Live data from Hacker News

Full Reverse Engineering of the TI-84 Plus Operating System

siraben.github.io

11–20 of 28 posts

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#11
post #5

I couldn't tell, is a person doing this? or was this an LLM dissecting it?

This was made collaboratively by me directing coding agents at the binary, using Ghidra MCP extensively, disassembly and also dynamic analysis with an emulator. I don't have a writeup of the process but it was definitely not fully automatable (I wish though). I might prepare a blog post with transcripts and session history and things I learned along the way. Broad takeaways: - Ghidra MCP is not a silver bullet. Lots…

Do you have plans to generate a buildable version of the sources, and do you know the original implementation language (C?).

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#12
post #5

Earlier quoted context omitted.

This was made collaboratively by me directing coding agents at the binary, using Ghidra MCP extensively, disassembly and also dynamic analysis with an emulator. I don't have a writeup of the process but it was definitely not fully automatable (I wish though). I might prepare a blog post with transcripts and session history and things I learned along the way. Broad takeaways: - Ghidra MCP is not a silver bullet. Lots…

Do you have plans to generate a buildable version of the sources, and do you know the original implementation language (C?).

It's highly likely that the original implementation language was assembly. The code is very idiomatic.

Regarding source build, I think reverse engineering it to the point where you can reconstruct the source is possibly legally problematic, so I don't plan to do this, but maybe for certain subsystems like MathPrint (equation display) which was especially fun to RE. I have a PR up for it and it will be live at

https://siraben.github.io/ti84p-re/mathprint

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#13
post #10

Earlier quoted context omitted.

how much have you spent so far on this (for tokens)?

The plans are heavily subsidized by the AI companies so I didn't end up needing to do API usage or buy another subscription. I have ChatGPT Pro and Claude Code Max.

[flagged]

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#14
post #13
post #10

Earlier quoted context omitted.

The plans are heavily subsidized by the AI companies so I didn't end up needing to do API usage or buy another subscription. I have ChatGPT Pro and Claude Code Max.

[flagged]

That's not at all how that works

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#15
post #12

Earlier quoted context omitted.

Do you have plans to generate a buildable version of the sources, and do you know the original implementation language (C?).

It's highly likely that the original implementation language was assembly. The code is very idiomatic. Regarding source build, I think reverse engineering it to the point where you can reconstruct the source is possibly legally problematic, so I don't plan to do this, but maybe for certain subsystems like MathPrint (equation display) which was especially fun to RE. I have a PR up for it and it will be live at https:/…

Typically the approach taken by people who are concerned about legal issues regarding disassemblies is that they distribute a script file that contains all the code/data annotations, comments, variable names, and labels, and then the user can feed this file and a copy of the original binary into the disassembler to reproduce the disassembly. Here's a random example for a 6502 codebase: https://github.com/TakuikaNinja/FDS-disksys . IDA Pro has this functionality built in, you can export a .idc script file that will reproduce the .idb file if you load the original binary into a fresh instance of IDA Pro and then run the script. Maybe Ghidra has something similar, if not I bet you can get your AI to write export/import scripts for Ghidra.

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#16
> TI-BASIC programs are stored as tokens, not text: every command, function, and variable is a token of 1 or 2 bytes. The OS detokenizes (token→display string) to show a program and tokenizes (keypress/text→token) on entry; the parser walks tokens to execute.

From my memory of using a TI-83 in the late 90s, I would not be surprised if the keypad UI injects tokens directly based on your keypress, rather than "tokenizing the text". I seem to recall, for example, you could not position the cursor in the middle of a BASIC token, and if you managed to type out the tokens it would not work; you needed to find the right menu item to inject the correct token.

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#17
post #5

I couldn't tell, is a person doing this? or was this an LLM dissecting it?

This was made collaboratively by me directing coding agents at the binary, using Ghidra MCP extensively, disassembly and also dynamic analysis with an emulator. I don't have a writeup of the process but it was definitely not fully automatable (I wish though). I might prepare a blog post with transcripts and session history and things I learned along the way. Broad takeaways: - Ghidra MCP is not a silver bullet. Lots…

Having just recently heard about Ghidra and started using it with Claude. I am absolutely blown away how little resistance it has decompiling old Win95/98 binaries. It's turning into a bit of a hobby of mine to take old software, decompile and find hidden treasures like images or messages.

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#18

> TI-BASIC programs are stored as tokens, not text: every command, function, and variable is a token of 1 or 2 bytes. The OS detokenizes (token→display string) to show a program and tokenizes (keypress/text→token) on entry; the parser walks tokens to execute. From my memory of using a TI-83 in the late 90s, I would not be surprised if the keypad UI injects tokens directly based on your keypress, rather than "tokenizi…

I can confirm that. On the TI-83, many of the TI-BASIC tokens contained lowercase characters which couldn't be typed at all - you could only type uppercase letters on the keyboard. (There were a few lowercase letters available as tokens for special purposes, but it wasn't a full set.)

Interestingly, you could print tokens in strings - e.g. you could Disp "Disp ".

Re: Full Reverse Engineering of the TI-84 Plus Operating System

#20

I couldn't tell, is a person doing this? or was this an LLM dissecting it?

> Confidence is flagged: ..... > The big picture > The structural reverse-engineering is comprehensive (every subsystem mapped, both cross-page mechanisms resolved ... > Confidence summary / open items Probably an LLM wrote the docs. > (the GhidraMCP plugin reconnects for interactive work) Probably LLM+Ghidra for the actual RevEng. Ultimately does it matter if the end product is works though

I think it’s fine as long as it works. Personally I prefer doing everything manually because that’s where the fun is, but everyone has their own fun.
Post reply on HN