In kvminithart, line 80 turns paging on with csrw satp. Nothing jumps to a new
address afterwards: the program counter simply moves on to the next instruction. Why
does that next instruction (the second sfence.vma) still get fetched correctly?
Test yourself · category 13 of 20
Page tables and address spaces
Sv39 page tables in this kernel, from PTE bits and walk() to the kernel’s direct map, the trampoline mapped twice, satp and the TLB on each hart, and what a user address space really contains.
A page-table page in Sv39 is one 4096-byte page. How many page-table entries (PTEs) does it hold?
Right after exec, the level-0 PTE for sh’s data page (virtual 0x2000) read
0x21fce817 in our run. Decode it using the macros in kernel/riscv.h.
Value: 0x21fce817
TRAMPOLINE is 0x3ffffff000. What is its index in the root (level-2)
page-table page, PX(2, TRAMPOLINE)?
Sv39 can translate 39-bit virtual addresses, 512 GiB. Why does xv6 set MAXVA to
1 << 38 (256 GiB) instead?
True or false: every xv6 user page table maps the whole kernel, protected from the
program only by leaving PTE_U clear.
Why?
Click the line in walk without which a freshly allocated page-table page would be
full of entries that look valid, so that walk would follow garbage pointers or
mappages would panic with “remap”.
Your pick: none yet (click a line in the code)
sh’s address space has these pages. Which of them have PTE_U set, so that sh
itself, in user mode, may touch them?
Line 47 of kvmmake maps the trampoline page at TRAMPOLINE, although the
direct map (line 39) already covers its physical page 0x80006000. Why is this second
mapping necessary?
A buggy program passes its trapframe’s address, 0x3fffffe000, as a buffer to a system
call, and the kernel calls copyout(p->pagetable, p->sz, 0x3fffffe000, src, 8). The
page is mapped in the user table (R W, no U). What happens?
sh runs lb a5, 0(a0) with a0 = 0x2020 in user mode, and the translation is not in
the TLB. Put the hardware’s steps in order.
- Read the level-2 PTE at index bits 38…30 (0); it has V and no R/W/X, so follow it
- Take the root page-table page’s physical address from satp’s PPN field
- Add the offset 0x020 to the leaf’s page address and load the byte
- Read the level-1 PTE at index bits 29…21 (0) and follow it
- Look up virtual page 0x2 in this hart’s TLB, and miss
- Read the level-0 PTE at index bits 20…12 (2) and check V, U and R
Match each macro from kernel/riscv.h with what it computes.
Hart 0 runs sh and hart 2 runs ls. At the same instant both execute a load from
virtual address 0x0. Why don’t they interfere?
Line 36 of kvmmake maps the PLIC: 64 MiB (0x4000000) starting at 0x0c000000.
The level-2 and level-1 tables for the first GiB already exist. How many level-0
page-table pages does walk allocate for this one call?
gdb shows satp = 0x8000000000087f41 on a hart. In this build the kernel’s root
page is at 0x87fff000. Decode it.
Value: 0x8000000000087f41
Hart 1 has left its spin loop in main, printed hart 1 starting, and has just
executed the csrw satp on line 80 of kvminithart (called from main line 39). What
is hart 1’s state?
Hart 0 executed sfence.vma around its csrw satp at boot. Why must harts 1 and 2 run
kvminithart, with its own two sfence.vma, for themselves?
True or false: because three harts translate through kernel_pagetable at the same
time, xv6 must protect it with a lock.
Why?
Suppose a buggy kernel function, handling sh’s read(0, buf, 100), did
*(char *)0x2020 = 'l' with the user’s address (buf is at 0x2020). What would
happen?
With KSTACK(p) = TRAMPOLINE - (p+1) × 2 × PGSIZE, what is mapped at virtual
address 0x3fffffc000 in the kernel page table?
Why does proc_freepagetable unmap TRAMPOLINE and TRAPFRAME (with do_free = 0)
before calling uvmfree?
Which of these mappings in the kernel page table have PTE_X (executable) set?
sh’s layout: code 0x0–0x1fff (R X U), data 0x2000 (R W U), guard 0x3000 (R W),
stack 0x4000 (R W U), sz = 0x5000, trapframe at 0x3fffffe000 (R W). Which of
these, executed by sh in user mode, raise a page fault?
What does the satp register give the hardware?
sh’s page table uses 5 page-table pages (root; a level-1 and a level-0 page for the
bottom; a level-1 and a level-0 page for the top). If its heap grew eagerly from
0x5000 by 4 MiB (to sz = 0x405000), how many page-table pages would the table use
in total?