What changed, and why it matters
This commit removes a build-time compatibility check that tested whether the C compiler supports the modern 'static_assert' keyword. It also deletes the small test program used for that check. On its own, this change does not introduce a direct security vulnerability; it is a build-system cleanup. The main risk is that on older compilers that only support the older '_Static_assert' keyword, the build might now fail or behave differently, because the code no longer automatically defines a fallback macro. There is no evidence in the commit of an exploit or security flaw.
Verify that all supported build toolchains now provide a working C11 static_assert without the shim. If older compilers are still supported, consider documenting the new minimum requirement or restoring the fallback macro. No immediate security patch is indicated by this commit alone.
Security signals we found
Build-system-only change with no runtime code modifications
Removal of a compiler-feature compatibility shim
No mention of security, vulnerability, CVE, or researcher attribution in commit message or diff
Potential for build breakage or changed behavior on compilers lacking C11 static_assert
Evidence from the diff
The patch removes a CMake try_compile() probe and the associated cmake/test-static-assert.c file. Previously, the build tested whether ‘static_assert’ compiled in C11 mode; if it failed, it defined -Dstatic_assert=_Static_assert as a compatibility shim. After the patch, that probe and macro fallback are gone. The diff shows only build-system deletions; no runtime source code is modified. The commit message gives no security context. The change likely assumes C11 support is now universal enough that the shim is unnecessary, but this is not explicitly stated.
Changed components
CMakeLists.txt build configurationcmake/test-static-assert.c (deleted)Inspect captured patch +0 / −40
diff --git a/CMakeLists.txt b/CMakeLists.txt
index b20f24f..72c7347 100644
--- a/CMakeLists.txt
+++ b/CMakeLists.txt
@@ -758,12 +758,6 @@ include(CheckTrezor)
endif()
set(C_WARNINGS "-Waggregate-return -Wnested-externs -Wold-style-definition -Wstrict-prototypes")
set(CXX_WARNINGS "-Wno-reorder -Wno-missing-field-initializers")
- try_compile(STATIC_ASSERT_RES "${CMAKE_CURRENT_BINARY_DIR}/static-assert" "${CMAKE_CURRENT_SOURCE_DIR}/cmake/test-static-assert.c" CMAKE_FLAGS -DCMAKE_C_STANDARD=11)
- if(STATIC_ASSERT_RES)
- set(STATIC_ASSERT_FLAG "")
- else()
- set(STATIC_ASSERT_FLAG "-Dstatic_assert=_Static_assert")
- endif()
monero_enable_coverage()
# With GCC 6.1.1 the compiled binary malfunctions due to aliasing. Until that
diff --git a/cmake/test-static-assert.c b/cmake/test-static-assert.c
deleted file mode 100644
index 4889ec0..0000000
--- a/cmake/test-static-assert.c
+++ /dev/null
@@ -1,34 +0,0 @@
-// Copyright (c) 2014-2024, The Monero Project
-//
-// All rights reserved.
-//
-// Redistribution and use in source and binary forms, with or without modification, are
-// permitted provided that the following conditions are met:
-//
-// 1. Redistributions of source code must retain the above copyright notice, this list of
-// conditions and the following disclaimer.
-//
-// 2. Redistributions in binary form must reproduce the above copyright notice, this list
-// of conditions and the following disclaimer in the documentation and/or other
-// materials provided with the distribution.
-//
-// 3. Neither the name of the copyright holder nor the names of its contributors may be
-// used to endorse or promote products derived from this software without specific
-// prior written permission.
-//
-// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY
-// EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
-// MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
-// THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
-// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
-// PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
-// INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
-// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
-// THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-
-#include <assert.h>
-
-static_assert(1, "FAIL");
-int main(int argc, char *argv[]) {
- return 0;
-}
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.