Sanitizers
Purpose
Guide agents through choosing, enabling, and interpreting compiler runtime sanitizers for finding memory errors, undefined behaviour, data races, and memory leaks.
Triggers
- "My program has a memory error — which sanitizer do I use?"
- "How do I enable ASan?"
- "How do I interpret an ASan/UBSan/TSan report?"
- "ASan says heap-buffer-overflow — what does that mean?"
- "How do I suppress false positives in sanitizers?"
- "Can I use sanitizers in CI?"
Workflow
1. Decision tree: which sanitizer?
2. AddressSanitizer (ASan)
Runtime options (via ASAN_OPTIONS):
Interpreting ASan output:
Reading: the top frame in WRITE/READ is the access site; the allocated at stack shows the allocation. The region is 40 bytes at [start, end) and the access is at end = one byte past the end (classic off-by-one).
3. UndefinedBehaviorSanitizer (UBSan)
Common UBSan checks:
signed-integer-overflowunsigned-integer-overflow(not inundefinedby default)null— null pointer dereferencebounds— array index OOB (compile-time knowable bounds)alignment— misaligned pointer accessfloat-cast-overflow— float-to-int conversion overflowvptr— C++ vtable type mismatchshift-exponent— shift >= bit width
-fno-sanitize-recover=all: makes UBSan abort on first error (important for CI).
Interpreting UBSan output:
4. ThreadSanitizer (TSan)
Interpreting TSan output:
5. MemorySanitizer (MSan)
MSan detects reads of uninitialised memory. Clang only. Requires all-instrumented build (no mixing of MSan and non-MSan objects).
System libraries must be rebuilt with MSan or substituted with MSan-instrumented wrappers. Use msan-libs toolchain from LLVM.
6. ASan + UBSan combined
Do not combine with TSan or MSan.
7. Suppressions
8. CMake integration
9. CI integration
10. HWASan (Hardware-Assisted AddressSanitizer)
Lower overhead than ASan on supported ARM64 hardware with TBI (Top Byte Ignore) or MTE.
11. MemTagSanitizer (ARM MTE)
Uses ARM Memory Tagging Extension hardware tags for heap/stack/memory safety.
12. GWP-ASan (production sampling)
Sampled guard-page ASan suitable for production (used in Android; upstream glibc integration is ongoing).
Catches heap OOB/UAF probabilistically with near-zero steady-state overhead.
13. KASAN for kernel modules
Pair with skills/kernel/kernel-testing for KUnit tests under KASAN. See skills/security/kernel-security for KASAN report triage.
For a quick flag reference, see references/flags.md [blocked]. For report interpretation examples, see references/reports.md [blocked].
Related skills
- Use
skills/profilers/valgrindfor Memcheck when ASan is unavailable - Use
skills/runtimes/fuzzingto auto-generate inputs that trigger sanitizer errors - Use
skills/compilers/gccorskills/compilers/clangfor build flag context


