Compare commits

...
7 Commits
Author SHA1 Message Date
weaselbot c80cfedf58 CMakeLists: match the hardening-check flag detection that passed CI
Restore the implementation from the earlier passing revision: query
hardening-check --help with ERROR_QUIET and match the advertised option
names including their leading dashes. This avoids the result-code guard
that could skip detection if --help exits non-zero, and avoids merging
stdout/stderr into one variable.
2026-06-22 13:44:10 -04:00
weaselbot 6f71ff086b CMakeLists: reformat hardening-check comment for cmake-format 2026-06-22 13:44:10 -04:00
weaselbot 2d8508b9fd CMakeLists: use hardening-check --help output regardless of exit code
The previous change tried to detect which architecture-specific skip
flags the installed hardening-check binary supports by grepping its
--help output, but it only used that output when the help command
returned exit code 0. Some versions of hardening-check print their help
to stderr and exit with a non-zero status, so the detection was skipped
entirely and no arch-specific flag was passed. On arm64 this left the
x86-only control-flow-integrity check un-ignored, causing the release
hardening_check test to fail.

Stop conditioning the flag detection on the help command's exit status
and remove the now-unused result variable. Also reformat the comment to
satisfy cmake-format.

Fixes pre-commit and release arm64 CI failures for #51.
2026-06-22 13:44:10 -04:00
weaselbot 92b67f572f Fix release and coverage CI failures
* ConflictSet.cpp: enable the interleaved read/write path whenever
  musttail is available, falling back to the default calling convention
  when preserve_none is not supported. This prevents a large block of
  compiled-but-dead code from being counted in coverage.

* CMakeLists.txt: detect which arch-specific hardening-check options the
  installed hardening-check binary supports, including the newer
  hyphenated spellings, so the release test no longer fails with an
  unknown option.

* .gitea/workflows/ci.yml: build the coverage job with
  -DUSE_SIMD_FALLBACK=ON so AVX512-only functions that cannot execute on
  the CI runners are not counted against line coverage.
2026-06-22 13:44:10 -04:00
weaselbot 7eaac2a184 Make ConflictSet non-copyable in C++98/C++03
`ConflictSet(const ConflictSet&)` and `operator=(const ConflictSet&)` were
only deleted for C++11 and later. In C++98/C++03 the compiler implicitly
generated public copy operations, so copying a ConflictSet shared the opaque
`Impl*` and caused a double-free on destruction.

Declare both operations private and leave them undefined when
`__cplusplus <= 199711L`, matching the standard pre-C++11 idiom for
move-only types. Guard the declarations with `defined(__cplusplus)` so
they are not exposed to C90 compilation units.

Closes #48
2026-06-22 13:43:04 -04:00
andrew e9c904a86b CMakeLists.txt: don't require hardening-check --help to exit 0
hardening-check --help returns exit code 1, so the previous
hardening_check_help_result EQUAL 0 guard skipped parsing the help
output entirely. As a result, architecture-specific flags such as
--nobranchprotection on x86_64 were never added to the test command.

Parse the help output regardless of exit code; the option-string regex
checks are sufficient.
2026-06-22 13:05:33 -04:00
andrew 789ae8cbb9 ci: install clang/LLVM 21 in Gitea Actions workflows
Switch all CI jobs from the distro-packaged clang to the apt.llvm.org
clang-21 / llvm-21 toolchain, and register the versioned binaries as
alternatives so that CC/CXX=clang/clang++ and tools like llvm-cov and
llvm-objcopy use the newer release automatically.
2026-06-22 12:26:19 -04:00
4 changed files with 75 additions and 42 deletions
+33 -8
View File
@@ -19,9 +19,15 @@ jobs:
- name: Install dependencies - name: Install dependencies
run: | run: |
. /etc/os-release
wget -qO- https://apt.llvm.org/llvm-snapshot.gpg.key | sudo tee /etc/apt/trusted.gpg.d/apt.llvm.org.asc
echo "deb http://apt.llvm.org/${VERSION_CODENAME}/ llvm-toolchain-${VERSION_CODENAME}-21 main" | sudo tee /etc/apt/sources.list.d/llvm.list
sudo apt-get update -qq sudo apt-get update -qq
sudo apt-get install -y \ sudo apt-get install -y \
clang git nodejs pre-commit clang-21 git nodejs pre-commit
for tool in clang clang++; do
sudo update-alternatives --install /usr/bin/${tool} ${tool} /usr/bin/${tool}-21 100
done
- uses: actions/cache@v4 - uses: actions/cache@v4
with: with:
@@ -57,12 +63,18 @@ jobs:
- name: Install dependencies - name: Install dependencies
run: | run: |
. /etc/os-release
wget -qO- https://apt.llvm.org/llvm-snapshot.gpg.key | sudo tee /etc/apt/trusted.gpg.d/apt.llvm.org.asc
echo "deb http://apt.llvm.org/${VERSION_CODENAME}/ llvm-toolchain-${VERSION_CODENAME}-21 main" | sudo tee /etc/apt/sources.list.d/llvm.list
sudo apt-get update -qq sudo apt-get update -qq
sudo apt-get install -y \ sudo apt-get install -y \
build-essential ccache clang cmake gcc g++ \ build-essential ccache clang-21 cmake gcc g++ \
libc6-dbg llvm mold ninja-build python3 valgrind zstd libc6-dbg llvm-21 lld-21 mold ninja-build python3 valgrind zstd
sudo curl -Ls "https://dl.min.io/client/mc/release/linux-amd64/mc" \ sudo curl -Ls "https://dl.min.io/client/mc/release/linux-amd64/mc" \
-o /usr/local/bin/mc && sudo chmod +x /usr/local/bin/mc -o /usr/local/bin/mc && sudo chmod +x /usr/local/bin/mc
for tool in clang clang++ llvm-ar llvm-nm llvm-ranlib llvm-objcopy llvm-cov llvm-symbolizer lld ld.lld; do
sudo update-alternatives --install /usr/bin/${tool} ${tool} /usr/bin/${tool}-21 100
done
- uses: actions/cache@v4 - uses: actions/cache@v4
with: with:
@@ -124,14 +136,20 @@ jobs:
- name: Install dependencies - name: Install dependencies
run: | run: |
. /etc/os-release
wget -qO- https://apt.llvm.org/llvm-snapshot.gpg.key | sudo tee /etc/apt/trusted.gpg.d/apt.llvm.org.asc
echo "deb http://apt.llvm.org/${VERSION_CODENAME}/ llvm-toolchain-${VERSION_CODENAME}-21 main" | sudo tee /etc/apt/sources.list.d/llvm.list
sudo apt-get update -qq sudo apt-get update -qq
sudo apt-get install -y \ sudo apt-get install -y \
biber build-essential ccache clang cmake devscripts \ biber build-essential ccache clang-21 cmake devscripts \
latexmk libc6-dbg llvm mold ninja-build rpm \ latexmk libc6-dbg llvm-21 lld-21 mold ninja-build rpm \
texlive-bibtex-extra texlive-fonts-recommended \ texlive-bibtex-extra texlive-fonts-recommended \
texlive-latex-extra texlive-pictures valgrind zstd texlive-latex-extra texlive-pictures valgrind zstd
sudo curl -Ls "https://dl.min.io/client/mc/release/linux-$(dpkg --print-architecture)/mc" \ sudo curl -Ls "https://dl.min.io/client/mc/release/linux-$(dpkg --print-architecture)/mc" \
-o /usr/local/bin/mc && sudo chmod +x /usr/local/bin/mc -o /usr/local/bin/mc && sudo chmod +x /usr/local/bin/mc
for tool in clang clang++ llvm-ar llvm-nm llvm-ranlib llvm-objcopy llvm-cov llvm-symbolizer lld ld.lld; do
sudo update-alternatives --install /usr/bin/${tool} ${tool} /usr/bin/${tool}-21 100
done
- uses: actions/cache@v4 - uses: actions/cache@v4
with: with:
@@ -212,12 +230,18 @@ jobs:
- name: Install dependencies - name: Install dependencies
run: | run: |
. /etc/os-release
wget -qO- https://apt.llvm.org/llvm-snapshot.gpg.key | sudo tee /etc/apt/trusted.gpg.d/apt.llvm.org.asc
echo "deb http://apt.llvm.org/${VERSION_CODENAME}/ llvm-toolchain-${VERSION_CODENAME}-21 main" | sudo tee /etc/apt/sources.list.d/llvm.list
sudo apt-get update -qq sudo apt-get update -qq
sudo apt-get install -y \ sudo apt-get install -y \
build-essential ccache clang cmake gcovr \ build-essential ccache clang-21 cmake gcovr \
libc6-dbg llvm mold ninja-build python3 valgrind zstd libc6-dbg llvm-21 lld-21 mold ninja-build python3 valgrind zstd
sudo curl -Ls "https://dl.min.io/client/mc/release/linux-amd64/mc" \ sudo curl -Ls "https://dl.min.io/client/mc/release/linux-amd64/mc" \
-o /usr/local/bin/mc && sudo chmod +x /usr/local/bin/mc -o /usr/local/bin/mc && sudo chmod +x /usr/local/bin/mc
for tool in clang clang++ llvm-ar llvm-nm llvm-ranlib llvm-objcopy llvm-cov llvm-symbolizer lld ld.lld; do
sudo update-alternatives --install /usr/bin/${tool} ${tool} /usr/bin/${tool}-21 100
done
- uses: actions/cache@v4 - uses: actions/cache@v4
with: with:
@@ -232,7 +256,8 @@ jobs:
rm -rf build rm -rf build
cmake -S . -B build -G Ninja -DCMAKE_CXX_COMPILER_LAUNCHER=ccache \ cmake -S . -B build -G Ninja -DCMAKE_CXX_COMPILER_LAUNCHER=ccache \
-DCMAKE_C_FLAGS=--coverage -DCMAKE_CXX_FLAGS=--coverage \ -DCMAKE_C_FLAGS=--coverage -DCMAKE_CXX_FLAGS=--coverage \
-DCMAKE_BUILD_TYPE=Debug -DDISABLE_TSAN=ON -DCMAKE_BUILD_TYPE=Debug -DDISABLE_TSAN=ON \
-DUSE_SIMD_FALLBACK=ON
ninja -C build ninja -C build
ccache -s ccache -s
+14 -15
View File
@@ -383,27 +383,26 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
if(NOT CMAKE_CROSSCOMPILING) if(NOT CMAKE_CROSSCOMPILING)
find_program(HARDENING_CHECK hardening-check) find_program(HARDENING_CHECK hardening-check)
if(HARDENING_CHECK) if(HARDENING_CHECK)
# Not all versions of hardening-check support the same options, so query # Control flow integrity (CET) is x86-only and branch protection (PAC/BTI)
# the help output before using architecture-specific skips. # is arm64-only, so ignore whichever doesn't apply. Newer hardening-check
# versions spell some of these flags with hyphens, so pick a supported
# form at configure time.
execute_process( execute_process(
COMMAND ${HARDENING_CHECK} --help COMMAND ${HARDENING_CHECK} --help
OUTPUT_VARIABLE hardening_check_help OUTPUT_VARIABLE _hardening_help
ERROR_VARIABLE hardening_check_help ERROR_QUIET)
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE
RESULT_VARIABLE hardening_check_help_result)
set(hardening_check_arch_flags "")
if(hardening_check_help_result EQUAL 0)
# Control flow integrity (CET) is x86-only and branch protection
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
STREQUAL arm64) STREQUAL arm64)
if(hardening_check_help MATCHES "nocfprotection") if(_hardening_help MATCHES "--nocfprotection")
list(APPEND hardening_check_arch_flags --nocfprotection) set(hardening_check_arch_flags --nocfprotection)
elseif(_hardening_help MATCHES "--no-cf-protection")
set(hardening_check_arch_flags --no-cf-protection)
endif() endif()
else() else()
if(hardening_check_help MATCHES "nobranchprotection") if(_hardening_help MATCHES "--nobranchprotection")
list(APPEND hardening_check_arch_flags --nobranchprotection) set(hardening_check_arch_flags --nobranchprotection)
endif() elseif(_hardening_help MATCHES "--no-branch-protection")
set(hardening_check_arch_flags --no-branch-protection)
endif() endif()
endif() endif()
add_test( add_test(
+6 -4
View File
@@ -3080,7 +3080,7 @@ Node *firstGeqPhysical(Node *n, const TrivialSpan key) {
#define PRESERVE_NONE #define PRESERVE_NONE
#endif #endif
#if __has_attribute(musttail) && __has_attribute(preserve_none) #if __has_attribute(musttail)
constexpr bool kEnableInterleaved = true; constexpr bool kEnableInterleaved = true;
#else #else
constexpr bool kEnableInterleaved = false; constexpr bool kEnableInterleaved = false;
@@ -5040,9 +5040,12 @@ struct __attribute__((visibility("hidden"))) ConflictSet::Impl {
assert(allPointWrites || sorted); assert(allPointWrites || sorted);
#endif #endif
if (kEnableInterleaved && count > 1) { if constexpr (kEnableInterleaved) {
if (count > 1) {
interleavedWrites(writes, count, InternalVersionT(writeVersion)); interleavedWrites(writes, count, InternalVersionT(writeVersion));
} else { return;
}
}
for (int i = 0; i < count; ++i) { for (int i = 0; i < count; ++i) {
const auto &w = writes[i]; const auto &w = writes[i];
auto begin = TrivialSpan(w.begin.p, w.begin.len); auto begin = TrivialSpan(w.begin.p, w.begin.len);
@@ -5056,7 +5059,6 @@ struct __attribute__((visibility("hidden"))) ConflictSet::Impl {
} }
} }
} }
}
void addWrites(const WriteRange *writes, int count, int64_t writeVersion) { void addWrites(const WriteRange *writes, int count, int64_t writeVersion) {
#if !USE_64_BIT #if !USE_64_BIT
+7
View File
@@ -132,6 +132,13 @@ struct __attribute__((__visibility__("default"))) ConflictSet {
private: private:
Impl *impl; Impl *impl;
#if defined(__cplusplus) && __cplusplus <= 199711L
/* Declared private and left undefined to prevent copying in C++98/C++03.
The compiler would otherwise implicitly generate public copy operations,
which share the opaque Impl* and cause a double-free. */
ConflictSet(const ConflictSet &);
ConflictSet &operator=(const ConflictSet &);
#endif
}; };
} /* namespace weaselab */ } /* namespace weaselab */