This series documents optional atclk for static CoreSight links and
removes unused clock references from several device trees. It also
describes the programmable Zynq-7000 funnel as dynamic.
Signed-off-by: Leo Yan <leo.yan(a)arm.com>
---
Leo Yan (5):
dt-bindings: arm: coresight: Limit static replicator to atclk
dt-bindings: arm: coresight: Allow atclk for static funnel
arm64: dts: hisilicon: Drop PCLK from static CoreSight links
ARM: dts: zynq: Use dynamic CoreSight funnel and trim clocks
ARM: dts: qcom: apq8064: Drop PCLK from static replicator
.../bindings/arm/arm,coresight-static-funnel.yaml | 6 ++++++
.../arm/arm,coresight-static-replicator.yaml | 11 ++--------
arch/arm/boot/dts/qcom/qcom-apq8064.dtsi | 3 ---
arch/arm/boot/dts/xilinx/zynq-7000.dtsi | 24 ++++++++++------------
.../arm64/boot/dts/hisilicon/hi3660-coresight.dtsi | 4 ----
.../arm64/boot/dts/hisilicon/hi6220-coresight.dtsi | 2 --
6 files changed, 19 insertions(+), 31 deletions(-)
---
base-commit: 551c722f40809618230001baccf219193e22fc5a
change-id: 20261001-arm_coresight_hi3660_remove_dynamic_funnel_clocks-d277556abe8d
Best regards,
--
Leo Yan <leo.yan(a)arm.com>
The driver might not always be able to write HW_IDs, but we don't need
them for unformatted mode anyway, so fix that in commit ("perf cs-etm:
Synthesize missing HW_ID mappings for raw trace").
Include some other minor improvements encountered on the way to appease
Sashiko, like properly freeing queues and ("perf: cs-etm: Respect
--no-itrace option") makes debugging broken Coresight perf.data files
easier.
Signed-off-by: James Clark <james.clark(a)linaro.org>
---
Changes in v2:
- Drop driver changes and move to https://lore.kernel.org/linux-perf-users/20261001-james-cs-retry-hw_id-v1-0…
- Don't process any HW_IDs for unformatted queues, just create decoders
unconditionally with trace ID 1.
- Use zfree() instead of etmq->decoder = NULL
- Remove dependency on "[PATCH v2 00/14] perf cs-etm: Per-thread mode
fixes and snapshot wrap support", it wasn't functionally dependant,
just touching some of the same lines.
- Link to v1: https://patch.msgid.link/20260821-james-cs-hw_id-output-failure-v1-0-9d532d…
---
James Clark (3):
perf: cs-etm: Don't add global v0 HW_IDs to unformatted queues
perf cs-etm: Free partially created queues
perf: cs-etm: Respect --no-itrace option
Leo Yan (1):
perf cs-etm: Synthesize missing HW_ID mappings for raw trace
tools/perf/util/auxtrace.c | 2 +-
tools/perf/util/auxtrace.h | 1 +
tools/perf/util/cs-etm-decoder/cs-etm-decoder.c | 12 +-
tools/perf/util/cs-etm-decoder/cs-etm-decoder.h | 2 +-
tools/perf/util/cs-etm.c | 184 +++++++++++++++---------
5 files changed, 123 insertions(+), 78 deletions(-)
---
base-commit: 78148c85297024ffe7a709acb7cc4fc907271176
change-id: 20260706-james-cs-hw_id-output-failure-1d06d042ef96
prerequisite-change-id: 20260605-james-cs-unformatted-per-thread-fix-50e723aa7f0e:v2
prerequisite-patch-id: 1aa32269a3a7dc76840dd8a24cb5a8715507e898
prerequisite-patch-id: ef471f468351462f67efa58a09a3461306ac5a0a
prerequisite-patch-id: c78946cf4ec1c7722570865403a3562625bdaa33
prerequisite-patch-id: 0b953eee0252db3c7ba3ef1e3397048a94482ca2
prerequisite-patch-id: 27da72c2f01bcc68205bbcc14d5019369c02cb83
prerequisite-patch-id: 365c6d5f71c754e4c690b5ebed3453565bb5b809
prerequisite-patch-id: 64e9419a41082a2db3daf255baf0fb40efbae5dd
prerequisite-patch-id: 1dc2e6ef8e76b369736b4c88560302861b2e4faf
prerequisite-patch-id: b7de38ec4d90f5b45d56390a4e5919a1d6439951
prerequisite-patch-id: 3548d5b161cfb8c11a166ca2b3228ca4821f1ca0
prerequisite-patch-id: 97e66600218a2b32e5b21d0abcb6321590f98de9
prerequisite-patch-id: 292282b20bd8ad7d096ee7ffbc55dcfb75455f53
prerequisite-patch-id: c80259b47850ba65c985c85a29c8cf4948463d59
Best regards,
--
James Clark <james.clark(a)linaro.org>
On Thu, Oct 01, 2026 at 07:04:44AM -0500, Rob Herring wrote:
[...]
> > The question is that a static funnel does not need to program any
> > registers, so in theory it should only need atclk as the module's core
> > clock, but not the APB programming clock (apb_pclk).
> >
> > Maybe I did not get this right when I initially enabled the static
> > funnel in hi3660-coresight.dtsi. We should probably remove pclk from the
> > static funnel node.
>
> Yes. I suppose in theory it has some clock, but if pclk needed to be
> enabled, it is shared with all the other coresight components and
> enabled anyways. And there's no atclk defined, so 'clocks' can just
> be removed. Can you send a patch to do that, and I'll drop this one.
Sure, I will prepare a patch for hi3660-coresight.dtsi.
> zynq7000 is even more of a mess I just noticed...
Agreed. It should bind to "arm,coresight-dynamic-funnel" instead.
However, I'm afraid the "dbg_trc" and "dbg_apb" clocks are never touched
by either the CoreSight driver or the AMBA driver after switching to the
dynamic funnel. These clocks should therefore be removed from all
CoreSight nodes.
Thanks,
Leo
The driver might not always be able to write HW_IDs, but we don't need
them for unformatted mode anyway, so fix that in commit ("perf cs-etm:
Synthesize missing HW_ID mappings for raw trace").
At the same time, give the driver another chance to send them in commit
("coresight: perf: Retry failed HW_ID writes"). The other commits are
semi-related improvements and fixes.
("perf: cs-etm: Respect --no-itrace option") makes debugging broken
Coresight perf.data files easier.
Applies on top of "[PATCH v2 00/14] perf cs-etm: Per-thread mode fixes
and snapshot wrap support"
Signed-off-by: James Clark <james.clark(a)linaro.org>
---
James Clark (5):
perf: cs-etm: Don't add global v0 HW_IDs to unformatted queues
perf cs-etm: Free partially created queues
perf: cs-etm: Respect --no-itrace option
perf/core: Return errors from perf_report_aux_output_id()
coresight: perf: Retry failed HW_ID writes
Leo Yan (1):
perf cs-etm: Synthesize missing HW_ID mappings for raw trace
drivers/hwtracing/coresight/coresight-etm-perf.c | 52 +++++----
include/linux/perf_event.h | 2 +-
kernel/events/core.c | 6 +-
tools/perf/util/auxtrace.c | 2 +-
tools/perf/util/auxtrace.h | 1 +
tools/perf/util/cs-etm.c | 143 ++++++++++++++++-------
6 files changed, 139 insertions(+), 67 deletions(-)
---
base-commit: 78148c85297024ffe7a709acb7cc4fc907271176
change-id: 20260706-james-cs-hw_id-output-failure-1d06d042ef96
prerequisite-change-id: 20260605-james-cs-unformatted-per-thread-fix-50e723aa7f0e:v2
prerequisite-patch-id: 1aa32269a3a7dc76840dd8a24cb5a8715507e898
prerequisite-patch-id: ef471f468351462f67efa58a09a3461306ac5a0a
prerequisite-patch-id: c78946cf4ec1c7722570865403a3562625bdaa33
prerequisite-patch-id: 0b953eee0252db3c7ba3ef1e3397048a94482ca2
prerequisite-patch-id: 27da72c2f01bcc68205bbcc14d5019369c02cb83
prerequisite-patch-id: 365c6d5f71c754e4c690b5ebed3453565bb5b809
prerequisite-patch-id: 64e9419a41082a2db3daf255baf0fb40efbae5dd
prerequisite-patch-id: 1dc2e6ef8e76b369736b4c88560302861b2e4faf
prerequisite-patch-id: b7de38ec4d90f5b45d56390a4e5919a1d6439951
prerequisite-patch-id: 3548d5b161cfb8c11a166ca2b3228ca4821f1ca0
prerequisite-patch-id: 97e66600218a2b32e5b21d0abcb6321590f98de9
prerequisite-patch-id: 292282b20bd8ad7d096ee7ffbc55dcfb75455f53
prerequisite-patch-id: c80259b47850ba65c985c85a29c8cf4948463d59
Best regards,
--
James Clark <james.clark(a)linaro.org>
Hi Rob,
On Mon, Sep 21, 2026 at 06:28:33PM -0500, Rob Herring (Arm) wrote:
> Some static funnel nodes have APB and AT clocks. Allow one or two
> clocks and the apb_pclk and atclk clock-names entries.
>
> Assisted-by: LLM
> Signed-off-by: Rob Herring (Arm) <robh(a)kernel.org>
>
> ---
> .../bindings/arm/arm,coresight-static-funnel.yaml | 10 ++++++++++
> 1 file changed, 10 insertions(+)
>
> diff --git a/Documentation/devicetree/bindings/arm/arm,coresight-static-funnel.yaml b/Documentation/devicetree/bindings/arm/arm,coresight-static-funnel.yaml
> index 9598a3d0a95b..4a3d08f9568c 100644
> --- a/Documentation/devicetree/bindings/arm/arm,coresight-static-funnel.yaml
> +++ b/Documentation/devicetree/bindings/arm/arm,coresight-static-funnel.yaml
> @@ -30,6 +30,16 @@ properties:
> power-domains:
> maxItems: 1
>
> + clocks:
> + minItems: 1
> + maxItems: 2
> +
> + clock-names:
> + minItems: 1
> + items:
> + - const: apb_pclk
> + - const: atclk
The question is that a static funnel does not need to program any
registers, so in theory it should only need atclk as the module's core
clock, but not the APB programming clock (apb_pclk).
Maybe I did not get this right when I initially enabled the static
funnel in hi3660-coresight.dtsi. We should probably remove pclk from the
static funnel node.
clocks:
minItems: 0
maxItems: 1
clock-names:
minItems: 0
items:
- const: atclk
Thanks,
Leo
Hi Will,
On Mon, Aug 10, 2026 at 04:10:48PM +0100, Will Deacon wrote:
> On Mon, Aug 10, 2026 at 03:44:42PM +0100, Leo Yan wrote:
> > Commit 18049c8cff9c ("perf/aux: Allocate non-contiguous AUX pages by
> > default") made the AUX allocator use order-0 pages by default unless a
> > PMU explicitly asks for contiguous allocations.
>
> But that commit specifically calls out SPE as benefitting from
> non-contiguous pages:
>
> "For instance, ARM SPE and TRBE operate with virtual pages, and
> Coresight ETR allocates a separate buffer. For these PMUs,
> allocating contiguous AUX pages unnecessarily exacerbates memory
> fragmentation. This fragmentation can prevent their use on
> long-running devices."
>
> so why doesn't passing PERF_PMU_CAP_AUX_PREFER_LARGE reintroduce the
> problems that 18049c8cff9c was trying to solve?
How about adding a field to struct pmu to specify a preferred maximum
page order for the AUX buffer? The perf core could try that order first
and fall back to smaller orders if the allocation fails.
For example, the Neoverse V2 TRM documents:
L1 Trace Buffer Extension (TRBE) TLB: 1 entry
Given the single L1 TRBE TLB entry, the TRBE driver could prefer
PMD_ORDER (2 MiB with 4 KiB pages) to reduce TLB pressure. This reflects
the hardware characteristic.
This could be a trade-off instead of using PERF_PMU_CAP_AUX_PREFER_LARGE,
avoiding large contiguous allocations that could reintroduce the Android
OOM issue. I did a quick test with this approach and the results look
positive.
Does this sound like a reasonable direction? I might also need Yabin's
judgement from Android side.
Thanks,
Leo
CoreSight currently models exception entry by changing the preceding
instruction range into a taken branch. This can give an IRQ the source
PC of an instruction that already retired and overwrite a real branch
immediately before the exception.
For an untaken B.LS followed by an IRQ, perf script currently reports:
hw int 4000f8 => ffff800080010c80 b.ls #0x400118
...
iret ffff800080012284 => 4000fc eret
The hardware trace supplies 0x4000fc as the preferred return address.
For an IRQ, this is the architectural resume PC (Arm ARM, R_VBQMV).
B.LS has retired, and the saved PC identifies the boundary before the
following MOV. Using this PC as the IRQ source reflects the
architectural state at exception entry:
hw int 4000fc => ffff800080010c80 movz x2, #0x1796
...
iret ffff800080012284 => 4000fc eret
The IRQ sample represents the transfer from this architectural execution
position to the handler. The series synthesizes exception entries from
exception packets, preserving the preceding branch and its outcome.
The supporting changes:
- Let decoders supply sample.ret_addr so later instruction fetching cannot
change thread-stack return addresses. Apply this to Intel PT
asynchronous samples as well.
- Prepare packet ISA and instruction-size handling and share sample
synthesis helpers. Mark untaken branches and break history when
instruction memory is unavailable.
- Add a thread-stack regression test and four AArch64 CoreSight tests.
IRQs and page faults must resume at the entry PC; SVC and emulated MRS
must resume four bytes later.
Based on the AI search and test on my x86 machine, this matches perf's
Intel PT handling of IRQs. Intel PT records the next instruction's IP in
the FUP packet, and Perf uses that IP as the interrupt sample's source.
This series is verified on Orion6 board with "perf test coresight".
Signed-off-by: Leo Yan <leo.yan(a)arm.com>
---
Changes in v2:
- Rework the fix around exception packets to preserve both exception
entries and preceding branches.
- Add explicit return addresses and the Intel PT asynchronous-branch fix.
- Split out packet/synthesis preparation, record not-taken branches and
handle unreadable instruction memory.
- Add thread-stack regression coverage and four CoreSight tests.
- Link to v1: https://lore.kernel.org/r/20260713-perf_cs_etm_fix_non_taken-v1-0-4561607fc…
---
Leo Yan (14):
perf sample: Allow decoders to supply branch return addresses
perf intel-pt: Preserve return addresses for asynchronous branches
perf cs-etm: Break branch history when instruction memory is unavailable
perf cs-etm: Centralize packet ISA initialization
perf cs-etm: Use the recorded instruction size for A32 and A64
perf cs-etm: Mark branches that were not taken
perf cs-etm: Factor out final instruction sample synthesis
perf cs-etm: Centralize branch sample synthesis checks
perf cs-etm: Classify exception calls using the exception packet
perf cs-etm: Synthesize exception entries separately from branches
perf tests: Check CoreSight IRQ entry and exit
perf tests: Check CoreSight syscall entry and exit
perf tests: Check CoreSight abort entry and exit
perf tests: Check CoreSight emulated instruction entry and exit
tools/perf/tests/Build | 1 +
tools/perf/tests/builtin-test.c | 3 +
.../perf/tests/shell/coresight/abort_entry_exit.sh | 21 ++
tools/perf/tests/shell/coresight/irq_entry_exit.sh | 37 ++++
.../tests/shell/coresight/syscall_entry_exit.sh | 21 ++
.../perf/tests/shell/coresight/trap_entry_exit.sh | 24 +++
tools/perf/tests/shell/lib/coresight_exception.sh | 165 +++++++++++++++
tools/perf/tests/tests.h | 3 +
tools/perf/tests/thread-stack.c | 106 ++++++++++
tools/perf/tests/workloads/Build | 4 +
tools/perf/tests/workloads/branch_not_taken_loop.c | 33 +++
tools/perf/tests/workloads/page_fault_loop.c | 37 ++++
tools/perf/util/cs-etm-decoder/cs-etm-decoder.c | 106 +++++++---
tools/perf/util/cs-etm.c | 222 ++++++++++-----------
tools/perf/util/cs-etm.h | 2 +
tools/perf/util/intel-pt.c | 7 +
tools/perf/util/sample.c | 1 +
tools/perf/util/sample.h | 5 +
tools/perf/util/thread-stack.c | 5 +-
19 files changed, 656 insertions(+), 147 deletions(-)
---
base-commit: edd8a9fe2eca009599e013a29c421c7a6b5ad1b9
change-id: 20260713-perf_cs_etm_fix_non_taken-5b4d7f73f41e
Best regards,
--
Leo Yan <leo.yan(a)arm.com>
Reviewed-by: Mike Leach <mike.leach(a)arm.com>
On 9/28/26 13:35, Yingchao Deng wrote:
> If cscfg_configfs_init() fails, cscfg_init() takes the exit_err path:
>
> cscfg_init() -> cscfg_clear_device() -> cscfg_configfs_release()
> -> configfs_unregister_subsystem()
>
> which tears down a configfs subsystem that was never registered.
> configfs_unregister_subsystem() begins with:
>
> struct dentry *dentry = dget(group->cg_item.ci_dentry);
> struct dentry *root = dentry->d_sb->s_root;
>
> ci_dentry is assigned in configfs_create_dir() only once the subsystem
> directory has been created, which never happened here. cscfg_mgr
> comes from kzalloc_obj(), so ci_dentry is still NULL, and dget()
> hands a NULL dentry back unchanged - the next line dereferences it.
>
> Handle the failure in cscfg_init() directly: unregister the device and
> return the error, releasing the devres-allocated config item type and
> cscfg_mgr without touching the subsystem.
>
> Fixes: a13d5a246aca ("coresight: syscfg: Add initial configfs support")
> Suggested-by: Leo Yan <leo.yan(a)arm.com>
> Link: https://lore.kernel.org/all/20260924162404.GN200420@e132581.arm.com/
> Signed-off-by: Yingchao Deng <dengyingchao(a)kylinsec.com.cn>
> ---
> drivers/hwtracing/coresight/coresight-syscfg.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/hwtracing/coresight/coresight-syscfg.c b/drivers/hwtracing/coresight/coresight-syscfg.c
> index 2bfdd7b45e49..00b29d1656c0 100644
> --- a/drivers/hwtracing/coresight/coresight-syscfg.c
> +++ b/drivers/hwtracing/coresight/coresight-syscfg.c
> @@ -1299,8 +1299,10 @@ int __init cscfg_init(void)
>
> /* initialise configfs subsystem */
> err = cscfg_configfs_init(cscfg_mgr);
> - if (err)
> - goto exit_err;
> + if (err) {
> + device_unregister(cscfg_device());
> + return err;
> + }
>
> /* preload built-in configurations */
> err = cscfg_preload(THIS_MODULE);
The current ETMx configuration via sysfs can lead to the following
inconsistencies:
- If a configuration is modified via sysfs while a perf session is
active, the running configuration may differ between before
a sched-out and after a subsequent sched-in.
- If a perf session and sysfs session tries to enable concurrently,
configuration from configfs could be corrupted (etm4).
- There is chance to corrupt drvdata->config if perf session tries
to enabled among handling cscfg_csdev_disable_active_config()
in etm4_disable_sysfs() (etm4).
To resolve these inconsistencies, the configuration should be separated into:
- curr_config, which is applied configuration for the current session
- config, which stores the settings configured via sysfs.
and apply configuration from configfs after taking a mode.
Patch History
=============
from v11 to v12:
- rename active_config to curr_config.
- rename config to sysfs_config.
- remove redundant config argument in etmX_args.
- add read-back and copy from curr_config to sysfs_config TRCSEQSTR
(seq_state).
- add r-b and t-b tags.
- Link to v11: https://lore.kernel.org/r/20260915-separate_etm_cfg_v2-v11-0-d2b258d51747@a…
from v10 to v11:
- replace direct register read from etm3 sysfs with IPI.
- fix issue cntr_val and others field which required to be shown after
sysfs session disable.
- prohibit the write for some etm3 sysfs while sysfs session is
enabled.
- drop locktype change in etm3
- Link to v10: https://lore.kernel.org/r/20260911-separate_etm_cfg_v2-v10-0-1b715d95927a@a…
from v9 to v10:
- rebase to coresight/next
- https://lore.kernel.org/all/20260725113645.57519-1-yeoreum.yun@arm.com/
from v8 to v9:
- add feat_csdev_lock guard interface.
- set feat_csdev->drv_spinlock as NULL for etmv4_drvdata.
- https://lore.kernel.org/all/20260629090007.1718746-1-yeoreum.yun@arm.com/
from v7 to v8:
- accept @Leo Yan' suggestion to handle error.
- small minor fixes following @Suzuki' suggestion.
- https://lore.kernel.org/all/20260519154812.254884-1-yeoreum.yun@arm.com/
from v6 to v7:
- rebase on coresight/next
- add ETM_MAX_SEQ_TRANSITIONS define
- remove redundant patch relavent cpu-hotplug as coresight-pm patch
merged.
- https://lore.kernel.org/all/20260422132203.977549-1-yeoreum.yun@arm.com/
from v5 to v6:
- fix missing of calling cscfg_csdev_disable_active_config()
- add rb & fixes tags.
- add ss_status field in etm4x_drvdata to expose STATUS and PENDING bits.
- https://lore.kernel.org/all/20260415165528.3369607-1-yeoreum.yun@arm.com/
from v4 to v5:
- add rb-tag.
- fix underflow issue for nrseqstate.
- fix wrong check in etm4_sspcicrn_present().
- remove redundant fields on etmv4_save_state.
- rename caps->ss_status to ss_cmp.
- fix wrong location of etm4_release_trace_id.
- https://lore.kernel.org/all/20260413142003.3549310-1-yeoreum.yun@arm.com/
from v3 to v4:
- change etm_drvdata->spinlock type to raw_spin_lock_t
- remove redundant call etmX_enable_hw() with starting_cpu() callsback.
- fix missing trace id release.
- add missing docs.
- https://lore.kernel.org/all/20260412175506.412301-1-yeoreum.yun@arm.com/
from v2 to v3:
- fix build error for etm3x.
- fix checkpatch warning.
- https://lore.kernel.org/all/20260410074310.2693385-1-yeoreum.yun@arm.com/
from v1 to v2
- rebased to v7.0-rc7.
- introduce etmX_caps structure to save etmX's capabilities.
- remove ss_status from etmv4_config.
- modify active_config after taking a mode (perf/sysfs).
- https://lore.kernel.org/all/20260317181705.2456271-1-yeoreum.yun@arm.com/
---
Yeoreum Yun (14):
coresight: etm4x: read-back TRCSEQSTR at disabling and prohibit modifying seq_state while enabling.
coresight: etm4x: prohibit modifying cntr_val while session is enabled
coresight: etm3x: prohibit modifying cntr_val and reset while session is enabled
coresight: etm4x: fix inconsistencies with sysfs configuration
coresight: etm3x: fix inconsistencies with sysfs configuration
coresight: etm3x: remove redundant cpu online check on etm_enable_sysfs()
coresight: etm4x: introduce struct etm4_caps
coresight: etm4x: exclude ss_status from drvdata->config
coresight: etm4x: remove s_ex_level from config
coresight: etm4x: rename local config as curr_config referring drvdata->curr_config
coresight: etm4x: rename drvdata->config to sysfs_config
coresight: etm3x: introduce struct etm_caps
coresight: etm3x: rename local config as curr_config referring drvdata->curr_config
coresight: etm3x: rename drvdata->config to sysfs_config
drivers/hwtracing/coresight/coresight-config.c | 18 +-
drivers/hwtracing/coresight/coresight-config.h | 22 +
drivers/hwtracing/coresight/coresight-etm.h | 48 +-
drivers/hwtracing/coresight/coresight-etm3x-core.c | 196 +++--
.../hwtracing/coresight/coresight-etm3x-sysfs.c | 461 +++++-----
drivers/hwtracing/coresight/coresight-etm4x-cfg.c | 14 +-
drivers/hwtracing/coresight/coresight-etm4x-core.c | 567 ++++++------
.../hwtracing/coresight/coresight-etm4x-sysfs.c | 961 +++++++++++----------
drivers/hwtracing/coresight/coresight-etm4x.h | 199 +++--
9 files changed, 1340 insertions(+), 1146 deletions(-)
---
base-commit: 9e3604d7369cfc0110100eb1a0acab1865ee2d18
change-id: 20260911-separate_etm_cfg_v2-3518a168cbff
Best regards,
--
Sincerely,
Yeoreum Yun