Sanitizers

mohitmishra786/low-level-dev-skills/skills/runtimes/sanitizers

作者 mohitmishra786bdc58472fa9f無授權條款253 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫3 個月前更新

Compiler sanitizer skill for runtime bug detection in C/C++. Use when enabling and interpreting AddressSanitizer (ASan), UndefinedBehaviorSanitizer (UBSan), ThreadSanitizer (TSan), MemorySanitizer (MSan), or LeakSanitizer (LSan) with GCC or Clang. Activates on queries about sanitizer flags, sanitizer reports, ASAN_OPTIONS, memory errors, data races, undefined behaviour, uninitialised reads, or choosing which sanitizer to use for a given bug class.

AI 產生的概覽

指導選擇、啟用與解讀 C/C++ 編譯器 sanitizer,例如 ASan、UBSan、TSan、MSan 與 LSan。

功能
說明各類缺陷(記憶體錯誤、未定義行為、資料競爭、未初始化讀取、記憶體洩漏)該選用哪種 sanitizer,並提供啟用所需的編譯選項。介紹如何閱讀 sanitizer 報告、設定 ASAN_OPTIONS 等執行階段選項、撰寫抑制檔案,以及在 CMake 與 CI 中整合 sanitizer。也涵蓋 HWASan、MemTagSanitizer、GWP-ASan 以及用於核心模組的 KASAN,並附有編譯選項與報告解讀的參考檔案。
適用情境
當 C/C++ 程式出現記憶體錯誤、當機、資料競爭或未定義行為,需要選擇並啟用合適的 sanitizer 時使用。也適用於解讀 sanitizer 報告、抑制誤報,或在建置與 CI 流程中執行 sanitizer。
執行需求
不需腳本,只有說明文件與兩份參考檔案。需要 C/C++ 工具鏈(GCC 或 Clang);部分 sanitizer 還需要 Clang、支援 TBI/MTE 的 ARM64 硬體,或啟用 KASAN 的核心。不需要憑證或網路存取。

Sanitizers

Purpose

Guide agents through choosing, enabling, and interpreting compiler runtime sanitizers for finding memory errors, undefined behaviour, data races, and memory leaks.

Triggers

  • "My program has a memory error — which sanitizer do I use?"
  • "How do I enable ASan?"
  • "How do I interpret an ASan/UBSan/TSan report?"
  • "ASan says heap-buffer-overflow — what does that mean?"
  • "How do I suppress false positives in sanitizers?"
  • "Can I use sanitizers in CI?"

Workflow

1. Decision tree: which sanitizer?

bash
Bug class?├── Memory OOB, use-after-free, double-free → AddressSanitizer (ASan)├── Stack OOB, global OOB → ASan (all three covered)├── Uninitialised reads → MemorySanitizer (MSan, Clang only, requires all-clang build)├── Undefined behaviour (int overflow, null deref, bad cast) → UBSan├── Data races (multi-thread) → ThreadSanitizer (TSan)├── Memory leaks only → LeakSanitizer (LSan, standalone or via ASan)└── Multiple classes → ASan + UBSan (common combo); cannot combine with TSan or MSan

2. AddressSanitizer (ASan)

bash
# GCC or Clanggcc -fsanitize=address -fno-omit-frame-pointer -g -O1 -o prog main.c# Orclang -fsanitize=address -fno-omit-frame-pointer -g -O1 -o prog main.c

Runtime options (via ASAN_OPTIONS):

bash
ASAN_OPTIONS=detect_leaks=1:abort_on_error=1:log_path=/tmp/asan.log ./prog
ASAN_OPTIONS keyEffect
detect_leaks=0/1Enable LeakSanitizer (default 1 on Linux)
abort_on_error=1Call abort() instead of _exit() (for core dumps)
log_path=pathWrite report to file
symbolize=1Symbolize addresses (needs llvm-symbolizer in PATH)
fast_unwind_on_malloc=0More accurate stacks (slower)
quarantine_size_mb=256Delay reuse of freed memory

Interpreting ASan output:

text
==12345==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x602000000050READ of size 4 at 0x602000000050 thread T0    #0 0x401234 in foo /home/user/src/main.c:15    #1 0x401567 in main /home/user/src/main.c:42
0x602000000050 is located 0 bytes after a 40-byte region[0x602000000028, 0x602000000050) allocated at:    #0 0x7f12345 in malloc ...    #1 0x401234 in main /home/user/src/main.c:10

Reading: the top frame in WRITE/READ is the access site; the allocated at stack shows the allocation. The region is 40 bytes at [start, end) and the access is at end = one byte past the end (classic off-by-one).

3. UndefinedBehaviorSanitizer (UBSan)

bash
gcc -fsanitize=undefined -g -O1 -o prog main.c# More complete: add specific checksgcc -fsanitize=undefined,integer -g -O1 -o prog main.c

Common UBSan checks:

  • signed-integer-overflow
  • unsigned-integer-overflow (not in undefined by default)
  • null — null pointer dereference
  • bounds — array index OOB (compile-time knowable bounds)
  • alignment — misaligned pointer access
  • float-cast-overflow — float-to-int conversion overflow
  • vptr — C++ vtable type mismatch
  • shift-exponent — shift >= bit width
bash
# Enable everything including integer overflowgcc -fsanitize=undefined \    -fsanitize=signed-integer-overflow,unsigned-integer-overflow,float-cast-overflow \    -fno-sanitize-recover=all \   # abort instead of continue    -g -O1 -o prog main.c

-fno-sanitize-recover=all: makes UBSan abort on first error (important for CI).

Interpreting UBSan output:

text
src/main.c:15:12: runtime error: signed integer overflow: 2147483647 + 1 cannot be represented in type 'int'

4. ThreadSanitizer (TSan)

bash
# Clang or GCC (GCC ≥ 4.8)clang -fsanitize=thread -g -O1 -o prog main.c
# TSan is incompatible with ASan and MSan

Interpreting TSan output:

text
WARNING: ThreadSanitizer: data race (pid=12345)  Write of size 4 at 0x7f... by thread T2:    #0 increment /home/user/src/counter.c:8  Previous read of size 4 at 0x7f... by thread T1:    #0 read_counter /home/user/src/counter.c:3

5. MemorySanitizer (MSan)

MSan detects reads of uninitialised memory. Clang only. Requires all-instrumented build (no mixing of MSan and non-MSan objects).

bash
clang -fsanitize=memory -fno-omit-frame-pointer -g -O1 -o prog main.c# With origin tracking (slower but shows where uninit value came from)clang -fsanitize=memory -fsanitize-memory-track-origins=2 -g -O1 -o prog main.c

System libraries must be rebuilt with MSan or substituted with MSan-instrumented wrappers. Use msan-libs toolchain from LLVM.

6. ASan + UBSan combined

bash
gcc -fsanitize=address,undefined -fno-sanitize-recover=all \    -fno-omit-frame-pointer -g -O1 -o prog main.c

Do not combine with TSan or MSan.

7. Suppressions

bash
# ASan suppression filecat > asan.supp << 'EOF'# Suppress leaks from OpenSSL initleak:CRYPTO_mallocEOF
LSAN_OPTIONS=suppressions=asan.supp ./prog
# UBSan suppressioncat > ubsan.supp << 'EOF'signed-integer-overflow:third_party/fast_math.cEOFUBSAN_OPTIONS=suppressions=ubsan.supp:print_stacktrace=1 ./prog

8. CMake integration

cmake
option(SANITIZE "Enable sanitizers" OFF)if(SANITIZE)    set(san_flags -fsanitize=address,undefined -fno-sanitize-recover=all                  -fno-omit-frame-pointer -g -O1)    add_compile_options(${san_flags})    add_link_options(${san_flags})endif()

9. CI integration

yaml
# GitHub Actions example- name: Build with ASan+UBSan  run: |    cmake -S . -B build -DSANITIZE=ON    cmake --build build -j$(nproc)
- name: Run tests under sanitizers  run: |    ASAN_OPTIONS=abort_on_error=1:detect_leaks=1 \    UBSAN_OPTIONS=print_stacktrace=1:halt_on_error=1 \    ctest --test-dir build -j$(nproc) --output-on-failure

10. HWASan (Hardware-Assisted AddressSanitizer)

Lower overhead than ASan on supported ARM64 hardware with TBI (Top Byte Ignore) or MTE.

bash
# Clang/LLVM HWASan (userspace)clang -fsanitize=hwaddress -g -O1 -o app app.c
# Requires ARM64 with TBI (most Android/arm64 servers) or HWASan tagging support# Cannot combine with ASan on same build
SanitizerOverheadPlatform
ASan~2xx86, arm64
HWASan~1.2–1.5xarm64 with TBI/MTE
MSan~3xLLVM only

11. MemTagSanitizer (ARM MTE)

Uses ARM Memory Tagging Extension hardware tags for heap/stack/memory safety.

bash
# Experimental — LLVM with MTE-capable hardware (arm64)clang -fsanitize=memtag -g -O1 -o app app.c
# Kernel MTE (separate from userspace MemTagSanitizer)# CONFIG_ARM64_MTE=y — hardware tagging in kernel allocator

12. GWP-ASan (production sampling)

Sampled guard-page ASan suitable for production (used in Android; upstream glibc integration is ongoing).

bash
# LLVM GWP-ASan (link-time, sampled allocations)clang -fsanitize=gwp-asan -O2 -o app app.c
# Android: enabled in some system components for sampled crash detection# glibc: experimental GWP-ASan allocator integration (check distro release notes)

Catches heap OOB/UAF probabilistically with near-zero steady-state overhead.

13. KASAN for kernel modules

bash
# Build test kernel with KASAN# CONFIG_KASAN=y CONFIG_KASAN_INLINE=y or CONFIG_KASAN_OUTLINE=y
# Boot KASAN kernel in QEMU for module developmentqemu-system-x86_64 -kernel bzImage -append "kasan=on" ...
# Load module — KASAN reports appear in dmesgsudo insmod mymod.kodmesg | tail -30

Pair with skills/kernel/kernel-testing for KUnit tests under KASAN. See skills/security/kernel-security for KASAN report triage.

For a quick flag reference, see references/flags.md [blocked]. For report interpretation examples, see references/reports.md [blocked].

Related skills

  • Use skills/profilers/valgrind for Memcheck when ASan is unavailable
  • Use skills/runtimes/fuzzing to auto-generate inputs that trigger sanitizer errors
  • Use skills/compilers/gcc or skills/compilers/clang for build flag context

來源與署名

來源:mohitmishra786/low-level-dev-skills位於skills/runtimes/sanitizers提交bdc5847

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架