build 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294
  1. #!/bin/bash
  2. [% c("var/set_default_env") -%]
  3. [% pc(c('var/compiler'), 'var/setup', { compiler_tarfile => c('input_files_by_name/' _ c('var/compiler')) }) %]
  4. distdir=/var/tmp/dist/[% project %]
  5. mkdir -p /var/tmp/build
  6. mkdir -p [% dest_dir _ '/' _ c('filename') %]
  7. [% IF c("var/windows") %]
  8. # Setting up fxc2
  9. tar -C /var/tmp/dist -xf [% c('input_files_by_name/fxc2') %]
  10. export PATH="/var/tmp/dist/fxc2/bin:$PATH"
  11. # fxc2 requires Wine.
  12. export WINEARCH=[% IF c("var/windows-x86_64") %]win64[% ELSE %]win32[% END %]
  13. export HOME=/var/tmp/home
  14. mkdir -p $HOME
  15. WINEROOT=$HOME/.wine/drive_c
  16. wine wineboot -i
  17. # Setting up stack protector support
  18. tar -C /var/tmp/dist -xf [% c('input_files_by_name/mingw-w64') %]
  19. cp /var/tmp/dist/mingw-w64/gcclibs/{libssp.a,libssp_nonshared.a} /var/tmp/dist/mingw-w64-clang/[% c("arch") %]-w64-mingw32/lib/
  20. [% END -%]
  21. tar -C /var/tmp/dist -xf [% c('input_files_by_name/rust') %]
  22. tar -C /var/tmp/dist -xf [% c('input_files_by_name/cbindgen') %]
  23. tar -C /var/tmp/dist -xf [% c('input_files_by_name/nasm') %]
  24. tar -C /var/tmp/dist -xf [% c('input_files_by_name/python') %]
  25. tar -C /var/tmp/dist -xf [% c('input_files_by_name/node') %]
  26. export PATH="/var/tmp/dist/rust/bin:/var/tmp/dist/cbindgen:/var/tmp/dist/nasm/bin:/var/tmp/dist/python/bin:/var/tmp/dist/node/bin:$PATH"
  27. tar -C /var/tmp/dist -xf [% c('input_files_by_name/clang') %]
  28. export LLVM_CONFIG="/var/tmp/dist/clang/bin/llvm-config"
  29. [% IF c("var/linux") || c("var/android") %]
  30. tar -C /var/tmp/dist -xf $rootdir/[% c('input_files_by_name/binutils') %]
  31. export PATH="/var/tmp/dist/binutils/bin:$PATH"
  32. # Use clang for everything on Linux and Android now if we don't build with
  33. # ASan.
  34. [% IF ! c("var/asan") -%]
  35. export PATH="/var/tmp/dist/clang/bin:$PATH"
  36. [% END -%]
  37. [% END -%]
  38. tar -C /var/tmp/build -xf [% project %]-[% c('version') %].tar.gz
  39. [% IF c("var/osx") %]
  40. mkdir -p "$distdir/Tor Browser.app/Contents/MacOS"
  41. [% ELSE %]
  42. mkdir -p $distdir/Browser
  43. [% END %]
  44. cd /var/tmp/build/[% project %]-[% c("version") %]
  45. mv -f $rootdir/[% c('input_files_by_name/mozconfig') %] .mozconfig
  46. [% IF c("var/asan") -%]
  47. mv -f .mozconfig-asan .mozconfig
  48. # Without disabling LSan our build is blowing up:
  49. # https://bugs.torproject.org/10599#comment:52
  50. export ASAN_OPTIONS="detect_leaks=0"
  51. [% END -%]
  52. [% IF c("var/android") %]
  53. export JAVA_HOME=/usr/lib/jvm/java-1.8.0-openjdk-amd64
  54. gradle_repo=/var/tmp/dist/gradle-dependencies
  55. export GRADLE_MAVEN_REPOSITORIES="file://$gradle_repo"
  56. export GRADLE_FLAGS="--no-daemon --offline"
  57. # Move Gradle Repo to hard-coded location. This location is embedded in the file
  58. # chrome/toolkit/content/global/buildconfig.html so needs to be standard for reproducibility
  59. mv $rootdir/[% c('input_files_by_name/gradle-dependencies') %] $gradle_repo
  60. cp -r $gradle_repo/m2/* $gradle_repo
  61. # Move Android library dependencies so they will be included in the apk during the build
  62. cp $rootdir/[% c('input_files_by_name/topl') %]/* mobile/android/app
  63. cp $rootdir/[% c('input_files_by_name/tor-android-service') %]/* mobile/android/app
  64. # Move emulator to location that firefox build expects
  65. mkdir /var/tmp/dist/android-toolchain/android-sdk-linux/emulator
  66. cp /var/tmp/dist/android-toolchain/android-sdk-linux/tools/emulator /var/tmp/dist/android-toolchain/android-sdk-linux/emulator
  67. # Prepare building the multi-locale .apk including our own strings
  68. mkdir -p /var/tmp/dist/locales
  69. tar -C /var/tmp/dist/locales -xf $rootdir/[% c('input_files_by_name/firefox-locale-bundle') %]
  70. tar -C /var/tmp/dist -xf $rootdir/[% c('input_files_by_name/tba-translation') %]
  71. [% END %]
  72. eval $(perl $rootdir/get-moz-build-date [% c("var/copyright_year") %] [% c("var/torbrowser_version") %])
  73. if [ -z $MOZ_BUILD_DATE ]
  74. then
  75. echo "MOZ_BUILD_DATE is not set"
  76. exit 1
  77. fi
  78. [% IF c("var/windows") %]
  79. # Make sure widl is not inserting random timestamps, see #21837.
  80. export WIDL_TIME_OVERRIDE="0"
  81. patch -p1 < $rootdir/nsis-uninstall.patch
  82. # Make sure we link without inserting timestamps in general.
  83. export LDFLAGS="-Wl,--no-insert-timestamp"
  84. [% END -%]
  85. [% IF c("var/namecoin") %]
  86. patch -p1 < $rootdir/namecoin-etld.patch
  87. [% END -%]
  88. [% IF ! c("var/android") %]
  89. # Place a copy of the Tor Launcher sources under browser/extensions
  90. tar -C browser/extensions -xf $rootdir/[% c('input_files_by_name/tor-launcher') %]
  91. [% END -%]
  92. [% IF c("var/namecoin") %]
  93. pushd toolkit/torproject/torbutton
  94. patch -p1 < $rootdir/namecoin-torbutton.patch
  95. popd
  96. [% END %]
  97. [% IF c("var/nightly") -%]
  98. # Add nightly mar signing key (#33403)
  99. cp $rootdir/nightly-marsigner.der toolkit/mozapps/update/updater/nightly_aurora_level3_primary.der
  100. cp $rootdir/nightly-marsigner.der toolkit/mozapps/update/updater/nightly_aurora_level3_secondary.der
  101. # Set app.update.url for nightly (#33402)
  102. sed -i 's|pref("app\.update\.url",.*|pref("app.update.url", "https://nightlies.tbb.torproject.org/nightly-updates/updates/nightly-[% c("var/osname") %]/%CHANNEL%/%BUILD_TARGET%/%VERSION%/%LOCALE%");|' browser/app/profile/firefox.js
  103. [% END -%]
  104. rm -f configure
  105. rm -f js/src/configure
  106. # Android does not support --enable-bundled-fonts option
  107. ./mach configure --with-tor-browser-version=[% c("var/torbrowser_version") %] --with-distribution-id=org.torproject --enable-update-channel=[% c("var/channel") %] [% IF ! c("var/android") %]--enable-bundled-fonts[% END -%] --with-branding=[% c("var/branding_directory") %]
  108. ./mach build --verbose
  109. [% IF c("var/android") %]
  110. # Building a multi-locale .apk
  111. [% FOREACH lang = c('var/locales');
  112. SET lang = tmpl(lang);
  113. # mk is unavailable on mobile.
  114. NEXT IF lang == 'mk'; %]
  115. # Copy our torbrowser_strings.dtd at the right place
  116. cp /var/tmp/dist/tba-translation/[% lang %]/torbrowser_strings.dtd /var/tmp/dist/locales/[% lang %]/mobile/android/base/
  117. ./mach build chrome-[% lang %];
  118. [% END %]
  119. # Include localization for all available locales.
  120. # mk is excluded above because Mozilla does not provide mk localization.
  121. # mk is included here because we may have localization for torbutton.
  122. export MOZ_CHROME_MULTILOCALE='[% tmpl(c('var/locales').join(' ')) %]'
  123. ./mach android assemble-app
  124. AB_CD=multi ./mach package
  125. # Copy the result over and return. There is nothing more to do for mobile.
  126. cp obj-*/dist/*unsigned-unaligned.apk [% dest_dir _ '/' _ c('filename') %]/tor-browser-unsigned-unaligned.apk
  127. [% RETURN %]
  128. [% END %]
  129. ./mach build stage-package
  130. [% IF c("var/osx") %]
  131. cp -a obj-macos/dist/firefox/* $distdir
  132. # Remove firefox-bin (we don't use it, see ticket #10126)
  133. rm -f "$distdir/Tor Browser.app/Contents/MacOS/firefox-bin"
  134. # Adjust the Info.plist file
  135. INFO_PLIST="$distdir/Tor Browser.app/Contents/Info.plist"
  136. mv "$INFO_PLIST" tmp.plist
  137. python $rootdir/fix-info-plist.py '[% c("var/torbrowser_version") %]' '[% c("var/copyright_year") %]' < tmp.plist > "$INFO_PLIST"
  138. rm -f tmp.plist
  139. [% END %]
  140. [% IF c("var/linux") %]
  141. [% IF c("var/linux-x86_64") %]
  142. cp obj-*/testing/geckodriver/x86_64-unknown-linux-gnu/release/geckodriver $distdir
  143. [% END %]
  144. cp -a obj-*/dist/firefox/* $distdir/Browser/
  145. # Remove firefox-bin (we don't use it, see ticket #10126)
  146. rm -f $distdir/Browser/firefox-bin
  147. # TODO: There goes FIPS-140.. We could upload these somewhere unique and
  148. # subsequent builds could test to see if they've been uploaded before...
  149. # But let's find out if it actually matters first..
  150. rm -f $distdir/Browser/*.chk
  151. # Replace firefox by a wrapper script (#25485)
  152. mv $distdir/Browser/firefox $distdir/Browser/firefox.real
  153. mv $rootdir/start-firefox $distdir/Browser/firefox
  154. chmod 755 $distdir/Browser/firefox
  155. [% END %]
  156. [% IF c("var/windows") %]
  157. cp -a obj-*/dist/firefox/* $distdir/Browser/
  158. cp -a /var/tmp/dist/fxc2/bin/d3dcompiler_47.dll $distdir/Browser
  159. [% END %]
  160. # Make MAR-based update tools available for use during the bundle phase.
  161. # Note that mar and mbsdiff are standalone tools, compiled for the build
  162. # host's architecture. We also include signmar, certutil, and the libraries
  163. # they require; these utilities and libraries are built for the target
  164. # architecture.
  165. MARTOOLS=$distdir/mar-tools
  166. mkdir -p $MARTOOLS
  167. cp -p config/createprecomplete.py $MARTOOLS/
  168. cp -p tools/update-packaging/*.sh $MARTOOLS/
  169. cp -p obj-*/dist/host/bin/mar $MARTOOLS/
  170. cp -p obj-*/dist/host/bin/mbsdiff $MARTOOLS/
  171. [% IF c("var/linux") || c("var/osx") %]
  172. cp -p obj-*/dist/bin/signmar $MARTOOLS/
  173. cp -p obj-*/dist/bin/certutil $MARTOOLS/
  174. cp -p obj-*/dist/bin/modutil $MARTOOLS/
  175. cp -p obj-*/dist/bin/pk12util $MARTOOLS/
  176. cp -p obj-*/dist/bin/shlibsign $MARTOOLS/
  177. [% IF c("var/linux") %]
  178. NSS_LIBS="libfreeblpriv3.so libmozsqlite3.so libnss3.so libnssckbi.so libnssdbm3.so libnssutil3.so libsmime3.so libsoftokn3.so libssl3.so"
  179. NSPR_LIBS="libnspr4.so libplc4.so libplds4.so"
  180. [% ELSE %]
  181. NSS_LIBS="libfreebl3.dylib libmozglue.dylib libnss3.dylib libnssckbi.dylib libnssdbm3.dylib libsoftokn3.dylib"
  182. # No NSPR_LIBS for macOS
  183. NSPR_LIBS=""
  184. [% END %]
  185. for LIB in $NSS_LIBS $NSPR_LIBS; do
  186. cp -p obj-*/dist/bin/$LIB $MARTOOLS/
  187. done
  188. [% END %]
  189. [% IF c("var/windows") %]
  190. cp -p obj-*/dist/bin/signmar.exe $MARTOOLS/
  191. cp -p obj-*/dist/bin/certutil.exe $MARTOOLS/
  192. cp -p obj-*/dist/bin/modutil.exe $MARTOOLS/
  193. cp -p obj-*/dist/bin/pk12util.exe $MARTOOLS/
  194. cp -p obj-*/dist/bin/shlibsign.exe $MARTOOLS/
  195. NSS_LIBS="freebl3.dll mozglue.dll nss3.dll nssckbi.dll nssdbm3.dll softokn3.dll"
  196. for LIB in $NSS_LIBS; do
  197. cp -p obj-*/dist/bin/$LIB $MARTOOLS/
  198. done
  199. [% END %]
  200. cd $distdir
  201. [% IF c("var/linux-x86_64") %]
  202. # No need for an unstripped geckodriver
  203. strip geckodriver
  204. mkdir -p $distdir/Debug/Browser/gtk2
  205. # Strip and generate debuginfo for the firefox binary that we keep, all *.so
  206. # files, the plugin-container, and the updater (see ticket #10126)
  207. for LIB in Browser/*.so Browser/gtk2/*.so Browser/firefox.real Browser/plugin-container Browser/updater
  208. do
  209. objcopy --only-keep-debug $LIB Debug/$LIB
  210. strip $LIB
  211. objcopy --add-gnu-debuglink=./Debug/$LIB $LIB
  212. done
  213. [% END %]
  214. # Re-zipping the omni.ja files is not needed to make them reproductible,
  215. # however if we don't re-zip them, the files become corrupt when we
  216. # update them using 'zip' and firefox will silently fail to load some
  217. # parts.
  218. [% IF c("var/windows") || c("var/linux") %]
  219. [% c("var/rezip", { rezip_file => 'Browser/omni.ja' }) %]
  220. [% c("var/rezip", { rezip_file => 'Browser/browser/omni.ja' }) %]
  221. [% ELSIF c("var/osx") %]
  222. [% c("var/rezip", { rezip_file => '"Tor Browser.app/Contents/Resources/omni.ja"' }) %]
  223. [% c("var/rezip", { rezip_file => '"Tor Browser.app/Contents/Resources/browser/omni.ja"' }) %]
  224. [% END %]
  225. [%
  226. IF c("var/osx");
  227. SET browserdir='"Tor Browser.app/Contents"';
  228. ELSE;
  229. SET browserdir='Browser';
  230. END;
  231. %]
  232. [% IF c("var/linux") %]
  233. /var/tmp/dist/gcc/bin/g++ $rootdir/abicheck.cc -o Browser/abicheck
  234. [% END %]
  235. [% c('tar', {
  236. tar_src => [ browserdir ],
  237. tar_args => '-czf ' _ dest_dir _ '/' _ c('filename') _ '/tor-browser.tar.gz',
  238. }) %]
  239. [% IF c("var/linux-x86_64") %]
  240. [% c('tar', {
  241. tar_src => [ 'Debug' ],
  242. tar_args => '-cJf ' _ dest_dir _ '/' _ c('filename') _ '/tor-browser-debug.tar.xz',
  243. }) %]
  244. [% c('tar', {
  245. tar_src => [ 'geckodriver' ],
  246. tar_args => '-cJf ' _ dest_dir _ '/' _ c('filename') _ '/geckodriver-linux64.tar.xz',
  247. }) %]
  248. [% END %]
  249. [% c('zip', {
  250. zip_src => [ 'mar-tools' ],
  251. zip_args => dest_dir _ '/' _ c('filename') _ '/' _ c('var/martools_filename'),
  252. }) %]
  253. [% IF c("var/build_infos_json") -%]
  254. cat > "[% dest_dir _ '/' _ c('filename') _ '/build-infos.json' %]" << EOF_BUILDINFOS
  255. {
  256. "firefox_platform_version" : "[% c("var/firefox_platform_version") %]",
  257. "firefox_buildid" : "$MOZ_BUILD_DATE"
  258. }
  259. EOF_BUILDINFOS
  260. [% END -%]