ci: Rewrite broken wrap-valgrind.sh to .py
What changed, and why it matters
This commit rewrites a CI helper script from Bash to Python. The script is only used in Bitcoin Core's automated testing environment to wrap test executables with Valgrind, a memory-error detection tool. There is no change to the Bitcoin software that users run, no network-facing code is affected, and no security vulnerability is fixed or introduced.
No security action required. Treat as a normal CI maintenance/refactoring commit.
Security signals we found
No security-relevant code change in the diff
Change is confined to CI/test helper tooling
No change to consensus, networking, wallet, or RPC code
No input parsing of untrusted data
Evidence from the diff
The change deletes ci/test/wrap-valgrind.sh and adds ci/test/wrap-valgrind.py, updating 03_test_script.sh to invoke the new Python script. Functionality is equivalent: it iterates over built binaries in BASE_OUTDIR/bin, finds matching executable files under BASE_ROOT_DIR, renames each to
Changed components
ci/test/03_test_script.shci/test/wrap-valgrind.pyci/test/wrap-valgrind.shInspect captured patch +33 / −19
diff --git a/ci/test/03_test_script.sh b/ci/test/03_test_script.sh
index b3ab1729..5ecbe863 100755
--- a/ci/test/03_test_script.sh
+++ b/ci/test/03_test_script.sh
@@ -168,7 +168,7 @@ if [ -n "${CI_LIMIT_STACK_SIZE}" ]; then
fi
if [ -n "$USE_VALGRIND" ]; then
- "${BASE_ROOT_DIR}/ci/test/wrap-valgrind.sh"
+ "${BASE_ROOT_DIR}/ci/test/wrap-valgrind.py"
fi
if [ "$RUN_CHECK_DEPS" = "true" ]; then
diff --git a/ci/test/wrap-valgrind.py b/ci/test/wrap-valgrind.py
new file mode 100755
index 00000000..6a79f2aa
--- /dev/null
+++ b/ci/test/wrap-valgrind.py
@@ -0,0 +1,32 @@
+#!/usr/bin/env python3
+# Copyright (c) The Bitcoin Core developers
+# Distributed under the MIT software license, see the accompanying
+# file COPYING or https://opensource.org/license/mit/.
+
+import os
+import shlex
+from pathlib import Path
+
+
+def main():
+ base_root = Path(os.environ["BASE_ROOT_DIR"])
+ base_out = Path(os.environ["BASE_OUTDIR"])
+ suppressions_file = base_root / "test" / "sanitizer_suppressions" / "valgrind.supp"
+ target_names = {b.name for b in (base_out / "bin").iterdir()}
+
+ for exe in base_root.rglob("*"):
+ if exe.name in target_names and exe.is_file() and os.access(exe, os.X_OK):
+ print(f"Wrap {exe} ...")
+ original_path = exe.with_name(f"{exe.name}_orig")
+ exe.rename(original_path)
+ exe.write_text(
+ "#!/usr/bin/env bash\n"
+ "exec valgrind --gen-suppressions=all --quiet --error-exitcode=1 "
+ f"--suppressions={shlex.quote(str(suppressions_file))} "
+ f'{shlex.quote(str(original_path))} "$@"\n'
+ )
+ exe.chmod(exe.stat().st_mode | 0o111)
+
+
+if __name__ == "__main__":
+ main()
diff --git a/ci/test/wrap-valgrind.sh b/ci/test/wrap-valgrind.sh
deleted file mode 100755
index 4ed3f2d6..00000000
--- a/ci/test/wrap-valgrind.sh
+++ /dev/null
@@ -1,18 +0,0 @@
-#!/usr/bin/env bash
-#
-# Copyright (c) 2018-present The Bitcoin Core developers
-# Distributed under the MIT software license, see the accompanying
-# file COPYING or http://www.opensource.org/licenses/mit-license.php.
-
-export LC_ALL=C.UTF-8
-
-for b_name in "${BASE_OUTDIR}/bin"/*; do
- # shellcheck disable=SC2044
- for b in $(find "${BASE_ROOT_DIR}" -executable -type f -name "$(basename "$b_name")"); do
- echo "Wrap $b ..."
- mv "$b" "${b}_orig"
- echo '#!/usr/bin/env bash' > "$b"
- echo "exec valgrind --gen-suppressions=all --quiet --error-exitcode=1 --suppressions=${BASE_ROOT_DIR}/test/sanitizer_suppressions/valgrind.supp \"${b}_orig\" \"\$@\"" >> "$b"
- chmod +x "$b"
- done
-done
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.