The hand-written parts of the manual still described how the retired xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of those 490 statements is now either restated as what Canary's emitters and x64 backend actually do (at the pinned canary_experimental commit), or dropped where it only made sense for xenia-rs. Checking them turned up claims that were wrong, not just outdated: - VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr cannot see it); the pages said saturating ops set it stickily. - Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1, vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them as working. - Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not 16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec. - Reservations are a 64 KiB block bitmap plus a value compare, not per-address tracking. Claims that neither Canary's source nor a public spec settles are marked unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness). Generated regions are untouched; re-running the generator changes nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
126 lines
5.4 KiB
Markdown
126 lines
5.4 KiB
Markdown
# `mtmsr` — Move to Machine State Register
|
||
|
||
> **Category:** [Control / CR / SPR](../categories/control.md) · **Form:** [X](../forms/X.md) · **Opcode:** `0x7c000124` · _sync_
|
||
|
||
<!-- GENERATED: BEGIN -->
|
||
|
||
## Assembler Mnemonics
|
||
|
||
| Mnemonic | XML entry | Flags | Description |
|
||
| --- | --- | --- | --- |
|
||
| `mtmsr` | `mtmsr` | — | Move to Machine State Register |
|
||
|
||
## Syntax
|
||
|
||
```asm
|
||
mtmsr [RS]
|
||
```
|
||
|
||
## Encoding
|
||
|
||
### `mtmsr` — form `X`
|
||
|
||
- **Opcode word:** `0x7c000124`
|
||
- **Primary opcode (bits 0–5):** `31`
|
||
- **Extended opcode:** `146`
|
||
- **Synchronising:** yes
|
||
|
||
| Bits | Field | Meaning |
|
||
| --- | --- | --- |
|
||
| 0–5 | `OPCD` | primary opcode |
|
||
| 6–10 | `RT/FRT/VRT` | destination |
|
||
| 11–15 | `RA/FRA/VRA` | source A |
|
||
| 16–20 | `RB/FRB/VRB` | source B |
|
||
| 21–30 | `XO` | extended opcode (10 bits) |
|
||
| 31 | `Rc` | record-form flag |
|
||
|
||
## Operands
|
||
|
||
| Field | Role | Description |
|
||
| --- | --- | --- |
|
||
| `RS` | mtmsr: read | Source GPR (alias for RD in some stores). |
|
||
| `MSR` | mtmsr: write | Machine State Register. |
|
||
|
||
## Register Effects
|
||
|
||
### `mtmsr`
|
||
|
||
- **Reads (always):** `RS`
|
||
- **Reads (conditional):** _none_
|
||
- **Writes (always):** `MSR`
|
||
- **Writes (conditional):** _none_
|
||
|
||
## Status-Register Effects
|
||
|
||
_No condition-register or status-register effects._
|
||
|
||
## Operation (pseudocode)
|
||
|
||
```
|
||
; No hand-written pseudocode for this instruction yet.
|
||
; The authoritative semantics are the Canary emitter snapshot under
|
||
; Implementation References; about half of Canary's emitters open
|
||
; with the PPC-style definition as a comment (`RD <- (RA) + (RB)`).
|
||
; Every side effect is also enumerated in the Register Effects and
|
||
; Status-Register Effects tables above.
|
||
```
|
||
|
||
## C Translation Example
|
||
|
||
```c
|
||
/* No hand-written C yet. Translate the Canary emitter snapshot */
|
||
/* under Implementation References; its HIR maps directly: */
|
||
/* f.LoadGPR(n) / f.StoreGPR(n, v) -> r[n] / r[n] = v */
|
||
/* f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n] */
|
||
/* f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters */
|
||
/* wrap them in f.ByteSwap for the big-endian guest value */
|
||
/* f.UpdateCR(n, v) -> CR field n from v's LOW 32 BITS vs 0 */
|
||
/* f.LoadCA / f.StoreCA -> xer.CA; f.StoreSAT -> vscr.SAT */
|
||
/* i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands */
|
||
/* The Register Effects and Status-Register Effects tables above */
|
||
/* enumerate every side effect a faithful translation must emit. */
|
||
```
|
||
|
||
## Implementation References
|
||
|
||
**`mtmsr`**
|
||
- Canary XML: [`tools/ppc-instructions.xml` — search for `mnem="mtmsr"`](https://github.com/xenia-canary/xenia-canary/blob/f21ebd49e979e44f081f474df78c3fbfee9cb3f2/tools/ppc-instructions.xml)
|
||
- Canary emitter: [`src/xenia/cpu/ppc/ppc_emit_control.cc:824`](https://github.com/xenia-canary/xenia-canary/blob/f21ebd49e979e44f081f474df78c3fbfee9cb3f2/src/xenia/cpu/ppc/ppc_emit_control.cc#L824)
|
||
- Sylpheed opcode: [`crates/sylpheed-ppc/src/opcode.rs:183`](../../../crates/sylpheed-ppc/src/opcode.rs#L183)
|
||
- Sylpheed decoder: [`crates/sylpheed-ppc/src/decoder.rs:895`](../../../crates/sylpheed-ppc/src/decoder.rs#L895)
|
||
<details><summary>Canary emitter (frozen snapshot @ <code>f21ebd49e9</code>)</summary>
|
||
|
||
```cpp
|
||
int InstrEmit_mtmsr(PPCHIRBuilder& f, const InstrData& i) {
|
||
f.StoreContext(offsetof(PPCContext, msr), f.LoadGPR(i.X.RT));
|
||
return 0;
|
||
}
|
||
```
|
||
</details>
|
||
|
||
<!-- GENERATED: END -->
|
||
|
||
## Special Cases & Edge Conditions
|
||
|
||
- **Privileged.** `mtmsr` is supervisor-only on real hardware. Executing it from problem state raises a Privileged Instruction interrupt. Game code never emits it; only the kernel and exception-return paths use it.
|
||
- **32-bit form.** `mtmsr` writes the **low 32 bits** of MSR (legacy PPC32 form). On the Xenon (a PPC64 implementation), use [`mtmsrd`](mtmsrd.md) for the full 64-bit MSR. Some Xenon kernel sequences still use `mtmsr` to leave the high half untouched while flipping low-half flags like EE/PR.
|
||
- **Synchronisation.** Marked `sync` — `mtmsr` is **execution-synchronising**. The Xenon must drain all preceding instructions before the new MSR takes effect, and PowerISA recommends a following `isync` to guarantee subsequent instructions execute under the new MSR.
|
||
- **`L` operand.** Modern PowerISA defines an `L` bit selecting "EE/RI only" (`L=1`) versus "all" (`L=0`); Canary's `mtmsr` ignores `L` and writes the entire MSR. Real Xbox 360 kernel code uses both `L=0` and `L=1`.
|
||
- **Canary model.** Treats MSR as a flat 64-bit context field. `mtmsr` stores `RS` whole; `mtmsrd` differs (see its page). No privilege or atomicity is enforced; no side effects on TLB / interrupt mask / endianness are simulated.
|
||
- **No CR / XER side effects.**
|
||
- **Caveat for translators.** Because Canary implements the kernel natively, the guest MSR has no architectural meaning beyond storage. Code that reads it back via [`mfmsr`](mfmsr.md) sees what `mtmsr` last wrote — `mtmsrd` changes only `EE`.
|
||
|
||
## Related Instructions
|
||
|
||
- [`mfmsr`](mfmsr.md) — read MSR.
|
||
- [`mtmsrd`](mtmsrd.md) — 64-bit form (writes the entire MSR).
|
||
- [`sc`](../branch/sc.md) — kernel entry; the kernel handler typically uses `mtmsr`/`rfid` to return.
|
||
- [`isync`](mtmsr.md) — companion fence after MSR writes.
|
||
|
||
`mtmsr` has no simplified mnemonics.
|
||
|
||
## IBM Reference
|
||
|
||
- [AIX 7.3 — `mtmsr` (Move to Machine State Register)](https://www.ibm.com/docs/en/aix/7.3.0?topic=set-mtmsr-move-machine-state-register-instruction)
|
||
- PowerISA v2.07B, Book III §4.3.1 — MSR field definitions and `L`-bit semantics.
|