fix(windows): enable secp256k1 recovery module in WSL build script
What changed, and why it matters
This commit changes a Windows build script used in WSL to compile the secp256k1 cryptographic library. It turns on the 'recovery' module, which adds support for recovering public keys from signatures, and adds a cleanup step to remove old build files. This is most likely a build-fix or feature-enablement rather than a security patch, but enabling extra cryptographic modules can have security implications depending on how the resulting library is used.
Verify that the recovery module is intentionally required by the application and that enabling it does not expose new attack surface (e.g., through signature malleability or public-key recovery misuse). Review downstream callers of secp256k1 to ensure they handle recovery outputs safely. No immediate patching action is indicated by this commit alone.
Security signals we found
Cryptographic library build configuration changed
New module (secp256k1 recovery) enabled in compiled binary
Build script cleanup added (rm -rf build) to avoid stale artifacts
Evidence from the diff
The patch modifies scripts/windows/build_secp256k1_wsl.sh. It adds ‘rm -rf build’ before creating the build directory and adds -DSECP256K1_ENABLE_MODULE_RECOVERY=ON to the cmake invocation for the secp256k1 library compiled with a MinGW toolchain for Windows. The secp256k1 recovery module provides functions such as secp256k1_ecdsa_recover and is required by some Bitcoin/Ethereum-style cryptographic workflows. There is no direct evidence in the commit that this fixes an active vulnerability; it appears to be enabling a missing build feature.
Changed components
scripts/windows/build_secp256k1_wsl.shWindows secp256k1 DLL build produced via WSL/MinGWInspect captured patch +2 / −1
diff --git a/scripts/windows/build_secp256k1_wsl.sh b/scripts/windows/build_secp256k1_wsl.sh
index a39cd3b..cedb2bc 100644
--- a/scripts/windows/build_secp256k1_wsl.sh
+++ b/scripts/windows/build_secp256k1_wsl.sh
@@ -6,8 +6,9 @@ fi
cd secp256k1
git checkout 68b55209f1ba3e6c0417789598f5f75649e9c14c
git reset --hard
+rm -rf build
mkdir -p build && cd build
-cmake .. -DCMAKE_TOOLCHAIN_FILE=../cmake/x86_64-w64-mingw32.toolchain.cmake
+cmake .. -DCMAKE_TOOLCHAIN_FILE=../cmake/x86_64-w64-mingw32.toolchain.cmake -DSECP256K1_ENABLE_MODULE_RECOVERY=ON
cmake --build .
mkdir -p ../../../../../build
cp bin/libsecp256k1-2.dll "../../../../../build/secp256k1.dll"
Why this scored 23/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.