Harden build and injection shell scripts

This commit is contained in:
√(noham)²
2026-08-25 23:40:08 +02:00
parent b672c6596f
commit b7f27b1671
3 changed files with 89 additions and 67 deletions

View File

@@ -3,10 +3,25 @@ set -euo pipefail
# Builds shadowhook as a static library for Android arm64.
# Produces: libs/libshadowhook.a and libs/libshadowhook_nothing.so
#
# Skips the build entirely if both outputs already exist. Set FORCE_REBUILD=1
# to rebuild anyway (e.g. after changing CFLAGS, the toolchain, or the
# shadowhook sources themselves).
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
PROJECT_DIR="$(dirname "$SCRIPT_DIR")"
BUILD_DIR="$PROJECT_DIR/build/deps"
OUT_DIR="$SCRIPT_DIR"
SH="$SCRIPT_DIR/shadowhook/shadowhook/src/main/cpp"
if [ "${FORCE_REBUILD:-0}" != "1" ] \
&& [ -f "$OUT_DIR/libshadowhook.a" ] \
&& [ -f "$OUT_DIR/libshadowhook_nothing.so" ]; then
echo "=== shadowhook already built, skipping (FORCE_REBUILD=1 to rebuild) ==="
exit 0
fi
mkdir -p "$BUILD_DIR"
# --- Auto-detect Android NDK (same logic as build.sh) ---
@@ -47,81 +62,67 @@ TOOLCHAIN_DIR="$(dirname "$CC")"
AR="$TOOLCHAIN_DIR/llvm-ar"
CFLAGS="-O2 -ffunction-sections -fdata-sections -fPIC -DANDROID -Wall -Wextra -Wno-unused-parameter -Wno-unused-function"
OUT_DIR="$SCRIPT_DIR"
SH_SRCS=(
"$SH/sh_elf.c"
"$SH/sh_enter.c"
"$SH/sh_hub.c"
"$SH/sh_island.c"
"$SH/sh_linker.c"
"$SH/sh_recorder.c"
"$SH/sh_safe.c"
"$SH/sh_switch.c"
"$SH/sh_task.c"
"$SH/sh_xdl.c"
"$SH/shadowhook.c"
"$SH/arch/arm64/sh_a64.c"
"$SH/arch/arm64/sh_inst.c"
"$SH/arch/arm64/sh_glue.S"
"$SH/common/bytesig.c"
"$SH/common/sh_errno.c"
"$SH/common/sh_log.c"
"$SH/common/sh_ref.c"
"$SH/common/sh_trampo.c"
"$SH/common/sh_util.c"
"$SH/third_party/xdl/xdl.c"
"$SH/third_party/xdl/xdl_iterate.c"
"$SH/third_party/xdl/xdl_linker.c"
"$SH/third_party/xdl/xdl_lzma.c"
"$SH/third_party/xdl/xdl_util.c"
)
SH_INCLUDES=(
"-I$SH"
"-I$SH/include"
"-I$SH/arch/arm64"
"-I$SH/common"
"-I$SH/third_party/xdl"
"-I$SH/third_party/bsd"
"-I$SH/third_party/lss"
)
NOTHING_SRC="$SH/nothing/sh_nothing.c"
echo "=== Building shadowhook (arm64-v8a) ==="
SH="$SCRIPT_DIR/shadowhook/shadowhook/src/main/cpp"
SH_SRCS="
$SH/sh_elf.c
$SH/sh_enter.c
$SH/sh_hub.c
$SH/sh_island.c
$SH/sh_linker.c
$SH/sh_recorder.c
$SH/sh_safe.c
$SH/sh_switch.c
$SH/sh_task.c
$SH/sh_xdl.c
$SH/shadowhook.c
$SH/arch/arm64/sh_a64.c
$SH/arch/arm64/sh_inst.c
$SH/arch/arm64/sh_glue.S
$SH/common/bytesig.c
$SH/common/sh_errno.c
$SH/common/sh_log.c
$SH/common/sh_ref.c
$SH/common/sh_trampo.c
$SH/common/sh_util.c
$SH/third_party/xdl/xdl.c
$SH/third_party/xdl/xdl_iterate.c
$SH/third_party/xdl/xdl_linker.c
$SH/third_party/xdl/xdl_lzma.c
$SH/third_party/xdl/xdl_util.c
"
SH_INCLUDES="
-I$SH
-I$SH/include
-I$SH/arch/arm64
-I$SH/common
-I$SH/third_party/xdl
-I$SH/third_party/bsd
-I$SH/third_party/lss
"
SH_OBJS=""
for src in $SH_SRCS; do
[ -z "$src" ] && continue
src=$(echo "$src" | xargs)
SH_OBJS=()
for src in "${SH_SRCS[@]}"; do
if [ ! -f "$src" ]; then
echo "ERROR: shadowhook source not found: $src"
exit 1
fi
basename=$(echo "$src" | sed "s|$SH/||" | tr '/' '_')
obj="$BUILD_DIR/sh_${basename%.c}.o"
obj="${obj%.S.o}.o"
rel="${src#"$SH"/}"
flat="$(echo "$rel" | tr '/' '_')"
obj="$BUILD_DIR/sh_${flat%.*}.o"
if [[ "$src" == *.S ]]; then
"$CC" $CFLAGS $SH_INCLUDES -c "$src" -o "$obj"
else
"$CC" $CFLAGS $SH_INCLUDES -c "$src" -o "$obj"
fi
SH_OBJS="$SH_OBJS $obj"
"$CC" $CFLAGS "${SH_INCLUDES[@]}" -c "$src" -o "$obj"
SH_OBJS+=("$obj")
done
if [ -z "$SH_OBJS" ]; then
echo "ERROR: shadowhook produced no object files."
exit 1
fi
"$AR" rcs "$OUT_DIR/libshadowhook.a" $SH_OBJS
"$AR" rcs "$OUT_DIR/libshadowhook.a" "${SH_OBJS[@]}"
SH_SIZE=$(wc -c < "$OUT_DIR/libshadowhook.a" 2>/dev/null || echo "unknown")
echo " Built $OUT_DIR/libshadowhook.a ($SH_SIZE bytes)"
NOTHING_SRC="$SH/nothing/sh_nothing.c"
if [ ! -f "$NOTHING_SRC" ]; then
echo "ERROR: ShadowHook companion source not found: $NOTHING_SRC"
exit 1
@@ -133,4 +134,4 @@ fi
-Wl,--strip-all -Wl,--as-needed -Wl,--hash-style=sysv \
-Wl,--build-id=none \
-o "$OUT_DIR/libshadowhook_nothing.so" "$NOTHING_SRC"
echo " Built $OUT_DIR/libshadowhook_nothing.so"
echo " Built $OUT_DIR/libshadowhook_nothing.so"