What changed, and why it matters
This commit simply moves Bitcoin Core's release-packaging shell code from one file into a new, separate file so it can be reused by other build scripts. No security-sensitive behavior was added, removed, or meaningfully changed. It is a routine build-system refactoring.
No security action needed; review as normal build-system refactoring if desired.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The change refactors contrib/guix/libexec/build.sh by extracting the packaging logic (splitting debug symbols, copying documentation, creating tarballs/zip files, codesigning preparation, and SHA256SUMS.part generation) into a new contrib/guix/libexec/package.sh. build.sh now sources package.sh. setup.sh gains an exported INSTALLPATH variable that was previously defined inside build.sh. The packaging commands and their order are preserved verbatim; only file organization and variable export placement changed.
Changed components
contrib/guix/libexec/build.shcontrib/guix/libexec/package.shcontrib/guix/libexec/setup.shInspect captured patch +136 / −122
diff --git a/contrib/guix/libexec/build.sh b/contrib/guix/libexec/build.sh
index d77bc5aa..000b4901 100755
--- a/contrib/guix/libexec/build.sh
+++ b/contrib/guix/libexec/build.sh
@@ -184,7 +184,6 @@ mkdir -p "$DISTSRC"
# Setup the directory where our Bitcoin Core build for HOST will be
# installed. This directory will also later serve as the input for our
# binary tarballs.
- INSTALLPATH="${PWD}/installed/${DISTNAME}"
mkdir -p "${INSTALLPATH}"
# Install built Bitcoin Core to $INSTALLPATH
case "$HOST" in
@@ -202,126 +201,7 @@ mkdir -p "$DISTSRC"
# Check that executables only contain allowed version symbols.
echo "Running symbol and dynamic library checks on installed executables..."
python3 "${DISTSRC}/contrib/guix/symbol-check.py" "${INSTALLPATH}/bin/"* "${INSTALLPATH}/libexec/"*
-
- (
- cd installed
-
- case "$HOST" in
- *darwin*) ;;
- *)
- # Split binaries from their debug symbols
- {
- find "${DISTNAME}/bin" "${DISTNAME}/libexec" -type f -executable -print0
- } | xargs -0 -P"$JOBS" -I{} "${DISTSRC}/build/split-debug.sh" {} {} {}.dbg
- ;;
- esac
-
- case "$HOST" in
- *mingw*)
- cp "${DISTSRC}/doc/README_windows.txt" "${DISTNAME}/readme.txt"
- ;;
- *linux*)
- cp "${DISTSRC}/README.md" "${DISTNAME}/"
- cp "${DISTSRC}/doc/INSTALL_linux.md" "${DISTNAME}/INSTALL.md"
- ;;
- esac
-
- # copy over the example bitcoin.conf file. if contrib/devtools/gen-bitcoin-conf.sh
- # has not been run before buildling, this file will be a stub
- cp "${DISTSRC}/share/examples/bitcoin.conf" "${DISTNAME}/"
-
- cp -r "${DISTSRC}/share/rpcauth" "${DISTNAME}/share/"
-
- # Deterministically produce {non-,}debug binary tarballs ready
- # for release
- case "$HOST" in
- *mingw*)
- find "${DISTNAME}" -not -name "*.dbg" -print0 \
- | xargs -0r touch --no-dereference --date="@${SOURCE_DATE_EPOCH}"
- find "${DISTNAME}" -not -name "*.dbg" \
- | sort \
- | zip -X@ "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-unsigned.zip" \
- || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-unsigned.zip" && exit 1 )
- find "${DISTNAME}" -name "*.dbg" -print0 \
- | xargs -0r touch --no-dereference --date="@${SOURCE_DATE_EPOCH}"
- find "${DISTNAME}" -name "*.dbg" \
- | sort \
- | zip -X@ "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-debug.zip" \
- || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-debug.zip" && exit 1 )
- ;;
- *linux*)
- find "${DISTNAME}" -not -name "*.dbg" -print0 \
- | sort --zero-terminated \
- | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
- | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}.tar.gz" \
- || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}.tar.gz" && exit 1 )
- find "${DISTNAME}" -name "*.dbg" -print0 \
- | sort --zero-terminated \
- | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
- | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}-debug.tar.gz" \
- || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}-debug.tar.gz" && exit 1 )
- ;;
- *darwin*)
- find "${DISTNAME}" -print0 \
- | sort --zero-terminated \
- | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
- | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}-unsigned.tar.gz" \
- || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}-unsigned.tar.gz" && exit 1 )
- ;;
- esac
- ) # $DISTSRC/installed
-
- # Finally make tarballs for codesigning
- case "$HOST" in
- *mingw*)
- cp -rf --target-directory=. contrib/windeploy
- (
- cd ./windeploy
- mkdir -p unsigned
- cp --target-directory=unsigned/ "${OUTDIR}/${DISTNAME}-win64-setup-unsigned.exe"
- cp -r --target-directory=unsigned/ "${INSTALLPATH}"
- find unsigned/ -name "*.dbg" -print0 \
- | xargs -0r rm
- find . -print0 \
- | sort --zero-terminated \
- | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
- | gzip -9n > "${OUTDIR}/${DISTNAME}-win64-codesigning.tar.gz" \
- || ( rm -f "${OUTDIR}/${DISTNAME}-win64-codesigning.tar.gz" && exit 1 )
- )
- ;;
- *darwin*)
- cmake --build build --target deploy ${V:+--verbose}
- mv build/dist/bitcoin-macos-app.zip "${OUTDIR}/${DISTNAME}-${HOST}-unsigned.zip"
- mkdir -p "unsigned-app-${HOST}"
- cp --target-directory="unsigned-app-${HOST}" \
- contrib/macdeploy/detached-sig-create.sh
- mv --target-directory="unsigned-app-${HOST}" build/dist
- cp -r --target-directory="unsigned-app-${HOST}" "${INSTALLPATH}"
- (
- cd "unsigned-app-${HOST}"
- find . -print0 \
- | sort --zero-terminated \
- | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
- | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}-codesigning.tar.gz" \
- || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}-codesigning.tar.gz" && exit 1 )
- )
- ;;
- esac
) # $DISTSRC
-rm -rf "$ACTUAL_OUTDIR"
-mv --no-target-directory "$OUTDIR" "$ACTUAL_OUTDIR" \
- || ( rm -rf "$ACTUAL_OUTDIR" && exit 1 )
-
-(
- tmp="$(mktemp)"
- cd /outdir-base
- {
- echo "$GIT_ARCHIVE"
- find "$ACTUAL_OUTDIR" -type f
- } | xargs realpath --relative-base="$PWD" \
- | xargs sha256sum \
- | sort -k2 \
- > "$tmp";
- mv "$tmp" "$ACTUAL_OUTDIR"/SHA256SUMS.part
-)
+# shellcheck source=package.sh
+source "$(dirname "${BASH_SOURCE[0]}")/package.sh"
diff --git a/contrib/guix/libexec/package.sh b/contrib/guix/libexec/package.sh
new file mode 100755
index 00000000..56bd957e
--- /dev/null
+++ b/contrib/guix/libexec/package.sh
@@ -0,0 +1,133 @@
+#!/usr/bin/env bash
+# Copyright (c) The Bitcoin Core developers
+# Distributed under the MIT software license, see the accompanying
+# file COPYING or https://opensource.org/license/mit.
+export LC_ALL=C
+set -e -o pipefail
+
+(
+ cd "$DISTSRC"
+
+ (
+ cd installed
+
+ case "$HOST" in
+ *darwin*) ;;
+ *)
+ # Split binaries from their debug symbols
+ {
+ find "${DISTNAME}/bin" "${DISTNAME}/libexec" -type f -executable -print0
+ } | xargs -0 -P"$JOBS" -I{} "${DISTSRC}/build/split-debug.sh" {} {} {}.dbg
+ ;;
+ esac
+
+ case "$HOST" in
+ *mingw*)
+ cp "${DISTSRC}/doc/README_windows.txt" "${DISTNAME}/readme.txt"
+ ;;
+ *linux*)
+ cp "${DISTSRC}/README.md" "${DISTNAME}/"
+ cp "${DISTSRC}/doc/INSTALL_linux.md" "${DISTNAME}/INSTALL.md"
+ ;;
+ esac
+
+ # copy over the example bitcoin.conf file. if contrib/devtools/gen-bitcoin-conf.sh
+ # has not been run before buildling, this file will be a stub
+ cp "${DISTSRC}/share/examples/bitcoin.conf" "${DISTNAME}/"
+
+ cp -r "${DISTSRC}/share/rpcauth" "${DISTNAME}/share/"
+
+ # Deterministically produce {non-,}debug binary tarballs ready
+ # for release
+ case "$HOST" in
+ *mingw*)
+ find "${DISTNAME}" -not -name "*.dbg" -print0 \
+ | xargs -0r touch --no-dereference --date="@${SOURCE_DATE_EPOCH}"
+ find "${DISTNAME}" -not -name "*.dbg" \
+ | sort \
+ | zip -X@ "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-unsigned.zip" \
+ || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-unsigned.zip" && exit 1 )
+ find "${DISTNAME}" -name "*.dbg" -print0 \
+ | xargs -0r touch --no-dereference --date="@${SOURCE_DATE_EPOCH}"
+ find "${DISTNAME}" -name "*.dbg" \
+ | sort \
+ | zip -X@ "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-debug.zip" \
+ || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST//x86_64-w64-mingw32/win64}-debug.zip" && exit 1 )
+ ;;
+ *linux*)
+ find "${DISTNAME}" -not -name "*.dbg" -print0 \
+ | sort --zero-terminated \
+ | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
+ | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}.tar.gz" \
+ || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}.tar.gz" && exit 1 )
+ find "${DISTNAME}" -name "*.dbg" -print0 \
+ | sort --zero-terminated \
+ | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
+ | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}-debug.tar.gz" \
+ || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}-debug.tar.gz" && exit 1 )
+ ;;
+ *darwin*)
+ find "${DISTNAME}" -print0 \
+ | sort --zero-terminated \
+ | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
+ | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}-unsigned.tar.gz" \
+ || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}-unsigned.tar.gz" && exit 1 )
+ ;;
+ esac
+ ) # $DISTSRC/installed
+
+ # Finally make tarballs for codesigning
+ case "$HOST" in
+ *mingw*)
+ cp -rf --target-directory=. contrib/windeploy
+ (
+ cd ./windeploy
+ mkdir -p unsigned
+ cp --target-directory=unsigned/ "${OUTDIR}/${DISTNAME}-win64-setup-unsigned.exe"
+ cp -r --target-directory=unsigned/ "${INSTALLPATH}"
+ find unsigned/ -name "*.dbg" -print0 \
+ | xargs -0r rm
+ find . -print0 \
+ | sort --zero-terminated \
+ | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
+ | gzip -9n > "${OUTDIR}/${DISTNAME}-win64-codesigning.tar.gz" \
+ || ( rm -f "${OUTDIR}/${DISTNAME}-win64-codesigning.tar.gz" && exit 1 )
+ )
+ ;;
+ *darwin*)
+ cmake --build build --target deploy ${V:+--verbose}
+ mv build/dist/bitcoin-macos-app.zip "${OUTDIR}/${DISTNAME}-${HOST}-unsigned.zip"
+ mkdir -p "unsigned-app-${HOST}"
+ cp --target-directory="unsigned-app-${HOST}" \
+ contrib/macdeploy/detached-sig-create.sh
+ mv --target-directory="unsigned-app-${HOST}" build/dist
+ cp -r --target-directory="unsigned-app-${HOST}" "${INSTALLPATH}"
+ (
+ cd "unsigned-app-${HOST}"
+ find . -print0 \
+ | sort --zero-terminated \
+ | tar --create --no-recursion --mode='u+rw,go+r-w,a+X' --null --files-from=- \
+ | gzip -9n > "${OUTDIR}/${DISTNAME}-${HOST}-codesigning.tar.gz" \
+ || ( rm -f "${OUTDIR}/${DISTNAME}-${HOST}-codesigning.tar.gz" && exit 1 )
+ )
+ ;;
+ esac
+
+) # $DISTSRC
+
+rm -rf "$ACTUAL_OUTDIR"
+mv --no-target-directory "$OUTDIR" "$ACTUAL_OUTDIR" \
+ || ( rm -rf "$ACTUAL_OUTDIR" && exit 1 )
+
+(
+ tmp="$(mktemp)"
+ cd /outdir-base
+ {
+ echo "$GIT_ARCHIVE"
+ find "$ACTUAL_OUTDIR" -type f
+ } | xargs realpath --relative-base="$PWD" \
+ | xargs sha256sum \
+ | sort -k2 \
+ > "$tmp";
+ mv "$tmp" "$ACTUAL_OUTDIR"/SHA256SUMS.part
+)
diff --git a/contrib/guix/libexec/setup.sh b/contrib/guix/libexec/setup.sh
index 617a7327..37388f98 100755
--- a/contrib/guix/libexec/setup.sh
+++ b/contrib/guix/libexec/setup.sh
@@ -41,6 +41,7 @@ EOF
export ACTUAL_OUTDIR="${OUTDIR}"
export OUTDIR="${DISTSRC}/output"
+export INSTALLPATH="${DISTSRC}/installed/${DISTNAME}"
#####################
# Environment Setup #
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.