Harden compiler flags, simplify CWE-134 script, fix bugs found by new warnings
configure.ac: - Replace basic -Wformat/-Wformat-nonliteral with -Wformat=2 - Add -Wextra, -Wnull-dereference, -Wpointer-arith, -Wimplicit-function-declaration - Add -fstack-protector-strong, -fno-common, -D_FORTIFY_SOURCE=2 - Add GCC-specific flags via AC_COMPILE_IFELSE: -Wlogical-op, -Wduplicated-cond, -Wduplicated-branches, -Wstringop-overflow - Add linker hardening via AC_LINK_IFELSE: -Wl,-z,relro -Wl,-z,now - Suppress noisy -Wextra sub-warnings: -Wno-unused-parameter, -Wno-missing-field-initializers, -Wno-sign-compare, -Wno-cast-function-type - Remove AM_CFLAGS/CFLAGS duplication line check-cwe134.sh: - Reduce from 5 checks to 2 (checks 1-3 are now redundant with -Wformat=2) - Check 1: verify known wrappers have G_GNUC_PRINTF attribute - Check 2: auto-detect unannotated variadic printf-like functions Bug fixes found by -Wduplicated-branches: - chatlog.c: non-MUCPM redact path passed resourcepart instead of NULL - rosterwin.c: two instances of if/else with identical branches in roster count - omemo.c: redundant else-if branch in omemo_automatic_start Other fixes for new warnings: - console.c: pointer compared to integer 0 instead of NULL (2 instances) - vcard.c: NULL guard for filename before g_file_set_contents - files.c: refactor to early return, eliminating NULL logfile path - database.c: const-correctness for type, query, sort variables - form.c/xmpp.h: const-correctness for form_set_value parameter - muc.c/muc.h: remove meaningless top-level const on return type - common.c: const-correctness for URL string literal - xmpp/omemo.c: scope block for declarations after goto, move from decl before goto, replace goto with direct return - http_common.h: add G_GNUC_PRINTF attributes for http_print_transfer* - test_common.c: add currb NULL check to silence -Wnull-dereference
This commit is contained in:
34
configure.ac
34
configure.ac
@@ -385,9 +385,39 @@ AC_CHECK_LIB([util], [forkpty], [AM_CONDITIONAL([HAVE_FORKPTY], [true]) FORKPTY_
|
||||
AC_SUBST([FORKPTY_LIB])
|
||||
|
||||
## Default parameters
|
||||
AM_CFLAGS="$AM_CFLAGS -Wall -Wformat -Wformat-nonliteral -Wno-format-zero-length -Wno-deprecated-declarations -std=gnu99 -ggdb3"
|
||||
AM_CFLAGS="$AM_CFLAGS -Wall -Wextra -Wformat=2 -Wno-format-zero-length"
|
||||
AM_CFLAGS="$AM_CFLAGS -Wno-deprecated-declarations -Wno-unused-parameter -Wno-missing-field-initializers -Wno-sign-compare -Wno-cast-function-type"
|
||||
AM_CFLAGS="$AM_CFLAGS -Wnull-dereference -Wpointer-arith"
|
||||
AM_CFLAGS="$AM_CFLAGS -Wimplicit-function-declaration"
|
||||
AM_CFLAGS="$AM_CFLAGS -fstack-protector-strong -fno-common"
|
||||
AM_CFLAGS="$AM_CFLAGS -D_FORTIFY_SOURCE=2"
|
||||
AM_CFLAGS="$AM_CFLAGS -std=gnu99 -ggdb3"
|
||||
|
||||
# GCC-specific warnings (not supported by clang) — test each one
|
||||
saved_CFLAGS="$CFLAGS"
|
||||
for _flag in -Wlogical-op -Wduplicated-cond -Wduplicated-branches \
|
||||
-Wstringop-overflow; do
|
||||
AC_MSG_CHECKING([whether $CC supports $_flag])
|
||||
CFLAGS="$saved_CFLAGS $_flag -Werror"
|
||||
AC_COMPILE_IFELSE([AC_LANG_PROGRAM()],
|
||||
[AC_MSG_RESULT([yes]); AM_CFLAGS="$AM_CFLAGS $_flag"],
|
||||
[AC_MSG_RESULT([no])])
|
||||
done
|
||||
CFLAGS="$saved_CFLAGS"
|
||||
|
||||
AM_LDFLAGS="$AM_LDFLAGS -export-dynamic"
|
||||
|
||||
# Linker hardening (RELRO + immediate binding)
|
||||
saved_LDFLAGS="$LDFLAGS"
|
||||
for _flag in -Wl,-z,relro -Wl,-z,now; do
|
||||
AC_MSG_CHECKING([whether linker supports $_flag])
|
||||
LDFLAGS="$saved_LDFLAGS $_flag"
|
||||
AC_LINK_IFELSE([AC_LANG_PROGRAM()],
|
||||
[AC_MSG_RESULT([yes]); AM_LDFLAGS="$AM_LDFLAGS $_flag"],
|
||||
[AC_MSG_RESULT([no])])
|
||||
done
|
||||
LDFLAGS="$saved_LDFLAGS"
|
||||
|
||||
AS_IF([test "x$enable_coverage" = xyes],
|
||||
[AM_CFLAGS="$AM_CFLAGS --coverage -O0"
|
||||
AM_LDFLAGS="$AM_LDFLAGS --coverage"
|
||||
@@ -401,7 +431,7 @@ AS_IF([test "x$PLATFORM" = xosx],
|
||||
AM_CFLAGS="$AM_CFLAGS $PTHREAD_CFLAGS $glib_CFLAGS $gio_CFLAGS $curl_CFLAGS ${SQLITE_CFLAGS}"
|
||||
AM_CFLAGS="$AM_CFLAGS $libnotify_CFLAGS ${GTK_CFLAGS} $python_CFLAGS"
|
||||
AM_CFLAGS="$AM_CFLAGS -DTHEMES_PATH=\"\\\"$THEMES_PATH\\\"\" -DICONS_PATH=\"\\\"$ICONS_PATH\\\"\" -DGLOBAL_PYTHON_PLUGINS_PATH=\"\\\"$GLOBAL_PYTHON_PLUGINS_PATH\\\"\" -DGLOBAL_C_PLUGINS_PATH=\"\\\"$GLOBAL_C_PLUGINS_PATH\\\"\""
|
||||
AM_CFLAGS="$AM_CFLAGS $CFLAGS"
|
||||
|
||||
LIBS="$glib_LIBS $gio_LIBS $PTHREAD_LIBS $curl_LIBS $libnotify_LIBS $python_LIBS ${GTK_LIBS} ${SQLITE_LIBS} $LIBS"
|
||||
|
||||
AC_SUBST(AM_LDFLAGS)
|
||||
|
||||
Reference in New Issue
Block a user