fix(linux): enable secp256k1 recovery module in build script
What changed, and why it matters
This commit changes a Linux build script for the secp256k1 cryptographic library so that it explicitly enables the 'recovery' module. The recovery module allows a wallet to recover the public key from a digital signature, which is needed for some Bitcoin-style transaction verification. Without this module enabled, the built library would lack those functions, which could cause wallet operations to fail or fall back to less secure behavior. The change itself is a build-configuration fix, not an active exploit.
Verify that the built libsecp256k1.so now exports recovery symbols (e.g., secp256k1_ecdsa_recover) and that Linux wallet builds pass integration tests for signing/recovery paths. Audit other platform build scripts for the same flag, since inconsistent builds could create cross-platform bugs. No emergency patch is required; treat as a build fix.
Security signals we found
Cryptographic library build configuration changed
Optional secp256k1 recovery module explicitly enabled
Build script now cleans stale build directory before reconfigure
No source-code vulnerability or exploit payload present in diff
Evidence from the diff
The patch modifies scripts/linux/build_secp256k1.sh to (1) remove any prior build directory before configuring, and (2) pass -DSECP256K1_ENABLE_MODULE_RECOVERY=ON to CMake when building libsecp256k1. The upstream secp256k1 project changed its CMake defaults so that optional modules such as recovery are disabled unless explicitly requested. Stack Wallet apparently depends on the recovery module (e.g., for public-key recovery from ECDSA signatures). The commit ensures the Linux build produces a library that includes secp256k1_ecdsa_recover and related functions. There is no direct evidence in the commit of a runtime vulnerability; the risk is functional breakage or a weakened/incomplete cryptographic workflow if the module remains disabled.
Changed components
scripts/linux/build_secp256k1.shLinux build of libsecp256k1Wallet operations relying on ECDSA public-key recoveryInspect captured patch +2 / −1
diff --git a/scripts/linux/build_secp256k1.sh b/scripts/linux/build_secp256k1.sh
index e139cc9..b6037a3 100755
--- a/scripts/linux/build_secp256k1.sh
+++ b/scripts/linux/build_secp256k1.sh
@@ -6,8 +6,9 @@ fi
cd secp256k1
git checkout 68b55209f1ba3e6c0417789598f5f75649e9c14c
git reset --hard
+rm -rf build
mkdir -p build && cd build
-cmake ..
+cmake .. -DSECP256K1_ENABLE_MODULE_RECOVERY=ON
cmake --build .
mkdir -p ../../../../../build
cp lib/libsecp256k1.so.2.*.* "../../../../../build/libsecp256k1.so"
Why this scored 44/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.