Statistical Profiling Control Register (EL2)
Provides EL2 controls for Statistical Profiling.
This register is present only when FEAT_SPE is implemented. Otherwise, direct accesses to PMSCR_EL2 are UNDEFINED.
If EL2 is not implemented, this register is RES0 from EL3.
PMSCR_EL2 is a 64-bit register.
| 63 | 62 | 61 | 60 | 59 | 58 | 57 | 56 | 55 | 54 | 53 | 52 | 51 | 50 | 49 | 48 | 47 | 46 | 45 | 44 | 43 | 42 | 41 | 40 | 39 | 38 | 37 | 36 | 35 | 34 | 33 | 32 |
| 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
| RES0 | |||||||||||||||||||||||||||||||
| RES0 | EnVM | KE | EE | PCT | TS | PA | CX | RES0 | E2SPE | E0HSPE | |||||||||||||||||||||
Reserved, RES0.
Enable use of physical address Profiling Buffer pointers.
| EnVM | Meaning |
|---|---|
| 0b0 |
Use of physical address Profiling Buffer pointers is disabled. The PE behaves as if PMBLIMITR_EL1.nVM is 0. |
| 0b1 |
Use of physical address Profiling Buffer pointers is permitted. |
If EL2 is disabled in the owning Security state, or the Profiling Buffer owning Exception level is EL2, then the Effective value of this field is 1.
The reset behavior of this field is:
Reserved, RES0.
Kernel exception enable for SPE Profiling exceptions taken to EL2.
| KE | Meaning |
|---|---|
| 0b0 |
SPE Profiling exceptions taken to EL2 are always masked at EL2. |
| 0b1 |
Enabled SPE Profiling exceptions taken to EL2 are masked at EL2 when PSTATE.PM is 1 and unmasked when PSTATE.PM is 0. |
The reset behavior of this field is:
Reserved, RES0.
Exception Enable.
| EE | Meaning |
|---|---|
| 0b00 | Disabled. SPE Profiling exceptions for EL2 and EL1 are disabled. All of the following apply:
|
| 0b01 | Delegated. SPE Profiling exceptions for EL2 are disabled, but might be enabled for EL1 by PMSCR_EL1.EE. All of the following apply: |
| 0b10 | Enabled. SPE Profiling exceptions for EL2 are enabled for Profiling Buffer management events targeting EL2, as follows:
|
| 0b11 | Trap all. SPE Profiling exceptions for EL2 are enabled for all Profiling Buffer management events, as follows: |
If the Effective value of MDCR_EL3.PMSEE is 0b00, then the Effective value of PMSCR_EL2.EE is 0b00. Otherwise, if EL2 is not implemented or the Effective value of SCR_EL3.{NS, EEL2} is {0, 0}, then the Effective value of PMSCR_EL2.EE is 0b01.
The reset behavior of this field is:
Reserved, RES0.
Physical Timestamp. If timestamp sampling is enabled, determines which counter is collected. The behavior depends on the Profiling Buffer owning Exception level.
If FEAT_ECV is implemented, this is a two-bit field as shown. Otherwise, bit[7] is RES0.
| PCT | Meaning | Applies when |
|---|---|---|
| 0b00 | Virtual timestamp. The collected timestamp is the physical counter minus a virtual offset. If the Profiling Buffer owning Exception level is EL2 and any of the following are true, then the virtual offset is zero:
Otherwise, the virtual offset is the value of CNTVOFF_EL2. | |
| 0b01 | If the Profiling Buffer owning Exception level is EL1, then the timestamp value is selected by PMSCR_EL1.PCT. Otherwise, physical timestamp. The collected timestamp is the physical counter. | |
| 0b11 | If the Profiling Buffer owning Exception level is EL1 and PMSCR_EL1.PCT is 0b00, then guest virtual timestamp. The collected timestamp is the physical counter minus the value of CNTVOFF_EL2. Otherwise, guest physical timestamp. The collected timestamp is the physical counter minus a physical offset. If any of the following are true, then the physical offset is zero, otherwise the physical offset is the value of CNTPOFF_EL2:
| When FEAT_ECV is implemented |
All other values are reserved.
If EL2 is not implemented or EL2 is disabled in the current Security state, then the Effective value of this field is 0b01, other than for a direct read of the register.
The reset behavior of this field is:
Timestamp packet sample enable. Enables recording of Timestamp packets when the Profiling Buffer owning Exception level is EL2.
| TS | Meaning |
|---|---|
| 0b0 |
Timestamp packet recording disabled. |
| 0b1 |
Timestamp packet recording enabled. |
If the Profiling Buffer owning Exception level is EL1, then this field is ignored by the PE. For more information, see Controlling the data that is collected.
When Timestamp packet recording is enabled, recording of End packets is disabled.
The reset behavior of this field is:
Physical Address packet sample enable. Enables recording of Physical Address packets when the Profiling Buffer owning Exception level is EL2.
| PA | Meaning |
|---|---|
| 0b0 |
Physical Address packet recording disabled. |
| 0b1 |
Physical Address packet recording is not disabled by this control. |
If the Profiling Buffer owning Exception level is EL2, then this field determines whether Physical Address packets are recorded.
If the Profiling Buffer owning Exception level is EL1, and EL2 is enabled in the owning Security state, then this field is combined with PMSCR_EL1.PA to determine whether Physical Address packets are recorded.
If EL2 is not implemented or EL2 is disabled in the owning Security state, then the Effective value of this field is 1.
For more information, see Controlling the data that is collected.
The reset behavior of this field is:
CONTEXTIDR_EL2 Context packet sample enable. Enables recording of Context packets containing the value of CONTEXTIDR_EL2.
| CX | Meaning |
|---|---|
| 0b0 |
CONTEXTIDR_EL2 Context packet recording disabled. |
| 0b1 |
CONTEXTIDR_EL2 Context packet recording enabled. |
The PE ignores the value of this field and CONTEXTIDR_EL2 Context packets are not recorded when EL2 is not implemented or EL2 is disabled in the current Security state.
For more information, see Controlling the data that is collected.
The reset behavior of this field is:
Reserved, RES0.
EL2 Statistical Profiling Enable.
| E2SPE | Meaning |
|---|---|
| 0b0 |
Sampling disabled at EL2. |
| 0b1 |
Sampling enabled at EL2. |
The reset behavior of this field is:
Accessing this field has the following behavior:
EL0 Statistical Profiling Enable.
| E0HSPE | Meaning |
|---|---|
| 0b0 |
Sampling disabled at EL0. |
| 0b1 |
Sampling enabled at EL0. |
If the Effective value of HCR_EL2.TGE is 0, then this field is ignored by the PE.
The reset behavior of this field is:
Accessing this field has the following behavior:
Accesses to this register use the following encodings in the System register encoding space:
MRS <Xt>, PMSCR_EL2
(op0 = 0b11, op1 = 0b100, CRn = 0b1001, CRm = 0b1001, op2 = 0b000)
if !IsFeatureImplemented(FEAT_SPE) then Undefined(); elsif HaveEL(EL3) && PSTATE.EL == EL2 && EL3SDDUndefPriority() && CheckMDCR_EL3_NSPBTrap() then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EffectiveHCR_EL2_NVx() IN {'xx1'} then AArch64_SystemAccessTrap(EL2, 0x18); else Undefined(); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && CheckMDCR_EL3_NSPBTrap() then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else X{64}(t) = PMSCR_EL2(); end; elsif PSTATE.EL == EL3 then X{64}(t) = PMSCR_EL2(); end;
MSR PMSCR_EL2, <Xt>
(op0 = 0b11, op1 = 0b100, CRn = 0b1001, CRm = 0b1001, op2 = 0b000)
if !IsFeatureImplemented(FEAT_SPE) then Undefined(); elsif HaveEL(EL3) && PSTATE.EL == EL2 && EL3SDDUndefPriority() && CheckMDCR_EL3_NSPBTrap() then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EffectiveHCR_EL2_NVx() IN {'xx1'} then AArch64_SystemAccessTrap(EL2, 0x18); else Undefined(); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && CheckMDCR_EL3_NSPBTrap() then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; else PMSCR_EL2() = X{64}(t); end; elsif PSTATE.EL == EL3 then PMSCR_EL2() = X{64}(t); end;
MRS <Xt>, PMSCR_EL1
(op0 = 0b11, op1 = 0b000, CRn = 0b1001, CRm = 0b1001, op2 = 0b000)
if !IsFeatureImplemented(FEAT_SPE) then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && CheckMDCR_EL3_NSPBTrap() then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && HDFGRTR_EL2().PMSCR_EL1 == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif EL2Enabled() && MDCR_EL2().TPMS == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif HaveEL(EL3) && CheckMDCR_EL3_NSPBTrap() then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif EffectiveHCR_EL2_NVx() IN {'111'} then X{64}(t) = NVMem(0x828); else X{64}(t) = PMSCR_EL1(); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && CheckMDCR_EL3_NSPBTrap() then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif ELIsInHost(EL2) then X{64}(t) = PMSCR_EL2(); else X{64}(t) = PMSCR_EL1(); end; elsif PSTATE.EL == EL3 then X{64}(t) = PMSCR_EL1(); end;
MSR PMSCR_EL1, <Xt>
(op0 = 0b11, op1 = 0b000, CRn = 0b1001, CRm = 0b1001, op2 = 0b000)
if !IsFeatureImplemented(FEAT_SPE) then Undefined(); elsif HaveEL(EL3) && !(EffectivelyAtEL0InHost() || EffectivelyAtEL0NotInHost() || PSTATE.EL == EL3) && EL3SDDUndefPriority() && CheckMDCR_EL3_NSPBTrap() then Undefined(); elsif PSTATE.EL == EL0 then Undefined(); elsif PSTATE.EL == EL1 then if EL2Enabled() && IsFeatureImplemented(FEAT_FGT) && (!HaveEL(EL3) || SCR_EL3().FGTEn == '1') && HDFGWTR_EL2().PMSCR_EL1 == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif EL2Enabled() && MDCR_EL2().TPMS == '1' then AArch64_SystemAccessTrap(EL2, 0x18); elsif HaveEL(EL3) && CheckMDCR_EL3_NSPBTrap() then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif EffectiveHCR_EL2_NVx() IN {'111'} then NVMem(0x828) = X{64}(t); else PMSCR_EL1() = X{64}(t); end; elsif PSTATE.EL == EL2 then if HaveEL(EL3) && CheckMDCR_EL3_NSPBTrap() then if EL3SDDUndef() then Undefined(); else AArch64_SystemAccessTrap(EL3, 0x18); end; elsif ELIsInHost(EL2) then PMSCR_EL2() = X{64}(t); else PMSCR_EL1() = X{64}(t); end; elsif PSTATE.EL == EL3 then PMSCR_EL1() = X{64}(t); end;
Version 2026.06 — Copyright © 2010-2026 Arm Limited or its affiliates.
This site is provided as a community resource and is NOT affiliated with nor endorsed by Arm Limited.