mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Restructure the package build to simplify signing and packaging stages (#19321)
This commit is contained in:
@@ -51,6 +51,7 @@ variables:
|
||||
value: spdx:2.2
|
||||
- name: BUILDSECMON_OPT_IN
|
||||
value: true
|
||||
- group: PoolNames
|
||||
|
||||
stages:
|
||||
- stage: prep
|
||||
@@ -68,30 +69,6 @@ stages:
|
||||
parameters:
|
||||
buildArchitecture: arm64
|
||||
|
||||
- template: templates/mac-file-signing.yml
|
||||
parameters:
|
||||
buildArchitecture: x64
|
||||
|
||||
- template: templates/mac-file-signing.yml
|
||||
parameters:
|
||||
buildArchitecture: arm64
|
||||
|
||||
- template: templates/mac-package-build.yml
|
||||
parameters:
|
||||
buildArchitecture: x64
|
||||
|
||||
- template: templates/mac-package-build.yml
|
||||
parameters:
|
||||
buildArchitecture: arm64
|
||||
|
||||
- template: templates/mac-package-signing.yml
|
||||
parameters:
|
||||
buildArchitecture: x64
|
||||
|
||||
- template: templates/mac-package-signing.yml
|
||||
parameters:
|
||||
buildArchitecture: arm64
|
||||
|
||||
- stage: linux
|
||||
dependsOn: ['prep']
|
||||
jobs:
|
||||
@@ -113,29 +90,6 @@ stages:
|
||||
parameters:
|
||||
buildName: alpine
|
||||
|
||||
- template: templates/linux-authenticode-sign.yml
|
||||
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: deb
|
||||
parentJob: sign_linux_builds
|
||||
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: rpm
|
||||
uploadDisplayName: Upload and Sign
|
||||
parentJob: sign_linux_builds
|
||||
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: alpine
|
||||
parentJob: sign_linux_builds
|
||||
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: fxdependent
|
||||
parentJob: sign_linux_builds
|
||||
|
||||
- stage: windows
|
||||
dependsOn: ['prep']
|
||||
jobs:
|
||||
@@ -168,66 +122,221 @@ stages:
|
||||
parameters:
|
||||
Architecture: fxdependentWinDesktop
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: x64
|
||||
parentJob: build_windows_x64_release
|
||||
- stage: SignFiles
|
||||
displayName: Sign files
|
||||
dependsOn: ['windows', 'linux', 'macos']
|
||||
jobs:
|
||||
- template: templates/mac-file-signing.yml
|
||||
parameters:
|
||||
buildArchitecture: x64
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: x64
|
||||
BuildConfiguration: minSize
|
||||
parentJob: build_windows_x64_minSize
|
||||
- template: templates/mac-file-signing.yml
|
||||
parameters:
|
||||
buildArchitecture: arm64
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: x86
|
||||
parentJob: build_windows_x86_release
|
||||
- job: SignFilesWinLinux
|
||||
pool:
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
displayName: Sign files
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: arm
|
||||
parentJob: build_windows_arm_release
|
||||
variables:
|
||||
- group: ESRP
|
||||
- name: runCodesignValidationInjection
|
||||
value: false
|
||||
- name: NugetSecurityAnalysisWarningLevel
|
||||
value: none
|
||||
- name: repoFolder
|
||||
value: PowerShell
|
||||
- name: repoRoot
|
||||
value: $(Agent.BuildDirectory)\$(repoFolder)
|
||||
- name: complianceRepoFolder
|
||||
value: compliance
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: arm64
|
||||
parentJob: build_windows_arm64_release
|
||||
strategy:
|
||||
matrix:
|
||||
linux-x64:
|
||||
runtime: linux-x64
|
||||
unsignedBuildArtifactContainer: pwshLinuxBuild.tar.gz
|
||||
unsignedBuildArtifactName: pwshLinuxBuild.tar.gz
|
||||
signedBuildArtifactName: pwshLinuxBuild.tar.gz
|
||||
signedArtifactContainer: authenticode-signed
|
||||
linux-x64-Alpine:
|
||||
runtime: linux-x64-Alpine
|
||||
unsignedBuildArtifactContainer: pwshLinuxBuildAlpine.tar.gz
|
||||
unsignedBuildArtifactName: pwshLinuxBuild.tar.gz
|
||||
signedBuildArtifactName: pwshLinuxBuildAlpine.tar.gz
|
||||
signedArtifactContainer: authenticode-signed
|
||||
linux-arm32:
|
||||
runtime: linux-arm32
|
||||
unsignedBuildArtifactContainer: pwshLinuxBuildArm32.tar.gz
|
||||
unsignedBuildArtifactName: pwshLinuxBuildArm32.tar.gz
|
||||
signedBuildArtifactName: pwshLinuxBuildArm32.tar.gz
|
||||
signedArtifactContainer: authenticode-signed
|
||||
linux-arm64:
|
||||
runtime: linux-arm64
|
||||
unsignedBuildArtifactContainer: pwshLinuxBuildArm64.tar.gz
|
||||
unsignedBuildArtifactName: pwshLinuxBuildArm64.tar.gz
|
||||
signedBuildArtifactName: pwshLinuxBuildArm64.tar.gz
|
||||
signedArtifactContainer: authenticode-signed
|
||||
linux-fxd:
|
||||
runtime: linux-fxd
|
||||
unsignedBuildArtifactContainer: pwshLinuxBuildFxdependent.tar.gz
|
||||
unsignedBuildArtifactName: pwshLinuxBuild.tar.gz
|
||||
signedBuildArtifactName: pwshLinuxBuildFxdependent.tar.gz
|
||||
signedArtifactContainer: authenticode-signed
|
||||
linux-mariner:
|
||||
runtime: linux-mariner
|
||||
unsignedBuildArtifactContainer: pwshMarinerBuildAmd64.tar.gz
|
||||
unsignedBuildArtifactName: pwshMarinerBuildAmd64.tar.gz
|
||||
signedBuildArtifactName: pwshMarinerBuildAmd64.tar.gz
|
||||
signedArtifactContainer: authenticode-signed
|
||||
linux-minsize:
|
||||
runtime: linux-minsize
|
||||
unsignedBuildArtifactContainer: pwshLinuxBuildMinSize.tar.gz
|
||||
unsignedBuildArtifactName: pwshLinuxBuildMinSize.tar.gz
|
||||
signedBuildArtifactName: pwshLinuxBuildMinSize.tar.gz
|
||||
signedArtifactContainer: authenticode-signed
|
||||
win-x64:
|
||||
runtime: win-x64
|
||||
unsignedBuildArtifactContainer: results
|
||||
unsignedBuildArtifactName: '**/*-symbols-win-x64.zip'
|
||||
signedBuildArtifactName: '-symbols-win-x64-signed.zip'
|
||||
signedArtifactContainer: results
|
||||
win-x86:
|
||||
runtime: win-x86
|
||||
unsignedBuildArtifactContainer: results
|
||||
unsignedBuildArtifactName: '**/*-symbols-win-x86.zip'
|
||||
signedBuildArtifactName: '-symbols-win-x86-signed.zip'
|
||||
signedArtifactContainer: results
|
||||
win-arm32:
|
||||
runtime: win-arm32
|
||||
unsignedBuildArtifactContainer: results
|
||||
unsignedBuildArtifactName: '**/*-symbols-win-arm32.zip'
|
||||
signedBuildArtifactName: '-symbols-win-arm32-signed.zip'
|
||||
signedArtifactContainer: results
|
||||
win-arm64:
|
||||
runtime: win-arm64
|
||||
unsignedBuildArtifactContainer: results
|
||||
unsignedBuildArtifactName: '**/*-symbols-win-arm64.zip'
|
||||
signedBuildArtifactName: '-symbols-win-arm64-signed.zip'
|
||||
signedArtifactContainer: results
|
||||
win-x64-gc:
|
||||
runtime: win-x64-gc
|
||||
unsignedBuildArtifactContainer: results
|
||||
unsignedBuildArtifactName: '**/*-symbols-win-x64-gc.zip'
|
||||
signedBuildArtifactName: '-symbols-win-x64-gc-signed.zip'
|
||||
signedArtifactContainer: results
|
||||
win-fxdependent:
|
||||
runtime: win-fxdependent
|
||||
unsignedBuildArtifactContainer: results
|
||||
unsignedBuildArtifactName: '**/*-symbols-win-fxdependent.zip'
|
||||
signedBuildArtifactName: '-symbols-win-fxdependent-signed.zip'
|
||||
signedArtifactContainer: results
|
||||
win-fxdependentWinDesktop:
|
||||
runtime: win-fxdependentWinDesktop
|
||||
unsignedBuildArtifactContainer: results
|
||||
unsignedBuildArtifactName: '**/*-symbols-win-fxdependentWinDesktop.zip'
|
||||
signedBuildArtifactName: '-symbols-win-fxdependentWinDesktop-signed.zip'
|
||||
signedArtifactContainer: results
|
||||
steps:
|
||||
- template: templates/sign-build-file.yml
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: fxdependent
|
||||
parentJob: build_windows_fxdependent_release
|
||||
- stage: mac_packaging
|
||||
displayName: macOS packaging
|
||||
dependsOn: ['SignFiles']
|
||||
jobs:
|
||||
- template: templates/mac-package-build.yml
|
||||
parameters:
|
||||
buildArchitecture: x64
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: fxdependentWinDesktop
|
||||
parentJob: build_windows_fxdependentWinDesktop_release
|
||||
- template: templates/mac-package-build.yml
|
||||
parameters:
|
||||
buildArchitecture: arm64
|
||||
|
||||
- template: templates/windows-package-signing.yml
|
||||
parameters:
|
||||
parentJobs:
|
||||
- sign_windows_x64_release
|
||||
- sign_windows_x64_minSize
|
||||
- sign_windows_x86_release
|
||||
- sign_windows_arm_release
|
||||
- sign_windows_arm64_release
|
||||
- sign_windows_fxdependent_release
|
||||
- sign_windows_fxdependentWinDesktop_release
|
||||
- stage: linux_packaging
|
||||
displayName: Linux Packaging
|
||||
dependsOn: ['SignFiles']
|
||||
jobs:
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: deb
|
||||
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: rpm
|
||||
uploadDisplayName: Upload and Sign
|
||||
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: alpine
|
||||
|
||||
- template: templates/linux-packaging.yml
|
||||
parameters:
|
||||
buildName: fxdependent
|
||||
|
||||
- stage: win_packaging
|
||||
displayName: Windows Packaging
|
||||
dependsOn: ['SignFiles']
|
||||
jobs:
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: x64
|
||||
parentJob: build_windows_x64_release
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: x64
|
||||
BuildConfiguration: minSize
|
||||
parentJob: build_windows_x64_minSize
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: x86
|
||||
parentJob: build_windows_x86_release
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: arm
|
||||
parentJob: build_windows_arm_release
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: arm64
|
||||
parentJob: build_windows_arm64_release
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: fxdependent
|
||||
parentJob: build_windows_fxdependent_release
|
||||
|
||||
- template: templates/windows-packaging.yml
|
||||
parameters:
|
||||
Architecture: fxdependentWinDesktop
|
||||
parentJob: build_windows_fxdependentWinDesktop_release
|
||||
|
||||
- stage: package_signing
|
||||
displayName: Package Signing
|
||||
dependsOn: ['mac_packaging', 'linux_packaging', 'win_packaging']
|
||||
jobs:
|
||||
- template: templates/windows-package-signing.yml
|
||||
|
||||
# This is done late so that we dont use resources before the big signing and packaging tasks.
|
||||
- stage: compliance
|
||||
dependsOn: ['windows']
|
||||
dependsOn: ['package_signing']
|
||||
jobs:
|
||||
- template: templates/compliance.yml
|
||||
|
||||
- stage: nuget_and_json
|
||||
dependsOn: ['windows','linux','macOS']
|
||||
displayName: NuGet Packaging and Build Json
|
||||
dependsOn: [package_signing]
|
||||
jobs:
|
||||
- template: templates/nuget.yml
|
||||
|
||||
- template: templates/json.yml
|
||||
|
||||
- stage: test_and_release_artifacts
|
||||
displayName: Test and Release Artifacts
|
||||
dependsOn: ['prep']
|
||||
jobs:
|
||||
- template: templates/testartifacts.yml
|
||||
@@ -235,7 +344,7 @@ stages:
|
||||
- job: release_json
|
||||
displayName: Create and Upload release.json
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
steps:
|
||||
|
||||
@@ -17,7 +17,7 @@ jobs:
|
||||
dependsOn:
|
||||
${{ parameters.parentJobs }}
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
|
||||
|
||||
@@ -13,7 +13,7 @@ jobs:
|
||||
${{ parameters.parentJobs }}
|
||||
condition: succeeded()
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
parameters:
|
||||
buildName: ''
|
||||
uploadDisplayName: 'Upload'
|
||||
parentJob: ''
|
||||
|
||||
jobs:
|
||||
- job: pkg_${{ parameters.buildName }}
|
||||
@@ -11,7 +10,6 @@ jobs:
|
||||
name: PowerShell1ES
|
||||
demands:
|
||||
- ImageOverride -equals PSMMSUbuntu20.04-Secure
|
||||
dependsOn: sign_linux_builds
|
||||
variables:
|
||||
- name: runCodesignValidationInjection
|
||||
value: false
|
||||
|
||||
@@ -4,7 +4,6 @@ parameters:
|
||||
jobs:
|
||||
- job: MacFileSigningJob_${{ parameters.buildArchitecture }}
|
||||
displayName: macOS File signing ${{ parameters.buildArchitecture }}
|
||||
dependsOn: build_macOS_${{ parameters.buildArchitecture }}
|
||||
condition: succeeded()
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
|
||||
@@ -5,7 +5,6 @@ parameters:
|
||||
jobs:
|
||||
- job: package_macOS_${{ parameters.buildArchitecture }}
|
||||
displayName: Package macOS ${{ parameters.buildArchitecture }}
|
||||
dependsOn: MacFileSigningJob_${{ parameters.buildArchitecture }}
|
||||
condition: succeeded()
|
||||
pool:
|
||||
vmImage: macos-latest
|
||||
|
||||
@@ -8,7 +8,7 @@ jobs:
|
||||
displayName: Build NuGet packages
|
||||
condition: succeeded()
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
|
||||
|
||||
@@ -0,0 +1,324 @@
|
||||
steps:
|
||||
- pwsh: |
|
||||
$platform = '$(runtime)' -match '^linux' ? 'linux' : 'windows'
|
||||
$vstsCommandString = "vso[task.setvariable variable=ArtifactPlatform]$platform"
|
||||
Write-Host ("sending " + $vstsCommandString)
|
||||
Write-Host "##$vstsCommandString"
|
||||
displayName: Set artifact platform
|
||||
|
||||
- task: DownloadPipelineArtifact@2
|
||||
inputs:
|
||||
artifactName: '$(unsignedBuildArtifactContainer)'
|
||||
itemPattern: '$(unsignedBuildArtifactName)'
|
||||
|
||||
- pwsh: |
|
||||
Get-ChildItem "$(Pipeline.Workspace)\*" -Recurse
|
||||
displayName: 'Capture Downloaded Artifacts'
|
||||
# Diagnostics is not critical it passes every time it runs
|
||||
continueOnError: true
|
||||
|
||||
- checkout: self
|
||||
clean: true
|
||||
path: $(repoFolder)
|
||||
|
||||
- template: SetVersionVariables.yml
|
||||
parameters:
|
||||
ReleaseTagVar: $(ReleaseTagVar)
|
||||
|
||||
- template: cloneToOfficialPath.yml
|
||||
|
||||
- pwsh: |
|
||||
$zipFileFilter = '$(unsignedBuildArtifactName)'
|
||||
$zipFileFilter = $zipFileFilter.Replace('**/', '')
|
||||
|
||||
Write-Verbose -Verbose -Message "zipFileFilter = $zipFileFilter"
|
||||
|
||||
Write-Verbose -Verbose -Message "Looking for $(Pipeline.Workspace)\$(unsignedBuildArtifactName)"
|
||||
|
||||
$zipFilePath = Get-ChildItem -Path '$(Pipeline.Workspace)\$(unsignedBuildArtifactName)' -recurse
|
||||
|
||||
if (-not (Test-Path $zipFilePath))
|
||||
{
|
||||
throw "zip file not found: $zipfilePath"
|
||||
}
|
||||
|
||||
if ($zipFilePath.Count -ne 1) {
|
||||
Write-Verbose "zip filename" -verbose
|
||||
$zipFilePath | Out-String | Write-Verbose -Verbose
|
||||
throw 'multiple zip files found when 1 was expected'
|
||||
}
|
||||
|
||||
$expandedFolderName = [System.io.path]::GetFileNameWithoutExtension($zipfilePath)
|
||||
$expandedFolderPath = Join-Path '$(Pipeline.Workspace)' 'expanded' $expandedFolderName
|
||||
|
||||
Write-Verbose -Verbose -Message "Expaning $zipFilePath to $expandedFolderPath"
|
||||
|
||||
New-Item -Path $expandedFolderPath -ItemType Directory
|
||||
Expand-Archive -Path $zipFilePath -DestinationPath $expandedFolderPath
|
||||
|
||||
if (-not (Test-Path $expandedFolderPath\pwsh.exe) ) {
|
||||
throw 'zip did not expand as expected'
|
||||
}
|
||||
else {
|
||||
$vstsCommandString = "vso[task.setvariable variable=BinPath]$expandedFolderPath"
|
||||
Write-Host ("sending " + $vstsCommandString)
|
||||
Write-Host "##$vstsCommandString"
|
||||
}
|
||||
|
||||
displayName: Expand zip packages
|
||||
condition: eq(variables['ArtifactPlatform'], 'windows')
|
||||
|
||||
- pwsh: |
|
||||
$tarPackageName = '$(unsignedBuildArtifactName)'
|
||||
|
||||
Write-Verbose -Verbose -Message "tarPackageName = $tarPackageName"
|
||||
|
||||
$tarPackagePath = Join-Path '$(Pipeline.Workspace)' $tarPackageName
|
||||
|
||||
Write-Verbose -Verbose -Message "Looking for: $tarPackagePath"
|
||||
|
||||
$expandedPathFolderName = $tarPackageName -replace '.tar.gz', ''
|
||||
$expandedFolderPath = Join-Path '$(Pipeline.Workspace)' 'expanded' $expandedPathFolderName
|
||||
|
||||
if (-not (Test-Path $tarPackagePath))
|
||||
{
|
||||
throw "tar file not found: $tarPackagePath"
|
||||
}
|
||||
|
||||
Write-Verbose -Verbose -Message "Expanding $tarPackagePath to $expandedFolderPath"
|
||||
|
||||
New-Item -Path $expandedFolderPath -ItemType Directory
|
||||
tar -xf $tarPackagePath -C $expandedFolderPath
|
||||
|
||||
if (-not (Test-Path $expandedFolderPath/pwsh) ) {
|
||||
throw 'tar.gz did not expand as expected'
|
||||
}
|
||||
else {
|
||||
$vstsCommandString = "vso[task.setvariable variable=BinPath]$expandedFolderPath"
|
||||
Write-Host ("sending " + $vstsCommandString)
|
||||
Write-Host "##$vstsCommandString"
|
||||
}
|
||||
|
||||
Write-Verbose -Verbose "File permisions after expanding"
|
||||
Get-ChildItem -Path "$expandedFolderPath/pwsh" | Select-Object -Property 'unixmode', 'size', 'name'
|
||||
displayName: Expand tar.gz packages
|
||||
condition: eq(variables['ArtifactPlatform'], 'linux')
|
||||
|
||||
- template: insert-nuget-config-azfeed.yml
|
||||
parameters:
|
||||
repoRoot: $(PowerShellRoot)
|
||||
|
||||
- pwsh: |
|
||||
Set-Location $env:POWERSHELLROOT
|
||||
import-module "$env:POWERSHELLROOT/build.psm1"
|
||||
Sync-PSTags -AddRemoteIfMissing
|
||||
displayName: SyncTags
|
||||
condition: and(succeeded(), ne(variables['SkipBuild'], 'true'))
|
||||
|
||||
- checkout: ComplianceRepo
|
||||
clean: true
|
||||
path: $(complianceRepoFolder)
|
||||
|
||||
- template: shouldSign.yml
|
||||
|
||||
- pwsh: |
|
||||
$fullSymbolsFolder = '$(BinPath)'
|
||||
Write-Verbose -Verbose "fullSymbolsFolder == $fullSymbolsFolder"
|
||||
|
||||
Get-ChildItem -Recurse $fullSymbolsFolder | out-string | Write-Verbose -Verbose
|
||||
|
||||
$filesToSignDirectory = "$(System.ArtifactsDirectory)\toBeSigned"
|
||||
|
||||
if ((Test-Path -Path $filesToSignDirectory)) {
|
||||
Remove-Item -Path $filesToSignDirectory -Recurse -Force
|
||||
}
|
||||
|
||||
$null = New-Item -ItemType Directory -Path $filesToSignDirectory -Force
|
||||
|
||||
$signedFilesDirectory = "$(System.ArtifactsDirectory)\signed"
|
||||
|
||||
if ((Test-Path -Path $signedFilesDirectory)) {
|
||||
Remove-Item -Path $signedFilesDirectory -Recurse -Force
|
||||
}
|
||||
|
||||
$null = New-Item -ItemType Directory -Path $signedFilesDirectory -Force
|
||||
|
||||
$itemsToCopyWithRecurse = @(
|
||||
"$($fullSymbolsFolder)\*.ps1"
|
||||
"$($fullSymbolsFolder)\Microsoft.PowerShell*.dll"
|
||||
)
|
||||
|
||||
$itemsToCopy = @{
|
||||
"$($fullSymbolsFolder)\*.ps1" = ""
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Host\Microsoft.PowerShell.Host.psd1" = "Modules\Microsoft.PowerShell.Host"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Management\Microsoft.PowerShell.Management.psd1" = "Modules\Microsoft.PowerShell.Management"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.psd1" = "Modules\Microsoft.PowerShell.Security"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Utility.psd1" = "Modules\Microsoft.PowerShell.Utility"
|
||||
"$($fullSymbolsFolder)\pwsh.dll" = ""
|
||||
"$($fullSymbolsFolder)\System.Management.Automation.dll" = ""
|
||||
}
|
||||
|
||||
## Windows only modules
|
||||
|
||||
if('$(ArtifactPlatform)' -eq 'windows') {
|
||||
$itemsToCopy += @{
|
||||
"$($fullSymbolsFolder)\pwsh.exe" = ""
|
||||
"$($fullSymbolsFolder)\Microsoft.Management.Infrastructure.CimCmdlets.dll" = ""
|
||||
"$($fullSymbolsFolder)\Microsoft.WSMan.*.dll" = ""
|
||||
"$($fullSymbolsFolder)\Modules\CimCmdlets\CimCmdlets.psd1" = "Modules\CimCmdlets"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Diagnostics.format.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Event.format.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\GetEvent.types.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Security\Security.types.ps1xml" = "Modules\Microsoft.PowerShell.Security"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Microsoft.PowerShell.Diagnostics.psd1" = "Modules\Microsoft.PowerShell.Diagnostics"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.WSMan.Management\Microsoft.WSMan.Management.psd1" = "Modules\Microsoft.WSMan.Management"
|
||||
"$($fullSymbolsFolder)\Modules\Microsoft.WSMan.Management\WSMan.format.ps1xml" = "Modules\Microsoft.WSMan.Management"
|
||||
"$($fullSymbolsFolder)\Modules\PSDiagnostics\PSDiagnostics.ps?1" = "Modules\PSDiagnostics"
|
||||
}
|
||||
}
|
||||
else {
|
||||
$itemsToCopy += @{
|
||||
"$($fullSymbolsFolder)\pwsh" = ""
|
||||
}
|
||||
}
|
||||
|
||||
$itemsToExclude = @(
|
||||
# This package is retrieved from https://www.github.com/powershell/MarkdownRender
|
||||
"$($fullSymbolsFolder)\Microsoft.PowerShell.MarkdownRender.dll"
|
||||
)
|
||||
|
||||
Write-Verbose -verbose "recusively copying $($itemsToCopyWithRecurse | out-string) to $filesToSignDirectory"
|
||||
Copy-Item -Path $itemsToCopyWithRecurse -Destination $filesToSignDirectory -Recurse -verbose -exclude $itemsToExclude
|
||||
|
||||
foreach($pattern in $itemsToCopy.Keys) {
|
||||
$destinationFolder = Join-Path $filesToSignDirectory -ChildPath $itemsToCopy.$pattern
|
||||
$null = New-Item -ItemType Directory -Path $destinationFolder -Force
|
||||
Write-Verbose -verbose "copying $pattern to $destinationFolder"
|
||||
Copy-Item -Path $pattern -Destination $destinationFolder -Recurse -verbose
|
||||
}
|
||||
displayName: 'Prepare files to be signed'
|
||||
|
||||
- template: EsrpSign.yml@ComplianceRepo
|
||||
parameters:
|
||||
buildOutputPath: $(System.ArtifactsDirectory)\toBeSigned
|
||||
signOutputPath: $(System.ArtifactsDirectory)\signed
|
||||
certificateId: "$(AUTHENTICODE_CERT)"
|
||||
pattern: |
|
||||
**\*.dll
|
||||
**\*.psd1
|
||||
**\*.psm1
|
||||
**\*.ps1xml
|
||||
**\*.ps1
|
||||
**\*.exe
|
||||
useMinimatch: true
|
||||
shouldSign: $(SHOULD_SIGN)
|
||||
displayName: Authenticode sign our binaries
|
||||
|
||||
- pwsh: |
|
||||
Import-Module $(PowerShellRoot)/build.psm1 -Force
|
||||
Import-Module $(PowerShellRoot)/tools/packaging -Force
|
||||
$signedFilesPath = '$(System.ArtifactsDirectory)\signed\'
|
||||
$BuildPath = '$(BinPath)'
|
||||
Write-Verbose -Verbose -Message "BuildPath: $BuildPath"
|
||||
|
||||
Update-PSSignedBuildFolder -BuildPath $BuildPath -SignedFilesPath $SignedFilesPath
|
||||
$dlls = Get-ChildItem $BuildPath\*.dll, $BuildPath\*.exe -Recurse
|
||||
$signatures = $dlls | Get-AuthenticodeSignature
|
||||
$missingSignatures = $signatures | Where-Object { $_.status -eq 'notsigned' -or $_.SignerCertificate.Issuer -notmatch '^CN=Microsoft.*'}| select-object -ExpandProperty Path
|
||||
|
||||
Write-Verbose -verbose "to be signed:`r`n $($missingSignatures | Out-String)"
|
||||
|
||||
$filesToSignDirectory = "$(System.ArtifactsDirectory)\thirdPartyToBeSigned"
|
||||
if (Test-Path $filesToSignDirectory) {
|
||||
Remove-Item -Path $filesToSignDirectory -Recurse -Force
|
||||
}
|
||||
|
||||
$null = New-Item -ItemType Directory -Path $filesToSignDirectory -Force -Verbose
|
||||
|
||||
$signedFilesDirectory = "$(System.ArtifactsDirectory)\thirdPartySigned"
|
||||
if (Test-Path $signedFilesDirectory) {
|
||||
Remove-Item -Path $signedFilesDirectory -Recurse -Force
|
||||
}
|
||||
|
||||
$null = New-Item -ItemType Directory -Path $signedFilesDirectory -Force -Verbose
|
||||
|
||||
$missingSignatures | ForEach-Object {
|
||||
$pathWithoutLeaf = Split-Path $_
|
||||
$relativePath = $pathWithoutLeaf.replace($BuildPath,'')
|
||||
Write-Verbose -Verbose -Message "relativePath: $relativePath"
|
||||
$targetDirectory = Join-Path -Path $filesToSignDirectory -ChildPath $relativePath
|
||||
Write-Verbose -Verbose -Message "targetDirectory: $targetDirectory"
|
||||
if(!(Test-Path $targetDirectory))
|
||||
{
|
||||
$null = New-Item -ItemType Directory -Path $targetDirectory -Force -Verbose
|
||||
}
|
||||
Copy-Item -Path $_ -Destination $targetDirectory
|
||||
}
|
||||
|
||||
displayName: Create ThirdParty Signing Folder
|
||||
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
|
||||
|
||||
- template: EsrpSign.yml@ComplianceRepo
|
||||
parameters:
|
||||
buildOutputPath: $(System.ArtifactsDirectory)\thirdPartyToBeSigned
|
||||
signOutputPath: $(System.ArtifactsDirectory)\thirdPartySigned
|
||||
certificateId: "CP-231522"
|
||||
pattern: |
|
||||
**\*.dll
|
||||
useMinimatch: true
|
||||
shouldSign: $(SHOULD_SIGN)
|
||||
displayName: Sign ThirdParty binaries
|
||||
|
||||
- pwsh: |
|
||||
Get-ChildItem '$(System.ArtifactsDirectory)\thirdPartySigned\*'
|
||||
displayName: Capture ThirdParty Signed files
|
||||
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
|
||||
|
||||
- pwsh: |
|
||||
Import-Module '$(PowerShellRoot)/build.psm1' -Force
|
||||
Import-Module '$(PowerShellRoot)/tools/packaging' -Force
|
||||
$signedFilesPath = '$(System.ArtifactsDirectory)\thirdPartySigned'
|
||||
$BuildPath = '$(BinPath)'
|
||||
|
||||
Update-PSSignedBuildFolder -BuildPath $BuildPath -SignedFilesPath $SignedFilesPath
|
||||
if ($env:BuildConfiguration -eq 'minSize') {
|
||||
## Remove XML files when making a min-size package.
|
||||
Remove-Item "$BuildPath/*.xml" -Force
|
||||
}
|
||||
displayName: Merge ThirdParty signed files with Build
|
||||
condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true'))
|
||||
|
||||
- pwsh: |
|
||||
$uploadFolder = '$(BinPath)'
|
||||
$containerName = '$(signedArtifactContainer)'
|
||||
|
||||
Write-Verbose -Verbose "File permissions after signing"
|
||||
Get-ChildItem $uploadFolder\pwsh | Select-Object -Property 'unixmode', 'size', 'name'
|
||||
|
||||
$uploadTarFilePath = Join-Path '$(System.ArtifactsDirectory)' '$(signedBuildArtifactName)'
|
||||
Write-Verbose -Verbose -Message "Creating tar.gz - $uploadTarFilePath"
|
||||
tar -czvf $uploadTarFilePath -C $uploadFolder *
|
||||
|
||||
Get-ChildItem '$(System.ArtifactsDirectory)' | Out-String | Write-Verbose -Verbose
|
||||
|
||||
Write-Host "##vso[artifact.upload containerfolder=$containerName;artifactname=$containerName]$uploadTarFilePath"
|
||||
displayName: Upload signed tar.gz files to artifacts
|
||||
condition: eq(variables['ArtifactPlatform'], 'linux')
|
||||
|
||||
- pwsh: |
|
||||
$uploadFolder = '$(BinPath)'
|
||||
$containerName = '$(signedArtifactContainer)'
|
||||
|
||||
Get-ChildItem $uploadFolder -Recurse | Out-String | Write-Verbose -Verbose
|
||||
|
||||
$uploadZipFilePath = Join-Path '$(System.ArtifactsDirectory)' 'PowerShell-$(Version)$(signedBuildArtifactName)'
|
||||
Write-Verbose -Verbose -Message "Creating zip - $uploadZipFilePath"
|
||||
Compress-Archive -Path $uploadFolder/* -DestinationPath $uploadZipFilePath -Verbose
|
||||
|
||||
Get-ChildItem '$(System.ArtifactsDirectory)' | Out-String | Write-Verbose -Verbose
|
||||
|
||||
Write-Host "##vso[artifact.upload containerfolder=$containerName;artifactname=$containerName]$uploadZipFilePath"
|
||||
displayName: Upload signed zip files to artifacts
|
||||
condition: eq(variables['ArtifactPlatform'], 'windows')
|
||||
|
||||
- template: /tools/releaseBuild/azureDevOps/templates/step/finalize.yml
|
||||
@@ -14,7 +14,7 @@ jobs:
|
||||
condition: succeeded()
|
||||
dependsOn: ${{ parameters.parentJob }}
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
variables:
|
||||
|
||||
@@ -8,7 +8,7 @@ jobs:
|
||||
${{ parameters.parentJobs }}
|
||||
condition: succeeded()
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
variables:
|
||||
|
||||
@@ -12,9 +12,8 @@ jobs:
|
||||
- job: sign_windows_${{ parameters.Architecture }}_${{ parameters.BuildConfiguration }}
|
||||
displayName: Package Windows - ${{ parameters.Architecture }} ${{ parameters.BuildConfiguration }}
|
||||
condition: succeeded()
|
||||
dependsOn: ${{ parameters.parentJob }}
|
||||
pool:
|
||||
name: PowerShell1ES
|
||||
name: $(windowsPool)
|
||||
demands:
|
||||
- ImageOverride -equals PSMMS2019-Secure
|
||||
variables:
|
||||
|
||||
Reference in New Issue
Block a user