feat: profile sixteen android and pinball front-ends

ES-DE standalone batch: PSX, DS, GBA, GBC, Xbox, Dolphin and pinball
front-ends, each read from its own source or shipped binary.
This commit is contained in:
Abdessamad Derraz committed 2026-08-11 14:21:29 +02:00
1 parent a372f2abf3
commit 17b4537bde
19 files changed
+5148 -23

No files matched your search

+10 -10
View File
@@ -20,7 +20,7 @@ notes: |
reference below names a method and an IL offset in the CSpect.exe of 3.3.1.0. reference below names a method and an IL offset in the CSpect.exe of 3.3.1.0.
Type and member names in that build are obfuscated and the string literals sit Type and member names in that build are obfuscated and the string literals sit
XOR encoded in one 18146 byte blob, decoded at class load by b[i] ^ i ^ 0xAA. XOR encoded in one 18146 byte blob, decoded at class load by b[i] ^ i ^ 0xAA.
ref: CSpect.exe 3.3.1.0, ReadMe.txt:9-12 ref: CSpect.exe 3.3.1.0, ReadMe.txt:9-11
The machine carries no built-in ROM. A cold reset either loads the Next ROMs The machine carries no built-in ROM. A cold reset either loads the Next ROMs
or allocates them zero filled, 65536 bytes for the ROM banks and 8192 each for or allocates them zero filled, 65536 bytes for the ROM banks and 8192 each for
@@ -47,12 +47,13 @@ notes: |
ref: es_systems.xml zxnext, A.h::A(string[]) IL_0697-IL_06f7, esxDOS.dll ref: es_systems.xml zxnext, A.h::A(string[]) IL_0697-IL_06f7, esxDOS.dll
CRST8.cs:286-302 CRST8.cs:286-302
A positional argument that ends in none of nex, sna, snx, rom or fw and does A positional argument ending in none of nex, sna, snx, rom or fw is taken for
not open as a FAT image is taken for a missing card: CSpect offers to fetch a card image, and when no file sits at that path CSpect offers to fetch one:
one, reads https://zxnext.uk/hosted/ for the first href holding 8gb, unzips it it reads https://zxnext.uk/hosted/ for the first href holding 8gb, unzips it
and copies the single .img inside to the requested path. A .rom argument is and copies the single .img inside to the path that was asked for. The path is
read into a 128 KB buffer entered at 0x6000 instead, and a .fw argument is then accepted only if its MBR and boot sector read. A .rom argument goes into
unpacked through the TBBLUE.FW header. a 128 KB buffer entered at 0x6000 instead, and a .fw argument is unpacked
through the TBBLUE.FW header.
ref: A.h::a(string[]) IL_00a6-IL_012c, A.h::b(string), A.h::B(string, string), ref: A.h::a(string[]) IL_00a6-IL_012c, A.h::b(string), A.h::B(string, string),
a.d::C(string) IL_0086-IL_01db a.d::C(string) IL_0086-IL_01db
@@ -78,7 +79,7 @@ files:
top bank unreadable. The image failing to hold it ends the process through top bank unreadable. The image failing to hold it ends the process through
Environment.FailFast. Bytes 6 and 7 carry the NextZXOS version as Environment.FailFast. Bytes 6 and 7 carry the NextZXOS version as
b[6] + ((b[7] & 0x0f) << 8), and a value of 518 or less clears the flag b[6] + ((b[7] & 0x0f) << 8), and a value of 518 or less clears the flag
that arms a per instruction hook. that arms the program counter watch the CPU runs before each instruction.
source_ref: "CSpect.exe 3.3.1.0 a.H::e() IL_00bd-IL_00c9, a.H::e() IL_0102-IL_0149, a.H::N(int32) IL_0051-IL_0086, A.h::a(string[]) IL_0637-IL_0644" source_ref: "CSpect.exe 3.3.1.0 a.H::e() IL_00bd-IL_00c9, a.H::e() IL_0102-IL_0149, a.H::N(int32) IL_0051-IL_0086, A.h::a(string[]) IL_0637-IL_0644"
- name: enNxtmmc.rom - name: enNxtmmc.rom
@@ -107,7 +108,6 @@ files:
source_ref: "CSpect.exe 3.3.1.0 a.H::e() IL_00eb-IL_00f7, a.H::N(int32) IL_00a1-IL_00b1" source_ref: "CSpect.exe 3.3.1.0 a.H::e() IL_00eb-IL_00f7, a.H::N(int32) IL_00a1-IL_00b1"
- name: TBBLUE.FW - name: TBBLUE.FW
path: "TBBLUE.FW"
system: sinclair-zx-spectrum-next system: sinclair-zx-spectrum-next
required: false required: false
description: "FPGA core firmware" description: "FPGA core firmware"
@@ -116,7 +116,7 @@ files:
Word 0 of its header gives the payload offset as (n + 1) * 512 and word 1 Word 0 of its header gives the payload offset as (n + 1) * 512 and word 1
the payload length as n * 512, and those bytes are written to memory from the payload length as n * 512, and those bytes are written to memory from
0x6000. A .fw file named on the command line takes the same route. 0x6000. A .fw file named on the command line takes the same route.
source_ref: "CSpect.exe 3.3.1.0 a.H::e() IL_0016-IL_00bb, A.h::A(string[]) IL_0164-IL_0197, a.d::C(string)" source_ref: "CSpect.exe 3.3.1.0 a.H::e() IL_0016-IL_00bb, A.h::A(string[]) IL_0164-IL_0197, a.d::C(string) IL_014b-IL_01db"
- name: "<sdcard>.img" - name: "<sdcard>.img"
system: sinclair-zx-spectrum-next system: sinclair-zx-spectrum-next
+239
View File
@@ -0,0 +1,239 @@
emulator: Cxbx-Reloaded
type: standalone
core_classification: embedded_hle
source: "https://github.com/Cxbx-Reloaded/Cxbx-Reloaded"
upstream: "https://github.com/Cxbx-Reloaded/Cxbx-Reloaded"
profiled_date: "2026-08-11"
source_commit: "585c49a50af1255ab155099e06f24505f9c5a800"
core_version: "CI-585c49a"
display_name: "Microsoft - Xbox / Sega Chihiro (Cxbx-Reloaded)"
cores:
- cxbx-reloaded
- cxbx
systems:
- microsoft-xbox
- sega-chihiro
mode: standalone
notes: |
Windows x86 emulator running Xbox and Sega Chihiro titles. The kernel is
reimplemented and XBE code executes natively, so no Xbox flash ROM or MCPX
image is read. The flash window answers the two addresses titles poll with
constants, hardware revision 1.6 among them, and the MCPX device is a PCI stub
whose revision comes from the hardware model. A title is opened as an XBE,
either from an unpacked directory or from an .iso or .xiso mounted to a drive
letter, in which case the default.xbe of the mount is what gets opened.
ref: src/devices/x86/EmuX86.cpp:162-180,
src/devices/MCPXDevice.cpp:36-70,
src/devices/Xbox.cpp:48-58,
src/devices/Xbox.cpp:132-155,
src/gui/WndMain.cpp:89-96,
src/gui/WndMain.cpp:2252-2272
Every path below is relative to the data directory, picked on first run
between the folder holding cxbx.exe, %APPDATA%\Cxbx-Reloaded and a custom
location. EmuDisk, EmuMediaBoard and EmuMu are created under it at startup.
ref: src/common/Settings.cpp:82,
src/common/Settings.cpp:902-937,
src/common/Settings.cpp:968-996,
src/common/FilePaths.cpp:81-137
A title counts as Chihiro when its XBE type says so or a boot.id sits beside
it. Launching one directly requires the media board ROM: its absence ends the
run. The 2 MB image is cut into two 1 MB halves written as Partition2.bin and
Partition3.bin, the old and new SEGABOOT, and the new one is launched, which
then boots the title. A title returning to firmware with an empty launch path
goes back to the same ROM.
ref: src/core/kernel/init/CxbxKrnl.cpp:573-578,
src/core/kernel/init/CxbxKrnl.cpp:590-655,
src/core/kernel/exports/EmuKrnlHal.cpp:546-556,
src/core/kernel/support/EmuFile.cpp:250-253
The JVS base board dumps are memory mapped read/write once the title is
Chihiro, and each one ends the run when it cannot be opened. Byte 0x1F00 of the
QC firmware carries the region, rewritten to one the title's BootID accepts so
the board does not reject the game. Titles read and write all four images
through the JVS patches at offsets of their own choosing; no size, bound or
hash check exists anywhere in that path.
ref: src/core/hle/JVS/JVS.cpp:129-145,
src/core/hle/JVS/JVS.cpp:174-213,
src/core/hle/JVS/JVS.cpp:241-259,
src/core/hle/JVS/JVS.cpp:397-435,
src/core/kernel/init/CxbxKrnl.cpp:1330-1333
On the Xbox side the emulated disk holds the dashboard on Partition2. A title
rebooting with an empty launch path lands there, as does the Open Dashboard
menu entry, and an absent dashboard raises the console's own unrecoverable
error screen rather than an emulator failure.
ref: src/core/kernel/exports/EmuKrnlHal.cpp:546-556,
src/gui/WndMain.cpp:2463-2467,
src/common/xbe/Xbe.cpp:62-96,
src/core/kernel/support/EmuDisk.cpp:269
files:
- name: fpr21042_m29w160et.bin
path: "EmuMediaBoard/fpr21042_m29w160et.bin"
system: sega-chihiro
required: true
size: 2097152
validation: [size]
description: "Chihiro media board flash ROM"
note: >-
Checked for existence, opened, and rejected unless it is exactly 2 MB; each
failure ends the run with a message naming the file and the EmuMediaBoard
folder. Read once, to write out the two SEGABOOT halves when they are
absent. It is also the target a Chihiro title returns to when it reboots
with an empty launch path.
source_ref: "src/core/kernel/init/CxbxKrnl.cpp:596-614, src/core/kernel/support/EmuFile.cpp:251, src/core/kernel/exports/EmuKrnlHal.cpp:550-553"
- name: ic10_g24lc64.bin
path: "EmuMediaBoard/Chihiro/ic10_g24lc64.bin"
system: sega-chihiro
required: true
min_size: 7937
description: "Base board QC microcontroller firmware"
note: >-
Memory mapped read/write at JVS setup, and the run ends when it cannot be
opened. Byte 0x1F00 is dereferenced straight after loading, which is the
floor the size carries: it holds the board region and is rewritten to USA,
export or Japan when the running title's BootID rejects the current value.
Titles read it through JvsFirmwareDownload and overwrite it through
JvsFirmwareUpload.
source_ref: "src/core/hle/JVS/JVS.cpp:181-188, src/core/hle/JVS/JVS.cpp:241-259, src/core/hle/JVS/JVS.cpp:484-523"
- name: pc20_g24lc64.bin
path: "EmuMediaBoard/Chihiro/pc20_g24lc64.bin"
system: sega-chihiro
required: true
description: "Base board SC microcontroller firmware"
note: >-
Memory mapped read/write at JVS setup, and the run ends when it cannot be
opened. Served to titles through JvsScFirmwareDownload and rewritten
through JvsScFirmwareUpload.
source_ref: "src/core/hle/JVS/JVS.cpp:182-192, src/core/hle/JVS/JVS.cpp:671-709"
- name: ic11_24lc024.bin
path: "EmuMediaBoard/Chihiro/ic11_24lc024.bin"
system: sega-chihiro
required: true
description: "Base board configuration EEPROM"
note: >-
Memory mapped read/write at JVS setup, and the run ends when it cannot be
opened. Writes from JvsEEPROM_Write are synced back to disk immediately,
so cabinet settings a title stores persist across runs.
source_ref: "src/core/hle/JVS/JVS.cpp:183-196, src/core/hle/JVS/JVS.cpp:437-482"
- name: backup_ram.bin
path: "EmuMediaBoard/Chihiro/backup_ram.bin"
system: sega-chihiro
required: false
has_builtin: true
size_note: "Created as 128 KB of zeros when absent, then memory mapped"
description: "Base board backup memory"
note: >-
The only one of the four JVS images the emulator will produce itself: when
the file is missing it writes 128 KB of zeros and maps that, so a fresh
board starts blank. Titles keep bookkeeping and high scores here through
JvsBACKUP_Read and JvsBACKUP_Write.
source_ref: "src/core/hle/JVS/JVS.cpp:184-213, src/core/hle/JVS/JVS.cpp:397-435"
- name: Partition2.bin
path: "EmuMediaBoard/Partition2.bin"
system: sega-chihiro
required: false
unsourceable: "first megabyte of the media board ROM, written by the emulator, with no distributed form of its own"
description: "SEGABOOT, old revision"
note: >-
Written by the emulator from the first megabyte of fpr21042_m29w160et.bin
when either half is missing, and mounted as the mbrom0 device. Supplying it
does not remove the need for the ROM, whose existence is checked before the
extraction block is reached.
source_ref: "src/core/kernel/init/CxbxKrnl.cpp:616-648, src/core/kernel/support/EmuFile.cpp:252, src/core/kernel/support/EmuMediaBoard.cpp:230-233"
- name: Partition3.bin
path: "EmuMediaBoard/Partition3.bin"
system: sega-chihiro
required: false
unsourceable: "second megabyte of the media board ROM, written by the emulator, with no distributed form of its own"
description: "SEGABOOT, current revision"
note: >-
Written from the second megabyte of fpr21042_m29w160et.bin under the same
condition as the old half, mounted as the mbrom1 device, and launched as
the XBE that boots the title.
source_ref: "src/core/kernel/init/CxbxKrnl.cpp:616-653, src/core/kernel/support/EmuFile.cpp:253, src/core/kernel/support/EmuMediaBoard.cpp:230-233"
- name: xboxdash.xbe
path: "EmuDisk/Partition2/xboxdash.xbe"
system: microsoft-xbox
required: false
description: "Xbox dashboard executable"
note: >-
Read from the shell partition of the emulated disk when a title reboots
with an empty launch path and when the Open Dashboard menu entry is used.
Its absence is handled as the console handles it, with the unrecoverable
error screen and the LED sequence that goes with it, the code carrying the
dashboard's own reason when the launch data page supplies one. Titles run
without it.
source_ref: "src/core/kernel/exports/EmuKrnlHal.cpp:546-556, src/gui/WndMain.cpp:2463-2467, src/common/xbe/Xbe.cpp:62-96, src/core/kernel/support/EmuDisk.cpp:269"
- name: EEPROM.bin
path: "EEPROM.bin"
system: microsoft-xbox
required: false
has_builtin: true
size: 256
validation: [size]
description: "Xbox EEPROM image"
note: >-
Opened at startup and mapped read/write; the file is created and filled
with defaults when it does not exist, and a file that is not 256 bytes ends
the run. Section checksums are recomputed on every load. The hard disk key
is taken from it, and the game region it carries becomes the factory
region. The GUI exposes an editor over the same file.
source_ref: "src/common/EmuEEPROM.cpp:93-193, src/common/FilePaths.cpp:125, src/core/kernel/init/CxbxKrnl.cpp:958, src/gui/DlgEepromConfig.cpp:212-230"
- name: keys.bin
path: "keys.bin"
system: microsoft-xbox
required: false
size: 32
validation: [size]
description: "Xbox EEPROM and certificate keys"
note: >-
Two 16 byte keys read in order, the EEPROM key then the certificate key,
as produced by dump-xbox. A file of any other length is refused with a
warning naming the expected length, and an absent file only costs the
ability to read save data from a real console. The certificate key derives
the LAN, signature and alternate signature keys of the running title; the
EEPROM key checks the EEPROM header and is read again by the EEPROM editor
to recompute the checksum it writes.
source_ref: "src/common/FilePaths.cpp:139-172, src/core/kernel/common/types.h:2232, src/core/kernel/init/CxbxKrnl.cpp:113-132, src/common/EmuEEPROM.cpp:184-191, src/gui/DlgEepromConfig.cpp:200-207"
- name: dokan2.dll
required: false
unsourceable: "signed kernel mode driver package installed by the Dokany runtime installer, not a file placed in a data folder"
description: "Dokany user mode library"
note: >-
Loaded by name with every entry point resolved individually, and the
failure message tells the user to install the upstream signed Dokany
runtime. It backs the only path that reads a disc image: an .iso or .xiso
is mounted to a drive letter and the default.xbe of the mount is opened, so
without it only unpacked titles load. The build produces an import library
from the Dokany definition file and takes headers from the vendored tree,
but ships no runtime of its own.
source_ref: "src/gui/xiso/XisoMount.cpp:36-61, src/gui/WndMain.cpp:2252-2272, projects/dokany/CMakeLists.txt:8-10, projects/cxbx/CMakeLists.txt:17-18"
exclusion_note: >
Five host libraries the code names are not listed. ntdll.dll and the XInput
libraries tried in turn, xinput1_4, xinput1_3 and xinput9_1_0, are Windows
components resolved by the loader, and cxbxr-emu.dll is the emulator's own
build output shipped beside cxbx.exe. xbdm.dll is not opened at all: the name
is compared against the import table of the loaded XBE so the debug monitor
imports can be thunked to the emulator's own implementations. Two further
files belong to the title rather than the system: boot.id, read from the title
directory for its region flags, and default.xbe. logo.bmp is only the name
offered in the open and save dialogs of the XBE logo editor.
ref: src/common/input/XInputPad.cpp:100-120,
src/core/kernel/init/CxbxKrnl.cpp:356-365,
src/devices/chihiro/MediaBoard.cpp:46-57,
src/gui/WndMain.cpp:880-890
+254
View File
@@ -0,0 +1,254 @@
emulator: Dolphin MMJR
type: standalone
core_classification: community_fork
source: "https://github.com/acidtech/Dolphin-MMJR"
upstream: "https://github.com/weihuoya/dolphin"
profiled_date: "2026-08-11"
source_commit: "1b095b64857c2eabb49a42cc56ffd9d7881bc263"
core_version: "11460 - bankaimaster999"
display_name: "Nintendo - GameCube / Wii (Dolphin MMJR)"
cores:
- dolphin-mmjr
systems:
- nintendo-gamecube
- nintendo-wii
mode: standalone
notes: |
Android-only Dolphin fork continuing the MMJ line, published as the org.mm.jr
package. The repositories it released from are gone, including the
Dolphin-MMJR1 link in its own README; this reading is taken from a surviving
copy that carries the release build metadata of the app, applicationId
org.mm.jr and versionCode 15808.
ref: Source/Android/app/build.gradle:23-29,
Source/Android/app/release/output-metadata.json
Two roots. The user directory is dolphin-mmjr at the root of external
storage. The Sys directory is extracted from the APK assets into the app's
internal files directory, and the first run after a versionCode change
deletes it and extracts it again, so nothing placed there survives an update.
Paths below are relative to the user directory; entries with no path are read
only from the Sys directory and name their location in their note.
ref: Source/Android/app/src/main/java/org/dolphinemu/dolphinemu/utils/DirectoryInitialization.java:93-134,
Source/Core/Common/CommonPaths.h:22-24, Source/Core/Common/FileUtil.cpp:756-807
The GameCube boot ROM is looked up as GC/<REGION>/IPL.bin, the region
directory being NTSC-J to JAP, NTSC-U to USA and PAL to EUR, in the user
directory first and the Sys directory second. Booting the IPL itself hashes
the whole file with crc32 and warns on an unknown dump, and again when a PAL
dump answers a non-PAL boot. SkipIPL defaults to true, so games start without
it.
ref: Source/Core/Core/ConfigManager.cpp:835-849, Source/Core/Core/ConfigManager.cpp:861-868,
Source/Core/Core/Boot/Boot.cpp:295-337, Source/Core/Core/Config/MainSettings.cpp:18
Fonts follow the IPL. When a dump is present the Shift JIS and Windows-1252
fonts are read out of it at offsets 0x1aff00 and 0x1fcf00, for 0x4a24d and
0x2575 bytes; otherwise the standalone font files are loaded whole, and the
bundled ones have different padding from the console fonts.
ref: Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:99-127,
Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:159-172,
Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:199-240
DSP HLE is the default and reads dsp_coef.bin alone, for polyphase resampling
coefficients, skipping any file that is not 0x1000 bytes. DSP LLE, reached by
setting DSPHLE to False in Dolphin.ini, loads both ROMs from GC/ in the user
directory then Sys/GC/, rejects either at the wrong size and refuses to start
when one is missing. Both are byte-swapped into memory and the pair is then
hashed with adler32 against six known combinations.
ref: Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:120-138,
Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:140-176,
Source/Core/Core/HW/DSPHLE/UCodes/AX.cpp:45-58,
Source/Core/Core/DSP/DSPCore.cpp:38-105, Source/Core/Core/HW/DSP.cpp:190
Wii emulation reads keys.bin from the NAND root every time the key store is
built, and keeps the built-in keys when it is absent. SYSCONF is read through
the emulated filesystem and rebuilt unless it is exactly 0x4000 bytes,
setting.txt is read for its serial number then deleted and written again, and
the WiiConnect24 files shipped in Sys/Wii are copied into the NAND without
overwriting what is there. A missing SD card image is created at 128 MB.
ref: Source/Core/Core/IOS/IOSC.cpp:94, Source/Core/Core/IOS/IOSC.cpp:136-140,
Source/Core/Core/IOS/IOSC.cpp:559-584, Source/Core/Core/SysConf.cpp:55-66,
Source/Core/Core/Boot/Boot_BS2Emu.cpp:228-256, Source/Core/Core/WiiRoot.cpp:217-227,
Source/Core/Core/IOS/SDIO/SDIOSlot0.cpp:60-79
Every boot looks for a symbol map named after the running game ID, in Maps/
then Sys/Maps/, and reloads it whenever the running title changes. The game
ID comes from the disc metadata, not from a debugger setting.
ref: Source/Core/Core/Boot/Boot.cpp:253-290, Source/Core/Core/ConfigManager.cpp:698-720,
Source/Core/Core/ConfigManager.cpp:742-754
files:
- name: IPL.bin
path: GC/USA/IPL.bin
system: nintendo-gamecube
required: false
hle_fallback: true
region: [north-america]
size: 2097152
validation: [crc32]
description: "GameCube boot ROM, NTSC-U directory"
note: "Read whole into a 2 MiB buffer with no size check, then descrambled from 0x100 for 0x1afe00 bytes. The crc32 gate runs when the IPL itself is booted, and the four non-PAL dumps pass here without complaint."
source_ref: "Source/Core/Core/ConfigManager.cpp:861-868, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:99-112, Source/Core/Core/HW/EXI/EXI_DeviceIPL.h:43, Source/Core/Core/Boot/Boot.cpp:296-330"
- name: IPL.bin
path: GC/EUR/IPL.bin
system: nintendo-gamecube
required: false
hle_fallback: true
region: [europe]
size: 2097152
validation: [crc32]
description: "GameCube boot ROM, PAL directory"
note: "The two PAL dumps are the ones this directory takes without a mismatch warning."
source_ref: "Source/Core/Core/ConfigManager.cpp:835-849, Source/Core/Core/Boot/Boot.cpp:298-337"
- name: IPL.bin
path: GC/JAP/IPL.bin
system: nintendo-gamecube
required: false
hle_fallback: true
region: [japan]
size: 2097152
validation: [crc32]
description: "GameCube boot ROM, NTSC-J directory"
note: "JAP is the only Japanese directory name this fork knows. FindIPLDump, which serves the font path, scans USA then EUR then JAP and stops at the first hit."
source_ref: "Source/Core/Common/CommonPaths.h:32-34, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:174-186"
- name: font_western.bin
path: null
required: false
hle_fallback: true
description: "Windows-1252 font, loaded at 0x1fcf00"
note: "Read from GC/ in the Sys directory, with no user directory fallback. Skipped in favour of the IPL dump whenever one is found."
source_ref: "Source/Core/Common/CommonPaths.h:105, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:126, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:199-240"
- name: font_japanese.bin
path: null
required: false
hle_fallback: true
description: "Shift JIS font, loaded at 0x1aff00"
note: "Read from GC/ in the Sys directory, with no user directory fallback. Skipped in favour of the IPL dump whenever one is found."
source_ref: "Source/Core/Common/CommonPaths.h:106, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:125, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:199-240"
- name: dsp_rom.bin
path: GC/dsp_rom.bin
required: false
hle_fallback: true
size: 8192
validation: [size]
known_hash_adler32: "0x66f334fe"
adler32_byteswap: true
description: "DSP instruction ROM"
note: "DSP LLE only, and LLE aborts when the file is absent or not 8192 bytes. The adler32 is taken over the byte-swapped image and the value here is the Nintendo pair; five replacement pairs are also accepted."
source_ref: "Source/Core/Common/CommonPaths.h:108, Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:120-152, Source/Core/Core/DSP/DSPCore.h:35, Source/Core/Core/DSP/DSPCore.cpp:38-80"
- name: dsp_coef.bin
path: GC/dsp_coef.bin
required: false
hle_fallback: true
size: 4096
validation: [size]
known_hash_adler32: "0xf3b93527"
adler32_byteswap: true
description: "DSP coefficient ROM"
note: "Read by DSP LLE alongside the instruction ROM, and by the AX ucode under HLE for polyphase resampling, which drops any file that is not 0x1000 bytes and plays on without it."
source_ref: "Source/Core/Common/CommonPaths.h:109, Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:120-152, Source/Core/Core/HW/DSPHLE/UCodes/AX.cpp:45-70, Source/Core/Core/DSP/DSPCore.h:49"
- name: codehandler.bin
path: null
required: false
description: "Gecko code handler"
note: "Read from the root of the Sys directory when cheats are enabled, and written into guest memory between the installer bounds; too large a file is refused and cheats stay off."
source_ref: "Source/Core/Common/CommonPaths.h:124, Source/Core/Core/GeckoCode.cpp:121-136"
- name: keys.bin
path: Wii/keys.bin
system: nintendo-wii
required: false
hle_fallback: true
size: 1024
validation: [size]
description: "BootMii key dump, console keys and identity"
note: "Read at every key store construction, so on every Wii title. Supplies the console private key and signature, the MS and CA identifiers, the NAND key and HMAC and the backup key. A short read leaves the built-in keys in place, the structure being fixed at 0x400 bytes."
source_ref: "Source/Core/Core/IOS/IOSC.cpp:94, Source/Core/Core/IOS/IOSC.cpp:136-140, Source/Core/Core/IOS/IOSC.cpp:559-584"
- name: SYSCONF
path: Wii/shared2/sys/SYSCONF
system: nintendo-wii
required: false
hle_fallback: true
size: 16384
validation: [size]
description: "Wii system configuration"
note: "Opened through the emulated filesystem and accepted only at 0x4000 bytes; anything else is replaced by a freshly generated one."
source_ref: "Source/Core/Common/CommonPaths.h:90, Source/Core/Core/SysConf.cpp:20, Source/Core/Core/SysConf.cpp:55-66"
- name: setting.txt
path: Wii/title/00000001/00000002/data/setting.txt
system: nintendo-wii
required: false
hle_fallback: true
size: 256
validation: [size]
description: "Wii region and language settings"
note: "Read for its serial number at Wii boot, then deleted and written again from the emulated region settings. The read fills a fixed 0x100 byte buffer, so a shorter file yields nothing."
source_ref: "Source/Core/Common/CommonPaths.h:122, Source/Core/Common/SettingsHandler.h:22-27, Source/Core/Core/Boot/Boot_BS2Emu.cpp:228-256"
- name: sd.raw
path: Wii/sd.raw
system: nintendo-wii
required: false
hle_fallback: true
description: "Wii SD card image"
note: "Opened read-write when the SD device is opened; a 128 MB image is created when the file is missing."
source_ref: "Source/Core/Common/CommonPaths.h:119, Source/Core/Common/FileUtil.cpp:802, Source/Core/Core/IOS/SDIO/SDIOSlot0.cpp:60-79"
- name: wiitdb.txt
path: Load/wiitdb.txt
aliases: [titles.txt]
required: false
description: "user title database"
note: "One title id equals name pair per line, ids of four characters and up. titles.txt is read only when wiitdb.txt yields nothing. Overlays the per-language databases shipped in the Sys directory."
source_ref: "Source/Core/Core/TitleDatabase.cpp:26-48, Source/Core/Core/TitleDatabase.cpp:50-63, Source/Core/Core/TitleDatabase.cpp:86-94"
- name: mios-ipl.map
path: Maps/mios-ipl.map
required: false
description: "MIOS symbol map"
note: "Read from Maps/ in the user directory when MIOS starts, and a successful load re-applies the HLE function patches against the symbols it names."
source_ref: "Source/Core/Core/IOS/MIOS.cpp:47, Source/Core/Core/IOS/MIOS.cpp:55-66"
- name: GFZE01.map
path: null
required: false
description: "symbol map for game id GFZE01"
note: "Reached by the per-title lookup, which reads Maps/<game id>.map from the user directory then the Sys directory. Ships in Maps/ inside the Sys directory."
source_ref: "Source/Core/Core/Boot/Boot.cpp:253-290"
- name: GMBE8P.map
path: null
required: false
description: "symbol map for game id GMBE8P"
note: "Reached by the per-title lookup, which reads Maps/<game id>.map from the user directory then the Sys directory. Ships in Maps/ inside the Sys directory."
source_ref: "Source/Core/Core/Boot/Boot.cpp:253-290"
valid_bios_crc32:
ipl_ntsc:
- { crc32: "6DAC1F2A", name: "NTSC v1.0" }
- { crc32: "D5E6FEEA", name: "NTSC v1.1" }
- { crc32: "86573808", name: "NTSC v1.2" }
- { crc32: "667D0B64", name: "MPAL v1.1 (Brazil)" }
ipl_pal:
- { crc32: "4F319F43", name: "PAL v1.0" }
- { crc32: "AD1B7F16", name: "PAL v1.2" }
exclusion_note: >
The NAND importer, which reads nand.bin and writes clientca.pem,
clientcakey.pem and rootca.pem, and the signature database totaldb.dsy are
reachable only from the Qt front-end, which the Android build does not
compile: the APK builds the core libraries and Source/Android/jni, and the
JNI surface exposes no NAND import or WAD install. libusb is switched off for
Android, so the Bluetooth passthrough firmware paths are out as well.
ref: Source/CMakeLists.txt:60-65, Source/Core/CMakeLists.txt:1-16,
Source/Core/DolphinQt/MainWindow.cpp:1510, Source/Core/DolphinQt/MenuBar.cpp:1092,
Source/Core/DolphinQt/MenuBar.cpp:1156, CMakeLists.txt:630-644
+426
View File
@@ -0,0 +1,426 @@
emulator: Dolphin MMJR2
type: standalone
core_classification: community_fork
source: "https://github.com/nachoverdon/Dolphin-MMJR2"
upstream: "https://github.com/dolphin-emu/dolphin"
profiled_date: "2026-08-11"
source_commit: "4d0fdb8eea616320e967408cf5547c72a95196f3"
core_version: "2.0-18025"
display_name: "Nintendo - GameCube / Wii (Dolphin MMJR2)"
cores:
- dolphin-mmjr2
systems:
- nintendo-gamecube
- nintendo-wii
mode: standalone
notes: |
Android-only Dolphin fork published as the org.dolphinemu.mmjr package. The
repositories it was developed and released from are gone; this reading is
taken from a surviving copy carrying the whole maintainer commit line, up to
the last one, which sets the version string to 2.0-18025. The tree is a
selective merge of Dolphin Official carrying that label rather than a
checkout of it: at Dolphin 5.0-18025 the memory subsystem has already moved
behind Core::System, and here it has not, so no single Dolphin revision
matches and no upstream pin is declared.
ref: Source/Android/app/build.gradle:32, Source/Android/app/build.gradle:135
Two roots. The user directory is mmjr-revamp at the root of external storage.
The Sys directory is extracted from the APK assets into the app's internal
files directory, and a change of git revision deletes it and extracts it
again, so nothing placed there survives an update. The build drops Resources
and Themes from the assets copy. Paths below are relative to the user
directory; entries with no path are read only from the Sys directory and name
their location in their note.
ref: Source/Android/app/src/main/java/org/dolphinemu/dolphinemu/utils/DirectoryInitialization.java:103,
Source/Android/app/src/main/java/org/dolphinemu/dolphinemu/utils/DirectoryInitialization.java:138-155,
Source/Core/Common/CommonPaths.h:23, Source/Android/jni/CMakeLists.txt:37-42
The GameCube boot ROM is looked up as GC/<REGION>/IPL.bin, in the user
directory first and the Sys directory second. The region directory is USA for
NTSC-U, EUR for PAL and JAP for NTSC-J: JPN also exists but only the memory
card folder path asks for it, every other caller takes the legacy default.
Booting the IPL itself hashes the whole file with crc32 and warns on an
unknown dump, then warns again when the dump and the boot region disagree on
PAL. SkipIPL defaults to true, so games start without it.
ref: Source/Core/Common/CommonPaths.h:34-35,
Source/Core/Core/Config/MainSettings.cpp:567-592,
Source/Core/Core/Config/MainSettings.cpp:594-600,
Source/Core/Core/Config/MainSettings.cpp:675-723,
Source/Core/Core/Boot/Boot.cpp:323-327, Source/Core/Core/Boot/Boot.cpp:408-442,
Source/Core/Core/Boot/Boot.cpp:444-449,
Source/Core/Core/Config/MainSettings.cpp:35
Fonts follow the IPL. When a dump is present the Shift JIS and Windows-1252
fonts are read out of it at offsets 0x1aff00 and 0x1fcf00, for 0x4a24d and
0x2575 bytes; otherwise the standalone font files are loaded whole, and the
bundled ones have different padding from the console fonts.
ref: Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:102-131,
Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:175-187,
Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:200-241
DSP HLE is the default and reads dsp_coef.bin alone, for polyphase resampling
coefficients, skipping any file that is not 0x1000 bytes. DSP LLE, reached by
setting DSPHLE to False, loads both ROMs from GC/ in the user directory then
Sys/GC/, rejects either at the wrong size, and a rejection aborts the
emulation thread. Both are byte-swapped into memory and the pair is then
hashed with adler32 against seven known combinations.
ref: Source/Core/Core/Config/MainSettings.cpp:40,
Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:87-105,
Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:107-120,
Source/Core/Core/HW/DSPHLE/UCodes/AX.cpp:42-69,
Source/Core/Core/DSP/DSPCore.cpp:28-71, Source/Core/Core/Core.cpp:556-559
Wii emulation reads keys.bin from the NAND root every time the key store is
built, and keeps the built-in keys when it is absent. SYSCONF is read through
the emulated filesystem and rebuilt unless it is exactly 0x4000 bytes, and
setting.txt is read for its serial number then written again from the
emulated region settings. A missing SD card image is created at 128 MB. The
three SSL files are hashed with sha256 against values held in the source and
refused on a mismatch, once per session.
ref: Source/Core/Core/IOS/IOSC.cpp:211, Source/Core/Core/IOS/IOSC.cpp:623-649,
Source/Core/Core/SysConf.cpp:19, Source/Core/Core/SysConf.cpp:54-65,
Source/Core/Core/Boot/Boot_BS2Emu.cpp:341-352,
Source/Core/Core/IOS/SDIO/SDIOSlot0.cpp:90-107,
Source/Core/Core/IOS/Network/SSL.cpp:135-181
The WiiConnect24 tree is copied out of Sys/Wii into the NAND at every Wii
boot, one file at a time, and a file already present in the NAND is left
alone. Copies placed under Wii/shared2/wc24 are therefore the ones that
survive, and the shipped blanks only fill what is still missing. Dolphin
itself reads nwc24msg.cfg and nwc24dl.bin back out of the NAND; the rest are
there because titles expect them.
ref: Source/Core/Core/WiiRoot.cpp:288-322, Source/Core/Core/WiiRoot.cpp:330-335,
Source/Core/Core/IOS/Network/KD/NWC24Config.cpp:24-38,
Source/Core/Core/IOS/Network/KD/NWC24DL.cpp:23-32
NAND import is compiled into the Android build and wired to both launchers. A
BootMii image writes keys.bin and the three certificates into the NAND root,
the certificates being carved out of the IOS13 content by searching for their
DER headers. The keys have to be appended to the image: the callback that
would ask for a separate OTP dump answers with an empty path here.
ref: Source/Android/jni/WiiUtils.cpp:97-116,
Source/Android/app/src/main/java/org/dolphinemu/dolphinemu/ui/main/MainActivity.java:240,
Source/Core/DiscIO/NANDImporter.cpp:26-40,
Source/Core/DiscIO/NANDImporter.cpp:189-256,
Source/Core/DiscIO/NANDImporter.cpp:258-267
Every boot looks for a symbol map named after the running game ID, in Maps/
in the user directory alone, and reloads it whenever the running title
changes. The game ID comes from the disc or TMD metadata, not from a debugger
setting. No map ships with the build.
ref: Source/Core/Core/Boot/Boot.cpp:373-399,
Source/Core/Core/ConfigManager.cpp:153-162,
Source/Core/Core/ConfigManager.cpp:189-199
files:
- name: IPL.bin
path: GC/USA/IPL.bin
system: nintendo-gamecube
required: false
hle_fallback: true
region: [north-america]
size: 2097152
validation: [crc32]
description: "GameCube boot ROM, NTSC-U directory"
note: "Read whole into a 2 MiB buffer with no size check, then descrambled from 0x100 for 0x1afe00 bytes. The crc32 gate runs when the IPL itself is booted and only warns; the four non-PAL dumps, the Brazilian MPAL one included, pass here without complaint."
source_ref: "Source/Core/Core/Config/MainSettings.cpp:594-600, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:105-113, Source/Core/Core/HW/EXI/EXI_DeviceIPL.h:43, Source/Core/Core/Boot/Boot.cpp:408-442, Source/Core/Core/Boot/Boot.cpp:444-449"
- name: IPL.bin
path: GC/EUR/IPL.bin
system: nintendo-gamecube
required: false
hle_fallback: true
region: [europe]
size: 2097152
validation: [crc32]
description: "GameCube boot ROM, PAL directory"
note: "The two PAL dumps are the ones this directory takes without a mismatch warning."
source_ref: "Source/Core/Core/Config/MainSettings.cpp:580-581, Source/Core/Core/Boot/Boot.cpp:444-449"
- name: IPL.bin
path: GC/JAP/IPL.bin
system: nintendo-gamecube
required: false
hle_fallback: true
region: [japan]
size: 2097152
validation: [crc32]
description: "GameCube boot ROM, NTSC-J directory"
note: "JPN is defined alongside JAP but the boot ROM callers use the legacy default, so JAP is the directory read. FindIPLDump, which serves the font path, scans USA then EUR then JAP and stops at the first hit."
source_ref: "Source/Core/Common/CommonPaths.h:34-35, Source/Core/Core/Config/MainSettings.cpp:574-575, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:175-187"
- name: font_western.bin
path: null
required: false
hle_fallback: true
description: "Windows-1252 font, loaded at 0x1fcf00"
note: "Read from GC/ in the Sys directory, with no user directory fallback. Skipped in favour of the IPL dump whenever one is found."
source_ref: "Source/Core/Common/CommonPaths.h:117, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:130, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:200-241"
- name: font_japanese.bin
path: null
required: false
hle_fallback: true
description: "Shift JIS font, loaded at 0x1aff00"
note: "Read from GC/ in the Sys directory, with no user directory fallback. Skipped in favour of the IPL dump whenever one is found."
source_ref: "Source/Core/Common/CommonPaths.h:118, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:129, Source/Core/Core/HW/EXI/EXI_DeviceIPL.cpp:200-241"
- name: dsp_rom.bin
path: GC/dsp_rom.bin
required: false
hle_fallback: true
size: 8192
validation: [size]
known_hash_adler32: "0x66f334fe"
adler32_byteswap: true
description: "DSP instruction ROM"
note: "DSP LLE only, and a file that is absent or not 8192 bytes fails initialisation, which aborts the emulation thread. The adler32 is taken over the byte-swapped image and the value here is the Nintendo pair; six replacement pairs are also accepted."
source_ref: "Source/Core/Common/CommonPaths.h:120, Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:87-105, Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:107-120, Source/Core/Core/DSP/DSPCore.h:44, Source/Core/Core/DSP/DSPCore.cpp:28-71"
- name: dsp_coef.bin
path: GC/dsp_coef.bin
required: false
hle_fallback: true
size: 4096
validation: [size]
known_hash_adler32: "0xf3b93527"
adler32_byteswap: true
description: "DSP coefficient ROM"
note: "Read by DSP LLE alongside the instruction ROM, and by the AX ucode under HLE for polyphase resampling, which drops any file that is not 0x1000 bytes and plays on without it."
source_ref: "Source/Core/Common/CommonPaths.h:121, Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:87-105, Source/Core/Core/HW/DSPLLE/DSPLLE.cpp:107-120, Source/Core/Core/HW/DSPHLE/UCodes/AX.cpp:42-69, Source/Core/Core/DSP/DSPCore.h:58"
- name: codehandler.bin
path: null
required: false
description: "Gecko code handler"
note: "Read from the root of the Sys directory when cheats are enabled, and written into guest memory between the installer bounds; too large a file is refused and cheats stay off."
source_ref: "Source/Core/Common/CommonPaths.h:139, Source/Core/Core/GeckoCode.cpp:120-134, Source/Core/Core/GeckoCode.cpp:142-144"
- name: keys.bin
path: Wii/keys.bin
system: nintendo-wii
required: false
hle_fallback: true
size: 1024
validation: [size]
description: "BootMii key dump, console keys and identity"
note: "Read at every key store construction, so on every Wii title. Supplies the console private key and signature, the MS and CA identifiers, the NAND key and HMAC and the backup key. A short read leaves the built-in keys in place, the structure being fixed at 0x400 bytes. NAND import writes this file from the keys appended to the image."
source_ref: "Source/Core/Core/IOS/IOSC.cpp:92, Source/Core/Core/IOS/IOSC.cpp:211, Source/Core/Core/IOS/IOSC.cpp:623-649, Source/Core/DiscIO/NANDImporter.cpp:258-267"
- name: SYSCONF
path: Wii/shared2/sys/SYSCONF
system: nintendo-wii
required: false
hle_fallback: true
size: 16384
validation: [size]
description: "Wii system configuration"
note: "Opened through the emulated filesystem and accepted only at 0x4000 bytes; anything else is replaced by a freshly generated one."
source_ref: "Source/Core/Common/CommonPaths.h:102, Source/Core/Core/SysConf.cpp:19, Source/Core/Core/SysConf.cpp:54-65"
- name: setting.txt
path: Wii/title/00000001/00000002/data/setting.txt
system: nintendo-wii
required: false
hle_fallback: true
size: 256
validation: [size]
description: "Wii region and language settings"
note: "Read for its serial number and model at Wii boot, then written again from the emulated region settings. The read fills a fixed 0x100 byte buffer, so a shorter file yields nothing."
source_ref: "Source/Core/Common/CommonPaths.h:137, Source/Core/Common/SettingsHandler.h:21-26, Source/Core/Core/Boot/Boot_BS2Emu.cpp:341-353"
- name: WiiSD.raw
path: Load/WiiSD.raw
system: nintendo-wii
required: false
hle_fallback: true
description: "Wii SD card image"
note: "Opened read-write when the SD device is opened; a 128 MB image is created when the file is missing. The configured override is empty by default, so the file stays under Load/."
source_ref: "Source/Core/Common/CommonPaths.h:134, Source/Core/Common/FileUtil.cpp:998, Source/Core/Core/Config/MainSettings.cpp:289, Source/Core/Core/IOS/SDIO/SDIOSlot0.cpp:90-107"
- name: clientca.pem
path: Wii/clientca.pem
system: nintendo-wii
required: false
hle_fallback: true
sha256: "229ec678525e060588e8ea23e5459ec14af3c2ebb7b9e69ec46b0faf011730d9"
validation: [sha256]
description: "console SSL client certificate"
note: "Read from the NAND root when a title asks for the built-in client certificate, and refused when the sha256 does not match the value in the source. One panic alert per IOS instance covers this file and the key together. NAND import carves it out of the IOS13 content by its DER header."
source_ref: "Source/Core/Core/IOS/Network/SSL.cpp:135-138, Source/Core/Core/IOS/Network/SSL.cpp:148-181, Source/Core/Core/IOS/Network/SSL.cpp:383-390, Source/Core/DiscIO/NANDImporter.cpp:224"
- name: clientcakey.pem
path: Wii/clientcakey.pem
system: nintendo-wii
required: false
hle_fallback: true
sha256: "723be9b32c3afb83a4a3757adf352529e90c0ad6fad52509963ba8942ae625df"
validation: [sha256]
description: "console SSL client private key"
note: "Read alongside the client certificate and parsed as the private key for it; either one failing leaves the connection without a client certificate."
source_ref: "Source/Core/Core/IOS/Network/SSL.cpp:139-142, Source/Core/Core/IOS/Network/SSL.cpp:383-395, Source/Core/DiscIO/NANDImporter.cpp:225"
- name: rootca.pem
path: Wii/rootca.pem
system: nintendo-wii
required: false
hle_fallback: true
sha256: "c5b0f8dfcec6b9ed2ac38b8bc69a4db7c209dc177d243c8df2bddf9e39171e5f"
validation: [sha256]
description: "console SSL root CA certificate"
note: "Read when a title asks for the built-in root CA, on the same sha256 check as the client pair."
source_ref: "Source/Core/Core/IOS/Network/SSL.cpp:143-146, Source/Core/Core/IOS/Network/SSL.cpp:449-455, Source/Core/DiscIO/NANDImporter.cpp:226"
- name: nand.bin
path: null
system: nintendo-wii
required: false
size: [553648128, 553649152]
validation: [size]
description: "BootMii NAND backup"
note: "Chosen through the app's import entry, not read from a fixed location. Accepted at the bare image size or that plus the 0x400 byte key block, and refused at any other. The pages are read 0x800 at a time with the 0x40 byte ECC block skipped. Import writes keys.bin and the three certificates, then unpacks the filesystem."
source_ref: "Source/Android/jni/WiiUtils.cpp:97-116, Source/Core/DiscIO/NANDImporter.cpp:19, Source/Core/DiscIO/NANDImporter.cpp:26-40, Source/Core/DiscIO/NANDImporter.cpp:42-72"
- name: mii.bin
path: Wii/mii.bin
system: nintendo-wii
required: false
description: "Mii database imported into the emulated Wii Remote"
note: "Read from the NAND root when an emulated Wii Remote is reset, and copied into both Mii blocks of its EEPROM. Absent, the EEPROM keeps its default contents."
source_ref: "Source/Core/Core/HW/WiimoteEmu/WiimoteEmu.cpp:156-165"
- name: nwc24msg.cfg
path: Wii/shared2/wc24/nwc24msg.cfg
system: nintendo-wii
required: false
size: 1024
validation: [size]
description: "WiiConnect24 account configuration"
note: "Read as one packed structure, so a shorter file fails the read and a default configuration is generated and written back. A file that reads is then checked for the WcCf magic, its own checksum, an id generation under 0x20 and version 8, each mismatch logged."
source_ref: "Source/Core/Core/IOS/Network/KD/NWC24Config.cpp:17, Source/Core/Core/IOS/Network/KD/NWC24Config.cpp:24-38, Source/Core/Core/IOS/Network/KD/NWC24Config.cpp:90-117, Source/Core/Core/IOS/Network/KD/NWC24Config.h:87-109"
- name: nwc24dl.bin
path: Wii/shared2/wc24/nwc24dl.bin
system: nintendo-wii
required: false
size: 63488
validation: [size]
description: "WiiConnect24 download task list"
note: "Read as one packed structure of a 128 byte header plus 120 records and 120 entries, so a shorter file fails the read and leaves the list empty. A file that reads is checked for the WcDl magic and version 1."
source_ref: "Source/Core/Core/IOS/Network/KD/NWC24DL.cpp:16, Source/Core/Core/IOS/Network/KD/NWC24DL.cpp:23-32, Source/Core/Core/IOS/Network/KD/NWC24DL.cpp:34-50, Source/Core/Core/IOS/Network/KD/NWC24DL.h:43, Source/Core/Core/IOS/Network/KD/NWC24DL.h:111-116"
- name: nwc24fl.bin
path: Wii/shared2/wc24/nwc24fl.bin
system: nintendo-wii
required: false
description: "WiiConnect24 friend list"
note: "Placed in the NAND by the Sys/Wii copy and read from there by the running title. Titles such as Mario Kart Wii expect the WiiConnect24 files to exist even on a first launch, which is why the copy happens without the system menu ever running."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322, Source/Core/Core/WiiRoot.cpp:330-335"
- name: nwc24fls.bin
path: Wii/shared2/wc24/nwc24fls.bin
system: nintendo-wii
required: false
description: "WiiConnect24 friend list backup"
note: "Placed in the NAND by the Sys/Wii copy, which never overwrites a file the NAND already holds."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322, Source/Core/Core/WiiRoot.cpp:334"
- name: nwc24msg.cbk
path: Wii/shared2/wc24/nwc24msg.cbk
system: nintendo-wii
required: false
description: "WiiConnect24 account configuration backup"
note: "Placed in the NAND by the Sys/Wii copy, which never overwrites a file the NAND already holds."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322, Source/Core/Core/WiiRoot.cpp:334"
- name: misc.bin
path: Wii/shared2/wc24/misc.bin
system: nintendo-wii
required: false
description: "WiiConnect24 miscellaneous state"
note: "Placed in the NAND by the Sys/Wii copy. The time device carries a note about writing it but no code path does."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322, Source/Core/Core/IOS/Network/KD/NetKDTime.cpp:34"
- name: wc24recv.ctl
path: Wii/shared2/wc24/mbox/wc24recv.ctl
system: nintendo-wii
required: false
description: "WiiConnect24 receive mailbox index"
note: "Placed in the NAND by the Sys/Wii copy, which recurses into mbox and never overwrites a file the NAND already holds."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322"
- name: wc24recv.mbx
path: Wii/shared2/wc24/mbox/wc24recv.mbx
system: nintendo-wii
required: false
description: "WiiConnect24 receive mailbox"
note: "Placed in the NAND by the Sys/Wii copy. The bundled file is a stub; the note shipped beside it gives 0x700000 as the size on a console."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322, Data/Sys/Wii/shared2/wc24/mbox/Readme.txt"
- name: wc24send.ctl
path: Wii/shared2/wc24/mbox/wc24send.ctl
system: nintendo-wii
required: false
description: "WiiConnect24 send mailbox index"
note: "Placed in the NAND by the Sys/Wii copy, which recurses into mbox and never overwrites a file the NAND already holds."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322"
- name: wc24send.mbx
path: Wii/shared2/wc24/mbox/wc24send.mbx
system: nintendo-wii
required: false
description: "WiiConnect24 send mailbox"
note: "Placed in the NAND by the Sys/Wii copy. The bundled file is a stub; the note shipped beside it gives 0x200000 as the size on a console."
source_ref: "Source/Core/Core/WiiRoot.cpp:288-322, Data/Sys/Wii/shared2/wc24/mbox/Readme.txt"
- name: Readme.txt
path: Wii/shared2/wc24/mbox/Readme.txt
system: nintendo-wii
required: false
size: 103
sha256: "e5a888912968050c6c1d46d1c364c324684e1d15aaa62cfe36cf7fce2c687b21"
description: "note on the truncated mailboxes, copied into the NAND"
note: "The Sys/Wii copy walks the directory and takes every entry, so this file lands in the NAND with the mailboxes. It records the console sizes of the two mbx files. The hash names the file carried in the source tree, the only form it has, and is not a check the code performs; without it the name alone matches any readme."
source_ref: "Source/Core/Core/WiiRoot.cpp:291-319, Data/Sys/Wii/shared2/wc24/mbox/Readme.txt"
- name: wiitdb.txt
path: Load/wiitdb.txt
aliases: [titles.txt]
required: false
description: "user title database"
note: "One title id equals name pair per line, ids of four characters and up. titles.txt is read only when wiitdb.txt yields nothing. Overlays the per-language databases shipped in the Sys directory, which cover ten languages; the Portuguese and Russian files also present there are never registered."
source_ref: "Source/Core/Core/TitleDatabase.cpp:29-51, Source/Core/Core/TitleDatabase.cpp:54-58, Source/Core/Core/TitleDatabase.cpp:63-79"
- name: mios-ipl.map
path: Maps/mios-ipl.map
required: false
description: "MIOS symbol map"
note: "Read from Maps/ in the user directory when MIOS starts, and a successful load re-applies the HLE function patches against the symbols it names."
source_ref: "Source/Core/Core/IOS/MIOS.cpp:67-72"
valid_bios_crc32:
ipl_ntsc:
- { crc32: "6DAC1F2A", name: "NTSC v1.0" }
- { crc32: "D5E6FEEA", name: "NTSC v1.1" }
- { crc32: "86573808", name: "NTSC v1.2" }
- { crc32: "667D0B64", name: "MPAL v1.1 (Brazil)" }
ipl_pal:
- { crc32: "4F319F43", name: "PAL v1.0" }
- { crc32: "AD1B7F16", name: "PAL v1.2" }
exclusion_note: >
gba_bios.bin has no reader in this build: HW/GBACore.cpp is compiled only
under USE_MGBA, which the root CMakeLists forces off whenever the Qt
front-end is off, and the Android branch turns Qt off. The path override is
itself behind HAS_LIBMGBA. The signature database totaldb.dsy is reached only
from the Qt menu bar, which the Android build does not compile. libusb is
switched off for Android, so the Bluetooth passthrough firmware paths are out
as well. Load/Textures, Load/Riivolution, Load/GraphicMods, the per-game inis
in Sys/GameSettings, the post-processing shaders in Sys/Shaders and the
per-title symbol maps under Maps/ are read by directory scan under a game id
or a user-chosen name, so they carry no fixed filename.
ref: CMakeLists.txt:495, CMakeLists.txt:943-945,
Source/Core/Core/CMakeLists.txt:652-660,
Source/Core/Core/HW/GBACore.cpp:202, Source/Core/UICommon/UICommon.cpp:106-110,
Source/Core/DolphinQt/MenuBar.cpp:1212, CMakeLists.txt:842-843
+382
View File
@@ -0,0 +1,382 @@
emulator: DraStic
type: standalone
core_classification: other
source: "https://archive.org/details/dra-stic-ds-emulator-r-2.6.0.4a"
upstream: closed-source
author: "Exophase (Gilead Kutnick)"
profiled_date: "2026-08-11"
core_version: "r2.6.0.4a"
display_name: "Nintendo - DS (DraStic)"
cores:
- drastic
systems:
- nintendo-ds
mode: standalone
notes: |
Nintendo DS emulator by Exophase, closed source and distributed as a binary.
Two releases are read here and they name the same files: the Android build
r2.6.0.4a build 109, package com.dsemu.drastic, apk md5
7df979ef9420c5053b27c838e6a7e20c, whose loader is
lib/arm64-v8a/libdrastic_arm64.so and whose installer is the smali of
DraSticActivity; and the Linux AArch64 build r2.5.2.2, md5
17550db727f3b59d36b57746ad1944be, which ships unstripped with 2731 named
functions and is cited by function name. r2.5.2.2 predates the firmware editor
and the user database, and that is the whole of the divergence. Every
reference below is an address in one of the two binaries or a line in the
apktool decode of the Android one.
ref: libdrastic_arm64.so, drastic r2.5.2.2 (DWARF comp_dir
/home/odroid/nds_emu/src/linux_odroid64), DraSticActivity.smali
One root holds everything. On Android it is a directory named DraStic at the
root of shared storage; on Linux it is the working directory. Startup creates
backup, savestates, config, unzip_cache, system, input_record, cheats, slot2,
microphone and scripts below it, and the Android build adds backgrounds,
icon_cache, users, shaders and virtual_controller. Paths below are relative to
that root.
ref: drastic r2.5.2.2 initialize_system_directories 0xf780,
drastic r2.5.2.2 0x11ac08-0x11ac80, drastic r2.5.2.2 initialize_system 0xf9e8,
DraSticPathCache.smali:44-56, DraSticActivity.smali:4373-4429,
DraSticActivity.smali:4187, DraSticActivity.smali:4482
load_system_file builds <root>/system/<name>, opens it read only, measures it
by seeking to the end, refuses any length other than the one its caller asks
for with "System file %s is the wrong size (should be %d bytes, is %d)", then
reads it whole. Size is the only test; no hash is computed on any file.
ref: drastic r2.5.2.2 load_system_file 0xea80-0xebe4,
libdrastic_arm64.so 0x1b4d4-0x1b510
Each BIOS slot has two candidates. The ARM9 slot takes nds_bios_arm9.bin, and
on failure logs "Can't find Nintendo ARM9 BIOS. Trying free DraStic ARM9
BIOS." and takes drastic_bios_arm9.bin; the ARM7 slot does the same with
nds_bios_arm7.bin then drastic_bios_arm7.bin. A slot left empty returns -1
from initialize_memory, and initialize_system answers that with the on-screen
warning naming the two Nintendo files and their sizes, the line "FATAL: Could
not load system files." and quit. Neither name in a slot is required on its
own, both slots are. Taking the replacement sets a bit per slot, which is what
savestates record so that a state made under one pair does not load under the
other.
ref: drastic r2.5.2.2 initialize_memory 0x1c398-0x1c3d4,
drastic r2.5.2.2 initialize_memory 0x1c4b0-0x1c52c,
drastic r2.5.2.2 initialize_system 0xf940-0xf944,
drastic r2.5.2.2 initialize_system 0xf9f8-0xfa10,
drastic r2.5.2.2 menu_bios_warning 0x801e0-0x80238,
libdrastic_arm64.so 0x2b6d0-0x2b764
Firmware is answered in code when no file loads: the 256 KB region is zeroed
and patch_firmware_header_data writes the header, the console identity and the
user settings block into it. r2.5.2.2 reads nds_firmware.bin alone; r2.6.0.4a
reads nds_firmware_modified.bin first, which is what its firmware editor
writes back, and falls through to nds_firmware.bin.
ref: drastic r2.5.2.2 initialize_memory 0x1c3e0-0x1c3f8,
drastic r2.5.2.2 initialize_memory 0x1c560-0x1c578,
drastic r2.5.2.2 patch_firmware_header_data 0x1b920,
libdrastic_arm64.so 0x2b768-0x2b7c4, libdrastic_arm64.so 0x774e0-0x7751c
The Nintendo ARM7 image still decides one thing. gamecard_load_program passes
the 0x1048 bytes at ARM7 BIOS offset 0x30 to gamecard_decrypt_secure_region as
the Blowfish key table, and a secure area that does not decrypt to the id
encryObj is reported and left alone. The free ARM7 replacement holds zeroes
there, so encrypted cards need the dumped image.
ref: drastic r2.5.2.2 gamecard_load_program 0x6fb98-0x6fbac,
drastic r2.5.2.2 gamecard_decrypt_secure_region 0x6e2c0-0x6e38c,
drastic r2.5.2.2 initialize_memory 0x1c3bc-0x1c3c8
Two databases sit at the root. game_database.xml carries the save type per
title and a failed open only logs "Error: could not load game database file
%s."; r2.6.0.4a reads game_database_user.xml after it as a user overlay.
usrcheat.dat is the Action Replay library, read by load_cheat_directory.
ref: drastic r2.5.2.2 initialize_gamecard 0x709bc-0x70a30,
drastic r2.5.2.2 initialize_game_database 0x73180,
drastic r2.5.2.2 initialize_game_database 0x73d24-0x73d38,
libdrastic_arm64.so 0x76ab8-0x76b58
The Android package carries its own copies of the files it needs and lays them
down on first run: the two free BIOS images into system, the default layout
into config, game_database.xml, usrcheat.dat and the BSD-licensed source
archive of the free BIOS at the root, and the shaders and virtual_controller
trees whole. Nothing already present is overwritten.
ref: DraSticActivity.smali:4052-4090, DraSticActivity.smali:5189-5200,
DraSticActivity.smali:5459, DraSticActivity.smali:5619-5624,
DraSticActivity.smali:5645, DraSticActivity.smali:5834,
DraSticActivity.smali:5974
A .dfx names the passes of a post-processing chain and pulls its GLSL stages,
its included headers and its lookup textures from paths relative to itself.
Nine chains ship: None, Linear, Quilez, Scale2X, Scanline, HQ2X, FXAA, FXAA HQ
and SMAA, the last two reading .raw lookup textures.
ref: assets/shaders/_shader_format_.txt:12-58, assets/shaders/SMAA.dfx:1-6
Per-title inputs are read beside the ROM name. reset_spu answers the
microphone with microphone/<game>.wav then microphone/microphone.wav, load_nds
runs scripts/<game>.lua then scripts/default.lua through the built-in Lua
5.3, load_custom_cheats reads cheats/<game>.cht on top of the library, and
gamecard_load_gba fills the slot 2 cart from slot2/<game>.gba with its save
beside it. Homebrew turns on R4 flashcart emulation and opens
drastic_dldi.img read-write for the fat:/ device, logging "Couldn't load
drastic_dldi.img: " and carrying on without one.
ref: drastic r2.5.2.2 reset_spu 0x6dba8-0x6dc5c,
drastic r2.5.2.2 load_nds 0x6ff78-0x6ffd0, drastic r2.5.2.2 load_nds 0x70054-0x70094,
drastic r2.5.2.2 load_custom_cheats 0x817b4,
drastic r2.5.2.2 gamecard_load_gba 0x6ec98, drastic r2.5.2.2 gamecard_load_gba 0x6eda0,
drastic r2.5.2.2 gamecard_initialize_homebrew 0x6e4e0-0x6e518,
drastic r2.5.2.2 gamecard_initialize_homebrew 0x6e5a4
The Linux build alone draws a splash, reading drastic_logo_0.raw or
drastic_logo_1.raw at 120000 bytes each, one of the two picked at random.
ref: drastic r2.5.2.2 load_logo 0x7fad0-0x7fb78
files:
- name: nds_bios_arm9.bin
path: system/nds_bios_arm9.bin
system: nintendo-ds
required: false
size: 4096
validation: [size]
description: "Nintendo DS ARM9 BIOS"
note: "First candidate for the ARM9 slot. Booting continues on the free replacement when it is absent, and the slot ending empty is fatal."
source_ref: "drastic r2.5.2.2 initialize_memory 0x1c398-0x1c3b0, drastic r2.5.2.2 load_system_file 0xea80-0xebe4, libdrastic_arm64.so 0x2b6d0-0x2b6ec"
- name: drastic_bios_arm9.bin
path: system/drastic_bios_arm9.bin
system: nintendo-ds
required: false
bundled: true
size: 4096
validation: [size]
description: "DraStic free ARM9 BIOS replacement"
note: "Second candidate for the ARM9 slot, written by Exophase from public documentation and released under a BSD licence. Installed from the package assets on first run."
source_ref: "drastic r2.5.2.2 initialize_memory 0x1c4b0-0x1c4d4, libdrastic_arm64.so 0x2b6f0-0x2b708, DraSticActivity.smali:4084-4090, drastic_bios_readme.txt:1-31"
- name: nds_bios_arm7.bin
path: system/nds_bios_arm7.bin
system: nintendo-ds
required: false
size: 16384
validation: [size]
description: "Nintendo DS ARM7 BIOS"
note: "First candidate for the ARM7 slot, and the only image carrying the Blowfish key table at offset 0x30 that the card secure area is decrypted with."
source_ref: "drastic r2.5.2.2 initialize_memory 0x1c3bc-0x1c3d4, drastic r2.5.2.2 gamecard_load_program 0x6fb98-0x6fbac, libdrastic_arm64.so 0x2b724-0x2b73c"
- name: drastic_bios_arm7.bin
path: system/drastic_bios_arm7.bin
system: nintendo-ds
required: false
bundled: true
size: 16384
validation: [size]
description: "DraStic free ARM7 BIOS replacement"
note: "Second candidate for the ARM7 slot. Offset 0x30 is zero filled, so cards whose secure area is encrypted do not decrypt under it."
source_ref: "drastic r2.5.2.2 initialize_memory 0x1c508-0x1c52c, libdrastic_arm64.so 0x2b740-0x2b758, DraSticActivity.smali:4078-4083"
- name: nds_firmware.bin
path: system/nds_firmware.bin
system: nintendo-ds
required: false
hle_fallback: true
size: 262144
validation: [size]
description: "Nintendo DS firmware"
note: "Absent, the region is zeroed and patch_firmware_header_data writes a header, a console identity and a user settings block into it, so the emulator boots either way. r2.6.0.4a reads nds_firmware_modified.bin before this."
source_ref: "drastic r2.5.2.2 initialize_memory 0x1c3e0-0x1c3f8, drastic r2.5.2.2 initialize_memory 0x1c560-0x1c578, drastic r2.5.2.2 patch_firmware_header_data 0x1b920, libdrastic_arm64.so 0x2b794-0x2b7c4"
- name: nds_firmware_modified.bin
path: system/nds_firmware_modified.bin
system: nintendo-ds
required: false
hle_fallback: true
size: 262144
validation: [size]
unsourceable: "written by the firmware editor of r2.6.0.4a from the emulated user settings, so no dump of it exists"
description: "firmware image edited in the emulator"
note: "Read before nds_firmware.bin in r2.6.0.4a and absent from r2.5.2.2."
source_ref: "libdrastic_arm64.so 0x2b768-0x2b790, libdrastic_arm64.so 0x774e0-0x7751c"
- name: game_database.xml
path: game_database.xml
system: nintendo-ds
required: false
bundled: true
category: game_data
description: "save type database, one entry per title"
note: "Parsed from the root of the data directory. A failed open logs an error and the session continues without it. Installed from the package assets on first run."
source_ref: "drastic r2.5.2.2 initialize_gamecard 0x709bc-0x70a00, drastic r2.5.2.2 initialize_game_database 0x73180, drastic r2.5.2.2 initialize_game_database 0x73d24-0x73d38, DraSticActivity.smali:5459"
- name: game_database_user.xml
path: game_database_user.xml
system: nintendo-ds
required: false
category: game_data
unsourceable: "user overlay of the save type database, authored per collection"
description: "user save type database"
note: "Read after game_database.xml in r2.6.0.4a and absent from r2.5.2.2."
source_ref: "libdrastic_arm64.so 0x76af8-0x76b28"
- name: usrcheat.dat
path: usrcheat.dat
system: nintendo-ds
required: false
bundled: true
category: game_data
description: "Action Replay cheat library"
note: "Read from the root of the data directory and written back when a cheat is toggled, so the file carries the enabled state. Installed from the package assets on first run."
source_ref: "drastic r2.5.2.2 initialize_gamecard 0x70a0c-0x70a30, libdrastic_arm64.so 0x76b34-0x76b58, DraSticActivity.smali:5974"
- name: drastic_bios.zip
path: drastic_bios.zip
required: false
bundled: true
category: game_data
description: "source archive of the free BIOS replacement"
note: "Copied to the root of the data directory on first run and never read back. Holds bios_common.S, a Makefile, the BSD licence notice and the two built images."
source_ref: "DraSticActivity.smali:5189-5200, drastic_bios_readme.txt:1-31"
- name: LC_default.dat
path: config/LC_default.dat
required: false
bundled: true
category: game_data
description: "default screen layout"
note: "Android only. Copied out of the package assets into config on first run, and offered from there by the layout list, which filters that directory on the .dat extension."
source_ref: "DraSticActivity.smali:4052-4066, DraSticActivity.smali:4830-4925"
- name: "<name>.dfx"
path: "shaders/<name>.dfx"
required: false
bundled: true
category: game_data
description: "post-processing chain definition"
note: "Android only. Names the passes, the texture inputs and the headers of one chain, all resolved relative to its own path. The package ships None, Linear, Quilez, Scale2X, Scanline, HQ2X, FXAA, FXAA HQ and SMAA."
source_ref: "DraSticActivity.smali:5619-5624, assets/shaders/_shader_format_.txt:11-21"
- name: "<name>.dsd"
path: "shaders/<name>.dsd"
required: false
bundled: true
category: game_data
description: "GLSL stage source named by a chain"
note: "Android only. Named by the shader entry of a pass, and carrying the vertex and fragment code for it, together with the .h and .hlsl files the include tags pull in. A stage that fails to compile leaves a <name>dsd.log beside it."
source_ref: "assets/shaders/_shader_format_.txt:8-9, assets/shaders/_shader_format_.txt:36-40, assets/shaders/_shader_format_.txt:59-72, assets/shaders/_shader_format_.txt:75-98"
- name: "<name>.raw"
path: "shaders/<name>.raw"
required: false
bundled: true
category: game_data
description: "lookup texture named by a chain"
note: "Android only. Loaded when a texture tag names a file instead of the framebuffer or an FBO, with the dimensions and the format taken from the tag. SMAA is the one shipped chain that names any, taking smaa/AreaTexRGB.raw and smaa/SearchTexRGB.raw; the package also carries the non-RGB pair of the same two tables, which no shipped chain names."
source_ref: "assets/shaders/_shader_format_.txt:42-56, assets/shaders/SMAA.dfx:1-6"
- name: "<name>.zip"
path: "virtual_controller/<name>.zip"
required: false
bundled: true
category: game_data
description: "on-screen controller skin"
note: "Android only. Installed from the package assets, which carry Simple, Simple-II and Neon."
source_ref: "DraSticActivity.smali:5645, DraSticActivity.smali:5834"
- name: microphone.wav
path: microphone/microphone.wav
system: nintendo-ds
required: false
category: game_data
unsourceable: "audio the user records to stand in for the console microphone"
description: "default microphone input"
note: "Read when no per-title file answers, and logged as the default fake microphone audio file."
source_ref: "drastic r2.5.2.2 reset_spu 0x6dc30-0x6dc5c"
- name: "<game>.wav"
path: "microphone/<game>.wav"
system: nintendo-ds
required: false
category: game_data
description: "per-title microphone input"
note: "Tried before microphone.wav and named after the running title."
source_ref: "drastic r2.5.2.2 reset_spu 0x6dba8-0x6dbe8"
- name: default.lua
path: scripts/default.lua
required: false
category: game_data
unsourceable: "script the user writes against the built-in Lua 5.3 interpreter"
description: "fallback Lua script"
note: "Loaded at game start when no per-title script answers, then handed the load-game callback."
source_ref: "drastic r2.5.2.2 load_nds 0x70054-0x70094"
- name: "<game>.lua"
path: "scripts/<game>.lua"
required: false
category: game_data
description: "per-title Lua script"
note: "Tried before default.lua and named after the running title."
source_ref: "drastic r2.5.2.2 load_nds 0x6ff78-0x6ffd0"
- name: "<game>.cht"
path: "cheats/<game>.cht"
system: nintendo-ds
required: false
category: game_data
description: "custom cheat file"
note: "Plain text, one bracketed cheat name per block followed by its codes, a trailing plus marking the cheat active. Read on top of the entries usrcheat.dat holds and written back when a cheat is toggled."
source_ref: "drastic r2.5.2.2 load_custom_cheats 0x817b4, drastic r2.5.2.2 save_custom_cheats 0x81d24, drastic_readme.txt:789-812"
- name: "<game>.gba"
path: "slot2/<game>.gba"
system: nintendo-ds
required: false
category: game_data
unsourceable: "Game Boy Advance cartridge the title reads for bonus content"
description: "slot 2 cartridge image"
note: "Loaded into the slot 2 cart window, with its save read from slot2/<game>.sav beside it."
source_ref: "drastic r2.5.2.2 gamecard_load_gba 0x6ec98, drastic r2.5.2.2 gamecard_load_gba 0x6eda0"
- name: drastic_dldi.img
path: drastic_dldi.img
system: nintendo-ds
required: false
category: game_data
unsourceable: "FAT image the user builds for the emulated flashcart"
description: "R4 flashcart disk image"
note: "Opened read-write when a homebrew title is recognised and mounted as the fat:/ device. Absent, the message is logged and the title runs without a card."
source_ref: "drastic r2.5.2.2 gamecard_initialize_homebrew 0x6e4e0-0x6e518, drastic r2.5.2.2 gamecard_initialize_homebrew 0x6e5a4"
- name: drastic_logo_0.raw
path: drastic_logo_0.raw
required: false
category: game_data
size: 120000
validation: [size]
unsourceable: "splash image of the Linux build, not carried by any distributed package"
description: "boot splash, first of two"
note: "Read from the root of the data directory in one 120000 byte request, so a shorter file is rejected. One of the two indices is picked at random and a missing file skips the splash."
source_ref: "drastic r2.5.2.2 load_logo 0x7fad0-0x7fb78"
- name: drastic_logo_1.raw
path: drastic_logo_1.raw
required: false
category: game_data
size: 120000
validation: [size]
unsourceable: "splash image of the Linux build, not carried by any distributed package"
description: "boot splash, second of two"
note: "Same read as index 0."
source_ref: "drastic r2.5.2.2 load_logo 0x7fad0-0x7fb78"
exclusion_note: >
fonts/orbitron.ttf and keymaps/Shield.dkm ship in the Android package and
nothing opens them: neither string appears in the classes dex of the official
apk nor in any of the native libraries, and the menus draw from a font
compiled into the binary. Left out with them are the files DraStic authors
itself and reads back, which are emulator state rather than system files:
drastic.cfg and the per-directory drastic.cf2, the config/<name>.cfg profiles,
savestates/<name>_<slot>.dss, the backup/<name>.dsv and .sav in-game saves,
input_record/<name>.ir, the icon and file info caches, unzip_cache and
unzipped_rom.nds, crash_dump.txt, the profiler dumps under profiles, and the
drastic_mapped_memory.dat and drastic_mapped_memory_vram.dat scratch files of
the memory mapper.
ref: official apk classes dex, libdrastic_arm64.so, drastic r2.5.2.2 0x11a938,
drastic r2.5.2.2 0x11aca8, drastic r2.5.2.2 0x11b440, drastic r2.5.2.2 0x11b650,
drastic r2.5.2.2 0x11edd8, drastic r2.5.2.2 0x120190, drastic r2.5.2.2 0x1201b0,
drastic r2.5.2.2 0x1202d0, drastic r2.5.2.2 0x1217f0, drastic r2.5.2.2 0x121868,
drastic r2.5.2.2 0x1249f8, drastic r2.5.2.2 0x124b08
+76
View File
@@ -0,0 +1,76 @@
emulator: DroidArcadia
type: standalone
core_classification: embedded_hle
source: "https://amigan.1emu.net/releases/"
upstream: "https://amigan.1emu.net/releases/"
author: "James Jacobs (Amigan Software)"
profiled_date: "2026-08-11"
core_version: "4.60"
display_name: "Emerson Arcadia 2001 / Interton VC 4000 (DroidArcadia)"
cores:
- droidarcadia
- com.amigan.droidarcadia
systems:
- emerson-arcadia-2001
- interton-vc4000
- elektor-tv-games-computer
- arcade
mode: standalone
notes: |
Android build of the Signetics 2650 emulator line by James Jacobs, published
as package com.amigan.droidarcadia. A game arrives as a content URI declared
by the manifest under MIME type application/octet-stream or application/zip,
a zip yielding its first member only, and the read stops at 32768 bytes. This
reading is taken from the author's own source archive DroidArcadia-src.rar
4.60, md5 5f88d8b01493a2430d2f9c94da69bf8a, and confirmed against the
published DroidArcadia.apk, md5 a72cf2f5e2b213577f3e185aa58f7e21.
ref: app/src/main/cpp/da.h:3-5, app/src/main/AndroidManifest.xml:21-37,
app/build.gradle:22-28, MainActivity.java:1502-1558,
res/values/strings.xml:5-6
Fifteen memory maps over five machines: Interton VC 4000 types A to D,
Elektor TV Games Computer basic and expanded, Emerson Arcadia 2001 types G
(Emerson), H (Tele-Fever) and I (Palladium), and the coin-ops Astro Wars,
Galaxia, Laser Battle and Lazarian (Zaccaria) with Malzak 1 and 2 (Kitronix).
ref: android.c:245-261, da.h:445-467
Every ROM those machines run is a const array compiled into
libdroidarcadia.so and copied into memory when the machine is set up:
a_bios[348] for the
Arcadia boot stub, i_bios[287] for the Interton one, e_bios_philips[2048] and
e_bios_hobbymodule[2048] for the two Elektor monitor ROMs, galaxia_game,
astrowars_game, lb_game and lz_game for the Zaccaria coin-ops, m1_bios and
m2_bios for the Malzak pair. The first sixteen bytes of all ten arrays are
present in the arm64 library of the published apk.
ref: android.c:588-596, arcadia.h:279 with arcadia.c:426, interton.h:1 with
interton.c:36, elektor.h:1,131 with elektor.c:95-103,
zaccaria.h:1,644,1599,3653 with zaccaria.c:243,325,423,436,
malzak.h:1,558 with malzak.c:363,373
The native side never opens a file. It receives the game as a byte array over
JNI and parses it in memory: a cartridge is matched on size and CRC32 against
the games.h table, and the bios field of the matched entry carries the Arcadia
region and picks which of the two Elektor monitor ROMs is installed.
RetroAchievements identification is handed that same memory with the file path
argument left NULL, so the file reader of the bundled rcheevos is never
reached. A coin-op is stepped to through the machine button rather than
loaded, and a raw binary aimed at Zaccaria or Malzak hardware is refused.
ref: android.c:877-894, android.c:2166-2192, android.c:2082-2096,
android.c:1010-1013, android.c:4592-4631, elektor.c:95-103,
OptionsActivity.java:455-465
exclusion_note: >
Nothing to obtain. The app reads back only what it writes in its own private
storage, each read wrapped in a catch that continues when the file is absent:
DroidArcadia.ini for settings, DroidArcadia.hgh for the high score table, and
Autosave.cos with Quicksave.cos for save states. Screenshots go out to
/sdcard/Pictures/DroidArcadia and are never read back, and RetroAchievements
traffic, login and badge and game images alike, is decoded in memory. The apk
carries no assets directory and no raw resource, so no payload is unpacked on
first run either.
ref: MainActivity.java:1123,1184,1242,1312,1340,1415,
OptionsActivity.java:224-235,682,742, RAActivity.java:237-238,268-269,
NetworkUtil.java:17-38
files: []
+106
View File
@@ -0,0 +1,106 @@
emulator: D.Smile
type: standalone
core_classification: other
source: "https://github.com/derik-dot-digital/D.Smile"
upstream: "https://github.com/derik-dot-digital/D.Smile"
profiled_date: "2026-08-11"
source_commit: "d4bbc3be27537def21513991647f14ea9a9c2d15"
core_version: "0.4.4"
display_name: "VTech - V.Smile (D.Smile)"
cores:
- dsmile
systems:
- vtech-vsmile
mode: standalone
notes: |
V.Smile emulator for Android, package com.dsmile.emulator, built on an SPG200
(unSP) core of its own. Frontends launch the exported EmuActivity either with
ACTION_VIEW and a content or file Uri, or with the LAUNCH_GAME action and a
rom, ROM, path or uri string extra carrying a path; ES-DE uses the first form.
ref: AndroidManifest.xml:34-51, EmuActivity.kt:123-145,
docs/iisu-integration.md:42-51
The machine never boots from the system ROM. UnSP::Reset takes the program
counter from 0xFFF7, and the FIQ, IRQ n and BREAK vectors are read from
0xFFF6, 0xFFF8+n and 0xFFF5; all four sit in bank 0, which ExtRead answers
from the cartridge under every decode mode. The system ROM sits on bank 3 and
is reachable only once cartridge code selects decode mode 2 or 3;
extmem_ctrl_ resets to 0x0028, which is decode 0, so nothing but the
cartridge is mapped at power on.
ref: unsp.cpp:49,67,77,253, spg200.cpp:188-209, spg200.cpp:37
Absent a file the constructor synthesises the region: 0x100000 words zero
filled, with 0x0031 written into the odd word of each pair across
0xFFFC0-0xFFFDB so that calls into the BIOS land on zeroed memory. LoadSysrom
replaces it, reading the image as little-endian 16-bit words and clamping at
0x100000 words, and runs only when bytes were passed.
ref: vsmile.cpp:273-283, vsmile.cpp:326-334, jni_bridge.cpp:34-40
Two paths reach LoadSysrom and one of them checks nothing. The BIOS button
imports through a file picker: validateBios demands exactly 0x200000 bytes and
nine of the eleven words at 0xFFF5-0xFFFF decoding inside 0x0100-0xFFF0, tries
both byte orders, rewrites the image to little-endian when the swapped reading
scores higher, and stores the result as sysrom.bin in the app's private
directory. With no imported file the ROM folder is searched instead: any entry
whose extension is bin, rom or vsmile and whose lowercased name holds bios,
sysrom or system rom, or begins with vsmile_v, is taken as the system ROM and
handed over unmeasured, the last match in directory order winning. No hash is
computed on either path. The three dumped revisions satisfy both tests as they
stand, scoring eleven of eleven in both byte orders, so they load unswapped.
ref: MainActivity.kt:31, MainActivity.kt:34, MainActivity.kt:215-236,
MainActivity.kt:238-261, MainActivity.kt:277-288, EmuActivity.kt:156-168
Region is a jumper, never a file. Port C carries the region code in its low
nibble and the intro jumper in bit 4. The code is fixed at 0xF and SetRegion
has no caller, so one image serves every session; the jumper is exposed only
as the Game intros setting, passed through nativeInit.
ref: vsmile.cpp:365-369, vsmile.h:76, vsmile.h:77, vsmile.h:116,
jni_bridge.cpp:39, MainActivity.kt:309,320
The system ROM has no directory of its own. The validated copy is written by
the app into private storage, which the user cannot reach, so the one
placement open to a collection is the folder chosen with ROM folder, beside
the cartridge dumps.
ref: MainActivity.kt:34, MainActivity.kt:154-168, MainActivity.kt:263-288
files:
- name: vsmile_v103.bin
system: vtech-vsmile
required: false
hle_fallback: true
size: 2097152
validation: [size]
description: "V.Smile system ROM, revision 1.03"
source_ref: "app/src/main/java/com/dsmile/emulator/ui/MainActivity.kt:238-261 (size and vector test), app/src/main/java/com/dsmile/emulator/ui/MainActivity.kt:277-288 (folder detection), app/src/main/java/com/dsmile/emulator/ui/EmuActivity.kt:156-168 (selection), app/src/main/cpp/jni_bridge.cpp:34-40, app/src/main/cpp/core/vsmile.cpp:326-334 (load)"
- name: vsmile_v102.bin
system: vtech-vsmile
required: false
hle_fallback: true
size: 2097152
validation: [size]
description: "V.Smile system ROM, revision 1.02"
source_ref: "app/src/main/java/com/dsmile/emulator/ui/MainActivity.kt:238-261 (size and vector test), app/src/main/java/com/dsmile/emulator/ui/MainActivity.kt:277-288 (folder detection), app/src/main/java/com/dsmile/emulator/ui/EmuActivity.kt:156-168 (selection), app/src/main/cpp/jni_bridge.cpp:34-40, app/src/main/cpp/core/vsmile.cpp:326-334 (load)"
- name: vsmile_v100.bin
system: vtech-vsmile
required: false
hle_fallback: true
size: 2097152
validation: [size]
description: "V.Smile system ROM, revision 1.00"
source_ref: "app/src/main/java/com/dsmile/emulator/ui/MainActivity.kt:238-261 (size and vector test), app/src/main/java/com/dsmile/emulator/ui/MainActivity.kt:277-288 (folder detection), app/src/main/java/com/dsmile/emulator/ui/EmuActivity.kt:156-168 (selection), app/src/main/cpp/jni_bridge.cpp:34-40, app/src/main/cpp/core/vsmile.cpp:326-334 (load)"
exclusion_note: >
The system ROM is the only file to obtain. The cartridge dump arrives as the
intent payload and everything else the app touches it writes itself: the save
states and their PNG thumbnails under states in the external files directory,
and the dsmile preferences, which also hold the touch layouts as a JSON
string rather than as files. The Art Studio NVRAM the SPG200 maps over bank 2
is dead here, the sole SetCart call passing a null pointer for it, so no such
image exists to name. Oboe and libc++_shared are linked into the package by
CMake at build time and are never opened as files. The native sources perform
no file I/O at all.
ref: EmuActivity.kt:123-145, EmuActivity.kt:246-296, EmuActivity.kt:528-555,
vsmile.cpp:294, spg200.cpp:204,214, CMakeLists.txt:11,26
+35
View File
@@ -0,0 +1,35 @@
emulator: Eden Nightly
type: alias
alias_of: eden
core_classification: alias
source: "https://git.eden-emu.dev/eden-emu/eden"
upstream: "https://git.eden-emu.dev/eden-emu/eden"
source_commit: "8648c27cbb4c17b176076b09ac245271829cbd9f"
profiled_date: "2026-08-11"
core_version: "Git"
display_name: "Eden Nightly (Nintendo Switch)"
cores: ["eden-nightly"]
systems: [nintendo-switch]
note: |
Same tree as eden, built from master with the gradle property nightly=true
(src/android/app/build.gradle.kts:41-42). The property sets applicationIdSuffix
".nightly" (:139) and passes -DNIGHTLY_BUILD=ON -DENABLE_UPDATE_CHECKER=ON (:95-99).
NIGHTLY_BUILD points the update feed at nightly.eden-emu.dev, repo eden-ci/nightly,
instead of stable.eden-emu.dev, repo eden-emu/eden
(CMakeModules/GenerateSCMRev.cmake:43-52), splits the release tag on "." before the
version compare (src/common/net/net.cpp:27-35,
src/frontend_common/update_checker.cpp:26-43), sets the g_is_nightly_build constant
(src/common/scm_rev.cpp.in:28,45) and exposes NativeLibrary.isNightlyBuild
(src/android/app/src/main/jni/native.cpp:1703-1711). No file loading path differs,
so the keys are those of eden.
Nightly builds carry no release tag: getGitVersion() returns git describe
(build.gradle.kts:368-383) and GenerateSCMRev.cmake:22-24 marks the result a dev build.
The android package ids are the three product flavors plus the suffix:
dev.eden.eden_emulator.nightly (build.gradle.kts:67),
com.miHoYo.Yuanshen.nightly (:206), dev.legacy.eden_emulator.nightly (:224).
files: []
+7 -1
View File
@@ -27,6 +27,13 @@ files:
note: "Production keys for NCA decryption (master, key area, header, titlekek)" note: "Production keys for NCA decryption (master, key area, header, titlekek)"
source_ref: "src/core/crypto/key_manager.cpp:574-575, 853" source_ref: "src/core/crypto/key_manager.cpp:574-575, 853"
- name: "dev.keys"
required: false
path: "switch/"
mode: standalone
note: "Development-unit keys, read instead of prod.keys when use_dev_keys is set"
source_ref: "src/core/crypto/key_manager.cpp:570-571, 852"
- name: "title.keys" - name: "title.keys"
required: false required: false
path: "switch/" path: "switch/"
@@ -51,6 +58,5 @@ files:
notes: | notes: |
Eden is a standalone Nintendo Switch emulator, community fork of yuzu by Camille LaVey. Eden is a standalone Nintendo Switch emulator, community fork of yuzu by Camille LaVey.
dev.keys can be used instead of prod.keys when use_dev_keys is enabled (for Switch dev units).
Firmware (system NCAs) must be installed through Eden's UI from a firmware ZIP or NCA folder. Firmware (system NCAs) must be installed through Eden's UI from a firmware ZIP or NCA folder.
Required for commercial games. Homebrew (.nro, .nso) can run without keys or firmware. Required for commercial games. Homebrew (.nro, .nso) can run without keys or firmware.
+310
View File
@@ -0,0 +1,310 @@
emulator: EmuCoreV
type: standalone
core_classification: community_fork
source: "https://github.com/sashkinbro/EmuCoreV"
upstream: "https://github.com/Vita3K/Vita3K"
author: "Oleksandr (sashkinbro)"
profiled_date: "2026-08-11"
source_commit: "b71d8cf5397b1c6394e92eeb48427cd17e542971"
core_version: "0.1.8"
display_name: "Sony - PlayStation Vita (EmuCoreV)"
cores:
- emucorev
systems:
- sony-playstation-vita
mode: standalone
notes: |
PlayStation Vita emulator for Android, package com.sbro.emucorev, arm64-v8a
only. A Kotlin and Compose front end drives a Vita3K tree vendored verbatim
under app/src/main/cpp/vita3k, reached through an adapter layer that owns
every JNI entry point. Frontends start the exported activity
com.sbro.emucorev.core.vita.Emulator with an AppStartParameters string array;
ES-DE passes -r followed by the title id read from the .psvita file.
ref: app/src/main/cpp/emucorev/README.md:1-13,
app/src/main/AndroidManifest.xml:85-101,
app/src/main/java/com/sbro/emucorev/core/vita/Emulator.kt:128,
app/src/main/java/com/sbro/emucorev/core/vita/Emulator.kt:140-152,
app/build.gradle.kts:85-86, app/build.gradle.kts:95
The Android library is built from the JNI sources plus interface.cpp and
performance.cpp, and links app, audio, compat, config, cppcommon, ctrl,
dialog, display, ime, lang, gdbstub, gxm, io, miniz, modules, motion,
packages, patch, renderer, shader, touch, util and psvpfsparser, with overlay
and np arriving through renderer and modules. The ImGui front end under
vita3k/gui is never added as
a subdirectory, gui-qt is desktop only, and the adapter drops those two and
updater from the link line as well when a configuration defines them. So the
home screen, live area, themes, trophy collection, user avatars and the pd0
background music player are not compiled: pd0 is written by a firmware install
and never read back, which is why no third preinst package is offered.
ref: app/src/main/cpp/vita3k/vita3k/CMakeLists.txt:122-124,
app/src/main/cpp/vita3k/vita3k/CMakeLists.txt:154-172,
app/src/main/cpp/vita3k/vita3k/CMakeLists.txt:212-215,
app/src/main/cpp/emucorev/cmake/AttachToVita3K.cmake:31,
app/src/main/cpp/emucorev/cmake/CoreTargetFilter.cmake:19-23
Firmware installation calls vanilla install_pup. The file is tested for the
SCEUF magic and nothing else, the SCE segments are decrypted with the built-in
keys, os0.img, pd0.img, sa0.img and vs0.img are joined from their pieces, and
each image with content is extracted into the Vita filesystem root. The
version string is read from the version.txt the package carries. No digest and
no length is compared.
ref: app/src/main/cpp/emucorev/src/vita_install_bridge.cpp:86-102,
app/src/main/cpp/vita3k/vita3k/packages/src/pup.cpp:119-123,
app/src/main/cpp/vita3k/vita3k/packages/src/pup.cpp:239-258,
app/src/main/cpp/vita3k/vita3k/packages/src/pup.cpp:260-314
Two packages are named in code, both pinned to firmware 3.74 and fetched from
Sony. Each URL carries the MD5 of the package it serves in its rel_ and sd_
path segment. The byte counts beside them feed the progress bar and its
fallback alone, and one of the two is not the length of the file it names, so
nothing measures what was downloaded.
ref: app/src/main/java/com/sbro/emucorev/core/FirmwareSource.kt:16-37,
app/src/main/java/com/sbro/emucorev/ui/onboarding/FirmwareDownloadViewModel.kt:96-124
Both packages are required. launchInstalledTitle returns MissingFirmware
before doing any work when vita/vs0 holds no file, and MissingFirmwareUpdate
when vita/sa0 holds no file, each with its own refusal string. The refusal is
the app's own: nothing in the vendored core tests either partition before a
run, and the only sa0 test in the tree sits in the front end that is not
compiled. The gate also sits in the in-app launcher alone, so a frontend
starting the activity itself, which is what ES-DE does, reaches the core
without passing through it.
ref: app/src/main/java/com/sbro/emucorev/core/VitaLaunchBridge.kt:24-30,
app/src/main/java/com/sbro/emucorev/core/EmulatorStorage.kt:262-272,
app/src/main/java/com/sbro/emucorev/core/vita/Emulator.kt:140-152,
app/src/main/res/values/strings.xml:27-31,
app/src/main/res/values/strings.xml:710-711
What the partitions are read for. Every launch queues os0:kd/bootimage.skprx
and os0:kd/sysmodule.skprx, then for each preload module that is LLE takes
app0:sce_module/<name>.suprx when the title carries one and
vs0:sys/external/<name>.suprx otherwise. libc, libSceFt2, libpvf and libfiber
are always LLE, alongside an automatic list of nineteen sysmodules, and a
failed module load is logged and stepped over. The overlay renderer registers
sa0/data/font/pvf as the firmware font directory and asks it for the ltn, jpn,
cn and kr faces by name, falling back to /system/fonts for its own text.
ref: app/src/main/cpp/vita3k/vita3k/interface.cpp:499-535,
app/src/main/cpp/vita3k/vita3k/module/src/load_module.cpp:142-161,
app/src/main/cpp/vita3k/vita3k/module/src/load_module.cpp:187-195,
app/src/main/cpp/vita3k/vita3k/renderer/src/renderer.cpp:114-127,
app/src/main/cpp/vita3k/vita3k/overlay/src/font.cpp:116-160,
app/src/main/cpp/vita3k/vita3k/overlay/src/font.cpp:174-234
Storage. The Vita filesystem is a directory named vita under a storage root
the user can move to a card, holding ux0 and the partitions a firmware install
writes. Configuration, logs, patches, the texture folders and the cache stay
on internal storage. Static assets never reach the filesystem: on Android the
static assets path is left empty and shaders, fonts and images are read out of
the package through SDL.
ref: app/src/main/java/com/sbro/emucorev/core/EmulatorStorage.kt:36-46,
app/src/main/java/com/sbro/emucorev/core/EmulatorStorage.kt:101-148,
app/src/main/cpp/vita3k/vita3k/app/src/app_init.cpp:244-256
Titles arrive as VPK, ZIP, PKG or an already extracted directory, and a PKG
needs a zRIF that is either typed in or derived from a license already
installed for that content id.
ref: app/src/main/cpp/emucorev/src/vita_install_bridge.cpp:104-197,
app/src/main/cpp/vita3k/vita3k/packages/src/pkg.cpp:356-376
files:
- name: PSVUPDAT.PUP
system: sony-playstation-vita
required: true
storage: large_file
md5: f2c7b12fe85496ec88a0391b514d6e3b
description: "PS Vita system software update package"
note: >-
Base firmware, pinned to 3.74 by a hardcoded URL whose rel_ segment is the
MD5 of the package. Downloaded on demand to firmware-downloads under the
external files directory, or picked from anywhere through the file picker,
then consumed by install_pup, which extracts whichever of os0, vs0, pd0 and
sa0 the package carries. This one is what fills vs0, and the app refuses to
start a title while vs0 is empty.
source_ref: "app/src/main/java/com/sbro/emucorev/core/FirmwareSource.kt:17-23, app/src/main/java/com/sbro/emucorev/ui/onboarding/FirmwareDownloadViewModel.kt:96-105, app/src/main/java/com/sbro/emucorev/core/VitaInstallBridge.kt:25-36, app/src/main/cpp/emucorev/src/vita_install_bridge.cpp:97-101, app/src/main/cpp/vita3k/vita3k/packages/src/pup.cpp:292-299, app/src/main/java/com/sbro/emucorev/core/VitaLaunchBridge.kt:25-27"
- name: PSP2UPDAT.PUP
system: sony-playstation-vita
required: true
storage: large_file
md5: 59dcf059d3328fb67be7e51f8aa33418
description: "PS Vita firmware font package"
note: >-
Second package of the same 3.74 release, pinned by a URL whose sd_ segment
is its MD5, and the one that fills sa0 with the PVF system fonts. Installed
through the same path as the base package. The app refuses to start a title
while sa0 is empty, and asks for it even though the overlay carries a
system font fallback of its own.
source_ref: "app/src/main/java/com/sbro/emucorev/core/FirmwareSource.kt:25-31, app/src/main/cpp/vita3k/vita3k/packages/src/pup.cpp:296-297, app/src/main/cpp/vita3k/vita3k/renderer/src/renderer.cpp:121-127, app/src/main/java/com/sbro/emucorev/core/VitaLaunchBridge.kt:28-30"
- name: app_compat_db.xml
path: "compatibility/app_compat_db.xml"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "dated snapshot of the Vita3K compatibility project, rebuilt upstream and refetched by the app every twelve hours"
description: "per-title compatibility ratings"
note: >-
Downloaded as app_compat_db.xml.zip from the Vita3K compatibility
releases, unpacked into the compatibility directory of internal storage
and parsed for the badges the library and catalog screens draw. The native
side looks for the same filename in the cache directory at bootstrap and
logs a warning when it finds none.
source_ref: "app/src/main/java/com/sbro/emucorev/data/VitaCompatibilityRepository.kt:18-20, app/src/main/java/com/sbro/emucorev/data/VitaCompatibilityRepository.kt:54-107, app/src/main/java/com/sbro/emucorev/data/VitaCompatibilityRepository.kt:346-350, app/src/main/cpp/vita3k/vita3k/android/jni/native_bootstrap.cpp:122, app/src/main/cpp/vita3k/vita3k/compat/src/compat.cpp:127-150"
- name: commercial_list.json
path: "compatibility/commercial_list.json"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "answer of a live web API, refetched on the same twelve hour cycle"
description: "commercial title index"
note: >-
Fetched from the Vita3K web API and merged over the XML snapshot, so a
title the database does not carry still resolves. Read only when the file
is present and not empty.
source_ref: "app/src/main/java/com/sbro/emucorev/data/VitaCompatibilityRepository.kt:20, app/src/main/java/com/sbro/emucorev/data/VitaCompatibilityRepository.kt:69-73, app/src/main/java/com/sbro/emucorev/data/VitaCompatibilityRepository.kt:349"
- name: psvita_games.db
path: "psvita_games.db"
system: sony-playstation-vita
required: false
bundled: true
category: game_data
description: "bundled catalog of Vita titles"
note: >-
SQLite catalog carried in the package assets and copied into internal
storage the first time the catalog screen opens, then reopened read only
from there. A copy already present is kept.
source_ref: "app/src/main/java/com/sbro/emucorev/data/VitaCatalogRepository.kt:8-9, app/src/main/java/com/sbro/emucorev/data/VitaCatalogRepository.kt:276-292"
- name: config.txt
path: "vita/ux0/tai/config.txt"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "plugin list the user writes for their own titles"
description: "taiHEN plugin configuration"
note: >-
Read once per session from ux0:tai/config.txt, then from ur0:tai/config.txt
when the first is absent. Sections name a title id or KERNEL and list the
plugin paths loaded for it. No file found is logged and the session
continues.
source_ref: "app/src/main/cpp/vita3k/vita3k/modules/taiHEN/taiHEN.cpp:1253-1272, app/src/main/cpp/vita3k/vita3k/interface.cpp:535"
- name: "<plugin>.suprx"
path: "vita/ux0/tai/<plugin>.suprx"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "homebrew plugin built against taiHEN, chosen per collection"
description: "taiHEN plugin"
note: >-
Loaded at the path config.txt gives it, kernel plugins once per session and
title plugins on each launch of the matching title id. A plugin that fails
to load is logged and skipped. Exports of a loaded plugin that already have
an HLE implementation are overridden by it.
source_ref: "app/src/main/cpp/vita3k/vita3k/modules/taiHEN/taiHEN.cpp:1362-1405, app/src/main/cpp/vita3k/vita3k/modules/taiHEN/taiHEN.cpp:1306-1359"
- name: "<TITLEID>.txt"
path: "patch/<TITLEID>.txt"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "patch list authored per title, with no released artefact behind it"
description: "per-title binary patch list"
note: >-
The patch directory is scanned at module load and any filename holding the
running title id and ending in .txt is parsed. A bracketed header names the
binary the lines under it apply to, eboot.bin until one says otherwise, and
each line is a segment and an offset followed by the values written there.
A line that fails to parse is logged and the rest of the file is kept.
source_ref: "app/src/main/cpp/vita3k/vita3k/patch/src/patch.cpp:26-70, app/src/main/cpp/vita3k/vita3k/patch/src/patch.cpp:77-90, app/src/main/cpp/vita3k/vita3k/patch/src/util.cpp:24-50, app/src/main/cpp/vita3k/vita3k/interface.cpp:482-484"
- name: PATCHLIST.TXT
path: "patch/PATCHLIST.TXT"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "collected patch list, authored rather than dumped"
description: "shared binary patch list"
note: >-
Read alongside the per-title files whatever the running title is, the name
matched case insensitively as a substring. Its headers take a title id and
an optional binary, so one file holds patches for several titles, and the
lines under a header for another title are skipped.
source_ref: "app/src/main/cpp/vita3k/vita3k/patch/src/patch.cpp:30-37, app/src/main/cpp/vita3k/vita3k/patch/src/patch.cpp:57-59, app/src/main/cpp/vita3k/vita3k/patch/src/util.cpp:30-38"
- name: "<hash>.png"
path: "textures/import/<TITLEID>/<hash>.png"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "replacement artwork authored against the texture hashes of one title"
description: "replacement texture"
note: >-
Read when the import textures option is on. The import folder is walked
recursively and a file counts only when its name parses as a hexadecimal
hash, which is the key the texture cache looks it up by.
source_ref: "app/src/main/cpp/vita3k/vita3k/renderer/src/texture/cache.cpp:312-315, app/src/main/cpp/vita3k/vita3k/renderer/src/texture/replacement.cpp:607-630, app/src/main/java/com/sbro/emucorev/core/VitaCoreConfigRepository.kt:30, app/src/main/java/com/sbro/emucorev/core/VitaCoreConfigRepository.kt:262"
- name: "<hash>.dds"
path: "textures/import/<TITLEID>/<hash>.dds"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "replacement artwork authored against the texture hashes of one title"
description: "replacement texture, compressed"
note: >-
Same folder and same hash naming as the png form, taken as a DDS instead
and used for the block compressed formats.
source_ref: "app/src/main/cpp/vita3k/vita3k/renderer/src/texture/replacement.cpp:624-629"
- name: "<driver>.zip"
system: sony-playstation-vita
required: false
unsourceable: "Vulkan driver built for one Adreno family, not an emulator artefact"
description: "replacement Vulkan driver package"
note: >-
Listed by a catalog fetched from the EmuCoreV-Drivers repository, or picked
from the device. The archive is unpacked into a directory named after it
under driver in internal storage, the Vulkan library it holds is recorded
in a driver_name.txt written beside it, libvulkan.so taken first and any
other name carrying vulkan after it, and the renderer resolves
vkGetInstanceProcAddr through adrenotools from that pair before the Vulkan
instance is created. The system loader is used when no driver is
configured or the injection fails. The setting is shown only when the
device strings name Qualcomm hardware, or match an sm model with no other
vendor named.
source_ref: "app/src/main/java/com/sbro/emucorev/core/GpuDriverCatalogRepository.kt:45-78, app/src/main/java/com/sbro/emucorev/core/GpuDriverCatalogRepository.kt:130-136, app/src/main/java/com/sbro/emucorev/core/GpuDriverManager.kt:52-125, app/src/main/java/com/sbro/emucorev/core/GpuDriverManager.kt:136-171, app/src/main/java/com/sbro/emucorev/ui/settings/SettingsTabContent.kt:215, app/src/main/cpp/vita3k/vita3k/util/src/android_driver.cpp:202-215, app/src/main/cpp/vita3k/vita3k/util/src/android_driver.cpp:362-380, app/src/main/cpp/vita3k/vita3k/renderer/src/vulkan/renderer.cpp:371-387, app/src/main/cpp/vita3k/vita3k/renderer/src/vulkan/renderer.cpp:569-578"
- name: work.bin
path: "vita/ux0/license/<TITLEID>/<CONTENTID>.rif"
system: sony-playstation-vita
required: false
category: game_data
unsourceable: "NpDrm license issued for one copy of one title"
description: "title license"
note: >-
A picked file named work.bin, or carrying the .rif or .bin extension, is
read as a license, checked for its magic and copied under ux0:license as
<content id>.rif. A PKG install with no zRIF given reads the license
already sitting there for that content id and derives one from it. A
missing or corrupt license is logged and the retail livearea path is used
instead.
source_ref: "app/src/main/cpp/emucorev/src/vita_install_bridge.cpp:122-124, app/src/main/cpp/vita3k/vita3k/packages/src/license.cpp:53-84, app/src/main/cpp/vita3k/vita3k/packages/src/license.cpp:99-106, app/src/main/cpp/vita3k/vita3k/packages/src/pkg.cpp:356-376"
exclusion_note: >
Left out are the files EmuCoreV writes and reads back, which are emulator
state rather than system files: config.yml and the per-title custom configs,
the shader and texture caches under cache, savedata and users under ux0, the
TROPUSR.DAT trophy progress, play_time.json, the settings backup JSON and the
driver_name.txt the driver installer writes. Left out with them are the static
assets of Vita3K, which on Android are read from inside the package and never
exist on the filesystem: the built-in shaders, the ImGui fonts and images, and
the language files.
ref: app/src/main/cpp/vita3k/vita3k/app/src/app_init.cpp:244-256,
app/src/main/java/com/sbro/emucorev/core/EmulatorStorage.kt:122-148,
app/src/main/java/com/sbro/emucorev/core/GpuDriverManager.kt:90,
app/src/main/cpp/vita3k/vita3k/np/src/trophy/collection.cpp:95
+596
View File
@@ -0,0 +1,596 @@
emulator: EmuCoreX
type: standalone
core_classification: community_fork
source: "https://github.com/sashkinbro/EmuCoreX"
upstream: "https://github.com/PCSX2/pcsx2"
author: "Oleksandr (sashkinbro)"
profiled_date: "2026-08-11"
source_commit: "7d103230adfa671a3e66b090b8a7fe8f44edc09c"
upstream_commit: "53e3838c1dd59f611fa3d2fd36915903a1304c6e"
core_version: "0.3.3"
display_name: "Sony - PlayStation 2 (EmuCoreX)"
cores:
- emucorex
systems:
- sony-playstation-2
mode: standalone
bios_directory: "bios/"
resources_directory: "resources/"
notes: |
PlayStation 2 emulator for Android, package com.sbro.emucorex, arm64-v8a only,
minSdk 29. A Kotlin and Compose front end drives a PCSX2 tree vendored under
app/src/main/cpp/pcsx2 and pinned to v2.7.316, reached through the ARM_ANDROID
adapter that owns the JNI entry points. Frontends start the exported activity
com.sbro.emucorex.MainActivity; ES-DE passes the disc as the intent data URI.
ref: app/build.gradle.kts:53-56, app/build.gradle.kts:77,
app/src/main/AndroidManifest.xml:48-62,
app/src/main/cpp/ARM_ANDROID/CMakeLists.txt:77-79,
app/src/main/cpp/ARM_ANDROID/CMakeLists.txt:338
The whole upstream core is linked, with three files swapped out of the target:
Achievements.cpp, Host/SDLAudioStream.cpp and Input/SDLInputSource.cpp are
removed and replaced by the adapter's own achievements, AAudio and OpenSL, and
input sources. OpenGL and Vulkan are on, pcsx2-qt is never added, and the
DX11 and DX12 renderers sit in the Windows branch of the core CMakeLists.
ref: app/src/main/cpp/ARM_ANDROID/CMakeLists.txt:239-256,
app/src/main/cpp/ARM_ANDROID/CMakeLists.txt:58-59,
app/src/main/cpp/pcsx2/pcsx2/CMakeLists.txt:691,
app/src/main/cpp/pcsx2/pcsx2/CMakeLists.txt:708-712
Storage. The data root is the app files directory; the app creates cache,
resources, inis, sstates and memcards under it, then copies the whole resources
asset tree out of the package into resources. The core is handed AppRoot,
DataRoot, Resources, Settings and Cache from that root, and the launcher sets
Folders for Bios, Savestates, MemoryCards, Textures, Cheats, Patches and Logs
per run.
ref: app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:28,
app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:163-165,
app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:293-300,
app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:316-348,
app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:135-139,
app/src/main/java/com/sbro/emucorex/core/EmulatorBridge.kt:546-552
A BIOS image is required and boot stops without one: LoadBIOS returning false
makes VMManager report that a PlayStation 2 BIOS is needed. Only a GS dump
replay skips the load. Detection is by content: the folder scan keeps files
between 4 and 8 MB and accepts an image whose romdir carries a RESET entry
followed by a readable ROMVER, the fifth ROMVER character giving the zone among
Japan, USA, Europe, Asia, China, T10K, COH-H, Test and Free, with EXTINFO
supplying the serial. An image named in the configuration is opened at its own
path without the size filter. No name and no hash is matched.
ref: app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:16-17,
app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:80-197,
app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:258-294,
app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:317-369,
app/src/main/cpp/pcsx2/pcsx2/VMManager.cpp:1487-1499
The app runs its own gate over the same test before launching. A candidate is
a .bin or .rom between 512 KB and 8 MB whose name carries scph, ps2, bios or
rom, and it is confirmed by isBiosPath or isBiosFd, both of which call the
core's IsBIOS on the path or on /proc/self/fd.
ref: app/src/main/java/com/sbro/emucorex/core/BiosValidator.kt:13-19,
app/src/main/java/com/sbro/emucorex/core/BiosValidator.kt:110-137,
app/src/main/cpp/ARM_ANDROID/src/jni/native_app_jni.cpp:414-436
A BIOS folder picked through the storage access framework is copied flat into
imported-bios under the external files directory, and Folders/Bios points there.
The import filter takes any .bin or .rom, plus .mec, .nvm and .elf whose name
carries one of the hints. Neither rom1 nor rom2 is an accepted extension, and
LoadExtraRom looks for exactly {bios}.rom1 or {biosbase}.rom1, so the two ROM
modules only reach the core when Folders/Bios is a plain filesystem path used
as-is. A re-import preserves the .nvm and .mec sitting beside the image.
ref: app/src/main/java/com/sbro/emucorex/core/DocumentPathResolver.kt:25-27,
app/src/main/java/com/sbro/emucorex/core/DocumentPathResolver.kt:101-154,
app/src/main/java/com/sbro/emucorex/core/DocumentPathResolver.kt:366-388,
app/src/main/java/com/sbro/emucorex/core/DocumentPathResolver.kt:433-438,
app/src/main/java/com/sbro/emucorex/core/DocumentPathResolver.kt:492-499
Much of the bundled resource tree is compiled out on this platform and never
read. ImGuiManager::Initialize returns false before creating the ImGui context,
so LoadFontData and the three fonts it reads are unreachable, and SetFonts and
ReloadFonts both guard on that context. InitializeFullscreenUI returns false
unconditionally, so FullscreenUI::Initialize never runs and nothing under
fullscreenui or icons is loaded. The adapter reads two fonts of its own instead
and hands them over through SetFonts.
ref: app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:115-128,
app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:132-136,
app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:147,
app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:193-198,
app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:262-281,
app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:449-511,
app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:254-282,
app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:307
The three achievement sounds are the one resource the code reads that the tree
does not carry. Their directory holds only the README naming their origin,
while upstream v2.7.316 ships message.wav at 15696 bytes, lbsubmit.wav at 82096
and unlock.wav at 202702. All four sound settings default on, so a signed-in
session asks for them at every notification.
ref: app/src/main/cpp/pcsx2/bin/resources/sounds/achievements/README.txt:1-3,
app/src/main/cpp/ARM_ANDROID/src/integration/pcsx2_achievements_android.cpp:81-83,
app/src/main/cpp/pcsx2/pcsx2/Config.h:1346-1349,
app/src/main/cpp/pcsx2/pcsx2/Pcsx2Config.cpp:1951-1954
files:
- name: ps2-0230a-20080220.bin
path: bios/ps2-0230a-20080220.bin
system: sony-playstation-2
agnostic: true
required: true
min_size: 4194304
max_size: 8388608
validation: [size]
description: "PS2 BIOS image"
note: >-
Any image whose romdir holds RESET and ROMVER is accepted, whatever its
name. The 4 to 8 MB range gates the folder scan; an image named in the
configuration skips that range. Read into the 4 MB ROM region and truncated
to it. Shorter than 2465792 bytes disables the OSDSys parameter HLE.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:16-17, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:80-197, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:258-294, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:317-369"
- name: ps2-0230a-20080220.rom1
path: bios/ps2-0230a-20080220.rom1
system: sony-playstation-2
required: false
max_size: 4194304
description: "DVD player ROM"
note: >-
Tried as {bios}.rom1 then {biosbase}.rom1, with a case-insensitive retry on
the open. Copied to the ROM1 region and truncated to 4 MB. Logged and
skipped when absent. The storage access framework import does not carry
this extension, so it is reachable only from a plain BIOS folder path.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:214-241, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:366, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:371-381, app/src/main/java/com/sbro/emucorex/core/DocumentPathResolver.kt:25-27, app/src/main/java/com/sbro/emucorex/core/DocumentPathResolver.kt:433-438"
- name: ps2-0230a-20080220.rom2
path: bios/ps2-0230a-20080220.rom2
system: sony-playstation-2
required: false
max_size: 4194304
description: "Chinese ROM extension"
note: >-
Same two-step naming as rom1, copied to the ROM2 region. Present on Chinese
region consoles. Carried by the same import restriction as rom1.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:214-241, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:367, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:371-381"
- name: ps2-0230a-20080220.nvm
path: bios/ps2-0230a-20080220.nvm
system: sony-playstation-2
required: false
hle_fallback: true
size: 1024
description: "Console NVRAM"
note: >-
Read at the BIOS path with the extension replaced by nvm, case-insensitively.
Carries the console id, the iLink id, the model number and the OSD
configuration. A 1024 byte image is built in memory when the file is absent,
short, or carries a blank config block, filled with a fixed iLink id and the
language and region defaults of the detected BIOS region.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/CDVD/CDVD.cpp:46-47, app/src/main/cpp/pcsx2/pcsx2/CDVD/CDVD.cpp:160-163, app/src/main/cpp/pcsx2/pcsx2/CDVD/CDVD.cpp:165-189"
- name: ps2-0230a-20080220.mec
path: bios/ps2-0230a-20080220.mec
system: sony-playstation-2
required: false
hle_fallback: true
size: 4
description: "Mechacon version"
note: >-
Read at the BIOS path with the extension replaced by mec. Defaults to
0x00020603 and is written back at that path when it cannot be read.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/CDVD/CDVD.cpp:49, app/src/main/cpp/pcsx2/pcsx2/CDVD/CDVD.cpp:191-204"
- name: eeprom.dat
system: sony-playstation-2
required: false
hle_fallback: true
size: 64
description: "DEV9 EEPROM"
note: >-
Opened from the working directory when the network adapter starts and mapped
over 64 bytes. A compiled-in image stands in when the file is missing or
cannot be mapped.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/DEV9/DEV9.cpp:97-160"
- name: flash.dat
system: sony-playstation-2
required: false
hle_fallback: true
max_size: 8650752
description: "DEV9 SmartMedia flash image"
note: >-
Opened from the working directory at network adapter init and read as 1024
blocks of 16 pages of 512 bytes plus 16 ECC bytes. The card is filled with
0xFF when the file is absent.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/DEV9/flash.cpp:9-16, app/src/main/cpp/pcsx2/pcsx2/DEV9/flash.cpp:62-86"
- name: "<module>.irx"
system: sony-playstation-2
required: false
config_key: "EmuCore/CurrentIRX"
unsourceable: "any IOP module the user points at, under no name and no version the code expects"
description: "IOP module injected at boot"
note: >-
Read into the ROM region at 0x3C0000 when the IOP program counter reaches
0x1630 and the setting is longer than three characters. The launcher fills
it from the boot parameters when the picked file is an IRX. Empty otherwise.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:243-256, app/src/main/cpp/pcsx2/pcsx2/ps2/BiosTools.cpp:384-385, app/src/main/cpp/pcsx2/pcsx2/VMManager.cpp:1434, app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:334"
- name: GameIndex.yaml
path: resources/GameIndex.yaml
system: sony-playstation-2
required: false
bundled: true
category: game_data
description: "per-title compatibility and fix database"
note: >-
Opened from the resources directory and parsed into the game database that
drives per-title rounding modes, clamp modes, GS hacks and memory card
filters. The Kotlin catalog reads the same file straight out of the package
for the compatibility badges it draws.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GameDatabase.cpp:39, app/src/main/cpp/pcsx2/pcsx2/GameDatabase.cpp:976-977, app/src/main/java/com/sbro/emucorex/ui/gamedb/GameDbCatalogRepository.kt:96, app/src/main/java/com/sbro/emucorex/ui/gamedb/GameDbCatalogRepository.kt:202"
- name: RedumpDatabase.yaml
path: resources/RedumpDatabase.yaml
system: sony-playstation-2
required: false
bundled: true
category: game_data
description: "disc hash database"
note: >-
Opened from the resources directory and parsed into the hash database used
to name a disc from its dump.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GameDatabase.cpp:1081, app/src/main/cpp/pcsx2/pcsx2/GameDatabase.cpp:1138-1139"
- name: patches.zip
path: resources/patches.zip
system: sony-playstation-2
required: false
bundled: true
category: game_data
description: "built-in game patch archive"
note: >-
Opened read only from the resources directory as a zip source and searched
for the pnach matching the running serial and CRC. A failure to open is
reported once and the built-in patches are dropped for the session.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/Patch.cpp:117, app/src/main/cpp/pcsx2/pcsx2/Patch.cpp:289-310, app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:163-165"
- name: Roboto-Regular.ttf
path: resources/fonts/Roboto-Regular.ttf
system: sony-playstation-2
required: false
bundled: true
description: "core text font"
note: >-
Read by the adapter's own font setup before the VM starts and handed to the
core as the standard font. An empty font list is logged as a setup failure.
source_ref: "app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:254-262, app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:271-282, app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:307"
- name: Twemoji.Mozilla.ttf
path: resources/fonts/Twemoji.Mozilla.ttf
system: sony-playstation-2
required: false
bundled: true
description: "core emoji font"
note: >-
Read by the same font setup and appended as the emoji face. Skipped when the
file cannot be read.
source_ref: "app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:263-270, app/src/main/cpp/ARM_ANDROID/src/runtime/upstream_vm_bridge.cpp:271-282"
- name: tfx.glsl
path: resources/shaders/vulkan/tfx.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan texture and framebuffer shader"
note: >-
Read from the resources directory when the Vulkan device is created. A read
failure is reported and device creation fails.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Common/GSDevice.cpp:346-349, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:2400-2404"
- name: convert.glsl
path: resources/shaders/vulkan/convert.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan format conversion shader"
note: >-
Read when the conversion pipelines are compiled and again as the vertex
stage of the FXAA pipeline.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4462-4466, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4847-4851"
- name: present.glsl
path: resources/shaders/vulkan/present.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan presentation shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4676-4680"
- name: interlace.glsl
path: resources/shaders/vulkan/interlace.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan deinterlacing shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4726-4730"
- name: merge.glsl
path: resources/shaders/vulkan/merge.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan field merge shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4777-4781"
- name: shadeboost.glsl
path: resources/shaders/vulkan/shadeboost.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan brightness and contrast shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4882-4886"
- name: cas.glsl
path: resources/shaders/vulkan/cas.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan contrast adaptive sharpening shader"
note: >-
Read as a compute shader and its two include lines substituted with the
contents of the common headers. The Vulkan device compiles the CAS
pipelines unconditionally and returns on a failure, so a missing file stops
device creation rather than dropping the feature.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:2438-2439, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4932-4934, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Common/GSDevice.cpp:1038-1049"
- name: imgui.glsl
path: resources/shaders/vulkan/imgui.glsl
system: sony-playstation-2
required: true
bundled: true
description: "Vulkan overlay shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4959-4962"
- name: tfx_vgs.glsl
path: resources/shaders/opengl/tfx_vgs.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL texture and framebuffer vertex shader"
note: >-
Read from the resources directory when the OpenGL device is created.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Common/GSDevice.cpp:346-349, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:778"
- name: tfx_fs.glsl
path: resources/shaders/opengl/tfx_fs.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL texture and framebuffer fragment shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:779"
- name: convert.glsl
path: resources/shaders/opengl/convert.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL format conversion shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:514-518"
- name: present.glsl
path: resources/shaders/opengl/present.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL presentation shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:584"
- name: interlace.glsl
path: resources/shaders/opengl/interlace.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL deinterlacing shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:643"
- name: merge.glsl
path: resources/shaders/opengl/merge.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL field merge shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:620"
- name: shadeboost.glsl
path: resources/shaders/opengl/shadeboost.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL brightness and contrast shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:2423"
- name: cas.glsl
path: resources/shaders/opengl/cas.glsl
system: sony-playstation-2
required: false
bundled: true
description: "OpenGL contrast adaptive sharpening shader"
note: >-
Read as a compute program with the two include lines substituted, and needs
an ES 3.1 or 3.2 context. A failure turns CAS sharpening off.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:2577-2597, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Common/GSDevice.cpp:1038-1049"
- name: imgui.glsl
path: resources/shaders/opengl/imgui.glsl
system: sony-playstation-2
required: true
bundled: true
description: "OpenGL overlay shader"
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:2661"
- name: fxaa.fx
path: resources/shaders/common/fxaa.fx
system: sony-playstation-2
required: true
bundled: true
description: "antialiasing shader shared by both renderers"
note: >-
Read as the fragment stage of the FXAA pipeline on Vulkan, inside the
post-processing pipelines the device creation chain requires, so a missing
file stops device creation there. On OpenGL the program is compiled on its
own and an invalid one makes the FXAA pass return without drawing.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:2425-2430, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:4854-4858, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:2385-2390, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:2404-2407"
- name: ffx_a.h
path: resources/shaders/common/ffx_a.h
system: sony-playstation-2
required: true
bundled: true
description: "CAS support header"
note: >-
Read from the resources directory and pasted over the matching include line
of the CAS shader, the compilers having no include support. It shares the
fate of the CAS shader it is pasted into: fatal to device creation on
Vulkan, and only the sharpening feature on OpenGL.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Common/GSDevice.cpp:1038-1049, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:2438-2439, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:667"
- name: ffx_cas.h
path: resources/shaders/common/ffx_cas.h
system: sony-playstation-2
required: true
bundled: true
description: "CAS kernel header"
note: >-
Read and substituted the same way as the other CAS header, with the same
consequence per renderer when it is missing.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Common/GSDevice.cpp:1038-1049, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/Vulkan/GSDeviceVK.cpp:2438-2439, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/OpenGL/GSDeviceOGL.cpp:667"
- name: message.wav
path: resources/sounds/achievements/message.wav
system: sony-playstation-2
required: false
description: "achievement notification sound"
note: >-
Played from the resources directory whenever an achievement notification is
raised and no custom sound is configured. Sound effects and the notification
sound both default on. The vendored tree carries only the README for this
directory, so the file has to be supplied; the Android sound callback
returns without playing when the path is not a file. Upstream v2.7.316
ships it at 15696 bytes.
source_ref: "app/src/main/cpp/ARM_ANDROID/src/integration/pcsx2_achievements_android.cpp:81, app/src/main/cpp/ARM_ANDROID/src/integration/pcsx2_achievements_android.cpp:1245-1250, app/src/main/cpp/pcsx2/pcsx2/Pcsx2Config.cpp:1951-1954, app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:194-200"
- name: unlock.wav
path: resources/sounds/achievements/unlock.wav
system: sony-playstation-2
required: false
description: "achievement unlock sound"
note: >-
Played on an unlock under the same two settings, both on by default. Absent
from the vendored tree. Upstream v2.7.316 ships it at 202702 bytes.
source_ref: "app/src/main/cpp/ARM_ANDROID/src/integration/pcsx2_achievements_android.cpp:82, app/src/main/cpp/ARM_ANDROID/src/integration/pcsx2_achievements_android.cpp:1313-1318"
- name: lbsubmit.wav
path: resources/sounds/achievements/lbsubmit.wav
system: sony-playstation-2
required: false
description: "leaderboard submission sound"
note: >-
Played on a leaderboard submission under the same two settings, both on by
default. Absent from the vendored tree. Upstream v2.7.316 ships it at 82096
bytes.
source_ref: "app/src/main/cpp/ARM_ANDROID/src/integration/pcsx2_achievements_android.cpp:83, app/src/main/cpp/ARM_ANDROID/src/integration/pcsx2_achievements_android.cpp:1458-1463"
- name: games.db
path: "games.db"
system: sony-playstation-2
required: false
bundled: true
category: game_data
description: "bundled catalog of PS2 titles"
note: >-
SQLite catalog carried in the package assets and copied into internal
storage the first time the catalog is queried, then read from there. A copy
already present is kept.
source_ref: "app/src/main/java/com/sbro/emucorex/data/ps2/Ps2CatalogRepository.kt:18, app/src/main/java/com/sbro/emucorex/data/ps2/Ps2CatalogRepository.kt:38-56"
- name: "<SERIAL>_<CRC>.pnach"
path: "cheats/<SERIAL>_<CRC>.pnach"
system: sony-playstation-2
required: false
category: game_data
unsourceable: "cheat list authored per title, with no released artefact behind it"
description: "per-title cheat file"
note: >-
The cheats folder is searched for the running serial and CRC, then for files
carrying the CRC alone, both with a trailing wildcard so a suffix after the
CRC is kept. The patches folder is searched the same way for patches rather
than cheats. The app also imports pnach files out of a picked zip.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/Patch.cpp:331-342, app/src/main/cpp/pcsx2/pcsx2/Patch.cpp:344-366, app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:355"
- name: "<hash>.png"
path: "textures/<SERIAL>/replacements/<hash>.png"
system: sony-playstation-2
required: false
category: game_data
unsourceable: "replacement artwork authored against the texture hashes of one title"
description: "replacement texture"
note: >-
Read when texture replacement is on. The replacements folder under the
running serial is walked recursively and a file counts only when its name
parses as the TEX0 hash, optional CLUT hash, optional region size and format
that the texture cache looks it up by. A directory whose case does not match
is reported.
source_ref: "app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/HW/GSTextureReplacements.cpp:36-42, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/HW/GSTextureReplacements.cpp:328-331, app/src/main/cpp/pcsx2/pcsx2/GS/Renderers/HW/GSTextureReplacements.cpp:442-500"
- name: "<driver>.zip"
system: sony-playstation-2
required: false
unsourceable: "Vulkan driver built for one Adreno family, not an emulator artefact"
description: "replacement Vulkan driver package"
note: >-
Listed by a catalog fetched from the EmuCoreV-Drivers repository, or picked
from the device. The archive is unpacked into a directory named after it
under driver in internal storage, entries carrying a parent path segment
being refused, and the Vulkan library it holds is recorded in a
driver_name.txt written beside it. The renderer then resolves the driver
through adrenotools from that pair. The system loader is used when no driver
is configured.
source_ref: "app/src/main/java/com/sbro/emucorex/core/GpuDriverCatalogRepository.kt:131-135, app/src/main/java/com/sbro/emucorex/core/GpuDriverManager.kt:89-128, app/src/main/java/com/sbro/emucorex/core/GpuDriverManager.kt:135-141, app/src/main/cpp/ARM_ANDROID/src/runtime/android_runtime.cpp:98-112, app/src/main/cpp/ARM_ANDROID/src/runtime/android_runtime.cpp:362"
exclusion_note: >
Left out are the parts of the bundled resource tree that this platform compiles
out. ImGuiManager::Initialize returns false before the ImGui context exists, so
LoadFontData never runs and fonts/RobotoMono-Medium.ttf, fonts/fa-solid-900.ttf
and fonts/promptfont.otf are never read; InitializeFullscreenUI returns false
unconditionally, so FullscreenUI::Initialize never runs and nothing under
fullscreenui or icons is loaded, cover-placeholder.png included. The DX11 and
DX12 renderers sit in the Windows branch of the core CMakeLists, so
shaders/dx11 is dead here. game_controller_db.txt has one consumer,
Input/SDLInputSource.cpp, which the adapter removes from the target and replaces
with a source that never opens it. The user resource override folder is only
ever consulted by those same font and controller database reads, so it is dead
with them. Left out with these are the app's other package assets, which are
read through the asset manager and never reach the filesystem:
catalog/rom_identity_index.json, catalog/rom_identity_overrides.json and
catalog/pcsx2_compat_index.json. Left out too is what the emulator writes and
reads back, which is state rather than system files: the inis, the per-game
settings and input profiles, the memory cards, the save states, the snapshots,
the shader and texture caches, the logs, the dumped textures, and the
system-ca-bundle.pem the app exports from the Android trust store. The covers
folder is inert: its only readers are the FullscreenUI game list and
GameList::DownloadCovers, which has no caller, and the app runs its own cover
cache.
ref: app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:133-136,
app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:193-198,
app/src/main/cpp/pcsx2/pcsx2/ImGui/ImGuiManager.cpp:449-511,
app/src/main/cpp/pcsx2/pcsx2/ImGui/FullscreenUI.cpp:335,
app/src/main/cpp/pcsx2/pcsx2/CMakeLists.txt:691,
app/src/main/cpp/pcsx2/pcsx2/CMakeLists.txt:708-712,
app/src/main/cpp/pcsx2/pcsx2/Input/SDLInputSource.cpp:24,
app/src/main/cpp/ARM_ANDROID/CMakeLists.txt:239-243,
app/src/main/cpp/pcsx2/pcsx2/Pcsx2Config.cpp:2439-2446,
app/src/main/cpp/pcsx2/pcsx2/GameList.cpp:1336,
app/src/main/java/com/sbro/emucorex/data/ps2/Ps2CatalogRepository.kt:191-203,
app/src/main/java/com/sbro/emucorex/core/NativeApp.kt:166-171
+672
View File
@@ -0,0 +1,672 @@
emulator: ePSXe
type: standalone
core_classification: other
source: "https://www.epsxe.com/download.php"
upstream: closed-source
author: "calb, _Demo_, Galtor (ePSXe Software S.L.)"
profiled_date: "2026-08-11"
core_version: "2.0.18"
display_name: "Sony - PlayStation (ePSXe)"
cores:
- epsxe
systems:
- sony-playstation
mode: standalone
bios_directory: "bios/"
bios_size: 524288
notes: |
PlayStation emulator, closed source and distributed as a binary. Five builds
are read here. The desktop ones come from the download page: 2.0.18 Windows
(md5 c1abd8cffcd0bc3dbd9c72b13bfc20e5, UPX packed, cited at the virtual
addresses of the unpacked image), 2.0.5 Windows (bfa6eb173d9bae9b2e7983b23383c789),
2.0.5 Linux x64 (52ef10e78aeec86f84105b7b59d375ee), 2.0.5 Linux x86
(efe6c2c6303d4f7c5251166342bfb002) and 2.0.5 macOS x64
(c4ca85710fbea827da2a1ce304536973). The Linux x64 build keeps 1771 of its own
functions in .dynsym although it reports as stripped, so it is cited by
function name. The Android side is package com.epsxe.ePSXe, versionCode 139
versionName 2.0.15, apk md5 e18988b825f263bbc961bfbed1c4bc0b, with 2.0.6
(fce9c60c5cbc4e075cf97a587e64eb78) read alongside it; both verify against the
epsxe.com signing certificate (CN=epsxeteam, serial 0x4fdaca68), every entry
digest matches and none is unsigned. Two copies of 2.0.16 circulating on
archive.org are repackaged, signed CN=A1 and ModYolo, and are not read here.
ref: epsxe.com/download.php, com.epsxe.ePSXe META-INF/CERT.RSA
One root holds everything. On Linux and macOS it is $HOME/.epsxe, created at
startup together with plugins, bios, cheats, sstates, patches, idx, config,
info, covers, memcards, memcards/games, memcards/net, shaders and configs, and
the process chdirs into it. On Windows it is the program directory with the
same names. On Android it is a directory named epsxe at the root of shared
storage, holding sstates, bios, isos, cheats, config, idx, patches, plugins,
faqs, shaders, memcards and covers. Paths below are relative to that root.
ref: ePSXe 2.0.5 Linux x64 create_folders 0x42a727-0x42abcf,
ePSXe.java:1517, ePSXe.java:1541-1577
Exactly one BIOS file is ever loaded, and its full path is a setting, not a
name the code looks for: BiosPath in $HOME/.epsxe/epsxerc on Linux and macOS,
biosPref in the shared preferences on Android, both defaulting to
bios/scph1001.bin below the root. load_bios opens it read only, reads one block
of 0x80000 bytes into the 0x80000-byte psxBIOS object and logs
" * ePSXe: PSX BIOS loaded [%s]. ". A file that will not open reaches
emu_mesg_exit_error with " * !Error: PSX BIOS not found [%s]. " and the run
ends. The HLE branch, taken when the BiosHLE setting is on, skips the read
entirely and logs " * ePSXe: using HLE BIOS (compatibility limited)", so any
one of the images below fills the slot and none of them is needed on its own.
HLE arrived in 1.9.25 and savestates made under it are not interchangeable
with savestates made under a real image.
ref: ePSXe 2.0.5 Linux x64 load_bios 0x433540-0x433621,
ePSXe 2.0.5 Linux x64 bios_name_select 0x4334c0-0x4334f2,
ePSXe 2.0.5 Linux x64 write_configfiledefault 0x42ae99-0x42aeeb,
ePSXeReadPreferences.java:20-30, ePSXe.java:445-453,
docs/ePSXe_en.txt:260-271, docs/ePSXe_en.txt:883-888
Both consumer families carry a table of the images they recognise, and the two
tables are built differently and do not hold the same set. Android ships 21
pairs of label and md5; findBios walks the tree to a depth of ten, skipping
DCIM, Camera, asec, secure, dev, obb, .lfs and anything under /Android/data,
keeps files whose lowercased name ends in .bin and whose length is exactly
524288, md5s each one and on a hit writes biosPref to that path and turns
BiosHLE off. Windows ships 21 records of a 32-byte name and a 32-bit id, globs
bios\*.bin, reads each candidate whole and identifies it by a checksum of its
own: over the 512 KB as big endian 16-bit words, the sum shifted left 16 bits
or'd with the low 16 bits of the xor. That value is looked up only to name the
image in the setup wizard. The Linux and macOS builds carry neither table.
Seventeen dumps are in both tables; four are known to Android alone; two are
known to Windows alone and both turn out to be dumps TOSEC marks [b].
ref: ScanBiosTask.java:28, ScanBiosTask.java:145-191, ePSXeNative.java:280,
ePSXe 2.0.18 Windows 0x5c1090-0x5c1384, ePSXe 2.0.18 Windows 0x5c108c,
ePSXe 2.0.18 Windows 0x42f264-0x42f2c7,
ePSXe 2.0.18 Windows 0x42f4b0-0x42f568,
ePSXe 2.0.18 Windows 0x42f584-0x42f5b4
No region decides which image is taken. findBios keeps the first md5 that
answers anywhere in the walk, the Windows ids only pick a label to display, and
the JP, US and PAL words are part of that label string. Automatic selection of
a required BIOS per game existed once and was removed because it stopped
Legend of Dragoon US and Wild Arms 2 US from running.
ref: ScanBiosTask.java:167-171, ePSXe 2.0.18 Windows 0x42f5aa-0x42f5c2,
docs/ePSXe_en.txt:1243-1244
Video, sound, cdrom and input go through the PSEmu Pro plugin interface.
init_gpu builds plugins/<name> from the configured name, dlopens it and
resolves GPUinit, GPUopen, GPUdmaChain and the rest of the entry points one by
one; init_spu_plugins and LoadPadPlugins do the same for their own. Windows
enumerates gpu*.dll, spu*.dll and cdr*.dll in plugins\. GPUCORE, SPUCORE and
INPUTCORE are the built-in defaults and are not files. Android has no PSEmu Pro
loader: its two OpenGL renderers ship inside the package and are only replaced
when a file of the matching name is found under plugins.
ref: ePSXe 2.0.5 Linux x64 init_gpu 0x4408a1-0x440bc0,
ePSXe 2.0.5 Linux x64 LoadPadPlugins 0x51927e,
ePSXe 2.0.5 Linux x64 write_configfiledefault 0x42ae29-0x42ae6e,
ePSXe.java:842-977
Per-title files are looked up beside the running game. ISOtestsubchannel reads
patches/<name>.SBI, then patches/<name>.sbi, and reports " * Subchannel support
from .sbi file. " when one answers. initGSCodes reads the cheat file
cheats/<code>.txt keyed on the game code, on top of the two cheat databases
load_cheat_dynamic_database opens from cheats. Android downloads the same cheat
file from epsxe.com into cheats, reads faqs/<code>.txt into its help viewer and
fills covers from epsxe.com.
ref: ePSXe 2.0.5 Linux x64 ISOtestsubchannel 0x46f198-0x46f263,
ePSXe 2.0.5 Linux x64 initGSCodes 0x432ea4-0x432f11,
ePSXe 2.0.5 Linux x64 load_cheat_dynamic_database 0x431bc7-0x431cac,
DownloadCheatFileTask.java:49-55, ePSXe.java:1047, ePSXe.java:1896,
ImageLoader.java:88
Shaders are directories, not single files. createProgramCustom reads
<dir>/gpuCore.slv and <dir>/gpuCore.slf and readPropertiesProgramCustom reads
<dir>/gpuCore.ini beside them, one directory per effect, and a stage that will
not open logs " (unable to read shader file %s) ". The shaders pack on
epsxe.com carries these triplets and Android pulls the same set one file at a
time from an index it downloads first. The integrated Pete OpenGL2 plugin has
its own set under the configured shader directory, defaulting to SHADERS\.
ref: ePSXe 2.0.5 Linux x64 createProgramCustom 0x4f7d7e-0x4f7f42,
ePSXe 2.0.18 Windows 0x4fb220-0x4fb263,
DownloadShaderPluginTask.java:56-80
files:
- name: scph1000.bin
path: bios/scph1000.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 239665b1a3dade1b5a52c06338011044
description: "SCPH-1000, DTL-H1000 (v1.0 J)"
note: "Windows names this image scph1000 - JP and identifies it by id 0xb817c93d."
source_ref: "ScanBiosTask.java:28, ScanBiosTask.java:162-172, ePSXe 2.0.18 Windows 0x5c10b4"
- name: scph1001.bin
path: bios/scph1001.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 924e392ed05558ffdb115408c263dccf
description: "SCPH-1001, DTL-H1201, DTL-H3001 (v2.2 12-04-95 A)"
note: "The name the default BiosPath and biosPref point at on every platform. Windows names it scph1001 - US (Recommended) and identifies it by id 0x4c1e4c6a."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.5 Linux x64 write_configfiledefault 0x42ae99, ePSXeReadPreferences.java:21, ePSXe 2.0.18 Windows 0x5c10d8"
- name: scph1001_v20.bin
path: bios/scph1001_v20.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: dc2b9bf8da62ec93e868cfd29f0d067d
description: "DTL-H1001 (v2.0 05-07-95 A)"
note: "Windows names this image scph1200 - JP and identifies it by id 0xdac96c37."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1120"
- name: scph1002a.bin
path: bios/scph1002a.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 54847e693405ffeb0359c6287434cbef
description: "SCPH-1002, DTL-H1002 (v2.0 05-10-95 E)"
note: "Windows names this image scph1002 - PAL and identifies it by id 0xea0b1691."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c10fc"
- name: scph3000.bin
path: bios/scph3000.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 849515939161e62f6b866f6853006780
description: "SCPH-3000, DTL-H1000H (v1.1 01-22-95)"
note: "Windows names this image scph3000 - JP and identifies it by id 0x4d0889a4."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1144"
- name: scph3500.bin
path: bios/scph3500.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: cba733ceeff5aef5c32254f1d617fa62
description: "SCPH-3500 (v2.1 07-17-95 J)"
note: "Windows names this image scph3500 - JP and identifies it by id 0x4dab5145."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1168"
- name: dtlh1100.bin
path: bios/dtlh1100.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "biosPref"
size: 524288
validation: [size, md5]
md5: ca5cfc321f916756e3f0effbfaeba13b
description: "DTL-H1100 (v2.2 03-06-96 D)"
note: "Known to the Android table alone; no Windows record carries its checksum."
source_ref: "ScanBiosTask.java:28, ScanBiosTask.java:162-172"
- name: scph1001_v21.bin
path: bios/scph1001_v21.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "biosPref"
size: 524288
validation: [size, md5]
md5: da27e8b6dab242d8f91a9b25d80c63b8
description: "DTL-H1101 (v2.1 07-17-95 A)"
note: "Known to the Android table alone; no Windows record carries its checksum."
source_ref: "ScanBiosTask.java:28, ScanBiosTask.java:162-172"
- name: scph1002b.bin
path: bios/scph1002b.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "biosPref"
size: 524288
validation: [size, md5]
md5: 417b34706319da7cf001e76e40136c23
description: "SCPH-1002, DTL-H1102 (v2.1 07-17-95 E)"
note: "Known to the Android table alone; no Windows record carries its checksum."
source_ref: "ScanBiosTask.java:28, ScanBiosTask.java:162-172"
- name: scph5000.bin
path: bios/scph5000.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "biosPref"
size: 524288
validation: [size, md5]
md5: 57a06303dfa9cf9351222dfcbb4a29d9
description: "SCPH-5000, DTL-H1200 (v2.2 12-04-95 J)"
note: "Known to the Android table alone. The Windows record labelled scph5000 identifies a different dump."
source_ref: "ScanBiosTask.java:28, ScanBiosTask.java:162-172"
- name: scph1002c.bin
path: bios/scph1002c.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: e2110b8a2b97a8e0b857a45d32f7e187
description: "SCPH-1002, DTL-H1202, DTL-H3002 (v2.2 12-04-95 E)"
note: "Windows names this image dtlh3002 - PAL and identifies it by id 0xc8ec73c0."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1090"
- name: scph5500.bin
path: bios/scph5500.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 8dd7d5296a650fac7319bce665a6a53c
description: "SCPH-5500 (v3.0 09-09-96 J)"
note: "Windows names this image scph5500 - JP and identifies it by id 0xa8bc4eba."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c11b0"
- name: scph5501.bin
path: bios/scph5501.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 490f666e1afb15b7362b406ed1cea246
description: "SCPH-5501, SCPH-7003 (v3.0 11-18-96 A)"
note: "Windows names this image scph7003 - JP and identifies it by id 0xbe16f916."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1288"
- name: scph5502.bin
path: bios/scph5502.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 32736f17079d0b2b7024407c39bd3050
description: "SCPH-5502, SCPH-5552 (v3.0 01-06-97 E)"
note: "Windows names this image scph5552 - PAL and identifies it by id 0x19181dce."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c11f8"
- name: scph7000.bin
path: bios/scph7000.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 8e4c14f567745eff2f0408c8129f72a6
description: "SCPH-7000, SCPH-9000 (v4.0 08-18-97 J)"
note: "Windows names this image scph7000 - JP and identifies it by id 0x43771cd1."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c121c"
- name: scph7001.bin
path: bios/scph7001.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 1e68c231d0896b7eadcad1d7d8e76129
description: "SCPH-7001, SCPH-7501, SCPH-7503, SCPH-9001 (v4.1 12-16-97 A)"
note: "Windows names this image scph7001 - US and identifies it by id 0x6c1ba989."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1240"
- name: scph7002.bin
path: bios/scph7002.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: b9d9a0286c33dc6b7237bb13cd46fdee
description: "SCPH-7002, SCPH-7502, SCPH-9002 (v4.1 12-16-97 E)"
note: "The one dump three Windows records share, scph7002 - PAL, scph7502 - PAL (Recommended) and scph9002 - PAL, all carrying id 0x701bad89."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1264, ePSXe 2.0.18 Windows 0x5c12ac, ePSXe 2.0.18 Windows 0x5c12d0"
- name: scph100.bin
path: bios/scph100.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 8abc1b549a4a80954addc48ef02c4521
description: "SCPH-100 (v4.3 03-11-00 J)"
note: "Windows names this image scph100 - JP and identifies it by id 0x061a33e2."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c12f4"
- name: scph102_v44.bin
path: bios/scph102_v44.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: b10f5e0e3d9eb60e5159690680b1e774
description: "SCPH-102 (v4.4 03-24-00 E)"
note: "Windows names this image scph102A - PAL and identifies it by id 0x9337252b, the A and B suffixes separating the two SCPH-102 revisions."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c133c"
- name: scph101_v45.bin
path: bios/scph101_v45.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: 6e3735ff4c7dc899ee98981385f6f3d0
description: "SCPH-101 (v4.5 05-25-00 A)"
note: "Windows names this image scph101 - US and identifies it by id 0x6e7f8edd."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1318"
- name: scph102_v45.bin
path: bios/scph102_v45.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size, md5]
md5: de93caec13d1a141a40a79f5c86168d6
description: "SCPH-102 (v4.5 05-25-00 E)"
note: "Windows names this image scph102B - PAL and identifies it by id 0x727f8add."
source_ref: "ScanBiosTask.java:28, ePSXe 2.0.18 Windows 0x5c1360"
- name: scph5000_b.bin
path: bios/scph5000_b.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size]
md5: eb201d2d98251a598af467d4347bb62f
description: "SCPH-5000, DTL-H1200, DTL-H3000 (v2.2 12-04-95 J), bad dump"
note: "Recognised by Windows alone, as scph5000 - JP with id 0xa63468aa. That record is pinned on a checksum, not on a hash the code spells out; the md5 here is the dump that reproduces the checksum. TOSEC tags the same dump [b]."
source_ref: "ePSXe 2.0.18 Windows 0x5c118c, ePSXe 2.0.18 Windows 0x42f525-0x42f568"
- name: scph5502_b.bin
path: bios/scph5502_b.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosPath"
size: 524288
validation: [size]
md5: e56ec1b027e2fe8a49217d9678f7f6bb
description: "SCPH-5502, SCPH-5552 (v3.0 01-06-97 E), bad dump"
note: "Recognised by Windows alone, as scph5502 - PAL with id 0x702fa307, resolved the same way as the SCPH-5000 bad dump above. TOSEC tags it [b]."
source_ref: "ePSXe 2.0.18 Windows 0x5c11d4, ePSXe 2.0.18 Windows 0x42f525-0x42f568"
- name: "<game>.sbi"
path: "patches/<game>.sbi"
system: sony-playstation
required: false
category: game_data
aliases: ["<game>.SBI"]
description: "subchannel data for a libcrypt protected disc"
note: "Named after the running disc. The uppercase extension is tried first and the lowercase one second, and a disc with neither runs on the built-in substitute, reported as fake .sbi."
source_ref: "ePSXe 2.0.5 Linux x64 ISOtestsubchannel 0x46f198-0x46f263"
- name: database.dat
path: cheats/database.dat
system: sony-playstation
required: false
category: game_data
description: "cheat code database"
note: "Opened read only from cheats at startup. Absent, the session runs with no library behind the per-title files."
source_ref: "ePSXe 2.0.5 Linux x64 load_cheat_dynamic_database 0x431bc7-0x431bd0"
- name: dataconf.dat
path: cheats/dataconf.dat
system: sony-playstation
required: false
category: game_data
description: "cheat database index, keyed on the disc serial"
note: "Read after database.dat into CheatDataConf, mapping serials such as SLUS_011.60 onto entries of the library."
source_ref: "ePSXe 2.0.5 Linux x64 load_cheat_dynamic_database 0x431ca7-0x431cfa"
- name: "<code>.txt"
path: "cheats/<code>.txt"
system: sony-playstation
required: false
category: game_data
description: "cheat codes for one title"
note: "Named after the disc serial and parsed as a list of hex address and value pairs under bracketed titles. Android downloads it from epsxe.com into the same directory."
source_ref: "ePSXe 2.0.5 Linux x64 initGSCodes 0x432ea4-0x43304d, DownloadCheatFileTask.java:49-55"
- name: gpuCore.slv
path: "shaders/<name>/gpuCore.slv"
required: false
category: game_data
description: "vertex stage of one GPUCORE shader effect"
note: "One directory per effect. A stage that will not open logs the unable to read shader file message and the effect is dropped. The shaders pack on epsxe.com carries the set."
source_ref: "ePSXe 2.0.5 Linux x64 createProgramCustom 0x4f7d7e-0x4f7db9, DownloadShaderPluginTask.java:68-76"
- name: gpuCore.slf
path: "shaders/<name>/gpuCore.slf"
required: false
category: game_data
description: "fragment stage of one GPUCORE shader effect"
note: "Read straight after the vertex stage from the same directory."
source_ref: "ePSXe 2.0.5 Linux x64 createProgramCustom 0x4f7dcd-0x4f7df1, DownloadShaderPluginTask.java:69-78"
- name: gpuCore.ini
path: "shaders/<name>/gpuCore.ini"
required: false
category: game_data
description: "parameters of one GPUCORE shader effect"
note: "Read beside the two stages once they link. Not every effect in the pack ships one."
source_ref: "ePSXe 2.0.5 Linux x64 readPropertiesProgramCustom 0x4f7c30, ePSXe 2.0.5 Linux x64 createProgramCustom 0x4f7f15, DownloadShaderPluginTask.java:70-80"
- name: gpuPeteOGL2.slv
path: "shaders/gpuPeteOGL2.slv"
required: false
category: game_data
description: "GLSlang vertex stage of the integrated Pete OpenGL2 plugin"
note: "Resolved under the configured shader directory, defaulting to SHADERS\\. Selected by the GLSlang shader effect setting."
source_ref: "ePSXe 2.0.18 Windows 0x4fbd79-0x4fbd7e, ePSXe 2.0.18 Windows 0x4fb220-0x4fb263"
- name: gpuPeteOGL2.slf
path: "shaders/gpuPeteOGL2.slf"
required: false
category: game_data
description: "GLSlang fragment stage of the integrated Pete OpenGL2 plugin"
note: "Read from the same directory as the vertex stage."
source_ref: "ePSXe 2.0.18 Windows 0x4fbe80, ePSXe 2.0.18 Windows 0x4fb220-0x4fb263"
- name: gpuPeteOGL2.vp
path: "shaders/gpuPeteOGL2.vp"
required: false
category: game_data
description: "ARB vertex program of the integrated Pete OpenGL2 plugin"
note: "The ARB alternative to the GLSlang pair, taken by a different value of the shader effect setting, and reporting the offset when the program fails to assemble."
source_ref: "ePSXe 2.0.18 Windows 0x4faaf2, ePSXe 2.0.18 Windows 0x59f534-0x59f580"
- name: gpuPeteOGL2.fp
path: "shaders/gpuPeteOGL2.fp"
required: false
category: game_data
description: "ARB fragment program of the integrated Pete OpenGL2 plugin"
note: "Read alongside the vertex program."
source_ref: "ePSXe 2.0.18 Windows 0x4fabbb, ePSXe 2.0.18 Windows 0x59f4c8-0x59f518"
- name: "gpuPeteOGL2_t<n>l.tga"
path: "shaders/gpuPeteOGL2_t<n>l.tga"
required: false
category: game_data
description: "linear lookup texture of the integrated Pete OpenGL2 plugin"
note: "Numbered per effect and resolved from the same directory as the shader stages. One of two names formatted into the same slot, the other being the nearest flavour, picked on the remainder of the effect index."
source_ref: "ePSXe 2.0.18 Windows 0x4fb429-0x4fb433, ePSXe 2.0.18 Windows 0x59f43c"
- name: "gpuPeteOGL2_t<n>n.tga"
path: "shaders/gpuPeteOGL2_t<n>n.tga"
required: false
category: game_data
description: "nearest lookup texture of the integrated Pete OpenGL2 plugin"
note: "The alternative to the linear flavour, taken when the index divides evenly, and read again on its own further in."
source_ref: "ePSXe 2.0.18 Windows 0x4fb3de, ePSXe 2.0.18 Windows 0x4fb573, ePSXe 2.0.18 Windows 0x59f424"
- name: "gpu<name>.dll"
path: "plugins/gpu<name>.dll"
system: sony-playstation
required: false
category: game_data
aliases: ["libgpu<name>.so"]
description: "PSEmu Pro video plugin"
note: "Named by the VideoPlugin setting, opened from plugins and bound entry point by entry point, from GPUinit and GPUopen through GPUdmaChain to GPUregisterResolutionCallback, each missing symbol logged as a dlsym error. Windows enumerates the directory on gpu*.dll. The built-in GPUCORE and the integrated Pete OpenGL2 plugin need no file."
source_ref: "ePSXe 2.0.5 Linux x64 init_gpu 0x4408a1-0x440d5d, ePSXe 2.0.18 Windows 0x58aded"
- name: "spu<name>.dll"
path: "plugins/spu<name>.dll"
system: sony-playstation
required: false
category: game_data
aliases: ["libspu<name>.so"]
description: "PSEmu Pro sound plugin"
note: "Named by the SoundPlugin setting. Windows enumerates the directory on spu*.dll. The built-in SPUCORE needs no file."
source_ref: "ePSXe 2.0.5 Linux x64 init_spu_plugins, ePSXe 2.0.5 Linux x64 write_configfiledefault 0x42ae40"
- name: "cdr<name>.dll"
path: "plugins/cdr<name>.dll"
system: sony-playstation
required: false
category: game_data
aliases: ["libcdr<name>.so"]
description: "PSEmu Pro cdrom plugin"
note: "Enumerated on cdr*.dll and initialised through init_plugins_cdrom. Reading a disc image directly needs none."
source_ref: "ePSXe 2.0.5 Linux x64 init_plugins_cdrom, ePSXe 2.0.18 Windows 0x58af0d"
- name: "pad<name>.dll"
path: "plugins/pad<name>.dll"
system: sony-playstation
required: false
category: game_data
aliases: ["libpad<name>.so"]
description: "PSEmu Pro input plugin"
note: "Named by the InputPlugin and Input2Plugin settings and loaded from plugins by LoadPadPlugins. The built-in INPUTCORE needs no file."
source_ref: "ePSXe 2.0.5 Linux x64 LoadPadPlugins 0x51927e, ePSXe 2.0.5 Linux x64 write_configfiledefault 0x42ae57-0x42ae6e"
- name: liboglplugin2.so
path: plugins/liboglplugin2.so
system: sony-playstation
required: false
bundled: true
category: game_data
description: "OpenGL2 renderer of the Android build"
note: "Android only. Read when the renderer setting is 5: a copy found under plugins is staged into the private directory and used, otherwise the one inside the package answers and the setting falls back to the software renderer if neither is there."
source_ref: "ePSXe.java:847-886"
- name: libogl2extplugin.so
path: plugins/libogl2extplugin.so
system: sony-playstation
required: false
bundled: true
category: game_data
description: "extended OpenGL2 renderer of the Android build"
note: "Android only. Same override path as liboglplugin2.so, taken when the renderer setting is 4."
source_ref: "ePSXe.java:887-926"
- name: libopenglplugin.so
path: libopenglplugin.so
system: sony-playstation
required: false
category: game_data
description: "external OpenGL plugin of the Android build"
note: "Android only. Named by the gpuPref setting, which points at the root of shared storage by default and is also looked for under the package library directory and the secondary card."
source_ref: "ePSXe.java:927-966, ePSXeReadPreferences.java:32-34, ePSXe 2.0.15 libepsxe.so 0x176128, ePSXe 2.0.15 libepsxe.so 0x176160"
- name: "<code>.txt"
path: "faqs/<code>.txt"
system: sony-playstation
required: false
category: game_data
unsourceable: "guide text the user files under the disc serial"
description: "in-app guide for one title"
note: "Android only. Named after the disc serial and loaded into the help viewer as a local page; the menu entry is offered only when the file is there."
source_ref: "ePSXe.java:1047, ePSXe.java:1857, ePSXe.java:1896"
- name: skin.png
path: skin.png
required: false
category: game_data
unsourceable: "pad artwork the user supplies"
description: "on-screen controller skin"
note: "Android only. Named by the skinPref setting, which points at the root of shared storage by default, and handed to the view as the input skin."
source_ref: "ePSXeReadPreferences.java:36-38, ePSXeNative.java:702"
- name: "<hash>.jpg"
path: "covers/<hash>.jpg"
system: sony-playstation
required: false
category: game_data
description: "cover art for one title"
note: "Cached under covers and fetched from epsxe.com when absent, the desktop builds falling back to a shipped na.jpg when the fetch finds nothing."
source_ref: "ImageLoader.java:88, ePSXe 2.0.5 Linux x64 download_covers, ePSXe 2.0.5 Linux x64 0x572ea0"
exclusion_note: >
Left out are the files ePSXe writes and reads back itself, which are emulator
state rather than files a user has to obtain: the epsxerc configuration and the
per-title profiles under config, the memory cards memcards/epsxe000.mcr and
epsxe001.mcr with the per-game pairs memcards/games/<name>-00.mcr and -01.mcr
and the Windows scratch pair memcards/temp.000 and temp.001, the savestates and
their .pic thumbnails under sstates, the ECM indexes under idx, the game list
and scan records under info, epsxe.log, and shadererr.txt, which is only
written when a shader stage fails to compile. Left out with them are the ROM
images themselves and the .cue, .ccd, .mds, .ecm and .pbp sidecars of a disc.
The HLE BIOS is not a file either: it is code, and the ASCII and JIS fonts it
draws with are compiled into the binary as bios_ascii_font and bios_jis_font.
ref: ePSXe 2.0.5 Linux x64 write_configuration 0x42d330,
ePSXe 2.0.5 Linux x64 bios_ascii_font 0x883740,
ePSXe 2.0.5 Linux x64 bios_jis_font 0x883d00,
ePSXe 2.0.5 Linux x64 0x565110, ePSXe 2.0.5 Linux x64 0x56d164,
ePSXe 2.0.18 Windows 0x595600
+302
View File
@@ -0,0 +1,302 @@
emulator: FPseNG
type: standalone
core_classification: other
source: "https://play.google.com/store/apps/details?id=com.emulator.fpse64"
upstream: closed-source
author: "Schtruck & LDchen"
profiled_date: "2026-08-11"
core_version: "1.13"
display_name: "Sony - PlayStation (FPseNG)"
cores:
- "fpse-ng"
- "fpseng"
- "fpse64"
systems:
- sony-playstation
mode: standalone
bios_directory: "bios/"
bios_size: 524288
notes: |
PlayStation emulator for Android, closed source, sold on Google Play as package
com.emulator.fpse64 and named FPse64 until the rename. The build read here is
1.13, versionCode 245, minSdk 23, targetSdk 33, activity
com.emulator.fpse64.Main. Google signs the package through Play App Signing,
CN=Android O=Google Inc. issued 2020-05-02, sha256
5df4c204abac4d2a10c4b8f497689e28c2bfb5dc44a56081ebb4a5e1c2f1d27f, and that
signature block travels inside the copy read here: the repackager kept the
original apk as assets/SignatureKiller/origin.apk, whose MANIFEST.MF carries
the sha256 of all 1278 entries of the distributed build. 1274 match byte for
byte, among them every native library and every resource; AndroidManifest.xml,
classes.dex and resources.arsc differ, stamp-cert-sha256 is dropped and one
class, bin/mt/signature/KillerApplication, is added. Native code and resources
are therefore the distributed ones and the java below is the application's own,
minus that injection. A second copy, apkvision 1.8, is signed with the Android
test key and ships three of the eight libraries its own core links against; it
is read only to confirm that the preference key, the two size tests and the
checksum constant below are the application's and not the repackager's.
ref: com.emulator.fpse64 1.13 assets/SignatureKiller/origin.apk
META-INF/GOOGPLAY.RSA, META-INF/MANIFEST.MF
Two roots hold everything. The private files directory of the package is the
one the core is given, and bios, plugin, cfg and skin are created under it
right after the libraries load; the emulator resolves its own paths against it.
The second is a directory named FPse64 at the root of shared storage, holding
memcards, cheats, shaders, ogl, sbi, sstates, titles, icons, videos and
filelist.txt. Paths below are relative to the first root unless they name the
second.
ref: Main.java:36420, Main.java:3004, Main.java:27329-27332,
Main.java:27458-27459, Main.java:30411-30413
Exactly one BIOS image is ever loaded and its full path is a setting rather
than a name the code looks for. The Load Bios browser keeps .bin files and
lists only those of exactly 524288 bytes, the chosen path is written to the
preference com.emulator.fpse64.biospath and pushed into the core as string
slot 6, and the stored path is re-checked at every start: a file that no longer
exists or is not exactly 524288 bytes clears the preference and the session
runs on HLE. Slot 6 receives the empty string whenever the path is empty, the
BIOS switch is off or the launching intent carried bios=0, which is the
documented way to ask for HLE; the shortcuts the application pins carry that
same extra. On the core side the value is opened as given, then retried below
bios/ under the root, so a bare name resolves there; a hit is read as one block
of 0x80000 bytes after "Loading '%s'...", and a miss reports "Can't load
biosfile '%s', switching to HLE", sets the HLE bit and writes
"CEX-3000/1001/1002 by K.S.", "System ROM Version 2.2 12/04/95 A" and the Sony
copyright line into BIOS memory, so no image is needed on its own. The FAQ on
the emulator's own site states that a file named scph1001.bin is recommended
and is not distributed with the emulator.
ref: Main.java:1169, Main.java:21925-21927, Main.java:25833-25835,
Main.java:9943-9977, Main.java:30177-30192, Main.java:5392-5396,
Main.java:36446-36451, Main.java:28751-28754,
libfpse.so 0x70e20-0x70f20, fpsece.net/faq.html
Automatic detection recognises one dump and does it on content. Scanning
storage, FPseNG keeps files whose lowercased name ends in .bin and whose length
is exactly 524288, reads all 524288 bytes, sums them as signed bytes and
accepts the file when the total is 85958, writing the path to the preference
and turning the BIOS on. The same constant answers over NFS through isnfsbios.
Recomputed over the collection, that sum resolves to a single image, the
v2.2 12/04/95 A dump listed below, and to no other. The HLE path impersonates
the same revision: its identification strings sit in .rodata beside "HLE
enabled." and the library carries no 512 KB image of its own.
ref: Main.java:24466-24487, Main.java:24491, Main.java:25670,
libfpse.so .rodata 0x1b8d81-0x1b8dfb
Emulation is split across libraries the core links against. libfpse.so lists
libopengl, libsoft1, libspuplugin, libneon, libsdl and libnfsplugin in
DT_NEEDED, and Main names uncompress, spuplugin, soft1, nfsplugin and opengl
before fpse; sdl and neon are named earlier from a static block that swallows
UnsatisfiedLinkError, the rest are not guarded. All eight ship in the package
for arm64-v8a and no other ABI. Eighteen constants naming nine plugins296
archives on fpse.net and fpsece.net survive in the class and nothing reads
them, and the two archive extractors keep a branch counting eight .so members
that no caller reaches. What getfile.php still answers, once per versionCode
and keyed by ABI as type p64, is a blob handed to setnfspos and summed into a
preference, not a library anything writes to disk. An OpenGL plugin picked by
hand from the .so browser is copied over libopengl1.so under the root.
libGLESv2, libjnigraphics, liblog, libstdc++, libdl, libm and libc are the
Android runtime and are not files anyone supplies.
ref: Main.java:25134-25137, Main.java:27300-27312, Main.java:9985,
Main.java:1116-1133, Main.java:8496, Main.java:13854,
Main.java:23615-23621, libfpse.so readelf -d
Resources unpack through helpers that differ in one respect. The guarded one
writes only when the target is absent, so bios/kanji.rom, fpse.ini and the
whole skin set survive being replaced by hand, and the same rule puts
slot1.mcd and slot2.mcd under FPse64/memcards on shared storage. The
unguarded one truncates, so gamelist.ini is rewritten from the package at every
start and a copy put there does not last. The shipped shaders are copied out of
assets into FPse64/shaders once storage access is granted.
ref: Main.java:33974-33977, Main.java:34054-34057, Main.java:34750-34753,
Main.java:27334, Main.java:27346-27347, Main.java:27463,
Main.java:35829-35845
What the application fetches for itself comes from the developer's servers:
cheat files from fpse.net/c/, per title OpenGL option files packed as
fpse.net/o/ogl.zip, covers from fpse.net/i64/, titles from fpse.net/t/, game
notes from fpse.net/games64/, overlay pad skins from fpse.net/s/ as
padtemp.zip extracted into skin/, and vrback.zip extracted at the root of
shared storage. Files named after a game identifier and ending in .sbi are
downloaded into FPse64/sbi for the titles of one internal list; no library and
no java path reads them back, and the string ".sbi" appears in none of the
eight libraries.
ref: Main.java:10505-10507, Main.java:16605, Main.java:16644,
Main.java:11468, Main.java:11827, l0.java:82-89, Main.java:10846,
Main.java:11014, Main.java:12555-12585, Main.java:15415-15430,
Main.java:15489
files:
- name: scph1001.bin
path: bios/scph1001.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "com.emulator.fpse64.biospath"
size: 524288
validation: [size]
md5: 924e392ed05558ffdb115408c263dccf
sha1: 10155d8d6e6e832d6ea66db9bc098321fb5e8ebf
description: "SCPH-1001, DTL-H1201, DTL-H3001 (v2.2 12-04-95 A)"
note: "The only image the code identifies, and it identifies it by a checksum of its own rather than by a hash it spells out: the 524288 bytes summed as signed bytes, accepted at 85958. The md5 and sha1 here are the dump that reproduces that sum. Selecting a BIOS by hand takes any .bin of exactly 524288 bytes, so the other images of the group fill the slot without being recognised by name or by sum."
source_ref: "Main.java:24466-24487, Main.java:9945-9952, Main.java:30177-30192, Main.java:5392-5396, libfpse.so 0x70e20-0x70ed0"
- name: kanji.rom
path: bios/kanji.rom
required: false
bundled: true
unsourceable: "ships inside the paid application package"
size: 238586
md5: 040d9dcbad83388c14d2628ac69ce88b
sha1: 915880f8bb04de39fd5132b92dfb99872f54fa47
description: "FONTX2 font the core draws Japanese text with"
note: "Header FONTX2X11. Unpacked into bios/ at first start and left alone afterwards, so a replacement stays. The core appends the name to the root and its bios/ component, opens the result read only and carries on when the file is absent."
source_ref: "Main.java:27334, Main.java:33974-33977, libfpse.so 0x71074-0x710b4, libfpse.so 0x95ce0-0x95ce8"
- name: libsoft1.so
required: true
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "software renderer plugin"
note: "Named by System.loadLibrary(\"soft1\") outside any catch and listed in DT_NEEDED by the core. Also holds the VR background loader."
source_ref: "Main.java:27302, libfpse.so readelf -d"
- name: libspuplugin.so
required: true
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "sound plugin"
note: "Named by System.loadLibrary(\"spuplugin\") outside any catch and listed in DT_NEEDED."
source_ref: "Main.java:27301, libfpse.so readelf -d"
- name: libopengl.so
required: true
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
aliases: ["libopengl1.so"]
description: "OpenGL renderer plugin"
note: "Named by System.loadLibrary(\"opengl\") outside any catch and listed in DT_NEEDED. A plugin chosen from the .so browser is copied over libopengl1.so under the root."
source_ref: "Main.java:27304, Main.java:9985, libfpse.so readelf -d"
- name: libnfsplugin.so
required: true
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "NFS client plugin, for discs read from a network share"
note: "Named by System.loadLibrary(\"nfsplugin\") outside any catch and listed in DT_NEEDED. Backs the isnfsbios and copyfromnfs entry points."
source_ref: "Main.java:27303, Main.java:25670, libfpse.so readelf -d"
- name: libsdl.so
required: true
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "SDL audio backend"
note: "Named by System.loadLibrary(\"sdl\") from a static block that catches UnsatisfiedLinkError, and listed in DT_NEEDED, so the core will not link without it."
source_ref: "Main.java:25134, libfpse.so readelf -d"
- name: libneon.so
required: true
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "NEON colour conversion routines"
note: "Named by System.loadLibrary(\"neon\") from the same static block and listed in DT_NEEDED."
source_ref: "Main.java:25135, libfpse.so readelf -d"
- name: libuncompress.so
required: true
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "archive extractor for .zip, .rar, .7z, .ape and .ecm images"
note: "Named by System.loadLibrary(\"uncompress\") outside any catch, and the only one of the plugins the core does not list in DT_NEEDED."
source_ref: "Main.java:27300, Main.java:25408, libfpse.so readelf -d"
- name: "<shader>.vsh"
path: "FPse64/shaders/<shader>.vsh"
required: false
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "vertex shader read whole and handed to the OpenGL renderer"
note: "The Shaders setting walks the directory and reads the selected pair, passing the bytes to setVSH. The packaged set is copied out of assets once storage access is granted, and a pair dropped in by hand joins the list."
source_ref: "Main.java:25962-25975, Main.java:35655-35669, Main.java:35829-35845"
- name: "<shader>.fsh"
path: "FPse64/shaders/<shader>.fsh"
required: false
bundled: true
unsourceable: "ships inside the paid application package"
category: game_data
description: "fragment shader read whole and handed to the OpenGL renderer"
note: "Read from the same directory as the vertex shader of the same name and passed to setFSH."
source_ref: "Main.java:25983-25996, Main.java:35677-35691, Main.java:35829-35845"
- name: vrback.raw
path: "vrback.raw"
required: false
category: game_data
description: "background image the software renderer draws behind the VR view"
note: "Opened read only at the root of shared storage and read as 640 by 512 sixteen bit pixels. Not carried by the package: the application downloads fpse.net/vrback.zip, extracts it at that root and deletes the archive. The distributed file is 655364 bytes."
source_ref: "libsoft1.so 0x5fda8-0x5fdb8, libsoft1.so 0x5fa3c-0x5fa50, Main.java:12555-12585"
- name: "<game>.txt"
path: "FPse64/cheats/<game>.txt"
required: false
category: game_data
unsourceable: "cheat codes fetched per title from the developer site or written by the user"
description: "cheat codes for one title"
note: "The path is pushed into the core as string slots 140, 141 and 143, keyed by the licence string of the running disc. A file chosen through a browser listing .txt is copied there, and the cheat search writes its results to the same name."
source_ref: "Main.java:21973-21975, Main.java:10319-10357, Main.java:26918, Main.java:28219-28226"
- name: "<game>.txt"
path: "FPse64/ogl/<game>.txt"
required: false
category: game_data
unsourceable: "per title OpenGL option value distributed by the developer"
description: "OpenGL option mask for one title"
note: "Read as a single integer and applied through setOptionGL, keyed by the licence string. Distributed as fpse.net/o/ogl.zip, which the application extracts into that directory, and rewritten there when the options are changed by hand."
source_ref: "Main.java:29309-29322, Main.java:18286-18294, Main.java:16605-16644"
- name: "<skin>.ini"
path: "skin/<skin>.ini"
required: false
category: game_data
unsourceable: "overlay pad artwork published by other users"
description: "external overlay pad skin"
note: "Selected through a browser listing .ini files. The default set unpacks from the package as skin/pad.ini with its button and stick artwork, and a pack downloaded from the developer arrives as padtemp.zip and is extracted into the same directory."
source_ref: "Main.java:21943-21947, Main.java:27355, Main.java:11014"
- name: LibPS.exe
system: sony-playstation
required: false
description: "PlayStation library executable loaded after the BIOS resources"
note: "Loaded by bare name during \"Loading files...\" when the matching option bit is set, reporting \"LibPS.exe found and loaded.\" on success and continuing untouched when the loader returns -1. Not carried by the package, and the core never chdirs, so it resolves against the working directory of the process."
source_ref: "libfpse.so 0x95de8-0x95e1c, libfpse.so .rodata 0x1ba534"
exclusion_note: >
Left out are the files FPseNG writes and reads back itself, which are emulator
state rather than files a user has to obtain: fpse.ini and the per-title
configurations under cfg, the memory cards slot1.mcd and slot2.mcd under
FPse64/memcards, the savestates and snapshots under FPse64/sstates, the game
list cache FPse64/filelist.txt, the recorded clips under FPse64/videos, and
the fpselog.txt, cpulog.txt and gpulog.txt traces. gamelist.ini is left out
with them for a different reason: it is rewritten from the package at every
start, so a copy placed there never survives. Left out too are the covers,
titles and game notes the application downloads into FPse64/icons,
FPse64/titles and fpse64/infos, which are interface metadata keyed by game
identifier, and the shipped overlay pad artwork, skin/pad.ini with its button
and stick images, which unpacks from the package. The .sbi files downloaded
into FPse64/sbi are left out on the ground that nothing loads them: neither
the java nor any of the eight libraries reads that directory back, and the
string ".sbi" appears nowhere in the native code. The disc images and their
.cue sidecars are not emulator files. The HLE BIOS is not a file either: it is
code, and the identification strings it answers with sit in .rodata beside the
rest of the core messages, with no 512 KB image anywhere in the library.
ref: res/raw fpse.ini MemCard1, Main.java:27463, Main.java:34054-34057,
Main.java:15415-15430, libfpse.so .rodata 0x1b8d81-0x1b8dfb
+223
View File
@@ -0,0 +1,223 @@
emulator: FPse
type: standalone
core_classification: other
source: "https://play.google.com/store/apps/details?id=com.emulator.fpse"
upstream: closed-source
author: "Schtruck & LDchen (EMUSOFT)"
profiled_date: "2026-08-11"
core_version: "12.1"
display_name: "Sony - PlayStation (FPse)"
cores:
- fpse
systems:
- sony-playstation
mode: standalone
bios_directory: "bios/"
bios_size: 524288
notes: |
PlayStation emulator for Android, closed source, sold on Google Play as package
com.emulator.fpse. Two builds are read here and both carry the same signing
certificate, CN=FPse Team issued 2011, sha256
9af45a593faf3b522c5120fc976a03b7d82a88a9e5008162b9d6822ade7c981a: 12.1
versionCode 940, apk md5 09160e917333d546296d4fcdae7b35f9, armeabi-v7a, and
0.11.190 versionCode 720, apk md5 818ee3fe71370ac983283926234e920e, armeabi
plus armeabi-v7a plus x86, taken from the OUYA store archive. The archive.org
item labelled FPse 1.7.8 is package com.emulator.fpse64, signed with the Android
test key and carrying an assets/hook.apk payload, and is not read here. The
emulator descends from LDchen's PC FPSE and keeps its console messages, its
fpse.ini keys and its bios, plugin, cfg and snaps directory names.
ref: com.emulator.fpse META-INF/BNDLTOOL.RSA, META-INF/CERT.RSA,
res/raw/fpse.ini
One root holds everything and it is the private files directory of the package,
not shared storage. Main sets it from getFilesDir and creates bios, plugin, cfg
and skin under it right after the native libraries load, then unpacks its own
resources into them. Paths below are relative to that root. The plugins have no
stable path of their own: 12.1 loads them from the native library directory of
the package and 0.11.190 loaded them from this root, so they are recorded by
name alone.
ref: Main.java:32088, Main.java:29716-29719
Exactly one BIOS image is ever loaded and its full path is a setting rather than
a name the code looks for. The Load Bios browser lists .bin files only, the
chosen path is written to the preference com.emulator.fpse.biospath and pushed
into the emulator core as string slot 6, and leaving the browser without a
choice writes an empty string, which is the documented way to switch to HLE.
The stored path is re-checked at every start: a file that no longer exists or is
not exactly 524288 bytes clears the preference and the session runs on HLE. On
the core side a path that will not open reports
"Can't load biosfile '%s', switching to HLE" and emulation continues, so no
image is needed on its own. fpse.ini ships with EnableHLE=on and BiosName set to
the placeholder scph1001.bin_is_recommended, and the core resolves BiosName
under bios/ when the setting is left alone.
ref: Main.java:5917-5919, Main.java:1173, Main.java:1965-1971,
Main.java:25213-25222, res/raw/fpse.ini BiosName,
FPse 0.11.190 libfpse.so x86 0x5c2c8-0x5c395
Automatic detection recognises one dump and does it on content. Scanning
storage, FPse keeps files whose lowercased name ends in .bin and whose length is
exactly 524288, reads all 524288 bytes, sums them as signed bytes and accepts
the file when the total is 85958, writing the path to the preference and turning
the BIOS on. The same constant answers over NFS through isnfsbios. Reimplemented
over the collection, that sum resolves to a single image, the v2.2 12/04/95 A
dump listed below, and to no other. The HLE path impersonates the same revision:
its identification strings sit in .rodata as ordinary C strings next to
"HLE enabled.", and the library carries no 512 KB image of its own.
ref: Main.java:4155-4175, Main.java:4185, Main.java:21188,
FPse 0.11.190 libfpse.so armeabi-v7a .rodata 0x245828-0x2458cc
Emulation itself lives in plugins that Main names one by one before the core:
uncompress, spuplugin, soft1, nfsplugin and opengl, then fpse. libfpse.so lists
all of them except uncompress in DT_NEEDED, so the core will not link without
them. They are distributed both ways. 0.11.190 shipped none of them, tested for
each file in the private directory, stopped on an error dialog before loading
the core when one was absent, and fetched plugins267.zip and its per GPU and per
ABI variants from fpse.net; 12.1 carries them in the package and keeps an
updater that asks getfile.php for the list matching its own versionCode and ABI,
alongside plugins605 constants nothing reads. Both generations of the pack still
answer: plugins605v7.zip is 1359776 bytes and holds the armeabi-v7a build of
libsoft1.so, libspuplugin.so, libopengl.so, libnfsplugin.so and
libuncompress.so at the same lengths as the copies inside 12.1 but not the same
bytes, plus the libopenglex.so, libspuplugin1.so and libspupluginex.so variants
the package does not carry, and twenty shader pairs. An OpenGL plugin picked by
hand from the .so browser is copied over libopengl1.so and used in place of the
packaged one. libGLESv2, libjnigraphics, liblog, libstdc++, libdl, libm and libc
are the Android runtime and are not files anyone supplies.
ref: Main.java:29686-29698, Main.java:20405-20406, Main.java:11010,
Main.java:3417-3423, Main.java:1120-1137,
FPse 0.11.190 Main.java:24126-24207, FPse 0.11.190 Main.java:860-871,
FPse 12.1 libfpse.so readelf -d,
fpse.net/plugins605v7.zip md5 ae5dbdc27452092af3e712448f427fd3
Resources unpack through two helpers that differ in one respect. b2 writes only
when the target is absent, so bios/kanji.rom, fpse.ini and the whole skin set
survive being replaced by hand. c2 truncates, so gamelist.ini is rewritten from
the package at every start and a copy put there does not last.
ref: Main.java:26892-26895, Main.java:26956-26957, Main.java:29721,
Main.java:29755-29758, Main.java:30046
files:
- name: scph1001.bin
path: bios/scph1001.bin
system: sony-playstation
required: false
hle_fallback: true
variant_group: "psx-bios"
config_key: "BiosName"
size: 524288
validation: [size]
md5: 924e392ed05558ffdb115408c263dccf
sha1: 10155d8d6e6e832d6ea66db9bc098321fb5e8ebf
description: "SCPH-1001, DTL-H1201, DTL-H3001 (v2.2 12-04-95 A)"
note: "The only image the code identifies, and it identifies it by a checksum of its own rather than by a hash it spells out: the 524288 bytes summed as signed bytes, accepted at 85958. The md5 and sha1 here are the dump that reproduces that sum. Selecting a BIOS by hand takes any file ending in .bin that is exactly 524288 bytes, so the other images of the group fill the slot without being recognised by name or by sum."
source_ref: "Main.java:4159-4175, Main.java:5919, Main.java:25217, res/raw/fpse.ini BiosName"
- name: LibPS.exe
system: sony-playstation
required: false
description: "PlayStation library executable loaded at startup when present"
note: "Loaded by bare name through the same loader as any PS-X EXE, reporting \"LibPS.exe found and loaded.\" on success and continuing untouched when the loader returns -1. Not carried by the package, and the core never chdirs, so it resolves against the working directory of the process."
source_ref: "FPse 0.11.190 libfpse.so x86 0x95545-0x9558a, FPse 12.1 libfpse.so .rodata 0x344634"
- name: libsoft1.so
required: true
bundled: true
category: game_data
description: "software renderer plugin"
note: "Named by System.loadLibrary(\"soft1\") and listed in DT_NEEDED by the core. 0.11.190 listed it the same way without shipping it, tested for the file in the private directory and stopped on an error dialog before the core when it was absent, the file coming from plugins267.zip."
source_ref: "Main.java:29688, FPse 0.11.190 Main.java:24148-24162"
- name: libspuplugin.so
required: true
bundled: true
category: game_data
description: "sound plugin"
note: "Named by System.loadLibrary(\"spuplugin\") and listed in DT_NEEDED. 0.11.190 picked libspupluginex.so, libspuplugin2.so or libspuplugin1.so by device and API level and copied the winner over this name."
source_ref: "Main.java:29687, FPse 0.11.190 Main.java:24126-24132"
- name: libopengl.so
required: true
bundled: true
category: game_data
aliases: ["libopengl1.so", "libopenglex.so"]
description: "OpenGL renderer plugin"
note: "Named by System.loadLibrary(\"opengl\") and listed in DT_NEEDED. A plugin chosen from the .so browser is copied over libopengl1.so, which 0.11.190 in turn copied over this name, the ex variant standing in for it on the devices that ask for it."
source_ref: "Main.java:29690, Main.java:11010, FPse 0.11.190 Main.java:24178-24199"
- name: libnfsplugin.so
required: true
bundled: true
category: game_data
aliases: ["libnfs.so"]
description: "NFS client plugin, for discs read from a network share"
note: "Named by System.loadLibrary(\"nfsplugin\") and listed in DT_NEEDED. Called libnfs.so through the 0.11.x line."
source_ref: "Main.java:29689, FPse 0.11.190 Main.java:24163-24177"
- name: libsdl.so
required: true
bundled: true
category: game_data
description: "SDL 1.2 audio backend"
note: "Named by System.loadLibrary(\"sdl\") and listed in DT_NEEDED."
source_ref: "Main.java:20405, FPse 12.1 libfpse.so readelf -d"
- name: libneon.so
required: true
bundled: true
category: game_data
description: "NEON colour conversion routines"
note: "Named by System.loadLibrary(\"neon\") and listed in DT_NEEDED, which resolves bgr555rgb565neon for the core."
source_ref: "Main.java:20406, FPse 12.1 libfpse.so readelf -d"
- name: libuncompress.so
required: false
bundled: true
category: game_data
description: "archive extractor for .zip, .rar, .7z, .ape and .ecm images"
note: "Named by System.loadLibrary(\"uncompress\") and the only one of the plugins the core does not list in DT_NEEDED. 0.11.190 loaded it on demand from the private directory."
source_ref: "Main.java:29686, FPse 0.11.190 Main.java:6244-6249"
- name: "<skin>.ini"
path: "skin/<skin>.ini"
required: false
category: game_data
unsourceable: "overlay pad artwork published by other users"
description: "external overlay pad skin"
note: "Selected through a browser listing .ini files, which is what the External entry of the gamepad skin setting opens. The default set unpacks from the package as skin/pad.ini with its button and stick artwork."
source_ref: "Main.java:5936-5938, Main.java:29758"
- name: "<game>.txt"
required: false
category: game_data
unsourceable: "cheat codes the user writes or collects per title"
description: "cheat codes for one title"
note: "Selected through a browser listing .txt files and parsed as titles between hashes followed by address and value pairs. Cheats apply only when a BIOS image is loaded."
source_ref: "Main.java:5965-5967, Main.java:30552"
exclusion_note: >
Left out are the files FPse writes and reads back itself, which are emulator
state rather than files a user has to obtain: fpse.ini and the per-title
configurations under cfg, the memory cards slot1.mcd and slot2.mcd, savestates
and the snapshots under snaps, fpselog.txt and the cpulog.txt and gpulog.txt
traces. gamelist.ini is left out with them for a different reason: it is
rewritten from the package at every start, so a copy placed there never
survives. Left out too are the shipped overlay pad artwork, skin/pad.ini with
its button and stick images, which unpack from the package, and the shader
pairs, which the package carries in assets while the Shaders setting selects a
directory rather than a file. bios/kanji.rom is left out on the same ground: it
is a FONTX2 font the core draws Japanese text with, header FONTX2X11, 238586
bytes, md5 040d9dcbad83388c14d2628ac69ce88b, sha1
915880f8bb04de39fd5132b92dfb99872f54fa47 in 12.1, and it has only ever existed
inside the package, unpacked into bios at first start and left alone afterwards
so a replacement stays. It is not a dump of the font ROM inside the Japanese
BIOS, and it shares its generic name with the unrelated kanji ROMs of the MSX
and the PC-88. Only
the ARM builds name it; the x86 build of 0.11.190 carries neither it nor the
v2.2 identification strings. The disc images and their .cue sidecars are not
emulator files. The HLE BIOS is not a file either: it is code, and the strings
it answers a BIOS identification with sit in .rodata beside the rest of the core
messages, with no 512 KB image anywhere in the library.
ref: res/raw/fpse.ini MemCard1, Main.java:30046, Main.java:29721,
Main.java:29758-29859, res/raw/kanji.rom,
FPse 0.11.190 libfpse.so armeabi-v7a .rodata 0x245818-0x2458cc
+887
View File
@@ -0,0 +1,887 @@
emulator: future-pinball-fploader
type: standalone
core_classification: enhanced_fork
source: "https://github.com/ravarcade/BAM_FPloader"
upstream: "https://www.ravarcade.pl/"
profiled_date: "2026-08-11"
source_commit: "e13007994011ae57dd9d9f48674c1f774183914b"
core_version: "1.5-408"
display_name: "Future Pinball (BAM)"
cores:
- future-pinball-fploader
- bam
systems:
- fpinball
mode: standalone
notes: |
BAM, Better Arcade Mode, by Rafal Janicki. FPLoader.exe starts
Future Pinball.exe suspended, writes the BAM.dll path into the new process
with VirtualAllocEx and WriteProcessMemory, runs LoadLibraryA on it through
CreateRemoteThread, waits for that thread and resumes the main one. Everything
else lives in BAM.dll, which detours the running program. The loader is
published as source; the shipped FPLoader.exe carries the same .text and
.rdata as the build committed to that repository and differs only by an
Authenticode blob, 9472 bytes against 5384.
ref: BAM_FPloader FPLoader.cpp:259-305, FPLoader.exe .text sha1
d5ca74154fe97002, PE timestamp 2016-04-25 19:17:12
BAM.dll is searched in the loader's own directory first, then in
C:\Games\Future Pinball\BAM\. Both missing puts up "Couldn't locate BAM.dll."
and returns -1. Future Pinball.exe comes from /FPEXE if that switch names an
existing file, otherwise from one level above the loader, then from the
loader's directory, then from C:\Games\Future Pinball\; the same failure path
reports "Couldn't locate Future Pinball.exe.". Before the process is created
the loader prepends its own directory to %PATH% so the system resolves
renderingengine.dll from there while the working directory is the game
directory. /STAYINRAM keeps the loader alive until the game thread ends; the
rest of the command line is handed to Future Pinball untouched, which is how
/Open, /Play, /Exit and /ArcadeRender reach it.
ref: BAM_FPloader FPLoader.cpp:40-48, 87-111, 166-240, 249-257
BAM.dll is closed source. Its version resource reads 1.5.408 and its debug
tags name BAM.cpp, dllmain.cpp, BallManager.cpp, RenderEngine.cpp,
plugin.cpp, pbo.cpp, stereo3d.cpp and debug.cpp. Twenty five entry points are
detoured in one pass: CreateFileA, CreateFileW, ReadFile, WriteFile,
CloseHandle, GetFileSize, DeleteFileA, FindResourceA, LoadResource,
LockResource, SizeofResource, CoCreateInstance, StgOpenStorage,
GetOpenFileNameA, ChooseColorA, GetDlgItem, SendMessageA, ShowWindow,
SwapBuffers, ChoosePixelFormat, SetPixelFormat, wglCreateContext,
wglDeleteContext, wglMakeCurrent and wglGetProcAddress, with glFrustum,
glTexImage2D and wglChoosePixelFormatARB taken separately. That is how BAM
sees the program's own resource and file traffic and can answer it. Newton is
reached through GetModuleHandleA on the copy Future Pinball already imported
followed by GetProcAddress on 83 entry points; no second copy is loaded.
ref: BAM.dll 1.5-408 .text:0x10082a75-0x10082f3d, 0x100831b3-0x100831d9,
0x1002ab92-0x1002abeb, .rsrc version, debug tags Routed_glTexImage2D and
Routed_wglChoosePixelFormatARB
Every path BAM builds hangs off the directory holding BAM.dll. The module
handle saved at load time goes through GetModuleFileNameA, the result is cut
at the last separator, and one of two format strings finishes the job:
"%s\%s.%s" for a name and an extension, "%s\%s" for the cfg subdirectory.
Settings for a table are cfg\<table>.cfg and cfg\<table>.seq, with default.cfg
and default.seq as the fallbacks.
ref: BAM.dll 1.5-408 .text:0x10025e40-0x1002605a, 0x100319a0-0x10031d48,
0x10032bdb-0x10032f23
Keys are the one text file. bam.cfg is read with fopen_s and parsed as
"%s = %s" lines over the names Menu, Menu2, Left, Right, Up, Down, Enter,
Snapshot, 3DSwitch, SaveXML, SnapShotPath, SnapShotBackboxPath, HeadTracking,
ForceArcadeMode, SwitchToNextBall, SwitchToPrevBall, RoomOnOff, Cam, Overlay,
BallShadows and OverlayAspectFix. A Keyboard.cfg found beside it is renamed to
bam.cfg first. RetroBat rewrites the two SnapShotPath lines before launching.
ref: BAM.dll 1.5-408 .text:0x100c3960-0x100c3a97, .rdata:0x10654208-0x10654324,
retrobat emulatorLauncher/Generators/Fpinball.Generator.cs:183-209
A ball or a room is a zip of BMP/<id>.bmp entries named for the resource ids
Future Pinball itself uses: the program carries 29 resources of type BMP and
every id the shipped packs contain is one of them, 452 being the ball.
balls\*.zip is walked with FindFirstFileA and each hit becomes a choice in the
menu; default.zip in the BAM directory is applied without being chosen. The
routed FindResourceA answers the nine SHADERS resources the same way, while
the single XML resource, id 464, is read straight from the program by the save
path and is what the presets under XML\ are edited copies of. The 83 GLSL
programs BAM renders with are
resources of type TEXT inside BAM.dll, so no shader file is read from disk.
ref: BAM.dll 1.5-408 .text:0x1002d4f3-0x1002d52d, 0x100ae8ec-0x100ae990,
0x10037130-0x100371de, 0x1007e83b-0x1007e896, .rsrc TEXT,
Future Pinball.exe 1.9.1.20101231 .rsrc BMP, SHADERS, XML
Plugins are loaded by changing the working directory to plugins\, walking
*.dll with FindFirstFileA, calling LoadLibraryA on each and binding
BAM_PluginStart and BAM_PluginStop. A plugin keeps its settings by writing a
raw structure to <its own name>.cfg in that working directory, which is why
the cfg files beside the plugins carry no text.
ref: BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c,
BAM_Plugins Common/BAM.h:116-157
renderingengine.dll is bound in BAM.dll's import directory through
FindProgram, SetModuleWithResources, LoadFileToMemory and SaveFileFromMemory,
so the loader resolves it before any BAM code runs. It carries Assimp, zlib,
libpng and libjpeg, reads the zip packs and writes the per table shadow cache
under Cache\.
ref: BAM.dll 1.5-408 import directory, .text:0x10105c18-0x1010697f
ES-DE declares the emulator as FUTURE-PINBALL-FPLOADER for Windows only,
finding FPLoader.exe under BAM\, BAM-OpenVR\ or BAM-OpenVR-OC\, and invokes it
with /Exit /Play /Open in the background. RetroBat reaches the same binary
under the emulator or core key bam, through the generator it shares with
Future Pinball. Two distributions are served: bam-setup.exe carries the
loader, the mod, the renderer, the tools, the plugins, the ball packs and the
physics presets, while BAM-OpenVR.zip carries the OpenVR plugin and the
settings files the other package leaves for the first save to create.
ref: es-de resources/systems/windows/es_find_rules.xml:448-461,
es-de resources/systems/windows/es_systems.xml:764,
retrobat emulatorLauncher/Generators/Fpinball.Generator.cs:131-135
files:
# -- The chain FPLoader needs before it can inject anything --
- name: BAM.dll
system: fpinball
required: true
bundled: true
size: 8266240
description: "The mod, injected into Future Pinball and holding every feature"
source_ref: "BAM_FPloader FPLoader.cpp:45, 166-182"
note: >-
Taken from the loader's directory, else from C:\Games\Future Pinball\BAM\.
Neither present ends the loader with a message box.
- name: renderingengine.dll
system: fpinball
required: true
bundled: true
size: 8791552
description: "Rendering engine and asset loader behind BAM"
source_ref: "BAM.dll 1.5-408 import directory, BAM_FPloader FPLoader.cpp:249-257"
note: >-
Bound statically by BAM.dll, so the injected LoadLibraryA fails without
it. The loader adds its own directory to %PATH% for this file alone.
- name: Future Pinball.exe
system: fpinball
required: true
size: 28547584
description: "The program BAM starts and modifies"
source_ref: "BAM_FPloader FPLoader.cpp:41, 46, 184-240"
note: >-
Probed with GetFileAttributesA at four locations, /FPEXE first. Absent,
the loader stops before creating any process. The size is that of
release 1.9.1.20101231.
# -- Tools shipped beside the loader --
- name: BAM-Tracker.exe
system: fpinball
required: false
bundled: true
size: 207104
description: "Head tracking calibration host"
source_ref: "BAM-Tracker.exe import directory, BAM.dll 1.5-408 .text:0x1008320e"
note: >-
Imports BAM.dll and runs it outside the game. BAM.dll lowercases the host
command line and looks for this name to know it is hosted by the tracker
rather than by Future Pinball.
- name: ModelImporter.exe
system: fpinball
required: false
bundled: true
size: 4553472
description: "Converts models to the .fpm form tables import"
source_ref: "ModelImporter.exe import directory, .rdata dialog filter"
note: >-
Bound to renderingengine.dll for the Assimp side. Its open dialog accepts
.fpm, .obj, .ms3d, .md5mesh and .fbx.
# -- Settings read from the BAM directory. BAM writes each of them, so a fresh
# install has only default.seq and the first save creates the rest.
- name: bam.cfg
system: fpinball
aliases:
- Keyboard.cfg
required: false
size: 316
description: "Key bindings and screenshot paths, the one text config"
source_ref: "BAM.dll 1.5-408 .text:0x100c3960-0x100c3a97"
note: >-
Keyboard.cfg is the older name and is renamed on sight. 9999 in a key
slot leaves the function unbound.
- name: default.cfg
system: fpinball
required: false
size: 3072
description: "Global camera, lighting, physics and rendering settings"
source_ref: "BAM.dll 1.5-408 .text:0x100326ba-0x100371bc"
note: >-
A binary block of the same shape as a per table cfg. Saving it reports
"default.cfg saved".
- name: default.seq
system: fpinball
required: false
bundled: true
size: 1284
category: game_data
description: "Camera animation sequences used when a table brings none"
source_ref: "BAM.dll 1.5-408 .text:0x10025e40-0x1002608f"
note: >-
Read as text. Every line is a comment to Future Pinball's own parser and
carries a position, a scale, two angles and a duration.
- name: default.xml
system: fpinball
required: false
description: "Physics values applied when a table specifies none"
source_ref: "BAM.dll 1.5-408 .text:0x100ae843-0x100ae8a7, 0x10037130-0x100371de"
note: >-
Same document shape as the presets under XML\. The save path produces one
by extracting resource 464 of type XML from Future Pinball, 6264 bytes, so
no copy ships.
- name: default.zip
system: fpinball
required: false
category: game_data
description: "Texture pack applied to every table"
source_ref: "BAM.dll 1.5-408 .text:0x100ae8ec-0x100ae990"
note: >-
Holds BMP/<id>.bmp entries keyed by Future Pinball resource id, the form
the ball packs and the Zendonius packs use.
- name: XML_Presets.txt
system: fpinball
required: false
description: "List of physics documents offered in the presets menu"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbd8a"
note: >-
Read whole and split on "%d: %s" lines. The menu entry Add current XML
appends to it, which is how the files under XML\ become reachable.
- name: Reality.dat
system: fpinball
required: false
size: 920
description: "Physical measurements of the cabinet and the screen"
source_ref: "BAM.dll 1.5-408 .text:0x10031bbb, 0x10031ebe"
note: >-
Read at startup and rewritten from the Reality submenu. Head tracking and
stereo geometry are computed from it.
- name: WiiMoteCams.dat
system: fpinball
required: false
size: 16
description: "WiiMote identifiers kept for the WiiMote camera mode"
source_ref: "BAM.dll 1.5-408 .text:0x10031d22, 0x10032f9f"
- name: CalibrationBoardData.cfg
system: fpinball
required: false
size: 272
description: "Dimensions of the printed board used to calibrate cameras"
source_ref: "BAM.dll 1.5-408 .text:0x10031ad8, 0x10032d4b"
- name: stereoCalibrationData.cfg
system: fpinball
required: false
size: 1160
description: "Result of the two camera calibration pass"
source_ref: "BAM.dll 1.5-408 .text:0x10031c75, 0x10032de3"
# -- Ball and room packs, walked as balls\*.zip --
- name: axis.zip
system: fpinball
path: "Balls/axis.zip"
required: false
bundled: true
category: game_data
size: 480842
description: "Ball texture showing the rotation axes"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Baseball.zip
system: fpinball
path: "Balls/Baseball.zip"
required: false
bundled: true
category: game_data
size: 248548
description: "Baseball ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Basketball 1.zip
system: fpinball
path: "Balls/Basketball 1.zip"
required: false
bundled: true
category: game_data
size: 148883
description: "Basketball ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Basketball 2.zip
system: fpinball
path: "Balls/Basketball 2.zip"
required: false
bundled: true
category: game_data
size: 74296
description: "Second basketball ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Cue Black.zip
system: fpinball
path: "Balls/Cue Black.zip"
required: false
bundled: true
category: game_data
size: 548084
description: "Black cue ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Cue White.zip
system: fpinball
path: "Balls/Cue White.zip"
required: false
bundled: true
category: game_data
size: 554040
description: "White cue ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: earth.zip
system: fpinball
path: "Balls/earth.zip"
required: false
bundled: true
category: game_data
size: 728508
description: "Globe ball texture, three BMP resources"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: EYETOY.zip
system: fpinball
path: "Balls/EYETOY.zip"
required: false
bundled: true
category: game_data
size: 373860
description: "EyeToy ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Fireball.zip
system: fpinball
path: "Balls/Fireball.zip"
required: false
bundled: true
category: game_data
size: 240337
description: "Fireball ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Knight.zip
system: fpinball
path: "Balls/Knight.zip"
required: false
bundled: true
category: game_data
size: 421287
description: "Knight ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: latlong.zip
system: fpinball
path: "Balls/latlong.zip"
required: false
bundled: true
category: game_data
size: 1066167
description: "Latitude and longitude grid ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
- name: Soccer Ball 1.zip
system: fpinball
path: "Balls/Soccer Ball 1.zip"
required: false
bundled: true
category: game_data
size: 54397
description: "Soccer ball texture"
source_ref: "BAM.dll 1.5-408 .text:0x1002d513-0x1002d52d"
# -- Physics documents, reached through XML_Presets.txt --
- name: fp-p1.0.xml
system: fpinball
path: "XML/fp-p1.0.xml"
required: false
bundled: true
category: game_data
size: 6290
description: "Physics 1.0 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.0.xml
system: fpinball
path: "XML/fp-p2.0.xml"
required: false
bundled: true
category: game_data
size: 6267
description: "Physics 2.0 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.1.xml
system: fpinball
path: "XML/fp-p2.1.xml"
required: false
bundled: true
category: game_data
size: 6267
description: "Physics 2.1 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.2.xml
system: fpinball
path: "XML/fp-p2.2.xml"
required: false
bundled: true
category: game_data
size: 6267
description: "Physics 2.2 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.3 Version 1.xml
system: fpinball
path: "XML/fp-p2.3 Version 1.xml"
required: false
bundled: true
category: game_data
size: 6278
description: "Physics 2.3 preset, first variant"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.3 Version 2.xml
system: fpinball
path: "XML/fp-p2.3 Version 2.xml"
required: false
bundled: true
category: game_data
size: 6278
description: "Physics 2.3 preset, second variant"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.4.xml
system: fpinball
path: "XML/fp-p2.4.xml"
required: false
bundled: true
category: game_data
size: 6267
description: "Physics 2.4 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.5.xml
system: fpinball
path: "XML/fp-p2.5.xml"
required: false
bundled: true
category: game_data
size: 6315
description: "Physics 2.5 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.5 slamtilt rubbers.xml
system: fpinball
path: "XML/fp-p2.5 slamtilt rubbers.xml"
required: false
bundled: true
category: game_data
size: 6335
description: "Physics 2.5 preset with the slamtilt rubber values"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.6.xml
system: fpinball
path: "XML/fp-p2.6.xml"
required: false
bundled: true
category: game_data
size: 6315
description: "Physics 2.6 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: fp-p2.7.xml
system: fpinball
path: "XML/fp-p2.7.xml"
required: false
bundled: true
category: game_data
size: 6314
description: "Physics 2.7 preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: Zendonius_v1.0.xml
system: fpinball
path: "XML/Zendonius_v1.0.xml"
required: false
bundled: true
category: game_data
size: 6333
description: "Zendonius physics preset"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: Zendonius_v1.1.xml
system: fpinball
path: "XML/Zendonius_v1.1.xml"
required: false
bundled: true
category: game_data
size: 6333
description: "Zendonius physics preset, second revision"
source_ref: "BAM.dll 1.5-408 .text:0x100fba6a-0x100fbb73"
- name: zedonius_v1_0.zip
system: fpinball
path: "XML/zedonius_v1_0.zip"
required: false
bundled: true
category: game_data
size: 862294
description: "Texture pack for the Zendonius preset, resources 315 to 464"
source_ref: "BAM.dll 1.5-408 .text:0x100ae8ec-0x100ae990"
- name: zedonius_v1_1.zip
system: fpinball
path: "XML/zedonius_v1_1.zip"
required: false
bundled: true
category: game_data
size: 862287
description: "Texture pack for the second Zendonius revision"
source_ref: "BAM.dll 1.5-408 .text:0x100ae8ec-0x100ae990"
# -- plugins\*.dll, every one walked and loaded at startup --
- name: DesktopCam.dll
system: fpinball
path: "plugins/DesktopCam.dll"
required: false
bundled: true
size: 3388680
description: "Head tracking from any webcam, desktop geometry"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
note: "Bound to AVICAP32 and MSVFW32 and reads the cascade files below."
- name: Simple Cam.dll
system: fpinball
path: "plugins/Simple Cam.dll"
required: false
bundled: true
size: 3262728
description: "Head tracking from any webcam, cabinet geometry"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
- name: PS3Eye.dll
system: fpinball
path: "plugins/PS3Eye.dll"
required: false
bundled: true
size: 1699080
description: "Head tracking from a PlayStation Eye"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
note: "Bound to CLEyeMulticam.dll, which comes from the CL-Eye SDK."
- name: DesktopPS3Eye.dll
system: fpinball
path: "plugins/DesktopPS3Eye.dll"
required: false
bundled: true
size: 1813768
description: "PlayStation Eye tracking with desktop geometry"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
- name: HT-PS3Eyes.dll
system: fpinball
path: "plugins/HT-PS3Eyes.dll"
required: false
bundled: true
size: 1432272
description: "Two PlayStation Eye cameras tracking an infrared marker"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
note: >-
Keeps its calibration in HT-PS3Eyes.dat and HT-PS3Eyes-FixCamExport.dat
beside itself, both produced by the calibration pass.
- name: Kinect.dll
system: fpinball
path: "plugins/Kinect.dll"
required: false
bundled: true
size: 2792144
description: "Head tracking from a Kinect for Xbox 360"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
note: "Bound to Kinect10.dll and FaceTrackLib.dll."
- name: DesktopKinect.dll
system: fpinball
path: "plugins/DesktopKinect.dll"
required: false
bundled: true
size: 31952
description: "Kinect tracking with desktop geometry"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
- name: Kinect2.dll
system: fpinball
path: "plugins/Kinect2.dll"
required: false
bundled: true
size: 2791632
description: "Head tracking from a Kinect for Windows v2"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
note: "Bound to Kinect20.dll."
- name: FaceTrackLib.dll
system: fpinball
path: "plugins/FaceTrackLib.dll"
required: false
bundled: true
size: 920272
description: "Microsoft face tracking library used by the Kinect plugins"
source_ref: "DesktopKinect.dll, Kinect.dll import directories"
- name: FaceTrackData.dll
system: fpinball
path: "plugins/FaceTrackData.dll"
required: false
bundled: true
size: 10650832
description: "Model data for the face tracking library"
source_ref: "FaceTrackLib.dll .rdata, wide literal FaceTrackData.dll"
- name: FreeTrack.dll
system: fpinball
path: "plugins/FreeTrack.dll"
required: false
bundled: true
size: 95440
description: "Head tracking from a FreeTrack server"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
- name: TrackIR.dll
system: fpinball
path: "plugins/TrackIR.dll"
required: false
bundled: true
size: 20176
description: "Head tracking from a NaturalPoint TrackIR"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c, TrackIR.dll .text:0x100018c7"
note: >-
Matches the name NPClient with strstr and pairs LoadLibraryA with
GetProcAddress on it. The plugin imports no registry function, so the
client library is resolved as a plain module name.
- name: PostFX.dll
system: fpinball
path: "plugins/PostFX.dll"
required: false
bundled: true
size: 39632
description: "Bloom and the unfinished ambient occlusion pass"
source_ref: "BAM.dll 1.5-408 .text:0x100cf5ff, BAM_Plugins PostFX/PostFX.cpp:41-45"
note: >-
Named in BAM.dll and compared against the enumerated file names, so it is
the one plugin the mod knows by name. Its nine GLSL programs are TEXT
resources inside the plugin, read with FindResourceA. Two builds circulate
under this name, the 39632 bytes of bam-setup.exe and 191240 bytes in
BAM-OpenVR.zip.
- name: PinballHighScore.dll
system: fpinball
path: "plugins/PinballHighScore.dll"
required: false
bundled: true
size: 918224
description: "Records high scores across tables"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
- name: PinballHighScore.cfg
system: fpinball
path: "plugins/PinballHighScore.cfg"
required: false
bundled: true
size: 1016
description: "Settings block the high score plugin reads and writes"
source_ref: "BAM_Plugins Common/BAM.h:136-157"
- name: PinballHighScore.db
system: fpinball
path: "plugins/PinballHighScore.db"
required: false
size: 45056
description: "Score database the plugin opens by name"
source_ref: "PinballHighScore.dll .rdata"
note: "Only BAM-OpenVR.zip carries a copy; the plugin creates one otherwise."
- name: PuPPlugin.dll
system: fpinball
path: "plugins/PuPPlugin.dll"
required: false
bundled: true
size: 240216
description: "PuPCOM script object drawing PinUP Player video onto table textures"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c, PuPPlugin.dll .rdata IPuPCOM, PuPVideo"
note: "Takes BAM_GetTextureId and BAM_ReplaceTexture from the plugin API."
- name: icom.dll
system: fpinball
path: "plugins/icom.dll"
required: false
bundled: true
size: 67280
description: "Gives a table script the COM objects the cabinet stack exposes"
source_ref: "BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c, icom.dll .rdata ProgID pattern"
note: >-
Matches created objects against
PinUpPlayer, Vpinmame, B2S, PUPDMDControl, UltraDMD, PinSSF and
DirectOutput.
- name: OpenVR.dll
system: fpinball
path: "plugins/OpenVR.dll"
required: false
bundled: true
size: 419328
description: "Renders the table to an OpenVR headset"
source_ref: "BAM_Plugins OpenVR/main.cpp, BAM.dll 1.5-408 .text:0x100cf400-0x100cf75c"
note: "Ships only in BAM-OpenVR.zip, which ES-DE also looks for as BAM-OpenVR\\."
- name: openvr_api.dll
system: fpinball
path: "plugins/openvr_api.dll"
required: false
bundled: true
size: 620760
description: "Valve OpenVR runtime interface"
source_ref: "OpenVR.dll import directory"
- name: haarcascade_frontalface_alt.xml
system: fpinball
path: "plugins/haarcascades/haarcascade_frontalface_alt.xml"
required: false
bundled: true
category: game_data
size: 919871
description: "OpenCV Haar cascade for frontal faces"
source_ref: "DesktopCam.dll, PS3Eye.dll, Simple Cam.dll .rdata"
- name: haarcascade_frontalface_default.xml
system: fpinball
path: "plugins/haarcascades/haarcascade_frontalface_default.xml"
required: false
bundled: true
category: game_data
size: 1254733
description: "Second OpenCV Haar cascade for frontal faces"
source_ref: "DesktopCam.dll, PS3Eye.dll, Simple Cam.dll .rdata"
- name: lbpcascade_frontalface.xml
system: fpinball
path: "plugins/lbpcascades/lbpcascade_frontalface.xml"
required: false
bundled: true
category: game_data
size: 51856
description: "OpenCV local binary pattern cascade for frontal faces"
source_ref: "DesktopCam.dll, PS3Eye.dll, Simple Cam.dll .rdata"
# -- Named by the code, absent from both distributions --
- name: opencv_ffmpeg2410.dll
system: fpinball
required: false
description: "OpenCV 2.4.10 FFmpeg bridge, video files as a camera source"
source_ref: "BAM.dll 1.5-408 .text:0x102a6013-0x102a605b"
note: >-
LoadLibraryA followed by GetProcAddress on cvCreateFileCapture_FFMPEG,
cvGrabFrame_FFMPEG and the rest. A null handle leaves the entry points
unbound and only the file source is lost.
- name: CLEyeMulticam.dll
system: fpinball
required: false
description: "CL-Eye Platform SDK driver interface for the PlayStation Eye"
source_ref: "PS3Eye.dll, DesktopPS3Eye.dll, HT-PS3Eyes.dll import directories"
- name: Kinect10.dll
system: fpinball
required: false
description: "Kinect for Windows SDK 1.x runtime"
source_ref: "Kinect.dll, DesktopKinect.dll, FaceTrackLib.dll import directories"
- name: Kinect20.dll
system: fpinball
required: false
description: "Kinect for Windows SDK 2.0 runtime"
source_ref: "Kinect2.dll import directory"
- name: NPClient.dll
system: fpinball
required: false
description: "NaturalPoint TrackIR client library"
source_ref: "TrackIR.dll .rdata"
note: >-
Comes from a TrackIR install rather than from any BAM distribution, which
is why no path is given here.
analysis:
written_not_read:
note: >-
Opened only for writing, so they are output rather than something to
obtain. All of them sit in the BAM directory.
entries:
- what: "cfg\\<table>.cfg and cfg\\<table>.seq, per table settings and camera sequences"
source_ref: "BAM.dll 1.5-408 .text:0x10025e59, 0x100319b9, 0x10032bdb"
note: >-
Built as cfg\\<table> then finished with the extension. Saved from the
menu and read back on the next launch of the same table.
- what: "Cache\\<table>-shadows.zip, precomputed shadow maps"
source_ref: "BAM.dll 1.5-408 .text:0x10105c18-0x1010697f"
note: >-
Checked with GetFileAttributesA and rebuilt when absent. Holds
shadowmaps.txt and one <name>-shadows.tga per light, written through
the rendering engine.
- what: "set3points.dat, the three point calibration of the screen corners"
source_ref: "BAM.dll 1.5-408 .text:0x10077b80-0x10077bd7"
note: "fopen_s with wb, fwrite, fclose. No read site exists."
- what: "BAM_debug.log, BAM_CRASH.log and OpenGLdbg.log"
source_ref: "BAM.dll 1.5-408 .text:0x1007a45b, 0x1007ae0a, 0x100d4318-0x100d4391"
note: >-
The crash log is written from the fault handler installed at load
time; the other two only when the matching switch is on the command
line.
shipped_but_not_loaded:
note: "Present in a distribution with no code path that opens it"
entries:
- what: "zlib.dll in BAM-OpenVR.zip"
source_ref: "BAM.dll, renderingengine.dll and every plugin import directory"
note: >-
No shipped binary imports it and neither BAM.dll nor
renderingengine.dll names it in any string; both carry their own zlib.
- what: "License.txt, 3741 bytes"
source_ref: "bam-setup.exe payload"
note: "The zlib licence the loader source carries, copied into the install."
named_but_not_obtainable:
note: "A literal the code opens that no distribution can provide"
entries:
- what: "c:\\games\\ppmm.bin"
source_ref: "BAM.dll 1.5-408 .text:0x100cff69-0x100cffa5"
note: >-
fopen_s with rb then fread, guarded by two globals and reached only
after glGetFloatv has read the modelview and projection matrices. The
path is absolute and points at a directory no install creates.
platform_components:
note: >-
Named in import directories but supplied by Windows or by a Microsoft
redistributable, so they are prerequisites rather than payload.
entries:
- what: "MSVCP140.dll, VCRUNTIME140.dll, CONCRT140.dll and the api-ms-win-crt set"
source_ref: "BAM.dll, renderingengine.dll import directories"
note: "Visual C++ 2015 or later runtime. Neither distribution carries it."
- what: "MSVCR100.dll, MSVCR120.dll and MSVCP120.dll"
source_ref: "PostFX.dll, TrackIR.dll, DesktopKinect.dll, PinballHighScore.dll import directories"
note: "Visual C++ 2010 and 2013 runtimes, for the older plugins."
- what: "opengl32, glu32, dinput8, hid, avicap32, avifil32, msvfw32, d3d11, dxgi"
source_ref: "BAM.dll, renderingengine.dll, plugin import directories"
note: "Windows components."
+430
View File
@@ -0,0 +1,430 @@
emulator: future-pinball
type: standalone
core_classification: game_engine
source: "https://futurepinball.com/"
upstream: closed-source
profiled_date: "2026-08-11"
core_version: "1.9.1.20101231"
display_name: "Future Pinball"
cores:
- fpinball
- future-pinball
systems:
- fpinball
mode: standalone
notes: |
Closed-source Windows pinball simulator and table editor written by Chris
Leathley for BSP Software Design Solutions. Development stopped with
v1.9.1.20101231, still served from futurepinball.com. Rendering is OpenGL
(88 imports from opengl32 and 4 from glu32); ddraw is loaded by name only to
call DirectDrawCreateEx while enumerating display modes. Physics come from
Newton Game Dynamics, audio from FMOD 3, image decoding from DevIL and the
script editor from Scintilla. The binary registers its own type library at
startup through LoadTypeLib and RegisterTypeLib on its own path, which is the
registration RetroBat checks under TypeLib\{FB22A459-4AD0-4CB3-B959-15158F7139F5}
before deciding to relaunch elevated.
ref: Future Pinball.exe 1.9.1.20101231 import directory, .text:0x0042c7a2-0x0042c82e
The release is named 1.9.1.20101231 but the executable inside it carries
FileVersion 1.9.2008.1225 in its version resource and prints
"Version 1.9.1.20091231" in its own banner.
ref: Future Pinball.exe 1.9.1.20101231 .rsrc version, .text:0x0043d288-0x0043d298
Every relative path below hangs off one root. At startup GetModuleFileNameA
fills a buffer, the code scans back to the last backslash and terminates the
string just after it, and that install directory with its trailing separator
is kept for the life of the process.
ref: Future Pinball.exe 1.9.1.20101231 .text:0x00432af0-0x00432b49
A table is an OLE compound document with the .fpt extension and it carries
its own media. Every FMOD load passes FSOUND_LOADMEMORY (mode 0x8130 for
samples, 0x4000a130 for streams) and images go through ilLoadL, the memory
lump entry point, never ilLoadImage. So sounds, music and textures are read
out of the table file and no external media is opened while a table plays.
ref: Future Pinball.exe 1.9.1.20101231 .text:0x00457ede,0x00457f6f,0x00457fe6,0x0045805b,0x004417f6
What a table can pull from outside itself is a resource library. Libraries
are .fpl files, also OLE compound documents, holding models, textures, sounds,
DMD fonts and scripts under one storage per item. The Texture, Sound, Model
and DMD Font managers each offer Import, which copies the item into the table,
and Link, which records the library name and the item name instead; the manual
recommends always linking to the shipped model library. A linked library is
opened by StgOpenStorage on the name as written, which resolves against the
table's own folder, and on failure against the install directory plus
"Libraries\". Both failing raises "Unabled to Open Library - '<name>'" followed
by "There will be some functions missing from the game." as a warning box, and
the program carries on.
ref: Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf, .rsrc string 149-150,
Future Pinball Manual.chm LibraryResourceManager.html, ModelManager.html, TextureManager.html,
SoundManager.html, FontManager.html
A table script reaches outside itself through LoadExternalScript, whose result
is handed to VBScript's ExecuteGlobal. When the reference ends in .fpl the
script is pulled from that library, otherwise the name is tried as given
against the working directory, then under the install directory with the
"Scripts\" prefix, then with "Tables\", and a miss reports
"Unable to load external script". No Scripts directory ships, so what it holds
is whatever a given table asks for.
ref: Future Pinball.exe 1.9.1.20101231 .text:0x004797c0-0x00479905, 0x00478be0-0x00478c66,
0x00478d20, Future Pinball Manual.chm GlobalScript.html
Settings live in the registry under HKCU\Software\Future Pinball, split into
GamePlayer, GamePlayer\Joypads and Editor keys; there is no ini file.
RetroBat writes resolution, aspect ratio, camera, render preset and the whole
joypad map there before launching. Per table state is written to
fpRAM\<table>.fpRAM beside the program. Nothing in the program verifies a size
or a hash on any file it opens, so the figures recorded below are those of the
1.9.1.20101231 release and are informative.
ref: Future Pinball.exe 1.9.1.20101231 .text:0x0043aa80,0x00475602,0x00475892,
retrobat emulatorLauncher/Generators/Fpinball.Generator.cs:326-491
Front ends drive it with the documented switches /Open "<table>", /Play, /Exit
and /ArcadeRender. ES-DE declares it for Windows only, as FUTURE-PINBALL
finding "Future Pinball.exe" and as FUTURE-PINBALL-FPLOADER finding
"BAM\FPLoader.exe", both invoked with /Exit /Play /Open; the fpinball system
is a placeholder on its six other platforms. RetroBat maps the emulator keys
fpinball and bam to one generator, one install folder and the same
"Future Pinball.exe" presence check, swapping only the launched binary, and
optionally starts dmdext against DmdDevice.ini to mirror the DMD. Batocera ran
it in a wine bottle on x86_64 and dropped it for Visual Pinball. BAM is
ravarcade's loader: FPLoader.exe starts the same executable with BAM.dll
injected, and it names none of its own files from inside Future Pinball.
ref: es-de resources/systems/windows/es_find_rules.xml:438-461,
es-de resources/systems/windows/es_systems.xml, Future Pinball Manual.chm CommandLine.html,
retrobat emulatorLauncher/Generators/Fpinball.Generator.cs:109-181,
batocera-linux batocera-Changelog.md:214
files:
# -- Bound in the import directory, so the loader resolves them before any
# Future Pinball code runs. A cold start opens these six and SciLexer,
# nothing else, in the program directory.
- name: Newton.dll
system: fpinball
required: true
bundled: true
size: 446464
description: "Newton Game Dynamics, the rigid body solver under the ball physics"
source_ref: "Future Pinball.exe 1.9.1.20101231 import directory"
note: >-
83 functions are bound from it, the largest third party surface in the
binary. The process does not start without it.
- name: fmod.dll
system: fpinball
required: true
bundled: true
size: 162816
description: "FMOD 3 audio engine"
source_ref: "Future Pinball.exe 1.9.1.20101231 import directory"
note: >-
22 functions bound, FSOUND_Init through the sample and stream calls. Every
one of those calls passes FSOUND_LOADMEMORY, so it decodes the table's own
buffers rather than reading files.
- name: devil.dll
system: fpinball
aliases:
- DevIL.dll
required: true
bundled: true
size: 269312
description: "DevIL image decoder"
source_ref: "Future Pinball.exe 1.9.1.20101231 import directory"
note: >-
8 functions bound, ilInit through ilLoadL. Spelled DevIL.dll in the import
descriptors and shipped lowercase, which the case insensitive loader treats
as one name.
- name: ilu.dll
system: fpinball
aliases:
- ILU.dll
required: true
bundled: true
size: 27648
description: "DevIL image utility library, scaling and canvas resize"
source_ref: "Future Pinball.exe 1.9.1.20101231 import directory"
note: >-
4 functions bound: iluInit, iluScale, iluEnlargeCanvas and
iluImageParameter, used to fit imported artwork to texture dimensions.
- name: ilut.dll
system: fpinball
aliases:
- ILUT.dll
required: true
bundled: true
size: 16384
description: "DevIL toolkit layer, image to Windows bitmap conversion"
source_ref: "Future Pinball.exe 1.9.1.20101231 import directory"
note: >-
3 functions bound: ilutRenderer, ilutConvertToHBitmap and ilutGetBmpInfo,
which produce the preview bitmaps the editor's manager windows draw.
- name: libcurl.dll
system: fpinball
required: true
bundled: true
size: 626688
description: "HTTP client for the table feed"
source_ref: "Future Pinball.exe 1.9.1.20101231 import directory, .text:0x0043dc70"
note: >-
Only four functions are bound, curl_easy_init, setopt, perform and cleanup,
and the single use is fetching the table list from
http://www.pinsimdb.org/fpreleases/backend_xml.php under the user agent
FuturePinball-agent/1.0. The binding is static all the same, so the process
still refuses to start without the file.
- name: SciLexer.dll
system: fpinball
required: false
bundled: true
size: 407552
description: "Scintilla, the editing control behind the table script editor"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x0042c501-0x0042c528"
note: >-
The one library taken with LoadLibraryA rather than the import directory.
A null return puts up "The Scintilla DLL could not be loaded.", stores a
null handle and falls through to the rest of startup, so the program runs
and only the script editor is lost.
# -- Resource libraries, resolved against the table's folder then against
# <install>\Libraries. Shipped names all start with fp and the manual asks
# designers not to modify them, because a release replaces them.
- name: fpModels.fpl
system: fpinball
path: "Libraries/fpModels.fpl"
required: false
bundled: true
category: game_data
size: 5166080
description: "260 pinball part models, the library the manual tells tables to link"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf, Future Pinball Manual.chm ModelManager.html"
note: >-
Models cannot be authored outside the development team, so a table that
wants a bumper cap or a flipper bat either embeds a copy or links here, and
the Model Manager documents linking as the recommended choice. Absent, the
table still loads and every model it linked is missing.
- name: fpTextures.fpl
system: fpinball
path: "Libraries/fpTextures.fpl"
required: false
bundled: true
category: game_data
size: 3495424
description: "90 textures for the standard table objects"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf, Future Pinball Manual.chm TextureManager.html"
note: >-
Carries the surface art the built in parts expect, bulbs, triggers,
plungers and the rest. Resolved the same way as every other library.
- name: fpRamps.fpl
system: fpinball
path: "Libraries/fpRamps.fpl"
required: false
bundled: true
category: game_data
size: 2813440
description: "82 ramp models, keyed by profile, width and height"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf"
note: >-
Storage names encode the shape and the dimensions, ramp-pool-t1_w30_h20
and so on, with a left and a right variant of each.
- name: fpSounds.fpl
system: fpinball
path: "Libraries/fpSounds.fpl"
required: false
bundled: true
category: game_data
size: 170496
description: "20 machine sounds, ball release, bumpers, coin in and the rest"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf, Future Pinball Manual.chm SoundManager.html"
- name: fpSphereMaps.fpl
system: fpinball
path: "Libraries/fpSphereMaps.fpl"
required: false
bundled: true
category: game_data
size: 223744
description: "11 sphere maps giving metal and plastic parts their reflections"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf"
note: >-
Storage names are bracketed, [chrome-silver], [chrome-gold] and similar,
which is how a material references one.
- name: fpDmdFonts.fpl
system: fpinball
path: "Libraries/fpDmdFonts.fpl"
required: false
bundled: true
category: game_data
size: 58880
description: "6 dot matrix fonts, named for their cell size"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf, Future Pinball Manual.chm FontManager.html"
note: >-
dmd05x05p through dmd08x13p. A DMD display element with no font draws
nothing.
- name: fpPlayfields.fpl
system: fpinball
path: "Libraries/fpPlayfields.fpl"
required: false
bundled: true
category: game_data
size: 364032
description: "3 playfield images, including the plunger cutout template"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004e6cf0-0x004e6ebf"
- name: fpScripts.fpl
system: fpinball
path: "Libraries/fpScripts.fpl"
required: false
bundled: true
category: game_data
size: 4096
description: "Script library, holding the one sample script the manual quotes"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x00478d20, Future Pinball Manual.chm GlobalScript.html"
note: >-
The manual's worked example is
ExecuteGlobal LoadExternalScript("fpScripts.fpl\myscript"), which is the
branch taken when a reference carries the .fpl extension. What ships is a
single storage named testscript.
# -- Named individually elsewhere in the binary --
- name: NewTable.fpt
system: fpinball
required: false
bundled: true
category: game_data
size: 226816
description: "Template opened by File then New"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x00448ea9-0x00448edb"
note: >-
The install directory is copied into the default table path buffer and this
name appended, then the result goes through the ordinary table open. It is
a full table with a playfield and a plunger, not an empty document.
- name: Future Pinball Manual.chm
system: fpinball
path: "Help/Future Pinball Manual.chm"
required: false
bundled: true
size: 8992653
description: "Development guide, 79 topics"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x00478477-0x004784c4"
note: >-
Opened with ShellExecuteA on the install directory plus this path when the
help command carries id 0x8043. It is the only description of the library
link mechanism and of LoadExternalScript.
- name: Script56.chm
system: fpinball
path: "Help/Script56.chm"
required: false
description: "Microsoft Windows Script 5.6 documentation, the VBScript reference"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004784a3-0x004784c4"
note: >-
The script editor's help falls to this path for every command id other
than 0x8043, again through ShellExecuteA against the install directory. No
Future Pinball release ships it: table scripts are VBScript and this is
Microsoft's own reference for the language, expected to be dropped into
Help beside the manual.
- name: fpLatestTables.xml
system: fpinball
path: "Feeds/fpLatestTables.xml"
required: false
bundled: true
size: 752639
description: "Cached table list from pinsimdb.org"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x0043dc70-0x0043dc99, 0x0043e776-0x0043e79c"
note: >-
libcurl writes it, CreateFileA with OPEN_EXISTING reads it back and
DeleteFileA drops it when the panel refreshes. The code builds the path as
feeds\ against a directory the installer creates as Feeds. A snapshot ships
with the release, so the panel has something to show before any fetch.
# -- Outside the program directory --
- name: NPClient.dll
system: fpinball
required: false
description: "NaturalPoint TrackIR client library, head tracking"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x0045f1b8-0x0045f1f8"
note: >-
The directory is read from HKCU\Software\NaturalPoint\NATURALPOINT\NPClient
Location, this name appended and the result given to LoadLibraryA;
NP_GetSignature and the rest are then bound with GetProcAddress. A null
handle jumps past all tracking setup. It comes from a TrackIR install, not
from any Future Pinball distribution, which is why no path is given here.
analysis:
shipped_with_the_binary:
note: >-
Present in the release and read by the program, but named at runtime rather
than by a literal in the code, so there is no fixed filename to record.
entries:
- what: "Tables\\, four demonstration tables"
source_ref: "FuturePinballSetup_v1.9.1.20101231.exe app/Tables"
note: >-
DmdDisplayDemo.fpt, LightSequencerDemo.fpt, Ramp-VUK-Demo.fpt and
SegmentDisplayDemo.fpt. The directory itself is the default table path
and the last prefix the external script resolver tries.
- what: "Feeds\\, 385 table screenshots"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x0043d60f"
note: >-
Named st_<id>_<n>_<n>.jpg from the entries of fpLatestTables.xml and
fetched with the same libcurl path, so the set changes with the feed.
user_supplied_paths:
note: "Named by a table or written by the program, with no fixed filename"
entries:
- what: "external table scripts, tried bare then under Scripts\\ then Tables\\"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004797c0-0x00479905, 0x00478be0"
note: >-
LoadExternalScript takes whatever name the table's script passes. The
bare attempt resolves against the working directory, which is the
table's own folder. No Scripts directory ships.
- what: "fpRAM\\<table>.fpRAM, per table persistent state"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x0043aa80, 0x00475602, 0x00475892"
note: >-
Built as the prefix, the table name and the .fpRAM extension. Written
from play, so it is save data rather than something to obtain. The
installer creates the directory empty.
- what: "DmdFonts\\ and Models\\, editor working directories"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x00443595, 0x00443efc, 0x00516ba8, 0x00516d31, 0x00441fc8, 0x004429bb, 0x004317fa"
note: >-
Each site only fills the initial directory of a GetOpenFileName or
GetSaveFileName call in the DMD font and model import and export
dialogs, so nothing is read until the user picks a file. DmdFonts ships
empty and Models is not created at all. Fonts carry .dmdf and models
.fpm, both authored rather than distributed.
named_but_not_read:
note: "String literals that survive a path scan without ever reaching a file"
entries:
- what: "skin\\toolbar.bmp"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x00438ff5, 0x00448ba0, 0x00432240-0x00432290"
note: >-
Passed to the toolbar builder, which calls CreateToolbarEx with
hBMInst zero and a bitmap handle held in a global as wBMID. The module
has no resource under that name and neither syscall trace shows an open
for it, although both traces reach the main window.
- what: "tables\\ in lower case"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x00439e40-0x00439e79"
note: >-
Searched for inside a feed URL and skipped past to recover the table
name, with the literal opps as the fallback. Not a path being built.
- what: ".jlb"
source_ref: "Future Pinball.exe 1.9.1.20101231 .text:0x004414d0"
note: >-
A second extension accepted beside .fpl in the library dialogs. No file
with it ships and nothing opens one by name.
+108
View File
@@ -0,0 +1,108 @@
emulator: "GBA.emu"
type: standalone
core_classification: community_fork
source: "https://github.com/Rakashazi/emu-ex-plus-alpha"
upstream: "https://github.com/visualboyadvance-m/visualboyadvance-m"
profiled_date: "2026-08-11"
source_commit: "1c12fac5ce49badaadff2e2f210dcc30b89f4943"
upstream_commit: "fbd043dea0920a2356c44e1458a160455403c640"
core_version: "1.5.85"
display_name: "Nintendo - Game Boy Advance (GBA.emu)"
mode: standalone
cores:
- "gba-emu"
- "GBA.emu"
- "GBA-EMU"
systems:
- nintendo-gba
notes: |
Android and Linux member of the EX Emulator series by Robert Broglia,
published as com.explusalpha.GbaEmu (GBA.emu/metadata/conf.mk:2,6,7) and
reached by ES-DE through its GBA-EMU find rule. VBA-M components are vendored
under GBA.emu/src/core (GBA.emu/metadata/conf.mk:8,
GBA.emu/src/main/AppMeta.cc:26) and driven by the app's own GBASys, video,
sound and IO layers. The build defines C_CORE, FINAL_VERSION, NO_PNG, NO_LINK
and NO_DEBUGGER (GBA.emu/CMakeLists.txt:14). Content is read from .gba and .mb
files, a .mb name sending the image to work RAM instead of the ROM area
(GBA.emu/metadata/conf.mk:5, GBA.emu/src/main/AppMeta.cc:31,
GBA.emu/src/main/Main.cc:182-183, GBA.emu/src/main/VbamApi.cc:211-246).
The BIOS is the one file the user supplies and it carries no name of its own.
The picker takes any .bin or .rom and stores the chosen URI in biosPath
(GBA.emu/src/main/EmuMenuViews.cc:485-510, GBA.emu/src/main/system.ccm:88,
GBA.emu/src/main/options.cc:50,79). loadContent reads the file whole and
throws unless it is exactly 16384 bytes (GBA.emu/src/main/Main.cc:190-197),
the length CPUInit tests again before copying it and setting useBios
(GBA.emu/src/core/gba/gba.cpp:3758-3778). Nothing else about the file is
examined: CPUIsGBABios, the extension test upstream passes to utilLoad, has no
caller here (GBA.emu/src/core/gba/gba.cpp:1655-1675; upstream
src/core/gba/gba.cpp:4975-4986).
Without a file the app runs on the built-in myROM stub copied into the BIOS
area (GBA.emu/src/core/gba/gba.cpp:131-305,3776-3778) and on the service call
implementations of gbaBios.cpp; useBios decides only whether an SWI enters
BIOS code or the HLE routine, and which register reset a boot performs
(GBA.emu/src/core/gba/gba.cpp:2525-2545,4104-4112). Two settings gate the
read: the per-content Use BIOS tristate defaults to Auto, which follows the
global Default Use BIOS switch, itself off until the user turns it on
(GBA.emu/src/main/system.ccm:107-108,165-174,
GBA.emu/src/main/EmuMenuViews.cc:387-395).
The 473 entry override table is byte-identical to VBA-M's
src/libretro/gba-over.inc, and its bios column is dropped on arrival:
setGameSpecificSettings takes save type, save size, RTC and mirroring and
nothing more (GBA.emu/src/main/gba-over.inc:1,
GBA.emu/src/main/Main.cc:283-319), so BIOS use never follows from the game.
Per content the app writes and reads files named after the ROM: .sav backup
memory created full of 0xFF (GBA.emu/src/main/Main.cc:98-108), .gqs states
(GBA.emu/src/main/system.ccm:128), and a .clt cheat list it saves itself under
the cheats path (GBA.emu/src/main/Cheats.cc:210-235,
GBA.emu/src/core/gba/gbaCheats.cpp:2738,2755). Under the patches path it
applies the first of .ips, .ups or .ppf that opens
(GBA.emu/src/main/Main.cc:147-178). ui.png, gpOverlay.png and the shader
sources are drawn by the framework from the application bundle
(EmuFramework/include/emuframework/AssetManager.hh:61-66,
EmuFramework/src/AssetManager.cc:58-73,
EmuFramework/src/VideoImageEffect.cc:164-172).
VBA-M's own file entry points reach nothing in this build. CPULoadRom, the
battery, state, GSA snapshot and eeprom import functions and the EmulatedSystem
table sit inside #if 0 blocks (GBA.emu/src/core/gba/gba.cpp:1301-1614,
1885-2134,4803-4869); CPUExportEepromFile and cheatsImportGSACodeFile keep no
caller (GBA.emu/src/core/gba/gba.cpp:1276,
GBA.emu/src/core/gba/gbaCheats.cpp:2081); and utilOpenFile, the call all of
them open files with, is implemented by no source in the build
(GBA.emu/src/CMakeLists.txt:6-36, GBA.emu/src/main/VbamApi.cc:279-321). The
e-Reader reads no dotcode either, the tree carrying its header alone and the
three entry points being stubbed (GBA.emu/src/core/gba/internal/gbaEreader.h,
GBA.emu/src/main/VbamApi.cc:109-113).
files:
- name: gba_bios.bin
system: nintendo-gba
required: false
hle_fallback: true
has_builtin: true
agnostic: true
size: 16384
validation: [size]
description: "Game Boy Advance BIOS"
note: >-
Picked by the user from any path, under any name ending in .bin or .rom.
The only test is the length, and a file of another length aborts the load
rather than falling back.
source_ref: "GBA.emu/src/main/Main.cc:190-197 (read and size check), GBA.emu/src/core/gba/gba.cpp:3758-3778 (second check, copy, useBios), GBA.emu/src/main/EmuMenuViews.cc:485-510 (picker and extension filter)"
- name: "Motocross Challenge.7z"
aliases: ["MotocrossChallenge.7z"]
system: nintendo-gba
required: false
bundled: true
category: game_data
description: "Bundled homebrew game, listed under Bundled Content"
note: >-
Opened from the application bundle by the name the build gives it, the
Linux build dropping the space.
source_ref: "GBA.emu/src/main/AppMeta.cc:32-33 (names), EmuFramework/src/gui/BundledGamesView.cc:41,47 (open and load)"
+73
View File
@@ -0,0 +1,73 @@
emulator: "GBC.emu"
type: standalone
core_classification: community_fork
source: "https://github.com/Rakashazi/emu-ex-plus-alpha"
upstream: "https://github.com/sinamas/gambatte"
profiled_date: "2026-08-11"
source_commit: "1c12fac5ce49badaadff2e2f210dcc30b89f4943"
core_version: "1.5.85"
display_name: "Nintendo - Game Boy / Color (GBC.emu)"
mode: standalone
cores:
- "gbc-emu"
- "GBC.emu"
- "GBC-EMU"
systems:
- nintendo-gb
- nintendo-gbc
notes: |
Member of the EX Emulator series by Robert Broglia, which targets Android and
Linux (README.md:3-4,12-13) and keeps iOS and Pandora build shortcuts in the
tree (GBC.emu/ios.mk, GBC.emu/pandora.mk). Published as
com.explusalpha.GbcEmu (GBC.emu/metadata/conf.mk:2,4,6,7) and reached by
ES-DE through its GBC-EMU find rule. Gambatte components are
vendored under GBC.emu/src/libgambatte (GBC.emu/metadata/conf.mk:8,
GBC.emu/src/main/AppMeta.cc:26) and driven by the app's own video, audio,
input and save layers, with the OSD compiled out
(GBC.emu/CMakeLists.txt:14-19). Content is read from .gb, .gbc and .dmg files
(GBC.emu/metadata/conf.mk:5, GBC.emu/src/main/AppMeta.cc:30); an archive is
opened by the framework, which keeps the first entry passing that same filter
(EmuFramework/src/EmuSystem.cc:392-419).
The content image is the only one the app loads. GB::load hands the buffer to
Cartridge::loadROM and starts the machine from the register, memory and
palette values setInitState writes, the path a reset takes as well
(GBC.emu/src/libgambatte/src/gambatte.cpp:83-121,
GBC.emu/src/libgambatte/src/mem/cartridge.cpp:557-669,
GBC.emu/src/libgambatte/src/initstate.cpp:1151). The vendored API carries no
boot ROM entry point (GBC.emu/src/libgambatte/include/gambatte.h:38-211) and
no menu offers a path for one, the file path view adding a cheats directory
to the stock save and screenshot entries
(GBC.emu/src/main/EmuMenuViews.cc:187-212,
EmuFramework/src/gui/FilePathOptionView.cc:159-163). Gambatte's own file
layer is left out of the build (GBC.emu/src/CMakeLists.txt:13-39).
DMG content is colored from tables held in the binary: 13 palettes and a
title-keyed list matched against the ROM header
(GBC.emu/src/main/Main.cc:41-57,155-161, GBC.emu/src/main/Palette.cc:352,359,
466-474, GBC.emu/src/main/EmuMenuViews.cc:74-96). Report Hardware as GBA
passes GBA_CGB to the load call (GBC.emu/src/main/Main.cc:150,
GBC.emu/src/main/system.ccm:113).
Per content the app writes and reads back files named after the ROM: a .sav
sized to the cartridge SRAM bank and created full of 0xFF
(GBC.emu/src/main/Main.cc:86-94,105-112, EmuFramework/src/EmuApp.cc:842-849),
a four byte .rtc base time for cartridges carrying a clock
(GBC.emu/src/main/Main.cc:95-102,113-124), .gqs states
(GBC.emu/src/main/Main.cc:66-69), a .gbcht cheat list under the cheats path
(GBC.emu/src/main/Cheats.cc:70-113) and GbcEmu.config
(GBC.emu/src/main/AppMeta.cc:27). Gambatte's own save file code sits inside
an #if 0 block and its two entry points are defined as no-ops by the app
(GBC.emu/src/libgambatte/src/mem/cartridge.cpp:671-715,
GBC.emu/src/main/Main.cc:308-313).
ui.png, gpOverlay.png and the shader sources are drawn from the application
bundle (EmuFramework/include/emuframework/AssetManager.hh:61-65,
EmuFramework/src/AssetManager.cc:58-65,
EmuFramework/src/VideoImageEffect.cc:163-173). The app declares no bundled
content, the framework definition defaulting to an empty span
(EmuFramework/src/AppMeta.cc:40,
EmuFramework/include/emuframework/AppMeta.hh:66-68).
files: []
+12 -12
View File
@@ -65,7 +65,7 @@ files:
- name: "us_scd2_9306.bin" - name: "us_scd2_9306.bin"
system: sega-segacd system: sega-segacd
region: [north-america] region: [north-america]
search_rank: 1 priority: 1
required: true required: true
size: 131072 # 128 KB (0x20000) size: 131072 # 128 KB (0x20000)
note: "US Sega CD Model 2 BIOS (September 1993). First in US search order." note: "US Sega CD Model 2 BIOS (September 1993). First in US search order."
@@ -74,7 +74,7 @@ files:
- name: "SegaCDBIOS9303.bin" - name: "SegaCDBIOS9303.bin"
system: sega-segacd system: sega-segacd
region: [north-america] region: [north-america]
search_rank: 2 priority: 2
required: false required: false
size: 131072 size: 131072
note: "US Sega CD BIOS (March 1993). Second in US search order." note: "US Sega CD BIOS (March 1993). Second in US search order."
@@ -83,7 +83,7 @@ files:
- name: "us_scd1_9210.bin" - name: "us_scd1_9210.bin"
system: sega-segacd system: sega-segacd
region: [north-america] region: [north-america]
search_rank: 3 priority: 3
required: false required: false
size: 131072 size: 131072
note: "US Sega CD Model 1 BIOS (October 1992). Third in US search order." note: "US Sega CD Model 1 BIOS (October 1992). Third in US search order."
@@ -92,7 +92,7 @@ files:
- name: "bios_CD_U.bin" - name: "bios_CD_U.bin"
system: sega-segacd system: sega-segacd
region: [north-america] region: [north-america]
search_rank: 4 priority: 4
required: false required: false
size: 131072 size: 131072
note: "US Sega CD BIOS (generic name). Last in US search order." note: "US Sega CD BIOS (generic name). Last in US search order."
@@ -104,7 +104,7 @@ files:
- name: "eu_mcd2_9306.bin" - name: "eu_mcd2_9306.bin"
system: sega-megacd system: sega-megacd
region: [europe] region: [europe]
search_rank: 1 priority: 1
required: true required: true
size: 131072 size: 131072
note: "EU Mega CD Model 2 BIOS (June 1993). First in EU search order." note: "EU Mega CD Model 2 BIOS (June 1993). First in EU search order."
@@ -113,7 +113,7 @@ files:
- name: "eu_mcd2_9303.bin" - name: "eu_mcd2_9303.bin"
system: sega-megacd system: sega-megacd
region: [europe] region: [europe]
search_rank: 2 priority: 2
required: false required: false
size: 131072 size: 131072
note: "EU Mega CD Model 2 BIOS (March 1993). Second in EU search order." note: "EU Mega CD Model 2 BIOS (March 1993). Second in EU search order."
@@ -122,7 +122,7 @@ files:
- name: "eu_mcd1_9210.bin" - name: "eu_mcd1_9210.bin"
system: sega-megacd system: sega-megacd
region: [europe] region: [europe]
search_rank: 3 priority: 3
required: false required: false
size: 131072 size: 131072
note: "EU Mega CD Model 1 BIOS (October 1992). Third in EU search order." note: "EU Mega CD Model 1 BIOS (October 1992). Third in EU search order."
@@ -131,7 +131,7 @@ files:
- name: "bios_CD_E.bin" - name: "bios_CD_E.bin"
system: sega-megacd system: sega-megacd
region: [europe] region: [europe]
search_rank: 4 priority: 4
required: false required: false
size: 131072 size: 131072
note: "EU Mega CD BIOS (generic name). Last in EU search order." note: "EU Mega CD BIOS (generic name). Last in EU search order."
@@ -143,7 +143,7 @@ files:
- name: "jp_mcd2_921222.bin" - name: "jp_mcd2_921222.bin"
system: sega-megacd system: sega-megacd
region: [japan] region: [japan]
search_rank: 1 priority: 1
required: true required: true
size: 131072 size: 131072
note: "JP Mega CD Model 2 BIOS (December 1992). First in JP search order." note: "JP Mega CD Model 2 BIOS (December 1992). First in JP search order."
@@ -152,7 +152,7 @@ files:
- name: "jp_mcd1_9112.bin" - name: "jp_mcd1_9112.bin"
system: sega-megacd system: sega-megacd
region: [japan] region: [japan]
search_rank: 2 priority: 2
required: false required: false
size: 131072 size: 131072
note: "JP Mega CD Model 1 BIOS (December 1991). Second in JP search order." note: "JP Mega CD Model 1 BIOS (December 1991). Second in JP search order."
@@ -161,7 +161,7 @@ files:
- name: "jp_mcd1_9111.bin" - name: "jp_mcd1_9111.bin"
system: sega-megacd system: sega-megacd
region: [japan] region: [japan]
search_rank: 3 priority: 3
required: false required: false
size: 131072 size: 131072
note: "JP Mega CD Model 1 BIOS (November 1991). Third in JP search order." note: "JP Mega CD Model 1 BIOS (November 1991). Third in JP search order."
@@ -170,7 +170,7 @@ files:
- name: "bios_CD_J.bin" - name: "bios_CD_J.bin"
system: sega-megacd system: sega-megacd
region: [japan] region: [japan]
search_rank: 4 priority: 4
required: false required: false
size: 131072 size: 131072
note: "JP Mega CD BIOS (generic name). Last in JP search order." note: "JP Mega CD BIOS (generic name). Last in JP search order."