From: Fuad Tabba <fuad.tabba@linux.dev>
To: Peter Maydell <peter.maydell@linaro.org>
Cc: qemu-arm@nongnu.org, qemu-devel@nongnu.org,
Richard Henderson <richard.henderson@linaro.org>,
Will Deacon <will@kernel.org>,
Itaru Kitayama <itaru.kitayama@linux.dev>,
Fuad Tabba <tabba@google.com>
Subject: [PATCH 0/2] target/arm: Fix the TTBR table base address in its 52-bit layout
Date: Fri, 2 Oct 2026 08:09:18 +0100 [thread overview]
Message-ID: <20261001175003.ttbr-baddr-52bit-0-fuad.tabba@linux.dev> (raw)
Hi folks,
Two fixes to how get_phys_addr_lpae() forms the initial table base
address when TTBR uses its 52-bit layout, each with a TCG test.
The first stops TTBR[5:4] leaking into the base address of a table
smaller than 64 bytes. KVM's page_fault_test hangs on it under TCG in
its 16KB, 52-bit PA guest mode. Itaru reported the 16KB hang on kvmarm
last year [1].
The second uses the 52-bit layout whenever TCR.DS is set, as the
architecture does, not only with a 52-bit OA. With a smaller OA a
non-zero TTBR[5:2] is then an Address size fault.
Based on QEMU master (f7ada39eda).
Cheers,
/fuad
[1] https://lore.kernel.org/kvmarm/B4C0AC3E-6A4F-4A7B-B7BC-81207539115E@linux.dev/
Fuad Tabba (2):
target/arm: Clear TTBR[5:0] from a 52-bit table base address
target/arm: Use the 52-bit TTBR base address layout when TCR.DS is set
target/arm/ptw.c | 15 +-
tests/tcg/aarch64/system/meson.build | 6 +
tests/tcg/aarch64/system/ttbr-baddr.c | 194 ++++++++++++++++++++++++++
3 files changed, 209 insertions(+), 6 deletions(-)
create mode 100644 tests/tcg/aarch64/system/ttbr-baddr.c
--
2.39.5
next reply other threads:[~2026-10-02 7:10 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 7:09 Fuad Tabba [this message]
2026-10-02 7:09 ` [PATCH 1/2] target/arm: Clear TTBR[5:0] from a 52-bit table base address Fuad Tabba
2026-10-05 20:06 ` Gustavo Romero
2026-10-05 21:44 ` Fuad Tabba
2026-10-06 9:03 ` Peter Maydell
2026-10-06 9:27 ` Fuad Tabba
2026-10-02 7:09 ` [PATCH 2/2] target/arm: Use the 52-bit TTBR base address layout when TCR.DS is set Fuad Tabba
2026-10-06 11:24 ` Peter Maydell
2026-10-06 13:20 ` Fuad Tabba
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001175003.ttbr-baddr-52bit-0-fuad.tabba@linux.dev \
--to=fuad.tabba@linux.dev \
--cc=itaru.kitayama@linux.dev \
--cc=peter.maydell@linaro.org \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=tabba@google.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.