Commit Graph
548 Commits
Author SHA1 Message Date
Henrik RydgårdandClaude Opus 5.5 8301c35d7d Threads: Let better threads preempt a long sceKernelCreateThread
On hardware the kernel fills a new thread's stack with interrupts on, so
a better thread that wakes during it runs before the call returns, the
time it takes doesn't count towards the call, and worse threads get
nothing (pspautotests threads/scheduling/preemptsyscall). PPSSPP ate the
whole cost at once and only rescheduled at the end.

__KernelBusyDelayResult() models such a syscall: the caller waits, an
idle thread stands in for it while nothing better wants the CPU, and its
remaining cycles only count down while that's the case. When done it
goes back ahead of threads of its own priority, having never given up
the CPU. sceKernelCreateThread uses it for the stack fill, unless a
thread event handler is about to run.

Booting 75 games against master shows no difference.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-29 09:56:28 -06:00
Henrik RydgårdandClaude Opus 5.5 960da1596c Threads: Charge for filling the stack on create, and for delete
From pspautotests threads/scheduling/costs: sceKernelCreateThread takes
about 150us plus roughly a cycle per byte of stack, which the kernel fills
with 0xFF (1.3ms for 256KB), and sceKernelDeleteThread 50-100us whatever
the stack size. Brings threads/scheduling/scheduling a good deal closer;
what's left needs a thread that wakes during a long syscall to preempt it.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-29 09:19:32 -06:00
Henrik RydgårdandClaude Opus 5.5 638da935ea Threads: sceKernelStartThread hands the CPU straight to a better thread
When the new thread outranks the caller, the firmware switches to it
directly, even if a thread of still better priority is ready but hasn't
been dispatched (one that a sceKernelTerminateThread woke, say). Verified
against the new pspautotests threads/threads/termsuspended.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-29 09:19:32 -06:00
Henrik RydgårdandClaude Opus 5.5 eda92c4ef2 Callbacks: Track callback nesting per thread, one level deep
Replaces the global in-callback counter with each thread's own mipscall
chain, so several threads can be inside callbacks at once, and other
threads' callbacks (better priority ones right away) run while one is.
Verified against pspautotests threads/callbacks/otherthread, recursion
and intrnotify:

- A callback nests only one level: a CB wait that would go deeper never
  returns on hardware, so the callback is left pending instead.
- A non-CB wait inside a callback no longer runs callbacks because of
  the CB wait the callback interrupted.
- Callbacks for a waiting thread are only taken when it beats both the
  running thread and every ready one. After an interrupt (which runs on
  the idle thread) that's the thread about to resume, not idle.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 15:59:25 -06:00
Henrik RydgårdandClaude Opus 5.5 24b41d3f23 Kernel waits: Fix VPL/FPL and msgpipe waits around callbacks, report timeout left
Verified against pspautotests threads/callbacks/waittypes:

- __KernelThreadingInit() cleared the wait type callback table after
  __KernelMemoryInit() had registered VPL and FPL in it, so a VPL or FPL
  wait interrupted by a callback was never paused or resumed, and could
  hang forever.
- A msgpipe deleted during a callback left its waiter waiting, instead
  of waking it with WAIT_DELETE.
- A wait that got its object during a callback reported no time left;
  put the timer back before trying to unlock, so the unlock writes what
  remains.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 15:59:25 -06:00
Henrik RydgårdandClaude Opus 5.5 acd2738b7a Callbacks: Deliver to other threads by priority, fix sceKernelCancelCallback
Verified against pspautotests threads/callbacks/delivery:

- Notifying the callback of a better priority thread in a CB wait runs
  it right away. Callbacks of other waiting threads stay pending until
  those threads would get to run, rather than being taken at any
  reschedule, so they can still be counted or canceled.
- sceKernelCancelCallback clears the notify count, not just the arg.

threads/callbacks/cancel, count and umd/wait/wait now pass.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 15:59:25 -06:00
Henrik RydgårdandClaude Opus 5.5 3bf8b5b5c9 Callbacks: Run nested callbacks from CB waits, match hardware ordering
Verified against new pspautotests threads/callbacks/afterwait and nested:

- A thread inside a callback runs its own pending callbacks (even the
  same one again) nested, when it enters a CB wait. Waits paused by a
  nested callback are keyed by the outer callback's id.
- sceKernelCheckCallback inside a callback returns ILLEGAL_CONTEXT
  without running anything.
- sceKernelSleepThreadCB with a queued wakeup runs pending callbacks
  before consuming it.
- A thread whose wait ended during a callback keeps the CPU, instead of
  queueing behind threads of the same priority.

threads/callbacks/notify now passes too.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 15:59:25 -06:00
Henrik RydgårdandClaude Opus 5.5 e7c23bb381 Don't run wait callback hooks for a thread that isn't waiting
A thread whose wait ends without a context switch (for example when a
callback run from the wait satisfies it) keeps its old waitType. If it
later ran a callback, from sceUmdWaitDriveStatCB with the drive already
ready for instance, the stale wait's begin/end hooks ran, couldn't find
the paused wait, and resumed the thread with SCE_KERNEL_ERROR_WAIT_DELETE,
overwriting the HLE call's return value.

Should fix "sceUmdWaitDriveStatCB: error 0x800201b5" dialog in
Maru Goukaku TOEIC Test Portable (#7576).

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 15:58:47 -06:00
Henrik RydgårdandClaude Opus 5.5 490f08d220 Savestate: Fix action and exit callback handling on load
Delete the old HLE mips call actions instead of leaking them or keeping
stale ones, fail the load on an unknown action type instead of crashing,
and derive the exit-callback-pending flag from the loaded state.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:06 -06:00
Henrik RydgårdandClaude Opus 5.5 d28b79960b Savestate: Fix loading kernel heaps and pre-exit-callback states
KernelHeap was missing from CreateByIDType, and an unknown type returned
without an error, desyncing the rest of the load. States from before exit
callbacks kept the boot-time action slot, which sceMpeg's restore took over.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:05 -06:00
Henrik Rydgård 41144e3b35 Give the memory partitions the caller's privilege, not the syscall's
PPSSPP decided whether a caller was privileged with hleIsKernelMode(), which reports whether the
syscall being executed is itself a kernel-only export. That's a different question from the one
the hardware answers: on a PSP the privilege belongs to the calling module, and a kernel module
reaches sceKernelCreateTlspl through the ordinary ThreadManForUser NID like anything else. So a
kernel module asking for partition 1, 3 or 4 got ILLEGAL_PERM where a real PSP hands it over,
which the new threads/tls/kernel/partition test shows directly.

BlockAllocatorFromID now also accepts a caller whose thread belongs to a kernel module, via a new
__KernelCurThreadIsKernelMode(). It checks the thread's own attribute first and then the owning
module, because a kernel module's main thread isn't necessarily flagged kernel - the attribute
comes from PSP_MAIN_THREAD_ATTR, which needn't set it. That mirrors how sceKernelCreateThread
already works out allowKernel.

This only ever widens access, and only for threads belonging to kernel modules, so games are
unaffected - they run in user modules and see exactly what they saw before.
2026-09-08 15:18:02 -06:00
Henrik RydgårdandClaude Opus 5 a91448b318 sceKernelThread: actually accumulate runForClocks
nt.runForClocks was zeroed when a thread was created and copied out by
sceKernelReferThreadStatus, but nothing ever added to it, so every thread
reported having run for zero time forever.

Crazy Taxi: Fare Wars uses it as a liveness check. Its music state machine
samples the mp3 thread's run time once every 60 frames and compares it with
the previous two samples; when it doesn't move it concludes playback is
wedged, sets the stop bit, and the thread tears itself down and exits. The
game restarts it, and about a second later decides it's wedged again - custom
soundtracks restarted roughly once a second forever, whatever the file.

Bill the time since the previous switch to the outgoing thread, which is
exactly the thread that was running for it. The field is already part of the
serialized thread struct, so savestates don't change format; the timestamp
itself is re-based on load rather than saved, and only on load - saving runs
a measure pass and a write pass, and re-basing in those would discard the
time the running thread had accumulated since the last switch, letting a save
change what the game can observe.

Risk: this runs on every context switch, the hottest path in the scheduler.
It adds one CoreTiming read and a 64-bit add. Games that poll thread run
times will now see them move, which is correct but is new behavior.

Co-Authored-By: Claude Opus 5 <[email protected]>
2026-09-07 12:48:22 -06:00
Henrik Rydgård 0f94e01241 HLE: Clamp the wait timeout remaining time to zero
CoreTiming::UnscheduleEvent returns the scheduled time minus the current time,
which is negative when the event is overdue but hasn't been processed yet - the
exact situation when a wait is satisfied right around its own timeout. Only the
semaphore clamped it; everywhere else we wrote (u32)cyclesToUs(negative) into
the game's timeout variable, i.e. a huge bogus "remaining time".

Pulled the shared shape into HLEKernel::WriteRemainingTimeout so it can't drift
apart again - event flags, mbx, fpl, vpl, msgpipe, mutex, lwmutex and semaphore
all go through it now. The two thread-end sites keep their own copy since they
unschedule even when the game passed no timeout pointer, and sceUsb just gets
the clamp.
2026-09-04 18:10:10 -06:00
Henrik Rydgård a0ecf545a6 Implement or stub assorted functions the VSH is calling 2026-08-21 10:56:06 +02:00
Henrik Rydgård 31decccb9a Style and comment settings. Surface a setting in the ImDebugger. 2026-08-20 01:05:19 +02:00
Henrik RydgårdandClaude Sonnet 5 43dccd5903 HLE: implement assorted stubs and minor functionality
This is stuff encountered in the VSH boot research.

sceRtc_driver, scePower_driver, sceImpose_driver, ThreadManForKernel funcs,
sceRtcGetAlarmTick, sceHprm_driver/sceHprmReadLatch

sceVshBridge_Driver imports sceKernelResumeDispatchThread, SuspendDispatchThread,
and NotifyCallback from ThreadManForKernel, but they were only registered under
ThreadManForUser. Added sceKernelGetUserLevel and sceKernelIsUserModeThread (new).

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01GZq8ZtJmFY7bkX5FVkr3P9
2026-08-19 18:38:03 +02:00
Henrik RydgårdandClaude Sonnet 5 21b7ce7392 Expose EventFlag/Mutex/Semaphore/MsgPipe/Callback in their headers
These KernelObject subclasses (and their Native* status structs) were
private implementation details of their respective .cpp files. Move them
into the matching .h instead, so external code - specifically the upcoming
WebSocket kernel-object introspection endpoints - can read a live object's
state directly via kernelObjects.Get<T>()/Iterate<T>(), the same way
PSPModule/PSPThread already can. Read-only by convention: nothing outside
each file should call DoState() or otherwise mutate these; the fields are
public here for that file's own pre-existing use, not an invitation to
write from elsewhere.

To avoid pulling each type's full dependency set (Memory::, BlockAllocator,
CoreTiming, HLEKernel::...) into headers many other files include, non-trivial
method bodies (DoState, and MsgPipe's buffer/wait-list management) are
declared in the header but still defined out-of-line in the .cpp, same as
before - only genuinely trivial one-liners went inline.

KernelObjectPool also gains IterateAll(), a type-agnostic sibling of the
existing Iterate<T>() - walks every live kernel object regardless of type,
for a coarse "what's alive right now" overview.

No behavior change - this is a pure visibility/declaration-vs-definition
move, not new functionality. That lands in a follow-up commit.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01GZq8ZtJmFY7bkX5FVkr3P9
2026-08-17 16:01:23 +02:00
Henrik Rydgård eb0813c0e3 Add a utility function for all the ABIs to call functions with a pointer arg. Use to call Advance from the JIT with the MIPSContext. Indent some code better. 2026-08-13 08:09:30 +02:00
Henrik Rydgård e9a3449ede More MIPSState * plumbing (manual) 2026-08-12 14:02:19 +02:00
Henrik Rydgård 0596ee97f6 More memory access cleanup 2026-08-11 20:14:01 +02:00
Henrik Rydgård 3bd41376da More memory cleanup 2026-08-11 20:12:10 +02:00
Henrik Rydgård cd052ea640 Adjust the level of Claude-based paranoia here and there 2026-08-11 20:08:01 +02:00
Henrik Rydgård 7824f69020 Code style updates 2026-08-10 11:17:58 +02:00
Henrik Rydgård e2bc017112 More removals of Read_U32 2026-08-10 11:17:45 +02:00
Henrik Rydgård 788150c28e Fix out-of-bounds reads in PGF font parsing
PGF::ReadPtr walked four length-prefixed tables and computed table sizes
before any bounds check, and used signed 32-bit size math that could
overflow, allowing a crafted font to read past the input buffer.

- Validate the total size of all tables up front using 64-bit math.
- Check the rev3 extra header fits before reading it.
- Cap charPointerLength/charMapLength/shadowMapLength to avoid absurd
  allocations.
- Bounds-check glyph data offsets before reading each glyph.

Also throw in a warning fix
2026-08-01 11:57:27 +02:00
Henrik Rydgård a7dc184613 Reapply "Implement exit callbacks. Attempt to solve #21828"
It was a mistake to revert c4d3cc8 , need to take savestates into
account

This reverts commit d5cec86933.
2026-07-08 19:45:42 +02:00
Henrik Rydgård d5cec86933 Revert "Implement exit callbacks. Attempt to solve #21828"
This reverts commit e4d3cc841c.
2026-07-08 18:09:09 +02:00
Henrik Rydgård e4d3cc841c Implement exit callbacks. Attempt to solve #21828 2026-06-15 12:12:57 +02:00
Henrik Rydgård 634b9dba9b Add some new NIDs, update some comments 2026-06-15 08:16:40 +02:00
Henrik Rydgård 3f6582aa7b Minor logging changes 2026-05-30 19:07:59 +02:00
Henrik Rydgård 3ecb54e70a More tweaking of gamelist icons 2026-02-11 01:24:11 +01:00
Katharine Chui 326448636b Run module_start of plugins before starting boot module 2025-06-13 23:29:49 +02:00
Henrik Rydgård ba148e5ec7 JIT/IRJit: Delete an old "function preloading" experiment
This caused some confusion while trying to debug #20502
2025-06-11 15:45:18 +02:00
Henrik Rydgård 61a89de6a7 Smash Court Tennis 3 unprintable thread name hack 2025-05-26 18:04:46 +02:00
Henrik Rydgård 15d24806bb sceKernelThread: Make a bunch of globals static 2025-05-25 12:40:16 +02:00
Henrik Rydgård 343ca2600a Add a developer setting to disable individual HLE modules, allowing them to be loaded properly.
Some games survive with a loaded sceAtrac, and start talking to
sceAudioCodec instead, the underlying library, though unsuccessfully
since it's not properly implemented yet.
2025-04-02 10:19:24 +02:00
Henrik Rydgård 2bfe327dbd Expose PSPThread in the same manner 2025-03-31 10:24:03 +02:00
Henrik Rydgård 644f5e4e6c Expose PSPModule (so the debugger can access it later) 2025-03-31 09:56:08 +02:00
Henrik Rydgård 0f840e6240 Move JPEG error codes to the big enum, some include cleanup 2025-03-21 20:44:46 +01:00
Henrik Rydgård bb436cda8f Reimplement a lot of logic, implement loop streaming properly 2025-03-18 09:36:33 +01:00
Henrik Rydgård af8d14c546 Buildfix 2025-03-08 23:56:01 +01:00
Henrik Rydgård 89e031fb8a Logging cleanup 2025-03-08 23:39:22 +01:00
Henrik Rydgård 881e88268f Fix log-stack problem in kernel 2025-03-08 23:37:48 +01:00
Henrik Rydgård 0f9c97c2a0 Another big batch of logging cleanup 2025-03-05 17:02:46 +01:00
Henrik Rydgård ad2791a9cf More HLE logging cleanup 2025-03-05 17:02:46 +01:00
Henrik Rydgård cb180bf781 A lot of log cleanup. It's quite useful as a forcing function to find missing logs. 2025-03-05 17:02:46 +01:00
Henrik Rydgård 36fa0fe343 Update logging in sceKernelResumeThread 2025-03-02 11:24:51 +01:00
Henrik Rydgård 28b2c7f540 HLE log rename part 1: Remove duplicate log functions. Return type should be determined by metadata. 2025-01-29 09:45:39 +01:00
Henrik Rydgård 16dcb9ee8a And more 2025-01-20 12:20:21 +01:00
Henrik Rydgård 26547e2629 More fixes 2025-01-20 12:20:21 +01:00