# `mtmsr` — Move to Machine State Register > **Category:** [Control / CR / SPR](../categories/control.md) · **Form:** [X](../forms/X.md) · **Opcode:** `0x7c000124` · _sync_ ## Assembler Mnemonics | Mnemonic | XML entry | Flags | Description | | --- | --- | --- | --- | | `mtmsr` | `mtmsr` | — | Move to Machine State Register | ## Syntax ```asm mtmsr [RS] ``` ## Encoding ### `mtmsr` — form `X` - **Opcode word:** `0x7c000124` - **Primary opcode (bits 0–5):** `31` - **Extended opcode:** `146` - **Synchronising:** yes | Bits | Field | Meaning | | --- | --- | --- | | 0–5 | `OPCD` | primary opcode | | 6–10 | `RT/FRT/VRT` | destination | | 11–15 | `RA/FRA/VRA` | source A | | 16–20 | `RB/FRB/VRB` | source B | | 21–30 | `XO` | extended opcode (10 bits) | | 31 | `Rc` | record-form flag | ## Operands | Field | Role | Description | | --- | --- | --- | | `RS` | mtmsr: read | Source GPR (alias for RD in some stores). | | `MSR` | mtmsr: write | Machine State Register. | ## Register Effects ### `mtmsr` - **Reads (always):** `RS` - **Reads (conditional):** _none_ - **Writes (always):** `MSR` - **Writes (conditional):** _none_ ## Status-Register Effects _No condition-register or status-register effects._ ## Operation (pseudocode) ``` ; No hand-written pseudocode for this instruction yet. ; The authoritative semantics are the Canary emitter snapshot under ; Implementation References; about half of Canary's emitters open ; with the PPC-style definition as a comment (`RD <- (RA) + (RB)`). ; Every side effect is also enumerated in the Register Effects and ; Status-Register Effects tables above. ``` ## C Translation Example ```c /* No hand-written C yet. Translate the Canary emitter snapshot */ /* under Implementation References; its HIR maps directly: */ /* f.LoadGPR(n) / f.StoreGPR(n, v) -> r[n] / r[n] = v */ /* f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n] */ /* f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters */ /* wrap them in f.ByteSwap for the big-endian guest value */ /* f.UpdateCR(n, v) -> CR field n from v's LOW 32 BITS vs 0 */ /* f.LoadCA / f.StoreCA -> xer.CA; f.StoreSAT -> vscr.SAT */ /* i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands */ /* The Register Effects and Status-Register Effects tables above */ /* enumerate every side effect a faithful translation must emit. */ ``` ## Implementation References **`mtmsr`** - Canary XML: [`tools/ppc-instructions.xml` — search for `mnem="mtmsr"`](https://github.com/xenia-canary/xenia-canary/blob/f21ebd49e979e44f081f474df78c3fbfee9cb3f2/tools/ppc-instructions.xml) - Canary emitter: [`src/xenia/cpu/ppc/ppc_emit_control.cc:824`](https://github.com/xenia-canary/xenia-canary/blob/f21ebd49e979e44f081f474df78c3fbfee9cb3f2/src/xenia/cpu/ppc/ppc_emit_control.cc#L824) - Sylpheed opcode: [`crates/sylpheed-ppc/src/opcode.rs:183`](../../../crates/sylpheed-ppc/src/opcode.rs#L183) - Sylpheed decoder: [`crates/sylpheed-ppc/src/decoder.rs:895`](../../../crates/sylpheed-ppc/src/decoder.rs#L895)
Canary emitter (frozen snapshot @ f21ebd49e9) ```cpp int InstrEmit_mtmsr(PPCHIRBuilder& f, const InstrData& i) { f.StoreContext(offsetof(PPCContext, msr), f.LoadGPR(i.X.RT)); return 0; } ```
## Special Cases & Edge Conditions - **Privileged.** `mtmsr` is supervisor-only on real hardware. Executing it from problem state raises a Privileged Instruction interrupt. Game code never emits it; only the kernel and exception-return paths use it. - **32-bit form.** `mtmsr` writes the **low 32 bits** of MSR (legacy PPC32 form). On the Xenon (a PPC64 implementation), use [`mtmsrd`](mtmsrd.md) for the full 64-bit MSR. Some Xenon kernel sequences still use `mtmsr` to leave the high half untouched while flipping low-half flags like EE/PR. - **Synchronisation.** Marked `sync` — `mtmsr` is **execution-synchronising**. The Xenon must drain all preceding instructions before the new MSR takes effect, and PowerISA recommends a following `isync` to guarantee subsequent instructions execute under the new MSR. - **`L` operand.** Modern PowerISA defines an `L` bit selecting "EE/RI only" (`L=1`) versus "all" (`L=0`); Canary's `mtmsr` ignores `L` and writes the entire MSR. Real Xbox 360 kernel code uses both `L=0` and `L=1`. - **Canary model.** Treats MSR as a flat 64-bit context field. `mtmsr` stores `RS` whole; `mtmsrd` differs (see its page). No privilege or atomicity is enforced; no side effects on TLB / interrupt mask / endianness are simulated. - **No CR / XER side effects.** - **Caveat for translators.** Because Canary implements the kernel natively, the guest MSR has no architectural meaning beyond storage. Code that reads it back via [`mfmsr`](mfmsr.md) sees what `mtmsr` last wrote — `mtmsrd` changes only `EE`. ## Related Instructions - [`mfmsr`](mfmsr.md) — read MSR. - [`mtmsrd`](mtmsrd.md) — 64-bit form (writes the entire MSR). - [`sc`](../branch/sc.md) — kernel entry; the kernel handler typically uses `mtmsr`/`rfid` to return. - [`isync`](mtmsr.md) — companion fence after MSR writes. `mtmsr` has no simplified mnemonics. ## IBM Reference - [AIX 7.3 — `mtmsr` (Move to Machine State Register)](https://www.ibm.com/docs/en/aix/7.3.0?topic=set-mtmsr-move-machine-state-register-instruction) - PowerISA v2.07B, Book III §4.3.1 — MSR field definitions and `L`-bit semantics.