#!/bin/bash

# Copyright (c) 2026 Red Hat.
#
# This is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License as published
# by the Free Software Foundation; either version 3, or (at your
# option) any later version.
#
# It is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.

# Test that annocheck detects the presence/absence of GNU RELRO via --test-gnu-relro

TEST_NAME=relro
. $srcdir/common.sh

PLUGIN_OPTS="-fplugin-arg-annobin-no-attach"
OPTS="-O2 -D_FORTIFY_SOURCE=2 -fPIE -Wall -fstack-protector-strong -D_GLIBCXX_ASSERTIONS -fstack-clash-protection"

start_test

# Compile test object files
$GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello.c && \
    $GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello2.c && \
    $GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello3.c && \
    $GCC -fplugin=$PLUGIN $PLUGIN_OPTS -c $OPTS $srcdir/hello_lib.c

if [ $? != 0 ];
then
    echo " $TEST_NAME: SKIP: unable to compile test files"
    end_test
    exit $EXIT_TEST_SKIPPED
fi

SKIPS="--skip-all --test-gnu-relro --suppress-version-warnings"
A_OUT=relro-test.out

# Part 1: Link with -z relro (RELRO enabled) - should PASS
EXE=relro-pass.exe

$GCC hello.o hello2.o hello3.o hello_lib.o -pie -Wl,-z,now,-z,relro -o $EXE > $G_OUT 2>&1
if [ $? != 0 ];
then
    echo " $TEST_NAME: SKIP: unable to link test executable with -z relro"
    cat $G_OUT
    end_test
    exit $EXIT_TEST_SKIPPED
fi

# Verify the RELRO segment is actually present
$READELF -l $EXE 2>/dev/null | grep -q GNU_RELRO
if [ $? != 0 ];
then
    echo " $TEST_NAME: SKIP: linked binary does not contain a GNU_RELRO segment"
    end_test
    exit $EXIT_TEST_SKIPPED
fi

A_COMMAND="$ANNOCHECK $EXE $SKIPS --verbose"
$A_COMMAND > $A_OUT

grep -q -e"PASS: gnu-relro test" $A_OUT
if [ $? != 0 ];
then
    echo " $TEST_NAME: FAIL: annocheck did not PASS for binary linked with -z relro"
    echo " $TEST_NAME: annocheck output:"
    cat $A_OUT
    end_test
    exit $EXIT_TEST_FAILED
fi

echo " $TEST_NAME: PASS: annocheck correctly passed a binary with GNU RELRO"

#------------------------------------------------------------------------------------

# Part 2: Link with -z norelro (RELRO disabled) - should FAIL
EXE=relro-fail.exe

$GCC hello.o hello2.o hello3.o hello_lib.o -pie -Wl,-z,now,-z,norelro -o $EXE > $G_OUT 2>&1
if [ $? != 0 ];
then
    echo " $TEST_NAME: SKIP: unable to link test executable with -z norelro"
    cat $G_OUT
    end_test
    exit $EXIT_TEST_SKIPPED
fi

A_COMMAND="$ANNOCHECK $EXE $SKIPS --verbose"
$A_COMMAND > $A_OUT

grep -q -e"FAIL: gnu-relro test" $A_OUT
if [ $? != 0 ];
then
    echo " $TEST_NAME: FAIL: annocheck did not detect missing RELRO in a -z norelro binary"
    echo " $TEST_NAME: annocheck output:"
    cat $A_OUT
    end_test
    exit $EXIT_TEST_FAILED
fi

echo " $TEST_NAME: PASS: annocheck detected missing RELRO in a -z norelro binary"

end_test
