FIX: enforce POSIX native binary hardening - #810
Sumit Sarabhai (sumitmsft) wants to merge 5 commits into
Conversation
AB#48377 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
ELF linker flags must be restricted to Linux targets to avoid unsupported options on other UNIX platforms.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This PR strengthens POSIX native-extension binary hardening and adds regression coverage.
Changes:
- Defaults single-config builds to Release.
- Adds compiler and linker hardening flags.
- Adds source-contract and ELF validation tests.
| File | Summary |
|---|---|
tests/test_040_native_binary_hardening.py |
Verifies hardening configuration and Linux ELF properties. |
mssql_python/pybind/CMakeLists.txt |
Configures build defaults and native hardening flags. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
📊 Code Coverage Report
Diff CoverageDiff: main...HEAD, staged and unstaged changesNo lines with coverage information in this diff. 📋 Files Needing Attention📉 Files with overall lowest coverage (click to expand)mssql_python.pybind.performance_counter.hpp: 0.7%
mssql_python.pybind.logger_bridge.cpp: 57.9%
mssql_python.pybind.ddbc_bindings.h: 62.6%
mssql_python.pybind.logger_bridge.hpp: 70.8%
mssql_python.pybind.ddbc_bindings.cpp: 79.1%
mssql_python.pybind.connection.connection_pool.cpp: 82.3%
mssql_python.pybind.connection.connection.cpp: 83.1%
mssql_python.logging.py: 86.2%
mssql_python.pooling.py: 90.1%
mssql_python.pybind.fetch_temporal.hpp: 92.1%🔗 Quick Links
|
Give each concurrent connect call its own configured native connection mock so MagicMock child creation cannot race during close. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
PR Performance Report✅ No regression detectedNo consistent slowdowns detected across all 2 environments. 0 IMPROVEMENTS 0 SLOWDOWNS 2/2 ENVIRONMENTS Coverage: 2 of 2 environments completed. Advisory result; does not block merging. Performance diagnosticsPhase times are inclusive diagnostics and must not be added together. They identify where measured time changed, not why it changed. No affected phases or call-count changes were recorded. All database tasks and timingsUnix / SQL Server 2022
Unix / SQL Server 2025
Build and measurement detailsPR head:
A consistent change requires more than 20% median paired movement, at least 1 ms between the median runtimes, and at least 80% of pairs exceeding the relative threshold in the same direction. A slowdown without enough pair agreement is reported as inconsistent. The displayed change is the median of paired before-and-after ratios. It is not recalculated from the two displayed median runtimes. Both revisions use profiling-enabled builds on the same agent and database, with alternating order and discarded warmups. Results are diagnostic and do not represent production-wheel latency. Raw samples and logs are attached to the ADO run as |

Summary
_FORTIFY_SOURCE=3when supported, otherwise level 2, excluding Debug buildsThe hardening options are private to
ddbc_bindings; simdutf compilation is unchanged. macOS retains its existing dynamic-link behavior, and Windows behavior is unchanged.Validation
AB#48377