From 205211d101acbeb56697a2bed7a39acdaf44457e Mon Sep 17 00:00:00 2001 From: Peter Bukva Date: Mon, 7 Sep 2026 14:04:43 +0100 Subject: [PATCH 1/5] First attempt --- Makefile | 36 +++++++++++++++++++++++++----------- 1 file changed, 25 insertions(+), 11 deletions(-) diff --git a/Makefile b/Makefile index 873b8bfb3..dc6eecb91 100644 --- a/Makefile +++ b/Makefile @@ -63,10 +63,18 @@ ldflags = -X github.com/cosmos/cosmos-sdk/version.Name=fetch \ ifeq ($(WITH_CLEVELDB),yes) ldflags += -X github.com/cosmos/cosmos-sdk/types.DBBackend=cleveldb endif + +ifeq ($(LINK_STATICALLY),true) + extldflags += -Wl,-z,muldefs -static-pie -z noexecstack + ldflags += -linkmode=external -extldflags "$(extldflags)" +endif + ldflags += $(LDFLAGS) ldflags := $(strip $(ldflags)) -BUILD_FLAGS := -tags $(build_tags_comma_sep) -ldflags '$(ldflags)' -trimpath +# PIE is enabled by default for all builds +buildmode_flags += -buildmode=pie +BUILD_FLAGS := -tags "$(build_tags_comma_sep)" -ldflags '$(ldflags)' -trimpath $(buildmode_flags) # The below include contains the tools target. #include contrib/devtools/Makefile @@ -83,6 +91,9 @@ endif build-linux: go.sum LEDGER_ENABLED=false GOOS=linux GOARCH=amd64 $(MAKE) build +build-linux-static: go.sum + LEDGER_ENABLED=false GOOS=linux GOARCH=amd64 LINK_STATICALLY=true $(MAKE) build + build-contract-tests-hooks: ifeq ($(OS),Windows_NT) go build -mod=readonly $(BUILD_FLAGS) -o build/contract_tests.exe ./cmd/contract_tests @@ -123,21 +134,21 @@ test: test-unit test-all: test-unit test-ledger-mock test-race test-cover TEST_PACKAGES=./... -TEST_TARGETS := test-unit test-unit-amino test-unit-proto test-ledger-mock test-race test-ledger test-race +TEST_TARGETS := test-unit test-unit-amino test-ledger-mock test-race test-ledger test-race -# Test runs-specific rules. To add a new test target, just add -# a new rule, customise ARGS or TEST_PACKAGES ad libitum, and -# append the new rule to the TEST_TARGETS list. +# Test runs-specific rules. To add a new test target, customise ARGS or +# TEST_PACKAGES ad libitum, and append the new rule to the TEST_TARGETS list. UNIT_TEST_ARGS = cgo ledger test_ledger_mock norace AMINO_TEST_ARGS = ledger test_ledger_mock test_amino norace LEDGER_TEST_ARGS = cgo ledger norace LEDGER_MOCK_ARGS = ledger test_ledger_mock norace TEST_RACE_ARGS = cgo ledger test_ledger_mock + ifeq ($(EXPERIMENTAL),true) UNIT_TEST_ARGS += experimental AMINO_TEST_ARGS += experimental - LEDGER_TEST_ARGS += experimental - LEDGER_MOCK_ARGS += experimental + LEDGER_TEST_ARGS += experimental + LEDGER_MOCK_ARGS += experimental TEST_RACE_ARGS += experimental endif @@ -152,6 +163,7 @@ $(TEST_TARGETS): run-tests SUB_MODULES = $(shell find . -type f -name 'go.mod' -print0 | xargs -0 -n1 dirname | sort) CURRENT_DIR = $(shell pwd) + run-tests: ifneq (,$(shell which tparse 2>/dev/null)) @echo "Unit tests"; \ @@ -190,11 +202,11 @@ localnet-start: build-linux localnet-stop @if ! [ -f build/node0/fetchd/config/genesis.json ]; then docker run --rm -v $(CURDIR)/build:/fetchd:Z tendermint/fetchdnode testnet --v 4 -o . --starting-ip-address 192.168.10.2 ; fi docker-compose up -d -# Stop testnet +# Stop local testnet localnet-stop: docker-compose down -.PHONY: all build-linux install install-debug \ +.PHONY: all build-linux build-linux-static-pie install install-debug \ go-mod-cache draw-deps clean build \ test test-all test-cover test-unit test-race @@ -242,15 +254,17 @@ COSMOS_PROTO_URL = https://raw.githubusercontent.com/cosmos/cosmos-sdk/master/ GOGO_PROTO_TYPES = third_party/proto/gogoproto REGEN_COSMOS_PROTO_TYPES = third_party/proto/cosmos_proto -COSMOS_PROTO_TYPES = third_party/proto/cosmos +COSMOS_PROTO_TYPES = third_party/proto/cosmos_proto proto-update-deps: @mkdir -p $(GOGO_PROTO_TYPES) - @curl -sSL $(GOGO_PROTO_URL)/gogoproto/gogo.proto > $(GOGO_PROTO_TYPES)/gogo.proto + @curl -sSL $(GOGO_PROTO_URL)/gogoproto/gogoproto.proto > $(GOGO_PROTO_TYPES)/gogoproto.proto @mkdir -p $(REGEN_COSMOS_PROTO_TYPES) @curl -sSL $(REGEN_COSMOS_PROTO_URL)/cosmos.proto > $(REGEN_COSMOS_PROTO_TYPES)/cosmos.proto @mkdir -p $(COSMOS_PROTO_TYPES)/base/query/v1beta1/ @curl -sSL $(COSMOS_PROTO_URL)/base/query/v1beta1/pagination.proto > $(COSMOS_PROTO_TYPES)/base/query/v1beta1/pagination.proto + + @mkdir -p $(COSMOS_PROTO_TYPES)/base/v1beta1/ @curl -sSL $(COSMOS_PROTO_URL)/base/v1beta1/coin.proto > $(COSMOS_PROTO_TYPES)/base/v1beta1/coin.proto From 39628a851bf04ace35855eb28d7c1749eb45bb0d Mon Sep 17 00:00:00 2001 From: Peter Bukva Date: Mon, 7 Sep 2026 14:04:54 +0100 Subject: [PATCH 2/5] Support macos and linux correctly --- Makefile | 42 ++++++++++++++++++++++++++++++++---------- 1 file changed, 32 insertions(+), 10 deletions(-) diff --git a/Makefile b/Makefile index dc6eecb91..9542c694c 100644 --- a/Makefile +++ b/Makefile @@ -5,6 +5,7 @@ PACKAGES_SIMTEST=$(shell go list ./... | grep '/simulation') VERSION := $(shell echo $(shell git describe --tags)) COMMIT := $(shell git log -1 --format='%H') LEDGER_ENABLED ?= true +STATIC_PIE ?= true BINDIR ?= $(GOPATH)/bin BUILDDIR ?= $(CURDIR)/build APP_DIR = ./app @@ -15,6 +16,10 @@ PROJECT_NAME = $(shell git remote get-url origin | xargs basename -s .git) export GO111MODULE = on +# Resolve the target OS used by Go. +# This works both for native builds and explicit cross-compilation. +BUILD_GOOS := $(shell go env GOOS) + # process build tags build_tags = netgo @@ -64,16 +69,30 @@ ifeq ($(WITH_CLEVELDB),yes) ldflags += -X github.com/cosmos/cosmos-sdk/types.DBBackend=cleveldb endif -ifeq ($(LINK_STATICALLY),true) - extldflags += -Wl,-z,muldefs -static-pie -z noexecstack - ldflags += -linkmode=external -extldflags "$(extldflags)" +# PIE is enabled for all builds. +# +# PIE and static linking are independent properties: +# -buildmode=pie -> position-independent executable +# -static-pie -> Linux static linking of the PIE executable +buildmode_flags += -buildmode=pie + +# Static PIE is supported here only for Linux. +# +# STATIC_PIE=true requests a statically linked PIE executable. +# The Linux-specific external linker flags must not be passed to +# macOS or Windows builds. +ifeq ($(STATIC_PIE),true) + ifeq ($(BUILD_GOOS),linux) + extldflags += -Wl,-z,muldefs -static-pie -z noexecstack + ldflags += -linkmode=external -extldflags "$(extldflags)" + else + $(warning STATIC_PIE=true requested for $(BUILD_GOOS); Linux static-PIE linker flags will not be applied) + endif endif ldflags += $(LDFLAGS) ldflags := $(strip $(ldflags)) -# PIE is enabled by default for all builds -buildmode_flags += -buildmode=pie BUILD_FLAGS := -tags "$(build_tags_comma_sep)" -ldflags '$(ldflags)' -trimpath $(buildmode_flags) # The below include contains the tools target. @@ -88,11 +107,14 @@ else go build -mod=readonly $(BUILD_FLAGS) -o build/fetchd ./cmd/fetchd endif +# Build for Linux while preserving the target architecture supplied by +# the environment (or Go's native GOARCH default). build-linux: go.sum - LEDGER_ENABLED=false GOOS=linux GOARCH=amd64 $(MAKE) build + GOOS=linux $(MAKE) build +# Build a Linux static PIE while preserving the target architecture. build-linux-static: go.sum - LEDGER_ENABLED=false GOOS=linux GOARCH=amd64 LINK_STATICALLY=true $(MAKE) build + GOOS=linux STATIC_PIE=true $(MAKE) build build-contract-tests-hooks: ifeq ($(OS),Windows_NT) @@ -206,7 +228,7 @@ localnet-start: build-linux localnet-stop localnet-stop: docker-compose down -.PHONY: all build-linux build-linux-static-pie install install-debug \ +.PHONY: all build-linux build-linux-static install install-debug \ go-mod-cache draw-deps clean build \ test test-all test-cover test-unit test-race @@ -222,7 +244,7 @@ containerProtoFmt=${PROJECT_NAME}-proto-fmt-$(containerProtoVer) containerProtoGenSwagger=${PROJECT_NAME}-proto-gen-swagger-$(containerProtoVer) proto-all: proto-gen proto-lint proto-check-breaking proto-format -.PHONY: proto-all proto-gen proto-gen-docker proto-lint proto-check-breaking proto-format +.PHONY: proto-all proto-gen proto-lint proto-check-breaking proto-format proto-gen: @echo "Generating Protobuf files" @@ -246,7 +268,7 @@ proto-check-breaking: @$(DOCKER_BUF) breaking --against $(HTTPS_GIT)#branch=master proto-check-breaking-direct: - @buf breaking --against '.git#branch=master' + @$(DOCKER_BUF) breaking --against '.git#branch=master' GOGO_PROTO_URL = https://raw.githubusercontent.com/regen-network/protobuf/cosmos REGEN_COSMOS_PROTO_URL = https://raw.githubusercontent.com/regen-network/cosmos-proto/master From 9a9a5bbc226fcd2084c77e9b6bbfc35eb37c172e Mon Sep 17 00:00:00 2001 From: Peter Bukva Date: Mon, 7 Sep 2026 14:35:10 +0100 Subject: [PATCH 3/5] Reverting to original v0.15.0 `proto-update-deps:` and `COSMOS_PROTO_TYPES` --- Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Makefile b/Makefile index 9542c694c..cdb3d65b1 100644 --- a/Makefile +++ b/Makefile @@ -276,11 +276,11 @@ COSMOS_PROTO_URL = https://raw.githubusercontent.com/cosmos/cosmos-sdk/master/ GOGO_PROTO_TYPES = third_party/proto/gogoproto REGEN_COSMOS_PROTO_TYPES = third_party/proto/cosmos_proto -COSMOS_PROTO_TYPES = third_party/proto/cosmos_proto +COSMOS_PROTO_TYPES = third_party/proto/cosmos proto-update-deps: @mkdir -p $(GOGO_PROTO_TYPES) - @curl -sSL $(GOGO_PROTO_URL)/gogoproto/gogoproto.proto > $(GOGO_PROTO_TYPES)/gogoproto.proto + @curl -sSL $(GOGO_PROTO_URL)/gogoproto/gogo.proto > $(GOGO_PROTO_TYPES)/gogo.proto @mkdir -p $(REGEN_COSMOS_PROTO_TYPES) @curl -sSL $(REGEN_COSMOS_PROTO_URL)/cosmos.proto > $(REGEN_COSMOS_PROTO_TYPES)/cosmos.proto From 27d7ff3b2aa2a2fc9fb29c7808a6d13af2e80ed2 Mon Sep 17 00:00:00 2001 From: Peter Bukva Date: Thu, 10 Sep 2026 10:54:50 +0100 Subject: [PATCH 4/5] Enable PIE (Position Indepenet Executable) --- Makefile | 34 +++++++++++++++++++++++----------- 1 file changed, 23 insertions(+), 11 deletions(-) diff --git a/Makefile b/Makefile index 873b8bfb3..35b86f949 100644 --- a/Makefile +++ b/Makefile @@ -16,7 +16,6 @@ PROJECT_NAME = $(shell git remote get-url origin | xargs basename -s .git) export GO111MODULE = on # process build tags - build_tags = netgo ifeq ($(LEDGER_ENABLED),true) ifeq ($(OS),Windows_NT) @@ -47,11 +46,6 @@ endif build_tags += $(BUILD_TAGS) build_tags := $(strip $(build_tags)) -empty := -space := $(empty) $(empty) -comma := , -build_tags_comma_sep := $(subst $(space),$(comma),$(build_tags)) - # process linker flags ldflags = -X github.com/cosmos/cosmos-sdk/version.Name=fetch \ @@ -63,10 +57,23 @@ ldflags = -X github.com/cosmos/cosmos-sdk/version.Name=fetch \ ifeq ($(WITH_CLEVELDB),yes) ldflags += -X github.com/cosmos/cosmos-sdk/types.DBBackend=cleveldb endif + +# PIE is enabled for all builds. +# +# PIE and static linking are *independent* properties: +# -buildmode=pie -> position-independent executable (platform *independent*) +# -static-pie -> *Linux* only *static* linking of the PIE executable +buildmode_flags += -buildmode=pie + ldflags += $(LDFLAGS) ldflags := $(strip $(ldflags)) -BUILD_FLAGS := -tags $(build_tags_comma_sep) -ldflags '$(ldflags)' -trimpath +empty := +space := $(empty) $(empty) +comma := , +build_tags_comma_sep := $(subst $(space),$(comma),$(build_tags)) + +BUILD_FLAGS := -tags "$(build_tags_comma_sep)" -ldflags '$(ldflags)' -trimpath $(buildmode_flags) # The below include contains the tools target. #include contrib/devtools/Makefile @@ -80,8 +87,10 @@ else go build -mod=readonly $(BUILD_FLAGS) -o build/fetchd ./cmd/fetchd endif +# Build for Linux while preserving the target architecture supplied by +# the environment (or Go's native GOARCH default). build-linux: go.sum - LEDGER_ENABLED=false GOOS=linux GOARCH=amd64 $(MAKE) build + GOOS=linux $(MAKE) build build-contract-tests-hooks: ifeq ($(OS),Windows_NT) @@ -152,6 +161,7 @@ $(TEST_TARGETS): run-tests SUB_MODULES = $(shell find . -type f -name 'go.mod' -print0 | xargs -0 -n1 dirname | sort) CURRENT_DIR = $(shell pwd) + run-tests: ifneq (,$(shell which tparse 2>/dev/null)) @echo "Unit tests"; \ @@ -190,7 +200,7 @@ localnet-start: build-linux localnet-stop @if ! [ -f build/node0/fetchd/config/genesis.json ]; then docker run --rm -v $(CURDIR)/build:/fetchd:Z tendermint/fetchdnode testnet --v 4 -o . --starting-ip-address 192.168.10.2 ; fi docker-compose up -d -# Stop testnet +# Stop local testnet localnet-stop: docker-compose down @@ -234,7 +244,7 @@ proto-check-breaking: @$(DOCKER_BUF) breaking --against $(HTTPS_GIT)#branch=master proto-check-breaking-direct: - @buf breaking --against '.git#branch=master' + @$(DOCKER_BUF) breaking --against '.git#branch=master' GOGO_PROTO_URL = https://raw.githubusercontent.com/regen-network/protobuf/cosmos REGEN_COSMOS_PROTO_URL = https://raw.githubusercontent.com/regen-network/cosmos-proto/master @@ -253,4 +263,6 @@ proto-update-deps: @mkdir -p $(COSMOS_PROTO_TYPES)/base/query/v1beta1/ @curl -sSL $(COSMOS_PROTO_URL)/base/query/v1beta1/pagination.proto > $(COSMOS_PROTO_TYPES)/base/query/v1beta1/pagination.proto - @curl -sSL $(COSMOS_PROTO_URL)/base/v1beta1/coin.proto > $(COSMOS_PROTO_TYPES)/base/v1beta1/coin.proto + + @mkdir -p $(COSMOS_PROTO_TYPES)/base/v1beta1/ + @curl -sSL $(COSMOS_PROTO_URL)/base/v1beta1/coin.proto > $(COSMOS_PROTO_TYPES)/base/v1beta1/coin.proto \ No newline at end of file From 5d57e5208f8c111740c3225adf06f512c6f8b2d8 Mon Sep 17 00:00:00 2001 From: Peter Bukva Date: Thu, 10 Sep 2026 11:53:18 +0100 Subject: [PATCH 5/5] Default STATIC_PIE to `false` --- Makefile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Makefile b/Makefile index 8ac40cc33..f263a36fa 100644 --- a/Makefile +++ b/Makefile @@ -5,7 +5,7 @@ PACKAGES_SIMTEST=$(shell go list ./... | grep '/simulation') VERSION := $(shell echo $(shell git describe --tags)) COMMIT := $(shell git log -1 --format='%H') LEDGER_ENABLED ?= true -STATIC_PIE ?= true +STATIC_PIE ?= false BINDIR ?= $(GOPATH)/bin BUILDDIR ?= $(CURDIR)/build APP_DIR = ./app