Files
uv-k5-v3-emulator/qemu
mckero e2d967aa0d Round 67: move the write probe into the model; the launch happens under it after two probe bugs
The probe is an io region overlapped over eight bytes of SRAM (UVK5_RAM_PROBE=0xADDR) whose write handler logs the PC and value and forwards to RAM, so no gdb and no halting. Watching 0x20000C0C: the overlay holds the app's code exactly at +0.05 s, one byte differs at +0.10 s, and the launch happens.

Two probe bugs came first. An io region over RAM intercepts reads too, and with no read handler it answered zero for those eight bytes, so the firmware read zeros where it expected its own data and the guest died with a QMP connection reset every run; forwarding reads fixed it. And a subregion callback's address is relative to that subregion, so forwarding it unchanged wrote to 0x20000000..7 rather than 0x20000C0C..13.

With the probe working the shape is clear: byte-perfect at +0.05 s and one byte wrong 50 ms later. 21 stores were logged into those eight bytes -- eight from 0x0801ae7a, eight from 0x08004874, both writing zero, plus five the summary cut off. Those five are the next thing to read.
2026-10-02 13:53:28 +08:00
..