← Home

BRBTGTINJ_EL1

Branch Record Buffer Target Address Injection Register

The target address of a Branch record for injection.

Configuration

This register is present only when FEAT_BRBE is implemented. Otherwise, direct accesses to BRBTGTINJ_EL1 are UNDEFINED.

Attributes

BRBTGTINJ_EL1 is a 64-bit register.

Field descriptions

6362616059585756555453525150494847464544434241403938373635343332
313029282726252423222120191817161514131211109876543210
ADDRESS
ADDRESS

ADDRESS, bits [63:0]:

Target virtual address of the Branch record.

When a direct write occurs with a value with ADDRESS bits [63:P] indicating an invalid address, an UNKNOWN value which indicates an invalid address is written to bits [63:P].

An invalid address is:

P is defined as:

The value in bits [P-1:0] is the value written.

When a direct write occurs with a value with ADDRESS bits [63:P] indicating a valid address, the written value is written to bits [63:0], and a read of the register returns the written value.

The reset behavior of this field is:

Accessing this field has the following behavior:

Access Instructions

Accesses to this register use the following encodings in the System register encoding space:

MRS <Xt>, BRBTGTINJ_EL1

(op0 = 0b10, op1 = 0b001, CRn = 0b1001, CRm = 0b0001, op2 = 0b010)

if !IsFeatureImplemented(FEAT_BRBE) then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && MDCR_EL3().SBRBE != '11' && SCR_EL3().NS == '0' then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && MDCR_EL3().SBRBE IN {'x0'} && SCR_EL3().NS == '1' then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && HDFGRTR_EL2().nBRBDATA == '0' then AArch64_SystemAccessTrap(EL2, 0x18); elsif HaveEL(EL3) && MDCR_EL3().SBRBE != '11' && SCR_EL3().NS == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif HaveEL(EL3) && MDCR_EL3().SBRBE IN {'x0'} && SCR_EL3().NS == '1' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else X{64}(t) = BRBTGTINJ_EL1(); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && MDCR_EL3().SBRBE != '11' && SCR_EL3().NS == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif HaveEL(EL3) && MDCR_EL3().SBRBE IN {'x0'} && SCR_EL3().NS == '1' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else X{64}(t) = BRBTGTINJ_EL1(); end; elsif PSTATE.EL == EL3 then X{64}(t) = BRBTGTINJ_EL1(); end;

MSR BRBTGTINJ_EL1, <Xt>

(op0 = 0b10, op1 = 0b001, CRn = 0b1001, CRm = 0b0001, op2 = 0b010)

if !IsFeatureImplemented(FEAT_BRBE) then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && MDCR_EL3().SBRBE != '11' && SCR_EL3().NS == '0' then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && MDCR_EL3().SBRBE IN {'x0'} && SCR_EL3().NS == '1' then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && HDFGWTR_EL2().nBRBDATA == '0' then AArch64_SystemAccessTrap(EL2, 0x18); elsif HaveEL(EL3) && MDCR_EL3().SBRBE != '11' && SCR_EL3().NS == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif HaveEL(EL3) && MDCR_EL3().SBRBE IN {'x0'} && SCR_EL3().NS == '1' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else BRBTGTINJ_EL1() = X{64}(t); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && MDCR_EL3().SBRBE != '11' && SCR_EL3().NS == '0' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif HaveEL(EL3) && MDCR_EL3().SBRBE IN {'x0'} && SCR_EL3().NS == '1' then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else BRBTGTINJ_EL1() = X{64}(t); end; elsif PSTATE.EL == EL3 then BRBTGTINJ_EL1() = X{64}(t); end;


Version 2026.06 — Copyright © 2010-2026 Arm Limited or its affiliates.

This site is provided as a community resource and is NOT affiliated with nor endorsed by Arm Limited.