With CONFIG_GCC_PLUGIN_STACKLEAK=y, kstack erase adds: -fplugin=$(objtree)/scripts/gcc-plugins/stackleak_plugin.so
For KBUILD_EXTMOD builds, recording gcc switches can embed this host/build specific plugin path into module DWARF producer strings, which trips QA checks looking for absolute path leakage. Disable gcc switch recording only for external modules by adding -gno-record-gcc-switches to kstack-erase-cflags when KBUILD_EXTMOD is set. This keeps stackleak plugin instrumentation enabled while avoiding leakage of host-specific paths in external module debug metadata. Suggested-by: Nathan Chancellor <[email protected]> Link: https://lore.kernel.org/all/20260803181217.GB1067866@ax162/ Signed-off-by: Jaihind Yadav <[email protected]> --- scripts/Makefile.kstack_erase | 1 + 1 file changed, 1 insertion(+) diff --git a/scripts/Makefile.kstack_erase b/scripts/Makefile.kstack_erase index ee7e4ef7b892..6f31a3915d24 100644 --- a/scripts/Makefile.kstack_erase +++ b/scripts/Makefile.kstack_erase @@ -5,6 +5,7 @@ kstack-erase-cflags-y += -fplugin=$(objtree)/scripts/gcc-plugins/stackleak_plugi kstack-erase-cflags-y += -fplugin-arg-stackleak_plugin-track-min-size=$(CONFIG_KSTACK_ERASE_TRACK_MIN_SIZE) kstack-erase-cflags-y += -fplugin-arg-stackleak_plugin-arch=$(SRCARCH) kstack-erase-cflags-$(CONFIG_GCC_PLUGIN_STACKLEAK_VERBOSE) += -fplugin-arg-stackleak_plugin-verbose +kstack-erase-cflags-$(if $(KBUILD_EXTMOD),y) += -gno-record-gcc-switches DISABLE_KSTACK_ERASE := -fplugin-arg-stackleak_plugin-disable endif -- 2.43.0

