What changed, and why it matters
This commit removes a build-time test that checked whether the Protobuf library could compile and link correctly for Trezor hardware wallet support. It does not change any runtime code that handles user funds, transactions, or network data. The change only affects the build system and removes a compile-time sanity check, so it is not a security vulnerability by itself.
No security action required. If removing the test causes build failures on some platforms to be detected later, consider reintroducing a lighter probe or improving CI coverage for Trezor builds.
Security signals we found
No runtime code changes
No cryptographic or transaction-handling changes
Build-system-only change
Removal of a compile-time sanity check, not a security control
Evidence from the diff
The commit deletes cmake/CheckTrezor.cmake logic that ran protoc on test-protobuf.proto, compiled the generated test-protobuf.pb.cc together with test-protobuf.cpp, and verified that the Protobuf library linked successfully. It also deletes the two test files. The remaining build still compiles the real Trezor .proto files later in the same CMake module, so functional Trezor support is unchanged; only the early compile/link probe is removed.
Changed components
cmake/CheckTrezor.cmakecmake/test-protobuf.cppcmake/test-protobuf.protoInspect captured patch +0 / −91
diff --git a/cmake/CheckTrezor.cmake b/cmake/CheckTrezor.cmake
index effeac8..063d9ff 100644
--- a/cmake/CheckTrezor.cmake
+++ b/cmake/CheckTrezor.cmake
@@ -80,45 +80,6 @@ else()
message(STATUS "Trezor: support disabled by USE_DEVICE_TREZOR")
endif()
-# Protobuf compilation test
-if(Protobuf_FOUND AND USE_DEVICE_TREZOR)
- execute_process(COMMAND ${Protobuf_PROTOC_EXECUTABLE} -I "${CMAKE_CURRENT_LIST_DIR}" -I "${Protobuf_INCLUDE_DIR}" "${CMAKE_CURRENT_LIST_DIR}/test-protobuf.proto" --cpp_out ${CMAKE_BINARY_DIR} RESULT_VARIABLE RET OUTPUT_VARIABLE OUT ERROR_VARIABLE ERR)
- if(RET)
- trezor_fatal_msg("Trezor: Protobuf test generation failed: ${OUT} ${ERR}")
- endif()
-
- if(ANDROID)
- set(CMAKE_TRY_COMPILE_LINKER_FLAGS "${CMAKE_TRY_COMPILE_LINKER_FLAGS} -llog")
- set(CMAKE_TRY_COMPILE_LINK_LIBRARIES "${CMAKE_TRY_COMPILE_LINK_LIBRARIES} log")
- endif()
-
- if(USE_DEVICE_TREZOR_PROTOBUF_TEST)
- if(PROTOBUF_LDFLAGS)
- set(PROTOBUF_TRYCOMPILE_LINKER "${PROTOBUF_LDFLAGS}")
- else()
- set(PROTOBUF_TRYCOMPILE_LINKER "${Protobuf_LIBRARY}")
- endif()
-
- try_compile(Protobuf_COMPILE_TEST_PASSED
- "${CMAKE_BINARY_DIR}"
- SOURCES
- "${CMAKE_BINARY_DIR}/test-protobuf.pb.cc"
- "${CMAKE_CURRENT_LIST_DIR}/test-protobuf.cpp"
- CMAKE_FLAGS
- CMAKE_EXE_LINKER_FLAGS ${CMAKE_TRY_COMPILE_LINKER_FLAGS}
- "-DINCLUDE_DIRECTORIES=${Protobuf_INCLUDE_DIR};${CMAKE_BINARY_DIR}"
- "-DCMAKE_CXX_STANDARD=${CMAKE_CXX_STANDARD}"
- LINK_LIBRARIES "${PROTOBUF_TRYCOMPILE_LINKER}" ${CMAKE_TRY_COMPILE_LINK_LIBRARIES}
- OUTPUT_VARIABLE OUTPUT
- )
- if(NOT Protobuf_COMPILE_TEST_PASSED)
- trezor_fatal_msg("Trezor: Protobuf Compilation test failed: ${OUTPUT}.")
- endif()
- else ()
- message(STATUS "Trezor: Protobuf Compilation test skipped, build may fail later")
- endif()
-endif()
-
# Try to build protobuf messages
if(Protobuf_FOUND AND USE_DEVICE_TREZOR)
# .proto files to compile
diff --git a/cmake/test-protobuf.cpp b/cmake/test-protobuf.cpp
deleted file mode 100644
index 8d77964..0000000
--- a/cmake/test-protobuf.cpp
+++ /dev/null
@@ -1,45 +0,0 @@
-// Copyright (c) 2014-2024, The Monero Project
-//
-// All rights reserved.
-//
-// Redistribution and use in source and binary forms, with or without modification, are
-// permitted provided that the following conditions are met:
-//
-// 1. Redistributions of source code must retain the above copyright notice, this list of
-// conditions and the following disclaimer.
-//
-// 2. Redistributions in binary form must reproduce the above copyright notice, this list
-// of conditions and the following disclaimer in the documentation and/or other
-// materials provided with the distribution.
-//
-// 3. Neither the name of the copyright holder nor the names of its contributors may be
-// used to endorse or promote products derived from this software without specific
-// prior written permission.
-//
-// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY
-// EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
-// MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
-// THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
-// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
-// PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
-// INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
-// STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
-// THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
-
-#include <string>
-#include <iostream>
-#include <google/protobuf/message.h>
-#include <google/protobuf/unknown_field_set.h>
-#include "test-protobuf.pb.h"
-
-int main(int argc, char *argv[]) {
- google::protobuf::UnknownFieldSet ufs;
- ufs.ClearAndFreeMemory();
-
- Success sc;
- sc.set_message("test");
- if (!sc.SerializeToOstream(&std::cerr)) {
- return -1;
- }
- return 0;
-}
diff --git a/cmake/test-protobuf.proto b/cmake/test-protobuf.proto
deleted file mode 100644
index 5300aea..0000000
--- a/cmake/test-protobuf.proto
+++ /dev/null
@@ -1,7 +0,0 @@
-syntax = "proto2";
-
-import "google/protobuf/descriptor.proto";
-
-message Success {
- optional string message = 1;
-}
Why this scored 12/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.