已合并
【构建安全】为 glfw 开启 CFI #57
【构建安全】为 glfw 开启 CFI #57
已合并
huaixu-y创建于 7月20日
huaixu-y
huaixu-y
7月20日

关联Issue

#25

修改内容

为 glfw 共享库开启 CFI:cfi = truecfi_cross_dso = truedebug = false

验证

cfi 相关编译选项仅在 is_ohos 时生效,glfw 仅在 preview 平台参与构建,对现有构建无影响;GN 配置解析通过。

likedislike
Pull Request已成功合入, 合并人@openharmony_ci
(感谢 huaixu-y 的贡献)
huaixu-yhuaixu-y
7月20日 关联了issue:【构建安全】为 glfw 开启 CFI
openharmony_ciopenharmony_ci成员
7月20日 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
7月20日 评论:

感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接


Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.

likedislike
openharmony_ciopenharmony_ci成员
7月20日 添加了label:dco检查成功
huaixu-y
huaixu-y
7月20日 评论:

start build

likedislike
openharmony_ci
openharmony_ci成员
7月20日 评论:

首次触发
门禁构建开始,包含静态检查、代码编译和测试【dayu600_7885编译, x86_64_virt编译, ohos-host_mini_tdd编译, master_inner_build编译, dayu200测试, dayu200编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/6a5dd89f64650f998bfa81a4/runlist

likedislike
openharmony_ciopenharmony_ci成员
7月20日 添加了label:编译成功
openharmony_ciopenharmony_ci成员
7月20日 添加了label:静态检查成功
openharmony_ciopenharmony_ci成员
7月20日 添加了label:冒烟测试成功
openharmony_ciopenharmony_ci成员
7月20日 通过测试
openharmony_ci
openharmony_ci成员
7月20日 评论:

代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a5dd89f64650f998bfa81a4/runlist

静态检查:

# check type result report
1 codeCheck pass >>>

编译测试:
# Device build result test result package
1 dayu200 success success >>>
2 master_inner_build success(IGNORE) NA >>>
3 ohos-host_mini_tdd success NA >>>
4 x86_64_virt success NA >>>
5 dayu600_7885 (IGNORE) NA >>>

likedislike
openharmony_ciopenharmony_ci成员
7月20日 删除了label:waiting_on_author
openharmony_ciopenharmony_ci成员
7月20日 添加了label:waiting_for_review
openharmony_ci
openharmony_ci成员
7月20日 评论:

您好,Committer @seaside_wu1 @lihao71 ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @seaside_wu1 @lihao71 . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
seaside_wu1seaside_wu1成员
7月21日 通过审查
openharmony_ci
openharmony_ci成员
7月21日 评论:

验证结果已超过12小时,之前验证结果无效,自动重新触发构建,请关注最新验证结果

likedislike
openharmony_ci
openharmony_ci成员
7月21日 评论:

start build

likedislike
openharmony_ciopenharmony_ci成员
7月21日 删除了label:编译成功
openharmony_ciopenharmony_ci成员
7月21日 删除了label:静态检查成功
openharmony_ciopenharmony_ci成员
7月21日 删除了label:冒烟测试成功
openharmony_ci
openharmony_ci成员
7月21日 评论:

上次构建已超过12小时,重新全量验证,重置所有关联PR的验证状态
门禁构建开始,包含静态检查、代码编译和测试【x86_64_virt编译, dayu200测试, dayu200编译, master_inner_build编译, ohos-host_mini_tdd编译, dayu600_7885编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/6a5ed48d64650f998b444995/runlist

likedislike
openharmony_ciopenharmony_ci成员
7月21日 添加了label:编译成功
openharmony_ciopenharmony_ci成员
7月21日 添加了label:静态检查成功
openharmony_ciopenharmony_ci成员
7月21日 添加了label:冒烟测试成功
openharmony_ciopenharmony_ci成员
7月21日 通过测试
openharmony_ci
openharmony_ci成员
7月21日 评论:

代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a5ed48d64650f998b444995/runlist

静态检查:

# check type result report
1 codeCheck pass >>>

编译测试:
# Device build result test result package
1 dayu200 success success >>>
2 master_inner_build success(IGNORE) NA >>>
3 ohos-host_mini_tdd success NA >>>
4 x86_64_virt success NA >>>
5 dayu600_7885 failed(IGNORE)(trigger pipeline timeout) NA >>>

likedislike
openharmony_ci
openharmony_ci成员
7月21日 评论:

您好,Committer @seaside_wu1 @lihao71 ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @seaside_wu1 @lihao71 . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
openharmony_ciopenharmony_ci成员
7月21日 关闭了关联的issue
openharmony_ciopenharmony_ci成员
7月21日 合入了pull request,合并节点 SHA:1d2c360116ad1e89c7065991603a93cb6e007180
openharmony_ciopenharmony_ci成员
7月21日 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
7月21日 添加了label:merged
LyBbq17 天前进行代码检视1
BUILD.gn
@@ -25,2 +25,4 @@
2525ohos_shared_library("glfw") {
2626 branch_protector_ret = "pac_ret"
27+ sanitize = {
28+ cfi = true
LyBbq17 天前评论:

新增cfi,校验防止下开启CFI后,无法正常启动应用

likedislike
LLyBbq
17 天前 解决了最后一个问题