diff --git a/CMakeLists.txt b/CMakeLists.txt index 150f179..c1a6b4c 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -383,13 +383,28 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING) if(NOT CMAKE_CROSSCOMPILING) find_program(HARDENING_CHECK hardening-check) if(HARDENING_CHECK) - # Control flow integrity (CET) is x86-only and branch protection (PAC/BTI) - # is arm64-only, so ignore whichever doesn't apply. - if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR - STREQUAL arm64) - set(hardening_check_arch_flags --nocfprotection) - else() - set(hardening_check_arch_flags --nobranchprotection) + # Not all versions of hardening-check support the same options, so query + # the help output before using architecture-specific skips. + execute_process( + COMMAND ${HARDENING_CHECK} --help + OUTPUT_VARIABLE hardening_check_help + ERROR_VARIABLE hardening_check_help + OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE + RESULT_VARIABLE hardening_check_help_result) + set(hardening_check_arch_flags "") + if(hardening_check_help_result EQUAL 0) + # Control flow integrity (CET) is x86-only and branch protection + # (PAC/BTI) is arm64-only, so ignore whichever doesn't apply. + if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR + STREQUAL arm64) + if(hardening_check_help MATCHES "nocfprotection") + list(APPEND hardening_check_arch_flags --nocfprotection) + endif() + else() + if(hardening_check_help MATCHES "nobranchprotection") + list(APPEND hardening_check_arch_flags --nobranchprotection) + endif() + endif() endif() add_test( NAME hardening_check