Files
Sylpheed/tools/ppc-manual/memory/lhz.md
sim f3c512f2ab docs(ppc-manual): check every xenia-rs claim against Canary's source
The hand-written parts of the manual still described how the retired
xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of
those 490 statements is now either restated as what Canary's emitters and
x64 backend actually do (at the pinned canary_experimental commit), or
dropped where it only made sense for xenia-rs.

Checking them turned up claims that were wrong, not just outdated:

- VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr
  cannot see it); the pages said saturating ops set it stickily.
- Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1,
  vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them
  as working.
- Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not
  16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims
  and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec.
- Reservations are a 64 KiB block bitmap plus a value compare, not
  per-address tracking.

Claims that neither Canary's source nor a public spec settles are marked
unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness).

Generated regions are untouched; re-running the generator changes nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 21:52:38 +02:00

11 KiB
Raw Permalink Blame History

lhz — Load Half Word and Zero

Category: Memory · Form: D · Opcode: 0xa0000000

Assembler Mnemonics

Mnemonic XML entry Flags Description
lhz lhz Load Half Word and Zero
lhzu lhzu Load Half Word and Zero with Update
lhzux lhzux Load Half Word and Zero with Update Indexed
lhzx lhzx Load Half Word and Zero Indexed

Syntax

lhz [RD], [d]([RA0])
lhzu [RD], [d]([RA])
lhzux [RD], [RA], [RB]
lhzx [RD], [RA0], [RB]

Encoding

lhz — form D

  • Opcode word: 0xa0000000
  • Primary opcode (bits 05): 40
  • Extended opcode:
  • Synchronising: no
Bits Field Meaning
05 OPCD primary opcode
610 RT destination GPR (or RS when storing)
1115 RA source GPR (0 ⇒ literal 0 for RA0 forms)
1631 D/SI/UI 16-bit signed or unsigned immediate

lhzu — form D

  • Opcode word: 0xa4000000
  • Primary opcode (bits 05): 41
  • Extended opcode:
  • Synchronising: no
Bits Field Meaning
05 OPCD primary opcode
610 RT destination GPR (or RS when storing)
1115 RA source GPR (0 ⇒ literal 0 for RA0 forms)
1631 D/SI/UI 16-bit signed or unsigned immediate

lhzux — form X

  • Opcode word: 0x7c00026e
  • Primary opcode (bits 05): 31
  • Extended opcode: 311
  • Synchronising: no
Bits Field Meaning
05 OPCD primary opcode
610 RT/FRT/VRT destination
1115 RA/FRA/VRA source A
1620 RB/FRB/VRB source B
2130 XO extended opcode (10 bits)
31 Rc record-form flag

lhzx — form X

  • Opcode word: 0x7c00022e
  • Primary opcode (bits 05): 31
  • Extended opcode: 279
  • Synchronising: no
Bits Field Meaning
05 OPCD primary opcode
610 RT/FRT/VRT destination
1115 RA/FRA/VRA source A
1620 RB/FRB/VRB source B
2130 XO extended opcode (10 bits)
31 Rc record-form flag

Operands

Field Role Description
RA0 lhz: read; lhzx: read Source GPR; when the encoded register number is 0 the operand is the literal 64-bit zero, not r0.
d lhz: read; lhzu: read 16-bit signed displacement (d) added to the base address register.
RD lhz: write; lhzu: write; lhzux: write; lhzx: write Destination GPR.
RA lhzu: read; lhzu: write; lhzux: read; lhzux: write Source GPR (r0r31).
RB lhzux: read; lhzx: read Source GPR.

Register Effects

lhz

  • Reads (always): RA0, d
  • Reads (conditional): none
  • Writes (always): RD
  • Writes (conditional): none

lhzu

  • Reads (always): RA, d
  • Reads (conditional): none
  • Writes (always): RD, RA
  • Writes (conditional): none

lhzux

  • Reads (always): RA, RB
  • Reads (conditional): none
  • Writes (always): RD, RA
  • Writes (conditional): none

lhzx

  • Reads (always): RA0, RB
  • Reads (conditional): none
  • Writes (always): RD
  • Writes (conditional): none

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

EA <- (RA|0) + EXTS(d)
RT <- ZEXT16_to_64(MEM(EA, 2))

C Translation Example

/* No hand-written C yet. Translate the Canary emitter snapshot   */
/* under Implementation References; its HIR maps directly:        */
/*   f.LoadGPR(n) / f.StoreGPR(n, v)  -> r[n] / r[n] = v          */
/*   f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n]        */
/*   f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters   */
/*     wrap them in f.ByteSwap for the big-endian guest value      */
/*   f.UpdateCR(n, v)  -> CR field n from v's LOW 32 BITS vs 0     */
/*   f.LoadCA / f.StoreCA -> xer.CA;  f.StoreSAT -> vscr.SAT       */
/*   i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands  */
/* The Register Effects and Status-Register Effects tables above  */
/* enumerate every side effect a faithful translation must emit.  */

Implementation References

lhz

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhz(PPCHIRBuilder& f, const InstrData& i) {
  // if RA = 0 then
  //   b <- 0
  // else
  //   b <- (RA)
  // EA <- b + EXTS(D)
  // RT <- i48.0 || MEM(EA, 2)
  Value* b;
  if (i.D.RA == 0) {
    b = f.LoadZeroInt64();
  } else {
    b = f.LoadGPR(i.D.RA);
  }

  Value* offset = f.LoadConstantInt64(XEEXTS16(i.D.DS));
  Value* rt =
      f.ZeroExtend(f.ByteSwap(f.LoadOffset(b, offset, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.D.RT, rt);
  return 0;
}

lhzu

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzu(PPCHIRBuilder& f, const InstrData& i) {
  // EA <- (RA) + EXTS(D)
  // RT <- i48.0 || MEM(EA, 2)
  // RA <- EA
  Value* ra = f.LoadGPR(i.D.RA);
  Value* offset = f.LoadConstantInt64(XEEXTS16(i.D.DS));
  Value* rt = f.ZeroExtend(f.ByteSwap(f.LoadOffset(ra, offset, INT16_TYPE)),
                           INT64_TYPE);
  f.StoreGPR(i.D.RT, rt);
  StoreEA(f, i.D.RA, f.Add(ra, offset));
  return 0;
}

lhzux

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzux(PPCHIRBuilder& f, const InstrData& i) {
  // EA <- (RA) + (RB)
  // RT <- i48.0 || MEM(EA, 2)
  // RA <- EA
  Value* ea = CalculateEA(f, i.X.RA, i.X.RB);
  Value* rt = f.ZeroExtend(f.ByteSwap(f.Load(ea, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.X.RT, rt);
  StoreEA(f, i.X.RA, ea);
  return 0;
}

lhzx

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzx(PPCHIRBuilder& f, const InstrData& i) {
  // if RA = 0 then
  //   b <- 0
  // else
  //   b <- (RA)
  // EA <- b + (RB)
  // RT <- i48.0 || MEM(EA, 2)
  Value* ea = CalculateEA_0(f, i.X.RA, i.X.RB);
  Value* rt = f.ZeroExtend(f.ByteSwap(f.Load(ea, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.X.RT, rt);
  return 0;
}

Special Cases & Edge Conditions

  • Big-endian read, zero-extension. Reads 2 bytes big-endian, treats them as an unsigned 16-bit integer, zero-extends to 64 bits. The high 48 bits of RT become zero. Compare with lha, which sign-extends.
  • RA0 (non-update forms). RA = 0 in lhz / lhzx selects literal zero for absolute-address access. Update forms lhzu / lhzux invoke RA = 0 and RA = RT as invalid forms.
  • Update-form ordering. Canary computes EA, performs the load into RT, then writes RA ← EA. If RA == RT (an invalid form per IBM), the load result is overwritten by EA immediately.
  • No alignment requirement. Xenon executes unaligned half-word loads without faulting. MEM(EA, 2) reads the two consecutive bytes at EA.
  • Common as Unicode codepoint loader. Xbox 360 system strings are UTF-16; lhz is the canonical load for a single 16-bit codepoint.
  • Use lhz rather than lbz × 2 + shift. One fused instruction is faster and lets the load-store unit handle alignment.
  • Indexed variant operand order. lhzx RT, RA, RBRA is the base (with RA0 semantics), RB is the offset.

IBM Reference