dma: don't copy out of range
[pcsx_rearmed.git] / libpcsxcore / psxdma.c
1 /***************************************************************************
2  *   Copyright (C) 2007 Ryan Schultz, PCSX-df Team, PCSX team              *
3  *                                                                         *
4  *   This program is free software; you can redistribute it and/or modify  *
5  *   it under the terms of the GNU General Public License as published by  *
6  *   the Free Software Foundation; either version 2 of the License, or     *
7  *   (at your option) any later version.                                   *
8  *                                                                         *
9  *   This program is distributed in the hope that it will be useful,       *
10  *   but WITHOUT ANY WARRANTY; without even the implied warranty of        *
11  *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the         *
12  *   GNU General Public License for more details.                          *
13  *                                                                         *
14  *   You should have received a copy of the GNU General Public License     *
15  *   along with this program; if not, write to the                         *
16  *   Free Software Foundation, Inc.,                                       *
17  *   51 Franklin Street, Fifth Floor, Boston, MA 02111-1307 USA.           *
18  ***************************************************************************/
19
20 /*
21 * Handles PSX DMA functions.
22 */
23
24 #include "psxdma.h"
25 #include "gpu.h"
26
27 #ifndef min
28 #define min(a, b) ((b) < (a) ? (b) : (a))
29 #endif
30
31 // Dma0/1 in Mdec.c
32 // Dma3   in CdRom.c
33
34 void spuInterrupt() {
35         if (HW_DMA4_CHCR & SWAP32(0x01000000))
36         {
37                 HW_DMA4_CHCR &= SWAP32(~0x01000000);
38                 DMA_INTERRUPT(4);
39         }
40 }
41
42 void psxDma4(u32 madr, u32 bcr, u32 chcr) { // SPU
43         u32 words, words_max, size;
44         u16 *ptr;
45
46         switch (chcr) {
47                 case 0x01000201: //cpu to spu transfer
48 #ifdef PSXDMA_LOG
49                         PSXDMA_LOG("*** DMA4 SPU - mem2spu *** %x addr = %x size = %x\n", chcr, madr, bcr);
50 #endif
51                         ptr = getDmaRam(madr, &words_max);
52                         if (ptr == INVALID_PTR) {
53 #ifdef CPU_LOG
54                                 CPU_LOG("*** DMA4 SPU - mem2spu *** NULL Pointer!!!\n");
55 #endif
56                                 break;
57                         }
58                         words = (bcr >> 16) * (bcr & 0xffff);
59                         size = min(words, words_max) * 2;
60                         SPU_writeDMAMem(ptr, size, psxRegs.cycle);
61                         HW_DMA4_MADR = SWAPu32((madr & ~3) + words * 4);
62                         SPUDMA_INT(words * 4);
63                         return;
64
65                 case 0x01000200: //spu to cpu transfer
66 #ifdef PSXDMA_LOG
67                         PSXDMA_LOG("*** DMA4 SPU - spu2mem *** %x addr = %x size = %x\n", chcr, madr, bcr);
68 #endif
69                         ptr = getDmaRam(madr, &words_max);
70                         if (ptr == INVALID_PTR) {
71 #ifdef CPU_LOG
72                                 CPU_LOG("*** DMA4 SPU - spu2mem *** NULL Pointer!!!\n");
73 #endif
74                                 break;
75                         }
76                         words = (bcr >> 16) * (bcr & 0xffff);
77                         size = min(words, words_max) * 2;
78                         SPU_readDMAMem(ptr, size, psxRegs.cycle);
79                         psxCpu->Clear(madr, words);
80
81                         HW_DMA4_MADR = SWAPu32(madr + words * 4);
82                         SPUDMA_INT(words * 4);
83                         return;
84
85                 default:
86                         log_unhandled("*** DMA4 SPU - unknown *** %x addr = %x size = %x\n", chcr, madr, bcr);
87                         break;
88         }
89
90         HW_DMA4_CHCR &= SWAP32(~0x01000000);
91         DMA_INTERRUPT(4);
92 }
93
94 // Taken from PEOPS SOFTGPU
95 static inline boolean CheckForEndlessLoop(u32 laddr, u32 *lUsedAddr) {
96         if (laddr == lUsedAddr[1]) return TRUE;
97         if (laddr == lUsedAddr[2]) return TRUE;
98
99         if (laddr < lUsedAddr[0]) lUsedAddr[1] = laddr;
100         else lUsedAddr[2] = laddr;
101
102         lUsedAddr[0] = laddr;
103
104         return FALSE;
105 }
106
107 static u32 gpuDmaChainSize(u32 addr) {
108         u32 size;
109         u32 DMACommandCounter = 0;
110         u32 lUsedAddr[3];
111
112         lUsedAddr[0] = lUsedAddr[1] = lUsedAddr[2] = 0xffffff;
113
114         // initial linked list ptr (word)
115         size = 1;
116
117         do {
118                 addr &= 0x1ffffc;
119
120                 if (DMACommandCounter++ > 2000000) break;
121                 if (CheckForEndlessLoop(addr, lUsedAddr)) break;
122
123                 // # 32-bit blocks to transfer
124                 size += psxMu8( addr + 3 );
125
126                 // next 32-bit pointer
127                 addr = psxMu32( addr & ~0x3 ) & 0xffffff;
128                 size += 1;
129         } while (!(addr & 0x800000)); // contrary to some documentation, the end-of-linked-list marker is not actually 0xFF'FFFF
130                                   // any pointer with bit 23 set will do.
131
132         return size;
133 }
134
135 void psxDma2(u32 madr, u32 bcr, u32 chcr) { // GPU
136         u32 *ptr, madr_next, *madr_next_p, size;
137         u32 words, words_max, words_copy;
138         int do_walking;
139
140         switch (chcr) {
141                 case 0x01000200: // vram2mem
142 #ifdef PSXDMA_LOG
143                         PSXDMA_LOG("*** DMA2 GPU - vram2mem *** %lx addr = %lx size = %lx\n", chcr, madr, bcr);
144 #endif
145                         ptr = getDmaRam(madr, &words_max);
146                         if (ptr == INVALID_PTR) {
147 #ifdef CPU_LOG
148                                 CPU_LOG("*** DMA2 GPU - vram2mem *** NULL Pointer!!!\n");
149 #endif
150                                 break;
151                         }
152                         // BA blocks * BS words (word = 32-bits)
153                         words = (bcr >> 16) * (bcr & 0xffff);
154                         words_copy = min(words, words_max);
155                         GPU_readDataMem(ptr, words_copy);
156                         psxCpu->Clear(madr, words_copy);
157
158                         HW_DMA2_MADR = SWAPu32((madr & ~3) + words * 4);
159
160                         // already 32-bit word size ((size * 4) / 4)
161                         GPUDMA_INT(words / 4);
162                         return;
163
164                 case 0x01000201: // mem2vram
165 #ifdef PSXDMA_LOG
166                         PSXDMA_LOG("*** DMA 2 - GPU mem2vram *** %lx addr = %lx size = %lx\n", chcr, madr, bcr);
167 #endif
168                         ptr = getDmaRam(madr, &words_max);
169                         if (ptr == INVALID_PTR) {
170 #ifdef CPU_LOG
171                                 CPU_LOG("*** DMA2 GPU - mem2vram *** NULL Pointer!!!\n");
172 #endif
173                                 break;
174                         }
175                         // BA blocks * BS words (word = 32-bits)
176                         words = (bcr >> 16) * (bcr & 0xffff);
177                         GPU_writeDataMem(ptr, min(words, words_max));
178
179                         HW_DMA2_MADR = SWAPu32((madr & ~3) + words * 4);
180
181                         // already 32-bit word size ((size * 4) / 4)
182                         GPUDMA_INT(words / 4);
183                         return;
184
185                 case 0x01000401: // dma chain
186 #ifdef PSXDMA_LOG
187                         PSXDMA_LOG("*** DMA 2 - GPU dma chain *** %lx addr = %lx size = %lx\n", chcr, madr, bcr);
188 #endif
189                         // when not emulating walking progress, end immediately
190                         madr_next = 0xffffff;
191
192                         do_walking = Config.GpuListWalking;
193                         if (do_walking < 0)
194                                 do_walking = Config.hacks.gpu_slow_list_walking;
195                         madr_next_p = do_walking ? &madr_next : NULL;
196
197                         size = GPU_dmaChain((u32 *)psxM, madr & 0x1fffff, madr_next_p);
198                         if ((int)size <= 0)
199                                 size = gpuDmaChainSize(madr);
200
201                         HW_GPU_STATUS &= SWAP32(~PSXGPU_nBUSY);
202                         HW_DMA2_MADR = SWAPu32(madr_next);
203
204                         // Tekken 3 = use 1.0 only (not 1.5x)
205
206                         // Einhander = parse linked list in pieces (todo)
207                         // Rebel Assault 2 = parse linked list in pieces (todo)
208                         GPUDMA_INT(size);
209                         return;
210
211                 default:
212                         log_unhandled("*** DMA 2 - GPU unknown *** %x addr = %x size = %x\n", chcr, madr, bcr);
213                         break;
214         }
215
216         HW_DMA2_CHCR &= SWAP32(~0x01000000);
217         DMA_INTERRUPT(2);
218 }
219
220 void gpuInterrupt() {
221         if (HW_DMA2_CHCR == SWAP32(0x01000401) && !(HW_DMA2_MADR & SWAP32(0x800000)))
222         {
223                 u32 size, madr_next = 0xffffff;
224                 size = GPU_dmaChain((u32 *)psxM, HW_DMA2_MADR & 0x1fffff, &madr_next);
225                 HW_DMA2_MADR = SWAPu32(madr_next);
226                 GPUDMA_INT(size);
227                 return;
228         }
229         if (HW_DMA2_CHCR & SWAP32(0x01000000))
230         {
231                 HW_DMA2_CHCR &= SWAP32(~0x01000000);
232                 DMA_INTERRUPT(2);
233         }
234         HW_GPU_STATUS |= SWAP32(PSXGPU_nBUSY); // GPU no longer busy
235 }
236
237 void psxDma6(u32 madr, u32 bcr, u32 chcr) {
238         u32 words;
239         u32 *mem = (u32 *)PSXM(madr);
240
241 #ifdef PSXDMA_LOG
242         PSXDMA_LOG("*** DMA6 OT *** %x addr = %x size = %x\n", chcr, madr, bcr);
243 #endif
244
245         if (chcr == 0x11000002) {
246                 if (mem == INVALID_PTR) {
247 #ifdef CPU_LOG
248                         CPU_LOG("*** DMA6 OT *** NULL Pointer!!!\n");
249 #endif
250                         HW_DMA6_CHCR &= SWAP32(~0x01000000);
251                         DMA_INTERRUPT(6);
252                         return;
253                 }
254
255                 // already 32-bit size
256                 words = bcr;
257
258                 while (bcr--) {
259                         *mem-- = SWAP32((madr - 4) & 0xffffff);
260                         madr -= 4;
261                 }
262                 *++mem = SWAP32(0xffffff);
263
264                 //GPUOTCDMA_INT(size);
265                 // halted
266                 psxRegs.cycle += words;
267                 GPUOTCDMA_INT(16);
268                 return;
269         }
270         else {
271                 // Unknown option
272                 log_unhandled("*** DMA6 OT - unknown *** %x addr = %x size = %x\n", chcr, madr, bcr);
273         }
274
275         HW_DMA6_CHCR &= SWAP32(~0x01000000);
276         DMA_INTERRUPT(6);
277 }
278
279 void gpuotcInterrupt()
280 {
281         if (HW_DMA6_CHCR & SWAP32(0x01000000))
282         {
283                 HW_DMA6_CHCR &= SWAP32(~0x01000000);
284                 DMA_INTERRUPT(6);
285         }
286 }