AArch64架构Neoverse-N3 CPU分支预测单元(BPU)失效相关技术问询
Great questions—let’s break them down clearly since they cover key details of branch predictor invalidation on Neoverse-N3:
No, you can’t. Neoverse-N3 is a pure 64-bit AArch64 core with no support for the AArch32 execution state whatsoever. Unlike older Cortex-A73/A75 cores which had mixed 32/64-bit capabilities, Neoverse-N3 was designed exclusively for 64-bit workloads. This means switching to AArch32 mode isn’t an option, and you’ll need to use the mitigation methods specifically documented for this core (either the loop workaround or SMCCC call).
SMCCC_ARCH_WORKAROUND_1 is a firmware-level mitigation for Spectre-BHB, delivered via Arm’s System Management Communication Channel (SMCCC). Here’s how to use it:
Invoking the call
To trigger the workaround:
- Make sure you’re running at an exception level that allows SMC instructions (typically EL1, or EL0 with appropriate system permissions—this depends on your firmware’s configuration).
- Prepare registers per SMCCC v1.1+ standards:
- Set
X0to the function ID:0x80000001(the standard ID for SMCCC_ARCH_WORKAROUND_1) - Clear all other general-purpose registers (X1-X7) to 0.
- Set
- Execute the
SMC #0instruction to pass the request to your EL3 firmware (like Trusted Firmware-A).
Verifying firmware support
There are two straightforward ways to check if your firmware implements this workaround:
- Check the return value: After running the SMC call,
X0will return:0(SMCCC_SUCCESS) if the workaround was executed successfully.0xFFFFFFFF(SMCCC_NOT_SUPPORTED) if the firmware doesn’t include this function.
- System-level checks: On Linux systems, if debug interfaces are enabled, you can inspect
/sys/kernel/debug/arm64/smcccto see a list of supported SMCCC functions. You can also use user-space tools likesmcc-toolsto test the call programmatically.
The value K=38 is not a direct count of branch history entries—it’s an empirically tested minimum number of loop iterations needed to fully flush the branch predictor’s speculative history on Neoverse-N3.
Branch predictor implementation details (like exact history entry counts) are microarchitecture-specific and not publicly disclosed by Arm (they can vary between core generations and silicon revisions). Instead, Arm’s engineering team runs extensive testing to determine how many "dummy" branch operations are needed to overwrite all relevant history state. For Neoverse-N3, 38 iterations are enough to ensure any exploitable branch history is discarded.
The workaround loop usually looks like this in AArch64 assembly:
flush_bpu: mov x0, #38 ; Set iteration count to K=38 1: subs x0, x0, #1 ; Decrement counter b.ne 1b ; Branch back until counter hits 0
Running this loop fills the branch predictor with irrelevant branch operations, effectively invalidating any previous speculative state that could be used in a Spectre-BHB attack.
内容的提问来源于stack exchange,提问作者Gal Kaptsenel

