2 /* Simulator for the MIPS architecture.
4 This file is part of the MIPS sim
6 THIS SOFTWARE IS NOT COPYRIGHTED
8 Cygnus offers the following for use in the public domain. Cygnus
9 makes no warranty with regard to the software or it's performance
10 and the user accepts the software "AS IS" with all faults.
12 CYGNUS DISCLAIMS ANY WARRANTIES, EXPRESS OR IMPLIED, WITH REGARD TO
13 THIS SOFTWARE INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
14 MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
18 The IDT monitor (found on the VR4300 board), seems to lie about
19 register contents. It seems to treat the registers as sign-extended
20 32-bit values. This cause *REAL* problems when single-stepping 64-bit
25 /* The TRACE manifests enable the provision of extra features. If they
26 are not defined then a simpler (quicker) simulator is constructed
27 without the required run-time checks, etc. */
28 #if 1 /* 0 to allow user build selection, 1 to force inclusion */
34 #include "sim-utils.h"
35 #include "sim-options.h"
36 #include "sim-assert.h"
62 #include "libiberty.h"
64 #include "gdb/callback.h" /* GDB simulator callback interface */
65 #include "gdb/remote-sim.h" /* GDB simulator interface */
73 char* pr_addr
PARAMS ((SIM_ADDR addr
));
74 char* pr_uword64
PARAMS ((uword64 addr
));
77 /* Within interp.c we refer to the sim_state and sim_cpu directly. */
82 /* The following reserved instruction value is used when a simulator
83 trap is required. NOTE: Care must be taken, since this value may be
84 used in later revisions of the MIPS ISA. */
86 #define RSVD_INSTRUCTION (0x00000005)
87 #define RSVD_INSTRUCTION_MASK (0xFC00003F)
89 #define RSVD_INSTRUCTION_ARG_SHIFT 6
90 #define RSVD_INSTRUCTION_ARG_MASK 0xFFFFF
93 /* Bits in the Debug register */
94 #define Debug_DBD 0x80000000 /* Debug Branch Delay */
95 #define Debug_DM 0x40000000 /* Debug Mode */
96 #define Debug_DBp 0x00000002 /* Debug Breakpoint indicator */
98 /*---------------------------------------------------------------------------*/
99 /*-- GDB simulator interface ------------------------------------------------*/
100 /*---------------------------------------------------------------------------*/
102 static void ColdReset
PARAMS((SIM_DESC sd
));
104 /*---------------------------------------------------------------------------*/
108 #define DELAYSLOT() {\
109 if (STATE & simDELAYSLOT)\
110 sim_io_eprintf(sd,"Delay slot already activated (branch in delay slot?)\n");\
111 STATE |= simDELAYSLOT;\
114 #define JALDELAYSLOT() {\
116 STATE |= simJALDELAYSLOT;\
120 STATE &= ~simDELAYSLOT;\
121 STATE |= simSKIPNEXT;\
124 #define CANCELDELAYSLOT() {\
126 STATE &= ~(simDELAYSLOT | simJALDELAYSLOT);\
129 #define INDELAYSLOT() ((STATE & simDELAYSLOT) != 0)
130 #define INJALDELAYSLOT() ((STATE & simJALDELAYSLOT) != 0)
132 /* Note that the monitor code essentially assumes this layout of memory.
133 If you change these, change the monitor code, too. */
134 /* FIXME Currently addresses are truncated to 32-bits, see
135 mips/sim-main.c:address_translation(). If that changes, then these
136 values will need to be extended, and tested for more carefully. */
137 #define K0BASE (0x80000000)
138 #define K0SIZE (0x20000000)
139 #define K1BASE (0xA0000000)
140 #define K1SIZE (0x20000000)
142 /* Simple run-time monitor support.
144 We emulate the monitor by placing magic reserved instructions at
145 the monitor's entry points; when we hit these instructions, instead
146 of raising an exception (as we would normally), we look at the
147 instruction and perform the appropriate monitory operation.
149 `*_monitor_base' are the physical addresses at which the corresponding
150 monitor vectors are located. `0' means none. By default,
152 The RSVD_INSTRUCTION... macros specify the magic instructions we
153 use at the monitor entry points. */
154 static int firmware_option_p
= 0;
155 static SIM_ADDR idt_monitor_base
= 0xBFC00000;
156 static SIM_ADDR pmon_monitor_base
= 0xBFC00500;
157 static SIM_ADDR lsipmon_monitor_base
= 0xBFC00200;
159 static SIM_RC
sim_firmware_command (SIM_DESC sd
, char* arg
);
162 #define MEM_SIZE (8 << 20) /* 8 MBytes */
166 static char *tracefile
= "trace.din"; /* default filename for trace log */
167 FILE *tracefh
= NULL
;
168 static void open_trace
PARAMS((SIM_DESC sd
));
171 static const char * get_insn_name (sim_cpu
*, int);
173 /* simulation target board. NULL=canonical */
174 static char* board
= NULL
;
177 static DECLARE_OPTION_HANDLER (mips_option_handler
);
180 OPTION_DINERO_TRACE
= OPTION_START
,
188 mips_option_handler (sd
, cpu
, opt
, arg
, is_command
)
198 case OPTION_DINERO_TRACE
: /* ??? */
200 /* Eventually the simTRACE flag could be treated as a toggle, to
201 allow external control of the program points being traced
202 (i.e. only from main onwards, excluding the run-time setup,
204 for (cpu_nr
= 0; cpu_nr
< MAX_NR_PROCESSORS
; cpu_nr
++)
206 sim_cpu
*cpu
= STATE_CPU (sd
, cpu_nr
);
209 else if (strcmp (arg
, "yes") == 0)
211 else if (strcmp (arg
, "no") == 0)
213 else if (strcmp (arg
, "on") == 0)
215 else if (strcmp (arg
, "off") == 0)
219 fprintf (stderr
, "Unrecognized dinero-trace option `%s'\n", arg
);
226 Simulator constructed without dinero tracing support (for performance).\n\
227 Re-compile simulator with \"-DTRACE\" to enable this option.\n");
231 case OPTION_DINERO_FILE
:
233 if (optarg
!= NULL
) {
235 tmp
= (char *)malloc(strlen(optarg
) + 1);
238 sim_io_printf(sd
,"Failed to allocate buffer for tracefile name \"%s\"\n",optarg
);
244 sim_io_printf(sd
,"Placing trace information into file \"%s\"\n",tracefile
);
250 case OPTION_FIRMWARE
:
251 return sim_firmware_command (sd
, arg
);
257 board
= zalloc(strlen(arg
) + 1);
268 static const OPTION mips_options
[] =
270 { {"dinero-trace", optional_argument
, NULL
, OPTION_DINERO_TRACE
},
271 '\0', "on|off", "Enable dinero tracing",
272 mips_option_handler
},
273 { {"dinero-file", required_argument
, NULL
, OPTION_DINERO_FILE
},
274 '\0', "FILE", "Write dinero trace to FILE",
275 mips_option_handler
},
276 { {"firmware", required_argument
, NULL
, OPTION_FIRMWARE
},
277 '\0', "[idt|pmon|lsipmon|none][@ADDRESS]", "Emulate ROM monitor",
278 mips_option_handler
},
279 { {"board", required_argument
, NULL
, OPTION_BOARD
},
280 '\0', "none" /* rely on compile-time string concatenation for other options */
282 #define BOARD_JMR3904 "jmr3904"
284 #define BOARD_JMR3904_PAL "jmr3904pal"
285 "|" BOARD_JMR3904_PAL
286 #define BOARD_JMR3904_DEBUG "jmr3904debug"
287 "|" BOARD_JMR3904_DEBUG
288 #define BOARD_BSP "bsp"
291 , "Customize simulation for a particular board.", mips_option_handler
},
293 { {NULL
, no_argument
, NULL
, 0}, '\0', NULL
, NULL
, NULL
}
297 int interrupt_pending
;
300 interrupt_event (SIM_DESC sd
, void *data
)
302 sim_cpu
*cpu
= STATE_CPU (sd
, 0); /* FIXME */
303 address_word cia
= CIA_GET (cpu
);
306 interrupt_pending
= 0;
307 SignalExceptionInterrupt (1); /* interrupt "1" */
309 else if (!interrupt_pending
)
310 sim_events_schedule (sd
, 1, interrupt_event
, data
);
314 /*---------------------------------------------------------------------------*/
315 /*-- Device registration hook -----------------------------------------------*/
316 /*---------------------------------------------------------------------------*/
317 static void device_init(SIM_DESC sd
) {
319 extern void register_devices(SIM_DESC
);
320 register_devices(sd
);
324 /*---------------------------------------------------------------------------*/
325 /*-- GDB simulator interface ------------------------------------------------*/
326 /*---------------------------------------------------------------------------*/
329 sim_open (kind
, cb
, abfd
, argv
)
335 SIM_DESC sd
= sim_state_alloc (kind
, cb
);
336 sim_cpu
*cpu
= STATE_CPU (sd
, 0); /* FIXME */
338 SIM_ASSERT (STATE_MAGIC (sd
) == SIM_MAGIC_NUMBER
);
340 /* FIXME: watchpoints code shouldn't need this */
341 STATE_WATCHPOINTS (sd
)->pc
= &(PC
);
342 STATE_WATCHPOINTS (sd
)->sizeof_pc
= sizeof (PC
);
343 STATE_WATCHPOINTS (sd
)->interrupt_handler
= interrupt_event
;
345 /* Initialize the mechanism for doing insn profiling. */
346 CPU_INSN_NAME (cpu
) = get_insn_name
;
347 CPU_MAX_INSNS (cpu
) = nr_itable_entries
;
351 if (sim_pre_argv_init (sd
, argv
[0]) != SIM_RC_OK
)
353 sim_add_option_table (sd
, NULL
, mips_options
);
356 /* getopt will print the error message so we just have to exit if this fails.
357 FIXME: Hmmm... in the case of gdb we need getopt to call
359 if (sim_parse_args (sd
, argv
) != SIM_RC_OK
)
361 /* Uninstall the modules to avoid memory leaks,
362 file descriptor leaks, etc. */
363 sim_module_uninstall (sd
);
367 /* handle board-specific memory maps */
370 /* Allocate core managed memory */
371 sim_memopt
*entry
, *match
= NULL
;
372 address_word mem_size
= 0;
375 /* For compatibility with the old code - under this (at level one)
376 are the kernel spaces K0 & K1. Both of these map to a single
377 smaller sub region */
378 sim_do_command(sd
," memory region 0x7fff8000,0x8000") ; /* MTZ- 32 k stack */
380 /* Look for largest memory region defined on command-line at
382 #ifdef SIM_HAVE_FLATMEM
383 mem_size
= STATE_MEM_SIZE (sd
);
385 for (entry
= STATE_MEMOPT (sd
); entry
!= NULL
; entry
= entry
->next
)
387 /* If we find an entry at address 0, then we will end up
388 allocating a new buffer in the "memory alias" command
389 below. The region at address 0 will be deleted. */
390 address_word size
= (entry
->modulo
!= 0
391 ? entry
->modulo
: entry
->nr_bytes
);
393 && (!match
|| entry
->level
< match
->level
))
395 else if (entry
->addr
== K0BASE
|| entry
->addr
== K1BASE
)
400 for (alias
= entry
->alias
; alias
!= NULL
; alias
= alias
->next
)
403 && (!match
|| entry
->level
< match
->level
))
405 else if (alias
->addr
== K0BASE
|| alias
->addr
== K1BASE
)
415 /* Get existing memory region size. */
416 mem_size
= (match
->modulo
!= 0
417 ? match
->modulo
: match
->nr_bytes
);
418 /* Delete old region. */
419 sim_do_commandf (sd
, "memory delete %d:0x%lx@%d",
420 match
->space
, match
->addr
, match
->level
);
422 else if (mem_size
== 0)
424 /* Limit to KSEG1 size (512MB) */
425 if (mem_size
> K1SIZE
)
427 /* memory alias K1BASE@1,K1SIZE%MEMSIZE,K0BASE */
428 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx%%0x%lx,0x%0x",
429 K1BASE
, K1SIZE
, (long)mem_size
, K0BASE
);
434 else if (board
!= NULL
435 && (strcmp(board
, BOARD_BSP
) == 0))
439 STATE_ENVIRONMENT (sd
) = OPERATING_ENVIRONMENT
;
441 /* ROM: 0x9FC0_0000 - 0x9FFF_FFFF and 0xBFC0_0000 - 0xBFFF_FFFF */
442 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx,0x%0x",
444 4 * 1024 * 1024, /* 4 MB */
447 /* SRAM: 0x8000_0000 - 0x803F_FFFF and 0xA000_0000 - 0xA03F_FFFF */
448 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx,0x%0x",
450 4 * 1024 * 1024, /* 4 MB */
453 /* DRAM: 0x8800_0000 - 0x89FF_FFFF and 0xA800_0000 - 0xA9FF_FFFF */
454 for (i
=0; i
<8; i
++) /* 32 MB total */
456 unsigned size
= 4 * 1024 * 1024; /* 4 MB */
457 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx,0x%0x",
458 0x88000000 + (i
* size
),
460 0xA8000000 + (i
* size
));
464 else if (board
!= NULL
465 && (strcmp(board
, BOARD_JMR3904
) == 0 ||
466 strcmp(board
, BOARD_JMR3904_PAL
) == 0 ||
467 strcmp(board
, BOARD_JMR3904_DEBUG
) == 0))
469 /* match VIRTUAL memory layout of JMR-TX3904 board */
472 /* --- disable monitor unless forced on by user --- */
474 if (! firmware_option_p
)
476 idt_monitor_base
= 0;
477 pmon_monitor_base
= 0;
478 lsipmon_monitor_base
= 0;
481 /* --- environment --- */
483 STATE_ENVIRONMENT (sd
) = OPERATING_ENVIRONMENT
;
487 /* ROM: 0x9FC0_0000 - 0x9FFF_FFFF and 0xBFC0_0000 - 0xBFFF_FFFF */
488 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx,0x%0x",
490 4 * 1024 * 1024, /* 4 MB */
493 /* SRAM: 0x8000_0000 - 0x803F_FFFF and 0xA000_0000 - 0xA03F_FFFF */
494 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx,0x%0x",
496 4 * 1024 * 1024, /* 4 MB */
499 /* DRAM: 0x8800_0000 - 0x89FF_FFFF and 0xA800_0000 - 0xA9FF_FFFF */
500 for (i
=0; i
<8; i
++) /* 32 MB total */
502 unsigned size
= 4 * 1024 * 1024; /* 4 MB */
503 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx,0x%0x",
504 0x88000000 + (i
* size
),
506 0xA8000000 + (i
* size
));
509 /* Dummy memory regions for unsimulated devices - sorted by address */
511 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xB1000000, 0x400); /* ISA I/O */
512 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xB2100000, 0x004); /* ISA ctl */
513 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xB2500000, 0x004); /* LED/switch */
514 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xB2700000, 0x004); /* RTC */
515 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xB3C00000, 0x004); /* RTC */
516 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xFFFF8000, 0x900); /* DRAMC */
517 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xFFFF9000, 0x200); /* EBIF */
518 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xFFFFE000, 0x01c); /* EBIF */
519 sim_do_commandf (sd
, "memory alias 0x%lx@1,0x%lx", 0xFFFFF500, 0x300); /* PIO */
522 /* --- simulated devices --- */
523 sim_hw_parse (sd
, "/tx3904irc@0xffffc000/reg 0xffffc000 0x20");
524 sim_hw_parse (sd
, "/tx3904cpu");
525 sim_hw_parse (sd
, "/tx3904tmr@0xfffff000/reg 0xfffff000 0x100");
526 sim_hw_parse (sd
, "/tx3904tmr@0xfffff100/reg 0xfffff100 0x100");
527 sim_hw_parse (sd
, "/tx3904tmr@0xfffff200/reg 0xfffff200 0x100");
528 sim_hw_parse (sd
, "/tx3904sio@0xfffff300/reg 0xfffff300 0x100");
530 /* FIXME: poking at dv-sockser internals, use tcp backend if
531 --sockser_addr option was given.*/
532 extern char* sockser_addr
;
533 if(sockser_addr
== NULL
)
534 sim_hw_parse (sd
, "/tx3904sio@0xfffff300/backend stdio");
536 sim_hw_parse (sd
, "/tx3904sio@0xfffff300/backend tcp");
538 sim_hw_parse (sd
, "/tx3904sio@0xfffff400/reg 0xfffff400 0x100");
539 sim_hw_parse (sd
, "/tx3904sio@0xfffff400/backend stdio");
541 /* -- device connections --- */
542 sim_hw_parse (sd
, "/tx3904irc > ip level /tx3904cpu");
543 sim_hw_parse (sd
, "/tx3904tmr@0xfffff000 > int tmr0 /tx3904irc");
544 sim_hw_parse (sd
, "/tx3904tmr@0xfffff100 > int tmr1 /tx3904irc");
545 sim_hw_parse (sd
, "/tx3904tmr@0xfffff200 > int tmr2 /tx3904irc");
546 sim_hw_parse (sd
, "/tx3904sio@0xfffff300 > int sio0 /tx3904irc");
547 sim_hw_parse (sd
, "/tx3904sio@0xfffff400 > int sio1 /tx3904irc");
549 /* add PAL timer & I/O module */
550 if(! strcmp(board
, BOARD_JMR3904_PAL
))
553 sim_hw_parse (sd
, "/pal@0xffff0000");
554 sim_hw_parse (sd
, "/pal@0xffff0000/reg 0xffff0000 64");
556 /* wire up interrupt ports to irc */
557 sim_hw_parse (sd
, "/pal@0x31000000 > countdown tmr0 /tx3904irc");
558 sim_hw_parse (sd
, "/pal@0x31000000 > timer tmr1 /tx3904irc");
559 sim_hw_parse (sd
, "/pal@0x31000000 > int int0 /tx3904irc");
562 if(! strcmp(board
, BOARD_JMR3904_DEBUG
))
564 /* -- DEBUG: glue interrupt generators --- */
565 sim_hw_parse (sd
, "/glue@0xffff0000/reg 0xffff0000 0x50");
566 sim_hw_parse (sd
, "/glue@0xffff0000 > int0 int0 /tx3904irc");
567 sim_hw_parse (sd
, "/glue@0xffff0000 > int1 int1 /tx3904irc");
568 sim_hw_parse (sd
, "/glue@0xffff0000 > int2 int2 /tx3904irc");
569 sim_hw_parse (sd
, "/glue@0xffff0000 > int3 int3 /tx3904irc");
570 sim_hw_parse (sd
, "/glue@0xffff0000 > int4 int4 /tx3904irc");
571 sim_hw_parse (sd
, "/glue@0xffff0000 > int5 int5 /tx3904irc");
572 sim_hw_parse (sd
, "/glue@0xffff0000 > int6 int6 /tx3904irc");
573 sim_hw_parse (sd
, "/glue@0xffff0000 > int7 int7 /tx3904irc");
574 sim_hw_parse (sd
, "/glue@0xffff0000 > int8 dmac0 /tx3904irc");
575 sim_hw_parse (sd
, "/glue@0xffff0000 > int9 dmac1 /tx3904irc");
576 sim_hw_parse (sd
, "/glue@0xffff0000 > int10 dmac2 /tx3904irc");
577 sim_hw_parse (sd
, "/glue@0xffff0000 > int11 dmac3 /tx3904irc");
578 sim_hw_parse (sd
, "/glue@0xffff0000 > int12 sio0 /tx3904irc");
579 sim_hw_parse (sd
, "/glue@0xffff0000 > int13 sio1 /tx3904irc");
580 sim_hw_parse (sd
, "/glue@0xffff0000 > int14 tmr0 /tx3904irc");
581 sim_hw_parse (sd
, "/glue@0xffff0000 > int15 tmr1 /tx3904irc");
582 sim_hw_parse (sd
, "/glue@0xffff0000 > int16 tmr2 /tx3904irc");
583 sim_hw_parse (sd
, "/glue@0xffff0000 > int17 nmi /tx3904cpu");
591 /* check for/establish the a reference program image */
592 if (sim_analyze_program (sd
,
593 (STATE_PROG_ARGV (sd
) != NULL
594 ? *STATE_PROG_ARGV (sd
)
598 sim_module_uninstall (sd
);
602 /* Configure/verify the target byte order and other runtime
603 configuration options */
604 if (sim_config (sd
) != SIM_RC_OK
)
606 sim_module_uninstall (sd
);
610 if (sim_post_argv_init (sd
) != SIM_RC_OK
)
612 /* Uninstall the modules to avoid memory leaks,
613 file descriptor leaks, etc. */
614 sim_module_uninstall (sd
);
618 /* verify assumptions the simulator made about the host type system.
619 This macro does not return if there is a problem */
620 SIM_ASSERT (sizeof(int) == (4 * sizeof(char)));
621 SIM_ASSERT (sizeof(word64
) == (8 * sizeof(char)));
623 /* This is NASTY, in that we are assuming the size of specific
627 for (rn
= 0; (rn
< (LAST_EMBED_REGNUM
+ 1)); rn
++)
630 cpu
->register_widths
[rn
] = WITH_TARGET_WORD_BITSIZE
;
631 else if ((rn
>= FGR_BASE
) && (rn
< (FGR_BASE
+ NR_FGR
)))
632 cpu
->register_widths
[rn
] = WITH_TARGET_FLOATING_POINT_BITSIZE
;
633 else if ((rn
>= 33) && (rn
<= 37))
634 cpu
->register_widths
[rn
] = WITH_TARGET_WORD_BITSIZE
;
635 else if ((rn
== SRIDX
)
638 || ((rn
>= 72) && (rn
<= 89)))
639 cpu
->register_widths
[rn
] = 32;
641 cpu
->register_widths
[rn
] = 0;
648 if (STATE
& simTRACE
)
653 sim_io_eprintf (sd, "idt@%x pmon@%x lsipmon@%x\n",
656 lsipmon_monitor_base);
659 /* Write the monitor trap address handlers into the monitor (eeprom)
660 address space. This can only be done once the target endianness
661 has been determined. */
662 if (idt_monitor_base
!= 0)
665 unsigned idt_monitor_size
= 1 << 11;
667 /* the default monitor region */
668 sim_do_commandf (sd
, "memory region 0x%x,0x%x",
669 idt_monitor_base
, idt_monitor_size
);
671 /* Entry into the IDT monitor is via fixed address vectors, and
672 not using machine instructions. To avoid clashing with use of
673 the MIPS TRAP system, we place our own (simulator specific)
674 "undefined" instructions into the relevant vector slots. */
675 for (loop
= 0; (loop
< idt_monitor_size
); loop
+= 4)
677 address_word vaddr
= (idt_monitor_base
+ loop
);
678 unsigned32 insn
= (RSVD_INSTRUCTION
|
679 (((loop
>> 2) & RSVD_INSTRUCTION_ARG_MASK
)
680 << RSVD_INSTRUCTION_ARG_SHIFT
));
682 sim_write (sd
, vaddr
, (char *)&insn
, sizeof (insn
));
686 if ((pmon_monitor_base
!= 0) || (lsipmon_monitor_base
!= 0))
688 /* The PMON monitor uses the same address space, but rather than
689 branching into it the address of a routine is loaded. We can
690 cheat for the moment, and direct the PMON routine to IDT style
691 instructions within the monitor space. This relies on the IDT
692 monitor not using the locations from 0xBFC00500 onwards as its
695 for (loop
= 0; (loop
< 24); loop
++)
697 unsigned32 value
= ((0x500 - 8) / 8); /* default UNDEFINED reason code */
713 value
= ((0x500 - 16) / 8); /* not an IDT reason code */
715 case 8: /* cliexit */
718 case 11: /* flush_cache */
723 SIM_ASSERT (idt_monitor_base
!= 0);
724 value
= ((unsigned int) idt_monitor_base
+ (value
* 8));
727 if (pmon_monitor_base
!= 0)
729 address_word vaddr
= (pmon_monitor_base
+ (loop
* 4));
730 sim_write (sd
, vaddr
, (char *)&value
, sizeof (value
));
733 if (lsipmon_monitor_base
!= 0)
735 address_word vaddr
= (lsipmon_monitor_base
+ (loop
* 4));
736 sim_write (sd
, vaddr
, (char *)&value
, sizeof (value
));
740 /* Write an abort sequence into the TRAP (common) exception vector
741 addresses. This is to catch code executing a TRAP (et.al.)
742 instruction without installing a trap handler. */
743 if ((idt_monitor_base
!= 0) ||
744 (pmon_monitor_base
!= 0) ||
745 (lsipmon_monitor_base
!= 0))
747 unsigned32 halt
[2] = { 0x2404002f /* addiu r4, r0, 47 */,
748 HALT_INSTRUCTION
/* BREAK */ };
751 sim_write (sd
, 0x80000000, (char *) halt
, sizeof (halt
));
752 sim_write (sd
, 0x80000180, (char *) halt
, sizeof (halt
));
753 sim_write (sd
, 0x80000200, (char *) halt
, sizeof (halt
));
754 /* XXX: Write here unconditionally? */
755 sim_write (sd
, 0xBFC00200, (char *) halt
, sizeof (halt
));
756 sim_write (sd
, 0xBFC00380, (char *) halt
, sizeof (halt
));
757 sim_write (sd
, 0xBFC00400, (char *) halt
, sizeof (halt
));
771 tracefh
= fopen(tracefile
,"wb+");
774 sim_io_eprintf(sd
,"Failed to create file \"%s\", writing trace information to stderr.\n",tracefile
);
780 /* Return name of an insn, used by insn profiling. */
782 get_insn_name (sim_cpu
*cpu
, int i
)
784 return itable
[i
].name
;
788 sim_close (sd
, quitting
)
793 printf("DBG: sim_close: entered (quitting = %d)\n",quitting
);
797 /* "quitting" is non-zero if we cannot hang on errors */
799 /* shut down modules */
800 sim_module_uninstall (sd
);
802 /* Ensure that any resources allocated through the callback
803 mechanism are released: */
804 sim_io_shutdown (sd
);
807 if (tracefh
!= NULL
&& tracefh
!= stderr
)
812 /* FIXME - free SD */
819 sim_write (sd
,addr
,buffer
,size
)
822 unsigned char *buffer
;
826 sim_cpu
*cpu
= STATE_CPU (sd
, 0); /* FIXME */
828 /* Return the number of bytes written, or zero if error. */
830 sim_io_printf(sd
,"sim_write(0x%s,buffer,%d);\n",pr_addr(addr
),size
);
833 /* We use raw read and write routines, since we do not want to count
834 the GDB memory accesses in our statistics gathering. */
836 for (index
= 0; index
< size
; index
++)
838 address_word vaddr
= (address_word
)addr
+ index
;
841 if (!address_translation (SD
, CPU
, NULL_CIA
, vaddr
, isDATA
, isSTORE
, &paddr
, &cca
, isRAW
))
843 if (sim_core_write_buffer (SD
, CPU
, read_map
, buffer
+ index
, paddr
, 1) != 1)
851 sim_read (sd
,addr
,buffer
,size
)
854 unsigned char *buffer
;
858 sim_cpu
*cpu
= STATE_CPU (sd
, 0); /* FIXME */
860 /* Return the number of bytes read, or zero if error. */
862 sim_io_printf(sd
,"sim_read(0x%s,buffer,%d);\n",pr_addr(addr
),size
);
865 for (index
= 0; (index
< size
); index
++)
867 address_word vaddr
= (address_word
)addr
+ index
;
870 if (!address_translation (SD
, CPU
, NULL_CIA
, vaddr
, isDATA
, isLOAD
, &paddr
, &cca
, isRAW
))
872 if (sim_core_read_buffer (SD
, CPU
, read_map
, buffer
+ index
, paddr
, 1) != 1)
880 sim_store_register (sd
,rn
,memory
,length
)
883 unsigned char *memory
;
886 sim_cpu
*cpu
= STATE_CPU (sd
, 0); /* FIXME */
887 /* NOTE: gdb (the client) stores registers in target byte order
888 while the simulator uses host byte order */
890 sim_io_printf(sd
,"sim_store_register(%d,*memory=0x%s);\n",rn
,pr_addr(*((SIM_ADDR
*)memory
)));
893 /* Unfortunately this suffers from the same problem as the register
894 numbering one. We need to know what the width of each logical
895 register number is for the architecture being simulated. */
897 if (cpu
->register_widths
[rn
] == 0)
899 sim_io_eprintf(sd
,"Invalid register width for %d (register store ignored)\n",rn
);
905 if (rn
>= FGR_BASE
&& rn
< FGR_BASE
+ NR_FGR
)
907 cpu
->fpr_state
[rn
- FGR_BASE
] = fmt_uninterpreted
;
908 if (cpu
->register_widths
[rn
] == 32)
912 cpu
->fgr
[rn
- FGR_BASE
] =
913 (unsigned32
) T2H_8 (*(unsigned64
*)memory
);
918 cpu
->fgr
[rn
- FGR_BASE
] = T2H_4 (*(unsigned32
*)memory
);
926 cpu
->fgr
[rn
- FGR_BASE
] = T2H_8 (*(unsigned64
*)memory
);
931 cpu
->fgr
[rn
- FGR_BASE
] = T2H_4 (*(unsigned32
*)memory
);
937 if (cpu
->register_widths
[rn
] == 32)
942 (unsigned32
) T2H_8 (*(unsigned64
*)memory
);
947 cpu
->registers
[rn
] = T2H_4 (*(unsigned32
*)memory
);
955 cpu
->registers
[rn
] = T2H_8 (*(unsigned64
*)memory
);
960 cpu
->registers
[rn
] = (signed32
) T2H_4(*(unsigned32
*)memory
);
969 sim_fetch_register (sd
,rn
,memory
,length
)
972 unsigned char *memory
;
975 sim_cpu
*cpu
= STATE_CPU (sd
, 0); /* FIXME */
976 /* NOTE: gdb (the client) stores registers in target byte order
977 while the simulator uses host byte order */
979 #if 0 /* FIXME: doesn't compile */
980 sim_io_printf(sd
,"sim_fetch_register(%d=0x%s,mem) : place simulator registers into memory\n",rn
,pr_addr(registers
[rn
]));
984 if (cpu
->register_widths
[rn
] == 0)
986 sim_io_eprintf (sd
, "Invalid register width for %d (register fetch ignored)\n",rn
);
992 /* Any floating point register */
993 if (rn
>= FGR_BASE
&& rn
< FGR_BASE
+ NR_FGR
)
995 if (cpu
->register_widths
[rn
] == 32)
999 *(unsigned64
*)memory
=
1000 H2T_8 ((unsigned32
) (cpu
->fgr
[rn
- FGR_BASE
]));
1005 *(unsigned32
*)memory
= H2T_4 (cpu
->fgr
[rn
- FGR_BASE
]);
1013 *(unsigned64
*)memory
= H2T_8 (cpu
->fgr
[rn
- FGR_BASE
]);
1018 *(unsigned32
*)memory
= H2T_4 ((unsigned32
)(cpu
->fgr
[rn
- FGR_BASE
]));
1024 if (cpu
->register_widths
[rn
] == 32)
1028 *(unsigned64
*)memory
=
1029 H2T_8 ((unsigned32
) (cpu
->registers
[rn
]));
1034 *(unsigned32
*)memory
= H2T_4 ((unsigned32
)(cpu
->registers
[rn
]));
1042 *(unsigned64
*)memory
=
1043 H2T_8 ((unsigned64
) (cpu
->registers
[rn
]));
1048 *(unsigned32
*)memory
= H2T_4 ((unsigned32
)(cpu
->registers
[rn
]));
1058 sim_create_inferior (sd
, abfd
, argv
,env
)
1066 #if 0 /* FIXME: doesn't compile */
1067 printf("DBG: sim_create_inferior entered: start_address = 0x%s\n",
1076 /* override PC value set by ColdReset () */
1078 for (cpu_nr
= 0; cpu_nr
< sim_engine_nr_cpus (sd
); cpu_nr
++)
1080 sim_cpu
*cpu
= STATE_CPU (sd
, cpu_nr
);
1081 CIA_SET (cpu
, (unsigned64
) bfd_get_start_address (abfd
));
1085 #if 0 /* def DEBUG */
1088 /* We should really place the argv slot values into the argument
1089 registers, and onto the stack as required. However, this
1090 assumes that we have a stack defined, which is not
1091 necessarily true at the moment. */
1093 sim_io_printf(sd
,"sim_create_inferior() : passed arguments ignored\n");
1094 for (cptr
= argv
; (cptr
&& *cptr
); cptr
++)
1095 printf("DBG: arg \"%s\"\n",*cptr
);
1103 sim_do_command (sd
,cmd
)
1107 if (sim_args_command (sd
, cmd
) != SIM_RC_OK
)
1108 sim_io_printf (sd
, "Error: \"%s\" is not a valid MIPS simulator command.\n",
1112 /*---------------------------------------------------------------------------*/
1113 /*-- Private simulator support interface ------------------------------------*/
1114 /*---------------------------------------------------------------------------*/
1116 /* Read a null terminated string from memory, return in a buffer */
1118 fetch_str (SIM_DESC sd
,
1124 while (sim_read (sd
, addr
+ nr
, &null
, 1) == 1 && null
!= 0)
1126 buf
= NZALLOC (char, nr
+ 1);
1127 sim_read (sd
, addr
, buf
, nr
);
1132 /* Implements the "sim firmware" command:
1133 sim firmware NAME[@ADDRESS] --- emulate ROM monitor named NAME.
1134 NAME can be idt, pmon, or lsipmon. If omitted, ADDRESS
1135 defaults to the normal address for that monitor.
1136 sim firmware none --- don't emulate any ROM monitor. Useful
1137 if you need a clean address space. */
1139 sim_firmware_command (SIM_DESC sd
, char *arg
)
1141 int address_present
= 0;
1144 /* Signal occurrence of this option. */
1145 firmware_option_p
= 1;
1147 /* Parse out the address, if present. */
1149 char *p
= strchr (arg
, '@');
1153 address_present
= 1;
1154 p
++; /* skip over @ */
1156 address
= strtoul (p
, &q
, 0);
1159 sim_io_printf (sd
, "Invalid address given to the"
1160 "`sim firmware NAME@ADDRESS' command: %s\n",
1167 address_present
= 0;
1168 address
= -1; /* Dummy value. */
1172 if (! strncmp (arg
, "idt", 3))
1174 idt_monitor_base
= address_present
? address
: 0xBFC00000;
1175 pmon_monitor_base
= 0;
1176 lsipmon_monitor_base
= 0;
1178 else if (! strncmp (arg
, "pmon", 4))
1180 /* pmon uses indirect calls. Hook into implied idt. */
1181 pmon_monitor_base
= address_present
? address
: 0xBFC00500;
1182 idt_monitor_base
= pmon_monitor_base
- 0x500;
1183 lsipmon_monitor_base
= 0;
1185 else if (! strncmp (arg
, "lsipmon", 7))
1187 /* lsipmon uses indirect calls. Hook into implied idt. */
1188 pmon_monitor_base
= 0;
1189 lsipmon_monitor_base
= address_present
? address
: 0xBFC00200;
1190 idt_monitor_base
= lsipmon_monitor_base
- 0x200;
1192 else if (! strncmp (arg
, "none", 4))
1194 if (address_present
)
1197 "The `sim firmware none' command does "
1198 "not take an `ADDRESS' argument.\n");
1201 idt_monitor_base
= 0;
1202 pmon_monitor_base
= 0;
1203 lsipmon_monitor_base
= 0;
1207 sim_io_printf (sd
, "\
1208 Unrecognized name given to the `sim firmware NAME' command: %s\n\
1209 Recognized firmware names are: `idt', `pmon', `lsipmon', and `none'.\n",
1219 /* Simple monitor interface (currently setup for the IDT and PMON monitors) */
1221 sim_monitor (SIM_DESC sd
,
1224 unsigned int reason
)
1227 printf("DBG: sim_monitor: entered (reason = %d)\n",reason
);
1230 /* The IDT monitor actually allows two instructions per vector
1231 slot. However, the simulator currently causes a trap on each
1232 individual instruction. We cheat, and lose the bottom bit. */
1235 /* The following callback functions are available, however the
1236 monitor we are simulating does not make use of them: get_errno,
1237 isatty, lseek, rename, system, time and unlink */
1241 case 6: /* int open(char *path,int flags) */
1243 char *path
= fetch_str (sd
, A0
);
1244 V0
= sim_io_open (sd
, path
, (int)A1
);
1249 case 7: /* int read(int file,char *ptr,int len) */
1253 char *buf
= zalloc (nr
);
1254 V0
= sim_io_read (sd
, fd
, buf
, nr
);
1255 sim_write (sd
, A1
, buf
, nr
);
1260 case 8: /* int write(int file,char *ptr,int len) */
1264 char *buf
= zalloc (nr
);
1265 sim_read (sd
, A1
, buf
, nr
);
1266 V0
= sim_io_write (sd
, fd
, buf
, nr
);
1268 sim_io_flush_stdout (sd
);
1270 sim_io_flush_stderr (sd
);
1275 case 10: /* int close(int file) */
1277 V0
= sim_io_close (sd
, (int)A0
);
1281 case 2: /* Densan monitor: char inbyte(int waitflag) */
1283 if (A0
== 0) /* waitflag == NOWAIT */
1284 V0
= (unsigned_word
)-1;
1286 /* Drop through to case 11 */
1288 case 11: /* char inbyte(void) */
1291 /* ensure that all output has gone... */
1292 sim_io_flush_stdout (sd
);
1293 if (sim_io_read_stdin (sd
, &tmp
, sizeof(char)) != sizeof(char))
1295 sim_io_error(sd
,"Invalid return from character read");
1296 V0
= (unsigned_word
)-1;
1299 V0
= (unsigned_word
)tmp
;
1303 case 3: /* Densan monitor: void co(char chr) */
1304 case 12: /* void outbyte(char chr) : write a byte to "stdout" */
1306 char tmp
= (char)(A0
& 0xFF);
1307 sim_io_write_stdout (sd
, &tmp
, sizeof(char));
1311 case 17: /* void _exit() */
1313 sim_io_eprintf (sd
, "sim_monitor(17): _exit(int reason) to be coded\n");
1314 sim_engine_halt (SD
, CPU
, NULL
, NULL_CIA
, sim_exited
,
1315 (unsigned int)(A0
& 0xFFFFFFFF));
1319 case 28: /* PMON flush_cache */
1322 case 55: /* void get_mem_info(unsigned int *ptr) */
1323 /* in: A0 = pointer to three word memory location */
1324 /* out: [A0 + 0] = size */
1325 /* [A0 + 4] = instruction cache size */
1326 /* [A0 + 8] = data cache size */
1329 unsigned_4 zero
= 0;
1330 address_word mem_size
;
1331 sim_memopt
*entry
, *match
= NULL
;
1333 /* Search for memory region mapped to KSEG0 or KSEG1. */
1334 for (entry
= STATE_MEMOPT (sd
);
1336 entry
= entry
->next
)
1338 if ((entry
->addr
== K0BASE
|| entry
->addr
== K1BASE
)
1339 && (!match
|| entry
->level
< match
->level
))
1344 for (alias
= entry
->alias
;
1346 alias
= alias
->next
)
1347 if ((alias
->addr
== K0BASE
|| alias
->addr
== K1BASE
)
1348 && (!match
|| entry
->level
< match
->level
))
1353 /* Get region size, limit to KSEG1 size (512MB). */
1354 SIM_ASSERT (match
!= NULL
);
1355 mem_size
= (match
->modulo
!= 0
1356 ? match
->modulo
: match
->nr_bytes
);
1357 if (mem_size
> K1SIZE
)
1362 sim_write (sd
, A0
+ 0, (char *)&value
, 4);
1363 sim_write (sd
, A0
+ 4, (char *)&zero
, 4);
1364 sim_write (sd
, A0
+ 8, (char *)&zero
, 4);
1365 /* sim_io_eprintf (sd, "sim: get_mem_info() deprecated\n"); */
1369 case 158: /* PMON printf */
1370 /* in: A0 = pointer to format string */
1371 /* A1 = optional argument 1 */
1372 /* A2 = optional argument 2 */
1373 /* A3 = optional argument 3 */
1375 /* The following is based on the PMON printf source */
1377 address_word s
= A0
;
1379 signed_word
*ap
= &A1
; /* 1st argument */
1380 /* This isn't the quickest way, since we call the host print
1381 routine for every character almost. But it does avoid
1382 having to allocate and manage a temporary string buffer. */
1383 /* TODO: Include check that we only use three arguments (A1,
1385 while (sim_read (sd
, s
++, &c
, 1) && c
!= '\0')
1390 enum {FMT_RJUST
, FMT_LJUST
, FMT_RJUST0
, FMT_CENTER
} fmt
= FMT_RJUST
;
1391 int width
= 0, trunc
= 0, haddot
= 0, longlong
= 0;
1392 while (sim_read (sd
, s
++, &c
, 1) && c
!= '\0')
1394 if (strchr ("dobxXulscefg%", c
))
1409 else if (c
>= '1' && c
<= '9')
1413 while (sim_read (sd
, s
++, &c
, 1) == 1 && isdigit (c
))
1416 n
= (unsigned int)strtol(tmp
,NULL
,10);
1429 sim_io_printf (sd
, "%%");
1434 address_word p
= *ap
++;
1436 while (sim_read (sd
, p
++, &ch
, 1) == 1 && ch
!= '\0')
1437 sim_io_printf(sd
, "%c", ch
);
1440 sim_io_printf(sd
,"(null)");
1443 sim_io_printf (sd
, "%c", (int)*ap
++);
1448 sim_read (sd
, s
++, &c
, 1);
1452 sim_read (sd
, s
++, &c
, 1);
1455 if (strchr ("dobxXu", c
))
1457 word64 lv
= (word64
) *ap
++;
1459 sim_io_printf(sd
,"<binary not supported>");
1462 sprintf (tmp
, "%%%s%c", longlong
? "ll" : "", c
);
1464 sim_io_printf(sd
, tmp
, lv
);
1466 sim_io_printf(sd
, tmp
, (int)lv
);
1469 else if (strchr ("eEfgG", c
))
1471 double dbl
= *(double*)(ap
++);
1472 sprintf (tmp
, "%%%d.%d%c", width
, trunc
, c
);
1473 sim_io_printf (sd
, tmp
, dbl
);
1479 sim_io_printf(sd
, "%c", c
);
1485 /* Unknown reason. */
1491 /* Store a word into memory. */
1494 store_word (SIM_DESC sd
,
1503 if ((vaddr
& 3) != 0)
1504 SignalExceptionAddressStore ();
1507 if (AddressTranslation (vaddr
, isDATA
, isSTORE
, &paddr
, &uncached
,
1510 const uword64 mask
= 7;
1514 paddr
= (paddr
& ~mask
) | ((paddr
& mask
) ^ (ReverseEndian
<< 2));
1515 byte
= (vaddr
& mask
) ^ (BigEndianCPU
<< 2);
1516 memval
= ((uword64
) val
) << (8 * byte
);
1517 StoreMemory (uncached
, AccessLength_WORD
, memval
, 0, paddr
, vaddr
,
1523 /* Load a word from memory. */
1526 load_word (SIM_DESC sd
,
1531 if ((vaddr
& 3) != 0)
1533 SIM_CORE_SIGNAL (SD
, cpu
, cia
, read_map
, AccessLength_WORD
+1, vaddr
, read_transfer
, sim_core_unaligned_signal
);
1540 if (AddressTranslation (vaddr
, isDATA
, isLOAD
, &paddr
, &uncached
,
1543 const uword64 mask
= 0x7;
1544 const unsigned int reverse
= ReverseEndian
? 1 : 0;
1545 const unsigned int bigend
= BigEndianCPU
? 1 : 0;
1549 paddr
= (paddr
& ~mask
) | ((paddr
& mask
) ^ (reverse
<< 2));
1550 LoadMemory (&memval
,NULL
,uncached
, AccessLength_WORD
, paddr
, vaddr
,
1552 byte
= (vaddr
& mask
) ^ (bigend
<< 2);
1553 return EXTEND32 (memval
>> (8 * byte
));
1560 /* Simulate the mips16 entry and exit pseudo-instructions. These
1561 would normally be handled by the reserved instruction exception
1562 code, but for ease of simulation we just handle them directly. */
1565 mips16_entry (SIM_DESC sd
,
1570 int aregs
, sregs
, rreg
;
1573 printf("DBG: mips16_entry: entered (insn = 0x%08X)\n",insn
);
1576 aregs
= (insn
& 0x700) >> 8;
1577 sregs
= (insn
& 0x0c0) >> 6;
1578 rreg
= (insn
& 0x020) >> 5;
1580 /* This should be checked by the caller. */
1589 /* This is the entry pseudo-instruction. */
1591 for (i
= 0; i
< aregs
; i
++)
1592 store_word (SD
, CPU
, cia
, (uword64
) (SP
+ 4 * i
), GPR
[i
+ 4]);
1600 store_word (SD
, CPU
, cia
, (uword64
) tsp
, RA
);
1603 for (i
= 0; i
< sregs
; i
++)
1606 store_word (SD
, CPU
, cia
, (uword64
) tsp
, GPR
[16 + i
]);
1614 /* This is the exit pseudo-instruction. */
1621 RA
= load_word (SD
, CPU
, cia
, (uword64
) tsp
);
1624 for (i
= 0; i
< sregs
; i
++)
1627 GPR
[i
+ 16] = load_word (SD
, CPU
, cia
, (uword64
) tsp
);
1632 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
)
1636 FGR
[0] = WORD64LO (GPR
[4]);
1637 FPR_STATE
[0] = fmt_uninterpreted
;
1639 else if (aregs
== 6)
1641 FGR
[0] = WORD64LO (GPR
[5]);
1642 FGR
[1] = WORD64LO (GPR
[4]);
1643 FPR_STATE
[0] = fmt_uninterpreted
;
1644 FPR_STATE
[1] = fmt_uninterpreted
;
1653 /*-- trace support ----------------------------------------------------------*/
1655 /* The TRACE support is provided (if required) in the memory accessing
1656 routines. Since we are also providing the architecture specific
1657 features, the architecture simulation code can also deal with
1658 notifying the TRACE world of cache flushes, etc. Similarly we do
1659 not need to provide profiling support in the simulator engine,
1660 since we can sample in the instruction fetch control loop. By
1661 defining the TRACE manifest, we add tracing as a run-time
1665 /* Tracing by default produces "din" format (as required by
1666 dineroIII). Each line of such a trace file *MUST* have a din label
1667 and address field. The rest of the line is ignored, so comments can
1668 be included if desired. The first field is the label which must be
1669 one of the following values:
1674 3 escape record (treated as unknown access type)
1675 4 escape record (causes cache flush)
1677 The address field is a 32bit (lower-case) hexadecimal address
1678 value. The address should *NOT* be preceded by "0x".
1680 The size of the memory transfer is not important when dealing with
1681 cache lines (as long as no more than a cache line can be
1682 transferred in a single operation :-), however more information
1683 could be given following the dineroIII requirement to allow more
1684 complete memory and cache simulators to provide better
1685 results. i.e. the University of Pisa has a cache simulator that can
1686 also take bus size and speed as (variable) inputs to calculate
1687 complete system performance (a much more useful ability when trying
1688 to construct an end product, rather than a processor). They
1689 currently have an ARM version of their tool called ChARM. */
1693 dotrace (SIM_DESC sd
,
1701 if (STATE
& simTRACE
) {
1703 fprintf(tracefh
,"%d %s ; width %d ; ",
1707 va_start(ap
,comment
);
1708 vfprintf(tracefh
,comment
,ap
);
1710 fprintf(tracefh
,"\n");
1712 /* NOTE: Since the "din" format will only accept 32bit addresses, and
1713 we may be generating 64bit ones, we should put the hi-32bits of the
1714 address into the comment field. */
1716 /* TODO: Provide a buffer for the trace lines. We can then avoid
1717 performing writes until the buffer is filled, or the file is
1720 /* NOTE: We could consider adding a comment field to the "din" file
1721 produced using type 3 markers (unknown access). This would then
1722 allow information about the program that the "din" is for, and
1723 the MIPs world that was being simulated, to be placed into the
1730 /*---------------------------------------------------------------------------*/
1731 /*-- simulator engine -------------------------------------------------------*/
1732 /*---------------------------------------------------------------------------*/
1735 ColdReset (SIM_DESC sd
)
1738 for (cpu_nr
= 0; cpu_nr
< sim_engine_nr_cpus (sd
); cpu_nr
++)
1740 sim_cpu
*cpu
= STATE_CPU (sd
, cpu_nr
);
1741 /* RESET: Fixed PC address: */
1742 PC
= (unsigned_word
) UNSIGNED64 (0xFFFFFFFFBFC00000);
1743 /* The reset vector address is in the unmapped, uncached memory space. */
1745 SR
&= ~(status_SR
| status_TS
| status_RP
);
1746 SR
|= (status_ERL
| status_BEV
);
1748 /* Cheat and allow access to the complete register set immediately */
1749 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
1750 && WITH_TARGET_WORD_BITSIZE
== 64)
1751 SR
|= status_FR
; /* 64bit registers */
1753 /* Ensure that any instructions with pending register updates are
1755 PENDING_INVALIDATE();
1757 /* Initialise the FPU registers to the unknown state */
1758 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
)
1761 for (rn
= 0; (rn
< 32); rn
++)
1762 FPR_STATE
[rn
] = fmt_uninterpreted
;
1765 /* Initialise the Config0 register. */
1766 C0_CONFIG
= 0x80000000 /* Config1 present */
1767 | 2; /* KSEG0 uncached */
1768 if (WITH_TARGET_WORD_BITSIZE
== 64)
1770 /* FIXME Currently mips/sim-main.c:address_translation()
1771 truncates all addresses to 32-bits. */
1772 if (0 && WITH_TARGET_ADDRESS_BITSIZE
== 64)
1773 C0_CONFIG
|= (2 << 13); /* MIPS64, 64-bit addresses */
1775 C0_CONFIG
|= (1 << 13); /* MIPS64, 32-bit addresses */
1778 C0_CONFIG
|= 0x00008000; /* Big Endian */
1785 /* Description from page A-26 of the "MIPS IV Instruction Set" manual (revision 3.1) */
1786 /* Signal an exception condition. This will result in an exception
1787 that aborts the instruction. The instruction operation pseudocode
1788 will never see a return from this function call. */
1791 signal_exception (SIM_DESC sd
,
1799 sim_io_printf(sd
,"DBG: SignalException(%d) PC = 0x%s\n",exception
,pr_addr(cia
));
1802 /* Ensure that any active atomic read/modify/write operation will fail: */
1805 /* Save registers before interrupt dispatching */
1806 #ifdef SIM_CPU_EXCEPTION_TRIGGER
1807 SIM_CPU_EXCEPTION_TRIGGER(sd
, cpu
, cia
);
1810 switch (exception
) {
1812 case DebugBreakPoint
:
1813 if (! (Debug
& Debug_DM
))
1819 Debug
|= Debug_DBD
; /* signaled from within in delay slot */
1820 DEPC
= cia
- 4; /* reference the branch instruction */
1824 Debug
&= ~Debug_DBD
; /* not signaled from within a delay slot */
1828 Debug
|= Debug_DM
; /* in debugging mode */
1829 Debug
|= Debug_DBp
; /* raising a DBp exception */
1831 sim_engine_restart (SD
, CPU
, NULL
, NULL_CIA
);
1835 case ReservedInstruction
:
1838 unsigned int instruction
;
1839 va_start(ap
,exception
);
1840 instruction
= va_arg(ap
,unsigned int);
1842 /* Provide simple monitor support using ReservedInstruction
1843 exceptions. The following code simulates the fixed vector
1844 entry points into the IDT monitor by causing a simulator
1845 trap, performing the monitor operation, and returning to
1846 the address held in the $ra register (standard PCS return
1847 address). This means we only need to pre-load the vector
1848 space with suitable instruction values. For systems were
1849 actual trap instructions are used, we would not need to
1850 perform this magic. */
1851 if ((instruction
& RSVD_INSTRUCTION_MASK
) == RSVD_INSTRUCTION
)
1853 int reason
= (instruction
>> RSVD_INSTRUCTION_ARG_SHIFT
) & RSVD_INSTRUCTION_ARG_MASK
;
1854 if (!sim_monitor (SD
, CPU
, cia
, reason
))
1855 sim_io_error (sd
, "sim_monitor: unhandled reason = %d, pc = 0x%s\n", reason
, pr_addr (cia
));
1857 /* NOTE: This assumes that a branch-and-link style
1858 instruction was used to enter the vector (which is the
1859 case with the current IDT monitor). */
1860 sim_engine_restart (SD
, CPU
, NULL
, RA
);
1862 /* Look for the mips16 entry and exit instructions, and
1863 simulate a handler for them. */
1864 else if ((cia
& 1) != 0
1865 && (instruction
& 0xf81f) == 0xe809
1866 && (instruction
& 0x0c0) != 0x0c0)
1868 mips16_entry (SD
, CPU
, cia
, instruction
);
1869 sim_engine_restart (sd
, NULL
, NULL
, NULL_CIA
);
1871 /* else fall through to normal exception processing */
1872 sim_io_eprintf(sd
,"ReservedInstruction at PC = 0x%s\n", pr_addr (cia
));
1876 /* Store exception code into current exception id variable (used
1879 /* TODO: If not simulating exceptions then stop the simulator
1880 execution. At the moment we always stop the simulation. */
1882 #ifdef SUBTARGET_R3900
1883 /* update interrupt-related registers */
1885 /* insert exception code in bits 6:2 */
1886 CAUSE
= LSMASKED32(CAUSE
, 31, 7) | LSINSERTED32(exception
, 6, 2);
1887 /* shift IE/KU history bits left */
1888 SR
= LSMASKED32(SR
, 31, 4) | LSINSERTED32(LSEXTRACTED32(SR
, 3, 0), 5, 2);
1890 if (STATE
& simDELAYSLOT
)
1892 STATE
&= ~simDELAYSLOT
;
1894 EPC
= (cia
- 4); /* reference the branch instruction */
1899 if (SR
& status_BEV
)
1900 PC
= (signed)0xBFC00000 + 0x180;
1902 PC
= (signed)0x80000000 + 0x080;
1904 /* See figure 5-17 for an outline of the code below */
1905 if (! (SR
& status_EXL
))
1907 CAUSE
= (exception
<< 2);
1908 if (STATE
& simDELAYSLOT
)
1910 STATE
&= ~simDELAYSLOT
;
1912 EPC
= (cia
- 4); /* reference the branch instruction */
1916 /* FIXME: TLB et.al. */
1917 /* vector = 0x180; */
1921 CAUSE
= (exception
<< 2);
1922 /* vector = 0x180; */
1925 /* Store exception code into current exception id variable (used
1928 if (SR
& status_BEV
)
1929 PC
= (signed)0xBFC00200 + 0x180;
1931 PC
= (signed)0x80000000 + 0x180;
1934 switch ((CAUSE
>> 2) & 0x1F)
1937 /* Interrupts arrive during event processing, no need to
1943 #ifdef SUBTARGET_3900
1944 /* Exception vector: BEV=0 BFC00000 / BEF=1 BFC00000 */
1945 PC
= (signed)0xBFC00000;
1946 #endif /* SUBTARGET_3900 */
1949 case TLBModification
:
1954 case InstructionFetch
:
1956 /* The following is so that the simulator will continue from the
1957 exception handler address. */
1958 sim_engine_halt (SD
, CPU
, NULL
, PC
,
1959 sim_stopped
, SIM_SIGBUS
);
1961 case ReservedInstruction
:
1962 case CoProcessorUnusable
:
1964 sim_engine_halt (SD
, CPU
, NULL
, PC
,
1965 sim_stopped
, SIM_SIGILL
);
1967 case IntegerOverflow
:
1969 sim_engine_halt (SD
, CPU
, NULL
, PC
,
1970 sim_stopped
, SIM_SIGFPE
);
1973 sim_engine_halt (SD
, CPU
, NULL
, PC
, sim_stopped
, SIM_SIGTRAP
);
1978 sim_engine_restart (SD
, CPU
, NULL
, PC
);
1983 sim_engine_halt (SD
, CPU
, NULL
, PC
,
1984 sim_stopped
, SIM_SIGTRAP
);
1986 default: /* Unknown internal exception */
1988 sim_engine_halt (SD
, CPU
, NULL
, PC
,
1989 sim_stopped
, SIM_SIGABRT
);
1993 case SimulatorFault
:
1997 va_start(ap
,exception
);
1998 msg
= va_arg(ap
,char *);
2000 sim_engine_abort (SD
, CPU
, NULL_CIA
,
2001 "FATAL: Simulator error \"%s\"\n",msg
);
2010 /* This function implements what the MIPS32 and MIPS64 ISAs define as
2011 "UNPREDICTABLE" behaviour.
2013 About UNPREDICTABLE behaviour they say: "UNPREDICTABLE results
2014 may vary from processor implementation to processor implementation,
2015 instruction to instruction, or as a function of time on the same
2016 implementation or instruction. Software can never depend on results
2017 that are UNPREDICTABLE. ..." (MIPS64 Architecture for Programmers
2018 Volume II, The MIPS64 Instruction Set. MIPS Document MD00087 revision
2021 For UNPREDICTABLE behaviour, we print a message, if possible print
2022 the offending instructions mips.igen instruction name (provided by
2023 the caller), and stop the simulator.
2025 XXX FIXME: eventually, stopping the simulator should be made conditional
2026 on a command-line option. */
2028 unpredictable_action(sim_cpu
*cpu
, address_word cia
)
2030 SIM_DESC sd
= CPU_STATE(cpu
);
2032 sim_io_eprintf(sd
, "UNPREDICTABLE: PC = 0x%s\n", pr_addr (cia
));
2033 sim_engine_halt (SD
, CPU
, NULL
, cia
, sim_stopped
, SIM_SIGABRT
);
2037 /*-- co-processor support routines ------------------------------------------*/
2040 CoProcPresent(unsigned int coproc_number
)
2042 /* Return TRUE if simulator provides a model for the given co-processor number */
2047 cop_lw (SIM_DESC sd
,
2052 unsigned int memword
)
2057 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
)
2060 printf("DBG: COP_LW: memword = 0x%08X (uword64)memword = 0x%s\n",memword
,pr_addr(memword
));
2062 StoreFPR(coproc_reg
,fmt_uninterpreted_32
,(uword64
)memword
);
2067 #if 0 /* this should be controlled by a configuration option */
2068 sim_io_printf(sd
,"COP_LW(%d,%d,0x%08X) at PC = 0x%s : TODO (architecture specific)\n",coproc_num
,coproc_reg
,memword
,pr_addr(cia
));
2077 cop_ld (SIM_DESC sd
,
2086 printf("DBG: COP_LD: coproc_num = %d, coproc_reg = %d, value = 0x%s : PC = 0x%s\n", coproc_num
, coproc_reg
, pr_uword64(memword
), pr_addr(cia
) );
2089 switch (coproc_num
) {
2091 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
)
2093 StoreFPR(coproc_reg
,fmt_uninterpreted_64
,memword
);
2098 #if 0 /* this message should be controlled by a configuration option */
2099 sim_io_printf(sd
,"COP_LD(%d,%d,0x%s) at PC = 0x%s : TODO (architecture specific)\n",coproc_num
,coproc_reg
,pr_addr(memword
),pr_addr(cia
));
2111 cop_sw (SIM_DESC sd
,
2117 unsigned int value
= 0;
2122 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
)
2124 value
= (unsigned int)ValueFPR(coproc_reg
,fmt_uninterpreted_32
);
2129 #if 0 /* should be controlled by configuration option */
2130 sim_io_printf(sd
,"COP_SW(%d,%d) at PC = 0x%s : TODO (architecture specific)\n",coproc_num
,coproc_reg
,pr_addr(cia
));
2139 cop_sd (SIM_DESC sd
,
2149 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
)
2151 value
= ValueFPR(coproc_reg
,fmt_uninterpreted_64
);
2156 #if 0 /* should be controlled by configuration option */
2157 sim_io_printf(sd
,"COP_SD(%d,%d) at PC = 0x%s : TODO (architecture specific)\n",coproc_num
,coproc_reg
,pr_addr(cia
));
2169 decode_coproc (SIM_DESC sd
,
2172 unsigned int instruction
)
2174 int coprocnum
= ((instruction
>> 26) & 3);
2178 case 0: /* standard CPU control and cache registers */
2180 int code
= ((instruction
>> 21) & 0x1F);
2181 int rt
= ((instruction
>> 16) & 0x1F);
2182 int rd
= ((instruction
>> 11) & 0x1F);
2183 int tail
= instruction
& 0x3ff;
2184 /* R4000 Users Manual (second edition) lists the following CP0
2186 CODE><-RT><RD-><--TAIL--->
2187 DMFC0 Doubleword Move From CP0 (VR4100 = 01000000001tttttddddd00000000000)
2188 DMTC0 Doubleword Move To CP0 (VR4100 = 01000000101tttttddddd00000000000)
2189 MFC0 word Move From CP0 (VR4100 = 01000000000tttttddddd00000000000)
2190 MTC0 word Move To CP0 (VR4100 = 01000000100tttttddddd00000000000)
2191 TLBR Read Indexed TLB Entry (VR4100 = 01000010000000000000000000000001)
2192 TLBWI Write Indexed TLB Entry (VR4100 = 01000010000000000000000000000010)
2193 TLBWR Write Random TLB Entry (VR4100 = 01000010000000000000000000000110)
2194 TLBP Probe TLB for Matching Entry (VR4100 = 01000010000000000000000000001000)
2195 CACHE Cache operation (VR4100 = 101111bbbbbpppppiiiiiiiiiiiiiiii)
2196 ERET Exception return (VR4100 = 01000010000000000000000000011000)
2198 if (((code
== 0x00) || (code
== 0x04) /* MFC0 / MTC0 */
2199 || (code
== 0x01) || (code
== 0x05)) /* DMFC0 / DMTC0 */
2202 /* Clear double/single coprocessor move bit. */
2205 /* M[TF]C0 (32 bits) | DM[TF]C0 (64 bits) */
2207 switch (rd
) /* NOTEs: Standard CP0 registers */
2209 /* 0 = Index R4000 VR4100 VR4300 */
2210 /* 1 = Random R4000 VR4100 VR4300 */
2211 /* 2 = EntryLo0 R4000 VR4100 VR4300 */
2212 /* 3 = EntryLo1 R4000 VR4100 VR4300 */
2213 /* 4 = Context R4000 VR4100 VR4300 */
2214 /* 5 = PageMask R4000 VR4100 VR4300 */
2215 /* 6 = Wired R4000 VR4100 VR4300 */
2216 /* 8 = BadVAddr R4000 VR4100 VR4300 */
2217 /* 9 = Count R4000 VR4100 VR4300 */
2218 /* 10 = EntryHi R4000 VR4100 VR4300 */
2219 /* 11 = Compare R4000 VR4100 VR4300 */
2220 /* 12 = SR R4000 VR4100 VR4300 */
2221 #ifdef SUBTARGET_R3900
2223 /* 3 = Config R3900 */
2225 /* 7 = Cache R3900 */
2227 /* 15 = PRID R3900 */
2233 /* 8 = BadVAddr R4000 VR4100 VR4300 */
2235 GPR
[rt
] = (signed_word
) (signed_address
) COP0_BADVADDR
;
2237 COP0_BADVADDR
= GPR
[rt
];
2240 #endif /* SUBTARGET_R3900 */
2247 /* 13 = Cause R4000 VR4100 VR4300 */
2254 /* 14 = EPC R4000 VR4100 VR4300 */
2257 GPR
[rt
] = (signed_word
) (signed_address
) EPC
;
2261 /* 15 = PRId R4000 VR4100 VR4300 */
2262 #ifdef SUBTARGET_R3900
2271 /* 16 = Config R4000 VR4100 VR4300 */
2274 GPR
[rt
] = C0_CONFIG
;
2276 /* only bottom three bits are writable */
2277 C0_CONFIG
= (C0_CONFIG
& ~0x7) | (GPR
[rt
] & 0x7);
2280 #ifdef SUBTARGET_R3900
2289 /* 17 = LLAddr R4000 VR4100 VR4300 */
2291 /* 18 = WatchLo R4000 VR4100 VR4300 */
2292 /* 19 = WatchHi R4000 VR4100 VR4300 */
2293 /* 20 = XContext R4000 VR4100 VR4300 */
2294 /* 26 = PErr or ECC R4000 VR4100 VR4300 */
2295 /* 27 = CacheErr R4000 VR4100 */
2296 /* 28 = TagLo R4000 VR4100 VR4300 */
2297 /* 29 = TagHi R4000 VR4100 VR4300 */
2298 /* 30 = ErrorEPC R4000 VR4100 VR4300 */
2299 if (STATE_VERBOSE_P(SD
))
2301 "Warning: PC 0x%lx:interp.c decode_coproc DEADC0DE\n",
2302 (unsigned long)cia
);
2303 GPR
[rt
] = 0xDEADC0DE; /* CPR[0,rd] */
2304 /* CPR[0,rd] = GPR[rt]; */
2307 GPR
[rt
] = (signed_word
) (signed32
) COP0_GPR
[rd
];
2309 COP0_GPR
[rd
] = GPR
[rt
];
2312 sim_io_printf(sd
,"Warning: MFC0 %d,%d ignored, PC=%08x (architecture specific)\n",rt
,rd
, (unsigned)cia
);
2314 sim_io_printf(sd
,"Warning: MTC0 %d,%d ignored, PC=%08x (architecture specific)\n",rt
,rd
, (unsigned)cia
);
2318 else if ((code
== 0x00 || code
== 0x01)
2321 /* [D]MFC0 RT,C0_CONFIG,SEL */
2323 switch (tail
& 0x07)
2329 /* MIPS32 r/o Config1:
2332 /* MIPS16 implemented.
2333 XXX How to check configuration? */
2335 if (CURRENT_FLOATING_POINT
== HARD_FLOATING_POINT
)
2336 /* MDMX & FPU implemented */
2340 /* MIPS32 r/o Config2:
2345 /* MIPS32 r/o Config3:
2346 SmartMIPS implemented. */
2352 else if (code
== 0x10 && (tail
& 0x3f) == 0x18)
2355 if (SR
& status_ERL
)
2357 /* Oops, not yet available */
2358 sim_io_printf(sd
,"Warning: ERET when SR[ERL] set not handled yet");
2368 else if (code
== 0x10 && (tail
& 0x3f) == 0x10)
2371 #ifdef SUBTARGET_R3900
2372 /* TX39: Copy IEp/KUp -> IEc/KUc, and IEo/KUo -> IEp/KUp */
2374 /* shift IE/KU history bits right */
2375 SR
= LSMASKED32(SR
, 31, 4) | LSINSERTED32(LSEXTRACTED32(SR
, 5, 2), 3, 0);
2377 /* TODO: CACHE register */
2378 #endif /* SUBTARGET_R3900 */
2380 else if (code
== 0x10 && (tail
& 0x3f) == 0x1F)
2388 sim_io_eprintf(sd
,"Unrecognised COP0 instruction 0x%08X at PC = 0x%s : No handler present\n",instruction
,pr_addr(cia
));
2389 /* TODO: When executing an ERET or RFE instruction we should
2390 clear LLBIT, to ensure that any out-standing atomic
2391 read/modify/write sequence fails. */
2395 case 2: /* co-processor 2 */
2402 sim_io_eprintf(sd
, "COP2 instruction 0x%08X at PC = 0x%s : No handler present\n",
2403 instruction
,pr_addr(cia
));
2408 case 1: /* should not occur (FPU co-processor) */
2409 case 3: /* should not occur (FPU co-processor) */
2410 SignalException(ReservedInstruction
,instruction
);
2418 /* This code copied from gdb's utils.c. Would like to share this code,
2419 but don't know of a common place where both could get to it. */
2421 /* Temporary storage using circular buffer */
2427 static char buf
[NUMCELLS
][CELLSIZE
];
2429 if (++cell
>=NUMCELLS
) cell
=0;
2433 /* Print routines to handle variable size regs, etc */
2435 /* Eliminate warning from compiler on 32-bit systems */
2436 static int thirty_two
= 32;
2442 char *paddr_str
=get_cell();
2443 switch (sizeof(addr
))
2446 sprintf(paddr_str
,"%08lx%08lx",
2447 (unsigned long)(addr
>>thirty_two
),(unsigned long)(addr
&0xffffffff));
2450 sprintf(paddr_str
,"%08lx",(unsigned long)addr
);
2453 sprintf(paddr_str
,"%04x",(unsigned short)(addr
&0xffff));
2456 sprintf(paddr_str
,"%x",addr
);
2465 char *paddr_str
=get_cell();
2466 sprintf(paddr_str
,"%08lx%08lx",
2467 (unsigned long)(addr
>>thirty_two
),(unsigned long)(addr
&0xffffffff));
2473 mips_core_signal (SIM_DESC sd
,
2479 transfer_type transfer
,
2480 sim_core_signals sig
)
2482 const char *copy
= (transfer
== read_transfer
? "read" : "write");
2483 address_word ip
= CIA_ADDR (cia
);
2487 case sim_core_unmapped_signal
:
2488 sim_io_eprintf (sd
, "mips-core: %d byte %s to unmapped address 0x%lx at 0x%lx\n",
2490 (unsigned long) addr
, (unsigned long) ip
);
2491 COP0_BADVADDR
= addr
;
2492 SignalExceptionDataReference();
2495 case sim_core_unaligned_signal
:
2496 sim_io_eprintf (sd
, "mips-core: %d byte %s to unaligned address 0x%lx at 0x%lx\n",
2498 (unsigned long) addr
, (unsigned long) ip
);
2499 COP0_BADVADDR
= addr
;
2500 if(transfer
== read_transfer
)
2501 SignalExceptionAddressLoad();
2503 SignalExceptionAddressStore();
2507 sim_engine_abort (sd
, cpu
, cia
,
2508 "mips_core_signal - internal error - bad switch");
2514 mips_cpu_exception_trigger(SIM_DESC sd
, sim_cpu
* cpu
, address_word cia
)
2516 ASSERT(cpu
!= NULL
);
2518 if(cpu
->exc_suspended
> 0)
2519 sim_io_eprintf(sd
, "Warning, nested exception triggered (%d)\n", cpu
->exc_suspended
);
2522 memcpy(cpu
->exc_trigger_registers
, cpu
->registers
, sizeof(cpu
->exc_trigger_registers
));
2523 cpu
->exc_suspended
= 0;
2527 mips_cpu_exception_suspend(SIM_DESC sd
, sim_cpu
* cpu
, int exception
)
2529 ASSERT(cpu
!= NULL
);
2531 if(cpu
->exc_suspended
> 0)
2532 sim_io_eprintf(sd
, "Warning, nested exception signal (%d then %d)\n",
2533 cpu
->exc_suspended
, exception
);
2535 memcpy(cpu
->exc_suspend_registers
, cpu
->registers
, sizeof(cpu
->exc_suspend_registers
));
2536 memcpy(cpu
->registers
, cpu
->exc_trigger_registers
, sizeof(cpu
->registers
));
2537 cpu
->exc_suspended
= exception
;
2541 mips_cpu_exception_resume(SIM_DESC sd
, sim_cpu
* cpu
, int exception
)
2543 ASSERT(cpu
!= NULL
);
2545 if(exception
== 0 && cpu
->exc_suspended
> 0)
2547 /* warn not for breakpoints */
2548 if(cpu
->exc_suspended
!= sim_signal_to_host(sd
, SIM_SIGTRAP
))
2549 sim_io_eprintf(sd
, "Warning, resuming but ignoring pending exception signal (%d)\n",
2550 cpu
->exc_suspended
);
2552 else if(exception
!= 0 && cpu
->exc_suspended
> 0)
2554 if(exception
!= cpu
->exc_suspended
)
2555 sim_io_eprintf(sd
, "Warning, resuming with mismatched exception signal (%d vs %d)\n",
2556 cpu
->exc_suspended
, exception
);
2558 memcpy(cpu
->registers
, cpu
->exc_suspend_registers
, sizeof(cpu
->registers
));
2560 else if(exception
!= 0 && cpu
->exc_suspended
== 0)
2562 sim_io_eprintf(sd
, "Warning, ignoring spontanous exception signal (%d)\n", exception
);
2564 cpu
->exc_suspended
= 0;
2568 /*---------------------------------------------------------------------------*/
2569 /*> EOF interp.c <*/