CMakeLists: use hardening-check --help output regardless of exit code
CI / pre-commit (pull_request) Failing after 1m54s
CI / release (arm64, ubuntu-latest-arm64) (pull_request) Successful in 3m40s
CI / test (-DCMAKE_BUILD_TYPE=Debug, debug) (pull_request) Successful in 3m47s
CI / test (-DCMAKE_CXX_FLAGS=-DUSE_64_BIT=1, 64-bit-versions) (pull_request) Successful in 3m36s
CI / test (-DCMAKE_C_COMPILER=gcc -DCMAKE_CXX_COMPILER=g++, gcc) (pull_request) Successful in 3m45s
CI / test (-DUSE_SIMD_FALLBACK=ON, simd-fallback) (pull_request) Successful in 3m39s
CI / release (amd64, ubuntu-latest-amd64) (pull_request) Successful in 5m1s
CI / coverage (pull_request) Failing after 13m37s

The previous change tried to detect which architecture-specific skip
flags the installed hardening-check binary supports by grepping its
--help output, but it only used that output when the help command
returned exit code 0. Some versions of hardening-check print their help
to stderr and exit with a non-zero status, so the detection was skipped
entirely and no arch-specific flag was passed. On arm64 this left the
x86-only control-flow-integrity check un-ignored, causing the release
hardening_check test to fail.

Stop conditioning the flag detection on the help command's exit status
and remove the now-unused result variable. Also reformat the comment to
satisfy cmake-format.

Fixes pre-commit and release arm64 CI failures for #51.
This commit is contained in:
2026-06-22 03:57:36 -04:00
parent becbbcbc28
commit be64ca7fcc
+4 -7
View File
@@ -384,17 +384,15 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
find_program(HARDENING_CHECK hardening-check)
if(HARDENING_CHECK)
# Not all versions of hardening-check support the same options, so query
# the help output before using architecture-specific skips. Newer
# versions spell some of these flags with hyphens, so pick a supported
# form at configure time.
# the help output before using architecture-specific skips. Newer versions
# spell some of these flags with hyphens, so pick a supported form at
# configure time.
execute_process(
COMMAND ${HARDENING_CHECK} --help
OUTPUT_VARIABLE hardening_check_help
ERROR_VARIABLE hardening_check_help
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE
RESULT_VARIABLE hardening_check_help_result)
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE)
set(hardening_check_arch_flags "")
if(hardening_check_help_result EQUAL 0)
# Control flow integrity (CET) is x86-only and branch protection
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
@@ -411,7 +409,6 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
list(APPEND hardening_check_arch_flags --no-branch-protection)
endif()
endif()
endif()
add_test(
NAME hardening_check
COMMAND ${HARDENING_CHECK} $<TARGET_FILE:${PROJECT_NAME}> --nofortify