f31522130f
Build system (5 gaps hardened): - COOKBOOK_OFFLINE defaults to true (fork-mode) - normalize_patch handles diff -ruN format - New 'repo validate-patches' command (25/25 relibc patches) - 14 patched Qt/Wayland/display recipes added to protected list - relibc archive regenerated with current patch chain Boot fixes (fixable): - Full ISO EFI partition: 16 MiB → 1 MiB (matches mini, BIOS hardcoded 2 MiB offset) - D-Bus system bus: absolute /usr/bin/dbus-daemon path (was skipped) - redbear-sessiond: absolute /usr/bin/redbear-sessiond path (was skipped) - daemon framework: silenced spurious INIT_NOTIFY warnings for oneshot_async services (P0-daemon-silence-init-notify.patch) - udev-shim: demoted INIT_NOTIFY warning to INFO (expected for oneshot_async) - relibc: comprehensive named semaphores (sem_open/close/unlink) replacing upstream todo!() stubs - greeterd: Wayland socket timeout 15s → 30s (compositor DRM wait) - greeter-ui: built and linked (header guard unification, sem_compat stubs removed) - mc: un-ignored in both configs, fixed glib/libiconv/pcre2 transitive deps - greeter config: removed stale keymapd dependency from display/greeter services - prefix toolchain: relibc headers synced, _RELIBC_STDLIB_H guard unified Unfixable (diagnosed, upstream): - i2c-hidd: abort on no-I2C-hardware (QEMU) — process::exit → relibc abort - kded6/greeter-ui: page fault 0x8 — Qt library null deref - Thread panics fd != -1 — Rust std library on Redox - DHCP timeout / eth0 MAC — QEMU user-mode networking - hwrngd/thermald — no hardware RNG/thermal in VM - live preload allocation — BIOS memory fragmentation, continues on demand
60 lines
2.7 KiB
Plaintext
60 lines
2.7 KiB
Plaintext
# Sanitizer flags
|
|
|
|
sanitize_address {
|
|
QMAKE_CFLAGS += $$QMAKE_SANITIZE_ADDRESS_CFLAGS
|
|
QMAKE_CXXFLAGS += $$QMAKE_SANITIZE_ADDRESS_CXXFLAGS
|
|
QMAKE_LFLAGS += $$QMAKE_SANITIZE_ADDRESS_LFLAGS
|
|
android {
|
|
# ARM 32 (armeabi-v7a & arm5) are not supported because Qt must be rebuilt with -marm
|
|
equals(ANDROID_TARGET_ARCH, arm64-v8a): ANDROID_LIBCLANG_RT_FILE = "libclang_rt.asan-aarch64-android.so"
|
|
else: equals(ANDROID_TARGET_ARCH, x86): ANDROID_LIBCLANG_RT_FILE = "libclang_rt.asan-i686-android.so"
|
|
else: equals(ANDROID_TARGET_ARCH, x86_64): ANDROID_LIBCLANG_RT_FILE = "libclang_rt.asan-x86_64-android.so"
|
|
else: error("ASAN: Unsupported platform $${ANDROID_TARGET_ARCH}")
|
|
|
|
ANDROID_LIBCLANG_RT_PATH = $${NDK_LLVM_PATH}/lib64/clang
|
|
ANDROID_CLANG_RT_VERSIONS = $$files($$ANDROID_LIBCLANG_RT_PATH/*)
|
|
for (VERSION, ANDROID_CLANG_RT_VERSIONS) {
|
|
greaterThan(VERSION, $$ANDROID_LIBCLANG_RT_PATH): ANDROID_LIBCLANG_RT_PATH = $$VERSION
|
|
}
|
|
ANDROID_LIBCLANG_RT_PATH = "$${ANDROID_LIBCLANG_RT_PATH}/lib/linux/"
|
|
ANDROID_WRAP_SH_CONTENT = "$$LITERAL_HASH!/system/bin/sh"
|
|
ANDROID_WRAP_SH_CONTENT += "HERE=\"$(cd \"$(dirname \"$0\")\" && pwd)\""
|
|
isEmpty(ANDROID_ASAN_OPTIONS): ANDROID_ASAN_OPTIONS = "log_to_syslog=false,allow_user_segv_handler=1"
|
|
ANDROID_WRAP_SH_CONTENT += "export ASAN_OPTIONS=$${ANDROID_ASAN_OPTIONS}"
|
|
ANDROID_WRAP_SH_CONTENT += "export LD_PRELOAD=$HERE/$${ANDROID_LIBCLANG_RT_FILE}"
|
|
ANDROID_WRAP_SH_CONTENT += "exec \"$@\""
|
|
write_file($$OUT_PWD/android-build/resources/lib/$${ANDROID_TARGET_ARCH}/wrap.sh, ANDROID_WRAP_SH_CONTENT) | error()
|
|
libclang_rt.path = /libs/$$ANDROID_TARGET_ARCH/
|
|
libclang_rt.files = "$${ANDROID_LIBCLANG_RT_PATH}/$${ANDROID_LIBCLANG_RT_FILE}"
|
|
INSTALLS += libclang_rt
|
|
}
|
|
}
|
|
|
|
sanitize_memory {
|
|
QMAKE_CFLAGS += $$QMAKE_SANITIZE_MEMORY_CFLAGS
|
|
QMAKE_CXXFLAGS += $$QMAKE_SANITIZE_MEMORY_CXXFLAGS
|
|
QMAKE_LFLAGS += $$QMAKE_SANITIZE_MEMORY_LFLAGS
|
|
}
|
|
|
|
sanitize_thread {
|
|
QMAKE_CFLAGS += $$QMAKE_SANITIZE_THREAD_CFLAGS
|
|
QMAKE_CXXFLAGS += $$QMAKE_SANITIZE_THREAD_CXXFLAGS
|
|
QMAKE_LFLAGS += $$QMAKE_SANITIZE_THREAD_LFLAGS
|
|
}
|
|
|
|
sanitize_fuzzer_no_link {
|
|
QMAKE_CFLAGS += $$QMAKE_SANITIZE_FUZZERNL_CFLAGS
|
|
QMAKE_CXXFLAGS += $$QMAKE_SANITIZE_FUZZERNL_CXXFLAGS
|
|
QMAKE_LFLAGS += $$QMAKE_SANITIZE_FUZZERNL_LFLAGS
|
|
}
|
|
|
|
sanitize_undefined {
|
|
QMAKE_CFLAGS += $$QMAKE_SANITIZE_UNDEFINED_CFLAGS
|
|
QMAKE_CXXFLAGS += $$QMAKE_SANITIZE_UNDEFINED_CXXFLAGS
|
|
QMAKE_LFLAGS += $$QMAKE_SANITIZE_UNDEFINED_LFLAGS
|
|
}
|
|
|
|
QMAKE_CFLAGS += $$QMAKE_COMMON_SANITIZE_CFLAGS
|
|
QMAKE_CXXFLAGS += $$QMAKE_COMMON_SANITIZE_CXXFLAGS
|
|
|