Skip to content

feat: add support for sanitization and fuzzing in the Windows cross-compilation scenario - #1463

Open
Ron (rjaegers) wants to merge 10 commits into
mainfrom
feat/clang-cl-sanitizer-support
Open

feat: add support for sanitization and fuzzing in the Windows cross-compilation scenario#1463
Ron (rjaegers) wants to merge 10 commits into
mainfrom
feat/clang-cl-sanitizer-support

Conversation

@rjaegers

@rjaegers Ron (rjaegers) commented Sep 12, 2026

Copy link
Copy Markdown
Member

🚀 Hey, I have created a Pull Request

Description of changes

This pull request significantly improves and extends the project's support for cross-compiling C++ code to Windows using both the clang-cl and clang drivers, with a particular focus on enabling, testing, and verifying fuzzing and sanitizer workflows for Windows targets. The changes introduce new build presets, CMake toolchain logic, runtime library handling, and comprehensive integration tests to ensure that Windows-targeted binaries are correctly built, linked, and validated.

Key changes include:

Windows Cross-Compilation Support:

  • Added new CMake build and test presets for cross-compiling to Windows using both clang-cl and clang drivers, including dedicated presets for fuzzing and sanitizers. (CMakePresets.json) [1] [2]
  • Introduced a new clang-windows test target and corresponding CMake logic and source files. (clang-windows/CMakeLists.txt, clang-windows/main.cpp, CMakeLists.txt) [1] [2] [3]

Toolchain and Linking Improvements:

  • Implemented a custom CMake link rules file for clang-cl to ensure sanitizer and fuzzing runtime libraries are properly linked via the compiler driver, resolving issues with direct linker invocation. (clang-cl/link-rules.cmake, clang-cl/toolchain.cmake) [1] [2]

Container and Runtime Library Handling:

  • Updated the development container Dockerfile to download, extract, and install Windows LLVM/Clang runtime libraries, ensuring that the correct versions are present for cross-compilation and that runtime checks enforce version consistency. (.devcontainer/cpp/Dockerfile) [1] [2] [3] [4] [5] [6] [7] [8] [9]

Integration and Verification Testing:

  • Expanded integration tests to cover building and verifying Windows executables, fuzzing, and sanitizer-enabled binaries for both clang-cl and clang drivers, including new helper functions to assert PE/COFF binary properties and runtime library presence. (integration-tests.bats) [1] [2] [3] [4] [5]
  • Updated Windows SDK installation in tests to use a newer manifest and include debug symbols. (integration-tests.bats)

These changes collectively ensure robust, automated support for building, testing, and verifying Windows-targeted C++ binaries within the project's CI and development workflows.

✔️ Checklist

  • I have followed the contribution guidelines for this repository
  • I have added tests for new behavior, and have not broken any existing tests
  • I have added or updated relevant documentation
  • I have verified that all added components are accounted for in the SBOM
  • I understand the image size delta and agree the functionality justifies it

Copilot AI lite review requested due to automatic review settings September 12, 2026 15:05
@rjaegers
Ron (rjaegers) requested a review from a team as a code owner September 12, 2026 15:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The reviewed changes are covered by integration tests and have no unresolved blocking issues.

Pull request overview

Adds a CMake preset and integration coverage for clang-cl AddressSanitizer and UndefinedBehaviorSanitizer builds.

Changes:

  • Adds the clang-cl-sanitizers preset.
  • Adds Bats coverage for sanitizer builds.
  • Reformats existing target lists.
File summaries
File Description
test/cpp/workspace/CMakePresets.json Defines the clang-cl sanitizer build preset.
test/cpp/integration-tests.bats Verifies sanitizer targets build successfully.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-base:edgeghcr.io/philips-software/amp-devcontainer-base:pr-1463

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 87.58 MB 87.58 MB +80 B (+0%) 🔼
linux/arm64 85.15 MB 85.15 MB 165 B (0%) 🔽

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 23 0 0 0.31s
✅ DOCKERFILE hadolint 4 0 0 0.42s
✅ JSON npm-package-json-lint yes no no 0.55s
✅ JSON prettier 46 8 0 0 0.87s
✅ JSON v8r 46 0 0 13.9s
✅ MARKDOWN markdownlint 13 0 0 0 1.14s
✅ MARKDOWN markdown-table-formatter 13 0 0 0 0.26s
✅ REPOSITORY betterleaks yes no no 1.22s
✅ REPOSITORY checkov yes no no 21.0s
✅ REPOSITORY git_diff yes no no 0.02s
✅ REPOSITORY grype yes no no 77.51s
⚠️ REPOSITORY osv-scanner yes 2 no 1.78s
✅ REPOSITORY secretlint yes no no 2.91s
✅ REPOSITORY syft yes no no 5.22s
✅ REPOSITORY trivy yes no no 10.94s
✅ REPOSITORY trivy-sbom yes no no 0.52s
✅ REPOSITORY trufflehog yes no no 3.87s
⚠️ SPELL lychee 119 1 0 10.38s
✅ YAML prettier 36 0 0 0 2.28s
✅ YAML v8r 36 0 0 10.91s
✅ YAML yamllint 36 0 0 1.34s

Detailed Issues

⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....148
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden

Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 2 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned package-lock.json file and found 73 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned .github/actions/update-vscode-extensions/package-lock.json file and found 288 packages
End status: 84 dirs visited, 285 inodes visited, 9 Extract calls, 45.640594ms elapsed, 45.640784ms wall time

Total 3 packages affected by 4 known vulnerabilities (0 Critical, 2 High, 0 Medium, 0 Low, 2 Unknown) from 2 ecosystems.
2 vulnerabilities can be fixed.

+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| OSV URL                             | CVSS | ECOSYSTEM | PACKAGE               | VERSION | FIXED VERSION | SOURCE                                            |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110   |      | crates.io | bare-metal            | 0.2.5   | --            | test/embedded-rust/workspace/cortex-m/Cargo.lock  |
| https://osv.dev/RUSTSEC-2026-0110   |      | crates.io | bare-metal            | 0.2.5   | --            | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
| https://osv.dev/GHSA-mh99-v99m-4gvg | 7.5  | npm       | brace-expansion (dev) | 5.0.7   | 5.0.8         | package-lock.json                                 |
| https://osv.dev/GHSA-rgw5-rvv9-x895 | 7.5  | npm       | brace-expansion (dev) | 5.0.7   | 5.0.9         | package-lock.json                                 |
+-------------------------------------+------+-----------+-----------------------+---------+---------------+---------------------------------------------------+

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-docs:edgeghcr.io/philips-software/amp-devcontainer-docs:pr-1463

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 219.12 MB 219.12 MB +465 B (+0%) 🔼
linux/arm64 214.83 MB 214.83 MB 1.06 kB (0%) 🔽

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edgeghcr.io/philips-software/amp-devcontainer-rust:pr-1463

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 443.49 MB 443.49 MB +581 B (+0%) 🔼
linux/arm64 393.02 MB 393.02 MB +2.52 kB (+0%) 🔼

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-rust:edgeghcr.io/philips-software/amp-devcontainer-embedded-rust:pr-1463

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 510.24 MB 510.24 MB +327 B (+0%) 🔼
linux/arm64 459.47 MB 459.46 MB 7.21 kB (0%) 🔽

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edgeghcr.io/philips-software/amp-devcontainer-cpp:pr-1463

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 407.71 MB 411.65 MB +3.94 MB (+0.97%) 🔼
linux/arm64 387.76 MB 391.69 MB +3.93 MB (+1.01%) 🔼

@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 12, 2026 15:13 — with GitHub Actions Active
@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-cpp:edgeghcr.io/philips-software/amp-devcontainer-embedded-cpp:pr-1463

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 609.99 MB 613.81 MB +3.82 MB (+0.63%) 🔼
linux/arm64 589.23 MB 593.13 MB +3.9 MB (+0.66%) 🔼

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Test Results

 25 files  ± 0   25 suites  ±0   1h 3m 12s ⏱️ + 43m 11s
 53 tests + 5   53 ✅ + 5  0 💤 ±0  0 ❌ ±0 
229 runs  +20  229 ✅ +20  0 💤 ±0  0 ❌ ±0 

Results for commit d3989ea. ± Comparison against base commit e7fc5ed.

♻️ This comment has been updated with latest results.

@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 12, 2026 19:01 — with GitHub Actions Active
@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 14, 2026 08:19 — with GitHub Actions Active
@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 14, 2026 09:43 — with GitHub Actions Active
@rjaegers Ron (rjaegers) changed the title feat: add test for clang-cl sanitizer support feat: add support for sanitization and fuzzing in the Windows cross-compilation scenario Sep 14, 2026
@rjaegers
Ron (rjaegers) force-pushed the feat/clang-cl-sanitizer-support branch from a7b1171 to d3989ea Compare September 14, 2026 11:51
@sonarqubecloud

sonarqubecloud Bot commented Sep 14, 2026

Copy link
Copy Markdown

Quality Gate Passed Quality Gate passed

Issues
1 New issue
1 Accepted issue

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 14, 2026 12:00 — with GitHub Actions Active
@rjaegers
Ron (rjaegers) deployed to acceptance-testing September 14, 2026 13:07 — with GitHub Actions Active
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants