mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Apply macOS entitlements to pwsh
Uses codesign in the macOS build step to apply entitlements from a plist. This is required for the hardened runtime (which is required for notarization). See: https://learn.microsoft.com/en-us/dotnet/core/install/macos-notarization-issues#default-entitlements Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -69,6 +69,14 @@ jobs:
|
||||
$psOptPath = "$(OB_OUTPUTDIRECTORY)/psoptions.json"
|
||||
Save-PSOptions -PSOptionsPath $psOptPath
|
||||
|
||||
$entitlements = "$(PowerShellRoot)/assets/macos-entitlements.plist"
|
||||
$pwshBin = "$(OB_OUTPUTDIRECTORY)/pwsh"
|
||||
Write-Verbose -Verbose "Applying entitlements to $pwshBin"
|
||||
codesign --sign - --force --options runtime --entitlements $entitlements $pwshBin
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "codesign failed with exit code $LASTEXITCODE"
|
||||
}
|
||||
|
||||
# Since we are using custom pool for macOS, we need to use artifact.upload to publish the artifacts
|
||||
Write-Host "##vso[artifact.upload containerfolder=$artifactName;artifactname=$artifactName]$(OB_OUTPUTDIRECTORY)"
|
||||
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>com.apple.security.cs.allow-jit</key>
|
||||
<true/>
|
||||
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
|
||||
<true/>
|
||||
<key>com.apple.security.cs.allow-dyld-environment-variables</key>
|
||||
<true/>
|
||||
<key>com.apple.security.cs.disable-library-validation</key>
|
||||
<true/>
|
||||
</dict>
|
||||
</plist>
|
||||
Reference in New Issue
Block a user