Phase 6 batch 3 — SPR/MSR/VSCR semantics. - PPCBUG-078 mtmsrd L=1: PowerISA requires partial-MSR-write — only MSR[EE] (u64 bit 15) and MSR[RI] (u64 bit 0) modified, all other MSR bits preserved. Used by kernel code to toggle external interrupts. Previously merged with mtmsr (full overwrite), silently corrupting MSR for any L=1 caller. - PPCBUG-080 mfvscr: ISA places VSCR in the rightmost word of VD with bytes 0-11 zeroed. Previously copied the full 128-bit ctx.vscr, leaking stale upper data to guest. Now zero-extends per canary. - PPCBUG-068 mcrfs VX summary: when mcrfs clears VX* exception bits, the VX summary bit at FPSCR[2] must be recomputed (clears if all contributors are 0; remains 1 otherwise). Previously left stale, causing subsequent CR-test sequences to misread the FPU state. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>