diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Let cgit build with or without Lua
Lua only powers the filter extensions, so it stays optional and autodetected. `NO_LUA` yields a self-contained binary and the release script links Lua only when asked to.
Diffstat (limited to '')
-rwxr-xr-xtools/release-build.sh23
1 file changed, 16 insertions, 7 deletions
diff --git a/tools/release-build.sh b/tools/release-build.sh
index 6dc9045..92aa78b 100755
--- a/tools/release-build.sh
+++ b/tools/release-build.sh
@@ -2,15 +2,24 @@
# Build cgit for a release with Linux hardening flags.
#
# These are ELF and GCC/Clang specific, so this targets a Linux deploy
-# rather than local macOS development, where `make NO_LUA=1` is enough.
-# The flags add a stack protector, fortified libc calls, a position
-# independent executable, and full RELRO. Lua is pinned off here; drop
-# NO_LUA=1 and install the Lua dev package if you use lua filters.
+# rather than local macOS development, where a plain make is enough. The
+# flags add a stack protector, fortified libc calls, a position independent
+# executable, and full RELRO.
#
-# Usage: ./tools/release-build.sh (run from the repository root)
+# By default Lua is pinned off so the binary needs no Lua at runtime. Pass
+# "lua" as the first argument to link the lua: filter backend instead, which
+# needs a Lua dev package installed.
+#
+# Usage: ./tools/release-build.sh [lua] (run from the repository root)
set -eu
+if [ "${1:-}" = "lua" ]; then
+ LUA=
+else
+ LUA=NO_LUA=1
+fi
+
CFLAGS="-O2 -g -Wall \
-fstack-protector-strong \
-U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2 \
@@ -23,5 +32,5 @@ LDFLAGS="-pie \
# A full rebuild so the bundled git objects pick up the same flags.
# cleanall also descends into git/, which plain clean does not.
-make NO_LUA=1 cleanall
-exec make NO_LUA=1 CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS"
+make $LUA cleanall
+exec make $LUA CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS"