blob: cfab7a2537bcae397fb4e276e28ad1e3c42ec4b3 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
#!/bin/sh
# Build cgit for a release with Linux hardening flags.
#
# These are ELF and GCC/Clang specific, so this targets a Linux deploy
# rather than local macOS development, where a plain make is enough. The
# flags add a stack protector, fortified libc calls, a position independent
# executable, and full RELRO.
#
# By default Lua is pinned off so the binary needs no Lua at runtime. Pass
# "lua" as the first argument to link the lua: filter backend instead, which
# needs a Lua dev package installed.
#
# Usage: ./tools/release-build.sh [lua]

set -eu

# The argument is checked rather than assumed, since anything unrecognised
# would otherwise fall through to a quiet Lua-less build that looks like it
# worked.
if [ "$#" -gt 1 ]; then
	echo "usage: $0 [lua]" >&2
	exit 2
fi
case "${1:-}" in
"")	set -- NO_LUA=1 ;;
lua)	set -- ;;
*)	echo "$0: unknown argument \"$1\", expected \"lua\" or nothing" >&2
	exit 2 ;;
esac

# Every make target below is written relative to the repository root, so go
# there rather than requiring the caller to.
cd "$(dirname "$0")/.."

CFLAGS="-O2 -g -Wall \
  -fstack-protector-strong \
  -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2 \
  -fPIE \
  -fno-plt"

LDFLAGS="-pie \
  -Wl,-z,relro,-z,now \
  -Wl,-z,noexecstack"

# A full rebuild so the bundled git objects pick up the same flags.
# cleanall also descends into vendor/git, which plain clean does not.
make cleanall
exec make "$@" CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS"