[PATCH] arch, mm: promote DEBUG_WX to CHECK_WX

Christophe Leroy (CS GROUP) chleroy at kernel.org
Fri Sep 25 23:47:50 PDT 2026


Hi Mike,

Le 25/09/2026 à 11:53, Mike Rapoport (Microsoft) a écrit :
> Verification that the kernel does not have writable + executable
> mappings is about detecting security risks rather than a pure debug
> feature.
> 
> Major distribution configurations enable it in their kernels as well as
> defconfigs of most architectures that have ARCH_HAS_DEBUG_WX.
> 
> Rename relevant generic configuration options to use CHECK_WX and move
> their definitions from mm/Kconfig.debug to mm/Kconfig.
> 
> For arm that does not widely enable it, only rename its variants of the
> config options.
> 
> Enabling CHECK_WX adds a few kilobytes to the kernel binary and while
> the added size can be slightly reduced with churny updates of
> architecture implementations of ptdump, the core functionality takes
> most of the added size. It cannot be moved to .init.text because the
> verification has to happen after init sections are freed.
> 
> With this, make generic CHECK_WX default to STRICT_KERNEL_RWX while
> still leaving users targeting small kernels the possibility to opt-out.

Looking at how it is done in powerpc I have some doubt with your reasoning.

ptdump_check_wx() will report regardless of CONFIG_DEBUG_WX:

	if (st.wx_pages) {
		pr_warn("Checked W+X mappings: FAILED, %lu W+X pages found\n",
			st.wx_pages);

		return false;
	} else {
		pr_info("Checked W+X mappings: passed, no W+X pages found\n");

		return true;
	}

The only difference is we won't get the WARN_ONCE():

	WARN_ONCE(IS_ENABLED(CONFIG_DEBUG_WX),
		  "powerpc/mm: Found insecure W+X mapping at address %p/%pS\n",
		  (void *)st->start_address, (void *)st->start_address);


And I believe a big fat warning like this is a debug option not to be 
enabled on production kernels.

So I think we should instead do:

diff --git a/include/linux/ptdump.h b/include/linux/ptdump.h
index 240bd3bff18dd..714f63fb604a0 100644
--- a/include/linux/ptdump.h
+++ b/include/linux/ptdump.h
@@ -33,7 +33,7 @@ bool ptdump_check_wx(void);

  static inline void debug_checkwx(void)
  {
-	if (IS_ENABLED(CONFIG_DEBUG_WX))
+	if (IS_ENABLED(CONFIG_PTDUMP))
  		ptdump_check_wx();
  }


That way you should get (untested) the following warning but not the big 
fat debug WARN():

   Checked W+X mappings: FAILED, %lu W+X pages found

Christophe




More information about the linux-riscv mailing list