Repository navigation
fix(build): keep POSIX-only build parts off Windows and refuse unguarded POSIX headers in msvcism - #2611
Merged
Conversation
…ded POSIX headers in msvcism (#2611) * fix(build): keep POSIX-only build parts off Windows and refuse unguarded POSIX headers in msvcism MSVC ships no <unistd.h>, <dlfcn.h>, <sys/socket.h> or the other POSIX-only headers, and only the required Windows MSVC lanes, which neither the local gates nor the merge train build, see an unguarded include of one. The RC4 Vulkan frame import added <unistd.h> to core/src/cuda/import_vulkan.c, a CUDA-backend source the Windows build compiles, and nothing local caught it. The msvcism stage of scripts/dev/preflight.sh now runs scripts/dev/find-posix-only-headers.py over the changed sources: a POSIX-only include outside every platform conditional, in a source the Windows build compiles (read from the meson.build gates, a header through its includers), fails the stage, and so does a scan that cannot run. The planted case in scripts/ci/tests/test-preflight-msvcism.sh passed master's stage and fails this one; make lint-sh runs the test. The MCP server, the libFuzzer harnesses and vmaf_vpl are POSIX-only and gated off Windows: enable_mcp=true and fuzz=true stop a Windows configure with an error that names the dependency, vmaf_vpl is not looked for and configure says so. The vendored MATLAB MEX source and the LD_PRELOAD fault-injection shim, which no meson.build builds, are named exceptions with an expiry (ADR-2646, Q-266, Q-269). Signed-off-by: Lusoris <lusoris@proton.me>
lusoris
force-pushed
the
fix/msvcism-posix-headers
branch
from
October 8, 2026 13:32
8f34bd2 to
583a30b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The
msvcismpreflight stage now refuses a POSIX-only header (<unistd.h>,<dlfcn.h>,<poll.h>,<sys/socket.h>, ...) outside a platform conditional in a source the Windows MSVC builds compile, and the three build parts that are POSIX-only by design (embedded MCP server, libFuzzer harnesses,vmaf_vpl) are gated off Windows, so a Windows configure that asks for MCP or fuzzing fails with the reason instead of in the compiler (ADR-2646, ledgerQ-266andQ-269).Every Linux and macOS lane accepts an unguarded POSIX include; only the required
Windows MSVC+CUDA/Windows MSVC+SYCLlanes refuse it (C1083), and neither the local gates nor the merge train build them. While landing the RC4 Vulkan frame import (#2375),core/src/cuda/import_vulkan.chad added<unistd.h>fordup()/close()(fixed in that lane withVMAF_DUP/VMAF_CLOSE), and nothing local caught it.What changes:
scripts/dev/find-posix-only-headers.pyreportspath:line: <header>for a POSIX-only include outside every preprocessor conditional that names a platform (_WIN32,_MSC_VER,__linux__,__unix__,__APPLE__,__has_include, aHAVE_*feature macro other than the backend switches), in a file the Windows build compiles. Which files those are comes from themeson.buildfiles: a source named only inside a block kept off Windows (host_machine.system() != 'windows',== 'linux', theelse/elifof== 'windows', thesubdir()that reads its directory, aforeachover a list filled only off Windows, a list kept empty off Linux) is not built there; a header counts through the sources that include it; a source nomeson.buildnames counts as built. It exits non-zero when git cannot list the build files.scripts/dev/preflight.sh --stage msvcismruns it over the changed sources (C, C++ and CUDA), afterlint_exceptions.py filter msvcism-posix-headers, and fails on a finding and when either step cannot run (no result is never a pass). It resolves both scripts next to itself (PREFLIGHT_DIR), so it also checks another checkout correctly.core/src/meson.build:enable_mcp=trueon Windows is a configureerror()naming<sys/socket.h>and<unistd.h>;subdir('mcp')andcompat/libvmaf/mcp.ccarry the gate.core/test/meson.build: the MCP tests carry it;subdir('fuzz')runs off Windows only, andfuzz=trueon Windows is anerror().core/tools/meson.build:vmaf_vpl(no option requests it) is not looked for on Windows, and configure printsvmaf_vpl tool: disabled (Linux only: VA-API, libva-drm and <unistd.h>). Nothing is skipped silently.meson.build: the vendored MATLAB MEX sourcecompat/python-vmaf/matlab/strred/matlabPyrTools/MEX/innerProd.cand theLD_PRELOADfault-injection shimffmpeg-patches/test/fault_inject_libvmaf.c, in.config/lint-exceptions.d/msvcism-posix-headers.tomlwith a reason and expiry 2027-06-30 (lint_exceptions.py check: 85 exceptions, 0 findings).scripts/ci/tests/test-preflight-msvcism.sh(now run bymake lint-sh) plants an unguarded<unistd.h>and requires the stage to fail and name it; a<unistd.h>under#ifndef _WIN32passes; a source whose onlymeson.buildtarget is gated off Windows passes and fails once the gate is removed; a scanner that cannot run (apython3that exits 3 first onPATH) fails the stage.Failing first: the extended test run against master's stage (
f225754c2): the planted unguarded<unistd.h>passes there (FAIL unguarded <unistd.h>: expected rc=1, got 0 ... PASS msvcism), which is the gap. On this branch all seven cases pass. Whole tree: before the gates, the scan found 32 includes in 9 groups (MCP server, fuzz harnesses,vmaf_vpl, the two excepted files, and files nomeson.buildbuilds); with them,scripts/dev/preflight.sh --full --stage msvcismpasses with 0 findings, and the scan ofa21d20ce1reportscore/src/cuda/import_vulkan.c:41: <unistd.h>, the defect that started this.Configure (Meson 1.12.1, MinGW-w64 cross file with
host_machine.system = 'windows', the closest local stand-in for the MSVC lanes):-Denable_mcp=truestops atcore/src/meson.build:274withenable_mcp=true: the embedded MCP server is POSIX-only (Unix-domain and TCP sockets through <sys/socket.h> and <unistd.h>) and cannot be built for Windows;-Dfuzz=truestops at theerror()incore/test/meson.build(line 8959 on the head) with the fuzz message; the default configure succeeds. Master's meson files accept-Denable_mcp=truefor that target (configure rc 0; the compiler fails later). Linux-Denable_mcp=trueconfigures as before.Type
fix— bug fixbuild/ci— tooling / infraChecklist
git commit -s; fix a branch withgit rebase --signoff origin/master). See DCO sign-off.make format && make lintis green locally. — the commit hooks (black, ruff, shfmt, shellcheck, markdownlint, semgrep, HISS audit) pass;ruff checkon the scanner: clean;shellcheckon the stage and the test: clean.python3 scripts/ci/run_meson_test.py -- -C build. — local gate on560119f73, the same change before the rebase onto4dad09e3e(which brought feat(api): import CUDA device frames with event fences and GL textures (RC4 WP3, ADR-2023) #2277 and feat(api): generate the custom resources, their CRDs and the operator role from the platform definition (ADR-2350) #2605, no conflict; on853e5ccd4the msvcism test, the full-tree stage, the configure checks and the train gates were repeated, same results) (CPU,-Db_lto=false,-j4, warnings as errors): build 0 warnings;--suite=fast411 OK, 0 failed (test_gpu_picture_pool_uafwithMALLOC_PERTURB_=0, fix(test): run the GPU pool UAF test without MALLOC_PERTURB_ so it cannot fill the host's memory #2547: 1 OK); codegen tests 151 passed;preflight.sh --stage msvcismpass; affected suites: tooling 2537 passed, 6 skipped, 0 failed;bash scripts/ci/tests/test-preflight-msvcism.sh: 7 of 7./cross-backend-diffand the worst ULP is ≤ 2. — not applicable: no GPU or SIMD code changed..c/.cpp/.cu/.h/.hpp, it has the appropriate license header (seeCONTRIBUTING.md). — no new C source; the new Python scanner carries the EUPL-1.2 header.!orBREAKING CHANGE:and the migration path is documented below. — not breaking: a Windows build withenable_mcp=trueorfuzz=truenever compiled; it now stops at configure.docs/adr/_index_fragments/<NNNN-slug>.mdand nothing else is touched for the index: do not editdocs/adr/README.md,docs/adr/by-tag/,docs/adr/titles.mdor_order.txt— ADR-2646 (claimed withscripts/adr/next-free.sh --claim), fragment added; the index, by-tag and title pages are rendered at landing (ADR-2197).Bug-status hygiene (ADR-0165)
docs/state.mdupdated in this PR — T-MSVCISM-POSIX-HEADER-UNCHECKED-2026-10-08 under Recently closed (found and fixed here).Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests, except by porting Netflix's own updated assertion verbatim from upstream (value and places as upstream has them, measured against the fork's CPU build first; ADR-1828).Golden gate (
GOLDEN_NINJA_JOBS=4 make test-netflix-golden,core/build-goldenbuilt with gcc): 280 passed, 3 skipped. The Linux build compiles the same sources as before; only Windows configures change.Cross-backend numerical results
Not applicable: no extractor, kernel or score path changed.
Deep-dive deliverables (ADR-0108)
## Alternatives considered(gate the three parts with two exceptions, one exception per file, scope the check tocore/src/, port to Windows).AGENTS.mdinvariant note —scripts/dev/AGENTS.md(the scan, its fail-closed exit, the exception file, the Meson gates; caveman check: pass).changelog.d/changed/msvcism-posix-headers.md.docs/rebase-notes.d/msvcism-posix-headers.md(the Meson gates an upstream sync keeps, the stage's fail-closed scan, the exceptions).Reproducer
Known follow-ups
if/elif/else,foreach,subdir()and the empty-list ternary of Meson. A new way of keeping a source off Windows may need the scanner extended or a named exception.Windows MSVC+*jobs on this PR are the confirmation.