Files
Sylpheed/tools/ppc-manual/memory/lhz.md
sim 7f8a81b8f8
All checks were successful
CI / Native — linux (pull_request) Successful in 2h2m37s
CI / WASM — Web (pull_request) Successful in 30m13s
CI / Formatting (pull_request) Successful in 1m23s
docs(ppc-manual): quote Canary and our own decoder, not the retired xenia-rs
The generator had not been able to run correctly since the manual moved into
`tools/ppc-manual/`: it computed the repository root as `HERE.parent.parent`,
which now names `tools/`, so the XML, Canary's emitters and xenia-rs all stopped
resolving — silently, because both scrapers skipped what they could not find.
Every page's references had been pointing at paths that exist nowhere.

What each source contributed, measured on the 350 pages before this change:

  Operation (pseudocode)  251 pages: fixed boilerplate "derives from the xenia-rs
                          interpreter"; 99 carry real hand-written seeds
  C translation           337 pages: the same kind of boilerplate
  xenia-rs snapshot       336 pages: the interpreter arm, pasted in — the only
                          per-instruction semantics on unseeded pages
  links                   xenia-rs opcode/decoder/interpreter + Canary emitter

Now:

  * semantics come from **Xenia Canary**, the reference emulator, read through
    `git show` at a pinned upstream commit (`origin/canary_experimental`,
    f21ebd49e9). Not our checkout: it carries instrumentation and lacked
    upstream's `mcrf` fix, so it would have published probes and a wrong `mcrf`.
    Each page embeds the emitter (`InstrEmit_<mnem>`), and for the 128 pure
    one-line delegations also the helper that holds the semantics.
  * decode references point at `crates/sylpheed-ppc` — the decoder that
    produces `sylpheed.db` — as in-repo relative links.
  * the boilerplate now says what is true, and the C translation guide maps
    Canary's actual HIR calls, checked against `ppc_hir_builder.h` (including
    that `UpdateCR(n, v)` truncates to 32 bits).
  * `rust_scraper.py` -> `decoder_scraper.py` (interpreter half dropped);
    missing sources are now errors, not empty results.

Verified:

  consistency checks        455 XML entries, 350 families, 598 index keys
  hand-written tails        386/386 byte-identical after regeneration
  xenia-rs in generated     0
  pages with a snapshot     349/350 (was 336) — `dcbi` has no Canary emitter at all
  in-repo decoder links     910/910 resolve to a line holding the identifier
  emitter boundaries        brace counter == column-0 `}` rule on 521/521;
                            preprocessor model unit-tested (#if 0/#else/#elif)
  idempotency               re-run: 0 pages updated, 0 working-tree changes

Hand-written notes (outside the generated regions) are not rewritten here:

  * 110 links into `../../xenia-rs/...` were dead; they now point at the file in
    the archived repository (git.mc02.dev/fabi/xenia-rs @ 8401d4d). Line anchors
    were dropped because the notes predate that commit — 0 of 441 old line
    ranges match it — and a precise-looking wrong anchor is worse than none. The
    link text, which carries the author's line numbers, is unchanged.
  * 140 prose claims about xenia-rs's behaviour remain. 23 are verified to hold
    for Canary too (the 32-bit CR0 truncation, OE left unimplemented); the other
    114 need checking one by one, and some invert — e.g. `divdx` notes a correct
    64-bit CR0 update in xenia-rs where Canary's `UpdateCR` truncates. Left for
    a deliberate pass rather than a blind substitution.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-16 20:34:34 +02:00

11 KiB
Raw Blame History

lhz — Load Half Word and Zero

Category: Memory · Form: D · Opcode: 0xa0000000

Assembler Mnemonics

Mnemonic XML entry Flags Description
lhz lhz — Load Half Word and Zero
lhzu lhzu — Load Half Word and Zero with Update
lhzux lhzux — Load Half Word and Zero with Update Indexed
lhzx lhzx — Load Half Word and Zero Indexed

Syntax

lhz [RD], [d]([RA0])
lhzu [RD], [d]([RA])
lhzux [RD], [RA], [RB]
lhzx [RD], [RA0], [RB]

Encoding

lhz — form D

  • Opcode word: 0xa0000000
  • Primary opcode (bits 0–5): 40
  • Extended opcode: —
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT destination GPR (or RS when storing)
11–15 RA source GPR (0 ⇒ literal 0 for RA0 forms)
16–31 D/SI/UI 16-bit signed or unsigned immediate

lhzu — form D

  • Opcode word: 0xa4000000
  • Primary opcode (bits 0–5): 41
  • Extended opcode: —
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT destination GPR (or RS when storing)
11–15 RA source GPR (0 ⇒ literal 0 for RA0 forms)
16–31 D/SI/UI 16-bit signed or unsigned immediate

lhzux — form X

  • Opcode word: 0x7c00026e
  • Primary opcode (bits 0–5): 31
  • Extended opcode: 311
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT/FRT/VRT destination
11–15 RA/FRA/VRA source A
16–20 RB/FRB/VRB source B
21–30 XO extended opcode (10 bits)
31 Rc record-form flag

lhzx — form X

  • Opcode word: 0x7c00022e
  • Primary opcode (bits 0–5): 31
  • Extended opcode: 279
  • Synchronising: no
Bits Field Meaning
0–5 OPCD primary opcode
6–10 RT/FRT/VRT destination
11–15 RA/FRA/VRA source A
16–20 RB/FRB/VRB source B
21–30 XO extended opcode (10 bits)
31 Rc record-form flag

Operands

Field Role Description
RA0 lhz: read; lhzx: read Source GPR; when the encoded register number is 0 the operand is the literal 64-bit zero, not r0.
d lhz: read; lhzu: read 16-bit signed displacement (d) added to the base address register.
RD lhz: write; lhzu: write; lhzux: write; lhzx: write Destination GPR.
RA lhzu: read; lhzu: write; lhzux: read; lhzux: write Source GPR (r0–r31).
RB lhzux: read; lhzx: read Source GPR.

Register Effects

lhz

  • Reads (always): RA0, d
  • Reads (conditional): none
  • Writes (always): RD
  • Writes (conditional): none

lhzu

  • Reads (always): RA, d
  • Reads (conditional): none
  • Writes (always): RD, RA
  • Writes (conditional): none

lhzux

  • Reads (always): RA, RB
  • Reads (conditional): none
  • Writes (always): RD, RA
  • Writes (conditional): none

lhzx

  • Reads (always): RA0, RB
  • Reads (conditional): none
  • Writes (always): RD
  • Writes (conditional): none

Status-Register Effects

No condition-register or status-register effects.

Operation (pseudocode)

EA <- (RA|0) + EXTS(d)
RT <- ZEXT16_to_64(MEM(EA, 2))

C Translation Example

/* No hand-written C yet. Translate the Canary emitter snapshot   */
/* under Implementation References; its HIR maps directly:        */
/*   f.LoadGPR(n) / f.StoreGPR(n, v)  -> r[n] / r[n] = v          */
/*   f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n]        */
/*   f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters   */
/*     wrap them in f.ByteSwap for the big-endian guest value      */
/*   f.UpdateCR(n, v)  -> CR field n from v's LOW 32 BITS vs 0     */
/*   f.LoadCA / f.StoreCA -> xer.CA;  f.StoreSAT -> vscr.SAT       */
/*   i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands  */
/* The Register Effects and Status-Register Effects tables above  */
/* enumerate every side effect a faithful translation must emit.  */

Implementation References

lhz

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhz(PPCHIRBuilder& f, const InstrData& i) {
  // if RA = 0 then
  //   b <- 0
  // else
  //   b <- (RA)
  // EA <- b + EXTS(D)
  // RT <- i48.0 || MEM(EA, 2)
  Value* b;
  if (i.D.RA == 0) {
    b = f.LoadZeroInt64();
  } else {
    b = f.LoadGPR(i.D.RA);
  }

  Value* offset = f.LoadConstantInt64(XEEXTS16(i.D.DS));
  Value* rt =
      f.ZeroExtend(f.ByteSwap(f.LoadOffset(b, offset, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.D.RT, rt);
  return 0;
}

lhzu

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzu(PPCHIRBuilder& f, const InstrData& i) {
  // EA <- (RA) + EXTS(D)
  // RT <- i48.0 || MEM(EA, 2)
  // RA <- EA
  Value* ra = f.LoadGPR(i.D.RA);
  Value* offset = f.LoadConstantInt64(XEEXTS16(i.D.DS));
  Value* rt = f.ZeroExtend(f.ByteSwap(f.LoadOffset(ra, offset, INT16_TYPE)),
                           INT64_TYPE);
  f.StoreGPR(i.D.RT, rt);
  StoreEA(f, i.D.RA, f.Add(ra, offset));
  return 0;
}

lhzux

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzux(PPCHIRBuilder& f, const InstrData& i) {
  // EA <- (RA) + (RB)
  // RT <- i48.0 || MEM(EA, 2)
  // RA <- EA
  Value* ea = CalculateEA(f, i.X.RA, i.X.RB);
  Value* rt = f.ZeroExtend(f.ByteSwap(f.Load(ea, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.X.RT, rt);
  StoreEA(f, i.X.RA, ea);
  return 0;
}

lhzx

Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_lhzx(PPCHIRBuilder& f, const InstrData& i) {
  // if RA = 0 then
  //   b <- 0
  // else
  //   b <- (RA)
  // EA <- b + (RB)
  // RT <- i48.0 || MEM(EA, 2)
  Value* ea = CalculateEA_0(f, i.X.RA, i.X.RB);
  Value* rt = f.ZeroExtend(f.ByteSwap(f.Load(ea, INT16_TYPE)), INT64_TYPE);
  f.StoreGPR(i.X.RT, rt);
  return 0;
}

Special Cases & Edge Conditions

  • Big-endian read, zero-extension. Reads 2 bytes big-endian, treats them as an unsigned 16-bit integer, zero-extends to 64 bits. The high 48 bits of RT become zero. Compare with lha, which sign-extends.
  • RA0 (non-update forms). RA = 0 in lhz / lhzx selects literal zero for absolute-address access. Update forms lhzu / lhzux invoke RA = 0 and RA = RT as invalid forms.
  • Update-form ordering. Xenia computes EA, performs the load, then writes RA ← EA. If RA == RT (an invalid form per IBM), the load result is overwritten by EA immediately.
  • No alignment requirement. Xenon executes unaligned half-word loads without faulting. MEM(EA, 2) reads the two consecutive bytes at EA.
  • Common as Unicode codepoint loader. Xbox 360 system strings are UTF-16; lhz is the canonical load for a single 16-bit codepoint.
  • Use lhz rather than lbz × 2 + shift. One fused instruction is faster and lets the load-store unit handle alignment.
  • Indexed variant operand order. lhzx RT, RA, RB — RA is the base (with RA0 semantics), RB is the offset.

IBM Reference