The current ETMx configuration via sysfs can lead to the following
inconsistencies:
- If a configuration is modified via sysfs while a perf session is
active, the running configuration may differ between before
a sched-out and after a subsequent sched-in.
- If a perf session and sysfs session tries to enable concurrently,
configuration from configfs could be corrupted (etm4).
- There is chance to corrupt drvdata->config if perf session tries
to enabled among handling cscfg_csdev_disable_active_config()
in etm4_disable_sysfs() (etm4).
To resolve these inconsistencies, the configuration should be separated into:
- active_config, which is applied configuration for the current session
- config, which stores the settings configured via sysfs.
and apply configuration from configfs after taking a mode.
Patch History
=============
from v10 to 11:
- replace direct register read from etm3 sysfs with IPI.
- fix issue cntr_val and others field which required to be shown after
sysfs session disable.
- prohibit the write for some etm3 sysfs while sysfs session is
enabled.
- drop locktype change in etm3
- Link to v10: https://lore.kernel.org/r/20260911-separate_etm_cfg_v2-v10-0-1b715d95927a@a…
from v9 to v10:
- rebase to coresight/next
- https://lore.kernel.org/all/20260725113645.57519-1-yeoreum.yun@arm.com/
from v8 to v9:
- add feat_csdev_lock guard interface.
- set feat_csdev->drv_spinlock as NULL for etmv4_drvdata.
- https://lore.kernel.org/all/20260629090007.1718746-1-yeoreum.yun@arm.com/
from v7 to v8:
- accept @Leo Yan' suggestion to handle error.
- small minor fixes following @Suzuki' suggestion.
- https://lore.kernel.org/all/20260519154812.254884-1-yeoreum.yun@arm.com/
from v6 to v7:
- rebase on coresight/next
- add ETM_MAX_SEQ_TRANSITIONS define
- remove redundant patch relavent cpu-hotplug as coresight-pm patch
merged.
- https://lore.kernel.org/all/20260422132203.977549-1-yeoreum.yun@arm.com/
from v5 to v6:
- fix missing of calling cscfg_csdev_disable_active_config()
- add rb & fixes tags.
- add ss_status field in etm4x_drvdata to expose STATUS and PENDING bits.
- https://lore.kernel.org/all/20260415165528.3369607-1-yeoreum.yun@arm.com/
from v4 to v5:
- add rb-tag.
- fix underflow issue for nrseqstate.
- fix wrong check in etm4_sspcicrn_present().
- remove redundant fields on etmv4_save_state.
- rename caps->ss_status to ss_cmp.
- fix wrong location of etm4_release_trace_id.
- https://lore.kernel.org/all/20260413142003.3549310-1-yeoreum.yun@arm.com/
from v3 to v4:
- change etm_drvdata->spinlock type to raw_spin_lock_t
- remove redundant call etmX_enable_hw() with starting_cpu() callsback.
- fix missing trace id release.
- add missing docs.
- https://lore.kernel.org/all/20260412175506.412301-1-yeoreum.yun@arm.com/
from v2 to v3:
- fix build error for etm3x.
- fix checkpatch warning.
- https://lore.kernel.org/all/20260410074310.2693385-1-yeoreum.yun@arm.com/
from v1 to v2
- rebased to v7.0-rc7.
- introduce etmX_caps structure to save etmX's capabilities.
- remove ss_status from etmv4_config.
- modify active_config after taking a mode (perf/sysfs).
- https://lore.kernel.org/all/20260317181705.2456271-1-yeoreum.yun@arm.com/
---
Yeoreum Yun (9):
coresight: etm4x: prohibit modifying ss_status and cntr_val while session is enabled
coresight: etm3x: prohibit modifying cntr_val and reset while session is enabled
coresight: etm4x: fix inconsistencies with sysfs configuration
coresight: etm3x: fix inconsistencies with sysfs configuration
coresight: etm3x: remove redundant cpu online check on etm_enable_sysfs()
coresight: etm4x: introduce struct etm4_caps
coresight: etm4x: exclude ss_status from drvdata->config
coresight: etm4x: remove s_ex_level from config
coresight: etm3x: introduce struct etm_caps
drivers/hwtracing/coresight/coresight-config.c | 18 +-
drivers/hwtracing/coresight/coresight-config.h | 22 ++
drivers/hwtracing/coresight/coresight-etm.h | 46 ++-
drivers/hwtracing/coresight/coresight-etm3x-core.c | 126 +++---
.../hwtracing/coresight/coresight-etm3x-sysfs.c | 104 +++--
drivers/hwtracing/coresight/coresight-etm4x-cfg.c | 14 +-
drivers/hwtracing/coresight/coresight-etm4x-core.c | 426 +++++++++++----------
.../hwtracing/coresight/coresight-etm4x-sysfs.c | 210 ++++++----
drivers/hwtracing/coresight/coresight-etm4x.h | 196 +++++-----
9 files changed, 676 insertions(+), 486 deletions(-)
---
base-commit: 9e3604d7369cfc0110100eb1a0acab1865ee2d18
change-id: 20260911-separate_etm_cfg_v2-3518a168cbff
Best regards,
--
Sincerely,
Yeoreum Yun
On Mon, Sep 14, 2026 at 03:49:00PM +0800, Yingchao Deng wrote:
> cscfg_create_device() calls put_device() on the error path while holding
> cscfg_mutex. If device_register() fails, put_device() drops the last
> reference and invokes cscfg_dev_release(), which takes cscfg_mutex again,
> deadlocking.
>
> Module init and exit are serialized by the kernel, so cscfg_mutex is not
> needed to protect the allocation and freeing of cscfg_mgr. Remove the
> mutex from cscfg_dev_release() and take it only while cscfg_mgr fields
> are being accessed.
>
> Fixes: 199380decc5f ("coresight: configfs: Fix unload of configurations on module exit")
> Suggested-by: Leo Yan <leo.yan(a)arm.com>
> Signed-off-by: Yingchao Deng <dengyingchao(a)kylinsec.com.cn>
For this patch:
Reviewed-by: Leo Yan <leo.yan(a)arm.com>
Sashiko reported an issue for null pointer dereference if configfs
init fails fails [1]. It is good to fix it using a separate patch:
@@ -1299,8 +1299,10 @@ int __init cscfg_init(void)
/* initialise configfs subsystem */
err = cscfg_configfs_init(cscfg_mgr);
- if (err)
- goto exit_err;
+ if (err) {
+ device_unregister(cscfg_device());
+ return err;
+ }
/* preload built-in configurations */
err = cscfg_preload(THIS_MODULE);
@Yingchao, do you mind to work out a formal patch for this?
Thanks,
Leo
[1] https://sashiko.dev/#/patchset/6CC680FFAC60931F%2B20260914074900.1711-1-den…
On Wed, Sep 23, 2026 at 08:18:56PM -0400, Yuho Choi wrote:
> @@ -843,7 +843,11 @@ static bool coresight_get_ref(struct coresight_device *csdev)
> goto err_module;
>
> /* Make sure the device is powered on */
> - pm_runtime_get_sync(parent);
> + if (pm_runtime_resume_and_get(parent) < 0) {
> + module_put(drv->owner);
> + goto err_module;
> + }
> +
There is already a patch that does something similar and fixes the same
errors across the CoreSight folder. See:
https://lore.kernel.org/linux-arm-kernel/20260911-b4-coresight-runtime-pm-f…
On 9/16/26 20:57, Rob Herring wrote:
> On Sat, Aug 22, 2026 at 10:19:12AM +0200, Karl Mehltretter wrote:
>> The option exposing CoreSight CTI integration registers is
>> CONFIG_CORESIGHT_CTI_INTEGRATION_REGS, not
>> CONFIG_CORESIGHT_CTI_INTEGRATION_TEST.
>
> DT bindings should not be referring to kernel kconfig symbols (or
> anything else in the kernel) in the first place.
>
Agreed - the comment in general is correct but the last sentence in the
paragraph should drop the config reference. e.g.
"This information might be found by using the CTI Integration Test
registers to explore the trigger connections between CTI and other
CoreSight components."
The coresight/KConfig file itself adequately documents adding this
support and the perils therein.
Mike
> Rob
Reviewed-by: Mike Leach <mike.leach(a)arm.com>
On 9/17/26 22:14, Kees Cook wrote:
> From: Kees Cook <kees+treewide(a)kernel.org>
>
> In preparation for making the devm_kmalloc family of allocators type
> aware, we need to make sure that the returned type from the allocation
> matches the type of the variable being assigned. (Before, the allocator
> would always return "void *", which can be implicitly cast to any
> pointer type.)
>
> The assigned type is "const struct attribute_group **", but the
> converted allocation type would be "struct attribute_group **", which is
> the same type without the const qualifier. As there is no general way to
> safely add const qualifiers, take the size from the assignment target
> instead. No change in allocation size results.
>
> Build tested ARCH=arm64 allmodconfig with GCC aarch64-linux-gnu 16.1.0:
> drivers/hwtracing/coresight/coresight-cti-sysfs.o
>
> Assisted-by: LLM coccinelle
> Signed-off-by: Kees Cook <kees+treewide(a)kernel.org>
> ---
> Cc: Suzuki K Poulose <suzuki.poulose(a)arm.com>
> Cc: Mike Leach <mike.leach(a)arm.com>
> Cc: James Clark <james.clark(a)linaro.org>
> Cc: Leo Yan <leo.yan(a)arm.com>
> Cc: Alexander Shishkin <alexander.shishkin(a)linux.intel.com>
> Cc: <coresight(a)lists.linaro.org>
> Cc: <linux-arm-kernel(a)lists.infradead.org>
> ---
> drivers/hwtracing/coresight/coresight-cti-sysfs.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/hwtracing/coresight/coresight-cti-sysfs.c b/drivers/hwtracing/coresight/coresight-cti-sysfs.c
> index 3fe2c916d228..2ed5d8eb1dda 100644
> --- a/drivers/hwtracing/coresight/coresight-cti-sysfs.c
> +++ b/drivers/hwtracing/coresight/coresight-cti-sysfs.c
> @@ -1132,7 +1132,7 @@ static int cti_create_cons_groups(struct device *dev, struct cti_device *ctidev)
> /* nr groups = dynamic + static + NULL terminator */
> nr_groups = ctidev->nr_trig_con + CORESIGHT_CTI_STATIC_GROUPS_MAX;
> ctidev->con_groups = devm_kcalloc(dev, nr_groups,
> - sizeof(struct attribute_group *),
> + sizeof(*ctidev->con_groups),
> GFP_KERNEL);
> if (!ctidev->con_groups)
> return -ENOMEM;
The current ETMx configuration via sysfs can lead to the following
inconsistencies:
- If a configuration is modified via sysfs while a perf session is
active, the running configuration may differ between before
a sched-out and after a subsequent sched-in.
- If a perf session and sysfs session tries to enable concurrently,
configuration from configfs could be corrupted (etm4).
- There is chance to corrupt drvdata->config if perf session tries
to enabled among handling cscfg_csdev_disable_active_config()
in etm4_disable_sysfs() (etm4).
To resolve these inconsistencies, the configuration should be separated into:
- active_config, which is applied configuration for the current session
- config, which stores the settings configured via sysfs.
and apply configuration from configfs after taking a mode.
Patch History
=============
from v9 to v10:
- rebase to coresight/next
- https://lore.kernel.org/all/20260725113645.57519-1-yeoreum.yun@arm.com/
from v8 to v9:
- add feat_csdev_lock guard interface.
- set feat_csdev->drv_spinlock as NULL for etmv4_drvdata.
- https://lore.kernel.org/all/20260629090007.1718746-1-yeoreum.yun@arm.com/
from v7 to v8:
- accept @Leo Yan' suggestion to handle error.
- small minor fixes following @Suzuki' suggestion.
- https://lore.kernel.org/all/20260519154812.254884-1-yeoreum.yun@arm.com/
from v6 to v7:
- rebase on coresight/next
- add ETM_MAX_SEQ_TRANSITIONS define
- remove redundant patch relavent cpu-hotplug as coresight-pm patch
merged.
- https://lore.kernel.org/all/20260422132203.977549-1-yeoreum.yun@arm.com/
from v5 to v6:
- fix missing of calling cscfg_csdev_disable_active_config()
- add rb & fixes tags.
- add ss_status field in etm4x_drvdata to expose STATUS and PENDING bits.
- https://lore.kernel.org/all/20260415165528.3369607-1-yeoreum.yun@arm.com/
from v4 to v5:
- add rb-tag.
- fix underflow issue for nrseqstate.
- fix wrong check in etm4_sspcicrn_present().
- remove redundant fields on etmv4_save_state.
- rename caps->ss_status to ss_cmp.
- fix wrong location of etm4_release_trace_id.
- https://lore.kernel.org/all/20260413142003.3549310-1-yeoreum.yun@arm.com/
from v3 to v4:
- change etm_drvdata->spinlock type to raw_spin_lock_t
- remove redundant call etmX_enable_hw() with starting_cpu() callsback.
- fix missing trace id release.
- add missing docs.
- https://lore.kernel.org/all/20260412175506.412301-1-yeoreum.yun@arm.com/
from v2 to v3:
- fix build error for etm3x.
- fix checkpatch warning.
- https://lore.kernel.org/all/20260410074310.2693385-1-yeoreum.yun@arm.com/
from v1 to v2
- rebased to v7.0-rc7.
- introduce etmX_caps structure to save etmX's capabilities.
- remove ss_status from etmv4_config.
- modify active_config after taking a mode (perf/sysfs).
- https://lore.kernel.org/all/20260317181705.2456271-1-yeoreum.yun@arm.com/
---
Yeoreum Yun (8):
coresight: etm4x: fix inconsistencies with sysfs configuration
coresight: etm3x: fix inconsistencies with sysfs configuration
coresight: etm3x: change drvdata->spinlock type to raw_spin_lock_t
coresight: etm3x: remove redundant cpu online check on etm_enable_sysfs()
coresight: etm4x: introduce struct etm4_caps
coresight: etm4x: exclude ss_status from drvdata->config
coresight: etm4x: remove s_ex_level from config
coresight: etm3x: introduce struct etm_caps
drivers/hwtracing/coresight/coresight-config.c | 18 +-
drivers/hwtracing/coresight/coresight-config.h | 22 ++
drivers/hwtracing/coresight/coresight-etm.h | 48 ++-
drivers/hwtracing/coresight/coresight-etm3x-core.c | 96 ++---
.../hwtracing/coresight/coresight-etm3x-sysfs.c | 155 ++++----
drivers/hwtracing/coresight/coresight-etm4x-cfg.c | 14 +-
drivers/hwtracing/coresight/coresight-etm4x-core.c | 413 +++++++++++----------
.../hwtracing/coresight/coresight-etm4x-sysfs.c | 204 +++++-----
drivers/hwtracing/coresight/coresight-etm4x.h | 196 +++++-----
9 files changed, 645 insertions(+), 521 deletions(-)
---
base-commit: 9e3604d7369cfc0110100eb1a0acab1865ee2d18
change-id: 20260911-separate_etm_cfg_v2-3518a168cbff
Best regards,
--
Sincerely,
Yeoreum Yun
On Wed, Sep 16, 2026 at 11:04:20AM +0800, Jie Gan wrote:
[...]
> > From: Min Chen <min.chen(a)siengine.com>
> >
> > The flat ETR buffer comes from dma_alloc_noncoherent(), which zeroes it
> > with CPU stores. The DMA API requires the caller to sync the buffer for
> > the device before the device writes into it, but the TMC driver only
> > ever syncs for the CPU afterwards. On a non-coherent sink the zero fill
> > is therefore still dirty in cache when the ETR starts writing, and its
> > write-back lands on top of the trace data.
Good catch! I'm curious how you observed the dirty cache lines
overwriting trace data in DDR and causing corruption.
> Agree, without the sync, the dirty data may overwrites the trace data.
> > Add a sync_for_device() buffer operation and call it from
> > __tmc_etr_enable_hw() just before the TMC is enabled.
I don't think __tmc_etr_enable_hw() is the best place for the sync, as
it can be called frequently when an event is enabled, e.g. when a task
is scheduled in or migrated between CPUs. We should be able to sync
once after dma_alloc_noncoherent() instead.
The issue is not limited to buffer init. The driver also injects barrier
packets into the bounce buffer, which can race with the sink. Even
worse, the barrier packet write may collide with trace data when they
share a cache line.
I think we should consider writing barrier packets directly into the
AUX buffer. This would avoid stale cache data from barrier packet writes
and simplify the flow without additional sync operations.
Would you mind if I pick up this patch (keeping you as the author) and
add a second patch to address the barrier packet issue? That part may
need some several rounds refactoring so can have better shape, I think
it would be easier to consolidate the fixes on my side.
Thanks,
Leo
P.s. Please CC me on future CoreSight patches. If you're using the
mainline ./scripts/get_maintainer.pl, it should add me automatically.
I didn't receive this patch directly, which is why I'm replying to
Jie's email (also thanks Jie's review).
This series adds AUX sampling support to Arm CoreSight. A PMU sample can
carry a window of recent AUX trace, which perf generates callchain and
branch stack for the sampled thread. This provides execution history for
context-based profiling.
The series can be divided into four parts:
1. Patches 01 ~ 03 for event core:
The perf event core changes warn on non-positive AUX snapshot
returns before checking alignment padding. Space for a non-zero AUX
payload has already been reserved, so a zero return leaves that
payload unwritten. CoreSight fills unavailable trace with zeros and
returns the requested size.
It also prevents AUX sampling and pause/resume from nesting through
an NMI. A driver guard alone can leave perf's pause state
(aux_paused) inconsistent with the hardware state. The event core
ensures only one AUX callback is exclusively invoked.
Export the output copy helpers so CoreSight can fill sample payloads
when the driver is built as a module.
2. Patches 04 ~ 09 for ETM perf:
The ETM perf changes separate the lifetime of the published CoreSight
context from that of the AUX output handle.
Centralize buffer updates, and end AUX output when throttling stops
an event without PERF_EF_UPDATE so a later restart can acquire a
fresh handle.
Make hardware-state transitions reflect completed operations.
3. Patches 10 ~ 13 for TRBE driver:
TRBE snapshot buffers need padding to meet the CPU's alignment and
wrap constraints. Use circular buffer mode for overwrite snapshots,
retaining Fill mode on CPUs that require the write out-of-range
workaround.
TRBE faults can still raise interrupts in circular mode. Track when
the sink is handling an interrupt so an AUX sampling NMI can skip a
snapshot while the interrupted handler is updating the buffer. Make
repeated sink disable safe for deferred cleanup after a snapshot
failure.
4. Patches 14 ~ 25 for AUX sampling and decoding:
Shared atomic STOP and AUX action bits prevent an NMI stop from
tearing down the context while pause, resume or snapshot accesses it.
The AUX operation finishes and then completes the deferred stop,
publishing the stopped state only after hardware teardown.
Add snapshot_aux() to the CoreSight driver to pause the source, update
the sink buffer, disable the path, copy the recent trace into the PMU
sample, and then re-enable the path and resume the source.
Patch 17 fixes history collection for zero-IP PMU samples. Perf clears
the IP when a user-only sampling interrupt skids into the kernel, but
the timestamp and TID remain valid for matching the trace history.
In perf, decode each embedded payload as an independent trace window,
selecting the decoder with the sampled CPU and using the sample's
PID/TID and traced context IDs to attribute history to the sampled
thread. Refactor common timeless decoding and history collection, and
drain pending OpenCSD output so buffered history is not lost.
Attach reconstructed callchains and branch stacks to the original PMU
samples, preserving histories already present in the samples. Add a
test, and document the recording and decoding workflow and its
limitations.
The initial support targets unformatted trace from per-CPU sinks such as
TRBE. Shared formatted sinks such as ETR can mix trace from multiple CPUs,
consuming the limited sample window with execution unrelated to the
sampled thread.
This series is based on Amir's series "perf: Add CoreSight branch
history to existing samples" [1] for perf tool's branch / callchain
generating.
[1] https://lore.kernel.org/linux-perf-users/cover.1787005265.git.aaupov@fb.com/
Signed-off-by: Leo Yan <leo.yan(a)arm.com>
---
Leo Yan (25):
perf/core: Reject non-positive AUX snapshot sizes
perf/core: Prevent AUX sampling from racing with pause/resume
perf/core: Export output copy helpers for CoreSight
coresight: perf: End AUX output when an event is throttled
coresight: perf: Extract AUX buffer update helper
coresight: perf: Simplify flow for CPUs without a path
coresight: perf: Validate the live context through its path
coresight: perf: Validate context before resuming trace
coresight: perf: Improve hardware state transitions
coresight: trbe: Pad snapshot buffers
coresight: trbe: Use circular buffer mode for snapshots
coresight: trbe: Track per-CPU sink interrupt handling
coresight: trbe: Handle an already disabled sink
coresight: perf: Look up the trace path in etm_event_pause()
coresight: perf: Serialize AUX pause and resume with event stops
coresight: perf: Support AUX sampling with per-CPU sinks
perf cs-etm: Allow history collection for samples with zero IP
perf cs-etm: Unify timeless buffer decoding
perf cs-etm: Propagate errors from trace queue flushing
perf cs-etm: Drain pending packets before finishing trace blocks
perf cs-etm: Complete packet draining with end of trace
perf cs-etm: Centralize sample history collection
perf cs-etm: Decode AUX samples into callchains and branch stacks
perf test: Add CoreSight AUX sample decoding test
Documentation: coresight: Document AUX sample decoding
Documentation/trace/coresight/coresight-perf.rst | 39 ++
drivers/hwtracing/coresight/coresight-etm-perf.c | 396 +++++++++++++-----
drivers/hwtracing/coresight/coresight-etm-perf.h | 2 +
drivers/hwtracing/coresight/coresight-trbe.c | 122 ++++--
include/linux/coresight.h | 2 +
kernel/events/core.c | 26 +-
kernel/events/ring_buffer.c | 2 +
tools/perf/arch/arm/util/cs-etm.c | 6 +
tools/perf/tests/shell/coresight/aux_sample.sh | 189 +++++++++
tools/perf/util/cs-etm-decoder/cs-etm-decoder.c | 39 ++
tools/perf/util/cs-etm-decoder/cs-etm-decoder.h | 7 +
tools/perf/util/cs-etm.c | 491 ++++++++++++++++-------
12 files changed, 1040 insertions(+), 281 deletions(-)
---
base-commit: 134e1295eedfc9a3c6e4e63d8ef45dc63749449b
change-id: 20260826-arm_cs_support_aux_sample-275664545588
Best regards,
--
Leo Yan <leo.yan(a)arm.com>