v0.0.2 - Add random mnemonic startup flow and multi-instance random socket naming
This commit is contained in:
@@ -1,77 +1,82 @@
|
||||
# Alpine-based MUSL static binary builder for nsigner
|
||||
# Produces portable binaries with zero runtime dependencies
|
||||
|
||||
ARG DEBUG_BUILD=false
|
||||
|
||||
FROM alpine:3.19 AS builder
|
||||
|
||||
ARG DEBUG_BUILD=false
|
||||
|
||||
RUN apk add --no-cache \
|
||||
build-base \
|
||||
musl-dev \
|
||||
linux-headers \
|
||||
openssl-dev \
|
||||
openssl-libs-static \
|
||||
curl-dev \
|
||||
curl-static \
|
||||
zlib-static \
|
||||
sqlite-dev \
|
||||
sqlite-static \
|
||||
brotli-static \
|
||||
c-ares-static \
|
||||
nghttp2-static \
|
||||
libidn2-static \
|
||||
libpsl-static \
|
||||
libunistring-static \
|
||||
zstd-static \
|
||||
git \
|
||||
cmake \
|
||||
pkgconfig \
|
||||
autoconf \
|
||||
automake \
|
||||
libtool \
|
||||
openssl-dev \
|
||||
openssl-libs-static \
|
||||
zlib-dev \
|
||||
zlib-static \
|
||||
curl-dev \
|
||||
curl-static \
|
||||
linux-headers \
|
||||
wget \
|
||||
pkgconfig \
|
||||
bash
|
||||
|
||||
WORKDIR /build
|
||||
|
||||
# Build libsecp256k1 static for nostr_core_lib
|
||||
# Build libsecp256k1 from source with schnorr support
|
||||
RUN cd /tmp && \
|
||||
git clone https://github.com/bitcoin-core/secp256k1.git && \
|
||||
git clone --depth 1 https://github.com/bitcoin-core/secp256k1.git && \
|
||||
cd secp256k1 && \
|
||||
./autogen.sh && \
|
||||
./configure --enable-static --disable-shared --prefix=/usr CFLAGS="-fPIC" && \
|
||||
make -j$(nproc) && \
|
||||
./configure \
|
||||
--prefix=/usr \
|
||||
--enable-static \
|
||||
--disable-shared \
|
||||
--enable-module-schnorrsig \
|
||||
--enable-module-extrakeys \
|
||||
--enable-module-recovery && \
|
||||
make -j"$(nproc)" && \
|
||||
make install && \
|
||||
rm -rf /tmp/secp256k1
|
||||
|
||||
# Copy and build nostr_core_lib with signer-focused NIPs
|
||||
COPY nostr_core_lib /build/nostr_core_lib/
|
||||
RUN cd nostr_core_lib && \
|
||||
chmod +x build.sh && \
|
||||
sed -i 's/CFLAGS="-Wall -Wextra -std=c99 -fPIC -O2"/CFLAGS="-U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=0 -Wall -Wextra -std=c99 -fPIC -O2"/' build.sh && \
|
||||
rm -f *.o *.a 2>/dev/null || true && \
|
||||
./build.sh --nips=1,6,13,17,19,44,46,59
|
||||
# Copy and build nostr_core_lib from project resources
|
||||
COPY resources/nostr_core_lib /build/nostr_core_lib/
|
||||
RUN cd /build/nostr_core_lib && \
|
||||
chmod +x ./build.sh && \
|
||||
./build.sh --nips=1,4,6,19,44,46
|
||||
|
||||
# Copy project source
|
||||
# Copy source files
|
||||
COPY src/ /build/src/
|
||||
|
||||
# Build nsigner static binary
|
||||
RUN if [ "$DEBUG_BUILD" = "true" ]; then \
|
||||
CFLAGS="-g -O2 -DDEBUG -fno-omit-frame-pointer"; \
|
||||
STRIP_CMD="echo 'Keeping debug symbols'"; \
|
||||
echo "Building debug binary"; \
|
||||
else \
|
||||
CFLAGS="-O2"; \
|
||||
STRIP_CMD="strip /build/nsigner_static"; \
|
||||
echo "Building production binary"; \
|
||||
fi && \
|
||||
gcc -static $CFLAGS -Wall -Wextra -std=c99 \
|
||||
-U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=0 \
|
||||
-Isrc \
|
||||
src/main.c \
|
||||
-o /build/nsigner_static && \
|
||||
eval "$STRIP_CMD"
|
||||
# Build nsigner as a fully static binary
|
||||
RUN gcc -static -O2 -Wall -Wextra -std=c99 \
|
||||
-I/build/nostr_core_lib \
|
||||
-I/build/nostr_core_lib/nostr_core \
|
||||
-I/build/nostr_core_lib/cjson \
|
||||
/build/src/main.c \
|
||||
/build/src/secure_mem.c \
|
||||
/build/src/mnemonic.c \
|
||||
/build/src/role_table.c \
|
||||
/build/src/selector.c \
|
||||
/build/src/enforcement.c \
|
||||
/build/src/dispatcher.c \
|
||||
/build/src/policy.c \
|
||||
/build/src/server.c \
|
||||
/build/src/crypto.c \
|
||||
/build/src/socket_name.c \
|
||||
/build/src/bip39_english.c \
|
||||
/build/nostr_core_lib/libnostr_core_x64.a \
|
||||
-o /build/nsigner_static \
|
||||
$(pkg-config --static --libs libcurl openssl) \
|
||||
-lsecp256k1 -lsqlite3 -lz -lpthread -lm
|
||||
|
||||
RUN echo "=== Binary Information ===" && \
|
||||
file /build/nsigner_static && \
|
||||
ls -lh /build/nsigner_static && \
|
||||
echo "=== Checking for dynamic dependencies ===" && \
|
||||
(ldd /build/nsigner_static 2>&1 || echo "Binary is static") && \
|
||||
echo "=== Build complete ==="
|
||||
RUN file /build/nsigner_static && \
|
||||
(ldd /build/nsigner_static 2>&1 || true)
|
||||
|
||||
FROM scratch AS output
|
||||
COPY --from=builder /build/nsigner_static /nsigner_static
|
||||
|
||||
Reference in New Issue
Block a user