What changed, and why it matters
This commit improves build reliability and supply-chain consistency for the Skylight Wallet. It switches the source of a key Monero-related library from a personal GitHub account (vtnerd) to the project's own organization (magicgrants), and it replaces a script that pinned the Rust compiler version for only the Tor plugin with a script that also pins the version for the OpenAlias plugin. There is no direct evidence of a security vulnerability being fixed; the changes are best described as hardening build reproducibility and reducing trust in an external repository.
Treat this as a build-hardening and supply-chain hygiene change rather than an urgent security patch. Verify that the magicgrants/monero_c fork matches the previously pinned commit and that reproducible build outputs are consistent. Continue normal dependency monitoring.
Security signals we found
Source repository changed for monero_c dependency (vtnerd -> magicgrants)
Build reproducibility hardening for Rust-based Flutter plugins
New script pins Rust toolchain for both tor_ffi_plugin and openalias_ffi
No direct vulnerability fix or cryptographic/authorization change present in diff
Evidence from the diff
The diff changes CI and build scripts to: (1) clone monero_c from https://github.com/magicgrants/monero_c instead of https://github.com/vtnerd/monero_c; (2) rename/replace scripts/pin-tor-rust-toolchain.sh with scripts/pin-rust-toolchain.sh, which now patches cargokit’s builder.dart in both the tor_ffi_plugin (PUB_CACHE) and openalias_ffi (in-repo PATH plugin) so both use a pinned Rust toolchain (default 1.96.1) instead of the moving ‘stable’ channel; and (3) update release.yml and fdroid-build.sh to call the new script. The stated goal is reproducible builds for openalias_ffi. No code-level vulnerability is patched in this commit.
Changed components
.github/workflows/build-monero-c.yml.github/workflows/release.ymlscripts/build-moneroc-ci.shscripts/fdroid-build.shscripts/pin-rust-toolchain.shscripts/pin-tor-rust-toolchain.shInspect captured patch +39 / −34
diff --git a/.github/workflows/build-monero-c.yml b/.github/workflows/build-monero-c.yml
index 9c3acb6..3c5fa0b 100644
--- a/.github/workflows/build-monero-c.yml
+++ b/.github/workflows/build-monero-c.yml
@@ -164,7 +164,7 @@ jobs:
git config --global --add safe.directory '*'
git config --global user.email "info@magicgrants.org"
git config --global user.name "MAGIC Grants"
- git clone https://github.com/vtnerd/monero_c.git /tmp/monero_c
+ git clone https://github.com/magicgrants/monero_c /tmp/monero_c
cd /tmp/monero_c
git checkout "$MONEROC_COMMIT"
git submodule update --init --recursive
@@ -351,7 +351,7 @@ jobs:
- `windows/libssp-0.dll` (x86_64-w64-mingw32)
- `ios/Frameworks/MoneroWallet.xcframework` (aarch64-apple-ios + aarch64-apple-iossimulator)
- Built from [monero_c](https://github.com/vtnerd/monero_c) at the commit pinned in `pubspec.lock`.
+ Built from [monero_c](https://github.com/magicgrants/monero_c) at the commit pinned in `pubspec.lock`.
To bump monero_c: edit the `monero` ref in `pubspec.yaml`, run `flutter pub get`, then re-run this workflow.
branch: update-moneroc-libs
delete-branch: true
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index e20e920..2d04a8c 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -150,7 +150,7 @@ jobs:
-w /tmp/skylight \
-e SOURCE_DATE_EPOCH \
ghcr.io/magicgrants/skylight-wallet-builder:latest \
- bash -c "cp -a /opt/cargo /tmp/skylight-cargo && export CARGO_HOME=/tmp/skylight-cargo && export PUB_CACHE=/tmp/skylight/.pub-cache && flutter pub get && bash scripts/pin-tor-rust-toolchain.sh && flutter build apk --dart-define=DEMO_MODE=true --release --split-per-abi && flutter build appbundle --dart-define=DEMO_MODE=true --release"
+ bash -c "cp -a /opt/cargo /tmp/skylight-cargo && export CARGO_HOME=/tmp/skylight-cargo && export PUB_CACHE=/tmp/skylight/.pub-cache && flutter pub get && bash scripts/pin-rust-toolchain.sh && flutter build apk --dart-define=DEMO_MODE=true --release --split-per-abi && flutter build appbundle --dart-define=DEMO_MODE=true --release"
mkdir -p dist
cp -v build/app/outputs/flutter-apk/app-arm64-v8a-release.apk "dist/skylight-wallet-${VERSION}-arm64-v8a.apk"
diff --git a/scripts/build-moneroc-ci.sh b/scripts/build-moneroc-ci.sh
index 6b8135c..f6cf377 100755
--- a/scripts/build-moneroc-ci.sh
+++ b/scripts/build-moneroc-ci.sh
@@ -21,5 +21,5 @@ REPO="$PWD"
# committed .so matches F-Droid's rebuild. Clones from the remote (this CI checkout has no
# populated submodule); then symlink output where build-monero-c.yml's cp step expects it.
rm -rf "$REPO/monero_c"
-bash scripts/build-moneroc.sh "$TARGET_ARCH" https://github.com/vtnerd/monero_c.git
+bash scripts/build-moneroc.sh "$TARGET_ARCH" https://github.com/magicgrants/monero_c
ln -s /tmp/monero_c "$REPO/monero_c"
\ No newline at end of file
diff --git a/scripts/fdroid-build.sh b/scripts/fdroid-build.sh
index 3f7167f..960ff31 100755
--- a/scripts/fdroid-build.sh
+++ b/scripts/fdroid-build.sh
@@ -58,7 +58,7 @@ export CARGO_HOME=/tmp/skylight-cargo
# cargokit requires an NDK package.xml (absent in unzipped NDKs)
[ -f "$ANDROID_HOME/ndk/$NDK/package.xml" ] || touch "$ANDROID_HOME/ndk/$NDK/package.xml"
"$FLUTTER/bin/flutter" pub get
-bash scripts/pin-tor-rust-toolchain.sh
+bash scripts/pin-rust-toolchain.sh
"$FLUTTER/bin/flutter" build apk --dart-define=DEMO_MODE=true --release --split-per-abi --target-platform="$PLATFORM"
# 3) Hand the APK to the builddir where fdroid's output: expects it.
diff --git a/scripts/pin-rust-toolchain.sh b/scripts/pin-rust-toolchain.sh
new file mode 100755
index 0000000..abced5a
--- /dev/null
+++ b/scripts/pin-rust-toolchain.sh
@@ -0,0 +1,34 @@
+#!/usr/bin/env bash
+#
+# Pin cargokit's Rust toolchain for reproducible Rust-plugin builds (tor + openalias).
+#
+# cargokit hardcodes the toolchain to "stable" and runs `rustup run stable cargo ...`
+# — a MOVING channel, so the plugin would be built with whatever stable is latest at
+# build time (non-reproducible across time). The explicit `rustup run` also overrides
+# both RUSTUP_TOOLCHAIN and the plugin's rust-toolchain.toml, so those pins don't take.
+# cargokit's config only allows the channel enum (stable/beta/nightly), not an exact
+# version — so we patch the default in the package instead.
+#
+# Two cargokit copies need patching, in different places:
+# - tor_ffi_plugin: a pub.dev/git dependency -> its cargokit lives in PUB_CACHE.
+# - openalias_ffi: an in-repo PATH plugin -> its cargokit lives in plugins/.
+#
+# Run AFTER `flutter pub get` (so the tor package is in PUB_CACHE) and BEFORE the
+# flutter build. Idempotent; safe if the string is already pinned.
+#
+set -euo pipefail
+
+TOOLCHAIN="${1:-1.96.1}"
+CACHE="${PUB_CACHE:-$HOME/.pub-cache}"
+ROOT="$(cd "$(dirname "$0")/.." && pwd)"
+
+n=0
+while IFS= read -r f; do
+ if grep -q "?? 'stable'" "$f"; then
+ sed -i "s/?? 'stable'/?? '$TOOLCHAIN'/" "$f"
+ n=$((n + 1))
+ fi
+done < <(find "$CACHE" "$ROOT/plugins" -path '*/cargokit/build_tool/lib/src/builder.dart' 2>/dev/null | sort -u)
+
+echo "pin-rust-toolchain: set cargokit toolchain to $TOOLCHAIN in $n file(s) (PUB_CACHE=$CACHE, repo=$ROOT)"
+[ "$n" -gt 0 ] || echo " (warning: no cargokit builder.dart found/patched — verify PUB_CACHE + that the string still exists)"
diff --git a/scripts/pin-tor-rust-toolchain.sh b/scripts/pin-tor-rust-toolchain.sh
deleted file mode 100755
index be19425..0000000
--- a/scripts/pin-tor-rust-toolchain.sh
+++ /dev/null
@@ -1,29 +0,0 @@
-#!/usr/bin/env bash
-#
-# Pin cargokit's Rust toolchain for a reproducible tor_ffi_plugin build.
-#
-# cargokit (used by the tor plugin) hardcodes the toolchain to "stable" and runs
-# `rustup run stable cargo ...` — a MOVING channel, so tor would be built with
-# whatever stable is latest at build time (non-reproducible across time, and
-# RUSTUP_TOOLCHAIN can't override an explicit `rustup run`). Its config only allows
-# the channel enum (stable/beta/nightly), not an exact version — so we patch the
-# default in the fetched package instead.
-#
-# Run AFTER `flutter pub get` (so the tor package is in PUB_CACHE) and BEFORE the
-# flutter build. Idempotent; safe if the string is already pinned.
-#
-set -euo pipefail
-
-TOOLCHAIN="${1:-1.96.1}"
-CACHE="${PUB_CACHE:-$HOME/.pub-cache}"
-
-n=0
-while IFS= read -r f; do
- if grep -q "?? 'stable'" "$f"; then
- sed -i "s/?? 'stable'/?? '$TOOLCHAIN'/" "$f"
- n=$((n + 1))
- fi
-done < <(find "$CACHE" -path '*/cargokit/build_tool/lib/src/builder.dart' 2>/dev/null)
-
-echo "pin-tor-rust-toolchain: set cargokit toolchain to $TOOLCHAIN in $n file(s) (PUB_CACHE=$CACHE)"
-[ "$n" -gt 0 ] || echo " (warning: no cargokit builder.dart found/patched — verify PUB_CACHE + that the string still exists)"
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.