Xiegu X6100 WiFi Adventures

Top Line

I ran into to major issues in getting my Xiegu X6100 WiFi/WLAN to work on my network under APP version 1.1.9, Sept 14 2024.

Firstly, a minor complaint (well, maybe pretty major), I found that the operation of the various buttons in the WLAN section can be very confusing. Here is what some of the ones that may not act as you expec actually seem to do:

  • WIFI SWITCH: Turns the WiFi radio off or on. One time, though, ONE TIME when I pressed this, it wiped out all of my WiFi settings.
  • CONFIG: This button recalls the settings for the network currently highlighted network from /usr/app_qt/.config/ssid. Otherwise, if the selection has not changed, then at least sometimes (but seemingly not always) it saves the current settings in that same file.
  • CONNECT: After you press CONFIG, this is used to connection to the currently selected network. It can also save settings into the file in .config if the selected network did not change. ALWAYS press CONFIG first, or you will end up wiping out your configuration in /usr/app_qt/.config/ssid
  • MFK Knob: Turning the MFK knob and then pressing it will allow you to select a network. NOTE: DO NOT turn the MFK knob to a displayed ssid and then press the CONNECT button to connect to that network. If you do, it will connect – but it will also overwrite the file in /usr/app_qt/.config file for the selected network. ALWAYS press CONFIG first.

A second minor complaint is that it stores information about WiFi in to different locations. For a given ssid, that information is found in /usr/app_qt/.conf/ssid AND in /etc/NetworkManager/system-connections/ssid.nmconnection and just because the information is in /usr/app_qt/.conf/ssid does NOT mean it gets were it really needs to go in /etc. So, the two can (and do) get out of sync.

The first major problem is that I have found that pretty consistently the radio GUI does not set (or change, on and update) the password in /etc/NetworkManager/system-connections/ssid .

So, if you attempt to connect to your WiFi network from a Xiegu X6100 and it fails to connect, attach a USB cable from the DEV port on your radio and a USB port on your PC, start up a terminal emulator on the . (There are YouTube videos and other places that document this process.) Then look in /etc/NetworkManager/system-connections for a file of your-ssid.nmconnection and look at it with “cat” or “vi”. If it has a password, is it correct? If no, You can fix the password with “nmcli con modify your-ssid wifi-sec.psk ‘my-password’

Here is an example the section that has to be set up right with the password in /etc/NetworkManager/system-connections/ssid.nmconnection:


The second major problem I ran into is that if you want to use a statically-assigned IP address (as opposed to DHCP), then to make it work consistently, I found I had to edit the file /usr/app_qt/.conf/ssid manually. It is important to realize that when you enter the IP address in the IP address field you have to also indicate the network mask – which the X6100 GUI does not seem to support. This will break how packets get routed to and from the X6100 on most networks. It seemed to work best to edit that file while a different ssid is selected in the radio (even if not connected). It found it best to use “CIDR” notation. For most folks, whose netmask is the usual, that means entering your IP address as something like — note the /24. I used the vi editor to do that. Once you do that, it does display properly. You might also then want to chmod 555 on that file so the GUI can’t change it on you. 😉

If you once set a static IP address, then setting it back to DHCP does not work. You would have to go in and either remove the connection files for that ssid from /usr/app_qt/.config and /etc/NetworkManager/system-connections, or edit them manually.

Here is what it looks like when correctly set up for a fixed IP address in /usr/app_qt/.config/ssid:


And here is what it should look like in /etc/NetworkManager/system-connections/ssid.nmconnection:


(Of course, your DNS server might be different.)

The Journey

In December, 2024 I received a new Xiegu X6100 QRP HF/50 Mhz Transceiver as a gift. Of course, being a techy, the first thing I wanted to do was connect it to my network, as WiFi is supported on the later firmware/software releases. However, I was unsuccessful at APP software level V1.1.9. Though I am aware of a third party GUI for this radio, WiFi is supposed to work with the GUI front end from Xiegu — I just had problems.

After going thru the steps recommended for the radio (at System Settings => WLAN) I found that when pressing the button under “CONNECT” it would try to connect, but fail. I tried all three of my WiFi access points using the radio’s WLAN configuration process – one of which broadcasts its SSID, but to no avail. In every case, when I clicked on “CONNECT” it had a pop up that showed it was trying to connect, but it was never able to do so.

I had learned along the way that one can also connect to the radio to get access to Linux by plugging a USB A to C cable (provided with the radio) to the DEV port on the right-hand side of the radio, and connecting the other end to a PC (in my case Windows). There are instructions and videos availble on the Internet which show how to do this. I used the program “putty” set to 115,200 bps to the port which shows up in Windows as a port named “USB-Enhanced-SERIAL-A CH342 (COM8)” to do so.

I then did what any Linux familiar person would do — look at the messages in /var/log/messages, and found these messages:

Jan 1 00:04:50 XIEGU-x6100 daemon.info NetworkManager[184]: [290.0567] audit: op=”connections-reload” pid=328 uid=0 result=”success”
Jan 1 00:04:52 XIEGU-x6100 daemon.info NetworkManager[184]: [292.8730] audit: op=”connection-update” uuid=”aa6acb02-9ae7-4eac-a1cc-5583af5d5f4c” name=”my-ssid” result=”fail” reason=”802-11-wireless-security.psk: property is invalid”
Jan 1 00:04:57 XIEGU-x6100 daemon.info NetworkManager[184]: [297.3599] audit: op=”connection-update” uuid=”aa6acb02-9ae7-4eac-a1cc-5583af5d5f4c” name=”my-ssid” pid=341 uid=0 result=”success”
Jan 1 00:05:02 XIEGU-x6100 daemon.warn NetworkManager[184]: [302.6258] keyfile: load: “/etc/NetworkManager/system-connections/Redmi_huai1.nmconnection”: failed to load connection: File permissions (100666) are insecure
Jan 1 00:05:06 XIEGU-x6100 daemon.info NetworkManager[184]: [306.0778] audit: op=”connections-reload” pid=345 uid=0 result=”success”
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1394] device (wlan0): Activation: starting connection ‘my-ssid 1’ (87230e25-962c-4a3f-8002-7a489a41a09c)
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1407] audit: op=”connection-activate” uuid=”87230e25-962c-4a3f-8002-7a489a41a09c” name=”my-ssid 1″ pid=350 uid=0 result=”success”
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1430] device (wlan0): state change: disconnected -> prepare (reason ‘none’, sys-iface-state: ‘managed’)
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1498] manager: NetworkManager state is now CONNECTING
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1589] device (wlan0): state change: prepare -> config (reason ‘none’, sys-iface-state: ‘managed’)
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1636] device (wlan0): Activation: (wifi) access point ‘my-ssid 1’ has security, but secrets are required.
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1638] device (wlan0): state change: config -> need-auth (reason ‘none’, sys-iface-state: ‘managed’)
Jan 1 00:05:10 XIEGU-x6100 daemon.warn NetworkManager[184]: [310.1859] device (wlan0): no secrets: No agents were available for this request.
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1863] device (wlan0): state change: need-auth -> failed (reason ‘no-secrets’, sys-iface-state: ‘managed’)
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.1979] manager: NetworkManager state is now DISCONNECTED
Jan 1 00:05:10 XIEGU-x6100 daemon.warn NetworkManager[184]: [310.2154] device (wlan0): Activation: failed for connection ‘my-ssid 1’
Jan 1 00:05:10 XIEGU-x6100 daemon.info NetworkManager[184]: [310.2295] device (wlan0): state change: failed -> disconnected (reason ‘none’, sys-iface-state: ‘managed’)

There are several things to notice here:

  • 1) The message with “audit: op=”connection-update” uuid=”aa6acb02-9ae7-4eac-a1cc-5583af5d5f4c” name=”my-ssid” result=”fail” reason=”802-11-wireless-security.psk: property is invalid”” looks like some kind of configuration error.
  • 2) The message keyfile: load: “/etc/NetworkManager/system-connections/Redmi_huai1.nmconnection”: failed to load connection: File permissions (100666) are insecure” is typical of many many more messages of that sort for various networks that appear to be present in the radio as remembered connections. There are 492 of them on my radio.
  • 3) The message: “device (wlan0): Activation: starting connection ‘my-ssid 1’ (87230e25-962c-4a3f-8002-7a489a41a09c)” appears to have a similar SSID to the network I was trying to connect to at the time (my-ssid) but with an extra ” 1″ at the end.
  • The message “device (wlan0): Activation: (wifi) access point ‘my-ssid 1’ has security, but secrets are required.” is the final message, and is somewhat confusing.

So, I searched the Internetnet for “has security, but secrets are required”, where in I found a page that had a suggestion to delete that existing connection, and then re-add it. https://unix.stackexchange.com/questions/420640/unable-to-connect-to-any-wifi-with-networkmanager-due-to-error-secrets-were-req

So, based on that website I first tried the command “nmcli con“. Whoa – that listed 431 lines of connections (see 2), above). I tabled fixing that, and then did “nmcli d wifi list“. that showed three connection possibilities, one for each of my WiFi networks in my house. So based on what I had read on the website, and what I saw in the messages, I did “nmcli con delete SSID” for each SSID listed.

At some point around then I entered “nmcli dev wifi connect my-ssid” (my-ssid being the SSID) and got a message “Error: Connection activation failed: (7) Secrets were required, but not provided“. That was hopeful, and made sense – I had not provided a password.

So then I then turned off wifi on the WiFi radio with “nmcli r wifi off” and back on with “nmcli r wifi on” and then did “nmcli dev wifi connect my-ssid password ‘my-password (I had to use apostrophes around my password because it has special characters in it that the Linux shell would mis-interpret). That worked. Yesterday.

HOWEVER, the next day, when I went to write this blog post, and in order to reproduce my results, I deleted the existing connections, tried the above commands to connect, it failed to work. So, I went in to /etc/NetworkManager/system-connection and deleted the entry my-ssid.nmconnection . That did not help, either.

I then decided to clean up the 430+ garbage connections the are present in the Linux image. To do that, I made a dierctory with “mkdir /etc/NetworkManager/removed-system-connections“, changed back to folder with “cd /etc/NetworkManager/system-connections” and then did a “mv *.nmconnection ../removed-system-connections” to get rid of the garbage.

I tried a bunch of things at that point, including telling it to connect without a password, and with a password — nothing seemed to help. But it had worked yesterday! WTF!!?? . Time for lunch,. 😉

After lunch, starting with an empty system-connections directory, I tried to connect to my-ssid again, using the radio GUI to set the password. The result was that the file my-ssid.nmconnection had indications that a password should be there – but the password itself was missing. The password is stored somewhere, because the radio does display it, but it apparently isn’t where it needs to be. (Spoiler: It turns out they are stored in files named /usr/app_qt/.config/ssid“)

So, I then entered the password into the connection file using: “nmcli con modify my-ssid wifi-sec.psk ‘my-password. THAT WORKED.

I then created a connection for another of my access points, and once again, it left out the actual password. It also did not include the IP address information I entered (this one doesn’t use DHCP). But, having entered the wrong password using the radio GUI I went back and fixed that, and then it was successful.

I then went to the root directory to see if I could find out where else some of this info might be getting saved, using “grep -r ‘part-of-password’ directory-name for each directory in the root directory, / . I then discovered the information stored in a file for each connection, named /usr/app_qt/.conf/ssid

Further testing revealed that when you change the settings on the radio itself, nothing happens at first – it is just on the screen. BUT, if you press “CONFIG” that information gets stored into /usr/app_qt/.conf/ssid but not into /etc/NetworkManager/system-connections/ssid.nmconnection . However, if you press “CONNECT” the information gets copied into both places.

That allowed me to get the X6100 to my network with my static network settings. However, at that point it would only talk to my firewall (which was also its default route.) But my firewall will not route between hosts on my own network. I temporarily fixed this with the command “route add -net my-network netmask my-netmask wlan0″ (A sample for my-network might be and my-netmaks – your network will probably be different.). Once I did that, everything worked. (If I were running dhcp, that routing would have happened automagically.)

It was at that point that I realized there was no way to enter the netmask/CIDR properly in the GUI, and edited the file in /usr/app_qt/.config/ssid to put in the proper information. Once I did that, everything worked fine.

Also, a note about NTP. I found that I had to manually edit /etc/ntp.conf to set NTP up the way I wanted it, stop ntpd (/etc/init.d/S49ntp stop), run ntpdate, and then restart ntpd. Setting the ntp server in the radio GUI did not seem to work correctly.

In Memoriam: R. Hannes Beinert

I learned that my friend R. Hannes Beinert (“Hannes”) passed away during the first day of January, 2024. As he was about eight years my junior, this was quite a shock. Although we had not been in contact for a few years, I still counted him among my friends, and I will miss him.

In the early 1970’s I tended to hang around the University of Wisconsin (UW) Computer Systems Lab (CSL). My friend Paul Pierce, a student at the time, was employed there. The computers at CSL were free to use on a sign-up basis, and time was regularly available. In those early years there were cables that ran between the PDP-11/20 and the Datacraft 6024 to a home-grown switch box that allowed one to switch simple peripherals, like paper tape, a printer, and a card reader, between the two. Hannes, a high school student at the time, would sometimes step on the cables, and we used to call him out on it and tease him mercilessly about it.

A year or two later, UW CSL was running UNIX 6th edition on a PDP-11/45 that was on loan from the Wisconsin state printing office. Hannes adopted the user name “oracle” (later he had an email address “oracle@dodona.com” as well.)

We played D & D together, Hannes, Paul, Steve LaMotte and myself first with Paul Trandel as our dungeon master, and later as Steve took over that role. Hannes and I also played ping pong at Union South. One evening we got into a friendly tussle, and Hannes accidentally ripped the pocket of my winter coat a bit. He felt badly about it, and gave me some of his D&D materials as recompense. Also during those years we took a raft trip down the Wolf river in Wisconsin, in part through the Menominee reservation, including a tumble over “Big Smokey” falls. Hannes, myself and my wife were in the same raft when we went over the falls — something over a 10 foot drop — and managed to stay upright. (In those days there were no helmets, either. 😉 ).

Around that time UW CSL purchased a PDP-11/70 to use for course instructional work, a machine well suited to running UNIX. Trouble was, it had no other software, and the UNIX we had, 7th edition, did not have a standalone program to support the tape drive it had to load the system onto disk, and although a tape drive that would have been supported existed on the CSL VAX 11/780, for some reason it was not a good idea to borrow it. I was already employed by Wisconsin DOT at the time, but we both (mostly Hannes) worked into the wee hours to get it loaded – I wrote the tape read routine, and Hannes the disk write routine. We assembled the code on the PDP-11/20 to get printed listings – the PDP-11/70 had no card reader, teletype or paper tape reader, just a 120cps DecWriter. I left about 2AM, and stopped in about 7:30 AM on my way into work to check in. Hannes had stayed all night and had the UNIX 7th edition booted up. (I used that system to work on Small-C for the IBM mainframe.)

During his high school and college years Hannes also became an accomplished sailor, sailing with the Hoofer Sailing Club. Somewhere along the line, Hannes also served as Fleet Captain for the Hoofer Sailing Club 470 fleet. Later he also raced, along with others in the Hoofer sailing club, on Lake Michigan on a sailboat known as “Marika” owned by Don Stitt, a member of the state’s legislature. In 1989 I had a kind of epiphany with respect to being more active, and Hannes offered to take me and my wife out on “Maria”, the Santa Cruz 33 foot sailboat owned by the Hoofer Sailing Club. (The plan had been to go out on Marika, I had taken the day off, but Hannes had kind of forgotten, and the weather on Lake Michigan that day was a bit windy anyway). I was hooked. A couple of weeks later he took me out on an M-20 Scow (I think it was the yellow one, that I later crewed on in Mendota Yacht Club races) and I was really hooked. I joined the club, and sailed actively for about 20 years – I last went out in 2019 before the pandemic hit. Hannes maintained the UW Outdoor Rentals Mooring field for a few years as well.

During those years Hannes studied and obtained his Masters license with a sail endorsement. He served as crew aboard the sailing vessel Rose (later renamed the Surprise), and he also served as boatswain on the sail training vessel Pogoria (wikipedia) from Poland for a trip across the Atlantic. We both attended the early meetings in the development of the sailing vessel Denis Sullivan, originally sailing out of Milwaukee, as well – that vessel has since relocated to Boston. A bit later Hannes served on the research vessel “R/V Acoustic Pioneer” doing sonar work off the cost of Alaska.

Hannes helped immensely in the acquisition of many of the minicomputers that are in my collection. He drove the trucks as I had no experience with them, and helped me carry equipment down our steps into the basement. Machines he helped with included the Data General Eclipse S/140, the PDP-11/24 (which we hauled out of Bascom Hall at UW), and a number of machines that had been in Professor Marleau’s electrical engineering computer lab at UW – including a PDP-11/20 (which I had used when I was in sch0ol), a PDP-11/40 and a PDP-11/45, and with the PDP-12 as well. Hannes and my friend Pete Mooney also once showed up in the evening with a truckload of gear, including a Data General Eclipse S/130, a Data General Nova 4, a Data General Nova 3 (since donated to the Large Scale System Museum) a Commodore PET and a Cromemco Z-2 S100 system.

One time, while Hannes was out of town, I got a call from his then girlfriend indicating that they were about to throw out a PDP-11/20. I rescued the “guts”, and Hannes later loaded the rack into the back of his parent’s Toyota Corolla station wagon to transport it to my house. I thus named this particular PDP-11/20 as the “Hannes’ PDP-11/20“.

In later years he served as caregiver at home for his mother (whom he referred to as “Mutti”) who suffered greatly with cancer and he continued to live in their house with his father, Helmut Beinert.

Unfortunately over the years we slowly drifted apart, and had only occasional contact. I regret that now, and he will be missed.

IBM 1410 FPGA: Input Check

The next issue to fix was another instruction check, this one after a console input instruction finished where the number of input characters was less than or equal to the number of expected input characters.

The basic problem was that as I/O was ending, the I CYCLE CTRL signal goes active while E CH UNOVERLAP IN PROCESS is also active.

The problem can be seen in this waveform capture:

Instruction Check during completion of console input where the number of characters entered is less than or equal to the number of expected characters.
Instruction Check during completion of console input where the number of characters entered is less than or equal to the number of expected characters.

What made this problem a bit more interesting was that this error did not occur if the number of characters entered was more than the available buffer (i.e., from the address specified in the read instruction up to and not including the group mark with a word mark that marks the end of the input buffer:

NO Instruction Check during completion of console input where the number of characters entered is greater than the number of expected characters.
NO Instruction Check during completion of console input where the number of characters entered is greater than the number of expected characters.

I spent quite a few days looking at this and that and trying this and that, without making much headway. And in the process I discovered a couple of interesting errors in the IBM CE documentation for the 1410.

One thing I noticed was that the logic for an Instruction Check that is shown in the IBM 1410 System Fundamentals manual, S223-2589 and is quite simple would not have caused this Instruction Check, and that the logic in the Instruction Logic Diagrams, R23-2936 does have logic that would trigger an error under these circumstances and is more complex. The latter matches (more or less — more on that later) the ALD and triggers this error from either of the bottom two sets of (ILD) AND/OR gates in the lower left hand corner of Figure 58 of the ILD. (In reality, these are implemented using AND/NOR gates – aka And/Or/Invert gates).

The second thing I noticed was that in the I-O sequence diagram on page 43 of the 1411 I/O Operations Manual 223-2692 depicts +S I CYCLE CTRL indeed overlapping +S E CH UNOVERLAP IN PROCESS – in contradiction to what is on the ILDs.

Finally, in comparing the ILD to the ALD I did spot one error in the ILD. In the bottom most And/Or gate on the ILD, there is an OR gate for signals E CH OVERLAP IN PROCESS and I CYC CTRL. In fact, that one is F CH on the ALD (which make more sense).

So, what to do. I had some concern that the change I made earlier to ALD page to inhibit E Cycle Required during Logic Gate A might be a problem, but thought experiments didn’t bear that out. Also, the condition seemed to be benign, in that once the I/O completed, E CH UNOVERLAP IN PROCESS would be de-asserted. Finally, I wondered it this might be another case where the speed of the FPGA logic for multiple layers via LUTs – look up tables – might be causing a race condition.

In the end, I decided on a simple approach. I created a variant of card type DHL, called DHLJ, with an extra direct input to the NOR gate, using otherwise unused pin K. I then fed in the I-O LAST EXEC CYC signal into ALD logic blocks 4E and 4H, which resolved the Instruction Check.

This is shown in the following timing diagram:

Input Instruction Check fixed by inhibiting an instruction check when IO is finishing up and +S I-O LAST EX CYCLE is active.
Input Instruction Check fixed by inhibiting an instruction check when IO is finishing up and +S I-O LAST EX CYCLE is active.

This isn’t the most satisfactory thing in the world, but given the contradictory nature of the IBM materials, I didn’t feel like I’d be able to sort it out properly – at least for now. (Also note in the above timing diagram the “notch” in +S E CYCLE REQUIRED during Logic Gate A, caused by the earlier fix.)

With this fix, there are no more problems running the 1410 diagnostic CU01C, nor the 1401 Mode diagnostic M011, including console input.

There is still much to do, including replicating the E Channel fix to ALD into the F channel. After that, I think I will spend some time cleaning up console operations, where there are lots of things to change on the PC Support program software side, as well as some hardware issues, like the improper prompt character during the start of a console Display operation (and other operations as well), and some possible issues during address set and storage load and regen operations.

IBM 1410 FPGA: No. 5 sez: Need More Input

As mentioned in the previous post, during testing of the 1401 compatibility of the IBM 1410 I discovered that console input was not working properly for the machine in either 1410 or 1401 mode. The 1411 CPU would accept the characters, but only the first was entered into storage (if that), and pressing Inquiry Release or Inquiry Cancel did not terminate the I/O operation. After some trial and error signal examination, I discovered that the E1 Register Full latch was “oscillating”, and the cause seemed to be a simultaneous set and reset signals.

In the original hardware, this was unlikely to occur, given multiple layers of logic gates, signal travel times on the backplane wiring, and so on. But in a simulation, or in an FPGA the combinatorial logic signals are implemented using look up tables (LUTs) making instantaneously simultaneous combinatorial signals a likely possibility.

Timing Diagram showing problem with E1 Reg Full being set and reset at the same time, resulting in an unstable latch.
Timing Diagram showing problem with E1 Reg Full being set and reset at the same time.

So, how to prevent that? The first, more or less obvious thing, was to condition one or both of the set and reset signals to give one or the other priority. I found that if I gave the reset signal priority (by inhibiting set when reset was active) that console output was negatively affected, because this change affected both input and output.

However, if I added an inhibit from the set signal to the logic block at 5A, so that set for just input had priority, the problem went away – I could type characters into the console and they were properly entered into memory.

But I also noticed that doing the fix that way I ended up with second pulse of +S SET E2 REG during the cycle. While this didn’t seem to cause any real problems, I was nervous about possible future effects. In addition, it left the E1 FULL signal active for longer than it needed to be.

First attempt to fix E1 Set/Reset Latch problem resulting in duplication of +S SET E2 REG
First attempt to fix E1 Set/Reset Latch problem resulting in duplication of +S SET E2 REG

While looking at ALD page, which generates signal +S SET E2 REG, I noticed another signal, delayed by 1 IBM 1410 clock pulse, +S SET E2 REG DELAYED. Feeding that into the logic block 5A on ALD page instead of +S SET E2 REG allowed an earlier reset of the E1 REG FULL latch to the time where it really should be happening, and prevented the extra +S SET E2 REG pulse from occurring.

Fix for E1 REG FULL latch problem by using +S SET E2 REG DELAYED
Fix for E1 REG FULL latch problem by using +S SET E2 REG DELAYED

I am a little concerned about the +S E CYCLE REQUIRED being inactive during Logic Gate A, but it doesn’t seem to be causing any problems so far.

However, there is still one remaining issue with console input. If I enter more characters than are allocated in the buffer (terminated by a Group Mark with a Word Mark), the M%T0xxxxxR instruction ends normally. But if I enter fewer characters or the exact number of characters expected, the instruction ends with an Instruction Check, I think because I CYCLE CTRL and E CH UNOVERLAP IN PROCESS are both active at the same time. In the CE instructional text manuals, this check is not present in the logic, however in the ILDs it is present. The question is whether the test should not be implemented the way it is (perhaps by adding some signal to the logic), or if it is just an inopportune appearance of a Error Sample pulse at that time.

IBM 1410 FPGA: We ain’t got no 1401 Overflow anymore?

The last issue that I had running the 1401 diagnostic (aside from Console I/O input working in neither 1410 nor 1401 mode) was “ERR ?3S” in diagnostic M011A, which corresponds to diagnostic location 07032 (the routine actually starts at location 06980). This is test RN111, the very last test in the diagnostic.

The diagnostic comment block says it all:


Trouble was, the overflow indicator was indeed off after executing the branch instruction at location 7016 (which branches to location 7899, which was set up to just branch right back to location 7020.) What is so special about the “Z”? Well, it turns out the “Z” is the d-character for a B(I)Z instruction – branch on overflow (a sample of which is at location 7027). But why should that ever be in the Op Modifier register for an unconditional branch instruction that has no “d” character?

Well, it turns out that the 1401 mode instruction readout often places a character from the address into the Op Modifier register, as noted in the IBM 1401-1410 Compatibility CE Instructional Manual, Figure 3B on page 9.

There were a few possibilities for this problem, and a few possible cures for this. In the end, some simulation runs demonstrated that the reset occurred because “Z” was indeed still in the Op Modifier register when the unconditional branch was set up.

Simulation trace showing the Overflow indicator being reset during readout of a Branch Unconditional instruction with "Z" as the last character of the address.
Simulation trace showing the Overflow indicator being reset during readout of a Branch Unconditional instruction with “Z” as the last character of the address.

There were several possible cures that might have fixed this, focused on the fact that in a normal B(I)d conditional branch the d character is read out later in the I cycle – so maybe one could reset the Op Modifier register after the address was read out and the following character had a word mark – indicating that the branch had not “d” character at all. But in thinking about it I wondered why this very specific test was in the diagnostic – and as the last test, which maybe meant this was an issue that was uncovered in the field (and perhaps only on machines with the Accelerator special feature).

The reset of the Op Modifier register is controlled on ALD Interestingly, a very relevant signal, +S CHAR TEST BRANCH OP CODE that this page says originates on page, does not show up on page as a destination. I had had to “add” that signal into the signal list when I came to page when I entered the data for that page into the database. Perhaps more interestingly, the Instructional Logic Diagram for this ALD, part of ILD Figure 26, shows the signal as instead being +S 1401 COND TEST OP CODE , and is designed to reset the Op Modifier register when:

  • +S 1401 COND TEST OP CODE is active AND
  • In 1401 Mode AND
  • The B Channel has a WM Bit (i.e., end of the instruction) AND
  • Logic Gate D AND
  • I Ring 8 Time

Well gee whiz… this was exactly the kind of signal I was looking for to fix this problem. So, to fix it, all I did was change +S CHAR TEST BRANCH OP CODE on the ALD to the one the ILD specified, +S 1401 COND TEST OP CODE, and the problem was cured, with no side effects causing other problems.

Simulation trace showing the reset of the Op Modifier register during I8 time during readout of an unconditional branch instruction.
Simulation trace showing the reset of the Op Modifier register during I8 time during readout of an unconditional branch instruction.

So this was presumably a case of either a) a mismatch between a page denoting it is for the ACC feature ( and the source page of which does not call out the ACC feature, or, perhaps, page being “down level” – not having a necessary ECO t fix this. When I did the change, I set up an “ECO” JRJ005 in the database.

With this, the 1401 diagnostic M011A runs to completion without errors, as does the 1410 CPU diagnostic CU01.

During this testing, however, I discovered an issue affecting both 1410 and 1401 mode: Console I/O Input does not work – the characters don’t seem to make it into “core”, and when Inquiry Release is pressed, the I/O operation does not complete. This could be something as simple as a support console software bug or, more likely, an issue in the interface between the 1415 console emulation VHDL and the 1411 CPU Channel, since 1415 Console Input during console control operations (setting addresses, memory data, etc. all seem to work mostly OK). Time will tell.

IBM 1410 FPGA: S’more SAR Instruction Issues

So, not the yummy treats, but a new problem that showed up with the SAR instruction.

The fix to ERR 60J was pretty easy. That was a gate for feature S10 – a 10K 1410 that needed removing (and its output replaced by a logic ‘1’) on page QED.

However, after fixing that, I then experienced an error near another Store A Address (SAR) instruction, at (just before) location 8624, exhibiting A Channel, Assembly Channel and Address Exit validity checks, with garbage in the B Address Register. However, when I ran the same instructions in the same place in the address space (but with memory otherwise all blanks) it seemed to work just fine. How could this be?

The first blind alley was either that the print chain used for the diagnostic listing printed the 1410 characters “?” and “!” as “&” and “-” respectively, or there was a bug in the listing version that was fixed on tape. So much for that hypothesis.

To figure this out it would be best if I could get it to fail under simulation (There is a scoping capability in the FPGA as well – but not as quick and easy to use.) As mentioned above, during initial testing for this problem, I just loaded the relevant instructions into the appropriate memory locations with memory from 10K up to 40K being blank characters and the failure did not occur. Further more, during testing I discovered that if I had only loaded the first 10K of the 1410 1401 mode diagnostic, M011, as the listing only went up to just under 9K, this problem also did not occur, and the only error ?3S (translated into address 07032). However, that diagnostic is ordinarily loaded from the 1410 diagnostic program TC50, and when I used the image that I have that goes up to 40K, all heck broke loose with the error noted above. I then changed my memory initialization to all ‘9’ characters aside from the instructions under test and was able to reproduce the issue under simulation.

This led me to an initial suspicion that something must be causing more than one B character register from “core” to read out simultaneously. Only one is supposed to read out at a time – and their outputs are OR’d together. If more than one read out at the same time, the results would be problematic. But how was this occuring?

After many simulation runs looking at various signals and what might be going on, I finally hit upon this one.

IBM 1410 1401 SAR Instruction Set / Reset Race with '9's in 10K-30K
IBM 1410 1401 SAR Instruction Set / Reset Race with ‘9’s in 10K-40K

Looking at the timing diagram one can see signal -Y MODIFY BY ZERO essentially “oscillating” starting shortly after 30.153 milliseconds. That in turn caused the Ten Thousands position to change quickly, resulting in the issues as that position is used to select among the B character registers from memory. That latch “oscillation” then in turn set up problems all over the place, particularly in the Address Channel.

Looking again at the same timing diagram, one might notice that +S ADDR MOD SET TO ZERO and +S RESET ADDR MOD CTRL LATCH are both active when +S RESET ADDR MOD LATCHES becomes inactive. Those two signals both impact the Modify By Zero CTRL latch at blocks 3A and 2A of ALD page, resulting in the signals trying to simultaneously set and reset that latch – a pair of cross connected NAND gates – a typical R/S latch. This is a big nono.

In my ALD page generation, these latches are recognized, and “D” flip flops are added after each gate involved. So instead of being undefined, in this kind of situation a kind of “oscillation” is set up at about 1/2 the FPGA clock speed of 100MHz (which is also the memory clock signal “MB 0 clka” in the diagram).

The general approach I took to fixing this was to either a) prevent a set during a time when the reset signal was present or b) prevent a reset during a time when the set signal was present.

To try the first approach, I added the +S ADDR MOD SET TO ZERO signal as an input to get logic block at 3C on page This was done directly in the VHDL – much quicker than puzzling out where to find/fudge a logic block to add to the equation and test – especially if, as in this case, the fix doesn’t work. So, apparently this situation really needed to do a Modify Address by Zero operation (which it did: this, like the previous problem, occurred while copying the contents of the A Address Register to the B Address Register.)

So, then I went to the other approach, (undoing the first one), which was to add the +S ADDR MOD SET TO ZERO signal in so as to inhibit a reset while it was active. That indeed fixed the problem, and the change to the ALD was very easy: all I had to do was add the +S ADDR MOD SET TO ZERO signal into the existing “wired OR” at ALD coordinate 4E, as “ECO” JRJ004.

As for the original 1410 implementation, this could easily be another case where the fast FPGA logic causes an issue that never cropped up in the real hardware.

After doing this, the diagnostic worked OK except for the ERR ?3S. (I have not yet tried the manual part of M011 – testing the sense switches, etc.).

Getting close…

IBM 1410 FPGA: 1401 Mode SAR Instruction

Having fixed the 1401 Store B Register instruction and gotten further in the 1410 1401 mode diagnostic program M011, it was time to look at the Store A Address Register (SAR) instruction again.

The CE Instruction materials say:

“Therefore the A address left from the previous operation must move to the BAR before the new A address reads in. This is done during a B cycle that occurs just after the Q-op is detected at I-op time.”

The first timing diagram, below shows that the +S RO A AR signal that presumably ought to be making the AAR contents available becomes inactive before the BAR is reset, so the BAR never receives valid contents – it ends up with invalid binary zeros. (In the 1410, the address registers contain 2 out of 5 code – and having no bits set at all is invalid.) The result was a number of errors, halting the CPU, as would be expected – B Channel, Address Channel, and B Character Select (because the resulting memory address was invalid, none of the 10K “core” modules was selected.

Timing diagram showing lack of A Address Register Readout while +S SET B AR is active, resulting in invalid B Register contents.
Timing diagram showing issue reading out A Address when setting B Address

There is a signal which looks like maybe it was intended to force the readout of the A Address Register – -S 1401 Q OP TRANS, however once the B cycle starts, the B Character register was cleared and so the signals that relied on – the “Q” character with at wordmark were no there once the B data register was reset early in the B Cycle.

This does not seem to be a race condition. Rather, I suspect it is resulting from the fact that some of the pages for the signals involved are for a 1410 with the accelerator feature, and some without. My hunch is that on a 1410 with the accelerator feature, all of the needed activities to copy the AAR to the BAR occur during the I OP cycle, driven by the -S 1401 Q OP TRANS signal. However, when I tried to force it that way, I was not successful.

To work around the problem, I added logic to ALD page (A Address Register Readout) to read out the AAR when signals +S 1401 MODE 1 AND +S STORE A AR OP CODE AND +S B CYCLE CONTROL are all active. The result was the timing diagram below (sorry that it is only half of the signals, but the important ones are there.) With that change, the +S RO AAR is active through the necessary part of the B Cycle so that the contents of the AAR are properly transferred to the BAR.

Timing diagram showing fix applied to ALD page to read out a register during the (first and only) B Cycle of the 1401 Store A Address Register (SAR) Instruction.
Timing diagram showing fix to page to read out AAR when setting BAR during B Cycle.

With that fix in place, the diagnostics mostly run but fail with console error message “ERR 601J”. So, on to the next fix…

IBM 1410 FPGA: (Address) Exit Stage Right

With the 1410 mode CPU running correctly, it was time to test out the 1401 side of things. The 1410 has a toggle switch, allowing the CPU to run as an IBM 1401 compatible with most 1401 programs. The 1410 and 1401 are similar, architecturally. The biggest difference is that the 1401 uses 3 character addresses, with the zone bits over the units and hundreds positions in order to address up to 16,000 characters, whereas the 1410 uses 4 character addresses, capable of addressing memory up to 100,000 characters.

The primary 1401 diagnostic is M011. Once I figured out a problem involving the 1401 addressing scheme, I turned my attention to the next failure: The Store A Address Register (SAR) instruction died a horrible death with B Channel, Address Channel and B Character Select Errors. That problem manifested as a failure to copy the A Address Register to the B Address Register for storing later. I tried for a bit to fix this first, but was not immediately successful, so I decided to try and NOP out the uses of SAR, that mostly had to do with storing the address of each test so it could print out a failure message.

Having done so, the next problem quickly cropped up: the partner instruction for the B address register, Store B Address Register (SBR) also failed – it is essentially the same as SAR, but without that first step of transferring the AAR to the BAR. And the failure error was different as well: an Address Chanel Exit error. The ALD for this circuit is . The ILD is on figure 59 at coordinate 2B – however there is also an error in that ILD. It shows the GateOff input to trigger DEZ as ground (the usual ground symbol). However, on the ALD, the F input it connect to M, which is -12 Volts, and in my scheme, that is logic 0. (Logic 1 being 0V).

The timing diagram below shows the timing issue. The B Address Register read out and validity check look like they are OK with respect to the Address Exit flip flop ACSET signal. However, the problem was that the VHDL for implementing the SMS card type DEZ has a 3 clock cycle “silo” for ACSET, so that the flip flop is not really set until 3 clock cycles after its ACSET input. In addition, there was no such silo for the other inputs. This silo was put in place to give the ACSET signal some noise immunity – so that a 1 cycle glitch would not set the trigger. But the fact that the other inputs did not have a silo meant that they were sampled 3 clock cycles (FPGA_CLK) after ACSET, and by that time the B Address Register Readout signal (PS_RO_B_AR, i.e. +S RO B AR) had become inactive.

Timing diagram for 1401 mode Store B Register instruction showing the delay in setting the Address Exit Check with respect to the readout of the B Address Register.
Delay in the Address Exit Check inputs with respect to the readout of the B address Register, resulting in an Address Exit Check.

The relevant VHDL looked like this:

        if(rising_edge(FPGA_CLK)) then
           if(DCRESET = '0' OR DCRFORCE = '1') then
              OUTOFF <= '1';
              OUTON <= '0';
              SSTAGE1 <= ACSET;
              SSTAGE2 <= ACSET;
              SSTAGE3 <= ACSET;
           elsif(DCSET = '0' OR DCSFORCE = '1') then
              OUTON <= '1';
              OUTOFF <= '0';
              SSTAGE1 <= ACSET;
              SSTAGE2 <= ACSET;
              SSTAGE3 <= ACSET;
              SSTAGE1 <= ACSET;
              SSTAGE2 <= SSTAGE1;
              SSTAGE3 <= SSTAGE2;
              if(GATEON = '1' AND SSTAGE2 = '1' AND 
                SSTAGE1 = '1' AND SSTAGE3 = '0') then
                  OUTON <= '1';
                  OUTOFF <= '0';
                elsif(GATEOFF = '1' AND SSTAGE2 = '1' AND
                  SSTAGE1 = '1' AND SSTAGE3 = '0') then
                   OUTOFF <= '1';
                   OUTON <= '0';               
               end if;
            end if;
        end if;
        end process;

Once I realized what was going on, the fix was pretty easy. Just add a 3 clock silo for the inputs as well as ACSET. I took the conservative approach, however, and created a separate special instance of SMS_DEZ.vhdl, called SMS_DEZ_SYNC.vhdl to use in the Address Exit validity check logic. This new implementation of DEZ would probably work fine across the board, but I am just using it in the one place, for now.

The timing diagram below shows that now the OUTON signal does not activate – no Address Exit Check, because now the inputs are sampled at the same time as ACSET, and those inputs are still active from the B Address Register readout.

Timing diagram for 1401 Mode Store B Register showing response after adding silos for all the inputs, and not just the clocks.
Timing diagram for 1401 mode SBR after fixes.

The relevant VHDL looks like this, for gate type SMS_DEZ_SYNC:

        if(rising_edge(FPGA_CLK)) then
           if(DCRESET = '0' OR DCRFORCE = '1') then
              OUTOFF <= '1';
              OUTON <= '0';
              SSTAGE1 <= ACSET;
              SSTAGE2 <= ACSET;
              SSTAGE3 <= ACSET;
              GON1 <= GATEON;
              GON2 <= GATEON;
              GON3 <= GATEON;
              GOFF1 <= GATEOFF;
              GOFF2 <= GATEOFF;
              GOFF3 <= GATEOFF;
           elsif(DCSET = '0' OR DCSFORCE = '1') then
              OUTON <= '1';
              OUTOFF <= '0';
              SSTAGE1 <= ACSET;
              SSTAGE2 <= ACSET;
              SSTAGE3 <= ACSET;
              GON1 <= GATEON;
              GON2 <= GATEON;
              GON3 <= GATEON;
              GOFF1 <= GATEOFF;
              GOFF2 <= GATEOFF;
              GOFF3 <= GATEOFF;
              SSTAGE1 <= ACSET;
              SSTAGE2 <= SSTAGE1;
              SSTAGE3 <= SSTAGE2;
              GON1 <= GATEON;
              GON2 <= GON1;
              GON3 <= GON2;
              GOFF1 <= GATEOFF;
              GOFF2 <= GOFF1;
              GOFF3 <= GOFF2;
              if(GON3 = '1' AND GON2 = '1' AND GON1 = '1' AND GATEON = '1' AND
                SSTAGE2 = '1' AND  SSTAGE1 = '1' AND SSTAGE3 = '0') then
                  OUTON <= '1';
                  OUTOFF <= '0';
                elsif(GOFF3 = '1' AND GOFF2 = '1' AND GOFF1 = '1' and GATEOFF = '1' AND 
                  SSTAGE2 = '1' AND SSTAGE1 = '1' AND SSTAGE3 = '0') then
                   OUTOFF <= '1';
                   OUTON <= '0';               
               end if;
            end if;
        end if;
        end process;

With that out of the way, I could run M011 diagnostics quite far into the tests, until it needed to use the SAR instruction for more than just tracking the test address.

IBM 1410 FPGA: 1401 Mode “Zoned Out”

Having fixed the problem with the space, I continued to test out the IBM 1410 in 1401 mode. At first, I had thought that it was getting quite far in the diagnostic M011 – it would error out with the I register (instruction counter) at 6029. I spent the better part of a day chasing down an apparent problem with the Store A Address Register (SAR – opcode Q) instruction at the indicate location. However, when I placed a halt at the test before that, it still failed at the same place. How could that be?

So, I decided it would be worth the trouble to run the 1401 diagnostic in Instruction Fetch/Execute mode (I/E). The problem became apparent much more quickly than I had anticipated. After halting at the halt and branch instruction at location 2018, it ended up trying to fetch an instruction at a location near 06020. (My memory is just a little fuzzy on when that flying leap actually occurred, and I don’t have the output anymore.)

As you may know, the 1410 has 5 digit addresses, whereas the 1401 used 3 digit addresses plus zone bits to address up to 16K of memory. It was clear that somehow the translation from the 1401 style address to the 1410 address register had gone awry.

A little digging reminded me that there was one page of the automated logic diagrams (ALDs) associated with this translation, part of what is called the “Zone Adder” that was missing – page After some time working with the xsim simulator under Vivado, I began to suspect a problem with my re-creation of the logic from that page.

  • Input “A”: -S ZONE ADDER A A DOT B A
  • Output “O”: +S A NOT A DOT B A DOT B BITS EVEN

The output name is sufficiently complicated that the equation for this is not self-evident. Looking at the ILD figure 55, it looks like the following should be the equation:

O <= NOT A and NOT B — The NOT A is because A, above is -S not +S

Interestingly, page is not referenced at all in the 1410 1401 Compatibility manual on page 7. On both the ILD and that manual, this signal is routed to the middle of a logical OR gate labeled “Zone Adder Carry”, which is laid out on page

Regardless this VHDL caused the problem noted above. However, I had also penciled in on the ILD an additional inverter, which would be the signal without the added inverter (double negative and all that…). For that, the equation would be:

O <= NOT(NOT A and NOT B)

And it actually takes one less “fudged” gate, because the SDRTL provides this result outright.

It turns out that removing that inverter from the logic for that ALD (and thus implementing this second equation) cured that particular problem, both under xsim and running on the FPGA. But, at least superficially, this makes it look like it does not match the ILD — at least at first.

However, and finally, examining the page to which this signal is routed,, one sees that it is routed to a logical OR (physical NAND) gate where -S / -B active inputs generated the +S active output. So if one takes the two together, the end result is such that it does match the ILD.

The diagnostic didn’t get very much further, however, and now fails at location 2032 on a SAR instruction, similar to the failure after the “flying leap” problem, just at a different location. SAR is interesting in that it first copies the A Address Register to the B Address Register, and that is apparently failing.

IBM 1410 FPGA: “Space Cadet”

No, not that kind of cadet. Unlike the IBM 1620, the IBM 1410 does have adder circuits for doing addition (and multiplication and division as well). Instead, this issue had to do with the IBM 1415 space function.

I had thought that the principle instruction diagnostic, CU01, was working perfectly, but it was not quite so. I had noticed that even after finishing the diagnostic, I kept getting space characters sent to the PC support program, but figured that was just a software bug somewhere. However, when I started to run IBM 1410 1401 compatibility diagnostic M011, it stopped typing its instructional message to switch to 1401 mode on the console when it hit the first space character.

After some sleuthing, I discovered that the console typewriter logic never asked the channel for the character after the space – it just kept sending that space to the console typewriter again and again and again.

As one might expect, the issue turned out to be in the console typewriter Selectric emulation VHDL code. I had miss-interpreted the signal -V CON PRINTER SPACE NO to just involve console input via the space bar. a closer look at the related automated logic diagrams (ALDs) made me realize that in fact this was also the Selectric’s way of telling the 1411 that the space process had been completed, and that it really had nothing to do with input from the space bar.

At first I tried to just use the relevant states of the finite state machine (FSM) that controls spacing. That did not work right, however, because that same FSM also controls back-spacing. Qualifying the logic signal to only be active during a space, but not backspace, operation filled the bill.