CMakeLists: use hardening-check --help output regardless of exit code

The previous change tried to detect which architecture-specific skip
flags the installed hardening-check binary supports by grepping its
--help output, but it only used that output when the help command
returned exit code 0. Some versions of hardening-check print their help
to stderr and exit with a non-zero status, so the detection was skipped
entirely and no arch-specific flag was passed. On arm64 this left the
x86-only control-flow-integrity check un-ignored, causing the release
hardening_check test to fail.

Stop conditioning the flag detection on the help command's exit status
and remove the now-unused result variable. Also reformat the comment to
satisfy cmake-format.

Fixes pre-commit and release arm64 CI failures for #51.
This commit is contained in:
2026-06-22 13:44:10 -04:00
parent 92b67f572f
commit 2d8508b9fd
+18 -21
View File
@@ -384,32 +384,29 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
find_program(HARDENING_CHECK hardening-check) find_program(HARDENING_CHECK hardening-check)
if(HARDENING_CHECK) if(HARDENING_CHECK)
# Not all versions of hardening-check support the same options, so query # Not all versions of hardening-check support the same options, so query
# the help output before using architecture-specific skips. Newer # the help output before using architecture-specific skips. Newer versions
# versions spell some of these flags with hyphens, so pick a supported # spell some of these flags with hyphens, so pick a supported form at
# form at configure time. # configure time.
execute_process( execute_process(
COMMAND ${HARDENING_CHECK} --help COMMAND ${HARDENING_CHECK} --help
OUTPUT_VARIABLE hardening_check_help OUTPUT_VARIABLE hardening_check_help
ERROR_VARIABLE hardening_check_help ERROR_VARIABLE hardening_check_help
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE)
RESULT_VARIABLE hardening_check_help_result)
set(hardening_check_arch_flags "") set(hardening_check_arch_flags "")
if(hardening_check_help_result EQUAL 0) # Control flow integrity (CET) is x86-only and branch protection
# Control flow integrity (CET) is x86-only and branch protection # (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply. if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR STREQUAL arm64)
STREQUAL arm64) if(hardening_check_help MATCHES "nocfprotection")
if(hardening_check_help MATCHES "nocfprotection") list(APPEND hardening_check_arch_flags --nocfprotection)
list(APPEND hardening_check_arch_flags --nocfprotection) elseif(hardening_check_help MATCHES "no-cf-protection")
elseif(hardening_check_help MATCHES "no-cf-protection") list(APPEND hardening_check_arch_flags --no-cf-protection)
list(APPEND hardening_check_arch_flags --no-cf-protection) endif()
endif() else()
else() if(hardening_check_help MATCHES "nobranchprotection")
if(hardening_check_help MATCHES "nobranchprotection") list(APPEND hardening_check_arch_flags --nobranchprotection)
list(APPEND hardening_check_arch_flags --nobranchprotection) elseif(hardening_check_help MATCHES "no-branch-protection")
elseif(hardening_check_help MATCHES "no-branch-protection") list(APPEND hardening_check_arch_flags --no-branch-protection)
list(APPEND hardening_check_arch_flags --no-branch-protection)
endif()
endif() endif()
endif() endif()
add_test( add_test(