+# Arguments missing.
+if (scalar @ARGV == 0) {
+ require Pod::Usage;
+ Pod::Usage::pod2usage(2);
+}
+
+# Don't load Term::ANSIColor in buildd mode because Term::ANSIColor is not
+# installed on Debian's buildds.
+if (not $option_buildd) {
+ require Term::ANSIColor;
+}
+
+if ($option_all) {
+ $option_pie = 1;
+ $option_bindnow = 1;
+}
+
+# Strip flags which should be ignored.
+if (scalar @option_ignore_flag > 0) {
+ my %ignores = map { $_ => 1 } @option_ignore_flag;
+ foreach my $flags (@flag_refs) {
+ @{$flags} = grep {
+ # Flag found as string.
+ not exists $ignores{$_}
+ # Flag found as string representation of regexp.
+ and (not defined $flag_renames{$_}
+ or not exists $ignores{$flag_renames{$_}})
+ } @{$flags};
+ }
+}
+
+# Precompile all flag regexps. any_flags_used(), all_flags_used() get a lot
+# faster with this.
+foreach my $flags (@flag_refs_all) {
+ @{$flags} = compile_flag_regexp(\%flag_renames, @{$flags});
+}
+
+# Precompile ignore line regexps, also anchor at beginning and end of line.
+foreach my $ignore (@option_ignore_line) {
+ $ignore = qr/^$ignore$/;
+}
+
+# Final exit code.
+my $exit = 0;
+
+FILE:
+foreach my $file (@ARGV) {
+ print "checking '$file'...\n" if scalar @ARGV > 1;
+
+ open my $fh, '<', $file or die "$!: $file";
+
+ # Architecture of this file.
+ my $arch = $option_arch;
+
+ # Hardening options. Not all architectures support all hardening options.
+ my $harden_format = 1;
+ my $harden_fortify = 1;
+ my $harden_stack = 1;
+ my $harden_relro = 1;
+ my $harden_bindnow = $option_bindnow; # defaults to 0
+ my $harden_pie = $option_pie; # defaults to 0
+
+ while (my $line = <$fh>) {
+ # Detect architecture automatically unless overridden. For buildd logs
+ # only, doesn't use the dpkg-buildpackage header. Necessary to ignore
+ # build logs which aren't built (wrong architecture, build error,
+ # etc.).
+ if (not $arch
+ and $line =~ /^Architecture: (.+)$/) {
+ $arch = $1;
+ }
+
+ # dpkg-buildflags only provides hardening flags since 1.16.1, don't
+ # check for hardening flags in buildd mode if an older dpkg-dev is
+ # used. Default flags (-g -O2) are still checked.
+ #
+ # Packages which were built before 1.16.1 but used their own hardening
+ # flags are not checked.
+ if ($option_buildd
+ and index($line, 'Toolchain package versions: ') == 0) {
+ require Dpkg::Version;
+ if (not $line =~ /\bdpkg-dev_(\S+)/
+ or Dpkg::Version::version_compare($1, '1.16.1') < 0) {
+ $harden_format = 0;
+ $harden_fortify = 0;
+ $harden_stack = 0;
+ $harden_relro = 0;
+ $harden_bindnow = 0;
+ $harden_pie = 0;
+ }
+ }
+
+ # The following two versions of CMake in Debian obeyed CPPFLAGS, but
+ # this was later dropped because upstream rejected the patch. Thus
+ # build logs with these versions will have fortify hardening flags
+ # enabled, even though they may be not correctly set and are missing
+ # when build with later CMake versions. Thanks to Aron Xu for letting
+ # me know.
+ if (index($line, 'Package versions: ') == 0
+ and $line =~ /\bcmake_(\S+)/
+ and ($1 eq '2.8.7-1' or $1 eq '2.8.7-2')) {
+ if (not $option_buildd) {
+ error_invalid_cmake($1);
+ } else {
+ print "W-invalid-cmake-used $1\n";
+ }
+ $exit |= $exit_code{invalid_cmake};
+ }
+
+ # If hardening wrapper is used (wraps calls to gcc and adds hardening
+ # flags automatically) we can't perform any checks, abort.
+ if (index($line, 'Build-Depends: ') == 0
+ and $line =~ /\bhardening-wrapper\b/) {
+ if (not $option_buildd) {
+ error_hardening_wrapper();
+ } else {
+ print "I-hardening-wrapper-used\n";
+ }
+ $exit |= $exit_code{hardening_wrapper};
+ next FILE;
+ }
+
+ # We skip over unimportant lines at the beginning of the log to
+ # prevent false positives.
+ last if index($line, 'dpkg-buildpackage: ') == 0;
+ }
+
+ # Input lines, contain only the lines with compiler commands.
+ my @input = ();
+
+ my $continuation = 0;
+ my $complete_line = undef;
+ while (my $line = <$fh>) {
+ # And stop at the end of the build log. Package details (reported by
+ # the buildd logs) are not important for us. This also prevents false
+ # positives.
+ last if $line =~ /^Build finished at \d{8}-\d{4}$/;
+
+ # Detect architecture automatically unless overridden.
+ if (not $arch
+ and $line =~ /^dpkg-buildpackage: host architecture (.+)$/) {
+ $arch = $1;
+ }
+
+ # Ignore compiler warnings for now.
+ next if $line =~ /$warning_regex/o;
+
+ if (not $option_buildd and index($line, "\033") != -1) { # esc
+ # Remove all ANSI color sequences which are sometimes used in
+ # non-verbose builds.
+ $line = Term::ANSIColor::colorstrip($line);
+ # Also strip '\0xf' (delete previous character), used by Elinks'
+ # build system.
+ $line =~ s/\x0f//g;
+ # And "ESC(B" which seems to be used on armhf and hurd (not sure
+ # what it does).
+ $line =~ s/\033\(B//g;
+ }
+
+ # Check if this line indicates a non verbose build.
+ my $non_verbose = is_non_verbose_build($line);
+
+ # One line may contain multiple commands (";"). Treat each one as
+ # single line. parse_line() is slow, only use it when necessary.
+ my @line = (index($line, ';') == -1)
+ ? ($line)
+ : map {
+ # Ensure newline at the line end - necessary for
+ # correct parsing later.
+ $_ =~ s/\s+$//;
+ $_ .= "\n";
+ } Text::ParseWords::parse_line(';', 1, $line);
+ foreach my $line (@line) {
+ if ($continuation) {
+ $continuation = 0;
+
+ # Join lines, but leave the "\" in place so it's clear where
+ # the original line break was.
+ chomp $complete_line;
+ $complete_line .= ' ' . $line;
+ }
+ # Line continuation, line ends with "\".
+ if ($line =~ /\\$/) {
+ $continuation = 1;
+ # Start line continuation.
+ if (not defined $complete_line) {
+ $complete_line = $line;
+ }
+ next;
+ }
+
+ # Use the complete line if a line continuation occurred.
+ if (defined $complete_line) {
+ $line = $complete_line;
+ $complete_line = undef;
+ }
+
+ # Ignore lines with no compiler commands.
+ next if not $non_verbose
+ and not $line =~ /\b$cc_regex(?:\s|\\)/o;
+ # Ignore lines with no filenames with extensions. May miss some
+ # non-verbose builds (e.g. "gcc -o test" [sic!]), but shouldn't be
+ # a problem as the log will most likely contain other non-verbose
+ # commands which are detected.
+ next if not $non_verbose
+ and not $line =~ /$file_extension_regex/o;
+
+ # Ignore false positives.
+ #
+ # `./configure` output.
+ next if not $non_verbose
+ and $line =~ /^(?:checking|[Cc]onfigure:) /;
+ next if $line =~ /^\s*(?:Host\s+)?(?:C(?:\+\+)?\s+)?
+ [Cc]ompiler[\s.]*:?\s+
+ /xo;
+ next if $line =~ /^\s*(?:- )?(?:HOST_)?(?:CC|CXX)\s*=\s*$cc_regex_full\s*$/o;
+
+ # Check if additional hardening options were used. Used to ensure
+ # they are used for the complete build.
+ $harden_pie = 1 if any_flags_used($line, @def_cflags_pie, @def_ldflags_pie);
+ $harden_bindnow = 1 if any_flags_used($line, @def_ldflags_bindnow);
+
+ push @input, $line;
+ }
+ }
+
+ close $fh or die $!;
+
+ # Ignore arch if requested.
+ if (scalar @option_ignore_arch > 0 and $arch) {
+ foreach my $ignore (@option_ignore_arch) {
+ if ($arch eq $ignore) {
+ print "ignoring architecture '$arch'\n";
+ next FILE;
+ }
+ }
+ }
+
+ if (scalar @input == 0) {
+ if (not $option_buildd) {
+ print "No compiler commands!\n";
+ } else {
+ print "W-no-compiler-commands\n";
+ }
+ $exit |= $exit_code{no_compiler_commands};
+ next FILE;
+ }
+
+ if ($option_buildd) {
+ $statistics{commands} += scalar @input;
+ }
+
+ # Option or auto detected.
+ if ($arch) {
+ # The following was partially copied from dpkg-dev 1.16.1.2
+ # (/usr/share/perl5/Dpkg/Vendor/Debian.pm, add_hardening_flags()),
+ # copyright Raphaƫl Hertzog <hertzog@debian.org>, Kees Cook
+ # <kees@debian.org>, Canonical, Ltd. licensed under GPL version 2 or
+ # later. Keep it in sync.
+
+ require Dpkg::Arch;
+ my ($abi, $os, $cpu) = Dpkg::Arch::debarch_to_debtriplet($arch);
+
+ # Disable unsupported hardening options.
+ if ($cpu =~ /^(?:ia64|alpha|mips|mipsel|hppa)$/ or $arch eq 'arm') {
+ $harden_stack = 0;
+ }
+ if ($cpu =~ /^(?:ia64|hppa|avr32)$/) {
+ $harden_relro = 0;
+ $harden_bindnow = 0;
+ }
+ }
+
+ # Default values.
+ my @cflags = @def_cflags;
+ my @cxxflags = @def_cxxflags;
+ my @cppflags = @def_cppflags;
+ my @ldflags = @def_ldflags;
+ # Check the specified hardening options, same order as dpkg-buildflags.
+ if ($harden_pie) {
+ @cflags = (@cflags, @def_cflags_pie);
+ @cxxflags = (@cxxflags, @def_cflags_pie);
+ @ldflags = (@ldflags, @def_ldflags_pie);
+ }
+ if ($harden_stack) {
+ @cflags = (@cflags, @def_cflags_stack);
+ @cxxflags = (@cxxflags, @def_cflags_stack);
+ }
+ if ($harden_fortify) {
+ @cflags = (@cflags, @def_cflags_fortify);
+ @cxxflags = (@cxxflags, @def_cflags_fortify);
+ @cppflags = (@cppflags, @def_cppflags_fortify);
+ }
+ if ($harden_format) {
+ @cflags = (@cflags, @def_cflags_format);
+ @cxxflags = (@cxxflags, @def_cflags_format);
+ }
+ if ($harden_relro) {
+ @ldflags = (@ldflags, @def_ldflags_relro);
+ }
+ if ($harden_bindnow) {
+ @ldflags = (@ldflags, @def_ldflags_bindnow);
+ }
+
+LINE:
+ for (my $i = 0; $i < scalar @input; $i++) {
+ my $line = $input[$i];
+
+ # Ignore line if requested.
+ foreach my $ignore (@option_ignore_line) {
+ next LINE if $line =~ /$ignore/;
+ }
+
+ my $skip = 0;
+ if (is_non_verbose_build($line, $input[$i + 1], \$skip)) {
+ if (not $option_buildd) {
+ error_non_verbose_build($line);
+ } else {
+ $statistics{commands_nonverbose}++;
+ }
+ $exit |= $exit_code{non_verbose_build};
+ next;
+ }
+ # Even if it's a verbose build, we might have to skip this line.
+ next if $skip;
+
+ # Remove everything until and including the compiler command. Makes
+ # checks easier and faster.
+ $line =~ s/^.*?$cc_regex//o;
+ # "([...] test.c)" is not detected as 'test.c' - fix this by removing
+ # the brace and similar characters.
+ $line =~ s/['")]+$//;
+
+ # Skip unnecessary tests when only preprocessing.
+ my $flag_preprocess = 0;
+
+ my $dependency = 0;
+ my $preprocess = 0;
+ my $compile = 0;
+ my $link = 0;
+
+ # Preprocess, compile, assemble.
+ if ($line =~ /\s(-E|-S|-c)\b/) {
+ $preprocess = 1;
+ $flag_preprocess = 1 if $1 eq '-E';
+ $compile = 1 if $1 eq '-S' or $1 eq '-c';
+ # Dependency generation for Makefiles. The other flags (-MF -MG -MP
+ # -MT -MQ) are always used with -M/-MM.
+ } elsif ($line =~ /\s(?:-M|-MM)\b/) {
+ $dependency = 1;
+ # Otherwise assume we are linking.
+ } else {
+ $link = 1;
+ }
+
+ # -MD/-MMD also cause dependency generation, but they don't imply -E!
+ if ($line =~ /\s(?:-MD|-MMD)\b/) {
+ $dependency = 0;
+ $flag_preprocess = 0;
+ }
+
+ # Dependency generation for Makefiles, no preprocessing or other flags
+ # needed.
+ next if $dependency;
+
+ # Get all file extensions on this line.
+ my @extensions = $line =~ /$file_extension_regex/go;
+ # Ignore all unknown extensions to speedup the search below.
+ @extensions = grep { exists $extension{$_} } @extensions;
+
+ # These file types don't require preprocessing.
+ if (extension_found(\%extensions_no_preprocess, @extensions)) {
+ $preprocess = 0;
+ }
+ # These file types require preprocessing.
+ if (extension_found(\%extensions_preprocess, @extensions)) {
+ $preprocess = 1;
+ }
+
+ # If there are source files then it's compiling/linking in one step
+ # and we must check both. We only check for source files here, because
+ # header files cause too many false positives.
+ if (not $flag_preprocess
+ and extension_found(\%extensions_compile_link, @extensions)) {
+ # Assembly files don't need CFLAGS.
+ if (not extension_found(\%extensions_compile, @extensions)
+ and extension_found(\%extensions_no_compile, @extensions)) {
+ $compile = 0;
+ # But the rest does.
+ } else {
+ $compile = 1;
+ }
+ }
+
+ # Assume CXXFLAGS are required when a C++ file is specified in the
+ # compiler line.
+ my $compile_cpp = 0;
+ if ($compile
+ and extension_found(\%extensions_compile_cpp, @extensions)) {
+ $compile = 0;
+ $compile_cpp = 1;
+ }
+
+ if ($option_buildd) {
+ $statistics{preprocess}++ if $preprocess;
+ $statistics{compile}++ if $compile;
+ $statistics{compile_cpp}++ if $compile_cpp;
+ $statistics{link}++ if $link;
+ }
+
+ # Check hardening flags.
+ my @missing;
+ if ($compile and not all_flags_used($line, \@missing, @cflags)
+ # Libraries linked with -fPIC don't have to (and can't) be
+ # linked with -fPIE as well. It's no error if only PIE flags
+ # are missing.
+ and not pic_pie_conflict($line, $harden_pie, \@missing, @def_cflags_pie)
+ # Assume dpkg-buildflags returns the correct flags.
+ and index($line, '`dpkg-buildflags --get CFLAGS`') == -1) {
+ if (not $option_buildd) {
+ error_flags('CFLAGS missing', \@missing, \%flag_renames, $input[$i]);
+ } else {
+ $statistics{compile_missing}++;
+ }
+ $exit |= $exit_code{flags_missing};
+ } elsif ($compile_cpp and not all_flags_used($line, \@missing, @cflags)
+ # Libraries linked with -fPIC don't have to (and can't) be
+ # linked with -fPIE as well. It's no error if only PIE flags
+ # are missing.
+ and not pic_pie_conflict($line, $harden_pie, \@missing, @def_cflags_pie)
+ # Assume dpkg-buildflags returns the correct flags.
+ and index($line, '`dpkg-buildflags --get CXXFLAGS`') == -1) {
+ if (not $option_buildd) {
+ error_flags('CXXFLAGS missing', \@missing, \%flag_renames, $input[$i]);
+ } else {
+ $statistics{compile_cpp_missing}++;
+ }
+ $exit |= $exit_code{flags_missing};
+ }
+ if ($preprocess and not all_flags_used($line, \@missing, @cppflags)
+ # Assume dpkg-buildflags returns the correct flags.
+ and index($line, '`dpkg-buildflags --get CPPFLAGS`') == -1) {
+ if (not $option_buildd) {
+ error_flags('CPPFLAGS missing', \@missing, \%flag_renames, $input[$i]);
+ } else {
+ $statistics{preprocess_missing}++;
+ }
+ $exit |= $exit_code{flags_missing};
+ }
+ if ($link and not all_flags_used($line, \@missing, @ldflags)
+ # Same here, -fPIC conflicts with -fPIE.
+ and not pic_pie_conflict($line, $harden_pie, \@missing, @def_ldflags_pie)
+ # Assume dpkg-buildflags returns the correct flags.
+ and index($line, '`dpkg-buildflags --get LDFLAGS`') == -1) {
+ if (not $option_buildd) {
+ error_flags('LDFLAGS missing', \@missing, \%flag_renames, $input[$i]);
+ } else {
+ $statistics{link_missing}++;
+ }
+ $exit |= $exit_code{flags_missing};
+ }
+ }
+}
+
+# Print statistics for buildd mode, only output in this mode.
+if ($option_buildd) {
+ my @warning;
+
+ if ($statistics{preprocess_missing}) {
+ push @warning, sprintf 'CPPFLAGS %d (of %d)',
+ $statistics{preprocess_missing},
+ $statistics{preprocess};
+ }
+ if ($statistics{compile_missing}) {
+ push @warning, sprintf 'CFLAGS %d (of %d)',
+ $statistics{compile_missing},
+ $statistics{compile};
+ }
+ if ($statistics{compile_cpp_missing}) {
+ push @warning, sprintf 'CXXFLAGS %d (of %d)',
+ $statistics{compile_cpp_missing},
+ $statistics{compile_cpp};
+ }
+ if ($statistics{link_missing}) {
+ push @warning, sprintf 'LDFLAGS %d (of %d)',
+ $statistics{link_missing},
+ $statistics{link};
+ }
+ if (scalar @warning) {
+ local $" = ', '; # array join string
+ print "W-dpkg-buildflags-missing @warning missing\n";
+ }
+
+ if ($statistics{commands_nonverbose}) {
+ printf "W-compiler-flags-hidden %d (of %d) hidden\n",
+ $statistics{commands_nonverbose},
+ $statistics{commands},
+ }
+}
+
+
+exit $exit;
+