What changed, and why it matters
This commit removes about 80 lines of CMake build configuration that automatically selected special ARM processor floating-point and CPU bug-workaround compiler flags. Without these flags, Monero may build differently (or fail to build/run correctly) on some ARM devices, but the change itself is a build-system cleanup, not a direct code vulnerability. The removed code included workarounds for known ARM Cortex-A53 CPU errata (hardware bugs 835769 and 843419). Dropping those workarounds could, in theory, allow rare hardware-triggered misbehavior on affected ARMv8 chips, but only if the compiler/toolchain no longer applies equivalent fixes by default.
Treat as a build-hygiene change. For users building Monero on ARM, verify that the resulting binary still passes tests and that the toolchain supplies equivalent default Cortex-A53 errata fixes if targeting affected cores. If the project intends to continue supporting ARM, consider documenting why these flags were removed and whether an alternative mechanism (e.g., relying on compiler defaults or external toolchain configuration) is sufficient. No immediate security patch is required based solely on this diff.
Security signals we found
Removal of CPU errata compiler workarounds (-mfix-cortex-a53-835769, -mfix-cortex-a53-843419)
Build-system-only change with no runtime code modifications
No explicit security rationale or CVE reference in commit message
Potential for incorrect floating-point ABI or feature selection on ARMv6/ARMv7 builds
Evidence from the diff
The patch deletes the ARM-specific branch in CMakeLists.txt that set -mfpu=…, -mfloat-abi=…, and -mfix-cortex-a53-* flags based on CMake-detected ARM6/ARM7/ARM8 variables. The most security-relevant removed items are the Cortex-A53 errata workarounds (GCC flags -mfix-cortex-a53-835769 and -mfix-cortex-a53-843419). Those errata can cause miscompilation or runtime corruption in certain code patterns on affected ARMv8 cores. Modern compilers often enable equivalent fixes by default, so the practical risk is low, but the commit provides no replacement logic and no explanation for why the flags are no longer needed.
Changed components
CMakeLists.txt build configurationARM (ARMv6/ARMv7/ARMv8) cross-compilation and native buildsCortex-A53 specific compiler mitigationsInspect captured patch +0 / −81
diff --git a/CMakeLists.txt b/CMakeLists.txt
index 2e58c1c..ecb7c2a 100644
--- a/CMakeLists.txt
+++ b/CMakeLists.txt
@@ -859,87 +859,6 @@ include(CheckTrezor)
set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -fno-strict-aliasing")
set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -fno-strict-aliasing")
- if(ARM)
- message(STATUS "Setting FPU Flags for ARM Processors")
-
- #NB NEON hardware does not fully implement the IEEE 754 standard for floating-point arithmetic
- #Need custom assembly code to take full advantage of NEON SIMD
-
- #Cortex-A5/9 -mfpu=neon-fp16
- #Cortex-A7/15 -mfpu=neon-vfpv4
- #Cortex-A8 -mfpu=neon
- #ARMv8 -FP and SIMD on by default for all ARM8v-A series, NO -mfpu setting needed
-
- #For custom -mtune, processor IDs for ARMv8-A series:
- #0xd04 - Cortex-A35
- #0xd07 - Cortex-A57
- #0xd08 - Cortex-A72
- #0xd03 - Cortex-A73
-
- if(NOT ARM8)
- CHECK_CXX_ACCEPTS_FLAG(-mfpu=vfp3-d16 CXX_ACCEPTS_VFP3_D16)
- CHECK_CXX_ACCEPTS_FLAG(-mfpu=vfp4 CXX_ACCEPTS_VFP4)
- CHECK_CXX_ACCEPTS_FLAG(-mfloat-abi=hard CXX_ACCEPTS_MFLOAT_HARD)
- CHECK_CXX_ACCEPTS_FLAG(-mfloat-abi=softfp CXX_ACCEPTS_MFLOAT_SOFTFP)
- endif()
-
- if(ARM8)
- CHECK_CXX_ACCEPTS_FLAG(-mfix-cortex-a53-835769 CXX_ACCEPTS_MFIX_CORTEX_A53_835769)
- CHECK_CXX_ACCEPTS_FLAG(-mfix-cortex-a53-843419 CXX_ACCEPTS_MFIX_CORTEX_A53_843419)
- endif()
-
- if(ARM6)
- message(STATUS "Selecting VFP for ARMv6")
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -mfpu=vfp")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -mfpu=vfp")
- if(DEPENDS)
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -marm")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -marm")
- endif()
- endif(ARM6)
-
- if(ARM7)
- if(CXX_ACCEPTS_VFP3_D16 AND NOT CXX_ACCEPTS_VFP4)
- message(STATUS "Selecting VFP3 for ARMv7")
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -mfpu=vfp3-d16")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -mfpu=vfp3-d16")
- endif()
-
- if(CXX_ACCEPTS_VFP4)
- message(STATUS "Selecting VFP4 for ARMv7")
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -mfpu=vfp4")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -mfpu=vfp4")
- endif()
-
- if(CXX_ACCEPTS_MFLOAT_HARD)
- message(STATUS "Setting Hardware ABI for Floating Point")
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -mfloat-abi=hard")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -mfloat-abi=hard")
- endif()
-
- if(CXX_ACCEPTS_MFLOAT_SOFTFP AND NOT CXX_ACCEPTS_MFLOAT_HARD)
- message(STATUS "Setting Software ABI for Floating Point")
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -mfloat-abi=softfp")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -mfloat-abi=softfp")
- endif()
- endif(ARM7)
-
- if(ARM8)
- if(CXX_ACCEPTS_MFIX_CORTEX_A53_835769)
- message(STATUS "Enabling Cortex-A53 workaround 835769")
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -mfix-cortex-a53-835769")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -mfix-cortex-a53-835769")
- endif()
-
- if(CXX_ACCEPTS_MFIX_CORTEX_A53_843419)
- message(STATUS "Enabling Cortex-A53 workaround 843419")
- set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -mfix-cortex-a53-843419")
- set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -mfix-cortex-a53-843419")
- endif()
- endif(ARM8)
-
- endif(ARM)
-
# random crash on startup when asan is on if pie is enabled
if(NOT SANITIZE AND ANDROID AND NOT BUILD_GUI_DEPS STREQUAL "ON" OR IOS)
#From Android 5: "only position independent executables (PIE) are supported"
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.