Files
sim f3c512f2ab docs(ppc-manual): check every xenia-rs claim against Canary's source
The hand-written parts of the manual still described how the retired
xenia-rs interpreter behaved: its snapshots, Rust casts and helpers. Each of
those 490 statements is now either restated as what Canary's emitters and
x64 backend actually do (at the pinned canary_experimental commit), or
dropped where it only made sense for xenia-rs.

Checking them turned up claims that were wrong, not just outdated:

- VSCR[SAT] is never modelled in Canary (DID_SATURATE is a stub and mfvscr
  cannot see it); the pages said saturating ops set it stickily.
- Canary does not implement lswi/lswx/stswi/stswx, dcbi, mtfsb0/mtfsb1,
  vmsum*, vmhaddshs, vupkhpx/vupklpx, and most SPRs; pages described them
  as working.
- Traps evaluate TO in Canary; stvebx/stvehx/stvewx store one element, not
  16 bytes; mtmsrd writes only EE; fres/frsqrte/vrsqrtefp precision claims
  and the stfs "rounds under RN / sets FPSCR" claim contradicted the spec.
- Reservations are a 64 KiB block bitmap plus a value compare, not
  per-address tracking.

Claims that neither Canary's source nor a public spec settles are marked
unverified (NI at boot, vmaddcfp128 operand order, estimate bit-exactness).

Generated regions are untouched; re-running the generator changes nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 21:52:38 +02:00

11 KiB
Raw Permalink Blame History

lhz — Load Half Word and Zero

Category: Memory · Form: D · Opcode: 0xa0000000

Assembler Mnemonics

Mnemonic XML entry Flags Description
lhz lhz — Load Half Word and Zero
lhzu lhzu — Load Half Word and Zero with Update
lhzux lhzux — Load Half Word and Zero with Update Indexed
lhzx lhzx — Load Half Word and Zero Indexed

Syntax

lhz [RD], [d]([RA0])
lhzu [RD], [d]([RA])
lhzux [RD], [RA], [RB]
lhzx [RD], [RA0], [RB]

Encoding

lhz — form D

  • Opcode word: 0xa0000000
  • Primary opcode (bits 0–5): 40
  • Extended opcode: —
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT destination GPR (or RS when storing)
11–15 RA source GPR (0 ⇒ literal 0 for RA0 forms)
16–31 D/SI/UI 16-bit signed or unsigned immediate

lhzu — form D

  • Opcode word: 0xa4000000
  • Primary opcode (bits 0–5): 41
  • Extended opcode: —
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT destination GPR (or RS when storing)
11–15 RA source GPR (0 ⇒ literal 0 for RA0 forms)
16–31 D/SI/UI 16-bit signed or unsigned immediate

lhzux — form X

  • Opcode word: 0x7c00026e
  • Primary opcode (bits 0–5): 31
  • Extended opcode: 311
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT/FRT/VRT destination
11–15 RA/FRA/VRA source A
16–20 RB/FRB/VRB source B
21–30 XO extended opcode (10 bits)
31 Rc record-form flag

lhzx — form X

  • Opcode word: 0x7c00022e
  • Primary opcode (bits 0–5): 31
  • Extended opcode: 279
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT/FRT/VRT destination
11–15 RA/FRA/VRA source A
16–20 RB/FRB/VRB source B
21–30 XO extended opcode (10 bits)
31 Rc record-form flag

Operands

Field Role Description
RA0 lhz: read; lhzx: read Source GPR; when the encoded register number is 0 the operand is the literal 64-bit zero, not r0.
d lhz: read; lhzu: read 16-bit signed displacement (d) added to the base address register.
RD lhz: write; lhzu: write; lhzux: write; lhzx: write Destination GPR.
RA lhzu: read; lhzu: write; lhzux: read; lhzux: write Source GPR (r0–r31).
RB lhzux: read; lhzx: read Source GPR.

Register Effects

lhz

  • Reads (always): RA0, d
  • Reads (conditional): none
  • Writes (always): RD
  • Writes (conditional): none

lhzu

  • Reads (always): RA, d
  • Reads (conditional): none
  • Writes (always): RD, RA
  • Writes (conditional): none

lhzux

  • Reads (always): RA, RB
  • Reads (conditional): none
  • Writes (always): RD, RA
  • Writes (conditional): none

lhzx

  • Reads (always): RA0, RB
  • Reads (conditional): none
  • Writes (always): RD
  • Writes (conditional): none

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

EA <- (RA|0) + EXTS(d)
RT <- ZEXT16_to_64(MEM(EA, 2))

C Translation Example

/* No hand-written C yet. Translate the Canary emitter snapshot   */
/* under Implementation References; its HIR maps directly:        */
/*   f.LoadGPR(n) / f.StoreGPR(n, v)  -> r[n] / r[n] = v          */
/*   f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n]        */
/*   f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters   */
/*     wrap them in f.ByteSwap for the big-endian guest value      */
/*   f.UpdateCR(n, v)  -> CR field n from v's LOW 32 BITS vs 0     */
/*   f.LoadCA / f.StoreCA -> xer.CA;  f.StoreSAT -> vscr.SAT       */
/*   i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands  */
/* The Register Effects and Status-Register Effects tables above  */
/* enumerate every side effect a faithful translation must emit.  */

Implementation References

lhz

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhz(PPCHIRBuilder& f, const InstrData& i) {
  // if RA = 0 then
  //   b <- 0
  // else
  //   b <- (RA)
  // EA <- b + EXTS(D)
  // RT <- i48.0 || MEM(EA, 2)
  Value* b;
  if (i.D.RA == 0) {
    b = f.LoadZeroInt64();
  } else {
    b = f.LoadGPR(i.D.RA);
  }

  Value* offset = f.LoadConstantInt64(XEEXTS16(i.D.DS));
  Value* rt =
      f.ZeroExtend(f.ByteSwap(f.LoadOffset(b, offset, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.D.RT, rt);
  return 0;
}

lhzu

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzu(PPCHIRBuilder& f, const InstrData& i) {
  // EA <- (RA) + EXTS(D)
  // RT <- i48.0 || MEM(EA, 2)
  // RA <- EA
  Value* ra = f.LoadGPR(i.D.RA);
  Value* offset = f.LoadConstantInt64(XEEXTS16(i.D.DS));
  Value* rt = f.ZeroExtend(f.ByteSwap(f.LoadOffset(ra, offset, INT16_TYPE)),
                           INT64_TYPE);
  f.StoreGPR(i.D.RT, rt);
  StoreEA(f, i.D.RA, f.Add(ra, offset));
  return 0;
}

lhzux

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzux(PPCHIRBuilder& f, const InstrData& i) {
  // EA <- (RA) + (RB)
  // RT <- i48.0 || MEM(EA, 2)
  // RA <- EA
  Value* ea = CalculateEA(f, i.X.RA, i.X.RB);
  Value* rt = f.ZeroExtend(f.ByteSwap(f.Load(ea, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.X.RT, rt);
  StoreEA(f, i.X.RA, ea);
  return 0;
}

lhzx

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzx(PPCHIRBuilder& f, const InstrData& i) {
  // if RA = 0 then
  //   b <- 0
  // else
  //   b <- (RA)
  // EA <- b + (RB)
  // RT <- i48.0 || MEM(EA, 2)
  Value* ea = CalculateEA_0(f, i.X.RA, i.X.RB);
  Value* rt = f.ZeroExtend(f.ByteSwap(f.Load(ea, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.X.RT, rt);
  return 0;
}

Special Cases & Edge Conditions

  • Big-endian read, zero-extension. Reads 2 bytes big-endian, treats them as an unsigned 16-bit integer, zero-extends to 64 bits. The high 48 bits of RT become zero. Compare with lha, which sign-extends.
  • RA0 (non-update forms). RA = 0 in lhz / lhzx selects literal zero for absolute-address access. Update forms lhzu / lhzux invoke RA = 0 and RA = RT as invalid forms.
  • Update-form ordering. Canary computes EA, performs the load into RT, then writes RA ← EA. If RA == RT (an invalid form per IBM), the load result is overwritten by EA immediately.
  • No alignment requirement. Xenon executes unaligned half-word loads without faulting. MEM(EA, 2) reads the two consecutive bytes at EA.
  • Common as Unicode codepoint loader. Xbox 360 system strings are UTF-16; lhz is the canonical load for a single 16-bit codepoint.
  • Use lhz rather than lbz × 2 + shift. One fused instruction is faster and lets the load-store unit handle alignment.
  • Indexed variant operand order. lhzx RT, RA, RB — RA is the base (with RA0 semantics), RB is the offset.

IBM Reference