IOS: checkpoint native Wii Shop connectivity and Starlet optimizations
Add opt-in AX88772 Ethernet with libslirp NAT, pinned Windows runtime setup and USB/network regressions. Correct Hollywood DI/reset interrupt routing and physical SRAM DMA for AES, SHA, NAND, SDIO and OHCI. Keep aligned Thumb bus accesses inside native JIT blocks. Validated: 164 targeted tests pass. User confirmed Wii Shop connection and channel-list navigation at 100% speed / 59.96 FPS on 2026-09-12. Downloads and general channel performance remain unvalidated; local firmware, keys and runtime data are excluded.
This commit is contained in:
+14
-4
@@ -16,6 +16,9 @@ that boot ROMs, console keys, and NAND contents cannot accidentally be committed
|
||||
|
||||
## Configuration
|
||||
|
||||
For the opt-in virtual USB Ethernet adapter and user-mode NAT, see
|
||||
[Wii LLE Ethernet](Wii_LLE_Ethernet.md). It is independent of IOS HLE networking.
|
||||
|
||||
Add the following values to Dolphin's main configuration:
|
||||
|
||||
```ini
|
||||
@@ -121,12 +124,19 @@ X2 and immediately submit the next request with X1 before Starlet is scheduled a
|
||||
- An x86-64 Starlet JIT translates the observed ARM and Thumb integer, branch, interworking and
|
||||
memory-transfer subset. Its inline generation-tagged TLB and direct fastmem paths cover ordinary
|
||||
MEM1/MEM2 accesses plus a measured, direction-specific subset of single SRAM reads. Every SRAM
|
||||
write, register-list transfer, TLB miss, MMIO access, protected boot0 overlay, invalid SRAM
|
||||
aperture or unsupported instruction remains an architectural side exit: registers are flushed,
|
||||
the exact interpreter/device operation runs, and the dispatcher re-samples IRQ/FIQ, IPC yield,
|
||||
CP15 and translation state before another native block executes.
|
||||
write and MMIO access still uses the exact bus. Aligned Thumb loads/stores can call that bus
|
||||
directly from native code, including 8-/16-/32-bit and signed reads, without re-decoding the
|
||||
instruction or returning through the dispatcher. Unaligned Thumb accesses retain interpreter
|
||||
semantics, including rotated word loads and halfwords crossing a translation boundary.
|
||||
Protected boot0 overlays and invalid SRAM apertures remain enforced by the bus.
|
||||
- Big-endian Starlet address space, 96 KiB of physical SRAM (64 KiB bank A plus 32 KiB bank B)
|
||||
exposed through the hardware's unusual 128 KiB windows, plus shared MEM1/MEM2 access.
|
||||
Device DMA uses the physical A/B bank layout at `0x0d400000`, independent of the CPU's
|
||||
`HW_SRNPROT.SM` bank swap. Applying the CPU mapping twice discarded AES output in IOS's SRAM
|
||||
stack and left `IOSC_GenerateRand` callers retrying during the Shop SSL handshake. The common
|
||||
DMA accessors cover AES, SHA, NAND, SD/SDIO and OHCI without changing CPU aliases or boot0
|
||||
protection. Known-answer AES/SHA tests and bank-boundary tests reproduce the old defect.
|
||||
See MINI's [CPU-to-DMA address conversion](https://github.com/fail0verflow/mini/blob/master/memory.c).
|
||||
- Raw NAND reads, chip identification/status, Wii ECC generation, ECC-enabled page programming
|
||||
(including the calculated-ECC DMA side buffer and random spare input), and 64-page block erase.
|
||||
Programming obeys the NAND 1-to-0 bit rule.
|
||||
|
||||
Reference in New Issue
Block a user