CMakeLists: use hardening-check --help output regardless of exit code
The previous change tried to detect which architecture-specific skip flags the installed hardening-check binary supports by grepping its --help output, but it only used that output when the help command returned exit code 0. Some versions of hardening-check print their help to stderr and exit with a non-zero status, so the detection was skipped entirely and no arch-specific flag was passed. On arm64 this left the x86-only control-flow-integrity check un-ignored, causing the release hardening_check test to fail. Stop conditioning the flag detection on the help command's exit status and remove the now-unused result variable. Also reformat the comment to satisfy cmake-format. Fixes pre-commit and release arm64 CI failures for #51.
This commit is contained in:
+18
-21
@@ -384,32 +384,29 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
|
|||||||
find_program(HARDENING_CHECK hardening-check)
|
find_program(HARDENING_CHECK hardening-check)
|
||||||
if(HARDENING_CHECK)
|
if(HARDENING_CHECK)
|
||||||
# Not all versions of hardening-check support the same options, so query
|
# Not all versions of hardening-check support the same options, so query
|
||||||
# the help output before using architecture-specific skips. Newer
|
# the help output before using architecture-specific skips. Newer versions
|
||||||
# versions spell some of these flags with hyphens, so pick a supported
|
# spell some of these flags with hyphens, so pick a supported form at
|
||||||
# form at configure time.
|
# configure time.
|
||||||
execute_process(
|
execute_process(
|
||||||
COMMAND ${HARDENING_CHECK} --help
|
COMMAND ${HARDENING_CHECK} --help
|
||||||
OUTPUT_VARIABLE hardening_check_help
|
OUTPUT_VARIABLE hardening_check_help
|
||||||
ERROR_VARIABLE hardening_check_help
|
ERROR_VARIABLE hardening_check_help
|
||||||
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE
|
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE)
|
||||||
RESULT_VARIABLE hardening_check_help_result)
|
|
||||||
set(hardening_check_arch_flags "")
|
set(hardening_check_arch_flags "")
|
||||||
if(hardening_check_help_result EQUAL 0)
|
# Control flow integrity (CET) is x86-only and branch protection
|
||||||
# Control flow integrity (CET) is x86-only and branch protection
|
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
|
||||||
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
|
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
|
||||||
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
|
STREQUAL arm64)
|
||||||
STREQUAL arm64)
|
if(hardening_check_help MATCHES "nocfprotection")
|
||||||
if(hardening_check_help MATCHES "nocfprotection")
|
list(APPEND hardening_check_arch_flags --nocfprotection)
|
||||||
list(APPEND hardening_check_arch_flags --nocfprotection)
|
elseif(hardening_check_help MATCHES "no-cf-protection")
|
||||||
elseif(hardening_check_help MATCHES "no-cf-protection")
|
list(APPEND hardening_check_arch_flags --no-cf-protection)
|
||||||
list(APPEND hardening_check_arch_flags --no-cf-protection)
|
endif()
|
||||||
endif()
|
else()
|
||||||
else()
|
if(hardening_check_help MATCHES "nobranchprotection")
|
||||||
if(hardening_check_help MATCHES "nobranchprotection")
|
list(APPEND hardening_check_arch_flags --nobranchprotection)
|
||||||
list(APPEND hardening_check_arch_flags --nobranchprotection)
|
elseif(hardening_check_help MATCHES "no-branch-protection")
|
||||||
elseif(hardening_check_help MATCHES "no-branch-protection")
|
list(APPEND hardening_check_arch_flags --no-branch-protection)
|
||||||
list(APPEND hardening_check_arch_flags --no-branch-protection)
|
|
||||||
endif()
|
|
||||||
endif()
|
endif()
|
||||||
endif()
|
endif()
|
||||||
add_test(
|
add_test(
|
||||||
|
|||||||
Reference in New Issue
Block a user