A playground, not yet a page

The NES at human speed

Everything a Nintendo does to put one picture on a television happens in 16.6 thousandths of a second. Here is the console the engineers rebuilt from the chips’ own transistors, running in this page, slowed down until you can watch it think.

Waking the console up...

Line
·
Dot
·
Beam
·
Into the frame
·
One dot lasts
·
Slower than real
·

Every hue at one brightness, the brightness stepping every few seconds. Nobody's game: we wrote it to test the picture.

Start here

A guided tour

This page is a workshop, not a book: the pieces are in no particular order, and any of them can be poked at on its own. If you would rather be shown around, this is one path through them.

It starts with a picture on a television and ends inside a single chip, with a line at each stop saying what to look at. A bar follows you down the page while it runs, and you can leave it whenever you like.

About twenty minutes, in this order, from a television picture to a single transistor. You can leave it at any point and come back.

The wire

A picture is one long wiggle

The NES never sends a picture to the television. It sends one wire’s worth of voltage that rises and falls, line after line, and the television rebuilds the picture from it. Click any line of the frame above and this is that line, exactly as the console’s model encodes it.

The deep dip is the sync: the television’s cue to start a new line. The little wave after it is the colour burst, a metronome the television tunes to. Then the picture: how high the wire sits is how bright a dot is, and the fast wiggle on top carries its colour.

Encoding the frame...

The colours

Every colour is a timing

The NES has a fixed set of colours: a handful of brightnesses, each crossed with every hue. Each colour here was made by the console’s model and decoded by our model of a television, just now, in your browser. None of them came from a chart.

Pick one. The wire swings up and down at the colour burst’s own beat, and the only thing that changes the hue is when it swings. The clock face shows how far each colour’s swing runs ahead of the burst: every hue has its own hour on the clock.

Measuring the colours...

A real game

Where Super Mario Bros. spends a frame

The engineers ran Super Mario Bros. on the model and wrote down, for one ordinary frame, what the processor was doing while the beam was at each point on the screen. This map is their table, painted onto the frame.

The surprise is the grey: most of the time, the game is doing nothing at all. It finishes its work early and waits. The top of the picture is spent waiting for the beam to pass the status bar, so the score can stay still while the level scrolls underneath.

Waiting for the console to report the frame's shape...

The controller

Eight buttons down one wire

Inside the pad is one small chip that takes a snapshot of all eight buttons when the console asks, then hands them over one at a time, a bit per tick, down a single wire. Hold some buttons, on screen or on your keyboard with the frame above focused, and watch a read.

A pressed button reads as a zero on the wire. The console flips it back.

Tap to hold a button down; tap again to let go.

Inside the pad: the snapshot

  1. A
  2. B
  3. Select
  4. Start
  5. Up
  6. Down
  7. Left
  8. Right

Inside the console: the byte

  1. A
  2. B
  3. Select
  4. Start
  5. Up
  6. Down
  7. Left
  8. Right

Ready.

Spot the difference

One button, one frame

Two consoles, the same cartridge, the same buttons, frame for frame. They are the same machine running the same program, so their pictures are the same. Now tap one button, for one frame, in one of them only.

Whatever differs from then on is that tap’s doing, and nothing else’s. Sometimes the two pictures come back together a moment later; sometimes they never do. This is how the engineers find out what a game does with a button, with no source code at all: they run it twice and look for the difference.

On the calibration cartridge the buttons are printed in its strip of black and white blocks, two frames after they were read. Watch for the block that lights, and how long it stays.

Waiting for the console to report the frame's shape...

Your own game

X-ray something you own

The same trick, on a cartridge of your own. Play for a while: the page writes down which buttons you held on every frame, exactly as the engineers’ bench writes down a run. Then ask it to x-ray a tap at the moment you stopped.

Both consoles replay everything you played, from the moment they were switched on, and one of them gets one extra tap. Anything they differ by after that is that tap’s doing, and the report says when the pictures first parted, where on the screen, how far apart they got and whether they ever came back together.

The cartridge is read in this browser and goes nowhere else.

Waiting for the console to report the frame's shape...

The sound

Five voices, one chip

All the NES’s music comes from five voices inside the processor chip: two squares, a triangle, a noise maker and a player for recorded samples. A game makes music by writing a few numbers into the chip every so often: which note, how loud, what shape.

Here you write those numbers by pressing keys. This is the engineers’ model of the sound hardware, built from measurements of the real chip’s transistors, playing in your browser. Each voice is drawn as the chip produces it, and its pitch is measured from that drawing, not assumed.

Mute a voice and listen to the others change slightly: the chip does not simply add its voices together. That mixing is written from the NES community’s published table, and the engineers mark it as a claim they have not yet measured on their own console. The steady offset the chip’s pins sit at is taken out before your speakers.

Waiting for the console to report its clock...

The slow chip

Every transistor, switching

Before the engineers wrote a fast picture chip, they built a slow one: a simulation of every transistor on the real chip’s silicon, switching on and off exactly as the photographs of the die say they are wired. Here it is, running in your browser, drawing the engineers’ test scene one dot at a time.

Beside it is their fast chip’s picture of the same scene. The fast one has to agree with the slow one on every single dot, and this page checks it as you watch. The lamps are the chip’s own wires: its dot and line counters counting in binary, and the colour leaving the chip.

The bars at the bottom are how many transistors change state for each dot. The chip fetches a new tile every few dots, and you can see its rhythm.

The slow chip: every transistor, simulated
The fast chip: the same frame, all at once

Waking the chip...

Line
·
Dot
·
Dots drawn
·
Agree with the fast chip
·
Differ
·
Alignment
·
Dots a second, here
·
Slower than the real chip
·
Transistors switched, this dot
·
Dot counter·
Line counter·
Colour out·
Clocks and bus

Transistors switched per dot, the last two lines

The die

The chip itself, lit up

This is the picture chip’s own silicon: the shapes traced from photographs of a real chip with its casing removed, which is where every one of these models came from in the first place. The wires that are carrying a signal right now are lit, as the transistor-level chip runs in your browser.

Point at anything to see which wire it is. Many of them have names, given by the people who traced the photographs, and those names are what the engineers’ reports talk about when they say a signal rose or a latch held.

The colours are the layers: the metal on top, the silicon underneath, and the switching layer between.

Drawing the die's shapes...

  • metal
  • diffusion
  • diffusion, to ground
  • diffusion, to the supply
  • polysilicon
  • high right now
The wire under the pointer
·
Its level
·
Wires high now
·
Half-steps run
·

The encyclopedia

Tricks every game uses

Taking games apart, the engineers keep finding the same tricks: the same few ways of reading the pad, switching memory, keeping time and changing the picture without tearing it. They are writing them down as an encyclopedia of code patterns.

Each picture here is one entry’s mechanism, drawn by us and moving. They are sketches, not recordings: no address or number in them is the game’s. The entry’s own words are beside each, and the full entry, with everything the engineers measured, is one click away.

Entry 1

The poll routine

in the pad: A and Right heldABSelStaUpDnLtRta byte of memory, filling from the leftread 1 of 8: A

Watch the buttons leave the pad one at a time and walk into a byte of memory, the newest on the left, until the whole pad fits in one number.

What it does, in the entry's words: Reads the controller: strobe the shift register (a 1 then a 0 to $4016), then read $4016 eight times, each read one button on D0, shifting the bits into a RAM byte.

Read entry 1 in full

Entry 2

The bank switch: a menu's Start

the cartridgethe menuthe first gamethe switchwritten0000ROM byte here0000so it stores0000andpicture onStart is pressed on the menu

Watch the order: the picture goes off, then the write. On this kind of cartridge a write is combined with the byte already stored at that spot, so the menu writes somewhere that byte already matches.

What it does, in the entry's words: A multicart's menu polls the pad, and on Start turns rendering off, writes the game's bank into the mapper's register and starts the game from its reset vector. The bytes are a commercial cartridge's, so this entry is shape only: addresses, counts, event kinds, and what the x-ray reported with every fetched byte masked.

Read entry 2 in full

Entry 3

The game loop inside the interrupt

the blankmain programjumps to itself, foreverthe interrupt handlerthe whole gamethe handler works, then goes back to sleep

Watch the main program do nothing, and the whole game happen when the blank taps the processor on the shoulder. On the second frame the game runs long, so the next tap is simply skipped.

What it does, in the entry's words: The main program spins on one instruction; the whole game runs in the NMI handler, which turns NMIs off at its entry and on before its RTI, so a long frame is dropped and never re-entered.

Read entry 3 in full

Entry 4

The sprite-0 split for a status bar

staysscrollsmarkerthe game waits, watching for the marker sprite

Watch the top stay put while the level slides under it. The game can only tell when the beam has passed the bar because a sprite is parked there as a marker.

What it does, in the entry's words: Waits for the sprite-0 hit flag at the bottom of a fixed status bar, then writes the level's scroll, so the bar stays and the world moves under it.

Read entry 4 in full

Entry 5

The VRAM buffer drained in the blank

drawinga list in memorythe picture chipdrawing: the game writes its changes down

Watch the changes pile up while the picture is drawn, and pour into the picture chip only in the blank, the one time it is free to take them.

What it does, in the entry's words: The game's logic, running during the picture, queues nametable and palette writes in RAM; the handler writes them to $2007 in the blank, after the DMA, before rendering goes on.

Read entry 5 in full

Entry 6

The jump engine

the game's codecall the engineaddress of routine 0address of routine 1address of routine 2address of routine 3the notecome back herenumber: 2the call is made; the table follows it

The processor has no instruction for pick one of these and go there, so the game borrows the note a call leaves about where to come back to, and uses it to find the table.

What it does, in the entry's words: A routine called by JSR pulls its own return address, indexes the table of addresses that follows the JSR, and lands by JMP indirect: a switch on a byte with the cases written as a table right after the call.

Read entry 6 in full

Entry 7

The state dispatch

on the groundin the airA pressedlandedthe on-the-ground routine runs

Watch the frames tick by. The state decides which routine each frame runs; one press on the ground changes the state, and from the next frame the game is doing something else.

What it does, in the entry's words: The player's state (on the ground, in the air, ...) indexes a jump-engine table; a press changes the state and the next frame runs a different routine.

Read entry 7 in full

Real or model

The same screen, three ways

The engineers put a real NES and their model side by side on the same cartridge’s title screen, and looked at the real one twice: once through a laboratory scope decoded by their own software, once through a cheap USB video grabber. Two different eyes on one real signal, and the model beside them.

The two real pictures agree closely. The model agrees on almost everything, but some colours are off: its cyan is a little bluer, its brown a little warmer. Slide, blink or subtract to see it, and point at a colour to measure it yourself.

The engineers tracked it down. The real chip’s output slows down on its brighter colours, and that shifts their hue; the model’s signal is too perfect to do it. Teaching the model that imperfection is still on their list.

Loading the pictures...

Left picture here
·
Right picture here
·
Hues apart
·
Brightness apart
·

Point at the cyan letters, then the brown sign, with the model on one side and a real console on the other.

What the engineers measured on these pictures

ComparedFlat blocks, mean differenceHue, middle valueBrightness pattern alike
model against decoder0.67 of 25512.6 degrees0.95
model against grabber1.26 of 25514.1 degrees0.95

The flat blocks agree, because most of a title screen is black. The hue does not. The logo's brown is (148, 92, 0) in the model, (132, 73, 0) off the scope and (121, 69, 0) off the grabber; the lettering's cyan is (59, 200, 251) in the model against (45, 200, 205) and (67, 202, 202). Where the two eyes, two different decoders on the one signal, agree to a degree, the model sits twelve to fourteen degrees away on the same colours: bluer in the cyan, warmer in the brown.

The part's output under load. Folding the real waves by subcarrier phase shows what the model's square waves are not: on the part, the rise takes about six phases and the fall about three, the low level sits a tenth of a volt under the table's, and the cyan's plateau at 1.05 V is rounded where the brown's at 0.80 V is not. That is the 2C02's known differential phase distortion (nesdev, "NTSC video"): the PPU's output impedance depends on the level, the board's capacitance slows the higher edges, and the effective hue rotates with the voltage, brighter colours more. The wiki models it as an RC lowpass whose time constant follows the voltage; applied to the model's waves it rotates row 2 by 14.7 degrees at its amount 4 (the cyan's 14.4), but row 1 by 7.5 where the brown measured 1.8, and it rotates every hue of a row alike, as the measurements do. What the title1 session had that the earlier records did not is the grabber on the same output as the probe: a different load on the part's output stage, a stronger and more nonlinear slew than one constant fits.

The bug museum

Every wrong turn, kept

Building a machine this carefully means being wrong a lot, and catching it. The engineers keep every mistake in their reports, beside the fix, instead of tidying it away. Here are some of the best.

Some bugs lived in the model, some in the bench wired to the real console, some in the tools, and some in the measuring itself. Each plaque says what you would have seen, why it happened and how it was caught; below it are the engineers’ own words, read from their reports.

Where the bug lived

A bug in the model

The title that read GWME

The model's title screen with one wrong tile
The model's title screen with one wrong tile
The title screen after the fix
The title screen after the fix
What you would have seen
Super Mario Bros.' title screen, perfect except for one letter: the menu offered a 1 PLAYER GWME.
Why
Right after counting up, the fast copy of the processor looked at its counter's old value, which was still on its way, so one read went to the wrong address and fetched a W instead of an A. None of the existing tests happened to put those two instructions together.
How it was caught
The engineers traced the wrong letter back to the exact read that fetched it and rebuilt the mistake in a few instructions against the transistor-level chip, which got it right. The first fix broke the menu a new way and was caught the same way; the second came with a set of new tests held to the slow chip.

In the engineers' words

1 PLAYER GWME. The events file located the write: the byte sent to $2007 for that tile was $20, the letter W, where the ROM's string, read out of CHR-ROM through $2007 a moment earlier, carried $0A, the letter A. The pins walked it back: the byte came from an LDA ($00),Y whose pointer and index crossed a page, and the CPU read the un-carried address, $0300, and never did the fixed-up read at $0400 where the A had been stored. Five instructions reproduced it on the 6502 repository's own lockstep of the switch-level chip beside the fast rung: after INY, the fast rung chose its variant of the next instruction by asking Y as stored, one instruction stale, because the result of the increment was still in the ALU's hold register and lands one half-cycle later. The switch-level chip has no such question to ask; the carry falls out of the transistors with the right Y.

Read the whole account

Write a program

Tell the chip what to do

A processor knows a few dozen instructions, and each one is tiny: put a number here, add one to it, compare it with something, go back a line. Games are made of nothing else. Here are a few lines you can change and run.

It runs on the 6502 itself, the transistor-level one this shop serves over its own interface, an instruction at a time. A, X and Y are the three places the chip can hold a number while it works; the grid at the bottom is the first page of its memory, and you can watch your program change it.

It is the same processor as the one inside the NES, which is where all of this started: the console’s chip is this one with its sound hardware beside it on the same piece of silicon.

The smallest program there is: put a number in the processor, then put it somewhere in memory.

Try one

What the chip was given

Press “Put it on the chip” and the assembled program appears here, with what each line does.

A, the working register
·
X
·
Y
·
Where it is
·
Flags
·
Instructions run
·

The first page of memory, as the program leaves it

································································································································································································································································································································································································································································································································

The bench

A real console, watched

None of this would settle anything without a real NES on a table. The engineers built a bench around one: a little board that presses its buttons, a laboratory scope on its video wire, and cameras on a frame watching the whole thing, so a run can be repeated exactly and what happened can be looked at afterwards.

These are their own photographs, with their own captions. Pick one to see it; the parts listed under each are what their caption names, in the order they wrote them.

The whole rig

Close up

the bench from the front: the console and its TV at the left, the frame over the backing board, the scope behind it

the bench from the front: the console and its TV at the left, the frame over the backing board, the scope behind it

In this picture

  1. the console and its TV at the left
  2. the frame over the backing board
  3. the scope behind it

From The QA rig.

What is watching, and what it watches

  • Logitech BRIOthe board eye: the hole map, the named close-ups, the timed board grabson the frame's cross-bar over the breadboards, straight down, raised and levelled 2026-09-15, gaffer-taped and velcroed
  • Logitech QuickCam Pro 9000the side eye across the board: the three chips and the UNO's leads in profile from the Pi's sideon the backing board's Pi side, low, looking across the breadboards toward the console
  • Logitech QuickCam Communicate Deluxe (OFF THE RIG 2026-09-24)was the second side eye, along the chip board's rails side from the cable end: the probe clips, the console cable's housing, U3's rails-side landingson the frame's upright at the cable end, low
  • Roxio capture (em28xx)the console's pictureon the splitter with the scope's CH3
  • Logitech BRIO`zoom_absolute``focus_absolute`, `focus_automatic_continuous`

Four phone photographs of the whole rig, 2026-09-15, after the lock (phone metadata stripped; the TV's picture blurred, since the site carries no commercial game screenshots).

How it was built

A fortnight of afternoons

The whole console, from the first sketch to a real NES wired to the model, was built in a few weeks, and every step of it was written down twice: a plan saying what would be checked, and a report saying what was found. This is all of it on one rail of days.

The shape tells the story. The television signal was finished almost at once; the two chips took a few days each, once at the level of their transistors and again as fast copies that had to agree; then the console, and then two weeks of building a bench out of real hardware, which is where most of the days went.

Pick any stop to see what that document is about, and follow it if you want the detail.

  1. Where it started

  2. The chips

  3. The signal

  4. The console

  5. The desk

  6. Planning the bench

  7. Building the bench

  8. What happened at the bench

  9. Experiments at the bench

  10. Exercising the bench

The whole arc

1 September to 29 September

Every plan and report the engineers wrote, in their own groups, day by day. A darker day is a day with more of them. Pick one to see what was written.

A document sits on the first date its own text mentions, which is usually the day the work was done. The 3 documents that carry no date in their text are listed here instead: N3 plan, P2 report, Where the signal path departs from the references.

The machine

A handful of parts, one clock

Everything above is these parts talking. The processor runs the game and leaves notes for the picture chip; the picture chip reads the cartridge's tiles and walks the beam; the television turns the wire back into light. Each part below links to where the engineers took it apart.

PadCrystal2A032C02CartridgeTelevisioneight buttonskeeps timethe brain and the soundthe picture chipprogram and tileslight, from one wirebuttonsticksticksnotesprogramtilessoundpicture
The processor and the picture chip never share a clock tick by accident: both count off the same crystal, and the engineers checked every way the two can line up at power on.

the glue between them

The board

A crystal that keeps time for everyone, a little working memory, and a handful of simple chips that decide who is talking on the shared wires at any moment.

On the bench next

Ideas this playground could grow

Proposals, not promises. Each would draw on something the engineers have already measured or built.

  • The sound beside a real console's

    The engineers hold their sound against recordings of real hardware. The same comparison here: a note from the model and the same note from a real chip, one after the other, with what differs marked.

  • The signal on a real scope

    Their scope's recording of a real console's video wire, drawn beside the model's own signal for the same screen, so a reader can see how close the wiggle is.

  • The cartridge, opened

    What is actually inside the plastic: the two memories, the board that swaps them, and the reader the engineers built to dump one, with their photographs.