From 75450307c0c5a0fdf9826e5b06bdf252cfe22df0 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sun, 6 Sep 2026 20:14:48 -1000 Subject: Trim the comments and dead code across the tree --- tools/release-build.sh | 27 ++++++++++----------------- 1 file changed, 10 insertions(+), 17 deletions(-) (limited to 'tools/release-build.sh') diff --git a/tools/release-build.sh b/tools/release-build.sh index 12f4260..0d9008f 100755 --- a/tools/release-build.sh +++ b/tools/release-build.sh @@ -1,17 +1,13 @@ #!/bin/sh -# Build cgit for a release with Linux hardening flags. These are ELF and GCC -# or Clang specific, so this targets a Linux deploy rather than local macOS -# development, where a plain make is enough. The flags add a stack protector, -# fortified libc calls, a position independent executable, and full RELRO. By -# default Lua is pinned off so the binary needs no Lua at runtime, and running -# it as ./tools/release-build.sh lua links in the backend behind the "lua:" -# filter prefix instead, which needs a Lua dev package installed. +# Build cgit for a release with Linux hardening flags, which are ELF and GCC or +# Clang specific. The flags add a stack protector, fortified libc calls, a +# position independent executable, and full RELRO. By default Lua is pinned off +# so the binary needs no Lua at runtime, and running it as +# ./tools/release-build.sh lua links in the backend behind the "lua:" filter +# prefix instead, which needs a Lua dev package installed. set -eu -# The argument is checked rather than assumed, since anything unrecognised -# would otherwise fall through to a quiet Lua-less build that looks like it -# worked. if [ "$#" -gt 1 ]; then echo "usage: $0 [lua]" >&2 exit 2 @@ -23,8 +19,7 @@ lua) set -- ;; exit 2 ;; esac -# Every make target below is written relative to the repository root, so go -# there rather than requiring the caller to. +# Every make target below is written relative to the repository root. cd "$(dirname "$0")/.." CC=${CC:-cc} @@ -68,11 +63,9 @@ LDFLAGS="-pie \ # These reach only the cgit objects, so git's own sources are not held to them. # -Wformat-security is an error because a non-literal format with no arguments -# is never intentional. The shape that let a repository supply its own format -# string through module-link was the other one, a non-literal that does take -# arguments, and only -Wformat-nonliteral reports that, and that one is left out because it also fires -# on forwarding a va_list and on local format constants, so it cannot be an -# error without false positives. It is still worth running by hand when +# is never intentional. -Wformat-nonliteral would catch the module-link shape, +# a non-literal that does take arguments, but it also fires on va_list +# forwarding and on local format constants, so it is left to manual runs when # touching anything that formats. # # make cgit CGIT_EXTRA_CFLAGS=-Wformat-nonliteral -- cgit v2.8.0