forked from weaselab/conflict-set
CMakeLists: only pass hardening-check arch flags the tool supports
The amd64 CI runner's hardening-check does not recognize --nobranchprotection, causing the hardening_check test to fail at configure time. Query the tool's help output and only include the architecture-specific skip flags when they are advertised.
This commit is contained in:
+19
-4
@@ -383,13 +383,28 @@ if(CMAKE_SOURCE_DIR STREQUAL CMAKE_CURRENT_SOURCE_DIR AND BUILD_TESTING)
|
||||
if(NOT CMAKE_CROSSCOMPILING)
|
||||
find_program(HARDENING_CHECK hardening-check)
|
||||
if(HARDENING_CHECK)
|
||||
# Control flow integrity (CET) is x86-only and branch protection (PAC/BTI)
|
||||
# is arm64-only, so ignore whichever doesn't apply.
|
||||
# Not all versions of hardening-check support the same options, so query
|
||||
# the help output before using architecture-specific skips.
|
||||
execute_process(
|
||||
COMMAND ${HARDENING_CHECK} --help
|
||||
OUTPUT_VARIABLE hardening_check_help
|
||||
ERROR_VARIABLE hardening_check_help
|
||||
OUTPUT_STRIP_TRAILING_WHITESPACE ERROR_STRIP_TRAILING_WHITESPACE
|
||||
RESULT_VARIABLE hardening_check_help_result)
|
||||
set(hardening_check_arch_flags "")
|
||||
if(hardening_check_help_result EQUAL 0)
|
||||
# Control flow integrity (CET) is x86-only and branch protection
|
||||
# (PAC/BTI) is arm64-only, so ignore whichever doesn't apply.
|
||||
if(CMAKE_SYSTEM_PROCESSOR STREQUAL aarch64 OR CMAKE_SYSTEM_PROCESSOR
|
||||
STREQUAL arm64)
|
||||
set(hardening_check_arch_flags --nocfprotection)
|
||||
if(hardening_check_help MATCHES "nocfprotection")
|
||||
list(APPEND hardening_check_arch_flags --nocfprotection)
|
||||
endif()
|
||||
else()
|
||||
set(hardening_check_arch_flags --nobranchprotection)
|
||||
if(hardening_check_help MATCHES "nobranchprotection")
|
||||
list(APPEND hardening_check_arch_flags --nobranchprotection)
|
||||
endif()
|
||||
endif()
|
||||
endif()
|
||||
add_test(
|
||||
NAME hardening_check
|
||||
|
||||
Reference in New Issue
Block a user