Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/md/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,8 @@ see the Copyright file in the distribution for details.
- (xmlsec-mscng) Enforced HMAC length checks similar to other crypto backends.
- (xmlsec-windows) Added `apps` option to `configure.ps1` to control whether the command-line binaries in
the `apps/` folder are built (default: `yes`).
- (xmlsec-windows) Added `hardening` option to `configure.ps1` to enable security hardening flags
(`/guard:cf`, `/DYNAMICBASE`, and `/NXCOMPAT`) in the MSVC build (default: `yes`).
- Several other small fixes (see [more details](https://github.com/lsh123/xmlsec/commits/xmlsec_1_3_13)).

- **June 23, 2026**
Expand Down
11 changes: 11 additions & 0 deletions win32/Makefile.msvc
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@ AUTOCONF = .\configure.txt
#STATIC = 0
#WITH_APPS = 1
#PEDANTIC = 1
#HARDENING = 1
#PREFIX = . # set this to the right value.
#BINPREFIX = $(PREFIX)\bin
#INCPREFIX = $(PREFIX)\include
Expand Down Expand Up @@ -499,6 +500,11 @@ CFLAGS = $(CFLAGS) /W4 /WX
CFLAGS = $(CFLAGS) /W1
!endif

# Security hardening: Control Flow Guard.
!if "$(HARDENING)" == "1"
CFLAGS = $(CFLAGS) /guard:cf
!endif

# C4127: conditional expression is constant
# this generates a false warning inside asserts
# C4130: '!=': logical operation on address of string constant:
Expand Down Expand Up @@ -580,6 +586,11 @@ ALIBS = libxml2s.lib $(LIBS)
LDFLAGS = $(LDFLAGS) /WX
!endif

# Security hardening: Control Flow Guard, ASLR, and DEP.
!if "$(HARDENING)" == "1"
LDFLAGS = $(LDFLAGS) /guard:cf /DYNAMICBASE /NXCOMPAT
!endif

# Enable memcheck.
!if "$(MEMCHECK)" == "asan"
LDFLAGS = $(LDFLAGS) /fsanitize=address
Expand Down
5 changes: 5 additions & 0 deletions win32/configure.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,7 @@ $script:buildUnicode = 1
$script:buildDebug = 0
$script:buildWithMemcheck = "no"
$script:buildPedantic = 1
$script:buildHardening = 1
$script:buildCc = "cl.exe"
$script:buildCflags = ""
$script:buildStatic = 1
Expand Down Expand Up @@ -120,6 +121,7 @@ function Show-Usage {
Write-Host " memcheck: Build unoptimised debug executables with memcheck reporting (default: '$($script:buildWithMemcheck)')"
Write-Host " with possible options: 'yes'/'leaks', 'asan', or 'no'."
Write-Host " pedantic: Build with more warnings enabled (default: '$(if ($script:buildPedantic) { 'yes' } else { 'no' })')"
Write-Host " hardening: Build with security hardening flags: /guard:cf, /DYNAMICBASE, and /NXCOMPAT (default: '$(if ($script:buildHardening) { 'yes' } else { 'no' })')"
Write-Host " cc: Build with the specified compiler (default: '$($script:buildCc)')"
Write-Host " cflags: Build with the specified compiler flags (default: '$($script:buildCflags)')"
Write-Host " static: Build static xmlsec libraries (default: '$(if ($script:buildStatic) { 'yes' } else { 'no' })')"
Expand Down Expand Up @@ -221,6 +223,7 @@ function DiscoverVersion {
$lines += "DEBUG=$(if ($script:buildDebug) { '1' } else { '0' })"
$lines += "MEMCHECK=$($script:buildWithMemcheck)"
$lines += "PEDANTIC=$(if ($script:buildPedantic) { '1' } else { '0' })"
$lines += "HARDENING=$(if ($script:buildHardening) { '1' } else { '0' })"
$lines += "CC=$($script:buildCc)"
$lines += "CFLAGS=$($script:buildCflags)"
$lines += "STATIC=$(if ($script:buildStatic) { '1' } else { '0' })"
Expand Down Expand Up @@ -336,6 +339,7 @@ for ($i = 0; ($i -lt $args.Count) -and ($script:errorFlag -eq 0); $i++) {
}
}
"pedantic" { $script:buildPedantic = StrToBool $val "pedantic" }
"hardening" { $script:buildHardening = StrToBool $val "hardening" }
"cc" { $script:buildCc = $val }
"cflags" { $script:buildCflags = $val }
"static" { $script:buildStatic = StrToBool $val "static" }
Expand Down Expand Up @@ -470,6 +474,7 @@ Write-Host ""
Write-Host "Win32 build configuration"
Write-Host "-------------------------"
Write-Host " Pedantic: $(BoolToStr $script:buildPedantic)"
Write-Host " Hardening: $(BoolToStr $script:buildHardening)"
Write-Host " C compiler: $($script:buildCc)"
Write-Host " C compiler flags: $($script:buildCflags)"
Write-Host " C-Runtime option: $($script:cruntime)"
Expand Down
Loading