Merge pull request #16122 from alalek:cmake_update_cpu_compiler_detection
[platform/upstream/opencv.git] / cmake / OpenCVCompilerDefenses.cmake
1 # Enable build defense flags.
2 # Performance may be affected.
3 # More information:
4 # - https://www.owasp.org/index.php/C-Based_Toolchain_Hardening
5 # - https://wiki.debian.org/Hardening
6 # - https://wiki.gentoo.org/wiki/Hardened/Toolchain
7 # - https://docs.microsoft.com/en-us/cpp/build/reference/sdl-enable-additional-security-checks
8 # - https://developer.apple.com/library/archive/documentation/Security/Conceptual/SecureCodingGuide/Articles/BufferOverflows.html
9
10 set(OPENCV_LINKER_DEFENSES_FLAGS_COMMON "")
11
12 macro(ocv_add_defense_compiler_flag option)
13   ocv_check_flag_support(CXX "${option}" _varname "${ARGN}")
14   if(${_varname})
15     set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} ${option}")
16   endif()
17
18   ocv_check_flag_support(C "${option}" _varname "${ARGN}")
19   if(${_varname})
20     set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} ${option}")
21   endif()
22 endmacro()
23
24 macro(ocv_add_defense_compiler_flag_release option)
25   ocv_check_flag_support(CXX "${option}" _varname "${ARGN}")
26   if(${_varname})
27     set(CMAKE_CXX_FLAGS_RELEASE "${CMAKE_CXX_FLAGS_RELEASE} ${option}")
28   endif()
29
30   ocv_check_flag_support(C "${option}" _varname "${ARGN}")
31   if(${_varname})
32     set(CMAKE_C_FLAGS_RELEASE "${CMAKE_C_FLAGS_RELEASE} ${option}")
33   endif()
34 endmacro()
35
36 # Define flags
37
38 if(MSVC)
39   ocv_add_defense_compiler_flag("/GS")
40   ocv_add_defense_compiler_flag("/sdl")
41   ocv_add_defense_compiler_flag("/guard:cf")
42   ocv_add_defense_compiler_flag("/w34018 /w34146 /w34244 /w34267 /w34302 /w34308 /w34509 /w34532 /w34533 /w34700 /w34789 /w34995 /w34996")
43   set(OPENCV_LINKER_DEFENSES_FLAGS_COMMON "${OPENCV_LINKER_DEFENSES_FLAGS_COMMON} /guard:cf /dynamicbase" )
44   if(NOT X86_64)
45     set(OPENCV_LINKER_DEFENSES_FLAGS_COMMON "${OPENCV_LINKER_DEFENSES_FLAGS_COMMON} /safeseh")
46   endif()
47 elseif(CV_CLANG)
48   ocv_add_defense_compiler_flag("-fstack-protector-strong")
49   ocv_add_defense_compiler_flag_release("-D_FORTIFY_SOURCE=2")
50   if (NOT APPLE)
51     set(OPENCV_LINKER_DEFENSES_FLAGS_COMMON "${OPENCV_LINKER_DEFENSES_FLAGS_COMMON} -z noexecstack -z relro -z now" )
52   endif()
53 elseif(CV_GCC)
54   if(CMAKE_CXX_COMPILER_VERSION VERSION_LESS "4.9")
55     ocv_add_defense_compiler_flag("-fstack-protector")
56   else()
57     ocv_add_defense_compiler_flag("-fstack-protector-strong")
58   endif()
59
60   # These flags is added by general options: -Wformat -Wformat-security
61   if(NOT CMAKE_CXX_FLAGS MATCHES "-Wformat" OR NOT CMAKE_CXX_FLAGS MATCHES "format-security")
62     message(FATAL_ERROR "Defense flags: uncompatible options")
63   endif()
64
65   if(ANDROID)
66     ocv_add_defense_compiler_flag_release("-D_FORTIFY_SOURCE=2")
67     if(NOT CMAKE_CXX_FLAGS_RELEASE MATCHES "-D_FORTIFY_SOURCE=2") # TODO Check this
68       ocv_add_defense_compiler_flag_release("-D_FORTIFY_SOURCE=1")
69     endif()
70   else()
71     ocv_add_defense_compiler_flag_release("-D_FORTIFY_SOURCE=2")
72   endif()
73
74   set(OPENCV_LINKER_DEFENSES_FLAGS_COMMON "${OPENCV_LINKER_DEFENSES_FLAGS_COMMON} -z noexecstack -z relro -z now" )
75 else()
76   # not supported
77 endif()
78
79 set(CMAKE_POSITION_INDEPENDENT_CODE TRUE)
80 if(CV_GCC OR CV_CLANG)
81     if(NOT CMAKE_CXX_FLAGS MATCHES "-fPIC")
82       ocv_add_defense_compiler_flag("-fPIC")
83     endif()
84   set(CMAKE_EXE_LINKER_FLAGS "${CMAKE_EXE_LINKER_FLAGS} -fPIE -pie")
85 endif()
86
87 set( CMAKE_SHARED_LINKER_FLAGS "${CMAKE_SHARED_LINKER_FLAGS} ${OPENCV_LINKER_DEFENSES_FLAGS_COMMON}" )
88 set( CMAKE_MODULE_LINKER_FLAGS "${CMAKE_MODULE_LINKER_FLAGS} ${OPENCV_LINKER_DEFENSES_FLAGS_COMMON}" )
89 set( CMAKE_EXE_LINKER_FLAGS "${CMAKE_EXE_LINKER_FLAGS} ${OPENCV_LINKER_DEFENSES_FLAGS_COMMON}" )
90
91 if(CV_GCC OR CV_CLANG)
92   foreach(flags
93           CMAKE_CXX_FLAGS CMAKE_CXX_FLAGS_RELEASE CMAKE_CXX_FLAGS_DEBUG
94           CMAKE_C_FLAGS CMAKE_C_FLAGS_RELEASE CMAKE_C_FLAGS_DEBUG)
95     string(REPLACE "-O3" "-O2" ${flags} "${${flags}}")
96   endforeach()
97 endif()