1985 · Domark
These pages explain Domark's Commodore 64 A View to a Kill from its own code. The game is five programs, and every claim links to the address it rests on in that program's copy; the notes below record who made the game, who made the pages, and how the conclusions were checked.
The roles below are as the intro's credits give them.
One copy was studied: a cracked disk titled "BOMBJACK LTD. presents A VIEW TO A KILL / Originally cracked by MAGIC... levelcrunched and modified by BJK". A BASIC menu loads one of five files, each a program packed into a single file that unpacks itself over memory and jumps into the game. The addresses on these pages are those of the unpacked programs. The disk's packers and menu are the crackers' and are not described.
The files carry older layers, left out of the other tabs:
$8020 patch over the start of another group's title and menu ("THE DYNAMIC-DUO PRESENTS … BROKEN BY THE DARK-ANGLE & THE EXECUTOR"), whose menu offers SEE OPENING, PARIS-CHASE, CITY ESCAPE, SILICON MINE and FINALE and loads files named P*, C*, S* and F*. The rest of it is still there and never runs.SYS 2067, "MAGIC") and its depacker at $0800.$0A00. Whether the code prompts in use are the game's or were written for the split is open.The original disk's own loader is not on this copy. No game image is hosted here.
The write-up, facts and symbol map are available under CC BY-SA 4.0; code is under MIT.
| Tier | silver |
|---|---|
| Coverage | 100 % of the bytes the game uses have a description |
| Build analysed | |
| Copy | agent-draft |
| Tools | host: Linux 6.18 x86_64, cloud container with no display, emulator: VICE, release v3.13.1, v3.13.1-linux-x86_64-gui.zip, disassembler: regenerator2000 0.9.20, one instance per part, each in its own network namespace, python: 3.11.15, depacking: the five packers run in kit/c64/cpu6502.js to learn what each file writes, browser check: Playwright with Chromium, subagents: five annotation agents, one per part; all claude-opus-5-5 |
| Model | claude-opus-5-5 |
| Kit version | 0.0.43 |
Read this before annotating code. What the game is documented to do, with verification status against the binary. Statuses: open (documented, not found yet), traced (in the code, could not be exercised; say what was tried), confirmed (in the code, consistent with the emulator), live (observed directly), differs (the code does something else). "Absent" is not a status.
The game is five programs, loaded one after another (orientation.md). Each row names its part; the addresses are in that part's own listing.
Sources:
| Feature | Part | Status | Where |
|---|---|---|---|
| Gun-barrel opening picture, the Domark logo and a scrolling roll of credits | intro | live | reference/intro-gun-barrel.png, intro-credits.png; white_wipe $C100, logo_assemble $C430, credits_scroll $C54E (intro) |
| Spoken words, "speech by B.-Jones" | intro | traced | a 1-bit sample player, speech_play $A000 (intro), heard as a burst of about 2.2 s; it says "My name's Bond. James Bond" (heard by the contributor); Paris adds "Well done, 007" ($1225), "You failed, Bond" ($190A) and "Damn it" ($1090) |
| Music by Tony Crowther: the James Bond theme and Duran Duran's "A View to a Kill" (Wikipedia, MI6-HQ) | all | traced | two tunes: one in the intro and City Hall ($C640, notes from $E000), one in Paris and the mine (notes $E000-$FFFF); the first is the James Bond theme, the second the tune based on the Duran Duran song (heard by the contributor) |
| A choice of theme tune only, sound effects only, or both | paris | confirmed | $02E0, chosen with the stick on the instruction page (title_page, $4F30, paris) |
| Chase May Day by car while she parachutes from the Eiffel Tower; be at her drop point when she lands | paris | confirmed | mayday_update $5200: she circles, then lands at one of eight points; a catch is possible below 060 (paris) |
| A first-person view from the car over an overhead map of the streets | paris | live | reference/paris-chase.png; build_3d_view $4600 (paris) |
| May Day's altitude counting down (the 890 readout) | paris | live | reference/paris-chase.png; altimeter_tick $5315 (paris) |
| A clock, a damage gauge | paris | live | update_clock $4170, add_damage $49A0 (paris) |
| Police and road blocks | paris | confirmed | fourteen police cars follow the player's route; place_roadblock $4900 (paris) |
| Stick: forward accelerates, back is reverse and brake, left and right steer, fire shoots, back with fire is a handbrake turn | paris | confirmed | $5AE0, $5B59, $5B9B, fire_bullet $4570 (paris) |
| Room-to-room view of the burning City Hall, with the building in miniature beneath it | city-hall | live | reference/city-hall-play.png |
| Memos from M and Q before the section | city-hall | live | reference/city-hall-memos.png; memo_page $1800 (city-hall) |
| Collect and use objects (keys, buckets of water) from icon menus to get through the floors and rescue Stacey before the fire spreads | city-hall | confirmed | item_menu $7A00, word_menu $8000, 24 USE handlers at $7CA6; fire_spread $94F0 (city-hall) |
| A thermometer and a clock | city-hall | live | $69E0, tick_clock $6E40 (city-hall); nothing reads the clock |
| Side view of the mine under Silicon Valley; find May Day, who is trapped | mine | confirmed | reference/mine-briefing.png; blasting rock fall 3 frees her ($3E00, mine) |
| Collect the code numbers that defuse Zorin's bomb before the time runs out | mine | live | end_check $25E0 (mine), run with set digits |
| A countdown clock (89:40:xx) and a Geiger counter | mine | traced | the clock is live (reference/mine-play.png, clock_tick $1C20); a meter on the panel ($3000) rises towards the upper right, whether it is the Geiger counter is open |
| Objects: a grapnel gun, wooden planks, a mine pass, a winch (Wikipedia, C64-Wiki) | mine | traced | planks ($3970), a rope ($38D8), the winch's four parts ($3F23), explosive and detonator ($3827, $39E0); the objects' names were not matched to their icons |
| The detonator combination 32768 (MI6-HQ) | mine | differs | the part checks 6 7 1 3 4 ($26F0, mine) |
| Each later section asks for the code the previous one gave; RETURN plays it without one | city-hall, mine, finale | live | the prompts, reference/city-hall-code-prompt.png; RETURN at the finale's prompt only asks again |
| The codes CCPHJ (City Hall), DB4CT (mine) and ILVCT (the ending) | city-hall, mine, finale | live | each typed at its prompt and accepted; read_code in each part |
| The ending: Bond seen through binoculars, then the lens cracks | finale | confirmed | reference/finale-shower.png, finale-cracked-lens.png; show_ending at $1000 (finale) |
| Keyboard control as well as the joystick (C64-Wiki) | all | differs | every playable part reads only the joystick in port 2 and stops the keyboard scan; keys are read only at the code prompts |
Found in the code, not in the manual.
$8061 (finale): nothing derives it from play, and the ending prints no code.finale_start points the NMI vector at itself ($8000, finale).facts.md, "The codes").$7090, city-hall).$4FBB, $8000, paris).$C540, intro).$4E80, paris).facts.md, "Layers of the copy studied").How to get from the contributor's own copy to the analysed state. Someone else must be able to follow this exactly.
VIEWKILL.D64, a single-sided 1541 disk image (174,848 bytes, SHA-256 cd34f0a3…e600). It is a crack, not the original: the disk name is "ASS PRESENTS:", and the directory holds a BASIC menu and five packed programs, plus a zero-block entry that is only a note:
| File | Blocks | Loads at | What it is |
|---|---|---|---|
A VIEW TO A KILL | 8 | $0801 | a packed BASIC program: the crackers' title page and the menu |
1 | 61 | $0801 | the intro |
2 | 90 | $0801 | Paris |
3 | 85 | $0801 | City Hall |
4 | 83 | $0801 | the mine |
5 | 66 | $0801 | the ending |
END CODE = ILVCT | 0 | a deleted entry used as a label |
The title page reads "BOMBJACK LTD. presents A VIEW TO A KILL / Originally cracked by MAGIC... levelcrunched and modified by BJK". "Levelcrunched" is the crackers' word for packing each loaded part into a file of its own.
LOAD"*",8,1, RUN).LOAD"n",8,1. The run loaded each file by name instead (vice_autostart with program set to 1 … 5), after a hard reset each time.SYS 2072 (SYS 2087 for file 5) into a packer (a "BOMBJACK!!" depacker in files 1 to 4, "THE-A-TEAM" in file 5) that unpacks the part over all of memory and jumps into it. A stopping checkpoint on that jump's target stops on the part's first instruction: $8020 (intro), $43B0 (Paris), $1000 (City Hall), $5660 (mine), $8000 (finale). That stop is saved as the part's work/entry.vsf.CCPHJ and RETURN at "PLEASE ENTER CODE", then fire on the memos page.DB4CT, RETURN, fire.ILVCT, RETURN; the ending runs by itself. A snapshot saved a few seconds into each is the part's work/play.vsf.Files 1 to 4's packers write every byte from $07E8 to $FFFF, so their hand-overs hold nothing from an earlier load. File 5's writes only $0800-$80FF, and the rest of its image is whatever was in memory before (checked by running each packer in kit/c64/cpu6502.js over memory filled with $00 and then $AA).
| Part | Interrupt vector in play | $01 in play |
|---|---|---|
| intro | $0314 = $CC00 | $37 |
| Paris | $0314 = $5026 | $36 |
| City Hall | $0314 = $4022 | $36 |
| mine | $0314 = $1022 | $36 |
| finale | the KERNAL's own ($EA31) | $37 |
Every part leaves the KERNAL in and hooks its handler into the KERNAL's vector at $0314. Nothing is loaded once a part is running: each part is one whole program, and the analysis treats each as its own image (parts/<id>/).
The emulator was the vice-mcp release v3.13.1 (v3.13.1-linux-x86_64-gui.zip) on Linux x86_64 in a container with no display. check-emulator passed 57 of 57 checks; no workarounds were needed.
The menu is BASIC. The BOMBJACK packers bank everything to RAM ($01 = $34), copy their depacker into the stack page and $0334 and run it from there; file 5's copies its packed stream to $BF89-$FFFF first. Each ends by setting $01 back and jumping to the part. None of this is the game's; it was run to its jump and not annotated. The original disk's own loader is not on this copy.
Every byte of the C64's 64 KB, one pixel each, 512 to a row, for each program. Lit pixels are code, graphics, sound, text, tables and variables; dim areas are screen and working memory.
| What | Bytes | Of 64 KB |
|---|---|---|
| Program | 27,588 | 42.1 % |
| Code | 3,015 | 4.6 % |
| Graphics | 16,768 | 25.6 % |
| Sound | 5,107 | 7.8 % |
| Text | 2,105 | 3.2 % |
| Tables | 492 | 0.8 % |
| Variables | 101 | 0.2 % |
| Screen, bitmap, colour, stack, I/O | 29,524 | 45.1 % |
| ROM the game runs under | 8,192 | 12.5 % |
| Unused | 232 | 0.4 % |
This game is in 5 parts, and the map is of one of them: Intro. The Source tab has the listing of each part that has one.
Each part of the game has its own symbol map and listing: Intro, symbols.json and listing.json; Paris chase, symbols.json and listing.json; City Hall, symbols.json and listing.json; The mine, symbols.json and listing.json; Finale, symbols.json and listing.json.