Harden compiler flags, simplify CWE-134 script, fix bugs found by new warnings

configure.ac:
- Replace basic -Wformat/-Wformat-nonliteral with -Wformat=2
- Add -Wextra, -Wnull-dereference, -Wpointer-arith, -Wimplicit-function-declaration
- Add -fstack-protector-strong, -fno-common, -D_FORTIFY_SOURCE=2
- Add GCC-specific flags via AC_COMPILE_IFELSE: -Wlogical-op, -Wduplicated-cond,
  -Wduplicated-branches, -Wstringop-overflow
- Add linker hardening via AC_LINK_IFELSE: -Wl,-z,relro -Wl,-z,now
- Suppress noisy -Wextra sub-warnings: -Wno-unused-parameter,
  -Wno-missing-field-initializers, -Wno-sign-compare, -Wno-cast-function-type
- Remove AM_CFLAGS/CFLAGS duplication line

check-cwe134.sh:
- Reduce from 5 checks to 2 (checks 1-3 are now redundant with -Wformat=2)
- Check 1: verify known wrappers have G_GNUC_PRINTF attribute
- Check 2: auto-detect unannotated variadic printf-like functions

Bug fixes found by -Wduplicated-branches:
- chatlog.c: non-MUCPM redact path passed resourcepart instead of NULL
- rosterwin.c: two instances of if/else with identical branches in roster count
- omemo.c: redundant else-if branch in omemo_automatic_start

Other fixes for new warnings:
- console.c: pointer compared to integer 0 instead of NULL (2 instances)
- vcard.c: NULL guard for filename before g_file_set_contents
- files.c: refactor to early return, eliminating NULL logfile path
- database.c: const-correctness for type, query, sort variables
- form.c/xmpp.h: const-correctness for form_set_value parameter
- muc.c/muc.h: remove meaningless top-level const on return type
- common.c: const-correctness for URL string literal
- xmpp/omemo.c: scope block for declarations after goto, move from decl
  before goto, replace goto with direct return
- http_common.h: add G_GNUC_PRINTF attributes for http_print_transfer*
- test_common.c: add currb NULL check to silence -Wnull-dereference
This commit is contained in:
2026-03-04 21:18:35 +03:00
parent 92953099e1
commit bb6d29a060
17 changed files with 156 additions and 240 deletions

View File

@@ -385,9 +385,39 @@ AC_CHECK_LIB([util], [forkpty], [AM_CONDITIONAL([HAVE_FORKPTY], [true]) FORKPTY_
AC_SUBST([FORKPTY_LIB])
## Default parameters
AM_CFLAGS="$AM_CFLAGS -Wall -Wformat -Wformat-nonliteral -Wno-format-zero-length -Wno-deprecated-declarations -std=gnu99 -ggdb3"
AM_CFLAGS="$AM_CFLAGS -Wall -Wextra -Wformat=2 -Wno-format-zero-length"
AM_CFLAGS="$AM_CFLAGS -Wno-deprecated-declarations -Wno-unused-parameter -Wno-missing-field-initializers -Wno-sign-compare -Wno-cast-function-type"
AM_CFLAGS="$AM_CFLAGS -Wnull-dereference -Wpointer-arith"
AM_CFLAGS="$AM_CFLAGS -Wimplicit-function-declaration"
AM_CFLAGS="$AM_CFLAGS -fstack-protector-strong -fno-common"
AM_CFLAGS="$AM_CFLAGS -D_FORTIFY_SOURCE=2"
AM_CFLAGS="$AM_CFLAGS -std=gnu99 -ggdb3"
# GCC-specific warnings (not supported by clang) — test each one
saved_CFLAGS="$CFLAGS"
for _flag in -Wlogical-op -Wduplicated-cond -Wduplicated-branches \
-Wstringop-overflow; do
AC_MSG_CHECKING([whether $CC supports $_flag])
CFLAGS="$saved_CFLAGS $_flag -Werror"
AC_COMPILE_IFELSE([AC_LANG_PROGRAM()],
[AC_MSG_RESULT([yes]); AM_CFLAGS="$AM_CFLAGS $_flag"],
[AC_MSG_RESULT([no])])
done
CFLAGS="$saved_CFLAGS"
AM_LDFLAGS="$AM_LDFLAGS -export-dynamic"
# Linker hardening (RELRO + immediate binding)
saved_LDFLAGS="$LDFLAGS"
for _flag in -Wl,-z,relro -Wl,-z,now; do
AC_MSG_CHECKING([whether linker supports $_flag])
LDFLAGS="$saved_LDFLAGS $_flag"
AC_LINK_IFELSE([AC_LANG_PROGRAM()],
[AC_MSG_RESULT([yes]); AM_LDFLAGS="$AM_LDFLAGS $_flag"],
[AC_MSG_RESULT([no])])
done
LDFLAGS="$saved_LDFLAGS"
AS_IF([test "x$enable_coverage" = xyes],
[AM_CFLAGS="$AM_CFLAGS --coverage -O0"
AM_LDFLAGS="$AM_LDFLAGS --coverage"
@@ -401,7 +431,7 @@ AS_IF([test "x$PLATFORM" = xosx],
AM_CFLAGS="$AM_CFLAGS $PTHREAD_CFLAGS $glib_CFLAGS $gio_CFLAGS $curl_CFLAGS ${SQLITE_CFLAGS}"
AM_CFLAGS="$AM_CFLAGS $libnotify_CFLAGS ${GTK_CFLAGS} $python_CFLAGS"
AM_CFLAGS="$AM_CFLAGS -DTHEMES_PATH=\"\\\"$THEMES_PATH\\\"\" -DICONS_PATH=\"\\\"$ICONS_PATH\\\"\" -DGLOBAL_PYTHON_PLUGINS_PATH=\"\\\"$GLOBAL_PYTHON_PLUGINS_PATH\\\"\" -DGLOBAL_C_PLUGINS_PATH=\"\\\"$GLOBAL_C_PLUGINS_PATH\\\"\""
AM_CFLAGS="$AM_CFLAGS $CFLAGS"
LIBS="$glib_LIBS $gio_LIBS $PTHREAD_LIBS $curl_LIBS $libnotify_LIBS $python_LIBS ${GTK_LIBS} ${SQLITE_LIBS} $LIBS"
AC_SUBST(AM_LDFLAGS)