[clang] 61ab635 - [clang][Driver] Prevent Safe Stack runtime from linking if enabled then disabled (#228537)

via cfe-commits cfe-commits at lists.llvm.org
Sat Oct 3 22:16:02 PDT 2026


Author: Douglas
Date: 2026-10-04T05:15:54Z
New Revision: 61ab63550e48c9f2e50aa2d5261ee8a5fe319c72

URL: https://github.com/llvm/llvm-project/commit/61ab63550e48c9f2e50aa2d5261ee8a5fe319c72
DIFF: https://github.com/llvm/llvm-project/commit/61ab63550e48c9f2e50aa2d5261ee8a5fe319c72.diff

LOG: [clang][Driver] Prevent Safe Stack runtime from linking if enabled then disabled (#228537)

Currently:
```
$ ./clang -fsanitize=safe-stack -fno-sanitize=safe-stack -Wl,--trace -x c++ -o- - < /dev/null
...
.../libclang_rt.safestack.a
...
```

See https://godbolt.org/z/e63za9sjn

With this change, `libclang_rt.safestack.a` is not included when Safe
Stack is disabled as the last option. This is because `Kinds` is the
final resolved set of sanitizers after removals via `-fno-sanitize`.
`AllAddedKinds` is the set of all sanitizers which were seen at least
once even if they were removed. This change makes it so we check against
`Kinds` instead of `AllAddedKinds`.

Besides Safe Stack, there are quite a few options resolved and passed to
the driver unintentionally when using particular combinations of
`-fsanitize` and `-fno-sanitize`. This is filed as
https://github.com/llvm/llvm-project/issues/228529.

Should fix https://github.com/llvm/llvm-project/issues/107763.

Added: 
    

Modified: 
    clang/lib/Driver/SanitizerArgs.cpp
    clang/test/Driver/sanitizer-ld.c

Removed: 
    


################################################################################
diff  --git a/clang/lib/Driver/SanitizerArgs.cpp b/clang/lib/Driver/SanitizerArgs.cpp
index 438283c60c0ba..a1bfa90e5dceb 100644
--- a/clang/lib/Driver/SanitizerArgs.cpp
+++ b/clang/lib/Driver/SanitizerArgs.cpp
@@ -1309,7 +1309,7 @@ SanitizerArgs::SanitizerArgs(const ToolChain &TC,
           HwasanUseAliases);
   }
 
-  if (AllAddedKinds & SanitizerKind::SafeStack) {
+  if (Kinds & SanitizerKind::SafeStack) {
     // SafeStack runtime is built into the system on Android and Fuchsia.
     SafeStackRuntime =
         !TC.getTriple().isAndroid() && !TC.getTriple().isOSFuchsia();

diff  --git a/clang/test/Driver/sanitizer-ld.c b/clang/test/Driver/sanitizer-ld.c
index f55c2917408a2..d54232e2650b2 100644
--- a/clang/test/Driver/sanitizer-ld.c
+++ b/clang/test/Driver/sanitizer-ld.c
@@ -1017,16 +1017,25 @@
 // RUN:     --target=x86_64-unknown-linux -fuse-ld=ld -fsanitize=safe-stack \
 // RUN:     -resource-dir=%S/Inputs/resource_dir \
 // RUN:     --sysroot=%S/Inputs/basic_linux_tree \
-// RUN:   | %{filecheck} --check-prefix=CHECK-SAFESTACK-LINUX
+// RUN:   | %{filecheck} --check-prefixes=CHECK-SAFESTACK-LINUX,CHECK-SAFESTACK-LINUX-ENABLED
+//
+// RUN: %clang -### %s 2>&1 \
+// RUN:     --target=x86_64-unknown-linux -fuse-ld=ld \
+// RUN:     -fsanitize=safe-stack -fno-sanitize=safe-stack \
+// RUN:     -resource-dir=%S/Inputs/resource_dir \
+// RUN:     --sysroot=%S/Inputs/basic_linux_tree \
+// RUN:   | %{filecheck} --check-prefixes=CHECK-SAFESTACK-LINUX,CHECK-SAFESTACK-LINUX-DISABLED
 //
 // CHECK-SAFESTACK-LINUX: "{{(.*[^-.0-9A-Z_a-z])?}}ld{{(.exe)?}}"
-// CHECK-SAFESTACK-LINUX-NOT: "-lc"
-// CHECK-SAFESTACK-LINUX-NOT: whole-archive
-// CHECK-SAFESTACK-LINUX: "-u" "__safestack_init"
-// CHECK-SAFESTACK-LINUX: libclang_rt.safestack.a"
-// CHECK-SAFESTACK-LINUX: "-lpthread"
-// CHECK-SAFESTACK-LINUX: "-ldl"
-// CHECK-SAFESTACK-LINUX: "-lresolv"
+// CHECK-SAFESTACK-LINUX-ENABLED-NOT: "-lc"
+// CHECK-SAFESTACK-LINUX-ENABLED-NOT: whole-archive
+// CHECK-SAFESTACK-LINUX-ENABLED: "-u" "__safestack_init"
+// CHECK-SAFESTACK-LINUX-ENABLED: libclang_rt.safestack.a"
+// CHECK-SAFESTACK-LINUX-ENABLED: "-lpthread"
+// CHECK-SAFESTACK-LINUX-ENABLED: "-ldl"
+// CHECK-SAFESTACK-LINUX-ENABLED: "-lresolv"
+// CHECK-SAFESTACK-LINUX-DISABLED-NOT: "-u" "__safestack_init"
+// CHECK-SAFESTACK-LINUX-DISABLED-NOT: libclang_rt.safestack.a"
 
 // RUN: %clang -fsanitize=shadow-call-stack -### %s 2>&1 \
 // RUN:     --target=x86_64-unknown-linux -fuse-ld=ld \


        


More information about the cfe-commits mailing list