Skip to content

Add support for -Zsanitizer-cfi-minimal-runtime - #162493

Merged
rust-bors[bot] merged 12 commits into
rust-lang:mainfrom
jakos-sec:ubsan-runtime-minimal
Sep 29, 2026
Merged

rust-bors[bot] merged 12 commits into
rust-lang:mainfrom
jakos-sec:ubsan-runtime-minimal

Conversation

@jakos-sec

@jakos-sec jakos-sec commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

View all comments

For production use, we should only link in the ubsan_minimal runtime,
instead of the complete ubsan runtime. This adds support for both
cfi-recover and cfi-diag to use the minimal runtime when
-Zsanitizer-cfi-minimal-runtime is specified.

This also includes tests, to ensure the flag can only be used if either
cfi-recover or cfi-diag is enabled, it doesn't disrupt the original
behavior, and links in the correct runtime when specified.

cc @1c3t3a

?r rcvalle

@rustbot

rustbot commented Sep 8, 2026

Copy link
Copy Markdown
Collaborator

Some changes occurred in tests/codegen-llvm/sanitizer

cc @rcvalle

This PR changes how LLVM is built. Consider updating src/bootstrap/download-ci-llvm-stamp.

Some changes occurred in tests/ui/sanitizer

cc @rcvalle

@rustbot rustbot added A-LLVM Area: Code generation parts specific to LLVM. Both correctness bugs and optimization-related issues. A-run-make Area: port run-make Makefiles to rmake.rs PG-exploit-mitigations Project group: Exploit mitigations S-waiting-on-review Status: Awaiting review from the assignee but also interested parties. T-bootstrap Relevant to the bootstrap subteam: Rust's build system (x.py and src/bootstrap) T-compiler Relevant to the compiler team, which will review and decide on the PR/issue. labels Sep 8, 2026
@rustbot

rustbot commented Sep 8, 2026

Copy link
Copy Markdown
Collaborator

r? @folkertdev

rustbot has assigned @folkertdev.
They will have a look at your PR within the next two weeks and either review your PR or reassign to another reviewer.

Use r? to explicitly pick a reviewer

Why was this reviewer chosen?

The reviewer was selected based on:

  • Owners of files modified in this PR: compiler
  • compiler expanded to 76 candidates
  • Random selection from 20 candidates

@folkertdev

Copy link
Copy Markdown
Contributor

r? rcvalle

@rustbot rustbot assigned rcvalle and unassigned folkertdev Sep 8, 2026
Comment thread compiler/rustc_codegen_llvm/src/builder.rs
@rcvalle

rcvalle commented Sep 8, 2026

Copy link
Copy Markdown
Member

@jakos-sec

Copy link
Copy Markdown
Contributor Author

Would you mind adding tests it similarly to https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/generalize-pointers-requires-cfi.rs and https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/normalize-integers-requires-cfi.rs (i.e., requires CFI, not just CFI diagnostics or CFI recovery)?

I'm not entirely sure what the best behavior is here. -Zsanitizer-cfi-minimal-runtime is strictly dependent on -Zsanitizer-cfi-recover / -Zsanitizer-cfi-diag (and both of those are dependent on -Zsanitizer=cfi.

Now that we have tests that cfi-diag and cfi-recover require cfi, this should already be enough. Otherwise we would need to add a separate error message for all the different cases (you need a specific error message for -Zsanitizer-cfi-minimal-runtime if used without cfi, without cfi-recover/diag or used without both).

@jakos-sec
jakos-sec force-pushed the ubsan-runtime-minimal branch from b2af13f to 5ee5ebd Compare September 10, 2026 14:43
@rust-log-analyzer

This comment has been minimized.

@jakos-sec

Copy link
Copy Markdown
Contributor Author

The job test-aarch64-gnu-llvm-21-1 failed! Check out the build log: (web) (plain enhanced) (plain)

Click to see the possible cause of the failure (guessed by this bot)

Failing tests I need to look at / fix before another round of reviews.

@rcvalle

rcvalle commented Sep 10, 2026

Copy link
Copy Markdown
Member

Would you mind adding tests it similarly to https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/generalize-pointers-requires-cfi.rs and https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/normalize-integers-requires-cfi.rs (i.e., requires CFI, not just CFI diagnostics or CFI recovery)?

Would you mind adding tests it similarly to https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/generalize-pointers-requires-cfi.rs and https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/normalize-integers-requires-cfi.rs (i.e., requires CFI, not just CFI diagnostics or CFI recovery)?

I'm not entirely sure what the best behavior is here. -Zsanitizer-cfi-minimal-runtime is strictly dependent on -Zsanitizer-cfi-recover / -Zsanitizer-cfi-diag (and both of those are dependent on -Zsanitizer=cfi.

Now that we have tests that cfi-diag and cfi-recover require cfi, this should already be enough. Otherwise we would need to add a separate error message for all the different cases (you need a specific error message for -Zsanitizer-cfi-minimal-runtime if used without cfi, without cfi-recover/diag or used without both).

Yes, I think this is how the Rust compiler does it and historically this is how we've been doing it. This also aligns with the philosophy of having clear and helpful error messages. In this case, with only one incorrect run, the user would be able to see both requirements without requiring one additional run.

@jakos-sec
jakos-sec force-pushed the ubsan-runtime-minimal branch from 5ee5ebd to b47e873 Compare September 11, 2026 09:02
@jakos-sec

Copy link
Copy Markdown
Contributor Author

Would you mind adding tests it similarly to https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/generalize-pointers-requires-cfi.rs and https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/normalize-integers-requires-cfi.rs (i.e., requires CFI, not just CFI diagnostics or CFI recovery)?

Would you mind adding tests it similarly to https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/generalize-pointers-requires-cfi.rs and https://github.com/rust-lang/rust/blob/main/tests/ui/sanitizer/cfi/normalize-integers-requires-cfi.rs (i.e., requires CFI, not just CFI diagnostics or CFI recovery)?

I'm not entirely sure what the best behavior is here. -Zsanitizer-cfi-minimal-runtime is strictly dependent on -Zsanitizer-cfi-recover / -Zsanitizer-cfi-diag (and both of those are dependent on -Zsanitizer=cfi.
Now that we have tests that cfi-diag and cfi-recover require cfi, this should already be enough. Otherwise we would need to add a separate error message for all the different cases (you need a specific error message for -Zsanitizer-cfi-minimal-runtime if used without cfi, without cfi-recover/diag or used without both).

Yes, I think this is how the Rust compiler does it and historically this is how we've been doing it. This also aligns with the philosophy of having clear and helpful error messages. In this case, with only one incorrect run, the user would be able to see both requirements without requiring one additional run.

Makes sense, should be added now.

The job test-aarch64-gnu-llvm-21-1 failed! Check out the build log: (web) (plain enhanced) (plain)
Click to see the possible cause of the failure (guessed by this bot)

Failing tests I need to look at / fix before another round of reviews.

These should also be addressed now.

@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

@rust-log-analyzer

This comment has been minimized.

@rust-bors

This comment has been minimized.

jakos-sec and others added 5 commits September 21, 2026 09:43
For production use, we should only link in the ubsan_minimal runtime,
instead of the complete ubsan runtime. This adds support for both
cfi-recover and cfi-diag to use the minimal runtime when
`-Zsanitizer-cfi-minimal-runtime` is specified.

This also includes tests, to ensure the flag can only be used if either
cfi-recover or cfi-diag is enabled, it doesn't disrupt the original
behavior, and links in the correct runtime when specified.

Co-Authored-By: Bastian Kersting <bkersting@google.com>
Co-Authored-By: Bastian Kersting <bkersting@google.com>
rust-bors Bot pushed a commit that referenced this pull request Sep 25, 2026
…uwer

Rollup of 7 pull requests

Successful merges:

 - #162493 (Add support for -Zsanitizer-cfi-minimal-runtime)
 - #163133 ([rustdoc] Fix invalid jump to def link when `#[rustc_allow_incoherent_impl]` is involved)
 - #163215 (Fix suggestion for Option to bool with proper precedence handling)
 - #163266 (More deferred liveness cleanups)
 - #163274 (Support -Z merge-functions with gcc and add stack-protector asm tests)
 - #163312 (Add rustdoc regression test for glob import of a crate that re-exports)
 - #163332 (Add some docs to `Global`)
@jhpratt

jhpratt commented Sep 26, 2026

Copy link
Copy Markdown
Member

@bors r- #163358 (comment)

---- [run-make] tests/run-make/sanitizer-cfi-runtime stdout ----

error: rmake recipe failed to complete
status: exit status: 1
command: cd "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out" && env -u RUSTFLAGS -u __STD_REMAP_DEBUGINFO_ENABLED AR="ar" BUILD_ROOT="/Users/runner/work/rust/rust/build/aarch64-apple-darwin" CC="cc" CC_DEFAULT_FLAGS="-ffunction-sections -fdata-sections -fPIC --target=arm64-apple-macosx -mmacosx-version-min=11 -w" CXX="c++" CXX_DEFAULT_FLAGS="-ffunction-sections -fdata-sections -fPIC --target=arm64-apple-macosx -mmacosx-version-min=11 -w -stdlib=libc++" DYLD_LIBRARY_PATH=":/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage0/lib/rustlib/aarch64-apple-darwin/lib" HOST_RUSTC_DYLIB_PATH="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib" LD_LIB_PATH_ENVVAR="DYLD_LIBRARY_PATH" LLVM_BIN_DIR="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/llvm/bin" LLVM_COMPONENTS="aarch64 aarch64asmparser aarch64codegen aarch64desc aarch64disassembler aarch64info aarch64utils abi aggressiveinstcombine all all-targets amdgpu amdgpuasmparser amdgpucodegen amdgpudesc amdgpudisassembler amdgpuinfo amdgputargetmca amdgpuutils analysis arm armasmparser armcodegen armdesc armdisassembler arminfo armutils asmparser asmprinter avr avrasmparser avrcodegen avrdesc avrdisassembler avrinfo binaryformat bitreader bitstreamreader bitwriter bpf bpfasmparser bpfcodegen bpfdesc bpfdisassembler bpfinfo cas cfguard cgdata codegen codegentypes core coroutines coverage csky cskyasmparser cskycodegen cskydesc cskydisassembler cskyinfo debuginfobtf debuginfocodeview debuginfodwarf debuginfodwarflowlevel debuginfogsym debuginfologicalview debuginfomsf debuginfopdb demangle dlltooldriver dtlto dwarfcfichecker dwarflinker dwarflinkerclassic dwarflinkerparallel dwp engine executionengine extensions filecheck frontendatomic frontenddirective frontenddriver frontendhlsl frontendoffloading frontendopenacc frontendopenmp fuzzercli fuzzmutate globalisel hexagon hexagonasmparser hexagoncodegen hexagondesc hexagondisassembler hexagoninfo hipstdpar instcombine instrumentation interfacestub interpreter ipo irprinter irreader jitlink libdriver lineeditor linker loongarch loongarchasmparser loongarchcodegen loongarchdesc loongarchdisassembler loongarchinfo lto m68k m68kasmparser m68kcodegen m68kdesc m68kdisassembler m68kinfo mc mca mcdisassembler mcjit mcparser mips mipsasmparser mipscodegen mipsdesc mipsdisassembler mipsinfo mirparser msp430 msp430asmparser msp430codegen msp430desc msp430disassembler msp430info native nativecodegen nvptx nvptxcodegen nvptxdesc nvptxinfo objcarcopts objcopy object objectyaml option orcdebugging orcjit orcshared orctargetprocess passes plugins powerpc powerpcasmparser powerpccodegen powerpcdesc powerpcdisassembler powerpcinfo profiledata remarks riscv riscvasmparser riscvcodegen riscvdesc riscvdisassembler riscvinfo riscvtargetmca runtimedyld sandboxir scalaropts selectiondag sparc sparcasmparser sparccodegen sparcdesc sparcdisassembler sparcinfo support supportlsp symbolize systemz systemzasmparser systemzcodegen systemzdesc systemzdisassembler systemzinfo tablegen target targetparser telemetry textapi textapibinaryreader transformutils vectorize webassembly webassemblyasmparser webassemblycodegen webassemblydesc webassemblydisassembler webassemblyinfo webassemblyutils windowsdriver windowsmanifest x86 x86asmparser x86codegen x86desc x86disassembler x86info x86targetmca xray xtensa xtensaasmparser xtensacodegen xtensadesc xtensadisassembler xtensainfo" LLVM_FILECHECK="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/llvm/bin/FileCheck" NODE="/opt/homebrew/bin/node" PYTHON="/opt/homebrew/opt/python@3.14/bin/python3.14" RUSTC="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/bin/rustc" RUSTDOC="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/bin/rustdoc" SOURCE_ROOT="/Users/runner/work/rust/rust" TARGET="aarch64-apple-darwin" TARGET_EXE_DYLIB_PATH="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/lib" __BOOTSTRAP_JOBS="3" __RMAKE_VERBOSE_SUBPROCESS_OUTPUT="1" __RUSTC_DEBUG_ASSERTIONS_ENABLED="1" __STD_DEBUG_ASSERTIONS_ENABLED="1" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake"
stdout: none
--- stderr -------------------------------
DYLD_LIBRARY_PATH="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out:/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib::/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage0/lib/rustlib/aarch64-apple-darwin/lib" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/bin/rustc" "-L" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out" "-Clto" "-Ccodegen-units=1" "-Ctarget-feature=-crt-static" "-Cunsafe-allow-abi-mismatch=sanitizer" "-Zsanitizer=cfi" "--print" "link-args" "program.rs" "--target=aarch64-apple-darwin"
output status: `exit status: 0`
=== STDOUT ===
env -u IPHONEOS_DEPLOYMENT_TARGET -u TVOS_DEPLOYMENT_TARGET -u XROS_DEPLOYMENT_TARGET LC_ALL="C" PATH="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/bin:/Users/runner/work/rust/rust/build/aarch64-apple-darwin/lld/bin:/opt/homebrew/lib/ruby/gems/3.3.0/bin:/opt/homebrew/opt/ruby@3.3/bin:/Users/runner/.local/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/Users/runner/.cargo/bin:/usr/local/opt/curl/bin:/usr/local/bin:/usr/local/sbin:/Users/runner/bin:/Users/runner/.yarn/bin:/Users/runner/Library/Android/sdk/tools:/Users/runner/Library/Android/sdk/platform-tools:/Library/Frameworks/Python.framework/Versions/Current/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands:/usr/bin:/bin:/usr/sbin:/sbin:/Users/runner/.dotnet/tools" SDKROOT="/Applications/Xcode_26.2.app/Contents/Developer/Platforms/MacOSX.platform/Developer/SDKs/MacOSX26.2.sdk" VSLANG="1033" ZERO_AR_DATE="1" "cc" "program.program.45572bc5f2b14090-cgu.0.rcgu.o" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/lib/libcompiler_builtins-69e41eb2221682ad.rlib" "-lSystem" "-lc" "-lm" "-arch" "arm64" "-mmacosx-version-min=11.0.0" "-L" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out" "-L" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/lib" "-o" "program" "-Wl,-dead_strip" "-nodefaultlibs"



=== STDERR ===



command failed at line 34
DYLD_LIBRARY_PATH="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out:/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib::/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage0/lib/rustlib/aarch64-apple-darwin/lib" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/bin/rustc" "-L" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out" "-Clto" "-Ccodegen-units=1" "-Ctarget-feature=-crt-static" "-Cunsafe-allow-abi-mismatch=sanitizer" "-Zsanitizer=cfi" "-Zsanitizer-cfi-diag=true" "--print" "link-args" "program.rs" "--target=aarch64-apple-darwin"
output status: `exit status: 1`
=== STDOUT ===
env -u IPHONEOS_DEPLOYMENT_TARGET -u TVOS_DEPLOYMENT_TARGET -u XROS_DEPLOYMENT_TARGET LC_ALL="C" PATH="/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/bin:/Users/runner/work/rust/rust/build/aarch64-apple-darwin/lld/bin:/opt/homebrew/lib/ruby/gems/3.3.0/bin:/opt/homebrew/opt/ruby@3.3/bin:/Users/runner/.local/bin:/opt/homebrew/bin:/opt/homebrew/sbin:/Users/runner/.cargo/bin:/usr/local/opt/curl/bin:/usr/local/bin:/usr/local/sbin:/Users/runner/bin:/Users/runner/.yarn/bin:/Users/runner/Library/Android/sdk/tools:/Users/runner/Library/Android/sdk/platform-tools:/Library/Frameworks/Python.framework/Versions/Current/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands:/usr/bin:/bin:/usr/sbin:/sbin:/Users/runner/.dotnet/tools" SDKROOT="/Applications/Xcode_26.2.app/Contents/Developer/Platforms/MacOSX.platform/Developer/SDKs/MacOSX26.2.sdk" VSLANG="1033" ZERO_AR_DATE="1" "cc" "-Wl,-rpath,/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/lib" "-lrustc-nightly_rt.ubsan" "program.program.45572bc5f2b14090-cgu.0.rcgu.o" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/lib/libcompiler_builtins-69e41eb2221682ad.rlib" "-lSystem" "-lc" "-lm" "-arch" "arm64" "-mmacosx-version-min=11.0.0" "-L" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out" "-L" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/stage2/lib/rustlib/aarch64-apple-darwin/lib" "-o" "program" "-Wl,-dead_strip" "-nodefaultlibs"



=== STDERR ===
error: linking with `cc` failed: exit status: 1
  |
  = note:  "cc" "-Wl,-rpath,<sysroot>/lib/rustlib/aarch64-apple-darwin/lib" "-lrustc-nightly_rt.ubsan" "<1 object files omitted>" "<sysroot>/lib/rustlib/aarch64-apple-darwin/lib/libcompiler_builtins-*.rlib" "-lSystem" "-lc" "-lm" "-arch" "arm64" "-mmacosx-version-min=11.0.0" "-L" "/Users/runner/work/rust/rust/build/aarch64-apple-darwin/test/run-make/sanitizer-cfi-runtime/rmake_out" "-L" "<sysroot>/lib/rustlib/aarch64-apple-darwin/lib" "-o" "program" "-Wl,-dead_strip" "-nodefaultlibs"
  = note: some arguments are omitted. use `--verbose` to show all linker arguments
  = note: ld: library 'rustc-nightly_rt.ubsan' not found
          clang: error: linker command failed with exit code 1 (use -v to see invocation)
          

error: aborting due to 1 previous error
------------------------------------------

Given two rollup failures, consider running a try job before further approval.

@rust-bors rust-bors Bot added S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. and removed S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. labels Sep 26, 2026
@rust-bors

rust-bors Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

This pull request was unapproved.

This PR was contained in a rollup (#163358), which was unapproved.

View changes since this unapproval

@jakos-sec

Copy link
Copy Markdown
Contributor Author

@bors try

@rust-bors

rust-bors Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

@jakos-sec: 🔑 Insufficient privileges: not in try users

@jakos-sec

Copy link
Copy Markdown
Contributor Author

@rcvalle I don't seem to have try privileges, could you start one? :/

@rcvalle

rcvalle commented Sep 28, 2026

Copy link
Copy Markdown
Member

@bors try

@rust-bors

This comment has been minimized.

rust-bors Bot pushed a commit that referenced this pull request Sep 28, 2026
Add support for -Zsanitizer-cfi-minimal-runtime
@rust-bors

rust-bors Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

☀️ Try build successful (CI)
Build commit: 06b1c2c (06b1c2cf618dd802ed7ce9b989622f057eb969e4)
Base parent: c1070d6 (c1070d69382b8d2f2eb65119c738a77d9e324c9e)

@rcvalle

rcvalle commented Sep 28, 2026

Copy link
Copy Markdown
Member

@bors r+

@rust-bors

rust-bors Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

📌 Commit 0879316 has been approved by rcvalle

It is now in the queue for this repository.

@rust-bors rust-bors Bot added S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. and removed S-waiting-on-author Status: This is awaiting some action (such as code changes or more information) from the author. labels Sep 28, 2026
JonathanBrouwer added a commit to JonathanBrouwer/rust that referenced this pull request Sep 28, 2026
…=rcvalle

Add support for -Zsanitizer-cfi-minimal-runtime

For production use, we should only link in the ubsan_minimal runtime,
instead of the complete ubsan runtime. This adds support for both
cfi-recover and cfi-diag to use the minimal runtime when
`-Zsanitizer-cfi-minimal-runtime` is specified.

This also includes tests, to ensure the flag can only be used if either
cfi-recover or cfi-diag is enabled, it doesn't disrupt the original
behavior, and links in the correct runtime when specified.

cc @1c3t3a

?r rcvalle
rust-bors Bot pushed a commit that referenced this pull request Sep 28, 2026
…uwer

Rollup of 15 pull requests

Successful merges:

 - #158936 (Add `std::fs::{Home|Media}Dirs`)
 - #129036 (Additional NonZero conversions)
 - #158997 (Avoid recording unnameable `extern crate` aliases in diagnostic metadata)
 - #161015 (Stabilize `funnel_shifts` (including `const`))
 - #161712 (Stabilize `Result::into_{ok,err}`)
 - #162493 (Add support for -Zsanitizer-cfi-minimal-runtime)
 - #162655 (next solver: prefer to select impl candidates over global where-clause candidates)
 - #162862 (Fix intra doc link resolution when a doc comment is composed of both inner and outer doc comment)
 - #163200 (make `RustaceansAreAwesome` satisfy trait bounds)
 - #163331 (Move `Arc` and `Rc` into `rcs` mod)
 - #163427 (implement #![feature(gca_adts)])
 - #163428 (do not complain about unstable target features on nightly)
 - #163444 (Add `stable_rustc` helper in `run-make-support`)
 - #163447 (Allow using different index types when reading and writing to tables)
 - #163450 (Force the correct type variable to never for method resolution on an adjusted never type)
tgross35 added a commit to tgross35/rust that referenced this pull request Sep 29, 2026
…=rcvalle

Add support for -Zsanitizer-cfi-minimal-runtime

For production use, we should only link in the ubsan_minimal runtime,
instead of the complete ubsan runtime. This adds support for both
cfi-recover and cfi-diag to use the minimal runtime when
`-Zsanitizer-cfi-minimal-runtime` is specified.

This also includes tests, to ensure the flag can only be used if either
cfi-recover or cfi-diag is enabled, it doesn't disrupt the original
behavior, and links in the correct runtime when specified.

cc @1c3t3a

?r rcvalle
rust-bors Bot pushed a commit that referenced this pull request Sep 29, 2026
Rollup of 9 pull requests

Successful merges:

 - #161015 (Stabilize `funnel_shifts` (including `const`))
 - #161712 (Stabilize `Result::into_{ok,err}`)
 - #162493 (Add support for -Zsanitizer-cfi-minimal-runtime)
 - #163427 (implement #![feature(gca_adts)])
 - #163390 (add `automatically_derived` attribute documentation)
 - #163428 (do not complain about unstable target features on nightly)
 - #163444 (Add `stable_rustc` helper in `run-make-support`)
 - #163447 (Allow using different index types when reading and writing to tables)
 - #163459 (Stabilize vec_try_remove)
@rust-bors
rust-bors Bot merged commit 538a927 into rust-lang:main Sep 29, 2026
14 checks passed
@rustbot rustbot added this to the 1.101.0 milestone Sep 29, 2026
pull Bot pushed a commit to LeeeeeeM/miri that referenced this pull request Sep 30, 2026
Rollup of 9 pull requests

Successful merges:

 - rust-lang/rust#161015 (Stabilize `funnel_shifts` (including `const`))
 - rust-lang/rust#161712 (Stabilize `Result::into_{ok,err}`)
 - rust-lang/rust#162493 (Add support for -Zsanitizer-cfi-minimal-runtime)
 - rust-lang/rust#163427 (implement #![feature(gca_adts)])
 - rust-lang/rust#163390 (add `automatically_derived` attribute documentation)
 - rust-lang/rust#163428 (do not complain about unstable target features on nightly)
 - rust-lang/rust#163444 (Add `stable_rustc` helper in `run-make-support`)
 - rust-lang/rust#163447 (Allow using different index types when reading and writing to tables)
 - rust-lang/rust#163459 (Stabilize vec_try_remove)
pull Bot pushed a commit to xtqqczze/rust-lang-rustc-dev-guide that referenced this pull request Sep 30, 2026
Rollup of 9 pull requests

Successful merges:

 - rust-lang/rust#161015 (Stabilize `funnel_shifts` (including `const`))
 - rust-lang/rust#161712 (Stabilize `Result::into_{ok,err}`)
 - rust-lang/rust#162493 (Add support for -Zsanitizer-cfi-minimal-runtime)
 - rust-lang/rust#163427 (implement #![feature(gca_adts)])
 - rust-lang/rust#163390 (add `automatically_derived` attribute documentation)
 - rust-lang/rust#163428 (do not complain about unstable target features on nightly)
 - rust-lang/rust#163444 (Add `stable_rustc` helper in `run-make-support`)
 - rust-lang/rust#163447 (Allow using different index types when reading and writing to tables)
 - rust-lang/rust#163459 (Stabilize vec_try_remove)
clarfonthey pushed a commit to clarfonthey/stdarch that referenced this pull request Sep 30, 2026
Rollup of 9 pull requests

Successful merges:

 - rust-lang/rust#161015 (Stabilize `funnel_shifts` (including `const`))
 - rust-lang/rust#161712 (Stabilize `Result::into_{ok,err}`)
 - rust-lang/rust#162493 (Add support for -Zsanitizer-cfi-minimal-runtime)
 - rust-lang/rust#163427 (implement #![feature(gca_adts)])
 - rust-lang/rust#163390 (add `automatically_derived` attribute documentation)
 - rust-lang/rust#163428 (do not complain about unstable target features on nightly)
 - rust-lang/rust#163444 (Add `stable_rustc` helper in `run-make-support`)
 - rust-lang/rust#163447 (Allow using different index types when reading and writing to tables)
 - rust-lang/rust#163459 (Stabilize vec_try_remove)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-LLVM Area: Code generation parts specific to LLVM. Both correctness bugs and optimization-related issues. A-run-make Area: port run-make Makefiles to rmake.rs PG-exploit-mitigations Project group: Exploit mitigations S-waiting-on-bors Status: Waiting on bors to run and complete tests. Bors will change the label on completion. T-bootstrap Relevant to the bootstrap subteam: Rust's build system (x.py and src/bootstrap) T-compiler Relevant to the compiler team, which will review and decide on the PR/issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants