Aaron Ballman, principal Clang compiler steward and participant in the WG21 (C++) and WG14 (C) standards development teams, has initiated a discussion regarding the addition of a security enhancement mode in the Clang compiler. This new mode will allow a set of options to be activated simultaneously to enhance protection, similar to the `-fhardened` flag added in GCC 14, which activates options like `-D_FORTIFY_SOURCE=3 -D_GLIBCXX_ASSERTIONS -ftrivial-auto-var-init=zero -fPIE -pie -Wl,-z,relro,-z,now -fstack-protector-strong -fstack-clash-protection -fcf-protection=full`.
It is noted that work is currently underway to add security enhancement features to the C and C++ standards, but this process is not quick. While individual options with additional protection mechanisms are already available in Clang, these security methods often lead to incompatibilities with existing code or ABI violations, preventing them from being activated by default. Furthermore, such options are scattered (compilation control flags, hardware architecture-specific instruction generation flags, warnings, diagnostic modes, macros), poorly documented, and often overlooked by many developers.
A unified setting will streamline the process of enabling security-related options and simplify their application. Several activation methods for the enhanced security mode are being considered, such as activation via the `-fhardened` flag, the configuration set `--config=hardened`, a separate driver (`clang --driver-mode`), or separate options `-fhardened, -mhardened, and -Whardened`, linked to compilation, code generation, and warning output. The mode may encompass:
- Compiler capabilities: `-ftrivial-auto-var-init`, `-fPIE`, `-fcf-protection`, etc.
- Capabilities linked to code generation for target platforms: `-mspeculative-load-hardening`, `-mlvi-hardening`, etc.
- Warnings: `-Wall`, `-Wextra`, `-Werror=return-type`, etc.
- Security enhancement modes in the standard library of functions.
- Macros: `_FORTIFY_SOURCE`, `_GLIBCXX_ASSERTIONS`, etc.
- Requirement for explicit selection of the language standard used.
- Refusal to compile code using obsolete standards C89 and C++98.
- Passing additional flags to the linker, for instance, to enable address randomization.
Sursa: opennet.ro
