2010-08-29 18:58:15 +02:00
|
|
|
Copyright (c) 2009-2010 Satoshi Nakamoto
|
2011-09-26 17:40:43 +02:00
|
|
|
Copyright (c) 2011 Bitcoin Developers
|
2010-08-29 18:58:15 +02:00
|
|
|
Distributed under the MIT/X11 software license, see the accompanying
|
|
|
|
file license.txt or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
This product includes software developed by the OpenSSL Project for use in
|
|
|
|
the OpenSSL Toolkit (http://www.openssl.org/). This product includes
|
2011-03-26 13:01:27 +01:00
|
|
|
cryptographic software written by Eric Young (eay@cryptsoft.com) and UPnP
|
|
|
|
software written by Thomas Bernard.
|
2010-08-29 18:58:15 +02:00
|
|
|
|
|
|
|
|
|
|
|
UNIX BUILD NOTES
|
|
|
|
================
|
|
|
|
|
2011-01-25 15:29:13 +01:00
|
|
|
To Build
|
|
|
|
--------
|
|
|
|
|
2011-04-23 11:49:47 +02:00
|
|
|
cd src/
|
2011-09-26 17:40:43 +02:00
|
|
|
make -f makefile.unix # Headless bitcoin
|
2011-04-23 11:49:47 +02:00
|
|
|
|
2011-09-26 17:40:43 +02:00
|
|
|
See readme-qt.rst for instructions on building Bitcoin QT,
|
|
|
|
the graphical bitcoin.
|
2011-01-25 15:29:13 +01:00
|
|
|
|
2010-08-29 18:58:15 +02:00
|
|
|
Dependencies
|
|
|
|
------------
|
|
|
|
sudo apt-get install build-essential
|
|
|
|
sudo apt-get install libssl-dev
|
2011-08-12 00:20:07 +02:00
|
|
|
sudo apt-get install libdb4.8-dev
|
|
|
|
sudo apt-get install libdb4.8++-dev
|
2010-08-29 18:58:15 +02:00
|
|
|
Boost 1.40+: sudo apt-get install libboost-all-dev
|
|
|
|
or Boost 1.37: sudo apt-get install libboost1.37-dev
|
|
|
|
|
|
|
|
If using Boost 1.37, append -mt to the boost libraries in the makefile.
|
|
|
|
|
2011-05-06 09:55:38 +02:00
|
|
|
Requires miniupnpc for UPnP port mapping. It can be downloaded from
|
|
|
|
http://miniupnp.tuxfamily.org/files/. UPnP support is compiled in and
|
|
|
|
turned off by default. Set USE_UPNP to a different value to control this:
|
|
|
|
USE_UPNP= no UPnP support, miniupnp not required;
|
|
|
|
USE_UPNP=0 (the default) UPnP support turned off by default at runtime;
|
|
|
|
USE_UPNP=1 UPnP support turned on by default at runtime.
|
2011-03-26 13:01:27 +01:00
|
|
|
|
2010-08-29 18:58:15 +02:00
|
|
|
Licenses of statically linked libraries:
|
|
|
|
Berkeley DB New BSD license with additional requirement that linked software must be free open source
|
|
|
|
Boost MIT-like license
|
2011-03-26 13:01:27 +01:00
|
|
|
miniupnpc New (3-clause) BSD license
|
2010-08-29 18:58:15 +02:00
|
|
|
|
|
|
|
Versions used in this release:
|
|
|
|
GCC 4.3.3
|
|
|
|
OpenSSL 0.9.8g
|
2011-08-12 00:20:07 +02:00
|
|
|
Berkeley DB 4.8.30.NC
|
2010-08-29 18:58:15 +02:00
|
|
|
Boost 1.37
|
2011-08-12 00:20:07 +02:00
|
|
|
miniupnpc 1.6
|
2010-08-29 18:58:15 +02:00
|
|
|
|
|
|
|
|
|
|
|
Notes
|
|
|
|
-----
|
|
|
|
The release is built with GCC and then "strip bitcoin" to strip the debug
|
|
|
|
symbols, which reduces the executable size by about 90%.
|
|
|
|
|
|
|
|
|
2011-03-26 13:01:27 +01:00
|
|
|
miniupnpc
|
|
|
|
---------
|
2011-08-12 00:20:07 +02:00
|
|
|
tar -xzvf miniupnpc-1.6.tar.gz
|
|
|
|
cd miniupnpc-1.6
|
2011-03-26 13:01:27 +01:00
|
|
|
make
|
|
|
|
sudo su
|
|
|
|
make install
|
|
|
|
|
|
|
|
|
2010-08-29 18:58:15 +02:00
|
|
|
Berkeley DB
|
|
|
|
-----------
|
2011-08-12 00:20:07 +02:00
|
|
|
You need Berkeley DB 4.8. If you have to build Berkeley DB yourself:
|
2010-08-29 18:58:15 +02:00
|
|
|
../dist/configure --enable-cxx
|
|
|
|
make
|
|
|
|
|
|
|
|
|
|
|
|
Boost
|
|
|
|
-----
|
|
|
|
If you need to build Boost yourself:
|
|
|
|
sudo su
|
|
|
|
./bootstrap.sh
|
|
|
|
./bjam install
|
2011-09-08 18:50:54 +02:00
|
|
|
|
|
|
|
|
|
|
|
Security
|
|
|
|
--------
|
|
|
|
To help make your bitcoin installation more secure by making certain attacks impossible to
|
|
|
|
exploit even if a vulnerability is found, you can take the following measures:
|
|
|
|
|
|
|
|
* Position Independent Executable
|
|
|
|
Build position independent code to take advantage of Address Space Layout Randomization
|
|
|
|
offered by some kernels. An attacker who is able to cause execution of code at an arbitrary
|
|
|
|
memory location is thwarted if he doesn't know where anything useful is located.
|
|
|
|
The stack and heap are randomly located by default but this allows the code section to be
|
|
|
|
randomly located as well.
|
|
|
|
|
|
|
|
On an Amd64 processor where a library was not compiled with -fPIC, this will cause an error
|
|
|
|
such as: "relocation R_X86_64_32 against `......' can not be used when making a shared object;"
|
|
|
|
|
|
|
|
To build with PIE, use:
|
|
|
|
make -f makefile.unix ... -e PIE=1
|
|
|
|
|
|
|
|
To test that you have built PIE executable, install scanelf, part of paxutils, and use:
|
|
|
|
scanelf -e ./bitcoin
|
|
|
|
|
|
|
|
The output should contain:
|
|
|
|
TYPE
|
|
|
|
ET_DYN
|
|
|
|
|
|
|
|
* Non-executable Stack
|
|
|
|
If the stack is executable then trivial stack based buffer overflow exploits are possible if
|
|
|
|
vulnerable buffers are found. By default, bitcoin should be built with a non-executable stack
|
|
|
|
but if one of the libraries it uses asks for an executable stack or someone makes a mistake
|
|
|
|
and uses a compiler extension which requires an executable stack, it will silently build an
|
|
|
|
executable without the non-executable stack protection.
|
|
|
|
|
|
|
|
To verify that the stack is non-executable after compiling use:
|
|
|
|
scanelf -e ./bitcoin
|
|
|
|
|
|
|
|
the output should contain:
|
|
|
|
STK/REL/PTL
|
|
|
|
RW- R-- RW-
|
|
|
|
|
|
|
|
The STK RW- means that the stack is readable and writeable but not executable.
|