Post by @rqm
so there's a rumor you can tickle the NEC uPD765 floppy controller just right and it will whisper sweet nothings in your ear
those sweet nothings being its microcode.
now, we already have the 765's microcode ROM array dumped via die photography thanks to @infosecdj .
so why might we want to proceed with the tickle party?
because the microcode ROM doesn't make any damn sense, that's why. so i'm curious if the debug mode might dump out something in a different order.
plus i'm just curious to see if I can figure out the method in the first place.
this rumor comes from a 14-year old comment Hackaday from a user 'NateOcean'.
Unfortunately nobody knows who the hell NateOcean is and he did not elaborate.
But thanks to him we know we have to tickle the DMA lines.
I mean if I was a fancy-pants NEC chip designer and I wanted to give my chip a microcode-yodelling debug mode using pin tickling i'd logically make it check said tickled pins during reset.
i could be wrong here! but it's good as any guess at the moment.
but then how does the microcode get read out? does it just come tumbling out as we clock the chip? do we have to toggle some other pin to advance it? who knows!
i figure we assert /CS and /RD and keep clocking it and if nothing exciting happens we can try twiddling /RD on and off.
I'm going to use my new best friend, the Pi Pico 2.
i added a bypass cap for the 765 and tied some of the unused inputs to ground, but i don't feel like taking another picture
initial check looks good - we're able to reset the 765.
I'm actually able to read 0x90 from the main status register which is remarkably plausible.
That's RQM and BUSY.