how a from-scratch PC emulator learned to boot Windows 2000

CHAPTER 7 · 19 JULY 2026, 03:02

THE FINAL NIGHT

By the evening of 18 July the CD was attached, the product key was in, and — for the first time in fifty-two days — Windows 2000’s setup was simply allowed to run. What follows is the last night of the campaign, minute by minute: three hours and forty minutes of “Performing Final Tasks” watched through video-plane memory, one final blue screen that was not what it seemed, and a desktop that settled at 03:02 with the taskbar clock reading 2:04 AM. Then the sober part: what two clean boots actually prove.

3h 40m
“Performing Final Tasks”, watched through 21 VGA-plane snapshots on the evening of 18 July
73 min
from the STOP 0x7B at 01:49 to desktop-settled.png at 03:02
the release binary rebuilt in the final hour — 02:36 and 02:54, both interpreter-only
2
independent fresh-copy acceptance boots — captures 46 and 47
2,512
mddosem-interp tests green on the final source, 0 failed
2:04 AM
the guest taskbar clock in the success shot, host time 03:02

Setup runs its course

By 18 July there was, at last, nothing left to diagnose. The Service Pack 4 CD was attached; the product key had been entered by the corrected, statically verified procedure of chapter 5; the hardware corrections of chapter 6 were landing. Capture 26 cold-booted a hash-verified copy of the capture-24 disk and typed the key properly into the five auto-advancing fields. Capture 28 then did something no run had managed in the fifty-two days since the first checkpoint: it let mddosem carry a native Windows 2000 Professional SP4 GUI setup, begun from blank media, all the way to the end — with nobody stepping in.

The phase that had eaten seven weeks — Performing Final Tasks — took three hours and forty minutes. It was watched, characteristically, through the side door: twenty-one 1-bit reconstructions of VGA plane memory (the X-ray technique of chapter 5), one roughly every ten minutes from 20:16 to 23:56, each showing the hidden progress dialog a little further along.

And then the guest reset itself. Every previous reset at the end of setup had been the bad kind — the pulse through the keyboard controller that fed the restart loop of chapter 2. This one was the good kind: the scheduled final reboot with which every healthy install hands over to the operating system it has just written. The journal records that capture 28 performed its final guest reset instead of returning to the former all-Waiting wall, and the campaign moved into its last night.

The final night, minute by minute

Everything from here happened between seven minutes past midnight and half past three in the morning of Sunday 19 July. The record is unusually exact — every capture booted a hash-verified fresh copy of the disk, and every binary printed its build stamp — so the night can be replayed.

THE FINAL NIGHT — 00:07 → 03:27, 19 JULY 2026 ◀ ▶ step · ← → keys
00:07
First boot of the installed disk
Capture 29: the freshly-installed system boots. First FreeCell attempt renders a black frame (ipc-freecell-black.png, 5,757 bytes — the same size as four days of wall screenshots).
00:07 First boot of the installed disk
event on the rail the STOP 0x7B false alarm acceptance recorded
1 / 10
Events transcribed in w2k-data.js from the branch journal (wrk_journals 2026.07.15, the Win2K boot-to-desktop goal) and the run artifacts’ file timestamps; times are host wall-clock. STOP 0x7B parameters from capture-38/bugcheck.png.

At 00:07 the installed disk booted (capture 29). Setup did not resume: the RestartSetup flag that had driven the wizard’s eternal return was finally clear. The first wrinkle came from the games menu instead — FreeCell’s first frame rendered pure black, a PNG of exactly 5,757 bytes, byte-for-byte the size of the wall screenshot that had recurred across four days of captures (chapter 4). Old ghosts. At 00:45 an eleven-megabyte VGA-register trace was pulled from the QEMU reference machine to compare rendering behaviour; what changed between the black frame and the good one is not spelled out in the record, but by 02:23 FreeCell was drawing its green felt correctly.

One last blue screen

At 01:49 the night produced its scare. Capture 38 bugchecked with STOP 0x0000007BINACCESSIBLE_BOOT_DEVICE, the stop an NT kernel raises when it cannot reach the volume it booted from. Seventy-three minutes before the finish line, the emulator appeared to have lost the hard disk.

01:49 — THE FALSE ALARM recreation — abridged
Recreation (abridged); the original is capture-38/bugcheck.png in the run archive — 32,694 bytes, written 01:49 host time on 19 July 2026, SHA-256 a00fdae727611e1ddc33b4d491617db12a8ba5f928a5621dea06c017d44f8f80.

The run-down was brisk and, by this stage of the campaign, well drilled. The bugcheck was not a fair experiment: the runs that hit it were carrying the campaign’s own diagnostic rig — capture 43 reproduced it while paused under a kernel breakpoint at DbgBreakPointWithStatus — and clean, production-style runs with the ISO attached never reproduced it at all. Capture 45’s temporary packet-level ATAPI trace then showed a perfectly healthy drive conversation — inquiry, capacity, table of contents, READ(10) — with Windows meeting the drive’s unsupported mode pages through ordinary sense-and-retry recovery. The journal’s verdict: “No ATAPI workaround or disabled device was needed, and all temporary diagnostics were removed.” The last blue screen of the campaign was self-inflicted — the instruments, not the machine.

capture-45 stderr — [WIN2K_ATAPI] ata cmd=A1 state=Idle media=true ua=true …

That A1 is IDENTIFY PACKET DEVICE: the probe was still chattering in the stderr of the victory-adjacent runs, a reminder of how thin the line between instrument and subject had become. The rest of the night is the good kind of uneventful. At 02:22 the Log On to Windows dialog appeared — Administrator, blank password (capture 42). At 02:23, green felt: “Cards Left: 0”. The release binary was rebuilt twice in the final hour, at 02:36 and 02:54 — mddosem v0.156.3, build 669806963, interpreter-only, as every run of the campaign had been. Capture 45 — the instrumented run, ATAPI probe still attached — ran the full sequence between 02:43 and 02:46: splash at 02:43, first desktop at 02:45, FreeCell at 02:46. Capture 46, from a fresh hash-verified copy with the ISO attached and a fixed diagnostic clock epoch, followed the 02:54 rebuild and ran Winlogon → Administrator login → Explorer → FreeCell → clean guest restart; its duration went unrecorded. Capture 47, from a second fresh copy with no fixed epoch, reached Winlogon and a responsive desktop between 03:00 and 03:02, and wrote desktop-settled.png. The last of the four fixes had been committed at 03:05 (chapter 6 tells that story); at 03:27 the acceptance was recorded, and MDD-BUG-KILN-00004 — raised on 30 June as “Windows 2000 GUI setup restart-loops at ‘set system security’” — was flipped to Fixed.

The desktop, settled

What does a fifty-three-day desktop look like? Unremarkable — which is the point. A maximised Search Results window idles behind (“0 object(s)”); in front, the Getting Started with Windows 2000 wizard offers to register, to discover, to connect; a line drawing of a two-button mouse explains double-clicking. A grey taskbar. A Start button. A clock.

03:02 — DESKTOP-SETTLED.PNG, RECREATED HTML/CSS recreation — not a screenshot
Recreation, simplified; the original is capture-47/desktop-settled.png in the run archive — 640 × 480, 286,234 bytes, written 03:02 host time on 19 July 2026, SHA-256 27e81cce208a302b9a223071c6003a1bd296cdec661a969016d787a82c36e337.

The clocks are the human detail. The host filesystem stamped desktop-settled.png at 03:02; the guest’s taskbar says 2:04 AM. In the FreeCell frame the gap yawns wider still: green felt written at 02:46 host time, 12:04 AM on the guest taskbar. An emulated machine keeps whatever time it is told to — one acceptance run pinned the real-time clock to a fixed diagnostic epoch, the other ran with none — and neither guest quite agreed with the host about the hour. Windows, for its part, kept both clocks with perfect composure.

GREEN FELT, CARDS LEFT: 0 HTML/CSS recreation — not a screenshot
Recreation, simplified; the original is capture-45/freecell.png — 271,599 bytes, written 02:46 host time on 19 July 2026, SHA-256 3afc41d729b02095f192f344048deb7dac3b034324b21a91ba2f717e211d35b9. In the original the Getting Started wizard overlaps the felt, its fat red arrow frozen mid-animation over the mouse illustration; the guest taskbar clock reads 12:04 AM.

The acceptance checklist, as recorded

The acceptance was a checklist, not a feeling. As recorded in the bug ledger and the branch journal:

The validation claims are scoped, and the record is explicit about it. A broader full_test quick run was bounded at 900 seconds and timed out after sixteen per-crate suites had passed — and was deliberately not claimed as a full gate. The exact-tree final gate belongs to the integration step, and the journal says so in as many words.

What two clean boots prove — and what they don’t

They prove that the default interpreter, presented with unmodified retail media and a product key, completes a native Windows 2000 Professional SP4 installation and reaches a repeatably usable desktop — twice, from independent hash-verified fresh copies, one of them with no diagnostic clock at all. And they prove it on the campaign’s own strict terms:

What they don’t prove is just as carefully recorded. The ledger entry is Fixed, not Closed: “Codex authored the final Open-to-Fixed transition and therefore must not close it” — the two-eyes rule holds, and a different verifier must reproduce the result before the bug may be closed. MDD-BUG-KILN-00005 — whether the dynamic recompiler can carry Windows 2000 — remains open; every banner of the campaign reads interpreter-only, and the recompiler sat this story out entirely. And two boots on one machine measure repeatability, not breadth: the wider compatibility matrix is a different campaign.

The method, in four habits

If the fifty-three days have a transferable lesson, it is not about Windows.

mddosem’s own engineering rule says that when an application works, it is because the emulation is right — never the other way round. On 19 July, at 03:02, Windows 2000 agreed.

How we know

Every number on this page traces to a preserved artifact, a ledger entry, or a journal line. The anchors, as transcribed in w2k-data.js:

Evidence anchors of the Windows 2000 boot campaign
ArtifactRecord

Sources for this chapter — the bug ledger MDD-BUG-KILN-00004 (raised 2026-06-30, Fixed 2026-07-19, closure pending under the two-eyes rule); the engineering journals, wrk_journals 2026.06.23 → 2026.07.15; the preserved run archive (47 hash-verified captures, ≈85 GiB, 15 July 16:08 → 19 July 03:02). All Windows imagery on this page is HTML/CSS recreation — the originals stay in the archive. The emulator’s own page: mddosem.