CMakeLists: match the hardening-check flag detection that passed CI
CI / release (arm64, ubuntu-latest-arm64) (pull_request) Successful in 3m33s
CI / pre-commit (pull_request) Successful in 2m10s
CI / test (-DCMAKE_BUILD_TYPE=Debug, debug) (pull_request) Successful in 3m36s
CI / test (-DCMAKE_CXX_FLAGS=-DUSE_64_BIT=1, 64-bit-versions) (pull_request) Successful in 3m31s
CI / test (-DCMAKE_C_COMPILER=gcc -DCMAKE_CXX_COMPILER=g++, gcc) (pull_request) Successful in 3m49s
CI / test (-DUSE_SIMD_FALLBACK=ON, simd-fallback) (pull_request) Successful in 3m33s
CI / release (amd64, ubuntu-latest-amd64) (pull_request) Successful in 5m2s
CI / coverage (pull_request) Successful in 3m49s
CI / release (arm64, ubuntu-latest-arm64) (pull_request) Successful in 3m33s
CI / pre-commit (pull_request) Successful in 2m10s
CI / test (-DCMAKE_BUILD_TYPE=Debug, debug) (pull_request) Successful in 3m36s
CI / test (-DCMAKE_CXX_FLAGS=-DUSE_64_BIT=1, 64-bit-versions) (pull_request) Successful in 3m31s
CI / test (-DCMAKE_C_COMPILER=gcc -DCMAKE_CXX_COMPILER=g++, gcc) (pull_request) Successful in 3m49s
CI / test (-DUSE_SIMD_FALLBACK=ON, simd-fallback) (pull_request) Successful in 3m33s
CI / release (amd64, ubuntu-latest-amd64) (pull_request) Successful in 5m2s
CI / coverage (pull_request) Successful in 3m49s
Restore the implementation from the earlier passing revision: query hardening-check --help with ERROR_QUIET and match the advertised option names including their leading dashes. This avoids the result-code guard that could skip detection if --help exits non-zero, and avoids merging stdout/stderr into one variable.
This commit is contained in:
+14
-18
@@ -383,30 +383,26 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
|
||||
if(NOT CMAKE_CROSSCOMPILING)
|
||||
find_program(HARDENING_CHECK hardening-check)
|
||||
if(HARDENING_CHECK)
|
||||
# Not all versions of hardening-check support the same options, so query
|
||||
# the help output before using architecture-specific skips. Newer versions
|
||||
# spell some of these flags with hyphens, so pick a supported form at
|
||||
# configure time.
|
||||
# Control flow integrity (CET) is x86-only and branch protection (PAC/BTI)
|
||||
# is arm64-only, so ignore whichever doesn't apply. Newer hardening-check
|
||||
# versions spell some of these flags with hyphens, so pick a supported
|
||||
# form at configure time.
|
||||
execute_process(
|
||||
COMMAND ${HARDENING_CHECK} --help
|
||||
OUTPUT_VARIABLE hardening_check_help
|
||||
ERROR_VARIABLE hardening_check_help
|
||||
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE)
|
||||
set(hardening_check_arch_flags "")
|
||||
# Control flow integrity (CET) is x86-only and branch protection (PAC/BTI)
|
||||
# is arm64-only, so ignore whichever doesn't apply.
|
||||
OUTPUT_VARIABLE _hardening_help
|
||||
ERROR_QUIET)
|
||||
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
|
||||
STREQUAL arm64)
|
||||
if(hardening_check_help MATCHES "nocfprotection")
|
||||
list(APPEND hardening_check_arch_flags --nocfprotection)
|
||||
elseif(hardening_check_help MATCHES "no-cf-protection")
|
||||
list(APPEND hardening_check_arch_flags --no-cf-protection)
|
||||
if(_hardening_help MATCHES "--nocfprotection")
|
||||
set(hardening_check_arch_flags --nocfprotection)
|
||||
elseif(_hardening_help MATCHES "--no-cf-protection")
|
||||
set(hardening_check_arch_flags --no-cf-protection)
|
||||
endif()
|
||||
else()
|
||||
if(hardening_check_help MATCHES "nobranchprotection")
|
||||
list(APPEND hardening_check_arch_flags --nobranchprotection)
|
||||
elseif(hardening_check_help MATCHES "no-branch-protection")
|
||||
list(APPEND hardening_check_arch_flags --no-branch-protection)
|
||||
if(_hardening_help MATCHES "--nobranchprotection")
|
||||
set(hardening_check_arch_flags --nobranchprotection)
|
||||
elseif(_hardening_help MATCHES "--no-branch-protection")
|
||||
set(hardening_check_arch_flags --no-branch-protection)
|
||||
endif()
|
||||
endif()
|
||||
add_test(
|
||||
|
||||
Reference in New Issue
Block a user