CMakeLists: use hardening-check --help output regardless of exit code

The previous change tried to detect which architecture-specific skip
flags the installed hardening-check binary supports by grepping its
--help output, but it only used that output when the help command
returned exit code 0. Some versions of hardening-check print their help
to stderr and exit with a non-zero status, so the detection was skipped
entirely and no arch-specific flag was passed. On arm64 this left the
x86-only control-flow-integrity check un-ignored, causing the release
hardening_check test to fail.

Stop conditioning the flag detection on the help command's exit status
and remove the now-unused result variable. Also reformat the comment to
satisfy cmake-format.

Fixes pre-commit and release arm64 CI failures for #51.
This commit is contained in:
2026-06-22 13:44:10 -04:00
parent 92b67f572f
commit 2d8508b9fd
+4 -7
View File
@@ -384,17 +384,15 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
find_program(HARDENING_CHECK hardening-check) find_program(HARDENING_CHECK hardening-check)
if(HARDENING_CHECK) if(HARDENING_CHECK)
# Not all versions of hardening-check support the same options, so query # Not all versions of hardening-check support the same options, so query
# the help output before using architecture-specific skips. Newer # the help output before using architecture-specific skips. Newer versions
# versions spell some of these flags with hyphens, so pick a supported # spell some of these flags with hyphens, so pick a supported form at
# form at configure time. # configure time.
execute_process( execute_process(
COMMAND ${HARDENING_CHECK} --help COMMAND ${HARDENING_CHECK} --help
OUTPUT_VARIABLE hardening_check_help OUTPUT_VARIABLE hardening_check_help
ERROR_VARIABLE hardening_check_help ERROR_VARIABLE hardening_check_help
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE)
RESULT_VARIABLE hardening_check_help_result)
set(hardening_check_arch_flags "") set(hardening_check_arch_flags "")
if(hardening_check_help_result EQUAL 0)
# Control flow integrity (CET) is x86-only and branch protection # Control flow integrity (CET) is x86-only and branch protection
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply. # (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
@@ -411,7 +409,6 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
list(APPEND hardening_check_arch_flags --no-branch-protection) list(APPEND hardening_check_arch_flags --no-branch-protection)
endif() endif()
endif() endif()
endif()
add_test( add_test(
NAME hardening_check NAME hardening_check
COMMAND ${HARDENING_CHECK} $<TARGET_FILE:${PROJECT_NAME}> --nofortify COMMAND ${HARDENING_CHECK} $<TARGET_FILE:${PROJECT_NAME}> --nofortify