6 ms·
Notes on the Pentium's microcode circuitry
- mmastrac 2y agoI'm surprised the microcode ROM and format hasn't been dumped already. Is anyone working on this? EDIT: The later Atom processors were dumped, are there any similarities? [1] https://x.com/_markel___/status/1262697756805795841 https://x.com/_markel___/status/1262697756805795841 [2] https://github.com/chip-red-pill/glm-ucode https://github.com/chip-red-pill/glm-ucode EDIT 2: Some Pentium Pro disassembly work: https://pbx.sh/pentiumii-part2/ https://pbx.sh/pentiumii-part2/
- kens 2y agoThere are some people working on the 386 microcode. Dumping the Pentium microcode ROM from the die photos would be straightforward (but tedious). The hard part is to figure out what all the bits mean.
- mmastrac 2y agoAny ideas if the mask ROM is scrambled? Apparently the P6 doesn't have a direct mask ROM : microcode relationship. https://github.com/peterbjornx/p6tools https://github.com/peterbjornx/p6tools
- kens 2y agoThe Pentium's ROM appears to be slightly scrambled (see footnote 6 in my article). ROMs are often a bit permuted for electrical reasons. For example, instead of columns ordered ABABABAB..., they will be ordered ABBAABBA... and then the A and B select lines can be shared by two columns. But the columns in the Pentium appear to be permuted in an irregular way. I'm not sure if this was for obfuscation or if automated layout software decided this was better.
- mmastrac 2y agoI'm curious if the register you see near the microcode ROM is potentially hooked up to MSRs -- it could potentially be a read or write buffer. https://www.cs.cmu.edu/~ralf/papers/highmsr.html https://www.cs.cmu.edu/~ralf/papers/highmsr.html > To the left of the MAR is a 32-bit register that is apparently unrelated to the microcode ROM, although I haven't determined its function.
- kens 2y agoThat register could be a Model-Specific Register; I haven't looked at it closely enough to see what it does. The Pentium is very complicated with 3.1 million transistors, so my reverse-engineering of it is essentially bits and pieces here and there.
- eigenform 2y ago> are there any similarities? Don't know about the format, but if you look thru old ITJ articles[^1], it seems like the "direct access" interface for reading out different memories exists on older Pentium parts too. Presumably, if it were possible to dump over JTAG, it would be at least a little bit similar to what Peter/Mark have already looked at on newer parts. [^1: https://www.intel.com/content/dam/www/public/us/en/documents/research/1998-vol02-iss-2-intel-technology-journal.pdf https://www.intel.com/content/dam/www/public/us/en/documents...
- devcoder78 2y ago[dead]
- dev_john15 2y ago[dead]
- Aardwolf 2y agoI would love to know how multiplication and division work in modern chips to have such low cycle count compared to addition, since in theory the addition complexity is linear in the amount of bits but multiplication and division are quadratic, or loglinear for large inputs. Part of that is solved by surface area rather than time I guess, but that's also true for the adders already with the carry logic
- RiverCrochet 2y agoI remember reading somewhere--memory is hazy--that at least division uses a partial look up table, kinda like how you'd do it in 6502 assembly back in the day. E.g., if you have to multiply something by 5, and you can get the range of inputs down to something reasonable, then you can just have a table of x*5 for that range and just look it up. Also I'm not sure multiplication/division are quadratic if your algorithm is not "add X to itself Y times." Look at this for 6502 16-bit multiply - https://www.llx.com/Neil/a2/mult.html https://www.llx.com/Neil/a2/mult.html - it's dependent on the bit width, not the value of the multiplier/cand. Of course this is for integers, not floating point.
- kens 2y agoI'm working on the multiplication circuit in the Pentium; I've done a partial writeup: https://www.righto.com/2025/03/pentium-multiplier-adder-reverse-engineered.html https://www.righto.com/2025/03/pentium-multiplier-adder-reve... The short answer is that multiplication uses a large tree of adders so it can add up all the long-division terms at once. It also uses base-8 for the multiplier to reduce the number of terms. The adders are 4:2 carry-save compressors that take four numbers as inputs and produce two numbers as outputs. I also wrote about the Pentium's division circuitry and the infamous FDIV bug: https://www.righto.com/2024/12/this-die-photo-of-pentium-shows.html https://www.righto.com/2024/12/this-die-photo-of-pentium-sho... The short answer is that the Pentium used base-4 SRT division, similar to long division but generating two bits of result per cycle. It used a lookup table to determine the two quotient bits; an error in this table resulted in the bug.
- kens 2y agoAuthor here for your Pentium questions :-)
- mesrik 2y agoHi Ken, Nice article. While reading I remembered that I watched some time ago the Oral History of Gary Davidian and he was quite bit involved with microcoding. And if I were you I would try asking him if he could be able to give you some ideas where to get more information about microcode workings and development. Here are links to that interview, if you have time to watch it. It's in two parts. - https://www.youtube.com/watch?v=l_Go9D1kLNU https://www.youtube.com/watch?v=l_Go9D1kLNU - https://www.youtube.com/watch?v=MVEKt_H3FsI https://www.youtube.com/watch?v=MVEKt_H3FsI Cheers, :-) riku
- nxobject 2y agoThis is the Gary Davidian of the Classic MacOS PPC nanokernel, no? I wish I've had as much fun work as he's had in his career.
- klelatti 2y agoAlso the Gary Davidian of Intel vs NEC fame! https://thechipletter.substack.com/p/intel-vs-nec-the-case-of-the-v20s https://thechipletter.substack.com/p/intel-vs-nec-the-case-o...
- vitalmixofntrnt 2y agoCan I add my own instruction set extensions to the original x86 isa as implemented by the 8086 without permission from Intel and / or AMD as long as I'm not copying any x86 instruction set extensions?
- kens 2y agoI don't know the legal details here but I think you can do whatever you want as long as you're not violating any patents (good luck). Also, Intel claims a copyright on the mnemonics for 8080 and 8086 assembly language. Microcode is also protected by copyright.