diff --git a/arch/Kconfig b/arch/Kconfig index d53afd0c8323..88401dab0689 100644 --- a/arch/Kconfig +++ b/arch/Kconfig @@ -549,6 +549,7 @@ config SHADOW_CALL_STACK config SHADOW_CALL_STACK_VMAP bool "Use virtually mapped shadow call stacks" depends on SHADOW_CALL_STACK + default y help Use virtually mapped shadow call stacks. Selecting this option provides better stack exhaustion protection, but increases per-thread diff --git a/include/linux/scs.h b/include/linux/scs.h index c5572fd770b0..f8c8beff7850 100644 --- a/include/linux/scs.h +++ b/include/linux/scs.h @@ -14,12 +14,17 @@ #ifdef CONFIG_SHADOW_CALL_STACK +#ifdef CONFIG_SHADOW_CALL_STACK_VMAP +#define SCS_SIZE PAGE_SIZE +#else /* * In testing, 1 KiB shadow stack size (i.e. 128 stack frames on a 64-bit * architecture) provided ~40% safety margin on stack usage while keeping * memory allocation overhead reasonable. */ #define SCS_SIZE 1024UL +#endif + #define GFP_SCS (GFP_KERNEL | __GFP_ZERO) /*