fix(verify): arm64 stack save, adaptive canary and host gating

Assisted-by: GLM 5.3
This commit is contained in:
2026-09-19 23:49:19 +02:00
parent 87b1081c53
commit 375182ef1f
25 changed files with 651 additions and 57 deletions
+15 -3
View File
@@ -20,8 +20,8 @@ import (
// This is the universal oracle: any file that `go tool asm` accepts can
// be verified, with no hand-written reference.
//
// For RISC-V sources the assembler is invoked with GOARCH=riscv64;
// the caller must set the architecture via GroundTruthArch.
// For the other architectures use the cross-assembly entry points
// GroundTruthARM64, GroundTruthRISCV and GroundTruthLOONG64.
func GroundTruth(path string) (map[string][]byte, error) {
return groundTruthArch(path, "")
}
@@ -82,7 +82,19 @@ func groundTruthArch(path, goarch string) (map[string][]byte, error) {
cmd := exec.Command(asmBin, "-I", includeDir, "-p", pkg, "-o", objPath, path)
if goarch != "" {
cmd.Env = append(os.Environ(), "GOARCH="+goarch)
// Replace, do not duplicate, any GOARCH the ambient environment
// exports. The Go runtime resolves duplicated keys last-wins,
// so the appended entry happens to win today; a single
// unambiguous entry keeps the child's target architecture from
// depending on that resolution order.
environ := os.Environ()
env := make([]string, 0, len(environ)+1)
for _, e := range environ {
if !strings.HasPrefix(e, "GOARCH=") {
env = append(env, e)
}
}
cmd.Env = append(env, "GOARCH="+goarch)
}
if out, err := cmd.CombinedOutput(); err != nil {
return nil, fmt.Errorf("verify: go tool asm (%s): %w\n%s", goarch, err, out)