guix: Update `python-signapple` and wrap with OpenSSL paths
What changed, and why it matters
This commit updates a build dependency called python-signapple, which is used to create and verify digital signatures on macOS Bitcoin binaries. It also adds environment variables so the tool can find OpenSSL libraries during the Guix reproducible build process. There is no direct evidence in the commit that this fixes an exploitable security flaw in Bitcoin Core itself; it appears to be a build tooling/maintenance change.
Treat as routine build maintenance. If reviewing for security, verify the upstream python-signapple changelog between commits 85bfcecc and 3fab3bb for any security-relevant fixes, and confirm the OpenSSL path wrapping does not introduce unexpected library loading behavior in the build.
Security signals we found
Dependency update (python-signapple) without stated security rationale
OpenSSL library path injection via environment variable wrapper
Build-time change only; no runtime Bitcoin Core code modified
Evidence from the diff
The change bumps the pinned python-signapple commit in contrib/guix/manifest.scm from 85bfcecc to 3fab3bb and updates the corresponding Guix sha256 hash. It also adds a new build phase ‘wrap-openssl-paths’ that wraps the signapple binary with SIGNAPPLE_OSCRYPTO_SSL_PATHS pointing to libcrypto.so and libssl.so from the OpenSSL input. This likely addresses oscrypto’s need for explicit OpenSSL library paths, possibly because the newer signapple version or its dependency chain requires it. The diff does not describe a vulnerability, CVE, or security fix.
Changed components
contrib/guix/manifest.scmGuix reproducible build environmentpython-signapple package definitionInspect captured patch +15 / −5
diff --git a/contrib/guix/manifest.scm b/contrib/guix/manifest.scm
index 4fd901e5..bf2c346a 100644
--- a/contrib/guix/manifest.scm
+++ b/contrib/guix/manifest.scm
@@ -278,7 +278,7 @@ specific moment in time, whitelisting and revocation checks.")
(license license:expat))))
(define-public python-signapple
- (let ((commit "85bfcecc33d2773bc09bc318cec0614af2c8e287"))
+ (let ((commit "3fab3bb57f227f0dd31007b417683035f5204838"))
(package
(name "python-signapple")
(version (git-version "0.2.0" "1" commit))
@@ -291,7 +291,7 @@ specific moment in time, whitelisting and revocation checks.")
(file-name (git-file-name name commit))
(sha256
(base32
- "17yqjll8nw83q6dhgqhkl7w502z5vy9sln8m6mlx0f1c10isg8yg"))))
+ "0qpr78bs50rw79dbihr9ifjq19y6819ih5pn9jd2rbjyifimzf7p"))))
(build-system pyproject-build-system)
(propagated-inputs
(list python-asn1crypto
@@ -299,9 +299,19 @@ specific moment in time, whitelisting and revocation checks.")
python-certvalidator
python-elfesteem))
(native-inputs (list python-poetry-core))
- ;; There are no tests, but attempting to run python setup.py test leads to
- ;; problems, just disable the test
- (arguments '(#:tests? #f))
+ (arguments
+ ;; There are no tests, but attempting to run python setup.py test leads to
+ ;; problems, just disable the test
+ (list #:tests? #f
+ #:phases
+ #~(modify-phases %standard-phases
+ ;; Add a phase to inject OpenSSL paths for oscrypto.
+ (add-after 'wrap 'wrap-openssl-paths
+ (lambda* (#:key inputs #:allow-other-keys)
+ (let ((openssl (assoc-ref inputs "openssl")))
+ (wrap-program (string-append #$output "/bin/signapple")
+ `("SIGNAPPLE_OSCRYPTO_SSL_PATHS" =
+ (,(string-append openssl "/lib/libcrypto.so" "," openssl "/lib/libssl.so"))))))))))
(home-page "https://github.com/achow101/signapple")
(synopsis "Mach-O binary signature tool")
(description "signapple is a Python tool for creating, verifying, and
Why this scored 20/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.