Skip to content
File

Blob: .bazelrc

28.3 KB
1common --enable_platform_specific_config
2build --verbose_failures
3build --build_tag_filters=-off-by-default,-requires-container-engine
4# block network access by default
5build --nosandbox_default_allow_network
6test --test_tag_filters=-off-by-default,-requires-fuzzilli,-requires-container-engine
7test:asan --test_tag_filters=-off-by-default,-no-asan,-requires-fuzzilli,-requires-container-engine
8# exclude enormous tests by default
9build --test_size_filters=-enormous
10# Don't run tests that set up TCP sockets in parallel since they may try to use the same ports. This
11# is less restrictive than marking such tests as "exclusive" since we can still run unrelated tests
12# at the same time.
13test --local_resources=socket=1
14 
15# use lower test timeouts: https://bazel.build/reference/test-encyclopedia#role-test-runner
16# corresponds to small,medium,large,enormous tests (medium is default)
17build --test_timeout=3,15,60,240
18 
19# As part of starlarkification, Bazel 8 and 9 remove a number of rules which now need to be imported
20# from other repositories. In the long term, load() statements will be needed to import these rules.
21# For now, we can still autoload the affected repositories when needed. Do this only for a remaining
22# protobuf component and rules_cc (needed with Bazel 9).
23# cc_test is only included because of highway; remove once they include cc_test properly.
24common --incompatible_autoload_externally="+ProtoInfo,+cc_binary,+cc_library,+cc_test"
25 
26# TODO(cleanup): Bazel 9 sets this by default, which breaks the macOS-cross build. Fix and re-enable.
27common --@bazel_tools//tools/test:incompatible_use_default_test_toolchain=False
28 
29# Enable proto toolchain resolution to use prebuilt protoc (starting with protobuf v34.0). Will be
30# the default starting with Bazel 10.
31common --incompatible_enable_proto_toolchain_resolution
32 
33# bazel7 enables Build without the Bytes (BwoB) by default. This significantly speeds up builds
34# using the remote cache since less data needs to be fetched.
35# Note that we use remote_download_minimal for test builds, which avoids fetching build outputs
36# where possible. While several previous BwoB bugs have been fixed, this is slower than it could be
37# due to https://github.com/bazelbuild/bazel/issues/20576.
38 
39# Import CI-specific configuration. As the amount of custom configuration settings we use grows,
40# consider moving more flags out to separate files.
41import %workspace%/build/ci.bazelrc
42import %workspace%/build/rust_lint.bazelrc
43import %workspace%/build/tools/clang_tidy/clang_tidy.bazelrc
44 
45# Continue building locally when remote cache entries fail to materialize
46build --incompatible_remote_local_fallback_for_remote_cache
47 
48# Use -isystem for cc_library includes attribute – this prevents warnings for misbehaving external
49# code.
50build:linux --features=external_include_paths --host_features=external_include_paths
51 
52# Forward compatibility with future Bazel versions:
53# Disable deprecated cfg = "host" Bazel rule setting. Blocked on perfetto.
54# common --incompatible_disable_starlark_host_transitions
55 
56# Our dependencies (ICU, zlib, etc.) produce a lot of these warnings, so we disable them.
57build --per_file_copt='external@-Wno-error'
58build --per_file_copt='external@-Wno-suggest-override'
59build --per_file_copt='external/.*v8@-Wno-unused-function'
60build --per_file_copt='external/zlib@-Wno-deprecated-non-prototype'
61build --host_per_file_copt='external/zlib@-Wno-deprecated-non-prototype'
62build --per_file_copt=external/protobuf@-Wno-deprecated-declarations
63build --host_per_file_copt=external/protobuf@-Wno-deprecated-declarations
64 
65# opt in to capnp deprecation warnings about trying to attach to a refcounted object
66build --cxxopt=-DKJ_WARN_REFCOUNTED_ATTACH=1
67 
68# TODO(cleanup): Causes warnings with LLVM20, fix and enable again
69build --copt=-Wno-nontrivial-memaccess
70 
71# Unconditionally optimize V8 heap.cc on macOS – when optimization or inlining are disabled, this
72# file appears to cause segfaults at workerd startup on macOS.
73# TODO(cleanup): Investigate why this happens, our patches do not modify heap.cc itself so the bug
74# might be introduced through a header included in heap.cc, through the Bazel build configuration or
75# a bug in Apple LLVM.
76build:macos --per_file_copt=v8/src/heap/heap.cc@-O3
77 
78# The macOS apple_support toolchain sets -DDEBUG for fastbuild, unlike the Linux toolchain. This is
79# unhelpful for compile speeds and test performance, and may cause compile errors based on V8 DCHECK
80# macros that reference symbols only available with V8_VERIFY_WRITE_BARRIERS (a debug-only define),
81# causing compile errors. Undefine DEBUG to match Linux behavior.
82build:macos --copt=-UDEBUG
83 
84# Increasing the optimization level of V8 significantly speeds up tests using V8 a lot, especially
85# python tests. This is useful for both CI and local development and enabled by default, but still
86# kept in a separate configuration to make it easy to disable.
87build:v8-codegen-opt --per_file_copt=v8/src@-O3
88# V8 is heavily using absl for hashing now, optimize it too.
89build:v8-codegen-opt --per_file_copt=external/abseil-cpp@-O3
90# zlib and tcmalloc (for Linux) are also CPU-intensive, optimize them too.
91build:v8-codegen-opt --per_file_copt=external/tcmalloc@-O3
92build:v8-codegen-opt --per_file_copt=external/zlib@-O3
93# BoringSSL is CPU-intensive for crypto tests, optimize it too.
94build:v8-codegen-opt --per_file_copt=external/boringssl@-O3
95# simdutf is used for fast string encoding/decoding
96build:v8-codegen-opt --per_file_copt=external/+http+simdutf@-O3
97# ICU and perfetto are generally updated with V8 and rarely need to be updated, optimize them too.
98build:v8-codegen-opt --per_file_copt=external/.*com_googlesource_chromium_icu@-O3
99build:v8-codegen-opt --per_file_copt=external/perfetto@-O3
100 
101build:v8-codegen-opt-windows --per_file_copt=v8/src@/O2,/clang:-O3
102build:v8-codegen-opt-windows --per_file_copt=external/abseil-cpp@/O2,/clang:-O3
103build:v8-codegen-opt-windows --per_file_copt=external/zlib@/O2,/clang:-O3
104build:v8-codegen-opt-windows --per_file_copt=external/boringssl@/O2,/clang:-O3
105build:v8-codegen-opt-windows --per_file_copt=external/+http+simdutf@/O2,/clang:-O3
106build:v8-codegen-opt-windows --per_file_copt=external/.*com_googlesource_chromium_icu@/O2,/clang:-O3
107build:v8-codegen-opt-windows --per_file_copt=external/perfetto@/O2,/clang:-O3
108 
109build:unix --config=v8-codegen-opt
110build:windows --config=v8-codegen-opt-windows
111 
112# In Google projects, exceptions are not used as a rule. Disabling them is more consistent with the
113# canonical V8 build and improves code size. Paths are adjusted for bzlmod mangling – V8 and ICU use
114# a wildcard for this as the prefix is some variation of +_repo_rules3+ where the number can change
115# when refactoring MODULE.bazel – setting this directly would be too brittle
116build:unix --per_file_copt=external/abseil-cpp@-fno-exceptions
117build:unix --per_file_copt=external/protobuf@-fno-exceptions
118build:unix --per_file_copt=external/tcmalloc@-fno-exceptions
119build:unix --per_file_copt=external/.*com_googlesource_chromium_icu@-fno-exceptions
120build:unix --per_file_copt=external/perfetto@-fno-exceptions
121build:unix --per_file_copt=external/boringssl@-fno-exceptions
122build:unix --per_file_copt=external/.*v8@-fno-exceptions
123build:unix --per_file_copt=external/ada-url@-fno-exceptions
124build:unix --per_file_copt=external/+http+simdutf@-fno-exceptions
125build:windows --per_file_copt=external/abseil-cpp@/clang:-fno-exceptions
126build:windows --per_file_copt=external/protobuf@/clang:-fno-exceptions
127build:windows --per_file_copt=external/tcmalloc@/clang:-fno-exceptions
128build:windows --per_file_copt=external/.*com_googlesource_chromium_icu@/clang:-fno-exceptions
129build:windows --per_file_copt=external/perfetto@/clang:-fno-exceptions
130build:windows --per_file_copt=external/boringssl@/clang:-fno-exceptions
131build:windows --per_file_copt=external/.*v8@/clang:-fno-exceptions
132build:windows --per_file_copt=external/ada-url@/clang:-fno-exceptions
133build:windows --per_file_copt=external/+http+simdutf@/clang:-fno-exceptions
134 
135# V8 torque is an exception from this policy, see v8 BUILD.gn.
136build:unix --per_file_copt=external/.*v8/src/torque@-fexceptions
137build:windows --per_file_copt=external/.*v8/src/torque@/clang:-fexceptions
138 
139# Limit transitive header includes within libc++. This improves compliance with IWYU, helps avoid
140# errors with downstream projects that implicitly define this already and reduces total include size.
141https://libcxx.llvm.org/DesignDocs/HeaderRemovalPolicy.html
142build:unix --cxxopt=-D_LIBCPP_REMOVE_TRANSITIVE_INCLUDES --host_cxxopt=-D_LIBCPP_REMOVE_TRANSITIVE_INCLUDES
143# Do not enable libc++ ABI tags. This makes mangled symbol names and thus include overhead and code
144# size slightly smaller and is safe as long as we don't link with several copies of libc++.
145build:unix --cxxopt=-D_LIBCPP_NO_ABI_TAG --host_cxxopt=-D_LIBCPP_NO_ABI_TAG
146# Disable the experimental (and currently incomplete) parallel STL implementation as with
147# downstream, this reduces the include overhead for <algorithm>.
148build:unix --cxxopt=-D_LIBCPP_HAS_NO_INCOMPLETE_PSTL --host_cxxopt=-D_LIBCPP_HAS_NO_INCOMPLETE_PSTL
149 
150# V8 redefines the _WIN32_WINNT set by bazel, disable warnings for redefined macros. Since V8 uses
151# a global define for this, we need to apply it for everything.
152# TODO(cleanup): Patch upstream V8 to use local_defines for this instead.
153build:windows --copt='-Wno-macro-redefined'
154build:windows --host_copt='-Wno-macro-redefined'
155 
156# typescript configuration
157# do more correct type checking
158common --@aspect_rules_ts//ts:skipLibCheck=honor_tsconfig
159# Use "tsc" as the transpiler when ts_project has no `transpiler` set.
160common --@aspect_rules_ts//ts:default_to_tsc_transpiler
161 
162# optimized LTO build.
163build:thin-lto --config=opt
164build:thin-lto --copt='-flto=thin'
165build:thin-lto --linkopt='-flto=thin'
166 
167# configuration used for performance profiling
168build:profile --config=thin-lto
169build:profile --copt="-fno-omit-frame-pointer" --copt="-mno-omit-leaf-frame-pointer"
170build:profile --config=limited-dbg-info
171build:profile --strip=never
172 
173# configuration used for performance benchmarking is the same as profiling for consistency
174build:benchmark --config=profile
175 
176# Define a debug config which is primarily intended for local development.
177build:debug -c dbg
178 
179# Using simple template names saves around 5% of binary size of workerd.
180build:unix --cxxopt='-gsimple-template-names' --host_cxxopt='-gsimple-template-names'
181# Enable hidden visibility for inline functions. This can cause problems when comparing pointers to
182# inline functions across shared library boundaries, but this is unlikely to be done anywhere
183# within workerd, V8 explicitly supports hidden visibility.
184build:unix --cxxopt='-fvisibility-inlines-hidden' --host_cxxopt='-fvisibility-inlines-hidden'
185 
186# Define a config mode which is fastbuild but with basic debug info.
187build:fastdbg -c fastbuild
188build:fastdbg --config=limited-dbg-info
189build:fastdbg --config=rust-debug
190build:fastdbg --strip=never
191build:fastdbg --//:dead_strip=False
192 
193# provide a limited amount of debug info, sufficient for qualified stack traces.
194build:limited-dbg-info --copt='-g1' --copt="-fdebug-info-for-profiling"
195 
196# Miscellaneous platform-independent options
197build --@capnp-cpp//src/kj:openssl=True --@capnp-cpp//src/kj:zlib=True --@capnp-cpp//src/kj:brotli=True
198build --@capnp-cpp//src/capnp:gen_rust=True
199# always have KJ_IREQUIRE checks enabled, this matches workers production.
200build --@capnp-cpp//src/kj:kj_enable_irequire=True
201# overriden in config=opt
202build --@capnp-cpp//src/kj:debug_memory=True
203build --cxxopt="-fbracket-depth=512" --host_cxxopt="-fbracket-depth=512"
204 
205# Additional Rust flags (see https://doc.rust-lang.org/rustc/codegen-options/index.html)
206# Need to disable debug-assertions for fastbuild, should be off automatically for opt.
207# Using extra_rustc_flag for non-exec flags so they can be overwritten selectively.
208build --@rules_rust//:extra_rustc_flag=-Cdebug-assertions=n
209build --@rules_rust//:extra_exec_rustc_flags=-Cdebug-assertions=n
210build --@rules_rust//:rustfmt.toml=//src/rust:rustfmt.toml
211 
212# We default to not enabling debug assertions and unwinding for Rust. For debug builds this is not
213# the right setting, but unfortunately we can't set that directly.
214build:rust-debug --@rules_rust//:extra_rustc_flag=-Cdebug-assertions=y
215# Use the equivalent of -g/-g2 for Rust here, this is necessary to get qualified stack traces while
216# -Zdebug-info-for-profiling is unavailable. Unlike gcc/clang, Rust defaults to -g3 otherwise.
217build:rust-debug --@rules_rust//:extra_rustc_flag=-Cdebuginfo=1
218build:rust-debug --@rules_rust//:extra_rustc_flag=-Cstrip=none
219 
220# Adding -C lto=thin here would improve binary size significantly – disable it for now due to
221# compile errors and wrong code generation when bazel and rust use different LLVM versions.
222build:thin-lto --@rules_rust//:extra_rustc_flag=-Ccodegen-units=1
223 
224# common sanitizers options
225build:sanitizer-common --@workerd//src/workerd/server:use_tcmalloc=False
226build:sanitizer-common --copt="-fsanitize-link-c++-runtime" --linkopt="-fsanitize-link-c++-runtime"
227build:sanitizer-common --copt="-Og"
228build:sanitizer-common --copt="-g" --strip=never
229build:sanitizer-common --copt="-fno-optimize-sibling-calls"
230build:sanitizer-common --copt="-fno-omit-frame-pointer" --copt="-mno-omit-leaf-frame-pointer"
231 
232# address sanitizer (https://github.com/google/sanitizers/wiki/AddressSanitizer)
233build:asan --config=sanitizer-common
234build:asan --copt="-fsanitize=address" --linkopt="-fsanitize=address"
235build:asan --test_env=ASAN_OPTIONS=abort_on_error=true
236build:asan --test_env=KJ_CLEAN_SHUTDOWN=1
237# Enable ASan, LSan support in V8
238build:asan --copt="-DV8_USE_ADDRESS_SANITIZER"
239build:asan --per_file_copt='external/.*v8@-DADDRESS_SANITIZER,-DLEAK_SANITIZER'
240 
241# fuzzilli (https://github.com/googleprojectzero/fuzzilli/)
242build:fuzzilli --config=asan
243build:fuzzilli --copt="-DWORKERD_FUZZILLI"
244build:fuzzilli --linkopt="-DWORKERD_FUZZILLI"
245build:fuzzilli --copt="-fsanitize-coverage=trace-pc-guard"
246build:fuzzilli --linkopt="-fsanitize-coverage=trace-pc-guard"
247build:fuzzilli --linkopt="-static-libasan"
248# Set ASan/UBSan options globally to abort on error (raise SIGABRT) for proper Fuzzilli crash detection
249build:fuzzilli --action_env=ASAN_OPTIONS=abort_on_error=1:symbolize=false
250build:fuzzilli --action_env=UBSAN_OPTIONS=abort_on_error=1:symbolize=false
251# Override test filters to include requires-fuzzilli tests (inherits asan's -no-asan filter)
252test:fuzzilli --test_tag_filters=-off-by-default
253 
254#
255# Linux and macOS
256#
257build:unix --workspace_status_command=./tools/unix/workspace-status.sh
258 
259build:unix --cxxopt='-std=c++23' --host_cxxopt='-std=c++23'
260build:unix --@capnp-cpp//src/kj:libdl=True
261 
262# Bazel uses CC to compile C and C++ actions, no need to define CXX.
263build:unix --repo_env=BAZEL_COMPILER=clang
264build:unix --repo_env=CC=clang
265 
266build:unix --test_env=LLVM_SYMBOLIZER=llvm-symbolizer
267 
268# Warning options.
269build:unix --cxxopt='-Wall' --host_cxxopt='-Wall'
270build:unix --cxxopt='-Wextra' --host_cxxopt='-Wextra'
271build:unix --cxxopt='-Wunused-function' --host_cxxopt='-Wunused-function'
272build:unix --cxxopt='-Wunused-lambda-capture' --host_cxxopt='-Wunused-lambda-capture'
273build:unix --cxxopt='-Wunused-variable' --host_cxxopt='-Wunused-variable'
274build:unix --cxxopt='-Wno-sign-compare' --host_cxxopt='-Wno-sign-compare'
275build:unix --cxxopt='-Wno-unused-parameter' --host_cxxopt='-Wno-unused-parameter'
276build:unix --cxxopt='-Wno-missing-field-initializers' --host_cxxopt='-Wno-missing-field-initializers'
277build:unix --cxxopt='-Wsuggest-override'
278 
279build:linux --config=unix
280build:macos --config=unix
281 
282# Support macOS 13 as the minimum version. There should be at least a warning when backward
283# compatibility is broken as -Wunguarded-availability-new is enabled by default. Only enable for
284# target configuration as host configuration tools are only used during the build process.
285build:macos --macos_minimum_os=13.5
286 
287# Avoid emitting duplicate unwind info where compact unwind info can be used. This reduces the
288# object size by ~5% on average, improving disk space usage and link times. The final binary size
289# is not affected. Note that this is on-by-default on arm64, but turning it on for all mac builds
290# is easier than adding the flag only on x86. See https://reviews.llvm.org/D122258 for detailed
291# information on the flag.
292build:macos --copt='-femit-dwarf-unwind=no-compact-unwind'
293 
294# Cross-Compilation
295# Only cross-compiling on macOS from Apple Silicon to x86_64 is supported – using apple_support
296# makes this much easier than on other platforms. We could define a configuration for cross-
297# compiling from Intel Mac too, but it lacks a means to run Apple Silicon binaries. We would have to
298# change V8 mksnapshot to build in the host configuration again (effectively compiling much of V8
299# twice) and couldn't run tests, so it would provide little value.
300#
301# Define the target platform
302build:macos-cross-x86_64 --cpu=darwin_x86_64 --host_cpu=darwin_arm64 --platforms //:macOS_x86
303# Some cross-compiled tests are slower when run over Rosetta, increase the medium test size timeout.
304# Test performance is still very much satisfactory considering that emulation is being used here.
305build:macos-cross-x86_64 --test_timeout=1,30,60,240
306 
307# On Linux, always link libc++ statically to avoid compatibility issues with different OS versions.
308# macOS links with dynamic libc++ by default, which has good backwards compatibility.
309# Drop default link flags, which include libstdc++ for Linux
310build:linux --features=-default_link_libs --host_features=-default_link_libs
311build:linux --cxxopt='-stdlib=libc++' --host_cxxopt='-stdlib=libc++'
312build:linux --linkopt='-stdlib=libc++' --host_linkopt='-stdlib=libc++'
313build:linux --linkopt='-l:libc++.a' --linkopt='-lm' --linkopt='-static-libgcc'
314# We don't expect to distribute host tools, no need to statically link libgcc.
315# TODO(cleanup): Ideally we'd also use shared libc++ here, we'd just need to install the
316# libunwind-<version>-dev and libc++abi-<version>-dev packages on CI to have all of shared libc++
317# available.
318build:linux --host_linkopt='-l:libc++.a' --host_linkopt='-lm'
319 
320# On Linux, enable PIC. In macos pic is the default, and the objc_library rule does not work
321# correctly if we use this flag since it will not find the object files to include
322# https://github.com/bazelbuild/bazel/issues/12439#issuecomment-914449079
323build:linux --force_pic
324 
325# On Linux, garbage collection sections and optimize binary size. These do not apply to the macOS
326# toolchain.
327build:linux --linkopt="-Wl,--gc-sections"
328build:linux --copt="-ffunction-sections" --host_copt="-ffunction-sections"
329build:linux --copt="-fdata-sections" --host_copt="-fdata-sections"
330 
331# On Linux, use clang lld.
332build:linux --linkopt="-fuse-ld=lld"
333 
334#
335# Windows
336#
337 
338# See https://bazel.build/configure/windows#symlink
339startup --windows_enable_symlinks
340build:windows --workspace_status_command=./tools/windows/workspace-status.cmd
341build:windows --enable_runfiles
342# We use LLVM's MSVC-compatible compiler driver to compile our code on Windows,
343# as opposed to using MSVC directly. This enables us to use the "same" compiler
344# frontend on Linux, macOS, and Windows, massively reducing the effort required
345# to compile workerd on Windows. Notably, this provides proper support for
346# `#pragma once` when using symlinked virtual includes, `__atomic_*` functions,
347# a standards-compliant preprocessor, support for GNU statement expressions
348# used by some KJ macros, and understands the `.c++` extension by default.
349# As of bazel 7, toolchain resolution is enabled by default, so we need to define a platform for
350# the clang-cl build.
351build:windows --extra_toolchains=@local_config_cc//:cc-toolchain-x64_windows-clang-cl
352build:windows --extra_execution_platforms=//:x64_windows-clang-cl
353 
354# The Windows fastbuild bazel configuration is broken in that it necessarily generates PDB debug
355# information while the Linux and macOS toolchains only compile with debug information in the dbg
356# configuration or when requested with the -g flag. This causes huge increases in compile time and
357# disk/cache space usage – a single test may come with a 490MB PDB file.
358# In an optional configuration, use the opt configuration and manually disable optimizations as a
359# workaround.
360 
361build:windows_no_dbg -c opt
362build:windows_no_dbg --copt='/Od'
363build:windows_no_dbg --linkopt='/INCREMENTAL:NO'
364build:windows_no_dbg --features=-smaller_binary
365 
366# Mitigate the large size impact of Windows debug binaries somewhat by applying string merging and
367# linker garbage collection.
368build:windows_dbg --config=debug
369build:windows_dbg --copt='/Gy' --copt='/Gw'
370build:windows_dbg --linkopt='/OPT:REF'
371build:windows_dbg --linkopt='/OPT:LLDTAILMERGE' --linkopt='/OPT:SAFEICF'
372 
373# This hides inline symbols in classes that are marked to be exported, similar to
374# -fvisibility-inlines-hidden on Unix systems (https://blog.llvm.org/2018/11/30-faster-windows-builds-with-clang-cl_14.html)
375# Currently this only reduces object sizes slightly, larger gains are possible if we compile V8 as
376# a shared library.
377build:windows --copt='/Zc:dllexportInlines-'
378 
379# Configuration for header parsing. Requires bazel toolchain support (available for macOS, Linux).
380build:parse_headers --features=parse_headers --process_headers_in_dependencies
381# Silence some capnproto warnings/errors that are not relevant for header parsing
382build:parse_headers --per_file_copt='.*\.h@-Wno-unused-function,-Wno-pragma-system-header-outside-header'
383build:parse_headers --per_file_copt=external/+http+capnp-cpp/src/kj/common.h@-Wno-unreachable-code
384build:parse_headers --per_file_copt=external/+http+capnp-cpp/src/capnp/arena.h@-DCAPNP_PRIVATE
385 
386# optimized configuration
387build:opt -c opt
388build:opt --@capnp-cpp//src/kj:debug_memory=False
389 
390# Release configuration.
391build:release --config=opt
392build:release --@rules_rust//:extra_rustc_flag=-Ccodegen-units=1
393 
394# enable -O3 for the release configuration. Based on benchmarking there is little difference in
395# performance, but -O3 should generally be expected to be faster for at least parts of the workerd API.
396build:release_unix --copt='-O3'
397build:release_unix --config=release
398 
399build:release_linux --config=release_unix
400build:release_linux --linkopt="-Wl,-O2"
401 
402build:release_macos --config=release_unix
403# Disable generating LC_DATA_IN_CODE and LC_FUNCTION_STARTS binary sections, two rarely used types
404# of macOS debug info. These sections are largely undocumented, but are used by LLDB to improve
405# debugging on binaries that are otherwise stripped. There should be no need to include this
406# data in releases.
407build:release_macos --linkopt="-Wl,-no_data_in_code_info"
408build:release_macos --linkopt="-Wl,-no_function_starts"
409 
410# Cross-compiled release build for x86_64.
411build:release_macos_cross_x86_64 --config=release_macos
412build:release_macos_cross_x86_64 --config=macos-cross-x86_64
413 
414# On macOS, optionally compile using LLD (19 or higher is compatible with the default flags added by
415# apple_support). Requires Homebrew's lld package to be installed and symlinked into /usr/local/bin.
416# This is less CPU intensive than the system linker, but also slightly slower in terms of wall time
417# since it is less parallel. More importantly, it allows us to enable LLD's ICF pass, which
418# significantly decreases binary sizes. We could use Xcode 16's -Wl,-deduplicate option instead, but
419# LLD's ICF appears to be superior. We also want to enable ICF for Linux, but there it causes
420# warnings when dynamically linking with libc++.
421build:macos_lld --linkopt=-fuse-ld=lld --linkopt=--ld-path=/usr/local/bin/ld64.lld
422build:macos_lld_icf --config=macos_lld
423build:macos_lld_icf --linkopt="-Wl,--icf=safe"
424 
425build:release_windows --config=release
426# Windows uses /O2 as its preferred optimization setting and enabled by bazel in the opt
427# configuration, but for clang-cl this is equivalent to only -O2 and a few other things. -O3 is
428# not exposed directly in the clang-cl driver, but we can access regular clang
429# flags using the /clang prefix anyway. https://clang.llvm.org/docs/UsersManual.html#the-clang-option
430build:release_windows --copt="/clang:-O3"
431# clang-cl does not enable strict aliasing by default to match MSVC's approach, unlike clang on
432# Unix which turns it on for opt builds.
433build:release_windows --copt="-fstrict-aliasing"
434# TODO(soon): Investigate these issues on an actual Windows system.
435# Compiling these files causes clang-cl 20 to crash on Windows release builds, work around this by
436# disabling inlining (using /Od would work too but we still want to have whatever optimizations we
437# can have)
438build:release_windows --per_file_copt="src/workerd/server/server"@/clang:-fno-inline
439build:release_windows --per_file_copt="src/workerd/server/container-client"@/clang:-fno-inline
440# Work around Windows test failures in rpc-related tests
441build:release_windows --per_file_copt=src/workerd/io/worker-interface@/clang:-fno-inline
442 
443build:windows --cxxopt='/std:c++23preview' --host_cxxopt='/std:c++23preview'
444build:windows --copt='/D_CRT_USE_BUILTIN_OFFSETOF' --host_copt='/D_CRT_USE_BUILTIN_OFFSETOF'
445build:windows --copt='/DWIN32_LEAN_AND_MEAN' --host_copt='/DWIN32_LEAN_AND_MEAN'
446build:windows --copt='/EHs' --host_copt='/EHs'
447# The `/std:c++23preview` argument is unused during BoringSSL compilation and we don't
448# want a warning when compiling each file.
449build:windows --per_file_copt=external/boringssl@-Wno-unused-command-line-argument --host_per_file_copt=external/boringssl@-Wno-unused-command-line-argument
450 
451# MSVC disappointingly sets __cplusplus to 199711L by default. Defining /Zc:__cplusplus makes it
452# set the correct value. We currently don't check __cplusplus, but some dependencies do.
453build:windows --cxxopt='/Zc:__cplusplus' --host_cxxopt='/Zc:__cplusplus'
454 
455# Coverage configuration using LLVM tools. These environment variables are used by rules_cc
456# to locate LLVM coverage tools. Users should ensure llvm-profdata and llvm-cov are available
457# in PATH (create symlinks to version-specific binaries if needed, e.g., ln -s llvm-cov-19 llvm-cov).
458build:coverage --repo_env=BAZEL_USE_LLVM_NATIVE_COVERAGE=1
459# GCOV is used by rules_cc to merge raw profile data (.profraw) into indexed profile data (.profdata)
460build:coverage --repo_env=GCOV=llvm-profdata
461# COVERAGE_GCOV_PATH is used by collect_cc_coverage.sh for merging .profraw files.
462build:coverage --repo_env=COVERAGE_GCOV_PATH=/usr/bin/llvm-profdata
463# BAZEL_LLVM_COV is used by collect_cc_coverage.sh to generate LCOV reports from profile data
464build:coverage --repo_env=BAZEL_LLVM_COV=llvm-cov
465build:coverage --experimental_use_llvm_covmap
466# experimental_generate_llvm_lcov tells collect_cc_coverage to use llvm-cov export to generate LCOV
467# format instead of just outputting raw profdata. LLVM_COV specifies the llvm-cov binary to use.
468build:coverage --experimental_generate_llvm_lcov
469# Ensure that we fetch coverage data from remote cache
470build:coverage --experimental_fetch_all_coverage_outputs
471build:coverage --experimental_split_coverage_postprocessing
472# Allow coverage outputs to be writable for post-processing
473build:coverage --experimental_writable_outputs
474build:coverage --collect_code_coverage
475# Only instrument source code, not tests or tools - significantly speeds up coverage builds
476build:coverage --instrumentation_filter="^//src/workerd[/:],^//src/rust[/:]"
477build:coverage --instrument_test_targets
478# Disable coverage instrumentation for external dependencies to speed up compilation.
479# Coverage for V8/external code is not useful for our purposes.
480# These flags negate -fprofile-instr-generate and -fcoverage-mapping set by rules_cc.
481build:coverage --per_file_copt=external/.*@-fno-profile-instr-generate,-fno-coverage-mapping
482# KJ uses _exit() by default which bypasses atexit handlers and prevents LLVM profile runtime
483# from writing coverage data. KJ_CLEAN_SHUTDOWN forces use of normal exit() instead.
484build:coverage --test_env=KJ_CLEAN_SHUTDOWN=1
485# Use -O1 for faster compilation - coverage builds don't need heavy optimization
486build:coverage --copt=-O1
487# Reduce debug info for faster compilation and smaller binaries
488build:coverage --copt=-g1
489# Use limited coverage mode for smaller binaries and faster execution (used by Chromium)
490build:coverage --copt=-mllvm --copt=-limited-coverage-experimental=true
491coverage --test_tag_filters=-off-by-default,-requires-fuzzilli,-requires-container-engine,-lint,-benchmark,-workerd-benchmark,-no-coverage
492# Coverage instrumentation slows down test execution, so extend timeouts
493# We disable enormous tests due to the slowdown (CI jobs have a 6h max duration)
494coverage --test_size_filters=-enormous
495coverage --test_timeout=240,240,240,240
496coverage --build_tests_only
497 
498# This config is defined internally and enabled on many machines.
499# Defining it as empty just so these machines can run build commands from the workerd repo
500build:rosetta-arm64 --define=rosetta_arm64_no_op=1