TCR_EL2
64-bitMemory managementHow the MMU at EL2 translates: how many address bits are significant, the granule size for each regime, and where each root table is expected to be aligned.
Field layout
Current value hover a field to locate it
Fields
| Bits | Field | Bits | Value | Description |
|---|---|---|---|---|
| 63:35 | — | 29 | Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise. | |
| 34:32 | IPS[34:32] | 3 | 0x0 | Physical address size. |
| 31:28 | — | 4 | Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise. | |
| 27 | TBI1[27:27] | 1 | 0x0 | Ignore the top byte for the TTBR1 regime. |
| 26:24 | — | 3 | Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise. | |
| 23 | EPD1[23:23] | 1 | 0x0 | TTBR1 walk disable. Position measured the same way: setting this bit alone made every high address fault. |
| 22 | — | 1 | Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise. | |
| 21:16 | T1SZ[21:16] | 6 | 0x0 (0) | Address bits ignored at EL1. Position measured: see verify-walk-qemu.mjs --sweep, where writing T1SZ at each candidate shift in turn left exactly one position translating a high-half address. |
| 15:14 | TG0[15:14] | 2 | 0x0 | TTBR0 granule size: 4 KiB, 64 KiB or 16 KiB. The order is not the obvious one, so read the architecture rather than assuming. |
| 13:10 | — | 4 | Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise. | |
| 9 | SH0[9:9] | 1 | 0x0 | TTBR0 walk shareability. |
| 8 | ORGN0[8:8] | 1 | 0x0 | TTBR0 walk cacheability for writes. |
| 7 | IRGN0[7:7] | 1 | 0x0 | TTBR0 walk cacheability for reads. |
| 6 | — | 1 | Not assigned to a documented field. Values written here are reserved and should be treated as read-as-zero unless the architecture says otherwise. | |
| 5:0 | T0SZ[5:0] | 6 | 0x0 (0) | Address bits ignored at EL0, so the TTBR0 regime covers 64 minus this many bits. |