fix(windows): enable secp256k1 recovery module in batch build script
What changed, and why it matters
This commit updates a Windows build script for a cryptographic library (secp256k1) used by Stack Wallet. It turns on the 'recovery' module, which is needed to recover public keys from signatures, and cleans up old build directories before compiling. There is no direct evidence in the commit that this fixes an active security vulnerability; it appears to be a build-configuration correction to make the wallet compile and function correctly on Windows.
Treat as a normal build-fix commit. Verify that enabling the recovery module is intentional and consistent with non-Windows build scripts. Review any code paths that use secp256k1 recovery functions to ensure they handle failures and invalid signatures safely. No urgent security response is indicated by this commit alone.
Security signals we found
Cryptographic library build configuration changed
Recovery module explicitly enabled
No direct vulnerability description in commit or diff
Evidence from the diff
The patch modifies scripts/windows/build_secp256k1.bat to (1) remove any pre-existing build directory before configuring, and (2) pass -DSECP256K1_ENABLE_MODULE_RECOVERY=ON to CMake when building bitcoin-core/secp256k1 at commit 68b55209. The recovery module provides secp256k1_ecdsa_recover and related functions. Without it, any code path in Stack Wallet that relies on public-key recovery from ECDSA signatures would fail to link or run on Windows. The change aligns the Windows build with what is presumably already done on other platforms.
Changed components
scripts/windows/build_secp256k1.batWindows build of secp256k1 dependencyInspect captured patch +2 / −1
diff --git a/scripts/windows/build_secp256k1.bat b/scripts/windows/build_secp256k1.bat
index bae7c97..b619e6e 100644
--- a/scripts/windows/build_secp256k1.bat
+++ b/scripts/windows/build_secp256k1.bat
@@ -4,7 +4,8 @@ git clone https://github.com/bitcoin-core/secp256k1
cd secp256k1
git checkout 68b55209f1ba3e6c0417789598f5f75649e9c14c
git reset --hard
-cmake -G "Visual Studio 17 2022" -A x64 -S . -B build
+if exist "build" rmdir /s /q "build"
+cmake -G "Visual Studio 17 2022" -A x64 -S . -B build -DSECP256K1_ENABLE_MODULE_RECOVERY=ON
cd build
cmake --build .
if not exist "..\..\..\..\..\build\" mkdir "..\..\..\..\..\build\"
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.