mirror of
https://github.com/apache/nuttx.git
synced 2026-10-10 15:50:23 +00:00
mmu_write_ttbr0() writes TTBR0_EL1 and then invalidates the TLB. A write to TTBR0_EL1 takes effect only at the next context synchronization event, so until the ISB at the end of the invalidation, a table walk can still use the old table. The instruction fetches of the invalidation sequence itself do such walks. An entry that they cache after the TLBI completes stays valid: walk cache entries are not tagged with the table base, and the kernel and every process use ASID 0. A kernel build then translates a user address of the new process through a level 0 entry of the old table, and gets a level 1 translation fault. Under QEMU with HVF on Apple silicon this happens on every boot of qemu-armv8a:knsh: up_addrenv_va_to_pa() fails for the first user buffer, and virtio gets a descriptor with address 0. TCG has no walk caches, so it does not show the problem. Add an ISB after the write, as the Arm ARM sequence for a TTBR change without an ASID change requires: write, ISB, TLBI, DSB, ISB. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com> |
||
|---|---|---|
| .. | ||
| arm | ||
| arm64 | ||
| avr | ||
| ceva | ||
| dummy | ||
| hc | ||
| mips | ||
| misoc | ||
| or1k | ||
| renesas | ||
| risc-v | ||
| sim | ||
| sparc | ||
| tricore | ||
| x86 | ||
| x86_64 | ||
| xtensa | ||
| z16 | ||
| z80 | ||
| CMakeLists.txt | ||
| Kconfig | ||