IOS: checkpoint native Wii Shop connectivity and Starlet optimizations

Add opt-in AX88772 Ethernet with libslirp NAT, pinned Windows runtime setup and USB/network regressions. Correct Hollywood DI/reset interrupt routing and physical SRAM DMA for AES, SHA, NAND, SDIO and OHCI. Keep aligned Thumb bus accesses inside native JIT blocks.

Validated: 164 targeted tests pass. User confirmed Wii Shop connection and channel-list navigation at 100% speed / 59.96 FPS on 2026-09-12. Downloads and general channel performance remain unvalidated; local firmware, keys and runtime data are excluded.
This commit is contained in:
2026-09-12 11:08:25 +02:00
parent ebb753d09a
commit b931671fde
24 changed files with 2952 additions and 64 deletions
+14 -4
View File
@@ -16,6 +16,9 @@ that boot ROMs, console keys, and NAND contents cannot accidentally be committed
## Configuration
For the opt-in virtual USB Ethernet adapter and user-mode NAT, see
[Wii LLE Ethernet](Wii_LLE_Ethernet.md). It is independent of IOS HLE networking.
Add the following values to Dolphin's main configuration:
```ini
@@ -121,12 +124,19 @@ X2 and immediately submit the next request with X1 before Starlet is scheduled a
- An x86-64 Starlet JIT translates the observed ARM and Thumb integer, branch, interworking and
memory-transfer subset. Its inline generation-tagged TLB and direct fastmem paths cover ordinary
MEM1/MEM2 accesses plus a measured, direction-specific subset of single SRAM reads. Every SRAM
write, register-list transfer, TLB miss, MMIO access, protected boot0 overlay, invalid SRAM
aperture or unsupported instruction remains an architectural side exit: registers are flushed,
the exact interpreter/device operation runs, and the dispatcher re-samples IRQ/FIQ, IPC yield,
CP15 and translation state before another native block executes.
write and MMIO access still uses the exact bus. Aligned Thumb loads/stores can call that bus
directly from native code, including 8-/16-/32-bit and signed reads, without re-decoding the
instruction or returning through the dispatcher. Unaligned Thumb accesses retain interpreter
semantics, including rotated word loads and halfwords crossing a translation boundary.
Protected boot0 overlays and invalid SRAM apertures remain enforced by the bus.
- Big-endian Starlet address space, 96 KiB of physical SRAM (64 KiB bank A plus 32 KiB bank B)
exposed through the hardware's unusual 128 KiB windows, plus shared MEM1/MEM2 access.
Device DMA uses the physical A/B bank layout at `0x0d400000`, independent of the CPU's
`HW_SRNPROT.SM` bank swap. Applying the CPU mapping twice discarded AES output in IOS's SRAM
stack and left `IOSC_GenerateRand` callers retrying during the Shop SSL handshake. The common
DMA accessors cover AES, SHA, NAND, SD/SDIO and OHCI without changing CPU aliases or boot0
protection. Known-answer AES/SHA tests and bank-boundary tests reproduce the old defect.
See MINI's [CPU-to-DMA address conversion](https://github.com/fail0verflow/mini/blob/master/memory.c).
- Raw NAND reads, chip identification/status, Wii ECC generation, ECC-enabled page programming
(including the calculated-ECC DMA side buffer and random spare input), and 64-page block erase.
Programming obeys the NAND 1-to-0 bit rule.