BTW: write_cr0(read_cr0() | 0x10000)
is a absolute no-go. It's a nice and funny kernel module but it dooms the kernel's security.
is a absolute no-go. It's a nice and funny kernel module but it dooms the kernel's security.
What this means is that the kernel can no longer see if a user is writing to a read-only location, which is a major part of memory protection. It has major security implications. I don't know whether other parts of the kernel enable or disable this at context switches or at other times.
What this also means is that this kernel module will only work on x86 CPU's. So no rickrolling you ARM boxes or smartphones.
No, disabling WP in CR0 is only relevant for privileged code. Writes to write protected pages in user mode will still trap. It might mess up some in-kernel COW stuff though.