Files
sim f3c512f2ab docs(ppc-manual): check every xenia-rs claim against Canary's source
The hand-written parts of the manual still described how the retired
xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of
those 490 statements is now either restated as what Canary's emitters and
x64 backend actually do (at the pinned canary_experimental commit), or
dropped where it only made sense for xenia-rs.

Checking them turned up claims that were wrong, not just outdated:

- VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr
  cannot see it); the pages said saturating ops set it stickily.
- Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1,
  vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them
  as working.
- Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not
  16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims
  and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec.
- Reservations are a 64 KiB block bitmap plus a value compare, not
  per-address tracking.

Claims that neither Canary's source nor a public spec settles are marked
unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness).

Generated regions are untouched; re-running the generator changes nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 21:52:38 +02:00

7.6 KiB
Raw Permalink Blame History

bcctrx — Branch Conditional to Count Register

Category: Branch & System · Form: XL · Opcode: 0x4c000420 · sync

Assembler Mnemonics

Mnemonic XML entry Flags Description
bcctr bcctrx Branch Conditional to Count Register
bcctrl bcctrx LK=1 Branch Conditional to Count Register

Syntax

bcctr[LK] [BO], [BI]

Encoding

bcctrx — form XL

  • Opcode word: 0x4c000420
  • Primary opcode (bits 05): 19
  • Extended opcode: 528
  • Synchronising: yes
Bits Field Meaning
05 OPCD primary opcode (19)
610 BT/BO target / branch options
1115 BA/BI source A / CR bit to test
1620 BB source B
2130 XO extended opcode (10 bits)
31 LK link flag

Operands

Field Role Description
LK bcctrx: read Link bit. When 1, LR ← address-of-next-instruction before the branch is taken.
BO bcctrx: read 5-bit branch options — selects CTR decrement, CTR test polarity, and CR bit test polarity. See forms/XL.md.
BI bcctrx: read CR bit index (031) selected by BO's condition test.
CR bcctrx: read Condition-register update. When Rc=1, CR field 0 (or CR6 for vector compares, CR1 for FPU) is updated from the result.
CTR bcctrx: read Count register. Decremented and optionally tested by conditional branches when BO[2]=0.
LR bcctrx: write (conditional) Link register. Written by bl/bla/bcl/bclrl/bcctrl; read by bclr/bclrl.

Register Effects

bcctrx

  • Reads (always): LK, BO, BI, CR, CTR
  • Reads (conditional): none
  • Writes (always): none
  • Writes (conditional): LR

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

cond_ok <- BO[0] | (CR[BI] ≡ BO[1])
if cond_ok then NIA <- CTR[0:61] || 0b00
if LK then LR <- CIA + 4

C Translation Example

/* No hand-written C yet. Translate the Canary emitter snapshot   */
/* under Implementation References; its HIR maps directly:        */
/*   f.LoadGPR(n) / f.StoreGPR(n, v)  -> r[n] / r[n] = v          */
/*   f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n]        */
/*   f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters   */
/*     wrap them in f.ByteSwap for the big-endian guest value      */
/*   f.UpdateCR(n, v)  -> CR field n from v's LOW 32 BITS vs 0     */
/*   f.LoadCA / f.StoreCA -> xer.CA;  f.StoreSAT -> vscr.SAT       */
/*   i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands  */
/* The Register Effects and Status-Register Effects tables above  */
/* enumerate every side effect a faithful translation must emit.  */

Implementation References

bcctrx

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_bcctrx(PPCHIRBuilder& f, const InstrData& i) {
  // cond_ok <- BO[0] | (CR[BI+32] ≡ BO[1])
  // if cond_ok then
  //   NIA <- CTR[0:61] || 0b00
  // if LK then
  //   LR <- CIA + 4

  // NOTE: the condition bits are reversed!
  // 01234 (docs)
  // 43210 (real)

  Value* cond_ok = NULL;
  bool not_cond_ok = false;
  if (select_bits(i.XL.BO, 4, 4)) {
    // Ignore cond.
  } else {
    Value* cr = f.LoadCRField(i.XL.BI >> 2, i.XL.BI & 3);
    cond_ok = cr;
    if (select_bits(i.XL.BO, 3, 3)) {
      // Expect true.
      not_cond_ok = false;
    } else {
      // Expect false.
      not_cond_ok = true;
    }
  }

  bool expect_true = !not_cond_ok;
  return InstrEmit_branch(f, "bcctrx", i.address, f.LoadCTR(), i.XL.LK, cond_ok,
                          expect_true);
}

Special Cases & Edge Conditions

  • No CTR decrement. Unlike bcx and bclrx, bcctr cannot decrement CTR (the CTR is the target). The PowerISA reserves BO[2] = 0 encodings — they are invalid on bcctrx. Canary ignores BO[2]/BO[3] and treats every bcctr as a pure CR-conditional branch.

  • CTR alignment mask. The target is CTR & ~3. Like bclr, the low two bits are stripped — a misaligned CTR is silently rounded down rather than trapping.

  • BO encoding (CR-only subset). Because CTR-test bits are unused, only four BO patterns are meaningful:

    BO (binary) Meaning
    0100z branch if CR[BI] false
    0101z branch if CR[BI] true
    1z1zz branch always (bctr)
    0000z/001at/etc. reserved — implementation-defined
  • Indirect call/dispatch idiom. mtctr rN; bctrl is the canonical PPC indirect call: load function pointer into CTR, call. With LK=1, PowerISA writes LR ← CIA + 4 whether or not the branch is taken, and Canary does the same — its InstrEmit_branch stores LR before the conditional transfer, exactly as for bcx.

  • bctr for switch tables. Compilers emit bctr (not bctrl) for jump-table dispatch, with CTR loaded from a base + (index*4) lookup. Canary emits an indirect call to the CTR value (CallIndirect).

  • Synchronisation. Marked sync in Canary's tools/ppc-instructions.xml — context-synchronising. JIT backends must ensure prior side effects have committed before the indirect transfer.

  • No prediction hint sensitivity. Xenon predicts indirect branches via a separate target cache; the BO[4] hint is mostly cosmetic for bcctr.

  • bclrx — branch conditional to LR (function returns).
  • bcx — branch conditional to displacement (B-form).
  • bx — unconditional displacement branch (I-form).
  • mtctr, mfctr — load/read CTR via mtspr 9 / mfspr 9.
  • sc — alternative control-flow exit (system call).

Simplified Mnemonics

Simplified Expansion
bctr bcctr BO=0b10100, BI=0 — unconditional indirect branch
bctrl bcctrl BO=0b10100, BI=0 — unconditional indirect call
beqctr crN bcctr BO=0b01100, BI=4·N+2 — call CTR if crN.EQ
bnectr crN bcctr BO=0b00100, BI=4·N+2 — call CTR if crN.NE
bltctr crN bcctr BO=0b01100, BI=4·N+0 — call CTR if crN.LT
bgectr crN bcctr BO=0b00100, BI=4·N+0 — call CTR if crN.GE
bgtctr crN bcctr BO=0b01100, BI=4·N+1 — call CTR if crN.GT
blectr crN bcctr BO=0b00100, BI=4·N+1 — call CTR if crN.LE

The unconditional bctr/bctrl are by far the most common in Xbox 360 disassembly (compiler-emitted indirect calls and switch dispatch).

IBM Reference