Second coverage batch, data-driven from the histogram. Diff harness validates every op against the interpreter (MISMATCHES=0 over 47.96M blocks). Update-form load/stores (24 ops: lbzu..stdux, lfsu..stfdux and their x-forms): same access as the base form but with EA = gpr[ra] + offset (ra used directly — update forms are illegal with ra==0) and rA := EA written back (zero-extended) after the access. New ea_d_update/ea_x_update/write_ea_back helpers; loads write rD then rA (so rA wins if rd==ra, matching the interpreter). stwu especially is the standard stack-frame push in every function prologue. mfspr/mtspr for LR and CTR only (64-bit field copies): the ubiquitous mflr/mtlr prologue-epilogue pair and mtctr. covered() gates on the compile-time SPR number so the offset always resolves; XER (packs CA/OV/SO) and the modelled SPRs stay uncovered. This is the biggest single jump — mflr/mtlr gate almost every non-leaf function's prologue and epilogue blocks. Coverage (single-block, diff mode): 80.6% -> 82.8% (update forms) -> 89.6% (mfspr/mtspr). 7/7 jit unit tests; foreground-validated per the bg-SIGTERM finding. Carry-setting shifts (sraw*/srad*), rotate-double (rldic*), and XER mfspr/mtspr remain for later batches; VMX128 is the long pole. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>