Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Armv8-A virtualization gives a hypervisor a privileged control point at Exception Level 2 (EL2), where it can manage guest execution, mediate selected operations, and isolate guest memory. A guest operating system normally runs at non-secure EL1, while applications run at EL0. The key mechanisms are EL2, two-stage address translation, traps, virtual interrupts, and per-VM identifiers.

What EL2 adds to an Armv8-A system

Armv8-A defines EL2 as the execution level for a hypervisor managing virtual machines. The hypervisor uses it to switch between guests, control guest-visible system state, and arbitrate access to shared physical resources. Guests typically run in non-secure EL1 and do not need to know that a hypervisor is managing the machine beneath them.

EL2 is a control point, not a complete virtualization solution by itself. A working system also needs suitable processor implementation support and hypervisor software to configure translations, handle traps, and manage interrupts.

How stage 1 and stage 2 address translation differ

Arm virtualization separates the guest operating system’s view of memory from the machine’s actual physical memory. The guest uses stage 1 translation; the hypervisor controls stage 2.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Translation stage Input and output Who controls it What it does
Stage 1 Guest virtual address (VA) → intermediate physical address (IPA) Guest operating system Maps the guest’s virtual addresses into the physical-address space it believes it owns.
Stage 2 Intermediate physical address (IPA) → physical address (PA) Hypervisor at EL2 Maps the guest’s IPA to real machine memory, allowing the hypervisor to enforce memory ownership and isolation.

The guest generally treats its IPA as if it were a physical address. The hypervisor applies stage 2 underneath that view, so the guest need not understand the additional mapping. The effective memory access therefore depends on both stages: the guest’s stage 1 mapping and the hypervisor-controlled stage 2 mapping.

How traps let the hypervisor mediate guest operations

The architecture allows EL2 to arrange for selected guest operations to trap rather than complete directly. Examples include accesses to many control registers and memory-management operations. When a configured operation traps, execution enters EL2, where the hypervisor can validate the request, emulate it, or service it before returning to the guest.

Hypervisor Configuration Register controls (HCR_EL2) govern virtualization and aspects of trapping behavior. After handling an exception, the hypervisor can use ERET to return from the exception to the guest. Which operations trap depends on the controls and the particular operation; virtualization does not mean every guest instruction must be intercepted.

How virtual interrupts reach a guest

Arm defines guest-visible virtual IRQ, FIQ, and SError signals: vIRQ, vFIQ, and vSError. Physical exceptions can be routed to EL2, and HCR_EL2 routing controls—including IMO, FMO, and AMO—also enable corresponding virtual exception signaling to EL0 or EL1. A hypervisor can manage virtual interrupt signaling through these controls or use a GICv2-or-later interrupt controller to deliver virtual interrupts to a selected virtual CPU.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Virtual interrupts are not taken while execution is at EL2 or EL3. Arm’s 2019 Armv8-A virtualization guide states: “It is not possible to receive a virtual interrupt while executing in EL2 or EL3.” This matters when designing interrupt handling: the hypervisor handles or routes events at its own level, while a guest receives virtual signaling when it is executing at a level that can take it.

What VMIDs do during guest context switches

A virtual machine can be assigned a VMID, or virtual machine identifier. EL2 uses the VMID together with translation-control state to associate stage 2 mappings with the correct VM as guest contexts change. This helps keep one guest’s memory translations distinct from another’s; VMIDs work alongside, rather than replace, the stage 2 page tables that define those mappings.

Rank #4
Sale
ARM System Developer's Guide: Designing and Optimizing System Software (The Morgan Kaufmann Series in Computer Architecture and Design)
  • New
  • Mint Condition
  • Dispatch same day for order received before 12 noon
  • Guaranteed packaging
  • No quibbles returns

Where VHE and Secure EL2 fit

VHE, or Virtualization Host Extensions, is relevant to host operating systems that run virtualization workloads. Android Open Source Project documentation describes different KVM/arm64 execution modes depending on whether VHE is available, so host configuration and implementation support affect which mode is used.

Secure EL2 extends virtualization support into secure state. Arm’s virtualization guide identifies secure-state virtualization support as introduced in Armv8.4-A. Neither Secure EL2 nor VHE should be assumed to exist on every Arm processor: support depends on the architecture version and the specific implementation. Arm’s A-profile learning material also groups nested virtualization and VMID with Armv8-A and Armv9-A virtualization topics.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What these facilities are used for

  • Server and embedded hypervisors: EL2 and stage 2 translation provide mechanisms to schedule guests and isolate their memory.
  • Device assignment and partitioning: Virtualization can support assigning or partitioning resources, with the hypervisor coordinating access to shared physical hardware.
  • Protected virtual machines: Android’s Virtualization Framework uses an EL2 hypervisor layer to isolate memory and devices in protected VMs. Its implementation documentation describes both two-stage memory translation and interrupt routing to the hypervisor or the appropriate guest.

What to check on a particular Arm system

The architecture describes available mechanisms, but the exact capabilities depend on the processor, interrupt controller, and software configuration. When evaluating a target system, check:

  • Whether its processor implements the required EL2 and virtualization facilities.
  • Whether the host and hypervisor configure stage 2 translations for the intended guests.
  • Which guest operations are configured to trap and how the hypervisor handles them.
  • Which interrupt controller is present and how virtual interrupts are delivered.
  • Whether VHE or Secure EL2 is supported and enabled for the intended software mode.
  • How VMIDs and translation state are managed when switching between guests.

These mechanisms explain how virtualization can be implemented; they do not establish a universal performance advantage. Performance depends on the implementation and workload, and architectural descriptions alone are not workload benchmarks.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.