Skip to content

FIX: enforce POSIX native binary hardening - #810

Open
Sumit Sarabhai (sumitmsft) wants to merge 5 commits into
mainfrom
sumitsar/fix-cf041-native-hardening
Open

Sumit Sarabhai (sumitmsft) wants to merge 5 commits into
mainfrom
sumitsar/fix-cf041-native-hardening

Conversation

@sumitmsft

@sumitmsft Sumit Sarabhai (sumitmsft) commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • default single-config POSIX builds to Release when no build type is supplied
  • enable stack protection for the native extension on POSIX
  • select _FORTIFY_SOURCE=3 when supported, otherwise level 2, excluding Debug builds
  • enable full RELRO, immediate binding, and non-executable stack declarations on Linux
  • add source-contract, ELF parser, and loaded-extension regression tests

The hardening options are private to ddbc_bindings; simdutf compilation is unchanged. macOS retains its existing dynamic-link behavior, and Windows behavior is unchanged.

Validation

  • Windows x64 native build
  • 37 passed, 4 expected platform skips
  • import, formatting, and diff checks
  • hosted CI will validate manylinux, musllinux, ARM64, macOS, and Clang coverage

AB#48377

AB#48377

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 23, 2026 18:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

ELF linker flags must be restricted to Linux targets to avoid unsupported options on other UNIX platforms.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

This PR strengthens POSIX native-extension binary hardening and adds regression coverage.

Changes:

  • Defaults single-config builds to Release.
  • Adds compiler and linker hardening flags.
  • Adds source-contract and ELF validation tests.
File Summary
tests/​test_040_native_binary_hardening.py Verifies hardening configuration and Linux ELF properties.
mssql_python/​pybind/​CMakeLists.txt Configures build defaults and native hardening flags.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread mssql_python/pybind/CMakeLists.txt
@github-actions github-actions Bot added the pr-size: medium Moderate update size label Sep 23, 2026
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

📊 Code Coverage Report

🔥 Diff Coverage

100%


🎯 Overall Coverage

84%


📈 Total Lines Covered: 9358 out of 11042
📁 Project: mssql-python


Diff Coverage

Diff: main...HEAD, staged and unstaged changes

No lines with coverage information in this diff.


📋 Files Needing Attention

📉 Files with overall lowest coverage (click to expand)
mssql_python.pybind.performance_counter.hpp: 0.7%
mssql_python.pybind.logger_bridge.cpp: 57.9%
mssql_python.pybind.ddbc_bindings.h: 62.6%
mssql_python.pybind.logger_bridge.hpp: 70.8%
mssql_python.pybind.ddbc_bindings.cpp: 79.1%
mssql_python.pybind.connection.connection_pool.cpp: 82.3%
mssql_python.pybind.connection.connection.cpp: 83.1%
mssql_python.logging.py: 86.2%
mssql_python.pooling.py: 90.1%
mssql_python.pybind.fetch_temporal.hpp: 92.1%

🔗 Quick Links

⚙️ Build Summary 📋 Coverage Details

View Azure DevOps Build

Browse Full Coverage Report

Give each concurrent connect call its own configured native connection mock so MagicMock child creation cannot race during close.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 24, 2026 06:18
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

PR Performance Report

✅ No regression detected

No consistent slowdowns detected across all 2 environments.

0 IMPROVEMENTS 0 SLOWDOWNS 2/2 ENVIRONMENTS

Coverage: 2 of 2 environments completed. Advisory result; does not block merging.

Performance diagnostics

Phase times are inclusive diagnostics and must not be added together. They identify where measured time changed, not why it changed.

No affected phases or call-count changes were recorded.

All database tasks and timings

Unix / SQL Server 2022

Database task Before After Paired change Result
Connection opening 10.621 ms 10.449 ms -2.8% no signal
SELECT queries 1.076 ms 1.071 ms -0.5% no signal
Row insertion 35.036 ms 34.843 ms -1.6% no signal
Executemany inserts 159.162 ms 161.601 ms +1.5% no signal
Fetch-all queries 123.375 ms 125.877 ms +2.3% no signal
Row-by-row fetching 14.386 ms 14.281 ms +1.2% no signal
Batched row fetching 118.617 ms 119.464 ms +0.7% no signal
Transaction commit and rollback 118.807 ms 114.827 ms -2.8% no signal
Arrow row fetching 94.676 ms 94.825 ms -0.1% no signal
100,000-row insertion 443.496 ms 435.053 ms -1.5% no signal
Row fetching in batches of 100 121.256 ms 122.041 ms +0.5% no signal
Row fetching in batches of 10,000 127.154 ms 129.824 ms +3.1% no signal
Repeated positional queries 34.207 ms 34.605 ms +1.2% no signal
Repeated named-parameter queries 36.906 ms 36.206 ms -0.3% no signal
Legacy 100,000-row insertion 349.196 ms 356.626 ms +3.4% no signal
Insertion with explicit input sizes 484.187 ms 489.367 ms +1.2% no signal
Joined aggregation queries 181.032 ms 177.972 ms -1.7% no signal
Large joined-result fetching 181.954 ms 195.166 ms +7.3% no signal
1.2-million-row fetching 3449.593 ms 3418.214 ms -0.7% no signal
Common table expression queries 5.342 ms 5.356 ms +0.2% no signal
256 KiB VARCHAR(MAX) / fetchall() 1.264 ms 1.359 ms +9.2% no signal

Unix / SQL Server 2025

Database task Before After Paired change Result
Connection opening 95.740 ms 95.591 ms -0.3% no signal
SELECT queries 1.040 ms 1.043 ms +1.4% no signal
Row insertion 31.845 ms 31.962 ms +0.6% no signal
Executemany inserts 136.788 ms 130.619 ms +0.9% no signal
Fetch-all queries 115.926 ms 117.735 ms +1.5% no signal
Row-by-row fetching 12.634 ms 12.905 ms +1.5% no signal
Batched row fetching 108.944 ms 112.291 ms +3.3% no signal
Transaction commit and rollback 103.056 ms 105.110 ms +2.3% no signal
Arrow row fetching 87.075 ms 87.386 ms +1.4% no signal
100,000-row insertion 391.339 ms 393.778 ms +0.5% no signal
Row fetching in batches of 100 105.560 ms 106.151 ms -0.4% no signal
Row fetching in batches of 10,000 128.999 ms 118.224 ms +0.7% no signal
Repeated positional queries 30.476 ms 30.432 ms +0.4% no signal
Repeated named-parameter queries 32.637 ms 32.882 ms +0.7% no signal
Legacy 100,000-row insertion 300.940 ms 305.105 ms +0.7% no signal
Insertion with explicit input sizes 430.541 ms 429.013 ms -0.4% no signal
Joined aggregation queries 164.145 ms 167.437 ms +1.0% no signal
Large joined-result fetching 175.801 ms 182.694 ms +2.0% no signal
1.2-million-row fetching 3547.269 ms 3475.703 ms -2.0% no signal
Common table expression queries 5.218 ms 5.242 ms -0.0% no signal
256 KiB VARCHAR(MAX) / fetchall() 1.434 ms 1.405 ms -1.5% no signal
Build and measurement details

ADO build 178136

PR head: bd6669efc8e991cd47279528478197b8b644a2fa
Base: 30893611a5858942b4a5c8576e433e8b2a3913a7
Measured merge: 94cab0e0bbde017cc6ea4eefad56201a437249b6

  • Unix / SQL Server 2022: Python 3.12.3, x86_64, SQL 16.0.4295.3; 5 paired comparisons and 1 warmup.
  • Unix / SQL Server 2025: Python 3.12.3, x86_64, SQL 17.0.5005.3; 5 paired comparisons and 1 warmup.

A consistent change requires more than 20% median paired movement, at least 1 ms between the median runtimes, and at least 80% of pairs exceeding the relative threshold in the same direction. A slowdown without enough pair agreement is reported as inconsistent.

The displayed change is the median of paired before-and-after ratios. It is not recalculated from the two displayed median runtimes.

Both revisions use profiling-enabled builds on the same agent and database, with alternating order and discarded warmups. Results are diagnostic and do not represent production-wheel latency.

Raw samples and logs are attached to the ADO run as profiler-* artifacts.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Native build and ELF hardening changes span multiple platforms and warrant final human validation.

Review effort: Lite
Findings: 1 High severity

Open (1)

@sumitmsft
Sumit Sarabhai (sumitmsft) marked this pull request as ready for review September 24, 2026 07:54
Copilot AI review requested due to automatic review settings September 24, 2026 09:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (1)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The hardening test must skip when the native extension is unavailable in source-only checkouts.

Review effort: Lite
Findings: None

Copilot AI review requested due to automatic review settings September 25, 2026 06:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved issues were identified.

Review effort: Lite
Findings: None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr-size: medium Moderate update size

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants