Exception vectors and basic RAM & ROM locations
===========#==#=======#===============================================#=====
----------------------|Exception Vectors |-----
===========#==#=======#===============================================#=====
$00000000.L|R-|XPT_SPR|SSP after Reset |
$00000000 and $00000004 Reset vectors
$00000000 longword, supervisor stack pointer after reset
$00000004 longword, program counter after reset
These two are read from ROM, not RAM. At reset the memory
controller maps ROM to address zero so the 68000 fetches the
initial stack pointer and start address from there, then TOS
switches the mapping so RAM appears at zero.
Add-on ROM boards commonly claim $00000000 to $00000007 for
exactly this reason: to supply their own reset vectors and
take control before TOS.
From the Atari Compendium and Atari TOS bios/startup.S.
$00000004.L|R-|XPT_PCR|PC after Reset |
$00000008.L|RW|XPT_BUS|Bus Error |
$0000000C.L|RW|XPT_ADR|Address Error |
$00000010.L|RW|XPT_ILL|Illegal Instruction |
$00000014.L|RW|XPT_DBZ|Divide by Zero |
$00000018.L|RW|XPT_CHK|Chk, Chk2 Instruction |
$0000001C.L|RW|XPT_TRV|Trapv Instruction |
$00000020.L|RW|XPT_PRV|Privilege Violation |
$00000024.L|RW|XPT_TRC|Trace |
$00000028.L|RW|XPT_LNA|Line-A |
$00000028 and $0000002C Line-A and Line-F vectors
$00000028 longword, Line-A exception
$0000002C longword, Line-F exception
The 68000 traps any instruction whose top four bits are $A or
$F, since neither is a valid opcode.
Atari used Line-A for a set of fast low level graphics
routines, documented on the wiki as Line-A. Those were removed
on later machines, so anything using them must check the
machine type first.
Line-F is used by the 68881 and 68882 floating point
coprocessors. On a machine without an FPU it is free.
From the Atari Compendium and Atari TOS common/tosvars.inc.
$0000002C.L|RW|XPT_LNF|Line-F |
$00000030.L|RW| - |reserved |
$00000034.L|RW|XPT_FPU|Coprocessor Protocol Violation |030+
$00000038.L|RW|XPT_FRM|Format Error |010+
$0000003C.L|RW|XPT_DSP|DSP Transfer Interrupt |*
$00000040.L|RW| - |reserved |
$00000044.L|RW| - |reserved |
$00000048.L|RW| - |reserved |
$0000004C.L|RW| - |reserved |
$00000050.L|RW| - |reserved |
$00000054.L|RW| - |reserved |
$00000058.L|RW| - |reserved |
$0000005C.L|RW| - |reserved |
$00000060.L|RW|XPT_SPU|Spurious Interrupt |
$00000064.L|RW|XPT_LV1|Level 1 - |
$00000068.L|RW|XPT_HBL|Level 2 - HBL |
$00000068 to $0000007C Auto-vector interrupts
$68 Level 2 HBL, horizontal blank
$70 Level 4 VBL, vertical blank
$78 Level 6 MFP 68901
Levels 1, 3, 5 and 7 exist in the table but are unused on a
standard ST. Level 5 is the SCC on machines that have one.
The VBL at level 4 is the one most software hooks, though the
supported route is the VBL queue at $00000456 rather than
taking the vector directly.
The MFP at level 6 is the busiest: every timer, the keyboard,
the floppy controller and the serial port all arrive through
it, dispatched by the MFP's own vector table at $00000100.
From the Atari Compendium and Atari TOS common/tosvars.inc.
$0000006C.L|RW|XPT_LV3|Level 3 - |
$00000070.L|RW|XPT_VBL|Level 4 - VBL |
$00000074.L|RW|XPT_LV5|Level 5 - SCC |
$00000078.L|RW|XPT_LV6|Level 6 - MFP |
$0000007C.L|RW|XPT_LV7|Level 7 - |
$00000080.L|RW|XPT_T00|Trap #00 |
$00000084.L|RW|XPT_T01|Trap #01 - GEMDOS |
$00000080 to $000000BC Trap vectors
Trap #1 ($84) GEMDOS
Trap #2 ($88) AES and VDI
Trap #13 ($B4) BIOS
Trap #14 ($B8) XBIOS
The remaining twelve traps are unused by TOS and free for
application use, though some resident utilities claim them.
Function number is passed on the stack, not in a register.
Full call documentation is in tos.hyp rather than this map.
From the Atari Compendium and Atari TOS common/tosvars.inc.
$00000088.L|RW|XPT_T02|Trap #02 - AES/VDI |
$0000008C.L|RW|XPT_T03|Trap #03 |
$00000090.L|RW|XPT_T04|Trap #04 |
$00000094.L|RW|XPT_T05|Trap #05 |
$00000098.L|RW|XPT_T06|Trap #06 |
$0000009C.L|RW|XPT_T07|Trap #07 |
$000000A0.L|RW|XPT_T08|Trap #08 |
$000000A4.L|RW|XPT_T09|Trap #09 |
$000000A8.L|RW|XPT_T10|Trap #10 |
$000000AC.L|RW|XPT_T11|Trap #11 |
$000000B0.L|RW|XPT_T12|Trap #12 |
$000000B4.L|RW|XPT_T13|Trap #13 - BIOS |
$000000B8.L|RW|XPT_T14|Trap #14 - XBIOS |
$000000BC.L|RW|XPT_T15|Trap #15 |
$000000C0.L|RW|FPU_BOS|FFCP Branch or Set |020+
$000000C4.L|RW|FPU_INX|FFCP Inexact Result |020+
$000000C8.L|RW|FPU_DBZ|FFCP Divide by Zero |020+
$000000CC.L|RW|FPU_UNR|FFCP Underflow |020+
$000000D0.L|RW|FPU_OPE|FFCP Operand Error |020+
$000000D4.L|RW|FPU_OVR|FFCP Overflow |020+
$000000D8.L|RW|FPU_NAN|FFCP signaling NAN |020+
$000000DC.L|RW| - |reserved |
$000000E0.L|RW|XPT_MMU|MMU Configuration Error |030+
$000000E4.L|RW| - |reserved |
$000000E8.L|RW| - |reserved |
$000000EC.L|RW| - |reserved |
$000000F0.L|RW| - |reserved |
$000000F4.L|RW| - |reserved |
$000000F8.L|RW| - |reserved |
$000000FC.L|RW| - |reserved |
$00000100.L|RW|XPT_CTR|B0 Centronics busy |*
$00000100 to $0000013C MFP interrupt vectors
The MFP 68901 supplies its own vector number, so its sixteen
interrupt sources each get a dedicated entry here rather than
sharing the level 6 auto-vector.
Which source maps to which vector is set by the MFP vector
register at $FFFFFA17, which holds the upper nibble of the
vector base. On the Atari that is $40, putting the sixteen
vectors at $40 to $4F, which are these addresses.
Priority runs from the top of the list down: B7 (FDC/HDC) is
higher priority than B0 (Centronics busy), and register A
sources outrank register B.
Enable, mask, pending and in-service for each source are
controlled by the MFP registers at $FFFFFA07 to $FFFFFA15.
From the Atari Compendium and Atari TOS common/tosvars.inc.
$00000104.L|RW|XPT_DCD|B1 RS232 DCD |*
$00000108.L|RW|XPT_CTS|B2 RS232 CTS |*
$0000010C.L|RW|XPT_BLT|B3 Blitter Done |*BLT
$00000110.L|RW|XPT_T_D|B4 Timer D |*
$00000114.L|RW|XPT_T_C|B5 Timer C |*
$00000118.L|RW|XPT_KBD|B6 IKBD/MIDI |*
$0000011C.L|RW|XPT_FDC|B7 FDC/HDC |*
$00000120.L|RW|XPT_T_B|A0 Timer B |*
$00000124.L|RW|XPT_XMT|A1 Transmit Error |*
$00000128.L|RW|XPT_EMP|A2 Transmit Buffer empty |*
$0000012C.L|RW|XPT_REC|A3 Receive Error |*
$00000130.L|RW|XPT_FUL|A4 Receive Buffer full |*
$00000134.L|RW|XPT_T_A|A5 Timer A |*
$00000138.L|RW|XPT_RNG|A6 RS232 Ring Indicator |*
$0000013C.L|RW|XPT_SND|A7 Monochrome Detect/Audio Subsystem |*
$00000140.L|RW| - |User defined Vectors |
...........|RW| - |.................... |
$000003FC.L|RW| - |User defined Vectors |
| | | CHECK: $140-$17C are the TT MFP vectors and |
| | | $180-$1BC the SCC vectors on machines that |
| | | have them; $380-$3CC is the TOS exception |
| | | crash save area. Not all of this range is |
| | | genuinely user defined. |
===========#==#=======#===============================================#=====
----------------------|Random Access Memory |-----
===========#==#=======#===============================================#=====
$00000008.B|RW|RAM_TOP|RAM TOP |
...........|RW| - |....... |
$00CFFFFF.B|RW|RAM_END|RAM END |
===========#==#=======#===============================================#=====
----------------------|Alternative RAM (add-on boards) |-----
===========#==#=======#===============================================#=====
$00400000.B|RW|ALT_TOP|Alt-RAM TOP, add-on boards |*
$00400000 onward Alternative RAM
Alt-RAM on the ST range conventionally starts at the 4MB mark,
$00400000, immediately above the 4MB of ST RAM a stock machine
can address.
Common fits:
$00400000 to $007FFFFF 4MB
$00400000 to $00BFFFFF 8MB, the usual size
$00400000 to $00DFFFFF 10MB
Boards exist that go higher.
The address range above the alt-RAM area is nominally VME bus
space on machines that have it, the TT and Mega STE. That
allocation should stand. In practice, on machines with no VME
bus fitted or with VME unused, alt-RAM boards sometimes extend
into that range as well.
THE VME OVERLAP, now confirmed. On a Mega STE the VME bus
address space begins at $00A00000, so it does NOT sit above
the alt-RAM area, it sits INSIDE it:
4MB fit $00400000-$007FFFFF no overlap
8MB fit $00400000-$00BFFFFF overlaps VME from $00A00000
10MB fit $00400000-$00DFFFFF covers the whole VME range
So an 8MB or larger alt-RAM board on a Mega STE is using
address space the VME bus would otherwise claim. That is
workable when no VME card is fitted, which is the usual case,
but the two cannot coexist at those addresses.
The TT is unaffected: its VME space is at $FE000000, well
clear of alt-RAM.
Ranges confirmed by Hatari src/scu_vme.c, which cites the
Atari TT030 Hardware Reference Manual (June 1990) and the
Atari Profibuch ST-STE-TT chapter 9 (1991), and independently
by the Atari Compendium.
This is separate from TT RAM on the TT and Falcon, which lives
at $01000000 and is reported through the ramtop system
variable at $000005A4, validated by ramvalid at $000005A8.
Known to be used by: FLASHY CLOCK, SEC BOOSTER.
STE CHIP DECODE IN THE SAME REGION: Atari's own STE ASIC
schematics decode part of this range for cartridge ROM, not
RAM. The /ROM5 and /ROM6 selects cover $00D00000-$00D7FFFF,
and setting the undocumented GAMECART bit at $FFFF9000 moves
the cartridge port selects to $00D80000-$00DFFFFF. This
applies to the GST MCU machines only, meaning the STE, Mega
STE and TT; the ST and STF use separate GLUE and MMU chips
with no such decodes. Neither select is connected on a
production machine and no TOS ever sets the bit, so in
practice the range is free. It is worth knowing about before
designing a board that claims these addresses. See $FFFF9000
on the MFP, RTC and anything else page.
...........|RW| - |............ |*
$00DFFFFF.B|RW|ALT_END|Alt-RAM END, largest fit seen |*
===========#==#=======#===============================================#=====
----------------------|VME Bus Address Space |-----
===========#==#=======#===============================================#=====
$00A00000.B|RW|VME_A24|VMEbus A24:D16 addressable area TOP |ME
$00A00000 onward VME Bus Address Space
The VME bus is fitted to the Mega STE and TT only. Two address
windows are provided on each, one for 24 bit VME addressing
and a smaller one for 16 bit.
Mega STE:
$00A00000 to $00DEFFFF VMEbus A24:D16
$00DF0000 to $00DFFFFF VMEbus A16:D16
TT:
$FE000000 to $FEFEFFFF VMEbus A24:D16
$FEFF0000 to $FEFFFFFF VMEbus A16:D16, shadow image
All transfers are word based, D16. The Mega STE window is the
more limited of the two.
IMPORTANT: on the Mega STE this space overlaps the range used
by alt-RAM boards of 8MB and larger. See the alt-RAM entry
above.
The VME control registers are separate and live in the I/O
area at $FFFF8E01 to $FFFF8E0F, documented on the MFP, RTC and
anything else page. Those cover the interrupt mask, interrupt
state and the two forced interrupt registers, alongside the
SCU general purpose registers.
From the TT hardware reference, VME SYSFAIL generates a
motherboard IRQ7 to the processor but does not generate an
IRQ7 back onto the VME bus. SCU generated IRQ1 and IRQ3 are
always auto vectored; only interrupts 5 and 6 have external
IACK pins and can produce vectored interrupts.
Ranges and interrupt behaviour from Hatari src/scu_vme.c,
citing the Atari TT030 Hardware Reference Manual (June 1990)
and the Atari Profibuch ST-STE-TT chapter 9 (1991).
Cross-checked against the Atari Compendium.
...........|RW| - |............................... |ME
$00DEFFFF.B|RW| - |VMEbus A24:D16 addressable area END |ME
$00DF0000.B|RW|VME_A16|VMEbus A16:D16 addressable area TOP |ME
...........|RW| - |............................... |ME
$00DFFFFF.B|RW| - |VMEbus A16:D16 addressable area END |ME
$FE000000.B|RW|VME_T24|VMEbus A24:D16 addressable area TOP |TT
...........|RW| - |............................... |TT
$FEFEFFFF.B|RW| - |VMEbus A24:D16 addressable area END |TT
$FEFF0000.B|RW|VME_T16|VMEbus A16:D16 area TOP, shadow image |TT
...........|RW| - |............................... |TT
$FEFFFFFF.B|RW| - |VMEbus A16:D16 area END |TT
===========#==#=======#===============================================#=====
----------------------|TT RAM (Fast RAM) |-----
===========#==#=======#===============================================#=====
$01000000.B|RW|TTR_TOP|TT Fast RAM TOP |TT,F
$01000000 onward TT RAM (Fast RAM)
Present on the TT and Falcon. Physically separate from ST RAM
and connected directly to the processor rather than through
the video and DMA hardware.
$01000000 to $01FFFFFF TT Fast RAM, up to 16MB
$02000000 to $FDFFFFFF Reserved
IMPORTANT: TT RAM is UNSUITABLE for direct DMA and Shifter
transfers. It cannot be used for screen memory, and it cannot
be the target or source of a DMA transfer. Anything going to
or from disk, or being displayed, has to live in ST RAM. This
is the single most important thing to know about it.
What it is good for is code and data, where the lack of
contention with the video hardware makes it appreciably faster
than ST RAM.
The top of installed TT RAM is reported in the system variable
ramtop at $000005A4, validated by ramvalid at $000005A8
holding $1357BD13. A zero ramtop means no TT RAM is fitted.
GEMDOS tracks it through a second memory descriptor chained
from themd at $0000048E, which is why Malloc can hand out
either kind. Mxalloc lets a program ask for one specifically.
CONFLICT on the extent, now leaning one way: the Atari
Compendium gives the range as $01000000 to $01FFFFFF, 16MB.
"The Atari A to Z" (Mark S Baines, 1998) independently gives
the same, listing $01000000 as the start of TT fast RAM and
$01FFFFFF as the end of TT RAM space. The older Hardware
Register Listing page is the only source giving $01000000 to
$013FFFFF, 4MB. Two independent sources against one puts 16MB
as the architectural extent, with 4MB most likely a common
fitted size that got written down as the limit. Not confirmed
on hardware, so still flagged.
Note this is entirely separate from alt-RAM on add-on boards
for the ST and STE, which lives at $00400000. See the
alternative RAM entry above.
Range and the DMA restriction from the Atari Compendium.
...........|RW| - |............... |TT,F
$01FFFFFF.B|RW|TTR_END|TT Fast RAM END |TT,F
$02000000.B|--| - |Reserved |
...........|--| - |........ |
$FDFFFFFF.B|--| - |Reserved |
| | | CHECK: was annotated "14MB". $00CFFFFF is |
| | | 13MB. For 14MB, RAM should end at $00DFFFFF. |
| | | Either the address or the size is wrong. |
===========#==#=======#===============================================#=====
----------------------|1MB System Read Only Memory |-----
===========#==#=======#===============================================#=====
$00E00000.B|R-|ROM_TOP|1MB ROM TOP |F
$00E00000 onward System ROM
$00E00000 to $00EFFFFF 1MB ROM area, Falcon and TT
$00FC0000 to $00FEFFFF 192KB ROM area, ST and STE
The ST and STE map their 192KB ROM at $00FC0000. The TT and
Falcon use a larger 1MB region starting at $00E00000.
ADD-ON BOARDS: ROM expansion boards commonly claim
$00E00000 to $00E3FFFF for their own 256KB ROM, and some add a
flash area at $00E40000 to $00E7FFFF. Known to be used by
FLASHY CLOCK, TRUDIE and SEC BOOSTER. Such boards also take
the reset vectors at $00000000 to $00000007 and the 192KB
region at $00FC0000 to $00FEFFFF.
RESOLVED: the wiki listing used to give the 1MB ROM area as
ending at $00F0003F, 1MB plus 64 bytes. The extra 64 bytes
are the Falcon IDE registers at $00F00000 to $00F0003F,
documented on the IDE page; the ROM decode itself ends at
$00EFFFFF.
Within the 1MB area the Falcon fits 512KB of TOS ROM at
$00E00000 to $00E7FFFF. The F030/CT60 listing documents
$00E80000 to $00EFFFFF as an image (mirror) of those 512KB
ROMs. CHECK: Hatari instead treats $00E80000 to $00EFFFFF as
empty space, so the mirror claim is unconfirmed by the
emulator sources; it may be true on real hardware only.
STE CHIP DECODE, a separate matter from the Falcon mirror
above: Atari's own STE ASIC schematics show the GST MCU
decoding $00E80000-$00EBFFFF as chip select /ROM0 and
$00E40000-$00E7FFFF as /ROM1. Both pins are left unconnected
on production machines, which is why the STE ships with 256KB
of TOS on /ROM2 rather than the 768KB the decoding would
allow. This is a GST MCU feature, so it applies to the STE,
Mega STE and TT and NOT to the ST or STF, which use separate
GLUE and MMU chips. Worth noting because the add-on flash
area below sits exactly on the /ROM1 range: on a GST MCU
machine, a board putting flash at $00E40000 is using an
address the chip already decodes for ROM. Source is Keli
Hlodversson's reading of the Christian Zietz schematic
recovery, https://www.keli.dk/old-asic/ - schematic evidence
only, not confirmed against Hatari, EmuTOS, TOS or the
Compendium, none of which mention these selects.
Extended bit information is not currently available for the
add-on ROM and flash areas.
...........|R-| - |........... |F
$00E7FFFF.B|R-| - |512KB TOS ROM END (fitted ROM) |F
$00E80000.B|R-| - |Image of the 512KB TOS ROMs (see CHECK above) |F
...........|R-| - |........... |F
$00EFFFFF.B|R-|ROM_END|1MB ROM area END |F
$00F0003F.B|R-| - |IDE registers end - see the IDE page |F
$00E40000.B|R-|FLA_TOP|Flash space TOP, add-on boards |*
$00E40000 to $00E7FFFF Flash space, add-on boards
Not present on stock Atari hardware. 256KB of flash memory
fitted by some ROM expansion boards, sitting immediately above
the add-on ROM area at $00E00000 to $00E3FFFF.
Known to be used by: FLASHY CLOCK.
Extended bit information is not currently available.
...........|R-| - |............... |*
$00E7FFFF.B|R-|FLA_END|Flash space END |*
| | | The 1MB ROM extent question is resolved in |
| | | the $00E00000 entry above: ROM decode ends at |
| | | $00EFFFFF, and $00F00000-$00F0003F is IDE. |
===========#==#=======#===============================================#=====
$00F00040.B|--| - |Illegal Address Space (ST/STE/TT) | | | | Falcon: Bus Expansion Space from $00F10000 |F
$00F00040 to $00F9FFFF
On the ST, STE and TT this range is illegal address space.
On the Falcon, $00F10000 to $00F9FFFF is the Falcon030 BUS
Expansion Space: 576KB of A24/D16 expansion decode, per the
F030/CT60 listing. This is where Falcon expansion hardware is
intended to live.
SUPERSEDED CLAIMS: the old Dan Hollis derived listing gave
five Mega STE "speed control" addresses in this range:
$00F10000 switch to 8MHz, $00F20000 high speed ROM on,
$00F30000 high speed ROM off, $00F40000 unknown, $00F50000
cache off at 16MHz. None of these appear in Hatari, EmuTOS or
any TOS source; Mega STE speed and cache control is the byte
at $FFFF8E21, documented on the MFP page. Treat the $00F1xxxx
speed claims as wrong.
CONFLICT: the CT60 accelerator claims $FFF00000 to $FFFBFFFF
in the IO mirror of this region for its own registers. See
the note in the IDE block.
...........|--| - |..................... |
$00F9FFFF.B|--| - |Illegal Address Space / Bus Expansion END |
===========#==#=======#===============================================#=====
----------------------|128KB Expansion Cartridge Port |-----
===========#==#=======#===============================================#=====
$00FA0000.L|R-|ROM_PRT|Cartridge Magic($FA52235F=Diag,$ABCDEF42=User*)|
$00FA0000 to $00FBFFFF Cartridge port, 128KB
$00FA0000 longword, cartridge magic
$00FA0004 longword, entry point for a diagnostic cartridge
Two magic values are recognised, and Atari's own TOS source
tests both:
$FA52235F diagnostic cartridge. Tested very early in
bios/startup.S, before RAM is even sized, and
jumped to immediately if found.
$ABCDEF42 normal application cartridge. Tested later, once
the system is up.
A diagnostic cartridge therefore takes control before almost
anything else, which is what makes it useful for hardware
fault finding on a machine that will not boot.
Magic values confirmed in Atari TOS bios/startup.S, which
compares against both.
$00FA0004.L|R-|ROM_CAL|Call Diagnostic Cartridge |
...........|R-| - |............ |
$00FBFFFF.B|R-| - |ROM Port END |
===========#==#=======#===============================================#=====
----------------------|192KB System Read Only Memory |-----
===========#==#=======#===============================================#=====
$00FC0000.B|--| - |192KB ROM TOP |ST
...........|--| - |............. |ST
$00FEFFFF.B|--| - |192KB ROM END |ST