v0.0.2 - Add random mnemonic startup flow and multi-instance random socket naming

This commit is contained in:
Laan Tungir
2026-05-02 13:46:01 -04:00
parent 268b33b6d3
commit 21f1258844
25 changed files with 1175 additions and 285 deletions

View File

@@ -1,77 +1,82 @@
# Alpine-based MUSL static binary builder for nsigner
# Produces portable binaries with zero runtime dependencies
ARG DEBUG_BUILD=false
FROM alpine:3.19 AS builder
ARG DEBUG_BUILD=false
RUN apk add --no-cache \
build-base \
musl-dev \
linux-headers \
openssl-dev \
openssl-libs-static \
curl-dev \
curl-static \
zlib-static \
sqlite-dev \
sqlite-static \
brotli-static \
c-ares-static \
nghttp2-static \
libidn2-static \
libpsl-static \
libunistring-static \
zstd-static \
git \
cmake \
pkgconfig \
autoconf \
automake \
libtool \
openssl-dev \
openssl-libs-static \
zlib-dev \
zlib-static \
curl-dev \
curl-static \
linux-headers \
wget \
pkgconfig \
bash
WORKDIR /build
# Build libsecp256k1 static for nostr_core_lib
# Build libsecp256k1 from source with schnorr support
RUN cd /tmp && \
git clone https://github.com/bitcoin-core/secp256k1.git && \
git clone --depth 1 https://github.com/bitcoin-core/secp256k1.git && \
cd secp256k1 && \
./autogen.sh && \
./configure --enable-static --disable-shared --prefix=/usr CFLAGS="-fPIC" && \
make -j$(nproc) && \
./configure \
--prefix=/usr \
--enable-static \
--disable-shared \
--enable-module-schnorrsig \
--enable-module-extrakeys \
--enable-module-recovery && \
make -j"$(nproc)" && \
make install && \
rm -rf /tmp/secp256k1
# Copy and build nostr_core_lib with signer-focused NIPs
COPY nostr_core_lib /build/nostr_core_lib/
RUN cd nostr_core_lib && \
chmod +x build.sh && \
sed -i 's/CFLAGS="-Wall -Wextra -std=c99 -fPIC -O2"/CFLAGS="-U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=0 -Wall -Wextra -std=c99 -fPIC -O2"/' build.sh && \
rm -f *.o *.a 2>/dev/null || true && \
./build.sh --nips=1,6,13,17,19,44,46,59
# Copy and build nostr_core_lib from project resources
COPY resources/nostr_core_lib /build/nostr_core_lib/
RUN cd /build/nostr_core_lib && \
chmod +x ./build.sh && \
./build.sh --nips=1,4,6,19,44,46
# Copy project source
# Copy source files
COPY src/ /build/src/
# Build nsigner static binary
RUN if [ "$DEBUG_BUILD" = "true" ]; then \
CFLAGS="-g -O2 -DDEBUG -fno-omit-frame-pointer"; \
STRIP_CMD="echo 'Keeping debug symbols'"; \
echo "Building debug binary"; \
else \
CFLAGS="-O2"; \
STRIP_CMD="strip /build/nsigner_static"; \
echo "Building production binary"; \
fi && \
gcc -static $CFLAGS -Wall -Wextra -std=c99 \
-U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=0 \
-Isrc \
src/main.c \
-o /build/nsigner_static && \
eval "$STRIP_CMD"
# Build nsigner as a fully static binary
RUN gcc -static -O2 -Wall -Wextra -std=c99 \
-I/build/nostr_core_lib \
-I/build/nostr_core_lib/nostr_core \
-I/build/nostr_core_lib/cjson \
/build/src/main.c \
/build/src/secure_mem.c \
/build/src/mnemonic.c \
/build/src/role_table.c \
/build/src/selector.c \
/build/src/enforcement.c \
/build/src/dispatcher.c \
/build/src/policy.c \
/build/src/server.c \
/build/src/crypto.c \
/build/src/socket_name.c \
/build/src/bip39_english.c \
/build/nostr_core_lib/libnostr_core_x64.a \
-o /build/nsigner_static \
$(pkg-config --static --libs libcurl openssl) \
-lsecp256k1 -lsqlite3 -lz -lpthread -lm
RUN echo "=== Binary Information ===" && \
file /build/nsigner_static && \
ls -lh /build/nsigner_static && \
echo "=== Checking for dynamic dependencies ===" && \
(ldd /build/nsigner_static 2>&1 || echo "Binary is static") && \
echo "=== Build complete ==="
RUN file /build/nsigner_static && \
(ldd /build/nsigner_static 2>&1 || true)
FROM scratch AS output
COPY --from=builder /build/nsigner_static /nsigner_static