All of lore.kernel.org
 help / color / mirror / Atom feed
From: Fuad Tabba <fuad.tabba@linux.dev>
To: Peter Maydell <peter.maydell@linaro.org>
Cc: qemu-arm@nongnu.org, qemu-devel@nongnu.org,
	Richard Henderson <richard.henderson@linaro.org>,
	Will Deacon <will@kernel.org>,
	Itaru Kitayama <itaru.kitayama@linux.dev>,
	Fuad Tabba <tabba@google.com>
Subject: [PATCH 0/2] target/arm: Fix the TTBR table base address in its 52-bit layout
Date: Fri,  2 Oct 2026 08:09:18 +0100	[thread overview]
Message-ID: <20261001175003.ttbr-baddr-52bit-0-fuad.tabba@linux.dev> (raw)

Hi folks,

Two fixes to how get_phys_addr_lpae() forms the initial table base
address when TTBR uses its 52-bit layout, each with a TCG test.

The first stops TTBR[5:4] leaking into the base address of a table
smaller than 64 bytes. KVM's page_fault_test hangs on it under TCG in
its 16KB, 52-bit PA guest mode. Itaru reported the 16KB hang on kvmarm
last year [1].

The second uses the 52-bit layout whenever TCR.DS is set, as the
architecture does, not only with a 52-bit OA. With a smaller OA a
non-zero TTBR[5:2] is then an Address size fault.

Based on QEMU master (f7ada39eda).

Cheers,
/fuad

[1] https://lore.kernel.org/kvmarm/B4C0AC3E-6A4F-4A7B-B7BC-81207539115E@linux.dev/

Fuad Tabba (2):
  target/arm: Clear TTBR[5:0] from a 52-bit table base address
  target/arm: Use the 52-bit TTBR base address layout when TCR.DS is set

 target/arm/ptw.c                      |  15 +-
 tests/tcg/aarch64/system/meson.build  |   6 +
 tests/tcg/aarch64/system/ttbr-baddr.c | 194 ++++++++++++++++++++++++++
 3 files changed, 209 insertions(+), 6 deletions(-)
 create mode 100644 tests/tcg/aarch64/system/ttbr-baddr.c

-- 
2.39.5



             reply	other threads:[~2026-10-02  7:10 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02  7:09 Fuad Tabba [this message]
2026-10-02  7:09 ` [PATCH 1/2] target/arm: Clear TTBR[5:0] from a 52-bit table base address Fuad Tabba
2026-10-05 20:06   ` Gustavo Romero
2026-10-05 21:44     ` Fuad Tabba
2026-10-06  9:03       ` Peter Maydell
2026-10-06  9:27         ` Fuad Tabba
2026-10-02  7:09 ` [PATCH 2/2] target/arm: Use the 52-bit TTBR base address layout when TCR.DS is set Fuad Tabba
2026-10-06 11:24   ` Peter Maydell
2026-10-06 13:20     ` Fuad Tabba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001175003.ttbr-baddr-52bit-0-fuad.tabba@linux.dev \
    --to=fuad.tabba@linux.dev \
    --cc=itaru.kitayama@linux.dev \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=richard.henderson@linaro.org \
    --cc=tabba@google.com \
    --cc=will@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.