TLB Range Invalidate by VA, All ASID, EL1, Outer Shareable
Invalidates cached copies of translation table entries from TLBs that meet all the following requirements:
The entry is one of the following:
A 128-bit stage 1 translation table entry, from any level of the translation table walk, to the level indicated by the TTL hint, and one of the following applies:
TTL64 is 0.
TTL64 is 1 and TTL is 0b00 or treated as 0b00.
A 64-bit stage 1 translation table entry, from any level of the translation table walk, to the level indicated by the TTL hint, and one of the following applies:
TTL64 is 0 and TTL is 0b00 or treated as 0b00.
TTL64 is 1.
The entry is within the address range determined by the formula [BaseADDR <= VA < BaseADDR + ((NUM +1)*2(5*SCALE +1) * Translation_Granule_Size)].
When EL2 is implemented and enabled in the current Security state:
If the Effective value of HCR_EL2.{E2H, TGE} is not {1, 1}, the entry would be used with the current VMID and would be required to translate any VA in the specified address range using the EL1&0 translation regime for the Security state.
If the Effective value of HCR_EL2.{E2H, TGE} is {1, 1}, the entry would be required to translate any VA in the specified address range using the EL2&0 translation regime for the Security state.
When EL2 is not implemented or is disabled in the current Security state, the entry would be required to translate any VA in the specified address range using the EL1&0 translation regime for the Security state.
The Security state is indicated by the value of SCR_EL3.NS if FEAT_RME is not implemented, or SCR_EL3.{NSE, NS} if FEAT_RME is implemented.
The invalidation applies to all PEs in the same Outer Shareable shareability domain as the PE that executes this System instruction.
If FEAT_TLBID is implemented, the set of PEs is reduced to be PEs that are also within the TLBI Domain specified in the TLBID field and System register configuration.
When a TLB maintenance instruction is generated to the Secure EL1&0 translation regime and is defined to pass a VMID argument, or would be defined to pass a VMID argument if SCR_EL3.EEL2==1, then:
For the EL1&0 and EL2&0 translation regimes, the invalidation applies to both global entries and non-global entries with any ASID.
For 128-bit translation table entry, the range of addresses invalidated is UNPREDICTABLE when Block or Page size corresponding to TTL and TG, for the translation system is not aligned.
If FEAT_XS is implemented, the nXS variant of this System instruction is defined.
It is IMPLEMENTATION SPECIFIC whether the TLBI System instruction with the nXS qualifier invalidates TLB entries with the XS attribute set to 1.
The TLBI System instruction without the nXS qualifier waits for all memory accesses using in-scope old translation information to complete before it is considered complete.
The TLBI System instruction with the nXS qualifier is considered complete when the subset of these memory accesses with XS attribute set to 0 are complete.
This instruction is present only when (FEAT_D128 is implemented or FEAT_TLBID is implemented) and FEAT_AA64 is implemented. Otherwise, direct accesses to TLBIP RVAAE1OS, TLBIP RVAAE1OSNXS are UNDEFINED.
TLBIP RVAAE1OS, TLBIP RVAAE1OSNXS is a 128-bit System instruction.
| 127 | 126 | 125 | 124 | 123 | 122 | 121 | 120 | 119 | 118 | 117 | 116 | 115 | 114 | 113 | 112 | 111 | 110 | 109 | 108 | 107 | 106 | 105 | 104 | 103 | 102 | 101 | 100 | 99 | 98 | 97 | 96 |
| RES0 | BaseADDR[55:12] | ||||||||||||||||||||||||||||||
| 95 | 94 | 93 | 92 | 91 | 90 | 89 | 88 | 87 | 86 | 85 | 84 | 83 | 82 | 81 | 80 | 79 | 78 | 77 | 76 | 75 | 74 | 73 | 72 | 71 | 70 | 69 | 68 | 67 | 66 | 65 | 64 |
| BaseADDR[55:12] | |||||||||||||||||||||||||||||||
| 63 | 62 | 61 | 60 | 59 | 58 | 57 | 56 | 55 | 54 | 53 | 52 | 51 | 50 | 49 | 48 | 47 | 46 | 45 | 44 | 43 | 42 | 41 | 40 | 39 | 38 | 37 | 36 | 35 | 34 | 33 | 32 |
| RES0 | TG | SCALE | NUM | TTL | RES0 | TTL64 | |||||||||||||||||||||||||
| 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
| RES0 | TLBID | ||||||||||||||||||||||||||||||
Reserved, RES0.
The starting address for the range of the maintenance instructions. This field is BaseADDR[55:12] for all translation granules.
Reserved, RES0.
Translation granule size.
| TG | Meaning |
|---|---|
| 0b00 |
Reserved. |
| 0b01 |
4K translation granule. |
| 0b10 |
16K translation granule. |
| 0b11 |
64K translation granule. |
The instruction takes a translation granule size for the translations that are being invalidated. If the translations used a different translation granule size than the one being specified, then the architecture does not require that the instruction invalidates any entries.
The exponent element of the calculation that is used to produce the upper range.
The base element of the calculation that is used to produce the upper range.
TTL Level hint. The TTL hint is only guaranteed to invalidate:
Non-leaf-level entries in the range up to but not including the level described by the TTL hint.
Leaf-level entries in the range that match the level described by the TTL hint.
| TTL | Meaning |
|---|---|
| 0b00 |
The entries in the range can be using any level for the translation table entries. |
| 0b01 |
The TTL hint indicates level 1. |
| 0b10 |
The TTL hint indicates level 2. |
| 0b11 |
The TTL hint indicates level 3. |
Reserved, RES0.
Specifies that the TTL hint applies to VMSAv8-64 TLB entries.
| TTL64 | Meaning |
|---|---|
| 0b0 |
The TTL field applies to cached copies of VMSAv9-128 translation table entries. |
| 0b1 |
The TTL field applies to cached copies of VMSAv8-64 translation table entries. |
Reserved, RES0.
Reserved, RES0.
TLBI Domain.
Reserved, RES0.
This system instruction is an alias of the SYSP instruction.
The following pseudocode describes traps which apply to the System instruction. For information about changes to the scope of the invalidation to the instruction under different conditions, see AArch64_TLBIP_RVAA() in the Pseudocode for AArch64 operation.
Accesses to this instruction use the following encodings in the System instruction encoding space:
TLBIP RVAAE1OS{, <Xt>, <Xt2>}
(op0 = 0b01, op1 = 0b000, CRn = 0b1000, CRm = 0b0101, op2 = 0b011)
if !((IsFeatureImplemented(FEAT_D128) || IsFeatureImplemented(FEAT_TLBID)) && IsFeatureImplemented(FEAT_AA64)) then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && (HCR_EL2().TTLB == '1' || HCR_EL2().TTLBOS == '1') && !(IsFeatureImplemented(FEAT_NV3) && EffectiveHCRX_EL2_NVTGE() == '1' && NVHCR_EL2().TGE == '1' && HCRX_EL2().NVnTTLBOS == '1') then AArch64_SystemAccessTrap(EL2, 0x14); elsif EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && HFGITR_EL2().TLBIRVAAE1OS == '1' then AArch64_SystemAccessTrap(EL2, 0x14); else AArch64_TLBIP_RVAA(SecurityStateAtEL(EL1), Regime_EL10, VMID(), Broadcast_OSH, TLBILevel_Any, TLBI_AllAttr, X{128}(t, t2)); end; elsif PSTATE.EL == EL2 then AArch64_TLBIP_RVAA(SecurityStateAtEL(EL1), Regime_EL10, VMID(), Broadcast_OSH, TLBILevel_Any, TLBI_AllAttr, X{128}(t, t2)); elsif PSTATE.EL == EL3 then if IsFeatureImplemented(FEAT_RME) && !ValidSecurityStateAtEL(EL1) then return; else AArch64_TLBIP_RVAA(SecurityStateAtEL(EL1), Regime_EL10, VMID(), Broadcast_OSH, TLBILevel_Any, TLBI_AllAttr, X{128}(t, t2)); end; end;
TLBIP RVAAE1OSNXS{, <Xt>, <Xt2>}
(op0 = 0b01, op1 = 0b000, CRn = 0b1001, CRm = 0b0101, op2 = 0b011)
if !((IsFeatureImplemented(FEAT_D128) || IsFeatureImplemented(FEAT_TLBID)) && IsFeatureImplemented(FEAT_AA64)) then Undefined(); elsif !IsFeatureImplemented(FEAT_XS) then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && (HCR_EL2().TTLB == '1' || HCR_EL2().TTLBOS == '1') && !(IsFeatureImplemented(FEAT_NV3) && EffectiveHCRX_EL2_NVTGE() == '1' && NVHCR_EL2().TGE == '1' && HCRX_EL2().NVnTTLBOS == '1') then AArch64_SystemAccessTrap(EL2, 0x14); elsif EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && IsFeatureImplemented(FEAT_HCX) && (!IsHCRXEL2Enabled() || HCRX_EL2().FGTnXS == '0') && HFGITR_EL2().TLBIRVAAE1OS == '1' then AArch64_SystemAccessTrap(EL2, 0x14); else AArch64_TLBIP_RVAA(SecurityStateAtEL(EL1), Regime_EL10, VMID(), Broadcast_OSH, TLBILevel_Any, TLBI_ExcludeXS, X{128}(t, t2)); end; elsif PSTATE.EL == EL2 then AArch64_TLBIP_RVAA(SecurityStateAtEL(EL1), Regime_EL10, VMID(), Broadcast_OSH, TLBILevel_Any, TLBI_ExcludeXS, X{128}(t, t2)); elsif PSTATE.EL == EL3 then if IsFeatureImplemented(FEAT_RME) && !ValidSecurityStateAtEL(EL1) then return; else AArch64_TLBIP_RVAA(SecurityStateAtEL(EL1), Regime_EL10, VMID(), Broadcast_OSH, TLBILevel_Any, TLBI_ExcludeXS, X{128}(t, t2)); end; end;
Version 2026.06 — Copyright © 2010-2026 Arm Limited or its affiliates.
This site is provided as a community resource and is NOT affiliated with nor endorsed by Arm Limited.