armviz

TCR_EL2

64-bitMemory management

How the MMU at EL2 translates: how many address bits are significant, the granule size for each regime, and where each root table is expected to be aligned.

Field layout

—
34:32
27
23
T1SZ[21:16]21:16
15:14
9
8
7
T0SZ[5:0]5:0
byte 7
byte 6
byte 5
byte 4
byte 3
byte 2
byte 1
byte 0

Current value hover a field to locate it

B7
B6
B5
B4
B3
B2
B1
B0

Fields

BitsFieldBitsValueDescription
63:35—29Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise.
34:32IPS[34:32]30x0

Physical address size.

31:28—4Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise.
27TBI1[27:27]10x0

Ignore the top byte for the TTBR1 regime.

26:24—3Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise.
23EPD1[23:23]10x0

TTBR1 walk disable. Position measured the same way: setting this bit alone made every high address fault.

22—1Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise.
21:16T1SZ[21:16]60x0 (0)

Address bits ignored at EL1. Position measured: see verify-walk-qemu.mjs --sweep, where writing T1SZ at each candidate shift in turn left exactly one position translating a high-half address.

15:14TG0[15:14]20x0

TTBR0 granule size: 4 KiB, 64 KiB or 16 KiB. The order is not the obvious one, so read the architecture rather than assuming.

13:10—4Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise.
9SH0[9:9]10x0

TTBR0 walk shareability.

8ORGN0[8:8]10x0

TTBR0 walk cacheability for writes.

7IRGN0[7:7]10x0

TTBR0 walk cacheability for reads.

6—1Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise.
5:0T0SZ[5:0]60x0 (0)

Address bits ignored at EL0, so the TTBR0 regime covers 64 minus this many bits.