Cyrix is a registered trademark of Cyrix Corporation.
Cyrix Trademarks include: Cx5520, Display Compression Technology (DCT), MediaGX, XpressAUDIO,
XpressGRAPHICS, XpressRAM, Virtual System Architecture (VSA)
All other products mentioned herein are trademarks of their respective owners and are hereby recognized as such.
Cyrix is a wholly-owned subsidiary of National Semiconductor® Corp.
Cyrix Corporation
2703 North Central Expr essway
Richardson, Texas 75080
United States of America
Cyrix Corporation (Cyrix) reserves the right to make changes in the devices or specification described herein without
notice. Before design-in or order placement, customers are advised to verify that the information on which orders or
design activities are based is current. Cyrix warrants its products to conform to current specifications in accordance
with Cyrix’ standard warranty. Testing is performed to the extent necessary as determined by Cyrix to support this
warranty. Unless expl icitly specified by customer order r equirements, and agreed to in writing by Cyrix , not all device
characteristics are ne cess arily tested . Cyrix assu mes n o liab ility, unless specifically agreed to in wr itin g, for c ustom er’s
product design or infringement of patents or copyrights of third parties arising from use of Cyrix devices. No license,
either express o r implied, to Cyrix p aten ts, copyrights, or other intellectual p rope rty rights pertainin g to a ny m ac hin e o r
combination of Cyrix devices is hereby granted. Cyrix products are not intended for use in any medical, life saving, or
life sustaining systems. Information in this document is subject to change without notice.
iiCyrix Corporation ConfidentialGXm_db_v2.0
Page 3
MediaGX™ MMX™-Enhanced Processor
Integrated x86 Solution with MMX Support
Introduction
♦
High Performance
- Processor speeds up to 300MHz
- Write-Back cache
- Memory management with Load Store and
Memory-Read Bypassing
- Six-stage integer pipeline
- XpressRAM™ and XpressGRAPHICS™
♦
MediaGX™ MMX™-Enhanced Processor
- Processor Integrated Functions:
- Graphics Pipeline
- Memory Controller (SDRAM)
- Display Controller
- PCI Controller
- Interfaces with Cx5520 or Cx5530 I/O
Companion chip
- 320 SPGA or 352 BGA package
♦
x86 Instruction Set with MMX Support
- Compatible with MMX Technology
- Runs Windows
NT, DOS, UNIX
®
95, Windows 3.x, Windows
®
, OS/2®, Solaris®, and others
The MediaGX™ MMX™-Enhanced Processor, in
combination with the Cx5520 or Cx5530 I/O
Companion chip provides advanced video and
audio functions and permits direct interface to
memory. This high-performance 64-bit processor is
x86 instruction set compatible and supports MMX
technology.
This processor is the latest member of the Cyrix
MediaGX family, offering high performance, fully
accelerated 2D graphics, a synchronous memory
interface and a PCI bus controller, all on a single
chip. As described in separate manuals, the
Cx5520 and Cx5530 I/O Companion chips enable
the full fe atures of the MediaGX processor with
MMX support. These features include full VGA and
VESA video, 16-bit stereo sound, IDE interface,
ISA interface, SMM power management, and AT
compatibility logic. In addition, the newer Cx5530
provides an Ultra DMA/33 interface, MPEG2
assist, and is AC97 Version 2.0 compliant audio.
Write-BackFloating
Cache UnitMgmt UnitUnitPoint Unit
The Cyrix MediaGX™ MMX™-Enhanced
Processor is the latest member of the Cyrix
MediaGX processor family. It is an advanced 64-bit
x86 compatible processor offering high performance, fully accelerated 2D graphics, a 64-bit
synchronous DRAM controller and a PCI bus
controller, all on a single chip. Plus it is compatible
with MMX™ technology. This latest generation of
the MediaGX processor enables a new class of low
cost, premium performance notebook/desktop
computer designs.
The MediaGX processor core is a proven design
that offers competitive CPU performance. It has
integer and floating point execution units that are
based on sixth-generation technology. The integer
core contains a single, six-stage execution pipeline
and offers advanced features such as operand
forwarding, branch target buffers, and extensive
write buffering. A 16KB write-back L1 cache is
accessed in a unique fashion that eliminates pipeline stalls to fetch operands that hit in the cache.
In addition to the advanced CPU features, the
MediaGX processor integrates a host of functions
which are typically implemented with external
components. A full-function graphics accelerator
provides pixel processing and rendering functions.
A separate on-chip video buffer enables >30FPS
MPEG1 video playback when used together with
either the Cx5520™ or Cx5530™ I/O Companion
chip. Graphics and system memory accesses are
supported by a tightly-coupled synchronous DRAM
(SDRAM) memory controller. This tightly coupled
memory subsystem eliminates the need for an
external L2 cache.
The MediaGX processor includes Cyrix’s Virtual
System Architecture™ (VSA™) enabling XpressGRAPHICS™ and XpressAUDIO™ as well as
generic emulation capabilities. Software handler
routines for XpressGRAPHICS and XpressAUDIO
are included in the BIOS and provide compatible
VGA and 16-bit industry standard audio emulation.
XpressAUDIO technology eliminates much of the
hardware traditionally associated with audio functions.
General Features
• Packaged in:
- 352-Terminal Ball Grid Array (BGA) or
- 320-Pin Staggered Pin Grid Array (SPGA)
• 0.35-micron four layer metal CMOS process
• Split rail design (3.3V I/O and 2.9V core)
64-Bit x86 Processor
• Supports the MMX™ instruction set extension
for the acceleration of multimedia applications
• Speeds offered up to 300MHz
• 16KB unified L1 cache
• Integrated Floating Point Unit (FPU)
• Re-entrant System Management Mode (SMM)
enhanced for the Cyrix Virtual System Architecture
GXm_db_v2.0Cyrix Corporation ConfidentialPage 1
Page 18
PCI Controller
• Fixed, rotating, hybrid, or ping-pong arbitration
• Supports up to three PCI bus masters
• Synchronous CPU and PCI bus clock frequency
• Supports concurrency between PCI master and
L1 cache
Power Management
• Designed to support Cx5520/Cx5530 power
management architecture
• CPU only Suspend or full 3V Suspend
supported:
- Clocks to CPU core stopped for CPU
Suspend
- All on-chip clocks stopped for 3V Suspend
- Suspend refresh supported for 3V Suspend
Virtual Systems Architecture™
• New architecture allowing OS independent (software) virtualization of hardware functions
• Full VGA and VESA mode support
• Special "Driver level” instructions utilize internal
scratchpad for enhanced performance
Display Controller
• Video Generator (VG) improves memory efficiency for display refresh with SDRAM
• Supports a separate MPEG1 video buffer and
data path to enable video acceleration in the
Cx5520
• Supports a separate MPEG2 video buffer and
data path to enable video acceleration in the
Cx5530
• Internal palette RAM for use with the
Cx5520/Cx5530
• Direct interface to Cx5520/Cx5530 for CRT and
TFT flat panel support which eliminates need for
external RAMDAC
• Hardware frame buffer compressor/decompressor
• Provides compatible high performance legacy
VGA core functionality
Note:
• Provides Cyrix’s 16-bit XpressAUDIO™
2D Graphics Accelerator
• Graphics pipeline performance significantly
increased over previous generations by pipelining burst reads/writes
• Accelerates BitBLTs, line draw, text
• Supports all 256 raster operations
• Supports transparent BLTs
• Runs at core clock frequency
Page 2Cyrix Corporation ConfidentialGXm_db_v2.0
GUI (Graphi cal User Interface) graphics
acceleration is pure hardware.
• Hardware cursor
• Supports up to 1280x1024x8 BPP and
1024x768x16 BPP
XpressRAM™ Memory Subsystem
• Memory control/interface directly from CPU
• 64-Bit wide memory bus
• SDRAM bus operating frequency range of 66 to
100MHz
• Support for:
- Two 168-pin unbuffered DIMMs
- Up to 16 open banks simultaneously
- Single or 16-byte reads (burst length of two)
• LVTTL technology compatible
Page 19
Architecture
1
1.1Architecture
The Cyrix MediaGX MMX-Enhanced Processor
represents a new generation of x86-compatible 64bit microprocessors with sixth-generation features.
The decoupled load/store unit (within the memory
management unit) allows multiple instructions in a
single clock cycle. Other features include singlecycle execution, single-cycle instruction decode,
16KB write-back cache, and clock rates up to
300MHz. These features are made possible by the
use of advanced-process technologies and superpipelining.
The MediaGX processor has low power consumption at all clock frequencies. Where additional
power savings are required, designers can make
use of Suspend mode, Stop Clock capability, and
System Management Mode (SMM).
Write-Back
Cache Unit
C-Bus
MMU
The MediaGX processor is divided into major functional blocks (as shown in Figure 1-1):
• Integer Unit
• Floating Point Unit (FPU)
• Write-Back Cache Unit
• Memory Management Unit (MMU)
• Internal Bus Interface Unit
• Integrated Functions
Instructions are executed in the integer unit and in
the floating point unit. The cache unit stores the
most recently used data and instructions and
provides fast access to this information for the
integer and floating point units.
Integer
Unit
FPU
Internal Bus Interface Unit
X-Bus
Integrated
Functions
GXm_db_v2.0Cyrix Corporation ConfidentialPage 3
GraphicsMemoryDisplayPCI
PipelineControllerControllerController
SDRAM PortCx5520/Cx5530
(CRT/LCD TFT)
Figure 1-1 Internal Block Diagram
PCI Bus
Page 20
Architecture
1.1.1Integer Unit
The integer unit consists of:
• Instruction Buffer
• Instruction Fetch
• Instruction Decoder and Execution
The superpipelined integer unit fetches, decodes,
and executes x86 instructions through the use of a
six-stage integer pipeline.
The instruction fetch pipeline stage generates,
from the on-chip cache, a continuous high-speed
instruction stream for use by the processor. Up to
128 bits of code are read during a single clock
cycle.
Branch prediction logic within the prefetch unit
generates a predicted target address for unconditional or conditional branch instructions. When a
branch instruction is detected, the instruction fetch
stage starts loading instructions at the predicted
address within a single clock cycle. Up to 48 bytes
of code are queued prior to the instruction decode
stage.
The instruction decode stage evaluates the code
stream provided by the instruction fetch stage and
determines the number of bytes in each instruction
and the instruction type. Instructions are processed
and decoded at a maximum rate of one instruction
per clock.
The address calculation function is super-pipelined
and contains two stages, AC1 and AC2. If the
instruction refers to a memory operand, AC1 calculates a linear memory address for the instruction.
The AC2 stage performs any required memory
management functions, cache accesses, and
register file accesses. If a floating point instruction
is detected by AC2, the instruction is sent to the
floating point unit for processing.
Write-back, the last stage of the integer unit,
updates the register file within the integer unit or
writes to the load/store unit within the memory
management unit.
1.1.2Floating Point Unit
The FPU (Floating Point Unit) interfaces to the
integer unit and the cache unit through a 64-bit
bus. The FPU is x87-instruction-set compatible and
adheres to the IEEE-754 standard. Because
almost all applications that contain FPU instructions also contain integer instructions, the
MediaGX processor’s FPU achieves high performance by completing integer and FPU operations
in parallel.
FPU instructions are dispatched to the pipeline
within the integer unit. The address calculation
stage of the pipeline checks for memory management exceptions and accesses memory operands
for use by the FPU. Once the instructions and
operands have been provided to the FPU, the FPU
completes instruction execution independently of
the integer unit.
1.1.3Write-Back Cache Unit
The 16KB write-back unified cache is a
data/instruction cache and is configured as fourway set associative. The cache stores up to 16KB
of code and data in 1024 cache lines.
The MediaGX processor provides the ability to allocate a portion of the L1 cache as a scratchpad,
which is used to accelerate the Virtual Systems
Architecture algorithms as well as for some
graphics operations.
The execution stage, under control of microcode,
executes instructions using the operands provided
by the address calculation stage.
Page 4Cyrix Corporation ConfidentialGXm_db_v2.0
Page 21
Integrated Functions
1
1.1.4Memory Management Unit
The memory management unit (MMU) translates
the linear address supplied by the integer unit into
a physical address to be used by the cache unit
and the internal bus interface unit. Memory
management procedures are x86-compatible,
adhering to standard paging mechanisms.
The MMU also contains a load/store unit that is
responsible for scheduling cache and external
memory accesses. The load/store unit incorporates two performance-enhancing features:
•
Load-store reordering
memory reads required by the integer unit over
writes to external memory.
•
Memory-read bypassing
unnecessary memory reads by using valid data
from the execution unit.
that gives priority to
that eliminates
1.1.5Internal Bus Interface Unit
The internal bus interface unit provides a bridge
from the MediaGX processor to the integrated
system functions (i.e., memory subsystem, display
controller, graphics pipeline) and the PCI bus interface.
When external memory access is required, the
physical address is calculated by the memory
management unit and then passed to the internal
bus interface unit, which translates the cycle to an
X-Bus cycle (the X-Bus is a Cyrix proprietary
internal bus which provides a common interface for
all of the system modules). The X-Bus memory
cycle now is arbitrated between other pending XBus memory requests to the SDRAM controller
before completing.
In addition, the internal bus interface unit provides
configuration control for up to 20 different regions
within system memory with separate controls for
read access, write access, cacheability, and PCI
access.
1.2Integrated Functions
The MediaGX processor integrate s the foll owi ng
functions traditionally implemented using external
devices:
• High-performance 2D graphics accelerator
• Separate CRT and TFT data paths from the
display controller
• SDRAM memory controller
• PCI bridge
The processor has also been enhanced to support
Cyrix’s proprietary Virtual System Architecture
(VSA) implementation.
The MediaGX processor implements a Unified
Memory Architecture (UMA). By using Cyrix’s
Display Compression Technology™ (DCT), the
performance degradation inh erent in tra di tio nal
UMA systems is elimi nated.
1.2.1Graphics Accelerator
The graphics accelerator is a full-featured GUI
(Graphical User Interface) accelerator. The
graphics pipeline implements a bitBLT engine for
frame buffer bitBLTs and rectangular fills. Additional instructions in the integer unit may be
processed, as the bitBLT engine assists the CPU in
the bitBLT operations that take place between
system memory and the frame buffer. This combination of hardware and software is used by the
display driver to provide very fast transfers in both
directions between system memory and the frame
buffer. The bitBLT engine also draws randomlyoriented vectors, and scanlines for polygon fill. All
of the pipeline operations described in the following
list can be applied to any bitBLT operation.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 5
Page 22
Integrated Functions
•
Pattern Memory.
monochrome, or 8x1 color pattern.
•
Color Expansion.
bitmaps to full-depth 8- or 16-bit colors.
•
Transparency.
ground pixels for transparent text.
•
Raster Operations.
combines source, destination, and pattern
bitmaps.
Render with 8x8 dither, 8x8
Expand monochrome
Suppresses drawing of back-
Boolean operation
1.2.2Display Controller
The display port is a direct interface to the
Cx5520/Cx5530 which drives a TFT flat panel
display, LCD panel, or a CRT display.
The display controller (video generator) retrieves
image data from the frame buffer region of
memory, performs a color-look-up if required,
inserts the cursor overlay into the pixel stream,
generates display timing, and formats the pixel
data for output to a variety of display devices. The
display controller contains Display Compression
Technology (DCT) that allows the MediaGX
processor to refresh the display from a
compressed copy of the frame buffer. DCT typically
decreases the screen-refresh bandwidth requirement by a factor of 15 to 20, further minimizing
bandwidth contention.
1.2.3XpressRAM™ Memory
Subsystem
The memory controller drives a 64-bit SDRAM port
directly. The SDRAM memory array contains both
the main system memory and the graphics frame
buffer. Up to four module banks of SDRAM are
supported. Each module bank will have two or four
component banks depending on the memory size
and organization. The maximum configuration is
four module banks with four component banks
providing a total of 16 open banks. The maximum
memory size is 1GB.
The memory controller handles multiple requests
for memory data from the MediaGX processor, the
graphics accelerator and the display controller. The
memory controller contains extensive buffering
logic that helps minimize contention for memory
bandwidth between graphics and CPU re que sts.
The memory controller cooperates with the internal
bus controller to determine the cacheability of all
memory references.
1.2.4PCI Controller
The MediaGX processor incorporates a full-function PCI interface module that includes the PCI
arbiter. All accesses to external I/O devices are
sent over the PCI bus, although most memory
accesses are serviced by the SDRAM controller.
The Internal Bus Interface Unit contains address
mapping logic that determines if memory accesses
are targeted for the SDRAM or for the PCI bus.
Page 6Cyrix Corporation ConfidentialGXm_db_v2.0
Page 23
System Designs
1
1.3System Designs
The Cyrix MediaGX™ Integrated Subsystem with
MMX™ support consists of two chips, the
MediaGX MMX-Enhanced Processor and the
Cx5520™ or Cx5530™ I/O Companion. The
subsystem provides high performance using 64-bit
x86 processing. The two chips integrate video,
audio and memory interface functions normally
performed by external hardware.
As described in separate manuals, the Cx5520 and
Cx5530 enable the full features of the MediaGX
processor with MMX support. These features
MD[63:0]
SDRAM
Clocks
USB
(2 Ports)
Speakers
CD
ROM
Audio
AC97
CODEC
System
Clocks
Cx55x0™
I/O Companion
include full VGA and VESA video, 16-bit stereo
sound, IDE interface, ISA interface, SMM power
management, and AT compatibility logic. In addition, the newer Cx5530 provides an Ultra DMA/33
interface, MPEG2 assist, and AC97 Version 2.0
compliant audio.
Figure 1-2 shows a basic block system diagram
(refer to Figure 2-4 on page 34 for detailed
subsystem interconnection signals). It includes the
Cyrix Cx9210™ Dual-Scan Flat Panel Display
Controller for designs that need to interface to a
DSTN panel (instead of TFT panel).
SDRAM
Port
MediaGX™
MMX™-Enhanced
Processor
Serial
Packet
PCI Interface
Graphics Data
Video Data
Analog RGB
Digital RGB
IDE Control
YUV Port
(Video)
RGB Port
(Graphics)
PCI Bus
(to TFT or DSTN Panel)
CRT
TF T
Panel
Microphone
GPIO
DC-DC & Battery
Dashed lines denote Cx5520 application.
Note:
14.31818
MHz Crystal
ISA Bus
Super
I/O
BIOS
IDE
Devices
Cx9210™
DSTN
Controller
DSTN Panel
Figure 1-2 System Block Diagram
GXm_db_v2.0Cyrix Corporation ConfidentialPage 7
Page 24
System Designs
The Cx9210 converts the digital RGB output of a
Cx5520 or Cx5530 I/O Companion chip to the
digital output suitable for driving a dual-scan color
STN (DSTN) flat panel LCD. It connects to the
digital RGB output of a MediaGX™ processor or
Cx55
x
0 and drives the graphics data onto a dual-
Pixel Data
MediaGX™
Processor
18
x
Cx55
0™
I/O
Companion
Pixel Port
Control
Figure 1-3 Cx9210 Interface System Diagram
scan flat panel LCD. It can drive all standard dualscan color STN flat panels up to 1024x768 resolution. Figure 1-3 shows an example of a Cx9210
interface in a typical MediaGX Integrated
Subsystem.
23
4
Cx9210™
DSTN
Controller
316
Clocks
Panel Data
3
Control
Addr Control
DRAM Data
Addr Control
DRAM Data
DSTN
LCD
13
16
13
16
LCD Power
DRAM A
256K x 16
DRAM B
256K x 16
Page 8Cyrix Corporation ConfidentialGXm_db_v2.0
Page 25
2Signal Definitions
MediaGX™ MMX™-Enhanced Processor
Integrated x86 Solution with MMX™ Support
This section describes the external interface of the
MediaGX processor. Figure 2-1 shows the signals
SYSCLK
CLKMODE[2:0]
RESET
System
Interface
Signals
PCI
Interface
Signals
INTR
IRQ13
SMI#
SUSP#
SUSPA#
SERIALP
AD[31:0]
C/BE[3:0]#
PAR
FRAME#
IRDY#
TRDY#
STOP#
LOCK#
DEVSEL#
PERR#
SERR#
REQ[2:0]#
GNT[2:0]#
MediaGX™
MMX™-Enhanced
Processor
organized by their functional interface groups
(internal test and electrical pins are not shown).
The MediaGX MMX-Enhanced processor is available in two packages, a 352 BGA package and a
320 SPGA package.
The pin assignment for the 352 BGA is shown in
Figure 2-2. Tables 2-2 and 2-3 are pin assignment
lists for the 352 BGA sorted by pin number and
alphabetically by signal name, respectively.
The 320 SPGA pin assignment is shown in Figure
2-3. Tables 2-4 and 2-5 are pin assignment lists for
the 320 SPGA sorted by pin number and alphabetically by signal name, respectively.
Abbreviations used in Tables 2-4 through 2-5 are
shown in Ta ble 2-1.
Section 2.2 on page 21 describes the signals which
are grouped according their functional group.
PU/PD indicates pin is
internally connected to
a 20-kohm pull-up/
down resistor
Page 20Cyrix Corporation ConfidentialGXm_db_v2.0
Page 37
2.2Signal Descriptions
2.2.1System Interface Signals
Signal Descriptions
2
BGA
Signal Name
SYSCLKP26V34ISystem Clock
CLKMODE[2 :0]M1, L1, M3G3, R2,
Pin No.
SPGA
Pin No.TypeDescription
System Clock runs synchronously with the PCI bus. The internal clock of the M edi aG X p r oc es sor is g enerated by an int erna l
PLL which multiplies the SYSCLK input and can run up to eight
times faster . The SYSCLK to core clock multiplier is con fig ured
using the CLKMOD[2:0] inputs.
The SYSCLK input is a fixed frequency which can only be
stopped or varied when the MediaGX processor is in a full 3V
Suspend. (Section 6.4 “3-Volt Suspend Mode” on page 203 for
details regarding this mode.)
IClock Mode
S1
These signals are u sed to set th e core c lock multi plier. The PCI
clock "SYSCLK" is multiplied by the value programmed by
CLKMODE[2:0] to generate the MediaGX processor’s core
clock. CLKMODE2 is valid only for MediaGX MMX-Enhanced
processor revision 4.0 and up. The value read from DIR1
(Device ID Register 1, refer to page 56) affects the definition of
the CLKMOD E pins.
If DIR1 = 30h -33h then CLK M ODE[1:0]:
00 = SYSCLK multiplied by 4 (Test mode only)
01 = SYSCLK multiplied by 6
10 = SYSCLK multiplied by 7
11 = SYSCLK multiplied by 5
If DIR1 = 34h-4Fh then CLKMODE[1:0]:
00 = SYSCLK multiplied by 4 (Test mode only)
01 = SYSCLK multiplied by 6
10 = SYSCLK multiplied by 7
11 = SYSCLK multiplied by 8
If DIR1 > or = 50h then CLKMODE[2:0]:
000 = SYSCLK multiplied by 4 (Test mode only)
001 = SYSCLK multiplied by 10
010 = SYSCLK multiplied by 9
01 1 = SYSCLK multi pli ed by 5
100 = SYSCLK multiplied by 4
101 = SYSCLK multiplied by 6
1 10 = SYSCLK multi pli ed by 7
111 = SYSCLK multiplied by 8
GXm_db_v2.0Cyrix Corporation ConfidentialPage 21
Page 38
Signal Descriptions
2.2.1System Interface Signals (cont.)
BGA
Signal Name
RESETJ3M2IReset
INTRB18D24I(Maskable) Interrupt Request
IRQ13C22C31OInterrupt Request Level 13
Pin No.
SPGA
Pin No.TypeDescription
RESET aborts all operations in progress and places the
MediaGX processor into a reset state. RESET forces the CPU
and peripheral functions to begin executing at a known state.
All data in the on-chip cache is invalidated.
RESET is an asynchronous input but must meet specified
setup and hold times to guarantee recognition at a particular
clock edge. This input is typically generated during the PowerOn-Reset sequence.
Note: Warm Reset does not re qui re a n in put o n the Me dia GX
processor since the function is virtualized using SMM.
INTR is a level-sensitive input that causes the MediaGX processor to Suspend execution of the current instruction stream
and begin execution of an interrupt service routine. The INTR
input can be masked through the Flags Register IF bit. (See
Table 3-4 "EFLAGS Register" on page 45 for bit definitions.)
IRQ13 is asserted if an on-chip floating point error occurs.
When a floating point error occurs, the MediaGX processor
asserts the IRQ13 pin. The floating point interrupt handler then
performs an OUT instruction to I/O address F0h or F1h. The
MediaGX processor accepts either of these cycles and clears
the IRQ13 pin.
Refer to Section 3.4.1 “I/O Address Space” on page 65 for further information on IN/OUT instructions.
SMI#C19B28ISystem Management Interrupt
SMI# is a level-sensitive interrupt. SMI# puts the MediaGX processor into System Management Mode (SMM).
Page 22Cyrix Corporation ConfidentialGXm_db_v2.0
Page 39
2.2.1System Interface Signals (cont.)
Signal Descriptions
2
BGA
Signal Name
SUSP#H2
SUSPA#E2H4OSuspend Acknowledge
Pin No.
(PU)
SPGA
Pin No.TypeDescription
M4
(PU)
ISuspend Request
This signal is used to request that the MediaGX processor
enter Suspend mode. After recognition of an active SUSP#
input, the processor completes execution of the current instruction, any pending decoded instructions and associated bus
cycles. SUSP# is ignored following RESET# and is enabled by
setting the SUSP bit in CCR2. (See Table 3-11 "Configuration
Registers" on page 52 for CCR2 bit definitions.)
Since the MediaGX processor includes s y stem logic functions
as well as the CPU core, there are special modes designed to
support the differe nt power manag ement states as sociated with
APM, ACPI, and portable designs. The part can be configured
to stop only the CPU core clocks, or all clocks. When all clocks
are stopped, the external clock can also be stopped. (See Section 6 “Power Management” on page 201 for more details
regarding power management states.)
This pin is internally connected to a 20-kohm pull-up resistor.
SUSP# is pulled up when not active.
Suspend Acknowledge indicates that the MediaGX processor
has entered low-power Suspend mode as a result of SUSP#
assertion or executi on of a HALT instruction. SUSP A# floats following RESET# and is enabled by setting the SUSP bit in
CCR2. (See Table 3-11 "Configuration Registers" on page 52
for CCR2 bit definitions.)
The SYSCLK input may be stopped after SUSPA# has been
asserted to further reduce power consumption if the system is
configured for 3V Suspend mode . (Sectio n 6.4 “3-Volt Suspend
Mode” on page 203 for details regarding this mode.)
SERIALPL3Q1OSerial Packet
Serial Packet is the s ing le wire s erial-tra ns mi ssion s ig nal to th e
Cx5520 chip. The clock used for this interface is the PCI clock
(SYSCLK). This interface carries packets of miscellaneous
information to the chipset to be used by the VSA software handlers.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 23
Page 40
Signal Descriptions
2.2.2PCI Interface Signals
BGA
Signal Name
AD[31:0]Refer
C/BE[3:0]#D5,
Pin No.
to T able
2-3
B8,
C13,
A15
SPGA
Pin NoTypeDescription
Refer
to T able
2-5
B6, B12,
B18,
E21
I/OMultiplexed Address and Data
Addresses and data are multiplexed on the same PCI pins. A
bus transaction consists of an address phase in the cycle in
which FRAME# is asserted followed by one or more data
phases. During the ad dress phase , AD[3 1:0] co ntain a phys ical
32-bit address. For I/O, this is a byte address, for configuration
and memory it is a DWORD address. During data phases,
AD[7:0] contain the least significant byte (LSB) and AD[31:24]
contain the most significant byte (MSB). Write data is stable
and valid when IRDY# is asserted and read data is stable and
valid when TRDY# is asserted. Data is transferred during those
SYSCLKS where both IRDY# and TRDY# are asserted.
I/OMultiplexed Command and Byte Enables
Bus command and byte enables are multiplexed on the same
PCI pins. During the address phase of a transaction when
FRAME# is active, C/BE[3:0]# define the bu s command. Durin g
the data phase C/BE[3:0]# are used as byte enables. The byte
enables are val id for t he entire data p hase an d deter mine whi ch
byte lanes carry meaningful data. C/BE0# applies to byte 0
(LSB) and C/BE3# applies to byte 3 (MSB).
The command encoding and types are listed below.
0000 = Interrupt Acknowledge
Parity generation is required by all PCI agents: the master
drives P AR for a ddress and w rite-data ph ases, the target drive s
PAR for read-data phases. Parity is even across AD[31:0] and
C/BE[3:0]#.
For address phases, PAR is stable and valid one SYSCLK after
the address phase. It has the same timing as AD[31:0] but
delayed by one SYSCLK.
For data phases, PAR is stable and valid one SYSCLK after
either IRDY# is asserted on a write transaction or after TRDY#
is asserted on a read transaction. Once PAR is valid, it remains
valid until one SYSCLK after the completion of the data phase.
(Also see PERR#.)
C13
(PU)
D14
(PU)
B14
(PU)
s/t/sFrame
Cycle Frame is driven by the current master to indicate the
beginning and duration of an access. FRAME# is asserted to
indicate a bus transaction is beginning. While FRAME# is
asserted, data transfers continue. When FRAME# is deasserted, the transaction is in the final data phase.
This pin is internally connected to a 20-kohm pull-up resistor.
s/t/sInitiator Ready
Initiator Ready is asserted to indicate that the bus master is
able to complete the current data phase of the transaction.
IRDY# is used in conjunction with TRDY#. A data phase is
completed on any SYSCLK in which both IRDY# and TRDY#
are sampled asserted. During a write, IRDY# indicates valid
data is present on AD[31:0]. During a read, it in dicat es the ma ster is prepared to accept data. Wait cycles are inserted until
both IRDY# and TRDY# are asserted together.
This pin is internally connected to a 20-kohm pull-up resistor.
s/t/sTarget Ready
TRDY# is asserted to indicate that the target agent is able to
complete the current data phase of the transaction. TRDY# is
used in conjunction with IRDY#. A data phase is complete on
any SYSCLK in which both TRDY# and IRDY# are sampled
asserted. During a read, TRDY# indicates that valid data is
present on AD[31:0]. During a write, it indicates the target is
prepared to accept data. Wait cycles are inserted until both
IRDY# and TRDY# are asserted together.
This pin is internally connected to a 20-kohm pull-up resistor.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 25
Page 42
Signal Descriptions
2.2.2PCI Interface Signals (cont.)
BGA
Signal Name
STOP#C11
LOCK#B11
DEVSEL#A9
Pin No.
(PU)
(PU)
(PU)
SPGA
Pin NoTypeDescription
A15
(PU)
B16
(PU)
E15
(PU)
s/t/sTarget Stop
STOP# is asserted to indicate that the current target is requesting the master to stop the current transaction. This signal is
used with DEVSEL# to indicate retry, disconnect or target
abort. If STOP# is sam ple d a cti ve whi le a m ast er, FRAME# will
be deasserted and the cycle stopped within three SYSCLK
cycles. As an input, STOP# can be asserted in the following
cases. 1) If a PCI master tries to acce ss memory that has bee n
locked by another mast er . This conditi on is detected if FRAME#
and LOCK# are asserted during an addr es s phas e. 2) ST O P#
will also be asserted if the PCI write buffers are full or if a previously buffered cycle has not completed. 3) Finally, STOP# can
be asserted on read cycles that cross cache line boundaries.
This is conditional based upon the programming of bit 1 in PCI
Control Function 2 Register. (See Table 4-38 "PCI Configuration Registers" on page 179 for programming details.)
This pin is internally connected to a 20-kohm pull-up resistor.
s/t/sLock Operation
LOCK# indicates an ato mi c o peration that may re qui re m ul tip le
transactions to complete. When LOCK# is asserted, nonexclusive transactions may pr oceed to an address that is not currently locked (at least 16 bytes must be locked). A grant to start
a transaction on PCI does not guarantee control of LOCK#.
Control of LOCK# is obtained under it own protocol in conjunction with GNT#. It is possible for different agents to use PCI
while a single master retains ownership of LOCK#. The arbiter
can implement a co mp lete system lock. In this mode, if LOCK#
is active, no other master can gain access to the system until
the LOCK# is deasserted.
This pin is internally connected to a 20-kohm pull-up resistor.
s/t/sDevice Select
DEVSEL# indicates that the driving device has decoded its
address as the target of the current access. As an input,
DEVSEL# indicates whether any device on the bus has been
selected. DEVSEL# will also be driven by any agent that has
the ability to accept cycles on a subtractive decode basis. As a
master, if no DEVSEL# is detec ted within and up to the subtra ctive decode clock, a master abort cycle will result expect for
special cycles which do not expect a DEVSEL# returned.
This pin is internally connected to a 20-kohm pull-up resistor.
Page 26Cyrix Corporation ConfidentialGXm_db_v2.0
Page 43
2.2.2PCI Interface Signals (cont.)
Signal Descriptions
2
BGA
Signal Name
PERR#A11
SERR#C12
REQ[2:0]#D3,
Pin No.
(PU)
(PU)
H3,
E3
(PU)
SPGA
Pin NoTypeDescription
D16
(PU)
A17
(PU)
E3,
K2,
E1
(PU)
s/t/sParity Error
PERR# is used for repor ting of data parity errors during all PCI
transactions except a Special Cycle. The PERR# line is driven
two SYSCLKs after the data in which the error was detected.
This is one SYSCLK after the PAR that is attached to the data.
The minimum duration of PE RR# is one SYSCLK for eac h data
phase in which a data parity error is detected. PERR# must be
driven high for one SYSCLK before being tristated. A target
asserts PERR# on write cycles if it has claimed the cycle with
DEVSEL#. The master asserts PERR# on read cycles.
This pin is internally connected to a 20-kohm pull-up resistor.
ODSystem Error
System Error may be asserted by any ag ent for reporting er rors
other than PCI parity. The intent is to have the PCI central
agent assert NMI to the processor. When the Parity Enable bit
is set in the Memory Controller Configuration register, SERR#
will be asserted upon detecting a parity error on read operations from DRAM.
IRequest Lines
Request indicates t o the arbite r that an agen t desires use of the
bus. Each master has its own REQ# line. REQ# priorities are
based on the arbitration scheme chosen.
Each of these pins are internally connected to a 20-kohm pullup resistor.
GNT[2:0]#E1,
F2,
D1
GXm_db_v2.0Cyrix Corporation ConfidentialPage 27
H2,
K4,
F2
OGrant Lines
Grant indicates to the requesting master that it has been
granted access to the bu s. Ea ch ma ster has its ow n GNT# line.
GNT# can be pulled away at any time a higher REQ# is
received or if the master does not begin a cycle within a minimum period of time (16 SYSCLKs).
Page 44
Signal Descriptions
2.2.3Memory Controller Interface Signals
BGA
Signal Name
Note: The memory controller interface supports two types of memory configurations: SDRAM modules on the sys-
tem board and JEDEC DIMM c onn ectors. Refer to Section 4.3 “M em ory C o ntro lle r” on p age 116 for detailed
information regarding signal connections.
MD[63:0]Refer
MA[12:0]Refer
BA[1:0]AD26,
CS[3:0]#AE23,
RASA#,
RASB#
CASA#,
CASB#
WEA#,
WEB#
Pin No.
to T able
2-3
to T able
2-3
AD25
V25,
AD23,
V26
W24,
W25
P25,
R26
R25,
R24
SPGA
Pin No.TypeDescription
Refer
to T able
2-5
Refer
to T able
2-5
AJ33,
AK36
AK32,
Z34,
AN33,
AA35
AB36,
AB34
W37,
X36
W33,
W35
I/OMemory Data Bus
The data bus lines driven to/from system memory.
OMemory Address Bus
The multiplexed ro w/column address li ne s driven to the s ys tem
memory.
Supports 256Mbit SDRAM.
OBank Address Bits
These bits are used to select the component bank within the
SDRAM.
OChip Selects
The chip selects are used to select the module bank within the
system memory. Each chip select corresponds to a specific
module bank.
If CS# is high, the bank(s) do not respond to RAS#, CAS#,
WE# until the bank is selected again.
ORow Address Strobe
RAS#, CAS#, WE# and CKE are encoded to support the different SDRAM commands. RASA# is used with CS[1: 0]# . RASB#
is used with CS[3:2]#.
OColumn Address Strobe
RAS#, CAS#, WE# and CKE are encoded to support the different SDRAM commands. CASA# is used with CS[1: 0]# . CASB#
is used with CS[3:2]#.
OWrite Enable
RAS#, CAS#, WE# and CKE are encoded to support the different SDRAM commands. WEA# is used with CS[1:0]#. WEB# is
used with CS[3:2]#.
Page 28Cyrix Corporation ConfidentialGXm_db_v2.0
Page 45
2.2.3Memory Controller Interface Signals (cont.)
Signal Descriptions
2
BGA
Signal Name
DQM[7:0]Refer
CKEA,
CKEB
SDCLK[3:0]AE4,
SDCLK_INAE8AK12ISDRAM Clock Input
SDCLK_OUTAF8AL13OSDRAM Clock Output
Pin No.
to T able
2-3
AF24,
AD16
AF5,
AE5,
AF4
SPGA
Pin No.TypeDescription
Refer
to T able
2-5
AL33,
AN23
AM8,
AK10,
AL7,
AK8
OData Mask Control Bits
During memory read cycles, these outputs control whether the
SDRAM output buffers are driven on the MD bus or not. All
DQM signals are asserted during read cycles.
During memory write cycles, these outputs control whether or
not MD data will be written into the SDRAM.
DQM[7:0] connect directly to the DQM7-0 pins of each connector.
OClock Enable
These signals are used to enter Suspend/power-down mode.
When CKE goes low when no read or write cycle is in progress,
the SDRAM enters power-down mode. To ensure that SDRAM
data remains valid, the self-refresh command is executed. To
exit this mode, drive CKE high.
For normal operation, CKE should be held high.
OSDRAM Clocks
The SDRAM samples all the control, address, and data using
these clocks. SDCLK[3:0] should be used with CS[3:0]#,
respectively, for the Suspend mode to function correctly.
The MediaGX proces sor sam ples the memo ry read d ata on t his
clock. Works in conjunction with the SDCLK_OUT signal.
This output is routed back to SDCLK_IN. The board designer
should vary the length of the board trace to control skew
between SDCLK_IN and SDCLK.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 29
Page 46
Signal Descriptions
2.2.4Video Interface Signals
BGA
Signal Name
PCLKAC1AJ1OPixel Port Clock
VID_CLKP1V4OVideo Clock
DCLKAB1AD4IDotclock
CRT_HSYNCW2AD2OCRT Horizontal Sync
CRT_VSYNCAA3AH2OCRT Vertical Sync
FP_HSYNCL2R4OFlat Panel Horizontal Sync
Pin No
SPGA
Pin NoTypeDescription
Pixel Port Clock rep resents t he pixel dotcloc k or a 2x multipl e of
the dotclock for some 16-bit-per-pixel modes. It determines the
data transfer rate from the MediaGX processor to the
Cx5520/Cx5530.
Video Clock represents the video port clock to the
Cx5520/Cx5530. This pin is only used if the Video Port is
enabled.
The DCLK input is driven from the Cx5520/Cx5530 and represents the pixel dot cloc k. In some cases, such as when displaying 16 BPP data with an eight-bit-graphics pixel port, this clock
will actually be a 2x multiple of th e dotclock.
CRT Horizontal Sync establishes the line rate and horizontal
retrace interval for an attached C RT. The polarity is programmable and depends on the display mode.
CRT V ertic al Sync es tablis hes th e screen re fresh rat e and vertical retrace interval for an attached CRT. The polarity is programmable and depends on the dis play mode.
Flat Panel Horizontal Sync establishes the line rate and horizontal retrace interval for a TFT display. Polarity is programmable and depends on the display mode.
This signal is an input to the Cx5520/Cx5530. The
Cx5520/Cx5530 re-drives this signal to the flat panel.
If no flat panel is used in the system, this signal does not need
to be connected.
FP_VSYNCJ1P2OFlat Panel Vertical Sync
Flat Panel V ertical Sync establ ishes the screen refre sh rate and
vertical retrace interval for a TFT display. Polarity is programmable and depends on the display mode.
This signal is an input to the Cx5520/Cx5530. The
Cx5520/Cx5530 re-drives this signal to the flat panel.
If no flat panel is used in the system, this signal does not need
to be connected.
Page 30Cyrix Corporation ConfidentialGXm_db_v2.0
Page 47
2.2.4Video Interface Signals (cont.)
Signal Descriptions
2
BGA
Signal Name
ENA_DISPAD5AM6ODisplay Enable
VID_RDYAD1AK2IVideo Ready
VID_VALM2S3OVideo Valid
VID_DA TA[7:0]Refer
PIXEL[17:0]Refer
Pin No
to T able
2-3
to T able
2-3
SPGA
Pin NoTypeDescription
Display Enable indicates the active display portion of a scan
line to the Cx5520/Cx5530.
In a Cx5520/Cx5530-ba sed sys tem, this signal i s required to be
connected even if there is no TFT panel in the system.
This input signal indicates that the video FIFO in the
Cx5520/Cx5530 is ready to receive more data.
VID_VAL qualifies valid video data to the Cx5520/Cx5530.
Refer
to T able
2-5
Refer
to T able
2-5
OVideo Data Bus
When the Video Port is enabled, this bus drives Video (Y-U-V)
data synchronous to the VID_CLK output.
OGraphics Pixel Data Bus
This bus drives graphics pixel data synchronous to the PCLK
output.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 31
Page 48
Signal Descriptions
2.2.5Power, Ground, and No Connect Signals
BGA
Signal Name
VOLDETAC5AM36OVoltage Detect
VSSRefer
VCC2Refer
VCC3Refer
NC--Q5, X2,
Pin No.
to T able
2-3
(T ot al of
71)
to T able
2-3
(T ot al of
32)
to T able
2-3
(T ot al of
32)
SPGA
Pin No.TypeDescription
In early schematic re visions this pin w as id entified as VOLDET.
However, in the production version this pin is a "no connect"
and should be left disconnected.
Refer
to T able
2-5
(T ot al of
50)
Refer
to T able
2-5
(T ot al of
32)
Refer
to T able
2-5
(T ot al of
18)
Z2
GNDGround Connection
PWR2.9V (nominal) Core Power Connection
PWR3.3V (nominal) I/O Power Connection
No Connection
A line designated as NC should be left disconnected.
Page 32Cyrix Corporation ConfidentialGXm_db_v2.0
Page 49
2.2.6Cyrix Internal Test and Measurement Signals
Signal Descriptions
2
BGA
Signal Name
FLT#AC2AJ3IFloat
RW_CLKAE6AL11ORaw Clock
TEST[3:0]B22,
TCLKJ2
TDID2
TDOF1J1OTest Data Output
TMSH1
Pin No.
A23,
B21,
C21
(PU)
(PU)
(PU)
SPGA
Pin No.TypeDescription
Float Outputs forces the Me diaGX p rocessor t o float a ll outpu ts
in the high-impedance state and to enter a power-down state.
This output is the MediaGX processor clock. This debug signal
can be used to verify clock operation.
D28,
B32,
D26,
A33
P4
(PU)
F4
(PU)
N3
(PU)
OSDRAM Test Outputs
These outputs are used for internal debug only.
ITest Clock
JTAG test clock.
This pin is internally connected to a 20-kohm pull-up resistor.
ITest Data Input
JTAG serial test-data input.
This pin is internally connected to a 20-kohm pull-up resistor.
JTAG serial test-data output.
ITest Mode Select
JTAG test-mode select.
This pin is internally connected to a 20-kohm pull-up resistor.
TESTF3
(PD)
TDPE24F36OThermal Diode Positive
TDND26E37OThermal Diode Negative
GXm_db_v2.0Cyrix Corporation ConfidentialPage 33
J5
(PD)
ITest
Test-mode input.
This pin is intern al ly c onn ec ted to a 2 0-k ohm pul l-do w n res is tor.
TDP is the positive terminal of the thermal dio de on the die. The
diode is used to do thermal characterization of the device in a
system. This signal works in conjunction with TDN.
TDN is the negative terminal of the thermal diode on the die.
The diode is used to do thermal characterization of the device
in a system. This signal works in conjunction with TDP.
Page 50
Subsystem Signal Connections
2.3Subsystem Signal Connections
As previously stated, the MediaGX Integrated
Subsystem with MMX support con sis ts of two
chips. The MediaGX MMX-Enhanced Processor
and either the Cx5520 or Cx5530 I/O Companion
Chip. Figure 2-4 shows the signal connections
between the processor and the I/O companion
chip.
Figure 2-6 shows layout recommendations for splitting the power plane between 2.9 (V
(V
) volts in the BGA package. The illustration
CC3
) and 3.3
CC2
assumes there is one power plane, and no components on the back of the board.
3.3V Plane
(VCC3)
3.3V Plane
(VCC3)
1
A
2.9V Plane
(VCC2)
26
A
MediaGX™
MMX™-Enhanced
Processor
352 BGA - Top View
2.9V Plane
(VCC2)
AF
1
Legend
= High frequency capacitor
= 220µF, low ESR capacitor
= 3.3V connection
= 2.9V connection
Figure 2-6 BGA Recommended Split Power Plane and Decoupling
Page 36Cyrix Corporation ConfidentialGXm_db_v2.0
3.3V Plane
(VCC3)
AF
26
Page 53
Power Planes
2
Figure 2-7 shows layout recommendations for splitting the power plane between 2.9 (V
137
A
) and 3.3
CC2
3.3V Plane
(VCC3)
2.9V Plane
(VCC2)
MediaGX™
MMX™-Enhanced
3.3V Plane
(VCC3)
Processor
320 SPGA - Top View
) volts in the SPGA package.
(V
CC3
A
3.3V Plane
(VCC3)
2.9V Plane
(VCC2)
Legend
AN
137
= High frequency capacitor
= 220µF, low ESR capacitor
= 3.3V connection
= 2.9V connection
To 2.9V
Regulator
3.3V Plane
(VCC3)
Where signals cross plane splits, it is recommended to include
Note:
AC decoupling between planes with 47pF capacitors.
AN
Figure 2-7 SPGA Recommended Split Power Plane and Decoupling
GXm_db_v2.0Cyrix Corporation ConfidentialPage 37
Page 54
Power Planes
Page 38Cyrix Corporation ConfidentialGXm_db_v2.0
Page 55
MediaGX™ MMX™-Enhanced Processor
Integrated x86 Solution with MMX™ Support
3Processor Programming
This section describes the internal operations of
the MediaGX MMX-Enhanced processor from a
programmer’s point of view. It includes a description of the traditional “core” processing and FPU
operations. The integrated function registers are
described at the end of this chapter.
The primary register sets within the processor core
include:
• Application Register Set
• System Register Set
• Model Specific Register Set
• Floating Point Unit Register Set.
The initialization of the major registers within in
core are shown in Table 3-1 on page 40.
The integrated function sets are located in main
memory space and include:
• Internal Bus Int erface Unit Register Se t
• Graphics Pipeline Register Set
• Display Controller Register Set
• Memory Controller Register Set
• Power Management Register Set
3.1 Core Processor Initialization
The MediaGX processor is initialized when the
RESET signal is asserted. The processor is placed
in real mode and the registers listed in Table 3-1
are set to their initialized values. RESET invalidates and disables the CPU cache, and turns off
paging. When RESET is asserted, the CPU terminates all local bus activity and all internal execution. During the entire time that RESET is asserted,
the internal pipeline is flushed and no instruction
execution or bus activity occurs.
Approximately 150 to 250 external clock cycles
after RESET is deasserted, the processor begins
executing instructions at the top of physical
memory (address location FFFF FFF0h). The actual
time depends on the clock scaling in use. Also, an
additional 2
test is requested.
Typically, an intersegment jump is placed at FFFF
FFF0h. This instruction will force the processor to
begin execution in the lowest 1MB of address
space.
The following table, Table 3-1, lists the core registers and illustrates how they are initialized.
LDTRLocal Descriptor Table Re
TRTask Re
CR0Machine Status Word6000 0010hSee Table 3-7 on pa
CR2Control Re
CR3Control Re
CR4Control Re
CCR1Confi
CCR2Confi
CCR3Confi
CCR7Confi
SMAR0SMM Address 000hSee Table 3-11 on pa
SMAR1SMM Address 1 00hSee Table 3-11 on pa
SMAR2SMM Address 2 / SMAR Size00hSee Table 3-11 on pa
DIR0Device Identification 04xhDevice ID and reads back initial CPU clock-
DIR1Device Identification 1xxhSteppin
DR7Debu
Note:
x = Undefined value
s0000 0002hSee Table 3-4 on page 45 for bit definitions.
ment0000hBase address set to 0000 0000h.
mentF000hBase address set to FFFF 0000h.
ment0000hBase address set to 0000 0000h.
ment0000hBase address set to 0000 0000h.
ment0000hBase address set to 0000 0000h.
ment0000hBase address set to 0000 0000h.
ister
Re
Re
ister
isterxxxxh
ister 2xxxx xxxxhSee Table 3-7 on page 48 for bit definitions.
ister 3xxxx xxxxhSee Table 3-7 on page 48 for bit definitions.
ister 40000 0000hSee Table 3-7 on page 48 for bit definitions.
uration Control 100hSee Table 3-11 on page 52 for bit definitions.
uration Control 200hSee Table 3-11 on page 52 for bit definitions.
uration Control 300hSee Table 3-11 on page 53 for bit definitions.
uration Control 700hSee Table 3-11 on page 54 for bit definitions.
Register 70000 0400hSee Table 3-13 on page 58 for bit definitions.
Base = 0, Limit = 3FFh
xxxx xxxxh xxxxh
isterxxxx xxxxh, xxxxh
Limit set to FFFFh.
Limit set to FFFFh.
Limit set to FFFFh.
Limit set to FFFFh.
Limit set to FFFFh.
Limit set to FFFFh.
speed settin
See Table 3-11 on pa
See Table 3-11 on pa
.
and Revision ID (RO).
e 48 for bit definitions.
e 55 for bit definitions.
e 55 for bit definitions.
e 55 for bit definitions.
e 56 for bit definitions.
e 56 for bit definitions.
Page 40Cyrix Corporation ConfidentialGXm_db_v2.0
Page 57
Instruction Set Overview
3
3.2Instruction Set Overview
The MediaGX processor instruction set can be
divided into nine types of operations:
• Arithmetic
• Bit Manipulation
• Shift/Rotate
• String Manipulation
• Control Transfer
• Data Transfer
• Floating Point
• High-Level Language Support
• Operating System Support
MediaGX processor instructions operate on as few
as zero operands and as many as three operands.
An NOP instruction (no operation) is an example of
a zero-operand instruction. Two-operand instructions allow the specification of an explicit source
and destination pair as part of the instruction.
These two-operand instructions can be divided into
ten groups according to operand types:
• Register to Register
• Register to Memory
• Memory to Register
• Memory to Memory
• Register to I/O
• I/O to Register
• Memory to I/O
• I/O to Memory
• Immediate Data to Register
• Immediate Data to Memory
An operand can be held in the instruction itself (as
in the case of an immediate operand), in one of the
processor’s registers or I/O ports, or in memory. An
immediate operand is fetched as part of the
opcode for the instruction.
Operand lengths of 8, 16, 32 or 48 bits are
supported as well as 64 or 80 bits associated with
floating-point instructions. Operand lengths of 8 or
32 bits are generally used when executing code
written for 386- or 486-class (32-bit code) processors. Operand lengths of 8 or 16 bits are generally
used when executing existing 8086 or 80286 code
(16-bit code). The default length of an operand can
be overridden by placing one or more instruction
prefixes in front of the opcode. For example, the
use of prefixes allows a 32-bit operand to be used
with 16-bit code or a 16-bit operand to be used with
32-bit code.
Section 9.1 “General Instruction Set Format” on
page 234 contains the clock count table that lists
each instruction in the CPU instruction set.
Included in the table are the associated opcodes,
execution clock counts, and effects on the Flags
register.
3.2.1Lock Prefix
The LOCK prefix may be placed before certain
instructions that read, modify, then write back to
memory. The PCI will not be granted access in the
middle of locked instructions. The LOCK prefix can
be used with the following instructions only when
the result is a write operation to memory.
Bit Test Instructions (BTS, BTR, BTC)
Exchange Instructions (XADD, XCHG,
CMPXCHG)
One-Operand Arithmetic and Logical Instruc-
tions (DEC, INC, NEG, NOT)
Two-Operand Arithmetic and Logical Instruc-
tions (ADC, ADD, AND, OR, SBB, SUB,
XOR).
An invalid opcode exception is generated if the
LOCK prefix is used with any other instruction or
with one of the instructions above when no write
operation to memory occurs (for example, when
the destination is a register).
GXm_db_v2.0Cyrix Corporation ConfidentialPage 41
Page 58
Register Sets
3.3Register Sets
The accessible registers in the processor are
grouped into three sets:
1) The
Application Register Set
contains the
registers frequently used by application
programmers. Table 3-2 shows the general
purpose registers, segment registers, the
instruction pointer register and the flag register.
2) The
System Register Set
contains the registers typically reserved for operating-systems
programmers: control registers, system
address registers, debug registers, configuration registe rs, and test registers.
Table 3-2Application Register Set
3116 158 70
EAX (Extended A Register)
EBX (Extended B Register)
ECX (Extended C Register)
EDX (Extended D Register)
ESI (Extended Source Index)
EDI (Extended Destination Index)
EBP (Extended Base Pointer)
ESP (Extended Stack Pointer)
EIP (Extended Instruction Pointer Register)Instruction Pointer and
EFLAGS (Extended Flags Register)Flags Register
3) The
Model Specific Register (MSR) Set
used to monitor the performance of the
processor or a specific component within the
processor. The model specific register set has
one 64-bit register called the Time Stamp
Counter.
Each of these register sets are discussed in detail
in the subsections that follow. Additional registers
to support integrated MediaGX processor
subsystems are described in Section 4.1 “Integrated Functions Programming Interface” of this
manual.
AX
AHAL
BX
BHBL
CX
CHCL
DX
DHDL
SI (Source Index)
DI (Destination Index)
BP (Base Pointer)
SP (Stack Pointer)
CS (Code Segment)
SS (Stack Segment)
DS (D Data Segment)
ES (E Data Segment)
FS (F Data Segment)
GS (G Data Segment)
is
General
Purpose
Registers
Segment
(Selector)
Registers
Page 42Cyrix Corporation ConfidentialGXm_db_v2.0
Page 59
Register Sets
3
3.3.1Application Register Set
The Application Register Set consists of the registers most often used by the applications
programmer. These registers are generally accessible, although some bits in the Flags register are
protected.
The
General Purpose Register
frequently modified by instructions and typically
contain arithmetic and logical instruction operands.
In real mode,
base address for each segment. In protected
mode, the segment registers contain segment
selectors. The segment selectors provide indexing
for tables (located in memory) that contain the
base address for each segment, as well as other
memory addressing information.
The
Instruction Pointer Register
next instruction that the processor will execute.
This register is automatically incremented by the
processor as execution progresses.
The
Flags Register
reflect the status of previously executed instructions. This register also contains control bits that
affect the operation of some instructions.
Segment Registers
contains control bits used to
contents are
contain the
points to the
3.3.1.1 General Purpose Registers
The General Purpose Registers are divided into
four data register s, two pointe r registe rs, an d two
index registers as shown in Table 3-2 on page 42.
The
Data Registers
programmer to manipulate data structures and to
hold the results of logical and arithmetic operations. Different portionsof general data registers
can be addressed by using different names.
An “E” prefix identifies the complete 32-bit register.
An “X” suffix without the “E” prefix identifies the
lower 16 bits of the register.
are used by the applications
The lower two bytes of a data register are
addressed with an “H” suffix (identifies the upper
byte) or an “L” suffix (identifies the lower byte).
These _L and _H portions of the data registers act
as independent registers. For example, if the AH
register is written to by an instruction, the AL
register bits remain unchanged.
The
Pointer and Index Registers
SI or ESISource Index
DI or EDIDestination Index
SP or ESPStack Pointer
BP or EBPBase Pointer
These registers can be addressed as 16- or 32-bit
registers, with the “E” prefix indicating 32 bits. The
pointer and index registers can be used as general
purpose registers; however, some instructions use
a fixed assignment of these registers. For example,
repeated string operations always use ESI as the
source pointer, EDI as the destination pointer, and
ECX as a counter. The instructions that use fixed
registers include multiply and divide, I/O access,
string operations, stack operations, loop, variable
shift and rotate, and translate instructions.
The MediaGX processor implements a stack using
the ESP register. This stack is accessed during th e
PUSH and POP instructions, procedure calls,
procedure returns, interrupts, exceptions, and
interrupt/exception returns. The MediaGX
processor automatically adjusts the value of the
ESP during operations that result from these
instructions.
The EBP register may be used to refer to data
passed on the stack during procedure calls. Local
data may also be placed on the stack and
accessed with BP. This register provides a mechanism to access tack data in high-level languages.
are listed below.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 43
Page 60
Register Sets
3.3.1.2 Segment Registers
The 16-bit segment registers, part of the main
memory addressing mechanism, are described in
Section 3.5 “Offset, Segm ent, an d Paging Mech anisms” on page 66. The six segment registers are:
CS - Code Segment
DS -Data Segment
SS -Stack Segment
ES -Extra Segment
FS -Additional Data Segment
GS -Additional Data Segment
The segment registers are used to select
segments in main memory. A segment acts as
private memory for different elements of a program
such as code space, data space and stack space.
There are two segment mechanisms, one for Real
and Virtual 8086 Operating Modes and one for
Protective Mode. Initialization and transition to
protective mode is described in Section 3.13.4
“Initialization and Transition to Protected Mode” on
page 99. The segment mechanisms are described
in Section 3.7 “Descriptors and Segment Mechanisms” on page 68.
The active segment register is selected according
to the rules listed in Table 3-3 and the type of
instruction being currently processed. In general,
the DS register selector is used for data references. Stack references use the SS register, and
instruction fetches use the CS register. While some
of these selections may be overridden, instruction
fetches, stack operations, and the destination write
operation of string operations cannot be overridden. Special segment-override instruction
prefixes allow the use of alternate segment registers. These segment registers include the ES, FS,
and GS registers.
3.3.1.3Instruction Pointer Register
The
Instruction Pointer (EIP) Register
the offset into the current code segment of the next
instruction to be executed. The register is normally
incremented by the length of the current instruction
with each instruction execution unless it is implicitly
modified through an interrupt, exception, or an
instruction that chang es the se quen tia l exe cu tio n
flow (for example JMP and CALL).
Table 3-3 illustrates the code segment selection
rules.
contains
Table 3-3Segment Register Selection Rules
Implied (Default)
Type of Memory Reference
Code FetchCSNone
Destination of PUSH, PUSHF, INT, CALL, PUSHA instructionsSSNone
Source of POP, POPA, POPF, IRET, RET instructionsSSNone
Destination of STOS, MOVS, REP STOS, REP MOVS instructionsESNone
Other data references with effective address using base registers of:
EAX, EBX, ECX, EDX, ESI, EDI, EBP, ESP
Page 44Cyrix Corporation ConfidentialGXm_db_v2.0
Segment
DS
SS
Segment-Override
Prefix
CS, ES, FS, GS, SS
CS, DS, ES, FS, GS
Page 61
3.3.1.4 Flags Register
The Flags Register contains status information and
controls certain operations on the MediaGX
processor. The lower 16 bits of this register are
Table 3-4EFLAGS Register
BitNameFlag TypeDescription
31:22RSVD--
21IDSystem
20:19RSVD--
18ACSystem
17VMSystem
16RFDebug
15RSV D-14NTSystem
13:12IOPLSystem
11OFArithmetic
10DFControl
9IFSystem
8TFDebug
7SFArithmetic
6ZFArithmetic
5RSVD-4AFArithmetic
3RSVD-2PFArithmetic
1RSVD
0CFArithmetic
Reserved
Identification Bit
supported. The ID can be modified only if the CPUID bit in CCR4 (Index E8h[7]) is set.
Reserved
Alignment Check Enable
whether or not misaligned accesses to memory cause a fault. If AC is set, alignment faults are
enabled.
Virtual 8086 Mode
operation handling segment loads as the 8086 does, but generating exception 13 faults on
privileged opcodes. The VM bit can be set by the IRET instruction (if current privilege level
is 0) or by task switches at any privilege level.
Resume Flag
instruction boundaries before breakpoint exception processing. If set, any debug fault is
ignored on the next instruction.
Reserved
Nested Task
current task is nested within another task.
I/O Privilege Level
rent privilege level (CPL) permitted to execute I/O instructions without generating an exception
13 fault or consulting the I/O permission bit map. IOPL also indicates the maximum CPL allowing alteration of the IF bit when new values are popped into the EFLAGS register.
Overflow Flag
but did not result in a carry or borrow out of the high-order bit. Also set if the operation resulted
in a carry or borrow out of the high-order bit but did not result in a carry or borrow into the sign
bit of the result.
Direction Flag
appropriate index registers (ESI and/or EDI). Setting DF causes auto-decrement of the index
registers to occur.
Interrupt Enable Flag
and serviced by the CPU.
Trap Enable Flag
pletes execution. TF is cleared by the single-step interrupt.
Sign Flag
Zero Flag
Reserved
Auxiliary Carry Flag
tion 3 of the result occurs; cleared otherwise.
Reserved
Parity Flag
otherwise PF is cleared.
Reserved
Carry Flag
cant bit of the result occurs; cleared otherwise.
— Set to 0.
— The ability to set and clear this bit indicates that the CPUID instruction is
— Set to 0.
— If set while in protected mode, the processor switches to virtual 8086
— Used in conjunction with debug register breakpoints. RF is checked at
— Set to 0.
— While executing in protected mode, NT indicates that the execution of the
— While executing in protected mode, IOPL indicates the maximum cur-
— Set if the operation resulted in a carry or borrow into the sign bit of the result
— When cleared, DF causes string instructions to auto-increment (default) the
— When set, maskable interrupts (INTR input pin) are acknowledged
— Once set, a single-step interrupt occurs after the next instruction com-
— Set equal to high-order bit of result (0 indicates positive, 1 indicates negative).
— Set if result is zero; cleared otherwise.
— Set to 0.
— Set when a carry out of (addition) or borrow into (subtraction) bit posi-
— Set to 0.
— Set when the low-order 8 bits of the result contain an even number of ones;
— Set to 1.
— Set when a carry out of (addition) or borrow into (subtraction) the most signifi-
Register Sets
3
referred to as the Flags register that is used when
executing 8086 or 80286 code. Table 3-4 gives the
bit formats for the EFLAGS Register.
— In conjunction with the AM flag in CR0, the AC flag determines
GXm_db_v2.0Cyrix Corporation ConfidentialPage 45
Page 62
Register Sets
3.3.2System Register Set
The system register set, shown in Table 3-5,
consists of registers not generally used by application programmers. These registers are typically
employed by system level programmers who
generate operating systems and memory management programs. Associated with the system
register set are certain tables and segments which
are listed in Table 3-5.
The Control Registers control certain aspects of
the MediaGX processor such as paging, coprocessor functions, and segment protection.
The Descriptor Tables hold descriptors that
manage memory segments and tables, interrupts
and task switching. The tables are defined by
corresponding registers.
The two Task State Segments Tables defined by
TSS register are used to save and load the
computer state when switching tasks.
The Configuration Registers are used to define
Cyrix MediaGX CPU setup including cache
management.
The ID registers allow BIOS and other software to
identify the specific CPU and stepping. Sys tem
Management Mode (SMM) control information is
stored in the SMM registers.
The Debug Registers provide debugging facilities
for the MediaGX processor and enable the use of
data access breakpoints and code execution
breakpoints.
The Test Registers provide a mechanism to test
the contents of both the on-chip 16KB cache and
the Translation Lookaside Buffer (TLB). The TLB is
used as a cache for the tables that are used in to
translate linear addresses to physical addresses
while paging is enabled.
Table 3-5 lists the system register sets along with
their size and function.
Tables
TRTSS Register Setup16
CCRnConfiguration Control
Registers
DIRnDevice Identification
Registers
SMARnSMM Address Region
Registers
SMHRnSMM Header Addresses8
PCR0Performance Control
Register
DR0Linear Breakpoint
Address 0
DR1Linear Breakpoint
Address 1
DR2Linear Breakpoint
Address 2
DR3Linear Breakpoint
Address 3
DR6Breakpoint Status32
DR7Breakpoint Control32
TR3Cache Test 32
TR4Cache Test 32
TR5Cache Test 32
TR6TLB Test Control32
TR7TLB Test Status32
Width
(Bits)
32
32
32
16
8
8
8
8
32
32
32
32
Page 46Cyrix Corporation ConfidentialGXm_db_v2.0
Page 63
Register Sets
3
3.3.2.1 Control Registers
A map of the Control Registers (CR0, CR2, CR3,
and CR4) is shown in Table 3-6 and the bit de fi nitions given in Table 3-7. ( These r egi sters sh ould not
be confused with the CRRn registers.) The CR0
register contains system control bits which
state of t he CPU. The lower 16 bits of CR0 are
referred to as the Machine Status Word (MSW).
When operating in real mode, any program can read
and write the control registers. In protected mode,
however, only privilege level 0 (most-privileged)
programs can read and write these registers.
configure operating modes and indicate the ge neral
If = 1 RDTSC instruction enabled for CPL = 0 only; reset state.
If = 0 RDTSC instruction enabled for all CPL states.
Reserved
Page Directory Base Register:
Reserved:
Page Fault Linear Address:
the address that caused the pa
Paging Enable Bit:
state of PG, software must execute an unconditional branch instruction (e.
take effect.
Cache Disable:
to be used if the requested address hits in the cache. Writes continue to update the cache and cache invalidations due to inquiry cycles occur normally . The cache must also be invalidated to completely disable any cache
activity.
Not Write-Through:
issued to the external bus only for a cache miss, a line replacement of a modified line, execution of a locked
instruction, or a line eviction as the result of a flush cycle. If NW = 0, the on-chip cache operates in write-throu
mode. In write-throu
chan
Alignment Check Mask:
ment check faults. Settin
Write Protect:
written from privile
Numerics Exception:
are to be handled by external interrupts.
Reserved:
Task Switched:
TS = 1 causes a DNA fault. If MP = 1 and TS = 1, a WAIT instruction also causes a DNA fault.
The configuration registers listed in Table 3-9 are
CPU registers and are selected by register index
numbers. The registers are accessed through I/O
memory locations 22h and 23h. Registers are
selected for access by writing an index number to
I/O Port 22h using an OUT instruction prior to
transferring data through I/O Port 23h.
Each data transfer through I/O Port 23h must be
preceded by a register index selection through I/O
Port 22h; otherwise, subsequent I/O Port 23h operations are directed off-chip and produce external
I/O cycles.
If MAPEN, bit 4 of CCR3 (Index C3h[4]) = 0,
external I/O cycles will occur if the register index
number is outside the range C0h-CFh, FEh, and
FFh. The MAPEN bit should remain 0 during
normal operation to allow system registers located
at I/O Port 22h to be accessed (see Table 3-11 on
page 53).
Table 3-9Configuration Register Summary
Access
IndexTypeName
C1hR/WCCR1 — Configuration Control 1 SMI_LOCK00hTable 3-11 on page52
C2hR/WCCR2 — Configuration Control 2 --00hTable 3-11 on page 52
C3hR/WCCR3 — Configuration Control 3SMI_LOCK00hTable 3-11 on page 53
E8hR/WCCR4 — Configuration Control 4MAPEN85hTable 3-11 on page 54
EBhR/WCCR7 — Configuration Control 7--00hTable 3-11 on page 54
20hR/WPCR — Performance ControlMAPEN07hTable 3-11 on page 54
B0hR/WS MHR0 — SMM Header Address 0MAPENxxhTable 3-11 on page 55
B1hR/WS MHR1 — SMM Header Address 1MAPENxxhTable 3-11 on page 55
B2hR/WS MHR2 — SMM Header Address 2MAPENxxhTable 3-11 on page 55
B3hR/WS MHR3 — SMM Header Address 3MAPENxxhTable 3-11 on page 55
B8hR/WGCR — Graphics Control RegisterMAPEN00hTable 4-1 on page 104
B9hVGACTL — VGA Control Register--00hTable 5-5 on page 200
BAh-BDhVGAM0 — VGA Mask Register--00hTable 5-5 on page 200
CDhR/WSMAR0 — SMM Address 0SMI_LOCK00hTable 3-11 on page 55
CEhR/WSMAR1 — SMM Address 1SMI_LOCK00hTabl e 3-11 on page 55
CFhR/WSMAR2 — SMM Address 2SMI_LOCK00hTable 3-11 on page 55
FEhRODIR0 — Device ID 0 --4xhTable 3-11 on page 56
FFhRODIR1 — Device ID 1 --xx hTable 3-11 on page 56
MAPEN = Index C3h[4] (CCR3) and SMI_LOCK = Index C3h[0] (CCR3).
access, the upper 4-bits of Port 23h hold SMAR[15:12].
ions bits SMAR[15:12] (see above) and size code bits SIZE[3:0].
SMHR address bits [31:0] contain the physical base address for
uration Registers” on page 89 for more information.
ister.
— SMAR address bits [31:12] contain the base
ions bits SMAR[15:12] and size code bits
uration Registers” on page 89 for more information.
— SIZE address bits contain the size code for the SMM re
isters/bits.
ion.
3
GXm_db_v2.0Cyrix Corporation ConfidentialPage 55
Page 72
Register Sets
g
g
g
Table 3-11 Configuration Registers (cont.)
BitNameDescription
Index FEhDIR0 — Device Identification Register 0 Default Value = 4xh
7:4DID[3:0]
3:0MULT[3:0]
Device ID (Read Only)
Core Multiplier (Read Only)
nal descriptions pa
If DIR1 (Index FFh) is 30h-4Fh then MULT[3:0]:
0000 = SYSCLK multiplied by 4 (Test mode only)
0001 = SYSCLK multiplied by 6
0010 = SYSCLK multiplied by 4 (Test mode only)
0011 = SYSCLK multiplied by 6
0100 = SYSCLK multiplied by 7
0101 = SYSCLK multiplied by 8
0110 = SYSCLK multiplied by 7
0111 = SYSCLK multiplied by 5
1xxx = Reserved
If DIR1 (Index FFh) is 50h or greater then MULT[3 : 0 ] :
0000 = SYSCLK multiplied by 4 (Test mode only)
0001 = SYSCLK multiplied by 10
0010 = SYSCLK multiplied by 4 (Test mode only)
0011 = SYSCLK multiplied by 6
0100 = SYSCLK multiplied by 9
0101 = SYSCLK multiplied by 5
0110 = SYSCLK multiplied by 7
0111 = SYSCLK multiplied by 8
1xxx = Reserved
— Identifies device as MediaGX MMX-Enhanced processor.
— Identifies the core multiplier set by the CLKMODE[2:0] pins (see si
e 21)
-
Index FFhDIR1 -- Device Identification Register 1 Default Value = xxh
7:0DIR1
Device Identification Revision (Read Only)
If DIR1 is 30h-33h = MediaGX MMX-Enhanced processor revision 1.0-2.3
If DIR1 is 34h-4Fh = MediaGX MMX-Enhanced processor revision 2.4-3.x
If DIR1 is 50h or
reater = MediaGX MMX-Enhanced processor revision 4.0 and up.
— DIR1 indicates device revision number.
Page 56Cyrix Corporation ConfidentialGXm_db_v2.0
Page 73
Register Sets
3
3.3.2.3 Debug Registers
Six debug registers (DR0-DR3, DR6 and DR7)
support debugging on the MediaGX processor.
Memory addresses loaded in the debug registers,
referred to as “breakpoints,” generate a debug
exception when a memory access of the specified
type occurs to the specified address. A breakpoint
can be specified for a particular kind of memory
access such as a read or write operation. Code
and data breakpoints can also be set allowing
debug exceptions to occur whenever a given data
access (read or write operation) or code access
(execute) occurs. The size of the debug target can
be set to 1, 2, or 4 bytes. The debug registers are
The Debug Address Registers (DR0-DR3) each
contains the linear address for one of four possible
breakpoints. Each breakpoint is further specified by
bits in the Debug Control Register (DR7). For each
breakpoint address in DR0-DR3, there are corresponding fields L, R/W, and LEN in DR7 that
specify the type of memory access associated with
the breakpoint.
The R/W field can be used to specify instruction
execution as well as data access breakpoints.
Instruction execution breakpoints are always taken
before execution of the instruction that matches the
breakpoint. The Debug Registers are mapped in
Table 3-12
accessed through MOV instructions that can be
executed only at privilege level 0 (real mode is
always privilege level 0).
All bits marked as 0 or 1 are reserved and should not be modified.
Note:
0
GXm_db_v2.0Cyrix Corporation ConfidentialPage 57
Page 74
Register Sets
The Debug Status Register (DR6) reflects conditions that were in effect at the time the debug
exception occurred. The contents of the DR6
register are not automatically cleared by the
processor after a debug exception occurs, and
therefore should be cleared by software at the
appropriate time. Table 3-13 lists the f i e l d d e f in i t i o n s
for the DR6 and DR7 registers.
Code execution breakpoints may also be generated by placing t he bre akpoint i nst ructio n (IN T3) at
the location where control is to be regained. The
single-step feature may be enabled by setting the
TF flag (bit 8) in the EFLAGS register. This causes
the processor to perform a debug exception after
the execution of every instruction. Debug Registers
6 and 7 are shown in Table 3-13.
Table 3-13 DR7 and DR6 Bit Definitions
Number
Field(s)
DR7 Register
R/Wn2Applies to the DRn breakpoint address register:
LENn2Applies to the DRn breakpoint address register:
Gn1If = 1: breakpoint in DRn is globally enabled for all tasks and is not cleared by the processor as the
Ln1If = 1: breakpoint in DRn is locally enabled for the current task and is cleared by the processor as
GD1Global disable of debug register access. GD bit is cleared whenever a debug exception occurs.
of BitsDescription
00 = Break on instruction execution only
01 = Break on data write operations only
10 = Not used
11 = Break on data reads or write operations.
00 = One-byte length
01 = Two-byte length
10 = Not used
11 = Four-byte length.
result of a task switch.
the result of a task switch.
DR6 Register
Bn1Bn is set by the processor if the conditions described by DRn, R/Wn, and LENn occurred when the
BT1BT is set by the processor before entering the debug handler if a task switch has occurred to a task
BS1BS is set by the processor if the debug exception was triggered by the single-step execution mode
n = 0, 1, 2, and 3
Note:
Page 58Cyrix Corporation ConfidentialGXm_db_v2.0
debug exception occurred, even if the breakpoint is not enabled via the Gn or Ln bits.
with the T bit in the TSS set.
(TF flag, bit 8, in EFLAGS set).
Page 75
Register Sets
3
3.3.2.4 Test Registers
The five test registers are used in testing the
CPU’s Translation Lookaside Buffer (TLB) and onchip cache. TR6 and TR7 are used for TLB testing,
and TR3-TR5 are used for cache testing. Table 3-14
is a register map for the Test Registers with their bit
definitions given in Tables 3-15 and 3-16.
TLB Test Registers
The CPU TLB is a 32-entry, four-way set associative memory. Each TLB entry consists of a 24-bit
tag and 20-bit data. The 24-bit tag represents the
high-order 20 bits of the linear address, a valid bit,
and three attribute bits. The 20-bit data portion
represents the upper 20 bits of the physical
address that corresponds to the linear address.
The TLB Test Data Register (TR7) contains the
upper 20 bits of the physical address (TLB data
field), three LRU bits and a control bit. During TLB
write operations, the physical address in TR7 is
written into the TLB entry selected by the contents
of TR6. During TLB lookup operations, the TLB
data selected by the contents of TR6 is loaded into
TR7. Table 3-15 lists the bit definitions for TR7 and
TR6.
The TLB Test Control Register (TR6) contains a
command bit, the upper 20 bits of a linear address,
a valid bit and the attribute bits used in the test
operation. The contents of TR6 are used to create
the 24-bi t TLB ta g du ring both writ e an d re ad ( TLB
lookup) test operations. The command bit defines
whether the test operation is a read or a write.
TLB lookup: Data field from the TLB.
TLB write: Data field written into the TLB.
Reserved:
LRU Bits:
TLB lookup: LRU bits associated with the TLB entry before the TLB lookup.
TLB write: I
PL Bit:
TLB lookup: If PL = 1, read hit occurred. If PL = 0, read miss occurred.
TLB write: If PL = 1, REP field is used to select the set. If PL = 0, the pseudo-LRU replacement al
rithm is used to select the set.
Set Selection:
TLB lookup: If PL = 1, this field indicates the set in which the ta
TLB write: If PL = 1, this field selects one of the four sets for replacement. If PL = 0, i
Reserved:
Linear Address:
TLB lookup: The TLB is interro
the rest of the fields in TR6 and TR7 are updated per the matchin
TLB write: A TLB entry is allocated to this linear address.
Valid Bit:
TLB write: If V = 1, the TLB entry contains valid data. If V = 0, tar
Dirty Attribute Bit and its Complement (D, D#)
User/Supervisor Attribute Bit and its Complement (U, U#)
Read/Write Attribute Bit and its Complement (R, R#)
00 = Do not matchUndefined
01 =Match if D, U, or R bit is a 0Clear the bit
10 =Match if D, U, or R bit is a 1Set the bit
11 =Match if D, U, or R bit is either a 1 or 0Undefined
Reserved:
Command Bit:
If C = 1: TLB lookup.
If C = 0: TLB write.
Set to 0.
nored.
Set to 0.
Effect on TLB LookupEffect on TLB Write
Set to 0.
Register Sets
o-
was found. If PL = 0, undefined data.
nored.
ated per this address. If one and only one match occurs in the TLB,
TLB entry.
et entry is invalidated.
Page 60Cyrix Corporation ConfidentialGXm_db_v2.0
Page 77
Register Sets
3
Cache Test Registers
The CPU’s 16KB on-chip cache is a four-way set
associative memory that is configured as writeback cache. Each cache set contains 256 entries.
Each entry consists of a 20-bit tag address, a 16byte data field, a valid bit, and four dirty bits.
The 20-bit tag represents the high-order 20 bits of
the physical address. The 16-byte data represents
the 16 bytes of data currently in memory at the
physical address represented by the tag. The valid
bit indicates whether the data bytes in the cache
actually contain valid data. The four dirty bits indicate if the data bytes in the cache have been modified internally without updating external memory
(write-back configuration). Each di rty bit indicates
Line
D
E
A11-A4
C
O
D
E
= Cache Entry (153 bits)
Tag Address (20 bits)
Data (128 bits)
Valid Status (1 bit)
Dirty Status (4 bits)
Address
255
254
.
.
0
Set 0Set 1Set 2Set 3LRU
.
.
152 --- 0 152 --- 0 152 --- 0 152 --- 0 2 --- 0
the status for one double-word (4 bytes) within the
16-byte data field.
For each line in the cache, there are three LRU bits
that indicate which of the four sets was most
recently accessed. A line is selected using bits
[1 1:4] of the physical address. Figure 3-2 illustrates
the CPU cache architecture.
The CPU contains three test registers (TR5-TR3)
that allow testing of its internal cache. Bit definitions for the cache test registers are shown in
Table 3-16. Using a 16-byte cache fill buffer and a
16-byte cache flush buffer, cache reads and writes
may be performed.
Figure 3-1 illustrates how the internal cache architecture works.
.
.
.
.
.
.
.
.
Figure 3-1 CPU Cache Architecture
GXm_db_v2.0Cyrix Corporation ConfidentialPage 61
Page 78
g
g
g
g
g
g
Table 3-16 TR5-TR3 Bit Definitions
BitNameDescription
TR5 Register
11:4Line Selec-
tion
3:2Set/DWord
Selection
1:0Control Bits
TR4 Register
31:12Upper Ta
Address
10Valid Bit
9:7LRU Bits
6:3Dirty Bits
2:0RSVD
Line Selection:
Physical address bits 11-4 used to select one of 256 lines.
Set/DWord Selection:
Cache read: Selects which of the four sets in the cache is used as the source for data
transferred to the cache flush buffer.
Cache write: Selects which of the four sets in the cache is used as the destination for data transferred
from the cache fill buffer.
Flush buffer read: Selects which of the four Dword in the flush buffer is
used durin
Fill buffer write: Selects which of the four Dword in the fill buffer is written durin
Control Bits:
If = 00: flush read or fill buffer write.
If = 01: cache write.
If = 10: cache read.
If = 11: cache flush.
Upper Tag Address:
Cache read: Upper 20 bits of ta
Cache write: Data written into the upper 20 bits of the ta
Valid Bit:
Cache read: Valid bit for the selected entry.
Cache write: Data written into the valid bit for the selected entry.
LRU Bits:
Cache read: The LRU bits for the selected line.
xx1 = Set 0 or Set 1 most recently accessed.
xx0 = Set 2 or Set 3 most recently accessed.
x1x = Most recent access to Set 0 or Set 1 was to Set 0.
x0x = Most recent access to Set 0 or Set 1 was to Set 1.
1xx = Most recent access to Set 2 or Set 3 was to Set 2.
0xx = Most recent access to Set 2 or Set 3 was to Set 3.
Cache write: I
Dirty Bits:
Cache read: The dirty bits for the selected entry (one bit per DWord).
Cache write: Data written into the dirty bits for the selected entry.
Reserved:
a TR3 read.
Set to 0.
Register Sets
a TR3 write.
address of the selected entry.
address of the selected entry.
nored.
TR3 Register
31:0Cache Data
Cache Data:
Flush buffer read: Data accessed from the cache flush buffer.
Fill buffer write: Data to be written into the cache fill buffer.
Page 62Cyrix Corporation ConfidentialGXm_db_v2.0
Page 79
Register Sets
3
There are five types of test operations that can be
executed:
buffer must be written four times. Once the fill
buffer holds a complete cache line of data (16
bytes), a cache write operation transfers the data
• Flush buffer read
from the fill buffer to the cache.
• Fill buffer write
• Cache write
• Cache read
• Cache flush
To read the contents of a cache line, cache read
operation transfers the data in the selected cache
line to the flush buffer. Once the flush buffer is
loaded, the programmer accesses the contents of
Each of these operations is described in detail in
Table 3-17. To fill a cache line with data, the fill
the flush buffer by executing four flush buffer read
Set DWORD = 0, control = 00 = flush buffer read.
Flush buffer (31:0) --> dest.
Set DWORD = 1, control = 00 = flush buffer read.
Flush buffer (63:32) --> dest.
Set DWORD = 2, control = 00 = flush buffer read.
Flush buffer (95:64) --> dest.
Set DWORD = 3, control = 00 = flush buffer read.
Flush buffer (127:96) --> dest.
Set DWORD = 0, control = 00 = fill buffer write.
Cache_data --> fill buffer (31:0).
Set DWORD = 1, control = 00 = fill buffer write.
Cache_data --> fill buffer (63:32).
Set DWORD = 2, control = 00 = fill buffer write.
Cache_data --> fill buffer (95:64).
Set DWORD = 3, control = 00 = fill buffer write.
Cache_data --> fill buffer (127:96).
Cache line (127:0) --> flush buffer (127:0).
Cache line tag address, valid/LRU/dirty bits --> dest.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 63
Page 80
Register Sets
3.3.3Model Specific Register
The model specific register (MSR) set is used to
monitor the performance of the processor or a
specific component within the processor.
A MSR register can be read using the RDMSR
instruction, opcode 0F32h. During a MSR register
read, the contents of the particular MSR register,
specified by the ECX register, is loaded into the
EDX:EAX regis ters.
A MSR register can be written using the WRMSR
instruction, opcode 0F30h. During a MSR register
write, the contents of EX:EAX are loaded into the
MSR register specified in the ECX register.
The RDMSR and WRMSR instructions are privileged instructions.
The MediaGX MMX-Enhanced processor contains
one 64-bit model specific register (MSR10) the
Time Stamp Counter (TSC).
3.3.4Time Stamp Counter
The processor contains a model specific register
(MSR) called the Time Stamp Counter (TSC). The
TSC, (MSR[10]), is a 64-bit counter that counts the
internal CPU clock cycles since the last reset. The
TSC uses a continuous CPU core clock and will
continue to count clock cycles even when the
processor is in suspend or shutdown mode.
The TSC is read using a RDMSR instruction,
opcode 0F 32h, with the ECX register set to 10h.
During a TSC read, the contents of the TSC
register is loaded into the EDX:EAX registers.
The TSC is written to using a WRMSR instruction,
opcode 0F 30h with the ECX register set to 10h.
During a TSC write, the contents of EX:EAX are
loaded into the TSC.
The RDMSR and WRMSR instructions are privi-
leged instructions.
In addition, the TSC can be read using the RDTSC
instruction, opcode 0F 31h. The RDTSC instruction
loads the contents of the TSC into EDX:EAX. The
use of the RDTSC instruction is restricted by the
TSC flag (bit 2) in the CR4 register (refer to Tables
3-6 and 3-7 on pages 47 and 48 for CR4 register
information). When the TSC bit = 0, the RDTSC
instruction can be executed at any privilege level.
When the TSC bit = 1, the RDTSC instruction can
only be executed at privilege level 0.
Page 64Cyrix Corporation ConfidentialGXm_db_v2.0
Page 81
3.4Address Spaces
The MediaGX processor can directly address
either memory or I/O space. Figure 3-2 illustrates
the range of addresses available for memory
address space and I/O address space. For the
CPU, the addr esses for physical memory range
between 00000000h and FFFFFFFFh
(4 GBytes). The accessible I/O addre sses spa ce
ranges between 00000000h and 0000FFFFh
(64KB). The CPU does not use coprocessor
communication space in upper I/O space between
800000F8h and 800000FFh as do the 386-style
CPUs. The I/O locations 22h and 23h are used for
MediaGX processor configuration register access.
3.4.1I/O Address Space
The CPU I/O address space is accessed using IN
and OUT instructions to addresses referred to as
“ports.” The accessible I/O address space is 64KB
and can be accessed as 8-bit, 16-bit or 32-bit
ports.
The MediaGX processor configuration registers
reside within the I/O address space at port
Address Spaces
3
addresses 22h and 23h and are accessed using
the standard IN and OUT instructions.
The configuration registers are modifi ed by writi ng
the index of the configuration register to port 22h,
and then transferring the data through port 23h.
Accesses to the on-chip configuration registers do
not generate external I/O cycles. However, each
operation on port 23h must be preceded by a write
to port 22h with a valid index value. Otherwise,
subsequent port 23h operations will communicate
through the I/O port t o produce external I/O cycles
without modifying the on-chip co nfigur ati on regis -
ters. Write operations to port 22h outside of the
CPU index range (C0h-CFh and FEh-FFh) result in
external I/O cycles and do not affect the on-chip
configuration registers. Reading port 22h gener-
ates external I/O cycles.
I/O accesses to port address range 3B0h through
3DFh can be trapped to SMI by the CPU if this
option is enabled in the BC_XMAP_1 register (see
SMIB, SMIC, and SMID bits in Table 4-9 on page
113). Figure 3-2 illustrates the I/O address space.
Accessible
Programmed
I/O Space
Not
Accessible
64KB
CPU General
Configuration
Register I/O
Space
0000 0023h
0000 0022h
FFFF FFFFh
0000 0000h
Physical
Memory Space
FFFF FFFFh
Physical Memory
4GB
0000 FFFFh
0000 0000h
Figure 3-2 Memory and I/O Address Spaces
GXm_db_v2.0Cyrix Corporation ConfidentialPage 65
Page 82
Offset, Segment, and Paging Mechanisms
3.4.2Memory Address Space
The processor directly addresses up to 4GB of
physical memory even though the memory
controller addresses only 128MB of DRAM. Much
of the other 4GB can be on PCI. Memory address
space is accessed as bytes, words (16 bits) or
DWORDs (32 bits). Words and DWORDs are
stored in consecutive memory bytes with the loworder byte located in the lowest address. The physical address of a word or DWORD is the byte
address of the low-order byte.
The processor allows memory to be addressed
using nine different addressing modes. These
addressing modes are used to calculate an offset
address, often referred to as an effective address.
Depending on the operating mode of the CPU, the
offset is then combined, using memory management mechanisms, into a physical address that is
applied to the physical memory devices.
Memory management mechanisms consist of
segmentation and paging. Segmentation allows
each program to use several independent,
protected address spaces. Paging translates a
logical address into a physical address using translation lookup tables. Virtual memory is often implemented using paging. Either or both of these
mechanisms can be used for management of the
MediaGX processor memory address space.
3.5Offset, Segment, and Paging
Mechanisms
The mapping of address space into a sequence of
memory locations (often cached) is performed by
the offset, segment and paging mechanisms.
In general, the offset, segment and paging mechanisms work in tandem as shown below:
instruction offset ➾
offset address
linear address ➾
As will be explained, the actual operations depend
on several factors such as the current operating
mode and if paging is enabled. Note: the paging
mechanism uses part of the linear address as an
offset on the physical page.
offset mechanism
segment mechanism
➾
paging mechanism
offset address
➾
➾ linear address
➾ physical page.
Page 66Cyrix Corporation ConfidentialGXm_db_v2.0
Page 83
Offset Mechanism
3
3.6Offset Mechanism
In all operating modes, the offset mechanism
computes an offset (effective) address by adding
together up to three values: a base, an index and a
displacement. The base, if present, is the value in
one of eight general registers at the time of the
execution of the instruction. The index, like the
base, is a value that is contained in one of the
general registers (except the ESP register) when
the instruction is executed. The index differs from
the base in that the index is first multiplied by a
scale factor of 1, 2, 4 or 8 before the summation is
made. The third component added to the memory
address calculation is the displacement that is a
value supplied as part of the instruction. Figure 3-3
illustrates the calculation of the offset address.
Nine valid combinations of the base, index, scale
factor and displacement can be used with the CPU
instruction set. These combinations are listed in
Table 3-18. The base and index both refer to
contents of a register as indicated by [Base] and
[Index].
In real mode operation, the CPU only addresses
the lowest 1MB of memory and the offset contains
16-bits. In protective mode the offset contains 32
bits. Initialization and transition to protective mode
is described in Section 3.13.4 “Initialization and
Transition to Protected Mode” on page 99.
Index
Base
Scaling
x1, x2, x4, x8
+
Displacement
Offset Address
(Effective Address)
Figure 3-3 Offset Address Calculation
Table 3-18 Memory Addressing Modes
Scale
Factor
Addressing ModeBaseIndex
DirectxOA = DP
Register IndirectxOA = [BASE]
BasedxxOA = [BASE] + DP
Index xxOA = [INDEX] + DP
Scaled Index xxxOA = ([INDEX] * SF) + DP
Based IndexxxOA = [BASE] + [INDEX]
Based Scaled IndexxxxOA = [BASE] + ([INDEX] * SF)
Based Index with
Displacement
Based Scaled Index
with Displacement
xxxOA = [BASE] + [INDEX] + DP
xxxxOA = [BASE] + ([INDEX] * SF) + DP
(SF)
Displacement
(DP)
Offset Address (OA)
Calculation
GXm_db_v2.0Cyrix Corporation ConfidentialPage 67
Page 84
Descriptors and Segment Mechanisms
3.7Descriptors and Segment
Mechanisms
Memory is divided into contiguous regions called
“segments.” The segments allow the partitioning of
individual elements of a program. Each segment
provides a zero address-based private memory for
such elements as code, data and stack space.
The segment mechanisms select a segment in
memory. Memory is divided into an arbitrary
number of segments, each containing usually
much less than the 2
There are two segment mechanisms, one for Real
and Virtual 8086 Operating Modes, and one for
Protective Mode.
32
byte (4 GByte) maximum.
3.7.1Real and Virtual 8086 Mode
Segment Mechanisms
Real Mode Segment Mechanism
In real mode operation, the CPU addresses only
the lowest 1MB of memory. In this mode a selector
located in a one of the segment registers is used to
locate a segment.
To calculate a physical memory address, the 16-bit
segment base address located in the selected
segment register is multiplied by 16 and then a 16bit offset address is added. The resulting 20-bit
address is then extended with twelve zeros in the
upper address bits to crate 32-bit physical address.
The value of the selector (the INDEX field) is multiplied by 16 to produce a base address (Figure 3 - 4. )
The base address is summed with the instruction
offset value to produce a physical address.
Virtual 8086 Mode Segment Mechanism
In Virtual 8086 mode the operation is performed as
in real mode except that a paging mechanism is
added. When paging is enabled, the paging
mechanism translates the linear address into a
physical address using cached look-up tables
(refer to Section 3.9 “Paging Mechanism” on page
80).
12 High Order Address Bits
000h
Offset Mechanism
Selected Segment
Register
Page 68Cyrix Corporation ConfidentialGXm_db_v2.0
Offset Address
16
X 16
Figure 3-4 Real Mode Address Calculation
16
20
Base Address
12
20
32
(Physical Address)
Linear Address
Page 85
Descriptors and Segment Mechanisms
3
3.7.2Segment Mechanism in
Protective Mode
The segment mechanism in protective mode is
more complex. Basically as in Real and Virtual
8086 modes the offset address is added to the
segment base address to produce a linear address
(Figure 3-5). However, the calculation of the
segment base address is based on the contents of
descriptor tables.
Again, if paging is enabled the linear address is
further processed by the paging mechanism.
A more detailed look at the segment mechanisms
for real, virtual 8086 and protective modes is illustrated in Figure 3-6. In protective mode, the
segment selector is cached. This is illustrated in
Figure 3-7 on page 71.
3.7.2.1 Segment Selectors
The segment registers are used to store segment
selectors. In protective mode, the segment
selectors are divided in to three fields: the RPL, TI
and INDEX fields as shown in Figure 3-6.
The segments are assigned permission le vels to
prevent applicat ion p rogra m e r ror s f rom dis ru pt ing
opera ti ng p ro gra ms . The Requested Privilege Level
(RPL) determines the E ffective Privilege L evel of a n
instruction. RPL = 0 indicates th e most privileg ed
level, and RPL = 3 indicates the least privileged level.
Refer to Section 3.13 “Protection” on page 97.
Descriptor tables hold descriptors that allow
management of segments and tables in address
space while in protective mode. The Table Indicator Bit (TI) in the selector selects either the
General Descriptor Table (GDT) or one Local
Descriptor Tables (LDT) tables. If TI = 0, GDT is
selected; if TI =1, LDT is selected. The 13-bit
INDEX field in the segment selector is used to
index a GDT or LDT table.
Offset Mechanism
Selector Mechanism
32
Offset Address
Linear
Segment Base
32
Address
32
Address
Optional
Paging Mechanism
Figure 3-5 Protected Mode Address Calculation
32
Physical
Memory
Address
GXm_db_v2.0Cyrix Corporation ConfidentialPage 69
Page 86
g
g
g
g
Descriptors and Segment Mechanisms
ical Address
Lo
150
Lo
Address
p= Paging Mechanism for Virtual 8086 Mode only
153 2 10
x 8
Segment Selector
INDEX
ical
x 16
Lo
Se
ment Selector
INDEXTI
Segment Descriptor
GDT or LDT Descriptor Table
Base
Address
Real and Virtual 8086 Modes
ical Address
RPL
Base
Address
INSTRUCTION OFFSET
+
Linear
Address
INSTRUCTION OFFSET
+
Linear
Address
p = Paging Mechanism
p
p
Physical
Address
Physical
Address
Segment
Main Memory
Segment
Main Memory
Protective Mode
Figure 3-6 Selector Mechanisms
Page 70Cyrix Corporation ConfidentialGXm_db_v2.0
Page 87
Selector Load Instruction
g
g
g
g
Descriptors and Segment Mechanisms
3
In Se
Selector
ment
ister
Re
150
INDEXTI RPL
Segment
Descriptor
Global Descriptor
Segment
Descriptor
Local Descriptor
Table
Table
TI = 0
TI = 1
Segment Register
Selected By Decoded
Instruction
Cached Segment
and Descriptor
Cached
Selector
Used If
Available
Se
ment
Cachin
Segment
Base
Address
Figure 3-7 Selector Mechanism Caching
GXm_db_v2.0Cyrix Corporation ConfidentialPage 71
Page 88
Descriptors and Segment Mechanisms
3.7.3GDTR and LDTR Registers
The GDT, and LDT descriptor tables are defined by
the Global Descriptor Table Register (GDTR) and
the Local Descriptor Table Register (LDTR) respectively. Some texts refer to these registers as GDT,
and LDT descriptors.
The following instructions are used in conjunction
with the GDTR and LDTR registers:
• LGDT - Load memory to GDTR
• LLDT - Load memory to LDTR
• SGDT - Store GDTR to memory
• SLDT - Store LDTR to memory
The GDTR is set up in REAL mode using the
LGDT instruction. This is possible as the LGDT
instructions are one of two instructions that directly
load a linear address (instead of a segment relative
address) in protective mode. (The other instruction
is the Load Interrupt Descriptor Table [LIDT]).
As shown in Table 3-19, the GDTR registers
contain a BASE ADDRESS field and a LIMIT field
to that define the GDT tables. (The IDTR register is
described in Section 3.7.3.2 “Task, Gate and Interrupt Descriptors” on page 73.)
Also shown in Table 3-19, the LDTR is only two
bytes wide as it contains only a SELECTOR field.
The contents of the SELECTOR field points to a
descriptor in the GDT table.
3.7.3.1Segment Descript o rs
There are several types of descriptors. A segment
descriptor defines the base address, limit and
attributes of a memory segment.
The GDT or LDT table can hold several types of
descriptors. In particular, the segment descriptors
are stored in either of two registers, the GDT , or the
LDT as shown in Table 3-19). Either of these tables
can store as many as 8,192 (2
tors taking as much as 64KB of memory.
The first descriptor in the GDT (location 0) is not
used by the CPU and is referred to as the “null
descriptor.”
Types of Segment Descriptors
The type of memory segments are defined as
defined by corresponding types of segment
descriptors:
• Code Segment Descriptors
• Data Segment Descriptors
• Stack Segment Descriptors
• LDT Segment Descriptors
13
) eight-byte selec-
Table 3-19 GDTR, LDTR and IDTR Registers
47 161514131211109876543210
GDTR Register
BASELIMIT
IDTR Register
BASELIMIT
LDTR Register
SELECTOR
Page 72Cyrix Corporation ConfidentialGXm_db_v2.0
Page 89
Descriptors and Segment Mechanisms
3
3.7.3.2 Task, Gate and Interrupt
Descriptors
Besides segment descriptors there are descriptors
used in task switching, switching between tasks
with different priority and those used to control
interrupt functions:
• Task State Segment Table Descriptors
• Gate Table Descriptor s
• Interrupt Descriptors.
All descriptors some things in common. They are
all eight bytes in length and have three fields in
(BASE, LIMIT and TYPE). The BASE field defines
the starting location for the table or segment. The
LIMIT field defines the size and the TYPE field
depends on the type of descriptor. One of the main
functions of the TYPE field is to define the access
rights to the associated segment or table.
Interrupt Descriptor Table
The Interrupt Descriptor Table is an array of 256 8byte (4-byte for real mode) interrupt descriptors,
each of which is used to point to an interrupt
service routine. Every interrupt that may occur in
the system must have an associated entry in the
IDT. The contents of the IDTR are completely
visible to the programmer through the use of the
SIDT instruction.
The IDT descriptor table is defined by the Interrupt
Descriptor Table Register (IDTR). Some texts refer
to this register as an IDT descriptor.
The following instructions are used in conjunction
with the IDTR registers:
• LIDT - Load memory to IDTR
• SIDT - Store IDTR to memory
The IDTR is set up in REAL mode using the LIDT
instruction. This is possible as the LIDT instructions is only one of two instructions that directly
load a linear address (instead of a segment relative
address) in protective mode.
As previously shown in Table 3-19, the IDTR
register contains a BASE ADDRESS field and a
LIMIT field that define the IDT tables.
3.7.4Descriptor Bit Structure
The bit structure for application and system
descriptors is shown in Table 3-20. The explanation of the TYPE field is shown in Table 3-22.
Table 3-20 Application and System Segment Descriptors
Table 3-21 Application and System Segment Descriptors Bit Definitions
Memory
Bit
31:24+4BASE
7:0+4
31:16+0
19:16+4LIMIT
15:0+0
14:13+4DPL
11:8+4TYPESe
OffsetNam eDescription
23+4G
22+4D
20+4AVL
15+4P
12+4S
Segment Base Address:
in 4GB physical address space.
Segment Limit:
Granularity Bit.
If G = 1: Limit value interpreted in units of 4KB.
If G = 0: Limit value is interpreted in bytes.
Segment Limit Granularity Bit:
If G = 1: Limit value interpreted in units of 4KB. Se
If G = 0: Limit value is interpreted in bytes. Se
Default Length for Operands and Effective Addresses:
If D = 1: Code se
If D = 0: Code se
If D = 1: Data se
If D = 0: Data se
Segment Available:
Segment Present:
If = 1: Se
If = 0: The BASE and LIMIT fields become available for use by the system. Also, If = 0, a se
not-present exception
virtual memory management.
allowin
Descriptor Privilege Level:
If = 00: Hi
If = 11: Low privile
Descriptor Type:
If = 1: Code or data se
If = 0: System se
ment Type - Refer to Table 3-22 for TYPE bit definitions.
Bit 11 = Executable
Bit 10 = Conformin
Bit 10 = Expand Down if bit 12 = 0
Bit 9 = Readable, if Bit 12 = 1
Bit 9 = Writable, if Bit 12 = 0
Bit 8 = Accessed
Two fields that define the size of the se
ment is memory segment allocated.
hest privilege level
Three fields which collectively define the base location for the se
ment based on the Segment Limit
Defines LIMIT multiplier.
ment size ranges from 1 byte to 1MB.
ment size ranges from 4KB to 4GB.
ment = 32-bit length for operands and effective addresses
ment = 16-bit length for operands and effective addresses
ment = Pushes, calls and pop instructions use 32-bit ESP register
ment = Stack operations use 16-bit SP register
This field is available for use by system software.
enerated when selector for the descriptor is loaded into a segment register
e level
ment
ment
if bit 12 = 1
ment
ment-
Page 74Cyrix Corporation ConfidentialGXm_db_v2.0
Page 91
Descriptors and Segment Mechanisms
g
g
g
g
g
g
Table 3-22 Application and System Segment Descriptors TYPE Bit Definitions
Four kinds of gate descriptors are used to provide
protection during control transfers: call gates, trap
gates, interrupt gates and task gates. (For more
information on protection refer to Section 3.13
“Protection” on page 97.)
Call Gate Descriptor (CGD).
to define legal entry points to a procedure with a
higher privilege level. The call gates are used by
CALL and JUMP instructions in much the same
manner as code segment descriptors. When the
CPU decodes an instruction and sees it refers to a
call gate descriptor in the GDT table or a LDT
table, the call gate is used to point to another
descriptor in the table that defines the destination
code segment.
The following privilege levels are tested during the
transfer through the call gate:
• CPL = Current Privilege Level
Call gates are used
• RPL = Segment Selector Field
• DPL = Descriptor Privilege Level in the call gate
descriptor.
• DPL = Descriptor Privilege Level in the destination code segment.
The maximum value of the CPL and RPL must be
equal or less than the gate DPL. For a JMP
instruction the destination DPL equals the CPL.
For a CALL instruction the destination DPL is less
or equals the CPL.
Conforming Code Segments.
Transfer to a
procedure with a higher privilege level can also be
accomplished by bypassing the use of call gates, if
the requested procedure is to be executed in a
conforming code segment. Conforming code
segments have the C bit set in the TYPE field in
their descriptor.
The bit structure and definitions for gate descriptors are shown in Tables 3-23 and 3-24.
: Number of parameters to copy from the caller’s stack to the called proce-
Page 93
Multitasking and Task State Segments
3
3.8Multitasking and Task State
Segments
The CPU enables rapid task switching using JMP
and CALL instructions that refer to Task State
Segments (TSS). During a switch, the complete
task state of the current task is stored in its TSS,
and the task state of the requested task is loaded
from its TSS. The TSSs are defined through
special segment descriptors and gates.
The
Task Register (TR)
that contain the base address and segment limit for
each task state segment. The TR is loaded and
stored via the LTR and STR instructions, respectively. The TR can only be accessed only during
protected mode and can be loaded when the privilege level is 0 (most privileged). When the TR is
loaded, the TR selector field indexes a TSS
descriptor that must reside in the Global Descriptor
Table (GDT).
holds 16-bit descriptors
Only the 16-bit selector of a TSS descriptor in the
TR is accessible. The BASE, TSS LIMT and
ACCESS RIGHT fields are program invisible.
During task switching, the processor saves the
current CPU state in the TSS before starting a new
task. The TSS can be either a 386/486-type 32-bit
TSS (see Table 3-25) or a 286-type 16-bit TSS (see
Table 3-26).
T ask Gate Descriptors.
provides controlled access to the descriptor for a
task switch. The DPL of the task gate is used to
control access. The selector’s RPL and the CPL of
the procedure must be a higher level (numerically
less) than the DPL of the descriptor. The RPL in
the task gate is not used.
The I/O Map Base Address field in the 32-bit TSS
points to an I/O permission bit map that often
follows the TSS at location +68h.
A task gate descriptor
GXm_db_v2.0Cyrix Corporation ConfidentialPage 77
Page 94
Multitasking and Task State Segments
Table 3-25 32-Bit Task State Segment (TSS) Table
31 16 15 0
I/O Map Base Address000000000000000T +64h
0000000000000000Selector for Task’s LDT+60h
0000000000000000GS+5Ch
0000000000000000FS+58h
0000000000000000DS+54h
0000000000000000SS+50h
0000000000000000CS+4Ch
0000000000000000ES+48h
EDI+44h
ESI+40h
EBP+3Ch
ESP+38h
EBX+34h
EDX+30h
ECX+2Ch
EAX+28h
EFLAGS+24h
EIP+20h
CR3+1Ch
0000000000000000SS for CPL = 2+18h
ESP for CPL = 2+14h
0000000000000000SS for CPL = 1+10h
ESP for CPL = 1+Ch
0000000000000000SS for CPL = 0+8h
ESP for CPL = 0+4h
0000000000000000Back Link (Old TSS Selector)+0h
Note:
0 = Reserved
Page 78Cyrix Corporation ConfidentialGXm_db_v2.0
Page 95
Multitasking and Task State Segments
g
g
g
g
g
g
Table 3-26 16-Bit Task State Segment (TSS) Table
150
Selector for Task’s LDT+2Ah
DS+28h
SS+26h
CS+24h
ES+22h
DI+20h
SI+1Eh
BP+1Ch
SP+1Ah
BX+18h
DX+16h
CX+14h
AX+12h
FLAGS+10h
IP+Eh
SS for Privile
SP for Privile
SS for Privile
SP for Privile
SS for Privile
SP for Privile
Back Link (Old TSS Selector)+0h
e Level 0+Ch
e Level 1+Ah
e Level 1+8h
e Level 1+6h
e Level 0+4h
e Level 0+2h
3
GXm_db_v2.0Cyrix Corporation ConfidentialPage 79
Page 96
Paging Mechanism
3.9Paging Mechanism
The paging mechanism either translates a linear
address to its corresponding physical address. If
the required page is not currently present in RAM,
an exception is generated. When the operating
system services the exception, the required page
can be loaded into memory and the instru ct io n
restarted. Pages are either 4KB or 1MB in size.
The CPU defaults to 4KB pages that are aligned to
4KB boundaries.
A page is addressed by using two levels of tables
as illustrated in Figure 3-8. Bits[31:22] of the 32-bit
linear address, the Directory Table Index (DTI) are
Linear
Address
3122 2112 110
Directory Table Index
(DTI)
Page Table Index
used to locate an entry in the page directory table.
The page directory table acts as a 32-bit master
index to up to 1K individual second-level page
tables. The selected entry in the page directory
table, ref erred to as the dire ctory tabl e entry (D TE),
identifies the starting address of the second-level
page table. The page directory table itself is a page
and is, therefore, aligned to a 4KB boundary. The
physical address of the current page directory table
is stored in the CR3 control register, also referred
to as the Page Directory Base Register (PDBR).
(PTI)
Page Frame Offset
(PFO)
CR3
Control
Register
DTE Cache
2-Entry
Fully Associative
DTE
Directory TablePage TableMemory
1
0
4KB
0
Figure 3-8 Paging Mechanism
Main TLB
32-Entry
4-Way Set
Associative
PTE
31
0
4KB
0
External Memory
Physical Page
4GB
-4KB
-0
0
Page 80Cyrix Corporation ConfidentialGXm_db_v2.0
Page 97
Paging Mechanism
3
Bits [21:12] of the 32-bit linear address, referred to
as the Page Table Index (PTI), locate a 32-bit entry
in the second-level page table. This Page Table
Entry (PTE) contains the base address of the
desired page frame. The second-level page table
addresses up to 1K individual page frames. A
second-level page table is 4KB in size and is itself
a page. Bits [11:0] of the 32-bit linear address, the
Page Frame Offset (PFO), locate the desired physical data within the page frame.
Since the page directory table can point to 1K page
tables, and each page table can point to 1K page
frames, a total of 1M page frames can be implemented. Since each page frame contains 4KB, up
to 4GB of virtual memory can be addressed by the
CPU with a single page directory table.
If the present bit (P) is set in the DTE, the page
table is present and the appropriate page table
entry is read. If P = 1 in the corresponding PTE
(indicating that the page is in memory), the
accessed and dirty bits are updated, if necessary,
and the operand is fetched. Both accessed bits are
set (DTE and PTE), if necessary, to indicate that
the table and the page have been used to translate
a linear address. The dirty bit (D) is set before the first
write is made to a page.
The present bits must be set to validate the
remaining bits in the DTE and PTE. If either of the
present bits are not set, a page fault is generated
when the DTE or PTE is accessed. If P = 0, the
remaining DTE/PTE bits are available for use by
the operating system. For example, the operating
system can use these bits to record where on the
Along with the base address of the page table or
the page frame, each directory table entry or page
table entry contains attribute bits and a present bit
hard disk the pages are located. A page fault is
also generated if the memory reference violates
the page protection attributes.
If = 1: Page is accessible by User at privilege level 3.
If = 0: Page is accessible by Supervisor only when CPL ≤ 2.
Write/Read Attribute:
If = 1: Page is writable.
If = 0: Page is read only.
Present Flag:
If = 1: The page is present in RAM and the remaining DTE/PTE bits are validated
If = 0: The page is not present in RAM and the remaining DTE/PTE bits are available for use by the
programmer.
Specifies the base address of the page or page table.
Undefined and Available to the Programmer
Unavailable to programmer
If set, indicates that a read access or write access has occurred to the page.
Set to 0.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 81
Page 98
Interrupts and Exceptions
Translation Look-Aside Buffer
The translation look-aside buffer (TLB) is a cache
for the paging mechanism and replaces the twolevel page table lookup procedure for TLB hits. The
TLB is a four-way set associative 32-entry page
table cache that automatically keeps the most
commonly used page table entries in the
processor. The 32-entry TLB, coupled with a 4K
page size, results in coverage of 128KB of memory
addresses.
The TLB must be flushed when entries in the page
tables are changed. The TLB is flushed whenever
the CR3 register is loaded. An individual entry in
the TLB can be flushed using the INVLPG instruction.
DTE Cache
The DTE cache caches the two most recent DTEs
so that future TLB misses only require a single
page table read to calculate the physical address.
The DTE cache is disabled following reset and can
be enabled by setting the DTE_EN bit in CCR4[4]
(Index E8h).
3.10Interrupts and Exceptions
The processing of either an interrupt or an exception changes the normal sequential flow of a
program by transferring program control to a
selected service routine. Except for SMM interrupts, the location of the selected service routine is
determined by one of the interrupt vectors stored in
the interrupt descriptor table.
True interrupts are hardware interrupts and are
generated by signal sources external to the CPU.
All exceptions (including so-called software interrupts)
are produced internally by the CPU.
3.10.1Interrupts
External events can interrupt normal program
execution by using one of the three interrupt pins
on the MediaGX processor:
• Non-maskable Interrupt (NMI pin)
• Maskable Interrupt (INTR pin)
• SMM Interrupt (SMI# pin)
For most interrupts, program transfer to the inter-
rupt routine occurs after the current instruction has
been completed. When the execution returns to the
original program, it begins immediately following
the interrupted instruction.
The
NMI interrupt
and always uses interrupt vector 2 to locate its
service routine. Since the interrupt vector is fixed
and is supplied internally , no interrupt acknowledge
bus cycles are performed. This interrupt is normally
reserved for unusual situations such as parity
errors and has priority over INTR interrupts.
Once NMI processing has started, no additional
NMIs are processed until an IRET instruction is
executed, typically at the end of the NMI service
routine. If NMI is re-asserted before execution of
the IRET instruction, one and only one NMI rising
edge is stored and then processed after execution
of the next IRET.
During the NMI service routine, maskable interrupts may be enabled. If an unmasked INTR
occurs during the NMI service routine, the INTR is
serviced and execution returns to the NMI service
routine following the next IRET. If a HAL T instruction is executed within the NMI service routine, the
CPU restarts execution only in response to
RESET, an unmasked INTR or a System Management Mode (SMM) interrupt. NMI does not restart
CPU execution under this condition.
cannot be masked by software
The
INTR interrupt
rupt Enable Flag (IF, bit 9) in the EFLAGS register
is set to 1. Except for string operations, INTR interrupts are acknowledged between instructions.
Long string operations have interrupt windows
Page 82Cyrix Corporation ConfidentialGXm_db_v2.0
is unmasked when the Inter-
between memory moves that allow INTR interrupts
to be acknowledged.
When an INTR interrupt occurs, the CPU performs
an interrupt-acknowledge bus cycle. During this
cycle, the CPU reads an 8-bit vector that is
supplied by an external interrupt controller. This
Page 99
Interrupts and Exceptions
3
vector selects which of the 256 possible interrupt
handlers will be executed in response to the interrupt.
The
SMM interrupt
INTR or NMI. After SMI# is asserted, program
execution is passed to an SMI service routine that
runs in SMM address space reserved for this
purpose. The remainder of this section does not
apply to the SMM interrupts. SMM interrupts are
described in greater detail later in this section.
has higher priority than either
3.10.2Exceptions
Exceptions are generated by an interrupt instruction or a program error. Exceptions are classified
as traps, faults or aborts depending on the mechanism used to report them and the restartability of
the instruction which first caused the exception.
A
Trap exception
following the instruction that generated the trap
exception. Trap exceptions are generated by
execution of a software interrupt instruction (INTO,
INT3, INTn, BOUND), by a single-step operation or
by a data breakpoint.
Software interrupts can be used to simulate hardware interrupts. For example, an INTn instruction
causes the processor to execute the interrupt
service routine pointed to by the nth vector in the
interrupt table. Execution of the interrupt service
routine occurs regardless of the state of the IF flag
(bit 9) in the EFLAGS register.
is reported immediately
A
Fault exception
the instruction that generated the exception. By
reporting the fault before instruction completion,
the CPU is left in a state that allows the instruction
to be restarted and the effects of the faulting
instruction to be nullified. Fault exceptions include
divide-by-zero errors, invalid opcodes, page faults
and coprocessor errors. Debug exceptions (vector
1) are also handled as faults (except for data
breakpoints and single- s tep oper at ion s). Afte r
execution of the fault service routine, the instruction pointer points to the instruction that caused the
fault.
An
Abort exception
that is severe enough that the CPU cannot restart
the program at the faulting instruction. The double
fault (vector 8) is the only abort exception that
occurs on the CPU.
is reported before completio n of
is a type of fault exception
3.10.3Interrupt Vectors
When the CPU services an interrupt or exception,
the current program’s instruction pointer and flags
are pushed onto the stack to allow resumption of
execution of the interrupted program. In protected
mode, the processor also saves an error code for
some exceptions. Program control is then transferred to the interrupt handler (also called the interrupt service routine). Upon execution of an IRET at
the end of the service routine, program execution
resumes at the instruction pointer address saved
on the stack when the interrupt was serviced.
The one byte INT3, or breakpoint interrupt (vector
3), is a particular case of the INTn instruction. By
inserting this one byte instruction in a program, the
user can set breakpoints in the code that can be
used during debug.
Single-step operation is enabled by setting the TF
bit (bit 8) in the EFLAGS register. When TF is set,
the CPU generates a debug exception (vector 1)
after the execution of every instruction. Data breakpoints also generate a debug exception and are
specified by loading the debug registers (DR0DR7) with the appropriate values.
GXm_db_v2.0Cyrix Corporation ConfidentialPage 83
3.10.3.1 Interrupt Vector Assignments
Each interrupt (except SMI#) and exception is
assigned one of 256 interrupt vector numbers as
shown in Table 3-28. The first 32 interrupt vector
assignments are defined or reserved. INT instructions acting as software interrupts may use any of
interrupt vecto rs, 0 th ro ug h 25 5.
The non-maskable hardware interrupt (NMI) is
assigned vector 2. Illegal opcodes including faulty
FPU instructions will cause an illegal opcode
exception, interrupt vector 6. NMI interrupts are
Page 100
Interrupts and Exceptions
enabled by setting bit 2 of the CCR7 register (Index
EBh[2] = 1, see Table 3-11 on page 54 for register
format).
In response to a maskable hardware interrupt
(INTR), the CPU issues interrupt acknowledge bus
cycles used to read the vector number from external
hardware. These vectors should be in the range 32
to 255 as vector s 0 t o 31 are predefined. In PCs,
vectors 8 through 15 are used.
3.10.3.2 Interrupt Descriptor Table
The interrupt vector number is used by the CPU to
locate an entry in the interrupt descriptor table
(IDT). In real mode, each IDT entry consists of a
four-byte far pointer to the beginning of the corresponding interrupt service routine. In protected
mode, each IDT entry is an 8-byte descriptor. The
Interrupt Descriptor Table Register (IDTR) specifies the beginning address and limit of the IDT.
Following reset, the IDTR contains a base address
of 0h with a limit of 3FFh.
The IDT can be located anywhere in physical
memory as determined by the IDTR register. The
IDT may contain different types of descriptors:
interrupt gates, trap gates and task gates. Interrupt
gates are used primarily to enter a hardware interrupt handler. Trap gates are generally used to
enter an exception handler or software interrupt
handler. If an interrupt gate is used, the Interrupt
Enable Flag (IF) in the EFLAGS register is cleared
before the interrupt handler is entered. Task gates
are used to make the transition to a new task.