stupid hack. One day epic and mwc will be proper libraries...
What changed, and why it matters
This commit changes build scripts so that two cryptocurrency wallet libraries (Epic Cash and MWC) are only bundled into the main Stack Wallet app, not into the lighter Campfire and Stack Duo variants. It is a build-packaging tweak, not a fix for an active security flaw. There is no evidence it addresses a vulnerability.
No security action required; treat as routine build maintenance. If reviewing supply chain risk, verify that the Epic and MWC libraries are still built from trusted sources when INCLUDE_EPIC_SO/INCLUDE_MWC_SO are ON.
Security signals we found
No security-relevant code change
Build/packaging configuration only
No mention of vulnerability, CVE, researcher, or security issue in commit title or message
Evidence from the diff
The patch introduces CMake flags INCLUDE_EPIC_SO and INCLUDE_MWC_SO, sets them per-product in configure_*.sh scripts, and uses them to conditionally install libepic_cash_wallet and libmwc_wallet shared libraries on Linux and Windows. Stack Wallet enables both; Campfire and Stack Duo disable both. The change reduces bundle size and avoids shipping unused native libraries in derivative products.
Changed components
scripts/app_config/configure_campfire.shscripts/app_config/configure_stack_duo.shscripts/app_config/configure_stack_wallet.shscripts/app_config/platforms/linux/platform_config.shscripts/app_config/platforms/windows/platform_config.shscripts/app_config/templates/linux/CMakeLists.txtscripts/app_config/templates/windows/CMakeLists.txtInspect captured patch +37 / −10
diff --git a/scripts/app_config/configure_campfire.sh b/scripts/app_config/configure_campfire.sh
index c5e4929..04054b9 100755
--- a/scripts/app_config/configure_campfire.sh
+++ b/scripts/app_config/configure_campfire.sh
@@ -40,6 +40,9 @@ dart "${APP_PROJECT_ROOT_DIR}/tool/gen_interfaces.dart" \
TOR \
FIRO
+export INCLUDE_EPIC_SO="OFF"
+export INCLUDE_MWC_SO="OFF"
+
pushd "${APP_PROJECT_ROOT_DIR}"
BUILT_COMMIT_HASH=$(git log -1 --pretty=format:"%H")
popd
diff --git a/scripts/app_config/configure_stack_duo.sh b/scripts/app_config/configure_stack_duo.sh
index 7a839ae..148775a 100755
--- a/scripts/app_config/configure_stack_duo.sh
+++ b/scripts/app_config/configure_stack_duo.sh
@@ -36,6 +36,9 @@ dart "${APP_PROJECT_ROOT_DIR}/tool/gen_interfaces.dart" \
TOR \
FROST
+export INCLUDE_EPIC_SO="OFF"
+export INCLUDE_MWC_SO="OFF"
+
pushd "${APP_PROJECT_ROOT_DIR}"
BUILT_COMMIT_HASH=$(git log -1 --pretty=format:"%H")
popd
diff --git a/scripts/app_config/configure_stack_wallet.sh b/scripts/app_config/configure_stack_wallet.sh
index e976821..f468180 100755
--- a/scripts/app_config/configure_stack_wallet.sh
+++ b/scripts/app_config/configure_stack_wallet.sh
@@ -48,6 +48,9 @@ dart "${APP_PROJECT_ROOT_DIR}/tool/gen_interfaces.dart" \
XEL \
FROST
+export INCLUDE_EPIC_SO="ON"
+export INCLUDE_MWC_SO="ON"
+
pushd "${APP_PROJECT_ROOT_DIR}"
BUILT_COMMIT_HASH=$(git log -1 --pretty=format:"%H")
popd
diff --git a/scripts/app_config/platforms/linux/platform_config.sh b/scripts/app_config/platforms/linux/platform_config.sh
index 018f80d..61dfdfb 100755
--- a/scripts/app_config/platforms/linux/platform_config.sh
+++ b/scripts/app_config/platforms/linux/platform_config.sh
@@ -12,6 +12,8 @@ for (( i=0; i<=1; i++ )); do
fi
done
-# Configure Linux for Duo.
+# Configure Linux
sed -i "s/${APP_BASIC_NAME_PLACEHOLDER}/${NEW_BASIC_NAME}/g" "${APP_PROJECT_ROOT_DIR}/${LINUX_TF_0}"
sed -i "s/${APP_NAME_PLACEHOLDER}/${NEW_NAME}/g" "${APP_PROJECT_ROOT_DIR}/${LINUX_TF_1}"
+sed -i "s/INCLUDE_EPIC_SO_FLAG/${INCLUDE_EPIC_SO}/g" "${APP_PROJECT_ROOT_DIR}/${LINUX_TF_0}"
+sed -i "s/INCLUDE_MWC_SO_FLAG/${INCLUDE_MWC_SO}/g" "${APP_PROJECT_ROOT_DIR}/${LINUX_TF_0}"
\ No newline at end of file
diff --git a/scripts/app_config/platforms/windows/platform_config.sh b/scripts/app_config/platforms/windows/platform_config.sh
index 4a0158c..cbce1d8 100755
--- a/scripts/app_config/platforms/windows/platform_config.sh
+++ b/scripts/app_config/platforms/windows/platform_config.sh
@@ -12,7 +12,9 @@ for (( i=0; i<=2; i++ )); do
fi
done
-# Configure Windows for Duo.
+# Configure Windows
sed -i "s/${APP_NAME_PLACEHOLDER}/${NEW_NAME}/g" "${APP_PROJECT_ROOT_DIR}/${WIN_TF_0}"
sed -i "s/${APP_NAME_PLACEHOLDER}/${NEW_NAME}/g" "${APP_PROJECT_ROOT_DIR}/${WIN_TF_1}"
sed -i "s/${APP_BASIC_NAME_PLACEHOLDER}/${NEW_BASIC_NAME}/g" "${APP_PROJECT_ROOT_DIR}/${WIN_TF_2}"
+sed -i "s/INCLUDE_EPIC_SO_FLAG/${INCLUDE_EPIC_SO}/g" "${APP_PROJECT_ROOT_DIR}/${WIN_TF_2}"
+sed -i "s/INCLUDE_MWC_SO_FLAG/${INCLUDE_MWC_SO}/g" "${APP_PROJECT_ROOT_DIR}/${WIN_TF_2}"
diff --git a/scripts/app_config/templates/linux/CMakeLists.txt b/scripts/app_config/templates/linux/CMakeLists.txt
index 4c140a4..4b0e69d 100644
--- a/scripts/app_config/templates/linux/CMakeLists.txt
+++ b/scripts/app_config/templates/linux/CMakeLists.txt
@@ -9,6 +9,9 @@ set(BINARY_NAME "place_holder")
# https://wiki.gnome.org/HowDoI/ChooseApplicationID
set(APPLICATION_ID "com.place.holder")
+set(INCLUDE_EPIC_SO INCLUDE_EPIC_SO_FLAG)
+set(INCLUDE_MWC_SO INCLUDE_EPIC_SO_FLAG)
+
# Explicitly opt in to modern CMake behaviors to avoid warnings with recent
# versions of CMake.
cmake_policy(SET CMP0063 NEW)
@@ -134,11 +137,15 @@ install(FILES "${FLUTTER_ICU_DATA_FILE}" DESTINATION "${INSTALL_BUNDLE_DATA_DIR}
install(FILES "${FLUTTER_LIBRARY}" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
COMPONENT Runtime)
-install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libepiccash/scripts/linux/build/rust/target/x86_64-unknown-linux-gnu/release/libepic_cash_wallet.so" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
- COMPONENT Runtime)
+if(INCLUDE_EPIC_SO)
+ install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libepiccash/scripts/linux/build/rust/target/x86_64-unknown-linux-gnu/release/libepic_cash_wallet.so" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
+ COMPONENT Runtime)
+endif()
-install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libmwc/scripts/linux/build/rust/target/x86_64-unknown-linux-gnu/release/libmwc_wallet.so" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
- COMPONENT Runtime)
+if(INCLUDE_MWC_SO)
+ install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libmwc/scripts/linux/build/rust/target/x86_64-unknown-linux-gnu/release/libmwc_wallet.so" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
+ COMPONENT Runtime)
+endif()
install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../scripts/linux/build/jsoncpp/build/src/lib_json/libjsoncpp.so.1.7.4" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
COMPONENT Runtime)
diff --git a/scripts/app_config/templates/windows/CMakeLists.txt b/scripts/app_config/templates/windows/CMakeLists.txt
index 7226cf1..02532aa 100644
--- a/scripts/app_config/templates/windows/CMakeLists.txt
+++ b/scripts/app_config/templates/windows/CMakeLists.txt
@@ -6,6 +6,9 @@ project(place_holder LANGUAGES CXX)
# the on-disk name of your application.
set(BINARY_NAME "place_holder")
+set(INCLUDE_EPIC_SO INCLUDE_EPIC_SO_FLAG)
+set(INCLUDE_MWC_SO INCLUDE_EPIC_SO_FLAG)
+
# Explicitly opt in to modern CMake behaviors to avoid warnings with recent
# versions of CMake.
cmake_policy(SET CMP0063 NEW)
@@ -80,11 +83,15 @@ install(FILES "${FLUTTER_ICU_DATA_FILE}" DESTINATION "${INSTALL_BUNDLE_DATA_DIR}
install(FILES "${FLUTTER_LIBRARY}" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
COMPONENT Runtime)
-install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libepiccash/scripts/windows/build/libepic_cash_wallet.dll" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
- COMPONENT Runtime)
+if(INCLUDE_EPIC_SO)
+ install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libepiccash/scripts/windows/build/libepic_cash_wallet.dll" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
+ COMPONENT Runtime)
+endif()
-install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libmwc/scripts/windows/build/libmwc_cash_wallet.dll" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
- COMPONENT Runtime)
+if(INCLUDE_MWC_SO)
+ install(FILES "${CMAKE_CURRENT_SOURCE_DIR}/../crypto_plugins/flutter_libmwc/scripts/windows/build/libmwc_cash_wallet.dll" DESTINATION "${INSTALL_BUNDLE_LIB_DIR}"
+ COMPONENT Runtime)
+endif()
if(PLUGIN_BUNDLED_LIBRARIES)
install(FILES "${PLUGIN_BUNDLED_LIBRARIES}"
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.