1 //===--- SanitizerArgs.cpp - Arguments for sanitizer tools  ---------------===//
2 //
3 //                     The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 #include "clang/Driver/SanitizerArgs.h"
10 #include "clang/Driver/Driver.h"
11 #include "clang/Driver/DriverDiagnostic.h"
12 #include "clang/Driver/Options.h"
13 #include "clang/Driver/ToolChain.h"
14 #include "llvm/ADT/StringExtras.h"
15 #include "llvm/ADT/StringSwitch.h"
16 #include "llvm/Support/FileSystem.h"
17 #include "llvm/Support/Path.h"
18 #include "llvm/Support/SpecialCaseList.h"
19 #include <memory>
20 
21 using namespace clang::driver;
22 using namespace llvm::opt;
23 
24 namespace {
25 /// Assign ordinals to possible values of -fsanitize= flag.
26 /// We use the ordinal values as bit positions within \c SanitizeKind.
27 enum SanitizeOrdinal {
28 #define SANITIZER(NAME, ID) SO_##ID,
29 #define SANITIZER_GROUP(NAME, ID, ALIAS) SO_##ID##Group,
30 #include "clang/Basic/Sanitizers.def"
31   SO_Count
32 };
33 
34 /// Represents a set of sanitizer kinds. It is also used to define:
35 /// 1) set of sanitizers each sanitizer group expands into.
36 /// 2) set of sanitizers sharing a specific property (e.g.
37 ///    all sanitizers with zero-base shadow).
38 enum SanitizeKind {
39 #define SANITIZER(NAME, ID) ID = 1 << SO_##ID,
40 #define SANITIZER_GROUP(NAME, ID, ALIAS)                                       \
41 ID = ALIAS, ID##Group = 1 << SO_##ID##Group,
42 #include "clang/Basic/Sanitizers.def"
43   NeedsUbsanRt = Undefined | Integer,
44   NotAllowedWithTrap = Vptr,
45   RequiresPIE = Memory | DataFlow,
46   NeedsUnwindTables = Address | Thread | Memory | DataFlow,
47   SupportsCoverage = Address | Memory | Leak | Undefined | Integer,
48   RecoverableByDefault = Undefined | Integer,
49   Unrecoverable = Address | Unreachable | Return,
50   LegacyFsanitizeRecoverMask = Undefined | Integer
51 };
52 }
53 
54 /// Returns true if set of \p Sanitizers contain at least one sanitizer from
55 /// \p Kinds.
56 static bool hasOneOf(const clang::SanitizerSet &Sanitizers, unsigned Kinds) {
57 #define SANITIZER(NAME, ID)                                                    \
58   if (Sanitizers.has(clang::SanitizerKind::ID) && (Kinds & ID))                \
59     return true;
60 #include "clang/Basic/Sanitizers.def"
61   return false;
62 }
63 
64 /// Adds all sanitizers from \p Kinds to \p Sanitizers.
65 static void addAllOf(clang::SanitizerSet &Sanitizers, unsigned Kinds) {
66 #define SANITIZER(NAME, ID) \
67   if (Kinds & ID) \
68     Sanitizers.set(clang::SanitizerKind::ID, true);
69 #include "clang/Basic/Sanitizers.def"
70 }
71 
72 static unsigned toSanitizeKind(clang::SanitizerKind K) {
73 #define SANITIZER(NAME, ID) \
74   if (K == clang::SanitizerKind::ID) \
75     return ID;
76 #include "clang/Basic/Sanitizers.def"
77   llvm_unreachable("Invalid SanitizerKind!");
78 }
79 
80 /// Parse a single value from a -fsanitize= or -fno-sanitize= value list.
81 /// Returns a member of the \c SanitizeKind enumeration, or \c 0
82 /// if \p Value is not known.
83 static unsigned parseValue(const char *Value);
84 
85 /// Parse a -fsanitize= or -fno-sanitize= argument's values, diagnosing any
86 /// invalid components. Returns OR of members of \c SanitizeKind enumeration.
87 static unsigned parseArgValues(const Driver &D, const llvm::opt::Arg *A,
88                                bool DiagnoseErrors);
89 
90 /// Produce an argument string from ArgList \p Args, which shows how it
91 /// provides some sanitizer kind from \p Mask. For example, the argument list
92 /// "-fsanitize=thread,vptr -fsanitize=address" with mask \c NeedsUbsanRt
93 /// would produce "-fsanitize=vptr".
94 static std::string lastArgumentForMask(const Driver &D,
95                                        const llvm::opt::ArgList &Args,
96                                        unsigned Mask);
97 
98 static std::string lastArgumentForKind(const Driver &D,
99                                        const llvm::opt::ArgList &Args,
100                                        clang::SanitizerKind K) {
101   return lastArgumentForMask(D, Args, toSanitizeKind(K));
102 }
103 
104 /// Produce an argument string from argument \p A, which shows how it provides
105 /// a value in \p Mask. For instance, the argument
106 /// "-fsanitize=address,alignment" with mask \c NeedsUbsanRt would produce
107 /// "-fsanitize=alignment".
108 static std::string describeSanitizeArg(const llvm::opt::Arg *A, unsigned Mask);
109 
110 /// Produce a string containing comma-separated names of sanitizers in \p
111 /// Sanitizers set.
112 static std::string toString(const clang::SanitizerSet &Sanitizers);
113 
114 /// For each sanitizer group bit set in \p Kinds, set the bits for sanitizers
115 /// this group enables.
116 static unsigned expandGroups(unsigned Kinds);
117 
118 static unsigned getToolchainUnsupportedKinds(const ToolChain &TC) {
119   bool IsFreeBSD = TC.getTriple().getOS() == llvm::Triple::FreeBSD;
120   bool IsLinux = TC.getTriple().getOS() == llvm::Triple::Linux;
121   bool IsX86 = TC.getTriple().getArch() == llvm::Triple::x86;
122   bool IsX86_64 = TC.getTriple().getArch() == llvm::Triple::x86_64;
123   bool IsMIPS64 = TC.getTriple().getArch() == llvm::Triple::mips64 ||
124                   TC.getTriple().getArch() == llvm::Triple::mips64el;
125 
126   unsigned Unsupported = 0;
127   if (!(IsLinux && (IsX86_64 || IsMIPS64))) {
128     Unsupported |= Memory | DataFlow;
129   }
130   if (!((IsLinux || IsFreeBSD) && IsX86_64)) {
131     Unsupported |= Thread;
132   }
133   if (!(IsLinux && (IsX86 || IsX86_64))) {
134     Unsupported |= Function;
135   }
136   return Unsupported;
137 }
138 
139 bool SanitizerArgs::needsUbsanRt() const {
140   return !UbsanTrapOnError && hasOneOf(Sanitizers, NeedsUbsanRt);
141 }
142 
143 bool SanitizerArgs::requiresPIE() const {
144   return AsanZeroBaseShadow || hasOneOf(Sanitizers, RequiresPIE);
145 }
146 
147 bool SanitizerArgs::needsUnwindTables() const {
148   return hasOneOf(Sanitizers, NeedsUnwindTables);
149 }
150 
151 void SanitizerArgs::clear() {
152   Sanitizers.clear();
153   RecoverableSanitizers.clear();
154   BlacklistFile = "";
155   SanitizeCoverage = 0;
156   MsanTrackOrigins = 0;
157   AsanFieldPadding = 0;
158   AsanZeroBaseShadow = false;
159   UbsanTrapOnError = false;
160   AsanSharedRuntime = false;
161   LinkCXXRuntimes = false;
162 }
163 
164 SanitizerArgs::SanitizerArgs(const ToolChain &TC,
165                              const llvm::opt::ArgList &Args) {
166   clear();
167   unsigned AllRemove = 0;  // During the loop below, the accumulated set of
168                            // sanitizers disabled by the current sanitizer
169                            // argument or any argument after it.
170   unsigned DiagnosedKinds = 0;  // All Kinds we have diagnosed up to now.
171                                 // Used to deduplicate diagnostics.
172   unsigned Kinds = 0;
173   unsigned NotSupported = getToolchainUnsupportedKinds(TC);
174   const Driver &D = TC.getDriver();
175   for (ArgList::const_reverse_iterator I = Args.rbegin(), E = Args.rend();
176        I != E; ++I) {
177     const auto *Arg = *I;
178     if (Arg->getOption().matches(options::OPT_fsanitize_EQ)) {
179       Arg->claim();
180       unsigned Add = parseArgValues(D, Arg, true);
181 
182       // Avoid diagnosing any sanitizer which is disabled later.
183       Add &= ~AllRemove;
184       // At this point we have not expanded groups, so any unsupported
185       // sanitizers in Add are those which have been explicitly enabled.
186       // Diagnose them.
187       if (unsigned KindsToDiagnose = Add & NotSupported & ~DiagnosedKinds) {
188         // Only diagnose the new kinds.
189         std::string Desc = describeSanitizeArg(*I, KindsToDiagnose);
190         D.Diag(diag::err_drv_unsupported_opt_for_target)
191             << Desc << TC.getTriple().str();
192         DiagnosedKinds |= KindsToDiagnose;
193       }
194       Add &= ~NotSupported;
195 
196       Add = expandGroups(Add);
197       // Group expansion may have enabled a sanitizer which is disabled later.
198       Add &= ~AllRemove;
199       // Silently discard any unsupported sanitizers implicitly enabled through
200       // group expansion.
201       Add &= ~NotSupported;
202 
203       Kinds |= Add;
204     } else if (Arg->getOption().matches(options::OPT_fno_sanitize_EQ)) {
205       Arg->claim();
206       unsigned Remove = parseArgValues(D, Arg, true);
207       AllRemove |= expandGroups(Remove);
208     }
209   }
210   addAllOf(Sanitizers, Kinds);
211 
212   // Parse -f(no-)?sanitize-recover flags.
213   unsigned RecoverableKinds = RecoverableByDefault;
214   unsigned DiagnosedUnrecoverableKinds = 0;
215   for (const auto *Arg : Args) {
216     if (Arg->getOption().matches(options::OPT_fsanitize_recover)) {
217       // FIXME: Add deprecation notice, and then remove this flag.
218       RecoverableKinds |= expandGroups(LegacyFsanitizeRecoverMask);
219       Arg->claim();
220     } else if (Arg->getOption().matches(options::OPT_fno_sanitize_recover)) {
221       // FIXME: Add deprecation notice, and then remove this flag.
222       RecoverableKinds &= ~expandGroups(LegacyFsanitizeRecoverMask);
223       Arg->claim();
224     } else if (Arg->getOption().matches(options::OPT_fsanitize_recover_EQ)) {
225       unsigned Add = parseArgValues(D, Arg, true);
226       // Report error if user explicitly tries to recover from unrecoverable
227       // sanitizer.
228       if (unsigned KindsToDiagnose =
229               Add & Unrecoverable & ~DiagnosedUnrecoverableKinds) {
230         SanitizerSet SetToDiagnose;
231         addAllOf(SetToDiagnose, KindsToDiagnose);
232         D.Diag(diag::err_drv_unsupported_option_argument)
233             << Arg->getOption().getName() << toString(SetToDiagnose);
234         DiagnosedUnrecoverableKinds |= KindsToDiagnose;
235       }
236       RecoverableKinds |= expandGroups(Add);
237       Arg->claim();
238     } else if (Arg->getOption().matches(options::OPT_fno_sanitize_recover_EQ)) {
239       RecoverableKinds &= ~expandGroups(parseArgValues(D, Arg, true));
240       Arg->claim();
241     }
242   }
243   RecoverableKinds &= Kinds;
244   RecoverableKinds &= ~Unrecoverable;
245   addAllOf(RecoverableSanitizers, RecoverableKinds);
246 
247   UbsanTrapOnError =
248     Args.hasFlag(options::OPT_fsanitize_undefined_trap_on_error,
249                  options::OPT_fno_sanitize_undefined_trap_on_error, false);
250 
251   // Warn about undefined sanitizer options that require runtime support.
252   if (UbsanTrapOnError && hasOneOf(Sanitizers, NotAllowedWithTrap)) {
253     D.Diag(clang::diag::err_drv_argument_not_allowed_with)
254       << lastArgumentForMask(D, Args, NotAllowedWithTrap)
255       << "-fsanitize-undefined-trap-on-error";
256   }
257 
258   // Check for incompatible sanitizers.
259   bool NeedsAsan = Sanitizers.has(SanitizerKind::Address);
260   bool NeedsTsan = Sanitizers.has(SanitizerKind::Thread);
261   bool NeedsMsan = Sanitizers.has(SanitizerKind::Memory);
262   bool NeedsLsan = Sanitizers.has(SanitizerKind::Leak);
263   if (NeedsAsan && NeedsTsan)
264     D.Diag(clang::diag::err_drv_argument_not_allowed_with)
265       << lastArgumentForKind(D, Args, SanitizerKind::Address)
266       << lastArgumentForKind(D, Args, SanitizerKind::Thread);
267   if (NeedsAsan && NeedsMsan)
268     D.Diag(clang::diag::err_drv_argument_not_allowed_with)
269       << lastArgumentForKind(D, Args, SanitizerKind::Address)
270       << lastArgumentForKind(D, Args, SanitizerKind::Memory);
271   if (NeedsTsan && NeedsMsan)
272     D.Diag(clang::diag::err_drv_argument_not_allowed_with)
273       << lastArgumentForKind(D, Args, SanitizerKind::Thread)
274       << lastArgumentForKind(D, Args, SanitizerKind::Memory);
275   if (NeedsLsan && NeedsTsan)
276     D.Diag(clang::diag::err_drv_argument_not_allowed_with)
277       << lastArgumentForKind(D, Args, SanitizerKind::Leak)
278       << lastArgumentForKind(D, Args, SanitizerKind::Thread);
279   if (NeedsLsan && NeedsMsan)
280     D.Diag(clang::diag::err_drv_argument_not_allowed_with)
281       << lastArgumentForKind(D, Args, SanitizerKind::Leak)
282       << lastArgumentForKind(D, Args, SanitizerKind::Memory);
283   // FIXME: Currently -fsanitize=leak is silently ignored in the presence of
284   // -fsanitize=address. Perhaps it should print an error, or perhaps
285   // -f(-no)sanitize=leak should change whether leak detection is enabled by
286   // default in ASan?
287 
288   // Parse -f(no-)sanitize-blacklist options.
289   if (Arg *BLArg = Args.getLastArg(options::OPT_fsanitize_blacklist,
290                                    options::OPT_fno_sanitize_blacklist)) {
291     if (BLArg->getOption().matches(options::OPT_fsanitize_blacklist)) {
292       std::string BLPath = BLArg->getValue();
293       if (llvm::sys::fs::exists(BLPath)) {
294         // Validate the blacklist format.
295         std::string BLError;
296         std::unique_ptr<llvm::SpecialCaseList> SCL(
297             llvm::SpecialCaseList::create(BLPath, BLError));
298         if (!SCL.get())
299           D.Diag(clang::diag::err_drv_malformed_sanitizer_blacklist) << BLError;
300         else
301           BlacklistFile = BLPath;
302       } else {
303         D.Diag(clang::diag::err_drv_no_such_file) << BLPath;
304       }
305     }
306   } else {
307     // If no -fsanitize-blacklist option is specified, try to look up for
308     // blacklist in the resource directory.
309     std::string BLPath;
310     if (getDefaultBlacklist(D, BLPath) && llvm::sys::fs::exists(BLPath))
311       BlacklistFile = BLPath;
312   }
313 
314   // Parse -f[no-]sanitize-memory-track-origins[=level] options.
315   if (NeedsMsan) {
316     if (Arg *A =
317             Args.getLastArg(options::OPT_fsanitize_memory_track_origins_EQ,
318                             options::OPT_fsanitize_memory_track_origins,
319                             options::OPT_fno_sanitize_memory_track_origins)) {
320       if (A->getOption().matches(options::OPT_fsanitize_memory_track_origins)) {
321         MsanTrackOrigins = 1;
322       } else if (A->getOption().matches(
323                      options::OPT_fno_sanitize_memory_track_origins)) {
324         MsanTrackOrigins = 0;
325       } else {
326         StringRef S = A->getValue();
327         if (S.getAsInteger(0, MsanTrackOrigins) || MsanTrackOrigins < 0 ||
328             MsanTrackOrigins > 2) {
329           D.Diag(clang::diag::err_drv_invalid_value) << A->getAsString(Args) << S;
330         }
331       }
332     }
333   }
334 
335   // Parse -fsanitize-coverage=N. Currently one of asan/msan/lsan is required.
336   if (hasOneOf(Sanitizers, SupportsCoverage)) {
337     if (Arg *A = Args.getLastArg(options::OPT_fsanitize_coverage)) {
338       StringRef S = A->getValue();
339       // Legal values are 0..4.
340       if (S.getAsInteger(0, SanitizeCoverage) || SanitizeCoverage < 0 ||
341           SanitizeCoverage > 4)
342         D.Diag(clang::diag::err_drv_invalid_value) << A->getAsString(Args) << S;
343     }
344   }
345 
346   if (NeedsAsan) {
347     AsanSharedRuntime =
348         Args.hasArg(options::OPT_shared_libasan) ||
349         (TC.getTriple().getEnvironment() == llvm::Triple::Android);
350     AsanZeroBaseShadow =
351         (TC.getTriple().getEnvironment() == llvm::Triple::Android);
352     if (Arg *A =
353             Args.getLastArg(options::OPT_fsanitize_address_field_padding)) {
354         StringRef S = A->getValue();
355         // Legal values are 0 and 1, 2, but in future we may add more levels.
356         if (S.getAsInteger(0, AsanFieldPadding) || AsanFieldPadding < 0 ||
357             AsanFieldPadding > 2) {
358           D.Diag(clang::diag::err_drv_invalid_value) << A->getAsString(Args) << S;
359         }
360     }
361 
362     if (Arg *WindowsDebugRTArg =
363             Args.getLastArg(options::OPT__SLASH_MTd, options::OPT__SLASH_MT,
364                             options::OPT__SLASH_MDd, options::OPT__SLASH_MD,
365                             options::OPT__SLASH_LDd, options::OPT__SLASH_LD)) {
366       switch (WindowsDebugRTArg->getOption().getID()) {
367       case options::OPT__SLASH_MTd:
368       case options::OPT__SLASH_MDd:
369       case options::OPT__SLASH_LDd:
370         D.Diag(clang::diag::err_drv_argument_not_allowed_with)
371             << WindowsDebugRTArg->getAsString(Args)
372             << lastArgumentForKind(D, Args, SanitizerKind::Address);
373         D.Diag(clang::diag::note_drv_address_sanitizer_debug_runtime);
374       }
375     }
376   }
377 
378   // Parse -link-cxx-sanitizer flag.
379   LinkCXXRuntimes =
380       Args.hasArg(options::OPT_fsanitize_link_cxx_runtime) || D.CCCIsCXX();
381 }
382 
383 static std::string toString(const clang::SanitizerSet &Sanitizers) {
384   std::string Res;
385 #define SANITIZER(NAME, ID)                                                    \
386   if (Sanitizers.has(clang::SanitizerKind::ID)) {                              \
387     if (!Res.empty())                                                          \
388       Res += ",";                                                              \
389     Res += NAME;                                                               \
390   }
391 #include "clang/Basic/Sanitizers.def"
392   return Res;
393 }
394 
395 void SanitizerArgs::addArgs(const llvm::opt::ArgList &Args,
396                             llvm::opt::ArgStringList &CmdArgs) const {
397   if (Sanitizers.empty())
398     return;
399   CmdArgs.push_back(Args.MakeArgString("-fsanitize=" + toString(Sanitizers)));
400 
401   if (!RecoverableSanitizers.empty())
402     CmdArgs.push_back(Args.MakeArgString("-fsanitize-recover=" +
403                                          toString(RecoverableSanitizers)));
404 
405   if (UbsanTrapOnError)
406     CmdArgs.push_back("-fsanitize-undefined-trap-on-error");
407 
408   if (!BlacklistFile.empty()) {
409     SmallString<64> BlacklistOpt("-fsanitize-blacklist=");
410     BlacklistOpt += BlacklistFile;
411     CmdArgs.push_back(Args.MakeArgString(BlacklistOpt));
412   }
413 
414   if (MsanTrackOrigins)
415     CmdArgs.push_back(Args.MakeArgString("-fsanitize-memory-track-origins=" +
416                                          llvm::utostr(MsanTrackOrigins)));
417   if (AsanFieldPadding)
418     CmdArgs.push_back(Args.MakeArgString("-fsanitize-address-field-padding=" +
419                                          llvm::utostr(AsanFieldPadding)));
420   if (SanitizeCoverage)
421     CmdArgs.push_back(Args.MakeArgString("-fsanitize-coverage=" +
422                                          llvm::utostr(SanitizeCoverage)));
423   // Workaround for PR16386.
424   if (Sanitizers.has(SanitizerKind::Memory))
425     CmdArgs.push_back(Args.MakeArgString("-fno-assume-sane-operator-new"));
426 }
427 
428 bool SanitizerArgs::getDefaultBlacklist(const Driver &D, std::string &BLPath) {
429   const char *BlacklistFile = nullptr;
430   if (Sanitizers.has(SanitizerKind::Address))
431     BlacklistFile = "asan_blacklist.txt";
432   else if (Sanitizers.has(SanitizerKind::Memory))
433     BlacklistFile = "msan_blacklist.txt";
434   else if (Sanitizers.has(SanitizerKind::Thread))
435     BlacklistFile = "tsan_blacklist.txt";
436   else if (Sanitizers.has(SanitizerKind::DataFlow))
437     BlacklistFile = "dfsan_abilist.txt";
438 
439   if (BlacklistFile) {
440     SmallString<64> Path(D.ResourceDir);
441     llvm::sys::path::append(Path, BlacklistFile);
442     BLPath = Path.str();
443     return true;
444   }
445   return false;
446 }
447 
448 unsigned parseValue(const char *Value) {
449   unsigned ParsedKind = llvm::StringSwitch<SanitizeKind>(Value)
450 #define SANITIZER(NAME, ID) .Case(NAME, ID)
451 #define SANITIZER_GROUP(NAME, ID, ALIAS) .Case(NAME, ID##Group)
452 #include "clang/Basic/Sanitizers.def"
453     .Default(SanitizeKind());
454   return ParsedKind;
455 }
456 
457 unsigned expandGroups(unsigned Kinds) {
458 #define SANITIZER(NAME, ID)
459 #define SANITIZER_GROUP(NAME, ID, ALIAS) if (Kinds & ID##Group) Kinds |= ID;
460 #include "clang/Basic/Sanitizers.def"
461   return Kinds;
462 }
463 
464 unsigned parseArgValues(const Driver &D, const llvm::opt::Arg *A,
465                         bool DiagnoseErrors) {
466   assert((A->getOption().matches(options::OPT_fsanitize_EQ) ||
467           A->getOption().matches(options::OPT_fno_sanitize_EQ) ||
468           A->getOption().matches(options::OPT_fsanitize_recover_EQ) ||
469           A->getOption().matches(options::OPT_fno_sanitize_recover_EQ)) &&
470          "Invalid argument in parseArgValues!");
471   unsigned Kinds = 0;
472   for (unsigned I = 0, N = A->getNumValues(); I != N; ++I) {
473     const char *Value = A->getValue(I);
474     unsigned Kind;
475     // Special case: don't accept -fsanitize=all.
476     if (A->getOption().matches(options::OPT_fsanitize_EQ) &&
477         0 == strcmp("all", Value))
478       Kind = 0;
479     else
480       Kind = parseValue(Value);
481 
482     if (Kind)
483       Kinds |= Kind;
484     else if (DiagnoseErrors)
485       D.Diag(clang::diag::err_drv_unsupported_option_argument)
486           << A->getOption().getName() << Value;
487   }
488   return Kinds;
489 }
490 
491 std::string lastArgumentForMask(const Driver &D, const llvm::opt::ArgList &Args,
492                                 unsigned Mask) {
493   for (llvm::opt::ArgList::const_reverse_iterator I = Args.rbegin(),
494                                                   E = Args.rend();
495        I != E; ++I) {
496     const auto *Arg = *I;
497     if (Arg->getOption().matches(options::OPT_fsanitize_EQ)) {
498       unsigned AddKinds = expandGroups(parseArgValues(D, Arg, false));
499       if (AddKinds & Mask)
500         return describeSanitizeArg(Arg, Mask);
501     } else if (Arg->getOption().matches(options::OPT_fno_sanitize_EQ)) {
502       unsigned RemoveKinds = expandGroups(parseArgValues(D, Arg, false));
503       Mask &= ~RemoveKinds;
504     }
505   }
506   llvm_unreachable("arg list didn't provide expected value");
507 }
508 
509 std::string describeSanitizeArg(const llvm::opt::Arg *A, unsigned Mask) {
510   assert(A->getOption().matches(options::OPT_fsanitize_EQ)
511          && "Invalid argument in describeSanitizerArg!");
512 
513   std::string Sanitizers;
514   for (unsigned I = 0, N = A->getNumValues(); I != N; ++I) {
515     if (expandGroups(parseValue(A->getValue(I))) & Mask) {
516       if (!Sanitizers.empty())
517         Sanitizers += ",";
518       Sanitizers += A->getValue(I);
519     }
520   }
521 
522   assert(!Sanitizers.empty() && "arg didn't provide expected value");
523   return "-fsanitize=" + Sanitizers;
524 }
525