> The content of reg_state + 0x40 is not the initial stack pointer, but > the entry point. Sure, but then we do a: bisl r1,r1 - so r1 is updated to the word following the bisl instruction, which is the stack :) Cheers, Jeremy