Hypervisor Configuration Register
Provides configuration controls for virtualization, including defining whether various operations are trapped to EL2.
AArch64 System register HCR_EL2 bits [31:0] are architecturally mapped to AArch32 System register HCR[31:0].
AArch64 System register HCR_EL2 bits [63:32] are architecturally mapped to AArch32 System register HCR2[31:0].
This register is present only when FEAT_AA64 is implemented. Otherwise, direct accesses to HCR_EL2 are UNDEFINED.
If EL2 is not implemented, this register is RES0 from EL3.
Unless otherwise stated, the bits in this register behave as if they are 0 for all purposes other than direct reads of the register if EL2 is not enabled in the current Security state.
HCR_EL2 is a 64-bit register.
| 63 | 62 | 61 | 60 | 59 | 58 | 57 | 56 | 55 | 54 | 53 | 52 | 51 | 50 | 49 | 48 | 47 | 46 | 45 | 44 | 43 | 42 | 41 | 40 | 39 | 38 | 37 | 36 | 35 | 34 | 33 | 32 |
| 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
| TWEDEL | TWEDEn | TID5 | DCT | ATA | TTLBOS | TTLBIS | EnSCXT | TOCU | AMVOFFEN | TICAB | TID4 | GPF | FIEN | FWB | NV2 | AT | NV1 | NV | API | APK | RES0 | TEA | TERR | TLOR | E2H | ID | CD | ||||
| RW | TRVM | HCD | TDZ | TGE | TVM | TTLB | TPU | TPCP | TSW | TACR | TIDCP | TSC | TID3 | TID2 | TID1 | TID0 | TWE | TWI | DC | BSU | FB | VSE | VI | VF | AMO | IMO | FMO | PTW | SWIO | VM | |
TWE Delay. A 4-bit unsigned number that, when HCR_EL2.TWEDEn is 1, encodes the minimum delay in taking a trap of WFE* caused by HCR_EL2.TWE as 2(TWEDEL + 8) cycles.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
TWE Delay Enable. Enables a configurable delayed trap of the WFE* instruction caused by HCR_EL2.TWE.
| TWEDEn | Meaning |
|---|---|
| 0b0 |
The delay for taking the trap is IMPLEMENTATION DEFINED. |
| 0b1 |
The delay for taking the trap is at least the number of cycles defined in HCR_EL2.TWEDEL. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap ID group 5. Traps the following register accesses to EL2, when EL2 is enabled in the current Security state:
AArch64:
| TID5 | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
The specified EL1 accesses to ID group 5 registers are trapped to EL2. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Default Cacheability Tagging. When HCR_EL2.DC is in effect, controls whether EL1&0 stage 1 translations have the Tagged attribute.
| DCT | Meaning |
|---|---|
| 0b0 |
Stage 1 translations do not have the Tagged attribute. |
| 0b1 |
Stage 1 translations have the Tagged attribute. |
This bit is permitted to be cached in a TLB.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Memory tagging enable override:
| ATA | Meaning |
|---|---|
| 0b0 | Disables the use of Memory tagging at EL1 and EL0. The specified registers are trapped to EL2. |
| 0b1 | This field has no effect on the use of Memory tagging at EL1 and EL0. The field does not trap the specified registers to EL2. |
The Effective value of this field is 1 if any of the following are true:
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap TLB maintenance instructions that operate on the Outer Shareable domain. Traps execution of those TLB maintenance instructions at EL1 using AArch64 to EL2, when EL2 is enabled in the current Security state. The following instructions are trapped and reported with EC syndrome value 0x18:
| TTLBOS | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Execution of the specified instructions are trapped to EL2. |
If the Effective value of NVHCR_EL2.TGE is 1 and the Effective value of HCRX_EL2.NVnTTLBOS is 1, TLBI OS instructions that apply to stage 1 of the EL1&0 translation regime have their architected effect instead of being trapped by HCR_EL2.TTLBOS.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap TLB maintenance instructions that operate on the Inner Shareable domain. Traps execution of those TLB maintenance instructions at EL1 to EL2, when EL2 is enabled in the current Security state, as follows:
| TTLBIS | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Execution of the specified instructions are trapped to EL2. |
If the Effective value of NVHCR_EL2.TGE is 1 and the Effective value of HCRX_EL2.NVnTTLBIS is 1, TLBI IS instructions that apply to stage 1 of the EL1&0 translation regime have their architected effect instead of being trapped by HCR_EL2.TTLBIS.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Enable Access to the SCXTNUM_EL1 and SCXTNUM_EL0 registers. The defined values are:
| EnSCXT | Meaning |
|---|---|
| 0b0 | When EL2 is enabled in the current Security state, EL1 accesses to SCXTNUM_EL0 and SCXTNUM_EL1 are disabled, causing an exception to EL2, and the value of the registers to be treated as 0. When the Effective value of HCR_EL2.{E2H, TGE} is not {1, 1} and EL2 is enabled in the current Security state, EL0 access to SCXTNUM_EL0 is disabled, causing an exception to EL2, and the value of the register to be treated as 0. |
| 0b1 |
This control does not cause accesses to SCXTNUM_EL0 or SCXTNUM_EL1 to be trapped. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1} and the value of this field is 0, accesses at EL0 are not trapped by this control.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap cache maintenance instructions that operate to the Point of Unification. Traps execution of those cache maintenance instructions at EL0 and EL1 to EL2, when EL2 is enabled in the current Security state, as follows:
When SCTLR_EL1.UCI is 0, the trap on execution of instructions at EL0 is higher priority than this control.
An exception generated because an instruction is UNDEFINED at EL0 is higher priority than this trap to EL2. In addition:
| TOCU | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
For each of the specified instructions, if the execution of the instruction can be trapped, accesses are trapped to EL2. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Activity Monitors Virtual Offsets Enable.
| AMVOFFEN | Meaning |
|---|---|
| 0b0 |
Virtualization of the Activity Monitors is disabled. Indirect reads of the virtual offset registers are zero. |
| 0b1 |
Virtualization of the Activity Monitors is enabled. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap ICIALLUIS and IC IALLUIS cache maintenance instructions. Traps execution of those cache maintenance instructions at EL1 to EL2, when EL2 is enabled in the current Security state, as follows:
| TICAB | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
For each of the specified instructions, if the execution of the instruction can be trapped, EL1 access is trapped to EL2. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap ID group 4. Traps the following register accesses to EL2, when EL2 is enabled in the current Security state:
AArch64:
AArch32:
| TID4 | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
The specified EL1 accesses to ID group 4 registers are trapped to EL2. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls the reporting of Granule protection faults at EL0 and EL1.
| GPF | Meaning |
|---|---|
| 0b0 |
This control does not cause exceptions to be routed from EL0 and EL1 to EL2. |
| 0b1 |
Instruction Abort exceptions and Data Abort exceptions due to GPFs from EL0 and EL1 are routed to EL2. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Fault Injection Enable. Unless this bit is set to 1, accesses to the ERXPFGCDN_EL1, ERXPFGCTL_EL1, and ERXPFGF_EL1 registers from EL1 generate a Trap exception to EL2, when EL2 is enabled in the current Security state, reported using EC syndrome value 0x18.
| FIEN | Meaning |
|---|---|
| 0b0 |
Accesses to the specified registers from EL1 are trapped to EL2, when EL2 is enabled in the current Security state. |
| 0b1 |
This control does not cause any instructions to be trapped. |
If EL2 is disabled in the current Security state, the Effective value of HCR_EL2.FIEN is 1.
If ERRIDR_EL1.NUM is zero, meaning no error records are implemented, or no error record accessible using System registers is owned by a node that implements the RAS Common Fault Injection Model Extension, then this bit might be RES0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Forced Write-Back. Defines the combined cacheability attributes in a 2 stage translation regime.
| FWB | Meaning |
|---|---|
| 0b0 |
When this bit is 0, then the combination of stage 1 and stage 2 translations on memory type and cacheability attributes are as described in the Armv8.0 architecture. For more information, see 'Combining stage 1 and stage 2 memory type attributes'. |
| 0b1 |
When this bit is 1, then the encoding of the stage 2 memory type and cacheability attributes in bits[5:2] of the stage 2 Page or Block descriptors are as described in 'Stage 2 memory type and Cacheability attributes when FEAT_S2FWB is enabled'. |
In Secure state, this bit applies to both the Secure stage 2 translation and the Non-secure stage 2 translation.
This bit is permitted to be cached in a TLB.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Nested Virtualization. Changes the behaviors of HCR_EL2.{NV1, NV} to provide a mechanism for hardware to transform reads and writes from System registers into reads and writes from memory.
| NV2 | Meaning |
|---|---|
| 0b0 |
This bit has no effect on the behavior of HCR_EL2.{NV1, NV}. The behavior of HCR_EL2.{NV1, NV} is as defined for FEAT_NV. |
| 0b1 | Redefines behavior of HCR_EL2{NV1, NV} to enable:
Any exception taken from EL1 and taken to EL1 causes SPSR_EL1.M[3:2] to be set to 0b10 and not 0b01. |
When the Effective value of HCR_EL2.NV is 0, the Effective value of this field is 0 and this field is treated as 0 for all purposes other than direct reads and writes of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Address Translation. EL1 execution of the following address translation instructions is trapped to EL2, when EL2 is enabled in the current Security state, reported using EC syndrome value 0x18:
| AT | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
EL1 execution of the specified instructions is trapped to EL2. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Nested Virtualization.
| NV1 | Meaning |
|---|---|
| 0b0 | If the Effective value of HCR_EL2.{NV2, NV} is {1, 1}, accesses executed from EL1 to implemented EL12, EL02, or EL2 registers are transformed to loads and stores. If the Effective value of HCR_EL2.{NV2, NV} is not {1, 1}, this control does not cause any instructions to be trapped. |
| 0b1 | If the Effective value of HCR_EL2.NV2 is 1, accesses executed from EL1 to implemented EL2 registers are transformed to loads and stores. If the Effective value of HCR_EL2.NV2 is 0, EL1 accesses to VBAR_EL1, ELR_EL1, SPSR_EL1, and, when FEAT_CSV2_2 or FEAT_CSV2_1p2 is implemented, SCXTNUM_EL1, are trapped to EL2, when EL2 is enabled in the current Security state, and are reported using EC syndrome value 0x18. |
If the Effective value of HCR_EL2.NV2 is 1, the Effective value of HCR_EL2.NV1 defines which EL1 register accesses are transformed to loads and stores.
The trapping of EL1 registers caused by other control bits has priority over the transformation of these accesses.
If a register is specified that is not implemented by an implementation, then access to that register are UNDEFINED.
For the list of registers affected, see 'Enhanced support for nested virtualization'.
If the Effective value of HCR_EL2.{NV1, NV} is {0, 1}, any exception taken from EL1, and taken to EL1, causes the SPSR_EL1.M[3:2] to be set to 0b10, and not 0b01.
If the Effective value of HCR_EL2.{NV1, NV} is {1, 1}, then:
If the Effective value of HCR_EL2.{NV1, NV} are {1, 0}, then the behavior is a CONSTRAINED UNPREDICTABLE choice of:
This bit is permitted to be cached in a TLB.
The reset behavior of this field is:
Accessing this field has the following behavior:
Nested Virtualization. EL1 accesses to certain registers are trapped to EL2, when EL2 is enabled in the current Security state.
| NV1 | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
EL1 accesses to VBAR_EL1, ELR_EL1, SPSR_EL1, and, when FEAT_CSV2_2 or FEAT_CSV2_1p2 is implemented, SCXTNUM_EL1, are trapped to EL2, when EL2 is enabled in the current Security state, and are reported using EC syndrome value 0x18. |
If the Effective value of HCR_EL2.{NV1, NV} is {0, 1}, then the following effects also apply:
If the Effective value of HCR_EL2.{NV1, NV} is {1, 1}, then the following effects also apply:
If the Effective value of HCR_EL2.{NV1, NV} is {1, 0}, then the behavior is a CONSTRAINED UNPREDICTABLE choice of:
This bit is permitted to be cached in a TLB.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Nested Virtualization.
When the Effective value of HCR_EL2.NV2 is 1, redefines register accesses so that:
When the Effective value of HCR_EL2.NV2 is 0, traps functionality that is permitted at EL2 and would be UNDEFINED at EL1 if this field was 0, when EL2 is enabled in the current Security state. This applies to the following operations:
| NV | Meaning |
|---|---|
| 0b0 | When this bit is set to 0, then the PE behaves as if the Effective value of HCR_EL2.NV2 is 0 for all purposes other than reading this register. This control does not cause any instructions to be trapped. When the Effective value of HCR_EL2.NV2 is 1, no FEAT_NV2 functionality is implemented. |
| 0b1 | When the Effective value of HCR_EL2.NV2 is 0, EL1 accesses to the specified registers or the execution of the specified instructions are trapped to EL2, when EL2 is enabled in the current Security state. EL1 read accesses to the CurrentEL register return a value of 0x2. When the Effective value of HCR_EL2.NV2 is 1, this control redefines EL1 register accesses so that instructions accessing SPSR_EL2, ELR_EL2, ESR_EL2, and FAR_EL2 instead access SPSR_EL1, ELR_EL1, ESR_EL1, and FAR_EL1 respectively. |
When the Effective value of HCR_EL2.NV2 is 0, then:
The priority of this trap is higher than the priority of the HCR_EL2.API trap. If both of these bits are set so that EL1 execution of an ERETAA or ERETAB instruction is trapped to EL2, then the syndrome reported is 0x1A.
The reset behavior of this field is:
Accessing this field has the following behavior:
Nested Virtualization. Traps functionality that is permitted at EL2 and would be UNDEFINED at EL1 if this field was 0, when EL2 is enabled in the current Security state. This applies to the following operations:
| NV | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
EL1 accesses to the specified registers or the execution of the specified instructions are trapped to EL2, when EL2 is enabled in the current Security state. EL1 read accesses to the CurrentEL register return a value of 0x2. |
The System or Special-purpose registers for which accesses are trapped and reported using EC syndrome value 0x18 are as follows:
The instructions for which the execution is trapped and reported using EC syndrome value 0x18 are as follows:
The execution of the ERET, ERETAA, and ERETAB instructions are trapped and reported using EC syndrome value 0x1A.
The priority of this trap is higher than the priority of the HCR_EL2.API trap. If both of these bits are set so that EL1 execution of an ERETAA or ERETAB instruction is trapped to EL2, then the syndrome reported is 0x1A.
The execution of the SMC instructions in an implementation that does not include EL3 and when HCR_EL2.TSC is 1 are trapped and reported using EC syndrome value 0x17. HCR_EL2.TSC bit is not RES0 in this case.
This bit is permitted to be cached in a TLB.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Controls the use of instructions related to Pointer Authentication:
This field is ignored if the instruction is disabled as a result of the SCTLR_ELx.{EnIB, EnIA, EnDA, EnDB} fields.
| API | Meaning |
|---|---|
| 0b0 | The instructions related to Pointer Authentication are trapped to EL2 and reported using EC syndrome value 0x09, when EL2 is enabled in the current Security state and the instructions are enabled for the EL1&0 translation regime, from:
If the Effective value of HCR_EL2.NV is 1, the HCR_EL2.NV trap takes precedence over the HCR_EL2.API trap for the ERETAA and ERETAB instructions. If EL2 is implemented and enabled in the current Security state and the Effective value of HFGITR_EL2.ERET is 1, execution at EL1 using AArch64 of ERETAA or ERETAB instructions is reported with EC syndrome value 0x1A with its associated ISS field, as the fine-grained trap has higher priority than the trap enabled by HCR_EL2.API == 0. |
| 0b1 |
This control does not cause any instructions to be trapped. |
If FEAT_PAuth is implemented but EL2 is not implemented or is disabled in the current Security state, the system behaves as if this bit is 1.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap registers holding "key" values for Pointer Authentication. Traps accesses to the following registers from EL1 to EL2, when EL2 is enabled in the current Security state, reported using EC syndrome value 0x18:
| APK | Meaning |
|---|---|
| 0b0 |
Access to the registers holding "key" values for pointer authentication from EL1 are trapped to EL2, when EL2 is enabled in the current Security state. |
| 0b1 |
This control does not cause any instructions to be trapped. |
If FEAT_PAuth is implemented but EL2 is not implemented or is disabled in the current Security state, the system behaves as if this bit is 1.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Reserved, RES0.
Route synchronous External abort exceptions to EL2.
| TEA | Meaning |
|---|---|
| 0b0 |
Synchronous External abort exceptions are unaffected by this mechanism. That is, synchronous External abort exceptions are not taken to EL2 unless routed to EL2 by another control. |
| 0b1 |
When executing at Exception levels below EL2, and EL2 is enabled in the current Security state, synchronous External abort exceptions are taken to EL2, unless they are routed to EL3. |
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap accesses of Error Record registers. Enables a trap to EL2 on accesses of Error Record registers.
| TERR | Meaning |
|---|---|
| 0b0 |
Accesses of the specified Error Record registers are not trapped by this mechanism. |
| 0b1 |
Accesses of the specified Error Record registers at EL1 are trapped to EL2, unless the instruction generates a higher priority exception. |
In AArch64 state, the instructions affected by this control are:
In AArch32 state, the instructions affected by this control are:
Unless the instruction generates a higher priority exception, trapped instructions generate an exception to EL2.
Trapped AArch64 instructions are reported using EC syndrome value 0x18.
Trapped AArch32 instructions are reported using EC syndrome value 0x03.
Accessing this field has the following behavior:
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Trap LOR registers. Traps Non-secure and Realm EL1 accesses to LORSA_EL1, LOREA_EL1, LORN_EL1, LORC_EL1, and LORID_EL1 registers to EL2.
| TLOR | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Non-secure and Realm EL1 accesses to the LOR registers are trapped to EL2. |
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
EL2 Host. Enables a configuration where a Host Operating System is running at EL2, and the Host Operating System's applications are running at EL0.
| E2H | Meaning |
|---|---|
| 0b0 |
The facilities to support a Host Operating System at EL2 are disabled. |
| 0b1 |
The facilities to support a Host Operating System at EL2 are enabled. |
For information on the behavior of this bit see 'Behavior of HCR_EL2.E2H'.
This bit is permitted to be cached in a TLB.
The reset behavior of this field is:
Accessing this field has the following behavior:
EL2 Host. Enables a configuration where a Host Operating System is running at EL2, and the Host Operating System's applications are running at EL0.
| E2H | Meaning |
|---|---|
| 0b1 |
The facilities to support a Host Operating System at EL2 are enabled. |
This field is RES1, regardless of whether EL2 is enabled in the current Security state.
Reserved, RES0.
Stage 2 Instruction access cacheability disable. For the EL1&0 translation regime, when EL2 is enabled in the current Security state and HCR_EL2.VM==1, this control forces all stage 2 translations for instruction accesses to Normal memory to be Non-cacheable.
| ID | Meaning |
|---|---|
| 0b0 |
This control has no effect on stage 2 of the EL1&0 translation regime. |
| 0b1 | Forces all stage 2 translations for instruction accesses to Normal memory to be Non-cacheable. This applies regardless of the value of HCR_EL2.FWB. |
This bit has no effect on the EL2, EL2&0, or EL3 translation regimes.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Stage 2 Data access cacheability disable. For the EL1&0 translation regime, when EL2 is enabled in the current Security state and HCR_EL2.VM==1, this control forces all stage 2 translations for data accesses and translation table walks to Normal memory to be Non-cacheable.
| CD | Meaning |
|---|---|
| 0b0 |
This control has no effect on stage 2 of the EL1&0 translation regime for data accesses and translation table walks. |
| 0b1 | Forces all stage 2 translations for data accesses and translation table walks to Normal memory to be Non-cacheable. This applies regardless of the value of HCR_EL2.FWB. |
This bit has no effect on the EL2, EL2&0, or EL3 translation regimes.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Execution state control for lower Exception levels:
| RW | Meaning |
|---|---|
| 0b0 |
Lower levels are all AArch32. |
| 0b1 |
The Execution state for EL1 is AArch64. The Execution state for EL0 is determined by the current value of PSTATE.nRW when executing at EL0. |
In an implementation that includes EL3, when EL2 is not enabled in Secure state, the PE behaves as if this bit has the same value as the SCR_EL3.RW bit for all purposes other than a direct read or write access of HCR_EL2.
The RW bit is permitted to be cached in a TLB.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 1.
The reset behavior of this field is:
Reserved, RAO/WI.
Trap Reads of Virtual Memory controls. Traps reads of the virtual memory control registers to EL2, when EL2 is enabled in the current Security state, as follows:
| TRVM | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Read accesses to the specified Virtual Memory control registers are trapped to EL2, when EL2 is enabled in the current Security state. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the PE ignores the value of this field for all purposes other than a direct read of this field.
EL2 provides a second stage of address translation, that a hypervisor can use to remap the address map defined by a Guest OS. In addition, a hypervisor can trap attempts by a Guest OS to write to the registers that control the memory system. A hypervisor might use this trap as part of its virtualization of memory management.
The reset behavior of this field is:
Accessing this field has the following behavior:
HVC instruction disable. Disables EL1 and EL2 execution of HVC instructions, from both Execution states, when EL2 is enabled in the current Security state, reported using EC syndrome value 0x00.
| HCD | Meaning |
|---|---|
| 0b0 |
HVC instruction execution is enabled at EL2 and EL1. |
| 0b1 |
HVC instructions are UNDEFINED at EL2 and EL1. Any resulting exception is taken to the Exception level at which the HVC instruction is executed. |
HVC instructions are always UNDEFINED at EL0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Traps EL0 and EL1 execution of the following instructions to EL2, when EL2 is enabled in the current Security state, from AArch64 state only, reported using EC syndrome value 0x18:
| TDZ | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 | In AArch64 state, any attempt to execute an instruction this trap applies to at EL1, or at EL0 when the instruction is not UNDEFINED at EL0, is trapped to EL2 when EL2 is enabled in the current Security state. Reading the DCZID_EL0 returns a value that indicates that the instructions this trap applies to are not supported. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap General Exceptions, from EL0.
| TGE | Meaning |
|---|---|
| 0b0 |
This control has no effect on execution at EL0. |
| 0b1 | When EL2 is not enabled in the current Security state, the Effective value of this field is 0 and this field have no effect on execution at EL0. When EL2 is enabled in the current Security state, in all cases:
In addition, when EL2 is enabled in the current Security state, if:
For further information on the behavior of this bit when the Effective value of E2H is 1, see 'Behavior of HCR_EL2.E2H'. |
HCR_EL2.TGE must not be cached in a TLB.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap Virtual Memory controls. Traps writes to the virtual memory control registers to EL2, when EL2 is enabled in the current Security state, as follows:
| TVM | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Write accesses to the specified Virtual Memory control registers are trapped to EL2, when EL2 is enabled in the current Security state. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap TLB maintenance instructions. Traps execution of TLB maintenance instructions at EL1 to EL2, when EL2 is enabled in the current Security state, as follows:
If EL1 is using AArch64, then the following instructions are trapped to EL2 and reported using EC syndrome value 0x18:
If EL1 is using AArch32, then the following instructions are trapped to EL2 and reported using EC syndrome value 0x03:
| TTLB | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
EL1 execution of the specified TLB maintenance instructions are trapped to EL2, when EL2 is enabled in the current Security state. |
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
If the Effective value of NVHCR_EL2.TGE is 1, TLBI instructions that apply to stage 1 of the EL1&0 translation regime have their architected effect instead of being trapped, in each of the following cases:
The TLB maintenance instructions are UNDEFINED at EL0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap cache maintenance instructions that operate to the Point of Unification. Traps execution of those cache maintenance instructions at EL0 and EL1 to EL2, when EL2 is enabled in the current Security state, as follows:
When SCTLR_EL1.UCI is 0, the trap on execution of instructions at EL0 is higher priority than this control.
An exception generated because an instruction is UNDEFINED at EL0 is higher priority than this trap to EL2. In addition:
| TPU | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
For each of the specified instructions, if the execution of the instruction can be trapped, access is trapped to EL2, when EL2 is enabled in the current Security state. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap data or unified cache maintenance instructions that operate to the Point of Coherency, Persistence, or Physical Storage. When EL2 is enabled in the current Security state, traps execution of cache maintenance instructions at EL0 and EL1 to EL2 as follows:
This field was previously named TPC.
When SCTLR_EL1.UCI is 0, the trap on execution of instructions at EL0 is higher priority than this control.
An exception generated because an instruction is UNDEFINED at EL0 is higher priority than this trap to EL2. In addition:
| TPCP | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
For each of the specified instructions, if the execution of the instruction can be trapped, it is trapped to EL2, when EL2 is enabled in the current Security state. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap data or unified cache maintenance instructions that operate by Set/Way. Traps execution of those cache maintenance instructions at EL1 to EL2, when EL2 is enabled in the current Security state, as follows:
An exception generated because an instruction is UNDEFINED at EL0 is higher priority than this trap to EL2, and these instructions are always UNDEFINED at EL0.
| TSW | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Execution of the specified instructions is trapped to EL2, when EL2 is enabled in the current Security state. |
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap Auxiliary Control Registers. Traps EL1 accesses to the Auxiliary Control Registers to EL2, when EL2 is enabled in the current Security state, as follows:
| TACR | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
EL1 accesses to the specified registers are trapped to EL2, when EL2 is enabled in the current Security state. |
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
ACTLR_EL1 is not accessible at EL0.
ACTLR and ACTLR2 are not accessible at EL0.
The Auxiliary Control Registers are IMPLEMENTATION DEFINED registers that might implement global control bits for the PE.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap IMPLEMENTATION DEFINED functionality. Traps EL1 accesses to the encodings reserved for IMPLEMENTATION DEFINED functionality to EL2, when EL2 is enabled in the current Security state as follows:
For accesses to these regions of encoding space by EL0, all of the following apply:
| TIDCP | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
EL1 accesses to or execution of the specified encodings reserved for IMPLEMENTATION DEFINED functionality are trapped to EL2, when EL2 is enabled in the current Security state. |
An implementation can also include IMPLEMENTATION DEFINED registers that provide additional controls, to give finer-grained control of the trapping of IMPLEMENTATION DEFINED features.
The trapping of accesses to these registers from EL1 is higher priority than an exception resulting from the register access being UNDEFINED.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap SMC instructions. Traps EL1 execution of SMC instructions to EL2, when EL2 is enabled in the current Security state.
If execution is in AArch64 state, the trap is reported using EC syndrome value 0x17.
If execution is in AArch32 state, the trap is reported using EC syndrome value 0x13.
HCR_EL2.TSC traps execution of the SMC instruction. It is not a routing control for the SMC exception. Trap exceptions and SMC exceptions have different preferred return addresses.
| TSC | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 | If EL3 is implemented, then any attempt to execute an SMC instruction at EL1 is trapped to EL2, when EL2 is enabled in the current Security state, regardless of the value of SCR_EL3.SMD. If EL3 is not implemented and the Effective value of HCR_EL2.NV is 1, then any attempt to execute an SMC instruction at EL1 using AArch64 is trapped to EL2. If EL3 is not implemented and the Effective value of HCR_EL2.NV is 0, then it is IMPLEMENTATION DEFINED whether:
|
In AArch32 state, the Armv8-A architecture permits, but does not require, this trap to apply to conditional SMC instructions that fail their condition code check, in the same way as with traps on other conditional instructions.
SMC instructions are UNDEFINED at EL0.
If EL3 is not implemented and the Effective value of HCR_EL2.NV is 0, then it is IMPLEMENTATION DEFINED whether this bit is:
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap ID group 3. Traps EL1 reads of group 3 ID registers to EL2, when EL2 is enabled in the current Security state, as follows:
In AArch64 state:
In AArch32 state:
| TID3 | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
The specified EL1 read accesses to ID group 3 registers are trapped to EL2, when EL2 is enabled in the current Security state. |
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap ID group 2. Traps the following register accesses to EL2, when EL2 is enabled in the current Security state, as follows:
| TID2 | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
The specified EL1 and EL0 accesses to ID group 2 registers are trapped to EL2, when EL2 is enabled in the current Security state. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap ID group 1. Traps EL1 reads of the following registers to EL2, when EL2 is enabled in the current Security state as follows:
| TID1 | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
The specified EL1 read accesses to ID group 1 registers are trapped to EL2, when EL2 is enabled in the current Security state. |
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Trap ID group 0. Traps the following register accesses to EL2:
| TID0 | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
The specified EL1 read accesses to ID group 0 registers are trapped to EL2, when EL2 is enabled in the current Security state. |
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Reserved, RES0.
Traps EL0 and EL1 execution of WFE instructions to EL2, when EL2 is enabled in the current Security state, from both Execution states, reported using EC syndrome value 0x01.
When FEAT_WFxT is implemented, this trap also applies to the WFET instruction.
| TWE | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Any attempt to execute a WFE instruction at EL1 or EL0 is trapped to EL2, when EL2 is enabled in the current Security state, if the instruction would otherwise have caused the PE to enter a low-power state and it is not trapped by SCTLR.nTWE or SCTLR_EL1.nTWE. |
In AArch32 state, the attempted execution of a conditional WFE instruction is trapped only if the instruction passes its condition code check.
Since a WFE can complete at any time, even without a Wakeup event, the traps on WFE are not guaranteed to be taken, even if the WFE is executed when there is no Wakeup event. The only guarantee is that if the instruction does not complete in finite time in the absence of a Wakeup event, the trap will be taken.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
For more information about when WFE instructions can cause the PE to enter a low-power state, see 'Wait for Event mechanism and Send event'.
The reset behavior of this field is:
Accessing this field has the following behavior:
Traps EL0 and EL1 execution of WFI instructions to EL2, when EL2 is enabled in the current Security state, from both Execution states, reported using EC syndrome value 0x01.
When FEAT_WFxT is implemented, this trap also applies to the WFIT instruction.
| TWI | Meaning |
|---|---|
| 0b0 |
This control does not cause any instructions to be trapped. |
| 0b1 |
Any attempt to execute a WFI instruction at EL0 or EL1 is trapped to EL2, when EL2 is enabled in the current Security state, if the instruction would otherwise have caused the PE to enter a low-power state and it is not trapped by SCTLR.nTWI or SCTLR_EL1.nTWI. |
In AArch32 state, the attempted execution of a conditional WFI instruction is trapped only if the instruction passes its condition code check.
Since a WFI can complete at any time, even without a Wakeup event, the traps on WFI are not guaranteed to be taken, even if the WFI is executed when there is no Wakeup event. The only guarantee is that if the instruction does not complete in finite time in the absence of a Wakeup event, the trap will be taken.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
For more information about when WFI instructions can cause the PE to enter a low-power state, see 'Wait for Interrupt'.
The reset behavior of this field is:
Accessing this field has the following behavior:
Default Cacheability.
| DC | Meaning |
|---|---|
| 0b0 |
This control has no effect on the EL1&0 translation regime. |
| 0b1 | In any Security state:
|
This field has no effect on the EL2, EL2&0, and EL3 translation regimes.
This bit is permitted to be cached in a TLB.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Barrier Shareability upgrade. This field determines the minimum shareability domain that is applied to any barrier instruction executed from EL1 or EL0:
| BSU | Meaning |
|---|---|
| 0b00 |
No effect. |
| 0b01 |
Inner Shareable. |
| 0b10 |
Outer Shareable. |
| 0b11 |
Full system. |
This value is combined with the specified level of the barrier held in its instruction, using the same principles as combining the shareability attributes from two stages of address translation.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Force broadcast. Configures how TLBI and IC instructions are broadcast when executed from EL1.
The Non-shareable invalidate instructions affected by this bit are:
The Inner-shareable invalidate instructions affected by this bit are:
This field is used in combination with HCRX_EL2.FNB control, as follows:
| FNB | FB | Meaning |
|---|---|---|
| 0b0 | 0b0 | The specified instructions are not affected by this control. |
| 0b0 | 0b1 | When one of the specified Non-shareable instructions is executed at EL1, the operation is broadcast within the Inner Shareable shareability domain. The specified Inner-shareable instructions are not affected by this control. |
| 0b1 | 0b0 | The specified Non-shareable instructions are not affected by this control. When one of the specified Inner-shareable instructions is executed at EL1, the operation affects only the PE on which the instruction was executed. |
| 0b1 | 0b1 | The specified Non-shareable instructions are not affected by this control. When one of the specified Inner-shareable instructions is executed at EL1, the operation is broadcast only to PEs which would share TLB entries with the current PE if CnP were 1. |
Regardless of the value of HCRX_EL2.FNB, if HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Force broadcast. Causes the following Non-shareable invalidate instructions to be broadcast within the Inner Shareable domain when executed from EL1:
For more information, see 'A64 System instructions for TLB maintenance'.
| FB | Meaning |
|---|---|
| 0b0 |
The specified instructions are not affected by this control. |
| 0b1 |
When one of the specified Non-shareable instructions is executed at EL1, the operation is broadcast within the Inner Shareable shareability domain. |
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Virtual SError exception.
| VSE | Meaning |
|---|---|
| 0b0 |
This mechanism is not making a virtual SError exception pending. |
| 0b1 |
A virtual SError exception is pending because of this mechanism. |
The virtual SError exception is enabled only when HCR_EL2.TGE is 0 and either HCR_EL2.AMO is 1 or FEAT_DoubleFault2 is implemented and the Effective value of HCRX_EL2.TMEA is 1.
When FEAT_E3DSE is implemented, virtual SError exceptions pended by this field have priority over delegated SError exceptions pended by SCR_EL3.DSE.
The reset behavior of this field is:
Accessing this field has the following behavior:
Virtual IRQ Interrupt.
| VI | Meaning |
|---|---|
| 0b0 |
This mechanism is not making a virtual IRQ pending. |
| 0b1 |
A virtual IRQ is pending because of this mechanism. |
The virtual IRQ is enabled only when the value of HCR_EL2.{TGE, IMO} is {0, 1}.
The reset behavior of this field is:
Accessing this field has the following behavior:
Virtual FIQ Interrupt.
| VF | Meaning |
|---|---|
| 0b0 |
This mechanism is not making a virtual FIQ pending. |
| 0b1 |
A virtual FIQ is pending because of this mechanism. |
The virtual FIQ is enabled only when the value of HCR_EL2.{TGE, FMO} is {0, 1}.
The reset behavior of this field is:
Accessing this field has the following behavior:
Physical SError exception routing.
| AMO | Meaning |
|---|---|
| 0b0 | When executing at Exception levels below EL3 and the Effective value of HCR_EL2.TGE is 0:
|
| 0b1 | When executing at Exception levels below EL3, EL2 is enabled in the current Security state, and the Effective value of HCR_EL2.TGE is 0:
|
When executing at EL3, the value of HCR_EL2.AMO has no impact on the behavior of the PE.
When executing at Exception levels below EL3, and EL2 is not enabled in the current Security state, the Effective value of HCR_EL2.AMO is 0.
When the Effective value of HCR_EL2.TGE is 1, regardless of the value of the AMO bit, all of the following are true:
When executing at EL2 and the Effective value of HCR_EL2.{E2H, TGE} is {1, 0}, it is IMPLEMENTATION DEFINED whether the Effective value of HCR_EL2.AMO is 1 or the value programmed.
For more information, see 'Asynchronous exception routing'.
The reset behavior of this field is:
Accessing this field has the following behavior:
Physical IRQ Routing.
| IMO | Meaning |
|---|---|
| 0b0 | When executing at Exception levels below EL3 and the Effective value of HCR_EL2.TGE is 0:
|
| 0b1 | When executing at Exception levels below EL3, EL2 is enabled in the current Security state, and the Effective value of HCR_EL2.TGE is 0:
|
When executing at EL3, the Effective value of HCR_EL2.IMO has no impact on the behavior of the PE.
When executing at Exception levels below EL3, and EL2 is not enabled in the current Security state, the Effective value of HCR_EL2.IMO is 0.
When the Effective value of HCR_EL2.TGE is 1, regardless of the value of the IMO bit, all of the following are true:
When executing at EL2 and the Effective value of HCR_EL2.{E2H, TGE} is {1, 0}, it is IMPLEMENTATION DEFINED whether the Effective value of HCR_EL2.IMO is 1 or the value programmed.
For more information, see 'Asynchronous exception routing'.
The reset behavior of this field is:
Accessing this field has the following behavior:
Physical FIQ Routing.
| FMO | Meaning |
|---|---|
| 0b0 | When executing at Exception levels below EL3 and the Effective value of HCR_EL2.TGE is 0:
|
| 0b1 | When executing at Exception levels below EL3, EL2 is enabled in the current Security state, and the Effective value of HCR_EL2.TGE is 0:
|
When executing at EL3, the Effective value of HCR_EL2.FMO has no impact on the behavior of the PE.
When executing at Exception levels below EL3, and EL2 is not enabled in the current Security state, the Effective value of HCR_EL2.FMO is 0.
When the Effective value of HCR_EL2.TGE is 1, regardless of the value of the FMO bit, all of the following are true:
When executing at EL2 and the Effective value of HCR_EL2.{E2H, TGE} is {1, 0}, it is IMPLEMENTATION DEFINED whether the Effective value of HCR_EL2.FMO is 1 or the value programmed.
For more information, see 'Asynchronous exception routing'.
The reset behavior of this field is:
Accessing this field has the following behavior:
Protected Table Walk. In the EL1&0 translation regime, a translation table access made as part of a stage 1 translation table walk is subject to a stage 2 translation. The combining of the memory type attributes from the two stages of translation means the access might be made to a type of Device memory. If this occurs, then the value of this bit determines the behavior:
| PTW | Meaning |
|---|---|
| 0b0 |
The translation table walk occurs as if it is to Normal Non-cacheable memory. This means it can be made speculatively. |
| 0b1 |
The memory access generates a stage 2 Permission fault. |
This bit is permitted to be cached in a TLB.
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Set/Way Invalidation Override. Causes EL1 execution of the data cache invalidate by set/way instructions to perform a data cache clean and invalidate by set/way:
| SWIO | Meaning |
|---|---|
| 0b0 |
This control has no effect on the operation of data cache invalidate by set/way instructions. |
| 0b1 |
Data cache invalidate by set/way instructions perform a data cache clean and invalidate by set/way. |
When the value of this bit is 1:
AArch32: DCISW performs the same invalidation as a DCCISW instruction.
AArch64: DC ISW performs the same invalidation as a DC CISW instruction.
This bit can be implemented as RES1.
When HCR_EL2.TGE is 1, the PE ignores the value of this field for all purposes other than a direct read of this field.
The reset behavior of this field is:
Accessing this field has the following behavior:
Virtualization enable. Enables stage 2 address translation for the EL1&0 translation regime, when EL2 is enabled in the current Security state.
| VM | Meaning |
|---|---|
| 0b0 |
EL1&0 stage 2 address translation disabled. |
| 0b1 |
EL1&0 stage 2 address translation enabled. |
When the value of this bit is 1, data cache invalidate instructions executed at EL1 perform a data cache clean and invalidate. For the invalidate by set/way instruction this behavior applies regardless of the value of the HCR_EL2.SWIO bit.
This bit is permitted to be cached in a TLB.
When the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the Effective value of this field is 0.
The reset behavior of this field is:
Accessing this field has the following behavior:
Accesses to this register use the following encodings in the System register encoding space:
MRS <Xt>, HCR_EL2
(op0 = 0b11, op1 = 0b100, CRn = 0b0001, CRm = 0b0001, op2 = 0b000)
if !IsFeatureImplemented(FEAT_AA64) then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if IsFeatureImplemented(FEAT_NV3) && EffectiveHCRX_EL2_NVTGE() == '1' then X{64}(t) = NVHCR_EL2(); elsif EffectiveHCR_EL2_NVx() IN {'1x1'} then X{64}(t) = NVMem(0x078); elsif EffectiveHCR_EL2_NVx() IN {'xx1'} then AArch64_SystemAccessTrap(EL2, 0x18); else Undefined(); end; elsif PSTATE.EL == EL2 then X{64}(t) = HCR_EL2(); elsif PSTATE.EL == EL3 then X{64}(t) = HCR_EL2(); end;
MSR HCR_EL2, <Xt>
(op0 = 0b11, op1 = 0b100, CRn = 0b0001, CRm = 0b0001, op2 = 0b000)
if !IsFeatureImplemented(FEAT_AA64) then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if IsFeatureImplemented(FEAT_NV3) && EffectiveHCRX_EL2_NVTGE() == '1' then NVHCR_EL2() = X{64}(t); elsif EffectiveHCR_EL2_NVx() IN {'1x1'} then NVMem(0x078) = X{64}(t); elsif EffectiveHCR_EL2_NVx() IN {'xx1'} then AArch64_SystemAccessTrap(EL2, 0x18); else Undefined(); end; elsif PSTATE.EL == EL2 then HCR_EL2() = X{64}(t); elsif PSTATE.EL == EL3 then HCR_EL2() = X{64}(t); end;
Version 2026.06 — Copyright © 2010-2026 Arm Limited or its affiliates.
This site is provided as a community resource and is NOT affiliated with nor endorsed by Arm Limited.