diff options
| author | Mike Rapoport (Microsoft) <rppt@kernel.org> | 2026-09-26 12:29:29 +0300 |
|---|---|---|
| committer | Andrew Morton <akpm@linux-foundation.org> | 2026-09-29 23:14:07 -0700 |
| commit | d4cabc260ed84d74542e1d45f91ee6ef8faad01c (patch) | |
| tree | 6f328ca3326175b8ed1a579ec6e520933a6ac59b /include/linux | |
| parent | fc00776ee78ab6d6ab9bc9e5ca2179b91a6de299 (diff) | |
| download | linux-next-d4cabc260ed84d74542e1d45f91ee6ef8faad01c.tar.gz linux-next-d4cabc260ed84d74542e1d45f91ee6ef8faad01c.zip | |
arch, mm: promote DEBUG_WX to CHECK_WX
Verification that the kernel does not have writable + executable mappings
is about detecting security risks rather than a pure debug feature.
Major distribution configurations enable it in their kernels as well as
defconfigs of most architectures that have ARCH_HAS_DEBUG_WX.
Rename relevant generic configuration options to use CHECK_WX and move
their definitions from mm/Kconfig.debug to mm/Kconfig.
Rename *debug_checkwx() funcitons and macros to *pgtable_checkwx().
For arm that does not widely enable it, only rename its variants of the
config options.
Enabling CHECK_WX adds a few kilobytes to the kernel binary and while the
added size can be slightly reduced with churny updates of architecture
implementations of ptdump, the core functionality takes most of the added
size. It cannot be moved to .init.text because the verification has to
happen after init sections are freed.
With this, make generic CHECK_WX default to STRICT_KERNEL_RWX while
still leaving users targeting small kernels the possibility to opt-out.
Link: https://lore.kernel.org/20260926-direct-map-verify-wx-v2-1-efcd64a6b74a@kernel.org
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Suggested-by: Dave Hansen <dave.hansen@linux.intel.com>
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Acked-by: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Albert Ou <aou@eecs.berkeley.edu>
Cc: Alexander Gordeev <agordeev@linux.ibm.com>
Cc: Alexandre Ghiti <alex@ghiti.fr>
Cc: Borislav Petkov <bp@alien8.de>
Cc: Catalin Marinas <catalin.marinas@arm.com>
Cc: Christophe Leroy <chleroy@kernel.org>
Cc: Christian Borntraeger <borntraeger@linux.ibm.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Gerald Schaefer <gerald.schaefer@linux.ibm.com>
Cc: Heiko Carstens <hca@linux.ibm.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Palmer Dabbelt <palmer@dabbelt.com>
Cc: Paul Walmsley <pjw@kernel.org>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Cc: Russell King <linux@armlinux.org.uk>
Cc: Shrikanth Hegde <sshegde@linux.ibm.com>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Sven Schnelle <svens@linux.ibm.com>
Cc: Thomas Gleixner <tglx@kernel.org>
Cc: Vasily Gorbik <gor@linux.ibm.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: Will Deacon <will@kernel.org>
Diffstat (limited to 'include/linux')
| -rw-r--r-- | include/linux/ptdump.h | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/include/linux/ptdump.h b/include/linux/ptdump.h index 240bd3bff18d..af18d1459b2f 100644 --- a/include/linux/ptdump.h +++ b/include/linux/ptdump.h @@ -31,9 +31,9 @@ bool ptdump_walk_pgd_level_core(struct seq_file *m, void ptdump_walk_pgd(struct ptdump_state *st, struct mm_struct *mm, pgd_t *pgd); bool ptdump_check_wx(void); -static inline void debug_checkwx(void) +static inline void pgtable_checkwx(void) { - if (IS_ENABLED(CONFIG_DEBUG_WX)) + if (IS_ENABLED(CONFIG_CHECK_WX)) ptdump_check_wx(); } |
