The hand-written parts of the manual still described how the retired xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of those 490 statements is now either restated as what Canary's emitters and x64 backend actually do (at the pinned canary_experimental commit), or dropped where it only made sense for xenia-rs. Checking them turned up claims that were wrong, not just outdated: - VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr cannot see it); the pages said saturating ops set it stickily. - Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1, vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them as working. - Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not 16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec. - Reservations are a 64 KiB block bitmap plus a value compare, not per-address tracking. Claims that neither Canary's source nor a public spec settles are marked unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness). Generated regions are untouched; re-running the generator changes nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
140 lines
5.5 KiB
Markdown
140 lines
5.5 KiB
Markdown
# `mfmsr` — Move from Machine State Register
|
||
|
||
> **Category:** [Control / CR / SPR](../categories/control.md) · **Form:** [X](../forms/X.md) · **Opcode:** `0x7c0000a6` · _sync_
|
||
|
||
<!-- GENERATED: BEGIN -->
|
||
|
||
## Assembler Mnemonics
|
||
|
||
| Mnemonic | XML entry | Flags | Description |
|
||
| --- | --- | --- | --- |
|
||
| `mfmsr` | `mfmsr` | — | Move from Machine State Register |
|
||
|
||
## Syntax
|
||
|
||
```asm
|
||
mfmsr [RD]
|
||
```
|
||
|
||
## Encoding
|
||
|
||
### `mfmsr` — form `X`
|
||
|
||
- **Opcode word:** `0x7c0000a6`
|
||
- **Primary opcode (bits 0–5):** `31`
|
||
- **Extended opcode:** `83`
|
||
- **Synchronising:** yes
|
||
|
||
| Bits | Field | Meaning |
|
||
| --- | --- | --- |
|
||
| 0–5 | `OPCD` | primary opcode |
|
||
| 6–10 | `RT/FRT/VRT` | destination |
|
||
| 11–15 | `RA/FRA/VRA` | source A |
|
||
| 16–20 | `RB/FRB/VRB` | source B |
|
||
| 21–30 | `XO` | extended opcode (10 bits) |
|
||
| 31 | `Rc` | record-form flag |
|
||
|
||
## Operands
|
||
|
||
| Field | Role | Description |
|
||
| --- | --- | --- |
|
||
| `MSR` | mfmsr: read | Machine State Register. |
|
||
| `RD` | mfmsr: write | Destination GPR. |
|
||
|
||
## Register Effects
|
||
|
||
### `mfmsr`
|
||
|
||
- **Reads (always):** `MSR`
|
||
- **Reads (conditional):** _none_
|
||
- **Writes (always):** `RD`
|
||
- **Writes (conditional):** _none_
|
||
|
||
## Status-Register Effects
|
||
|
||
_No condition-register or status-register effects._
|
||
|
||
## Operation (pseudocode)
|
||
|
||
```
|
||
; No hand-written pseudocode for this instruction yet.
|
||
; The authoritative semantics are the Canary emitter snapshot under
|
||
; Implementation References; about half of Canary's emitters open
|
||
; with the PPC-style definition as a comment (`RD <- (RA) + (RB)`).
|
||
; Every side effect is also enumerated in the Register Effects and
|
||
; Status-Register Effects tables above.
|
||
```
|
||
|
||
## C Translation Example
|
||
|
||
```c
|
||
/* No hand-written C yet. Translate the Canary emitter snapshot */
|
||
/* under Implementation References; its HIR maps directly: */
|
||
/* f.LoadGPR(n) / f.StoreGPR(n, v) -> r[n] / r[n] = v */
|
||
/* f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n] */
|
||
/* f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters */
|
||
/* wrap them in f.ByteSwap for the big-endian guest value */
|
||
/* f.UpdateCR(n, v) -> CR field n from v's LOW 32 BITS vs 0 */
|
||
/* f.LoadCA / f.StoreCA -> xer.CA; f.StoreSAT -> vscr.SAT */
|
||
/* i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands */
|
||
/* The Register Effects and Status-Register Effects tables above */
|
||
/* enumerate every side effect a faithful translation must emit. */
|
||
```
|
||
|
||
## Implementation References
|
||
|
||
**`mfmsr`**
|
||
- Canary XML: [`tools/ppc-instructions.xml` — search for `mnem="mfmsr"`](https://github.com/xenia-canary/xenia-canary/blob/f21ebd49e979e44f081f474df78c3fbfee9cb3f2/tools/ppc-instructions.xml)
|
||
- Canary emitter: [`src/xenia/cpu/ppc/ppc_emit_control.cc:816`](https://github.com/xenia-canary/xenia-canary/blob/f21ebd49e979e44f081f474df78c3fbfee9cb3f2/src/xenia/cpu/ppc/ppc_emit_control.cc#L816)
|
||
- Sylpheed opcode: [`crates/sylpheed-ppc/src/opcode.rs:173`](../../../crates/sylpheed-ppc/src/opcode.rs#L173)
|
||
- Sylpheed decoder: [`crates/sylpheed-ppc/src/decoder.rs:886`](../../../crates/sylpheed-ppc/src/decoder.rs#L886)
|
||
<details><summary>Canary emitter (frozen snapshot @ <code>f21ebd49e9</code>)</summary>
|
||
|
||
```cpp
|
||
int InstrEmit_mfmsr(PPCHIRBuilder& f, const InstrData& i) {
|
||
// bit 48 = EE; interrupt enabled
|
||
// bit 62 = RI; recoverable interrupt
|
||
// return 8000h if unlocked (interrupts enabled), else 0
|
||
f.StoreGPR(i.X.RT, f.LoadContext(offsetof(PPCContext, msr), INT64_TYPE));
|
||
return 0;
|
||
}
|
||
```
|
||
</details>
|
||
|
||
<!-- GENERATED: END -->
|
||
|
||
## Special Cases & Edge Conditions
|
||
|
||
- **Privileged.** `mfmsr` is supervisor-only; executing it from problem state on real hardware raises a Privileged Instruction interrupt. Title code does use it anyway — Project Sylpheed's disassembly in `sylpheed.db` has 612 `mfmsr` (and 1,239 `mtmsrd`) — and Canary does not enforce privilege.
|
||
- **MSR layout (Xenon-relevant fields, big-endian bit numbering).**
|
||
|
||
| Bit | Name | Meaning |
|
||
| --- | --- | --- |
|
||
| 32 | EE | external interrupts enabled |
|
||
| 33 | PR | problem state (1 = user) |
|
||
| 34 | FP | floating-point available |
|
||
| 35 | ME | machine-check enable |
|
||
| 38 | DR | data address translation |
|
||
| 39 | IR | instruction address translation |
|
||
| 50 | LE | little-endian (always 0 on Xenon) |
|
||
| 63 | RI | recoverable interrupt |
|
||
|
||
The Xenon also exposes `MSR[SF]` (bit 0) = 1 for 64-bit mode; `MSR[HV]` (bit 3) for hypervisor. See PowerISA Book III for the full table.
|
||
- **Synchronisation.** Marked `sync` in Canary's `tools/ppc-instructions.xml` — `mfmsr` is execution-synchronising on real hardware (drains the pipeline before sampling MSR).
|
||
- **Canary model.** Canary stores MSR as a flat 64-bit context field and `mfmsr` returns it raw. No real bit semantics are modelled, and privilege is ignored.
|
||
- **Initial value.** Canary starts every thread with `MSR = 0x9030` (its comment: "dumped from a real 360") and changes it only through `mtmsr`/`mtmsrd`.
|
||
|
||
## Related Instructions
|
||
|
||
- [`mtmsr`](mtmsr.md) — write MSR from a GPR (32-bit form).
|
||
- [`mtmsrd`](mtmsrd.md) — write the full 64-bit MSR (PPC64 form).
|
||
- [`mfspr`](mfspr.md) — for non-MSR special registers; MSR has its own dedicated opcode.
|
||
- [`sc`](../branch/sc.md) — kernel entry where MSR transitions occur via `rfid`/`hrfid`.
|
||
|
||
`mfmsr` has no simplified mnemonics.
|
||
|
||
## IBM Reference
|
||
|
||
- [AIX 7.3 — `mfmsr` (Move from Machine State Register)](https://www.ibm.com/docs/en/aix/7.3.0?topic=set-mfmsr-move-from-machine-state-register-instruction)
|
||
- PowerISA v2.07B, Book III §4.3 — MSR field definitions.
|