10 ms·
DOS game “F-15 Strike Eagle II” reverse engineering/reconstruction war stories
- boricj 2y agoI've exchanged a couple of emails with the author a while ago. Reverse-engineering and decompiling DOS software running in real mode and especially video games is a particularly tricky endeavor, a notch above other similar projects on other platforms. The combination of janky PC hardware, paper-thin MS-DOS operating system and prehistoric development tooling makes for an environment where anything goes. Real mode segmented memory and large memory models utterly confuse Ghidra's analyzers and decompiler, most common modern reverse-engineering tools either do not support 16-bit MS-DOS executables or have third-rate support. It is more art than science in a way that I don't think reverse-engineering later software can match.
- duskwuff 2y agoIt's a little awful to think about just how much collective human effort was wasted by segmented memory. Everyone knew that 32-bit flat memory was the future; it just took a long time for the PC platform to get there.
- jandrese 2y agoYeah, but when you are shipping computers with 256kb like the original PC/XT those extra two bytes per pointer start to look like a major luxury. There was a heroic amount of effort in those days to make due with as little memory as possible because memory was so expensive that nobody had more than was absolutely necessary.
- ghaff 2y agoYeah. I’m not going to defend x86 segment registers and real-mode DOS too vigorously. (I programmed in x86 assembler for many years.) But I’m pretty sure the right approach wasn’t to say Screw it. Let’s wait until a 32-bit flat address space processor and OS come along at the consumer and individual business user level.
- jojobas 2y agoSegment:offset addresses were still 32 bits right? And most of the arseache was from the fact that the segments were overlapping as I understand.
- skissane 2y agoYes, but if your program required no more than 64KB of data, then you could use near pointers everywhere, halving the pointer size from 4 bytes to 2 bytes. Also, even if the program as a whole required more than 64KB of data, if you knew you required no more than 64KB of data for objects of type X, then you could use 2 byte pointers for all type X objects, with a fixed data segment. X here might, for example, be strings. When you only have 256KB of RAM to begin with, the odds that all data overall, or at least all X object data for some X, will fit in 64KB is quite high. And if you have a lot of pointers, halving their size makes a big difference when you have so little memory.
- MagerValp 2y agoBut segmented memory isn’t a requirement, that technique works just as well with linear address space. You use a single 32-bit base pointer and then store 16-bit offsets for your data. We used that all the time on 68K and other architectures.
- skissane 2y agoThe difference is that 68K is designed as fundamentally a 32-bit architecture. (Even though the original implementation was physically 16-bit.) Whereas 8086 is a 16-bit architecture with an extended address space. The use of segmentation to enable a 16-bit architecture to address more than 64K was not original to the 8086, many 16-bit minicomputers (e.g. the PDP-11) used the same basic idea, although the specific implementation Intel chose was rather unique Part of why the 8086 was 16-bit not 32-bit, was to make it easier to port software to it from the 8080, which was an 8-bit architecture with 16-bit addressing. It also was likely one of the reasons why the 8086/8088 was cheaper than the 68K, which is part of why IBM chose it over the 68K for the IBM PC
- skissane 2y agoI think it was unfortunate Intel went with 16 byte paragraphs instead of 256 byte. With 256 byte paragraphs, you would have been able to address 16MB instead of 1MB in real mode.
- iforgotpassword 2y agoWhy not just the full 64k. The sliding window trick was of such limited use compared to the headaches it caused. Or maybe 32k as a compromise. But then they repeated the same mistake with the 286, again!
- skissane 2y ago> Why not just the full 64k. The sliding window trick was of such limited use compared to the headaches it caused. As I pointed out in my other comment, the full 64KB would have made it harder to support child processes under DOS. Suppose I have 300KB of free conventional memory, and run an 8KB program (something like a menu program, for example.) If it starts a child process, that child process has about 292KB of free conventional memory to use. With your idea, it could only have 236KB, because even though the parent process only needs 8KB of memory, it would consume a whole 64KB.
- banish-m4 2y agoReal mode profiling and debugging is damn easy, it's protected mode debugging that requires more work. I used Turbo Debugger for years.
- LowLevelMahn 2y agoIDA Pro disassembler fully supports 16Bit DOS executables (they only removed the support from the recent free versions - thats why most using IDA Pro Free 5.0) but Hexrays the decompiler does sadly not support 16bit code (intentionaly) but i think the Hexrays guys could do wonders here (in comparison what Ghidra is able to do)
- anthk 2y agoBochs can help there.
- LowLevelMahn 2y agohow?
- anthk 2y agoIt has a debugger.
- boyter 2y agoWow... bookmarked. F-15 Strike Eagle II is one of those games I played the hell out of as a child. So much so I wore out two joysticks that my parents bought as a result. I was a child so it took me a long time to learn to actually do what the game wanted, and then learn after taking out the targets you got more medals by then bombing or strafing other targets. I don't think I ever got the hang of landing back on the aircraft carrier though.
- gladiatr72 2y agoThat was my experience with it, too. Microprose could do no wrong.
- alexpotato 2y agoI owned multiple Microprose games and the manuals that came with the games were simply fantastic. There would be a section on the gameplay itself and then usually some historical reference about the setting of the game. E.g. if it was a WW1 flight combat simulator, there would be a section on the history of aerial dogfighting and then specs on each plane. I know that nowadays it's common knowledge that most people don't read the manuals and it's easier to get people into a game with a combination first level /introduction/tutorial. That being said, I feel like we lost something by taking out the manuals with all that rich historical detail.
- boyter 2y agoKnights of the Sky was that WW1 flight combat game. Also a wonderful chunk of my childhood went into that. Although I found SEII to be more fun.
- ghaff 2y agoI miss the simulation games of that era. They’ve pretty much faded away. At one point I dove back in a bit but everything was so janky trying to run that I quickly lost interest.
- wkat4242 2y ago
- kurjryhw 2y agothe original f-15 strike eagle pc version was super interesting in that it didn't run on dos. you had to load the game as a boot disk
- khaki54 2y agoCustom os?
- jmts 2y agoMy understanding of PC game development at the time was that most games would re-implement their own drivers for system hardware, hence why you would often need to select what kind of graphics card, sound card, and their settings during the setup. As such, a game running from a boot disk is closer to just skipping DOS and having no OS rather than implementing a custom OS, although from another perspective you might just say that the game is the OS.
- contingencies 2y agoSort-of. IIRC DOS games that wanted to use more than 512KB(?) of memory had to use one of a series of particular high memory access drivers. HIGHMEM.SYS ("XMS"?), EMM386.SYS ("EMS"?), etc. You had to load these and other drivers (in particular sound and mouse drivers, antivirus programs, etc.) when booting up in your CONFIG.SYS and/or AUTOEXEC.BAT. These were referred to as 'TSR' (terminate and stay resident) programs. There were all sorts of tricks to get things working... LOADHIGH, etc. In the end, most games required one particular approach to high memory, and you had to have a CONFIG.SYS/AUTOEXEC.BAT that left enough base memory free as well. It was a huge hassle. In later days most programs used DOS4GW ... https://en.wikipedia.org/wiki/DOS/4G https://en.wikipedia.org/wiki/DOS/4G ... which made things a lot easier.
- ajxs 2y agoI was a 90s kid, and was totally head over heels for Origin Systems' games (Ultima, Wing Commander, etc). Par for course, I had a selection of DOS boot disks to set up the right operating environment for each game. Ultima VII featured a memory manager[0] based on 'Unreal Mode', which made getting it running even more precarious. The quote at the bottom of that link from the developer is really telling. 0: https://www.wiki.ultimacodex.com/wiki/Voodoo_Memory_Manager https://www.wiki.ultimacodex.com/wiki/Voodoo_Memory_Manager
- antod 2y agoI never played that one, but the Microprose "look" just leapt out at me from those screenshots (similarities with F-19, Gunship 2000 etc etc). I did play the later Janes F-15E sim - much more complicated/harder than the Microprose ones were. Not sure it was more fun though, lots more study needed and probably needed proper stick and pedals etc to get much out of it.
- pictureofabear 2y agoF-19 Stealth Fighter was my jam.
- nullify88 2y agoF22 Intercepter over here on the genesis. I recall the game over scene being a image of a skull on a ekg machine flat lining. Used to scare the crap out of me as a kid. Went on to play a lot of F22 Lighting 2 / 3 by Novalogic. Then Delta Force Land Warrior.
- m0zzie 2y ago> Delta Force Land Warrior There's a name I've not heard in a long time. I loved that game so much, the engine and gameplay was ahead of its time (or felt that way). It was sad to see NovaLogic fall behind in the years that followed.
- colechristensen 2y agoSid Meier's Memoir! is a great read if you're a fan of those kinds of things. https://www.goodreads.com/book/show/50489373-sid-meier-s-memoir https://www.goodreads.com/book/show/50489373-sid-meier-s-mem...
- ggambetta 2y agoOh, I loved Gunship 2000. So many hours flying those low-poly missions!
- _mlbt 2y agoI loved the Jane's series of combat simulators! My favorite was Longbow 2... https://en.wikipedia.org/wiki/Jane%27s_Longbow_2 https://en.wikipedia.org/wiki/Jane%27s_Longbow_2
- RachelF 2y agoAs a kid in the 1980s, I "debugged" the original F-15 Strike Eagle One - it was written in AppleSoft basic.
- JoeMattiello 2y agoMe too. My first “hacking” experience was loading the save files into a hex editor and flipping bits to award medals and ranks. I still win every the old way too. Bombed the heck out of Baghdad.
- ElCapitanMarkla 2y agoWhen I was about 8 years old I can remember walking into the office at home this game was on the screen. One of the fighters was flying towards an airstrip and I thought I'd helpfully land it, I crashed. Turns out dad had it on autopilot to return to home after some mission which he had to repeat thanks to me :)
- redconfetti 2y agoI've thought to myself that if I want a cool project that would motivate me to re-learn C just for the sake of making an NES game (ala 8-bit workshop - https://8bitworkshop.com/ https://8bitworkshop.com/), I would really like to learn how to apply the pseudo-3d or 2.5d methods that were used by Microprose in F-19 Stealth fighter. I don't know the first thing about 3D programming. I tried to follow a book on writing a ray-tracer from scratch just to see if I could pick up the principles and do it myself, but I got frustrated by the ambiguity of the approach. Like I was trying to use Ruby with Rspec, but I'm not even sure if I'd run into a performance issue or not be implementing the interfaces correctly. I just want to know what method was used. Maybe 3D projection? https://en.wikipedia.org/wiki/3D_projection https://en.wikipedia.org/wiki/3D_projection Microprose had 3D flight simulators going back to 1984 on Atari 400/800, Commodore 64, and IBM PC. That's really impressive. https://en.wikipedia.org/wiki/Hellcat_Ace https://en.wikipedia.org/wiki/Hellcat_Ace Kind of like how Myst was able to deliver ultra-high resolution 3D images in a video game in ways that had never been done before, even though it was really just a point-and-click slideshow with embedded videos and scripted interactions (Hypercard)... Hellcat Ace provided an experience far ahead of its time.
- ahefner 2y agoOn the NES (or other 6502 machines), use assembly. That CPU just isn't a good target for C - pointers are awkward, you can't really do stack frames, and the addressing modes don't even support 'structs' very well. Fun to program assembly on, though. For your purpose the NES makes it double hard because it hardly has any ram (2 KB, and typically an additional 8 KB inside each cartridge except in the oldest games), and a character-mode graphics architecture rather than a framebuffer. If you do really want to do an 8-bit flight sim, the Atari 400/800 machines are an okay target. The Atari ST would be a better target. Speaking of those machines, I'd love to see someone deeply reverse engineer the pseudo-voxel/fractal landscape engine that Lucasfilm Games invented for Rescue on Fractalus, Koronis Rift, etc. It still seems completely magical that they could pull that off on a machine with those specs. Starting from zero, you might start at a high level and work your way down. Do a simple polygon flight engine using OpenGL and your favorite high level language of choice. Then write your own polygon rasterizer that you can overlay versus the OpenGL rendering as a reference. Then maybe rework it in pseudo 8-bit code (C constrained to only unsigned char variables, or similar), which should translate directly to assembly language on the target of choice. On a real 8-bit machine, unless you want low single digit frame rates, you probably have to pull a lot of dirty tricks. Maybe a 16-bit platform would be a better choice. This is speculative - I learned 3D (to a novice degree..) on a 486 PC under 16-bit DOS using C and assembly for inner loops (bitblts, texture mapping). There's something about the aesthetic of late 80s PC flight sims (F-19 Stealth Fighter, LHX Attack Chopper, etc.) and their flat shaded polygon graphics that feels in vogue right now. Check out Thunder Helix on Steam. Anyway there's definitely a magical feeling writing graphics code when you get your first feeling of realistic movement and rotation in 3D space working. Hopefully the ubiquity of ultra-realistic doesn't diminish that sensation too much.
- newsre4der 2y agoHe could try Spice86 it's seems to be good to decompile old DOS games.
- LowLevelMahn 2y agoSpice86 is currently not a real decompiler - but its more and more becoming one
- sumtechguy 2y agoIs it any good at win16? The other free ones I have used are kind of lacking. I have a win16 game I have been meaning to decompile nicely.
- LowLevelMahn 2y agoSpice86 is some sort of tracking emulator like Dosbox giving you the ability to replace original code parts with C# - i don't think that Spice86 can emulate Win16 currently
- wkat4242 2y agoI didn't play this that much back in the day, but seeing it now it looks extremely similar to LHX Attack Chopper from the same era. Same kind of displays and fonts, same kind of briefing.. Probably from the same studio I guess? Edit: Nope. LHX was not from Microprose but EA instead. Weird. What I liked about LHX was that it was pretty versatile with its cameras and modes. You could focus the camera on enemy tanks etc. It was very bad at actual helicopter combat though. The terrain was all flat and there was no scenery to hide in, no hills to sneak behind, no trees. The only objects were enemy tanks, camps etc. Later another game came out with a weird kind of voxel graphics, Comanche, that fixed all that.
- rzzzt 2y agoNovalogic's one weird trick was using voxel terrains as much as possible, like Comanche or the Delta Force series. I'm not sure if "Black Hawk Down" still had a voxel level or if they have changed the secret recipe at that point.
- wkat4242 2y agoI have to say it looked amazing. I just wasn't able to play it at the time because I only had a 386sx and it really required a 486. By the time I upgraded to a Pentium (on the weird cpu board) the game was already old news.
- smallstepforman 2y agoThere was also an Amiga version of this game, with a sanner 68000 flat memory architecture which could have been easier to reverse engineer (compared to real mode segmented x86).
- huhtenberg 2y agoDoes anyone remember a PC flight sim from the (mid?) 90s that supported dogfights over a null modem cable? Have been trying to remember its name for ages.
- nicholasbraker 2y agoStrike Eagle 3 (the successor to version II) could do this. It supported null-modem as well as Ethernet/IP connectivity to do dogfights, campaigns etc.
- huhtenberg 2y agoThanks, looking. That's pretty damn close.
- postexitus 2y agoLiterally Dogfight by MicroProse? https://en.wikipedia.org/wiki/Dogfight_(video_game) https://en.wikipedia.org/wiki/Dogfight_(video_game)
- huhtenberg 2y agoNope, not the one. Mine had a large-ish detailed minimap and generally was really good-looking for its time (think, Comanche-level graphics).
- m000 2y agoDid you try ChatGPT? Yes, the game you're thinking of is likely "Chuck Yeager's Air Combat," developed by Electronic Arts and released in 1991. It was one of the first flight simulation games to support multiplayer dogfights over a null modem cable. Players could connect two PCs directly via a null modem cable and engage in aerial combat against each other. The game was quite popular for its time and is fondly remembered by many flight simulation enthusiasts.
- huhtenberg 2y agoThanks, but that's not the one.
- p0w3n3d 2y agoMy beloved was a little bit newer DOS game F22 Lightning II. The best memories I have from it are when I was cycling through targets, and there was Air Force One which we were escorting. And just because I had armed missiles, AWACS detected radio pulses on the Air Force One, and every other aircraft in the air shot a missile on my machine. This caused first of all my computer to lag, then "incoming missile" from the speaker repeated hundred times, and after that I saw an animation of all the other missiles flying through the remains of my plane. Wonderful experience
- Arrath 2y agoOh man I loved that game.
- LowLevelMahn 2y agoThere is a discord chat (by the author) for technical discussion: https://discord.com/channels/819897993624682516/1155564470828007434 https://discord.com/channels/819897993624682516/115556447082...
- Vistoad 2y ago[flagged]
- Vistoad 2y agoThanks for sharing this. https://leecountypropertyappraiser.site/ https://leecountypropertyappraiser.site/
- litenboll 2y agoNot this game, but DOS game + reconstruction made me think about something from my childhood. I used to get around 1h of Internet time (modem) per week. I used this to download stuff that I could use for the rest of the week. One time I started downloading a game, but a bit too late so I never got to finish the download before my time was up. Of course the game would not work as it was only partially downloaded (IIRC it was a zip file, but not 100% sure). There was some message from Windows telling me that there was something wrong with the exe. But I continued trying to open the game over and over again (maybe fiddled with the properties?) and one day it magically started, ran for a while and then crashed. It was possible to restart it, but it would crash at the same point every time. It's still a mystery how it was possible, I guess it only had "content" left and the exe itself was fine, but that doesn't really explain why Windows initially refused to start it.
- dreadnaut 2y agoThe page "What does it take to take an old game apart? (Part 3)" mentions the 'restunts' project to reverse-engineer Stunts / 4d Sports Driving, and finding limited information about it. There's actually a small group working on it, and more details here: https://forum.stunts.hu/index.php?board=90.0 https://forum.stunts.hu/index.php?board=90.0 Disclosure: I manage the forum where the discussion is happening, I'll need up my SEO if the author could not find it :P
- herio 2y agoI love the inconsistency between "I don't have time to learn DCS" and "so I'll spend two years reverse engineering an old DOS game instead" :) Good articles, I agree that there isn't enough technical articles about reverse engineering like this, it's an interesting hobby.
- maupin 2y agoAccidentally read the last post first. My mind immediately jumped to copy protection as the purpose for that large nonsensical routine.
- iancmceachern 2y agoAnyone remember the movie "Iron Eagle"?
- LowLevelMahn 2y agoim not the author of these blogs but love to read his tales of reconstructing the C code part by part using IDA/Ghidra and some of his own tools - maybe others are interested in reading too :) read from bottom up
- dang 2y agoNormally we'd suggest picking the most interesting article from the list, but given that there's a clear sequence here, I think this submission is ok. For people who want to start at the beginning: https://neuviemeporte.github.io/f15-se2/2022/06/05/origins.html https://neuviemeporte.github.io/f15-se2/2022/06/05/origins.h... The most recent article in the sequence is interesting own its own: https://neuviemeporte.github.io/f15-se2/2024/05/05/ghidra.html https://neuviemeporte.github.io/f15-se2/2024/05/05/ghidra.ht....