CMakeLists.txt: don't require hardening-check --help to exit 0
CI / pre-commit (push) Successful in 2m9s
CI / test (-DCMAKE_BUILD_TYPE=Debug, debug) (push) Successful in 3m39s
CI / test (-DCMAKE_CXX_FLAGS=-DUSE_64_BIT=1, 64-bit-versions) (push) Successful in 3m37s
CI / test (-DCMAKE_C_COMPILER=gcc -DCMAKE_CXX_COMPILER=g++, gcc) (push) Successful in 3m41s
CI / test (-DUSE_SIMD_FALLBACK=ON, simd-fallback) (push) Successful in 3m37s
CI / release (amd64, ubuntu-latest-amd64) (push) Successful in 5m3s
CI / coverage (push) Successful in 3m54s
CI / release (arm64, ubuntu-latest-arm64) (push) Successful in 3m25s
CI / pre-commit (push) Successful in 2m9s
CI / test (-DCMAKE_BUILD_TYPE=Debug, debug) (push) Successful in 3m39s
CI / test (-DCMAKE_CXX_FLAGS=-DUSE_64_BIT=1, 64-bit-versions) (push) Successful in 3m37s
CI / test (-DCMAKE_C_COMPILER=gcc -DCMAKE_CXX_COMPILER=g++, gcc) (push) Successful in 3m41s
CI / test (-DUSE_SIMD_FALLBACK=ON, simd-fallback) (push) Successful in 3m37s
CI / release (amd64, ubuntu-latest-amd64) (push) Successful in 5m3s
CI / coverage (push) Successful in 3m54s
CI / release (arm64, ubuntu-latest-arm64) (push) Successful in 3m25s
hardening-check --help returns exit code 1, so the previous hardening_check_help_result EQUAL 0 guard skipped parsing the help output entirely. As a result, architecture-specific flags such as --nobranchprotection on x86_64 were never added to the test command. Parse the help output regardless of exit code; the option-string regex checks are sufficient.
This commit is contained in:
+3
-6
@@ -389,12 +389,10 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
|
|||||||
COMMAND ${HARDENING_CHECK} --help
|
COMMAND ${HARDENING_CHECK} --help
|
||||||
OUTPUT_VARIABLE hardening_check_help
|
OUTPUT_VARIABLE hardening_check_help
|
||||||
ERROR_VARIABLE hardening_check_help
|
ERROR_VARIABLE hardening_check_help
|
||||||
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE
|
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE)
|
||||||
RESULT_VARIABLE hardening_check_help_result)
|
|
||||||
set(hardening_check_arch_flags "")
|
set(hardening_check_arch_flags "")
|
||||||
if(hardening_check_help_result EQUAL 0)
|
# Control flow integrity (CET) is x86-only and branch protection (PAC/BTI)
|
||||||
# Control flow integrity (CET) is x86-only and branch protection
|
# is arm64-only, so ignore whichever doesn't apply.
|
||||||
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
|
|
||||||
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
|
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
|
||||||
STREQUAL arm64)
|
STREQUAL arm64)
|
||||||
if(hardening_check_help MATCHES "nocfprotection")
|
if(hardening_check_help MATCHES "nocfprotection")
|
||||||
@@ -405,7 +403,6 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
|
|||||||
list(APPEND hardening_check_arch_flags --nobranchprotection)
|
list(APPEND hardening_check_arch_flags --nobranchprotection)
|
||||||
endif()
|
endif()
|
||||||
endif()
|
endif()
|
||||||
endif()
|
|
||||||
add_test(
|
add_test(
|
||||||
NAME hardening_check
|
NAME hardening_check
|
||||||
COMMAND ${HARDENING_CHECK} $<TARGET_FILE:${PROJECT_NAME}> --nofortify
|
COMMAND ${HARDENING_CHECK} $<TARGET_FILE:${PROJECT_NAME}> --nofortify
|
||||||
|
|||||||
Reference in New Issue
Block a user