mem_helper.c 29.9 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21
/*
 *  S/390 memory access helper routines
 *
 *  Copyright (c) 2009 Ulrich Hecht
 *  Copyright (c) 2009 Alexander Graf
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
 */

#include "cpu.h"
22
#include "exec/helper-proto.h"
P
Paolo Bonzini 已提交
23
#include "exec/cpu_ldst.h"
24 25 26 27 28 29 30 31 32

/*****************************************************************************/
/* Softmmu support */
#if !defined(CONFIG_USER_ONLY)

/* try to fill the TLB and return an exception if error. If retaddr is
   NULL, it means that the function was called in C code (i.e. not
   from generated code or from helper.c) */
/* XXX: fix it to restore all registers */
33
void tlb_fill(CPUState *cs, target_ulong addr, int is_write, int mmu_idx,
34 35 36 37
              uintptr_t retaddr)
{
    int ret;

38
    ret = s390_cpu_handle_mmu_fault(cs, addr, is_write, mmu_idx);
39 40 41
    if (unlikely(ret != 0)) {
        if (likely(retaddr)) {
            /* now we have a real cpu fault */
42
            cpu_restore_state(cs, retaddr);
43
        }
44
        cpu_loop_exit(cs);
45 46 47 48 49 50 51 52 53 54 55 56
    }
}

#endif

/* #define DEBUG_HELPER */
#ifdef DEBUG_HELPER
#define HELPER_LOG(x...) qemu_log(x)
#else
#define HELPER_LOG(x...)
#endif

57 58 59 60 61 62 63 64 65 66 67
/* Reduce the length so that addr + len doesn't cross a page boundary.  */
static inline uint64_t adj_len_to_page(uint64_t len, uint64_t addr)
{
#ifndef CONFIG_USER_ONLY
    if ((addr & ~TARGET_PAGE_MASK) + len - 1 >= TARGET_PAGE_SIZE) {
        return -addr & ~TARGET_PAGE_MASK;
    }
#endif
    return len;
}

68 69 70 71
#ifndef CONFIG_USER_ONLY
static void mvc_fast_memset(CPUS390XState *env, uint32_t l, uint64_t dest,
                            uint8_t byte)
{
72
    S390CPU *cpu = s390_env_get_cpu(env);
A
Avi Kivity 已提交
73 74
    hwaddr dest_phys;
    hwaddr len = l;
75 76 77 78
    void *dest_p;
    uint64_t asc = env->psw.mask & PSW_MASK_ASC;
    int flags;

79
    if (mmu_translate(env, dest, 1, asc, &dest_phys, &flags, true)) {
80
        cpu_stb_data(env, dest, byte);
81
        cpu_abort(CPU(cpu), "should never reach here");
82 83 84 85 86 87 88 89 90 91 92 93 94
    }
    dest_phys |= dest & ~TARGET_PAGE_MASK;

    dest_p = cpu_physical_memory_map(dest_phys, &len, 1);

    memset(dest_p, byte, len);

    cpu_physical_memory_unmap(dest_p, 1, len, len);
}

static void mvc_fast_memmove(CPUS390XState *env, uint32_t l, uint64_t dest,
                             uint64_t src)
{
95
    S390CPU *cpu = s390_env_get_cpu(env);
A
Avi Kivity 已提交
96 97 98
    hwaddr dest_phys;
    hwaddr src_phys;
    hwaddr len = l;
99 100 101 102 103
    void *dest_p;
    void *src_p;
    uint64_t asc = env->psw.mask & PSW_MASK_ASC;
    int flags;

104
    if (mmu_translate(env, dest, 1, asc, &dest_phys, &flags, true)) {
105
        cpu_stb_data(env, dest, 0);
106
        cpu_abort(CPU(cpu), "should never reach here");
107 108 109
    }
    dest_phys |= dest & ~TARGET_PAGE_MASK;

110
    if (mmu_translate(env, src, 0, asc, &src_phys, &flags, true)) {
111
        cpu_ldub_data(env, src);
112
        cpu_abort(CPU(cpu), "should never reach here");
113 114 115 116 117 118 119 120 121 122 123 124 125 126
    }
    src_phys |= src & ~TARGET_PAGE_MASK;

    dest_p = cpu_physical_memory_map(dest_phys, &len, 1);
    src_p = cpu_physical_memory_map(src_phys, &len, 0);

    memmove(dest_p, src_p, len);

    cpu_physical_memory_unmap(dest_p, 1, len, len);
    cpu_physical_memory_unmap(src_p, 0, len, len);
}
#endif

/* and on array */
127 128
uint32_t HELPER(nc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
129 130 131 132 133 134 135 136
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);
    for (i = 0; i <= l; i++) {
137
        x = cpu_ldub_data(env, dest + i) & cpu_ldub_data(env, src + i);
138 139 140
        if (x) {
            cc = 1;
        }
141
        cpu_stb_data(env, dest + i, x);
142 143 144 145 146
    }
    return cc;
}

/* xor on array */
147 148
uint32_t HELPER(xc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);

#ifndef CONFIG_USER_ONLY
    /* xor with itself is the same as memset(0) */
    if ((l > 32) && (src == dest) &&
        (src & TARGET_PAGE_MASK) == ((src + l) & TARGET_PAGE_MASK)) {
        mvc_fast_memset(env, l + 1, dest, 0);
        return 0;
    }
#else
    if (src == dest) {
        memset(g2h(dest), 0, l + 1);
        return 0;
    }
#endif

    for (i = 0; i <= l; i++) {
172
        x = cpu_ldub_data(env, dest + i) ^ cpu_ldub_data(env, src + i);
173 174 175
        if (x) {
            cc = 1;
        }
176
        cpu_stb_data(env, dest + i, x);
177 178 179 180 181
    }
    return cc;
}

/* or on array */
182 183
uint32_t HELPER(oc)(CPUS390XState *env, uint32_t l, uint64_t dest,
                    uint64_t src)
184 185 186 187 188 189 190 191
{
    int i;
    unsigned char x;
    uint32_t cc = 0;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);
    for (i = 0; i <= l; i++) {
192
        x = cpu_ldub_data(env, dest + i) | cpu_ldub_data(env, src + i);
193 194 195
        if (x) {
            cc = 1;
        }
196
        cpu_stb_data(env, dest + i, x);
197 198 199 200 201
    }
    return cc;
}

/* memmove */
202
void HELPER(mvc)(CPUS390XState *env, uint32_t l, uint64_t dest, uint64_t src)
203 204 205 206 207 208 209 210 211 212 213 214 215
{
    int i = 0;
    int x = 0;
    uint32_t l_64 = (l + 1) / 8;

    HELPER_LOG("%s l %d dest %" PRIx64 " src %" PRIx64 "\n",
               __func__, l, dest, src);

#ifndef CONFIG_USER_ONLY
    if ((l > 32) &&
        (src & TARGET_PAGE_MASK) == ((src + l) & TARGET_PAGE_MASK) &&
        (dest & TARGET_PAGE_MASK) == ((dest + l) & TARGET_PAGE_MASK)) {
        if (dest == (src + 1)) {
216
            mvc_fast_memset(env, l + 1, dest, cpu_ldub_data(env, src));
217 218 219 220 221 222 223 224
            return;
        } else if ((src & TARGET_PAGE_MASK) != (dest & TARGET_PAGE_MASK)) {
            mvc_fast_memmove(env, l + 1, dest, src);
            return;
        }
    }
#else
    if (dest == (src + 1)) {
225
        memset(g2h(dest), cpu_ldub_data(env, src), l + 1);
226
        return;
227 228
    /* mvc and memmove do not behave the same when areas overlap! */
    } else if ((dest < src) || (src + l < dest)) {
229 230 231 232 233 234
        memmove(g2h(dest), g2h(src), l + 1);
        return;
    }
#endif

    /* handle the parts that fit into 8-byte loads/stores */
235
    if ((dest + 8 <= src) || (src + 8 <= dest)) {
236
        for (i = 0; i < l_64; i++) {
237
            cpu_stq_data(env, dest + x, cpu_ldq_data(env, src + x));
238 239 240 241
            x += 8;
        }
    }

242
    /* slow version with byte accesses which always work */
243
    for (i = x; i <= l; i++) {
244
        cpu_stb_data(env, dest + i, cpu_ldub_data(env, src + i));
245 246 247 248
    }
}

/* compare unsigned byte arrays */
249
uint32_t HELPER(clc)(CPUS390XState *env, uint32_t l, uint64_t s1, uint64_t s2)
250 251 252 253 254 255 256 257
{
    int i;
    unsigned char x, y;
    uint32_t cc;

    HELPER_LOG("%s l %d s1 %" PRIx64 " s2 %" PRIx64 "\n",
               __func__, l, s1, s2);
    for (i = 0; i <= l; i++) {
258 259
        x = cpu_ldub_data(env, s1 + i);
        y = cpu_ldub_data(env, s2 + i);
260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275
        HELPER_LOG("%02x (%c)/%02x (%c) ", x, x, y, y);
        if (x < y) {
            cc = 1;
            goto done;
        } else if (x > y) {
            cc = 2;
            goto done;
        }
    }
    cc = 0;
 done:
    HELPER_LOG("\n");
    return cc;
}

/* compare logical under mask */
276 277
uint32_t HELPER(clm)(CPUS390XState *env, uint32_t r1, uint32_t mask,
                     uint64_t addr)
278 279 280 281 282 283 284 285 286
{
    uint8_t r, d;
    uint32_t cc;

    HELPER_LOG("%s: r1 0x%x mask 0x%x addr 0x%" PRIx64 "\n", __func__, r1,
               mask, addr);
    cc = 0;
    while (mask) {
        if (mask & 8) {
287
            d = cpu_ldub_data(env, addr);
288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306
            r = (r1 & 0xff000000UL) >> 24;
            HELPER_LOG("mask 0x%x %02x/%02x (0x%" PRIx64 ") ", mask, r, d,
                       addr);
            if (r < d) {
                cc = 1;
                break;
            } else if (r > d) {
                cc = 2;
                break;
            }
            addr++;
        }
        mask = (mask << 1) & 0xf;
        r1 <<= 8;
    }
    HELPER_LOG("\n");
    return cc;
}

307 308 309 310 311 312 313 314 315
static inline uint64_t fix_address(CPUS390XState *env, uint64_t a)
{
    /* 31-Bit mode */
    if (!(env->psw.mask & PSW_MASK_64)) {
        a &= 0x7fffffff;
    }
    return a;
}

316
static inline uint64_t get_address(CPUS390XState *env, int x2, int b2, int d2)
317 318 319 320 321 322 323 324
{
    uint64_t r = d2;
    if (x2) {
        r += env->regs[x2];
    }
    if (b2) {
        r += env->regs[b2];
    }
325
    return fix_address(env, r);
326 327
}

328
static inline uint64_t get_address_31fix(CPUS390XState *env, int reg)
329
{
330
    return fix_address(env, env->regs[reg]);
331 332 333
}

/* search string (c is byte to search, r2 is string, r1 end of string) */
R
Richard Henderson 已提交
334 335
uint64_t HELPER(srst)(CPUS390XState *env, uint64_t r0, uint64_t end,
                      uint64_t str)
336
{
R
Richard Henderson 已提交
337 338
    uint32_t len;
    uint8_t v, c = r0;
339

R
Richard Henderson 已提交
340 341
    str = fix_address(env, str);
    end = fix_address(env, end);
342

R
Richard Henderson 已提交
343 344 345 346
    /* Assume for now that R2 is unmodified.  */
    env->retxl = str;

    /* Lest we fail to service interrupts in a timely manner, limit the
347
       amount of work we're willing to do.  For now, let's cap at 8k.  */
R
Richard Henderson 已提交
348 349 350 351 352 353 354 355 356 357 358
    for (len = 0; len < 0x2000; ++len) {
        if (str + len == end) {
            /* Character not found.  R1 & R2 are unmodified.  */
            env->cc_op = 2;
            return end;
        }
        v = cpu_ldub_data(env, str + len);
        if (v == c) {
            /* Character found.  Set R1 to the location; R2 is unmodified.  */
            env->cc_op = 1;
            return str + len;
359 360 361
        }
    }

R
Richard Henderson 已提交
362 363 364 365
    /* CPU-determined bytes processed.  Advance R2 to next byte to process.  */
    env->retxl = str + len;
    env->cc_op = 3;
    return end;
366 367 368
}

/* unsigned string compare (c is string terminator) */
369
uint64_t HELPER(clst)(CPUS390XState *env, uint64_t c, uint64_t s1, uint64_t s2)
370
{
371
    uint32_t len;
372 373

    c = c & 0xff;
374 375 376 377
    s1 = fix_address(env, s1);
    s2 = fix_address(env, s2);

    /* Lest we fail to service interrupts in a timely manner, limit the
378
       amount of work we're willing to do.  For now, let's cap at 8k.  */
379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395
    for (len = 0; len < 0x2000; ++len) {
        uint8_t v1 = cpu_ldub_data(env, s1 + len);
        uint8_t v2 = cpu_ldub_data(env, s2 + len);
        if (v1 == v2) {
            if (v1 == c) {
                /* Equal.  CC=0, and don't advance the registers.  */
                env->cc_op = 0;
                env->retxl = s2;
                return s1;
            }
        } else {
            /* Unequal.  CC={1,2}, and advance the registers.  Note that
               the terminator need not be zero, but the string that contains
               the terminator is by definition "low".  */
            env->cc_op = (v1 == c ? 1 : v2 == c ? 2 : v1 < v2 ? 1 : 2);
            env->retxl = s2 + len;
            return s1 + len;
396 397 398
        }
    }

399 400 401 402
    /* CPU-determined bytes equal; advance the registers.  */
    env->cc_op = 3;
    env->retxl = s2 + len;
    return s1 + len;
403 404 405
}

/* move page */
406
void HELPER(mvpg)(CPUS390XState *env, uint64_t r0, uint64_t r1, uint64_t r2)
407 408
{
    /* XXX missing r0 handling */
R
Richard Henderson 已提交
409
    env->cc_op = 0;
410
#ifdef CONFIG_USER_ONLY
R
Richard Henderson 已提交
411
    memmove(g2h(r1), g2h(r2), TARGET_PAGE_SIZE);
412 413 414 415 416 417
#else
    mvc_fast_memmove(env, TARGET_PAGE_SIZE, r1, r2);
#endif
}

/* string copy (c is string terminator) */
418
uint64_t HELPER(mvst)(CPUS390XState *env, uint64_t c, uint64_t d, uint64_t s)
419
{
420
    uint32_t len;
421 422

    c = c & 0xff;
423 424 425 426
    d = fix_address(env, d);
    s = fix_address(env, s);

    /* Lest we fail to service interrupts in a timely manner, limit the
427
       amount of work we're willing to do.  For now, let's cap at 8k.  */
428 429 430
    for (len = 0; len < 0x2000; ++len) {
        uint8_t v = cpu_ldub_data(env, s + len);
        cpu_stb_data(env, d + len, v);
431
        if (v == c) {
432 433 434 435
            /* Complete.  Set CC=1 and advance R1.  */
            env->cc_op = 1;
            env->retxl = s;
            return d + len;
436 437
        }
    }
438 439 440 441 442

    /* Incomplete.  Set CC=3 and signal to advance R1 and R2.  */
    env->cc_op = 3;
    env->retxl = s + len;
    return d + len;
443 444
}

445 446
static uint32_t helper_icm(CPUS390XState *env, uint32_t r1, uint64_t address,
                           uint32_t mask)
447 448 449 450 451 452 453 454 455 456
{
    int pos = 24; /* top of the lower half of r1 */
    uint64_t rmask = 0xff000000ULL;
    uint8_t val = 0;
    int ccd = 0;
    uint32_t cc = 0;

    while (mask) {
        if (mask & 8) {
            env->regs[r1] &= ~rmask;
457
            val = cpu_ldub_data(env, address);
458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482
            if ((val & 0x80) && !ccd) {
                cc = 1;
            }
            ccd = 1;
            if (val && cc == 0) {
                cc = 2;
            }
            env->regs[r1] |= (uint64_t)val << pos;
            address++;
        }
        mask = (mask << 1) & 0xf;
        pos -= 8;
        rmask >>= 8;
    }

    return cc;
}

/* execute instruction
   this instruction executes an insn modified with the contents of r1
   it does not change the executed instruction in memory
   it does not change the program counter
   in other words: tricky...
   currently implemented by interpreting the cases it is most commonly used in
*/
483 484
uint32_t HELPER(ex)(CPUS390XState *env, uint32_t cc, uint64_t v1,
                    uint64_t addr, uint64_t ret)
485
{
486
    S390CPU *cpu = s390_env_get_cpu(env);
487
    uint16_t insn = cpu_lduw_code(env, addr);
488 489 490 491 492 493 494

    HELPER_LOG("%s: v1 0x%lx addr 0x%lx insn 0x%x\n", __func__, v1, addr,
               insn);
    if ((insn & 0xf0ff) == 0xd000) {
        uint32_t l, insn2, b1, b2, d1, d2;

        l = v1 & 0xff;
495
        insn2 = cpu_ldl_code(env, addr + 2);
496 497 498 499 500 501
        b1 = (insn2 >> 28) & 0xf;
        b2 = (insn2 >> 12) & 0xf;
        d1 = (insn2 >> 16) & 0xfff;
        d2 = insn2 & 0xfff;
        switch (insn & 0xf00) {
        case 0x200:
502 503
            helper_mvc(env, l, get_address(env, 0, b1, d1),
                       get_address(env, 0, b2, d2));
504
            break;
505 506 507 508
        case 0x400:
            cc = helper_nc(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
            break;
509
        case 0x500:
510 511
            cc = helper_clc(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
512
            break;
513 514 515 516
        case 0x600:
            cc = helper_oc(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
            break;
517
        case 0x700:
518 519
            cc = helper_xc(env, l, get_address(env, 0, b1, d1),
                           get_address(env, 0, b2, d2));
520 521
            break;
        case 0xc00:
522 523
            helper_tr(env, l, get_address(env, 0, b1, d1),
                      get_address(env, 0, b2, d2));
524 525 526
        case 0xd00:
            cc = helper_trt(env, l, get_address(env, 0, b1, d1),
                            get_address(env, 0, b2, d2));
527 528 529 530 531 532 533 534 535
            break;
        default:
            goto abort;
        }
    } else if ((insn & 0xff00) == 0x0a00) {
        /* supervisor call */
        HELPER_LOG("%s: svc %ld via execute\n", __func__, (insn | v1) & 0xff);
        env->psw.addr = ret - 4;
        env->int_svc_code = (insn | v1) & 0xff;
536
        env->int_svc_ilen = 4;
537
        helper_exception(env, EXCP_SVC);
538 539 540
    } else if ((insn & 0xff00) == 0xbf00) {
        uint32_t insn2, r1, r3, b2, d2;

541
        insn2 = cpu_ldl_code(env, addr + 2);
542 543 544 545
        r1 = (insn2 >> 20) & 0xf;
        r3 = (insn2 >> 16) & 0xf;
        b2 = (insn2 >> 12) & 0xf;
        d2 = insn2 & 0xfff;
546
        cc = helper_icm(env, r1, get_address(env, 0, b2, d2), r3);
547 548
    } else {
    abort:
549
        cpu_abort(CPU(cpu), "EXECUTE on instruction prefix 0x%x not implemented\n",
550 551 552 553 554 555
                  insn);
    }
    return cc;
}

/* load access registers r1 to r3 from memory at a2 */
556
void HELPER(lam)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
557 558 559 560
{
    int i;

    for (i = r1;; i = (i + 1) % 16) {
561
        env->aregs[i] = cpu_ldl_data(env, a2);
562 563 564 565 566 567 568 569 570
        a2 += 4;

        if (i == r3) {
            break;
        }
    }
}

/* store access registers r1 to r3 in memory at a2 */
571
void HELPER(stam)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
572 573 574 575
{
    int i;

    for (i = r1;; i = (i + 1) % 16) {
576
        cpu_stl_data(env, a2, env->aregs[i]);
577 578 579 580 581 582 583 584 585
        a2 += 4;

        if (i == r3) {
            break;
        }
    }
}

/* move long */
586
uint32_t HELPER(mvcl)(CPUS390XState *env, uint32_t r1, uint32_t r2)
587 588
{
    uint64_t destlen = env->regs[r1 + 1] & 0xffffff;
589
    uint64_t dest = get_address_31fix(env, r1);
590
    uint64_t srclen = env->regs[r2 + 1] & 0xffffff;
591
    uint64_t src = get_address_31fix(env, r2);
592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608
    uint8_t pad = src >> 24;
    uint8_t v;
    uint32_t cc;

    if (destlen == srclen) {
        cc = 0;
    } else if (destlen < srclen) {
        cc = 1;
    } else {
        cc = 2;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen && srclen; src++, dest++, destlen--, srclen--) {
609 610
        v = cpu_ldub_data(env, src);
        cpu_stb_data(env, dest, v);
611 612 613
    }

    for (; destlen; dest++, destlen--) {
614
        cpu_stb_data(env, dest, pad);
615 616 617 618 619 620 621 622 623 624 625 626
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    env->regs[r2 + 1] -= src - env->regs[r2];
    env->regs[r1] = dest;
    env->regs[r2] = src;

    return cc;
}

/* move long extended another memcopy insn with more bells and whistles */
627 628
uint32_t HELPER(mvcle)(CPUS390XState *env, uint32_t r1, uint64_t a2,
                       uint32_t r3)
629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657
{
    uint64_t destlen = env->regs[r1 + 1];
    uint64_t dest = env->regs[r1];
    uint64_t srclen = env->regs[r3 + 1];
    uint64_t src = env->regs[r3];
    uint8_t pad = a2 & 0xff;
    uint8_t v;
    uint32_t cc;

    if (!(env->psw.mask & PSW_MASK_64)) {
        destlen = (uint32_t)destlen;
        srclen = (uint32_t)srclen;
        dest &= 0x7fffffff;
        src &= 0x7fffffff;
    }

    if (destlen == srclen) {
        cc = 0;
    } else if (destlen < srclen) {
        cc = 1;
    } else {
        cc = 2;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen && srclen; src++, dest++, destlen--, srclen--) {
658 659
        v = cpu_ldub_data(env, src);
        cpu_stb_data(env, dest, v);
660 661 662
    }

    for (; destlen; dest++, destlen--) {
663
        cpu_stb_data(env, dest, pad);
664 665 666 667 668 669 670 671 672 673 674 675 676
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    /* FIXME: 31-bit mode! */
    env->regs[r3 + 1] -= src - env->regs[r3];
    env->regs[r1] = dest;
    env->regs[r3] = src;

    return cc;
}

/* compare logical long extended memcompare insn with padding */
677 678
uint32_t HELPER(clcle)(CPUS390XState *env, uint32_t r1, uint64_t a2,
                       uint32_t r3)
679 680
{
    uint64_t destlen = env->regs[r1 + 1];
681
    uint64_t dest = get_address_31fix(env, r1);
682
    uint64_t srclen = env->regs[r3 + 1];
683
    uint64_t src = get_address_31fix(env, r3);
684 685 686 687 688 689 690 691 692 693 694 695 696
    uint8_t pad = a2 & 0xff;
    uint8_t v1 = 0, v2 = 0;
    uint32_t cc = 0;

    if (!(destlen || srclen)) {
        return cc;
    }

    if (srclen > destlen) {
        srclen = destlen;
    }

    for (; destlen || srclen; src++, dest++, destlen--, srclen--) {
697 698
        v1 = srclen ? cpu_ldub_data(env, src) : pad;
        v2 = destlen ? cpu_ldub_data(env, dest) : pad;
699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714
        if (v1 != v2) {
            cc = (v1 < v2) ? 1 : 2;
            break;
        }
    }

    env->regs[r1 + 1] = destlen;
    /* can't use srclen here, we trunc'ed it */
    env->regs[r3 + 1] -= src - env->regs[r3];
    env->regs[r1] = dest;
    env->regs[r3] = src;

    return cc;
}

/* checksum */
R
Richard Henderson 已提交
715 716
uint64_t HELPER(cksm)(CPUS390XState *env, uint64_t r1,
                      uint64_t src, uint64_t src_len)
717
{
R
Richard Henderson 已提交
718 719
    uint64_t max_len, len;
    uint64_t cksm = (uint32_t)r1;
720

R
Richard Henderson 已提交
721
    /* Lest we fail to service interrupts in a timely manner, limit the
722
       amount of work we're willing to do.  For now, let's cap at 8k.  */
R
Richard Henderson 已提交
723
    max_len = (src_len > 0x2000 ? 0x2000 : src_len);
724

R
Richard Henderson 已提交
725 726 727
    /* Process full words as available.  */
    for (len = 0; len + 4 <= max_len; len += 4, src += 4) {
        cksm += (uint32_t)cpu_ldl_data(env, src);
728 729
    }

R
Richard Henderson 已提交
730
    switch (max_len - len) {
731
    case 1:
732
        cksm += cpu_ldub_data(env, src) << 24;
R
Richard Henderson 已提交
733
        len += 1;
734 735
        break;
    case 2:
736
        cksm += cpu_lduw_data(env, src) << 16;
R
Richard Henderson 已提交
737
        len += 2;
738 739
        break;
    case 3:
740 741
        cksm += cpu_lduw_data(env, src) << 16;
        cksm += cpu_ldub_data(env, src + 2) << 8;
R
Richard Henderson 已提交
742
        len += 3;
743 744 745
        break;
    }

R
Richard Henderson 已提交
746 747 748 749 750 751 752 753
    /* Fold the carry from the checksum.  Note that we can see carry-out
       during folding more than once (but probably not more than twice).  */
    while (cksm > 0xffffffffull) {
        cksm = (uint32_t)cksm + (cksm >> 32);
    }

    /* Indicate whether or not we've processed everything.  */
    env->cc_op = (len == src_len ? 0 : 3);
754

R
Richard Henderson 已提交
755 756 757
    /* Return both cksm and processed length.  */
    env->retxl = cksm;
    return len;
758 759
}

760 761
void HELPER(unpk)(CPUS390XState *env, uint32_t len, uint64_t dest,
                  uint64_t src)
762 763 764 765 766 767 768 769 770 771
{
    int len_dest = len >> 4;
    int len_src = len & 0xf;
    uint8_t b;
    int second_nibble = 0;

    dest += len_dest;
    src += len_src;

    /* last byte is special, it only flips the nibbles */
772 773
    b = cpu_ldub_data(env, src);
    cpu_stb_data(env, dest, (b << 4) | (b >> 4));
774 775 776 777 778 779 780 781 782
    src--;
    len_src--;

    /* now pad every nibble with 0xf0 */

    while (len_dest > 0) {
        uint8_t cur_byte = 0;

        if (len_src > 0) {
783
            cur_byte = cpu_ldub_data(env, src);
784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801
        }

        len_dest--;
        dest--;

        /* only advance one nibble at a time */
        if (second_nibble) {
            cur_byte >>= 4;
            len_src--;
            src--;
        }
        second_nibble = !second_nibble;

        /* digit */
        cur_byte = (cur_byte & 0xf);
        /* zone bits */
        cur_byte |= 0xf0;

802
        cpu_stb_data(env, dest, cur_byte);
803 804 805
    }
}

806 807
void HELPER(tr)(CPUS390XState *env, uint32_t len, uint64_t array,
                uint64_t trans)
808 809 810 811
{
    int i;

    for (i = 0; i <= len; i++) {
812 813
        uint8_t byte = cpu_ldub_data(env, array + i);
        uint8_t new_byte = cpu_ldub_data(env, trans + byte);
814

815
        cpu_stb_data(env, array + i, new_byte);
816 817 818
    }
}

819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857
uint64_t HELPER(tre)(CPUS390XState *env, uint64_t array,
                     uint64_t len, uint64_t trans)
{
    uint8_t end = env->regs[0] & 0xff;
    uint64_t l = len;
    uint64_t i;

    if (!(env->psw.mask & PSW_MASK_64)) {
        array &= 0x7fffffff;
        l = (uint32_t)l;
    }

    /* Lest we fail to service interrupts in a timely manner, limit the
       amount of work we're willing to do.  For now, let's cap at 8k.  */
    if (l > 0x2000) {
        l = 0x2000;
        env->cc_op = 3;
    } else {
        env->cc_op = 0;
    }

    for (i = 0; i < l; i++) {
        uint8_t byte, new_byte;

        byte = cpu_ldub_data(env, array + i);

        if (byte == end) {
            env->cc_op = 1;
            break;
        }

        new_byte = cpu_ldub_data(env, trans + byte);
        cpu_stb_data(env, array + i, new_byte);
    }

    env->retxl = len - i;
    return array + i;
}

858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878
uint32_t HELPER(trt)(CPUS390XState *env, uint32_t len, uint64_t array,
                     uint64_t trans)
{
    uint32_t cc = 0;
    int i;

    for (i = 0; i <= len; i++) {
        uint8_t byte = cpu_ldub_data(env, array + i);
        uint8_t sbyte = cpu_ldub_data(env, trans + byte);

        if (sbyte != 0) {
            env->regs[1] = array + i;
            env->regs[2] = (env->regs[2] & ~0xff) | sbyte;
            cc = (i == len) ? 2 : 1;
            break;
        }
    }

    return cc;
}

879
#if !defined(CONFIG_USER_ONLY)
880
void HELPER(lctlg)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
881
{
882
    S390CPU *cpu = s390_env_get_cpu(env);
883 884 885 886
    int i;
    uint64_t src = a2;

    for (i = r1;; i = (i + 1) % 16) {
887
        env->cregs[i] = cpu_ldq_data(env, src);
888 889 890 891 892 893 894 895 896
        HELPER_LOG("load ctl %d from 0x%" PRIx64 " == 0x%" PRIx64 "\n",
                   i, src, env->cregs[i]);
        src += sizeof(uint64_t);

        if (i == r3) {
            break;
        }
    }

897
    tlb_flush(CPU(cpu), 1);
898 899
}

900
void HELPER(lctl)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
901
{
902
    S390CPU *cpu = s390_env_get_cpu(env);
903 904 905 906
    int i;
    uint64_t src = a2;

    for (i = r1;; i = (i + 1) % 16) {
907 908
        env->cregs[i] = (env->cregs[i] & 0xFFFFFFFF00000000ULL) |
            cpu_ldl_data(env, src);
909 910 911 912 913 914 915
        src += sizeof(uint32_t);

        if (i == r3) {
            break;
        }
    }

916
    tlb_flush(CPU(cpu), 1);
917 918
}

919
void HELPER(stctg)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
920 921 922 923 924
{
    int i;
    uint64_t dest = a2;

    for (i = r1;; i = (i + 1) % 16) {
925
        cpu_stq_data(env, dest, env->cregs[i]);
926 927 928 929 930 931 932 933
        dest += sizeof(uint64_t);

        if (i == r3) {
            break;
        }
    }
}

934
void HELPER(stctl)(CPUS390XState *env, uint32_t r1, uint64_t a2, uint32_t r3)
935 936 937 938 939
{
    int i;
    uint64_t dest = a2;

    for (i = r1;; i = (i + 1) % 16) {
940
        cpu_stl_data(env, dest, env->cregs[i]);
941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956
        dest += sizeof(uint32_t);

        if (i == r3) {
            break;
        }
    }
}

uint32_t HELPER(tprot)(uint64_t a1, uint64_t a2)
{
    /* XXX implement */

    return 0;
}

/* insert storage key extended */
957
uint64_t HELPER(iske)(CPUS390XState *env, uint64_t r2)
958
{
959
    uint64_t addr = get_address(env, 0, 0, r2);
960 961 962 963 964 965 966 967 968

    if (addr > ram_size) {
        return 0;
    }

    return env->storage_keys[addr / TARGET_PAGE_SIZE];
}

/* set storage key extended */
R
Richard Henderson 已提交
969
void HELPER(sske)(CPUS390XState *env, uint64_t r1, uint64_t r2)
970
{
971
    uint64_t addr = get_address(env, 0, 0, r2);
972 973 974 975 976 977 978 979 980

    if (addr > ram_size) {
        return;
    }

    env->storage_keys[addr / TARGET_PAGE_SIZE] = r1;
}

/* reset reference bit extended */
R
Richard Henderson 已提交
981
uint32_t HELPER(rrbe)(CPUS390XState *env, uint64_t r2)
982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006
{
    uint8_t re;
    uint8_t key;

    if (r2 > ram_size) {
        return 0;
    }

    key = env->storage_keys[r2 / TARGET_PAGE_SIZE];
    re = key & (SK_R | SK_C);
    env->storage_keys[r2 / TARGET_PAGE_SIZE] = (key & ~SK_R);

    /*
     * cc
     *
     * 0  Reference bit zero; change bit zero
     * 1  Reference bit zero; change bit one
     * 2  Reference bit one; change bit zero
     * 3  Reference bit one; change bit one
     */

    return re >> 1;
}

/* compare and swap and purge */
R
Richard Henderson 已提交
1007
uint32_t HELPER(csp)(CPUS390XState *env, uint32_t r1, uint64_t r2)
1008
{
1009
    S390CPU *cpu = s390_env_get_cpu(env);
1010 1011
    uint32_t cc;
    uint32_t o1 = env->regs[r1];
R
Richard Henderson 已提交
1012
    uint64_t a2 = r2 & ~3ULL;
1013
    uint32_t o2 = cpu_ldl_data(env, a2);
1014 1015

    if (o1 == o2) {
1016
        cpu_stl_data(env, a2, env->regs[(r1 + 1) & 15]);
R
Richard Henderson 已提交
1017
        if (r2 & 0x3) {
1018
            /* flush TLB / ALB */
1019
            tlb_flush(CPU(cpu), 1);
1020 1021 1022 1023 1024 1025 1026 1027 1028 1029
        }
        cc = 0;
    } else {
        env->regs[r1] = (env->regs[r1] & 0xffffffff00000000ULL) | o2;
        cc = 1;
    }

    return cc;
}

1030
uint32_t HELPER(mvcs)(CPUS390XState *env, uint64_t l, uint64_t a1, uint64_t a2)
1031
{
1032
    int cc = 0, i;
1033

1034 1035 1036 1037
    HELPER_LOG("%s: %16" PRIx64 " %16" PRIx64 " %16" PRIx64 "\n",
               __func__, l, a1, a2);

    if (l > 256) {
1038 1039 1040 1041 1042 1043 1044
        /* max 256 */
        l = 256;
        cc = 3;
    }

    /* XXX replace w/ memcpy */
    for (i = 0; i < l; i++) {
1045
        cpu_stb_secondary(env, a1 + i, cpu_ldub_primary(env, a2 + i));
1046 1047 1048 1049 1050
    }

    return cc;
}

1051
uint32_t HELPER(mvcp)(CPUS390XState *env, uint64_t l, uint64_t a1, uint64_t a2)
1052
{
1053 1054
    int cc = 0, i;

1055 1056 1057
    HELPER_LOG("%s: %16" PRIx64 " %16" PRIx64 " %16" PRIx64 "\n",
               __func__, l, a1, a2);

1058 1059 1060 1061 1062
    if (l > 256) {
        /* max 256 */
        l = 256;
        cc = 3;
    }
1063

1064 1065 1066 1067
    /* XXX replace w/ memcpy */
    for (i = 0; i < l; i++) {
        cpu_stb_primary(env, a1 + i, cpu_ldub_secondary(env, a2 + i));
    }
1068

1069
    return cc;
1070 1071 1072
}

/* invalidate pte */
1073
void HELPER(ipte)(CPUS390XState *env, uint64_t pte_addr, uint64_t vaddr)
1074
{
1075
    CPUState *cs = CPU(s390_env_get_cpu(env));
1076 1077 1078 1079 1080 1081 1082 1083 1084
    uint64_t page = vaddr & TARGET_PAGE_MASK;
    uint64_t pte = 0;

    /* XXX broadcast to other CPUs */

    /* XXX Linux is nice enough to give us the exact pte address.
       According to spec we'd have to find it out ourselves */
    /* XXX Linux is fine with overwriting the pte, the spec requires
       us to only set the invalid bit */
1085
    stq_phys(cs->as, pte_addr, pte | _PAGE_INVALID);
1086 1087 1088

    /* XXX we exploit the fact that Linux passes the exact virtual
       address here - it's not obliged to! */
1089
    tlb_flush_page(cs, page);
1090 1091 1092

    /* XXX 31-bit hack */
    if (page & 0x80000000) {
1093
        tlb_flush_page(cs, page & ~0x80000000);
1094
    } else {
1095
        tlb_flush_page(cs, page | 0x80000000);
1096 1097 1098 1099
    }
}

/* flush local tlb */
1100
void HELPER(ptlb)(CPUS390XState *env)
1101
{
1102 1103 1104
    S390CPU *cpu = s390_env_get_cpu(env);

    tlb_flush(CPU(cpu), 1);
1105 1106
}

1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121
/* load using real address */
uint64_t HELPER(lura)(CPUS390XState *env, uint64_t addr)
{
    CPUState *cs = CPU(s390_env_get_cpu(env));

    return (uint32_t)ldl_phys(cs->as, get_address(env, 0, 0, addr));
}

uint64_t HELPER(lurag)(CPUS390XState *env, uint64_t addr)
{
    CPUState *cs = CPU(s390_env_get_cpu(env));

    return ldq_phys(cs->as, get_address(env, 0, 0, addr));
}

1122
/* store using real address */
R
Richard Henderson 已提交
1123
void HELPER(stura)(CPUS390XState *env, uint64_t addr, uint64_t v1)
1124
{
1125 1126
    CPUState *cs = CPU(s390_env_get_cpu(env));

R
Richard Henderson 已提交
1127
    stl_phys(cs->as, get_address(env, 0, 0, addr), (uint32_t)v1);
1128 1129
}

1130 1131 1132 1133 1134 1135 1136
void HELPER(sturg)(CPUS390XState *env, uint64_t addr, uint64_t v1)
{
    CPUState *cs = CPU(s390_env_get_cpu(env));

    stq_phys(cs->as, get_address(env, 0, 0, addr), v1);
}

1137
/* load real address */
R
Richard Henderson 已提交
1138
uint64_t HELPER(lra)(CPUS390XState *env, uint64_t addr)
1139
{
1140
    CPUState *cs = CPU(s390_env_get_cpu(env));
1141
    uint32_t cc = 0;
1142
    int old_exc = cs->exception_index;
1143 1144 1145 1146 1147 1148 1149 1150 1151
    uint64_t asc = env->psw.mask & PSW_MASK_ASC;
    uint64_t ret;
    int flags;

    /* XXX incomplete - has more corner cases */
    if (!(env->psw.mask & PSW_MASK_64) && (addr >> 32)) {
        program_interrupt(env, PGM_SPECIAL_OP, 2);
    }

1152
    cs->exception_index = old_exc;
1153
    if (mmu_translate(env, addr, 0, asc, &ret, &flags, true)) {
1154 1155
        cc = 3;
    }
1156
    if (cs->exception_index == EXCP_PGM) {
1157 1158 1159 1160
        ret = env->int_pgm_code | 0x80000000;
    } else {
        ret |= addr & ~TARGET_PAGE_MASK;
    }
1161
    cs->exception_index = old_exc;
1162

R
Richard Henderson 已提交
1163 1164
    env->cc_op = cc;
    return ret;
1165 1166
}
#endif