Clang prévoit d'ajouter un mode de sécurité renforcé

Aaron Ballman, principal compiler maintainer of Clang and a member of the WG21 (C++) and WG14 (C) standard development teams, has initiated a discussion on adding a security hardening mode to the Clang compiler. The new mode will allow users to activate a set of options for enhanced protection, similar to the '-fhardened' flag introduced in GCC 14, which activates options like '-D_FORTIFY_SOURCE=3 -D_GLIBCXX_ASSERTIONS -ftrivial-auto-var-init=zero -fPIE -pie -Wl,-z,relro,-z,now -fstack-protector-strong -fstack-clash-protection -fcf-protection=full'.

It is noted that work is currently underway to add security hardening features to the C and C++ standards, but this process is slow, despite individual options with additional protection mechanisms already being available in Clang. The implemented protection methods often lead to specific incompatibilities with existing code or ABI violations, preventing them from being activated by default. Additionally, these options are scattered (flags for compilation control, flags for machine instruction generation tied to hardware architectures, warnings, diagnostic modes, macros), poorly documented, and fall off the radar for many developers.

A unified setting will standardize the enabling of security-related options and simplify their application. Several options for activating the security hardening mode are being considered, such as activation through the '-fhardened' flag, a settings set like '--config=hardened', a separate driver (clang --driver-mode), or separate options '-fhardened, -mhardened and -Whardened' tied to compilation, code generation, and warning output. The mode may cover:

  • Compiler features: -ftrivial-auto-var-init, -fPIE, -fcf-protection, etc.
  • Features tied to code generation for target platforms: -mspeculative-load-hardening, -mlvi-hardening, etc.
  • Warnings: -Wall, -Wextra, -Werror=return-type, etc.
  • Security enhancement modes in the standard function library.
  • Macros: _FORTIFY_SOURCE, _GLIBCXX_ASSERTIONS, etc.
  • Requirement for explicit selection of the used language standard.
  • Refusal to compile code using outdated C89 and C++98 standards.
  • Passing additional flags to the linker, for example, to enable address randomization.

Source : opennet.ru

Acheter un hébergement fiable pour les sites avec protection DDoS, serveurs VPS VDS 🔥 Acheter un hébergement fiable pour les sites avec protection DDoS, serveurs VPS VDS | ProHoster