Files
sim f3c512f2ab docs(ppc-manual): check every xenia-rs claim against Canary's source
The hand-written parts of the manual still described how the retired
xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of
those 490 statements is now either restated as what Canary's emitters and
x64 backend actually do (at the pinned canary_experimental commit), or
dropped where it only made sense for xenia-rs.

Checking them turned up claims that were wrong, not just outdated:

- VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr
  cannot see it); the pages said saturating ops set it stickily.
- Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1,
  vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them
  as working.
- Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not
  16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims
  and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec.
- Reservations are a 64 KiB block bitmap plus a value compare, not
  per-address tracking.

Claims that neither Canary's source nor a public spec settles are marked
unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness).

Generated regions are untouched; re-running the generator changes nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 21:52:38 +02:00

5.5 KiB
Raw Permalink Blame History

mtmsrd — Move to Machine State Register Doubleword

Category: Control / CR / SPR · Form: X · Opcode: 0x7c000164 · sync

Assembler Mnemonics

Mnemonic XML entry Flags Description
mtmsrd mtmsrd Move to Machine State Register Doubleword

Syntax

mtmsrd [RS]

Encoding

mtmsrd — form X

  • Opcode word: 0x7c000164
  • Primary opcode (bits 05): 31
  • Extended opcode: 178
  • Synchronising: yes
Bits Field Meaning
05 OPCD primary opcode
610 RT/FRT/VRT destination
1115 RA/FRA/VRA source A
1620 RB/FRB/VRB source B
2130 XO extended opcode (10 bits)
31 Rc record-form flag

Operands

Field Role Description
RS mtmsrd: read Source GPR (alias for RD in some stores).
MSR mtmsrd: write Machine State Register.

Register Effects

mtmsrd

  • Reads (always): RS
  • Reads (conditional): none
  • Writes (always): MSR
  • Writes (conditional): none

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

; No hand-written pseudocode for this instruction yet.
; The authoritative semantics are the Canary emitter snapshot under
; Implementation References; about half of Canary's emitters open
; with the PPC-style definition as a comment (`RD <- (RA) + (RB)`).
; Every side effect is also enumerated in the Register Effects and
; Status-Register Effects tables above.

C Translation Example

/* No hand-written C yet. Translate the Canary emitter snapshot   */
/* under Implementation References; its HIR maps directly:        */
/*   f.LoadGPR(n) / f.StoreGPR(n, v)  -> r[n] / r[n] = v          */
/*   f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n]        */
/*   f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters   */
/*     wrap them in f.ByteSwap for the big-endian guest value      */
/*   f.UpdateCR(n, v)  -> CR field n from v's LOW 32 BITS vs 0     */
/*   f.LoadCA / f.StoreCA -> xer.CA;  f.StoreSAT -> vscr.SAT       */
/*   i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands  */
/* The Register Effects and Status-Register Effects tables above  */
/* enumerate every side effect a faithful translation must emit.  */

Implementation References

mtmsrd

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_mtmsrd(PPCHIRBuilder& f, const InstrData& i) {
  // todo: this is moving msr under a mask, so only writing EE and RI

  Value* from = f.LoadGPR(i.X.RT);
  Value* mtmsrd_mask = f.LoadConstantUint64((1ULL << 15));
  Value* msr = f.LoadContext(offsetof(PPCContext, msr), INT64_TYPE);

  Value* new_msr = f.Or(f.And(from, mtmsrd_mask), f.AndNot(msr, mtmsrd_mask));

  f.StoreContext(offsetof(PPCContext, msr), new_msr);
  return 0;
}

Special Cases & Edge Conditions

  • Privileged. Like mtmsr, supervisor-only. Game code never emits it.
  • 64-bit form. Writes all 64 MSR bits — including MSR[SF] (bit 0) which selects 64-bit mode, MSR[HV] (bit 3, hypervisor), MSR[EE] (32, external interrupts), MSR[PR] (33, problem state), MSR[FP] (34), MSR[ME] (35, machine-check enable), MSR[DR]/MSR[IR] (data/instruction translation, 38/39), MSR[RI] (63, recoverable interrupt). On the Xenon kernel this is the canonical MSR-write instruction.
  • L operand. Same L-bit selector as mtmsr: L=1 updates only MSR[EE] and MSR[RI]; L=0 updates the full register. ⚠️ Canary ignores L and always updates only MSR[EE] (mask 0x8000), leaving every other bit — including RI — unchanged.
  • Synchronisation. Marked sync — execution-synchronising. PowerISA recommends isync afterwards if subsequent fetch / data semantics depend on the new MSR.
  • Canary model. Not shared with mtmsr: mtmsrd computes (RS & 0x8000) | (MSR & ~0x8000). No architectural side effects beyond writing the storage; no privilege check.
  • No CR / XER updates.
  • Used in interrupt return paths. Kernel handlers commonly write SRR1 (saved MSR) into MSR via mtmsrd followed by rfid to atomically restore state and jump to SRR0.
  • mfmsr — read MSR.
  • mtmsr — 32-bit form (low half only).
  • sc — kernel entry; the kernel typically pairs mtmsrd + rfid to return.

mtmsrd has no simplified mnemonics.

IBM Reference