[PATCH] arch, mm: promote DEBUG_WX to CHECK_WX
Christophe Leroy (CS GROUP)
chleroy at kernel.org
Fri Sep 25 23:47:50 PDT 2026
Hi Mike,
Le 25/09/2026 à 11:53, Mike Rapoport (Microsoft) a écrit :
> Verification that the kernel does not have writable + executable
> mappings is about detecting security risks rather than a pure debug
> feature.
>
> Major distribution configurations enable it in their kernels as well as
> defconfigs of most architectures that have ARCH_HAS_DEBUG_WX.
>
> Rename relevant generic configuration options to use CHECK_WX and move
> their definitions from mm/Kconfig.debug to mm/Kconfig.
>
> For arm that does not widely enable it, only rename its variants of the
> config options.
>
> Enabling CHECK_WX adds a few kilobytes to the kernel binary and while
> the added size can be slightly reduced with churny updates of
> architecture implementations of ptdump, the core functionality takes
> most of the added size. It cannot be moved to .init.text because the
> verification has to happen after init sections are freed.
>
> With this, make generic CHECK_WX default to STRICT_KERNEL_RWX while
> still leaving users targeting small kernels the possibility to opt-out.
Looking at how it is done in powerpc I have some doubt with your reasoning.
ptdump_check_wx() will report regardless of CONFIG_DEBUG_WX:
if (st.wx_pages) {
pr_warn("Checked W+X mappings: FAILED, %lu W+X pages found\n",
st.wx_pages);
return false;
} else {
pr_info("Checked W+X mappings: passed, no W+X pages found\n");
return true;
}
The only difference is we won't get the WARN_ONCE():
WARN_ONCE(IS_ENABLED(CONFIG_DEBUG_WX),
"powerpc/mm: Found insecure W+X mapping at address %p/%pS\n",
(void *)st->start_address, (void *)st->start_address);
And I believe a big fat warning like this is a debug option not to be
enabled on production kernels.
So I think we should instead do:
diff --git a/include/linux/ptdump.h b/include/linux/ptdump.h
index 240bd3bff18dd..714f63fb604a0 100644
--- a/include/linux/ptdump.h
+++ b/include/linux/ptdump.h
@@ -33,7 +33,7 @@ bool ptdump_check_wx(void);
static inline void debug_checkwx(void)
{
- if (IS_ENABLED(CONFIG_DEBUG_WX))
+ if (IS_ENABLED(CONFIG_PTDUMP))
ptdump_check_wx();
}
That way you should get (untested) the following warning but not the big
fat debug WARN():
Checked W+X mappings: FAILED, %lu W+X pages found
Christophe
More information about the linux-riscv
mailing list