summaryrefslogtreecommitdiff
path: root/arch/arm
diff options
context:
space:
mode:
authorMike Rapoport (Microsoft) <rppt@kernel.org>2026-09-26 12:29:29 +0300
committerAndrew Morton <akpm@linux-foundation.org>2026-09-30 16:57:51 -0700
commit259f8ff4d35fadd660501d13a5ec9b86ead33a82 (patch)
tree28355ce83afed7bbc9aed2d8323331bae5d50dc8 /arch/arm
parent772b18ca6c9b7d720c2cd128173e89da410b74f1 (diff)
downloadlinux-next-259f8ff4d35fadd660501d13a5ec9b86ead33a82.tar.gz
linux-next-259f8ff4d35fadd660501d13a5ec9b86ead33a82.zip
arch, mm: promote DEBUG_WX to CHECK_WX
Verification that the kernel does not have writable + executable mappings is about detecting security risks rather than a pure debug feature. Major distribution configurations enable it in their kernels as well as defconfigs of most architectures that have ARCH_HAS_DEBUG_WX. Rename relevant generic configuration options to use CHECK_WX and move their definitions from mm/Kconfig.debug to mm/Kconfig. Rename *debug_checkwx() funcitons and macros to *pgtable_checkwx(). For arm that does not widely enable it, only rename its variants of the config options. Enabling CHECK_WX adds a few kilobytes to the kernel binary and while the added size can be slightly reduced with churny updates of architecture implementations of ptdump, the core functionality takes most of the added size. It cannot be moved to .init.text because the verification has to happen after init sections are freed. With this, make generic CHECK_WX default to STRICT_KERNEL_RWX while still leaving users targeting small kernels the possibility to opt-out. Link: https://lore.kernel.org/20260926-direct-map-verify-wx-v2-1-efcd64a6b74a@kernel.org Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org> Signed-off-by: Andrew Morton <akpm@linux-foundation.org> Suggested-by: Dave Hansen <dave.hansen@linux.intel.com> Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org> Acked-by: Dave Hansen <dave.hansen@linux.intel.com> Acked-by: David Hildenbrand (Arm) <david@kernel.org> Cc: Albert Ou <aou@eecs.berkeley.edu> Cc: Alexander Gordeev <agordeev@linux.ibm.com> Cc: Alexandre Ghiti <alex@ghiti.fr> Cc: Borislav Petkov <bp@alien8.de> Cc: Catalin Marinas <catalin.marinas@arm.com> Cc: Christophe Leroy <chleroy@kernel.org> Cc: Christian Borntraeger <borntraeger@linux.ibm.com> Cc: Gerald Schaefer <gerald.schaefer@linux.ibm.com> Cc: Heiko Carstens <hca@linux.ibm.com> Cc: Ingo Molnar <mingo@redhat.com> Cc: Liam R. Howlett <liam@infradead.org> Cc: Madhavan Srinivasan <maddy@linux.ibm.com> Cc: Mark Rutland <mark.rutland@arm.com> Cc: Michael Ellerman <mpe@ellerman.id.au> Cc: Michal Hocko <mhocko@suse.com> Cc: Nicholas Piggin <npiggin@gmail.com> Cc: Palmer Dabbelt <palmer@dabbelt.com> Cc: Paul Walmsley <pjw@kernel.org> Cc: H. Peter Anvin <hpa@zytor.com> Cc: Ritesh Harjani (IBM) <ritesh.list@gmail.com> Cc: Russell King <linux@armlinux.org.uk> Cc: Shrikanth Hegde <sshegde@linux.ibm.com> Cc: Suren Baghdasaryan <surenb@google.com> Cc: Sven Schnelle <svens@linux.ibm.com> Cc: Thomas Gleixner <tglx@kernel.org> Cc: Vasily Gorbik <gor@linux.ibm.com> Cc: Vlastimil Babka <vbabka@kernel.org> Cc: Will Deacon <will@kernel.org>
Diffstat (limited to 'arch/arm')
-rw-r--r--arch/arm/Kconfig.debug2
-rw-r--r--arch/arm/configs/aspeed_g4_defconfig2
-rw-r--r--arch/arm/configs/aspeed_g5_defconfig2
-rw-r--r--arch/arm/configs/shmobile_defconfig2
-rw-r--r--arch/arm/include/asm/ptdump.h6
-rw-r--r--arch/arm/mm/init.c2
6 files changed, 8 insertions, 8 deletions
diff --git a/arch/arm/Kconfig.debug b/arch/arm/Kconfig.debug
index 366f162e147d..abcf14f10276 100644
--- a/arch/arm/Kconfig.debug
+++ b/arch/arm/Kconfig.debug
@@ -17,7 +17,7 @@ config ARM_PTDUMP_DEBUGFS
kernel.
If in doubt, say "N"
-config ARM_DEBUG_WX
+config ARM_CHECK_WX
bool "Warn on W+X mappings at boot"
depends on MMU
select ARM_PTDUMP_CORE
diff --git a/arch/arm/configs/aspeed_g4_defconfig b/arch/arm/configs/aspeed_g4_defconfig
index f86dd4ce7d0d..2c9d5a644ae9 100644
--- a/arch/arm/configs/aspeed_g4_defconfig
+++ b/arch/arm/configs/aspeed_g4_defconfig
@@ -249,7 +249,7 @@ CONFIG_DEBUG_INFO_REDUCED=y
CONFIG_GDB_SCRIPTS=y
CONFIG_STRIP_ASM_SYMS=y
CONFIG_DEBUG_FS=y
-CONFIG_ARM_DEBUG_WX=y
+CONFIG_ARM_CHECK_WX=y
CONFIG_SCHED_STACK_END_CHECK=y
CONFIG_PANIC_ON_OOPS=y
CONFIG_PANIC_TIMEOUT=-1
diff --git a/arch/arm/configs/aspeed_g5_defconfig b/arch/arm/configs/aspeed_g5_defconfig
index 45b937419dbd..1327a09e163a 100644
--- a/arch/arm/configs/aspeed_g5_defconfig
+++ b/arch/arm/configs/aspeed_g5_defconfig
@@ -300,7 +300,7 @@ CONFIG_DEBUG_INFO_REDUCED=y
CONFIG_GDB_SCRIPTS=y
CONFIG_STRIP_ASM_SYMS=y
CONFIG_DEBUG_FS=y
-CONFIG_ARM_DEBUG_WX=y
+CONFIG_ARM_CHECK_WX=y
CONFIG_SCHED_STACK_END_CHECK=y
CONFIG_PANIC_ON_OOPS=y
CONFIG_PANIC_TIMEOUT=-1
diff --git a/arch/arm/configs/shmobile_defconfig b/arch/arm/configs/shmobile_defconfig
index 6f9696e9fe17..cc22e22b989e 100644
--- a/arch/arm/configs/shmobile_defconfig
+++ b/arch/arm/configs/shmobile_defconfig
@@ -225,4 +225,4 @@ CONFIG_CMA_SIZE_MBYTES=64
CONFIG_PRINTK_TIME=y
CONFIG_DEBUG_KERNEL=y
CONFIG_DEBUG_FS=y
-CONFIG_ARM_DEBUG_WX=y
+CONFIG_ARM_CHECK_WX=y
diff --git a/arch/arm/include/asm/ptdump.h b/arch/arm/include/asm/ptdump.h
index 46a4575146ee..3c5245220ecf 100644
--- a/arch/arm/include/asm/ptdump.h
+++ b/arch/arm/include/asm/ptdump.h
@@ -32,10 +32,10 @@ void ptdump_check_wx(void);
#endif /* CONFIG_ARM_PTDUMP_CORE */
-#ifdef CONFIG_ARM_DEBUG_WX
-#define arm_debug_checkwx() ptdump_check_wx()
+#ifdef CONFIG_ARM_CHECK_WX
+#define arm_pgtable_checkwx() ptdump_check_wx()
#else
-#define arm_debug_checkwx() do { } while (0)
+#define arm_pgtable_checkwx() do { } while (0)
#endif
#endif /* __ASM_PTDUMP_H */
diff --git a/arch/arm/mm/init.c b/arch/arm/mm/init.c
index 0cc1bf04686d..c515faf22eeb 100644
--- a/arch/arm/mm/init.c
+++ b/arch/arm/mm/init.c
@@ -403,7 +403,7 @@ static int __mark_rodata_ro(void *unused)
void mark_rodata_ro(void)
{
stop_machine(__mark_rodata_ro, NULL, NULL);
- arm_debug_checkwx();
+ arm_pgtable_checkwx();
}
#else