Files
sim f3c512f2ab docs(ppc-manual): check every xenia-rs claim against Canary's source
The hand-written parts of the manual still described how the retired
xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of
those 490 statements is now either restated as what Canary's emitters and
x64 backend actually do (at the pinned canary_experimental commit), or
dropped where it only made sense for xenia-rs.

Checking them turned up claims that were wrong, not just outdated:

- VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr
  cannot see it); the pages said saturating ops set it stickily.
- Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1,
  vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them
  as working.
- Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not
  16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims
  and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec.
- Reservations are a 64 KiB block bitmap plus a value compare, not
  per-address tracking.

Claims that neither Canary's source nor a public spec settles are marked
unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness).

Generated regions are untouched; re-running the generator changes nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 21:52:38 +02:00

6.4 KiB
Raw Permalink Blame History

mtspr — Move to Special-Purpose Register

Category: Control / CR / SPR · Form: XFX · Opcode: 0x7c0003a6

Assembler Mnemonics

Mnemonic XML entry Flags Description
mtspr mtspr Move to Special-Purpose Register

Syntax

mtspr [SPR], [RS]

Encoding

mtspr — form XFX

  • Opcode word: 0x7c0003a6
  • Primary opcode (bits 05): 31
  • Extended opcode: 467
  • Synchronising: no
Bits Field Meaning
05 OPCD primary opcode (31)
610 RT destination / source GPR
1120 spr/tbr/FXM SPR/TBR number (byte-swapped halves) or CR field mask
2130 XO extended opcode
31 reserved

Operands

Field Role Description
RS mtspr: read Source GPR (alias for RD in some stores).
SPR mtspr: write Special-Purpose-Register number. Encoded with the two 5-bit halves swapped (bits 11-15 become the high half, bits 16-20 the low half).

Register Effects

mtspr

  • Reads (always): RS
  • Reads (conditional): none
  • Writes (always): SPR
  • Writes (conditional): none

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

n <- spr_number(SPR)
SPR(n) <- (RS)

C Translation Example

/* No hand-written C yet. Translate the Canary emitter snapshot   */
/* under Implementation References; its HIR maps directly:        */
/*   f.LoadGPR(n) / f.StoreGPR(n, v)  -> r[n] / r[n] = v          */
/*   f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n]        */
/*   f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters   */
/*     wrap them in f.ByteSwap for the big-endian guest value      */
/*   f.UpdateCR(n, v)  -> CR field n from v's LOW 32 BITS vs 0     */
/*   f.LoadCA / f.StoreCA -> xer.CA;  f.StoreSAT -> vscr.SAT       */
/*   i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands  */
/* The Register Effects and Status-Register Effects tables above  */
/* enumerate every side effect a faithful translation must emit.  */

Implementation References

mtspr

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_mtspr(PPCHIRBuilder& f, const InstrData& i) {
  // n <- spr[5:9] || spr[0:4]
  // if length(SPR(n)) = 64 then
  //   SPR(n) <- (RS)
  // else
  //   SPR(n) <- (RS)[32:63]

  Value* rt = f.LoadGPR(i.XFX.RT);

  const uint32_t n = ((i.XFX.spr & 0x1F) << 5) | ((i.XFX.spr >> 5) & 0x1F);
  switch (n) {
    case 1:
      // XER
      f.StoreXER(rt);
      break;
    case 8:
      // LR
      f.StoreLR(rt);
      break;
    case 9:
      // CTR
      f.StoreCTR(rt);
      break;
    case 256:

      f.StoreContext(offsetof(PPCContext, vrsave), f.Truncate(rt, INT32_TYPE));
      // VRSAVE
      break;
    default:
      XEINSTRNOTIMPLEMENTED();
      return 1;
  }

  return 0;
}

Special Cases & Edge Conditions

  • SPR halves are swapped in the encoding. As with mfspr, the 10-bit spr field stores the two 5-bit halves transposed. Software always names the logical SPR number; assemblers handle the swap. Decoded number n = ((field & 0x1F) << 5) | ((field >> 5) & 0x1F).

  • SPRs writable from userspace (Xenon) — the only ones Canary implements.

    Decoded # Name Effect
    1 XER StoreXER(RS)
    8 LR StoreLR(RS)
    9 CTR StoreCTR(RS)
    256 VRSAVE low 32 bits of RS into vrsave
  • Every other SPR is unimplemented in Canary. SPRG0..3, HID0, HID1, DAR, DSISR and the rest are not swallowed: translating the mtspr logs "Unimplemented instr" and, with the default break_on_unimplemented_instructions, breaks.

  • Privileged SPRs. On real hardware, writes to MSR-visible kernel SPRs (SPRG0..3, HID0/1, DSISR, DAR, PIR, etc.) require supervisor mode and trap from problem state. Canary does not enforce privilege — it implements only XER, LR, CTR and VRSAVE and treats mtspr to any other SPR as an unimplemented instruction.

  • Time-base writes are privileged. mtspr 268/269 (TBL/TBU) only works in supervisor mode on real hardware, and Canary treats them as unimplemented — do not assume the time base can be guest-written.

  • Simplified mnemonics. mtxer RSmtspr 1, RS, mtlr RSmtspr 8, RS, mtctr RSmtspr 9, RS. These dominate Xbox 360 disassembly.

  • No CR / XER side effects. mtspr itself doesn't record (the target SPR may itself be XER, in which case XER is being directly overwritten).

  • Not synchronising. Canary's tools/ppc-instructions.xml omits the sync flag; PowerISA does require some mtspr cases (e.g. SDR1, MMU regs) to be context-synchronising — none of them appear in title binaries.

  • mfspr — inverse: read an SPR into a GPR.
  • mftb — read time-base (preferred over mfspr TBL/TBU).
  • mtmsr, mtmsrd — write MSR (separate opcode).
  • mcrxr — sample-and-clear XER's overflow/carry bits.

Simplified Mnemonics

Simplified Expansion
mtxer RS mtspr 1, RS
mtlr RS mtspr 8, RS
mtctr RS mtspr 9, RS

IBM Reference