What changed, and why it matters
This commit adds automated GitHub Actions workflows to build a Monero wallet library from an external source and create pull requests with the compiled binaries. It also renames a Dockerfile and moves an existing script that removes an executable-stack flag from a Linux library. The changes are mostly build-infrastructure housekeeping. There is no direct evidence of a security vulnerability being introduced, but the workflow does clone and build code from a third-party repository (vtnerd/monero_c) without pinned commit verification at build time, and it later edits pubspec.lock using a remote branch's current commit hash. That creates a supply-chain risk if the upstream repository is compromised, but it is not a confirmed incident.
Review the workflow to pin the exact commit hash of vtnerd/monero_c at build time and verify it against an expected value stored in the repository, rather than relying on the lwsf branch tip. Consider verifying artifact checksums, signing build outputs, and requiring human review before merging the automated PR that commits compiled libraries. Fix the paths filter typo in build-builder-image.yml (.github/workflows/build-builder-image.yml.yml).
Security signals we found
Build workflow clones and compiles third-party source (vtnerd/monero_c lwsf branch) without a pinned commit hash inside the build script
Workflow later updates pubspec.lock resolved-ref from remote branch HEAD, making dependency version dependent on upstream state at run time
Compiled native libraries are committed back into the repository via automated pull request, increasing binary supply-chain surface
Executable-stack mitigation script is preserved, which is a defensive hardening signal rather than a vulnerability
No vendor disclosure, CVE, or researcher attribution present in commit materials
Evidence from the diff
The commit introduces .github/workflows/build-monero-c.yml, which builds libwallet2_api_c.so for four architectures inside debian:bullseye containers by running scripts/build-moneroc.sh. The build script clones https://github.com/vtnerd/monero_c.git, checks out the lwsf branch, initializes submodules, applies patches, and builds. Artifacts are downloaded into a create-pr job, placed into linux/ and android/app/src/main/jniLibs/, and the Linux library’s GNU_STACK executable flag is cleared via scripts/fix-linux-moneroc-execstack.sh. The workflow then fetches the current lwsf branch HEAD and updates pubspec.lock’s resolved-ref, finally opening a PR via peter-evans/create-pull-request. The old Dockerfile is renamed to Dockerfile.builder and the old builder-image-build.yml is renamed to build-builder-image.yml (with a minor paths typo: .github/workflows/build-builder-image.yml.yml). The fix_execstack.sh script is moved from linux/ to scripts/ and its LIB_PATH adjusted. No runtime application code is changed.
Changed components
.github/workflows/build-monero-c.yml.github/workflows/build-builder-image.ymlDockerfile.builderscripts/build-moneroc.shscripts/fix-linux-moneroc-execstack.shInspect captured patch +432 / −227
diff --git a/.github/workflows/build-builder-image.yml b/.github/workflows/build-builder-image.yml
new file mode 100644
index 0000000..8f6ca3e
--- /dev/null
+++ b/.github/workflows/build-builder-image.yml
@@ -0,0 +1,67 @@
+name: Build Builder Docker Image
+
+on:
+ push:
+ branches:
+ - main
+ paths:
+ - 'Dockerfile'
+ - '.github/workflows/build-builder-image.yml.yml'
+ workflow_dispatch:
+
+env:
+ REGISTRY: ghcr.io
+ IMAGE_NAME: ${{ github.repository }}-builder
+
+jobs:
+ build-and-push:
+ name: Build and Push Docker Image
+ runs-on: ubuntu-latest
+ permissions:
+ contents: read
+ packages: write
+ id-token: write
+ attestations: write
+
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+
+ - name: Set up Docker Buildx
+ uses: docker/setup-buildx-action@v3
+
+ - name: Log in to GitHub Container Registry
+ uses: docker/login-action@v3
+ with:
+ registry: ${{ env.REGISTRY }}
+ username: ${{ github.actor }}
+ password: ${{ secrets.GITHUB_TOKEN }}
+
+ - name: Extract metadata for Docker
+ id: meta
+ uses: docker/metadata-action@v5
+ with:
+ images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
+ tags: |
+ type=sha,prefix=
+ type=raw,value=latest
+
+ - name: Build and push Docker image
+ id: build
+ uses: docker/build-push-action@v5
+ with:
+ context: .
+ file: Dockerfile.builder
+ platforms: linux/amd64
+ push: true
+ tags: ${{ steps.meta.outputs.tags }}
+ labels: ${{ steps.meta.outputs.labels }}
+ cache-from: type=gha
+ cache-to: type=gha,mode=max
+
+ - name: Generate artifact attestation
+ uses: actions/attest-build-provenance@v2
+ with:
+ subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
+ subject-digest: ${{ steps.build.outputs.digest }}
+ push-to-registry: true
diff --git a/.github/workflows/build-monero-c.yml b/.github/workflows/build-monero-c.yml
new file mode 100644
index 0000000..06a6ba0
--- /dev/null
+++ b/.github/workflows/build-monero-c.yml
@@ -0,0 +1,186 @@
+name: Build monero_c
+
+on:
+ workflow_dispatch:
+
+permissions:
+ contents: write
+ pull-requests: write
+
+jobs:
+ build-x86_64-linux-gnu:
+ name: Build x86_64-linux-gnu
+ runs-on: ubuntu-latest
+ container:
+ image: debian:bullseye
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+
+ - name: Build monero_c
+ env:
+ TARGET_ARCH: x86_64-linux-gnu
+ run: scripts/build-moneroc.sh
+
+ - name: Copy built library
+ run: |
+ mkdir -p artifacts
+ cp monero_c/monero_libwallet2_api_c/build/x86_64-linux-gnu/libwallet2_api_c.so artifacts/monero_libwallet2_api_c.so
+
+ - name: Upload artifact
+ uses: actions/upload-artifact@v4
+ with:
+ name: x86_64-linux-gnu
+ path: artifacts/monero_libwallet2_api_c.so
+
+ build-x86_64-linux-android:
+ name: Build x86_64-linux-android
+ runs-on: ubuntu-latest
+ container:
+ image: debian:bullseye
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+
+ - name: Build monero_c
+ env:
+ TARGET_ARCH: x86_64-linux-android
+ run: scripts/build-moneroc.sh
+
+ - name: Copy built library
+ run: |
+ mkdir -p artifacts
+ cp monero_c/monero_libwallet2_api_c/build/x86_64-linux-android/libwallet2_api_c.so artifacts/libmonero_libwallet2_api_c.so
+
+ - name: Upload artifact
+ uses: actions/upload-artifact@v4
+ with:
+ name: x86_64-linux-android
+ path: artifacts/libmonero_libwallet2_api_c.so
+
+ build-aarch64-linux-android:
+ name: Build aarch64-linux-android
+ runs-on: ubuntu-latest
+ container:
+ image: debian:bullseye
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+
+ - name: Build monero_c
+ env:
+ TARGET_ARCH: aarch64-linux-android
+ run: scripts/build-moneroc.sh
+
+ - name: Copy built library
+ run: |
+ mkdir -p artifacts
+ cp monero_c/monero_libwallet2_api_c/build/aarch64-linux-android/libwallet2_api_c.so artifacts/libmonero_libwallet2_api_c.so
+
+ - name: Upload artifact
+ uses: actions/upload-artifact@v4
+ with:
+ name: aarch64-linux-android
+ path: artifacts/libmonero_libwallet2_api_c.so
+
+ build-armv7a-linux-androideabi:
+ name: Build armv7a-linux-androideabi
+ runs-on: ubuntu-latest
+ container:
+ image: debian:bullseye
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+
+ - name: Build monero_c
+ env:
+ TARGET_ARCH: armv7a-linux-androideabi
+ run: scripts/build-moneroc.sh
+
+ - name: Copy built library
+ run: |
+ mkdir -p artifacts
+ cp monero_c/monero_libwallet2_api_c/build/armv7a-linux-androideabi/libwallet2_api_c.so artifacts/libmonero_libwallet2_api_c.so
+
+ - name: Upload artifact
+ uses: actions/upload-artifact@v4
+ with:
+ name: armv7a-linux-androideabi
+ path: artifacts/libmonero_libwallet2_api_c.so
+
+ create-pr:
+ name: Create Pull Request
+ runs-on: ubuntu-latest
+ needs:
+ - build-x86_64-linux-gnu
+ - build-x86_64-linux-android
+ - build-aarch64-linux-android
+ - build-armv7a-linux-androideabi
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@v4
+
+ - name: Download x86_64-linux-gnu artifact
+ uses: actions/download-artifact@v4
+ with:
+ name: x86_64-linux-gnu
+ path: artifacts/x86_64-linux-gnu
+
+ - name: Download x86_64-linux-android artifact
+ uses: actions/download-artifact@v4
+ with:
+ name: x86_64-linux-android
+ path: artifacts/x86_64-linux-android
+
+ - name: Download aarch64-linux-android artifact
+ uses: actions/download-artifact@v4
+ with:
+ name: aarch64-linux-android
+ path: artifacts/aarch64-linux-android
+
+ - name: Download armv7a-linux-androideabi artifact
+ uses: actions/download-artifact@v4
+ with:
+ name: armv7a-linux-androideabi
+ path: artifacts/armv7a-linux-androideabi
+
+ - name: Place libraries in correct locations
+ run: |
+ # Linux x86_64
+ cp artifacts/x86_64-linux-gnu/monero_libwallet2_api_c.so linux/monero_libwallet2_api_c.so
+
+ # Android x86_64
+ cp artifacts/x86_64-linux-android/libmonero_libwallet2_api_c.so android/app/src/main/jniLibs/x86_64/libmonero_libwallet2_api_c.so
+
+ # Android arm64-v8a
+ cp artifacts/aarch64-linux-android/libmonero_libwallet2_api_c.so android/app/src/main/jniLibs/arm64-v8a/libmonero_libwallet2_api_c.so
+
+ # Android armeabi-v7a
+ cp artifacts/armv7a-linux-androideabi/libmonero_libwallet2_api_c.so android/app/src/main/jniLibs/armeabi-v7a/libmonero_libwallet2_api_c.so
+
+ - name: Fix Linux library executable stack
+ run: scripts/fix-linux-moneroc-execstack.sh
+
+ - name: Update pubspec.lock with monero_c commit hash
+ run: |
+ COMMIT_HASH=$(git ls-remote https://github.com/vtnerd/monero_c refs/heads/lwsf | cut -f1)
+ sed -i "s/resolved-ref: \"[a-f0-9]*\"/resolved-ref: \"${COMMIT_HASH}\"/" pubspec.lock
+
+ - name: Create Pull Request
+ uses: peter-evans/create-pull-request@v8
+ with:
+ token: ${{ secrets.GITHUB_TOKEN }}
+ commit-message: "Update monero_c libraries"
+ title: "Update monero_c libraries"
+ body: |
+ This PR updates the monero_c libraries for all supported architectures:
+
+ - `linux/monero_libwallet2_api_c.so` (x86_64-linux-gnu)
+ - `android/app/src/main/jniLibs/x86_64/libmonero_libwallet2_api_c.so` (x86_64-linux-android)
+ - `android/app/src/main/jniLibs/arm64-v8a/libmonero_libwallet2_api_c.so` (aarch64-linux-android)
+ - `android/app/src/main/jniLibs/armeabi-v7a/libmonero_libwallet2_api_c.so` (armv7a-linux-androideabi)
+
+ Built from [monero_c](https://github.com/vtnerd/monero_c) branch `lwsf`.
+ branch: update-moneroc-libs
+ delete-branch: true
+
diff --git a/.github/workflows/builder-image-build.yml b/.github/workflows/builder-image-build.yml
deleted file mode 100644
index a872f3f..0000000
--- a/.github/workflows/builder-image-build.yml
+++ /dev/null
@@ -1,66 +0,0 @@
-name: Build Builder Docker Image
-
-on:
- push:
- branches:
- - main
- paths:
- - 'Dockerfile'
- - '.github/workflows/builder-image-build.yml'
- workflow_dispatch:
-
-env:
- REGISTRY: ghcr.io
- IMAGE_NAME: ${{ github.repository }}-builder
-
-jobs:
- build-and-push:
- name: Build and Push Docker Image
- runs-on: ubuntu-latest
- permissions:
- contents: read
- packages: write
- id-token: write
- attestations: write
-
- steps:
- - name: Checkout repository
- uses: actions/checkout@v4
-
- - name: Set up Docker Buildx
- uses: docker/setup-buildx-action@v3
-
- - name: Log in to GitHub Container Registry
- uses: docker/login-action@v3
- with:
- registry: ${{ env.REGISTRY }}
- username: ${{ github.actor }}
- password: ${{ secrets.GITHUB_TOKEN }}
-
- - name: Extract metadata for Docker
- id: meta
- uses: docker/metadata-action@v5
- with:
- images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
- tags: |
- type=sha,prefix=
- type=raw,value=latest
-
- - name: Build and push Docker image
- id: build
- uses: docker/build-push-action@v5
- with:
- context: .
- platforms: linux/amd64
- push: true
- tags: ${{ steps.meta.outputs.tags }}
- labels: ${{ steps.meta.outputs.labels }}
- cache-from: type=gha
- cache-to: type=gha,mode=max
-
- - name: Generate artifact attestation
- uses: actions/attest-build-provenance@v2
- with:
- subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
- subject-digest: ${{ steps.build.outputs.digest }}
- push-to-registry: true
diff --git a/Dockerfile b/Dockerfile
deleted file mode 100644
index b042545..0000000
--- a/Dockerfile
+++ /dev/null
@@ -1,81 +0,0 @@
-# Using Debian Bullseye for maximum AppImage compatibility (GLIBC 2.31)
-FROM debian:bullseye-20251117@sha256:ee239c601913c0d3962208299eef70dcffcb7aac1787f7a02f6d3e2b518755e6
-
-ARG TARGETARCH
-
-ARG FLUTTER_VERSION=3.38.5
-ARG RUST_VERSION=1.83.0
-ARG ANDROID_CMDLINE_TOOLS_VERSION=11076708
-ARG ANDROID_BUILD_TOOLS_VERSION=36.0.0
-ARG ANDROID_PLATFORM_VERSION=36
-ARG ANDROID_NDK_VERSION=28.0.13004108
-
-# Install system dependencies with pinned versions
-RUN apt-get update && \
- apt-get install -y --no-install-recommends \
- curl=7.74.0-1.3+deb11u15 \
- wget=1.21-1+deb11u2 \
- git=1:2.30.2-1+deb11u5 \
- unzip=6.0-26+deb11u1 \
- xz-utils=5.2.5-2.1~deb11u1 \
- zip=3.0-12 \
- libglu1-mesa=9.0.1-1 \
- clang=1:11.0-51+nmu5 \
- cmake=3.18.4-2+deb11u1 \
- ninja-build=1.10.1-1 \
- pkg-config=0.29.2-1 \
- libgtk-3-dev=3.24.24-4+deb11u4 \
- liblzma-dev=5.2.5-2.1~deb11u1 \
- libstdc++-10-dev=10.2.1-6 \
- openjdk-17-jdk=17.0.17+10-1~deb11u1 \
- ca-certificates=20210119 \
- build-essential=12.9 \
- make=4.3-4.1 \
- perl=5.32.1-4+deb11u4 \
- libssl-dev=1.1.1w-0+deb11u4 \
- libsecret-1-dev=0.20.4-2 \
- libsecret-1-0=0.20.4-2 \
- file=1:5.39-3+deb11u1 && \
- apt-get clean && \
- rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
-
-ENV JAVA_HOME=/usr/lib/jvm/java-17-openjdk-${TARGETARCH}
-ENV ANDROID_HOME=/opt/android-sdk
-ENV ANDROID_SDK_ROOT=/opt/android-sdk
-ENV CARGO_HOME=/opt/cargo
-ENV RUSTUP_HOME=/opt/rustup
-ENV PATH="/flutter/bin:${ANDROID_HOME}/cmdline-tools/latest/bin:${ANDROID_HOME}/platform-tools:${CARGO_HOME}/bin:${PATH}"
-ENV FLUTTER_ROOT="/flutter"
-
-# Install Rust with pinned version
-RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --default-toolchain ${RUST_VERSION} --profile minimal && \
- . ${CARGO_HOME}/env && \
- rustup target add aarch64-linux-android armv7-linux-androideabi x86_64-linux-android i686-linux-android
-
-# Install Android SDK command-line tools with pinned version
-RUN mkdir -p ${ANDROID_HOME}/cmdline-tools && \
- cd ${ANDROID_HOME}/cmdline-tools && \
- curl -o cmdtools.zip https://dl.google.com/android/repository/commandlinetools-linux-${ANDROID_CMDLINE_TOOLS_VERSION}_latest.zip && \
- unzip cmdtools.zip && \
- mv cmdline-tools latest && \
- rm cmdtools.zip
-
-# Install Android SDK components with pinned versions
-RUN yes | sdkmanager --licenses && \
- sdkmanager --install \
- "platform-tools" \
- "platforms;android-${ANDROID_PLATFORM_VERSION}" \
- "build-tools;${ANDROID_BUILD_TOOLS_VERSION}" \
- "ndk;${ANDROID_NDK_VERSION}" && \
- rm -rf ${ANDROID_HOME}/.android/cache
-
-# Install Flutter with pinned version
-RUN git clone https://github.com/flutter/flutter.git -b ${FLUTTER_VERSION} --depth 1 /flutter && \
- flutter doctor -v && \
- flutter config --enable-linux-desktop && \
- flutter config --no-analytics && \
- flutter precache --linux --android && \
- find /flutter -name "*.zip" -delete
-
-WORKDIR /workspace
-
diff --git a/Dockerfile.builder b/Dockerfile.builder
new file mode 100644
index 0000000..b042545
--- /dev/null
+++ b/Dockerfile.builder
@@ -0,0 +1,81 @@
+# Using Debian Bullseye for maximum AppImage compatibility (GLIBC 2.31)
+FROM debian:bullseye-20251117@sha256:ee239c601913c0d3962208299eef70dcffcb7aac1787f7a02f6d3e2b518755e6
+
+ARG TARGETARCH
+
+ARG FLUTTER_VERSION=3.38.5
+ARG RUST_VERSION=1.83.0
+ARG ANDROID_CMDLINE_TOOLS_VERSION=11076708
+ARG ANDROID_BUILD_TOOLS_VERSION=36.0.0
+ARG ANDROID_PLATFORM_VERSION=36
+ARG ANDROID_NDK_VERSION=28.0.13004108
+
+# Install system dependencies with pinned versions
+RUN apt-get update && \
+ apt-get install -y --no-install-recommends \
+ curl=7.74.0-1.3+deb11u15 \
+ wget=1.21-1+deb11u2 \
+ git=1:2.30.2-1+deb11u5 \
+ unzip=6.0-26+deb11u1 \
+ xz-utils=5.2.5-2.1~deb11u1 \
+ zip=3.0-12 \
+ libglu1-mesa=9.0.1-1 \
+ clang=1:11.0-51+nmu5 \
+ cmake=3.18.4-2+deb11u1 \
+ ninja-build=1.10.1-1 \
+ pkg-config=0.29.2-1 \
+ libgtk-3-dev=3.24.24-4+deb11u4 \
+ liblzma-dev=5.2.5-2.1~deb11u1 \
+ libstdc++-10-dev=10.2.1-6 \
+ openjdk-17-jdk=17.0.17+10-1~deb11u1 \
+ ca-certificates=20210119 \
+ build-essential=12.9 \
+ make=4.3-4.1 \
+ perl=5.32.1-4+deb11u4 \
+ libssl-dev=1.1.1w-0+deb11u4 \
+ libsecret-1-dev=0.20.4-2 \
+ libsecret-1-0=0.20.4-2 \
+ file=1:5.39-3+deb11u1 && \
+ apt-get clean && \
+ rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
+
+ENV JAVA_HOME=/usr/lib/jvm/java-17-openjdk-${TARGETARCH}
+ENV ANDROID_HOME=/opt/android-sdk
+ENV ANDROID_SDK_ROOT=/opt/android-sdk
+ENV CARGO_HOME=/opt/cargo
+ENV RUSTUP_HOME=/opt/rustup
+ENV PATH="/flutter/bin:${ANDROID_HOME}/cmdline-tools/latest/bin:${ANDROID_HOME}/platform-tools:${CARGO_HOME}/bin:${PATH}"
+ENV FLUTTER_ROOT="/flutter"
+
+# Install Rust with pinned version
+RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --default-toolchain ${RUST_VERSION} --profile minimal && \
+ . ${CARGO_HOME}/env && \
+ rustup target add aarch64-linux-android armv7-linux-androideabi x86_64-linux-android i686-linux-android
+
+# Install Android SDK command-line tools with pinned version
+RUN mkdir -p ${ANDROID_HOME}/cmdline-tools && \
+ cd ${ANDROID_HOME}/cmdline-tools && \
+ curl -o cmdtools.zip https://dl.google.com/android/repository/commandlinetools-linux-${ANDROID_CMDLINE_TOOLS_VERSION}_latest.zip && \
+ unzip cmdtools.zip && \
+ mv cmdline-tools latest && \
+ rm cmdtools.zip
+
+# Install Android SDK components with pinned versions
+RUN yes | sdkmanager --licenses && \
+ sdkmanager --install \
+ "platform-tools" \
+ "platforms;android-${ANDROID_PLATFORM_VERSION}" \
+ "build-tools;${ANDROID_BUILD_TOOLS_VERSION}" \
+ "ndk;${ANDROID_NDK_VERSION}" && \
+ rm -rf ${ANDROID_HOME}/.android/cache
+
+# Install Flutter with pinned version
+RUN git clone https://github.com/flutter/flutter.git -b ${FLUTTER_VERSION} --depth 1 /flutter && \
+ flutter doctor -v && \
+ flutter config --enable-linux-desktop && \
+ flutter config --no-analytics && \
+ flutter precache --linux --android && \
+ find /flutter -name "*.zip" -delete
+
+WORKDIR /workspace
+
diff --git a/linux/fix_execstack.sh b/linux/fix_execstack.sh
deleted file mode 100755
index b814be6..0000000
--- a/linux/fix_execstack.sh
+++ /dev/null
@@ -1,80 +0,0 @@
-#!/bin/bash
-# Script to fix executable stack flag in monero_libwallet2_api_c.so
-# This should be run whenever monero_libwallet2_api_c.so file is updated.
-
-LIB_PATH="$(dirname "$0")/monero_libwallet2_api_c.so"
-
-if [ ! -f "$LIB_PATH" ]; then
- echo "Error: $LIB_PATH not found"
- exit 1
-fi
-
-python3 << PYTHON_SCRIPT
-import struct
-import sys
-
-lib_path = "$LIB_PATH"
-
-# Read the ELF file
-with open(lib_path, 'rb') as f:
- data = bytearray(f.read())
-
-# Check ELF magic
-if data[:4] != b'\x7fELF':
- print('Error: Not an ELF file')
- sys.exit(1)
-
-# Get ELF class (32 or 64 bit)
-elf_class = data[4]
-if elf_class == 1: # 32-bit
- phoff = struct.unpack('<I', data[28:32])[0]
- phentsize = struct.unpack('<H', data[42:44])[0]
- phnum = struct.unpack('<H', data[44:46])[0]
-else: # 64-bit
- phoff = struct.unpack('<Q', data[32:40])[0]
- phentsize = struct.unpack('<H', data[54:56])[0]
- phnum = struct.unpack('<H', data[56:58])[0]
-
-# Find GNU_STACK segment and clear executable flag
-found = False
-for i in range(phnum):
- offset = phoff + i * phentsize
- if elf_class == 1: # 32-bit
- p_type = struct.unpack('<I', data[offset:offset+4])[0]
- else: # 64-bit
- p_type = struct.unpack('<I', data[offset:offset+4])[0]
-
- # Check if it's PT_GNU_STACK (0x6474e551)
- if p_type == 0x6474e551:
- found = True
- if elf_class == 1: # 32-bit
- p_flags_offset = offset + 24
- else: # 64-bit
- p_flags_offset = offset + 4
-
- # Read current flags
- p_flags = struct.unpack('<I', data[p_flags_offset:p_flags_offset+4])[0]
- # Clear executable bit (remove PF_X = 0x1)
- p_flags = p_flags & ~0x1
- # Write back
- data[p_flags_offset:p_flags_offset+4] = struct.pack('<I', p_flags)
- print(f'Cleared executable flag. New flags: 0x{p_flags:x}')
- break
-
-if found:
- # Write back the modified file
- with open(lib_path, 'wb') as f:
- f.write(data)
- print('File updated successfully')
-else:
- print('Warning: GNU_STACK segment not found')
- sys.exit(1)
-PYTHON_SCRIPT
-
-if [ $? -eq 0 ]; then
- echo "Successfully fixed executable stack flag in $LIB_PATH"
-else
- echo "Failed to fix executable stack flag"
- exit 1
-fi
-
diff --git a/scripts/build-moneroc.sh b/scripts/build-moneroc.sh
new file mode 100755
index 0000000..4f0085d
--- /dev/null
+++ b/scripts/build-moneroc.sh
@@ -0,0 +1,18 @@
+#!/bin/bash
+set -e
+
+apt update
+apt upgrade -y
+apt install -y build-essential pkg-config autoconf libtool ccache make cmake gcc g++ git curl \
+ lbzip2 libtinfo5 gperf unzip python-is-python3 gcc-mingw-w64-x86-64 g++-mingw-w64-x86-64
+
+git config --global --add safe.directory '*'
+git config --global user.email "info@magicgrants.org"
+git config --global user.name "MAGIC Grants"
+
+git clone https://github.com/vtnerd/monero_c.git
+cd monero_c
+git checkout lwsf
+git submodule update --init
+./apply_patches.sh monero
+./build_single.sh monero $TARGET_ARCH -j$(nproc)
\ No newline at end of file
diff --git a/scripts/fix-linux-moneroc-execstack.sh b/scripts/fix-linux-moneroc-execstack.sh
new file mode 100755
index 0000000..be8622a
--- /dev/null
+++ b/scripts/fix-linux-moneroc-execstack.sh
@@ -0,0 +1,80 @@
+#!/bin/bash
+# Script to fix executable stack flag in monero_libwallet2_api_c.so
+# This should be run whenever monero_libwallet2_api_c.so file is updated.
+
+LIB_PATH="$(dirname "$0")/../linux/monero_libwallet2_api_c.so"
+
+if [ ! -f "$LIB_PATH" ]; then
+ echo "Error: $LIB_PATH not found"
+ exit 1
+fi
+
+python3 << PYTHON_SCRIPT
+import struct
+import sys
+
+lib_path = "$LIB_PATH"
+
+# Read the ELF file
+with open(lib_path, 'rb') as f:
+ data = bytearray(f.read())
+
+# Check ELF magic
+if data[:4] != b'\x7fELF':
+ print('Error: Not an ELF file')
+ sys.exit(1)
+
+# Get ELF class (32 or 64 bit)
+elf_class = data[4]
+if elf_class == 1: # 32-bit
+ phoff = struct.unpack('<I', data[28:32])[0]
+ phentsize = struct.unpack('<H', data[42:44])[0]
+ phnum = struct.unpack('<H', data[44:46])[0]
+else: # 64-bit
+ phoff = struct.unpack('<Q', data[32:40])[0]
+ phentsize = struct.unpack('<H', data[54:56])[0]
+ phnum = struct.unpack('<H', data[56:58])[0]
+
+# Find GNU_STACK segment and clear executable flag
+found = False
+for i in range(phnum):
+ offset = phoff + i * phentsize
+ if elf_class == 1: # 32-bit
+ p_type = struct.unpack('<I', data[offset:offset+4])[0]
+ else: # 64-bit
+ p_type = struct.unpack('<I', data[offset:offset+4])[0]
+
+ # Check if it's PT_GNU_STACK (0x6474e551)
+ if p_type == 0x6474e551:
+ found = True
+ if elf_class == 1: # 32-bit
+ p_flags_offset = offset + 24
+ else: # 64-bit
+ p_flags_offset = offset + 4
+
+ # Read current flags
+ p_flags = struct.unpack('<I', data[p_flags_offset:p_flags_offset+4])[0]
+ # Clear executable bit (remove PF_X = 0x1)
+ p_flags = p_flags & ~0x1
+ # Write back
+ data[p_flags_offset:p_flags_offset+4] = struct.pack('<I', p_flags)
+ print(f'Cleared executable flag. New flags: 0x{p_flags:x}')
+ break
+
+if found:
+ # Write back the modified file
+ with open(lib_path, 'wb') as f:
+ f.write(data)
+ print('File updated successfully')
+else:
+ print('Warning: GNU_STACK segment not found')
+ sys.exit(1)
+PYTHON_SCRIPT
+
+if [ $? -eq 0 ]; then
+ echo "Successfully fixed executable stack flag in $LIB_PATH"
+else
+ echo "Failed to fix executable stack flag"
+ exit 1
+fi
+
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.