A CLI that turns the SameBoy Game Boy emulator core into a stateful dynamic-analysis service for AI agents and scripts. One long-lived process reads JSON commands (one per line) on stdin and answers in JSON on stdout — step/run execution, breakpoints, watchpoints, execution+memory-access tracing, call backtraces, ROM coverage, snapshots, time-travel rewind, memory diff/search, symbol-aware disassembly, scripted input, and PNG screenshots.
Built on the unmodified SameBoy 1.0.3 Core (vendored under SameBoy/ — see
VENDORED.md). See PROTOCOL.md for the full command reference and SKILL.md
for agent-oriented analysis recipes.
macOS toolchain trap (observed 2026-09-28, CLT clang 17 + MacOSX27.0 SDK): the link fails with
tapi error: ... unknown architecturein the SDK's.tbdstubs, and the failed link DELETES the existingbuild/gbemuthat downstream harnesses run. Link against an older installed SDK instead:SDKROOT=/Library/Developer/CommandLineTools/SDKs/MacOSX26.5.sdk make.
make # builds build/gbemu from SameBoy/Core + cli/src (needs clang/gcc + libz)
make bootroms # vendors boot ROM binaries into cli/bootroms (RGBDS, or download fallback)
make test # builds a deterministic test ROM and runs the smoke + sanitizer suites (python3)
Boot ROMs: dmg_boot.bin etc. are looked up in cli/bootroms/ (override with
--bootrom-dir or GBEMU_BOOTROM_DIR). For tests/CI, boot:"builtin" uses the
embedded minimal DMG boot ROM — no files needed.
./build/gbemu # JSON-lines REPL on stdin
./build/gbemu --script run.jsonl # replay a command script, then exit
Example session (each line sent to stdin):
{"id":1,"cmd":"load_rom","params":{"path":"pokemon.gb","model":"dmg","symbols":"pokemon.sym","seed":42}}
{"id":2,"cmd":"run.frames","params":{"n":600}}
{"id":3,"cmd":"break.add","params":{"addr":"$3d7e"}}
{"id":4,"cmd":"run.until","params":{"expr":"$c3e0 > 0","max_instructions":5000000}}
{"id":5,"cmd":"backtrace"}
{"id":6,"cmd":"mem.read","params":{"addr":"$c100","len":64}}
{"id":7,"cmd":"screen.capture","params":{"path":"shot.png"}}
{"id":8,"cmd":"quit"}
import sys; sys.path.insert(0, "cli/py")
from gbemu import GBEmu
with GBEmu("build/gbemu") as g:
g.load_rom("game.gb", model="dmg", boot="builtin")
g.run_frames(60)
g.watch_add(addr=0xC000, access="w")
r = g.run_frames(10)
if r["stopped"]:
print(r["reason"], g.backtrace()["entries"])
"new != old", "new < 5") over RAM/HRAM/cart RAM (SameBoy cheat engine)..sym support; addresses everywhere accept symbol names.Makefile build entry point
cli/src/*.c gbemu server (json, exec, mem, history, video, input, png)
cli/py/gbemu.py Python client wrapper (stdlib only)
cli/tests/ make_test_rom.py (deterministic ROM generator), smoke.py
cli/bootroms/ vendored boot ROM binaries (see cli/bootroms/README.md)
tools/fetch_bootroms.sh boot ROM provisioning
SameBoy/ vendored SameBoy subset (see VENDORED.md)
The gbemu CLI, Python client and tests are released under the Expat (MIT)
License — see LICENSE.
The vendored SameBoy emulator core and its boot ROMs are copyright
(c) 2015-2026 Lior Halphon, also under the Expat License — see
SameBoy/LICENSE and VENDORED.md for
provenance and the scope of the vendored subset. Boot ROM provenance details
are in cli/bootroms/README.md.
C
90.7%
Python
3.5%
Makefile
2.9%
Assembly
2.7%
A CLI that turns the SameBoy Game Boy emulator core into a stateful dynamic-analysis service for AI agents and scripts. One long-lived process reads JSON commands (one per line) on stdin and answers in JSON on stdout — step/run execution, breakpoints, watchpoints, execution+memory-access tracing, call backtraces, ROM coverage, snapshots, time-travel rewind, memory diff/search, symbol-aware disassembly, scripted input, and PNG screenshots.
Built on the unmodified SameBoy 1.0.3 Core (vendored under SameBoy/ — see
VENDORED.md). See PROTOCOL.md for the full command reference and SKILL.md
for agent-oriented analysis recipes.
macOS toolchain trap (observed 2026-09-28, CLT clang 17 + MacOSX27.0 SDK): the link fails with
tapi error: ... unknown architecturein the SDK's.tbdstubs, and the failed link DELETES the existingbuild/gbemuthat downstream harnesses run. Link against an older installed SDK instead:SDKROOT=/Library/Developer/CommandLineTools/SDKs/MacOSX26.5.sdk make.
make # builds build/gbemu from SameBoy/Core + cli/src (needs clang/gcc + libz)
make bootroms # vendors boot ROM binaries into cli/bootroms (RGBDS, or download fallback)
make test # builds a deterministic test ROM and runs the smoke + sanitizer suites (python3)
Boot ROMs: dmg_boot.bin etc. are looked up in cli/bootroms/ (override with
--bootrom-dir or GBEMU_BOOTROM_DIR). For tests/CI, boot:"builtin" uses the
embedded minimal DMG boot ROM — no files needed.
./build/gbemu # JSON-lines REPL on stdin
./build/gbemu --script run.jsonl # replay a command script, then exit
Example session (each line sent to stdin):
{"id":1,"cmd":"load_rom","params":{"path":"pokemon.gb","model":"dmg","symbols":"pokemon.sym","seed":42}}
{"id":2,"cmd":"run.frames","params":{"n":600}}
{"id":3,"cmd":"break.add","params":{"addr":"$3d7e"}}
{"id":4,"cmd":"run.until","params":{"expr":"$c3e0 > 0","max_instructions":5000000}}
{"id":5,"cmd":"backtrace"}
{"id":6,"cmd":"mem.read","params":{"addr":"$c100","len":64}}
{"id":7,"cmd":"screen.capture","params":{"path":"shot.png"}}
{"id":8,"cmd":"quit"}
import sys; sys.path.insert(0, "cli/py")
from gbemu import GBEmu
with GBEmu("build/gbemu") as g:
g.load_rom("game.gb", model="dmg", boot="builtin")
g.run_frames(60)
g.watch_add(addr=0xC000, access="w")
r = g.run_frames(10)
if r["stopped"]:
print(r["reason"], g.backtrace()["entries"])
"new != old", "new < 5") over RAM/HRAM/cart RAM (SameBoy cheat engine)..sym support; addresses everywhere accept symbol names.Makefile build entry point
cli/src/*.c gbemu server (json, exec, mem, history, video, input, png)
cli/py/gbemu.py Python client wrapper (stdlib only)
cli/tests/ make_test_rom.py (deterministic ROM generator), smoke.py
cli/bootroms/ vendored boot ROM binaries (see cli/bootroms/README.md)
tools/fetch_bootroms.sh boot ROM provisioning
SameBoy/ vendored SameBoy subset (see VENDORED.md)
The gbemu CLI, Python client and tests are released under the Expat (MIT)
License — see LICENSE.
The vendored SameBoy emulator core and its boot ROMs are copyright
(c) 2015-2026 Lior Halphon, also under the Expat License — see
SameBoy/LICENSE and VENDORED.md for
provenance and the scope of the vendored subset. Boot ROM provenance details
are in cli/bootroms/README.md.
C
90.7%
Python
3.5%
Makefile
2.9%
Assembly
2.7%