mirror of
https://github.com/simplex-chat/simplex-chat.git
synced 2026-08-06 23:39:54 +00:00
docs: verify and reproduce builds (#6515)
* docs/REPRODUCIBLE: add new * docs/REPRODUCIBLE: clarify Android requirements * rename to REPRODUCE * expand and fix sections * website * docs, site: change links to simplex.apk to simplex-aarch64.apk --------- Co-authored-by: Evgeny Poberezkin <evgeny@poberezkin.com>
This commit is contained in:
+5
-1
@@ -24,6 +24,8 @@ You can link your mobile device with desktop to use the same profile remotely, b
|
||||
- Ubuntu 22.04 and Debian-based distros ([x86_64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-desktop-ubuntu-22_04-x86_64.deb), [aarch64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-desktop-ubuntu-22_04-aarch64.deb)).
|
||||
- Ubuntu 24.04 ([x86_64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-desktop-ubuntu-24_04-x86_64.deb), [aarch64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-desktop-ubuntu-24_04-aarch64.deb)).
|
||||
|
||||
You can [verify and reproduce](./REPRODUCE.md) Linux builds.
|
||||
|
||||
**Mac**: [x86_64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-desktop-macos-x86_64.dmg) (Intel), [aarch64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-desktop-macos-aarch64.dmg) (Apple Silicon).
|
||||
|
||||
**Windows**: [x86_64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-desktop-windows-x86_64.msi).
|
||||
@@ -32,7 +34,9 @@ You can link your mobile device with desktop to use the same profile remotely, b
|
||||
|
||||
**iOS**: [App store](https://apps.apple.com/us/app/simplex-chat/id1605771084), [TestFlight](https://testflight.apple.com/join/DWuT2LQu).
|
||||
|
||||
**Android**: [Play store](https://play.google.com/store/apps/details?id=chat.simplex.app), [F-Droid](https://simplex.chat/fdroid/), [APK aarch64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk), [APK armv7](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-armv7a.apk).
|
||||
**Android**: [Play store](https://play.google.com/store/apps/details?id=chat.simplex.app), [F-Droid](https://simplex.chat/fdroid/), [APK aarch64](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk), [APK armv7](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-armv7a.apk).
|
||||
|
||||
You can [verify and reproduce](./REPRODUCE.md) Android APKs.
|
||||
|
||||
## Terminal (console) app
|
||||
|
||||
|
||||
@@ -0,0 +1,203 @@
|
||||
---
|
||||
title: Verify and reproduce builds
|
||||
permalink: /reproduce/index.html
|
||||
revision: 19.12.2025
|
||||
---
|
||||
|
||||
# Verifying and reproducing release builds
|
||||
|
||||
- [Obtain release signing key](#obtain-release-signing-key)
|
||||
- [Verify release signature](#verify-release-signature)
|
||||
- [How to reproduce builds](#how-to-reproduce-builds)
|
||||
- [Server binaries](#server-binaries)
|
||||
- [Linux desktop apps and CLI](#linux-desktop-apps-and-cli)
|
||||
- [Android apps](#android-apps)
|
||||
|
||||
## Obtain release signing key
|
||||
|
||||
To verify the signature of `_sha256sums` or apks you need to obtain the signing key. You can do it from keyservers:
|
||||
|
||||
```sh
|
||||
gpg --keyserver hkps://keys.openpgp.org --search build@simplex.chat
|
||||
gpg --keyserver hkps://keyserver.ubuntu.com --search build@simplex.chat
|
||||
```
|
||||
|
||||
```sh
|
||||
gpg --list-keys build@simplex.chat
|
||||
```
|
||||
|
||||
Once you obtain the signing key, verify that its fingerprint is:
|
||||
|
||||
```
|
||||
BBDF 7BDA D154 8B16 836A F5B9 D53B DFD1 53C3 66BA
|
||||
```
|
||||
|
||||
Additionally, compare the key fingerprint with:
|
||||
|
||||
- [simplexchat.eth](https://app.ens.domains/simplexchat.eth) (release key record)
|
||||
- [Mastodon](https://mastodon.social/@simplex) (profile)
|
||||
- [Reddit](https://www.reddit.com/r/SimpleXChat/) (side panel)
|
||||
|
||||
You can set the imported key as "ultimately trusted":
|
||||
|
||||
```sh
|
||||
echo -e "trust\n5\ny\nquit" | gpg --command-fd 0 --edit-key build@simplex.chat
|
||||
```
|
||||
|
||||
## Verify release signature
|
||||
|
||||
**Linux dekstop apps and CLI**:
|
||||
|
||||
Download the file with executable hashes and the signature. For example, to verify the `v6.5.0-beta.3` release:
|
||||
|
||||
```sh
|
||||
curl -LO 'https://github.com/simplex-chat/simplex-chat/releases/download/v6.5.0-beta.3/_sha256sums.asc'
|
||||
curl -LO 'https://github.com/simplex-chat/simplex-chat/releases/download/v6.5.0-beta.3/_sha256sums'
|
||||
```
|
||||
|
||||
Verify the signature:
|
||||
|
||||
```sh
|
||||
gpg --verify _sha256sums.asc _sha256sums
|
||||
```
|
||||
|
||||
**Android APKs**:
|
||||
|
||||
Download the APK files and signatures. For example, to verify the `v6.5.0-beta.3` release:
|
||||
|
||||
```sh
|
||||
curl -LO 'https://github.com/simplex-chat/simplex-chat/releases/download/v6.5.0-beta.3/simplex-aarch64.apk'
|
||||
curl -LO 'https://github.com/simplex-chat/simplex-chat/releases/download/v6.5.0-beta.3/_simplex-aarch64.apk.asc'
|
||||
curl -LO 'https://github.com/simplex-chat/simplex-chat/releases/download/v6.5.0-beta.3/simplex-armv7a.apk'
|
||||
curl -LO 'https://github.com/simplex-chat/simplex-chat/releases/download/v6.5.0-beta.3/_simplex-armv7a.apk.asc'
|
||||
```
|
||||
|
||||
Verify the signatures:
|
||||
|
||||
```sh
|
||||
gpg --verify _simplex-armv7a.apk.asc simplex-armv7a.apk
|
||||
gpg --verify _simplex-aarch64.apk.asc simplex-aarch64.apk
|
||||
```
|
||||
|
||||
## How to reproduce builds
|
||||
|
||||
To reproduce the build you must have:
|
||||
|
||||
- Linux machine
|
||||
- `x86-64` architecture
|
||||
- Installed `docker`, `curl` and `git`
|
||||
|
||||
### Server binaries
|
||||
|
||||
1. Download script:
|
||||
|
||||
```sh
|
||||
curl -LO 'https://raw.githubusercontent.com/simplex-chat/simplexmq/refs/heads/master/scripts/simplexmq-reproduce-builds.sh'
|
||||
```
|
||||
|
||||
2. Make it executable:
|
||||
|
||||
```sh
|
||||
chmod +x simplexmq-reproduce-builds.sh
|
||||
```
|
||||
|
||||
3. Execute the script with the required tag:
|
||||
|
||||
```sh
|
||||
./simplexmq-reproduce-builds.sh 'v6.3.1'
|
||||
```
|
||||
|
||||
The script executes these steps (please review the script to confirm):
|
||||
|
||||
1) builds all server binaries for the release in docker container.
|
||||
2) downloads binaries from the same GitHub release and compares them with the built binaries.
|
||||
3) if they all match, generates _sha256sums file with their checksums.
|
||||
|
||||
This will take a while.
|
||||
|
||||
4. After compilation, you should see the folder named as the tag and repository name (e.g., `v6.3.1-simplexmq`) with two subfolders:
|
||||
|
||||
```sh
|
||||
ls v6.3.1-simplexmq
|
||||
```
|
||||
|
||||
```sh
|
||||
from-source prebuilt _sha256sums
|
||||
```
|
||||
|
||||
The file _sha256sums contains the hashes of all builds - you can compare it with the same file in GitHub release.
|
||||
|
||||
### Linux desktop apps and CLI
|
||||
|
||||
1. Download script:
|
||||
|
||||
```sh
|
||||
curl -LO 'https://raw.githubusercontent.com/simplex-chat/simplex-chat/refs/heads/master/scripts/simplex-chat-reproduce-builds.sh'
|
||||
```
|
||||
|
||||
2. Make it executable:
|
||||
|
||||
```sh
|
||||
chmod +x simplex-chat-reproduce-builds.sh
|
||||
```
|
||||
|
||||
3. Execute the script with the required tag:
|
||||
|
||||
```sh
|
||||
./simplex-chat-reproduce-builds.sh 'v6.4.8'
|
||||
```
|
||||
|
||||
The script executes these steps (please review the script to confirm):
|
||||
|
||||
1) builds all Linux CLI and Dekstop binaries for the release in docker container.
|
||||
2) downloads binaries from the same GitHub release and compares them with the built binaries.
|
||||
3) if they all match, generates _sha256sums file with their checksums.
|
||||
|
||||
This will take a while.
|
||||
|
||||
4. After compilation, you should see the folder named as the tag and reprository name (e.g., `v6.4.8-simplex-chat`) with two subfolders:
|
||||
|
||||
```sh
|
||||
ls v6.4.8-simplex-chat
|
||||
```
|
||||
|
||||
```sh
|
||||
from-source prebuilt _sha256sums
|
||||
```
|
||||
|
||||
The file _sha256sums contains the hashes of all builds - you can compare it with the same file in GitHub release.
|
||||
|
||||
### Android apps
|
||||
|
||||
In addition to basic requirments, Android build will:
|
||||
|
||||
- Take ~150gb of disc space
|
||||
- Take ~20h to build all the architectures (depends on core count)
|
||||
- Require at least 16gb of RAM
|
||||
|
||||
1. Download script:
|
||||
|
||||
```sh
|
||||
curl -LO 'https://raw.githubusercontent.com/simplex-chat/simplex-chat/refs/heads/master/scripts/simplex-chat-reproduce-builds-android.sh'
|
||||
```
|
||||
|
||||
2. Make it executable:
|
||||
|
||||
```sh
|
||||
chmod +x simplex-chat-reproduce-builds-android.sh
|
||||
```
|
||||
|
||||
3. Execute the script with the required tag:
|
||||
|
||||
```sh
|
||||
./simplex-chat-reproduce-builds-android.sh 'v6.5.0-beta.3'
|
||||
```
|
||||
|
||||
The script executes these steps (please review the script to confirm):
|
||||
|
||||
1) Downloads and checks that APKs from GitHub are signed with valid key.
|
||||
2) Builds Android APKs in a docker container.
|
||||
3) Compares the releases by copying the signature from downloaded APKs to locally built APKs.
|
||||
4) If the resulting build is bit-by-bit identical, prints the message that this tag was reproduced.
|
||||
|
||||
This will take a while.
|
||||
@@ -1,5 +1,5 @@
|
||||
---
|
||||
title: Contributing translations to SimpleX Chat
|
||||
title: Contributing SimpleX app translations
|
||||
revision: 19.03.2023
|
||||
---
|
||||
|
||||
|
||||
+1
-2
@@ -1,5 +1,5 @@
|
||||
---
|
||||
title: Using custom WebRTC ICE servers in SimpleX Chat
|
||||
title: Using custom WebRTC ICE servers
|
||||
revision: 31.01.2023
|
||||
---
|
||||
|
||||
@@ -155,4 +155,3 @@ This is it - you now can make audio and video calls via your own server, without
|
||||
<img src="./stun_3.png">
|
||||
|
||||
If results show `srflx` and `relay` candidates, everything is set up correctly!
|
||||
|
||||
|
||||
@@ -18,11 +18,11 @@
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/testflight.png" alt="iOS TestFlight" height="41">](https://testflight.apple.com/join/DWuT2LQu)
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)
|
||||
|
||||
- 🖲 Chrání vaše zprávy a metadata - s kým a kdy mluvíte.
|
||||
- 🔐 Koncové šifrování s další vrstvou šifrování.
|
||||
- 📱 Mobilní aplikace pro Android ([Google Play](https://play.google.com/store/apps/details?id=chat.simplex.app), [APK](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)) a [iOS](https://apps.apple.com/us/app/simplex-chat/id1605771084).
|
||||
- 📱 Mobilní aplikace pro Android ([Google Play](https://play.google.com/store/apps/details?id=chat.simplex.app), [APK](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)) a [iOS](https://apps.apple.com/us/app/simplex-chat/id1605771084).
|
||||
- 🚀 [TestFlight preview for iOS](https://testflight.apple.com/join/DWuT2LQu) s novými funkcemi o 1-2 týdny dříve - **omezeno na 10 000 uživatelů**!
|
||||
- 🖥 K dispozici jako terminálová (konzolová) [aplikace / CLI](#zap-quick-installation-of-a-terminal-app) v systémech Linux, MacOS, Windows.
|
||||
|
||||
@@ -324,4 +324,4 @@ Jakákoli zjištění možných útoků korelace provozu umožňujících korelo
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/testflight.png" alt="iOS TestFlight" height="41">](https://testflight.apple.com/join/DWuT2LQu)
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)
|
||||
|
||||
@@ -32,11 +32,11 @@
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/testflight.png" alt="iOS TestFlight" height="41">](https://testflight.apple.com/join/DWuT2LQu)
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)
|
||||
|
||||
- 🖲 Protégez vos messages et vos métadonnées - avec qui vous parlez et quand.
|
||||
- 🔐 Chiffrement de bout en bout à double ratchet, avec couche de chiffrement supplémentaire.
|
||||
- 📱 Apps mobiles pour Android ([Google Play](https://play.google.com/store/apps/details?id=chat.simplex.app), [APK](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)) et [iOS](https://apps.apple.com/us/app/simplex-chat/id1605771084).
|
||||
- 📱 Apps mobiles pour Android ([Google Play](https://play.google.com/store/apps/details?id=chat.simplex.app), [APK](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)) et [iOS](https://apps.apple.com/us/app/simplex-chat/id1605771084).
|
||||
- 🚀 [Bêta TestFlight pour iOS](https://testflight.apple.com/join/DWuT2LQu) avec les nouvelles fonctionnalités 1 à 2 semaines plus tôt - **limitée à 10 000 utilisateurs** !
|
||||
- 🖥 Disponible en tant que [terminal (console) / CLI](#⚡-installation-rapide-dune-application-pour-terminal) sur Linux, MacOS, Windows.
|
||||
|
||||
@@ -351,4 +351,4 @@ Veuillez traiter toute découverte d'une éventuelle attaque par corrélation de
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/testflight.png" alt="iOS TestFlight" height="41">](https://testflight.apple.com/join/DWuT2LQu)
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)
|
||||
|
||||
@@ -32,11 +32,11 @@
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/testflight.png" alt="iOS TestFlight" height="41">](https://testflight.apple.com/join/DWuT2LQu)
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)
|
||||
|
||||
- 🖲 Chroni Twoje wiadomości i metadane - z kim rozmawiasz i kiedy.
|
||||
- 🔐 Szyfrowanie end-to-end double ratchet, z dodatkową warstwą szyfrowania.
|
||||
- 📱 Aplikacje mobilne dla Androida ([Google Play](https://play.google.com/store/apps/details?id=chat.simplex.app), [APK](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)) oraz [iOS](https://apps.apple.com/us/app/simplex-chat/id1605771084).
|
||||
- 📱 Aplikacje mobilne dla Androida ([Google Play](https://play.google.com/store/apps/details?id=chat.simplex.app), [APK](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)) oraz [iOS](https://apps.apple.com/us/app/simplex-chat/id1605771084).
|
||||
- 🚀 [TestFlight dla iOS](https://testflight.apple.com/join/DWuT2LQu) z nowymi funkcjami na tydzień-dwa wcześniej - **limitowane do 10,000 użytkowników**!
|
||||
- 🖥 Dostępny jako terminalowa (konsolowa) [aplikacja / CLI](#zap-quick-installation-of-a-terminal-app) na Linuxa, MacOSa, Windowsa.
|
||||
|
||||
@@ -198,9 +198,9 @@ Twórca SimpleX Chat.
|
||||
|
||||
## Dlaczego prywatność ma znaczenie
|
||||
|
||||
Każdy powinien dbać o prywatność i bezpieczeństwo swojej komunikacji - nieszkodliwe rozmowy mogą narazić Cię na niebezpieczeństwo, nawet jeśli nie masz nic do ukrycia.
|
||||
Każdy powinien dbać o prywatność i bezpieczeństwo swojej komunikacji - nieszkodliwe rozmowy mogą narazić Cię na niebezpieczeństwo, nawet jeśli nie masz nic do ukrycia.
|
||||
|
||||
Jedną z najbardziej wstrząsających historii jest doświadczenie [Mohamedou Ould Salahi](https://en.wikipedia.org/wiki/Mohamedou_Ould_Slahi). opisane w jego pamiętniku i pokazane w filmie Mauretańczyk (2021). Został on umieszczony w obozie Guantanamo, bez procesu, i był tam torturowany przez 15 lat po telefonie do swojego krewnego w Afganistanie, pod zarzutem udziału w atakach 9/11, mimo że przez poprzednie 10 lat mieszkał w Niemczech.
|
||||
Jedną z najbardziej wstrząsających historii jest doświadczenie [Mohamedou Ould Salahi](https://en.wikipedia.org/wiki/Mohamedou_Ould_Slahi). opisane w jego pamiętniku i pokazane w filmie Mauretańczyk (2021). Został on umieszczony w obozie Guantanamo, bez procesu, i był tam torturowany przez 15 lat po telefonie do swojego krewnego w Afganistanie, pod zarzutem udziału w atakach 9/11, mimo że przez poprzednie 10 lat mieszkał w Niemczech.
|
||||
|
||||
Używanie szyfrowanego komunikatora end-to-end nie jest wystarczające. Powinniśmy używać komunikatorów, które zapewniają prywatność naszym powiązaniom, czyli tym z kim jesteśmy jakkolwiek połączeni.
|
||||
|
||||
@@ -432,4 +432,4 @@ Prosimy o traktowanie wszelkich ustaleń dotyczących możliwych ataków korelac
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/testflight.png" alt="iOS TestFlight" height="41">](https://testflight.apple.com/join/DWuT2LQu)
|
||||
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex.apk)
|
||||
[<img src="https://github.com/simplex-chat/.github/blob/master/profile/images/apk_icon.png" alt="APK" height="41">](https://github.com/simplex-chat/simplex-chat/releases/latest/download/simplex-aarch64.apk)
|
||||
|
||||
Reference in New Issue
Block a user