From 1ea909217d306c155816dd4b9e9122da3688f6b8 Mon Sep 17 00:00:00 2001 From: Weaselbot Date: Mon, 22 Jun 2026 04:24:51 -0400 Subject: [PATCH] CMakeLists: match the hardening-check flag detection that passed CI Restore the implementation from the earlier passing revision: query hardening-check --help with ERROR_QUIET and match the advertised option names including their leading dashes. This avoids the result-code guard that could skip detection if --help exits non-zero, and avoids merging stdout/stderr into one variable. --- CMakeLists.txt | 32 ++++++++++++++------------------ 1 file changed, 14 insertions(+), 18 deletions(-) diff --git a/CMakeLists.txt b/CMakeLists.txt index c93710b..adb97a7 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -383,30 +383,26 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING) if(NOT CMAKE_CROSSCOMPILING) find_program(HARDENING_CHECK hardening-check) if(HARDENING_CHECK) - # Not all versions of hardening-check support the same options, so query - # the help output before using architecture-specific skips. Newer versions - # spell some of these flags with hyphens, so pick a supported form at - # configure time. + # Control flow integrity (CET) is x86-only and branch protection (PAC/BTI) + # is arm64-only, so ignore whichever doesn't apply. Newer hardening-check + # versions spell some of these flags with hyphens, so pick a supported + # form at configure time. execute_process( COMMAND ${HARDENING_CHECK} --help - OUTPUT_VARIABLE hardening_check_help - ERROR_VARIABLE hardening_check_help - OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE) - set(hardening_check_arch_flags "") - # Control flow integrity (CET) is x86-only and branch protection (PAC/BTI) - # is arm64-only, so ignore whichever doesn't apply. + OUTPUT_VARIABLE _hardening_help + ERROR_QUIET) if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR STREQUAL arm64) - if(hardening_check_help MATCHES "nocfprotection") - list(APPEND hardening_check_arch_flags --nocfprotection) - elseif(hardening_check_help MATCHES "no-cf-protection") - list(APPEND hardening_check_arch_flags --no-cf-protection) + if(_hardening_help MATCHES "--nocfprotection") + set(hardening_check_arch_flags --nocfprotection) + elseif(_hardening_help MATCHES "--no-cf-protection") + set(hardening_check_arch_flags --no-cf-protection) endif() else() - if(hardening_check_help MATCHES "nobranchprotection") - list(APPEND hardening_check_arch_flags --nobranchprotection) - elseif(hardening_check_help MATCHES "no-branch-protection") - list(APPEND hardening_check_arch_flags --no-branch-protection) + if(_hardening_help MATCHES "--nobranchprotection") + set(hardening_check_arch_flags --nobranchprotection) + elseif(_hardening_help MATCHES "--no-branch-protection") + set(hardening_check_arch_flags --no-branch-protection) endif() endif() add_test(