build 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321
  1. #!/bin/bash
  2. [% c("var/setarch") -%]
  3. [% c("var/set_default_env") -%]
  4. [% IF c("var/windows") -%]
  5. [% pc('gcc', 'var/setup', { compiler_tarfile => c('input_files_by_name/gcc') }) %]
  6. # We need a link to our GCC, otherwise the system cc gets used which points to
  7. # /usr/bin/gcc.
  8. ln -s gcc /var/tmp/dist/gcc/bin/cc
  9. [% END -%]
  10. [% pc(c('var/compiler'), 'var/setup', { compiler_tarfile => c('input_files_by_name/' _ c('var/compiler')) }) %]
  11. distdir=/var/tmp/dist/[% project %]
  12. mkdir -p /var/tmp/build
  13. mkdir -p [% dest_dir _ '/' _ c('filename') %]
  14. [% IF c("var/windows") -%]
  15. mingwdir=/var/tmp/dist/mingw-w64
  16. mkdir -p $mingwdir/helpers
  17. cat > $mingwdir/helpers/[% c("arch") %]-w64-mingw32-g++ << 'EOF'
  18. #!/bin/sh
  19. /var/tmp/dist/mingw-w64/bin/[% c("arch") %]-w64-mingw32-g++ [% c("var/LDFLAGS") %] [% c("var/CFLAGS") %] "$@"
  20. EOF
  21. cat > $mingwdir/helpers/[% c("arch") %]-w64-mingw32-gcc << 'EOF'
  22. #!/bin/sh
  23. /var/tmp/dist/mingw-w64/bin/[% c("arch") %]-w64-mingw32-gcc [% c("var/LDFLAGS") %] [% c("var/CFLAGS") %] "$@"
  24. EOF
  25. cat > $mingwdir/helpers/[% c("arch") %]-w64-mingw32-ld << 'EOF'
  26. #!/bin/sh
  27. /var/tmp/dist/mingw-w64/bin/[% c("arch") %]-w64-mingw32-ld [% c("var/LDFLAGS") %] "$@"
  28. EOF
  29. chmod +x $mingwdir/helpers/*
  30. export PATH="$mingwdir/helpers:$PATH"
  31. [% END -%]
  32. [% IF c("var/windows") %]
  33. # Unpack fxc2.
  34. mkdir -p /var/tmp/dist
  35. tar -C /var/tmp/dist -xf [% c('input_files_by_name/fxc2') %]
  36. fxcdir=/var/tmp/dist/fxc2/bin
  37. cp $mingwdir/[% c("arch") %]-w64-mingw32/bin/libwinpthread-1.dll $fxcdir
  38. export PATH="$fxcdir:$PATH"
  39. # fxc2 requires Wine.
  40. [% IF c("var/windows-x86_64") %]
  41. export WINEARCH=win64
  42. [% END %]
  43. export HOME=/var/tmp/home
  44. mkdir -p $HOME
  45. WINEROOT=$HOME/.wine/drive_c
  46. wine wineboot -i
  47. [% END -%]
  48. [% IF c("var/linux") %]
  49. mkdir -p /var/tmp/dist
  50. tar -C /var/tmp/dist -xf $rootdir/[% c('input_files_by_name/binutils') %]
  51. export PATH="/var/tmp/dist/binutils/bin:$PATH"
  52. [% END -%]
  53. mkdir -p /var/tmp/dist
  54. tar -C /var/tmp/dist -xf [% c('input_files_by_name/rust') %]
  55. export PATH="/var/tmp/dist/rust/bin:$PATH"
  56. [% IF c("var/linux") %]
  57. # Add llvm so stylo can build
  58. tar -C /var/tmp/dist -xf [% c('input_files_by_name/llvm') %]
  59. export LLVM_CONFIG="/var/tmp/dist/llvm/bin/llvm-config"
  60. [% END -%]
  61. tar -C /var/tmp/build -xf [% project %]-[% c('version') %].tar.gz
  62. [% IF c("var/osx") %]
  63. mkdir -p "$distdir/Tor Browser.app/Contents/MacOS"
  64. [% ELSE %]
  65. mkdir -p $distdir/Browser
  66. [% END %]
  67. cd /var/tmp/build/[% project %]-[% c("version") %]
  68. mv -f $rootdir/[% c('input_files_by_name/mozconfig') %] .mozconfig
  69. [% IF c("var/asan") -%]
  70. mv -f .mozconfig-asan .mozconfig
  71. # Without disabling LSan our build is blowing up:
  72. # https://bugs.torproject.org/10599#comment:52
  73. export ASAN_OPTIONS="detect_leaks=0"
  74. [% END -%]
  75. [% IF c("var/android") %]
  76. gradle_repo=/var/tmp/dist/gradle-dependencies
  77. export GRADLE_MAVEN_REPOSITORIES="file://$gradle_repo"
  78. # Move Gradle Repo to hard-coded location. This location is embedded in the file
  79. # chrome/toolkit/content/global/buildconfig.html so needs to be standard for reproducibility
  80. mv $rootdir/[% c('input_files_by_name/gradle-dependencies') %] $gradle_repo
  81. cp -r $gradle_repo/plugins-release/* $gradle_repo
  82. cp -r $gradle_repo/maven2/* $gradle_repo
  83. # Move Android library dependencies so they will be included in the apk during the build
  84. cp $rootdir/[% c('input_files_by_name/topl') %]/* mobile/android/app
  85. cp $rootdir/[% c('input_files_by_name/tor-android-service') %]/* mobile/android/app
  86. # Apply patches
  87. patch -p1 < $rootdir/android-dependencies.patch
  88. # Prepare building the multi-locale .apk including our own strings
  89. mkdir -p /var/tmp/dist/locales
  90. tar -C /var/tmp/dist/locales -xf $rootdir/[% c('input_files_by_name/firefox-locale-bundle') %]
  91. tar -C /var/tmp/dist -xf $rootdir/[% c('input_files_by_name/tba-translation') %]
  92. [% END %]
  93. eval $(perl $rootdir/get-moz-build-date [% c("var/copyright_year") %] [% c("var/torbrowser_version") %])
  94. if [ -z $MOZ_BUILD_DATE ]
  95. then
  96. echo "MOZ_BUILD_DATE is not set"
  97. exit 1
  98. fi
  99. [% IF c("var/windows") %]
  100. # FIXME
  101. # Ideally, using LDFLAGS (and e.g. DLLFLAGS for NSS) would be enough to get
  102. # all Firefox libraries linked against msvcr100. Alas, this does not hold for
  103. # NSPR. Without patching it we get a "missing entry points for _strcmpi in
  104. # msvcr100.dll". Now, this should be fixed in rev>=6179 as the def file there
  105. # contains a proper patch according to the mingw-w64 developers.
  106. # However, even with this patch the _strcmpi issue is still popping up,
  107. # probably due to a bug in our current linking setup. The small patch below
  108. # is therefore just a workaround which should get fixed but is at least
  109. # justified as the signature of _strcmpi and _stricmp is the same, see:
  110. # http://msdn.microsoft.com/en-us/library/k59z8dwe.aspx.
  111. sed 's/strcmpi/stricmp/' -i nsprpub/pr/src/linking/prlink.c
  112. export HOST_LDFLAGS=" "
  113. export LDFLAGS="-specs=/var/tmp/dist/mingw-w64/msvcr100.spec"
  114. # Our flags don't get passed to NSS. We need to do that manually using an
  115. # obscure one.
  116. export DLLFLAGS="-specs=/var/tmp/dist/mingw-w64/msvcr100.spec"
  117. # Make sure widl is not inserting random timestamps, see #21837.
  118. export WIDL_TIME_OVERRIDE="0"
  119. [% END %]
  120. [% IF c("var/osname") == "linux-i686" -%]
  121. export LDFLAGS=-m32
  122. export CFLAGS=-m32
  123. export CC='gcc -m32'
  124. [% END -%]
  125. [% IF c("var/windows") %]
  126. patch -p1 < $rootdir/nsis-uninstall.patch
  127. [% END -%]
  128. # Backporting a sec-high bugfix to ESR 60, but making sure it is only applied to
  129. # mobile, as desktop ESR has not seen any testing with this mobile-related patch
  130. [% IF c("var/android") %]
  131. patch -p1 < $rootdir/1527534.patch
  132. [% END -%]
  133. [% IF ! c("var/android") %]
  134. # Place a copy of the Tor Launcher sources under browser/extensions
  135. tar -C browser/extensions -xf $rootdir/[% c('input_files_by_name/tor-launcher') %]
  136. [% END -%]
  137. rm -f configure
  138. rm -f js/src/configure
  139. ./mach configure --with-tor-browser-version=[% c("var/torbrowser_version") %] --with-distribution-id=org.torproject --enable-update-channel=[% c("var/torbrowser_update_channel") %] --enable-bundled-fonts --with-branding=[% c("var/branding_directory") %]
  140. ./mach build --verbose
  141. [% IF c("var/android") %]
  142. # Building a multi-locale .apk
  143. [% FOREACH lang = c('var/locales');
  144. SET lang = tmpl(lang);
  145. # mk is unavailable on mobile.
  146. NEXT IF lang == 'mk'; %]
  147. # Copy our torbrowser_strings.dtd at the right place
  148. cp /var/tmp/dist/tba-translation/[% lang %]/torbrowser_strings.dtd /var/tmp/dist/locales/[% lang %]/mobile/android/base/
  149. ./mach build chrome-[% lang %];
  150. [% END %]
  151. export MOZ_CHROME_MULTILOCALE='[% tmpl(c('var/locales').join(' ')) %]'
  152. AB_CD=multi ./mach package
  153. # Copy the result over and return. There is nothing more to do for mobile.
  154. cp obj-*/dist/*unsigned-unaligned.apk [% dest_dir _ '/' _ c('filename') %]/tor-browser-unsigned-unaligned.apk
  155. [% RETURN %]
  156. [% END %]
  157. ./mach build stage-package
  158. [% IF c("var/osx") %]
  159. cp -a obj-macos/dist/firefox/* $distdir
  160. # Remove firefox-bin (we don't use it, see ticket #10126)
  161. rm -f "$distdir/Tor Browser.app/Contents/MacOS/firefox-bin"
  162. # Adjust the Info.plist file
  163. INFO_PLIST="$distdir/Tor Browser.app/Contents/Info.plist"
  164. mv "$INFO_PLIST" tmp.plist
  165. python $rootdir/fix-info-plist.py '[% c("var/torbrowser_version") %]' '[% c("var/copyright_year") %]' < tmp.plist > "$INFO_PLIST"
  166. rm -f tmp.plist
  167. [% END %]
  168. [% IF c("var/linux") %]
  169. cp -a obj-*/dist/firefox/* $distdir/Browser/
  170. # Remove firefox-bin (we don't use it, see ticket #10126)
  171. rm -f $distdir/Browser/firefox-bin
  172. # TODO: There goes FIPS-140.. We could upload these somewhere unique and
  173. # subsequent builds could test to see if they've been uploaded before...
  174. # But let's find out if it actually matters first..
  175. rm -f $distdir/Browser/*.chk
  176. # Replace firefox by a wrapper script (#25485)
  177. mv $distdir/Browser/firefox $distdir/Browser/firefox.real
  178. mv $rootdir/start-firefox $distdir/Browser/firefox
  179. chmod 755 $distdir/Browser/firefox
  180. [% END %]
  181. [% IF c("var/windows-x86_64") -%]
  182. mv $rootdir/msvcr100-x86_64.dll $rootdir/msvcr100.dll
  183. [% END -%]
  184. [% IF c("var/windows") %]
  185. cp -a obj-*/dist/firefox/* $distdir/Browser/
  186. cp -a $rootdir/msvcr100.dll $distdir/Browser
  187. cp -a $gcclibs/libssp-0.dll $distdir/Browser
  188. cp -a $fxcdir/d3dcompiler_47.dll $distdir/Browser
  189. [% END %]
  190. # Make MAR-based update tools available for use during the bundle phase.
  191. # Note that mar and mbsdiff are standalone tools, compiled for the build
  192. # host's architecture. We also include signmar, certutil, and the libraries
  193. # they require; these utilities and libraries are built for the target
  194. # architecture.
  195. MARTOOLS=$distdir/mar-tools
  196. mkdir -p $MARTOOLS
  197. cp -p config/createprecomplete.py $MARTOOLS/
  198. cp -p tools/update-packaging/*.sh $MARTOOLS/
  199. cp -p obj-*/dist/host/bin/mar $MARTOOLS/
  200. cp -p obj-*/dist/host/bin/mbsdiff $MARTOOLS/
  201. [% IF c("var/linux") %]
  202. cp -p obj-*/modules/libmar/tool/signmar $MARTOOLS/
  203. cp -p obj-*/security/nss/cmd/certutil/certutil_certutil/certutil $MARTOOLS/
  204. cp -p obj-*/security/nss/cmd/modutil/modutil_modutil/modutil $MARTOOLS/
  205. cp -p obj-*/security/nss/cmd/pk12util/pk12util_pk12util/pk12util $MARTOOLS/
  206. cp -p obj-*/security/nss/cmd/shlibsign/shlibsign_shlibsign/shlibsign $MARTOOLS/
  207. NSS_LIBS="libfreeblpriv3.so libmozsqlite3.so libnss3.so libnssckbi.so libnssdbm3.so libnssutil3.so libsmime3.so libsoftokn3.so libssl3.so"
  208. NSPR_LIBS="libnspr4.so libplc4.so libplds4.so"
  209. for LIB in $NSS_LIBS $NSPR_LIBS; do
  210. cp -p obj-*/dist/bin/$LIB $MARTOOLS/
  211. done
  212. [% END %]
  213. [% IF c("var/osx") %]
  214. cp -p obj-*/modules/libmar/tool/signmar $MARTOOLS/
  215. cp -p obj-*/security/nss/cmd/certutil/certutil_certutil/certutil $MARTOOLS/
  216. cp -p obj-*/security/nss/cmd/modutil/modutil_modutil/modutil $MARTOOLS/
  217. cp -p obj-*/security/nss/cmd/pk12util/pk12util_pk12util/pk12util $MARTOOLS/
  218. cp -p obj-*/security/nss/cmd/shlibsign/shlibsign_shlibsign/shlibsign $MARTOOLS/
  219. NSS_LIBS="libfreebl3.dylib libmozglue.dylib libnss3.dylib libnssckbi.dylib libnssdbm3.dylib libsoftokn3.dylib"
  220. for LIB in $NSS_LIBS; do
  221. cp -p obj-*/dist/bin/$LIB $MARTOOLS/
  222. done
  223. [% END %]
  224. [% IF c("var/windows") %]
  225. cp -p obj-*/modules/libmar/tool/signmar.exe $MARTOOLS/
  226. cp -p obj-*/security/nss/cmd/certutil/certutil_certutil/certutil.exe $MARTOOLS/
  227. cp -p obj-*/security/nss/cmd/modutil/modutil_modutil/modutil.exe $MARTOOLS/
  228. cp -p obj-*/security/nss/cmd/pk12util/pk12util_pk12util/pk12util.exe $MARTOOLS/
  229. cp -p obj-*/security/nss/cmd/shlibsign/shlibsign_shlibsign/shlibsign.exe $MARTOOLS/
  230. NSS_LIBS="freebl3.dll mozglue.dll nss3.dll nssckbi.dll nssdbm3.dll softokn3.dll"
  231. for LIB in $NSS_LIBS; do
  232. cp -p obj-*/dist/bin/$LIB $MARTOOLS/
  233. done
  234. cp -a $rootdir/msvcr100.dll $MARTOOLS/
  235. [% END %]
  236. cd $distdir
  237. [% IF c("var/linux") %]
  238. mkdir -p $distdir/Debug/Browser/gtk2
  239. # Strip and generate debuginfo for the firefox binary that we keep, all *.so
  240. # files, the plugin-container, and the updater (see ticket #10126)
  241. for LIB in Browser/*.so Browser/gtk2/*.so Browser/firefox.real Browser/plugin-container Browser/updater
  242. do
  243. objcopy --only-keep-debug $LIB Debug/$LIB
  244. strip $LIB
  245. objcopy --add-gnu-debuglink=./Debug/$LIB $LIB
  246. done
  247. [% END %]
  248. # Re-zipping the omni.ja files is not needed to make them reproductible,
  249. # however if we don't re-zip them, the files become corrupt when we
  250. # update them using 'zip' and firefox will silently fail to load some
  251. # parts.
  252. [% IF c("var/windows") || c("var/linux") %]
  253. [% c("var/rezip", { rezip_file => 'Browser/omni.ja' }) %]
  254. [% c("var/rezip", { rezip_file => 'Browser/browser/omni.ja' }) %]
  255. [% ELSIF c("var/osx") %]
  256. [% c("var/rezip", { rezip_file => '"Tor Browser.app/Contents/Resources/omni.ja"' }) %]
  257. [% c("var/rezip", { rezip_file => '"Tor Browser.app/Contents/Resources/browser/omni.ja"' }) %]
  258. [% END %]
  259. [%
  260. IF c("var/osx");
  261. SET browserdir='"Tor Browser.app/Contents"';
  262. ELSE;
  263. SET browserdir='Browser';
  264. END;
  265. %]
  266. [% IF c("var/linux") %]
  267. /var/tmp/dist/gcc/bin/g++ $rootdir/abicheck.cc -o Browser/abicheck
  268. [% END %]
  269. [% c('tar', {
  270. tar_src => [ browserdir ],
  271. tar_args => '-czf ' _ dest_dir _ '/' _ c('filename') _ '/tor-browser.tar.gz',
  272. }) %]
  273. [% IF c("var/linux") %]
  274. [% c('tar', {
  275. tar_src => [ 'Debug' ],
  276. tar_args => '-cJf ' _ dest_dir _ '/' _ c('filename') _ '/tor-browser-debug.tar.xz',
  277. }) %]
  278. [% END %]
  279. [% c('zip', {
  280. zip_src => [ 'mar-tools' ],
  281. zip_args => dest_dir _ '/' _ c('filename') _ '/' _ c('var/martools_filename'),
  282. }) %]