Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 44 additions & 0 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,50 @@ jobs:
- name: Check license header
run: make check-license

- name: Setup Go
uses: actions/setup-go@v6
with:
go-version-file: go.mod

- name: Install go-licenses
run: go install github.com/google/go-licenses@v1.6.0

# LGPL-3.0 is classified as restricted, and go-licenses reads go-ethereum's
# root COPYING file, so it reports the whole module as GPL-3.0. Only library
# packages outside cmd/ are linked, which are LGPL-3.0, and that combination
# is allowed here deliberately. See dev/licenses-overrides.tsv.
# The targets and cgo modes match dev/licenses-generate.sh, because the
# linked packages differ between them.
- name: Check third party licenses
run: |
for target in linux/amd64 linux/arm64; do
for cgo in 1 0; do
GOOS="${target%/*}" GOARCH="${target#*/}" CGO_ENABLED=$cgo \
go-licenses check ./... \
--disallowed_types=forbidden,restricted,unknown \
--ignore github.com/ethereum/go-ethereum
done
done

# The go-ethereum exception above holds only while no package under its
# GPL-3.0 cmd/ directory is linked.
- name: Check that no go-ethereum command is linked
run: |
for target in linux/amd64 linux/arm64; do
for cgo in 1 0; do
deps=$(GOOS="${target%/*}" GOARCH="${target#*/}" CGO_ENABLED=$cgo go list -deps ./...)
if grep '^github.com/ethereum/go-ethereum/cmd/' <<<"$deps"; then
echo "a go-ethereum cmd/ package is linked for $target with CGO_ENABLED=$cgo" >&2
exit 1
fi
done
done

- name: Check third party notices are current
run: |
dev/licenses-generate.sh > THIRD_PARTY_LICENSES.md
git diff --exit-code THIRD_PARTY_LICENSES.md

- name: Lint Markdown docs
uses: DavidAnson/markdownlint-cli2-action@ded1f9488f68a970bc66ea5619e13e9b52e601cd # v23
with:
Expand Down
6 changes: 3 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -51,10 +51,10 @@ FROM common-env AS go-installer
RUN <<EOF
set -e
ARCH=$(dpkg --print-architecture)
wget -O /tmp/go.tar.gz "https://go.dev/dl/go1.26.3.linux-${ARCH}.tar.gz"
wget -O /tmp/go.tar.gz "https://go.dev/dl/go1.27.1.linux-${ARCH}.tar.gz"
case "$ARCH" in
amd64) echo "2b2cfc7148493da5e73981bffbf3353af381d5f93e789c82c79aff64962eb556 /tmp/go.tar.gz" | sha256sum --check ;;
arm64) echo "9d89a3ea57d141c2b22d70083f2c8459ba3890f2d9e818e7e933b75614936565 /tmp/go.tar.gz" | sha256sum --check ;;
amd64) echo "63d339f0da5ab53635a56f2490a7984dfe12dfcff22ad749f63edaf590168445 /tmp/go.tar.gz" | sha256sum --check ;;
arm64) echo "3450b45a3f9ee8568792736a5c5e70a1f2e9b36c35a8f74958c03e51d7d92bec /tmp/go.tar.gz" | sha256sum --check ;;
*) echo "unsupported architecture: $ARCH"; exit 1 ;;
esac
tar -C /opt -xzf /tmp/go.tar.gz
Expand Down
33 changes: 28 additions & 5 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
TARGET_OS?=$(shell uname)
export TARGET_OS

ROLLUPS_NODE_VERSION := 2.0.0-alpha.12
ROLLUPS_NODE_VERSION := 2.0.0-alpha.13
ROLLUPS_CONTRACTS_VERSION := 3.0.0-alpha.10
ROLLUPS_CONTRACTS_URL:=https://github.com/cartesi/rollups-contracts/releases/download/
ROLLUPS_CONTRACTS_ARTIFACT:=cartesi-rollups-contracts-$(ROLLUPS_CONTRACTS_VERSION)-artifacts.tar.gz
Expand All @@ -42,7 +42,7 @@ PREFIX ?= /usr
endif

BIN_RUNTIME_PATH= $(PREFIX)/bin
DOC_RUNTIME_PATH= $(PREFIX)/doc/cartesi-rollups-node
DOC_RUNTIME_PATH= $(PREFIX)/share/doc/cartesi-rollups-node

BIN_INSTALL_PATH= $(abspath $(DESTDIR)$(BIN_RUNTIME_PATH))
DOC_INSTALL_PATH= $(abspath $(DESTDIR)$(DOC_RUNTIME_PATH))
Expand Down Expand Up @@ -120,6 +120,13 @@ ifeq ($(COVER),true)
COVER_REPORT := coverage-report
endif

# The pure Go artifacts are built without cgo, which changes what they link:
# go-ethereum, for one, uses a pure Go secp256k1 instead of libsecp256k1. The
# unit tests of the packages they link also run that way, without coverage.
PURE_GO_TEST_PACKAGES = $(filter $(shell go list $(GO_TEST_PACKAGES)), \
$(shell CGO_ENABLED=0 go list -deps $(addprefix ./cmd/,$(PURE_GO_ARTIFACTS))))
PURE_GO_TEST_FLAGS = $(filter-out -coverprofile=% -covermode=% -coverpkg=%,$(GO_TEST_FLAGS))


ROLLUPS_CONTRACTS_ABI_BASEDIR:= rollups-contracts/
ROLLUPS_PRT_CONTRACTS_ABI_BASEDIR:= rollups-prt-contracts/
Expand Down Expand Up @@ -312,6 +319,9 @@ unit-test: $(COVER_DEPS) ## Execute go unit tests
@echo "Running go unit tests"
@go clean -testcache
@go test -p 1 $(GO_BUILD_PARAMS) $(GO_TEST_FLAGS) $(GO_TEST_PACKAGES)
@echo "Running go unit tests of the pure Go artifacts without cgo"
@packages="$(PURE_GO_TEST_PACKAGES)"; [ -z "$$packages" ] || \
CGO_ENABLED=0 go test -p 1 $(PURE_GO_BUILD_PARAMS) $(PURE_GO_TEST_FLAGS) $$packages
@$(if $(COVER_REPORT),$(MAKE) $(COVER_REPORT))

GOTESTSUM_FORMAT ?= testdox
Expand Down Expand Up @@ -837,8 +847,11 @@ help: ## Show help for each of the Makefile recipes
version: ## Show the current version
@echo $(ROLLUPS_NODE_VERSION)

THIRD_PARTY_LICENSES.md: dev/licenses.tpl go.mod ## Update the THIRD_PARTY_LICENSES.md file
go-licenses report --template dev/licenses.tpl ./... > $@
# Phony, because the notices depend on more than files make can see: go.sum,
# the imported packages, and licence URLs that go-licenses resolves online.
THIRD_PARTY_LICENSES.md: ## Update the THIRD_PARTY_LICENSES.md file
dev/licenses-generate.sh > $@.tmp || { rm -f $@.tmp; exit 1; }
mv $@.tmp $@

# =============================================================================
# Install
Expand All @@ -859,6 +872,16 @@ copy-debian-package: ## Copy debian package from debian packager image
build-debian-package: install
mkdir -p $(DESTDIR)/DEBIAN $(DOC_INSTALL_PATH)
install -m0644 LICENSE $(DOC_INSTALL_PATH)/copyright
install -m0644 THIRD_PARTY_LICENSES.md $(DOC_INSTALL_PATH)/
install -m0644 licenses/LGPL-3.0.txt $(DOC_INSTALL_PATH)/
install -m0644 licenses/GPL-3.0.txt $(DOC_INSTALL_PATH)/
{ \
echo ""; \
echo "The binaries in this package statically link third party components."; \
echo "They are listed with their licences in THIRD_PARTY_LICENSES.md, in this"; \
echo "directory. Some are covered by the GNU LGPL-3.0, whose text is in"; \
echo "LGPL-3.0.txt, alongside the GPL-3.0.txt it builds on."; \
} >> $(DOC_INSTALL_PATH)/copyright
sed 's|ARG_VERSION|$(ROLLUPS_NODE_VERSION)|g;s|ARG_ARCH|$(DEB_ARCH)|g' control.template > $(DESTDIR)/DEBIAN/control
dpkg-deb -Zxz --root-owner-group --build $(DESTDIR) $(DEB_FILENAME)

Expand All @@ -867,7 +890,7 @@ build-debian-package: install
clean clean-go clean-contracts clean-docs clean-devnet-files clean-dapps clean-test-dependencies clean-test-logs clean-integration-compose clean-debian-packages \
test unit-test unit-test-with-compose integration-test integration-test-with-compose integration-test-local test-with-compose ci-test coverage-report \
integration-test-shard-check list-integration-shards list-integration-cells \
generate generate-contracts generate-config generate-inspect check-generate generate-db \
generate generate-contracts generate-config generate-inspect check-generate generate-db THIRD_PARTY_LICENSES.md \
docs generate-cli-docs generate-config-docs \
lint fmt fmt-check vet escape check-license \
devnet image tester-image debian-packager run-with-compose shutdown-compose \
Expand Down
11 changes: 8 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,9 +16,9 @@ We provide packages for debian (.deb) in **amd64** and **arm64** variants on the

##### System Requirements

- Cartesi Machine emulator == 0.20.x
- Cartesi Machine emulator == 0.21.x
- GNU Make >= 3.81
- Go >= 1.24.1
- Go >= 1.27.1

Follow the [Cartesi Machine installation instructions](https://github.com/cartesi/machine-emulator?tab=readme-ov-file#installation).

Expand Down Expand Up @@ -106,7 +106,7 @@ Note we have a [code of conduct](CODE_OF_CONDUCT.md), please follow it in all yo

## Authors

The Cartesi Machine emulator is actively developed by [Cartesi](https://cartesi.io/)'s Machine Reference Unit, with significant contributions from many open-source developers.
The Cartesi Rollups Node is actively developed by [Cartesi](https://cartesi.io/)'s Node Reference Unit, with significant contributions from many open-source developers.
For a complete list of authors, see the [AUTHORS](AUTHORS) file.

## License
Expand All @@ -115,3 +115,8 @@ The repository and all contributions to it are licensed under the [Apache 2.0](h
Please review our [LICENSE](LICENSE) file for the Apache 2.0 license and also the [third party licenses](THIRD_PARTY_LICENSES.md) file for information on third-party software licenses.

Note: This component currently has dependencies licensed under the GNU LGPL, version 3, so you should treat this component as a whole as being under the LGPL version 3. But all Cartesi-written code in this component is licensed under the Apache License, version 2, and can be used independently under the Apache v2 license.

The Cartesi Machine emulator is a dynamic library in its own package. A recipient can replace it without a new build of the node.
go-ethereum is statically linked into every binary. Only its library packages are used, that is, everything outside `cmd/`.
The complete source of this project is in this repository under Apache 2.0. To build the node against a different go-ethereum, add a `replace` directive for `github.com/ethereum/go-ethereum` to `go.mod` and run `make build`.
The full text of the LGPL-3.0 and the GPL-3.0 is in [licenses/](licenses).
Loading