test/encoding: use setarch -R for ASAN builds in readable.sh#67531
Open
test/encoding: use setarch -R for ASAN builds in readable.sh#67531
Conversation
When running readable.sh with a WITH_ASAN=ON build of ceph-dencoder, ASAN processes need to find a contiguous 16+ TB shadow memory region (1/8 of the 128 TB x86-64 user VA space). High ASLR entropy can fragment the VA space, preventing ASAN from finding a suitable region. Instead of requiring system-wide vm.mmap_rnd_bits=28 (which weakens ASLR security for the entire host), wrap ceph-dencoder with 'setarch $(uname -m) -R' when ASAN is detected. This disables ASLR only for the specific ceph-dencoder processes, with no system-wide security impact. Also simplify parallelism logic: extract NPROC calculation into a shared variable and use it consistently across FreeBSD, Darwin, and Linux. Reference: https://clang.llvm.org/docs/AddressSanitizer.html Signed-off-by: Kefu Chai <k.chai@proxmox.com>
14 tasks
Contributor
Author
|
@ceph/core hello maintainers, could you help review this change? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When running readable.sh with a WITH_ASAN=ON build of ceph-dencoder, ASAN processes need to find a contiguous 16+ TB shadow memory region (1/8 of the 128 TB x86-64 user VA space). High ASLR entropy can fragment the VA space, preventing ASAN from finding a suitable region.
Instead of requiring system-wide vm.mmap_rnd_bits=28 (which weakens ASLR security for the entire host), wrap ceph-dencoder with 'setarch $(uname -m) -R' when ASAN is detected. This disables ASLR only for the specific ceph-dencoder processes, with no system-wide security impact.
Also simplify parallelism logic: extract NPROC calculation into a shared variable and use it consistently across FreeBSD, Darwin, and Linux.
Reference: https://clang.llvm.org/docs/AddressSanitizer.html
Contribution Guidelines
To sign and title your commits, please refer to Submitting Patches to Ceph.
If you are submitting a fix for a stable branch (e.g. "quincy"), please refer to Submitting Patches to Ceph - Backports for the proper workflow.
When filling out the below checklist, you may click boxes directly in the GitHub web UI. When entering or editing the entire PR message in the GitHub web UI editor, you may also select a checklist item by adding an
xbetween the brackets:[x]. Spaces and capitalization matter when checking off items this way.Checklist
Show available Jenkins commands
jenkins test classic perfJenkins Job | Jenkins Job Definitionjenkins test crimson perfJenkins Job | Jenkins Job Definitionjenkins test signedJenkins Job | Jenkins Job Definitionjenkins test make checkJenkins Job | Jenkins Job Definitionjenkins test make check arm64Jenkins Job | Jenkins Job Definitionjenkins test submodulesJenkins Job | Jenkins Job Definitionjenkins test dashboardJenkins Job | Jenkins Job Definitionjenkins test dashboard cephadmJenkins Job | Jenkins Job Definitionjenkins test apiJenkins Job | Jenkins Job Definitionjenkins test docsReadTheDocs | Github Workflow Definitionjenkins test ceph-volume allJenkins Jobs | Jenkins Jobs Definitionjenkins test windowsJenkins Job | Jenkins Job Definitionjenkins test rook e2eJenkins Job | Jenkins Job DefinitionYou must only issue one Jenkins command per-comment. Jenkins does not understand
comments with more than one command.