Skip to content

Commit 78f7a3f

Browse files
ebiggerskees
authored andcommitted
randstruct: disable Clang 15 support
The randstruct support released in Clang 15 is unsafe to use due to a bug that can cause miscompilations: "-frandomize-layout-seed inconsistently randomizes all-function-pointers structs" (llvm/llvm-project#60349). It has been fixed on the Clang 16 release branch, so add a Clang version check. Fixes: 035f7f8 ("randstruct: Enable Clang support") Cc: [email protected] Signed-off-by: Eric Biggers <[email protected]> Acked-by: Nick Desaulniers <[email protected]> Reviewed-by: Nathan Chancellor <[email protected]> Reviewed-by: Bill Wendling <[email protected]> Signed-off-by: Kees Cook <[email protected]> Link: https://lore.kernel.org/r/[email protected]
1 parent 04ffde1 commit 78f7a3f

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

security/Kconfig.hardening

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -281,6 +281,9 @@ endmenu
281281

282282
config CC_HAS_RANDSTRUCT
283283
def_bool $(cc-option,-frandomize-layout-seed-file=/dev/null)
284+
# Randstruct was first added in Clang 15, but it isn't safe to use until
285+
# Clang 16 due to https://github.com/llvm/llvm-project/issues/60349
286+
depends on !CC_IS_CLANG || CLANG_VERSION >= 160000
284287

285288
choice
286289
prompt "Randomize layout of sensitive kernel structures"

0 commit comments

Comments
 (0)