On Fri, Sep 25, 2026 at 12:53:46PM +0300, Mike Rapoport (Microsoft) wrote: > Verification that the kernel does not have writable + executable > mappings is about detecting security risks rather than a pure debug > feature. > > Major distribution configurations enable it in their kernels as well as > defconfigs of most architectures that have ARCH_HAS_DEBUG_WX. > > Rename relevant generic configuration options to use CHECK_WX and move > their definitions from mm/Kconfig.debug to mm/Kconfig. > > For arm that does not widely enable it, only rename its variants of the > config options. > > Enabling CHECK_WX adds a few kilobytes to the kernel binary and while > the added size can be slightly reduced with churny updates of > architecture implementations of ptdump, the core functionality takes > most of the added size. It cannot be moved to .init.text because the > verification has to happen after init sections are freed. > > With this, make generic CHECK_WX default to STRICT_KERNEL_RWX while > still leaving users targeting small kernels the possibility to opt-out. > > Suggested-by: Dave Hansen <[email protected]> > Signed-off-by: Mike Rapoport (Microsoft) <[email protected]> > --- ... > arch/s390/Kconfig | 2 +- > arch/s390/configs/debug_defconfig | 2 +- > arch/s390/configs/defconfig | 2 +- > arch/s390/mm/dump_pagetables.c | 2 +-
Acked-by: Heiko Carstens <[email protected]> # s390 > diff --git a/arch/s390/mm/dump_pagetables.c b/arch/s390/mm/dump_pagetables.c > index 89badbe72ae7..a23a0bd4d8a8 100644 > --- a/arch/s390/mm/dump_pagetables.c > +++ b/arch/s390/mm/dump_pagetables.c > @@ -86,7 +86,7 @@ static void note_prot_wx(struct pg_state *st, unsigned long > addr) > */ > if (addr == PAGE_SIZE && (nospec_uses_trampoline() || !cpu_has_bear())) > return; > - WARN_ONCE(IS_ENABLED(CONFIG_DEBUG_WX), > + WARN_ONCE(IS_ENABLED(CONFIG_CHECK_WX), Hm... looks like there is bug with relocated lowcore handling in the if condition above the WARN_ONCE(). I'm going to address that, but that has nothing to do with your patch.
