diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Add a hardened release build script
The hardening flags are ELF specific and would break local macOS development, so they stay out of the default build.
Diffstat (limited to 'tools')
-rwxr-xr-xtools/release-build.sh27
1 file changed, 27 insertions, 0 deletions
diff --git a/tools/release-build.sh b/tools/release-build.sh
new file mode 100755
index 0000000..6dc9045
--- /dev/null
+++ b/tools/release-build.sh
@@ -0,0 +1,27 @@
+#!/bin/sh
+# Build cgit for a release with Linux hardening flags.
+#
+# These are ELF and GCC/Clang specific, so this targets a Linux deploy
+# rather than local macOS development, where `make NO_LUA=1` is enough.
+# The flags add a stack protector, fortified libc calls, a position
+# independent executable, and full RELRO. Lua is pinned off here; drop
+# NO_LUA=1 and install the Lua dev package if you use lua filters.
+#
+# Usage: ./tools/release-build.sh (run from the repository root)
+
+set -eu
+
+CFLAGS="-O2 -g -Wall \
+ -fstack-protector-strong \
+ -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2 \
+ -fPIE \
+ -fno-plt"
+
+LDFLAGS="-pie \
+ -Wl,-z,relro,-z,now \
+ -Wl,-z,noexecstack"
+
+# A full rebuild so the bundled git objects pick up the same flags.
+# cleanall also descends into git/, which plain clean does not.
+make NO_LUA=1 cleanall
+exec make NO_LUA=1 CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS"