Before every release candidate:
- Update translations (ping wumpus on IRC) see translation_process.md.
Before every minor and major release:
- Update bips.md to account for changes since the last release.
- Update version in sources (see below)
- Write release notes (see below)
- Update
src/chainparams.cpp
nMinimumChainWork with information from the getblockchaininfo rpc.
Before every major release:
- Update hardcoded seeds, see this pull request for an example.
Check out the source code in the following directory hierarchy.
cd /path/to/your/toplevel/build
git clone https://github.com/florincoin-project/gitian.sigs.ltc.git
git clone https://github.com/florincoin-project/florincoin-detached-sigs.git
git clone https://github.com/devrandom/gitian-builder.git
git clone https://github.com/florincoin-project/florincoin.git
Update the following:
configure.ac
:_CLIENT_VERSION_MAJOR
_CLIENT_VERSION_MINOR
_CLIENT_VERSION_REVISION
- Don't forget to set
_CLIENT_VERSION_IS_RELEASE
totrue
src/clientversion.h
: (this mirrorsconfigure.ac
- see issue #3539)CLIENT_VERSION_MAJOR
CLIENT_VERSION_MINOR
CLIENT_VERSION_REVISION
- Don't forget to set
CLIENT_VERSION_IS_RELEASE
totrue
doc/README.md
anddoc/README_windows.txt
doc/Doxyfile
:PROJECT_NUMBER
contains the full versioncontrib/gitian-descriptors/*.yml
: usually one'd want to do this on master after branching off the release - but be sure to at least do it before a new major release
Write release notes. git shortlog helps a lot, for example:
git shortlog --no-merges v(current version, e.g. 0.7.2)..v(new version, e.g. 0.8.0)
(or ping @wumpus on IRC, he has specific tooling to generate the list of merged pulls and sort them into categories based on labels)
Generate list of authors:
git log --format='%aN' "$*" | sort -ui | sed -e 's/^/- /'
Tag version (or release candidate) in git
git tag -s v(new version, e.g. 0.8.0)
Setup Gitian descriptors:
pushd ./florincoin
export SIGNER=(your Gitian key, ie bluematt, sipa, etc)
export VERSION=(new version, e.g. 0.8.0)
git fetch
git checkout v${VERSION}
popd
Ensure your gitian.sigs.ltc are up-to-date if you wish to gverify your builds against other Gitian signatures.
pushd ./gitian.sigs.ltc
git pull
popd
Ensure gitian-builder is up-to-date:
pushd ./gitian-builder
git pull
popd
pushd ./gitian-builder
mkdir -p inputs
wget -P inputs https://bitcoincore.org/cfields/osslsigncode-Backports-to-1.7.1.patch
wget -P inputs http://downloads.sourceforge.net/project/osslsigncode/osslsigncode/osslsigncode-1.7.1.tar.gz
popd
Create the OS X SDK tarball, see the OS X readme for details, and copy it into the inputs directory.
By default, Gitian will fetch source files as needed. To cache them ahead of time:
pushd ./gitian-builder
make -C ../florincoin/depends download SOURCES_PATH=`pwd`/cache/common
popd
Only missing files will be fetched, so this is safe to re-run for each build.
NOTE: Offline builds must use the --url flag to ensure Gitian fetches only from local URLs. For example:
pushd ./gitian-builder
./bin/gbuild --url florincoin=/path/to/florincoin,signature=/path/to/sigs {rest of arguments}
popd
The gbuild invocations below DO NOT DO THIS by default.
pushd ./gitian-builder
./bin/gbuild --memory 3000 --commit florincoin=v${VERSION} ../florincoin/contrib/gitian-descriptors/gitian-linux.yml
./bin/gsign --signer $SIGNER --release ${VERSION}-linux --destination ../gitian.sigs.ltc/ ../florincoin/contrib/gitian-descriptors/gitian-linux.yml
mv build/out/florincoin-*.tar.gz build/out/src/florincoin-*.tar.gz ../
./bin/gbuild --memory 3000 --commit florincoin=v${VERSION} ../florincoin/contrib/gitian-descriptors/gitian-win.yml
./bin/gsign --signer $SIGNER --release ${VERSION}-win-unsigned --destination ../gitian.sigs.ltc/ ../florincoin/contrib/gitian-descriptors/gitian-win.yml
mv build/out/florincoin-*-win-unsigned.tar.gz inputs/florincoin-win-unsigned.tar.gz
mv build/out/florincoin-*.zip build/out/florincoin-*.exe ../
./bin/gbuild --memory 3000 --commit florincoin=v${VERSION} ../florincoin/contrib/gitian-descriptors/gitian-osx.yml
./bin/gsign --signer $SIGNER --release ${VERSION}-osx-unsigned --destination ../gitian.sigs.ltc/ ../florincoin/contrib/gitian-descriptors/gitian-osx.yml
mv build/out/florincoin-*-osx-unsigned.tar.gz inputs/florincoin-osx-unsigned.tar.gz
mv build/out/florincoin-*.tar.gz build/out/florincoin-*.dmg ../
popd
Build output expected:
- source tarball (
florincoin-${VERSION}.tar.gz
) - linux 32-bit and 64-bit dist tarballs (
florincoin-${VERSION}-linux[32|64].tar.gz
) - windows 32-bit and 64-bit unsigned installers and dist zips (
florincoin-${VERSION}-win[32|64]-setup-unsigned.exe
,florincoin-${VERSION}-win[32|64].zip
) - OS X unsigned installer and dist tarball (
florincoin-${VERSION}-osx-unsigned.dmg
,florincoin-${VERSION}-osx64.tar.gz
) - Gitian signatures (in
gitian.sigs.ltc/${VERSION}-<linux|{win,osx}-unsigned>/(your Gitian key)/
)
Add other gitian builders keys to your gpg keyring
gpg --import florincoin/contrib/gitian-keys/*.pgp
Verify the signatures
pushd ./gitian-builder
./bin/gverify -v -d ../gitian.sigs.ltc/ -r ${VERSION}-linux ../florincoin/contrib/gitian-descriptors/gitian-linux.yml
./bin/gverify -v -d ../gitian.sigs.ltc/ -r ${VERSION}-win-unsigned ../florincoin/contrib/gitian-descriptors/gitian-win.yml
./bin/gverify -v -d ../gitian.sigs.ltc/ -r ${VERSION}-osx-unsigned ../florincoin/contrib/gitian-descriptors/gitian-osx.yml
popd
Commit your signature to gitian.sigs.ltc:
pushd gitian.sigs.ltc
git add ${VERSION}-linux/${SIGNER}
git add ${VERSION}-win-unsigned/${SIGNER}
git add ${VERSION}-osx-unsigned/${SIGNER}
git commit -a
git push # Assuming you can push to the gitian.sigs.ltc tree
popd
Wait for Windows/OS X detached signatures:
- Once the Windows/OS X builds each have 3 matching signatures, they will be signed with their respective release keys.
- Detached signatures will then be committed to the florincoin-detached-sigs repository, which can be combined with the unsigned apps to create signed binaries.
Create (and optionally verify) the signed OS X binary:
pushd ./gitian-builder
./bin/gbuild -i --commit signature=v${VERSION} ../florincoin/contrib/gitian-descriptors/gitian-osx-signer.yml
./bin/gsign --signer $SIGNER --release ${VERSION}-osx-signed --destination ../gitian.sigs.ltc/ ../florincoin/contrib/gitian-descriptors/gitian-osx-signer.yml
./bin/gverify -v -d ../gitian.sigs.ltc/ -r ${VERSION}-osx-signed ../florincoin/contrib/gitian-descriptors/gitian-osx-signer.yml
mv build/out/florincoin-osx-signed.dmg ../florincoin-${VERSION}-osx.dmg
popd
Create (and optionally verify) the signed Windows binaries:
pushd ./gitian-builder
./bin/gbuild -i --commit signature=v${VERSION} ../florincoin/contrib/gitian-descriptors/gitian-win-signer.yml
./bin/gsign --signer $SIGNER --release ${VERSION}-win-signed --destination ../gitian.sigs.ltc/ ../florincoin/contrib/gitian-descriptors/gitian-win-signer.yml
./bin/gverify -v -d ../gitian.sigs.ltc/ -r ${VERSION}-win-signed ../florincoin/contrib/gitian-descriptors/gitian-win-signer.yml
mv build/out/florincoin-*win64-setup.exe ../florincoin-${VERSION}-win64-setup.exe
mv build/out/florincoin-*win32-setup.exe ../florincoin-${VERSION}-win32-setup.exe
popd
Commit your signature for the signed OS X/Windows binaries:
pushd gitian.sigs.ltc
git add ${VERSION}-osx-signed/${SIGNER}
git add ${VERSION}-win-signed/${SIGNER}
git commit -a
git push # Assuming you can push to the gitian.sigs.ltc tree
popd
- Create
SHA256SUMS.asc
for the builds, and GPG-sign it:
sha256sum * > SHA256SUMS
The list of files should be:
florincoin-${VERSION}-aarch64-linux-gnu.tar.gz
florincoin-${VERSION}-arm-linux-gnueabihf.tar.gz
florincoin-${VERSION}-i686-pc-linux-gnu.tar.gz
florincoin-${VERSION}-x86_64-linux-gnu.tar.gz
florincoin-${VERSION}-osx64.tar.gz
florincoin-${VERSION}-osx.dmg
florincoin-${VERSION}.tar.gz
florincoin-${VERSION}-win32-setup.exe
florincoin-${VERSION}-win32.zip
florincoin-${VERSION}-win64-setup.exe
florincoin-${VERSION}-win64.zip
The *-debug*
files generated by the gitian build contain debug symbols
for troubleshooting by developers. It is assumed that anyone that is interested
in debugging can run gitian to generate the files for themselves. To avoid
end-user confusion about which file to pick, as well as save storage
space do not upload these to the florincoin.org server, nor put them in the torrent.
- GPG-sign it, delete the unsigned file:
gpg --digest-algo sha256 --clearsign SHA256SUMS # outputs SHA256SUMS.asc
rm SHA256SUMS
(the digest algorithm is forced to sha256 to avoid confusion of the Hash:
header that GPG adds with the SHA256 used for the files)
Note: check that SHA256SUMS itself doesn't end up in SHA256SUMS, which is a spurious/nonsensical entry.
-
Upload zips and installers, as well as
SHA256SUMS.asc
from last step, to the florincoin.org server. -
Update florincoin.org version
-
Announce the release:
-
florincoin-dev mailing list
-
Florincoin Core announcements list https://groups.google.com/forum/#!forum/florincoin-dev
-
blog.florincoin.org blog post
-
florincointalk.io forum announcement
-
Update title of #florincoin on Freenode IRC
-
Optionally twitter, reddit /r/Florincoin, ... but this will usually sort out itself
-
Add release notes for the new version to the directory
doc/release-notes
in git master -
Celebrate
-