF JSR MLL 65 HS 65 EXECUTE QUIT CODE 52 20 DA PARMS s x END OF DRIVER INSTALLATION CODE 2% > 04 PARUS HS 04 INDICATE # PARMS 00 HS 00 00 00 HS 0000 00 HS 00 0 00 HS 0000 > BEGINNING OF DRIVER * % % CLKSTART BB cly AQ 40 LOA #940 HOLD THE CLOCK 8D FE C2 ‘STA CLKADR AQ 03 LDA #3. MINUTE ADDRESS 20 9F 20 JSRI JSR ROCLK 8D 92 BF STA SBF92 STORE MINUTES DIRECTLY AI 05 LDA #5 HOURS ADDRESS 2C 06 BF BIT SBFO6 SET V FLAG 20 :9F 20 JSR2 JSR RDCLK HOURS GET SPEC HANDLING 8D 93 BF STA SBF93 88 cL AQ OC LDA #12 YEAR ADDRESS: 20 9F 20 JSR3 JSR RDCLK 80 91 BF STA SBF91 © STORE !T UNSHIFTED AQ OA LOA #10 MONTH ADDRESS 20 9F 20 JSR& JSR ROCLK 4h LSR SHIFT INTO PLACE 6A ROR 6A ROR 6A ROR 8D 90 BF STA SBF9O PUT WHATS LEFT WHERE AD 91 BF LDA $BF91 GET THE YEAR BACK 2A ROL .& STICK IN THE MONTH'S 8D 91 BF ‘STA SBFO1 & PUT IT BACK AD 08 LOA #8: ADDRESS OF DAY 20 9F 20 JSRS JSR ROCLK 00 90 BF ORA $BF90 = PUT THE MONTH IN & 8D 90 BF STA SBF9O. PUT IT BACK Ag 00 LDA #0 TAKE CLOCK OFF HOLD 8D FE C2 STA CLKADR 60 RTS # % % ROCLK--ON ENTRY 'A’ CONTAINS A CLOCK FIELD ADDRESS ON EXIT ‘A’ CONTAINS ITS BINARY VALUE ROCLK 09 10 ORA #READ PUT READ FLAG INTO ADDRESS. AA TAX HOLD THE ADDRESS 8D FE C2 STA CLKADR GET TENS PLACE AD F9 C2 LDA CLKDATA 50 02 VC NORM SKIP THIS MASK EXCEPT 29 03 AND #3 HOURS NEEDS 2 BITS NORM 29 OF AND #$F OTHERWISE, 1 NIBBLE 85 3A STA TENS A ASL MULTIPLY BY TEN 0A ASL 65 3A ADC TENS OA ASL 85 3A STA TENS CA DEX POINT TOONES PLACE 8E FE C2 STX CLKADR AND GET IT AD F9 C2 LDA CLKDATA. 29 OF AND #SF KEEP A NIBBLE 65 3A ADC TENS 60 CLKEND RTS file. The TSYS commund tells ProDOS that the file type we're working with is SYS CType SYStem™). This will keep ProDOS from complaining. BLOAD CPS.DRIVER CREATE CLOCK.SYSTEM,TSYS,D2 BSAVE CLOCK.SYSTEM, TSYS,A$2000,L$C3 The hexdump contains the program in binary with the checksums created by CHECKBIN. You can run CHECKBIN under ProDOS by using the ProDOS CONVERT Utility to make ita ProDOS file. Always perform the above on a backup disk only, never on the original. When you boot the modified disk, it will prompt you: ENTER PREFIX. Hit RETURN at this point. It will then prompt you for the program name. Type in GO (in upper or lower case) and hit RETURN. The program will then proceed as italways did before. If you mistype the program name, the QUIT code will say FILE/PATH NOT FOUND and stop. Don't panic. Simply hit Reset and it returns to the ENTER PREFIX prompt. Adyanced Improvements Two additional features can be added to this program. If you need to make the installation code work with the clock in any slot, you can add code to find the slot that your clock is currently in. Your CPS Setup Disk has a BASIC program called CPS SLOT FINDER that can easily be converted to assembly language. To see this program, boot the Setup disk, quit into BASIC. type in NEW, then EXEC CPS SLOT FINDER and LIST, If you do not like to type GO every time you boot. you can add code to relocate the installation code, load the GO program at location $2000 and JMP to it. Personally, I find both of these features more trouble than they are worth. CLOCK.SYSTEM Hexdump 2000: A9 4C 8D 06 BF 18 AD 07 SCORE % 2008: BF 69 46 85 3A AD 08 BF © S3DAE 2010; 69 00 8D 63 20 8D GE 20 $2409 2018: 80 77 20 80 7F 20 8D 92 S2F9E 2020: 20 AS 3A 8D 62 20 8D 6D SDE6] 2028: 20 8D 76 20 80 7E 20 8D $0763 2030: 91 20 AD 07 BF 85 3A AD $9205 2038: 08 BF 85 3B AD 8B CO AD S6E88 2040; 8B CO AO 69 B9 59 20.91 $3606 2048; 3A 88 10 F8 20 00 BF 65 © SBF93 2050: 52 20 04 00 00 00 00 00 ©5437 2058: 00 BB A9 40 8D FE C2 A9 = $60A6 2060: 03 20 9F 20 8D 92 BF AQ © $3A0F 2068; 05 2C 06 BF 20 9F 20 8D $F0B2 2070; 93 BF B8 AQ OC 20 9F 20 $3615 2078: 8D 91 BF AD OA 20 9F 20 SC14E 2080: 4A 6A 6A 6A 8D 90 BF AD $3104 2088: 91 BF 2A 8D 91 BF A9 08 $8760 2090: 20 9F 20 00.90 BF 80 90 $5602 2098: BF A9 00 8D FE C2 60 89 S03DA 20A0: 10 AA 8D FE C2 AD F9 C2 $BD89 2008; 50 02 29 03 29 OF 85 3A $8700 2080. OA BA 65 3A 0A 85 3A CA $7F6E 2088; 8E FE C2 AD F9 C2 29 OF $75EB 20C0: 65 3A 60 $F385 = = COMPUTIST No. 35 19 Putting a New F8 On Your Language Card by Ken Burnell Requirements: Apple Language Card Low wattage soldering iron Small diameter solder Small diameter wire strap Apple |[ Plus or equivalent computer (not //e or //¢) 2716 EPROM Exacto knife or equivalent Access to an EPROM burner Note: The following procedure involes modification of your motherboard and/or your Language Card. COMPUTIST will not be held responsible for any damages incurred while following this procedure. Ever since I read an article in ‘Computers & Electronics" on custom programming Apple EPROMs (reference #1), and bought an inexpensive EPROM burner, I have been burning custom F8 EPROM’s for my Apple. and enjoying it more. (I had previously built a ROM/EPROM adaptor socket for the Apple motherboard (reference # 2)). Therefore, when I read Ray Darrah’s article in COMPUTIST No. 19 (reference # 3) Ihappily set out to round up a 2732 EPROM and miscellancous small parts and program up a new, improved, expanded super F8. But, after re-reading Ray’s article completely through again, I realized that I didn’t really want to fool around with adding an extra chip to my virgin motherboard, cutting traces, etc. So, I shelved the project (with several others) until I could find a better way. The procedure I finally came up with assumes that you have an Apple Language Card, APPLE Product #A2B0006 or equivalent. The way to spot this card is that it has a short sixteen-wire cable extending from a DIP socket on the card to a RAM socket on the motherboards (Apple says to use the RAM socket at location E8 but replacing other RAM chips in other locations will also work), Most important of all, this card has an an F8 ROM chip (usually a 9316) mounted near the rear of that curd, There are a few things you should know about the Apple Language Card and its ROM chip, First, the ROM on the card effective! aces the F8 ROM on the motherboard. In fact, with the Language Card installed, you can remove the F8-ROM altogether on the motherboard (with the power turned OFF, of course!) and the computer will still work just fine. But the second, and more important fact is that the Apple Language Card, like the Apple eger Card (remember those?), has two sets . When these pads are modified, the substitution of a programmable 2716 EPROM for the standard 9316 non programmable ROM supplied with the card is allowed. The Way The procedure, which references the sketch on page 21, requires the use of an exacto knife or equivalent, a small (1/4 inch or so) piece of wire (28 to 30 gauge, solid copper if you have it) and a low temperature soldering iron. Note: Using a standard “soldering gun” type iron on any printed circuit board could damage the board. 20 COMPUTIST No, 35 For printed circuit (PC) work, I use a fifteen to thirty watt iron, maximum, with small diameter resin core solder. I have found that solder diameter size # 30 works fine for the what we will be doing. The procedure for modifying the Language Card to accept EPROMS instead of ROMs is as follow 1) Using the knife, cut the copper circuit trace at the X-shaped pads marked **2716"" as shown on the sketch at point A. Only a small, deep, cut is needed to sever the trace. If you have a continuity + (or VOM meter), place it on a low-resistance setting and u: to test for no continuity between the cut traces after performing the surgery 2) Place a short piece of small diameter copper wire across the O-shaped pads marked “*2716"° at point B on the sketch. Solder the jumper across the pads, joining the pads. 3) Install your EPROM being sure that the notch is pointed in the same direction (usually up) as the ROM you're replacing. 4) Re-install the card and its jumper cable back onto the motherboard, and you're done. The next time you boot up your computer, it will boot from your new EPROM on the Language Card. Burning EPROMs At the end of this article, I’ve listed several references to various articles and published letters previously written about burning EPROM's for Apple ][ computers. One of the problems I had, initially, with this process was that the authors told how to modify the EPROM’s code, and how to write binary programs of them, but not how to get the binary code into the EPROM’s! Fortunately, the BSAVE and BLOAD commands of DOS helps to make this job easy. For example, to save the contents of the F8 ROM (‘‘uploading’’ in computer talk), you would type BSAVE STDF8,$AF800,L$800 where "'STDF8"" is the file name I chose, $F800 is the beginning address in memory and $800 is the length of the file (SF800 through $SFFFF in the ROM). This would create a binary file of the code in the F8 ROM (which, by the way is printed in Apple’s reference manual in an appendix (reference # D)). Later, when you want to transfer the binary file on disk to an EPROM in your EPROM. burner, it is first necessary to select an address in RAM for the file to go. T usually use address $1000 for ease of making address calculations. Then, transfer the file from disk to the memory of the computer (‘‘downloading™). The command to use here is BLOAD and it would look like this: BLOAD STDF8,$A1000 Now, you would typically transfer control to your EPROM burner and instruct it to burn an EPROM using the data starting at $1000. EPROM’s And Special Keyboards There are several keyboards around that are claimed to be exactly “plug compatible’* with the standard Apple keyboard - that is, you can unplug your Apple keyboard at its sixteen-pin plug (better note the orientation of that plug or bad things may happen) without using a special adaptor board. But, if the replacement keyboard has lower case capability, you probably won't see the lower case characters on your monitor! This is because the Apple's F8 ROM converts the lowercase characters to uppercase before putting them on the screen, Well, we can’t have that can we? In Mr. Mitchell's article (reference # 1) he told how to fix this problem by modifying the code in a new F8 ROM, and he also told how to do some other interesting things like having your name displayed on the computer’s monitor when it boots up instead of Apple's, etc. 1 strongly recommend Mr. Mitchell's article to anyone wishing to customize ROM’s in his Apple ][. In COMPUTIST No. 9, (reference # 4) an the author told how to modify ProDOS 1,0.1 to run on Franklin Ace and other Apple clones. Recently, Beagle Brothers (reference # 5) gave a tip on how to modify ProDOS 1.1.1 in much the same manner. Some software checks for a code at location $FD83 in the F8 ROM. This code indicates that @ particular computer (][ +, //e, Franklin, other) is being used and then bombs if it doesn’t like the answer. Likewise, the software may checksum-check the whole ROM. One solution to this problem is to use Ray Darrah’s 2732-chip-with-a-switch trick (reference # 3) and switch between a standard F8 image and your custom one in either half of the 2732 - mounted on your motherboard, Integer Card, Language Card or... The variations are limited only by your imagination and pocket book. The Integer Card I mentioned earlier that the Apple Integer Card might also be modified to take 2716 EPROM'’s. Well. it can, in much the same way as the Language Card - by changing the wiring on two sets of O-shaped and X-shaped pads as above. Then the five ROM’s - D0, D8, E0, E8. FO and F8 can all be replaced with 2716 EPROM's. Now, suppose you want to program often- used utility software into memory locations $D000 through $F7FF, ordinarily taken up by Applesoft in the ][ +. Do you suppose I could break up my favorite binary program into 2,048 word (2K) blocks, store them on disk as binary files, download them to 2K 2716 EPROM’s in my EPROM burner, replace the D0-FO Applesoft EPROM’s (that I previously replaced the 9316's with), flip that magic red switch on the back of the Integer Card, and have, say the Copy J[ Plus utility programs up and running at the flip of a switch? I'm sure it can be done but I haven't tried it myself. About EPROM Burners EPROM burners can be expensive. I've seen them from thirty five dollars (the card fits into a slot in the Apple) to thousands of dollars. And EPROM erasers ain't cheap, either - they can run from about $ 50 to $ 80 and up. But, EPROM’s are erased by UV (ultraviolet) rays like those given off by the sun and many fluorescent tubes. So. they say it’s possible to tape an EPROM to a fluorescent tube or set it out in the sun for a week or so, and it should erase. Or, you may want to get together with a few friends and share the cost of an inexpensive burner, and, maybe an eraser. The price of 2716 chips is down to a dollars each. You don't need the **fas ms jobs. The slower, less expensive ones at 450 ms or so will work just fine. A good source of all this hardware is advertisements in the back of Byte. Computers & Electronics or COMPUTIST magazines. Have fun burning. References: 1) Computers & Electronics, November 1983, Pages 58-60, Customize Your Apple With an EPROM Plug by S. F. Mitchell 2) COMPUTIST No. 6, Pages 14-16, Modified ROMs by Ernie Young (see COMPUTIST No. 8 page 26) 3) COMPUTIST No. 19, Pages 9-11, Double Your ROM Space by Ray Darrah 4) COMPUTIST No. 9, Page 18, Using ProDOS On A Franklin ACE 5) Pro-Byter by Beagle Bros, page 78 6) COMPUTIST No. 8, Page 3, Reading Apple ROM'’s 7) The Best of Hardcore Computing, Page 46 Curing Those Auto-Start Blues by Charles R Haight 8) COMPUTIST No. 9, Page 5, Mod2 ROMs 9) COMPUTIST No. 12, Pages 24-26, Pseudo- ROMs On The Franklin ACE by Ken Stutzman (see COMPUTIST No. 14, page 9) A) COMPUTIST No. 19, Pages 18-24, Towards A Better F8 ROM by Earl Taylor B) COMPUTIST No. 22, Pages 4-5, Modified PROMs On The //e C) COMPUTIST No, 24, Page 5, Double Those ROMs D) Apple j Reference Manual, APPLE Product #A2LO001A, Appendix C b> solder Z here HEE 8 HR \d i i va? cut here COMPUTIST No. 35 21 A Review of.. The Senior PROM by Robert Knowles Cutting Edge Enterprises Box 43234 Ren Cen Station Detroit, MI 48243 $79.95 So you want to take control of your Apple //e or //e? You've decided you need: a way to reset directly into the Monitor, an NMI & copy card, a sector editor, and some machine language utilites, but you only have 80 bucks to spend? A new, low-cost device consisting of 32K of ROM and a pair of switches attached by a ribbon cable, going by the name of the Senior PROM, may be just what you've been looking for Description The Senior PROM (SP) is a printed circuit (PC) card about two inches square. that replaces the 8K (2764) CD and EF ROMs on the motherboard with a pair of 16K (27128) EPROMs. These contain an image of the original Apple ROMs in one half and the SP firmware in the other half. At the end of the two fvot long ribbon cable is a second PC card (2" by 1”) with a pushbutton switch for performing Non-Maskable Interrupts (NMI’s) and a three-position toggle switch to select and deselect SP. A small micro-probe with just enough wire to reach from the SP card to pin 6 of the 6502 provides the hookup for the NMI A companion disk (described below) is included, Installation Installation is slightly more complex than just plugging in a card. You must remove the CD and EF ROMs, observing the usual precautions, insert the Senior PROM into the empty sockets. and attach the NMI wire to the processor. Although I have not tried the SP on a //c, I'm sure that installation in the //c will be a bit trickier, as the case **snaps’” together. Documentation The documentation included with the SP is comprised of three stacks of stapled-together pages, all of which have clear, easy to read print. The thickest stack (54 pages) contains installation instructions for both the //e and //e and gives a thorough description of all the SP’s features. In many cases, the instructions explain why a feature is provided and possible uses for it are given. The smallest stack contains a keyboard overlay (on ordinary paper in two black and white halves that must be cut out and taped together) for quick reference to the options that become available directly after pressing Reset. This stack also contains diagrams for opening your computer and installing the SP. The third stack is entitled *Deprotection Methods and Techniques Using the Senior PROM.” This one gives an introduction to copy protection and indicates things to look for when identifying a protection scheme, with some ways to get around them, This is a very general manual (not much detail does 33 pages make), but it should provide a good starting point for the novice, assuming he knows assembly language. The Switches The SP firmware is inactive when the toggle switch is toward the rear of the computer. In this mode your Apple works like normal, ROMS and all. When you switch it to the forward (activated) position, Applesoft BASIC disappears (this could cause bad things to happen if you happen to be running an Applesoft program) and the only means of talking to your computer is through the SP’s enhanced monitor. Once here. you have several utilities at your disposal including a sector 22 COMPUTIST No. 35 editor, RWTS menu (with a disk copier) and Memory Management. However, the real power is available when you press Reset or the NMI button. If the SP is in the “activated” or **transparent’’ (middle) position, the computer stops everything, responds with a distinctive beep, and sits in the “Wait Mode.”* At this point there are a number of options available. You can drop directly into the Monitor, reboot without destroying memory, or go directly to the built-in RWTS utilities. You can copy all of the main RAM to the auxiliary RAM (assuming of course you have at least 128K RAM) for saving; swap main and auxiliary; see where the program was when you interrupted it (if you used NMI); restart program from the last time you interrupted and saved it; dump the text screen to the printer; and a few other things. All these options appear on the keyboard overlay so you can quickly choose the one you want. If however, you refuse to tape the keyboard overlay to your computer, you will be forced to memorize several arbitrarily assigned keys. The Menus The RWTS Utilities, also called the Main Menu, appears on the screen after pressing the “0” key from the wait mode. From here you can format a blank disk without DOS, copy a disk, alter the prologs and/or ignore the epilogs when reading a disk, or ignore most other RWTS errors (via the handy-dandy B942:18). The sector editor and disk copier can use either the RWTS kept in ROM or use an RWTS captured from a program you wish to examine or deprotect, From the Main Menu, one can also enter the sector editor or go to the Memory Management Menu. The built-in sector editor is not the greatest ever, but it has many features. The standard features like switching between ASCII and hex display, reading incrementing sectors. editing bytes. and disassembling the sector are there as well as multiple sector buffering, disk and memory searching, reading sequential sectors into sequential memory, and nibble viewing of a track. In addition to all that, viewing the catalog, free sector map, disk comparison and reading half tracks are also supported. The Memory Management Menu is a repeat of some of the memory move features available through the Wait Mode with the addition of copying sections of auxiliary RAM to useable main RAM for examination. Another option writes a test pattern into main memory for tracking what memory a program takes up. This menu could have been easily incorporated into the Wait Mode, but wasn't for some reason. A New Monitor The modified monitor will be a welcome addition for those who have 65C02s and want to use the extra opcodes available. The disassembler and the mini-assembler are both fully 65C02 compatible (a function not available even in the enhanced //e ROMs). The Step and Trace commands have been resurrected from the grave Apple put them into and may come in handy. The hexdump and disassembler have an ASCH display along the right side of the screen, useful for searching for text strings. This part has a harmless bug in which the ASCII is only printed at the bottom of the screen, It scrolls up normally, but if you start disassembly at the top of the screen the ASCII does not get printed ‘on the same line until the display does start scrolling. I hope this will be corrected in later versions, ‘The Fun Part One of the features that the SP’s advertisement is trying to push is the ability “*to halt a program and instantly swap between two different 64K programs.’” It usually can. The catch is, you have to be able to break the program with an NMI so that i

Showing the first 100000 of 150152 characters.

mp.ls