Files
Sylpheed/tools/ppc-manual/branch/bx.md
MechaCat02 6bdbf89ebc
All checks were successful
CI / Native — linux (pull_request) Successful in 37m56s
CI / WASM — Web (pull_request) Successful in 28m5s
CI / Formatting (pull_request) Successful in 59s
chore(tools): adopt the PPC manual and a canary launcher that works anywhere
CONSOLIDATION.md Phase 6. Both lived untracked in the project root -- on one
disk, backed up by nothing.

  tools/ppc-manual/   393 files, 3.7 MB. 455 instructions, 350 family pages,
                      598 mnemonics resolvable through index.json, plus the
                      generator that produced them.
  tools/run-canary.sh the oracle launcher.

🔴 THE LAUNCHER WAS BROKEN IN TWO WAYS AND IS REWRITTEN, not copied:

  * it pointed at `xenia-rs/sylpheed.iso`, a SYMLINK. Wine cannot resolve one
    and says "path invalid", which reads as a corrupt image rather than a path
    problem -- it has cost a session before. It now points at the real file and
    warns if handed a symlink.
  * it hardcoded one machine's absolute paths, and named `xenia-rs`, which this
    consolidation retires. Now derived from the script's own location, with
    SYLPH_CANARY_BIN / SYLPH_ISO overrides and a check that each exists.

The standing constraints are in its header where someone will read them: one
emulator at a time, Canary runs MUTED, and never judge a crash or a hang from
a Bash-launched run -- a SIGKILL that looked like the binary was the editor's
process supervisor.

⚠️ The manual's GENERATOR reads the xenia-rs source tree, which is going away.
Its decoder now lives here as crates/sylpheed-ppc, so the generator must be
repointed before it is run again. Recorded in the README rather than left for
someone to discover; the manual's content is checked in and regenerates from
nothing implicitly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-13 21:18:00 +02:00

5.6 KiB
Raw Blame History

bx — Branch

Category: Branch & System · Form: I · Opcode: 0x48000000 · sync

Assembler Mnemonics

Mnemonic XML entry Flags Description
b bx Branch
bl bx LK=1 Branch

Syntax

b[LK][AA] [ADDR]

Encoding

bx — form I

  • Opcode word: 0x48000000
  • Primary opcode (bits 05): 18
  • Extended opcode:
  • Synchronising: yes
Bits Field Meaning
05 OPCD primary opcode
629 LI signed 24-bit word-offset target
30 AA absolute-address flag
31 LK link flag (bl/ba/bla)

Operands

Field Role Description
LK bx: read Link bit. When 1, LR ← address-of-next-instruction before the branch is taken.
AA bx: read Absolute-address bit. When 1, the branch target is the sign-extended displacement itself; when 0, it is added to the current instruction address.
ADDR bx: read Encoded branch target displacement (24-bit for I-form, 14-bit for B-form, word-shifted).
LR bx: write (conditional) Link register. Written by bl/bla/bcl/bclrl/bcctrl; read by bclr/bclrl.

Register Effects

bx

  • Reads (always): LK, AA, ADDR
  • Reads (conditional): none
  • Writes (always): none
  • Writes (conditional): LR

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

NIA <- (CIA + EXTS(LI || 0b00))                   if AA=0
       <-          EXTS(LI || 0b00)                   if AA=1
if LK then LR <- CIA + 4

C Translation Example

/* b / bl / ba / bla — unconditional branch (I-form, primary 18)   */
int32_t  li     = (int32_t)(insn.LI << 2);  /* sign-extended word-offset */
uint32_t target = insn.AA ? (uint32_t)li : (uint32_t)(pc + li);
uint32_t next   = pc + 4;
if (insn.LK) lr = next;                  /* bl / bla save return addr */
pc = target;

Implementation References

bx

xenia-rs interpreter body (frozen snapshot)
        PpcOpcode::bx => {
            let target = if instr.aa() {
                instr.li() as u32
            } else {
                ctx.pc.wrapping_add(instr.li() as u32)
            };
            if instr.lk() {
                ctx.lr = (ctx.pc + 4) as u64;
            }
            ctx.pc = target;
        }

Special Cases & Edge Conditions

  • 24-bit word-aligned target. LI is a 24-bit signed word-count. Hardware concatenates LI || 0b00 (adds the implicit two low zero bits) and sign-extends to 64 bits before using it as an address. The displacement range is therefore ±32 MiB in bytes (2^25 … +2^25 4).
  • Four mnemonics, one opcode. The four runtime variants selected by AA and LK:
    • bAA = 0, LK = 0 — PC-relative, no link.
    • blAA = 0, LK = 1 — PC-relative, LR = CIA + 4 (the ubiquitous function-call primitive).
    • baAA = 1, LK = 0 — absolute, no link.
    • blaAA = 1, LK = 1 — absolute, link. Xbox 360 code almost exclusively uses b and bl; ba / bla appear only in kernel / firmware stubs.
  • Target alignment. LI is scaled by 4, so all targets are 4-byte aligned by construction. There is no low-bit encoding of ARM-style Thumb — PPC has one instruction width.
  • LR write is before the branch. In bl, LR receives CIA + 4 (the address of the instruction after the branch) before execution transfers to the target. Nested calls naturally overwrite LR; callees must spill it (mflr + std) before making their own bl.
  • Indirect tail calls. A tail call to an indirect target is encoded as mtctr + bctr (see bcctrx), not bxbx has no register-based form.
  • No condition test. Use bcx for conditional displacement branches or bclrx / bcctrx for conditional LR/CTR jumps.
  • Speculative execution. The Xenon fetches past bx; translators that mask control flow must treat the target as a single-destination control transfer.
  • bcx — conditional displacement branch (B-form, ±32 KiB range).
  • bclrx, bcctrx — branch to LR / CTR, conditional and unconditional.
  • mtlr, mflr — LR save/restore for nested bl calls.
  • sc — system call; an alternative control-flow exit to the kernel.

Simplified Mnemonics

Assemblers emit b, bl, ba, bla for the four runtime combinations. There is no further simplification.

IBM Reference