From cbe183b1c22d6aa507a518c9ed34c53d08659016 Mon Sep 17 00:00:00 2001 From: Aleksey Sanin Date: Wed, 30 Sep 2026 11:32:37 -0400 Subject: [PATCH] (xmlsec-windows) Added `hardening` option to `configure.ps1` to enable security hardening flags in the MSVC build --- docs/md/index.md | 2 ++ win32/Makefile.msvc | 11 +++++++++++ win32/configure.ps1 | 5 +++++ 3 files changed, 18 insertions(+) diff --git a/docs/md/index.md b/docs/md/index.md index dffbd3b79..1a46eb31b 100644 --- a/docs/md/index.md +++ b/docs/md/index.md @@ -34,6 +34,8 @@ see the Copyright file in the distribution for details. - (xmlsec-mscng) Enforced HMAC length checks similar to other crypto backends. - (xmlsec-windows) Added `apps` option to `configure.ps1` to control whether the command-line binaries in the `apps/` folder are built (default: `yes`). + - (xmlsec-windows) Added `hardening` option to `configure.ps1` to enable security hardening flags + (`/guard:cf`, `/DYNAMICBASE`, and `/NXCOMPAT`) in the MSVC build (default: `yes`). - Several other small fixes (see [more details](https://github.com/lsh123/xmlsec/commits/xmlsec_1_3_13)). - **June 23, 2026** diff --git a/win32/Makefile.msvc b/win32/Makefile.msvc index 78e9a668c..ad898cec8 100644 --- a/win32/Makefile.msvc +++ b/win32/Makefile.msvc @@ -45,6 +45,7 @@ AUTOCONF = .\configure.txt #STATIC = 0 #WITH_APPS = 1 #PEDANTIC = 1 +#HARDENING = 1 #PREFIX = . # set this to the right value. #BINPREFIX = $(PREFIX)\bin #INCPREFIX = $(PREFIX)\include @@ -499,6 +500,11 @@ CFLAGS = $(CFLAGS) /W4 /WX CFLAGS = $(CFLAGS) /W1 !endif +# Security hardening: Control Flow Guard. +!if "$(HARDENING)" == "1" +CFLAGS = $(CFLAGS) /guard:cf +!endif + # C4127: conditional expression is constant # this generates a false warning inside asserts # C4130: '!=': logical operation on address of string constant: @@ -580,6 +586,11 @@ ALIBS = libxml2s.lib $(LIBS) LDFLAGS = $(LDFLAGS) /WX !endif +# Security hardening: Control Flow Guard, ASLR, and DEP. +!if "$(HARDENING)" == "1" +LDFLAGS = $(LDFLAGS) /guard:cf /DYNAMICBASE /NXCOMPAT +!endif + # Enable memcheck. !if "$(MEMCHECK)" == "asan" LDFLAGS = $(LDFLAGS) /fsanitize=address diff --git a/win32/configure.ps1 b/win32/configure.ps1 index fc868ba6c..6d324d649 100755 --- a/win32/configure.ps1 +++ b/win32/configure.ps1 @@ -68,6 +68,7 @@ $script:buildUnicode = 1 $script:buildDebug = 0 $script:buildWithMemcheck = "no" $script:buildPedantic = 1 +$script:buildHardening = 1 $script:buildCc = "cl.exe" $script:buildCflags = "" $script:buildStatic = 1 @@ -120,6 +121,7 @@ function Show-Usage { Write-Host " memcheck: Build unoptimised debug executables with memcheck reporting (default: '$($script:buildWithMemcheck)')" Write-Host " with possible options: 'yes'/'leaks', 'asan', or 'no'." Write-Host " pedantic: Build with more warnings enabled (default: '$(if ($script:buildPedantic) { 'yes' } else { 'no' })')" + Write-Host " hardening: Build with security hardening flags: /guard:cf, /DYNAMICBASE, and /NXCOMPAT (default: '$(if ($script:buildHardening) { 'yes' } else { 'no' })')" Write-Host " cc: Build with the specified compiler (default: '$($script:buildCc)')" Write-Host " cflags: Build with the specified compiler flags (default: '$($script:buildCflags)')" Write-Host " static: Build static xmlsec libraries (default: '$(if ($script:buildStatic) { 'yes' } else { 'no' })')" @@ -221,6 +223,7 @@ function DiscoverVersion { $lines += "DEBUG=$(if ($script:buildDebug) { '1' } else { '0' })" $lines += "MEMCHECK=$($script:buildWithMemcheck)" $lines += "PEDANTIC=$(if ($script:buildPedantic) { '1' } else { '0' })" + $lines += "HARDENING=$(if ($script:buildHardening) { '1' } else { '0' })" $lines += "CC=$($script:buildCc)" $lines += "CFLAGS=$($script:buildCflags)" $lines += "STATIC=$(if ($script:buildStatic) { '1' } else { '0' })" @@ -336,6 +339,7 @@ for ($i = 0; ($i -lt $args.Count) -and ($script:errorFlag -eq 0); $i++) { } } "pedantic" { $script:buildPedantic = StrToBool $val "pedantic" } + "hardening" { $script:buildHardening = StrToBool $val "hardening" } "cc" { $script:buildCc = $val } "cflags" { $script:buildCflags = $val } "static" { $script:buildStatic = StrToBool $val "static" } @@ -470,6 +474,7 @@ Write-Host "" Write-Host "Win32 build configuration" Write-Host "-------------------------" Write-Host " Pedantic: $(BoolToStr $script:buildPedantic)" +Write-Host " Hardening: $(BoolToStr $script:buildHardening)" Write-Host " C compiler: $($script:buildCc)" Write-Host " C compiler flags: $($script:buildCflags)" Write-Host " C-Runtime option: $($script:cruntime)"