Skip to content

Commit 78f7a3f

Browse files
ebiggerskees
authored andcommitted
randstruct: disable Clang 15 support
The randstruct support released in Clang 15 is unsafe to use due to a bug that can cause miscompilations: "-frandomize-layout-seed inconsistently randomizes all-function-pointers structs" (llvm/llvm-project#60349). It has been fixed on the Clang 16 release branch, so add a Clang version check. Fixes: 035f7f8 ("randstruct: Enable Clang support") Cc: stable@vger.kernel.org Signed-off-by: Eric Biggers <ebiggers@google.com> Acked-by: Nick Desaulniers <ndesaulniers@google.com> Reviewed-by: Nathan Chancellor <nathan@kernel.org> Reviewed-by: Bill Wendling <morbo@google.com> Signed-off-by: Kees Cook <keescook@chromium.org> Link: https://lore.kernel.org/r/20230208065133.220589-1-ebiggers@kernel.org
1 parent 04ffde1 commit 78f7a3f

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

security/Kconfig.hardening

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -281,6 +281,9 @@ endmenu
281281

282282
config CC_HAS_RANDSTRUCT
283283
def_bool $(cc-option,-frandomize-layout-seed-file=/dev/null)
284+
# Randstruct was first added in Clang 15, but it isn't safe to use until
285+
# Clang 16 due to https://github.com/llvm/llvm-project/issues/60349
286+
depends on !CC_IS_CLANG || CLANG_VERSION >= 160000
284287

285288
choice
286289
prompt "Randomize layout of sensitive kernel structures"

0 commit comments

Comments
 (0)