Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Flash page map

This page maps the contents of all 64 physical 16 KiB Flash pages. OS code occupies pages 00–07 and 33–3D; page 2F contains retail USB boot support, page 3E holds two certificate sectors, and page 3F is the retail boot page. Pages 08–2E and 30–32 are blank in this image. [confirmed]

On a retail unit, the blank range stores archived variables and can carry Flash Apps. Flash memory describes physical erase-sector geometry and the dynamic archive/App boundary. The page roles below use resolved bcall targets. Counts are main-table rows in tools/symbols/bcall_targets.txt, including aliases and inferred names; they are not recovered function counts.

OS pages (carry bcall entry points)

PageMain-table rowsRoleRepresentative routines
00297Kernel — mapped at 0x0000; RST vectors, bcall dispatcher, FP core, VAT, memory, integer math_JErrorNo, _LdHLind, _DivHLBy10, _FindSym, _FPAdd, _InsertMem
0131Text display / homescreen_PutMap, _PutC, _PutS, _DispHL, _NewLine, _ClrLCDFull
0276Float transcendentals & advanced math_SqRoot, _LnX, _RnFx, _RndGuard
038Edit-buffer / small font_CloseEditBufNoR, _Load_SFont, _SFont_Len
0438Graph drawing (pixel/line)_DarkLine, _ILine, _IPoint, _DarkPnt
055TABLE editor + Graph-Table split-screentable_editor_main, table_recompute, table_paint_grid
0612Key input & edit/cursor_GetKey, _CursorOn, _CursorOff, _PutTokString (note _GetCSC’s body is on page 00)
0724Archive / list & matrix ops; error messages; large-font glyph table @ 07:45FF (7-byte stride) read by put_glyph_large (07:4588)_Arc_Unarc, _CleanAll, _RedimMat, _IncLstSize, put_glyph_large
3328Graph coordinate math and programmable timer API_SetXXOP1, _UCLineS, _InitTimer, _StartTimer, timer_irq
3614Mode setters (Func/Param/Polar/Seq)_SetFuncM, _SetParM, _SetPolM, _SetSeqM
3730Graph coordinate conversion, RTC, and date/time formatting_XftoI, _YftoI, _getDate, _getTime, rtc_read_seconds
3826TI-BASIC parser / evaluator_ParseInp, _Find_Parse_Formula, parse_init
395Equation pretty-printer (2D MathPrint layout) + menuseqdisp_render_entry, eqdisp_emit_glyph, _DispMenuTitle
3A4Statistics (1/2-var, regressions); some iterative numeric callers remain unmapped_OneVar, reg_gauss_solve, numeric_iterate_64
343Token/parser scanning_AHEADEQUAL, _PARSAHEADS, _PARSAHEAD, parse_scan_table
353USB controller paths, memory-reset engine, factorialusb_timeout_irq, mem_reset_dispatch, ram_reset_wipe, op1_factorial
3B24bcall jump table + mem utils(table data) _MemClear, _MemSet, _DrawCirc2
3C10Link / variable transfer_SendAByte, _RecAByteIO, _SendVarCmd, _Rec1stByte
3D7App management & Flash_FindApp, _FindAppUp, _FindAppDn, _FlashToRam

Blank, boot, and system pages

The complete 1 MiB image contains no 80 0F Flash App header at any byte offset, including its 64 page boundaries. The image therefore contains no bundled Flash App. [confirmed]

Byte-level notes on the empty page range and the boot/system pages, some of which also carry the bcalls listed above:

PageVerified contents
08–2E, 30–32Blank or unused in this OS image — 100% 0xFF in tools/rom.bin. No app headers.
2FRetail USB boot support installed from the checksum- and hash-validated local D84PBE2.8Xv. This installation changes 8,615 bytes of the pinned base. The page-3F boot table maps _AttemptUSBOSReceive, _ReceiveOS_USB, _USBErrorCleanup, _InitUSB, and _KillUSB here; tools/rom.bin contains the payload and tools/symbols/bcalls8x_targets.txt records their bodies. [confirmed]
34–39More OS code (parser scan, USB, graph, mode, menu, and RTC); approximately 0.2–17.3% of each page’s bytes are 0xFF.
3Bbcall jump table — starts 99 27 00 = entry 0 (_JErrorNo → ram:2799).
3CLink code, archive garbage collection, and the OS version string — page starts with ASCII 32 2E 35 35 4D 50 = "2.55MP"; archive_gc_collect is at 3C:7733.
3ECertification page and GC journal — two physical 8 KiB sectors. _GetCertificateStart (ID 8057h) selects the active half; _GetCertificateEnd (ID 802Dh) bounds it; _FindFirstCertField (ID 8027h) and _FindNextCertField (ID 8078h) walk TLV fields. GC transactionally copies the used tail through the inactive half and stores phase bytes near its end. [confirmed]
3FRetail boot page — the pinned base matches the checksum- and hash-validated local D84PBE1.8Xv payload byte for byte; starts 3E 07 D3 04 3E 7F D3 06 3E 03 D3 0E C3 2C 81, carries boot version 1.03, and hosts the boot bcall table. Boot and hardware-version bcalls resolve to _getBootVer (ID 80B7h, body 3F:477C) and _getHardwareVersion (ID 80BAh, body 3F:4781). [confirmed]

The large-font glyph table is on Flash page 07; see Display and LCD. Alternate large fonts live on Flash pages 01 and 36, selected by IY+0x35 bits 5 and 1. Flash page 07 contains archive code, list and matrix code, error messages, and the large font. [confirmed]

Page specialization

Related routines often share a page, but subsystem boundaries cross pages. For example, graph rendering uses pages 04, 33, and 37, and page 07 combines VAT services with glyph data. The bcall and bjump mechanisms connect these routines across the fixed and banked windows.