Repository navigation
Support cross-compilation of bare-metal binaries? #269
Description
Activity
cargo-auditable already omits SHF_ALLOC on ELF.
= note: rust-lld: error: unknown argument '-Wl,-u,AUDITABLE_VERSION_INFO'
It failed to detect that you are using a bare linker. It looks at the
-Clinkerargument passed, not at target defaults:cargo-auditable/cargo-auditable/src/rustc_arguments.rs
Lines 40 to 62 in fb744c1
/// Normally `rustc` uses a C compiler such as `cc` or `clang` as linker, /// and arguments to the actual linker need to be passed prefixed with `-Wl,`. /// But it is possible to configure Cargo and rustc to call a linker directly, /// and the breakage it causes is subtle enough that people just roll with it /// and complain when cargo-auditable doesn't support this configuration: /// <https://github.com/rust-secure-code/cargo-auditable/issues/202> /// /// This function can tell you if a bare linker is in use /// and whether you need to prepend `-Wl,` or not. /// /// Such setups are exceptionally rare and frankly it's a misconfiguration /// that will break more than just `cargo auditable`, but I am feeling generous. pub fn bare_linker(&self) -> bool { let linker_flag = self.codegen.iter().find(|s| s.starts_with("linker=")); if let Some(linker_flag) = linker_flag { let linker = linker_flag.strip_prefix("linker=").unwrap(); if linker.ends_with("ld") { return true; } } false } } Ah.
Adding
linker = "rust-lld"to.cargo/config.tomlallowed the build to work, but it's not ideal (and most people won't have that set).$ cargo audit bin ../target/thumbv8m.main-none-eabi/release/standalone-hello Fetching advisory database from `https://github.com/RustSec/advisory-db.git` Loaded 1277 security advisories (from /Users/jonathan/.cargo/advisory-db) Updating crates.io index Found 'cargo auditable' data in ../target/thumbv8m.main-none-eabi/release/standalone-hello (59 dependencies) Crate: bare-metal Version: 0.2.5 Warning: unmaintained Title: bare-metal is deprecated Date: 2026-04-23 ID: RUSTSEC-2026-0110 URL: https://rustsec.org/advisories/RUSTSEC-2026-0110 warning: 1 allowed warning found in ../target/thumbv8m.main-none-eabi/release/standalone-hello
/// Such setups are exceptionally rare and frankly it's a misconfiguration
/// that will break more than justcargo auditable, but I am feeling generous.I mean, basically all the Rust bare-metal targets are configured to use
rust-llddirectly, so it's not that rare.Unfortunately I don't know how to work out that
rustcis using a bare linker, beyond holding a big database of target strings that will often be slightly out of date.I think there are two options to get this info from rustc. One is this:
rustc +nightly -Z unstable-options \ --target x86_64-unknown-linux-gnu \ --print target-spec-json | jq -r '."linker-flavor"'Requires nightly, but we can just pass
RUSTC_BOOTSTRAP=1, and if it breaks then all non-bare-metal platforms will keep working so it's probably fine.Technically we also have this on stable:
rustc --print link-args main.rs --target x86_64-unknown-linux-gnuBut the output is not machine-readable, and it actually compiles and links a small binary, which is pretty slow.
I'll try to implement the
RUSTC_BOOTSTRAPJSON option and see if that works.However, ELF executables (the format typically used produced by rustc when building bare-metal code) has the concept of a 'NOLOAD' section - this would leave the audit data in the ELF file, but it would not take up any space on the microcontroller.
cargo-auditable already omits SHF_ALLOC on ELF.
It would be great news if we happened to already pass the correct flags! I would like to get an experimental confirmation of this, however. @jonathanpallant now that you got it working, do you think you could measure the flashed binary size before and after to see if the audit info is correctly omitted?
$ cargo build --release --bin standalone-hello && rust-size ./target/thumbv8m.main-none-eabi/release/standalone-hello Finished `release` profile [optimized + debuginfo] target(s) in 11.09s text data bss dec hex filename 5524 56 1032 6612 19d4 ./target/thumbv8m.main-none-eabi/release/standalone-hello $ cargo auditable build --release --bin standalone-hello && rust-size ./target/thumbv8m.main-none-eabi/release/standalone-hello Finished `release` profile [optimized + debuginfo] target(s) in 0.62s text data bss dec hex filename 5524 56 1032 6612 19d4 ./target/thumbv8m.main-none-eabi/release/standalone-hello
No change in code size. But here's the section:
$ cargo auditable build --release --bin standalone-hello && rust-size -Ax ./target/thumbv8m.main-none-eabi/release/standalone-hello Finished `release` profile [optimized + debuginfo] target(s) in 0.04s ./target/thumbv8m.main-none-eabi/release/standalone-hello : section size addr .vector_table 0x258 0x8000000 .text 0x10ac 0x8000258 .rodata 0x290 0x8001304 .data 0x38 0x20000000 .gnu.sgstubs 0 0x80015e0 .bss 0x8 0x20000038 .uninit 0x400 0x20000040 .defmt 0x4 0 .debug_abbrev 0x2407 0 .debug_info 0x558e5 0 .debug_aranges 0x24e0 0 .debug_ranges 0x140e0 0 .debug_str 0x88753 0 .comment 0xa1 0 .ARM.attributes 0x32 0 .debug_frame 0x7230 0 .debug_line 0x2a101 0 .debug_loc 0x7149 0 .dep-v0 0x38c 0 <<<<< it's this one Total 0x130cb0
Reacted by Sergey "Shnatsel" DavidoffDone in #270
Release as v0.7.7
The README notes:
However, ELF executables (the format typically used produced by
rustcwhen building bare-metal code) has the concept of a 'NOLOAD' section - this would leave the audit data in the ELF file, but it would not take up any space on the microcontroller. We already use this trick for debug info,defmtlogs, etc, so it seems an ideal place to store dependency information.I naively tried to just build a
thumbv8m.main-none-eabibinary withcargo auditable buildon my macOS machine, and I got a linker error: