Programmatic C64 analysis and system emulation

Analyze C64 software.Inspect cycle-level behavior.

TREX64 combines three tools. TRX64 provides cycle-accurate C64, 1541, and 1581 emulation with rewind and JSON-RPC control. C64RE imports deterministic analysis into a persistent typed 6502 graph, provides pre-edit impact queries, and verifies rebuilt output byte for byte. External LLM agents query the graph through MCP and add semantic annotations and evidence. The C64U / UE2 Emulator provides the Ultimate target environment for firmware validation and Made for Ultimate software development: unmodified firmware, UCI, turbo modes up to 64 MHz, Ultimate Audio, and modeled board hardware backed by TRX64.

Semantic analysis / C64RE

Build an evidence-linked 6502 analysis graph.

C64RE imports deterministic reports to build typed control-flow and memory-access relations and infer routine contracts. Agents add semantic annotations; reassembly verifies output byte for byte.

System / C64U / UE2 Emulator

Develop and test for the Ultimate platform.

UE2 runs unmodified firmware and C64 software that uses UCI, turbo modes, REU, Ultimate Audio, and other C64U-specific interfaces. MCP, scripts, REST, and CI provide control.

Emulation runtime / TRX64

Run and inspect a reversible C64.

TRX64 emulates the C64, 1541, and 1581 with cycle-accurate execution, rewind, headless operation, and JSON-RPC control.

6510 · VIC-II · SID Rewind JSON-RPC Shared sessions

01 / Interfaces

Each component exposes its primary functions through a machine-callable interface.

C64RE uses MCP and calls the TRX64 daemon for runtime evidence. TRX64 exposes JSON-RPC and an embeddable Rust core. The C64U / UE2 Emulator embeds that core and adds MCP, REST, scripts, and headless control.

C64RE / MCP

An external LLM drives the C64RE workflow through MCP.

The agent instructs C64RE to extract media and run deterministic analyzers, queries the resulting typed 6502 graph, reads complete listings, writes semantic annotations, and records evidence.

TRX64 / JSON-RPC + Rust core

Daemon and embedded clients use one runtime implementation.

The CLI, C64RE, scripts, and agents control a reversible session through JSON-RPC. The C64U / UE2 Emulator links the Rust core directly.

C64U / UE2 / MCP + control

Agents test firmware and Made for Ultimate software locally or in CI.

Automation boots firmware, loads C64 software, sends UI and C64 input, inspects video and UART state, calls REST services, asserts results, and shuts down the instance.

02 / Components

TRX64 runs the C64; C64RE records analysis and evidence; the C64U / UE2 Emulator provides the Ultimate target environment.

TRX64 does not own the reverse-engineering analysis pipeline. C64RE contains no emulator and uses the TRX64 daemon when static evidence requires runtime validation.

TRX64 showing C64 output beside its terminal cockpit
C64 display and TRX64 CLI cockpit

01 · Runtime / TRX64

Run, inspect, and rewind a cycle-accurate C64.

TRX64 is a Rust runtime for the C64, 1541, and 1581. The CLI, JSON-RPC daemon, and embeddable library use one command-dispatch path.

  • Rewinds execution, reverse-steps, identifies the last writer to an address, and diagnoses JAM states
  • Runs PAL, NTSC, or PAL-N with disks, cartridges, drives, and expansions
  • Allows a user, a script, and an LLM agent to share one live session
6502 disassembly with semantic labels in C64RE
Semantically annotated disassembly and verified source

02 · Knowledge / C64RE

Generate source and a typed 6502 analysis graph from C64 media.

C64RE is an MCP workbench for media extraction, deterministic disassembly, typed graph construction, semantic annotation, pre-edit impact queries, and byte-for-byte comparison of rebuilt output with the imported artifact. A user defines the objective; an external LLM agent reads complete listings, labels segments and routines, and records evidence.

  • Extracts PRG, CRT, D64, and G64 inputs and runs nine deterministic analyzers in parallel
  • Builds typed relations from routine and label nodes to address, zero-page, ROM, and hardware-register nodes for calls, jumps, branches, memory accesses, and pointer references
  • Computes routine contracts: inferred inputs and outputs, clobbers, preserved registers and flags, stack effects, call-site arguments, and unresolved exits
  • The change_impact query reports incoming control flow, shared-state dependencies, claims affected by the change, inferred state-preservation requirements, and unresolved control-flow paths
  • External LLM agents classify segments, name routines, explain control flow, and connect artifacts
  • Stores findings, supporting evidence, artifact lineage, control-flow and memory-access relations, and open questions; re-analysis does not overwrite human assertions
  • Reassembles with KickAssembler or 64tass and compares output with the imported artifact byte for byte; annotations do not modify output bytes
Ultimate file browser running in the C64U / UE2 Emulator
Ultimate target: firmware, UCI, and C64 software on TRX64

03 · Ultimate target / C64U / UE2

Develop firmware and Made for Ultimate software on an emulated target.

C64U / UE2 combines unmodified Ultimate 64 Elite II or C64 Ultimate firmware, modeled board hardware, and the TRX64 core. C64 programs can use UCI, the Ultimate speed registers, REU, Ultimate Audio, and other C64U-specific interfaces. The system runs interactively, headlessly, or under CI.

  • Implements UCI register windows and the unmodified firmware command targets used by Made for Ultimate software
  • Provides C64U turbo modes up to 64 MHz, REU, GeoRAM, UltiSID, and Ultimate Audio
  • Models two 1541/1581 drives, Software IEC, 28 cartridge types, and the expansion slot
  • Implements SD and USB storage, networking, REST services, a web UI, FTP, Telnet, GDB, scripts, and MCP
  • Lets an agent boot firmware, load C64 software, send input, inspect video and UART state, execute tests, and terminate an isolated system instance

C64RE / Analysis output

C64RE imports each deterministic analysis report into a persistent typed graph of 6502 code and data.

Deterministic results and human assertions are stored in separate layers in knowledge/graph.sqlite. Applied semantic annotations are stored in the human layer and retained across re-analysis. Trace imports add observed execution and memory-access edges without replacing static evidence. MCP tools resolve nodes, traverse typed edges, find control-flow paths, and execute impact queries against the same graph.

01 / Typed relations

Model control flow, memory access, and machine resources.

The graph stores routine, label, address, zero-page, ROM, and hardware-register nodes. Typed edges represent calls, ROM calls, jumps, branches, reads, writes, indirect accesses, and pointer references. Artifact, cartridge-bank, and drive-CPU identifiers distinguish identical 16-bit addresses. Each edge stores supporting evidence and a confidence value.

02 / Routine contracts

Infer routine contracts from 6502 code.

C64RE infers inputs, outputs, clobbers, preserved registers and flags, stack effects, call-site arguments, patched operands, and unresolved exits. Analysis includes known ROM ABIs and recursive call relationships; unresolved callees leave contracts partial.

03 / Change impact

Identify affected code and state before changing bytes.

change_impact traverses incoming call, jump, and branch edges; identifies readers of written addresses and references through pointer and jump tables; and finds claims that may be invalidated. It reports inferred state-preservation requirements. If trace data is available, the report includes observed raster-line timing, worst observed line occupancy, and remaining margin. Unresolved indirect jumps, self-modifying-code paths, and drive-CPU paths are reported as UNKNOWN rather than low risk.

Graph views: force-directed layout · structural layers · concentric rings centered on a selected node · address axis with one lane per bank

03 / C64RE workflow

Five project stages. Seven per-artifact analysis phases.

The human defines the objective and approves decisions. An LLM agent invokes C64RE through MCP, interprets the resulting evidence, and persists project knowledge. C64RE performs deterministic analysis and byte comparison. TRX64 supplies runtime evidence for hypotheses derived from static analysis.

01 / ONBOARDING

Initialize the project

Create or resume the project, record the human objective, and select a workflow profile.

02 / DISCOVERY

Inventory media and loaders

Extract and register every payload, analyze the loader and packer chain, and map medium locations to load addresses.

03 / REVERSE ENGINEERING

Analyze and annotate payloads

Generate deterministic first-pass source and import its analysis report into the typed 6502 graph. Inspect each non-trivial segment, add semantic annotations, connect artifacts, and validate each interpretation against recorded evidence.

04 / BUILD

Produce modified artifacts

Run change_impact before changing bytes. Apply patches or implement the target medium, loader, or feature; record the rationale, modified byte ranges, and validation evidence.

05 / RELEASE

Test and release

Run local and external tests, record known issues, create release candidates, and package the final artifact with its documentation.

Per-artifact analysis phases

Phases 1–2 run during Discovery. Phases 3–7 run during Reverse Engineering. Each phase has an explicit completion criterion.

DiscoveryPhases 1–2
01

Extraction and Inventory

Extract payload bytes and register every source and generated artifact. Complete when no visible payload remains unregistered.

02

Loader / Load Behaviour / Sequence

Statically disassemble and annotate loader and drive code. Record entry points, load contexts, and the flow to runtime addresses.

Reverse EngineeringPhases 3–7
03

Heuristic Disassembly

Run deterministic analysis and import the report into the typed 6502 graph. Generate first-pass source for KickAssembler and 64tass without semantic annotations, then attempt a rebuild.

04

Segment Analysis

The LLM agent inspects each non-trivial segment, classifies it from static evidence, or records an open question.

05

Semantic Analysis V1

The LLM agent proposes labels, routine explanations, and segment annotations. After application, C64RE stores them in the human graph layer, re-disassembles the artifact, and compares rebuilt output with the imported artifact byte for byte.

06

Meta Connections

The LLM agent links entities and records cross-artifact relations and flows. C64RE preserves artifact lineage and refuted hypotheses.

07

Semantic V2

Refine annotations with project-wide context, perform final rebuild verification, render documentation, and complete the artifact checklist.

Static evidence first. Read bytes and loader code before requesting runtime evidence. Semantic interpretation. The LLM records names, explanations, relations, and open questions. Targeted runtime validation. TRX64 supplies evidence for a stated address-level hypothesis; the agent records whether the evidence confirms or refutes it. Byte verification. KickAssembler or 64tass rebuilds the source; byte comparison determines equality.
04 / Install and run

Install and run the tools.

C64 ROMs, Ultimate firmware, and third-party media are not distributed with these projects. Supply files from legally obtained copies.

TRX64 / macOS

Install and open TRX64

Homebrew installs trx64cli and trx64-daemon. Place C64 ROMs in ~/.trx64/roms or pass --rom-dir.

$ brew install jondalar/tap/trx64
$ trx64cli --window
All platforms ↗

C64RE / npm · Node 22+

Install C64RE and its runtime

npx fetches the MCP server @trex64/c64re on first use. runtime install downloads the pinned TRX64 daemon and verifies its checksum. The MCP client runs npx -y @trex64/c64re with C64RE_PROJECT_DIR set. ui serves the workbench on 127.0.0.1:4310.

$ npx -y @trex64/c64re --help
$ npx @trex64/c64re runtime install
$ npx -y @trex64/c64re ui --project <dir>
Install guide ↗

C64U / UE2 · macOS

Install and configure UE2

Create a flash image from update.ue2, supply the roms directory from a 1541ultimate checkout, and start the firmware.

$ brew install jondalar/ue2emu/ue2emu
$ ue2emu install --update update.ue2 --flash flash.bin --roms 1541ultimate/roms --yes --c64-roms
$ ue2emu run --firmware update.ue2 --flash flash.bin --roms 1541ultimate/roms --net user
Getting started ↗