Commit Graph
48113 Commits
Author SHA1 Message Date
Henrik RydgårdandClaude Opus 5.5 639e57c2bd Savestate: Keep pending adhocctl requests, so a waiting Init survives a load
With WLAN on and no server reachable, sceNetAdhocctlInit keeps its thread
waiting for the login. The load dropped the request, and the wait ended in
BUSY, which Init can't retry. Splinter Cell then ran its failure path with
a deleted event flag. Also stop freeing matching event buffers into the
restored allocator, and take the event lock when clearing.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:06 -06:00
Henrik RydgårdandClaude Opus 5.5 4bfaab058b GPU: Reject savestates with display list ids out of range
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:05 -06:00
Henrik RydgårdandClaude Opus 5.5 84f64a9fdf Savedata: Don't free stale icon textures after a state load
The old icons stayed in PPGe's decimation list with kernel addresses from
before the load, and got freed out of whatever the loaded state had there.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:05 -06:00
Henrik RydgårdandClaude Opus 5.5 db071361b0 Savestate: Wait for the SAS and IO threads before touching memory
Both drained only in their own DoState, after memory and Atrac contexts
had already been replaced under a mix or read still in flight. Also fix
sceUmd loading umdActivated into the wrong variable, and count each save
once in saveStateGeneration (it also bumped in the measuring pass).

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:05 -06:00
Henrik RydgårdandClaude Opus 5.5 d28b79960b Savestate: Fix loading kernel heaps and pre-exit-callback states
KernelHeap was missing from CreateByIDType, and an unknown type returned
without an error, desyncing the rest of the load. States from before exit
callbacks kept the boot-time action slot, which sceMpeg's restore took over.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:05 -06:00
Henrik RydgårdandClaude Opus 5.5 797957ea25 OSK: Fix a use-after-free when loading a savestate
DoState replaced native_ while holding a lock_guard on its mutex, so the
old NativeInput could be freed before the guard unlocked it. Crashed every
state load (e.g. Splinter Cell Essentials, anywhere in the game).

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:05 -06:00
Henrik Rydgård 547d032995 Merge pull request #22359 from hrydgard/video-pacing-investigation
Video pacing investigation: Fix Ys I&II pacing by adding a cost model for video blits
2026-09-28 09:31:30 -06:00
Henrik Rydgård d2d9828288 Merge pull request #22360 from sum2012/memory_leak
Fix windows memory leak when close PPSSPP by Gemini
2026-09-28 09:29:52 -06:00
Henrik Rydgård 9fc4eb3e4d Merge pull request #22362 from 4RH1T3CT0R7/fix/caching-loader-eof
CachingFileLoader, DiskCachingFileLoader: keep the partial last block of the file
2026-09-27 08:16:16 -06:00
Artem Lytkin 670486d2f8 DiskCachingFileLoader: keep the partial last block of the file too
same problem since f7f92c5db. also only count blocks that were actually
allocated.
2026-09-27 15:31:17 +03:00
Artem Lytkin a3e84adab9 CachingFileLoader: keep the partial last block of the file
since 7e6405291 only full 64 KB reads get cached, so any read touching the
shorter last block of a file came back short. count blocks with
blocks_.size() too, so failed reads can't inflate the count until
MakeCacheSpaceFor loops forever. also stop read-ahead from asking the
backend for blocks past the end of the file.
2026-09-27 15:31:04 +03:00
sum2012 a960350e50 Fix windows leak when close PPSSPP by Gemini
'PPSSPPDebug64.exe' (Win32): Unloaded 'C:\Windows\System32\mfreadwrite.dll'
The thread 'RecentISOThreadFunc' (9920) has exited with code 0 (0x0).
The thread 'Console' (10488) has exited with code 0 (0x0).
Detected memory leaks!
Dumping objects ->
{17571338} normal block at 0x00000214CC4A3FE0, 16 bytes long.
 Data: < Cf             > E8 43 66 CD 14 02 00 00 00 00 00 00 00 00 00 00
{17571337} normal block at 0x00000214CC4A3B80, 16 bytes long.
 Data: < Cf             > C8 43 66 CD 14 02 00 00 00 00 00 00 00 00 00 00
D:\project\memory_leak\ppsspp\Windows\Debugger\Debugger_Disasm.cpp(174) : {17571336} normal block at 0x00000214CD664190, 640 bytes long.
 Data: < C              > 90 43 F2 C0 F6 7F 00 00 F6 0C 04 00 00 00 00 00
D:\project\memory_leak\ppsspp\UI\NativeApp.cpp(879) : {84582} normal block at 0x00000214CE8C5DB0, 4224 bytes long.
 Data: <                > 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
{2432} normal block at 0x00000214D6255C20, 16 bytes long.
 Data: <0 $             > 30 E7 24 D6 14 02 00 00 00 00 00 00 00 00 00 00
D:\project\memory_leak\ppsspp\Common\Net\HTTPNaettRequest.cpp(43) : {2431} normal block at 0x00000214D624E730, 32 bytes long.
 Data: < \%             > 20 5C 25 D6 14 02 00 00 00 00 00 00 00 00 00 00
Object dump complete.
The thread 22000 has exited with code 0 (0x0).
The thread 21248 has exited with code 0 (0x0).
The thread 38104 has exited with code 0 (0x0).
The thread 27860 has exited with code 0 (0x0).
The thread 33240 has exited with code 0 (0x0).
The thread 29352 has exited with code 0 (0x0).
The thread 13964 has exited with code 0 (0x0).
The thread 5640 has exited with code 0 (0x0).
The thread 10528 has exited with code 0 (0x0).
The thread 15252 has exited with code 0 (0x0).
The thread 23016 has exited with code 0 (0x0).
The thread 31424 has exited with code 0 (0x0).
The thread 7000 has exited with code 0 (0x0).
The thread 11620 has exited with code 0 (0x0).
The thread 36264 has exited with code 0 (0x0).
The thread 27248 has exited with code 0 (0x0).
The thread 24780 has exited with code 0 (0x0).
The thread 26228 has exited with code 0 (0x0).
The thread 13676 has exited with code 0 (0x0).
The thread 16828 has exited with code 0 (0x0).
The thread 27388 has exited with code 0 (0x0).
The thread 1668 has exited with code 0 (0x0).
The thread 37272 has exited with code 0 (0x0).
The program '[23456] PPSSPPDebug64.exe' has exited with code 0 (0x0).
2026-09-26 22:24:26 +08:00
Henrik RydgårdandClaude Opus 5.5 ad25588651 GPU: Allow for main RAM contention in the movie blit cost
The blit rates were measured with nothing else running. In a game, threads
waking up and SAS mixing on the Media Engine compete with the GE for main RAM:
Star Wars: Lethal Alliance's movie blit takes 8.65ms alone and 10.3ms in the
game. We don't model that load, so RAM texture fetches get a fixed 1.17x for a
typical one. With it, that game's long movie plays at 30 fps as on hardware.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 17:37:53 -06:00
Henrik RydgårdandClaude Opus 5.5 b39cf47124 Charge measured SAS mix time, and share the Media Engine between its jobs
The SAS mix estimate was a guess capped at 1200us. Measured on a PSP
(pspautotests audio/timing/sastiming), a mix costs 110us plus 0.49us per grain
sample, plus per voice and sample 0.445us + 0.0675us per unit of pitch ratio
(VAG; PCM and noise slightly less), plus 0.64us per sample with a reverb type
set. Linear to 1% across 64-2048 samples and 0-32 voices: 32 VAG voices at 512
samples take 8.7ms, not 1.2.

The mix runs on the Media Engine, as do video and audio decoding, so they now
queue behind each other there (MEScheduleJob). A game that keeps SAS running
during a movie - Star Wars: Lethal Alliance - decodes more slowly for it, like
on hardware.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 17:33:33 -06:00
Henrik RydgårdandClaude Opus 5.5 8f66065f53 GPU: Add a clear cost, disabled for now
Full-screen clears measured on a PSP (pspautotests gpu/timing/blittiming):
0.49ms on a 16-bit framebuffer whatever is cleared, 0.69ms on 8888, 1.02ms on
8888 with depth. Charging them may help games that spin hard on an empty
screen, but it's off (chargeClearTime) until tried on some. The video blit
cost moves into the same function, now EstimateFillCycles.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 17:18:42 -06:00
Henrik RydgårdandClaude Opus 5.5 242ef0a984 GPU: Track video frames in GPUCommon, so they expire for the blit cost too
The blit cost remembered only the last buffer a decoder wrote into, forever.
Move the texture cache's video list (with its ageing out a few flips after
the last write) into GPUCommon, so the texture cache, the blit cost and
SoftGPU all share one. That also counts both of a double-buffered player's
frames, which exposed that a clear drawn with texturing still enabled was
being charged as a blit - skip clears and draws without texture coordinates.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 17:00:11 -06:00
Henrik RydgårdandClaude Opus 5.5 8f70003cce Remove the PaceVideocodecDecode workaround for Ys I & II
The blit cost model now paces its movies at 30 fps without it.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 16:44:28 -06:00
Henrik RydgårdandClaude Opus 5.5 7a675b42d5 Model the movie blit by texture format, location and width; scale costs with the clock
Measured on a PSP (pspautotests gpu/timing/blittiming), a full-screen blit
from an unswizzled texture costs what the texture fetch costs: 16-bit formats
half of 32-bit, VRAM a fifth of RAM, and rectangles wider than ~128 texels
~7.5x as much as narrow strips, from texture cache thrashing. Framebuffer
format, filtering and blending don't matter. Ys I & II draws its movie as one
full-width sprite from a 565 texture in RAM, which takes 33ms - that, not the
decode, is what holds it to 30 fps.

All of the ME and GE costs speed up with the clock (2/3 as long at 333/166),
since the whole system runs from the one PLL.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 16:40:11 -06:00
Henrik RydgårdandClaude Opus 5.5 298facd614 sceAudiocodec: Charge AAC decode time too
sceMp4AacDecode of an AAC-LC stereo frame takes about 1.7ms on a PSP, measured
with pspautotests video/mp4/mp4timing.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 16:14:37 -06:00
Henrik RydgårdandClaude Opus 5.5 e6330a58f4 Headless: --dump-file lists a directory when given one
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 15:34:47 -06:00
Henrik RydgårdandClaude Opus 5.5 a0b812bc31 Charge hardware-measured time for movie decode, colour conversion and blit
Movie players like the one in Star Wars: Lethal Alliance present every decoded
frame after a single vblank wait, with no clock or timestamp check, so the
frame rate depends on decode, CSC, ATRAC decode and the GE blit adding up to
more than a vblank. We charged nearly nothing for any of them, so such movies
ran at 60 fps until the ringbuffer's slack ran out.

Costs measured on a PSP with a copy of that player (pspautotests
video/mpeg/playertiming), for a 480x272 frame:

- sceVideocodecDecode: 3.4ms (sceMpegAvcDecode 5.8ms less sceMpegAvcCsc 2.4ms)
- sceMpegBaseCscAvc: 2.4ms, was a flat 4ms
- sceAudiocodecDecode, ATRAC3+ only: 2.5ms per frame
- GE: 9.7ms for a through-mode rectangle blit from a decoded video frame,
  charged by area, only for textures in the buffer a decoder last wrote.

GE time also now carries across stall address updates. Before, a list sent
in stalled chunks only had its last chunk's time counted, so sceGeDrawSync
returned 39us after a blit that takes 9.7ms. This affects every game that
builds its lists incrementally, so GE-timing-sensitive games need checking.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 15:23:08 -06:00
Henrik RydgårdandClaude Opus 5.5 e015977f3c Headless: Add --dump-file to copy a file out of a disc image
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 15:23:08 -06:00
Henrik Rydgård cae623f4e6 Merge pull request #22349 from hrydgard/sceutility-morework
sceUtility: Move all save/load file I/O to be off the main thread, assorted fixes
2026-09-25 14:12:52 -06:00
Henrik Rydgård f506efeade Merge pull request #22358 from hrydgard/parseuri-dns-fixes
Make Wipeout Pure's browser work (just because), minor fixes
2026-09-25 13:25:05 -06:00
Henrik RydgårdandClaude Opus 5.5 76eceac7fb Netconf: Don't hold back the fade-in while joining the access point
While apctl was in JOINING, every Update restarted the fade-in, so the dialog
sat at its first, barely visible step until the state moved on to getting an
IP. It now keeps the fade-in it started with.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:59:00 -06:00
Henrik RydgårdandClaude Opus 5.5 b9e7d9e0a0 Netconf: Report success, and don't get stuck without a way out
- The result was only ever written on cancel, so a connection that worked
  gave the game back whatever was in the field, which some fill with -1.
- Infrastructure mode drew a Cancel button that did nothing, so if the
  access point never gave an IP there was no way out. Cancelling now also
  disconnects the connect it started, so the game isn't left connected
  after being told the dialog was aborted.
- An unknown netAction went down neither path and never finished.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:41 -06:00
Henrik RydgårdandClaude Opus 5.5 1d07fdba86 Utility: Small fixes from reviewing the dialogs
- Loading a utility module without room for our (rough) memory block stored
  (u32)-1 as its address, which av_atrac3plus then memset. It now loads
  without the block, which HLE doesn't need.
- LoadNetModule's module id was unsigned, so a load error was passed on to
  sceKernelStartModule as an id.
- The dialog helper threads put the game's priorities straight into ORI
  immediates; ones that aren't a priority at all now fall back to 0x20.
- A fade never finished with an animSpeed of 0 or less.
- MsgDialog V3 button captions filling all 64 bytes ran on into the next
  field.
- GamedataInstall: a file shorter than it claimed was retried forever, Abort
  worked in any state and wrote through an unchecked pointer, and the game
  and data names were read as C strings from fixed-size fields.
- NpSignin: a cancel was overwritten with SUCCESS in the same frame, so the
  game saw a sign-in. The status is reset on start, so a reused struct no
  longer hangs.
- Unloading av_atrac3plus never reached __AtracNotifyUnloadModule, leaving
  the atrac state pointing at freed memory.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:41 -06:00
Henrik RydgårdandClaude Opus 5.5 52e47f8e39 OSK: Check the request and output like the firmware, fix native box races
- InitStart checks the address and size the way sceUtility_Driver does
  (0x40 and 0x44 are both fine, utility/dialog/sizes) and that the field
  struct is in memory.
- The input text was read up to a terminator with no limit and no memory
  check, and the output was written through an unchecked pointer every
  Update. Both are bounded and checked now.
- Converting a string to UTF-8 checked for room before each character, then
  wrote up to three bytes and a terminator, overflowing a 2048-byte stack
  buffer on long non-ASCII text (both conversions did).
- An output buffer of length 0 made FieldMaxLength wrap around, and the
  keyboard preview then indexed the text at -1.
- The native input box's callbacks captured the dialog and could write into
  it after it was deleted, and its status was read and written without the
  lock. They now share a small state object instead, a new one per start
  and per state load (unless a box is still open, which answers into the
  loaded state).
- Savestates keep the current keyboard and the Korean combining state. With
  older ones, it picks a keyboard the field allows, as Init does.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:41 -06:00
Henrik RydgårdandClaude Opus 5.5 41b5074a98 Utility: Release volatile memory on a forced shutdown, fix dialog savestates
- The Yugioh savedata workaround force-stopped the other dialog without
  releasing the volatile memory it held, so the savedata helper then waited
  for it forever.
- Screenshot's ShutdownStart and Update succeeded when no screenshot was
  running, putting it back into SHUTDOWN.
- Savestates: Netconf didn't keep its request address, and a DNS json
  download going on was gone after a load, so it could wait for it forever;
  it now fetches the json again (it's cached). NpSignin didn't keep its
  request address either. Both restart their timeouts instead of timing out
  at once. With states from before, they keep the current address as they
  used to.
- Loading a state from before NpSignin, GameSharing or HtmlViewer were saved
  resets them rather than keeping this session's state (including the
  HtmlViewer's memory block), and without Shutdown's side effects, which
  would write to the loaded memory and release its volatile lock.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:41 -06:00
Henrik RydgårdandClaude Opus 5.5 6dffcc91d2 Utility: Check request sizes like the firmware
InitStart sizes: Netconf and NpSignin accepted any size, then wrote
common.size bytes back from a 64-68 byte host struct, copying host memory
into PSP RAM. GamedataInstall looked for install files before checking the
size, and the HtmlViewer read options before checking the whole request was
in memory. All the dialogs now check the address, then the sizes
sceUtility_Driver accepts (utility/dialog/sizes), before anything else, as
the firmware does (a bad address is INVALID_ADDRESS), and write back no more
than the struct.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:41 -06:00
Henrik RydgårdandClaude Opus 5.5 9e69c1f9aa Savedata: Keep the IO thread out of the dialog's state
Replaces the temporary fix that did the hidden modes' IO inside Update.

The IO thread read and wrote the dialog's request, display state and save
list, all shared with the emulator thread, which kept using them to draw the
dialog and reload the request from the game.

Now the IO thread works on its own copy of the request, its own SavedataParam
and directory names resolved up front, and shares nothing else with the
emulator thread but the (locked) file system, MemoryStick_FreeSpace's cached
use and sceChnnlsv's scratch buffer and kirk state, the last two now under
locks too. It still reads and writes the game's buffers directly, like a PSP's
utility threads and sceIoReadAsync do, so a savestate waits for it before it
saves or loads memory. Save
bookkeeping, the save indicator and display changes happen on the emulator
thread when the results are taken, and only the request fields the IO changed
are copied back, so a game's own edits in the meantime survive.

Hidden modes take the results at the next Update (or, with Host IO timing,
the first Update that finds them done). The visible dialogs keep drawing and
take them once the IO is done; save and load used to stall the emulator
thread for the whole operation. Savestates keep results that haven't been
taken yet.

When the results land in PSP memory doesn't matter to games, so
utility/savedata/filelist now only prints them once the utility has finished.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:39 -06:00
Henrik RydgårdandClaude Opus 5.5 1f1c478c92 MsgDialog: An Abort takes effect from the 8th Update, like on a PSP
Until then the dialog runs normally (and writes result = 0, which an
immediate abort skipped). Measured with one Update per vblank; at one every
other vblank a PSP took 6, so it isn't purely a count.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:23 -06:00
Henrik RydgårdandClaude Opus 5.5 5f261bd7ff Utility: Stand in for the HtmlViewer, offering to open the page in a browser
Instead of the PSP's web browser, a dialog shows the URL the game wants
and opens it in the host's browser on X, or backs out on O. Either way the
game sees the browser closed normally. Platforms that can't open a URL
(the new SYSPROP_CAN_LAUNCH_URL) only offer to back out. Only plain
printable-ASCII http(s) addresses are handed over, and on Linux without a
shell.

What the firmware does (sceUtility_Driver, 6.61, plus
utility/dialog/htmlviewer): the HtmlViewer has its own state apart from the
other dialogs, so they don't block each other, and its calls return
WRONG_TYPE until one has started. The request size picks the 2.00 to 3.00
layout, and InitStart allocates 3.5MB of user memory (4.5MB with options
bit 0x400 from 2.70 on), failing with 800200d9 without it.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:23 -06:00
Henrik RydgårdandClaude Opus 5.5 3c15b2b112 Utility: One dialog at a time whatever its type, like the firmware
On a PSP, every InitStart fails with INVALID_STATUS until the last dialog
started is back at NONE, including while it's shutting down, and before
its params are checked. A failed InitStart leaves the current type alone.
We returned WRONG_TYPE instead, and a failed InitStart (e.g. a bad size)
still switched the current type, so every later dialog was refused. (One of
ours that fails after already starting, as savedata can, still becomes the
current type, since the game may poll it.)

The busy check applies status changes that are due, but doesn't use up an
auto status dialog's one-time INITIALIZE/SHUTDOWN reports; one that only
waits to report SHUTDOWN is let finish. Auto status dialogs now release
volatile memory on the way to NONE, including when the game saw RUNNING
before the init thread was done, which used to leave it locked for the next
dialog. GamedataInstall no longer requires currentDialogActive, which its
ShutdownStart cleared even when it then failed, so it could never finish -
and would now have blocked every other dialog.

Also: MsgDialog accepts exactly the three sizes sceUtility_Driver does (we
memcpy'd whatever size was given), and HtmlViewer GetStatus answers
WRONG_TYPE.

Adds utility/dialog/status and utility/dialog/priority, recorded on a PSP.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:50:23 -06:00
Henrik Rydgård 74cbbc067c Merge pull request #22357 from hrydgard/ir-interpreter-opts
IR interpreter optimizations
2026-09-25 12:48:17 -06:00
Henrik Rydgård 774ed9a5a9 Logging cleanups in sceHttp/sceHttps 2026-09-25 12:38:40 -06:00
Henrik RydgårdandClaude Opus 5.5 e310d144c9 Headless: Don't end a --debugger-run run when the CPU stops
A stop ended the run unless the CPU had been told to break at start, which is
only --debugger. So under --debugger-run, pausing from the debugger (or any
breakpoint) exited the process. Key it on whether the debugger is on instead.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:35:41 -06:00
Henrik RydgårdandClaude Opus 5.5 be30966079 sceNet: Update the connection's DNS server when the infra-dns json arrives
The apctl info copies the AutoDNS server when the connection gets its IP, which
normally happens before netconf has downloaded infra-dns.json, so games that read
the primary DNS server afterwards (to do their own lookups) got an empty string.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:24:02 -06:00
Henrik RydgårdandClaude Opus 5.5 6cb7c985bd sceHttp/sceParseUri: Fix the size query and header block, Wipeout Pure's browser works
sceUriParse's size query (no parsed-URI or work area) returns 0 on a PSP, not -1,
which made Wipeout Pure's embedded browser give up before connecting. And
sceHttpGetAllHeader hands out the header block as received, ending with the blank
line, NUL-terminated and with the NUL counted; without the blank line the browser
never displayed the image the page consists of. Both from the 6.60 firmware
modules (libparse_uri.prx, libhttp.prx).

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 12:24:02 -06:00
Henrik RydgårdandClaude Opus 5.5 4fc858d6db arm64 IR JIT: Pair adjacent loads and stores into LDP/STP
When a Load32, Store32, LoadFloat or StoreFloat is followed by the same op
on the next or previous word through the same base, and the base can be
mapped as a pointer, emit one LDP/STP for both. A struct-copying loop runs
about 24% faster; code without such pairs is unaffected.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 11:47:17 -06:00
Henrik RydgårdandClaude Opus 5.5 d1c04d70a6 IR interpreter: Use threaded dispatch with GCC and Clang
Every op ended with a break back to one shared indirect jump, which the
CPU has to predict for every op in the program. With labels as values,
each op jumps through a table from its own site instead, which predicts
much better: an integer-heavy benchmark runs about 13% faster on an M1.
Other compilers keep the switch, and ops missing from the table fall back
to it.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 11:47:17 -06:00
Henrik RydgårdandClaude Opus 5.5 7eb371b231 IR interpreter: Merge a conditional exit with the ExitToConst after it
Blocks ending in a branch dispatch a conditional exit and then the
fallthrough ExitToConst. One op now returns either target, reading the
second from the ExitToConst, which stays behind unexecuted.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 11:47:17 -06:00
Henrik RydgårdandClaude Opus 5.5 c6aea794f6 IR interpreter: Skip ReduceVec4Flush
It avoids flushes a native backend would need, at the cost of extra
instructions (a copy of each scalar before a Vec4Scale, for instance) that
the interpreter only has to dispatch.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 11:47:17 -06:00
Henrik Rydgård 0d93194d7f Merge pull request #22356 from hrydgard/mfic-mtic
Implement mfic and mtic CPU instructions
2026-09-25 11:40:38 -06:00
Henrik Rydgård d4544e3a42 Merge pull request #22355 from hrydgard/headless-gl-offscreen
Make headless work off-screen with OpenGL on the Mac
2026-09-25 11:14:46 -06:00
Henrik RydgårdandClaude Opus 5.5 feb6caa3c4 Implement mfic and mtic
Both were no-ops, so mfic left its destination unchanged. They read and
write the interrupt enable flag that sceKernelCpuSuspendIntr/ResumeIntr
use. Only bit 0 counts for mtic, which also goes for
sceKernelCpuResumeIntr, since on hardware it's just mtic.

Adds the intr/mfic test, recorded on hardware.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 11:08:13 -06:00
Henrik Rydgård a9d63d2ee1 Merge pull request #22354 from hrydgard/tlspl-allocate
Implement _sceKernelAllocateTlspl
2026-09-25 10:36:46 -06:00
Henrik RydgårdandClaude Opus 5.5 f47269864a _sceKernelAllocateTlspl: Check user pointers, support the timeout
The third argument is a timeout pointer, as threadman.prx shows. A kernel
address from user mode is ILLEGAL_ADDR there; we used to write through it.
Also, no lookup by index: the syscall requires the exact uid.

Adds the threads/tls/allocate test, recorded on hardware.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 10:05:07 -06:00
Henrik RydgårdandClaude Opus 5.5 ac39c55c36 Implement _sceKernelAllocateTlspl
This is the syscall usersystemlib's sceKernelGetTlsAddr makes when the
thread's cached TLS address is null, as (uid, &addr, 0). Code that has to
run before usersystemlib.prx is loaded (like plugins built with a Rust SDK)
inlines sceKernelGetTlsAddr and imports this directly.

Shares the allocation with sceKernelGetTlsAddr. A thread waiting on a full
pool stores its address pointer as the wait value, so no state changes.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 10:04:44 -06:00
Henrik RydgårdandClaude Opus 5.5 2b954b6a37 docs: Replace the headless hang history with what each GPU backend does
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-25 09:47:58 -06:00