#467 was a real instance of package metadata flowing into linker arguments and being interpreted as a directive (@scope/pkg parsed by ld64 as a response-file). Generalize the fix.
Mechanism
Single sanitizer applied at every site where package-name / package-path / package-derived-symbol-name flows into a linker arg. Reject leading @, -, /; reject unescaped spaces; reject shell metacharacters; reject characters not in [A-Za-z0-9_./-] for path-shaped args. Add a fuzz suite over crafted package names so future regressions are caught.
Zero runtime cost (compile-time string sanitization).
Acceptance
Part of the supply-chain hardening series. Zero runtime cost.
#467 was a real instance of package metadata flowing into linker arguments and being interpreted as a directive (
@scope/pkgparsed by ld64 as a response-file). Generalize the fix.Mechanism
Single sanitizer applied at every site where package-name / package-path / package-derived-symbol-name flows into a linker arg. Reject leading
@,-,/; reject unescaped spaces; reject shell metacharacters; reject characters not in[A-Za-z0-9_./-]for path-shaped args. Add a fuzz suite over crafted package names so future regressions are caught.Zero runtime cost (compile-time string sanitization).
Acceptance
@, embedded newlines, response-file directives, ld64-specific edge cases)Part of the supply-chain hardening series. Zero runtime cost.