CMakeLists: match the hardening-check flag detection that passed CI
CI / pre-commit (pull_request) Successful in 2m9s
CI / release (arm64, ubuntu-latest-arm64) (pull_request) Successful in 3m28s
CI / test (-DCMAKE_BUILD_TYPE=Debug, debug) (pull_request) Successful in 3m38s
CI / test (-DCMAKE_CXX_FLAGS=-DUSE_64_BIT=1, 64-bit-versions) (pull_request) Successful in 3m28s
CI / test (-DCMAKE_C_COMPILER=gcc -DCMAKE_CXX_COMPILER=g++, gcc) (pull_request) Successful in 3m36s
CI / test (-DUSE_SIMD_FALLBACK=ON, simd-fallback) (pull_request) Successful in 3m27s
CI / release (amd64, ubuntu-latest-amd64) (pull_request) Successful in 4m52s
CI / coverage (pull_request) Successful in 3m36s

Restore the implementation from the earlier passing revision: query
hardening-check --help with ERROR_QUIET and match the advertised option
names including their leading dashes. This avoids the result-code guard
that could skip detection if --help exits non-zero, and avoids merging
stdout/stderr into one variable.
This commit is contained in:
2026-06-22 13:44:10 -04:00
parent 6f71ff086b
commit c80cfedf58
+14 -18
View File
@@ -383,30 +383,26 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
if(NOT CMAKE_CROSSCOMPILING)
find_program(HARDENING_CHECK hardening-check)
if(HARDENING_CHECK)
# Not all versions of hardening-check support the same options, so query
# the help output before using architecture-specific skips. Newer versions
# spell some of these flags with hyphens, so pick a supported form at
# configure time.
# Control flow integrity (CET) is x86-only and branch protection (PAC/BTI)
# is arm64-only, so ignore whichever doesn't apply. Newer hardening-check
# versions spell some of these flags with hyphens, so pick a supported
# form at configure time.
execute_process(
COMMAND ${HARDENING_CHECK} --help
OUTPUT_VARIABLE hardening_check_help
ERROR_VARIABLE hardening_check_help
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE)
set(hardening_check_arch_flags "")
# Control flow integrity (CET) is x86-only and branch protection (PAC/BTI)
# is arm64-only, so ignore whichever doesn't apply.
OUTPUT_VARIABLE _hardening_help
ERROR_QUIET)
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
STREQUAL arm64)
if(hardening_check_help MATCHES "nocfprotection")
list(APPEND hardening_check_arch_flags --nocfprotection)
elseif(hardening_check_help MATCHES "no-cf-protection")
list(APPEND hardening_check_arch_flags --no-cf-protection)
if(_hardening_help MATCHES "--nocfprotection")
set(hardening_check_arch_flags --nocfprotection)
elseif(_hardening_help MATCHES "--no-cf-protection")
set(hardening_check_arch_flags --no-cf-protection)
endif()
else()
if(hardening_check_help MATCHES "nobranchprotection")
list(APPEND hardening_check_arch_flags --nobranchprotection)
elseif(hardening_check_help MATCHES "no-branch-protection")
list(APPEND hardening_check_arch_flags --no-branch-protection)
if(_hardening_help MATCHES "--nobranchprotection")
set(hardening_check_arch_flags --nobranchprotection)
elseif(_hardening_help MATCHES "--no-branch-protection")
set(hardening_check_arch_flags --no-branch-protection)
endif()
endif()
add_test(