Computer Engineering DISCUSSION

How is a virtual address translated to a physical address, and what does the TLB do?

Started by vannhan virtual memorypage tableTLBaddress translationhuge pages
5 replies 248 views 6 participants
Latest activity · 30 Sep 2026

How is a virtual address translated to a physical address, and what does the TLB do?

vannhan Computer Engineering Forum
#1

I am studying virtual memory on x86-64: 4 KiB pages, 48-bit virtual addresses and a four-level page table. If every memory access has to be translated by walking four levels of tables, it seems each load would need four extra memory reads, which cannot be how it works in practice.

How is the address actually split up, where does the TLB come in, and why are the virtual addresses 48 bits and not the full 64?

Community replies 5

Re: How is a virtual address translated to a physical address, and what does the TLB do?

#2

A 4 KiB page is 2^12 bytes, so the low 12 bits of an address are the offset inside the page and are never translated. The remaining 36 bits of a 48-bit address are the virtual page number. Translation replaces the virtual page number with a physical frame number and keeps the offset.

Example: the virtual address 0x00007F3A12345678 has offset 0x678 and virtual page number 0x7F3A12345. If the page table maps that page to physical frame 0x1A2B3, the physical address is 0x1A2B3678.

Re: How is a virtual address translated to a physical address, and what does the TLB do?

#3

The four levels exist because a flat table is impossible. One 8-byte entry for each of 2^36 pages would be 512 GiB per process. Instead the 36-bit page number is cut into four 9-bit fields. Each field indexes a table of 512 entries, and 512 × 8 bytes is exactly one 4 KiB page, so every table fits in one page. Only the tables for address ranges a process actually uses are allocated.

That is also where 48 comes from: 4 × 9 + 12. The upper 16 bits must be copies of bit 47 (a canonical address). Newer processors add a fifth level for 57-bit addresses. Full 64-bit translation would need more levels and cost every page walk more for address space nobody could use yet.

Re: How is a virtual address translated to a physical address, and what does the TLB do?

#4

The TLB (translation lookaside buffer) is what makes it fast. It is a small cache inside the processor that stores recent page-number-to-frame translations. On a hit the translation costs essentially nothing, because the lookup runs alongside the first-level cache access. Only on a TLB miss does the hardware page walker read the four table levels, and those table entries are ordinary memory that is usually in the data caches, with extra caches for the upper levels, so a walk typically costs tens of cycles, not four trips to main memory.

The limit is reach. A first-level data TLB with 64 entries covers 64 × 4 KiB = 256 KiB; a second-level TLB with 1536 entries, to take one example size, covers 6 MiB. Programs that jump around in gigabytes of data miss often.

Re: How is a virtual address translated to a physical address, and what does the TLB do?

#5

Huge pages are the standard answer to limited TLB reach. A 2 MiB page has a 21-bit offset and ends the walk one level early, and one TLB entry then covers 512 times as much memory; 1 GiB pages end it two levels early. Databases, virtual machines and numerical codes with large arrays benefit most. Linux can apply 2 MiB pages automatically through transparent huge pages or explicitly through hugetlbfs.

The costs are coarser allocation, since memory is handed out in 2 MiB units, and the need for contiguous free physical memory, which gets harder to find on a long-running system.

Re: How is a virtual address translated to a physical address, and what does the TLB do?

#6

Keep a TLB miss and a page fault apart, since they sound similar. A TLB miss just means the translation was not cached; the walker finds a valid entry and execution continues without the operating system being involved on x86 or ARM. A page fault happens when the walk finds an entry marked not present or the access violates its permissions. The processor then raises an exception and the operating system decides: allocate a fresh page on first touch, read the page back from disk, copy it for copy-on-write, or terminate the process with a segmentation fault.

Because each process has its own tables, a context switch must not reuse stale translations. Processors tag TLB entries with an address-space identifier so the whole TLB need not be flushed on every switch.

TEP COMMUNITY