diff --git a/tools/releaseBuild/azureDevOps/releaseBuild.yml b/tools/releaseBuild/azureDevOps/releaseBuild.yml index 32f6bcca59..b670d55de7 100644 --- a/tools/releaseBuild/azureDevOps/releaseBuild.yml +++ b/tools/releaseBuild/azureDevOps/releaseBuild.yml @@ -51,6 +51,7 @@ variables: value: spdx:2.2 - name: BUILDSECMON_OPT_IN value: true + - group: PoolNames stages: - stage: prep @@ -68,30 +69,6 @@ stages: parameters: buildArchitecture: arm64 - - template: templates/mac-file-signing.yml - parameters: - buildArchitecture: x64 - - - template: templates/mac-file-signing.yml - parameters: - buildArchitecture: arm64 - - - template: templates/mac-package-build.yml - parameters: - buildArchitecture: x64 - - - template: templates/mac-package-build.yml - parameters: - buildArchitecture: arm64 - - - template: templates/mac-package-signing.yml - parameters: - buildArchitecture: x64 - - - template: templates/mac-package-signing.yml - parameters: - buildArchitecture: arm64 - - stage: linux dependsOn: ['prep'] jobs: @@ -113,29 +90,6 @@ stages: parameters: buildName: alpine - - template: templates/linux-authenticode-sign.yml - - - template: templates/linux-packaging.yml - parameters: - buildName: deb - parentJob: sign_linux_builds - - - template: templates/linux-packaging.yml - parameters: - buildName: rpm - uploadDisplayName: Upload and Sign - parentJob: sign_linux_builds - - - template: templates/linux-packaging.yml - parameters: - buildName: alpine - parentJob: sign_linux_builds - - - template: templates/linux-packaging.yml - parameters: - buildName: fxdependent - parentJob: sign_linux_builds - - stage: windows dependsOn: ['prep'] jobs: @@ -168,66 +122,221 @@ stages: parameters: Architecture: fxdependentWinDesktop - - template: templates/windows-packaging.yml - parameters: - Architecture: x64 - parentJob: build_windows_x64_release + - stage: SignFiles + displayName: Sign files + dependsOn: ['windows', 'linux', 'macos'] + jobs: + - template: templates/mac-file-signing.yml + parameters: + buildArchitecture: x64 - - template: templates/windows-packaging.yml - parameters: - Architecture: x64 - BuildConfiguration: minSize - parentJob: build_windows_x64_minSize + - template: templates/mac-file-signing.yml + parameters: + buildArchitecture: arm64 - - template: templates/windows-packaging.yml - parameters: - Architecture: x86 - parentJob: build_windows_x86_release + - job: SignFilesWinLinux + pool: + name: $(windowsPool) + demands: + - ImageOverride -equals PSMMS2019-Secure + displayName: Sign files - - template: templates/windows-packaging.yml - parameters: - Architecture: arm - parentJob: build_windows_arm_release + variables: + - group: ESRP + - name: runCodesignValidationInjection + value: false + - name: NugetSecurityAnalysisWarningLevel + value: none + - name: repoFolder + value: PowerShell + - name: repoRoot + value: $(Agent.BuildDirectory)\$(repoFolder) + - name: complianceRepoFolder + value: compliance - - template: templates/windows-packaging.yml - parameters: - Architecture: arm64 - parentJob: build_windows_arm64_release + strategy: + matrix: + linux-x64: + runtime: linux-x64 + unsignedBuildArtifactContainer: pwshLinuxBuild.tar.gz + unsignedBuildArtifactName: pwshLinuxBuild.tar.gz + signedBuildArtifactName: pwshLinuxBuild.tar.gz + signedArtifactContainer: authenticode-signed + linux-x64-Alpine: + runtime: linux-x64-Alpine + unsignedBuildArtifactContainer: pwshLinuxBuildAlpine.tar.gz + unsignedBuildArtifactName: pwshLinuxBuild.tar.gz + signedBuildArtifactName: pwshLinuxBuildAlpine.tar.gz + signedArtifactContainer: authenticode-signed + linux-arm32: + runtime: linux-arm32 + unsignedBuildArtifactContainer: pwshLinuxBuildArm32.tar.gz + unsignedBuildArtifactName: pwshLinuxBuildArm32.tar.gz + signedBuildArtifactName: pwshLinuxBuildArm32.tar.gz + signedArtifactContainer: authenticode-signed + linux-arm64: + runtime: linux-arm64 + unsignedBuildArtifactContainer: pwshLinuxBuildArm64.tar.gz + unsignedBuildArtifactName: pwshLinuxBuildArm64.tar.gz + signedBuildArtifactName: pwshLinuxBuildArm64.tar.gz + signedArtifactContainer: authenticode-signed + linux-fxd: + runtime: linux-fxd + unsignedBuildArtifactContainer: pwshLinuxBuildFxdependent.tar.gz + unsignedBuildArtifactName: pwshLinuxBuild.tar.gz + signedBuildArtifactName: pwshLinuxBuildFxdependent.tar.gz + signedArtifactContainer: authenticode-signed + linux-mariner: + runtime: linux-mariner + unsignedBuildArtifactContainer: pwshMarinerBuildAmd64.tar.gz + unsignedBuildArtifactName: pwshMarinerBuildAmd64.tar.gz + signedBuildArtifactName: pwshMarinerBuildAmd64.tar.gz + signedArtifactContainer: authenticode-signed + linux-minsize: + runtime: linux-minsize + unsignedBuildArtifactContainer: pwshLinuxBuildMinSize.tar.gz + unsignedBuildArtifactName: pwshLinuxBuildMinSize.tar.gz + signedBuildArtifactName: pwshLinuxBuildMinSize.tar.gz + signedArtifactContainer: authenticode-signed + win-x64: + runtime: win-x64 + unsignedBuildArtifactContainer: results + unsignedBuildArtifactName: '**/*-symbols-win-x64.zip' + signedBuildArtifactName: '-symbols-win-x64-signed.zip' + signedArtifactContainer: results + win-x86: + runtime: win-x86 + unsignedBuildArtifactContainer: results + unsignedBuildArtifactName: '**/*-symbols-win-x86.zip' + signedBuildArtifactName: '-symbols-win-x86-signed.zip' + signedArtifactContainer: results + win-arm32: + runtime: win-arm32 + unsignedBuildArtifactContainer: results + unsignedBuildArtifactName: '**/*-symbols-win-arm32.zip' + signedBuildArtifactName: '-symbols-win-arm32-signed.zip' + signedArtifactContainer: results + win-arm64: + runtime: win-arm64 + unsignedBuildArtifactContainer: results + unsignedBuildArtifactName: '**/*-symbols-win-arm64.zip' + signedBuildArtifactName: '-symbols-win-arm64-signed.zip' + signedArtifactContainer: results + win-x64-gc: + runtime: win-x64-gc + unsignedBuildArtifactContainer: results + unsignedBuildArtifactName: '**/*-symbols-win-x64-gc.zip' + signedBuildArtifactName: '-symbols-win-x64-gc-signed.zip' + signedArtifactContainer: results + win-fxdependent: + runtime: win-fxdependent + unsignedBuildArtifactContainer: results + unsignedBuildArtifactName: '**/*-symbols-win-fxdependent.zip' + signedBuildArtifactName: '-symbols-win-fxdependent-signed.zip' + signedArtifactContainer: results + win-fxdependentWinDesktop: + runtime: win-fxdependentWinDesktop + unsignedBuildArtifactContainer: results + unsignedBuildArtifactName: '**/*-symbols-win-fxdependentWinDesktop.zip' + signedBuildArtifactName: '-symbols-win-fxdependentWinDesktop-signed.zip' + signedArtifactContainer: results + steps: + - template: templates/sign-build-file.yml - - template: templates/windows-packaging.yml - parameters: - Architecture: fxdependent - parentJob: build_windows_fxdependent_release + - stage: mac_packaging + displayName: macOS packaging + dependsOn: ['SignFiles'] + jobs: + - template: templates/mac-package-build.yml + parameters: + buildArchitecture: x64 - - template: templates/windows-packaging.yml - parameters: - Architecture: fxdependentWinDesktop - parentJob: build_windows_fxdependentWinDesktop_release + - template: templates/mac-package-build.yml + parameters: + buildArchitecture: arm64 - - template: templates/windows-package-signing.yml - parameters: - parentJobs: - - sign_windows_x64_release - - sign_windows_x64_minSize - - sign_windows_x86_release - - sign_windows_arm_release - - sign_windows_arm64_release - - sign_windows_fxdependent_release - - sign_windows_fxdependentWinDesktop_release + - stage: linux_packaging + displayName: Linux Packaging + dependsOn: ['SignFiles'] + jobs: + - template: templates/linux-packaging.yml + parameters: + buildName: deb + - template: templates/linux-packaging.yml + parameters: + buildName: rpm + uploadDisplayName: Upload and Sign + + - template: templates/linux-packaging.yml + parameters: + buildName: alpine + + - template: templates/linux-packaging.yml + parameters: + buildName: fxdependent + + - stage: win_packaging + displayName: Windows Packaging + dependsOn: ['SignFiles'] + jobs: + - template: templates/windows-packaging.yml + parameters: + Architecture: x64 + parentJob: build_windows_x64_release + + - template: templates/windows-packaging.yml + parameters: + Architecture: x64 + BuildConfiguration: minSize + parentJob: build_windows_x64_minSize + + - template: templates/windows-packaging.yml + parameters: + Architecture: x86 + parentJob: build_windows_x86_release + + - template: templates/windows-packaging.yml + parameters: + Architecture: arm + parentJob: build_windows_arm_release + + - template: templates/windows-packaging.yml + parameters: + Architecture: arm64 + parentJob: build_windows_arm64_release + + - template: templates/windows-packaging.yml + parameters: + Architecture: fxdependent + parentJob: build_windows_fxdependent_release + + - template: templates/windows-packaging.yml + parameters: + Architecture: fxdependentWinDesktop + parentJob: build_windows_fxdependentWinDesktop_release + + - stage: package_signing + displayName: Package Signing + dependsOn: ['mac_packaging', 'linux_packaging', 'win_packaging'] + jobs: + - template: templates/windows-package-signing.yml + + # This is done late so that we dont use resources before the big signing and packaging tasks. - stage: compliance - dependsOn: ['windows'] + dependsOn: ['package_signing'] jobs: - template: templates/compliance.yml - stage: nuget_and_json - dependsOn: ['windows','linux','macOS'] + displayName: NuGet Packaging and Build Json + dependsOn: [package_signing] jobs: - template: templates/nuget.yml - - template: templates/json.yml - stage: test_and_release_artifacts + displayName: Test and Release Artifacts dependsOn: ['prep'] jobs: - template: templates/testartifacts.yml @@ -235,7 +344,7 @@ stages: - job: release_json displayName: Create and Upload release.json pool: - name: PowerShell1ES + name: $(windowsPool) demands: - ImageOverride -equals PSMMS2019-Secure steps: diff --git a/tools/releaseBuild/azureDevOps/templates/compliance/compliance.yml b/tools/releaseBuild/azureDevOps/templates/compliance/compliance.yml index 13603a0c80..8db52fc83f 100644 --- a/tools/releaseBuild/azureDevOps/templates/compliance/compliance.yml +++ b/tools/releaseBuild/azureDevOps/templates/compliance/compliance.yml @@ -17,7 +17,7 @@ jobs: dependsOn: ${{ parameters.parentJobs }} pool: - name: PowerShell1ES + name: $(windowsPool) demands: - ImageOverride -equals PSMMS2019-Secure diff --git a/tools/releaseBuild/azureDevOps/templates/json.yml b/tools/releaseBuild/azureDevOps/templates/json.yml index 1d6c10b8f3..48a50e0bf1 100644 --- a/tools/releaseBuild/azureDevOps/templates/json.yml +++ b/tools/releaseBuild/azureDevOps/templates/json.yml @@ -13,7 +13,7 @@ jobs: ${{ parameters.parentJobs }} condition: succeeded() pool: - name: PowerShell1ES + name: $(windowsPool) demands: - ImageOverride -equals PSMMS2019-Secure diff --git a/tools/releaseBuild/azureDevOps/templates/linux-packaging.yml b/tools/releaseBuild/azureDevOps/templates/linux-packaging.yml index 6837444b1b..1d6925c737 100644 --- a/tools/releaseBuild/azureDevOps/templates/linux-packaging.yml +++ b/tools/releaseBuild/azureDevOps/templates/linux-packaging.yml @@ -1,7 +1,6 @@ parameters: buildName: '' uploadDisplayName: 'Upload' - parentJob: '' jobs: - job: pkg_${{ parameters.buildName }} @@ -11,7 +10,6 @@ jobs: name: PowerShell1ES demands: - ImageOverride -equals PSMMSUbuntu20.04-Secure - dependsOn: sign_linux_builds variables: - name: runCodesignValidationInjection value: false diff --git a/tools/releaseBuild/azureDevOps/templates/mac-file-signing.yml b/tools/releaseBuild/azureDevOps/templates/mac-file-signing.yml index 5af4295994..8159c2bc7d 100644 --- a/tools/releaseBuild/azureDevOps/templates/mac-file-signing.yml +++ b/tools/releaseBuild/azureDevOps/templates/mac-file-signing.yml @@ -4,7 +4,6 @@ parameters: jobs: - job: MacFileSigningJob_${{ parameters.buildArchitecture }} displayName: macOS File signing ${{ parameters.buildArchitecture }} - dependsOn: build_macOS_${{ parameters.buildArchitecture }} condition: succeeded() pool: name: PowerShell1ES diff --git a/tools/releaseBuild/azureDevOps/templates/mac-package-build.yml b/tools/releaseBuild/azureDevOps/templates/mac-package-build.yml index 0f5b9acbc1..fc5c638c26 100644 --- a/tools/releaseBuild/azureDevOps/templates/mac-package-build.yml +++ b/tools/releaseBuild/azureDevOps/templates/mac-package-build.yml @@ -5,7 +5,6 @@ parameters: jobs: - job: package_macOS_${{ parameters.buildArchitecture }} displayName: Package macOS ${{ parameters.buildArchitecture }} - dependsOn: MacFileSigningJob_${{ parameters.buildArchitecture }} condition: succeeded() pool: vmImage: macos-latest diff --git a/tools/releaseBuild/azureDevOps/templates/nuget.yml b/tools/releaseBuild/azureDevOps/templates/nuget.yml index 269b614964..ddff73d351 100644 --- a/tools/releaseBuild/azureDevOps/templates/nuget.yml +++ b/tools/releaseBuild/azureDevOps/templates/nuget.yml @@ -8,7 +8,7 @@ jobs: displayName: Build NuGet packages condition: succeeded() pool: - name: PowerShell1ES + name: $(windowsPool) demands: - ImageOverride -equals PSMMS2019-Secure diff --git a/tools/releaseBuild/azureDevOps/templates/sign-build-file.yml b/tools/releaseBuild/azureDevOps/templates/sign-build-file.yml new file mode 100644 index 0000000000..cfa172796d --- /dev/null +++ b/tools/releaseBuild/azureDevOps/templates/sign-build-file.yml @@ -0,0 +1,324 @@ +steps: +- pwsh: | + $platform = '$(runtime)' -match '^linux' ? 'linux' : 'windows' + $vstsCommandString = "vso[task.setvariable variable=ArtifactPlatform]$platform" + Write-Host ("sending " + $vstsCommandString) + Write-Host "##$vstsCommandString" + displayName: Set artifact platform + +- task: DownloadPipelineArtifact@2 + inputs: + artifactName: '$(unsignedBuildArtifactContainer)' + itemPattern: '$(unsignedBuildArtifactName)' + +- pwsh: | + Get-ChildItem "$(Pipeline.Workspace)\*" -Recurse + displayName: 'Capture Downloaded Artifacts' + # Diagnostics is not critical it passes every time it runs + continueOnError: true + +- checkout: self + clean: true + path: $(repoFolder) + +- template: SetVersionVariables.yml + parameters: + ReleaseTagVar: $(ReleaseTagVar) + +- template: cloneToOfficialPath.yml + +- pwsh: | + $zipFileFilter = '$(unsignedBuildArtifactName)' + $zipFileFilter = $zipFileFilter.Replace('**/', '') + + Write-Verbose -Verbose -Message "zipFileFilter = $zipFileFilter" + + Write-Verbose -Verbose -Message "Looking for $(Pipeline.Workspace)\$(unsignedBuildArtifactName)" + + $zipFilePath = Get-ChildItem -Path '$(Pipeline.Workspace)\$(unsignedBuildArtifactName)' -recurse + + if (-not (Test-Path $zipFilePath)) + { + throw "zip file not found: $zipfilePath" + } + + if ($zipFilePath.Count -ne 1) { + Write-Verbose "zip filename" -verbose + $zipFilePath | Out-String | Write-Verbose -Verbose + throw 'multiple zip files found when 1 was expected' + } + + $expandedFolderName = [System.io.path]::GetFileNameWithoutExtension($zipfilePath) + $expandedFolderPath = Join-Path '$(Pipeline.Workspace)' 'expanded' $expandedFolderName + + Write-Verbose -Verbose -Message "Expaning $zipFilePath to $expandedFolderPath" + + New-Item -Path $expandedFolderPath -ItemType Directory + Expand-Archive -Path $zipFilePath -DestinationPath $expandedFolderPath + + if (-not (Test-Path $expandedFolderPath\pwsh.exe) ) { + throw 'zip did not expand as expected' + } + else { + $vstsCommandString = "vso[task.setvariable variable=BinPath]$expandedFolderPath" + Write-Host ("sending " + $vstsCommandString) + Write-Host "##$vstsCommandString" + } + + displayName: Expand zip packages + condition: eq(variables['ArtifactPlatform'], 'windows') + +- pwsh: | + $tarPackageName = '$(unsignedBuildArtifactName)' + + Write-Verbose -Verbose -Message "tarPackageName = $tarPackageName" + + $tarPackagePath = Join-Path '$(Pipeline.Workspace)' $tarPackageName + + Write-Verbose -Verbose -Message "Looking for: $tarPackagePath" + + $expandedPathFolderName = $tarPackageName -replace '.tar.gz', '' + $expandedFolderPath = Join-Path '$(Pipeline.Workspace)' 'expanded' $expandedPathFolderName + + if (-not (Test-Path $tarPackagePath)) + { + throw "tar file not found: $tarPackagePath" + } + + Write-Verbose -Verbose -Message "Expanding $tarPackagePath to $expandedFolderPath" + + New-Item -Path $expandedFolderPath -ItemType Directory + tar -xf $tarPackagePath -C $expandedFolderPath + + if (-not (Test-Path $expandedFolderPath/pwsh) ) { + throw 'tar.gz did not expand as expected' + } + else { + $vstsCommandString = "vso[task.setvariable variable=BinPath]$expandedFolderPath" + Write-Host ("sending " + $vstsCommandString) + Write-Host "##$vstsCommandString" + } + + Write-Verbose -Verbose "File permisions after expanding" + Get-ChildItem -Path "$expandedFolderPath/pwsh" | Select-Object -Property 'unixmode', 'size', 'name' + displayName: Expand tar.gz packages + condition: eq(variables['ArtifactPlatform'], 'linux') + +- template: insert-nuget-config-azfeed.yml + parameters: + repoRoot: $(PowerShellRoot) + +- pwsh: | + Set-Location $env:POWERSHELLROOT + import-module "$env:POWERSHELLROOT/build.psm1" + Sync-PSTags -AddRemoteIfMissing + displayName: SyncTags + condition: and(succeeded(), ne(variables['SkipBuild'], 'true')) + +- checkout: ComplianceRepo + clean: true + path: $(complianceRepoFolder) + +- template: shouldSign.yml + +- pwsh: | + $fullSymbolsFolder = '$(BinPath)' + Write-Verbose -Verbose "fullSymbolsFolder == $fullSymbolsFolder" + + Get-ChildItem -Recurse $fullSymbolsFolder | out-string | Write-Verbose -Verbose + + $filesToSignDirectory = "$(System.ArtifactsDirectory)\toBeSigned" + + if ((Test-Path -Path $filesToSignDirectory)) { + Remove-Item -Path $filesToSignDirectory -Recurse -Force + } + + $null = New-Item -ItemType Directory -Path $filesToSignDirectory -Force + + $signedFilesDirectory = "$(System.ArtifactsDirectory)\signed" + + if ((Test-Path -Path $signedFilesDirectory)) { + Remove-Item -Path $signedFilesDirectory -Recurse -Force + } + + $null = New-Item -ItemType Directory -Path $signedFilesDirectory -Force + + $itemsToCopyWithRecurse = @( + "$($fullSymbolsFolder)\*.ps1" + "$($fullSymbolsFolder)\Microsoft.PowerShell*.dll" + ) + + $itemsToCopy = @{ + "$($fullSymbolsFolder)\*.ps1" = "" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Host\Microsoft.PowerShell.Host.psd1" = "Modules\Microsoft.PowerShell.Host" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Management\Microsoft.PowerShell.Management.psd1" = "Modules\Microsoft.PowerShell.Management" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Security\Microsoft.PowerShell.Security.psd1" = "Modules\Microsoft.PowerShell.Security" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Utility\Microsoft.PowerShell.Utility.psd1" = "Modules\Microsoft.PowerShell.Utility" + "$($fullSymbolsFolder)\pwsh.dll" = "" + "$($fullSymbolsFolder)\System.Management.Automation.dll" = "" + } + + ## Windows only modules + + if('$(ArtifactPlatform)' -eq 'windows') { + $itemsToCopy += @{ + "$($fullSymbolsFolder)\pwsh.exe" = "" + "$($fullSymbolsFolder)\Microsoft.Management.Infrastructure.CimCmdlets.dll" = "" + "$($fullSymbolsFolder)\Microsoft.WSMan.*.dll" = "" + "$($fullSymbolsFolder)\Modules\CimCmdlets\CimCmdlets.psd1" = "Modules\CimCmdlets" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Diagnostics.format.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Event.format.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\GetEvent.types.ps1xml" = "Modules\Microsoft.PowerShell.Diagnostics" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Security\Security.types.ps1xml" = "Modules\Microsoft.PowerShell.Security" + "$($fullSymbolsFolder)\Modules\Microsoft.PowerShell.Diagnostics\Microsoft.PowerShell.Diagnostics.psd1" = "Modules\Microsoft.PowerShell.Diagnostics" + "$($fullSymbolsFolder)\Modules\Microsoft.WSMan.Management\Microsoft.WSMan.Management.psd1" = "Modules\Microsoft.WSMan.Management" + "$($fullSymbolsFolder)\Modules\Microsoft.WSMan.Management\WSMan.format.ps1xml" = "Modules\Microsoft.WSMan.Management" + "$($fullSymbolsFolder)\Modules\PSDiagnostics\PSDiagnostics.ps?1" = "Modules\PSDiagnostics" + } + } + else { + $itemsToCopy += @{ + "$($fullSymbolsFolder)\pwsh" = "" + } + } + + $itemsToExclude = @( + # This package is retrieved from https://www.github.com/powershell/MarkdownRender + "$($fullSymbolsFolder)\Microsoft.PowerShell.MarkdownRender.dll" + ) + + Write-Verbose -verbose "recusively copying $($itemsToCopyWithRecurse | out-string) to $filesToSignDirectory" + Copy-Item -Path $itemsToCopyWithRecurse -Destination $filesToSignDirectory -Recurse -verbose -exclude $itemsToExclude + + foreach($pattern in $itemsToCopy.Keys) { + $destinationFolder = Join-Path $filesToSignDirectory -ChildPath $itemsToCopy.$pattern + $null = New-Item -ItemType Directory -Path $destinationFolder -Force + Write-Verbose -verbose "copying $pattern to $destinationFolder" + Copy-Item -Path $pattern -Destination $destinationFolder -Recurse -verbose + } + displayName: 'Prepare files to be signed' + +- template: EsrpSign.yml@ComplianceRepo + parameters: + buildOutputPath: $(System.ArtifactsDirectory)\toBeSigned + signOutputPath: $(System.ArtifactsDirectory)\signed + certificateId: "$(AUTHENTICODE_CERT)" + pattern: | + **\*.dll + **\*.psd1 + **\*.psm1 + **\*.ps1xml + **\*.ps1 + **\*.exe + useMinimatch: true + shouldSign: $(SHOULD_SIGN) + displayName: Authenticode sign our binaries + +- pwsh: | + Import-Module $(PowerShellRoot)/build.psm1 -Force + Import-Module $(PowerShellRoot)/tools/packaging -Force + $signedFilesPath = '$(System.ArtifactsDirectory)\signed\' + $BuildPath = '$(BinPath)' + Write-Verbose -Verbose -Message "BuildPath: $BuildPath" + + Update-PSSignedBuildFolder -BuildPath $BuildPath -SignedFilesPath $SignedFilesPath + $dlls = Get-ChildItem $BuildPath\*.dll, $BuildPath\*.exe -Recurse + $signatures = $dlls | Get-AuthenticodeSignature + $missingSignatures = $signatures | Where-Object { $_.status -eq 'notsigned' -or $_.SignerCertificate.Issuer -notmatch '^CN=Microsoft.*'}| select-object -ExpandProperty Path + + Write-Verbose -verbose "to be signed:`r`n $($missingSignatures | Out-String)" + + $filesToSignDirectory = "$(System.ArtifactsDirectory)\thirdPartyToBeSigned" + if (Test-Path $filesToSignDirectory) { + Remove-Item -Path $filesToSignDirectory -Recurse -Force + } + + $null = New-Item -ItemType Directory -Path $filesToSignDirectory -Force -Verbose + + $signedFilesDirectory = "$(System.ArtifactsDirectory)\thirdPartySigned" + if (Test-Path $signedFilesDirectory) { + Remove-Item -Path $signedFilesDirectory -Recurse -Force + } + + $null = New-Item -ItemType Directory -Path $signedFilesDirectory -Force -Verbose + + $missingSignatures | ForEach-Object { + $pathWithoutLeaf = Split-Path $_ + $relativePath = $pathWithoutLeaf.replace($BuildPath,'') + Write-Verbose -Verbose -Message "relativePath: $relativePath" + $targetDirectory = Join-Path -Path $filesToSignDirectory -ChildPath $relativePath + Write-Verbose -Verbose -Message "targetDirectory: $targetDirectory" + if(!(Test-Path $targetDirectory)) + { + $null = New-Item -ItemType Directory -Path $targetDirectory -Force -Verbose + } + Copy-Item -Path $_ -Destination $targetDirectory + } + + displayName: Create ThirdParty Signing Folder + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) + +- template: EsrpSign.yml@ComplianceRepo + parameters: + buildOutputPath: $(System.ArtifactsDirectory)\thirdPartyToBeSigned + signOutputPath: $(System.ArtifactsDirectory)\thirdPartySigned + certificateId: "CP-231522" + pattern: | + **\*.dll + useMinimatch: true + shouldSign: $(SHOULD_SIGN) + displayName: Sign ThirdParty binaries + +- pwsh: | + Get-ChildItem '$(System.ArtifactsDirectory)\thirdPartySigned\*' + displayName: Capture ThirdParty Signed files + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) + +- pwsh: | + Import-Module '$(PowerShellRoot)/build.psm1' -Force + Import-Module '$(PowerShellRoot)/tools/packaging' -Force + $signedFilesPath = '$(System.ArtifactsDirectory)\thirdPartySigned' + $BuildPath = '$(BinPath)' + + Update-PSSignedBuildFolder -BuildPath $BuildPath -SignedFilesPath $SignedFilesPath + if ($env:BuildConfiguration -eq 'minSize') { + ## Remove XML files when making a min-size package. + Remove-Item "$BuildPath/*.xml" -Force + } + displayName: Merge ThirdParty signed files with Build + condition: and(succeeded(), eq(variables['SHOULD_SIGN'], 'true')) + +- pwsh: | + $uploadFolder = '$(BinPath)' + $containerName = '$(signedArtifactContainer)' + + Write-Verbose -Verbose "File permissions after signing" + Get-ChildItem $uploadFolder\pwsh | Select-Object -Property 'unixmode', 'size', 'name' + + $uploadTarFilePath = Join-Path '$(System.ArtifactsDirectory)' '$(signedBuildArtifactName)' + Write-Verbose -Verbose -Message "Creating tar.gz - $uploadTarFilePath" + tar -czvf $uploadTarFilePath -C $uploadFolder * + + Get-ChildItem '$(System.ArtifactsDirectory)' | Out-String | Write-Verbose -Verbose + + Write-Host "##vso[artifact.upload containerfolder=$containerName;artifactname=$containerName]$uploadTarFilePath" + displayName: Upload signed tar.gz files to artifacts + condition: eq(variables['ArtifactPlatform'], 'linux') + +- pwsh: | + $uploadFolder = '$(BinPath)' + $containerName = '$(signedArtifactContainer)' + + Get-ChildItem $uploadFolder -Recurse | Out-String | Write-Verbose -Verbose + + $uploadZipFilePath = Join-Path '$(System.ArtifactsDirectory)' 'PowerShell-$(Version)$(signedBuildArtifactName)' + Write-Verbose -Verbose -Message "Creating zip - $uploadZipFilePath" + Compress-Archive -Path $uploadFolder/* -DestinationPath $uploadZipFilePath -Verbose + + Get-ChildItem '$(System.ArtifactsDirectory)' | Out-String | Write-Verbose -Verbose + + Write-Host "##vso[artifact.upload containerfolder=$containerName;artifactname=$containerName]$uploadZipFilePath" + displayName: Upload signed zip files to artifacts + condition: eq(variables['ArtifactPlatform'], 'windows') + +- template: /tools/releaseBuild/azureDevOps/templates/step/finalize.yml diff --git a/tools/releaseBuild/azureDevOps/templates/windows-hosted-build.yml b/tools/releaseBuild/azureDevOps/templates/windows-hosted-build.yml index fd04f5ba5f..d0952568bf 100644 --- a/tools/releaseBuild/azureDevOps/templates/windows-hosted-build.yml +++ b/tools/releaseBuild/azureDevOps/templates/windows-hosted-build.yml @@ -14,7 +14,7 @@ jobs: condition: succeeded() dependsOn: ${{ parameters.parentJob }} pool: - name: PowerShell1ES + name: $(windowsPool) demands: - ImageOverride -equals PSMMS2019-Secure variables: diff --git a/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml b/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml index c2e3f4d1c1..44b76127dd 100644 --- a/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml +++ b/tools/releaseBuild/azureDevOps/templates/windows-package-signing.yml @@ -8,7 +8,7 @@ jobs: ${{ parameters.parentJobs }} condition: succeeded() pool: - name: PowerShell1ES + name: $(windowsPool) demands: - ImageOverride -equals PSMMS2019-Secure variables: diff --git a/tools/releaseBuild/azureDevOps/templates/windows-packaging.yml b/tools/releaseBuild/azureDevOps/templates/windows-packaging.yml index 0b9ff979ef..f0b1e10bbb 100644 --- a/tools/releaseBuild/azureDevOps/templates/windows-packaging.yml +++ b/tools/releaseBuild/azureDevOps/templates/windows-packaging.yml @@ -12,9 +12,8 @@ jobs: - job: sign_windows_${{ parameters.Architecture }}_${{ parameters.BuildConfiguration }} displayName: Package Windows - ${{ parameters.Architecture }} ${{ parameters.BuildConfiguration }} condition: succeeded() - dependsOn: ${{ parameters.parentJob }} pool: - name: PowerShell1ES + name: $(windowsPool) demands: - ImageOverride -equals PSMMS2019-Secure variables: