1985 · Domark

A View to a Kill: the source

This minisite was contributed by air, unorig. It’s agent-generated and needs a human editor. Clone https://github.com/gamesexplained/gamesexplained and follow kit/START.md to curate games/c64/a-view-to-a-kill with me to Gold.

Every routine, table and variable the game uses, with the names and descriptions given to them. Click an operand to follow it; the counter beside a label lists what refers to it. The reference below the fold is rendered from the game's facts file.

This game is in 5 parts, and the same addresses hold something else in each. Each part has a listing of its own.

Technical reference: memory map, timing, tables, cheats

Intro

File 1 of the copy studied. Every fact names the routine or table it comes from, in this part's listing.

Memory

RangeWhat
$0800-$17FFsprite shapes: $20 the rolling dot, $22-$39 Bond walking (eight frames of three stacked sprites), $3A-$3F Bond turning, $40-$45 the six pieces of the Domark logo, $46-$48 the sparkles; $21 and $49-$5F are never pointed at
$1800-$1BFFthe credits' character set, 128 glyphs, copied to $4800
$2000-$3F3Fthe gun barrel, a multicolour bitmap, copied to $6000
$8000-$801Acopy_tune_start: copies the tune to $E000 and starts the intro
$8500-$8EFFthe tune, the James Bond theme (heard by the contributor): three note lists
$9000-$9B9Fthe credits: printer, 85 entries (credit_lines), their strings, the title rows
$A000-$AA82speech_play and its samples
$B000-$B9FFa hires fragment with "A VIEW TO A KILL" lettering that nothing shows
$C000-$CEFFthe intro's code, its interrupt handler at $CC00 and the music driver ($C640-$C7B5, state at $C600)

Start and interrupts

The running order

In frames of a whole-part run in kit/c64/cpu6502.js (no bad lines, so the real machine runs a little longer):

FrameWhat
14two white dots roll across the screen (rolling_dots, $C000)
226the barrel is wiped in from the right (white_wipe, $C100)
269it scrolls left while Bond walks in (barrel_step, $C809; bond_step, $C200)
551the gunshot (gunshot, $CABC)
559blood runs down (blood_step, $C840)
782the screen shakes (shake, $C900)
1053the speech (speech_play, $A000)
1163the picture dissolves (speech_and_fade, $CA80; bitmap_mask, $CA50)
1215the Domark logo flies together from six sprites (logo_assemble, $C430)
1485"D O M A R K / presents you / as / JAMES BOND 007" (title_print, $90A0)
1850the credits begin to scroll (credits_scroll, $C54E)
5171the end, about 103 s in

Music

Speech

speech_play ($A000) plays one bit at a time by switching the SID's volume, $D418, between 0 and 15. Its data is a length word at $A090 and samples at $A092-$AA81; in the simulator it ran 2,149,012 cycles (about 2.2 s, some 9,400 bits a second) with 20,355 writes to $D418. $A453-$A715 is zeros, a silence of about 0.6 s. It runs with BASIC banked out ($01 = $36, $CA90).

Left from an older crack

The credits that sometimes never scroll

credits_setup ($CB50) writes $97 to $D011, whose top bit is bit 8 of the raster line the interrupt is asked for: line $1F0, which a PAL screen never reaches. The only thing that clears it is the read, AND and write of $D011 at $C540, and a read of that bit gives the line the beam is on. If $C540 runs while the beam is below line 255, the bit is written back set, no raster interrupt comes again, and the credits, the music and everything else driven from irq_handler stop.

Live, 30 September 2026, four boots with the start moved by a tenth of a second each time: three read A = $17 at $C545 and scrolled the credits (100 calls of credits_scroll in 15 s); one read $97, at raster line 38 after the store, and credits_scroll never ran.

The whole game

Current truth for this game. The workflow lives in kit/skills/; how this understanding developed lives in agent-history.md. Every fact names the routine or table it comes from. Unless marked live, a fact comes from reading the code in the snapshots named in orientation.md.

The game is five programs, and each has its own facts, listing and symbols under parts/<id>/: parts/intro/facts.md, parts/paris/facts.md, parts/city-hall/facts.md, parts/mine/facts.md, parts/finale/facts.md. An address is always an address in the part named with it. This file holds what spans the parts.

Build

Five programs, loaded one at a time from a menu, each unpacked over the whole of memory and started at its own entry (orientation.md):

PartEntryInterrupt in playScreenSound
intro$8020$CC00bitmap, banks 1 and 2the Bond theme, speech
Paris$43B0, then $5A00$5026$0400the theme, effects, speech
City Hall$1000$4022$0400the intro's tune, effects
mine$5660$1022$4000Paris's tune, effects
finale$8000the KERNAL'sbitmap $2000, $6000none

Nothing is loaded once a part runs, and no part loads the next: the player goes back to the menu for each.

The codes

The three later parts start at a KERNAL "PLEASE ENTER CODE" prompt with the same routine (read_code: City Hall $1088, mine $5707, finale $804C): five characters through CHRIN, compared with a fixed string. A match stores 1 in $1BA0; RETURN before five characters stores 0 and plays on without the code (the finale goes back to its prompt instead); a wrong code is read again, with no limit on tries.

Given byWhere it is shownCodeChecked by
Paris, on a catchthe telex, Paris $8140CCPHJCity Hall $10D8
City Hall, on escapemission_complete, City Hall $1334DB4CTmine $5757
the mine, on defusingmission_complete, mine $0AFEILVCTfinale $809C
  • Every code is fixed text. No part computes one from play: there is no score, no time or result in them (read in each part's end routine).
  • $1BA0 is the same address in all three parts, and a part reads it once, at its end:
  • City Hall ($7096): with the code, reaching room 76 with Stacey shows DB4CT; without it the game starts again ($8600).
  • mine ($25F2): with the code, the right bomb digits show ILVCT; without it the bomb goes off, whatever the digits (game_over, $25D0).
  • finale: written, never read. The ending plays only after ILVCT.
  • Live, 30 September 2026: CCPHJ, DB4CT and ILVCT were each accepted at their prompts. City Hall's end with and without CCPHJ, and the mine's with and without DB4CT, behaved as above (parts/city-hall/facts.md, parts/mine/facts.md). The finale compared only five characters: ILVCTX was accepted.
  • So a part can be played from the menu without its code, but only Paris gives a code without one: City Hall and the mine can be finished only by a player who typed the code that came before.

Code the parts share

Bytes identical at the same addresses, compared in the unpacked images:

WhatWhere
the three-voice music driverintro and City Hall $C621-$C7FE
the Bond theme's notesintro $E000, City Hall $E000 (and intro $8500, the copy it moves there)
the second tune's notesParis and mine $E000-$FFFF
read_joystickCity Hall $4700, mine $17A0
tick_clockParis $4170, City Hall $6E40
the "OK" soundCity Hall $6B50, mine $3B7D
read_codeCity Hall $1088, mine $5707, finale $804C, apart from the addresses they name
mission_complete and its text with ILVCTmine $0A00-$0B04, and the same bytes in City Hall, where nothing calls them

All four playable parts read the joystick in port 2 only ($DC00) and stop CIA 1's timer A, so the KERNAL never scans the keyboard during play; the keyboard is used only at the code prompts.

Layers of the copy studied

Each part carries leftovers of earlier work on the game, none of which runs:

  • intro: a crack's menu and title ("THE DYNAMIC-DUO PRESENTS"), $8020 onwards, overwritten by a 14-byte patch (parts/intro/facts.md).
  • Paris: an earlier crack's BASIC line and depacker at $0800.
  • City Hall: an older code prompt (code "QRS21", $967B), an older end screen ("WEBL DONE 007 YOUR CODE IS 111122", $7E5A), and the mine's end screen at $0A00.
  • mine: stretches that match City Hall at the same addresses ($0B04-$0FFF).
  • finale: memory the part's packer never writes, holding bytes that match Paris's code in part.

Whether the code prompts and end screens are the original game's or the crackers' is open. For the crackers: the older prompt and end screen left in City Hall, and the mine's prompt placed in character-set glyphs the mine's tiles do not use. Against: the memos, which are plainly the game's, also print through the KERNAL. The published game is documented with the three codes (C64-Wiki, features.md).

Live tests

TestPartResult
each code at its prompt; a wrong code; RETURNCity Hall, mine, finaleas above
four intro boots, start moved a tenth of a second each timeintrothe credits stalled in one (parts/intro/facts.md)
Bond's room set burning, with and without CCPHJCity Hallthe DB4CT screen; a new game
end_check run with set digits, with and without DB4CTmineILVCT; game_over
RESTORE after the endingfinalethe prompt again, blind
holding fire for 1.2 s on Paris's instruction pageParisthe chase started normally; a stuck start seen once earlier was not reproduced

Cheats

Pokes that change the game within its own parameters. Each one names the variable it changes and whether it has been tested live. Untested pokes are labelled as candidates. Addresses are in the part named.

EffectPokeStatus
Play City Hall or the mine without the previous codepress RETURN at "PLEASE ENTER CODE"live
Codes: City Hall CCPHJ, the mine DB4CT, the finale ILVCTtype at the promptlive
City Hall: end the part at once (with CCPHJ typed)set byte 12 of Bond's room record: POKE the address in $3F/$40 plus 12 with 1live
Mine: the bomb's combinationnumbered items 6, 7, 1, 3, 4 ($26F0)live, by storing the digits
Mine: stop the clock$1B80 = 1 (the PAUSE flag)candidate
Paris: repair the car$03A1 = 0 (damage, 40 loses)candidate
City Hall: refill Bond's energy figure$1B5B = 42 (the gauge never kills)candidate
routines tables variables strings branch labels

Loading listing…