mem_helper.c 27.9 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
/*
 *  S/390 memory access helper routines
 *
 *  Copyright (c) 2009 Ulrich Hecht
 *  Copyright (c) 2009 Alexander Graf
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
 */

#include "cpu.h"
#include "helper.h"

/*****************************************************************************/
/* Softmmu support */
#if !defined(CONFIG_USER_ONLY)
27
#include "exec/softmmu_exec.h"
28 29 30 31

#define MMUSUFFIX _mmu

#define SHIFT 0
32
#include "exec/softmmu_template.h"
33 34

#define SHIFT 1
35
#include "exec/softmmu_template.h"
36 37

#define SHIFT 2
38
#include "exec/softmmu_template.h"
39 40

#define SHIFT 3
41
#include "exec/softmmu_template.h"
42 43 44 45 46

/* try to fill the TLB and return an exception if error. If retaddr is
   NULL, it means that the function was called in C code (i.e. not
   from generated code or from helper.c) */
/* XXX: fix it to restore all registers */
47
void tlb_fill(CPUState *cs, target_ulong addr, int is_write, int mmu_idx,
48 49 50 51
              uintptr_t retaddr)
{
    int ret;

52
    ret = s390_cpu_handle_mmu_fault(cs, addr, is_write, mmu_idx);
53 54 55
    if (unlikely(ret != 0)) {
        if (likely(retaddr)) {
            /* now we have a real cpu fault */
56
            cpu_restore_state(cs, retaddr);
57
        }
58
        cpu_loop_exit(cs);
59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74
    }
}

#endif

/* #define DEBUG_HELPER */
#ifdef DEBUG_HELPER
#define HELPER_LOG(x...) qemu_log(x)
#else
#define HELPER_LOG(x...)
#endif

#ifndef CONFIG_USER_ONLY
static void mvc_fast_memset(CPUS390XState *env, uint32_t l, uint64_t dest,
                            uint8_t byte)
{
75
    S390CPU *cpu = s390_env_get_cpu(env);
A
Avi Kivity 已提交
76 77
    hwaddr dest_phys;
    hwaddr len = l;
78 79 80 81 82
    void *dest_p;
    uint64_t asc = env->psw.mask & PSW_MASK_ASC;
    int flags;

    if (mmu_translate(env, dest, 1, asc, &dest_phys, &flags)) {
83
        cpu_stb_data(env, dest, byte);
84
        cpu_abort(CPU(cpu), "should never reach here");
85 86 87 88 89 90 91 92 93 94 95 96 97
    }
    dest_phys |= dest & ~TARGET_PAGE_MASK;

    dest_p = cpu_physical_memory_map(dest_phys, &len, 1);

    memset(dest_p, byte, len);

    cpu_physical_memory_unmap(dest_p, 1, len, len);
}

static void mvc_fast_memmove(CPUS390XState *env, uint32_t l, uint64_t dest,
                             uint64_t src)
{
98
    S390CPU *cpu = s390_env_get_cpu(env);
A
Avi Kivity 已提交
99 100 101
    hwaddr dest_phys;
    hwaddr src_phys;
    hwaddr len = l;
102 103 104 105 106 107
    void *dest_p;
    void *src_p;
    uint64_t asc = env->psw.mask & PSW_MASK_ASC;
    int flags;

    if (mmu_translate(env, dest, 1, asc, &dest_phys, &flags)) {
108
        cpu_stb_data(env, dest, 0);
109
        cpu_abort(CPU(cpu), "should never reach here");
110 111 112 113
    }
    dest_phys |= dest & ~TARGET_PAGE_MASK;

    if (mmu_translate(env, src, 0, asc, &src_phys, &flags)) {
114
        cpu_ldub_data(env, src);
115
        cpu_abort(CPU(cpu), "should never reach here");
116 117 118 119 120 121 122 123 124 125 126 127 128 129
    }
    src_phys |= src & ~TARGET_PAGE_MASK;

    dest_p = cpu_physical_memory_map(dest_phys, &len, 1);
    src_p = cpu_physical_memory_map(src_phys, &len, 0);

    memmove(dest_p, src_p, len);

    cpu_physical_memory_unmap(dest_p, 1, len, len);
    cpu_physical_memory_unmap(src_p, 0, len, len);
}
#endif

/* and on array */
130 131
uint32_t HELPER(nc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
132 133 134 135 136 137 138 139
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);
    for (i = 0; i <= l; i++) {
140
        x = cpu_ldub_data(env, dest + i) & cpu_ldub_data(env, src + i);
141 142 143
        if (x) {
            cc = 1;
        }
144
        cpu_stb_data(env, dest + i, x);
145 146 147 148 149
    }
    return cc;
}

/* xor on array */
150 151
uint32_t HELPER(xc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);

#ifndef CONFIG_USER_ONLY
    /* xor with itself is the same as memset(0) */
    if ((l > 32) && (src == dest) &&
        (src & TARGET_PAGE_MASK) == ((src + l) & TARGET_PAGE_MASK)) {
        mvc_fast_memset(env, l + 1, dest, 0);
        return 0;
    }
#else
    if (src == dest) {
        memset(g2h(dest), 0, l + 1);
        return 0;
    }
#endif

    for (i = 0; i <= l; i++) {
175
        x = cpu_ldub_data(env, dest + i) ^ cpu_ldub_data(env, src + i);
176 177 178
        if (x) {
            cc = 1;
        }
179
        cpu_stb_data(env, dest + i, x);
180 181 182 183 184
    }
    return cc;
}

/* or on array */
185 186
uint32_t HELPER(oc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
187 188 189 190 191 192 193 194
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);
    for (i = 0; i <= l; i++) {
195
        x = cpu_ldub_data(env, dest + i) | cpu_ldub_data(env, src + i);
196 197 198
        if (x) {
            cc = 1;
        }
199
        cpu_stb_data(env, dest + i, x);
200 201 202 203 204
    }
    return cc;
}

/* memmove */
205
void HELPER(mvc)(CPUS390XState *env, uint32_t l, uint64_t dest, uint64_t src)
206 207 208 209 210 211 212 213 214 215 216 217 218
{
    int i = 0;
    int x = 0;
    uint32_t l_64 = (l + 1) / 8;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);

#ifndef CONFIG_USER_ONLY
    if ((l > 32) &&
        (src & TARGET_PAGE_MASK) == ((src + l) & TARGET_PAGE_MASK) &&
        (dest & TARGET_PAGE_MASK) == ((dest + l) & TARGET_PAGE_MASK)) {
        if (dest == (src + 1)) {
219
            mvc_fast_memset(env, l + 1, dest, cpu_ldub_data(env, src));
220 221 222 223 224 225 226 227
            return;
        } else if ((src & TARGET_PAGE_MASK) != (dest & TARGET_PAGE_MASK)) {
            mvc_fast_memmove(env, l + 1, dest, src);
            return;
        }
    }
#else
    if (dest == (src + 1)) {
228
        memset(g2h(dest), cpu_ldub_data(env, src), l + 1);
229 230 231 232 233 234 235 236 237 238
        return;
    } else {
        memmove(g2h(dest), g2h(src), l + 1);
        return;
    }
#endif

    /* handle the parts that fit into 8-byte loads/stores */
    if (dest != (src + 1)) {
        for (i = 0; i < l_64; i++) {
239
            cpu_stq_data(env, dest + x, cpu_ldq_data(env, src + x));
240 241 242 243 244 245
            x += 8;
        }
    }

    /* slow version crossing pages with byte accesses */
    for (i = x; i <= l; i++) {
246
        cpu_stb_data(env, dest + i, cpu_ldub_data(env, src + i));
247 248 249 250
    }
}

/* compare unsigned byte arrays */
251
uint32_t HELPER(clc)(CPUS390XState *env, uint32_t l, uint64_t s1, uint64_t s2)
252 253 254 255 256 257 258 259
{
    int i;
    unsigned char x, y;
    uint32_t cc;

    HELPER_LOG("%s l %d s1 %" PRIx64 " s2 %" PRIx64 "\n",
               __func__, l, s1, s2);
    for (i = 0; i <= l; i++) {
260 261
        x = cpu_ldub_data(env, s1 + i);
        y = cpu_ldub_data(env, s2 + i);
262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277
        HELPER_LOG("%02x (%c)/%02x (%c) ", x, x, y, y);
        if (x < y) {
            cc = 1;
            goto done;
        } else if (x > y) {
            cc = 2;
            goto done;
        }
    }
    cc = 0;
 done:
    HELPER_LOG("\n");
    return cc;
}

/* compare logical under mask */
278 279
uint32_t HELPER(clm)(CPUS390XState *env, uint32_t r1, uint32_t mask,
                     uint64_t addr)
280 281 282 283 284 285 286 287 288
{
    uint8_t r, d;
    uint32_t cc;

    HELPER_LOG("%s: r1 0x%x mask 0x%x addr 0x%" PRIx64 "\n", __func__, r1,
               mask, addr);
    cc = 0;
    while (mask) {
        if (mask & 8) {
289
            d = cpu_ldub_data(env, addr);
290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308
            r = (r1 & 0xff000000UL) >> 24;
            HELPER_LOG("mask 0x%x %02x/%02x (0x%" PRIx64 ") ", mask, r, d,
                       addr);
            if (r < d) {
                cc = 1;
                break;
            } else if (r > d) {
                cc = 2;
                break;
            }
            addr++;
        }
        mask = (mask << 1) & 0xf;
        r1 <<= 8;
    }
    HELPER_LOG("\n");
    return cc;
}

309 310 311 312 313 314 315 316 317
static inline uint64_t fix_address(CPUS390XState *env, uint64_t a)
{
    /* 31-Bit mode */
    if (!(env->psw.mask & PSW_MASK_64)) {
        a &= 0x7fffffff;
    }
    return a;
}

318
static inline uint64_t get_address(CPUS390XState *env, int x2, int b2, int d2)
319 320 321 322 323 324 325 326
{
    uint64_t r = d2;
    if (x2) {
        r += env->regs[x2];
    }
    if (b2) {
        r += env->regs[b2];
    }
327
    return fix_address(env, r);
328 329
}

330
static inline uint64_t get_address_31fix(CPUS390XState *env, int reg)
331
{
332
    return fix_address(env, env->regs[reg]);
333 334 335
}

/* search string (c is byte to search, r2 is string, r1 end of string) */
R
Richard Henderson 已提交
336 337
uint64_t HELPER(srst)(CPUS390XState *env, uint64_t r0, uint64_t end,
                      uint64_t str)
338
{
R
Richard Henderson 已提交
339 340
    uint32_t len;
    uint8_t v, c = r0;
341

R
Richard Henderson 已提交
342 343
    str = fix_address(env, str);
    end = fix_address(env, end);
344

R
Richard Henderson 已提交
345 346 347 348
    /* Assume for now that R2 is unmodified.  */
    env->retxl = str;

    /* Lest we fail to service interrupts in a timely manner, limit the
349
       amount of work we're willing to do.  For now, let's cap at 8k.  */
R
Richard Henderson 已提交
350 351 352 353 354 355 356 357 358 359 360
    for (len = 0; len < 0x2000; ++len) {
        if (str + len == end) {
            /* Character not found.  R1 & R2 are unmodified.  */
            env->cc_op = 2;
            return end;
        }
        v = cpu_ldub_data(env, str + len);
        if (v == c) {
            /* Character found.  Set R1 to the location; R2 is unmodified.  */
            env->cc_op = 1;
            return str + len;
361 362 363
        }
    }

R
Richard Henderson 已提交
364 365 366 367
    /* CPU-determined bytes processed.  Advance R2 to next byte to process.  */
    env->retxl = str + len;
    env->cc_op = 3;
    return end;
368 369 370
}

/* unsigned string compare (c is string terminator) */
371
uint64_t HELPER(clst)(CPUS390XState *env, uint64_t c, uint64_t s1, uint64_t s2)
372
{
373
    uint32_t len;
374 375

    c = c & 0xff;
376 377 378 379
    s1 = fix_address(env, s1);
    s2 = fix_address(env, s2);

    /* Lest we fail to service interrupts in a timely manner, limit the
380
       amount of work we're willing to do.  For now, let's cap at 8k.  */
381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397
    for (len = 0; len < 0x2000; ++len) {
        uint8_t v1 = cpu_ldub_data(env, s1 + len);
        uint8_t v2 = cpu_ldub_data(env, s2 + len);
        if (v1 == v2) {
            if (v1 == c) {
                /* Equal.  CC=0, and don't advance the registers.  */
                env->cc_op = 0;
                env->retxl = s2;
                return s1;
            }
        } else {
            /* Unequal.  CC={1,2}, and advance the registers.  Note that
               the terminator need not be zero, but the string that contains
               the terminator is by definition "low".  */
            env->cc_op = (v1 == c ? 1 : v2 == c ? 2 : v1 < v2 ? 1 : 2);
            env->retxl = s2 + len;
            return s1 + len;
398 399 400
        }
    }

401 402 403 404
    /* CPU-determined bytes equal; advance the registers.  */
    env->cc_op = 3;
    env->retxl = s2 + len;
    return s1 + len;
405 406 407
}

/* move page */
408
void HELPER(mvpg)(CPUS390XState *env, uint64_t r0, uint64_t r1, uint64_t r2)
409 410
{
    /* XXX missing r0 handling */
R
Richard Henderson 已提交
411
    env->cc_op = 0;
412
#ifdef CONFIG_USER_ONLY
R
Richard Henderson 已提交
413
    memmove(g2h(r1), g2h(r2), TARGET_PAGE_SIZE);
414 415 416 417 418 419
#else
    mvc_fast_memmove(env, TARGET_PAGE_SIZE, r1, r2);
#endif
}

/* string copy (c is string terminator) */
420
uint64_t HELPER(mvst)(CPUS390XState *env, uint64_t c, uint64_t d, uint64_t s)
421
{
422
    uint32_t len;
423 424

    c = c & 0xff;
425 426 427 428
    d = fix_address(env, d);
    s = fix_address(env, s);

    /* Lest we fail to service interrupts in a timely manner, limit the
429
       amount of work we're willing to do.  For now, let's cap at 8k.  */
430 431 432
    for (len = 0; len < 0x2000; ++len) {
        uint8_t v = cpu_ldub_data(env, s + len);
        cpu_stb_data(env, d + len, v);
433
        if (v == c) {
434 435 436 437
            /* Complete.  Set CC=1 and advance R1.  */
            env->cc_op = 1;
            env->retxl = s;
            return d + len;
438 439
        }
    }
440 441 442 443 444

    /* Incomplete.  Set CC=3 and signal to advance R1 and R2.  */
    env->cc_op = 3;
    env->retxl = s + len;
    return d + len;
445 446
}

447 448
static uint32_t helper_icm(CPUS390XState *env, uint32_t r1, uint64_t address,
                           uint32_t mask)
449 450 451 452 453 454 455 456 457 458
{
    int pos = 24; /* top of the lower half of r1 */
    uint64_t rmask = 0xff000000ULL;
    uint8_t val = 0;
    int ccd = 0;
    uint32_t cc = 0;

    while (mask) {
        if (mask & 8) {
            env->regs[r1] &= ~rmask;
459
            val = cpu_ldub_data(env, address);
460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484
            if ((val & 0x80) && !ccd) {
                cc = 1;
            }
            ccd = 1;
            if (val && cc == 0) {
                cc = 2;
            }
            env->regs[r1] |= (uint64_t)val << pos;
            address++;
        }
        mask = (mask << 1) & 0xf;
        pos -= 8;
        rmask >>= 8;
    }

    return cc;
}

/* execute instruction
   this instruction executes an insn modified with the contents of r1
   it does not change the executed instruction in memory
   it does not change the program counter
   in other words: tricky...
   currently implemented by interpreting the cases it is most commonly used in
*/
485 486
uint32_t HELPER(ex)(CPUS390XState *env, uint32_t cc, uint64_t v1,
                    uint64_t addr, uint64_t ret)
487
{
488
    S390CPU *cpu = s390_env_get_cpu(env);
489
    uint16_t insn = cpu_lduw_code(env, addr);
490 491 492 493 494 495 496

    HELPER_LOG("%s: v1 0x%lx addr 0x%lx insn 0x%x\n", __func__, v1, addr,
               insn);
    if ((insn & 0xf0ff) == 0xd000) {
        uint32_t l, insn2, b1, b2, d1, d2;

        l = v1 & 0xff;
497
        insn2 = cpu_ldl_code(env, addr + 2);
498 499 500 501 502 503
        b1 = (insn2 >> 28) & 0xf;
        b2 = (insn2 >> 12) & 0xf;
        d1 = (insn2 >> 16) & 0xfff;
        d2 = insn2 & 0xfff;
        switch (insn & 0xf00) {
        case 0x200:
504 505
            helper_mvc(env, l, get_address(env, 0, b1, d1),
                       get_address(env, 0, b2, d2));
506 507
            break;
        case 0x500:
508 509
            cc = helper_clc(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
510 511
            break;
        case 0x700:
512 513
            cc = helper_xc(env, l, get_address(env, 0, b1, d1),
                           get_address(env, 0, b2, d2));
514 515
            break;
        case 0xc00:
516 517
            helper_tr(env, l, get_address(env, 0, b1, d1),
                      get_address(env, 0, b2, d2));
518 519 520 521 522 523 524 525 526
            break;
        default:
            goto abort;
        }
    } else if ((insn & 0xff00) == 0x0a00) {
        /* supervisor call */
        HELPER_LOG("%s: svc %ld via execute\n", __func__, (insn | v1) & 0xff);
        env->psw.addr = ret - 4;
        env->int_svc_code = (insn | v1) & 0xff;
527
        env->int_svc_ilen = 4;
528
        helper_exception(env, EXCP_SVC);
529 530 531
    } else if ((insn & 0xff00) == 0xbf00) {
        uint32_t insn2, r1, r3, b2, d2;

532
        insn2 = cpu_ldl_code(env, addr + 2);
533 534 535 536
        r1 = (insn2 >> 20) & 0xf;
        r3 = (insn2 >> 16) & 0xf;
        b2 = (insn2 >> 12) & 0xf;
        d2 = insn2 & 0xfff;
537
        cc = helper_icm(env, r1, get_address(env, 0, b2, d2), r3);
538 539
    } else {
    abort:
540
        cpu_abort(CPU(cpu), "EXECUTE on instruction prefix 0x%x not implemented\n",
541 542 543 544 545 546
                  insn);
    }
    return cc;
}

/* load access registers r1 to r3 from memory at a2 */
547
void HELPER(lam)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
548 549 550 551
{
    int i;

    for (i = r1;; i = (i + 1) % 16) {
552
        env->aregs[i] = cpu_ldl_data(env, a2);
553 554 555 556 557 558 559 560 561
        a2 += 4;

        if (i == r3) {
            break;
        }
    }
}

/* store access registers r1 to r3 in memory at a2 */
562
void HELPER(stam)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
563 564 565 566
{
    int i;

    for (i = r1;; i = (i + 1) % 16) {
567
        cpu_stl_data(env, a2, env->aregs[i]);
568 569 570 571 572 573 574 575 576
        a2 += 4;

        if (i == r3) {
            break;
        }
    }
}

/* move long */
577
uint32_t HELPER(mvcl)(CPUS390XState *env, uint32_t r1, uint32_t r2)
578 579
{
    uint64_t destlen = env->regs[r1 + 1] & 0xffffff;
580
    uint64_t dest = get_address_31fix(env, r1);
581
    uint64_t srclen = env->regs[r2 + 1] & 0xffffff;
582
    uint64_t src = get_address_31fix(env, r2);
583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599
    uint8_t pad = src >> 24;
    uint8_t v;
    uint32_t cc;

    if (destlen == srclen) {
        cc = 0;
    } else if (destlen < srclen) {
        cc = 1;
    } else {
        cc = 2;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen && srclen; src++, dest++, destlen--, srclen--) {
600 601
        v = cpu_ldub_data(env, src);
        cpu_stb_data(env, dest, v);
602 603 604
    }

    for (; destlen; dest++, destlen--) {
605
        cpu_stb_data(env, dest, pad);
606 607 608 609 610 611 612 613 614 615 616 617
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    env->regs[r2 + 1] -= src - env->regs[r2];
    env->regs[r1] = dest;
    env->regs[r2] = src;

    return cc;
}

/* move long extended another memcopy insn with more bells and whistles */
618 619
uint32_t HELPER(mvcle)(CPUS390XState *env, uint32_t r1, uint64_t a2,
                       uint32_t r3)
620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648
{
    uint64_t destlen = env->regs[r1 + 1];
    uint64_t dest = env->regs[r1];
    uint64_t srclen = env->regs[r3 + 1];
    uint64_t src = env->regs[r3];
    uint8_t pad = a2 & 0xff;
    uint8_t v;
    uint32_t cc;

    if (!(env->psw.mask & PSW_MASK_64)) {
        destlen = (uint32_t)destlen;
        srclen = (uint32_t)srclen;
        dest &= 0x7fffffff;
        src &= 0x7fffffff;
    }

    if (destlen == srclen) {
        cc = 0;
    } else if (destlen < srclen) {
        cc = 1;
    } else {
        cc = 2;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen && srclen; src++, dest++, destlen--, srclen--) {
649 650
        v = cpu_ldub_data(env, src);
        cpu_stb_data(env, dest, v);
651 652 653
    }

    for (; destlen; dest++, destlen--) {
654
        cpu_stb_data(env, dest, pad);
655 656 657 658 659 660 661 662 663 664 665 666 667
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    /* FIXME: 31-bit mode! */
    env->regs[r3 + 1] -= src - env->regs[r3];
    env->regs[r1] = dest;
    env->regs[r3] = src;

    return cc;
}

/* compare logical long extended memcompare insn with padding */
668 669
uint32_t HELPER(clcle)(CPUS390XState *env, uint32_t r1, uint64_t a2,
                       uint32_t r3)
670 671
{
    uint64_t destlen = env->regs[r1 + 1];
672
    uint64_t dest = get_address_31fix(env, r1);
673
    uint64_t srclen = env->regs[r3 + 1];
674
    uint64_t src = get_address_31fix(env, r3);
675 676 677 678 679 680 681 682 683 684 685 686 687
    uint8_t pad = a2 & 0xff;
    uint8_t v1 = 0, v2 = 0;
    uint32_t cc = 0;

    if (!(destlen || srclen)) {
        return cc;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen || srclen; src++, dest++, destlen--, srclen--) {
688 689
        v1 = srclen ? cpu_ldub_data(env, src) : pad;
        v2 = destlen ? cpu_ldub_data(env, dest) : pad;
690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705
        if (v1 != v2) {
            cc = (v1 < v2) ? 1 : 2;
            break;
        }
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    env->regs[r3 + 1] -= src - env->regs[r3];
    env->regs[r1] = dest;
    env->regs[r3] = src;

    return cc;
}

/* checksum */
R
Richard Henderson 已提交
706 707
uint64_t HELPER(cksm)(CPUS390XState *env, uint64_t r1,
                      uint64_t src, uint64_t src_len)
708
{
R
Richard Henderson 已提交
709 710
    uint64_t max_len, len;
    uint64_t cksm = (uint32_t)r1;
711

R
Richard Henderson 已提交
712
    /* Lest we fail to service interrupts in a timely manner, limit the
713
       amount of work we're willing to do.  For now, let's cap at 8k.  */
R
Richard Henderson 已提交
714
    max_len = (src_len > 0x2000 ? 0x2000 : src_len);
715

R
Richard Henderson 已提交
716 717 718
    /* Process full words as available.  */
    for (len = 0; len + 4 <= max_len; len += 4, src += 4) {
        cksm += (uint32_t)cpu_ldl_data(env, src);
719 720
    }

R
Richard Henderson 已提交
721
    switch (max_len - len) {
722
    case 1:
723
        cksm += cpu_ldub_data(env, src) << 24;
R
Richard Henderson 已提交
724
        len += 1;
725 726
        break;
    case 2:
727
        cksm += cpu_lduw_data(env, src) << 16;
R
Richard Henderson 已提交
728
        len += 2;
729 730
        break;
    case 3:
731 732
        cksm += cpu_lduw_data(env, src) << 16;
        cksm += cpu_ldub_data(env, src + 2) << 8;
R
Richard Henderson 已提交
733
        len += 3;
734 735 736
        break;
    }

R
Richard Henderson 已提交
737 738 739 740 741 742 743 744
    /* Fold the carry from the checksum.  Note that we can see carry-out
       during folding more than once (but probably not more than twice).  */
    while (cksm > 0xffffffffull) {
        cksm = (uint32_t)cksm + (cksm >> 32);
    }

    /* Indicate whether or not we've processed everything.  */
    env->cc_op = (len == src_len ? 0 : 3);
745

R
Richard Henderson 已提交
746 747 748
    /* Return both cksm and processed length.  */
    env->retxl = cksm;
    return len;
749 750
}

751 752
void HELPER(unpk)(CPUS390XState *env, uint32_t len, uint64_t dest,
                  uint64_t src)
753 754 755 756 757 758 759 760 761 762
{
    int len_dest = len >> 4;
    int len_src = len & 0xf;
    uint8_t b;
    int second_nibble = 0;

    dest += len_dest;
    src += len_src;

    /* last byte is special, it only flips the nibbles */
763 764
    b = cpu_ldub_data(env, src);
    cpu_stb_data(env, dest, (b << 4) | (b >> 4));
765 766 767 768 769 770 771 772 773
    src--;
    len_src--;

    /* now pad every nibble with 0xf0 */

    while (len_dest > 0) {
        uint8_t cur_byte = 0;

        if (len_src > 0) {
774
            cur_byte = cpu_ldub_data(env, src);
775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792
        }

        len_dest--;
        dest--;

        /* only advance one nibble at a time */
        if (second_nibble) {
            cur_byte >>= 4;
            len_src--;
            src--;
        }
        second_nibble = !second_nibble;

        /* digit */
        cur_byte = (cur_byte & 0xf);
        /* zone bits */
        cur_byte |= 0xf0;

793
        cpu_stb_data(env, dest, cur_byte);
794 795 796
    }
}

797 798
void HELPER(tr)(CPUS390XState *env, uint32_t len, uint64_t array,
                uint64_t trans)
799 800 801 802
{
    int i;

    for (i = 0; i <= len; i++) {
803 804
        uint8_t byte = cpu_ldub_data(env, array + i);
        uint8_t new_byte = cpu_ldub_data(env, trans + byte);
805

806
        cpu_stb_data(env, array + i, new_byte);
807 808 809 810
    }
}

#if !defined(CONFIG_USER_ONLY)
811
void HELPER(lctlg)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
812 813 814 815 816
{
    int i;
    uint64_t src = a2;

    for (i = r1;; i = (i + 1) % 16) {
817
        env->cregs[i] = cpu_ldq_data(env, src);
818 819 820 821 822 823 824 825 826 827 828 829
        HELPER_LOG("load ctl %d from 0x%" PRIx64 " == 0x%" PRIx64 "\n",
                   i, src, env->cregs[i]);
        src += sizeof(uint64_t);

        if (i == r3) {
            break;
        }
    }

    tlb_flush(env, 1);
}

830
void HELPER(lctl)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
831 832 833 834 835
{
    int i;
    uint64_t src = a2;

    for (i = r1;; i = (i + 1) % 16) {
836 837
        env->cregs[i] = (env->cregs[i] & 0xFFFFFFFF00000000ULL) |
            cpu_ldl_data(env, src);
838 839 840 841 842 843 844 845 846 847
        src += sizeof(uint32_t);

        if (i == r3) {
            break;
        }
    }

    tlb_flush(env, 1);
}

848
void HELPER(stctg)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
849 850 851 852 853
{
    int i;
    uint64_t dest = a2;

    for (i = r1;; i = (i + 1) % 16) {
854
        cpu_stq_data(env, dest, env->cregs[i]);
855 856 857 858 859 860 861 862
        dest += sizeof(uint64_t);

        if (i == r3) {
            break;
        }
    }
}

863
void HELPER(stctl)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
864 865 866 867 868
{
    int i;
    uint64_t dest = a2;

    for (i = r1;; i = (i + 1) % 16) {
869
        cpu_stl_data(env, dest, env->cregs[i]);
870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885
        dest += sizeof(uint32_t);

        if (i == r3) {
            break;
        }
    }
}

uint32_t HELPER(tprot)(uint64_t a1, uint64_t a2)
{
    /* XXX implement */

    return 0;
}

/* insert storage key extended */
886
uint64_t HELPER(iske)(CPUS390XState *env, uint64_t r2)
887
{
888
    uint64_t addr = get_address(env, 0, 0, r2);
889 890 891 892 893 894 895 896 897

    if (addr > ram_size) {
        return 0;
    }

    return env->storage_keys[addr / TARGET_PAGE_SIZE];
}

/* set storage key extended */
R
Richard Henderson 已提交
898
void HELPER(sske)(CPUS390XState *env, uint64_t r1, uint64_t r2)
899
{
900
    uint64_t addr = get_address(env, 0, 0, r2);
901 902 903 904 905 906 907 908 909

    if (addr > ram_size) {
        return;
    }

    env->storage_keys[addr / TARGET_PAGE_SIZE] = r1;
}

/* reset reference bit extended */
R
Richard Henderson 已提交
910
uint32_t HELPER(rrbe)(CPUS390XState *env, uint64_t r2)
911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935
{
    uint8_t re;
    uint8_t key;

    if (r2 > ram_size) {
        return 0;
    }

    key = env->storage_keys[r2 / TARGET_PAGE_SIZE];
    re = key & (SK_R | SK_C);
    env->storage_keys[r2 / TARGET_PAGE_SIZE] = (key & ~SK_R);

    /*
     * cc
     *
     * 0  Reference bit zero; change bit zero
     * 1  Reference bit zero; change bit one
     * 2  Reference bit one; change bit zero
     * 3  Reference bit one; change bit one
     */

    return re >> 1;
}

/* compare and swap and purge */
R
Richard Henderson 已提交
936
uint32_t HELPER(csp)(CPUS390XState *env, uint32_t r1, uint64_t r2)
937 938 939
{
    uint32_t cc;
    uint32_t o1 = env->regs[r1];
R
Richard Henderson 已提交
940
    uint64_t a2 = r2 & ~3ULL;
941
    uint32_t o2 = cpu_ldl_data(env, a2);
942 943

    if (o1 == o2) {
944
        cpu_stl_data(env, a2, env->regs[(r1 + 1) & 15]);
R
Richard Henderson 已提交
945
        if (r2 & 0x3) {
946 947 948 949 950 951 952 953 954 955 956 957
            /* flush TLB / ALB */
            tlb_flush(env, 1);
        }
        cc = 0;
    } else {
        env->regs[r1] = (env->regs[r1] & 0xffffffff00000000ULL) | o2;
        cc = 1;
    }

    return cc;
}

958 959
static uint32_t mvc_asc(CPUS390XState *env, int64_t l, uint64_t a1,
                        uint64_t mode1, uint64_t a2, uint64_t mode2)
960
{
961
    CPUState *cs = CPU(s390_env_get_cpu(env));
962 963 964 965 966 967 968 969 970 971 972 973
    target_ulong src, dest;
    int flags, cc = 0, i;

    if (!l) {
        return 0;
    } else if (l > 256) {
        /* max 256 */
        l = 256;
        cc = 3;
    }

    if (mmu_translate(env, a1 & TARGET_PAGE_MASK, 1, mode1, &dest, &flags)) {
974
        cpu_loop_exit(CPU(s390_env_get_cpu(env)));
975 976 977 978
    }
    dest |= a1 & ~TARGET_PAGE_MASK;

    if (mmu_translate(env, a2 & TARGET_PAGE_MASK, 0, mode2, &src, &flags)) {
979
        cpu_loop_exit(CPU(s390_env_get_cpu(env)));
980 981 982 983 984 985 986 987
    }
    src |= a2 & ~TARGET_PAGE_MASK;

    /* XXX replace w/ memcpy */
    for (i = 0; i < l; i++) {
        /* XXX be more clever */
        if ((((dest + i) & TARGET_PAGE_MASK) != (dest & TARGET_PAGE_MASK)) ||
            (((src + i) & TARGET_PAGE_MASK) != (src & TARGET_PAGE_MASK))) {
988
            mvc_asc(env, l - i, a1 + i, mode1, a2 + i, mode2);
989 990
            break;
        }
991
        stb_phys(cs->as, dest + i, ldub_phys(cs->as, src + i));
992 993 994 995 996
    }

    return cc;
}

997
uint32_t HELPER(mvcs)(CPUS390XState *env, uint64_t l, uint64_t a1, uint64_t a2)
998 999 1000 1001
{
    HELPER_LOG("%s: %16" PRIx64 " %16" PRIx64 " %16" PRIx64 "\n",
               __func__, l, a1, a2);

1002
    return mvc_asc(env, l, a1, PSW_ASC_SECONDARY, a2, PSW_ASC_PRIMARY);
1003 1004
}

1005
uint32_t HELPER(mvcp)(CPUS390XState *env, uint64_t l, uint64_t a1, uint64_t a2)
1006 1007 1008 1009
{
    HELPER_LOG("%s: %16" PRIx64 " %16" PRIx64 " %16" PRIx64 "\n",
               __func__, l, a1, a2);

1010
    return mvc_asc(env, l, a1, PSW_ASC_PRIMARY, a2, PSW_ASC_SECONDARY);
1011 1012 1013
}

/* invalidate pte */
1014
void HELPER(ipte)(CPUS390XState *env, uint64_t pte_addr, uint64_t vaddr)
1015
{
1016
    CPUState *cs = CPU(s390_env_get_cpu(env));
1017 1018 1019 1020 1021 1022 1023 1024 1025
    uint64_t page = vaddr & TARGET_PAGE_MASK;
    uint64_t pte = 0;

    /* XXX broadcast to other CPUs */

    /* XXX Linux is nice enough to give us the exact pte address.
       According to spec we'd have to find it out ourselves */
    /* XXX Linux is fine with overwriting the pte, the spec requires
       us to only set the invalid bit */
1026
    stq_phys(cs->as, pte_addr, pte | _PAGE_INVALID);
1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040

    /* XXX we exploit the fact that Linux passes the exact virtual
       address here - it's not obliged to! */
    tlb_flush_page(env, page);

    /* XXX 31-bit hack */
    if (page & 0x80000000) {
        tlb_flush_page(env, page & ~0x80000000);
    } else {
        tlb_flush_page(env, page | 0x80000000);
    }
}

/* flush local tlb */
1041
void HELPER(ptlb)(CPUS390XState *env)
1042 1043 1044 1045 1046
{
    tlb_flush(env, 1);
}

/* store using real address */
R
Richard Henderson 已提交
1047
void HELPER(stura)(CPUS390XState *env, uint64_t addr, uint64_t v1)
1048
{
1049 1050
    CPUState *cs = CPU(s390_env_get_cpu(env));

1051
    stw_phys(cs->as, get_address(env, 0, 0, addr), (uint32_t)v1);
1052 1053 1054
}

/* load real address */
R
Richard Henderson 已提交
1055
uint64_t HELPER(lra)(CPUS390XState *env, uint64_t addr)
1056
{
1057
    CPUState *cs = CPU(s390_env_get_cpu(env));
1058
    uint32_t cc = 0;
1059
    int old_exc = cs->exception_index;
1060 1061 1062 1063 1064 1065 1066 1067 1068
    uint64_t asc = env->psw.mask & PSW_MASK_ASC;
    uint64_t ret;
    int flags;

    /* XXX incomplete - has more corner cases */
    if (!(env->psw.mask & PSW_MASK_64) && (addr >> 32)) {
        program_interrupt(env, PGM_SPECIAL_OP, 2);
    }

1069
    cs->exception_index = old_exc;
1070 1071 1072
    if (mmu_translate(env, addr, 0, asc, &ret, &flags)) {
        cc = 3;
    }
1073
    if (cs->exception_index == EXCP_PGM) {
1074 1075 1076 1077
        ret = env->int_pgm_code | 0x80000000;
    } else {
        ret |= addr & ~TARGET_PAGE_MASK;
    }
1078
    cs->exception_index = old_exc;
1079

R
Richard Henderson 已提交
1080 1081
    env->cc_op = cc;
    return ret;
1082 1083
}
#endif