1 // SPDX-License-Identifier: GPL-2.0
2 /* arch/sparc64/kernel/process.c
4 * Copyright (C) 1995, 1996, 2008 David S. Miller (davem@davemloft.net)
5 * Copyright (C) 1996 Eddie C. Dost (ecd@skynet.be)
6 * Copyright (C) 1997, 1998 Jakub Jelinek (jj@sunsite.mff.cuni.cz)
10 * This file handles the architecture-dependent parts of process handling..
15 #include <linux/errno.h>
16 #include <linux/export.h>
17 #include <linux/sched.h>
18 #include <linux/sched/debug.h>
19 #include <linux/sched/task.h>
20 #include <linux/sched/task_stack.h>
21 #include <linux/kernel.h>
24 #include <linux/smp.h>
25 #include <linux/stddef.h>
26 #include <linux/ptrace.h>
27 #include <linux/slab.h>
28 #include <linux/user.h>
29 #include <linux/delay.h>
30 #include <linux/compat.h>
31 #include <linux/tick.h>
32 #include <linux/init.h>
33 #include <linux/cpu.h>
34 #include <linux/perf_event.h>
35 #include <linux/elfcore.h>
36 #include <linux/sysrq.h>
37 #include <linux/nmi.h>
38 #include <linux/context_tracking.h>
39 #include <linux/signal.h>
41 #include <linux/uaccess.h>
43 #include <asm/pgalloc.h>
44 #include <asm/processor.h>
45 #include <asm/pstate.h>
47 #include <asm/fpumacro.h>
49 #include <asm/cpudata.h>
50 #include <asm/mmu_context.h>
51 #include <asm/unistd.h>
52 #include <asm/hypervisor.h>
53 #include <asm/syscalls.h>
54 #include <asm/irq_regs.h>
60 /* Idle loop support on sparc64. */
61 void arch_cpu_idle(void)
63 if (tlb_type
!= hypervisor
) {
71 /* The sun4v sleeping code requires that we have PSTATE.IE cleared over
72 * the cpu sleep hypervisor call.
75 "rdpr %%pstate, %0\n\t"
77 "wrpr %0, %%g0, %%pstate"
81 if (!need_resched() && !cpu_is_offline(smp_processor_id())) {
83 /* If resumed by cpu_poke then we need to explicitly
84 * call scheduler_ipi().
89 /* Re-enable interrupts. */
91 "rdpr %%pstate, %0\n\t"
93 "wrpr %0, %%g0, %%pstate"
99 #ifdef CONFIG_HOTPLUG_CPU
100 void arch_cpu_idle_dead(void)
102 sched_preempt_enable_no_resched();
108 static void show_regwindow32(struct pt_regs
*regs
)
110 struct reg_window32 __user
*rw
;
111 struct reg_window32 r_w
;
114 __asm__
__volatile__ ("flushw");
115 rw
= compat_ptr((unsigned int)regs
->u_regs
[14]);
118 if (copy_from_user (&r_w
, rw
, sizeof(r_w
))) {
124 printk("l0: %08x l1: %08x l2: %08x l3: %08x "
125 "l4: %08x l5: %08x l6: %08x l7: %08x\n",
126 r_w
.locals
[0], r_w
.locals
[1], r_w
.locals
[2], r_w
.locals
[3],
127 r_w
.locals
[4], r_w
.locals
[5], r_w
.locals
[6], r_w
.locals
[7]);
128 printk("i0: %08x i1: %08x i2: %08x i3: %08x "
129 "i4: %08x i5: %08x i6: %08x i7: %08x\n",
130 r_w
.ins
[0], r_w
.ins
[1], r_w
.ins
[2], r_w
.ins
[3],
131 r_w
.ins
[4], r_w
.ins
[5], r_w
.ins
[6], r_w
.ins
[7]);
134 #define show_regwindow32(regs) do { } while (0)
137 static void show_regwindow(struct pt_regs
*regs
)
139 struct reg_window __user
*rw
;
140 struct reg_window
*rwk
;
141 struct reg_window r_w
;
144 if ((regs
->tstate
& TSTATE_PRIV
) || !(test_thread_flag(TIF_32BIT
))) {
145 __asm__
__volatile__ ("flushw");
146 rw
= (struct reg_window __user
*)
147 (regs
->u_regs
[14] + STACK_BIAS
);
148 rwk
= (struct reg_window
*)
149 (regs
->u_regs
[14] + STACK_BIAS
);
150 if (!(regs
->tstate
& TSTATE_PRIV
)) {
153 if (copy_from_user (&r_w
, rw
, sizeof(r_w
))) {
161 show_regwindow32(regs
);
164 printk("l0: %016lx l1: %016lx l2: %016lx l3: %016lx\n",
165 rwk
->locals
[0], rwk
->locals
[1], rwk
->locals
[2], rwk
->locals
[3]);
166 printk("l4: %016lx l5: %016lx l6: %016lx l7: %016lx\n",
167 rwk
->locals
[4], rwk
->locals
[5], rwk
->locals
[6], rwk
->locals
[7]);
168 printk("i0: %016lx i1: %016lx i2: %016lx i3: %016lx\n",
169 rwk
->ins
[0], rwk
->ins
[1], rwk
->ins
[2], rwk
->ins
[3]);
170 printk("i4: %016lx i5: %016lx i6: %016lx i7: %016lx\n",
171 rwk
->ins
[4], rwk
->ins
[5], rwk
->ins
[6], rwk
->ins
[7]);
172 if (regs
->tstate
& TSTATE_PRIV
)
173 printk("I7: <%pS>\n", (void *) rwk
->ins
[7]);
176 void show_regs(struct pt_regs
*regs
)
178 show_regs_print_info(KERN_DEFAULT
);
180 printk("TSTATE: %016lx TPC: %016lx TNPC: %016lx Y: %08x %s\n", regs
->tstate
,
181 regs
->tpc
, regs
->tnpc
, regs
->y
, print_tainted());
182 printk("TPC: <%pS>\n", (void *) regs
->tpc
);
183 printk("g0: %016lx g1: %016lx g2: %016lx g3: %016lx\n",
184 regs
->u_regs
[0], regs
->u_regs
[1], regs
->u_regs
[2],
186 printk("g4: %016lx g5: %016lx g6: %016lx g7: %016lx\n",
187 regs
->u_regs
[4], regs
->u_regs
[5], regs
->u_regs
[6],
189 printk("o0: %016lx o1: %016lx o2: %016lx o3: %016lx\n",
190 regs
->u_regs
[8], regs
->u_regs
[9], regs
->u_regs
[10],
192 printk("o4: %016lx o5: %016lx sp: %016lx ret_pc: %016lx\n",
193 regs
->u_regs
[12], regs
->u_regs
[13], regs
->u_regs
[14],
195 printk("RPC: <%pS>\n", (void *) regs
->u_regs
[15]);
196 show_regwindow(regs
);
197 show_stack(current
, (unsigned long *)regs
->u_regs
[UREG_FP
], KERN_DEFAULT
);
200 union global_cpu_snapshot global_cpu_snapshot
[NR_CPUS
];
201 static DEFINE_SPINLOCK(global_cpu_snapshot_lock
);
203 static void __global_reg_self(struct thread_info
*tp
, struct pt_regs
*regs
,
206 struct global_reg_snapshot
*rp
;
210 rp
= &global_cpu_snapshot
[this_cpu
].reg
;
212 rp
->tstate
= regs
->tstate
;
214 rp
->tnpc
= regs
->tnpc
;
215 rp
->o7
= regs
->u_regs
[UREG_I7
];
217 if (regs
->tstate
& TSTATE_PRIV
) {
218 struct reg_window
*rw
;
220 rw
= (struct reg_window
*)
221 (regs
->u_regs
[UREG_FP
] + STACK_BIAS
);
222 if (kstack_valid(tp
, (unsigned long) rw
)) {
224 rw
= (struct reg_window
*)
225 (rw
->ins
[6] + STACK_BIAS
);
226 if (kstack_valid(tp
, (unsigned long) rw
))
227 rp
->rpc
= rw
->ins
[7];
236 /* In order to avoid hangs we do not try to synchronize with the
237 * global register dump client cpus. The last store they make is to
238 * the thread pointer, so do a short poll waiting for that to become
241 static void __global_reg_poll(struct global_reg_snapshot
*gp
)
245 while (!gp
->thread
&& ++limit
< 100) {
251 void arch_trigger_cpumask_backtrace(const cpumask_t
*mask
, bool exclude_self
)
253 struct thread_info
*tp
= current_thread_info();
254 struct pt_regs
*regs
= get_irq_regs();
261 spin_lock_irqsave(&global_cpu_snapshot_lock
, flags
);
263 this_cpu
= raw_smp_processor_id();
265 memset(global_cpu_snapshot
, 0, sizeof(global_cpu_snapshot
));
267 if (cpumask_test_cpu(this_cpu
, mask
) && !exclude_self
)
268 __global_reg_self(tp
, regs
, this_cpu
);
270 smp_fetch_global_regs();
272 for_each_cpu(cpu
, mask
) {
273 struct global_reg_snapshot
*gp
;
275 if (exclude_self
&& cpu
== this_cpu
)
278 gp
= &global_cpu_snapshot
[cpu
].reg
;
280 __global_reg_poll(gp
);
283 printk("%c CPU[%3d]: TSTATE[%016lx] TPC[%016lx] TNPC[%016lx] TASK[%s:%d]\n",
284 (cpu
== this_cpu
? '*' : ' '), cpu
,
285 gp
->tstate
, gp
->tpc
, gp
->tnpc
,
286 ((tp
&& tp
->task
) ? tp
->task
->comm
: "NULL"),
287 ((tp
&& tp
->task
) ? tp
->task
->pid
: -1));
289 if (gp
->tstate
& TSTATE_PRIV
) {
290 printk(" TPC[%pS] O7[%pS] I7[%pS] RPC[%pS]\n",
296 printk(" TPC[%lx] O7[%lx] I7[%lx] RPC[%lx]\n",
297 gp
->tpc
, gp
->o7
, gp
->i7
, gp
->rpc
);
300 touch_nmi_watchdog();
303 memset(global_cpu_snapshot
, 0, sizeof(global_cpu_snapshot
));
305 spin_unlock_irqrestore(&global_cpu_snapshot_lock
, flags
);
308 #ifdef CONFIG_MAGIC_SYSRQ
310 static void sysrq_handle_globreg(int key
)
312 trigger_all_cpu_backtrace();
315 static const struct sysrq_key_op sparc_globalreg_op
= {
316 .handler
= sysrq_handle_globreg
,
317 .help_msg
= "global-regs(y)",
318 .action_msg
= "Show Global CPU Regs",
321 static void __global_pmu_self(int this_cpu
)
323 struct global_pmu_snapshot
*pp
;
329 pp
= &global_cpu_snapshot
[this_cpu
].pmu
;
332 if (tlb_type
== hypervisor
&&
333 sun4v_chip_type
>= SUN4V_CHIP_NIAGARA4
)
336 for (i
= 0; i
< num
; i
++) {
337 pp
->pcr
[i
] = pcr_ops
->read_pcr(i
);
338 pp
->pic
[i
] = pcr_ops
->read_pic(i
);
342 static void __global_pmu_poll(struct global_pmu_snapshot
*pp
)
346 while (!pp
->pcr
[0] && ++limit
< 100) {
352 static void pmu_snapshot_all_cpus(void)
357 spin_lock_irqsave(&global_cpu_snapshot_lock
, flags
);
359 memset(global_cpu_snapshot
, 0, sizeof(global_cpu_snapshot
));
361 this_cpu
= raw_smp_processor_id();
363 __global_pmu_self(this_cpu
);
365 smp_fetch_global_pmu();
367 for_each_online_cpu(cpu
) {
368 struct global_pmu_snapshot
*pp
= &global_cpu_snapshot
[cpu
].pmu
;
370 __global_pmu_poll(pp
);
372 printk("%c CPU[%3d]: PCR[%08lx:%08lx:%08lx:%08lx] PIC[%08lx:%08lx:%08lx:%08lx]\n",
373 (cpu
== this_cpu
? '*' : ' '), cpu
,
374 pp
->pcr
[0], pp
->pcr
[1], pp
->pcr
[2], pp
->pcr
[3],
375 pp
->pic
[0], pp
->pic
[1], pp
->pic
[2], pp
->pic
[3]);
377 touch_nmi_watchdog();
380 memset(global_cpu_snapshot
, 0, sizeof(global_cpu_snapshot
));
382 spin_unlock_irqrestore(&global_cpu_snapshot_lock
, flags
);
385 static void sysrq_handle_globpmu(int key
)
387 pmu_snapshot_all_cpus();
390 static const struct sysrq_key_op sparc_globalpmu_op
= {
391 .handler
= sysrq_handle_globpmu
,
392 .help_msg
= "global-pmu(x)",
393 .action_msg
= "Show Global PMU Regs",
396 static int __init
sparc_sysrq_init(void)
398 int ret
= register_sysrq_key('y', &sparc_globalreg_op
);
401 ret
= register_sysrq_key('x', &sparc_globalpmu_op
);
405 core_initcall(sparc_sysrq_init
);
409 /* Free current thread data structures etc.. */
410 void exit_thread(struct task_struct
*tsk
)
412 struct thread_info
*t
= task_thread_info(tsk
);
415 if (t
->utraps
[0] < 2)
422 void flush_thread(void)
424 struct thread_info
*t
= current_thread_info();
425 struct mm_struct
*mm
;
429 tsb_context_switch(mm
);
431 set_thread_wsaved(0);
433 /* Clear FPU register state. */
437 /* It's a bit more tricky when 64-bit tasks are involved... */
438 static unsigned long clone_stackframe(unsigned long csp
, unsigned long psp
)
440 bool stack_64bit
= test_thread_64bit_stack(psp
);
441 unsigned long fp
, distance
, rval
;
446 __get_user(fp
, &(((struct reg_window __user
*)psp
)->ins
[6]));
448 if (test_thread_flag(TIF_32BIT
))
451 __get_user(fp
, &(((struct reg_window32 __user
*)psp
)->ins
[6]));
453 /* Now align the stack as this is mandatory in the Sparc ABI
454 * due to how register windows work. This hides the
455 * restriction from thread libraries etc.
460 rval
= (csp
- distance
);
461 if (copy_in_user((void __user
*) rval
, (void __user
*) psp
, distance
))
463 else if (!stack_64bit
) {
464 if (put_user(((u32
)csp
),
465 &(((struct reg_window32 __user
*)rval
)->ins
[6])))
468 if (put_user(((u64
)csp
- STACK_BIAS
),
469 &(((struct reg_window __user
*)rval
)->ins
[6])))
472 rval
= rval
- STACK_BIAS
;
478 /* Standard stuff. */
479 static inline void shift_window_buffer(int first_win
, int last_win
,
480 struct thread_info
*t
)
484 for (i
= first_win
; i
< last_win
; i
++) {
485 t
->rwbuf_stkptrs
[i
] = t
->rwbuf_stkptrs
[i
+1];
486 memcpy(&t
->reg_window
[i
], &t
->reg_window
[i
+1],
487 sizeof(struct reg_window
));
491 void synchronize_user_stack(void)
493 struct thread_info
*t
= current_thread_info();
494 unsigned long window
;
496 flush_user_windows();
497 if ((window
= get_thread_wsaved()) != 0) {
500 struct reg_window
*rwin
= &t
->reg_window
[window
];
501 int winsize
= sizeof(struct reg_window
);
504 sp
= t
->rwbuf_stkptrs
[window
];
506 if (test_thread_64bit_stack(sp
))
509 winsize
= sizeof(struct reg_window32
);
511 if (!copy_to_user((char __user
*)sp
, rwin
, winsize
)) {
512 shift_window_buffer(window
, get_thread_wsaved() - 1, t
);
513 set_thread_wsaved(get_thread_wsaved() - 1);
519 static void stack_unaligned(unsigned long sp
)
521 force_sig_fault(SIGBUS
, BUS_ADRALN
, (void __user
*) sp
, 0);
524 static const char uwfault32
[] = KERN_INFO \
525 "%s[%d]: bad register window fault: SP %08lx (orig_sp %08lx) TPC %08lx O7 %08lx\n";
526 static const char uwfault64
[] = KERN_INFO \
527 "%s[%d]: bad register window fault: SP %016lx (orig_sp %016lx) TPC %08lx O7 %016lx\n";
529 void fault_in_user_windows(struct pt_regs
*regs
)
531 struct thread_info
*t
= current_thread_info();
532 unsigned long window
;
534 flush_user_windows();
535 window
= get_thread_wsaved();
537 if (likely(window
!= 0)) {
540 struct reg_window
*rwin
= &t
->reg_window
[window
];
541 int winsize
= sizeof(struct reg_window
);
542 unsigned long sp
, orig_sp
;
544 orig_sp
= sp
= t
->rwbuf_stkptrs
[window
];
546 if (test_thread_64bit_stack(sp
))
549 winsize
= sizeof(struct reg_window32
);
551 if (unlikely(sp
& 0x7UL
))
554 if (unlikely(copy_to_user((char __user
*)sp
,
556 if (show_unhandled_signals
)
557 printk_ratelimited(is_compat_task() ?
558 uwfault32
: uwfault64
,
559 current
->comm
, current
->pid
,
562 regs
->u_regs
[UREG_I7
]);
567 set_thread_wsaved(0);
571 set_thread_wsaved(window
+ 1);
575 asmlinkage
long sparc_do_fork(unsigned long clone_flags
,
576 unsigned long stack_start
,
577 struct pt_regs
*regs
,
578 unsigned long stack_size
)
580 int __user
*parent_tid_ptr
, *child_tid_ptr
;
581 unsigned long orig_i1
= regs
->u_regs
[UREG_I1
];
585 if (test_thread_flag(TIF_32BIT
)) {
586 parent_tid_ptr
= compat_ptr(regs
->u_regs
[UREG_I2
]);
587 child_tid_ptr
= compat_ptr(regs
->u_regs
[UREG_I4
]);
591 parent_tid_ptr
= (int __user
*) regs
->u_regs
[UREG_I2
];
592 child_tid_ptr
= (int __user
*) regs
->u_regs
[UREG_I4
];
595 ret
= do_fork(clone_flags
, stack_start
, stack_size
,
596 parent_tid_ptr
, child_tid_ptr
);
598 /* If we get an error and potentially restart the system
599 * call, we're screwed because copy_thread() clobbered
600 * the parent's %o1. So detect that case and restore it
603 if ((unsigned long)ret
>= -ERESTART_RESTARTBLOCK
)
604 regs
->u_regs
[UREG_I1
] = orig_i1
;
609 /* Copy a Sparc thread. The fork() return value conventions
610 * under SunOS are nothing short of bletcherous:
611 * Parent --> %o0 == childs pid, %o1 == 0
612 * Child --> %o0 == parents pid, %o1 == 1
614 int copy_thread(unsigned long clone_flags
, unsigned long sp
,
615 unsigned long arg
, struct task_struct
*p
)
617 struct thread_info
*t
= task_thread_info(p
);
618 struct pt_regs
*regs
= current_pt_regs();
619 struct sparc_stackf
*parent_sf
;
620 unsigned long child_stack_sz
;
621 char *child_trap_frame
;
623 /* Calculate offset to stack_frame & pt_regs */
624 child_stack_sz
= (STACKFRAME_SZ
+ TRACEREG_SZ
);
625 child_trap_frame
= (task_stack_page(p
) +
626 (THREAD_SIZE
- child_stack_sz
));
629 t
->ksp
= ((unsigned long) child_trap_frame
) - STACK_BIAS
;
630 t
->kregs
= (struct pt_regs
*) (child_trap_frame
+
631 sizeof(struct sparc_stackf
));
634 if (unlikely(p
->flags
& PF_KTHREAD
)) {
635 memset(child_trap_frame
, 0, child_stack_sz
);
636 __thread_flag_byte_ptr(t
)[TI_FLAG_BYTE_CWP
] =
637 (current_pt_regs()->tstate
+ 1) & TSTATE_CWP
;
638 t
->current_ds
= ASI_P
;
639 t
->kregs
->u_regs
[UREG_G1
] = sp
; /* function */
640 t
->kregs
->u_regs
[UREG_G2
] = arg
;
644 parent_sf
= ((struct sparc_stackf
*) regs
) - 1;
645 memcpy(child_trap_frame
, parent_sf
, child_stack_sz
);
646 if (t
->flags
& _TIF_32BIT
) {
647 sp
&= 0x00000000ffffffffUL
;
648 regs
->u_regs
[UREG_FP
] &= 0x00000000ffffffffUL
;
650 t
->kregs
->u_regs
[UREG_FP
] = sp
;
651 __thread_flag_byte_ptr(t
)[TI_FLAG_BYTE_CWP
] =
652 (regs
->tstate
+ 1) & TSTATE_CWP
;
653 t
->current_ds
= ASI_AIUS
;
654 if (sp
!= regs
->u_regs
[UREG_FP
]) {
657 csp
= clone_stackframe(sp
, regs
->u_regs
[UREG_FP
]);
660 t
->kregs
->u_regs
[UREG_FP
] = csp
;
665 /* Set the return value for the child. */
666 t
->kregs
->u_regs
[UREG_I0
] = current
->pid
;
667 t
->kregs
->u_regs
[UREG_I1
] = 1;
669 /* Set the second return value for the parent. */
670 regs
->u_regs
[UREG_I1
] = 0;
672 if (clone_flags
& CLONE_SETTLS
)
673 t
->kregs
->u_regs
[UREG_G7
] = regs
->u_regs
[UREG_I3
];
678 /* TIF_MCDPER in thread info flags for current task is updated lazily upon
679 * a context switch. Update this flag in current task's thread flags
680 * before dup so the dup'd task will inherit the current TIF_MCDPER flag.
682 int arch_dup_task_struct(struct task_struct
*dst
, struct task_struct
*src
)
685 register unsigned long tmp_mcdper
;
687 __asm__
__volatile__(
688 ".word 0x83438000\n\t" /* rd %mcdper, %g1 */
694 set_thread_flag(TIF_MCDPER
);
696 clear_thread_flag(TIF_MCDPER
);
705 unsigned int pr_regs
[32];
706 unsigned long pr_dregs
[16];
708 unsigned int __unused
;
710 unsigned char pr_qcnt
;
711 unsigned char pr_q_entrysize
;
713 unsigned int pr_q
[64];
717 * fill in the fpu structure for a core dump.
719 int dump_fpu (struct pt_regs
* regs
, elf_fpregset_t
* fpregs
)
721 unsigned long *kfpregs
= current_thread_info()->fpregs
;
722 unsigned long fprs
= current_thread_info()->fpsaved
[0];
724 if (test_thread_flag(TIF_32BIT
)) {
725 elf_fpregset_t32
*fpregs32
= (elf_fpregset_t32
*)fpregs
;
728 memcpy(&fpregs32
->pr_fr
.pr_regs
[0], kfpregs
,
729 sizeof(unsigned int) * 32);
731 memset(&fpregs32
->pr_fr
.pr_regs
[0], 0,
732 sizeof(unsigned int) * 32);
733 fpregs32
->pr_qcnt
= 0;
734 fpregs32
->pr_q_entrysize
= 8;
735 memset(&fpregs32
->pr_q
[0], 0,
736 (sizeof(unsigned int) * 64));
737 if (fprs
& FPRS_FEF
) {
738 fpregs32
->pr_fsr
= (unsigned int) current_thread_info()->xfsr
[0];
741 fpregs32
->pr_fsr
= 0;
746 memcpy(&fpregs
->pr_regs
[0], kfpregs
,
747 sizeof(unsigned int) * 32);
749 memset(&fpregs
->pr_regs
[0], 0,
750 sizeof(unsigned int) * 32);
752 memcpy(&fpregs
->pr_regs
[16], kfpregs
+16,
753 sizeof(unsigned int) * 32);
755 memset(&fpregs
->pr_regs
[16], 0,
756 sizeof(unsigned int) * 32);
757 if(fprs
& FPRS_FEF
) {
758 fpregs
->pr_fsr
= current_thread_info()->xfsr
[0];
759 fpregs
->pr_gsr
= current_thread_info()->gsr
[0];
761 fpregs
->pr_fsr
= fpregs
->pr_gsr
= 0;
763 fpregs
->pr_fprs
= fprs
;
767 EXPORT_SYMBOL(dump_fpu
);
769 unsigned long get_wchan(struct task_struct
*task
)
771 unsigned long pc
, fp
, bias
= 0;
772 struct thread_info
*tp
;
773 struct reg_window
*rw
;
774 unsigned long ret
= 0;
777 if (!task
|| task
== current
||
778 task
->state
== TASK_RUNNING
)
781 tp
= task_thread_info(task
);
783 fp
= task_thread_info(task
)->ksp
+ bias
;
786 if (!kstack_valid(tp
, fp
))
788 rw
= (struct reg_window
*) fp
;
790 if (!in_sched_functions(pc
)) {
794 fp
= rw
->ins
[6] + bias
;
795 } while (++count
< 16);