Re: [PATCH] arch, mm: promote DEBUG_WX to CHECK_WX

From: Heiko Carstens

Date: Fri Sep 25 2026 - 09:48:57 EST


On Fri, Sep 25, 2026 at 12:53:46PM +0300, Mike Rapoport (Microsoft) wrote:
> Verification that the kernel does not have writable + executable
> mappings is about detecting security risks rather than a pure debug
> feature.
>
> Major distribution configurations enable it in their kernels as well as
> defconfigs of most architectures that have ARCH_HAS_DEBUG_WX.
>
> Rename relevant generic configuration options to use CHECK_WX and move
> their definitions from mm/Kconfig.debug to mm/Kconfig.
>
> For arm that does not widely enable it, only rename its variants of the
> config options.
>
> Enabling CHECK_WX adds a few kilobytes to the kernel binary and while
> the added size can be slightly reduced with churny updates of
> architecture implementations of ptdump, the core functionality takes
> most of the added size. It cannot be moved to .init.text because the
> verification has to happen after init sections are freed.
>
> With this, make generic CHECK_WX default to STRICT_KERNEL_RWX while
> still leaving users targeting small kernels the possibility to opt-out.
>
> Suggested-by: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
> Signed-off-by: Mike Rapoport (Microsoft) <rppt@xxxxxxxxxx>
> ---
...
> arch/s390/Kconfig | 2 +-
> arch/s390/configs/debug_defconfig | 2 +-
> arch/s390/configs/defconfig | 2 +-
> arch/s390/mm/dump_pagetables.c | 2 +-

Acked-by: Heiko Carstens <hca@xxxxxxxxxxxxx> # s390

> diff --git a/arch/s390/mm/dump_pagetables.c b/arch/s390/mm/dump_pagetables.c
> index 89badbe72ae7..a23a0bd4d8a8 100644
> --- a/arch/s390/mm/dump_pagetables.c
> +++ b/arch/s390/mm/dump_pagetables.c
> @@ -86,7 +86,7 @@ static void note_prot_wx(struct pg_state *st, unsigned long addr)
> */
> if (addr == PAGE_SIZE && (nospec_uses_trampoline() || !cpu_has_bear()))
> return;
> - WARN_ONCE(IS_ENABLED(CONFIG_DEBUG_WX),
> + WARN_ONCE(IS_ENABLED(CONFIG_CHECK_WX),

Hm... looks like there is bug with relocated lowcore handling in the if
condition above the WARN_ONCE(). I'm going to address that, but that
has nothing to do with your patch.