armviz

ESR_EL1

64-bitTrap

The syndrome register: why the exception happened. A handler reads EC to learn the class of exception, then interprets ISS, whose layout depends entirely on that class. IL records whether the faulting instruction was 32 or 64 bits, which is the first thing to check when stepping through an unknown exception.

ISS means something different for every EC value -- there are 35 layouts for 35 classes -- so a handler must switch on EC before trusting the field. All 35 are decoded, by src/lib/esr.ts, from a table generated from an independent decoder and checked against it on every run.

Field layout

—
EC[31:26]31:26
25
ISS[24:0]24:0
byte 7
byte 6
byte 5
byte 4
byte 3
byte 2
byte 1
byte 0

Current value hover a field to locate it

B7
B6
B5
B4
B3
B2
B1
B0

Fields

BitsFieldBitsValueDescription
63:32—32Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise.
31:26EC[31:26]6

Exception class. The high-level summary of the cause: an instruction abort, a data abort, a system call, a breakpoint. Everything else in the register is read through this, because ISS means something different for each class.

0b000000
Unknown reason
0b000001
Wrapped WF* instruction execution
0b000011
Trapped MCR or MRC access with coproc = 0b1111
0b000100
Trapped MCRR or MRRC access with coproc = 0b1111
0b000101
Trapped MCR or MRC access with coproc = 0b1110
0b000110
Trapped LDC or STC access
0b000111
Trapped access to SVE, Advanced SIMD or floating point
0b001010
Trapped execution of an LD64B, ST64B, ST64BV or ST64BV0 instruction
0b001100
Trapped MRRC access with coproc = 0b1110
0b001101
Branch Target Exception
0b001110
Illegal Execution state
0b010001
SVC instruction execution in AArch32 state
0b010101
SVC instruction execution in AArch64 state
0b010110
HVC instruction execution in AArch64 state
0b010111
SMC instruction execution in AArch64 state
0b011000
Trapped MSR, MRS or System instruction execution in AArch64 state
0b011001
Access to SVE functionality trapped by CPACR_EL1.ZEN, CPTR_EL2.ZEN, CPTR_EL2.TZ or CPTR_EL3.EZ
0b011100
Exception from a Pointer Authentication instruction authentication failure
0b100000
Instruction Abort from a lower Exception level
0b100001
Instruction Abort taken without a change in Exception level
0b100010
PC alignment fault exception
0b100100
Data Abort from a lower Exception level
0b100101
Data Abort taken without a change in Exception level
0b100110
SP alignment fault exception
0b101000
Trapped floating-point exception taken from AArch32 state
0b101100
Trapped floating-point exception taken from AArch64 state
0b101111
SError interrupt
0b110000
Breakpoint exception from a lower Exception level
0b110001
Breakpoint exception taken without a change in Exception level
0b110010
Software Step exception from a lower Exception level
0b110011
Software Step exception taken without a change in Exception level
0b110100
Watchpoint exception from a lower Exception level
0b110101
Watchpoint exception taken without a change in Exception level
0b111000
BKPT instruction execution in AArch32 state
0b111100
BRK instruction execution in AArch64 state
25IL[25]1

Instruction length. Set means the faulting instruction was a 32-bit AArch32 instruction, clear means it was an AArch64 instruction.

0
AArch64 instruction
1
AArch32 instruction
24:0ISS[24:0]250x0 (0)

Instruction specific syndrome. Its layout is chosen by EC. For a data abort it holds the faulting address's page table entry fields and the fault status code; for an exception generated by a system register it holds the register's five op encoding fields, letting a handler identify which register was touched.