-
Notifications
You must be signed in to change notification settings - Fork 2
16 November 2025
In comparing Segment 6 between serial book dumps, it appears that this segment is the same in between Series of books (ie: Elephant, Puppy, Lion).
In Audacity (default endianness, mono, 0 offset, 100% import, 8000hz), running the regions in segment 3 that the pointers reference seem to produce only static sound except for when imported as NMS ADPCM (sounds like popcorn), and GSM 6.10 (sounds like a robot blaring tones).
In consulting with GainSec a few months ago, it seems like the main projector chip is a GPCE3400A, which identification may help in discovering how to decompress these regions in segment 3. It seems like each region has an initial compressed audio area followed by a decompression key (possibly).
Additionally, GainSec had identified that this suite of programs could potentially be the ones GeneralPlus used to make these books (Suite). I had to use the wayback machine from internet archive to restore access to the link, as I continually get ERR_CONNECTION_RESET when trying to access the url directly.
| Segment | Starting Address | Ending Address (inclusive) | Binary | Notes |
|---|---|---|---|---|
| 1 | 0x0 | 0x6F | 1A 00 0C 00 6C 00 00 00 3A 24 00 00 E8 4E 00 00 76 D8 00 00 0A F7 00 00 32 53 01 00 14 B0 01 00 36 FA 01 00 12 46 02 00 B6 7C 02 00 0A B4 02 00 D8 E0 02 00 AE 51 03 00 14 95 03 00 6A CB 03 00 B0 CC 03 00 4E D0 03 00 3C D4 03 00 2A D8 03 00 50 DB 03 00 26 DE 03 00 84 E0 03 00 32 E3 03 00 F0 E4 03 00 66 E8 03 00 FC E9 03 00 CA 23 00 00 | |
| 2 | 0x70 | 0x4EE7 | ... | Fully conservative region |
| 3 | 0x4EE8 | 0x3CB65 | ... | unique region |
| 4 | 0x3CB66 | 0x3ECD1 | Conservative terminal data | |
| 5 | 0x3ECD2 | 0xFFF7F | FF rpt... | Blank "FF" data |
| 6 | 0xFFF80 | 0xFFF8F | Variable region = 00 01 06 | Id code or something... Address will be same for all chips. |
| 7 | 0xFFF90 | 0xFFFFF | FF rpt... | Final padding of blank "FF" data |
If Segment 1 is a pointer table like suggested by Gemini (in the format of quad-byte addresses in reverse order), I should have pointers in segment 1 of:
- [E8 4E 00 00] (checks out)
- [66 CB 03 00] (almost)
- [D2 EC 03 00] (doesnt go that high)
- [80 FF 0F 00]
- [90 FF 0F 00]
As per Gemini's suggestion, there should be separate segments at the following addresses:
| Proposed pointer address | Conserved in Pointer Table? | Points to conserved region? | String of bytes prior (of any interest) | String of bytes starting | Notes |
|---|---|---|---|---|---|
| [0x0C001A] | some | -- | -- | -- | This may be a cartridge signature and event # |
| [0x6C] | conserved | -- | -- | -- | ??? |
| [0x243A] | conserved | conserved seg2 | -- | -- | ??? |
| [0x4EE8] | conserved | unique seg3 | -- | -- | Points to the start of Segment 3's unique region |
| [0xD876] | unique seg1 | unique seg3 | 00 08 80 F9 81 F9 08 80 E5 81 E5 08 80 D1 81 D1 08 80 BD 81 BD 08 80 A9 81 A9 08 80 95 81 95 08 80 81 81 81 08 80 6D 81 6D 08 80 59 81 59 08 80 45 81 45 08 80 30 81 30 08 80 1C 81 1C 0C 80 08 81 08 F1 00 00 | 02 1E 00 00 80 3E 9E 08 12 E1 C5 85 0A 5A 45 BD 6E 6B 07 7A 53 88 B6 D7 C7 92 3C 82 32 25 20 4D... | Prior bytes seem to repeat in 08 80 couples with 3 bytes in between. Some such "between" sequences repeat byte 1 and 3. |
| [0xF70A] | unique seg1 | unique seg3 | 00 AB 3B CB 13 36 34 95 DD C9 8C 14 05 D8 64 06 E7 00 8C AF 38 42 A6 88 0F AA A1 1F 01 12 09 1E 1A 81 99 9F 8E C2 E9 F4 C8 70 B5 70 65 FA 40 34 24 B5 A9 35 3B 0A 32 87 B6 F0 1D D5 AD AD 08 3A 26 3B 90 06 2B 10 0B 84 05 55 E9 FB 9F 35 41 B0 1F C6 57 06 56 1C E9 6A A4 B6 98 6F 96 35 F3 9E 7B 80 04 FB 71 C0 70 F1 4C FF BB FF FF 04 F0 00 08 80 30 82 30 08 80 61 82 61 08 80 92 82 92 08 80 C3 82 C3 08 80 F4 82 F4 08 80 FF 82 FF 08 81 04 82 FA 08 81 16 82 E8 08 81 29 82 D5 08 81 3B 82 C3 08 81 4E 82 B0 08 81 61 82 9D 08 81 73 82 8B 08 81 86 82 78 08 81 98 82 66 08 81 AB 82 53 08 81 BE 82 40 08 81 D0 82 2E 08 81 E3 82 1B 08 81 F5 82 09 08 81 FF 82 00 08 80 E8 81 E8 08 80 BF 81 BF 08 80 97 81 97 08 80 6F 81 6F 08 80 47 81 47 08 80 1E 81 1E 04 F1 00 00 | F2 5A 00 00 80 3E 9C 08 35 65 01 99 76 06 62 CF 7E E5 2F E4 EA 35 FE 50 FF 14 C6 62 47 4A 2B 22 8E 27 F8 81 0E 94 03 4C A3 99 21 54 FF 61 9C 08 7E 65 A8 18 AA 32 30 AA 64 6A 7D C5 84 2A 2D AD 4D 4B C6 BC A8 1D D8 03 46 57 22 D3 6D 2A 2B 33 8C CA D5 B2 17 2B 9C 08 6B 09 D0 0B 56 61 8D 96 5E AD 8F A6 9B 86 A9 A1 A5 AF D5 50 9E 0C 13 0A 52 40 12 8B 83 1F 9A 0D 03 AD A7 3C FE 17 9E 08 6B 69 19 3D D4 0B 5E 25 E7 2B AC 81 C3 BD 65 24 73 AB CE 36 26 10 A9 B5 6F E7 B9 06 82 2E 2D DC 24 A8 CC 5A FF BA 1F 08 3C 01 14 7F F5 61 12 52 96 00... | Before this pointer, it seems that there is another table of 08 80 dividing tri-byte tables. |
| [0x15332] | unique | unique | the "01 of 32 53 01 is conserved among many cartridges, but not all (YES in: BSLSBS, Elephant, Puppy; NO in: Lion) | ||
| [0x1B014] | |||||
| [0x1FA36] | |||||
| [0x24612] | |||||
| [0x27CB6] | |||||
| [0x2B40A] | |||||
| [0x2E0D8] | |||||
| [0x351AE] | |||||
| [0x39514] | |||||
| [0x3CB6A] | This could correlate with the beginning of the terminal segment 4 section. Differs from /u/phenakist's analysis, though, by 4 bytes. | ||||
| [0x3CCB0] | |||||
| [0x3D04E] | |||||
| [0x3D43C] | |||||
| [0x3D82A] | |||||
| [0x3DB50] | |||||
| [0x3DE26] | |||||
| [0x3E084] | |||||
| [0x3E332] | |||||
| [0x3E4F0] | |||||
| [0x3E866] | |||||
| [0x3E9FC] | This is the last unique pointer. It ends before segment 5 begins, so that is reassuring. | ||||
| [0x23CA] | This is conserved. I have doubts that its an address based on the first "pointer" being likely a signature. |
I would also analyze 0x60100 as the address-converted segment of the unique portion of the ID (segment 6).
The pointers in the table seem to only ascend, and stop before segment 5 (most contained in the unique segment 4). It may be logical to deduce that these are indeed specific addresses instead of any specified lengths.
It seems that there is space for just 23 unique pointers per cartridge.
- Double check phenakist's address analysis for segment 4.
- Analyze all Table pointers before- and after- bytes. Compare to other relative regions.
- check segment 6 address.
- Save certain segments and import them into Audacity as raw binary. See if anything plays.
- Check if any pointers are actually "n-bytes," signifying a length of a binary chapter to read, etc.
| Segment # | Start Address | End Address (inclusive) | Note |
|---|---|---|---|
| 1 | 0x0 | 0x6F | ?pointer table |
| 2 | 0x70 | 0x4EE7 | conserved region |
| 3 | 0x4EE8 | 0x769C0 | unique region - the ending has that hash table of 08 80 again... but with different digits |
| 4 | 0x769C1 | 0x78B2B | Conservative terminal |
| 5 | 0x78B2C | 0xFFF7F | FF... |
| 6 | 0xFFF80 | 0xFFF8F | conserved except for ... wait... the original 3 books match exactly... is it a series stamp? |
| 7 | 0xFFF90 | 0xFFFFF | FF... |
| Segment # | Start Address | End Address (inclusive) | Note |
|---|---|---|---|
| 1 | 0x0 | 0x6F | ?pointer table |
| 2 | 0x70 | 0x4EE7 | conserved region |
| 3 | 0x4EE8 | 0x73AB9 | unique region |
| 4 | 0x73ABA | 0x75C25 | Conservative terminal |
| 5 | 0x75C26 | 0xFFF7F | FF... |
| 6 | 0xFFF80 | 0xFFF8F | conserved except for 00 01 06 |
| 7 | 0xFFF90 | 0xFFFFF | FF... |
| Segment # | Start Address | End Address (inclusive) | Note |
|---|---|---|---|
| 1 | 0x0 | 0x6F | ?pointer table |
| 2 | 0x70 | 0x4EE7 | conserved region |
| 3 | 0x4EE8 | 0x67EC7 | unique region - the end is also some sort of table again... |
| 4 | 0x67EC8 | 0x6A033 | Conservative terminal |
| 5 | 0x6A034 | 0xFFF7F | FF... |
| 6 | 0xFFF80 | 0xFFF8F | conserved except for... the 3 original books match exactly = series stamp? |
| 7 | 0xFFF90 | 0xFFFFF | FF... |
Possible unique pointers from seg1 table
- [0155BA] [0194CE] [01EE44] [025548] [028FE2] [0302C6] [037358] [040192] [049E5E] [04EF24] [055FBA] [067ECC]
| ⟵ Older | Table of Contents | Newer ⟶ |
|---|