Registers

The revocation bitmap is not a register but a memory window on the revbm interface; see the Theory of Operation.

Summary

NameOffsetLengthDescription
cheriot_mem_sys.INTR_STATE0x04Interrupt State Register
cheriot_mem_sys.INTR_ENABLE0x44Interrupt Enable Register
cheriot_mem_sys.INTR_TEST0x84Interrupt Test Register
cheriot_mem_sys.ALERT_TEST0xc4Alert Test Register
cheriot_mem_sys.TBRE_REGWEN0x104Write enable for the revocation engine registers.
cheriot_mem_sys.TBRE_BASE_ADDR0x144Address of the first capability the revocation engine sweeps.
cheriot_mem_sys.TBRE_NUM_CAPS0x184Number of capabilities the revocation engine sweeps, each of them two 32-bit words.
cheriot_mem_sys.TBRE_START0x1c4Starts a sweep over the capabilities TBRE_BASE_ADDR and TBRE_NUM_CAPS describe.
cheriot_mem_sys.TBRE_STATUS0x204Status of the revocation engine.
cheriot_mem_sys.TBRE_EPOCH0x244Sweep epoch, twice the number of sweeps that ended without an error, plus one while the

INTR_STATE

Interrupt State Register

  • Offset: 0x0
  • Reset default: 0x0
  • Reset mask: 0x1

Fields

{"reg": [{"name": "tbre_done", "bits": 1, "attr": ["rw1c"], "rotate": -90}, {"bits": 31}], "config": {"lanes": 1, "fontsize": 10, "vspace": 110}}
BitsTypeResetNameDescription
31:1Reserved
0rw1c0x0tbre_doneRaised when the revocation engine has resolved every capability of a sweep.

INTR_ENABLE

Interrupt Enable Register

  • Offset: 0x4
  • Reset default: 0x0
  • Reset mask: 0x1

Fields

{"reg": [{"name": "tbre_done", "bits": 1, "attr": ["rw"], "rotate": -90}, {"bits": 31}], "config": {"lanes": 1, "fontsize": 10, "vspace": 110}}
BitsTypeResetNameDescription
31:1Reserved
0rw0x0tbre_doneEnable interrupt when INTR_STATE.tbre_done is set.

INTR_TEST

Interrupt Test Register

  • Offset: 0x8
  • Reset default: 0x0
  • Reset mask: 0x1

Fields

{"reg": [{"name": "tbre_done", "bits": 1, "attr": ["wo"], "rotate": -90}, {"bits": 31}], "config": {"lanes": 1, "fontsize": 10, "vspace": 110}}
BitsTypeResetNameDescription
31:1Reserved
0wo0x0tbre_doneWrite 1 to force INTR_STATE.tbre_done to 1.

ALERT_TEST

Alert Test Register

  • Offset: 0xc
  • Reset default: 0x80000000
  • Reset mask: 0x80000001

Fields

{"reg": [{"name": "fatal_fault", "bits": 1, "attr": ["wo"], "rotate": -90}, {"bits": 30}, {"name": "regwen", "bits": 1, "attr": ["rw0c"], "rotate": -90}], "config": {"lanes": 1, "fontsize": 10, "vspace": 130}}
BitsTypeResetNameDescription
31rw0c0x1regwenWrite 0 to disable alert testing until the next reset.
30:1Reserved
0wo0x0fatal_faultWrite 1 to trigger one alert event of this kind.

TBRE_REGWEN

Write enable for the revocation engine registers.

  • Offset: 0x10
  • Reset default: 0x1
  • Reset mask: 0x1

Fields

{"reg": [{"name": "en", "bits": 1, "attr": ["ro"], "rotate": -90}, {"bits": 31}], "config": {"lanes": 1, "fontsize": 10, "vspace": 80}}
BitsTypeResetNameDescription
31:1Reserved
0ro0x1enLow while the revocation engine is active, locking TBRE_BASE_ADDR, TBRE_NUM_CAPS and TBRE_START. TBRE_STATUS.busy follows the same state one cycle later.

TBRE_BASE_ADDR

Address of the first capability the revocation engine sweeps.

  • Offset: 0x14
  • Reset default: 0x0
  • Reset mask: 0xfffffff8
  • Register enable: TBRE_REGWEN

Fields

{"reg": [{"bits": 3}, {"name": "addr", "bits": 29, "attr": ["rw"], "rotate": 0}], "config": {"lanes": 1, "fontsize": 10, "vspace": 80}}
BitsTypeResetNameDescription
31:3rw0x0addrBits 31:3 of the address. The sweep starts at a capability boundary; bits 2:0 read as zero. The address must lie in a tagged region, the main SRAM or the NVM; the sweep stops at the top of that region.
2:0Reserved

TBRE_NUM_CAPS

Number of capabilities the revocation engine sweeps, each of them two 32-bit words.

  • Offset: 0x18
  • Reset default: 0x0
  • Reset mask: 0x7fffffff
  • Register enable: TBRE_REGWEN

Fields

{"reg": [{"name": "num", "bits": 31, "attr": ["rw"], "rotate": 0}, {"bits": 1}], "config": {"lanes": 1, "fontsize": 10, "vspace": 80}}
BitsTypeResetNameDescription
31Reserved
30:0rw0x0numNumber of capabilities. A sweep reaching past the top of its tagged region ends at its top; the register keeps the value written.

TBRE_START

Starts a sweep over the capabilities TBRE_BASE_ADDR and TBRE_NUM_CAPS describe. TBRE_STATUS.busy reflects the sweep in progress. A start outside CHERIoT mode, with TBRE_NUM_CAPS zero, or with TBRE_BASE_ADDR outside the tagged regions, is ignored and sets TBRE_STATUS.start_err.

  • Offset: 0x1c
  • Reset default: 0x0
  • Reset mask: 0x1
  • Register enable: TBRE_REGWEN

Fields

{"reg": [{"name": "start", "bits": 1, "attr": ["wo"], "rotate": -90}, {"bits": 31}], "config": {"lanes": 1, "fontsize": 10, "vspace": 80}}
BitsTypeResetNameDescription
31:1Reserved
0wo0x0startWrite 1 to start a sweep.

TBRE_STATUS

Status of the revocation engine.

  • Offset: 0x20
  • Reset default: 0x0
  • Reset mask: 0x301

Fields

{"reg": [{"name": "busy", "bits": 1, "attr": ["ro"], "rotate": -90}, {"bits": 7}, {"name": "start_err", "bits": 1, "attr": ["rw1c"], "rotate": -90}, {"name": "sweep_err", "bits": 1, "attr": ["rw1c"], "rotate": -90}, {"bits": 22}], "config": {"lanes": 1, "fontsize": 10, "vspace": 110}}
BitsTypeResetName
31:10Reserved
9rw1c0x0sweep_err
8rw1c0x0start_err
7:1Reserved
0ro0x0busy

TBRE_STATUS . sweep_err

A response to the revocation engine was an error, failed its integrity check or was malformed, or the RMW filter reported a fault, during a sweep. Except for an error response to a read of the swept memory, the fatal_fault alert is raised as well. Stays set until software writes 1 to it.

TBRE_STATUS . start_err

A start was ignored because the subsystem was not in CHERIoT mode, TBRE_NUM_CAPS was zero or TBRE_BASE_ADDR was outside the tagged regions. Stays set until software writes 1 to it.

TBRE_STATUS . busy

The revocation engine is sweeping; it is low once every capability of the sweep is resolved.

TBRE_EPOCH

Sweep epoch, twice the number of sweeps that ended without an error, plus one while the revocation engine is active. It is odd from the cycle a start is taken, when TBRE_REGWEN falls, until the engine is inactive again, and even otherwise. A sweep that ends with an error (see TBRE_STATUS.sweep_err) is not counted, so the epoch returns to the even value it had before that start, and no software waiting for a completed sweep proceeds on it.

  • Offset: 0x24
  • Reset default: 0x0
  • Reset mask: 0xffffffff

Fields

{"reg": [{"name": "active", "bits": 1, "attr": ["ro"], "rotate": -90}, {"name": "count", "bits": 31, "attr": ["ro"], "rotate": 0}], "config": {"lanes": 1, "fontsize": 10, "vspace": 80}}
BitsTypeResetNameDescription
31:1ro0x0countSweeps that ended without an error, modulo 2^31; a sweep counts in the cycle TBRE_EPOCH.active clears.
0ro0x0activeThe revocation engine is active; the inverse of TBRE_REGWEN.