feat: add support for sanitization and fuzzing in the Windows cross-compilation scenario - #1463
feat: add support for sanitization and fuzzing in the Windows cross-compilation scenario#1463Ron (rjaegers) wants to merge 10 commits into
Conversation
There was a problem hiding this comment.
🟢 Approval recommended
The reviewed changes are covered by integration tests and have no unresolved blocking issues.
Pull request overview
Adds a CMake preset and integration coverage for clang-cl AddressSanitizer and UndefinedBehaviorSanitizer builds.
Changes:
- Adds the
clang-cl-sanitizerspreset. - Adds Bats coverage for sanitizer builds.
- Reformats existing target lists.
File summaries
| File | Description |
|---|---|
test/cpp/workspace/CMakePresets.json |
Defines the clang-cl sanitizer build preset. |
test/cpp/integration-tests.bats |
Verifies sanitizer targets build successfully. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 23 | 0 | 0 | 0.31s | ||
| ✅ DOCKERFILE | hadolint | 4 | 0 | 0 | 0.42s | ||
| ✅ JSON | npm-package-json-lint | yes | no | no | 0.55s | ||
| ✅ JSON | prettier | 46 | 8 | 0 | 0 | 0.87s | |
| ✅ JSON | v8r | 46 | 0 | 0 | 13.9s | ||
| ✅ MARKDOWN | markdownlint | 13 | 0 | 0 | 0 | 1.14s | |
| ✅ MARKDOWN | markdown-table-formatter | 13 | 0 | 0 | 0 | 0.26s | |
| ✅ REPOSITORY | betterleaks | yes | no | no | 1.22s | ||
| ✅ REPOSITORY | checkov | yes | no | no | 21.0s | ||
| ✅ REPOSITORY | git_diff | yes | no | no | 0.02s | ||
| ✅ REPOSITORY | grype | yes | no | no | 77.51s | ||
| osv-scanner | yes | 2 | no | 1.78s | |||
| ✅ REPOSITORY | secretlint | yes | no | no | 2.91s | ||
| ✅ REPOSITORY | syft | yes | no | no | 5.22s | ||
| ✅ REPOSITORY | trivy | yes | no | no | 10.94s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.52s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 3.87s | ||
| lychee | 119 | 1 | 0 | 10.38s | |||
| ✅ YAML | prettier | 36 | 0 | 0 | 0 | 2.28s | |
| ✅ YAML | v8r | 36 | 0 | 0 | 10.91s | ||
| ✅ YAML | yamllint | 36 | 0 | 0 | 1.34s |
Detailed Issues
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....148
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1
Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden
Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 2 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned package-lock.json file and found 73 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned .github/actions/update-vscode-extensions/package-lock.json file and found 288 packages
End status: 84 dirs visited, 285 inodes visited, 9 Extract calls, 45.640594ms elapsed, 45.640784ms wall time
Total 3 packages affected by 4 known vulnerabilities (0 Critical, 2 High, 0 Medium, 0 Low, 2 Unknown) from 2 ecosystems.
2 vulnerabilities can be fixed.
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110 | | crates.io | bare-metal | 0.2.5 | -- | test/embedded-rust/workspace/cortex-m/Cargo.lock |
| https://osv.dev/RUSTSEC-2026-0110 | | crates.io | bare-metal | 0.2.5 | -- | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
| https://osv.dev/GHSA-mh99-v99m-4gvg | 7.5 | npm | brace-expansion (dev) | 5.0.7 | 5.0.8 | package-lock.json |
| https://osv.dev/GHSA-rgw5-rvv9-x895 | 7.5 | npm | brace-expansion (dev) | 5.0.7 | 5.0.9 | package-lock.json |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
See detailed reports in MegaLinter artifacts
You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
- oxsecurity/megalinter/flavors/salesforce@v10.0.0 (57 linters)
- oxsecurity/megalinter/flavors/javascript@v10.0.0 (62 linters)
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
Co-Authored-By: Finnean van den Boorn <48602431+FMLGamer@users.noreply.github.com>
Co-Authored-By: Finnean van den Boorn <48602431+FMLGamer@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: Ron <45816308+rjaegers@users.noreply.github.com>
a7b1171 to
d3989ea
Compare
|

🚀 Hey, I have created a Pull Request
Description of changes
This pull request significantly improves and extends the project's support for cross-compiling C++ code to Windows using both the
clang-clandclangdrivers, with a particular focus on enabling, testing, and verifying fuzzing and sanitizer workflows for Windows targets. The changes introduce new build presets, CMake toolchain logic, runtime library handling, and comprehensive integration tests to ensure that Windows-targeted binaries are correctly built, linked, and validated.Key changes include:
Windows Cross-Compilation Support:
clang-clandclangdrivers, including dedicated presets for fuzzing and sanitizers. (CMakePresets.json) [1] [2]clang-windowstest target and corresponding CMake logic and source files. (clang-windows/CMakeLists.txt,clang-windows/main.cpp,CMakeLists.txt) [1] [2] [3]Toolchain and Linking Improvements:
clang-clto ensure sanitizer and fuzzing runtime libraries are properly linked via the compiler driver, resolving issues with direct linker invocation. (clang-cl/link-rules.cmake,clang-cl/toolchain.cmake) [1] [2]Container and Runtime Library Handling:
.devcontainer/cpp/Dockerfile) [1] [2] [3] [4] [5] [6] [7] [8] [9]Integration and Verification Testing:
clang-clandclangdrivers, including new helper functions to assert PE/COFF binary properties and runtime library presence. (integration-tests.bats) [1] [2] [3] [4] [5]integration-tests.bats)These changes collectively ensure robust, automated support for building, testing, and verifying Windows-targeted C++ binaries within the project's CI and development workflows.
✔️ Checklist