[release/v7.5] Add rebuild branch support with conditional MSIX signing (#26817)

This commit is contained in:
Dongbo Wang
2026-02-13 15:16:12 -08:00
committed by GitHub
parent 579b53ea83
commit 914288e476
9 changed files with 144 additions and 20 deletions
@@ -354,6 +354,9 @@ try {
$skipPublish = $metadataContent.SkipPublish
$lts = $metadataContent.LTS
# Check if this is a rebuild version (e.g., 7.4.13-rebuild.5)
$isRebuild = $releaseVersion -match '-rebuild\.'
if ($releaseVersion.Contains('-')) {
$channel = 'preview'
$packageNames = @('powershell-preview')
@@ -363,7 +366,8 @@ try {
$packageNames = @('powershell')
}
if ($lts) {
# Only add LTS package if not a rebuild branch
if ($lts -and -not $isRebuild) {
$packageNames += @('powershell-lts')
}
@@ -284,9 +284,20 @@ extends:
- template: /.pipelines/templates/SetVersionVariables.yml@self
parameters:
ReleaseTagVar: $(ReleaseTagVar)
- template: /.pipelines/templates/rebuild-branch-check.yml@self
- powershell: |
$metadata = Get-Content '$(Build.SourcesDirectory)/PowerShell/tools/metadata.json' -Raw | ConvertFrom-Json
$LTS = $metadata.LTSRelease.Package
# Use the rebuild branch check from the template
$isRebuildBranch = '$(RebuildBranchCheck.IsRebuildBranch)' -eq 'true'
# Don't mark as LTS release for rebuild branches
$LTS = $metadata.LTSRelease.Package -and -not $isRebuildBranch
if ($isRebuildBranch) {
Write-Verbose -Message "Rebuild branch detected, not marking as LTS release" -Verbose
}
@{ ReleaseVersion = "$(Version)"; LTSRelease = $LTS } | ConvertTo-Json | Out-File "$(Build.StagingDirectory)\release.json"
Get-Content "$(Build.StagingDirectory)\release.json"
@@ -293,6 +293,8 @@ extends:
dependsOn: [windows_package_build] # Only depends on unsigned packages
jobs:
- template: /.pipelines/templates/package-create-msix.yml@self
parameters:
OfficialBuild: ${{ parameters.OfficialBuild }}
- stage: upload
displayName: 'Upload'
+22 -4
View File
@@ -2,13 +2,31 @@ steps:
- pwsh: |
# Determine LTS, Preview, or Stable
$metadata = Get-Content "$(Build.SourcesDirectory)/PowerShell/tools/metadata.json" -Raw | ConvertFrom-Json
$releaseTag = '$(OutputReleaseTag.releaseTag)'
# Rebuild branches should be treated as preview builds
# NOTE: The following regex is duplicated from rebuild-branch-check.yml.
# This duplication is necessary because channelSelection.yml does not call rebuild-branch-check.yml,
# and is used in contexts where that check may not have run.
# If you update this regex, also update it in rebuild-branch-check.yml to keep them in sync.
$isRebuildBranch = '$(Build.SourceBranch)' -match 'refs/heads/rebuild/.*-rebuild\.'
$LTS = $metadata.LTSRelease.Latest
$Stable = $metadata.StableRelease.Latest
$isPreview = '$(OutputReleaseTag.releaseTag)' -match '-'
$isPreview = $releaseTag -match '-'
$IsLTS = [bool]$LTS
$IsStable = [bool]$Stable
$IsPreview = [bool]$isPreview
# If this is a rebuild branch, force preview mode and ignore LTS metadata
if ($isRebuildBranch) {
$IsLTS = $false
$IsStable = $false
$IsPreview = $true
Write-Verbose -Message "Rebuild branch detected, forcing Preview channel" -Verbose
}
else {
$IsLTS = [bool]$LTS
$IsStable = [bool]$Stable
$IsPreview = [bool]$isPreview
}
$channelVars = @{
IsLTS = $IsLTS
+17 -1
View File
@@ -62,6 +62,8 @@ jobs:
parameters:
nativePathRoot: '$(Agent.TempDirectory)'
- template: rebuild-branch-check.yml@self
- download: CoOrdinatedBuildPipeline
artifact: ${{ parameters.unsignedDrop }}
displayName: 'Download unsigned artifacts'
@@ -139,7 +141,21 @@ jobs:
}
$metadata = Get-Content "$repoRoot/tools/metadata.json" -Raw | ConvertFrom-Json
$LTS = $metadata.LTSRelease.Package
Write-Verbose -Verbose "metadata:"
$metadata | Out-String | Write-Verbose -Verbose
# Use the rebuild branch check from the template
$isRebuildBranch = '$(RebuildBranchCheck.IsRebuildBranch)' -eq 'true'
# Don't build LTS packages for rebuild branches
$LTS = $metadata.LTSRelease.Package -and -not $isRebuildBranch
if ($isRebuildBranch) {
Write-Verbose -Message "Rebuild branch detected, skipping LTS package build" -Verbose
}
Write-Verbose -Verbose "LTS: $LTS"
if ($LTS) {
Write-Verbose -Message "LTS Release: $LTS"
+17 -1
View File
@@ -60,6 +60,8 @@ jobs:
parameters:
nativePathRoot: '$(Agent.TempDirectory)'
- template: rebuild-branch-check.yml@self
- download: CoOrdinatedBuildPipeline
artifact: macosBinResults-${{ parameters.buildArchitecture }}
@@ -103,7 +105,21 @@ jobs:
Get-PSOptions | Write-Verbose -Verbose
$metadata = Get-Content "$repoRoot/tools/metadata.json" -Raw | ConvertFrom-Json
$LTS = $metadata.LTSRelease.Package
Write-Verbose -Verbose "metadata:"
$metadata | Out-String | Write-Verbose -Verbose
# Use the rebuild branch check from the template
$isRebuildBranch = '$(RebuildBranchCheck.IsRebuildBranch)' -eq 'true'
# Don't build LTS packages for rebuild branches
$LTS = $metadata.LTSRelease.Package -and -not $isRebuildBranch
if ($isRebuildBranch) {
Write-Verbose -Message "Rebuild branch detected, skipping LTS package build" -Verbose
}
Write-Verbose -Verbose "LTS: $LTS"
if ($LTS) {
Write-Verbose -Message "LTS Release: $LTS"
+35 -11
View File
@@ -1,3 +1,8 @@
parameters:
- name: OfficialBuild
type: boolean
default: false
jobs:
- job: CreateMSIXBundle
displayName: Create .msixbundle file
@@ -45,7 +50,7 @@ jobs:
**/*.msix
targetPath: '$(Build.ArtifactStagingDirectory)/downloads'
displayName: Download windows x86 packages
# Finds the makeappx tool on the machine with image: 'onebranch.azurecr.io/windows/ltsc2022/vse2022:latest'
- pwsh: |
$cmd = Get-Command makeappx.exe -ErrorAction Ignore
@@ -95,12 +100,13 @@ jobs:
- task: onebranch.pipeline.signing@1
displayName: Sign MsixBundle
condition: eq('${{ parameters.OfficialBuild }}', 'true')
inputs:
command: 'sign'
signing_profile: $(MSIXProfile)
files_to_sign: '**/*.msixbundle'
search_root: '$(BundleDir)'
- pwsh: |
$signedBundle = Get-ChildItem -Path $(BundleDir) -Filter "*.msixbundle" -File
Write-Verbose -Verbose "Signed bundle: $signedBundle"
@@ -124,12 +130,12 @@ jobs:
Get-ChildItem -Path $(System.DefaultWorkingDirectory) -Recurse | Select-Object -ExpandProperty FullName
Test-Path -Path '$(System.DefaultWorkingDirectory)/PowerShell/.pipelines/store/PDP-Private.xml' | Write-Verbose -Verbose
displayName: Output Pipeline.Workspace and System.DefaultWorkingDirectory
- template: channelSelection.yml@self
- pwsh: |
$IsLTS = '$(ChannelSelection.IsLTS)' -eq 'true'
$IsStable = '$(ChannelSelection.IsStable)' -eq 'true'
$IsStable = '$(ChannelSelection.IsStable)' -eq 'true'
$IsPreview = '$(ChannelSelection.IsPreview)' -eq 'true'
Write-Verbose -Verbose "Channel Selection - LTS: $IsLTS, Stable: $IsStable, Preview: $IsPreview"
@@ -156,11 +162,11 @@ jobs:
$currentChannel = if ($IsLTS) { 'LTS' }
elseif ($IsStable) { 'Stable' }
elseif ($IsPreview) { 'Preview' }
else {
else {
Write-Error "No valid channel detected"
exit 1
}
$config = $channelConfigs[$currentChannel]
Write-Verbose -Verbose "Selected channel: $currentChannel"
Write-Verbose -Verbose "App Store Name: $($config.AppStoreName)"
@@ -209,12 +215,30 @@ jobs:
Write-Host "##vso[task.setvariable variable=SBConfigPath]$($sbConfigPath)"
# These variables are used in the next tasks to determine which ServiceEndpoint to use
Write-Host "##vso[task.setvariable variable=LTS]$($IsLTS.ToString().ToLower())"
Write-Host "##vso[task.setvariable variable=STABLE]$($IsStable.ToString().ToLower())"
Write-Host "##vso[task.setvariable variable=PREVIEW]$($IsPreview.ToString().ToLower())"
$ltsValue = $IsLTS.ToString().ToLower()
$stableValue = $IsStable.ToString().ToLower()
$previewValue = $IsPreview.ToString().ToLower()
Write-Verbose -Verbose "About to set variables:"
Write-Verbose -Verbose " LTS=$ltsValue"
Write-Verbose -Verbose " STABLE=$stableValue"
Write-Verbose -Verbose " PREVIEW=$previewValue"
Write-Host "##vso[task.setvariable variable=LTS]$ltsValue"
Write-Host "##vso[task.setvariable variable=STABLE]$stableValue"
Write-Host "##vso[task.setvariable variable=PREVIEW]$previewValue"
Write-Verbose -Verbose "Variables set successfully"
name: UpdateConfigs
displayName: Update PDPs and SBConfig.json
- pwsh: |
Write-Verbose -Verbose "Checking variables after UpdateConfigs:"
Write-Verbose -Verbose "LTS=$(LTS)"
Write-Verbose -Verbose "STABLE=$(STABLE)"
Write-Verbose -Verbose "PREVIEW=$(PREVIEW)"
displayName: Debug - Check Variables
- task: MS-RDX-MRO.windows-store-publish.package-task.store-package@3
displayName: 'Create StoreBroker Package (Preview)'
condition: eq('$(PREVIEW)', 'true')
@@ -243,14 +267,14 @@ jobs:
$submissionPackageDir = "$(System.DefaultWorkingDirectory)/SBOutDir"
$jsonFile = "$submissionPackageDir/PowerShellStorePackage.json"
$zipFile = "$submissionPackageDir/PowerShellStorePackage.zip"
if ((Test-Path $jsonFile) -and (Test-Path $zipFile)) {
Write-Verbose -Verbose "Uploading StoreBroker Package files:"
Write-Verbose -Verbose "JSON File: $jsonFile"
Write-Verbose -Verbose "ZIP File: $zipFile"
Copy-Item -Path $submissionPackageDir -Destination "$(ob_outputDirectory)" -Verbose -Recurse
}
}
else {
Write-Error "Required files not found in $submissionPackageDir"
@@ -60,6 +60,8 @@ jobs:
nativePathRoot: '$(Agent.TempDirectory)'
ob_restore_phase: false
- template: rebuild-branch-check.yml@self
- download: CoOrdinatedBuildPipeline
artifact: drop_windows_build_windows_${{ parameters.runtime }}_release
displayName: Download signed artifacts
@@ -127,7 +129,21 @@ jobs:
Get-PSOptions | Write-Verbose -Verbose
$metadata = Get-Content "$repoRoot/tools/metadata.json" -Raw | ConvertFrom-Json
$LTS = $metadata.LTSRelease.Package
Write-Verbose -Verbose "metadata:"
$metadata | Out-String | Write-Verbose -Verbose
# Use the rebuild branch check from the template
$isRebuildBranch = '$(RebuildBranchCheck.IsRebuildBranch)' -eq 'true'
# Don't build LTS packages for rebuild branches
$LTS = $metadata.LTSRelease.Package -and -not $isRebuildBranch
if ($isRebuildBranch) {
Write-Verbose -Message "Rebuild branch detected, skipping LTS package build" -Verbose
}
Write-Verbose -Verbose "LTS: $LTS"
if ($LTS) {
Write-Verbose -Message "LTS Release: $LTS"
@@ -0,0 +1,17 @@
# This template checks if the current branch is a rebuild branch
# and sets an output variable IsRebuildBranch that can be used by other templates
steps:
- pwsh: |
# Check if this is a rebuild branch (e.g., rebuild/v7.4.13-rebuild.5)
$isRebuildBranch = '$(Build.SourceBranch)' -match 'refs/heads/rebuild/.*-rebuild\.'
$value = if ($isRebuildBranch) { 'true' } else { 'false' }
Write-Verbose -Message "IsRebuildBranch: $value" -Verbose
if ($isRebuildBranch) {
Write-Verbose -Message "Rebuild branch detected: $(Build.SourceBranch)" -Verbose
}
Write-Host "##vso[task.setvariable variable=IsRebuildBranch;isOutput=true]$value"
name: RebuildBranchCheck
displayName: Check if Rebuild Branch