Restructure the package build to simplify signing and packaging stages (#19321)

This commit is contained in:
Aditya Patwardhan
2023-04-07 12:00:20 -07:00
committed by Dongbo Wang
parent 9386b76796
commit 2642167489
11 changed files with 529 additions and 101 deletions
+199 -90
View File
@@ -49,6 +49,7 @@ variables:
value: spdx:2.2
- name: BUILDSECMON_OPT_IN
value: true
- group: PoolNames
stages:
- stage: prep
@@ -66,30 +67,6 @@ stages:
parameters:
buildArchitecture: arm64
- template: templates/mac-file-signing.yml
parameters:
buildArchitecture: x64
- template: templates/mac-file-signing.yml
parameters:
buildArchitecture: arm64
- template: templates/mac-package-build.yml
parameters:
buildArchitecture: x64
- template: templates/mac-package-build.yml
parameters:
buildArchitecture: arm64
- template: templates/mac-package-signing.yml
parameters:
buildArchitecture: x64
- template: templates/mac-package-signing.yml
parameters:
buildArchitecture: arm64
- stage: linux
dependsOn: ['prep']
jobs:
@@ -111,29 +88,6 @@ stages:
parameters:
buildName: alpine
- template: templates/linux-authenticode-sign.yml
- template: templates/linux-packaging.yml
parameters:
buildName: deb
parentJob: sign_linux_builds
- template: templates/linux-packaging.yml
parameters:
buildName: rpm
uploadDisplayName: Upload and Sign
parentJob: sign_linux_builds
- template: templates/linux-packaging.yml
parameters:
buildName: alpine
parentJob: sign_linux_builds
- template: templates/linux-packaging.yml
parameters:
buildName: fxdependent
parentJob: sign_linux_builds
- stage: windows
dependsOn: ['prep']
jobs:
@@ -166,66 +120,221 @@ stages:
parameters:
Architecture: fxdependentWinDesktop
- template: templates/windows-packaging.yml
parameters:
Architecture: x64
parentJob: build_windows_x64_release
- stage: SignFiles
displayName: Sign files
dependsOn: ['windows', 'linux', 'macos']
jobs:
- template: templates/mac-file-signing.yml
parameters:
buildArchitecture: x64
- template: templates/windows-packaging.yml
parameters:
Architecture: x64
BuildConfiguration: minSize
parentJob: build_windows_x64_minSize
- template: templates/mac-file-signing.yml
parameters:
buildArchitecture: arm64
- template: templates/windows-packaging.yml
parameters:
Architecture: x86
parentJob: build_windows_x86_release
- job: SignFilesWinLinux
pool:
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
displayName: Sign files
- template: templates/windows-packaging.yml
parameters:
Architecture: arm
parentJob: build_windows_arm_release
variables:
- group: ESRP
- name: runCodesignValidationInjection
value: false
- name: NugetSecurityAnalysisWarningLevel
value: none
- name: repoFolder
value: PowerShell
- name: repoRoot
value: $(Agent.BuildDirectory)\$(repoFolder)
- name: complianceRepoFolder
value: compliance
- template: templates/windows-packaging.yml
parameters:
Architecture: arm64
parentJob: build_windows_arm64_release
strategy:
matrix:
linux-x64:
runtime: linux-x64
unsignedBuildArtifactContainer: pwshLinuxBuild.tar.gz
unsignedBuildArtifactName: pwshLinuxBuild.tar.gz
signedBuildArtifactName: pwshLinuxBuild.tar.gz
signedArtifactContainer: authenticode-signed
linux-x64-Alpine:
runtime: linux-x64-Alpine
unsignedBuildArtifactContainer: pwshLinuxBuildAlpine.tar.gz
unsignedBuildArtifactName: pwshLinuxBuild.tar.gz
signedBuildArtifactName: pwshLinuxBuildAlpine.tar.gz
signedArtifactContainer: authenticode-signed
linux-arm32:
runtime: linux-arm32
unsignedBuildArtifactContainer: pwshLinuxBuildArm32.tar.gz
unsignedBuildArtifactName: pwshLinuxBuildArm32.tar.gz
signedBuildArtifactName: pwshLinuxBuildArm32.tar.gz
signedArtifactContainer: authenticode-signed
linux-arm64:
runtime: linux-arm64
unsignedBuildArtifactContainer: pwshLinuxBuildArm64.tar.gz
unsignedBuildArtifactName: pwshLinuxBuildArm64.tar.gz
signedBuildArtifactName: pwshLinuxBuildArm64.tar.gz
signedArtifactContainer: authenticode-signed
linux-fxd:
runtime: linux-fxd
unsignedBuildArtifactContainer: pwshLinuxBuildFxdependent.tar.gz
unsignedBuildArtifactName: pwshLinuxBuild.tar.gz
signedBuildArtifactName: pwshLinuxBuildFxdependent.tar.gz
signedArtifactContainer: authenticode-signed
linux-mariner:
runtime: linux-mariner
unsignedBuildArtifactContainer: pwshMarinerBuildAmd64.tar.gz
unsignedBuildArtifactName: pwshMarinerBuildAmd64.tar.gz
signedBuildArtifactName: pwshMarinerBuildAmd64.tar.gz
signedArtifactContainer: authenticode-signed
linux-minsize:
runtime: linux-minsize
unsignedBuildArtifactContainer: pwshLinuxBuildMinSize.tar.gz
unsignedBuildArtifactName: pwshLinuxBuildMinSize.tar.gz
signedBuildArtifactName: pwshLinuxBuildMinSize.tar.gz
signedArtifactContainer: authenticode-signed
win-x64:
runtime: win-x64
unsignedBuildArtifactContainer: results
unsignedBuildArtifactName: '**/*-symbols-win-x64.zip'
signedBuildArtifactName: '-symbols-win-x64-signed.zip'
signedArtifactContainer: results
win-x86:
runtime: win-x86
unsignedBuildArtifactContainer: results
unsignedBuildArtifactName: '**/*-symbols-win-x86.zip'
signedBuildArtifactName: '-symbols-win-x86-signed.zip'
signedArtifactContainer: results
win-arm32:
runtime: win-arm32
unsignedBuildArtifactContainer: results
unsignedBuildArtifactName: '**/*-symbols-win-arm32.zip'
signedBuildArtifactName: '-symbols-win-arm32-signed.zip'
signedArtifactContainer: results
win-arm64:
runtime: win-arm64
unsignedBuildArtifactContainer: results
unsignedBuildArtifactName: '**/*-symbols-win-arm64.zip'
signedBuildArtifactName: '-symbols-win-arm64-signed.zip'
signedArtifactContainer: results
win-x64-gc:
runtime: win-x64-gc
unsignedBuildArtifactContainer: results
unsignedBuildArtifactName: '**/*-symbols-win-x64-gc.zip'
signedBuildArtifactName: '-symbols-win-x64-gc-signed.zip'
signedArtifactContainer: results
win-fxdependent:
runtime: win-fxdependent
unsignedBuildArtifactContainer: results
unsignedBuildArtifactName: '**/*-symbols-win-fxdependent.zip'
signedBuildArtifactName: '-symbols-win-fxdependent-signed.zip'
signedArtifactContainer: results
win-fxdependentWinDesktop:
runtime: win-fxdependentWinDesktop
unsignedBuildArtifactContainer: results
unsignedBuildArtifactName: '**/*-symbols-win-fxdependentWinDesktop.zip'
signedBuildArtifactName: '-symbols-win-fxdependentWinDesktop-signed.zip'
signedArtifactContainer: results
steps:
- template: templates/sign-build-file.yml
- template: templates/windows-packaging.yml
parameters:
Architecture: fxdependent
parentJob: build_windows_fxdependent_release
- stage: mac_packaging
displayName: macOS packaging
dependsOn: ['SignFiles']
jobs:
- template: templates/mac-package-build.yml
parameters:
buildArchitecture: x64
- template: templates/windows-packaging.yml
parameters:
Architecture: fxdependentWinDesktop
parentJob: build_windows_fxdependentWinDesktop_release
- template: templates/mac-package-build.yml
parameters:
buildArchitecture: arm64
- template: templates/windows-package-signing.yml
parameters:
parentJobs:
- sign_windows_x64_release
- sign_windows_x64_minSize
- sign_windows_x86_release
- sign_windows_arm_release
- sign_windows_arm64_release
- sign_windows_fxdependent_release
- sign_windows_fxdependentWinDesktop_release
- stage: linux_packaging
displayName: Linux Packaging
dependsOn: ['SignFiles']
jobs:
- template: templates/linux-packaging.yml
parameters:
buildName: deb
- template: templates/linux-packaging.yml
parameters:
buildName: rpm
uploadDisplayName: Upload and Sign
- template: templates/linux-packaging.yml
parameters:
buildName: alpine
- template: templates/linux-packaging.yml
parameters:
buildName: fxdependent
- stage: win_packaging
displayName: Windows Packaging
dependsOn: ['SignFiles']
jobs:
- template: templates/windows-packaging.yml
parameters:
Architecture: x64
parentJob: build_windows_x64_release
- template: templates/windows-packaging.yml
parameters:
Architecture: x64
BuildConfiguration: minSize
parentJob: build_windows_x64_minSize
- template: templates/windows-packaging.yml
parameters:
Architecture: x86
parentJob: build_windows_x86_release
- template: templates/windows-packaging.yml
parameters:
Architecture: arm
parentJob: build_windows_arm_release
- template: templates/windows-packaging.yml
parameters:
Architecture: arm64
parentJob: build_windows_arm64_release
- template: templates/windows-packaging.yml
parameters:
Architecture: fxdependent
parentJob: build_windows_fxdependent_release
- template: templates/windows-packaging.yml
parameters:
Architecture: fxdependentWinDesktop
parentJob: build_windows_fxdependentWinDesktop_release
- stage: package_signing
displayName: Package Signing
dependsOn: ['mac_packaging', 'linux_packaging', 'win_packaging']
jobs:
- template: templates/windows-package-signing.yml
# This is done late so that we dont use resources before the big signing and packaging tasks.
- stage: compliance
dependsOn: ['windows']
dependsOn: ['package_signing']
jobs:
- template: templates/compliance.yml
- stage: nuget_and_json
dependsOn: ['windows','linux','macOS']
displayName: NuGet Packaging and Build Json
dependsOn: [package_signing]
jobs:
- template: templates/nuget.yml
- template: templates/json.yml
- stage: test_and_release_artifacts
displayName: Test and Release Artifacts
dependsOn: ['prep']
jobs:
- template: templates/testartifacts.yml
@@ -233,7 +342,7 @@ stages:
- job: release_json
displayName: Create and Upload release.json
pool:
name: PowerShell1ES
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
steps:
@@ -17,7 +17,7 @@ jobs:
dependsOn:
${{ parameters.parentJobs }}
pool:
name: PowerShell1ES
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
@@ -13,7 +13,7 @@ jobs:
${{ parameters.parentJobs }}
condition: succeeded()
pool:
name: PowerShell1ES
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
@@ -1,7 +1,6 @@
parameters:
buildName: ''
uploadDisplayName: 'Upload'
parentJob: ''
jobs:
- job: pkg_${{ parameters.buildName }}
@@ -11,7 +10,6 @@ jobs:
name: PowerShell1ES
demands:
- ImageOverride -equals PSMMSUbuntu20.04-Secure
dependsOn: sign_linux_builds
variables:
- name: runCodesignValidationInjection
value: false
@@ -4,7 +4,6 @@ parameters:
jobs:
- job: MacFileSigningJob_${{ parameters.buildArchitecture }}
displayName: macOS File signing ${{ parameters.buildArchitecture }}
dependsOn: build_macOS_${{ parameters.buildArchitecture }}
condition: succeeded()
pool:
name: PowerShell1ES
@@ -5,7 +5,6 @@ parameters:
jobs:
- job: package_macOS_${{ parameters.buildArchitecture }}
displayName: Package macOS ${{ parameters.buildArchitecture }}
dependsOn: MacFileSigningJob_${{ parameters.buildArchitecture }}
condition: succeeded()
pool:
vmImage: macos-latest
@@ -8,7 +8,7 @@ jobs:
displayName: Build NuGet packages
condition: succeeded()
pool:
name: PowerShell1ES
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
@@ -0,0 +1,324 @@
steps:
- pwsh: |
$platform = '$(runtime)' -match '^linux' ? 'linux' : 'windows'
$vstsCommandString = "vso[task.setvariable variable=ArtifactPlatform]$platform"
Write-Host ("sending " + $vstsCommandString)
Write-Host "##$vstsCommandString"
displayName: Set artifact platform
- task: DownloadPipelineArtifact@2
inputs:
artifactName: '$(unsignedBuildArtifactContainer)'
itemPattern: '$(unsignedBuildArtifactName)'
- pwsh: |
Get-ChildItem "$(Pipeline.Workspace)\*" -Recurse
displayName: 'Capture Downloaded Artifacts'
# Diagnostics is not critical it passes every time it runs
continueOnError: true
- checkout: self
clean: true
path: $(repoFolder)
- template: SetVersionVariables.yml
parameters:
ReleaseTagVar: $(ReleaseTagVar)
- template: cloneToOfficialPath.yml
- pwsh: |
$zipFileFilter = '$(unsignedBuildArtifactName)'
$zipFileFilter = $zipFileFilter.Replace('**/', '')
Write-Verbose -Verbose -Message "zipFileFilter = $zipFileFilter"
Write-Verbose -Verbose -Message "Looking for $(Pipeline.Workspace)\$(unsignedBuildArtifactName)"
$zipFilePath = Get-ChildItem -Path '$(Pipeline.Workspace)\$(unsignedBuildArtifactName)' -recurse
if (-not (Test-Path $zipFilePath))
{
throw "zip file not found: $zipfilePath"
}
if ($zipFilePath.Count -ne 1) {
Write-Verbose "zip filename" -verbose
$zipFilePath | Out-String | Write-Verbose -Verbose
throw 'multiple zip files found when 1 was expected'
}
$expandedFolderName = [System.io.path]::GetFileNameWithoutExtension($zipfilePath)
$expandedFolderPath = Join-Path '$(Pipeline.Workspace)' 'expanded' $expandedFolderName
Write-Verbose -Verbose -Message "Expaning $zipFilePath to $expandedFolderPath"
New-Item -Path $expandedFolderPath -ItemType Directory
Expand-Archive -Path $zipFilePath -DestinationPath $expandedFolderPath
if (-not (Test-Path $expandedFolderPath\pwsh.exe) ) {
throw 'zip did not expand as expected'
}
else {
$vstsCommandString = "vso[task.setvariable variable=BinPath]$expandedFolderPath"
Write-Host ("sending " + $vstsCommandString)
Write-Host "##$vstsCommandString"
}
displayName: Expand zip packages
condition: eq(variables['ArtifactPlatform'], 'windows')
- pwsh: |
$tarPackageName = '$(unsignedBuildArtifactName)'
Write-Verbose -Verbose -Message "tarPackageName = $tarPackageName"
$tarPackagePath = Join-Path '$(Pipeline.Workspace)' $tarPackageName
Write-Verbose -Verbose -Message "Looking for: $tarPackagePath"
$expandedPathFolderName = $tarPackageName -replace '.tar.gz', ''
$expandedFolderPath = Join-Path '$(Pipeline.Workspace)' 'expanded' $expandedPathFolderName
if (-not (Test-Path $tarPackagePath))
{
throw "tar file not found: $tarPackagePath"
}
Write-Verbose -Verbose -Message "Expanding $tarPackagePath to $expandedFolderPath"
New-Item -Path $expandedFolderPath -ItemType Directory
tar -xf $tarPackagePath -C $expandedFolderPath
if (-not (Test-Path $expandedFolderPath/pwsh) ) {
throw 'tar.gz did not expand as expected'
}
else {
$vstsCommandString = "vso[task.setvariable variable=BinPath]$expandedFolderPath"
Write-Host ("sending " + $vstsCommandString)
Write-Host "##$vstsCommandString"
}
Write-Verbose -Verbose "File permisions after expanding"
Get-ChildItem -Path "$expandedFolderPath/pwsh" | Select-Object -Property 'unixmode', 'size', 'name'
displayName: Expand tar.gz packages
condition: eq(variables['ArtifactPlatform'], 'linux')
- template: insert-nuget-config-azfeed.yml
parameters:
repoRoot: $(PowerShellRoot)
- pwsh: |
Set-Location $env:POWERSHELLROOT
import-module "$env:POWERSHELLROOT/build.psm1"
Sync-PSTags -AddRemoteIfMissing
displayName: SyncTags
condition: and(succeeded(), ne(variables['SkipBuild'], 'true'))
- checkout: ComplianceRepo
clean: true
path: $(complianceRepoFolder)
- template: shouldSign.yml
- pwsh: |
$fullSymbolsFolder = '$(BinPath)'
Write-Verbose -Verbose "fullSymbolsFolder == $fullSymbolsFolder"
Get-ChildItem -Recurse $fullSymbolsFolder | out-string | Write-Verbose -Verbose
$filesToSignDirectory = "$(System.ArtifactsDirectory)\toBeSigned"
if ((Test-Path -Path $filesToSignDirectory)) {
Remove-Item -Path $filesToSignDirectory -Recurse -Force
}
$null = New-Item -ItemType Directory -Path $filesToSignDirectory -Force
$signedFilesDirectory = "$(System.ArtifactsDirectory)\signed"
if ((Test-Path -Path $signedFilesDirectory)) {
Remove-Item -Path $signedFilesDirectory -Recurse -Force
}
$null = New-Item -ItemType Directory -Path $signedFilesDirectory -Force
$itemsToCopyWithRecurse = @(
"$($fullSymbolsFolder)\*.ps1"
"$($fullSymbolsFolder)\Microsoft.PowerShell*.dll"
)
$itemsToCopy = @{
"$($fullSymbolsFolder)\*.ps1" = ""
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Host\Microsoft.PowerShell.Host.psd1" = "Modules\Microsoft.PowerShell.Host"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Management\Microsoft.PowerShell.Management.psd1" = "Modules\Microsoft.PowerShell.Management"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.psd1" = "Modules\Microsoft.PowerShell.Security"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Utility.psd1" = "Modules\Microsoft.PowerShell.Utility"
"$($fullSymbolsFolder)\pwsh.dll" = ""
"$($fullSymbolsFolder)\System.Management.Automation.dll" = ""
}
## Windows only modules
if('$(ArtifactPlatform)' -eq 'windows') {
$itemsToCopy += @{
"$($fullSymbolsFolder)\pwsh.exe" = ""
"$($fullSymbolsFolder)\Microsoft.Management.Infrastructure.CimCmdlets.dll" = ""
"$($fullSymbolsFolder)\Microsoft.WSMan.*.dll" = ""
"$($fullSymbolsFolder)\Modules\CimCmdlets\CimCmdlets.psd1" = "Modules\CimCmdlets"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Diagnostics.format.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Event.format.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\GetEvent.types.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Security\Security.types.ps1xml" = "Modules\Microsoft.PowerShell.Security"
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Microsoft.PowerShell.Diagnostics.psd1" = "Modules\Microsoft.PowerShell.Diagnostics"
"$($fullSymbolsFolder)\Modules\Microsoft.WSMan.Management\Microsoft.WSMan.Management.psd1" = "Modules\Microsoft.WSMan.Management"
"$($fullSymbolsFolder)\Modules\Microsoft.WSMan.Management\WSMan.format.ps1xml" = "Modules\Microsoft.WSMan.Management"
"$($fullSymbolsFolder)\Modules\PSDiagnostics\PSDiagnostics.ps?1" = "Modules\PSDiagnostics"
}
}
else {
$itemsToCopy += @{
"$($fullSymbolsFolder)\pwsh" = ""
}
}
$itemsToExclude = @(
# This package is retrieved from https://www.github.com/powershell/MarkdownRender
"$($fullSymbolsFolder)\Microsoft.PowerShell.MarkdownRender.dll"
)
Write-Verbose -verbose "recusively copying $($itemsToCopyWithRecurse | out-string) to $filesToSignDirectory"
Copy-Item -Path $itemsToCopyWithRecurse -Destination $filesToSignDirectory -Recurse -verbose -exclude $itemsToExclude
foreach($pattern in $itemsToCopy.Keys) {
$destinationFolder = Join-Path $filesToSignDirectory -ChildPath $itemsToCopy.$pattern
$null = New-Item -ItemType Directory -Path $destinationFolder -Force
Write-Verbose -verbose "copying $pattern to $destinationFolder"
Copy-Item -Path $pattern -Destination $destinationFolder -Recurse -verbose
}
displayName: 'Prepare files to be signed'
- template: EsrpSign.yml@ComplianceRepo
parameters:
buildOutputPath: $(System.ArtifactsDirectory)\toBeSigned
signOutputPath: $(System.ArtifactsDirectory)\signed
certificateId: "$(AUTHENTICODE_CERT)"
pattern: |
**\*.dll
**\*.psd1
**\*.psm1
**\*.ps1xml
**\*.ps1
**\*.exe
useMinimatch: true
shouldSign: $(SHOULD_SIGN)
displayName: Authenticode sign our binaries
- pwsh: |
Import-Module $(PowerShellRoot)/build.psm1 -Force
Import-Module $(PowerShellRoot)/tools/packaging -Force
$signedFilesPath = '$(System.ArtifactsDirectory)\signed\'
$BuildPath = '$(BinPath)'
Write-Verbose -Verbose -Message "BuildPath: $BuildPath"
Update-PSSignedBuildFolder -BuildPath $BuildPath -SignedFilesPath $SignedFilesPath
$dlls = Get-ChildItem $BuildPath\*.dll, $BuildPath\*.exe -Recurse
$signatures = $dlls | Get-AuthenticodeSignature
$missingSignatures = $signatures | Where-Object { $_.status -eq 'notsigned' -or $_.SignerCertificate.Issuer -notmatch '^CN=Microsoft.*'}| select-object -ExpandProperty Path
Write-Verbose -verbose "to be signed:`r`n $($missingSignatures | Out-String)"
$filesToSignDirectory = "$(System.ArtifactsDirectory)\thirdPartyToBeSigned"
if (Test-Path $filesToSignDirectory) {
Remove-Item -Path $filesToSignDirectory -Recurse -Force
}
$null = New-Item -ItemType Directory -Path $filesToSignDirectory -Force -Verbose
$signedFilesDirectory = "$(System.ArtifactsDirectory)\thirdPartySigned"
if (Test-Path $signedFilesDirectory) {
Remove-Item -Path $signedFilesDirectory -Recurse -Force
}
$null = New-Item -ItemType Directory -Path $signedFilesDirectory -Force -Verbose
$missingSignatures | ForEach-Object {
$pathWithoutLeaf = Split-Path $_
$relativePath = $pathWithoutLeaf.replace($BuildPath,'')
Write-Verbose -Verbose -Message "relativePath: $relativePath"
$targetDirectory = Join-Path -Path $filesToSignDirectory -ChildPath $relativePath
Write-Verbose -Verbose -Message "targetDirectory: $targetDirectory"
if(!(Test-Path $targetDirectory))
{
$null = New-Item -ItemType Directory -Path $targetDirectory -Force -Verbose
}
Copy-Item -Path $_ -Destination $targetDirectory
}
displayName: Create ThirdParty Signing Folder
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
- template: EsrpSign.yml@ComplianceRepo
parameters:
buildOutputPath: $(System.ArtifactsDirectory)\thirdPartyToBeSigned
signOutputPath: $(System.ArtifactsDirectory)\thirdPartySigned
certificateId: "CP-231522"
pattern: |
**\*.dll
useMinimatch: true
shouldSign: $(SHOULD_SIGN)
displayName: Sign ThirdParty binaries
- pwsh: |
Get-ChildItem '$(System.ArtifactsDirectory)\thirdPartySigned\*'
displayName: Capture ThirdParty Signed files
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
- pwsh: |
Import-Module '$(PowerShellRoot)/build.psm1' -Force
Import-Module '$(PowerShellRoot)/tools/packaging' -Force
$signedFilesPath = '$(System.ArtifactsDirectory)\thirdPartySigned'
$BuildPath = '$(BinPath)'
Update-PSSignedBuildFolder -BuildPath $BuildPath -SignedFilesPath $SignedFilesPath
if ($env:BuildConfiguration -eq 'minSize') {
## Remove XML files when making a min-size package.
Remove-Item "$BuildPath/*.xml" -Force
}
displayName: Merge ThirdParty signed files with Build
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
- pwsh: |
$uploadFolder = '$(BinPath)'
$containerName = '$(signedArtifactContainer)'
Write-Verbose -Verbose "File permissions after signing"
Get-ChildItem $uploadFolder\pwsh | Select-Object -Property 'unixmode', 'size', 'name'
$uploadTarFilePath = Join-Path '$(System.ArtifactsDirectory)' '$(signedBuildArtifactName)'
Write-Verbose -Verbose -Message "Creating tar.gz - $uploadTarFilePath"
tar -czvf $uploadTarFilePath -C $uploadFolder *
Get-ChildItem '$(System.ArtifactsDirectory)' | Out-String | Write-Verbose -Verbose
Write-Host "##vso[artifact.upload containerfolder=$containerName;artifactname=$containerName]$uploadTarFilePath"
displayName: Upload signed tar.gz files to artifacts
condition: eq(variables['ArtifactPlatform'], 'linux')
- pwsh: |
$uploadFolder = '$(BinPath)'
$containerName = '$(signedArtifactContainer)'
Get-ChildItem $uploadFolder -Recurse | Out-String | Write-Verbose -Verbose
$uploadZipFilePath = Join-Path '$(System.ArtifactsDirectory)' 'PowerShell-$(Version)$(signedBuildArtifactName)'
Write-Verbose -Verbose -Message "Creating zip - $uploadZipFilePath"
Compress-Archive -Path $uploadFolder/* -DestinationPath $uploadZipFilePath -Verbose
Get-ChildItem '$(System.ArtifactsDirectory)' | Out-String | Write-Verbose -Verbose
Write-Host "##vso[artifact.upload containerfolder=$containerName;artifactname=$containerName]$uploadZipFilePath"
displayName: Upload signed zip files to artifacts
condition: eq(variables['ArtifactPlatform'], 'windows')
- template: /tools/releaseBuild/azureDevOps/templates/step/finalize.yml
@@ -14,7 +14,7 @@ jobs:
condition: succeeded()
dependsOn: ${{ parameters.parentJob }}
pool:
name: PowerShell1ES
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
variables:
@@ -8,7 +8,7 @@ jobs:
${{ parameters.parentJobs }}
condition: succeeded()
pool:
name: PowerShell1ES
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
variables:
@@ -12,9 +12,8 @@ jobs:
- job: sign_windows_${{ parameters.Architecture }}_${{ parameters.BuildConfiguration }}
displayName: Package Windows - ${{ parameters.Architecture }} ${{ parameters.BuildConfiguration }}
condition: succeeded()
dependsOn: ${{ parameters.parentJob }}
pool:
name: PowerShell1ES
name: $(windowsPool)
demands:
- ImageOverride -equals PSMMS2019-Secure
variables: