7 Commits
Author SHA1 Message Date
wangdefa 596ffc1567 feat: 重构 CI/CD 流水线,拆分为独立的构建和发布流程,更新相关文档和脚本
CI / validate (push) Successful in 5s
CI / build (amd64) (push) Successful in 3m38s
CI / build (arm64) (push) Successful in 8m39s
Release / build (amd64) (push) Successful in 3m35s
Release / build (arm64) (push) Successful in 8m58s
Release / release (push) Successful in 42s
- 新增 .gitea/workflows/ci.yml,包含版本校验、构建和冒烟测试
- 新增 .gitea/workflows/release.yml,处理 tag 发布,上传包到仓库并创建 Release
- 更新 README.md 和 CLAUDE.md,描述新的 CI/CD 流程和版本号约定
- 修改 init.sh,增加对关键锚点的检查,确保源码结构一致性
- 更新 Dockerfile,使用 OpenSSL 3.0.21 和 unbound 1.25.1,确保与 Monero 版本一致
- 更新 build-deb.sh 示例,反映最新版本号
- 新增 VERSION 文件,统一版本管理
2026-08-07 09:51:47 +08:00
wangdefaandClaude Opus 4.8 4b587550a1 精简 README,对齐 xxxig/p2pool 等项目风格
Build and Release Mond / build-and-test (amd64) (push) Successful in 5s
Build and Release Mond / build-and-test (arm64) (push) Successful in 31s
Build and Release Mond / release (push) Has been skipped
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 15:00:49 +08:00
wangdefaandClaude Opus 4.8 b44b118be7 改用 musl 全静态构建,零依赖跨发行版
Build and Release Mond / release (push) Successful in 19s
Build and Release Mond / build-and-test (amd64) (push) Successful in 4m11s
Build and Release Mond / build-and-test (arm64) (push) Successful in 9m19s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 12:03:43 +08:00
wangdefaandClaude Opus 4.8 5430297ff9 fix: 版本变量改 PACKAGE_VERSION、CI 触发 tags['*']、修正静态措辞
Build and Release Mond / build-and-test (amd64) (push) Successful in 1s
Build and Release Mond / build-and-test (arm64) (push) Successful in 35s
Build and Release Mond / release (push) Successful in 16s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-09 22:30:53 +08:00
wangdefaandClaude Opus 4.8 317973e94d feat: 对齐 xxxig/proxy 打包规范并迁移配置至 /etc/mond
Build and Release Mond / build-and-test (amd64) (push) Successful in 11m47s
Build and Release Mond / build-and-test (arm64) (push) Successful in 18m24s
Build and Release Mond / release (push) Has been skipped
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-09 22:00:48 +08:00
wangdefa 2862374985 feat: 更新 Monero 版本至 v0.18.4.6,并调整相关文档和脚本
Build and Release Mond / build-and-test (arm64) (push) Successful in -17s
Build and Release Mond / build-and-test (amd64) (push) Successful in -1m16s
Build and Release Mond / release (push) Successful in -1m6s
2026-03-14 16:42:07 +08:00
wangdefa 1faa92266e fix: 修复 apt 升级后服务需要手动重新启用的问题
Build and Release Mond / build-and-test (arm64) (push) Successful in -17s
Build and Release Mond / build-and-test (amd64) (push) Successful in -19s
Build and Release Mond / release (push) Has been skipped
- 修改 prerm 脚本,升级时只停止服务不禁用
- 修改 postinst 脚本,升级后自动重启已启用的服务
- 首次安装仍保持手动启用服务的行为
2026-01-21 12:40:29 +08:00
16 changed files with 546 additions and 646 deletions
-207
View File
@@ -1,207 +0,0 @@
# .gitea/workflows/ci.yaml
name: Build and Release Mond
on:
push:
branches: [main, master, develop]
tags: ['v*']
env:
DOCKER_BUILDKIT: "1"
PRODUCT_NAME: "mond"
MONERO_VERSION: "v0.18.4.5"
BUILDX_NO_DEFAULT_ATTESTATIONS: "1"
jobs:
build-and-test:
runs-on: ${{ matrix.arch == 'amd64' && 'ubuntu-latest-amd64' || 'ubuntu-latest-arm64' }}
strategy:
matrix:
arch: [amd64, arm64]
steps:
- uses: actions/checkout@v4
- name: Setup Docker Buildx
run: |
# 创建 buildx builder(原生构建不需要 QEMU)
docker buildx create --use --name native-builder \
--driver docker-container \
--driver-opt network=host \
--driver-opt env.BUILDKIT_STEP_LOG_MAX_SIZE=50000000 \
--driver-opt env.BUILDKIT_STEP_LOG_MAX_SPEED=10000000 \
|| true
docker buildx inspect --bootstrap
- name: Build binaries
run: |
PLATFORM="linux/${{ matrix.arch }}"
echo "🏗️ Building ${PLATFORM} on native ${{ matrix.arch }} runner"
echo "📦 Using Ubuntu 20.04 with depends system"
echo "📦 Monero Version: ${MONERO_VERSION}"
echo "🔗 Static linking enabled"
# 设置 BuildKit 优化参数
export BUILDKIT_PROGRESS=plain
docker buildx build --pull \
--platform ${PLATFORM} \
--build-arg MONERO_VERSION=${MONERO_VERSION} \
--output type=local,dest=./output \
-f docker/Dockerfile.ubuntu .
- name: Package and test
run: |
DIR="./output/linux_${{ matrix.arch }}"
VERSION=${MONERO_VERSION#v} # 移除前导 v
TARGZ="${PRODUCT_NAME}-${{ matrix.arch }}-ubuntu-${VERSION}.tar.gz"
tar -czf "${TARGZ}" -C "$DIR" .
echo "📦 Created package: ${TARGZ}"
ls -lh "${TARGZ}"
# 快速验证
mkdir -p test && tar -xzf "${TARGZ}" -C test
test/mond --version 2>/dev/null || echo "⚠️ 跳过版本检查"
rm -rf test
- name: Build Debian package
run: |
# 安装 dpkg-deb(如果需要)
sudo apt-get update && sudo apt-get install -y dpkg-dev
DIR="./output/linux_${{ matrix.arch }}"
VERSION=${MONERO_VERSION#v} # 移除前导 v
echo "📦 Building Debian package for ${{ matrix.arch }}..."
chmod +x debian/build-deb.sh
./debian/build-deb.sh ${{ matrix.arch }} ${VERSION} "${DIR}"
ls -lh *.deb
- uses: https://github.com/ChristopherHX/gitea-upload-artifact@v4
with:
name: binaries-${{ matrix.arch }}
path: |
*.tar.gz
*.deb
retention-days: 1
release:
runs-on: ubuntu-latest-amd64
needs: build-and-test
if: startsWith(github.ref, 'refs/tags/')
steps:
- uses: https://github.com/ChristopherHX/gitea-download-artifact@v4
with:
pattern: binaries-*
path: ./packages
merge-multiple: true
- name: Upload packages and create release
env:
TOKEN: ${{ secrets.BUILD_TOKEN }}
TAG: ${{ github.ref_name }}
run: |
cd packages
# 提取仓库信息(移除 https:// 前缀和仓库路径)
REGISTRY=$(echo "${{ gitea.server_url }}" | sed 's|https\?://||')
OWNER="${{ gitea.repository_owner }}"
REPO_NAME=$(echo "${{ gitea.repository }}" | cut -d'/' -f2)
echo "📦 上传包到 Generic Package Registry..."
echo " Registry: ${REGISTRY}"
echo " Owner: ${OWNER}"
echo " Package: ${PRODUCT_NAME}"
echo " Version: ${TAG}"
# 上传所有 tar.gz 包到 Generic Package Registry
for file in *.tar.gz; do
[ ! -f "$file" ] && continue
echo " ⬆️ $file"
curl -fsSL -X PUT \
-H "Authorization: token ${TOKEN}" \
--upload-file "$file" \
"https://${REGISTRY}/api/packages/${OWNER}/generic/${PRODUCT_NAME}/${TAG}/$file" || {
echo "❌ 上传失败: $file"
exit 1
}
done
# 上传 Debian 包到 Debian Package Registry (通用稳定版)
echo ""
echo "📦 上传 Debian 包到 Debian Package Registry..."
for file in *.deb; do
[ ! -f "$file" ] && continue
# 上传到 stable (通用稳定版)
echo " ⬆️ $file → stable"
curl -fsSL -X PUT \
-H "Authorization: token ${TOKEN}" \
--upload-file "$file" \
"https://${REGISTRY}/api/packages/${OWNER}/debian/pool/stable/main/upload" || {
echo "❌ Debian 包上传失败: $file (stable)"
exit 1
}
done
# 生成 Release JSON payload
echo ""
echo "📝 生成 Release..."
export REGISTRY OWNER TAG
RELEASE_DATA=$(python3 -c 'import json,glob,os;r=os.environ["REGISTRY"];o=os.environ["OWNER"];p=os.environ["PRODUCT_NAME"];t=os.environ["TAG"];b=["## Release "+t,"","Mond 是 Monero 守护进程 (monerod) 的定制版本。","","### ✨ 主要特性","","- 🔗 **纯静态链接** - 无需依赖,可在任意 Linux 系统运行","- 🏗️ **多架构支持** - 原生支持 AMD64 和 ARM64","- 📦 **官方构建系统** - 使用 Monero 官方 depends 系统构建,确保可靠性","","### 📥 下载方式","","#### 方式一:直接下载(推荐)","","点击下方 **Assets** 区域的文件名直接下载。","","**可用安装包:**",""]+[f"- [`{f}`](https://{r}/api/packages/{o}/generic/{p}/{t}/{f})" for f in sorted(glob.glob("*.tar.gz"))]+["","#### 方式二:通用软件包仓库","","通过命令行下载:",""]+[f"```bash\nwget https://{r}/api/packages/{o}/generic/{p}/{t}/{f}\n```" for f in sorted(glob.glob("*.tar.gz"))[:1]]+["","#### 方式三:Debian 软件源","","```bash","# 下载 GPG 密钥",f"sudo curl https://{r}/api/packages/{o}/debian/repository.key -o /etc/apt/keyrings/gitea-{o}.asc","","# 添加软件源",f"echo \"deb [signed-by=/etc/apt/keyrings/gitea-{o}.asc] https://{r}/api/packages/{o}/debian stable main\" | sudo tee -a /etc/apt/sources.list.d/{o}.list","","# 更新并安装","sudo apt-get update","sudo apt-get install mond","```"];print(json.dumps({"tag_name":t,"name":f"Release {t}","body":"\n".join(b),"draft":False,"prerelease":False}))')
# 创建 Release
echo ""
echo "🎉 创建 Release..."
RESPONSE=$(curl -fsSL -w "\n%{http_code}" -X POST \
-H "Authorization: token ${TOKEN}" \
-H "Content-Type: application/json" \
"https://${REGISTRY}/api/v1/repos/${{ gitea.repository }}/releases" \
-d "${RELEASE_DATA}")
HTTP_CODE=$(echo "$RESPONSE" | tail -n1)
RESPONSE_BODY=$(echo "$RESPONSE" | head -n-1)
if [ "$HTTP_CODE" = "201" ]; then
echo "✅ Release 创建成功"
RELEASE_ID=$(echo "$RESPONSE_BODY" | grep -o '"id":[0-9]*' | head -1 | cut -d':' -f2)
echo " Release ID: ${RELEASE_ID}"
elif [ "$HTTP_CODE" = "409" ]; then
echo "⚠️ Release 已存在,获取现有 Release ID..."
RELEASE_ID=$(curl -fsSL \
-H "Authorization: token ${TOKEN}" \
"https://${REGISTRY}/api/v1/repos/${{ gitea.repository }}/releases/tags/${TAG}" | \
grep -o '"id":[0-9]*' | head -1 | cut -d':' -f2)
echo " Release ID: ${RELEASE_ID}"
else
echo "❌ 创建 Release 失败 (HTTP ${HTTP_CODE})"
echo "$RESPONSE_BODY"
exit 1
fi
# 上传文件作为 Release 附件
echo ""
echo "📎 上传文件作为 Release 附件..."
for file in *.tar.gz *.deb; do
[ ! -f "$file" ] && continue
echo " ⬆️ $file"
# 使用 multipart/form-data 上传附件
curl -fsSL -X POST \
-H "Authorization: token ${TOKEN}" \
-F "attachment=@${file}" \
"https://${REGISTRY}/api/v1/repos/${{ gitea.repository }}/releases/${RELEASE_ID}/assets?name=${file}" || {
echo " ⚠️ 附件上传失败: $file(可能已存在)"
}
done
echo ""
echo "✅ Release 创建完成!"
echo "🔗 访问: https://${REGISTRY}/${{ gitea.repository }}/releases/tag/${TAG}"
# 清理临时文件
rm -f release_body.md
+83
View File
@@ -0,0 +1,83 @@
name: CI
# 分支推送只做校验和原生构建;tag 发布由 release.yml 独立处理。
on:
push:
branches: ["**"]
env:
DOCKER_BUILDKIT: "1"
BUILDX_NO_DEFAULT_ATTESTATIONS: "1"
BUILDKIT_PROGRESS: plain
jobs:
validate:
runs-on: ubuntu-latest-amd64
steps:
- uses: actions/checkout@v4
- name: 校验版本、配置和脚本语法
run: |
VERSION=$(tr -d '\r\n' < VERSION)
[[ "${VERSION}" =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]]
test -s conf/params.example.conf
bash -n debian/build-deb.sh
sh -n init.sh debian/postinst debian/prerm debian/postrm
build:
needs: validate
runs-on: ${{ matrix.arch == 'amd64' && 'ubuntu-latest-amd64' || 'ubuntu-latest-arm64' }}
strategy:
fail-fast: false
matrix:
arch: [amd64, arm64]
steps:
- uses: actions/checkout@v4
- name: 准备原生 Buildx
run: |
BUILDER=$(docker buildx create --use \
--driver docker-container \
--driver-opt network=host \
--driver-opt env.BUILDKIT_STEP_LOG_MAX_SIZE=50000000 \
--driver-opt env.BUILDKIT_STEP_LOG_MAX_SPEED=10000000)
echo "BUILDER=${BUILDER}" >> "$GITHUB_ENV"
docker buildx inspect --bootstrap
- name: 构建 ${{ matrix.arch }} 二进制
run: |
VERSION=$(tr -d '\r\n' < VERSION)
docker buildx build --pull \
--platform "linux/${{ matrix.arch }}" \
--build-arg "MONERO_VERSION=v${VERSION}" \
--output type=local,dest=./output \
-f docker/Dockerfile .
- name: 冒烟测试
run: |
DIR="./output/linux_${{ matrix.arch }}"
test -x "${DIR}/mond"
"${DIR}/mond" --version
"${DIR}/mond" --help >/dev/null
LDD_OUT=$(ldd "${DIR}/mond" 2>&1 || true)
grep -qE 'statically linked|not a dynamic executable' <<<"${LDD_OUT}"
- name: 验证 Debian 打包
run: |
VERSION=$(tr -d '\r\n' < VERSION)
TARGZ="mond-${{ matrix.arch }}-linux-static-${VERSION}.tar.gz"
tar -czf "${TARGZ}" -C "./output/linux_${{ matrix.arch }}" .
if ! command -v dpkg-deb >/dev/null; then
sudo apt-get update
sudo apt-get install -y dpkg-dev
fi
./debian/build-deb.sh "${{ matrix.arch }}" "${VERSION}" "${TARGZ}"
DEB="mond_${VERSION}_${{ matrix.arch }}.deb"
CONTENTS=$(dpkg-deb --contents "${DEB}")
grep -Fq 'opt/mond/mond' <<<"${CONTENTS}"
grep -Fq 'opt/mond/params.conf' <<<"${CONTENTS}"
grep -Fq 'lib/systemd/system/mond.service' <<<"${CONTENTS}"
- name: 清理 Buildx
if: always()
run: docker buildx rm "${BUILDER}" || true
+169
View File
@@ -0,0 +1,169 @@
name: Release
on:
push:
tags: ["*"]
env:
DOCKER_BUILDKIT: "1"
BUILDX_NO_DEFAULT_ATTESTATIONS: "1"
BUILDKIT_PROGRESS: plain
PRODUCT_NAME: mond
jobs:
build:
runs-on: ${{ matrix.arch == 'amd64' && 'ubuntu-latest-amd64' || 'ubuntu-latest-arm64' }}
strategy:
fail-fast: false
matrix:
arch: [amd64, arm64]
steps:
- uses: actions/checkout@v4
- name: 校验 tag 与源码版本
env:
TAG: ${{ gitea.ref_name }}
run: |
VERSION=$(tr -d '\r\n' < VERSION)
TAG_VERSION="${TAG#v}"
[[ "${TAG_VERSION}" =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]]
[ "${TAG_VERSION}" = "${VERSION}" ] || {
echo "tag ${TAG_VERSION} 与 VERSION ${VERSION} 不一致"
exit 1
}
echo "VERSION=${VERSION}" >> "$GITHUB_ENV"
- name: 准备原生 Buildx
run: |
BUILDER=$(docker buildx create --use \
--driver docker-container \
--driver-opt network=host \
--driver-opt env.BUILDKIT_STEP_LOG_MAX_SIZE=50000000 \
--driver-opt env.BUILDKIT_STEP_LOG_MAX_SPEED=10000000)
echo "BUILDER=${BUILDER}" >> "$GITHUB_ENV"
docker buildx inspect --bootstrap
- name: 构建 ${{ matrix.arch }} 二进制
run: |
docker buildx build --pull \
--platform "linux/${{ matrix.arch }}" \
--build-arg "MONERO_VERSION=v${VERSION}" \
--output type=local,dest=./output \
-f docker/Dockerfile .
- name: 打包并冒烟测试
run: |
DIR="./output/linux_${{ matrix.arch }}"
TARGZ="${PRODUCT_NAME}-${{ matrix.arch }}-linux-static-${VERSION}.tar.gz"
test -x "${DIR}/mond"
tar -czf "${TARGZ}" -C "${DIR}" .
TEST_DIR=$(mktemp -d)
trap 'rm -rf "${TEST_DIR}"' EXIT
tar -xzf "${TARGZ}" -C "${TEST_DIR}"
"${TEST_DIR}/mond" --version
"${TEST_DIR}/mond" --help >/dev/null
LDD_OUT=$(ldd "${TEST_DIR}/mond" 2>&1 || true)
grep -qE 'statically linked|not a dynamic executable' <<<"${LDD_OUT}"
- name: 构建 Debian 包
run: |
if ! command -v dpkg-deb >/dev/null; then
sudo apt-get update
sudo apt-get install -y dpkg-dev
fi
TARGZ="${PRODUCT_NAME}-${{ matrix.arch }}-linux-static-${VERSION}.tar.gz"
./debian/build-deb.sh "${{ matrix.arch }}" "${VERSION}" "${TARGZ}"
DEB="${PRODUCT_NAME}_${VERSION}_${{ matrix.arch }}.deb"
CONTENTS=$(dpkg-deb --contents "${DEB}")
grep -Fq 'opt/mond/mond' <<<"${CONTENTS}"
grep -Fq 'opt/mond/params.conf' <<<"${CONTENTS}"
grep -Fq 'lib/systemd/system/mond.service' <<<"${CONTENTS}"
- uses: https://github.com/ChristopherHX/gitea-upload-artifact@v4
with:
name: packages-${{ matrix.arch }}
path: |
*.tar.gz
*.deb
if-no-files-found: error
retention-days: 1
- name: 清理 Buildx
if: always()
run: docker buildx rm "${BUILDER}" || true
release:
needs: build
runs-on: ubuntu-latest-amd64
steps:
- uses: actions/checkout@v4
- uses: https://github.com/ChristopherHX/gitea-download-artifact@v4
with:
pattern: packages-*
path: ./packages
merge-multiple: true
- name: 校验发布文件并生成校验和
env:
TAG: ${{ gitea.ref_name }}
run: |
VERSION=$(tr -d '\r\n' < VERSION)
TAG_VERSION="${TAG#v}"
[ "${TAG_VERSION}" = "${VERSION}" ]
for arch in amd64 arm64; do
test -f "packages/${PRODUCT_NAME}-${arch}-linux-static-${VERSION}.tar.gz"
test -f "packages/${PRODUCT_NAME}_${VERSION}_${arch}.deb"
done
(cd packages && sha256sum *.tar.gz *.deb > SHA256SUMS)
REGISTRY=$(echo "${{ gitea.server_url }}" | sed 's|https\?://||')
echo "VERSION=${VERSION}" >> "$GITHUB_ENV"
echo "REGISTRY=${REGISTRY}" >> "$GITHUB_ENV"
- name: 上传 Generic 和 Debian 软件包
env:
TOKEN: ${{ secrets.BUILD_TOKEN }}
run: |
OWNER="${{ gitea.repository_owner }}"
for file in packages/*.tar.gz; do
name=$(basename "${file}")
curl -fsSL -X PUT \
-H "Authorization: token ${TOKEN}" \
--upload-file "${file}" \
"https://${REGISTRY}/api/packages/${OWNER}/generic/${PRODUCT_NAME}/${VERSION}/${name}"
done
for file in packages/*.deb; do
curl -fsSL -X PUT \
-H "Authorization: token ${TOKEN}" \
--upload-file "${file}" \
"https://${REGISTRY}/api/packages/${OWNER}/debian/pool/stable/main/upload"
done
- name: 生成 Release 描述
run: |
cat > release-notes.md <<EOF
## Release ${VERSION}
上游版本:[Monero v${VERSION}](https://github.com/monero-project/monero/releases/tag/v${VERSION})
### Debian/Ubuntu 安装
\`\`\`bash
sudo curl https://${REGISTRY}/api/packages/${{ gitea.repository_owner }}/debian/repository.key -o /etc/apt/keyrings/gitea-${{ gitea.repository_owner }}.asc
echo "deb [signed-by=/etc/apt/keyrings/gitea-${{ gitea.repository_owner }}.asc] https://${REGISTRY}/api/packages/${{ gitea.repository_owner }}/debian stable main" | sudo tee /etc/apt/sources.list.d/${{ gitea.repository_owner }}.list
sudo apt-get update && sudo apt-get install mond
\`\`\`
发布附件包含 amd64、arm64 的 tar.gz、Debian 包和 SHA256SUMS。
EOF
- name: 创建或更新 Release 并上传附件
uses: https://gitea.com/actions/gitea-release-action@v1
with:
token: ${{ secrets.BUILD_TOKEN }}
name: Release ${{ gitea.ref_name }}
body_path: release-notes.md
files: |
packages/*.tar.gz
packages/*.deb
packages/SHA256SUMS
+6
View File
@@ -8,3 +8,9 @@
llmdoc/ llmdoc/
example/ example/
.source/ .source/
# 构建产物
*.deb
*.tar.gz
output/
packages/
+59
View File
@@ -0,0 +1,59 @@
# CLAUDE.md
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
## 仓库性质
本仓库**只包含构建与打包基础设施**,不含 mond 源码。源码在编译时从外部仓库克隆(见 [docker/Dockerfile](docker/Dockerfile)):
- 源码仓库:`github.com/monero-project/monero.git`(**Monero 官方仓库**,非换名仓库)
- 发布仓库:Gitea `gitea.bcde.io` 下 `wangdefa/mond` 的 Generic / Debian 包仓库
mond 是 Monero 守护进程 `monerod` 的定制换名构建。换名通过 [init.sh](init.sh) 在编译期对源码做 `sed` 改写完成:`project(monero)→project(mond)`、二进制 `OUTPUT_NAME monerod→mond`、`MONERO_VERSION_*` 宏 → `MOND_VERSION_*`、用户可见字符串 `Monero→Mond`。**改动版本宏或显示字符串相关逻辑时,改 init.sh 而非源码**(源码每次构建都重新克隆)。init.sh 末尾还含 musl 纯静态所需的 CMakeLists patch(见下「为何 patch」)。
> **与同目录 `gitea-xxxig` / `gitea-xxxig-proxy` 的关键差异**:那两个项目源码来自 `wangdefaa`(双 a)换名仓库;mond 直接克隆 Monero 官方仓库,靠 init.sh 现场改名。三者共享同一套 CI / build-deb / debian 打包骨架,且均为 **musl fully-static** 构建;mond 的版本号格式为四段 `0.18.5.1`。
## 整体架构:单二进制
编译产出单个可执行文件 `mond`:Monero 全节点守护进程,负责 P2P 同步区块链、提供 RPC。配置来自 [conf/params.example.conf](conf/params.example.conf)。
## 构建与发布流程(CI)
Gitea Actions 拆成两条独立流水线:
1. [.gitea/workflows/ci.yml](.gitea/workflows/ci.yml) 仅由分支推送触发:先检查版本、配置与 shell 语法,再用 amd64、arm64 原生 runner 并行编译,执行严格冒烟测试并验证 DEB 包内容;不上传 artifact。
2. [.gitea/workflows/release.yml](.gitea/workflows/release.yml) 仅由 tag 推送触发:校验 tag 与 [VERSION](VERSION) 一致,双架构原生构建 → tar.gz → DEB → artifact 汇总 → SHA256SUMS → Generic/Debian Registry → Gitea Release。
关键点:
- **musl fully-static(Alpine 构建,勿改回 glibc)**:[docker/Dockerfile](docker/Dockerfile) 在 `alpine:3.23` 下手动源码编译 5 个静态库(OpenSSL 3.0.21 / libsodium 1.0.20 / libzmq 4.3.5 / expat 2.6.4 / unbound 1.25.1),编出 **static-pie 纯静态**二进制:`ldd` = `statically linked`、零外部依赖,**glibc/musl 任意发行版直接运行**(实测 musl 产物在 Debian 13 上正常运行)。`make daemon` 约 7 分钟/架构(5 库命中 Docker 层缓存后),远快于原 glibc depends 系统的 30–60 分钟。
- **为何用 musl 而非 glibc 全静态**:glibc 的 `getaddrinfo` 依赖运行时 `dlopen` NSS 模块,`-static` 全静态后无法加载 → DNS 解析失败(`DNS error: resource busy or locked`);musl 的 `getaddrinfo` 自带实现,全静态也能正常解析。与 `gitea-xxxig`/`gitea-xxxig-proxy` 一致。曾用的 glibc(ubuntu) depends 构建线已删除。
- **为何 patch monero 源码([init.sh](init.sh) 末尾,勿删)**:monero 官方明确「不支持 fully static」——`CMakeLists.txt` 中 `STATIC=ON` 在 Linux 只加 `-static-libgcc -static-libstdc++`(非真 `-static`),且强制追加 `-pie` 安全加固,会让链接结果带 musl interpreter、退化成动态。故 init.sh 用 `sed` 去掉 `-pie`、把 Linux 的 `STATIC_FLAGS` 改成真 `-static`。Alpine gcc 默认 PIE,`-static` 自动产出 static-pie(零外部依赖)。init.sh 在修改前后都会校验关键锚点,上游结构变化时必须直接失败,不能跳过补丁继续构建。
- **版本号约定**:根目录 [VERSION](VERSION) 是唯一版本来源,内容为不带 `v` 的四段版本号(当前 `0.18.5.1`)。上游 Monero git tag 带 `v`,构建时补回后传给 Dockerfile;tar.gz、DEB 和 Registry 路径使用纯数字版本。发布 tag 可带或不带 `v`,归一后必须与 VERSION 完全一致。
- **依赖精简**:5 个静态库 + libstdc++/libgcc 全部静态链入(真 `-static`),故 [debian/control.template](debian/control.template) **无 `Depends` 字段**(纯静态,连 libc6 都不需要)。
- 架构映射:Dockerfile 内 `arm64→ARCH=armv8-a / BUILD_TAG=linux-armv8`、`amd64→ARCH=x86-64 / BUILD_TAG=linux-x64`(传给 monero cmake);OpenSSL target `aarch64→linux-aarch64`、`x86_64→linux-x86_64`。
- tar.gz 下载 URL 形如 `https://gitea.bcde.io/api/packages/wangdefa/generic/mond/{version}/mond-{arch}-linux-static-{version}.tar.gz`(version 为纯数字)。
## 本地常用命令
```bash
# 本地编译某架构的二进制(输出到 ./output/linux_<arch>/mond)
docker buildx build --platform linux/amd64 \
--build-arg MONERO_VERSION="v$(cat VERSION)" \
--output type=local,dest=./output \
-f docker/Dockerfile .
# 用已有 tar.gz 打 .deb 包(注意第三个参数是 tar.gz,不是目录)
./debian/build-deb.sh amd64 0.18.5.1 mond-amd64-linux-static-0.18.5.1.tar.gz
# 改 shell 脚本后做静态检查(需自行安装 shellcheck)
shellcheck debian/*.sh
```
CI 对二进制执行 `mond --version` 和 `mond --help`,用 `ldd` 严格校验为纯静态,并检查 DEB 内的二进制、默认配置和 systemd 服务。
## Debian 包布局与服务
- 二进制装到 `/opt/mond/mond`,systemd 服务文件 [debian/mond.service](debian/mond.service),维护脚本 `debian/{postinst,prerm,postrm}`。
- **配置流转(单一数据源)**:`conf/params.example.conf` 是唯一配置源 → build-deb.sh 复制进包内 `/opt/mond/params.conf` → postinst 首次安装时 `cp` 到 `/etc/mond/params.conf`(**升级不覆盖**用户已有配置;旧版本位于 `/var/lib/mond/params.conf` 时 postinst 会自动迁移到 `/etc/mond/`)。service 的 `ExecStart` 用 `--config-file=/etc/mond/params.conf`。**改默认配置改 conf/params.example.conf 一处即可**(不要再在 postinst 内联)。
- 数据目录 `/var/lib/mond/data`、日志目录 `/var/log/mond`,均归 `mond` 系统用户。
- postinst 创建 `mond` 系统用户/组。**服务不自动启用/启动**(首次同步需用户确认配置),升级时若服务原为 enabled 则重启以加载新二进制。.deb 安装后手动 `systemctl enable --now mond`。
+72 -207
View File
@@ -1,239 +1,104 @@
# Mond # Mond
> Monero daemon 的定制版本 Mond 是 [Monero](https://github.com/monero-project/monero) 守护进程 `monerod` 的定制换名构建——Monero 全节点,负责 P2P 同步区块链、提供 RPC。换名(`monero→mond`、`monerod→mond`、`MONERO_*→MOND_*`)由 [init.sh](init.sh) 在构建期对官方源码做 `sed` 改写完成,不维护源码分叉。
[![License](https://img.shields.io/badge/license-BSD--3--Clause-blue.svg)](LICENSE) **本仓库只包含构建与打包基础设施**,不含 mond 源码:二进制在 CI 中从上游官方仓库 `github.com/monero-project/monero` 编译(init.sh 现场换名),再打包分发到 [gitea.bcde.io](https://gitea.bcde.io) 的 Generic / Debian 包仓库。
[![Build Status](https://img.shields.io/badge/build-passing-brightgreen.svg)](.gitea/workflows/ci.yaml)
## 🎯 主要特性 ## 产物
- 🏗️ **多架构支持** - 原生支持 AMD64 和 ARM64 架构 每次构建产出单个可执行文件(musl 纯静态,boost/OpenSSL/libzmq/libsodium/unbound/expat 及 libc 全部静态链入,无外部动态库依赖,任意 Linux 发行版可跑):
- 📦 **多种安装方式** - 提供 Debian 包和通用二进制包
- 🐧 **多发行版兼容** - 支持 Ubuntu 和 Debian
- 🔗 **纯静态链接** - 无需依赖,可在任意 Linux 系统运行
- 🔒 **隐私优先** - 基于 Monero 的隐私保护技术
- 🔄 **自动更新** - 通过 Debian 仓库轻松安装和更新
## 🚀 快速开始 | 二进制 | 作用 |
|---|---|
| `mond` | Monero 全节点守护进程:P2P 同步区块链、提供 RPC |
### Debian/Ubuntu(推荐) 支持架构 `amd64` / `arm64`;musl 纯静态(static-pie),任意 Linux 发行版(Debian/Ubuntu/Alpine/CentOS 等)开箱即跑。
## 安装
### APT(Debian / Ubuntu)
```bash ```bash
# 下载 GPG 密钥
sudo curl https://gitea.bcde.io/api/packages/wangdefa/debian/repository.key -o /etc/apt/keyrings/gitea-wangdefa.asc sudo curl https://gitea.bcde.io/api/packages/wangdefa/debian/repository.key -o /etc/apt/keyrings/gitea-wangdefa.asc
echo "deb [signed-by=/etc/apt/keyrings/gitea-wangdefa.asc] https://gitea.bcde.io/api/packages/wangdefa/debian stable main" | sudo tee /etc/apt/sources.list.d/wangdefa.list
# 添加仓库 sudo apt-get update && sudo apt-get install mond
echo "deb [signed-by=/etc/apt/keyrings/gitea-wangdefa.asc] https://gitea.bcde.io/api/packages/wangdefa/debian stable main" | sudo tee -a /etc/apt/sources.list.d/wangdefa.list
# 更新并安装
sudo apt-get update
sudo apt-get install mond
``` ```
### 方式二:通用二进制包 安装布局:
| | 路径 |
|---|---|
| 二进制 | `/opt/mond/mond` |
| 默认配置 | `/opt/mond/params.conf`(postinst 复制到 `/etc/mond/params.conf`) |
| 数据 | `/var/lib/mond/data` |
| 日志 | `/var/log/mond/` |
| 服务 | `mond.service` |
> 安装后服务**不会自动启动**(首次全节点同步前需确认配置)。按需编辑 `/etc/mond/params.conf`,再启用:
>
> ```bash
> sudo systemctl enable --now mond
> ```
### tar.gz(通用:Alpine / Ubuntu / Debian)
从 Generic Package Registry 下载对应架构的 tar.gz,解压即用(单二进制):
```bash ```bash
# 1. 下载对应架构的包 curl -fSL -o mond.tar.gz \
wget https://gitea.bcde.io/releases/download/v0.18.4.5/mond-amd64-ubuntu-v0.18.4.5.tar.gz https://gitea.bcde.io/api/packages/wangdefa/generic/mond/0.18.5.1/mond-amd64-linux-static-0.18.5.1.tar.gz
tar -xzf mond.tar.gz
# 2. 解压 ./mond --config-file params.conf # 配置模板见仓库 conf/params.example.conf
tar -xzf mond-amd64-ubuntu-v0.18.4.5.tar.gz
# 3. 运行
./mond --help
``` ```
## 📋 使用说明 ## 构建与发布
### Debian/Ubuntu 系统服务 Gitea Actions 分为两条流水线:
#### 启动服务 - [.gitea/workflows/ci.yml](.gitea/workflows/ci.yml):分支推送时检查版本、配置和 shell 语法,并在 amd64、arm64 原生 runner 上编译、严格冒烟测试和验证 DEB 包内容。
- [.gitea/workflows/release.yml](.gitea/workflows/release.yml):tag 推送时构建 tar.gz 和 DEB,生成 `SHA256SUMS`,上传包仓库并创建或更新 Release。
musl 纯静态在 `alpine:3.23` 下手编 5 个静态库(OpenSSL 3.0.21、libsodium 1.0.20、libzmq 4.3.5、expat 2.6.4、unbound 1.25.1)并 patch monero CMakeLists(去 `-pie`、Linux `STATIC_FLAGS` 改真 `-static`),产出 static-pie 零依赖二进制。换名 + patch 逻辑见 [init.sh](init.sh)。
本地构建:
```bash ```bash
# 启用并启动服务 # 编译某架构二进制(输出到 ./output/linux_<arch>/mond)
sudo systemctl enable mond.service
sudo systemctl start mond.service
# 查看状态
sudo systemctl status mond.service
# 查看日志
sudo journalctl -u mond -f
```
#### 停止服务
```bash
sudo systemctl stop mond.service
sudo systemctl disable mond.service
```
### 直接运行
```bash
# 基本运行
./mond
# 指定数据目录
./mond --data-dir=/path/to/data
# 指定日志文件
./mond --log-file=/path/to/log
# 后台运行
./mond --detach
```
## ⚙️ 配置说明
### 目录结构
#### Debian/Ubuntu 系统包
```
/opt/mond/mond # 二进制文件
/var/lib/mond/params.conf # 配置文件
/var/lib/mond/data/ # 区块链数据目录
/var/log/mond/ # 日志目录
```
### 修改配置
Debian/Ubuntu 系统包使用配置文件方式运行,修改配置非常简单:
```bash
# 1. 编辑配置文件
sudo nano /var/lib/mond/params.conf
# 2. 重启服务使配置生效
sudo systemctl restart mond.service
```
**优势**:配置文件在升级时不会被覆盖,您的自定义设置会被保留。
#### 通用二进制包
```
./mond # 二进制文件
```
### 常用命令行选项
```bash
--data-dir <path> # 指定数据目录
--log-file <path> # 指定日志文件路径
--log-level <level> # 日志级别 (0-4)
--detach # 后台运行
--rpc-bind-ip <ip> # RPC 绑定 IP (默认: 127.0.0.1)
--rpc-bind-port <port> # RPC 绑定端口 (默认: 18081)
--p2p-bind-ip <ip> # P2P 绑定 IP (默认: 0.0.0.0)
--p2p-bind-port <port> # P2P 绑定端口 (默认: 18080)
```
## 🔄 修改内容
本项目基于 [Monero](https://github.com/monero-project/monero) 进行以下修改:
1. **项目重命名**:`monero` → `mond`
2. **二进制文件名**:`monerod` → `mond`
3. **版本标识**:`MONERO_*` → `MOND_*`
所有修改通过 [init.sh](init.sh) 在构建过程中自动应用。
## 🏗️ 构建说明
### Docker 构建(推荐)
本项目使用 Docker 和官方 depends 系统构建,确保纯静态链接。
#### 构建多架构二进制文件
```bash
# 构建 amd64 和 arm64 架构
docker buildx build --platform linux/amd64,linux/arm64 \
-f docker/Dockerfile.ubuntu \
--output type=local,dest=./output .
```
#### 构建单一架构
```bash
# 仅构建 amd64
docker buildx build --platform linux/amd64 \ docker buildx build --platform linux/amd64 \
-f docker/Dockerfile.ubuntu \ --build-arg MONERO_VERSION="v$(cat VERSION)" \
--output type=local,dest=./output . --output type=local,dest=./output \
-f docker/Dockerfile .
# 仅构建 arm64 # 校验纯静态(应输出 "statically linked")
docker buildx build --platform linux/arm64 \
-f docker/Dockerfile.ubuntu \
--output type=local,dest=./output .
```
#### 验证静态链接
```bash
# 检查二进制文件是否为纯静态链接
ldd output/linux_amd64/mond ldd output/linux_amd64/mond
# 预期输出: "not a dynamic executable"
file output/linux_amd64/mond # 用产物 tar.gz 打 .deb
# 预期输出: "statically linked" ./debian/build-deb.sh amd64 0.18.5.1 mond-amd64-linux-static-0.18.5.1.tar.gz
``` ```
### 本地构建 ## 版本号约定
如果不使用 Docker,可以手动构建: - 根目录 [VERSION](VERSION) 是唯一版本来源,使用不带 `v` 的四段版本号。
- **上游源码 git tag** 带 `v`(如 `v0.18.5.1`),CI 构建时自动补回。
- **包版本**(tar.gz / deb / registry 路径)一律用数字(如 `0.18.5.1`),符合 Debian 版本规范。
- 发布 tag 可写成 `0.18.5.1` 或 `v0.18.5.1`,去掉 `v` 后必须与 VERSION 一致。
```bash 发版时先更新 VERSION 并提交,再创建同版本 tag。
# 1. 克隆并准备源代码
git clone https://github.com/monero-project/monero.git .source
cd .source
git checkout v0.18.3.4
git submodule update --init --force
# 2. 应用修改 ## 修改内容
../init.sh
# 3. 使用 depends 系统构建(推荐) 基于 [Monero](https://github.com/monero-project/monero)(BSD-3-Clause),由 [init.sh](init.sh) 在构建期自动应用,不维护源码分叉:
make -j$(nproc) depends target=x86_64-linux-gnu
# 二进制文件位于: build/x86_64-linux-gnu/release/bin/mond - 项目名 `monero` → `mond`
- 二进制 `monerod` → `mond`
- 版本宏 `MONERO_*` → `MOND_*`
## 目录结构
# 或者简单构建(需要手动安装依赖)
mkdir -p build/release && cd build/release
cmake ../.. -DCMAKE_BUILD_TYPE=Release -DBUILD_GUI_DEPS=OFF
make -j$(nproc) daemon
``` ```
.gitea/workflows/ CI 流水线
### 构建环境要求 docker/ Dockerfile(musl 纯静态,从上游官方源码编译 + init.sh 换名)
debian/ .deb 打包:control 模板、维护脚本、systemd 服务
- **操作系统**: Ubuntu 20.04(推荐)或更新版本 conf/ params.example.conf 默认配置模板
- **CPU**: 多核 CPU(构建时间约 30-60 分钟) init.sh 构建期换名 + 静态 patch 脚本
- **内存**: 至少 4GB RAM ```
- **磁盘**: 至少 10GB 可用空间
- **Docker**: 如使用 Docker 构建,需安装 Docker 和 buildx
## 📝 许可证
本项目基于 BSD-3-Clause 许可证开源。
- 原始项目:[Monero](https://github.com/monero-project/monero) (BSD-3-Clause)
- 修改内容:详见 [init.sh](init.sh)
## 🙏 致谢
- [Monero Project](https://github.com/monero-project/monero) - 原始项目和核心技术
## ⚠️ 免责声明
本软件仅供学习和研究使用。使用本软件进行任何活动请遵守当地法律法规。作者不对使用本软件造成的任何损失或法律问题负责。
## 📞 支持
如有问题或建议,请通过以下方式联系:
- 提交 Issue
- 发送 Pull Request
---
**注意**:本项目是 Monero 的定制版本,不代表官方 Monero 项目。
+1
View File
@@ -0,0 +1 @@
0.18.5.1
+20 -17
View File
@@ -3,16 +3,18 @@ set -e
# 参数检查 # 参数检查
if [ $# -ne 3 ]; then if [ $# -ne 3 ]; then
echo "Usage: $0 <ARCH> <VERSION> <BINARY_DIR>" echo "Usage: $0 <ARCH> <VERSION> <TARGZ_FILE>"
echo "Example: $0 amd64 0.18.4.5 build/Linux/release/bin" echo "Example: $0 amd64 0.18.5.1 mond-amd64-linux-static-0.18.5.1.tar.gz"
exit 1 exit 1
fi fi
ARCH=$1 ARCH=$1
VERSION=$2 VERSION=$2
BINARY_DIR=$3 TARGZ_FILE=$3
PKG_NAME="mond" PKG_NAME="mond"
DEB_FILE="${PKG_NAME}_${VERSION}_${ARCH}.deb" DEB_VERSION="${VERSION#v}" # Debian 版本号必须以数字开头,去掉可能的 v 前缀
[ -f "$TARGZ_FILE" ] || { echo "❌ 找不到产物包: $TARGZ_FILE"; exit 1; }
# 转换架构名称(Docker 使用的架构名到 Debian 架构名) # 转换架构名称(Docker 使用的架构名到 Debian 架构名)
case "$ARCH" in case "$ARCH" in
@@ -28,34 +30,34 @@ case "$ARCH" in
;; ;;
esac esac
DEB_FILE="${PKG_NAME}_${DEB_VERSION}_${DEB_ARCH}.deb"
echo "📦 Building Debian package: ${DEB_FILE}" echo "📦 Building Debian package: ${DEB_FILE}"
echo " Architecture: ${DEB_ARCH}" echo " Architecture: ${DEB_ARCH}"
echo " Version: ${VERSION}" echo " Version: ${DEB_VERSION}"
echo " Binary directory: ${BINARY_DIR}" echo " Source: ${TARGZ_FILE}"
# 检查二进制文件是否存在
if [ ! -f "${BINARY_DIR}/mond" ]; then
echo "❌ Error: mond binary not found in ${BINARY_DIR}"
exit 1
fi
# 创建临时目录 # 创建临时目录
BUILD_DIR=$(mktemp -d) BUILD_DIR=$(mktemp -d)
trap "rm -rf $BUILD_DIR" EXIT trap "rm -rf $BUILD_DIR" EXIT
# 创建包目录结构 # 创建包目录结构
PKG_DIR="${BUILD_DIR}/${PKG_NAME}_${VERSION}_${DEB_ARCH}" PKG_DIR="${BUILD_DIR}/${PKG_NAME}_${DEB_VERSION}_${DEB_ARCH}"
mkdir -p "${PKG_DIR}/DEBIAN" mkdir -p "${PKG_DIR}/DEBIAN"
mkdir -p "${PKG_DIR}/opt/mond" mkdir -p "${PKG_DIR}/opt/mond"
mkdir -p "${PKG_DIR}/lib/systemd/system" mkdir -p "${PKG_DIR}/lib/systemd/system"
# 复制二进制文件 # 解压二进制文件
echo "📂 Copying binary..." echo "📂 Extracting binary..."
cp "${BINARY_DIR}/mond" "${PKG_DIR}/opt/mond/mond" tar -xzf "${TARGZ_FILE}" -C "${PKG_DIR}/opt/mond"
# 打入默认配置(conf/params.example.conf 为唯一配置源,postinst 据此生成 /etc/mond/params.conf)
echo "📄 Bundling default config..."
cp conf/params.example.conf "${PKG_DIR}/opt/mond/params.conf"
# 生成 control 文件 # 生成 control 文件
echo "📝 Generating control file..." echo "📝 Generating control file..."
sed -e "s/{{VERSION}}/${VERSION}/" \ sed -e "s/{{VERSION}}/${DEB_VERSION}/" \
-e "s/{{ARCH}}/${DEB_ARCH}/" \ -e "s/{{ARCH}}/${DEB_ARCH}/" \
debian/control.template > "${PKG_DIR}/DEBIAN/control" debian/control.template > "${PKG_DIR}/DEBIAN/control"
@@ -74,6 +76,7 @@ cp debian/mond.service "${PKG_DIR}/lib/systemd/system/"
# 设置权限 # 设置权限
chmod 755 "${PKG_DIR}/opt/mond/mond" chmod 755 "${PKG_DIR}/opt/mond/mond"
chmod 644 "${PKG_DIR}/opt/mond/params.conf"
chmod 644 "${PKG_DIR}/lib/systemd/system/mond.service" chmod 644 "${PKG_DIR}/lib/systemd/system/mond.service"
# 构建 deb 包 # 构建 deb 包
-1
View File
@@ -3,7 +3,6 @@ Version: {{VERSION}}
Section: net Section: net
Priority: optional Priority: optional
Architecture: {{ARCH}} Architecture: {{ARCH}}
Depends: libc6, libboost-system1.74.0 | libboost-system1.81.0 | libboost-system1.83.0, libboost-filesystem1.74.0 | libboost-filesystem1.81.0 | libboost-filesystem1.83.0, libboost-thread1.74.0 | libboost-thread1.81.0 | libboost-thread1.83.0, libboost-program-options1.74.0 | libboost-program-options1.81.0 | libboost-program-options1.83.0, libssl3 | libssl1.1, libzmq5, libunwind8
Maintainer: Mond Team <noreply@example.com> Maintainer: Mond Team <noreply@example.com>
Homepage: https://github.com/monero-project/monero Homepage: https://github.com/monero-project/monero
Description: Mond cryptocurrency daemon Description: Mond cryptocurrency daemon
+1 -1
View File
@@ -9,7 +9,7 @@ Type=simple
WorkingDirectory=/opt/mond WorkingDirectory=/opt/mond
# 执行命令 - 使用配置文件 # 执行命令 - 使用配置文件
ExecStart=/opt/mond/mond --config-file=/var/lib/mond/params.conf --non-interactive ExecStart=/opt/mond/mond --config-file=/etc/mond/params.conf --non-interactive
# 重启策略 # 重启策略
Restart=always Restart=always
+32 -126
View File
@@ -17,120 +17,43 @@ mkdir -p /var/log/mond
chown mond:mond /var/log/mond chown mond:mond /var/log/mond
chmod 750 /var/log/mond chmod 750 /var/log/mond
# Create data directory # Create data directory(非递归设权限,避免升级时遍历庞大的区块链数据目录)
mkdir -p /var/lib/mond/data mkdir -p /var/lib/mond/data
chown -R mond:mond /var/lib/mond chown mond:mond /var/lib/mond /var/lib/mond/data
chmod -R 750 /var/lib/mond chmod 750 /var/lib/mond /var/lib/mond/data
# Create configuration file if it doesn't exist # Create config directory
if [ ! -f /var/lib/mond/params.conf ]; then mkdir -p /etc/mond
cat > /var/lib/mond/params.conf << 'EOF'
# Mond Configuration File
# This file is automatically created during installation
# Edit this file to customize your Mond daemon settings
# After modifying, restart the service: sudo systemctl restart mond.service
# DATA STORAGE # 兼容旧版本:配置文件曾位于 /var/lib/mond/params.conf,迁移到 /etc/mond/params.conf
# ============================================================================ if [ ! -f /etc/mond/params.conf ] && [ -f /var/lib/mond/params.conf ]; then
# data-dir: 区块链数据存储目录 echo "Migrating existing config from /var/lib/mond to /etc/mond..."
data-dir=/var/lib/mond/data cp /var/lib/mond/params.conf /etc/mond/params.conf
# BLOCKCHAIN PRUNING
# ============================================================================
# prune-blockchain: 启用区块链修剪模式
prune-blockchain=1
# sync-pruned-blocks: 同步已修剪的区块(默认启用)
sync-pruned-blocks=1
# NETWORK PEER SETTINGS
# ============================================================================
# out-peers: 主动连接的对等节点数量(出站连接)
out-peers=32
# in-peers: 接受连接的对等节点数量(入站连接)
in-peers=64
# limit-rate-up: 上传速率限制(kB/s)
limit-rate-up=1048576
# limit-rate-down: 下载速率限制(kB/s)
limit-rate-down=1048576
# PRIORITY NODES
# ============================================================================
# add-priority-node: 优先连接的可信节点
add-priority-node=p2pmd.xmrvsbeast.com:18080
add-priority-node=nodes.hashvault.pro:18080
# SECURITY AND NETWORK INTEGRITY
# ============================================================================
# enforce-dns-checkpointing: 强制执行 DNS 检查点验证
enforce-dns-checkpointing=1
# enable-dns-blocklist: 启用 DNS 黑名单
enable-dns-blocklist=1
# ZMQ NOTIFICATION SYSTEM
# ============================================================================
# zmq-pub: ZeroMQ 发布接口,用于实时广播区块链事件
zmq-pub=tcp://127.0.0.1:18083
# P2P AND RPC NETWORK BINDING
# ============================================================================
# p2p-bind-ip: P2P 网络监听地址(默认启用,绑定所有网络接口)
p2p-bind-ip=0.0.0.0
# p2p-bind-port: P2P 网络监听端口
p2p-bind-port=18080
# rpc-bind-ip: RPC 接口监听地址
#rpc-bind-ip=0.0.0.0
# rpc-bind-port: RPC 接口监听端口
#rpc-bind-port=18081
# confirm-external-bind: 确认外部网络绑定
#confirm-external-bind=1
# RPC AUTHENTICATION
# ============================================================================
# rpc-login: RPC 访问认证凭据
#rpc-login=user:password
# RPC SSL/TLS ENCRYPTION
# ============================================================================
# rpc-ssl: 启用 RPC 连接的 SSL/TLS 加密(语义更清晰的启用方式)
#rpc-ssl=enabled
# rpc-ssl-certificate: SSL 证书文件路径
#rpc-ssl-certificate=/path/to/your/certificate.pem
# rpc-ssl-private-key: SSL 私钥文件路径
#rpc-ssl-private-key=/path/to/your/private_key.pem
# LOGGING SETTINGS
# ============================================================================
# log-level: 日志详细程度(调整为详细日志级别)
log-level=1
# log-file: 日志文件保存路径
log-file=/var/log/mond/mond.log
EOF
chown mond:mond /var/lib/mond/params.conf
chmod 640 /var/lib/mond/params.conf
fi fi
# Set permissions on binary # 首次安装:从包内默认配置生成(源:conf/params.example.conf)。升级不覆盖已有配置
chown root:mond /opt/mond/mond if [ ! -f /etc/mond/params.conf ]; then
cp /opt/mond/params.conf /etc/mond/params.conf
fi
chown mond:mond /etc/mond/params.conf
chmod 640 /etc/mond/params.conf
# Set permissions:/opt 目录与二进制 755,数据文件 644(对齐 xxxig / xxxig-proxy)
chown -R root:root /opt/mond
find /opt/mond -type d -exec chmod 755 {} +
find /opt/mond -type f -exec chmod 644 {} +
chmod 755 /opt/mond/mond chmod 755 /opt/mond/mond
# Reload systemd # Reload systemd
if [ -d /run/systemd/system ]; then if [ -d /run/systemd/system ]; then
systemctl daemon-reload systemctl daemon-reload
# Note: Service is NOT auto-enabled or auto-started # 升级时重启正在运行的服务以加载新二进制;try-restart 不会启动未运行的服务,
# Users should manually enable the service: # 故首次安装仍保持"不自动启动"语义
systemctl try-restart mond.service 2>/dev/null || true
# Note: On fresh install, service is NOT auto-enabled or auto-started
# systemctl enable mond.service # systemctl enable mond.service
# systemctl start mond.service # systemctl start mond.service
fi fi
@@ -138,31 +61,14 @@ fi
echo "" echo ""
echo "✅ Mond installed successfully!" echo "✅ Mond installed successfully!"
echo "" echo ""
echo "📋 Configuration and startup:"
echo ""
echo "1. Review and configure settings (optional):"
echo " sudo nano /var/lib/mond/params.conf"
echo ""
echo " Adjust network settings, peer connections, and other options as needed."
echo ""
echo "2. Start Mond:"
echo " sudo systemctl enable mond.service"
echo " sudo systemctl start mond.service"
echo ""
echo "3. Check status:"
echo " sudo systemctl status mond.service"
echo " sudo journalctl -u mond -f"
echo ""
echo "📁 Important paths:" echo "📁 Important paths:"
echo " Config file: /var/lib/mond/params.conf" echo " Config file: /etc/mond/params.conf"
echo " Data directory: /var/lib/mond/data" echo " Data directory: /var/lib/mond/data"
echo " Log directory: /var/log/mond" echo " Log directory: /var/log/mond"
echo " Binary: /opt/mond/mond" echo " Binaries: /opt/mond/mond"
echo " Systemd services: mond.service"
echo "" echo ""
echo "💡 Tip: Your params.conf will NOT be overwritten during package upgrades." echo "💡 Tip: Your config files will NOT be overwritten during package upgrades."
echo ""
echo "For help:"
echo " /opt/mond/mond --help"
echo "" echo ""
exit 0 exit 0
+2 -1
View File
@@ -12,9 +12,10 @@ case "$1" in
delgroup --quiet mond || true delgroup --quiet mond || true
fi fi
# Remove data directories (only on purge) # Remove data/config directories (only on purge)
rm -rf /var/log/mond rm -rf /var/log/mond
rm -rf /var/lib/mond rm -rf /var/lib/mond
rm -rf /etc/mond
;; ;;
remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear) remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear)
+3 -2
View File
@@ -1,8 +1,9 @@
#!/bin/sh #!/bin/sh
set -e set -e
# Stop and disable service if running # 仅在卸载(remove)时停用服务;升级(upgrade)时保持运行,
if [ -d /run/systemd/system ]; then # 由 postinst 的 try-restart 重启以加载新二进制
if [ "$1" = "remove" ] && [ -d /run/systemd/system ]; then
if systemctl is-active --quiet mond.service; then if systemctl is-active --quiet mond.service; then
echo "Stopping mond service..." echo "Stopping mond service..."
systemctl stop mond.service systemctl stop mond.service
+66
View File
@@ -0,0 +1,66 @@
# musl fully-static 构建 mond(monerod 换名):手编 5 个静态库 + patch CMakeLists + static-pie。
# 为何 musl 而非 glibc:musl 的 getaddrinfo 自包含,全静态可跨发行版运行;glibc 静态会因 NSS
# 运行时 dlopen 失败(DNS error: resource busy or locked)。详见 CLAUDE.md。
# 产物为 static-pie(Alpine gcc 默认 PIE),零外部依赖,可在 glibc/musl 任意发行版直接运行。
# ---- Stage 1: 静态依赖库(版本固定 → Docker 层缓存,源码不变不重编)----
FROM alpine:3.23 AS deps
RUN apk add --no-cache g++ gcc make cmake git linux-headers autoconf automake libtool \
pkgconf perl wget tar xz bzip2 file flex bison boost-static boost-dev rapidjson-dev
ENV CFLAGS="-fPIC -O2" CXXFLAGS="-fPIC -O2"
WORKDIR /deps
# OpenSSL 3.0.21(与 Monero v0.18.5.1 depends 对齐;Alpine 仓库只有 .so,须源码编静态)
RUN wget -q https://github.com/openssl/openssl/releases/download/openssl-3.0.21/openssl-3.0.21.tar.gz && \
tar xf openssl-3.0.21.tar.gz && cd openssl-3.0.21 && \
if [ "$(uname -m)" = aarch64 ]; then OSSL_T=linux-aarch64; else OSSL_T=linux-x86_64; fi && \
./Configure no-shared no-tests --prefix=/usr --libdir=lib $OSSL_T && \
make -j"$(nproc)" && make install_sw && cd / && rm -rf /deps/openssl-3.0.21*
# libsodium 1.0.20
RUN wget -q https://download.libsodium.org/libsodium/releases/libsodium-1.0.20.tar.gz && \
tar xf libsodium-1.0.20.tar.gz && cd libsodium-1.0.20 && \
./configure --enable-static --disable-shared --prefix=/usr && \
make -j"$(nproc)" && make install && cd / && rm -rf /deps/libsodium-1.0.20*
# libzmq 4.3.5
RUN wget -q https://github.com/zeromq/libzmq/releases/download/v4.3.5/zeromq-4.3.5.tar.gz && \
tar xf zeromq-4.3.5.tar.gz && cd zeromq-4.3.5 && \
./configure --enable-static --disable-shared --prefix=/usr --without-docs --enable-drafts=no && \
make -j"$(nproc)" && make install && cd / && rm -rf /deps/zeromq-4.3.5*
# expat 2.6.4
RUN wget -q https://github.com/libexpat/libexpat/releases/download/R_2_6_4/expat-2.6.4.tar.bz2 && \
tar xf expat-2.6.4.tar.bz2 && cd expat-2.6.4 && \
./configure --enable-static --disable-shared --prefix=/usr && \
make -j"$(nproc)" && make install && cd / && rm -rf /deps/expat-2.6.4*
# unbound 1.25.1(DNSSEC,与 Monero v0.18.5.1 depends 对齐)
RUN wget -q https://www.nlnetlabs.nl/downloads/unbound/unbound-1.25.1.tar.gz && \
tar xf unbound-1.25.1.tar.gz && cd unbound-1.25.1 && \
./configure --disable-shared --enable-static --prefix=/usr --with-libexpat=/usr --with-ssl=/usr \
--with-libevent=no --without-pythonmodule --without-pyunbound --with-libunbound-only --with-pic && \
make -j"$(nproc)" && make install && cd / && rm -rf /deps/unbound*
# ---- Stage 2: 换名 + patch + 编译 mond ----
FROM deps AS build
ARG MONERO_VERSION
ARG TARGETARCH
WORKDIR /src
RUN git clone --recursive --branch "${MONERO_VERSION}" --depth 1 --shallow-submodules \
https://github.com/monero-project/monero.git monero
WORKDIR /src/monero
# init.sh:monero→mond 换名 + musl fully-static patch(去 -pie、STATIC_FLAGS 改 -static)
COPY ./init.sh ./init.sh
RUN sh ./init.sh
RUN if [ "$TARGETARCH" = "arm64" ]; then MARCH=armv8-a; MTAG=linux-armv8; \
else MARCH=x86-64; MTAG=linux-x64; fi && \
cmake -S . -B build/release -DSTATIC=ON -DSTACK_TRACE=OFF -DBUILD_64=ON \
-DCMAKE_BUILD_TYPE=Release -DARCH="$MARCH" -DBUILD_TAG="$MTAG" -DUSE_DEVICE_TREZOR=OFF && \
make -j"$(nproc)" -C build/release daemon && \
mkdir -p /output && cp build/release/bin/mond /output/mond
# ---- Stage 3: 导出(保持 CI 期望的 linux_<arch>/mond 布局)----
FROM scratch
ARG TARGETARCH
COPY --from=build /output/mond /linux_${TARGETARCH}/mond
-83
View File
@@ -1,83 +0,0 @@
FROM ubuntu:20.04 AS base
ARG TARGETARCH
ARG BUILDPLATFORM
ENV DEBIAN_FRONTEND=noninteractive
# 安装构建依赖(包括 depends 系统所需工具)
RUN apt-get update && apt-get install -y \
git \
wget \
curl \
build-essential \
cmake \
pkg-config \
autoconf \
automake \
libtool \
bzip2 \
xz-utils \
python3 \
gperf \
libboost-all-dev \
libssl-dev \
libzmq3-dev \
libunbound-dev \
libsodium-dev \
libunwind8-dev \
liblzma-dev \
libreadline-dev \
libexpat1-dev \
libpgm-dev \
qttools5-dev-tools \
libhidapi-dev \
libusb-1.0-0-dev \
libprotobuf-dev \
protobuf-compiler \
libudev-dev \
libgtest-dev \
&& rm -rf /var/lib/apt/lists/*
FROM base AS build
ARG MONERO_VERSION=v0.18.4.5
ARG TARGETARCH
ARG BUILDPLATFORM
ARG TARGETPLATFORM
# 克隆 Monero 项目
RUN git clone --recursive https://github.com/monero-project/monero.git && \
cd monero && \
git checkout ${MONERO_VERSION} && \
git submodule update --init --force
WORKDIR /monero
# 复制并运行 init.sh 脚本进行修改
COPY ./init.sh ./init.sh
RUN chmod +x ./init.sh && ./init.sh
# 使用官方 depends 系统构建静态依赖(参考 .source/Dockerfile)
RUN if [ "$BUILDPLATFORM" != "$TARGETPLATFORM" ]; then \
MAKE_JOBS=2; \
else \
MAKE_JOBS=$(nproc); \
fi && \
if [ "$TARGETARCH" = "arm64" ]; then \
DEPENDS_TARGET="aarch64-linux-gnu"; \
else \
DEPENDS_TARGET="x86_64-linux-gnu"; \
fi && \
echo "Building dependencies for $DEPENDS_TARGET with $MAKE_JOBS parallel jobs" && \
make -j$MAKE_JOBS depends target=$DEPENDS_TARGET && \
mkdir -p /output && \
cp build/$DEPENDS_TARGET/release/bin/mond /output/mond
# 最终阶段 - 只复制静态链接的二进制文件
FROM scratch
ARG TARGETARCH
COPY --from=build /output/mond /linux_${TARGETARCH}/mond
+31
View File
@@ -1,4 +1,22 @@
#!/bin/sh #!/bin/sh
set -eu
require_pattern() {
pattern=$1
file=$2
grep -Fq -- "$pattern" "$file" || {
echo "Required patch anchor not found in $file: $pattern" >&2
exit 1
}
}
require_pattern 'project(monero)' CMakeLists.txt
require_pattern 'OUTPUT_NAME "monerod"' src/daemon/CMakeLists.txt
require_pattern '${monero_SOURCE_DIR}' cmake/CheckLinkerFlag.cmake
require_pattern 'DEF_MONERO_VERSION' src/version.cpp.in
require_pattern 'DEF_MONERO_RELEASE_NAME "Fluorine Fermi"' src/version.cpp.in
require_pattern 'add_linker_flag_if_supported("-pie" LD_SECURITY_FLAGS)' CMakeLists.txt
require_pattern 'set(STATIC_FLAGS "-static-libgcc -static-libstdc++")' CMakeLists.txt
# Modify the CMakeLists.txt and source files to change the project name from "monero" to "mond" # Modify the CMakeLists.txt and source files to change the project name from "monero" to "mond"
@@ -50,6 +68,19 @@ find tests -type f -name "*.cpp" -exec sed -i 's/"Monero '"'"'/"Mond '"'"'/g' {}
# Uncomment the following lines if you want to remove Monero Project copyright # Uncomment the following lines if you want to remove Monero Project copyright
# find . -type f \( -name "*.cpp" -o -name "*.h" \) -exec sed -i '/Copyright.*The Monero Project/d' {} \; # find . -type f \( -name "*.cpp" -o -name "*.h" \) -exec sed -i '/Copyright.*The Monero Project/d' {} \;
# 8. musl fully-static patch(配合 docker/Dockerfile,产出无 interpreter、零外部依赖的 static-pie)
# monero 官方"不支持 fully static":STATIC=ON 在 Linux 仅给 -static-libgcc/-static-libstdc++,且强制 -pie。
# 去掉 -pie(否则强制动态 PIE/带 musl interpreter,无法跨发行版)
sed -i 's|add_linker_flag_if_supported("-pie" LD_SECURITY_FLAGS)|# -pie removed for fully-static|' CMakeLists.txt
# Linux STATIC_FLAGS 从 -static-libgcc/-static-libstdc++ 改真 -static
sed -i 's|set(STATIC_FLAGS "-static-libgcc -static-libstdc++")|set(STATIC_FLAGS "-static")|' CMakeLists.txt
require_pattern 'project(mond)' CMakeLists.txt
require_pattern 'OUTPUT_NAME "mond"' src/daemon/CMakeLists.txt
require_pattern 'DEF_MOND_VERSION' src/version.cpp.in
require_pattern '# -pie removed for fully-static' CMakeLists.txt
require_pattern 'set(STATIC_FLAGS "-static")' CMakeLists.txt
echo "Project successfully modified from Monero to Mond!" echo "Project successfully modified from Monero to Mond!"
echo "Binary output name: mond" echo "Binary output name: mond"
echo "Project name: mond" echo "Project name: mond"