No description
  • Go 87.3%
  • Go Template 11.1%
  • Shell 1.6%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-23 08:25:19 +02:00
spitfire Updated --pgo handeling 2026-09-23 08:25:19 +02:00
.gitignore Added linux package support, alpine build sys, musl version support 2026-06-10 00:21:18 +02:00
go.mod Added k: kind for APPINDEX support 2026-08-21 15:10:36 +02:00
go.sum Updated Repo lib 2026-09-03 10:51:02 +02:00
main.go Updated --pgo handeling 2026-09-23 08:25:19 +02:00
README.md Add --pgo 2026-09-21 23:54:23 +02:00
setup.sh Added linux repo uploads 2026-06-16 00:25:31 +02:00

Logo

Spitfire Builder

This is a "simple" script for building the Spitfire Browser based on Mozilla Firefox source code.

Quick-start

curl -fsSL https://weforge.xyz/Spitfire/Builder/raw/branch/main/setup.sh | bash

Only Debian/Fedora/Tumbleweed/Alpine Linux is currently supported by quick-start script.

Project Overview

Spitfire Builder is an automation toolchain for producing customized builds of the Spitfire Browser (a fork of Mozilla Firefox).
It handles the entire build process, including:

  • Source management - clone, update, and clean the upstream Mozilla repository.
  • Patching - apply Spitfire branding, configuration, and optional custom .mozconfig flags through a patching system.
  • Compilation - configure and build for different platforms and architectures.
  • Packaging - compress build artifacts into distributable archives.
  • Deployment - upload releases to S3 and update the project's APPINDEX metadata.

By consolidating these steps into a single script, Spitfire Builder reduces manual work, ensures consistent builds, and makes it easy to produce.

System requirements

Debian or Fedora based distro.

Windows running with MozillaBuild shell

MacOS is not currently supported. But generally speaking you should follow this guide. After meeting all dependencies clone this repository and run this script.

Dependencies

  • Git
  • Curl
  • Mercurial
  • Golang 1.22 or later
  • Python & pip 3.9 or later

Flags

Below is a description of all supported flags:

General

  • -h, --help
    Show help and exit.

Build process

  • -a, --all
    Run full flow: clone/update, discard changes, clean, apply pre-patche, configure, build, resolve build dir, apply post-patches. (No upload unless you also pass --upload.)
  • -b, --build
    Build only (plus optional pre/post patch steps if you pass --pre-patch / --post-patch).
  • -u, --update
    Clone (if missing) and update the Mozilla repo.
  • --clean
    Revert uncommitted changes without removing build artifacts.
  • --full-clean
    Full clobber of build artifacts.
  • --pre-patch
    Apply pre-compile patches to source.
  • --post-patch
    Apply post-compile patches to built output.
  • --skip-patch-update
    Don't fetch/reset the patches repo (use what's already cloned).
  • --patches-ref=<ref>
    Patcher branch, tag or commit to build with (default: main). Pin it together with --branch for reproducible release builds.
  • --source-ref=<ref>
    Upstream commit or tag to build instead of the tip of --branch.
  • --pgo
    Profile-guided optimisation: instrumented build, profile run through Mozilla's page set, then the optimised rebuild. About twice the build time. Needs the Patcher's pgo-1/pgo-2 patches.
  • --extra-mozconfig="<lines>"
    Extra .mozconfig lines to inject via a local patch after all standard pre-patches and before configure/build.
    Accepts semicolon (;) or newline separators. Lines are written into a patch targeting .mozconfig.
  • -r, --run
    Run the built project after a successful build.
  • --skip-deps
    Skip system dependency checks.
  • --ignore-errors
    Keep going even if a step fails (errors are collected and printed at the end).

Compression & upload

  • -c, --compress
    Compress the target directory into a .tar.xz (used for release artifacts).
  • --upload
    Upload the compressed file to S3, requires correct env variabes.
  • --output-dir=<path>
    Directory to save the compressed package (default: current dir).

Customization & targeting

  • -t=<component-arch-release-platform>, --target=<...>
    Target tuple for naming/artifacts.
  • -v=<version>, --version=<version>
    Package version. For nightly, defaults to current date (YYYY.MM.DD).
  • --component=<name>
    Component name (default: browser).
  • --arch=<arch>
    Architecture (default: host arch, e.g. amd64).
  • --release=<type>
    Release channel (default: nightly).
  • --platform=<platform>
    Platform (default: host OS, e.g. linux, windows). Use linux-musl for a musl/Alpine build.
  • --microarch=<level>
    x86-64 microarch level: v2, v3, v4 (empty = baseline). Injects -march=x86-64-v<N>.
  • --container=<name>
    Distrobox container name to run mach commands in (by default used only when needed -> Alpine container for a musl build).
  • --formats=<list>
    Packages to create from build tar.xz, currently supported: deb,rpm,archlinux,apk,appimage,xbps.
  • --repo-url=<url>
    Public base URL of the bucket (e.g. https://dl.example.com), enables apt/dnf/pacman repo install snippets. Env: REPO_BASE_URL.
  • --no-repo-containers
    Don't auto-create a distrobox for repo tools missing on host. It will continue even with missing tools (env: SPITFIRE_REPO_CONTAINERS=0).
  • --channel=<name>
    Release channel name (default: nightly).
  • --branch=<branch>
    Branch of the source repository to track (default: tor-browser-150.0a1-16.0-2).
  • --app-id=<id>
    Reverse-domain app ID (default: xyz.weforge.Spitfire).
  • --app-name=<name>
    Display name for the app (default: Spitfire Browser).
  • --description=<text>
    APPINDEX description (default: Nightly build of <app-name>).
  • --tags=<list>
    APPINDEX tags, comma-separated (default: browser).
  • --kind=<kind>
    APPINDEX package kind written to k: (default: browser).
  • --work-dir=<path>
    Working directory (default: ./mozilla-release).

Example usage:

  • All build steps:
go run . -a
  • All build setps without fetching new patches:
go run . -a --skip-patch-update
  • Upload:
go run . --upload -c
  • Build and upload:
go run . --upload -c -a
  • Custom Mozbuild Flags (Example fix OOM by switching to ThinLTO and fewer jobs):
go run . -a \
 --extra-mozconfig='ac_add_options MOZ_LTO=thin; mk_add_options MOZ_MAKE_FLAGS=-j6; export RUSTFLAGS="-C codegen-units=8"'
  • Display all flags:
go run . -h

Bucket layout

Everything lives under a single root prefix linux:

linux/deb/                          apt repository (multi-arch)
  pool/main/s/<pkg>/*.deb           -> pkg is spitfire (release) or spitfire-<channel>
  dists/release/{Release,InRelease,Release.gpg}
  dists/release/main/binary-<arch>/{Packages,Packages.gz}
linux/deb-amd64v3/*
linux/deb-amd64v4/*

linux/rpm/<basearch>/               dnf repository
  <pkg>.<rpmarch>.rpm
  repodata/*
  manifest.json
  <pkg>.repo

linux/apk/<arch>/                   apk repository (baseline only)

linux/arch/<archlevel>/             pacman repository
 -> archlevel is x86_64, x86_64_v3, x86_64_v4 or aarch64

linux/appimage/                     plain AppImage downloads (baseline only)

linux/xbps/                         Void repository (baseline only, both libcs in one dir)
  <pkg>-<ver>_1.<arch>.xbps{,.sig2}
  <arch>-repodata                   -> arch is x86_64 or x86_64-musl
  <pkg>.conf                        drop into /etc/xbps.d/

linux/pubkey.asc                    OpenPGP public key (apt + dnf trust anchor)
linux/spitfire.asc                  same key, at the path install.sh expects (key files are not channel-suffixed)
linux/spitfire-archive-keyring.gpg  dearmored key for apt Signed-By

Env for the build

Env var Default Effect
SPITFIRE_RUST_TOOLCHAIN pinned by the tree rustc version to build with (rustup). Its LLVM must not be newer than the tree's clang, empty disables the pin.
SPITFIRE_SOURCE_REF tip of --branch Upstream commit or tag to build, same as --source-ref.

Env for uploads to linux repos

Env var Default Effect
LINUX_REPO_PREFIX linux Bucket key prefix the whole repo tree lives under.
GPG_PRIVATE_KEY - OpenPGP signing key (required; repo metadata must be signed).
ABUILD_PRIVKEY - apk (Alpine) signing key.
XBPS_PRIVATE_KEY - xbps (Void) RSA signing key, PEM text or path (required, remote xbps repos must be signed).
XBPS_SIGNEDBY app name Signer string embedded in the xbps repodata.