From be64ca7fcc0281b43ab2ee92970b436d85292c54 Mon Sep 17 00:00:00 2001 From: Weaselbot Date: Mon, 22 Jun 2026 03:57:36 -0400 Subject: [PATCH] CMakeLists: use hardening-check --help output regardless of exit code The previous change tried to detect which architecture-specific skip flags the installed hardening-check binary supports by grepping its --help output, but it only used that output when the help command returned exit code 0. Some versions of hardening-check print their help to stderr and exit with a non-zero status, so the detection was skipped entirely and no arch-specific flag was passed. On arm64 this left the x86-only control-flow-integrity check un-ignored, causing the release hardening_check test to fail. Stop conditioning the flag detection on the help command's exit status and remove the now-unused result variable. Also reformat the comment to satisfy cmake-format. Fixes pre-commit and release arm64 CI failures for #51. --- CMakeLists.txt | 39 ++++++++++++++++++--------------------- 1 file changed, 18 insertions(+), 21 deletions(-) diff --git a/CMakeLists.txt b/CMakeLists.txt index 19f2709..bfb4659 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -384,32 +384,29 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING) find_program(HARDENING_CHECK hardening-check) if(HARDENING_CHECK) # Not all versions of hardening-check support the same options, so query - # the help output before using architecture-specific skips. Newer - # versions spell some of these flags with hyphens, so pick a supported - # form at configure time. + # the help output before using architecture-specific skips. Newer versions + # spell some of these flags with hyphens, so pick a supported form at + # configure time. execute_process( COMMAND ${HARDENING_CHECK} --help OUTPUT_VARIABLE hardening_check_help ERROR_VARIABLE hardening_check_help - OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE - RESULT_VARIABLE hardening_check_help_result) + OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE) set(hardening_check_arch_flags "") - if(hardening_check_help_result EQUAL 0) - # Control flow integrity (CET) is x86-only and branch protection - # (PAC/BTI) is arm64-only, so ignore whichever doesn't apply. - if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR - STREQUAL arm64) - if(hardening_check_help MATCHES "nocfprotection") - list(APPEND hardening_check_arch_flags --nocfprotection) - elseif(hardening_check_help MATCHES "no-cf-protection") - list(APPEND hardening_check_arch_flags --no-cf-protection) - endif() - else() - if(hardening_check_help MATCHES "nobranchprotection") - list(APPEND hardening_check_arch_flags --nobranchprotection) - elseif(hardening_check_help MATCHES "no-branch-protection") - list(APPEND hardening_check_arch_flags --no-branch-protection) - endif() + # Control flow integrity (CET) is x86-only and branch protection + # (PAC/BTI) is arm64-only, so ignore whichever doesn't apply. + if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR + STREQUAL arm64) + if(hardening_check_help MATCHES "nocfprotection") + list(APPEND hardening_check_arch_flags --nocfprotection) + elseif(hardening_check_help MATCHES "no-cf-protection") + list(APPEND hardening_check_arch_flags --no-cf-protection) + endif() + else() + if(hardening_check_help MATCHES "nobranchprotection") + list(APPEND hardening_check_arch_flags --nobranchprotection) + elseif(hardening_check_help MATCHES "no-branch-protection") + list(APPEND hardening_check_arch_flags --no-branch-protection) endif() endif() add_test(