#!/bin/sh # Build cgit for a release with Linux hardening flags. # # These are ELF and GCC/Clang specific, so this targets a Linux deploy # rather than local macOS development, where a plain make is enough. The # flags add a stack protector, fortified libc calls, a position independent # executable, and full RELRO. # # By default Lua is pinned off so the binary needs no Lua at runtime. Pass # "lua" as the first argument to link the lua: filter backend instead, which # needs a Lua dev package installed. # # Usage: ./tools/release-build.sh [lua] (run from the repository root) set -eu if [ "${1:-}" = "lua" ]; then LUA= else LUA=NO_LUA=1 fi CFLAGS="-O2 -g -Wall \ -fstack-protector-strong \ -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2 \ -fPIE \ -fno-plt" LDFLAGS="-pie \ -Wl,-z,relro,-z,now \ -Wl,-z,noexecstack" # A full rebuild so the bundled git objects pick up the same flags. # cleanall also descends into git/, which plain clean does not. make $LUA cleanall exec make $LUA CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS"