The generator had not been able to run correctly since the manual moved into
`tools/ppc-manual/`: it computed the repository root as `HERE.parent.parent`,
which now names `tools/`, so the XML, Canary's emitters and xenia-rs all stopped
resolving — silently, because both scrapers skipped what they could not find.
Every page's references had been pointing at paths that exist nowhere.
What each source contributed, measured on the 350 pages before this change:
Operation (pseudocode) 251 pages: fixed boilerplate "derives from the xenia-rs
interpreter"; 99 carry real hand-written seeds
C translation 337 pages: the same kind of boilerplate
xenia-rs snapshot 336 pages: the interpreter arm, pasted in — the only
per-instruction semantics on unseeded pages
links xenia-rs opcode/decoder/interpreter + Canary emitter
Now:
* semantics come from **Xenia Canary**, the reference emulator, read through
`git show` at a pinned upstream commit (`origin/canary_experimental`,
f21ebd49e9). Not our checkout: it carries instrumentation and lacked
upstream's `mcrf` fix, so it would have published probes and a wrong `mcrf`.
Each page embeds the emitter (`InstrEmit_<mnem>`), and for the 128 pure
one-line delegations also the helper that holds the semantics.
* decode references point at `crates/sylpheed-ppc` — the decoder that
produces `sylpheed.db` — as in-repo relative links.
* the boilerplate now says what is true, and the C translation guide maps
Canary's actual HIR calls, checked against `ppc_hir_builder.h` (including
that `UpdateCR(n, v)` truncates to 32 bits).
* `rust_scraper.py` -> `decoder_scraper.py` (interpreter half dropped);
missing sources are now errors, not empty results.
Verified:
consistency checks 455 XML entries, 350 families, 598 index keys
hand-written tails 386/386 byte-identical after regeneration
xenia-rs in generated 0
pages with a snapshot 349/350 (was 336) — `dcbi` has no Canary emitter at all
in-repo decoder links 910/910 resolve to a line holding the identifier
emitter boundaries brace counter == column-0 `}` rule on 521/521;
preprocessor model unit-tested (#if 0/#else/#elif)
idempotency re-run: 0 pages updated, 0 working-tree changes
Hand-written notes (outside the generated regions) are not rewritten here:
* 110 links into `../../xenia-rs/...` were dead; they now point at the file in
the archived repository (git.mc02.dev/fabi/xenia-rs @ 8401d4d). Line anchors
were dropped because the notes predate that commit — 0 of 441 old line
ranges match it — and a precise-looking wrong anchor is worse than none. The
link text, which carries the author's line numbers, is unchanged.
* 140 prose claims about xenia-rs's behaviour remain. 23 are verified to hold
for Canary too (the 32-bit CR0 truncation, OE left unimplemented); the other
114 need checking one by one, and some invert — e.g. `divdx` notes a correct
64-bit CR0 update in xenia-rs where Canary's `UpdateCR` truncates. Left for
a deliberate pass rather than a blind substitution.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
7.7 KiB
bcctrx — Branch Conditional to Count Register
Category: Branch & System · Form: XL · Opcode:
0x4c000420· sync
Assembler Mnemonics
| Mnemonic | XML entry | Flags | Description |
|---|---|---|---|
bcctr |
bcctrx |
— | Branch Conditional to Count Register |
bcctrl |
bcctrx |
LK=1 | Branch Conditional to Count Register |
Syntax
bcctr[LK] [BO], [BI]
Encoding
bcctrx — form XL
- Opcode word:
0x4c000420 - Primary opcode (bits 0–5):
19 - Extended opcode:
528 - Synchronising: yes
| Bits | Field | Meaning |
|---|---|---|
| 0–5 | OPCD |
primary opcode (19) |
| 6–10 | BT/BO |
target / branch options |
| 11–15 | BA/BI |
source A / CR bit to test |
| 16–20 | BB |
source B |
| 21–30 | XO |
extended opcode (10 bits) |
| 31 | LK |
link flag |
Operands
| Field | Role | Description |
|---|---|---|
LK |
bcctrx: read | Link bit. When 1, LR ← address-of-next-instruction before the branch is taken. |
BO |
bcctrx: read | 5-bit branch options — selects CTR decrement, CTR test polarity, and CR bit test polarity. See forms/XL.md. |
BI |
bcctrx: read | CR bit index (0–31) selected by BO's condition test. |
CR |
bcctrx: read | Condition-register update. When Rc=1, CR field 0 (or CR6 for vector compares, CR1 for FPU) is updated from the result. |
CTR |
bcctrx: read | Count register. Decremented and optionally tested by conditional branches when BO[2]=0. |
LR |
bcctrx: write (conditional) | Link register. Written by bl/bla/bcl/bclrl/bcctrl; read by bclr/bclrl. |
Register Effects
bcctrx
- Reads (always):
LK,BO,BI,CR,CTR - Reads (conditional): none
- Writes (always): none
- Writes (conditional):
LR
Status-Register Effects
No condition-register or status-register effects.
Operation (pseudocode)
cond_ok <- BO[0] | (CR[BI] ≡ BO[1])
if cond_ok then NIA <- CTR[0:61] || 0b00
if LK then LR <- CIA + 4
C Translation Example
/* No hand-written C yet. Translate the Canary emitter snapshot */
/* under Implementation References; its HIR maps directly: */
/* f.LoadGPR(n) / f.StoreGPR(n, v) -> r[n] / r[n] = v */
/* f.LoadFPR / StoreFPR, f.LoadVR / StoreVR -> f[n], v[n] */
/* f.Load(ea, T), f.Store(ea, v) -> raw read / write; emitters */
/* wrap them in f.ByteSwap for the big-endian guest value */
/* f.UpdateCR(n, v) -> CR field n from v's LOW 32 BITS vs 0 */
/* f.LoadCA / f.StoreCA -> xer.CA; f.StoreSAT -> vscr.SAT */
/* i.XO.RA, i.D.DS, ... -> the bit-fields listed under Operands */
/* The Register Effects and Status-Register Effects tables above */
/* enumerate every side effect a faithful translation must emit. */
Implementation References
bcctrx
- Canary XML:
tools/ppc-instructions.xml— search formnem="bcctrx" - Canary emitter:
src/xenia/cpu/ppc/ppc_emit_control.cc:250 - Sylpheed opcode:
crates/sylpheed-ppc/src/opcode.rs:22 - Sylpheed decoder:
crates/sylpheed-ppc/src/decoder.rs:836
Canary emitter (frozen snapshot @ f21ebd49e9)
int InstrEmit_bcctrx(PPCHIRBuilder& f, const InstrData& i) {
// cond_ok <- BO[0] | (CR[BI+32] ≡ BO[1])
// if cond_ok then
// NIA <- CTR[0:61] || 0b00
// if LK then
// LR <- CIA + 4
// NOTE: the condition bits are reversed!
// 01234 (docs)
// 43210 (real)
Value* cond_ok = NULL;
bool not_cond_ok = false;
if (select_bits(i.XL.BO, 4, 4)) {
// Ignore cond.
} else {
Value* cr = f.LoadCRField(i.XL.BI >> 2, i.XL.BI & 3);
cond_ok = cr;
if (select_bits(i.XL.BO, 3, 3)) {
// Expect true.
not_cond_ok = false;
} else {
// Expect false.
not_cond_ok = true;
}
}
bool expect_true = !not_cond_ok;
return InstrEmit_branch(f, "bcctrx", i.address, f.LoadCTR(), i.XL.LK, cond_ok,
expect_true);
}
Special Cases & Edge Conditions
-
No CTR decrement. Unlike
bcxandbclrx,bcctrcannot decrement CTR (the CTR is the target). The PowerISA reservesBO[2] = 0encodings — they are invalid onbcctrx. xenia silently ignoresBO[2]/BO[3]and treats everybcctras a pure CR-conditional branch, which matches both the canary emit and real Xenon hardware behaviour. -
CTR alignment mask. The target is
CTR & ~3. Likebclr, the low two bits are stripped — a misaligned CTR is silently rounded down rather than trapping. -
BO encoding (CR-only subset). Because CTR-test bits are unused, only four
BOpatterns are meaningful:BO (binary) Meaning 0100zbranch if CR[BI]false0101zbranch if CR[BI]true1z1zzbranch always ( bctr)0000z/001at/etc.reserved — implementation-defined -
Indirect call/dispatch idiom.
mtctr rN; bctrlis the canonical PPC indirect call: load function pointer into CTR, call. The xenia interpreter writesLR ← CIA + 4only when the branch is taken — this matches the PowerISA, but contrast withbcxwhereLKalways writes LR (even if the branch is not taken). The C-translation reference handles this asymmetry explicitly. -
bctrfor switch tables. Compilers emitbctr(notbctrl) for jump-table dispatch, with CTR loaded from a base + (index*4) lookup. Xenia honours this by simply jumping toCTR & ~3. -
Synchronisation. Marked
syncin xenia's XML — context-synchronising. JIT backends must ensure prior side effects have committed before the indirect transfer. -
No prediction hint sensitivity. Xenon predicts indirect branches via a separate target cache; the
BO[4]hint is mostly cosmetic forbcctr.
Related Instructions
bclrx— branch conditional to LR (function returns).bcx— branch conditional to displacement (B-form).bx— unconditional displacement branch (I-form).mtctr,mfctr— load/read CTR viamtspr 9/mfspr 9.sc— alternative control-flow exit (system call).
Simplified Mnemonics
| Simplified | Expansion |
|---|---|
bctr |
bcctr BO=0b10100, BI=0 — unconditional indirect branch |
bctrl |
bcctrl BO=0b10100, BI=0 — unconditional indirect call |
beqctr crN |
bcctr BO=0b01100, BI=4·N+2 — call CTR if crN.EQ |
bnectr crN |
bcctr BO=0b00100, BI=4·N+2 — call CTR if crN.NE |
bltctr crN |
bcctr BO=0b01100, BI=4·N+0 — call CTR if crN.LT |
bgectr crN |
bcctr BO=0b00100, BI=4·N+0 — call CTR if crN.GE |
bgtctr crN |
bcctr BO=0b01100, BI=4·N+1 — call CTR if crN.GT |
blectr crN |
bcctr BO=0b00100, BI=4·N+1 — call CTR if crN.LE |
The unconditional bctr/bctrl are by far the most common in Xbox 360 disassembly (compiler-emitted indirect calls and switch dispatch).