Re: [PATCH v4 2/7] arm64: KVM: Use shared area to pass PMU event state to hypervisor

From: Marc Zyngier
Date: Mon Feb 05 2024 - 08:21:24 EST


On Mon, 05 Feb 2024 13:04:51 +0000,
Oliver Upton <oliver.upton@xxxxxxxxx> wrote:
>
> Unless someone has strong opinions about making this work in protected
> mode, I am happy to see tracing support limited to the 'normal' nVHE
> configuration. The protected feature as a whole is just baggage until
> upstream support is completed.

Limiting tracing to non-protected mode is a must IMO. Allowing tracing
when pKVM is enabled is a sure way to expose secrets that should
stay... secret. The only exception I can think of is when
CONFIG_NVHE_EL2_DEBUG is enabled, at which point all bets are off.

Thanks,

M.

--
Without deviation from the norm, progress is not possible.