Emulation issues and roadblocks
- For modern techniques and methods used for emulation, see High and low-level emulation#Future Outlook.
- For ways to support or contribute to an emulation or similar project, see Support emulation projects.
placeholder text
Platforms that need attention
[edit | edit source]- Main article: Category:Partially emulated
- There are several systems that require more attention from the emulation community. While multiple emulators may exist, none of them appear particularly promising. These systems for which a PC cannot yet fully replicate the experience, because emulators are incomplete, or lack support for key hardware features, peripherals, or specialized components. As a result, certain software or functions remain usable only on original hardware.
- Gizmondo
- Apple iPod
- Apple iOS
- PlayStation Mobile
- GP2X, GP2X Wiz
- Pokitto
- Thumby
- Xbox 360's Avatars, HD DVD player, XBLIG and Kinect
- PSP's XrossMediaBar (XMB) and UMD Video, UMD Music, UMD-PG
- CD-i DVC — No existing emulator fully supports CD-i games with full-motion video due to the absence of DVC emulation. Implementing DVC emulation would significantly enhance CD-i emulation compatibility, and also enabling proper/full support for CD-i Digital Video and Video CD 1.1 on PCs as well. Good news is, there are promising progress for DVC emulation on both CDi_MiSTer core and CD-i Emu.
- Game Boy (Color) hardware feature implementations
- Game Boy Advance hardware feature implementations
- DS hardware feature implementations and enhancement features
- Enhancement features for Original Xbox
- ACPI PC hardware support implementations and enhancement features
- Enhancement features for J2ME
- Apple Pippin
- Symbian
- Xbox One (X/S)
- Windows XP
- Mac OS X PPC
- Zeebo and BREW
- Nuance
- Official emulators
Home Computers
[edit | edit source]Windows XP
[edit | edit source]- Main article: Windows NT 5.x emulators
For PC games up to roughly 1997, emulators such as 86Box and DOSBox#Forks accurately recreate the hardware environment of the era. Beginning around 1998, however, PC games increasingly depended on hardware-accelerated 3D graphics, SSE instructions, and substantially more CPU performance. A fully cycle-accurate implementation of an entire 2001-2006 Windows XP-era PC including the CPU, chipset and graphics hardware is impractical due to the computational cost of faithfully reproducing that generation of x86 systems.
Instead, modern PC emulation generally relies on either hardware-assisted virtualization (such as KVM or WHPX) or dynamic binary translation (DBT). Hardware-assisted virtualization executes guest code directly on the host processor and therefore provides substantially higher CPU performance, but requires compatible host hardware and introduces a dependency on the host operating system's virtualization facilities. Generic dynamic binary translation engines such as QEMU's TCG/MTTCG provide a flexible software-only foundation but generally do not deliver sufficient performance in their standard form. Nevertheless, projects such as Xemu, RPCS3 and Cemu demonstrate that carefully optimized, workload-specific dynamic recompilers can achieve practical performance even for systems that very complex.
But unlike a typical console emulator, a Windows XP emulator could target the same general x86 instruction set used by modern desktop processors. Although privilege levels, segmentation, paging, exceptions, self-modifying code and other architectural differences still require translation, guest instructions can often be mapped to relatively efficient native host code. Rather than attempting cycle-accurate execution, a specialized recompiler could instead optimize frequently executed code paths through techniques such as larger translation blocks, aggressive block linking, profile-guided optimization and guest operating system-aware fast paths. The performance target is substantially lower than native execution on modern processors; many games and applications released during this period were designed to run on hardware comparable to a 32-bit Intel Pentium 4 "Prescott" CPU with SSE3 support.[1] Consequently, the software emulator only needs to match this legacy performance while minimizing translation overhead. The most significant remaining technical hurdle for the 2001–2006 era is efficient 3D graphics acceleration; a DirectX 9.0c Shader Model 3.0 GPU would be the perfect target to run the vast majority of software from this generation. While projects such as QEMU 3dfx demonstrate that application-level API pass-through is feasible, these solutions typically rely on guest-side wrapper libraries, manual configuration, and external translation layers. Other projects including SoftGPU, Gallium Nine, and experimental virtio-gpu implementations explore different approaches to accelerating legacy graphics APIs. A fully integrated software emulator combining a high-performance dynamic recompiler with a paravirtualized graphics architecture remains an area of active research rather than an established solution.
Approach 1: User-Space API Pass-Through
[edit | edit source]Historically, developing complete virtual graphics drivers for closed-source legacy Windows environments (particularly Windows 9x and XP) has been significantly more complex than implementing user-space API forwarding. Projects such as QEMU 3dfx therefore adopted an API Pass-Through (or Forwarding) approach.[1]
- This approach injects custom user-space library stubs into individual game directories or system locations to intercept graphics API calls before they reach the guest's virtual display driver.*
- For Direct3D acceleration, this method relies on a complex manual "ddthru" configuration. Users must modify Windows ACPI settings through Device Manager, install proxy libraries (such as
ddraw.dll,ddrawwq.dll, anddsound.dll) into%SYSTEMROOT%\system32, and use tools such aswine-getto deploy matching WineD3D wrapper DLLs into individual game directories. Because the guest desktop is rendered through a virtual 2D display driver such as BoxVNT, which provides no native 3D acceleration, the pass-through layer intercepts graphics API calls before they reach the virtual display device and forwards them to host-side rendering backends. - When an application invokes a supported graphics API, the injected libraries intercept those API calls and forward them to compatible host-side wrapper libraries (such as dgVoodoo2, nGlide, or Mesa), where they are translated into graphics commands executable by the host GPU.
- Drawbacks: Because interception occurs above the graphics driver layer, compatibility depends on successfully replacing or proxying application-visible libraries. The resulting configuration process is often complex, requiring manual installation of wrapper DLLs, per-game configuration, and system modifications. Compatibility can vary between titles, particularly for applications that rely on undocumented behavior or interact directly with graphics resources outside the expected API pathways. In addition, implementations frequently rely on host virtualization technologies (such as WHPX or KVM), introducing another software layer whose behavior and timing characteristics are outside the emulator's direct control.
+───────────────────────────────────────────────────────────────────────────+
| GUEST OS (Windows XP) |
| |
| [ Manual Device Manager Tweak ] ──► (Switches Kernel to ACPI PC) |
| |
| [ 2D Desktop / GUI Pipeline ] ────► [ BoxVNT Virtual Display Driver ] |
| |
| [ Target Retro Game Folder ] |
| ├── game.exe |
| └── [ Injected Stubs ] (wine-get: d3d8.dll / d3d9.dll / ddraw.dll) |
| │ |
| ▼ (Intercepts graphics API calls before BoxVNT) |
| [ Global System Directory ] (%SYSTEMROOT%\system32) |
| └── [ Proxy Wrappers ] (ddraw.dll, ddrawwq.dll, etc.) |
+─────────────────────────────────┬─────────────────────────────────────────+
│
▼ (Forwards intercepted API calls)
=====================================================================
HOST VIRTUALIZATION BOUNDARY
=====================================================================
│
▼
+─────────────────────────────────┴─────────────────────────────────────────+
| HOST OS / EMULATOR |
| |
| [ QEMU API Pass-Through Backend ] |
| │ |
| ▼ (Routes calls to host wrapper libraries) |
| [ Translation Layer ] (dgVoodoo2, nGlide, Mesa, etc.) |
| │ |
| ▼ |
| [ Host GPU ] ─────────────► [ Emulator Display Window ] |
+───────────────────────────────────────────────────────────────────────────+
Approach 2: Paravirtualized GPU Device
[edit | edit source]An alternative architectural approach is to virtualize the guest graphics device itself rather than modifying individual applications or replacing system libraries. Following the same general design philosophy as modern paravirtualized GPU implementations (such as VirtualBox's VBoxVGA or QEMU's VirGL), the guest OS exposes a virtual graphics adapter whose driver presents a standard graphics device to Windows while forwarding rendering commands to the emulator. Unlike existing virtual GPU implementations, however, this approach specifically targets legacy Windows 9x/XP graphics APIs within a software-emulated environment.
- Guest-side virtual graphics driver: The guest installs an OS-compliant virtual graphics driver consisting of a User-Mode Driver (UMD) and a Kernel-Mode Miniport Driver (KMD). Applications continue using the original Microsoft Direct3D runtime (such as
d3d8.dllord3d9.dll) without modification. Rendering requests naturally flow through the registered virtual graphics device instead of requiring per-game DLL replacement or API hooks. - Shared-memory command transport: Rather than performing expensive hypercalls for every rendering operation, the emulator exposes a shared-memory command queue (such as a ring buffer). The guest graphics driver serializes rendering commands, resource updates, and synchronization events into this queue, allowing the host to consume them asynchronously with minimal virtualization overhead.
- Host-side virtual GPU renderer: The emulator reconstructs the guest rendering state from the command stream and executes it using a dedicated virtual GPU renderer implemented on top of a modern, low-level explicit graphics API backend such as Vulkan. Unlike application-level wrapper projects, the renderer operates entirely within the emulator rather than inside the guest operating system.
+───────────────────────────────────────────────────────────────────────────+
| GUEST OS (Windows XP) |
| |
| [ Retro Game ] |
| │ |
| ▼ |
| [ Microsoft Direct3D Runtime ] |
| (d3d8.dll / d3d9.dll) |
| │ |
| ▼ |
| [ Virtual Graphics Driver ] |
| (UMD + Kernel Miniport Driver) |
+─────────────────────────────────┬─────────────────────────────────────────+
│
▼
=================================
SHARED MEMORY COMMAND QUEUE
=================================
│
▼
+───────────────────────────────────────────────────────────────────────────+
| HOST OS / EMULATOR |
| |
| [ Command Queue Consumer ] |
| │ |
| ▼ |
| [ Virtual GPU Command Decoder ] |
| │ |
| ▼ (Unified Internal Rendering Representation) |
| [ Virtual GPU Renderer ] |
| │ |
| ▼ (Shader Translation / Backend Interface) |
| [ Vulkan / Direct3D 12 / Metal Backend ] |
| │ |
| ▼ |
| [ Host GPU ] ─────────────► [ Emulator Display Window ] |
+───────────────────────────────────────────────────────────────────────────+
Unlike application-level API forwarding, the virtual graphics driver does not simply relay Direct3D API calls to the host. Instead, it implements a complete virtual graphics device whose command stream serves as the interface between the guest operating system and the emulator. The guest driver translates Direct3D operations into commands understood by the virtual GPU, while the emulator reconstructs those commands and executes them using a modern graphics backend. This avoids the considerably more difficult task of emulating the register-level behavior and rendering pipeline of a physical GPU while still allowing Windows and applications to interact with what appears to be standard graphics hardware.
Since rendering is performed entirely on the host GPU, completed frames generally do not need to be copied back into the guest frame buffer unless required for compatibility (such as guest software that reads the front buffer directly). Instead, the emulator presents the rendered output directly within its own display window while maintaining the guest-visible synchronization state. Consequently, the primary challenge is implementation complexity rather than raw GPU performance. A complete virtual graphics device must faithfully virtualize Direct3D state management, resource creation, explicit synchronization primitives, presentation, capability reporting, shader handling, and device-loss behavior so that Windows and its applications observe behavior consistent with physical hardware. To manage this complexity across multiple host operating system ecosystems (beyond just Windows machines), a modern implementation could rely on a unified internal rendering architecture. Under this approach, the virtual GPU command stream is decoded into an implementation-defined rendering representation describing pipeline state, resources, synchronization primitives, and draw commands independently of any particular host graphics API. Shader programs are translated separately into an appropriate intermediate representation for the selected backend, such as SPIR-V for Vulkan, or into DXIL or Metal Shading Language (MSL) for Direct3D 12 and Metal. This separation allows the same rendering architecture to target multiple host APIs while minimizing duplicated implementation effort. Legacy fixed-function features such as table fog or texture combiners that no longer exist on modern programmable GPUs can be reconstructed through generated shader programs or specialized rendering passes rather than game-specific compatibility hacks. Likewise, legacy implicit synchronization semantics can be mapped onto modern explicit primitives such as timeline semaphores and fine-grained synchronization barriers provided by contemporary graphics APIs.
Compared to application-level API forwarding, this approach offers several advantages:
- Pristine Guest Environment: The original Microsoft graphics runtime remains entirely untouched, avoiding error-prone per-game DLL replacement, manual system tweaks, and compatibility hacks.
- Universal Virtual Pipeline: Graphics virtualization occurs at the device-driver level, allowing all legacy software, system components, and multimedia applications to use the exact same accelerated rendering infrastructure automatically.
- Architectural Hardware Abstraction: The virtual GPU provides a stable, modern hardware abstraction for the guest while the emulator translates its command stream directly into explicit APIs, eliminating the need to emulate obsolete register-level structures or specific physical GPU architectures.
- Low-Overhead Command Flow: Shared-memory command transport paired with modern explicit timeline synchronization minimizes host-guest messaging overhead and prevents VM exits or hypercall stalls.
- Centralized Rendering Architecture: All translation logic, shader recompilation pipelines, and backward-compatible fixed-function approximations reside entirely within the host-side emulator engine, creating a highly organized, modular, and maintainable subsystem.
For more information about PC emulation and their reverse engineering;
- DOSBox Pure: MMX Instruction Set Support issue page
- DOSBox-X: 3D Graphics Cards that aren't emulated yet
- DOSBox-X: KVM and Hyper-V issue page
- DOSBox-X: virtual GPU adapters such as VMware SVGA/SVGA II, VBoxVGA issue page
- softgpu: https://github.com/JHRobotics/softgpu/issues/22, https://github.com/JHRobotics/softgpu/issues/12
- Gallium Nine
- virtio-gpu: https://github.com/virtio-win/kvm-guest-drivers-windows/issues/841 https://github.com/virtio-win/kvm-guest-drivers-windows/pull/943 https://docs.mesa3d.org/drivers/venus.html
- VBoxVGA and 86Box: VBoxVGA implementation.
- PCem: Future graphics card emulation
- Pull request for Bochs: Improve glxgears support for GeForce
- nt5src - Source code of Windows XP (NT5).
- Other projects and emulated systems that have helped, or may potentially help, PC emulators in the future;
- PlayStation 3 emulators - Due to RSX GPU
- PlayStation 4 emulators - Same architecture
- PlayStation 5 emulators - Same architecture
- Xbox emulators - Due to Celeron, NV2A GPU, and is based on modified Windows NT 3.5[2]
- Xbox 360 emulators - Due to Xenos GPU and is based on Windows 2000
- Xbox One emulators - Same architecture
- Xbox Series X and Series S - Same architecture
- macOS emulators - Using same GPUs and Intel CPUs
- PC-based arcade hardware - Uses PC components and run on Windows or Linux
- Wrappers
- Compatibility layers
- Hypervisor's Virtual GPU Adapters for legacy operating systems
- libcdio, picogus, Duckstation's cd image ccd, cd image cue, 86Box' aaru support, Ymir's low-level cd block and PCSX2's CDVD - Could be beneficial for implementing reading capability for capable disc image formats.
- ymfm
Mac OS X and macOS
[edit | edit source]PowerPC
[edit | edit source]Currently, no 3rd-party Macintosh emulators support hardware graphics acceleration, due to certain CPU instructions left unimplemented in their upstream PPC softcores. This means no GLIDE, RAVE, or OpenGL. Fortunately, though as was generally the case in every platform of the period significant visual and feature differences exist between the two, the majority of Mac-exclusive software using these APIs also included software fallback renderers. It is however possible to pass through a real GPU to a PowerPC Mac being emulated by QEMU provided you have one that's compatible with OpenFirmware
x86
[edit | edit source]Despite an x86-based Mac is very similar to a general non-Apple PC in hardware architecture (which makes Boot Camp and Hackintosh possible), it still contains Apple proprietary hardware such as closed-source EFI BootROM, System Management Controller (SMC) and later T1/T2 security chip that either requires bypassing or emulation in order to run macOS. macOS also contains countermeasures that prevent it from being run on a non-Apple PC such as the infamous Don't Steal Mac OS X.kext.
Another big hurdle is that macOS only contains drivers for hardware components used in actual Mac computers, which means a large portion of PC users who use different hardware combinations than actual Mac computers need to bypass, patch, or port drivers for their hardware in order to boot macOS and promote it to a usable state, and might still with crippled functionalities due to no or imperfect solutions to drive some of the hardware.
ARM
[edit | edit source]Hurdles in emulating ARM-based Mac are basically the same as emulating iOS devices: Apple's proprietary M1/M2 SoC which has little to no documentation, and hardened security measures inherited from iOS devices. However if Apple discontinues support for x86 in XCode, there will be no way to code modern iOS apps on other platforms or use macOS apps in general. If an ARM macOS emulator is sucessful, modern iOS emulation will be "cracked" too (apart from Corellium though).
Home Consoles
[edit | edit source]Pioneer LaserActive
[edit | edit source]The LaserActive Project wishes to document all LaserActive media. On their FAQ page, they have this to say about the possibility of creating a LaserActive emulator:
Emulation of the LaserActive, if attempted at all, would be an incredibly difficult task – due to the hybrid nature of the system's hardware (utilizing Sega/NEC hardware in synchronization with the unique LD player hardware) and the analog-digital composite image (analog video background, digital in-game graphics generated by said Sega/NEC hardware).[3]
Emulator developer Nemesis has made an effort to dump the games for the system (except for porn games).[4] Copies of the games sent to him were supposed to be dumped and then returned.[4]
ares has made the most significant progress to date, featuring active support for a majority of the LaserActive's expansion PACs.
Philips CD-i
[edit | edit source]The accurate emulation of the Philips CD-i (Compact Disc Interactive) system presents several significant challenges for developers. These complexities have historically limited the availability and completeness of CD-i emulators. The primary difficulties can be categorized as follows:
- Limited Demand: Compared to highly popular gaming consoles and computer systems (such as the NES, SNES, PlayStation series, or Xbox series), the demand for a fully functional CD-i emulator is relatively low. This lower interest translates into a smaller pool of developers willing to invest the substantial time and effort required for such a complex project.
- Hardware Proliferation and Variation: The CD-i platform saw a wide array of hardware releases. There are at least 32 known distinct CD-i player models, many of which underwent major internal revisions. Nearly every model featured some degree of hardware difference. These variations ranged from minor (e.g., the Philips CD-i 550 model essentially being a CD-i 450 with a pre-installed Digital Video Cartridge) to complete mainboard overhauls (e.g., the CD-i 220 model is known to have at least five revisions, each with a different mainboard). Compounding this, a diverse range of peripherals was available for CD-i players. Consequently, for an emulator to be considered "fully functional," it would ideally need to accurately replicate the behavior of every known player model and peripheral.
- Scarcity of Technical Documentation: While foundational aspects of the CD-i standard and its players are understood – such as their common reliance on the Philips SCC68070 CPU (a specialized variant of the Motorola 68000) or its derivatives (like the MC68341 Integrated CD-i Engine), and the identification of many common support chips – detailed public documentation for critical components is scarce. CD-i players utilized numerous custom integrated circuits (ICs) that were often exclusive to the platform. The lack of public datasheets and technical information for these custom chips means that emulating their precise behavior often requires extensive and time-consuming reverse-engineering. The development of CD-i Emu, currently the most feature-complete CD-i emulator, exemplifies this challenge. Its developer, known as CDiFan, has made a significant personal investment of time, financial resources, and effort over nearly two decades. This includes amassing an extensive personal collection of CD-i hardware and software, which has reportedly been instrumental in the complex reverse-engineering process necessary to understand the functions of various player components. The developer has stated that CD-i Emu represents over 120,000 lines of hand-written code. This substantial individual effort highlights the barrier posed by the lack of public documentation. A core aspect of CD-i operation that influences emulation is that the entire player hardware must be simulated, not just the software environment for a game or application. This includes the player's boot sequence into its operating system shell (the menu). Therefore, emulators require a ROM image (firmware dump) from an original CD-i player to function, even for running "base-case" titles that do not require specialized add-on hardware. Further complicating emulation efforts is the optional Digital Video Cartridge (DVC). The DVC provided two main benefits: an additional 1.5 MB of RAM and, more significantly, the hardware capabilities for decoding and playing back MPEG-1 video. This video processing was handled by yet more custom chips, which also suffer from a lack of comprehensive public documentation. The DVC contains its own ROM, distinct from the player's main ROM, which is necessary for emulating titles that utilize its FMV/video playback features (including CD-i Digital Video and VCD support).
As of early 2025, DVC MPEG-1 emulation support is largely in a proof-of-concept stage and is primarily, if not exclusively, found in CD-i Emu. Other emulators generally do not yet offer DVC functionality.
A notable consideration in the CD-i emulation landscape is that the source code for CD-i Emu is not publicly available. While this is the prerogative of the author, it means that prospective contributors to CD-i emulation who wish to build upon existing advanced work may be unable to do so directly with this codebase. Instead, new efforts often necessitate starting an emulation project from the ground up. The significant undertaking of managing an open-source project, particularly for a developer working largely solo as a hobby, is a factor in such decisions. Furthermore, the pool of developers possessing both the requisite skills and the specific interest in CD-i emulation may be inherently limited, potentially mitigating the impact of a closed-source approach on overall development velocity within the niche. The developer of CD-i Emu offers a full version of the emulator for a fee, a decision understandable in light of the extensive, long-term personal investment involved in its creation.
Despite these hurdles, progress in CD-i emulation continues, albeit concentrated. CDi_MiSTer core and the developer of CD-i Emu is actively working on improving the emulator.
PlayStation
[edit | edit source]Rendering quirks
[edit | edit source]

The PlayStation takes shortcuts when rendering as a result of making most of the hardware available. This can cause some quirks that become even more noticeable when the internal resolution increases.
Polygons may jitter as a result of low-precision, fixed-point (to the native resolution) math, but this is mostly unnoticeable at native resolutions. Emulators that can increase the internal resolution of games have attempted to fix this.
There is no z-buffer in the hardware. This can cause things like polygons to pop over others; the limbs of Tekken characters are a good example of this. It is theoretically possible to implement this, but it wouldn't be accurate to the hardware.[5][6]
When perspective correction isn't applied to textures, certain viewing angles can make them distorted, more so when an object is near the edge of the camera up close. Tenchu: Stealth Assassins is particularly infamous for texture distortion, most noticeably in the
training level where floor textures appear wavy at oblique angles; developers usually mitigate this by adding polygons to walls, floors and other scenery, but at the cost of filling the PlayStation's geometry rate. In DuckStation, at least, this problem has been solved.
Many PlayStation games dither to varying degrees due to having a low color depth. On most TVs, this dithering would blend in order to make new colors and smooth gradients. Plugin-based emulators usually have graphical plugins that use a 32-bit color depth, which removes dithering, while software-rendered plugins and emulators tend to retain it. While higher color depth can be considered an enhancement since it results in less noise and smooth gradients, some think of dithering as seen on real hardware as added shading and texture, especially on untextured polygons. The emulators that use software rendering and can increase the internal resolution of games can retain dithering for the shading and texturing aspect, and it's made more subtle by shrinking the artifacts.
Less-notable games using special peripherals
[edit | edit source]ZXE-D: Legend of Plasmalite requires the use of a special peripheral to play the game. It is a robot with connectable parts that plug into the memory card slot, which is then replicated in the game. No emulator has ever focused on it, probably due to a number of reasons:
- It's not a well-known game.
- No third-party controller and memory card connector has gotten support from emulators the same way that Nintendo's official GameCube controller adapter has.
- To emulate this purely in software means it has to be reverse-engineered, which can take a bit of time.
CD format
[edit | edit source]PS1 games use the CD-ROM XA (eXtended Architecture) format, which is based on CDi and allows developers to use both CD-ROM and CD-DA (audio) tracks on the same disc.[7]
Certain image formats and CD dumping methods don't support this format correctly and end up with the CD-DA tracks missing or corrupted, hence no audio. The ISO format in particular only stores the content of a CD-ROM filesystem and cannot store CD-DA tracks at all. So it's generally a very bad idea to use ISO for PS1 games (even though it should work for single-track games). Even running an ISO file based on a PS1 game (i.e., Ridge Racer, Tomb Raider 1-2) with CD-DA audio may often cause an emulator such as ePSXe and other peers to freeze and/or hang up, especially during loading of a saved data or in-game levels and transactions.
- However, a mounted image (Using Daemon Tools), running from a CD-ROM or using the Mooby2 plugin can solve these CD-DA problems. The MDS/MDF format is good for backing up the CD-DA, audio-equipped PS1 games. However, the best Image format for any PS1 game is the CUE/BIN format. The reason being that almost all the burning programs can read it, and the relevant patching programs (i.e., PPF-O-Matic) are designed for that format. Clone CD images in IMH/CCD format provide another ideal option as it has virtually the same structure as CUE/BIN format (The IMH file is the same data as a BIN file at the hex level). However, the available burning programs are largely unable to read Clone CD format. ISObuster and ImgBurn are good tools for some of the aforementioned notes.[8]
- The European regional versions of many PS1 games tended to have copy-protection embedded, so they could cause problems with backing up images. These game backups could cause hangs or show a black screen infinitely in a typical emulator. An easy way to avoid that problem is to try the US regional versions. Another way is to patch it using a .sbi file which contains the protection information needed to run the game, see #CD player section for more information about this.
- The perfect solution possible, at least for the ePSXe emulator—and perhaps other similar plugins-based emulators—would be (No virtual drive mounting needed)::
- 1. Use the Mooby2 2.8 CD-ROM plugin, and uncheck 'subchannel reading' in the plugin's settings.
- (Just in case: also make sure 'repeat all cdda' is checked, and 'cdda volume' is set to something like 50 or 60, or else you won't hear anything.)
- 2. Launch the game with File → Run CDrom (browse, find and select your CD image as the window pops up.)
- It's recommended you use the Eternal 1.41 sound plugin with default settings along with this. The SaPu CDRom Plugin v.1.0/1.3 is good if you're running official CDs. It especially works well with Daemon Tools Lite or Alcohol 120% when mounting an image.
- If running ePSXe or a similar emulator on an old Windows OS (E.g., 9x, ME, 2000, XP), use ForceASPI to initialize the ASPI layer (For your disc drive) and a plugin like P.E.Op.S. CDR Version 1.4 plugin or similar. Then set the plugin to "W2K/XP IOCTL scsi commands" before running your PS1 CDs.
For more information about PlayStation hardware and its reverse engineering;
- MVG:
Why PlayStation 1 Graphics Warped and Wobbled so much,
How the Sony PlayStation PS1 Security was defeated,
Why did the PlayStation 1 have so much Dithering?,
How the Sony PlayStation Net Yaroze DevKit brought Indie Game Development to Consoles - Rodrigo Copetti: PlayStation Architecture analysis
Technology Connections: Sony's Clever but Flawed PlayStation Copy Protection--And How They Might Have Fixed It- PSDevWiki: PlayStation 1
- consoledev: PlayStation 1
- psx-spx.consoledev.net
- no$psx: Playstation Specifications
Sega Saturn
[edit | edit source]- This section was copied from Wikipedia in 2014. For an up-to-date explanation, see Sega Saturn § Technical specifications
The complexity of the system has made the creation of a proper emulator for it rather difficult.
One very fast central processor would be preferable. I don't think all programmers have the ability to program two CPUs — most can only get about one-and-a-half times the speed you can get from one SH-2. I think that only 1 in 100 programmers are good enough to get this kind of speed [nearly double] out of the Saturn. "Yu Suzuki reflecting upon Saturn's Virtua Fighter development[9].
The Saturn had technically impressive hardware at the time of its release, but its complex design, with two CPUs and six other processors, made harnessing this power difficult for developers accustomed to conventional programming. The biggest disadvantage was that both CPUs shared the same bus and were unable to access system memory at the same time. Making full use of the 4 kB of cache memory in each CPU was critical to maintaining performance. One example of how the Saturn was utilized was with Virtua Fighter's use of one CPU for each character[9]. Many of the Saturn's developers, such as Lobotomy Software programmer Ezra Dreisbach, found it difficult to develop for compared to the PlayStation because of its more complex graphics hardware[10]. In order to port Duke Nukem 3D and PowerSlave to the Saturn, Lobotomy Software had to almost entirely rewrite the Build engine to take advantage of the Saturn's unconventional hardware[10]. Third-party development was initially hindered by the lack of useful software libraries and development tools, requiring developers to write in assembly language to achieve good performance. During early Saturn development, programming in assembly could offer a two to fivefold speed increase over C language[9]. Sega responded to these criticisms by writing new graphics libraries which were claimed to help make development easier[11]. These libraries were presented as a new operating system by Sega of Japan[11].
Unlike the PlayStation and Nintendo 64 which used triangles as their basic geometric primitive, the Saturn rendered quadrilaterals with forward texture mapping. This proved to be a hindrance because most of the industry's standard design tools were based on triangles, with independent texture UV coordinates specified per vertex. One of the challenges brought forth by quadrilateral-based rendering was problems with textured surfaces containing triangles. To make a triangular-shaped object, rendering had a fourth side with a length of zero. This technique proved problematic as it caused texture distortion and required careful reworking to achieve the desired appearance—Sega provided tools for remapping textures from UV space into rectangular tiles. These complications can be seen in the Saturn version of Tomb Raider[10].
For more information about Sega Saturn hardware and its reverse engineering;
- Rodrigo Copetti: Sega Saturn Architecture analysis
MVG: How the SEGA Saturn CD Security was defeated- PSDevWiki: PS4's Sega Saturn Emulation
LGR: Oddware - Diamond Edge 3D (nVidia NV1+Sega Saturn Ports)- yabasanshiro blog: new vdp2 emulation
Sega Dreamcast
[edit | edit source]Developer interest in Dreamcast emulation was previously hindered by the availability of the closed-source but "good enough" Chankast, and by less interest in the console relative to other 6th generation consoles. For the emulators that are either mature or maturing, a very large percentage of games work well, but some games still have problems and glitches.
For more information about Dreamcast hardware and its reverse engineering;
- MVG:
How the Sega Dreamcast Copy Protection Worked - And how it Failed,
The Sega Dreamcast 20 years later 9-9-99,
The Arcade Sega Dreamcast - Revisiting the Sega Naomi Arcade Hardware,
What happened to Windows CE on the SEGA Dreamcast? - Rodrigo Copetti's Dreamcast Architecture Practical Analysis,
The Original Xbox is the Sega Dreamcast 2?
PlayStation 2
[edit | edit source]Despite a large interest in sixth generation consoles as a whole and the PlayStation 2 in particular, it remains one of the more difficult consoles to emulate accurately. The PlayStation 2's main processor, the Emotion Engine (EE), is built around the 64-bit R5900 running at 294MHz (299MHz on later revisions). Although derived from the MIPS architecture, the R5900 is not a standard MIPS III or MIPS IV implementation; instead, it is a heavily customized design featuring proprietary Multimedia Instructions (MMI), non-IEEE-754 floating-point behavior, and numerous architectural extensions unique to the PlayStation 2.
Architecturally, the R5900 exposes the standard MIPS coprocessor interface consisting of COP0 (system control), COP1 (Floating-Point Unit), and COP2 (Vector Unit 0). Beyond the CPU core, the Emotion Engine also incorporates numerous dedicated hardware engines, including Vector Unit 1 (VU1), the Image Processing Unit (IPU), Vector Interface Units (VIF0/VIF1), the Graphics Interface (GIF), the Direct Memory Access Controller (DMAC), on-die instruction and data caches, and 16KB of scratchpad RAM. These components operate largely independently, communicating through DMA and dedicated internal interconnects while synchronizing only at specific execution points. Accurately reproducing their execution order, synchronization behavior and timing requires considerable computational resources.
Furthermore, the proprietary extensions and execution semantics of the R5900 differ substantially from conventional x86 and ARM processors, creating significant challenges for dynamic recompilation. Beyond instruction translation itself, many PlayStation 2 titles depend on subtle interactions between otherwise independent hardware blocks. Consequently, interrupt timing, DMA scheduling, VIF/GIF packet processing and bus synchronization are often just as important to compatibility as correct instruction execution. The PS2's heavily parallel design frequently leads to the misconception that its emulation should scale linearly across modern multi-core CPUs. In practice, many hardware components require extremely precise synchronization, limiting how aggressively emulator developers can distribute workloads across threads without introducing timing inaccuracies or race-condition-related bugs.[12]
Vector Units (VU0 / VU1)
[edit | edit source]The Emotion Engine derives much of its computational performance from its two programmable Vector Units. Within emulation, these processors represent one of the architecture's primary computational bottlenecks, much like the SPUs in PlayStation 3 emulation. Because they execute independently of the main R5900 core while maintaining strict synchronization requirements, reproducing their behavior accurately without sacrificing host performance remains one of the emulator's most demanding tasks.
- VU0 can operate either as the R5900's COP2 vector coprocessor or independently through its own microprogram execution mode. It was commonly used for matrix mathematics, collision detection, physics calculations (which was vital for the physics-driven design trends of the sixth generation) and general gameplay logic.
- VU1 is a fully programmable vector processor dedicated primarily to geometry processing. Fed through VIF1, it transforms and prepares vertex data before forwarding command streams to the Graphics Synthesizer through the Graphics Interface (GIF). This forward-thinking programmable geometry pipeline contrasted sharply with contemporary PC graphics cards from NVIDIA and ATI, which relied on rigid, fixed-function pipelines before eventually adopting programmable shaders years later.
Both Vector Units receive data through dedicated Vector Interface (VIF) processors, which unpack DMA streams, perform data conversions and execute microcode commands before dispatching work to the VUs. Correctly reproducing VIF behavior (including DMA interactions, unpacking rules and synchronization semantics) is essential for both rendering accuracy and game logic.
PCSX2 maps many Vector Unit operations onto host SIMD instruction sets such as SSE and AVX to improve performance. One of the project's largest architectural improvements was replacing the older SuperVU implementation with the significantly more accurate microVU recompilers. Additional optimizations such as Multi-Threaded VU (MTVU) and "Instant VU1" were introduced to offset the increased computational cost. However, because the EE's floating-point implementation and vector arithmetic differ substantially from standard IEEE 754 behavior, efficiently translating VU programs still requires handling numerous hardware-specific edge cases.
Floating-Point Accuracy & The "SoftFPU" Solution
[edit | edit source]A major hurdle in PlayStation 2 emulation is accurately reproducing floating-point behavior. Neither the Emotion Engine FPU nor the Vector Units implement IEEE 754 arithmetic; instead, they exhibit unique behavior for underflows, overflows, rounding and exceptional values such as NaNs and infinities. Even minor inaccuracies can result in exploded geometry, broken collision detection, corrupted animation or failed game logic. [2]
Historically, PCSX2 relied on configurable clamping and rounding modes to approximate hardware behavior. While these database driven per-game compatibility hacks resolved many visual and gameplay issues, they did not faithfully reproduce the hardware.[13][14][15][16]
To eliminate these approximations, developers introduced accurate software implementations of the hardware FPU.
- SoftFPU (Interpreter): A software implementation that reproduces EE floating-point behavior at the bit level, aims to eliminate many legacy game-specific floating-point hacks. While highly accurate, its interpreted execution incurs a substantial performance penalty, making it impractical as the default floating-point backend for general emulation, although it remains useful for debugging and titles with known floating-point accuracy issues.
- SoftFPU Recompiler (JIT): A long-term approach that translates SoftFPU semantics directly into optimized native machine code. By preserving accurate floating-point behavior while retaining dynamic recompilation performance, aims making it practical as the default floating-point backend for general emulation. Developer DiscoStarslayer has already experimented with this concept within his pcsx2-reliquary fork.[3]
Subsystems & Security
[edit | edit source]- IOP (I/O Processor): A MIPS R3000A core (originally the PlayStation 1 main processor) running at 36.864 MHz or 33.8688 MHz. It manages peripheral communication, file I/O, and backward compatibility. In later slim revisions (SCPH-7500X and onward), it was replaced by a PowerPC 405 core running a MIPS emulation layer.
- USB Controller: Provides USB 1.1 connectivity for peripherals such as keyboards, mice, microphones, EyeToy cameras, storage devices and specialty controllers. Although the controller itself is well understood, accurate emulation depends on faithfully reproducing USB device behavior and timing. Modern versions of PCSX2 support a broad range of USB peripherals through integrated device emulation.
- IEEE 1394 (i.LINK): Early PlayStation 2 models included an IEEE 1394 interface intended primarily for multiplayer connectivity. Only a small number of commercial titles utilized the port, making it a relatively low priority for emulator development compared to other subsystems.
- DEV9C: The expansion interface controller responsible for the network adapter and hard disk drive (HDD) systems. Emulating its sub-registers is documented extensively across historical progress reports.[17][18]
- CDVD: The PlayStation 2's CD/DVD subsystem is responsible for reading game data from optical media and exposing it to software through the I/O Processor (IOP). The CDVD hardware works alongside several system modules such as `CDVDMAN` and `CDVDFSV`, allowing games to access files, stream assets, and read disc metadata. While optical drive emulation is generally considered a more mature area of PlayStation 2 emulation than the Emotion Engine, Vector Units, or Graphics Synthesizer, accurate CDVD behavior remains important for compatibility. Some titles continuously stream data from disc during gameplay, requiring the emulator to provide data at rates and timings consistent with software expectations. Improper handling of disc reads can lead to loading issues, audio synchronization problems, or streaming-related bugs in affected titles. The PlayStation 2 supported multiple media formats, including CD-ROM, DVD-5, and DVD-9 discs. Internally, PCSX2 emulates the system software interfaces used by games to communicate with the CDVD hardware rather than attempting to model every physical characteristic of the optical drive at a mechanical level. Modern versions generally provide highly compatible CD/DVD emulation, and CDVD behavior is no longer considered one of the primary obstacles to PlayStation 2 emulation.
Media Type Typical Capacity Emulation Considerations CD-ROM ~650–700 MB May require preservation of raw sector layouts and auxiliary disc data depending on the title. DVD-5 ~4.7 GB The most common PlayStation 2 format and generally straightforward to emulate. DVD-9 ~8.5 GB Dual-layer media requiring correct handling of layer transitions and disc layout information.
- Emotion Engine peripherals
- IPU (Image Processing Unit): A dedicated hardware MPEG-2 macroblock decoder used primarily for full-motion video (FMV), home media playback, and real-time texture decompression. Because the IPU operates asynchronously alongside the main CPU core, matching its exact decoding throughput and signaling timing is vital. Edge-case and minor bugs in IPU emulation still persist within PCSX2 (skipped or stuttering FMVs, out-of-sync audio during cutscenes, or total system lockups when a game attempts to initialize a movie sequence).
- SPU2 (Sound Processing Unit 2): A dedicated dual-core audio processor handling digital sound effects, streaming ADPCM audio, and real-time reverb processing. Maintaining tight synchronization loops between the SPU2 and the main CPU (Emotion Engine) represents one of the architecture's complex emulation hurdles.
- System Controllers & Security
- MechaCon: A dedicated security microcontroller responsible for console authentication, boot security, optical disc authentication, and coordinating security features such as MagicGate memory card authentication and KELF decryption. Because portions of its operation rely on proprietary cryptographic material, complete emulation presents unique legal and technical challenges.[19][20]
- MagicGate: Sony's authentication and encryption technology used primarily by PlayStation 2 memory cards. Community projects have implemented varying degrees of MagicGate support, although these generally require user-supplied cryptographic material dumped from original hardware. See the PS2's DVD player and Konami Python 2 sections.
- Syscon: A dedicated system controller responsible for power management, the real-time clock, thermal monitoring, and coordinating system startup and shutdown. Most commercial software interacts with Syscon only indirectly through the BIOS.
Graphics Synthesizer (GS) & paraLLEl-GS Solution
[edit | edit source]The Graphics Synthesizer (GS) acts completely differently from traditional graphics card architectures. Commands reach the GS through the Graphics Interface (GIF), which arbitrates multiple rendering paths and packet streams originating from the Emotion Engine and VU1. Correctly emulating GIF packet processing, state tracking, and path interactions is necessary for accurate rendering behavior. Crucial to feeding the GS is the Direct Memory Access Controller (DMAC), which routes data packets across the system bus. On real hardware, games frequently relied on massive, precisely timed bursts of data to transfer vertex textures and geometry data without stalling the processors.
Rather than utilizing a conventional fixed pipeline or complex shader cores, the GS achieved its results through raw, uncompressed fill rate power. It used a massive 2,560-bit internal data bus hooked directly to 4 MB of embedded DRAM (eDRAM), pushing an unprecedented 48 GB/s of bandwidth. This allowed developers to bypass standard hardware bottlenecks and implement intricate visual anomalies such as real-time frame buffer read-modify-write operations, which allowed for visual effects that contemporary PCs struggled to reproduce like the heat-haze distortion in Gran Turismo 3.
Translating this extreme bus width and eDRAM behavior into high-level emulation (with the GSdx renderer) using hardware APIs like DirectX, OpenGL, or Vulkan historically forced PCSX2 to rely on lots of hacks (such as offset hacks, skipdraw functions, and frame-buffer blending approximations). While PCSX2 eventually abandoned its legacy plugin architecture entirely, and internal core GS emulation has significantly improved in recent years with introducing robust solutions for notoriously difficult hardware behaviors like complex alpha blending and render-to-texture targets[21][22], some accuracy and compatibility issues remain. This ongoing reliance on game-specific hacks creates a cumbersome maintenance burden for developers and testers similar to clamping and rounding modes situation, who must constantly update and manage the database-driven compatibility database. On top of that, a notable subset of titles still strictly require a pure CPU Software Renderer to avoid game-breaking visual bugs, forcing a heavy reliance on the host CPU's single-threaded performance, significantly increasing hardware requirements while stripping away modern visual enhancement options such as high-resolution upscaling.
The introduction of paraLLEl-GS represents a major step toward addressing this fundamental issue. Similar to other low-level compute renderers for other projects, paraLLEl-GS reconstructs the GS inside Vulkan compute shaders instead of forcing it through a traditional rasterization pipeline. This approach achieves the absolute precision of a CPU software renderer while simultaneously providing upscaling, super-sampling, and high-performance execution on mainstream GPU hardware. It has been integrated directly into custom standalone builds and the LRPS2 Libretro core.[23]
CRT Output Video Quirks
[edit | edit source]- Main article: Shaders, presets, and filters#6th and 7th Generation (PS2, GameCube, Xbox, Wii, Xbox_360)
The PS2 frequently leveraged standard-definition CRT video techniques to save memory or compensate for performance limits. Techniques included aggressive dithering patterns, low color depth channels, inter-field blurring (proto-FXAA), non-standard vertical resolutions and continuous interlacing. When outputted onto high-definition flat panels, these features result in noticeable pixel combing and a loss of visual characteristics of the PlayStation 2.[24] Consequently, modern emulation depends heavily on enhancement implementations like post-processing layers, advanced deinterlacing algorithms and comprehensive shader injection frameworks like `librashader` to simulate those visual characteristics. Projects like paraLLEl-GS's CRT simulation aim to natively handle most of these cleanly.[25]
For more information about PlayStation 2 hardware and its reverse engineering;
- FOSDEM 2021 - The PlayStation 2: From Emotion to Emulation, Celebrating 20 Years of Reverse Engineering
- MVG:
Why was the Sony PlayStation 2 so hard to develop games for?,
How the Sony Playstation 2 Security Was Defeated,
Was the PS2 "Emotion Engine" over hyped? - Rodrigo Copetti's PlayStation 2 Architecture Practical Analysis
- ps2tek: Documentation on PS2 internals
- PSDevWiki: PlayStation 2
- Govanify: Implementation matters: PS2 weirdness and Path Two Rendering
- emudev: Dynarec
- fobes.dev
- (Reddit Thread) ELI5: Why do PS2 emulation be like that?
- Implicit Conversions: The Origin Story - From Self-Taught Developer to Emulation Expert
- PCSX2: Blog
Xbox
[edit | edit source]
The Xbox is infamous in the emulation scene for being the worst case of false advertising. For the projects currently available and active, there is a high barrier to entry for the effort involved, and it is the same reason why consoles using off-the-shelf hardware (or reused hardware) are easier to emulate. To users, being "basically a PC" and "x86-based" is a selling point despite that not being the case, as the Xbox has a number of proprietary elements that are nothing like standard PC hardware (like the eighth-gen "x86-based" consoles). Many aspects of the Xbox's architecture aren't openly documented, making it a major pain to figure out.[26][27][28][29][30] For example, the APU; one of two sound processors on the MCPX southbridge chip of the Xbox chipset, is incredibly powerful and uses complex processing steps that are difficult to figure out using clean-room reverse engineering.
Original Xbox emulator development took a long time to show major results, but thanks to the Cxbx-Reloaded and xemu teams, current efforts are now making a real difference.
For more information about the Xbox system and its reverse engineering;
- XboxDevWiki; for Xbox hardware documentation.
- Rodrigo Copetti: Xbox Architecture - A practical analysis
- hawk - Open Source Recreation of the Xbox Live Communicator for Original Xbox
- Microsoft Xbox Live docs
Code Not Magic: Archive Formats on the Xbox: Why and How with BLiNX 2- lib86cpu project
- MVG:
Original Xbox Emulation on the PC,
Original Xbox Emulation on the PC,
Xbox System-Link works across four console generations,
Revisiting Original Xbox Backward Compatibility (Fusion) on the Xbox 360,
Secrets of The Scene: How Cracking Groups Ripped Original Xbox Discs,
The Original Xbox is the Sega Dreamcast 2? - CXBX-Reloaded Discord server, xemu Discord Server (For general and development discussions on OG Xbox emulation, especially for xemu, Cxbx-Reloaded and any legacy emulators.)
- Personal Remarks about the Xbox Emulator (Fusion) by Michael Brundage
- Digital Foundry:
Xbox Series X: Auto HDR Mode Tested - What Works and What Doesn't
Xbox 360
[edit | edit source][Xenos] was a playground for experiments — it was developed near the end of the Direct3D 9 era, but still before Direct3D 10, and contained many features not standardized or even available at all on the PC, but when they ended up on the PC, the actual implementation could be significantly different; it also included completely unique features. […] Contrarily to a common misconception, the Xbox 360 [isn't] just a “DirectX 9 box.” It essentially contains a [tile-inspired] mobile-like GPU with much more raw power than a comparable mobile GPU. If you compare the registers of the Xenos and the Qualcomm Adreno 200, you can see that most of them are the same, as they are almost the same GPUs — the Adreno 200 was called the AMD Z430 before having been acquired by Qualcomm and was even referred to as the "mini-Xenos"!"
-Triang3l[31]
Despite being one of the most popular seventh gen home console, due to requiring many resources as well as the hardware not being properly documented yet[32], Xbox 360 emulation development has unfortunately lost momentum in recent years, with updates becoming less frequent. That, plus the fact that Microsoft's own implemented official emulation (Fission) of the system through the Xbox One and Series S/X ended with a November 2021 update. Fortunately, Xenia is making slowly but surely progress on that front.
I wouldn't say that Xenia has developers, we're just a bunch of community members with enough skills to do something. […] It is easier to slowly fix the emulator than write GUI, and I personally prefer having more games working than GUI.
-Gliniak
For more information about Xbox 360 system and its reverse engineering;
- Rodrigo Copetti: Xbox 360 Architecture Analysis
- Xenon Wiki
- XenonLibrary
- consolemods: Xbox 360
- Free60 Wiki
- emoose: xbox-reversing - Information & parsers for some under-documented Xbox360 structures/file formats (STFS/GDFX/XDBF/XEX...)
- libfreenect - Drivers and libraries for the Xbox Kinect device on Windows, Linux, and OS X.
- rexdex: recompiler and references list
- XenonRecomp and XenosRecomp
- I Code 4 Coffee - Ryan Miceli: Hacking the Xbox 360 Hypervisor Part 1: System Overview
- InvoxiPlayGames: research and reverse engineering notes/utilities relating to the Xbox 360
- Discord: Xenon and Xenia (For general and development discussions about Xbox 360 emulation)
- Mesa gallium R300~R500
- Specs are the most Xenos related in terms of registers; the closest is the Adreno 200 registers from Qualcomm's Code Aurora Forum release (that
drivers/mxc/amd-gpu/yamatodirectory in some Linux kernel forks). For the shader unit though, there are various specification versions in the exhibits at https://portal.unifiedpatents.com/ptab/case/IPR2015-00325 but they all are very preliminary. Many shader instructions are documented at http://web.archive.org/web/20100423054747/http://msdn.microsoft.com:80/en-us/library/bb313877.aspx but without the encodings. Also http://fileadmin.cs.lth.se/cs/Personal/Michael_Doggett/talks/unc-xenos-doggett.pdf for texture formats. https://www.slideshare.net/blackdevilvikas/next-generation-graphics-programming-on-xbox-360 for tessellation. R600 has some similarities, but it's more for conceptual referencing rather than copying and pasting. - Open-Source "Terakan" Vulkan Driver For Radeon HD 6000 Series Shown On Windows - Vitaliy Kuzmin "Triang3l": TeraScale GPUs working on Vulkan and leveraging the Mesa codebase.
- Aleksandra Uvarova: Realm of gaming experiments: potential developer errors in emulator creating
- Microsoft Xbox Live docs
- Xbox Connected Storage Manager - Accessing games using Xbox Live's save data requires authorization for the 'TitleStorage' service. This requires a device authenticated token and user token. However, the device token originally went through a Microsoft SOAP-based stage which required more effort than it was worth. Instead, using the 'wincred' storage was helpful as this is where the relevant Gaming Services on Windows caches tokens. This application to make the process more clean and easier.
- MVG:
Xbox 360 Emulation on the PC with Xenia takes a huge step forward,
Why Microsoft switched from Intel to Power PC for the Xbox 360,
The Story of Xbox 360 PartnerNet Game Leaks,
How a Mini drill tool defeated security on the Xbox 360,
How the Xbox 360 Hypervisor Security was Defeated,
Why YOU need a Modded Xbox 360 in 2018,
The Xbox 360 is still awesome in 2019,
Xbox 360 Blades Dashboard,
MVG: Any Xbox 360 can now be hacked with just a USB Flash Drive - Digital Foundry:
Xbox Series X: Auto HDR Mode Tested - What Works and What Doesn't,
FPS Boost For Xbox 360 Games,
Xbox Series X Backwards Compatibility Tested
PlayStation 3
[edit | edit source]PlayStation consoles were always notorious for system complexity. Sony's technology being developer-unfriendly makes it emulator-unfriendly as well, and RPCS3's steep system requirements prove it. Even if done properly, an LLE approach would be performance suicide, as some things just have to be abstracted enough to get high framerates in games.
Sony has never released an official PS3 emulator or native backwards compatibility for the PS4 or PS5. Instead, it offers select PS3 titles through cloud-based streaming on PlayStation Plus Premium. The primary technical challenge is the PS3's Cell Broadband Engine architecture, which differs significantly from the x86-64 architecture used in the PS4 and PS5 (especially considering the PS4's very weak hardware even at the time of its announcement, let alone its release). This makes accurate and performant software emulation considerably more difficult. While the PS5's hardware seems sufficient (as some independent experiments have shown some success running PS3 code through custom emulation efforts)[33][34], the prevailing narrative still falls back on the old assumption that achieving broad compatibility would just be too big of an engineering hurdle. Sony has opted for cloud streaming (which runs games on actual or virtualized PS3 hardware in data centers) rather than investing in a full native emulator for consumer devices. Additional factors likely include development and long-term maintenance costs, although these maintenance costs are often claimed by some to be a major issue when they are not actually a huge factor. Other potential reasons may stem from the difficulty in justifying the complex copyright and licensing situation for hundreds of old titles, diminishing returns for a relatively niche audience (based on Sony's experience with previous generations' backwards compatibility through PSN titles),[35][36] and potential political or investor pressure to avoid re-releasing older games that could be perceived as controversial under today's Overton window. On top of that, there is a strong monetary appetite for remakes and remasters (which often leads to poor releases, heavy censorship of the original games, and turning them into soulless re-releases aimed at younger audiences, delisting the original and unaltered versions of the game from digital storefronts) sold at full retail price instead of affordable offering emulation software. Despite these hurdles, the PlayStation 3 emulation scene (much like the Switch emulation scene) possesses two major advantages. First, unlike many proprietary "black box" systems, the Cell architecture was thoroughly documented by IBM. Furthermore, the RPCS3 project has benefited from over a decade of continuous development; since its early stages, it has maintained a dedicated donor base that provides the consistent financial support.
There are two major bottlenecks at play:
- Cell Broadband Engine - consists of two architectures that developers have to program for; PowerPC, and... whatever the SPEs really are; and you have a great formula for high system requirements, SPU hardware environment is the furthest thing from a x86 PC processor. "Cell Broadband Engine" (i.e. the PS3 CPU) leaned into SIMD with the SPUs recklessly, ease of programming be damned, but it broke records in 2006. Four pipelines of 512-bit wide ALUs per core is an absolute bonkers amount of computational capability. The main issue is that SPU code is stored as data blobs anywhere the game shoved it into: main executable constants, resource files, generated on the fly...anything goes, and it’s impossible to extract before it is submitted to SPEs for processing (same with the RSX shaders). Another half is that a way SPU are utilised in later games is a sort of microservices with context switching and load balancing (i.e several microtasks code can be uploaded/replaced/switched into single SPE memory at runtime during one frame cycle of game logic). Like SPURS for example. Old style SPE programming from early games with fixed systems bound to specific cores and not changed since works well with static recompilation. Unfortunately, this way was suboptimal for games and developers quickly went into "microtasks" design. SPEs are closer to VUs from the PS2 than a GPU. They're a SIMD cluster, don't be fooled by their apparent similarity to GPUs. GPU are low throughput but very wide. SPEs are also wide, but not nearly as much so. However, their individual thread throughput is insane even compared to a something like an RTX 4090. It's not possible to beat SPUs 1:1 (it's ALL vector, it doesn't have scalar registers at least not general-purpose ones), they have 128 registers and very low latency SRAM, almost no memory fetches and everything is async. Although AVX-512 comes close in performance (at 5+ GHz). GPUs on the other hand are around 10-100x slower, but that's just because of how their cores are designed and the fact that SPU kernels are optimized to run in much smaller groups. There's too much working against emulation at 3.2 GHz rate since most SPU instructions need many instructions on PC (like dozens in some cases), so the PC side needs to be an order of magnitude faster.
- RSX (Reality Synthesizer): The PlayStation 3 GPU went unemulated for a long time, simply because of how many components were undocumented; the RSX Reality Synthesizer is a custom-designed chip similar to the GeForce 7800 GTX developed by Nvidia specifically for the PlayStation 3. It's not well-documented, and developers have to figure out how it displays graphics and graphical effects. Without access to Nvidia's resources, which would normally be included with an SDK, this is very difficult.
- Something of note is that this GPU was also managed by two different memory units with very disparate frequency speeds; 1) 256 MB of GDDR3 RAM clocked at 650 MHz with an effective transmission rate of 1.4 GHz, and 2) up to 224 MB of the 3.2 GHz XDR main memory via the CPU (480 MB max).
In practice, smaller devs use the PPE most of the time, but AAA use everything what PS3 had. It took an eternity for AVX-512 to arrive, with Intel releasing their first implementation only in 2016; but wide availability in consumer grade PCs only started with AMD's Ryzen 7000 series in late 2022. Fortunately, most of the optimizations in RPCS3 still apply for AVX2, e.g., the 512bit checksum is still much faster than a full comparison, and the LTO, rotated checksum, and the other optimizations added also apply for machines without AVX-512. The RPCS3 developers use ahead-of-time recompilation via an LLVM. RPCS3 is not just compiling the code it runs, it also needs to compile a real-time environment simulator e.g. the 128x128bit register file, LS SRAM, the very weird memory flow controller, etc.
For more information about PlayStation 3 hardware and its reverse engineering;
- MVG:
Why is the Sony PlayStation PS3 so hard to emulate?,
Why was the Sony PlayStation 3 so hard to develop games for ? - Zygal Studios:
Why was the PS3 Difficult to Develop Games For? - Modded Warfare:
PS3 Jailbreak Tutorials
Alexandro Sanchez: FOSDEM'22 - PlayStation 3 Emulation- Rodrigo Copetti: PLAYSTATION 3 Architecture Practical Analysis
- psdevwiki: PlayStation 3
- Whatcookie:
How does Static Recompilation differ from Emulation?,
whatcookie: The most efficient way to do nothing,
Why is PS3 emulation so fast: RPCS3 optimizations explained,
It took 5 years to make this code 11.8 times faster, Why Is AVX 512 Useful for RPCS3?,
How to uncap framerates,
Why Intel and AMD couldn't play LittleBigPlanet together and
RPCS3 developer optimizing code in RPCS3. - RPCS3's progress report August 2020: Since intel dropped TSX due to security reasons, RPCS3 will use TSX-FA/TSX Force Abort on CPUs with new microcode and this will result potential regressions, good news is RPCS3 has improved non-TSX performance, because of this, even if your CPU supports TSX it will be disabled for RPCS3 by default.
- Ps3GhidraScripts - A collection of scripts for parsing PS3 executables with Ghidra.
- T2 SDE discord - ppc-aim-ps3 channel
- RPCS3: Blog, Discord,
YouTube. - Emulation books and articles
- Console-specific development wikis
- PSGL API
Xbox One
[edit | edit source]With the Xbox One, Microsoft had two important security goals in mind, to prevent piracy and cheating (these can be seen in the their
"Guarding Against Physical Attacks" video. To achieve this, much of the hardware was modified to prevent tampering. On the software side, the Xbox One used a new XVD (Xbox Virtual Drive) format to store its operating systems, SystemOS (runs a cut-down version of Windows), HostOS (manages the other two) and GameOS (runs game titles). For the storing of Xbox One titles, the console used another format (XVCs or Xbox Virtual Containers) to store games on Blu-ray discs. With all this security, it became a challenge to homebrew the console. For technical Xbox One research, see the Xbox One Research Wiki.
At least part of the Xbox One's optical disc drive source code leaked in 2020 ("Damien's XDK leak", "XSec", "xsec.rar" leak). Damien confirmed this came from wack0's 2017 Microsoft hack. It is impressive how long the Xbox One held up compared to literally any other console in history. However, on May 15, 2024, baw released an Xbox One dumping exploit. This was used to dump games when Collateral Damage came out. Now, Xbox One games have been dumped and decrypted.[4][5]
It should also be noted that the vast majority of Xbox One games are also available on PC (similarly to PlayStation 4 (Pro), PlayStation 5 (Pro) and Xbox Series X|S situations in recent years), so there is increased lack of interest to emulate the console. Having said that, there are still a considerable number of games exclusive to those consoles, this includes games for both PlayStation 4 (Pro) and Xbox One (X|S) that haven't been ported and titles lacking enhanced/next-gen update for PC. See List of notable ports#Console multi-platform exclusives section for all of those games.
Running UWP apps without emulation
[edit | edit source]By going to X:\ and copying app files, users could dump a range of system packages such as the Xbox One version of the Microsoft Store. To run these apps, all a user needed to do was to change the application's information file, or AppXManifest from Windows.Xbox to say, Windows.Desktop as well as removing Xbox only parts of the manifest, and certain applications would run, but issues would occur, such as a lack of input. The same dumping methods don't work for important system packages or games, as they're placed in a more secure location and need compatibility layers to run.
For more information about Xbox One (X|S) system and its reverse engineering;
- Xbox One Research Wiki
- ConsoleMods: Xbox One
- Reddit Thread: "Explanation on Xbox One/Series emulation"
- Microsoft Xbox Live docs
- libfreenect2 - Open source Driver for Kinect for Windows v2 (K4W2) devices (release and developer preview). libfreenect2 does not do anything for either Kinect for Windows v1 or Kinect for Xbox 360 sensors. Use libfreenect1 for those sensors.
- Collateral Damage - Collateral Damage is a kernel exploit for Xbox SystemOS using CVE-2024-30088. It targets Xbox One and Xbox Series consoles running kernel versions 25398.4478, 25398.4908, and 25398.4909. The initial entrypoint is via the Game Script UWP application.
- Artifice - A custom tool designed to achieve privilege escalation autonomously for Xbox One Developer Mode.
- XDL Compiler
- EuroGamer - Xbox One backwards compatibility: how does it actually work?
835
similar video- WinDurango Discord
MattKC Bytes: Xbox One emulation is making INCREDIBLE progress in 2025
PS4
[edit | edit source]Due to the PS4's x86 architecture and FreeBSD-based operating system, emulators for the device will, by and large, be very unconventional. Despite the x86's instruction set being huge[37], a trait that would typically lead to years of development time by emulators, it opens the ability for hypervisor to do the heavy lifting, eliminating the need for a recompiler. In recent years many PlayStation 4 (Pro)-exclusive titles are now being ported to PC with enhancements, so similarly to PlayStation 5, Xbox One (X|S) and Xbox Series X|S situations this could lead to a decreased interest in development. Having said that, there are still considerable amount of games exclusive to those consoles, this includes games for both PlayStation 4 (Pro) and Xbox One (X|S) that haven't been ported and titles lacking enhanced/next-gen update for PC. See List of notable ports#Console multi-platform exclusives section for all of those games.
Reverse-engineering PlayStation 4
[edit | edit source]See these resources for reverse-engineering PlayStation 4[38];
- Modded Warfare:
PS4 Jailbreak Tutorials (9.00 or Lower)
- General
-
- Graphics
- PlayStation 4-specific
-
- CPU
- Intel® 64 and IA-32 Architectures Software Developer Manuals
- BIOS and Kernel Developer's Guide (BKDG) for AMD Family 16h Models 00h-0Fh Processors
- Revision Guide for AMD Family 16h Models 00h-0Fh Processors
- Software Optimization Guide for AMD Family 16h Processors
- AMD I/O Virtualization Technology (IOMMU) Specification
- GPU
- Misc.
- PS4 Developer Wiki
- Linux kernel fork with PS4 support
- Implementation of the kexec system call for PS4
Console Hacking 2016 (33C3)- Open source projects (FreeBSD, AMDGPU drivers, etc.): FreeBSD system calls, GPUOpen-Drivers
- RPCSX: Discord, Blogs
- ShadPS4: Discord, Blogs
Xbox Series X/S
[edit | edit source]It should be noted that the vast majority of Xbox Series X|S games are also available on PC with ports of usually high quality (similarly to Xbox One and even PS4 and PS5 due to Sony's enduring will to port PlayStation exclusives to PC), so there is a greater lack of interest in emulating 8th and 9th-gen Xbox, especially compared to consoles with a rich backlog of exclusives such as the PS3 or Switch. Having said that, there are still a considerable number of games exclusive to modern consoles, this includes games for both PS5 and Series X|S that haven't been ported and titles (such as Devil May Cry 5, Dragon Ball Z: Kakarot, and some sports games) lacking next-gen versions for PC. See List of notable ports#Console multi-platform exclusives for more information.
Similar OS structure
[edit | edit source]Since the Xbox Series family uses the same operating system as the Xbox One, there is considerable intersection between Xbox One and Xbox Series X|S development and their reverse engineering. The Xbox One Research GitHub has a few interesting articles for the Xbox Series consoles.
For more information about the Xbox Series X|S system and its reverse engineering;
- Xbox One Research Wiki
- Reddit Thread: "Explanation on Xbox One/Series emulation"
- Microsoft Xbox Live docs
- Collateral Damage - Collateral Damage is a kernel exploit for Xbox SystemOS using CVE-2024-30088. It targets Xbox One and Xbox Series consoles running kernel versions 25398.4478, 25398.4908, and 25398.4909. The initial entrypoint is via the Game Script UWP application.
PS5
[edit | edit source]On top of PlayStation 4 emulation issues, there are additional obstacles for PlayStation 5 emulation such as Kraken, different custom APIs compared to prior generation and different GPU drivers to reverse-engineer all over again. As of this time, the PS5's APU can now be found as the AMD BC-250, which gives direct confirmation that the Playstation 5 uses a hybrid GPU, "Cyan Skillfish"/gfx1013 with no support for certain machine learning operations and with some desktop RDNA 2 features cut out such as Variable Rate Shading. Otherwise, it supports most RDNA 2 features and enhancements over RDNA 1. This does not mean the AMD BC-250 itself can help PS5 emulator development in any way.
In recent years many PlayStation 5 exclusive titles are now being ported to PC with enhancements, so similarly to PlayStation 4 (Pro), Xbox One (X|S) and Xbox Series X|S situations this could lead to a decreased interest in development. Having said that, there are still considerable amount of games exclusive to those consoles, this includes games for both PlayStation 5 and Xbox Series X|S that haven't been ported such as Astro Bot and Ghost of Yotei and titles lacking enhanced/next-gen update for PC See List of notable ports#Console multi-platform exclusives section for all of those games.
Reverse-engineering PlayStation 5
[edit | edit source]See these resources for reverse-engineering PlayStation 5;
MVG: The PS5 Jailbreak is here- Modded Warfare:
PS5 Tutorials
- General
-
- Graphics
- PlayStation 5-specific
-
- CPU
- N/A
- GPU
- N/A
- Misc
- PS5 Developer Wiki
- Open source projects (FreeBSD, AMDGPU drivers, etc.): FreeBSD system calls, GPUOpen-Drivers
- Reddit Thread: Has anyone done an nmap scan of the PS5
Nintendo Entertainment System
[edit | edit source]QD FDS support
[edit | edit source]Games dumped off the Famicom Disk System come into two major types:
- .fds format: Most common format. Ubiquitous in ROM sets (GoodSets, No-Intro). Omits some checksum data.
- .qd format (stands for QuickDisk): Only ever used in official Nintendo re-releases. Almost identical to FDS, except QD is a full dump with checksum data. May omit padding.
The checksum data in question would be checked at BIOS startup to verify the integrity of the image and whether it was tampered with, in which case it will throw an anti-piracy error. puNES added QD support in v0.111. As of now, no other NES emulators support the alternate, more complete dumps and fudging that check's result to always return a negative. To emulate a .qd image with those, stripping the checksum data with a custom script is needed.
Overscan
[edit | edit source]- Main article: Overscan

Several NES games need their overscan to be cropped to look proper. Unfortunately, there is no standard level of overcropping. Many games require different levels for the best results. For example, Super Mario Bros. 3 requires quite a bit of cropping. However, the same level of cropping will obscure the letters of the status bar in Castlevania games.
Color palette
[edit | edit source]- Main article: Famicom color palette
Unlike consoles such as the SNES, which natively generate their image in pure RGB, the Famicom normally generates and outputs an encoded NTSC video signal. This must then be decoded by the TV's built-in NTSC decoder, which means the resulting color palette often varies depending on the display's decoder. For this reason, NES games will appear to have different colors on different TV sets. To properly emulate this part of the NES experience, many Famicom emulators have a variety of different palettes to choose from.
The Wii and Wii U versions of Virtual Console use extremely dark color palettes. This is apparently not an accuracy issue, but rather an anti-epilepsy measure. For the Nintendo Switch Online service, the games were directly edited to remove seizure-inducing patterns, allowing it to use a normal palette.
PC Engine (TurboGrafx-16)
[edit | edit source]Color palette
[edit | edit source]
The color palettes generated by the PC Engine for Composite and RGB actually differ due to its own color tables being non-linear. This can result in colors ending up looking wrong or blended when the system is emulated or played in RGB. A composite palette was eventually made mathematically and with some extra tweaks from the PC Engine's RGB to YUV lookup table after its HuC6270 video chip had been decapped. This palette is used by default in the PC Engine core for the MiSTer[39]. It can be downloaded for use in other emulators and devices.
Nintendo 64
[edit | edit source]Nintendo 64 emulation is now decent. A lot of the major problems that N64 emulation had in the past have been fixed for quite some time now. The only catch is that the accurate emulators have higher system requirements. The main remaining problem is the lack of accurate cycle counting.
High-level vs. low-level graphics
[edit | edit source]One of the biggest hurdles to emulating the Nintendo 64 was the Reality Display Processor (RDP), which used a custom design that had to be fine-tuned to get higher performance out of the system using microcode. To emulate the RDP accurately, one would have to execute said microcode the way the RDP did, which differed from the PC graphics cards of the day. To complicate matters further, API standards available on PCs two decades ago were nowhere near as flexible as they're today. If you wanted to make an accurate GPU-accelerated RDP plugin in 2003, you simply couldn't with the APIs of the time (OpenGL 1.x and Direct3D 9). For the average user, hardware-accurate GPU acceleration would be out of reach for a long time.
UltraHLE offered a compromise. In contrast to earlier consoles (whose video chips, in hindsight, had been easy to render to the host CPU's framebuffer), performant RDP emulation had to take shortcuts, including programming around specific games' microcode to cleanly translate their graphics commands into API calls using Direct3D, OpenGL, and even Glide. With this, the theoretical system requirements plummeted, and the host graphics card could reproduce a functional equivalent rather than the exact method. This also gave way to prettier, higher-resolution graphics, though whether this is an improvement is subjective and a common point of discussion. Unfortunately, it proved to be hit or miss, owing to the nature of per-game microcode detection and having to tweak settings to prevent some games from running into graphical glitches.
Low-level RDP emulation was continually improved in that time, most notably by MESS up until its merger with MAME, where its RDP code was turned into a plugin by Angrylion. Compatibility-wise, Angrylion's RDP was considered flawless by the community. Though the reception wasn't as warm overall, since it ran only on the CPU and was thus painfully slow on mid-grade machines. A dozen forks attempted to bring the system requirements down, and the current incarnation that does so is Angrylion RDP Plus, using multithreading. Accurate low-level emulation would only come to the GPU in 2020 when a new version of the Mupen64Plus-based ParaLLEl libretro core was released containing a rewritten RDP plugin using compute shaders in Vulkan. Though it isn't a direct fork of Angrylion, Themaister says the Angrylion code was the central point of reference for developing the plugin,[40] meaning ParaLLEl uses the same strategies that Angrylion does to emulate the RDP while running on the host GPU (as long as said GPU supports Vulkan).
On the high-level side, gonetz and one or two assistants spent a large portion of development improving GlideN64's microcode handling throughout 2016-2018.[41][42] This means that
Factor 5's games are now working in high-level graphics mode.[43][44] Other games may still have issues with RDP quirks like frame buffer/depth buffer access (including issues with how the framebuffer is used as well as performance issues), VI emulation, and how combine/blending modes are emulated (such as noise issues and combiner accuracy).
-
Low-level emulation of Majora's Mask using SoftGraphic
-
High-level emulation of Majora's Mask using Jabo's Direct3D
The Nintendo 64 was the first consumer device to be able to filter textures when rendering 3D objects. However, unlike every console and PC graphics card made after the N64, its implementation of bilinear was primitive in that, to reduce strain on the system, it only used three samples as opposed to four, resulting in slightly jagged, asymmetrically filtered textures. Instead of faithfully applying this "imperfect" version of bilinear filtering, HLE plugins instead applied conventional bilinear filtering, interpolating straight from the source texture up to the output resolution the same way a PC game would. While that method is technically superior, it can result in textures that look even blurrier than they would on real hardware.
Another issue lies with the appliance of texture filtering per quad on static images, text, and sprites. Because each quad is filtered separately, this can cause some visual inconsistencies. Text and UI elements often look as though their edges cut off abruptly, and static images, such as pre-rendered backgrounds or menu screens, may look as though they're separated into squares (see images below; note how OoT's Quest Status screen appears to be divided into a grid). Some plugins allow the user to turn off texture filtering to remedy this, but, unfortunately, this also applies to textures in the game world, exposing their often low resolutions.
Modern emulators and plugins have taken some steps that help remedy these problems. For instance, GLideN64 now supports N64-style three-point texture filtering, which results in a more faithful look. It can also render at 320x240, which sidesteps the issues with filtered text, UI elements, and menu screens while still retaining texture filtering. Pixel-accurate plugins such as Angrylion and ParaLLEl-RDP don't have these problems at all.
-
Conker's Bad Fur Day copyright screen displaying issues with filtered text.
-
Ocarina of Time's menu subscreen displaying issues with filtering.
Timing issues
[edit | edit source]One of the biggest remaining problems in N64 emulation is the lack of accurate core timings, which, in practice, means games don't always run at the speed they would on real hardware. While this technically affects all games, the majority are only affected to a negligible degree. In some instances (particularly in Rare games) this can actually result in fewer framerate drops and lag, which can be seen as beneficial. However, some game engines actually depend on accurate timings for proper game behavior, and not emulating them properly can result in considerable to major issues. Some notable examples include the following:
- Intros and cutscenes playing too fast and not correctly syncing up with musical cues. Seen in GoldenEye's intro and Body Harvest's beginning cutscene.
- Gameplay demos running at hyper speeds. Earthworm Jim 3D is most notorious for this, though the main game itself is largely unaffected.
- Game physics not working properly due to being tied to framerate. A good example is Donkey Kong 64, which is programmed to boost the character's speed and momentum proportional to in-game lag (most likely to make up for the game's frequent framerate drops), which can be exploited for certain glitches and sequence breaks on real hardware. Emulators currently run the game too well and with too little lag, making most of these tricks impossible to pull off.
- Possibly the most affected game is Knife's Edge, which runs like it is on permanent fast-forward, making it all but unplayable. Messing with timing-related settings such as CounterFactor can mitigate this somewhat, but nowhere near enough to fix the issue.
Fortunately, tackling these problems has recently become a core focus of development in some N64 emulators, and attempts are underway to improve the situation. ares currently has the most accurate timings overall and already runs Earthworm Jim 3D's demos much better than other emulators. Meanwhile, simple64 has recently pushed various timing-related commits aimed at improving accuracy, and as a result, it may now be the only emulator that runs Donkey Kong 64 properly. As these efforts progress, it should be noted that a side effect of improved timings may be greater in-game lag. This shouldn't be seen as the emulator becoming slower, but rather as the emulator behaving exactly like the real hardware does, as many N64 games were notorious for framerate drops.
For more information about Nintendo 64 hardware and its reverse engineering;
- MVG videos about Nintendo 64
Kaze Emanuar: How we BEAT the Limitations that defined the N64s Artstyle- James Lambert:
How I optimized Portal to run on the Nintendo 64,
How I implemented MegaTextures on real Nintendo 64 hardware - Rodrigo Copetti: Nintendo 64 Architecture Analysis
- N64brew Wiki
Nintendo GameCube and Wii
[edit | edit source]For more information about Nintendo GameCube hardware and its reverse engineering;
- MVG:
How the Nintendo GameCube Security was defeated,
The Nintendo GameCube is still awesome - Games, Homebrew, Modding and More,
Dolphin has been ported to the Xbox - Dolphin: Blog, Discord
- Awesome GameCube Development
- Rodrigo Colpetti's GameCube practical analysis
- GC-Forever
- ConsoleMods - GameCube
For more information about Nintendo Wii hardware and its reverse engineering;
- MVG:
How a pair of Tweezers defeated security on the Nintendo Wii,
Homebrew Wars : Original Xbox vs Nintendo Wii,
Online with the Nintendo Wii in 2019,
Nintendo Wii Shop is going offline forever. How to play WiiWare games in 2019 Emulation issues and roadblocks,
Why did Nintendo Release the Wii MINI ? A look back,
Hacking the Nintendo Wii Mini - Dolphin: Blog, Discord
- WiiBrew
- Rodrigo Copetti's Wii practical analysis
Nintendo Switch and Switch 2
[edit | edit source]For more information about Nintendo Switch hardware and its reverse engineering;
- MVG:
How the Nintendo Switch Security was defeated - Ryujinx: Blog, Discord
- yuzu: Blog
- Torzu: Blog (NotABug mirror)
- SwitchBrew
- dekuNukem - Nintendo Switch reverse engineering attempts
- ReSwitched - Awesome Switch: resources
The Switch 2's custom processor, unlike the vulnerable Tegra X1 with pre-existing exploits, is likely built with stronger security measures. With Nintendo targeting emulators like Yuzu and Ryujinx, and their forks, hacking and emulator development have been discouraged. Homebrew development faces issues in the current environment. Even if a Switch 2 emulator emerges in a few years, it will likely be tightly controlled within private communities, limiting accessibility. See GBATemp thread for rumors about Switch 2 exploitability.
Handhelds
[edit | edit source]Game Boy (Color)
[edit | edit source]Oversaturation
[edit | edit source]
The Game Boy Color's screen is under-saturated. Game developers often work around this by using brighter colors knowing it'll be compensated for on hardware. This does not translate well in emulation, because standard LCD screens don't account for this sort of issue. Many emulators attempt to combat this issue with options that adjust accordingly; if not directly, then shader functionality may be implemented.
This issue also affects Game Boy Advance emulation.
Emulator options
[edit | edit source]mGBA: Under Tools > Settings > Shaders, you will find three customizable Desaturation parameters.
VBA-M: Under Options > Game Boy, you will find the GB color option. The recent nightly builds also include the LCD Filter option.
For more information about Game Boy hardware and its reverse engineering;
- meganesu: Game Boy CPU Instructions
- Rodrigo Copetti: Game Boy Architecture Practical Analysis
- MVG:
How Graphics worked on the Nintendo Game Boy,
Learn to code and write games on the Nintendo Game Boy,
Secrets of the Nintendo Game Boy Boot Logo,
How Cartridges worked on the Nintendo Game Boy - kOOPa and nocash: Pan Docs
- Game Boy Development Wiki
Game Boy Advance
[edit | edit source]Oversaturation
[edit | edit source]
Right: The "Game Boy Colors" mode on VBA-M.
The screen on the original Game Boy Advance is not backlit and can be hard to see in some conditions. To compensate, game developers often used oversaturated colors by default so that the result would look normal on hardware. On standard computer screens, saturation is not an issue, so this can look jarring and undesirable for gameplay. Some games made after 2003 may have also taken the Game Boy Advance SP model (AGS-001) into account, since its screen was actually frontlit; a newer model, AGS-101, was released in 2005 that was actually backlit. For everything else though, emudevs have given some solutions:
Emulator Options
[edit | edit source]No$GBA: Under "Emulation Options," select "GBA Mode". There are four modes.
- GBA (no backlight): Strong desaturation
- GBA SP (backlight): Strong desaturation
- Nintendo DS in GBA mode: Some desaturation
- VGA Mode (poppy bright): No desaturation
mGBA: Under Tools > Settings > Shaders > Load New Shader, select "gba-color.shader"
VBA-M: (nightly only): Under Options > Game Boy Advance, you will find the option, LCD Filter.
higan: Under Settings > Video Filter, you will find the "Color Emulation" checkbox.
- Color Emulation off: No desaturation
- Color Emulation on: Gamma correction and adjusted color range.
NanoBoyAdvance: Enabled by default. Under Config > Video > Color Correction > GBA
SkyEmu: Color Correction is set by default to 1.00 force in this emulator, and there are 2 types of desaturation methods. The first one is named SkyEmu and is selected by default, and the other one is named Higan and, as its name suggests, is based on higan's color correction. Change the desaturation type by pressing the ≡ button, then select GBA Color Correction Type. You can also change the intensity of the desaturation: slide the slider to 0.00 to brighten the screen a tad bit.
Shaders
[edit | edit source]Cg shaders can be used in OpenEmu or RetroArch that adjust the colors to those of a real GBA screen, as well as other screen types. These are available in GLSL[45] for OpenGL, and Slang[46] for Vulkan.
For GBA, there is gba-color.cg[47], which simulates the color profile of a GBA screen under an external light source more accurately than VBA-M or No$GBA color options. If you prefer the darker color options that those emulators have, then use vba-color.cg[48] instead.
There is also nds-color.cg[49] and psp-color.cg[50], which simulates the color profiles of the original Nintendo DS frontlit screen and the PSP-1000/PSP-2000 backlit screen, respectively.
For Game Boy Advance shader presets, see the "Shader Presets" page;
- Main article: Shader_Presets
Horrible Sound Quality
[edit | edit source]As a handheld rushed to the market (because of the WonderSwan Color competition), the Game Boy Advance had some cut corners. The sound hardware was affected the hardest: while it could play Game Boy Color sound in addition to samples and sequenced music like what would be heard on the SNES, the actual playback quality is awful compared to the sound samples stored internally in the ROM.
There were tools made to extract the internal high-quality music (as midi files plus a sound font, to be played on foobar2000); however, interest remains limited in implementing its playback in real-time on emulators. It's worth noting that NanoBoyAdvance includes an high quality audio mixer and there's a very experimental feature exists on mGBA (nightly versions) under Enhancements as "XQ GBA Audio", but it's very buggy and still limited to games using the standard sound engine, the so-called "Sappy" engine, which is still a big part of the GBA's software library.
High Resolution Affine Transformation Graphical Effects
[edit | edit source]Similarly to the scaling effects used on the Super NES known commonly as "Mode 7" graphics, the Game Boy Advance has affine transformation effects for some backgrounds and individual sprites that can be done in hardware. Due to the GBA's lower resolution, some detail may be lost.
The mGBA emulator added an Enhancements menu where you can change the resolution of those graphical effects, for a smoother effect. The graphical render engine will need to be OpenGL for those to take effect. It won't work on games where those effects are done in software instead of the hardware scaling features (like the 3D environment in Asterix & Obelix XXL)
Save formats
[edit | edit source]Originally, when saves were implemented, nobody settled on a format, so the Visual Boy Advance devs made their own. Because other emulators often went with raw data, having to exchange different saves caused problems. The original Visual Boy Advance tries to figure out which format a given save is but often fails at it. By explicitly telling the emulator to read it as a specific type using a file called vba-over.ini, VBA complies. VBA-M includes this config file by default, but older revisions like VBA 1.7.2 and VBALink don't.
The VBA-Next and VBA-M cores in Libretro have the file baked into the binary so that it can load raw .sav files. However, they convert the format to its own derivative at exactly 136 KB every time, with save type info contained within the file. This completely avoids the previous issues at the cost of incompatibility with standalone VBA and most others.
To solve this incompatibility, Libretro devs created a command-line tool to convert .srm save files made from these cores to raw .sav save data for other emulators. It takes standard input (i.e., drag and drop the .srm onto the executable) and outputs accordingly. It can also be done in reverse. A website version of this tool can be found here.
For more information about Game Boy Advance hardware and its reverse engineering;
- Rodrigo Copetti: Game Boy Advance Architecture Practical Analysis
- MVG:
The Story of Quake on the Game Boy Advance,
How the Game Boy Advance knew it was running a Game Boy Game,
Tomb Raider on the Nintendo Game Boy Advance is incredible,
How Graphics worked on the Nintendo Game Boy Advance - martin korth: gbatek
- akkera102.sakura gbadev (Japanese)
- gbadev - gbadoc
- WikiBooks - GBA Development Resources
PlayStation Portable
[edit | edit source]For more information about PSP hardware and its reverse engineering;
- MVG:
PSP in 2023,
How the Sony PlayStation Portable PSP Security was defeated,
A closer look at the Sony PSP DTP-T1000 Development Kit,
Another look at the Sony PSP GO Handheld in 2018 - Rodrigo Copetti's PSP Architecture Practical Analysis
- PPSSPP: Blog, Discord, Docs
- PSDevWiki - PSP
Nintendo 3DS
[edit | edit source]For more information about Nintendo 3DS hardware and its reverse engineering;
- MVG:
The most important Nintendo 3DS Game Ever Made,
Homebrew on a $100 New Nintendo 3DS LL,
The Nintendo 3DS eShop Is Going Offline Forever. How to Play All Games After 2023, - Citra: Blog
- Tanuki3DS: Discord
- Azahar: Blog
- 3dbrew
- GBATemp - 3DS Homebrew Development
- 3DS Hacks Guide
- FOSDEM '24: Panda3DS - Climbing the tree of 3DS emulation
See also
[edit | edit source]- Emulator scams
- Console-specific development wikis
- Emulation books and articles
- Legal status and history of emulation
- Licensing
- Copy protection
- Preservation projects
- ↑ While the Prescott microarchitecture was designed with Intel 64 capabilities, the initial desktop models shipped with 64-bit support disabled. Consequently, these early variants do not qualify as x86-64-v1 processors and function strictly as 32-bit x86 processors with SSE3 support. Intel later enabled 64-bit support in subsequent Prescott revisions, such as the 5xxF and 6xx series.
- ↑ https://github.com/xemu-project/xemu/blob/master/target/i386/ops_sse.h
https://github.com/xemu-project/xemu/tree/master/hw/xbox/nv2a
https://github.com/xemu-project/xemu/blob/master/hw/xbox/xbox_pci.c#L47 - ↑ https://laseractive.wordpress.com/faq/
- ↑ 4.0 4.1 https://gendev.spritesmind.net/forum/viewtopic.php?t=1647&postdays=0&postorder=asc&start=0
- ↑ Plugin info, news. / Information about the plugin, news. (gpuBladeSoft discussion). forum.emu-russia (2011-09-16)
- ↑ Playstation 1 does not have z-buffer and floating points, yet how could it play 3D games?
- ↑ List of PlayStation games with CD-DA (From deprecated Wikipedia article - dated 11/27/2016)
- ↑ ECM And APE Guide. www.epforums.org (2011-Feb-16; Last edited: 2017-Jan-15)
- ↑ 9.0 9.1 9.2 Next Generation (magazine) issue 2, 1995
- ↑ 10.0 10.1 10.2 Interview: Ezra Dreisbach. Curmudgeon Gamer (July 9, 2002)
- ↑ 11.0 11.1 So many 32-Bit Systems To Choose From Next Generation (magazine) issue 12, 1995
- ↑ https://forums.pcsx2.net/Thread-Why-is-PCSX2-slow
- ↑ https://wiki.pcsx2.net/PCSX2_Documentation/Nightmare_on_Floating-Point_Street
- ↑ https://github.com/PSI-Rockin/DobieStation/issues/51
- ↑ https://github.com/PCSX2/pcsx2/issues/2990
- ↑ https://github.com/PCSX2/pcsx2/issues/5137
- ↑ https://pcsx2.net/blog/2025/pcsx2-2.4_2.2/#dev9-fixes
- ↑ https://pcsx2.net/blog/2023/q1-2022-progress-report#dev9
- ↑ https://github.com/PCSX2/pcsx2/pull/4274#issuecomment-795316629
- ↑ https://github.com/PCSX2/pcsx2/pull/10836#issuecomment-1954866179
- ↑ https://pcsx2.net/blog/2021/q3-2021-progress-report#gs-improvements https://pcsx2.net/blog/2022/q4-2021-progress-report#gs-improvements https://pcsx2.net/blog/2023/q1-2022-progress-report#gs-improvements https://pcsx2.net/blog/2025/pcsx2-2.4_2.2/#will-it-blend https://pcsx2.net/blog/2025/pcsx2-2.4_2.2/#rt-in-rt-support https://github.com/PCSX2/pcsx2/pull/13795 https://github.com/PCSX2/pcsx2/pull/13681 https://github.com/PCSX2/pcsx2/pull/13792 https://github.com/PCSX2/pcsx2/pull/13754 https://github.com/PCSX2/pcsx2/pull/13854 https://github.com/PCSX2/pcsx2/pull/13923
- ↑ https://pcsx2.net/blog/tags/progress-report/
- ↑ https://themaister.net/blog/2024/07/03/playstation-2-gs-emulation-the-final-frontier-of-vulkan-compute-emulation/
- ↑ https://www.libretro.com/index.php/playstation2-and-the-crt-tv/
- ↑ https://themaister.net/blog/2026/05/09/emulating-old-junk-from-yesteryear-or-my-obsession-making-native-resolution-ps2-emulation-look-good/
- ↑ Why is XBOX emulation premature?. ngemu (2010-02-15)
- ↑ /LTCG (Link-time Code Generation). Microsoft
- ↑ Under The Hood: Link-time Code Generation. Microsoft
- ↑
Xbox Emulation: The History & Roadblocks
- ↑ Why is there a lack of Original Xbox emulation?. Reddit (2017-05-29)
- ↑ Triang3l (April 27, 2021). Leaving No Pixel Behind: New Render Target Cache, 3x3 Resolution Scaling & Three Years in Xenia’s GPU Emulation. Xenia.
- ↑ Building an Xbox 360 Emulator
- ↑
I Ran PS3 Games on PS5 Silicon to Prove Sony Wrong
- ↑ PS3 Emulation Tested on PS5 under Linux with RPCS3
- ↑
Why PS4 Doesn't Have Backwards Compatibility and Xbox One Does
- ↑
MVG: Sony's complicated history with Backwards Compatibility
- ↑ x86 instruction listings
- ↑ RPCSX discord channel: Various resources for reverse-engineering PlayStation 4.
- ↑ https://www.retrorgb.com/pc-engine-palette-improvements-the-amazing-people-behind-the-technology.html
- ↑ README for parallel-rdp repository on GitHub. § Disclaimer. "While paraLLEl-RDP uses Angrylion-Plus as an implementation reference, it is not a port, and not a derived codebase of said project. It is written from scratch by studying Angrylion-Plus and trying to understand what is going on. The test suite uses Angrylion-Plus as a reference to validate implementation and cross-checking behavior."
- ↑ Public Release 3.0. Blogspot (2017-12-29)
- ↑ Initial implementation of BOSS ZSort ucode (WDC, Stunt Racer). GitHub (2018-02-10)
- ↑ "Indiana J. & Infernal Machine" HLE. Indiegogo (2018-05-17)
- ↑ HLE implementation of microcodes for "Indiana Jones" and "Battle for Naboo" completed.. Blogspot (2018-05-26)
- ↑ https://github.com/libretro/glsl-shaders/tree/master/handheld/shaders/color
- ↑ https://github.com/libretro/slang-shaders/tree/master/handheld/shaders/color
- ↑ https://github.com/libretro/common-shaders/blob/master/handheld/shaders/color/gba-color.cg
- ↑ https://github.com/libretro/common-shaders/blob/master/handheld/shaders/color/vba-color.cg
- ↑ https://github.com/libretro/common-shaders/blob/master/handheld/shaders/color/nds-color.cg
- ↑ https://github.com/libretro/common-shaders/blob/master/handheld/shaders/color/psp-color.cg