From 12911bbb40fe40a871a0f0b0b890533c72d08abc Mon Sep 17 00:00:00 2001 From: Travis Plunk Date: Wed, 13 May 2020 11:40:54 -0700 Subject: [PATCH] Update the combined package build to release the daily builds (#10449) # Conflicts: # .vsts-ci/install-ps.yml # .vsts-ci/templates/install-ps-phase.yml # tools/install-powershell.ps1 # tools/releaseBuild/azureDevOps/templates/windows-build.yml --- tools/packaging/packaging.psm1 | 6 +++ .../templates/SetVersionVariables.yml | 5 ++- .../azureDevOps/templates/linux.yml | 16 +++---- .../templates/mac-package-signing.yml | 28 ++++++++++--- .../azureDevOps/templates/nuget.yml | 6 ++- .../azureDevOps/templates/shouldSign.yml | 17 ++++++++ .../azureDevOps/templates/upload.yml | 6 +-- .../azureDevOps/templates/windows-build.yml | 42 +++++-------------- .../templates/windows-package-signing.yml | 9 +++- tools/releaseBuild/setReleaseTag.ps1 | 4 ++ 10 files changed, 87 insertions(+), 52 deletions(-) create mode 100644 tools/releaseBuild/azureDevOps/templates/shouldSign.yml diff --git a/tools/packaging/packaging.psm1 b/tools/packaging/packaging.psm1 index e412e525c7..24d9b8833f 100644 --- a/tools/packaging/packaging.psm1 +++ b/tools/packaging/packaging.psm1 @@ -3144,6 +3144,12 @@ function Get-PackageVersionAsMajorMinorBuildRevision if ($packageBuildTokens) { + if($packageBuildTokens.length -gt 4) + { + # MSIX will fail if it is more characters + $packageBuildTokens = $packageBuildTokens.Substring(0,4) + } + $packageVersion = $packageVersion + '.' + $packageBuildTokens } else diff --git a/tools/releaseBuild/azureDevOps/templates/SetVersionVariables.yml b/tools/releaseBuild/azureDevOps/templates/SetVersionVariables.yml index 32b7c9ea9c..b4f5ab826c 100644 --- a/tools/releaseBuild/azureDevOps/templates/SetVersionVariables.yml +++ b/tools/releaseBuild/azureDevOps/templates/SetVersionVariables.yml @@ -1,18 +1,19 @@ parameters: ReleaseTagVar: v6.2.0 ReleaseTagVarName: ReleaseTagVar + CreateJson: 'no' steps: - powershell: | $releaseTag = tools/releaseBuild/setReleaseTag.ps1 -ReleaseTag ${{ parameters.ReleaseTagVar }} -Variable "${{ parameters.ReleaseTagVarName }}" $version = $releaseTag.Substring(1) $vstsCommandString = "vso[task.setvariable variable=Version]$version" - Write-Host "sending " + $vstsCommandString + Write-Host ("sending " + $vstsCommandString) Write-Host "##$vstsCommandString" $azureVersion = $releaseTag.ToLowerInvariant() -replace '\.', '-' $vstsCommandString = "vso[task.setvariable variable=AzureVersion]$azureVersion" - Write-Host "sending " + $vstsCommandString + Write-Host ("sending " + $vstsCommandString) Write-Host "##$vstsCommandString" displayName: 'Set ${{ parameters.ReleaseTagVarName }} and other version Variables' diff --git a/tools/releaseBuild/azureDevOps/templates/linux.yml b/tools/releaseBuild/azureDevOps/templates/linux.yml index 0bb2c3a8e5..f46a1f3037 100644 --- a/tools/releaseBuild/azureDevOps/templates/linux.yml +++ b/tools/releaseBuild/azureDevOps/templates/linux.yml @@ -51,6 +51,8 @@ jobs: buildName: ${{ parameters.buildName }} steps: + - template: shouldSign.yml + - template: SetVersionVariables.yml parameters: ReleaseTagVar: $(ReleaseTagVar) @@ -86,12 +88,12 @@ jobs: Get-ChildItem -Path '$(System.ArtifactsDirectory)\rpm\*.rpm' -recurse | ForEach-Object { $authenticodefiles += $_.FullName} tools/releaseBuild/generatePackgeSigning.ps1 -LinuxFiles $authenticodeFiles -path "$(System.ArtifactsDirectory)\package.xml" displayName: 'Generate RPM Signing Xml' - condition: and(and(succeeded(), eq(variables['Build.Reason'], 'Manual')),eq(variables['buildName'], 'RPM')) + condition: and(and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')),eq(variables['buildName'], 'RPM')) - powershell: | Get-Content "$(System.ArtifactsDirectory)\package.xml" displayName: 'Capture RPM signing xml' - condition: and(and(succeeded(), eq(variables['Build.Reason'], 'Manual')),eq(variables['buildName'], 'RPM')) + condition: and(and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')),eq(variables['buildName'], 'RPM')) - task: PkgESCodeSign@10 displayName: 'CodeSign RPM $(System.ArtifactsDirectory)\package.xml' @@ -102,7 +104,7 @@ jobs: outPathRoot: '$(Build.StagingDirectory)\signedPackages' binVersion: $(SigingVersion) binVersionOverride: $(SigningVersionOverride) - condition: and(and(succeeded(), eq(variables['Build.Reason'], 'Manual')),eq(variables['buildName'], 'RPM')) + condition: and(and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')),eq(variables['buildName'], 'RPM')) - task: AzureFileCopy@1 displayName: 'Upload to Azure - DEB and tar.gz' @@ -125,7 +127,7 @@ jobs: Destination: AzureBlob storage: '$(StorageAccount)' ContainerName: '$(AzureVersion)' - condition: and(and(succeeded(), ne(variables['Build.Reason'], 'Manual')),eq(variables['buildName'], 'RPM')) + condition: and(and(succeeded(), ne(variables['SHOULD_SIGN'], 'true')),eq(variables['buildName'], 'RPM')) - task: AzureFileCopy@1 displayName: 'Upload to Azure - RPM - Signed' @@ -135,17 +137,17 @@ jobs: Destination: AzureBlob storage: '$(StorageAccount)' ContainerName: '$(AzureVersion)' - condition: and(and(succeeded(), eq(variables['Build.Reason'], 'Manual')),eq(variables['buildName'], 'RPM')) + condition: and(and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')),eq(variables['buildName'], 'RPM')) - template: upload-final-results.yml parameters: artifactPath: $(System.ArtifactsDirectory)\rpm\release - condition: and(and(succeeded(), ne(variables['Build.Reason'], 'Manual')),eq(variables['buildName'], 'RPM')) + condition: and(and(succeeded(), ne(variables['SHOULD_SIGN'], 'true')),eq(variables['buildName'], 'RPM')) - template: upload-final-results.yml parameters: artifactPath: '$(Build.StagingDirectory)\signedPackages' - condition: and(and(succeeded(), eq(variables['Build.Reason'], 'Manual')),eq(variables['buildName'], 'RPM')) + condition: and(and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')),eq(variables['buildName'], 'RPM')) - task: ms.vss-governance-buildtask.governance-build-task-component-detection.ComponentGovernanceComponentDetection@0 displayName: 'Component Detection' diff --git a/tools/releaseBuild/azureDevOps/templates/mac-package-signing.yml b/tools/releaseBuild/azureDevOps/templates/mac-package-signing.yml index c82dbd8d1e..79674ff94e 100644 --- a/tools/releaseBuild/azureDevOps/templates/mac-package-signing.yml +++ b/tools/releaseBuild/azureDevOps/templates/mac-package-signing.yml @@ -11,6 +11,8 @@ jobs: steps: + - template: shouldSign.yml + - template: SetVersionVariables.yml parameters: ReleaseTagVar: $(ReleaseTagVar) @@ -55,7 +57,7 @@ jobs: outPathRoot: '$(Build.StagingDirectory)\signedMacOSPackages' binVersion: $(SigingVersion) binVersionOverride: $(SigningVersionOverride) - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) - template: upload-final-results.yml parameters: @@ -70,24 +72,40 @@ jobs: $targzPath = dir "$(System.ArtifactsDirectory)\*.tar.gz" -Recurse | select-object -expandproperty fullname Copy-Item -Path $targzPath -Destination $destination displayName: 'Extract and copy macOS artifacts for upload' - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) - template: upload-final-results.yml parameters: artifactPath: $(System.ArtifactsDirectory)\azureMacOs artifactFilter: "*.pkg" - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) + - powershell: | + $null = new-item -type directory -path "$(Build.StagingDirectory)\macos-unsigned" + Copy-Item -Path "$(System.ArtifactsDirectory)\results\powershell-$(Version)-osx-x64.pkg" -Destination "$(Build.StagingDirectory)\macos-unsigned" + Copy-Item -Path "$(System.ArtifactsDirectory)\results\powershell-$(Version)-osx-x64.tar.gz" -Destination "$(Build.StagingDirectory)\macos-unsigned" + displayName: 'Create unsigned folder to upload' + condition: and(succeeded(), ne(variables['SHOULD_SIGN'], 'true')) - task: AzureFileCopy@1 - displayName: 'AzureBlob File Copy' + displayName: 'AzureBlob File Copy - unsigned' + inputs: + SourcePath: '$(Build.StagingDirectory)\macos-unsigned' + azureSubscription: '$(AzureFileCopySubscription)' + Destination: AzureBlob + storage: '$(StorageAccount)' + ContainerName: '$(AzureVersion)' + condition: and(succeeded(), ne(variables['SHOULD_SIGN'], 'true')) + + - task: AzureFileCopy@1 + displayName: 'AzureBlob File Copy - signed' inputs: SourcePath: '$(System.ArtifactsDirectory)\azureMacOs' azureSubscription: '$(AzureFileCopySubscription)' Destination: AzureBlob storage: '$(StorageAccount)' ContainerName: '$(AzureVersion)' - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) - task: securedevelopmentteam.vss-secure-development-tools.build-task-antimalware.AntiMalware@3 displayName: 'Run Defender Scan' diff --git a/tools/releaseBuild/azureDevOps/templates/nuget.yml b/tools/releaseBuild/azureDevOps/templates/nuget.yml index c324baa203..57c2ddb295 100644 --- a/tools/releaseBuild/azureDevOps/templates/nuget.yml +++ b/tools/releaseBuild/azureDevOps/templates/nuget.yml @@ -119,6 +119,8 @@ jobs: packageSources: 'https://nuget.org/api/v2' installRoot: '$(GenAPIToolPath)' + - template: shouldSign.yml + - template: SetVersionVariables.yml parameters: ReleaseTagVar: $(ReleaseTagVar) @@ -208,7 +210,7 @@ jobs: Destination: AzureBlob storage: '$(StorageAccount)' ContainerName: '$(AzureVersion)-nuget' - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) - task: AzureFileCopy@1 displayName: 'Upload global tool packages to Azure' @@ -219,7 +221,7 @@ jobs: storage: '$(GlobalToolStorageAccount)' ContainerName: 'tool' blobPrefix: '$(Version)' - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) - task: ms.vss-governance-buildtask.governance-build-task-component-detection.ComponentGovernanceComponentDetection@0 displayName: 'Component Detection' diff --git a/tools/releaseBuild/azureDevOps/templates/shouldSign.yml b/tools/releaseBuild/azureDevOps/templates/shouldSign.yml new file mode 100644 index 0000000000..affc523be6 --- /dev/null +++ b/tools/releaseBuild/azureDevOps/templates/shouldSign.yml @@ -0,0 +1,17 @@ +steps: +- powershell: | + $shouldSign = $true + if($env:BUILD_REASON -ne 'Manual') + { + $shouldSign = $false + } + + if($env:SKIP_SIGNING -eq 'Yes') + { + $shouldSign = $false + } + + $vstsCommandString = "vso[task.setvariable variable=SHOULD_SIGN]$($shouldSign.ToString().ToLowerInvariant())" + Write-Host "sending " + $vstsCommandString + Write-Host "##$vstsCommandString" + displayName: 'Set SHOULD_SIGN Variable' diff --git a/tools/releaseBuild/azureDevOps/templates/upload.yml b/tools/releaseBuild/azureDevOps/templates/upload.yml index 2d965c434a..1e4dc08633 100644 --- a/tools/releaseBuild/azureDevOps/templates/upload.yml +++ b/tools/releaseBuild/azureDevOps/templates/upload.yml @@ -19,7 +19,7 @@ steps: Destination: AzureBlob storage: '$(StorageAccount)' ContainerName: '$(AzureVersion)' - condition: and(succeeded(), eq('${{ parameters.msi }}', 'yes'), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq('${{ parameters.msi }}', 'yes')) - template: upload-final-results.yml parameters: @@ -34,7 +34,7 @@ steps: Destination: AzureBlob storage: '$(StorageAccount)' ContainerName: '$(AzureVersion)' - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: succeeded() - template: upload-final-results.yml parameters: @@ -50,4 +50,4 @@ steps: Destination: AzureBlob storage: '$(StorageAccount)' ContainerName: '$(AzureVersion)' - condition: and(succeeded(), eq('${{ parameters.msix }}', 'yes'), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq('${{ parameters.msix }}', 'yes')) diff --git a/tools/releaseBuild/azureDevOps/templates/windows-build.yml b/tools/releaseBuild/azureDevOps/templates/windows-build.yml index f340300411..f0c77272c8 100644 --- a/tools/releaseBuild/azureDevOps/templates/windows-build.yml +++ b/tools/releaseBuild/azureDevOps/templates/windows-build.yml @@ -8,7 +8,7 @@ jobs: displayName: Build Windows - ${{ parameters.Architecture }} condition: succeeded() pool: - name: Package ES Standard Build + name: PowerShell variables: BuildConfiguration: ${{ parameters.BuildConfiguration }} BuildPlatform: ${{ parameters.BuildPlatform }} @@ -20,6 +20,11 @@ jobs: clean: true persistCredentials: true + - template: shouldSign.yml + - template: SetVersionVariables.yml + parameters: + ReleaseTagVar: $(ReleaseTagVar) + - task: PkgESSetupBuild@10 displayName: 'Initialize build' env: @@ -31,27 +36,7 @@ jobs: disableWorkspace: true disableBuildTools: true disableNugetPack: true - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) - - - template: SetVersionVariables.yml - parameters: - ReleaseTagVar: $(ReleaseTagVar) - - - powershell: | - Write-Verbose -Verbose "$(Architecture)" - - if ('$(Architecture)' -eq 'fxdependent' -and '$(ReleaseTagVar)' -match '6.0.*') - { - $vstsCommandString = "vso[task.setvariable variable=SkipFxDependent]true" - } - else - { - $vstsCommandString = "vso[task.setvariable variable=SkipFxDependent]false" - } - - Write-Verbose -Message "$vstsCommandString " -Verbose - Write-Host -Object "##$vstsCommandString" - displayName: 'Skip FxDependent for PS v6.0.*' + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) - template: insert-nuget-config-azfeed.yml @@ -61,7 +46,6 @@ jobs: displayName: 'Remove all containers [Port to PSRelease]' # Cleanup is not critical it passes every time it runs continueOnError: true - condition: and(succeeded(), ne(variables['SkipFxDependent'], 'true')) - powershell: | docker image ls --format '{{ json .}}'|ConvertFrom-Json| ForEach-Object { @@ -80,7 +64,6 @@ jobs: displayName: 'Remove old images [Port to PSRelease]' # Cleanup is not critical it passes every time it runs continueOnError: true - condition: and(succeeded(), ne(variables['SkipFxDependent'], 'true')) - powershell: | Write-verbose "--docker info---" -verbose @@ -93,15 +76,13 @@ jobs: displayName: 'Capture docker info' # Diagnostics is not critical it passes every time it runs continueOnError: true - condition: and(succeeded(), ne(variables['SkipFxDependent'], 'true')) - powershell: | tools/releaseBuild/vstsbuild.ps1 -ReleaseTag $(ReleaseTagVar) -Name win-$(Architecture)-symbols displayName: 'Build Windows Universal - $(Architecture) Symbols zip' - condition: and(succeeded(), ne(variables['SkipFxDependent'], 'true')) - powershell: | - if ("$env:Architecture" -eq 'fxdependent') + if ("$env:Architecture" -like 'fxdependent*') { $(Build.SourcesDirectory)\tools\releaseBuild\updateSigning.ps1 -SkipPwshExe } @@ -110,14 +91,12 @@ jobs: $(Build.SourcesDirectory)\tools\releaseBuild\updateSigning.ps1 } displayName: 'Update Signing Xml' - condition: and(succeeded(), ne(variables['SkipFxDependent'], 'true')) - powershell: | $vstsCommandString = "vso[task.setvariable variable=Symbols]${env:Symbols_$(Architecture)}" Write-Host "sending " + $vstsCommandString Write-Host "##$vstsCommandString" displayName: 'Get Symbols path [Update build.json]' - condition: and(succeeded(), ne(variables['SkipFxDependent'], 'true')) - task: PkgESCodeSign@10 displayName: 'CodeSign $(Architecture)' @@ -129,17 +108,16 @@ jobs: outPathRoot: '$(Symbols)\signed' binVersion: $(SigingVersion) binVersionOverride: $(SigningVersionOverride) - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual'), ne(variables['SkipFxDependent'], 'true')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) - powershell: | New-Item -ItemType Directory -Path $(Symbols)\signed -Force displayName: 'Create empty signed folder' - condition: and(succeeded(), ne(variables['Build.Reason'], 'Manual'), ne(variables['SkipFxDependent'], 'true')) + condition: and(succeeded(), ne(variables['SHOULD_SIGN'], 'true')) - powershell: | tools/releaseBuild/vstsbuild.ps1 -ReleaseTag $(ReleaseTagVar) -Name win-$(Architecture)-package -BuildPath $(Symbols) -SignedFilesPath $(Symbols)\signed displayName: 'Build Windows Universal - $(Architecture) Package' - condition: and(succeeded(), ne(variables['SkipFxDependent'], 'true')) - task: ms.vss-governance-buildtask.governance-build-task-component-detection.ComponentGovernanceComponentDetection@0 displayName: 'Component Detection' diff --git a/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml b/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml index da05a52d04..a92f7de47a 100644 --- a/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml +++ b/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml @@ -15,6 +15,7 @@ jobs: steps: + - template: shouldSign.yml - template: SetVersionVariables.yml parameters: ReleaseTagVar: $(ReleaseTagVar) @@ -57,7 +58,13 @@ jobs: outPathRoot: '$(Build.StagingDirectory)\signedPackages' binVersion: $(SigingVersion) binVersionOverride: $(SigningVersionOverride) - condition: and(succeeded(), eq(variables['Build.Reason'], 'Manual')) + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) + + - powershell: | + new-item -itemtype Directory -path '$(Build.StagingDirectory)\signedPackages' + Get-ChildItem "$(System.ArtifactsDirectory)\signed\PowerShell-$(Version)-win-*.msi*" | copy-item -Destination '$(Build.StagingDirectory)\signedPackages' + displayName: 'Fake Signing' + condition: and(succeeded(), ne(variables['SHOULD_SIGN'], 'true')) - template: upload.yml parameters: diff --git a/tools/releaseBuild/setReleaseTag.ps1 b/tools/releaseBuild/setReleaseTag.ps1 index 64b6331bf6..41468692d4 100644 --- a/tools/releaseBuild/setReleaseTag.ps1 +++ b/tools/releaseBuild/setReleaseTag.ps1 @@ -47,4 +47,8 @@ if($ReleaseTag -eq 'fromBranch' -or !$ReleaseTag) } } +$vstsCommandString = "vso[task.setvariable variable=IS_DAILY]false" +Write-Verbose -Message "$vstsCommandString" -Verbose +Write-Host -Object "##$vstsCommandString" + Write-Output $releaseTag