blob: 92aa78be5fe127e125ebb28d9827462f2aea5675 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
#!/bin/sh
# Build cgit for a release with Linux hardening flags.
#
# These are ELF and GCC/Clang specific, so this targets a Linux deploy
# rather than local macOS development, where a plain make is enough. The
# flags add a stack protector, fortified libc calls, a position independent
# executable, and full RELRO.
#
# By default Lua is pinned off so the binary needs no Lua at runtime. Pass
# "lua" as the first argument to link the lua: filter backend instead, which
# needs a Lua dev package installed.
#
# Usage: ./tools/release-build.sh [lua]   (run from the repository root)

set -eu

if [ "${1:-}" = "lua" ]; then
	LUA=
else
	LUA=NO_LUA=1
fi

CFLAGS="-O2 -g -Wall \
  -fstack-protector-strong \
  -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=2 \
  -fPIE \
  -fno-plt"

LDFLAGS="-pie \
  -Wl,-z,relro,-z,now \
  -Wl,-z,noexecstack"

# A full rebuild so the bundled git objects pick up the same flags.
# cleanall also descends into git/, which plain clean does not.
make $LUA cleanall
exec make $LUA CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS"