diff options
context:
space:
mode:
-rw-r--r--Makefile7
-rwxr-xr-xtools/release-build.sh6
2 files changed, 11 insertions, 2 deletions
diff --git a/Makefile b/Makefile
index 53580f3..fe65cba 100644
--- a/Makefile
+++ b/Makefile
@@ -65,8 +65,11 @@ all: cgit
# be WITH_RUST, so Rust is now compiled in unless it is turned off, and leaving
# this out would quietly make Cargo a build requirement. Git 3.0 drops the
# choice entirely, at which point this stops working and Rust becomes
-# mandatory.
-GIT_BUILD_FLAGS = NO_CURL=1 NO_OPENSSL=1 NO_RUST=1
+# mandatory. Git's own build defaults prefix to $HOME and compiles it in as
+# its fallback runtime prefix, so without the last flag every binary carries
+# the home directory of whoever built it and no two builders get the same
+# bytes.
+GIT_BUILD_FLAGS = NO_CURL=1 NO_OPENSSL=1 NO_RUST=1 prefix='$(prefix)'
# Apple's linker otherwise stamps each object's mtime into the debug map, so
# two builds of the same sources would differ.
diff --git a/tools/release-build.sh b/tools/release-build.sh
index c5ca6e9..a6d10dc 100755
--- a/tools/release-build.sh
+++ b/tools/release-build.sh
@@ -62,6 +62,12 @@ if supports "-fstack-clash-protection"; then
CFLAGS="$CFLAGS -fstack-clash-protection"
fi
+# The debug info otherwise records the absolute build directory, so the same
+# sources built in two checkouts would differ.
+if supports "-ffile-prefix-map=/x=."; then
+ CFLAGS="$CFLAGS -ffile-prefix-map=$PWD=."
+fi
+
LDFLAGS="-pie -Wl,-z,relro,-z,now -Wl,-z,noexecstack"
# These reach only the cgit objects, so git's own sources are not held to them.