mem_helper.c 29.0 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
/*
 *  S/390 memory access helper routines
 *
 *  Copyright (c) 2009 Ulrich Hecht
 *  Copyright (c) 2009 Alexander Graf
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
 */

#include "cpu.h"
22
#include "exec/helper-proto.h"
P
Paolo Bonzini 已提交
23
#include "exec/cpu_ldst.h"
24 25 26 27 28 29 30 31 32

/*****************************************************************************/
/* Softmmu support */
#if !defined(CONFIG_USER_ONLY)

/* try to fill the TLB and return an exception if error. If retaddr is
   NULL, it means that the function was called in C code (i.e. not
   from generated code or from helper.c) */
/* XXX: fix it to restore all registers */
33
void tlb_fill(CPUState *cs, target_ulong addr, int is_write, int mmu_idx,
34 35 36 37
              uintptr_t retaddr)
{
    int ret;

38
    ret = s390_cpu_handle_mmu_fault(cs, addr, is_write, mmu_idx);
39 40 41
    if (unlikely(ret != 0)) {
        if (likely(retaddr)) {
            /* now we have a real cpu fault */
42
            cpu_restore_state(cs, retaddr);
43
        }
44
        cpu_loop_exit(cs);
45 46 47 48 49 50 51 52 53 54 55 56
    }
}

#endif

/* #define DEBUG_HELPER */
#ifdef DEBUG_HELPER
#define HELPER_LOG(x...) qemu_log(x)
#else
#define HELPER_LOG(x...)
#endif

57 58 59 60 61 62 63 64 65 66 67
/* Reduce the length so that addr + len doesn't cross a page boundary.  */
static inline uint64_t adj_len_to_page(uint64_t len, uint64_t addr)
{
#ifndef CONFIG_USER_ONLY
    if ((addr & ~TARGET_PAGE_MASK) + len - 1 >= TARGET_PAGE_SIZE) {
        return -addr & ~TARGET_PAGE_MASK;
    }
#endif
    return len;
}

68 69
static void fast_memset(CPUS390XState *env, uint64_t dest, uint8_t byte,
                        uint32_t l)
70
{
71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87
    int mmu_idx = cpu_mmu_index(env);

    while (l > 0) {
        void *p = tlb_vaddr_to_host(env, dest, MMU_DATA_STORE, mmu_idx);
        if (p) {
            /* Access to the whole page in write mode granted.  */
            int l_adj = adj_len_to_page(l, dest);
            memset(p, byte, l_adj);
            dest += l_adj;
            l -= l_adj;
        } else {
            /* We failed to get access to the whole page. The next write
               access will likely fill the QEMU TLB for the next iteration.  */
            cpu_stb_data(env, dest, byte);
            dest++;
            l--;
        }
88 89 90
    }
}

91 92
static void fast_memmove(CPUS390XState *env, uint64_t dest, uint64_t src,
                         uint32_t l)
93
{
94
    int mmu_idx = cpu_mmu_index(env);
95

96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115
    while (l > 0) {
        void *src_p = tlb_vaddr_to_host(env, src, MMU_DATA_LOAD, mmu_idx);
        void *dest_p = tlb_vaddr_to_host(env, dest, MMU_DATA_STORE, mmu_idx);
        if (src_p && dest_p) {
            /* Access to both whole pages granted.  */
            int l_adj = adj_len_to_page(l, src);
            l_adj = adj_len_to_page(l_adj, dest);
            memmove(dest_p, src_p, l_adj);
            src += l_adj;
            dest += l_adj;
            l -= l_adj;
        } else {
            /* We failed to get access to one or both whole pages. The next
               read or write access will likely fill the QEMU TLB for the
               next iteration.  */
            cpu_stb_data(env, dest, cpu_ldub_data(env, src));
            src++;
            dest++;
            l--;
        }
116 117 118 119
    }
}

/* and on array */
120 121
uint32_t HELPER(nc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
122 123 124 125 126 127 128 129
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);
    for (i = 0; i <= l; i++) {
130
        x = cpu_ldub_data(env, dest + i) & cpu_ldub_data(env, src + i);
131 132 133
        if (x) {
            cc = 1;
        }
134
        cpu_stb_data(env, dest + i, x);
135 136 137 138 139
    }
    return cc;
}

/* xor on array */
140 141
uint32_t HELPER(xc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
142 143 144 145 146 147 148 149 150 151
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);

    /* xor with itself is the same as memset(0) */
    if (src == dest) {
152
        fast_memset(env, dest, 0, l + 1);
153 154 155 156
        return 0;
    }

    for (i = 0; i <= l; i++) {
157
        x = cpu_ldub_data(env, dest + i) ^ cpu_ldub_data(env, src + i);
158 159 160
        if (x) {
            cc = 1;
        }
161
        cpu_stb_data(env, dest + i, x);
162 163 164 165 166
    }
    return cc;
}

/* or on array */
167 168
uint32_t HELPER(oc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
169 170 171 172 173 174 175 176
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);
    for (i = 0; i <= l; i++) {
177
        x = cpu_ldub_data(env, dest + i) | cpu_ldub_data(env, src + i);
178 179 180
        if (x) {
            cc = 1;
        }
181
        cpu_stb_data(env, dest + i, x);
182 183 184 185 186
    }
    return cc;
}

/* memmove */
187
void HELPER(mvc)(CPUS390XState *env, uint32_t l, uint64_t dest, uint64_t src)
188 189 190 191 192 193
{
    int i = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);

194 195 196 197 198 199
    /* mvc with source pointing to the byte after the destination is the
       same as memset with the first source byte */
    if (dest == (src + 1)) {
        fast_memset(env, dest, cpu_ldub_data(env, src), l + 1);
        return;
    }
200

201
    /* mvc and memmove do not behave the same when areas overlap! */
202
    if ((dest < src) || (src + l < dest)) {
203
        fast_memmove(env, dest, src, l + 1);
204 205 206
        return;
    }

207
    /* slow version with byte accesses which always work */
208
    for (i = 0; i <= l; i++) {
209
        cpu_stb_data(env, dest + i, cpu_ldub_data(env, src + i));
210 211 212 213
    }
}

/* compare unsigned byte arrays */
214
uint32_t HELPER(clc)(CPUS390XState *env, uint32_t l, uint64_t s1, uint64_t s2)
215 216 217 218 219 220 221 222
{
    int i;
    unsigned char x, y;
    uint32_t cc;

    HELPER_LOG("%s l %d s1 %" PRIx64 " s2 %" PRIx64 "\n",
               __func__, l, s1, s2);
    for (i = 0; i <= l; i++) {
223 224
        x = cpu_ldub_data(env, s1 + i);
        y = cpu_ldub_data(env, s2 + i);
225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240
        HELPER_LOG("%02x (%c)/%02x (%c) ", x, x, y, y);
        if (x < y) {
            cc = 1;
            goto done;
        } else if (x > y) {
            cc = 2;
            goto done;
        }
    }
    cc = 0;
 done:
    HELPER_LOG("\n");
    return cc;
}

/* compare logical under mask */
241 242
uint32_t HELPER(clm)(CPUS390XState *env, uint32_t r1, uint32_t mask,
                     uint64_t addr)
243 244 245 246 247 248 249 250 251
{
    uint8_t r, d;
    uint32_t cc;

    HELPER_LOG("%s: r1 0x%x mask 0x%x addr 0x%" PRIx64 "\n", __func__, r1,
               mask, addr);
    cc = 0;
    while (mask) {
        if (mask & 8) {
252
            d = cpu_ldub_data(env, addr);
253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271
            r = (r1 & 0xff000000UL) >> 24;
            HELPER_LOG("mask 0x%x %02x/%02x (0x%" PRIx64 ") ", mask, r, d,
                       addr);
            if (r < d) {
                cc = 1;
                break;
            } else if (r > d) {
                cc = 2;
                break;
            }
            addr++;
        }
        mask = (mask << 1) & 0xf;
        r1 <<= 8;
    }
    HELPER_LOG("\n");
    return cc;
}

272 273 274 275 276 277 278 279 280
static inline uint64_t fix_address(CPUS390XState *env, uint64_t a)
{
    /* 31-Bit mode */
    if (!(env->psw.mask & PSW_MASK_64)) {
        a &= 0x7fffffff;
    }
    return a;
}

281
static inline uint64_t get_address(CPUS390XState *env, int x2, int b2, int d2)
282 283 284 285 286 287 288 289
{
    uint64_t r = d2;
    if (x2) {
        r += env->regs[x2];
    }
    if (b2) {
        r += env->regs[b2];
    }
290
    return fix_address(env, r);
291 292
}

293
static inline uint64_t get_address_31fix(CPUS390XState *env, int reg)
294
{
295
    return fix_address(env, env->regs[reg]);
296 297 298
}

/* search string (c is byte to search, r2 is string, r1 end of string) */
R
Richard Henderson 已提交
299 300
uint64_t HELPER(srst)(CPUS390XState *env, uint64_t r0, uint64_t end,
                      uint64_t str)
301
{
R
Richard Henderson 已提交
302 303
    uint32_t len;
    uint8_t v, c = r0;
304

R
Richard Henderson 已提交
305 306
    str = fix_address(env, str);
    end = fix_address(env, end);
307

R
Richard Henderson 已提交
308 309 310 311
    /* Assume for now that R2 is unmodified.  */
    env->retxl = str;

    /* Lest we fail to service interrupts in a timely manner, limit the
312
       amount of work we're willing to do.  For now, let's cap at 8k.  */
R
Richard Henderson 已提交
313 314 315 316 317 318 319 320 321 322 323
    for (len = 0; len < 0x2000; ++len) {
        if (str + len == end) {
            /* Character not found.  R1 & R2 are unmodified.  */
            env->cc_op = 2;
            return end;
        }
        v = cpu_ldub_data(env, str + len);
        if (v == c) {
            /* Character found.  Set R1 to the location; R2 is unmodified.  */
            env->cc_op = 1;
            return str + len;
324 325 326
        }
    }

R
Richard Henderson 已提交
327 328 329 330
    /* CPU-determined bytes processed.  Advance R2 to next byte to process.  */
    env->retxl = str + len;
    env->cc_op = 3;
    return end;
331 332 333
}

/* unsigned string compare (c is string terminator) */
334
uint64_t HELPER(clst)(CPUS390XState *env, uint64_t c, uint64_t s1, uint64_t s2)
335
{
336
    uint32_t len;
337 338

    c = c & 0xff;
339 340 341 342
    s1 = fix_address(env, s1);
    s2 = fix_address(env, s2);

    /* Lest we fail to service interrupts in a timely manner, limit the
343
       amount of work we're willing to do.  For now, let's cap at 8k.  */
344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360
    for (len = 0; len < 0x2000; ++len) {
        uint8_t v1 = cpu_ldub_data(env, s1 + len);
        uint8_t v2 = cpu_ldub_data(env, s2 + len);
        if (v1 == v2) {
            if (v1 == c) {
                /* Equal.  CC=0, and don't advance the registers.  */
                env->cc_op = 0;
                env->retxl = s2;
                return s1;
            }
        } else {
            /* Unequal.  CC={1,2}, and advance the registers.  Note that
               the terminator need not be zero, but the string that contains
               the terminator is by definition "low".  */
            env->cc_op = (v1 == c ? 1 : v2 == c ? 2 : v1 < v2 ? 1 : 2);
            env->retxl = s2 + len;
            return s1 + len;
361 362 363
        }
    }

364 365 366 367
    /* CPU-determined bytes equal; advance the registers.  */
    env->cc_op = 3;
    env->retxl = s2 + len;
    return s1 + len;
368 369 370
}

/* move page */
371
void HELPER(mvpg)(CPUS390XState *env, uint64_t r0, uint64_t r1, uint64_t r2)
372 373
{
    /* XXX missing r0 handling */
R
Richard Henderson 已提交
374
    env->cc_op = 0;
375
    fast_memmove(env, r1, r2, TARGET_PAGE_SIZE);
376 377 378
}

/* string copy (c is string terminator) */
379
uint64_t HELPER(mvst)(CPUS390XState *env, uint64_t c, uint64_t d, uint64_t s)
380
{
381
    uint32_t len;
382 383

    c = c & 0xff;
384 385 386 387
    d = fix_address(env, d);
    s = fix_address(env, s);

    /* Lest we fail to service interrupts in a timely manner, limit the
388
       amount of work we're willing to do.  For now, let's cap at 8k.  */
389 390 391
    for (len = 0; len < 0x2000; ++len) {
        uint8_t v = cpu_ldub_data(env, s + len);
        cpu_stb_data(env, d + len, v);
392
        if (v == c) {
393 394 395 396
            /* Complete.  Set CC=1 and advance R1.  */
            env->cc_op = 1;
            env->retxl = s;
            return d + len;
397 398
        }
    }
399 400 401 402 403

    /* Incomplete.  Set CC=3 and signal to advance R1 and R2.  */
    env->cc_op = 3;
    env->retxl = s + len;
    return d + len;
404 405
}

406 407
static uint32_t helper_icm(CPUS390XState *env, uint32_t r1, uint64_t address,
                           uint32_t mask)
408 409 410 411 412 413 414 415 416 417
{
    int pos = 24; /* top of the lower half of r1 */
    uint64_t rmask = 0xff000000ULL;
    uint8_t val = 0;
    int ccd = 0;
    uint32_t cc = 0;

    while (mask) {
        if (mask & 8) {
            env->regs[r1] &= ~rmask;
418
            val = cpu_ldub_data(env, address);
419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443
            if ((val & 0x80) && !ccd) {
                cc = 1;
            }
            ccd = 1;
            if (val && cc == 0) {
                cc = 2;
            }
            env->regs[r1] |= (uint64_t)val << pos;
            address++;
        }
        mask = (mask << 1) & 0xf;
        pos -= 8;
        rmask >>= 8;
    }

    return cc;
}

/* execute instruction
   this instruction executes an insn modified with the contents of r1
   it does not change the executed instruction in memory
   it does not change the program counter
   in other words: tricky...
   currently implemented by interpreting the cases it is most commonly used in
*/
444 445
uint32_t HELPER(ex)(CPUS390XState *env, uint32_t cc, uint64_t v1,
                    uint64_t addr, uint64_t ret)
446
{
447
    S390CPU *cpu = s390_env_get_cpu(env);
448
    uint16_t insn = cpu_lduw_code(env, addr);
449 450 451 452 453 454 455

    HELPER_LOG("%s: v1 0x%lx addr 0x%lx insn 0x%x\n", __func__, v1, addr,
               insn);
    if ((insn & 0xf0ff) == 0xd000) {
        uint32_t l, insn2, b1, b2, d1, d2;

        l = v1 & 0xff;
456
        insn2 = cpu_ldl_code(env, addr + 2);
457 458 459 460 461 462
        b1 = (insn2 >> 28) & 0xf;
        b2 = (insn2 >> 12) & 0xf;
        d1 = (insn2 >> 16) & 0xfff;
        d2 = insn2 & 0xfff;
        switch (insn & 0xf00) {
        case 0x200:
463 464
            helper_mvc(env, l, get_address(env, 0, b1, d1),
                       get_address(env, 0, b2, d2));
465
            break;
466 467 468 469
        case 0x400:
            cc = helper_nc(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
            break;
470
        case 0x500:
471 472
            cc = helper_clc(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
473
            break;
474 475 476 477
        case 0x600:
            cc = helper_oc(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
            break;
478
        case 0x700:
479 480
            cc = helper_xc(env, l, get_address(env, 0, b1, d1),
                           get_address(env, 0, b2, d2));
481 482
            break;
        case 0xc00:
483 484
            helper_tr(env, l, get_address(env, 0, b1, d1),
                      get_address(env, 0, b2, d2));
485 486 487
        case 0xd00:
            cc = helper_trt(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
488 489 490 491 492 493 494 495 496
            break;
        default:
            goto abort;
        }
    } else if ((insn & 0xff00) == 0x0a00) {
        /* supervisor call */
        HELPER_LOG("%s: svc %ld via execute\n", __func__, (insn | v1) & 0xff);
        env->psw.addr = ret - 4;
        env->int_svc_code = (insn | v1) & 0xff;
497
        env->int_svc_ilen = 4;
498
        helper_exception(env, EXCP_SVC);
499 500 501
    } else if ((insn & 0xff00) == 0xbf00) {
        uint32_t insn2, r1, r3, b2, d2;

502
        insn2 = cpu_ldl_code(env, addr + 2);
503 504 505 506
        r1 = (insn2 >> 20) & 0xf;
        r3 = (insn2 >> 16) & 0xf;
        b2 = (insn2 >> 12) & 0xf;
        d2 = insn2 & 0xfff;
507
        cc = helper_icm(env, r1, get_address(env, 0, b2, d2), r3);
508 509
    } else {
    abort:
510
        cpu_abort(CPU(cpu), "EXECUTE on instruction prefix 0x%x not implemented\n",
511 512 513 514 515 516
                  insn);
    }
    return cc;
}

/* load access registers r1 to r3 from memory at a2 */
517
void HELPER(lam)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
518 519 520 521
{
    int i;

    for (i = r1;; i = (i + 1) % 16) {
522
        env->aregs[i] = cpu_ldl_data(env, a2);
523 524 525 526 527 528 529 530 531
        a2 += 4;

        if (i == r3) {
            break;
        }
    }
}

/* store access registers r1 to r3 in memory at a2 */
532
void HELPER(stam)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
533 534 535 536
{
    int i;

    for (i = r1;; i = (i + 1) % 16) {
537
        cpu_stl_data(env, a2, env->aregs[i]);
538 539 540 541 542 543 544 545 546
        a2 += 4;

        if (i == r3) {
            break;
        }
    }
}

/* move long */
547
uint32_t HELPER(mvcl)(CPUS390XState *env, uint32_t r1, uint32_t r2)
548 549
{
    uint64_t destlen = env->regs[r1 + 1] & 0xffffff;
550
    uint64_t dest = get_address_31fix(env, r1);
551
    uint64_t srclen = env->regs[r2 + 1] & 0xffffff;
552
    uint64_t src = get_address_31fix(env, r2);
553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569
    uint8_t pad = src >> 24;
    uint8_t v;
    uint32_t cc;

    if (destlen == srclen) {
        cc = 0;
    } else if (destlen < srclen) {
        cc = 1;
    } else {
        cc = 2;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen && srclen; src++, dest++, destlen--, srclen--) {
570 571
        v = cpu_ldub_data(env, src);
        cpu_stb_data(env, dest, v);
572 573 574
    }

    for (; destlen; dest++, destlen--) {
575
        cpu_stb_data(env, dest, pad);
576 577 578 579 580 581 582 583 584 585 586 587
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    env->regs[r2 + 1] -= src - env->regs[r2];
    env->regs[r1] = dest;
    env->regs[r2] = src;

    return cc;
}

/* move long extended another memcopy insn with more bells and whistles */
588 589
uint32_t HELPER(mvcle)(CPUS390XState *env, uint32_t r1, uint64_t a2,
                       uint32_t r3)
590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618
{
    uint64_t destlen = env->regs[r1 + 1];
    uint64_t dest = env->regs[r1];
    uint64_t srclen = env->regs[r3 + 1];
    uint64_t src = env->regs[r3];
    uint8_t pad = a2 & 0xff;
    uint8_t v;
    uint32_t cc;

    if (!(env->psw.mask & PSW_MASK_64)) {
        destlen = (uint32_t)destlen;
        srclen = (uint32_t)srclen;
        dest &= 0x7fffffff;
        src &= 0x7fffffff;
    }

    if (destlen == srclen) {
        cc = 0;
    } else if (destlen < srclen) {
        cc = 1;
    } else {
        cc = 2;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen && srclen; src++, dest++, destlen--, srclen--) {
619 620
        v = cpu_ldub_data(env, src);
        cpu_stb_data(env, dest, v);
621 622 623
    }

    for (; destlen; dest++, destlen--) {
624
        cpu_stb_data(env, dest, pad);
625 626 627 628 629 630 631 632 633 634 635 636 637
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    /* FIXME: 31-bit mode! */
    env->regs[r3 + 1] -= src - env->regs[r3];
    env->regs[r1] = dest;
    env->regs[r3] = src;

    return cc;
}

/* compare logical long extended memcompare insn with padding */
638 639
uint32_t HELPER(clcle)(CPUS390XState *env, uint32_t r1, uint64_t a2,
                       uint32_t r3)
640 641
{
    uint64_t destlen = env->regs[r1 + 1];
642
    uint64_t dest = get_address_31fix(env, r1);
643
    uint64_t srclen = env->regs[r3 + 1];
644
    uint64_t src = get_address_31fix(env, r3);
645 646 647 648 649 650 651 652 653 654 655 656 657
    uint8_t pad = a2 & 0xff;
    uint8_t v1 = 0, v2 = 0;
    uint32_t cc = 0;

    if (!(destlen || srclen)) {
        return cc;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen || srclen; src++, dest++, destlen--, srclen--) {
658 659
        v1 = srclen ? cpu_ldub_data(env, src) : pad;
        v2 = destlen ? cpu_ldub_data(env, dest) : pad;
660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675
        if (v1 != v2) {
            cc = (v1 < v2) ? 1 : 2;
            break;
        }
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    env->regs[r3 + 1] -= src - env->regs[r3];
    env->regs[r1] = dest;
    env->regs[r3] = src;

    return cc;
}

/* checksum */
R
Richard Henderson 已提交
676 677
uint64_t HELPER(cksm)(CPUS390XState *env, uint64_t r1,
                      uint64_t src, uint64_t src_len)
678
{
R
Richard Henderson 已提交
679 680
    uint64_t max_len, len;
    uint64_t cksm = (uint32_t)r1;
681

R
Richard Henderson 已提交
682
    /* Lest we fail to service interrupts in a timely manner, limit the
683
       amount of work we're willing to do.  For now, let's cap at 8k.  */
R
Richard Henderson 已提交
684
    max_len = (src_len > 0x2000 ? 0x2000 : src_len);
685

R
Richard Henderson 已提交
686 687 688
    /* Process full words as available.  */
    for (len = 0; len + 4 <= max_len; len += 4, src += 4) {
        cksm += (uint32_t)cpu_ldl_data(env, src);
689 690
    }

R
Richard Henderson 已提交
691
    switch (max_len - len) {
692
    case 1:
693
        cksm += cpu_ldub_data(env, src) << 24;
R
Richard Henderson 已提交
694
        len += 1;
695 696
        break;
    case 2:
697
        cksm += cpu_lduw_data(env, src) << 16;
R
Richard Henderson 已提交
698
        len += 2;
699 700
        break;
    case 3:
701 702
        cksm += cpu_lduw_data(env, src) << 16;
        cksm += cpu_ldub_data(env, src + 2) << 8;
R
Richard Henderson 已提交
703
        len += 3;
704 705 706
        break;
    }

R
Richard Henderson 已提交
707 708 709 710 711 712 713 714
    /* Fold the carry from the checksum.  Note that we can see carry-out
       during folding more than once (but probably not more than twice).  */
    while (cksm > 0xffffffffull) {
        cksm = (uint32_t)cksm + (cksm >> 32);
    }

    /* Indicate whether or not we've processed everything.  */
    env->cc_op = (len == src_len ? 0 : 3);
715

R
Richard Henderson 已提交
716 717 718
    /* Return both cksm and processed length.  */
    env->retxl = cksm;
    return len;
719 720
}

721 722
void HELPER(unpk)(CPUS390XState *env, uint32_t len, uint64_t dest,
                  uint64_t src)
723 724 725 726 727 728 729 730 731 732
{
    int len_dest = len >> 4;
    int len_src = len & 0xf;
    uint8_t b;
    int second_nibble = 0;

    dest += len_dest;
    src += len_src;

    /* last byte is special, it only flips the nibbles */
733 734
    b = cpu_ldub_data(env, src);
    cpu_stb_data(env, dest, (b << 4) | (b >> 4));
735 736 737 738 739 740 741 742 743
    src--;
    len_src--;

    /* now pad every nibble with 0xf0 */

    while (len_dest > 0) {
        uint8_t cur_byte = 0;

        if (len_src > 0) {
744
            cur_byte = cpu_ldub_data(env, src);
745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762
        }

        len_dest--;
        dest--;

        /* only advance one nibble at a time */
        if (second_nibble) {
            cur_byte >>= 4;
            len_src--;
            src--;
        }
        second_nibble = !second_nibble;

        /* digit */
        cur_byte = (cur_byte & 0xf);
        /* zone bits */
        cur_byte |= 0xf0;

763
        cpu_stb_data(env, dest, cur_byte);
764 765 766
    }
}

767 768
void HELPER(tr)(CPUS390XState *env, uint32_t len, uint64_t array,
                uint64_t trans)
769 770 771 772
{
    int i;

    for (i = 0; i <= len; i++) {
773 774
        uint8_t byte = cpu_ldub_data(env, array + i);
        uint8_t new_byte = cpu_ldub_data(env, trans + byte);
775

776
        cpu_stb_data(env, array + i, new_byte);
777 778 779
    }
}

780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818
uint64_t HELPER(tre)(CPUS390XState *env, uint64_t array,
                     uint64_t len, uint64_t trans)
{
    uint8_t end = env->regs[0] & 0xff;
    uint64_t l = len;
    uint64_t i;

    if (!(env->psw.mask & PSW_MASK_64)) {
        array &= 0x7fffffff;
        l = (uint32_t)l;
    }

    /* Lest we fail to service interrupts in a timely manner, limit the
       amount of work we're willing to do.  For now, let's cap at 8k.  */
    if (l > 0x2000) {
        l = 0x2000;
        env->cc_op = 3;
    } else {
        env->cc_op = 0;
    }

    for (i = 0; i < l; i++) {
        uint8_t byte, new_byte;

        byte = cpu_ldub_data(env, array + i);

        if (byte == end) {
            env->cc_op = 1;
            break;
        }

        new_byte = cpu_ldub_data(env, trans + byte);
        cpu_stb_data(env, array + i, new_byte);
    }

    env->retxl = len - i;
    return array + i;
}

819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839
uint32_t HELPER(trt)(CPUS390XState *env, uint32_t len, uint64_t array,
                     uint64_t trans)
{
    uint32_t cc = 0;
    int i;

    for (i = 0; i <= len; i++) {
        uint8_t byte = cpu_ldub_data(env, array + i);
        uint8_t sbyte = cpu_ldub_data(env, trans + byte);

        if (sbyte != 0) {
            env->regs[1] = array + i;
            env->regs[2] = (env->regs[2] & ~0xff) | sbyte;
            cc = (i == len) ? 2 : 1;
            break;
        }
    }

    return cc;
}

840
#if !defined(CONFIG_USER_ONLY)
841
void HELPER(lctlg)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
842
{
843
    S390CPU *cpu = s390_env_get_cpu(env);
844 845 846 847
    int i;
    uint64_t src = a2;

    for (i = r1;; i = (i + 1) % 16) {
848
        env->cregs[i] = cpu_ldq_data(env, src);
849 850 851 852 853 854 855 856 857
        HELPER_LOG("load ctl %d from 0x%" PRIx64 " == 0x%" PRIx64 "\n",
                   i, src, env->cregs[i]);
        src += sizeof(uint64_t);

        if (i == r3) {
            break;
        }
    }

858
    tlb_flush(CPU(cpu), 1);
859 860
}

861
void HELPER(lctl)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
862
{
863
    S390CPU *cpu = s390_env_get_cpu(env);
864 865 866 867
    int i;
    uint64_t src = a2;

    for (i = r1;; i = (i + 1) % 16) {
868 869
        env->cregs[i] = (env->cregs[i] & 0xFFFFFFFF00000000ULL) |
            cpu_ldl_data(env, src);
870 871 872 873 874 875 876
        src += sizeof(uint32_t);

        if (i == r3) {
            break;
        }
    }

877
    tlb_flush(CPU(cpu), 1);
878 879
}

880
void HELPER(stctg)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
881 882 883 884 885
{
    int i;
    uint64_t dest = a2;

    for (i = r1;; i = (i + 1) % 16) {
886
        cpu_stq_data(env, dest, env->cregs[i]);
887 888 889 890 891 892 893 894
        dest += sizeof(uint64_t);

        if (i == r3) {
            break;
        }
    }
}

895
void HELPER(stctl)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
896 897 898 899 900
{
    int i;
    uint64_t dest = a2;

    for (i = r1;; i = (i + 1) % 16) {
901
        cpu_stl_data(env, dest, env->cregs[i]);
902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917
        dest += sizeof(uint32_t);

        if (i == r3) {
            break;
        }
    }
}

uint32_t HELPER(tprot)(uint64_t a1, uint64_t a2)
{
    /* XXX implement */

    return 0;
}

/* insert storage key extended */
918
uint64_t HELPER(iske)(CPUS390XState *env, uint64_t r2)
919
{
920
    uint64_t addr = get_address(env, 0, 0, r2);
921 922 923 924 925 926 927 928 929

    if (addr > ram_size) {
        return 0;
    }

    return env->storage_keys[addr / TARGET_PAGE_SIZE];
}

/* set storage key extended */
R
Richard Henderson 已提交
930
void HELPER(sske)(CPUS390XState *env, uint64_t r1, uint64_t r2)
931
{
932
    uint64_t addr = get_address(env, 0, 0, r2);
933 934 935 936 937 938 939 940 941

    if (addr > ram_size) {
        return;
    }

    env->storage_keys[addr / TARGET_PAGE_SIZE] = r1;
}

/* reset reference bit extended */
R
Richard Henderson 已提交
942
uint32_t HELPER(rrbe)(CPUS390XState *env, uint64_t r2)
943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967
{
    uint8_t re;
    uint8_t key;

    if (r2 > ram_size) {
        return 0;
    }

    key = env->storage_keys[r2 / TARGET_PAGE_SIZE];
    re = key & (SK_R | SK_C);
    env->storage_keys[r2 / TARGET_PAGE_SIZE] = (key & ~SK_R);

    /*
     * cc
     *
     * 0  Reference bit zero; change bit zero
     * 1  Reference bit zero; change bit one
     * 2  Reference bit one; change bit zero
     * 3  Reference bit one; change bit one
     */

    return re >> 1;
}

/* compare and swap and purge */
R
Richard Henderson 已提交
968
uint32_t HELPER(csp)(CPUS390XState *env, uint32_t r1, uint64_t r2)
969
{
970
    S390CPU *cpu = s390_env_get_cpu(env);
971 972
    uint32_t cc;
    uint32_t o1 = env->regs[r1];
R
Richard Henderson 已提交
973
    uint64_t a2 = r2 & ~3ULL;
974
    uint32_t o2 = cpu_ldl_data(env, a2);
975 976

    if (o1 == o2) {
977
        cpu_stl_data(env, a2, env->regs[(r1 + 1) & 15]);
R
Richard Henderson 已提交
978
        if (r2 & 0x3) {
979
            /* flush TLB / ALB */
980
            tlb_flush(CPU(cpu), 1);
981 982 983 984 985 986 987 988 989 990
        }
        cc = 0;
    } else {
        env->regs[r1] = (env->regs[r1] & 0xffffffff00000000ULL) | o2;
        cc = 1;
    }

    return cc;
}

991
uint32_t HELPER(mvcs)(CPUS390XState *env, uint64_t l, uint64_t a1, uint64_t a2)
992
{
993
    int cc = 0, i;
994

995 996 997 998
    HELPER_LOG("%s: %16" PRIx64 " %16" PRIx64 " %16" PRIx64 "\n",
               __func__, l, a1, a2);

    if (l > 256) {
999 1000 1001 1002 1003 1004 1005
        /* max 256 */
        l = 256;
        cc = 3;
    }

    /* XXX replace w/ memcpy */
    for (i = 0; i < l; i++) {
1006
        cpu_stb_secondary(env, a1 + i, cpu_ldub_primary(env, a2 + i));
1007 1008 1009 1010 1011
    }

    return cc;
}

1012
uint32_t HELPER(mvcp)(CPUS390XState *env, uint64_t l, uint64_t a1, uint64_t a2)
1013
{
1014 1015
    int cc = 0, i;

1016 1017 1018
    HELPER_LOG("%s: %16" PRIx64 " %16" PRIx64 " %16" PRIx64 "\n",
               __func__, l, a1, a2);

1019 1020 1021 1022 1023
    if (l > 256) {
        /* max 256 */
        l = 256;
        cc = 3;
    }
1024

1025 1026 1027 1028
    /* XXX replace w/ memcpy */
    for (i = 0; i < l; i++) {
        cpu_stb_primary(env, a1 + i, cpu_ldub_secondary(env, a2 + i));
    }
1029

1030
    return cc;
1031 1032 1033
}

/* invalidate pte */
1034
void HELPER(ipte)(CPUS390XState *env, uint64_t pte_addr, uint64_t vaddr)
1035
{
1036
    CPUState *cs = CPU(s390_env_get_cpu(env));
1037 1038 1039 1040 1041 1042 1043 1044 1045
    uint64_t page = vaddr & TARGET_PAGE_MASK;
    uint64_t pte = 0;

    /* XXX broadcast to other CPUs */

    /* XXX Linux is nice enough to give us the exact pte address.
       According to spec we'd have to find it out ourselves */
    /* XXX Linux is fine with overwriting the pte, the spec requires
       us to only set the invalid bit */
1046
    stq_phys(cs->as, pte_addr, pte | _PAGE_INVALID);
1047 1048 1049

    /* XXX we exploit the fact that Linux passes the exact virtual
       address here - it's not obliged to! */
1050
    tlb_flush_page(cs, page);
1051 1052 1053

    /* XXX 31-bit hack */
    if (page & 0x80000000) {
1054
        tlb_flush_page(cs, page & ~0x80000000);
1055
    } else {
1056
        tlb_flush_page(cs, page | 0x80000000);
1057 1058 1059 1060
    }
}

/* flush local tlb */
1061
void HELPER(ptlb)(CPUS390XState *env)
1062
{
1063 1064 1065
    S390CPU *cpu = s390_env_get_cpu(env);

    tlb_flush(CPU(cpu), 1);
1066 1067
}

1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082
/* load using real address */
uint64_t HELPER(lura)(CPUS390XState *env, uint64_t addr)
{
    CPUState *cs = CPU(s390_env_get_cpu(env));

    return (uint32_t)ldl_phys(cs->as, get_address(env, 0, 0, addr));
}

uint64_t HELPER(lurag)(CPUS390XState *env, uint64_t addr)
{
    CPUState *cs = CPU(s390_env_get_cpu(env));

    return ldq_phys(cs->as, get_address(env, 0, 0, addr));
}

1083
/* store using real address */
R
Richard Henderson 已提交
1084
void HELPER(stura)(CPUS390XState *env, uint64_t addr, uint64_t v1)
1085
{
1086 1087
    CPUState *cs = CPU(s390_env_get_cpu(env));

R
Richard Henderson 已提交
1088
    stl_phys(cs->as, get_address(env, 0, 0, addr), (uint32_t)v1);
1089 1090
}

1091 1092 1093 1094 1095 1096 1097
void HELPER(sturg)(CPUS390XState *env, uint64_t addr, uint64_t v1)
{
    CPUState *cs = CPU(s390_env_get_cpu(env));

    stq_phys(cs->as, get_address(env, 0, 0, addr), v1);
}

1098
/* load real address */
R
Richard Henderson 已提交
1099
uint64_t HELPER(lra)(CPUS390XState *env, uint64_t addr)
1100
{
1101
    CPUState *cs = CPU(s390_env_get_cpu(env));
1102
    uint32_t cc = 0;
1103
    int old_exc = cs->exception_index;
1104 1105 1106 1107 1108 1109 1110 1111 1112
    uint64_t asc = env->psw.mask & PSW_MASK_ASC;
    uint64_t ret;
    int flags;

    /* XXX incomplete - has more corner cases */
    if (!(env->psw.mask & PSW_MASK_64) && (addr >> 32)) {
        program_interrupt(env, PGM_SPECIAL_OP, 2);
    }

1113
    cs->exception_index = old_exc;
1114
    if (mmu_translate(env, addr, 0, asc, &ret, &flags, true)) {
1115 1116
        cc = 3;
    }
1117
    if (cs->exception_index == EXCP_PGM) {
1118 1119 1120 1121
        ret = env->int_pgm_code | 0x80000000;
    } else {
        ret |= addr & ~TARGET_PAGE_MASK;
    }
1122
    cs->exception_index = old_exc;
1123

R
Richard Henderson 已提交
1124 1125
    env->cc_op = cc;
    return ret;
1126 1127
}
#endif