From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-9.8 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH, MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6912EC433DF for ; Thu, 15 Oct 2020 16:04:38 +0000 (UTC) Received: from merlin.infradead.org (merlin.infradead.org [205.233.59.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id D588221D7F for ; Thu, 15 Oct 2020 16:04:37 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="1qv8OIuA"; dkim=fail reason="signature verification failed" (2048-bit key) header.d=linaro.org header.i=@linaro.org header.b="WMP4y67p" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org D588221D7F Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=linaro.org Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=merlin.20170209; h=Sender:Content-Transfer-Encoding: Content-Type:Cc:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References:Message-ID: Subject:To:From:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=tTVcuIKLLoagOyZRg8TBKpLy9PJRqQOwTotAOMFeOlA=; b=1qv8OIuAKA1TessXrV73FXsFu rqvvRT0yIwo5/1uxHsoE39qELDJGo8gQnvHL3+QHRXz8yiM0oeMdZRSLCY5xr2jmmp5J9zgh64Gzv qQYDyEuTPzabr1RXdh5zjHFbSpS4kBx8UH7RaM7BUoW5FwAkgJ7rPME0eVPrnOgibZZrZIHW05nHY dmM013qGM9dw9/TiNJaueVPKU+iz351mRLKTjSoYn+gSuKa9OsbzLYmJj+oC2KQOIDJ5V3X4LIfYp nvu6742m4SrfIIa/7q32YJiKOy53wPEPB/gaOotLpukBEhdBK88iRDlsQcJiOWZsPDXsn/pbdVFnn syw68j/CQ==; Received: from localhost ([::1] helo=merlin.infradead.org) by merlin.infradead.org with esmtp (Exim 4.92.3 #3 (Red Hat Linux)) id 1kT5ic-0006zi-TN; Thu, 15 Oct 2020 16:03:07 +0000 Received: from mail-pl1-x643.google.com ([2607:f8b0:4864:20::643]) by merlin.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1kT5iZ-0006yT-5m for linux-arm-kernel@lists.infradead.org; Thu, 15 Oct 2020 16:03:04 +0000 Received: by mail-pl1-x643.google.com with SMTP id o9so1842067plx.10 for ; Thu, 15 Oct 2020 09:03:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=Iv2OYAnv0SA23u+SDCrJEFVeIFrM8td2tmeExloIU5M=; b=WMP4y67p7K2jBWI8kiEW/1mYKERGeEA8o4azow+B1ckeg5kmfX0f0KUshy0CIDEzvZ ECOITkGCaMHeGCe1f8GRrsbhbRh7kEUWzQYYS2HfyontUnA8rPrUcVddem9BHoofetTR JDACBNsZUzKEhdFB28TxjiHCL4s0UfHm2lJi/2zD3rYVujTQVpmh8txHyXUM3L/J6ATh ZttJ68BfA/++TMOSM5r6ruoOqSiIF4DgLbuOQjfg1SF1mO87JGQJP2mjPJV57v0bKpoS tjeejwK48/Ix3bnLBLsGi04q6grhk850aFoW1h1bIOvdChjissWnNXgzk7Wdq4CpnzHZ hMWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=Iv2OYAnv0SA23u+SDCrJEFVeIFrM8td2tmeExloIU5M=; b=toSBzoChHUnUoPd1NtbwQUQp8mVQcduDtpiKaROryDUuvH4E3Wquk7BrSs1HoW6dJA MD7p9ioiefy15I/giWhGZitXCEGGsYByuI4UjU2fGzdYqthlN4LApVJpyGjMS9mYBu9o ruwWNiZ815ghFaWPT7dW76wi8T6VEFclEvMj/TR0+z7vziWwZkV1bhkMp1do+NO92/xN 0D4rHNcO+qhvsx8kRiJdXgH7tUe7UtrF8GwIQzxoUhW404RHCs1XPh+rDOFasogNvDZ8 v5BW+EeXnSCJh//DDAQOgFKoZiZYOCspRgPUw9TPzYjnTSuZU1qCv/5kIvI8T+4p3tvO myRQ== X-Gm-Message-State: AOAM532YiuQ4QzGE+rh2SE+fVdFVGUkdpoVe4O561+wlTLPgvsJ9UjD3 6zfDvspVHMjBSzSKdpt08Zo70g== X-Google-Smtp-Source: ABdhPJwfIKbf4iP20eUHbQ17ExMMt9lJlaF7boqyuBwhO2o5YDtjBcdTQ4yl+RKs1Dq25HBcaUH+wQ== X-Received: by 2002:a17:90a:1702:: with SMTP id z2mr5026194pjd.88.1602777780374; Thu, 15 Oct 2020 09:03:00 -0700 (PDT) Received: from xps15 (S0106002369de4dac.cg.shawcable.net. [68.147.8.254]) by smtp.gmail.com with ESMTPSA id s186sm3920831pfc.171.2020.10.15.09.02.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 15 Oct 2020 09:02:59 -0700 (PDT) Date: Thu, 15 Oct 2020 10:02:57 -0600 From: Mathieu Poirier To: Sai Prakash Ranjan Subject: Re: [PATCH] coresight: etm4x: Add config to exclude kernel mode tracing Message-ID: <20201015160257.GA1450102@xps15> References: <20201015124522.1876-1-saiprakash.ranjan@codeaurora.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20201015124522.1876-1-saiprakash.ranjan@codeaurora.org> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20201015_120303_513062_9AD03B8D X-CRM114-Status: GOOD ( 24.25 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Denis Nikitin , Suzuki K Poulose , linux-arm-msm@vger.kernel.org, coresight@lists.linaro.org, linux-kernel@vger.kernel.org, Stephen Boyd , linux-arm-kernel@lists.infradead.org, Mike Leach Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Thu, Oct 15, 2020 at 06:15:22PM +0530, Sai Prakash Ranjan wrote: > On production systems with ETMs enabled, it is preferred to > exclude kernel mode(NS EL1) tracing for security concerns and > support only userspace(NS EL0) tracing. So provide an option > via kconfig to exclude kernel mode tracing if it is required. > This config is disabled by default and would not affect the > current configuration which has both kernel and userspace > tracing enabled by default. > One requires root access (or be part of a special trace group) to be able to use the cs_etm PMU. With this kind of elevated access restricting tracing at EL1 provides little in terms of security. Thanks, Mathieu > Signed-off-by: Sai Prakash Ranjan > --- > drivers/hwtracing/coresight/Kconfig | 9 +++++++++ > drivers/hwtracing/coresight/coresight-etm4x-core.c | 6 +++++- > 2 files changed, 14 insertions(+), 1 deletion(-) > > diff --git a/drivers/hwtracing/coresight/Kconfig b/drivers/hwtracing/coresight/Kconfig > index c1198245461d..52435de8824c 100644 > --- a/drivers/hwtracing/coresight/Kconfig > +++ b/drivers/hwtracing/coresight/Kconfig > @@ -110,6 +110,15 @@ config CORESIGHT_SOURCE_ETM4X > To compile this driver as a module, choose M here: the > module will be called coresight-etm4x. > > +config CORESIGHT_ETM4X_EXCL_KERN > + bool "Coresight ETM 4.x exclude kernel mode tracing" > + depends on CORESIGHT_SOURCE_ETM4X > + help > + This will exclude kernel mode(NS EL1) tracing if enabled. This option > + will be useful to provide more flexible options on production systems > + where only userspace(NS EL0) tracing might be preferred for security > + reasons. > + > config CORESIGHT_STM > tristate "CoreSight System Trace Macrocell driver" > depends on (ARM && !(CPU_32v3 || CPU_32v4 || CPU_32v4T)) || ARM64 > diff --git a/drivers/hwtracing/coresight/coresight-etm4x-core.c b/drivers/hwtracing/coresight/coresight-etm4x-core.c > index abd706b216ac..7e5669e5cd1f 100644 > --- a/drivers/hwtracing/coresight/coresight-etm4x-core.c > +++ b/drivers/hwtracing/coresight/coresight-etm4x-core.c > @@ -832,6 +832,9 @@ static u64 etm4_get_ns_access_type(struct etmv4_config *config) > { > u64 access_type = 0; > > + if (IS_ENABLED(CONFIG_CORESIGHT_ETM4X_EXCL_KERN)) > + config->mode |= ETM_MODE_EXCL_KERN; > + > /* > * EXLEVEL_NS, bits[15:12] > * The Exception levels are: > @@ -849,7 +852,8 @@ static u64 etm4_get_ns_access_type(struct etmv4_config *config) > access_type = ETM_EXLEVEL_NS_HYP; > } > > - if (config->mode & ETM_MODE_EXCL_USER) > + if (config->mode & ETM_MODE_EXCL_USER && > + !IS_ENABLED(CONFIG_CORESIGHT_ETM4X_EXCL_KERN)) > access_type |= ETM_EXLEVEL_NS_APP; > > return access_type; > > base-commit: 3477326277451000bc667dfcc4fd0774c039184c > -- > QUALCOMM INDIA, on behalf of Qualcomm Innovation Center, Inc. is a member > of Code Aurora Forum, hosted by The Linux Foundation > _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel