[glibc/release/2.38/master] i386: Fail if configured with --enable-cet

H.J. Lu hjl@sourceware.org
Wed Aug 20 01:23:21 GMT 2025


https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=16c478bc2891c739951b4811b06ec6c29afd6c49

commit 16c478bc2891c739951b4811b06ec6c29afd6c49
Author: Adhemerval Zanella <adhemerval.zanella@linaro.org>
Date:   Fri Jan 5 10:41:03 2024 -0300

    i386: Fail if configured with --enable-cet
    
    Since it is only supported for x86_64.
    
    Checked on i686-linux-gnu.
    
    (cherry picked from commit a0cfc48e8a67506e3f0b2d3ea5e04b45408b3683)

Diff:
---
 INSTALL                   | 3 +--
 NEWS                      | 4 ++--
 manual/install.texi       | 3 +--
 sysdeps/i386/configure    | 8 ++++----
 sysdeps/i386/configure.ac | 7 ++++---
 5 files changed, 12 insertions(+), 13 deletions(-)

diff --git a/INSTALL b/INSTALL
index d583ca7b44..4365d909a2 100644
--- a/INSTALL
+++ b/INSTALL
@@ -147,8 +147,7 @@ if ‘CFLAGS’ is specified it must enable optimization.  For example:
      ‘--enable-cet=permissive’, CET is disabled when dlopening a non CET
      enabled shared library in CET enabled application.
 
-     NOTE: ‘--enable-cet’ has been tested for x86_64 and x32 on non-CET
-     and CET processors.
+     NOTE: ‘--enable-cet’ is only supported on x86_64 and x32.
 
 ‘--enable-memory-tagging’
      Enable memory tagging support if the architecture supports it.
diff --git a/NEWS b/NEWS
index 65b5903622..77e89c9619 100644
--- a/NEWS
+++ b/NEWS
@@ -7,8 +7,8 @@ using `glibc' in the "product" field.
 

 Version 2.38.1
 
-* Sync with Linux kernel 6.6 shadow stack interface.  Since only x86-64
-  is supported, --enable-cet is ignored for i386.
+* Sync with Linux kernel 6.6 shadow stack interface.  The --enable-cet
+  configure option in only supported on x86-64.
 
 Deprecated and removed features, and other changes affecting compatibility:
 
diff --git a/manual/install.texi b/manual/install.texi
index 2af7f35c4e..479a49c7dc 100644
--- a/manual/install.texi
+++ b/manual/install.texi
@@ -175,8 +175,7 @@ enabled shared library in CET enabled application.  With
 @option{--enable-cet=permissive}, CET is disabled when dlopening a
 non CET enabled shared library in CET enabled application.
 
-NOTE: @option{--enable-cet} has been tested for x86_64 and x32
-on non-CET and CET processors.
+NOTE: @option{--enable-cet} is only supported on x86_64 and x32.
 
 @item --enable-memory-tagging
 Enable memory tagging support if the architecture supports it.  When
diff --git a/sysdeps/i386/configure b/sysdeps/i386/configure
index cd63d314fa..84656cef6e 100644
--- a/sysdeps/i386/configure
+++ b/sysdeps/i386/configure
@@ -1,10 +1,10 @@
 # This file is generated from configure.ac by Autoconf.  DO NOT EDIT!
  # Local configure fragment for sysdeps/i386.
 
-# CET is only supported for x86-64.  Set enable-cet to "no" to allow
-# "ifneq ($(enable-cet),no)" in x86 Makefiles.
-config_vars="$config_vars
-enable-cet = "no""
+# CET is only supported for x86-64.
+if test $enable_cet != no; then
+  as_fn_error $? "\"CET is only supported on x86_64 or x32\"" "$LINENO" 5
+fi
 
 # We no longer support i386 since it lacks the atomic instructions
 # required to implement NPTL threading.
diff --git a/sysdeps/i386/configure.ac b/sysdeps/i386/configure.ac
index b7d9436557..7f68e6210a 100644
--- a/sysdeps/i386/configure.ac
+++ b/sysdeps/i386/configure.ac
@@ -1,9 +1,10 @@
 GLIBC_PROVIDES dnl See aclocal.m4 in the top level source directory.
 # Local configure fragment for sysdeps/i386.
 
-# CET is only supported for x86-64.  Set enable-cet to "no" to allow
-# "ifneq ($(enable-cet),no)" in x86 Makefiles.
-LIBC_CONFIG_VAR([enable-cet], ["no"])
+# CET is only supported for x86-64.
+if test $enable_cet != no; then
+  AC_MSG_ERROR(["CET is only supported on x86_64 or x32"])
+fi
 
 # We no longer support i386 since it lacks the atomic instructions
 # required to implement NPTL threading.


More information about the Glibc-cvs mailing list