build 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322
  1. #!/bin/bash
  2. [% c("var/set_default_env") -%]
  3. [% IF ! c("var/linux-cross") %]
  4. [% pc(c('var/compiler'), 'var/setup', { compiler_tarfile => c('input_files_by_name/' _ c('var/compiler')) }) %]
  5. [% END %]
  6. mkdir -p /var/tmp/dist
  7. distdir=/var/tmp/dist/[% project %]
  8. mkdir -p /var/tmp/build
  9. mkdir -p [% dest_dir _ '/' _ c('filename') %]
  10. [% IF c("var/windows") %]
  11. # Setting up fxc2
  12. tar -C /var/tmp/dist -xf [% c('input_files_by_name/fxc2') %]
  13. export PATH="/var/tmp/dist/fxc2/bin:$PATH"
  14. # fxc2 requires Wine.
  15. export WINEARCH=[% IF c("var/windows-x86_64") %]win64[% ELSE %]win32[% END %]
  16. export HOME=/var/tmp/home
  17. mkdir -p $HOME
  18. WINEROOT=$HOME/.wine/drive_c
  19. wine wineboot -i
  20. # Setting up stack protector support
  21. tar -C /var/tmp/dist -xf [% c('input_files_by_name/mingw-w64') %]
  22. cp /var/tmp/dist/mingw-w64/gcclibs/{libssp.a,libssp_nonshared.a} /var/tmp/dist/mingw-w64-clang/[% c("arch") %]-w64-mingw32/lib/
  23. [% END -%]
  24. tar -C /var/tmp/dist -xf [% c('input_files_by_name/rust') %]
  25. [% IF c("var/linux-cross") %]
  26. # rustup expects Wheezy openssl, so we provide it here
  27. export LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/var/tmp/dist/rust/lib_host"
  28. [% END %]
  29. tar -C /var/tmp/dist -xf [% c('input_files_by_name/cbindgen') %]
  30. tar -C /var/tmp/dist -xf [% c('input_files_by_name/nasm') %]
  31. tar -C /var/tmp/dist -xf [% c('input_files_by_name/python') %]
  32. tar -C /var/tmp/dist -xf [% c('input_files_by_name/node') %]
  33. export PATH="/var/tmp/dist/rust/bin:/var/tmp/dist/cbindgen:/var/tmp/dist/nasm/bin:/var/tmp/dist/python/bin:/var/tmp/dist/node/bin:$PATH"
  34. tar -C /var/tmp/dist -xf [% c('input_files_by_name/clang') %]
  35. export LLVM_CONFIG="/var/tmp/dist/clang/bin/llvm-config"
  36. [% IF c("var/linux") || c("var/android") %]
  37. tar -C /var/tmp/dist -xf $rootdir/[% c('input_files_by_name/binutils') %]
  38. export PATH="/var/tmp/dist/binutils/bin:$PATH"
  39. # Use clang for everything on Linux and Android now if we don't build with
  40. # ASan.
  41. [% IF ! c("var/asan") -%]
  42. export PATH="/var/tmp/dist/clang/bin:$PATH"
  43. [% END -%]
  44. [% END -%]
  45. tar -C /var/tmp/build -xf [% project %]-[% c('version') %].tar.gz
  46. [% IF c("var/osx") %]
  47. mkdir -p "$distdir/Tor Browser.app/Contents/MacOS"
  48. [% ELSE %]
  49. mkdir -p $distdir/Browser
  50. [% END %]
  51. cd /var/tmp/build/[% project %]-[% c("version") %]
  52. mv -f $rootdir/[% c('input_files_by_name/mozconfig') %] .mozconfig
  53. [% IF c("var/asan") -%]
  54. mv -f .mozconfig-asan .mozconfig
  55. # Without disabling LSan our build is blowing up:
  56. # https://bugs.torproject.org/10599#comment:52
  57. export ASAN_OPTIONS="detect_leaks=0"
  58. [% END -%]
  59. [% IF c("var/android") %]
  60. export JAVA_HOME=/usr/lib/jvm/java-1.8.0-openjdk-amd64
  61. gradle_repo=/var/tmp/dist/gradle-dependencies
  62. export GRADLE_MAVEN_REPOSITORIES="file://$gradle_repo"
  63. export GRADLE_FLAGS="--no-daemon --offline"
  64. # Move Gradle Repo to hard-coded location. This location is embedded in the file
  65. # chrome/toolkit/content/global/buildconfig.html so needs to be standard for reproducibility
  66. mv $rootdir/[% c('input_files_by_name/gradle-dependencies') %] $gradle_repo
  67. cp -r $gradle_repo/m2/* $gradle_repo
  68. # Move Android library dependencies so they will be included in the apk during the build
  69. cp $rootdir/[% c('input_files_by_name/topl') %]/* mobile/android/app
  70. cp $rootdir/[% c('input_files_by_name/tor-android-service') %]/* mobile/android/app
  71. # Move emulator to location that firefox build expects
  72. mkdir /var/tmp/dist/android-toolchain/android-sdk-linux/emulator
  73. cp /var/tmp/dist/android-toolchain/android-sdk-linux/tools/emulator /var/tmp/dist/android-toolchain/android-sdk-linux/emulator
  74. # Prepare building the multi-locale .apk including our own strings
  75. mkdir -p /var/tmp/dist/locales
  76. tar -C /var/tmp/dist/locales -xf $rootdir/[% c('input_files_by_name/firefox-locale-bundle') %]
  77. tar -C /var/tmp/dist -xf $rootdir/[% c('input_files_by_name/tba-translation') %]
  78. [% END %]
  79. eval $(perl $rootdir/get-moz-build-date [% c("var/copyright_year") %] [% c("var/torbrowser_version") %])
  80. if [ -z $MOZ_BUILD_DATE ]
  81. then
  82. echo "MOZ_BUILD_DATE is not set"
  83. exit 1
  84. fi
  85. [% IF c("var/windows") %]
  86. # Make sure widl is not inserting random timestamps, see #21837.
  87. export WIDL_TIME_OVERRIDE="0"
  88. patch -p1 < $rootdir/nsis-uninstall.patch
  89. # Make sure we link without inserting timestamps in general.
  90. export LDFLAGS="-Wl,--no-insert-timestamp"
  91. [% END -%]
  92. [% IF c("var/linux-arm") %]
  93. patch -p1 < $rootdir/linux-arm-neon.patch
  94. patch -p1 < $rootdir/linux-arm-wasm.patch
  95. [% END %]
  96. [% IF c("var/namecoin") %]
  97. patch -p1 < $rootdir/namecoin-etld.patch
  98. [% END -%]
  99. [% IF ! c("var/android") %]
  100. # Place a copy of the Tor Launcher sources under browser/extensions
  101. tar -C browser/extensions -xf $rootdir/[% c('input_files_by_name/tor-launcher') %]
  102. [% END -%]
  103. [% IF c("var/namecoin") %]
  104. pushd toolkit/torproject/torbutton
  105. patch -p1 < $rootdir/namecoin-torbutton.patch
  106. popd
  107. [% END %]
  108. [% IF c("var/nightly") -%]
  109. # Add nightly mar signing key (#33403)
  110. cp $rootdir/nightly-marsigner.der toolkit/mozapps/update/updater/nightly_aurora_level3_primary.der
  111. cp $rootdir/nightly-marsigner.der toolkit/mozapps/update/updater/nightly_aurora_level3_secondary.der
  112. # Set app.update.url for nightly (#33402)
  113. sed -i 's|pref("app\.update\.url",.*|pref("app.update.url", "https://nightlies.tbb.torproject.org/nightly-updates/updates/nightly-[% c("var/osname") %]/%CHANNEL%/%BUILD_TARGET%/%VERSION%/%LOCALE%");|' browser/app/profile/firefox.js
  114. [% END -%]
  115. rm -f configure
  116. rm -f js/src/configure
  117. # Android does not support --enable-bundled-fonts option
  118. ./mach configure --with-tor-browser-version=[% c("var/torbrowser_version") %] --with-distribution-id=org.torproject --enable-update-channel=[% c("var/channel") %] [% IF ! c("var/android") %]--enable-bundled-fonts[% END -%] --with-branding=[% c("var/branding_directory") %]
  119. ./mach build --verbose
  120. [% IF c("var/android") %]
  121. # Building a multi-locale .apk
  122. [% FOREACH lang = c('var/locales');
  123. SET lang = tmpl(lang);
  124. # mk is unavailable on mobile.
  125. NEXT IF lang == 'mk'; %]
  126. # Copy our torbrowser_strings.dtd at the right place
  127. cp /var/tmp/dist/tba-translation/[% lang %]/torbrowser_strings.dtd /var/tmp/dist/locales/[% lang %]/mobile/android/base/
  128. ./mach build chrome-[% lang %];
  129. [% END %]
  130. # Include localization for all available locales.
  131. # mk is excluded above because Mozilla does not provide mk localization.
  132. # mk is included here because we may have localization for torbutton.
  133. export MOZ_CHROME_MULTILOCALE='[% tmpl(c('var/locales').join(' ')) %]'
  134. ./mach android assemble-app
  135. AB_CD=multi ./mach package
  136. # Copy the result over and return. There is nothing more to do for mobile.
  137. cp obj-*/dist/*unsigned-unaligned.apk [% dest_dir _ '/' _ c('filename') %]/tor-browser-unsigned-unaligned.apk
  138. [% RETURN %]
  139. [% END %]
  140. ./mach build stage-package
  141. [% IF c("var/osx") %]
  142. cp -a obj-macos/dist/firefox/* $distdir
  143. # Remove firefox-bin (we don't use it, see ticket #10126)
  144. rm -f "$distdir/Tor Browser.app/Contents/MacOS/firefox-bin"
  145. # Adjust the Info.plist file
  146. INFO_PLIST="$distdir/Tor Browser.app/Contents/Info.plist"
  147. mv "$INFO_PLIST" tmp.plist
  148. python $rootdir/fix-info-plist.py '[% c("var/torbrowser_version") %]' '[% c("var/copyright_year") %]' < tmp.plist > "$INFO_PLIST"
  149. rm -f tmp.plist
  150. [% END %]
  151. [% IF c("var/linux") %]
  152. [% IF c("var/linux-x86_64") %]
  153. cp obj-*/testing/geckodriver/x86_64-unknown-linux-gnu/release/geckodriver $distdir
  154. [% END %]
  155. cp -a obj-*/dist/firefox/* $distdir/Browser/
  156. # Remove firefox-bin (we don't use it, see ticket #10126)
  157. rm -f $distdir/Browser/firefox-bin
  158. # TODO: There goes FIPS-140.. We could upload these somewhere unique and
  159. # subsequent builds could test to see if they've been uploaded before...
  160. # But let's find out if it actually matters first..
  161. rm -f $distdir/Browser/*.chk
  162. # Replace firefox by a wrapper script (#25485)
  163. mv $distdir/Browser/firefox $distdir/Browser/firefox.real
  164. mv $rootdir/start-firefox $distdir/Browser/firefox
  165. chmod 755 $distdir/Browser/firefox
  166. [% END %]
  167. [% IF c("var/windows") %]
  168. cp -a obj-*/dist/firefox/* $distdir/Browser/
  169. cp -a /var/tmp/dist/fxc2/bin/d3dcompiler_47.dll $distdir/Browser
  170. [% END %]
  171. [% IF c("var/linux-cross") -%]
  172. #cp -a /var/tmp/dist/gcc-cross/[% c("var/crosstarget") %]/lib/libssp.so* $distdir/Browser
  173. [% END %]
  174. # Make MAR-based update tools available for use during the bundle phase.
  175. # Note that mar and mbsdiff are standalone tools, compiled for the build
  176. # host's architecture. We also include signmar, certutil, and the libraries
  177. # they require; these utilities and libraries are built for the target
  178. # architecture.
  179. MARTOOLS=$distdir/mar-tools
  180. mkdir -p $MARTOOLS
  181. cp -p config/createprecomplete.py $MARTOOLS/
  182. cp -p tools/update-packaging/*.sh $MARTOOLS/
  183. cp -p obj-*/dist/host/bin/mar $MARTOOLS/
  184. cp -p obj-*/dist/host/bin/mbsdiff $MARTOOLS/
  185. [% IF c("var/linux") || c("var/osx") %]
  186. cp -p obj-*/dist/bin/signmar $MARTOOLS/
  187. cp -p obj-*/dist/bin/certutil $MARTOOLS/
  188. cp -p obj-*/dist/bin/modutil $MARTOOLS/
  189. cp -p obj-*/dist/bin/pk12util $MARTOOLS/
  190. cp -p obj-*/dist/bin/shlibsign $MARTOOLS/
  191. [% IF c("var/linux") %]
  192. NSS_LIBS="libfreeblpriv3.so libmozsqlite3.so libnss3.so libnssckbi.so libnssdbm3.so libnssutil3.so libsmime3.so libsoftokn3.so libssl3.so"
  193. NSPR_LIBS="libnspr4.so libplc4.so libplds4.so"
  194. [% ELSE %]
  195. NSS_LIBS="libfreebl3.dylib libmozglue.dylib libnss3.dylib libnssckbi.dylib libnssdbm3.dylib libsoftokn3.dylib"
  196. # No NSPR_LIBS for macOS
  197. NSPR_LIBS=""
  198. [% END %]
  199. for LIB in $NSS_LIBS $NSPR_LIBS; do
  200. cp -p obj-*/dist/bin/$LIB $MARTOOLS/
  201. done
  202. [% END %]
  203. [% IF c("var/windows") %]
  204. cp -p obj-*/dist/bin/signmar.exe $MARTOOLS/
  205. cp -p obj-*/dist/bin/certutil.exe $MARTOOLS/
  206. cp -p obj-*/dist/bin/modutil.exe $MARTOOLS/
  207. cp -p obj-*/dist/bin/pk12util.exe $MARTOOLS/
  208. cp -p obj-*/dist/bin/shlibsign.exe $MARTOOLS/
  209. NSS_LIBS="freebl3.dll mozglue.dll nss3.dll nssckbi.dll nssdbm3.dll softokn3.dll"
  210. for LIB in $NSS_LIBS; do
  211. cp -p obj-*/dist/bin/$LIB $MARTOOLS/
  212. done
  213. [% END %]
  214. cd $distdir
  215. [% IF c("var/linux-x86_64") %]
  216. # No need for an unstripped geckodriver
  217. strip geckodriver
  218. mkdir -p $distdir/Debug/Browser/gtk2
  219. [% IF c("var/linux-cross") %]
  220. TARGET_OBJCOPY=[% c("var/crosstarget") %]-objcopy
  221. TARGET_STRIP=[% c("var/crosstarget") %]-strip
  222. [% ELSE %]
  223. TARGET_OBJCOPY=objcopy
  224. TARGET_STRIP=strip
  225. [% END %]
  226. # Strip and generate debuginfo for the firefox binary that we keep, all *.so
  227. # files, the plugin-container, and the updater (see ticket #10126)
  228. for LIB in Browser/*.so Browser/gtk2/*.so Browser/firefox.real Browser/plugin-container Browser/updater
  229. do
  230. $TARGET_OBJCOPY --only-keep-debug $LIB Debug/$LIB
  231. $TARGET_STRIP $LIB
  232. $TARGET_OBJCOPY --add-gnu-debuglink=./Debug/$LIB $LIB
  233. done
  234. [% END %]
  235. # Re-zipping the omni.ja files is not needed to make them reproductible,
  236. # however if we don't re-zip them, the files become corrupt when we
  237. # update them using 'zip' and firefox will silently fail to load some
  238. # parts.
  239. [% IF c("var/windows") || c("var/linux") %]
  240. [% c("var/rezip", { rezip_file => 'Browser/omni.ja' }) %]
  241. [% c("var/rezip", { rezip_file => 'Browser/browser/omni.ja' }) %]
  242. [% ELSIF c("var/osx") %]
  243. [% c("var/rezip", { rezip_file => '"Tor Browser.app/Contents/Resources/omni.ja"' }) %]
  244. [% c("var/rezip", { rezip_file => '"Tor Browser.app/Contents/Resources/browser/omni.ja"' }) %]
  245. [% END %]
  246. [%
  247. IF c("var/osx");
  248. SET browserdir='"Tor Browser.app/Contents"';
  249. ELSE;
  250. SET browserdir='Browser';
  251. END;
  252. %]
  253. [% IF c("var/linux") %]
  254. [% IF c("var/linux-cross") %]
  255. clang++ --target=[% c("var/crosstarget") %] $rootdir/abicheck.cc -o Browser/abicheck
  256. [% ELSE %]
  257. /var/tmp/dist/gcc/bin/g++ $rootdir/abicheck.cc -o Browser/abicheck
  258. [% END %]
  259. [% END %]
  260. [% c('tar', {
  261. tar_src => [ browserdir ],
  262. tar_args => '-czf ' _ dest_dir _ '/' _ c('filename') _ '/tor-browser.tar.gz',
  263. }) %]
  264. [% IF c("var/linux-x86_64") %]
  265. [% c('tar', {
  266. tar_src => [ 'Debug' ],
  267. tar_args => '-cJf ' _ dest_dir _ '/' _ c('filename') _ '/tor-browser-debug.tar.xz',
  268. }) %]
  269. [% c('tar', {
  270. tar_src => [ 'geckodriver' ],
  271. tar_args => '-cJf ' _ dest_dir _ '/' _ c('filename') _ '/geckodriver-linux64.tar.xz',
  272. }) %]
  273. [% END %]
  274. [% c('zip', {
  275. zip_src => [ 'mar-tools' ],
  276. zip_args => dest_dir _ '/' _ c('filename') _ '/' _ c('var/martools_filename'),
  277. }) %]
  278. [% IF c("var/build_infos_json") -%]
  279. cat > "[% dest_dir _ '/' _ c('filename') _ '/build-infos.json' %]" << EOF_BUILDINFOS
  280. {
  281. "firefox_platform_version" : "[% c("var/firefox_platform_version") %]",
  282. "firefox_buildid" : "$MOZ_BUILD_DATE"
  283. }
  284. EOF_BUILDINFOS
  285. [% END -%]