[llvm] [LLVM] Disable IO sandbox in collectAddressSymbols (PR #194597)
via llvm-commits
llvm-commits at lists.llvm.org
Tue Apr 28 04:23:55 PDT 2026
llvmbot wrote:
<!--LLVM PR SUMMARY COMMENT-->
@llvm/pr-subscribers-llvm-support
Author: Stephen Tozer (SLTozer)
<details>
<summary>Changes</summary>
The function `collectAddressSymbols` is used by debugify to symbolize addresses captured in the current invocation of LLVM, which it does by executing llvm-symbolizer with temporary input and output files. Creating the temporary files has an explicit sandbox exclusion, as temporary files are necessarily not part of the compiler's formal output, but attempting to read back the output file via MemoryBuffer triggers a sandbox violation. Since we are always only operating on temporary files within collectAddressSymbols, this patch disables the IO sandbox in that function.
---
Full diff: https://github.com/llvm/llvm-project/pull/194597.diff
1 Files Affected:
- (modified) llvm/lib/Support/Signals.cpp (+4)
``````````diff
diff --git a/llvm/lib/Support/Signals.cpp b/llvm/lib/Support/Signals.cpp
index f160a135f623d..7936a715fb4f6 100644
--- a/llvm/lib/Support/Signals.cpp
+++ b/llvm/lib/Support/Signals.cpp
@@ -155,6 +155,10 @@ std::optional<SmallVector<std::pair<unsigned, std::string>, 0>>
collectAddressSymbols(void **AddressList, unsigned AddressCount,
const char *MainExecutableName,
const std::string &LLVMSymbolizerPath) {
+ // This function deals with temporary files for the purposes of symbolization
+ // only, not formal compiler output.
+ auto BypassSandbox = sys::sandbox::scopedDisable();
+
BumpPtrAllocator Allocator;
StringSaver StrPool(Allocator);
SmallVector<const char *, 0> Modules(AddressCount, nullptr);
``````````
</details>
https://github.com/llvm/llvm-project/pull/194597
More information about the llvm-commits
mailing list