Files
sim f3c512f2ab docs(ppc-manual): check every xenia-rs claim against Canary's source
The hand-written parts of the manual still described how the retired
xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of
those 490 statements is now either restated as what Canary's emitters and
x64 backend actually do (at the pinned canary_experimental commit), or
dropped where it only made sense for xenia-rs.

Checking them turned up claims that were wrong, not just outdated:

- VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr
  cannot see it); the pages said saturating ops set it stickily.
- Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1,
  vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them
  as working.
- Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not
  16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims
  and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec.
- Reservations are a 64 KiB block bitmap plus a value compare, not
  per-address tracking.

Claims that neither Canary's source nor a public spec settles are marked
unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness).

Generated regions are untouched; re-running the generator changes nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 21:52:38 +02:00

5.5 KiB
Raw Permalink Blame History

mfmsr — Move from Machine State Register

Category: Control / CR / SPR · Form: X · Opcode: 0x7c0000a6 · sync

Assembler Mnemonics

Mnemonic XML entry Flags Description
mfmsr mfmsr Move from Machine State Register

Syntax

mfmsr [RD]

Encoding

mfmsr — form X

  • Opcode word: 0x7c0000a6
  • Primary opcode (bits 05): 31
  • Extended opcode: 83
  • Synchronising: yes
Bits Field Meaning
05 OPCD primary opcode
610 RT/FRT/VRT destination
1115 RA/FRA/VRA source A
1620 RB/FRB/VRB source B
2130 XO extended opcode (10 bits)
31 Rc record-form flag

Operands

Field Role Description
MSR mfmsr: read Machine State Register.
RD mfmsr: write Destination GPR.

Register Effects

mfmsr

  • Reads (always): MSR
  • Reads (conditional): none
  • Writes (always): RD
  • Writes (conditional): none

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

; No hand-written pseudocode for this instruction yet.
; The authoritative semantics are the Canary emitter snapshot under
; Implementation References; about half of Canary's emitters open
; with the PPC-style definition as a comment (`RD <- (RA) + (RB)`).
; Every side effect is also enumerated in the Register Effects and
; Status-Register Effects tables above.

C Translation Example

/* No hand-written C yet. Translate the Canary emitter snapshot   */
/* under Implementation References; its HIR maps directly:        */
/*   f.LoadGPR(n) / f.StoreGPR(n, v)  -> r[n] / r[n] = v          */
/*   f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n]        */
/*   f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters   */
/*     wrap them in f.ByteSwap for the big-endian guest value      */
/*   f.UpdateCR(n, v)  -> CR field n from v's LOW 32 BITS vs 0     */
/*   f.LoadCA / f.StoreCA -> xer.CA;  f.StoreSAT -> vscr.SAT       */
/*   i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands  */
/* The Register Effects and Status-Register Effects tables above  */
/* enumerate every side effect a faithful translation must emit.  */

Implementation References

mfmsr

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_mfmsr(PPCHIRBuilder& f, const InstrData& i) {
  // bit 48 = EE; interrupt enabled
  // bit 62 = RI; recoverable interrupt
  // return 8000h if unlocked (interrupts enabled), else 0
  f.StoreGPR(i.X.RT, f.LoadContext(offsetof(PPCContext, msr), INT64_TYPE));
  return 0;
}

Special Cases & Edge Conditions

  • Privileged. mfmsr is supervisor-only; executing it from problem state on real hardware raises a Privileged Instruction interrupt. Title code does use it anyway — Project Sylpheed's disassembly in sylpheed.db has 612 mfmsr (and 1,239 mtmsrd) — and Canary does not enforce privilege.

  • MSR layout (Xenon-relevant fields, big-endian bit numbering).

    Bit Name Meaning
    32 EE external interrupts enabled
    33 PR problem state (1 = user)
    34 FP floating-point available
    35 ME machine-check enable
    38 DR data address translation
    39 IR instruction address translation
    50 LE little-endian (always 0 on Xenon)
    63 RI recoverable interrupt

    The Xenon also exposes MSR[SF] (bit 0) = 1 for 64-bit mode; MSR[HV] (bit 3) for hypervisor. See PowerISA Book III for the full table.

  • Synchronisation. Marked sync in Canary's tools/ppc-instructions.xmlmfmsr is execution-synchronising on real hardware (drains the pipeline before sampling MSR).

  • Canary model. Canary stores MSR as a flat 64-bit context field and mfmsr returns it raw. No real bit semantics are modelled, and privilege is ignored.

  • Initial value. Canary starts every thread with MSR = 0x9030 (its comment: "dumped from a real 360") and changes it only through mtmsr/mtmsrd.

  • mtmsr — write MSR from a GPR (32-bit form).
  • mtmsrd — write the full 64-bit MSR (PPC64 form).
  • mfspr — for non-MSR special registers; MSR has its own dedicated opcode.
  • sc — kernel entry where MSR transitions occur via rfid/hrfid.

mfmsr has no simplified mnemonics.

IBM Reference