From 2296fb59155171b79cdd90dd8220ad519563630d Mon Sep 17 00:00:00 2001 From: Peter Maydell Date: Tue, 20 Feb 2018 22:21:08 -0500 Subject: [PATCH] target-arm: Forbid mode switch to Mon from Secure EL1 In v8 trying to switch mode to Mon from Secure EL1 is an illegal mode switch. (In v7 this is impossible as all secure modes except User are at EL3.) We can handle this case by making a switch to Mon valid only if the current EL is 3, which then gives the correct answer whether EL3 is AArch32 or AArch64. Backports commit 58ae2d1f037fae1d90eed4522053a85d79edfbec from qemu --- qemu/target-arm/helper.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/qemu/target-arm/helper.c b/qemu/target-arm/helper.c index 139b2c8b..21a91dd8 100644 --- a/qemu/target-arm/helper.c +++ b/qemu/target-arm/helper.c @@ -4525,7 +4525,7 @@ static int bad_mode_switch(CPUARMState *env, int mode) return !arm_feature(env, ARM_FEATURE_EL2) || arm_current_el(env) < 2 || arm_is_secure(env); case ARM_CPU_MODE_MON: - return !arm_is_secure(env); + return arm_current_el(env) < 3; default: return 1; }