It turns out we can't fix this without also fixing our implementation of signal trampolines.
** Changed in: qemu Status: New => Confirmed -- You received this bug notification because you are a member of qemu- devel-ml, which is subscribed to QEMU. https://bugs.launchpad.net/bugs/1832916 Title: linux-user does not check PROT_EXEC Status in QEMU: Confirmed Bug description: At no point do we actually verify that a page is PROT_EXEC before translating. All we end up verifying is that the page is readable. Not the same thing, obviously. The following test case should work for any architecture, though I've only validated it for x86_64 and aarch64. To manage notifications about this bug go to: https://bugs.launchpad.net/qemu/+bug/1832916/+subscriptions